Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Schwarzer Bildschirm nach Virenbefall. (https://www.trojaner-board.de/140958-schwarzer-bildschirm-virenbefall.html)

Rickalon 03.09.2013 18:56

Schwarzer Bildschirm nach Virenbefall.
 
Ich grüsse Euch...

Ich habe eine Laptop zur Reperatur von einem Arbeitskollegen entgegengenommen. Der meinte er habe den Polizeivirus.
Ich habe mir die Sache angesehen und ja.. ich konnte einen Trojaner mit Stinger ausfindig machen. Er hatte sich in eine Skypedatei hineingesetzt.
Ich konnte ihn entfernen und das System schien wieder richtig zu laufen.

Doch dann.
Ich startete am nächsten Tag den Laptop nochmal und führte einen Virenscan durch. Neuerlich wurden 10 infzierte Dateien gefunden. Nach entfernung dieser durch das Antivirenprogram und einem Neustart blieb der Monitor schwarz und es war nur eine weisser Mauszeiger zu sehen, so als wäre das System zwar aktiv, aber immer noch durch den Polizeivirus abegedeckt.

Über F8 bin ich dann in die Reperaturkonsole gestiegen und versucht 1. den Startvorgang wieder zum laufen zu bringen. weiters über die Eingabekonsole zugriff zu erlangen.

Alles blieb ohne erfolg und beim schwarzen Bildschirm.
Im normalen Systemstart und im abgesicherten Modus.

Wenn es nicht darum ginge die Daten zu retten, um die mich mein Arbeitskollege geben hätte, würde ich das Ding einfach formatieren.

Ich habe mich durch zufall auf eurem Forum widergefunden und bin in erster Linie sehr positiv überrascht. Ich habe einige Beiträge gesehen, die ein gleiches oder ähnliches Problem schildern und habe somit dort angefangen wo ihr Rat erteilt habt.

Das System ist ein Laptop Win 7 32 bit.

bezugnehment auf den link
http://www.trojaner-board.de/138960-...isse-maus.html

bin ich die schritte durchgegangen und möchte euch nun den log zeigen, den ich von frst.exe erhalten habe.

Ich bin mir sicher, dass ihr mir einen Rat geben könnt und danke schon im Vorfeld.

Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-09-2013 02
Ran by SYSTEM on MININT-Q2GJ5N4 on 03-09-2013 19:35:44
Running from F:\
Windows 7 Professional (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet002
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [13797992 2009-08-31] (NVIDIA Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1545512 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [248040 2010-02-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [NBKeyScan] - C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe [2254120 2008-12-05] (Nero AG)
HKLM\...\Run: [PDFHook] - C:\Program Files\Nuance\PDF Create! 5\pdfcreate5hook.exe [795936 2008-07-30] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] - C:\Program Files\Nuance\PDF Create! 5\RegistryController.exe [58656 2008-07-30] (Nuance Communications, Inc.)
HKLM\...\Run: [ISUSScheduler] - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation)
HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4767304 2013-03-06] (AVAST Software)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-02] (Adobe Systems Incorporated)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [262656 2010-11-20] (Microsoft Corporation)
HKU\Karl\...\Run: [ISUSPM Startup] - c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [ 2005-02-16] (InstallShield Software Corporation)
HKU\Karl\...\Winlogon: [Shell] explorer.exe <==== ATTENTION

========================== Services (Whitelisted) =================

S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [45248 2013-03-06] (AVAST Software)
S2 PLFlash DeviceIoControl Service; C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe [81920 2008-12-05] (Prolific Technology Inc.)

==================== Drivers (Whitelisted) ====================

S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-03-06] (AVAST Software)
S1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21576 2013-03-06] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-03-06] (AVAST Software)
S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [60656 2013-03-06] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49248 2013-03-06] ()
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [765736 2013-03-06] (AVAST Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [368176 2013-03-06] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [62376 2013-03-06] (AVAST Software)
S3 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [164736 2013-03-06] ()
S0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-13] (Microsoft Corporation)
S3 FSCSLII; C:\Windows\System32\DRIVERS\FSCSLII.sys [16384 2009-05-18] (Fujitsu)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-02 21:23 - 2013-09-02 21:23 - 00000000 ____D C:\96f3389910d5162ef3339e1855e1b9
2013-09-02 06:17 - 2013-09-02 06:17 - 00000552 _____ C:\Windows\System32\spsys.log
2013-09-02 06:16 - 2013-09-03 06:25 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-02 06:16 - 2013-09-03 06:25 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-02 05:56 - 2013-09-02 05:56 - 00000000 ____D C:\Quarantine
2013-09-02 05:49 - 2013-09-02 05:44 - 09945120 _____ (McAfee Inc) C:\Users\Karl\Desktop\stinger32_12.0.0.508.exe
2013-09-02 05:48 - 2013-09-02 06:10 - 00000000 ____D C:\Program Files\stinger
2013-09-02 05:19 - 2013-09-02 05:19 - 00000000 ____D C:\Windows\pss

==================== One Month Modified Files and Folders =======

2013-09-03 09:32 - 2009-07-13 20:39 - 00107003 _____ C:\Windows\setupact.log
2013-09-03 09:15 - 2010-03-23 05:39 - 00000000 ____D C:\users\Karl
2013-09-03 09:15 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\wfp
2013-09-03 09:15 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\registration
2013-09-03 08:55 - 2010-03-23 05:33 - 01060705 _____ C:\Windows\WindowsUpdate.log
2013-09-03 06:25 - 2013-09-02 06:16 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-03 06:25 - 2013-09-02 06:16 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-03 06:23 - 2010-03-23 05:41 - 01507104 _____ C:\Windows\System32\PerfStringBackup.INI
2013-09-03 00:29 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache
2013-09-03 00:01 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\LogFiles
2013-09-02 21:23 - 2013-09-02 21:23 - 00000000 ____D C:\96f3389910d5162ef3339e1855e1b9
2013-09-02 07:00 - 2010-03-24 00:22 - 00000406 __RSH C:\ProgramData\ntuser.pol
2013-09-02 06:59 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-09-02 06:59 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\de-DE
2013-09-02 06:17 - 2013-09-02 06:17 - 00000552 _____ C:\Windows\System32\spsys.log
2013-09-02 06:10 - 2013-09-02 05:48 - 00000000 ____D C:\Program Files\stinger
2013-09-02 05:56 - 2013-09-02 05:56 - 00000000 ____D C:\Quarantine
2013-09-02 05:44 - 2013-09-02 05:49 - 09945120 _____ (McAfee Inc) C:\Users\Karl\Desktop\stinger32_12.0.0.508.exe
2013-09-02 05:22 - 2013-05-07 06:17 - 00000004 _____ C:\Users\Karl\AppData\Roaming\skype.ini
2013-09-02 05:19 - 2013-09-02 05:19 - 00000000 ____D C:\Windows\pss

Files to move or delete:
====================
C:\Users\Karl\AppData\Roaming\skype.ini
C:\Users\Karl\AppData\Local\Temp\comver.dll
C:\Users\Karl\AppData\Local\Temp\DRPCUNLR.dll
C:\Users\Karl\AppData\Local\Temp\GLF6C7D.tmp.ConduitEngineSetup.exe
C:\Users\Karl\AppData\Local\Temp\GoogleToolbarInstaller_en32_signed.exe
C:\Users\Karl\AppData\Local\Temp\ose00000.exe
C:\Users\Karl\AppData\Local\Temp\prxGLF6C7D.tmp.tbDVDV.dll
C:\Users\Karl\AppData\Local\Temp\TB_3CF0.exe
C:\Users\Karl\AppData\Local\Temp\{E7FDFA05-81BD-4E65-89A0-3B42B25297BE}-28.0.1500.72_chrome_installer.exe
C:\Users\Karl\AppData\Local\Temp\{DBD0D921-EBAE-4E11-AFB0-F9047597CCB9}\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\isrt.dll
C:\Users\Karl\AppData\Local\Temp\{DBD0D921-EBAE-4E11-AFB0-F9047597CCB9}\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\_IsRes.dll
C:\Users\Karl\AppData\Local\Temp\{DBD0D921-EBAE-4E11-AFB0-F9047597CCB9}\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\_ISUser.dll
C:\Users\Karl\AppData\Local\Temp\ispC1FA.tmp\_Setup.dll
C:\Users\Karl\AppData\Local\Temp\ispB435.tmp\_Setup.dll
C:\Users\Karl\AppData\Local\Temp\isp539E.tmp\_Setup.dll
C:\Users\Karl\AppData\Local\Temp\isp3610.tmp\_Setup.dll
C:\Users\Karl\AppData\Local\Temp\isp147C.tmp\_Setup.dll

==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

Restore point made on: 2013-04-13 11:00:56
Restore point made on: 2013-04-20 07:35:52
Restore point made on: 2013-04-26 06:13:47
Restore point made on: 2013-04-26 08:18:28
Restore point made on: 2013-04-26 20:47:01
Restore point made on: 2013-04-27 03:05:30
Restore point made on: 2013-04-28 10:51:38
Restore point made on: 2013-04-30 03:32:37
Restore point made on: 2013-05-01 21:40:53
Restore point made on: 2013-05-01 22:18:56
Restore point made on: 2013-05-04 03:16:26
Restore point made on: 2013-05-04 06:30:13
Restore point made on: 2013-05-04 08:52:55
Restore point made on: 2013-05-04 10:03:54
Restore point made on: 2013-05-05 12:10:38
Restore point made on: 2013-05-06 11:12:13
Restore point made on: 2013-07-16 04:12:45
Restore point made on: 2013-09-02 06:26:50
Restore point made on: 2013-09-02 21:17:55
Restore point made on: 2013-09-02 21:36:27
Restore point made on: 2013-09-02 23:56:04
Restore point made on: 2013-09-03 00:37:11
Restore point made on: 2013-09-03 00:37:15
Restore point made on: 2013-09-03 00:37:16
Restore point made on: 2013-09-03 00:37:16
Restore point made on: 2013-09-03 00:37:21
Restore point made on: 2013-09-03 00:37:22
Restore point made on: 2013-09-03 00:37:23

==================== Memory info ===========================

Percentage of memory in use: 17%
Total physical RAM: 2558.42 MB
Available physical RAM: 2098.23 MB
Total Pagefile: 2554.64 MB
Available Pagefile: 2095.81 MB
Total Virtual: 2047.88 MB
Available Virtual: 1936.21 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.79 GB) (Free:146.17 GB) NTFS
Drive f: () (Removable) (Total:1.87 GB) (Free:0.23 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: B43DDC96)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=2 GB) - (Type=06)


LastRegBack: 2013-09-03 00:22

==================== End Of Log ============================


schrauber 03.09.2013 20:13

hi,

Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\Karl\...\Winlogon: [Shell] explorer.exe <==== ATTENTION
C:\Users\Karl\AppData\Roaming\skype.ini
C:\Users\Karl\AppData\Local\Temp\comver.dll
C:\Users\Karl\AppData\Local\Temp\DRPCUNLR.dll
C:\Users\Karl\AppData\Local\Temp\GLF6C7D.tmp.ConduitEngineSetup.exe
C:\Users\Karl\AppData\Local\Temp\GoogleToolbarInstaller_en32_signed.exe
C:\Users\Karl\AppData\Local\Temp\ose00000.exe
C:\Users\Karl\AppData\Local\Temp\prxGLF6C7D.tmp.tbDVDV.dll
C:\Users\Karl\AppData\Local\Temp\TB_3CF0.exe
C:\Users\Karl\AppData\Local\Temp\{E7FDFA05-81BD-4E65-89A0-3B42B25297BE}-28.0.1500.72_chrome_installer.exe
C:\Users\Karl\AppData\Local\Temp\{DBD0D921-EBAE-4E11-AFB0-F9047597CCB9}\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\isrt.dll
C:\Users\Karl\AppData\Local\Temp\{DBD0D921-EBAE-4E11-AFB0-F9047597CCB9}\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\_IsRes.dll
C:\Users\Karl\AppData\Local\Temp\{DBD0D921-EBAE-4E11-AFB0-F9047597CCB9}\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\_ISUser.dll
C:\Users\Karl\AppData\Local\Temp\ispC1FA.tmp\_Setup.dll
C:\Users\Karl\AppData\Local\Temp\ispB435.tmp\_Setup.dll
C:\Users\Karl\AppData\Local\Temp\isp539E.tmp\_Setup.dll
C:\Users\Karl\AppData\Local\Temp\isp3610.tmp\_Setup.dll
C:\Users\Karl\AppData\Local\Temp\isp147C.tmp\_Setup.dll

Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Entfernen Button.

Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.


Rechner normal starten :)

Rickalon 03.09.2013 21:01

Erstmal Danke für die schnelle Antwort..

und hier kommt der Fixlog

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 03-09-2013 02
Ran by SYSTEM at 2013-09-03 21:57:55 Run:1
Running from F:\
Boot Mode: Recovery

==============================================

Content of fixlist:
*****************
HKU\Karl\...\Winlogon: [Shell] explorer.exe <==== ATTENTION
C:\Users\Karl\AppData\Roaming\skype.ini
C:\Users\Karl\AppData\Local\Temp\comver.dll
C:\Users\Karl\AppData\Local\Temp\DRPCUNLR.dll
C:\Users\Karl\AppData\Local\Temp\GLF6C7D.tmp.ConduitEngineSetup.exe
C:\Users\Karl\AppData\Local\Temp\GoogleToolbarInstaller_en32_signed.exe
C:\Users\Karl\AppData\Local\Temp\ose00000.exe
C:\Users\Karl\AppData\Local\Temp\prxGLF6C7D.tmp.tbDVDV.dll
C:\Users\Karl\AppData\Local\Temp\TB_3CF0.exe
C:\Users\Karl\AppData\Local\Temp\{E7FDFA05-81BD-4E65-89A0-3B42B25297BE}-28.0.1500.72_chrome_installer.exe
C:\Users\Karl\AppData\Local\Temp\{DBD0D921-EBAE-4E11-AFB0-F9047597CCB9}\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\isrt.dll
C:\Users\Karl\AppData\Local\Temp\{DBD0D921-EBAE-4E11-AFB0-F9047597CCB9}\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\_IsRes.dll
C:\Users\Karl\AppData\Local\Temp\{DBD0D921-EBAE-4E11-AFB0-F9047597CCB9}\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\_ISUser.dll
C:\Users\Karl\AppData\Local\Temp\ispC1FA.tmp\_Setup.dll
C:\Users\Karl\AppData\Local\Temp\ispB435.tmp\_Setup.dll
C:\Users\Karl\AppData\Local\Temp\isp539E.tmp\_Setup.dll
C:\Users\Karl\AppData\Local\Temp\isp3610.tmp\_Setup.dll
C:\Users\Karl\AppData\Local\Temp\isp147C.tmp\_Setup.dll
*****************

HKU\Karl\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully.
C:\Users\Karl\AppData\Roaming\skype.ini => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\comver.dll => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\DRPCUNLR.dll => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\GLF6C7D.tmp.ConduitEngineSetup.exe => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\GoogleToolbarInstaller_en32_signed.exe => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\ose00000.exe => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\prxGLF6C7D.tmp.tbDVDV.dll => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\TB_3CF0.exe => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\{E7FDFA05-81BD-4E65-89A0-3B42B25297BE}-28.0.1500.72_chrome_installer.exe => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\{DBD0D921-EBAE-4E11-AFB0-F9047597CCB9}\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\isrt.dll => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\{DBD0D921-EBAE-4E11-AFB0-F9047597CCB9}\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\_IsRes.dll => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\{DBD0D921-EBAE-4E11-AFB0-F9047597CCB9}\{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}\_ISUser.dll => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\ispC1FA.tmp\_Setup.dll => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\ispB435.tmp\_Setup.dll => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\isp539E.tmp\_Setup.dll => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\isp3610.tmp\_Setup.dll => Moved successfully.
C:\Users\Karl\AppData\Local\Temp\isp147C.tmp\_Setup.dll => Moved successfully.

==== End of Fixlog ====


Ergebnis....schwarzer Bildschirm, weisse maus

schrauber 04.09.2013 08:57

Weird. Poste bitte ein frisches FRST log aus der Recovery.

Wann kommt der Bildschirm? Direkt oder erst nach Benutzeranmeldung?

Rickalon 04.09.2013 11:19

Hallo,..

Ich poste dir zuerst mal den Log den ich gestern Abend noch angefertig habe.:


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-09-2013 02
Ran by SYSTEM on MININT-7O01RKF on 03-09-2013 22:33:44
Running from F:\
Windows 7 Professional (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet002
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [13797992 2009-08-31] (NVIDIA Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1545512 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [248040 2010-02-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [NBKeyScan] - C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe [2254120 2008-12-05] (Nero AG)
HKLM\...\Run: [PDFHook] - C:\Program Files\Nuance\PDF Create! 5\pdfcreate5hook.exe [795936 2008-07-30] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] - C:\Program Files\Nuance\PDF Create! 5\RegistryController.exe [58656 2008-07-30] (Nuance Communications, Inc.)
HKLM\...\Run: [ISUSScheduler] - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation)
HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4767304 2013-03-06] (AVAST Software)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-02] (Adobe Systems Incorporated)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [262656 2010-11-20] (Microsoft Corporation)
HKU\Karl\...\Run: [ISUSPM Startup] - c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [ 2005-02-16] (InstallShield Software Corporation)

========================== Services (Whitelisted) =================

S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [45248 2013-03-06] (AVAST Software)
S2 PLFlash DeviceIoControl Service; C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe [81920 2008-12-05] (Prolific Technology Inc.)

==================== Drivers (Whitelisted) ====================

S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-03-06] (AVAST Software)
S1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21576 2013-03-06] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-03-06] (AVAST Software)
S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [60656 2013-03-06] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49248 2013-03-06] ()
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [765736 2013-03-06] (AVAST Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [368176 2013-03-06] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [62376 2013-03-06] (AVAST Software)
S3 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [164736 2013-03-06] ()
S0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-13] (Microsoft Corporation)
S3 FSCSLII; C:\Windows\System32\DRIVERS\FSCSLII.sys [16384 2009-05-18] (Fujitsu)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-02 21:23 - 2013-09-02 21:23 - 00000000 ____D C:\96f3389910d5162ef3339e1855e1b9
2013-09-02 06:17 - 2013-09-02 06:17 - 00000552 _____ C:\Windows\System32\spsys.log
2013-09-02 06:16 - 2013-09-03 06:25 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-02 06:16 - 2013-09-03 06:25 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-02 05:56 - 2013-09-02 05:56 - 00000000 ____D C:\Quarantine
2013-09-02 05:49 - 2013-09-02 05:44 - 09945120 _____ (McAfee Inc) C:\Users\Karl\Desktop\stinger32_12.0.0.508.exe
2013-09-02 05:48 - 2013-09-02 06:10 - 00000000 ____D C:\Program Files\stinger
2013-09-02 05:19 - 2013-09-02 05:19 - 00000000 ____D C:\Windows\pss

==================== One Month Modified Files and Folders =======

2013-09-03 19:35 - 2013-09-03 19:35 - 00000000 ____D C:\FRST
2013-09-03 11:59 - 2009-07-13 20:39 - 00107059 _____ C:\Windows\setupact.log
2013-09-03 09:32 - 2010-03-23 05:33 - 01064952 _____ C:\Windows\WindowsUpdate.log
2013-09-03 09:15 - 2010-03-23 05:39 - 00000000 ____D C:\users\Karl
2013-09-03 09:15 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\wfp
2013-09-03 09:15 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\registration
2013-09-03 06:25 - 2013-09-02 06:16 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-03 06:25 - 2013-09-02 06:16 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-03 06:23 - 2010-03-23 05:41 - 01507104 _____ C:\Windows\System32\PerfStringBackup.INI
2013-09-03 00:29 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache
2013-09-03 00:01 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\LogFiles
2013-09-02 21:23 - 2013-09-02 21:23 - 00000000 ____D C:\96f3389910d5162ef3339e1855e1b9
2013-09-02 07:00 - 2010-03-24 00:22 - 00000406 __RSH C:\ProgramData\ntuser.pol
2013-09-02 06:59 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-09-02 06:59 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\de-DE
2013-09-02 06:17 - 2013-09-02 06:17 - 00000552 _____ C:\Windows\System32\spsys.log
2013-09-02 06:10 - 2013-09-02 05:48 - 00000000 ____D C:\Program Files\stinger
2013-09-02 05:56 - 2013-09-02 05:56 - 00000000 ____D C:\Quarantine
2013-09-02 05:44 - 2013-09-02 05:49 - 09945120 _____ (McAfee Inc) C:\Users\Karl\Desktop\stinger32_12.0.0.508.exe
2013-09-02 05:19 - 2013-09-02 05:19 - 00000000 ____D C:\Windows\pss

==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

Restore point made on: 2013-04-13 11:00:56
Restore point made on: 2013-04-20 07:35:52
Restore point made on: 2013-04-26 06:13:47
Restore point made on: 2013-04-26 08:18:28
Restore point made on: 2013-04-26 20:47:01
Restore point made on: 2013-04-27 03:05:30
Restore point made on: 2013-04-28 10:51:38
Restore point made on: 2013-04-30 03:32:37
Restore point made on: 2013-05-01 21:40:53
Restore point made on: 2013-05-01 22:18:56
Restore point made on: 2013-05-04 03:16:26
Restore point made on: 2013-05-04 06:30:13
Restore point made on: 2013-05-04 08:52:55
Restore point made on: 2013-05-04 10:03:54
Restore point made on: 2013-05-05 12:10:38
Restore point made on: 2013-05-06 11:12:13
Restore point made on: 2013-07-16 04:12:45
Restore point made on: 2013-09-02 06:26:50
Restore point made on: 2013-09-02 21:17:55
Restore point made on: 2013-09-02 21:36:27
Restore point made on: 2013-09-02 23:56:04
Restore point made on: 2013-09-03 00:37:11
Restore point made on: 2013-09-03 00:37:15
Restore point made on: 2013-09-03 00:37:16
Restore point made on: 2013-09-03 00:37:16
Restore point made on: 2013-09-03 00:37:21
Restore point made on: 2013-09-03 00:37:22
Restore point made on: 2013-09-03 00:37:23

==================== Memory info ===========================

Percentage of memory in use: 17%
Total physical RAM: 2558.42 MB
Available physical RAM: 2106.11 MB
Total Pagefile: 2554.64 MB
Available Pagefile: 2104.22 MB
Total Virtual: 2047.88 MB
Available Virtual: 1945.11 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.79 GB) (Free:146.17 GB) NTFS
Drive f: () (Removable) (Total:1.87 GB) (Free:0.23 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: B43DDC96)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=2 GB) - (Type=06)


LastRegBack: 2013-09-03 00:22

==================== End Of Log ============================

--- --- ---


So nun weiter... :D

Also per Knopfdruck startet der Laptop... das Bios fährt hoch.. nach Beendigung wechselt er auf einen schwarzen Bildschirm mit der Schrift Windows wird gestartet... es erscheinen die 4 verschiedenfärbigen Punkte die sich zum Windowslogo verbinden.
Nun wechselt er wieder in einen schwarzen Bildschirm und es erscheint ein weisser Mauszeiger.

Ich vermute... da der Laptop/ Benutzer nicht mit einem Passwort abgesichert ist, dass er nach dem Windowslogo direkt auf den Desktop geht und dort seine Arbeit verrichten will..
denn hin und wieder.. taucht bei diesem schwarzen Bildschirm mit der weissen Maus.. ein blauer Kreis auf, als würde er etwas laden.. Die Festplatte verarbeitet vermutlich die Programme die beim Start geladen werden, denn nach einiger Zeit beendet sie ihre Arbeit.

Dies geschied beim Normalstart sowie im abgesicherten Modus (hier natürlich ohne Windowslogo und blauen Ladekreis neben der Maus)


Hier im Anschluss habe ich jetzt nochmal einen ganz frischen frst.txt. den ich gerade eben gemacht habe.


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 03-09-2013 02
Ran by SYSTEM on MININT-PUSS9IC on 04-09-2013 12:14:00
Running from F:\
Windows 7 Professional (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet002
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [13797992 2009-08-31] (NVIDIA Corporation)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1545512 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [248040 2010-02-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [NBKeyScan] - C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe [2254120 2008-12-05] (Nero AG)
HKLM\...\Run: [PDFHook] - C:\Program Files\Nuance\PDF Create! 5\pdfcreate5hook.exe [795936 2008-07-30] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] - C:\Program Files\Nuance\PDF Create! 5\RegistryController.exe [58656 2008-07-30] (Nuance Communications, Inc.)
HKLM\...\Run: [ISUSScheduler] - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation)
HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4767304 2013-03-06] (AVAST Software)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-02] (Adobe Systems Incorporated)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [262656 2010-11-20] (Microsoft Corporation)
HKU\Karl\...\Run: [ISUSPM Startup] - c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [ 2005-02-16] (InstallShield Software Corporation)

========================== Services (Whitelisted) =================

S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [45248 2013-03-06] (AVAST Software)
S2 PLFlash DeviceIoControl Service; C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe [81920 2008-12-05] (Prolific Technology Inc.)

==================== Drivers (Whitelisted) ====================

S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-03-06] (AVAST Software)
S1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21576 2013-03-06] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-03-06] (AVAST Software)
S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [60656 2013-03-06] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49248 2013-03-06] ()
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [765736 2013-03-06] (AVAST Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [368176 2013-03-06] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [62376 2013-03-06] (AVAST Software)
S3 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [164736 2013-03-06] ()
S0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-13] (Microsoft Corporation)
S3 FSCSLII; C:\Windows\System32\DRIVERS\FSCSLII.sys [16384 2009-05-18] (Fujitsu)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-02 21:23 - 2013-09-02 21:23 - 00000000 ____D C:\96f3389910d5162ef3339e1855e1b9
2013-09-02 06:17 - 2013-09-02 06:17 - 00000552 _____ C:\Windows\System32\spsys.log
2013-09-02 06:16 - 2013-09-03 06:25 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-02 06:16 - 2013-09-03 06:25 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-02 05:56 - 2013-09-02 05:56 - 00000000 ____D C:\Quarantine
2013-09-02 05:49 - 2013-09-02 05:44 - 09945120 _____ (McAfee Inc) C:\Users\Karl\Desktop\stinger32_12.0.0.508.exe
2013-09-02 05:48 - 2013-09-02 06:10 - 00000000 ____D C:\Program Files\stinger
2013-09-02 05:19 - 2013-09-02 05:19 - 00000000 ____D C:\Windows\pss

==================== One Month Modified Files and Folders =======

2013-09-03 19:35 - 2013-09-03 19:35 - 00000000 ____D C:\FRST
2013-09-03 12:42 - 2009-07-13 20:39 - 00107171 _____ C:\Windows\setupact.log
2013-09-03 12:02 - 2010-03-23 05:33 - 01064952 _____ C:\Windows\WindowsUpdate.log
2013-09-03 09:15 - 2010-03-23 05:39 - 00000000 ____D C:\users\Karl
2013-09-03 09:15 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\wfp
2013-09-03 09:15 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\registration
2013-09-03 06:25 - 2013-09-02 06:16 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-03 06:25 - 2013-09-02 06:16 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-03 06:23 - 2010-03-23 05:41 - 01507104 _____ C:\Windows\System32\PerfStringBackup.INI
2013-09-03 00:29 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache
2013-09-03 00:01 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\LogFiles
2013-09-02 21:23 - 2013-09-02 21:23 - 00000000 ____D C:\96f3389910d5162ef3339e1855e1b9
2013-09-02 07:00 - 2010-03-24 00:22 - 00000406 __RSH C:\ProgramData\ntuser.pol
2013-09-02 06:59 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-09-02 06:59 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\de-DE
2013-09-02 06:17 - 2013-09-02 06:17 - 00000552 _____ C:\Windows\System32\spsys.log
2013-09-02 06:10 - 2013-09-02 05:48 - 00000000 ____D C:\Program Files\stinger
2013-09-02 05:56 - 2013-09-02 05:56 - 00000000 ____D C:\Quarantine
2013-09-02 05:44 - 2013-09-02 05:49 - 09945120 _____ (McAfee Inc) C:\Users\Karl\Desktop\stinger32_12.0.0.508.exe
2013-09-02 05:19 - 2013-09-02 05:19 - 00000000 ____D C:\Windows\pss

==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

Restore point made on: 2013-04-13 11:00:56
Restore point made on: 2013-04-20 07:35:52
Restore point made on: 2013-04-26 06:13:47
Restore point made on: 2013-04-26 08:18:28
Restore point made on: 2013-04-26 20:47:01
Restore point made on: 2013-04-27 03:05:30
Restore point made on: 2013-04-28 10:51:38
Restore point made on: 2013-04-30 03:32:37
Restore point made on: 2013-05-01 21:40:53
Restore point made on: 2013-05-01 22:18:56
Restore point made on: 2013-05-04 03:16:26
Restore point made on: 2013-05-04 06:30:13
Restore point made on: 2013-05-04 08:52:55
Restore point made on: 2013-05-04 10:03:54
Restore point made on: 2013-05-05 12:10:38
Restore point made on: 2013-05-06 11:12:13
Restore point made on: 2013-07-16 04:12:45
Restore point made on: 2013-09-02 06:26:50
Restore point made on: 2013-09-02 21:17:55
Restore point made on: 2013-09-02 21:36:27
Restore point made on: 2013-09-02 23:56:04
Restore point made on: 2013-09-03 00:37:11
Restore point made on: 2013-09-03 00:37:15
Restore point made on: 2013-09-03 00:37:16
Restore point made on: 2013-09-03 00:37:16
Restore point made on: 2013-09-03 00:37:21
Restore point made on: 2013-09-03 00:37:22
Restore point made on: 2013-09-03 00:37:23

==================== Memory info ===========================

Percentage of memory in use: 17%
Total physical RAM: 2558.42 MB
Available physical RAM: 2106.25 MB
Total Pagefile: 2554.64 MB
Available Pagefile: 2104.21 MB
Total Virtual: 2047.88 MB
Available Virtual: 1953.11 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.79 GB) (Free:146.18 GB) NTFS
Drive f: () (Removable) (Total:1.87 GB) (Free:0.23 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: B43DDC96)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=2 GB) - (Type=06)


LastRegBack: 2013-09-03 00:22

==================== End Of Log ============================

--- --- ---

schrauber 04.09.2013 13:48

win7 DVD zur Hand?

Rickalon 04.09.2013 15:16

Ja habe eine hier... aber können wir die Daten der Arbeitskollegen noch retten? oder müssen wir Notschlachten?

schrauber 04.09.2013 20:01

Ich will eigentlich nur ne Rep-Installation machen.

Reparaturinstallation unter Windows Vista / Windows 7 » WinTotal.de

Rickalon 05.09.2013 07:31

ich hatte dies schon erwogen gehabt,.. hatte nur Angst dass ich hierbei Daten verliere.

Die Anleitung klingt irgendwie etwas viel,. aber ich werde es gerne versuchen.

bin jetzt ab Heute 5 Tage in Nürnberg um versuche am Dienstag die Anleitung durchzugehen.

vielen Danke jedenfalls bis hierher.. ihr kennt euch wirklich gut aus :abklatsch:

Wenn ich darf werde ich am Dienstag eine Zwischenmeldung abgeben, wie es aussieht.

gruss Chris

schrauber 05.09.2013 10:37

ok :)

Rickalon 28.09.2013 13:19

Sei gegrüßt,..

Ich muss mich erstmal entschuldigen, dass ich etwas länger nicht mehr online war, als ursprünglich geplant.

Ich bin nun mal die Anleitung zur Reperatur durchgegangen. Allerdings.

Der Laptop, den ich richten soll,.. hat selbst keine Win 7 DVD /CD,.. die Reperatur über das eigene X: laufwerk /Installation verlangt selbst dann ein Medium.
Da der Arbeitskollege dies ebenso nicht gemacht hat wie eine Datensicherung... oder zumindest mal einen Virenschutz zu kaufen, mit dem das Problem angefangen hat. *ärg*
Habe ich versucht über meine Win 7 DvD im da auzuhelfen.. diese wird allerdings als nicht kompatible Version empfunden.
Jetzt hat sich der Arbeitskollege eine Versino besorgt, die geladen wird...
ich kann die Schritte bis zum Punkt "wählen sie das Upgrade aus" gekommen.
es kommt auch wie schon in der Anleitung angegeben die Warnmeldung. Hier befindet sich allerdings nur ein Schliessen Button. Man landet also wieder draussen.

Jetzt die Frage von mir.. wenn ich die Benutzerdefnierte Installation auswähle, würde dort stehen, dass eine Kopie von Win erstellt wird. die Programme etc. gelöscht.. die Löschung bezieht sich auch auf die Dateien des Users? Wie Bilder, Dokumente etc?

Ich bin jetzt noch einen Schritt davon entfernt, den PC einfach zu formatieren und neu zu Installieren.

Kennst du vielleicht noch einen Trick, einen Schme oder irgendwas um seine Daten zu retten?

gruss
Chris

schrauber 29.09.2013 05:47

Ich glaube die Daten werden in einem Windows.Old Ordner gesichert, aber bin nicht genau sicher.

Rickalon 30.09.2013 08:44

Sei gegrüsst.

Ich bin jetzt noch beim überlegen. Das windwos scheint ja irgendwie zu funktionieren nur eben schwarzer bildschirm, weisse maus, und dass eben im normalmodus und abgesicherten. Der cd/dvd autostart geht immer noch.
Angefangen hat das ganze ja mit dem polizeivirus.
Könnte dieser immer noch auf dem system sein und sich so verbreitet haben, dass wir deshalb weder im abgesicherten bzw normalmodus arbeiten können?
Wenn ja, haben wir eine möglichkeit über msdos diesen zu entfernen?

Oder sollte in diesem fall doch eine neuinstallation in betracht gezogen werden?

Vielleicht könntest du mir eine richtung vorgeben als rat. Neuinstallation ist halt wirklich der letzte weg den ich gehen möchte.

Gruss chris

schrauber 30.09.2013 16:34

Poste bitte nochmal ein frisches FRST log aus der REcovery, lad vorher ne neue Version von FRST.

Rickalon 01.10.2013 09:29

Hier kommt das aktuelle Frstlog


FRST Logfile:

FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-09-2013 01
Ran by SYSTEM on MININT-P2IRAG4 on 30-09-2013 22:29:26
Running from F:\
Windows 7 Professional (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet002
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1545512 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [248040 2010-02-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [NBKeyScan] - C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe [2254120 2008-12-05] (Nero AG)
HKLM\...\Run: [PDFHook] - C:\Program Files\Nuance\PDF Create! 5\pdfcreate5hook.exe [795936 2008-07-30] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] - C:\Program Files\Nuance\PDF Create! 5\RegistryController.exe [58656 2008-07-30] (Nuance Communications, Inc.)
HKLM\...\Run: [ISUSScheduler] - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation)
HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4767304 2013-03-06] (AVAST Software)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-02] (Adobe Systems Incorporated)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [262656 2010-11-20] (Microsoft Corporation)
HKU\Karl\...\Run: [ISUSPM Startup] - c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [ 2005-02-16] (InstallShield Software Corporation)

========================== Services (Whitelisted) =================

S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [45248 2013-03-06] (AVAST Software)
S2 PLFlash DeviceIoControl Service; C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe [81920 2008-12-05] (Prolific Technology Inc.)

==================== Drivers (Whitelisted) ====================

S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-03-06] (AVAST Software)
S1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21576 2013-03-06] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-03-06] (AVAST Software)
S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [60656 2013-03-06] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49248 2013-03-06] ()
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [765736 2013-03-06] (AVAST Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [368176 2013-03-06] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [62376 2013-03-06] (AVAST Software)
S3 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [164736 2013-03-06] ()
S0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-13] (Microsoft Corporation)
S3 FSCSLII; C:\Windows\System32\DRIVERS\FSCSLII.sys [16384 2009-05-18] (Fujitsu)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-03 19:35 - 2013-09-03 19:35 - 00000000 ____D C:\FRST
2013-09-02 21:23 - 2013-09-02 21:23 - 00000000 ____D C:\96f3389910d5162ef3339e1855e1b9
2013-09-02 06:17 - 2013-09-02 06:17 - 00000552 _____ C:\Windows\System32\spsys.log
2013-09-02 06:16 - 2013-09-28 04:33 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-02 06:16 - 2013-09-28 04:33 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-02 05:56 - 2013-09-02 05:56 - 00000000 ____D C:\Quarantine
2013-09-02 05:49 - 2013-09-02 05:44 - 09945120 _____ (McAfee Inc) C:\Users\Karl\Desktop\stinger32_12.0.0.508.exe
2013-09-02 05:48 - 2013-09-02 06:10 - 00000000 ____D C:\Program Files\stinger
2013-09-02 05:19 - 2013-09-02 05:19 - 00000000 ____D C:\Windows\pss

==================== One Month Modified Files and Folders =======

2013-09-28 13:39 - 2010-03-23 05:39 - 00000000 ____D C:\users\Karl
2013-09-28 13:39 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\wfp
2013-09-28 13:39 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\registration
2013-09-28 04:33 - 2013-09-02 06:16 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-28 04:33 - 2013-09-02 06:16 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-28 04:29 - 2010-03-23 05:41 - 01507104 _____ C:\Windows\System32\PerfStringBackup.INI
2013-09-28 04:29 - 2010-03-23 05:33 - 01235954 _____ C:\Windows\WindowsUpdate.log
2013-09-28 04:25 - 2009-07-13 20:39 - 00107507 _____ C:\Windows\setupact.log
2013-09-03 19:35 - 2013-09-03 19:35 - 00000000 ____D C:\FRST
2013-09-03 00:29 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache
2013-09-03 00:01 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\LogFiles
2013-09-02 21:23 - 2013-09-02 21:23 - 00000000 ____D C:\96f3389910d5162ef3339e1855e1b9
2013-09-02 07:00 - 2010-03-24 00:22 - 00000406 __RSH C:\ProgramData\ntuser.pol
2013-09-02 06:59 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-09-02 06:59 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\de-DE
2013-09-02 06:17 - 2013-09-02 06:17 - 00000552 _____ C:\Windows\System32\spsys.log
2013-09-02 06:10 - 2013-09-02 05:48 - 00000000 ____D C:\Program Files\stinger
2013-09-02 05:56 - 2013-09-02 05:56 - 00000000 ____D C:\Quarantine
2013-09-02 05:44 - 2013-09-02 05:49 - 09945120 _____ (McAfee Inc) C:\Users\Karl\Desktop\stinger32_12.0.0.508.exe
2013-09-02 05:19 - 2013-09-02 05:19 - 00000000 ____D C:\Windows\pss

==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

29
Restore point made on: 2013-04-20 07:35:52
Restore point made on: 2013-04-26 06:13:47
Restore point made on: 2013-04-26 08:18:28
Restore point made on: 2013-04-26 20:47:01
Restore point made on: 2013-04-27 03:05:30
Restore point made on: 2013-04-28 10:51:38
Restore point made on: 2013-04-30 03:32:37
Restore point made on: 2013-05-01 21:40:53
Restore point made on: 2013-05-01 22:18:56
Restore point made on: 2013-05-04 03:16:26
Restore point made on: 2013-05-04 06:30:13
Restore point made on: 2013-05-04 08:52:55
Restore point made on: 2013-05-04 10:03:54
Restore point made on: 2013-05-05 12:10:38
Restore point made on: 2013-05-06 11:12:13
Restore point made on: 2013-07-16 04:12:45
Restore point made on: 2013-09-02 06:26:50
Restore point made on: 2013-09-02 21:17:55
Restore point made on: 2013-09-02 21:36:27
Restore point made on: 2013-09-02 23:56:04
Restore point made on: 2013-09-04 02:22:46
Restore point made on: 2013-09-04 06:38:02
Restore point made on: 2013-09-04 06:38:06
Restore point made on: 2013-09-04 06:38:06
Restore point made on: 2013-09-04 06:38:07
Restore point made on: 2013-09-04 06:38:13
Restore point made on: 2013-09-04 06:38:15
Restore point made on: 2013-09-04 06:38:16
Restore point made on: 2013-09-28 03:27:32

==================== Memory info ===========================

Percentage of memory in use: 17%
Total physical RAM: 2558.42 MB
Available physical RAM: 2104.96 MB
Total Pagefile: 2554.64 MB
Available Pagefile: 2102.48 MB
Total Virtual: 2047.88 MB
Available Virtual: 1952.73 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.79 GB) (Free:145.97 GB) NTFS
Drive f: () (Removable) (Total:1.87 GB) (Free:0.01 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: B43DDC96)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=2 GB) - (Type=06)


LastRegBack: 2013-09-03 00:22

==================== End Of Log ============================

--- --- ---

--- --- ---

--- --- ---

Allerdings bin ich mir jetzt nicht ganz sicher, ob ich wenn du recovery meinst, dass gleiche verstehe wie du. Also hab unter F8 gestartet und die frst ausgeführt.

schrauber 01.10.2013 18:44

Ja genau das meine ich :)

Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\Karl\...\Run: [ISUSPM Startup] - c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [ 2005-02-16] (InstallShield Software Corporation)
Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Entfernen Button.

Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.

Rickalon 02.10.2013 15:22

Ok,.. ich dachte schon.. ich mache was falsch :D

Nun ich habe den Fix ausgeführt,...

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 27-09-2013 01
Ran by SYSTEM at 2013-10-02 16:11:10 Run:2
Running from F:\
Boot Mode: Recovery

==============================================

Content of fixlist:
*****************
HKU\Karl\...\Run: [ISUSPM Startup] - c:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\isuspm.exe [ 2005-02-16] (InstallShield Software Corporation)
*****************

HKU\Karl\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSPM Startup => Value deleted successfully.

==== End of Fixlog ====

Ich habe nun den PC wieder gestartet um zu sehen ob sich etwas verändert hat...

nach dem Windowslogo kommt wieder der schwarze Bildschirm mit der weissen Maus.

Ich habe jetzt nochmal Frst gestaret.. und jedes Häckchen angemacht welches das Programm enthält,. vielleicht kann man hier mehr rauslesen?!?


FRST Logfile:

FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 27-09-2013 01
Ran by SYSTEM on MININT-83AJNP1 on 02-10-2013 16:18:04
Running from F:\
Windows 7 Professional (X86) OS Language: English(US)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet002
ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log.

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [NvCplDaemon] - RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1545512 2009-07-20] (Synaptics Incorporated)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [248040 2010-02-18] (Sun Microsystems, Inc.)
HKLM\...\Run: [NBKeyScan] - C:\Program Files\Nero\Nero BackItUp 4\NBKeyScan.exe [2254120 2008-12-05] (Nero AG)
HKLM\...\Run: [PDFHook] - C:\Program Files\Nuance\PDF Create! 5\pdfcreate5hook.exe [795936 2008-07-30] (Nuance Communications, Inc.)
HKLM\...\Run: [PDF5 Registry Controller] - C:\Program Files\Nuance\PDF Create! 5\RegistryController.exe [58656 2008-07-30] (Nuance Communications, Inc.)
HKLM\...\Run: [ISUSScheduler] - C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe [81920 2005-02-16] (InstallShield Software Corporation)
HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4767304 2013-03-06] (AVAST Software)
HKLM\...\Run: [Adobe Reader Speed Launcher] - C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe [37296 2012-01-03] (Adobe Systems Incorporated)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [946352 2012-12-02] (Adobe Systems Incorporated)
HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [262656 2010-11-20] (Microsoft Corporation)

========================== Services (Whitelisted) =================

S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [45248 2013-03-06] (AVAST Software)
S2 PLFlash DeviceIoControl Service; C:\Program Files\Nero\Nero BackItUp 4\IoctlSvc.exe [81920 2008-12-05] (Prolific Technology Inc.)

==================== Drivers (Whitelisted) ====================

S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-03-06] (AVAST Software)
S1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [21576 2013-03-06] (AVAST Software)
S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-03-06] (AVAST Software)
S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [60656 2013-03-06] (AVAST Software)
S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49248 2013-03-06] ()
S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [765736 2013-03-06] (AVAST Software)
S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [368176 2013-03-06] (AVAST Software)
S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [62376 2013-03-06] (AVAST Software)
S3 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [164736 2013-03-06] ()
S0 CLFS; C:\Windows\System32\CLFS.sys [249408 2009-07-13] (Microsoft Corporation)
S3 FSCSLII; C:\Windows\System32\DRIVERS\FSCSLII.sys [16384 2009-05-18] (Fujitsu)

========================== Drivers MD5 =======================

C:\Windows\system32\drivers\1394ohci.sys ==> MD5 is legit
C:\Windows\System32\drivers\ACPI.sys ==> MD5 is legit
C:\Windows\system32\drivers\acpipmi.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\adp94xx.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\adpahci.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\adpu320.sys ==> MD5 is legit
C:\Windows\system32\drivers\afd.sys 9EBBBA55060F786F0FCAA3893BFA2806
C:\Windows\system32\drivers\agp440.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\djsvs.sys ==> MD5 is legit
C:\Windows\system32\drivers\aliide.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdagp.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdide.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\amdk8.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\amdppm.sys ==> MD5 is legit
C:\Windows\system32\drivers\amdsata.sys D320BF87125326F996D4904FE24300FC
C:\Windows\system32\DRIVERS\amdsbs.sys ==> MD5 is legit
C:\Windows\System32\drivers\amdxata.sys 46387FB17B086D16DEA267D5BE23A2F2
C:\Windows\system32\drivers\appid.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\arc.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\arcsas.sys ==> MD5 is legit
C:\Windows\System32\Drivers\aswFsBlk.sys CCDA8D84FD02AEC52E62F296433AE9DC
C:\Windows\System32\Drivers\aswKbd.sys 4691B3FE3717F9D9C64A5282C8543D4D
C:\Windows\system32\drivers\aswMonFlt.sys A6E20E62871A28A0F1C05B1681848FA7
C:\Windows\System32\Drivers\aswrdr2.sys 6844738D52970A0F482768EEA941C78E
C:\Windows\System32\Drivers\aswRvrt.sys 657A61979F40D67CA29716149766FFA7
C:\Windows\System32\Drivers\aswSnx.sys 0E604867FC28F00D91CB0B00D2EC830D
C:\Windows\System32\Drivers\aswSP.sys 6FC4AA106AA505394C908D37CCCB9148
C:\Windows\System32\Drivers\aswTdi.sys 33E21FFB063CA6C7E00D568467DC72E4
C:\Windows\System32\Drivers\aswVmm.sys EDB0C9BA44B748E420CCA989FD8B826E
C:\Windows\System32\DRIVERS\asyncmac.sys ==> MD5 is legit
C:\Windows\System32\drivers\atapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\athr.sys 76BAB0C824E2D05B940C4DD40A9B08BF
C:\Windows\system32\DRIVERS\bxvbdx.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\b57nd60x.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Beep.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\blbdrive.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\bowser.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\BrFiltLo.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\BrFiltUp.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Brserid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrSerWdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbMdm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\BrUsbSer.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\bthmodem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\cdfs.sys ==> MD5 is legit
C:\Windows\system32\drivers\cdrom.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\circlass.sys ==> MD5 is legit
C:\Windows\System32\CLFS.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\CmBatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\cmdide.sys ==> MD5 is legit
C:\Windows\System32\Drivers\cng.sys 247B4CE2DAB1160CD422D532D5241E1F
C:\Windows\System32\DRIVERS\compbatt.sys ==> MD5 is legit
C:\Windows\system32\drivers\CompositeBus.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\crcdisk.sys ==> MD5 is legit
C:\Windows\System32\drivers\csc.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\dc3d.sys 4D926450AB184BF42AEC1401D264ACDC
C:\Windows\System32\Drivers\dfsc.sys ==> MD5 is legit
C:\Windows\System32\drivers\discache.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\disk.sys ==> MD5 is legit
C:\Windows\System32\drivers\drmkaud.sys ==> MD5 is legit
C:\Windows\System32\drivers\dxgkrnl.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\evbdx.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\elxstor.sys ==> MD5 is legit
C:\Windows\system32\drivers\errdev.sys ==> MD5 is legit
C:\Windows\System32\Drivers\exfat.sys ==> MD5 is legit
C:\Windows\System32\Drivers\fastfat.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\fdc.sys ==> MD5 is legit
C:\Windows\System32\drivers\fileinfo.sys ==> MD5 is legit
C:\Windows\System32\drivers\filetrace.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\flpydisk.sys ==> MD5 is legitB
C:\Windows\System32\drivers\fltmgr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\FSCSLII.sys FE36D7BD7351C6F5FE3F417F71C1D92B
C:\Windows\System32\drivers\FsDepends.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Fs_Rec.sys 7DAE5EBCC80E45D3253F4923DC424D05
C:\Windows\System32\DRIVERS\fvevol.sys E306A24D9694C724FA2491278BF50FDB
C:\Windows\system32\DRIVERS\gagp30kx.sys ==> MD5 is legit
C:\Windows\system32\drivers\hcw85cir.sys ==> MD5 is legit
C:\Windows\system32\drivers\HdAudio.sys A5EF29D5315111C80A5C1ABAD14C8972
C:\Windows\system32\drivers\HDAudBus.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\HidBatt.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\hidbth.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\hidir.sys ==> MD5 is legit
C:\Windows\system32\drivers\hidusb.sys ==> MD5 is legit
C:\Windows\system32\drivers\HpSAMD.sys ==> MD5 is legit
C:\Windows\System32\drivers\HTTP.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ewusbmdm.sys 988C0A49F09D75D3341CB419141793C1
C:\Windows\System32\drivers\hwpolicy.sys ==> MD5 is legit
C:\Windows\system32\drivers\i8042prt.sys ==> MD5 is legit
C:\Windows\system32\drivers\iaStorV.sys 5CD5F9A5444E6CDCB0AC89BD62D8B76E
C:\Windows\system32\DRIVERS\iirsp.sys ==> MD5 is legit
C:\Windows\system32\drivers\intelide.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\intelppm.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ipfltdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\IPMIDrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\ipnat.sys ==> MD5 is legit
C:\Windows\System32\drivers\irenum.sys ==> MD5 is legit
C:\Windows\system32\drivers\isapnp.sys ==> MD5 is legit
C:\Windows\system32\drivers\msiscsi.sys ==> MD5 is legit
C:\Windows\system32\drivers\kbdclass.sys ==> MD5 is legit
C:\Windows\system32\drivers\kbdhid.sys ==> MD5 is legit
C:\Windows\System32\Drivers\ksecdd.sys B7895B4182C0D16F6EFADEB8081E8D36
C:\Windows\System32\Drivers\ksecpkg.sys D30159AC9237519FBC62C6EC247D2D46
C:\Windows\System32\DRIVERS\lltdio.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\lsi_fc.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\lsi_sas.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\lsi_sas2.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\lsi_scsi.sys ==> MD5 is legit
C:\Windows\system32\drivers\luafv.sys ==> MD5 is legit
C:\Windows\System32\drivers\massfilter.sys 59A2783ABA6019BED0C843C706E10A6A
C:\Windows\system32\DRIVERS\megasas.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\MegaSR.sys ==> MD5 is legit
C:\Windows\System32\drivers\modem.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\monitor.sys ==> MD5 is legit
C:\Windows\system32\drivers\mouclass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mouhid.sys ==> MD5 is legit
C:\Windows\System32\drivers\mountmgr.sys ==> MD5 is legit
C:\Windows\system32\drivers\mpio.sys ==> MD5 is legit
C:\Windows\System32\drivers\mpsdrv.sys ==> MD5 is legit
C:\Windows\system32\drivers\mrxdav.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\mrxsmb.sys 5D16C921E3671636C0EBA3BBAAC5FD25
C:\Windows\System32\DRIVERS\mrxsmb10.sys 6D17A4791ACA19328C685D256349FEFC
C:\Windows\System32\DRIVERS\mrxsmb20.sys B81F204D146000BE76651A50670A5E9E
C:\Windows\system32\drivers\msahci.sys ==> MD5 is legit
C:\Windows\system32\drivers\msdsm.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Msfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\mshidkmdf.sys ==> MD5 is legit
C:\Windows\System32\drivers\msisadrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSKSSRV.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPCLOCK.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSPQM.sys ==> MD5 is legit
C:\Windows\System32\Drivers\MsRPC.sys ==> MD5 is legit
C:\Windows\system32\drivers\mssmbios.sys ==> MD5 is legit
C:\Windows\System32\drivers\MSTEE.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\MTConfig.sys ==> MD5 is legit
C:\Windows\System32\Drivers\mup.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\nwifi.sys ==> MD5 is legit
C:\Windows\System32\drivers\ndis.sys 8C9C922D71F1CD4DEF73F186416B7896
C:\Windows\System32\DRIVERS\ndiscap.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndistapi.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndisuio.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\ndiswan.sys ==> MD5 is legit
C:\Windows\System32\Drivers\NDProxy.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbios.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\netbt.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\nfrd960.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Npfs.sys ==> MD5 is legit
C:\Windows\System32\drivers\nsiproxy.sys ==> MD5 is legit
C:\Windows\System32\Drivers\Ntfs.sys 5E43D2B0EE64123D4880DFA6626DEFDE
C:\Windows\System32\Drivers\Null.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\nvm62x32.sys B5E37E31C053BC9950455A257526514B
C:\Windows\System32\DRIVERS\nvlddmkm.sys 2713392707E515EFB671751FA767EBD2
C:\Windows\System32\DRIVERS\nvmf6232.sys C9C82E1A08955FDBDF92AAC55BC3A4E4
C:\Windows\system32\drivers\nvraid.sys B3E25EE28883877076E0E1FF877D02E0
C:\Windows\System32\DRIVERS\nvsmu.sys F13618F0CB1E95232F4C2401592A59E9
C:\Windows\system32\drivers\nvstor.sys 4380E59A170D88C4F1022EFF6719A8A4
C:\Windows\system32\drivers\nv_agp.sys ==> MD5 is legit
C:\Windows\system32\drivers\ohci1394.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\parport.sys ==> MD5 is legit
C:\Windows\System32\drivers\partmgr.sys 3F34A1B4C5F6475F320C275E63AFCE9B
C:\Windows\system32\DRIVERS\parvdm.sys ==> MD5 is legit
C:\Windows\System32\drivers\pci.sys ==> MD5 is legit
C:\Windows\System32\drivers\pciide.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\pcmcia.sys ==> MD5 is legit
C:\Windows\System32\drivers\pcw.sys ==> MD5 is legit
C:\Windows\System32\drivers\peauth.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspptp.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\processr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\pacer.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\ql2300.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\ql40xx.sys ==> MD5 is legit
C:\Windows\system32\drivers\qwavedrv.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasacd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\AgileVpn.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rasl2tp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\raspppoe.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rassstp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdbss.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rdpbus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\RDPCDD.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpdr.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdpencdd.sys ==> MD5 is legit
C:\Windows\System32\drivers\rdprefmp.sys ==> MD5 is legit
C:\Windows\System32\Drivers\RDPWD.sys F031683E6D1FEA157ABB2FF260B51E61
C:\Windows\System32\drivers\rdyboost.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\rspndr.sys ==> MD5 is legit
C:\Windows\system32\drivers\vms3cap.sys ==> MD5 is legit
C:\Windows\system32\drivers\sbp2port.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\scfilter.sys ==> MD5 is legit
C:\Windows\System32\Drivers\secdrv.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\serenum.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\serial.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\sermouse.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffdisk.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_mmc.sys ==> MD5 is legit
C:\Windows\system32\drivers\sffp_sd.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\sfloppy.sys ==> MD5 is legit
C:\Windows\system32\drivers\sisagp.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\SiSRaid2.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\sisraid4.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\smb.sys ==> MD5 is legit
C:\Windows\System32\Drivers\spldr.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\srv.sys E4C2764065D66EA1D2D3EBC28FE99C46
C:\Windows\System32\DRIVERS\srv2.sys 03F0545BD8D4C77FA0AE1CEEDFCC71AB
C:\Windows\System32\DRIVERS\srvnet.sys BE6BD660CAA6F291AE06A718A4FA8ABC
C:\Windows\system32\DRIVERS\stexstor.sys ==> MD5 is legit
C:\Windows\System32\drivers\vmstorfl.sys ==> MD5 is legit
C:\Windows\system32\drivers\storvsc.sys ==> MD5 is legit
C:\Windows\system32\drivers\swenum.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\SynTP.sys 8BD10DC8809DC69A1C5A795CB10ADD76
C:\Windows\System32\drivers\tcpip.sys 7C0507D2391AF5933600CBCED799F277
C:\Windows\System32\DRIVERS\tcpip.sys 7C0507D2391AF5933600CBCED799F277
C:\Windows\System32\drivers\tcpipreg.sys 3EEBD3BD93DA46A26E89893C7AB2FF3B
C:\Windows\System32\drivers\tdpipe.sys ==> MD5 is legit
C:\Windows\System32\drivers\tdtcp.sys 2C2C5AFE7EE4F620D69C23C0617651A8
C:\Windows\System32\DRIVERS\tdx.sys ==> MD5 is legit
C:\Windows\system32\drivers\termdd.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\tssecsrv.sys ==> MD5 is legit
C:\Windows\System32\drivers\tsusbflt.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\tunnel.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\uagp35.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\udfs.sys ==> MD5 is legit
C:\Windows\system32\drivers\uliagpkx.sys ==> MD5 is legit
C:\Windows\system32\drivers\umbus.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\umpass.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\usbccgp.sys BD9C55D7023C5DE374507ACC7A14E2AC
C:\Windows\system32\drivers\usbcir.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\usbehci.sys F92DE757E4B7CE9C07C5E65423F3AE3B
C:\Windows\System32\DRIVERS\usbhub.sys 8DC94AEC6A7E644A06135AE7506DC2E9
C:\Windows\System32\DRIVERS\usbohci.sys E185D44FAC515A18D9DEDDC23C2CDF44
C:\Windows\System32\DRIVERS\usbprint.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\usbscan.sys 576096CCBC07E7C4EA4F5E6686D6888F
C:\Windows\System32\DRIVERS\USBSTOR.SYS F991AB9CC6B908DB552166768176896A
C:\Windows\system32\drivers\usbuhci.sys 68DF884CF41CDADA664BEB01DAF67E3D
C:\Windows\System32\drivers\vdrvroot.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vgapnp.sys ==> MD5 is legit
C:\Windows\System32\drivers\vga.sys ==> MD5 is legit
C:\Windows\system32\drivers\vhdmp.sys ==> MD5 is legit
C:\Windows\system32\drivers\viaagp.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\viac7.sys ==> MD5 is legit
C:\Windows\system32\drivers\viaide.sys ==> MD5 is legit
C:\Windows\System32\drivers\vmbus.sys ==> MD5 is legit
C:\Windows\system32\drivers\VMBusHID.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgr.sys ==> MD5 is legit
C:\Windows\System32\drivers\volmgrx.sys ==> MD5 is legit
C:\Windows\System32\drivers\volsnap.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\vsmraid.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vwifibus.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\vwififlt.sys 7090D3436EEB4E7DA3373090A23448F7
C:\Windows\system32\DRIVERS\wacompen.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\wanarp.sys ==> MD5 is legit
C:\Windows\system32\DRIVERS\wd.sys ==> MD5 is legit
C:\Windows\System32\drivers\Wdf01000.sys A840213F1ACDCC175B4D1D5AAEAC0D7A
C:\Windows\System32\DRIVERS\wfplwf.sys ==> MD5 is legit
C:\Windows\System32\drivers\wimmount.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\WinUsb.sys A67E5F9A400F3BD1BE3D80613B45F708
C:\Windows\system32\drivers\wmiacpi.sys ==> MD5 is legit
C:\Windows\system32\drivers\ws2ifsl.sys ==> MD5 is legit
C:\Windows\System32\DRIVERS\WSDPrint.sys 553F6CCD7C58EB98D4A8FBDAF283D7A9
C:\Windows\System32\DRIVERS\WSDScan.sys 7DC0270CFD4A05B4112E3EBBF083B595
C:\Windows\System32\drivers\WudfPf.sys 06E6F32C8D0A3F66D956F57B43A2E070
C:\Windows\System32\DRIVERS\WUDFRd.sys 867C301E8B790040AE9CF6486E8041DF

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-09-03 19:35 - 2013-09-03 19:35 - 00000000 ____D C:\FRST
2013-09-02 21:23 - 2013-09-02 21:23 - 00000000 ____D C:\96f3389910d5162ef3339e1855e1b9
2013-09-02 06:17 - 2013-09-02 06:17 - 00000552 _____ C:\Windows\System32\spsys.log
2013-09-02 06:16 - 2013-09-28 04:33 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-02 06:16 - 2013-09-28 04:33 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-02 05:56 - 2013-09-02 05:56 - 00000000 ____D C:\Quarantine
2013-09-02 05:49 - 2013-09-02 05:44 - 09945120 _____ (McAfee Inc) C:\Users\Karl\Desktop\stinger32_12.0.0.508.exe
2013-09-02 05:48 - 2013-09-02 06:10 - 00000000 ____D C:\Program Files\stinger
2013-09-02 05:19 - 2013-09-02 05:19 - 00000000 ____D C:\Windows\pss

==================== One Month Modified Files and Folders =======

2013-10-02 06:12 - 2009-07-13 20:39 - 00107563 _____ C:\Windows\setupact.log
2013-09-28 13:39 - 2010-03-23 05:39 - 00000000 ____D C:\users\Karl
2013-09-28 13:39 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\wfp
2013-09-28 13:39 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\registration
2013-09-28 04:33 - 2013-09-02 06:16 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-09-28 04:33 - 2013-09-02 06:16 - 00007248 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-09-28 04:29 - 2010-03-23 05:41 - 01507104 _____ C:\Windows\System32\PerfStringBackup.INI
2013-09-28 04:29 - 2010-03-23 05:33 - 01286613 _____ C:\Windows\WindowsUpdate.log
2013-09-03 19:35 - 2013-09-03 19:35 - 00000000 ____D C:\FRST
2013-09-03 00:29 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\rescache
2013-09-03 00:01 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\LogFiles
2013-09-02 21:23 - 2013-09-02 21:23 - 00000000 ____D C:\96f3389910d5162ef3339e1855e1b9
2013-09-02 07:00 - 2010-03-24 00:22 - 00000406 __RSH C:\ProgramData\ntuser.pol
2013-09-02 06:59 - 2009-07-13 20:52 - 00000000 ____D C:\Program Files\Windows Defender
2013-09-02 06:59 - 2009-07-13 18:37 - 00000000 ____D C:\Windows\System32\de-DE
2013-09-02 06:17 - 2013-09-02 06:17 - 00000552 _____ C:\Windows\System32\spsys.log
2013-09-02 06:10 - 2013-09-02 05:48 - 00000000 ____D C:\Program Files\stinger
2013-09-02 05:56 - 2013-09-02 05:56 - 00000000 ____D C:\Quarantine
2013-09-02 05:44 - 2013-09-02 05:49 - 09945120 _____ (McAfee Inc) C:\Users\Karl\Desktop\stinger32_12.0.0.508.exe
2013-09-02 05:19 - 2013-09-02 05:19 - 00000000 ____D C:\Windows\pss

==================== Known DLLs (Whitelisted) ============


==================== Bamital & volsnap Check =================

C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== EXE ASSOCIATION =====================

HKLM\...\.exe: exefile => OK
HKLM\...\exefile\DefaultIcon: %1 => OK
HKLM\...\exefile\open\command: "%1" %* => OK

==================== Restore Points  =========================

29
Restore point made on: 2013-04-20 07:35:52
Restore point made on: 2013-04-26 06:13:47
Restore point made on: 2013-04-26 08:18:28
Restore point made on: 2013-04-26 20:47:01
Restore point made on: 2013-04-27 03:05:30
Restore point made on: 2013-04-28 10:51:38
Restore point made on: 2013-04-30 03:32:37
Restore point made on: 2013-05-01 21:40:53
Restore point made on: 2013-05-01 22:18:56
Restore point made on: 2013-05-04 03:16:26
Restore point made on: 2013-05-04 06:30:13
Restore point made on: 2013-05-04 08:52:55
Restore point made on: 2013-05-04 10:03:54
Restore point made on: 2013-05-05 12:10:38
Restore point made on: 2013-05-06 11:12:13
Restore point made on: 2013-07-16 04:12:45
Restore point made on: 2013-09-02 06:26:50
Restore point made on: 2013-09-02 21:17:55
Restore point made on: 2013-09-02 21:36:27
Restore point made on: 2013-09-02 23:56:04
Restore point made on: 2013-09-04 02:22:46
Restore point made on: 2013-09-04 06:38:02
Restore point made on: 2013-09-04 06:38:06
Restore point made on: 2013-09-04 06:38:06
Restore point made on: 2013-09-04 06:38:07
Restore point made on: 2013-09-04 06:38:13
Restore point made on: 2013-09-04 06:38:15
Restore point made on: 2013-09-04 06:38:16
Restore point made on: 2013-09-28 03:27:32

==================== BCD ================================

Windows Boot Manager
--------------------
identifier              {bootmgr}
device                  partition=Y:
path                    \bootmgr
description            Windows Boot Manager
locale                  de-DE
inherit                {globalsettings}
default                {default}
resumeobject            {9b00e3c0-36cb-11df-88e3-d409e3b5888f}
displayorder            {default}
toolsdisplayorder      {memdiag}
timeout                30

Windows Boot Loader
-------------------
identifier              {default}
device                  partition=C:
path                    \Windows\system32\winload.exe
description            Windows 7
locale                  de-DE
inherit                {bootloadersettings}
recoverysequence        {current}
recoveryenabled        Yes
osdevice                partition=C:
systemroot              \Windows
resumeobject            {9b00e3c0-36cb-11df-88e3-d409e3b5888f}
nx                      OptIn

Windows Boot Loader
-------------------
identifier              {current}
device                  ramdisk=[C:]\Recovery\9b00e3c2-36cb-11df-88e3-d409e3b5888f\Winre.wim,{9b00e3c3-36cb-11df-88e3-d409e3b5888f}
path                    \windows\system32\winload.exe
description            Windows Recovery Environment
inherit                {bootloadersettings}
osdevice                ramdisk=[C:]\Recovery\9b00e3c2-36cb-11df-88e3-d409e3b5888f\Winre.wim,{9b00e3c3-36cb-11df-88e3-d409e3b5888f}
systemroot              \windows
nx                      OptIn
winpe                  Yes

Resume from Hibernate
---------------------
identifier              {9b00e3c0-36cb-11df-88e3-d409e3b5888f}
device                  partition=C:
path                    \Windows\system32\winresume.exe
description            Windows Resume Application
locale                  de-DE
inherit                {resumeloadersettings}
filedevice              partition=C:
filepath                \hiberfil.sys
pae                    No
debugoptionenabled      No

Windows Memory Tester
---------------------
identifier              {memdiag}
device                  partition=Y:
path                    \boot\memtest.exe
description            Windows-Speicherdiagnose
locale                  de-DE
inherit                {globalsettings}
badmemoryaccess        Yes

EMS Settings
------------
identifier              {emssettings}
bootems                Yes

Debugger Settings
-----------------
identifier              {dbgsettings}
debugtype              Serial
debugport              1
baudrate                115200

RAM Defects
-----------
identifier              {badmemory}

Global Settings
---------------
identifier              {globalsettings}
inherit                {dbgsettings}
                        {emssettings}
                        {badmemory}

Boot Loader Settings
--------------------
identifier              {bootloadersettings}
inherit                {globalsettings}
                        {hypervisorsettings}

Hypervisor Settings
-------------------
identifier              {hypervisorsettings}
hypervisordebugtype    Serial
hypervisordebugport    1
hypervisorbaudrate      115200

Resume Loader Settings
----------------------
identifier              {resumeloadersettings}
inherit                {globalsettings}

Device options
--------------
identifier              {9b00e3c3-36cb-11df-88e3-d409e3b5888f}
description            Ramdisk Options
ramdisksdidevice        partition=C:
ramdisksdipath          \Recovery\9b00e3c2-36cb-11df-88e3-d409e3b5888f\boot.sdi


==================== Memory info ===========================

Percentage of memory in use: 17%
Total physical RAM: 2558.42 MB
Available physical RAM: 2103.79 MB
Total Pagefile: 2554.64 MB
Available Pagefile: 2100.35 MB
Total Virtual: 2047.88 MB
Available Virtual: 1952.71 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:232.79 GB) (Free:145.97 GB) NTFS
Drive f: () (Removable) (Total:1.87 GB) (Free:0.01 GB) FAT
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: B43DDC96)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=233 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 2 GB) (Disk ID: C3072E18)
Partition 1: (Active) - (Size=2 GB) - (Type=06)


LastRegBack: 2013-09-03 00:22

==================== End Of Log ============================

--- --- ---

--- --- ---

schrauber 03.10.2013 07:28

Log ist sauber.

Versuch nocmal ob einer der drei abgesicherten Modi geht.

In der REcovery auch mal das versuchen:

sfc /scannow

Wenn das alles nix bringt würd ich die Rep-Installation machen.

Rickalon 03.10.2013 17:02

Also,... Keine der drei abgesicherten Modi funktionierte,..

Sfc /scannow brachte leider auch nicht.

Ich führe jetzt eine installation durch ( leider kein Upgrade/ Reperatur, da er diese auch nicht akzeptierte)
Also eine neuinstallation.
Das System meint es würde vorhandene Dateien in einen Windows old Ordner verschieben.

Mal schaun wieviele Dateien der Arbeitskollege wiederfindet. Schade eigentlich. Aber naja, das kommt halt davon, wenn man weder Datensicherungbetreibt noch einen Virenschutz verwendet.:stirn:

Nach der Neuinstallation wurden alle Dateien, die in Benutzer, Desktop, Programme, Windows etc. in einen Windows.old Ordner kopiert. Ich glaube dass so gut wie die meisten Dateien erhalten geblieben sind. Jetzt muss er sich das System halt wieder so zusammenstellen wie er es braucht.

Ich dank dir auf alle Fälle für deine Hilfe und deine Gedult bei diesem komischen und für mich unklaren Fall. Vielen Dank.

schrauber 04.10.2013 02:06

ok :)


Alle Zeitangaben in WEZ +1. Es ist jetzt 13:01 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131