bronski123 | 03.01.2014 12:06 | Laptop reagiert immer langsamer Hallo, mein Laptop wir immer langsamer d.h. beim Start , im Netz und überhaupt wenn ich Programme öffne
wie in der Anleitung beschrieben, habe ich die Log-Dateien schonmal erstellt
wäre schön wenn ihr mir helfen könnt ... Danke Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 02-01-2014 01
Ran by Anke (administrator) on ANKE-PC on 03-01-2014 11:07:43
Running from C:\Users\Anke\Desktop
Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Sandboxie Holdings, LLC) C:\Program Files\Sandboxie\SbieSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Microsoft\BingBar\SeaPort.EXE
(Secunia) C:\Program Files\Secunia\PSI\psia.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe
(TuneUp Software) C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE
(TuneUp Software) C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesApp32.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
(Facebook Inc.) C:\Users\Anke\AppData\Local\Facebook\Update\FacebookUpdate.exe
(Secure Banking) C:\Program Files\Secure Banking\SecureBanking.exe
() C:\Program Files\Secure Banking\sbservice.exe
(OpenOffice.org) C:\Program Files\program\soffice.exe
(OpenOffice.org) C:\Program Files\program\soffice.bin
(Secunia) C:\Program Files\Secunia\PSI\sua.exe
(Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Intel Corporation) C:\Windows\System32\igfxsrvc.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAStorIcon] - C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284696 2010-03-03] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7731744 2009-08-31] (Realtek Semiconductor)
HKLM\...\Run: [AppleSyncNotifier] - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-11-02] (Apple Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.)
HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [1157640 2009-10-07] (Dritek System Inc.)
HKLM\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3764024 2014-01-01] (AVAST Software)
HKCU\...\Run: [Facebook Update] - C:\Users\Anke\AppData\Local\Facebook\Update\FacebookUpdate.exe [138096 2012-11-05] (Facebook Inc.)
HKCU\...\Run: [SecureBanking] - C:\Program Files\Secure Banking\SecureBanking.exe [507904 2013-06-30] (Secure Banking)
HKCU\...\Policies\Explorer: [NoInternetOpenWith] 1
HKCU\...\Policies\Explorer: [NoRecentDocsNetHood] 1
Startup: C:\Users\Anke\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files\program\quickstart.exe ()
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/
SearchScopes: HKLM - DefaultScope value is missing.
BHO: ZoneAlarm Security Engine Registrar - {8A4A36C2-0535-4D2C-BD3D-496CB7EED6E3} - No File
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Windows Live Messenger Companion Helper - {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKCU - ZoneAlarm Security Engine - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No File
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\aab16fmb.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_117.dll ()
FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf - C:\Program Files\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin: @java.com/DTPlugin,version=1.6.0_37 - C:\Windows\system32\npdeployJava1.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin: @videolan.org/vlc,version=1.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin: @videolan.org/vlc,version=2.1.0 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\Anke\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Anke\AppData\Roaming\Mozilla\Firefox\Profiles\aab16fmb.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: No Name - C:\Program Files\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF HKLM\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF
Chrome:
=======
CHR HomePage: hxxp://www.google.com
CHR RestoreOnStartup: "hxxp://www.google.com"
CHR DefaultSearchKeyword: fbdownloader
CHR DefaultSearchProvider: FBDownloader
CHR DefaultSearchURL: hxxp://search.fbdownloader.com/search.php?channel=sfde203fbdgy21&q={searchTerms}
CHR Extension: (Docs) - C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0
CHR Extension: (Google Drive) - C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0
CHR Extension: (YouTube) - C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0
CHR Extension: (Google Search) - C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0
CHR Extension: (Click to call with Skype) - C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.6.0.8153_0
CHR Extension: (Gmail) - C:\Users\Anke\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files\Skype\Toolbars\Skype for Chromium\skype_chrome_extension.crx
========================== Services (Whitelisted) =================
R2 Akamai; c:\program files\common files\akamai/netsession_win_8fa3539.dll [4569856 2013-07-07] (Akamai Technologies, Inc.)
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-01-01] (AVAST Software)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
S3 npggsvc; C:\Windows\system32\GameMon.des [4137464 2011-05-04] (INCA Internet Co., Ltd.)
R2 SbieSvc; C:\Program Files\Sandboxie\SbieSvc.exe [130248 2013-10-16] (Sandboxie Holdings, LLC)
R2 Secunia PSI Agent; C:\Program Files\Secunia\PSI\PSIA.exe [1328736 2012-09-24] (Secunia)
R2 Secunia Update Agent; C:\Program Files\Secunia\PSI\sua.exe [656480 2012-09-24] (Secunia)
R2 TuneUp.UtilitiesSvc; C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesService32.exe [1739576 2013-10-30] (TuneUp Software)
==================== Drivers (Whitelisted) ====================
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [67824 2014-01-01] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [79720 2014-01-01] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49944 2014-01-01] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [775952 2014-01-01] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [410528 2014-01-01] (AVAST Software)
R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [64168 2014-01-01] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [180248 2014-01-01] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf.sys [15544 2011-12-16] (Secunia)
R3 SbieDrv; C:\Program Files\Sandboxie\SbieDrv.sys [159840 2013-10-16] (Sandboxie Holdings, LLC)
R3 TuneUpUtilitiesDrv; C:\Program Files\TuneUp Utilities 2014\TuneUpUtilitiesDriver32.sys [12320 2013-09-18] (TuneUp Software)
S3 catchme; \??\C:\Users\Anke\AppData\Local\Temp\catchme.sys [x]
S3 RtsUIR; system32\DRIVERS\Rts516xIR.sys [x]
S3 USBCCID; system32\DRIVERS\RtsUCcid.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-03 11:05 - 2014-01-03 11:07 - 00019378 _____ C:\Users\Anke\Desktop\Addition.txt
2014-01-03 11:04 - 2014-01-03 11:08 - 00012126 _____ C:\Users\Anke\Desktop\FRST.txt
2014-01-03 11:03 - 2014-01-03 11:03 - 00000000 ____D C:\FRST
2014-01-03 11:02 - 2014-01-03 11:03 - 01064581 _____ (Farbar) C:\Users\Anke\Desktop\FRST.exe
2014-01-03 10:59 - 2014-01-03 11:00 - 00000470 _____ C:\Users\Anke\Desktop\defogger_disable.log
2014-01-03 10:59 - 2014-01-03 10:59 - 00000000 _____ C:\Users\Anke\defogger_reenable
2014-01-03 10:57 - 2014-01-03 10:57 - 00050477 _____ C:\Users\Anke\Desktop\Defogger.exe
2014-01-01 12:44 - 2014-01-01 12:44 - 00000000 ____D C:\Users\Anke\AppData\Roaming\AVAST Software
2014-01-01 12:43 - 2014-01-01 12:43 - 00002129 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-01-01 12:42 - 2014-01-01 12:43 - 00064168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00775952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00410528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00270240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-01-01 12:42 - 2014-01-01 12:42 - 00180248 _____ C:\Windows\system32\Drivers\aswVmm.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00079720 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00049944 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-01-01 12:42 - 2014-01-01 12:42 - 00000350 ____H C:\Windows\Tasks\avast! Emergency Update.job
2014-01-01 12:41 - 2014-01-01 12:41 - 00000000 ____D C:\Program Files\AVAST Software
2014-01-01 12:37 - 2014-01-01 12:37 - 91412976 _____ (AVAST Software) C:\Users\Anke\Downloads\avast_free_antivirus_setup(1).exe
2013-12-27 11:22 - 2014-01-03 10:37 - 00001120 _____ C:\Windows\setupact.log
2013-12-27 11:22 - 2014-01-01 14:20 - 00497572 _____ C:\Windows\PFRO.log
2013-12-27 11:22 - 2013-12-27 11:22 - 00000000 _____ C:\Windows\setuperr.log
2013-12-26 17:15 - 2013-12-26 17:15 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Anke\Downloads\mbam-setup-1.75.0.1300.exe
2013-12-20 10:38 - 2013-12-20 10:39 - 00000000 ____D C:\Users\Anke\Documents\Kreisjugendring
2013-12-19 10:59 - 2013-12-19 11:00 - 00000000 ____D C:\Users\Anke\AppData\Roaming\Mozilla
2013-12-19 10:59 - 2013-12-19 10:59 - 00001115 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-12-19 10:59 - 2013-12-19 10:59 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-12-16 21:22 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-12-16 21:22 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-12-16 21:22 - 2013-11-26 10:22 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2013-12-16 21:22 - 2013-11-26 09:53 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-12-16 21:22 - 2013-11-26 09:52 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2013-12-16 21:22 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-12-16 21:22 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-12-16 21:22 - 2013-11-26 09:36 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-12-16 21:22 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-12-16 21:22 - 2013-11-26 09:29 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2013-12-16 21:22 - 2013-11-26 09:29 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2013-12-16 21:22 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2013-12-16 21:22 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-12-16 21:22 - 2013-11-26 09:13 - 00208896 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-12-16 21:22 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2013-12-16 21:22 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-12-16 21:22 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2013-12-16 21:22 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-12-16 21:22 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-12-16 19:47 - 2013-12-16 19:48 - 00296080 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-15 19:49 - 2013-12-15 19:49 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-15 19:49 - 2013-12-15 19:49 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-15 19:49 - 2013-12-15 19:49 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-15 19:49 - 2013-12-15 19:49 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-15 19:49 - 2013-12-15 19:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-15 19:49 - 2013-12-15 19:49 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-15 19:49 - 2013-12-15 19:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-15 19:49 - 2013-12-15 19:49 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-15 19:49 - 2013-12-15 19:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-15 19:49 - 2013-12-15 19:49 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-15 19:48 - 2013-12-15 19:48 - 03969472 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-12-15 19:48 - 2013-12-15 19:48 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-12-15 19:48 - 2013-12-15 19:48 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-12-15 19:48 - 2013-12-15 19:48 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-12-15 19:48 - 2013-12-15 19:48 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-12-15 19:48 - 2013-12-15 19:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-12-15 19:48 - 2013-12-15 19:48 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-12-15 19:48 - 2013-12-15 19:48 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-12-15 19:48 - 2013-12-15 19:48 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-12-15 19:11 - 2013-12-15 19:11 - 00064312 _____ C:\Users\Anke\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-14 14:12 - 2013-12-14 14:12 - 00000000 ____D C:\Users\Anke\AppData\Local\Avg2014
2013-12-14 11:00 - 2013-12-14 11:00 - 00000228 _____ C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job
2013-12-14 09:54 - 2013-11-12 03:07 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2013-12-14 09:54 - 2013-10-19 02:36 - 00159232 _____ (Microsoft Corporation) C:\Windows\system32\imagehlp.dll
2013-12-14 09:54 - 2013-10-12 03:04 - 00121856 _____ (Microsoft Corporation) C:\Windows\system32\wshom.ocx
2013-12-14 09:54 - 2013-10-12 03:03 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\scrrun.dll
2013-12-14 09:54 - 2013-10-12 02:15 - 00141824 _____ (Microsoft Corporation) C:\Windows\system32\wscript.exe
2013-12-14 09:54 - 2013-10-12 02:15 - 00126976 _____ (Microsoft Corporation) C:\Windows\system32\cscript.exe
2013-12-14 09:53 - 2013-10-30 02:27 - 02349056 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-12-14 09:53 - 2013-10-04 02:49 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\drmk.sys
2013-12-14 09:53 - 2013-10-04 02:17 - 00177152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\portcls.sys
2013-12-11 16:02 - 2013-10-30 10:45 - 00036152 _____ (TuneUp Software) C:\Windows\system32\uxtuneup.dll
2013-12-11 16:02 - 2013-10-30 10:45 - 00025400 _____ (TuneUp Software) C:\Windows\system32\authuitu.dll
2013-12-11 15:58 - 2013-12-11 15:58 - 00002165 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2013-12-11 15:58 - 2013-12-11 15:58 - 00002145 _____ C:\Users\Public\Desktop\TuneUp Utilities 2014.lnk
2013-12-11 15:58 - 2013-10-30 10:45 - 00036664 _____ (TuneUp Software) C:\Windows\system32\TURegOpt.exe
2013-12-11 15:56 - 2013-12-11 16:02 - 00000000 ____D C:\Program Files\TuneUp Utilities 2014
2013-12-11 15:55 - 2013-12-14 09:49 - 00000000 __SHD C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-12-11 15:54 - 2013-12-11 15:55 - 32522152 _____ (TuneUp Software) C:\Users\Anke\Downloads\TuneUpUtilities2014_de-DE(1).exe
2013-12-11 15:54 - 2013-12-11 15:54 - 32522152 _____ (TuneUp Software) C:\Users\Anke\Downloads\TuneUpUtilities2014_de-DE.exe
2013-12-11 15:41 - 2013-12-11 15:41 - 00000000 ____D C:\Program Files\Allin1Convert_8h
2013-12-11 15:09 - 2013-12-11 15:18 - 00000000 ____D C:\Program Files\MyPC Backup
2013-12-11 15:08 - 2013-12-26 15:27 - 00000000 ____D C:\Users\Anke\AppData\Roaming\systweak
2013-12-11 15:06 - 2013-12-11 15:06 - 06175624 _____ (Systweak Inc ) C:\Users\Anke\Downloads\rcpsetupmarm1_marm1164704522de_yas.exe
2013-12-10 09:26 - 2014-01-01 12:03 - 00264560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
==================== One Month Modified Files and Folders =======
2014-01-03 11:08 - 2014-01-03 11:04 - 00012126 _____ C:\Users\Anke\Desktop\FRST.txt
2014-01-03 11:07 - 2014-01-03 11:05 - 00019378 _____ C:\Users\Anke\Desktop\Addition.txt
2014-01-03 11:07 - 2009-07-14 05:34 - 00014080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-03 11:07 - 2009-07-14 05:34 - 00014080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-03 11:03 - 2014-01-03 11:03 - 00000000 ____D C:\FRST
2014-01-03 11:03 - 2014-01-03 11:02 - 01064581 _____ (Farbar) C:\Users\Anke\Desktop\FRST.exe
2014-01-03 11:00 - 2014-01-03 10:59 - 00000470 _____ C:\Users\Anke\Desktop\defogger_disable.log
2014-01-03 10:59 - 2014-01-03 10:59 - 00000000 _____ C:\Users\Anke\defogger_reenable
2014-01-03 10:59 - 2010-08-05 22:21 - 00000000 ____D C:\Users\Anke
2014-01-03 10:57 - 2014-01-03 10:57 - 00050477 _____ C:\Users\Anke\Desktop\Defogger.exe
2014-01-03 10:47 - 2012-12-30 20:11 - 01053457 _____ C:\Windows\WindowsUpdate.log
2014-01-03 10:38 - 2012-03-12 15:21 - 00000000 ____D C:\Program Files\Common Files\Akamai
2014-01-03 10:37 - 2013-12-27 11:22 - 00001120 _____ C:\Windows\setupact.log
2014-01-01 14:20 - 2013-12-27 11:22 - 00497572 _____ C:\Windows\PFRO.log
2014-01-01 12:44 - 2014-01-01 12:44 - 00000000 ____D C:\Users\Anke\AppData\Roaming\AVAST Software
2014-01-01 12:43 - 2014-01-01 12:43 - 00002129 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk
2014-01-01 12:43 - 2014-01-01 12:42 - 00064168 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00775952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00410528 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00270240 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-01-01 12:42 - 2014-01-01 12:42 - 00180248 _____ C:\Windows\system32\Drivers\aswVmm.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00079720 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00067824 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00049944 _____ C:\Windows\system32\Drivers\aswRvrt.sys
2014-01-01 12:42 - 2014-01-01 12:42 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-01-01 12:42 - 2014-01-01 12:42 - 00000350 ____H C:\Windows\Tasks\avast! Emergency Update.job
2014-01-01 12:41 - 2014-01-01 12:41 - 00000000 ____D C:\Program Files\AVAST Software
2014-01-01 12:39 - 2013-01-03 21:53 - 00000000 ____D C:\ProgramData\AVAST Software
2014-01-01 12:37 - 2014-01-01 12:37 - 91412976 _____ (AVAST Software) C:\Users\Anke\Downloads\avast_free_antivirus_setup(1).exe
2014-01-01 12:03 - 2013-12-10 09:26 - 00264560 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys
2013-12-29 23:10 - 2013-01-05 16:41 - 00002682 _____ C:\Windows\Sandboxie.ini
2013-12-27 11:31 - 2010-08-06 10:29 - 01472002 _____ C:\Windows\system32\PerfStringBackup.INI
2013-12-27 11:22 - 2013-12-27 11:22 - 00000000 _____ C:\Windows\setuperr.log
2013-12-26 18:45 - 2013-11-17 11:05 - 00000000 ____D C:\Program Files\Mozilla Firefox
2013-12-26 18:45 - 2010-08-05 23:04 - 00000000 ____D C:\Windows\Panther
2013-12-26 17:18 - 2013-01-02 14:17 - 00001077 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2013-12-26 17:18 - 2013-01-02 14:16 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2013-12-26 17:15 - 2013-12-26 17:15 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Anke\Downloads\mbam-setup-1.75.0.1300.exe
2013-12-26 15:28 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system
2013-12-26 15:27 - 2013-12-11 15:08 - 00000000 ____D C:\Users\Anke\AppData\Roaming\systweak
2013-12-20 10:39 - 2013-12-20 10:38 - 00000000 ____D C:\Users\Anke\Documents\Kreisjugendring
2013-12-19 11:00 - 2013-12-19 10:59 - 00000000 ____D C:\Users\Anke\AppData\Roaming\Mozilla
2013-12-19 10:59 - 2013-12-19 10:59 - 00001115 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-12-19 10:59 - 2013-12-19 10:59 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service
2013-12-16 19:48 - 2013-12-16 19:47 - 00296080 _____ C:\Windows\system32\FNTCACHE.DAT
2013-12-16 19:46 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\system32\de-DE
2013-12-15 19:49 - 2013-12-15 19:49 - 01051136 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2013-12-15 19:49 - 2013-12-15 19:49 - 00645120 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat
2013-12-15 19:49 - 2013-12-15 19:49 - 00610304 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00523776 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00454656 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00367104 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00337408 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2013-12-15 19:49 - 2013-12-15 19:49 - 00244736 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00238288 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00233472 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00208384 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00194048 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00182272 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00151552 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe
2013-12-15 19:49 - 2013-12-15 19:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe
2013-12-15 19:49 - 2013-12-15 19:49 - 00127488 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00116736 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00083456 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00074240 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe
2013-12-15 19:49 - 2013-12-15 19:49 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-12-15 19:49 - 2013-12-15 19:49 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00069120 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx
2013-12-15 19:49 - 2013-12-15 19:49 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00036352 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00034816 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll
2013-12-15 19:49 - 2013-12-15 19:49 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2013-12-15 19:49 - 2013-12-15 19:49 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2013-12-15 19:48 - 2013-12-15 19:48 - 03969472 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe
2013-12-15 19:48 - 2013-12-15 19:48 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2013-12-15 19:48 - 2013-12-15 19:48 - 01505280 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll
2013-12-15 19:48 - 2013-12-15 19:48 - 01294272 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys
2013-12-15 19:48 - 2013-12-15 19:48 - 01289096 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll
2013-12-15 19:48 - 2013-12-15 19:48 - 00640512 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll
2013-12-15 19:48 - 2013-12-15 19:48 - 00619520 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll
2013-12-15 19:48 - 2013-12-15 19:48 - 00338944 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys
2013-12-15 19:48 - 2013-12-15 19:48 - 00231424 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll
2013-12-15 19:11 - 2013-12-15 19:11 - 00064312 _____ C:\Users\Anke\AppData\Local\GDIPFONTCACHEV1.DAT
2013-12-15 15:39 - 2013-08-15 08:52 - 00000000 ____D C:\Windows\system32\MRT
2013-12-15 15:32 - 2013-01-03 18:41 - 88123800 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-12-14 14:12 - 2013-12-14 14:12 - 00000000 ____D C:\Users\Anke\AppData\Local\Avg2014
2013-12-14 11:00 - 2013-12-14 11:00 - 00000228 _____ C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job
2013-12-14 09:49 - 2013-12-11 15:55 - 00000000 __SHD C:\ProgramData\{FE8D473A-6F06-4F99-B5F4-BED72B2A038C}
2013-12-11 16:03 - 2012-11-07 19:56 - 00000000 ____D C:\ProgramData\TuneUp Software
2013-12-11 16:02 - 2013-12-11 15:56 - 00000000 ____D C:\Program Files\TuneUp Utilities 2014
2013-12-11 15:58 - 2013-12-11 15:58 - 00002165 _____ C:\Users\Public\Desktop\TuneUp 1-Klick-Wartung.lnk
2013-12-11 15:58 - 2013-12-11 15:58 - 00002145 _____ C:\Users\Public\Desktop\TuneUp Utilities 2014.lnk
2013-12-11 15:57 - 2012-11-07 19:58 - 00000000 ____D C:\Users\Anke\AppData\Roaming\TuneUp Software
2013-12-11 15:55 - 2013-12-11 15:54 - 32522152 _____ (TuneUp Software) C:\Users\Anke\Downloads\TuneUpUtilities2014_de-DE(1).exe
2013-12-11 15:54 - 2013-12-11 15:54 - 32522152 _____ (TuneUp Software) C:\Users\Anke\Downloads\TuneUpUtilities2014_de-DE.exe
2013-12-11 15:48 - 2013-01-13 20:03 - 00000000 ____D C:\Users\Anke\AppData\Roaming\Foxit Software
2013-12-11 15:41 - 2013-12-11 15:41 - 00000000 ____D C:\Program Files\Allin1Convert_8h
2013-12-11 15:18 - 2013-12-11 15:09 - 00000000 ____D C:\Program Files\MyPC Backup
2013-12-11 15:06 - 2013-12-11 15:06 - 06175624 _____ (Systweak Inc ) C:\Users\Anke\Downloads\rcpsetupmarm1_marm1164704522de_yas.exe
Files to move or delete:
====================
C:\Windows\Tasks\{7648A30F-8D12-4774-9628-95DF148E7966}.job
C:\Windows\Tasks\{D49D7C32-07B9-403B-89F8-7AA71184B49F}.job
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2010-08-06 13:00
==================== End Of Log ============================ Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 02-01-2014 01
Ran by Anke at 2014-01-03 11:09:24
Running from C:\Users\Anke\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
==================== Installed Programs ======================
7-Zip 9.22beta (Version: - )
Adobe Flash Player 11 ActiveX (Version: 11.8.800.94 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (Version: 11.9.900.117 - Adobe Systems Incorporated)
Akamai NetSession Interface (Version: - )
Akamai NetSession Interface (Version: - Akamai Technologies, Inc)
Apple Application Support (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (Version: 2.1.3.127 - Apple Inc.)
avast! Free Antivirus (Version: 9.0.2011 - Avast Software)
Bing Bar (Version: 7.0.619.0 - Microsoft Corporation)
Bonjour (Version: 3.0.0.10 - Apple Inc.)
D3DX10 (Version: 15.4.2368.0902 - Microsoft) Hidden
ESET Online Scanner v3 (Version: - )
Facebook Video Calling 1.2.0.287 (Version: 1.2.287 - Skype Limited)
Foxit Reader (Version: 6.1.1.1031 - Foxit Corporation)
iCloud (Version: 3.0.2.163 - Apple Inc.)
iLivid (Version: 1.92.0.122194 - Bandoo Media Inc.) Hidden <==== ATTENTION
Intel(R) Control Center (Version: 1.2.1.1007 - Intel Corporation)
Intel(R) Graphics Media Accelerator Driver (Version: 8.15.10.1930 - Intel Corporation)
Intel(R) Rapid Storage Technology (Version: 9.6.0.1014 - Intel Corporation)
iTunes (Version: 11.1.3.8 - Apple Inc.)
Junk Mail filter update (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300 - Malwarebytes Corporation)
Mesh Runtime (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6012.5000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
MobileMe Control Panel (Version: 3.1.8.0 - Apple Inc.)
Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla)
Mozilla Maintenance Service (Version: 26.0 - Mozilla)
MSVCRT (Version: 15.4.2862.0708 - Microsoft) Hidden
OpenOffice.org 3.4.1 (Version: 3.41.9593 - Apache Software Foundation)
QuickTime (Version: 7.74.80.86 - Apple Inc.)
Realtek High Definition Audio Driver (Version: 6.0.1.5928 - Realtek Semiconductor Corp.)
Realtek USB 2.0 Card Reader (Version: 6.1.7100.30094 - Realtek Semiconductor Corp.)
Safari (Version: 5.34.57.2 - Apple Inc.)
Sandboxie 4.06 (32-bit) (Version: 4.06 - Sandboxie Holdings, LLC)
Secunia PSI (3.0.0.4001) (Version: 3.0.0.4001 - Secunia)
Secure Banking Version 1.5.2 (Version: 1.5.2 - Hopfgartner Niklas)
Skype Click to Call (Version: 5.6.8442 - Skype Technologies S.A.)
Skype™ 6.0 (Version: 6.0.126 - Skype Technologies S.A.)
TuneUp Utilities 2014 (de-DE) (Version: 14.0.1000.169 - TuneUp Software) Hidden
TuneUp Utilities 2014 (Version: 14.0.1000.169 - TuneUp Software)
TuneUp Utilities 2014 (Version: 14.0.1000.169 - TuneUp Software) Hidden
TuneUp Utilities Language Pack (de-DE) (Version: 12.0.3600.73 - TuneUp Software) Hidden
VLC media player 2.1.0 (Version: 2.1.0 - VideoLAN)
Windows Live Communications Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mail (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX control for remote connections (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger Companion Core (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Movie Maker 2.6 (Version: 2.6.4037.0 - Microsoft Corporation)
WinRAR 5.00 (32-bit) (Version: 5.00.0 - win.rar GmbH)
==================== Restore Points =========================
15-12-2013 14:15:53 Windows Update
15-12-2013 18:46:53 Windows Update
16-12-2013 20:21:47 Windows Update
20-12-2013 08:00:11 Windows Update
26-12-2013 10:38:30 Windows Update
31-12-2013 15:55:44 Windows Update
01-01-2014 11:02:01 avast! antivirus system restore point
01-01-2014 11:05:18 Gerätetreiber-Paketinstallation: Avast Netzwerkdienst
01-01-2014 11:29:20 avast! antivirus system restore point
01-01-2014 11:40:34 avast! antivirus system restore point
==================== Hosts content: ==========================
2009-07-14 03:04 - 2012-12-30 21:50 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\avast! Emergency Update.job => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-711859982-3773503475-4091641601-1000Core.job => C:\Users\Anke\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-711859982-3773503475-4091641601-1000Core1cdbb4ab62f6d96.job => C:\Users\Anke\AppData\Local\Facebook\Update\FacebookUpdate.exe
Task: C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2013.job => C:\Program Files\TuneUp Utilities 2014\OneClick.exe
Task: C:\Windows\Tasks\User_Feed_Synchronization-{15785F72-F135-411B-91A3-8DA824C4E669}.job => C:\Windows\system32\msfeedssync.exe
Task: C:\Windows\Tasks\{7648A30F-8D12-4774-9628-95DF148E7966}.job => C:\Program Files\Skype\Phone\Skype.exe
Task: C:\Windows\Tasks\{D49D7C32-07B9-403B-89F8-7AA71184B49F}.job => C:\Program Files\Skype\Phone\Skype.exe
==================== Loaded Modules (whitelisted) =============
2014-01-02 18:08 - 2014-01-02 11:43 - 02152960 _____ () C:\Program Files\AVAST Software\Avast\defs\14010200\algo.dll
2014-01-03 10:39 - 2014-01-02 19:10 - 02152960 _____ () C:\Program Files\AVAST Software\Avast\defs\14010201\algo.dll
2011-06-24 21:56 - 2011-06-24 21:56 - 00087328 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2011-06-24 21:56 - 2011-06-24 21:56 - 01241888 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-10-30 10:46 - 2013-10-30 10:46 - 00501560 _____ () C:\Program Files\TuneUp Utilities 2014\avgreplibx.dll
2014-01-01 12:42 - 2014-01-01 12:42 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2013-07-25 20:50 - 2013-06-30 16:01 - 00017920 _____ () C:\Program Files\Secure Banking\SecureBanking.dll
2013-07-25 20:50 - 2013-05-26 12:13 - 00008704 _____ () C:\Program Files\Secure Banking\funcs.dll
2012-08-10 16:51 - 2012-08-10 16:51 - 00985088 _____ () C:\Program Files\program\libxml2.dll
2013-09-01 10:11 - 2013-09-01 10:11 - 00170496 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_32\IsdiInterop\44bfa824a3b8a6f789fda79a2e01a8db\IsdiInterop.ni.dll
2010-08-06 11:25 - 2010-03-03 19:08 - 00058880 _____ () C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IsdiInterop.dll
2013-12-19 10:59 - 2013-12-05 20:36 - 03559024 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Users\Anke\Documents\mbam-log-2012-12-22 (20-45-00).eml:OECustomProperty
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/02/2014 00:42:10 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15694
Error: (01/02/2014 00:42:10 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15694
Error: (01/02/2014 00:42:10 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/01/2014 03:06:12 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15663
Error: (01/01/2014 03:06:12 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15663
Error: (01/01/2014 03:06:12 PM) (Source: Bonjour Service) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/01/2014 00:40:41 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary ylhslixn.
System Error:
Das System kann die angegebene Datei nicht finden.
.
Error: (01/01/2014 00:40:33 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {712a4d51-cc7c-4b72-922a-93d8a7bd168a}
Error: (01/01/2014 00:29:19 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {672b4647-ec0d-4408-8065-9f3ca0aef7e8}
Error: (01/01/2014 00:05:24 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddLegacyDriverFiles: Unable to back up image of binary aswFsBlk.
System Error:
Das System kann die angegebene Datei nicht finden.
.
System errors:
=============
Error: (01/03/2014 10:38:22 AM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (01/02/2014 06:07:19 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (01/02/2014 00:01:29 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (01/02/2014 07:59:12 AM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (01/01/2014 08:26:41 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (01/01/2014 08:25:38 PM) (Source: EventLog) (User: )
Description: Das System wurde zuvor am 01.01.2014 um 18:54:08 unerwartet heruntergefahren.
Error: (01/01/2014 05:04:03 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst ShellHWDetection erreicht.
Error: (01/01/2014 02:20:49 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (01/01/2014 00:33:18 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Error: (01/01/2014 00:14:23 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
cdrom
Microsoft Office Sessions:
=========================
Error: (01/02/2014 00:42:10 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15694
Error: (01/02/2014 00:42:10 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15694
Error: (01/02/2014 00:42:10 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/01/2014 03:06:12 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 15663
Error: (01/01/2014 03:06:12 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: m->NextScheduledEvent 15663
Error: (01/01/2014 03:06:12 PM) (Source: Bonjour Service)(User: )
Description: Task Scheduling Error: Continuously busy for more than a second
Error: (01/01/2014 00:40:41 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary ylhslixn.
System Error:
Das System kann die angegebene Datei nicht finden.
Error: (01/01/2014 00:40:33 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {712a4d51-cc7c-4b72-922a-93d8a7bd168a}
Error: (01/01/2014 00:29:19 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {672b4647-ec0d-4408-8065-9f3ca0aef7e8}
Error: (01/01/2014 00:05:24 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddLegacyDriverFiles: Unable to back up image of binary aswFsBlk.
System Error:
Das System kann die angegebene Datei nicht finden.
CodeIntegrity Errors:
===================================
Date: 2012-11-06 09:56:52.664
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-11-05 20:54:55.540
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-11-05 20:40:10.600
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-11-05 20:22:33.004
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-11-05 19:44:08.420
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-11-05 19:29:43.724
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-11-05 19:19:57.593
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-11-05 17:14:42.869
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-11-05 17:04:40.795
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2012-11-05 16:56:36.975
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\Plugins\ISWSHEX.dll" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 80%
Total physical RAM: 1013.95 MB
Available physical RAM: 202.77 MB
Total Pagefile: 2037.95 MB
Available Pagefile: 905.47 MB
Total Virtual: 2047.88 MB
Available Virtual: 1902.91 MB
==================== Drives ================================
Drive c: (Festplatte) (Fixed) (Total:148.95 GB) (Free:42.85 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 09020A9C)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Code:
GMER 2.1.19163 - hxxp://www.gmer.net
Rootkit scan 2014-01-03 12:04:06
Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD16 rev.11.0 149,05GB
Running: gmer_2.1.19163.exe; Driver: C:\Users\Anke\AppData\Local\Temp\kxtdrpog.sys
---- System - GMER 2.1 ----
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwAddBootEntry [0x8BA03AD0]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwAssignProcessToJobObject [0x8BA045AE]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateEvent [0x8BA105E0]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateEventPair [0x8BA1062C]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateIoCompletion [0x8BA107C6]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateMutant [0x8BA1054E]
SSDT \??\C:\Windows\system32\drivers\aswSP.sys ZwCreateSection [0x8BABA386]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateSemaphore [0x8BA10596]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateThread [0x8BA04AE4]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateThreadEx [0x8BA04D00]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwCreateTimer [0x8BA10780]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwDebugActiveProcess [0x8BA0539C]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwDeleteBootEntry [0x8BA03B36]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwDuplicateObject [0x8BA08B32]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwLoadDriver [0x8BA0371E]
SSDT \??\C:\Windows\system32\drivers\aswSP.sys ZwMapViewOfSection [0x8BABA466]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwModifyBootEntry [0x8BA03B9C]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwNotifyChangeKey [0x8BA08F28]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwNotifyChangeMultipleKeys [0x8BA05E2C]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenEvent [0x8BA1060A]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenEventPair [0x8BA1064E]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenIoCompletion [0x8BA107EA]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenMutant [0x8BA10574]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenProcess [0x8BA0842C]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenSection [0x8BA106FE]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenSemaphore [0x8BA105BE]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenThread [0x8BA08814]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwOpenTimer [0x8BA107A4]
SSDT \??\C:\Windows\system32\drivers\aswSP.sys ZwProtectVirtualMemory [0x8BABA20A]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwQueryObject [0x8BA05CF8]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwQueueApcThreadEx [0x8BA05A06]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSetBootEntryOrder [0x8BA03C02]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSetBootOptions [0x8BA03C68]
SSDT \??\C:\Windows\system32\drivers\aswSP.sys ZwSetContextThread [0x8BABA562]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSetSystemInformation [0x8BA037B8]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSetSystemPowerState [0x8BA0398E]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwShutdownSystem [0x8BA0391C]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSuspendProcess [0x8BA05566]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSuspendThread [0x8BA056C8]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwSystemDebugControl [0x8BA03A16]
SSDT \??\C:\Windows\system32\drivers\aswSP.sys ZwTerminateProcess [0x8BABA2D8]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwTerminateThread [0x8BA051F6]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwVdmControl [0x8BA03CCE]
SSDT \??\C:\Windows\system32\drivers\aswSnx.sys ZwWriteVirtualMemory [0x8BA0460A]
---- Kernel code sections - GMER 2.1 ----
.text ntoskrnl.exe!ZwRollbackEnlistment + 1409 820409A5 1 Byte [06]
.text ntoskrnl.exe!KiDispatchInterrupt + 5A2 82060512 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3}
.text ntoskrnl.exe!KeRemoveQueueEx + 1393 82067988 4 Bytes [D0, 3A, A0, 8B]
.text ntoskrnl.exe!KeRemoveQueueEx + 141B 82067A10 4 Bytes [AE, 45, A0, 8B]
.text ntoskrnl.exe!KeRemoveQueueEx + 146F 82067A64 8 Bytes [E0, 05, A1, 8B, 2C, 06, A1, ...]
.text ntoskrnl.exe!KeRemoveQueueEx + 147B 82067A70 4 Bytes [C6, 07, A1, 8B]
.text ntoskrnl.exe!KeRemoveQueueEx + 1497 82067A8C 4 Bytes [4E, 05, A1, 8B]
.text ...
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\csrss.exe[468] kernel32.dll!GetBinaryTypeW + 70 764D69E4 1 Byte [62]
.text C:\Windows\system32\wininit.exe[512] kernel32.dll!GetBinaryTypeW + 70 764D69E4 1 Byte [62]
.text C:\Windows\system32\csrss.exe[520] kernel32.dll!GetBinaryTypeW + 70 764D69E4 1 Byte [62]
.text C:\Windows\system32\services.exe[568] kernel32.dll!GetBinaryTypeW + 70 764D69E4 1 Byte [62]
.text C:\Windows\system32\winlogon.exe[600] kernel32.dll!GetBinaryTypeW + 70 764D69E4 1 Byte [62]
.text ...
---- EOF - GMER 2.1 ---- |