|
Plagegeister aller Art und deren Bekämpfung: Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik'Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
01.10.2014, 10:47 | #1 |
| Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' Guten Tag Ich habe die Statistiksoftware 'R Statistik' heruntergeladen, welches mir sehrwahrscheinlich einen Virus eingebrockt hat.. Wenn ich meinen Laptop starte, folgt ein schwarzer Bildschirm, keine Maus ist zu erkennen.. Leider habe ich im Bereich Informatik resp. Virusbekämpfung keine Ahnung und wäre um jede Hilfe wirklich sehr dankbar!! LG Woles |
01.10.2014, 11:24 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' Hi,
__________________Zitat:
Betriebssystem???
__________________ |
01.10.2014, 11:40 | #3 |
| Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' Es gibt mehrere Seiten, wo man diese Software herunterladen kann..Und ich bin mir nicht zu 100% sicher, aber ich glaube, ich habe es auf folgender Seite heruntergeladen:
__________________hxxp://www.soft-ware.net/r-for-windows Das Betriebssystem ist Windows 7 Vielen Dank schonmal!! |
01.10.2014, 14:27 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR oder 7Z-Archiv zu packen erschwert mir massiv die Arbeit. Auch wenn die Logs für einen Beitrag zu groß sein sollten, bitte ich dich die Logs direkt und notfalls über mehrere Beiträge verteilt zu posten. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ Logfiles bitte immer in CODE-Tags posten |
01.10.2014, 15:21 | #5 |
| Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' Ich weiss nicht, wie man weitere Logs findet.. Hier erst mal das FRST Logfile: (und danke für deine schnelle Antwort!!!) Noch eine dumme Frage: Wie findet man die Addition.txt? FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 30-09-2014 Ran by SYSTEM on MININT-96LMEA5 on 01-10-2014 16:11:59 Running from F:\ Platform: Windows 7 Home Premium (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log. Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7719456 2009-08-24] (Realtek Semiconductor) HKLM\...\Run: [Microsoft Default Manager] => C:\Program Files\Microsoft\Search Enhancement Pack\Default Manager\DefMgr.exe [288080 2009-07-17] (Microsoft Corporation) HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [703736 2014-10-01] (Avira Operations GmbH & Co. KG) HKU\Monika\...\Run: [Optimizer Pro] => C:\Program Files\Optimizer Pro\OptProLauncher.exe [146888 2014-08-21] (PC Utilities Software Limited) HKU\Monika\...\Run: [BRS] => C:\Program Files\WSE_Astromenda\BRS\brs.exe [1074688 2014-09-30] () HKU\Monika\...\RunOnce: [WSE_Astromenda] => wscript /E:vbscript /B "C:\Users\Monika\AppData\Roaming\WSE_Astromenda\UpdateProc\bkup.dat" AppInit_DLLs: C:\Users\Monika\AppData\Local\Linkey\IEEXTE~1\iedll.dll => C:\Users\Monika\AppData\Local\Linkey\IEEXTE~1\iedll.dll File Not Found IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe Lsa: [Authentication Packages] msv1_0 relog_ap Startup: C:\Users\Monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\MyPC Backup.lnk ShortcutTarget: MyPC Backup.lnk -> C:\Program Files\MyPC Backup\MyPC Backup.exe (MyPCBackup.com) Startup: C:\Users\Monika\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Tintenwarnungen überwachen - HP Deskjet 3520 series (Netzwerk).lnk HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Settings Manager\smdmf\sysapcrt.dll [488464 2014-07-22] () HKLM\...\AppCertDlls: [x64] -> c:\program files\settings manager\smdmf\x64\sysapcrt.dll ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S2 AcrSch2Svc; C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exe [427288 2007-08-31] (Acronis) S2 AntiVirFirewallService; C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe [1044784 2014-10-01] (Avira Operations GmbH & Co. KG) S2 AntiVirMailService; C:\Program Files\Avira\AntiVir Desktop\avmailc.exe [805112 2014-10-01] (Avira Operations GmbH & Co. KG) S2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) S2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [431920 2014-10-01] (Avira Operations GmbH & Co. KG) S2 AntiVirWebService; C:\Program Files\Avira\AntiVir Desktop\AVWEBGRD.EXE [994552 2014-10-01] (Avira Operations GmbH & Co. KG) S4 APNMCP; C:\Program Files\AskPartnerNetwork\Toolbar\apnmcp.exe [166296 2014-09-03] () S2 BackupStack; C:\Program Files\MyPC Backup\BackupStack.exe [36936 2014-09-10] (Just Develop It) <==== ATTENTION S2 ca82e1a5; c:\Program Files\Optimizer Pro\OptProCrash.dll [3541448 2014-09-30] () S2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39568 2014-04-06] () S2 RealPlayer Cloud Service; c:\program files\real\realplayer\RPDS\Bin\rpdsvc.exe [1141848 2014-05-01] (RealNetworks, Inc.) S2 RealPlayerUpdateSvc; C:\Program Files\Real\UpdateService\RealPlayerUpdateSvc.exe [23552 2014-04-07] () S2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1228504 2013-07-03] (Secunia) S2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [660184 2013-07-03] (Secunia) S2 SmdmFService; C:\Program Files\Settings Manager\smdmf\SmdmFService.exe [3572240 2014-07-22] (Aztec Media Inc) S2 StarWindServiceAE; C:\Program Files\Alcohol Soft\Alcohol 120\StarWind\StarWindServiceAE.exe [275968 2007-05-28] (Rocket Division Software) S2 TryAndDecideService; C:\Program Files\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe [498872 2007-08-31] () S2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesService32.exe [1529656 2013-12-11] (TuneUp Software) S3 NMIndexingService; "C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe" [X] S2 Update Framed Display; "C:\Program Files\Framed Display\updateFramedDisplay.exe" [X] S2 UtilityChest_49Service; C:\PROGRA~1\UTILIT~2\bar\1.bin\49barsvc.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S0 AFS; C:\Windows\System32\Drivers\AFS.sys [77004 2013-02-25] (Oak Technology Inc.) S3 avfwim; C:\Windows\System32\DRIVERS\avfwim.sys [92448 2013-09-25] (Avira GmbH) S1 avfwot; C:\Windows\System32\DRIVERS\avfwot.sys [113024 2013-09-25] (Avira GmbH) S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [98160 2014-10-01] (Avira Operations GmbH & Co. KG) S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [136216 2014-10-01] (Avira Operations GmbH & Co. KG) S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-10-07] (Avira Operations GmbH & Co. KG) S1 F06DEFF2-5B9C-490D-910F-35D3A9119622; C:\Program Files\Settings Manager\smdmf\smdmfmgrc2.cfg [34192 2014-07-22] (Aztec Media Inc) S3 HPZid412; C:\Windows\System32\DRIVERS\HPZid412.sys [49920 2005-10-21] (HP) S3 HPZipr12; C:\Windows\System32\DRIVERS\HPZipr12.sys [16496 2005-10-21] (HP) S3 HPZius12; C:\Windows\System32\DRIVERS\HPZius12.sys [21456 2003-03-09] (HP) S3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-07-03] (Secunia) S0 sptd; C:\Windows\System32\Drivers\sptd.sys [722416 2010-08-27] (Duplex Secure Ltd.) S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-09-25] (Avira GmbH) S0 tdrpman; C:\Windows\System32\DRIVERS\tdrpman.sys [368736 2010-09-09] (Acronis) S2 tifsfilter; C:\Windows\System32\DRIVERS\tifsfilt.sys [44416 2010-09-09] (Acronis) S3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2012\TuneUpUtilitiesDriver32.sys [10064 2011-09-22] (TuneUp Software) S3 UVCFTR; C:\Windows\System32\Drivers\UVCFTR_S.SYS [17960 2009-04-10] (Chicony Electronics Co., Ltd.) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-01 10:16 - 2014-10-01 10:16 - 00000000 ____D () C:\Users\Monika\AppData\Local\Astromenda 2014-09-30 16:17 - 2014-10-01 10:16 - 00000067 _____ () C:\Users\Monika\AppData\Roaming\WB.CFG 2014-09-30 15:17 - 2014-09-30 15:23 - 00000000 ____D () C:\Program Files\MyPC Backup 2014-09-30 15:17 - 2014-09-30 15:17 - 00001921 _____ () C:\Users\Monika\Desktop\Sync Folder.lnk 2014-09-30 15:17 - 2014-09-30 15:17 - 00001051 _____ () C:\Users\Monika\Desktop\MyPC Backup.lnk 2014-09-30 15:17 - 2014-09-30 15:17 - 00000269 _____ () C:\Users\Monika\Desktop\Cut the Rope.url 2014-09-30 15:17 - 2014-09-30 15:17 - 00000000 ____D () C:\Users\Monika\AppData\Roaming\WSE_Astromenda 2014-09-30 15:17 - 2014-09-30 15:17 - 00000000 ____D () C:\Program Files\WSE_Astromenda 2014-09-30 15:16 - 2014-09-30 15:16 - 48883240 _____ () C:\Users\Monika\Downloads\R-2.14.2-win [1].exe 2014-09-30 15:16 - 2014-09-30 15:16 - 00001026 _____ () C:\Users\Monika\Desktop\Optimizer Pro.lnk 2014-09-30 15:16 - 2014-09-30 15:16 - 00000000 ____D () C:\Program Files\Optimizer Pro 2014-09-30 15:15 - 2014-09-30 15:15 - 00783784 _____ ( ) C:\Users\Monika\Downloads\R-2.14.2-win.exe 2014-09-29 18:39 - 2014-09-29 18:39 - 06795038 _____ () C:\Users\Monika\Downloads\Knappheit(1).zip 2014-09-24 19:32 - 2014-09-30 15:46 - 00077712 _____ () C:\Users\Monika\Documents\Seminararbeit - Nash-GG in gemischten Strategien.synctex.gz 2014-09-24 18:30 - 2014-09-24 18:30 - 00000000 ____D () C:\Users\Monika\Documents\plots 2014-09-24 18:11 - 2014-09-24 18:11 - 00000133 _____ () C:\Users\Monika\Documents\Seminararbeit - Nash-GG in gemischten Strategien.exp.gnuplot 2014-09-24 18:11 - 2014-09-24 18:11 - 00000128 _____ () C:\Users\Monika\Documents\Seminararbeit - Nash-GG in gemischten Strategien.sin.gnuplot 2014-09-24 18:11 - 2014-09-24 18:11 - 00000121 _____ () C:\Users\Monika\Documents\Seminararbeit - Nash-GG in gemischten Strategien.x.gnuplot 2014-09-24 17:25 - 2014-09-09 22:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll 2014-09-20 22:59 - 2014-09-20 22:59 - 00379952 _____ () C:\Windows\Minidump\092014-23056-01.dmp 2014-09-17 13:50 - 2014-09-17 13:50 - 07891037 _____ () C:\Users\Monika\Downloads\Klimaerwaermung und Kyoto.zip 2014-09-17 13:50 - 2014-09-17 13:50 - 05587284 _____ () C:\Users\Monika\Downloads\Preisinsel.zip 2014-09-17 00:47 - 2014-09-17 00:47 - 00485600 _____ () C:\Windows\Minidump\091714-29936-01.dmp 2014-09-17 00:31 - 2014-09-17 00:31 - 06795038 _____ () C:\Users\Monika\Downloads\Knappheit.zip 2014-09-13 00:45 - 2014-08-18 22:57 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2014-09-13 00:45 - 2014-08-18 22:57 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll 2014-09-13 00:45 - 2014-08-18 22:45 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2014-09-13 00:45 - 2014-08-18 22:44 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll 2014-09-13 00:45 - 2014-08-18 22:39 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2014-09-13 00:45 - 2014-08-18 22:37 - 00440320 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2014-09-13 00:45 - 2014-08-18 22:36 - 00112128 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2014-09-13 00:45 - 2014-08-18 22:35 - 00597504 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll 2014-09-13 00:45 - 2014-08-18 22:27 - 00365056 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2014-09-13 00:45 - 2014-08-18 22:19 - 00164864 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll 2014-09-13 00:45 - 2014-08-18 22:17 - 00069632 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2014-09-13 00:45 - 2014-08-18 21:36 - 00678400 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2014-09-13 00:44 - 2014-08-19 18:39 - 00327872 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2014-09-13 00:44 - 2014-08-18 23:26 - 17455104 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2014-09-13 00:44 - 2014-08-18 23:08 - 04232704 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2014-09-13 00:44 - 2014-08-18 22:46 - 00454656 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2014-09-13 00:44 - 2014-08-18 22:44 - 00051200 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll 2014-09-13 00:44 - 2014-08-18 22:42 - 02185728 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2014-09-13 00:44 - 2014-08-18 22:39 - 00032768 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2014-09-13 00:44 - 2014-08-18 22:36 - 00108032 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe 2014-09-13 00:44 - 2014-08-18 22:30 - 00646144 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2014-09-13 00:44 - 2014-08-18 22:22 - 00060416 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll 2014-09-13 00:44 - 2014-08-18 22:17 - 00243200 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2014-09-13 00:44 - 2014-08-18 22:15 - 11769856 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2014-09-13 00:44 - 2014-08-18 22:09 - 00603136 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2014-09-13 00:44 - 2014-08-18 22:08 - 02014208 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2014-09-13 00:44 - 2014-08-18 22:08 - 00673792 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2014-09-13 00:44 - 2014-08-18 22:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2014-09-13 00:44 - 2014-08-18 21:46 - 01812992 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2014-09-13 00:44 - 2014-08-18 21:38 - 01190400 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2014-09-13 00:44 - 2014-06-27 02:45 - 02285056 _____ (Microsoft Corporation) C:\Windows\System32\msmpeg2vdec.dll 2014-09-12 20:07 - 2014-08-01 12:35 - 00793600 _____ (Microsoft Corporation) C:\Windows\System32\TSWorkspace.dll 2014-09-12 20:07 - 2014-07-07 02:40 - 01059840 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll 2014-09-12 20:07 - 2014-07-07 02:40 - 00550912 _____ (Microsoft Corporation) C:\Windows\System32\kerberos.dll 2014-09-12 20:07 - 2014-06-24 03:59 - 01987584 _____ (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2014-09-02 00:50 - 2014-09-02 00:50 - 00379952 _____ () C:\Windows\Minidump\090214-26005-01.dmp 2014-09-01 09:07 - 2014-09-01 09:07 - 00000000 ____D () C:\Windows\Hewlett-Packard ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-10-01 16:11 - 2013-09-21 21:14 - 00000000 ____D () C:\FRST 2014-10-01 14:21 - 2014-07-27 20:55 - 00000000 ____D () C:\ProgramData\smdmf 2014-10-01 14:21 - 2010-08-26 11:06 - 01904048 _____ () C:\Windows\WindowsUpdate.log 2014-10-01 14:16 - 2013-09-30 17:23 - 00037384 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avnetflt.sys 2014-10-01 14:16 - 2013-09-25 17:06 - 00136216 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avipbb.sys 2014-10-01 14:16 - 2013-09-25 17:06 - 00098160 _____ (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avgntflt.sys 2014-10-01 14:01 - 2014-08-16 14:01 - 00001414 _____ () C:\Users\Monika\Desktop\Registry kostenlos entrümpeln!.lnk 2014-10-01 10:19 - 2010-08-26 11:14 - 01620684 _____ () C:\Windows\System32\PerfStringBackup.INI 2014-09-30 15:46 - 2014-08-31 12:30 - 00075637 _____ () C:\Users\Monika\Documents\Seminararbeit - Nash-GG in gemischten Strategien.log 2014-09-30 15:46 - 2014-08-31 12:30 - 00000857 _____ () C:\Users\Monika\Documents\Seminararbeit - Nash-GG in gemischten Strategien.aux 2014-09-30 15:46 - 2014-08-31 12:30 - 00000686 _____ () C:\Users\Monika\Documents\Seminararbeit - Nash-GG in gemischten Strategien.toc 2014-09-30 15:46 - 2014-08-29 13:32 - 00024415 _____ () C:\Users\Monika\Documents\Seminararbeit - Nash-GG in gemischten Strategien.tex 2014-09-30 15:45 - 2011-10-31 21:05 - 00124131 _____ () C:\Windows\setupact.log 2014-09-30 15:35 - 2009-07-14 05:34 - 00015344 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-09-30 15:35 - 2009-07-14 05:34 - 00015344 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-09-30 15:21 - 2011-12-12 18:18 - 00081292 _____ () C:\Windows\PFRO.log 2014-09-26 20:18 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2014-09-25 18:17 - 2012-06-19 11:41 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-09-25 15:25 - 2014-06-18 21:24 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-09-24 23:15 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\System32\de-DE 2014-09-24 12:20 - 2012-06-19 11:38 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2014-09-24 12:20 - 2011-09-15 17:37 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2014-09-21 20:32 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\System32\NDF 2014-09-20 22:59 - 2013-02-26 14:08 - 264695133 _____ () C:\Windows\MEMORY.DMP 2014-09-20 22:59 - 2010-09-29 20:38 - 00000000 ____D () C:\Windows\Minidump 2014-09-15 08:06 - 2010-08-26 21:24 - 00231568 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe 2014-09-13 18:43 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-09-13 00:38 - 2013-09-23 21:42 - 00000000 ____D () C:\Windows\System32\MRT 2014-09-13 00:38 - 2010-08-30 09:19 - 98758480 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2014-09-01 09:08 - 2012-02-14 16:22 - 00000000 ____D () C:\Users\Monika\AppData\Roaming\HpUpdate Some content of TEMP: ==================== C:\Users\Monika\AppData\Local\Temp\avgnt.exe C:\Users\Monika\AppData\Local\Temp\CloudBackup9587.exe C:\Users\Monika\AppData\Local\Temp\optprosetup.exe ==================== Known DLLs (Whitelisted) ============ ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== Restore Points ========================= Restore point made on: 2014-09-05 13:23:56 Restore point made on: 2014-09-05 13:26:32 Restore point made on: 2014-09-12 20:01:01 Restore point made on: 2014-09-13 00:33:48 Restore point made on: 2014-09-16 20:10:15 Restore point made on: 2014-09-20 12:50:11 Restore point made on: 2014-09-23 08:33:11 Restore point made on: 2014-09-24 23:14:39 Restore point made on: 2014-09-28 20:25:44 Restore point made on: 2014-09-30 15:07:34 Restore point made on: 2014-09-30 15:18:53 Restore point made on: 2014-09-30 15:18:59 Restore point made on: 2014-09-30 15:19:25 ==================== Memory info =========================== Percentage of memory in use: 12% Total physical RAM: 3932.89 MB Available physical RAM: 3448.68 MB Total Pagefile: 3931.17 MB Available Pagefile: 3451.8 MB Total Virtual: 2047.88 MB Available Virtual: 1962.45 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:152.43 GB) (Free:82.06 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (daten) (Fixed) (Total:145.66 GB) (Free:144.04 GB) NTFS Drive f: (TRANSCEND) (Removable) (Total:7.48 GB) (Free:7.47 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: 63160D35) Partition 1: (Active) - (Size=152.4 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=145.7 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 7.5 GB) (Disk ID: 00000000) Partition: GPT Partition Type. LastRegBack: 2014-09-26 20:07 ==================== End Of Log ============================ --- --- --- --- --- --- Geändert von woles (01.10.2014 um 15:29 Uhr) |
01.10.2014, 19:17 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' Funktioniert noch der abgesicherte Modus? Wenn du Windows sonst normal starten konnten, wurde dein Benutzerkonto mit dem du unter Windows immer arbeitest automatisch eingeloggt?
__________________ --> Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' |
01.10.2014, 19:47 | #7 |
| Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' der abgesicherte Modus funktioniert einwandfrei. Das Benutzerkonto wurde immer automatisch eingeloggt, hatte also keinen Code. |
01.10.2014, 19:54 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' Dann geh mal im abgesicherten Modus in die Benutzerkonten über die Systemsteuerung. Erstell nen neuen User mit Adminrechten zum Testen...und stell das Autologin da ab! Starte dann neu in den normalen Modus. Berichten bitte was passiert und so.
__________________ Logfiles bitte immer in CODE-Tags posten |
01.10.2014, 20:47 | #9 |
| Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' ich muss mich korrigieren, der abgesicherte Modus funktioniert nicht. Es ist weiterhin ein komplett schwarzer Bildschirm vorhanden. (Ich dachte, solange keine Fehlermeldung auftaucht, funktioniert er) |
01.10.2014, 22:25 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' Na, dann probieren wir mal: Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\Monika\...\RunOnce: [WSE_Astromenda] => wscript /E:vbscript /B "C:\Users\Monika\AppData\Roaming\WSE_Astromenda\UpdateProc\bkup.dat" HKU\Monika\...\Run: [Optimizer Pro] => C:\Program Files\Optimizer Pro\OptProLauncher.exe [146888 2014-08-21] (PC Utilities Software Limited) HKU\Monika\...\Run: [BRS] => C:\Program Files\WSE_Astromenda\BRS\brs.exe [1074688 2014-09-30] () HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Settings Manager\smdmf\sysapcrt.dll [488464 2014-07-22] () HKLM\...\AppCertDlls: [x64] -> c:\program files\settings manager\smdmf\x64\sysapcrt.dll AppInit_DLLs: C:\Users\Monika\AppData\Local\Linkey\IEEXTE~1\iedll.dll => C:\Users\Monika\AppData\Local\Linkey\IEEXTE~1\iedll.dll File Not Found IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe C:\ProgramData\smdmf C:\Users\Monika\AppData\Local\Temp\avgnt.exe C:\Users\Monika\AppData\Local\Temp\CloudBackup9587.exe C:\Users\Monika\AppData\Local\Temp\optprosetup.exe
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.
__________________ Logfiles bitte immer in CODE-Tags posten |
01.10.2014, 22:56 | #11 |
| Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' hier wäre die Fixlog.txt: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 30-09-2014 Ran by SYSTEM at 2014-10-01 23:52:56 Run:2 Running from F:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** HKU\Monika\...\RunOnce: [WSE_Astromenda] => wscript /E:vbscript /B "C:\Users\Monika\AppData\Roaming\WSE_Astromenda\UpdateProc\bkup.dat" HKU\Monika\...\Run: [Optimizer Pro] => C:\Program Files\Optimizer Pro\OptProLauncher.exe [146888 2014-08-21] (PC Utilities Software Limited) HKU\Monika\...\Run: [BRS] => C:\Program Files\WSE_Astromenda\BRS\brs.exe [1074688 2014-09-30] () HKLM\...\AppCertDlls: [x86] -> C:\Program Files\Settings Manager\smdmf\sysapcrt.dll [488464 2014-07-22] () HKLM\...\AppCertDlls: [x64] -> c:\program files\settings manager\smdmf\x64\sysapcrt.dll AppInit_DLLs: C:\Users\Monika\AppData\Local\Linkey\IEEXTE~1\iedll.dll => C:\Users\Monika\AppData\Local\Linkey\IEEXTE~1\iedll.dll File Not Found IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\bpsvc.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe IFEO\browsersafeguard.exe: [Debugger] tasklist.exe IFEO\dprotectsvc.exe: [Debugger] tasklist.exe IFEO\jumpflip: [Debugger] tasklist.exe IFEO\protectedsearch.exe: [Debugger] tasklist.exe IFEO\searchinstaller.exe: [Debugger] tasklist.exe IFEO\searchprotection.exe: [Debugger] tasklist.exe IFEO\searchprotector.exe: [Debugger] tasklist.exe IFEO\searchsettings.exe: [Debugger] tasklist.exe IFEO\searchsettings64.exe: [Debugger] tasklist.exe IFEO\snapdo.exe: [Debugger] tasklist.exe IFEO\stinst32.exe: [Debugger] tasklist.exe IFEO\stinst64.exe: [Debugger] tasklist.exe IFEO\umbrella.exe: [Debugger] tasklist.exe IFEO\utiljumpflip.exe: [Debugger] tasklist.exe IFEO\volaro: [Debugger] tasklist.exe IFEO\vonteera: [Debugger] tasklist.exe IFEO\websteroids.exe: [Debugger] tasklist.exe IFEO\websteroidsservice.exe: [Debugger] tasklist.exe C:\ProgramData\smdmf C:\Users\Monika\AppData\Local\Temp\avgnt.exe C:\Users\Monika\AppData\Local\Temp\CloudBackup9587.exe C:\Users\Monika\AppData\Local\Temp\optprosetup.exe ***************** HKU\Monika\Software\Microsoft\Windows\CurrentVersion\RunOnce\\WSE_Astromenda => value deleted successfully. HKU\Monika\Software\Microsoft\Windows\CurrentVersion\Run\\Optimizer Pro => value deleted successfully. HKU\Monika\Software\Microsoft\Windows\CurrentVersion\Run\\BRS => value deleted successfully. HKLM\System\ControlSet001\Control\Session Manager\AppCertDlls\\x86 => value deleted successfully. HKLM\System\ControlSet001\Control\Session Manager\AppCertDlls\\x64 => value deleted successfully. "C:\Users\Monika\AppData\Local\Linkey\IEEXTE~1\iedll.dll" => Value Data removed successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bitguard.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bprotect.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\bpsvc.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserdefender.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browserprotect.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\browsersafeguard.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\dprotectsvc.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\jumpflip" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\protectedsearch.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchinstaller.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotection.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchprotector.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\searchsettings64.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\snapdo.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst32.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\stinst64.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\umbrella.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\utiljumpflip.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\volaro" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\vonteera" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroids.exe" => Key deleted successfully. "HKLM\Software\microsoft\windows nt\currentversion\Image File Execution Options\websteroidsservice.exe" => Key deleted successfully. C:\ProgramData\smdmf => Moved successfully. C:\Users\Monika\AppData\Local\Temp\avgnt.exe => Moved successfully. C:\Users\Monika\AppData\Local\Temp\CloudBackup9587.exe => Moved successfully. C:\Users\Monika\AppData\Local\Temp\optprosetup.exe => Moved successfully. ==== End of Fixlog ==== |
02.10.2014, 09:23 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' Startet Windows wieder normal oder zumindest im abgesicherten Modus?
__________________ Logfiles bitte immer in CODE-Tags posten |
02.10.2014, 09:44 | #13 |
| Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' Windows startet weder im normalen noch im abgesicherten Modus normal.. |
02.10.2014, 10:06 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' Dann brauchst du eine Windows-DVD, mit der du eine Reparatur- oder Neuinstallation des Systems machen musst.
__________________ Logfiles bitte immer in CODE-Tags posten |
02.10.2014, 10:48 | #15 |
| Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' dann kaufe ich mir heute eine Windows-DVD.. klingt, also wäre es eher ein schwerwiegender Virus..! noch eine Frage: Ist Windows 7 das Gleiche wie Windows Vista? resp. ist das Vorgehen bei der Neuinstallation das Gleiche? Geändert von woles (02.10.2014 um 10:56 Uhr) |
Themen zu Schwarzer Bildschirm nach Herunterladen der Statistiksoftware 'R Statistik' |
ahnung, bereich, bildschirm, dankbar, erkenne, guten, herunterladen, hilfe, keine ahnung, laptop, maus, schwarzer, schwarzer bildschirm, starte, virus, wirklich |