Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Weißer Bildschirm nach Laptopstart (https://www.trojaner-board.de/162111-weisser-bildschirm-laptopstart.html)

Machiavelli 23.12.2014 20:19

Startet das System wieder?

Knescht 23.12.2014 20:22

Nein, immer noch ein weißer Bildschirm zusehen.

Machiavelli 23.12.2014 20:27

Mach einen neuen FRST Scan und poste das Log.

Knescht 23.12.2014 20:34


FRST Logfile:
Code:

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 23-12-2014
Ran by SYSTEM on MININT-HLNDIS0 on 23-12-2014 20:32:04
Running from h:\
Platform: Windows 7 Home Premium (X64) OS Language: Englisch (USA)
Internet Explorer Version 9
Boot Mode: Recovery

The current controlset is ControlSet001
ATTENTION!:=====> If the system is bootable FRST must be run from normal or Safe mode to create a complete log.

Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [SysTrayApp] => C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-01-04] (IDT, Inc.)
HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2837288 2011-10-13] (Synaptics Incorporated)
HKLM\...\Run: [SetDefault] => C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe [44880 2011-12-19] (Hewlett-Packard Development Company, L.P.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [499608 2011-06-16] (Adobe Systems Incorporated)
HKLM\...\Run: [Samsung Link] => C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe [597576 2013-09-03] (Copyright 2013 SAMSUNG)
HKLM\...\Run: [VX3000] => C:\Windows\vVX3000.exe [762736 2010-05-20] (Microsoft Corporation)
HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291096 2011-12-05] (Intel Corporation)
HKLM-x32\...\Run: [Easybits Recovery] => C:\Program Files (x86)\EasyBits For Kids\ezRecover.exe [61112 2011-09-15] (EasyBits Software AS)
HKLM-x32\...\Run: [HP Quick Launch] => C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [576568 2011-11-29] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HPOSD] => C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe [379960 2011-08-19] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [HP CoolSense] => C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe [1342008 2011-08-26] (Hewlett-Packard Development Company, L.P.)
HKLM-x32\...\Run: [avgnt] => C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [702768 2014-12-17] (Avira Operations GmbH & Co. KG)
HKLM-x32\...\Run: [BambooCore] => C:\Program Files (x86)\Bamboo Dock\BambooCore.exe [646744 2012-10-16] ()
HKLM-x32\...\Run: [YouCam Service6] => C:\Program Files (x86)\CyberLink\YouCam6\YouCamService6.exe [504792 2014-03-27] (CyberLink Corp.)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Razer Synapse] => C:\Program Files (x86)\Razer\Synapse\RzSynapse.exe [585536 2014-11-03] (Razer Inc.)
HKLM-x32\...\Run: [LifeCam] => C:\Program Files (x86)\Microsoft LifeCam\LifeExp.exe [119152 2010-05-20] (Microsoft Corporation)
HKLM-x32\...\Run: [Avira Systray] => C:\Program Files (x86)\Avira\My Avira\Avira.OE.Systray.exe [126200 2014-11-20] (Avira Operations GmbH & Co. KG)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKLM\...\Policies\Explorer: [EnableShellExecuteHooks] 1
HKU\USer\...\Run: [ManyCam] => C:\Program Files (x86)\ManyCam\Bin\ManyCam.exe [5379472 2012-12-04] (ManyCam LLC)
HKU\USer\...\Run: [Spotify Web Helper] => C:\Users\USer\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2014-12-21] (Spotify Ltd)
HKU\USer\...\Run: [Pokki] => "%LOCALAPPDATA%\Pokki\Engine\HostAppServiceUpdater.exe" /LOGON
HKU\USer\...\Run: [HP ENVY 110 series (NET)] => C:\Program Files\HP\HP ENVY 110 series\Bin\ScanToPCActivationApp.exe [2676584 2011-09-19] (Hewlett-Packard Co.)
HKU\USer\...\Run: [Sony PC Companion] => C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe [468192 2014-10-15] (Sony)
HKU\USer\...\Run: [Spotify] => C:\Users\USer\AppData\Roaming\Spotify\spotify.exe [6737976 2014-12-21] (Spotify Ltd)
HKU\USer\...\Run: [Akamai NetSession Interface] => C:\Users\USer\AppData\Local\Akamai\netsession_win.exe [4673432 2014-10-29] (Akamai Technologies, Inc.)
HKU\USer\...\Run: [SkyDrive] => C:\Users\USer\AppData\Local\Microsoft\SkyDrive\SkyDrive.exe [277672 2014-09-25] (Microsoft Corporation)
HKU\USer\...\Run: [puush] => C:\Program Files (x86)\puush\puush.exe
AppInit_DLLs: c:\windows\system32\nvinitx.dll => c:\windows\system32\nvinitx.dll [260928 2012-02-02] (NVIDIA Corporation)
Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll
Startup: C:\Users\USer\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\An OneNote senden.lnk
ShortcutTarget: An OneNote senden.lnk -> C:\Program Files\Microsoft Office 15\root\office15\ONENOTEM.EXE (Microsoft Corporation)

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 AdobeActiveFileMonitor10.0; C:\Program Files (x86)\Adobe\Elements 10 Organizer\PhotoshopElementsFileAgent.exe [169624 2011-08-31] (Adobe Systems Incorporated)
S2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.17\AllShareFrameworkManagerDMS.exe [404360 2013-08-23] (Samsung)
S2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [431920 2014-12-17] (Avira Operations GmbH & Co. KG)
S2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [431920 2014-12-17] (Avira Operations GmbH & Co. KG)
S2 Avira.OE.ServiceHost; C:\Program Files (x86)\Avira\My Avira\Avira.OE.ServiceHost.exe [166192 2014-11-20] (Avira Operations GmbH & Co. KG)
S3 Boonty Games; C:\Program Files (x86)\Common Files\BOONTY Shared\Service\Boonty.exe [69120 2012-12-15] (BOONTY)
S2 ClickToRunSvc; C:\Program Files\Microsoft Office 15\ClientX64\OfficeClickToRun.exe [2449592 2014-11-11] (Microsoft Corporation)
S2 FPLService; C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe [260424 2011-12-10] (HP)
S2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2011-12-16] ()
S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2011-12-16] (Intel Corporation)
S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.150\McCHSvc.exe [289256 2014-04-09] (McAfee, Inc.)
S2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [605768 2013-09-03] (Copyright 2013 SAMSUNG)
S3 TrueService; C:\Program Files\Common Files\AuthenTec\TrueService.exe [269640 2011-12-08] (AuthenTec, Inc.)
S2 WTabletServiceCon; C:\Program Files\Tablet\Pen\WTabletServiceCon.exe [656664 2014-08-19] (Wacom Technology, Corp.)
S2 ezSharedSvc; No ImagePath

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [119272 2014-10-21] (Avira Operations GmbH & Co. KG)
S1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [46368 2013-09-30] (AVG Technologies)
S1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131608 2014-10-21] (Avira Operations GmbH & Co. KG)
S1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-05-09] (Avira Operations GmbH & Co. KG)
S3 bcbtums; C:\Windows\System32\drivers\bcbtums.sys [134696 2011-11-03] (Broadcom Corporation.)
S3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [89640 2011-05-20] (Broadcom Corporation.)
S3 clwvd6; C:\Windows\System32\DRIVERS\clwvd6.sys [41704 2013-10-28] (CyberLink Corporation)
S3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [44928 2012-10-10] (ManyCam LLC)
S3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [29696 2012-10-10] (ManyCam LLC)
S3 RSP2STOR; C:\Windows\System32\DRIVERS\RtsP2Stor.sys [259688 2011-10-27] (Realtek Semiconductor Corp.)
S3 SmbDrv; C:\Windows\system32\drivers\Smb_driver.sys [20016 2011-10-13] (Synaptics Incorporated)
S3 clwvd; system32\DRIVERS\clwvd.sys [X]
S3 cpuz134; \??\C:\Users\USer\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-23 19:45 - 2014-12-23 20:32 - 00000000 ____D () C:\FRST
2014-12-21 09:03 - 2014-12-21 09:03 - 00000000 ____D () C:\Users\USer\AppData\Roaming\WTablet
2014-12-21 09:03 - 2014-08-19 11:12 - 01493784 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Wintab32.dll
2014-12-21 08:56 - 2014-12-21 08:56 - 40103880 _____ () C:\Users\USer\Downloads\PenTablet_5.3.5-3 (10).exe
2014-12-21 08:46 - 2014-12-22 10:50 - 00003106 _____ () C:\Windows\System32\Tasks\WinThruster
2014-12-21 08:46 - 2014-12-22 10:40 - 00000280 _____ () C:\Windows\Tasks\WinThruster_UPDATES.job
2014-12-21 08:46 - 2014-12-22 10:40 - 00000272 _____ () C:\Windows\Tasks\WinThruster_DEFAULT.job
2014-12-21 08:46 - 2014-12-21 08:46 - 03894696 _____ (solvusoft Corporation ) C:\Users\USer\Downloads\Libxml2.dll-Reparaturprogramm-WinThruster.exe
2014-12-21 08:46 - 2014-12-21 08:46 - 00003018 _____ () C:\Windows\System32\Tasks\WinThruster_UPDATES
2014-12-21 08:46 - 2014-12-21 08:46 - 00002862 _____ () C:\Windows\System32\Tasks\WinThruster_DEFAULT
2014-12-21 08:46 - 2014-12-21 08:46 - 00000000 ____D () C:\Users\USer\AppData\Roaming\Solvusoft
2014-12-21 08:46 - 2014-12-21 08:46 - 00000000 ____D () C:\Program Files (x86)\WinThruster
2014-12-21 08:45 - 2014-12-21 08:49 - 05344984 _____ (Dll-Files.com ) C:\Users\USer\Downloads\dffsetup-libxml2.exe
2014-12-21 08:40 - 2014-12-23 11:21 - 00005128 _____ () C:\Windows\System32\Tasks\Microsoft Office 15 Sync Maintenance for USer-HP-USer USer-HP
2014-12-21 08:34 - 2014-12-21 08:34 - 00000000 ____D () C:\Program Files\TabletPlugins
2014-12-21 08:34 - 2014-12-21 08:34 - 00000000 ____D () C:\Program Files (x86)\TabletPlugins
2014-12-21 08:34 - 2014-08-19 11:12 - 02006808 _____ (Wacom Technology, Corp.) C:\Windows\System32\WacomMT.dll
2014-12-21 08:34 - 2014-08-19 11:12 - 01991448 _____ (Wacom Technology, Corp.) C:\Windows\System32\Pen_Tablet.dll
2014-12-21 08:34 - 2014-08-19 11:12 - 01984792 _____ (Wacom Technology, Corp.) C:\Windows\System32\Pen_Touch_Tablet.dll
2014-12-21 08:34 - 2014-08-19 11:12 - 01858328 _____ (Wacom Technology, Corp.) C:\Windows\System32\Wintab32.dll
2014-12-21 08:34 - 2014-08-19 11:12 - 01610008 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\WacomMT.dll
2014-12-21 08:34 - 2014-08-19 11:12 - 01607448 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Pen_Touch_Tablet.dll
2014-12-21 08:34 - 2014-08-06 10:15 - 00102200 _____ (Wacom Technology) C:\Windows\System32\Drivers\wachidrouter.sys
2014-12-21 08:34 - 2014-08-06 10:15 - 00015160 _____ (Wacom Technology) C:\Windows\System32\Drivers\wacomrouterfilter.sys
2014-12-21 08:32 - 2014-12-21 08:33 - 40103880 _____ () C:\Users\USer\Downloads\PenTablet_5.3.5-3 (9).exe
2014-12-18 08:16 - 2014-12-18 08:21 - 40103880 _____ () C:\Users\USer\Downloads\PenTablet_5.3.5-3 (8).exe
2014-12-18 06:22 - 2014-12-18 06:22 - 00001137 _____ () C:\Users\Public\Desktop\Avira.lnk
2014-12-18 06:22 - 2014-12-18 06:22 - 00001137 _____ () C:\ProgramData\Desktop\Avira.lnk
2014-12-18 04:03 - 2014-12-18 04:06 - 40103880 _____ () C:\Users\USer\Downloads\PenTablet_5.3.5-3 (7).exe
2014-12-18 03:59 - 2014-08-19 11:12 - 01614104 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Pen_Tablet.dln
2014-12-18 03:54 - 2014-12-18 03:57 - 40103880 _____ () C:\Users\USer\Downloads\PenTablet_5.3.5-3 (6).exe
2014-12-18 03:48 - 2014-08-19 11:12 - 01614104 _____ (Wacom Technology, Corp.) C:\Windows\SysWOW64\Pen_Tablet.dlm
2014-12-18 03:43 - 2014-12-18 03:47 - 40103880 _____ () C:\Users\USer\Downloads\PenTablet_5.3.5-3 (5).exe
2014-12-15 06:13 - 2014-12-15 06:13 - 00001258 _____ () C:\Users\Public\Desktop\World of Warcraft.lnk
2014-12-15 06:13 - 2014-12-15 06:13 - 00001258 _____ () C:\ProgramData\Desktop\World of Warcraft.lnk
2014-12-15 06:08 - 2014-12-18 04:06 - 00000000 ____D () C:\Program Files (x86)\World of Warcraft
2014-12-15 06:07 - 2014-12-21 08:33 - 00000000 ____D () C:\Users\USer\AppData\Local\Battle.net
2014-12-15 06:07 - 2014-12-15 06:08 - 00000000 ____D () C:\Users\USer\AppData\Roaming\Battle.net
2014-12-15 06:07 - 2014-12-15 06:07 - 00001122 _____ () C:\Users\Public\Desktop\Battle.net.lnk
2014-12-15 06:07 - 2014-12-15 06:07 - 00001122 _____ () C:\ProgramData\Desktop\Battle.net.lnk
2014-12-15 06:07 - 2014-12-15 06:07 - 00000000 ____D () C:\Users\USer\AppData\Local\Blizzard Entertainment
2014-12-15 06:06 - 2014-12-15 06:07 - 00000000 ____D () C:\ProgramData\Blizzard Entertainment
2014-12-15 06:06 - 2014-12-15 06:07 - 00000000 ____D () C:\Program Files (x86)\Battle.net
2014-12-15 06:05 - 2014-12-15 06:05 - 02942368 _____ (Blizzard Entertainment) C:\Users\USer\Downloads\World-of-Warcraft-Setup-deDE.exe
2014-12-15 06:05 - 2014-12-15 06:05 - 00000000 ____D () C:\ProgramData\Battle.net
2014-12-15 05:44 - 2014-12-15 05:44 - 00000000 ____D () C:\Program Files\McAfee Security Scan
2014-12-04 11:33 - 2014-12-15 05:44 - 00001931 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk
2014-12-04 11:33 - 2014-12-15 05:44 - 00001931 _____ () C:\ProgramData\Desktop\McAfee Security Scan Plus.lnk
2014-12-04 11:33 - 2014-12-15 05:44 - 00000000 ____D () C:\ProgramData\McAfee Security Scan
2014-12-04 11:25 - 2014-12-04 11:25 - 00002026 _____ () C:\Users\Public\Desktop\Sony PC Companion 2.1.lnk
2014-12-04 11:25 - 2014-12-04 11:25 - 00002026 _____ () C:\ProgramData\Desktop\Sony PC Companion 2.1.lnk
2014-11-29 10:19 - 2014-11-29 10:19 - 00000000 ____D () C:\Users\USer\Downloads\TubeStar v1.6.5.10
2014-11-29 10:18 - 2014-11-29 10:18 - 01870350 _____ () C:\Users\USer\Downloads\TubeStar v1.6.5.10.zip

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-12-23 11:28 - 2009-07-13 20:45 - 00031248 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-12-23 11:28 - 2009-07-13 20:45 - 00031248 ____H () C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-12-23 11:24 - 2009-07-13 21:13 - 00781298 _____ () C:\Windows\System32\PerfStringBackup.INI
2014-12-23 11:20 - 2014-05-01 13:39 - 00001106 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-12-23 11:20 - 2014-03-31 03:38 - 00017104 _____ () C:\Windows\setupact.log
2014-12-23 11:20 - 2009-07-13 21:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-12-23 09:54 - 2012-02-24 09:55 - 00149034 _____ () C:\Windows\System32\perfc007.dat
2014-12-23 09:21 - 2014-03-31 03:38 - 00291744 _____ () C:\Windows\PFRO.log
2014-12-22 11:35 - 2012-09-12 04:54 - 00003922 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{6B68E1B9-7268-4935-94D5-F8D93E608BCA}
2014-12-22 11:33 - 2012-09-12 04:25 - 01677004 _____ () C:\Windows\WindowsUpdate.log
2014-12-22 11:32 - 2014-05-30 09:38 - 00000000 ____D () C:\Program Files\Microsoft Office 15
2014-12-22 11:01 - 2012-11-28 08:02 - 00000254 _____ () C:\Windows\Tasks\HP Photo Creations Messager.job
2014-12-22 10:43 - 2013-03-09 04:49 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-12-21 10:13 - 2014-09-16 06:02 - 00000000 ____D () C:\Users\USer\Desktop\Easy Paint Tool SAI
2014-12-21 10:05 - 2014-03-21 10:05 - 00000288 _____ () C:\Windows\Tasks\Funmoods.job
2014-12-21 09:50 - 2013-02-17 13:15 - 00000000 ____D () C:\Users\USer\AppData\Roaming\Spotify
2014-12-21 09:45 - 2014-05-01 13:39 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-12-21 09:05 - 2012-11-24 13:47 - 00000000 ____D () C:\Users\USer\AppData\Local\CrashDumps
2014-12-21 09:03 - 2014-10-01 09:18 - 00000000 ____D () C:\Program Files\Tablet
2014-12-21 08:45 - 2013-08-07 03:02 - 00000000 ____D () C:\Users\USer\AppData\Local\Pokki
2014-12-21 08:44 - 2013-04-14 03:56 - 00001327 _____ () C:\Windows\wininit.ini
2014-12-21 08:41 - 2012-10-13 03:49 - 00000000 ____D () C:\Users\USer\Documents\Youcam
2014-12-21 08:39 - 2014-05-30 09:51 - 00000000 ___RD () C:\Users\USer\OneDrive
2014-12-21 08:32 - 2012-09-21 23:18 - 00000166 _____ () C:\Windows\SysWOW64\DOErrors.log
2014-12-18 12:15 - 2013-02-17 13:16 - 00000000 ____D () C:\Users\USer\AppData\Local\Spotify
2014-12-18 09:02 - 2013-08-16 11:49 - 00000000 ____D () C:\Users\USer\AppData\Roaming\TS3Client
2014-12-18 06:22 - 2014-05-30 09:29 - 00000000 ____D () C:\ProgramData\Package Cache
2014-12-18 06:22 - 2014-05-30 09:29 - 00000000 ____D () C:\Program Files (x86)\Avira
2014-12-18 05:30 - 2012-11-24 07:36 - 00000000 ____D () C:\Users\USer\AppData\Roaming\.minecraft
2014-12-17 09:08 - 2014-07-26 07:42 - 00003850 _____ () C:\Windows\System32\Tasks\Opera scheduled Autoupdate 1399201204
2014-12-17 09:08 - 2013-02-07 09:29 - 00000000 ____D () C:\Program Files (x86)\Opera
2014-12-15 09:12 - 2013-03-09 04:49 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-12-15 09:12 - 2013-03-08 11:17 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-12-15 09:12 - 2013-02-07 07:40 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-12-15 05:49 - 2014-05-01 13:40 - 00002175 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-12-15 05:49 - 2014-05-01 13:40 - 00002175 _____ () C:\ProgramData\Desktop\Google Chrome.lnk
2014-12-04 11:34 - 2012-11-28 11:45 - 00000000 ____D () C:\Users\USer\AppData\Local\Adobe
2014-12-04 11:25 - 2014-03-26 07:30 - 00097958 _____ () C:\Windows\DPINST.LOG
2014-12-04 11:24 - 2012-02-24 01:37 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information
2014-11-29 06:57 - 2014-09-16 06:02 - 00000000 ____D () C:\Users\USer\Downloads\Easy Paint Tool SAI

==================== Known DLLs (Whitelisted) ================


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

==================== Restore Points  =========================

Restore point made on: 2014-11-20 04:40:59
Restore point made on: 2014-11-23 01:44:19
Restore point made on: 2014-12-15 05:46:20
Restore point made on: 2014-12-21 08:53:50
Restore point made on: 2014-12-22 10:53:57

==================== Memory info ===========================

Percentage of memory in use: 11%
Total physical RAM: 8091.31 MB
Available physical RAM: 7148.56 MB
Total Pagefile: 8089.46 MB
Available Pagefile: 7140.62 MB
Total Virtual: 8192 MB
Available Virtual: 8191.89 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:909.03 GB) (Free:599.94 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive e: (Recovery) (Fixed) (Total:22.19 GB) (Free:2.36 GB) NTFS ==>[System with boot components (obtained from reading drive)]
Drive f: (HP_TOOLS) (Fixed) (Total:0.1 GB) (Free:0.08 GB) FAT32
Drive h: (LEON SPECHT) (Removable) (Total:14.92 GB) (Free:14.92 GB) FAT32
Drive x: (Boot) (Fixed) (Total:0.25 GB) (Free:0.25 GB) NTFS
Drive y: (SYSTEM) (Fixed) (Total:0.19 GB) (Free:0.16 GB) NTFS ==>[System with boot components (obtained from reading drive)]

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 931.5 GB) (Disk ID: 12E059A3)
Partition 1: (Active) - (Size=199 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=909 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=22.2 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=102 MB) - (Type=0C)

========================================================
Disk: 1 (Size: 14.9 GB) (Disk ID: 00000000)

Partition: GPT Partition Type.


LastRegBack: 2014-11-17 06:14

==================== End Of Log ============================

--- --- ---

Machiavelli 23.12.2014 20:55

Wie lange besteht das Problem bereits?

Knescht 23.12.2014 20:58

Seit gestern.

Machiavelli 23.12.2014 21:02

Anstatt auf Eingabeaufforderung zu klicken, klickst Du nun auf Systemwiederherstellung. Dann wählst Du einen aus, an dem der PC noch ging.

Berichte mir , ob der PC wieder bootet.

Knescht 23.12.2014 21:13

Das Problem besteht immer noch.

Machiavelli 23.12.2014 21:55

Wenn Du Dich einloggst und diesen weißen Bildschirm siehst, funktioniert der Task Manager.

Ich denke, das Problem ist nicht malwarebezogen (bzw. nicht direkt!).

Knescht 23.12.2014 22:07

Ja, der Task Manager funktioniert.
Was soll ich laut ihrer Meinung jetzt machen? Bzw wissen sie, wie ich jetzt weiter vorgehen kann?

Machiavelli 23.12.2014 22:22

Das machen: Reparaturinstallation unter Windows Vista / Windows 7 » WinTotal.de

Knescht 24.12.2014 12:47

Habe den Laptop gerade hochgefahren und er zeigt mir wieder alles normal an. :Boogie:

Machiavelli 24.12.2014 12:55

Nachdem Du die Reperaturinstallation gemacht hast?

Knescht 24.12.2014 13:37

Nein, die habe ich nicht gemacht.

Machiavelli 24.12.2014 14:46

Komisch.

Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST Download FRST 32-Bit | FRST 64-Bit
(Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
  • Starte jetzt FRST.
  • Ändere ungefragt keine der Checkboxen und klicke auf Untersuchen.
  • Die Logdateien werden nun erstellt und befinden sich danach auf deinem Desktop.
  • Poste mir die FRST.txt und nach dem ersten Scan auch die Addition.txt in deinem Thread (#-Symbol im Eingabefenster der Webseite anklicken)



Alle Zeitangaben in WEZ +1. Es ist jetzt 16:46 Uhr.

Copyright ©2000-2026, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58