![]() |
|
Plagegeister aller Art und deren Bekämpfung: alle Antiviren Syteme aus und alles ist extrem langsamWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() alle Antiviren Syteme aus und alles ist extrem langsam Wenn Du im Admin Account bist und FRST im normalen Modus startest sollte es funktionieren. Ich brauche ein Log aus dem normalen Modus.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #2 |
![]() ![]() | ![]() alle Antiviren Syteme aus und alles ist extrem langsam War im Admin Account musste aber trotzdem als Admin asuführen machen.
__________________Ging also nicht. Habs jez nochmal so gemacht wie du es mir in einer der vorherigen Antworten gesagt hast. Hoffe das passt so. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-11-2013 Ran by SYSTEM on MININT-EVES5UR on 27-11-2013 14:19:19 Running from I:\ Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [472984 2013-06-03] (Adobe Systems Incorporated) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-03-26] (Intel Corporation) HKLM-x32\...\Run: [AVMWlanClient] - C:\Program Files (x86)\avmwlanstick\WLanGUI.exe [2105344 2010-10-22] (AVM Berlin) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [EEventManager] - C:\Program Files (x86)\EPSON Software\Event Manager\EEventManager.exe [1058400 2011-10-31] (SEIKO EPSON CORPORATION) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-08-16] (Apple Inc.) HKLM-x32\...\Run: [Adobe Creative Cloud] - C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe [2236816 2013-07-12] (Adobe Systems Incorporated) HKLM-x32\...\Run: [LogMeIn Hamachi Ui] - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe [2255184 2013-05-15] (LogMeIn Inc.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM-x32\...\Run: [20131121] - C:\Program Files\AVAST Software\Avast\Setup\emupdate\5e44d591-9d2f-46ec-9f21-702865bc2944.exe [180184 2013-11-24] (AVAST Software) HKU\Curdt Marcus\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1820584 2013-10-30] (Valve Corporation) HKU\Curdt Marcus\...\Run: [EADM] - C:\Program Files (x86)\Origin\Origin.exe [3561816 2013-10-18] (Electronic Arts) HKU\Curdt Marcus\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [19875432 2013-06-21] (Skype Technologies S.A.) HKU\Curdt Marcus\...\Run: [EPLTarget\P0000000000000000] - C:\Windows\System32\spool\drivers\x64\3\E_IATIINE.EXE [283232 2012-02-29] (SEIKO EPSON CORPORATION) HKU\Curdt Marcus\...\Run: [RocketDock] - C:\Program Files (x86)\RocketDock\RocketDock.exe [495616 2007-09-02] () Startup: C:\Users\Curdt Marcus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Services (Whitelisted) ================= S2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) S2 AVM WLAN Connection Service; C:\Program Files (x86)\avmwlanstick\WlanNetService.exe [376832 2010-10-22] (AVM Berlin) S3 BEService; C:\Program Files (x86)\Common Files\BattlEye\BEService.exe [49152 2013-10-27] () S2 EpsonCustomerResearchParticipation; C:\Program Files\EPSON\EpsonCustomerResearchParticipation\EPCP.exe [653888 2013-10-03] (SEIKO EPSON CORPORATION) S2 EpsonScanSvc; C:\Windows\system32\EscSvc64.exe [135824 2011-12-12] (Seiko Epson Corporation) S2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [165144 2012-03-29] (Intel Corporation) S2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [76888 2013-10-31] () S2 MSI_SuperCharger; C:\Program Files (x86)\MSI\Super-Charger\ChargeService.exe [x] ==================== Drivers (Whitelisted) ==================== S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) S1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software) S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) S1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-31] (AVAST Software) S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-31] (AVAST Software) S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) S0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-08-31] () S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [14120 2010-10-22] (AVM Berlin) S3 fwlanusbn; C:\Windows\System32\DRIVERS\fwlanusbn.sys [714368 2010-10-22] (AVM GmbH) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S0 PxHlpa64; C:\Windows\System32\Drivers\PxHlpa64.sys [56336 2012-06-22] (Corel Corporation) S3 RTL8187B; C:\Windows\System32\DRIVERS\rtl8187B.sys [446976 2009-11-05] (Realtek Semiconductor Corporation ) S5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 MSICDSetup; \??\E:\CDriver64.sys [x] S3 NTIOLib_1_0_C; \??\E:\NTIOLib_X64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-27 14:10 - 2013-11-22 15:17 - 01957998 _____ (Farbar) C:\Users\Curdt Marcus\Desktop\FRST64.exe 2013-11-26 16:54 - 2013-11-26 16:54 - 00003341 _____ C:\Users\Curdt Marcus\Desktop\JRT.txt 2013-11-25 13:03 - 2013-11-25 13:03 - 00003408 ____N C:\bootsqm.dat 2013-11-24 11:08 - 2013-11-24 11:08 - 00033026 _____ C:\ComboFix.txt 2013-11-24 10:58 - 2013-11-24 11:08 - 00000000 ____D C:\Qoobox 2013-11-24 10:58 - 2013-11-24 11:07 - 00000000 ____D C:\Windows\erdnt 2013-11-24 10:58 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2013-11-24 10:58 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2013-11-24 10:58 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-11-24 10:58 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-11-24 10:58 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-11-24 10:58 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2013-11-24 10:58 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2013-11-24 10:58 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2013-11-23 12:50 - 2013-11-23 12:50 - 00000000 ____D C:\FRST 2013-11-22 15:11 - 2013-11-22 15:11 - 01957998 _____ (Farbar) C:\Users\Curdt Marcus\Downloads\FRST64.exe 2013-11-17 20:00 - 2013-11-17 21:05 - 00018180 _____ C:\Users\Curdt Marcus\Desktop\Bewerbung-1.sxw 2013-11-17 19:59 - 2013-11-17 19:59 - 00015932 _____ C:\Users\Curdt Marcus\Desktop\Lebenslauf-1.sxw 2013-11-16 10:31 - 2013-11-16 10:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-10 14:03 - 2013-11-10 14:03 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\Blizzard Entertainment 2013-11-10 13:16 - 2013-11-16 12:02 - 00000000 ____D C:\Program Files (x86)\World of Warcraft 2013-11-10 13:16 - 2013-11-10 13:16 - 00001256 _____ C:\Users\Public\Desktop\Wetin3.lnk 2013-11-10 13:02 - 2013-11-10 13:09 - 83293072 _____ (Blizzard Entertainment) C:\Users\Curdt Marcus\Downloads\World-of-Warcraft-Setup-deDE.exe 2013-11-10 11:39 - 2013-11-10 11:39 - 00239064 _____ C:\Users\Curdt Marcus\Downloads\MCPatcherPro_downloader-afQyrH7m.exe 2013-11-10 11:39 - 2013-11-10 11:39 - 00003288 _____ C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart 2013-11-10 11:23 - 2013-09-04 13:12 - 00343040 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbhub.sys 2013-11-10 11:23 - 2013-09-04 13:11 - 00325120 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbport.sys 2013-11-10 11:23 - 2013-09-04 13:11 - 00099840 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbccgp.sys 2013-11-10 11:23 - 2013-09-04 13:11 - 00052736 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbehci.sys 2013-11-10 11:23 - 2013-09-04 13:11 - 00030720 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbuhci.sys 2013-11-10 11:23 - 2013-09-04 13:11 - 00025600 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbohci.sys 2013-11-10 11:23 - 2013-09-04 13:11 - 00007808 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbd.sys 2013-11-09 16:14 - 2013-11-10 13:24 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\.technic 2013-11-09 16:10 - 2013-11-10 11:45 - 02300919 _____ () C:\Users\Curdt Marcus\Desktop\TechnicLauncher.exe 2013-11-07 16:17 - 2013-11-07 16:17 - 01970848 _____ C:\Users\Curdt Marcus\Downloads\winrar-x64-500.exe 2013-11-07 16:14 - 2013-11-07 16:14 - 01609146 _____ C:\Users\Curdt Marcus\Downloads\wrar420d.exe 2013-11-07 16:14 - 2013-11-07 16:14 - 00000000 ____D C:\Program Files (x86)\WinRAR 2013-11-07 16:07 - 2013-11-07 16:08 - 18080872 _____ (Adobe Systems Inc.) C:\Users\Curdt Marcus\Downloads\AdobeAIRInstaller.exe 2013-10-31 12:20 - 2013-10-31 12:20 - 00000000 ____D C:\Program Files (x86)\EA Games 2013-10-28 18:00 - 2013-10-29 22:02 - 00000000 ____D C:\Program Files (x86)\The Mighty Quest For Epic Loot 2013-10-28 18:00 - 2013-10-28 18:00 - 00001400 _____ C:\Users\Public\Desktop\The Mighty Quest For Epic Loot.lnk 2013-10-28 17:59 - 2013-10-28 17:59 - 28382568 _____ ( ) C:\Users\Curdt Marcus\Downloads\MightyQuestSetup_219367.exe 2013-10-28 17:59 - 2013-10-28 17:59 - 03174799 _____ ( ) C:\Users\Curdt Marcus\Downloads\MightyQuestSetup_219367(1).exe.part ==================== One Month Modified Files and Folders ======= 2013-11-27 14:10 - 2013-01-13 14:25 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\Adobe 2013-11-27 14:10 - 2012-12-24 20:49 - 00000000 ____D C:\Program Files (x86)\Steam 2013-11-27 14:09 - 2013-08-09 13:34 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\LogMeIn Hamachi 2013-11-27 14:07 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\tracing 2013-11-27 13:56 - 2012-12-24 20:41 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-11-27 13:47 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-27 13:45 - 2012-12-19 15:51 - 00000000 ____D C:\ProgramData\NVIDIA 2013-11-27 13:45 - 2009-07-14 05:51 - 00021256 _____ C:\Windows\setupact.log 2013-11-26 16:54 - 2013-11-26 16:54 - 00003341 _____ C:\Users\Curdt Marcus\Desktop\JRT.txt 2013-11-26 16:53 - 2013-08-30 11:34 - 00000000 ____D C:\Windows\ERUNT 2013-11-26 16:41 - 2013-08-28 12:56 - 00000000 ____D C:\AdwCleaner 2013-11-26 16:31 - 2010-11-21 04:47 - 00029282 _____ C:\Windows\PFRO.log 2013-11-26 16:29 - 2013-07-19 13:35 - 00000000 ____D C:\Users\Curdt Marcus\Sony Vegas Pro 12 for Free 2013-11-26 15:06 - 2009-07-14 05:45 - 00021840 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-26 15:06 - 2009-07-14 05:45 - 00021840 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-26 15:05 - 2011-04-12 08:43 - 01351010 _____ C:\Windows\System32\perfh007.dat 2013-11-26 15:05 - 2011-04-12 08:43 - 00351226 _____ C:\Windows\System32\perfc007.dat 2013-11-26 15:05 - 2009-07-14 06:13 - 00006248 _____ C:\Windows\System32\PerfStringBackup.INI 2013-11-26 15:01 - 2012-12-19 15:42 - 01602750 _____ C:\Windows\WindowsUpdate.log 2013-11-26 15:00 - 2009-07-14 06:32 - 00000000 ____D C:\Windows\System32\FxsTmp 2013-11-26 14:51 - 2012-12-24 20:39 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-26 14:37 - 2012-12-24 20:41 - 00001122 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-11-26 14:06 - 2013-08-30 09:51 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-11-25 13:21 - 2013-02-03 18:31 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\CrashDumps 2013-11-25 13:21 - 2012-12-24 21:01 - 00000000 ____D C:\Program Files (x86)\Origin 2013-11-25 13:20 - 2013-08-31 15:57 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-25 13:03 - 2013-11-25 13:03 - 00003408 ____N C:\bootsqm.dat 2013-11-24 11:08 - 2013-11-24 11:08 - 00033026 _____ C:\ComboFix.txt 2013-11-24 11:08 - 2013-11-24 10:58 - 00000000 ____D C:\Qoobox 2013-11-24 11:07 - 2013-11-24 10:58 - 00000000 ____D C:\Windows\erdnt 2013-11-24 11:07 - 2012-12-19 15:48 - 00000000 ____D C:\users\Curdt Marcus 2013-11-24 11:07 - 2009-07-14 03:34 - 00000243 _____ C:\Windows\system.ini 2013-11-23 12:50 - 2013-11-23 12:50 - 00000000 ____D C:\FRST 2013-11-22 15:17 - 2013-11-27 14:10 - 01957998 _____ (Farbar) C:\Users\Curdt Marcus\Desktop\FRST64.exe 2013-11-22 15:11 - 2013-11-22 15:11 - 01957998 _____ (Farbar) C:\Users\Curdt Marcus\Downloads\FRST64.exe 2013-11-22 14:31 - 2013-02-25 16:36 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Skype 2013-11-18 18:28 - 2013-05-20 11:12 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\.minecraft 2013-11-17 21:05 - 2013-11-17 20:00 - 00018180 _____ C:\Users\Curdt Marcus\Desktop\Bewerbung-1.sxw 2013-11-17 19:59 - 2013-11-17 19:59 - 00015932 _____ C:\Users\Curdt Marcus\Desktop\Lebenslauf-1.sxw 2013-11-17 18:49 - 2012-12-27 16:54 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\TS3Client 2013-11-17 18:48 - 2012-12-27 16:53 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\TeamSpeak 3 Client 2013-11-17 00:15 - 2012-12-24 20:34 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-16 15:28 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-16 12:02 - 2013-11-10 13:16 - 00000000 ____D C:\Program Files (x86)\World of Warcraft 2013-11-16 10:31 - 2013-11-16 10:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-15 19:42 - 2013-06-10 16:04 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\AIMP3 2013-11-15 19:39 - 2013-03-03 21:31 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\Audacity 2013-11-14 19:24 - 2013-07-20 21:03 - 00000000 ____D C:\Windows\System32\MRT 2013-11-14 19:22 - 2013-01-20 10:02 - 82896128 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-11-10 14:03 - 2013-11-10 14:03 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\Blizzard Entertainment 2013-11-10 13:24 - 2013-11-09 16:14 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\.technic 2013-11-10 13:16 - 2013-11-10 13:16 - 00001256 _____ C:\Users\Public\Desktop\Wetin3.lnk 2013-11-10 13:09 - 2013-11-10 13:02 - 83293072 _____ (Blizzard Entertainment) C:\Users\Curdt Marcus\Downloads\World-of-Warcraft-Setup-deDE.exe 2013-11-10 11:45 - 2013-11-09 16:10 - 02300919 _____ () C:\Users\Curdt Marcus\Desktop\TechnicLauncher.exe 2013-11-10 11:39 - 2013-11-10 11:39 - 00239064 _____ C:\Users\Curdt Marcus\Downloads\MCPatcherPro_downloader-afQyrH7m.exe 2013-11-10 11:39 - 2013-11-10 11:39 - 00003288 _____ C:\Windows\System32\Tasks\SomotoUpdateCheckerAutoStart 2013-11-07 16:17 - 2013-11-07 16:17 - 01970848 _____ C:\Users\Curdt Marcus\Downloads\winrar-x64-500.exe 2013-11-07 16:17 - 2012-12-24 21:34 - 00000000 ____D C:\Program Files\WinRAR 2013-11-07 16:14 - 2013-11-07 16:14 - 01609146 _____ C:\Users\Curdt Marcus\Downloads\wrar420d.exe 2013-11-07 16:14 - 2013-11-07 16:14 - 00000000 ____D C:\Program Files (x86)\WinRAR 2013-11-07 16:08 - 2013-11-07 16:07 - 18080872 _____ (Adobe Systems Inc.) C:\Users\Curdt Marcus\Downloads\AdobeAIRInstaller.exe 2013-11-03 15:15 - 2013-06-19 17:16 - 00517754 _____ () C:\Users\Curdt Marcus\Downloads\FTB_Launcher.exe 2013-11-03 15:15 - 2013-06-19 17:16 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Roaming\ftblauncher 2013-11-01 15:51 - 2013-02-23 17:46 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\ArmA 2 OA 2013-10-31 13:14 - 2013-09-01 13:50 - 00282296 _____ C:\Windows\SysWOW64\PnkBstrB.exe 2013-10-31 13:14 - 2012-12-25 10:44 - 00282296 _____ C:\Windows\SysWOW64\PnkBstrB.xtr 2013-10-31 13:08 - 2013-09-01 13:49 - 00076888 _____ C:\Windows\SysWOW64\PnkBstrA.exe 2013-10-31 13:07 - 2012-12-24 23:00 - 00282296 _____ C:\Windows\SysWOW64\PnkBstrB.ex0 2013-10-31 13:01 - 2012-12-25 10:44 - 00000000 ____D C:\Users\Curdt Marcus\AppData\Local\PunkBuster 2013-10-31 12:20 - 2013-10-31 12:20 - 00000000 ____D C:\Program Files (x86)\EA Games 2013-10-29 22:02 - 2013-10-28 18:00 - 00000000 ____D C:\Program Files (x86)\The Mighty Quest For Epic Loot 2013-10-28 18:00 - 2013-10-28 18:00 - 00001400 _____ C:\Users\Public\Desktop\The Mighty Quest For Epic Loot.lnk 2013-10-28 17:59 - 2013-10-28 17:59 - 28382568 _____ ( ) C:\Users\Curdt Marcus\Downloads\MightyQuestSetup_219367.exe 2013-10-28 17:59 - 2013-10-28 17:59 - 03174799 _____ ( ) C:\Users\Curdt Marcus\Downloads\MightyQuestSetup_219367(1).exe.part Files to move or delete: ==================== C:\Users\Curdt Marcus\Minecraft(2).exe C:\Users\Curdt Marcus\AppData\Roaming\Origin ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= 1 Restore point made on: 2013-11-22 15:59:51 ==================== Memory info =========================== Percentage of memory in use: 9% Total physical RAM: 8136.92 MB Available physical RAM: 7325.55 MB Total Pagefile: 8135.12 MB Available Pagefile: 7311.12 MB Total Virtual: 8192 MB Available Virtual: 8191.87 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:244.04 GB) (Free:63.2 GB) NTFS Drive e: () (Fixed) (Total:221.62 GB) (Free:161.85 GB) NTFS Drive g: (Volume) (Fixed) (Total:931.51 GB) (Free:552.51 GB) NTFS Drive i: (USB DISK) (Removable) (Total:0.93 GB) (Free:0.64 GB) FAT Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 8F85853A) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=244 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=222 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: 32C6D9E4) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 3 (MBR Code: Windows XP) (Size: 956 MB) (Disk ID: C3072E18) Partition 1: (Active) - (Size=956 MB) - (Type=06) LastRegBack: 2013-11-22 15:52 ==================== End Of Log ============================ |
![]() |
Themen zu alle Antiviren Syteme aus und alles ist extrem langsam |
antiviren, avast, brauche, community, defender, extrem, extrem langsam, freezt, hoffe, keine programme, langsam, min, programme, scan, schonmal, screen, security, security scan, starte, startet, systeme, win, win7, windows, windows defender |