![]() |
|
Log-Analyse und Auswertung: RE-EL60022132 *doc Mailanhang Dummerweise geönffnet und gescheichert!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() RE-EL60022132 *doc Mailanhang Dummerweise geönffnet und gescheichert! Hallo, kurze Vorstellung: neu hier, 46 Jahre und dummerweise im Büro anscheinend einem Trojaner aufgesessen! Ich hatte heute früh eine Mail mit *doc Anhang die anscheinend von meinem Chef kam. Im 'Halbschlaf' versucht das Dokument zu öffnen und dummerweise auch noch Inhalt aktivieren usw. gedrückt, gespeichert und nochmal das Gleiche! Erst dann sah ich genauer hin und merkte dass icch tatsächlich in die Falle getappt war. Der Avast Scanner fand nichts, online hat Kaspersky aber Trojan-Downloader.MSOffice.SLoad gefunden. https://www.virustotal.com/#/file/7bc72a8b1db7005daa42ad4ba06c4626876b489f89394e9acd445c6383ea0922/detection und https://virusscan.jotti.org/de-DE/filescanjob/6x8fi0c59h Hijackthis hier: Code:
ATTFilter Logfile of HijackThis Fork (Beta) by Alex Dragokas v.2.8.0.4 Platform: x64 Windows 10 (Pro), 10.0.17134.345 (ReleaseId: 1803), Service Pack: 0 Time: 06.11.2018 - 08:57 (UTC+01:00) Language: OS: German (0x407). Display: German (0x407). Non-Unicode: German (0x407) Elevated: Yes Ran by: Jens (group: Administrator) on DESKTOP-0PI5060, FirstRun: no Firefox: 63.0.1.6877 Edge: 11.0.17134.345 Internet Explorer: 11.0.17134.1 Default: "C:\Program Files\Mozilla Firefox\firefox.exe" -osint -url "%1" (Firefox) Boot mode: Normal Running processes: Number | Path 1 C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe 1 C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe 1 C:\Program Files (x86)\Citrix\ICA Client\SelfServicePlugin\SelfServicePlugin.exe 1 C:\Program Files (x86)\Citrix\ICA Client\concentr.exe 1 C:\Program Files (x86)\Citrix\ICA Client\redirector.exe 1 C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe 1 C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 1 C:\Program Files (x86)\Common Files\Java\Java Update\jucheck.exe 1 C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe 1 C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe 1 C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXRCV.exe 1 C:\Program Files (x86)\EPSON Software\FAX Utility\FUFAXSTM.exe 1 C:\Program Files (x86)\FreePDF_XP\fpassist.exe 1 C:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe 1 C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe 1 C:\Program Files (x86)\HP\HP MAC Address Manager\hpMAMSrv.exe 1 C:\Program Files (x86)\HP\HP Notifications\HPNotifications.exe 1 C:\Program Files (x86)\HP\HP ProtectTools Security Manager\Bin\DPAgent.exe 1 C:\Program Files (x86)\HP\Shared\hpqwmiex.exe 1 C:\Program Files (x86)\Hardcopy\hardcopy.exe 1 C:\Program Files (x86)\Hardcopy\hcdll2_ex_Win32.exe 1 C:\Program Files (x86)\Hardcopy\hcdll2_ex_x64.exe 1 C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe 1 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe 1 C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe 1 C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe 1 C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe 1 C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe 1 C:\Program Files (x86)\PDF Architect 6 Manager\PDF Architect 6\Architect Manager.exe 1 C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe 1 C:\Program Files (x86)\inSign-Offline\InsignHotspotServiceHost.exe 1 C:\Program Files (x86)\inSign\UPadBridge\openjre\launch4j-tmp\inSign UPad-Bridge.exe 1 C:\Program Files\AVAST Software\Avast\AvastSvc.exe 1 C:\Program Files\AVAST Software\Avast\AvastUI.exe 1 C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe 1 C:\Program Files\Bonjour\mDNSResponder.exe 1 C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe 1 C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeClickToRun.exe 1 C:\Program Files\Conexant\Flow\Flow.exe 1 C:\Program Files\Conexant\SA3\HP-NB-AIO\SmartAudio3.exe 1 C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe 1 C:\Program Files\HPCommRecovery\HPCommRecovery.exe 1 C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpAgent.exe 1 C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpCardEngine.exe 1 C:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpHostW.exe 1 C:\Program Files\HP\HP Velocity\systray.exe 1 C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe 1 C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe 1 C:\Program Files\Intel\WiFi\bin\EvtEng.exe 1 C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe 6 C:\Program Files\Mozilla Firefox\firefox.exe 2 C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe 1 C:\Program Files\PDF Architect 6\creator\common\creator-ws.exe 1 C:\Program Files\Synaptics\SynTP\SynTPEnh.exe 1 C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe 1 C:\Program Files\Synaptics\SynTP\SynTPHelper.exe 1 C:\Program Files\Windows Defender\MSASCuiL.exe 1 C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\SkypeApp.exe 1 C:\Program Files\WindowsApps\Microsoft.SkypeApp_14.33.41.0_x64__kzf8qxf38zg5c\SkypeBackgroundHost.exe 1 C:\Users\Jens\AppData\Local\Microsoft\OneDrive\OneDrive.exe 1 C:\Users\Jens\Downloads\HiJackThis_v2.8.0.4.exe 1 C:\Users\Jens\Downloads\MemCompression 1 C:\Users\Jens\Downloads\Registry 1 C:\Windows\CxSvc\CxMonSvc.exe 1 C:\Windows\CxSvc\CxUtilSvc.exe 1 C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe 1 C:\Windows\SysWOW64\UIUSrv.exe 1 C:\Windows\System32\DriverStore\FileRepository\ki124451.inf_amd64_1b1f9cf580c10ff8\IntelCpHDCPSvc.exe 1 C:\Windows\System32\DriverStore\FileRepository\ki124451.inf_amd64_1b1f9cf580c10ff8\IntelCpHeciSvc.exe 1 C:\Windows\System32\DriverStore\FileRepository\ki124451.inf_amd64_1b1f9cf580c10ff8\igfxCUIService.exe 1 C:\Windows\System32\DriverStore\FileRepository\ki124451.inf_amd64_1b1f9cf580c10ff8\igfxEM.exe 1 C:\Windows\System32\Intel\DPTF\dptf_helper.exe 1 C:\Windows\System32\Intel\DPTF\esif_uf.exe 1 C:\Windows\System32\MicTray64.exe 4 C:\Windows\System32\RuntimeBroker.exe 1 C:\Windows\System32\SearchIndexer.exe 1 C:\Windows\System32\SecurityHealthService.exe 1 C:\Windows\System32\SgrmBroker.exe 2 C:\Windows\System32\WUDFHost.exe 1 C:\Windows\System32\audiodg.exe 1 C:\Windows\System32\cAVS\Intel(R) Audio Service\IntelAudioService.exe 1 C:\Windows\System32\conhost.exe 2 C:\Windows\System32\csrss.exe 1 C:\Windows\System32\ctfmon.exe 1 C:\Windows\System32\dasHost.exe 2 C:\Windows\System32\dllhost.exe 1 C:\Windows\System32\dwm.exe 1 C:\Windows\System32\escsvc64.exe 2 C:\Windows\System32\fontdrvhost.exe 1 C:\Windows\System32\fpCSEvtSvc.exe 1 C:\Windows\System32\ibtsiva.exe 1 C:\Windows\System32\lsass.exe 1 C:\Windows\System32\services.exe 1 C:\Windows\System32\sihost.exe 1 C:\Windows\System32\smartscreen.exe 1 C:\Windows\System32\smss.exe 2 C:\Windows\System32\spool\drivers\x64\3\E_YATIQCE.EXE 1 C:\Windows\System32\spoolsv.exe 75 C:\Windows\System32\svchost.exe 1 C:\Windows\System32\taskhostw.exe 1 C:\Windows\System32\valWBFPolicyService.exe 1 C:\Windows\System32\wbem\WmiPrvSE.exe 2 C:\Windows\System32\wbem\unsecapp.exe 1 C:\Windows\System32\wininit.exe 1 C:\Windows\System32\winlogon.exe 1 C:\Windows\System32\wlanext.exe 1 C:\Windows\SystemApps\Microsoft.Windows.Cortana_cw5n1h2txyewy\SearchUI.exe 1 C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe 1 C:\Windows\explorer.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main: [Default_Page_URL] = hxxp://hp17win10.msn.com/?pc=HCTE R0 - HKCU\Software\Microsoft\Internet Explorer\Main: [Start Page] = hxxp://www.bing.com/?pc=COSP&ptag=D031918-N0690A6B219395BABB4E59ADF&form=CONMHP&conlogo=CT3332005 R0 - HKLM\Software\Microsoft\Internet Explorer\Main: [Default_Page_URL] = hxxp://hp17win10.msn.com/?pc=HCTE R0 - HKLM\Software\Microsoft\Internet Explorer\Main: [Start Page] = hxxp://hp17win10.msn.com/?pc=HCTE R4 - SearchScopes: HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A} = hxxp://www.bing.com/search?pc=COSP&ptag=D031918-A6B219395BABB4E59ADF&form=CONBDF&conlogo=CT3332005&q={searchTerms} - Bing F2 - HKLM\..\WinLogon: [UserInit] = C:\Windows\system32\userinit.exe,c:\Program Files (x86)\HP\HP ProtectTools Security Manager\Bin\DPAgent.exe, O2 - HKLM\..\BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll O2-32 - HKLM\..\BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll O2-32 - HKLM\..\BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll O2-32 - HKLM\..\BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll O2-32 - HKLM\..\BHO: PDF Architect 6 Helper - {9FD094B1-A4BF-415A-82AE-8C2845D0B769} - C:\Program Files (x86)\PDF Architect 6\creator\plugins\IEAddin\creator-ie-helper.dll O3-32 - HKLM\..\Toolbar: PDF Architect 6 Toolbar - {E8536605-CA24-4DFF-B1BC-316EE27F6DF7} - C:\Program Files (x86)\PDF Architect 6\creator\plugins\IEAddin\creator-ie-plugin.dll O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] = C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIQCE.EXE /EPT "EPLTarget\P0000000000000000" /M "WF-4740 Series" O4 - HKCU\..\Run: [EPLTarget\P0000000000000001] = C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YATIQCE.EXE /EPT "EPLTarget\P0000000000000001" /M "WF-4740 Series" O4 - HKCU\..\Run: [OneDrive] = C:\Users\Jens\AppData\Local\Microsoft\OneDrive\OneDrive.exe /background O4 - HKCU\..\Run: [Steam] = C:\Program Files (x86)\Steam\steam.exe -silent O4 - HKCU\..\Run: [Web Companion] = C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize O4 - HKLM\..\StartupApproved\Run32: [EEventManager] (1601/01/01) = C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe O4 - HKLM\..\StartupApproved\Run32: [FUFAXRCV] (1601/01/01) = C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXRCV.exe O4 - HKLM\..\StartupApproved\Run32: [FUFAXSTM] (1601/01/01) = C:\Program Files (x86)\Epson Software\FAX Utility\FUFAXSTM.exe O4 - HKLM\..\StartupApproved\Run32: [FreePDF Assistant] (1601/01/01) = C:\Program Files (x86)\FreePDF_XP\fpassist.exe O4 - HKLM\..\StartupApproved\Run32: [HPNotifications] (1601/01/01) = C:\Program Files (x86)\HP\HP Notifications\HPNotifications.exe O4 - HKLM\..\StartupApproved\Run32: [SunJavaUpdateSched] (1601/01/01) = C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe O4 - HKLM\..\StartupApproved\Run: [AvastUI.exe] (1601/01/01) = C:\Program Files\AVAST Software\Avast\AvLaunch.exe /gui O4 - HKLM\..\StartupApproved\Run: [IAStorIcon] (1601/01/01) = C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60 O4 - HKLM\..\StartupApproved\Run: [RtsCM] (1601/01/01) = C:\WINDOWS\RTSCM64.EXE O4 - HKLM\..\StartupApproved\Run: [SecurityHealth] (1601/01/01) = C:\Program Files\Windows Defender\MSASCuiL.exe O4 - HKLM\..\StartupApproved\StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\HP Velocity.lnk -> C:\Program Files\HP\HP Velocity\systray.exe (1601/01/01) O4 - HKLM\..\StartupApproved\StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Hardcopy.LNK -> C:\Program Files (x86)\Hardcopy\hardcopy.exe (1601/01/01) O4 - HKLM\..\StartupApproved\StartupFolder: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\UPadBridge.lnk -> C:\Program Files (x86)\inSign\UPadBridge\inSign UPad-Bridge.exe (1601/01/01) O4 - HKU\S-1-5-19\..\RunOnce: [WAB Migrate] = C:\Program Files\Windows Mail\wab.exe /Upgrade O4 - HKU\S-1-5-20\..\RunOnce: [WAB Migrate] = C:\Program Files\Windows Mail\wab.exe /Upgrade O4-32 - HKLM\..\Run: [ConnectionCenter] = C:\Program Files (x86)\Citrix\ICA Client\concentr.exe /startup O4-32 - HKLM\..\Run: [Redirector] = C:\Program Files (x86)\Citrix\ICA Client\redirector.exe /startup O9 - Button: HKLM\..\{25510184-5A38-4A99-B273-DCA8EEF6CD08} - Startet das Hilfsprogramm HP-Netzwerktest, das Ihnen bei der Behebung von Netzwerkproblemen hilft. - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9 - Tools menu item: HKLM\..\{25510184-5A38-4A99-B273-DCA8EEF6CD08} - HP-Netzwerktest - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9-32 - Button: HKLM\..\{25510184-5A38-4A99-B273-DCA8EEF6CD08} - Startet das Hilfsprogramm HP-Netzwerktest, das Ihnen bei der Behebung von Netzwerkproblemen hilft. - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O9-32 - Tools menu item: HKLM\..\{25510184-5A38-4A99-B273-DCA8EEF6CD08} - HP-Netzwerktest - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe O15 - Trusted Zone: HKCU - *.localhost O15 - Trusted Zone: HKCU - hxxp://webcompanion.com O15 - Trusted Zone: HKU\.DEFAULT - *.localhost O15 - Trusted Zone: HKU\.DEFAULT - hxxp://webcompanion.com O17 - DHCP DNS 1: 192.168.1.254 O18 - Filter hijack: ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica; charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=ISO-8859-1 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=MS936 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=MS949 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=MS950 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=UTF-8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=UTF8 - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O18 - Filter: application/x-ica;charset=euc-jp - {CFB6322E-CC85-4d1b-82C7-893888A236BC} - C:\Program Files (x86)\Citrix\ICA Client\IcaMimeFilter.dll O21 - HKLM\..\ShellIconOverlayIdentifiers: avast - {472083B0-C522-11CF-8763-00608CC02F24} - C:\Program Files\AVAST Software\Avast\ashShA64.dll O22 - Task (Job): (Not scheduled) EPSON WF-4740 Series Update {165741EF-BB4D-48DC-BEF6-2741536E5F83}.job - C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSQCE.EXE /EXE:"{165741EF-BB4D-48DC-BEF6-2741536E5F83}" /F:"Update" O22 - Task (Job): (Not scheduled) EPSON WF-4740 Series Update {EB035632-5461-4D14-85D8-3B5105A1AC70}.job - C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSQCE.EXE /EXE:"{EB035632-5461-4D14-85D8-3B5105A1AC70}" /F:"Update" O22 - Task (Job): (Not scheduled) G2MUpdateTask-S-1-5-21-3642975892-4094710876-1693064538-1002.job - C:\Users\Jens\AppData\Local\GoToMeeting\10996\g2mupdate.exe O22 - Task (Job): (Not scheduled) G2MUploadTask-S-1-5-21-3642975892-4094710876-1693064538-1002.job - C:\Users\Jens\AppData\Local\GoToMeeting\10996\g2mupload.exe O22 - Task (Job): (Not scheduled) HPCeeScheduleForJens.job - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForJens (null) O22 - Task (Job): (Not scheduled) TrackerAutoUpdate.job - C:\Program Files\Tracker Software\Update\TrackerUpdate.exe -CheckUpdate O22 - Task: (disabled) \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceLocationRightsChange - {AE31B729-D5FD-401E-AF42-784074835AFE},-RegisterDevice -SettingChange - C:\WINDOWS\system32\DeviceDirectoryClient.dll (Microsoft) O22 - Task: (disabled) \Microsoft\Windows\HelloFace\FODCleanupTask - C:\WINDOWS\System32\WinBioPlugIns\FaceFodUninstaller.exe (Microsoft) O22 - Task: (disabled) \Microsoft\Windows\InstallService\WakeUpAndContinueUpdates - {0DC331EE-8438-49D5-A721-E10B937CE459} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft) O22 - Task: (disabled) \Microsoft\Windows\InstallService\WakeUpAndScanForUpdates - {D5A04D91-6FE6-4FE4-A98A-FEB4500C5AF7} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft) O22 - Task: Adobe Acrobat Update Task - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe O22 - Task: Avast Emergency Update - C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe O22 - Task: EPSON WF-4740 Series Update {165741EF-BB4D-48DC-BEF6-2741536E5F83} - C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSQCE.EXE /EXE:"{165741EF-BB4D-48DC-BEF6-2741536E5F83}" /F:"Update" O22 - Task: EPSON WF-4740 Series Update {EB035632-5461-4D14-85D8-3B5105A1AC70} - C:\WINDOWS\system32\spool\DRIVERS\x64\3\E_YTSQCE.EXE /EXE:"{EB035632-5461-4D14-85D8-3B5105A1AC70}" /F:"Update" O22 - Task: ExclusiveTool - C:\Program Files (x86)\DSDCS\InputMapper\ExclusiveModeTool.exe /a O22 - Task: G2MUpdateTask-S-1-5-21-3642975892-4094710876-1693064538-1002 - C:\Users\Jens\AppData\Local\GoToMeeting\10996\g2mupdate.exe O22 - Task: G2MUploadTask-S-1-5-21-3642975892-4094710876-1693064538-1002 - C:\Users\Jens\AppData\Local\GoToMeeting\10996\g2mupload.exe O22 - Task: HPCeeScheduleForJens - C:\Program Files (x86)\Hewlett-Packard\HP Ceement\HPCEE.exe HPCeeScheduleForJens (null) O22 - Task: HPEA3JOBS - C:\Program Files\HP\HP ePrint\hpeprint.exe /CheckJobs (file missing) O22 - Task: HPJumpStartLaunch - C:\Program Files (x86)\HP\HP JumpStart Launch\HPJumpStartLaunch.exe O22 - Task: NvProfileUpdaterDaily_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe O22 - Task: NvProfileUpdaterOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files\NVIDIA Corporation\Update Core\NvProfileUpdater64.exe O22 - Task: NvTmMon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmMon.exe O22 - Task: NvTmRepOnLogon_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe --logon O22 - Task: NvTmRep_{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8} - C:\Program Files (x86)\NVIDIA Corporation\Update Core\NvTmRep.exe O22 - Task: TrackerAutoUpdate - C:\Program Files\Tracker Software\Update\TrackerUpdate.exe -CheckUpdate O22 - Task: \Avast Software\Overseer - C:\Program Files\Common Files\AVAST Software\Overseer\overseer.exe /from_scheduler:1 O22 - Task: \HP\HP Hotkey Support\Start QLBController Process - C:\Program Files (x86)\HP\HP Hotkey Support\QLBController.exe (file missing) O22 - Task: \Hewlett-Packard\HP Active Health\HP Active Health Scan (HPSA) - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPActiveHealth\ActiveHealth.exe -task -source HPSA O22 - Task: \Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe /taskrestart O22 - Task: \Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Report - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSFReport.exe /send O22 - Task: \Hewlett-Packard\HP Support Assistant\HP Support Solutions Framework Updater - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\Modules\HPSSFUpdater.exe /u O22 - Task: \Hewlett-Packard\HP Support Assistant\PC Health Analysis - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe /L Analysis O22 - Task: \Hewlett-Packard\HP Support Assistant\Product Configurator - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\ProductConfig.exe /noreport O22 - Task: \Hewlett-Packard\HP Support Assistant\WarrantyChecker - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe O22 - Task: \Hewlett-Packard\HP Support Assistant\WarrantyChecker_DeviceScan - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPWarrantyCheck\HPWarrantyChecker.exe /DeviceScanR6 O22 - Task: \Microsoft\Office\Office Automatic Updates 2.0 - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /frequentupdate SCHEDULEDTASK displaylevel=False (Microsoft) O22 - Task: \Microsoft\Office\Office ClickToRun Service Monitor - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeC2RClient.exe /WatchService (Microsoft) O22 - Task: \Microsoft\Office\Office Feature Updates - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe (Microsoft) O22 - Task: \Microsoft\Office\Office Feature Updates Logon - C:\Program Files (x86)\Microsoft Office\root\VFS\ProgramFilesCommonX86\Microsoft Shared\Office16\sdxhelper.exe /onlogon (Microsoft) O22 - Task: \Microsoft\Office\OfficeBackgroundTaskHandlerLogon - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe (Microsoft) O22 - Task: \Microsoft\Office\OfficeBackgroundTaskHandlerRegistration - C:\Program Files (x86)\Microsoft Office\root\Office16\officebackgroundtaskhandler.exe (Microsoft) O22 - Task: \Microsoft\Windows\Conexant\FLOW - C:\Program Files\CONEXANT\FLOW\SACpl.exe /sa3 /uid:FLOW /delay:30 O22 - Task: \Microsoft\Windows\Conexant\MicTray - C:\Windows\System32\MicTray64.exe O22 - Task: \Microsoft\Windows\DeviceDirectoryClient\RegisterDevicePolicyChange - {AE31B729-D5FD-401E-AF42-784074835AFE},-RegisterDevice -SettingChange - C:\WINDOWS\system32\DeviceDirectoryClient.dll (Microsoft) O22 - Task: \Microsoft\Windows\DeviceDirectoryClient\RegisterDeviceProtectionStateChanged - {AE31B729-D5FD-401E-AF42-784074835AFE},-RegisterDevice -ProtectionStateChanged -FreeNetworkOnly - C:\WINDOWS\system32\DeviceDirectoryClient.dll (Microsoft) O22 - Task: \Microsoft\Windows\DirectX\DXGIAdapterCache - C:\WINDOWS\system32\dxgiadaptercache.exe (Microsoft) O22 - Task: \Microsoft\Windows\InstallService\ScanForUpdates - {A558C6A5-B42B-4C98-B610-BF9559143139} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft) O22 - Task: \Microsoft\Windows\InstallService\ScanForUpdatesAsUser - {DDAFAEA2-8842-4E96-BADE-D44A8D676FDB} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft) O22 - Task: \Microsoft\Windows\InstallService\SmartRetry - {F3A219C3-2698-4CBF-9C07-037EDB8E72E6} - C:\Windows\System32\InstallServiceTasks.dll (Microsoft) O22 - Task: \Microsoft\Windows\LanguageComponentsInstaller\ReconcileLanguageResources - {D0582E3B-3126-4CAA-9155-AC37C912A489} - C:\WINDOWS\System32\LanguageOverlayServer.dll (Microsoft) O22 - Task: \Microsoft\Windows\SMB\UninstallSMB1ClientTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Client" O22 - Task: \Microsoft\Windows\SMB\UninstallSMB1ServerTask - C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe -ExecutionPolicy Unrestricted -NonInteractive -NoProfile -WindowStyle Hidden "& C:\WINDOWS\system32\WindowsPowerShell\v1.0\Modules\SmbShare\DisableUnusedSmb1.ps1 -Scenario Server" O22 - Task: \Microsoft\Windows\Speech\HeadsetButtonPress - C:\WINDOWS\system32\speech_onecore\common\SpeechRuntime.exe StartedFromTask (Microsoft) O22 - Task: \Microsoft\Windows\UpdateOrchestrator\UpdateAssistant - C:\WINDOWS\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV13SIH:{} (Microsoft) O22 - Task: \Microsoft\Windows\UpdateOrchestrator\UpdateAssistantCalendarRun - C:\WINDOWS\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV13SIH:{} /CalendarRun (Microsoft) O22 - Task: \Microsoft\Windows\UpdateOrchestrator\UpdateAssistantWakeupRun - C:\WINDOWS\UpdateAssistant\UpdateAssistant.exe /ClientID Win10Upgrade:VNL:NHV13SIH:{} /WakeupRun (Microsoft) O22 - Task: \Microsoft\Windows\WaaSMedic\PerformRemediation - {72566E27-1ABB-4EB3-B4F0-EB431CB1CB32},None - C:\WINDOWS\System32\WaaSMedicSvc.dll (Microsoft) O22 - Task: \Microsoft\Windows\Windows Defender\Windows Defender Cache Maintenance - C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCacheMaintenance O22 - Task: \Microsoft\Windows\Windows Defender\Windows Defender Cleanup - C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdCleanup O22 - Task: \Microsoft\Windows\Windows Defender\Windows Defender Scheduled Scan - C:\Program Files\Windows Defender\MpCmdRun.exe Scan -ScheduleJob O22 - Task: \Microsoft\Windows\Windows Defender\Windows Defender Verification - C:\Program Files\Windows Defender\MpCmdRun.exe -IdleTask -TaskName WdVerification O22 - Task: hcdll2_ex_Win32 - "C:\Program Files (x86)\Hardcopy"\hcdll2_ex_Win32.exe (file missing) O22 - Task: hcdll2_ex_x64 - "C:\Program Files (x86)\Hardcopy"\hcdll2_ex_x64.exe (file missing) O23 - Service R2: Adobe Acrobat Update Service - (AdobeARMservice) - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service R2: Avast Antivirus - (avast! Antivirus) - C:\Program Files\AVAST Software\Avast\AvastSvc.exe O23 - Service R2: Conexant UIU Service - (UIUService) - C:\WINDOWS\system32\UIUSrv.exe (file missing) O23 - Service R2: CxMonSvc - C:\WINDOWS\CxSvc\CxMonSvc.exe O23 - Service R2: CxUtilSvc - C:\WINDOWS\CxSvc\CxUtilSvc.exe O23 - Service R2: Dienst "Bonjour" - (Bonjour Service) - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service R2: DigitalPersona Authentifizierungsdienst - (DpHost) - c:\Program Files\HP\HP ProtectTools Security Manager\Bin\DpHostW.exe O23 - Service R2: Epson Scanner Service - (EpsonScanSvc) - C:\WINDOWS\system32\EscSvc64.exe O23 - Service R2: EpsonCustomerResearchParticipation - C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe O23 - Service R2: HP Comm Recovery - (HP Comm Recover) - C:\Program Files\HPCommRecovery\HPCommRecovery.exe O23 - Service R2: HP JumpStart Bridge - (HPJumpStartBridge) - c:\Program Files (x86)\HP\HP JumpStart Bridge\HPJumpStartBridge.exe O23 - Service R2: HP MAC Address Manager Service - (HPMAMSrv) - C:\Program Files (x86)\HP\HP MAC Address Manager\hpMAMSrv.exe O23 - Service R2: HP Support Solutions Framework Service - (HPSupportSolutionsFrameworkService) - C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFrameworkService.exe O23 - Service R2: Intel Bluetooth Service - (ibtsiva) - C:\WINDOWS\system32\ibtsiva.exe O23 - Service R2: Intel(R) Audio Service - (IntelAudioService) - C:\WINDOWS\system32\cAVS\Intel(R) Audio Service\IntelAudioService.exe O23 - Service R2: Intel(R) Content Protection HDCP Service - (cplspcon) - C:\WINDOWS\System32\DriverStore\FileRepository\ki124451.inf_amd64_1b1f9cf580c10ff8\IntelCpHDCPSvc.exe O23 - Service R2: Intel(R) Dynamic Application Loader Host Interface Service - (jhi_service) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service R2: Intel(R) Dynamic Platform and Thermal Framework service - (esifsvc) - C:\WINDOWS\system32\Intel\DPTF\esif_uf.exe O23 - Service R2: Intel(R) HD Graphics Control Panel Service - (igfxCUIService2.0.0.0) - C:\WINDOWS\System32\DriverStore\FileRepository\ki124451.inf_amd64_1b1f9cf580c10ff8\igfxCUIService.exe O23 - Service R2: Intel(R) Management and Security Application Local Management Service - (LMS) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service R2: Intel(R) PROSet/Wireless Event Log - (EvtEng) - C:\Program Files\Intel\WiFi\bin\EvtEng.exe O23 - Service R2: Intel(R) PROSet/Wireless Registry Service - (RegSrvc) - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe O23 - Service R2: Intel(R) PROSet/Wireless Zero Configuration Service - (ZeroConfigService) - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe O23 - Service R2: Intel(R) Rapid Storage Technology - (IAStorDataMgrSvc) - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service R2: Microsoft Office Click-to-Run Service - (ClickToRunSvc) - C:\Program Files\Common Files\Microsoft Shared\ClickToRun\OfficeClickToRun.exe /service O23 - Service R2: NVIDIA Display Container LS - (NVDisplay.ContainerLocalSystem) - C:\Program Files\NVIDIA Corporation\Display.NvContainer\NVDisplay.Container.exe -s NVDisplay.ContainerLocalSystem -f "C:\ProgramData\NVIDIA\NVDisplay.ContainerLocalSystem.log" -l 3 -d "C:\Program Files\NVIDIA Corporation\Display.NvContainer\plugins\LocalSystem" -r -p 30000 O23 - Service R2: NVIDIA Telemetry Container - (NvTelemetryContainer) - C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\NvTelemetryContainer.exe -s NvTelemetryContainer -f "C:\ProgramData\NVIDIA\NvTelemetryContainer.log" -l 3 -d "C:\Program Files (x86)\NVIDIA Corporation\NvTelemetry\plugin" O23 - Service R2: PDF Architect 6 Creator - C:\Program Files\PDF Architect 6\creator\common\creator-ws.exe O23 - Service R2: PDF Architect 6 Manager - C:\Program Files (x86)\PDF Architect 6 Manager\PDF Architect 6\Architect Manager.exe O23 - Service R2: SynTPEnh Caller Service - (SynTPEnhService) - C:\Program Files\Synaptics\SynTP\SynTPEnhService.exe O23 - Service R2: Synaptics FP WBF Policy Service - (valWBFPolicyService) - C:\WINDOWS\system32\valWBFPolicyService.exe O23 - Service R2: TeamViewer 13 - (TeamViewer) - C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe O23 - Service R2: WC Assistant - (WCAssistantService) - C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe O23 - Service R2: chip 1-click download service - (chip1click) - C:\Program Files (x86)\Chip Digital GmbH\chip1click\chip 1-click installer.exe O23 - Service R2: fpCSEvtSvc - (fpCsEvtSvc) - C:\WINDOWS\system32\fpCSEvtSvc.exe O23 - Service R2: inSign HotspotService - (inSignHSP) - C:\Program Files (x86)\inSign-Offline\InsignHotspotServiceHost.exe O23 - Service R3: HP CASL Framework Service - (hpqcaslwmiex) - C:\Program Files (x86)\HP\Shared\hpqwmiex.exe O23 - Service R3: Intel(R) Content Protection HECI Service - (cphs) - C:\WINDOWS\System32\DriverStore\FileRepository\ki124451.inf_amd64_1b1f9cf580c10ff8\IntelCpHeciSvc.exe O23 - Service R3: aswbIDSAgent - C:\Program Files\AVAST Software\Avast\x64\aswidsagenta.exe O23 - Service S2: Intel(R) TPM Provisioning Service - C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\TPMProvisioningService.exe O23 - Service S3: AvastWscReporter - C:\Program Files\AVAST Software\Avast\wsc_proxy.exe /runassvc O23 - Service S3: HP Gerätesperre/Überwachung - (FLCDLOCK) - c:\windows\SysWOW64\flcdlock.exe O23 - Service S3: HP WorkWise - (HPWorkWise) - C:\Program Files (x86)\HP\HP WorkWise\HPWorkWiseService.exe O23 - Service S3: Intel(R) Capability Licensing Service TCP IP Interface - C:\Program Files\Intel\Intel(R) Management Engine Components\iCLS\SocketHeciServer.exe O23 - Service S3: Intel(R) Optane(TM) Memory Service - (iaStorAfsService) - C:\windows\IAStorAfsService\iaStorAfsService.exe O23 - Service S3: Mozilla Maintenance Service - (MozillaMaintenance) - C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe O23 - Service S3: PDF Architect 6 - C:\Program Files\PDF Architect 6\ws.exe O23 - Service S3: Steam Client Service - C:\Program Files (x86)\Common Files\Steam\SteamService.exe /RunAsService O23 - Service S3: Windows Defender Advanced Threat Protection-Dienst - (Sense) - C:\Program Files\Windows Defender Advanced Threat Protection\MsSense.exe O23 - Service S3: Windows Defender Antivirus Service - (WinDefend) - C:\Program Files\Windows Defender\MsMpEng.exe O23 - Service S3: Windows Defender Antivirus-Netzwerkinspektionsdienst - (WdNisSvc) - C:\Program Files\Windows Defender\NisSrv.exe O23 - Service S3: Wireless PAN DHCP Server - (MyWiFiDHCPDNS) - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe -- End of file - Time spent: 10 sec. - 66576 bytes, CRC32: FFFFFFFF. Sign: 㟭難 FAKE oder tatsächliches Problem? Schnelle Hilfe wäre super. Ich habe von diesem Latop keinen direkten Zugang auf den Firmenserver. Das wird über einen Despktop PC gemacht auf den ich mit dem Laptop per Teamviewer aufschalte. Die Verbindung war glaube ich aktiviert aber ich habe auf dem Dektop selbst nach Fund dieses Problems nichts mehr gemacht. BITTE schnelle Hilfe... Gruß Jens Geändert von cosinus (06.11.2018 um 09:33 Uhr) Grund: code tags |
Themen zu RE-EL60022132 *doc Mailanhang Dummerweise geönffnet und gescheichert! |
administrator, adobe, antivirus, avast, bho, bonjour, defender, explorer, hotkey, ics, kaspersky, mac, microsoft, monitor, mozilla, neu, nvidia, scan, security, software, speechruntime.exe, system, system32, tcp, trojaner, windows, windowsapps |