![]() |
| |||||||
Log-Analyse und Auswertung: Win7 wird immer langsamer und Norton wird ab und an doppelt autogestartetWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #5 |
![]() ![]() | Win7 wird immer langsamer und Norton wird ab und an doppelt autogestartet Norton ist Geschichte. Code:
ATTFilter Emsisoft Internet Security - Version 9.0
Letztes Update: 14.10.2014 18:59:05
Benutzerkonto: Rollostoimetz-p\Rollostoimetz
Scan Einstellungen:
Scan Methode: Smart Scan
Objekte: Rootkits, Speicher, Traces, C:\Windows\, C:\Program Files\
PUPs-Erkennung: An
Archiv Scan: Aus
ADS Scan: An
Dateitypen-Filter: Aus
Erweitertes Caching: An
Direkter Festplattenzugriff: Aus
Scan Beginn: 14.10.2014 19:01:55
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS gefunden: Setting.DisableRegistryTools (A)
Gescannt 144921
Gefunden 1
Scan Ende: 14.10.2014 20:06:27
Scan Zeit: 1:04:32
Value: HKEY_LOCAL_MACHINE\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\POLICIES\SYSTEM -> DISABLEREGISTRYTOOLS Quarantäne Setting.DisableRegistryTools (A)
Quarantäne 1
Code:
ATTFilter # AdwCleaner v4.000 - Bericht erstellt am 14/10/2014 um 20:51:50
# DB v2014-10-13.5
# Aktualisiert 12/10/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits)
# Benutzername : Rollostoimetz - ROLLOSTOIMETZ-P
# Gestartet von : C:\Users\Rollostoimetz\Desktop\AdwCleaner_4.000.exe
# Option : Löschen
***** [ Dienste ] *****
***** [ Dateien / Ordner ] *****
***** [ Tasks ] *****
***** [ Verknüpfungen ] *****
***** [ Registrierungsdatenbank ] *****
***** [ Browser ] *****
-\\ Internet Explorer v11.0.9600.17280
-\\ Mozilla Firefox v32.0.3 (x86 de)
*************************
AdwCleaner[R0].txt - [796 octets] - [14/10/2014 20:45:21]
AdwCleaner[S0].txt - [710 octets] - [14/10/2014 20:51:50]
########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [769 octets] ##########
Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.3.3 (10.14.2014:1)
OS: Windows 7 Home Premium x86
Ran by Rollostoimetz on 14.10.2014 at 21:01:51,72
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
~~~ Files
~~~ Folders
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 14.10.2014 at 21:18:14,36
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 12-10-2014
Ran by Rollostoimetz (administrator) on ROLLOSTOIMETZ-P on 14-10-2014 21:19:07
Running from C:\Users\Rollostoimetz\Desktop
Loaded Profile: Rollostoimetz (Available profiles: Rollostoimetz & Katrin & Gast)
Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: Deutsch (Deutschland)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Internet Security\a2service.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe
(Emsisoft GmbH) C:\Program Files\Emsisoft Internet Security\a2guard.exe
(Adobe Systems Incorporated) C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(BillP Studios) C:\Program Files\BillP Studios\WinPatrol\WinPatrol.exe
(Google Inc.) C:\Program Files\Google\Update\1.3.24.15\GoogleCrashHandler.exe
() C:\Users\Rollostoimetz\AppData\Local\Amazon Music\Amazon Music Helper.exe
(Symantec Corporation) C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\nst.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(Symantec Corporation) C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\nst.exe
(Secunia) C:\Program Files\Secunia\PSI\psi_tray.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
(Secunia) C:\Program Files\Secunia\PSI\psia.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [55824 2009-06-17] (Logitech, Inc.)
HKLM\...\Run: [NvBackend] => C:\Program Files\NVIDIA Corporation\Update Core\NvBackend.exe [2404296 2014-08-09] (NVIDIA Corporation)
HKLM\...\Run: [ShadowPlay] => C:\Windows\system32\rundll32.exe C:\Windows\system32\nvspcap.dll,ShadowPlayOnSystemStart
HKLM\...\Run: [emsisoft anti-malware] => C:\Program Files\Emsisoft Internet Security\a2guard.exe [4873248 2014-10-14] (Emsisoft GmbH)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
HKU\S-1-5-21-1442112818-2063436954-1665047480-1001\...\Run: [WinPatrol] => C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe [1128000 2014-06-03] (BillP Studios)
HKU\S-1-5-21-1442112818-2063436954-1665047480-1001\...\Run: [Amazon Music] => C:\Users\Rollostoimetz\AppData\Local\Amazon Music\Amazon Music Helper.exe [3356480 2014-07-22] ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files\Secunia\PSI\psi_tray.exe (Secunia)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xC34A27FF5C78CF01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
BHO: Norton Identity Protection -> {AB4C7833-A6EC-433f-B9FE-6B14B1A2F836} -> C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\coIEPlg.dll (Symantec Corporation)
Toolbar: HKLM - Norton Identity Safe Toolbar - {A13C2648-91D4-4bf3-BC6D-0079707C4389} - C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\coIEPlg.dll (Symantec Corporation)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - C:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Rollostoimetz\AppData\Roaming\Mozilla\Firefox\Profiles\8bfr56ku.default-1410371457966
FF Homepage: https://www.google.de/?gws_rd=ssl
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_15_0_0_152.dll ()
FF Plugin: @Google.com/GoogleEarthPlugin -> C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin: @google.com/npPicasa3,version=3.0.0 -> C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 -> C:\Users\Rollostoimetz\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll No File
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Ghostery - C:\Users\Rollostoimetz\AppData\Roaming\Mozilla\Firefox\Profiles\8bfr56ku.default-1410371457966\Extensions\firefox@ghostery.com.xpi [2014-09-10]
FF Extension: NoScript - C:\Users\Rollostoimetz\AppData\Roaming\Mozilla\Firefox\Profiles\8bfr56ku.default-1410371457966\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-09-10]
FF HKLM\...\Firefox\Extensions: [{F04D2D30-776C-4d02-8627-8E4385ECA58D}] - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.7.3.12\coFFPlgn
FF Extension: Norton Identity Safe Toolbar - C:\ProgramData\Norton\{92622AAD-05E8-4459-B256-765CE1E929FB}\NST_2014.7.3.12\coFFPlgn [2014-10-14]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [nppllibpnmahfaklnpggkibhkapjkeob] - C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\Exts\Chrome.crx [2014-09-23]
========================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 a2AntiMalware; C:\Program Files\Emsisoft Internet Security\a2service.exe [4816568 2014-10-14] (Emsisoft GmbH)
R2 AdobeActiveFileMonitor8.0; C:\Program Files\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [169312 2009-10-09] (Adobe Systems Incorporated)
S2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1871160 2014-10-01] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [968504 2014-10-01] (Malwarebytes Corporation)
R2 NCO; C:\Program Files\Norton Identity Safe\Engine\2014.7.8.23\NST.exe [130104 2014-09-20] (Symantec Corporation)
R2 NvNetworkService; C:\Program Files\NVIDIA Corporation\NetService\NvNetworkService.exe [1721800 2014-08-09] (NVIDIA Corporation)
R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [17551816 2014-08-09] (NVIDIA Corporation)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1229528 2013-12-06] (Secunia)
S2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [662232 2013-12-06] (Secunia)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R3 a2acc; C:\PROGRAM FILES\EMSISOFT INTERNET SECURITY\a2accx86.sys [58200 2014-05-12] (Emsisoft GmbH)
R1 A2DDA; C:\Program Files\Emsisoft Internet Security\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH)
R1 a2injectiondriver; C:\Program Files\Emsisoft Internet Security\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH)
R1 a2util; C:\Program Files\Emsisoft Internet Security\a2util32.sys [18552 2014-05-12] (Emsisoft GmbH)
R1 ccSet_NST; C:\Windows\system32\drivers\NST\7DE07080.017\ccSetx86.sys [127064 2013-09-27] (Symantec Corporation)
R3 cleanhlp; C:\Program Files\Emsisoft Internet Security\cleanhlp32.sys [50200 2013-12-04] (Emsisoft GmbH)
R1 EfwTdiFlt; C:\Program Files\Emsisoft Internet Security\fwtdi32.sys [35512 2014-10-06] (Emsisoft)
R3 fwndis; C:\Windows\System32\DRIVERS\fwndis32.sys [33312 2014-10-06] ()
R3 LUsbFilt; C:\Windows\System32\Drivers\LUsbFilt.Sys [28560 2009-06-17] (Logitech, Inc.)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-10-01] (Malwarebytes Corporation)
S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-10-01] (Malwarebytes Corporation)
R3 NvStreamKms; C:\Program Files\NVIDIA Corporation\NvStreamSrv\NvStreamKms.sys [20424 2014-08-09] (NVIDIA Corporation)
R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad32v.sys [34080 2014-03-31] (NVIDIA Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_x86.sys [16024 2013-12-06] (Secunia)
U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation)
S3 catchme; \??\C:\Users\ROLLOS~1\AppData\Local\Temp\catchme.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-14 21:18 - 2014-10-14 21:18 - 00000633 _____ () C:\Users\Rollostoimetz\Desktop\JRT.txt
2014-10-14 20:45 - 2014-10-14 20:52 - 00000000 ____D () C:\AdwCleaner
2014-10-14 20:43 - 2014-10-14 20:43 - 01976320 _____ () C:\Users\Rollostoimetz\Desktop\AdwCleaner_4.000.exe
2014-10-14 20:43 - 2014-10-14 20:43 - 01705698 _____ (Thisisu) C:\Users\Rollostoimetz\Desktop\JRT.exe
2014-10-14 20:06 - 2014-10-14 20:06 - 00000000 ____D () C:\ProgramData\Emsisoft
2014-10-14 18:51 - 2014-10-14 18:51 - 00001088 _____ () C:\Users\Public\Desktop\Emsisoft Internet Security.lnk
2014-10-14 18:51 - 2014-10-14 18:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Emsisoft Internet Security
2014-10-14 18:50 - 2014-10-06 18:43 - 00033312 _____ () C:\Windows\system32\Drivers\fwndis32.sys
2014-10-14 18:49 - 2014-10-14 21:01 - 00000000 ____D () C:\Program Files\Emsisoft Internet Security
2014-10-14 18:43 - 2014-10-14 18:43 - 05582915 _____ (Swearware) C:\Users\Rollostoimetz\Desktop\combofix.exe
2014-10-14 18:35 - 2014-10-14 18:43 - 163407496 _____ (Emsisoft GmbH ) C:\Users\Rollostoimetz\Desktop\EmsisoftInternetSecuritySetup.exe
2014-10-14 18:33 - 2014-10-14 18:33 - 00000015 _____ () C:\Users\Rollostoimetz\Documents\emsi.txt
2014-10-13 21:15 - 2014-10-13 21:15 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-10-13 19:46 - 2014-10-13 19:46 - 00012835 _____ () C:\ComboFix.txt
2014-10-13 19:19 - 2014-10-13 19:46 - 00000000 ____D () C:\Qoobox
2014-10-13 19:19 - 2011-06-26 08:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-10-13 19:19 - 2010-11-07 19:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-10-13 19:19 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-10-13 19:19 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-10-13 19:19 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-10-13 19:19 - 2000-08-31 02:00 - 00098816 _____ () C:\Windows\sed.exe
2014-10-13 19:19 - 2000-08-31 02:00 - 00080412 _____ () C:\Windows\grep.exe
2014-10-13 19:19 - 2000-08-31 02:00 - 00068096 _____ () C:\Windows\zip.exe
2014-10-12 15:23 - 2014-10-12 15:25 - 00022721 _____ () C:\Users\Rollostoimetz\Desktop\Addition.txt
2014-10-12 15:21 - 2014-10-14 21:19 - 00010935 _____ () C:\Users\Rollostoimetz\Desktop\FRST.txt
2014-10-12 15:21 - 2014-10-14 21:19 - 00000000 ____D () C:\FRST
2014-10-12 15:20 - 2014-10-12 16:35 - 01101824 _____ (Farbar) C:\Users\Rollostoimetz\Desktop\FRST.exe
2014-10-12 15:16 - 2014-10-12 15:16 - 00000462 _____ () C:\Users\Rollostoimetz\Desktop\defogger_disable.log
2014-10-12 15:16 - 2014-10-12 15:16 - 00000000 _____ () C:\Users\Rollostoimetz\defogger_reenable
2014-10-12 15:15 - 2014-10-12 15:15 - 00380416 _____ () C:\Users\Rollostoimetz\Desktop\Gmer-19357.exe
2014-10-12 15:14 - 2014-10-12 15:14 - 00050477 _____ () C:\Users\Rollostoimetz\Desktop\Defogger.exe
2014-10-09 21:04 - 2014-10-09 21:07 - 00000000 ____D () C:\Users\Rollostoimetz\AppData\Roaming\Media Player Classic
2014-10-01 17:49 - 2014-09-25 03:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-09-24 20:35 - 2014-09-24 20:35 - 00000000 ____H () C:\Windows\system32\Drivers\Msft_User_WpdMtpDr_01_09_00.Wdf
2014-09-23 20:00 - 2014-09-09 23:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-21 17:37 - 2014-09-21 17:37 - 00000065 _____ () C:\Users\Rollostoimetz\Documents\gawenda.txt
2014-09-19 20:13 - 2014-09-25 18:37 - 00000000 ____D () C:\Program Files\Mozilla Firefox
2014-09-18 21:54 - 2014-09-18 21:54 - 00001309 _____ () C:\Users\Public\Desktop\GeForce Experience.lnk
2014-09-18 21:52 - 2010-05-26 11:41 - 01998168 _____ (Microsoft Corporation) C:\Windows\system32\D3DX9_43.dll
2014-09-18 21:52 - 2010-05-26 11:41 - 00470880 _____ (Microsoft Corporation) C:\Windows\system32\d3dx10_43.dll
2014-09-18 21:52 - 2010-05-26 11:41 - 00248672 _____ (Microsoft Corporation) C:\Windows\system32\d3dx11_43.dll
2014-09-18 21:48 - 2014-09-18 21:55 - 00000000 ____D () C:\Users\Rollostoimetz\AppData\Local\NVIDIA Corporation
2014-09-18 21:48 - 2014-09-18 21:55 - 00000000 ____D () C:\Users\Rollostoimetz\AppData\Local\NVIDIA
2014-09-18 21:48 - 2014-09-18 21:48 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NVIDIA Corporation
2014-09-18 21:48 - 2014-08-09 02:28 - 01291280 _____ (NVIDIA Corporation) C:\Windows\system32\nvspbridge.dll
2014-09-18 21:48 - 2014-08-09 02:28 - 01126480 _____ (NVIDIA Corporation) C:\Windows\system32\nvspcap.dll
2014-09-18 21:47 - 2014-03-31 18:42 - 00034760 _____ (NVIDIA Corporation) C:\Windows\system32\nvaudcap32v.dll
2014-09-18 21:47 - 2014-03-31 18:42 - 00034080 _____ (NVIDIA Corporation) C:\Windows\system32\Drivers\nvvad32v.sys
2014-09-18 21:42 - 2014-09-18 21:44 - 29849176 _____ (NVIDIA Corporation) C:\Users\Rollostoimetz\Downloads\GeForce_Experience_v2.1.1.1.exe
2014-09-14 09:07 - 2014-09-14 09:07 - 07611199 _____ (XMedia Recode ) C:\Users\Rollostoimetz\Downloads\XMediaRecode3195_setup.exe
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2014-10-14 21:04 - 2009-07-14 06:34 - 00028720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-14 21:04 - 2009-07-14 06:34 - 00028720 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-14 20:59 - 2014-05-27 07:44 - 00001112 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-14 20:59 - 2014-05-27 07:44 - 00001108 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-14 20:58 - 2014-06-23 23:30 - 00114904 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-14 20:55 - 2009-07-14 06:39 - 00057183 _____ () C:\Windows\setupact.log
2014-10-14 20:54 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-14 20:52 - 2014-05-29 23:47 - 01937042 _____ () C:\Windows\WindowsUpdate.log
2014-10-14 20:37 - 2014-09-10 19:46 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-14 20:31 - 2014-05-28 19:04 - 00001152 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1442112818-2063436954-1665047480-1001UA.job
2014-10-14 20:12 - 2014-05-25 23:20 - 00000000 ____D () C:\ProgramData\Norton
2014-10-14 20:12 - 2010-11-20 23:48 - 03202290 _____ () C:\Windows\PFRO.log
2014-10-13 21:15 - 2014-06-23 23:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware
2014-10-13 21:15 - 2014-06-23 23:29 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware
2014-10-13 19:42 - 2009-07-14 04:04 - 00000215 _____ () C:\Windows\system.ini
2014-10-13 19:18 - 2014-06-07 23:09 - 00000000 ____D () C:\Windows\erdnt
2014-10-12 16:32 - 2014-07-10 18:51 - 00000000 ____D () C:\Users\Rollostoimetz\AppData\Local\CrashDumps
2014-10-12 15:29 - 2014-05-28 19:04 - 00001100 _____ () C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1442112818-2063436954-1665047480-1001Core.job
2014-10-12 15:16 - 2014-05-25 23:00 - 00000000 ____D () C:\Users\Rollostoimetz
2014-10-12 14:49 - 2014-05-26 13:37 - 00007593 _____ () C:\Users\Rollostoimetz\AppData\Local\Resmon.ResmonCfg
2014-10-09 21:46 - 2014-08-09 10:35 - 00000851 _____ () C:\DelFix.txt
2014-10-01 11:11 - 2014-06-23 23:29 - 00075480 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-10-01 11:11 - 2014-06-23 23:29 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys
2014-10-01 11:11 - 2014-06-23 23:29 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-09-28 10:19 - 2014-05-26 13:55 - 00000000 ____D () C:\Users\Rollostoimetz\Desktop\Microsoft Office
2014-09-27 14:44 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache
2014-09-26 17:20 - 2010-11-20 23:01 - 01618320 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-09-26 17:09 - 2009-07-14 06:53 - 00032640 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-09-26 13:58 - 2014-05-26 08:34 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service
2014-09-25 18:41 - 2014-06-12 19:19 - 00004030 _____ () C:\Windows\SecuniaPackage.log
2014-09-25 18:38 - 2014-05-26 08:34 - 00001045 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
2014-09-25 18:38 - 2014-05-26 08:34 - 00001033 _____ () C:\Users\Public\Desktop\Mozilla Firefox.lnk
2014-09-25 18:12 - 2014-07-21 21:21 - 00000000 ____D () C:\Windows\system32\Drivers\NST
2014-09-25 18:11 - 2014-07-21 21:21 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Identity Safe
2014-09-23 21:47 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE
2014-09-20 10:03 - 2014-05-26 09:02 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader XI.lnk
2014-09-18 21:55 - 2014-05-25 23:28 - 00000000 ____D () C:\ProgramData\NVIDIA Corporation
2014-09-18 21:53 - 2014-05-25 23:29 - 00000000 ____D () C:\ProgramData\NVIDIA
2014-09-18 21:48 - 2014-05-25 23:28 - 00000000 ____D () C:\Program Files\NVIDIA Corporation
Some content of TEMP:
====================
C:\Users\Rollostoimetz\AppData\Local\Temp\Quarantine.exe
C:\Users\Rollostoimetz\AppData\Local\Temp\sqlite3.dll
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\system32\winlogon.exe => File is digitally signed
C:\Windows\system32\wininit.exe => File is digitally signed
C:\Windows\system32\svchost.exe => File is digitally signed
C:\Windows\system32\services.exe => File is digitally signed
C:\Windows\system32\User32.dll => File is digitally signed
C:\Windows\system32\userinit.exe => File is digitally signed
C:\Windows\system32\rpcss.dll => File is digitally signed
C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2014-10-07 19:15
==================== End Of Log ============================
Geändert von Fellefant (14.10.2014 um 20:27 Uhr) |
| Themen zu Win7 wird immer langsamer und Norton wird ab und an doppelt autogestartet |
| adware, cpu, email, excel, failed, fehlercode 0x5, fehlercode 28, fehlercode windows, firefox, flash player, home, homepage, msil/solimba.n, programm, registry, scan, security, svchost.exe, symantec, traces, windows, windows xp |