hallo schrauber,
Hier noch die zwei fehlen logs: Code:
Results of screen317's Security Check version 0.99.71
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 10 ``````````````Antivirus/Firewall Check:``````````````
AVG Anti-Virus Free Edition 2012
Antivirus up to date! `````````Anti-malware/Other Utilities Check:`````````
Spybot - Search & Destroy
Malwarebytes Anti-Malware Version 1.75.0.1300
Java 7 Update 25
Adobe Flash Player 10 Flash Player out of Date!
Adobe Flash Player 11.8.800.94
Adobe Reader 9
Adobe Reader XI
Mozilla Firefox (22.0) ````````Process Check: objlist.exe by Laurent````````
Spybot Teatimer.exe is disabled!
AVG avgwdsvc.exe
AVG avgtray.exe
AVG avgemc.exe `````````````````System Health check`````````````````
Total Fragmentation on Drive C: ````````````````````End of Log``````````````````````
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-07-2013 03 (ATTENTION: ====> FRST version is 6 days old and could be outdated)
Ran by user (administrator) on 05-08-2013 16:05:09
Running from D:\EiDaUk\52-Proj. Lernen - Informatik\Malware entfernen
Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe
(Apple Computer, Inc.) C:\Program Files (x86)\Bonjour\mDNSResponder.exe
(SafeNet Inc.) C:\Windows\system32\hasplms.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe
(Nero AG) C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
(Prolific Technology Inc.) C:\Windows\SysWOW64\IoctlSvc.exe
() C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe
(Microsoft Corporation) C:\Windows\System32\snmp.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
(Microsoft Corporation) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe
(AVG Secure Search) C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe
(X-Rite Inc.) C:\Program Files (x86)\X-Rite\Devices\Services\xrdd.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.153\GoogleCrashHandler64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe
(ACD Systems International Inc.) C:\Program Files (x86)\Common Files\ACD Systems\DE\DevDetect.exe
(ACD Systems) C:\Program Files (x86)\ACD Systems\ACDSee Pro\5.0\ACDSeeProInTouch2.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2012\avgtray.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Safer Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe
(Brother Industries, Ltd.) C:\Program Files (x86)\Browny02\BrYNSvc.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2012\avgnsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2012\avgrsa.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2012\avgcsrva.exe
(AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2012\avgcsrvx.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Source Engine\OSE.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [8312352 2009-10-28] (Realtek Semiconductor)
HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\nvtmru.exe [1012000 2013-05-16] (NVIDIA Corporation)
HKCU\...\Run: [Device Detector] - DevDetect.exe -autorun [x]
HKCU\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-02-04] (Google Inc.)
HKLM-x32\...\Run: [ACPW05DE] - C:\Program Files (x86)\ACD Systems\ACDSee Pro\5.0\ACDSeeProInTouch2.exe [822384 2011-11-17] (ACD Systems)
HKLM-x32\...\Run: [AVG_TRAY] - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe [2598520 2012-11-19] (AVG Technologies CZ, s.r.o.)
HKLM-x32\...\Run: [BrStsMon00] - C:\Program Files (x86)\Browny02\Brother\BrStMonW.exe [2621440 2010-06-10] (Brother Industries, Ltd.)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\XRGamma.lnk
ShortcutTarget: XRGamma.lnk -> C:\Program Files (x86)\X-Rite\i1Profiler\XRGamma.exe (LOGO Kommunikations- und Drucktechnik GmbH & Co. KG)
BootExecute: autocheck autochk * C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.ch/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
BHO: AVG Do Not Track - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO-x32: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files (x86)\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Handler: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
Handler-x32: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\cz04geis.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll ()
FF Plugin: @java.com/DTPlugin,version=10.5.0 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=10.5.0 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_94.dll ()
FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @real.com/nppl3260;version=16.0.0.282 - c:\program files (x86)\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlchromebrowserrecordext;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlhtml5videoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprndlpepperflashvideoshim;version=1.3.0 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF Plugin-x32: @real.com/nprpplugin;version=16.0.0.282 - c:\program files (x86)\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF Plugin-x32: @realnetworks.com/npdlplugin;version=1 - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Extension: No Name - C:\Users\user\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [{1E73965B-8B48-48be-9C8D-68B920ABC1C4}] C:\Program Files (x86)\AVG\AVG2012\Firefox4\
FF Extension: AVG Safe Search - C:\Program Files (x86)\AVG\AVG2012\Firefox4\
FF HKLM-x32\...\Firefox\Extensions: [{34712C68-7391-4c47-94F3-8F88D49AD632}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\
FF HKLM-x32\...\Firefox\Extensions: [{ABDE892B-13A8-4d1b-88E6-365A6E755758}] C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF Extension: RealDownloader - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext
FF HKLM-x32\...\Firefox\Extensions: [FFPDFArchitectConverter@pdfarchitect.com] C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
FF Extension: PDF Architect Converter For Firefox - C:\Program Files (x86)\PDF Architect\FFPDFArchitectExt
Chrome:
=======
CHR RestoreOnStartup: {"countryid_at_install":17224,"default_search_provider":{"enabled":true,"encodings":"UTF-8","icon_url":"hxxp://www.google.com/favicon.ico","id":"2","instant_url":"{google:baseURL}search?{google:RLZ}sourceid=chrome-instant&ie={inputEncoding}&q={searchTerms}","keyword":"google.com","name":"Google","prepopulate_id":"1","search_url":"{google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}sourceid=chrome&ie={inputEncoding}&q={searchTerms}","suggest_url":"{google:baseSuggestURL}search?client=chrome&hl={language}&q={searchTerms}"},"distribution":{"create_all_shortcuts":true,"do_not_launch_chrome":true,"import_history":false,"import_search_engine":true,"make_chrome_default":false,"show_welcome_page":true,"skip_first_run_ui":true,"verbose_logging":false},"download":{"directory_upgrade":true},"extensions":{"autoupdate":{"next_check":"12936254404717650"},"chrome_url_overrides":{"bookmarks":["chrome-extension://eemcgdkfndhakfknompkggombfjjjeno/main.html"]}},"ntp":{"pref_version":3,"shown_sections":1,"web_resource_cache_update":""},"profile":{"content_settings":{"pref_version":1},"exited_cleanly":true},"session":{"restore_on_startup":null,"urls_to_restore_on_startup":null}}
CHR HKLM-x32\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx
==================== Services (Whitelisted) =================
R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe [5174392 2012-11-02] (AVG Technologies CZ, s.r.o.)
R2 avgwd; C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe [193288 2012-02-14] (AVG Technologies CZ, s.r.o.)
R2 hasplms; C:\Windows\system32\hasplms.exe [3750400 2009-12-16] (SafeNet Inc.)
R2 LPDSVC; C:\Windows\system32\lpdsvc.dll [45568 2009-07-14] (Microsoft Corporation)
R2 MSSQL$MSSMLBIZ; C:\Program Files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe [29293408 2010-12-10] (Microsoft Corporation)
R2 Nero BackItUp Scheduler 3; C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBService.exe [877864 2008-06-08] (Nero AG)
S3 NMIndexingService; C:\Program Files (x86)\Common Files\Nero\Lib\NMIndexingService.exe [537896 2008-06-24] (Nero AG)
S4 PDF Architect Helper Service; C:\Program Files (x86)\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
S4 PDF Architect Service; C:\Program Files (x86)\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
R2 PLFlash DeviceIoControl Service; C:\Windows\SysWOW64\IoctlSvc.exe [81920 2006-12-19] (Prolific Technology Inc.)
R2 RealNetworks Downloader Resolver Service; C:\Program Files (x86)\RealNetworks\RealDownloader\rndlresolversvc.exe [38608 2012-11-29] ()
R2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.)
R2 SNMP; C:\Windows\System32\snmp.exe [49664 2010-11-20] (Microsoft Corporation)
R2 vToolbarUpdater15.3.0; C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\15.3.0\ToolbarUpdater.exe [1598128 2013-06-30] (AVG Secure Search)
R2 xrdd.exe; C:\Program Files (x86)\X-Rite\Devices\Services\xrdd.exe [203088 2011-03-10] (X-Rite Inc.)
S3 MozillaMaintenance; "C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe" [x]
==================== Drivers (Whitelisted) ====================
R3 AVGIDSDriver; C:\Windows\System32\DRIVERS\avgidsdrivera.sys [127328 2012-12-10] (AVG Technologies CZ, s.r.o. )
R3 AVGIDSFilter; C:\Windows\System32\DRIVERS\avgidsfiltera.sys [29776 2011-12-23] (AVG Technologies CZ, s.r.o. )
R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [28480 2012-04-19] (AVG Technologies CZ, s.r.o. )
R1 Avgldx64; C:\Windows\System32\DRIVERS\avgldx64.sys [307040 2012-11-08] (AVG Technologies CZ, s.r.o.)
R1 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [47696 2011-12-23] (AVG Technologies CZ, s.r.o.)
R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [36944 2012-01-31] (AVG Technologies CZ, s.r.o.)
R1 Avgtdia; C:\Windows\System32\DRIVERS\avgtdia.sys [384800 2013-04-11] (AVG Technologies CZ, s.r.o.)
R1 avgtp; C:\Windows\system32\drivers\avgtpx64.sys [45856 2013-06-30] (AVG Technologies)
S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-04-22] (EnTech Taiwan)
S3 ENTECH64; C:\Windows\system32\DRIVERS\ENTECH64.sys [12744 2008-04-22] (EnTech Taiwan)
R2 NPF_devolo; C:\Windows\sysWOW64\drivers\npf_devolo.sys [34048 2008-11-28] (CACE Technologies)
R2 WinI2C-DDC; C:\Windows\system32\drivers\DDCDrv.sys [20832 2011-06-22] (Nicomsoft Ltd.)
R2 WinI2C-DDC; C:\Windows\system32\drivers\DDCDrv.sys [20832 2011-06-22] (Nicomsoft Ltd.)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-05 15:53 - 2013-08-05 15:53 - 00000979 _____ C:\Users\user\Desktop\checkup.txt
2013-08-05 12:11 - 2013-08-05 12:11 - 00000000 ____D C:\Program Files (x86)\ESET
2013-08-05 11:56 - 2013-08-05 12:02 - 02347384 _____ (ESET) C:\Users\user\Desktop\esetsmartinstaller_enu.exe
2013-08-04 23:16 - 2013-08-04 23:21 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-04 23:16 - 2013-08-04 23:16 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-08-04 23:16 - 2013-08-04 23:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-04 12:07 - 2013-08-04 12:08 - 00891098 _____ C:\Users\user\Desktop\SecurityCheck.exe
2013-08-03 15:54 - 2013-08-01 15:47 - 01781589 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-08-03 15:29 - 2013-08-03 15:29 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-08-03 15:28 - 2013-08-03 15:28 - 00001113 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-03 15:28 - 2013-08-03 15:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-03 15:28 - 2013-08-03 15:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-03 15:28 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-03 14:13 - 2013-08-05 10:27 - 00003352 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3010914483-3101283893-2833772310-1000
2013-08-03 14:13 - 2013-08-05 10:27 - 00003216 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3010914483-3101283893-2833772310-1000
2013-08-03 14:06 - 2013-08-03 14:07 - 00008046 _____ C:\AdwCleaner[S2].txt
2013-08-03 14:06 - 2013-08-03 14:07 - 00000121 _____ C:\Windows\DeleteOnReboot.bat
2013-08-03 13:20 - 2013-08-03 13:20 - 00000338 _____ C:\AdwCleaner[S1].txt
2013-08-03 13:19 - 2013-08-03 13:19 - 00666633 _____ C:\Users\user\Desktop\adwcleaner.exe
2013-08-01 22:44 - 2013-08-01 22:44 - 00000000 ____D C:\Users\user\AppData\Local\MFAData
2013-08-01 22:44 - 2013-08-01 22:44 - 00000000 ____D C:\Users\user\AppData\Local\Avg2013
2013-08-01 19:10 - 2013-08-01 19:10 - 00315783 _____ C:\ComboFix.txt
2013-08-01 18:49 - 2013-08-01 19:11 - 00000000 ____D C:\Qoobox
2013-08-01 18:49 - 2013-08-01 19:08 - 00000000 ____D C:\Windows\erdnt
2013-08-01 18:49 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-01 18:49 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-01 18:49 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-01 18:49 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-01 18:49 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-01 18:49 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-01 18:49 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-01 18:49 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-01 18:19 - 2013-08-01 18:19 - 523735094 _____ C:\Windows\MEMORY.DMP
2013-08-01 18:19 - 2013-08-01 18:19 - 00473200 _____ C:\Windows\Minidump\080113-31824-01.dmp
2013-08-01 15:53 - 2013-08-01 15:53 - 00000000 ____D C:\FRST
2013-08-01 15:05 - 2013-08-01 15:05 - 00000000 _____ C:\Users\user\defogger_reenable
2013-08-01 15:04 - 2013-08-01 15:04 - 00050477 _____ C:\Users\user\Downloads\Defogger.exe
2013-07-31 19:12 - 2013-07-31 19:12 - 00000000 ____D C:\Users\user\Desktop\Alte Firefox-Daten
2013-07-31 18:43 - 2013-07-31 18:43 - 00002954 _____ C:\Windows\System32\Tasks\{95BB1E77-4514-463B-9347-810162D7973A}
2013-07-31 13:16 - 2013-07-31 13:16 - 21703480 _____ (Mozilla) C:\Users\user\Downloads\Firefox Setup 22.0.exe
2013-07-12 09:17 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-12 09:17 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-12 09:17 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-12 09:17 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-12 09:17 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-12 09:17 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-12 09:17 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-12 09:17 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-12 09:17 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-12 09:17 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-12 09:17 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-12 09:17 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-12 09:17 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-12 09:17 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-12 09:17 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-12 09:17 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-12 09:17 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-12 09:17 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-12 09:17 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-12 09:17 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-12 09:17 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-12 09:17 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-12 09:17 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-12 09:17 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-12 09:17 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-12 09:17 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-12 09:17 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-12 09:17 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-12 09:17 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-12 09:17 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-12 09:17 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-11 23:01 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-11 23:01 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-11 23:01 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-11 23:01 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-11 22:51 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-11 22:45 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-11 22:45 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
==================== One Month Modified Files and Folders =======
2013-08-05 16:00 - 2012-06-07 21:41 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-08-05 15:53 - 2013-08-05 15:53 - 00000979 _____ C:\Users\user\Desktop\checkup.txt
2013-08-05 15:44 - 2009-11-26 23:08 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-08-05 15:10 - 2009-12-24 22:19 - 01629283 _____ C:\Windows\WindowsUpdate.log
2013-08-05 14:30 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\tracing
2013-08-05 14:01 - 2012-06-01 10:53 - 00000000 ____D C:\Windows\system32\Drivers\AVG
2013-08-05 12:43 - 2009-07-14 19:58 - 00759880 _____ C:\Windows\system32\perfh007.dat
2013-08-05 12:43 - 2009-07-14 19:58 - 00173992 _____ C:\Windows\system32\perfc007.dat
2013-08-05 12:43 - 2009-07-14 07:13 - 01772164 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-05 12:11 - 2013-08-05 12:11 - 00000000 ____D C:\Program Files (x86)\ESET
2013-08-05 12:02 - 2013-08-05 11:56 - 02347384 _____ (ESET) C:\Users\user\Desktop\esetsmartinstaller_enu.exe
2013-08-05 10:34 - 2009-07-14 06:45 - 00015168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-05 10:34 - 2009-07-14 06:45 - 00015168 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-05 10:27 - 2013-08-03 14:13 - 00003352 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-3010914483-3101283893-2833772310-1000
2013-08-05 10:27 - 2013-08-03 14:13 - 00003216 _____ C:\Windows\System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-3010914483-3101283893-2833772310-1000
2013-08-05 10:27 - 2009-11-26 23:08 - 00001102 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-08-05 10:26 - 2013-01-29 17:28 - 00065536 _____ C:\Windows\system32\Ikeext.etl
2013-08-05 10:26 - 2012-09-16 21:46 - 00028217 _____ C:\Windows\setupact.log
2013-08-05 10:26 - 2009-11-10 19:22 - 00000000 ____D C:\ProgramData\NVIDIA
2013-08-05 10:26 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-05 09:57 - 2013-05-18 08:44 - 00003238 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-3010914483-3101283893-2833772310-1000
2013-08-05 09:57 - 2013-04-14 12:55 - 00003374 _____ C:\Windows\System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-3010914483-3101283893-2833772310-1000
2013-08-04 23:48 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-08-04 23:38 - 2009-11-17 17:08 - 00000000 ____D C:\Users\user\AppData\Roaming\Adobe
2013-08-04 23:21 - 2013-08-04 23:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-08-04 23:21 - 2013-01-10 00:10 - 00216788 _____ C:\Windows\PFRO.log
2013-08-04 23:16 - 2013-08-04 23:16 - 00001151 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-08-04 23:16 - 2013-08-04 23:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-08-04 22:07 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2013-08-04 17:41 - 2013-04-28 22:38 - 00007612 _____ C:\Users\user\AppData\Local\resmon.resmoncfg
2013-08-04 12:08 - 2013-08-04 12:07 - 00891098 _____ C:\Users\user\Desktop\SecurityCheck.exe
2013-08-03 16:03 - 2009-11-26 23:08 - 00000000 ____D C:\Users\user\AppData\Local\Google
2013-08-03 15:29 - 2013-08-03 15:29 - 00000000 ____D C:\Users\user\AppData\Roaming\Malwarebytes
2013-08-03 15:28 - 2013-08-03 15:28 - 00001113 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-08-03 15:28 - 2013-08-03 15:28 - 00000000 ____D C:\ProgramData\Malwarebytes
2013-08-03 15:28 - 2013-08-03 15:28 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-03 14:07 - 2013-08-03 14:06 - 00008046 _____ C:\AdwCleaner[S2].txt
2013-08-03 14:07 - 2013-08-03 14:06 - 00000121 _____ C:\Windows\DeleteOnReboot.bat
2013-08-03 13:20 - 2013-08-03 13:20 - 00000338 _____ C:\AdwCleaner[S1].txt
2013-08-03 13:19 - 2013-08-03 13:19 - 00666633 _____ C:\Users\user\Desktop\adwcleaner.exe
2013-08-01 22:46 - 2012-05-31 18:05 - 00000000 ____D C:\ProgramData\MFAData
2013-08-01 22:44 - 2013-08-01 22:44 - 00000000 ____D C:\Users\user\AppData\Local\MFAData
2013-08-01 22:44 - 2013-08-01 22:44 - 00000000 ____D C:\Users\user\AppData\Local\Avg2013
2013-08-01 20:39 - 2009-11-10 18:09 - 00000000 ____D C:\Users\user\AppData\Local\VirtualStore
2013-08-01 19:11 - 2013-08-01 18:49 - 00000000 ____D C:\Qoobox
2013-08-01 19:11 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2013-08-01 19:10 - 2013-08-01 19:10 - 00315783 _____ C:\ComboFix.txt
2013-08-01 19:08 - 2013-08-01 18:49 - 00000000 ____D C:\Windows\erdnt
2013-08-01 19:01 - 2009-07-14 04:34 - 00000248 _____ C:\Windows\system.ini
2013-08-01 18:19 - 2013-08-01 18:19 - 523735094 _____ C:\Windows\MEMORY.DMP
2013-08-01 18:19 - 2013-08-01 18:19 - 00473200 _____ C:\Windows\Minidump\080113-31824-01.dmp
2013-08-01 18:19 - 2010-08-21 12:34 - 00000000 ____D C:\Windows\Minidump
2013-08-01 15:53 - 2013-08-01 15:53 - 00000000 ____D C:\FRST
2013-08-01 15:47 - 2013-08-03 15:54 - 01781589 _____ (Farbar) C:\Users\user\Desktop\FRST64.exe
2013-08-01 15:05 - 2013-08-01 15:05 - 00000000 _____ C:\Users\user\defogger_reenable
2013-08-01 15:04 - 2013-08-01 15:04 - 00050477 _____ C:\Users\user\Downloads\Defogger.exe
2013-07-31 19:12 - 2013-07-31 19:12 - 00000000 ____D C:\Users\user\Desktop\Alte Firefox-Daten
2013-07-31 18:43 - 2013-07-31 18:43 - 00002954 _____ C:\Windows\System32\Tasks\{95BB1E77-4514-463B-9347-810162D7973A}
2013-07-31 13:16 - 2013-07-31 13:16 - 21703480 _____ (Mozilla) C:\Users\user\Downloads\Firefox Setup 22.0.exe
2013-07-31 11:59 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\AppCompat
2013-07-31 11:58 - 2009-11-25 22:46 - 00000000 ____D C:\ProgramData\FLEXnet
2013-07-31 11:57 - 2009-11-26 23:14 - 00000000 ____D C:\ProgramData\Real
2013-07-31 11:57 - 2009-11-26 23:08 - 00000000 ____D C:\Program Files (x86)\Google
2013-07-31 11:57 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\registration
2013-07-29 10:59 - 2010-02-05 01:12 - 00000000 ____D C:\Users\user\AppData\Roaming\Canon
2013-07-12 19:39 - 2009-11-26 23:08 - 00004102 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2013-07-12 19:39 - 2009-11-26 23:08 - 00003850 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2013-07-12 09:04 - 2009-07-14 06:45 - 02356784 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-12 09:03 - 2012-05-11 19:06 - 00000000 ____D C:\Program Files\Microsoft Silverlight
2013-07-12 09:03 - 2009-07-14 20:18 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-12 09:03 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-12 09:03 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-12 09:02 - 2012-05-11 19:06 - 00000000 ____D C:\Program Files (x86)\Microsoft Silverlight
2013-07-12 00:38 - 2009-11-10 18:23 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-07-12 00:37 - 2009-11-10 19:01 - 00000000 ____D C:\ProgramData\Microsoft Help
2013-07-12 00:26 - 2009-11-17 18:22 - 00000000 ____D C:\Users\user\AppData\Local\Adobe
2013-07-12 00:20 - 2012-06-07 21:41 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-07-12 00:20 - 2012-06-07 21:40 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-07-12 00:20 - 2011-11-24 11:25 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-02 11:44
==================== End Of Log ============================ --- --- ---
Finden sich da noch Probleme?
Von meiner Seite aus ist zu melden, dass Firefox und Download besser gehen, die Geschwindigkeit ist aber noch nicht berauschend ist, vor allem beim Bilder herunterladen. gibt es eine Möglichkeit, die Downloadkapazität zu erhöhen?
Wie schon angedeutet: Das Tempo von Firefox und Download nimmt rapide ab, wenn ich externe Devices angedockt habe. Ist das normal oder kann man da etwas dagegen tun?
Gruss
knibuy |