Hallo, ein Bekannter hat sich leider das BKA Virus unter Windows 7 eingefangen. Leider besitzt der Rechner kein CD-Rom-Laufwerk. Ein Versuch, den Rechner via USB-Stick mit OTLPESTD zu starten, schlug auch fehl. obwohl wir im Bios die Startreihenfolge geändert haben, starterte immer das infizierte Windows 7 mit dem BKA Virus. Was können wir tun?
hi,
__________________Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8) Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
Danke, ich habe FRST heruntergeladen. Der PC hat wohl ein UEFI Bios. Hatte ich so noch nie gesehen. Leider gelang ich zunächst nicht in den Systemwiederherstellungsmodus, der PC bootete immer den BKA Trojaner hoch.
Schließlich konnte ich jedoch in ein englischsprachiges Wiederherstellungsmenü gelangen, wie weiß ich auch nicht. Dort gab es aber keinen Eintrag Computer reparieren, aber ich kam in den abgesicherten Modus. Dort suchte ich dann nach neueren exe-Dateien und habe eine Datei gefunden, die mir seltsam vorkam: ARPPRODUCTICON.exe. Diese habe ich umbenannt in ARPPRODUCTICON.oldexe. Treffer, denn dann habe ich den PC neu gestartet und der BKA Virus tauchte nicht mehr auf! Ich habe dann mittels FRST das System gescannt. Denn ich denke, wir sind noch nicht fertig, weil die latente Gefahr ist ja noch da, oder?
Wenn der Rechner doch nit gesperrt ist und du FRST aus dem normalen Modus laufen lassen kannst, dann bitte noch die Addition.txt posten
Ok, hier die Addition.txt
hi, Scan mit Combofix
Hallo, hier nur die Log-Datei aus Combofix.
Downloade Dir bitte
Downloade Dir bitte
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. Noch Probleme?
Ok, dann wollen wir mal. Hier die gewünschten Anhänge:
(Microsoft Corporation) C:\Windows\System32\psxss.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (phion AG) C:\Program Files\netfenceVPN\phions.exe () C:\Program Files\netfenceVPN\Opswat\CAntiVirusCOM.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (phion AG) C:\Program Files\netfenceVPN\phion.exe () C:\Program Files\ASUS\AXSP\1.01.02\atkexComSvc.exe (Microsoft Corporation) C:\Windows\System32\CISVC.EXE (Intel Corporation) C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe (Microsoft Corporation) C:\Windows\System32\DialogFilter.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe (Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE (Microsoft Corporation) C:\Windows\System32\snmp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Windows\System32\mqtgsvc.exe (Microsoft Corporation) C:\Windows\System32\nfsclnt.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\tv_w32.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [phion] => C:\Program Files\netfenceVPN\phion.exe [2712920 2010-03-10] (phion AG) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [USB3MON] => c:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation) HKLM\...\Run: [RTHDVCPL] => c:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe [6336216 2013-08-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] => c:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [978648 2013-08-07] (Realtek Semiconductor) HKLM\...\Run: [MsmqIntCert] => regsvr32 /s mqrt.dll HKLM\...\Policies\Explorer: [] HKLM\...\Policies\Explorer: [NoStartMenuMyGames] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\system: [DisableChangePassword] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarNoDragToolbar] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [NoUserNameInStartMenu] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [NoStartMenuSubFolders] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarNoRedock] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarNoResize] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarNoAddRemoveToolbar] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [HideSCAVolume] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarLockAll] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [LockTaskbar] 1 ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.web.de/ SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} hxxp://download.microsoft.com/download/C/9/C/C9C3D86D-84AC-4AF0-8584-842756A66467/MicrosoftDownloadManager.cab Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> c:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater -> c:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 asComSvc; C:\Program Files\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-05-07] () R2 DialogFilter; C:\Windows\System32\DialogFilterSvc.dll [27496 2010-04-02] (Microsoft Corporation) R2 DTSAudioSvc; c:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe [193480 2012-10-02] (DTS, Inc) R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [310272 2012-06-01] (Microsoft Corporation) R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [13824 2009-07-14] (Microsoft Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [586240 2013-05-11] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [637912 2013-05-11] (Intel(R) Corporation) R2 Intel(R) PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [132768 2011-11-09] (Intel Corporation) U2 iprip; C:\Windows\System32\iprip.dll [29696 2009-07-14] (Microsoft Corporation) R2 jhi_service; c:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation) R2 KeyboardFilter; C:\Windows\System32\KeyboardFilterSvc.dll [37736 2011-09-16] (Microsoft Corporation) R2 MBAMScheduler; c:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; c:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 MSMQ; C:\Windows\system32\mqsvc.exe [8704 2009-07-14] (Microsoft Corporation) R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [126464 2010-11-20] (Microsoft Corporation) R2 NfsClnt; C:\Windows\system32\nfsclnt.exe [52736 2010-11-20] (Microsoft Corporation) R2 phions; C:\Program Files\netfenceVPN\phions.exe [4498776 2010-03-10] (phion AG) S4 POSPerformanceCounters; C:\Program Files\Microsoft Point Of Service\Microsoft.PointOfService.Service.exe [42056 2008-02-29] (Microsoft Corporation) R2 WinDefend; c:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) S2 AdobeARMservice; "C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [14720 2012-08-22] () S3 asmthub3; C:\Windows\System32\DRIVERS\asmthub3.sys [102888 2011-11-03] (ASMedia Technology Inc) S3 asmtxhci; C:\Windows\System32\DRIVERS\asmtxhci.sys [313832 2011-11-03] (ASMedia Technology Inc) S3 e1kexpress; C:\Windows\System32\DRIVERS\e1k6032.sys [164864 2009-07-14] (Intel Corporation) S3 e1qexpress; C:\Windows\System32\DRIVERS\e1q6232.sys [279208 2011-10-13] (Intel Corporation) R0 iaStorA; C:\Windows\System32\DRIVERS\iaStorA.sys [505192 2013-08-07] (Intel Corporation) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [25448 2013-08-07] (Intel Corporation) R0 iusb3hcs; C:\Windows\System32\DRIVERS\iusb3hcs.sys [16880 2013-04-26] (Intel Corporation) R3 iusb3hub; C:\Windows\System32\DRIVERS\iusb3hub.sys [361968 2013-04-26] (Intel Corporation) R3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [793072 2013-04-26] (Intel Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation) S3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-01-30] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation) R3 MEI; C:\Windows\System32\DRIVERS\TeeDriver.sys [85464 2013-09-03] (Intel Corporation) R3 mf; C:\Windows\System32\DRIVERS\mf.sys [114176 2009-07-14] (Microsoft Corporation) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [141824 2010-11-20] (Microsoft Corporation) S3 NmPar; C:\Windows\System32\DRIVERS\NmPar.sys [80896 2012-09-17] () R3 nmserial; C:\Windows\System32\DRIVERS\nmserial.sys [70656 2012-09-17] (Windows (R) Win 7 DDK provider) S3 phionvpn; C:\Windows\System32\DRIVERS\phionvpn.sys [31728 2009-11-23] (Phion AG) R3 Ramdisk; C:\Windows\System32\DRIVERS\ramdisk.sys [22016 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\****\AppData\Local\Temp\catchme.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) NETSVC: DialogFilter -> C:\Windows\System32\DialogFilterSvc.dll (Microsoft Corporation) NETSVC: KeyboardFilter -> C:\Windows\System32\KeyboardFilterSvc.dll (Microsoft Corporation) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-30 19:11 - 2015-01-30 19:11 - 00012007 _____ () C:\Users\****\Desktop\FRST.txt 2015-01-30 19:11 - 2015-01-28 20:18 - 01121792 _____ (Farbar) C:\Users\****\Desktop\FRST.exe 2015-01-30 19:09 - 2015-01-30 19:09 - 00000631 _____ () C:\Users\****\Desktop\JRT.txt 2015-01-30 19:06 - 2015-01-30 19:06 - 00000000 ____D () C:\Windows\ERUNT 2015-01-30 19:05 - 2015-01-30 18:20 - 01707939 _____ (Thisisu) C:\Users\****\Desktop\JRT.exe 2015-01-30 18:58 - 2015-01-30 19:02 - 00000000 ____D () C:\AdwCleaner 2015-01-30 18:58 - 2015-01-30 18:23 - 02194432 _____ () C:\Users\****\Desktop\AdwCleaner_4.109.exe 2015-01-30 00:01 - 2015-01-30 00:01 - 00014651 _____ () C:\ComboFix.txt 2015-01-30 00:00 - 2015-01-30 19:02 - 00000850 _____ () C:\Windows\PFRO.log 2015-01-29 23:54 - 2015-01-30 00:01 - 00000000 ____D () C:\Qoobox 2015-01-29 23:54 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-01-29 23:54 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-01-29 23:54 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-01-29 23:54 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-01-29 23:54 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-01-29 23:54 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2015-01-29 23:54 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2015-01-29 23:54 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2015-01-29 23:51 - 2015-01-30 00:00 - 00000000 ____D () C:\Windows\erdnt 2015-01-29 23:48 - 2015-01-29 23:44 - 05611408 ____R (Swearware) C:\Users\****\Desktop\ComboFix.exe 2015-01-29 23:38 - 2015-01-30 19:07 - 00029365 _____ () C:\Windows\WindowsUpdate.log 2015-01-29 23:36 - 2015-01-30 19:02 - 00001130 _____ () C:\Windows\setupact.log 2015-01-29 23:36 - 2015-01-29 23:36 - 00000000 _____ () C:\Windows\setuperr.log 2015-01-29 23:29 - 2015-01-29 23:29 - 00000000 ____D () C:\Windows\pss 2015-01-28 22:26 - 2015-01-30 18:44 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-28 22:26 - 2015-01-29 23:19 - 00000000 ____D () c:\Program Files\ Malwarebytes Anti-Malware 2015-01-28 22:26 - 2015-01-28 22:26 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-28 22:26 - 2015-01-28 22:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-28 22:26 - 2015-01-28 22:26 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-28 22:26 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-28 22:26 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-28 22:26 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-28 22:25 - 2015-01-28 22:23 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\****\Downloads\mbam-setup- 2015-01-28 20:50 - 2015-01-30 19:11 - 00000000 ____D () C:\FRST 2015-01-28 20:38 - 2015-01-28 20:38 - 00000969 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2015-01-28 20:38 - 2015-01-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2015-01-28 20:38 - 2015-01-28 20:38 - 00000000 ____D () c:\Program Files\CCleaner 2015-01-28 20:38 - 2013-03-23 10:47 - 04190272 _____ (Piriform Ltd) C:\Users\****\Downloads\ccsetup328.exe 2015-01-18 09:40 - 2014-12-19 03:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-18 09:40 - 2014-12-19 02:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-18 09:40 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-01-18 09:40 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-18 09:40 - 2014-12-11 18:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-18 09:40 - 2014-12-06 04:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-18 09:40 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2015-01-18 09:40 - 2012-10-03 17:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-30 19:11 - 2010-12-10 19:06 - 00018352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-30 19:11 - 2010-12-10 19:06 - 00018352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-30 19:09 - 2010-12-10 19:13 - 01715020 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-01-30 19:04 - 2010-04-02 07:08 - 00000000 ____D () C:\Windows\system32\inetsrv 2015-01-30 19:02 - 2013-12-28 17:06 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-01-30 19:02 - 2011-09-16 03:16 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-30 00:01 - 2010-04-02 07:08 - 00000000 __RHD () C:\Users\Default 2015-01-30 00:01 - 2010-04-02 07:08 - 00000000 ___RD () C:\Users\Public 2015-01-30 00:00 - 2010-04-02 06:55 - 00000215 _____ () C:\Windows\system.ini 2015-01-30 00:00 - 2010-04-02 06:54 - 44826624 _____ () C:\Windows\system32\config\SYSTEM.bak 2015-01-30 00:00 - 2010-04-02 06:54 - 39845888 _____ () C:\Windows\system32\config\SOFTWARE.bak 2015-01-30 00:00 - 2010-04-02 06:54 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2015-01-30 00:00 - 2010-04-02 06:54 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2015-01-30 00:00 - 2010-04-02 06:54 - 00262144 _____ () C:\Windows\system32\config\DEFAULT.bak 2015-01-28 20:39 - 2013-12-29 08:42 - 00000000 ____D () C:\Windows\Panther 2015-01-27 20:37 - 2011-09-16 03:16 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-24 12:04 - 2014-07-31 08:44 - 00000600 _____ () C:\Users\****\AppData\Local\PUTTY.RND 2015-01-08 09:55 - 2013-12-28 17:30 - 00249488 _____ (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Files in the root of some directories ======= 2014-07-31 08:44 - 2015-01-24 12:04 - 0000600 _____ () C:\Users\****\AppData\Local\PUTTY.RND 2014-07-29 20:12 - 2014-07-29 20:12 - 0000017 _____ () C:\Users\****\AppData\Local\resmon.resmoncfg 2008-02-05 13:28 - 2008-02-05 13:28 - 0000051 _____ () C:\Users\****\AppData\Local\setup.txt 2014-02-26 16:35 - 2014-02-26 16:35 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some content of TEMP: ==================== C:\Users\****\AppData\Local\temp\Quarantine.exe C:\Users\****\AppData\Local\temp\sqlite3.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-28 22:55 ==================== End Of Log ============================ --- --- --- |
nur noch Kontrollscans: ESET Online Scanner
Downloade Dir bitte
und ein frisches FRST log bitte. Noch Probleme?
Hi, hier die Dateien. Probleme tauchen nicht mehr auf. Ich sehe aber gerade, dass gar kein Anti-Virus-Programm installiert ist. Gibt es da von dir evtl eine Empfehlung?
(Microsoft Corporation) C:\Windows\System32\psxss.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (phion AG) C:\Program Files\netfenceVPN\phions.exe () C:\Program Files\netfenceVPN\Opswat\CAntiVirusCOM.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe () C:\Program Files\ASUS\AXSP\1.01.02\atkexComSvc.exe (phion AG) C:\Program Files\netfenceVPN\phion.exe (Microsoft Corporation) C:\Windows\System32\CISVC.EXE (DTS, Inc) C:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe (Microsoft Corporation) C:\Windows\System32\DialogFilter.exe (Microsoft Corporation) C:\Windows\System32\inetsrv\inetinfo.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe (Microsoft Corporation) C:\Windows\System32\mqsvc.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Microsoft Corporation) C:\Windows\System32\TCPSVCS.EXE (Microsoft Corporation) C:\Windows\System32\snmp.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer_Service.exe (Microsoft Corporation) C:\Windows\System32\mqtgsvc.exe (Microsoft Corporation) C:\Windows\System32\nfsclnt.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\SMSvcHost.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\TeamViewer.exe (TeamViewer GmbH) C:\Program Files\TeamViewer\Version9\tv_w32.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Malwarebytes Corporation) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [phion] => C:\Program Files\netfenceVPN\phion.exe [2712920 2010-03-10] (phion AG) HKLM\...\Run: [IAStorIcon] => C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [287592 2013-08-07] (Intel Corporation) HKLM\...\Run: [USB3MON] => c:\Program Files\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [292848 2013-04-26] (Intel Corporation) HKLM\...\Run: [RTHDVCPL] => c:\Program Files\Realtek\Audio\HDA\RtkNGUI.exe [6336216 2013-08-19] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_DTS] => c:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe [978648 2013-08-07] (Realtek Semiconductor) HKLM\...\Run: [MsmqIntCert] => regsvr32 /s mqrt.dll HKLM\...\Policies\Explorer: [] HKLM\...\Policies\Explorer: [NoStartMenuMyGames] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\system: [DisableChangePassword] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarNoDragToolbar] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [NoUserNameInStartMenu] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [NoStartMenuSubFolders] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarNoRedock] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarNoResize] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarNoAddRemoveToolbar] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [HideSCAVolume] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarLockAll] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [LockTaskbar] 1 ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.web.de/ SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = DPF: {B479199A-1242-4E3C-AD81-7F0DF801B4AE} hxxp://download.microsoft.com/download/C/9/C/C9C3D86D-84AC-4AF0-8584-842756A66467/MicrosoftDownloadManager.cab Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF Plugin: @intel-webapi.intel.com/Intel WebAPI ipt;version=4.0.5 -> c:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin: @intel-webapi.intel.com/Intel WebAPI updater -> c:\Program Files\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 asComSvc; C:\Program Files\ASUS\AXSP\1.01.02\atkexComSvc.exe [936728 2013-05-07] () R2 DialogFilter; C:\Windows\System32\DialogFilterSvc.dll [27496 2010-04-02] (Microsoft Corporation) R2 DTSAudioSvc; c:\Program Files\Realtek\Audio\HDA\DTSU2PAuSrv32.exe [193480 2012-10-02] (DTS, Inc) R2 ftpsvc; C:\Windows\system32\inetsrv\ftpsvc.dll [310272 2012-06-01] (Microsoft Corporation) R2 IISADMIN; C:\Windows\system32\inetsrv\inetinfo.exe [13824 2009-07-14] (Microsoft Corporation) R2 Intel(R) Capability Licensing Service Interface; C:\Program Files\Intel\iCLS Client\HeciServer.exe [586240 2013-05-11] (Intel(R) Corporation) [File not signed] S3 Intel(R) Capability Licensing Service TCP IP Interface; C:\Program Files\Intel\iCLS Client\SocketHeciServer.exe [637912 2013-05-11] (Intel(R) Corporation) R2 Intel(R) PROSet Monitoring Service; C:\Windows\system32\IProsetMonitor.exe [132768 2011-11-09] (Intel Corporation) U2 iprip; C:\Windows\System32\iprip.dll [29696 2009-07-14] (Microsoft Corporation) R2 jhi_service; c:\Program Files\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [169432 2013-09-03] (Intel Corporation) R2 KeyboardFilter; C:\Windows\System32\KeyboardFilterSvc.dll [37736 2011-09-16] (Microsoft Corporation) R2 MBAMScheduler; c:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-11-21] (Malwarebytes Corporation) R2 MBAMService; c:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [969016 2014-11-21] (Malwarebytes Corporation) R2 MSMQ; C:\Windows\system32\mqsvc.exe [8704 2009-07-14] (Microsoft Corporation) R2 MSMQTriggers; C:\Windows\system32\mqtgsvc.exe [126464 2010-11-20] (Microsoft Corporation) R2 NfsClnt; C:\Windows\system32\nfsclnt.exe [52736 2010-11-20] (Microsoft Corporation) R2 phions; C:\Program Files\netfenceVPN\phions.exe [4498776 2010-03-10] (phion AG) S4 POSPerformanceCounters; C:\Program Files\Microsoft Point Of Service\Microsoft.PointOfService.Service.exe [42056 2008-02-29] (Microsoft Corporation) R2 WinDefend; c:\Program Files\Windows Defender\mpsvc.dll [680960 2013-05-27] (Microsoft Corporation) S2 AdobeARMservice; "C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R1 AsIO; C:\Windows\System32\drivers\AsIO.sys [14720 2012-08-22] () S3 asmthub3; C:\Windows\System32\DRIVERS\asmthub3.sys [102888 2011-11-03] (ASMedia Technology Inc) S3 asmtxhci; C:\Windows\System32\DRIVERS\asmtxhci.sys [313832 2011-11-03] (ASMedia Technology Inc) S3 e1kexpress; C:\Windows\System32\DRIVERS\e1k6032.sys [164864 2009-07-14] (Intel Corporation) S3 e1qexpress; C:\Windows\System32\DRIVERS\e1q6232.sys [279208 2011-10-13] (Intel Corporation) R0 iaStorA; C:\Windows\System32\DRIVERS\iaStorA.sys [505192 2013-08-07] (Intel Corporation) R0 iaStorF; C:\Windows\System32\DRIVERS\iaStorF.sys [25448 2013-08-07] (Intel Corporation) R0 iusb3hcs; C:\Windows\System32\DRIVERS\iusb3hcs.sys [16880 2013-04-26] (Intel Corporation) R3 iusb3hub; C:\Windows\System32\DRIVERS\iusb3hub.sys [361968 2013-04-26] (Intel Corporation) R3 iusb3xhc; C:\Windows\System32\DRIVERS\iusb3xhc.sys [793072 2013-04-26] (Intel Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-11-21] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [114904 2015-02-02] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-11-21] (Malwarebytes Corporation) R3 MEI; C:\Windows\System32\DRIVERS\TeeDriver.sys [85464 2013-09-03] (Intel Corporation) R3 mf; C:\Windows\System32\DRIVERS\mf.sys [114176 2009-07-14] (Microsoft Corporation) R3 MQAC; C:\Windows\System32\drivers\mqac.sys [141824 2010-11-20] (Microsoft Corporation) S3 NmPar; C:\Windows\System32\DRIVERS\NmPar.sys [80896 2012-09-17] () R3 nmserial; C:\Windows\System32\DRIVERS\nmserial.sys [70656 2012-09-17] (Windows (R) Win 7 DDK provider) S3 phionvpn; C:\Windows\System32\DRIVERS\phionvpn.sys [31728 2009-11-23] (Phion AG) R3 Ramdisk; C:\Windows\System32\DRIVERS\ramdisk.sys [22016 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\****\AppData\Local\Temp\catchme.sys [X] S3 VGPU; System32\drivers\rdvgkmd.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) NETSVC: DialogFilter -> C:\Windows\System32\DialogFilterSvc.dll (Microsoft Corporation) NETSVC: KeyboardFilter -> C:\Windows\System32\KeyboardFilterSvc.dll (Microsoft Corporation) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-02 22:47 - 2015-02-02 22:47 - 00012121 _____ () C:\Users\****\Desktop\FRST.txt 2015-02-02 22:47 - 2015-02-02 22:47 - 00000000 ____D () C:\Users\****\Desktop\FRST-OlderVersion 2015-02-02 19:47 - 2015-01-30 19:55 - 00852573 _____ () C:\Users\****\Desktop\SecurityCheck.exe 2015-02-02 19:47 - 2015-01-30 19:53 - 02347384 _____ (ESET) C:\Users\****\Desktop\esetsmartinstaller_deu.exe 2015-01-30 19:11 - 2015-02-02 22:47 - 01122304 _____ (Farbar) C:\Users\****\Desktop\FRST.exe 2015-01-30 19:06 - 2015-01-30 19:06 - 00000000 ____D () C:\Windows\ERUNT 2015-01-30 19:05 - 2015-01-30 18:20 - 01707939 _____ (Thisisu) C:\Users\****\Desktop\JRT.exe 2015-01-30 18:58 - 2015-01-30 19:02 - 00000000 ____D () C:\AdwCleaner 2015-01-30 18:58 - 2015-01-30 18:23 - 02194432 _____ () C:\Users\****\Desktop\AdwCleaner_4.109.exe 2015-01-30 00:01 - 2015-01-30 00:01 - 00014651 _____ () C:\ComboFix.txt 2015-01-30 00:00 - 2015-01-30 19:02 - 00000850 _____ () C:\Windows\PFRO.log 2015-01-29 23:54 - 2015-01-30 00:01 - 00000000 ____D () C:\Qoobox 2015-01-29 23:54 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2015-01-29 23:54 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2015-01-29 23:54 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2015-01-29 23:54 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2015-01-29 23:54 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2015-01-29 23:54 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2015-01-29 23:54 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2015-01-29 23:54 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2015-01-29 23:51 - 2015-01-30 00:00 - 00000000 ____D () C:\Windows\erdnt 2015-01-29 23:48 - 2015-01-29 23:44 - 05611408 ____R (Swearware) C:\Users\****\Desktop\ComboFix.exe 2015-01-29 23:38 - 2015-02-02 22:12 - 00063008 _____ () C:\Windows\WindowsUpdate.log 2015-01-29 23:36 - 2015-02-02 22:04 - 00001298 _____ () C:\Windows\setupact.log 2015-01-29 23:36 - 2015-01-29 23:36 - 00000000 _____ () C:\Windows\setuperr.log 2015-01-29 23:29 - 2015-01-29 23:29 - 00000000 ____D () C:\Windows\pss 2015-01-28 22:26 - 2015-02-02 22:41 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-01-28 22:26 - 2015-01-29 23:19 - 00000000 ____D () c:\Program Files\ Malwarebytes Anti-Malware 2015-01-28 22:26 - 2015-01-28 22:26 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-01-28 22:26 - 2015-01-28 22:26 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-01-28 22:26 - 2015-01-28 22:26 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-01-28 22:26 - 2014-11-21 06:14 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-01-28 22:26 - 2014-11-21 06:14 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-01-28 22:26 - 2014-11-21 06:14 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2015-01-28 22:25 - 2015-01-28 22:23 - 20447072 _____ (Malwarebytes Corporation ) C:\Users\****\Downloads\mbam-setup- 2015-01-28 20:50 - 2015-02-02 22:47 - 00000000 ____D () C:\FRST 2015-01-28 20:38 - 2015-01-28 20:38 - 00000969 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2015-01-28 20:38 - 2015-01-28 20:38 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner 2015-01-28 20:38 - 2015-01-28 20:38 - 00000000 ____D () c:\Program Files\CCleaner 2015-01-28 20:38 - 2013-03-23 10:47 - 04190272 _____ (Piriform Ltd) C:\Users\****\Downloads\ccsetup328.exe 2015-01-18 09:40 - 2014-12-19 03:43 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2015-01-18 09:40 - 2014-12-19 02:34 - 00116224 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-18 09:40 - 2014-12-12 06:11 - 03971512 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-01-18 09:40 - 2014-12-12 06:11 - 03916728 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-01-18 09:40 - 2014-12-11 18:47 - 00046592 _____ (Microsoft Corporation) C:\Windows\system32\TSWbPrxy.exe 2015-01-18 09:40 - 2014-12-06 04:50 - 00242688 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-18 09:40 - 2012-10-03 17:42 - 00156672 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2015-01-18 09:40 - 2012-10-03 17:42 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-02 22:16 - 2010-12-10 19:06 - 00018352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-02 22:16 - 2010-12-10 19:06 - 00018352 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-02 22:11 - 2010-12-10 19:13 - 01715020 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-02 22:06 - 2010-04-02 07:08 - 00000000 ____D () C:\Windows\system32\inetsrv 2015-02-02 22:04 - 2013-12-28 17:06 - 00000000 ____D () C:\ProgramData\NVIDIA 2015-02-02 22:04 - 2011-09-16 03:16 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-30 00:01 - 2010-04-02 07:08 - 00000000 __RHD () C:\Users\Default 2015-01-30 00:01 - 2010-04-02 07:08 - 00000000 ___RD () C:\Users\Public 2015-01-30 00:00 - 2010-04-02 06:55 - 00000215 _____ () C:\Windows\system.ini 2015-01-30 00:00 - 2010-04-02 06:54 - 44826624 _____ () C:\Windows\system32\config\SYSTEM.bak 2015-01-30 00:00 - 2010-04-02 06:54 - 39845888 _____ () C:\Windows\system32\config\SOFTWARE.bak 2015-01-30 00:00 - 2010-04-02 06:54 - 00262144 _____ () C:\Windows\system32\config\SECURITY.bak 2015-01-30 00:00 - 2010-04-02 06:54 - 00262144 _____ () C:\Windows\system32\config\SAM.bak 2015-01-30 00:00 - 2010-04-02 06:54 - 00262144 _____ () C:\Windows\system32\config\DEFAULT.bak 2015-01-28 20:39 - 2013-12-29 08:42 - 00000000 ____D () C:\Windows\Panther 2015-01-27 20:37 - 2011-09-16 03:16 - 00032608 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-24 12:04 - 2014-07-31 08:44 - 00000600 _____ () C:\Users\****\AppData\Local\PUTTY.RND 2015-01-08 09:55 - 2013-12-28 17:30 - 00249488 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe ==================== Files in the root of some directories ======= 2014-07-31 08:44 - 2015-01-24 12:04 - 0000600 _____ () C:\Users\****\AppData\Local\PUTTY.RND 2014-07-29 20:12 - 2014-07-29 20:12 - 0000017 _____ () C:\Users\****\AppData\Local\resmon.resmoncfg 2008-02-05 13:28 - 2008-02-05 13:28 - 0000051 _____ () C:\Users\****\AppData\Local\setup.txt 2014-02-26 16:35 - 2014-02-26 16:35 - 0000000 ____H () C:\ProgramData\DP45977C.lfl ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-28 22:55 ==================== End Of Log ============================ --- --- --- |
Ich empfehle immer Emsisoft. hast Du die ganzen Policies mit Absicht gesetzt?
Nein, ich habe nichts mit Absicht gesetzt. Ich weiß, ehrlich gesagt, auch gar nicht, was Policies genau sind. Macht es Sinn diese wieder herauszunehmen und wenn ja wie geht das? Gibt es auch eine Empfehlung für ein kostenloses Antivirus-Programm? Sonst scheint der PC wieder i.O. zu sein oder was sagen dir die Log-Dateien?
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument
ATTFilter HKLM\...\Run: [MsmqIntCert] => regsvr32 /s mqrt.dll HKLM\...\Policies\Explorer: [] HKLM\...\Policies\Explorer: [NoStartMenuMyGames] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\system: [DisableChangePassword] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarNoDragToolbar] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [NoUserNameInStartMenu] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [NoStartMenuSubFolders] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarNoRedock] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarNoResize] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarNoAddRemoveToolbar] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [HideSCAVolume] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [TaskbarLockAll] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\...\Policies\Explorer: [LockTaskbar] 1 HKU\S-1-5-21-3317138025-3548756383-1990335332-1001\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Free AV gibt es eigentlich mittlerweile nur noch Bitdefender, die dich nicht mit Werbung, Toolbars oder Adware erschlagen. Aber 11 Cent am Tag für nen AV find ich jetzt nit tragisch Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun ![]() Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
Hallo, danke für deine Unterstützung. Abschließend nochmals die Log-Datei. Alles soweit i.O.?
