![]() |
|
Log-Analyse und Auswertung: Über Nacht: Kein ereignisprotokoll, keine Internetverbindung, PC sehr langsam nach AnmeldungWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Über Nacht: Kein ereignisprotokoll, keine Internetverbindung, PC sehr langsam nach Anmeldung Hallo zusammen, ich versuche nun schon seit 3 Wochen meinen Rechner zu reparieren, leider zwecklos trotz Google und diversen Foren. Deshalb probiere ich nun mal selbst ein Thema zu eröffnen in der Hoffnung, dass ich mal einen Schritt vorwärts mache. Zum Problem: Ich hatte versehentlich meinen Rechner über Nacht laufen lassen, da ich u.a. ein Backup meines Samsung Handys durchgeführt hatte. Am nächsten Morgen bemerkte ich beim Herunterfahren des Rechners, dass er extrem lange benötigt. Fahre ich den Rechner hoch läuft alles Problemlos bis nach der Anmeldung als Admin-Benutzer. Ab hier geht alles sehr langsam (Rechner braucht sehr lange bis der Startbildschirm bzw. Desktop erscheint). Des Weiteren habe ich keine Internetverbindung mehr. Folgende Meldung poppt u.a. auf: Es konnte keine Verbindung mit einem Windows-Dienst hergestellt (das ist die Überschrift) Es konnte keine Verbindung mit dem Dienst "Benachrichtigungsdienst für Systemereignisse" hergestellt werden. Daher können sich Standardnutzer nicht am System anmelden. Wenn Sie Administrator sind, finden Sie weitere Details zu diesem Fehler im systemere Sobald ich die Maus bewege verschwindet die Meldung. Später habe ich noch herausgefunden, dass das Ereignisprotokoll nicht aktiviert ist. Auch durch vieles und langes googeln konnte ich das Ereignisprotokoll nicht aktivieren. Im abgesicherten Modus läuft der Rechner aber auch hier keine Internetverbindung und kein Erreignisprotokoll Ich habe sfc scans durchgeführt -> nichts gefunden Anti-Malware scan -> hat ca. 10 Dateien gefunden die ich bereits gelöscht habe G-Data start-scan -> nichts gefunden (mittlerweile habe ich GData deinstalliert da ich dachte das Programm blockiert irgendetwas Trojan-Remover scan: hat einen Trojaner gefunden (bereits gelöscht) HijackThis scan: LogFile liegt vor falls benötigt Win7 Reparatur mit DVD durchgeführt -> fehlgeschlagen, ohne Internet Verbindung schwierig da nicht aktuelle Version Reparaturversuch mit Win7 Möglichkeiten (F8) -> kein erfolg Gmer.txt log file ist leer, deshalb nicht gepostet Ich hoffe mir kann jemand weiterhelfen. Bin um jeden Rat dankbar. defogger_disable.txt Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 21:19 on 29/07/2014 (sauterch) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-07-2014 Ran by sauterch (administrator) on SAUTERCH-PC on 29-07-2014 20:33:17 Running from N:\ Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 Boot Mode: Safe Mode (minimal) The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap64.dll,ShadowPlayOnSystemStart HKLM-x32\...\Run: [IMSS] => C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IMSS\PIconStartup.exe [111640 2009-09-30] () HKLM-x32\...\runonceex: [ContentMerger] => C:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\ContentMerger10.exe [19952 2009-06-26] (Sonic Solutions) Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.) HKU\.DEFAULT\...\Run: [GarminExpressTrayApp] => D:\Garmin\Express Tray\ExpressTray.exe [122200 2014-06-09] (Garmin Ltd or its subsidiaries) HKU\S-1-5-19\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\S-1-5-20\...\RunOnce: [mctadmin] => C:\Windows\System32\mctadmin.exe [97280 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-2386147833-3081857437-1213626127-1000\...\Run: [ctfmon.exe] => C:\Windows\system32\ctfmon.exe [9728 2009-07-14] (Microsoft Corporation) HKU\S-1-5-21-2386147833-3081857437-1213626127-1000\...\Run: [AVMUSBFernanschluss] => "C:\Users\sauterch\AppData\Local\Apps\2.0\N7JC67JJ.28D\EXZ09BGP.07J\frit..tion_1acae14e4778b8d2_0002 (the data entry has 41 more characters). HKU\S-1-5-21-2386147833-3081857437-1213626127-1000\...\Policies\Explorer: [NoRecentDocsHistory] 1 HKU\S-1-5-21-2386147833-3081857437-1213626127-1000\...\Policies\Explorer: [NoRecentDocsMenu] 1 ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.my-online-search.com/?babsrc=HP_ofln&mntrId=D840ED1AFF0F1A72&cat=delta&dlb=0&affID=122471 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x618CF0B50BFACD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKCU - DefaultScope {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p24_serp_ie_de_display?ie=UTF8&tagbase=bds-p24&tag=bds-p24-serp-de-ie-21&tbrId=v1_abb-channel-24_4bd9705f7ce34286b66d3eda149032da_39_1007_20130820_DE_ie_ds_&query={searchTerms} SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.my-online-search.com/?q={searchTerms}&babsrc=SP_ofln&mntrId=D840ED1AFF0F1A72&cat=delta&dlb=0&affID=122471 SearchScopes: HKCU - {B3B3A6AC-74EC-BD56-BCDB-EFA4799FB9DF} URL = hxxp://www.amazon.de/gp/bit/amazonserp/ref=bit_bds-p24_serp_ie_de_display?ie=UTF8&tagbase=bds-p24&tag=bds-p24-serp-de-ie-21&tbrId=v1_abb-channel-24_4bd9705f7ce34286b66d3eda149032da_39_1007_20130820_DE_ie_ds_&query={searchTerms} SearchScopes: HKCU - {C1712D6F-212C-4935-9DA4-A11FDD428DAB} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=827316&p={searchTerms} BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> D:\Java\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> D:\Java\bin\jp2ssv.dll (Oracle Corporation) DPF: HKLM-x32 {49312E18-AA92-4CC2-BB97-55DEA7BCADD6} https://support.dell.com/systemprofiler/SysProExe.CAB DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 05 %ProgramFiles(x86)%\FRITZ!DSL\\sarah.dll File Not found () Winsock: Missing Catalog5-x64 entry, broken internet access. <===== ATTENTION. Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\sauterch\AppData\Roaming\Mozilla\Firefox\Profiles\yzhn2xac.default FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_14_0_0_125.dll () FF Plugin: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - D:\PDF_XChange Viewer\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - D:\PDF_XChange Viewer\Tracker Software\PDF Viewer\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_14_0_0_125.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - D:\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - D:\PDF_XChange Viewer\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - D:\Picasa\Picasa3\npPicasa3.dll (Google, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.55.2 - D:\Java\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.55.2 - D:\Java\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=16.4.3503.0728 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nullsoft.com/winampDetector;version=1 - D:\Winamp Detect\npwachk.dll (Nullsoft, Inc.) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tracker-software.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - D:\PDF_XChange Viewer\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF Plugin-x32: @videolan.org/vlc,version=2.1.0 - D:\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - D:\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: PDF Architect 2 - C:\Program Files (x86)\PDF Architect 2\np-previewer.dll (pdfforge GmbH) FF Plugin HKCU: @docu-track.com/PDF-XChange Viewer Plugin,version=1.0,application/pdf - D:\PDF_XChange Viewer\Tracker Software\PDF Viewer\Win32\npPDFXCviewNPPlugin.dll (Tracker Software Products Ltd.) FF user.js: detected! => C:\Users\sauterch\AppData\Roaming\Mozilla\Firefox\Profiles\yzhn2xac.default\user.js FF SearchPlugin: C:\Users\sauterch\AppData\Roaming\Mozilla\Firefox\Profiles\yzhn2xac.default\searchplugins\amazon.xml FF Extension: ProxTube - Unblock YouTube - C:\Users\sauterch\AppData\Roaming\Mozilla\Firefox\Profiles\yzhn2xac.default\Extensions\ich@maltegoetz.de [2013-12-30] FF Extension: Garmin Communicator - C:\Users\sauterch\AppData\Roaming\Mozilla\Firefox\Profiles\yzhn2xac.default\Extensions\{195A3098-0BD5-4e90-AE22-BA1C540AFD1E} [2014-05-13] FF Extension: Add-on Compatibility Reporter - C:\Users\sauterch\AppData\Roaming\Mozilla\Firefox\Profiles\yzhn2xac.default\Extensions\compatibility@addons.mozilla.org.xpi [2011-11-10] FF Extension: Session Manager - C:\Users\sauterch\AppData\Roaming\Mozilla\Firefox\Profiles\yzhn2xac.default\Extensions\{1280606b-2510-4fe0-97ef-9b5a22eafe30}.xpi [2013-08-22] FF Extension: Adblock Plus - C:\Users\sauterch\AppData\Roaming\Mozilla\Firefox\Profiles\yzhn2xac.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2011-03-28] FF Extension: Tab Mix Plus - C:\Users\sauterch\AppData\Roaming\Mozilla\Firefox\Profiles\yzhn2xac.default\Extensions\{dc572301-7619-498c-a57d-39143191b318}.xpi [2011-05-11] FF StartMenuInternet: FIREFOX.EXE - D:\Mozilla Firefox\firefox.exe ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) ATTENTION: => Could not perform signature verification. Cryptographic Service is not running. S2 AAV UpdateService; D:\Steuer-Spar-Erklaerung\AAVUpdateManager\aavus.exe [128296 2008-10-24] () S2 CLKMSVC10_C19A2874; D:\Cyberlink PowerDVD\PowerDVD9\NavFilter\kmsvc.exe [247768 2013-04-03] (CyberLink) S2 Garmin Core Update Service; D:\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [435032 2014-06-09] (Garmin Ltd or its subsidiaries) S2 IGDCTRL; C:\Program Files\FRITZ!DSL\IGDCTRL.EXE [88888 2009-07-28] (AVM Berlin) S2 NvNetworkService; C:\Program Files (x86)\NVIDIA Corporation\NetService\NvNetworkService.exe [1631008 2014-05-30] (NVIDIA Corporation) S2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [21055432 2014-05-30] (NVIDIA Corporation) S3 PDF Architect 2; C:\Program Files (x86)\PDF Architect 2\ws.exe [1716264 2014-04-30] (pdfforge GmbH) S3 pdfforge CrashHandler; C:\Program Files (x86)\PDF Architect 2\crash-handler-ws.exe [861736 2014-04-30] (pdfforge GmbH) S2 SkypeUpdate; D:\Skype\Updater\Updater.exe [172192 2013-10-23] (Skype Technologies) S2 TuneUp.UtilitiesSvc; D:\TuneUp Utilities 2011\TuneUpUtilitiesService64.exe [2028864 2011-12-13] (TuneUp Software) S2 SessionLauncher; C:\Users\sauterch\AppData\Local\Temp\DX9\SessionLauncher.exe [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 avmaudio; C:\Windows\System32\DRIVERS\avmaudio.sys [116096 2011-01-08] (AVM Berlin) S3 avmaura; C:\Windows\System32\DRIVERS\avmaura.sys [116480 2012-12-22] (AVM Berlin) S3 FsUsbExDisk; C:\Windows\SysWOW64\FsUsbExDisk.SYS [37344 2013-02-05] () S3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [62368 2013-01-08] (G Data Software AG) S3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20256 2014-05-30] (NVIDIA Corporation) S3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [40392 2014-03-31] (NVIDIA Corporation) S1 RxFilter; C:\Windows\SysWOW64\DRIVERS\RxFilter.sys [65520 2009-06-26] (Sonic Solutions) S3 TuneUpUtilitiesDrv; D:\TuneUp Utilities 2011\TuneUpUtilitiesDriver64.sys [11856 2010-11-29] (TuneUp Software) U5 UnlockerDriver5; D:\Unlocker\UnlockerDriver5.sys [12352 2010-07-01] () ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2014-07-29 20:30 - 2014-07-29 20:30 - 00000000 _____ () C:\Users\sauterch\Desktop\Gmer.txt 2014-07-29 20:10 - 2014-07-29 20:33 - 00000000 ___DC () C:\FRST 2014-07-29 20:08 - 2014-07-29 20:08 - 00000000 _____ () C:\Users\sauterch\defogger_reenable 2014-07-29 18:13 - 2014-07-29 18:13 - 00009034 _____ () C:\Users\sauterch\Desktop\E597QJAQ.log 2014-07-29 07:12 - 2014-07-29 07:12 - 00074720 _____ () C:\Users\sauterch\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-29 07:12 - 2014-07-29 07:12 - 00000000 ____D () C:\Users\sauterch\AppData\Local\Deployment 2014-07-25 21:30 - 2014-07-25 21:31 - 00010029 _____ () C:\Users\sauterch\Desktop\hijackthis.log 2014-07-24 22:20 - 2009-06-10 23:00 - 00000824 _____ () C:\Windows\system32\Drivers\etc\hosts.trb 2014-07-22 20:08 - 2014-07-22 20:08 - 00000000 ___DC () C:\bootmedium 2014-07-22 19:58 - 2014-07-23 17:44 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-22 19:57 - 2014-07-22 19:57 - 00000622 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-22 19:57 - 2014-07-22 19:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-22 19:57 - 2014-05-12 07:26 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-07-22 19:57 - 2014-05-12 07:26 - 00063704 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-07-22 19:57 - 2014-05-12 07:25 - 00025816 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-07-22 19:55 - 2014-07-22 19:55 - 00388608 _____ (Trend Micro Inc.) C:\Users\sauterch\Desktop\HiJackThis204.exe 2014-07-22 19:40 - 2014-07-22 19:57 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-22 19:40 - 2014-07-22 19:40 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-07-20 13:41 - 2014-03-04 13:32 - 00599840 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvStreaming.exe 2014-07-20 13:39 - 2014-03-04 16:35 - 31474976 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 25255256 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 23716640 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 18302384 _____ (NVIDIA Corporation) C:\Windows\system32\nvwgf2umx.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 17755424 _____ (NVIDIA Corporation) C:\Windows\system32\nvd3dumx.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 17561544 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 15783992 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvwgf2um.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 14709720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvd3dum.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 12708128 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2014-07-20 13:39 - 2014-03-04 16:35 - 11636176 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 11589272 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 09728064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 09690424 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvopencl.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 03143456 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 03093280 _____ (NVIDIA Corporation) C:\Windows\system32\nvapi64.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 02958792 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 02783008 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 02715264 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvapi.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 02411976 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 00947808 _____ (NVIDIA Corporation) C:\Windows\system32\nvumdshimx.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 00892704 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 00877856 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 00863064 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 00846168 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 00832936 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvumdshim.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 00353504 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglshim64.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 00305600 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglshim32.dll 2014-07-20 13:39 - 2014-03-04 16:35 - 00174296 _____ (NVIDIA Corporation) C:\Windows\system32\nvinitx.dll 2014-07-20 11:40 - 2014-05-20 04:44 - 01889112 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433788.dll 2014-07-20 11:40 - 2014-05-20 04:44 - 01541576 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433788.dll 2014-07-20 01:30 - 2014-03-04 16:35 - 00062408 _____ (Khronos Group) C:\Windows\system32\OpenCL.dll 2014-07-20 01:30 - 2014-03-04 16:35 - 00054216 _____ (Khronos Group) C:\Windows\SysWOW64\OpenCL.dll 2014-07-20 01:29 - 2013-11-28 15:38 - 00197408 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2014-07-20 01:29 - 2013-11-28 15:38 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2014-07-19 22:00 - 2014-03-04 15:06 - 06714312 _____ (NVIDIA Corporation) C:\Windows\system32\nvcpl.dll 2014-07-19 22:00 - 2014-03-04 15:06 - 03497816 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvc64.dll 2014-07-19 22:00 - 2014-03-04 15:05 - 03649185 _____ () C:\Windows\system32\nvcoproc.bin 2014-07-19 22:00 - 2014-03-04 15:05 - 02558808 _____ (NVIDIA Corporation) C:\Windows\system32\nvsvcr.dll 2014-07-19 22:00 - 2014-03-04 15:05 - 00922968 _____ (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe 2014-07-19 22:00 - 2014-03-04 15:05 - 00386336 _____ (NVIDIA Corporation) C:\Windows\system32\nvmctray.dll 2014-07-19 22:00 - 2014-03-04 15:05 - 00064968 _____ (NVIDIA Corporation) C:\Windows\system32\nvshext.dll 2014-07-19 21:01 - 2014-03-04 16:35 - 01885472 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6433523.dll 2014-07-19 21:01 - 2014-03-04 16:35 - 01516488 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6433523.dll 2014-07-19 13:24 - 2009-08-15 11:44 - 00008494 _____ () C:\Users\sauterch\Desktop\[1].xml 2014-07-19 13:02 - 2014-07-19 13:02 - 00000000 ____D () C:\Windows\8A809006C25A4A3A9DAB94659BCDB107.TMP 2014-07-19 12:57 - 2014-07-19 12:57 - 00000000 ___DC () C:\NVIDIA 2014-07-19 12:57 - 2010-06-22 00:07 - 00255592 _____ (NVIDIA Corporation) C:\Windows\system32\nvcohda6.dll 2014-07-19 12:47 - 2010-08-06 11:27 - 00314984 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvdecodemft.dll 2014-07-17 20:42 - 2014-07-17 20:42 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\Apple Computer 2014-07-15 19:15 - 2014-07-24 22:47 - 00022958 _____ () C:\Windows\PFRO.log 2014-07-13 15:48 - 2014-07-25 22:06 - 00029955 _____ () C:\Windows\diagwrn.xml 2014-07-13 15:48 - 2014-07-25 22:03 - 00001890 _____ () C:\Windows\diagerr.xml 2014-07-13 11:26 - 2014-07-13 11:26 - 00000553 _____ () C:\Users\sauterch\Desktop\Start Unlocker.lnk 2014-07-12 16:36 - 2014-07-12 16:36 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker 2014-07-12 16:36 - 2014-07-12 16:36 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\Babylon 2014-07-12 16:36 - 2014-07-12 16:36 - 00000000 ____D () C:\ProgramData\Babylon 2014-07-12 12:10 - 2014-07-25 17:44 - 00049635 _____ () C:\Windows\avmacc.log 2014-07-11 20:08 - 2014-07-11 20:08 - 00000200 _____ () C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2011.job 2014-07-11 20:06 - 2014-07-12 14:38 - 00002512 _____ () C:\Windows\LkmdfCoInst.log 2014-07-10 22:27 - 2014-07-10 22:27 - 00016648 ____C () C:\bootsqm.dat 2014-07-08 20:45 - 2014-07-25 22:20 - 00006620 _____ () C:\Users\sauterch\Desktop\Windows Compatibility Report.htm 2014-07-07 17:25 - 2014-07-29 07:12 - 00013370 _____ () C:\Windows\setupact.log 2014-07-03 22:12 - 2014-07-03 22:12 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Control Center 2014-07-03 20:15 - 2014-07-03 20:15 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_netaapl64_01009.Wdf 2014-07-03 20:12 - 2014-07-12 05:59 - 00000000 ____D () C:\Users\sauterch\Documents\Audible 2014-07-03 20:12 - 2014-07-03 20:45 - 00000000 ____D () C:\Program Files (x86)\Audible 2014-06-29 15:36 - 2014-06-29 15:36 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\pdfforge_GmbH 2014-06-29 15:36 - 2014-06-29 15:36 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\PDF Architect 2 ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2014-07-29 20:33 - 2014-07-29 20:10 - 00000000 ___DC () C:\FRST 2014-07-29 20:30 - 2014-07-29 20:30 - 00000000 _____ () C:\Users\sauterch\Desktop\Gmer.txt 2014-07-29 20:08 - 2014-07-29 20:08 - 00000000 _____ () C:\Users\sauterch\defogger_reenable 2014-07-29 20:08 - 2010-12-30 22:36 - 00000000 ____D () C:\Users\sauterch 2014-07-29 18:13 - 2014-07-29 18:13 - 00009034 _____ () C:\Users\sauterch\Desktop\E597QJAQ.log 2014-07-29 18:11 - 2011-01-03 17:48 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\vlc 2014-07-29 08:19 - 2010-12-30 22:28 - 01067859 _____ () C:\Windows\WindowsUpdate.log 2014-07-29 08:04 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-07-29 08:04 - 2009-07-14 06:45 - 00014016 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-07-29 07:12 - 2014-07-29 07:12 - 00074720 _____ () C:\Users\sauterch\AppData\Local\GDIPFONTCACHEV1.DAT 2014-07-29 07:12 - 2014-07-29 07:12 - 00000000 ____D () C:\Users\sauterch\AppData\Local\Deployment 2014-07-29 07:12 - 2014-07-07 17:25 - 00013370 _____ () C:\Windows\setupact.log 2014-07-29 07:12 - 2011-01-06 12:19 - 00000000 ____D () C:\Users\sauterch\AppData\Local\Apps\2.0 2014-07-29 07:09 - 2010-12-31 12:47 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-07-25 22:20 - 2014-07-08 20:45 - 00006620 _____ () C:\Users\sauterch\Desktop\Windows Compatibility Report.htm 2014-07-25 22:06 - 2014-07-13 15:48 - 00029955 _____ () C:\Windows\diagwrn.xml 2014-07-25 22:03 - 2014-07-13 15:48 - 00001890 _____ () C:\Windows\diagerr.xml 2014-07-25 22:03 - 2014-04-07 06:57 - 00000000 _____ () C:\Windows\setuperr.log 2014-07-25 21:31 - 2014-07-25 21:30 - 00010029 _____ () C:\Users\sauterch\Desktop\hijackthis.log 2014-07-25 17:44 - 2014-07-12 12:10 - 00049635 _____ () C:\Windows\avmacc.log 2014-07-24 22:47 - 2014-07-15 19:15 - 00022958 _____ () C:\Windows\PFRO.log 2014-07-24 22:15 - 2011-01-06 13:02 - 00000000 ____D () C:\ProgramData\Temp 2014-07-23 17:44 - 2014-07-22 19:58 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-07-23 17:30 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\AppCompat 2014-07-22 20:28 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Branding 2014-07-22 20:08 - 2014-07-22 20:08 - 00000000 ___DC () C:\bootmedium 2014-07-22 19:57 - 2014-07-22 19:57 - 00000622 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-07-22 19:57 - 2014-07-22 19:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-07-22 19:57 - 2014-07-22 19:40 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-07-22 19:55 - 2014-07-22 19:55 - 00388608 _____ (Trend Micro Inc.) C:\Users\sauterch\Desktop\HiJackThis204.exe 2014-07-22 19:40 - 2014-07-22 19:40 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-07-20 13:54 - 2013-09-09 22:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation 2014-07-20 13:41 - 2013-03-09 22:47 - 00000000 ____D () C:\Program Files (x86)\NVIDIA Corporation 2014-07-19 22:00 - 2010-12-31 12:45 - 00000000 ____D () C:\Program Files\NVIDIA Corporation 2014-07-19 22:00 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\Help 2014-07-19 21:59 - 2011-12-10 18:36 - 00000000 ____D () C:\Temp 2014-07-19 13:02 - 2014-07-19 13:02 - 00000000 ____D () C:\Windows\8A809006C25A4A3A9DAB94659BCDB107.TMP 2014-07-19 12:57 - 2014-07-19 12:57 - 00000000 ___DC () C:\NVIDIA 2014-07-19 11:56 - 2010-12-31 07:23 - 00699868 _____ () C:\Windows\system32\perfh007.dat 2014-07-19 11:56 - 2010-12-31 07:23 - 00149750 _____ () C:\Windows\system32\perfc007.dat 2014-07-19 11:56 - 2009-07-14 07:13 - 01622164 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-07-19 11:54 - 2011-01-06 13:57 - 00000000 ____D () C:\ProgramData\InstallShield 2014-07-19 11:54 - 2011-01-06 12:58 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2014-07-19 11:54 - 2010-12-31 12:38 - 00000000 ____D () C:\Program Files (x86)\Intel 2014-07-17 20:42 - 2014-07-17 20:42 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\Apple Computer 2014-07-17 20:23 - 2010-12-31 19:38 - 00000000 ____D () C:\Windows\pss 2014-07-15 21:24 - 2013-10-20 18:23 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Screenomania 2014-07-15 21:24 - 2013-10-20 13:25 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Java Development Kit 2014-07-15 19:15 - 2010-12-31 12:24 - 00000000 ____D () C:\ProgramData\G DATA 2014-07-13 11:26 - 2014-07-13 11:26 - 00000553 _____ () C:\Users\sauterch\Desktop\Start Unlocker.lnk 2014-07-12 16:36 - 2014-07-12 16:36 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Unlocker 2014-07-12 16:36 - 2014-07-12 16:36 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\Babylon 2014-07-12 16:36 - 2014-07-12 16:36 - 00000000 ____D () C:\ProgramData\Babylon 2014-07-12 14:38 - 2014-07-11 20:06 - 00002512 _____ () C:\Windows\LkmdfCoInst.log 2014-07-12 14:36 - 2011-01-06 21:30 - 00018960 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2014-07-12 05:59 - 2014-07-03 20:12 - 00000000 ____D () C:\Users\sauterch\Documents\Audible 2014-07-12 05:59 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\NDF 2014-07-12 05:59 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-07-11 20:08 - 2014-07-11 20:08 - 00000200 _____ () C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2011.job 2014-07-10 22:27 - 2014-07-10 22:27 - 00016648 ____C () C:\bootsqm.dat 2014-07-07 21:47 - 2014-05-19 22:35 - 00001114 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-07-07 21:25 - 2013-10-14 19:49 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-07-07 18:35 - 2014-05-19 22:35 - 00001110 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-07-07 17:31 - 2011-11-02 20:35 - 01366861 _____ () C:\Windows\SysWOW64\sig.bin 2014-07-07 17:31 - 2011-11-02 20:35 - 00064099 _____ () C:\Windows\SysWOW64\nmp.map 2014-07-07 17:28 - 2011-01-03 17:46 - 00003954 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{E65FAF42-D005-4209-8259-34AE0371B7A1} 2014-07-07 17:25 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-07-06 17:39 - 2013-08-11 19:39 - 00000000 ____D () C:\Windows\Minidump 2014-07-03 22:12 - 2014-07-03 22:12 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CopyTrans Control Center 2014-07-03 22:12 - 2014-02-14 12:02 - 00001343 _____ () C:\Users\sauterch\Desktop\CopyTrans Control Center.lnk 2014-07-03 20:45 - 2014-07-03 20:12 - 00000000 ____D () C:\Program Files (x86)\Audible 2014-07-03 20:15 - 2014-07-03 20:15 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_Kernel_netaapl64_01009.Wdf 2014-06-29 15:36 - 2014-06-29 15:36 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\pdfforge_GmbH 2014-06-29 15:36 - 2014-06-29 15:36 - 00000000 ____D () C:\Users\sauterch\AppData\Roaming\PDF Architect 2 2014-06-29 12:42 - 2014-05-19 22:35 - 00004110 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-06-29 12:42 - 2014-05-19 22:35 - 00003858 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore Files to move or delete: ==================== C:\Users\Public\AlexaNSISPlugin.1072.dll Some content of TEMP: ==================== C:\Users\sauterch\AppData\Local\Temp\AudibleDM_iTunesSetup(1).exe C:\Users\sauterch\AppData\Local\Temp\AudibleDM_iTunesSetup.exe C:\Users\sauterch\AppData\Local\Temp\nvStInst.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-06-29 16:49 ==================== End Of Log ============================ |
Themen zu Über Nacht: Kein ereignisprotokoll, keine Internetverbindung, PC sehr langsam nach Anmeldung |
benachrichtigungsdienst, bildschirm, blockiert, desktop, flash player, homepage, installation, ohne internet, problem, programm, pup.optional.alexatb.a, pup.optional.babylon.a, pup.optional.conduit, pup.optional.helperbar.a, pup.optional.opencandy, pup.optional.pcspeedup.a, rojaner gefunden, services.exe, startbildschirm, svchost.exe, systemereignisse, tracker |