![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastetWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
| |
| | #1 |
| | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Hallo Lieber Helfer, schon seit Monaten ist mein Arbeitsspeicher dauerhaft zu ca. 80 % ausgelastet. Außerdem funktioniert im Mozilla Firefox kein kopieren, einfügen und ausschneiden von Textbereichen. Habe gestern im abgesicherten Modus Avira deinstalliert und musste im normalen Modus Avast intallieren, weil dies im abgesicherten Modus nicht möglich war. Zudem führte ich gestern eine Vollständige Übeprüfung mit Avast durch und gefunden wurde: nsis.hdr / NSIS:Nextlive-A automatisch in den Container verschoben Logdateien hatte ich bis heute noch nie erstellt und weiß nicht ob Avast eine Logdatei erstellt hat. Habe die FAQ's aufmerksam gelesen und die Suchfunktion von Trojaner-board genutzt, sowie Google und den Hilfe-Inhalt von Avast, außerdem die Suchfunktion in meinem Windows System. Aber bisherige Log files konnte ich nicht finden! Mir ist der Ort bekannt, wo eine Log von Avast existieren müsste: C:\Programme\AVAST Software\Acast Doch ich kann nichts näheres zum letzten Fund finden.. entschuldige, wenn ich auf dem Schlauch stehen sollte. Bitte sage mir ob du etwas sehen kannst, in meinen hochgeladenen Log's, was meinen Arbeitsspeicher auslastet und/oder ob mein PC infiziert ist, und wie ich für weitere Hilfestellungen deinerseits behilflich sein kann. Vielen Dank im voraus Liebe Grüße kazuya |
| | #2 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es:Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
| | #3 |
| | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Huhu,
__________________hier dann der richtige Post. Danke für den Hinweis: (Kurze Wiederholung zu meinem Anliegen: kannst du mir sagen, was meinen Arbeitsspeicher dauerhaft zu ca. 80 % auslastet?) Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1)
Log created at 14:20 on 06/04/2014 (Kazuya)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01
Ran by Kazuya (administrator) on KOICHI on 06-04-2014 14:30:20
Running from C:\Users\Kazuya\Downloads\Schritt für Schritt
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Seiko Epson Corporation) C:\windows\system32\EscSvc.exe
(IObit) C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIJAE.EXE
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Microsoft Corporation) C:\windows\system32\wuauclt.exe
(Intel Corporation) C:\windows\system32\igfxsrvc.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [FUFAXRCV] - C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe [502952 2012-07-09] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [FUFAXSTM] - C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [863400 2012-07-09] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [EEventManager] - C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1058912 2012-04-02] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-05] (AVAST Software)
HKU\.DEFAULT\...\RunOnce: [WLStart] - C:\Program Files\Windows Live\Installer\wlstart.exe [786760 2009-07-26] (Microsoft Corporation)
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\Run: [EPLTarget\P0000000000000000] - C:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIJAE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION)
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {10f43e9d-bb56-11df-a143-806e6f6e6963} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {1b8f9919-b087-11e0-bbb2-705ab658f2fe} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {1b8f9923-b087-11e0-bbb2-705ab658f2fe} - F:\setup_vmc_lite.exe /checkApplicationPresence
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {2f3f4fe1-a70b-11e0-a1f6-705ab658f2fe} - F:\Install.exe
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {61a25b02-bb94-11df-b98d-705ab658f2fe} - F:\setup_vmc_lite.exe /checkApplicationPresence
IFEO\bitguard.exe: [Debugger] tasklist.exe
IFEO\bprotect.exe: [Debugger] tasklist.exe
IFEO\browserdefender.exe: [Debugger] tasklist.exe
IFEO\browserprotect.exe: [Debugger] tasklist.exe
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
URLSearchHook: HKCU - (No Name) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - No File
SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll No File
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
Toolbar: HKCU - No Name - {8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} - No File
Toolbar: HKCU - No Name - {30F9B915-B755-4826-820B-08FBA6BD249D} - No File
Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Kazuya\AppData\Roaming\Mozilla\Firefox\Profiles\miuov82a.default-1388595698206
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-05]
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-05] (AVAST Software)
R2 EpsonScanSvc; C:\windows\system32\EscSvc.exe [122000 2011-12-12] (Seiko Epson Corporation)
R2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2151744 2013-12-31] (IObit)
S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-07-04] (Vodafone)
S4 AntiVirWebService; "C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe" [X]
==================== Drivers (Whitelisted) ====================
R3 ACPIVPC; C:\windows\System32\DRIVERS\AcpiVpc.sys [21520 2009-05-19] (Lenovo Corporation)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [67824 2014-04-05] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [81768 2014-04-05] (AVAST Software)
R0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49944 2014-04-05] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [776976 2014-04-05] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [411552 2014-04-05] (AVAST Software)
R3 aswStm; C:\windows\system32\drivers\aswStm.sys [67264 2014-04-05] (AVAST Software)
R0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [180760 2014-04-05] ()
R1 funfrm; C:\windows\system32\Drivers\funfrm.sys [54800 2010-02-09] ()
S3 wdmirror; C:\windows\System32\DRIVERS\WDMirror.sys [11792 2009-07-16] (Windows (R) Codename Longhorn DDK provider)
S3 wsvd; C:\windows\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink)
S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X]
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
S3 WinRing0_1_2_0; \??\D:\test\ECECECEC\WinRing0.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-06 14:28 - 2014-04-06 14:30 - 00000000 ____D () C:\FRST
2014-04-06 14:20 - 2014-04-06 14:21 - 00000474 _____ () C:\Users\Kazuya\Desktop\defogger_disable.log
2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable
2014-04-06 14:17 - 2014-04-06 14:30 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt
2014-04-06 14:16 - 2014-04-06 14:16 - 00050477 _____ () C:\Users\Kazuya\Desktop\Defogger.exe
2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia
2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-04-05 22:10 - 2014-04-06 13:57 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-05 21:58 - 2014-04-05 21:58 - 00002123 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software
2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software
2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys
2014-04-05 21:50 - 2014-04-05 21:54 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys
2014-04-05 21:37 - 2014-04-05 21:38 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe
2014-03-31 08:50 - 2014-03-31 08:53 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik Konzeptverkäufer HRO 4 2014.ods
2014-03-25 20:14 - 2014-03-25 20:15 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe
2014-03-16 19:32 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-16 19:32 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-16 19:32 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-03-16 19:32 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-03-16 19:32 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-03-16 19:32 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-03-16 19:32 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-03-16 19:32 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-03-16 19:32 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-03-16 19:32 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-03-16 19:32 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-03-16 19:32 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-03-16 19:32 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-03-16 19:32 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-03-16 19:32 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-03-16 19:32 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-03-16 19:32 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-03-16 19:32 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-03-16 19:32 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-03-16 19:32 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-03-16 19:32 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-03-16 19:32 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-03-16 19:26 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-03-16 19:26 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-03-16 19:26 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-03-16 19:26 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2014-03-16 19:26 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2014-03-11 13:59 - 2014-03-21 23:56 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx
2014-03-11 13:57 - 2014-03-25 20:23 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff
2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx
==================== One Month Modified Files and Folders =======
2014-04-06 14:30 - 2014-04-06 14:28 - 00000000 ____D () C:\FRST
2014-04-06 14:30 - 2014-04-06 14:17 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt
2014-04-06 14:28 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-06 14:28 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-06 14:21 - 2014-04-06 14:20 - 00000474 _____ () C:\Users\Kazuya\Desktop\defogger_disable.log
2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable
2014-04-06 14:20 - 2010-09-08 16:02 - 00000000 ____D () C:\Users\Kazuya
2014-04-06 14:16 - 2014-04-06 14:16 - 00050477 _____ () C:\Users\Kazuya\Desktop\Defogger.exe
2014-04-06 14:15 - 2010-02-09 10:45 - 01912579 _____ () C:\windows\WindowsUpdate.log
2014-04-06 14:09 - 2013-09-24 19:27 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-04-06 14:09 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-06 14:09 - 2009-07-14 06:39 - 00113231 _____ () C:\windows\setupact.log
2014-04-06 13:57 - 2014-04-05 22:10 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-06 13:56 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\tracing
2014-04-06 00:41 - 2010-01-18 19:03 - 01765534 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia
2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-04-05 22:16 - 2013-09-24 18:58 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2014-04-05 22:16 - 2013-04-07 17:59 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2014-04-05 21:58 - 2014-04-05 21:58 - 00002123 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software
2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software
2014-04-05 21:54 - 2014-04-05 21:50 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys
2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys
2014-04-05 21:49 - 2010-01-18 19:12 - 00631348 _____ () C:\windows\PFRO.log
2014-04-05 21:48 - 2013-09-28 21:38 - 00000000 ____D () C:\ProgramData\Avira
2014-04-05 21:38 - 2014-04-05 21:37 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe
2014-04-05 21:29 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\FxsTmp
2014-04-05 20:27 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\wfp
2014-04-05 20:26 - 2011-01-28 17:09 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\vlc
2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\NDF
2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\AppCompat
2014-04-05 20:25 - 2010-01-18 18:57 - 00000000 __RHD () C:\MSOCache
2014-04-05 20:25 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\registration
2014-04-01 01:53 - 2009-07-29 12:50 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-03-31 08:53 - 2014-03-31 08:50 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik Konzeptverkäufer HRO 4 2014.ods
2014-03-26 21:26 - 2013-12-31 19:52 - 00000000 ____D () C:\ProgramData\ProductData
2014-03-25 20:23 - 2014-03-11 13:57 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff
2014-03-25 20:19 - 2010-01-18 19:13 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-25 20:18 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\Adobe
2014-03-25 20:17 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Adobe
2014-03-25 20:15 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe
2014-03-21 23:56 - 2014-03-11 13:59 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx
2014-03-16 19:41 - 2009-07-14 06:33 - 00414320 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-16 19:36 - 2013-09-30 15:36 - 00000000 ____D () C:\windows\system32\MRT
2014-03-16 19:33 - 2013-09-30 15:36 - 87350280 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-03-11 13:59 - 2010-09-13 21:36 - 00000000 ____D () C:\Users\Public\Documents\texte
2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx
Some content of TEMP:
====================
C:\Users\Kazuya\AppData\Local\Temp\0kzpwa6k.dll
C:\Users\Kazuya\AppData\Local\Temp\2f5dddvp.dll
C:\Users\Kazuya\AppData\Local\Temp\33972uninstall.exe
C:\Users\Kazuya\AppData\Local\Temp\3im0mncd.dll
C:\Users\Kazuya\AppData\Local\Temp\4vtwgrfo.dll
C:\Users\Kazuya\AppData\Local\Temp\6vuldinv.dll
C:\Users\Kazuya\AppData\Local\Temp\7xcn6fpl.dll
C:\Users\Kazuya\AppData\Local\Temp\7z916.exe
C:\Users\Kazuya\AppData\Local\Temp\8ceuvc6z.dll
C:\Users\Kazuya\AppData\Local\Temp\agtp5wny.dll
C:\Users\Kazuya\AppData\Local\Temp\app.exe
C:\Users\Kazuya\AppData\Local\Temp\avgnt.exe
C:\Users\Kazuya\AppData\Local\Temp\BackupSetup.exe
C:\Users\Kazuya\AppData\Local\Temp\BundleSweetIMSetup.exe
C:\Users\Kazuya\AppData\Local\Temp\cbyaagar.dll
C:\Users\Kazuya\AppData\Local\Temp\DeleteEcUninstall.exe
C:\Users\Kazuya\AppData\Local\Temp\donw3fx6.dll
C:\Users\Kazuya\AppData\Local\Temp\drm_dyndata_7400005.dll
C:\Users\Kazuya\AppData\Local\Temp\eq1x7zjn.dll
C:\Users\Kazuya\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe
C:\Users\Kazuya\AppData\Local\Temp\g3-rymre.dll
C:\Users\Kazuya\AppData\Local\Temp\GLF848F.tmp.ConduitEngineSetup.exe
C:\Users\Kazuya\AppData\Local\Temp\i399ol3f.dll
C:\Users\Kazuya\AppData\Local\Temp\ilsqm4bc.dll
C:\Users\Kazuya\AppData\Local\Temp\l6wk4tg7.dll
C:\Users\Kazuya\AppData\Local\Temp\lrun8vok.dll
C:\Users\Kazuya\AppData\Local\Temp\mg02ea0h.dll
C:\Users\Kazuya\AppData\Local\Temp\MybabylonTB.exe
C:\Users\Kazuya\AppData\Local\Temp\ncq7qzzc.dll
C:\Users\Kazuya\AppData\Local\Temp\ndtdsia_.dll
C:\Users\Kazuya\AppData\Local\Temp\nf_lag8i.dll
C:\Users\Kazuya\AppData\Local\Temp\p9jdhxwr.dll
C:\Users\Kazuya\AppData\Local\Temp\promote-upx.exe
C:\Users\Kazuya\AppData\Local\Temp\propsys.dll
C:\Users\Kazuya\AppData\Local\Temp\pzcx1s-o.dll
C:\Users\Kazuya\AppData\Local\Temp\SIntf16.dll
C:\Users\Kazuya\AppData\Local\Temp\SIntf32.dll
C:\Users\Kazuya\AppData\Local\Temp\SIntfNT.dll
C:\Users\Kazuya\AppData\Local\Temp\Softonic_Deutsch.exe
C:\Users\Kazuya\AppData\Local\Temp\Sqlite3.dll
C:\Users\Kazuya\AppData\Local\Temp\tbSoft.dll
C:\Users\Kazuya\AppData\Local\Temp\tbu15B1.exe
C:\Users\Kazuya\AppData\Local\Temp\tbu17B5.exe
C:\Users\Kazuya\AppData\Local\Temp\tbuF4BA.exe
C:\Users\Kazuya\AppData\Local\Temp\uchhlufn.dll
C:\Users\Kazuya\AppData\Local\Temp\uninst1.exe
C:\Users\Kazuya\AppData\Local\Temp\uninstall.exe
C:\Users\Kazuya\AppData\Local\Temp\vbxb5orq.dll
C:\Users\Kazuya\AppData\Local\Temp\vcredist_x86.exe
C:\Users\Kazuya\AppData\Local\Temp\w8dqhfu5.dll
C:\Users\Kazuya\AppData\Local\Temp\wm4bjeyn.dll
C:\Users\Kazuya\AppData\Local\Temp\wtr2y8ud.dll
C:\Users\Kazuya\AppData\Local\Temp\yfejxr3f.dll
C:\Users\Kazuya\AppData\Local\Temp\yg6mvt_-.dll
C:\Users\Kazuya\AppData\Local\Temp\yurmxiym.dll
C:\Users\Kazuya\AppData\Local\Temp\_isC2A3.exe
C:\Users\Kazuya\AppData\Local\Temp\_isE780.exe
==================== Bamital & volsnap Check =================
C:\windows\explorer.exe => MD5 is legit
C:\windows\system32\winlogon.exe => MD5 is legit
C:\windows\system32\wininit.exe => MD5 is legit
C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\system32\services.exe => MD5 is legit
C:\windows\system32\User32.dll => MD5 is legit
C:\windows\system32\userinit.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit
C:\windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-31 03:14
==================== End Of Log ============================
Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-03-2014 01
Ran by Kazuya at 2014-04-06 14:31:13
Running from C:\Users\Kazuya\Downloads\Schritt für Schritt
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2016 - Avast Software)
Broadcom 802.11 Wireless Driver (HKLM\...\{8991E763-21F5-4DEA-A938-5D9D77DCB488}) (Version: 1.0.0.0 - )
Business Contact Manager für Outlook 2007 SP2 (HKLM\...\Business Contact Manager) (Version: 3.0.8619.1 - Microsoft Corporation)
Business Contact Manager für Outlook 2007 SP2 (Version: 3.0.8619.1 - Microsoft Corporation) Hidden
Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.98.4.0 - Conexant)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{81FB7C60-565A-4869-9D90-3BE1D270E8B7}) (Version: - Microsoft)
Energy Management (HKLM\...\{AE1E24C2-E720-42D5-B8E1-48F71A97B4DB}) (Version: 4.3.1.5 - Lenovo)
Epson Benutzerhandbuch XP-800 Series (HKLM\...\XP-800 Series Useg) (Version: - )
Epson Connect Guide (HKLM\...\Epson Connect Guide) (Version: - )
Epson Event Manager (HKLM\...\{8F01524C-0676-4CC1-B4AE-64753C723391}) (Version: 3.01.0005 - Seiko Epson Corporation)
Epson FAX Utility (HKLM\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.31.00 - SEIKO EPSON CORPORATION)
Epson Netzwerkhandbuch XP-800 Series (HKLM\...\XP-800 Series Netg) (Version: - )
Epson PC-FAX Driver (HKLM\...\EPSON PC-FAX Driver 2) (Version: - )
EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation)
EPSON XP-800 Series Printer Uninstall (HKLM\...\EPSON XP-800 Series) (Version: - SEIKO EPSON Corporation)
EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.5.00 - SEIKO EPSON CORPORATION)
Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation)
Intel(R) TV Wizard (HKLM\...\TVWiz) (Version: - Intel Corporation)
Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation)
Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Choice Guard (Version: 2.0.48.0 - Microsoft Corporation) Hidden
Microsoft Office 2003 Web Components (HKLM\...\{90A40407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8003.0 - Microsoft Corporation)
Microsoft Office 2007 Primary Interop Assemblies (HKLM\...\{50120000-1105-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Single Image 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Small Business Connectivity Components (HKLM\...\{A939D341-5A04-4E0A-BB55-3E65B386432D}) (Version: 2.0.7024.0 - Microsoft Corporation)
Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 (HKLM\...\Microsoft SQL Server 2005) (Version: - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) (Version: 9.4.5000.00 - Microsoft Corporation) Hidden
Microsoft SQL Server Native Client (HKLM\...\{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server Setup Support Files (English) (HKLM\...\{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft SQL Server VSS Writer (HKLM\...\{E7084B89-69E0-46B3-A118-8F99D06988CD}) (Version: 9.00.5000.00 - Microsoft Corporation)
Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 28.0 (x86 de) (HKLM\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla)
Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla)
MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden
Power2Go (HKLM\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.4809d4 - CyberLink Corp.)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (Version: - Microsoft) Hidden
Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{001E8BF3-EDC3-4D5E-9C11-1D0E599B6497}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2494150) (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{D7D96A96-F61F-48AD-B2DC-4F4B6938D2AB}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{B5C70C99-B109-42FD-B219-FF12CA543F19}) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3EFF1957-7DEA-4C7A-8E9C-2D6D58E4B2ED}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{81812245-FC84-426A-BC02-6659C88CC7B2}) (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{190EC86F-5867-4D7A-B9F3-D14D82C26F3D}) (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{E78E2B68-8FD1-42EE-BB74-99A4D9E6222D}) (Version: - Microsoft)
VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Vodafone Mobile Connect Lite (HKLM\...\{C656142F-EFE1-44CD-BFAD-6CBC6DCB9860}) (Version: 9.3.3.10523 - Vodafone)
Windows Live Call (Version: 14.0.8064.0206 - Microsoft Corporation) Hidden
Windows Live Communications Platform (Version: 14.0.8064.206 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation)
Windows Live Essentials (Version: 14.0.8089.726 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (Version: 14.0.8081.709 - Microsoft Corporation) Hidden
Windows Live Mail (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Messenger (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live Movie Maker (Version: 14.0.8091.0730 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live Writer (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden
Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation)
WinRAR 5.01 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH)
==================== Restore Points =========================
16-03-2014 17:32:50 Windows Update
21-03-2014 21:40:57 Windows Update
30-03-2014 19:20:30 Windows Update
31-03-2014 23:50:43 Wiederherstellungsvorgang
03-04-2014 17:52:58 Windows Update
05-04-2014 18:11:15 Wiederherstellungsvorgang
05-04-2014 19:56:02 avast! antivirus system restore point
==================== Hosts content: ==========================
2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {2F88FC51-99EC-417F-A32F-C4FEE72D7DF6} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-04-05] (AVAST Software)
Task: {5134E82E-2A0D-4C9F-9736-29215B99C6C9} - System32\Tasks\{70EC7443-1025-4672-BBD2-4F8A7C694DCE} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {5A517D2E-F200-4FF2-A957-EEB67D57964D} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-05] (Adobe Systems Incorporated)
Task: {93A6E725-6732-4B51-9BF7-89AD55373E9C} - System32\Tasks\{2D5CFE77-0C81-42B1-B938-1A843BEF1831} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {A2B5D60B-552E-4F64-B5B1-4C15B48D83FF} - System32\Tasks\{089487B7-4BEA-4417-B583-30CDBA1402C3} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {B2A1CFFD-E741-47CE-92FC-EC8B3332D205} - System32\Tasks\{C7C8E65B-5D02-4ABA-95EB-BA64C2D24D5E} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {BB2F5FE5-7D8B-4571-9178-D91B49A53A0D} - System32\Tasks\{8EF0B629-6E06-40A5-8B8D-1B74D49EBD5C} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {C76794B6-1B4F-4332-8489-3C42ED98A25C} - System32\Tasks\{BB7A5E64-78D6-4D3C-9F15-1899A5E8C355} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {C8DD6C9E-6149-40EF-B2A1-018EA0C02921} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup
Task: {E3C06A89-3FF8-421A-A1E3-27030FBD2837} - System32\Tasks\{C056EB45-A940-48FF-A65A-1D3D68FDFFD4} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: {FD9171C0-7AAF-443F-83CF-28E5E2562BE3} - System32\Tasks\{0619CB49-03E9-470F-A041-410D67E10D97} => C:\Program Files\Ablaze\ablaze_v106.exe
Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2014-04-06 13:56 - 2014-04-06 13:56 - 02189824 _____ () C:\Program Files\AVAST Software\Avast\defs\14040600\algo.dll
2014-04-05 21:57 - 2014-04-05 21:57 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-04-05 22:39 - 2014-04-05 22:39 - 03642480 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver"
==================== Disabled items from MSCONFIG ==============
MSCONFIG\startupreg: avgnt => "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min
MSCONFIG\startupreg: Energy Management => C:\Program Files\Lenovo\Energy Management\Energy Management.exe
MSCONFIG\startupreg: EnergyUtility => C:\Program Files\Lenovo\Energy Management\utility.exe
MSCONFIG\startupreg: HotKeysCmds => C:\windows\system32\hkcmd.exe
MSCONFIG\startupreg: IAAnotif => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
MSCONFIG\startupreg: IgfxTray => C:\windows\system32\igfxtray.exe
MSCONFIG\startupreg: MobileConnect => %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent
MSCONFIG\startupreg: mobilegeni daemon => C:\Program Files\Mobogenie\DaemonProcess.exe
MSCONFIG\startupreg: Persistence => C:\windows\system32\igfxpers.exe
MSCONFIG\startupreg: SmartAudio => C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t
MSCONFIG\startupreg: UpdateP2GShortCut => "C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0"
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (04/06/2014 02:10:12 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (04/06/2014 01:54:47 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (04/06/2014 00:37:14 AM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 09:56:12 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary xpvzlpga.
System Error:
Das System kann die angegebene Datei nicht finden.
.
Error: (04/05/2014 09:56:01 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {777785d9-4bbc-4c2b-8619-a7e65b0de15b}
Error: (04/05/2014 09:52:54 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 08:27:25 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT)
Description: 0x0
Error: (04/05/2014 08:15:51 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 08:07:44 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 07:44:03 PM) (Source: VMCService) (User: )
Description: conflictManagerTypeValue
System errors:
=============
Error: (04/05/2014 09:51:22 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:51:01 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%1068
Error: (04/05/2014 09:50:10 PM) (Source: DCOM) (User: )
Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}
Error: (04/05/2014 09:50:10 PM) (Source: DCOM) (User: )
Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39}
Microsoft Office Sessions:
=========================
Error: (04/06/2014 02:10:12 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (04/06/2014 01:54:47 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (04/06/2014 00:37:14 AM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 09:56:12 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary xpvzlpga.
System Error:
Das System kann die angegebene Datei nicht finden.
Error: (04/05/2014 09:56:01 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {777785d9-4bbc-4c2b-8619-a7e65b0de15b}
Error: (04/05/2014 09:52:54 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 08:27:25 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT)
Description: 0x0
Error: (04/05/2014 08:15:51 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 08:07:44 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
Error: (04/05/2014 07:44:03 PM) (Source: VMCService)(User: )
Description: conflictManagerTypeValue
==================== Memory info ===========================
Percentage of memory in use: 77%
Total physical RAM: 984.6 MB
Available physical RAM: 216.92 MB
Total Pagefile: 2008.6 MB
Available Pagefile: 931.06 MB
Total Virtual: 2047.88 MB
Available Virtual: 1903.04 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:187.69 GB) (Free:156.28 GB) NTFS
Drive d: (Lenovo) (Fixed) (Total:30.25 GB) (Free:28.5 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: BEC90B8D)
Partition: GPT Partition Type.
==================== End Of Log ============================
Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-04-06 15:40:57
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD25 rev.01.0 232,89GB
Running: k23zf1j3.exe; Driver: C:\Users\Kazuya\AppData\Local\Temp\fxldqpog.sys
---- System - GMER 2.1 ----
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0x8D24FA9C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x8D25057A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0x8D25C5C4]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0x8D25C610]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x8D25C7AA]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0x8D25C532]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateSection [0x8D3066C2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x8D25C57A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0x8D250AB0]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThreadEx [0x8D250CCC]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0x8D25C764]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x8D251368]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x8D24FB02]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0x8D254B3C]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0x8D24F6EE]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0x8D3067A2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x8D24FB68]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x8D254F32]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x8D251E50]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0x8D25C5EE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0x8D25C632]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x8D25C7CE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0x8D25C558]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0x8D254436]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0x8D25C6E2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x8D25C5A2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0x8D25481E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0x8D25C788]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x8D306546]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0x8D251CC4]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThreadEx [0x8D2519D2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x8D24FBCE]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0x8D24FC34]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwSetContextThread [0x8D30689E]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x8D24F788]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x8D24F95A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0x8D24F8E8]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0x8D251532]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0x8D251694]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x8D24F9E2]
SSDT \SystemRoot\system32\drivers\aswSP.sys ZwTerminateProcess [0x8D306614]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0x8D2511C2]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0x8D24FC9A]
SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0x8D2505D6]
---- Kernel code sections - GMER 2.1 ----
.text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 82E8AA15 1 Byte [06]
.text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82EC4212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 82ECB460 4 Bytes [9C, FA, 24, 8D] {PUSHF ; CLI ; AND AL, 0x8d}
.text ntkrnlpa.exe!KeRemoveQueueEx + 1153 82ECB4E8 4 Bytes [7A, 05, 25, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 82ECB53C 8 Bytes [C4, C5, 25, 8D, 10, C6, 25, ...]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 82ECB548 4 Bytes [AA, C7, 25, 8D]
.text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82ECB564 4 Bytes [32, C5, 25, 8D]
.text ...
---- User code sections - GMER 2.1 ----
.text C:\windows\system32\EscSvc.exe[348] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe[388] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\csrss.exe[444] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\wininit.exe[496] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\csrss.exe[504] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text ...
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1392] kernel32.dll!SetUnhandledExceptionFilter 7601F4EB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1392] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\svchost.exe[1512] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\Dwm.exe[1528] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\Explorer.EXE[1540] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\System32\svchost.exe[1604] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text ...
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3108] kernel32.dll!SetUnhandledExceptionFilter 7601F4EB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP }
.text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3108] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\Program Files\Windows Sidebar\sidebar.exe[3124] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\Windows\System32\spool\drivers\w32x86\3\E_FATIJAE.EXE[3144] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\wuauclt.exe[3172] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text C:\windows\system32\wbem\wmiprvse.exe[3624] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62]
.text ...
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002269ec2d88
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002269ec2d88 (not active ControlSet)
---- EOF - GMER 2.1 ----
|
| | #4 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #5 |
| | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Huhu schrauber, habe deine Anweisung ausgeführt. Wie geht es weiter? Liebe Grüße Kazuya Code:
ATTFilter ComboFix 14-04-06.01 - Kazuya 07.04.2014 15:48:37.1.2 - x86
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.985.279 [GMT 2:00]
ausgeführt von:: c:\users\Kazuya\Desktop\ComboFix.exe
AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\users\Kazuya\AppData\Local\Microsoft\Windows\Temporary Internet Files\{4020D4E9-53CC-435F-B76C-F251D0F09E3F}.xps
c:\windows\IsUn0407.exe
c:\windows\security\Database\tmp.edb
c:\program files\AVAST Software\Avast\setup\83a86efa-df02-4a95-90cc-24cf6e129713.exe . . . . Nicht in der Lage zu löschen
.
.
((((((((((((((((((((((( Dateien erstellt von 2014-03-07 bis 2014-04-07 ))))))))))))))))))))))))))))))
.
.
2014-04-06 13:58 . 2014-04-07 13:54 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A28D44C7-5522-4043-B3F8-24309FDB5020}\offreg.dll
2014-04-06 12:28 . 2014-04-06 12:32 -------- d-----w- C:\FRST
2014-04-05 20:42 . 2014-04-05 20:42 -------- d-----w- c:\users\Kazuya\AppData\Local\Macromedia
2014-04-05 19:58 . 2014-04-05 19:58 -------- d-----w- c:\users\Kazuya\AppData\Roaming\AVAST Software
2014-04-05 19:57 . 2014-04-05 19:57 776976 ----a-w- c:\windows\system32\drivers\aswSnx.sys
2014-04-05 19:57 . 2014-04-05 19:57 67264 ----a-w- c:\windows\system32\drivers\aswStm.sys
2014-04-05 19:57 . 2014-04-05 19:57 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys
2014-04-05 19:57 . 2014-04-05 19:57 411552 ----a-w- c:\windows\system32\drivers\aswSP.sys
2014-04-05 19:57 . 2014-04-05 19:57 180760 ----a-w- c:\windows\system32\drivers\aswVmm.sys
2014-04-05 19:57 . 2014-04-05 19:57 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys
2014-04-05 19:57 . 2014-04-05 19:57 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys
2014-04-05 19:57 . 2014-04-05 19:57 271264 ----a-w- c:\windows\system32\aswBoot.exe
2014-04-05 19:57 . 2014-04-05 19:57 43152 ----a-w- c:\windows\avastSS.scr
2014-04-05 19:56 . 2014-04-05 19:56 -------- d-----w- c:\program files\AVAST Software
2014-04-05 19:51 . 2014-04-05 19:51 411552 ----a-w- c:\windows\system32\drivers\rtgdysgh.sys
2014-04-05 19:50 . 2014-04-05 19:50 411552 ----a-w- c:\windows\system32\drivers\ptzlzhni.sys
2014-04-05 19:50 . 2014-04-05 19:54 -------- d-----w- c:\programdata\AVAST Software
2014-04-05 18:28 . 2014-02-06 07:08 7947048 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A28D44C7-5522-4043-B3F8-24309FDB5020}\mpengine.dll
2014-03-25 18:14 . 2014-03-25 18:15 -------- d-----w- c:\program files\Common Files\Adobe
2014-03-16 17:26 . 2014-02-07 01:07 2349056 ----a-w- c:\windows\system32\win32k.sys
2014-03-16 17:26 . 2014-01-29 02:06 381440 ----a-w- c:\windows\system32\wer.dll
2014-03-16 17:26 . 2014-02-04 02:04 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll
2014-03-16 17:26 . 2014-02-04 02:04 509440 ----a-w- c:\windows\system32\qedit.dll
2014-03-16 17:26 . 2014-01-28 02:07 185344 ----a-w- c:\windows\system32\wwansvc.dll
.
.
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2014-04-05 20:16 . 2013-09-24 16:58 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe
2014-04-05 20:16 . 2013-04-07 15:59 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl
.
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast]
@="{472083B0-C522-11CF-8763-00608CC02F24}"
[HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}]
2014-04-05 19:57 260976 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016]
"EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIJAE.EXE" [2012-02-28 249440]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"FUFAXRCV"="c:\program files\Epson Software\FAX Utility\FUFAXRCV.exe" [2012-07-09 502952]
"FUFAXSTM"="c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe" [2012-07-09 863400]
"EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2012-04-02 1058912]
"Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-12-21 959904]
"AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-04-05 3854640]
.
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce]
"WLStart"="c:\program files\Windows Live\Installer\wlstart.exe" [2009-07-26 786760]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Energy Management]
2009-09-29 16:22 5064560 ----a-w- c:\program files\Lenovo\Energy Management\Energy Management.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EnergyUtility]
2009-09-29 16:23 4114288 ----a-w- c:\program files\Lenovo\Energy Management\utility.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds]
2009-09-18 05:35 174104 ----a-w- c:\windows\System32\hkcmd.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif]
2009-06-04 19:03 186904 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray]
2009-09-18 05:35 141848 ----a-w- c:\windows\System32\igfxtray.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileConnect]
2008-07-04 10:52 2072576 ----a-w- c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence]
2009-09-18 05:35 150552 ----a-w- c:\windows\System32\igfxpers.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartAudio]
2009-07-16 05:38 307768 ------w- c:\program files\CONEXANT\SAII\SAIICpl.exe
.
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GShortCut]
2008-12-03 22:15 218408 ------w- c:\program files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe
.
R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-04-05 67264]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-03-01 108032]
R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888]
R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848]
R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x]
R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664]
R3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11792]
R3 WinRing0_1_2_0;WinRing0_1_2_0;d:\test\ECECECEC\WinRing0.sys [x]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 81704]
R4 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\avwebg7.exe [x]
S0 aswRvrt;avast! Revert; [x]
S0 aswVmm;avast! VM Monitor; [x]
S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-04-05 776976]
S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-04-05 411552]
S1 funfrm;funfrm; [x]
S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-04-05 67824]
S2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc.exe [2011-12-11 122000]
S2 LiveUpdateSvc;LiveUpdate;c:\program files\IObit\LiveUpdate\LiveUpdate.exe [2013-12-31 2151744]
S2 VMCService;Vodafone Mobile Connect Service;c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2008-07-04 14336]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2009-05-19 21520]
.
.
--- Andere Dienste/Treiber im Speicher ---
.
*NewlyCreated* - WS2IFSL
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost]
LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc Mcx2Svc
.
Inhalt des "geplante Tasks" Ordners
.
2014-04-07 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-24 20:16]
.
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://www.google.de/
mStart Page = hxxp://www.google.com
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000
TCP: DhcpNameServer = 192.168.2.1
FF - ProfilePath - c:\users\Kazuya\AppData\Roaming\Mozilla\Firefox\Profiles\miuov82a.default-1388595698206\
FF - prefs.js: browser.startup.homepage - www.google.de
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
URLSearchHooks-{8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - (no file)
BHO-{10921475-03CE-4E04-90CE-E2E7EF20C814} - c:\program files\IObit\IObit Uninstaller\UninstallExplorer32.dll
Toolbar-Locked - (no file)
Toolbar-10 - (no file)
WebBrowser-{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} - (no file)
WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file)
WebBrowser-{41564952-412D-5637-00A7-7A786E7484D7} - (no file)
SafeBoot-Wdf01000.sys
SafeBoot-mcmscsvc
SafeBoot-MCODS
MSConfigStartUp-avgnt - c:\program files\Avira\AntiVir Desktop\avgnt.exe
MSConfigStartUp-mobilegeni daemon - c:\program files\Mobogenie\DaemonProcess.exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Weitere laufende Prozesse ------------------------
.
c:\windows\system32\WLANExt.exe
c:\windows\system32\conhost.exe
c:\program files\AVAST Software\Avast\AvastSvc.exe
c:\windows\system32\taskhost.exe
c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe
c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe
c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
c:\windows\servicing\TrustedInstaller.exe
c:\windows\system32\conhost.exe
c:\program files\Windows Media Player\wmpnetwk.exe
c:\windows\system32\sppsvc.exe
c:\program files\AVAST Software\Avast\AvastEmUpdate.exe
.
**************************************************************************
.
Zeit der Fertigstellung: 2014-04-07 16:09:23 - PC wurde neu gestartet
ComboFix-quarantined-files.txt 2014-04-07 14:09
.
Vor Suchlauf: 7 Verzeichnis(se), 167.261.696.000 Bytes frei
Nach Suchlauf: 11 Verzeichnis(se), 169.584.164.864 Bytes frei
.
- - End Of File - - 667DCF8E003166A3E152DCE02DC229CF
A36C5E4F47E84449FF07ED3517B43A31
|
| | #6 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Downloade Dir bitte
Downloade Dir bitte
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet |
| | #7 |
| | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Huhu schrauber, Anweisungen ausgeführt? Check! Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 08.04.2014 Suchlauf-Zeit: 19:42:22 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.08.05 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: Kazuya Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 240872 Verstrichene Zeit: 17 Min, 16 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 08/04/2014 um 19:55:35
# Aktualisiert 01/04/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : Kazuya - KOICHI
# Gestartet von : C:\Users\Kazuya\Desktop\adwcleaner.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
Ordner Gelöscht : C:\Program Files\BrowseSmart
Ordner Gelöscht : C:\Program Files\Mobogenie
Ordner Gelöscht : C:\Users\Kazuya\AppData\Local\Mobogenie
Ordner Gelöscht : C:\Users\Kazuya\AppData\LocalLow\Softonic_Deutsch
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
Schlüssel Gelöscht : HKCU\Software\Classes\iLivid.torrent
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateWebConnect_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateWebConnect_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_download_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_download_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\532de8db538ed43
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D86A75B-CB6B-4764-885D-CA6336F04BA2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F}
Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.16521
-\\ Mozilla Firefox v28.0 (de)
[ Datei : C:\Users\Kazuya\AppData\Roaming\Mozilla\Firefox\Profiles\miuov82a.default-1388595698206\prefs.js ]
*************************
AdwCleaner[R0].txt - [2648 octets] - [08/04/2014 19:54:37]
AdwCleaner[S0].txt - [2577 octets] - [08/04/2014 19:55:35]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2637 octets] ##########
Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.4 (04.06.2014:1)
OS: Windows 7 Home Premium x86
Ran by Kazuya on 08.04.2014 at 20:03:18,11
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 08.04.2014 at 20:07:29,86
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01 (ATTENTION: ====> FRST version is 26 days old and could be outdated)
Ran by Kazuya (administrator) on KOICHI on 08-04-2014 20:13:54
Running from C:\Users\Kazuya\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\windows\System32\lpksetup.exe
(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(Seiko Epson Corporation) C:\windows\system32\EscSvc.exe
(IObit) C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
(SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIJAE.EXE
(Microsoft Corporation) C:\windows\system32\wuauclt.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [FUFAXRCV] - C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe [502952 2012-07-09] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [FUFAXSTM] - C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [863400 2012-07-09] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [EEventManager] - C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1058912 2012-04-02] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-05] (AVAST Software)
HKU\.DEFAULT\...\RunOnce: [WLStart] - C:\Program Files\Windows Live\Installer\wlstart.exe [786760 2009-07-26] (Microsoft Corporation)
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\Run: [EPLTarget\P0000000000000000] - C:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIJAE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Kazuya\AppData\Roaming\Mozilla\Firefox\Profiles\miuov82a.default-1388595698206
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-05]
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-05] (AVAST Software)
R2 EpsonScanSvc; C:\windows\system32\EscSvc.exe [122000 2011-12-12] (Seiko Epson Corporation)
R2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2151744 2013-12-31] (IObit)
S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-07-04] (Vodafone)
S4 AntiVirWebService; "C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe" [X]
==================== Drivers (Whitelisted) ====================
R3 ACPIVPC; C:\windows\System32\DRIVERS\AcpiVpc.sys [21520 2009-05-19] (Lenovo Corporation)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [67824 2014-04-05] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [81768 2014-04-05] (AVAST Software)
R0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49944 2014-04-05] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [776976 2014-04-05] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [411552 2014-04-05] (AVAST Software)
R3 aswStm; C:\windows\system32\drivers\aswStm.sys [67264 2014-04-05] (AVAST Software)
R0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [180760 2014-04-05] ()
R1 funfrm; C:\windows\system32\Drivers\funfrm.sys [54800 2010-02-09] ()
S3 wdmirror; C:\windows\System32\DRIVERS\WDMirror.sys [11792 2009-07-16] (Windows (R) Codename Longhorn DDK provider)
S3 wsvd; C:\windows\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink)
S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X]
U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Kazuya\AppData\Local\Temp\catchme.sys [X]
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
S3 WinRing0_1_2_0; \??\D:\test\ECECECEC\WinRing0.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-08 20:13 - 2014-04-08 20:13 - 00008450 _____ () C:\Users\Kazuya\Desktop\FRST.txt
2014-04-08 20:07 - 2014-04-08 20:07 - 00000626 _____ () C:\Users\Kazuya\Desktop\JRT.txt
2014-04-08 20:01 - 2014-04-08 20:01 - 01016261 _____ (Thisisu) C:\Users\Kazuya\Desktop\JRT.exe
2014-04-08 20:00 - 2014-04-08 20:00 - 00002717 _____ () C:\Users\Kazuya\Desktop\AdwCleaner[S0].txt
2014-04-08 19:54 - 2014-04-08 19:55 - 00000000 ____D () C:\AdwCleaner
2014-04-08 19:53 - 2014-04-08 19:53 - 01426178 _____ () C:\Users\Kazuya\Desktop\adwcleaner.exe
2014-04-08 19:52 - 2014-04-08 19:52 - 00001150 _____ () C:\Users\Kazuya\Desktop\mbam.txt
2014-04-08 19:22 - 2014-04-08 19:25 - 00107736 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-08 19:22 - 2014-04-08 19:22 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware
2014-04-08 19:22 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-04-08 19:22 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-04-08 19:22 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-04-07 15:45 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe
2014-04-07 15:45 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe
2014-04-07 15:45 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-04-07 15:45 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-04-07 15:45 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-04-07 15:45 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe
2014-04-07 15:45 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe
2014-04-07 15:45 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe
2014-04-07 15:44 - 2014-04-07 16:09 - 00000000 ____D () C:\Qoobox
2014-04-07 15:44 - 2014-04-07 16:09 - 00000000 ____D () C:\ComboFix
2014-04-07 15:44 - 2014-04-07 16:08 - 00000000 ____D () C:\windows\erdnt
2014-04-06 16:39 - 2014-04-06 16:39 - 00000000 ____D () C:\Users\Kazuya\Documents\Fax
2014-04-06 15:05 - 2014-04-06 15:05 - 00145256 _____ () C:\windows\Minidump\040614-18579-01.dmp
2014-04-06 15:05 - 2014-04-06 15:05 - 00000000 ____D () C:\windows\Minidump
2014-04-06 15:04 - 2014-04-06 15:04 - 184417329 _____ () C:\windows\MEMORY.DMP
2014-04-06 14:28 - 2014-04-08 20:13 - 00000000 ____D () C:\FRST
2014-04-06 14:23 - 2014-04-06 14:23 - 01145856 _____ (Farbar) C:\Users\Kazuya\Desktop\FRST.exe
2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable
2014-04-06 14:17 - 2014-04-08 20:10 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt
2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia
2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-04-05 22:10 - 2014-04-08 19:57 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software
2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software
2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys
2014-04-05 21:50 - 2014-04-05 21:54 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys
2014-04-05 21:37 - 2014-04-05 21:38 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe
2014-03-31 08:50 - 2014-03-31 08:53 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik Konzeptverkäufer HRO 4 2014.ods
2014-03-25 20:14 - 2014-03-25 20:15 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe
2014-03-16 19:32 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-16 19:32 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-16 19:32 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-03-16 19:32 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-03-16 19:32 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-03-16 19:32 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-03-16 19:32 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-03-16 19:32 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-03-16 19:32 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-03-16 19:32 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-03-16 19:32 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-03-16 19:32 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-03-16 19:32 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-03-16 19:32 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-03-16 19:32 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-03-16 19:32 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-03-16 19:32 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-03-16 19:32 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-03-16 19:32 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-03-16 19:32 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-03-16 19:32 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-03-16 19:32 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-03-16 19:26 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-03-16 19:26 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-03-16 19:26 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-03-16 19:26 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2014-03-16 19:26 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2014-03-11 13:59 - 2014-03-21 23:56 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx
2014-03-11 13:57 - 2014-03-25 20:23 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff
2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx
==================== One Month Modified Files and Folders =======
2014-04-08 20:14 - 2014-04-08 20:13 - 00008450 _____ () C:\Users\Kazuya\Desktop\FRST.txt
2014-04-08 20:13 - 2014-04-06 14:28 - 00000000 ____D () C:\FRST
2014-04-08 20:10 - 2014-04-06 14:17 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt
2014-04-08 20:07 - 2014-04-08 20:07 - 00000626 _____ () C:\Users\Kazuya\Desktop\JRT.txt
2014-04-08 20:06 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-08 20:06 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-08 20:01 - 2014-04-08 20:01 - 01016261 _____ (Thisisu) C:\Users\Kazuya\Desktop\JRT.exe
2014-04-08 20:00 - 2014-04-08 20:00 - 00002717 _____ () C:\Users\Kazuya\Desktop\AdwCleaner[S0].txt
2014-04-08 19:58 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-08 19:58 - 2009-07-14 06:39 - 00113903 _____ () C:\windows\setupact.log
2014-04-08 19:57 - 2014-04-05 22:10 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-08 19:56 - 2010-02-09 10:45 - 02011090 _____ () C:\windows\WindowsUpdate.log
2014-04-08 19:55 - 2014-04-08 19:54 - 00000000 ____D () C:\AdwCleaner
2014-04-08 19:53 - 2014-04-08 19:53 - 01426178 _____ () C:\Users\Kazuya\Desktop\adwcleaner.exe
2014-04-08 19:52 - 2014-04-08 19:52 - 00001150 _____ () C:\Users\Kazuya\Desktop\mbam.txt
2014-04-08 19:25 - 2014-04-08 19:22 - 00107736 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-08 19:22 - 2014-04-08 19:22 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware
2014-04-08 19:22 - 2013-12-31 20:30 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-08 18:51 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\tracing
2014-04-08 00:53 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\FxsTmp
2014-04-07 16:09 - 2014-04-07 15:44 - 00000000 ____D () C:\Qoobox
2014-04-07 16:09 - 2014-04-07 15:44 - 00000000 ____D () C:\ComboFix
2014-04-07 16:09 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2014-04-07 16:09 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-04-07 16:08 - 2014-04-07 15:44 - 00000000 ____D () C:\windows\erdnt
2014-04-07 16:03 - 2009-07-14 04:04 - 00000215 _____ () C:\windows\system.ini
2014-04-07 16:01 - 2010-01-18 19:12 - 00631888 _____ () C:\windows\PFRO.log
2014-04-06 16:39 - 2014-04-06 16:39 - 00000000 ____D () C:\Users\Kazuya\Documents\Fax
2014-04-06 15:05 - 2014-04-06 15:05 - 00145256 _____ () C:\windows\Minidump\040614-18579-01.dmp
2014-04-06 15:05 - 2014-04-06 15:05 - 00000000 ____D () C:\windows\Minidump
2014-04-06 15:04 - 2014-04-06 15:04 - 184417329 _____ () C:\windows\MEMORY.DMP
2014-04-06 14:23 - 2014-04-06 14:23 - 01145856 _____ (Farbar) C:\Users\Kazuya\Desktop\FRST.exe
2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable
2014-04-06 14:20 - 2010-09-08 16:02 - 00000000 ____D () C:\Users\Kazuya
2014-04-06 14:09 - 2013-09-24 19:27 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-04-06 00:41 - 2010-01-18 19:03 - 01765534 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia
2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-04-05 22:16 - 2013-09-24 18:58 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2014-04-05 22:16 - 2013-04-07 17:59 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software
2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software
2014-04-05 21:54 - 2014-04-05 21:50 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys
2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys
2014-04-05 21:48 - 2013-09-28 21:38 - 00000000 ____D () C:\ProgramData\Avira
2014-04-05 21:38 - 2014-04-05 21:37 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe
2014-04-05 20:27 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\wfp
2014-04-05 20:26 - 2011-01-28 17:09 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\vlc
2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\NDF
2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\AppCompat
2014-04-05 20:25 - 2010-01-18 18:57 - 00000000 ___RD () C:\MSOCache
2014-04-05 20:25 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\registration
2014-04-03 09:51 - 2014-04-08 19:22 - 00073432 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-08 19:22 - 00051416 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-08 19:22 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-04-01 01:53 - 2009-07-29 12:50 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-03-31 08:53 - 2014-03-31 08:50 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik 2014.ods
2014-03-26 21:26 - 2013-12-31 19:52 - 00000000 ____D () C:\ProgramData\ProductData
2014-03-25 20:23 - 2014-03-11 13:57 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff
2014-03-25 20:19 - 2010-01-18 19:13 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-25 20:18 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\Adobe
2014-03-25 20:17 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Adobe
2014-03-25 20:15 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe
2014-03-21 23:56 - 2014-03-11 13:59 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx
2014-03-16 19:41 - 2009-07-14 06:33 - 00414320 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-16 19:36 - 2013-09-30 15:36 - 00000000 ____D () C:\windows\system32\MRT
2014-03-16 19:33 - 2013-09-30 15:36 - 87350280 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-03-11 13:59 - 2010-09-13 21:36 - 00000000 ____D () C:\Users\Public\Documents\texte
2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx
Some content of TEMP:
====================
C:\Users\Kazuya\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\windows\explorer.exe => MD5 is legit
C:\windows\system32\winlogon.exe => MD5 is legit
C:\windows\system32\wininit.exe => MD5 is legit
C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\system32\services.exe => MD5 is legit
C:\windows\system32\User32.dll => MD5 is legit
C:\windows\system32\userinit.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit
C:\windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-31 03:14
==================== End Of Log ============================
|
| | #8 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastetESET Online Scanner
Downloade Dir bitte
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #9 |
| | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Huhu schrauber, hier die Log's: Code:
ATTFilter ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=d8d391a628a5b84b8132e9be7f5cbb85
# engine=17823
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-04-09 10:07:42
# local_time=2014-04-10 12:07:42 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=774 16777213 71 74 353413 353431 0 0
# compatibility_mode=5893 16776573 100 94 100126 148712453 0 0
# scanned=115485
# found=0
# cleaned=0
# scan_time=3806
Code:
ATTFilter Results of screen317's Security Check version 0.99.81
Windows 7 Service Pack 1 x86 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
avast! Antivirus
Antivirus up to date! (On Access scanning disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Adobe Flash Player 12.0.0.77
Adobe Reader XI
Mozilla Firefox (28.0)
````````Process Check: objlist.exe by Laurent````````
system32 AvastSvc.exe -?-
AVAST Software Avast AvastUI.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C:
````````````````````End of Log``````````````````````
FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01 (ATTENTION: ====> FRST version is 28 days old and could be outdated)
Ran by Kazuya (administrator) on KOICHI on 10-04-2014 00:12:34
Running from C:\Users\Kazuya\Desktop
Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Microsoft Corporation) C:\windows\system32\WLANExt.exe
(Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe
(SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Seiko Epson Corporation) C:\windows\system32\EscSvc.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(IObit) C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
(Microsoft Corporation) C:\windows\system32\wuauclt.exe
(Intel Corporation) C:\windows\system32\igfxsrvc.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [FUFAXRCV] - C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe [502952 2012-07-09] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [FUFAXSTM] - C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [863400 2012-07-09] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [EEventManager] - C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1058912 2012-04-02] (SEIKO EPSON CORPORATION)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-05] (AVAST Software)
HKU\.DEFAULT\...\RunOnce: [WLStart] - C:\Program Files\Windows Live\Installer\wlstart.exe [786760 2009-07-26] (Microsoft Corporation)
HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\Run: [EPLTarget\P0000000000000000] - C:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIJAE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Kazuya\AppData\Roaming\Mozilla\Firefox\Profiles\miuov82a.default-1388595698206
FF Homepage: www.google.de
FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-05]
========================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-05] (AVAST Software)
R2 EpsonScanSvc; C:\windows\system32\EscSvc.exe [122000 2011-12-12] (Seiko Epson Corporation)
R2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2151744 2013-12-31] (IObit)
S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation)
R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-07-04] (Vodafone)
S4 AntiVirWebService; "C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe" [X]
==================== Drivers (Whitelisted) ====================
R3 ACPIVPC; C:\windows\System32\DRIVERS\AcpiVpc.sys [21520 2009-05-19] (Lenovo Corporation)
R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [67824 2014-04-05] (AVAST Software)
R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [81768 2014-04-05] (AVAST Software)
R0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49944 2014-04-05] ()
R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [776976 2014-04-05] (AVAST Software)
R1 aswSP; C:\windows\system32\drivers\aswSP.sys [411552 2014-04-05] (AVAST Software)
S3 aswStm; C:\windows\system32\drivers\aswStm.sys [67264 2014-04-05] (AVAST Software)
R0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [180760 2014-04-05] ()
R1 funfrm; C:\windows\system32\Drivers\funfrm.sys [54800 2010-02-09] ()
S3 wdmirror; C:\windows\System32\DRIVERS\WDMirror.sys [11792 2009-07-16] (Windows (R) Codename Longhorn DDK provider)
S3 wsvd; C:\windows\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink)
S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X]
U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\Kazuya\AppData\Local\Temp\catchme.sys [X]
S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X]
S3 WinRing0_1_2_0; \??\D:\test\ECECECEC\WinRing0.sys [X]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-04-10 00:12 - 2014-04-10 00:12 - 00008469 _____ () C:\Users\Kazuya\Desktop\FRST.txt
2014-04-10 00:12 - 2014-04-10 00:12 - 00000752 _____ () C:\Users\Kazuya\Desktop\checkup.txt
2014-04-10 00:10 - 2014-04-10 00:10 - 00987448 _____ () C:\Users\Kazuya\Desktop\SecurityCheck.exe
2014-04-09 23:02 - 2014-04-09 23:02 - 00000000 ____D () C:\Program Files\ESET
2014-04-09 22:59 - 2014-04-09 22:59 - 00016384 _____ () C:\windows\system32\Ikeext.etl
2014-04-09 22:55 - 2014-04-09 22:55 - 02347384 _____ (ESET) C:\Users\Kazuya\Desktop\esetsmartinstaller_enu.exe
2014-04-08 19:54 - 2014-04-08 19:55 - 00000000 ____D () C:\AdwCleaner
2014-04-08 19:22 - 2014-04-08 20:34 - 00107736 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-08 19:22 - 2014-04-08 19:22 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware
2014-04-08 19:22 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-04-08 19:22 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-04-08 19:22 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-04-07 15:45 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe
2014-04-07 15:45 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe
2014-04-07 15:45 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe
2014-04-07 15:45 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe
2014-04-07 15:45 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe
2014-04-07 15:45 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe
2014-04-07 15:45 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe
2014-04-07 15:45 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe
2014-04-07 15:44 - 2014-04-07 16:09 - 00000000 ____D () C:\Qoobox
2014-04-07 15:44 - 2014-04-07 16:09 - 00000000 ____D () C:\ComboFix
2014-04-07 15:44 - 2014-04-07 16:08 - 00000000 ____D () C:\windows\erdnt
2014-04-06 16:39 - 2014-04-06 16:39 - 00000000 ____D () C:\Users\Kazuya\Documents\Fax
2014-04-06 15:05 - 2014-04-06 15:05 - 00145256 _____ () C:\windows\Minidump\040614-18579-01.dmp
2014-04-06 15:05 - 2014-04-06 15:05 - 00000000 ____D () C:\windows\Minidump
2014-04-06 15:04 - 2014-04-06 15:04 - 184417329 _____ () C:\windows\MEMORY.DMP
2014-04-06 14:28 - 2014-04-10 00:12 - 00000000 ____D () C:\FRST
2014-04-06 14:23 - 2014-04-06 14:23 - 01145856 _____ (Farbar) C:\Users\Kazuya\Desktop\FRST.exe
2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable
2014-04-06 14:17 - 2014-04-10 00:11 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt
2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia
2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-04-05 22:10 - 2014-04-09 23:57 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software
2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software
2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys
2014-04-05 21:50 - 2014-04-05 21:54 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys
2014-04-05 21:37 - 2014-04-05 21:38 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe
2014-03-31 08:50 - 2014-03-31 08:53 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik 2014.ods
2014-03-25 20:14 - 2014-03-25 20:15 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe
2014-03-16 19:32 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll
2014-03-16 19:32 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb
2014-03-16 19:32 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll
2014-03-16 19:32 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll
2014-03-16 19:32 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll
2014-03-16 19:32 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll
2014-03-16 19:32 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll
2014-03-16 19:32 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll
2014-03-16 19:32 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll
2014-03-16 19:32 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe
2014-03-16 19:32 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe
2014-03-16 19:32 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll
2014-03-16 19:32 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe
2014-03-16 19:32 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe
2014-03-16 19:32 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll
2014-03-16 19:32 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll
2014-03-16 19:32 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll
2014-03-16 19:32 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl
2014-03-16 19:32 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll
2014-03-16 19:32 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll
2014-03-16 19:32 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll
2014-03-16 19:32 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll
2014-03-16 19:26 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys
2014-03-16 19:26 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll
2014-03-16 19:26 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll
2014-03-16 19:26 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll
2014-03-16 19:26 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll
2014-03-11 13:59 - 2014-03-21 23:56 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx
2014-03-11 13:57 - 2014-03-25 20:23 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff
2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx
==================== One Month Modified Files and Folders =======
2014-04-10 00:12 - 2014-04-10 00:12 - 00008469 _____ () C:\Users\Kazuya\Desktop\FRST.txt
2014-04-10 00:12 - 2014-04-10 00:12 - 00000752 _____ () C:\Users\Kazuya\Desktop\checkup.txt
2014-04-10 00:12 - 2014-04-06 14:28 - 00000000 ____D () C:\FRST
2014-04-10 00:11 - 2014-04-06 14:17 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt
2014-04-10 00:10 - 2014-04-10 00:10 - 00987448 _____ () C:\Users\Kazuya\Desktop\SecurityCheck.exe
2014-04-09 23:57 - 2014-04-05 22:10 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job
2014-04-09 23:40 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\tracing
2014-04-09 23:22 - 2010-02-09 10:45 - 02057635 _____ () C:\windows\WindowsUpdate.log
2014-04-09 23:02 - 2014-04-09 23:02 - 00000000 ____D () C:\Program Files\ESET
2014-04-09 22:59 - 2014-04-09 22:59 - 00016384 _____ () C:\windows\system32\Ikeext.etl
2014-04-09 22:55 - 2014-04-09 22:55 - 02347384 _____ (ESET) C:\Users\Kazuya\Desktop\esetsmartinstaller_enu.exe
2014-04-09 22:53 - 2009-07-14 06:39 - 00114105 _____ () C:\windows\setupact.log
2014-04-09 22:51 - 2010-01-18 19:03 - 01765534 _____ () C:\windows\system32\PerfStringBackup.INI
2014-04-09 22:41 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-09 22:41 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-09 22:34 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT
2014-04-09 01:01 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\FxsTmp
2014-04-08 20:34 - 2014-04-08 19:22 - 00107736 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys
2014-04-08 19:55 - 2014-04-08 19:54 - 00000000 ____D () C:\AdwCleaner
2014-04-08 19:22 - 2014-04-08 19:22 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware
2014-04-08 19:22 - 2013-12-31 20:30 - 00000000 ____D () C:\ProgramData\Malwarebytes
2014-04-07 16:09 - 2014-04-07 15:44 - 00000000 ____D () C:\Qoobox
2014-04-07 16:09 - 2014-04-07 15:44 - 00000000 ____D () C:\ComboFix
2014-04-07 16:09 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default
2014-04-07 16:09 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public
2014-04-07 16:08 - 2014-04-07 15:44 - 00000000 ____D () C:\windows\erdnt
2014-04-07 16:03 - 2009-07-14 04:04 - 00000215 _____ () C:\windows\system.ini
2014-04-07 16:01 - 2010-01-18 19:12 - 00631888 _____ () C:\windows\PFRO.log
2014-04-06 16:39 - 2014-04-06 16:39 - 00000000 ____D () C:\Users\Kazuya\Documents\Fax
2014-04-06 15:05 - 2014-04-06 15:05 - 00145256 _____ () C:\windows\Minidump\040614-18579-01.dmp
2014-04-06 15:05 - 2014-04-06 15:05 - 00000000 ____D () C:\windows\Minidump
2014-04-06 15:04 - 2014-04-06 15:04 - 184417329 _____ () C:\windows\MEMORY.DMP
2014-04-06 14:23 - 2014-04-06 14:23 - 01145856 _____ (Farbar) C:\Users\Kazuya\Desktop\FRST.exe
2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable
2014-04-06 14:20 - 2010-09-08 16:02 - 00000000 ____D () C:\Users\Kazuya
2014-04-06 14:09 - 2013-09-24 19:27 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia
2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk
2014-04-05 22:16 - 2013-09-24 18:58 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe
2014-04-05 22:16 - 2013-04-07 17:59 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl
2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software
2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe
2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys
2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr
2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software
2014-04-05 21:54 - 2014-04-05 21:50 - 00000000 ____D () C:\ProgramData\AVAST Software
2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys
2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys
2014-04-05 21:48 - 2013-09-28 21:38 - 00000000 ____D () C:\ProgramData\Avira
2014-04-05 21:38 - 2014-04-05 21:37 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe
2014-04-05 20:27 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\wfp
2014-04-05 20:26 - 2011-01-28 17:09 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\vlc
2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\NDF
2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\AppCompat
2014-04-05 20:25 - 2010-01-18 18:57 - 00000000 ___RD () C:\MSOCache
2014-04-05 20:25 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\registration
2014-04-03 09:51 - 2014-04-08 19:22 - 00073432 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys
2014-04-03 09:51 - 2014-04-08 19:22 - 00051416 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys
2014-04-03 09:50 - 2014-04-08 19:22 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys
2014-04-01 01:53 - 2009-07-29 12:50 - 00000000 ___RD () C:\Users\Public\Recorded TV
2014-03-31 08:53 - 2014-03-31 08:50 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik 2014.ods
2014-03-26 21:26 - 2013-12-31 19:52 - 00000000 ____D () C:\ProgramData\ProductData
2014-03-25 20:23 - 2014-03-11 13:57 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff
2014-03-25 20:19 - 2010-01-18 19:13 - 00000000 ____D () C:\ProgramData\Adobe
2014-03-25 20:18 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\Adobe
2014-03-25 20:17 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Adobe
2014-03-25 20:15 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Common Files\Adobe
2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe
2014-03-21 23:56 - 2014-03-11 13:59 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx
2014-03-16 19:41 - 2009-07-14 06:33 - 00414320 _____ () C:\windows\system32\FNTCACHE.DAT
2014-03-16 19:36 - 2013-09-30 15:36 - 00000000 ____D () C:\windows\system32\MRT
2014-03-16 19:33 - 2013-09-30 15:36 - 87350280 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe
2014-03-11 13:59 - 2010-09-13 21:36 - 00000000 ____D () C:\Users\Public\Documents\texte
2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx
Some content of TEMP:
====================
C:\Users\Kazuya\AppData\Local\temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\windows\explorer.exe => MD5 is legit
C:\windows\system32\winlogon.exe => MD5 is legit
C:\windows\system32\wininit.exe => MD5 is legit
C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\system32\services.exe => MD5 is legit
C:\windows\system32\User32.dll => MD5 is legit
C:\windows\system32\userinit.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit
C:\windows\system32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-03-31 03:14
==================== End Of Log ============================
--- --- --- Das war es schon?^^ Hmm.. Auslastung des Arbeitsspeichers nur noch mit Mozilla um die 80 %. Das ist wohl normal. (Ohne irgend ein Programm geöffnet zu haben, 50 % Auslastung) IE öffnet keine Links mehr, aber den Explorer brauche ich eh nicht. Seit dem vorletzten Suchlauf stürzt Shockwave hin und wieder ab, aber mit F5 ist es wieder gut. Copy / Paste funktioniert wieder im Mozilla. Ordentlich bereinigt wurde mein Laptop ja nun auch und ungewöhnliche "Macken", wie disconnect / keine Verbindung zum Internet möglich; treten nicht mehr auf. Also vielen vielen Dank für deine Mühen und deinen Einsatz. Erscheint die Lösung einfach, kam Hilfe vom Profi! Danke Liebe Grüße Kazuya Geändert von Kazuya (10.04.2014 um 11:11 Uhr) |
| | #10 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Setze folgendermassen den Internet Explorer zurück:
Fertig ![]() Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun ![]() Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #11 |
| | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Huhu schrauber, vielen Dank für deine Tips und Hinweise. Habe dank dir viel dazu gelernt und kann mich nun sicherer im Internet bewegen ![]() Für mich sind definitiv alle Fragen beantwortet, du hast mir sehr geholfen. Liebe Grüße Kazuya |
| | #12 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |
| Themen zu Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet |
| abgesicherten, arbeitsspeicher, ausgelastet, automatisch, avast, avira, einfügen, erstell, erstellt, files, firefox, funktioniert, google, heute, infiziert, kopieren, lieber, log's, modus, mozilla, nichts, pc infiziert, programme, software, suchfunktion, windows, windows 7 |