|
Log-Analyse und Auswertung: Arbeitsspeicher im Leerlauf fast zu 100% ausgelastet.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
22.04.2012, 15:43 | #1 |
| Arbeitsspeicher im Leerlauf fast zu 100% ausgelastet. Hallo. Seit heute morgen geht mein PC kurz nach dem Start durchgängig auf etwa 3,80 GB verwendeten Arbeitsspeicher (von 4 GB) und bleibt so, selbst im Leerlauf. Ich habe in letzter Zeit weder neue Programme installiert noch auf irgendwelchen "gefährlichen Webseiten" gesurft (was ich generell nicht mache). Auch mein Virenschutz hat nirgends angeschlagen! Kann mir da jemand helfen? Danke schonmal! dds.txt: [CODE].DDS Logfile: Code:
ATTFilter DDS (Ver_2011-08-26.01) - NTFSAMD64 Internet Explorer: 9.0.8112.16421 Run by *** at 16:26:19 on 2012-04-22 Microsoft Windows 7 Ultimate 6.1.7601.1.1252.49.1031.18.4087.2684 [GMT 2:00] . AV: G Data InternetSecurity 2012 *Enabled/Updated* {39B780B4-63C2-05B0-3B40-8F7A21E4F496} SP: G Data InternetSecurity 2012 *Enabled/Updated* {82D66150-45F8-0A3E-01F0-B4085A63BE2B} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: G Data Personal Firewall *Enabled* {018C0191-29AD-04E8-101F-264FDF37B3ED} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\svchost.exe -k RPCSS C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlX64.exe C:\Windows\system32\atiesrxx.exe C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\atieclxx.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\taskhost.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe C:\Program Files\Logitech\SetPointP\SetPoint.exe C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe C:\Program Files\Bonjour\mDNSResponder.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe C:\Windows\system32\svchost.exe -k imgsvc C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe C:\Program Files\Common Files\LogiShrd\KHAL3\KHALMNPR.EXE C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe C:\Program Files (x86)\iTunes\iTunesHelper.exe C:\Program Files (x86)\dcmsvc\dcmsvc.exe C:\Program Files\iPod\bin\iPodService.exe C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Program Files (x86)\Common Files\G Data\AVKProxy\AvkBap64.exe C:\Windows\System32\svchost.exe -k secsvcs C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\system32\taskmgr.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe C:\Windows\System32\svchost.exe -k LocalServicePeerNet C:\Windows\system32\wbem\wmiprvse.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\conhost.exe C:\Windows\SysWOW64\cscript.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uStart Page = *** uInternet Settings,ProxyOverride = *.local mWinlogon: Userinit=userinit.exe BHO: G Data WebFilter: {0124123d-61b4-456f-af86-78c53a0790c5} - C:\Program Files (x86)\G Data\InternetSecurity\WebFilter\AVKWebIE.dll BHO: ContributeBHO Class: {074c1dc5-9320-4a9a-947d-c042949c6216} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll BHO: Adobe PDF Link Helper: {18df081c-e8ad-4283-a596-fa578c2ebdc3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll BHO: DivX Plus Web Player HTML5 <video>: {326e768d-4182-46fd-9c16-1449a49795f4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File BHO: Adobe PDF Conversion Toolbar Helper: {ae7cd045-e861-484f-8273-0445ee161910} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL BHO: G Data BankGuard: {ba3295cf-17ed-4f49-9e95-d999a0adbfdc} - C:\Program Files (x86)\Common Files\G DATA\AVKProxy\BanksafeBHO.dll BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File BHO: SmartSelect Class: {f4971ee7-daa0-4053-9964-665d8ee6a077} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll TB: G Data WebFilter: {0124123d-61b4-456f-af86-78c53a0790c5} - C:\Program Files (x86)\G Data\InternetSecurity\WebFilter\AVKWebIE.dll TB: Contribute Toolbar: {517bdde4-e3a7-4570-b21e-2b52b6139fc7} - C:\Program Files (x86)\Adobe\Adobe Contribute CS5\Plugins\IEPlugin\contributeieplugin.dll TB: Adobe PDF: {47833539-d0c5-4125-9fa8-0819e2eaac93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll uRun: [AdobeBridge] uRun: [Facebook Update] "C:\Users\***\AppData\Local\Facebook\Update\FacebookUpdate.exe" /c /nocrashserver mRun: [G Data AntiVirus Tray Application] C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe mRun: [GDFirewallTray] C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe mRun: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe mRun: [<NO NAME>] mRun: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" mRun: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun: [dcmsvc] C:\Program Files (x86)\dcmsvc\dcmsvc.exe StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\AMLDEV~1.LNK - C:\Program Files (x86)\AMD AVT\bin\kdbsync.exe mPolicies-explorer: NoActiveDesktop = 1 (0x1) mPolicies-explorer: NoActiveDesktopChanges = 1 (0x1) mPolicies-system: ConsentPromptBehaviorAdmin = 0 (0x0) mPolicies-system: ConsentPromptBehaviorUser = 3 (0x3) mPolicies-system: EnableLUA = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) mPolicies-system: PromptOnSecureDesktop = 0 (0x0) IE: An OneNote s&enden - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105 IE: Free YouTube to MP3 Converter - C:\Users\***\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Nach Microsoft E&xcel exportieren - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll TCP: DhcpNameServer = 192.168.178.1 TCP: Interfaces\{0DEBA4FF-E258-49B1-B577-FE34ECED913E} : DhcpNameServer = 192.168.178.1 TCP: Interfaces\{31BB69D3-1422-4881-9498-1718DD0095FF} : DhcpNameServer = 192.168.178.1 TCP: Interfaces\{9B53052A-EBE2-434D-AB05-5D921BFA5890} : DhcpNameServer = 7.254.254.254 TCP: Interfaces\{F5BCB89C-60F4-498C-B248-58A4D31DD013} : DhcpNameServer = 192.168.178.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\MSOXMLMF.DLL Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL {0124123D-61B4-456f-AF86-78C53A0790C5} {074C1DC5-9320-4A9A-947D-C042949C6216} {18DF081C-E8AD-4283-A596-FA578C2EBDC3} {326E768D-4182-46FD-9C16-1449A49795F4} BHO-X64: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File {AE7CD045-E861-484f-8273-0445EE161910} {B4F3A835-0E21-4959-BA22-42B3008E02FF} {BA3295CF-17ED-4F49-9E95-D999A0ADBFDC} BHO-X64: {DBC80044-A445-435b-BC74-9C25C1C588A9} - No File {F4971EE7-DAA0-4053-9964-665D8EE6A077} {0124123D-61B4-456f-AF86-78C53A0790C5} {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} {47833539-D0C5-4125-9FA8-0819E2EAAC93} mRun-x64: [G Data AntiVirus Tray Application] C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe mRun-x64: [GDFirewallTray] C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe mRun-x64: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" mRun-x64: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe mRun-x64: [(Standard)] mRun-x64: [AdobeCS5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin mRun-x64: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe mRun-x64: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" mRun-x64: [Adobe Acrobat Speed Launcher] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe" mRun-x64: [Acrobat Assistant 8.0] "C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe" mRun-x64: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun mRun-x64: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime mRun-x64: [AdobeCS4ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin mRun-x64: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW mRun-x64: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" mRun-x64: [dcmsvc] C:\Program Files (x86)\dcmsvc\dcmsvc.exe . ================= FIREFOX =================== . FF - ProfilePath - C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\8ozzat0q.default\ FF - prefs.js: browser.startup.homepage - www.google.de FF - prefs.js: network.proxy.socks - 96.255.182.15 FF - prefs.js: network.proxy.socks_port - 1028 FF - prefs.js: network.proxy.type - 0 FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL FF - plugin: C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrlui.dll FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll FF - plugin: C:\Users\***\AppData\Local\Facebook\Messenger\2.0.4478.0\npFbDesktopPlugin.dll FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_2_202_233.dll . ============= SERVICES / DRIVERS =============== . R0 GDBehave;GDBehave;C:\Windows\system32\drivers\GDBehave.sys --> C:\Windows\system32\drivers\GDBehave.sys [?] R0 PxHlpa64;PxHlpa64;C:\Windows\system32\Drivers\PxHlpa64.sys --> C:\Windows\system32\Drivers\PxHlpa64.sys [?] R1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;C:\Windows\system32\DRIVERS\dtsoftbus01.sys --> C:\Windows\system32\DRIVERS\dtsoftbus01.sys [?] R1 GDMnIcpt;GDMnIcpt;\??\C:\Windows\system32\drivers\MiniIcpt.sys --> C:\Windows\system32\drivers\MiniIcpt.sys [?] R1 gdwfpcd;G Data WFP CD;C:\Windows\system32\drivers\gdwfpcd64.sys --> C:\Windows\system32\drivers\gdwfpcd64.sys [?] R1 GRD;G Data Rootkit Detector Driver;\??\C:\Windows\system32\drivers\GRD.sys --> C:\Windows\system32\drivers\GRD.sys [?] R1 HookCentre;HookCentre;\??\C:\Windows\system32\drivers\HookCentre.sys --> C:\Windows\system32\drivers\HookCentre.sys [?] R1 vwififlt;Virtual WiFi Filter Driver;C:\Windows\system32\DRIVERS\vwififlt.sys --> C:\Windows\system32\DRIVERS\vwififlt.sys [?] R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\system32\atiesrxx.exe --> C:\Windows\system32\atiesrxx.exe [?] R2 AVKProxy;G Data AntiVirus Proxy;C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2012-2-24 1506824] R2 AVKService;G Data Scheduler;C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [2011-8-17 464392] R2 AVKWCtl;G Data Dateisystem Wächter;C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe [2012-2-24 2191808] R2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2012-2-28 2343816] R3 amdkmdag;amdkmdag;C:\Windows\system32\DRIVERS\atikmdag.sys --> C:\Windows\system32\DRIVERS\atikmdag.sys [?] R3 amdkmdap;amdkmdap;C:\Windows\system32\DRIVERS\atikmpag.sys --> C:\Windows\system32\DRIVERS\atikmpag.sys [?] R3 AtiHDAudioService;AMD Function Driver for HD Audio Service;C:\Windows\system32\drivers\AtihdW76.sys --> C:\Windows\system32\drivers\AtihdW76.sys [?] R3 GDFwSvc;G Data Personal Firewall;C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [2011-8-10 1556816] R3 GDPkIcpt;GDPkIcpt;\??\C:\Windows\system32\drivers\PktIcpt.sys --> C:\Windows\system32\drivers\PktIcpt.sys [?] R3 GDScan;G Data Scanner;C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [2012-2-24 457536] R3 netr28ux;RT2870-USB-Drahtlos-LAN-Kartentreiber für Vista;C:\Windows\system32\DRIVERS\netr28ux.sys --> C:\Windows\system32\DRIVERS\netr28ux.sys [?] R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\system32\DRIVERS\Rt64win7.sys --> C:\Windows\system32\DRIVERS\Rt64win7.sys [?] R3 tap0901t;TAP-Win32 Adapter V9 (Tunngle);C:\Windows\system32\DRIVERS\tap0901t.sys --> C:\Windows\system32\DRIVERS\tap0901t.sys [?] S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384] S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576] S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2012-2-15 158856] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-4-14 253088] S3 GdNetMon;G Data Network Monitor;\??\C:\Windows\system32\drivers\GdNetMon64.sys --> C:\Windows\system32\drivers\GdNetMon64.sys [?] S3 osppsvc;Office Software Protection Platform;C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-1-9 4925184] S3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;C:\Windows\system32\drivers\rdpvideominiport.sys --> C:\Windows\system32\drivers\rdpvideominiport.sys [?] S3 SwitchBoard;SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096] S3 TsUsbFlt;TsUsbFlt;C:\Windows\system32\drivers\tsusbflt.sys --> C:\Windows\system32\drivers\tsusbflt.sys [?] S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\system32\Drivers\usbaapl64.sys --> C:\Windows\system32\Drivers\usbaapl64.sys [?] . =============== Created Last 30 ================ . 2012-04-20 14:28:21 8917360 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{77584E52-B5DD-4CDD-9B72-C788897E87C6}\mpengine.dll 2012-04-15 10:24:55 -------- d-----w- C:\Program Files (x86)\Mass Effect 2012-04-13 23:53:26 8766112 ----a-w- C:\Windows\SysWow64\FlashPlayerInstaller.exe 2012-04-13 23:07:06 418464 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe 2012-04-11 23:54:27 81408 ----a-w- C:\Windows\System32\imagehlp.dll 2012-04-11 23:54:27 23408 ----a-w- C:\Windows\System32\drivers\fs_rec.sys 2012-04-11 23:54:27 159232 ----a-w- C:\Windows\SysWow64\imagehlp.dll 2012-04-11 23:54:26 5120 ----a-w- C:\Windows\SysWow64\wmi.dll 2012-04-11 23:54:26 5120 ----a-w- C:\Windows\System32\wmi.dll 2012-04-11 23:54:26 220672 ----a-w- C:\Windows\System32\wintrust.dll 2012-04-11 23:54:26 172544 ----a-w- C:\Windows\SysWow64\wintrust.dll 2012-04-11 23:50:51 -------- d-----w- C:\Program Files (x86)\dcmsvc 2012-04-11 23:48:05 -------- d-----w- C:\Users\***\AppData\Roaming\com.warnerbros.DigitalCopyManager.449F66ACC381FDC604DC2AA255FEECEEBBBEE1E5.1 2012-04-11 23:48:04 -------- d-----w- C:\Program Files (x86)\Warner Bros. Digital Copy Manager 2012-04-11 22:43:18 -------- d-----w- C:\Users\***\AppData\Local\Facebook 2012-04-11 17:24:12 178800 ----a-w- C:\Windows\SysWow64\CmdLineExt_x64.dll 2012-04-11 12:18:37 -------- d-----w- C:\Program Files (x86)\Tools&More 2012-04-11 12:18:04 -------- d-----w- C:\Windows\Downloaded Installations 2012-04-10 13:06:40 -------- d-----w- C:\ProgramData\Media Center Programs 2012-04-10 13:06:30 -------- d-----w- C:\Program Files (x86)\Common Files\BioWare 2012-04-04 14:10:45 -------- d-----w- C:\Users\***\AppData\Roaming\Meine Die Schlacht um Mittelerde™ II-Dateien 2012-04-04 11:42:18 -------- d-----w- C:\Program Files (x86)\Smart PC Solutions 2012-04-04 05:54:08 182160 ----a-w- C:\Program Files (x86)\Mozilla Firefox\plugins\nppdf32.dll 2012-04-01 13:40:58 -------- d-----w- C:\Users\***\AppData\Roaming\Applian FLV and Media Player 2012-03-30 14:25:46 -------- d-----w- C:\Program Files\iPod 2012-03-30 14:25:45 -------- d-----w- C:\Program Files\iTunes 2012-03-26 19:57:44 580096 ----a-w- C:\Windows\System32\ac3filter64.acm 2012-03-26 19:57:44 497664 ----a-w- C:\Windows\SysWow64\ac3filter.acm 2012-03-26 19:57:44 -------- d-----w- C:\Program Files (x86)\AC3Filter 2012-03-26 09:53:55 -------- d-----w- C:\Users\***\AppData\Local\DDMSettings 2012-03-26 09:50:34 -------- d-----w- C:\Program Files\DivX 2012-03-26 09:49:34 -------- d-----w- C:\Program Files (x86)\Common Files\DivX Shared 2012-03-26 09:46:07 -------- d-----w- C:\Program Files (x86)\DivX 2012-03-26 09:40:13 -------- d-----w- C:\ProgramData\DivX 2012-03-24 00:21:37 -------- d-----w- C:\Users\***\AppData\Local\AutoIt Debugger 2012-03-24 00:03:18 -------- d-----w- C:\Users\***\AppData\Roaming\Tunngle 2012-03-24 00:03:18 -------- d-----w- C:\ProgramData\Tunngle 2012-03-24 00:03:13 31232 ----a-w- C:\Windows\System32\drivers\tap0901t.sys 2012-03-24 00:03:12 -------- d-----w- C:\Program Files (x86)\Tunngle 2012-03-23 18:53:20 -------- d-----w- C:\Program Files (x86)\HVB eFIN-Datensicherung 2012-03-23 18:52:58 -------- d-----w- C:\Program Files (x86)\HVB eFIN 3.0 . ==================== Find3M ==================== . 2012-04-21 19:38:11 615141 ----a-w- C:\Windows\SysWow64\sig.bin 2012-04-13 23:53:57 70304 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl 2012-03-19 17:54:35 106648 ----a-w- C:\Windows\System32\drivers\GRD.sys 2012-03-17 21:43:47 955848 ----a-w- C:\Windows\System32\npDeployJava1.dll 2012-03-17 21:43:47 839112 ----a-w- C:\Windows\System32\deployJava1.dll 2012-03-06 06:53:37 5559152 ----a-w- C:\Windows\System32\ntoskrnl.exe 2012-03-06 05:59:47 3968368 ----a-w- C:\Windows\SysWow64\ntkrnlpa.exe 2012-03-06 05:59:41 3913072 ----a-w- C:\Windows\SysWow64\ntoskrnl.exe 2012-03-01 17:36:15 98304 ----a-w- C:\Windows\SysWow64\CmdLineExt.dll 2012-02-28 13:39:11 472808 ----a-w- C:\Windows\SysWow64\deployJava1.dll 2012-02-28 11:35:00 152576 ----a-w- C:\Windows\SysWow64\msclmd.dll 2012-02-28 11:34:59 175616 ----a-w- C:\Windows\System32\msclmd.dll 2012-02-28 06:56:48 2311168 ----a-w- C:\Windows\System32\jscript9.dll 2012-02-28 06:49:56 1390080 ----a-w- C:\Windows\System32\wininet.dll 2012-02-28 06:48:57 1493504 ----a-w- C:\Windows\System32\inetcpl.cpl 2012-02-28 06:42:55 2382848 ----a-w- C:\Windows\System32\mshtml.tlb 2012-02-28 01:18:55 1799168 ----a-w- C:\Windows\SysWow64\jscript9.dll 2012-02-28 01:11:21 1427456 ----a-w- C:\Windows\SysWow64\inetcpl.cpl 2012-02-28 01:11:07 1127424 ----a-w- C:\Windows\SysWow64\wininet.dll 2012-02-28 01:03:16 2382848 ----a-w- C:\Windows\SysWow64\mshtml.tlb 2012-02-26 19:26:07 2368 ----a-w- C:\Windows\SysWow64\SVKP.sys 2012-02-26 17:47:07 283200 ----a-w- C:\Windows\System32\drivers\dtsoftbus01.sys 2012-02-24 22:31:36 18960 ----a-w- C:\Windows\System32\drivers\LNonPnP.sys 2012-02-24 16:44:06 0 ----a-w- C:\Windows\ativpsrm.bin 2012-02-24 16:41:57 65912 ----a-w- C:\Windows\System32\drivers\gdwfpcd64.sys 2012-02-24 16:41:57 53112 ----a-w- C:\Windows\System32\drivers\HookCentre.sys 2012-02-24 16:41:57 50552 ----a-w- C:\Windows\System32\drivers\GDBehave.sys 2012-02-24 16:41:57 111992 ----a-w- C:\Windows\System32\drivers\MiniIcpt.sys 2012-02-24 16:27:49 59256 ----a-w- C:\Windows\System32\drivers\PktIcpt.sys 2012-02-24 16:27:26 31608 ----a-w- C:\Windows\System32\drivers\GdNetMon64.sys 2012-02-23 08:18:36 279656 ------w- C:\Windows\System32\MpSigStub.exe 2012-02-17 06:38:27 1112064 ----a-w- C:\Windows\System32\rdpcorets.dll 2012-02-17 06:38:26 1031680 ----a-w- C:\Windows\System32\rdpcore.dll 2012-02-17 05:34:22 826880 ----a-w- C:\Windows\SysWow64\rdpcore.dll 2012-02-17 04:58:24 210944 ----a-w- C:\Windows\System32\drivers\rdpwd.sys 2012-02-17 04:57:32 23552 ----a-w- C:\Windows\System32\drivers\tdtcp.sys 2012-02-15 10:01:50 52736 ----a-w- C:\Windows\System32\drivers\usbaapl64.sys 2012-02-15 10:01:50 4547944 ----a-w- C:\Windows\System32\usbaaplrc.dll 2012-02-15 03:48:32 10856960 ----a-w- C:\Windows\System32\drivers\atikmdag.sys 2012-02-15 03:21:24 25839104 ----a-w- C:\Windows\System32\atio6axx.dll 2012-02-15 03:18:56 159744 ----a-w- C:\Windows\System32\atiapfxx.exe 2012-02-15 03:18:40 791040 ----a-w- C:\Windows\SysWow64\aticfx32.dll 2012-02-15 03:17:04 957952 ----a-w- C:\Windows\System32\aticfx64.dll 2012-02-15 03:13:56 442368 ----a-w- C:\Windows\System32\ATIDEMGX.dll 2012-02-15 03:13:40 496128 ----a-w- C:\Windows\System32\atieclxx.exe 2012-02-15 03:13:00 235520 ----a-w- C:\Windows\System32\atiesrxx.exe 2012-02-15 03:11:42 120320 ----a-w- C:\Windows\System32\atitmm64.dll 2012-02-15 03:10:58 21504 ----a-w- C:\Windows\System32\atimuixx.dll 2012-02-15 03:10:54 59392 ----a-w- C:\Windows\System32\atiedu64.dll 2012-02-15 03:10:48 43520 ----a-w- C:\Windows\SysWow64\ati2edxx.dll 2012-02-15 03:07:44 6200320 ----a-w- C:\Windows\SysWow64\atidxx32.dll 2012-02-15 02:58:56 19392000 ----a-w- C:\Windows\SysWow64\atioglxx.dll 2012-02-15 02:52:28 7646208 ----a-w- C:\Windows\System32\atidxx64.dll 2012-02-15 02:41:28 1113088 ----a-w- C:\Windows\System32\atiumd6v.dll 2012-02-15 02:40:54 1828864 ----a-w- C:\Windows\SysWow64\atiumdmv.dll 2012-02-15 02:40:42 4958208 ----a-w- C:\Windows\System32\atiumd6a.dll 2012-02-15 02:34:56 51200 ----a-w- C:\Windows\System32\aticalrt64.dll 2012-02-15 02:34:54 46080 ----a-w- C:\Windows\SysWow64\aticalrt.dll 2012-02-15 02:34:46 44544 ----a-w- C:\Windows\System32\aticalcl64.dll 2012-02-15 02:34:44 44032 ----a-w- C:\Windows\SysWow64\aticalcl.dll 2012-02-15 02:34:36 5954048 ----a-w- C:\Windows\SysWow64\atiumdag.dll 2012-02-15 02:34:30 13859840 ----a-w- C:\Windows\System32\aticaldd64.dll 2012-02-15 02:29:52 5062656 ----a-w- C:\Windows\SysWow64\atiumdva.dll 2012-02-15 02:29:50 11561984 ----a-w- C:\Windows\SysWow64\aticaldd.dll 2012-02-15 02:25:06 7551488 ----a-w- C:\Windows\System32\atiumd64.dll 2012-02-15 02:16:38 58880 ----a-w- C:\Windows\System32\coinst.dll 2012-02-15 02:14:00 512000 ----a-w- C:\Windows\System32\atiadlxx.dll 2012-02-15 02:13:50 356352 ----a-w- C:\Windows\SysWow64\atiadlxy.dll 2012-02-15 02:13:36 17408 ----a-w- C:\Windows\System32\atig6pxx.dll 2012-02-15 02:13:32 14336 ----a-w- C:\Windows\SysWow64\atiglpxx.dll 2012-02-15 02:13:32 14336 ----a-w- C:\Windows\System32\atiglpxx.dll 2012-02-15 02:13:28 39936 ----a-w- C:\Windows\System32\atig6txx.dll 2012-02-15 02:13:20 33280 ----a-w- C:\Windows\SysWow64\atigktxx.dll 2012-02-15 02:13:12 327680 ----a-w- C:\Windows\System32\drivers\atikmpag.sys 2012-02-15 02:12:22 43008 ----a-w- C:\Windows\System32\atiuxp64.dll 2012-02-15 02:12:14 33280 ----a-w- C:\Windows\SysWow64\atiuxpag.dll 2012-02-15 02:12:08 39936 ----a-w- C:\Windows\System32\atiu9p64.dll 2012-02-15 02:12:00 30208 ----a-w- C:\Windows\SysWow64\atiu9pag.dll 2012-02-15 02:11:22 53248 ----a-w- C:\Windows\System32\drivers\ati2erec.dll 2012-02-15 02:11:16 54784 ----a-w- C:\Windows\System32\atimpc64.dll 2012-02-15 02:11:16 54784 ----a-w- C:\Windows\System32\amdpcom64.dll 2012-02-15 02:11:10 53760 ----a-w- C:\Windows\SysWow64\atimpc32.dll 2012-02-15 02:11:10 53760 ----a-w- C:\Windows\SysWow64\amdpcom32.dll 2012-02-14 21:05:32 69632 ----a-w- C:\Windows\System32\OpenVideo64.dll 2012-02-14 21:05:26 59904 ----a-w- C:\Windows\SysWow64\OpenVideo.dll 2012-02-14 21:05:20 61952 ----a-w- C:\Windows\System32\OVDecode64.dll 2012-02-14 21:05:16 54784 ----a-w- C:\Windows\SysWow64\OVDecode.dll 2012-02-14 21:05:08 16507904 ----a-w- C:\Windows\System32\amdocl64.dll 2012-02-14 21:04:26 13238272 ----a-w- C:\Windows\SysWow64\amdocl.dll 2012-02-14 21:03:44 54272 ----a-w- C:\Windows\System32\OpenCL.dll 2012-02-14 21:03:38 48128 ----a-w- C:\Windows\SysWow64\OpenCL.dll 2012-02-14 10:09:44 1070352 ----a-w- C:\Windows\SysWow64\MSCOMCTL.OCX 2012-02-10 06:36:07 1544192 ----a-w- C:\Windows\System32\DWrite.dll 2012-02-10 05:38:43 1077248 ----a-w- C:\Windows\SysWow64\DWrite.dll 2012-02-03 04:34:34 3145728 ----a-w- C:\Windows\System32\win32k.sys 2012-01-31 05:02:26 21504 ----a-w- C:\Windows\System32\kdbsdk64.dll 2012-01-31 05:00:24 16896 ----a-w- C:\Windows\SysWow64\kdbsdk32.dll 2012-01-25 06:38:39 77312 ----a-w- C:\Windows\System32\rdpwsx.dll 2012-01-25 06:38:38 149504 ----a-w- C:\Windows\System32\rdpcorekmts.dll 2012-01-25 06:33:30 9216 ----a-w- C:\Windows\System32\rdrmemptylst.exe . ============= FINISH: 16:27:31,43 =============== attach.txt: Code:
ATTFilter . UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft Windows 7 Ultimate Boot Device: \Device\HarddiskVolume1 Install Date: 24.02.2012 16:59:01 System Uptime: 22.04.2012 15:16:09 (1 hours ago) . Motherboard: Gigabyte Technology Co., Ltd. | | P55-UD4 Processor: Intel(R) Core(TM) i5 CPU 750 @ 2.67GHz | Socket 1156 | 2102/133mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 466 GiB total, 131,332 GiB free. D: is CDROM () F: is CDROM () . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . RP48: 20.04.2012 16:27:46 - Windows Update RP49: 21.04.2012 16:50:44 - Installed Safari . ==== Installed Programs ====================== . AC3Filter 1.63b Acrobat.com Adobe Acrobat X Pro - English, Français, Deutsch Adobe After Effects CS4 Third Party Content Adobe AIR Adobe Anchor Service CS4 Adobe Community Help Adobe Creative Suite 4 Master Collection Adobe Creative Suite 5 Master Collection Adobe CSI CS4 Adobe Dreamweaver CS4 Adobe Encore CS4 Codecs Adobe ExtendScript Toolkit CS4 Adobe Media Encoder CS4 Exporter Adobe Media Encoder CS4 Importer Adobe Media Player Adobe Search for Help Adobe Service Manager Extension Adobe Setup Adobe Soundbooth CS4 Codecs Adobe Update Manager CS4 Apple Application Support Apple Software Update Audacity 1.3.14 (Unicode) AutoIt Debugger 0.45.1 AutoIt v3.3.8.1 Catalyst Control Center Catalyst Control Center - Branding Catalyst Control Center Graphics Previews Common Catalyst Control Center InstallProxy Catalyst Control Center Localization All CCC Help Chinese Standard CCC Help Chinese Traditional CCC Help Czech CCC Help Danish CCC Help Dutch CCC Help English CCC Help Finnish CCC Help French CCC Help German CCC Help Greek CCC Help Hungarian CCC Help Italian CCC Help Japanese CCC Help Korean CCC Help Norwegian CCC Help Polish CCC Help Portuguese CCC Help Russian CCC Help Spanish CCC Help Swedish CCC Help Thai CCC Help Turkish Connect DAEMON Tools Lite dcmsvc 1.0 Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition Die Schlacht um Mittelerde™ II DivX-Setup eReg Facebook Messenger 2.0.4478.0 FileZilla Client 3.5.3 FLV Player 2.0 (build 25) Fraps (remove only) Free YouTube to MP3 Converter version 3.10.17.221 G Data InternetSecurity 2012 Gothic II HijackThis 2.0.2 HP Officejet 6500 E710n-z Hilfe HP Update HVB eFIN 3.0 I.R.I.S. OCR ImageMixer 3 SE Joe kuler LogMeIn Hamachi Magic Bullet Looks Magic Bullet PhotoLooks for Photoshop 64 bit Mass Effect Mass Effect™ 3 Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (German) 2010 Microsoft Office Excel MUI (German) 2010 Microsoft Office Home and Student 2010 Microsoft Office OneNote MUI (German) 2010 Microsoft Office Outlook MUI (German) 2010 Microsoft Office PowerPoint MUI (German) 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (German) 2010 Microsoft Office Proof (Italian) 2010 Microsoft Office Proofing (German) 2010 Microsoft Office Publisher MUI (German) 2010 Microsoft Office Shared MUI (German) 2010 Microsoft Office Single Image 2010 Microsoft Office Word MUI (German) 2010 Microsoft Silverlight Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft_VC80_ATL_x86 Microsoft_VC80_CRT_x86 Microsoft_VC80_MFC_x86 Microsoft_VC80_MFCLOC_x86 Microsoft_VC90_ATL_x86 Microsoft_VC90_CRT_x86 Microsoft_VC90_MFC_x86 Mozilla Firefox 11.0 (x86 de) NVIDIA PhysX Origin Pando Media Booster PDF Settings CS5 PxMergeModule QuickTime RAD Video Tools Realtek High Definition Audio Driver Safari Security Update for Microsoft .NET Framework 4 Client Profile (KB2518870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2572078) Security Update for Microsoft .NET Framework 4 Client Profile (KB2633870) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656351) Security Update for Microsoft .NET Framework 4 Client Profile (KB2656368) Security Update for Microsoft .NET Framework 4 Client Profile DEU Language Pack (KB2518870) Security Update for Microsoft Office 2010 (KB2553091) Security Update for Microsoft Office 2010 (KB2553096) Security Update for Microsoft Office 2010 (KB2589320) 32-Bit Edition Security Update for Microsoft Office 2010 (KB2598039) 32-Bit Edition Security Update for Microsoft PowerPoint 2010 (KB2553185) 32-Bit Edition Security Update for Microsoft SharePoint Workspace 2010 (KB2566445) Security Update for Microsoft Visio Viewer 2010 (KB2597170) 32-Bit Edition Skype™ 5.8 Smart Data Recovery v4.3 Steam Suite Shared Configuration CS4 Tunngle beta Update for Microsoft .NET Framework 4 Client Profile (KB2468871) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) Update for Microsoft Excel 2010 (KB2553439) 32-Bit Edition Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition Update for Microsoft Office 2010 (KB2553270) 32-Bit Edition Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition Update for Microsoft Office 2010 (KB2553385) 32-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition Update for Microsoft Office 2010 (KB2597091) 32-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition Update for Microsoft Outlook 2010 (KB2553248) 32-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition VC80CRTRedist - 8.0.50727.6195 Warner Bros. Digital Copy Manager WinRAR . ==== End Of File =========================== |
22.04.2012, 20:23 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Arbeitsspeicher im Leerlauf fast zu 100% ausgelastet. Bitte erstmal routinemäßig einen Vollscan mit Malwarebytes machen und Log posten. =>ALLE lokalen Datenträger (außer CD/DVD) überprüfen lassen!
__________________Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Außerdem müssen alle Funde entfernt werden. Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! ESET Online Scanner
Bitte alles nach Möglichkeit hier in CODE-Tags posten. Wird so gemacht: [code] hier steht das Log [/code] Und das ganze sieht dann so aus: Code:
ATTFilter hier steht das Log
__________________ |
Themen zu Arbeitsspeicher im Leerlauf fast zu 100% ausgelastet. |
100%, adobe, antivirus, ausgelastet, bankguard, bonjour, converter, cpu, dateisystem, defender, document, explorer, firefox, firewall, flash player, monitor, mozilla, mp3, officejet, outlook 2010, photoshop, realtek, rootkit, schutz, security, software, svchost.exe, system, third party, vista, windows |