Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Virus: PC fährt nicht mehr hoch - Abgesicherter Modus, Systemwiederherstellung etc. Nicht möglich (https://www.trojaner-board.de/145440-virus-pc-faehrt-mehr-hoch-abgesicherter-modus-systemwiederherstellung-etc-moeglich.html)

manolis 01.12.2013 18:11

Virus: PC fährt nicht mehr hoch - Abgesicherter Modus, Systemwiederherstellung etc. Nicht möglich
 
Hallo an alle!
Ich hoffe ihr könnt mir bei meinem Problem helfen!

Hatte seit Aktivierung einer neuen Lizenz von Avira antivir das Problem das der PC ständig abgestürzt ist.

Daraufhin habe ich heute das Antivirus Programm entfernt um es wieder neu zu installieren.
Nun startet mein Pc nicht mehr! Das heißt, ich komme nicht mehr auf den Desktop von Windows!
Auch bei den Abgesicherten Modusen startet der Pc auch immer wieder neu!

Nun weis ich nicht mehr was ich machen soll! Gibt es eine Möglichkeit die Viruse zu entfernen, ohne meine Daten zu verlieren?

Habe im Forum ein ähnliches Problem gefunden und schon einige Schritte erledigt. Hoffentlich war dies nicht falsch.

Hab Farbar Recovery Scan Tool heruntergeladen und habe schon eine FRST.txt

Bin leider kein Profi auf diesem Gebiet bin.
Ich freue mich über jede Hilfe!

Danke!

FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 01-12-2013
Ran by SYSTEM on MININT-TB7L294 on 01-12-2013 18:51:37
Running from F:\
Windows 7 Home Premium (X86) OS Language: 0Greek
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [UpdateLBPShortCut] - C:\Program Files\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM\...\Run: [MDS_Menu] - C:\Program Files\CyberLink\MediaShow4\MUITransfer\MUIStartMenu.exe [218408 2009-02-25] (CyberLink Corp.)
HKLM\...\Run: [CLMLServer] - C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe [103720 2009-06-03] (CyberLink)
HKLM\...\Run: [UpdateP2GoShortCut] - C:\Program Files\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM\...\Run: [UpdatePDRShortCut] - C:\Program Files\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe [218408 2008-12-03] (CyberLink Corp.)
HKLM\...\Run: [PDVD9LanguageShortcut] - C:\Program Files\CyberLink\PowerDVD9\Language\Language.exe [50472 2009-04-27] (CyberLink Corp.)
HKLM\...\Run: [UpdatePPShortCut] - C:\Program Files\CyberLink\PowerProducer\MUITransfer\MUIStartMenu.exe [222504 2009-05-19] (CyberLink Corp.)
HKLM\...\Run: [YouCam Mirror Tray icon] - C:\Program Files\CyberLink\YouCam\YouCamTray.exe [167008 2009-12-23] (CyberLink Corp.)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7866912 2009-11-10] (Realtek Semiconductor)
HKLM\...\Run: [GrooveMonitor] - C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM\...\Run: [avgnt] - "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
HKU\Manolis\...\Run: [ApplePhotoStreams] - C:\Program Files\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [ 2013-09-15] (Apple Inc.)
Startup: C:\Users\Manolis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk ->  (No File)
Startup: C:\Users\Manolis\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Screen Clipper and Launcher.lnk
ShortcutTarget: OneNote 2007 Screen Clipper and Launcher.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation)

========================== Services (Whitelisted) =================

S4 M4-Service; C:\Users\Manolis\AppData\Roaming\Mikogo 4\M4-Service.exe [1007472 2012-01-16] ()
S2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S2 RichVideo; C:\Program Files\CyberLink\Shared files\RichVideo.exe [244904 2009-07-27] ()
S2 WMI_Hook_Service; C:\Program Files\msi\OSD hot keys\WMI_Hook_Service.exe [100152 2009-12-24] (MICRO-STAR INT'L,.LTD.)
S2 AntiVirFirewallService; "C:\Program Files\Avira\AntiVir Desktop\avfwsvc.exe" [x]
S2 AntiVirSchedulerService; "C:\Program Files\Avira\AntiVir Desktop\sched.exe" [x]
S2 AntiVirService; "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [x]

==================== Drivers (Whitelisted) ====================

S3 hidkmdf; C:\Windows\System32\DRIVERS\hidkmdf.sys [10360 2009-10-29] (Windows (R) Win 7 DDK provider)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2013-12-01] (Malwarebytes Corporation)
S3 MSIDriver_IO_2; C:\Program Files\msi\OSD hot keys\MSI_MAINSYS.sys [26424 2009-12-10] (Your Corporation)
S0 nvamacpi; C:\Windows\System32\DRIVERS\NVAMACPI.sys [24608 2009-07-17] (NVIDIA Corporation)
S3 NW1950; C:\Windows\System32\DRIVERS\NW1950.sys [22392 2009-10-29] ()
S3 NxpCap; C:\Windows\System32\DRIVERS\NxpCap.sys [1558368 2009-12-22] (NXP Semiconductors Germany GmbH)
S1 avfwot; system32\DRIVERS\avfwot.sys [x]
S2 avgntflt; system32\DRIVERS\avgntflt.sys [x]
S1 avipbb; system32\DRIVERS\avipbb.sys [x]
S1 avkmgr; system32\DRIVERS\avkmgr.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-12-01 18:44 - 2013-12-01 18:44 - 00000000 ____D C:\FRST
2013-12-01 18:04 - 2013-12-01 18:04 - 00003480 ____N C:\bootsqm.dat
2013-12-01 18:04 - 2013-12-01 18:04 - 00000000 __SHD C:\found.002
2013-11-30 19:32 - 2013-12-01 10:42 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2013-11-25 19:15 - 2013-11-25 19:15 - 09721463 _____ C:\Users\Manolis\Documents\Presentation1.pptx
2013-11-20 09:54 - 2013-11-20 09:54 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-20 01:34 - 2013-11-20 01:34 - 00000000 __SHD C:\found.001
2013-11-20 01:22 - 2013-11-20 01:23 - 00160704 _____ C:\Windows\Minidump\112013-27253-01.dmp
2013-11-19 19:02 - 2013-11-20 01:22 - 502563072 _____ C:\Windows\MEMORY.DMP
2013-11-19 19:02 - 2013-11-19 19:02 - 00160704 _____ C:\Windows\Minidump\111913-25240-01.dmp
2013-11-19 18:33 - 2013-11-19 18:33 - 17142784 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 11220992 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 04240384 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-11-19 18:33 - 2013-11-19 18:33 - 02166272 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 01926656 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-11-19 18:33 - 2013-11-19 18:33 - 01818112 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 01156608 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 01051136 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00703488 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00646144 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00645120 _____ (Microsoft Corporation) C:\Windows\System32\jsIntl.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00616104 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2013-11-19 18:33 - 2013-11-19 18:33 - 00610304 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00553472 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00523776 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00454656 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00440832 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00367104 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00337408 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
2013-11-19 18:33 - 2013-11-19 18:33 - 00244736 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00238288 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00233472 _____ (Microsoft Corporation) C:\Windows\System32\url.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00208896 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00208384 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00194048 _____ (Microsoft Corporation) C:\Windows\System32\elshyph.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00182272 _____ (Microsoft Corporation) C:\Windows\System32\msls31.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00164864 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00151552 _____ (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\wextract.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00127488 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00116736 _____ (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00112128 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00108032 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00086016 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00083456 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00074240 _____ (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00071680 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00069632 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00069120 _____ (Microsoft Corporation) C:\Windows\System32\icardie.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2013-11-19 18:33 - 2013-11-19 18:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00056832 _____ (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00036352 _____ (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00024576 _____ (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\mshta.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00012800 _____ (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2013-11-19 18:32 - 2013-11-19 18:36 - 00009298 _____ C:\Windows\IE11_main.log
2013-11-19 18:16 - 2013-10-04 03:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\System32\SmartcardCredentialProvider.dll
2013-11-19 18:16 - 2013-10-04 03:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll
2013-11-19 18:16 - 2013-10-04 03:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\System32\credui.dll
2013-11-19 18:16 - 2013-10-03 03:58 - 00305152 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2013-11-19 18:16 - 2013-09-25 04:01 - 00136640 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2013-11-19 18:16 - 2013-09-25 04:01 - 00067520 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\ksecdd.sys
2013-11-19 18:16 - 2013-09-25 03:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-11-19 18:16 - 2013-09-25 03:57 - 00099840 _____ (Microsoft Corporation) C:\Windows\System32\sspicli.dll
2013-11-19 18:16 - 2013-09-25 03:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\secur32.dll
2013-11-19 18:16 - 2013-09-25 03:56 - 01038848 _____ (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2013-11-19 18:16 - 2013-09-25 03:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\System32\ncrypt.dll
2013-11-19 18:16 - 2013-09-25 02:49 - 00022016 _____ (Microsoft Corporation) C:\Windows\System32\lsass.exe
2013-11-19 18:16 - 2013-09-25 02:49 - 00015872 _____ (Microsoft Corporation) C:\Windows\System32\sspisrv.dll
2013-11-19 18:16 - 2013-07-04 14:16 - 00369848 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2013-11-19 18:14 - 2013-10-12 04:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\System32\nshwfp.dll
2013-11-19 18:14 - 2013-10-12 04:01 - 00679424 _____ (Microsoft Corporation) C:\Windows\System32\IKEEXT.DLL
2013-11-19 18:14 - 2013-10-12 04:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\System32\FWPUCLNT.DLL
2013-11-19 18:14 - 2013-10-05 21:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-11-19 17:44 - 2013-11-19 17:44 - 00000000 __SHD C:\found.000
2013-11-13 14:57 - 2013-11-13 15:31 - 00012038 _____ C:\Users\Manolis\Documents\Book1.xlsx
2013-11-10 11:55 - 2013-11-10 11:55 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-11-10 11:52 - 2013-11-10 11:54 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-11-10 11:52 - 2013-11-10 11:54 - 00000000 ____D C:\Program Files\iTunes
2013-11-10 11:52 - 2013-11-10 11:52 - 00000000 ____D C:\Program Files\iPod
2013-11-08 10:36 - 2013-11-08 10:36 - 00000000 ___SD C:\Users\Manolis\Documents\My Data Sources

==================== One Month Modified Files and Folders =======

2013-12-01 18:44 - 2013-12-01 18:44 - 00000000 ____D C:\FRST
2013-12-01 18:07 - 2012-03-27 16:11 - 01089833 _____ C:\Windows\WindowsUpdate.log
2013-12-01 18:05 - 2013-03-12 13:54 - 00007782 _____ C:\Windows\PFRO.log
2013-12-01 18:05 - 2012-03-27 18:04 - 00000000 ____D C:\Program Files\Avira
2013-12-01 18:04 - 2013-12-01 18:04 - 00003480 ____N C:\bootsqm.dat
2013-12-01 18:04 - 2013-12-01 18:04 - 00000000 __SHD C:\found.002
2013-12-01 18:00 - 2012-04-23 19:16 - 00000000 ____D C:\Users\Manolis\AppData\Local\TSVNCache
2013-12-01 16:50 - 2013-03-11 10:17 - 00000000 ___RD C:\Users\Manolis\Dropbox
2013-12-01 16:50 - 2013-03-11 10:09 - 00000000 ____D C:\Users\Manolis\AppData\Roaming\Dropbox
2013-12-01 12:18 - 2009-07-14 06:34 - 00009920 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-12-01 12:18 - 2009-07-14 06:34 - 00009920 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-12-01 12:10 - 2013-03-05 12:45 - 00018928 _____ C:\Windows\setupact.log
2013-12-01 11:47 - 2012-03-28 15:29 - 00000000 ____D C:\OutLook
2013-12-01 11:47 - 2012-03-28 15:28 - 00000000 ____D C:\Outlook - Group Use
2013-12-01 10:42 - 2013-11-30 19:32 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbamswissarmy.sys
2013-11-30 13:06 - 2012-03-29 15:30 - 00000000 ___RD C:\Users\Manolis\Spielhalle
2013-11-25 19:15 - 2013-11-25 19:15 - 09721463 _____ C:\Users\Manolis\Documents\Presentation1.pptx
2013-11-24 10:26 - 2013-09-25 11:49 - 00000000 ____D C:\Users\Manolis\CIP
2013-11-21 18:45 - 2012-11-28 14:25 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-11-21 14:47 - 2012-03-27 16:14 - 01490422 _____ C:\Windows\System32\PerfStringBackup.INI
2013-11-20 13:36 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\rescache
2013-11-20 11:29 - 2012-10-19 17:23 - 00018288 _____ C:\Users\Manolis\Documents\Monthly Budget.xlsx
2013-11-20 09:54 - 2013-11-20 09:54 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-11-20 01:34 - 2013-11-20 01:34 - 00000000 __SHD C:\found.001
2013-11-20 01:23 - 2013-11-20 01:22 - 00160704 _____ C:\Windows\Minidump\112013-27253-01.dmp
2013-11-20 01:22 - 2013-11-19 19:02 - 502563072 _____ C:\Windows\MEMORY.DMP
2013-11-20 01:22 - 2012-03-28 20:14 - 00000000 ____D C:\Windows\Minidump
2013-11-19 19:02 - 2013-11-19 19:02 - 00160704 _____ C:\Windows\Minidump\111913-25240-01.dmp
2013-11-19 18:37 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\System32\el-GR
2013-11-19 18:36 - 2013-11-19 18:32 - 00009298 _____ C:\Windows\IE11_main.log
2013-11-19 18:33 - 2013-11-19 18:33 - 17142784 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 11220992 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 04240384 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-11-19 18:33 - 2013-11-19 18:33 - 02166272 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 01926656 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2013-11-19 18:33 - 2013-11-19 18:33 - 01818112 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 01156608 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 01051136 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00703488 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00646144 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00645120 _____ (Microsoft Corporation) C:\Windows\System32\jsIntl.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00616104 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat
2013-11-19 18:33 - 2013-11-19 18:33 - 00610304 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00553472 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00523776 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00454656 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00440832 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00367104 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00337408 _____ (Microsoft Corporation) C:\Windows\System32\html.iec
2013-11-19 18:33 - 2013-11-19 18:33 - 00244736 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00238288 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00233472 _____ (Microsoft Corporation) C:\Windows\System32\url.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00208896 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00208384 _____ (Microsoft Corporation) C:\Windows\System32\webcheck.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00194048 _____ (Microsoft Corporation) C:\Windows\System32\elshyph.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00182272 _____ (Microsoft Corporation) C:\Windows\System32\msls31.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00164864 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00151552 _____ (Microsoft Corporation) C:\Windows\System32\iexpress.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\wextract.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00127488 _____ (Microsoft Corporation) C:\Windows\System32\occache.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00116736 _____ (Microsoft Corporation) C:\Windows\System32\iepeers.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00112128 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00108032 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00086016 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00083456 _____ (Microsoft Corporation) C:\Windows\System32\inseng.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00074240 _____ (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00071680 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00069632 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00069120 _____ (Microsoft Corporation) C:\Windows\System32\icardie.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00062464 _____ (Microsoft Corporation) C:\Windows\System32\tdc.ocx
2013-11-19 18:33 - 2013-11-19 18:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00061952 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00056832 _____ (Microsoft Corporation) C:\Windows\System32\pngfilt.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\mshtmler.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00043008 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00036352 _____ (Microsoft Corporation) C:\Windows\System32\imgutil.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00034816 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00032768 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00024576 _____ (Microsoft Corporation) C:\Windows\System32\licmgr10.dll
2013-11-19 18:33 - 2013-11-19 18:33 - 00013312 _____ (Microsoft Corporation) C:\Windows\System32\mshta.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00012800 _____ (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe
2013-11-19 18:33 - 2013-11-19 18:33 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2013-11-19 18:22 - 2012-03-28 11:35 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-11-19 18:19 - 2013-07-20 23:05 - 00000000 ____D C:\Windows\System32\MRT
2013-11-19 18:17 - 2012-03-27 21:41 - 80340640 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-11-19 17:54 - 2012-03-27 16:11 - 00000000 ____D C:\users\Manolis
2013-11-19 17:54 - 2009-07-14 10:42 - 00000000 ___RD C:\Users\Public\Recorded TV
2013-11-19 17:54 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\System32\wfp
2013-11-19 17:54 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration
2013-11-19 17:54 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\AppCompat
2013-11-19 17:54 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared
2013-11-19 17:44 - 2013-11-19 17:44 - 00000000 __SHD C:\found.000
2013-11-19 17:43 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\System32\LogFiles
2013-11-13 17:46 - 2013-08-20 15:17 - 00000000 ____D C:\Users\Manolis\Documents\Takis Bekas - Latino Hair Lauf
2013-11-13 15:31 - 2013-11-13 14:57 - 00012038 _____ C:\Users\Manolis\Documents\Book1.xlsx
2013-11-10 12:40 - 2013-06-01 09:57 - 00000000 ____D C:\Users\Manolis\Eurobank
2013-11-10 11:55 - 2013-11-10 11:55 - 00001753 _____ C:\Users\Public\Desktop\iTunes.lnk
2013-11-10 11:54 - 2013-11-10 11:52 - 00000000 ____D C:\ProgramData\188F1432-103A-4ffb-80F1-36B633C5C9E1
2013-11-10 11:54 - 2013-11-10 11:52 - 00000000 ____D C:\Program Files\iTunes
2013-11-10 11:52 - 2013-11-10 11:52 - 00000000 ____D C:\Program Files\iPod
2013-11-10 11:52 - 2012-03-28 13:23 - 00000000 ____D C:\Program Files\Common Files\Apple
2013-11-08 10:36 - 2013-11-08 10:36 - 00000000 ___SD C:\Users\Manolis\Documents\My Data Sources
2013-11-03 19:19 - 2012-03-29 18:55 - 00000000 ____D C:\Users\Manolis\AppData\Roaming\Skype
2013-11-03 18:26 - 2012-03-29 18:55 - 00000000 ___RD C:\Program Files\Skype
2013-11-03 18:26 - 2012-03-29 18:55 - 00000000 ____D C:\ProgramData\Skype
2013-11-01 11:15 - 2013-04-08 13:33 - 00000000 ___RD C:\Users\Manolis\HypoVereinsbank

Some content of TEMP:
====================
C:\Users\Manolis\AppData\Local\Temp\avgnt.exe
C:\Users\Manolis\AppData\Local\Temp\jre-7u17-windows-i586-iftw.exe
C:\Users\Manolis\AppData\Local\Temp\jre-7u21-windows-i586-iftw.exe
C:\Users\Manolis\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe
C:\Users\Manolis\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Manolis\AppData\Local\Temp\SkypeSetup.exe


==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================


==================== Memory info ===========================

Percentage of memory in use: 13%
Total physical RAM: 3839.24 MB
Available physical RAM: 3312.44 MB
Total Pagefile: 3837.52 MB
Available Pagefile: 3335.63 MB
Total Virtual: 2047.88 MB
Available Virtual: 1935.04 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:931.41 GB) (Free:826.42 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (MEDHPELL32) (CDROM) (Total:2.26 GB) (Free:0 GB) CDFS
Drive f: () (Removable) (Total:1.86 GB) (Free:1.44 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (Δεσμευμένο από το σύστημα) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 2BD2C32A)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (Size: 2 GB) (Disk ID: 496B48DD)
Partition 1: (Not Active) - (Size=2 GB) - (Type=0C)


LastRegBack: 2013-11-30 13:35

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

schrauber 01.12.2013 18:13

Hi,

hast Du Antivir auch wieder neu installiert oder ist das Problem seit der Deinstallation?

Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

LastRegBack: 2013-11-30 13:35
Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Entfernen Button.

Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.

manolis 01.12.2013 18:25

Hallo,

das Problem habe ich seit der Deinstallierung.

Anbei die Fixlog
Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 01-12-2013
Ran by SYSTEM at 2013-12-01 19:23:05 Run:1
Running from F:\
Boot Mode: Recovery

==============================================

Content of fixlist:
*****************
LastRegBack: 2013-11-30 13:35
*****************

DEFAULT hive was successfully copied to System32\config\HiveBackup
DEFAULT hive was successfully restored from registry back up.
SAM hive was successfully copied to System32\config\HiveBackup
SAM hive was successfully restored from registry back up.
SECURITY hive was successfully copied to System32\config\HiveBackup
SECURITY hive was successfully restored from registry back up.
SOFTWARE hive was successfully copied to System32\config\HiveBackup
SOFTWARE hive was successfully restored from registry back up.
SYSTEM hive was successfully copied to System32\config\HiveBackup
SYSTEM hive was successfully restored from registry back up.

==== End of Fixlog ====


schrauber 02.12.2013 11:26

Geht es jetzt wieder?

manolis 03.12.2013 20:09

Nein geht leider immer noch nicht. Immer noch das selbe Problem.

schrauber 04.12.2013 11:48

Als aller erstes würd ich jetzt mal Daten sichern von Aussen, mit Linux oder so. ich glaub das Ding ist hin.


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:02 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131