hab mein windows nochma rausgekramt und neu auf den pc gemacht. irgendwie sind aber noch alte daten vorhanden. das c-laufwerk fürs windows wurde also scheinbar 'nur' überspeichert und enthält einen alten restdatenbestand, was mich verunsichert in bezug darauf, ob der rechner denn nun sauber ist.
wichtige daten speicherte ich aber ulkigerweise sowieso zwei tage oder so, bevor mein rechner irgendwie was abbekommen hat, auf meiner externen festplatte. ob sie sauber ist, weiß ich aber nicht genau. den rechner (mehr oder weniger) platt machen schien mir daher einen versuch wert, denn die daten waren eh auf der externen gesichert und dort zudem vllt auch sauber, jedoch nicht unsauberer als die auf dem pc. mein avast fand vorhin irgendwas, aber das steht sicher in einem der logs. name ist geändert in "xxx". ganz ganz lieben dank schon einmal.
frst.txt Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02.01.2018
Ran by xxx (administrator) on xxx-PC (08-01-2018 19:41:23)
Running from C:\Users\xxx\Downloads
Loaded Profiles: xxx (Available Profiles: xxx)
Platform: Microsoft Windows 7 Professional (X86) Language: English (United States)
Internet Explorer Version 8 (Default browser: Chrome)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(Microsoft Corporation) C:\Program Files\Windows Media Player\wmplayer.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\aswidsagent.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Registry (Whitelisted) ===========================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvLaunch.exe [246120 2018-01-08] (AVAST Software)
HKLM\SOFTWARE\Policies\Microsoft\Windows Defender: Restriction <==== ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
Tcpip\Parameters: [DhcpNameServer] 213.211.192.34 213.187.64.1
Tcpip\..\Interfaces\{E7B74564-93E9-488E-A663-75DDBE077E72}: [DhcpNameServer] 213.211.192.34 213.187.64.1
Internet Explorer:
==================
HKU\S-1-5-21-3067330445-848040545-2019120767-1000\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://www.msn.com/de-de/?ocid=iehp
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll [2018-01-08] (AVAST Software)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2018-01-08] (Google Inc.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll [2018-01-08] (Google Inc.)
FireFox:
========
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-08] (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.33.7\npGoogleUpdate3.dll [2018-01-08] (Google Inc.)
Chrome:
=======
CHR Profile: C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default [2018-01-08]
CHR Extension: (Präsentationen) - C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2018-01-08]
CHR Extension: (Docs) - C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2018-01-08]
CHR Extension: (Google Drive) - C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2018-01-08]
CHR Extension: (YouTube) - C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2018-01-08]
CHR Extension: (Tabellen) - C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2018-01-08]
CHR Extension: (Google Docs Offline) - C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2018-01-08]
CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2018-01-08]
CHR Extension: (Google Mail) - C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2018-01-08]
CHR Extension: (Chrome Media Router) - C:\Users\xxx\AppData\Local\Google\Chrome\User Data\Default\Extensions\pkedcjkdefgpdelpbcmbmeomcjbeemfm [2018-01-08]
==================== Services (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R3 aswbIDSAgent; C:\Program Files\AVAST Software\Avast\aswidsagent.exe [5906816 2018-01-08] (AVAST Software)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [301168 2018-01-08] (AVAST Software)
S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [680960 2009-07-14] (Microsoft Corporation)
===================== Drivers (Whitelisted) ======================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R1 aswArPot; C:\Windows\System32\drivers\aswArPot.sys [158224 2018-01-08] (AVAST Software)
R1 aswbidsdriver; C:\Windows\System32\drivers\aswbidsdriverx.sys [255584 2018-01-08] (AVAST Software)
R0 aswbidsh; C:\Windows\System32\drivers\aswbidshx.sys [157376 2018-01-08] (AVAST Software)
R0 aswblog; C:\Windows\System32\drivers\aswblogx.sys [276696 2018-01-08] (AVAST Software)
R0 aswbuniv; C:\Windows\System32\drivers\aswbunivx.sys [50344 2018-01-08] (AVAST Software)
R1 aswHdsKe; C:\Windows\System32\drivers\aswHdsKe.sys [118144 2018-01-08] (AVAST Software)
S3 aswHwid; C:\Windows\System32\drivers\aswHwid.sys [42824 2018-01-08] (AVAST Software)
R2 aswMonFlt; C:\Windows\System32\drivers\aswMonFlt.sys [124408 2018-01-08] (AVAST Software)
R1 aswRdr; C:\Windows\System32\drivers\aswRdr2.sys [99528 2018-01-08] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\drivers\aswRvrt.sys [70832 2018-01-08] (AVAST Software)
R1 aswSnx; C:\Windows\System32\drivers\aswSnx.sys [783104 2018-01-08] (AVAST Software)
R1 aswSP; C:\Windows\System32\drivers\aswSP.sys [390272 2018-01-08] (AVAST Software)
R2 aswStm; C:\Windows\System32\drivers\aswStm.sys [151328 2018-01-08] (AVAST Software)
R0 aswVmm; C:\Windows\System32\drivers\aswVmm.sys [294680 2018-01-08] (AVAST Software)
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-01-08 19:41 - 2018-01-08 19:41 - 000006894 _____ C:\Users\xxx\Downloads\FRST.txt
2018-01-08 19:40 - 2018-01-08 19:41 - 000000000 ____D C:\FRST
2018-01-08 19:40 - 2018-01-08 19:40 - 001753600 _____ (Farbar) C:\Users\xxx\Downloads\FRST.exe
2018-01-08 18:26 - 2018-01-08 18:26 - 000000000 ____D C:\ProgramData\Google
2018-01-08 18:22 - 2018-01-08 18:25 - 000002207 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome.lnk
2018-01-08 18:22 - 2018-01-08 18:25 - 000002195 _____ C:\Users\Public\Desktop\Google Chrome.lnk
2018-01-08 18:21 - 2018-01-08 18:30 - 000000000 ____D C:\Users\xxx\AppData\Local\Google
2018-01-08 18:21 - 2018-01-08 18:26 - 000000000 ____D C:\Program Files\Google
2018-01-08 18:20 - 2018-01-08 18:21 - 000000000 ____D C:\Users\xxx\AppData\Local\Deployment
2018-01-08 18:20 - 2018-01-08 18:20 - 000000000 ____D C:\Users\xxx\AppData\Local\Apps\2.0
2018-01-08 18:08 - 2018-01-08 18:08 - 000000000 ___SD C:\Users\xxx\AppData\LocalLow\Temp
2018-01-08 18:06 - 2018-01-08 18:06 - 000390272 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2018-01-08 18:06 - 2018-01-08 18:06 - 000294680 _____ (AVAST Software) C:\Windows\system32\Drivers\aswVmm.sys
2018-01-08 18:06 - 2018-01-08 18:06 - 000158224 _____ (AVAST Software) C:\Windows\system32\Drivers\aswArPot.sys
2018-01-08 18:06 - 2018-01-08 18:06 - 000151328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswStm.sys
2018-01-08 18:06 - 2018-01-08 18:06 - 000124408 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2018-01-08 18:06 - 2018-01-08 18:06 - 000099528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2018-01-08 18:06 - 2018-01-08 18:06 - 000070832 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRvrt.sys
2018-01-08 18:06 - 2018-01-08 18:06 - 000042824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHwid.sys
2018-01-08 18:06 - 2018-01-08 18:06 - 000002077 _____ C:\Users\Public\Desktop\Avast Free Antivirus.lnk
2018-01-08 18:06 - 2018-01-08 18:06 - 000000000 ____D C:\Users\xxx\AppData\Roaming\AVAST Software
2018-01-08 18:06 - 2018-01-08 18:06 - 000000000 ____D C:\Users\xxx\AppData\Local\CEF
2018-01-08 18:06 - 2018-01-08 18:06 - 000000000 ____D C:\ProgramData\SWCUTemp
2018-01-08 18:06 - 2018-01-08 18:06 - 000000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVAST Software
2018-01-08 18:06 - 2018-01-08 18:06 - 000000000 ____D C:\Program Files\Common Files\Avast Software
2018-01-08 18:06 - 2018-01-08 18:05 - 001142072 _____ (Microsoft Corporation) C:\Windows\ucrtbase.dll
2018-01-08 18:06 - 2018-01-08 18:05 - 000783104 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2018-01-08 18:06 - 2018-01-08 18:05 - 000305840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2018-01-08 18:06 - 2018-01-08 18:05 - 000276696 _____ (AVAST Software) C:\Windows\system32\Drivers\aswblogx.sys
2018-01-08 18:06 - 2018-01-08 18:05 - 000255584 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidsdriverx.sys
2018-01-08 18:06 - 2018-01-08 18:05 - 000157376 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbidshx.sys
2018-01-08 18:06 - 2018-01-08 18:05 - 000118144 _____ (AVAST Software) C:\Windows\system32\Drivers\aswHdsKe.sys
2018-01-08 18:06 - 2018-01-08 18:05 - 000050344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswbunivx.sys
2018-01-08 18:03 - 2018-01-08 18:41 - 000000000 ____D C:\ProgramData\AVAST Software
2018-01-08 18:03 - 2018-01-08 18:03 - 000057560 _____ C:\Users\xxx\AppData\Local\GDIPFONTCACHEV1.DAT
2018-01-08 18:03 - 2018-01-08 18:03 - 000000000 ____D C:\Program Files\AVAST Software
2018-01-08 17:59 - 2012-06-02 23:19 - 001933848 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll
2018-01-08 17:59 - 2012-06-02 23:19 - 000053784 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe
2018-01-08 17:59 - 2012-06-02 23:19 - 000045080 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll
2018-01-08 17:59 - 2012-06-02 23:12 - 002422272 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll
2018-01-08 17:59 - 2012-06-02 15:19 - 000171904 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll
2018-01-08 17:59 - 2012-06-02 15:12 - 000033792 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe
2018-01-08 03:10 - 2018-01-08 17:08 - 000713888 _____ C:\Windows\system32\PerfStringBackup.INI
2018-01-08 02:35 - 2018-01-08 02:35 - 000001345 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk
2018-01-08 02:35 - 2018-01-08 02:35 - 000001326 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows DVD Maker.lnk
2018-01-08 02:33 - 2018-01-08 02:33 - 000000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdFs_01_09_00.Wdf
2018-01-08 02:31 - 2018-01-07 18:11 - 000000000 ____D C:\Windows\Panther
2018-01-08 02:18 - 2018-01-08 02:18 - 000000000 ____D C:\Windows.old
2018-01-07 19:38 - 2018-01-07 19:38 - 000000000 ____D C:\Users\xxx\Documents\Simply Super Software
2018-01-07 19:38 - 2018-01-07 19:38 - 000000000 ____D C:\ProgramData\TEMP
2018-01-07 19:38 - 2018-01-07 19:38 - 000000000 ____D C:\ProgramData\Simply Super Software
2018-01-07 18:13 - 2018-01-07 18:13 - 000001415 _____ C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
2018-01-07 18:12 - 2018-01-07 18:13 - 000000000 ____D C:\Users\xxx
2018-01-07 18:12 - 2018-01-07 18:12 - 000000020 ___SH C:\Users\xxx\ntuser.ini
2018-01-07 18:12 - 2018-01-07 18:12 - 000000000 ____D C:\Users\xxx\AppData\Local\VirtualStore
2018-01-07 18:12 - 2009-07-14 08:49 - 000000000 ____D C:\Users\xxx\AppData\Roaming\Media Center Programs
2018-01-01 17:21 - 2018-01-06 11:52 - 000000000 ____D C:\Users\xxx\Desktop\Bewerbungsunterlagen
2018-01-01 12:56 - 2018-01-06 11:24 - 000002073 _____ C:\Users\xxx\Desktop\job.txt
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2018-01-08 19:06 - 2009-07-14 05:34 - 000013728 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2018-01-08 19:06 - 2009-07-14 05:34 - 000013728 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2018-01-08 18:51 - 2010-08-15 13:29 - 000000000 ____D C:\Users\xxx\Desktop\Programme
2018-01-08 18:04 - 2009-07-14 03:37 - 000000000 __RHD C:\Users\Public\Libraries
2018-01-08 17:22 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\inf
2018-01-08 17:18 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\system32\NDF
2018-01-08 17:04 - 2009-07-14 05:53 - 000000006 ____H C:\Windows\Tasks\SA.DAT
2018-01-08 03:06 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\rescache
2018-01-08 02:35 - 2009-07-14 03:37 - 000000000 ____D C:\Windows\system32\sysprep
2018-01-08 02:32 - 2009-07-14 08:50 - 000000000 ____D C:\Windows\CSC
2018-01-08 02:30 - 2009-07-14 05:52 - 000028672 _____ C:\Windows\system32\config\BCD-Template
2018-01-07 20:39 - 2009-07-14 05:33 - 000265640 _____ C:\Windows\system32\FNTCACHE.DAT
2018-01-07 14:20 - 2009-07-14 04:20 - 000000000 ____D C:\Program Files (x86)
2018-01-06 23:15 - 2016-04-30 21:35 - 000003283 _____ C:\Users\xxx\Desktop\Notizen.txt
2018-01-06 00:37 - 2016-12-29 20:36 - 000002742 _____ C:\Users\xxx\Desktop\Musik.txt
2018-01-04 20:20 - 2016-06-26 17:25 - 000000000 ____D C:\Users\xxx\Desktop\Hausarbeit (Müll)
2018-01-04 10:57 - 2017-03-18 11:45 - 000000000 ____D C:\Users\xxx\Desktop\Kram
2018-01-04 10:51 - 2016-12-05 13:32 - 000000000 ____D C:\Users\xxx\Desktop\Bachelorarbeit
2017-12-27 21:11 - 2017-05-08 12:46 - 000000388 _____ C:\Users\xxx\Desktop\Studium.txt
2017-12-19 22:03 - 2017-11-11 16:58 - 000000220 _____ C:\Users\xxx\Desktop\TO-DO-LISTE.txt
2017-12-19 22:02 - 2016-04-30 21:35 - 000000541 _____ C:\Users\xxx\Desktop\Besorgungen.txt
==================== Bamital & volsnap ======================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\dnsapi.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2018-01-08 12:36
==================== End of FRST.txt ============================
addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 02.01.2018
Ran by xxx (08-01-2018 19:41:54)
Running from C:\Users\xxx\Downloads
Microsoft Windows 7 Professional (X86) (2018-01-07 17:12:49)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3067330445-848040545-2019120767-500 - Administrator - Disabled)
Guest (S-1-5-21-3067330445-848040545-2019120767-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3067330445-848040545-2019120767-1002 - Limited - Enabled)
xxx (S-1-5-21-3067330445-848040545-2019120767-1000 - Administrator - Enabled) => C:\Users\xxx
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Avast Antivirus (Enabled - Up to date) {8EA8924E-BC81-DC44-8BB0-8BAE75D86EBF}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avast Antivirus (Enabled - Up to date) {35C973AA-9ABB-D3CA-B100-B0DC0E5F2402}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Avast Free Antivirus (HKLM\...\Avast Antivirus) (Version: 17.9.2322 - AVAST Software)
Google Chrome (HKLM\...\Google Chrome) (Version: 63.0.3239.132 - Google Inc.)
Google Toolbar for Internet Explorer (HKLM\...\{18455581-E099-4BA8-BC6B-F34B2F06600C}) (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (HKLM\...\{2318C2B1-4965-11d4-9B18-009027A5CD4F}) (Version: 7.5.8231.2252 - Google Inc.)
Google Update Helper (HKLM\...\{60EC980A-BDA2-4CB6-A427-B07A5498B4CA}) (Version: 1.3.33.7 - Google Inc.) Hidden
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
ShellIconOverlayIdentifiers: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-01-08] (AVAST Software)
ContextMenuHandlers1: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-01-08] (AVAST Software)
ContextMenuHandlers3: [00asw] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-01-08] (AVAST Software)
ContextMenuHandlers6: [avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShell.dll [2018-01-08] (AVAST Software)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {4C0EFA8C-DF49-4E99-AE63-0BF431AEC942} - System32\Tasks\Avast Emergency Update => C:\Program Files\AVAST Software\Avast\AvEmUpdate.exe [2018-01-08] (AVAST Software)
Task: {6DB47800-C68D-4DD6-998C-8F4E6BBC8887} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2018-01-08] (Google Inc.)
Task: {983F0C30-0AED-4F03-9318-7AF0C9CE2517} - System32\Tasks\Avast Software\Overseer => C:\Program Files\Common Files\Avast Software\Overseer\overseer.exe [2018-01-08] (AVAST Software)
Task: {C7E19058-3FEA-46DB-A03A-0AE792BCCDDD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2018-01-08] (Google Inc.)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
==================== Shortcuts & WMI ========================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2018-01-08 18:05 - 2018-01-08 18:05 - 000057504 _____ () C:\Program Files\AVAST Software\Avast\dll_loader.dll
2018-01-08 18:05 - 2018-01-08 18:05 - 000058016 _____ () C:\Program Files\AVAST Software\Avast\module_lifetime.dll
2018-01-08 18:05 - 2018-01-08 18:05 - 000206152 _____ () C:\Program Files\AVAST Software\Avast\JsonRpcServer.dll
2018-01-08 18:05 - 2018-01-08 18:05 - 000289272 _____ () C:\Program Files\AVAST Software\Avast\tasks_core.dll
2018-01-08 18:05 - 2018-01-08 18:05 - 000196248 _____ () C:\Program Files\AVAST Software\Avast\network_notifications.dll
2018-01-08 18:06 - 2018-01-08 18:06 - 005853008 _____ () C:\Program Files\AVAST Software\Avast\defs\18010799\algo.dll
2018-01-08 18:05 - 2018-01-08 18:05 - 000745408 _____ () C:\Program Files\AVAST Software\Avast\ffl2.dll
2018-01-08 18:05 - 2018-01-08 18:05 - 000148936 _____ () C:\Program Files\AVAST Software\Avast\hns_tools.dll
2018-01-08 18:05 - 2018-01-08 18:05 - 000293944 _____ () C:\Program Files\AVAST Software\Avast\streamback.dll
2018-01-08 18:08 - 2018-01-08 18:08 - 005768336 _____ () C:\Program Files\AVAST Software\Avast\defs\18010804\algo.dll
2018-01-08 18:05 - 2018-01-08 18:05 - 067109376 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2018-01-08 18:05 - 2018-01-08 18:05 - 000282560 _____ () C:\Program Files\AVAST Software\Avast\gaming_mode_ui.dll
2018-01-08 18:05 - 2018-01-08 18:05 - 000196816 _____ () c:\Program Files\AVAST Software\Avast\vaarclient.dll
2018-01-08 18:22 - 2018-01-03 09:56 - 002195800 _____ () C:\Program Files\Google\Chrome\Application\63.0.3239.132\swiftshader\libglesv2.dll
2018-01-08 18:22 - 2018-01-03 09:56 - 000111448 _____ () C:\Program Files\Google\Chrome\Application\63.0.3239.132\swiftshader\libegl.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
==================== Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2009-07-14 03:04 - 2009-06-10 22:39 - 000000824 _____ C:\Windows\system32\Drivers\etc\hosts
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3067330445-848040545-2019120767-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\xxx\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg
DNS Servers: 213.211.192.34 - 213.187.64.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [SPPSVC-In-TCP] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [SPPSVC-In-TCP-NoScope] => (Allow) %SystemRoot%\system32\sppsvc.exe
FirewallRules: [{EDAA926D-A09C-4964-AB0E-1EA464F1B9DF}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
==================== Restore Points =========================
08-01-2018 12:43:35 Scheduled Checkpoint
08-01-2018 17:59:08 Windows Update
08-01-2018 18:03:00 Windows Update
==================== Faulty Device Manager Devices =============
Name: PCI Simple Communications Controller
Description: PCI Simple Communications Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
Name: Ethernet Controller
Description: Ethernet Controller
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (01/08/2018 06:23:28 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Faulting application name: iexplore.exe, version: 8.0.7600.16385, time stamp: 0x4a5bc69e
Faulting module name: unknown, version: 0.0.0.0, time stamp: 0x00000000
Exception code: 0xc0000005
Fault offset: 0x02760000
Faulting process id: 0xa4
Faulting application start time: 0x01d388a48616a82e
Faulting application path: C:\Program Files\Internet Explorer\iexplore.exe
Faulting module path: unknown
Report Id: a385e243-f498-11e7-baf4-cc4b214db885
Error: (01/08/2018 06:06:48 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files\AVAST Software\Avast\setup\iplugins\IStats.dll".
Dependent Assembly Avast.VC110.CRT,processorArchitecture="x86",publicKeyToken="2036b14a11e83e4a",type="win32",version="11.0.60610.1" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/08/2018 05:48:02 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows.old\Windows\regedit.exe".
Dependent Assembly Microsoft.Windows.Common-Controls,processorArchitecture="amd64",publicKeyToken="6595b64144ccf1df",type="win32",version="6.0.0.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/08/2018 05:47:59 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Windows.old\Windows\avastSS.scr".
Dependent Assembly Avast.VC140.CRT,processorArchitecture="x86",publicKeyToken="fcc99ee6193ebbca",type="win32",version="14.0.23918.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/08/2018 12:14:35 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program wmplayer.exe version 12.0.7600.16385 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: bc4
Start Time: 01d3886fe053b665
Termination Time: 0
Application Path: C:\Program Files\Windows Media Player\wmplayer.exe
Report Id: 0b8eeddb-f465-11e7-8b86-c3f6bf9f46fa
Error: (01/08/2018 11:49:49 AM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program wmplayer.exe version 12.0.7600.16385 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.
Process ID: 64c
Start Time: 01d3886d41f94621
Termination Time: 60000
Application Path: C:\Program Files\Windows Media Player\wmplayer.exe
Report Id: 7c8e16f7-f461-11e7-8b86-c3f6bf9f46fa
Error: (01/07/2018 07:36:40 PM) (Source: SideBySide) (EventID: 33) (User: )
Description: Activation context generation failed for "C:\Program Files (x86)\Microsoft Office\Office12\SETLANG.EXE".
Dependent Assembly Microsoft.VC80.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0" could not be found.
Please use sxstrace.exe for detailed diagnosis.
Error: (01/07/2018 06:11:47 PM) (Source: Software Protection Platform Service) (EventID: 1017) (User: )
Description: Installation of the Proof of Purchase failed. 0xC004F050
Partial Pkey=BBBBB
ACID=?
Detailed Error[?]
System errors:
=============
Error: (01/08/2018 05:04:51 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (01/08/2018 05:04:44 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (01/08/2018 12:18:21 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (01/08/2018 12:18:16 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (01/08/2018 12:16:27 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (01/08/2018 12:16:23 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (01/08/2018 12:16:19 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (01/08/2018 12:16:14 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (01/08/2018 12:16:10 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
Error: (01/08/2018 12:16:06 PM) (Source: cdrom) (EventID: 7) (User: )
Description: The device, \Device\CdRom0, has a bad block.
==================== Memory info ===========================
Processor: Intel(R) Core(TM) i3 CPU 540 @ 3.07GHz
Percentage of memory in use: 60%
Total physical RAM: 3063.12 MB
Available physical RAM: 1199.99 MB
Total Virtual: 6124.51 MB
Available Virtual: 4785.48 MB
==================== Drives ================================
Drive c: (OS) (Fixed) (Total:473.64 GB) (Free:320.76 GB) NTFS
Drive d: (2013-12-26 0122) (CDROM) (Total:0.45 GB) (Free:0 GB) UDF
Drive e: (RECOVERY) (Fixed) (Total:11.44 GB) (Free:4.87 GB) NTFS ==>[system with boot components (obtained from drive)]
Drive s: (Daten) (Fixed) (Total:446.31 GB) (Free:445.65 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 48000000)
Partition 1: (Not Active) - (Size=118 MB) - (Type=DE)
Partition 2: (Active) - (Size=11.4 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=473.6 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=446.3 GB) - (Type=OF Extended)
==================== End of Addition.txt ============================ |