|
Plagegeister aller Art und deren Bekämpfung: AVG - Programm wurde durch eine Gruppenrichtlinie blockiertWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
03.09.2014, 17:11 | #1 | ||
| AVG - Programm wurde durch eine Gruppenrichtlinie blockiert Hallo Leute, Ich war gestern mal wieder die Familie besuchen. Es gibt da nur eine sehr schlechte Leitung und mein Bruder hat sich 2 Spiele per Steam gekauft, die aber ewig zum Runterladen brauchen. Nett wie ich bin, hab ich meine Festplatte mitgenommen, angesteckt und ihm die beiden Spiele in den Steamordner kopiert. Mir ist allerdings bei ihm schon aufgefallen, dass Avira ständig inaktiv war und sich auch nicht hat aktivieren lassen. War mir schon klar, dass da was drauf ist, hab meine Festplatte also schnellstmöglich abgestöpselt und gehofft, dass nix passiert ist. Aufgrund der Tatsache, dass ich hier bin, kann man ja entnehmen, dass doch etwas passiert ist. Es gab ein kurzes Popup von Windows, dass AVG nicht aktiv ist, und es war auch nicht im System Tray zu finden. Beim Starten hat er dann eben die Fehlermeldung ausgespuckt: Zitat:
Die Logs häng ich unten an. Ich selber fummel da jetzt nicht rum, weil ich mich mit so nem Virus echt nicht auskenne. Gruß G230 FRST.txt FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2014 02 Ran by Les Enfants terrible (administrator) on GRANDMASTER-PC on 03-09-2014 17:57:50 Running from C:\Progr\Downloads Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SbieSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\xampp\mysql\bin\mysqld.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe (TeamViewer GmbH) C:\Progr()\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SbieCtrl.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Samsung) F:\Programme\Kies\Kies\Kies.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Samsung Electronics Co., Ltd.) F:\Programme\Kies\Kies\KiesTrayAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () F:\Games\RiotGames\League of Legends\RADS\system\rads_user_kernel.exe () F:\Games\RiotGames\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.218\deploy\LoLLauncher.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SbieSvc.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SandboxieRpcSs.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SandboxieDcomLaunch.exe (Mozilla Corporation) C:\Sandbox\Les_Enfants_terrible\DefaultBox\drive\C\Progr\Nightly\firefox.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\32\SbieSvc.exe () F:\Games\RiotGames\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.2\deploy\LoLPatcher.exe () F:\Games\RiotGames\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.2\deploy\LoLPatcher.exe () F:\Games\RiotGames\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.2\deploy\LoLPatcher.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (Mozilla Corporation) C:\Sandbox\Les_Enfants_terrible\DefaultBox\drive\C\Progr\Nightly\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7188552 2013-05-27] (Realtek Semiconductor) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5188112 2014-08-25] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [KiesTrayAgent] => F:\Programme\Kies\Kies\KiesTrayAgent.exe [311616 2014-02-07] (Samsung Electronics Co., Ltd.) HKLM Group Policy restriction on software: C:\Program Files (x86)\AVG <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\AVG <====== ATTENTION HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [SandboxieControl] => C:\Progr\Sandboxie\SbieCtrl.exe [759496 2013-10-16] (Sandboxie Holdings, LLC) HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\Les Enfants terrible\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=aa0b8eefa6ee47d2a909057438040658-2ee9e78203d112addbcd299bd4ed93e05fb659f6 /CMPID=1213b HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21650016 2014-07-24] (Skype Technologies S.A.) HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [KiesPreload] => F:\Programme\Kies\Kies\Kies.exe [1564992 2014-02-07] (Samsung) HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [KiesAirMessage] => F:\Programme\Kies\Kies\KiesAirMessage.exe -startup HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\MountPoints2: {32dafb45-70cf-11e3-b0ab-806e6f6e6963} - D:\autorun.exe HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\MountPoints2: {8c87f698-85a7-11e3-8dfc-d43d7ee0efab} - G:\autorun.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Les Enfants terrible\AppData\Roaming\Mozilla\Firefox\Profiles\u9fibwzu.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF StartMenuInternet: FIREFOX.EXE - C:\Progr\Nightly\firefox.exe Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Apache2.4; c:\xampp\apache\bin\httpd.exe [22016 2012-06-06] (Apache Software Foundation) [File not signed] R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3242000 2014-08-25] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-08-25] (AVG Technologies CZ, s.r.o.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-08-08] () [File not signed] S3 FileZillaServer; c:\xampp\FileZillaFTP\FileZillaServer.exe [632320 2012-05-11] (FileZilla Project) [File not signed] R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-17] (Intel Corporation) R2 mysql; c:\xampp\mysql\bin\mysqld.exe [8180224 2012-06-29] () [File not signed] R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-14] () R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2009-07-10] (Realtek) [File not signed] R2 SbieSvc; C:\Progr\Sandboxie\SbieSvc.exe [186056 2013-10-16] (Sandboxie Holdings, LLC) R2 TeamViewer9; C:\Progr()\TeamViewer\Version9\TeamViewer_Service.exe [5037888 2014-07-02] (TeamViewer GmbH) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [244504 2014-07-21] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-08-06] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2014-01-25] (DT Soft Ltd) R3 SbieDrv; C:\Progr\Sandboxie\SbieDrv.sys [200552 2013-10-16] (Sandboxie Holdings, LLC) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 MSICDSetup; \??\D:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-03 17:57 - 2014-09-03 17:57 - 00000000 ____D () C:\FRST 2014-08-31 07:07 - 2014-08-31 07:07 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\Dishonored.url 2014-08-30 08:06 - 2014-08-30 08:30 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (6) 2014-08-29 22:13 - 2014-08-29 22:13 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\KnightShift.url 2014-08-27 18:16 - 2014-08-27 18:16 - 00003312 _____ () C:\Users\Les Enfants terrible\AppData\Local\recently-used.xbel 2014-08-26 17:49 - 2014-08-26 17:49 - 00002468 _____ () C:\Windows\System32\Tasks\0814avUpdateInfo 2014-08-26 17:49 - 2014-08-26 17:49 - 00000320 _____ () C:\Windows\Tasks\0814avUpdateInfo.job 2014-08-26 17:49 - 2014-08-26 17:49 - 00000000 ____D () C:\ProgramData\Avg_Update_0814av 2014-08-25 21:41 - 2014-08-25 22:35 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Darksiders 2014-08-25 21:38 - 2014-08-25 21:40 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-08-25 21:38 - 2014-08-25 21:38 - 00002105 _____ () C:\Users\Public\Desktop\Darksiders Comic.lnk 2014-08-25 21:38 - 2014-08-25 21:38 - 00001957 _____ () C:\Users\Public\Desktop\Darksiders SoundTrack.lnk 2014-08-25 21:38 - 2014-08-25 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ 2014-08-25 21:38 - 2014-08-25 21:38 - 00000000 ____D () C:\Program Files (x86)\THQ 2014-08-24 22:58 - 2014-08-24 22:58 - 00000201 _____ () C:\Users\Les Enfants terrible\Desktop\Darksiders II.url 2014-08-24 15:56 - 2014-08-24 15:56 - 00000000 ____D () C:\Windows\46ED2B6485C74E1F920CA555B21F2E4C.TMP 2014-08-18 22:16 - 2014-08-18 22:16 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\The Witcher 2014-08-18 22:09 - 2014-08-18 22:09 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (5) 2014-08-17 23:06 - 2014-08-17 23:07 - 00000000 ____D () C:\ProgramData\IhupgApeve 2014-08-15 14:44 - 2014-08-15 14:44 - 00108144 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll 2014-08-13 15:56 - 2014-08-13 15:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf 2014-08-13 12:08 - 2014-08-13 12:08 - 00000674 _____ () C:\Users\Public\Desktop\Cube World.lnk 2014-08-13 12:08 - 2014-08-13 12:08 - 00000000 ____D () C:\ProgramData\Picroma 2014-08-12 20:37 - 2014-08-12 20:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec 2014-08-12 20:35 - 2014-08-12 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2014-08-12 20:35 - 2014-02-07 16:33 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll 2014-08-12 20:35 - 2014-01-23 18:31 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll 2014-08-12 20:34 - 2014-08-12 20:34 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Downloaded Installations 2014-08-12 20:24 - 2014-08-12 20:35 - 00000000 ____D () C:\ProgramData\Samsung 2014-08-12 20:24 - 2014-08-12 20:24 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-08-12 20:24 - 2013-12-26 07:41 - 01919168 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01005.dll 2014-08-12 20:24 - 2013-12-26 07:41 - 01919168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01005.dll 2014-08-12 20:24 - 2013-12-26 07:41 - 00188232 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdmdm.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00188232 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadmdm.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00169288 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdbus.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00169288 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadbus.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00158024 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadserd.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00038080 _____ (Google Inc) C:\Windows\system32\Drivers\ssadadb.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00021320 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdmdfl.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00021320 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadmdfl.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017736 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdwhnt.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017736 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdwh.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017736 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadwhnt.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017736 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadwh.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017224 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdcmnt.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017224 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdcm.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017224 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadcmnt.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017224 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadcm.sys 2014-08-12 20:03 - 2014-08-12 20:34 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\odin 2014-08-12 13:09 - 2014-08-12 13:09 - 00000960 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim Launcher.lnk 2014-08-12 13:09 - 2014-08-12 13:09 - 00000908 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim.lnk 2014-08-11 14:29 - 2014-08-13 19:13 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\ZSNES 2014-08-08 20:02 - 2014-08-08 20:18 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\DayZ 2014-08-08 20:02 - 2014-08-08 20:18 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\DayZ 2014-08-08 13:53 - 2014-08-08 13:53 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\DayZ.url 2014-08-07 15:08 - 2014-08-07 15:08 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Risen 2014-08-06 10:50 - 2014-08-06 10:50 - 00123672 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-03 17:57 - 2014-09-03 17:57 - 00000000 ____D () C:\FRST 2014-09-03 17:51 - 2009-07-14 06:45 - 00028976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-03 17:51 - 2009-07-14 06:45 - 00028976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-03 17:50 - 2014-04-02 17:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2014-09-03 17:50 - 2013-12-30 08:15 - 00709292 _____ () C:\Windows\system32\perfh007.dat 2014-09-03 17:50 - 2013-12-30 08:15 - 00153728 _____ () C:\Windows\system32\perfc007.dat 2014-09-03 17:50 - 2013-12-29 23:53 - 00000981 _____ () C:\Users\Public\Desktop\AVG 2014.lnk 2014-09-03 17:50 - 2013-12-29 23:52 - 00000000 ____D () C:\ProgramData\MFAData 2014-09-03 17:50 - 2009-07-14 07:13 - 01647128 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-03 17:47 - 2013-12-29 23:26 - 01085441 _____ () C:\Windows\WindowsUpdate.log 2014-09-03 17:46 - 2013-12-30 00:11 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Roaming\Skype 2014-09-03 17:44 - 2013-12-29 23:36 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-09-03 17:44 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-03 17:44 - 2009-07-14 06:51 - 00066801 _____ () C:\Windows\setupact.log 2014-09-01 18:43 - 2013-12-29 22:44 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Roaming\.minecraft 2014-08-31 07:07 - 2014-08-31 07:07 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\Dishonored.url 2014-08-30 08:30 - 2014-08-30 08:06 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (6) 2014-08-29 22:13 - 2014-08-29 22:13 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\KnightShift.url 2014-08-29 19:56 - 2014-08-03 12:15 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (4) 2014-08-29 18:27 - 2014-01-01 03:35 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Skyrim 2014-08-27 18:16 - 2014-08-27 18:16 - 00003312 _____ () C:\Users\Les Enfants terrible\AppData\Local\recently-used.xbel 2014-08-27 18:16 - 2014-01-16 20:01 - 00000000 ____D () C:\Users\Les Enfants terrible\.gimp-2.8 2014-08-26 17:49 - 2014-08-26 17:49 - 00002468 _____ () C:\Windows\System32\Tasks\0814avUpdateInfo 2014-08-26 17:49 - 2014-08-26 17:49 - 00000320 _____ () C:\Windows\Tasks\0814avUpdateInfo.job 2014-08-26 17:49 - 2014-08-26 17:49 - 00000000 ____D () C:\ProgramData\Avg_Update_0814av 2014-08-25 22:35 - 2014-08-25 21:41 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Darksiders 2014-08-25 21:41 - 2013-12-30 00:23 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\My Games 2014-08-25 21:40 - 2014-08-25 21:38 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-08-25 21:40 - 2013-12-29 23:32 - 00184632 _____ () C:\Windows\DirectX.log 2014-08-25 21:38 - 2014-08-25 21:38 - 00002105 _____ () C:\Users\Public\Desktop\Darksiders Comic.lnk 2014-08-25 21:38 - 2014-08-25 21:38 - 00001957 _____ () C:\Users\Public\Desktop\Darksiders SoundTrack.lnk 2014-08-25 21:38 - 2014-08-25 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ 2014-08-25 21:38 - 2014-08-25 21:38 - 00000000 ____D () C:\Program Files (x86)\THQ 2014-08-25 07:51 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-08-24 22:58 - 2014-08-24 22:58 - 00000201 _____ () C:\Users\Les Enfants terrible\Desktop\Darksiders II.url 2014-08-24 15:56 - 2014-08-24 15:56 - 00000000 ____D () C:\Windows\46ED2B6485C74E1F920CA555B21F2E4C.TMP 2014-08-18 22:16 - 2014-08-18 22:16 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\The Witcher 2014-08-18 22:09 - 2014-08-18 22:09 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (5) 2014-08-17 23:07 - 2014-08-17 23:06 - 00000000 ____D () C:\ProgramData\IhupgApeve 2014-08-17 23:07 - 2013-12-29 23:52 - 00000000 ____D () C:\ProgramData\AVG2014 2014-08-15 14:44 - 2014-08-15 14:44 - 00108144 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll 2014-08-13 19:13 - 2014-08-11 14:29 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\ZSNES 2014-08-13 15:56 - 2014-08-13 15:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf 2014-08-13 12:08 - 2014-08-13 12:08 - 00000674 _____ () C:\Users\Public\Desktop\Cube World.lnk 2014-08-13 12:08 - 2014-08-13 12:08 - 00000000 ____D () C:\ProgramData\Picroma 2014-08-12 20:37 - 2014-08-12 20:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec 2014-08-12 20:35 - 2014-08-12 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2014-08-12 20:35 - 2014-08-12 20:24 - 00000000 ____D () C:\ProgramData\Samsung 2014-08-12 20:35 - 2013-12-29 23:26 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-08-12 20:34 - 2014-08-12 20:34 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Downloaded Installations 2014-08-12 20:34 - 2014-08-12 20:03 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\odin 2014-08-12 20:24 - 2014-08-12 20:24 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-08-12 13:10 - 2014-02-01 15:49 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-12 13:09 - 2014-08-12 13:09 - 00000960 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim Launcher.lnk 2014-08-12 13:09 - 2014-08-12 13:09 - 00000908 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim.lnk 2014-08-12 13:09 - 2014-02-01 15:48 - 00000785 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim Creation Kit.lnk 2014-08-11 20:05 - 2014-02-23 16:40 - 00011781 _____ () C:\Users\Les Enfants terrible\Documents\TombRaider.log 2014-08-08 20:18 - 2014-08-08 20:02 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\DayZ 2014-08-08 20:18 - 2014-08-08 20:02 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\DayZ 2014-08-08 13:53 - 2014-08-08 13:53 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\DayZ.url 2014-08-08 11:21 - 2014-01-16 20:04 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\gtk-2.0 2014-08-07 15:08 - 2014-08-07 15:08 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Risen 2014-08-07 12:51 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-08-07 07:50 - 2014-07-27 08:41 - 00000000 ____D () C:\ProgramData\Skype 2014-08-06 10:50 - 2014-08-06 10:50 - 00123672 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys Some content of TEMP: ==================== C:\Users\Grandmaster\AppData\Local\Temp\AutoRun.exe C:\Users\Grandmaster\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Grandmaster\AppData\Local\Temp\AVGTBInstall.exe C:\Users\Grandmaster\AppData\Local\Temp\devcon64.exe C:\Users\Grandmaster\AppData\Local\Temp\EBU3EF3.EXE C:\Users\Grandmaster\AppData\Local\Temp\EBU3FDD.DLL C:\Users\Grandmaster\AppData\Local\Temp\EBU685.exe C:\Users\Grandmaster\AppData\Local\Temp\EBUC5F.DLL C:\Users\Les Enfants terrible\AppData\Local\Temp\CmdLineExt.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\drm_dialogs.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\drm_dyndata_7300014.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\drm_dyndata_7370014.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\jansi-64-git-Bukkit-1.7.2-R0.2-b2974jnks.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\restarter1694885236210521250.exe C:\Users\Les Enfants terrible\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-29 22:02 ==================== End Of Log ============================ --- --- --- Addition.txt Zitat:
Geändert von G230 (03.09.2014 um 17:26 Uhr) |
03.09.2014, 17:30 | #2 |
/// TB-Ausbilder | AVG - Programm wurde durch eine Gruppenrichtlinie blockiert Hallo G230
__________________Mein Name ist Timo und ich werde Dir bei deinem Problem behilflich sein.
Hinweis: Ich kann Dir niemals eine Garantie geben, dass ich auch alles finde. Eine Formatierung ist immer der sicherste Weg. Wir "arbeiten" hier alle freiwillig und in unserer Freizeit *hust*. Daher kann es bei Antworten zu Verzögerungen kommen. Solltest du innerhalb 48 Std keine Antwort von mir erhalten, dann schreib mit eine PM Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis ich oder jemand vom Team sagt, dass Du clean bist.
__________________ |
03.09.2014, 17:34 | #3 |
/// TB-Ausbilder | AVG - Programm wurde durch eine Gruppenrichtlinie blockiert Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.
__________________Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM Group Policy restriction on software: C:\Program Files (x86)\AVG <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\AVG <====== ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Downloade Dir bitte Malwarebytes Anti-Malware
Starte noch einmal FRST.
__________________ |
03.09.2014, 17:39 | #4 | ||
| AVG - Programm wurde durch eine Gruppenrichtlinie blockiert Fixlog.txt Zitat:
AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v3.309 - Bericht erstellt am 03/09/2014 um 19:10:03 # Aktualisiert 02/09/2014 von Xplode # Betriebssystem : Windows 7 Ultimate Service Pack 1 (64 bits) # Benutzername : Les Enfants terrible - GRANDMASTER-PC # Gestartet von : C:\Progr\Downloads\adwcleaner_3.309.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** [/!\] Nicht Gelöscht ( Junction ) : C:\Program Files\Gemeinsame Dateien ***** [ Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKCU\Software\AVG Secure Search Schlüssel Gelöscht : HKCU\Software\Myfree Codec Schlüssel Gelöscht : HKLM\SOFTWARE\Myfree Codec ***** [ Browser ] ***** -\\ Internet Explorer v8.0.7601.17514 -\\ Mozilla Firefox v [ Datei : C:\Users\Grandmaster\AppData\Roaming\Mozilla\Firefox\Profiles\dntmqmw3.default\prefs.js ] [ Datei : C:\Users\Les Enfants terrible\AppData\Roaming\Mozilla\Firefox\Profiles\u9fibwzu.default\prefs.js ] ************************* AdwCleaner[R0].txt - [2236 octets] - [03/09/2014 19:09:26] AdwCleaner[S0].txt - [2052 octets] - [03/09/2014 19:10:03] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2112 octets] ########## JRT.txt Zitat:
MBAM hat nichts gefunden! FRST.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2014 02 Ran by Les Enfants terrible (administrator) on GRANDMASTER-PC on 03-09-2014 19:29:58 Running from C:\Progr\Downloads Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SbieSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\xampp\mysql\bin\mysqld.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe (TeamViewer GmbH) C:\Progr()\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SbieCtrl.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Samsung) F:\Programme\Kies\Kies\Kies.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (Samsung Electronics Co., Ltd.) F:\Programme\Kies\Kies\KiesTrayAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SbieSvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SandboxieRpcSs.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SandboxieDcomLaunch.exe (Mozilla Corporation) C:\Sandbox\Les_Enfants_terrible\DefaultBox\drive\C\Progr\Nightly\firefox.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\32\SbieSvc.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SandboxieCrypto.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbam.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7188552 2013-05-27] (Realtek Semiconductor) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5188112 2014-08-25] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [KiesTrayAgent] => F:\Programme\Kies\Kies\KiesTrayAgent.exe [311616 2014-02-07] (Samsung Electronics Co., Ltd.) HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [SandboxieControl] => C:\Progr\Sandboxie\SbieCtrl.exe [759496 2013-10-16] (Sandboxie Holdings, LLC) HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\Les Enfants terrible\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=aa0b8eefa6ee47d2a909057438040658-2ee9e78203d112addbcd299bd4ed93e05fb659f6 /CMPID=1213b HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21650016 2014-07-24] (Skype Technologies S.A.) HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [KiesPreload] => F:\Programme\Kies\Kies\Kies.exe [1564992 2014-02-07] (Samsung) HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [KiesAirMessage] => F:\Programme\Kies\Kies\KiesAirMessage.exe -startup HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\MountPoints2: {32dafb45-70cf-11e3-b0ab-806e6f6e6963} - D:\autorun.exe HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\MountPoints2: {8c87f698-85a7-11e3-8dfc-d43d7ee0efab} - G:\autorun.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Les Enfants terrible\AppData\Roaming\Mozilla\Firefox\Profiles\u9fibwzu.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF StartMenuInternet: FIREFOX.EXE - C:\Progr\Nightly\firefox.exe Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Apache2.4; c:\xampp\apache\bin\httpd.exe [22016 2012-06-06] (Apache Software Foundation) [File not signed] R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3242000 2014-08-25] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-08-25] (AVG Technologies CZ, s.r.o.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-08-08] () [File not signed] S3 FileZillaServer; c:\xampp\FileZillaFTP\FileZillaServer.exe [632320 2012-05-11] (FileZilla Project) [File not signed] R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-17] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) R2 mysql; c:\xampp\mysql\bin\mysqld.exe [8180224 2012-06-29] () [File not signed] R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-14] () R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2009-07-10] (Realtek) [File not signed] R2 SbieSvc; C:\Progr\Sandboxie\SbieSvc.exe [186056 2013-10-16] (Sandboxie Holdings, LLC) R2 TeamViewer9; C:\Progr()\TeamViewer\Version9\TeamViewer_Service.exe [5037888 2014-07-02] (TeamViewer GmbH) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [244504 2014-07-21] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-08-06] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2014-01-25] (DT Soft Ltd) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25816 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [122584 2014-09-03] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [63704 2014-05-12] (Malwarebytes Corporation) R3 SbieDrv; C:\Progr\Sandboxie\SbieDrv.sys [200552 2013-10-16] (Sandboxie Holdings, LLC) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 MSICDSetup; \??\D:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-03 19:21 - 2014-09-03 19:23 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-03 19:21 - 2014-09-03 19:21 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-09-03 19:21 - 2014-09-03 19:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-03 19:21 - 2014-09-03 19:21 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-09-03 19:21 - 2014-09-03 19:21 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-03 19:21 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-09-03 19:21 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-09-03 19:21 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-09-03 19:20 - 2014-09-03 19:20 - 00003667 _____ () C:\Users\Les Enfants terrible\Desktop\Neues Textdokument (6).txt 2014-09-03 19:17 - 2014-09-03 19:17 - 00000636 _____ () C:\Users\Les Enfants terrible\Desktop\JRT.txt 2014-09-03 19:14 - 2014-09-03 19:14 - 00000000 ____D () C:\Windows\ERUNT 2014-09-03 19:09 - 2014-09-03 19:10 - 00000000 ____D () C:\AdwCleaner 2014-09-03 17:57 - 2014-09-03 19:29 - 00000000 ____D () C:\FRST 2014-08-31 07:07 - 2014-08-31 07:07 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\Dishonored.url 2014-08-30 08:06 - 2014-08-30 08:30 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (6) 2014-08-29 22:13 - 2014-08-29 22:13 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\KnightShift.url 2014-08-27 18:16 - 2014-08-27 18:16 - 00003312 _____ () C:\Users\Les Enfants terrible\AppData\Local\recently-used.xbel 2014-08-26 17:49 - 2014-08-26 17:49 - 00002468 _____ () C:\Windows\System32\Tasks\0814avUpdateInfo 2014-08-26 17:49 - 2014-08-26 17:49 - 00000320 _____ () C:\Windows\Tasks\0814avUpdateInfo.job 2014-08-26 17:49 - 2014-08-26 17:49 - 00000000 ____D () C:\ProgramData\Avg_Update_0814av 2014-08-25 21:41 - 2014-08-25 22:35 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Darksiders 2014-08-25 21:38 - 2014-08-25 21:40 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-08-25 21:38 - 2014-08-25 21:38 - 00002105 _____ () C:\Users\Public\Desktop\Darksiders Comic.lnk 2014-08-25 21:38 - 2014-08-25 21:38 - 00001957 _____ () C:\Users\Public\Desktop\Darksiders SoundTrack.lnk 2014-08-25 21:38 - 2014-08-25 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ 2014-08-25 21:38 - 2014-08-25 21:38 - 00000000 ____D () C:\Program Files (x86)\THQ 2014-08-24 22:58 - 2014-08-24 22:58 - 00000201 _____ () C:\Users\Les Enfants terrible\Desktop\Darksiders II.url 2014-08-24 15:56 - 2014-08-24 15:56 - 00000000 ____D () C:\Windows\46ED2B6485C74E1F920CA555B21F2E4C.TMP 2014-08-18 22:16 - 2014-08-18 22:16 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\The Witcher 2014-08-18 22:09 - 2014-08-18 22:09 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (5) 2014-08-17 23:06 - 2014-08-17 23:07 - 00000000 ____D () C:\ProgramData\IhupgApeve 2014-08-15 14:44 - 2014-08-15 14:44 - 00108144 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll 2014-08-13 15:56 - 2014-08-13 15:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf 2014-08-13 12:08 - 2014-08-13 12:08 - 00000674 _____ () C:\Users\Public\Desktop\Cube World.lnk 2014-08-13 12:08 - 2014-08-13 12:08 - 00000000 ____D () C:\ProgramData\Picroma 2014-08-12 20:37 - 2014-08-12 20:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec 2014-08-12 20:35 - 2014-08-12 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2014-08-12 20:35 - 2014-02-07 16:33 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll 2014-08-12 20:35 - 2014-01-23 18:31 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll 2014-08-12 20:34 - 2014-08-12 20:34 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Downloaded Installations 2014-08-12 20:24 - 2014-08-12 20:35 - 00000000 ____D () C:\ProgramData\Samsung 2014-08-12 20:24 - 2014-08-12 20:24 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-08-12 20:24 - 2013-12-26 07:41 - 01919168 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01005.dll 2014-08-12 20:24 - 2013-12-26 07:41 - 01919168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01005.dll 2014-08-12 20:24 - 2013-12-26 07:41 - 00188232 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdmdm.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00188232 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadmdm.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00169288 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdbus.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00169288 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadbus.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00158024 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadserd.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00038080 _____ (Google Inc) C:\Windows\system32\Drivers\ssadadb.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00021320 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdmdfl.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00021320 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadmdfl.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017736 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdwhnt.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017736 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdwh.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017736 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadwhnt.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017736 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadwh.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017224 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdcmnt.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017224 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdcm.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017224 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadcmnt.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017224 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadcm.sys 2014-08-12 20:03 - 2014-08-12 20:34 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\odin 2014-08-12 13:09 - 2014-08-12 13:09 - 00000960 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim Launcher.lnk 2014-08-12 13:09 - 2014-08-12 13:09 - 00000908 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim.lnk 2014-08-11 14:29 - 2014-08-13 19:13 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\ZSNES 2014-08-08 20:02 - 2014-08-08 20:18 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\DayZ 2014-08-08 20:02 - 2014-08-08 20:18 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\DayZ 2014-08-08 13:53 - 2014-08-08 13:53 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\DayZ.url 2014-08-07 15:08 - 2014-08-07 15:08 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Risen 2014-08-06 10:50 - 2014-08-06 10:50 - 00123672 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-03 19:29 - 2014-09-03 17:57 - 00000000 ____D () C:\FRST 2014-09-03 19:23 - 2014-09-03 19:21 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-09-03 19:21 - 2014-09-03 19:21 - 00001106 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-09-03 19:21 - 2014-09-03 19:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-09-03 19:21 - 2014-09-03 19:21 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-09-03 19:21 - 2014-09-03 19:21 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2014-09-03 19:20 - 2014-09-03 19:20 - 00003667 _____ () C:\Users\Les Enfants terrible\Desktop\Neues Textdokument (6).txt 2014-09-03 19:18 - 2009-07-14 06:45 - 00028976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-03 19:18 - 2009-07-14 06:45 - 00028976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-03 19:17 - 2014-09-03 19:17 - 00000636 _____ () C:\Users\Les Enfants terrible\Desktop\JRT.txt 2014-09-03 19:17 - 2013-12-30 08:15 - 00709292 _____ () C:\Windows\system32\perfh007.dat 2014-09-03 19:17 - 2013-12-30 08:15 - 00153728 _____ () C:\Windows\system32\perfc007.dat 2014-09-03 19:17 - 2009-07-14 07:13 - 01647128 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-03 19:14 - 2014-09-03 19:14 - 00000000 ____D () C:\Windows\ERUNT 2014-09-03 19:14 - 2013-12-29 23:26 - 01088948 _____ () C:\Windows\WindowsUpdate.log 2014-09-03 19:11 - 2013-12-30 00:11 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Roaming\Skype 2014-09-03 19:11 - 2013-12-29 23:36 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-09-03 19:11 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-03 19:11 - 2009-07-14 06:51 - 00066857 _____ () C:\Windows\setupact.log 2014-09-03 19:10 - 2014-09-03 19:09 - 00000000 ____D () C:\AdwCleaner 2014-09-03 19:10 - 2013-12-29 23:52 - 00000000 ____D () C:\ProgramData\MFAData 2014-09-03 19:10 - 2010-11-21 05:47 - 00104220 _____ () C:\Windows\PFRO.log 2014-09-03 17:50 - 2014-04-02 17:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2014-09-03 17:50 - 2013-12-29 23:53 - 00000981 _____ () C:\Users\Public\Desktop\AVG 2014.lnk 2014-09-01 18:43 - 2013-12-29 22:44 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Roaming\.minecraft 2014-08-31 07:07 - 2014-08-31 07:07 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\Dishonored.url 2014-08-30 08:30 - 2014-08-30 08:06 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (6) 2014-08-29 22:13 - 2014-08-29 22:13 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\KnightShift.url 2014-08-29 19:56 - 2014-08-03 12:15 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (4) 2014-08-29 18:27 - 2014-01-01 03:35 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Skyrim 2014-08-27 18:16 - 2014-08-27 18:16 - 00003312 _____ () C:\Users\Les Enfants terrible\AppData\Local\recently-used.xbel 2014-08-27 18:16 - 2014-01-16 20:01 - 00000000 ____D () C:\Users\Les Enfants terrible\.gimp-2.8 2014-08-26 17:49 - 2014-08-26 17:49 - 00002468 _____ () C:\Windows\System32\Tasks\0814avUpdateInfo 2014-08-26 17:49 - 2014-08-26 17:49 - 00000320 _____ () C:\Windows\Tasks\0814avUpdateInfo.job 2014-08-26 17:49 - 2014-08-26 17:49 - 00000000 ____D () C:\ProgramData\Avg_Update_0814av 2014-08-25 22:35 - 2014-08-25 21:41 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Darksiders 2014-08-25 21:41 - 2013-12-30 00:23 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\My Games 2014-08-25 21:40 - 2014-08-25 21:38 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-08-25 21:40 - 2013-12-29 23:32 - 00184632 _____ () C:\Windows\DirectX.log 2014-08-25 21:38 - 2014-08-25 21:38 - 00002105 _____ () C:\Users\Public\Desktop\Darksiders Comic.lnk 2014-08-25 21:38 - 2014-08-25 21:38 - 00001957 _____ () C:\Users\Public\Desktop\Darksiders SoundTrack.lnk 2014-08-25 21:38 - 2014-08-25 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ 2014-08-25 21:38 - 2014-08-25 21:38 - 00000000 ____D () C:\Program Files (x86)\THQ 2014-08-25 07:51 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-08-24 22:58 - 2014-08-24 22:58 - 00000201 _____ () C:\Users\Les Enfants terrible\Desktop\Darksiders II.url 2014-08-24 15:56 - 2014-08-24 15:56 - 00000000 ____D () C:\Windows\46ED2B6485C74E1F920CA555B21F2E4C.TMP 2014-08-18 22:16 - 2014-08-18 22:16 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\The Witcher 2014-08-18 22:09 - 2014-08-18 22:09 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (5) 2014-08-17 23:07 - 2014-08-17 23:06 - 00000000 ____D () C:\ProgramData\IhupgApeve 2014-08-17 23:07 - 2013-12-29 23:52 - 00000000 ____D () C:\ProgramData\AVG2014 2014-08-15 14:44 - 2014-08-15 14:44 - 00108144 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll 2014-08-13 19:13 - 2014-08-11 14:29 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\ZSNES 2014-08-13 15:56 - 2014-08-13 15:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf 2014-08-13 12:08 - 2014-08-13 12:08 - 00000674 _____ () C:\Users\Public\Desktop\Cube World.lnk 2014-08-13 12:08 - 2014-08-13 12:08 - 00000000 ____D () C:\ProgramData\Picroma 2014-08-12 20:37 - 2014-08-12 20:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec 2014-08-12 20:35 - 2014-08-12 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2014-08-12 20:35 - 2014-08-12 20:24 - 00000000 ____D () C:\ProgramData\Samsung 2014-08-12 20:35 - 2013-12-29 23:26 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-08-12 20:34 - 2014-08-12 20:34 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Downloaded Installations 2014-08-12 20:34 - 2014-08-12 20:03 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\odin 2014-08-12 20:24 - 2014-08-12 20:24 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-08-12 13:10 - 2014-02-01 15:49 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-12 13:09 - 2014-08-12 13:09 - 00000960 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim Launcher.lnk 2014-08-12 13:09 - 2014-08-12 13:09 - 00000908 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim.lnk 2014-08-12 13:09 - 2014-02-01 15:48 - 00000785 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim Creation Kit.lnk 2014-08-11 20:05 - 2014-02-23 16:40 - 00011781 _____ () C:\Users\Les Enfants terrible\Documents\TombRaider.log 2014-08-08 20:18 - 2014-08-08 20:02 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\DayZ 2014-08-08 20:18 - 2014-08-08 20:02 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\DayZ 2014-08-08 13:53 - 2014-08-08 13:53 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\DayZ.url 2014-08-08 11:21 - 2014-01-16 20:04 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\gtk-2.0 2014-08-07 15:08 - 2014-08-07 15:08 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Risen 2014-08-07 12:51 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-08-07 07:50 - 2014-07-27 08:41 - 00000000 ____D () C:\ProgramData\Skype 2014-08-06 10:50 - 2014-08-06 10:50 - 00123672 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys Some content of TEMP: ==================== C:\Users\Grandmaster\AppData\Local\Temp\AutoRun.exe C:\Users\Grandmaster\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Grandmaster\AppData\Local\Temp\AVGTBInstall.exe C:\Users\Grandmaster\AppData\Local\Temp\devcon64.exe C:\Users\Grandmaster\AppData\Local\Temp\EBU3EF3.EXE C:\Users\Grandmaster\AppData\Local\Temp\EBU3FDD.DLL C:\Users\Grandmaster\AppData\Local\Temp\EBU685.exe C:\Users\Grandmaster\AppData\Local\Temp\EBUC5F.DLL C:\Users\Les Enfants terrible\AppData\Local\Temp\CmdLineExt.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\drm_dialogs.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\drm_dyndata_7300014.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\drm_dyndata_7370014.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\jansi-64-git-Bukkit-1.7.2-R0.2-b2974jnks.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\Quarantine.exe C:\Users\Les Enfants terrible\AppData\Local\Temp\restarter1694885236210521250.exe C:\Users\Les Enfants terrible\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-29 22:02 ==================== End Of Log ============================ Geändert von G230 (03.09.2014 um 18:30 Uhr) |
04.09.2014, 09:32 | #5 |
/// TB-Ausbilder | AVG - Programm wurde durch eine Gruppenrichtlinie blockiert Hast du auch noch das Malwarebytes Log ? AVG sollte wieder funktionieren, richtig ? Downloade Dir bitte SecurityCheck und:
ESET Online Scanner
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
04.09.2014, 19:53 | #6 | ||
| AVG - Programm wurde durch eine Gruppenrichtlinie blockiert Nein, MBAM gab mir keine Möglichkeit, ein Logfile zu erstellen, oder zumindest hab ich sie dann übersehen. :s AVG funktioniert wieder, ja. Hat jetzt etwas gedauert, der ESET Scan hat über 2 Stunden gedauert. checkup.txt Zitat:
Zitat:
|
04.09.2014, 22:28 | #7 |
/// TB-Ausbilder | AVG - Programm wurde durch eine Gruppenrichtlinie blockiert Ja, das heisst auch nur, das der Installer mit ner Toolbar im "Bundle" kommt. Am besten von Hand löschen. Flash Player veraltet ! Deinstalliere bitte deine aktuelle Version von Adobe Player Start--> Systemsteuerung--> Software--> Adobe Player und lade dir die neue Version von Hier herunter- Entferne den Haken für den McAfee SecurityScan bzw. Google Chrome. Ansonsten sind die Logs sauber Die Reihenfolge ist hier entscheidend.
Abschließend habe ich noch ein paar Tipps zur Absicherung deines Systems. Ändere regelmäßig alle deine Passwörter, jetzt, nach der Bereinigung ist ein idealer Zeitpunkt dafür
Ich kann gar nicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti-Viren-Programm und zusätzlicher Schutz
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden. Mozilla Firefox
Performance
Was du vermeiden solltest:
Nun bleibt mir nur noch dir viel Spaß beim sicheren Surfen zu wünschen... ... und vielleicht möchtest du ja das Trojaner-Board unterstützen? Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so dass ich dieses Thema aus meinen Abos löschen kann.
__________________ Lerne, zurück zu schlagen und unterstütze uns! TB Akademie | Spende | Lob & Kritik |
05.09.2014, 14:50 | #8 |
| AVG - Programm wurde durch eine Gruppenrichtlinie blockiert Alles klar, vielen Dank! Ich persönlich nutze den Flash Player überhaupt nicht bzw. hab das Addon dazu im Firefox ohnehin deaktiviert, im Zeitalter von HTML5 ist Flash doch irgendwo outdated. Die Programme aus der Bereinigung sind auch ohne Probleme abgezogen, hat ohne Probleme geklappt. Vielen Dank auch nochmal für die Tipps! Das meiste davon hab ich zwar befolgt, allerdings muss ich mir einfach angewöhnen, für fremde PCs einen USB Stick zu nutzen und nicht meine externe Festplatte. Hab auch soweit keine Fragen mehr. Vielen dank nochmal für die schnelle und kompetente Hilfe! |
Themen zu AVG - Programm wurde durch eine Gruppenrichtlinie blockiert |
adware, antivirus, avira, blockiert, cpu, desktop, festplatte, flash player, gruppenrichtlinie blockiert, helper, iexplore.exe, league of legends, lightning, mozilla, popup, programm, realtek, registry, scan, security, software, starten, svchost.exe, system, usb, virus, warnung, windows |