|
Plagegeister aller Art und deren Bekämpfung: Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastetWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
06.04.2014, 16:37 | #1 |
| Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Hallo Lieber Helfer, schon seit Monaten ist mein Arbeitsspeicher dauerhaft zu ca. 80 % ausgelastet. Außerdem funktioniert im Mozilla Firefox kein kopieren, einfügen und ausschneiden von Textbereichen. Habe gestern im abgesicherten Modus Avira deinstalliert und musste im normalen Modus Avast intallieren, weil dies im abgesicherten Modus nicht möglich war. Zudem führte ich gestern eine Vollständige Übeprüfung mit Avast durch und gefunden wurde: nsis.hdr / NSIS:Nextlive-A automatisch in den Container verschoben Logdateien hatte ich bis heute noch nie erstellt und weiß nicht ob Avast eine Logdatei erstellt hat. Habe die FAQ's aufmerksam gelesen und die Suchfunktion von Trojaner-board genutzt, sowie Google und den Hilfe-Inhalt von Avast, außerdem die Suchfunktion in meinem Windows System. Aber bisherige Log files konnte ich nicht finden! Mir ist der Ort bekannt, wo eine Log von Avast existieren müsste: C:\Programme\AVAST Software\Acast Doch ich kann nichts näheres zum letzten Fund finden.. entschuldige, wenn ich auf dem Schlauch stehen sollte. Bitte sage mir ob du etwas sehen kannst, in meinen hochgeladenen Log's, was meinen Arbeitsspeicher auslastet und/oder ob mein PC infiziert ist, und wie ich für weitere Hilfestellungen deinerseits behilflich sein kann. Vielen Dank im voraus Liebe Grüße kazuya |
06.04.2014, 18:29 | #2 |
/// the machine /// TB-Ausbilder | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
06.04.2014, 22:55 | #3 |
| Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Huhu,
__________________hier dann der richtige Post. Danke für den Hinweis: (Kurze Wiederholung zu meinem Anliegen: kannst du mir sagen, was meinen Arbeitsspeicher dauerhaft zu ca. 80 % auslastet?) Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 14:20 on 06/04/2014 (Kazuya) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01 Ran by Kazuya (administrator) on KOICHI on 06-04-2014 14:30:20 Running from C:\Users\Kazuya\Downloads\Schritt für Schritt Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\windows\system32\WLANExt.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Seiko Epson Corporation) C:\windows\system32\EscSvc.exe (IObit) C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIJAE.EXE (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Microsoft Corporation) C:\windows\system32\wuauclt.exe (Intel Corporation) C:\windows\system32\igfxsrvc.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [FUFAXRCV] - C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe [502952 2012-07-09] (SEIKO EPSON CORPORATION) HKLM\...\Run: [FUFAXSTM] - C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [863400 2012-07-09] (SEIKO EPSON CORPORATION) HKLM\...\Run: [EEventManager] - C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1058912 2012-04-02] (SEIKO EPSON CORPORATION) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-05] (AVAST Software) HKU\.DEFAULT\...\RunOnce: [WLStart] - C:\Program Files\Windows Live\Installer\wlstart.exe [786760 2009-07-26] (Microsoft Corporation) HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\Run: [EPLTarget\P0000000000000000] - C:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIJAE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {10f43e9d-bb56-11df-a143-806e6f6e6963} - F:\setup_vmc_lite.exe /checkApplicationPresence HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {1b8f9919-b087-11e0-bbb2-705ab658f2fe} - F:\setup_vmc_lite.exe /checkApplicationPresence HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {1b8f9923-b087-11e0-bbb2-705ab658f2fe} - F:\setup_vmc_lite.exe /checkApplicationPresence HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {2f3f4fe1-a70b-11e0-a1f6-705ab658f2fe} - F:\Install.exe HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\MountPoints2: {61a25b02-bb94-11df-b98d-705ab658f2fe} - F:\setup_vmc_lite.exe /checkApplicationPresence IFEO\bitguard.exe: [Debugger] tasklist.exe IFEO\bprotect.exe: [Debugger] tasklist.exe IFEO\browserdefender.exe: [Debugger] tasklist.exe IFEO\browserprotect.exe: [Debugger] tasklist.exe ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ URLSearchHook: HKCU - (No Name) - {8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - No File SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search BHO: ExplorerWnd Helper - {10921475-03CE-4E04-90CE-E2E7EF20C814} - C:\Program Files\IObit\IObit Uninstaller\UninstallExplorer32.dll No File BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File Toolbar: HKCU - No Name - {8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} - No File Toolbar: HKCU - No Name - {30F9B915-B755-4826-820B-08FBA6BD249D} - No File Toolbar: HKCU - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Kazuya\AppData\Roaming\Mozilla\Firefox\Profiles\miuov82a.default-1388595698206 FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-05] ========================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-05] (AVAST Software) R2 EpsonScanSvc; C:\windows\system32\EscSvc.exe [122000 2011-12-12] (Seiko Epson Corporation) R2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2151744 2013-12-31] (IObit) S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-07-04] (Vodafone) S4 AntiVirWebService; "C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe" [X] ==================== Drivers (Whitelisted) ==================== R3 ACPIVPC; C:\windows\System32\DRIVERS\AcpiVpc.sys [21520 2009-05-19] (Lenovo Corporation) R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [67824 2014-04-05] (AVAST Software) R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [81768 2014-04-05] (AVAST Software) R0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49944 2014-04-05] () R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [776976 2014-04-05] (AVAST Software) R1 aswSP; C:\windows\system32\drivers\aswSP.sys [411552 2014-04-05] (AVAST Software) R3 aswStm; C:\windows\system32\drivers\aswStm.sys [67264 2014-04-05] (AVAST Software) R0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [180760 2014-04-05] () R1 funfrm; C:\windows\system32\Drivers\funfrm.sys [54800 2010-02-09] () S3 wdmirror; C:\windows\System32\DRIVERS\WDMirror.sys [11792 2009-07-16] (Windows (R) Codename Longhorn DDK provider) S3 wsvd; C:\windows\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink) S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X] S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X] S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X] S3 WinRing0_1_2_0; \??\D:\test\ECECECEC\WinRing0.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-06 14:28 - 2014-04-06 14:30 - 00000000 ____D () C:\FRST 2014-04-06 14:20 - 2014-04-06 14:21 - 00000474 _____ () C:\Users\Kazuya\Desktop\defogger_disable.log 2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable 2014-04-06 14:17 - 2014-04-06 14:30 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt 2014-04-06 14:16 - 2014-04-06 14:16 - 00050477 _____ () C:\Users\Kazuya\Desktop\Defogger.exe 2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia 2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-04-05 22:10 - 2014-04-06 13:57 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-04-05 21:58 - 2014-04-05 21:58 - 00002123 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software 2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe 2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software 2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys 2014-04-05 21:50 - 2014-04-05 21:54 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys 2014-04-05 21:37 - 2014-04-05 21:38 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe 2014-03-31 08:50 - 2014-03-31 08:53 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik Konzeptverkäufer HRO 4 2014.ods 2014-03-25 20:14 - 2014-03-25 20:15 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe 2014-03-16 19:32 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-03-16 19:32 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-03-16 19:32 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-03-16 19:32 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-03-16 19:32 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-03-16 19:32 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-03-16 19:32 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-03-16 19:32 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-03-16 19:32 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-03-16 19:32 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-03-16 19:32 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-03-16 19:32 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-03-16 19:32 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-03-16 19:32 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-03-16 19:32 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-03-16 19:32 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-03-16 19:32 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-03-16 19:32 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-03-16 19:32 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-03-16 19:32 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-03-16 19:32 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-03-16 19:32 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-03-16 19:26 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2014-03-16 19:26 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll 2014-03-16 19:26 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2014-03-16 19:26 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll 2014-03-16 19:26 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll 2014-03-11 13:59 - 2014-03-21 23:56 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx 2014-03-11 13:57 - 2014-03-25 20:23 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff 2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx ==================== One Month Modified Files and Folders ======= 2014-04-06 14:30 - 2014-04-06 14:28 - 00000000 ____D () C:\FRST 2014-04-06 14:30 - 2014-04-06 14:17 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt 2014-04-06 14:28 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-06 14:28 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-06 14:21 - 2014-04-06 14:20 - 00000474 _____ () C:\Users\Kazuya\Desktop\defogger_disable.log 2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable 2014-04-06 14:20 - 2010-09-08 16:02 - 00000000 ____D () C:\Users\Kazuya 2014-04-06 14:16 - 2014-04-06 14:16 - 00050477 _____ () C:\Users\Kazuya\Desktop\Defogger.exe 2014-04-06 14:15 - 2010-02-09 10:45 - 01912579 _____ () C:\windows\WindowsUpdate.log 2014-04-06 14:09 - 2013-09-24 19:27 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-04-06 14:09 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-04-06 14:09 - 2009-07-14 06:39 - 00113231 _____ () C:\windows\setupact.log 2014-04-06 13:57 - 2014-04-05 22:10 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-04-06 13:56 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\tracing 2014-04-06 00:41 - 2010-01-18 19:03 - 01765534 _____ () C:\windows\system32\PerfStringBackup.INI 2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia 2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-04-05 22:16 - 2013-09-24 18:58 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe 2014-04-05 22:16 - 2013-04-07 17:59 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl 2014-04-05 21:58 - 2014-04-05 21:58 - 00002123 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software 2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe 2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software 2014-04-05 21:54 - 2014-04-05 21:50 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys 2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys 2014-04-05 21:49 - 2010-01-18 19:12 - 00631348 _____ () C:\windows\PFRO.log 2014-04-05 21:48 - 2013-09-28 21:38 - 00000000 ____D () C:\ProgramData\Avira 2014-04-05 21:38 - 2014-04-05 21:37 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe 2014-04-05 21:29 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\FxsTmp 2014-04-05 20:27 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\wfp 2014-04-05 20:26 - 2011-01-28 17:09 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\vlc 2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\NDF 2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\AppCompat 2014-04-05 20:25 - 2010-01-18 18:57 - 00000000 __RHD () C:\MSOCache 2014-04-05 20:25 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\registration 2014-04-01 01:53 - 2009-07-29 12:50 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-03-31 08:53 - 2014-03-31 08:50 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik Konzeptverkäufer HRO 4 2014.ods 2014-03-26 21:26 - 2013-12-31 19:52 - 00000000 ____D () C:\ProgramData\ProductData 2014-03-25 20:23 - 2014-03-11 13:57 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff 2014-03-25 20:19 - 2010-01-18 19:13 - 00000000 ____D () C:\ProgramData\Adobe 2014-03-25 20:18 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\Adobe 2014-03-25 20:17 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Adobe 2014-03-25 20:15 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe 2014-03-21 23:56 - 2014-03-11 13:59 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx 2014-03-16 19:41 - 2009-07-14 06:33 - 00414320 _____ () C:\windows\system32\FNTCACHE.DAT 2014-03-16 19:36 - 2013-09-30 15:36 - 00000000 ____D () C:\windows\system32\MRT 2014-03-16 19:33 - 2013-09-30 15:36 - 87350280 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-03-11 13:59 - 2010-09-13 21:36 - 00000000 ____D () C:\Users\Public\Documents\texte 2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx Some content of TEMP: ==================== C:\Users\Kazuya\AppData\Local\Temp\0kzpwa6k.dll C:\Users\Kazuya\AppData\Local\Temp\2f5dddvp.dll C:\Users\Kazuya\AppData\Local\Temp\33972uninstall.exe C:\Users\Kazuya\AppData\Local\Temp\3im0mncd.dll C:\Users\Kazuya\AppData\Local\Temp\4vtwgrfo.dll C:\Users\Kazuya\AppData\Local\Temp\6vuldinv.dll C:\Users\Kazuya\AppData\Local\Temp\7xcn6fpl.dll C:\Users\Kazuya\AppData\Local\Temp\7z916.exe C:\Users\Kazuya\AppData\Local\Temp\8ceuvc6z.dll C:\Users\Kazuya\AppData\Local\Temp\agtp5wny.dll C:\Users\Kazuya\AppData\Local\Temp\app.exe C:\Users\Kazuya\AppData\Local\Temp\avgnt.exe C:\Users\Kazuya\AppData\Local\Temp\BackupSetup.exe C:\Users\Kazuya\AppData\Local\Temp\BundleSweetIMSetup.exe C:\Users\Kazuya\AppData\Local\Temp\cbyaagar.dll C:\Users\Kazuya\AppData\Local\Temp\DeleteEcUninstall.exe C:\Users\Kazuya\AppData\Local\Temp\donw3fx6.dll C:\Users\Kazuya\AppData\Local\Temp\drm_dyndata_7400005.dll C:\Users\Kazuya\AppData\Local\Temp\eq1x7zjn.dll C:\Users\Kazuya\AppData\Local\Temp\FP_PL_PFS_INSTALLER.exe C:\Users\Kazuya\AppData\Local\Temp\g3-rymre.dll C:\Users\Kazuya\AppData\Local\Temp\GLF848F.tmp.ConduitEngineSetup.exe C:\Users\Kazuya\AppData\Local\Temp\i399ol3f.dll C:\Users\Kazuya\AppData\Local\Temp\ilsqm4bc.dll C:\Users\Kazuya\AppData\Local\Temp\l6wk4tg7.dll C:\Users\Kazuya\AppData\Local\Temp\lrun8vok.dll C:\Users\Kazuya\AppData\Local\Temp\mg02ea0h.dll C:\Users\Kazuya\AppData\Local\Temp\MybabylonTB.exe C:\Users\Kazuya\AppData\Local\Temp\ncq7qzzc.dll C:\Users\Kazuya\AppData\Local\Temp\ndtdsia_.dll C:\Users\Kazuya\AppData\Local\Temp\nf_lag8i.dll C:\Users\Kazuya\AppData\Local\Temp\p9jdhxwr.dll C:\Users\Kazuya\AppData\Local\Temp\promote-upx.exe C:\Users\Kazuya\AppData\Local\Temp\propsys.dll C:\Users\Kazuya\AppData\Local\Temp\pzcx1s-o.dll C:\Users\Kazuya\AppData\Local\Temp\SIntf16.dll C:\Users\Kazuya\AppData\Local\Temp\SIntf32.dll C:\Users\Kazuya\AppData\Local\Temp\SIntfNT.dll C:\Users\Kazuya\AppData\Local\Temp\Softonic_Deutsch.exe C:\Users\Kazuya\AppData\Local\Temp\Sqlite3.dll C:\Users\Kazuya\AppData\Local\Temp\tbSoft.dll C:\Users\Kazuya\AppData\Local\Temp\tbu15B1.exe C:\Users\Kazuya\AppData\Local\Temp\tbu17B5.exe C:\Users\Kazuya\AppData\Local\Temp\tbuF4BA.exe C:\Users\Kazuya\AppData\Local\Temp\uchhlufn.dll C:\Users\Kazuya\AppData\Local\Temp\uninst1.exe C:\Users\Kazuya\AppData\Local\Temp\uninstall.exe C:\Users\Kazuya\AppData\Local\Temp\vbxb5orq.dll C:\Users\Kazuya\AppData\Local\Temp\vcredist_x86.exe C:\Users\Kazuya\AppData\Local\Temp\w8dqhfu5.dll C:\Users\Kazuya\AppData\Local\Temp\wm4bjeyn.dll C:\Users\Kazuya\AppData\Local\Temp\wtr2y8ud.dll C:\Users\Kazuya\AppData\Local\Temp\yfejxr3f.dll C:\Users\Kazuya\AppData\Local\Temp\yg6mvt_-.dll C:\Users\Kazuya\AppData\Local\Temp\yurmxiym.dll C:\Users\Kazuya\AppData\Local\Temp\_isC2A3.exe C:\Users\Kazuya\AppData\Local\Temp\_isE780.exe ==================== Bamital & volsnap Check ================= C:\windows\explorer.exe => MD5 is legit C:\windows\system32\winlogon.exe => MD5 is legit C:\windows\system32\wininit.exe => MD5 is legit C:\windows\system32\svchost.exe => MD5 is legit C:\windows\system32\services.exe => MD5 is legit C:\windows\system32\User32.dll => MD5 is legit C:\windows\system32\userinit.exe => MD5 is legit C:\windows\system32\rpcss.dll => MD5 is legit C:\windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-31 03:14 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 13-03-2014 01 Ran by Kazuya at 2014-04-06 14:31:13 Running from C:\Users\Kazuya\Downloads\Schritt für Schritt Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== Activation Assistant for the 2007 Microsoft Office suites (HKLM\...\Activation Assistant for the 2007 Microsoft Office suites) (Version: - Microsoft Corporation) Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden Adobe Flash Player 12 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: 12.0.0.77 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) avast! Free Antivirus (HKLM\...\Avast) (Version: 9.0.2016 - Avast Software) Broadcom 802.11 Wireless Driver (HKLM\...\{8991E763-21F5-4DEA-A938-5D9D77DCB488}) (Version: 1.0.0.0 - ) Business Contact Manager für Outlook 2007 SP2 (HKLM\...\Business Contact Manager) (Version: 3.0.8619.1 - Microsoft Corporation) Business Contact Manager für Outlook 2007 SP2 (Version: 3.0.8619.1 - Microsoft Corporation) Hidden Conexant HD Audio (HKLM\...\CNXT_AUDIO_HDA) (Version: 4.98.4.0 - Conexant) Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{81FB7C60-565A-4869-9D90-3BE1D270E8B7}) (Version: - Microsoft) Energy Management (HKLM\...\{AE1E24C2-E720-42D5-B8E1-48F71A97B4DB}) (Version: 4.3.1.5 - Lenovo) Epson Benutzerhandbuch XP-800 Series (HKLM\...\XP-800 Series Useg) (Version: - ) Epson Connect Guide (HKLM\...\Epson Connect Guide) (Version: - ) Epson Event Manager (HKLM\...\{8F01524C-0676-4CC1-B4AE-64753C723391}) (Version: 3.01.0005 - Seiko Epson Corporation) Epson FAX Utility (HKLM\...\{0CBE6C93-CB2E-4378-91EE-12BE6D4E2E4A}) (Version: 1.31.00 - SEIKO EPSON CORPORATION) Epson Netzwerkhandbuch XP-800 Series (HKLM\...\XP-800 Series Netg) (Version: - ) Epson PC-FAX Driver (HKLM\...\EPSON PC-FAX Driver 2) (Version: - ) EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EPSON XP-800 Series Printer Uninstall (HKLM\...\EPSON XP-800 Series) (Version: - SEIKO EPSON Corporation) EpsonNet Print (HKLM\...\{3E31400D-274E-4647-916C-2CACC3741799}) (Version: 2.5.00 - SEIKO EPSON CORPORATION) Intel(R) Graphics Media Accelerator Driver (HKLM\...\HDMI) (Version: - Intel Corporation) Intel(R) TV Wizard (HKLM\...\TVWiz) (Version: - Intel Corporation) Intel® Matrix Storage Manager (HKLM\...\{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}) (Version: - Intel Corporation) Junk Mail filter update (Version: 14.0.8089.726 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden Microsoft Choice Guard (Version: 2.0.48.0 - Microsoft Corporation) Hidden Microsoft Office 2003 Web Components (HKLM\...\{90A40407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8003.0 - Microsoft Corporation) Microsoft Office 2007 Primary Interop Assemblies (HKLM\...\{50120000-1105-0000-0000-0000000FF1CE}) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Home and Student 2010 (HKLM\...\Office14.SingleImage) (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Small Business Connectivity Components (HKLM\...\{A939D341-5A04-4E0A-BB55-3E65B386432D}) (Version: 2.0.7024.0 - Microsoft Corporation) Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft SQL Server 2005 (HKLM\...\Microsoft SQL Server 2005) (Version: - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft SQL Server 2005 Express Edition (MSSMLBIZ) (Version: 9.4.5000.00 - Microsoft Corporation) Hidden Microsoft SQL Server Native Client (HKLM\...\{7670D32F-DAE6-4E49-8C8B-B3F08B5B1686}) (Version: 9.00.5000.00 - Microsoft Corporation) Microsoft SQL Server Setup Support Files (English) (HKLM\...\{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}) (Version: 9.00.5000.00 - Microsoft Corporation) Microsoft SQL Server VSS Writer (HKLM\...\{E7084B89-69E0-46B3-A118-8F99D06988CD}) (Version: 9.00.5000.00 - Microsoft Corporation) Microsoft Sync Framework Runtime Native v1.0 (x86) (HKLM\...\{8A74E887-8F0F-4017-AF53-CBA42211AAA5}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Sync Framework Services Native v1.0 (x86) (HKLM\...\{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}) (Version: 1.0.1215.0 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 28.0 (x86 de) (HKLM\...\Mozilla Firefox 28.0 (x86 de)) (Version: 28.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 28.0 - Mozilla) MSVCRT (Version: 14.0.1468.721 - Microsoft) Hidden Power2Go (HKLM\...\{40BF1E83-20EB-11D8-97C5-0009C5020658}) (Version: 5.6.0.4809d4 - CyberLink Corp.) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DE28B448-32E8-4E8F-84F0-A52B21A49B5B}) (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 32-Bit Edition (Version: - Microsoft) Hidden Update for Microsoft Access 2010 (KB2553446) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{B4A38370-2ADB-46B0-A1B0-0C4A2F7DCA31}) (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2810071) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{001E8BF3-EDC3-4D5E-9C11-1D0E599B6497}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2494150) (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3FCFD88F-4D13-4F38-8625-ABABEA7F61EA}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{DADF7E25-FFA4-4D02-BE84-1DAE62C18516}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{F4284D93-7AE8-4309-8CF3-9AD394F35F3A}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{287A1E92-9E41-4BC1-8920-B3D0E9220800}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{9D69691D-823D-4C3E-9B12-563A3F520366}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{ECFE33A3-B8B7-439A-ADE4-59FBD29EF9B8}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{35698CB7-AAA2-4577-B505-DBFF504AEF23}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{5AA578BB-759C-40FD-9661-A737C0884541}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2826026) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{D7D96A96-F61F-48AD-B2DC-4F4B6938D2AB}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{C70D2038-A2C4-4A99-87DE-5272BB44F0CE}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{B5C70C99-B109-42FD-B219-FF12CA543F19}) (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 32-Bit Edition (HKLM\...\{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{82F87E28-B18E-46D6-A399-E2F19CF5949B}) (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2810072) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{3EFF1957-7DEA-4C7A-8E9C-2D6D58E4B2ED}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM\...\{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{81812245-FC84-426A-BC02-6659C88CC7B2}) (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{190EC86F-5867-4D7A-B9F3-D14D82C26F3D}) (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{8C55AA83-54C2-4236-A622-78440A411DC5}) (Version: - Microsoft) Update for Microsoft Word 2010 (KB2837593) 32-Bit Edition (HKLM\...\{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{E78E2B68-8FD1-42EE-BB74-99A4D9E6222D}) (Version: - Microsoft) VLC media player 2.1.3 (HKLM\...\VLC media player) (Version: 2.1.3 - VideoLAN) Vodafone Mobile Connect Lite (HKLM\...\{C656142F-EFE1-44CD-BFAD-6CBC6DCB9860}) (Version: 9.3.3.10523 - Vodafone) Windows Live Call (Version: 14.0.8064.0206 - Microsoft Corporation) Hidden Windows Live Communications Platform (Version: 14.0.8064.206 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM\...\WinLiveSuite_Wave3) (Version: 14.0.8089.0726 - Microsoft Corporation) Windows Live Essentials (Version: 14.0.8089.726 - Microsoft Corporation) Hidden Windows Live Fotogalerie (Version: 14.0.8081.709 - Microsoft Corporation) Hidden Windows Live Mail (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live Messenger (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live Movie Maker (Version: 14.0.8091.0730 - Microsoft Corporation) Hidden Windows Live Sync (HKLM\...\{76618402-179D-4699-A66B-D351C59436BC}) (Version: 14.0.8089.726 - Microsoft Corporation) Windows Live Writer (Version: 14.0.8089.0726 - Microsoft Corporation) Hidden Windows Live-Uploadtool (HKLM\...\{205C6BDD-7B73-42DE-8505-9A093F35A238}) (Version: 14.0.8014.1029 - Microsoft Corporation) WinRAR 5.01 (32-bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) ==================== Restore Points ========================= 16-03-2014 17:32:50 Windows Update 21-03-2014 21:40:57 Windows Update 30-03-2014 19:20:30 Windows Update 31-03-2014 23:50:43 Wiederherstellungsvorgang 03-04-2014 17:52:58 Windows Update 05-04-2014 18:11:15 Wiederherstellungsvorgang 05-04-2014 19:56:02 avast! antivirus system restore point ==================== Hosts content: ========================== 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {2F88FC51-99EC-417F-A32F-C4FEE72D7DF6} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-04-05] (AVAST Software) Task: {5134E82E-2A0D-4C9F-9736-29215B99C6C9} - System32\Tasks\{70EC7443-1025-4672-BBD2-4F8A7C694DCE} => C:\Program Files\Ablaze\ablaze_v106.exe Task: {5A517D2E-F200-4FF2-A957-EEB67D57964D} - System32\Tasks\Adobe Flash Player Updater => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-04-05] (Adobe Systems Incorporated) Task: {93A6E725-6732-4B51-9BF7-89AD55373E9C} - System32\Tasks\{2D5CFE77-0C81-42B1-B938-1A843BEF1831} => C:\Program Files\Ablaze\ablaze_v106.exe Task: {A2B5D60B-552E-4F64-B5B1-4C15B48D83FF} - System32\Tasks\{089487B7-4BEA-4417-B583-30CDBA1402C3} => C:\Program Files\Ablaze\ablaze_v106.exe Task: {B2A1CFFD-E741-47CE-92FC-EC8B3332D205} - System32\Tasks\{C7C8E65B-5D02-4ABA-95EB-BA64C2D24D5E} => C:\Program Files\Ablaze\ablaze_v106.exe Task: {BB2F5FE5-7D8B-4571-9178-D91B49A53A0D} - System32\Tasks\{8EF0B629-6E06-40A5-8B8D-1B74D49EBD5C} => C:\Program Files\Ablaze\ablaze_v106.exe Task: {C76794B6-1B4F-4332-8489-3C42ED98A25C} - System32\Tasks\{BB7A5E64-78D6-4D3C-9F15-1899A5E8C355} => C:\Program Files\Ablaze\ablaze_v106.exe Task: {C8DD6C9E-6149-40EF-B2A1-018EA0C02921} - System32\Tasks\Microsoft\Windows\WindowsBackup\AutomaticBackup => Rundll32.exe /d sdengin2.dll,ExecuteScheduledBackup Task: {E3C06A89-3FF8-421A-A1E3-27030FBD2837} - System32\Tasks\{C056EB45-A940-48FF-A65A-1D3D68FDFFD4} => C:\Program Files\Ablaze\ablaze_v106.exe Task: {FD9171C0-7AAF-443F-83CF-28E5E2562BE3} - System32\Tasks\{0619CB49-03E9-470F-A041-410D67E10D97} => C:\Program Files\Ablaze\ablaze_v106.exe Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2014-04-06 13:56 - 2014-04-06 13:56 - 02189824 _____ () C:\Program Files\AVAST Software\Avast\defs\14040600\algo.dll 2014-04-05 21:57 - 2014-04-05 21:57 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2014-04-05 22:39 - 2014-04-05 22:39 - 03642480 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcmscsvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MCODS => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: avgnt => "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min MSCONFIG\startupreg: Energy Management => C:\Program Files\Lenovo\Energy Management\Energy Management.exe MSCONFIG\startupreg: EnergyUtility => C:\Program Files\Lenovo\Energy Management\utility.exe MSCONFIG\startupreg: HotKeysCmds => C:\windows\system32\hkcmd.exe MSCONFIG\startupreg: IAAnotif => C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe MSCONFIG\startupreg: IgfxTray => C:\windows\system32\igfxtray.exe MSCONFIG\startupreg: MobileConnect => %programfiles%\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe /silent MSCONFIG\startupreg: mobilegeni daemon => C:\Program Files\Mobogenie\DaemonProcess.exe MSCONFIG\startupreg: Persistence => C:\windows\system32\igfxpers.exe MSCONFIG\startupreg: SmartAudio => C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t MSCONFIG\startupreg: UpdateP2GShortCut => "C:\Program Files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files\Lenovo\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\5.0" ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/06/2014 02:10:12 PM) (Source: VMCService) (User: ) Description: conflictManagerTypeValue Error: (04/06/2014 01:54:47 PM) (Source: VMCService) (User: ) Description: conflictManagerTypeValue Error: (04/06/2014 00:37:14 AM) (Source: VMCService) (User: ) Description: conflictManagerTypeValue Error: (04/05/2014 09:56:12 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer". Details: AddLegacyDriverFiles: Unable to back up image of binary xpvzlpga. System Error: Das System kann die angegebene Datei nicht finden. . Error: (04/05/2014 09:56:01 PM) (Source: VSS) (User: ) Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert . Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess. Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {777785d9-4bbc-4c2b-8619-a7e65b0de15b} Error: (04/05/2014 09:52:54 PM) (Source: VMCService) (User: ) Description: conflictManagerTypeValue Error: (04/05/2014 08:27:25 PM) (Source: Avira Antivirus) (User: NT-AUTORITÄT) Description: 0x0 Error: (04/05/2014 08:15:51 PM) (Source: VMCService) (User: ) Description: conflictManagerTypeValue Error: (04/05/2014 08:07:44 PM) (Source: VMCService) (User: ) Description: conflictManagerTypeValue Error: (04/05/2014 07:44:03 PM) (Source: VMCService) (User: ) Description: conflictManagerTypeValue System errors: ============= Error: (04/05/2014 09:51:22 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (04/05/2014 09:51:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (04/05/2014 09:50:12 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (04/05/2014 09:50:10 PM) (Source: DCOM) (User: ) Description: 1084WSearch{9E175B6D-F52A-11D8-B9A5-505054503030} Error: (04/05/2014 09:50:10 PM) (Source: DCOM) (User: ) Description: 1084WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Microsoft Office Sessions: ========================= Error: (04/06/2014 02:10:12 PM) (Source: VMCService)(User: ) Description: conflictManagerTypeValue Error: (04/06/2014 01:54:47 PM) (Source: VMCService)(User: ) Description: conflictManagerTypeValue Error: (04/06/2014 00:37:14 AM) (Source: VMCService)(User: ) Description: conflictManagerTypeValue Error: (04/05/2014 09:56:12 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: Details: AddLegacyDriverFiles: Unable to back up image of binary xpvzlpga. System Error: Das System kann die angegebene Datei nicht finden. Error: (04/05/2014 09:56:01 PM) (Source: VSS)(User: ) Description: 0x80070005, Zugriff verweigert Vorgang: Generatordaten werden gesammelt Kontext: Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220} Generatorname: System Writer Generatorinstanz-ID: {777785d9-4bbc-4c2b-8619-a7e65b0de15b} Error: (04/05/2014 09:52:54 PM) (Source: VMCService)(User: ) Description: conflictManagerTypeValue Error: (04/05/2014 08:27:25 PM) (Source: Avira Antivirus)(User: NT-AUTORITÄT) Description: 0x0 Error: (04/05/2014 08:15:51 PM) (Source: VMCService)(User: ) Description: conflictManagerTypeValue Error: (04/05/2014 08:07:44 PM) (Source: VMCService)(User: ) Description: conflictManagerTypeValue Error: (04/05/2014 07:44:03 PM) (Source: VMCService)(User: ) Description: conflictManagerTypeValue ==================== Memory info =========================== Percentage of memory in use: 77% Total physical RAM: 984.6 MB Available physical RAM: 216.92 MB Total Pagefile: 2008.6 MB Available Pagefile: 931.06 MB Total Virtual: 2047.88 MB Available Virtual: 1903.04 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:187.69 GB) (Free:156.28 GB) NTFS Drive d: (Lenovo) (Fixed) (Total:30.25 GB) (Free:28.5 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 233 GB) (Disk ID: BEC90B8D) Partition: GPT Partition Type. ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-04-06 15:40:57 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD25 rev.01.0 232,89GB Running: k23zf1j3.exe; Driver: C:\Users\Kazuya\AppData\Local\Temp\fxldqpog.sys ---- System - GMER 2.1 ---- SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAddBootEntry [0x8D24FA9C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x8D25057A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEvent [0x8D25C5C4] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateEventPair [0x8D25C610] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x8D25C7AA] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateMutant [0x8D25C532] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwCreateSection [0x8D3066C2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x8D25C57A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThread [0x8D250AB0] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateThreadEx [0x8D250CCC] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwCreateTimer [0x8D25C764] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x8D251368] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x8D24FB02] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwDuplicateObject [0x8D254B3C] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwLoadDriver [0x8D24F6EE] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwMapViewOfSection [0x8D3067A2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x8D24FB68] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x8D254F32] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x8D251E50] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEvent [0x8D25C5EE] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenEventPair [0x8D25C632] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x8D25C7CE] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenMutant [0x8D25C558] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenProcess [0x8D254436] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSection [0x8D25C6E2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x8D25C5A2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenThread [0x8D25481E] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwOpenTimer [0x8D25C788] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x8D306546] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueryObject [0x8D251CC4] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwQueueApcThreadEx [0x8D2519D2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x8D24FBCE] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetBootOptions [0x8D24FC34] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwSetContextThread [0x8D30689E] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x8D24F788] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x8D24F95A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwShutdownSystem [0x8D24F8E8] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendProcess [0x8D251532] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSuspendThread [0x8D251694] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x8D24F9E2] SSDT \SystemRoot\system32\drivers\aswSP.sys ZwTerminateProcess [0x8D306614] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwTerminateThread [0x8D2511C2] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwVdmControl [0x8D24FC9A] SSDT \SystemRoot\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0x8D2505D6] ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 82E8AA15 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82EC4212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntkrnlpa.exe!KeRemoveQueueEx + 10CB 82ECB460 4 Bytes [9C, FA, 24, 8D] {PUSHF ; CLI ; AND AL, 0x8d} .text ntkrnlpa.exe!KeRemoveQueueEx + 1153 82ECB4E8 4 Bytes [7A, 05, 25, 8D] .text ntkrnlpa.exe!KeRemoveQueueEx + 11A7 82ECB53C 8 Bytes [C4, C5, 25, 8D, 10, C6, 25, ...] .text ntkrnlpa.exe!KeRemoveQueueEx + 11B3 82ECB548 4 Bytes [AA, C7, 25, 8D] .text ntkrnlpa.exe!KeRemoveQueueEx + 11CF 82ECB564 4 Bytes [32, C5, 25, 8D] .text ... ---- User code sections - GMER 2.1 ---- .text C:\windows\system32\EscSvc.exe[348] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe[388] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text C:\windows\system32\csrss.exe[444] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text C:\windows\system32\wininit.exe[496] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text C:\windows\system32\csrss.exe[504] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text ... .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1392] kernel32.dll!SetUnhandledExceptionFilter 7601F4EB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text C:\Program Files\AVAST Software\Avast\AvastSvc.exe[1392] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text C:\windows\system32\svchost.exe[1512] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text C:\windows\system32\Dwm.exe[1528] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text C:\windows\Explorer.EXE[1540] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text C:\windows\System32\svchost.exe[1604] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text ... .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3108] kernel32.dll!SetUnhandledExceptionFilter 7601F4EB 8 Bytes [31, C0, C2, 04, 00, 90, 90, ...] {XOR EAX, EAX; RET 0x4; NOP ; NOP ; NOP } .text C:\Program Files\AVAST Software\Avast\AvastUI.exe[3108] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text C:\Program Files\Windows Sidebar\sidebar.exe[3124] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text C:\Windows\System32\spool\drivers\w32x86\3\E_FATIJAE.EXE[3144] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text C:\windows\system32\wuauclt.exe[3172] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text C:\windows\system32\wbem\wmiprvse.exe[3624] kernel32.dll!GetBinaryTypeW + 70 760369E4 1 Byte [62] .text ... ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\002269ec2d88 Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\002269ec2d88 (not active ControlSet) ---- EOF - GMER 2.1 ---- |
07.04.2014, 13:56 | #4 |
/// the machine /// TB-Ausbilder | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet hi, Scan mit Combofix
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.04.2014, 15:43 | #5 |
| Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Huhu schrauber, habe deine Anweisung ausgeführt. Wie geht es weiter? Liebe Grüße Kazuya Code:
ATTFilter ComboFix 14-04-06.01 - Kazuya 07.04.2014 15:48:37.1.2 - x86 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.985.279 [GMT 2:00] ausgeführt von:: c:\users\Kazuya\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Kazuya\AppData\Local\Microsoft\Windows\Temporary Internet Files\{4020D4E9-53CC-435F-B76C-F251D0F09E3F}.xps c:\windows\IsUn0407.exe c:\windows\security\Database\tmp.edb c:\program files\AVAST Software\Avast\setup\83a86efa-df02-4a95-90cc-24cf6e129713.exe . . . . Nicht in der Lage zu löschen . . ((((((((((((((((((((((( Dateien erstellt von 2014-03-07 bis 2014-04-07 )))))))))))))))))))))))))))))) . . 2014-04-06 13:58 . 2014-04-07 13:54 62576 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A28D44C7-5522-4043-B3F8-24309FDB5020}\offreg.dll 2014-04-06 12:28 . 2014-04-06 12:32 -------- d-----w- C:\FRST 2014-04-05 20:42 . 2014-04-05 20:42 -------- d-----w- c:\users\Kazuya\AppData\Local\Macromedia 2014-04-05 19:58 . 2014-04-05 19:58 -------- d-----w- c:\users\Kazuya\AppData\Roaming\AVAST Software 2014-04-05 19:57 . 2014-04-05 19:57 776976 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2014-04-05 19:57 . 2014-04-05 19:57 67264 ----a-w- c:\windows\system32\drivers\aswStm.sys 2014-04-05 19:57 . 2014-04-05 19:57 49944 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2014-04-05 19:57 . 2014-04-05 19:57 411552 ----a-w- c:\windows\system32\drivers\aswSP.sys 2014-04-05 19:57 . 2014-04-05 19:57 180760 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2014-04-05 19:57 . 2014-04-05 19:57 67824 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2014-04-05 19:57 . 2014-04-05 19:57 81768 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2014-04-05 19:57 . 2014-04-05 19:57 271264 ----a-w- c:\windows\system32\aswBoot.exe 2014-04-05 19:57 . 2014-04-05 19:57 43152 ----a-w- c:\windows\avastSS.scr 2014-04-05 19:56 . 2014-04-05 19:56 -------- d-----w- c:\program files\AVAST Software 2014-04-05 19:51 . 2014-04-05 19:51 411552 ----a-w- c:\windows\system32\drivers\rtgdysgh.sys 2014-04-05 19:50 . 2014-04-05 19:50 411552 ----a-w- c:\windows\system32\drivers\ptzlzhni.sys 2014-04-05 19:50 . 2014-04-05 19:54 -------- d-----w- c:\programdata\AVAST Software 2014-04-05 18:28 . 2014-02-06 07:08 7947048 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A28D44C7-5522-4043-B3F8-24309FDB5020}\mpengine.dll 2014-03-25 18:14 . 2014-03-25 18:15 -------- d-----w- c:\program files\Common Files\Adobe 2014-03-16 17:26 . 2014-02-07 01:07 2349056 ----a-w- c:\windows\system32\win32k.sys 2014-03-16 17:26 . 2014-01-29 02:06 381440 ----a-w- c:\windows\system32\wer.dll 2014-03-16 17:26 . 2014-02-04 02:04 1230336 ----a-w- c:\windows\system32\WindowsCodecs.dll 2014-03-16 17:26 . 2014-02-04 02:04 509440 ----a-w- c:\windows\system32\qedit.dll 2014-03-16 17:26 . 2014-01-28 02:07 185344 ----a-w- c:\windows\system32\wwansvc.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-04-05 20:16 . 2013-09-24 16:58 692616 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2014-04-05 20:16 . 2013-04-07 15:59 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2014-04-05 19:57 260976 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-20 1174016] "EPLTarget\P0000000000000000"="c:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIJAE.EXE" [2012-02-28 249440] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "FUFAXRCV"="c:\program files\Epson Software\FAX Utility\FUFAXRCV.exe" [2012-07-09 502952] "FUFAXSTM"="c:\program files\Epson Software\FAX Utility\FUFAXSTM.exe" [2012-07-09 863400] "EEventManager"="c:\program files\Epson Software\Event Manager\EEventManager.exe" [2012-04-02 1058912] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-12-21 959904] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-04-05 3854640] . [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce] "WLStart"="c:\program files\Windows Live\Installer\wlstart.exe" [2009-07-26 786760] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Energy Management] 2009-09-29 16:22 5064560 ----a-w- c:\program files\Lenovo\Energy Management\Energy Management.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\EnergyUtility] 2009-09-29 16:23 4114288 ----a-w- c:\program files\Lenovo\Energy Management\utility.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HotKeysCmds] 2009-09-18 05:35 174104 ----a-w- c:\windows\System32\hkcmd.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IAAnotif] 2009-06-04 19:03 186904 ----a-w- c:\program files\Intel\Intel Matrix Storage Manager\IAAnotif.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IgfxTray] 2009-09-18 05:35 141848 ----a-w- c:\windows\System32\igfxtray.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MobileConnect] 2008-07-04 10:52 2072576 ----a-w- c:\program files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Persistence] 2009-09-18 05:35 150552 ----a-w- c:\windows\System32\igfxpers.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SmartAudio] 2009-07-16 05:38 307768 ------w- c:\program files\CONEXANT\SAII\SAIICpl.exe . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\UpdateP2GShortCut] 2008-12-03 22:15 218408 ------w- c:\program files\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe . R3 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys [2014-04-05 67264] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe [2014-03-01 108032] R3 k57nd60x;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60x.sys [2009-07-13 229888] R3 netw5v32;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 32 Bit;c:\windows\system32\DRIVERS\netw5v32.sys [2009-07-13 4231168] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848] R3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [x] R3 RtsUIR;Realtek IR Driver;c:\windows\system32\DRIVERS\Rts516xIR.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664] R3 wdmirror;wdmirror;c:\windows\system32\DRIVERS\WDMirror.sys [2009-07-16 11792] R3 WinRing0_1_2_0;WinRing0_1_2_0;d:\test\ECECECEC\WinRing0.sys [x] R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 81704] R4 AntiVirWebService;Avira Browser-Schutz;c:\program files\Avira\AntiVir Desktop\avwebg7.exe [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys [2014-04-05 776976] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys [2014-04-05 411552] S1 funfrm;funfrm; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2014-04-05 67824] S2 EpsonScanSvc;Epson Scanner Service;c:\windows\system32\EscSvc.exe [2011-12-11 122000] S2 LiveUpdateSvc;LiveUpdate;c:\program files\IObit\LiveUpdate\LiveUpdate.exe [2013-12-31 2151744] S2 VMCService;Vodafone Mobile Connect Service;c:\program files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [2008-07-04 14336] S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2009-05-19 21520] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - WS2IFSL . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] LocalServiceAndNoImpersonation REG_MULTI_SZ SSDPSRV upnphost SCardSvr TBS fdrespub AppIDSvc QWAVE wcncsvc SensrSvc Mcx2Svc . Inhalt des "geplante Tasks" Ordners . 2014-04-07 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-24 20:16] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.de/ mStart Page = hxxp://www.google.com IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~2\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.2.1 FF - ProfilePath - c:\users\Kazuya\AppData\Roaming\Mozilla\Firefox\Profiles\miuov82a.default-1388595698206\ FF - prefs.js: browser.startup.homepage - www.google.de . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{8dbb6d8e-e4a6-4e3b-9753-af78b226441c} - (no file) BHO-{10921475-03CE-4E04-90CE-E2E7EF20C814} - c:\program files\IObit\IObit Uninstaller\UninstallExplorer32.dll Toolbar-Locked - (no file) Toolbar-10 - (no file) WebBrowser-{8DBB6D8E-E4A6-4E3B-9753-AF78B226441C} - (no file) WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file) WebBrowser-{41564952-412D-5637-00A7-7A786E7484D7} - (no file) SafeBoot-Wdf01000.sys SafeBoot-mcmscsvc SafeBoot-MCODS MSConfigStartUp-avgnt - c:\program files\Avira\AntiVir Desktop\avgnt.exe MSConfigStartUp-mobilegeni daemon - c:\program files\Mobogenie\DaemonProcess.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\system32\WLANExt.exe c:\windows\system32\conhost.exe c:\program files\AVAST Software\Avast\AvastSvc.exe c:\windows\system32\taskhost.exe c:\program files\Common Files\Adobe\ARM\1.0\armsvc.exe c:\program files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe c:\program files\Microsoft SQL Server\90\Shared\sqlbrowser.exe c:\program files\Microsoft SQL Server\90\Shared\sqlwriter.exe c:\program files\Intel\Intel Matrix Storage Manager\IAANTMon.exe c:\windows\servicing\TrustedInstaller.exe c:\windows\system32\conhost.exe c:\program files\Windows Media Player\wmpnetwk.exe c:\windows\system32\sppsvc.exe c:\program files\AVAST Software\Avast\AvastEmUpdate.exe . ************************************************************************** . Zeit der Fertigstellung: 2014-04-07 16:09:23 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2014-04-07 14:09 . Vor Suchlauf: 7 Verzeichnis(se), 167.261.696.000 Bytes frei Nach Suchlauf: 11 Verzeichnis(se), 169.584.164.864 Bytes frei . - - End Of File - - 667DCF8E003166A3E152DCE02DC229CF A36C5E4F47E84449FF07ED3517B43A31 |
08.04.2014, 11:16 | #6 |
/// the machine /// TB-Ausbilder | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ --> Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet |
08.04.2014, 19:27 | #7 |
| Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Huhu schrauber, Anweisungen ausgeführt? Check! Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 08.04.2014 Suchlauf-Zeit: 19:42:22 Logdatei: mbam.txt Administrator: Ja Version: 2.00.1.1004 Malware Datenbank: v2014.04.08.05 Rootkit Datenbank: v2014.03.27.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Chameleon: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: Kazuya Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 240872 Verstrichene Zeit: 17 Min, 16 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Aktiviert Shuriken: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.023 - Bericht erstellt am 08/04/2014 um 19:55:35 # Aktualisiert 01/04/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : Kazuya - KOICHI # Gestartet von : C:\Users\Kazuya\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Program Files\BrowseSmart Ordner Gelöscht : C:\Program Files\Mobogenie Ordner Gelöscht : C:\Users\Kazuya\AppData\Local\Mobogenie Ordner Gelöscht : C:\Users\Kazuya\AppData\LocalLow\Softonic_Deutsch ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Classes\iLivid.torrent Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\WLXQuickTimeShellExt.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateWebConnect_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\updateWebConnect_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_download_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_download_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\532de8db538ed43 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C292AD0A-C11F-479B-B8DB-743E72D283B0} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{3D86A75B-CB6B-4764-885D-CA6336F04BA2} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{CFD485F0-96BD-47CD-BB6D-CD7DDA95F102} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{77AA745B-F4F8-45DA-9B14-61D2D95054C8} Schlüssel Gelöscht : HKCU\Software\AppDataLow\{1146AC44-2F03-4431-B4FD-889BC837521F} Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4 ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16521 -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\Kazuya\AppData\Roaming\Mozilla\Firefox\Profiles\miuov82a.default-1388595698206\prefs.js ] ************************* AdwCleaner[R0].txt - [2648 octets] - [08/04/2014 19:54:37] AdwCleaner[S0].txt - [2577 octets] - [08/04/2014 19:55:35] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [2637 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x86 Ran by Kazuya on 08.04.2014 at 20:03:18,11 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 08.04.2014 at 20:07:29,86 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01 (ATTENTION: ====> FRST version is 26 days old and could be outdated) Ran by Kazuya (administrator) on KOICHI on 08-04-2014 20:13:54 Running from C:\Users\Kazuya\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\windows\system32\WLANExt.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\windows\System32\lpksetup.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (Seiko Epson Corporation) C:\windows\system32\EscSvc.exe (IObit) C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIJAE.EXE (Microsoft Corporation) C:\windows\system32\wuauclt.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [FUFAXRCV] - C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe [502952 2012-07-09] (SEIKO EPSON CORPORATION) HKLM\...\Run: [FUFAXSTM] - C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [863400 2012-07-09] (SEIKO EPSON CORPORATION) HKLM\...\Run: [EEventManager] - C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1058912 2012-04-02] (SEIKO EPSON CORPORATION) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-05] (AVAST Software) HKU\.DEFAULT\...\RunOnce: [WLStart] - C:\Program Files\Windows Live\Installer\wlstart.exe [786760 2009-07-26] (Microsoft Corporation) HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\Run: [EPLTarget\P0000000000000000] - C:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIJAE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Kazuya\AppData\Roaming\Mozilla\Firefox\Profiles\miuov82a.default-1388595698206 FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-05] ========================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-05] (AVAST Software) R2 EpsonScanSvc; C:\windows\system32\EscSvc.exe [122000 2011-12-12] (Seiko Epson Corporation) R2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2151744 2013-12-31] (IObit) S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-07-04] (Vodafone) S4 AntiVirWebService; "C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe" [X] ==================== Drivers (Whitelisted) ==================== R3 ACPIVPC; C:\windows\System32\DRIVERS\AcpiVpc.sys [21520 2009-05-19] (Lenovo Corporation) R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [67824 2014-04-05] (AVAST Software) R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [81768 2014-04-05] (AVAST Software) R0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49944 2014-04-05] () R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [776976 2014-04-05] (AVAST Software) R1 aswSP; C:\windows\system32\drivers\aswSP.sys [411552 2014-04-05] (AVAST Software) R3 aswStm; C:\windows\system32\drivers\aswStm.sys [67264 2014-04-05] (AVAST Software) R0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [180760 2014-04-05] () R1 funfrm; C:\windows\system32\Drivers\funfrm.sys [54800 2010-02-09] () S3 wdmirror; C:\windows\System32\DRIVERS\WDMirror.sys [11792 2009-07-16] (Windows (R) Codename Longhorn DDK provider) S3 wsvd; C:\windows\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink) S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X] U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\Kazuya\AppData\Local\Temp\catchme.sys [X] S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X] S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X] S3 WinRing0_1_2_0; \??\D:\test\ECECECEC\WinRing0.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-08 20:13 - 2014-04-08 20:13 - 00008450 _____ () C:\Users\Kazuya\Desktop\FRST.txt 2014-04-08 20:07 - 2014-04-08 20:07 - 00000626 _____ () C:\Users\Kazuya\Desktop\JRT.txt 2014-04-08 20:01 - 2014-04-08 20:01 - 01016261 _____ (Thisisu) C:\Users\Kazuya\Desktop\JRT.exe 2014-04-08 20:00 - 2014-04-08 20:00 - 00002717 _____ () C:\Users\Kazuya\Desktop\AdwCleaner[S0].txt 2014-04-08 19:54 - 2014-04-08 19:55 - 00000000 ____D () C:\AdwCleaner 2014-04-08 19:53 - 2014-04-08 19:53 - 01426178 _____ () C:\Users\Kazuya\Desktop\adwcleaner.exe 2014-04-08 19:52 - 2014-04-08 19:52 - 00001150 _____ () C:\Users\Kazuya\Desktop\mbam.txt 2014-04-08 19:22 - 2014-04-08 19:25 - 00107736 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-08 19:22 - 2014-04-08 19:22 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-04-08 19:22 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-04-08 19:22 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-04-08 19:22 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-04-07 15:45 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe 2014-04-07 15:45 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe 2014-04-07 15:45 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe 2014-04-07 15:45 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe 2014-04-07 15:45 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe 2014-04-07 15:45 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe 2014-04-07 15:45 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe 2014-04-07 15:45 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe 2014-04-07 15:44 - 2014-04-07 16:09 - 00000000 ____D () C:\Qoobox 2014-04-07 15:44 - 2014-04-07 16:09 - 00000000 ____D () C:\ComboFix 2014-04-07 15:44 - 2014-04-07 16:08 - 00000000 ____D () C:\windows\erdnt 2014-04-06 16:39 - 2014-04-06 16:39 - 00000000 ____D () C:\Users\Kazuya\Documents\Fax 2014-04-06 15:05 - 2014-04-06 15:05 - 00145256 _____ () C:\windows\Minidump\040614-18579-01.dmp 2014-04-06 15:05 - 2014-04-06 15:05 - 00000000 ____D () C:\windows\Minidump 2014-04-06 15:04 - 2014-04-06 15:04 - 184417329 _____ () C:\windows\MEMORY.DMP 2014-04-06 14:28 - 2014-04-08 20:13 - 00000000 ____D () C:\FRST 2014-04-06 14:23 - 2014-04-06 14:23 - 01145856 _____ (Farbar) C:\Users\Kazuya\Desktop\FRST.exe 2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable 2014-04-06 14:17 - 2014-04-08 20:10 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt 2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia 2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-04-05 22:10 - 2014-04-08 19:57 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software 2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe 2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software 2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys 2014-04-05 21:50 - 2014-04-05 21:54 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys 2014-04-05 21:37 - 2014-04-05 21:38 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe 2014-03-31 08:50 - 2014-03-31 08:53 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik Konzeptverkäufer HRO 4 2014.ods 2014-03-25 20:14 - 2014-03-25 20:15 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe 2014-03-16 19:32 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-03-16 19:32 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-03-16 19:32 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-03-16 19:32 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-03-16 19:32 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-03-16 19:32 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-03-16 19:32 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-03-16 19:32 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-03-16 19:32 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-03-16 19:32 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-03-16 19:32 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-03-16 19:32 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-03-16 19:32 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-03-16 19:32 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-03-16 19:32 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-03-16 19:32 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-03-16 19:32 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-03-16 19:32 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-03-16 19:32 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-03-16 19:32 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-03-16 19:32 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-03-16 19:32 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-03-16 19:26 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2014-03-16 19:26 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll 2014-03-16 19:26 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2014-03-16 19:26 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll 2014-03-16 19:26 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll 2014-03-11 13:59 - 2014-03-21 23:56 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx 2014-03-11 13:57 - 2014-03-25 20:23 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff 2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx ==================== One Month Modified Files and Folders ======= 2014-04-08 20:14 - 2014-04-08 20:13 - 00008450 _____ () C:\Users\Kazuya\Desktop\FRST.txt 2014-04-08 20:13 - 2014-04-06 14:28 - 00000000 ____D () C:\FRST 2014-04-08 20:10 - 2014-04-06 14:17 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt 2014-04-08 20:07 - 2014-04-08 20:07 - 00000626 _____ () C:\Users\Kazuya\Desktop\JRT.txt 2014-04-08 20:06 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-08 20:06 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-08 20:01 - 2014-04-08 20:01 - 01016261 _____ (Thisisu) C:\Users\Kazuya\Desktop\JRT.exe 2014-04-08 20:00 - 2014-04-08 20:00 - 00002717 _____ () C:\Users\Kazuya\Desktop\AdwCleaner[S0].txt 2014-04-08 19:58 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-04-08 19:58 - 2009-07-14 06:39 - 00113903 _____ () C:\windows\setupact.log 2014-04-08 19:57 - 2014-04-05 22:10 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-04-08 19:56 - 2010-02-09 10:45 - 02011090 _____ () C:\windows\WindowsUpdate.log 2014-04-08 19:55 - 2014-04-08 19:54 - 00000000 ____D () C:\AdwCleaner 2014-04-08 19:53 - 2014-04-08 19:53 - 01426178 _____ () C:\Users\Kazuya\Desktop\adwcleaner.exe 2014-04-08 19:52 - 2014-04-08 19:52 - 00001150 _____ () C:\Users\Kazuya\Desktop\mbam.txt 2014-04-08 19:25 - 2014-04-08 19:22 - 00107736 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-08 19:22 - 2014-04-08 19:22 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-04-08 19:22 - 2013-12-31 20:30 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-08 18:51 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\tracing 2014-04-08 00:53 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\FxsTmp 2014-04-07 16:09 - 2014-04-07 15:44 - 00000000 ____D () C:\Qoobox 2014-04-07 16:09 - 2014-04-07 15:44 - 00000000 ____D () C:\ComboFix 2014-04-07 16:09 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default 2014-04-07 16:09 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public 2014-04-07 16:08 - 2014-04-07 15:44 - 00000000 ____D () C:\windows\erdnt 2014-04-07 16:03 - 2009-07-14 04:04 - 00000215 _____ () C:\windows\system.ini 2014-04-07 16:01 - 2010-01-18 19:12 - 00631888 _____ () C:\windows\PFRO.log 2014-04-06 16:39 - 2014-04-06 16:39 - 00000000 ____D () C:\Users\Kazuya\Documents\Fax 2014-04-06 15:05 - 2014-04-06 15:05 - 00145256 _____ () C:\windows\Minidump\040614-18579-01.dmp 2014-04-06 15:05 - 2014-04-06 15:05 - 00000000 ____D () C:\windows\Minidump 2014-04-06 15:04 - 2014-04-06 15:04 - 184417329 _____ () C:\windows\MEMORY.DMP 2014-04-06 14:23 - 2014-04-06 14:23 - 01145856 _____ (Farbar) C:\Users\Kazuya\Desktop\FRST.exe 2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable 2014-04-06 14:20 - 2010-09-08 16:02 - 00000000 ____D () C:\Users\Kazuya 2014-04-06 14:09 - 2013-09-24 19:27 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-04-06 00:41 - 2010-01-18 19:03 - 01765534 _____ () C:\windows\system32\PerfStringBackup.INI 2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia 2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-04-05 22:16 - 2013-09-24 18:58 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe 2014-04-05 22:16 - 2013-04-07 17:59 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl 2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software 2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe 2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software 2014-04-05 21:54 - 2014-04-05 21:50 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys 2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys 2014-04-05 21:48 - 2013-09-28 21:38 - 00000000 ____D () C:\ProgramData\Avira 2014-04-05 21:38 - 2014-04-05 21:37 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe 2014-04-05 20:27 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\wfp 2014-04-05 20:26 - 2011-01-28 17:09 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\vlc 2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\NDF 2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\AppCompat 2014-04-05 20:25 - 2010-01-18 18:57 - 00000000 ___RD () C:\MSOCache 2014-04-05 20:25 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\registration 2014-04-03 09:51 - 2014-04-08 19:22 - 00073432 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-08 19:22 - 00051416 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-08 19:22 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-04-01 01:53 - 2009-07-29 12:50 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-03-31 08:53 - 2014-03-31 08:50 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik 2014.ods 2014-03-26 21:26 - 2013-12-31 19:52 - 00000000 ____D () C:\ProgramData\ProductData 2014-03-25 20:23 - 2014-03-11 13:57 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff 2014-03-25 20:19 - 2010-01-18 19:13 - 00000000 ____D () C:\ProgramData\Adobe 2014-03-25 20:18 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\Adobe 2014-03-25 20:17 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Adobe 2014-03-25 20:15 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe 2014-03-21 23:56 - 2014-03-11 13:59 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx 2014-03-16 19:41 - 2009-07-14 06:33 - 00414320 _____ () C:\windows\system32\FNTCACHE.DAT 2014-03-16 19:36 - 2013-09-30 15:36 - 00000000 ____D () C:\windows\system32\MRT 2014-03-16 19:33 - 2013-09-30 15:36 - 87350280 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-03-11 13:59 - 2010-09-13 21:36 - 00000000 ____D () C:\Users\Public\Documents\texte 2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx Some content of TEMP: ==================== C:\Users\Kazuya\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\windows\explorer.exe => MD5 is legit C:\windows\system32\winlogon.exe => MD5 is legit C:\windows\system32\wininit.exe => MD5 is legit C:\windows\system32\svchost.exe => MD5 is legit C:\windows\system32\services.exe => MD5 is legit C:\windows\system32\User32.dll => MD5 is legit C:\windows\system32\userinit.exe => MD5 is legit C:\windows\system32\rpcss.dll => MD5 is legit C:\windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-31 03:14 ==================== End Of Log ============================ |
09.04.2014, 14:59 | #8 |
/// the machine /// TB-Ausbilder | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastetESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
10.04.2014, 10:30 | #9 |
| Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Huhu schrauber, hier die Log's: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=d8d391a628a5b84b8132e9be7f5cbb85 # engine=17823 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-04-09 10:07:42 # local_time=2014-04-10 12:07:42 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 71 74 353413 353431 0 0 # compatibility_mode=5893 16776573 100 94 100126 148712453 0 0 # scanned=115485 # found=0 # cleaned=0 # scan_time=3806 Code:
ATTFilter Results of screen317's Security Check version 0.99.81 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` avast! Antivirus Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Adobe Flash Player 12.0.0.77 Adobe Reader XI Mozilla Firefox (28.0) ````````Process Check: objlist.exe by Laurent```````` system32 AvastSvc.exe -?- AVAST Software Avast AvastUI.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 13-03-2014 01 (ATTENTION: ====> FRST version is 28 days old and could be outdated) Ran by Kazuya (administrator) on KOICHI on 10-04-2014 00:12:34 Running from C:\Users\Kazuya\Desktop Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Microsoft Corporation) C:\windows\system32\WLANExt.exe (Microsoft Corporation) C:\Program Files\Microsoft Small Business\Business Contact Manager\BcmSqlStartupSvc.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe (SEIKO EPSON CORPORATION) C:\Program Files\Epson Software\Event Manager\EEventManager.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Seiko Epson Corporation) C:\windows\system32\EscSvc.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (IObit) C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe (Microsoft Corporation) c:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe (Vodafone) C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe (Microsoft Corporation) C:\windows\system32\wuauclt.exe (Intel Corporation) C:\windows\system32\igfxsrvc.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [FUFAXRCV] - C:\Program Files\Epson Software\FAX Utility\FUFAXRCV.exe [502952 2012-07-09] (SEIKO EPSON CORPORATION) HKLM\...\Run: [FUFAXSTM] - C:\Program Files\Epson Software\FAX Utility\FUFAXSTM.exe [863400 2012-07-09] (SEIKO EPSON CORPORATION) HKLM\...\Run: [EEventManager] - C:\Program Files\Epson Software\Event Manager\EEventManager.exe [1058912 2012-04-02] (SEIKO EPSON CORPORATION) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-12-21] (Adobe Systems Incorporated) HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3854640 2014-04-05] (AVAST Software) HKU\.DEFAULT\...\RunOnce: [WLStart] - C:\Program Files\Windows Live\Installer\wlstart.exe [786760 2009-07-26] (Microsoft Corporation) HKU\S-1-5-21-2525846817-1715903705-3963689401-1003\...\Run: [EPLTarget\P0000000000000000] - C:\windows\system32\spool\DRIVERS\W32X86\3\E_FATIJAE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search BHO: No Name - {5C255C8A-E604-49b4-9D64-90988571CECB} - No File BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} https://fpdownload.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Handler: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.14.0.8089.0726.dll (Microsoft Corporation) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Kazuya\AppData\Roaming\Mozilla\Firefox\Profiles\miuov82a.default-1388595698206 FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\windows\system32\Macromed\Flash\NPSWF32_12_0_0_77.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=14.0.8081.0709 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.3 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-04-05] ========================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-04-05] (AVAST Software) R2 EpsonScanSvc; C:\windows\system32\EscSvc.exe [122000 2011-12-12] (Seiko Epson Corporation) R2 LiveUpdateSvc; C:\Program Files\IObit\LiveUpdate\LiveUpdate.exe [2151744 2013-12-31] (IObit) S4 MSSQLServerADHelper; c:\Program Files\Microsoft SQL Server\90\Shared\sqladhlp90.exe [44384 2010-12-10] (Microsoft Corporation) R2 VMCService; C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe [14336 2008-07-04] (Vodafone) S4 AntiVirWebService; "C:\Program Files\Avira\AntiVir Desktop\avwebg7.exe" [X] ==================== Drivers (Whitelisted) ==================== R3 ACPIVPC; C:\windows\System32\DRIVERS\AcpiVpc.sys [21520 2009-05-19] (Lenovo Corporation) R2 aswMonFlt; C:\windows\system32\drivers\aswMonFlt.sys [67824 2014-04-05] (AVAST Software) R1 aswRdr; C:\windows\system32\drivers\aswRdr2.sys [81768 2014-04-05] (AVAST Software) R0 aswRvrt; C:\windows\system32\Drivers\aswRvrt.sys [49944 2014-04-05] () R1 aswSnx; C:\windows\system32\drivers\aswSnx.sys [776976 2014-04-05] (AVAST Software) R1 aswSP; C:\windows\system32\drivers\aswSP.sys [411552 2014-04-05] (AVAST Software) S3 aswStm; C:\windows\system32\drivers\aswStm.sys [67264 2014-04-05] (AVAST Software) R0 aswVmm; C:\windows\system32\Drivers\aswVmm.sys [180760 2014-04-05] () R1 funfrm; C:\windows\system32\Drivers\funfrm.sys [54800 2010-02-09] () S3 wdmirror; C:\windows\System32\DRIVERS\WDMirror.sys [11792 2009-07-16] (Windows (R) Codename Longhorn DDK provider) S3 wsvd; C:\windows\System32\DRIVERS\wsvd.sys [81704 2009-07-21] (CyberLink) S3 ApfiltrService; system32\DRIVERS\Apfiltr.sys [X] U5 AppMgmt; C:\windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\Users\Kazuya\AppData\Local\Temp\catchme.sys [X] S3 RSUSBSTOR; System32\Drivers\RtsUStor.sys [X] S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [X] S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [X] S3 WinRing0_1_2_0; \??\D:\test\ECECECEC\WinRing0.sys [X] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-10 00:12 - 2014-04-10 00:12 - 00008469 _____ () C:\Users\Kazuya\Desktop\FRST.txt 2014-04-10 00:12 - 2014-04-10 00:12 - 00000752 _____ () C:\Users\Kazuya\Desktop\checkup.txt 2014-04-10 00:10 - 2014-04-10 00:10 - 00987448 _____ () C:\Users\Kazuya\Desktop\SecurityCheck.exe 2014-04-09 23:02 - 2014-04-09 23:02 - 00000000 ____D () C:\Program Files\ESET 2014-04-09 22:59 - 2014-04-09 22:59 - 00016384 _____ () C:\windows\system32\Ikeext.etl 2014-04-09 22:55 - 2014-04-09 22:55 - 02347384 _____ (ESET) C:\Users\Kazuya\Desktop\esetsmartinstaller_enu.exe 2014-04-08 19:54 - 2014-04-08 19:55 - 00000000 ____D () C:\AdwCleaner 2014-04-08 19:22 - 2014-04-08 20:34 - 00107736 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-08 19:22 - 2014-04-08 19:22 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-04-08 19:22 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-04-08 19:22 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-04-08 19:22 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-04-07 15:45 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe 2014-04-07 15:45 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe 2014-04-07 15:45 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe 2014-04-07 15:45 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe 2014-04-07 15:45 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe 2014-04-07 15:45 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe 2014-04-07 15:45 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe 2014-04-07 15:45 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe 2014-04-07 15:44 - 2014-04-07 16:09 - 00000000 ____D () C:\Qoobox 2014-04-07 15:44 - 2014-04-07 16:09 - 00000000 ____D () C:\ComboFix 2014-04-07 15:44 - 2014-04-07 16:08 - 00000000 ____D () C:\windows\erdnt 2014-04-06 16:39 - 2014-04-06 16:39 - 00000000 ____D () C:\Users\Kazuya\Documents\Fax 2014-04-06 15:05 - 2014-04-06 15:05 - 00145256 _____ () C:\windows\Minidump\040614-18579-01.dmp 2014-04-06 15:05 - 2014-04-06 15:05 - 00000000 ____D () C:\windows\Minidump 2014-04-06 15:04 - 2014-04-06 15:04 - 184417329 _____ () C:\windows\MEMORY.DMP 2014-04-06 14:28 - 2014-04-10 00:12 - 00000000 ____D () C:\FRST 2014-04-06 14:23 - 2014-04-06 14:23 - 01145856 _____ (Farbar) C:\Users\Kazuya\Desktop\FRST.exe 2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable 2014-04-06 14:17 - 2014-04-10 00:11 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt 2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia 2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-04-05 22:10 - 2014-04-09 23:57 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software 2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe 2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software 2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys 2014-04-05 21:50 - 2014-04-05 21:54 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys 2014-04-05 21:37 - 2014-04-05 21:38 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe 2014-03-31 08:50 - 2014-03-31 08:53 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik 2014.ods 2014-03-25 20:14 - 2014-03-25 20:15 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe 2014-03-16 19:32 - 2014-03-01 06:30 - 17074688 _____ (Microsoft Corporation) C:\windows\system32\mshtml.dll 2014-03-16 19:32 - 2014-03-01 06:11 - 02724864 _____ (Microsoft Corporation) C:\windows\system32\mshtml.tlb 2014-03-16 19:32 - 2014-03-01 06:10 - 00004096 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollectorres.dll 2014-03-16 19:32 - 2014-03-01 05:52 - 00061952 _____ (Microsoft Corporation) C:\windows\system32\iesetup.dll 2014-03-16 19:32 - 2014-03-01 05:51 - 00051200 _____ (Microsoft Corporation) C:\windows\system32\ieetwproxystub.dll 2014-03-16 19:32 - 2014-03-01 05:47 - 02168320 _____ (Microsoft Corporation) C:\windows\system32\iertutil.dll 2014-03-16 19:32 - 2014-03-01 05:43 - 00043008 _____ (Microsoft Corporation) C:\windows\system32\jsproxy.dll 2014-03-16 19:32 - 2014-03-01 05:43 - 00032768 _____ (Microsoft Corporation) C:\windows\system32\iernonce.dll 2014-03-16 19:32 - 2014-03-01 05:40 - 00440832 _____ (Microsoft Corporation) C:\windows\system32\ieui.dll 2014-03-16 19:32 - 2014-03-01 05:38 - 00112128 _____ (Microsoft Corporation) C:\windows\system32\ieUnatt.exe 2014-03-16 19:32 - 2014-03-01 05:38 - 00108032 _____ (Microsoft Corporation) C:\windows\system32\ieetwcollector.exe 2014-03-16 19:32 - 2014-03-01 05:37 - 00553472 _____ (Microsoft Corporation) C:\windows\system32\jscript9diag.dll 2014-03-16 19:32 - 2014-03-01 05:31 - 00646144 _____ (Microsoft Corporation) C:\windows\system32\MsSpellCheckingFacility.exe 2014-03-16 19:32 - 2014-03-01 05:25 - 00208896 _____ (Microsoft Corporation) C:\windows\system32\ie4uinit.exe 2014-03-16 19:32 - 2014-03-01 05:16 - 00164864 _____ (Microsoft Corporation) C:\windows\system32\msrating.dll 2014-03-16 19:32 - 2014-03-01 05:14 - 04244480 _____ (Microsoft Corporation) C:\windows\system32\jscript9.dll 2014-03-16 19:32 - 2014-03-01 05:03 - 00524288 _____ (Microsoft Corporation) C:\windows\system32\msfeeds.dll 2014-03-16 19:32 - 2014-03-01 05:00 - 01964032 _____ (Microsoft Corporation) C:\windows\system32\inetcpl.cpl 2014-03-16 19:32 - 2014-03-01 04:57 - 11266048 _____ (Microsoft Corporation) C:\windows\system32\ieframe.dll 2014-03-16 19:32 - 2014-03-01 04:32 - 01820160 _____ (Microsoft Corporation) C:\windows\system32\wininet.dll 2014-03-16 19:32 - 2014-03-01 04:27 - 01156096 _____ (Microsoft Corporation) C:\windows\system32\urlmon.dll 2014-03-16 19:32 - 2014-03-01 04:25 - 00703488 _____ (Microsoft Corporation) C:\windows\system32\ieapfltr.dll 2014-03-16 19:26 - 2014-02-07 03:07 - 02349056 _____ (Microsoft Corporation) C:\windows\system32\win32k.sys 2014-03-16 19:26 - 2014-02-04 04:04 - 01230336 _____ (Microsoft Corporation) C:\windows\system32\WindowsCodecs.dll 2014-03-16 19:26 - 2014-02-04 04:04 - 00509440 _____ (Microsoft Corporation) C:\windows\system32\qedit.dll 2014-03-16 19:26 - 2014-01-29 04:06 - 00381440 _____ (Microsoft Corporation) C:\windows\system32\wer.dll 2014-03-16 19:26 - 2014-01-28 04:07 - 00185344 _____ (Microsoft Corporation) C:\windows\system32\wwansvc.dll 2014-03-11 13:59 - 2014-03-21 23:56 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx 2014-03-11 13:57 - 2014-03-25 20:23 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff 2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx ==================== One Month Modified Files and Folders ======= 2014-04-10 00:12 - 2014-04-10 00:12 - 00008469 _____ () C:\Users\Kazuya\Desktop\FRST.txt 2014-04-10 00:12 - 2014-04-10 00:12 - 00000752 _____ () C:\Users\Kazuya\Desktop\checkup.txt 2014-04-10 00:12 - 2014-04-06 14:28 - 00000000 ____D () C:\FRST 2014-04-10 00:11 - 2014-04-06 14:17 - 00000000 ____D () C:\Users\Kazuya\Downloads\Schritt für Schritt 2014-04-10 00:10 - 2014-04-10 00:10 - 00987448 _____ () C:\Users\Kazuya\Desktop\SecurityCheck.exe 2014-04-09 23:57 - 2014-04-05 22:10 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2014-04-09 23:40 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\tracing 2014-04-09 23:22 - 2010-02-09 10:45 - 02057635 _____ () C:\windows\WindowsUpdate.log 2014-04-09 23:02 - 2014-04-09 23:02 - 00000000 ____D () C:\Program Files\ESET 2014-04-09 22:59 - 2014-04-09 22:59 - 00016384 _____ () C:\windows\system32\Ikeext.etl 2014-04-09 22:55 - 2014-04-09 22:55 - 02347384 _____ (ESET) C:\Users\Kazuya\Desktop\esetsmartinstaller_enu.exe 2014-04-09 22:53 - 2009-07-14 06:39 - 00114105 _____ () C:\windows\setupact.log 2014-04-09 22:51 - 2010-01-18 19:03 - 01765534 _____ () C:\windows\system32\PerfStringBackup.INI 2014-04-09 22:41 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-09 22:41 - 2009-07-14 06:34 - 00009696 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-09 22:34 - 2009-07-14 06:53 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2014-04-09 01:01 - 2009-07-14 06:52 - 00000000 ____D () C:\windows\system32\FxsTmp 2014-04-08 20:34 - 2014-04-08 19:22 - 00107736 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\MBAMSwissArmy.sys 2014-04-08 19:55 - 2014-04-08 19:54 - 00000000 ____D () C:\AdwCleaner 2014-04-08 19:22 - 2014-04-08 19:22 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-04-08 19:22 - 2013-12-31 20:30 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-04-07 16:09 - 2014-04-07 15:44 - 00000000 ____D () C:\Qoobox 2014-04-07 16:09 - 2014-04-07 15:44 - 00000000 ____D () C:\ComboFix 2014-04-07 16:09 - 2009-07-14 04:37 - 00000000 __RHD () C:\Users\Default 2014-04-07 16:09 - 2009-07-14 04:37 - 00000000 ___RD () C:\Users\Public 2014-04-07 16:08 - 2014-04-07 15:44 - 00000000 ____D () C:\windows\erdnt 2014-04-07 16:03 - 2009-07-14 04:04 - 00000215 _____ () C:\windows\system.ini 2014-04-07 16:01 - 2010-01-18 19:12 - 00631888 _____ () C:\windows\PFRO.log 2014-04-06 16:39 - 2014-04-06 16:39 - 00000000 ____D () C:\Users\Kazuya\Documents\Fax 2014-04-06 15:05 - 2014-04-06 15:05 - 00145256 _____ () C:\windows\Minidump\040614-18579-01.dmp 2014-04-06 15:05 - 2014-04-06 15:05 - 00000000 ____D () C:\windows\Minidump 2014-04-06 15:04 - 2014-04-06 15:04 - 184417329 _____ () C:\windows\MEMORY.DMP 2014-04-06 14:23 - 2014-04-06 14:23 - 01145856 _____ (Farbar) C:\Users\Kazuya\Desktop\FRST.exe 2014-04-06 14:20 - 2014-04-06 14:20 - 00000000 _____ () C:\Users\Kazuya\defogger_reenable 2014-04-06 14:20 - 2010-09-08 16:02 - 00000000 ____D () C:\Users\Kazuya 2014-04-06 14:09 - 2013-09-24 19:27 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-04-05 22:42 - 2014-04-05 22:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Macromedia 2014-04-05 22:39 - 2014-04-05 22:39 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-04-05 22:25 - 2014-04-05 22:25 - 00001028 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2014-04-05 22:16 - 2013-09-24 18:58 - 00692616 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerApp.exe 2014-04-05 22:16 - 2013-04-07 17:59 - 00071048 _____ (Adobe Systems Incorporated) C:\windows\system32\FlashPlayerCPLApp.cpl 2014-04-05 21:58 - 2014-04-05 21:58 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\AVAST Software 2014-04-05 21:57 - 2014-04-05 21:57 - 00776976 _____ (AVAST Software) C:\windows\system32\Drivers\aswSnx.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\aswSP.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00271264 _____ (AVAST Software) C:\windows\system32\aswBoot.exe 2014-04-05 21:57 - 2014-04-05 21:57 - 00180760 _____ () C:\windows\system32\Drivers\aswVmm.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00081768 _____ (AVAST Software) C:\windows\system32\Drivers\aswRdr2.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00067824 _____ (AVAST Software) C:\windows\system32\Drivers\aswMonFlt.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00067264 _____ (AVAST Software) C:\windows\system32\Drivers\aswStm.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00049944 _____ () C:\windows\system32\Drivers\aswRvrt.sys 2014-04-05 21:57 - 2014-04-05 21:57 - 00043152 _____ (AVAST Software) C:\windows\avastSS.scr 2014-04-05 21:56 - 2014-04-05 21:56 - 00000000 ____D () C:\Program Files\AVAST Software 2014-04-05 21:54 - 2014-04-05 21:50 - 00000000 ____D () C:\ProgramData\AVAST Software 2014-04-05 21:51 - 2014-04-05 21:51 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\rtgdysgh.sys 2014-04-05 21:50 - 2014-04-05 21:50 - 00411552 _____ (AVAST Software) C:\windows\system32\Drivers\ptzlzhni.sys 2014-04-05 21:48 - 2013-09-28 21:38 - 00000000 ____D () C:\ProgramData\Avira 2014-04-05 21:38 - 2014-04-05 21:37 - 88551496 _____ (AVAST Software) C:\Users\Kazuya\Downloads\avast_free_antivirus_setup.exe 2014-04-05 20:27 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\wfp 2014-04-05 20:26 - 2011-01-28 17:09 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\vlc 2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\system32\NDF 2014-04-05 20:26 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\AppCompat 2014-04-05 20:25 - 2010-01-18 18:57 - 00000000 ___RD () C:\MSOCache 2014-04-05 20:25 - 2009-07-14 04:37 - 00000000 ____D () C:\windows\registration 2014-04-03 09:51 - 2014-04-08 19:22 - 00073432 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbamchameleon.sys 2014-04-03 09:51 - 2014-04-08 19:22 - 00051416 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mwac.sys 2014-04-03 09:50 - 2014-04-08 19:22 - 00023256 _____ (Malwarebytes Corporation) C:\windows\system32\Drivers\mbam.sys 2014-04-01 01:53 - 2009-07-29 12:50 - 00000000 ___RD () C:\Users\Public\Recorded TV 2014-03-31 08:53 - 2014-03-31 08:50 - 00004979 _____ () C:\Users\Kazuya\Downloads\Statistik 2014.ods 2014-03-26 21:26 - 2013-12-31 19:52 - 00000000 ____D () C:\ProgramData\ProductData 2014-03-25 20:23 - 2014-03-11 13:57 - 00000000 ____D () C:\Users\Kazuya\Desktop\stuff 2014-03-25 20:19 - 2010-01-18 19:13 - 00000000 ____D () C:\ProgramData\Adobe 2014-03-25 20:18 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Roaming\Adobe 2014-03-25 20:17 - 2010-09-15 15:42 - 00000000 ____D () C:\Users\Kazuya\AppData\Local\Adobe 2014-03-25 20:15 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-03-25 20:14 - 2014-03-25 20:14 - 00000000 ____D () C:\Program Files\Adobe 2014-03-21 23:56 - 2014-03-11 13:59 - 00010532 _____ () C:\Users\Kazuya\Desktop\autoabzahlung dez12-dez14.xlsx 2014-03-16 19:41 - 2009-07-14 06:33 - 00414320 _____ () C:\windows\system32\FNTCACHE.DAT 2014-03-16 19:36 - 2013-09-30 15:36 - 00000000 ____D () C:\windows\system32\MRT 2014-03-16 19:33 - 2013-09-30 15:36 - 87350280 _____ (Microsoft Corporation) C:\windows\system32\MRT.exe 2014-03-11 13:59 - 2010-09-13 21:36 - 00000000 ____D () C:\Users\Public\Documents\texte 2014-03-11 13:56 - 2014-03-11 13:56 - 00011350 _____ () C:\Users\Kazuya\Desktop\Kostenaufstellung.xlsx Some content of TEMP: ==================== C:\Users\Kazuya\AppData\Local\temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\windows\explorer.exe => MD5 is legit C:\windows\system32\winlogon.exe => MD5 is legit C:\windows\system32\wininit.exe => MD5 is legit C:\windows\system32\svchost.exe => MD5 is legit C:\windows\system32\services.exe => MD5 is legit C:\windows\system32\User32.dll => MD5 is legit C:\windows\system32\userinit.exe => MD5 is legit C:\windows\system32\rpcss.dll => MD5 is legit C:\windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-03-31 03:14 ==================== End Of Log ============================ --- --- --- Das war es schon?^^ Hmm.. Auslastung des Arbeitsspeichers nur noch mit Mozilla um die 80 %. Das ist wohl normal. (Ohne irgend ein Programm geöffnet zu haben, 50 % Auslastung) IE öffnet keine Links mehr, aber den Explorer brauche ich eh nicht. Seit dem vorletzten Suchlauf stürzt Shockwave hin und wieder ab, aber mit F5 ist es wieder gut. Copy / Paste funktioniert wieder im Mozilla. Ordentlich bereinigt wurde mein Laptop ja nun auch und ungewöhnliche "Macken", wie disconnect / keine Verbindung zum Internet möglich; treten nicht mehr auf. Also vielen vielen Dank für deine Mühen und deinen Einsatz. Erscheint die Lösung einfach, kam Hilfe vom Profi! Danke Liebe Grüße Kazuya Geändert von Kazuya (10.04.2014 um 11:11 Uhr) |
11.04.2014, 06:37 | #10 |
/// the machine /// TB-Ausbilder | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Setze folgendermassen den Internet Explorer zurück:
Fertig Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.04.2014, 00:45 | #11 |
| Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Huhu schrauber, vielen Dank für deine Tips und Hinweise. Habe dank dir viel dazu gelernt und kann mich nun sicherer im Internet bewegen Für mich sind definitiv alle Fragen beantwortet, du hast mir sehr geholfen. Liebe Grüße Kazuya |
15.04.2014, 10:23 | #12 |
/// the machine /// TB-Ausbilder | Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7: Arbeitsspeicher dauerhaft zu 80 % ausgelastet |
abgesicherten, arbeitsspeicher, ausgelastet, automatisch, avast, avira, einfügen, erstell, erstellt, files, firefox, funktioniert, google, heute, infiziert, kopieren, lieber, log's, modus, mozilla, nichts, pc infiziert, programme, software, suchfunktion, windows, windows 7 |