|
Plagegeister aller Art und deren Bekämpfung: Super-Gau nach phising mailWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
16.01.2015, 16:07 | #1 |
| Super-Gau nach phising mail hallo, heute gab es den supergau bei meinem Freund! 1. Er ist dummerweise auf eine phising mail reingefallen und hat seine Daten eingegeben... total dumm dumm dumm!!! Die Bank wurde informiert und die Konten schon mal gesperrt, was aber mit den persönlichen Daten geschehen mag ist total offen. 2. Er hat einen link innerhalb der mail geöffnet und ist so auf die fake website geleitet worden wo er dann die seine Daten eingegeben hat. 3. Um zu kontrollieren ob auch ein schädling jetzt auf dem pc gelandet ist, wurde ein avg scan durchgeführt, eine Bedrohung wurde erkannt. 4. Zur Sicherheit wurde dann noch der awd cleaner eingesetzt, der nur eine Meldung gefunden hatte, ask.com oder so ähnlich. 5. awd cleaner führt ja dann automatisch einen Neustart durch. 6. Und seitdem Neustart geht garnichts mehr... Der PC braucht lange um hochzufahren (WIN 8) , dann sind ein paar Klicks möglich und dann geht nichts mehr. Maus ist deaktiviert und eine Steuerung mit Tasten geht auch nicht. Nach strg und alt und entferntaste kommt dann die Meldung Dp.. watchdog violation. Wir bitten um Hilfe!!! Danke |
16.01.2015, 18:21 | #2 |
/// the machine /// TB-Ausbilder | Super-Gau nach phising mail hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
16.01.2015, 20:20 | #3 |
| pc stürzt immer wieder ab hallo,
__________________ich konnte frst zwar runterladen, aber während des scans ist der pc wieder abgestürzt, watchdog violation.. nochmal versucht, diesmal pc absturz fast sofort... ich werde es weiter versuchen, aber gibt es alternativen? |
17.01.2015, 12:28 | #4 |
/// the machine /// TB-Ausbilder | Super-Gau nach phising mail Mach bitte ne Systemwiederherstellung auf den Punkt vor AdwCleaner, dann FRST.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.01.2015, 20:22 | #5 |
| Super-Gau nach phising mail okay, versuche es. Wiederherstellungspunkt und systemstart konnte ich aktivieren, jetzt hängt der pc in einer endlosschleife, " ..die systemwiederherstellung wird initialisiert". mal schauen wielange das dauert. systemwiederherstellung wurde durchgeführt, hat aber nichts daran geändert, dass der pc nach ca. 2 Minuten einfriert. aber inzwischen konnte ich eine frst.txt datei sichern, die addition gibt es nicht. die txt ist von vor dem versuch der systemwiederherstellung FRST Logfile: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-01-2015 01 Ran by Saturn sw (administrator) on SATURN on 17-01-2015 11:48:18 Running from C:\Users\Saturn sw\Downloads Loaded Profiles: Saturn sw (Available profiles: Saturn sw) Platform: Windows 8.1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgcsrva.exe (ABBYY) C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (Windows (R) Win 7 DDK provider) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgfws.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe (AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe (Seiko Epson Corporation) C:\Windows\System32\escsvc64.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgemca.exe (AVG Technologies) C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesApp64.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.5.9600.20689_x64__8wekyb3d8bbwe\livecomm.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Atheros Communications) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe () C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\ActivateDesktop.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Integrated Clock Controller Service\ICCProxy.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ZTE) C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe (SEIKO EPSON CORPORATION) C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2014\avgui.exe (Haufe-Lexware GmbH & Co. KG) C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe () C:\Program Files (x86)\congstar\Internet-Manager\Bin\dbus-daemon.exe () C:\Program Files (x86)\congstar\Internet-Manager\Bin\db_daemon.exe (Lexware GmbH & Co. KG) C:\Program Files (x86)\Common Files\Lexware\LxWebAccess\LxWebAccess.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Farbar) C:\Users\Saturn sw\Downloads\FRST64(1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2890640 2013-04-22] (ELAN Microelectronics Corp.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13550152 2013-05-30] (Realtek Semiconductor) HKLM\...\Run: [Logitech Download Assistant] => C:\Windows\system32\rundll32.exe C:\Windows\System32\LogiLDA.dll,LogiFetch HKLM-x32\...\Run: [EEventManager] => C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe [1058400 2011-10-31] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [AVG_UI] => C:\Program Files (x86)\AVG\AVG2014\avgui.exe [5188112 2014-12-16] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [271744 2014-09-26] (Oracle Corporation) HKLM-x32\...\Run: [LexwareInfoService] => C:\Program Files (x86)\Common Files\Lexware\Update Manager\LxUpdateManager.exe [339312 2010-09-15] (Haufe-Lexware GmbH & Co. KG) Winlogon\Notify\igfxcui: C:\WINDOWS\system32\igfxdev.dll (Intel Corporation) HKLM\...\Policies\Explorer\Run: [BtvStack] => C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\BtvStack.exe [133248 2013-05-31] ( (Atheros Communications)) HKU\S-1-5-21-3878855970-111228901-362715822-1001\...\Run: [AVG-Secure-Search-Update_1213b] => C:\Users\Saturn sw\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=e6dc76f2478b47d3a1ea999b620f451f-87ccd9cad13721a48b74d94bcc10349563f865aa /CMPID=1213b HKU\S-1-5-21-3878855970-111228901-362715822-1001\...\MountPoints2: {9f981085-912f-11e4-beb3-48d224ebacec} - "E:\HTC_Sync_Manager_PC.exe" HKU\S-1-5-21-3878855970-111228901-362715822-1001\...\MountPoints2: {dd8b467f-9989-11e4-beb3-48d224ebacec} - "E:\windows\Data\setup.exe" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MCtlSvc.lnk ShortcutTarget: MCtlSvc.lnk -> C:\Program Files (x86)\congstar\Internet-Manager\Bin\mcserver.exe (ZTE) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com StartMenuInternet: IEXPLORE.EXE - iexplore.exe SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3878855970-111228901-362715822-1001 -> {5CE856F3-585F-49A5-AB10-63701B8BEE9C} URL = BHO: Plus-HD-3.8 -> {11111111-1111-1111-1111-110311901130} -> No File BHO: Easy Photo Print -> {9421DD08-935F-4701-A9CA-22DF90AC4EA6} -> C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) BHO-x32: E-Web Print -> {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} -> C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files (x86)\Epson Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION) Toolbar: HKLM-x32 - E-Web Print - {201CF130-E29C-4E5C-A73F-CD197DEFA6AE} - C:\Program Files (x86)\Epson Software\E-Web Print\ewps_tb.dll (SEIKO EPSON CORPORATION) Tcpip\..\Interfaces\{9F97C8DB-7492-466A-8AC7-5F50E06ACA05}: [NameServer] 10.74.210.210 10.74.210.211 FireFox: ======== FF ProfilePath: C:\Users\Saturn sw\AppData\Roaming\Mozilla\Firefox\Profiles\ngmituxw.default FF SearchEngineOrder.1: Amazon FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\WINDOWS\system32\Macromed\Flash\NPSWF64_16_0_0_257.dll () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\WINDOWS\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_257.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.66 -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.71.2 -> C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Extension: Adblock Plus - C:\Users\Saturn sw\AppData\Roaming\Mozilla\Firefox\Profiles\ngmituxw.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2013-12-09] FF HKLM-x32\...\Firefox\Extensions: [e-webprint@epson.com] - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on FF Extension: E-Web Print - C:\Program Files (x86)\Epson Software\E-Web Print\Firefox Add-on [2013-11-13] FF HKLM-x32\...\Firefox\Extensions: [{ee8cd9f6-dae3-4889-816b-99fe80dae284}] - C:\Program Files (x86)\WinSecurity\winsecurity.xpi FF HKLM-x32\...\Firefox\Extensions: [ff-bmboc@bytemobile.com] - C:\Program Files (x86)\congstar\Internet-Manager\Bin\addon FF Extension: Bytemobile Optimization Client - C:\Program Files (x86)\congstar\Internet-Manager\Bin\addon [2015-01-16] Chrome: ======= CHR HomePage: Default -> CHR StartupUrls: Default -> "hxxp://www.search.ask.com/?tpid=ORJ-SPE&o=APN11412&pf=V7&trgb=CR&p2=%5EBBK%5EOSJ000%5EYY%5EDE&gct=hp&apn_ptnrs=BBK&apn_dtid=%5EOSJ000%5EYY%5EDE&apn_dbr=cr_36.0.1985.125&apn_uid=CD00C4C6-15C2-4108-AB4C-F0C5977CD6D0&itbv=12.15.1.20&doi=2014-07-23&psv=&pt=tb" CHR DefaultSuggestURL: Default -> hxxp://ssmsp.ask.com/query?sstype=prefix&li=ff&q={searchTerms} CHR Profile: C:\Users\Saturn sw\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Saturn sw\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-09-02] CHR Extension: (AdBlock) - C:\Users\Saturn sw\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-21] CHR Extension: (WEB.DE MailCheck) - C:\Users\Saturn sw\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaogepninmlbinccpbiakcgiolijlllo [2014-09-28] CHR Extension: (Google Wallet) - C:\Users\Saturn sw\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-10] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 ABBYY.Licensing.FineReader.Sprint.9.0; C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [759048 2009-05-14] (ABBYY) R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [310912 2013-05-31] (Windows (R) Win 7 DDK provider) R2 avgfws; C:\Program Files (x86)\AVG\AVG2014\avgfws.exe [1417160 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2014\avgidsagent.exe [3247120 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2014\avgwdsvc.exe [289328 2014-12-16] (AVG Technologies CZ, s.r.o.) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-27] (Acer Incorporated) S3 DeviceFastLaneService; C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe [470056 2013-04-30] (Acer Incorporated) S3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [662088 2013-03-15] (Acer Incorporated) R2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [732160 2012-12-10] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [803872 2012-12-10] (Intel(R) Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165336 2013-01-14] (Intel Corporation) R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-06-17] (Acer Incorporate) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesService64.exe [2604856 2014-11-24] (AVG Technologies) S3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [368632 2014-09-22] (Microsoft Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [23792 2014-09-22] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20496 2013-09-04] (AVG Technologies CZ, s.r.o.) R1 Avgdiska; C:\Windows\System32\DRIVERS\avgdiska.sys [152344 2014-06-30] (AVG Technologies CZ, s.r.o.) R1 Avgfwfd; C:\Windows\system32\DRIVERS\avgfwd6a.sys [57144 2013-09-26] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [244504 2014-07-21] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [190744 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [237848 2014-10-24] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [328984 2014-06-17] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [123672 2014-10-29] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [31512 2014-06-17] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [270104 2014-06-30] (AVG Technologies CZ, s.r.o.) R0 BMLoad; C:\Windows\System32\drivers\BMLoad.sys [16512 2009-12-15] (Bytemobile, Inc.) [File not signed] S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-05-30] (Qualcomm Atheros) R3 BthLEEnum; C:\Windows\System32\drivers\BthLEEnum.sys [226304 2013-12-04] (Microsoft Corporation) S3 HSPADataCardusbmdm; C:\Windows\system32\DRIVERS\HSPADataCardusbmdm.sys [122752 2011-08-19] (HSPADataCard Incorporated) S3 HSPADataCardusbnmea; C:\Windows\system32\DRIVERS\HSPADataCardusbnmea.sys [122752 2011-08-19] (HSPADataCard Incorporated) S3 HSPADataCardusbser; C:\Windows\system32\DRIVERS\HSPADataCardusbser.sys [122752 2011-08-19] (HSPADataCard Incorporated) R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated) R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated) R1 tcpipBM; C:\WINDOWS\system32\drivers\tcpipBM.sys [39552 2009-12-15] (Bytemobile, Inc.) [File not signed] R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\AVG\AVG PC TuneUp\TuneUpUtilitiesDriver64.sys [14112 2014-11-24] (TuneUp Software) S3 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [114496 2014-09-22] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-16 20:22 - 2015-01-16 20:22 - 00284768 _____ () C:\WINDOWS\Minidump\011615-31093-01.dmp 2015-01-16 20:17 - 2015-01-16 20:17 - 00284768 _____ () C:\WINDOWS\Minidump\011615-31078-01.dmp 2015-01-16 20:11 - 2015-01-16 20:11 - 00284768 _____ () C:\WINDOWS\Minidump\011615-34625-01.dmp 2015-01-16 20:06 - 2015-01-16 20:07 - 02125312 _____ (Farbar) C:\Users\Saturn sw\Downloads\FRST64(1).exe 2015-01-16 20:04 - 2015-01-16 20:04 - 00284768 _____ () C:\WINDOWS\Minidump\011615-29359-01.dmp 2015-01-16 16:06 - 2015-01-16 16:06 - 00284768 _____ () C:\WINDOWS\Minidump\011615-32781-01.dmp 2015-01-16 15:58 - 2015-01-16 15:58 - 00284768 _____ () C:\WINDOWS\Minidump\011615-34953-01.dmp 2015-01-16 15:52 - 2015-01-16 15:52 - 00284768 _____ () C:\WINDOWS\Minidump\011615-33437-01.dmp 2015-01-16 15:47 - 2015-01-16 15:47 - 00284768 _____ () C:\WINDOWS\Minidump\011615-35859-01.dmp 2015-01-16 15:35 - 2015-01-16 15:36 - 00284768 _____ () C:\WINDOWS\Minidump\011615-45640-01.dmp 2015-01-16 15:30 - 2015-01-16 20:22 - 354478114 _____ () C:\WINDOWS\MEMORY.DMP 2015-01-16 15:30 - 2015-01-16 20:22 - 00000000 ____D () C:\WINDOWS\Minidump 2015-01-16 15:30 - 2015-01-16 15:30 - 00284768 _____ () C:\WINDOWS\Minidump\011615-48781-01.dmp 2015-01-16 14:55 - 2015-01-16 14:55 - 02191360 _____ () C:\Users\Saturn sw\Downloads\AdwCleaner_4.107.exe 2015-01-16 12:16 - 2015-01-16 12:16 - 00000000 ____D () C:\Users\Saturn sw\AppData\Roaming\Internet-Manager 2015-01-16 12:12 - 2015-01-16 12:12 - 00002215 _____ () C:\Users\Public\Desktop\congstar Internet-Manager.lnk 2015-01-16 12:12 - 2015-01-16 12:12 - 00000518 _____ () C:\WINDOWS\SysWOW64\bocinstall.ini 2015-01-16 12:12 - 2015-01-16 12:12 - 00000518 _____ () C:\WINDOWS\system32\bocinstall.ini 2015-01-16 12:12 - 2015-01-16 12:12 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\congstar Internet-Manager 2015-01-16 12:12 - 2011-08-19 11:25 - 00122752 _____ (HSPADataCard Incorporated) C:\WINDOWS\system32\Drivers\HSPADataCardusbser.sys 2015-01-16 12:12 - 2011-08-19 11:25 - 00122752 _____ (HSPADataCard Incorporated) C:\WINDOWS\system32\Drivers\HSPADataCardusbnmea.sys 2015-01-16 12:12 - 2011-08-19 11:25 - 00122752 _____ (HSPADataCard Incorporated) C:\WINDOWS\system32\Drivers\HSPADataCardusbmdm.sys 2015-01-16 12:12 - 2011-08-19 11:25 - 00012800 _____ (ZTE Incorporated) C:\WINDOWS\system32\Drivers\massfilter.sys 2015-01-16 12:12 - 2010-02-01 13:29 - 00002960 _____ () C:\WINDOWS\SysWOW64\boc.ini 2015-01-16 12:12 - 2010-02-01 13:29 - 00002960 _____ () C:\WINDOWS\system32\boc.ini 2015-01-16 12:12 - 2009-12-15 03:46 - 00724608 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\bmutil.dll 2015-01-16 12:12 - 2009-12-15 03:46 - 00724608 _____ (Microsoft Corporation) C:\WINDOWS\system32\bmutil.dll 2015-01-16 12:12 - 2009-12-15 03:46 - 00480384 _____ (Bytemobile, Inc.) C:\WINDOWS\SysWOW64\bmnet.dll 2015-01-16 12:12 - 2009-12-15 03:46 - 00480384 _____ (Bytemobile, Inc.) C:\WINDOWS\system32\bmnet.dll 2015-01-16 12:12 - 2009-12-15 03:46 - 00308352 _____ (Bytemobile, Inc.) C:\WINDOWS\SysWOW64\bminstall.dll 2015-01-16 12:12 - 2009-12-15 03:46 - 00308352 _____ (Bytemobile, Inc.) C:\WINDOWS\system32\bminstall.dll 2015-01-16 12:12 - 2009-12-15 03:46 - 00271488 _____ (Bytemobile, Inc.) C:\WINDOWS\SysWOW64\bmapi.dll 2015-01-16 12:12 - 2009-12-15 03:46 - 00271488 _____ (Bytemobile, Inc.) C:\WINDOWS\system32\bmapi.dll 2015-01-16 12:12 - 2009-12-15 03:46 - 00193664 _____ () C:\WINDOWS\SysWOW64\bmsdk.exe 2015-01-16 12:12 - 2009-12-15 03:46 - 00193664 _____ () C:\WINDOWS\system32\bmsdk.exe 2015-01-16 12:12 - 2009-12-15 03:46 - 00132224 _____ (Bytemobile, Inc.) C:\WINDOWS\SysWOW64\bmdumpd.bin 2015-01-16 12:12 - 2009-12-15 03:46 - 00132224 _____ (Bytemobile, Inc.) C:\WINDOWS\system32\bmdumpd.bin 2015-01-16 12:12 - 2009-12-15 03:46 - 00039552 _____ (Bytemobile, Inc.) C:\WINDOWS\system32\Drivers\tcpipBM.sys 2015-01-16 12:12 - 2009-12-15 03:46 - 00016512 _____ (Bytemobile, Inc.) C:\WINDOWS\system32\Drivers\BMLoad.sys 2015-01-16 12:12 - 2009-12-15 03:46 - 00013712 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\sporder.dll 2015-01-16 12:12 - 2009-12-15 03:46 - 00013712 _____ (Microsoft Corporation) C:\WINDOWS\system32\sporder.dll 2015-01-16 12:11 - 2015-01-16 12:12 - 00000000 ____D () C:\WINDOWS\SysWOW64\SupportAppZXH 2015-01-16 12:11 - 2015-01-16 12:11 - 00000000 ____D () C:\Program Files (x86)\congstar 2015-01-14 11:49 - 2015-01-14 11:51 - 00002685 _____ () C:\Users\Public\Desktop\Steuer 2009.lnk 2015-01-14 11:49 - 2015-01-14 11:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steuer 2009 2015-01-14 11:48 - 2015-01-14 11:48 - 00000000 ____D () C:\ProgramData\BTrieve 2015-01-14 11:37 - 2015-01-14 11:37 - 00006982 _____ () C:\Users\Saturn sw\Desktop\Lexware Installations Report.zip 2015-01-14 11:37 - 2015-01-14 11:37 - 00000000 ____D () C:\Users\Saturn sw\AppData\Roaming\Lexware 2015-01-14 11:36 - 2015-01-14 11:40 - 00002685 _____ () C:\Users\Public\Desktop\Steuer 2010.lnk 2015-01-14 11:36 - 2015-01-14 11:40 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steuer 2010 2015-01-14 11:36 - 2015-01-14 11:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lexware 2015-01-14 11:35 - 2015-01-16 12:09 - 00000000 ____D () C:\ProgramData\Lexware 2015-01-14 11:35 - 2015-01-14 11:35 - 00000000 ____D () C:\Program Files (x86)\Lexware 2015-01-14 10:50 - 2015-01-14 11:59 - 00000000 ____D () C:\Users\Saturn sw\AppData\Local\Lexware 2015-01-14 10:00 - 2014-12-19 07:26 - 00140800 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\mrxdav.sys 2015-01-14 10:00 - 2014-12-12 03:04 - 00087040 _____ (Microsoft Corporation) C:\WINDOWS\system32\TSWbPrxy.exe 2015-01-14 10:00 - 2014-12-12 01:51 - 00075776 _____ (Microsoft Corporation) C:\WINDOWS\system32\Drivers\ahcache.sys 2015-01-14 10:00 - 2014-12-09 02:50 - 00225280 _____ (Microsoft Corporation) C:\WINDOWS\system32\profsvc.dll 2015-01-14 10:00 - 2014-12-08 20:42 - 00535640 _____ (Microsoft Corporation) C:\WINDOWS\system32\wer.dll 2015-01-14 10:00 - 2014-12-08 20:42 - 00531616 _____ (Microsoft Corporation) C:\WINDOWS\system32\ci.dll 2015-01-14 10:00 - 2014-12-08 20:42 - 00448792 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wer.dll 2015-01-14 10:00 - 2014-12-08 20:42 - 00413248 _____ (Microsoft Corporation) C:\WINDOWS\system32\Faultrep.dll 2015-01-14 10:00 - 2014-12-08 20:42 - 00372408 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\Faultrep.dll 2015-01-14 10:00 - 2014-12-08 20:42 - 00108944 _____ (Microsoft Corporation) C:\WINDOWS\system32\EncDump.dll 2015-01-14 10:00 - 2014-12-08 20:42 - 00038264 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFaultSecure.exe 2015-01-14 10:00 - 2014-12-08 20:42 - 00033584 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFaultSecure.exe 2015-01-14 10:00 - 2014-12-06 04:17 - 00360448 _____ (Microsoft Corporation) C:\WINDOWS\system32\ncsi.dll 2015-01-14 10:00 - 2014-12-06 02:41 - 00391680 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlasvc.dll 2015-01-14 10:00 - 2014-12-06 02:35 - 00229888 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEndpointBuilder.dll 2015-01-14 10:00 - 2014-10-29 05:00 - 00465320 _____ (Microsoft Corporation) C:\WINDOWS\system32\WerFault.exe 2015-01-14 10:00 - 2014-10-29 05:00 - 00139984 _____ (Microsoft Corporation) C:\WINDOWS\system32\wermgr.exe 2015-01-14 10:00 - 2014-10-29 04:52 - 00500016 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioSes.dll 2015-01-14 10:00 - 2014-10-29 04:52 - 00482872 _____ (Microsoft Corporation) C:\WINDOWS\system32\AudioEng.dll 2015-01-14 10:00 - 2014-10-29 04:52 - 00394120 _____ (Microsoft Corporation) C:\WINDOWS\system32\AUDIOKSE.dll 2015-01-14 10:00 - 2014-10-29 04:52 - 00272248 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiodg.exe 2015-01-14 10:00 - 2014-10-29 04:12 - 00413136 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\WerFault.exe 2015-01-14 10:00 - 2014-10-29 04:12 - 00136296 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\wermgr.exe 2015-01-14 10:00 - 2014-10-29 04:07 - 00424544 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioEng.dll 2015-01-14 10:00 - 2014-10-29 04:07 - 00370424 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AudioSes.dll 2015-01-14 10:00 - 2014-10-29 04:07 - 00344536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\AUDIOKSE.dll 2015-01-14 10:00 - 2014-10-29 03:44 - 00037888 _____ (Microsoft Corporation) C:\WINDOWS\system32\werdiagcontroller.dll 2015-01-14 10:00 - 2014-10-29 02:59 - 00033280 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\werdiagcontroller.dll 2015-01-14 10:00 - 2014-10-29 02:24 - 00086016 _____ (Microsoft Corporation) C:\WINDOWS\system32\nlaapi.dll 2015-01-14 10:00 - 2014-10-29 02:02 - 00911360 _____ (Microsoft Corporation) C:\WINDOWS\system32\audiosrv.dll 2015-01-14 10:00 - 2014-10-29 02:01 - 00065536 _____ (Microsoft Corporation) C:\WINDOWS\SysWOW64\nlaapi.dll 2015-01-13 14:29 - 2015-01-13 14:29 - 00000590 _____ () C:\Users\Public\Desktop\Steuer 2014.lnk 2015-01-13 10:33 - 2015-01-13 10:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steuer 2014 2015-01-13 10:21 - 2015-01-13 10:21 - 00000000 ____D () C:\ProgramData\Package Cache 2015-01-02 19:48 - 2015-01-02 19:48 - 00157035 _____ () C:\Users\Saturn sw\Downloads\system (1).odt 2015-01-02 17:11 - 2015-01-02 17:11 - 00157035 _____ () C:\Users\Saturn sw\Downloads\system.odt 2015-01-02 16:35 - 2015-01-02 16:35 - 00063605 _____ () C:\Users\Saturn sw\Downloads\getmykeysback2 (1).zip 2015-01-01 00:51 - 2015-01-01 00:51 - 00000000 ____H () C:\WINDOWS\system32\Drivers\Msft_User_WpdMtpDr_01_11_00.Wdf 2014-12-31 22:12 - 2014-12-31 22:12 - 00003886 _____ () C:\WINDOWS\System32\Tasks\Adobe Acrobat Update Task 2014-12-28 19:00 - 2015-01-17 11:47 - 00011833 _____ () C:\WINDOWS\setupact.log 2014-12-28 19:00 - 2014-12-28 19:00 - 00000000 _____ () C:\WINDOWS\setuperr.log 2014-12-24 09:04 - 2014-12-24 09:04 - 00244264 _____ () C:\Users\Saturn sw\Downloads\Firefox Setup Stub 34.0.5.exe 2014-12-23 11:29 - 2014-12-23 11:29 - 00062464 ___SH () C:\Users\Saturn sw\Desktop\Thumbs.db 2014-12-20 16:00 - 2014-12-20 16:00 - 00002762 _____ () C:\WINDOWS\System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013 ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-17 11:48 - 2013-12-21 19:42 - 00017097 _____ () C:\Users\Saturn sw\Downloads\FRST.txt 2015-01-17 11:48 - 2013-12-21 19:42 - 00000000 ____D () C:\FRST 2015-01-17 11:48 - 2013-11-10 11:36 - 00001128 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-17 11:47 - 2013-12-21 20:48 - 00000000 __RDO () C:\Users\Saturn sw\SkyDrive 2015-01-17 11:47 - 2013-08-22 15:45 - 00000006 ____H () C:\WINDOWS\Tasks\SA.DAT 2015-01-16 20:08 - 2013-11-13 16:30 - 00000000 ____D () C:\ProgramData\MFAData 2015-01-16 20:08 - 2013-11-10 18:14 - 00000884 _____ () C:\WINDOWS\Tasks\Adobe Flash Player Updater.job 2015-01-16 20:07 - 2013-11-19 22:59 - 01078380 _____ () C:\WINDOWS\WindowsUpdate.log 2015-01-16 20:00 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\sru 2015-01-16 15:30 - 2013-11-19 22:40 - 00000000 ____D () C:\Users\Saturn sw 2015-01-16 15:24 - 2013-08-22 15:44 - 00510528 _____ () C:\WINDOWS\system32\FNTCACHE.DAT 2015-01-16 15:23 - 2013-09-29 20:04 - 00175398 _____ () C:\WINDOWS\PFRO.log 2015-01-16 15:22 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\BBI 2015-01-16 15:20 - 2013-12-21 22:10 - 00000000 ____D () C:\AdwCleaner 2015-01-16 14:22 - 2013-11-10 11:36 - 00001132 _____ () C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-16 13:56 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\AppReadiness 2015-01-16 13:12 - 2013-08-22 14:25 - 00262144 ___SH () C:\WINDOWS\system32\config\ELAM 2015-01-16 12:18 - 2013-09-30 05:14 - 01776918 _____ () C:\WINDOWS\system32\PerfStringBackup.INI 2015-01-16 12:18 - 2013-09-30 04:56 - 00765582 _____ () C:\WINDOWS\system32\perfh007.dat 2015-01-16 12:18 - 2013-09-30 04:56 - 00159366 _____ () C:\WINDOWS\system32\perfc007.dat 2015-01-16 12:17 - 2013-11-24 11:33 - 00003938 _____ () C:\WINDOWS\System32\Tasks\User_Feed_Synchronization-{CCC06904-AB93-48BA-B487-38F608E81796} 2015-01-16 12:16 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\tracing 2015-01-16 12:14 - 2013-10-31 15:04 - 00003594 _____ () C:\WINDOWS\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3878855970-111228901-362715822-1001 2015-01-16 12:11 - 2013-06-04 05:35 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-01-16 12:11 - 2012-07-26 08:59 - 00000000 ____D () C:\WINDOWS\CbsTemp 2015-01-14 12:11 - 2013-12-30 10:51 - 00000000 ____D () C:\ProgramData\Buhl Data Service GmbH 2015-01-14 11:26 - 2013-12-30 11:05 - 00000963 _____ () C:\WINDOWS\wiso.ini 2015-01-14 10:56 - 2013-12-30 11:05 - 00000000 ____D () C:\Users\Saturn sw\AppData\Local\Buhl 2015-01-14 10:08 - 2013-11-10 18:14 - 00003772 _____ () C:\WINDOWS\System32\Tasks\Adobe Flash Player Updater 2015-01-13 14:42 - 2014-06-24 14:05 - 00000000 ____D () C:\Users\Saturn sw\Documents\Steuer 2015-01-13 08:53 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\system32\FxsTmp 2015-01-08 17:01 - 2014-04-03 18:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG 2015-01-08 17:01 - 2013-11-13 16:32 - 00000961 _____ () C:\Users\Public\Desktop\AVG 2014.lnk 2015-01-06 01:08 - 2014-09-19 14:54 - 00714720 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerApp.exe 2015-01-06 01:08 - 2014-09-19 14:54 - 00106976 _____ (Adobe Systems Incorporated) C:\WINDOWS\SysWOW64\FlashPlayerCPLApp.cpl 2015-01-02 19:53 - 2013-12-29 12:44 - 00031232 ___SH () C:\Users\Saturn sw\Downloads\Thumbs.db 2014-12-31 21:56 - 2013-11-10 18:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-12-31 21:47 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\registration 2014-12-24 11:47 - 2013-11-18 21:56 - 00000000 ____D () C:\Users\Saturn sw\AppData\Local\Adobe 2014-12-24 09:05 - 2014-07-10 06:44 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-12-24 09:05 - 2013-11-10 18:12 - 00001135 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk 2014-12-24 09:05 - 2013-11-10 18:12 - 00001123 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk 2014-12-23 11:37 - 2013-12-29 17:37 - 00000000 ____D () C:\Users\Saturn sw\AppData\Local\Deployment 2014-12-20 16:41 - 2013-08-22 16:36 - 00000000 ____D () C:\WINDOWS\rescache Files to move or delete: ==================== C:\Users\Public\AlexaNSISPlugin.6920.dll Some content of TEMP: ==================== C:\Users\Saturn sw\AppData\Local\Temp\Quarantine.exe C:\Users\Saturn sw\AppData\Local\Temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-03 13:48 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- reicht das protokoll um schon einen ansatz zu finden? Geändert von wunderlicher (17.01.2015 um 17:01 Uhr) Grund: nachtrag |
17.01.2015, 23:40 | #6 |
/// the machine /// TB-Ausbilder | Super-Gau nach phising mail Nö soweit seh ich nix. Bei der Phishing Seite kommt ja auch keine Malware auf den Rechner. FRST öffnen, Haken setzen bei Addition und scannen, Addition.txt posten.
__________________ --> Super-Gau nach phising mail |
19.01.2015, 16:49 | #7 |
| nichts geht mehr So, der pc ist zur Reparatur. Erste Diagnose ???? Kann alles sein. Nichts geht mehr, auch eine Systemwiederherstellung ist nicht möglich, da Dateien nicht erkannt werden obwohl sie auf dem Datendräger vorhanden sind. Zur Option steht nun ein Hardwaredefekt/Festplatte oder einen fiesen Schädling eingefangen, oder kann der awg cleaner ( von file pony) den Defekt verursacht haben? |
19.01.2015, 19:51 | #8 |
/// the machine /// TB-Ausbilder | Super-Gau nach phising mail Nee kann er eigentlich nicht. Da ich aber keinerlei Logs gesehen hab kann ich gar nix sagen.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Super-Gau nach phising mail |
automatisch, avg, bedrohung, brauch, cleaner, daten, deaktiviert, durchgeführt, fake, freund, gesperrt, hilfe!, konten, lange, link, mail, meldung, neustart, persönliche, phising mail, scan, schädling, sicherheit, strg, website, win |