|
Log-Analyse und Auswertung: Logfile auswerten / PC macht ProblemeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
02.03.2012, 18:26 | #1 |
| Logfile auswerten / PC macht Probleme Hallo Leute! Mein PC ist in letzter Zeit sehr langsam. Außerdem ist mir aufgefallen, dass Battlefield 3 vorher auf extrem hoher Grafik lief und jetzt nur noch auf niedriger Einstellung. Aber ich bin einfach ein Grafikenthusiast Dazu funktioniert das Windoof Media Center nicht mehr richtig. Ich habe Microsoft Security Essentials. Allerdings findet das Prog. nichts. Und ein Windoof 7 32 Bit Hier die HijackThis Logfile Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:10:12, on 02.03.2012 Platform: Unknown Windows (WinNT 6.01.3505 SP1) MSIE: Internet Explorer v9.00 (9.00.8112.16421) Boot mode: Normal Running processes: C:\Windows\system32\Dwm.exe C:\Windows\system32\taskhost.exe C:\Windows\Explorer.EXE C:\Program Files\avmwlanstick\WLanGUI.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Brownie\BrStsWnd.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe C:\Program Files\Brownie\Brnipmon.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\***\Downloads\HiJackThis.exe C:\Windows\system32\SearchFilterHost.exe C:\Users\***\Desktop\HiJackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://facebook.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll O4 - HKLM\..\Run: [AVMWlanClient] C:\Program Files\avmwlanstick\wlangui.exe O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey O4 - HKLM\..\Run: [LWS] C:\Program Files\Logitech\LWS\Webcam Software\LWS.exe -hide O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" O4 - HKLM\..\Run: [BrStsWnd] C:\Program Files\Brownie\BrstsWnd.exe Autorun O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe" O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [Remote Control Editor] "C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe" O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST') O8 - Extra context menu item: Free YouTube to iPhone Converter - C:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetoiphoneconverter.htm O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm O9 - Extra button: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O13 - Gopher Prefix: O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O20 - AppInit_DLLs: O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: AVM WLAN Connection Service - AVM Berlin - C:\Program Files\avmwlanstick\WlanNetService.exe O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: EyeTV Netstream - Elgato Systems GmbH - C:\Program Files\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: UMVPFSrv - Logitech Inc. - C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe -- End of file - 6303 bytes Hier die DDS Files: Code:
ATTFilter . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 BrowserJavaVersion: 1.6.0_31 Run by Tim at 18:32:48 on 2012-03-02 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.3071.1830 [GMT 1:00] . AV: Microsoft Security Essentials *Enabled/Updated* {108DAC43-C256-20B7-BB05-914135DA5160} SP: Microsoft Security Essentials *Enabled/Updated* {ABEC4DA7-E46C-2F39-81B5-AA334E5D1BDD} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Program Files\Common Files\logishrd\LVMVFM\UMVPFSrv.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\atieclxx.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe C:\Windows\system32\Dwm.exe C:\Windows\system32\taskhost.exe C:\Windows\Explorer.EXE C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\avmwlanstick\WlanNetService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Program Files\Elgato\EyeTV Netstream\EyeTVNetstreamSvc.exe C:\Program Files\avmwlanstick\WLanGUI.exe C:\Program Files\Microsoft Security Client\msseces.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Common Files\Java\Java Update\jusched.exe C:\Program Files\Skype\Phone\Skype.exe C:\Program Files\Common Files\TerraTec\Remote\TTTvRc.exe C:\Windows\system32\PnkBstrA.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe C:\Windows\ehome\ehRecvr.exe c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe C:\Program Files\iPod\bin\iPodService.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\svchost.exe -k SDRSVC C:\Program Files\Mozilla Firefox\firefox.exe C:\Users\Tim\Downloads\HiJackThis.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\conhost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = hxxp://facebook.de/ uInternet Settings,ProxyOverride = *.local BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelperShim.dll BHO: Java(tm) Plug-In SSV Helper: {761497bb-d6f0-462c-b6eb-d4daf1d92d43} - c:\program files\java\jre6\bin\ssv.dll BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - c:\program files\common files\microsoft shared\windows live\WindowsLiveLogin.dll BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll uRun: [Skype] "c:\program files\skype\phone\Skype.exe" /nosplash /minimized uRun: [Remote Control Editor] "c:\program files\common files\terratec\remote\TTTvRc.exe" mRun: [AVMWlanClient] c:\program files\avmwlanstick\wlangui.exe mRun: [MSC] "c:\program files\microsoft security client\msseces.exe" -hide -runkey mRun: [LWS] c:\program files\logitech\lws\webcam software\LWS.exe -hide mRun: [QuickTime Task] "c:\program files\quicktime\QTTask.exe" -atboottime mRun: [iTunesHelper] "c:\program files\itunes\iTunesHelper.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mRun: [BrStsWnd] c:\program files\brownie\BrstsWnd.exe Autorun mRun: [StartCCC] "c:\program files\ati technologies\ati.ace\core-static\CLIStart.exe" MSRun mRun: [SunJavaUpdateSched] "c:\program files\common files\java\java update\jusched.exe" mPolicies-system: ConsentPromptBehaviorAdmin = 5 (0x5) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: Free YouTube to iPhone Converter - c:\users\tim\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetoiphoneconverter.htm IE: Free YouTube to MP3 Converter - c:\users\tim\appdata\roaming\dvdvideosoftiehelpers\freeyoutubetomp3converter.htm IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - c:\program files\windows live\writer\WriterBrowserExtension.dll DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab TCP: DhcpNameServer = 192.168.1.1 TCP: Interfaces\{41D5D9D2-A654-45E5-9280-06E02CC09FED} : DhcpNameServer = 192.168.1.1 TCP: Interfaces\{69F31596-2908-4435-B8F0-AE9962E0ACE8} : DhcpNameServer = 139.7.30.126 139.7.30.125 TCP: Interfaces\{A5D004DF-D310-4842-8B3C-C514C1369EE8} : DhcpNameServer = 192.168.1.1 Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - c:\program files\windows live\photo gallery\AlbumDownloadProtocolHandler.dll AppInit_DLLs: . ================= FIREFOX =================== . FF - ProfilePath - c:\users\tim\appdata\roaming\mozilla\firefox\profiles\fu4rtxua.default\ FF - prefs.js: browser.search.selectedEngine - YouTube-Videosuche FF - prefs.js: browser.startup.homepage - hxxp://facebook.de/ FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\program files\adobe\reader 10.0\reader\air\nppdf32.dll FF - plugin: c:\program files\battlelog web plugins\1.110.0\npesnlaunch.dll FF - plugin: c:\program files\battlelog web plugins\sonar\0.70.4\npesnsonar.dll FF - plugin: c:\program files\java\jre6\bin\plugin2\npdeployJava1.dll FF - plugin: c:\program files\java\jre6\bin\plugin2\npjp2.dll FF - plugin: c:\program files\microsoft silverlight\4.1.10111.0\npctrlui.dll FF - plugin: c:\program files\windows live\photo gallery\NPWLPG.dll . ---- FIREFOX POLICIES ---- FF - user.js: yahoo.ytff.general.dontshowhpoffer - true ============= SERVICES / DRIVERS =============== . R1 MpFilter;Microsoft Malware Protection Driver;c:\windows\system32\drivers\MpFilter.sys [2011-4-18 165648] R2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files\common files\adobe\arm\1.0\armsvc.exe [2012-1-3 63928] R2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2011-12-6 163328] R2 AMD FUEL Service;AMD FUEL Service;c:\program files\ati technologies\ati.ace\fuel\Fuel.Service.exe [2011-12-5 291840] R2 EyeTV Netstream;EyeTV Netstream;c:\program files\elgato\eyetv netstream\EyeTVNetstreamSvc.exe [2010-2-3 399880] R2 UMVPFSrv;UMVPFSrv;c:\program files\common files\logishrd\lvmvfm\UMVPFSrv.exe [2011-8-19 450848] R3 amdiox86;AMD IO Driver;c:\windows\system32\drivers\amdiox86.sys [2012-1-6 37944] R3 amdkmdag;amdkmdag;c:\windows\system32\drivers\atikmdag.sys [2011-12-6 9067008] R3 amdkmdap;amdkmdap;c:\windows\system32\drivers\atikmpag.sys [2011-12-6 264192] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW73.sys [2011-10-17 85520] R3 fwlanusb4;FRITZ!WLAN N/G;c:\windows\system32\drivers\fwlanusb4.sys [2012-1-12 926080] R3 MpNWMon;Microsoft Malware Protection Network Driver;c:\windows\system32\drivers\MpNWMon.sys [2011-4-18 43392] R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\drivers\NisDrvWFP.sys [2011-4-27 65024] R3 NisSrv;Microsoft-Netzwerkinspektion;c:\program files\microsoft security client\antimalware\NisSrv.exe [2011-4-27 208944] R3 WSDPrintDevice;WSD-Druckunterstützung durch UMB;c:\windows\system32\drivers\WSDPrint.sys [2009-7-14 17920] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\microsoft.net\framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys [2012-1-12 4352] S3 b57nd60x;Broadcom NetXtreme Gigabit Ethernet - NDIS 6.0;c:\windows\system32\drivers\b57nd60x.sys [2009-7-13 229888] S3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\drivers\fwlanusb.sys [2012-1-6 264704] S3 Netaapl;Apple Mobile Device Ethernet Service;c:\windows\system32\drivers\netaapl.sys [2011-5-10 18432] S3 StorSvc;Speicherdienst;c:\windows\system32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-14 20992] S3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\TsUsbFlt.sys [2012-1-8 52224] . =============== Created Last 30 ================ . 2012-03-02 17:07:51 56200 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{da1de406-a0ac-4ad9-beef-9ff76a52e6d0}\offreg.dll 2012-03-02 13:27:30 6552120 ----a-w- c:\programdata\microsoft\microsoft antimalware\definition updates\{da1de406-a0ac-4ad9-beef-9ff76a52e6d0}\mpengine.dll 2012-03-01 10:08:36 2300696 ----a-w- c:\programdata\microsoft\ehome\packages\mceclientux\updateablemarkup-2\markup.dll 2012-03-01 10:08:25 42776 ----a-w- c:\programdata\microsoft\ehome\packages\mceclientux\dsm-2\StartResources.dll 2012-02-21 20:32:04 -------- d-----w- c:\program files\CCleaner 2012-02-20 20:09:04 -------- d-----w- c:\users\tim\appdata\local\{49434CC8-C107-477D-BE03-9530006D1943} 2012-02-20 20:08:54 -------- d-----w- c:\users\tim\appdata\local\{822F1304-A961-42B3-BB7D-878755B85148} 2012-02-20 14:40:37 -------- d-----w- c:\users\tim\appdata\local\{30724917-512E-4EA1-AB94-545E8B6FAC97} 2012-02-19 21:07:50 -------- d-----w- c:\users\tim\appdata\roaming\Applian FLV and Media Player 2012-02-19 17:00:47 -------- d-----w- c:\program files\Applian Technologies 2012-02-19 16:45:55 -------- d-----w- c:\program files\DownloadToolz 2012-02-17 14:07:40 -------- d-----w- c:\program files\AMD APP 2012-02-17 14:02:45 -------- d-----w- C:\AMD 2012-02-16 14:33:58 1427456 ----a-w- c:\windows\system32\inetcpl.cpl 2012-02-16 13:23:37 478720 ----a-w- c:\windows\system32\timedate.cpl 2012-02-16 13:23:29 690688 ----a-w- c:\windows\system32\msvcrt.dll 2012-02-16 13:23:26 442880 ----a-w- c:\windows\system32\ntshrui.dll 2012-02-16 13:23:24 2343424 ----a-w- c:\windows\system32\win32k.sys 2012-02-15 13:37:03 -------- d-----w- c:\users\tim\dwhelper 2012-02-14 13:39:44 -------- d-----w- c:\programdata\EA Logs 2012-02-12 20:29:24 -------- d-----w- c:\users\tim\appdata\local\{FAC52250-1CBA-4EB7-82A1-6630CE8033DE} 2012-02-12 20:29:00 -------- d-----w- c:\users\tim\appdata\local\{C03551E3-7137-4ED4-82E3-5D0DC0F7EF69} 2012-02-10 19:33:34 703824 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\nisbackup\gapaengine.dll 2012-02-10 19:33:32 713784 ------w- c:\programdata\microsoft\microsoft antimalware\definition updates\{1235d74d-33e2-49eb-952c-88235f51d1c7}\gapaengine.dll 2012-02-10 19:24:09 -------- d-----w- c:\users\tim\appdata\roaming\.minecraft 2012-02-10 19:20:44 472808 ----a-w- c:\windows\system32\deployJava1.dll 2012-02-07 20:11:47 -------- d-----w- c:\users\tim\appdata\local\{1536C0EE-0A53-4F96-A12E-63C75C93C9C9} 2012-02-07 20:11:26 -------- d-----w- c:\users\tim\appdata\local\{29C86469-AABF-47CE-BE80-1C6A4E4FAF17} 2012-02-02 19:48:34 -------- d-----r- c:\users\tim\appdata\roaming\Brother 2012-02-02 19:41:24 266240 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\iscript.dll 2012-02-02 19:41:24 172032 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\iuser.dll 2012-02-02 19:41:23 733184 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\iKernel.dll 2012-02-02 19:41:23 69715 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\ctor.dll 2012-02-02 19:41:23 5632 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\DotNetInstaller.exe 2012-02-02 19:41:23 180356 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\iGdi.dll 2012-02-02 19:41:22 303236 ----a-w- c:\program files\common files\installshield\professional\runtime\10\00\intel32\setup.dll . ==================== Find3M ==================== . 2012-03-02 15:28:17 139176 ----a-w- c:\windows\system32\drivers\PnkBstrK.sys 2012-03-02 15:28:09 282864 ----a-w- c:\windows\system32\PnkBstrB.xtr 2012-03-02 15:28:09 282864 ----a-w- c:\windows\system32\PnkBstrB.exe 2012-03-02 15:27:58 280904 ----a-w- c:\windows\system32\PnkBstrB.ex0 2012-02-21 20:36:11 414368 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2012-02-15 13:52:21 76888 ----a-w- c:\windows\system32\PnkBstrA.exe 2012-02-15 13:51:56 360448 ----a-w- c:\windows\system32\TubeFinder.exe 2012-02-14 13:39:05 138056 ----a-w- c:\users\tim\appdata\roaming\PnkBstrK.sys 2012-01-31 12:44:05 237072 ------w- c:\windows\system32\MpSigStub.exe 2012-01-09 20:29:32 152576 ----a-w- c:\windows\system32\msclmd.dll 2012-01-06 21:51:42 0 ----a-w- c:\windows\ativpsrm.bin 2011-12-14 03:04:54 1798656 ----a-w- c:\windows\system32\jscript9.dll 2011-12-14 02:57:18 1127424 ----a-w- c:\windows\system32\wininet.dll 2011-12-14 02:50:04 2382848 ----a-w- c:\windows\system32\mshtml.tlb 2011-12-06 03:44:22 9067008 ----a-w- c:\windows\system32\drivers\atikmdag.sys 2011-12-06 03:17:50 159744 ----a-w- c:\windows\system32\atiapfxx.exe 2011-12-06 03:17:36 778752 ----a-w- c:\windows\system32\aticfx32.dll 2011-12-06 03:12:52 466944 ----a-w- c:\windows\system32\ATIDEMGX.dll 2011-12-06 03:12:16 404992 ----a-w- c:\windows\system32\atieclxx.exe 2011-12-06 03:11:44 163328 ----a-w- c:\windows\system32\atiesrxx.exe 2011-12-06 03:10:30 163840 ----a-w- c:\windows\system32\atitmmxx.dll 2011-12-06 03:10:12 360448 ----a-w- c:\windows\system32\atipdlxx.dll 2011-12-06 03:10:00 278528 ----a-w- c:\windows\system32\Oemdspif.dll 2011-12-06 03:09:54 20992 ----a-w- c:\windows\system32\atimuixx.dll 2011-12-06 03:09:44 43520 ----a-w- c:\windows\system32\ati2edxx.dll 2011-12-06 03:06:38 6159872 ----a-w- c:\windows\system32\atidxx32.dll 2011-12-06 02:56:40 19125760 ----a-w- c:\windows\system32\atioglxx.dll 2011-12-06 02:39:24 1828864 ----a-w- c:\windows\system32\atiumdmv.dll 2011-12-06 02:34:24 46080 ----a-w- c:\windows\system32\aticalrt.dll 2011-12-06 02:34:14 44032 ----a-w- c:\windows\system32\aticalcl.dll 2011-12-06 02:33:36 5919232 ----a-w- c:\windows\system32\atiumdag.dll 2011-12-06 02:29:30 11484672 ----a-w- c:\windows\system32\aticaldd.dll 2011-12-06 02:28:50 4206592 ----a-w- c:\windows\system32\atiumdva.dll 2011-12-06 02:18:42 51200 ----a-w- c:\windows\system32\coinst.dll 2011-12-06 02:12:50 356352 ----a-w- c:\windows\system32\atiadlxx.dll 2011-12-06 02:12:34 14336 ----a-w- c:\windows\system32\atiglpxx.dll 2011-12-06 02:12:22 33280 ----a-w- c:\windows\system32\atigktxx.dll 2011-12-06 02:11:50 264192 ----a-w- c:\windows\system32\drivers\atikmpag.sys 2011-12-06 02:11:16 33280 ----a-w- c:\windows\system32\atiuxpag.dll 2011-12-06 02:11:02 29696 ----a-w- c:\windows\system32\atiu9pag.dll 2011-12-06 02:10:42 53760 ----a-w- c:\windows\system32\atimpc32.dll 2011-12-06 02:10:42 53760 ----a-w- c:\windows\system32\amdpcom32.dll 2011-12-06 02:10:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll 2011-12-05 21:04:00 59904 ----a-w- c:\windows\system32\OpenVideo.dll 2011-12-05 21:03:52 54784 ----a-w- c:\windows\system32\OVDecode.dll 2011-12-05 21:03:04 14499328 ----a-w- c:\windows\system32\amdocl.dll . ============= FINISH: 18:33:23,91 =============== Geändert von Beiger (02.03.2012 um 18:35 Uhr) Grund: Logfile |
05.03.2012, 15:17 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Logfile auswerten / PC macht Probleme Bitte nun routinemäßig einen Vollscan mit Malwarebytes machen und Log posten.
__________________Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden. Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! ESET Online Scanner
Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log
__________________ |
Themen zu Logfile auswerten / PC macht Probleme |
32 bit, acrobat update, adobe, auswerten, battlefield 3, bho, bonjour, converter, desktop, explorer, firefox, hijack, hijackthis, internet, internet explorer, käsee, langsam, log auswerten, logfile, logfile auswerten, microsoft, microsoft security, mozilla, mp3, plug-in, problem, remote control, security, software, stick, system, webcam, windows, winsock |