Alles rund um Windows: Allgemeiner Check - Wie kann ich meinen PC optimieren?
![]() | ![]() Problem: Allgemeiner Check - Wie kann ich meinen PC optimieren? Hey! Nachdem ich durch ein Problem an einem anderen PC um zu Helfen auf dieses Forum stieß würde ich nun auch meinen eigenen PC gerne optimieren. Über Optimierungsvorschläge in Programmwahl, Sicherheit etc. würde ich mich sehr freuen. Vielen Dank im Voraus! ![]() Im folgenden die Logs der ersten Scans, die man vor einer Themeneröffnung durchführen soll: Defogger: Code:
ATTFilter defogger_disable by jpshortstuff ( Log created at 11:17 on 03/08/2013 (Nora) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... SPTD -> Disabled (Service running -> reboot required) -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-08-2013 Ran by Nora (administrator) on 03-08-2013 11:31:06 Running from C:\Users\Nora\Desktop Windows 7 Ultimate Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (AMD) C:\Windows\system32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe (TuneUp Software) C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesApp64.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe () C:\Program Files (x86)\RocketDock\RocketDock.exe (Spotify Ltd) C:\Users\Nora\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Spotify Ltd) C:\Users\Nora\AppData\Roaming\Spotify\spotify.exe (Dropbox, Inc.) C:\Users\Nora\AppData\Roaming\Dropbox\bin\Dropbox.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_8_800_94.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Farbar) C:\Users\Nora\Desktop\FRST64(1).exe ==================== Registry (Whitelisted) ================== HKCU\...\Run: [RocketDock] - C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] () HKCU\...\Run: [Spotify Web Helper] - C:\Users\Nora\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-07] (Spotify Ltd) HKCU\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKCU\...\Run: [Spotify] - C:\Users\Nora\AppData\Roaming\Spotify\Spotify.exe [4640768 2013-07-07] (Spotify Ltd) HKCU\...\RunOnce: [FlashPlayerUpdate] - C:\Windows\system32\Macromed\Flash\FlashUtil64_11_7_700_224_ActiveX.exe -update activex [514952 2013-06-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-10-01] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS5ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe [406992 2010-02-22] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [345144 2013-06-27] (Avira Operations GmbH & Co. KG) IMEO\bootstrapper_0-uvdhqmap_.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe" IMEO\ccd-uninst.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe" IMEO\clonecd.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe" IMEO\clonecdtray.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe" IMEO\helplauncher.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe" IMEO\imbooster.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe" IMEO\regclonecd.exe: [Debugger] "C:\Program Files (x86)\TuneUp Utilities 2012\TUAutoReactivator64.exe" Startup: C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Nora\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) BHO-x32: Mein Gutscheincode - {11111111-1111-1111-1111-110211941181} - C:\Program Files (x86)\Mein Gutscheincode\Mein Gutscheincode-bho.dll (Mein Gutscheincode GmbH) BHO-x32: TubeSaver - {57F2FC14-BE99-4DFB-B9F1-2458A4F496AB} - C:\Program Files (x86)\TubeSaver\125.dll (istqt Soft) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\hhpinp0d.default FF user.js: detected! => C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\hhpinp0d.default\user.js FF Homepage: https://www.google.de/ FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll () FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF Plugin: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll () FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation) FF Plugin-x32: @java.com/JavaPlugin - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.) FF Plugin-x32: @microsoft.com/GENUINE - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.1 - D:\Programme\VLC\npvlc.dll (VideoLAN) FF SearchPlugin: C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\hhpinp0d.default\searchplugins\11-suche.xml FF SearchPlugin: C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\hhpinp0d.default\searchplugins\englische-ergebnisse.xml FF SearchPlugin: C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\hhpinp0d.default\searchplugins\gmx-suche.xml FF SearchPlugin: C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\hhpinp0d.default\searchplugins\lastminute.xml FF SearchPlugin: C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\hhpinp0d.default\searchplugins\webde-suche.xml FF Extension: No Name - C:\Users\Nora\AppData\Roaming\Mozilla\Extensions\celtx@celtx.com FF Extension: No Name - C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\hhpinp0d.default\Extensions\{19503e42-ca3c-4c27-b1e2-9cdb2170ee34}.xpi FF Extension: No Name - C:\Users\Nora\AppData\Roaming\Mozilla\Firefox\Profiles\hhpinp0d.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A} FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKCU\...\Firefox\Extensions: [Tubesaver@istqt.co] C:\Program Files (x86)\TubeSaver\125.xpi FF Extension: No Name - C:\Program Files (x86)\TubeSaver\125.xpi ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG) R2 TuneUp.UtilitiesSvc; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesService64.exe [2123584 2011-12-14] (TuneUp Software) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-06-10] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-06-10] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-06-10] (Avira Operations GmbH & Co. KG) R3 ElbyCDFL; C:\Windows\System32\Drivers\ElbyCDFL.sys [40648 2007-02-16] (SlySoft, Inc.) R3 ManyCam; C:\Windows\System32\DRIVERS\mcvidrv_x64.sys [34304 2012-01-11] (ManyCam LLC) R3 mcaudrv_simple; C:\Windows\System32\drivers\mcaudrv_x64.sys [28160 2012-02-22] (ManyCam LLC) R3 MTsensor; C:\Windows\System32\DRIVERS\ATK64AMD.sys [13680 2007-08-09] () S4 sptd; C:\Windows\System32\Drivers\sptd.sys [834544 2012-08-06] (Duplex Secure Ltd.) R3 TuneUpUtilitiesDrv; C:\Program Files (x86)\TuneUp Utilities 2012\TuneUpUtilitiesDriver64.sys [11856 2011-11-08] (TuneUp Software) U4 SR; S3 VGPU; System32\drivers\rdvgkmd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-03 11:29 - 2013-08-03 11:26 - 01781485 _____ (Farbar) C:\Users\Nora\Desktop\FRST64(1).exe 2013-08-03 11:26 - 2013-08-03 11:26 - 01781485 _____ (Farbar) C:\Users\Nora\Downloads\FRST64(1).exe 2013-08-03 11:17 - 2013-08-03 11:17 - 00000580 _____ C:\Users\Nora\Desktop\defogger_disable.log 2013-08-03 11:17 - 2013-08-03 11:17 - 00000020 _____ C:\Users\Nora\defogger_reenable 2013-08-03 10:30 - 2013-08-03 10:29 - 00050477 _____ C:\Users\Nora\Desktop\Defogger.exe 2013-08-03 10:29 - 2013-08-03 10:29 - 00050477 _____ C:\Users\Nora\Downloads\Defogger.exe 2013-08-03 10:13 - 2013-08-03 10:13 - 00000000 ____D C:\Program Files (x86)\TubeSaver 2013-08-03 09:05 - 2013-08-03 09:10 - 00006157 _____ C:\Windows\IE10_main.log 2013-08-03 08:50 - 2013-05-29 08:15 - 17829376 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-08-03 08:50 - 2013-05-29 07:50 - 10926080 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-08-03 08:50 - 2013-05-29 07:43 - 02312704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-08-03 08:50 - 2013-05-29 07:36 - 01346560 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-08-03 08:50 - 2013-05-29 07:35 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-08-03 08:50 - 2013-05-29 07:34 - 01494528 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-08-03 08:50 - 2013-05-29 07:33 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-08-03 08:50 - 2013-05-29 07:31 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-08-03 08:50 - 2013-05-29 07:29 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-08-03 08:50 - 2013-05-29 07:29 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-08-03 08:50 - 2013-05-29 07:29 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-08-03 08:50 - 2013-05-29 07:27 - 02147840 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-08-03 08:50 - 2013-05-29 07:27 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-08-03 08:50 - 2013-05-29 07:25 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-08-03 08:50 - 2013-05-29 07:25 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-08-03 08:50 - 2013-05-29 07:18 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-08-03 08:50 - 2013-05-29 03:56 - 12333568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-08-03 08:50 - 2013-05-29 03:50 - 01800704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-08-03 08:50 - 2013-05-29 03:48 - 09738752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-08-03 08:50 - 2013-05-29 03:41 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-08-03 08:50 - 2013-05-29 03:41 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-08-03 08:50 - 2013-05-29 03:41 - 01104384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-08-03 08:50 - 2013-05-29 03:40 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-08-03 08:50 - 2013-05-29 03:38 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-08-03 08:50 - 2013-05-29 03:37 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-08-03 08:50 - 2013-05-29 03:36 - 00420864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-08-03 08:50 - 2013-05-29 03:35 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-08-03 08:50 - 2013-05-29 03:35 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-08-03 08:50 - 2013-05-29 03:33 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-08-03 08:50 - 2013-05-29 03:33 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-08-03 08:50 - 2013-05-29 03:33 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-08-03 08:50 - 2013-05-29 03:29 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-19 02:05 - 2013-07-19 02:05 - 00003092 _____ C:\Windows\System32\Tasks\{57D0FE36-3BA4-41C4-AD52-2F4E7DAD63C2} 2013-07-18 10:41 - 2013-07-18 10:41 - 00003086 _____ C:\Windows\System32\Tasks\{2AB7090F-7109-4BE0-B3D0-18838F551201} 2013-07-18 10:41 - 2013-07-18 10:41 - 00003086 _____ C:\Windows\System32\Tasks\{2261156F-C9C3-48EA-A298-F9A47D926050} 2013-07-18 10:40 - 2013-07-18 10:40 - 00003086 _____ C:\Windows\System32\Tasks\{B6A28E56-BAE1-44EE-9F13-D721C60A0444} 2013-07-17 23:07 - 2013-07-17 23:07 - 00003034 _____ C:\Windows\System32\Tasks\{9ED3574B-2AD4-4838-A628-BA8F1E30D604} 2013-07-17 23:07 - 2013-07-17 23:07 - 00003028 _____ C:\Windows\System32\Tasks\{29ECDB01-AA39-4C02-A986-387686FCA4D0} 2013-07-13 14:31 - 2013-07-13 15:53 - 212202294 _____ C:\Users\Nora\Downloads\Entlassfeier Céline.zip 2013-07-10 10:44 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-10 10:44 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-10 10:44 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 10:44 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-10 10:32 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-10 10:28 - 2013-04-10 07:45 - 01545728 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-10 10:28 - 2013-04-10 07:02 - 01077760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-08 08:38 - 2013-07-08 08:38 - 00035135 _____ C:\Users\Nora\Desktop\Druck Zulassungsantrag.htm 2013-07-05 10:09 - 2013-07-05 10:09 - 00022148 _____ C:\Users\Nora\Downloads\Abi-godi-Akkorde.odt 2013-07-05 09:39 - 2013-07-05 10:56 - 164233693 _____ C:\Users\Nora\Downloads\Was ist Kultur.mp4 101 ==================== One Month Modified Files and Folders ======= 2013-08-03 11:30 - 2013-08-03 11:30 - 00000000 ____D C:\FRST 2013-08-03 11:30 - 2009-07-14 06:45 - 00021280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-03 11:30 - 2009-07-14 06:45 - 00021280 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-03 11:26 - 2013-08-03 11:29 - 01781485 _____ (Farbar) C:\Users\Nora\Desktop\FRST64(1).exe 2013-08-03 11:26 - 2013-08-03 11:26 - 01781485 _____ (Farbar) C:\Users\Nora\Downloads\FRST64(1).exe 2013-08-03 11:23 - 2011-12-27 17:18 - 01801176 _____ C:\Windows\WindowsUpdate.log 2013-08-03 11:22 - 2012-05-02 20:40 - 00000000 ____D C:\Users\Nora\AppData\Roaming\Dropbox 2013-08-03 11:21 - 2012-03-13 18:55 - 00000000 ____D C:\Users\Nora\AppData\Roaming\Spotify 2013-08-03 11:20 - 2012-05-02 20:44 - 00000000 ___RD C:\Users\Nora\Dropbox 2013-08-03 11:19 - 2013-07-02 14:00 - 00000370 _____ C:\Windows\Tasks\TubeSaver Update.job 2013-08-03 11:19 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-03 11:19 - 2009-07-14 06:51 - 00060338 _____ C:\Windows\setupact.log 2013-08-03 11:18 - 2010-11-21 05:47 - 00303342 _____ C:\Windows\PFRO.log 2013-08-03 11:17 - 2013-08-03 11:17 - 00000580 _____ C:\Users\Nora\Desktop\defogger_disable.log 2013-08-03 11:17 - 2013-08-03 11:17 - 00000020 _____ C:\Users\Nora\defogger_reenable 2013-08-03 11:17 - 2011-12-27 17:51 - 00000000 ____D C:\Users\Nora 2013-08-03 10:52 - 2012-04-17 20:59 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-08-03 10:29 - 2013-08-03 10:30 - 00050477 _____ C:\Users\Nora\Desktop\Defogger.exe 2013-08-03 10:29 - 2013-08-03 10:29 - 00050477 _____ C:\Users\Nora\Downloads\Defogger.exe 2013-08-03 10:28 - 2012-04-17 20:59 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-08-03 10:28 - 2011-04-12 09:43 - 00696870 _____ C:\Windows\system32\perfh007.dat 2013-08-03 10:28 - 2011-04-12 09:43 - 00148134 _____ C:\Windows\system32\perfc007.dat 2013-08-03 10:28 - 2009-07-14 07:13 - 01612484 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-03 10:27 - 2012-04-17 20:59 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-08-03 10:27 - 2011-12-27 18:01 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-08-03 10:18 - 2011-12-29 21:06 - 00000000 ____D C:\Users\Nora\AppData\Local\Adobe 2013-08-03 10:17 - 2012-01-05 19:09 - 00000000 ____D C:\Users\Nora\AppData\Roaming\Skype 2013-08-03 10:17 - 2012-01-05 19:08 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-08-03 10:17 - 2012-01-05 19:08 - 00000000 ____D C:\ProgramData\Skype 2013-08-03 10:13 - 2013-08-03 10:13 - 00000000 ____D C:\Program Files (x86)\TubeSaver 2013-08-03 10:13 - 2011-12-27 17:51 - 00000000 ___RD C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-08-03 10:13 - 2011-12-27 17:51 - 00000000 ___RD C:\Users\Nora\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2013-08-03 10:11 - 2009-07-14 06:45 - 04879176 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-03 10:08 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2013-08-03 10:08 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-08-03 09:18 - 2011-12-27 20:02 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-08-03 09:10 - 2013-08-03 09:05 - 00006157 _____ C:\Windows\IE10_main.log 2013-07-19 02:05 - 2013-07-19 02:05 - 00003092 _____ C:\Windows\System32\Tasks\{57D0FE36-3BA4-41C4-AD52-2F4E7DAD63C2} 2013-07-18 11:39 - 2012-03-13 19:02 - 00000000 ____D C:\Users\Nora\AppData\Local\Spotify 2013-07-18 10:41 - 2013-07-18 10:41 - 00003086 _____ C:\Windows\System32\Tasks\{2AB7090F-7109-4BE0-B3D0-18838F551201} 2013-07-18 10:41 - 2013-07-18 10:41 - 00003086 _____ C:\Windows\System32\Tasks\{2261156F-C9C3-48EA-A298-F9A47D926050} 2013-07-18 10:40 - 2013-07-18 10:40 - 00003086 _____ C:\Windows\System32\Tasks\{B6A28E56-BAE1-44EE-9F13-D721C60A0444} 2013-07-17 23:07 - 2013-07-17 23:07 - 00003034 _____ C:\Windows\System32\Tasks\{9ED3574B-2AD4-4838-A628-BA8F1E30D604} 2013-07-17 23:07 - 2013-07-17 23:07 - 00003028 _____ C:\Windows\System32\Tasks\{29ECDB01-AA39-4C02-A986-387686FCA4D0} 2013-07-16 00:40 - 2013-06-25 18:31 - 00017164 _____ C:\Users\Nora\Desktop\Sammelkiste.odt 2013-07-14 14:33 - 2012-04-02 22:26 - 00000000 ____D C:\Users\Nora\AppData\Roaming\vlc 2013-07-13 15:53 - 2013-07-13 14:31 - 212202294 _____ C:\Users\Nora\Downloads\Entlassfeier Céline.zip 2013-07-13 11:22 - 2013-06-30 22:50 - 00000000 ____D C:\Users\Nora\AppData\Roaming\Foxit Software 2013-07-11 13:53 - 2013-07-03 13:20 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-11 13:52 - 2012-04-30 20:37 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-07-11 13:50 - 2013-07-02 14:00 - 00003016 _____ C:\Windows\System32\Tasks\TubeSaver Update 2013-07-09 22:37 - 2011-12-27 17:51 - 00066488 _____ C:\Users\Nora\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-08 08:43 - 2013-04-06 13:46 - 00000432 _____ C:\Windows\BRWMARK.INI 2013-07-08 08:38 - 2013-07-08 08:38 - 00035135 _____ C:\Users\Nora\Desktop\Druck Zulassungsantrag.htm 2013-07-07 14:50 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache 2013-07-05 10:56 - 2013-07-05 09:39 - 164233693 _____ C:\Users\Nora\Downloads\Was ist Kultur.mp4 2013-07-05 10:09 - 2013-07-05 10:09 - 00022148 _____ C:\Users\Nora\Downloads\Abi-godi-Akkorde.odt 2013-07-04 16:28 - 2009-07-14 07:32 - 00000000 ____D C:\Windows\system32\FxsTmp 2013-07-04 16:26 - 2013-04-06 12:21 - 00000322 _____ C:\Windows\Brownie.ini ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe [2011-06-16 19:09] - [2011-06-18 01:30] - 2871808 ____A (Microsoft Corporation) 5740B1555D51D56547043181789027A5 C:\Windows\SysWOW64\explorer.exe [2011-06-16 19:09] - [2011-06-18 01:35] - 2616320 ____A (Microsoft Corporation) 88B413E78ADB75A062AB947C1BF6D49A C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-03 12:57 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-08-2013 Ran by Nora at 2013-08-03 11:32:42 Running from C:\Users\Nora\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 7-Zip 9.20 (x64 edition) (Version: Adobe AIR (x32 Version: Adobe Community Help (x32 Version: 3.0.0) Adobe Community Help (x32 Version: Adobe Creative Suite 5 Production Premium (x32 Version: 5.0) Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224) Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.94) Adobe Media Player (x32 Version: 1.8) Adobe Shockwave Player 11.6 (x32 Version: Adobe Shockwave Player 11.6 (x32 Version: AMD USB Filter Driver (x32 Version: ASUS Live Update (x32 Version: 3.0.6) ATI Catalyst Install Manager (Version: 3.0.745.0) Avira Free Antivirus (x32 Version: Brother HL-2030 (x32 Version: 1.00) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Core Implementation (x32 Version: 2009.1001.2247.39050) Catalyst Control Center Graphics Full Existing (x32 Version: 2009.1001.2247.39050) Catalyst Control Center Graphics Full New (x32 Version: 2009.1001.2247.39050) Catalyst Control Center Graphics Light (x32 Version: 2009.1001.2247.39050) Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.1001.2247.39050) Catalyst Control Center InstallProxy (x32 Version: 2009.1001.2247.39050) Catalyst Control Center Localization All (x32 Version: 2009.1001.2247.39050) CCC Help Chinese Standard (x32 Version: 2009.1001.2246.39050) CCC Help Chinese Traditional (x32 Version: 2009.1001.2246.39050) CCC Help Czech (x32 Version: 2009.1001.2246.39050) CCC Help Danish (x32 Version: 2009.1001.2246.39050) CCC Help Dutch (x32 Version: 2009.1001.2246.39050) CCC Help English (x32 Version: 2009.1001.2246.39050) CCC Help Finnish (x32 Version: 2009.1001.2246.39050) CCC Help French (x32 Version: 2009.1001.2246.39050) CCC Help German (x32 Version: 2009.1001.2246.39050) CCC Help Greek (x32 Version: 2009.1001.2246.39050) CCC Help Hungarian (x32 Version: 2009.1001.2246.39050) CCC Help Italian (x32 Version: 2009.1001.2246.39050) CCC Help Japanese (x32 Version: 2009.1001.2246.39050) CCC Help Korean (x32 Version: 2009.1001.2246.39050) CCC Help Norwegian (x32 Version: 2009.1001.2246.39050) CCC Help Polish (x32 Version: 2009.1001.2246.39050) CCC Help Portuguese (x32 Version: 2009.1001.2246.39050) CCC Help Russian (x32 Version: 2009.1001.2246.39050) CCC Help Spanish (x32 Version: 2009.1001.2246.39050) CCC Help Swedish (x32 Version: 2009.1001.2246.39050) CCC Help Thai (x32 Version: 2009.1001.2246.39050) CCC Help Turkish (x32 Version: 2009.1001.2246.39050) ccc-core-static (x32 Version: 2009.1001.2247.39050) ccc-utility64 (Version: 2009.1001.2247.39050) Celtx (2.9) (x32 Version: 2.9 (de)) CloneCD (x32) CPUID CPU-Z 1.61 Die Siedler II - Die nächste Generation (x32) Dropbox (HKCU Version: 2.0.22) eaner (Version: 3.07) Foxit Reader (x32 Version: HashCheck Shell Extension (x86-32) (x32 Version: HashCheck Shell Extension (x86-64) (Version: ICQ7.7 (x32 Version: 7.7) Imagebatch Resizer 1.3 (x32) ImgBurn (x32 Version: Java Auto Updater (x32 Version: Java(TM) 6 Update 22 (x32 Version: 6.0.220) Java(TM) 6 Update 26 (64-bit) (Version: 6.0.260) Java(TM) 6 Update 31 (x32 Version: 6.0.310) JDownloader (x32 Version: 0.9.581) K-Lite Codec Pack (64-bit) v4.7.0 (Version: 4.7.0) K-Lite Mega Codec Pack 7.2.0 (x32 Version: 7.2.0) ManyCam 3.0.80 (remove only) (x32 Version: 3.0.80) Mein Gutscheincode (x32 Version: Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft Camera Codec Pack (Version: 16.4.1620.0719) Microsoft Silverlight (Version: 5.1.20125.0) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft_VC80_ATL_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_ATL_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_CRT_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFC_x86_x64 (Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86 (x32 Version: 8.0.50727.4053) Microsoft_VC80_MFCLOC_x86_x64 (Version: 80.50727.4053) Microsoft_VC90_ATL_x86 (x32 Version: 1.00.0000) Microsoft_VC90_ATL_x86_x64 (Version: 1.00.0000) Microsoft_VC90_CRT_x86 (x32 Version: 1.00.0000) Microsoft_VC90_CRT_x86_x64 (Version: 1.00.0000) Microsoft_VC90_MFC_x86 (x32 Version: 1.00.0000) Microsoft_VC90_MFC_x86_x64 (Version: 1.00.0000) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) Notepad++ (x32 Version: 5.9.2) OpenOffice.org 3.3 (x32 Version: 3.3.9567) PC Suite (x32 Version: 12.09.106) PDF Settings CS5 (x32 Version: 10.0) RocketDock 1.3.5 (x32) Skype Click to Call (x32 Version: 5.9.9216) Skype™ 6.6 (x32 Version: 6.6.106) SpeedCommander 13 (x64) (Version: 13.50.16400) Spotify (HKCU Version: SUPER © +Recorder.2013.55 (Mar 7, 2013) Version +Recorder.2013. (x32 Version: +Recorder.2013.55) swMSM (x32 Version: TubeSaver (x32) TuneUp Utilities 2012 (x32 Version: 12.0.2160.11) TuneUp Utilities Language Pack (de-DE) (x32 Version: 12.0.2160.11) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Vista Game Explorer Editor (x32 Version: Beta 2.14a) VLC media player 2.0.1 (x32 Version: 2.0.1) WeatherBug Alert (x32 Version: WinRAR 4.01 (64-Bit) (Version: 4.01.0) ==================== Restore Points ========================= 29-06-2013 17:02:22 Windows Update 29-06-2013 18:03:31 Removed Adobe Reader XI - Deutsch. 07-07-2013 12:46:37 Geplanter Prüfpunkt 03-08-2013 06:35:36 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2012-08-06 11:58 - 00000922 ____A C:\Windows\system32\Drivers\etc\hosts activate.adobe.com practivate.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {04D9917E-A9F3-4CF0-A744-E297DF2CE47E} - System32\Tasks\{2AB7090F-7109-4BE0-B3D0-18838F551201} => c:\program files (x86)\mozilla firefox\firefox.exe [2013-07-03] (Mozilla Corporation) Task: {083D3871-4750-4012-BE21-E860505E46D4} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-08-31] (ASUSTeK Computer Inc.) Task: {17490ABC-2572-4CDF-8BA5-531F99434F69} - System32\Tasks\TuneUpUtilities_Task_BkGndMaintenance2012 => C:\Program Files (x86)\TuneUp Utilities 2012\OneClick.exe [2011-12-14] (TuneUp Software) Task: {33F78884-5BEB-47B2-8555-C611491184DD} - System32\Tasks\{9ED3574B-2AD4-4838-A628-BA8F1E30D604} => c:\program files (x86)\mozilla firefox\firefox.exe [2013-07-03] (Mozilla Corporation) Task: {4E69F852-24DC-4159-B61B-2FA87E7E2793} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe No File Task: {65F0D4E9-776E-4A82-9146-4F0B16D39992} - System32\Tasks\AdobeAAMUpdater-1.0-Nora-PC-Nora => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [2010-03-06] (Adobe Systems Incorporated) Task: {6AC058D2-8822-45D6-87C7-6693C0ACB70E} - System32\Tasks\{57D0FE36-3BA4-41C4-AD52-2F4E7DAD63C2} => c:\program files (x86)\mozilla firefox\firefox.exe [2013-07-03] (Mozilla Corporation) Task: {6C6DDC97-6210-468D-9137-70286B138D11} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2011-04-08] (Sun Microsystems, Inc.) Task: {9680C83E-AE31-4928-8643-088FA8F36F72} - System32\Tasks\TubeSaver Update => C:\Program Files (x86)\TubeSaver\tbsUd.exe [2013-07-27] (istqt Soft) Task: {A1D60D55-A6B8-401B-BC05-2938E02DF2F2} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => d:\program files\windows defender\MpCmdRun.exe No File Task: {A923965C-F1AF-42B8-8F7C-0FCDD8ABE597} - System32\Tasks\{2261156F-C9C3-48EA-A298-F9A47D926050} => c:\program files (x86)\mozilla firefox\firefox.exe [2013-07-03] (Mozilla Corporation) Task: {C32FBC72-F53F-4832-8723-DF2713B8D066} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-08-03] (Adobe Systems Incorporated) Task: {C4E8B14A-4159-4C58-BDAD-281DBBFC97E8} - System32\Tasks\Microsoft\Windows Defender\MpIdleTask => d:\program files\windows defender\MpCmdRun.exe No File Task: {D9124431-EF29-4674-A9F2-9AFCA32A3974} - System32\Tasks\{29ECDB01-AA39-4C02-A986-387686FCA4D0} => c:\program files (x86)\mozilla firefox\firefox.exe [2013-07-03] (Mozilla Corporation) Task: {DE29F206-0286-4FE3-9DBD-D1257DB6C60E} - System32\Tasks\{B6A28E56-BAE1-44EE-9F13-D721C60A0444} => c:\program files (x86)\mozilla firefox\firefox.exe [2013-07-03] (Mozilla Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\TubeSaver Update.job => C:\Program Files (x86)\TubeSaver\tbsUd.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/03/2013 11:20:36 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/03/2013 10:18:25 AM) (Source: MsiInstaller) (User: Nora-PC) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (08/03/2013 10:18:24 AM) (Source: MsiInstaller) (User: Nora-PC) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (08/03/2013 10:18:23 AM) (Source: MsiInstaller) (User: Nora-PC) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (08/03/2013 10:18:14 AM) (Source: MsiInstaller) (User: Nora-PC) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (08/03/2013 10:12:08 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/03/2013 08:27:52 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: FlashPlayerPlugin_11_7_700_224.exe, Version: 11.7.700.224, Zeitstempel: 0x51a67447 Name des fehlerhaften Moduls: unknown, Version:, Zeitstempel: 0x00000000 Ausnahmecode: 0xc0000005 Fehleroffset: 0x00000000 ID des fehlerhaften Prozesses: 0x1d30 Startzeit der fehlerhaften Anwendung: 0xFlashPlayerPlugin_11_7_700_224.exe0 Pfad der fehlerhaften Anwendung: FlashPlayerPlugin_11_7_700_224.exe1 Pfad des fehlerhaften Moduls: FlashPlayerPlugin_11_7_700_224.exe2 Berichtskennung: FlashPlayerPlugin_11_7_700_224.exe3 Error: (07/07/2013 09:40:09 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (07/07/2013 02:41:42 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (07/03/2013 08:48:45 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. System errors: ============= Error: (08/03/2013 10:25:41 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst LanmanServer erreicht. Error: (08/03/2013 09:34:04 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft .NET Framework 4 unter Windows XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows Server 2008 R2 für x64-basierte Systeme (KB2840628) Error: (08/03/2013 09:10:26 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Internet Explorer 10 für Windows 7 für x64-basierte Systeme Error: (08/03/2013 09:04:34 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft .NET Framework 4 unter Windows XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows Server 2008 R2 für x64-basierte Systeme (KB2804576) Error: (08/03/2013 08:50:21 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft .NET Framework 4 unter Windows XP, Windows Server 2003, Windows Vista, Windows 7, Windows Server 2008, Windows Server 2008 R2 für x64-basierte Systeme (KB2835393) Error: (08/03/2013 08:39:12 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Sicherheitsupdate für Microsoft Silverlight (KB2847559) Error: (07/15/2013 01:09:56 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WSearch erreicht. Error: (07/15/2013 01:09:26 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst LanmanServer erreicht. Error: (07/14/2013 07:57:12 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst WSearch erreicht. Error: (07/14/2013 07:56:42 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst LanmanServer erreicht. Microsoft Office Sessions: ========================= Error: (08/03/2013 11:20:36 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/03/2013 10:18:25 AM) (Source: MsiInstaller)(User: Nora-PC) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (08/03/2013 10:18:24 AM) (Source: MsiInstaller)(User: Nora-PC) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (08/03/2013 10:18:23 AM) (Source: MsiInstaller)(User: Nora-PC) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (08/03/2013 10:18:14 AM) (Source: MsiInstaller)(User: Nora-PC) Description: Product: Skype Click to Call -- Error 1609. An error occurred while applying security settings. Users is not a valid user or group. This could be a problem with the package, or a problem connecting to a domain controller on the network. Check your network connection and click Retry, or Cancel to end the install. Unable to locate the user's SID, system error 1332(NULL)(NULL)(NULL)(NULL)(NULL) Error: (08/03/2013 10:12:08 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/03/2013 08:27:52 AM) (Source: Application Error)(User: ) Description: FlashPlayerPlugin_11_7_700_224.exe11.7.700.22451a67447unknown0.0.0.000000000c0000005000000001d3001ce818e2d186768C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exeunknownd2f77fb3-fc05-11e2-ad84-00261888daeb Error: (07/07/2013 09:40:09 PM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (07/07/2013 02:41:42 PM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllC:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (07/03/2013 08:48:45 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Users\Nora\Downloads\SoftonicDownloader_fuer_office-2007-service-pack.exe ==================== Memory info =========================== Percentage of memory in use: 47% Total physical RAM: 3839.12 MB Available physical RAM: 2017.09 MB Total Pagefile: 7676.42 MB Available Pagefile: 5536.59 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (VistaOS) (Fixed) (Total:149.04 GB) (Free:77.77 GB) NTFS (Disk=0 Partition=2) ==>[Drive with boot components (obtained from BCD)] Drive d: (DATA) (Fixed) (Total:137.33 GB) (Free:25.18 GB) NTFS (Disk=0 Partition=3) Drive f: () (Removable) (Total:3.66 GB) (Free:2.66 GB) FAT32 (Disk=2 Partition=1) Drive k: (HDDRIVE2GO) (Fixed) (Total:1862.56 GB) (Free:1307 GB) FAT32 (Disk=1 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 97646C29) Partition 1: (Not Active) - (Size=12 GB) - (Type=1C) Partition 2: (Active) - (Size=149 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=137 GB) - (Type=OF Extended) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 1863 GB) (Disk ID: 21450836) Partition 1: (Active) - (Size=-198626508800) - (Type=0C) ======================================================== Disk: 2 (Size: 4 GB) (Disk ID: 00000000) Partition 1: (Not Active) - (Size=4 GB) - (Type=0B) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-08-03 11:55:45 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST9320325AS rev.0002SDM1 298,09GB Running: 2ztyyo3s.exe; Driver: C:\Users\Nora\AppData\Local\Temp\kwtdqpow.sys ---- Kernel code sections - GMER 2.1 ---- INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 560 fffff80002e01000 10 bytes [0A, 00, C7, 41, 68, 01, 00, ...] INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 577 fffff80002e01011 15 bytes [89, 5C, 24, 18, 44, 89, 4C, ...] .text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000123e00 7 bytes [00, A3, F3, FF, 01, AF, F0] .text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff96000123e08 3 bytes [C0, 06, 02] ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\RocketDock\RocketDock.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076eb1465 2 bytes {JMP 0x78} .text C:\Program Files (x86)\RocketDock\RocketDock.exe[2360] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076eb14bb 2 bytes {JMP 0x78} .text ... * 2 .text C:\Users\Nora\AppData\Roaming\Dropbox\bin\Dropbox.exe[2452] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076eb1465 2 bytes {JMP 0x78} .text C:\Users\Nora\AppData\Roaming\Dropbox\bin\Dropbox.exe[2452] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076eb14bb 2 bytes {JMP 0x78} .text ... * 2 .text C:\Users\Nora\Desktop\2ztyyo3s.exe[4512] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000076eb1465 2 bytes {JMP 0x78} .text C:\Users\Nora\Desktop\2ztyyo3s.exe[4512] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000076eb14bb 2 bytes {JMP 0x78} .text ... * 2 ---- Threads - GMER 2.1 ---- Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [1752:684] 00000000755f7587 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [1752:660] 0000000062f50cb3 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [1752:4328] 0000000077c82e25 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [1752:4808] 0000000077c83e45 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [1752:2168] 0000000077c83e45 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [1752:3844] 0000000077c83e45 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\ Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x29 0x37 0x63 0x82 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD7 0x1C 0x97 0x5A ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x00 0xBB 0x56 0xAE ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xEB 0xA5 0xEB 0x37 ... Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 Reg HKLM\SYSTEM\CurrentControlSet\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0xD2 0x0B 0xFB 0x98 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@p0 C:\Program Files (x86)\DAEMON Tools Lite\ Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@u0 0x00 0x00 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@h0 0 Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC@hdf12 0x29 0x37 0x63 0x82 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@a0 0x20 0x01 0x00 0x00 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001@hdf12 0xD7 0x1C 0x97 0x5A ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq0@hdf12 0x00 0xBB 0x56 0xAE ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq1@hdf12 0xEB 0xA5 0xEB 0x37 ... Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\sptd\Cfg\14919EA49A8F3B4AA3CF1058D9A64CEC\00000001\gdq2@hdf12 0xD2 0x0B 0xFB 0x98 ... ---- EOF - GMER 2.1 ---- |
/// Malwareteam
__________________Keine gecrackte Software verwenden! ![]()
/// Malwareteam
![]() | ![]() Allgemeiner Check - Wie kann ich meinen PC optimieren? Details Vielen Dank, wenn du dir meine Logs angeschaut hättest, hättest du vielleicht erkannt, dass ich das nicht tue. (Jedenfalls nicht bewusst!)
/// Malwareteam
/// Malwareteam ![]() ![]() ![]() ![]() | ![]() Lösung: Allgemeiner Check - Wie kann ich meinen PC optimieren?Zitat:
Schmeiß alles an illegaler Software runter, dann sehen wir weiter!
/// Malwareteam
![]() | ![]() Wie Allgemeiner Check - Wie kann ich meinen PC optimieren? Könntest du mir vielleicht sagen, was auf meinem PC illegal ist? |
/// Malwareteam
__________________ --> Allgemeiner Check - Wie kann ich meinen PC optimieren? |
