![]() |
|
Log-Analyse und Auswertung: Avast blockt verschiedene Seiten, svchost beteiligtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Avast blockt verschiedene Seiten, svchost beteiligt Hallo! Avast blockt immer wieder Seiten - auch ohne dass ein Browser offen ist bzw. die Seiten aufgerufen werden - und svchost wird dabei ebenfalls angezeigt. Es handelt sich dabei z.B. um die Seite blackled.info/* Eine Seite, die ich nie aufgerufen habe und die mir bisher unbekannt war. Das Ganze tritt nur auf, wenn ich als Administrator angemeldet bin (normalerweise bin ich mit einem eingeschränkten Benutzerkonto unterwegs). Ich habe bereits mit Avast einen Scan der Betriebssystem-Festplatte (WIN7) gemacht und es wurde nicht gefunden. Auch Malwarebytes Anti-Malware hat nichts gefunden (Log ebenfalls am Ende). Ich bin dann doch schnell mit meinem Latein am Ende und bräuchte Hilfe: Hier die Logs, die FRST ausgibt: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-02-2015 Ran by Administrator (administrator) on KRAXI on 01-03-2015 13:15:04 Running from C:\Users\Administrator\Desktop Loaded Profiles: Administrator (Available profiles: Standart & Administrator) Platform: Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (hxxp://kay-bruns.de) C:\Windows\SuRun.exe (AVAST Software) C:\Program Files\Avast\AvastSvc.exe (AMD) C:\Windows\System32\atieclxx.exe (Brother Industries, Ltd.) C:\Program Files\Brother\ControlCenter3\BrccMCtl.exe (Guillemot Corporation S.A.) C:\Program Files\Hercules\Dualpix Exchange\XtrCtrlEx.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe () C:\Program Files\Unlocker\UnlockerAssistant.exe (hxxp://kay-bruns.de) C:\Windows\SuRun.exe (AVAST Software) C:\Program Files\Avast\avastui.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Almico Software (www.almico.com)) D:\Portable Programme\K10Stat\speedfan.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (AVAST Software) C:\Program Files\Avast\ng\ngtool.exe (Avast Software) C:\Program Files\Avast\ng\vbox\AvastVBoxSVC.exe (AVAST Software) C:\Program Files\Avast\ng\vbox\aswFe.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ControlCenter3] => C:\Program Files\Brother\ControlCenter3\brctrcen.exe [114688 2008-12-24] (Brother Industries, Ltd.) HKLM\...\Run: [CamserviceExchange] => C:\Program Files\Hercules\Dualpix Exchange\XtrCtrlEx.exe [3228968 2011-09-07] (Guillemot Corporation S.A.) HKLM\...\Run: [RTHDVCPL] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12000984 2013-07-26] (Realtek Semiconductor) HKLM\...\Run: [UnlockerAssistant] => C:\Program Files\Unlocker\UnlockerAssistant.exe [17408 2010-07-04] () HKLM\...\Run: [SuRun Systemmenü-Erweiterung] => C:\Windows\SuRun.exe [678912 2013-10-19] (hxxp://kay-bruns.de) HKLM\...\Run: [AvastUI.exe] => C:\Program Files\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software) HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1 HKU\S-1-5-21-3658721051-4004364685-709729734-500\...\Policies\Explorer: [NoCDBurning] 1 HKU\S-1-5-21-3658721051-4004364685-709729734-500\Control Panel\Desktop\\SCRNSAVE.EXE -> C:\Windows\system32\Mystify.scr [221184 2010-11-20] (Microsoft Corporation) HKU\S-1-5-18\...\Policies\Explorer: [NoCDBurning] 1 Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\K10STAT.lnk ShortcutTarget: K10STAT.lnk -> D:\Portable Programme\K10Stat\K10STAT.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Speedfan.lnk ShortcutTarget: Speedfan.lnk -> D:\Portable Programme\K10Stat\speedfan.exe (Almico Software (www.almico.com)) ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\Avast\ashShell.dll (AVAST Software) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\.DEFAULT\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3658721051-4004364685-709729734-500\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=56626&homepage=https://de.yahoo.com?fr=hp-avast&type=prc265 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = HKU\S-1-5-21-3658721051-4004364685-709729734-500\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKLM -> DefaultScope {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?type=prc265&hspart=avast&hsimp=yhs-001&p={searchTerms} SearchScopes: HKLM -> {9CB96984-43C3-4D44-90EF-01466EFCF7BB} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?type=prc265&hspart=avast&hsimp=yhs-001&p={searchTerms} SearchScopes: HKU\.DEFAULT -> DefaultScope {637D6E3C-DF93-48A5-8362-159A8AC56B11} URL = hxxp://www.google.com/search?hl=en&q={searchTerms}&meta= SearchScopes: HKU\.DEFAULT -> {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\.DEFAULT -> {637D6E3C-DF93-48A5-8362-159A8AC56B11} URL = hxxp://www.google.com/search?hl=en&q={searchTerms}&meta= SearchScopes: HKU\S-1-5-21-3658721051-4004364685-709729734-500 -> DefaultScope {637D6E3C-DF93-48A5-8362-159A8AC56B11} URL = hxxp://www.google.com/search?hl=en&q={searchTerms}&meta= SearchScopes: HKU\S-1-5-21-3658721051-4004364685-709729734-500 -> {637D6E3C-DF93-48A5-8362-159A8AC56B11} URL = hxxp://www.google.com/search?hl=en&q={searchTerms}&meta= BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\Avast\aswWebRepIE.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks: SuRun Shell Extension - {2C7B6088-5A77-4d48-BE43-30337DCA9A86} - C:\Windows\SuRunExt.dll [175616 2013-10-19] (hxxp://kay-bruns.de) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default FF Homepage: about:newtab FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin: @adobe.com/ShockwavePlayer -> C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @videolan.org/vlc,version=2.1.0 -> C:\Program Files\VideoLAN\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.1 -> C:\Program Files\VideoLAN\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.2 -> C:\Program Files\VideoLAN\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\searchplugins\startpage-https---deutsch.xml FF SearchPlugin: C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\searchplugins\yahoo-avast.xml FF Extension: HTTPS-Everywhere - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\https-everywhere@eff.org [2014-11-08] FF Extension: FoxLingo - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\{ef62e1ce-d2a4-4cdd-b7ec-92b120366b66} [2014-06-01] FF Extension: Disconnect - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\2.0@disconnect.me.xpi [2014-06-01] FF Extension: Copy Plain Text 2 - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\copyplaintext@teo.pl.xpi [2014-06-01] FF Extension: Element Hiding Helper for Adblock Plus - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\elemhidehelper@adblockplus.org.xpi [2015-02-23] FF Extension: Extended Copy Menu (fix version) - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\extended.copy.menu@fix.version.xpi [2014-06-01] FF Extension: Myibidder (Myibay) Bid Sniper for eBay - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\firefox1@myibay.com.xpi [2014-06-01] FF Extension: Imgur Uploader - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\giorgio@gilestro.tk.xpi [2014-06-01] FF Extension: RequestPolicy - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\requestpolicy@requestpolicy.com.xpi [2014-06-01] FF Extension: Stylish - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi [2015-01-01] FF Extension: NoScript - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-06-01] FF Extension: BBCodeXtra - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\{af79f858-4b25-4ca4-822b-b5db1be628fc}.xpi [2015-01-01] FF Extension: RightToClick - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\{cd617375-6743-4ee8-bac4-fbf10f35729e}.xpi [2014-06-01] FF Extension: Adblock Plus - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-06-01] FF Extension: BetterPrivacy - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2014-06-01] FF Extension: Plain Text Links - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\{ec268e28-22c6-4a6c-ac22-635cabee283c}.xpi [2014-06-01] FF Extension: Download Manager Tweak - C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\k9u6a6ot.default\Extensions\{F8A55C97-3DB6-4961-A81D-0DE0080E53CB}.xpi [2014-06-01] FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\Avast\WebRep\FF [2013-10-15] Chrome: ======= CHR dev: Chrome dev build detected! <======= ATTENTION CHR HKLM\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-11-19] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\Avast\AvastSvc.exe [50344 2014-11-19] (AVAST Software) R3 AvastVBoxSvc; C:\Program Files\Avast\ng\vbox\AvastVBoxSVC.exe [3192344 2014-11-19] (Avast Software) S3 c2wts; C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe [15768 2013-10-13] (Microsoft Corporation) R2 SuRunSVC; C:\Windows\SuRun.exe [678912 2013-10-19] (hxxp://kay-bruns.de) [File not signed] R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2013-10-13] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 ampa; C:\Windows\system32\ampa.sys [14448 2013-11-29] () R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [24184 2014-11-19] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [70384 2014-11-19] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [81768 2014-11-19] (AVAST Software) R0 aswRvrt; C:\Windows\system32\Drivers\aswRvrt.sys [49944 2014-11-19] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [787800 2014-11-22] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423784 2014-11-20] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [91496 2014-11-19] (AVAST Software) R0 aswVmm; C:\Windows\system32\Drivers\aswVmm.sys [206248 2014-11-19] () R0 giveio; C:\Windows\System32\giveio.sys [5248 1996-04-03] () [File not signed] S3 hxctlflt; C:\Windows\System32\Drivers\hxctlflt.sys [99968 2009-02-08] (Guillemot Corporation) S3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [3482112 2009-04-22] () R0 speedfan; C:\Windows\System32\speedfan.sys [24184 2012-12-29] (Almico Software) R2 VBoxAswDrv; C:\Program Files\Avast\ng\vbox\VBoxAswDrv.sys [218192 2014-11-19] (Avast Software) S4 ALSysIO; \??\C:\Users\Admin.KRAXI\AppData\Local\Temp\ALSysIO.sys [X] U3 Bonjour Service; No ImagePath U5 UnlockerDriver5; C:\Program Files\Unlocker\UnlockerDriver5.sys [4096 2010-07-04] () [File not signed] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-01 13:15 - 2015-03-01 13:15 - 00014040 _____ () C:\Users\Administrator\Desktop\FRST.txt 2015-03-01 13:14 - 2015-03-01 13:14 - 00000488 _____ () C:\Users\Administrator\Desktop\defogger_disable.log 2015-03-01 13:14 - 2015-03-01 13:14 - 00000000 _____ () C:\Users\Administrator\defogger_reenable 2015-03-01 13:13 - 2015-03-01 13:13 - 01132032 _____ (Farbar) C:\Users\Administrator\Desktop\FRST.exe 2015-03-01 13:13 - 2015-03-01 13:13 - 00380416 _____ () C:\Users\Administrator\Desktop\Gmer-19357.exe 2015-03-01 13:13 - 2015-03-01 13:13 - 00050477 _____ () C:\Users\Administrator\Desktop\Defogger.exe 2015-03-01 13:13 - 2015-03-01 13:13 - 00000217 _____ () C:\Windows\system32\2015-03-01-12-13-52.024-aswFe.exe-5716.log 2015-03-01 13:13 - 2015-03-01 13:13 - 00000167 _____ () C:\Windows\system32\2015-03-01-12-13-48.096-AvastVBoxSVC.exe-2504.log 2015-03-01 10:32 - 2015-03-01 10:32 - 00000167 _____ () C:\Windows\system32\2015-03-01-09-32-14.098-AvastVBoxSVC.exe-2232.log 2015-02-28 18:38 - 2015-02-28 18:38 - 00000217 _____ () C:\Windows\system32\2015-02-28-17-38-47.093-aswFe.exe-5404.log 2015-02-28 18:34 - 2015-02-28 18:38 - 00000217 _____ () C:\Windows\system32\2015-02-28-17-34-12.097-aswFe.exe-5492.log 2015-02-28 18:34 - 2015-02-28 18:34 - 00000167 _____ () C:\Windows\system32\2015-02-28-17-34-09.053-AvastVBoxSVC.exe-4476.log 2015-02-28 11:06 - 2015-02-28 11:07 - 00000167 _____ () C:\Windows\system32\2015-02-28-10-06-36.060-AvastVBoxSVC.exe-2616.log 2015-02-28 08:23 - 2015-02-28 08:23 - 00000217 _____ () C:\Windows\system32\2015-02-28-07-23-35.070-aswFe.exe-6108.log 2015-02-28 08:18 - 2015-02-28 08:23 - 00000217 _____ () C:\Windows\system32\2015-02-28-07-18-10.011-aswFe.exe-3812.log 2015-02-28 08:18 - 2015-02-28 08:18 - 00000167 _____ () C:\Windows\system32\2015-02-28-07-18-08.003-AvastVBoxSVC.exe-4276.log 2015-02-27 19:44 - 2015-02-27 19:44 - 00000167 _____ () C:\Windows\system32\2015-02-27-18-44-18.066-AvastVBoxSVC.exe-2452.log 2015-02-27 17:16 - 2015-02-28 22:27 - 00000000 ____D () C:\Users\Admin.KRAXI\AppData\Roaming\XnViewMP 2015-02-27 17:12 - 2015-02-27 17:12 - 00000000 ____D () C:\Users\Admin.KRAXI\AppData\Roaming\XnConvert 2015-02-27 17:05 - 2015-02-27 17:06 - 00000167 _____ () C:\Windows\system32\2015-02-27-16-05-57.036-AvastVBoxSVC.exe-2412.log 2015-02-27 09:33 - 2015-02-27 09:33 - 00000167 _____ () C:\Windows\system32\2015-02-27-08-33-58.047-AvastVBoxSVC.exe-3732.log 2015-02-27 08:20 - 2015-02-27 08:20 - 00000167 _____ () C:\Windows\system32\2015-02-27-07-20-24.001-AvastVBoxSVC.exe-3524.log 2015-02-26 17:24 - 2015-02-26 17:24 - 00000167 _____ () C:\Windows\system32\2015-02-26-16-24-18.081-AvastVBoxSVC.exe-2616.log 2015-02-26 14:09 - 2015-02-26 14:09 - 00000167 _____ () C:\Windows\system32\2015-02-26-13-09-51.066-AvastVBoxSVC.exe-2416.log 2015-02-26 09:03 - 2015-02-26 09:03 - 00000217 _____ () C:\Windows\system32\2015-02-26-08-03-26.024-aswFe.exe-1776.log 2015-02-26 08:58 - 2015-02-26 09:03 - 00000217 _____ () C:\Windows\system32\2015-02-26-07-58-39.049-aswFe.exe-2576.log 2015-02-26 08:58 - 2015-02-26 08:58 - 00000167 _____ () C:\Windows\system32\2015-02-26-07-58-36.027-AvastVBoxSVC.exe-4032.log 2015-02-26 06:02 - 2015-02-26 06:03 - 00000167 _____ () C:\Windows\system32\2015-02-26-05-02-54.015-AvastVBoxSVC.exe-2752.log 2015-02-25 16:41 - 2015-02-25 16:41 - 00000167 _____ () C:\Windows\system32\2015-02-25-15-41-41.043-AvastVBoxSVC.exe-2476.log 2015-02-25 10:12 - 2015-02-25 10:12 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-02-25 08:58 - 2015-01-09 00:45 - 00419648 _____ () C:\Windows\system32\locale.nls 2015-02-25 08:54 - 2015-02-25 08:54 - 00000167 _____ () C:\Windows\system32\2015-02-25-07-54-49.067-AvastVBoxSVC.exe-2788.log 2015-02-24 09:21 - 2015-02-24 09:21 - 00000167 _____ () C:\Windows\system32\2015-02-24-08-21-39.044-AvastVBoxSVC.exe-2432.log 2015-02-23 08:57 - 2015-02-23 08:57 - 00000000 __HDC () C:\ProgramData\{68D9EB6A-D28F-437C-ACB3-C801259CFA2B} 2015-02-23 08:55 - 2015-02-23 08:55 - 00000000 __HDC () C:\ProgramData\{D4F46F7B-EA64-43A2-9BE5-84321CB4D190} 2015-02-23 08:54 - 2015-02-23 08:54 - 00000000 __HDC () C:\ProgramData\{90D8CE90-3E6B-4034-A281-BC9F19B60A5B} 2015-02-23 08:06 - 2015-02-23 08:06 - 00000167 _____ () C:\Windows\system32\2015-02-23-07-06-01.052-AvastVBoxSVC.exe-2672.log 2015-02-22 08:14 - 2015-02-22 08:14 - 00000167 _____ () C:\Windows\system32\2015-02-22-07-14-35.044-AvastVBoxSVC.exe-2636.log 2015-02-21 23:07 - 2015-02-21 23:07 - 00000167 _____ () C:\Windows\system32\2015-02-21-22-07-01.079-AvastVBoxSVC.exe-2556.log 2015-02-21 19:00 - 2015-02-25 15:45 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\Mp3tag 2015-02-21 10:15 - 2015-02-21 10:15 - 00000167 _____ () C:\Windows\system32\2015-02-21-09-15-16.064-AvastVBoxSVC.exe-2428.log 2015-02-20 20:35 - 2015-02-20 20:35 - 00000167 _____ () C:\Windows\system32\2015-02-20-19-35-43.041-AvastVBoxSVC.exe-2536.log 2015-02-20 14:38 - 2015-02-20 14:38 - 00000167 _____ () C:\Windows\system32\2015-02-20-13-38-22.066-AvastVBoxSVC.exe-2484.log 2015-02-20 11:04 - 2015-02-20 11:09 - 00000217 _____ () C:\Windows\system32\2015-02-20-10-04-37.038-aswFe.exe-5696.log 2015-02-19 21:13 - 2015-02-19 21:13 - 00000167 _____ () C:\Windows\system32\2015-02-19-20-13-17.047-AvastVBoxSVC.exe-2832.log 2015-02-19 17:14 - 2015-02-19 17:14 - 00000167 _____ () C:\Windows\system32\2015-02-19-16-14-24.036-AvastVBoxSVC.exe-2468.log 2015-02-19 09:30 - 2015-02-19 09:30 - 00000167 _____ () C:\Windows\system32\2015-02-19-08-30-00.060-AvastVBoxSVC.exe-2604.log 2015-02-18 19:59 - 2015-02-18 20:00 - 00000167 _____ () C:\Windows\system32\2015-02-18-18-59-55.076-AvastVBoxSVC.exe-2528.log 2015-02-18 14:46 - 2015-02-18 14:46 - 00000217 _____ () C:\Windows\system32\2015-02-18-13-46-29.036-aswFe.exe-724.log 2015-02-18 14:41 - 2015-02-18 14:46 - 00000217 _____ () C:\Windows\system32\2015-02-18-13-41-36.016-aswFe.exe-1088.log 2015-02-18 14:41 - 2015-02-18 14:41 - 00000167 _____ () C:\Windows\system32\2015-02-18-13-41-33.037-AvastVBoxSVC.exe-776.log 2015-02-18 09:39 - 2015-02-18 09:39 - 00000167 _____ () C:\Windows\system32\2015-02-18-08-39-13.065-AvastVBoxSVC.exe-2644.log 2015-02-17 18:24 - 2015-02-17 18:24 - 00000217 _____ () C:\Windows\system32\2015-02-17-17-24-51.000-aswFe.exe-1288.log 2015-02-17 18:20 - 2015-02-17 18:24 - 00000217 _____ () C:\Windows\system32\2015-02-17-17-20-07.018-aswFe.exe-3428.log 2015-02-17 18:20 - 2015-02-17 18:20 - 00000167 _____ () C:\Windows\system32\2015-02-17-17-20-04.085-AvastVBoxSVC.exe-3876.log 2015-02-17 12:07 - 2015-02-17 12:07 - 00000167 _____ () C:\Windows\system32\2015-02-17-11-07-23.043-AvastVBoxSVC.exe-2588.log 2015-02-17 08:50 - 2015-02-17 08:51 - 00000167 _____ () C:\Windows\system32\2015-02-17-07-50-58.083-AvastVBoxSVC.exe-2784.log 2015-02-16 08:41 - 2015-02-16 08:41 - 00000167 _____ () C:\Windows\system32\2015-02-16-07-41-01.064-AvastVBoxSVC.exe-2412.log 2015-02-15 21:36 - 2015-02-15 21:37 - 00000167 _____ () C:\Windows\system32\2015-02-15-20-36-40.001-AvastVBoxSVC.exe-2552.log 2015-02-15 15:01 - 2015-02-15 15:01 - 00000167 _____ () C:\Windows\system32\2015-02-15-14-01-41.006-AvastVBoxSVC.exe-2532.log 2015-02-15 13:53 - 2015-02-15 13:53 - 00000167 _____ () C:\Windows\system32\2015-02-15-12-53-26.012-AvastVBoxSVC.exe-2508.log 2015-02-14 22:27 - 2015-02-14 22:28 - 00000167 _____ () C:\Windows\system32\2015-02-14-21-27-46.039-AvastVBoxSVC.exe-2532.log 2015-02-14 08:34 - 2015-02-14 08:35 - 00000167 _____ () C:\Windows\system32\2015-02-14-07-34-58.041-AvastVBoxSVC.exe-2552.log 2015-02-13 09:34 - 2015-02-13 09:34 - 00000167 _____ () C:\Windows\system32\2015-02-13-08-34-19.039-AvastVBoxSVC.exe-2428.log 2015-02-12 21:25 - 2015-02-12 21:25 - 00000217 _____ () C:\Windows\system32\2015-02-12-20-25-43.097-aswFe.exe-2492.log 2015-02-12 21:20 - 2015-02-12 21:25 - 00000217 _____ () C:\Windows\system32\2015-02-12-20-20-15.063-aswFe.exe-3384.log 2015-02-12 21:20 - 2015-02-12 21:20 - 00000167 _____ () C:\Windows\system32\2015-02-12-20-20-10.037-AvastVBoxSVC.exe-3132.log 2015-02-12 19:17 - 2015-02-12 19:17 - 00000167 _____ () C:\Windows\system32\2015-02-12-18-17-47.057-AvastVBoxSVC.exe-2652.log 2015-02-12 15:27 - 2015-02-12 15:27 - 00000167 _____ () C:\Windows\system32\2015-02-12-14-27-38.042-AvastVBoxSVC.exe-2336.log 2015-02-12 07:07 - 2015-01-23 04:00 - 01810944 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-02-12 07:07 - 2015-01-23 03:51 - 00717824 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-02-12 06:58 - 2015-02-12 06:58 - 00000167 _____ () C:\Windows\system32\2015-02-12-05-58-44.061-AvastVBoxSVC.exe-2576.log 2015-02-11 20:22 - 2015-02-11 20:22 - 00000167 _____ () C:\Windows\system32\2015-02-11-19-22-27.064-AvastVBoxSVC.exe-2436.log 2015-02-11 17:53 - 2015-02-11 17:53 - 00000167 _____ () C:\Windows\system32\2015-02-11-16-53-25.052-AvastVBoxSVC.exe-2156.log 2015-02-11 16:12 - 2015-01-09 03:48 - 00635904 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll 2015-02-11 16:12 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll 2015-02-11 16:12 - 2015-01-09 03:48 - 00027136 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll 2015-02-11 15:28 - 2015-02-11 15:29 - 00000167 _____ () C:\Windows\system32\2015-02-11-14-28-48.088-AvastVBoxSVC.exe-2544.log 2015-02-11 10:55 - 2015-02-11 10:55 - 00000167 _____ () C:\Windows\system32\2015-02-11-09-55-39.029-AvastVBoxSVC.exe-2232.log 2015-02-11 09:05 - 2015-01-14 02:51 - 12371456 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-02-11 09:05 - 2015-01-14 02:49 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2015-02-11 09:05 - 2015-01-14 02:46 - 09742336 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-02-11 09:05 - 2015-01-14 02:43 - 01139712 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-02-11 09:05 - 2015-01-14 02:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-02-11 09:05 - 2015-01-14 02:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-02-11 09:05 - 2015-01-14 02:41 - 01802752 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-02-11 09:05 - 2015-01-14 02:41 - 00607744 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-02-11 09:05 - 2015-01-14 02:41 - 00421376 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-02-11 09:05 - 2015-01-14 02:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2015-02-11 09:05 - 2015-01-14 02:41 - 00142848 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-02-11 09:05 - 2015-01-14 02:41 - 00065024 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-02-11 09:05 - 2015-01-14 02:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-02-11 09:05 - 2015-01-14 02:40 - 00353792 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-02-11 09:05 - 2015-01-14 02:40 - 00223232 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-02-11 09:05 - 2015-01-14 02:40 - 00176640 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-02-11 09:05 - 2015-01-14 02:40 - 00073216 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-02-11 09:05 - 2015-01-14 02:40 - 00041472 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2015-02-11 09:05 - 2015-01-14 02:40 - 00011776 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2015-02-11 09:05 - 2015-01-14 02:40 - 00010752 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2015-02-11 09:03 - 2015-01-13 03:49 - 01011200 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-02-11 09:03 - 2015-01-09 02:52 - 02388992 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-02-11 09:02 - 2015-01-15 09:09 - 01062912 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-02-11 09:02 - 2015-01-15 09:09 - 00248832 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-02-11 09:02 - 2015-01-15 09:09 - 00220160 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-02-11 09:02 - 2015-01-15 05:22 - 00369976 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-02-11 09:02 - 2015-01-14 07:25 - 03977656 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2015-02-11 09:02 - 2015-01-14 07:25 - 03921848 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-02-11 09:02 - 2014-12-12 06:38 - 01175040 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2015-02-11 09:02 - 2014-12-08 04:03 - 00308224 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll 2015-02-11 09:02 - 2014-10-30 03:14 - 00145920 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll 2015-02-11 09:00 - 2015-02-04 03:54 - 00482304 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll 2015-02-11 09:00 - 2015-02-04 03:53 - 00767488 _____ (Microsoft Corporation) C:\Windows\system32\appraiser.dll 2015-02-11 09:00 - 2015-02-04 03:53 - 00621056 _____ (Microsoft Corporation) C:\Windows\system32\invagent.dll 2015-02-11 09:00 - 2015-02-04 03:53 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\devinv.dll 2015-02-11 09:00 - 2015-02-04 03:53 - 00202752 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2015-02-11 09:00 - 2015-02-04 03:53 - 00159744 _____ (Microsoft Corporation) C:\Windows\system32\aepic.dll 2015-02-11 09:00 - 2015-02-04 03:49 - 00886784 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2015-02-11 09:00 - 2015-01-28 00:36 - 01167520 _____ (Microsoft Corporation) C:\Windows\system32\aitstatic.exe 2015-02-11 09:00 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2015-02-11 08:54 - 2015-02-11 08:54 - 00000167 _____ () C:\Windows\system32\2015-02-11-07-54-48.017-AvastVBoxSVC.exe-3512.log 2015-02-10 21:40 - 2015-02-10 21:40 - 00000217 _____ () C:\Windows\system32\2015-02-10-20-40-18.087-aswFe.exe-5832.log 2015-02-10 21:35 - 2015-02-10 21:40 - 00000217 _____ () C:\Windows\system32\2015-02-10-20-35-29.069-aswFe.exe-5856.log 2015-02-10 21:35 - 2015-02-10 21:35 - 00000167 _____ () C:\Windows\system32\2015-02-10-20-35-24.082-AvastVBoxSVC.exe-2032.log 2015-02-10 13:30 - 2015-02-10 13:30 - 00000167 _____ () C:\Windows\system32\2015-02-10-12-30-13.073-AvastVBoxSVC.exe-2468.log 2015-02-10 11:01 - 2015-02-10 11:01 - 00000167 _____ () C:\Windows\system32\2015-02-10-10-01-43.011-AvastVBoxSVC.exe-2424.log 2015-02-10 09:30 - 2015-02-10 09:30 - 00000167 _____ () C:\Windows\system32\2015-02-10-08-30-34.068-AvastVBoxSVC.exe-2464.log 2015-02-09 19:58 - 2015-02-09 19:58 - 00000167 _____ () C:\Windows\system32\2015-02-09-18-58-24.060-AvastVBoxSVC.exe-2456.log 2015-02-09 14:45 - 2015-02-09 14:45 - 00000167 _____ () C:\Windows\system32\2015-02-09-13-45-47.051-AvastVBoxSVC.exe-2364.log 2015-02-09 09:51 - 2015-02-09 09:51 - 00000167 _____ () C:\Windows\system32\2015-02-09-08-51-38.080-AvastVBoxSVC.exe-2328.log 2015-02-08 20:17 - 2015-02-08 20:17 - 00000167 _____ () C:\Windows\system32\2015-02-08-19-17-34.070-AvastVBoxSVC.exe-2248.log 2015-02-08 14:44 - 2015-02-08 14:44 - 00000167 _____ () C:\Windows\system32\2015-02-08-13-44-08.026-AvastVBoxSVC.exe-2396.log 2015-02-08 09:17 - 2015-02-08 09:17 - 00000167 _____ () C:\Windows\system32\2015-02-08-08-17-42.073-AvastVBoxSVC.exe-2568.log 2015-02-07 22:36 - 2015-02-07 22:37 - 00000167 _____ () C:\Windows\system32\2015-02-07-21-36-15.035-AvastVBoxSVC.exe-2512.log 2015-02-07 18:13 - 2015-02-07 18:13 - 00000167 _____ () C:\Windows\system32\2015-02-07-17-13-25.075-AvastVBoxSVC.exe-2488.log 2015-02-07 17:09 - 2015-02-07 17:10 - 00000167 _____ () C:\Windows\system32\2015-02-07-16-09-55.036-AvastVBoxSVC.exe-2376.log 2015-02-07 14:06 - 2015-02-07 14:06 - 00000167 _____ () C:\Windows\system32\2015-02-07-13-06-05.063-AvastVBoxSVC.exe-2536.log 2015-02-07 13:14 - 2015-02-07 13:14 - 00000167 _____ () C:\Windows\system32\2015-02-07-12-14-16.000-AvastVBoxSVC.exe-2544.log 2015-02-07 12:09 - 2015-02-07 12:09 - 00000167 _____ () C:\Windows\system32\2015-02-07-11-09-12.059-AvastVBoxSVC.exe-2588.log 2015-02-07 10:07 - 2015-02-07 10:07 - 00000167 _____ () C:\Windows\system32\2015-02-07-09-07-27.017-AvastVBoxSVC.exe-2528.log 2015-02-06 18:31 - 2015-02-06 18:31 - 00000167 _____ () C:\Windows\system32\2015-02-06-17-31-04.069-AvastVBoxSVC.exe-2576.log 2015-02-06 13:52 - 2015-02-06 13:52 - 00000167 _____ () C:\Windows\system32\2015-02-06-12-52-42.026-AvastVBoxSVC.exe-2572.log 2015-02-06 08:02 - 2015-02-06 08:02 - 00000167 _____ () C:\Windows\system32\2015-02-06-07-02-19.006-AvastVBoxSVC.exe-2536.log 2015-02-05 16:31 - 2015-02-05 16:31 - 00000167 _____ () C:\Windows\system32\2015-02-05-15-31-06.099-AvastVBoxSVC.exe-2548.log 2015-02-05 13:38 - 2015-02-05 13:39 - 00000167 _____ () C:\Windows\system32\2015-02-05-12-38-33.053-AvastVBoxSVC.exe-3096.log 2015-02-05 08:45 - 2015-02-05 08:45 - 00000167 _____ () C:\Windows\system32\2015-02-05-07-45-16.039-AvastVBoxSVC.exe-2384.log 2015-02-04 18:05 - 2015-02-04 18:05 - 00000167 _____ () C:\Windows\system32\2015-02-04-17-05-07.024-AvastVBoxSVC.exe-2824.log 2015-02-04 14:24 - 2015-02-04 14:24 - 00000167 _____ () C:\Windows\system32\2015-02-04-13-24-03.001-AvastVBoxSVC.exe-2624.log 2015-02-04 12:06 - 2015-02-04 12:06 - 00000167 _____ () C:\Windows\system32\2015-02-04-11-06-32.051-AvastVBoxSVC.exe-976.log 2015-02-04 08:13 - 2015-02-04 08:13 - 00000167 _____ () C:\Windows\system32\2015-02-04-07-13-31.045-AvastVBoxSVC.exe-2548.log 2015-02-03 20:30 - 2015-02-03 20:30 - 00000167 _____ () C:\Windows\system32\2015-02-03-19-30-07.064-AvastVBoxSVC.exe-2512.log 2015-02-03 13:57 - 2015-02-03 13:57 - 00000167 _____ () C:\Windows\system32\2015-02-03-12-57-18.013-AvastVBoxSVC.exe-2556.log 2015-02-03 12:59 - 2015-02-03 12:59 - 00000167 _____ () C:\Windows\system32\2015-02-03-11-59-37.071-AvastVBoxSVC.exe-2488.log 2015-02-03 09:17 - 2015-02-03 09:18 - 00000167 _____ () C:\Windows\system32\2015-02-03-08-17-55.005-AvastVBoxSVC.exe-2544.log 2015-02-02 19:16 - 2015-02-02 19:16 - 00000167 _____ () C:\Windows\system32\2015-02-02-18-16-04.014-AvastVBoxSVC.exe-2528.log 2015-02-02 09:06 - 2015-02-02 09:06 - 00000167 _____ () C:\Windows\system32\2015-02-02-08-06-02.045-AvastVBoxSVC.exe-2408.log 2015-02-01 16:40 - 2015-02-01 16:40 - 00000167 _____ () C:\Windows\system32\2015-02-01-15-40-48.079-AvastVBoxSVC.exe-2552.log 2015-02-01 11:19 - 2015-02-01 11:19 - 00000167 _____ () C:\Windows\system32\2015-02-01-10-19-47.097-AvastVBoxSVC.exe-2464.log 2015-01-31 18:42 - 2015-01-31 18:42 - 00000167 _____ () C:\Windows\system32\2015-01-31-17-42-10.038-AvastVBoxSVC.exe-2484.log 2015-01-31 15:56 - 2015-01-31 15:56 - 00000167 _____ () C:\Windows\system32\2015-01-31-14-56-42.071-AvastVBoxSVC.exe-2576.log 2015-01-31 15:00 - 2015-01-31 15:00 - 00000167 _____ () C:\Windows\system32\2015-01-31-14-00-50.072-AvastVBoxSVC.exe-2336.log 2015-01-31 10:51 - 2015-01-31 10:52 - 00000167 _____ () C:\Windows\system32\2015-01-31-09-51-59.086-AvastVBoxSVC.exe-2264.log 2015-01-30 19:22 - 2015-01-30 19:22 - 00000167 _____ () C:\Windows\system32\2015-01-30-18-22-12.055-AvastVBoxSVC.exe-2656.log 2015-01-30 14:59 - 2015-01-30 15:00 - 00000167 _____ () C:\Windows\system32\2015-01-30-13-59-54.039-AvastVBoxSVC.exe-2796.log 2015-01-30 11:45 - 2015-01-30 11:45 - 00000167 _____ () C:\Windows\system32\2015-01-30-10-45-39.008-AvastVBoxSVC.exe-2292.log 2015-01-30 09:07 - 2015-01-30 09:07 - 00000167 _____ () C:\Windows\system32\2015-01-30-08-07-53.048-AvastVBoxSVC.exe-2372.log 2015-01-30 07:07 - 2015-01-30 07:07 - 00000167 _____ () C:\Windows\system32\2015-01-30-06-07-39.050-AvastVBoxSVC.exe-2684.log ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-03-01 13:15 - 2015-01-01 10:46 - 00000000 ____D () C:\FRST 2015-03-01 13:14 - 2013-10-14 18:04 - 00000000 ____D () C:\Users\Administrator 2015-03-01 13:14 - 2009-07-14 05:34 - 00030880 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-03-01 13:14 - 2009-07-14 05:34 - 00030880 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-03-01 13:10 - 2013-10-14 17:34 - 01834421 _____ () C:\Windows\WindowsUpdate.log 2015-03-01 13:05 - 2013-10-15 21:11 - 00000000 ____D () C:\Temp 2015-03-01 13:05 - 2009-07-14 05:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-28 19:11 - 2013-10-18 19:13 - 00000000 ____D () C:\Users\Admin.KRAXI\AppData\Roaming\uTorrent 2015-02-28 09:09 - 2014-10-04 11:33 - 00000000 ____D () C:\Users\Admin.KRAXI\AppData\Roaming\Mp3tag 2015-02-25 16:42 - 2013-10-19 11:06 - 00000000 ____D () C:\Users\Admin.KRAXI\AppData\Local\CrashDumps 2015-02-25 16:39 - 2014-06-01 13:08 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-02-24 10:26 - 2013-10-16 13:30 - 00000000 ____D () C:\Users\Administrator\AppData\Roaming\uTorrent 2015-02-23 16:40 - 2015-01-01 09:52 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-02-23 08:53 - 2013-10-14 17:44 - 00000000 ____D () C:\ProgramData\Package Cache 2015-02-22 14:30 - 2013-10-15 22:18 - 00000000 ____D () C:\Users\Administrator\.VirtualBox 2015-02-21 23:12 - 2014-10-01 18:15 - 00000000 ____D () C:\Program Files\QNAP 2015-02-21 23:04 - 2009-07-14 05:53 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-02-14 09:18 - 1899-12-30 01:00 - 00000000 ___RD () C:\Users\Administrator\Desktop\Arbeitsordner 2015-02-12 09:26 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\rescache 2015-02-11 16:13 - 2009-07-14 03:37 - 00000000 ____D () C:\Windows\tracing 2015-02-11 10:53 - 2009-07-14 05:33 - 00269664 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-02-11 09:38 - 2014-12-10 16:41 - 00000000 ____D () C:\Windows\system32\appraiser 2015-02-11 09:38 - 2014-04-23 10:17 - 00000000 ___SD () C:\Windows\system32\CompatTel 2015-02-11 09:14 - 2013-10-14 21:40 - 00000000 ____D () C:\Windows\system32\MRT 2015-02-11 09:08 - 2013-10-15 11:23 - 113756392 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-02-05 09:04 - 2013-10-14 17:49 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-02-05 09:04 - 2013-10-14 17:49 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-01-30 15:39 - 2013-10-17 17:45 - 00000000 ___RD () C:\Users\Admin.KRAXI\Desktop\Arbeitsordner ==================== Files in the root of some directories ======= 2013-10-14 19:08 - 2005-12-09 03:52 - 0000060 ____R () C:\Program Files\BRINST.INI 2013-10-27 12:46 - 2013-10-27 12:46 - 0007633 _____ () C:\Users\Administrator\AppData\Local\Resmon.ResmonCfg 2013-10-14 18:31 - 2013-10-14 18:31 - 0000000 ____H () C:\ProgramData\DP45977C.lfl Some content of TEMP: ==================== C:\Users\Admin.KRAXI\AppData\Local\Temp\sfamcc00001.dll C:\Users\Administrator\AppData\Local\Temp\sfamcc00001.dll C:\Users\Administrator\AppData\Local\Temp\sfareca00001.dll ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-25 21:51 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 29-02-2015 Ran by Administrator at 2015-03-01 13:15:42 Running from C:\Users\Administrator\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) µtorrent 3.0.0 (build 25422) Leecher Pack (HKLM\...\µtorrent 3.0.0 (build 25422) Leecher Pack by seba14_is1) (Version: - seba14) Adobe Digital Editions 2.0 (HKLM\...\Adobe Digital Editions 2.0) (Version: 2.0.1 - Adobe Systems Incorporated) Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Adobe Shockwave Player 12.0 (HKLM\...\{BCFB58FF-181E-472F-A9DB-827B75C1EDF7}) (Version: 12.0.4.144 - Adobe Systems, Inc) Allgemeine Runtime Files (x86) (HKLM\...\{1F6D1DB5-82B5-41A4-85A2-0A382C142A35}_is1) (Version: 1.0.3.0 - Sereby Corporation) AMD Catalyst Install Manager (HKLM\...\{5C085A19-B4A1-6686-0103-E9E6F7B2831A}) (Version: 3.0.864.0 - Advanced Micro Devices, Inc.) Avast Free Antivirus (HKLM\...\avast) (Version: 10.0.2208 - AVAST Software) Brother Driver Deployment Wizard (HKLM\...\{0ED38503-B69A-44B4-98BE-21BFF284A9B6}) (Version: 1.09.000 - Brother) Brother MFL-Pro Suite DCP-195C (HKLM\...\{6BF66AED-3EA4-4106-B240-5CE96C9B76B0}) (Version: 2.0.0.0 - Brother Industries, Ltd.) Default Programs Editor (HKLM\...\Default Programs Editor) (Version: 2.7.2675.2253 - factormystic.net) DirectX 9.0c Extra Files (x86, x64) (HKLM\...\{8729E65B-8C12-4A42-B1FE-E4DA7ED52855}_is1) (Version: 1.10.06.0 - Sereby Corporation) DirectX for Managed Code (HKLM\...\{FDF7187F-3960-4BEC-916D-98C9A83E3A68}_is1) (Version: 1.0.0.0 - Sereby Corporation) Dualpix Exchange (HKLM\...\{2FDDE008-7BAA-4CAC-9AC3-92C0C1111A3A}) (Version: 4.0.2.1 - Hercules) Free Mp3 Wma Converter V 2.2 (HKLM\...\Free Mp3 Wma Converter_is1) (Version: 2.2.0.0 - Koyote Lab Inc.) Hercules Webcam Station Evolution SE (HKLM\...\{C3C44248-B8F7-4B20-A5C7-994870B60F55}) (Version: 3.2.2.1 - Hercules) Java 8 Update 31 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation) Malwarebytes Anti-Malware Version 2.0.4.1028 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.4.1028 - Malwarebytes Corporation) M-Audio FireWire 6.0.4 (x86) (HKLM\...\{CF9FEB7B-3BBF-47D6-801B-09530B7DA7CA}) (Version: 6.0.4 - M-Audio) Microsoft .NET Framework 1.1 Security Update (KB2698023) (HKLM\...\M2698023) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB2742597) (HKLM\...\M2742597) (Version: - ) Microsoft .NET Framework 1.1 Security Update (KB979906) (HKLM\...\M979906) (Version: - ) Microsoft .NET Framework 1.1 SP1 (HKLM\...\Microsoft .NET Framework 1.1 (1033)) (Version: - ) Microsoft .NET Framework 4.5.2 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.51209 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Application Compatibility Toolkit 5.6 (HKLM\...\{0F5AEBB0-43F3-4571-ACE7-A7942E8AA179}) (Version: 5.6.7324.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.60830 (HKLM\...\{9dba0447-b749-41ea-90bc-2aa19a9eb580}) (Version: 11.0.60830.0 - Microsoft Corporation) Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation) Microsoft Visual J# 2.0 Redistributable Package - SE (HKLM\...\Microsoft Visual J# 2.0 Redistributable Package - SE) (Version: - Microsoft Corporation) Monkey's Audio (HKLM\...\Monkey's Audio_is1) (Version: - ) Mozilla Firefox 36.0 (x86 de) (HKLM\...\Mozilla Firefox 36.0 (x86 de)) (Version: 36.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MP3-Info extension V3.4.23 (HKLM\...\MP3-Info extension_is1) (Version: 3.4.23 - Michael Mutschler) Mp3tag v2.66 (HKLM\...\Mp3tag) (Version: v2.66 - Florian Heidenreich) MusicBrainz Picard (HKLM\...\MusicBrainz Picard) (Version: 1.4.0dev2_win_20141219105800 - MusicBrainz) Oracle VM VirtualBox 4.2.18 (HKLM\...\{2C00465A-EA83-4D9B-9482-9180FBEBD4AC}) (Version: 4.2.18 - Oracle Corporation) QNAP Qfinder (HKLM\...\QNAP_FINDER) (Version: 4.2.5.0108 - QNAP Systems, Inc.) Realtek Ethernet Controller Driver (HKLM\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.72.410.2013 - Realtek) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.7004 - Realtek Semiconductor Corp.) Skype™ 6.11 (HKLM\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) SpeedFan (remove only) (HKLM\...\SpeedFan) (Version: - ) Super User Run (SuRun) (HKLM\...\SuRun) (Version: 1.2.1.0 - Kay Bruns) UltraISO Premium V9.52 (HKLM\...\UltraISO_is1) (Version: - ) Unlocker 1.9.2 (HKLM\...\Unlocker) (Version: 1.9.2 - Cedrick Collomb) VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) WinRAR 5.00 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.00.0 - win.rar GmbH) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-3658721051-4004364685-709729734-500_Classes\CLSID\{6D68FD0E-A1D4-67DA-F02A-E60DD72474B6}\InprocServer32 -> C:\Windows\system32\ole32.dll (Microsoft Corporation) ==================== Restore Points ========================= ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {2DEB7EB8-F744-45DC-9809-1ECA206E5584} - System32\Tasks\avast! Emergency Update => C:\Program Files\Avast\AvastEmUpdate.exe [2014-11-19] (AVAST Software) Task: {31AA4E9C-8A7D-4CC8-BD24-09A5973B0558} - System32\Tasks\{5D562E85-38F0-46DC-AC54-EBF248A2517F} => pcalua.exe -a "H:\WaveLab LE 7 for Windows\Setup.exe" -d "H:\WaveLab LE 7 for Windows" Task: {67705D0E-6E0F-4ADA-ABB7-AD9D3F8A9A66} - System32\Tasks\K10Stat Autostart => D:\Portable Programme\K10Stat\K10STAT.exe [2011-08-06] () Task: {7C6C99B4-0EBF-47AB-8325-46AEDAE223EB} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {ACFD7EC4-0390-40B9-926C-01AD056ABCDA} - System32\Tasks\iSCSIAgentAutoStartup => C:\Program Files\QNAP\Qfinder\iSCSIAgent.exe [2015-01-27] () Task: {E3AF7CB3-9AB9-4CD5-BCC9-9777EDD37DF9} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) ==================== Loaded Modules (whitelisted) ============== 2015-02-28 22:25 - 2015-02-28 22:25 - 02913792 _____ () C:\Program Files\Avast\defs\15022801\algo.dll 2014-11-19 20:44 - 2014-11-19 20:44 - 02151544 _____ () C:\Program Files\Avast\ng\vbox\VBoxVMM.dll 2014-11-19 20:44 - 2014-11-19 20:44 - 00021488 _____ () C:\Program Files\Avast\ng\vbox\VBoxREM.dll 2014-11-19 20:44 - 2014-11-19 20:44 - 04474224 _____ () C:\Program Files\Avast\ng\vbox\VBoxRT.dll 2015-03-01 13:08 - 2015-03-01 13:08 - 02913792 _____ () C:\Program Files\Avast\defs\15030100\algo.dll 2013-10-14 19:26 - 2009-02-27 15:38 - 00139264 ____R () C:\Program Files\Brother\BrUtilities\BrLogAPI.dll 2010-07-04 22:32 - 2010-07-04 22:32 - 00004608 _____ () C:\Program Files\Unlocker\UnlockerHook.dll 2013-11-04 16:03 - 2009-03-13 15:33 - 00593920 _____ () C:\Program Files\Hercules\Dualpix Exchange\highgui110.dll 2013-11-04 16:03 - 2009-03-13 15:32 - 00958464 _____ () C:\Program Files\Hercules\Dualpix Exchange\cxcore110.dll 2013-11-04 16:03 - 2009-03-13 15:33 - 00876544 _____ () C:\Program Files\Hercules\Dualpix Exchange\cv110.dll 2010-07-04 20:51 - 2010-07-04 20:51 - 00017408 _____ () C:\Program Files\Unlocker\UnlockerAssistant.exe 2014-11-19 20:44 - 2014-11-19 20:44 - 38562088 _____ () C:\Program Files\Avast\libcef.dll 2015-03-01 13:08 - 2015-03-01 13:08 - 00158720 _____ () C:\Users\Administrator\AppData\Local\Temp\sfareca00001.dll 2013-10-15 17:41 - 2015-03-01 13:08 - 00192512 _____ () C:\Users\Administrator\AppData\Local\Temp\sfamcc00001.dll 2014-11-19 20:44 - 2014-11-19 20:44 - 00317632 _____ () C:\Program Files\Avast\ng\vbox\VBoxDDU.dll 2014-11-19 20:44 - 2014-11-19 20:44 - 00028712 _____ () C:\Program Files\Avast\ng\vbox\VBoxSharedClipboard.DLL 2014-11-19 20:44 - 2014-11-19 20:44 - 00042616 _____ () C:\Program Files\Avast\ng\vbox\VBoxDragAndDropSvc.DLL 2014-11-19 20:44 - 2014-11-19 20:44 - 00040056 _____ () C:\Program Files\Avast\ng\vbox\VBoxGuestControlSvc.DLL 2014-11-19 20:44 - 2014-11-19 20:44 - 01129784 _____ () C:\Program Files\Avast\ng\vbox\VBoxREM64.DLL 2014-11-19 20:44 - 2014-11-19 20:44 - 01274448 _____ () C:\Program Files\Avast\ng\vbox\VBoxDD.DLL 2014-11-19 20:44 - 2014-11-19 20:44 - 00198152 _____ () C:\Program Files\Avast\ng\vbox\VBoxDD2.dll 2014-11-19 20:44 - 2014-11-19 20:44 - 00037984 _____ () C:\Program Files\Avast\ng\vbox\VBoxSharedFolders.DLL ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3658721051-4004364685-709729734-500\Control Panel\Desktop\\Wallpaper -> C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.178.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: M-Audio Taskbar Icon => C:\Windows\system32\MAFWTray.exe ==================== Accounts: ============================= Administrator (S-1-5-21-3658721051-4004364685-709729734-500 - Administrator - Enabled) => C:\Users\Administrator Gast (S-1-5-21-3658721051-4004364685-709729734-501 - Limited - Disabled) Standart (S-1-5-21-3658721051-4004364685-709729734-1002 - Limited - Enabled) => C:\Users\Admin.KRAXI ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/23/2015 03:58:32 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm TagRename.exe, Version 3.8.1.41 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1324 Startzeit: 01d04f6573daaae6 Endzeit: 131 Anwendungspfad: D:\Portable Programme\TagRename 3.81\TagRename.exe Berichts-ID: 6cdf6817-bb6c-11e4-ab04-40618667f7ca Error: (02/22/2015 08:12:32 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/21/2015 11:05:00 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/21/2015 10:13:15 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/20/2015 08:33:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/20/2015 02:37:20 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/20/2015 10:54:09 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/19/2015 09:12:13 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/19/2015 05:12:25 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (03/01/2015 01:06:33 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (03/01/2015 10:30:04 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (02/28/2015 06:23:48 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (02/28/2015 11:05:11 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (02/28/2015 08:07:44 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (02/27/2015 07:42:05 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (02/27/2015 05:03:43 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (02/27/2015 09:30:44 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (02/27/2015 08:17:19 AM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (02/26/2015 05:22:12 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Microsoft Office Sessions: ========================= Error: (02/23/2015 03:58:32 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: TagRename.exe3.8.1.41132401d04f6573daaae6131D:\Portable Programme\TagRename 3.81\TagRename.exe6cdf6817-bb6c-11e4-ab04-40618667f7ca Error: (02/22/2015 08:12:32 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/21/2015 11:05:00 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/21/2015 10:13:15 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/20/2015 08:33:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/20/2015 02:37:20 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/20/2015 10:54:09 AM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/19/2015 09:12:13 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/19/2015 05:12:25 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Processor: AMD Athlon(tm) II X2 250 Processor Percentage of memory in use: 54% Total physical RAM: 3327.18 MB Available physical RAM: 1519.9 MB Total Pagefile: 6652.66 MB Available Pagefile: 4649.26 MB Total Virtual: 2047.88 MB Available Virtual: 1896.6 MB ==================== Drives ================================ Drive c: (System) (Fixed) (Total:78.03 GB) (Free:52.42 GB) NTFS Drive d: (Temp) (Fixed) (Total:219.96 GB) (Free:164.7 GB) NTFS Drive e: (Privat) (Fixed) (Total:48.83 GB) (Free:15.41 GB) NTFS Drive f: (Musik) (Fixed) (Total:833.84 GB) (Free:832.61 GB) NTFS Drive g: (Software) (Fixed) (Total:48.83 GB) (Free:23.3 GB) NTFS Drive x: () (Network) (Total:1374.26 GB) (Free:580.2 GB) Drive z: () (Network) (Total:1374.26 GB) (Free:580.2 GB) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: D9D0D9D0) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=78 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=220 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: E8900690) Partition 1: (Not Active) - (Size=48.8 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=833.8 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=48.8 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Hier der Log von GMER: Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2015-03-01 13:52:05 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD3200AVVS-63L2B0 rev.01.03A01 298,09GB Running: Gmer-19357.exe; Driver: C:\Users\Administrator\AppData\Local\Temp\pgddqpog.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0x90C50AC4] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwAllocateVirtualMemory [0x90D0C0BA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x90C515A2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0x90C5D63C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0x90C5D688] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x90C5D822] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0x90C5D5AA] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateSection [0x90D0C494] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x90C5D5F2] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateThread [0x90D0C724] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateThreadEx [0x90D0C80E] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0x90C5D7DC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x90C52390] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x90C50B2A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0x90C55B86] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0x90C50716] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0x90D0C574] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x90C50B90] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x90C55F7C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x90C52E78] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0x90C5D666] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0x90C5D6AA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x90C5D846] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0x90C5D5D0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0x90C5547E] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0x90C5D75A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x90C5D61A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0x90C5586A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0x90C5D800] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x90D0C312] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0x90C52CEC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThreadEx [0x90C529FA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x90C50BF6] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0x90C50C5C] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwSetContextThread [0x90D0C670] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x90C507B0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x90C50982] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0x90C50910] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0x90C5255A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0x90C526BC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x90C50A0A] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwTerminateProcess [0x90D0C3E0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0x90C521EA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0x90C50CC2] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwWriteVirtualMemory [0x90D0C244] ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwRequestPort + 14A9 82C3DE65 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82C77812 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 82C7EA30 4 Bytes [C4, 0A, C5, 90] .text ntkrnlpa.exe!KeRemoveQueueEx + 10F3 82C7EA58 4 Bytes [BA, C0, D0, 90] .text ntkrnlpa.exe!KeRemoveQueueEx + 1153 82C7EAB8 4 Bytes [A2, 15, C5, 90] .text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 82C7EB0C 8 Bytes [3C, D6, C5, 90, 88, D6, C5, ...] {CMP AL, 0xd6; LDS EDX, [EAX-0x6f3a2978]} .text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 82C7EB18 4 Bytes [22, D8, C5, 90] .text ... PAGE ntkrnlpa.exe!ZwReplyWaitReceivePortEx + 108 82E3A9BF 4 Bytes CALL 90C5355F \SystemRoot\system32\drivers\aswSnx.sys PAGE ntkrnlpa.exe!ZwAlpcSendWaitReceivePort + 122 82E54748 4 Bytes CALL 90C53575 \SystemRoot\system32\drivers\aswSnx.sys .text C:\Windows\system32\DRIVERS\atikmdag.sys section is writeable [0x93A06000, 0x3C8045, 0xE8000020] ---- User code sections - GMER 2.1 ---- .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] ntdll.dll!NtCreateFile 772555E8 5 Bytes JMP 5DEB43A3 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] ntdll.dll!NtFlushBuffersFile 77255978 5 Bytes JMP 5DEB40E3 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] ntdll.dll!NtQueryFullAttributesFile 77256008 5 Bytes JMP 5DEB421B C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] ntdll.dll!NtReadFile 772562D8 5 Bytes JMP 5DEB411D C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] ntdll.dll!NtReadFileScatter 772562E8 5 Bytes JMP 5E1CD260 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] ntdll.dll!NtWriteFile 77256A88 5 Bytes JMP 5DEB4547 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] ntdll.dll!NtWriteFileGather 77256A98 5 Bytes JMP 5E1CD2B0 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] ntdll.dll!LdrUnloadDll 7726C8EE 5 Bytes JMP 000703FC .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] ntdll.dll!LdrLoadDll 772722BE 5 Bytes JMP 698C9662 C:\Program Files\Mozilla Firefox\mozglue.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] KERNEL32.dll!K32GetDeviceDriverBaseNameW + 5D 76FB94E6 7 Bytes JMP 5E1B8526 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] KERNEL32.dll!QueryPerformanceCounter + 13 76FBC4F5 7 Bytes JMP 5E1B9C50 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] KERNEL32.dll!LoadAppInitDlls + 355 76FBF5B6 7 Bytes JMP 5DF61F21 C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] user32.dll!GetWindowInfo 76744B2E 5 Bytes JMP 5EC499FF C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Mozilla Firefox\firefox.exe[1264] GDI32.dll!GetViewportOrgEx + 26C 773D884B 7 Bytes JMP 5E1B6CFC C:\Program Files\Mozilla Firefox\xul.dll .text C:\Program Files\Avast\AvastSvc.exe[1548] kernel32.dll!SetUnhandledExceptionFilter 76FBF5BB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text C:\Program Files\Avast\avastui.exe[2292] kernel32.dll!SetUnhandledExceptionFilter 76FBF5BB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text C:\Windows\Explorer.EXE[2344] SHELL32.dll!SHFileOperationW 75B396EC 5 Bytes JMP 10001102 C:\Program Files\Unlocker\UnlockerHook.dll ---- EOF - GMER 2.1 ---- Malware-Log: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 23.02.2015 Suchlauf-Zeit: 16:42:00 Logdatei: Malware23.2.15.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2015.02.23.04 Rootkit Datenbank: v2015.02.22.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: Administrator Suchlauf-Art: Benutzerdefinierter Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 626542 Verstrichene Zeit: 1 Std, 37 Min, 26 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 0 (Keine schädliche Elemente erkannt) Registrierungswerte: 0 (Keine schädliche Elemente erkannt) Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 0 (Keine schädliche Elemente erkannt) Dateien: 0 (Keine schädliche Elemente erkannt) Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) |
Themen zu Avast blockt verschiedene Seiten, svchost beteiligt |
adware, antivirus, askbar, blackled.info, bonjour, browser, converter, defender, ebay, firefox, flash player, helper, homepage, mozilla, mp3, musik, realtek, registry, scan, schutz, security, services.exe, software, svchost, svchost.exe, windows, wma |