Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Windows7 64Bit: Computer startet nicht mehr, hängt sich bei "Windows wird gestartet" auf und startet neu. (https://www.trojaner-board.de/157660-windows7-64bit-computer-startet-mehr-haengt-windows-gestartet-startet-neu.html)

mavko 16.08.2014 13:17

Windows7 64Bit: Computer startet nicht mehr, hängt sich bei "Windows wird gestartet" auf und startet neu.
 
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-08-2014
Ran by SYSTEM on MININT-BFDQ34G on 16-08-2014 13:59:33
Running from h:\
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.


The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [XboxStat] => C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe [825184 2009-10-01] (Microsoft Corporation)
HKLM-x32\...\Run: [avgnt] => "D:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min
HKLM-x32\...\Run: [ROCCAT Savu Gaming Mouse] => "D:\Program Files (x86)\ROCCAT\Savu Mouse\Savu Monitor.exe" /Automation
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [256896 2014-07-11] (Oracle Corporation)
HKLM-x32\...\Run: [LogMeIn Hamachi Ui] => "D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" --auto-start
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [190032 2014-07-24] (Avira Operations GmbH & Co. KG)
HKU\Default\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\Default User\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun
HKU\Marvin Spielen\...\Run: [Spotify Web Helper] => C:\Users\Marvin Spielen\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1178168 2014-07-04] (Spotify Ltd)
HKU\Marvin Spielen\...\Run: [Microsoft Firewall 2.9] => C:\Users\Marvin Spielen\AppData\Roaming\WMPRWISE.EXE [244224 2014-08-15] (Adobe Systems Incorporated)
HKU\_ocster_backup_\...\Run: [Sidebar] => %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [344064 2014-04-17] (Advanced Micro Devices, Inc.)
S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [141392 2014-07-24] (Avira Operations GmbH & Co. KG)
S3 OpenVPNService; C:\Program Files (x86)\OpenVPN\bin\openvpnserv.exe [14848 2011-04-26] ()
S2 PnkBstrA; C:\Windows\SysWOW64\PnkBstrA.exe [76888 2014-06-19] ()
S3 rpcapd; C:\Program Files (x86)\WinPcap\rpcapd.exe [117264 2010-06-25] (CACE Technologies, Inc.)
S2 AntiVirSchedulerService; "D:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe" [X]
S2 AntiVirService; "D:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe" [X]
S2 Hamachi2Svc; "D:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe" -s [X]
S2 nlsvc; "D:\Program Files\NetLimiter 3\nlsvc.exe" [X]
S2 ocster_backup; "d:\Program Files\Ocster Backup\bin\backupService-ox.exe" "--controlFolder=c:\ProgramData\Ocster Backup\control" "--id=ocster_backup" daemon
S2 SkypeUpdate; "D:\Program Files (x86)\Skype\Updater\Updater.exe" [X]
S2 TeamViewer6; D:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [X]

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S0 amdkmpfd; C:\Windows\System32\DRIVERS\amdkmpfd.sys [35496 2012-07-10] (Advanced Micro Devices, Inc.)
S2 AODDriver4.3; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [59616 2014-02-11] (Advanced Micro Devices)
S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [117712 2014-06-24] (Avira Operations GmbH & Co. KG)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130584 2014-05-22] (Avira Operations GmbH & Co. KG)
S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-10-07] (Avira Operations GmbH & Co. KG)
S3 NPF; C:\Windows\System32\drivers\npf.sys [35344 2010-06-25] (CACE Technologies, Inc.)
S3 RAMDiskVE; C:\Windows\System32\Drivers\RAMDiskVE.sys [73552 2012-11-29] (Dataram, Inc.)
S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [X]
S3 FairplayKD; \??\C:\ProgramData\MTA San Andreas All\1.3\temp\FairplayKD.sys [X]
S1 nltdi; \??\D:\Program Files\NetLimiter 3\nltdi.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-16 13:59 - 2014-08-16 13:59 - 00000000 ____D () C:\FRST
2014-08-15 13:42 - 2014-08-15 13:42 - 00244224 ____H (Adobe Systems Incorporated) C:\Users\Marvin Spielen\AppData\Roaming\WMPRWISE.EXE
2014-08-15 13:42 - 2014-08-15 13:42 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-08-14 01:35 - 2014-06-30 23:24 - 00008856 _____ (Microsoft Corporation) C:\Windows\System32\icardres.dll
2014-08-14 01:35 - 2014-06-30 23:14 - 00008856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardres.dll
2014-08-14 01:35 - 2014-06-06 07:16 - 00035480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TsWpfWrp.exe
2014-08-14 01:35 - 2014-06-06 07:12 - 00035480 _____ (Microsoft Corporation) C:\Windows\System32\TsWpfWrp.exe
2014-08-14 01:35 - 2014-03-09 22:48 - 01389208 _____ (Microsoft Corporation) C:\Windows\System32\icardagt.exe
2014-08-14 01:35 - 2014-03-09 22:48 - 00171160 _____ (Microsoft Corporation) C:\Windows\System32\infocardapi.dll
2014-08-14 01:35 - 2014-03-09 22:47 - 00619672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardagt.exe
2014-08-14 01:35 - 2014-03-09 22:47 - 00099480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\infocardapi.dll
2014-08-13 18:33 - 2014-08-13 18:33 - 00005895 _____ () C:\Users\Marvin Spielen\Desktop\LOL_OPGG_Observer_1435762167.bat
2014-08-13 14:09 - 2014-07-16 04:23 - 00002048 _____ (Microsoft Corporation) C:\Windows\System32\tzres.dll
2014-08-13 14:09 - 2014-07-16 03:46 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-08-13 14:09 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\KBDYAK.DLL
2014-08-13 14:09 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\KBDTAT.DLL
2014-08-13 14:09 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\KBDRU1.DLL
2014-08-13 14:09 - 2014-07-09 03:03 - 00007168 _____ (Microsoft Corporation) C:\Windows\System32\KBDBASH.DLL
2014-08-13 14:09 - 2014-07-09 03:03 - 00006656 _____ (Microsoft Corporation) C:\Windows\System32\KBDRU.DLL
2014-08-13 14:09 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDYAK.DLL
2014-08-13 14:09 - 2014-07-09 02:31 - 00007168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDTAT.DLL
2014-08-13 14:09 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU1.DLL
2014-08-13 14:09 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDRU.DLL
2014-08-13 14:09 - 2014-07-09 02:31 - 00006656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KBDBASH.DLL
2014-08-13 14:09 - 2014-07-08 23:38 - 00419992 _____ () C:\Windows\System32\locale.nls
2014-08-13 14:09 - 2014-07-08 23:30 - 00419992 _____ () C:\Windows\SysWOW64\locale.nls
2014-08-13 14:09 - 2014-06-03 11:02 - 03241984 _____ (Microsoft Corporation) C:\Windows\System32\msi.dll
2014-08-13 14:09 - 2014-06-03 11:02 - 01941504 _____ (Microsoft Corporation) C:\Windows\System32\authui.dll
2014-08-13 14:09 - 2014-06-03 11:02 - 00504320 _____ (Microsoft Corporation) C:\Windows\System32\msihnd.dll
2014-08-13 14:09 - 2014-06-03 11:02 - 00112064 _____ (Microsoft Corporation) C:\Windows\System32\consent.exe
2014-08-13 14:09 - 2014-06-03 10:29 - 02363392 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-08-13 14:09 - 2014-06-03 10:29 - 01805824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll
2014-08-13 14:09 - 2014-06-03 10:29 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msihnd.dll
2014-08-13 14:08 - 2014-08-01 00:41 - 00348856 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2014-08-13 14:08 - 2014-08-01 00:16 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-08-13 14:08 - 2014-07-25 15:52 - 23645696 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2014-08-13 14:08 - 2014-07-25 15:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2014-08-13 14:08 - 2014-07-25 15:01 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2014-08-13 14:08 - 2014-07-25 14:51 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-08-13 14:08 - 2014-07-25 14:30 - 00066048 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2014-08-13 14:08 - 2014-07-25 14:28 - 00548352 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2014-08-13 14:08 - 2014-07-25 14:28 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2014-08-13 14:08 - 2014-07-25 14:25 - 02774528 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2014-08-13 14:08 - 2014-07-25 14:25 - 00083968 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2014-08-13 14:08 - 2014-07-25 14:11 - 00051200 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2014-08-13 14:08 - 2014-07-25 14:10 - 00033792 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2014-08-13 14:08 - 2014-07-25 14:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-08-13 14:08 - 2014-07-25 14:03 - 00598016 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2014-08-13 14:08 - 2014-07-25 14:00 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2014-08-13 14:08 - 2014-07-25 14:00 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2014-08-13 14:08 - 2014-07-25 13:59 - 00758272 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2014-08-13 14:08 - 2014-07-25 13:47 - 00940032 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2014-08-13 14:08 - 2014-07-25 13:40 - 00452096 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2014-08-13 14:08 - 2014-07-25 13:34 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-08-13 14:08 - 2014-07-25 13:34 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-08-13 14:08 - 2014-07-25 13:33 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-08-13 14:08 - 2014-07-25 13:30 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-08-13 14:08 - 2014-07-25 13:28 - 05824512 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2014-08-13 14:08 - 2014-07-25 13:28 - 00072704 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-08-13 14:08 - 2014-07-25 13:21 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-08-13 14:08 - 2014-07-25 13:19 - 00195584 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2014-08-13 14:08 - 2014-07-25 13:18 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-08-13 14:08 - 2014-07-25 13:17 - 00085504 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2014-08-13 14:08 - 2014-07-25 13:17 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-08-13 14:08 - 2014-07-25 13:12 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-08-13 14:08 - 2014-07-25 13:10 - 00292864 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2014-08-13 14:08 - 2014-07-25 13:10 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-08-13 14:08 - 2014-07-25 13:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-08-13 14:08 - 2014-07-25 13:06 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-08-13 14:08 - 2014-07-25 12:52 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-08-13 14:08 - 2014-07-25 12:47 - 00631808 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2014-08-13 14:08 - 2014-07-25 12:43 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-08-13 14:08 - 2014-07-25 12:42 - 00692736 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2014-08-13 14:08 - 2014-07-25 12:39 - 02087936 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2014-08-13 14:08 - 2014-07-25 12:39 - 01249280 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2014-08-13 14:08 - 2014-07-25 12:36 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-08-13 14:08 - 2014-07-25 12:34 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-08-13 14:08 - 2014-07-25 12:29 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-08-13 14:08 - 2014-07-25 12:23 - 13547008 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2014-08-13 14:08 - 2014-07-25 12:13 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-08-13 14:08 - 2014-07-25 12:07 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-08-13 14:08 - 2014-07-25 12:07 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-08-13 14:08 - 2014-07-25 12:03 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-08-13 14:08 - 2014-07-25 11:52 - 02266624 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2014-08-13 14:08 - 2014-07-25 11:26 - 01431040 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2014-08-13 14:08 - 2014-07-25 11:17 - 00846336 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2014-08-13 14:08 - 2014-07-25 11:09 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-08-13 14:08 - 2014-07-25 11:05 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-08-13 14:08 - 2014-07-25 11:00 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-08-13 14:08 - 2014-07-16 04:25 - 00404480 _____ (Microsoft Corporation) C:\Windows\System32\gdi32.dll
2014-08-13 14:08 - 2014-07-16 03:46 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll
2014-08-13 14:08 - 2014-07-16 03:12 - 03163648 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys
2014-08-13 14:08 - 2014-07-14 03:02 - 01216000 _____ (Microsoft Corporation) C:\Windows\System32\rpcrt4.dll
2014-08-13 14:08 - 2014-07-14 02:40 - 00664064 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rpcrt4.dll
2014-08-13 14:08 - 2014-06-25 03:05 - 14175744 _____ (Microsoft Corporation) C:\Windows\System32\shell32.dll
2014-08-13 14:08 - 2014-06-25 02:41 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll
2014-08-13 14:08 - 2014-06-16 03:10 - 00985536 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys
2014-08-07 11:58 - 2014-08-07 11:58 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-08-07 11:53 - 2014-08-07 11:58 - 00001143 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-08-01 10:53 - 2014-05-14 17:23 - 02477536 _____ (Microsoft Corporation) C:\Windows\System32\wuaueng.dll
2014-08-01 10:53 - 2014-05-14 17:23 - 00058336 _____ (Microsoft Corporation) C:\Windows\System32\wuauclt.exe
2014-08-01 10:53 - 2014-05-14 17:23 - 00044512 _____ (Microsoft Corporation) C:\Windows\System32\wups2.dll
2014-08-01 10:53 - 2014-05-14 17:21 - 02620928 _____ (Microsoft Corporation) C:\Windows\System32\wucltux.dll
2014-08-01 10:52 - 2014-05-14 17:23 - 00700384 _____ (Microsoft Corporation) C:\Windows\System32\wuapi.dll
2014-08-01 10:52 - 2014-05-14 17:23 - 00581600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapi.dll
2014-08-01 10:52 - 2014-05-14 17:23 - 00038880 _____ (Microsoft Corporation) C:\Windows\System32\wups.dll
2014-08-01 10:52 - 2014-05-14 17:23 - 00036320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wups.dll
2014-08-01 10:52 - 2014-05-14 17:20 - 00097792 _____ (Microsoft Corporation) C:\Windows\System32\wudriver.dll
2014-08-01 10:52 - 2014-05-14 17:17 - 00092672 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wudriver.dll
2014-08-01 10:52 - 2014-05-14 08:23 - 00198600 _____ (Microsoft Corporation) C:\Windows\System32\wuwebv.dll
2014-08-01 10:52 - 2014-05-14 08:23 - 00179656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuwebv.dll
2014-08-01 10:52 - 2014-05-14 08:20 - 00036864 _____ (Microsoft Corporation) C:\Windows\System32\wuapp.exe
2014-08-01 10:52 - 2014-05-14 08:17 - 00033792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wuapp.exe
2014-07-28 21:34 - 2014-07-28 21:35 - 01592398 _____ (TeamExtreme) C:\Users\Marvin Spielen\Desktop\Minecraft Cracked Launcher.exe
2014-07-24 18:49 - 2014-07-24 19:33 - 00000000 ____D () C:\Users\Marvin Spielen\Desktop\SpiderMod Isaac
2014-07-21 18:38 - 2014-07-21 18:38 - 00004286 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-21 18:38 - 2014-07-11 02:02 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-07-21 18:38 - 2014-07-11 01:56 - 00272808 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-07-21 18:38 - 2014-07-11 01:56 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-07-21 18:38 - 2014-07-11 01:55 - 00175528 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-07-20 14:56 - 2014-07-20 20:40 - 00000000 ____D () C:\Users\Marvin Spielen\AppData\Local\Fallout3

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-08-16 13:59 - 2014-08-16 13:59 - 00000000 ____D () C:\FRST
2014-08-15 13:43 - 2013-01-15 19:48 - 00000000 ____D () C:\Users\Marvin Spielen\AppData\Roaming\Skype
2014-08-15 13:43 - 2013-01-12 23:30 - 01773285 _____ () C:\Windows\WindowsUpdate.log
2014-08-15 13:42 - 2014-08-15 13:42 - 00244224 ____H (Adobe Systems Incorporated) C:\Users\Marvin Spielen\AppData\Roaming\WMPRWISE.EXE
2014-08-15 13:42 - 2014-08-15 13:42 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
2014-08-15 13:36 - 2013-01-13 16:08 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-08-15 12:33 - 2009-07-14 05:45 - 00022704 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-08-15 12:33 - 2009-07-14 05:45 - 00022704 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-08-15 12:30 - 2013-02-10 17:49 - 00000000 ____D () C:\Users\Marvin Spielen\AppData\Local\LogMeIn Hamachi
2014-08-15 12:30 - 2013-01-13 16:08 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-08-15 12:25 - 2013-01-13 03:34 - 00080086 _____ () C:\Windows\setupact.log
2014-08-15 12:25 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-08-15 01:10 - 2013-05-08 19:05 - 00000000 ____D () C:\Users\Marvin Spielen\AppData\Roaming\Spotify
2014-08-14 14:33 - 2013-01-13 11:38 - 00000000 ____D () C:\ProgramData\Skype
2014-08-14 12:40 - 2010-11-21 07:50 - 00699700 _____ () C:\Windows\System32\perfh007.dat
2014-08-14 12:40 - 2010-11-21 07:50 - 00149840 _____ () C:\Windows\System32\perfc007.dat
2014-08-14 12:40 - 2009-07-14 06:13 - 01621772 _____ () C:\Windows\System32\PerfStringBackup.INI
2014-08-14 12:33 - 2009-07-14 05:45 - 00408800 _____ () C:\Windows\System32\FNTCACHE.DAT
2014-08-14 12:31 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-08-13 18:33 - 2014-08-13 18:33 - 00005895 _____ () C:\Users\Marvin Spielen\Desktop\LOL_OPGG_Observer_1435762167.bat
2014-08-13 14:16 - 2013-05-08 19:05 - 00000000 ____D () C:\Users\Marvin Spielen\AppData\Local\Spotify
2014-08-13 01:41 - 2014-02-20 16:22 - 00000000 ____D () C:\Users\Marvin Spielen\AppData\Local\Battle.net
2014-08-09 12:18 - 2013-04-01 16:44 - 00000000 ____D () C:\Users\Marvin Spielen\Desktop\Programme
2014-08-07 11:58 - 2014-08-07 11:58 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-08-07 11:58 - 2014-08-07 11:53 - 00001143 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-08-07 11:58 - 2014-06-14 13:55 - 00000000 ____D () C:\ProgramData\Package Cache
2014-08-07 11:53 - 2013-01-18 22:25 - 00000000 ____D () C:\ProgramData\Avira
2014-08-02 15:19 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-08-01 00:41 - 2014-08-13 14:08 - 00348856 _____ (Microsoft Corporation) C:\Windows\System32\iedkcs32.dll
2014-08-01 00:16 - 2014-08-13 14:08 - 00307384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-07-31 19:57 - 2013-05-10 19:07 - 00000000 ____D () C:\Users\Marvin Spielen\Documents\TrackMania
2014-07-28 22:29 - 2013-01-26 19:02 - 00000000 ____D () C:\Users\Marvin Spielen\AppData\Roaming\.minecraft
2014-07-28 21:35 - 2014-07-28 21:34 - 01592398 _____ (TeamExtreme) C:\Users\Marvin Spielen\Desktop\Minecraft Cracked Launcher.exe
2014-07-28 21:30 - 2013-01-13 12:45 - 00000000 ____D () C:\Users\Marvin\Desktop\Programme
2014-07-27 21:32 - 2013-02-02 23:18 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.exe
2014-07-27 21:32 - 2013-01-24 13:18 - 00281688 _____ () C:\Windows\SysWOW64\PnkBstrB.xtr
2014-07-27 15:38 - 2013-06-02 18:13 - 00000000 ____D () C:\ProgramData\TrackMania
2014-07-27 00:09 - 2013-01-20 17:12 - 00000000 ____D () C:\Users\Marvin Spielen\AppData\Roaming\OBS
2014-07-25 15:52 - 2014-08-13 14:08 - 23645696 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2014-07-25 15:02 - 2014-08-13 14:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2014-07-25 15:01 - 2014-08-13 14:08 - 00004096 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollectorres.dll
2014-07-25 14:51 - 2014-08-13 14:08 - 17524224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-07-25 14:30 - 2014-08-13 14:08 - 00066048 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2014-07-25 14:28 - 2014-08-13 14:08 - 00548352 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll
2014-07-25 14:28 - 2014-08-13 14:08 - 00048640 _____ (Microsoft Corporation) C:\Windows\System32\ieetwproxystub.dll
2014-07-25 14:25 - 2014-08-13 14:08 - 02774528 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2014-07-25 14:25 - 2014-08-13 14:08 - 00083968 _____ (Microsoft Corporation) C:\Windows\System32\MshtmlDac.dll
2014-07-25 14:11 - 2014-08-13 14:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2014-07-25 14:10 - 2014-08-13 14:08 - 00033792 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2014-07-25 14:04 - 2014-08-13 14:08 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-07-25 14:03 - 2014-08-13 14:08 - 00598016 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll
2014-07-25 14:00 - 2014-08-13 14:08 - 00139264 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe
2014-07-25 14:00 - 2014-08-13 14:08 - 00111616 _____ (Microsoft Corporation) C:\Windows\System32\ieetwcollector.exe
2014-07-25 13:59 - 2014-08-13 14:08 - 00758272 _____ (Microsoft Corporation) C:\Windows\System32\jscript9diag.dll
2014-07-25 13:47 - 2014-08-13 14:08 - 00940032 _____ (Microsoft Corporation) C:\Windows\System32\MsSpellCheckingFacility.exe
2014-07-25 13:40 - 2014-08-13 14:08 - 00452096 _____ (Microsoft Corporation) C:\Windows\System32\dxtmsft.dll
2014-07-25 13:34 - 2014-08-13 14:08 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-07-25 13:34 - 2014-08-13 14:08 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-07-25 13:33 - 2014-08-13 14:08 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-07-25 13:30 - 2014-08-13 14:08 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-07-25 13:28 - 2014-08-13 14:08 - 05824512 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2014-07-25 13:28 - 2014-08-13 14:08 - 00072704 _____ (Microsoft Corporation) C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-07-25 13:21 - 2014-08-13 14:08 - 02184704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-07-25 13:19 - 2014-08-13 14:08 - 00195584 _____ (Microsoft Corporation) C:\Windows\System32\msrating.dll
2014-07-25 13:18 - 2014-08-13 14:08 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-07-25 13:17 - 2014-08-13 14:08 - 00085504 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll
2014-07-25 13:17 - 2014-08-13 14:08 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-07-25 13:12 - 2014-08-13 14:08 - 00438784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-07-25 13:10 - 2014-08-13 14:08 - 00292864 _____ (Microsoft Corporation) C:\Windows\System32\dxtrans.dll
2014-07-25 13:10 - 2014-08-13 14:08 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-07-25 13:08 - 2014-08-13 14:08 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-07-25 13:06 - 2014-08-13 14:08 - 04204032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-07-25 12:52 - 2014-08-13 14:08 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-07-25 12:47 - 2014-08-13 14:08 - 00631808 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2014-07-25 12:43 - 2014-08-13 14:08 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-07-25 12:42 - 2014-08-13 14:08 - 00692736 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2014-07-25 12:39 - 2014-08-13 14:08 - 02087936 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl
2014-07-25 12:39 - 2014-08-13 14:08 - 01249280 _____ (Microsoft Corporation) C:\Windows\System32\mshtmlmedia.dll
2014-07-25 12:36 - 2014-08-13 14:08 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-07-25 12:34 - 2014-08-13 14:08 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-07-25 12:29 - 2014-08-13 14:08 - 00239616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-07-25 12:23 - 2014-08-13 14:08 - 13547008 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2014-07-25 12:13 - 2014-08-13 14:08 - 00526336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-07-25 12:07 - 2014-08-13 14:08 - 02001920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-07-25 12:07 - 2014-08-13 14:08 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-07-25 12:03 - 2014-08-13 14:08 - 11772928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-07-25 11:52 - 2014-08-13 14:08 - 02266624 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll
2014-07-25 11:26 - 2014-08-13 14:08 - 01431040 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2014-07-25 11:17 - 2014-08-13 14:08 - 00846336 _____ (Microsoft Corporation) C:\Windows\System32\ieapfltr.dll
2014-07-25 11:09 - 2014-08-13 14:08 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-07-25 11:05 - 2014-08-13 14:08 - 01792512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-07-25 11:00 - 2014-08-13 14:08 - 01169920 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-07-24 19:33 - 2014-07-24 18:49 - 00000000 ____D () C:\Users\Marvin Spielen\Desktop\SpiderMod Isaac
2014-07-24 11:57 - 2013-01-13 11:16 - 00699056 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-07-24 11:57 - 2013-01-13 11:16 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-07-23 20:22 - 2013-01-23 22:13 - 00000000 ____D () C:\ProgramData\Origin
2014-07-21 18:39 - 2014-06-25 12:12 - 00000000 ____D () C:\ProgramData\Oracle
2014-07-21 18:38 - 2014-07-21 18:38 - 00004286 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_65-b20.log
2014-07-21 18:38 - 2013-07-15 13:31 - 00000000 ____D () C:\Program Files (x86)\Java
2014-07-21 12:23 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-07-20 20:40 - 2014-07-20 14:56 - 00000000 ____D () C:\Users\Marvin Spielen\AppData\Local\Fallout3
2014-07-20 14:55 - 2013-01-13 00:16 - 00277596 _____ () C:\Windows\DirectX.log
2014-07-20 14:54 - 2013-01-17 20:08 - 00000000 ____D () C:\Users\Marvin Spielen\Documents\My Games

Some content of TEMP:
====================
C:\Users\Marvin Spielen\AppData\Local\Temp\5qdw5col.dll
C:\Users\Marvin Spielen\AppData\Local\Temp\avgnt.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\CmdLineExt02.dll
C:\Users\Marvin Spielen\AppData\Local\Temp\drm_dyndata_7370014.dll
C:\Users\Marvin Spielen\AppData\Local\Temp\drm_dyndata_7380014.dll
C:\Users\Marvin Spielen\AppData\Local\Temp\i4jdel0.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\jansi-32-git-Bukkit-1.5.2-R1.0-b2788jnks.dll
C:\Users\Marvin Spielen\AppData\Local\Temp\jre-7u60-windows-i586-iftw.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\jre-7u65-windows-i586-iftw.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\Nexus%20Mod%20Manager-0.43.1.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\Nexus%20Mod%20Manager-0.44.3.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\Nexus%20Mod%20Manager-0.44.8.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\raptrpatch.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\raptr_stub.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\riftuninstall.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\SkypeSetup.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\sonarinst.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\SRLDetectionLibrary5032816237251818250.dll
C:\Users\Marvin Spielen\AppData\Local\Temp\UpdateCheckerSetup.exe
C:\Users\Marvin Spielen\AppData\Local\Temp\UpdateFlashPlayer_4bd6164e.exe


==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points  =========================


==================== Memory info ===========================

Percentage of memory in use: 9%
Total physical RAM: 8173.19 MB
Available physical RAM: 7371.58 MB
Total Pagefile: 8171.39 MB
Available Pagefile: 7365.22 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB

==================== Drives ================================

Drive c: (system) (Fixed) (Total:48.83 GB) (Free:9.07 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (programme) (Fixed) (Total:249.26 GB) (Free:15.87 GB) NTFS
Drive f: (Notfall-DVD-4) (CDROM) (Total:2.63 GB) (Free:0 GB) CDFS
Drive h: (SCHLÜSSEL4G) (Removable) (Total:3.91 GB) (Free:3.91 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (Daten) (Fixed) (Total:279.46 GB) (Free:244.86 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 279 GB) (Disk ID: 1927568C)
Partition 1: (Not Active) - (Size=279 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 3D273D26)
Partition 1: (Active) - (Size=49 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=249 GB) - (Type=05)

========================================================
Disk: 3 (Size: 4 GB) (Disk ID: 9FCE4444)
Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)


LastRegBack: 2014-08-07 14:54

==================== End Of Log ============================
==================== Memory info ===========================

Percentage of memory in use: 9%
Total physical RAM: 8173.19 MB
Available physical RAM: 7378.42 MB
Total Pagefile: 8171.39 MB
Available Pagefile: 7374.2 MB
Total Virtual: 8192 MB
Available Virtual: 8191.9 MB

==================== Drives ================================

Drive c: (system) (Fixed) (Total:48.83 GB) (Free:9.07 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (programme) (Fixed) (Total:249.26 GB) (Free:15.87 GB) NTFS
Drive f: (Notfall-DVD-4) (CDROM) (Total:2.63 GB) (Free:0 GB) CDFS
Drive h: (SCHLÜSSEL4G) (Removable) (Total:3.91 GB) (Free:3.91 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS
Drive y: (Daten) (Fixed) (Total:279.46 GB) (Free:244.86 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 279 GB) (Disk ID: 1927568C)
Partition 1: (Not Active) - (Size=279 GB) - (Type=07 NTFS)

========================================================
Disk: 1 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 3D273D26)
Partition 1: (Active) - (Size=49 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=249 GB) - (Type=05)

========================================================
Disk: 3 (Size: 4 GB) (Disk ID: 9FCE4444)
Partition 1: (Not Active) - (Size=4 GB) - (Type=0B)


LastRegBack: 2014-08-07 14:54

==================== End Of Log ============================


schrauber 16.08.2014 13:34

hi,

Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster.

Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument

Code:

HKU\Marvin Spielen\...\Run: [Microsoft Firewall 2.9] => C:\Users\Marvin Spielen\AppData\Roaming\WMPRWISE.EXE [244224 2014-08-15] (Adobe Systems Incorporated)
C:\Users\Marvin Spielen\AppData\Roaming\WMPRWISE.EXE
2014-08-15 13:42 - 2014-08-15 13:42 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage

Speichere diese bitte als Fixlist.txt auf deinem USB Stick.
  • Starte deinen Rechner erneut in die Reparaturoptionen
  • Starte nun die FRST.exe erneut und klicke den Entfernen Button.

Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier.


Rechner normal starten.

mavko 16.08.2014 13:46

Danke erstmal für die schnelle Antwort, hier die Fixlog.txt:

Code:

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-08-2014
Ran by SYSTEM at 2014-08-16 14:43:41 Run:1
Running from g:\
Boot Mode: Recovery
==============================================

Content of fixlist:
*****************
HKU\Marvin Spielen\...\Run: [Microsoft Firewall 2.9] => C:\Users\Marvin Spielen\AppData\Roaming\WMPRWISE.EXE [244224 2014-08-15] (Adobe Systems Incorporated)
C:\Users\Marvin Spielen\AppData\Roaming\WMPRWISE.EXE
2014-08-15 13:42 - 2014-08-15 13:42 - 00000000 ____D () C:\ProgramData\Windows Genuine Advantage
       
*****************

HKU\Marvin Spielen\Software\Microsoft\Windows\CurrentVersion\Run\\Microsoft Firewall 2.9 => value deleted successfully.
C:\Users\Marvin Spielen\AppData\Roaming\WMPRWISE.EXE => Moved successfully.
C:\ProgramData\Windows Genuine Advantage => Moved successfully.

==== End of Fixlog ====


schrauber 17.08.2014 07:17

Startet der Rechner normal?


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:22 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131