superuser9 | 12.04.2014 19:14 | So hier die FRST.txt und addition.txt von meinem Vater:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-03-2014 (ATTENTION: ====> FRST version is 29 days old and could be outdated)
Ran by Markus (administrator) on MARKUS-PC on 11-04-2014 14:03:47
Running from C:\Users\Markus\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(Foxit Corporation) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(Renesas Electronics Corporation) C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(Dropbox, Inc.) C:\Users\Markus\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Windows\system32\wbem\WMIADAP.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2052392 2010-02-12] (Synaptics Incorporated)
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3774312 2014-04-02] (AVAST Software)
HKLM-x32\...\Run: [NUSB3MON] - C:\Program Files (x86)\Renesas Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [113288 2010-11-18] (Renesas Electronics Corporation)
Startup: C:\Users\Markus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Markus\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\ysuz479e.default
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: WOT - C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\ysuz479e.default\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-03-01]
FF Extension: DownloadHelper - C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\ysuz479e.default\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-30]
FF Extension: NoScript - C:\Users\Markus\AppData\Roaming\Mozilla\Firefox\Profiles\ysuz479e.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-03-01]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-03-01]
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-03-01] (AVAST Software)
R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [239680 2014-02-19] (Foxit Corporation)
==================== Drivers (Whitelisted) ====================
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-03-01] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2014-03-01] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-03-01] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-03-01] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-03-01] (AVAST Software)
R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-03-01] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-03-01] ()
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-11 14:03 - 2014-04-11 14:04 - 00005947 _____ () C:\Users\Markus\Desktop\FRST.txt
2014-04-11 14:03 - 2014-04-11 14:03 - 00000000 ____D () C:\FRST
2014-04-11 14:02 - 2014-04-11 14:03 - 02157056 _____ (Farbar) C:\Users\Markus\Desktop\FRST64.exe
2014-04-11 14:00 - 2014-04-11 14:00 - 01070840 _____ (Solid State Networks) C:\Users\Markus\Downloads\install_flashplayer13x32au_mssd_aaa_aih.exe
2014-04-10 20:42 - 2014-04-10 20:45 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-10 20:42 - 2014-04-10 20:42 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-10 20:42 - 2014-04-10 20:42 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-10 20:42 - 2014-04-10 20:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-10 20:42 - 2014-04-03 09:51 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-10 20:42 - 2014-04-03 09:51 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-10 20:42 - 2014-04-03 09:50 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-10 20:40 - 2014-04-10 20:41 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Markus\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-10 20:13 - 2014-04-10 20:13 - 00037784 _____ () C:\Users\Markus\Desktop\00 KollplanPlan 2014neu1004 klf.ods
2014-04-09 18:46 - 2014-03-31 03:16 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-09 18:46 - 2014-03-31 03:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-09 18:46 - 2014-03-31 02:13 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-09 18:46 - 2014-03-31 01:57 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-09 18:45 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-09 18:45 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-09 18:45 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-09 18:45 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-09 18:45 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-09 18:45 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-09 18:45 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-09 18:45 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-09 18:45 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-09 18:45 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-09 18:45 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-07 18:15 - 2014-04-07 18:15 - 00026239 _____ () C:\Users\Markus\Desktop\W-Semin Latein.odt
2014-04-04 18:25 - 2014-04-04 18:25 - 00000000 ____D () C:\Users\Markus\Documents\Berichte Qd
2014-04-04 18:24 - 2014-04-04 18:24 - 00094526 _____ () C:\Users\Markus\Downloads\kursdb2(1).frx
2014-04-04 18:24 - 2014-04-04 18:24 - 00044921 _____ () C:\Users\Markus\Downloads\kursdb2.FRT
2014-04-04 17:59 - 2014-04-04 17:59 - 00079641 _____ () C:\Users\Markus\Downloads\kursdb1.frx
2014-04-03 20:15 - 2014-04-03 20:15 - 00094526 _____ () C:\Users\Markus\Downloads\kursdb2.frx
2014-04-02 16:09 - 2014-04-02 16:09 - 437478278 _____ () C:\Windows\MEMORY.DMP
2014-04-02 16:09 - 2014-04-02 16:09 - 00293608 _____ () C:\Windows\Minidump\040214-14586-01.dmp
2014-04-02 16:09 - 2014-04-02 16:09 - 00000000 ____D () C:\Windows\Minidump
2014-04-02 15:32 - 2014-04-02 15:32 - 00014977 _____ () C:\Users\Markus\Desktop\Q 12 Jahrgangssliste.ods
2014-04-01 16:35 - 2014-04-01 16:36 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-04-01 16:00 - 2014-04-01 16:48 - 00014256 _____ () C:\Users\Markus\Desktop\grprainer cs euroreal.odt
2014-03-22 17:23 - 2014-04-04 18:17 - 00000000 ____D () C:\Users\Markus\Documents\Familie
2014-03-19 19:15 - 2014-03-19 19:15 - 00000153 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2-1.aac.error.log
2014-03-19 19:15 - 2014-03-19 19:15 - 00000153 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2.aac.error.log
2014-03-19 19:00 - 2014-03-19 19:17 - 125452055 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2-3.mp4
2014-03-19 19:00 - 2014-03-19 19:17 - 125452055 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2-2.mp4
2014-03-19 19:00 - 2014-03-19 19:16 - 125452055 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2.mp4
2014-03-19 19:00 - 2014-03-19 19:15 - 100599003 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2-1.flv
2014-03-19 19:00 - 2014-03-19 19:15 - 100599003 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2.flv
2014-03-19 18:59 - 2014-03-19 18:59 - 00000153 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 1.aac.error.log
2014-03-19 18:56 - 2014-03-19 18:59 - 132522264 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 1.flv
2014-03-19 18:56 - 2014-03-19 18:56 - 00000153 _____ () C:\Users\Markus\Desktop\Terra XXL - Vergessene Metropolen - Rom.aac.error.log
2014-03-18 21:53 - 2014-03-18 21:53 - 00031511 _____ () C:\Users\Markus\Desktop\Verjährung Schadensersatz.odt
2014-03-15 15:38 - 2014-03-01 07:16 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-03-15 15:38 - 2014-03-01 06:58 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-03-15 15:38 - 2014-03-01 06:52 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-03-15 15:38 - 2014-03-01 06:51 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-03-15 15:38 - 2014-03-01 06:42 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-03-15 15:38 - 2014-03-01 06:40 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-03-15 15:38 - 2014-03-01 06:37 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-03-15 15:38 - 2014-03-01 06:33 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-03-15 15:38 - 2014-03-01 06:33 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-03-15 15:38 - 2014-03-01 06:32 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-03-15 15:38 - 2014-03-01 06:23 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-03-15 15:38 - 2014-03-01 06:17 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-03-15 15:38 - 2014-03-01 06:02 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-03-15 15:38 - 2014-03-01 05:54 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-03-15 15:38 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-03-15 15:38 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-03-15 15:38 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-03-15 15:38 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-03-15 15:38 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-03-15 15:38 - 2014-03-01 05:42 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-03-15 15:38 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-03-15 15:38 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-03-15 15:38 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-03-15 15:38 - 2014-03-01 05:35 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-03-15 15:38 - 2014-03-01 05:18 - 13051904 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-03-15 15:38 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-03-15 15:38 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-03-15 15:38 - 2014-03-01 05:10 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-03-15 15:38 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-03-15 15:38 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-03-15 15:38 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-03-15 15:38 - 2014-03-01 04:38 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-03-15 15:38 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-03-15 15:38 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-03-15 15:38 - 2014-03-01 04:25 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-03-15 15:38 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-03-15 15:38 - 2014-02-07 03:23 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-03-15 15:38 - 2014-01-29 04:32 - 00484864 _____ (Microsoft Corporation) C:\Windows\system32\wer.dll
2014-03-15 15:38 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wer.dll
2014-03-15 15:35 - 2014-02-04 04:32 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2014-03-15 15:35 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2014-03-13 20:52 - 2014-03-13 20:52 - 00000000 ____D () C:\Users\Public\Foxit Software
==================== One Month Modified Files and Folders =======
2014-04-11 14:04 - 2014-04-11 14:03 - 00005947 _____ () C:\Users\Markus\Desktop\FRST.txt
2014-04-11 14:03 - 2014-04-11 14:03 - 00000000 ____D () C:\FRST
2014-04-11 14:03 - 2014-04-11 14:02 - 02157056 _____ (Farbar) C:\Users\Markus\Desktop\FRST64.exe
2014-04-11 14:02 - 2014-03-01 19:01 - 01984692 _____ () C:\Windows\WindowsUpdate.log
2014-04-11 14:00 - 2014-04-11 14:00 - 01070840 _____ (Solid State Networks) C:\Users\Markus\Downloads\install_flashplayer13x32au_mssd_aaa_aih.exe
2014-04-11 14:00 - 2014-03-02 10:50 - 00000000 ___RD () C:\Users\Markus\Dropbox
2014-04-11 14:00 - 2014-03-02 10:45 - 00000000 ____D () C:\Users\Markus\AppData\Roaming\Dropbox
2014-04-11 13:59 - 2014-03-01 19:19 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-04-11 13:59 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-11 13:59 - 2009-07-14 06:51 - 00028497 _____ () C:\Windows\setupact.log
2014-04-10 20:45 - 2014-04-10 20:42 - 00119512 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-10 20:42 - 2014-04-10 20:42 - 00001102 _____ () C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-04-10 20:42 - 2014-04-10 20:42 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-10 20:42 - 2014-04-10 20:42 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes Anti-Malware
2014-04-10 20:41 - 2014-04-10 20:40 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Markus\Downloads\mbam-setup-2.0.1.1004.exe
2014-04-10 20:13 - 2014-04-10 20:13 - 00037784 _____ () C:\Users\Markus\Desktop\00 KollplanPlan 2014neu1004 klf.ods
2014-04-10 20:00 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-10 20:00 - 2009-07-14 06:45 - 00021664 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-10 19:57 - 2010-11-21 08:50 - 00696912 _____ () C:\Windows\system32\perfh007.dat
2014-04-10 19:57 - 2010-11-21 08:50 - 00148176 _____ () C:\Windows\system32\perfc007.dat
2014-04-10 19:57 - 2009-07-14 07:13 - 01612656 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-07 18:15 - 2014-04-07 18:15 - 00026239 _____ () C:\Users\Markus\Desktop\W-Semin Latein.odt
2014-04-04 18:25 - 2014-04-04 18:25 - 00000000 ____D () C:\Users\Markus\Documents\Berichte Qd
2014-04-04 18:24 - 2014-04-04 18:24 - 00094526 _____ () C:\Users\Markus\Downloads\kursdb2(1).frx
2014-04-04 18:24 - 2014-04-04 18:24 - 00044921 _____ () C:\Users\Markus\Downloads\kursdb2.FRT
2014-04-04 18:17 - 2014-03-22 17:23 - 00000000 ____D () C:\Users\Markus\Documents\Familie
2014-04-04 17:59 - 2014-04-04 17:59 - 00079641 _____ () C:\Users\Markus\Downloads\kursdb1.frx
2014-04-03 20:15 - 2014-04-03 20:15 - 00094526 _____ () C:\Users\Markus\Downloads\kursdb2.frx
2014-04-03 09:51 - 2014-04-10 20:42 - 00088280 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-10 20:42 - 00063192 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-10 20:42 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-04-02 16:09 - 2014-04-02 16:09 - 437478278 _____ () C:\Windows\MEMORY.DMP
2014-04-02 16:09 - 2014-04-02 16:09 - 00293608 _____ () C:\Windows\Minidump\040214-14586-01.dmp
2014-04-02 16:09 - 2014-04-02 16:09 - 00000000 ____D () C:\Windows\Minidump
2014-04-02 15:32 - 2014-04-02 15:32 - 00014977 _____ () C:\Users\Markus\Desktop\Q 12 Jahrgangssliste.ods
2014-04-01 19:54 - 2014-03-01 20:09 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-04-01 16:48 - 2014-04-01 16:00 - 00014256 _____ () C:\Users\Markus\Desktop\grprainer cs euroreal.odt
2014-04-01 16:36 - 2014-04-01 16:35 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-03-31 19:12 - 2014-03-01 19:54 - 00000000 ____D () C:\Users\Markus\AppData\Roaming\vlc
2014-03-31 19:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-03-31 18:15 - 2014-03-01 19:19 - 00001966 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-03-31 18:13 - 2014-03-01 19:01 - 00000000 ____D () C:\Users\Markus
2014-03-31 03:16 - 2014-04-09 18:46 - 23134208 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-03-31 03:13 - 2014-04-09 18:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-03-31 02:13 - 2014-04-09 18:46 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-03-31 01:57 - 2014-04-09 18:46 - 17073152 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-03-30 11:23 - 2014-01-05 11:07 - 00000000 ____D () C:\Users\Markus\Desktop\00 Medien Ges
2014-03-30 10:51 - 2014-03-11 21:11 - 00000000 ____D () C:\Users\Markus\dwhelper
2014-03-24 19:10 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\rescache
2014-03-23 16:20 - 2014-03-01 19:47 - 00000000 ____D () C:\Windows\SysWOW64\Macromed
2014-03-23 16:20 - 2014-03-01 19:47 - 00000000 ____D () C:\Windows\system32\Macromed
2014-03-21 16:00 - 2014-03-01 20:13 - 00000000 ____D () C:\Users\Markus\AppData\Roaming\Foxit Software
2014-03-19 19:17 - 2014-03-19 19:00 - 125452055 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2-3.mp4
2014-03-19 19:17 - 2014-03-19 19:00 - 125452055 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2-2.mp4
2014-03-19 19:16 - 2014-03-19 19:00 - 125452055 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2.mp4
2014-03-19 19:15 - 2014-03-19 19:15 - 00000153 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2-1.aac.error.log
2014-03-19 19:15 - 2014-03-19 19:15 - 00000153 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2.aac.error.log
2014-03-19 19:15 - 2014-03-19 19:00 - 100599003 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2-1.flv
2014-03-19 19:15 - 2014-03-19 19:00 - 100599003 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 2.flv
2014-03-19 18:59 - 2014-03-19 18:59 - 00000153 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 1.aac.error.log
2014-03-19 18:59 - 2014-03-19 18:56 - 132522264 _____ () C:\Users\Markus\Desktop\Rom - Die Entstehung eines Weltreichs Teil 1.flv
2014-03-19 18:56 - 2014-03-19 18:56 - 00000153 _____ () C:\Users\Markus\Desktop\Terra XXL - Vergessene Metropolen - Rom.aac.error.log
2014-03-18 21:53 - 2014-03-18 21:53 - 00031511 _____ () C:\Users\Markus\Desktop\Verjährung Schadensersatz.odt
2014-03-16 11:18 - 2009-07-14 06:45 - 00293320 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-03-13 20:52 - 2014-03-13 20:52 - 00000000 ____D () C:\Users\Public\Foxit Software
Some content of TEMP:
====================
C:\Users\Markus\AppData\Local\Temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpzvsgnx.dll
C:\Users\Markus\AppData\Local\Temp\Foxit Reader Updater.exe
C:\Users\Markus\AppData\Local\Temp\SETUP.EXE
C:\Users\Markus\AppData\Local\Temp\vlc-2.1.4-win64.exe
C:\Users\Markus\AppData\Local\Temp\_ISDEL.EXE
C:\Users\Markus\AppData\Local\Temp\_setup.dll
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-04-10 21:20
==================== End Of Log ============================ --- --- ---
Addition.txt: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-03-2014
Ran by Markus at 2014-04-11 14:04:28
Running from C:\Users\Markus\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.70 - Adobe Systems Incorporated)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2013 - Avast Software)
Dropbox (HKCU\...\Dropbox) (Version: 2.6.2 - Dropbox, Inc.)
Foxit Cloud (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 1.2.75.126 - Foxit Corporation)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 6.1.4.217 - Foxit Corporation)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation)
JMicron Ethernet Adapter NDIS Driver (HKLM-x32\...\{96DCEE2F-98EE-4F80-8C0F-7C04D1FB9D7F}) (Version: 6.0.31.6 - JMicron Technology Corp.)
JMicron Flash Media Controller Driver (HKLM-x32\...\{26604C7E-A313-4D12-867F-7C6E7820BE4C}) (Version: 1.0.62.0 - JMicron Technology Corp.)
Malwarebytes Anti-Malware Version 2.0.1.1004 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.1.1004 - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile (HKLM\...\Microsoft .NET Framework 4 Client Profile) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Client Profile DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (HKLM\...\Microsoft .NET Framework 4 Extended) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended DEU Language Pack (HKLM\...\Microsoft .NET Framework 4 Extended DEU Language Pack) (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 28.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
Mozilla Thunderbird 24.3.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.3.0 (x86 de)) (Version: 24.3.0 - Mozilla)
NVIDIA Grafiktreiber 334.89 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 334.89 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.147.1067 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
NVIDIA Systemsteuerung 334.89 (Version: 334.89 - NVIDIA Corporation) Hidden
OpenOffice 4.0.1 (HKLM-x32\...\{0AEC308E-7EB3-47F7-BB59-F2C9C6166B27}) (Version: 4.01.9714 - Apache Software Foundation)
Qualifikationsphasendatei (HKLM-x32\...\Qualifikationsphasendatei) (Version: - )
Renesas Electronics USB 3.0 Host Controller Driver (HKLM-x32\...\InstallShield_{5442DAB8-7177-49E1-8B22-09A049EA5996}) (Version: 2.0.30.0 - Renesas Electronics Corporation)
Renesas Electronics USB 3.0 Host Controller Driver (x32 Version: 2.0.30.0 - Renesas Electronics Corporation) Hidden
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 15.0.8.0 - Synaptics Incorporated)
TrueCrypt (HKLM-x32\...\TrueCrypt) (Version: 7.1a - TrueCrypt Foundation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (HKLM-x32\...\{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}.KB2836939v3) (Version: 3 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (HKLM-x32\...\{8E34682C-8118-31F1-BC4C-98CD9675E1C2}.KB2836939v3) (Version: 3 - Microsoft Corporation)
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Willi 2.130 (HKLM-x32\...\Willi_is1) (Version: - )
==================== Restore Points =========================
03-03-2014 13:36:20 Windows Update
04-03-2014 10:14:30 Windows Update
11-03-2014 16:08:45 Windows Update
15-03-2014 13:35:57 Windows Update
15-03-2014 14:13:15 Windows Update
18-03-2014 18:22:57 Windows Update
23-03-2014 14:21:47 avast! antivirus system restore point
23-03-2014 14:27:09 Windows Update
28-03-2014 15:45:49 Windows Update
30-03-2014 07:08:41 avast! antivirus system restore point
30-03-2014 07:12:28 Windows Update
31-03-2014 16:13:34 avast! antivirus system restore point
31-03-2014 16:17:33 Windows Update
04-04-2014 15:59:38 Windows Update
08-04-2014 11:06:24 Windows Update
09-04-2014 16:55:24 Windows Update
==================== Hosts content: ==========================
2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {19872001-15BA-4AF7-BB9A-F005407C97CA} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-03-01] (AVAST Software)
==================== Loaded Modules (whitelisted) =============
2014-03-01 19:38 - 2014-02-08 19:42 - 00117024 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2014-04-10 19:53 - 2014-04-10 10:08 - 02193408 _____ () C:\Program Files\AVAST Software\Avast\defs\14041000\algo.dll
2014-04-11 14:00 - 2014-04-11 09:45 - 02209792 _____ () C:\Program Files\AVAST Software\Avast\defs\14041100\algo.dll
2014-03-01 19:18 - 2014-03-01 19:18 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-04-11 14:00 - 2014-04-11 14:00 - 00041984 _____ () c:\users\markus\appdata\local\temp\dropbox_sqlite_ext.{5f3e3153-5bce-5766-8f84-3e3e7ecf0d81}.tmpzvsgnx.dll
2013-10-19 01:55 - 2013-10-19 01:55 - 25100288 _____ () C:\Users\Markus\AppData\Roaming\Dropbox\bin\libcef.dll
2014-04-01 16:35 - 2014-04-01 16:35 - 03642480 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
Name: Fingerprint Sensor
Description: Fingerprint Sensor
Class Guid:
Manufacturer:
Service:
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.
==================== Event log errors: =========================
Application errors:
==================
Error: (04/11/2014 02:01:06 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/10/2014 07:57:06 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: TrustedInstaller.exe, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7989b
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.1.7601.18247, Zeitstempel: 0x521eaf24
Ausnahmecode: 0xc0000374
Fehleroffset: 0x00000000000c4102
ID des fehlerhaften Prozesses: 0x464
Startzeit der fehlerhaften Anwendung: 0xTrustedInstaller.exe0
Pfad der fehlerhaften Anwendung: TrustedInstaller.exe1
Pfad des fehlerhaften Moduls: TrustedInstaller.exe2
Berichtskennung: TrustedInstaller.exe3
Error: (04/10/2014 07:54:26 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/09/2014 06:41:35 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/08/2014 01:04:15 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/08/2014 01:03:16 PM) (Source: Application Error) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7a144
Name des fehlerhaften Moduls: ole32.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7c92c
Ausnahmecode: 0xc0000005
Fehleroffset: 0x000000000002902a
ID des fehlerhaften Prozesses: 0xb20
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
Error: (04/07/2014 06:09:32 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/07/2014 03:29:17 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/06/2014 10:54:35 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/05/2014 08:14:54 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (04/10/2014 07:59:09 PM) (Source: Service Control Manager) (User: )
Description: Der Versuch des Dienststeuerungs-Managers, nach dem unerwarteten Beenden des Dienstes "Windows Modules Installer" Korrekturmaßnahmen (Neustart des Diensts) durchzuführen, ist fehlgeschlagen. Fehler:
%%1056
Error: (04/10/2014 07:57:39 PM) (Source: DCOM) (User: )
Description: {752073A1-23F2-4396-85F0-8FDB879ED0ED}
Error: (04/10/2014 07:57:09 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Windows Modules Installer" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 120000 Millisekunden durchgeführt: Neustart des Diensts.
Error: (04/03/2014 10:44:21 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Server" wurde mit folgendem Fehler beendet:
%%1115
Error: (04/03/2014 08:30:10 PM) (Source: DCOM) (User: )
Description: {AB8902B4-09CA-4BB6-B78D-A8F59079A8D5}
Error: (04/02/2014 04:09:51 PM) (Source: BugCheck) (User: )
Description: 0x00000050 (0xfffff880083bddb8, 0x0000000000000000, 0xfffff80002e0a7f1, 0x0000000000000000)C:\Windows\MEMORY.DMP040214-14586-01
Error: (04/02/2014 04:09:49 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 02.04.2014 um 16:07:53 unerwartet heruntergefahren.
Error: (03/27/2014 06:12:15 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "UPnP-Gerätehost" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Error: (03/27/2014 06:12:15 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "upnphost" konnte sich nicht als "NT AUTHORITY\LocalService" mit dem aktuellen Kennwort aufgrund des folgenden Fehlers anmelden:
%%50
Vergewissern Sie sich, dass der Dienst richtig konfiguriert ist im Dienste-Snap-In in der Microsoft Management Console (MMC).
Error: (03/27/2014 06:12:15 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "UPnP-Gerätehost" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1069
Microsoft Office Sessions:
=========================
Error: (04/11/2014 02:01:06 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/10/2014 07:57:06 PM) (Source: Application Error)(User: )
Description: TrustedInstaller.exe6.1.7601.175144ce7989bntdll.dll6.1.7601.18247521eaf24c000037400000000000c410246401cf54e5bb2e714dC:\Windows\servicing\TrustedInstaller.exeC:\Windows\SYSTEM32\ntdll.dll8719a165-c0d9-11e3-82ab-0090f5b74f49
Error: (04/10/2014 07:54:26 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/09/2014 06:41:35 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/08/2014 01:04:15 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/08/2014 01:03:16 PM) (Source: Application Error)(User: )
Description: Explorer.EXE6.1.7601.175144ce7a144ole32.dll6.1.7601.175144ce7c92cc0000005000000000002902ab2001cf531a1a88d09aC:\Windows\Explorer.EXEC:\Windows\system32\ole32.dll62623864-bf0d-11e3-85e4-0090f5b74f49
Error: (04/07/2014 06:09:32 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/07/2014 03:29:17 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/06/2014 10:54:35 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (04/05/2014 08:14:54 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Percentage of memory in use: 20%
Total physical RAM: 8169.19 MB
Available physical RAM: 6534.57 MB
Total Pagefile: 16336.56 MB
Available Pagefile: 14562.04 MB
Total Virtual: 8192 MB
Available Virtual: 8191.82 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:297.99 GB) (Free:252.05 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 000D526D)
Partition: GPT Partition Type.
==================== End Of Log ============================ Edit:
Hier noch die mbam.txt eines gestern (mit Rootkitsuche) durchgeführten Scans: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Scan Date: 10.04.2014
Scan Time: 21:08:08
Logfile: mbam.txt
Administrator: Yes
Version: 2.00.1.1004
Malware Database: v2014.04.10.07
Rootkit Database: v2014.03.27.01
License: Free
Malware Protection: Disabled
Malicious Website Protection: Disabled
Chameleon: Disabled
OS: Windows 7 Service Pack 1
CPU: x64
File System: NTFS
User: Markus
Scan Type: Threat Scan
Result: Completed
Objects Scanned: 235884
Time Elapsed: 22 min, 48 sec
Memory: Enabled
Startup: Enabled
Filesystem: Enabled
Archives: Enabled
Rootkits: Enabled
Shuriken: Enabled
PUP: Enabled
PUM: Enabled
Processes: 0
(No malicious items detected)
Modules: 0
(No malicious items detected)
Registry Keys: 0
(No malicious items detected)
Registry Values: 0
(No malicious items detected)
Registry Data: 0
(No malicious items detected)
Folders: 0
(No malicious items detected)
Files: 0
(No malicious items detected)
Physical Sectors: 0
(No malicious items detected)
(end) Können die Dateien, die sich auf den Sticks befinden, auf einem Rechner zwischengelagert werden vor dem Formatieren oder ist die Gefahr zu groß, dass dann auch noch Schadware überspielt wird?
Hallo, ich habe hier noch eine Datei entdeckt, die wohl durch die Malware erstellt wurde, einfach durch die Suche nach "autorun.inf".
Und zwar im Ordner C:\Windows\winsxs\x86_microsoft-windows-s..ccessagent-binaries_31bf3856ad364e35_6.1.7600.16385_none_de06b4fbd5b45f78
Die Datei enthalt folgenden Inhalt: Code:
[autorun]
action=BitLocker To Go Reader
icon=BitLockerToGo.exe,-1
ShellExecute=BitLockerToGo.exe
UseAutoPlay=1 Die genannte Exe ist in diesem Ordner, wird allerdings als Microsoft-Datei bezeichnet. Es könnte ja sein, dass es ein Zwischenspeicher für den Wurm ist.
Allerdings stelle ich mir spätestens an diesem Punkt die Frage, ob es nicht sinnvoll wäre, das System neu aufzusetzen, wenn dieser Ordner wirklich verseucht ist und ihn die Scans nicht gefunden haben.
hxxp://forums.comodo.com/virusmalware-removal-assistance-b58.0/-t59583.0.html
Ergänzung:
Ich habe jetzt die Bereinigung auf meinem System durchgeführt. Allerdings hat Combofix/Unistall nicht funktioniert. Dann habe ich Combix in uninstall.exe umbenannt und gestartet. Statt sich zu löschen, hat er aber einen weiteren Test durchgeführt.
Später sah ich dann, dass es daran lag, dass das Programm nicht in Combofix.exe umbenannt wurde, sondern in Combofix.exe.exe, was auf dem Desktop so scheinbar nicht zu verhindern ist. Ich hoffe mal, das hat jetzt keinen Schaden angerichtet, da dieses Programm ja nicht unbedarft benutzt werden sollte. Hier nochmal das Logfile, da er scheinbar noch etwas gemacht hat. Code:
ComboFix 14-04-06.01 - Lukas 12.04.2014 18:37:29.2.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4078.2286 [GMT 2:00]
ausgeführt von:: c:\users\Lukas\Desktop\uninstall.exe.exe
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
Infizierte Kopie von c:\windows\SysWow64\wshtcpip.dll wurde gefunden und desinfiziert
Kopie von - c:\windows\erdnt\cache86\WSHTCPIP.DLL wurde wiederhergestellt
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-03-12 bis 2014-04-12 ))))))))))))))))))))))))))))))
.
.
2014-04-12 16:44 . 2014-04-12 16:44 -------- d-----w- c:\users\Gast\AppData\Local\temp
2014-04-12 16:44 . 2014-04-12 16:44 -------- d-----w- c:\users\Default\AppData\Local\temp
2014-04-11 19:09 . 2014-04-11 19:09 43152 ----a-w- c:\windows\avastSS.scr
2014-04-08 20:04 . 2014-04-08 20:06 -------- d-----w- C:\AdwCleaner
2014-04-08 19:44 . 2014-04-10 18:25 119512 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys
2014-04-08 19:44 . 2014-04-08 19:44 -------- d-----w- c:\program files (x86)\Malwarebytes Anti-Malware
2014-04-08 19:44 . 2014-04-03 07:51 63192 ----a-w- c:\windows\system32\drivers\mwac.sys
2014-04-08 19:44 . 2014-04-03 07:51 88280 ----a-w- c:\windows\system32\drivers\mbamchameleon.sys
2014-04-07 19:02 . 2014-04-07 19:02 -------- d-----w- c:\programdata\Panda Security
2014-04-07 19:02 . 2014-04-07 19:02 -------- d-----w- c:\program files (x86)\Panda USB Vaccine
2014-04-04 19:43 . 2014-03-07 04:43 10521840 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{0B2C8991-182D-4BD4-81CF-1DE22391E203}\mpengine.dll
2014-03-23 20:16 . 2014-03-23 20:16 -------- d-----w- c:\program files (x86)\AGEIA Technologies
2014-03-23 20:16 . 2014-03-23 20:18 -------- d-----w- c:\programdata\NVIDIA
2014-03-23 19:59 . 2014-03-04 13:06 6714312 ----a-w- c:\windows\system32\nvcpl.dll
2014-03-23 19:59 . 2014-03-04 13:06 3497816 ----a-w- c:\windows\system32\nvsvc64.dll
2014-03-23 19:59 . 2014-03-04 13:05 922968 ----a-w- c:\windows\system32\nvvsvc.exe
2014-03-23 19:59 . 2014-03-04 13:05 64968 ----a-w- c:\windows\system32\nvshext.dll
2014-03-23 19:59 . 2014-03-04 13:05 2558808 ----a-w- c:\windows\system32\nvsvcr.dll
2014-03-23 19:59 . 2014-03-04 13:05 386336 ----a-w- c:\windows\system32\nvmctray.dll
2014-03-23 19:59 . 2014-03-04 13:05 3649185 ----a-w- c:\windows\system32\nvcoproc.bin
2014-03-23 19:58 . 2014-03-23 20:16 -------- d-----w- c:\programdata\NVIDIA Corporation
2014-03-23 19:58 . 2014-03-23 20:21 -------- d-----w- c:\program files (x86)\NVIDIA Corporation
2014-03-23 19:56 . 2014-03-23 20:14 -------- d-----w- c:\program files\NVIDIA Corporation
2014-03-23 19:56 . 2014-03-23 19:56 -------- d-----w- C:\NVIDIA
2014-03-23 19:52 . 2014-03-23 19:52 -------- d-----w- c:\program files (x86)\Driver Cleaner Pro
2014-03-14 19:44 . 2014-02-04 02:32 624128 ----a-w- c:\windows\system32\qedit.dll
2014-03-14 19:44 . 2014-02-04 02:04 509440 ----a-w- c:\windows\SysWow64\qedit.dll
2014-03-14 19:44 . 2014-02-04 02:32 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-03-14 19:44 . 2014-02-04 02:04 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-11 19:09 . 2014-01-12 19:05 84816 ----a-w- c:\windows\system32\drivers\aswstm.sys
2014-04-11 19:09 . 2013-04-27 11:09 423240 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-04-11 19:09 . 2013-04-27 11:09 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-04-11 19:09 . 2013-04-27 11:09 1039096 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-04-11 19:09 . 2013-04-27 11:09 208928 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-04-11 19:09 . 2013-04-27 11:09 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-04-11 19:09 . 2013-04-27 11:09 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-04-11 19:09 . 2012-11-02 21:16 334648 ----a-w- c:\windows\system32\aswBoot.exe
2014-04-09 15:52 . 2013-01-01 18:00 90655440 ----a-w- c:\windows\system32\MRT.exe
2014-04-03 07:50 . 2014-02-09 20:38 25816 ----a-w- c:\windows\system32\drivers\mbam.sys
2014-03-17 18:38 . 2012-11-09 18:03 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-03-17 18:38 . 2012-11-09 18:03 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2014-03-04 14:35 . 2014-03-09 10:32 62408 ----a-w- c:\windows\system32\OpenCL.dll
2014-03-04 14:35 . 2014-03-09 10:32 54216 ----a-w- c:\windows\SysWow64\OpenCL.dll
2014-03-04 09:17 . 2014-04-09 14:33 44032 ----a-w- c:\windows\apppatch\acwow64.dll
2014-02-08 18:34 . 2014-03-09 11:33 1885472 ----a-w- c:\windows\system32\nvdispco6433489.dll
2014-02-08 18:34 . 2014-03-09 11:33 1515296 ----a-w- c:\windows\system32\nvdispgenco6433489.dll
2013-09-23 17:30 . 2013-11-03 11:00 6583664 ----a-w- c:\program files\AV
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"f.lux"="c:\users\Lukas\AppData\Local\FluxSoftware\Flux\flux.exe" [2013-10-23 1017224]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-04-11 3854640]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 GPU-Z;GPU-Z;c:\users\Lukas\AppData\Local\Temp\GPU-Z.sys;c:\users\Lukas\AppData\Local\Temp\GPU-Z.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 NPF;NetGroup Packet Filter Driver;c:\windows\system32\drivers\npf.sys;c:\windows\SYSNATIVE\drivers\npf.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x]
R3 USBTINSP;TI-Nspire(TM) Handheld or TI Network Bridge Device Driver;c:\windows\system32\DRIVERS\tinspusb.sys;c:\windows\SYSNATIVE\DRIVERS\tinspusb.sys [x]
R4 Skype C2C Service;Skype C2C Service;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe;c:\programdata\Skype\Toolbars\Skype C2C Service\c2c_service.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S0 vmci;VMware VMCI Bus Driver;c:\windows\system32\DRIVERS\vmci.sys;c:\windows\SYSNATIVE\DRIVERS\vmci.sys [x]
S0 vsock;vSockets Driver;c:\windows\system32\drivers\vsock.sys;c:\windows\SYSNATIVE\drivers\vsock.sys [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x]
S2 VMUSBArbService;VMware USB Arbitration Service;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe;c:\program files (x86)\Common Files\VMware\USB\vmware-usbarbitrator64.exe [x]
S3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x]
S3 cmudaxp;ASUS Xonar DG Audio Interface;c:\windows\system32\drivers\cmudaxp.sys;c:\windows\SYSNATIVE\drivers\cmudaxp.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
.
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-04-11 19:33 1077576 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe
.
Inhalt des "geplante Tasks" Ordners
.
2014-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-09 18:22]
.
2014-04-12 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2013-01-09 18:22]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-04-11 19:09 290888 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Cmaudio8788"="c:\windows\Syswow64\cmicnfgp.dll" [2012-11-20 12935168]
"Cmaudio8788GX"="c:\windows\syswow64\HsMgr.exe" [2008-07-11 200704]
"Cmaudio8788GX64"="c:\windows\system\HsMgr64.exe" [2008-07-11 282112]
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
LSP: %windir%\system32\vsocklib.dll
Trusted Zone: clonewarsadventures.com
Trusted Zone: freerealms.com
Trusted Zone: soe.com
Trusted Zone: sony.com
TCP: DhcpNameServer = 192.168.2.1
TCP: Interfaces\{C665D4D5-3551-48D8-A246-F51C74BFBA7C}: NameServer = 8.8.8.8
FF - ProfilePath - c:\users\Lukas\AppData\Roaming\Mozilla\Firefox\Profiles\eq41rqzz.default\
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
AddRemove-PunkBusterSvc - c:\windows\system32\pbsvc.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_USERS\S-1-5-21-3184381043-3283243088-2878847548-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*]
"??"=hex:e4,b1,ad,00,b2,df,9b,0a,e0,f2,44,07,6e,78,70,d3,e5,53,d3,6b,f7,8f,8d,
21,91,a2,96,ee,b0,ce,ed,ec,83,e5,40,cc,e3,1c,cc,44,09,fe,a2,81,63,b6,07,52,\
"??"=hex:a1,5e,47,db,25,65,bb,27,8b,92,55,34,10,3f,d9,49
.
[HKEY_USERS\S-1-5-21-3184381043-3283243088-2878847548-1000\Software\SecuROM\License information*]
"datasecu"=hex:d8,58,45,a2,3d,53,b6,be,f6,b1,9c,64,f4,3e,58,51,d6,54,02,4c,88,
75,7c,b1,9f,28,23,bb,15,f9,b0,7d,b8,54,d1,0e,51,f6,e0,47,5c,6c,df,50,48,ef,\
"rkeysecu"=hex:dc,a7,92,56,2f,2a,d7,63,ba,b5,ef,2c,63,e8,0e,ec
.
[HKEY_USERS\S-1-5-21-3184381043-3283243088-2878847548-1000_Classes\CLSID]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-3184381043-3283243088-2878847548-1000_Classes\CLSID\{087B3AE3-E237-4467-B8DB-5A38AB959AC9}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-3184381043-3283243088-2878847548-1000_Classes\CLSID\{3B092F0C-7696-40E3-A80F-68D74DA84210}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-3184381043-3283243088-2878847548-1000_Classes\CLSID\{63542C48-9552-494A-84F7-73AA6A7C99C1}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-3184381043-3283243088-2878847548-1000_Classes\CLSID\{7BC0E710-5703-45BE-A29D-5D46D8B39262}]
@DACL=(02 0000)
@="OpenDocument Format Filter"
.
[HKEY_USERS\S-1-5-21-3184381043-3283243088-2878847548-1000_Classes\CLSID\{7BC0E713-5703-45BE-A29D-5D46D8B39262}]
@DACL=(02 0000)
@="OpenDocument Format Persistent Handler"
.
[HKEY_USERS\S-1-5-21-3184381043-3283243088-2878847548-1000_Classes\CLSID\{AE424E85-F6DF-4910-A6A9-438797986431}]
@DACL=(02 0000)
@="OpenOffice Property Handler"
.
[HKEY_USERS\S-1-5-21-3184381043-3283243088-2878847548-1000_Classes\CLSID\{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}]
@DACL=(02 0000)
.
[HKEY_USERS\S-1-5-21-3184381043-3283243088-2878847548-1000_Classes\CLSID\{D45F043D-F17F-4e8a-8435-70971D9FA46D}]
@DACL=(02 0000)
@="Blender Thumbnail Handler"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\SysWOW64\vmnat.exe
c:\program files (x86)\VMware\VMware Player\vmware-authd.exe
c:\windows\SysWOW64\vmnetdhcp.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-04-12 18:53:08 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-04-12 16:53
ComboFix2.txt 2014-04-07 19:14
.
Vor Suchlauf: 15 Verzeichnis(se), 291.560.112.128 Bytes frei
Nach Suchlauf: 17 Verzeichnis(se), 291.324.747.776 Bytes frei
.
- - End Of File - - BEFD3FDA80AEE26C5E1CED634F3A6966
A36C5E4F47E84449FF07ED3517B43A31 |