|
Log-Analyse und Auswertung: Win7: Netbook RAM immer ausgelastetWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
16.01.2014, 19:09 | #1 | ||
| Win7: Netbook RAM immer ausgelastet Hallo Leute Ich habe hier einen Acer Aspire one ( Modelnr.: KAV60) Verbaut ist: Intel Atom Prozessor mit 1,6GHz 1GB Arbeitsspeicher 250GB HDD Betriebssystem : Windows 7 32bit Das Problem: -Arbeitsspeicher Auslastung liegt zwischen 80 und 100% auch bei keiner Nutzung - Browser laufen langsam ( Chrome / Internet Explorer ) Es war vorher "Norten" drauf .. es wurde versucht Kaspersky zu installieren. Davor lief alles ohne Probleme. Versucht wurde : -Kaspersky Deinstalliert mit "Entfernungs-Tool für Produkte von Kaspersky Lab" -Norton Removal Tool -Treiber Aktualisiert -Kaspersky neu Installation -CCleaner -Adwcleaner -Kaspersky wurde wieder mit dem Entfernungs-Tool deinstalliert -AVG Installiert -Virus Scan = keine Treffer Im Task Manager sind 60 und mehr Prozesse geöffnet, direkt nach dem Start. Ganz oben steht "explorer.exe" Mein Momentaner Verdacht, ist das dass Netbook einfach zu wenig Power hat, aber wie gesagt, lief es vor der Installation geschmeidiger Hier habe ich die Logs: FRST FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 15-01-2014 03 Ran by Sabrina (administrator) on SABRINA-PC on 16-01-2014 17:00:04 Running from C:\Users\Sabrina\Desktop Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) =================== (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgrsx.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgcsrvx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgwdsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files\Acer\Registration\GregHSRW.exe (Egis Technology Inc.) C:\Program Files\EgisTec\MyWinLocker 3\x86\MWLService.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe (Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe (Acer) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Egis Technology Inc.) C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Sony Corporation) C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (AVG Technologies CZ, s.r.o.) C:\Program Files\AVG\AVG2014\avgui.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [186904 2009-06-05] (Intel Corporation) HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [1130504 2009-06-02] (Dritek System Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [12017368 2013-10-24] (Realtek Semiconductor) HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [707104 2009-08-06] (Acer Incorporated) HKLM\...\Run: [mwlDaemon] - C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe [349480 2009-08-06] (Egis Technology Inc.) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1557800 2009-09-03] (Synaptics Incorporated) HKLM\...\Run: [ControlCenter3] - C:\Program Files\Brother\ControlCenter3\brctrcen.exe [65536 2007-01-26] (Brother Industries, Ltd.) HKLM\...\Run: [PMBVolumeWatcher] - C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe [599328 2010-03-24] (Sony Corporation) HKLM\...\Run: [fspuip] - C:\Program Files\FSP\fspuip.exe [5411664 2013-04-02] (Sentelic Corporation) HKLM\...\Run: [AVG_UI] - C:\Program Files\AVG\AVG2014\avgui.exe [4956176 2013-11-07] (AVG Technologies CZ, s.r.o.) HKCU\...\Run: [AVG-Secure-Search-Update_1213b] - C:\Users\Sabrina\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=23cc23b0b28d47d2be35d16f648bca08-59cf74f9f326035203b89ca744273a964084841c /CMPID=1213b MountPoints2: D - D:\autorun.exe MountPoints2: {bc25117a-d680-11df-8759-0026226f23fb} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {bc25118f-d680-11df-8759-0026226f23fb} - D:\setup_vmc_lite.exe /checkApplicationPresence MountPoints2: {bc25119e-d680-11df-8759-0026226f23fb} - D:\setup_vmc_lite.exe /checkApplicationPresence HKU\Default\...\RunOnce: [ScrSav] - C:\Windows\Screensavers\Acer\run_Acer.exe [ 2009-03-03] (TODO: <Company name>) HKU\Default User\...\RunOnce: [ScrSav] - C:\Windows\Screensavers\Acer\run_Acer.exe [ 2009-03-03] (TODO: <Company name>) Startup: C:\Users\Sabrina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk ShortcutTarget: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk -> C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE (Microsoft Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_one&r=07b501103555l0344wwh5w48m26659 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_one&r=07b501103555l0344wwh5w48m26659 SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_deDE367 BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation) BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8064.0206.dll (Microsoft Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 05 C:\Program Files\Bonjour\mdnsNSP.dll [152864] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\jmyivncz.default FF NewTab: chrome://unitedtb/content/newtab/newtab-page.xhtml FF Homepage: hxxp://www.google.de/webhp?rls=ig FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @java.com/DTPlugin,version=10.4.1 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.4.1 - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WLPG,version=14.0.8064.0206 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Sabrina\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Sabrina\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.) FF Extension: WEB.DE MailCheck - C:\Users\Sabrina\AppData\Roaming\Mozilla\Firefox\Profiles\jmyivncz.default\Extensions\toolbar@web.de.xpi [2012-01-06] Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 [2014-01-12] CHR Extension: (Google Drive) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 [2014-01-12] CHR Extension: (YouTube) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 [2014-01-12] CHR Extension: (Google Search) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 [2014-01-12] CHR Extension: (Google Wallet) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_0 [2014-01-12] CHR Extension: (Gmail) - C:\Users\Sabrina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 [2014-01-12] ========================== Services (Whitelisted) ================= R2 AVGIDSAgent; C:\Program Files\AVG\AVG2014\avgidsagent.exe [3478544 2013-11-11] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files\AVG\AVG2014\avgwdsvc.exe [348008 2013-09-24] (AVG Technologies CZ, s.r.o.) R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [727584 2009-08-06] (Acer Incorporated) R2 Greg_Service; C:\Program Files\Acer\Registration\GregHSRW.exe [1150496 2009-06-04] (Acer Incorporated) R2 MWLService; C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe [311592 2009-08-06] (Egis Technology Inc.) R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [253952 2009-07-10] (Acer Incorporated) R2 Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [240160 2009-07-04] (Acer) R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-07-04] (Vodafone) ==================== Drivers (Whitelisted) ==================== R1 Avgdiskx; C:\Windows\System32\DRIVERS\avgdiskx.sys [120600 2013-11-05] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdriverx.sys [209176 2013-11-04] (AVG Technologies CZ, s.r.o.) R0 AVGIDSHX; C:\Windows\System32\DRIVERS\avgidshx.sys [147768 2013-10-24] (AVG Technologies CZ, s.r.o.) R1 AVGIDSShim; C:\Windows\System32\DRIVERS\avgidsshimx.sys [22840 2013-09-17] (AVG Technologies CZ, s.r.o.) R1 Avgldx86; C:\Windows\System32\DRIVERS\avgldx86.sys [176952 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avglogx; C:\Windows\System32\DRIVERS\avglogx.sys [222520 2013-10-31] (AVG Technologies CZ, s.r.o.) R0 Avgmfx86; C:\Windows\System32\DRIVERS\avgmfx86.sys [102712 2013-10-01] (AVG Technologies CZ, s.r.o.) R0 Avgrkx86; C:\Windows\System32\DRIVERS\avgrkx86.sys [27448 2013-09-10] (AVG Technologies CZ, s.r.o.) R3 fspad_win732; C:\Windows\System32\DRIVERS\fspad_win732.sys [130384 2013-04-02] (Sentelic Corporation) R0 iusb3hcs; C:\Windows\System32\DRIVERS\iusb3hcs.sys [16880 2013-07-17] (Intel Corporation) R3 L1C; C:\Windows\System32\DRIVERS\L1C62x86.sys [110280 2013-07-18] (Qualcomm Atheros Co., Ltd.) R1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [18992 2009-06-02] (Egis Technology Inc.) R1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16432 2009-06-02] (Egis Technology Inc.) R1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [60976 2009-06-02] (Egis Technology Inc.) S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-16 17:00 - 2014-01-16 17:00 - 00013855 _____ C:\Users\Sabrina\Desktop\FRST.txt 2014-01-16 16:59 - 2014-01-16 16:59 - 00000000 ____D C:\FRST 2014-01-16 16:50 - 2014-01-16 16:51 - 00000476 _____ C:\Users\Sabrina\Desktop\defogger_disable.log 2014-01-16 16:50 - 2014-01-16 16:50 - 00000000 _____ C:\Users\Sabrina\defogger_reenable 2014-01-16 16:49 - 2014-01-16 16:48 - 00379904 _____ C:\Users\Sabrina\Desktop\03vc2w3l.exe 2014-01-16 16:49 - 2014-01-16 16:48 - 00050477 _____ C:\Users\Sabrina\Desktop\Defogger.exe 2014-01-16 16:49 - 2014-01-16 16:47 - 01221120 _____ (Farbar) C:\Users\Sabrina\Desktop\FRST.exe 2014-01-16 16:25 - 2014-01-16 16:34 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-15 17:08 - 2014-01-15 17:21 - 00000000 ____D C:\AdwCleaner 2014-01-15 17:02 - 2014-01-15 17:02 - 01236282 _____ C:\Users\Sabrina\Desktop\adwcleaner_3.017.exe 2014-01-15 16:58 - 2014-01-15 16:58 - 00388608 _____ (Trend Micro Inc.) C:\Users\Sabrina\Desktop\HiJackThis204.exe 2014-01-13 18:39 - 2014-01-13 18:39 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\AVG 2014-01-13 18:37 - 2014-01-13 19:01 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} 2014-01-13 18:37 - 2014-01-13 18:42 - 00000000 ____D C:\ProgramData\AVG 2014-01-13 18:28 - 2014-01-13 18:28 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\AVG2014 2014-01-13 18:27 - 2014-01-13 18:27 - 00000955 _____ C:\Users\Public\Desktop\AVG 2014.lnk 2014-01-13 18:27 - 2014-01-13 18:27 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\TuneUp Software 2014-01-13 18:23 - 2014-01-13 18:27 - 00000000 ____D C:\ProgramData\AVG2014 2014-01-13 18:23 - 2014-01-13 18:23 - 00000000 ___HD C:\$AVG 2014-01-13 18:22 - 2014-01-13 21:50 - 00000000 ____D C:\Program Files\AVG 2014-01-13 18:20 - 2014-01-16 16:21 - 00000000 ____D C:\ProgramData\MFAData 2014-01-13 18:20 - 2014-01-13 21:35 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Avg2014 2014-01-13 18:20 - 2014-01-13 18:20 - 00000000 ____D C:\Users\Sabrina\AppData\Local\MFAData 2014-01-13 18:16 - 2014-01-13 18:16 - 00182706 _____ C:\Users\Sabrina\Downloads\kavremvr 2014-01-13 18-16-27 (pid 1936).log 2014-01-13 18:15 - 2014-01-13 18:18 - 137189352 _____ (AVG Technologies) C:\Users\Sabrina\Downloads\avg_free_x86_all_2014_4259a6848.exe 2014-01-13 17:24 - 2014-01-13 17:29 - 02124846 _____ C:\Users\Sabrina\Downloads\kavremvr 2014-01-13 17-24-57 (pid 3852).log 2014-01-13 16:56 - 2014-01-13 16:56 - 00007605 _____ C:\Users\Sabrina\AppData\Local\Resmon.ResmonCfg 2014-01-13 16:45 - 2014-01-15 16:55 - 01087236 _____ C:\Windows\PFRO.log 2014-01-12 15:27 - 2014-01-12 15:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_iusb3hcs_01009.Wdf 2014-01-12 15:26 - 2013-07-17 22:43 - 00016880 _____ (Intel Corporation) C:\Windows\system32\Drivers\iusb3hcs.sys 2014-01-12 15:23 - 2013-11-05 19:44 - 08360656 _____ (Broadcom Corporation) C:\Windows\system32\Drivers\BCMWL6.SYS 2014-01-12 15:23 - 2013-11-05 19:44 - 04263936 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvsrv.dll 2014-01-12 15:23 - 2013-11-05 19:44 - 03653632 _____ (Broadcom Corporation) C:\Windows\system32\bcmihvui.dll 2014-01-12 15:23 - 2013-11-05 19:44 - 00092464 _____ (Broadcom Corporation) C:\Windows\system32\bcmwlcoi.dll 2014-01-12 15:19 - 2014-01-16 16:57 - 00001407 _____ C:\Windows\sentelic.log 2014-01-12 15:19 - 2014-01-12 15:19 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_fspad_win732_01009.Wdf 2014-01-12 15:19 - 2014-01-12 15:19 - 00000000 ____D C:\Program Files\FSP 2014-01-12 15:11 - 2013-04-02 08:34 - 01636176 _____ (Sentelic Corporation.) C:\Windows\system32\StlFspAPI32.dll 2014-01-12 15:11 - 2013-04-02 08:34 - 00130384 _____ (Sentelic Corporation) C:\Windows\system32\Drivers\fspad_win732.sys 2014-01-12 15:11 - 2013-04-02 08:34 - 00080208 _____ (Sentelic Corporation) C:\Windows\system32\fspadco.dll 2014-01-12 15:10 - 2014-01-12 15:10 - 00000000 ____H C:\ProgramData\DP45977C.lfl 2014-01-12 15:07 - 2013-09-10 01:02 - 06176944 _____ (Dolby Laboratories) C:\Windows\system32\DDPP32A.dll 2014-01-12 15:07 - 2013-09-10 01:02 - 00272048 _____ (Dolby Laboratories) C:\Windows\system32\DDPO32A.dll 2014-01-12 15:07 - 2013-09-10 01:01 - 01489072 _____ (Dolby Laboratories) C:\Windows\system32\DDPD32A.dll 2014-01-12 15:07 - 2013-09-10 01:01 - 00219312 _____ (Dolby Laboratories) C:\Windows\system32\DDPA32.dll 2014-01-12 15:07 - 2012-08-31 16:17 - 07162128 _____ (Dolby Laboratories) C:\Windows\system32\R4EEP32A.dll 2014-01-12 15:07 - 2012-08-31 16:17 - 00352016 _____ (Dolby Laboratories) C:\Windows\system32\R4EED32A.dll 2014-01-12 15:07 - 2012-08-31 16:17 - 00106768 _____ (Dolby Laboratories) C:\Windows\system32\R4EEL32A.dll 2014-01-12 15:07 - 2012-08-31 16:17 - 00091920 _____ (Dolby Laboratories) C:\Windows\system32\R4EEA32A.dll 2014-01-12 15:07 - 2012-08-31 16:17 - 00062224 _____ (Dolby Laboratories) C:\Windows\system32\R4EEG32A.dll 2014-01-12 15:06 - 2013-11-05 12:48 - 00681905 _____ C:\Windows\system32\Drivers\RTAIODAT.DAT 2014-01-12 15:06 - 2013-09-09 12:32 - 05681192 _____ C:\Windows\system32\Drivers\rtvienna.dat 2014-01-12 15:05 - 2013-11-05 16:47 - 02888536 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\Drivers\RTKVHDA.sys 2014-01-12 15:05 - 2013-11-05 15:55 - 38385664 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RCoRes.dat 2014-01-12 15:05 - 2013-11-04 16:26 - 00124632 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoInstII.dll 2014-01-12 15:05 - 2013-11-04 08:11 - 02328792 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkAPO.dll 2014-01-12 15:05 - 2013-10-30 13:30 - 00877880 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOSettingsIPC.dll 2014-01-12 15:05 - 2013-10-30 13:29 - 05773592 _____ (Nahimic Inc) C:\Windows\system32\NAHIMICAPOlfx.dll 2014-01-12 15:05 - 2013-10-28 14:29 - 00782040 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkApoApi.dll 2014-01-12 15:05 - 2013-10-16 00:43 - 00182472 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTACap.dll 2014-01-12 15:05 - 2013-10-11 09:47 - 00092584 _____ (Real Sound Lab SIA) C:\Windows\system32\CONEQMSAPOGUILibrary.dll 2014-01-12 15:05 - 2013-10-11 08:31 - 00919600 _____ (Sony Corporation) C:\Windows\system32\SFSS_APO.dll 2014-01-12 15:05 - 2013-10-09 17:14 - 13881088 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek.dll 2014-01-12 15:05 - 2013-10-09 17:14 - 03444992 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnN.dll 2014-01-12 15:05 - 2013-10-09 17:13 - 01677568 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioRealtek2.dll 2014-01-12 15:05 - 2013-10-09 17:13 - 01097984 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO50.dll 2014-01-12 15:05 - 2013-10-09 17:13 - 00926976 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxSpeechAPO.dll 2014-01-12 15:05 - 2013-10-09 17:12 - 27369216 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioVnA.dll 2014-01-12 15:05 - 2013-10-09 17:12 - 01935104 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioEQ.dll 2014-01-12 15:05 - 2013-10-09 17:12 - 01824000 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesGUILib.dll 2014-01-12 15:05 - 2013-10-09 17:12 - 00859904 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPOShell.dll 2014-01-12 15:05 - 2013-10-07 08:05 - 02547928 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkPgExt.dll 2014-01-12 15:05 - 2013-10-06 21:14 - 00426944 _____ (DTS) C:\Windows\system32\DTSU2PLFX32.dll 2014-01-12 15:05 - 2013-10-06 21:14 - 00403392 _____ (DTS) C:\Windows\system32\DTSU2PGFX32.dll 2014-01-12 15:05 - 2013-10-06 21:14 - 00346048 _____ (DTS) C:\Windows\system32\DTSU2PREC32.dll 2014-01-12 15:05 - 2013-08-24 00:14 - 00938752 _____ (SRS Labs, Inc.) C:\Windows\system32\slcnt32.dll 2014-01-12 15:05 - 2013-08-24 00:14 - 00823040 _____ (DTS, Inc.) C:\Windows\system32\sl3apo32.dll 2014-01-12 15:05 - 2013-08-24 00:14 - 00604928 _____ (DTS, Inc.) C:\Windows\system32\sltech32.dll 2014-01-12 15:05 - 2013-08-24 00:14 - 00218368 _____ (TODO: <Company name>) C:\Windows\system32\slprp32.dll 2014-01-12 15:05 - 2013-08-20 14:36 - 00502584 _____ C:\Windows\system32\audioLibVc.dll 2014-01-12 15:05 - 2013-08-14 13:36 - 00873728 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO40.dll 2014-01-12 15:05 - 2013-08-14 13:36 - 00509184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVolumeSDAPO.dll 2014-01-12 15:05 - 2013-08-14 13:35 - 00761088 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxVoiceAPO20.dll 2014-01-12 15:05 - 2013-08-14 13:35 - 00509184 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO30.dll 2014-01-12 15:05 - 2013-08-05 15:10 - 02395680 _____ (Fortemedia Corporation) C:\Windows\system32\FMAPO.dll 2014-01-12 15:05 - 2013-06-17 17:20 - 00188696 _____ C:\Windows\system32\AcpiServiceVnA.dll 2014-01-12 15:05 - 2013-04-24 14:16 - 01596488 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RTSndMgr.cpl 2014-01-12 15:05 - 2013-04-03 11:12 - 00852016 _____ (Sony Corporation) C:\Windows\system32\MISS_APO.dll 2014-01-12 15:05 - 2012-03-08 08:47 - 00095840 _____ (Andrea Electronics Corporation) C:\Windows\system32\AERTARen.dll 2014-01-12 15:05 - 2012-01-30 08:42 - 00819648 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo2.dll 2014-01-12 15:05 - 2012-01-10 07:20 - 00058264 _____ (TOSHIBA CORPORATION.) C:\Windows\system32\TepeqAPO.dll 2014-01-12 15:05 - 2011-11-22 13:28 - 00013416 _____ (Realtek Semiconductor Corp.) C:\Windows\system32\RtkCoLDR.dll 2014-01-12 15:05 - 2011-09-02 11:21 - 00214368 _____ (Synopsys, Inc.) C:\Windows\system32\SFNHK.dll 2014-01-12 15:05 - 2011-09-02 11:21 - 00074080 _____ (Synopsys, Inc.) C:\Windows\system32\SFCOM.dll 2014-01-12 15:05 - 2011-09-02 11:21 - 00068960 _____ (Synopsys, Inc.) C:\Windows\system32\SFAPO.dll 2014-01-12 15:05 - 2011-08-23 14:00 - 00357712 _____ (Knowles Acoustics ) C:\Windows\system32\KAAPORT.dll 2014-01-12 15:05 - 2011-05-31 06:42 - 01509480 _____ (DTS) C:\Windows\system32\DTSS2SpeakerDLL.dll 2014-01-12 15:05 - 2011-05-31 06:42 - 01292904 _____ (DTS) C:\Windows\system32\DTSS2HeadphoneDLL.dll 2014-01-12 15:05 - 2011-05-31 06:42 - 01220200 _____ (DTS) C:\Windows\system32\DTSBoostDLL.dll 2014-01-12 15:05 - 2011-05-31 06:42 - 00654952 _____ (DTS) C:\Windows\system32\DTSBassEnhancementDLL.dll 2014-01-12 15:05 - 2011-05-31 06:42 - 00631400 _____ (DTS) C:\Windows\system32\DTSSymmetryDLL.dll 2014-01-12 15:05 - 2011-05-31 06:42 - 00601704 _____ (DTS) C:\Windows\system32\DTSVoiceClarityDLL.dll 2014-01-12 15:05 - 2011-05-31 06:42 - 00458344 _____ (DTS) C:\Windows\system32\DTSNeoPCDLL.dll 2014-01-12 15:05 - 2011-05-31 06:42 - 00389736 _____ (DTS) C:\Windows\system32\DTSGainCompensatorDLL.dll 2014-01-12 15:05 - 2011-05-31 06:42 - 00375400 _____ (DTS) C:\Windows\system32\DTSLimiterDLL.dll 2014-01-12 15:05 - 2011-05-31 06:42 - 00218728 _____ (DTS) C:\Windows\system32\DTSGFXAPONS.dll 2014-01-12 15:05 - 2011-05-31 06:42 - 00218728 _____ (DTS) C:\Windows\system32\DTSGFXAPO.dll 2014-01-12 15:05 - 2011-05-31 06:42 - 00218216 _____ (DTS) C:\Windows\system32\DTSLFXAPO.dll 2014-01-12 15:05 - 2011-03-17 09:16 - 01379760 _____ (TOSHIBA Corporation) C:\Windows\system32\tosade.dll 2014-01-12 15:05 - 2011-03-07 14:03 - 00134584 _____ (TOSHIBA Corporation) C:\Windows\system32\tadefxapo.dll 2014-01-12 15:05 - 2010-11-08 04:31 - 00359768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEP32A.dll 2014-01-12 15:05 - 2010-11-08 04:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DHT32.dll 2014-01-12 15:05 - 2010-11-08 04:31 - 00295768 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RP3DAA32.dll 2014-01-12 15:05 - 2010-11-08 04:31 - 00170840 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEED32A.dll 2014-01-12 15:05 - 2010-11-08 04:31 - 00078680 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEL32A.dll 2014-01-12 15:05 - 2010-11-08 04:31 - 00064856 _____ (Dolby Laboratories, Inc.) C:\Windows\system32\RTEEG32A.dll 2014-01-12 15:05 - 2010-09-27 06:34 - 00232792 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO20.dll 2014-01-12 15:05 - 2009-12-04 12:43 - 00132368 _____ (Waves Audio Ltd.) C:\Windows\system32\MaxxAudioAPO.dll 2014-01-12 15:05 - 2009-11-24 06:55 - 00345328 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSXT.dll 2014-01-12 15:05 - 2009-11-24 06:55 - 00185584 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSTSHD.dll 2014-01-12 15:05 - 2009-11-24 06:55 - 00173296 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSHP360.dll 2014-01-12 15:05 - 2009-11-24 06:55 - 00140528 _____ (SRS Labs, Inc.) C:\Windows\system32\SRSWOW.dll 2014-01-12 15:05 - 2009-11-18 15:42 - 01783056 _____ (Waves Audio Ltd.) C:\Windows\system32\WavesLib.dll 2014-01-12 15:04 - 2014-01-12 15:04 - 00016400 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2014-01-12 15:04 - 2014-01-12 15:04 - 00000388 _____ C:\Windows\LkmdfCoInst.log 2014-01-12 15:03 - 2013-05-23 07:12 - 01581848 _____ (Logitech, Inc.) C:\Windows\system32\LkmdfCoInst.dll 2014-01-12 15:03 - 2013-05-23 07:12 - 00053528 _____ (Logitech, Inc.) C:\Windows\system32\LMouFiltCoInst.dll 2014-01-12 15:03 - 2013-05-23 07:12 - 00043800 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LHidFilt.Sys 2014-01-12 15:03 - 2013-05-23 07:12 - 00037528 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LMouFilt.Sys 2014-01-12 15:03 - 2012-06-12 18:29 - 00470848 _____ (Intel Corporation) C:\Windows\system32\Drivers\iaStor.sys 2014-01-12 15:01 - 2013-07-18 06:54 - 00110280 _____ (Qualcomm Atheros Co., Ltd.) C:\Windows\system32\Drivers\L1C62x86.sys 2014-01-12 14:54 - 2014-01-12 14:54 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-01-12 14:53 - 2014-01-16 16:29 - 00001076 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3565509933-3837324759-615651996-1000Core.job 2014-01-12 14:53 - 2014-01-16 16:19 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3565509933-3837324759-615651996-1000UA.job 2014-01-12 14:23 - 2014-01-12 14:23 - 00001413 _____ C:\Users\Sabrina\Desktop\Internet Explorer.lnk 2014-01-12 14:13 - 2014-01-16 16:56 - 00001641 _____ C:\Windows\setupact.log 2014-01-12 14:13 - 2014-01-12 14:13 - 00000000 _____ C:\Windows\setuperr.log 2014-01-12 14:08 - 2014-01-14 16:49 - 00025564 _____ C:\Windows\IE11_main.log 2014-01-12 13:09 - 2014-01-16 16:16 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-12 13:09 - 2014-01-12 13:54 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-01-12 12:40 - 2014-01-12 12:40 - 00000969 _____ C:\Users\Public\Desktop\CCleaner.lnk 2014-01-12 12:40 - 2014-01-12 12:40 - 00000000 ____D C:\Program Files\CCleaner 2014-01-12 09:08 - 2014-01-12 09:09 - 00000000 ____D C:\ae1d51fb7fddd640b4c06efc47f1ce 2013-12-28 18:14 - 2013-05-10 05:56 - 12625408 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL 2013-12-28 18:14 - 2013-05-10 05:56 - 11410432 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll 2013-12-28 18:10 - 2013-10-25 05:45 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-28 18:10 - 2013-10-25 05:45 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-28 18:10 - 2013-10-25 05:44 - 14356992 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-28 18:10 - 2013-10-25 05:44 - 01140736 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-28 18:10 - 2013-10-25 05:43 - 13761536 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-28 18:10 - 2013-10-25 05:43 - 02877952 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-28 18:10 - 2013-10-25 05:43 - 02049024 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-28 18:10 - 2013-10-25 05:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-28 18:10 - 2013-10-25 05:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-28 18:10 - 2013-10-25 05:43 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-28 18:10 - 2013-10-25 05:43 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-28 18:10 - 2013-10-25 05:43 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-28 18:10 - 2013-10-25 05:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-28 18:10 - 2013-10-25 05:43 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-28 18:10 - 2013-10-25 04:41 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-28 18:10 - 2013-10-25 03:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-17 16:51 - 2013-11-23 19:26 - 00417792 _____ (Microsoft Corporation) C:\Windows\system32\WMPhoto.dll 2013-12-17 16:51 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll 2013-12-17 16:51 - 2013-10-30 03:19 - 00301568 _____ (Microsoft Corporation) C:\Windows\system32\msieftp.dll 2013-12-17 16:51 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll 2013-12-17 16:51 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx 2013-12-17 16:51 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll 2013-12-17 16:51 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe 2013-12-17 16:51 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe 2013-12-17 16:50 - 2013-10-04 02:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys 2013-12-17 16:50 - 2013-10-04 02:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys 2013-12-17 16:49 - 2013-10-30 02:27 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys ==================== One Month Modified Files and Folders ======= 2014-01-16 17:00 - 2014-01-16 17:00 - 00013855 _____ C:\Users\Sabrina\Desktop\FRST.txt 2014-01-16 17:00 - 2009-10-24 11:15 - 01388588 _____ C:\Windows\WindowsUpdate.log 2014-01-16 16:59 - 2014-01-16 16:59 - 00000000 ____D C:\FRST 2014-01-16 16:57 - 2014-01-12 15:19 - 00001407 _____ C:\Windows\sentelic.log 2014-01-16 16:56 - 2014-01-12 14:13 - 00001641 _____ C:\Windows\setupact.log 2014-01-16 16:56 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-16 16:51 - 2014-01-16 16:50 - 00000476 _____ C:\Users\Sabrina\Desktop\defogger_disable.log 2014-01-16 16:50 - 2014-01-16 16:50 - 00000000 _____ C:\Users\Sabrina\defogger_reenable 2014-01-16 16:50 - 2010-01-14 12:36 - 00000000 ____D C:\Users\Sabrina 2014-01-16 16:48 - 2014-01-16 16:49 - 00379904 _____ C:\Users\Sabrina\Desktop\03vc2w3l.exe 2014-01-16 16:48 - 2014-01-16 16:49 - 00050477 _____ C:\Users\Sabrina\Desktop\Defogger.exe 2014-01-16 16:47 - 2014-01-16 16:49 - 01221120 _____ (Farbar) C:\Users\Sabrina\Desktop\FRST.exe 2014-01-16 16:43 - 2009-08-14 09:46 - 00000000 ____D C:\Program Files\Acer GameZone 2014-01-16 16:34 - 2014-01-16 16:25 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-16 16:29 - 2014-01-12 14:53 - 00001076 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3565509933-3837324759-615651996-1000Core.job 2014-01-16 16:21 - 2014-01-13 18:20 - 00000000 ____D C:\ProgramData\MFAData 2014-01-16 16:19 - 2014-01-12 14:53 - 00001128 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3565509933-3837324759-615651996-1000UA.job 2014-01-16 16:16 - 2014-01-12 13:09 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-15 17:33 - 2010-01-14 12:37 - 00000000 ____D C:\Users\Sabrina\AppData\Local\VirtualStore 2014-01-15 17:31 - 2009-07-14 05:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-15 17:31 - 2009-07-14 05:34 - 00009696 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-15 17:24 - 2010-06-23 08:06 - 00000000 ____D C:\Users\Sabrina\Tracing 2014-01-15 17:21 - 2014-01-15 17:08 - 00000000 ____D C:\AdwCleaner 2014-01-15 17:02 - 2014-01-15 17:02 - 01236282 _____ C:\Users\Sabrina\Desktop\adwcleaner_3.017.exe 2014-01-15 16:58 - 2014-01-15 16:58 - 00388608 _____ (Trend Micro Inc.) C:\Users\Sabrina\Desktop\HiJackThis204.exe 2014-01-15 16:55 - 2014-01-13 16:45 - 01087236 _____ C:\Windows\PFRO.log 2014-01-14 16:49 - 2014-01-12 14:08 - 00025564 _____ C:\Windows\IE11_main.log 2014-01-13 21:50 - 2014-01-13 18:22 - 00000000 ____D C:\Program Files\AVG 2014-01-13 21:35 - 2014-01-13 18:20 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Avg2014 2014-01-13 19:01 - 2014-01-13 18:37 - 00000000 __SHD C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308} 2014-01-13 19:01 - 2011-09-27 01:37 - 00000000 __HDC C:\ProgramData\{3C0AACBF-B491-4BE5-BAF9-AA46E0629E42} 2014-01-13 19:01 - 2010-10-28 18:22 - 00000000 ____D C:\ProgramData\{429CAD59-35B1-4DBC-BB6D-1DB246563521} 2014-01-13 18:42 - 2014-01-13 18:37 - 00000000 ____D C:\ProgramData\AVG 2014-01-13 18:39 - 2014-01-13 18:39 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\AVG 2014-01-13 18:28 - 2014-01-13 18:28 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\AVG2014 2014-01-13 18:27 - 2014-01-13 18:27 - 00000955 _____ C:\Users\Public\Desktop\AVG 2014.lnk 2014-01-13 18:27 - 2014-01-13 18:27 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\TuneUp Software 2014-01-13 18:27 - 2014-01-13 18:23 - 00000000 ____D C:\ProgramData\AVG2014 2014-01-13 18:23 - 2014-01-13 18:23 - 00000000 ___HD C:\$AVG 2014-01-13 18:20 - 2014-01-13 18:20 - 00000000 ____D C:\Users\Sabrina\AppData\Local\MFAData 2014-01-13 18:18 - 2014-01-13 18:15 - 137189352 _____ (AVG Technologies) C:\Users\Sabrina\Downloads\avg_free_x86_all_2014_4259a6848.exe 2014-01-13 18:16 - 2014-01-13 18:16 - 00182706 _____ C:\Users\Sabrina\Downloads\kavremvr 2014-01-13 18-16-27 (pid 1936).log 2014-01-13 17:29 - 2014-01-13 17:24 - 02124846 _____ C:\Users\Sabrina\Downloads\kavremvr 2014-01-13 17-24-57 (pid 3852).log 2014-01-13 16:56 - 2014-01-13 16:56 - 00007605 _____ C:\Users\Sabrina\AppData\Local\Resmon.ResmonCfg 2014-01-12 15:27 - 2014-01-12 15:27 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_iusb3hcs_01009.Wdf 2014-01-12 15:27 - 2009-08-14 09:37 - 01486084 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-12 15:19 - 2014-01-12 15:19 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_fspad_win732_01009.Wdf 2014-01-12 15:19 - 2014-01-12 15:19 - 00000000 ____D C:\Program Files\FSP 2014-01-12 15:10 - 2014-01-12 15:10 - 00000000 ____H C:\ProgramData\DP45977C.lfl 2014-01-12 15:08 - 2009-08-14 09:44 - 00000000 ____D C:\Windows\system32\RTCOM 2014-01-12 15:04 - 2014-01-12 15:04 - 00016400 _____ (Logitech, Inc.) C:\Windows\system32\Drivers\LNonPnP.sys 2014-01-12 15:04 - 2014-01-12 15:04 - 00000388 _____ C:\Windows\LkmdfCoInst.log 2014-01-12 14:54 - 2014-01-12 14:54 - 00000000 ____D C:\Users\Sabrina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-01-12 14:54 - 2010-01-14 16:11 - 00000000 ____D C:\Users\Sabrina\AppData\Local\Google 2014-01-12 14:26 - 2012-05-20 16:05 - 00000000 ____D C:\ProgramData\tmp 2014-01-12 14:23 - 2014-01-12 14:23 - 00001413 _____ C:\Users\Sabrina\Desktop\Internet Explorer.lnk 2014-01-12 14:16 - 2009-07-14 05:33 - 00336040 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-12 14:14 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE 2014-01-12 14:13 - 2014-01-12 14:13 - 00000000 _____ C:\Windows\setuperr.log 2014-01-12 14:12 - 2009-08-14 09:54 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-12 14:03 - 2012-05-20 16:17 - 00000000 ____D C:\Users\Sabrina\AppData\Local\CrashDumps 2014-01-12 14:03 - 2012-01-05 22:38 - 00000000 ____D C:\Windows\Minidump 2014-01-12 14:03 - 2007-07-12 02:49 - 00000000 ____D C:\Windows\Panther 2014-01-12 13:54 - 2014-01-12 13:09 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-01-12 13:54 - 2011-11-08 22:38 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-01-12 13:40 - 2012-01-06 00:05 - 00000000 ____D C:\ProgramData\Norton 2014-01-12 13:03 - 2009-08-14 10:14 - 00000000 ____D C:\Program Files\Google 2014-01-12 12:40 - 2014-01-12 12:40 - 00000969 _____ C:\Users\Public\Desktop\CCleaner.lnk 2014-01-12 12:40 - 2014-01-12 12:40 - 00000000 ____D C:\Program Files\CCleaner 2014-01-12 12:15 - 2009-08-14 10:14 - 00000000 ____D C:\ProgramData\Google 2014-01-12 09:09 - 2014-01-12 09:08 - 00000000 ____D C:\ae1d51fb7fddd640b4c06efc47f1ce 2014-01-12 09:09 - 2013-08-24 12:11 - 00000000 ____D C:\Windows\system32\MRT 2014-01-12 09:09 - 2012-01-05 17:05 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe Some content of TEMP: ==================== C:\Users\Sabrina\AppData\Local\Temp\DseShExt-x86.dll C:\Users\Sabrina\AppData\Local\Temp\Quarantine.exe C:\Users\Sabrina\AppData\Local\Temp\SDShelEx-win32.dll C:\Users\Sabrina\AppData\Local\Temp\TUUUninstallHelper.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-05 19:55 ==================== End Of Log ============================ defogger_disable Zitat:
Zitat:
hijackthis HiJackthis Logfile: Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 17:37:48, on 15.01.2014 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v10.0 (10.00.9200.16750) Boot mode: Normal Running processes: C:\Windows\system32\taskhost.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe C:\Program Files\Launch Manager\LManager.exe C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe C:\Windows\system32\igfxsrvc.exe C:\Windows\system32\igfxext.exe C:\Program Files\AVG\AVG2014\avgui.exe C:\Program Files\Acer\Acer VCM\AcerVCM.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Windows\system32\taskhost.exe C:\Windows\system32\RunDll32.exe C:\Users\Sabrina\Desktop\HiJackThis204.exe C:\Windows\system32\SearchFilterHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_one&r=07b501103555l0344wwh5w48m26659 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_one&r=07b501103555l0344wwh5w48m26659 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [LManager] C:\Program Files\Launch Manager\LManager.exe O4 - HKLM\..\Run: [RtHDVCpl] "C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe" -s O4 - HKLM\..\Run: [Acer ePower Management] C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe O4 - HKLM\..\Run: [mwlDaemon] C:\Program Files\EgisTec\MyWinLocker 3\x86\mwlDaemon.exe O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorun O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [PMBVolumeWatcher] C:\Program Files\Sony\PMB\PMBVolumeWatcher.exe O4 - HKLM\..\Run: [fspuip] %ProgramFiles%\FSP\fspuip.exe O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2014\avgui.exe" /TRAYONLY O4 - HKCU\..\Run: [AVG-Secure-Search-Update_1213b] C:\Users\Sabrina\AppData\Roaming\AVG 1213b Campaign\AVG-Secure-Search-Update-1213b.exe /PROMPT /mid=23cc23b0b28d47d2be35d16f648bca08-59cf74f9f326035203b89ca744273a964084841c /CMPID=1213b O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETZWERKDIENST') O4 - Startup: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: Acer VCM.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: Get More Games - {120CC99A-8016-42d4-93AF-8C5FE64FE4E3} - hxxp://www.yogli.com/ (file missing) O9 - Extra 'Tools' menuitem: Get More Games - {120CC99A-8016-42d4-93AF-8C5FE64FE4E3} - hxxp://www.yogli.com/ (file missing) O9 - Extra button: In Blog veröffentlichen - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: In Windows Live Writer in Blog veröffentliche&n - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgidsagent.exe O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2014\avgwdsvc.exe O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe O23 - Service: Acer ePower Service (ePowerSvc) - Acer Incorporated - C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe O23 - Service: GRegService (Greg_Service) - Acer Incorporated - C:\Program Files\Acer\Registration\GregHSRW.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: MyWinLocker Service (MWLService) - Egis Technology Inc. - C:\Program Files\EgisTec\MyWinLocker 3\x86\\MWLService.exe O23 - Service: PMBDeviceInfoProvider - Sony Corporation - C:\Program Files\Sony\PMB\PMBDeviceInfoProvider.exe O23 - Service: Raw Socket Service (RS_Service) - Acer Incorporated - C:\Program Files\Acer\Acer VCM\RS_Service.exe O23 - Service: Updater Service - Acer - C:\Program Files\Acer\Acer Updater\UpdaterService.exe O23 - Service: Vodafone Mobile Connect Service (VMCService) - Vodafone - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe -- End of file - 7863 bytes Hoffe ihr könnt mir helfen Dahaca //GMER konnte ich nicht ausführen. Beim ersten versuch gab es einen Bluescreen, beim Zweiten wurde der Prozess beendet ( keine Reaktion von Programm ) Geändert von Dahaca (16.01.2014 um 19:11 Uhr) Grund: //GMER |
17.01.2014, 08:01 | #2 |
/// the machine /// TB-Ausbilder | Win7: Netbook RAM immer ausgelastet hi,
__________________ProcessExplorer als Ersatz für den Windows Taskmanager installieren Lade Dir den Process Explorer als Ersatz für den Taskmanager herunter und installiere ihn, hier findest Du eine Anleitung. Das ist ein wesentlich leistungsfähigerer Ersatz für den Windows-Taskmanager. Im Menü unter "Options" kannst Du den ProcessExplorer dauerhaft als Ersatz für den Taskmanager einrichten (Replace Taskmanager). Das ist sehr empfehlenswert, weil der ProcessExplorer erheblich mehr Funktionen als der Taskmanager hat. Wenn Du diese Einstellung gemacht hast, öffnet sich mit der Tastenkombination STRG + ALT + Entf. nicht mehr der Taskmanager, sondern der ProcessExplorer. Das kann jederzeit durch Abhaken dieser Einstellung wieder rückgängig gemacht werden. Was wir jetzt konkret brauchen: In jeder Zeile steht ein Prozess, ein paar der Zeilen sind keine richtigen Prozesse, sondern nur Pseudoprozesse für die Tätigkeit des Windos-Kernels. Im Menü View => Select Columns wird ein Dialog geöffnet, in dem Du auswählen kannst, welche Spalten mit Informationen zu den Prozessen angezeigt werden sollen. In dem gehe in das Register "Process Performance" und stelle sicher, dass dort "CPU Usage" angehakt ist, "CPU History" wäre ebenfalls sinnvoll. Unter "CPU Usage" wird der aktuelle Wert der Prozessorauslastung für jeden Prozess angezeigt (im Tabellentitel steht nur kurz "CPU"), "CPU History" blendet für jeden Prozess ein Diagramm ein, das eine Kurve mit der Prozessorauslastung für die letzte Zeit anzeigt. Damit sollte es Dir möglich sein, zu identifizieren, welcher Prozess Deine CPU in Trab hält. Mache einen Doppelklick auf den Prozess. Du kannst von dem ganzen auch einen Screenshot machen und ihn als Anhang mit Deiner Antwort hochladen (auf "Erweitert" unter dem Textfeld klicken und über "Anhänge verwalten" auf Deinem Rechner suchen lassen und über "Hochladen" anhängen).
__________________ |
17.01.2014, 16:55 | #3 | |
| Win7: Netbook RAM immer ausgelastet Hallo schrauber
__________________Hier hab ich mal das Ergebnis als .txt Zitat:
Und als Anhang hab ich noch einen 3 teiligen Screenshot. Hoffe du erkennst da mehr als ich Dahaca |
18.01.2014, 07:54 | #4 |
/// the machine /// TB-Ausbilder | Win7: Netbook RAM immer ausgelastet Screenshot 1, TrustedInstaller zieht Power, was ist da gelaufen?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.01.2014, 09:02 | #5 |
| Win7: Netbook RAM immer ausgelastet Hallo schrauber Eigentlich nichts... habe das Netbook gerade nochmal frisch gestartet und Trustedinstaller.exe läuft wieder ... obwohl alle Programme beendenet wurden. Wenn ich diesen Prozess kille, läuft das Netbook etwas besser. Aber wieso läut dieser im Hintergrund, wenn keine anderes Programm aktiv ist ( bis auf AVG) Dahaca Geändert von Dahaca (18.01.2014 um 09:09 Uhr) |
18.01.2014, 17:06 | #6 |
/// the machine /// TB-Ausbilder | Win7: Netbook RAM immer ausgelastet Mach bitte nen Klick auf das Plus vor TrustedInstaller, dann nochmal einen Screenshot davon.
__________________ --> Win7: Netbook RAM immer ausgelastet |
19.01.2014, 11:17 | #7 |
| Win7: Netbook RAM immer ausgelastet Nachdem ich den Prozess gekillt habe, wird er nicht mehr angezeigt .. auch nich nach einem neustart. |
19.01.2014, 11:26 | #8 |
/// the machine /// TB-Ausbilder | Win7: Netbook RAM immer ausgelastet Auch gut. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
22.01.2014, 16:44 | #9 |
| Win7: Netbook RAM immer ausgelastet Das sollte alles gewesen sein, insofern das die Logs nich noch irgend etwas zeigen Viele Dank Dahaca |
23.01.2014, 10:44 | #10 |
/// the machine /// TB-Ausbilder | Win7: Netbook RAM immer ausgelastet Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Win7: Netbook RAM immer ausgelastet |
acer aspire, acrobat update, antivirus, ausgelastet, auslastung, avg antivirus, bonjour, browser, device driver, error, excel, flash player, helper, hijack, hijackthis, kaspersky, klelam.sys, langsam, launch, logfile, mozilla, newtab, problem, prozessor, realtek, registry, scan, security, software, svchost.exe, vista, windows, wlansvc |