![]() |
Plagegeister aller Art und deren Bekämpfung: Virus verlangsamt Internetverbindung?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
![]() | #1 |
![]() | ![]() Virus verlangsamt Internetverbindung?Hi, also ich wurde von gutefrage.net geschickt, da ich hier eine professionellere Auskunft bekommen könnte wegen meines Problems. Ich habe schon seit ca. 2 Monaten schlechtes Internet währendessen alle anderen im Haushalt relativ gute Verbindung haben. Ich hatte vor ein paar Wochen noch D-Lan und hatte immer schlechte Verbindung als meine Mutter parallel an ihrem Pc im Internet war, also hab ich mir Lan gelegt und gehofft das ich damit bessere Verbindung hätte was aber nicht so war. Ich hatte und habe immernoch alle 6 Sekunden eine verlangsamung meines Internets, welch meinen Ping von 50 ms auf 200 ms springen lässt und meine Down- Uploadrate in den Keller jagt. Ich gehe davon aus dass ich einen Virus auf meinem PC habe, der gezielt meine Interverbindung drosselt oder etwas downloaded und somit meine Leitung auslastet. Könnt ihr mir bei meinem Problem helfen? LG Browneeh |
![]() | #2 |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Virus verlangsamt Internetverbindung?![]() ist nur der Ping schecht? Was fuer Werte liefert speedtest.net?
__________________ |
![]() | #3 |
![]() | ![]() Virus verlangsamt Internetverbindung? Hi t'john,
__________________also so sieht mein Internet aus wenn es am besten läuft, damit bin ich auch sehr zufrieden obwohl es beim HD Video schauen kritisch wird. ![]() Aber meisten eben nur einen Ping von 100-200 ms, eine Downloadrate von ~0,80 Mbps und eine Uploadrate von ~0,05 Mbps. Und von diesen werten springt es immer hin und her, in der einen Sekunde noch schnelles Internet und dann plötzlich langsames. LG Browneeh |
![]() | #4 |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Virus verlangsamt Internetverbindung? Hasst du bei anderen Rechnern in deinem Netzwerk bessere Werte? Downloade dir bitte Farbar's MiniToolBox auf deinen Desktop und starte das Tool Setze einen Haken bei folgenden Einträgen
Klicke Go und poste den Inhalt der Result.txt. |
![]() | #5 |
![]() | ![]() Virus verlangsamt Internetverbindung? Bessere Werte haben alle anderen Pc's die mit unserem Router verbunden sind nicht aber durchgehend die selben wie ich oben als Bild gepostet habe. Code:
ATTFilter MiniToolBox by Farbar Version: 13-07-2013 Ran by Martin (administrator) on 04-08-2013 at 18:48:46 Running from "C:\Users\Martin\Downloads" Microsoft Windows 7 Professional Service Pack 1 (X64) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= FF Proxy Settings: ============================== "network.proxy.type", 2 "Reset FF Proxy Settings": Firefox Proxy settings were reset. ========================= Hosts content: ================================= ========================= IP Configuration: ================================ Realtek PCIe GBE Family Controller = LAN-Verbindung (Connected) # ---------------------------------- # IPv4-Konfiguration # ---------------------------------- pushd interface ipv4 reset set global icmpredirects=enabled popd # Ende der IPv4-Konfiguration Windows-IP-Konfiguration Hostname . . . . . . . . . . . . : Browneeh Prim„res DNS-Suffix . . . . . . . : Knotentyp . . . . . . . . . . . . : Hybrid IP-Routing aktiviert . . . . . . : Nein WINS-Proxy aktiviert . . . . . . : Nein DNS-Suffixsuchliste . . . . . . . : fritz.box Ethernet-Adapter LAN-Verbindung: Verbindungsspezifisches DNS-Suffix: fritz.box Beschreibung. . . . . . . . . . . : Realtek PCIe GBE Family Controller Physikalische Adresse . . . . . . : 30-85-A9-B0-F0-95 DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja IPv4-Adresse . . . . . . . . . . : Subnetzmaske . . . . . . . . . . : Lease erhalten. . . . . . . . . . : Sonntag, 4. August 2013 06:56:34 Lease l„uft ab. . . . . . . . . . : Mittwoch, 14. August 2013 06:56:41 Standardgateway . . . . . . . . . : DHCP-Server . . . . . . . . . . . : DNS-Server . . . . . . . . . . . : NetBIOS ber TCP/IP . . . . . . . : Aktiviert Tunneladapter isatap.fritz.box: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: fritz.box Beschreibung. . . . . . . . . . . : Microsoft-ISATAP-Adapter Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja Tunneladapter Teredo Tunneling Pseudo-Interface: Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja IPv6-Adresse. . . . . . . . . . . : 2001:0:5ef5:79fb:cf2:3648:3f57:4dce(Bevorzugt) Verbindungslokale IPv6-Adresse . : fe80::cf2:3648:3f57:4dce%11(Bevorzugt) Standardgateway . . . . . . . . . : :: NetBIOS ber TCP/IP . . . . . . . : Deaktiviert Server: fritz.box Address: Name: google.com Addresses: 2a00:1450:4001:80a::1001 Ping wird ausgefhrt fr google.com [] mit 32 Bytes Daten: Antwort von Bytes=32 Zeit=95ms TTL=56 Antwort von Bytes=32 Zeit=54ms TTL=56 Ping-Statistik fr Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust), Ca. Zeitangaben in Millisek.: Minimum = 54ms, Maximum = 95ms, Mittelwert = 74ms Server: fritz.box Address: Name: yahoo.com Addresses: Ping wird ausgefhrt fr yahoo.com [] mit 32 Bytes Daten: Antwort von Bytes=32 Zeit=190ms TTL=52 Antwort von Bytes=32 Zeit=186ms TTL=50 Ping-Statistik fr Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust), Ca. Zeitangaben in Millisek.: Minimum = 186ms, Maximum = 190ms, Mittelwert = 188ms Ping wird ausgefhrt fr mit 32 Bytes Daten: Antwort von Bytes=32 Zeit<1ms TTL=128 Antwort von Bytes=32 Zeit<1ms TTL=128 Ping-Statistik fr Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust), Ca. Zeitangaben in Millisek.: Minimum = 0ms, Maximum = 0ms, Mittelwert = 0ms =========================================================================== Schnittstellenliste 10...30 85 a9 b0 f0 95 ......Realtek PCIe GBE Family Controller 1...........................Software Loopback Interface 1 13...00 00 00 00 00 00 00 e0 Microsoft-ISATAP-Adapter 11...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface =========================================================================== IPv4-Routentabelle =========================================================================== Aktive Routen: Netzwerkziel Netzwerkmaske Gateway Schnittstelle Metrik 10 Auf Verbindung 306 Auf Verbindung 306 Auf Verbindung 306 Auf Verbindung 266 Auf Verbindung 266 Auf Verbindung 266 Auf Verbindung 306 Auf Verbindung 266 Auf Verbindung 306 Auf Verbindung 266 =========================================================================== St„ndige Routen: Keine IPv6-Routentabelle =========================================================================== Aktive Routen: If Metrik Netzwerkziel Gateway 11 58 ::/0 Auf Verbindung 1 306 ::1/128 Auf Verbindung 11 58 2001::/32 Auf Verbindung 11 306 2001:0:5ef5:79fb:cf2:3648:3f57:4dce/128 Auf Verbindung 11 306 fe80::/64 Auf Verbindung 11 306 fe80::cf2:3648:3f57:4dce/128 Auf Verbindung 1 306 ff00::/8 Auf Verbindung 11 306 ff00::/8 Auf Verbindung =========================================================================== St„ndige Routen: Keine ========================= Winsock entries ===================================== Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation) Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation) Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation) Catalog5 07 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [134528] (Microsoft Corporation) Catalog5 08 C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [134528] (Microsoft Corporation) Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [232448] (Microsoft Corporation) x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation) x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation) x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation) x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation) x64-Catalog5 07 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [168304] (Microsoft Corporation) x64-Catalog5 08 C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL [168304] (Microsoft Corporation) x64-Catalog9 01 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation) x64-Catalog9 02 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation) x64-Catalog9 03 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation) x64-Catalog9 04 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation) x64-Catalog9 05 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation) x64-Catalog9 06 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation) x64-Catalog9 07 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation) x64-Catalog9 08 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation) x64-Catalog9 09 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation) x64-Catalog9 10 C:\Windows\System32\mswsock.dll [326144] (Microsoft Corporation) ========================= Memory info: =================================== Percentage of memory in use: 35% Total physical RAM: 8190.12 MB Available physical RAM: 5281.39 MB Total Pagefile: 16378.42 MB Available Pagefile: 12843.76 MB Total Virtual: 4095.88 MB Available Virtual: 3972.04 MB ========================= Partitions: ===================================== 1 Drive c: () (Fixed) (Total:931.5 GB) (Free:795.37 GB) NTFS 2 Drive d: (STALKER) (CDROM) (Total:3.12 GB) (Free:0 GB) UDF ========================= Users: ======================================== Benutzerkonten fr \\BROWNEEH Administrator Gast Martin UpdatusUser Der Befehl wurde erfolgreich ausgefhrt. **** End of log **** |
![]() | #6 |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Virus verlangsamt Internetverbindung? Windows Repair Tool (AIO)
__________________ --> Virus verlangsamt Internetverbindung? |
![]() | #7 |
![]() | ![]() Virus verlangsamt Internetverbindung? Ausgeführt, neu gestartet und dann hat mir mein Pc erst angezeigt das Windows Defender und Avast aktiviert werden müssen. Hab dann nochmal neu gestartet und jetzt sind die Meldungen weg aber mein Pc läd sehr lang bei allen was ich mache, Firefox läd fast garnicht mehr richtig, als ob mein Pc gerade total ausgelastet und allem überfordert ist. Was nun? LG Browneeh |
![]() | #8 |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Virus verlangsamt Internetverbindung? ok: Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
![]() | #9 |
![]() | ![]() Virus verlangsamt Internetverbindung? FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-08-2013 Ran by Martin (administrator) on 08-08-2013 14:54:10 Running from C:\Users\Martin\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.) C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe () C:\Program Files (x86)\ASUS\Turbo Key\TurboKey.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Cm108Sound] - C:\Windows\Syswow64\cm108.dll [8146944 2012-04-10] (C-Media Corporation) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation) HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [7174728 2013-03-29] (Realtek Semiconductor) MountPoints2: {6349625f-b1d5-11e2-a0b4-806e6f6e6963} - D:\setup.exe HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [Turbo Key] - C:\Program Files (x86)\ASUS\Turbo Key\TurboKey.exe [1769472 2009-06-02] () HKLM-x32\...\Run: [DATAMNGR] - [x] HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-06-28] (LogMeIn Inc.) ==================== Internet (Whitelisted) ==================== BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) FireFox: ======== FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t13r4o26.default FF user.js: detected! => C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t13r4o26.default\user.js FF Homepage: hxxp://www.eliteanimes.com/profil/13339/Browneeh FF NetworkProxy: "type", 2 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.6 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1202122.dll (Adobe Systems, Inc.) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @unity3d.com/UnityPlayer,version=1.0 - C:\Users\Martin\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS) FF Plugin HKCU: pandonetworks.com/PandoWebPlugin - C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks) FF Extension: ProxTube - Gesperrte YouTube Videos entsperren - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t13r4o26.default\Extensions\{2541D29A-DB9E-4c1e-949A-31EFB4AEF4E7} FF Extension: No Name - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t13r4o26.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= R2 AsSysCtrlService; C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [90112 2009-08-20] (ASUSTeK Computer Inc.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) ==================== Drivers (Whitelisted) ==================== R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-05] () R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-05] () R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-06-27] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-06-27] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-06-27] () R3 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-05-29] (DT Soft Ltd) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-18] () S3 EagleX64; \??\C:\Windows\system32\drivers\EagleX64.sys [x] S3 VBoxNetFlt; system32\DRIVERS\VBoxNetFlt.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-08 14:53 - 2013-08-08 14:53 - 00000000 ____D C:\FRST 2013-08-08 13:58 - 2013-08-08 14:06 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-08-08 13:52 - 2013-08-08 13:52 - 00000207 _____ C:\Windows\tweaking.com-regbackup-BROWNEEH-Microsoft-Windows-7-Professional-(64-Bit).dat 2013-08-08 13:49 - 2013-08-08 13:51 - 01790059 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe 2013-08-08 13:26 - 2013-08-08 13:26 - 00001336 _____ C:\Users\Public\Desktop\DayZ Commander.lnk 2013-08-08 13:26 - 2013-08-08 13:26 - 00000000 ____D C:\Users\Martin\AppData\Local\DayZCommander 2013-08-08 13:26 - 2013-08-08 13:26 - 00000000 ____D C:\Program Files (x86)\Dotjosh Studios 2013-08-08 13:24 - 2013-08-08 13:24 - 02936832 _____ C:\Users\Martin\Downloads\Dotjosh.DayZCommander.Installer.msi 2013-08-08 01:45 - 2013-08-08 01:45 - 00000221 _____ C:\Users\Martin\Desktop\Arma 2 Operation Arrowhead.url 2013-08-07 21:55 - 2013-08-07 21:57 - 39328099 _____ C:\Users\Martin\Downloads\Slendytubbies V2 BETA 64bit -FIX.rar 2013-08-07 21:49 - 2013-08-08 14:32 - 00000000 ____D C:\Users\Martin\AppData\Local\LogMeIn Hamachi 2013-08-07 21:49 - 2013-08-07 21:49 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Unity 2013-08-07 21:49 - 2013-08-07 21:49 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-08-07 21:49 - 2009-03-18 18:35 - 00033856 ____H (LogMeIn, Inc.) C:\Windows\system32\hamachi.sys 2013-08-07 21:48 - 2013-08-07 21:49 - 00000926 _____ C:\Users\Public\Desktop\LogMeIn Hamachi.lnk 2013-08-07 21:47 - 2013-08-07 21:47 - 04292608 _____ C:\Users\Martin\Downloads\hamachi_2.1.0.362.msi 2013-08-06 16:42 - 2013-08-06 16:42 - 00000000 ____D C:\RegBackup 2013-08-06 16:41 - 2013-08-06 16:41 - 00002159 _____ C:\Users\Martin\Desktop\Tweaking.com - Windows Repair (All in One).lnk 2013-08-06 16:41 - 2013-08-06 16:41 - 00000000 ____D C:\Program Files (x86)\Tweaking.com 2013-08-06 16:40 - 2013-08-06 16:41 - 05373340 _____ C:\Users\Martin\Downloads\tweaking.com_windows_repair_aio_setup.exe 2013-08-06 16:39 - 2013-08-06 16:39 - 00000000 ____D C:\Users\Martin\Downloads\tweaking.com_windows_repair_aio 2013-08-06 16:28 - 2013-08-06 16:28 - 03517580 _____ C:\Users\Martin\Downloads\tweaking.com_windows_repair_aio.zip 2013-08-06 10:16 - 2013-07-12 20:23 - 00000000 ____D C:\Users\Martin\Downloads\left4gore-2.3-windows 2013-08-06 10:15 - 2013-08-06 10:15 - 00022202 _____ C:\Users\Martin\Downloads\left4gore-2.3-windows.zip 2013-08-06 09:51 - 2013-08-06 09:51 - 00000000 ____D C:\Windows\pss 2013-08-05 17:15 - 2013-08-05 17:15 - 00001166 _____ C:\Users\Public\Desktop\Elsword.lnk 2013-08-05 17:13 - 2013-08-05 17:13 - 00000000 ____D C:\Program Files (x86)\Gameforge4D 2013-08-05 15:12 - 2013-08-05 15:12 - 00029088 _____ C:\Users\Martin\AppData\Local\recently-used.xbel 2013-08-05 14:01 - 2013-08-05 16:25 - 2073283024 _____ (Gameforge4D ) C:\Users\Martin\Downloads\Elsword_DE_3.0313.7.1.exe 2013-08-05 14:01 - 2013-08-05 14:01 - 00344728 _____ (Gameforge 4D ) C:\Users\Martin\Downloads\Downloader_Elsword_de.exe 2013-08-04 18:48 - 2013-08-04 18:48 - 00011109 _____ C:\Users\Martin\Downloads\Result.txt 2013-08-04 18:45 - 2013-08-04 18:45 - 00760937 _____ (Farbar) C:\Users\Martin\Downloads\MiniToolBox.exe 2013-08-02 11:46 - 2013-08-02 11:46 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA 2013-08-01 11:44 - 2013-08-01 11:44 - 11983949 _____ (Softinventive Lab Inc. ) C:\Users\Martin\Downloads\tnm-setup.exe 2013-08-01 11:41 - 2013-08-01 11:41 - 00019281 _____ C:\Users\Martin\Downloads\NetTrafficMon.zip 2013-08-01 10:30 - 2013-08-01 10:30 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-08-01 10:30 - 2013-08-01 10:30 - 00000000 ____D C:\Program Files\Realtek 2013-08-01 10:29 - 2013-03-29 21:42 - 03379272 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHD64.sys 2013-08-01 10:29 - 2013-03-29 17:52 - 00914992 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll 2013-08-01 10:29 - 2013-03-26 17:06 - 02797128 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtPgEx64.dll 2013-08-01 10:29 - 2013-03-26 15:40 - 03693128 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO64.dll 2013-08-01 10:29 - 2013-03-26 14:38 - 01659464 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSnMg64.cpl 2013-08-01 10:29 - 2013-03-25 17:32 - 03180264 _____ C:\Windows\system32\Drivers\rtvienna.dat 2013-08-01 10:29 - 2013-03-20 13:16 - 02102040 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib64.dll 2013-08-01 10:29 - 2013-03-15 19:34 - 04957976 _____ (A-volute) C:\Windows\system32\RTKSMlfx.dll 2013-08-01 10:29 - 2013-03-15 19:33 - 00887640 _____ (A-Volute) C:\Windows\system32\RTKSMSettingsIPC.dll 2013-08-01 10:29 - 2013-02-27 05:37 - 00823072 _____ (SRS Labs, Inc.) C:\Windows\system32\slcnt64.dll 2013-08-01 10:29 - 2013-02-27 05:37 - 00633632 _____ (SRS Labs, Inc.) C:\Windows\system32\sltech64.dll 2013-08-01 10:29 - 2013-02-27 05:37 - 00517408 _____ (SRS Labs, Inc.) C:\Windows\system32\sl3apo64.dll 2013-08-01 10:29 - 2013-02-27 05:37 - 00213792 _____ (TODO: <Company name>) C:\Windows\system32\slprp64.dll 2013-08-01 10:29 - 2013-02-21 17:26 - 00858032 _____ (TOSHIBA Corporation) C:\Windows\system32\tossaeapo64.dll 2013-08-01 10:29 - 2013-02-21 17:26 - 00148912 _____ (TOSHIBA Corporation) C:\Windows\system32\toseaeapo64.dll 2013-08-01 10:29 - 2013-02-21 17:25 - 00569256 _____ (TOSHIBA Corporation) C:\Windows\system32\tosasfapo64.dll 2013-08-01 10:29 - 2013-02-19 18:52 - 00991816 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApi64.dll 2013-08-01 10:29 - 2012-01-30 11:43 - 00836544 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo264.dll 2013-08-01 10:29 - 2012-01-10 10:20 - 00065944 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\tepeqapo64.dll 2013-08-01 10:29 - 2011-12-20 15:32 - 00331880 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtlCPAPI64.dll 2013-08-01 10:29 - 2011-11-22 16:28 - 00014952 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR64.dll 2013-08-01 10:29 - 2011-09-02 14:21 - 00221024 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK64.dll 2013-08-01 10:29 - 2011-09-02 14:21 - 00081248 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM64.dll 2013-08-01 10:29 - 2011-09-02 14:21 - 00078688 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO64.dll 2013-08-01 10:29 - 2011-03-17 12:17 - 01361336 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll 2013-08-01 10:29 - 2011-03-07 17:11 - 00148416 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll 2013-08-01 10:29 - 2010-11-08 07:31 - 00375128 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP64A.dll 2013-08-01 10:29 - 2010-11-08 07:31 - 00101208 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL64A.dll 2013-08-01 10:29 - 2010-11-08 07:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG64A.dll 2013-08-01 10:29 - 2010-11-03 18:30 - 00149608 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCfg64.dll 2013-08-01 10:29 - 2010-07-22 16:48 - 00074064 _____ (Virage Logic Corporation / Sonic Focus) C:\Windows\SysWOW64\SFCOM.dll 2013-08-01 10:29 - 2009-11-24 09:55 - 00518896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSX64.dll 2013-08-01 10:29 - 2009-11-24 09:55 - 00211184 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSH64.dll 2013-08-01 10:29 - 2009-11-24 09:55 - 00198896 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP64.dll 2013-08-01 10:29 - 2009-11-24 09:55 - 00155888 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW64.dll 2013-08-01 10:28 - 2013-03-29 18:04 - 21170176 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes64.dat 2013-08-01 10:28 - 2013-03-29 17:10 - 00449481 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT 2013-08-01 10:28 - 2013-03-27 16:57 - 00135240 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoInstII64.dll 2013-08-01 10:28 - 2013-03-26 17:04 - 02734624 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO64.dll 2013-08-01 10:28 - 2013-03-23 03:43 - 00208072 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAC64.dll 2013-08-01 10:28 - 2013-03-20 13:17 - 09123608 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnA64.dll 2013-08-01 10:28 - 2013-03-20 13:16 - 01900312 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek264.dll 2013-08-01 10:28 - 2013-03-20 13:16 - 00910104 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell64.dll 2013-08-01 10:28 - 2013-03-12 18:16 - 00613448 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtDataProc64.dll 2013-08-01 10:28 - 2013-03-08 12:51 - 00904752 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll 2013-08-01 10:28 - 2013-02-28 13:10 - 14021912 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek64.dll 2013-08-01 10:28 - 2013-02-28 13:10 - 02032408 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ64.dll 2013-08-01 10:28 - 2013-02-20 18:55 - 01284680 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTCOM64.dll 2013-08-01 10:28 - 2013-01-17 19:32 - 00719640 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO5064.dll 2013-08-01 10:28 - 2012-12-12 11:17 - 00395208 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll 2013-08-01 10:28 - 2012-10-02 14:41 - 00501192 _____ (DTS) C:\Windows\system32\DTSU2PLFX64.dll 2013-08-01 10:28 - 2012-10-02 14:41 - 00487368 _____ (DTS) C:\Windows\system32\DTSU2PGFX64.dll 2013-08-01 10:28 - 2012-10-02 14:41 - 00415688 _____ (DTS) C:\Windows\system32\DTSU2PREC64.dll 2013-08-01 10:28 - 2012-09-10 20:06 - 00612728 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO4064.dll 2013-08-01 10:28 - 2012-08-31 19:18 - 07164176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP64A.dll 2013-08-01 10:28 - 2012-08-31 19:17 - 00434960 _____ (Dolby Laboratories) C:\Windows\system32\R4EED64A.dll 2013-08-01 10:28 - 2012-08-31 19:17 - 00141584 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL64A.dll 2013-08-01 10:28 - 2012-08-31 19:17 - 00124176 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA64A.dll 2013-08-01 10:28 - 2012-08-31 19:17 - 00075024 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG64A.dll 2013-08-01 10:28 - 2012-07-15 21:13 - 00394616 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll 2013-08-01 10:28 - 2012-06-20 17:26 - 00110592 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2013-08-01 10:28 - 2012-03-08 11:47 - 00108640 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTAR64.dll 2013-08-01 10:28 - 2011-08-23 17:00 - 00603984 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT64.dll 2013-08-01 10:28 - 2011-05-31 09:42 - 01756264 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL64.dll 2013-08-01 10:28 - 2011-05-31 09:42 - 01568360 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL64.dll 2013-08-01 10:28 - 2011-05-31 09:42 - 01486952 _____ (DTS) C:\Windows\system32\DTSBoostDLL64.dll 2013-08-01 10:28 - 2011-05-31 09:42 - 00728680 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL64.dll 2013-08-01 10:28 - 2011-05-31 09:42 - 00712296 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL64.dll 2013-08-01 10:28 - 2011-05-31 09:42 - 00693352 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL64.dll 2013-08-01 10:28 - 2011-05-31 09:42 - 00491112 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL64.dll 2013-08-01 10:28 - 2011-05-31 09:42 - 00432744 _____ (DTS) C:\Windows\system32\DTSLimiterDLL64.dll 2013-08-01 10:28 - 2011-05-31 09:42 - 00428648 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL64.dll 2013-08-01 10:28 - 2011-05-31 09:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSLFXAPO64.dll 2013-08-01 10:28 - 2011-05-31 09:42 - 00242792 _____ (DTS) C:\Windows\system32\DTSGFXAPO64.dll 2013-08-01 10:28 - 2011-05-31 09:42 - 00241768 _____ (DTS) C:\Windows\system32\DTSGFXAPONS64.dll 2013-08-01 10:28 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT64.dll 2013-08-01 10:28 - 2010-11-08 07:31 - 00310104 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA64.dll 2013-08-01 10:28 - 2010-11-08 07:31 - 00204120 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED64A.dll 2013-08-01 10:28 - 2010-09-27 09:34 - 00318808 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2013-08-01 10:23 - 2013-08-01 10:23 - 00000000 ____D C:\Users\Martin\Downloads\EyeToy_Driver_Logitech_x64 2013-08-01 10:15 - 2013-08-01 10:15 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-08-01 10:07 - 2013-06-21 14:06 - 27781920 _____ (NVIDIA Corporation) C:\Windows\system32\nvoglv64.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 25256224 _____ (NVIDIA Corporation) C:\Windows\system32\nvcompiler.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 21102368 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvoglv32.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 17560352 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcompiler.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 11235104 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvlddmkm.sys 2013-08-01 10:07 - 2013-06-21 14:06 - 09239344 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuda.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 07687592 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuda.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 07641832 _____ (NVIDIA Corporation) C:\Windows\system32\nvopencl.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 02953504 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvid.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 02777888 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvid.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 02363680 _____ (NVIDIA Corporation) C:\Windows\system32\nvcuvenc.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 02002720 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\nvcuvenc.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 01832224 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispco6432049.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 01511712 _____ (NVIDIA Corporation) C:\Windows\system32\nvdispgenco6432049.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 00572704 _____ (NVIDIA Corporation) C:\Windows\system32\NvFBC64.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 00570656 _____ (NVIDIA Corporation) C:\Windows\system32\NvIFR64.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 00467232 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvIFR.dll 2013-08-01 10:07 - 2013-06-21 14:06 - 00465184 _____ (NVIDIA Corporation) C:\Windows\SysWOW64\NvFBC.dll 2013-08-01 10:07 - 2013-02-25 07:27 - 00194848 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvhda64v.sys 2013-08-01 10:07 - 2013-02-25 07:27 - 00031520 _____ (NVIDIA Corporation) C:\Windows\system32\nvhdap64.dll 2013-08-01 09:42 - 2012-06-13 07:00 - 00726160 _____ (Realtek ) C:\Windows\system32\Drivers\Rt64win7.sys 2013-08-01 09:42 - 2012-06-13 07:00 - 00074344 _____ (Realtek Semiconductor Corporation) C:\Windows\system32\RtNicProp64.dll 2013-08-01 09:37 - 2013-08-01 09:37 - 00021712 _____ (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS 2013-08-01 09:37 - 2013-08-01 09:37 - 00000000 ____D C:\Users\Martin\AppData\Local\eSupport.com 2013-07-31 09:01 - 2013-07-31 09:01 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll 2013-07-29 09:48 - 2013-05-10 07:49 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\cryptdlg.dll 2013-07-29 09:48 - 2013-05-10 05:20 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll 2013-07-29 09:48 - 2013-04-26 01:30 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-07-29 09:48 - 2013-04-17 09:02 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2013-07-29 09:48 - 2013-04-17 08:24 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2013-07-29 09:48 - 2013-04-01 00:52 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-07-29 04:28 - 2013-07-29 04:28 - 00003548 _____ C:\Windows\System32\Tasks\IR5 2013-07-29 04:11 - 2012-11-23 18:15 - 00000000 ____D C:\Users\Martin\Downloads\Trilogy 4.2 2013-07-28 18:54 - 2013-07-28 18:54 - 00000221 _____ C:\Users\Martin\Desktop\Arma 2.url 2013-07-26 08:02 - 2013-07-26 08:01 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-07-26 08:01 - 2013-07-26 08:01 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-07-26 08:01 - 2013-07-26 08:01 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-07-26 08:01 - 2013-07-26 08:01 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-07-26 07:58 - 2013-07-26 07:58 - 00001066 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-07-26 07:52 - 2013-08-08 14:32 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-07-20 13:26 - 2013-07-20 13:26 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2013-07-18 17:56 - 2013-07-18 17:56 - 00000022 _____ C:\Users\Martin\Neues Textdokument (2).txt 2013-07-15 02:50 - 2013-07-16 13:45 - 00000000 ____D C:\Users\Martin\Downloads\coach_master_chief_160512_17028-L4D2 2013-07-13 19:53 - 2013-07-13 19:53 - 00000219 _____ C:\Users\Martin\Desktop\Left 4 Dead 2.url 2013-07-13 12:40 - 2013-07-13 12:54 - 00000049 _____ C:\Users\Martin\Neues Textdokument.txt 2013-07-10 10:41 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-10 10:41 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-10 10:41 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-10 10:41 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-10 10:41 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-10 10:41 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-10 10:41 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-10 10:41 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-10 10:41 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-10 10:41 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-10 10:41 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-10 10:41 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-10 10:41 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-10 10:41 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-10 10:41 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-10 10:40 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-10 10:40 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-10 10:40 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-10 10:40 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-10 10:40 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-10 10:40 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-10 10:40 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-10 10:40 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-10 10:40 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-10 10:40 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-10 10:40 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-10 10:40 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-10 10:40 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-10 10:40 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-10 10:40 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-10 10:40 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-10 06:40 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-10 06:40 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-10 06:40 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 06:40 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-10 06:39 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-10 06:38 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-10 06:38 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll ==================== One Month Modified Files and Folders ======= 2013-08-08 14:53 - 2013-08-08 14:53 - 00000000 ____D C:\FRST 2013-08-08 14:38 - 2013-04-30 22:41 - 01942075 _____ C:\Windows\WindowsUpdate.log 2013-08-08 14:32 - 2013-08-07 21:49 - 00000000 ____D C:\Users\Martin\AppData\Local\LogMeIn Hamachi 2013-08-08 14:32 - 2013-07-26 07:52 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-08-08 14:31 - 2013-05-01 06:43 - 00000000 ____D C:\ProgramData\NVIDIA 2013-08-08 14:31 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-08 14:31 - 2009-07-14 06:51 - 00037291 _____ C:\Windows\setupact.log 2013-08-08 14:29 - 2009-07-14 06:45 - 00017648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-08 14:29 - 2009-07-14 06:45 - 00017648 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-08 14:25 - 2013-05-01 06:31 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-08 14:14 - 2013-05-01 08:32 - 00696832 _____ C:\Windows\system32\perfh007.dat 2013-08-08 14:14 - 2013-05-01 08:32 - 00148128 _____ C:\Windows\system32\perfc007.dat 2013-08-08 14:14 - 2009-07-14 07:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-08 14:08 - 2013-05-01 06:45 - 00008412 _____ C:\Windows\PFRO.log 2013-08-08 14:06 - 2013-08-08 13:58 - 00181064 _____ (Sysinternals) C:\Windows\PSEXESVC.EXE 2013-08-08 14:05 - 2009-07-14 04:34 - 00000439 _____ C:\Windows\win.ini 2013-08-08 13:58 - 2013-05-01 13:33 - 00000000 ____D C:\Users\Martin\AppData\Local\PMB Files 2013-08-08 13:58 - 2013-05-01 13:33 - 00000000 ____D C:\ProgramData\PMB Files 2013-08-08 13:52 - 2013-08-08 13:52 - 00000207 _____ C:\Windows\tweaking.com-regbackup-BROWNEEH-Microsoft-Windows-7-Professional-(64-Bit).dat 2013-08-08 13:51 - 2013-08-08 13:49 - 01790059 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe 2013-08-08 13:50 - 2013-05-01 11:27 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Skype 2013-08-08 13:27 - 2013-05-01 13:21 - 00000000 ____D C:\Users\Martin\AppData\Roaming\TS3Client 2013-08-08 13:26 - 2013-08-08 13:26 - 00001336 _____ C:\Users\Public\Desktop\DayZ Commander.lnk 2013-08-08 13:26 - 2013-08-08 13:26 - 00000000 ____D C:\Users\Martin\AppData\Local\DayZCommander 2013-08-08 13:26 - 2013-08-08 13:26 - 00000000 ____D C:\Program Files (x86)\Dotjosh Studios 2013-08-08 13:24 - 2013-08-08 13:24 - 02936832 _____ C:\Users\Martin\Downloads\Dotjosh.DayZCommander.Installer.msi 2013-08-08 10:47 - 2013-05-01 12:12 - 00000000 ____D C:\Users\Martin\Downloads\ppl 2013-08-08 03:25 - 2013-05-01 11:44 - 00000000 ____D C:\Program Files (x86)\Steam 2013-08-08 01:45 - 2013-08-08 01:45 - 00000221 _____ C:\Users\Martin\Desktop\Arma 2 Operation Arrowhead.url 2013-08-08 01:45 - 2013-05-03 16:10 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Steam 2013-08-07 21:57 - 2013-08-07 21:55 - 39328099 _____ C:\Users\Martin\Downloads\Slendytubbies V2 BETA 64bit -FIX.rar 2013-08-07 21:49 - 2013-08-07 21:49 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Unity 2013-08-07 21:49 - 2013-08-07 21:49 - 00000000 ____D C:\Program Files (x86)\LogMeIn Hamachi 2013-08-07 21:49 - 2013-08-07 21:48 - 00000926 _____ C:\Users\Public\Desktop\LogMeIn Hamachi.lnk 2013-08-07 21:47 - 2013-08-07 21:47 - 04292608 _____ C:\Users\Martin\Downloads\hamachi_2.1.0.362.msi 2013-08-06 18:14 - 2013-05-01 06:03 - 00000000 ____D C:\Users\Martin 2013-08-06 18:12 - 2009-07-14 09:45 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-08-06 18:11 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration 2013-08-06 16:42 - 2013-08-06 16:42 - 00000000 ____D C:\RegBackup 2013-08-06 16:41 - 2013-08-06 16:41 - 00002159 _____ C:\Users\Martin\Desktop\Tweaking.com - Windows Repair (All in One).lnk 2013-08-06 16:41 - 2013-08-06 16:41 - 00000000 ____D C:\Program Files (x86)\Tweaking.com 2013-08-06 16:41 - 2013-08-06 16:40 - 05373340 _____ C:\Users\Martin\Downloads\tweaking.com_windows_repair_aio_setup.exe 2013-08-06 16:39 - 2013-08-06 16:39 - 00000000 ____D C:\Users\Martin\Downloads\tweaking.com_windows_repair_aio 2013-08-06 16:28 - 2013-08-06 16:28 - 03517580 _____ C:\Users\Martin\Downloads\tweaking.com_windows_repair_aio.zip 2013-08-06 10:15 - 2013-08-06 10:15 - 00022202 _____ C:\Users\Martin\Downloads\left4gore-2.3-windows.zip 2013-08-06 09:51 - 2013-08-06 09:51 - 00000000 ____D C:\Windows\pss 2013-08-05 17:15 - 2013-08-05 17:15 - 00001166 _____ C:\Users\Public\Desktop\Elsword.lnk 2013-08-05 17:13 - 2013-08-05 17:13 - 00000000 ____D C:\Program Files (x86)\Gameforge4D 2013-08-05 16:25 - 2013-08-05 14:01 - 2073283024 _____ (Gameforge4D ) C:\Users\Martin\Downloads\Elsword_DE_3.0313.7.1.exe 2013-08-05 15:12 - 2013-08-05 15:12 - 00029088 _____ C:\Users\Martin\AppData\Local\recently-used.xbel 2013-08-05 15:12 - 2013-05-01 15:49 - 00000000 ____D C:\Users\Martin\.gimp-2.8 2013-08-05 14:01 - 2013-08-05 14:01 - 00344728 _____ (Gameforge 4D ) C:\Users\Martin\Downloads\Downloader_Elsword_de.exe 2013-08-05 10:50 - 2013-05-01 13:21 - 00000000 ____D C:\Users\Martin\AppData\Local\TeamSpeak 3 Client 2013-08-04 18:48 - 2013-08-04 18:48 - 00011109 _____ C:\Users\Martin\Downloads\Result.txt 2013-08-04 18:45 - 2013-08-04 18:45 - 00760937 _____ (Farbar) C:\Users\Martin\Downloads\MiniToolBox.exe 2013-08-02 16:16 - 2013-05-01 11:27 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-08-02 16:16 - 2013-05-01 11:26 - 00000000 ____D C:\ProgramData\Skype 2013-08-02 11:46 - 2013-08-02 11:46 - 00000000 ____D C:\Users\Martin\AppData\Local\NVIDIA 2013-08-02 11:46 - 2013-05-01 09:43 - 00000000 ____D C:\ProgramData\NVIDIA Corporation 2013-08-01 11:44 - 2013-08-01 11:44 - 11983949 _____ (Softinventive Lab Inc. ) C:\Users\Martin\Downloads\tnm-setup.exe 2013-08-01 11:41 - 2013-08-01 11:41 - 00019281 _____ C:\Users\Martin\Downloads\NetTrafficMon.zip 2013-08-01 10:30 - 2013-08-01 10:30 - 00000000 ____D C:\Windows\SysWOW64\RTCOM 2013-08-01 10:30 - 2013-08-01 10:30 - 00000000 ____D C:\Program Files\Realtek 2013-08-01 10:28 - 2013-05-01 06:18 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information 2013-08-01 10:23 - 2013-08-01 10:23 - 00000000 ____D C:\Users\Martin\Downloads\EyeToy_Driver_Logitech_x64 2013-08-01 10:16 - 2013-05-01 06:42 - 00000000 ____D C:\Program Files (x86)\NVIDIA Corporation 2013-08-01 10:15 - 2013-08-01 10:15 - 00000000 ____D C:\Program Files (x86)\AGEIA Technologies 2013-08-01 10:10 - 2013-05-01 06:18 - 00000000 ____D C:\Program Files (x86)\Realtek 2013-08-01 10:06 - 2013-05-01 06:43 - 00000000 ____D C:\NVIDIA 2013-08-01 09:37 - 2013-08-01 09:37 - 00021712 _____ (Phoenix Technologies) C:\Windows\SysWOW64\Drivers\DrvAgent64.SYS 2013-08-01 09:37 - 2013-08-01 09:37 - 00000000 ____D C:\Users\Martin\AppData\Local\eSupport.com 2013-07-31 09:05 - 2013-05-03 16:12 - 00000000 ____D C:\Users\Public\Documents\STALKER-SHOC 2013-07-31 09:01 - 2013-07-31 09:01 - 00178800 _____ (Sony DADC Austria AG.) C:\Windows\SysWOW64\CmdLineExt_x64.dll 2013-07-29 04:28 - 2013-07-29 04:28 - 00003548 _____ C:\Windows\System32\Tasks\IR5 2013-07-28 18:54 - 2013-07-28 18:54 - 00000221 _____ C:\Users\Martin\Desktop\Arma 2.url 2013-07-26 08:01 - 2013-07-26 08:02 - 00263592 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-07-26 08:01 - 2013-07-26 08:01 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-07-26 08:01 - 2013-07-26 08:01 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-07-26 08:01 - 2013-07-26 08:01 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-07-26 08:01 - 2013-05-23 17:20 - 00867240 _____ (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll 2013-07-26 08:01 - 2013-05-23 17:20 - 00789416 _____ (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll 2013-07-26 08:01 - 2013-05-23 17:19 - 00000000 ____D C:\Program Files (x86)\Java 2013-07-26 07:58 - 2013-07-26 07:58 - 00001066 _____ C:\Users\Public\Desktop\VLC media player.lnk 2013-07-26 07:52 - 2013-05-01 07:22 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-07-24 04:11 - 2013-05-27 23:53 - 00000000 ____D C:\Users\Martin\AppData\Roaming\BitTorrent 2013-07-24 04:08 - 2013-07-08 15:59 - 00000000 ____D C:\Program Files (x86)\osu! 2013-07-24 04:07 - 2013-05-04 10:56 - 00000000 ____D C:\Users\Martin\Documents\My Games 2013-07-24 04:06 - 2013-05-12 11:28 - 00000000 ____D C:\Windows\system32\appmgmt 2013-07-24 01:17 - 2013-06-11 21:22 - 00000000 ____D C:\Program Files (x86)\LOLReplay 2013-07-20 13:26 - 2013-07-20 13:26 - 00000000 ____H C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf 2013-07-18 20:17 - 2009-07-14 07:08 - 00032632 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-07-18 17:56 - 2013-07-18 17:56 - 00000022 _____ C:\Users\Martin\Neues Textdokument (2).txt 2013-07-16 13:45 - 2013-07-15 02:50 - 00000000 ____D C:\Users\Martin\Downloads\coach_master_chief_160512_17028-L4D2 2013-07-13 19:53 - 2013-07-13 19:53 - 00000219 _____ C:\Users\Martin\Desktop\Left 4 Dead 2.url 2013-07-13 12:54 - 2013-07-13 12:40 - 00000049 _____ C:\Users\Martin\Neues Textdokument.txt 2013-07-12 20:23 - 2013-08-06 10:16 - 00000000 ____D C:\Users\Martin\Downloads\left4gore-2.3-windows 2013-07-12 10:21 - 2013-05-01 11:21 - 00000000 ____D C:\Users\Martin\AppData\Local\Adobe 2013-07-12 10:20 - 2013-05-01 06:31 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-07-12 10:19 - 2013-05-01 06:31 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-07-12 10:19 - 2013-05-01 06:31 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-07-10 10:53 - 2009-07-14 06:45 - 00280104 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-10 10:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-10 10:51 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-10 10:50 - 2009-07-14 09:47 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-10 10:43 - 2013-05-01 10:07 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-23 00:13 ==================== End Of Log ============================ --- --- --- Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-08-2013 Ran by Martin at 2013-08-08 14:54:37 Running from C:\Users\Martin\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= PnP Sound Device 7-Zip 9.22beta (x32) Adobe AIR (x32 Version: Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03) Adobe Shockwave Player 12.0 (x32 Version: Arma 2 (x32) Arma 2: Operation Arrowhead (x32) ATI Catalyst Install Manager (Version: 3.0.762.0) avast! Free Antivirus (x32 Version: 8.0.1489.0) CDBurnerXP (x32 Version: DAEMON Tools Lite (x32 Version: DayZ Commander (x32 Version: 0.92.85) Dead Island (x32) Dead Rising 2 (x32 Version: 1.0.0000.130) Dead Rising 2 (x32 Version: 1.0.0002.130) Elsword_DE (x32) EVEREST Ultimate Edition v5.50 (x32 Version: 5.50) FFHC Kasumi: Rebirth (x32) FormatFactory 3.0.1 (x32 Version: 3.0.1) Fraps (x32) GIMP 2.8.4 (Version: 2.8.4) HF pAppLoc version 1.0 (x32 Version: 1.0) Inkscape 0.48.4 (x32 Version: 0.48.4) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: League of Legends (x32 Version: 1.3) Left 4 Dead 2 (x32) LogMeIn Hamachi (x32 Version: LOLReplay (x32 Version: Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Games for Windows - LIVE (x32 Version: Microsoft Games for Windows - LIVE Redistributable (x32 Version: Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.51106 (x32 Version: 11.0.51106.1) Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106 (x32 Version: 11.0.51106.1) Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.51106 (Version: 11.0.51106) Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.51106 (Version: 11.0.51106) Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.51106 (x32 Version: 11.0.51106) Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.51106 (x32 Version: 11.0.51106) Microsoft Windows Application Compatibility Database Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) NVIDIA 3D Vision Controller-Treiber 320.49 (Version: 320.49) NVIDIA 3D Vision Treiber 320.49 (Version: 320.49) NVIDIA Display Control Panel (Version: NVIDIA GeForce Experience 1.5 (Version: 1.5) NVIDIA Grafiktreiber 320.49 (Version: 320.49) NVIDIA HD-Audiotreiber (Version: NVIDIA Install Application (Version: 2.1002.124.810) NVIDIA PhysX (x32 Version: 9.13.0604) NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604) NVIDIA Stereoscopic 3D Driver (x32 Version: NVIDIA Systemsteuerung 320.49 (Version: 320.49) NVIDIA Update 4.11.9 (Version: 4.11.9) NVIDIA Update Components (Version: 4.11.9) Pando Media Booster (x32 Version: piaip AppLocale (x32 Version: 1.0.0) Realtek Ethernet Controller Driver (x32 Version: 7.61.612.2012) Realtek High Definition Audio Driver (x32 Version: S.T.A.L.K.E.R. - Shadow of Chernobyl (x32 Version: 1.0000) Skype™ 6.6 (x32 Version: 6.6.106) Steam (x32 Version: swMSM (x32 Version: TeamSpeak 3 Client (HKCU Version: 3.0.11) TERA (x32 Version: 7) The Walking Dead (x32) Turbo Key (x32 Version: 1.00.13) Tweaking.com - Windows Repair (All in One) (x32 Version: 1.9.15) Unity Web Player (HKCU Version: ) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) VLC media player 2.0.6 (Version: 2.0.6) VLC media player 2.0.7 (x32 Version: 2.0.7) Windows Live ID Sign-in Assistant (Version: 6.500.3165.0) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 07-08-2013 19:48:06 Installed LogMeIn Hamachi 08-08-2013 11:26:20 Installed DayZ Commander 08-08-2013 11:50:58 Tweaking.com - Windows Repair ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {14D907C6-0755-41DE-A7F7-77B14A038464} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-12] (Adobe Systems Incorporated) Task: {2EB3EB7D-3F5D-443F-BE08-7C62A5C5973C} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2010-11-20] (Microsoft Corporation) Task: {34262C2F-1F31-42E2-8415-21BE2892F663} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {6AF784D3-22AE-4A3F-ACF7-391BA33B14FC} - System32\Tasks\{B7CC2BEC-C45A-4842-9096-463D70D5FD5F} => C:\Users\Martin\Downloads\Pizza_Tycoon\PIZZA\INSTALL.EXE No File Task: {6D67936A-F464-4095-B7C2-CA397EA7D1B1} - System32\Tasks\{EEC3AC8D-287A-4EF5-A3EC-03DCE3FC1A95} => C:\Users\Martin\Downloads\Pizza_Tycoon\PIZZA\INSTALL.EXE No File Task: {7DCE6478-6342-47B5-99B3-B87075D52291} - System32\Tasks\{08298FC7-9A11-4B86-82A3-61067BB96743} => C:\Users\Martin\Downloads\Pizza_Tycoon\PIZZA\INSTALL.EXE No File Task: {96A4C300-FF63-40EE-BEA5-3A2418DA4BBB} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-11-20] (Microsoft Corporation) Task: {CF618625-1403-43CF-AB20-9A21334EDCF5} - System32\Tasks\IR5 => C:\Windows\system32\cmd.exe [2010-11-20] (Microsoft Corporation) Task: {FD1C5916-89FC-4AC0-BEA0-27B6C51917D7} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Faulty Device Manager Devices ============= Name: EyeToy USB camera Namtai Description: EyeToy USB camera Namtai Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (08/07/2013 11:04:33 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_8_800_94.exe, Version: 11.8.800.94, Zeitstempel: 0x51c4d74d Name des fehlerhaften Moduls: FlashPlayerPlugin_11_8_800_94.exe, Version: 11.8.800.94, Zeitstempel: 0x51c4d74d Ausnahmecode: 0x40000015 Fehleroffset: 0x00017ae0 ID des fehlerhaften Prozesses: 0x19a8 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_11_8_800_94.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_11_8_800_94.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_11_8_800_94.exe2 Berichtskennung: FlashPlayerPlugin_11_8_800_94.exe3 Error: (08/06/2013 04:53:26 PM) (Source: System Restore) (User: ) Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\wbem\wmiprvse.exe; Beschreibung = Tweaking.com - Windows Repair; Fehler = 0x81000101). Error: (08/06/2013 10:34:58 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_8_800_94.exe, Version: 11.8.800.94, Zeitstempel: 0x51c4d74d Name des fehlerhaften Moduls: FlashPlayerPlugin_11_8_800_94.exe, Version: 11.8.800.94, Zeitstempel: 0x51c4d74d Ausnahmecode: 0x40000015 Fehleroffset: 0x00017ae0 ID des fehlerhaften Prozesses: 0xccc Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_11_8_800_94.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_11_8_800_94.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_11_8_800_94.exe2 Berichtskennung: FlashPlayerPlugin_11_8_800_94.exe3 Error: (08/05/2013 00:32:33 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_8_800_94.exe, Version: 11.8.800.94, Zeitstempel: 0x51c4d74d Name des fehlerhaften Moduls: FlashPlayerPlugin_11_8_800_94.exe, Version: 11.8.800.94, Zeitstempel: 0x51c4d74d Ausnahmecode: 0x40000015 Fehleroffset: 0x00017ae0 ID des fehlerhaften Prozesses: 0xc44 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_11_8_800_94.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_11_8_800_94.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_11_8_800_94.exe2 Berichtskennung: FlashPlayerPlugin_11_8_800_94.exe3 Error: (08/01/2013 05:00:38 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_8_800_94.exe, Version: 11.8.800.94, Zeitstempel: 0x51c4d74d Name des fehlerhaften Moduls: FlashPlayerPlugin_11_8_800_94.exe, Version: 11.8.800.94, Zeitstempel: 0x51c4d74d Ausnahmecode: 0x40000015 Fehleroffset: 0x00017ae0 ID des fehlerhaften Prozesses: 0x434 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_11_8_800_94.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_11_8_800_94.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_11_8_800_94.exe2 Berichtskennung: FlashPlayerPlugin_11_8_800_94.exe3 Error: (08/01/2013 00:52:16 AM) (Source: Application Hang) (User: ) Description: Programm rads_user_kernel.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 19a4 Startzeit: 01ce8e4011ce6339 Endzeit: 3 Anwendungspfad: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Berichts-ID: d62a0b6e-fa33-11e2-9cb1-3085a9b0f095 Error: (07/31/2013 10:04:51 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_8_800_94.exe, Version: 11.8.800.94, Zeitstempel: 0x51c4d74d Name des fehlerhaften Moduls: FlashPlayerPlugin_11_8_800_94.exe, Version: 11.8.800.94, Zeitstempel: 0x51c4d74d Ausnahmecode: 0x40000015 Fehleroffset: 0x00017ae0 ID des fehlerhaften Prozesses: 0x1734 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_11_8_800_94.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_11_8_800_94.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_11_8_800_94.exe2 Berichtskennung: FlashPlayerPlugin_11_8_800_94.exe3 Error: (07/31/2013 03:30:02 AM) (Source: Application Hang) (User: ) Description: Programm LolClient.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: e94 Startzeit: 01ce8d554e516c48 Endzeit: 8 Anwendungspfad: C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\\deploy\LolClient.exe Berichts-ID: b5a864d0-f980-11e2-97dd-3085a9b0f095 Error: (07/30/2013 05:47:15 AM) (Source: Application Hang) (User: ) Description: Programm rads_user_kernel.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1334 Startzeit: 01ce8cd774a2aa2c Endzeit: 2 Anwendungspfad: C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exe Berichts-ID: b616bb20-f8ca-11e2-80c9-3085a9b0f095 Error: (07/29/2013 03:37:08 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: LolClient.exe, Version:, Zeitstempel: 0x515663e0 Name des fehlerhaften Moduls: Adobe AIR.dll, Version:, Zeitstempel: 0x5156646c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0006dd76 ID des fehlerhaften Prozesses: 0x1aec Startzeit der fehlerhaften Anwendung: 0xLolClient.exe0 Pfad der fehlerhaften Anwendung: LolClient.exe1 Pfad des fehlerhaften Moduls: LolClient.exe2 Berichtskennung: LolClient.exe3 System errors: ============= Error: (08/08/2013 02:31:58 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Net.Tcp-Listeneradapter" ist vom Dienst "Net.Tcp-Portfreigabedienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/08/2013 02:31:58 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Net.Pipe-Listeneradapter" ist von folgendem Dienst abhängig: was. Dieser Dienst ist eventuell nicht installiert. Error: (08/08/2013 02:31:58 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Net.Msmq-Listeneradapter" ist von folgendem Dienst abhängig: msmq. Dieser Dienst ist eventuell nicht installiert. Error: (08/08/2013 02:15:44 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Error: (08/08/2013 02:10:59 PM) (Source: WMPNetworkSvc) (User: ) Description: WMPNetworkSvc0x80004005 Error: (08/08/2013 02:08:54 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Net.Tcp-Listeneradapter" ist vom Dienst "Net.Tcp-Portfreigabedienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (08/08/2013 02:08:54 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Net.Pipe-Listeneradapter" ist von folgendem Dienst abhängig: was. Dieser Dienst ist eventuell nicht installiert. Error: (08/08/2013 02:08:54 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Net.Msmq-Listeneradapter" ist von folgendem Dienst abhängig: msmq. Dieser Dienst ist eventuell nicht installiert. Error: (08/07/2013 09:50:00 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "LogMeIn Hamachi Tunneling Engine" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (08/07/2013 09:50:00 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst LogMeIn Hamachi Tunneling Engine erreicht. Microsoft Office Sessions: ========================= Error: (08/07/2013 11:04:33 PM) (Source: Application Error)(User: ) Description: FlashPlayerPlugin_11_8_800_94.exe11.8.800.9451c4d74dFlashPlayerPlugin_11_8_800_94.exe11.8.800.9451c4d74d4000001500017ae019a801ce93a79fe4c023C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exeC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exef4f1319b-ffa4-11e2-ad75-3085a9b0f095 Error: (08/06/2013 04:53:26 PM) (Source: System Restore)(User: ) Description: C:\Windows\system32\wbem\wmiprvse.exeTweaking.com - Windows Repair0x81000101 Error: (08/06/2013 10:34:58 AM) (Source: Application Error)(User: ) Description: FlashPlayerPlugin_11_8_800_94.exe11.8.800.9451c4d74dFlashPlayerPlugin_11_8_800_94.exe11.8.800.9451c4d74d4000001500017ae0ccc01ce927a3ec1de2aC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exeC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe13a406c6-fe73-11e2-a0ef-3085a9b0f095 Error: (08/05/2013 00:32:33 PM) (Source: Application Error)(User: ) Description: FlashPlayerPlugin_11_8_800_94.exe11.8.800.9451c4d74dFlashPlayerPlugin_11_8_800_94.exe11.8.800.9451c4d74d4000001500017ae0c4401ce91bf4156e70dC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exeC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe55ebe501-fdba-11e2-b8e9-3085a9b0f095 Error: (08/01/2013 05:00:38 AM) (Source: Application Error)(User: ) Description: FlashPlayerPlugin_11_8_800_94.exe11.8.800.9451c4d74dFlashPlayerPlugin_11_8_800_94.exe11.8.800.9451c4d74d4000001500017ae043401ce8e52202f8dabC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exeC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe8a900550-fa56-11e2-9cb1-3085a9b0f095 Error: (08/01/2013 00:52:16 AM) (Source: Application Hang)(User: ) Description: rads_user_kernel.exe0.0.0.019a401ce8e4011ce63393C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exed62a0b6e-fa33-11e2-9cb1-3085a9b0f095 Error: (07/31/2013 10:04:51 AM) (Source: Application Error)(User: ) Description: FlashPlayerPlugin_11_8_800_94.exe11.8.800.9451c4d74dFlashPlayerPlugin_11_8_800_94.exe11.8.800.9451c4d74d4000001500017ae0173401ce8dbe2e5645d1C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exeC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exedfb896a0-f9b7-11e2-9cb1-3085a9b0f095 Error: (07/31/2013 03:30:02 AM) (Source: Application Hang)(User: ) Description: LolClient.exe0.0.0.0e9401ce8d554e516c488C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\\deploy\LolClient.exeb5a864d0-f980-11e2-97dd-3085a9b0f095 Error: (07/30/2013 05:47:15 AM) (Source: Application Hang)(User: ) Description: rads_user_kernel.exe0.0.0.0133401ce8cd774a2aa2c2C:\Riot Games\League of Legends\RADS\system\rads_user_kernel.exeb616bb20-f8ca-11e2-80c9-3085a9b0f095 Error: (07/29/2013 03:37:08 AM) (Source: Application Error)(User: ) Description: LolClient.exe0.0.0.0515663e0Adobe AIR.dll3.7.0.15305156646cc00000050006dd761aec01ce8bf68cf053f6C:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\\deploy\LolClient.exeC:\Riot Games\League of Legends\RADS\projects\lol_air_client\releases\\deploy\Adobe AIR\Versions\1.0\Adobe AIR.dll60f13752-f7ef-11e2-b77f-3085a9b0f095 ==================== Memory info =========================== Percentage of memory in use: 21% Total physical RAM: 8190.12 MB Available physical RAM: 6442.31 MB Total Pagefile: 16378.42 MB Available Pagefile: 14426.69 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.5 GB) (Free:785.57 GB) NTFS (Disk=0 Partition=1) ==>[Drive with boot components (obtained from BCD)] Drive d: (STALKER) (CDROM) (Total:3.12 GB) (Free:0 GB) UDF ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 14D614D5) Partition 1: (Active) - (Size=932 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
![]() | #10 |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Virus verlangsamt Internetverbindung? hier: Downloade dir bitte ![]()
Poste bitte den Inhalt hier. |
![]() | #11 |
![]() | ![]() Virus verlangsamt Internetverbindung?Code:
ATTFilter Farbar Service Scanner Version: 04-08-2013 Ran by Martin (administrator) on 10-08-2013 at 13:16:52 Running from "C:\Users\Martin\Downloads" Microsoft Windows 7 Professional Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** |
![]() | #12 |
![]() | ![]() Virus verlangsamt Internetverbindung?Code:
ATTFilter Farbar Service Scanner Version: 04-08-2013 Ran by Martin (administrator) on 12-08-2013 at 15:41:27 Running from "C:\Users\Martin\Downloads" Microsoft Windows 7 Professional Service Pack 1 (X64) Boot Mode: Normal **************************************************************** Internet Services: ============ Connection Status: ============== Localhost is accessible. LAN connected. Google IP is accessible. Google.com is accessible. Yahoo.com is accessible. Windows Firewall: ============= Firewall Disabled Policy: ================== System Restore: ============ System Restore Disabled Policy: ======================== Action Center: ============ Windows Update: ============ Windows Autoupdate Disabled Policy: ============================ Windows Defender: ============== Other Services: ============== File Check: ======== C:\Windows\System32\nsisvc.dll => MD5 is legit C:\Windows\System32\drivers\nsiproxy.sys => MD5 is legit C:\Windows\System32\dhcpcore.dll => MD5 is legit C:\Windows\System32\drivers\afd.sys => MD5 is legit C:\Windows\System32\drivers\tdx.sys => MD5 is legit C:\Windows\System32\Drivers\tcpip.sys => MD5 is legit C:\Windows\System32\dnsrslvr.dll => MD5 is legit C:\Windows\System32\mpssvc.dll => MD5 is legit C:\Windows\System32\bfe.dll => MD5 is legit C:\Windows\System32\drivers\mpsdrv.sys => MD5 is legit C:\Windows\System32\SDRSVC.dll => MD5 is legit C:\Windows\System32\vssvc.exe => MD5 is legit C:\Windows\System32\wscsvc.dll => MD5 is legit C:\Windows\System32\wbem\WMIsvc.dll => MD5 is legit C:\Windows\System32\wuaueng.dll => MD5 is legit C:\Windows\System32\qmgr.dll => MD5 is legit C:\Windows\System32\es.dll => MD5 is legit C:\Windows\System32\cryptsvc.dll => MD5 is legit C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit C:\Windows\System32\ipnathlp.dll => MD5 is legit C:\Windows\System32\iphlpsvc.dll => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit **** End of log **** Edit: Ausversehen, übersehen das ich es schon gepostet habe. |
![]() | #13 |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Virus verlangsamt Internetverbindung? ok: Scan mit Combofix
![]() | #14 |
![]() | ![]() Virus verlangsamt Internetverbindung?Code:
ATTFilter ComboFix 13-08-19.02 - Martin 20.08.2013 7:31.1.4 - x64 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.12286.10467 [GMT 2:00] ausgeführt von:: c:\users\Martin\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\apppatch\AppLoc.exe c:\windows\apppatch\AppLocA.exe c:\windows\AppPatch\Custom\{deb7008b-681e-4a4a-8aae-cc833e8216ce}.sdb c:\windows\apppatch\unins000.dat c:\windows\apppatch\unins000.exe c:\windows\IsUn0407.exe c:\windows\SysWow64\frapsvid.dll . . ((((((((((((((((((((((( Dateien erstellt von 2013-07-20 bis 2013-08-20 )))))))))))))))))))))))))))))) . . 2013-08-20 05:37 . 2013-08-20 05:37 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-08-20 05:05 . 2013-08-20 05:05 76232 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{744ED4B7-88F7-4F3E-B2CF-EC8191985EF6}\offreg.dll 2013-08-17 13:33 . 2013-08-17 13:33 -------- d-----w- c:\users\Martin\AppData\Roaming\TERA 2013-08-16 06:06 . 2013-07-02 08:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{744ED4B7-88F7-4F3E-B2CF-EC8191985EF6}\mpengine.dll 2013-08-15 16:14 . 2013-08-15 16:17 -------- d-----w- c:\windows\system32\MRT 2013-08-15 05:02 . 2013-08-15 05:05 -------- d-----w- c:\program files (x86)\Google 2013-08-15 05:02 . 2013-08-15 05:05 -------- d-----w- c:\users\Martin\AppData\Local\Google 2013-08-15 00:16 . 2013-07-09 05:46 1472512 ----a-w- c:\windows\system32\crypt32.dll 2013-08-15 00:16 . 2013-07-09 04:46 1166848 ----a-w- c:\windows\SysWow64\crypt32.dll 2013-08-15 00:16 . 2013-07-09 05:52 224256 ----a-w- c:\windows\system32\wintrust.dll 2013-08-15 00:16 . 2013-07-09 04:52 175104 ----a-w- c:\windows\SysWow64\wintrust.dll 2013-08-15 00:16 . 2013-07-09 05:46 184320 ----a-w- c:\windows\system32\cryptsvc.dll 2013-08-15 00:16 . 2013-07-09 05:46 139776 ----a-w- c:\windows\system32\cryptnet.dll 2013-08-15 00:16 . 2013-07-09 04:46 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll 2013-08-15 00:16 . 2013-07-09 04:46 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll 2013-08-14 06:19 . 2013-08-17 14:08 -------- d-----w- c:\program files (x86)\TERA 2013-08-12 15:02 . 2013-08-12 15:02 -------- d-----w- c:\program files (x86)\Common Files\BattlEye 2013-08-12 14:56 . 2013-08-12 14:56 -------- d-----w- c:\programdata\Bohemia Interactive Studio 2013-08-12 14:22 . 2013-08-12 14:22 466456 ----a-w- c:\windows\system32\wrap_oal.dll 2013-08-12 14:22 . 2013-08-12 14:22 122904 ----a-w- c:\windows\system32\OpenAL32.dll 2013-08-12 14:22 . 2013-08-12 14:22 444952 ----a-w- c:\windows\SysWow64\wrap_oal.dll 2013-08-12 14:22 . 2013-08-12 14:22 -------- d-----w- c:\program files (x86)\OpenAL 2013-08-12 14:22 . 2013-08-12 14:22 109080 ----a-w- c:\windows\SysWow64\OpenAL32.dll 2013-08-12 14:06 . 2013-08-12 14:06 -------- d-----w- c:\program files (x86)\Eidos 2013-08-11 22:40 . 2013-08-11 23:25 -------- d-----w- c:\users\Martin\AppData\Roaming\Origin 2013-08-11 22:40 . 2013-08-12 13:21 -------- d-----w- c:\users\Martin\AppData\Local\Origin 2013-08-11 22:39 . 2013-08-11 23:25 -------- d-----w- c:\program files (x86)\Origin Games 2013-08-11 22:39 . 2013-08-11 23:25 -------- d-----w- c:\programdata\Origin 2013-08-11 22:39 . 2013-08-11 22:39 -------- d-----w- c:\programdata\Electronic Arts 2013-08-11 22:39 . 2013-08-13 12:38 -------- d-----w- c:\program files (x86)\Origin 2013-08-11 16:32 . 2013-08-11 16:32 -------- d-----w- c:\program files (x86)\Geeks3D 2013-08-09 15:55 . 2013-08-09 15:55 -------- d-----w- c:\programdata\ATI 2013-08-09 15:54 . 2013-08-09 15:54 -------- d-----w- c:\program files (x86)\AMD AVT 2013-08-09 15:27 . 2013-08-09 15:47 -------- d-----w- C:\AMD 2013-08-09 15:12 . 2013-08-09 15:12 -------- d-----w- c:\program files (x86)\HIS iTurbo 2013-08-09 14:56 . 2013-08-09 14:56 -------- d-----w- c:\users\Martin\AppData\Local\AMD 2013-08-09 14:55 . 2013-08-09 14:55 -------- d-----w- c:\users\Martin\AppData\Roaming\ATI 2013-08-09 14:55 . 2013-08-09 14:55 -------- d-----w- c:\users\Martin\AppData\Local\ATI 2013-08-09 14:54 . 2013-08-09 14:54 0 ----a-w- c:\windows\ativpsrm.bin 2013-08-09 14:52 . 2013-08-09 14:52 -------- d-----w- c:\program files\AMD 2013-08-09 14:52 . 2013-08-09 14:52 -------- d-----w- c:\program files (x86)\AMD 2013-08-09 14:52 . 2013-08-09 14:52 -------- d-----w- c:\program files\Common Files\ATI Technologies 2013-08-09 14:52 . 2013-08-09 14:52 -------- d-----w- c:\program files (x86)\Common Files\ATI Technologies 2013-08-09 14:50 . 2013-08-09 15:54 -------- d-----w- c:\programdata\AMD 2013-08-09 14:49 . 2013-03-29 02:13 1187342 ----a-w- c:\windows\system32\amdocl_as64.exe 2013-08-09 14:49 . 2013-03-29 02:13 1061902 ----a-w- c:\windows\system32\amdocl_ld64.exe 2013-08-09 14:49 . 2013-03-29 02:13 798734 ----a-w- c:\windows\SysWow64\amdocl_ld32.exe 2013-08-09 14:49 . 2013-03-29 02:13 995342 ----a-w- c:\windows\SysWow64\amdocl_as32.exe 2013-08-09 14:48 . 2013-08-09 14:48 -------- d-----w- c:\program files (x86)\ATI Technologies 2013-08-09 10:27 . 2013-08-13 18:40 -------- d-----w- c:\users\Martin\AppData\Local\ArmA 2 OA 2013-08-09 10:22 . 2013-08-09 10:23 -------- d-----w- c:\users\Martin\AppData\Local\ArmA 2 2013-08-08 12:53 . 2013-08-08 12:53 -------- d-----w- C:\FRST 2013-08-08 12:09 . 2013-08-16 23:22 -------- d-----w- c:\windows\system32\catroot2 2013-08-08 11:58 . 2013-08-08 12:06 181064 ----a-w- c:\windows\PSEXESVC.EXE 2013-08-08 11:26 . 2013-08-08 11:26 -------- d-----w- c:\users\Martin\AppData\Local\DayZCommander 2013-08-08 11:26 . 2013-08-08 11:26 -------- d-----w- c:\program files (x86)\Dotjosh Studios 2013-08-07 19:49 . 2009-03-18 16:35 33856 ---ha-w- c:\windows\system32\hamachi.sys 2013-08-07 19:49 . 2013-08-07 19:49 -------- d-----w- c:\program files (x86)\LogMeIn Hamachi 2013-08-07 19:49 . 2013-08-20 05:22 -------- d-----w- c:\users\Martin\AppData\Local\LogMeIn Hamachi 2013-08-07 19:49 . 2013-08-07 19:49 -------- d-----w- c:\users\Martin\AppData\Roaming\Unity 2013-08-06 14:52 . 2013-08-08 12:03 -------- d-----w- c:\windows\SysWow64\wbem\Performance 2013-08-06 14:42 . 2013-08-06 14:42 -------- d-----w- C:\RegBackup 2013-08-06 14:41 . 2013-08-06 14:41 -------- d-----w- c:\program files (x86)\Tweaking.com 2013-08-05 15:13 . 2013-08-05 15:13 -------- d-----w- c:\program files (x86)\Gameforge4D 2013-08-02 09:46 . 2013-08-09 15:00 -------- d-----w- c:\users\Martin\AppData\Local\NVIDIA 2013-08-01 08:30 . 2013-08-01 08:30 -------- d-----w- c:\windows\SysWow64\RTCOM 2013-08-01 08:30 . 2013-08-01 08:30 -------- d-----w- c:\program files\Realtek 2013-08-01 08:28 . 2013-03-29 16:04 21170176 ----a-w- c:\windows\system32\RCoRes64.dat 2013-08-01 07:42 . 2012-06-13 05:00 74344 ----a-w- c:\windows\system32\RtNicProp64.dll 2013-08-01 07:42 . 2012-06-13 05:00 726160 ----a-w- c:\windows\system32\drivers\Rt64win7.sys 2013-08-01 07:37 . 2013-08-01 07:37 21712 ----a-w- c:\windows\SysWow64\drivers\DrvAgent64.SYS 2013-08-01 07:37 . 2013-08-01 07:37 -------- d-----w- c:\users\Martin\AppData\Local\eSupport.com 2013-07-31 07:01 . 2013-07-31 07:01 178800 ----a-w- c:\windows\SysWow64\CmdLineExt_x64.dll 2013-07-29 07:48 . 2013-05-10 05:49 30720 ----a-w- c:\windows\system32\cryptdlg.dll 2013-07-29 07:48 . 2013-05-10 03:20 24576 ----a-w- c:\windows\SysWow64\cryptdlg.dll 2013-07-29 07:48 . 2013-04-17 07:02 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2013-07-29 07:48 . 2013-04-17 06:24 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2013-07-29 07:48 . 2013-04-25 23:30 1505280 ----a-w- c:\windows\SysWow64\d3d11.dll 2013-07-29 07:48 . 2013-03-31 22:52 1887232 ----a-w- c:\windows\system32\d3d11.dll 2013-07-26 06:03 . 2013-07-26 06:03 -------- d-----w- c:\program files (x86)\Common Files\Java 2013-07-26 06:01 . 2013-07-26 06:01 96168 ----a-w- c:\windows\SysWow64\WindowsAccessBridge-32.dll 2013-07-24 00:39 . 2013-07-24 00:39 157736 ----a-w- c:\windows\system32\amdhcp64.dll 2013-07-24 00:39 . 2013-07-24 00:39 142304 ----a-w- c:\windows\SysWow64\amdhcp32.dll 2013-07-24 00:39 . 2013-07-24 00:39 78432 ----a-w- c:\windows\system32\atimpc64.dll 2013-07-24 00:39 . 2013-07-24 00:39 78432 ----a-w- c:\windows\system32\amdpcom64.dll 2013-07-24 00:39 . 2013-07-24 00:39 71704 ----a-w- c:\windows\SysWow64\atimpc32.dll 2013-07-24 00:39 . 2013-07-24 00:39 71704 ----a-w- c:\windows\SysWow64\amdpcom32.dll 2013-07-24 00:39 . 2013-07-24 00:39 126336 ----a-w- c:\windows\SysWow64\atiuxpag.dll 2013-07-24 00:39 . 2013-07-24 00:39 98496 ----a-w- c:\windows\SysWow64\atiu9pag.dll 2013-07-24 00:39 . 2013-07-24 00:39 1043000 ----a-w- c:\windows\SysWow64\aticfx32.dll 2013-07-24 00:39 . 2013-07-24 00:39 9066784 ----a-w- c:\windows\system32\atidxx64.dll 2013-07-24 00:39 . 2013-07-24 00:39 7918816 ----a-w- c:\windows\SysWow64\atidxx32.dll 2013-07-24 00:38 . 2013-07-24 00:38 6475232 ----a-w- c:\windows\SysWow64\atiumdva.dll 2013-07-24 00:38 . 2013-07-24 00:38 6532912 ----a-w- c:\windows\SysWow64\atiumdag.dll 2013-07-24 00:36 . 2013-07-24 00:36 12721664 ----a-w- c:\windows\system32\drivers\atikmdag.sys 2013-07-24 00:19 . 2013-07-24 00:19 229376 ----a-w- c:\windows\system32\clinfo.exe 2013-07-24 00:18 . 2013-07-24 00:18 98816 ----a-w- c:\windows\system32\OpenVideo64.dll 2013-07-24 00:18 . 2013-07-24 00:18 83456 ----a-w- c:\windows\SysWow64\OpenVideo.dll 2013-07-24 00:18 . 2013-07-24 00:18 86528 ----a-w- c:\windows\system32\OVDecode64.dll 2013-07-24 00:18 . 2013-07-24 00:18 73216 ----a-w- c:\windows\SysWow64\OVDecode.dll 2013-07-24 00:18 . 2013-07-24 00:18 28193280 ----a-w- c:\windows\system32\amdocl64.dll 2013-07-24 00:16 . 2013-07-24 00:16 129536 ----a-w- c:\windows\system32\coinst_13.20.dll 2013-07-24 00:16 . 2013-07-24 00:16 23761408 ----a-w- c:\windows\SysWow64\amdocl.dll 2013-07-24 00:14 . 2013-07-24 00:14 63488 ----a-w- c:\windows\system32\OpenCL.dll 2013-07-24 00:14 . 2013-07-24 00:14 57344 ----a-w- c:\windows\SysWow64\OpenCL.dll 2013-07-24 00:04 . 2013-07-24 00:04 368640 ----a-w- c:\windows\system32\atiapfxx.exe 2013-07-24 00:03 . 2013-07-24 00:03 62464 ----a-w- c:\windows\system32\aticalrt64.dll 2013-07-24 00:03 . 2013-07-24 00:03 52224 ----a-w- c:\windows\SysWow64\aticalrt.dll 2013-07-24 00:03 . 2013-07-24 00:03 55808 ----a-w- c:\windows\system32\aticalcl64.dll 2013-07-24 00:03 . 2013-07-24 00:03 49152 ----a-w- c:\windows\SysWow64\aticalcl.dll 2013-07-24 00:03 . 2013-07-24 00:03 15716352 ----a-w- c:\windows\system32\aticaldd64.dll 2013-07-24 00:00 . 2013-07-24 00:00 25609728 ----a-w- c:\windows\system32\atio6axx.dll 2013-07-24 00:00 . 2013-07-24 00:00 14302208 ----a-w- c:\windows\SysWow64\aticaldd.dll 2013-07-23 23:42 . 2013-07-23 23:42 442368 ----a-w- c:\windows\system32\atidemgy.dll 2013-07-23 23:41 . 2013-07-23 23:41 26112 ----a-w- c:\windows\system32\atimuixx.dll 2013-07-23 23:41 . 2013-07-23 23:41 21624832 ----a-w- c:\windows\SysWow64\atioglxx.dll 2013-07-23 23:41 . 2013-07-23 23:41 574976 ----a-w- c:\windows\system32\atieclxx.exe 2013-07-23 23:40 . 2013-07-23 23:40 239616 ----a-w- c:\windows\system32\atiesrxx.exe 2013-07-23 23:39 . 2013-07-23 23:39 190976 ----a-w- c:\windows\system32\atitmm64.dll 2013-07-23 23:11 . 2013-07-23 23:11 1091584 ----a-w- c:\windows\system32\atiadlxx.dll 2013-07-23 23:11 . 2013-07-23 23:11 824320 ----a-w- c:\windows\SysWow64\atiadlxy.dll 2013-07-23 23:10 . 2013-07-23 23:10 75264 ----a-w- c:\windows\system32\atig6pxx.dll 2013-07-23 23:10 . 2013-07-23 23:10 69632 ----a-w- c:\windows\SysWow64\atiglpxx.dll 2013-07-23 23:10 . 2013-07-23 23:10 69632 ----a-w- c:\windows\system32\atiglpxx.dll 2013-07-23 23:10 . 2013-07-23 23:10 100352 ----a-w- c:\windows\system32\atig6txx.dll . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-15 16:14 . 2013-05-01 08:07 78161360 ----a-w- c:\windows\system32\MRT.exe 2013-07-26 06:01 . 2013-05-23 15:20 789416 ----a-w- c:\windows\SysWow64\deployJava1.dll 2013-07-26 06:01 . 2013-05-23 15:20 867240 ----a-w- c:\windows\SysWow64\npDeployJava1.dll 2013-07-24 00:39 . 2013-03-29 02:37 143304 ----a-w- c:\windows\system32\atiuxp64.dll 2013-07-24 00:39 . 2013-03-29 02:37 115512 ----a-w- c:\windows\system32\atiu9p64.dll 2013-07-24 00:39 . 2013-03-29 02:37 1251120 ----a-w- c:\windows\system32\aticfx64.dll 2013-07-24 00:38 . 2013-03-29 02:36 7093744 ----a-w- c:\windows\system32\atiumd6a.dll 2013-07-24 00:38 . 2013-03-29 02:36 7607720 ----a-w- c:\windows\system32\atiumd64.dll 2013-07-12 08:19 . 2013-05-01 04:31 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-07-12 08:19 . 2013-05-01 04:31 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-07-09 04:45 . 2013-08-15 00:15 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2013-07-05 08:40 . 2013-07-05 08:40 96256 ----a-w- c:\windows\system32\drivers\AtihdW76.sys 2013-07-05 08:40 . 2013-07-05 08:40 110080 ----a-w- c:\windows\system32\DelayAPO.dll 2013-06-27 19:13 . 2013-05-01 05:22 378944 ----a-w- c:\windows\system32\drivers\aswSP.sys 2013-06-27 19:13 . 2013-05-01 05:22 1030952 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2013-06-27 19:13 . 2013-05-01 05:22 189936 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-06-21 14:01 . 2013-07-02 05:51 238352 ----a-w- c:\windows\system32\drivers\VBoxDrv.sys 2013-06-21 14:00 . 2013-07-02 05:51 120080 ----a-w- c:\windows\system32\drivers\VBoxUSBMon.sys 2013-06-21 14:00 . 2013-06-21 14:00 204048 ------w- c:\windows\system32\VBoxNetFltNobj.dll 2013-06-21 14:00 . 2013-06-21 14:00 131856 ----a-w- c:\windows\system32\drivers\VBoxNetAdp.sys 2013-06-05 03:34 . 2013-07-10 04:39 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-06-04 06:00 . 2013-07-10 04:40 624128 ----a-w- c:\windows\system32\qedit.dll 2013-06-04 04:53 . 2013-07-10 04:40 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2013-05-29 00:49 . 2013-05-29 00:49 283200 ----a-w- c:\windows\system32\drivers\dtsoftbus01.sys . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1475584] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] "LogMeIn Hamachi Ui"="c:\program files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" [2013-06-28 2255184] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\amd64\CLIStart.exe" [2013-07-23 766208] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 BEService;BattlEye Service;c:\program files (x86)\Common Files\BattlEye\BEService.exe;c:\program files (x86)\Common Files\BattlEye\BEService.exe [x] R3 DrvAgent64;DrvAgent64;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS;c:\windows\SysWOW64\Drivers\DrvAgent64.SYS [x] R3 EagleX64;EagleX64;c:\windows\system32\drivers\EagleX64.sys;c:\windows\SYSNATIVE\drivers\EagleX64.sys [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetAdp.sys [x] R3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys;c:\windows\SYSNATIVE\DRIVERS\VBoxNetFlt.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AMD FUEL Service;AMD FUEL Service;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe;c:\program files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [x] S2 AODDriver4.2;AODDriver4.2;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys;c:\program files\ATI Technologies\ATI.ACE\Fuel\amd64\AODDriver2.sys [x] S2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 Hamachi2Svc;LogMeIn Hamachi Tunneling Engine;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe;c:\program files (x86)\LogMeIn Hamachi\hamachi-2.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM10864.sys;c:\windows\SYSNATIVE\drivers\CM10864.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2013-08-20 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-05-01 08:19] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 133840 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Cm108Sound"="c:\windows\Syswow64\cm108.dll" [2012-04-10 8146944] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RtkNGUI64.exe" [2013-03-29 7174728] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = FF - ProfilePath - c:\users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t13r4o26.default\ FF - prefs.js: browser.startup.homepage - hxxp://www.eliteanimes.com/profil/13339/Browneeh FF - prefs.js: network.proxy.type - 2 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKLM-Run-DATAMNGR - (no file) Wow6432Node-HKU-Default-RunOnce-SPReview - c:\windows\System32\SPReview\SPReview.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start AddRemove-BattlEye for A2 - c:\program files (x86)\Steam\steamapps\common\Arma 2BattlEye\UnInstallBE.exe AddRemove-BattlEye for OA - c:\program files (x86)\Steam\steamapps\common\Arma 2 Operation Arrowhead\Expansion\BattlEye\UnInstallBE.exe AddRemove-{9143B17E-BBDE-4EA7-A4E3-20D384D9C8A5}_is1 - c:\windows\AppPatch\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-08-20 07:39:51 ComboFix-quarantined-files.txt 2013-08-20 05:39 . Vor Suchlauf: 14 Verzeichnis(se), 822.381.436.928 Bytes frei Nach Suchlauf: 18 Verzeichnis(se), 822.484.869.120 Bytes frei . - - End Of File - - BC013009D5DD126BCCB93C138DCF48CA A36C5E4F47E84449FF07ED3517B43A31 |
![]() | #15 |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Virus verlangsamt Internetverbindung? Sorry! ESET Online Scanner
![]() |
Themen zu Virus verlangsamt Internetverbindung? |
andere, anderen, auskunft, bessere, center, d-lan, gelegt, geschickt, gezielt, immernoch, interne, internet, internetverbindung, keller, leitung, monate, parallel, relativ, schlechte verbindung, schlechtes, sekunden, uploadrate, verbindung, verlangsamt, virus, woche, wochen |