![]() |
|
Log-Analyse und Auswertung: Browser total langsam hängt bei manchen seiten.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Browser total langsam hängt bei manchen seiten. Hallo also folgendes problem hab mir vor paar tagen nen trojaner eingefangen den ich aber (glaub ich) direkt vernichetet habe malewarebytes spybot avira etc durch gejagt und finde jetzt auch keine infiziereten dateien mehr. jetzt hängt sich mein firefox allerdings manchma komplett auf wenn ich ne seite laden will oder er brauch ewig die elemte zu laden. ich denke das ich vieleicht irgend nen java mist gelöscht hab un der deswegen zicken macht. will aber sicher sein das ich kein virus oder sowas hab deswegen wärs nett wenn sich jemand meine log files anschauen könnte damit ich entscheiden kann ob ich neu formatiere oder nich. danke schon ma hier meine log files: Logfile of random's system information tool 1.06 (written by random/random) Run by *** at 2010-04-22 10:43:16 Microsoft Windows XP Professional Service Pack 1 System drive C: has 10 GB (65%) free of 15 GB Total RAM: 1023 MB (41% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 10:43:41, on 22.04.2010 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe D:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe D:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\Explorer.EXE C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Programme\Trend Micro\HijackThis\HijackThis.exe E:\RSIT.exe C:\Programme\Trend Micro\HijackThis\ulti.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = ht*p://search.orbitdownloader.com/ O2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - d:\Programme\Orbitdownloader\orbitcth.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - d:\Programme\Orbitdownloader\GrabPro.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: &Download by Orbit - res://d:\Programme\Orbitdownloader\orbitmxt.dll/201 O8 - Extra context menu item: &Grab video by Orbit - res://d:\Programme\Orbitdownloader\orbitmxt.dll/204 O8 - Extra context menu item: Do&wnload selected by Orbit - res://d:\Programme\Orbitdownloader\orbitmxt.dll/203 O8 - Extra context menu item: Down&load all by Orbit - res://d:\Programme\Orbitdownloader\orbitmxt.dll/202 O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - d:\Programme\PartyGaming\PartyPoker\RunApp.exe O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - d:\Programme\PartyGaming\PartyPoker\RunApp.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - d:\Programme\ICQ6.5\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - d:\Programme\ICQ6.5\ICQ.exe O9 - Extra button: Cool Hand Poker - {00000000-0000-0000-0000-000000000000} - C:\WINDOWS\System32\shdocvw.dll (HKCU) O9 - Extra button: CarbonPoker - {e4e8c758-34b4-44bb-8ef9-1f0786e81d2d} - C:\Dokumente und Einstellungen\ulti\Startmenü\Programme\CarbonPoker\CarbonPoker.lnk (HKCU) O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - hxxp://utilities.pcpitstop.com/da2/PCPitStop2.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - (no file) O23 - Service: Avira AntiVir Personal - Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - D:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - D:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Programme\WinPcap\rpcapd.exe -- End of file - 4858 bytes ======Scheduled tasks folder====== C:\WINDOWS\tasks\AppleSoftwareUpdate.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{000123B4-9B42-4900-B3F7-F4B073EFC214}] Octh Class - d:\Programme\Orbitdownloader\orbitcth.dll [2009-02-27 134344] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{18DF081C-E8AD-4283-A596-FA578C2EBDC3}] Adobe PDF Link Helper - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2009-02-27 75128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{53707962-6F74-2D53-2644-206D7942484F}] Spybot-S&D IE Protection - D:\PROGRA~1\SPYBOT~1\SDHelper.dll [2009-01-26 1879896] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] Java(tm) Plug-In 2 SSV Helper - C:\Programme\Java\jre6\bin\jp2ssv.dll [2009-03-10 35840] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] JQSIEStartDetectorImpl Class - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-10 73728] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {8E718888-423F-11D2-876E-00A0C9082467} - &Radio - C:\WINDOWS\System32\msdxm.ocx [2002-08-29 845852] {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - Grab Pro - d:\Programme\Orbitdownloader\GrabPro.dll [2009-02-27 646264] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"=C:\WINDOWS\System32\NvCpl.dll [2006-11-17 7700480] "nwiz"=nwiz.exe /install [] "avgnt"=C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497] "NvMediaCenter"=C:\WINDOWS\System32\NvMcTray.dll [2006-11-17 86016] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Reader Speed Launcher] D:\Programme\Adobe\Reader 9.0\Reader\Reader_sl.exe [2009-02-27 35696] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AdobeUpdater6] C:\Programme\Gemeinsame Dateien\Adobe\Updater6\Adobe_Updater.exe [2009-01-08 2521464] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AlcoholAutomount] d:\Programme\Alcohol Soft\Alcohol 52\axcmd.exe [2009-04-24 203416] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\C-Media Mixer] Mixer.exe /startup [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe [2002-08-29 13312] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ICQ] d:\Programme\ICQ6.5\ICQ.exe [2009-03-01 172792] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\KernelFaultCheck] C:\WINDOWS\system32\dumprep 0 -k [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] C:\Programme\Messenger\msmsgs.exe [2002-08-20 1511453] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck] C:\WINDOWS\system32\NeroCheck.exe [2003-07-13 155648] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] D:\Programme\QuickTime\qttask.exe [2006-09-01 282624] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RegistryMechanic] [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] C:\Programme\Skype\Phone\Skype.exe [2009-09-02 25623336] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SpybotSD TeaTimer] d:\Programme\Spybot - Search & Destroy\TeaTimer.exe [2009-03-05 2260480] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Steam] [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SunJavaUpdateSched] C:\Programme\Java\jre6\bin\jusched.exe [2009-03-10 148888] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Trickler] [] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\uTorrent] d:\Programme\uTorrent\uTorrent.exe [2009-06-29 288048] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\WinampAgent] d:\Programme\Winamp\winampa.exe [2006-11-21 35328] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^WinZip Quick Pick.lnk] D:\PROGRA~1\WinZip\WZQKPICK.EXE [2003-02-11 106560] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Dokumente und Einstellungen^****^Startmenü^Programme^Autostart^Adobe Gamma.lnk] C:\PROGRA~1\GEMEIN~1\Adobe\CALIBR~1\ADOBEG~1.EXE [2005-03-16 113664] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services] "SharedAccess"=3 "Messenger"=2 "BITS"=3 "PnkBstrA"=2 "npggsvc"=3 "JavaQuickStarterService"=2 "StarWindServiceAE"=2 "Adobe LM Service"=3 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\nm.sys] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\UploadMgr] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 "NoActiveDesktop"=0 [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "d:\Programme\Orbitdownloader\orbitdm.exe"="d:\Programme\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit" "d:\Programme\Orbitdownloader\orbitnet.exe"="d:\Programme\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit" "e:\Programme\Gameforge4D\AirRivals_DE\Launcher.atm"="e:\Programme\Gameforge4D\AirRivals_DE\Launcher.atm:Enabled:GameExe2" "e:\Programme\Gameforge4D\AirRivals_DE\Res-Voip\SCVoIP.exe"="e:\Programme\Gameforge4D\AirRivals_DE\Res-Voip\SCVoIP.exe:Enabled:GameVoIP" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] ======List of files/folders created in the last 1 months====== 2010-04-22 10:43:15 ----D---- C:\rsit 2010-04-22 10:04:50 ----D---- C:\Programme\CCleaner 2010-04-19 15:45:42 ----D---- C:\Programme\Trend Micro 2010-04-19 12:34:27 ----D---- C:\Programme\TeaTimer (Spybot - Search & Destroy) 2010-04-19 12:34:27 ----D---- C:\Programme\Misc. Support Library (Spybot - Search & Destroy) 2010-04-19 12:34:26 ----D---- C:\Programme\SDHelper (Spybot - Search & Destroy) 2010-04-19 12:32:14 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy 2010-04-18 01:36:11 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SecTaskMan 2010-04-18 01:36:08 ----D---- C:\Programme\Security Task Manager 2010-04-17 00:08:41 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Malwarebytes 2010-04-17 00:08:29 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes 2010-03-23 16:13:45 ----A---- C:\WINDOWS\System32\d3dx10_40.dll 2010-03-23 16:13:45 ----A---- C:\WINDOWS\System32\D3DCompiler_40.dll 2010-03-23 16:13:43 ----A---- C:\WINDOWS\System32\D3DX9_40.dll 2010-03-23 16:13:29 ----A---- C:\WINDOWS\System32\xinput1_3.dll 2010-03-23 16:12:16 ----A---- C:\WINDOWS\System32\wstdecod.dll 2010-03-23 16:12:16 ----A---- C:\WINDOWS\System32\psisdecd.dll 2010-03-23 16:12:15 ----A---- C:\WINDOWS\System32\msyuv.dll 2010-03-23 16:12:15 ----A---- C:\WINDOWS\System32\msvidctl.dll 2010-03-23 16:12:13 ----A---- C:\WINDOWS\System32\qdvd.dll 2010-03-23 16:12:13 ----A---- C:\WINDOWS\System32\qdv.dll 2010-03-23 16:12:13 ----A---- C:\WINDOWS\System32\dmusic.dll 2010-03-23 16:12:13 ----A---- C:\WINDOWS\System32\dmime.dll 2010-03-23 16:12:12 ----A---- C:\WINDOWS\System32\dxdiagn.dll 2010-03-23 16:12:12 ----A---- C:\WINDOWS\System32\dxdiag.exe 2010-03-23 16:12:12 ----A---- C:\WINDOWS\System32\d3d9.dll 2010-03-23 16:12:12 ----A---- C:\WINDOWS\System32\d3d8.dll 2010-03-23 16:12:09 ----A---- C:\WINDOWS\System32\dpwsockx.dll 2010-03-23 16:12:09 ----A---- C:\WINDOWS\System32\dplayx.dll ======List of files/folders modified in the last 1 months====== 2010-04-22 10:37:33 ----D---- C:\WINDOWS\Temp 2010-04-22 10:06:15 ----D---- C:\WINDOWS\Minidump 2010-04-22 10:06:15 ----D---- C:\WINDOWS\Debug 2010-04-22 10:06:15 ----AD---- C:\WINDOWS 2010-04-22 10:04:50 ----RD---- C:\Programme 2010-04-22 09:59:17 ----D---- C:\WINDOWS\System32\CatRoot2 2010-04-21 23:21:31 ----SH---- C:\boot.ini 2010-04-21 23:21:31 ----A---- C:\WINDOWS\win.ini 2010-04-21 23:21:31 ----A---- C:\WINDOWS\system.ini 2010-04-21 15:00:28 ----D---- C:\WINDOWS\system32 2010-04-19 15:56:30 ----SD---- C:\WINDOWS\Downloaded Program Files 2010-04-19 12:30:54 ----D---- C:\Dokumente und Einstellungen 2010-04-18 01:30:53 ----D---- C:\WINDOWS\System32\drivers 2010-04-18 01:30:53 ----D---- C:\WINDOWS\RegisteredPackages 2010-04-17 02:17:11 ----RSHDC---- C:\WINDOWS\System32\dllcache 2010-04-17 00:23:45 ----SHD---- C:\WINDOWS\Installer 2010-04-17 00:23:45 ----HD---- C:\Programme\InstallShield Installation Information 2010-04-17 00:16:44 ----D---- C:\WINDOWS\twain_32 2010-03-28 12:07:45 ----AC---- C:\WINDOWS\System32\PerfStringBackup.INI 2010-03-25 01:22:41 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Orbit 2010-03-23 16:13:54 ----D---- C:\WINDOWS\System32\DirectX 2010-03-23 16:13:52 ----HD---- C:\WINDOWS\inf 2010-03-23 16:13:24 ----RSD---- C:\WINDOWS\assembly 2010-03-23 16:12:42 ----D---- C:\WINDOWS\System32\CatRoot 2010-03-23 16:12:42 ----D---- C:\WINDOWS\Help ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 avgntdd;avgntdd; C:\WINDOWS\SYSTEM32\DRIVERS\avgntdd.sys [2009-11-23 45400] R1 avipbb;avipbb; C:\WINDOWS\System32\DRIVERS\avipbb.sys [2009-11-23 75096] R1 ElbyCDIO;ElbyCDIO Driver; C:\WINDOWS\System32\Drivers\ElbyCDIO.sys [2009-02-17 24232] R1 ssmdrv;ssmdrv; C:\WINDOWS\System32\DRIVERS\ssmdrv.sys [2007-11-08 21248] R2 atksgt;atksgt; C:\WINDOWS\System32\DRIVERS\atksgt.sys [2010-03-23 281760] R2 lirsgt;lirsgt; C:\WINDOWS\System32\DRIVERS\lirsgt.sys [2010-03-23 25888] R2 nvcap;nVidia WDM Video Capture (universal); C:\WINDOWS\System32\DRIVERS\nvcap.sys [2005-04-01 123614] R2 nvTUNEP;nVidia WDM TVTuner; C:\WINDOWS\System32\DRIVERS\nvtunep.sys [2005-04-01 21906] R2 nvtvSND;nVidia WDM TVAudio Crossbar; C:\WINDOWS\System32\DRIVERS\nvtvsnd.sys [2005-04-01 25442] R2 NVXBAR;nVidia WDM A/V Crossbar; C:\WINDOWS\System32\DRIVERS\NVxbar.sys [2005-04-01 13696] R3 cmpci;C-Media PCI Audio Driver (WDM); C:\WINDOWS\system32\drivers\cmaudio.sys [2002-11-18 377358] R3 DumaNT;DumaNT; C:\WINDOWS\System32\drivers\DumaNT.sys [2006-06-01 334976] R3 ms_mpu401;Microsoft MPU-401 MIDI UART-Treiber; C:\WINDOWS\system32\drivers\msmpu401.sys [2001-08-17 2944] R3 nv;nv; C:\WINDOWS\System32\DRIVERS\nv4_mini.sys [2006-11-17 3994688] R3 rtl8139;NT-Treiber für Realtek RTL8139(A/B/C)-basierten PCI-Fast Ethernet-Adapter; C:\WINDOWS\System32\DRIVERS\RTL8139.SYS [2001-08-17 23070] R3 usbehci;Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller; C:\WINDOWS\System32\DRIVERS\usbehci.sys [2002-08-29 19328] R3 usbhub;USB2-aktivierter Hub; C:\WINDOWS\System32\DRIVERS\usbhub.sys [2002-08-29 51968] R3 usbuhci;Miniporttreiber für universellen Microsoft USB-Hostcontroller; C:\WINDOWS\System32\DRIVERS\usbuhci.sys [2002-08-29 19328] S3 a2w67ee6;a2w67ee6; C:\WINDOWS\System32\drivers\a2w67ee6.sys [] S3 CCDECODE;Closed Caption Decoder; C:\WINDOWS\System32\DRIVERS\CCDECODE.sys [2004-07-09 16384] S3 GarenaPEngine;GarenaPEngine; \??\C:\DOKUME~1\***\LOKALE~1\Temp\EZW1D.tmp [] S3 HidUsb;Microsoft HID Class-Treiber; C:\WINDOWS\System32\DRIVERS\hidusb.sys [2001-08-17 9600] S3 mouhid;Maus-HID-Treiber; C:\WINDOWS\System32\DRIVERS\mouhid.sys [2001-08-18 12288] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink Converter; C:\WINDOWS\system32\drivers\MSTEE.sys [2002-12-12 5504] S3 NABTSFEC;NABTS/FEC VBI Codec; C:\WINDOWS\System32\DRIVERS\NABTSFEC.sys [2004-07-09 83968] S3 NdisIP;Microsoft TV/Video Connection; C:\WINDOWS\System32\DRIVERS\NdisIP.sys [2004-07-09 10112] S3 nm;Netzwerkmonitortreiber; C:\WINDOWS\System32\DRIVERS\NMnt.sys [2002-08-29 38272] S3 NPF;NetGroup Packet Filter Driver; C:\WINDOWS\system32\drivers\npf.sys [2007-11-06 34064] S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\System32\DRIVERS\SLIP.sys [2004-07-09 10880] S3 streamip;BDA IPSink; C:\WINDOWS\System32\DRIVERS\StreamIP.sys [2004-07-09 14976] S3 usbprint;Microsoft USB-Druckerklasse; C:\WINDOWS\System32\DRIVERS\usbprint.sys [2002-08-29 24960] S3 USBSTOR;USB-Massenspeichertreiber; C:\WINDOWS\System32\DRIVERS\USBSTOR.SYS [2002-08-29 21760] S3 WSTCODEC;World Standard Teletext Codec; C:\WINDOWS\System32\DRIVERS\WSTCODEC.SYS [2004-07-09 18688] S4 IntelIde;IntelIde; C:\WINDOWS\System32\drivers\IntelIde.sys [] ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 AntiVirScheduler;Avira AntiVir Personal - Free Antivirus Planer; D:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe [2008-10-15 68865] R2 AntiVirService;Avira AntiVir Personal - Free Antivirus Guard; D:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe [2008-10-15 151297] R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\System32\nvsvc32.exe [2006-11-17 159811] R2 UMWdf;Windows User Mode Driver Framework; C:\WINDOWS\System32\wdfmgr.exe [2005-01-28 38912] S3 aspnet_state;ASP.NET State Service; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2005-09-23 29896] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2005-09-23 66240] S3 ose;Office Source Engine; C:\Programme\Gemeinsame Dateien\Microsoft Shared\Source Engine\OSE.EXE [2003-07-28 89136] S3 rpcapd;Remote Packet Capture Protocol v.0 (experimental); C:\Programme\WinPcap\rpcapd.exe [2007-11-06 92792] S4 Adobe LM Service;Adobe LM Service; C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-07-23 72704] S4 JavaQuickStarterService;Java Quick Starter; C:\Programme\Java\jre6\bin\jqs.exe [2009-03-10 152984] S4 npggsvc;nProtect GameGuard Service; C:\WINDOWS\System32\GameMon.des [2009-02-17 2736890] S4 PCPitstop Scheduling;PCPitstop Scheduling; d:\Programme\PCPitstop\PCPitstopScheduleService.exe [2009-06-26 85504] S4 PnkBstrA;PnkBstrA; C:\WINDOWS\System32\PnkBstrA.exe [2009-09-20 75064] S4 StarWindServiceAE;StarWind AE Service; d:\Programme\Alcohol Soft\Alcohol 52\StarWind\StarWindServiceAE.exe [2007-05-28 275968] -----------------EOF----------------- info.txt logfile of random's system information tool 1.06 2010-04-22 10:43:42 ======Uninstall list====== -->d:\Programme\DivX\DivXConverterUninstall.exe /CONVERTER -->rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf AC3Filter (remove only)-->d:\Programme\AC3Filter\uninstall.exe Adobe AIR-->c:\Programme\Gemeinsame Dateien\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe -arp:uninstall Adobe AIR-->MsiExec.exe /I{A2BCA9F1-566C-4805-97D1-7FDC93386723} Adobe Bridge 1.0-->MsiExec.exe /I{B74D4E10-6884-0000-0000-000000000101} Adobe Common File Installer-->MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5101} Adobe Flash Player 10 ActiveX-->C:\WINDOWS\System32\Macromed\Flash\uninstall_activeX.exe Adobe Flash Player 10 Plugin-->C:\WINDOWS\System32\Macromed\Flash\uninstall_plugin.exe Adobe Help Center 1.0-->MsiExec.exe /I{E9787678-119F-4D52-B551-6739B2B22101} Adobe Photoshop CS2-->msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D} Adobe Reader 9.1.3 - Deutsch-->MsiExec.exe /I{AC76BA86-7AD7-1031-7B44-A91000000001} Adobe Shockwave Player 11.5-->"C:\WINDOWS\System32\Adobe\Shockwave 11\uninstaller.exe" Adobe Stock Photos 1.0-->MsiExec.exe /I{786C5747-0C40-4930-9AFE-113BCE553101} Ahead Nero Burning ROM-->D:\Programme\nero\uninstall\UNNERO.exe /UNINSTALL Apple Software Update-->MsiExec.exe /I{55FA89BD-21D3-42F7-9249-C94C0094A83C} AutoHotkey 1.0.48.03-->d:\Programme\AutoHotkey\uninst.exe Avira AntiVir Personal - Free Antivirus-->C:\Programme\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE Canon i850-->C:\WINDOWS\System32\CNMCP4b.exe "-PRINTERNAMECanon i850" "-HELPERDLLC:\BJPrinter\CNMWINDOWS\Canon i850 Installer\Inst2\cnmis.dll" "-RCDLLC:\BJPrinter\CNMWINDOWS\Canon i850 Installer\Inst2\cnmi0407.dll" CCleaner-->"C:\Programme\CCleaner\uninst.exe" ClearProg 1.4.2 Beta 13-->d:\Programme\ClearProg\Uninstall.exe CloneDVD2-->"d:\Programme\Elaborate Bytes\CloneDVD2\CloneDVD2-uninst.exe" /D="d:\Programme\Elaborate Bytes\CloneDVD2" Combined Community Codec Pack 2008-09-21 16:18-->"d:\Programme\Combined Community Codec Pack\unins000.exe" DivX Codec-->d:\Programme\DivX\DivXCodecUninstall.exe /CODEC DivX Converter-->d:\Programme\DivX\DivXConverterUninstall.exe /CONVERTER DivX Player-->C:\WINDOWS\unvise32.exe C:\Programme\DivX\DivX Player\uninstal.log DivX Player-->d:\Programme\DivX\DivXPlayerUninstall.exe /PLAYER DivX Plus DirectShow Filters-->d:\Programme\DivX\DivXDSFiltersUninstall.exe /DSFILTERS DivX Web Player-->d:\Programme\DivX\DivXWebPlayerUninstall.exe /PLUGIN DotAzilla-->e:\Programme\DotAzilla\Uninstall.exe eMusic - 50 Free MP3 offer-->"d:\Programme\Winamp\eMusic\Uninst-eMusic-promotion.exe" EVEREST Home Edition v2.20-->"d:\Programme\Lavalys\EVEREST Home Edition\unins000.exe" Full Tilt Poker-->"C:\Programme\InstallShield Installation Information\{D4C9692E-4EFA-4DA0-8B7F-9439466D9E31}\setup.exe" -runfromtemp -l0x0009 -removeonly Game Booster-->"C:\Programme\IObit\Game Booster\unins000.exe" Garena-->C:\Programme\InstallShield Installation Information\{89C89156-A70F-4C6D-9CAE-2EA71F1396FE}\setup.exe -runfromtemp -l0x0009 -removeonly High Pulse-->MsiExec.exe /X{AC05AC51-5E65-448C-B555-CF956768B76C} HijackThis 2.0.2-->"C:\Programme\Trend Micro\HijackThis\HijackThis.exe" /uninstall ICQ6.5-->"C:\Programme\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe" -runfromtemp -l0x0009 -removeonly IrfanView (remove only)-->d:\Programme\IrfanView\iv_uninstall.exe iView-->C:\WINDOWS\uninst.exe -f"d:\Program Files\iView\DeIsL1.isu" -c"d:\Program Files\iView\_ISREG32.DLL" Java 2 Runtime Environment Standard Edition 1.3.1_07-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{0E65518E-EC48-11D6-88B8-0050DA21757E}\Setup.exe" -uninst Java(TM) 6 Update 12-->MsiExec.exe /X{26A24AE4-039D-4CA4-87B4-2F83216012FF} Malwarebytes' Anti-Malware-->"d:\Programme\Malwarebytes' Anti-Malware\unins000.exe" Microsoft .NET Framework 2.0-->C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\Microsoft .NET Framework 2.0\install.exe Microsoft Office Excel Viewer 2003-->MsiExec.exe /I{90840407-6000-11D3-8CFE-0150048383C9} Microsoft Visual C++ 2005 Redistributable-->MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022-->MsiExec.exe /X{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4} Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17-->MsiExec.exe /X{9A25302D-30C0-39D9-BD6F-21E6EC160475} Mozilla Firefox (3.6.3)-->D:\Programme\Mozilla Firefox\uninstall\helper.exe NVIDIA Drivers-->C:\WINDOWS\System32\nvudisp.exe UninstallGUI NVIDIA WDM Drivers-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{B023185F-F1EF-4F97-B0BD-AE6D802226D1}\Setup.exe" Orbit Downloader-->"d:\Programme\Orbitdownloader\unins000.exe" PartyPoker-->"d:\Programme\PartyGaming\PartyPoker\Uninstall.exe" "d:\Programme\PartyGaming\PartyPoker\install.log" PC Pitstop Driver Alert2 2.0.0.0-->"d:\Programme\PCPitstop\Driver Alert2\unins000.exe" PokerStars-->"d:\Programme\PokerStars\PokerStarsUninstall.exe" /u:PokerStars PunkBuster Services-->C:\WINDOWS\System32\pbsvc.exe -u QuickTime-->MsiExec.exe /I{F07B861C-72B9-40A4-8B1A-AAED4C06A7E8} Realtek AC'97 Audio-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{FB08F381-6533-4108-B7DD-039E11FBC27E}\setup.exe" REMOVE Registry Mechanic 6.0-->"d:\Programme\Registry Mechanic\unins000.exe" Security Task Manager 1.7h-->C:\Programme\Security Task Manager\Uninstal.exe "C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Security Task Manager" Skype™ 4.1-->MsiExec.exe /X{D103C4BA-F905-437A-8049-DB24763BBE36} Spybot - Search & Destroy 1.4-->"d:\Programme\Spybot - Search & Destroy\unins000.exe" Spybot - Search & Destroy-->"d:\Programme\Spybot - Search & Destroy\unins001.exe" Star Wars JK II Jedi Outcast-->RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{576E71DA-3000-48F6-9B21-B9A70D47DFCF}\Setup.exe" Taksi Desktop Video Recorder v0.765-->MsiExec.exe /I{7F9129B6-C438-4CCB-80CB-A97E9F3B6B8C} VC80CRTRedist - 8.0.50727.762-->MsiExec.exe /I{767CC44C-9BBC-438D-BAD3-FD4595DD148B} Ventrilo Client-->MsiExec.exe /I{789289CA-F73A-4A16-A331-54D498CE069F} VideoLAN VLC media player 0.8.6a-->d:\Programme\VideoLAN\VLC\uninstall.exe Warcraft III-->C:\Programme\Gemeinsame Dateien\Blizzard Entertainment\Warcraft III (2)\Uninstall.exe Winamp (remove only)-->"d:\Programme\Winamp\UninstWA.exe" Windows Installer 3.1 (KB893803)-->"C:\WINDOWS\$MSI31Uninstall_KB893803v2$\spuninst\spuninst.exe" Windows Media Format Runtime-->"C:\Programme\Windows Media Player\wmsetsdk.exe" /UninstallAll WinPcap 4.0.2-->C:\Programme\WinPcap\uninstall.exe WinRAR archiver-->d:\Programme\WinRAR\uninstall.exe WinZip-->"d:\Programme\WinZip\WINZIP32.EXE" /uninstall Xvid 1.2.1 final uninstall-->"d:\Programme\Xvid\unins000.exe" =====HijackThis Backups===== O16 - DPF: {F7EDBBEA-1AD2-4EBF-AA07-D453CC29EE65} (Flash Casino Helper Control) - https://plugins.valueactive.eu/flashax/iefax.cab [2010-04-19] O16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} (FlashXControl Object) - https://signin9.valueactive.eu/Register/Branding/olr3313/OCX/flashax.cab [2010-04-22] ======Hosts File====== 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com ======System event log====== Computer Name: ****** Event Code: 7036 Message: Dienst "Terminaldienste" befindet sich jetzt im Status "Ausgeführt". Record Number: 18409 Source Name: Service Control Manager Time Written: 20100307122504.000000+060 Event Type: Informationen User: Computer Name: ****** Event Code: 7035 Message: Der Steuerbefehl "starten" wurde erfolgreich an den Dienst "Terminaldienste" gesendet. Record Number: 18408 Source Name: Service Control Manager Time Written: 20100307122504.000000+060 Event Type: Informationen User: NT-AUTORITÄT\SYSTEM Computer Name: ****** Event Code: 26 Message: Anwendungspopup: : Machine Check: Regs Record Number: 18407 Source Name: Application Popup Time Written: 20100307122347.000000+060 Event Type: Informationen User: Computer Name: ***** Event Code: 26 Message: Anwendungspopup: : Machine Check: Record Number: 18406 Source Name: Application Popup Time Written: 20100307122347.000000+060 Event Type: Informationen User: Computer Name: ****** Event Code: 26 Message: Anwendungspopup: : Machine Check: Regs Record Number: 18405 Source Name: Application Popup Time Written: 20100307122347.000000+060 Event Type: Informationen User: =====Application event log===== Computer Name: ****** Event Code: 11728 Message: Produkt: Adobe Reader 9.1.2 - Deutsch -- Configuration completed successfully. Record Number: 378 Source Name: MsiInstaller Time Written: 20090621130815.000000+120 Event Type: Informationen User: ****** Computer Name: ****** Event Code: 1022 Message: Produkt: Adobe Reader 9.1.2 - Deutsch - Update "Adobe Reader 9.1.2 - CPSID_49166" wurde installiert. Record Number: 377 Source Name: MsiInstaller Time Written: 20090621130815.000000+120 Event Type: Informationen User: ******* Computer Name: ****** Event Code: 4096 Message: Der AntiVir Dienst wurde erfolgreich gestartet! Record Number: 376 Source Name: Avira AntiVir Time Written: 20090621125805.000000+120 Event Type: Informationen User: NT-AUTORITÄT\SYSTEM Computer Name: **** Event Code: 4096 Message: Der AntiVir Dienst wurde erfolgreich gestartet! Record Number: 375 Source Name: Avira AntiVir Time Written: 20090620161631.000000+120 Event Type: Informationen User: NT-AUTORITÄT\SYSTEM Computer Name: **** Event Code: 4096 Message: Der AntiVir Dienst wurde erfolgreich gestartet! Record Number: 374 Source Name: Avira AntiVir Time Written: 20090620112558.000000+120 Event Type: Informationen User: NT-AUTORITÄT\SYSTEM ======Environment variables====== "ComSpec"=%SystemRoot%\system32\cmd.exe "Path"=%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\Wbem;D:\Programme\QuickTime\QTSystem\;C:\Programme\Gemeinsame Dateien\Adobe\AGL "windir"=%SystemRoot% "OS"=Windows_NT "PROCESSOR_ARCHITECTURE"=x86 "PROCESSOR_LEVEL"=6 "PROCESSOR_IDENTIFIER"=x86 Family 6 Model 10 Stepping 0, AuthenticAMD "PROCESSOR_REVISION"=0a00 "NUMBER_OF_PROCESSORS"=1 "PATHEXT"=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH "TEMP"=%SystemRoot%\TEMP "TMP"=%SystemRoot%\TEMP "CLASSPATH"=.;D:\Programme\QuickTime\QTSystem\QTJava.zip "QTJAVA"=D:\Programme\QuickTime\QTSystem\QTJava.zip -----------------EOF----------------- ok hier hab ich noch nen male log Datenbank Version: 3999 Windows 5.1.2600 Service Pack 1 Internet Explorer 6.0.2800.1106 22.04.2010 10:11:56 mbam-log-2010-04-22 (10-11-56).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 113285 Laufzeit: 4 Minute(n), 40 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
Themen zu Browser total langsam hängt bei manchen seiten. |
antivir, antivirus, avira, bho, browser, converter, excel, firefox, flash player, hijack, hijackthis, hkus\s-1-5-18, home, hängt, install.exe, iobit, jusched.exe, langsam, log files, mp3, msiexec.exe, plug-in, problem, realtek, security, skype.exe, software, starten, system, trojaner, trojaner eingefangen, virus, vlc media player, windows, windows xp |