![]() |
|
Plagegeister aller Art und deren Bekämpfung: Windows 7, hohe CPU Auslastung, Windows Sicherheitsupdate fehlgeschlagen, Bluescreen im abgesicherten ModusWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #9 |
| ![]() Windows 7, hohe CPU Auslastung, Windows Sicherheitsupdate fehlgeschlagen, Bluescreen im abgesicherten Modus Eset Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=3d68647c57a0c1459cf4eb4afc852978 # engine=17289 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-03-03 12:26:07 # local_time=2014-03-03 05:56:07 (+0530, Indien Normalzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 94 0 1495521 5077 0 # compatibility_mode=5122 16777214 66 88 435765 142630363 0 0 # compatibility_mode=5893 16776574 100 94 619129 145480607 0 0 # scanned=308618 # found=0 # cleaned=0 # scan_time=19655 Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop McAfee Anti-Virus und Anti-Spyware Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 25 Java version out of Date! Adobe Flash Player 11.9.900.117 Adobe Reader XI Mozilla Firefox 14.0.1 Firefox out of Date! Google Chrome 32.0.1700.107 Google Chrome 33.0.1750.117 ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 26-02-2014 Ran by Admin (administrator) on ELLISTUDIO on 03-03-2014 18:31:24 Running from C:\Users\Admin\Desktop Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (IDT, Inc.) C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe (SANDBOXIE L.T.D) C:\Program Files\Sandboxie\SbieSvc.exe (AMD) C:\Windows\system32\atieclxx.exe () C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRYSVC.EXE (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Dell Inc.) C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.EXE (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Akamai Technologies, Inc.) C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (McAfee, Inc.) C:\Program Files\McAfee Security Scan\3.8.141\SSScheduler.exe (Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe () C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe (Creative Technology Ltd) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe (Akamai Technologies, Inc.) C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe (Advanced Micro Devices Inc.) c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\mcuicnt.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (McAfee, Inc.) C:\Windows\system32\mfevtps.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (McAfee, Inc.) C:\Program Files\McAfee\MSC\McAPExe.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\SystemCore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\OIS.EXE (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\saUI.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1812776 2009-06-26] (Synaptics Incorporated) HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Program Files\Dell\Dell Wireless WLAN Card\WLTRAY.exe [4968960 2009-07-17] (Dell Inc.) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [444416 2009-06-29] (IDT, Inc.) HKLM\...\Run: [AdobeAAMUpdater-1.0] - C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [StartCCC] - c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-06-26] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Dell DataSafe Online] - C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe [1779952 2009-09-11] () HKLM-x32\...\Run: [Dell Webcam Central] - C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell2.exe [409744 2009-06-25] (Creative Technology Ltd) HKLM-x32\...\Run: [mcui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-01-28] (McAfee, Inc.) HKLM-x32\...\Run: [SwitchBoard] - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] - C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKLM-x32\...\Run: [mcpltui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [537992 2014-01-28] (McAfee, Inc.) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-14] (Avira Operations GmbH & Co. KG) HKU\.DEFAULT\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.) HKU\S-1-5-21-514620546-2420533273-4033156755-1001\...\Run: [Akamai NetSession Interface] - C:\Users\Admin\AppData\Local\Akamai\netsession_win.exe [4489472 2013-06-05] (Akamai Technologies, Inc.) HKU\S-1-5-21-514620546-2420533273-4033156755-1001\...\Run: [Skype] - C:\Program Files (x86)\Skype\Phone\Skype.exe [17418928 2012-07-13] (Skype Technologies S.A.) HKU\S-1-5-21-514620546-2420533273-4033156755-1001\...\Policies\system: [LogonHoursAction] 2 HKU\S-1-5-21-514620546-2420533273-4033156755-1001\...\Policies\system: [DontDisplayLogonHoursWarnings] 1 Startup: C:\Users\Admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Elena\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Gast\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Mein PC ist kapputt!\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\TEMP.ElliStudio.004\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) GroupPolicyUsers\S-1-5-21-514620546-2420533273-4033156755-1008\User: Group Policy restriction detected <======= ATTENTION GroupPolicyUsers\S-1-5-21-514620546-2420533273-4033156755-1003\User: Group Policy restriction detected <======= ATTENTION ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.arcor.de HKCU\Software\Microsoft\Internet Explorer\Main,First Home Page = hxxp://www.arcor.de HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.arcor.de HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.arcor.de HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,First Home Page = hxxp://www.arcor.de URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) URLSearchHook: HKCU - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {209BB6AF-0FF3-4C88-8D7B-131450AF8B07} URL = hxxp://de.search.yahoo.com/search?fr=mcafee&p={SearchTerms} SearchScopes: HKCU - {2982BB9C-0A29-437F-90DD-DDCC5EE7425F} URL = SearchScopes: HKCU - {5EE2827A-84BA-473D-9320-706815A290D2} URL = SearchScopes: HKCU - {70529E6B-2032-4E4A-99A8-EE1D3EEE2F98} URL = hxxp://de.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&type=971163&p={searchTerms} BHO: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - c:\PROGRA~1\mcafee\msk\MSKAPB~1.DLL No File BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll No File BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files\McAfee Security Scan\3.8.141\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: McAfee Phishing Filter - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - C:\Program Files\McAfee\MSK\mskapbho.dll () BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.) Tcpip\..\Interfaces\{10DD2073-AB81-4288-903C-6A92B4A1620C}: [NameServer]208.67.222.222,208.67.220.220 FireFox: ======== FF ProfilePath: C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\lcb8owwo.default FF SelectedSearchEngine: Sichere Suche FF Homepage: hxxp://www.google.de/ FF Keyword.URL: hxxp://de.search.yahoo.com/search?fr=mcafee&p= FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_117.dll () FF Plugin: @mcafee.com/MSC,version=10 - c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_117.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @mcafee.com/McAfeeMssPlugin - C:\Program Files\McAfee Security Scan\3.8.141\npMcAfeeMss.dll (McAfee, Inc.) FF Plugin-x32: @mcafee.com/MSC,version=10 - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=14.0.8117.0416 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: wacom.com/WacomTabletPlugin - C:\Program Files (x86)\TabletPlugins\npWacomTabletPlugin.dll No File FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\McSiteAdvisor.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Start Page - C:\Users\Admin\AppData\Roaming\Mozilla\Firefox\Profiles\lcb8owwo.default\Extensions\{badea1ae-72ed-4f6a-8c37-4db9a4ac7bc9} [2013-12-11] FF HKLM-x32\...\Firefox\Extensions: [{4ED1F68A-5463-4931-9384-8FFF5ED91D92}] - C:\Program Files (x86)\McAfee\SiteAdvisor FF Extension: McAfee SiteAdvisor - C:\Program Files (x86)\McAfee\SiteAdvisor [2011-03-27] FF HKLM-x32\...\Thunderbird\Extensions: [msktbird@mcafee.com] - C:\Program Files\McAfee\MSK FF Extension: McAfee Anti-Spam Thunderbird Extension - C:\Program Files\McAfee\MSK [2011-03-27] Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-11-07] CHR Extension: (Google Drive) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-11-07] CHR Extension: (YouTube) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-11-07] CHR Extension: (McAfee Security Scan+) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\bopakagnckmlgajfccecajhnimjiiedh [2014-02-26] CHR Extension: (Google-Suche) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-11-07] CHR Extension: (SiteAdvisor) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2014-02-20] CHR Extension: (Google Wallet) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-11-07] CHR Extension: (Google Mail) - C:\Users\Admin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-11-07] CHR HKCU\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\Admin\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-11-07] CHR HKLM-x32\...\Chrome\Extension: [cflheckfmhopnialghigdlggahiomebp] - C:\Users\Admin\AppData\Local\CRE\cflheckfmhopnialghigdlggahiomebp.crx [2013-11-07] ==================== Services (Whitelisted) ================= S3 Adobe LM Service; C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe [72704 2012-06-21] (Adobe Systems) R2 Akamai; c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-02] (Akamai Technologies, Inc.) R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [440400 2014-02-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-14] (Avira Operations GmbH & Co. KG) R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McAfee SiteAdvisor Service; C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe [201304 2012-08-31] (McAfee, Inc.) R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178528 2014-01-28] (McAfee, Inc.) S3 McComponentHostService; C:\Program Files\McAfee Security Scan\3.8.141\McCHSvc.exe [289256 2014-01-16] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S3 McODS; C:\Program Files\McAfee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1025232 2013-12-11] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219752 2014-01-27] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [185792 2014-01-27] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S3 npggsvc; C:\Windows\SysWOW64\GameMon.des [3453712 2009-12-16] (INCA Internet Co., Ltd.) R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [97552 2012-02-06] (SANDBOXIE L.T.D) R2 STacSV; C:\Windows\System32\DriverStore\FileRepository\stwrt64.inf_amd64_neutral_afc3018f8cfedd20\STacSV64.exe [240128 2009-06-29] (IDT, Inc.) R2 wltrysvc; C:\Program Files\Dell\Dell Wireless WLAN Card\bcmwltry.exe [3417088 2009-07-17] (Dell Inc.) ==================== Drivers (Whitelisted) ==================== S3 ALCATELUSB; C:\Windows\System32\Drivers\AlcatelUsb.sys [25088 2011-06-20] (Windows (R) Codename Longhorn DDK provider) S2 atksgt; C:\Windows\System32\DRIVERS\atksgt.sys [303616 2010-02-23] () R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [108440 2014-02-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [131576 2014-02-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2014-02-14] (Avira Operations GmbH & Co. KG) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70592 2014-01-27] (McAfee, Inc.) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) S3 jrdusbser; C:\Windows\System32\DRIVERS\jrdusbser.sys [120832 2011-06-20] (TCT International Mobile Ltd) S2 lirsgt; C:\Windows\System32\DRIVERS\lirsgt.sys [35328 2010-02-23] () R2 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [180272 2014-01-27] (McAfee, Inc.) R2 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311600 2014-01-27] (McAfee, Inc.) S3 mfebopk; C:\Windows\System32\drivers\mfebopk.sys [41032 2009-06-18] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [520696 2014-01-27] (McAfee, Inc.) R2 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [783864 2014-01-27] (McAfee, Inc.) R3 mfencbdc; C:\Windows\System32\DRIVERS\mfencbdc.sys [411944 2013-11-26] (McAfee, Inc.) S3 mfencrk; C:\Windows\System32\DRIVERS\mfencrk.sys [96112 2013-11-26] (McAfee, Inc.) S3 mferkdk; C:\Windows\System32\drivers\mferkdk.sys [40904 2009-11-04] (McAfee, Inc.) S3 mfesmfk; C:\Windows\System32\drivers\mfesmfk.sys [49480 2009-11-04] (McAfee, Inc.) R2 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [344688 2014-01-27] (McAfee, Inc.) S3 NPPTNT2; C:\Windows\SysWOW64\npptNT2.sys [4682 2004-12-31] (INCA Internet Co., Ltd.) R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [161432 2012-02-06] (SANDBOXIE L.T.D) S1 SSHDRV76; C:\Windows\SysWOW64\drivers\SSHDRV76.sys [53760 2010-03-01] () U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [X] S3 dump_wmimmc; \??\C:\Program Files\gPotato.eu\Rappelz\GameGuard\dump_wmimmc.sys [X] S3 hwdatacard; system32\DRIVERS\ewusbmdm.sys [X] S3 hwusbdev; system32\DRIVERS\ewusbdev.sys [X] S3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0; \??\c:\program files\dell support center\pcdsrvc_x64.pkms [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-03-03 18:31 - 2014-03-03 18:31 - 00001037 _____ () C:\Users\Admin\Desktop\checkup.txt 2014-03-03 18:00 - 2014-03-03 18:00 - 00003354 _____ () C:\Windows\System32\Tasks\{1FB7A1BA-1258-4B0B-B392-3CE3B83EA99B} 2014-03-03 17:54 - 2014-03-03 17:54 - 00987425 _____ () C:\Users\Admin\Desktop\SecurityCheck.exe 2014-03-03 12:18 - 2014-03-03 12:18 - 02347384 _____ (ESET) C:\Users\Admin\Desktop\esetsmartinstaller_enu.exe 2014-03-01 17:17 - 2014-03-03 18:31 - 00023535 _____ () C:\Users\Admin\Desktop\FRST.txt 2014-03-01 17:16 - 2014-03-01 17:16 - 00000000 ____D () C:\Users\Admin\Desktop\1 2014-03-01 17:13 - 2014-03-01 17:13 - 00000694 _____ () C:\Users\Admin\Desktop\JRT.txt 2014-03-01 16:13 - 2014-03-01 16:13 - 00000000 ____D () C:\Windows\ERUNT 2014-03-01 16:08 - 2014-03-01 16:08 - 01037734 _____ (Thisisu) C:\Users\Admin\Desktop\JRT.exe 2014-03-01 15:48 - 2014-03-01 15:54 - 00000000 ____D () C:\AdwCleaner 2014-03-01 15:30 - 2014-03-01 15:30 - 01244192 _____ () C:\Users\Admin\Desktop\adwcleaner.exe 2014-03-01 15:22 - 2014-03-01 15:22 - 00001071 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-01 15:22 - 2014-03-01 15:22 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Malwarebytes 2014-03-01 15:22 - 2014-03-01 15:22 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-01 15:22 - 2014-03-01 15:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-01 15:22 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-03-01 15:16 - 2014-03-01 15:17 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Admin\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-28 11:39 - 2014-02-28 11:39 - 00029818 _____ () C:\Users\Admin\Desktop\ComboFix.txt 2014-02-28 11:09 - 2014-02-28 11:39 - 00000000 ____D () C:\Qoobox 2014-02-28 11:09 - 2014-02-28 11:39 - 00000000 ____D () C:\ComboFix 2014-02-28 11:09 - 2014-02-28 11:35 - 00000000 ____D () C:\Windows\erdnt 2014-02-28 11:09 - 2011-06-26 12:15 - 00256000 _____ () C:\Windows\PEV.exe 2014-02-28 11:09 - 2010-11-07 22:50 - 00208896 _____ () C:\Windows\MBR.exe 2014-02-28 11:09 - 2009-04-20 10:26 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-02-28 11:09 - 2000-08-31 05:30 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-02-28 11:09 - 2000-08-31 05:30 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-02-28 11:09 - 2000-08-31 05:30 - 00098816 _____ () C:\Windows\sed.exe 2014-02-28 11:09 - 2000-08-31 05:30 - 00080412 _____ () C:\Windows\grep.exe 2014-02-28 11:09 - 2000-08-31 05:30 - 00068096 _____ () C:\Windows\zip.exe 2014-02-28 10:42 - 2014-02-28 10:43 - 05185084 ____R (Swearware) C:\Users\Admin\Desktop\ComboFix.exe 2014-02-26 16:04 - 2014-03-03 18:31 - 00000000 ____D () C:\FRST 2014-02-26 16:00 - 2014-02-26 16:01 - 02155520 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe 2014-02-26 16:00 - 2014-02-26 16:00 - 00000000 ____D () C:\Users\Admin\Desktop\aufräumen 2014-02-26 11:16 - 2014-02-26 11:01 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-02-25 17:25 - 2014-02-25 17:25 - 00001933 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2014-02-25 17:25 - 2014-02-25 17:25 - 00000000 ____D () C:\Program Files\McAfee Security Scan 2014-02-24 16:28 - 2014-02-24 16:28 - 00000000 ____D () C:\Users\Elena\AppData\Roaming\Avira 2014-02-24 16:27 - 2014-02-24 16:27 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Avira 2014-02-24 16:20 - 2014-02-24 16:20 - 00002028 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-02-24 16:19 - 2014-02-24 16:19 - 00000000 ____D () C:\ProgramData\Avira 2014-02-24 16:19 - 2014-02-24 16:19 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-02-24 16:19 - 2014-02-14 11:00 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-02-24 16:19 - 2014-02-14 11:00 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-02-24 16:19 - 2014-02-14 11:00 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-02-24 15:54 - 2014-02-24 16:14 - 137004504 _____ () C:\Users\Elena\Downloads\avira_free_antivirus1403_de.exe 2014-02-24 13:38 - 2014-02-24 13:38 - 00275504 _____ () C:\Windows\Minidump\022414-19765-01.dmp 2014-02-24 10:55 - 2014-02-24 10:55 - 00271200 _____ () C:\Windows\Minidump\022414-21356-01.dmp 2014-02-22 16:00 - 2014-02-22 16:00 - 00000000 ____D () C:\Windows\CheckSur 2014-02-22 15:09 - 2014-02-26 11:02 - 01594964 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-06 17:02 - 2014-02-22 10:43 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-06 16:49 - 2014-02-06 16:53 - 24243336 _____ (Skype Technologies S.A.) C:\Users\Elena\Downloads\SkypeSetupFull_201202221217.exe ==================== One Month Modified Files and Folders ======= 2014-03-03 18:32 - 2014-03-01 17:17 - 00023535 _____ () C:\Users\Admin\Desktop\FRST.txt 2014-03-03 18:31 - 2014-03-03 18:31 - 00001037 _____ () C:\Users\Admin\Desktop\checkup.txt 2014-03-03 18:31 - 2014-02-26 16:04 - 00000000 ____D () C:\FRST 2014-03-03 18:31 - 2012-07-28 18:44 - 00575067 _____ () C:\Windows\setupact.log 2014-03-03 18:29 - 2010-02-17 13:16 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Skype 2014-03-03 18:21 - 2009-07-14 10:15 - 00014240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-03-03 18:21 - 2009-07-14 10:15 - 00014240 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-03-03 18:18 - 2009-07-14 10:40 - 01066012 _____ () C:\Windows\WindowsUpdate.log 2014-03-03 18:12 - 2013-05-17 00:35 - 00001104 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-03-03 18:11 - 2012-07-29 06:50 - 00219986 _____ () C:\Windows\PFRO.log 2014-03-03 18:11 - 2009-07-14 10:38 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-03-03 18:00 - 2014-03-03 18:00 - 00003354 _____ () C:\Windows\System32\Tasks\{1FB7A1BA-1258-4B0B-B392-3CE3B83EA99B} 2014-03-03 17:54 - 2014-03-03 17:54 - 00987425 _____ () C:\Users\Admin\Desktop\SecurityCheck.exe 2014-03-03 17:42 - 2013-05-17 00:35 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-03-03 13:01 - 2011-03-03 02:43 - 00000422 _____ () C:\Windows\Tasks\SystemToolsDailyTest.job 2014-03-03 13:00 - 2011-03-03 02:43 - 00003488 _____ () C:\Windows\System32\Tasks\PCDEventLauncher 2014-03-03 13:00 - 2011-03-03 02:43 - 00003452 _____ () C:\Windows\System32\Tasks\SystemToolsDailyTest 2014-03-03 12:18 - 2014-03-03 12:18 - 02347384 _____ (ESET) C:\Users\Admin\Desktop\esetsmartinstaller_enu.exe 2014-03-03 12:09 - 2010-01-23 22:08 - 00000000 ____D () C:\Users\Elena\AppData\Roaming\Skype 2014-03-03 10:24 - 2010-04-26 00:58 - 00003938 _____ () C:\Windows\System32\Tasks\User_Feed_Synchronization-{C38EF1FB-FE2A-49F0-AD8B-E8FFC2AE5DD3} 2014-03-01 17:16 - 2014-03-01 17:16 - 00000000 ____D () C:\Users\Admin\Desktop\1 2014-03-01 17:13 - 2014-03-01 17:13 - 00000694 _____ () C:\Users\Admin\Desktop\JRT.txt 2014-03-01 16:13 - 2014-03-01 16:13 - 00000000 ____D () C:\Windows\ERUNT 2014-03-01 16:08 - 2014-03-01 16:08 - 01037734 _____ (Thisisu) C:\Users\Admin\Desktop\JRT.exe 2014-03-01 15:54 - 2014-03-01 15:48 - 00000000 ____D () C:\AdwCleaner 2014-03-01 15:30 - 2014-03-01 15:30 - 01244192 _____ () C:\Users\Admin\Desktop\adwcleaner.exe 2014-03-01 15:22 - 2014-03-01 15:22 - 00001071 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-03-01 15:22 - 2014-03-01 15:22 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Malwarebytes 2014-03-01 15:22 - 2014-03-01 15:22 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-03-01 15:22 - 2014-03-01 15:22 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-03-01 15:17 - 2014-03-01 15:16 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Admin\Desktop\mbam-setup-1.75.0.1300.exe 2014-02-28 14:24 - 2012-11-04 22:06 - 00000000 ___RD () C:\Users\Elena\Eigene Dokumente 2014-02-28 11:39 - 2014-02-28 11:39 - 00029818 _____ () C:\Users\Admin\Desktop\ComboFix.txt 2014-02-28 11:39 - 2014-02-28 11:09 - 00000000 ____D () C:\Qoobox 2014-02-28 11:39 - 2014-02-28 11:09 - 00000000 ____D () C:\ComboFix 2014-02-28 11:39 - 2009-07-14 08:50 - 00000000 __RHD () C:\Users\Default 2014-02-28 11:35 - 2014-02-28 11:09 - 00000000 ____D () C:\Windows\erdnt 2014-02-28 11:33 - 2009-07-14 08:04 - 00000215 _____ () C:\Windows\system.ini 2014-02-28 10:43 - 2014-02-28 10:42 - 05185084 ____R (Swearware) C:\Users\Admin\Desktop\ComboFix.exe 2014-02-26 17:22 - 2011-03-27 01:02 - 00000000 ____D () C:\Program Files\Common Files\McAfee 2014-02-26 16:01 - 2014-02-26 16:00 - 02155520 _____ (Farbar) C:\Users\Admin\Desktop\FRST64.exe 2014-02-26 16:00 - 2014-02-26 16:00 - 00000000 ____D () C:\Users\Admin\Desktop\aufräumen 2014-02-26 11:39 - 2009-12-25 18:03 - 00071080 _____ () C:\Users\Admin\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-26 11:02 - 2014-02-22 15:09 - 01594964 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2014-02-26 11:02 - 2009-07-14 23:28 - 00699682 _____ () C:\Windows\system32\perfh007.dat 2014-02-26 11:02 - 2009-07-14 23:28 - 00149790 _____ () C:\Windows\system32\perfc007.dat 2014-02-26 11:01 - 2014-02-26 11:16 - 00084720 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avnetflt.sys 2014-02-26 11:01 - 2009-07-14 10:43 - 01594964 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-25 17:25 - 2014-02-25 17:25 - 00001933 _____ () C:\Users\Public\Desktop\McAfee Security Scan Plus.lnk 2014-02-25 17:25 - 2014-02-25 17:25 - 00000000 ____D () C:\Program Files\McAfee Security Scan 2014-02-25 16:04 - 2009-12-25 18:19 - 00071080 _____ () C:\Users\Elena\AppData\Local\GDIPFONTCACHEV1.DAT 2014-02-25 01:06 - 2013-05-30 21:32 - 00000000 ____D () C:\Users\TEMP.ElliStudio.004 2014-02-25 01:06 - 2013-04-30 18:47 - 00000000 ____D () C:\Users\Mein PC ist kapputt! 2014-02-25 01:06 - 2010-11-28 02:06 - 00000000 ____D () C:\Users\Gast 2014-02-25 01:06 - 2009-12-25 18:07 - 00000000 ____D () C:\Users\Admin 2014-02-25 01:06 - 2009-07-14 08:50 - 00000000 ____D () C:\Windows\registration 2014-02-24 22:24 - 2011-11-10 11:29 - 00000000 ____D () C:\Users\Elena\AppData\Local\Akamai 2014-02-24 22:11 - 2012-05-21 23:33 - 00000000 ____D () C:\Users\Elena\Downloads\Resource Hacker 2014-02-24 16:28 - 2014-02-24 16:28 - 00000000 ____D () C:\Users\Elena\AppData\Roaming\Avira 2014-02-24 16:27 - 2014-02-24 16:27 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Avira 2014-02-24 16:23 - 2012-02-07 23:15 - 00002496 _____ () C:\Windows\Sandboxie.ini 2014-02-24 16:20 - 2014-02-24 16:20 - 00002028 _____ () C:\Users\Public\Desktop\Avira Control Center.lnk 2014-02-24 16:19 - 2014-02-24 16:19 - 00000000 ____D () C:\ProgramData\Avira 2014-02-24 16:19 - 2014-02-24 16:19 - 00000000 ____D () C:\Program Files (x86)\Avira 2014-02-24 16:14 - 2014-02-24 15:54 - 137004504 _____ () C:\Users\Elena\Downloads\avira_free_antivirus1403_de.exe 2014-02-24 15:50 - 2009-12-25 18:18 - 00000000 ____D () C:\Users\Elena 2014-02-24 13:38 - 2014-02-24 13:38 - 00275504 _____ () C:\Windows\Minidump\022414-19765-01.dmp 2014-02-24 13:38 - 2012-10-18 20:51 - 228173398 _____ () C:\Windows\MEMORY.DMP 2014-02-24 13:38 - 2010-02-19 00:27 - 00000000 ____D () C:\Windows\Minidump 2014-02-24 10:55 - 2014-02-24 10:55 - 00271200 _____ () C:\Windows\Minidump\022414-21356-01.dmp 2014-02-22 16:37 - 2013-05-17 00:35 - 00004104 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-02-22 16:37 - 2013-05-17 00:35 - 00003852 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-02-22 16:20 - 2011-03-03 02:43 - 00000564 _____ () C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job 2014-02-22 16:00 - 2014-02-22 16:00 - 00000000 ____D () C:\Windows\CheckSur 2014-02-22 15:46 - 2009-12-13 16:46 - 00000000 ____D () C:\ProgramData\PCDr 2014-02-22 15:25 - 2013-08-06 15:21 - 00000000 ____D () C:\Windows\system32\MRT 2014-02-22 15:17 - 2010-03-09 14:28 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-02-22 15:10 - 2011-03-03 02:43 - 00004272 _____ () C:\Windows\System32\Tasks\PCDoctorBackgroundMonitorTask 2014-02-22 10:43 - 2014-02-06 17:02 - 00000000 ___RD () C:\Program Files (x86)\Skype 2014-02-22 10:43 - 2013-11-29 07:24 - 00000000 ____D () C:\Program Files (x86)\Idea Net Setter 2014-02-22 10:43 - 2012-08-22 20:14 - 00000000 ____D () C:\ProgramData\McAfee Security Scan 2014-02-22 10:43 - 2012-04-25 19:35 - 00000000 ____D () C:\Users\Admin\AppData\Local\Akamai 2014-02-22 10:43 - 2011-04-09 20:47 - 00000000 ____D () C:\Users\Elena\AppData\Roaming\PhotoScape 2014-02-22 10:43 - 2010-01-23 22:07 - 00000000 ____D () C:\ProgramData\Skype 2014-02-22 10:43 - 2009-07-14 08:50 - 00000000 ____D () C:\Windows\AppCompat 2014-02-22 10:41 - 2011-03-27 01:02 - 00000000 ____D () C:\Program Files\McAfee 2014-02-22 10:41 - 2009-12-13 17:01 - 00000000 ____D () C:\ProgramData\McAfee 2014-02-14 11:00 - 2014-02-24 16:19 - 00131576 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avipbb.sys 2014-02-14 11:00 - 2014-02-24 16:19 - 00108440 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys 2014-02-14 11:00 - 2014-02-24 16:19 - 00028600 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avkmgr.sys 2014-02-12 18:31 - 2013-01-24 20:07 - 00000000 ____D () C:\Users\Admin\AppData\Roaming\Dropbox 2014-02-12 18:31 - 2013-01-24 20:06 - 00000000 ____D () C:\Users\Elena\AppData\Roaming\Dropbox 2014-02-12 18:29 - 2012-09-17 00:24 - 00000000 ____D () C:\Program Files (x86)\JDownloader 2014-02-12 15:07 - 2013-01-24 20:15 - 00000000 ___RD () C:\Users\Elena\Dropbox 2014-02-06 16:53 - 2014-02-06 16:49 - 24243336 _____ (Skype Technologies S.A.) C:\Users\Elena\Downloads\SkypeSetupFull_201202221217.exe 2014-02-01 19:53 - 2009-07-14 10:38 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT Some content of TEMP: ==================== C:\Users\Admin\AppData\Local\Temp\avgnt.exe C:\Users\Admin\AppData\Local\Temp\Quarantine.exe C:\Users\Elena\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-03 11:21 ==================== End Of Log ============================ Jetzt gerade war der PC wieder sehr langsam. Kann vielleicht an den ganzen Scanns liegen kann, ich werde jetzt mal testen, auch ob sich die windows updates nun installieren lassen. Kannst du erklären was das Problem war? In den Logfiles steht ja dies und das, aber woran es jetzt so richtig lag kann ich daraus nicht lesen. :s Welche (freeware) Virensoftware ist denn zu empfehlen, die ich jetzt erstmal für den Übergang nehmen kann; da mein McAfee ja in 5 Tagen ausläuft und jetzt sagen muss, dass es ja offensichtlich nicht so eine gute arbeit geleistet hat.. Gibt es da kostenlose Programme mit denen ich soweit erstmal sicher bin, bis ich mir ein neues Programm kaufen kann? Soweit schon mal vielen herzlichen Dank! ![]() Geändert von Anina (03.03.2014 um 14:14 Uhr) |
Themen zu Windows 7, hohe CPU Auslastung, Windows Sicherheitsupdate fehlgeschlagen, Bluescreen im abgesicherten Modus |
antivirus, auslastung, bluescreen, cpu auslastung, hohe, hohe cpu, nichts, pup.optional.installcore.a, pup.optional.valueapps.a, pup.optional.wajam.a, scanner, viren, windows 7 |