|
Plagegeister aller Art und deren Bekämpfung: Netbook macht ProblemeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
12.01.2015, 16:49 | #31 | |
/// the machine /// TB-Ausbilder | Netbook macht ProblemeZitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.01.2015, 17:16 | #32 |
| Netbook macht ProblemeFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-01-2015 Ran by Steffan (administrator) on STEFFAN-VARIO on 12-01-2015 17:15:13 Running from C:\Users\Steffan\Desktop Loaded Profile: Steffan (Available profiles: Steffan) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: Opera) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AdminService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgr.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (Sony Corporation) C:\Program Files (x86)\Sony\VAIO Control Center\VESMgrSub.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe (Microsoft Corporation) C:\Program Files\Microsoft Mouse and Keyboard Center\itype.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Ruiware LLC) C:\Program Files (x86)\Ruiware\WinPatrol\WinPatrol.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Dolby Laboratories Inc.) C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe (Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe (Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements 9 Organizer\PhotoshopElementsFileAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (InterVideo) C:\Program Files (x86)\Common Files\InterVideo\RegMgr\iviRegMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCSystemTray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Sony Corporation) C:\Program Files\Sony\VAIO Update Common\VUAgent.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAdmin.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Microsoft Corporation) C:\Windows\System32\dinotify.exe (Opera Software) C:\Program Files (x86)\Opera\26.0.1656.60\opera.exe () C:\Program Files (x86)\Opera\26.0.1656.60\opera_crashreporter.exe (Opera Software) C:\Program Files (x86)\Opera\26.0.1656.60\opera.exe (Opera Software) C:\Program Files (x86)\Opera\26.0.1656.60\opera.exe (Opera Software) C:\Program Files (x86)\Opera\26.0.1656.60\opera.exe (Opera Software) C:\Program Files (x86)\Opera\26.0.1656.60\opera.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11895400 2011-11-14] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-11-14] (Realtek Semiconductor) HKLM\...\Run: [AtherosBtStack] => C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe [947360 2011-07-05] (Atheros Communications) HKLM\...\Run: [AthBtTray] => C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe [797344 2011-07-05] (Atheros Commnucations) HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2531624 2011-06-22] (Synaptics Incorporated) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [497648 2010-07-29] (Adobe Systems Incorporated) HKLM-x32\...\Run: [IAStorIcon] => C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2011-01-12] (Intel Corporation) HKLM-x32\...\Run: [Dolby Home Theater v4] => C:\Program Files (x86)\Dolby Home Theater v4\pcee4.exe [500736 2011-05-02] (Dolby Laboratories Inc.) HKLM-x32\...\Run: [ISBMgr.exe] => C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe [60552 2011-09-20] (Sony Corporation) HKLM-x32\...\Run: [PMBVolumeWatcher] => c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [651832 2011-08-24] (Sony Corporation) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-09] (AVAST Software) HKLM-x32\...\RunOnce: [20150107] => C:\Program Files\AVAST Software\Avast\setup\emupdate\6fa05948-e40a-460f-9c93-0fb3c6be6fd4.exe [183232 2015-01-12] (AVAST Software) HKU\S-1-5-21-583113307-2265806991-2562450481-1000\...\Run: [CCleaner Monitoring] => C:\Program Files\CCleaner\CCleaner64.exe [7063832 2014-11-21] (Piriform Ltd) HKU\S-1-5-21-583113307-2265806991-2562450481-1000\...\Run: [WinPatrol] => C:\Program Files (x86)\Ruiware\WinPatrol\winpatrol.exe [1154112 2014-07-21] (Ruiware LLC) Startup: C:\Users\Steffan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-583113307-2265806991-2562450481-1000\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://vaioportal.sony.eu HKU\S-1-5-21-583113307-2265806991-2562450481-1000\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://sony.msn.com HKU\S-1-5-21-583113307-2265806991-2562450481-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://sony.msn.com SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-583113307-2265806991-2562450481-1000 -> {27FA1562-0713-4C2C-8A29-F24D26A1A99F} URL = hxxp://rover.ebay.com/rover/1/707-37276-16609-27/4?mpre=hxxp://shop.ebay.de/?oemInLn=ieSrch-Q112&_nkw={searchTerms} SearchScopes: HKU\S-1-5-21-583113307-2265806991-2562450481-1000 -> {DFAB032C-3D64-4122-A442-32BBE54C2D77} URL = https://www.google.com/search?q={searchTerms} BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: CIESpeechBHO Class -> {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} -> C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll () FF Plugin: @java.com/JavaPlugin -> C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll () FF Plugin-x32: @java.com/JavaPlugin -> C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @playstation.com/PsndlCheck,version=1.00 -> C:\Program Files (x86)\Sony\PLAYSTATION Network Downloader\nppsndl.dll (Sony Computer Entertainment Inc.) FF Plugin-x32: @SonyCreativeSoftware.com/Media Go,version=1.0 -> C:\Program Files (x86)\Sony\Media Go\npmediago.dll (Sony Network Entertainment International LLC) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-583113307-2265806991-2562450481-1000: pandonetworks.com/PandoWebPlugin -> C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-06-24] FF HKU\S-1-5-21-583113307-2265806991-2562450481-1000\...\Firefox\Extensions: [{b64982b1-d112-42b5-b1e4-d3867c4533f8}] - C:\ProgramData\Browser Manager\2.3.787.43\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.google.com" CHR Profile: C:\Users\Steffan\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\Steffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-12-12] CHR Extension: (YouTube) - C:\Users\Steffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-12-12] CHR Extension: (Google-Suche) - C:\Users\Steffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-12-12] CHR Extension: (Google Tabellen) - C:\Users\Steffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2014-12-12] CHR Extension: (Google Wallet) - C:\Users\Steffan\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-12-12] CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-08] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.) R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [138400 2011-07-05] (Atheros) [File not signed] R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [98976 2011-07-05] (Atheros Commnucations) [File not signed] R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-08] (AVAST Software) S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [111776 2011-08-25] (Atheros Communication Inc.) [File not signed] S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [4519472 2013-11-06] (INCA Internet Co., Ltd.) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [260768 2011-11-30] (Sony Corporation) R2 uCamMonitor; c:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.) S3 VCFw; C:\Program Files (x86)\Common Files\Sony Shared\VAIO Content Folder Watcher\VCFw.exe [894624 2011-09-01] (Sony Corporation) S3 COMSysApp; %SystemRoot%\system32\dllhost.exe /Processid:{02D4B3F1-FD88-11D1-960D-00805FC79235} ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-08] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2015-01-08] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-08] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-08] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-09] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-08] (AVAST Software) S2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-08] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-08] () R2 risdsnpe; C:\Windows\system32\drivers\risdsnxc64.sys [98816 2011-06-23] (REDC) S3 ALSysIO; \??\C:\Users\Steffan\AppData\Local\Temp\ALSysIO64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-12 15:44 - 2015-01-12 15:44 - 00852505 _____ () C:\Users\Steffan\Desktop\SecurityCheck.exe 2015-01-12 13:48 - 2015-01-12 13:48 - 02347384 _____ (ESET) C:\Users\Steffan\Desktop\esetsmartinstaller_deu.exe 2015-01-12 13:48 - 2015-01-12 13:48 - 00000000 ____D () C:\Program Files (x86)\ESET 2015-01-11 22:40 - 2015-01-11 22:40 - 00001897 _____ () C:\Users\Steffan\Desktop\JRT.txt 2015-01-11 22:36 - 2015-01-11 22:36 - 00000000 ____D () C:\Windows\ERUNT 2015-01-11 22:34 - 2015-01-11 22:34 - 01707939 _____ (Thisisu) C:\Users\Steffan\Desktop\JRT.exe 2015-01-11 22:32 - 2015-01-11 22:32 - 00000000 ___RD () C:\Users\Steffan\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2015-01-11 22:28 - 2015-01-11 22:30 - 00000000 ____D () C:\AdwCleaner 2015-01-11 22:24 - 2015-01-11 22:24 - 00001205 _____ () C:\Users\Steffan\Desktop\mbam.txt 2015-01-11 17:50 - 2015-01-12 17:15 - 00016597 _____ () C:\Users\Steffan\Desktop\FRST.txt 2015-01-11 17:50 - 2015-01-11 17:51 - 00046592 _____ () C:\Users\Steffan\Desktop\Addition.txt 2015-01-11 17:49 - 2015-01-12 17:15 - 00000000 ____D () C:\FRST 2015-01-11 17:49 - 2015-01-11 17:49 - 02124288 _____ (Farbar) C:\Users\Steffan\Desktop\FRST64.exe 2015-01-10 10:44 - 2015-01-10 10:45 - 00496600 _____ () C:\Windows\Minidump\011015-18844-01.dmp 2015-01-10 10:44 - 2015-01-10 10:44 - 632879166 _____ () C:\Windows\MEMORY.DMP 2015-01-09 10:25 - 2014-09-05 03:11 - 06584320 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2015-01-09 10:25 - 2014-09-05 02:52 - 05703168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2015-01-09 10:25 - 2014-08-29 03:07 - 03179520 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorets.dll 2015-01-09 10:25 - 2014-05-08 10:32 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\RdpGroupPolicyExtension.dll 2015-01-09 00:18 - 2015-01-09 00:18 - 00448512 _____ (OldTimer Tools) C:\Users\Steffan\Desktop\TFC (1).exe 2015-01-09 00:12 - 2015-01-09 00:17 - 00000000 ____D () C:\ProgramData\TEMP 2015-01-09 00:12 - 2015-01-09 00:17 - 00000000 ____D () C:\Program Files (x86)\SpywareBlaster 2015-01-09 00:12 - 2015-01-09 00:12 - 00001079 _____ () C:\Users\Public\Desktop\SpywareBlaster.lnk 2015-01-09 00:12 - 2015-01-09 00:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SpywareBlaster 2015-01-09 00:12 - 2015-01-09 00:12 - 00000000 ____D () C:\ProgramData\Licenses 2015-01-09 00:12 - 2009-03-24 12:52 - 00129872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MSSTDFMT.DLL 2015-01-08 23:49 - 2015-01-08 23:49 - 00000000 ____D () C:\Users\Steffan\AppData\Roaming\AVAST Software 2015-01-08 23:39 - 2015-01-08 23:39 - 00001964 _____ () C:\Users\Public\Desktop\Avast Free Antivirus.lnk 2015-01-08 23:38 - 2015-01-08 23:38 - 00364512 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2015-01-08 23:38 - 2015-01-08 23:38 - 00116728 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys 2015-01-08 23:38 - 2015-01-08 23:38 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2015-01-08 23:38 - 2015-01-08 23:38 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2015-01-08 23:23 - 2015-01-08 23:23 - 00000000 ____D () C:\Users\Steffan\AppData\Roaming\WinPatrol 2015-01-08 23:23 - 2015-01-08 23:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinPatrol 2015-01-08 23:23 - 2015-01-08 23:23 - 00000000 ____D () C:\ProgramData\InstallMate 2015-01-08 23:23 - 2015-01-08 23:23 - 00000000 ____D () C:\Program Files (x86)\Ruiware 2015-01-08 23:12 - 2015-01-11 21:04 - 00129752 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-08 23:11 - 2015-01-08 23:11 - 00001102 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-08 23:11 - 2015-01-08 23:11 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-08 23:11 - 2015-01-08 23:11 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-08 23:11 - 2015-01-08 23:11 - 00000000 ____D () C:\Program Files (x86)\ Malwarebytes Anti-Malware 2015-01-08 23:11 - 2014-11-21 06:14 - 00093400 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-08 23:11 - 2014-11-21 06:14 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-08 23:11 - 2014-11-21 06:14 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-08 22:24 - 2013-10-02 03:22 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbFlt.sys 2015-01-08 22:24 - 2013-10-02 03:11 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyControl.exe 2015-01-08 22:24 - 2013-10-02 03:08 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbRedirectionGroupPolicyExtension.dll 2015-01-08 22:24 - 2013-10-02 02:48 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\MsRdpWebAccess.dll 2015-01-08 22:24 - 2013-10-02 02:48 - 00018944 _____ (Microsoft Corporation) C:\Windows\system32\wksprtPS.dll 2015-01-08 22:24 - 2013-10-02 02:29 - 00062976 _____ (Microsoft Corporation) C:\Windows\system32\tsgqec.dll 2015-01-08 22:24 - 2013-10-02 02:10 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\TsUsbGDCoInstaller.dll 2015-01-08 22:24 - 2013-10-02 01:15 - 01057280 _____ (Microsoft Corporation) C:\Windows\system32\rdvidcrl.dll 2015-01-08 22:24 - 2013-10-02 01:14 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll 2015-01-08 22:24 - 2013-10-02 01:14 - 00017920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll 2015-01-08 22:24 - 2013-10-02 01:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-08 22:24 - 2013-10-02 01:01 - 00420864 _____ (Microsoft Corporation) C:\Windows\system32\wksprt.exe 2015-01-08 22:24 - 2013-10-02 00:58 - 00053248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll 2015-01-08 22:24 - 2013-10-02 00:31 - 01147392 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe 2015-01-08 22:24 - 2013-10-02 00:08 - 00855552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdvidcrl.dll 2015-01-08 22:24 - 2013-10-01 23:34 - 01068544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe 2015-01-08 22:24 - 2012-08-23 15:13 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\rdpudd.dll 2015-01-08 22:24 - 2012-08-23 15:10 - 00019456 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpvideominiport.sys 2015-01-08 22:24 - 2012-08-23 15:08 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\TsUsbGD.sys 2015-01-08 22:24 - 2012-08-23 12:12 - 00192000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll 2015-01-08 22:24 - 2012-08-23 11:51 - 00228864 _____ (Microsoft Corporation) C:\Windows\system32\rdpendp_winip.dll 2015-01-01 04:47 - 2015-01-01 04:47 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_ZuneDriver_01_09_00.Wdf 2015-01-01 04:47 - 2015-01-01 04:47 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_WinUsb_01009.Wdf 2014-12-18 16:37 - 2014-12-13 06:09 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-12-18 16:37 - 2014-12-13 04:33 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-12-13 00:42 - 2014-12-13 00:42 - 00074160 _____ () C:\Users\Steffan\AppData\Local\GDIPFONTCACHEV1.DAT 2014-12-13 00:41 - 2015-01-12 02:59 - 00009544 _____ () C:\Windows\setupact.log 2014-12-13 00:41 - 2014-12-13 00:41 - 00000000 _____ () C:\Windows\setuperr.log 2014-12-13 00:40 - 2015-01-11 22:31 - 00221410 _____ () C:\Windows\PFRO.log 2014-12-13 00:40 - 2014-12-13 00:40 - 00326744 _____ () C:\Windows\system32\FNTCACHE.DAT ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-12 16:50 - 2012-07-31 19:22 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-12 16:36 - 2014-12-12 23:24 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-12 13:29 - 2014-08-17 19:59 - 01186858 _____ () C:\Windows\WindowsUpdate.log 2015-01-12 08:05 - 2009-07-14 05:45 - 00028352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-12 08:05 - 2009-07-14 05:45 - 00028352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-12 02:42 - 2014-12-12 23:24 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-12 02:42 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-12 02:41 - 2009-07-14 06:08 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-12 01:33 - 2013-08-13 22:44 - 00000000 ____D () C:\Users\Steffan\AppData\Local\Battle.net 2015-01-11 22:36 - 2012-02-10 09:50 - 00699666 _____ () C:\Windows\system32\perfh007.dat 2015-01-11 22:36 - 2012-02-10 09:50 - 00149774 _____ () C:\Windows\system32\perfc007.dat 2015-01-11 22:36 - 2009-07-14 06:13 - 01620612 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-11 22:31 - 2012-02-10 10:14 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-01-11 22:26 - 2013-04-26 00:30 - 00003958 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{9B8DFD85-188D-46BF-9E32-303FC49C205F} 2015-01-11 22:02 - 2012-10-25 22:24 - 00000000 ____D () C:\Users\Steffan\AppData\Local\Deployment 2015-01-10 10:44 - 2012-10-13 02:38 - 00000000 ____D () C:\Windows\Minidump 2015-01-10 09:42 - 2014-05-13 21:50 - 00000000 ____D () C:\Users\Steffan\Desktop\Königspython 2015-01-10 09:41 - 2013-09-29 05:25 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2015-01-10 09:41 - 2012-06-22 22:48 - 00000000 ____D () C:\Users\Steffan\AppData\Roaming\Atheros 2015-01-09 23:06 - 2012-06-22 22:49 - 00000000 ____D () C:\Users\Steffan\Documents\Bluetooth Folder 2015-01-09 10:52 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache 2015-01-09 00:09 - 2012-06-24 18:32 - 01050432 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2015-01-08 23:38 - 2013-09-29 05:25 - 00267632 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2015-01-08 23:38 - 2013-09-29 05:25 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2015-01-08 23:38 - 2012-06-24 18:32 - 00436624 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2015-01-08 23:38 - 2012-06-24 18:32 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2015-01-08 23:38 - 2012-06-24 18:32 - 00083280 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2015-01-08 23:36 - 2012-06-24 18:32 - 00000000 ____D () C:\ProgramData\AVAST Software 2015-01-08 23:36 - 2012-06-24 18:32 - 00000000 _____ () C:\Windows\SysWOW64\config.nt 2015-01-08 23:33 - 2009-07-14 06:32 - 00000000 ____D () C:\Windows\Performance 2015-01-08 22:27 - 2009-07-14 04:20 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-01-08 22:25 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2015-01-06 18:55 - 2013-01-17 21:52 - 00000518 _____ () C:\Users\Steffan\Desktop\Neues Textdokument (2).txt 2015-01-06 04:36 - 2010-11-21 04:27 - 00298120 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-01-01 23:55 - 2014-08-15 22:43 - 00000000 ____D () C:\Users\Steffan\AppData\Local\Adobe 2015-01-01 23:55 - 2012-07-31 19:22 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-01-01 23:55 - 2012-07-31 19:22 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-01-01 23:55 - 2012-02-10 10:58 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-12-21 00:00 - 2012-10-23 20:23 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft 2014-12-17 16:04 - 2014-06-08 23:45 - 00003862 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1402267513 2014-12-17 16:04 - 2012-06-22 22:58 - 00000000 ____D () C:\Program Files (x86)\Opera 2014-12-16 00:56 - 2014-11-25 12:24 - 00000000 ____D () C:\Users\Steffan\Desktop\Familien Bilder 2014-12-14 08:19 - 2012-10-19 11:58 - 00000000 ____D () C:\Users\Steffan\AppData\Roaming\TS3Client 2014-12-13 15:50 - 2013-08-13 22:44 - 00000000 ____D () C:\Program Files (x86)\Battle.net Some content of TEMP: ==================== C:\Users\Steffan\AppData\Local\Temp\Quarantine.exe C:\Users\Steffan\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-04 02:12 ==================== End Of Log ============================ |
12.01.2015, 17:27 | #33 |
/// the machine /// TB-Ausbilder | Netbook macht Probleme Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster.
__________________Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Program Files (x86)\SpottyFiles Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ |
12.01.2015, 18:06 | #34 |
| Netbook macht ProblemeCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-01-2015 Ran by Steffan at 2015-01-12 18:01:53 Run:1 Running from C:\Users\Steffan\Desktop Loaded Profile: Steffan (Available profiles: Steffan) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Program Files (x86)\SpottyFiles Emptytemp: ***************** C:\Program Files (x86)\SpottyFiles => Moved successfully. EmptyTemp: => Removed 16.2 MB temporary data. The system needed a reboot. ==== End of Fixlog 18:01:58 ==== |
12.01.2015, 18:07 | #35 |
/// the machine /// TB-Ausbilder | Netbook macht Probleme fertig
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
12.01.2015, 18:27 | #36 |
| Netbook macht Probleme |
12.01.2015, 19:20 | #37 |
/// the machine /// TB-Ausbilder | Netbook macht Probleme Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Netbook macht Probleme |
browser, cpu, dauert, experte, experten, express, hoffe, klick, langsam, marke, medion, minute, minuten, mobile, ordner, problem, probleme, ram, reagiert, schonmal, spass, ultimate, virus, ziemlich, öffnen |