![]() |
|
Plagegeister aller Art und deren Bekämpfung: AVG - Programm wurde durch eine Gruppenrichtlinie blockiertWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 | ||
| ![]() AVG - Programm wurde durch eine Gruppenrichtlinie blockiert Hallo Leute, Ich war gestern mal wieder die Familie besuchen. Es gibt da nur eine sehr schlechte Leitung und mein Bruder hat sich 2 Spiele per Steam gekauft, die aber ewig zum Runterladen brauchen. Nett wie ich bin, hab ich meine Festplatte mitgenommen, angesteckt und ihm die beiden Spiele in den Steamordner kopiert. Mir ist allerdings bei ihm schon aufgefallen, dass Avira ständig inaktiv war und sich auch nicht hat aktivieren lassen. War mir schon klar, dass da was drauf ist, hab meine Festplatte also schnellstmöglich abgestöpselt und gehofft, dass nix passiert ist. Aufgrund der Tatsache, dass ich hier bin, kann man ja entnehmen, dass doch etwas passiert ist. Es gab ein kurzes Popup von Windows, dass AVG nicht aktiv ist, und es war auch nicht im System Tray zu finden. Beim Starten hat er dann eben die Fehlermeldung ausgespuckt: Zitat:
Die Logs häng ich unten an. Ich selber fummel da jetzt nicht rum, weil ich mich mit so nem Virus echt nicht auskenne. Gruß G230 FRST.txt FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 03-09-2014 02 Ran by Les Enfants terrible (administrator) on GRANDMASTER-PC on 03-09-2014 17:57:50 Running from C:\Progr\Downloads Platform: Windows 7 Ultimate Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SbieSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\xampp\mysql\bin\mysqld.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Realtek) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe (Realtek Semiconductor Corp.) C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtWLan.exe (TeamViewer GmbH) C:\Progr()\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Apache Software Foundation) C:\xampp\apache\bin\httpd.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SbieCtrl.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Samsung) F:\Programme\Kies\Kies\Kies.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Samsung Electronics Co., Ltd.) F:\Programme\Kies\Kies\KiesTrayAgent.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe () F:\Games\RiotGames\League of Legends\RADS\system\rads_user_kernel.exe () F:\Games\RiotGames\League of Legends\RADS\projects\lol_launcher\releases\0.0.0.218\deploy\LoLLauncher.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SbieSvc.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SandboxieRpcSs.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\SandboxieDcomLaunch.exe (Mozilla Corporation) C:\Sandbox\Les_Enfants_terrible\DefaultBox\drive\C\Progr\Nightly\firefox.exe (Sandboxie Holdings, LLC) C:\Progr\Sandboxie\32\SbieSvc.exe () F:\Games\RiotGames\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.2\deploy\LoLPatcher.exe () F:\Games\RiotGames\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.2\deploy\LoLPatcher.exe () F:\Games\RiotGames\League of Legends\RADS\projects\lol_patcher\releases\0.0.0.2\deploy\LoLPatcher.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Windows\System32\msiexec.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (Mozilla Corporation) C:\Sandbox\Les_Enfants_terrible\DefaultBox\drive\C\Progr\Nightly\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7188552 2013-05-27] (Realtek Semiconductor) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5188112 2014-08-25] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [KiesTrayAgent] => F:\Programme\Kies\Kies\KiesTrayAgent.exe [311616 2014-02-07] (Samsung Electronics Co., Ltd.) HKLM Group Policy restriction on software: C:\Program Files (x86)\AVG <====== ATTENTION HKLM Group Policy restriction on software: C:\Program Files (x86)\AVG <====== ATTENTION HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [SandboxieControl] => C:\Progr\Sandboxie\SbieCtrl.exe [759496 2013-10-16] (Sandboxie Holdings, LLC) HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\Les Enfants terrible\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=aa0b8eefa6ee47d2a909057438040658-2ee9e78203d112addbcd299bd4ed93e05fb659f6 /CMPID=1213b HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [Skype] => C:\Program Files (x86)\Skype\Phone\Skype.exe [21650016 2014-07-24] (Skype Technologies S.A.) HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [KiesPreload] => F:\Programme\Kies\Kies\Kies.exe [1564992 2014-02-07] (Samsung) HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\Run: [KiesAirMessage] => F:\Programme\Kies\Kies\KiesAirMessage.exe -startup HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\MountPoints2: {32dafb45-70cf-11e3-b0ab-806e6f6e6963} - D:\autorun.exe HKU\S-1-5-21-2168255348-3041620924-3134857489-1002\...\MountPoints2: {8c87f698-85a7-11e3-8dfc-d43d7ee0efab} - G:\autorun.exe ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.dell.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.dell.com StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Les Enfants terrible\AppData\Roaming\Mozilla\Firefox\Profiles\u9fibwzu.default FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 -> C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=3.5.29 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF StartMenuInternet: FIREFOX.EXE - C:\Progr\Nightly\firefox.exe Chrome: ======= ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 Apache2.4; c:\xampp\apache\bin\httpd.exe [22016 2012-06-06] (Apache Software Foundation) [File not signed] R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3242000 2014-08-25] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-08-25] (AVG Technologies CZ, s.r.o.) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2014-08-08] () [File not signed] S3 FileZillaServer; c:\xampp\FileZillaFTP\FileZillaServer.exe [632320 2012-05-11] (FileZilla Project) [File not signed] R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [731648 2013-02-13] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [820184 2013-02-13] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-05-17] (Intel Corporation) R2 mysql; c:\xampp\mysql\bin\mysqld.exe [8180224 2012-06-29] () [File not signed] R2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-04-14] () R2 Realtek11nSU; C:\Program Files (x86)\Realtek\11n USB Wireless LAN Utility\RtlService.exe [36864 2009-07-10] (Realtek) [File not signed] R2 SbieSvc; C:\Progr\Sandboxie\SbieSvc.exe [186056 2013-10-16] (Sandboxie Holdings, LLC) R2 TeamViewer9; C:\Progr()\TeamViewer\Version9\TeamViewer_Service.exe [5037888 2014-07-02] (TeamViewer GmbH) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [244504 2014-07-21] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [235800 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-08-06] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [269080 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2014-01-25] (DT Soft Ltd) R3 SbieDrv; C:\Progr\Sandboxie\SbieDrv.sys [200552 2013-10-16] (Sandboxie Holdings, LLC) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) S3 MSICDSetup; \??\D:\CDriver64.sys [X] S3 NTIOLib_1_0_C; \??\D:\NTIOLib_X64.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-03 17:57 - 2014-09-03 17:57 - 00000000 ____D () C:\FRST 2014-08-31 07:07 - 2014-08-31 07:07 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\Dishonored.url 2014-08-30 08:06 - 2014-08-30 08:30 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (6) 2014-08-29 22:13 - 2014-08-29 22:13 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\KnightShift.url 2014-08-27 18:16 - 2014-08-27 18:16 - 00003312 _____ () C:\Users\Les Enfants terrible\AppData\Local\recently-used.xbel 2014-08-26 17:49 - 2014-08-26 17:49 - 00002468 _____ () C:\Windows\System32\Tasks\0814avUpdateInfo 2014-08-26 17:49 - 2014-08-26 17:49 - 00000320 _____ () C:\Windows\Tasks\0814avUpdateInfo.job 2014-08-26 17:49 - 2014-08-26 17:49 - 00000000 ____D () C:\ProgramData\Avg_Update_0814av 2014-08-25 21:41 - 2014-08-25 22:35 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Darksiders 2014-08-25 21:38 - 2014-08-25 21:40 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-08-25 21:38 - 2014-08-25 21:38 - 00002105 _____ () C:\Users\Public\Desktop\Darksiders Comic.lnk 2014-08-25 21:38 - 2014-08-25 21:38 - 00001957 _____ () C:\Users\Public\Desktop\Darksiders SoundTrack.lnk 2014-08-25 21:38 - 2014-08-25 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ 2014-08-25 21:38 - 2014-08-25 21:38 - 00000000 ____D () C:\Program Files (x86)\THQ 2014-08-24 22:58 - 2014-08-24 22:58 - 00000201 _____ () C:\Users\Les Enfants terrible\Desktop\Darksiders II.url 2014-08-24 15:56 - 2014-08-24 15:56 - 00000000 ____D () C:\Windows\46ED2B6485C74E1F920CA555B21F2E4C.TMP 2014-08-18 22:16 - 2014-08-18 22:16 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\The Witcher 2014-08-18 22:09 - 2014-08-18 22:09 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (5) 2014-08-17 23:06 - 2014-08-17 23:07 - 00000000 ____D () C:\ProgramData\IhupgApeve 2014-08-15 14:44 - 2014-08-15 14:44 - 00108144 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll 2014-08-13 15:56 - 2014-08-13 15:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf 2014-08-13 12:08 - 2014-08-13 12:08 - 00000674 _____ () C:\Users\Public\Desktop\Cube World.lnk 2014-08-13 12:08 - 2014-08-13 12:08 - 00000000 ____D () C:\ProgramData\Picroma 2014-08-12 20:37 - 2014-08-12 20:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec 2014-08-12 20:35 - 2014-08-12 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2014-08-12 20:35 - 2014-02-07 16:33 - 04659712 _____ (Dmitry Streblechenko) C:\Windows\SysWOW64\Redemption.dll 2014-08-12 20:35 - 2014-01-23 18:31 - 00821824 _____ (Devguru Co., Ltd.) C:\Windows\SysWOW64\dgderapi.dll 2014-08-12 20:34 - 2014-08-12 20:34 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Downloaded Installations 2014-08-12 20:24 - 2014-08-12 20:35 - 00000000 ____D () C:\ProgramData\Samsung 2014-08-12 20:24 - 2014-08-12 20:24 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-08-12 20:24 - 2013-12-26 07:41 - 01919168 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01005.dll 2014-08-12 20:24 - 2013-12-26 07:41 - 01919168 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\WdfCoInstaller01005.dll 2014-08-12 20:24 - 2013-12-26 07:41 - 00188232 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdmdm.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00188232 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadmdm.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00169288 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdbus.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00169288 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadbus.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00158024 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadserd.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00038080 _____ (Google Inc) C:\Windows\system32\Drivers\ssadadb.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00021320 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdmdfl.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00021320 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadmdfl.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017736 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdwhnt.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017736 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdwh.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017736 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadwhnt.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017736 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadwh.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017224 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdcmnt.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017224 _____ (MCCI Corporation) C:\Windows\system32\Drivers\sscdcm.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017224 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadcmnt.sys 2014-08-12 20:24 - 2013-12-26 07:41 - 00017224 _____ (MCCI Corporation) C:\Windows\system32\Drivers\ssadcm.sys 2014-08-12 20:03 - 2014-08-12 20:34 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\odin 2014-08-12 13:09 - 2014-08-12 13:09 - 00000960 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim Launcher.lnk 2014-08-12 13:09 - 2014-08-12 13:09 - 00000908 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim.lnk 2014-08-11 14:29 - 2014-08-13 19:13 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\ZSNES 2014-08-08 20:02 - 2014-08-08 20:18 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\DayZ 2014-08-08 20:02 - 2014-08-08 20:18 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\DayZ 2014-08-08 13:53 - 2014-08-08 13:53 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\DayZ.url 2014-08-07 15:08 - 2014-08-07 15:08 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Risen 2014-08-06 10:50 - 2014-08-06 10:50 - 00123672 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-09-03 17:57 - 2014-09-03 17:57 - 00000000 ____D () C:\FRST 2014-09-03 17:51 - 2009-07-14 06:45 - 00028976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-03 17:51 - 2009-07-14 06:45 - 00028976 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-03 17:50 - 2014-04-02 17:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2014-09-03 17:50 - 2013-12-30 08:15 - 00709292 _____ () C:\Windows\system32\perfh007.dat 2014-09-03 17:50 - 2013-12-30 08:15 - 00153728 _____ () C:\Windows\system32\perfc007.dat 2014-09-03 17:50 - 2013-12-29 23:53 - 00000981 _____ () C:\Users\Public\Desktop\AVG 2014.lnk 2014-09-03 17:50 - 2013-12-29 23:52 - 00000000 ____D () C:\ProgramData\MFAData 2014-09-03 17:50 - 2009-07-14 07:13 - 01647128 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-09-03 17:47 - 2013-12-29 23:26 - 01085441 _____ () C:\Windows\WindowsUpdate.log 2014-09-03 17:46 - 2013-12-30 00:11 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Roaming\Skype 2014-09-03 17:44 - 2013-12-29 23:36 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-09-03 17:44 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-09-03 17:44 - 2009-07-14 06:51 - 00066801 _____ () C:\Windows\setupact.log 2014-09-01 18:43 - 2013-12-29 22:44 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Roaming\.minecraft 2014-08-31 07:07 - 2014-08-31 07:07 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\Dishonored.url 2014-08-30 08:30 - 2014-08-30 08:06 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (6) 2014-08-29 22:13 - 2014-08-29 22:13 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\KnightShift.url 2014-08-29 19:56 - 2014-08-03 12:15 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (4) 2014-08-29 18:27 - 2014-01-01 03:35 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Skyrim 2014-08-27 18:16 - 2014-08-27 18:16 - 00003312 _____ () C:\Users\Les Enfants terrible\AppData\Local\recently-used.xbel 2014-08-27 18:16 - 2014-01-16 20:01 - 00000000 ____D () C:\Users\Les Enfants terrible\.gimp-2.8 2014-08-26 17:49 - 2014-08-26 17:49 - 00002468 _____ () C:\Windows\System32\Tasks\0814avUpdateInfo 2014-08-26 17:49 - 2014-08-26 17:49 - 00000320 _____ () C:\Windows\Tasks\0814avUpdateInfo.job 2014-08-26 17:49 - 2014-08-26 17:49 - 00000000 ____D () C:\ProgramData\Avg_Update_0814av 2014-08-25 22:35 - 2014-08-25 21:41 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Darksiders 2014-08-25 21:41 - 2013-12-30 00:23 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\My Games 2014-08-25 21:40 - 2014-08-25 21:38 - 00000000 ____D () C:\Windows\SysWOW64\directx 2014-08-25 21:40 - 2013-12-29 23:32 - 00184632 _____ () C:\Windows\DirectX.log 2014-08-25 21:38 - 2014-08-25 21:38 - 00002105 _____ () C:\Users\Public\Desktop\Darksiders Comic.lnk 2014-08-25 21:38 - 2014-08-25 21:38 - 00001957 _____ () C:\Users\Public\Desktop\Darksiders SoundTrack.lnk 2014-08-25 21:38 - 2014-08-25 21:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\THQ 2014-08-25 21:38 - 2014-08-25 21:38 - 00000000 ____D () C:\Program Files (x86)\THQ 2014-08-25 07:51 - 2009-07-14 07:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2014-08-24 22:58 - 2014-08-24 22:58 - 00000201 _____ () C:\Users\Les Enfants terrible\Desktop\Darksiders II.url 2014-08-24 15:56 - 2014-08-24 15:56 - 00000000 ____D () C:\Windows\46ED2B6485C74E1F920CA555B21F2E4C.TMP 2014-08-18 22:16 - 2014-08-18 22:16 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\The Witcher 2014-08-18 22:09 - 2014-08-18 22:09 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\Neuer Ordner (5) 2014-08-17 23:07 - 2014-08-17 23:06 - 00000000 ____D () C:\ProgramData\IhupgApeve 2014-08-17 23:07 - 2013-12-29 23:52 - 00000000 ____D () C:\ProgramData\AVG2014 2014-08-15 14:44 - 2014-08-15 14:44 - 00108144 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt.dll 2014-08-13 19:13 - 2014-08-11 14:29 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\ZSNES 2014-08-13 15:56 - 2014-08-13 15:56 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_ssadadb_01005.Wdf 2014-08-13 12:08 - 2014-08-13 12:08 - 00000674 _____ () C:\Users\Public\Desktop\Cube World.lnk 2014-08-13 12:08 - 2014-08-13 12:08 - 00000000 ____D () C:\ProgramData\Picroma 2014-08-12 20:37 - 2014-08-12 20:37 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MyFree Codec 2014-08-12 20:35 - 2014-08-12 20:35 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung 2014-08-12 20:35 - 2014-08-12 20:24 - 00000000 ____D () C:\ProgramData\Samsung 2014-08-12 20:35 - 2013-12-29 23:26 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-08-12 20:34 - 2014-08-12 20:34 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Downloaded Installations 2014-08-12 20:34 - 2014-08-12 20:03 - 00000000 ____D () C:\Users\Les Enfants terrible\Desktop\odin 2014-08-12 20:24 - 2014-08-12 20:24 - 00000000 ____D () C:\Program Files\SAMSUNG 2014-08-12 13:10 - 2014-02-01 15:49 - 00000000 ____D () C:\ProgramData\Package Cache 2014-08-12 13:09 - 2014-08-12 13:09 - 00000960 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim Launcher.lnk 2014-08-12 13:09 - 2014-08-12 13:09 - 00000908 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim.lnk 2014-08-12 13:09 - 2014-02-01 15:48 - 00000785 _____ () C:\Users\Public\Desktop\The Elder Scrolls V - Skyrim Creation Kit.lnk 2014-08-11 20:05 - 2014-02-23 16:40 - 00011781 _____ () C:\Users\Les Enfants terrible\Documents\TombRaider.log 2014-08-08 20:18 - 2014-08-08 20:02 - 00000000 ____D () C:\Users\Les Enfants terrible\Documents\DayZ 2014-08-08 20:18 - 2014-08-08 20:02 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\DayZ 2014-08-08 13:53 - 2014-08-08 13:53 - 00000202 _____ () C:\Users\Les Enfants terrible\Desktop\DayZ.url 2014-08-08 11:21 - 2014-01-16 20:04 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\gtk-2.0 2014-08-07 15:08 - 2014-08-07 15:08 - 00000000 ____D () C:\Users\Les Enfants terrible\AppData\Local\Risen 2014-08-07 12:51 - 2009-07-14 07:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-08-07 07:50 - 2014-07-27 08:41 - 00000000 ____D () C:\ProgramData\Skype 2014-08-06 10:50 - 2014-08-06 10:50 - 00123672 _____ (AVG Technologies CZ, s.r.o.) C:\Windows\system32\Drivers\avgmfx64.sys Some content of TEMP: ==================== C:\Users\Grandmaster\AppData\Local\Temp\AutoRun.exe C:\Users\Grandmaster\AppData\Local\Temp\AutoRunGUI.dll C:\Users\Grandmaster\AppData\Local\Temp\AVGTBInstall.exe C:\Users\Grandmaster\AppData\Local\Temp\devcon64.exe C:\Users\Grandmaster\AppData\Local\Temp\EBU3EF3.EXE C:\Users\Grandmaster\AppData\Local\Temp\EBU3FDD.DLL C:\Users\Grandmaster\AppData\Local\Temp\EBU685.exe C:\Users\Grandmaster\AppData\Local\Temp\EBUC5F.DLL C:\Users\Les Enfants terrible\AppData\Local\Temp\CmdLineExt.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\drm_dialogs.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\drm_dyndata_7300014.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\drm_dyndata_7370014.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\jansi-64-git-Bukkit-1.7.2-R0.2-b2974jnks.dll C:\Users\Les Enfants terrible\AppData\Local\Temp\restarter1694885236210521250.exe C:\Users\Les Enfants terrible\AppData\Local\Temp\SkypeSetup.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2014-08-29 22:02 ==================== End Of Log ============================ --- --- --- Addition.txt Zitat:
Geändert von G230 (03.09.2014 um 17:26 Uhr) |
Themen zu AVG - Programm wurde durch eine Gruppenrichtlinie blockiert |
adware, antivirus, avira, blockiert, cpu, desktop, festplatte, flash player, gruppenrichtlinie blockiert, helper, iexplore.exe, league of legends, lightning, mozilla, popup, programm, realtek, registry, scan, security, software, starten, svchost.exe, system, usb, virus, warnung, windows |