|  | 
| 
 | |||||||
| Plagegeister aller Art und deren Bekämpfung: Laptop VirenverdachtWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. | 
|  | 
|  | 
|  28.12.2015, 16:32 | #1 | 
|   |   Laptop Virenverdacht Hi, hab wiedermal ein Problem mit dem Laptop und wollte ihn einmal komplett bereinigen, falls sich Viren darauf befinden. Hier schonmal ein frisches FRST: Code: 
  ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:28-12-2015 Ran by Tabiga (administrator) on CELIK (28-12-2015 16:23:01) Running from C:\Users\Tabiga\Downloads Loaded Profiles: Tabiga & (Available Profiles: Tabiga) Platform: Microsoft Windows 8.1 Pro (X86) Language: Englisch (Vereinigte Staaten) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (Stardock Software, Inc) C:\Program Files\Stardock\Start8\Start8Srv.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation) C:\Program Files\Windows Defender\NisSrv.exe (Google Inc.) C:\Program Files\Google\Update\1.3.29.1\GoogleCrashHandler.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (AMD) C:\Windows\System32\atieclxx.exe (Stardock Software, Inc) C:\Program Files\Stardock\Start8\Start8.exe (Microsoft Corporation) C:\Windows\System32\SkyDrive.exe (Microsoft Corporation) C:\Windows\System32\GWX\GWX.exe (Advanced Micro Devices Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (ATI Technologies Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe (Microsoft Corporation) C:\Windows\System32\SettingSyncHost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Malwarebytes) C:\Program Files\ Malwarebytes Anti-Malware \mbam.exe (Malwarebytes) C:\Program Files\ Malwarebytes Anti-Malware \mbamresearch.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe ==================== Registry (Whitelisted) =========================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [StartCCC] => C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\x86\CLIStart.exe [747744 2014-07-04] (Advanced Micro Devices, Inc.) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [157480 2015-02-13] (Apple Inc.) HKU\S-1-5-21-3321966403-3621999409-2987640249-1001\...\MountPoints2: {e1acc6b8-5eb1-11e4-9719-dc0ea1110096} - "I:\SETUP.EXE" HKU\S-1-5-21-3321966403-3621999409-2987640249-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\MountPoints2: {e1acc6b8-5eb1-11e4-9719-dc0ea1110096} - "I:\SETUP.EXE" Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk [2015-12-15] ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files\McAfee Security Scan\3.11.266\SSScheduler.exe (McAfee, Inc.) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704 2011-08-30] (Apple Inc.) Hosts: 0.0.0.1 mssplus.mcafee.com Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 192.168.2.1 Tcpip\..\Interfaces\{214CCE12-3240-48B2-B5D2-3349032FB47E}: [DhcpNameServer] 192.168.2.1 192.168.2.1 Internet Explorer: ================== BHO: Microsoft SkyDrive Pro Browser Helper -> {D0498E0A-45B7-42AE-A9AA-ABA463DBD3BF} -> C:\Program Files\Microsoft Office\Office15\GROOVEEX.DLL [2015-11-10] (Microsoft Corporation) Handler: osf - {D924BDC6-C83A-4BD5-90D0-095128A113D1} - C:\Program Files\Microsoft Office\Office15\MSOSB.DLL [2015-02-17] (Microsoft Corporation) FireFox: ======== FF ProfilePath: C:\Users\Tabiga\AppData\Roaming\Mozilla\Firefox\Profiles\yztt6gk7.default FF Homepage: about:cliqz FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_20_0_0_235.dll [2015-12-09] () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll [2014-10-30] () FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll [2015-05-20] (Google) FF Plugin: @microsoft.com/SharePoint,version=14.0 -> C:\PROGRA~1\MICROS~1\Office15\NPSPWRAP.DLL [2014-01-23] (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=16.4.3528.0331 -> C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll [2014-03-31] (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.29.1\npGoogleUpdate3.dll [2015-12-05] (Google Inc.) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll [2015-09-27] (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Tabiga\AppData\Roaming\Mozilla\Firefox\Profiles\yztt6gk7.default\searchplugins\google-images.xml [2014-11-07] FF SearchPlugin: C:\Users\Tabiga\AppData\Roaming\Mozilla\Firefox\Profiles\yztt6gk7.default\searchplugins\google-maps.xml [2014-11-07] FF SearchPlugin: C:\Users\Tabiga\AppData\Roaming\Mozilla\Firefox\Profiles\yztt6gk7.default\searchplugins\youtube.xml [2015-11-13] FF Extension: Cliqz - C:\Users\Tabiga\AppData\Roaming\Mozilla\Firefox\Profiles\yztt6gk7.default\Extensions\cliqz@cliqz.com.xpi [2015-12-22] FF Extension: Adblock Plus - C:\Users\Tabiga\AppData\Roaming\Mozilla\Firefox\Profiles\yztt6gk7.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-12-15] FF HKU\S-1-5-21-3321966403-3621999409-2987640249-1001\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Tabiga\AppData\Roaming\Mozilla\Firefox\Profiles\yztt6gk7.default\extensions\cliqz@cliqz.com => not found FF HKU\S-1-5-21-3321966403-3621999409-2987640249-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\Tabiga\AppData\Roaming\Mozilla\Firefox\Profiles\yztt6gk7.default\extensions\cliqz@cliqz.com => not found FF ExtraCheck: C:\Program Files\mozilla firefox\defaults\pref\itms.js [2015-02-09] Chrome: ======= CHR Profile: C:\Users\Tabiga\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Präsentationen) - C:\Users\Tabiga\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-18] CHR Extension: (Google Docs) - C:\Users\Tabiga\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-18] CHR Extension: (Google Drive) - C:\Users\Tabiga\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-07-20] CHR Extension: (YouTube) - C:\Users\Tabiga\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-10-12] CHR Extension: (Google-Suche) - C:\Users\Tabiga\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-04-14] CHR Extension: (Google Tabellen) - C:\Users\Tabiga\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-18] CHR Extension: (Google Docs Offline) - C:\Users\Tabiga\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghbmnnjooekpmoecnnnilnnbdlolhkhi [2015-10-12] CHR Extension: (Chrome Hotword Shared Module) - C:\Users\Tabiga\AppData\Local\Google\Chrome\User Data\Default\Extensions\lccekmodgklaepjeofjdjpbminllajkg [2015-07-16] CHR Extension: (Chrome Web Store-Zahlungen) - C:\Users\Tabiga\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-10-12] CHR Extension: (Google Mail) - C:\Users\Tabiga\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-04-14] ==================== Services (Whitelisted) ======================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [276992 2014-07-04] (Advanced Micro Devices, Inc.) [File not signed] S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [1135416 2015-10-05] (Malwarebytes) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.11.266\McCHSvc.exe [235696 2015-12-02] (McAfee, Inc.) S2 Service KMSELDI; C:\Program Files\KMSpico\Service_KMS.exe [977088 2014-03-02] () [File not signed] R2 Start8; C:\Program Files\Stardock\Start8\Start8Srv.exe [142960 2013-03-19] (Stardock Software, Inc) R3 WdNisSvc; C:\Program Files\Windows Defender\NisSrv.exe [284520 2015-07-07] (Microsoft Corporation) R2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [22224 2015-07-07] (Microsoft Corporation) ===================== Drivers (Whitelisted) ========================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R3 athr; C:\Windows\system32\DRIVERS\athw8.sys [2795520 2013-06-18] (Qualcomm Atheros Communications, Inc.) R1 dtsoftbus01; C:\Windows\System32\drivers\dtsoftbus01.sys [218688 2014-10-30] (DT Soft Ltd) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2015-10-05] (Malwarebytes) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [170200 2015-12-28] (Malwarebytes) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2015-10-05] (Malwarebytes Corporation) S0 WdBoot; C:\Windows\System32\drivers\WdBoot.sys [38928 2015-07-07] (Microsoft Corporation) R0 WdFilter; C:\Windows\System32\drivers\WdFilter.sys [233304 2015-07-07] (Microsoft Corporation) R2 WdNisDrv; C:\Windows\System32\Drivers\WdNisDrv.sys [84824 2015-07-07] (Microsoft Corporation) S3 WinDivert1.1; C:\Program Files\KMSpico\WinDivert.sys [30256 2014-10-23] (Basil Projects) S3 WUDFSensorLP; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-29] (Microsoft Corporation) S3 WUDFWpdMtp; C:\Windows\System32\drivers\WUDFRd.sys [190976 2014-10-29] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-12-28 16:23 - 2015-12-28 16:23 - 00010842 _____ C:\Users\Tabiga\Downloads\FRST.txt 2015-12-28 16:22 - 2015-12-28 16:23 - 00000000 ____D C:\FRST 2015-12-28 16:22 - 2015-12-28 16:22 - 01721856 _____ (Farbar) C:\Users\Tabiga\Downloads\FRST.exe 2015-12-28 16:09 - 2015-12-28 16:10 - 00170200 _____ (Malwarebytes) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2015-12-28 16:09 - 2015-12-28 16:09 - 00001076 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2015-12-28 16:09 - 2015-12-28 16:09 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2015-12-28 16:08 - 2015-12-28 16:09 - 00000000 ____D C:\Program Files\ Malwarebytes Anti-Malware 2015-12-28 16:08 - 2015-12-28 16:08 - 00000000 ____D C:\ProgramData\Malwarebytes 2015-12-28 16:08 - 2015-10-05 09:50 - 00094936 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbamchameleon.sys 2015-12-28 16:08 - 2015-10-05 09:50 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2015-12-28 16:08 - 2015-10-05 09:50 - 00023256 _____ (Malwarebytes) C:\Windows\system32\Drivers\mbam.sys 2015-12-28 16:05 - 2015-12-28 16:05 - 01466656 _____ C:\Users\Tabiga\Downloads\Malwarebytes Anti Malware Malware Scanner - CHIP-Installer.exe 2015-12-23 12:52 - 2015-12-23 12:52 - 00000000 ____D C:\Program Files\Mozilla Firefox 2015-12-15 21:51 - 2015-12-15 21:51 - 00002061 _____ C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2015-12-15 21:51 - 2015-12-15 21:51 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee Security Scan Plus 2015-12-10 20:00 - 2015-10-22 17:59 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\kbdgeoqw.dll 2015-12-10 20:00 - 2015-10-22 17:59 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZST.DLL 2015-12-10 20:00 - 2015-10-22 17:59 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZEL.DLL 2015-12-10 20:00 - 2015-10-22 17:59 - 00006144 _____ (Microsoft Corporation) C:\Windows\system32\KBDAZE.DLL 2015-12-10 20:00 - 2015-10-22 16:58 - 00868864 _____ (Microsoft Corporation) C:\Windows\system32\Windows.Globalization.dll 2015-12-10 20:00 - 2015-10-22 16:58 - 00200704 _____ (Microsoft Corporation) C:\Windows\system32\GlobCollationHost.dll 2015-12-10 20:00 - 2015-10-22 15:10 - 00513456 _____ C:\Windows\system32\locale.nls 2015-12-10 20:00 - 2015-10-11 07:39 - 00382808 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2015-12-10 20:00 - 2015-10-11 07:39 - 00378712 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2015-12-10 20:00 - 2015-10-11 07:39 - 00377176 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\USBHUB3.SYS 2015-12-10 20:00 - 2015-10-11 07:39 - 00074584 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2015-12-10 20:00 - 2015-10-11 07:39 - 00023896 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2015-12-10 20:00 - 2015-10-10 18:36 - 00026112 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2015-12-10 20:00 - 2015-10-10 18:36 - 00022016 ____C (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2015-12-10 20:00 - 2015-10-10 17:41 - 00148480 _____ (Microsoft Corporation) C:\Windows\system32\dpapisrv.dll 2015-12-10 20:00 - 2015-10-08 16:50 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\PCPKsp.dll 2015-12-10 20:00 - 2015-10-05 20:30 - 00115712 _____ (Microsoft Corporation) C:\Windows\system32\wininit.exe 2015-12-10 20:00 - 2015-10-05 20:29 - 00465920 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2015-12-10 20:00 - 2015-10-03 20:41 - 01124384 _____ (Microsoft Corporation) C:\Windows\system32\msctf.dll 2015-12-10 14:09 - 2015-11-05 09:21 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rmcast.sys 2015-12-10 14:09 - 2015-10-28 16:29 - 02462720 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2015-12-10 14:06 - 2015-11-22 08:05 - 01469968 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2015-12-10 14:06 - 2015-11-22 08:05 - 01393584 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2015-12-10 14:06 - 2015-11-22 08:04 - 05766488 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-12-10 14:06 - 2015-11-22 08:04 - 01282528 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2015-12-10 14:06 - 2015-11-22 08:04 - 01269072 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2015-12-10 14:06 - 2015-11-22 08:04 - 01168920 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2015-12-10 14:06 - 2015-11-21 17:49 - 01344000 _____ (Microsoft Corporation) C:\Windows\system32\comsvcs.dll 2015-12-10 14:06 - 2015-11-21 17:40 - 00414208 _____ (Microsoft Corporation) C:\Windows\system32\catsrvut.dll 2015-12-10 14:06 - 2015-11-10 01:13 - 00496640 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-12-10 14:06 - 2015-11-10 01:02 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2015-12-10 14:06 - 2015-11-10 00:46 - 04514816 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-12-10 14:06 - 2015-11-10 00:17 - 02011136 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-12-10 14:06 - 2015-11-08 23:44 - 01403304 _____ (Microsoft Corporation) C:\Windows\system32\user32.dll 2015-12-10 14:06 - 2015-11-08 22:48 - 03520000 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-12-10 14:06 - 2015-11-08 21:52 - 01559552 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2015-12-10 14:06 - 2015-11-08 21:49 - 01087488 _____ (Microsoft Corporation) C:\Windows\system32\FntCache.dll 2015-12-10 14:06 - 2015-11-08 21:42 - 01490944 _____ (Microsoft Corporation) C:\Windows\system32\GdiPlus.dll 2015-12-10 14:05 - 2015-11-11 17:00 - 12856832 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-12-10 14:05 - 2015-11-11 16:44 - 00279040 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-12-10 14:05 - 2015-11-11 16:44 - 00128000 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2015-12-10 14:05 - 2015-11-11 16:41 - 20366848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-12-10 14:05 - 2015-11-10 01:11 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-12-10 14:05 - 2015-11-10 01:08 - 02280448 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-12-10 14:05 - 2015-11-10 01:04 - 00476160 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-12-10 14:05 - 2015-11-10 00:41 - 00880128 _____ (Microsoft Corporation) C:\Windows\system32\inetcomm.dll 2015-12-10 14:05 - 2015-11-10 00:37 - 00230400 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2015-12-10 14:05 - 2015-11-10 00:36 - 02050560 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-12-10 14:05 - 2015-11-10 00:36 - 00687104 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-12-10 14:05 - 2015-11-10 00:36 - 00684032 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-12-10 14:05 - 2015-11-10 00:36 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-12-10 14:05 - 2015-11-10 00:25 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\actxprxy.dll 2015-12-10 14:05 - 2015-11-10 00:14 - 01311744 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-12-10 14:05 - 2015-11-10 00:12 - 00710144 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-12-10 13:54 - 2015-11-20 23:52 - 00128568 _____ (Microsoft Corporation) C:\Windows\system32\wuauclt.exe 2015-12-10 13:54 - 2015-11-20 18:30 - 00023552 _____ (Microsoft Corporation) C:\Windows\system32\wups2.dll 2015-12-10 13:54 - 2015-11-20 17:32 - 03066880 _____ (Microsoft Corporation) C:\Windows\system32\wuaueng.dll 2015-12-10 13:54 - 2015-11-20 17:30 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\wuapp.exe 2015-12-10 13:54 - 2015-11-20 17:29 - 00124928 _____ (Microsoft Corporation) C:\Windows\system32\wuwebv.dll 2015-12-10 13:54 - 2015-11-20 17:28 - 00334336 _____ (Microsoft Corporation) C:\Windows\system32\WUSettingsProvider.dll 2015-12-10 13:54 - 2015-11-20 17:28 - 00081920 _____ (Microsoft Corporation) C:\Windows\system32\wudriver.dll 2015-12-10 13:54 - 2015-11-20 17:27 - 00726528 _____ (Microsoft Corporation) C:\Windows\system32\wuapi.dll 2015-12-10 13:54 - 2015-11-20 17:24 - 02176512 _____ (Microsoft Corporation) C:\Windows\system32\wucltux.dll 2015-12-09 14:19 - 2015-12-09 14:19 - 00083248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dc3d.sys ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-12-28 16:23 - 2013-08-22 07:21 - 00000000 ____D C:\Windows 2015-12-28 16:20 - 2014-10-24 16:56 - 00000830 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-12-25 15:37 - 2013-08-22 07:21 - 00000000 ____D C:\Windows\inf 2015-12-20 17:49 - 2014-10-23 19:27 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2015-12-20 17:48 - 2014-10-23 19:14 - 00000000 __RDO C:\Users\Tabiga\SkyDrive 2015-12-18 18:49 - 2013-08-22 09:05 - 00000000 ____D C:\Windows\CbsTemp 2015-12-17 18:37 - 2014-11-23 18:39 - 00002141 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2015-12-15 21:50 - 2015-11-19 11:31 - 00000000 ____D C:\Program Files\McAfee Security Scan 2015-12-15 16:48 - 2013-08-22 09:17 - 00000000 ____D C:\Windows\rescache 2015-12-15 15:40 - 2013-08-22 08:23 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-12-15 15:40 - 2013-08-22 08:22 - 00472672 _____ C:\Windows\system32\FNTCACHE.DAT 2015-12-15 15:38 - 2013-08-22 07:13 - 00262144 ___SH C:\Windows\system32\config\BBI 2015-12-15 15:27 - 2014-10-26 12:03 - 00000000 ____D C:\Windows\system32\MRT 2015-12-15 15:27 - 2014-10-26 12:02 - 137798368 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-12-15 15:24 - 2014-10-31 21:16 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-12-15 15:13 - 2014-11-06 20:35 - 00000000 ___RD C:\Users\Tabiga\OneDrive 2015-12-10 14:28 - 2014-10-31 21:21 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2013 2015-12-10 14:19 - 2013-08-22 07:13 - 00000167 _____ C:\Windows\win.ini 2015-12-09 20:04 - 2013-08-22 09:17 - 00000000 ____D C:\Windows\AppReadiness 2015-12-09 04:39 - 2014-10-25 12:35 - 00247976 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2015-12-05 16:50 - 2014-11-23 18:14 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-12-05 16:50 - 2014-11-23 18:14 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-12-01 18:19 - 2015-10-18 14:23 - 00826872 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-12-01 18:19 - 2015-10-18 14:23 - 00176632 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-11-29 16:07 - 2014-10-24 04:47 - 00000000 ____D C:\Windows\Panther 2015-11-29 15:09 - 2015-10-30 08:33 - 00000000 ___HD C:\$WINDOWS.~BT Some files in TEMP: ==================== C:\Users\Tabiga\AppData\Local\Temp\ose00000.exe ==================== Bamital & volsnap ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\dnsapi.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-12-26 12:28 ==================== End of FRST.txt ============================ Code: 
  ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:28-12-2015
Ran by Tabiga (2015-12-28 16:25:08)
Running from C:\Users\Tabiga\Downloads
Microsoft Windows 8.1 Pro (X86) (2014-10-23 18:10:51)
Boot Mode: Normal
==========================================================
==================== Accounts: =============================
Administrator (S-1-5-21-3321966403-3621999409-2987640249-500 - Administrator - Disabled)
Guest (S-1-5-21-3321966403-3621999409-2987640249-501 - Limited - Disabled)
Tabiga (S-1-5-21-3321966403-3621999409-2987640249-1001 - Administrator - Enabled) => C:\Users\Tabiga
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "Hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
Adobe Flash Player 20 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 20.0.0.235 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.13) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.13 - Adobe Systems Incorporated)
AMD VISION Engine Control Center (HKLM\...\WUCCCApp) (Version: 1.00.0000 - AMD)
Apple Application Support (32-Bit) (HKLM\...\{447CDCE5-F555-429B-BFA6-642C3C6D684F}) (Version: 3.1.2 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{E1DB0812-2D60-43DB-AE09-6C7027D93B28}) (Version: 8.1.1.3 - Apple Inc.)
Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.)
Cliqz (HKLM\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.31 - Cliqz.com)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
Fotogalerie (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Google Chrome (HKLM\...\Google Chrome) (Version: 47.0.2526.106 - Google Inc.)
Google Earth (HKLM\...\{817750FA-EC6A-485D-9901-0683AE6FFDF1}) (Version: 7.1.5.1557 - Google)
Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden
Google Update Helper (Version: 1.3.29.1 - Google Inc.) Hidden
iTunes (HKLM\...\{3A9FE6B1-EE7F-40AC-B831-AC7C9ABB58A0}) (Version: 12.1.1.4 - Apple Inc.)
Junk Mail filter update (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
KMSpico v9.2.3 (HKLM\...\KMSpico_is1) (Version: 9.2.3 - )
Malwarebytes Anti-Malware Version 2.2.0.1024 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.2.0.1024 - Malwarebytes)
McAfee Security Scan Plus (HKLM\...\McAfee Security Scan) (Version: 3.11.266.3 - McAfee, Inc.)
Microsoft Office Standard 2013 (HKLM\...\Office15.STANDARD) (Version: 15.0.4569.1506 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3321966403-3621999409-2987640249-1001\...\OneDriveSetup.exe) (Version: 17.3.6281.1202 - Microsoft Corporation)
Microsoft OneDrive (HKU\S-1-5-21-3321966403-3621999409-2987640249-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\...\OneDriveSetup.exe) (Version: 17.3.6281.1202 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030 (HKLM\...\{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}) (Version: 11.0.61030.0 - Microsoft Corporation)
Microsoft Visual Studio 2010 Tools for Office Runtime (x86) (HKLM\...\Microsoft Visual Studio 2010 Tools for Office Runtime (x86)) (Version: 10.0.50903 - Microsoft Corporation)
Movie Maker (Version: 16.4.3528.0331 - Microsoft Corporation) Hidden
Mozilla Firefox 43.0.2 (x86 de) (HKLM\...\Mozilla Firefox 43.0.2 (x86 de)) (Version: 43.0.2 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 43.0.2.5833 - Mozilla)
Outils de vérification linguistique 2013 de Microsoft Office*- Français (Version: 15.0.4569.1506 - Microsoft Corporation) Hidden
Stardock Start8 (HKLM\...\Start8_is1) (Version: 1.30.1 - Stardock Software, Inc.)
VLC media player (HKLM\...\VLC media player) (Version: 2.2.1 - VideoLAN)
Windows Live Essentials (HKLM\...\WinLiveSuite) (Version: 16.4.3528.0331 - Microsoft Corporation)
WinRAR 5.11 (32-Bit) (HKLM\...\WinRAR archiver) (Version: 5.11.0 - win.rar GmbH)
==================== Custom CLSID (Whitelisted): ==========================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== Scheduled Tasks (Whitelisted) =============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
Task: {3755938F-1324-4EF3-9535-3C0A6074DE74} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {4D97457D-AE66-4076-B9C4-E4D7E2B3EFFE} - System32\Tasks\Microsoft\Office\Office 15 Subscription Heartbeat => C:\Program Files\Common Files\Microsoft Shared\Office15\OLicenseHeartbeat.exe [2014-01-23] (Microsoft Corporation)
Task: {4E8B283C-0FB6-44B3-A385-E540631D747B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {63C07D02-6E6D-4112-8C28-3D7EC0063060} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2015-12-15] (Microsoft Corporation)
Task: {7AB22EB7-37E1-45F9-96C4-F6B8EF717EFE} - System32\Tasks\Microsoft\Office\OfficeTelemetryAgentFallBack => C:\Program Files\Microsoft Office\Office15\msoia.exe [2014-01-23] (Microsoft Corporation)
Task: {7AFDDE3E-84DF-4FA3-BF27-A642D83F3ED5} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2014-10-31] ()
Task: {B367F498-F239-48D2-B529-0DFC7AC6A041} - System32\Tasks\Microsoft OneDrive Auto Update Task-S-1-5-21-3321966403-3621999409-2987640249-1001 => C:\Users\Tabiga\AppData\Local\Microsoft\OneDrive\OneDrive.exe [2015-12-15] (Microsoft Corporation)
Task: {B769144B-2651-47CC-BB89-02A6A553D3E2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2015-08-30] (Google Inc.)
Task: {D3B2261E-07F9-4313-BB04-D789FED2095F} - System32\Tasks\AutoPico Daily Restart => C:\Program Files\KMSpico\AutoPico.exe [2014-03-02] ()
Task: {EE10631C-F344-4464-98A2-C0FEB7623225} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-12-09] (Adobe Systems Incorporated)
Task: {EF1DE69A-9C38-4A34-AE76-8D76D0D1706B} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2015-10-28] (Adobe Systems Incorporated)
(If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Shortcuts =============================
(The entries could be listed to be restored or removed.)
==================== Loaded Modules (Whitelisted) ==============
2014-07-04 20:33 - 2014-07-04 20:33 - 00114688 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Container.Wlan.dll
2015-02-13 04:20 - 2015-02-13 04:20 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2015-02-13 04:20 - 2015-02-13 04:20 - 01044776 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2014-07-04 20:33 - 2014-07-04 20:33 - 00095744 _____ () C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
==================== Alternate Data Streams (Whitelisted) =========
(If an entry is included in the fixlist, only the ADS will be removed.)
==================== Safe Mode (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The "AlternateShell" value will be restored.)
==================== EXE Association (Whitelisted) ===============
(If an entry is included in the fixlist, the registry item will be restored to default or removed.)
==================== Internet Explorer trusted/restricted ===============
(If an entry is included in the fixlist, it will be removed from the registry.)
==================== Hosts content: ===============================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2013-08-22 07:13 - 2015-12-15 21:51 - 00000860 ____A C:\Windows\system32\Drivers\etc\hosts
0.0.0.1	mssplus.mcafee.com
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-3321966403-3621999409-2987640249-1001\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
HKU\S-1-5-21-3321966403-3621999409-2987640249-1001-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\Control Panel\Desktop\\Wallpaper -> C:\Windows\web\wallpaper\Windows\img0.jpg
DNS Servers: 192.168.2.1
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System => (ConsentPromptBehaviorAdmin: 5) (ConsentPromptBehaviorUser: 3) (EnableLUA: 1)
Windows Firewall is enabled.
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== FirewallRules (Whitelisted) ===============
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
FirewallRules: [vm-monitoring-nb-session] => (Allow) LPort=139
FirewallRules: [{E3F0B89E-DC74-41D1-B0A1-12541CAF6803}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{3072EE1B-3459-4806-B0A5-67AAA6444764}] => (Allow) C:\Program Files\KMSpico\KMSELDI.exe
FirewallRules: [{A4D64E34-C2E2-4BFE-9EB4-15004D441458}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{93417AB8-BFEC-4AF5-BF88-850451EE1FF7}] => (Allow) C:\Program Files\KMSpico\AutoPico.exe
FirewallRules: [{EBDF1CEB-F303-4A1D-A30C-539AED5DF7C7}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{90B4D6F0-4623-4379-BEDD-8985A56ECA67}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{77B2CDFE-F1C1-4AE9-B0AE-E0D7C9DC28B8}] => (Allow) C:\Users\Tabiga\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe
FirewallRules: [{00E65202-E918-4DF6-9816-AD3723FDF478}] => (Allow) C:\Program Files\Windows Live\Contacts\wlcomm.exe
FirewallRules: [{7D981719-04E0-4C7E-9F9C-D64A2DE8D709}] => (Allow) LPort=2869
FirewallRules: [{C71B3D6F-5F90-4F79-A3C4-013E098EDB04}] => (Allow) LPort=1900
FirewallRules: [{178EECE8-AB42-498F-8E23-23C8E09476B5}] => (Allow) C:\Program Files\Windows Live\Messenger\msnmsgr.exe
FirewallRules: [{6DC03612-435B-4F7F-B6A9-FF59C6D5F1F3}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{42C782F3-F905-44CA-88DC-071D978EDC59}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [TCP Query User{0850FD2A-C832-4455-9D29-102A2E3ED6A7}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [UDP Query User{804FACF3-851E-4B19-8B6F-DE982ACEF0A3}C:\program files\mozilla firefox\firefox.exe] => (Block) C:\program files\mozilla firefox\firefox.exe
FirewallRules: [{5E1E91D1-4272-4477-A3C9-2F734B47D791}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{64424B24-293A-41FF-B3FF-06E15B8F904E}] => (Allow) C:\Program Files\Bonjour\mDNSResponder.exe
FirewallRules: [{F1DC0647-46D9-4408-8684-98A9554037FE}] => (Allow) C:\Program Files\iTunes\iTunes.exe
FirewallRules: [{B419C8E8-FAAC-4132-B11D-3A31DF50D36D}] => (Allow) LPort=1689
FirewallRules: [{9B5C0622-A4A7-4D59-8954-5DB36174EF0A}] => (Allow) LPort=1688
FirewallRules: [{C71CDB7B-057A-4766-8BD2-37ADF8D01C98}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{A9099707-4630-4415-83ED-E541C700DA43}] => (Allow) C:\Program Files\KMSpico\Service_KMS.exe
FirewallRules: [{941EF0CC-BA00-4792-9118-428235BF5C8D}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{286C94BA-4B85-4B56-86C7-1C4EED85038E}] => (Allow) C:\Program Files\Mozilla Firefox\firefox.exe
FirewallRules: [{4AB4E444-8FC2-4ED8-8252-5B6CA326F6DD}] => (Allow) C:\Program Files\Google\Chrome\Application\chrome.exe
FirewallRules: [{C86DFBD6-DED6-4B49-9F40-23E79D10B6B7}] => (Allow) C:\Windows\AutoKMS\AutoKMS.exe
FirewallRules: [{722E84D0-2956-4C7F-AC31-AF0D1E402C69}] => (Allow) C:\Windows\AutoKMS\AutoKMS.exe
==================== Restore Points =========================
10-12-2015 14:15:26 Windows Update
15-12-2015 15:22:39 Windows Update
18-12-2015 18:45:35 Windows Update
25-12-2015 12:34:52 Windows Update
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (12/27/2015 03:22:06 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AutoKMS.exe, Version: 2.5.0.0, Zeitstempel: 0x52ea7aea
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.3.9600.18007, Zeitstempel: 0x55c4bd56
Ausnahmecode: 0xe0434352
Fehleroffset: 0x00011b2a
ID des fehlerhaften Prozesses: 0x9e9c
Startzeit der fehlerhaften Anwendung: 0xAutoKMS.exe0
Pfad der fehlerhaften Anwendung: AutoKMS.exe1
Pfad des fehlerhaften Moduls: AutoKMS.exe2
Berichtskennung: AutoKMS.exe3
Vollständiger Name des fehlerhaften Pakets: AutoKMS.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: AutoKMS.exe5
Error: (12/27/2015 03:22:06 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: AutoKMS.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.UnauthorizedAccessException
Stack:
   at System.IO.__Error.WinIOError(Int32, System.String)
   at System.IO.FileInfo.Delete()
   at ..(System.String)
   at ..()
   at ..(., System.String, Boolean, System.String, Int32, System.String, System.String, Boolean, Boolean, Boolean, Boolean, Boolean, Boolean, System.String, System.String)
   at ..(Int32, System.String, System.String, System.String, Boolean, Boolean, Boolean, ., Boolean, Boolean, System.String, Boolean, Boolean, System.String)
   at ..(.)
   at ..()
Error: (12/27/2015 12:29:16 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AutoPico.exe, Version: 12.1.0.0, Zeitstempel: 0x5313ef46
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.3.9600.18007, Zeitstempel: 0x55c4bd56
Ausnahmecode: 0xe0434352
Fehleroffset: 0x00011b2a
ID des fehlerhaften Prozesses: 0xa670
Startzeit der fehlerhaften Anwendung: 0xAutoPico.exe0
Pfad der fehlerhaften Anwendung: AutoPico.exe1
Pfad des fehlerhaften Moduls: AutoPico.exe2
Berichtskennung: AutoPico.exe3
Vollständiger Name des fehlerhaften Pakets: AutoPico.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: AutoPico.exe5
Error: (12/27/2015 12:29:14 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: AutoPico.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.Management.ManagementException
Stack:
   at System.Management.ManagementException.ThrowWithExtendedInfo(System.Management.ManagementStatus)
   at System.Management.ManagementObject.InvokeMethod(System.String, System.Management.ManagementBaseObject, System.Management.InvokeMethodOptions)
   at AutoPico.Activador.WMI.SoftwareLicensingProduct.Activate()
   at AutoPico.Activador.WMISoftwareLicense.Activate(AutoPico.Activador.Variables ByRef, System.Collections.Generic.List`1<AutoPico.Activador.WMI.SoftwareLicensingProduct> ByRef)
   at AutoPico.Activador.Activador.ActivarWindows(AutoPico.Activador.Variables ByRef)
   at AutoPico.Activador.WMISoftwareLicense.ErrorActivacion(AutoPico.Activador.Variables ByRef, AutoPico.Activador.WMI.SoftwareLicensingProduct ByRef, System.String ByRef, Boolean ByRef, Boolean ByRef)
   at AutoPico.Activador.WMISoftwareLicense.Activate(AutoPico.Activador.Variables ByRef, System.Collections.Generic.List`1<AutoPico.Activador.WMI.SoftwareLicensingProduct> ByRef)
   at AutoPico.Activador.Activador.ActivarWindows(AutoPico.Activador.Variables ByRef)
   at AutoPico.Activador.Activador+_Closure$__1._Lambda$__1()
   at System.Threading.ThreadHelper.ThreadStart_Context(System.Object)
   at System.Threading.ExecutionContext.RunInternal(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object, Boolean)
   at System.Threading.ExecutionContext.Run(System.Threading.ExecutionContext, System.Threading.ContextCallback, System.Object)
   at System.Threading.ThreadHelper.ThreadStart()
Error: (12/26/2015 03:22:08 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: AutoKMS.exe, Version: 2.5.0.0, Zeitstempel: 0x52ea7aea
Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.3.9600.18007, Zeitstempel: 0x55c4bd56
Ausnahmecode: 0xe0434352
Fehleroffset: 0x00011b2a
ID des fehlerhaften Prozesses: 0x1d00
Startzeit der fehlerhaften Anwendung: 0xAutoKMS.exe0
Pfad der fehlerhaften Anwendung: AutoKMS.exe1
Pfad des fehlerhaften Moduls: AutoKMS.exe2
Berichtskennung: AutoKMS.exe3
Vollständiger Name des fehlerhaften Pakets: AutoKMS.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: AutoKMS.exe5
Error: (12/26/2015 03:22:07 PM) (Source: .NET Runtime) (EventID: 1026) (User: )
Description: Application: AutoKMS.exe
Framework Version: v4.0.30319
Description: The process was terminated due to an unhandled exception.
Exception Info: System.UnauthorizedAccessException
Stack:
   at System.IO.__Error.WinIOError(Int32, System.String)
   at System.IO.FileInfo.Delete()
   at ..(System.String)
   at ..()
   at ..(., System.String, Boolean, System.String, Int32, System.String, System.String, Boolean, Boolean, Boolean, Boolean, Boolean, Boolean, System.String, System.String)
   at ..(Int32, System.String, System.String, System.String, Boolean, Boolean, Boolean, ., Boolean, Boolean, System.String, Boolean, Boolean, System.String)
   at ..(.)
   at ..()
Error: (12/25/2015 03:37:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 13078
Error: (12/25/2015 03:37:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 13078
Error: (12/25/2015 03:37:11 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (12/25/2015 03:37:09 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 11469
System errors:
=============
Error: (12/28/2015 10:33:40 AM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (12/27/2015 10:44:14 AM) (Source: Ntfs) (EventID: 55) (User: NT AUTHORITY)
Description: In der Dateisystemstruktur auf Volume "??" wurde eine Beschädigung erkannt.
A corruption was found in a file system index structure.  The file reference number is 0x1000000000dcc.  The name of the file is "\Windows\System32".  The corrupted index attribute is ":$I30:$INDEX_ALLOCATION".
Error: (12/26/2015 12:17:03 PM) (Source: Tcpip) (EventID: 4199) (User: )
Description: Das System hat einen Adressenkonflikt der IP-Adresse 0.0.0.0 mit dem Computer mit der
Netzwerkhardwareadresse 00-00-00-00-00-00 ermittelt. Netzwerkvorgänge könnten daher auf diesem
System unterbrochen werden.
Error: (12/25/2015 12:36:50 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (12/23/2015 08:55:21 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (12/23/2015 07:45:11 PM) (Source: ACPI) (EventID: 13) (User: )
Description: : Der eingebettete Controller (EC) hat nicht innerhalb des angegebenen Zeitlimits reagiert. Dies deutet auf einen Fehler in der EC-Hardware oder -Firmware hin bzw. darauf, dass das BIOS auf falsche Art auf den EC zugreift. Fragen Sie den Computerhersteller nach einem aktualisierten BIOS. Dieser Fehler kann in einigen Situationen zur Folge haben, dass der Computer fehlerhaft läuft.
Error: (12/23/2015 01:30:31 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (12/23/2015 01:18:48 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (12/23/2015 01:03:14 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
Error: (12/22/2015 08:15:20 PM) (Source: Microsoft-Windows-Kernel-Power) (EventID: 137) (User: )
Description: 4
CodeIntegrity:
===================================
  Date: 2015-12-15 16:01:07.844
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
  Date: 2015-12-10 20:22:44.495
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
  Date: 2015-11-26 18:42:44.060
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
  Date: 2015-11-09 12:24:41.435
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
  Date: 2015-09-17 12:19:31.450
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
  Date: 2015-09-09 10:53:23.204
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
  Date: 2015-08-15 16:29:05.270
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
  Date: 2015-08-08 03:22:30.089
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
  Date: 2015-07-31 04:49:03.771
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
  Date: 2015-07-22 10:34:58.815
  Description: Code Integrity determined that a process (\Device\HarddiskVolume3\Program Files\Windows Defender\MsMpEng.exe) attempted to load \Device\HarddiskVolume3\Program Files\Common Files\microsoft shared\OFFICE15\MSOXMLMF.DLL that did not meet the Custom 3 / Antimalware signing level requirements.
==================== Memory info =========================== 
Processor: AMD E-300 APU with Radeon(tm) HD Graphics
Percentage of memory in use: 44%
Total physical RAM: 3578.9 MB
Available physical RAM: 1987.77 MB
Total Virtual: 7780.45 MB
Available Virtual: 5903.47 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:222.73 GB) (Free:171.29 GB) NTFS
Drive d: () (Fixed) (Total:223.4 GB) (Free:223.26 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 465.8 GB) (Disk ID: AB6848C7)
Partition 1: (Not Active) - (Size=19.5 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=222.7 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=223.4 GB) - (Type=07 NTFS)
==================== End of Addition.txt ============================
          | 
|  28.12.2015, 17:13 | #2 | 
| /// TB-Ausbilder /// Anleitungs-Guru      |   Laptop Virenverdacht Mein Name ist Jürgen und ich werde Dir bei Deinem Problem behilflich sein. Zusammen schaffen wir das...  
  Hinweis: Ich kann Dir niemals eine Garantie geben, dass wir alle schädlichen Dateien finden werden. Eine Formatierung ist meist der schnellere und immer der sicherste Weg, aber auch nur bei wirklicher Malware empfehlenswert. Adware & Co. können wir sehr gut entfernen. Solltest Du Dich für eine Bereinigung entscheiden, arbeite solange mit, bis Du mein clean  bekommst. Los geht's: Welche Probleme bestehen im Detail? 
				__________________ | 
|  | 
| Themen zu Laptop Virenverdacht | 
| adobe, adware, autokms, beschädigung, bonjour, browser, computer, defender, desktop, dnsapi.dll, explorer, firefox, flash player, frage, google, homepage, mozilla, problem, registry, scan, security, services.exe, software, svchost.exe, system, udp, viren, windows |