![]() |
logfile von Acer Laptop Hallo zusammen, finde es echt klasse das Ihr dieses Forum habt, bin durch die g..gle suche zu euch gestoßen, klasse Arbeit. Nun zum Problem: der Rechner eines freundes gab einst eine Meldung des Polzieivirus (wie mein Freund sagte) mehr konnte er mir dazu nicht sagen. Ein Normaler Virenscann hatte nichts gefunden, aber das was ich über den vermeindlichen Polizeivirus gelesen hatte, war das es auch kein Virus sei. Hier die Log: Zitat:
|
Hi, Systemscan mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
|
Hallo Schrauber, fank für die schnelle Antwort, hier die Dateien FRST.txt FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-06-2013 Addition.txt Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 21-06-2013 |
Fix mit FRST Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: C:\Users\dnro\AppData\Roaming\skype.dat
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
|
Code: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-06-2013 |
Dann noch Combofix bitte. |
sorry, war gestern verhindert, hier die ComboFix [/CODE]ComboFix 13-06-21.02 - dnro 21.06.2013 11:08:55.1.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8044.6201 [GMT 2:00] ausgeführt von:: C:\Users\Waldemar\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) C:\Users\dnro\AppData\Roaming\skype.dat C:\Users\Public\Documents\NTILiveUpdateV9.dll C:\Users\Public\Documents\NTIMMV9Acer.dll ((((((((((((((((((((((( Dateien erstellt von 2013-05-21 bis 2013-06-21 )))))))))))))))))))))))))))))) 2013-06-21 09:18:10 . 2013-06-21 09:18:10 -------- d-----w- C:\Users\Default\AppData\Local\temp 2013-06-21 09:18:06 . 2013-06-21 09:18:06 -------- d-----w- C:\Users\UpdatusUser\AppData\Local\temp 2013-06-21 09:18:06 . 2013-06-21 09:18:06 -------- d-----w- C:\Users\dnro\AppData\Local\temp 2013-06-21 06:20:54 . 2013-06-21 08:42:06 -------- d-----w- C:\FRST 2013-06-21 04:52:14 . 2013-06-21 04:52:14 -------- d-----w- C:\Users\Waldemar\AppData\Roaming\Avira 2013-06-21 04:51:27 . 2013-06-21 04:51:09 83160 ----a-w- C:\Windows\system32\drivers\avnetflt.sys 2013-06-21 04:46:41 . 2013-03-06 14:13:37 28600 ----a-w- C:\Windows\system32\drivers\avkmgr.sys 2013-06-21 04:46:41 . 2013-02-26 14:56:51 130016 ----a-w- C:\Windows\system32\drivers\avipbb.sys 2013-06-21 04:46:41 . 2013-02-26 14:56:50 100712 ----a-w- C:\Windows\system32\drivers\avgntflt.sys 2013-06-21 04:46:39 . 2013-06-21 04:46:39 -------- d-----w- C:\ProgramData\Avira 2013-06-21 04:46:39 . 2013-06-21 04:46:39 -------- d-----w- C:\Program Files (x86)\Avira 2013-06-21 04:41:34 . 2013-06-17 00:10:22 9552976 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{3D0D7E56-B95F-4E3D-AC2E-3BED2F718BFC}\mpengine.dll . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) 2013-06-21 05:26:32 . 2012-08-21 11:52:33 692104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2013-06-21 05:26:32 . 2011-10-14 03:49:38 71048 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2013-06-21 04:29:53 . 2011-03-29 01:36:46 22240 ----a-w- C:\ProgramData\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2013-05-02 00:06:08 . 2010-11-21 03:27:21 278800 ------w- C:\Windows\system32\MpSigStub.exe 2013-04-11 09:26:36 . 2012-11-30 19:58:41 72702784 ----a-w- C:\Windows\system32\MRT.exe 2013-04-02 09:51:33 . 2013-04-02 09:51:33 97280 ----a-w- C:\Windows\system32\mshtmled.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 905728 ----a-w- C:\Windows\system32\mshtmlmedia.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 81408 ----a-w- C:\Windows\system32\icardie.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 762368 ----a-w- C:\Windows\system32\ieapfltr.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 73728 ----a-w- C:\Windows\SysWow64\SetIEInstalledDate.exe 2013-04-02 09:51:33 . 2013-04-02 09:51:33 719360 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 62976 ----a-w- C:\Windows\system32\pngfilt.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 61952 ----a-w- C:\Windows\SysWow64\tdc.ocx 2013-04-02 09:51:33 . 2013-04-02 09:51:33 599552 ----a-w- C:\Windows\system32\vbscript.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 523264 ----a-w- C:\Windows\SysWow64\vbscript.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 52224 ----a-w- C:\Windows\system32\msfeedsbs.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 51200 ----a-w- C:\Windows\system32\imgutil.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 48640 ----a-w- C:\Windows\SysWow64\mshtmler.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 452096 ----a-w- C:\Windows\system32\dxtmsft.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 441856 ----a-w- C:\Windows\system32\html.iec 2013-04-02 09:51:33 . 2013-04-02 09:51:33 38400 ----a-w- C:\Windows\SysWow64\imgutil.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 361984 ----a-w- C:\Windows\SysWow64\html.iec 2013-04-02 09:51:33 . 2013-04-02 09:51:33 281600 ----a-w- C:\Windows\system32\dxtrans.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 27648 ----a-w- C:\Windows\system32\licmgr10.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 270848 ----a-w- C:\Windows\system32\iedkcs32.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 247296 ----a-w- C:\Windows\system32\webcheck.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 235008 ----a-w- C:\Windows\system32\url.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 23040 ----a-w- C:\Windows\SysWow64\licmgr10.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 226304 ----a-w- C:\Windows\system32\elshyph.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 216064 ----a-w- C:\Windows\system32\msls31.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 197120 ----a-w- C:\Windows\system32\msrating.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 185344 ----a-w- C:\Windows\SysWow64\elshyph.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 173568 ----a-w- C:\Windows\system32\ieUnatt.exe 2013-04-02 09:51:33 . 2013-04-02 09:51:33 167424 ----a-w- C:\Windows\system32\iexpress.exe 2013-04-02 09:51:33 . 2013-04-02 09:51:33 158720 ----a-w- C:\Windows\SysWow64\msls31.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 1509376 ----a-w- C:\Windows\system32\inetcpl.cpl 2013-04-02 09:51:33 . 2013-04-02 09:51:33 150528 ----a-w- C:\Windows\SysWow64\iexpress.exe 2013-04-02 09:51:33 . 2013-04-02 09:51:33 149504 ----a-w- C:\Windows\system32\occache.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 144896 ----a-w- C:\Windows\system32\wextract.exe 2013-04-02 09:51:33 . 2013-04-02 09:51:33 1441280 ----a-w- C:\Windows\SysWow64\inetcpl.cpl 2013-04-02 09:51:33 . 2013-04-02 09:51:33 1400416 ----a-w- C:\Windows\system32\ieapfltr.dat 2013-04-02 09:51:33 . 2013-04-02 09:51:33 138752 ----a-w- C:\Windows\SysWow64\wextract.exe 2013-04-02 09:51:33 . 2013-04-02 09:51:33 13824 ----a-w- C:\Windows\system32\mshta.exe 2013-04-02 09:51:33 . 2013-04-02 09:51:33 137216 ----a-w- C:\Windows\SysWow64\ieUnatt.exe 2013-04-02 09:51:33 . 2013-04-02 09:51:33 136192 ----a-w- C:\Windows\system32\iepeers.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 12800 ----a-w- C:\Windows\SysWow64\mshta.exe 2013-04-02 09:51:33 . 2013-04-02 09:51:33 12800 ----a-w- C:\Windows\system32\msfeedssync.exe 2013-04-02 09:51:33 . 2013-04-02 09:51:33 110592 ----a-w- C:\Windows\SysWow64\IEAdvpack.dll 2013-04-02 09:51:33 . 2013-04-02 09:51:33 1054720 ----a-w- C:\Windows\system32\MsSpellCheckingFacility.exe 2013-04-02 09:51:33 . 2013-04-02 09:51:33 102912 ----a-w- C:\Windows\system32\inseng.dll 2013-04-02 09:51:32 . 2013-04-02 09:51:32 92160 ----a-w- C:\Windows\system32\SetIEInstalledDate.exe 2013-04-02 09:51:32 . 2013-04-02 09:51:32 77312 ----a-w- C:\Windows\system32\tdc.ocx 2013-04-02 09:51:32 . 2013-04-02 09:51:32 48640 ----a-w- C:\Windows\system32\mshtmler.dll 2013-04-02 09:51:32 . 2013-04-02 09:51:32 135680 ----a-w- C:\Windows\system32\IEAdvpack.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 9728 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 9728 ---ha-w- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 648192 ----a-w- C:\Windows\system32\d3d10level9.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 604160 ----a-w- C:\Windows\SysWow64\d3d10level9.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 5632 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 5632 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 5632 ---ha-w- C:\Windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 5632 ---ha-w- C:\Windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 522752 ----a-w- C:\Windows\system32\XpsGdiConverter.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 465920 ----a-w- C:\Windows\system32\WMPhoto.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 417792 ----a-w- C:\Windows\SysWow64\WMPhoto.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 4096 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 4096 ---ha-w- C:\Windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 3928064 ----a-w- C:\Windows\system32\d2d1.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 364544 ----a-w- C:\Windows\SysWow64\XpsGdiConverter.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 363008 ----a-w- C:\Windows\system32\dxgi.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 3584 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 3584 ---ha-w- C:\Windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 3419136 ----a-w- C:\Windows\SysWow64\d2d1.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 333312 ----a-w- C:\Windows\system32\d3d10_1core.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 3072 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 3072 ---ha-w- C:\Windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 3072 ---ha-w- C:\Windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 296960 ----a-w- C:\Windows\system32\d3d10core.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 293376 ----a-w- C:\Windows\SysWow64\dxgi.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 2776576 ----a-w- C:\Windows\system32\msmpeg2vdec.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 2565120 ----a-w- C:\Windows\system32\d3d10warp.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 2560 ---ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 2560 ---ha-w- C:\Windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 249856 ----a-w- C:\Windows\SysWow64\d3d10_1core.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 245248 ----a-w- C:\Windows\system32\WindowsCodecsExt.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 2284544 ----a-w- C:\Windows\SysWow64\msmpeg2vdec.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 221184 ----a-w- C:\Windows\system32\UIAnimation.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 220160 ----a-w- C:\Windows\SysWow64\d3d10core.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 207872 ----a-w- C:\Windows\SysWow64\WindowsCodecsExt.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 1988096 ----a-w- C:\Windows\SysWow64\d3d10warp.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 194560 ----a-w- C:\Windows\system32\d3d10_1.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 1887232 ----a-w- C:\Windows\system32\d3d11.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 187392 ----a-w- C:\Windows\SysWow64\UIAnimation.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 1682432 ----a-w- C:\Windows\system32\XpsPrint.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 1643520 ----a-w- C:\Windows\system32\DWrite.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 161792 ----a-w- C:\Windows\SysWow64\d3d10_1.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 1504768 ----a-w- C:\Windows\SysWow64\d3d11.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 1424384 ----a-w- C:\Windows\system32\WindowsCodecs.dll 2013-04-02 09:49:16 . 2013-04-02 09:49:16 1247744 ----a-w- C:\Windows\SysWow64\DWrite.dll (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Skype"="C:\Program Files (x86)\Skype\Phone\Skype.exe" [2013-02-28 16:50:02 18642024] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "Adobe ARM"="C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-06-06 19:55:28 937920] "BackupManagerTray"="C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe" [2011-04-24 01:28:38 297280] "LManager"="C:\Program Files (x86)\Launch Manager\LManager.exe" [2011-07-01 02:51:12 1103440] "NUSB3MON"="C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe" [2010-11-17 01:53:16 113288] "Dolby Advanced Audio v2"="C:\Dolby PCEE4\pcee4.exe" [2011-06-01 09:32:06 506712] "SuiteTray"="C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2011-09-20 09:25:58 341360] "APSDaemon"="C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2011-11-01 22:25:58 59240] "iTunesHelper"="C:\Program Files (x86)\iTunes\iTunesHelper.exe" [2012-01-16 16:22:12 421736] "SunJavaUpdateSched"="C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-18 13:02:04 254696] "InboxToolbar"="C:\Program Files (x86)\Inbox Toolbar\Inbox.exe" [2013-04-12 01:12:52 1713296] "PMBVolumeWatcher"="C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe" [2011-12-16 20:49:26 694328] "avgnt"="C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-04-04 09:22:39 345312] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "IsMyWinLockerReboot"="msiexec.exe" [2010-11-21 03:24:28 73216] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) [HKEY_CURRENT_USER\software\microsoft\windows nt\currentversion\winlogon] "shell"="explorer.exe,C:\Users\dnro\AppData\Roaming\skype.dat" [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=C:\Windows\SysWOW64\nvinit.dll [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe;C:\Program Files (x86)\Skype\Updater\Updater.exe [x] R3 EgisTec Ticket Service;EgisTec Ticket Service;C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe;C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe [x] R3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [x] R3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys;C:\Windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\system32\drivers\TsUsbGD.sys;C:\Windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R3 TurboBoost;Intel(R) Turbo Boost Technology Monitor 2.0;C:\Program Files\Intel\TurboBoost\TurboBoost.exe;C:\Program Files\Intel\TurboBoost\TurboBoost.exe [x] R3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys;C:\Windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;C:\Windows\system32\Wat\WatAdminSvc.exe;C:\Windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] R4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [x] S0 nvpciflt;nvpciflt;C:\Windows\system32\DRIVERS\nvpciflt.sys;C:\Windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S1 aswKbd;aswKbd; [x] S1 avkmgr;avkmgr;C:\Windows\system32\DRIVERS\avkmgr.sys;C:\Windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 mwlPSDFilter;mwlPSDFilter;C:\Windows\system32\DRIVERS\mwlPSDFilter.sys;C:\Windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x] S1 mwlPSDNServ;mwlPSDNServ;C:\Windows\system32\DRIVERS\mwlPSDNServ.sys;C:\Windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x] S1 mwlPSDVDisk;mwlPSDVDisk;C:\Windows\system32\DRIVERS\mwlPSDVDisk.sys;C:\Windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x] S2 AntiVirSchedulerService;Avira Planer;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe;C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 cvhsvc;Client Virtualization Handler;C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 DsiWMIService;Dritek WMI Service;C:\Program Files (x86)\Launch Manager\dsiwmis.exe;C:\Program Files (x86)\Launch Manager\dsiwmis.exe [x] S2 ePowerSvc;ePower Service;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe;C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [x] S2 GREGService;GREGService;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe;C:\Program Files (x86)\Acer\Registration\GREGsvc.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 Live Updater Service;Live Updater Service;C:\Program Files\Acer\Acer Updater\UpdaterService.exe;C:\Program Files\Acer\Acer Updater\UpdaterService.exe [x] S2 NTI IScheduleSvc;NTI IScheduleSvc;C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe;C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe [x] S2 PMBDeviceInfoProvider;PMBDeviceInfoProvider;C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe;C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe [x] S2 sftlist;Application Virtualization Client;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 TurboB;Turbo Boost UI Monitor driver;C:\Windows\system32\DRIVERS\TurboB.sys;C:\Windows\SYSNATIVE\DRIVERS\TurboB.sys [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 b57xdbd;Broadcom xD Picture Bus Driver Service;C:\Windows\system32\DRIVERS\b57xdbd.sys;C:\Windows\SYSNATIVE\DRIVERS\b57xdbd.sys [x] S3 b57xdmp;Broadcom xD Picture vstorp client drv;C:\Windows\system32\DRIVERS\b57xdmp.sys;C:\Windows\SYSNATIVE\DRIVERS\b57xdmp.sys [x] S3 bScsiMSa;bScsiMSa;C:\Windows\system32\DRIVERS\bScsiMSa.sys;C:\Windows\SYSNATIVE\DRIVERS\bScsiMSa.sys [x] S3 bScsiSDa;bScsiSDa;C:\Windows\system32\DRIVERS\bScsiSDa.sys;C:\Windows\SYSNATIVE\DRIVERS\bScsiSDa.sys [x] S3 ETD;ELAN PS/2 Port Input Device;C:\Windows\system32\DRIVERS\ETD.sys;C:\Windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 IntcDAud;Intel(R) Display-Audio;C:\Windows\system32\DRIVERS\IntcDAud.sys;C:\Windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;C:\Windows\system32\DRIVERS\k57nd60a.sys;C:\Windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x] S3 nusb3hub;Renesas Electronics USB 3.0 Hub Driver;C:\Windows\system32\DRIVERS\nusb3hub.sys;C:\Windows\SYSNATIVE\DRIVERS\nusb3hub.sys [x] S3 nusb3xhc;Renesas Electronics USB 3.0 Host Controller Driver;C:\Windows\system32\DRIVERS\nusb3xhc.sys;C:\Windows\SYSNATIVE\DRIVERS\nusb3xhc.sys [x] S3 Sftfs;Sftfs;C:\Windows\system32\DRIVERS\Sftfslh.sys;C:\Windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;C:\Windows\system32\DRIVERS\Sftplaylh.sys;C:\Windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;C:\Windows\system32\DRIVERS\Sftredirlh.sys;C:\Windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;C:\Windows\system32\DRIVERS\Sftvollh.sys;C:\Windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] Inhalt des "geplante Tasks" Ordners 2013-06-21 C:\Windows\Tasks\Adobe Flash Player Updater.job - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-08-21 11:52:34 . 2013-06-21 05:26:33] --------- X64 Entries ----------- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="C:\Windows\system32\igfxtray.exe" [2011-06-21 02:19:12 167704] "HotKeysCmds"="C:\Windows\system32\hkcmd.exe" [2011-06-21 02:19:00 392472] "Persistence"="C:\Windows\system32\igfxpers.exe" [2011-06-21 02:19:06 416024] "IntelTBRunOnce"="wscript.exe" [2009-07-14 01:39:57 168960] "RtHDVCpl"="C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-08-16 08:34:58 12673128] "RtHDVBg_Dolby"="C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe" [2011-08-16 07:02:12 2277480] "Power Management"="C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe" [2011-08-02 10:59:48 1831016] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=C:\Windows\System32\nvinitx.dll ------- Zusätzlicher Suchlauf ------- uStart Page = https://ixquick.com/deu/ uLocal Page = C:\Windows\system32\blank.htm mLocal Page = C:\Windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Free YouTube Download - C:\Users\dnro\AppData\Roaming\DVDVideoSoftIEHelpers\freeytvdownloader.htm IE: Free YouTube to MP3 Converter - C:\Users\dnro\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm TCP: DhcpNameServer = 192.168.178.1 - - - - Entfernte verwaiste Registrierungseinträge - - - - Toolbar-Locked - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) HKLM-Run-ETDCtrl - C:\Program Files (x86)\Elantech\ETDCtrl.exe AddRemove-OpenAL - C:\Program Files (x86)\OpenAL\oalinst.exe AddRemove-WildTangent acer Master Uninstall - C:\Program Files (x86)\Acer Games\Uninstall.exe AddRemove-WildTangentGameProvider-acer-main - C:\Program Files (x86)\Acer Games\Game Explorer Categories - main\Uninstall.exe AddRemove-WTA-02dacc7f-67cc-400c-823a-ce27319d16b8 - C:\Program Files (x86)\Acer Games\Jewel Quest Solitaire\uninstall\uninstaller.exe AddRemove-WTA-097a7825-65ed-480c-9f87-000aecf38871 - C:\Program Files (x86)\Acer Games\Bejeweled 2 Deluxe\uninstall\uninstaller.exe AddRemove-WTA-0f25fa6f-22d0-43a0-a210-512d185fa377 - C:\Program Files (x86)\Acer Games\FATE\uninstall\uninstaller.exe AddRemove-WTA-14e6272a-622e-4cff-88f3-3d50b867a798 - C:\Program Files (x86)\Acer Games\Penguins!\uninstall\uninstaller.exe AddRemove-WTA-1689a3f1-93a8-4030-aa91-b3db1b00c954 - C:\Program Files (x86)\Acer Games\Agatha Christie - Death on the Nile\uninstall\uninstaller.exe AddRemove-WTA-340b756c-1998-4ad2-a6ed-3815f55402fa - C:\Program Files (x86)\Acer Games\Plants vs Zombies - Game of the Year\uninstall\uninstaller.exe AddRemove-WTA-42564979-3cff-4b03-b7c4-6e7896fd2136 - C:\Program Files (x86)\Acer Games\Slingo Deluxe\uninstall\uninstaller.exe AddRemove-WTA-65a73bf0-a974-441c-930b-dffe1d1da13c - C:\Program Files (x86)\Acer Games\Virtual Villagers 4 - The Tree of Life\uninstall\uninstaller.exe AddRemove-WTA-6e5c2c20-a40e-4e09-bba0-1fb88678f826 - C:\Program Files (x86)\Acer Games\Insaniquarium Deluxe\uninstall\uninstaller.exe AddRemove-WTA-73de62fc-cc0f-4be3-919f-e685d89951a8 - C:\Program Files (x86)\Acer Games\Jewel Match 3\uninstall\uninstaller.exe AddRemove-WTA-846ff209-a66c-4103-b130-b10d1c79618c - C:\Program Files (x86)\Acer Games\John Deere Drive Green\uninstall\uninstaller.exe AddRemove-WTA-8c5f24c6-3964-4af0-8484-103340113929 - C:\Program Files (x86)\Acer Games\Torchlight\uninstall\uninstaller.exe AddRemove-WTA-ae1a2602-36d4-4072-97e2-77bfef0b84a6 - C:\Program Files (x86)\Acer Games\Polar Bowler\uninstall\uninstaller.exe AddRemove-WTA-b00d9f85-11a8-4969-a447-0e485697b806 - C:\Program Files (x86)\Acer Games\Zuma Deluxe\uninstall\uninstaller.exe AddRemove-WTA-be4223be-166b-4a3e-ab6e-429e3a89c877 - C:\Program Files (x86)\Acer Games\Mystery of Mortlake Mansion\uninstall\uninstaller.exe AddRemove-WTA-c680f1ec-6566-435d-bae8-c7c9cd2c07b0 - C:\Program Files (x86)\Acer Games\Final Drive Nitro\uninstall\uninstaller.exe AddRemove-WTA-d2380050-7eb2-4d53-9f2e-4d5becce4063 - C:\Program Files (x86)\Acer Games\Crazy Chicken Kart 2\uninstall\uninstaller.exe AddRemove-WTA-d8c6f271-11d8-46f1-876c-8a108a0bc881 - C:\Program Files (x86)\Acer Games\Wedding Dash\uninstall\uninstaller.exe AddRemove-WTA-ddb8f684-52c3-4b55-90df-4ab4f60c88d4 - C:\Program Files (x86)\Acer Games\Chuzzle Deluxe\uninstall\uninstaller.exe [/CODE] |
Hi, Combofix-Skript
|
Hallo, sorry das ich erst jetzt dazu gekomen bin, hier die Log. Vilen dank für Euere Arbeit Code: ComboFix 13-06-26.01 - dnro 26.06.2013 23:41:24.2.8 - x64 |
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST Log bitte. |
Code: # AdwCleaner v2.303 - Datei am 27/06/2013 um 21:00:59 erstellt Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-06-2013 02 --- --- --- |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST Log, noch Probleme? :) |
Code: ESETSmartInstaller@High as downloader log: |
und weiter :) |
Code: Results of screen317's Security Check version 0.99.68 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 22:48 Uhr. |
Copyright ©2000-2025, Trojaner-Board