![]() |
Prima. :daumenhoc Aber das Log ist unvollständig. Ist das wirklich alles, was in diesem Textfile drin ist...? |
Log von FRST * Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2013 (ATTENTION: FRST version is 25 days old) Ran by SYSTEM at 07-04-2013 20:38:31 Running from H:\ Windows 7 Home Premium (X86) OS Language: German Standard The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [102400 2010-06-08] (Advanced Micro Devices, Inc.) HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1725736 2010-04-22] (Synaptics Incorporated) HKLM\...\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-11-02] (CyberLink) HKLM\...\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe [2478080 2010-06-22] (Micro-Star International Co., Ltd.) HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [9267816 2010-06-08] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe /FORPCEE3 [1481320 2010-06-08] (Realtek Semiconductor) HKLM\...\Run: [FUFAXSTM] "C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe" [847872 2009-12-02] (SEIKO EPSON CORPORATION) HKLM\...\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe" [976320 2009-12-03] (SEIKO EPSON CORPORATION) HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-03] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [41208 2012-12-19] (Adobe Systems Incorporated) HKLM\...\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-10] (Avira Operations GmbH & Co. KG) HKU\Default\...\RunOnce: [Screensaver] C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-22] () HKU\Default\...\RunOnce: [MEDION] C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-22] () HKU\Default User\...\RunOnce: [Screensaver] C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-22] () HKU\Default User\...\RunOnce: [MEDION] C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-22] () HKU\Otto\...\Run: [Epson Stylus Office BX320FW(Netzwerk)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGIE.EXE /FU "C:\Windows\TEMP\E_S4308.tmp" /EF "HKCU" [200704 2009-09-14] (SEIKO EPSON CORPORATION) HKU\Otto\...\Winlogon: [Shell] explorer.exe,C:\Users\Otto\AppData\Roaming\skype.dat [94208 2011-11-17] () Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 ==================== Services (Whitelisted) =================== 2 AntiVirSchedulerService; "C:\Program Files\Avira\AntiVir Desktop\sched.exe" [86224 2012-05-13] (Avira Operations GmbH & Co. KG) 2 AntiVirService; "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [110032 2012-05-13] (Avira Operations GmbH & Co. KG) 2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) 2 Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [160768 2009-07-09] (Micro-Star International Co., Ltd.) 2 PSI_SVC_2; "c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" [x] ==================== Drivers (Whitelisted) ==================== 2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [83392 2012-05-13] (Avira GmbH) 1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137928 2012-05-13] (Avira GmbH) 1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [36000 2011-09-16] (Avira GmbH) 3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [22112 2012-06-26] (Microsoft Corporation) 3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [168480 2009-12-02] (Realtek Semiconductor Corp.) 1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-10-08] (Avira GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-04-07 20:38 - 2013-04-07 20:38 - 00000000 ____D C:\FRST 2013-04-02 19:01 - 2013-04-07 18:54 - 00000004 ____A C:\Users\Otto\AppData\Roaming\skype.ini 2013-04-02 19:00 - 2013-04-02 19:00 - 00094208 ____A C:\Users\Otto\2874592.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 14317568 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 13761024 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 02877440 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-03-30 18:52 - 2013-03-30 18:52 - 02046464 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 01766912 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 01441280 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-03-30 18:52 - 2013-03-30 18:52 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-03-30 18:52 - 2013-03-30 18:52 - 01129984 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00745472 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00719360 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00690688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00629248 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00493056 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00391680 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00361984 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-03-30 18:52 - 2013-03-30 18:52 - 00357888 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00242200 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00232960 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00226816 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00185344 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00158720 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00138752 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00137216 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00125440 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00117248 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00109056 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00079872 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00073728 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00069120 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00061952 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-03-30 18:52 - 2013-03-30 18:52 - 00061440 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00042496 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00038400 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00023040 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00011776 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-03-30 18:51 - 2013-03-30 18:54 - 00009482 ____A C:\Windows\IE10_main.log 2013-03-30 18:07 - 2013-02-12 04:32 - 00015872 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023.sys ==================== One Month Modified Files and Folders ======== 2013-04-07 19:02 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\LogFiles 2013-04-07 18:54 - 2013-04-02 19:01 - 00000004 ____A C:\Users\Otto\AppData\Roaming\skype.ini 2013-04-07 18:52 - 2010-06-22 11:24 - 01500254 ____A C:\Windows\System32\PerfStringBackup.INI 2013-04-07 18:48 - 2009-07-14 05:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-04-07 18:48 - 2009-07-14 05:39 - 00082345 ____A C:\Windows\setupact.log 2013-04-07 17:09 - 2012-04-06 14:36 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-04-07 17:09 - 2009-07-14 05:34 - 00009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-04-07 17:09 - 2009-07-14 05:34 - 00009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-04-07 17:06 - 2010-08-06 20:45 - 01928066 ____A C:\Windows\WindowsUpdate.log 2013-04-02 19:00 - 2013-04-02 19:00 - 00094208 ____A C:\Users\Otto\2874592.exe 2013-04-02 19:00 - 2010-08-06 20:51 - 00000000 ____D C:\users\Otto 2013-03-31 16:32 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2013-03-31 14:39 - 2010-12-28 14:55 - 00000000 ____D C:\Users\Otto\Tracing 2013-03-31 07:27 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\de-DE 2013-03-31 07:26 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\DriverStore 2013-03-30 18:56 - 2010-06-22 11:24 - 69796088 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-03-30 18:56 - 2010-06-22 11:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-03-30 18:54 - 2013-03-30 18:51 - 00009482 ____A C:\Windows\IE10_main.log 2013-03-30 18:52 - 2013-03-30 18:52 - 14317568 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 13761024 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 02877440 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-03-30 18:52 - 2013-03-30 18:52 - 02046464 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 01766912 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 01441280 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-03-30 18:52 - 2013-03-30 18:52 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-03-30 18:52 - 2013-03-30 18:52 - 01129984 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00745472 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00719360 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00690688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00629248 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00493056 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00391680 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00361984 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-03-30 18:52 - 2013-03-30 18:52 - 00357888 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00242200 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00232960 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00226816 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00185344 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00158720 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00138752 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00137216 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00125440 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00117248 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00109056 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00079872 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00073728 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00069120 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00061952 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-03-30 18:52 - 2013-03-30 18:52 - 00061440 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00042496 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00038400 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00023040 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00011776 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-03-30 18:09 - 2012-04-06 14:36 - 00693976 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2013-03-30 18:09 - 2011-12-19 10:02 - 00073432 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2013-03-30 17:59 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\NDF 2013-03-25 15:21 - 2010-08-06 21:39 - 00000000 ____D C:\Users\Otto\AppData\Roaming\SoftGrid Client 2013-03-12 00:10 - 2010-06-22 11:23 - 00237088 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit |
Immer noch unvollständig ;) |
jetzt isser vollständig... Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2013 (ATTENTION: FRST version is 25 days old) Ran by SYSTEM at 07-04-2013 20:38:31 Running from H:\ Windows 7 Home Premium (X86) OS Language: German Standard The current controlset is ControlSet001 ==================== Registry (Whitelisted) =================== HKLM\...\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun [102400 2010-06-08] (Advanced Micro Devices, Inc.) HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1725736 2010-04-22] (Synaptics Incorporated) HKLM\...\Run: [CLMLServer] "C:\Program Files\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-11-02] (CyberLink) HKLM\...\Run: [MGSysCtrl] C:\Program Files\System Control Manager\MGSysCtrl.exe [2478080 2010-06-22] (Micro-Star International Co., Ltd.) HKLM\...\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -s [9267816 2010-06-08] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] C:\Program Files\Realtek\Audio\HDA\RtHDVBg.exe /FORPCEE3 [1481320 2010-06-08] (Realtek Semiconductor) HKLM\...\Run: [FUFAXSTM] "C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe" [847872 2009-12-02] (SEIKO EPSON CORPORATION) HKLM\...\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe" [976320 2009-12-03] (SEIKO EPSON CORPORATION) HKLM\...\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [946352 2012-12-03] (Adobe Systems Incorporated) HKLM\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [41208 2012-12-19] (Adobe Systems Incorporated) HKLM\...\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min [348664 2012-08-10] (Avira Operations GmbH & Co. KG) HKU\Default\...\RunOnce: [Screensaver] C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-22] () HKU\Default\...\RunOnce: [MEDION] C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-22] () HKU\Default User\...\RunOnce: [Screensaver] C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-22] () HKU\Default User\...\RunOnce: [MEDION] C:\Windows\Web\Wallpaper\MEDION\start.vbs [129 2009-10-22] () HKU\Otto\...\Run: [Epson Stylus Office BX320FW(Netzwerk)] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIGIE.EXE /FU "C:\Windows\TEMP\E_S4308.tmp" /EF "HKCU" [200704 2009-09-14] (SEIKO EPSON CORPORATION) HKU\Otto\...\Winlogon: [Shell] explorer.exe,C:\Users\Otto\AppData\Roaming\skype.dat [94208 2011-11-17] () Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 ==================== Services (Whitelisted) =================== 2 AntiVirSchedulerService; "C:\Program Files\Avira\AntiVir Desktop\sched.exe" [86224 2012-05-13] (Avira Operations GmbH & Co. KG) 2 AntiVirService; "C:\Program Files\Avira\AntiVir Desktop\avguard.exe" [110032 2012-05-13] (Avira Operations GmbH & Co. KG) 2 EpsonBidirectionalService; C:\Program Files\Common Files\EPSON\EBAPI\eEBSVC.exe [94208 2006-12-19] (SEIKO EPSON CORPORATION) 2 Micro Star SCM; C:\Program Files\System Control Manager\MSIService.exe [160768 2009-07-09] (Micro-Star International Co., Ltd.) 2 PSI_SVC_2; "c:\Program Files\Common Files\Protexis\License Service\PsiService_2.exe" [x] ==================== Drivers (Whitelisted) ==================== 2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [83392 2012-05-13] (Avira GmbH) 1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [137928 2012-05-13] (Avira GmbH) 1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [36000 2011-09-16] (Avira GmbH) 3 NuidFltr; C:\Windows\System32\DRIVERS\NuidFltr.sys [22112 2012-06-26] (Microsoft Corporation) 3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [168480 2009-12-02] (Realtek Semiconductor Corp.) 1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2009-10-08] (Avira GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-04-07 20:38 - 2013-04-07 20:38 - 00000000 ____D C:\FRST 2013-04-02 19:01 - 2013-04-07 18:54 - 00000004 ____A C:\Users\Otto\AppData\Roaming\skype.ini 2013-04-02 19:00 - 2013-04-02 19:00 - 00094208 ____A C:\Users\Otto\2874592.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 14317568 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 13761024 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 02877440 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-03-30 18:52 - 2013-03-30 18:52 - 02046464 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 01766912 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 01441280 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-03-30 18:52 - 2013-03-30 18:52 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-03-30 18:52 - 2013-03-30 18:52 - 01129984 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00745472 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00719360 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00690688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00629248 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00493056 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00391680 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00361984 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-03-30 18:52 - 2013-03-30 18:52 - 00357888 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00242200 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00232960 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00226816 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00185344 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00158720 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00138752 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00137216 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00125440 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00117248 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00109056 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00079872 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00073728 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00069120 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00061952 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-03-30 18:52 - 2013-03-30 18:52 - 00061440 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00042496 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00038400 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00023040 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00011776 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-03-30 18:51 - 2013-03-30 18:54 - 00009482 ____A C:\Windows\IE10_main.log 2013-03-30 18:07 - 2013-02-12 04:32 - 00015872 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\usb8023.sys ==================== One Month Modified Files and Folders ======== 2013-04-07 19:02 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\LogFiles 2013-04-07 18:54 - 2013-04-02 19:01 - 00000004 ____A C:\Users\Otto\AppData\Roaming\skype.ini 2013-04-07 18:52 - 2010-06-22 11:24 - 01500254 ____A C:\Windows\System32\PerfStringBackup.INI 2013-04-07 18:48 - 2009-07-14 05:53 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-04-07 18:48 - 2009-07-14 05:39 - 00082345 ____A C:\Windows\setupact.log 2013-04-07 17:09 - 2012-04-06 14:36 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-04-07 17:09 - 2009-07-14 05:34 - 00009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-04-07 17:09 - 2009-07-14 05:34 - 00009696 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-04-07 17:06 - 2010-08-06 20:45 - 01928066 ____A C:\Windows\WindowsUpdate.log 2013-04-02 19:00 - 2013-04-02 19:00 - 00094208 ____A C:\Users\Otto\2874592.exe 2013-04-02 19:00 - 2010-08-06 20:51 - 00000000 ____D C:\users\Otto 2013-03-31 16:32 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\rescache 2013-03-31 14:39 - 2010-12-28 14:55 - 00000000 ____D C:\Users\Otto\Tracing 2013-03-31 07:27 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\de-DE 2013-03-31 07:26 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\DriverStore 2013-03-30 18:56 - 2010-06-22 11:24 - 69796088 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-03-30 18:56 - 2010-06-22 11:23 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-03-30 18:54 - 2013-03-30 18:51 - 00009482 ____A C:\Windows\IE10_main.log 2013-03-30 18:52 - 2013-03-30 18:52 - 14317568 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 13761024 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 02877440 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-03-30 18:52 - 2013-03-30 18:52 - 02046464 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 01766912 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 01441280 ____A (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-03-30 18:52 - 2013-03-30 18:52 - 01400416 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dat 2013-03-30 18:52 - 2013-03-30 18:52 - 01129984 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00745472 ____A (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00719360 ____A (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00690688 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00629248 ____A (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00523264 ____A (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00493056 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00391680 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00361984 ____A (Microsoft Corporation) C:\Windows\System32\html.iec 2013-03-30 18:52 - 2013-03-30 18:52 - 00357888 ____A (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00242200 ____A (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00232960 ____A (Microsoft Corporation) C:\Windows\System32\url.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00226816 ____A (Microsoft Corporation) C:\Windows\System32\dxtrans.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00204800 ____A (Microsoft Corporation) C:\Windows\System32\webcheck.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00185344 ____A (Microsoft Corporation) C:\Windows\System32\elshyph.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00163840 ____A (Microsoft Corporation) C:\Windows\System32\msrating.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00158720 ____A (Microsoft Corporation) C:\Windows\System32\msls31.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00150528 ____A (Microsoft Corporation) C:\Windows\System32\iexpress.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00138752 ____A (Microsoft Corporation) C:\Windows\System32\wextract.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00137216 ____A (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00125440 ____A (Microsoft Corporation) C:\Windows\System32\occache.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00117248 ____A (Microsoft Corporation) C:\Windows\System32\iepeers.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00110592 ____A (Microsoft Corporation) C:\Windows\System32\IEAdvpack.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00109056 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00082432 ____A (Microsoft Corporation) C:\Windows\System32\inseng.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00079872 ____A (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00073728 ____A (Microsoft Corporation) C:\Windows\System32\SetIEInstalledDate.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00071680 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00069120 ____A (Microsoft Corporation) C:\Windows\System32\icardie.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00061952 ____A (Microsoft Corporation) C:\Windows\System32\tdc.ocx 2013-03-30 18:52 - 2013-03-30 18:52 - 00061440 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00057344 ____A (Microsoft Corporation) C:\Windows\System32\pngfilt.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00048640 ____A (Microsoft Corporation) C:\Windows\System32\mshtmler.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00042496 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00041984 ____A (Microsoft Corporation) C:\Windows\System32\msfeedsbs.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00038400 ____A (Microsoft Corporation) C:\Windows\System32\imgutil.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00033280 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00023040 ____A (Microsoft Corporation) C:\Windows\System32\licmgr10.dll 2013-03-30 18:52 - 2013-03-30 18:52 - 00012800 ____A (Microsoft Corporation) C:\Windows\System32\mshta.exe 2013-03-30 18:52 - 2013-03-30 18:52 - 00011776 ____A (Microsoft Corporation) C:\Windows\System32\msfeedssync.exe 2013-03-30 18:09 - 2012-04-06 14:36 - 00693976 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2013-03-30 18:09 - 2011-12-19 10:02 - 00073432 ____A (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2013-03-30 17:59 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\NDF 2013-03-25 15:21 - 2010-08-06 21:39 - 00000000 ____D C:\Users\Otto\AppData\Roaming\SoftGrid Client 2013-03-12 00:10 - 2010-06-22 11:23 - 00237088 ____N (Microsoft Corporation) C:\Windows\System32\MpSigStub.exe ==================== Known DLLs (Whitelisted) ================= ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-01-10 14:31:08 Restore point made on: 2013-01-10 17:04:44 Restore point made on: 2013-01-15 19:57:04 Restore point made on: 2013-01-22 15:23:30 Restore point made on: 2013-03-04 15:59:39 Restore point made on: 2013-03-05 15:36:37 Restore point made on: 2013-03-05 16:57:04 Restore point made on: 2013-03-30 18:06:41 Restore point made on: 2013-03-30 18:51:02 Restore point made on: 2013-04-07 17:05:19 ==================== Memory info =========================== Percentage of memory in use: 12% Total physical RAM: 3839.24 MB Available physical RAM: 3351.49 MB Total Pagefile: 3837.52 MB Available Pagefile: 3351.12 MB Total Virtual: 2047.88 MB Available Virtual: 1962.3 MB ==================== Partitions ============================= 1 Drive c: (BOOT) (Fixed) (Total:256.99 GB) (Free:215.77 GB) NTFS 2 Drive e: (Recover) (Fixed) (Total:40 GB) (Free:30.9 GB) NTFS 4 Drive g: (U3 System) (CDROM) (Total:0.01 GB) (Free:0 GB) CDFS 5 Drive h: (Cruzer) (Removable) (Total:1.86 GB) (Free:1.86 GB) FAT 6 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS 7 Drive y: () (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] Datentr„ger ### Status Gr”áe Frei Dyn GPT --------------- ------------- ------- ------- --- --- Datentr„ger 0 Online 298 GB 0 B Datentr„ger 1 Online 1907 MB 0 B Partitions of Disk 0: =============== Datentr„ger-ID: 64608E42 Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 100 MB 1024 KB Partition 2 Prim„r 256 GB 101 MB Partition 3 Prim„r 40 GB 257 GB Partition 4 OEM 1026 MB 297 GB ========================================================= Disk: 0 Partition 1 Typ : 07 Versteckt: Nein Aktiv : Ja Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 2 Y NTFS Partition 100 MB Fehlerfre ========================================================= Disk: 0 Partition 2 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 3 C BOOT NTFS Partition 256 GB Fehlerfre ========================================================= Disk: 0 Partition 3 Typ : 07 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 4 E Recover NTFS Partition 40 GB Fehlerfre ========================================================= Disk: 0 Partition 4 Typ : 12 Versteckt: Ja Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 6 NTFS Partition 1026 MB Fehlerfre Versteck ========================================================= Partitions of Disk 1: =============== Datentr„ger-ID: 00000000 Partition ### Typ Gr”áe Offset ------------- ---------------- ------- ------- Partition 1 Prim„r 1907 MB 64 KB ========================================================= Disk: 1 Partition 1 Typ : 06 Versteckt: Nein Aktiv : Nein Volume ### Bst Bezeichnung DS Typ Gr”áe Status Info ---------- --- ----------- ----- ---------- ------- --------- -------- * Volume 5 H Cruzer FAT Wechselmed 1907 MB Fehlerfre ========================================================= ============================== MBR Partition Table ================== ============================== Partitions of Disk 0: =============== Disk ID: 64608E42 Partition 1: ========= Hex: 8020210007DF130C0008000000200300 Active: YES Type: 07 (NTFS) Size: 100 MB Partition 2: ========= Hex: 00DF140C07FEFFFF0028030000A81F20 Active: NO Type: 07 (NTFS) Size: 257 GB Partition 3: ========= Hex: 00FEFFFF07FEFFFF00D0222000000005 Active: NO Type: 07 (NTFS) Size: 40 GB Partition 4: ========= Hex: 00FEFFFF12FEFFFF00D0222500102000 Active: NO Type: 12 Size: 1 GB ============================== Partitions of Disk 1: =============== Disk ID: 00000000 Partition 1: ========= Hex: 00020400063FFFC8810000003F9D3B00 Active: NO Type: 06 Size: 2 GB Last Boot: 2013-04-07 17:51 ==================== End Of Log ============================ |
Hallo, Zitat:
Nach Schritt 1 sollte der Sperrbildschirm weg sein und du kannst wieder ganz normal nach Windows starten. Führe danach die weiteren Schritte bitte im normalen Modus aus. Schritt 1 Drücke auf einem Zweitrechner bitte die http://larusso.trojaner-board.de/Images/windows.jpg + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument: Code: HKU\Otto\...\Winlogon: [Shell] explorer.exe,C:\Users\Otto\AppData\Roaming\skype.dat [94208 2011-11-17] ()
Ab hier wieder im normalen Modus von Windows arbeiten: Schritt 2 Lade dir Gmer herunter (auf den Button Download EXE drücken) und speichere das Programm auf den Desktop.
Schritt 3 Lade dir bitte OTL (von Oldtimer) herunter und speichere es auf deinen Desktop.
Bitte poste in deiner nächsten Antwort:
|
Fixlog von FRST * Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 13-03-2013 Ran by SYSTEM at 2013-04-07 21:34:43 Run:2 Running from H:\ ============================================== C:\Users\Otto\AppData\Roaming\skype.dat not found. C:\Users\Otto\AppData\Roaming\skype.ini not found. C:\Users\Otto\2874592.exe not found. ==== End of Fixlog ==== so... Laptop / Windows sind/ist wieder normal gestartet.... die Schritte 2 + 3 können auch später durchgeführt werden??? |
Hallo, Zitat:
Aber wir sollten schon noch weitermachen und schauen, ob sonst noch was drauf ist. Melde dich einfach wieder, sobald du die Logs aus den Schritten 2 und 3 hast, dann geht's weiter. |
okay... werde Schritte 2+3 morgen gleich "machen" und bedanke mich erstmal für die sehr gute Hilfe... danke... Gruß Micha |
In Ordnung, danke für die Mitteilung. |
Guten Tag Leo... hier ist...Log von Gmer GMER Logfile: Code: GMER 2.1.19163 - hxxp://www.gmer.net ################ hier ist Log von OTL ..aber den/die Extras.txt wurde nicht erstellt....OTL Logfile: Code: OTL logfile created on: 08.04.2013 10:49:03 - Run 1 |
Prima. Schritt 1 Downloade dir bitte AdwCleaner und speichere es auf deinen Desktop.
Schritt 2 Starte bitte die OTL.exe.
Bitte poste in deiner nächsten Antwort:
|
Log Extras... doch noch gefunden... *OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 08.04.2013 10:49:03 - Run 1 |
Ok, danke. Dann weiter mit oben angegebenen Schritten. |
Log von AdwCleaner *AdwCleaner Logfile: Code: # AdwCleaner v2.200 - Datei am 08/04/2013 um 13:54:55 erstellt ********** Log von OTL *OTL Logfile: Code: OTL logfile created on: 08.04.2013 14:00:45 - Run 2 |
Hallo, wie läuft der Rechner jetzt? Schritt 1
Code: :commands
Schritt 2 Downloade dir bitte Malwarebytes Anti-Malware.
Schritt 3 Lade das Setup des ESET Online Scanners herunter und speichere es auf den Desktop.
Schritt 4 Downloade dir bitte SecurityCheck (Link 1, Link 2).
Bitte poste in deiner nächsten Antwort:
|
Alle Zeitangaben in WEZ +1. Es ist jetzt 13:30 Uhr. |
Copyright ©2000-2025, Trojaner-Board