![]() |
|
Log-Analyse und Auswertung: Win 7 - Firefox langsam, Skript-Warnmeldungen und "keine Rückmeldung" in TitelleisteWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() ![]() | ![]() Win 7 - Firefox langsam, Skript-Warnmeldungen und "keine Rückmeldung" in Titelleiste Hallo, ich bin neu hier und in sachen computer ein totaler Dummie.... so nun zu meinem Problem. seit einiger zeit ist mir schon aufgefallen das der rechner langsamer hochfährt. Firefox ist stellenweise sehr langsam und schon einige mal komplett abgestürzt; außerdem erhalte ich öfters in der Titelleistung die Meldung "(keine Rückmeldung)" und Warnmeldungen, dass ein Skript nicht antwortet oder beschädigt ist, wie z.B.: "Skript: chrome://wrc/content/common/scripts/bal.js:1172 Ich hab mal versucht nach Anleitung die Log Files zu erstellen Log File FRST: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-02-2014 01 Ran by oliver at 2014-02-12 09:25:43 Running from C:\Users\oliver\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== Adobe AIR (x32 Version: 2.6.0.19120 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 2.6.0.19120 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader XI (11.0.03) - Deutsch (x32 Version: 11.0.03 - Adobe Systems Incorporated) AMD APP SDK Runtime (Version: 10.0.851.4 - Advanced Micro Devices Inc.) Hidden AMD Catalyst Install Manager (Version: 3.0.859.0 - Advanced Micro Devices, Inc.) AMD Media Foundation Decoders (Version: 1.0.70314.1441 - Advanced Micro Devices, Inc.) Hidden AMD Steady Video Plug-In (Version: 2.03.0000 - AMD) Hidden AMD VISION Engine Control Center (x32 Version: 2012.0314.1418.23691 - Ihr Firmenname) Hidden Apple Application Support (x32 Version: 2.3 - Apple Inc.) Apple Software Update (x32 Version: 2.1.3.127 - Apple Inc.) Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (x32 Version: 2.0.12.13 - Atheros Communications Inc.) Atheros Driver Installation Program (x32 Version: 9.0 - Atheros) avast! Free Antivirus (x32 Version: 9.0.2011 - Avast Software) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0314.1418.23691 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center InstallProxy (x32 Version: 2012.0314.1418.23691 - Advanced Micro Devices, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2012.0314.1418.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Standard (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Chinese Traditional (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Czech (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Danish (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Dutch (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help English (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Finnish (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help French (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help German (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Greek (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Hungarian (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Italian (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Japanese (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Korean (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Norwegian (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Polish (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Portuguese (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Russian (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Spanish (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Swedish (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Thai (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden CCC Help Turkish (x32 Version: 2012.0314.1417.23691 - Advanced Micro Devices, Inc.) Hidden ccc-utility64 (Version: 2012.0314.1418.23691 - Advanced Micro Devices, Inc.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dropbox (HKCU Version: 2.4.10 - Dropbox, Inc.) ETDWare PS/2-X64 10.6.9.9_WHQL (Version: 10.6.9.9 - ELAN Microelectronic Corp.) Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Free YouTube to MP3 Converter version 3.12.16.1030 (x32 Version: 3.12.16.1030 - DVDVideoSoft Ltd.) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotogràfica del Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden GIMP 2.8.2 (Version: 2.8.2 - The GIMP Team) Inkscape 0.48.4 (x32 Version: 0.48.4 - ) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Launch Manager (x32 Version: 5.1.15 - Packard Bell) LiveSupport (x32 Version: 1.2.7.0 - PC Utilities Software Limited) <==== ATTENTION Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (x32 Version: 10.0.30319 - Microsoft Corporation) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) Mozilla Maintenance Service (x32 Version: 26.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) Nero BackItUp 10 (x32 Version: 5.8.11100.9.100 - Nero AG) Nero BackItUp 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden Nero Control Center 10 (x32 Version: 10.6.12700.0.7 - Nero AG) Hidden Nero ControlCenter 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden Nero Core Components 10 (x32 Version: 2.0.19900.9.11 - Nero AG) Hidden Nero DiscSpeed 10 (x32 Version: 6.4.10500.1.100 - Nero AG) Nero DiscSpeed 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden Nero Express 10 (x32 Version: 10.6.10700.5.100 - Nero AG) Nero Express 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden Nero Multimedia Suite 10 Essentials (x32 Version: 10.6.10300 - Nero AG) Nero Multimedia Suite 10 Essentials (x32 Version: 10.6.10400 - Nero AG) Nero RescueAgent 10 (x32 Version: 3.6.10500.3.100 - Nero AG) Nero RescueAgent 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden Nero StartSmart 10 (x32 Version: 10.6.10600.4.100 - Nero AG) Nero StartSmart 10 Help (CHM) (x32 Version: 10.6.10700 - Nero AG) Hidden Nero Update (x32 Version: 1.0.10900.31.0 - Nero AG) OpenOffice.org 3.4.1 (x32 Version: 3.41.9593 - Apache Software Foundation) Packard Bell Power Management (x32 Version: 6.00.3010 - Packard Bell) Packard Bell Recovery Management (x32 Version: 5.00.3507 - Packard Bell) Packard Bell Updater (x32 Version: 1.02.3501 - Packard Bell) Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden PosteRazor (x32 Version: 1.5.2 - Alessandro Portale) QuickTime (x32 Version: 7.73.80.64 - Apple Inc.) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden RealDownloader (x32 Version: 1.3.3 - RealNetworks, Inc.) Hidden RealNetworks - Microsoft Visual C++ 2008 Runtime (x32 Version: 9.0 - RealNetworks, Inc) Hidden RealNetworks - Microsoft Visual C++ 2010 Runtime (x32 Version: 10.0 - RealNetworks, Inc) Hidden RealPlayer (x32 Version: 16.0.3 - RealNetworks) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6559 - Realtek Semiconductor Corp.) Realtek PCIE Card Reader (x32 Version: 6.1.7601.28094 - Realtek Semiconductor Corp.) RealUpgrade 1.1 (x32 Version: 1.1.0 - RealNetworks, Inc.) Hidden Skype™ 5.10 (x32 Version: 5.10.116 - Skype Technologies S.A.) Sony PC Companion 2.10.181 (x32 Version: 2.10.181 - Sony) StreamTransport version: 1.1.0.2 (x32 Version: - ) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Video Web Camera (x32 Version: 1.5.2624.00 - CyberLink Corp.) Video Web Camera (x32 Version: 1.5.2624.00 - CyberLink Corp.) Hidden Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Windows Live Fotogaléria (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalleri (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotótár (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galeria de Fotos (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Galerija fotografija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven sähköposti (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 03-01-2014 09:38:42 Windows Update 04-01-2014 09:54:22 TuneUp Utilities 2014 wird entfernt 04-01-2014 09:55:32 TuneUp Utilities 2014 (de-DE) wird entfernt 07-01-2014 08:00:09 Windows Update 14-01-2014 07:37:06 Windows Update 15-01-2014 21:17:17 Windows Update 21-01-2014 18:28:38 Windows Update 28-01-2014 07:40:02 Windows Update 31-01-2014 16:11:41 Windows Update 04-02-2014 16:18:23 Windows Update 07-02-2014 20:19:23 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2013-08-26 09:37 - 00450636 ____R C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123fporn.info 127.0.0.1 www.123fporn.info 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123moviedownload.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {012F7C0A-3174-4723-8CEA-C18746449FDF} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-1750516870-544835136-2035900611-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {1181BE52-D6BB-43DA-9861-F59AE74FB943} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-1750516870-544835136-2035900611-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {36A31E85-73A9-49B0-8482-C9EA1EFF7971} - System32\Tasks\Real Player-Online-Aktualisierungsprogramm => c:\program files (x86)\real\realplayer\Update\realsched.exe [2013-09-05] (RealNetworks, Inc.) Task: {37E61DF0-8440-47B7-96EB-CAC9344B9742} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-05-11] (Adobe Systems Incorporated) Task: {5610F3DB-AF64-4982-B226-238CF61E5AF1} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-1750516870-544835136-2035900611-1001 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe [2013-08-14] (RealNetworks, Inc.) Task: {E89694AE-1FEF-46D7-8191-66E4568A999C} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-12-29] (AVAST Software) ==================== Loaded Modules (whitelisted) ============= 2014-02-11 20:11 - 2014-02-11 10:39 - 02172928 _____ () C:\Program Files\AVAST Software\Avast\defs\14021100\algo.dll 2014-02-12 08:52 - 2014-02-11 20:39 - 02172928 _____ () C:\Program Files\AVAST Software\Avast\defs\14021101\algo.dll 2013-08-14 14:19 - 2013-08-14 14:19 - 00039056 _____ () C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe 2013-12-29 19:41 - 2013-12-29 19:41 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2013-12-20 19:57 - 2013-12-20 19:57 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupfolder: C:^Users^oliver^AppData^Roaming^Microsoft^Windows^Start Menu^Programs^Startup^Dropbox.lnk => C:\Windows\pss\Dropbox.lnk.Startup MSCONFIG\startupreg: LManager => C:\Program Files (x86)\Launch Manager\LManager.exe MSCONFIG\startupreg: mobilegeni daemon => C:\Program Files (x86)\Mobogenie\DaemonProcess.exe MSCONFIG\startupreg: NextLive => C:\Windows\SysWOW64\rundll32.exe "C:\Users\oliver\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l MSCONFIG\startupreg: Power Management => C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe MSCONFIG\startupreg: Sony PC Companion => "C:\Program Files (x86)\Sony\Sony PC Companion\PCCompanion.exe" /Background MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: TkBellExe => "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot MSCONFIG\startupreg: Vidalia => "C:\Program Files (x86)\Vidalia Relay Bundle\Vidalia\vidalia.exe" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/12/2014 08:52:38 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/11/2014 08:10:56 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/11/2014 08:34:09 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/10/2014 10:00:16 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: plugin-container.exe, Version: 26.0.0.5087, Zeitstempel: 0x52a0d293 Name des fehlerhaften Moduls: mozalloc.dll, Version: 26.0.0.5087, Zeitstempel: 0x52a0af28 Ausnahmecode: 0x80000003 Fehleroffset: 0x0000119c ID des fehlerhaften Prozesses: 0x90c Startzeit der fehlerhaften Anwendung: 0xplugin-container.exe0 Pfad der fehlerhaften Anwendung: plugin-container.exe1 Pfad des fehlerhaften Moduls: plugin-container.exe2 Berichtskennung: plugin-container.exe3 Error: (02/10/2014 06:57:42 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/10/2014 09:06:36 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/09/2014 08:58:24 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1". Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (02/09/2014 07:18:17 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 07:18:16 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (02/09/2014 07:18:16 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest2" in Zeile C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Komponente 2: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. System errors: ============= Error: (02/09/2014 07:26:11 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "SUSI-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{79CF20AC-3CBA-4637-96A2-5DB6BCE2774B}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (02/09/2014 06:50:29 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "SUSI-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{79CF20AC-3CBA-4637-96A2-5DB6BCE2774B}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (02/09/2014 06:38:28 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "SUSI-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{79CF20AC-3CBA-4637-96A2-5DB6BCE2774B}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (02/04/2014 02:11:23 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht. Error: (01/15/2014 10:17:05 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (01/12/2014 06:54:40 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "WinkHandler" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (01/12/2014 06:54:40 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SProtection" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (01/11/2014 08:41:01 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst Dnscache erreicht. Error: (01/10/2014 08:41:59 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Server" wurde mit folgendem Fehler beendet: %%1062 Error: (01/10/2014 08:41:58 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-2147467243. Microsoft Office Sessions: ========================= Error: (02/12/2014 08:52:38 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/11/2014 08:10:56 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/11/2014 08:34:09 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/10/2014 10:00:16 PM) (Source: Application Error)(User: ) Description: plugin-container.exe26.0.0.508752a0d293mozalloc.dll26.0.0.508752a0af28800000030000119c90c01cf2689d936e893C:\Program Files (x86)\Mozilla Firefox\plugin-container.exeC:\Program Files (x86)\Mozilla Firefox\mozalloc.dll56fe31b9-9296-11e3-9d76-dc0ea1b04dff Error: (02/10/2014 06:57:42 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/10/2014 09:06:36 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (02/09/2014 08:58:24 PM) (Source: SideBySide)(User: ) Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{C8E8D2E3-EF6A-4B1D-A09E-7B27EBE2F3CE}\recordingmanager.exe Error: (02/09/2014 07:18:17 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\$Recycle.Bin\S-1-5-21-1750516870-544835136-2035900611-1001\$RBH6G7P.exe Error: (02/09/2014 07:18:16 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\$Recycle.Bin\S-1-5-21-1750516870-544835136-2035900611-1001\$RFVIZ2K.exe Error: (02/09/2014 07:18:16 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\$Recycle.Bin\S-1-5-21-1750516870-544835136-2035900611-1001\$R2XLTT9.exe ==================== Memory info =========================== Percentage of memory in use: 40% Total physical RAM: 3689.37 MB Available physical RAM: 2185.71 MB Total Pagefile: 7376.91 MB Available Pagefile: 5749.96 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (Packard Bell) (Fixed) (Total:279.99 GB) (Free:223.63 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 71F384DC) Partition 1: (Not Active) - (Size=18 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=280 GB) - (Type=07 NTFS) ==================== End Of Log ============================ LOg File GMER Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-02-14 09:16:10 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 TOSHIBA_MK3259GSXP rev.GN003J 298,09GB Running: Gmer-19357.exe; Driver: C:\Users\oliver\AppData\Local\Temp\ufriapob.sys ---- User code sections - GMER 2.1 ---- .text C:\Windows\system32\wininit.exe[592] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\system32\services.exe[648] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\system32\winlogon.exe[728] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[812] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\system32\atiesrxx.exe[956] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\System32\svchost.exe[240] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\System32\svchost.exe[148] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[448] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[924] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\system32\WLANExt.exe[1412] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\System32\spoolsv.exe[1588] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1624] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe[1728] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000766ba2ba 1 byte [62] .text C:\Program Files (x86)\Launch Manager\dsiwmis.exe[1776] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000766ba2ba 1 byte [62] .text C:\Program Files (x86)\Launch Manager\LMutilps32.exe[1824] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000766ba2ba 1 byte [62] .text C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe[1836] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\system32\svchost.exe[1868] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe[1908] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000766ba2ba 1 byte [62] .text C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe[2004] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000766ba2ba 1 byte [62] .text C:\Windows\system32\svchost.exe[1200] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\system32\taskhost.exe[2356] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\Explorer.EXE[2512] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[2732] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000766ba2ba 1 byte [62] .text C:\Windows\system32\SearchIndexer.exe[2056] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Program Files\Windows Media Player\wmpnetwk.exe[3716] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe[4016] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe[3936] C:\Windows\system32\kernel32.dll!GetBinaryTypeW + 189 000000007743eecd 1 byte [62] .text C:\Program Files (x86)\Nero\Update\NASvc.exe[4024] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000766ba2ba 1 byte [62] .text C:\Users\oliver\Downloads\Gmer-19357.exe[3636] C:\Windows\syswow64\kernel32.dll!GetBinaryTypeW + 112 00000000766ba2ba 1 byte [62] ---- Threads - GMER 2.1 ---- Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3496:3748] 00000000764d7587 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3496:3740] 000000006c0b0cb3 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3496:784] 0000000077732e65 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3496:2028] 0000000077733e85 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3496:3932] 0000000077733e85 Thread C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [3496:1736] 0000000077733e85 Thread C:\Windows\System32\svchost.exe [4084:1056] 000007fef16e9688 ---- EOF - GMER 2.1 ---- |
Themen zu Win 7 - Firefox langsam, Skript-Warnmeldungen und "keine Rückmeldung" in Titelleiste |
"keine rückmeldung", antivirus, branding, computer, converter, dvdvideosoft ltd., error, firefox, flash player, help, installation, keine rückmeldung, langsam, log, mobogenie, mobogenie entfernen, neu, nextlive, packard bell, rundll, security, server, services.exe, software, svchost.exe, taskhost.exe, win32/bagle.gen.zip, winlogon.exe, wmp |