|
Plagegeister aller Art und deren Bekämpfung: Internet total langsamWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
07.07.2013, 20:50 | #46 |
/// the machine /// TB-Ausbilder | Internet total langsam Poste mal ein frisches FRST Log. Wir bekommen das bstimmt hin, aber wenn die dir ein so verbogenes Ding andrehen wäre sauber installieren die bessere Alternative.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.07.2013, 21:45 | #47 |
| Internet total langsam Hi schrauber,
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013 Ran by asus pro 5if (administrator) on 07-07-2013 22:43:51 Running from C:\Users\asus pro 5if\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe (ASUS) C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe () C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe () C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe (4G Systems GmbH & Co. KG) C:\Windows\starter4g.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUS) C:\Windows\AsScrPro.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe () C:\Program Files (x86)\XSManager\WTGService.exe (4G Systems GmbH & Co. KG) C:\Windows\service4g.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe [649608 2010-06-10] (ELAN Microelectronic Corp.) HKLM\...\Run: [ASUS WebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-16] () HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-19] () HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1928976 2010-03-05] (Intel(R) Corporation) HKLM\...\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd [x] HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" [87336 2009-07-06] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2010-06-25] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [Boingo Wi-Fi] "C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2429 2010-10-12] () HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS) HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-08-12] () HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2011-09-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [starter4g] C:\Windows\starter4g.exe [160992 2010-07-08] (4G Systems GmbH & Co. KG) HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-11-02] (CyberLink) HKLM-x32\...\Run: [ADSMTray] C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [272952 2009-06-24] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [3054136 2010-10-12] (ASUS) HKU\Gast\...\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe [370480 2010-04-05] (syncables, LLC) HKU\Gast\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x] ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 83.169.184.225 83.169.184.161 Chrome: ======= CHR HomePage: "homepage": null, CHR DefaultSearchURL: (Delta Search) - hxxp://www.yd.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=E220001E64563571&affID=119392&tt=040713_rdrctful&tsp=4934 CHR DefaultSuggestURL: (Delta Search) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Extension: (Skype Click to Call) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0 CHR Extension: (Amazon 1Button App for Chrome) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam\3.2013.627.0_0 ==================== Services (Whitelisted) ================= R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] () R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-03-05] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] () S3 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () R2 WTGService; C:\Program Files (x86)\XSManager\WTGService.exe [329168 2010-04-12] () R2 XS Stick Service; C:\Windows\service4g.exe [145120 2010-07-08] (4G Systems GmbH & Co. KG) ==================== Drivers (Whitelisted) ==================== S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2011-11-21] (Mobile Connector) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () S3 catchme; \??\C:\ComboFix\catchme.sys [x] U2 ezGOSvc; ==================== NetSvcs (Whitelisted) =================== NETSVC: ezGOSvc -> No ServiceDLL Path. ==================== One Month Created Files and Folders ======== 2013-07-07 21:49 - 2013-07-07 21:49 - 00095168 ____A C:\Users\asus pro 5if\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-07 21:48 - 2013-07-07 22:41 - 00000112 ____A C:\Windows\setupact.log 2013-07-07 21:48 - 2013-07-07 21:48 - 00358904 ____A C:\Windows\System32\FNTCACHE.DAT 2013-07-07 21:48 - 2013-07-07 21:48 - 00000000 ____A C:\Windows\setuperr.log 2013-07-07 21:47 - 2013-07-07 21:47 - 00001863 ____A C:\AdwCleaner[S7].txt 2013-07-07 11:45 - 2013-07-07 11:45 - 00001079 ____A C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Program Files\VS Revo Group 2013-07-07 11:45 - 2009-12-30 11:21 - 00031800 ____A (VS Revo Group) C:\Windows\System32\Drivers\revoflt.sys 2013-07-06 22:41 - 2013-07-06 22:41 - 00005794 ____A C:\AdwCleaner[S6].txt 2013-07-06 22:40 - 2013-07-06 22:40 - 00650027 ____A C:\Users\asus pro 5if\Desktop\adwcleaner.exe 2013-07-06 13:37 - 2013-07-06 13:37 - 00000002 ____A C:\AvastSetup.log 2013-07-06 13:31 - 2013-07-06 13:36 - 06604352 ____A (AVAST Software) C:\Users\asus pro 5if\Desktop\avast_free_antivirus_setup_online.exe 2013-07-06 06:34 - 2013-07-07 15:56 - 00000000 ____D C:\Windows\Minidump 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-04 22:11 - 2013-07-04 22:12 - 00760775 ____A (Farbar) C:\Users\asus pro 5if\Desktop\MiniToolBox.exe 2013-07-04 22:06 - 2013-07-07 11:38 - 00448512 ____A (OldTimer Tools) C:\Users\asus pro 5if\Desktop\TFC.exe 2013-07-04 22:05 - 2013-07-04 22:05 - 00522216 ____A C:\Users\asus pro 5if\Desktop\Zipper.exe 2013-07-04 07:43 - 2013-07-04 07:43 - 00165376 ____A C:\Users\asus pro 5if\Desktop\SystemLook_x64.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 01093032 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00972712 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00000000 ____D C:\Program Files\Java 2013-07-03 20:51 - 2013-07-03 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-03 20:50 - 2013-07-03 20:52 - 00890988 ____A C:\Users\asus pro 5if\Desktop\SecurityCheck.exe 2013-07-03 19:34 - 2013-07-03 19:34 - 02347384 ____A (ESET) C:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe 2013-07-03 19:07 - 2013-07-06 22:46 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\asus pro 5if\Desktop\JRT.exe 2013-07-03 19:07 - 2013-07-06 22:46 - 00000000 ____D C:\JRT 2013-07-03 19:07 - 2013-07-03 19:07 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 19:01 - 2013-07-03 19:01 - 00002865 ____A C:\AdwCleaner[S5].txt 2013-07-03 19:00 - 2013-07-03 19:01 - 00002931 ____A C:\AdwCleaner[R5].txt 2013-07-03 19:00 - 2013-07-03 19:00 - 00002871 ____A C:\AdwCleaner[R4].txt 2013-07-03 18:47 - 2013-07-03 18:47 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-07-03 18:46 - 2013-07-03 18:47 - 00774592 ____A C:\Users\asus pro 5if\Downloads\ZipOpenerSetup.exe 2013-07-03 18:30 - 2013-07-03 18:30 - 00001111 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-03 18:30 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2013-07-03 18:27 - 2013-07-03 18:27 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\asus pro 5if\Desktop\mbam-setup-1.75.0.1300.exe 2013-07-02 19:55 - 2013-07-02 20:27 - 00000000 ____D C:\ComboFix 2013-07-02 19:55 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-07-02 19:55 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-07-02 19:55 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-07-02 19:54 - 2013-07-02 20:27 - 00000000 ____D C:\Qoobox 2013-07-02 19:54 - 2013-07-02 20:21 - 00000000 ____D C:\Windows\erdnt 2013-07-02 19:49 - 2013-07-02 19:53 - 05084414 ____R (Swearware) C:\Users\asus pro 5if\Desktop\ComboFix.exe 2013-07-02 18:59 - 2013-07-07 14:49 - 00000000 ____D C:\FRST 2013-07-02 18:57 - 2013-07-06 10:18 - 01934636 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-02 11:22 - 2013-07-02 11:23 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-05 18:16 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:37 - 2013-07-01 19:40 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:35 - 2012-07-25 12:03 - 00016896 ____A C:\Windows\System32\sasnative64.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:33 - 2013-07-02 14:18 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-01 19:33 - 2013-05-27 16:01 - 00020312 ____A (Systweak Inc., (www.systweak.com)) C:\Windows\System32\roboot64.exe 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-07-01 19:19 - 2013-06-27 07:14 - 00031816 ____A C:\Windows\Launcher.exe 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 21:59 - 2013-06-27 22:00 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:23 - 2013-04-23 22:06 - 00000567 ____A C:\zoek-results23.04.2013-2206.log 2013-06-27 20:07 - 2013-06-27 20:08 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:44 - 2013-06-27 19:45 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:43 - 2013-06-27 19:44 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-20 19:23 - 2013-07-07 17:13 - 00002098 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt ==================== One Month Modified Files and Folders ======= 2013-07-07 22:44 - 2010-10-12 21:13 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-07 22:41 - 2013-07-07 21:48 - 00000112 ____A C:\Windows\setupact.log 2013-07-07 22:41 - 2010-10-12 21:13 - 00001120 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-07 22:41 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-07 21:49 - 2013-07-07 21:49 - 00095168 ____A C:\Users\asus pro 5if\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-07 21:48 - 2013-07-07 21:48 - 00358904 ____A C:\Windows\System32\FNTCACHE.DAT 2013-07-07 21:48 - 2013-07-07 21:48 - 00000000 ____A C:\Windows\setuperr.log 2013-07-07 21:47 - 2013-07-07 21:47 - 00001863 ____A C:\AdwCleaner[S7].txt 2013-07-07 21:47 - 2010-10-12 20:50 - 01559293 ____A C:\Windows\WindowsUpdate.log 2013-07-07 21:10 - 2012-07-02 22:16 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-07 17:13 - 2013-06-20 19:23 - 00002098 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt 2013-07-07 15:56 - 2013-07-06 06:34 - 00000000 ____D C:\Windows\Minidump 2013-07-07 15:00 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-07 15:00 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-07 14:49 - 2013-07-02 18:59 - 00000000 ____D C:\FRST 2013-07-07 11:45 - 2013-07-07 11:45 - 00001079 ____A C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Program Files\VS Revo Group 2013-07-07 11:40 - 2011-08-01 23:49 - 00045056 ____A C:\Windows\System32\acovcnt.exe 2013-07-07 11:40 - 2010-10-12 21:13 - 00000000 ____D C:\Program Files\Google 2013-07-07 11:40 - 2010-10-12 21:13 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-07 11:38 - 2013-07-04 22:06 - 00448512 ____A (OldTimer Tools) C:\Users\asus pro 5if\Desktop\TFC.exe 2013-07-07 11:22 - 2010-10-12 21:45 - 00000000 ____D C:\Windows\SysWOW64\K_Series_ScreenSaver_EN dir 2013-07-07 11:20 - 2011-07-27 03:26 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Google 2013-07-07 11:20 - 2010-10-12 21:13 - 00000000 ____D C:\ProgramData\Google 2013-07-07 11:12 - 2010-10-12 21:43 - 00000000 ____D C:\Program Files\ASUS 2013-07-06 22:46 - 2013-07-03 19:07 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\asus pro 5if\Desktop\JRT.exe 2013-07-06 22:46 - 2013-07-03 19:07 - 00000000 ____D C:\JRT 2013-07-06 22:41 - 2013-07-06 22:41 - 00005794 ____A C:\AdwCleaner[S6].txt 2013-07-06 22:40 - 2013-07-06 22:40 - 00650027 ____A C:\Users\asus pro 5if\Desktop\adwcleaner.exe 2013-07-06 13:37 - 2013-07-06 13:37 - 00000002 ____A C:\AvastSetup.log 2013-07-06 13:36 - 2013-07-06 13:31 - 06604352 ____A (AVAST Software) C:\Users\asus pro 5if\Desktop\avast_free_antivirus_setup_online.exe 2013-07-06 13:01 - 2011-10-22 03:59 - 00000000 ____D C:\ProgramData\Avira 2013-07-06 12:59 - 2011-12-11 13:17 - 00000000 ____D C:\Program Files (x86)\Pontifex II 2013-07-06 10:33 - 2012-07-02 22:16 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-07-06 10:33 - 2011-10-12 11:51 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-07-06 10:33 - 2011-07-31 07:09 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Adobe 2013-07-06 10:18 - 2013-07-02 18:57 - 01934636 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-05 18:16 - 2013-07-01 19:44 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-05 18:16 - 2013-07-01 19:44 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-04 22:12 - 2013-07-04 22:11 - 00760775 ____A (Farbar) C:\Users\asus pro 5if\Desktop\MiniToolBox.exe 2013-07-04 22:05 - 2013-07-04 22:05 - 00522216 ____A C:\Users\asus pro 5if\Desktop\Zipper.exe 2013-07-04 20:36 - 2011-08-03 17:01 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Skype 2013-07-04 07:43 - 2013-07-04 07:43 - 00165376 ____A C:\Users\asus pro 5if\Desktop\SystemLook_x64.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 01093032 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00972712 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00000000 ____D C:\Program Files\Java 2013-07-03 22:38 - 2011-07-27 05:31 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\SoftGrid Client 2013-07-03 21:33 - 2009-08-04 11:51 - 00697550 ____A C:\Windows\System32\perfh007.dat 2013-07-03 21:33 - 2009-08-04 11:51 - 00148556 ____A C:\Windows\System32\perfc007.dat 2013-07-03 21:33 - 2009-07-14 07:13 - 01614964 ____A C:\Windows\System32\PerfStringBackup.INI 2013-07-03 21:26 - 2011-08-06 07:22 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Paint.NET 2013-07-03 20:52 - 2013-07-03 20:50 - 00890988 ____A C:\Users\asus pro 5if\Desktop\SecurityCheck.exe 2013-07-03 20:51 - 2013-07-03 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-03 19:34 - 2013-07-03 19:34 - 02347384 ____A (ESET) C:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe 2013-07-03 19:07 - 2013-07-03 19:07 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 19:01 - 2013-07-03 19:01 - 00002865 ____A C:\AdwCleaner[S5].txt 2013-07-03 19:01 - 2013-07-03 19:00 - 00002931 ____A C:\AdwCleaner[R5].txt 2013-07-03 19:00 - 2013-07-03 19:00 - 00002871 ____A C:\AdwCleaner[R4].txt 2013-07-03 18:47 - 2013-07-03 18:47 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-07-03 18:47 - 2013-07-03 18:46 - 00774592 ____A C:\Users\asus pro 5if\Downloads\ZipOpenerSetup.exe 2013-07-03 18:30 - 2013-07-03 18:30 - 00001111 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-03 18:27 - 2013-07-03 18:27 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\asus pro 5if\Desktop\mbam-setup-1.75.0.1300.exe 2013-07-02 20:27 - 2013-07-02 19:55 - 00000000 ____D C:\ComboFix 2013-07-02 20:27 - 2013-07-02 19:54 - 00000000 ____D C:\Qoobox 2013-07-02 20:21 - 2013-07-02 19:54 - 00000000 ____D C:\Windows\erdnt 2013-07-02 20:10 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-07-02 19:53 - 2013-07-02 19:49 - 05084414 ____R (Swearware) C:\Users\asus pro 5if\Desktop\ComboFix.exe 2013-07-02 14:18 - 2013-07-01 19:33 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-02 11:23 - 2013-07-02 11:22 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:40 - 2013-07-01 19:37 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 22:00 - 2013-06-27 21:59 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:23 - 2013-04-23 18:49 - 00000393 ____A C:\zoek-results.log 2013-06-27 20:08 - 2013-06-27 20:07 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:04 - 2009-07-29 08:03 - 00000000 ____D C:\Windows\Panther 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:45 - 2013-06-27 19:44 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:44 - 2013-06-27 19:43 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:29 - 2011-08-03 17:01 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-27 19:29 - 2011-08-03 17:00 - 00000000 ____D C:\ProgramData\Skype 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-27 07:14 - 2013-07-01 19:19 - 00031816 ____A C:\Windows\Launcher.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-03 08:24 ==================== End Of Log ============================ FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-07-2013 Ran by asus pro 5if at 2013-07-07 22:44:22 Running from C:\Users\asus pro 5if\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 1.6.65) Adobe AIR (x32 Version: 1.5.0.7220) Adobe Flash Player 10 ActiveX (x32 Version: 10.0.42.34) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Reader 9.4.6 MUI (x32 Version: 9.4.6) ASUS AI Recovery (x32 Version: 1.0.24) ASUS CopyProtect (x32 Version: 1.0.0015) ASUS Data Security Manager (x32 Version: 1.00.0014) ASUS FancyStart (x32 Version: 1.0.8) ASUS LifeFrame3 (x32 Version: 3.0.20) ASUS Live Update (x32 Version: 2.5.9) ASUS MultiFrame (x32 Version: 1.0.0021) ASUS Power4Gear Hybrid (Version: 1.1.37) ASUS SmartLogon (x32 Version: 1.0.0008) ASUS Splendid Video Enhancement Technology (x32 Version: 1.02.0028) ASUS Video Magic (x32 Version: 6.0.4015) ASUS Virtual Camera (x32 Version: 1.0.20) ASUS WebStorage (x32 Version: 2.0.46.1429) ATK Package (x32 Version: 1.0.0006) AutoCAD 2012 - Deutsch (Version: 18.2.51.0) AutoCAD 2012 Language Pack - Deutsch (Version: 18.2.51.0) Autodesk Content Service (x32 Version: 2.0.90) Autodesk Material Library 2012 (x32 Version: 2.5.0.8) Autodesk Material Library Base Resolution Image Library 2012 (x32 Version: 2.5.0.8) Boingo Wi-Fi (x32 Version: 1.7.0048) CCleaner (Version: 4.03) Choice Guard (x32 Version: 1.2.87.0) Conexant HD Audio (Version: 4.111.0.63) ControlDeck (x32 Version: 1.0.8) CyberLink LabelPrint (x32 Version: 2.5.1908) CyberLink MediaShow Espresso (x32 Version: 5.0.1606_25588) CyberLink PhotoNow (x32 Version: 1.1.6904) CyberLink Power2Go (x32 Version: 6.1.3602c) CyberLink PowerDirector (x32 Version: 8.0.2609a) CyberLink PowerDVD 9 (x32 Version: 9.0.3009.50) EasyBits GO (HKCU) ETDWare PS/2-x64 7.0.5.13_WHQL (Version: 7.0.5.13) FARO LS 1.1.406.58 (x32 Version: 4.6.58.2) FLV-Media Player 1.8 (x32 Version: 1.8) Google Chrome (x32 Version: 27.0.1453.116) Google Update Helper (x32 Version: 1.3.21.145) Iminent (x32 Version: 6.25.21.0) Intel PROSet Wireless Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Graphics Media Accelerator Driver (x32 Version: 8.15.10.2125) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) PROSet/Wireless WiFi Software (Version: 13.02.0000) Intel(R) Wireless Display (Version: 1.2.20.0) Java 7 Update 25 (64-bit) (Version: 7.0.250) JMicron Ethernet Adapter NDIS Driver (x32 Version: 6.0.17.1) JMicron Flash Media Controller Driver (x32 Version: 1.0.33.2) Junk Mail filter update (x32 Version: 14.0.8050.1202) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000) Microsoft Silverlight (x32 Version: 4.1.10111.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Sync Framework Runtime Native v1.0 (x86) (x32 Version: 1.0.1215.0) Microsoft Sync Framework Services Native v1.0 (x86) (x32 Version: 1.0.1215.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) MSVCRT (x32 Version: 14.0.1468.721) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) NB Probe (x32) Net4Switch (x32 Version: 1.00.0020) Open It! (x32 Version: 1.1.1) Opera 12.15 (x32 Version: 12.15.1748) Paint.NET v3.5.8 (Version: 3.58.0) Revo Uninstaller Pro 3.0.5 (Version: 3.0.5) Skype Click to Call (x32 Version: 5.10.9560) Skype™ 6.5 (x32 Version: 6.5.158) syncables desktop SE (x32 Version: 5.5.615.9518) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Zip Opener (HKCU) USB2.0 UVC VGA WebCam (Version: 5.8.54000.207) VLC media player 1.1.11 (x32 Version: 1.1.11) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.6) Windows Live Call (x32 Version: 14.0.8050.1202) Windows Live Communications Platform (x32 Version: 14.0.8050.1202) Windows Live Essentials (x32 Version: 14.0.8050.1202) Windows Live Family Safety (Version: 14.0.8052.1208) Windows Live Fotogalerie (x32 Version: 14.0.8051.1204) Windows Live Mail (x32 Version: 14.0.8050.1202) Windows Live Messenger (x32 Version: 14.0.8050.1202) Windows Live Sync (x32 Version: 14.0.8050.1202) Windows Live Writer (x32 Version: 14.0.8050.1202) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029) WinFlash (x32 Version: 2.30.3) WinRAR 4.20 (32-Bit) (x32 Version: 4.20.0) Wireless Console 3 (x32 Version: 3.0.18) XSManager (x32 Version: 3.0) ==================== Restore Points ========================= 01-07-2013 17:17:34 Free System Utilities 01-07-2013 17:29:31 Free System Utilities 01.07.2013 19:29:29 01-07-2013 17:30:43 Free System Utilities 01.07.2013 19:30:42 01-07-2013 17:34:30 RegClean Pro Mo, Jul 01, 13 19:34 03-07-2013 20:51:55 Installed Java 7 Update 25 (64-bit) 07-07-2013 09:12:23 Removed Fast Boot 07-07-2013 09:30:03 Free System Utilities ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-07-02 20:09 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {12DABD06-C8D2-462E-937F-3FBADA8A559B} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] () Task: {24A34CFE-2CBD-4913-9E96-5861F6F5F99C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-05-28] (ATK) Task: {24CC42E7-515E-4C08-8365-D1A50F36E458} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {2B2AA4C6-9B2F-4725-9B63-1BE51240A6A8} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe No File Task: {324E82F7-D064-44D5-BA77-75826922E3CA} - System32\Tasks\ASUSControlDeck => C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe [2010-06-09] (asus) Task: {3951030E-CB71-486D-B3D8-8AF547C9905D} - System32\Tasks\{78ABA6A5-01CC-4830-ABA9-AAEEAAFA3211} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-06-03] (Skype Technologies S.A.) Task: {433DA0EA-37B2-4EB0-A90C-D4008A1BD429} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe No File Task: {4827FB5B-6911-4ABF-A52C-339F77BBDD17} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {52FC4F05-4CEA-4A42-9741-6D0D7BF5A73D} - System32\Tasks\Net4Switch => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe [2009-09-23] (ASUS) Task: {699264D4-0D35-4784-AD7F-8CBF3D5E29A4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {6B60EE87-CF7B-496D-932A-82D77CFB20BC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-06] (Adobe Systems Incorporated) Task: {765D21BA-0C98-45DD-A5A2-C1AD88B0DCEC} - System32\Tasks\{26D6A9BB-3CFC-4286-AB29-46DF1F2FA2DE} => C:\program files (x86)\opera\opera.exe [2013-04-09] (Opera Software) Task: {79492728-14A4-4634-B22B-234AB4A0FEA2} - System32\Tasks\ASPG => C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS) Task: {7CA210CD-3096-4280-A903-23CFFF2FB634} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {80C1B2D2-609C-4064-960D-6C79413850B3} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe No File Task: {A585B730-AA46-4D11-A49C-B597D9067F7A} - System32\Tasks\Software Updater => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe No File Task: {A738714F-FDF5-4018-89D1-C58261B4A148} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {B02BD60F-1E22-4AA8-A1E8-9D11BC6CF3D8} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2009-07-14] (Microsoft Corporation) Task: {B92D7D8E-825D-4858-B1E5-577192A364A8} - System32\Tasks\AIRecoveryRemind => C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe [2012-03-09] (ASUSTek Computer Inc.) Task: {BFD2AAB0-9059-4444-8B96-E22B494E7A1B} - System32\Tasks\Freemium1ClickMaint => C:\Users\asus pro 5if\Downloads\1Click.exe No File Task: {DC2F45BA-04CC-414C-9B50-10F48095D6FA} - System32\Tasks\Software Updater Ui => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Ui.exe No File Task: {DF45D3D6-E963-44A8-9F0D-D49D1EE068CB} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-07-31] (ASUS) Task: {E2B3EB42-00D0-4770-9664-63BE47C60241} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK) Task: {F46AB22C-23A3-4EE7-BF5A-C9FA3785801E} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-08-04] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Net4Switch.job => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service) (User: ) Description: Das Gatherer-Objekt kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service) (User: ) Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=4700} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Der Jet-Eigenschaftenspeicher kann von Windows Search nicht geöffnet werden. Details: 0x%08x (0xc0041800 - Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800)) Error: (07/07/2013 09:49:17 PM) (Source: ESENT) (User: ) Description: Windows (4312) Windows: Fehler -1811 beim Öffnen von Protokolldatei C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0000A.log. System errors: ============= Error: (07/07/2013 10:42:07 PM) (Source: DCOM) (User: ) Description: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Error: (07/07/2013 09:49:35 PM) (Source: DCOM) (User: ) Description: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Error: (07/07/2013 09:49:20 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/07/2013 09:49:18 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535. Error: (07/07/2013 02:54:15 PM) (Source: DCOM) (User: ) Description: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Error: (07/07/2013 02:43:18 PM) (Source: DCOM) (User: ) Description: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Error: (07/07/2013 02:41:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (07/07/2013 02:41:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (07/07/2013 02:41:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (07/07/2013 02:41:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Microsoft Office Sessions: ========================= Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Search.TripoliIndexer Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Search.JetPropStore Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) The catalog is corrupt Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) 4700 Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Details: 0x%08x (0xc0041800 - Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800)) Error: (07/07/2013 09:49:17 PM) (Source: ESENT)(User: ) Description: Windows4312Windows: C:\ProgramData\Microsoft\Search\Data\Applications\Windows\MSS0000A.log-1811 CodeIntegrity Errors: =================================== Date: 2013-07-02 20:04:39.311 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-07-02 20:04:39.264 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 2924.56 MB Available physical RAM: 1579.05 MB Total Pagefile: 5847.26 MB Available Pagefile: 4174.23 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:72.69 GB) (Free:39.58 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:205.87 GB) (Free:203.68 GB) NTFS (Disk=0 Partition=3) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 0237A506) Partition 1: (Not Active) - (Size=20 GB) - (Type=1C) Partition 2: (Active) - (Size=73 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=206 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
08.07.2013, 07:58 | #48 | |
/// the machine /// TB-Ausbilder | Internet total langsamZitat:
__________________ |
08.07.2013, 18:37 | #49 |
| Internet total langsam Hi schrauber, nö kenn ich net. Noch nie benutzt. Aber ich habs grad mal gegoogelt: hxxp://boingo-wireless.softonic.de/ "Boingo Wireless macht kabellose Netzwerke in der Umgebung ausfindig. Das kostenlose Programm stellt automatisch eine Verbindung her. Das kleine Werkzeug identifiziert automatisch Wireless-LANs und verbindet sich automatisch mit unterschiedlichen eingestellten WLAN-Netzen – sei es das Firmennetzwerk oder die Verbindung zuhause. Zudem erkennt Boingo automatisch, in Nähe welches Netzes man sich gerade befindet und stellt selbstständig eine Verbindung her. Dabei unterstützt Boingo Wireless sowohl WEP und WPA als auch 802.1x-Verbindungen. Fazit Boingo Wireless findet WLAN-Verbindungen schnell und zuverlässig. Ein praktischer Helfer für Laptop-Besitzer." |
08.07.2013, 18:43 | #50 |
/// the machine /// TB-Ausbilder | Internet total langsam Deinstallieren, ebenso alles deinstallieren was Du nicht brauchst oder kennst. rebooten und ein frisches FRST Log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.07.2013, 19:05 | #51 |
| Internet total langsam N´Abend. FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013 Ran by asus pro 5if (administrator) on 08-07-2013 20:03:46 Running from C:\Users\asus pro 5if\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe (ASUS) C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe () C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUS) C:\Windows\AsScrPro.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe [649608 2010-06-10] (ELAN Microelectronic Corp.) HKLM\...\Run: [ASUS WebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-16] () HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-19] () HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1928976 2010-03-05] (Intel(R) Corporation) HKLM\...\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd [x] HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" [87336 2009-07-06] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2010-06-25] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [Boingo Wi-Fi] "C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2429 2010-10-12] () HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS) HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-08-12] () HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2011-09-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-11-02] (CyberLink) HKLM-x32\...\Run: [ADSMTray] C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [272952 2009-06-24] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [3054136 2010-10-12] (ASUS) HKU\Gast\...\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe [370480 2010-04-05] (syncables, LLC) HKU\Gast\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x] ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 83.169.184.225 83.169.184.161 Chrome: ======= CHR HomePage: "homepage": null, CHR DefaultSearchURL: (Delta Search) - hxxp://www.yd.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=E220001E64563571&affID=119392&tt=040713_rdrctful&tsp=4934 CHR DefaultSuggestURL: (Delta Search) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Extension: (Skype Click to Call) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0 CHR Extension: (Amazon 1Button App for Chrome) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam\3.2013.627.0_0 ==================== Services (Whitelisted) ================= R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-03-05] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] () S3 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () ==================== Drivers (Whitelisted) ==================== S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2011-11-21] (Mobile Connector) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-08 19:57 - 2013-07-08 19:57 - 00000040 ____A C:\Users\Public\Documents\_rgpl 2013-07-07 21:49 - 2013-07-07 21:49 - 00095168 ____A C:\Users\asus pro 5if\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-07 21:48 - 2013-07-07 22:41 - 00000112 ____A C:\Windows\setupact.log 2013-07-07 21:48 - 2013-07-07 21:48 - 00358904 ____A C:\Windows\System32\FNTCACHE.DAT 2013-07-07 21:48 - 2013-07-07 21:48 - 00000000 ____A C:\Windows\setuperr.log 2013-07-07 21:47 - 2013-07-07 21:47 - 00001863 ____A C:\AdwCleaner[S7].txt 2013-07-07 11:45 - 2013-07-07 11:45 - 00001079 ____A C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Program Files\VS Revo Group 2013-07-07 11:45 - 2009-12-30 11:21 - 00031800 ____A (VS Revo Group) C:\Windows\System32\Drivers\revoflt.sys 2013-07-06 22:41 - 2013-07-06 22:41 - 00005794 ____A C:\AdwCleaner[S6].txt 2013-07-06 22:40 - 2013-07-06 22:40 - 00650027 ____A C:\Users\asus pro 5if\Desktop\adwcleaner.exe 2013-07-06 13:37 - 2013-07-06 13:37 - 00000002 ____A C:\AvastSetup.log 2013-07-06 13:31 - 2013-07-06 13:36 - 06604352 ____A (AVAST Software) C:\Users\asus pro 5if\Desktop\avast_free_antivirus_setup_online.exe 2013-07-06 06:34 - 2013-07-07 15:56 - 00000000 ____D C:\Windows\Minidump 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-04 22:11 - 2013-07-04 22:12 - 00760775 ____A (Farbar) C:\Users\asus pro 5if\Desktop\MiniToolBox.exe 2013-07-04 22:06 - 2013-07-07 11:38 - 00448512 ____A (OldTimer Tools) C:\Users\asus pro 5if\Desktop\TFC.exe 2013-07-04 22:05 - 2013-07-04 22:05 - 00522216 ____A C:\Users\asus pro 5if\Desktop\Zipper.exe 2013-07-04 07:43 - 2013-07-04 07:43 - 00165376 ____A C:\Users\asus pro 5if\Desktop\SystemLook_x64.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 01093032 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00972712 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00000000 ____D C:\Program Files\Java 2013-07-03 20:51 - 2013-07-03 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-03 20:50 - 2013-07-03 20:52 - 00890988 ____A C:\Users\asus pro 5if\Desktop\SecurityCheck.exe 2013-07-03 19:34 - 2013-07-03 19:34 - 02347384 ____A (ESET) C:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe 2013-07-03 19:07 - 2013-07-06 22:46 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\asus pro 5if\Desktop\JRT.exe 2013-07-03 19:07 - 2013-07-06 22:46 - 00000000 ____D C:\JRT 2013-07-03 19:07 - 2013-07-03 19:07 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 19:01 - 2013-07-03 19:01 - 00002865 ____A C:\AdwCleaner[S5].txt 2013-07-03 19:00 - 2013-07-03 19:01 - 00002931 ____A C:\AdwCleaner[R5].txt 2013-07-03 19:00 - 2013-07-03 19:00 - 00002871 ____A C:\AdwCleaner[R4].txt 2013-07-03 18:47 - 2013-07-03 18:47 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-07-03 18:46 - 2013-07-03 18:47 - 00774592 ____A C:\Users\asus pro 5if\Downloads\ZipOpenerSetup.exe 2013-07-03 18:30 - 2013-07-03 18:30 - 00001111 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-03 18:30 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2013-07-03 18:27 - 2013-07-03 18:27 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\asus pro 5if\Desktop\mbam-setup-1.75.0.1300.exe 2013-07-02 19:55 - 2013-07-02 20:27 - 00000000 ____D C:\ComboFix 2013-07-02 19:55 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-07-02 19:55 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-07-02 19:55 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-07-02 19:54 - 2013-07-02 20:27 - 00000000 ____D C:\Qoobox 2013-07-02 19:54 - 2013-07-02 20:21 - 00000000 ____D C:\Windows\erdnt 2013-07-02 19:49 - 2013-07-02 19:53 - 05084414 ____R (Swearware) C:\Users\asus pro 5if\Desktop\ComboFix.exe 2013-07-02 18:59 - 2013-07-07 14:49 - 00000000 ____D C:\FRST 2013-07-02 18:57 - 2013-07-06 10:18 - 01934636 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-02 11:22 - 2013-07-02 11:23 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-05 18:16 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:37 - 2013-07-01 19:40 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:35 - 2012-07-25 12:03 - 00016896 ____A C:\Windows\System32\sasnative64.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:33 - 2013-07-02 14:18 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-01 19:33 - 2013-05-27 16:01 - 00020312 ____A (Systweak Inc., (www.systweak.com)) C:\Windows\System32\roboot64.exe 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-07-01 19:19 - 2013-06-27 07:14 - 00031816 ____A C:\Windows\Launcher.exe 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 21:59 - 2013-06-27 22:00 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:23 - 2013-04-23 22:06 - 00000567 ____A C:\zoek-results23.04.2013-2206.log 2013-06-27 20:07 - 2013-06-27 20:08 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:44 - 2013-06-27 19:45 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:43 - 2013-06-27 19:44 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-20 19:23 - 2013-07-07 17:13 - 00002098 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt ==================== One Month Modified Files and Folders ======= 2013-07-08 19:57 - 2013-07-08 19:57 - 00000040 ____A C:\Users\Public\Documents\_rgpl 2013-07-08 19:57 - 2011-08-03 17:02 - 00000000 ____D C:\ProgramData\Skype Extras 2013-07-08 19:55 - 2010-10-12 20:50 - 01613162 ____A C:\Windows\WindowsUpdate.log 2013-07-08 19:54 - 2012-01-02 22:23 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared 2013-07-08 19:54 - 2012-01-02 22:03 - 00000000 ____D C:\ProgramData\Autodesk 2013-07-08 19:53 - 2012-01-02 22:03 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Autodesk 2013-07-08 19:51 - 2010-10-12 21:14 - 00000000 ____D C:\Program Files (x86)\ASUS 2013-07-08 19:44 - 2010-10-12 21:13 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-08 19:30 - 2012-07-02 22:16 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-08 12:44 - 2010-10-12 21:13 - 00001120 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-07 22:48 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-07 22:48 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-07 22:41 - 2013-07-07 21:48 - 00000112 ____A C:\Windows\setupact.log 2013-07-07 22:41 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-07 21:49 - 2013-07-07 21:49 - 00095168 ____A C:\Users\asus pro 5if\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-07 21:48 - 2013-07-07 21:48 - 00358904 ____A C:\Windows\System32\FNTCACHE.DAT 2013-07-07 21:48 - 2013-07-07 21:48 - 00000000 ____A C:\Windows\setuperr.log 2013-07-07 21:47 - 2013-07-07 21:47 - 00001863 ____A C:\AdwCleaner[S7].txt 2013-07-07 17:13 - 2013-06-20 19:23 - 00002098 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt 2013-07-07 15:56 - 2013-07-06 06:34 - 00000000 ____D C:\Windows\Minidump 2013-07-07 14:49 - 2013-07-02 18:59 - 00000000 ____D C:\FRST 2013-07-07 11:45 - 2013-07-07 11:45 - 00001079 ____A C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Program Files\VS Revo Group 2013-07-07 11:40 - 2011-08-01 23:49 - 00045056 ____A C:\Windows\System32\acovcnt.exe 2013-07-07 11:40 - 2010-10-12 21:13 - 00000000 ____D C:\Program Files\Google 2013-07-07 11:40 - 2010-10-12 21:13 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-07 11:38 - 2013-07-04 22:06 - 00448512 ____A (OldTimer Tools) C:\Users\asus pro 5if\Desktop\TFC.exe 2013-07-07 11:22 - 2010-10-12 21:45 - 00000000 ____D C:\Windows\SysWOW64\K_Series_ScreenSaver_EN dir 2013-07-07 11:20 - 2011-07-27 03:26 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Google 2013-07-07 11:20 - 2010-10-12 21:13 - 00000000 ____D C:\ProgramData\Google 2013-07-07 11:12 - 2010-10-12 21:43 - 00000000 ____D C:\Program Files\ASUS 2013-07-06 22:46 - 2013-07-03 19:07 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\asus pro 5if\Desktop\JRT.exe 2013-07-06 22:46 - 2013-07-03 19:07 - 00000000 ____D C:\JRT 2013-07-06 22:41 - 2013-07-06 22:41 - 00005794 ____A C:\AdwCleaner[S6].txt 2013-07-06 22:40 - 2013-07-06 22:40 - 00650027 ____A C:\Users\asus pro 5if\Desktop\adwcleaner.exe 2013-07-06 13:37 - 2013-07-06 13:37 - 00000002 ____A C:\AvastSetup.log 2013-07-06 13:36 - 2013-07-06 13:31 - 06604352 ____A (AVAST Software) C:\Users\asus pro 5if\Desktop\avast_free_antivirus_setup_online.exe 2013-07-06 13:01 - 2011-10-22 03:59 - 00000000 ____D C:\ProgramData\Avira 2013-07-06 12:59 - 2011-12-11 13:17 - 00000000 ____D C:\Program Files (x86)\Pontifex II 2013-07-06 10:33 - 2012-07-02 22:16 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-07-06 10:33 - 2011-10-12 11:51 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-07-06 10:33 - 2011-07-31 07:09 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Adobe 2013-07-06 10:18 - 2013-07-02 18:57 - 01934636 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-05 18:16 - 2013-07-01 19:44 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-05 18:16 - 2013-07-01 19:44 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-04 22:12 - 2013-07-04 22:11 - 00760775 ____A (Farbar) C:\Users\asus pro 5if\Desktop\MiniToolBox.exe 2013-07-04 22:05 - 2013-07-04 22:05 - 00522216 ____A C:\Users\asus pro 5if\Desktop\Zipper.exe 2013-07-04 20:36 - 2011-08-03 17:01 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Skype 2013-07-04 07:43 - 2013-07-04 07:43 - 00165376 ____A C:\Users\asus pro 5if\Desktop\SystemLook_x64.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 01093032 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00972712 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00000000 ____D C:\Program Files\Java 2013-07-03 22:38 - 2011-07-27 05:31 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\SoftGrid Client 2013-07-03 21:33 - 2009-08-04 11:51 - 00697550 ____A C:\Windows\System32\perfh007.dat 2013-07-03 21:33 - 2009-08-04 11:51 - 00148556 ____A C:\Windows\System32\perfc007.dat 2013-07-03 21:33 - 2009-07-14 07:13 - 01614964 ____A C:\Windows\System32\PerfStringBackup.INI 2013-07-03 21:26 - 2011-08-06 07:22 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Paint.NET 2013-07-03 20:52 - 2013-07-03 20:50 - 00890988 ____A C:\Users\asus pro 5if\Desktop\SecurityCheck.exe 2013-07-03 20:51 - 2013-07-03 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-03 19:34 - 2013-07-03 19:34 - 02347384 ____A (ESET) C:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe 2013-07-03 19:07 - 2013-07-03 19:07 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 19:01 - 2013-07-03 19:01 - 00002865 ____A C:\AdwCleaner[S5].txt 2013-07-03 19:01 - 2013-07-03 19:00 - 00002931 ____A C:\AdwCleaner[R5].txt 2013-07-03 19:00 - 2013-07-03 19:00 - 00002871 ____A C:\AdwCleaner[R4].txt 2013-07-03 18:47 - 2013-07-03 18:47 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-07-03 18:47 - 2013-07-03 18:46 - 00774592 ____A C:\Users\asus pro 5if\Downloads\ZipOpenerSetup.exe 2013-07-03 18:30 - 2013-07-03 18:30 - 00001111 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-03 18:27 - 2013-07-03 18:27 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\asus pro 5if\Desktop\mbam-setup-1.75.0.1300.exe 2013-07-02 20:27 - 2013-07-02 19:55 - 00000000 ____D C:\ComboFix 2013-07-02 20:27 - 2013-07-02 19:54 - 00000000 ____D C:\Qoobox 2013-07-02 20:21 - 2013-07-02 19:54 - 00000000 ____D C:\Windows\erdnt 2013-07-02 20:10 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-07-02 19:53 - 2013-07-02 19:49 - 05084414 ____R (Swearware) C:\Users\asus pro 5if\Desktop\ComboFix.exe 2013-07-02 14:18 - 2013-07-01 19:33 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-02 11:23 - 2013-07-02 11:22 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:40 - 2013-07-01 19:37 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 22:00 - 2013-06-27 21:59 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:23 - 2013-04-23 18:49 - 00000393 ____A C:\zoek-results.log 2013-06-27 20:08 - 2013-06-27 20:07 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:04 - 2009-07-29 08:03 - 00000000 ____D C:\Windows\Panther 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:45 - 2013-06-27 19:44 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:44 - 2013-06-27 19:43 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:29 - 2011-08-03 17:01 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-27 19:29 - 2011-08-03 17:00 - 00000000 ____D C:\ProgramData\Skype 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-27 07:14 - 2013-07-01 19:19 - 00031816 ____A C:\Windows\Launcher.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-03 08:24 ==================== End Of Log ============================ --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-07-2013 Ran by asus pro 5if at 2013-07-08 20:04:08 Running from C:\Users\asus pro 5if\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 1.6.65) Adobe AIR (x32 Version: 1.5.0.7220) Adobe Flash Player 10 ActiveX (x32 Version: 10.0.42.34) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Reader 9.4.6 MUI (x32 Version: 9.4.6) ASUS AI Recovery (x32 Version: 1.0.24) ASUS CopyProtect (x32 Version: 1.0.0015) ASUS Data Security Manager (x32 Version: 1.00.0014) ASUS FancyStart (x32 Version: 1.0.8) ASUS LifeFrame3 (x32 Version: 3.0.20) ASUS Live Update (x32 Version: 3.0.3) ASUS MultiFrame (x32 Version: 1.0.0021) ASUS Power4Gear Hybrid (Version: 1.1.37) ASUS SmartLogon (x32 Version: 1.0.0008) ASUS Splendid Video Enhancement Technology (x32 Version: 1.02.0028) ASUS Video Magic (x32 Version: 6.0.4015) ASUS Virtual Camera (x32 Version: 1.0.20) ASUS WebStorage (x32 Version: 2.0.46.1429) ATK Package (x32 Version: 1.0.0006) Boingo Wi-Fi (x32 Version: 1.7.0048) CCleaner (Version: 4.03) Choice Guard (x32 Version: 1.2.87.0) Conexant HD Audio (Version: 4.111.0.63) ControlDeck (x32 Version: 1.0.8) CyberLink LabelPrint (x32 Version: 2.5.1908) CyberLink MediaShow Espresso (x32 Version: 5.0.1606_25588) CyberLink PhotoNow (x32 Version: 1.1.6904) CyberLink Power2Go (x32 Version: 6.1.3602c) CyberLink PowerDirector (x32 Version: 8.0.2609a) CyberLink PowerDVD 9 (x32 Version: 9.0.3009.50) ETDWare PS/2-x64 7.0.5.13_WHQL (Version: 7.0.5.13) FLV-Media Player 1.8 (x32 Version: 1.8) Google Chrome (x32 Version: 27.0.1453.116) Google Update Helper (x32 Version: 1.3.21.145) Iminent (x32 Version: 6.25.21.0) Intel PROSet Wireless Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Graphics Media Accelerator Driver (x32 Version: 8.15.10.2125) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) PROSet/Wireless WiFi Software (Version: 13.02.0000) Intel(R) Wireless Display (Version: 1.2.20.0) Java 7 Update 25 (64-bit) (Version: 7.0.250) JMicron Ethernet Adapter NDIS Driver (x32 Version: 6.0.17.1) JMicron Flash Media Controller Driver (x32 Version: 1.0.33.2) Junk Mail filter update (x32 Version: 14.0.8050.1202) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000) Microsoft Silverlight (x32 Version: 4.1.10111.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Sync Framework Runtime Native v1.0 (x86) (x32 Version: 1.0.1215.0) Microsoft Sync Framework Services Native v1.0 (x86) (x32 Version: 1.0.1215.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) MSVCRT (x32 Version: 14.0.1468.721) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) NB Probe (x32) Net4Switch (x32 Version: 1.00.0020) Open It! (x32 Version: 1.1.1) Opera 12.15 (x32 Version: 12.15.1748) Paint.NET v3.5.8 (Version: 3.58.0) Revo Uninstaller Pro 3.0.5 (Version: 3.0.5) Skype Click to Call (x32 Version: 5.10.9560) Skype™ 6.5 (x32 Version: 6.5.158) syncables desktop SE (x32 Version: 5.5.615.9518) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Zip Opener (HKCU) USB2.0 UVC VGA WebCam (Version: 5.8.54000.207) VLC media player 1.1.11 (x32 Version: 1.1.11) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.6) Windows Live Call (x32 Version: 14.0.8050.1202) Windows Live Communications Platform (x32 Version: 14.0.8050.1202) Windows Live Essentials (x32 Version: 14.0.8050.1202) Windows Live Family Safety (Version: 14.0.8052.1208) Windows Live Fotogalerie (x32 Version: 14.0.8051.1204) Windows Live Mail (x32 Version: 14.0.8050.1202) Windows Live Messenger (x32 Version: 14.0.8050.1202) Windows Live Sync (x32 Version: 14.0.8050.1202) Windows Live Writer (x32 Version: 14.0.8050.1202) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029) WinFlash (x32 Version: 2.30.3) WinRAR 4.20 (32-Bit) (x32 Version: 4.20.0) Wireless Console 3 (x32 Version: 3.0.18) ==================== Restore Points ========================= 03-07-2013 20:51:55 Installed Java 7 Update 25 (64-bit) 07-07-2013 09:12:23 Removed Fast Boot 07-07-2013 09:30:03 Free System Utilities 08-07-2013 17:50:56 Installed ASUS Live Update 08-07-2013 17:54:38 Autodesk Content Service wird entfernt 08-07-2013 17:55:17 Removed Autodesk Material Library 2012. 08-07-2013 17:55:55 Removed Autodesk Material Library Base Resolution Image Library 2012. 08-07-2013 17:59:31 Removed FARO LS 1.1.406.58 ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-07-02 20:09 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {24A34CFE-2CBD-4913-9E96-5861F6F5F99C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-05-28] (ATK) Task: {24CC42E7-515E-4C08-8365-D1A50F36E458} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {2B2AA4C6-9B2F-4725-9B63-1BE51240A6A8} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe No File Task: {324E82F7-D064-44D5-BA77-75826922E3CA} - System32\Tasks\ASUSControlDeck => C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe [2010-06-09] (asus) Task: {3951030E-CB71-486D-B3D8-8AF547C9905D} - System32\Tasks\{78ABA6A5-01CC-4830-ABA9-AAEEAAFA3211} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-06-03] (Skype Technologies S.A.) Task: {433DA0EA-37B2-4EB0-A90C-D4008A1BD429} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe No File Task: {4429AA03-2279-4817-A8C8-45BA6621C69B} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {52FC4F05-4CEA-4A42-9741-6D0D7BF5A73D} - System32\Tasks\Net4Switch => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe [2009-09-23] (ASUS) Task: {699264D4-0D35-4784-AD7F-8CBF3D5E29A4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {6B60EE87-CF7B-496D-932A-82D77CFB20BC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-06] (Adobe Systems Incorporated) Task: {765D21BA-0C98-45DD-A5A2-C1AD88B0DCEC} - System32\Tasks\{26D6A9BB-3CFC-4286-AB29-46DF1F2FA2DE} => C:\program files (x86)\opera\opera.exe [2013-04-09] (Opera Software) Task: {79492728-14A4-4634-B22B-234AB4A0FEA2} - System32\Tasks\ASPG => C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS) Task: {7CA210CD-3096-4280-A903-23CFFF2FB634} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {80C1B2D2-609C-4064-960D-6C79413850B3} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe No File Task: {A585B730-AA46-4D11-A49C-B597D9067F7A} - System32\Tasks\Software Updater => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe No File Task: {A738714F-FDF5-4018-89D1-C58261B4A148} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {B02BD60F-1E22-4AA8-A1E8-9D11BC6CF3D8} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2009-07-14] (Microsoft Corporation) Task: {B78EE339-3FF1-4668-A11F-58350B88A23F} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-07-18] (ASUSTeK Computer Inc.) Task: {B92D7D8E-825D-4858-B1E5-577192A364A8} - System32\Tasks\AIRecoveryRemind => C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe [2012-03-09] (ASUSTek Computer Inc.) Task: {BFD2AAB0-9059-4444-8B96-E22B494E7A1B} - System32\Tasks\Freemium1ClickMaint => C:\Users\asus pro 5if\Downloads\1Click.exe No File Task: {DC2F45BA-04CC-414C-9B50-10F48095D6FA} - System32\Tasks\Software Updater Ui => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Ui.exe No File Task: {DF45D3D6-E963-44A8-9F0D-D49D1EE068CB} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-07-31] (ASUS) Task: {E2B3EB42-00D0-4770-9664-63BE47C60241} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK) Task: {F46AB22C-23A3-4EE7-BF5A-C9FA3785801E} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-08-04] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Net4Switch.job => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/08/2013 00:32:55 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service) (User: ) Description: Das Gatherer-Objekt kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service) (User: ) Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=4700} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Der Jet-Eigenschaftenspeicher kann von Windows Search nicht geöffnet werden. Details: 0x%08x (0xc0041800 - Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800)) System errors: ============= Error: (07/07/2013 10:42:07 PM) (Source: DCOM) (User: ) Description: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Error: (07/07/2013 09:49:35 PM) (Source: DCOM) (User: ) Description: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Error: (07/07/2013 09:49:20 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/07/2013 09:49:18 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535. Error: (07/07/2013 02:54:15 PM) (Source: DCOM) (User: ) Description: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Error: (07/07/2013 02:43:18 PM) (Source: DCOM) (User: ) Description: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Error: (07/07/2013 02:41:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (07/07/2013 02:41:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (07/07/2013 02:41:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (07/07/2013 02:41:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Microsoft Office Sessions: ========================= Error: (07/08/2013 00:32:55 AM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Search.TripoliIndexer Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Search.JetPropStore Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) The catalog is corrupt Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) 4700 Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Details: 0x%08x (0xc0041800 - Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800)) CodeIntegrity Errors: =================================== Date: 2013-07-02 20:04:39.311 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-07-02 20:04:39.264 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 48% Total physical RAM: 2924.56 MB Available physical RAM: 1499.19 MB Total Pagefile: 5847.26 MB Available Pagefile: 3926.88 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:72.69 GB) (Free:41.19 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:205.87 GB) (Free:205.54 GB) NTFS (Disk=0 Partition=3) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 0237A506) Partition 1: (Not Active) - (Size=20 GB) - (Type=1C) Partition 2: (Active) - (Size=73 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=206 GB) - (Type=OF Extended) ==================== End Of Log ============================ Gruß Hannes |
08.07.2013, 21:12 | #52 |
/// the machine /// TB-Ausbilder | Internet total langsam Boingo is ja immer noch drauf.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.07.2013, 21:33 | #53 |
| Internet total langsam Servus. Ähm, hatte es eigentlich deinstalliert. War aber wieder drauf komischerweise. Habs jetzt nochmal deinstalliert, und jetzt müsste es weg sein, oder ? FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-07-2013 Ran by asus pro 5if (administrator) on 08-07-2013 22:30:54 Running from C:\Users\asus pro 5if\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe () C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUS) C:\Windows\AsScrPro.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe [649608 2010-06-10] (ELAN Microelectronic Corp.) HKLM\...\Run: [ASUS WebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-16] () HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-19] () HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1928976 2010-03-05] (Intel(R) Corporation) HKLM\...\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd [x] HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" [87336 2009-07-06] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2010-06-25] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS) HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-08-12] () HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2011-09-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-11-02] (CyberLink) HKLM-x32\...\Run: [ADSMTray] C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [272952 2009-06-24] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [3054136 2010-10-12] (ASUS) HKU\Gast\...\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe [370480 2010-04-05] (syncables, LLC) HKU\Gast\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x] ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 83.169.184.225 83.169.184.161 Chrome: ======= CHR HomePage: "homepage": null, CHR DefaultSearchURL: (Delta Search) - hxxp://www.yd.delta-search.com/?q={searchTerms}&babsrc=SP_ss&mntrId=E220001E64563571&affID=119392&tt=040713_rdrctful&tsp=4934 CHR DefaultSuggestURL: (Delta Search) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Extension: (Skype Click to Call) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0 CHR Extension: (Amazon 1Button App for Chrome) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam\3.2013.627.0_0 ==================== Services (Whitelisted) ================= R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-03-05] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] () S3 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () ==================== Drivers (Whitelisted) ==================== S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2011-11-21] (Mobile Connector) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-08 20:04 - 2013-07-08 20:04 - 00020266 ____A C:\Users\asus pro 5if\Desktop\Addition.txt 2013-07-08 19:57 - 2013-07-08 19:57 - 00000040 ____A C:\Users\Public\Documents\_rgpl 2013-07-07 21:49 - 2013-07-08 22:29 - 00063152 ____A C:\Users\asus pro 5if\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-07 21:48 - 2013-07-08 22:28 - 00276976 ____A C:\Windows\System32\FNTCACHE.DAT 2013-07-07 21:48 - 2013-07-08 22:28 - 00000168 ____A C:\Windows\setupact.log 2013-07-07 21:48 - 2013-07-07 21:48 - 00000000 ____A C:\Windows\setuperr.log 2013-07-07 21:47 - 2013-07-07 21:47 - 00001863 ____A C:\AdwCleaner[S7].txt 2013-07-07 11:45 - 2013-07-07 11:45 - 00001079 ____A C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Program Files\VS Revo Group 2013-07-07 11:45 - 2009-12-30 11:21 - 00031800 ____A (VS Revo Group) C:\Windows\System32\Drivers\revoflt.sys 2013-07-06 22:41 - 2013-07-06 22:41 - 00005794 ____A C:\AdwCleaner[S6].txt 2013-07-06 22:40 - 2013-07-06 22:40 - 00650027 ____A C:\Users\asus pro 5if\Desktop\adwcleaner.exe 2013-07-06 13:37 - 2013-07-06 13:37 - 00000002 ____A C:\AvastSetup.log 2013-07-06 13:31 - 2013-07-06 13:36 - 06604352 ____A (AVAST Software) C:\Users\asus pro 5if\Desktop\avast_free_antivirus_setup_online.exe 2013-07-06 06:34 - 2013-07-07 15:56 - 00000000 ____D C:\Windows\Minidump 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-04 22:11 - 2013-07-04 22:12 - 00760775 ____A (Farbar) C:\Users\asus pro 5if\Desktop\MiniToolBox.exe 2013-07-04 22:06 - 2013-07-07 11:38 - 00448512 ____A (OldTimer Tools) C:\Users\asus pro 5if\Desktop\TFC.exe 2013-07-04 22:05 - 2013-07-04 22:05 - 00522216 ____A C:\Users\asus pro 5if\Desktop\Zipper.exe 2013-07-04 07:43 - 2013-07-04 07:43 - 00165376 ____A C:\Users\asus pro 5if\Desktop\SystemLook_x64.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 01093032 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00972712 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00000000 ____D C:\Program Files\Java 2013-07-03 20:51 - 2013-07-03 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-03 20:50 - 2013-07-03 20:52 - 00890988 ____A C:\Users\asus pro 5if\Desktop\SecurityCheck.exe 2013-07-03 19:34 - 2013-07-03 19:34 - 02347384 ____A (ESET) C:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe 2013-07-03 19:07 - 2013-07-06 22:46 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\asus pro 5if\Desktop\JRT.exe 2013-07-03 19:07 - 2013-07-06 22:46 - 00000000 ____D C:\JRT 2013-07-03 19:07 - 2013-07-03 19:07 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 19:01 - 2013-07-03 19:01 - 00002865 ____A C:\AdwCleaner[S5].txt 2013-07-03 19:00 - 2013-07-03 19:01 - 00002931 ____A C:\AdwCleaner[R5].txt 2013-07-03 19:00 - 2013-07-03 19:00 - 00002871 ____A C:\AdwCleaner[R4].txt 2013-07-03 18:47 - 2013-07-03 18:47 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-07-03 18:46 - 2013-07-03 18:47 - 00774592 ____A C:\Users\asus pro 5if\Downloads\ZipOpenerSetup.exe 2013-07-03 18:30 - 2013-07-03 18:30 - 00001111 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-03 18:30 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2013-07-03 18:27 - 2013-07-03 18:27 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\asus pro 5if\Desktop\mbam-setup-1.75.0.1300.exe 2013-07-02 19:55 - 2013-07-02 20:27 - 00000000 ____D C:\ComboFix 2013-07-02 19:55 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-07-02 19:55 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-07-02 19:55 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-07-02 19:54 - 2013-07-02 20:27 - 00000000 ____D C:\Qoobox 2013-07-02 19:54 - 2013-07-02 20:21 - 00000000 ____D C:\Windows\erdnt 2013-07-02 19:49 - 2013-07-02 19:53 - 05084414 ____R (Swearware) C:\Users\asus pro 5if\Desktop\ComboFix.exe 2013-07-02 18:59 - 2013-07-07 14:49 - 00000000 ____D C:\FRST 2013-07-02 18:57 - 2013-07-06 10:18 - 01934636 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-02 11:22 - 2013-07-02 11:23 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-05 18:16 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:37 - 2013-07-01 19:40 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:35 - 2012-07-25 12:03 - 00016896 ____A C:\Windows\System32\sasnative64.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:33 - 2013-07-02 14:18 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-01 19:33 - 2013-05-27 16:01 - 00020312 ____A (Systweak Inc., (www.systweak.com)) C:\Windows\System32\roboot64.exe 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-07-01 19:19 - 2013-06-27 07:14 - 00031816 ____A C:\Windows\Launcher.exe 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 21:59 - 2013-06-27 22:00 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:23 - 2013-04-23 22:06 - 00000567 ____A C:\zoek-results23.04.2013-2206.log 2013-06-27 20:07 - 2013-06-27 20:08 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:44 - 2013-06-27 19:45 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:43 - 2013-06-27 19:44 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-20 19:23 - 2013-07-07 17:13 - 00002098 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt ==================== One Month Modified Files and Folders ======= 2013-07-08 22:29 - 2013-07-07 21:49 - 00063152 ____A C:\Users\asus pro 5if\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-08 22:29 - 2010-10-12 21:13 - 00001120 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-08 22:29 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-08 22:28 - 2013-07-07 21:48 - 00276976 ____A C:\Windows\System32\FNTCACHE.DAT 2013-07-08 22:28 - 2013-07-07 21:48 - 00000168 ____A C:\Windows\setupact.log 2013-07-08 22:27 - 2010-10-12 21:13 - 00000000 ____D C:\ProgramData\GoBoingo 2013-07-08 22:27 - 2010-10-12 20:50 - 01623228 ____A C:\Windows\WindowsUpdate.log 2013-07-08 22:10 - 2012-07-02 22:16 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-08 21:44 - 2010-10-12 21:13 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-08 20:04 - 2013-07-08 20:04 - 00020266 ____A C:\Users\asus pro 5if\Desktop\Addition.txt 2013-07-08 19:57 - 2013-07-08 19:57 - 00000040 ____A C:\Users\Public\Documents\_rgpl 2013-07-08 19:57 - 2011-08-03 17:02 - 00000000 ____D C:\ProgramData\Skype Extras 2013-07-08 19:54 - 2012-01-02 22:23 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared 2013-07-08 19:54 - 2012-01-02 22:03 - 00000000 ____D C:\ProgramData\Autodesk 2013-07-08 19:53 - 2012-01-02 22:03 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Autodesk 2013-07-08 19:51 - 2010-10-12 21:14 - 00000000 ____D C:\Program Files (x86)\ASUS 2013-07-07 22:48 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-07 22:48 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-07 21:48 - 2013-07-07 21:48 - 00000000 ____A C:\Windows\setuperr.log 2013-07-07 21:47 - 2013-07-07 21:47 - 00001863 ____A C:\AdwCleaner[S7].txt 2013-07-07 17:13 - 2013-06-20 19:23 - 00002098 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt 2013-07-07 15:56 - 2013-07-06 06:34 - 00000000 ____D C:\Windows\Minidump 2013-07-07 14:49 - 2013-07-02 18:59 - 00000000 ____D C:\FRST 2013-07-07 11:45 - 2013-07-07 11:45 - 00001079 ____A C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Program Files\VS Revo Group 2013-07-07 11:40 - 2011-08-01 23:49 - 00045056 ____A C:\Windows\System32\acovcnt.exe 2013-07-07 11:40 - 2010-10-12 21:13 - 00000000 ____D C:\Program Files\Google 2013-07-07 11:40 - 2010-10-12 21:13 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-07 11:38 - 2013-07-04 22:06 - 00448512 ____A (OldTimer Tools) C:\Users\asus pro 5if\Desktop\TFC.exe 2013-07-07 11:22 - 2010-10-12 21:45 - 00000000 ____D C:\Windows\SysWOW64\K_Series_ScreenSaver_EN dir 2013-07-07 11:20 - 2011-07-27 03:26 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Google 2013-07-07 11:20 - 2010-10-12 21:13 - 00000000 ____D C:\ProgramData\Google 2013-07-07 11:12 - 2010-10-12 21:43 - 00000000 ____D C:\Program Files\ASUS 2013-07-06 22:46 - 2013-07-03 19:07 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\asus pro 5if\Desktop\JRT.exe 2013-07-06 22:46 - 2013-07-03 19:07 - 00000000 ____D C:\JRT 2013-07-06 22:41 - 2013-07-06 22:41 - 00005794 ____A C:\AdwCleaner[S6].txt 2013-07-06 22:40 - 2013-07-06 22:40 - 00650027 ____A C:\Users\asus pro 5if\Desktop\adwcleaner.exe 2013-07-06 13:37 - 2013-07-06 13:37 - 00000002 ____A C:\AvastSetup.log 2013-07-06 13:36 - 2013-07-06 13:31 - 06604352 ____A (AVAST Software) C:\Users\asus pro 5if\Desktop\avast_free_antivirus_setup_online.exe 2013-07-06 13:01 - 2011-10-22 03:59 - 00000000 ____D C:\ProgramData\Avira 2013-07-06 12:59 - 2011-12-11 13:17 - 00000000 ____D C:\Program Files (x86)\Pontifex II 2013-07-06 10:33 - 2012-07-02 22:16 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-07-06 10:33 - 2011-10-12 11:51 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-07-06 10:33 - 2011-07-31 07:09 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Adobe 2013-07-06 10:18 - 2013-07-02 18:57 - 01934636 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-05 18:16 - 2013-07-01 19:44 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-05 18:16 - 2013-07-01 19:44 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-04 22:12 - 2013-07-04 22:11 - 00760775 ____A (Farbar) C:\Users\asus pro 5if\Desktop\MiniToolBox.exe 2013-07-04 22:05 - 2013-07-04 22:05 - 00522216 ____A C:\Users\asus pro 5if\Desktop\Zipper.exe 2013-07-04 20:36 - 2011-08-03 17:01 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Skype 2013-07-04 07:43 - 2013-07-04 07:43 - 00165376 ____A C:\Users\asus pro 5if\Desktop\SystemLook_x64.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 01093032 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00972712 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00000000 ____D C:\Program Files\Java 2013-07-03 22:38 - 2011-07-27 05:31 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\SoftGrid Client 2013-07-03 21:33 - 2009-08-04 11:51 - 00697550 ____A C:\Windows\System32\perfh007.dat 2013-07-03 21:33 - 2009-08-04 11:51 - 00148556 ____A C:\Windows\System32\perfc007.dat 2013-07-03 21:33 - 2009-07-14 07:13 - 01614964 ____A C:\Windows\System32\PerfStringBackup.INI 2013-07-03 21:26 - 2011-08-06 07:22 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Paint.NET 2013-07-03 20:52 - 2013-07-03 20:50 - 00890988 ____A C:\Users\asus pro 5if\Desktop\SecurityCheck.exe 2013-07-03 20:51 - 2013-07-03 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-03 19:34 - 2013-07-03 19:34 - 02347384 ____A (ESET) C:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe 2013-07-03 19:07 - 2013-07-03 19:07 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 19:01 - 2013-07-03 19:01 - 00002865 ____A C:\AdwCleaner[S5].txt 2013-07-03 19:01 - 2013-07-03 19:00 - 00002931 ____A C:\AdwCleaner[R5].txt 2013-07-03 19:00 - 2013-07-03 19:00 - 00002871 ____A C:\AdwCleaner[R4].txt 2013-07-03 18:47 - 2013-07-03 18:47 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-07-03 18:47 - 2013-07-03 18:46 - 00774592 ____A C:\Users\asus pro 5if\Downloads\ZipOpenerSetup.exe 2013-07-03 18:30 - 2013-07-03 18:30 - 00001111 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-03 18:27 - 2013-07-03 18:27 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\asus pro 5if\Desktop\mbam-setup-1.75.0.1300.exe 2013-07-02 20:27 - 2013-07-02 19:55 - 00000000 ____D C:\ComboFix 2013-07-02 20:27 - 2013-07-02 19:54 - 00000000 ____D C:\Qoobox 2013-07-02 20:21 - 2013-07-02 19:54 - 00000000 ____D C:\Windows\erdnt 2013-07-02 20:10 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-07-02 19:53 - 2013-07-02 19:49 - 05084414 ____R (Swearware) C:\Users\asus pro 5if\Desktop\ComboFix.exe 2013-07-02 14:18 - 2013-07-01 19:33 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-02 11:23 - 2013-07-02 11:22 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:40 - 2013-07-01 19:37 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 22:00 - 2013-06-27 21:59 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:23 - 2013-04-23 18:49 - 00000393 ____A C:\zoek-results.log 2013-06-27 20:08 - 2013-06-27 20:07 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:04 - 2009-07-29 08:03 - 00000000 ____D C:\Windows\Panther 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:45 - 2013-06-27 19:44 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:44 - 2013-06-27 19:43 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:29 - 2011-08-03 17:01 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-27 19:29 - 2011-08-03 17:00 - 00000000 ____D C:\ProgramData\Skype 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-27 07:14 - 2013-07-01 19:19 - 00031816 ____A C:\Windows\Launcher.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-03 08:24 ==================== End Of Log ============================ --- --- --- FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-07-2013 Ran by asus pro 5if at 2013-07-08 22:31:25 Running from C:\Users\asus pro 5if\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 1.6.65) Adobe AIR (x32 Version: 1.5.0.7220) Adobe Flash Player 10 ActiveX (x32 Version: 10.0.42.34) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Reader 9.4.6 MUI (x32 Version: 9.4.6) ASUS AI Recovery (x32 Version: 1.0.24) ASUS CopyProtect (x32 Version: 1.0.0015) ASUS Data Security Manager (x32 Version: 1.00.0014) ASUS FancyStart (x32 Version: 1.0.8) ASUS LifeFrame3 (x32 Version: 3.0.20) ASUS Live Update (x32 Version: 3.0.3) ASUS MultiFrame (x32 Version: 1.0.0021) ASUS Power4Gear Hybrid (Version: 1.1.37) ASUS SmartLogon (x32 Version: 1.0.0008) ASUS Splendid Video Enhancement Technology (x32 Version: 1.02.0028) ASUS Video Magic (x32 Version: 6.0.4015) ASUS Virtual Camera (x32 Version: 1.0.20) ASUS WebStorage (x32 Version: 2.0.46.1429) ATK Package (x32 Version: 1.0.0006) CCleaner (Version: 4.03) Choice Guard (x32 Version: 1.2.87.0) Conexant HD Audio (Version: 4.111.0.63) ControlDeck (x32 Version: 1.0.8) CyberLink LabelPrint (x32 Version: 2.5.1908) CyberLink MediaShow Espresso (x32 Version: 5.0.1606_25588) CyberLink PhotoNow (x32 Version: 1.1.6904) CyberLink Power2Go (x32 Version: 6.1.3602c) CyberLink PowerDirector (x32 Version: 8.0.2609a) CyberLink PowerDVD 9 (x32 Version: 9.0.3009.50) ETDWare PS/2-x64 7.0.5.13_WHQL (Version: 7.0.5.13) FLV-Media Player 1.8 (x32 Version: 1.8) Google Chrome (x32 Version: 27.0.1453.116) Google Update Helper (x32 Version: 1.3.21.145) Iminent (x32 Version: 6.25.21.0) Intel PROSet Wireless Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Graphics Media Accelerator Driver (x32 Version: 8.15.10.2125) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) PROSet/Wireless WiFi Software (Version: 13.02.0000) Intel(R) Wireless Display (Version: 1.2.20.0) Java 7 Update 25 (64-bit) (Version: 7.0.250) JMicron Ethernet Adapter NDIS Driver (x32 Version: 6.0.17.1) JMicron Flash Media Controller Driver (x32 Version: 1.0.33.2) Junk Mail filter update (x32 Version: 14.0.8050.1202) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000) Microsoft Silverlight (x32 Version: 4.1.10111.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Sync Framework Runtime Native v1.0 (x86) (x32 Version: 1.0.1215.0) Microsoft Sync Framework Services Native v1.0 (x86) (x32 Version: 1.0.1215.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) MSVCRT (x32 Version: 14.0.1468.721) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) NB Probe (x32) Net4Switch (x32 Version: 1.00.0020) Open It! (x32 Version: 1.1.1) Opera 12.15 (x32 Version: 12.15.1748) Paint.NET v3.5.8 (Version: 3.58.0) Revo Uninstaller Pro 3.0.5 (Version: 3.0.5) Skype Click to Call (x32 Version: 5.10.9560) Skype™ 6.5 (x32 Version: 6.5.158) syncables desktop SE (x32 Version: 5.5.615.9518) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Zip Opener (HKCU) USB2.0 UVC VGA WebCam (Version: 5.8.54000.207) VLC media player 1.1.11 (x32 Version: 1.1.11) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.6) Windows Live Call (x32 Version: 14.0.8050.1202) Windows Live Communications Platform (x32 Version: 14.0.8050.1202) Windows Live Essentials (x32 Version: 14.0.8050.1202) Windows Live Family Safety (Version: 14.0.8052.1208) Windows Live Fotogalerie (x32 Version: 14.0.8051.1204) Windows Live Mail (x32 Version: 14.0.8050.1202) Windows Live Messenger (x32 Version: 14.0.8050.1202) Windows Live Sync (x32 Version: 14.0.8050.1202) Windows Live Writer (x32 Version: 14.0.8050.1202) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029) WinFlash (x32 Version: 2.30.3) WinRAR 4.20 (32-Bit) (x32 Version: 4.20.0) Wireless Console 3 (x32 Version: 3.0.18) ==================== Restore Points ========================= 03-07-2013 20:51:55 Installed Java 7 Update 25 (64-bit) 07-07-2013 09:12:23 Removed Fast Boot 07-07-2013 09:30:03 Free System Utilities 08-07-2013 17:50:56 Installed ASUS Live Update 08-07-2013 17:54:38 Autodesk Content Service wird entfernt 08-07-2013 17:55:17 Removed Autodesk Material Library 2012. 08-07-2013 17:55:55 Removed Autodesk Material Library Base Resolution Image Library 2012. 08-07-2013 17:59:31 Removed FARO LS 1.1.406.58 08-07-2013 20:27:03 Removed Boingo Wi-Fi ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-07-02 20:09 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {24A34CFE-2CBD-4913-9E96-5861F6F5F99C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-05-28] (ATK) Task: {24CC42E7-515E-4C08-8365-D1A50F36E458} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {2B2AA4C6-9B2F-4725-9B63-1BE51240A6A8} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe No File Task: {324E82F7-D064-44D5-BA77-75826922E3CA} - System32\Tasks\ASUSControlDeck => C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe [2010-06-09] (asus) Task: {3951030E-CB71-486D-B3D8-8AF547C9905D} - System32\Tasks\{78ABA6A5-01CC-4830-ABA9-AAEEAAFA3211} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-06-03] (Skype Technologies S.A.) Task: {433DA0EA-37B2-4EB0-A90C-D4008A1BD429} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe No File Task: {4429AA03-2279-4817-A8C8-45BA6621C69B} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {52FC4F05-4CEA-4A42-9741-6D0D7BF5A73D} - System32\Tasks\Net4Switch => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe [2009-09-23] (ASUS) Task: {699264D4-0D35-4784-AD7F-8CBF3D5E29A4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {6B60EE87-CF7B-496D-932A-82D77CFB20BC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-06] (Adobe Systems Incorporated) Task: {765D21BA-0C98-45DD-A5A2-C1AD88B0DCEC} - System32\Tasks\{26D6A9BB-3CFC-4286-AB29-46DF1F2FA2DE} => C:\program files (x86)\opera\opera.exe [2013-04-09] (Opera Software) Task: {79492728-14A4-4634-B22B-234AB4A0FEA2} - System32\Tasks\ASPG => C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS) Task: {7CA210CD-3096-4280-A903-23CFFF2FB634} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {80C1B2D2-609C-4064-960D-6C79413850B3} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe No File Task: {A585B730-AA46-4D11-A49C-B597D9067F7A} - System32\Tasks\Software Updater => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe No File Task: {A738714F-FDF5-4018-89D1-C58261B4A148} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {B02BD60F-1E22-4AA8-A1E8-9D11BC6CF3D8} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2009-07-14] (Microsoft Corporation) Task: {B78EE339-3FF1-4668-A11F-58350B88A23F} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-07-18] (ASUSTeK Computer Inc.) Task: {B92D7D8E-825D-4858-B1E5-577192A364A8} - System32\Tasks\AIRecoveryRemind => C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe [2012-03-09] (ASUSTek Computer Inc.) Task: {BFD2AAB0-9059-4444-8B96-E22B494E7A1B} - System32\Tasks\Freemium1ClickMaint => C:\Users\asus pro 5if\Downloads\1Click.exe No File Task: {DC2F45BA-04CC-414C-9B50-10F48095D6FA} - System32\Tasks\Software Updater Ui => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Ui.exe No File Task: {DF45D3D6-E963-44A8-9F0D-D49D1EE068CB} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-07-31] (ASUS) Task: {E2B3EB42-00D0-4770-9664-63BE47C60241} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK) Task: {F46AB22C-23A3-4EE7-BF5A-C9FA3785801E} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-08-04] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Net4Switch.job => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/08/2013 00:32:55 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service) (User: ) Description: Das Gatherer-Objekt kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service) (User: ) Description: Plug-In in <Search.TripoliIndexer> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Plug-In in <Search.JetPropStore> kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Die Eigenschaftenspeicherdaten können von Windows Search nicht geladen werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=4700} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service) (User: ) Description: Der Jet-Eigenschaftenspeicher kann von Windows Search nicht geöffnet werden. Details: 0x%08x (0xc0041800 - Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800)) System errors: ============= Error: (07/07/2013 10:42:07 PM) (Source: DCOM) (User: ) Description: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Error: (07/07/2013 09:49:35 PM) (Source: DCOM) (User: ) Description: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Error: (07/07/2013 09:49:20 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde unerwartet beendet. Dies ist bereits 1 Mal vorgekommen. Folgende Korrekturmaßnahmen werden in 30000 Millisekunden durchgeführt: Neustart des Diensts. Error: (07/07/2013 09:49:18 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde mit folgendem dienstspezifischem Fehler beendet: %%-1073473535. Error: (07/07/2013 02:54:15 PM) (Source: DCOM) (User: ) Description: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Error: (07/07/2013 02:43:18 PM) (Source: DCOM) (User: ) Description: {49BD2028-1523-11D1-AD79-00C04FD8FDFF} Error: (07/07/2013 02:41:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (07/07/2013 02:41:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (07/07/2013 02:41:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error: (07/07/2013 02:41:32 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Netzwerklistendienst" ist vom Dienst "NLA (Network Location Awareness)" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Microsoft Office Sessions: ========================= Error: (07/08/2013 00:32:55 AM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (07/07/2013 09:49:18 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Element nicht gefunden. (HRESULT : 0x80070490) (0x80070490) Search.TripoliIndexer Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Search.JetPropStore Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800) (0xc0041800) Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) The catalog is corrupt Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) 4700 Error: (07/07/2013 09:49:17 PM) (Source: Windows Search Service)(User: ) Description: Details: 0x%08x (0xc0041800 - Die Inhaltsindexdatenbank ist fehlerhaft. (HRESULT : 0xc0041800)) CodeIntegrity Errors: =================================== Date: 2013-07-02 20:04:39.311 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-07-02 20:04:39.264 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 47% Total physical RAM: 2924.56 MB Available physical RAM: 1530.2 MB Total Pagefile: 5847.26 MB Available Pagefile: 4131.78 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:72.69 GB) (Free:40.97 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:205.87 GB) (Free:205.54 GB) NTFS (Disk=0 Partition=3) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 0237A506) Partition 1: (Not Active) - (Size=20 GB) - (Type=1C) Partition 2: (Active) - (Size=73 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=206 GB) - (Type=OF Extended) ==================== End Of Log ============================ Des Iminentding bekomme ich irgendwie net zu fassen. |
08.07.2013, 21:43 | #54 |
/// the machine /// TB-Ausbilder | Internet total langsam Falls schon vorhanden löschen und neu laden. Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST Log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
08.07.2013, 22:17 | #55 |
| Internet total langsam Hallo Meister schrauber,AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.304 - Datei am 08/07/2013 um 23:01:41 erstellt # Aktualisiert am 03/07/2013 von Xplode # Betriebssystem : Windows 7 Home Premium (64 bits) # Benutzer : asus pro 5if - ASUSPRO5IF-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\asus pro 5if\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKLM\Software\Iminent Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS ***** [Internet Browser] ***** -\\ Internet Explorer v8.0.7600.16968 [OK] Die Registrierungsdatenbank ist sauber. -\\ Google Chrome v27.0.1453.116 Datei : C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. -\\ Opera v12.15.1748.0 Datei : C:\Users\asus pro 5if\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [3505 octets] - [24/04/2013 04:49:33] AdwCleaner[R2].txt - [1095 octets] - [27/06/2013 19:43:42] AdwCleaner[R3].txt - [1215 octets] - [27/06/2013 20:07:57] AdwCleaner[R4].txt - [2871 octets] - [03/07/2013 19:00:23] AdwCleaner[R5].txt - [2931 octets] - [03/07/2013 19:00:55] AdwCleaner[S1].txt - [3567 octets] - [24/04/2013 04:50:29] AdwCleaner[S2].txt - [1158 octets] - [27/06/2013 19:44:31] AdwCleaner[S3].txt - [1294 octets] - [27/06/2013 21:59:31] AdwCleaner[S4].txt - [38089 octets] - [02/07/2013 11:22:42] AdwCleaner[S5].txt - [2865 octets] - [03/07/2013 19:01:25] AdwCleaner[S6].txt - [5794 octets] - [06/07/2013 22:41:24] AdwCleaner[S7].txt - [1863 octets] - [07/07/2013 21:47:23] AdwCleaner[S8].txt - [1768 octets] - [08/07/2013 23:01:41] ########## EOF - C:\AdwCleaner[S8].txt - [1828 octets] ########## ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.7 (07.08.2013:2) OS: Windows 7 Home Premium x64 Ran by asus pro 5if on 08.07.2013 at 23:06:46,79 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 08.07.2013 at 23:12:13,76 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 08-07-2013 Ran by asus pro 5if (administrator) on 08-07-2013 23:14:42 Running from C:\Users\asus pro 5if\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe () C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUS) C:\Windows\AsScrPro.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (ASUS) C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe (ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe [649608 2010-06-10] (ELAN Microelectronic Corp.) HKLM\...\Run: [ASUS WebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-16] () HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-19] () HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1928976 2010-03-05] (Intel(R) Corporation) HKLM\...\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd [x] HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" [87336 2009-07-06] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2010-06-25] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS) HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-08-12] () HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2011-09-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" [103720 2009-11-02] (CyberLink) HKLM-x32\...\Run: [ADSMTray] C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe [272952 2009-06-24] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUS Screen Saver Protector] C:\Windows\AsScrPro.exe [3054136 2010-10-12] (ASUS) HKU\Gast\...\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe [370480 2010-04-05] (syncables, LLC) HKU\Gast\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [x] ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 83.169.184.225 83.169.184.161 Chrome: ======= CHR RestoreOnStartup: "urls_to_restore_on_startup": null CHR DefaultSearchURL: (My Online Search) - hxxp://www.my-online-search.com/?q={searchTerms}&babsrc=SP_ofln&mntrId=E220001E64563571&cat=delta&dlb=2&affID=119357 CHR DefaultSuggestURL: (My Online Search) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll No File CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Extension: (Skype Click to Call) - C:\Users\ASUSPR~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0 CHR Extension: (Amazon 1Button App for Chrome) - C:\Users\ASUSPR~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam\3.2013.627.0_0 ==================== Services (Whitelisted) ================= R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-03-05] () R2 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] () S3 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () ==================== Drivers (Whitelisted) ==================== S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2011-11-21] (Mobile Connector) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () S3 catchme; \??\C:\ComboFix\catchme.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-08 23:12 - 2013-07-08 23:12 - 00000632 ____A C:\Users\asus pro 5if\Desktop\JRT.txt 2013-07-08 23:03 - 2013-07-08 23:03 - 00001897 ____A C:\Users\asus pro 5if\Desktop\AdwCleaner[S8].txt 2013-07-08 23:01 - 2013-07-08 23:01 - 00001897 ____A C:\AdwCleaner[S8].txt 2013-07-08 19:57 - 2013-07-08 19:57 - 00000040 ____A C:\Users\Public\Documents\_rgpl 2013-07-07 21:49 - 2013-07-08 22:29 - 00063152 ____A C:\Users\asus pro 5if\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-07 21:48 - 2013-07-08 23:03 - 00000280 ____A C:\Windows\setupact.log 2013-07-07 21:48 - 2013-07-08 22:28 - 00276976 ____A C:\Windows\System32\FNTCACHE.DAT 2013-07-07 21:48 - 2013-07-07 21:48 - 00000000 ____A C:\Windows\setuperr.log 2013-07-07 21:47 - 2013-07-07 21:47 - 00001863 ____A C:\AdwCleaner[S7].txt 2013-07-07 11:45 - 2013-07-07 11:45 - 00001079 ____A C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Program Files\VS Revo Group 2013-07-07 11:45 - 2009-12-30 11:21 - 00031800 ____A (VS Revo Group) C:\Windows\System32\Drivers\revoflt.sys 2013-07-06 22:41 - 2013-07-06 22:41 - 00005794 ____A C:\AdwCleaner[S6].txt 2013-07-06 22:40 - 2013-07-08 23:01 - 00650027 ____A C:\Users\asus pro 5if\Desktop\adwcleaner.exe 2013-07-06 13:37 - 2013-07-06 13:37 - 00000002 ____A C:\AvastSetup.log 2013-07-06 13:31 - 2013-07-06 13:36 - 06604352 ____A (AVAST Software) C:\Users\asus pro 5if\Desktop\avast_free_antivirus_setup_online.exe 2013-07-06 06:34 - 2013-07-07 15:56 - 00000000 ____D C:\Windows\Minidump 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-04 22:11 - 2013-07-04 22:12 - 00760775 ____A (Farbar) C:\Users\asus pro 5if\Desktop\MiniToolBox.exe 2013-07-04 22:06 - 2013-07-07 11:38 - 00448512 ____A (OldTimer Tools) C:\Users\asus pro 5if\Desktop\TFC.exe 2013-07-04 22:05 - 2013-07-04 22:05 - 00522216 ____A C:\Users\asus pro 5if\Desktop\Zipper.exe 2013-07-04 07:43 - 2013-07-04 07:43 - 00165376 ____A C:\Users\asus pro 5if\Desktop\SystemLook_x64.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 01093032 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00972712 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00000000 ____D C:\Program Files\Java 2013-07-03 20:51 - 2013-07-03 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-03 20:50 - 2013-07-03 20:52 - 00890988 ____A C:\Users\asus pro 5if\Desktop\SecurityCheck.exe 2013-07-03 19:34 - 2013-07-03 19:34 - 02347384 ____A (ESET) C:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe 2013-07-03 19:07 - 2013-07-08 23:06 - 00000000 ____D C:\JRT 2013-07-03 19:07 - 2013-07-08 23:05 - 00547139 ____A (Oleg N. Scherbakov) C:\Users\asus pro 5if\Desktop\JRT.exe 2013-07-03 19:07 - 2013-07-03 19:07 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 19:01 - 2013-07-03 19:01 - 00002865 ____A C:\AdwCleaner[S5].txt 2013-07-03 19:00 - 2013-07-03 19:01 - 00002931 ____A C:\AdwCleaner[R5].txt 2013-07-03 19:00 - 2013-07-03 19:00 - 00002871 ____A C:\AdwCleaner[R4].txt 2013-07-03 18:47 - 2013-07-03 18:47 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-07-03 18:46 - 2013-07-03 18:47 - 00774592 ____A C:\Users\asus pro 5if\Downloads\ZipOpenerSetup.exe 2013-07-03 18:30 - 2013-07-03 18:30 - 00001111 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-03 18:30 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2013-07-03 18:27 - 2013-07-03 18:27 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\asus pro 5if\Desktop\mbam-setup-1.75.0.1300.exe 2013-07-02 19:55 - 2013-07-02 20:27 - 00000000 ____D C:\ComboFix 2013-07-02 19:55 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-07-02 19:55 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-07-02 19:55 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-07-02 19:54 - 2013-07-02 20:27 - 00000000 ____D C:\Qoobox 2013-07-02 19:54 - 2013-07-02 20:21 - 00000000 ____D C:\Windows\erdnt 2013-07-02 19:49 - 2013-07-02 19:53 - 05084414 ____R (Swearware) C:\Users\asus pro 5if\Desktop\ComboFix.exe 2013-07-02 18:59 - 2013-07-07 14:49 - 00000000 ____D C:\FRST 2013-07-02 18:57 - 2013-07-08 23:14 - 01934554 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-02 11:22 - 2013-07-02 11:23 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-05 18:16 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:37 - 2013-07-01 19:40 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:35 - 2012-07-25 12:03 - 00016896 ____A C:\Windows\System32\sasnative64.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:33 - 2013-07-02 14:18 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-01 19:33 - 2013-05-27 16:01 - 00020312 ____A (Systweak Inc., (www.systweak.com)) C:\Windows\System32\roboot64.exe 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-07-01 19:19 - 2013-06-27 07:14 - 00031816 ____A C:\Windows\Launcher.exe 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 21:59 - 2013-06-27 22:00 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:23 - 2013-04-23 22:06 - 00000567 ____A C:\zoek-results23.04.2013-2206.log 2013-06-27 20:07 - 2013-06-27 20:08 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:44 - 2013-06-27 19:45 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:43 - 2013-06-27 19:44 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-20 19:23 - 2013-07-07 17:13 - 00002098 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt ==================== One Month Modified Files and Folders ======= 2013-07-08 23:14 - 2013-07-02 18:57 - 01934554 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-08 23:12 - 2013-07-08 23:12 - 00000632 ____A C:\Users\asus pro 5if\Desktop\JRT.txt 2013-07-08 23:10 - 2012-07-02 22:16 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-08 23:10 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-08 23:10 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-08 23:06 - 2013-07-03 19:07 - 00000000 ____D C:\JRT 2013-07-08 23:05 - 2013-07-03 19:07 - 00547139 ____A (Oleg N. Scherbakov) C:\Users\asus pro 5if\Desktop\JRT.exe 2013-07-08 23:03 - 2013-07-08 23:03 - 00001897 ____A C:\Users\asus pro 5if\Desktop\AdwCleaner[S8].txt 2013-07-08 23:03 - 2013-07-07 21:48 - 00000280 ____A C:\Windows\setupact.log 2013-07-08 23:03 - 2010-10-12 21:13 - 00001120 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-08 23:03 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-08 23:02 - 2010-10-12 20:50 - 01636965 ____A C:\Windows\WindowsUpdate.log 2013-07-08 23:01 - 2013-07-08 23:01 - 00001897 ____A C:\AdwCleaner[S8].txt 2013-07-08 23:01 - 2013-07-06 22:40 - 00650027 ____A C:\Users\asus pro 5if\Desktop\adwcleaner.exe 2013-07-08 22:46 - 2011-08-01 23:49 - 00045056 ____A C:\Windows\System32\acovcnt.exe 2013-07-08 22:44 - 2010-10-12 21:13 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-08 22:29 - 2013-07-07 21:49 - 00063152 ____A C:\Users\asus pro 5if\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-08 22:28 - 2013-07-07 21:48 - 00276976 ____A C:\Windows\System32\FNTCACHE.DAT 2013-07-08 22:27 - 2010-10-12 21:13 - 00000000 ____D C:\ProgramData\GoBoingo 2013-07-08 19:57 - 2013-07-08 19:57 - 00000040 ____A C:\Users\Public\Documents\_rgpl 2013-07-08 19:57 - 2011-08-03 17:02 - 00000000 ____D C:\ProgramData\Skype Extras 2013-07-08 19:54 - 2012-01-02 22:23 - 00000000 ____D C:\Program Files\Common Files\Autodesk Shared 2013-07-08 19:54 - 2012-01-02 22:03 - 00000000 ____D C:\ProgramData\Autodesk 2013-07-08 19:53 - 2012-01-02 22:03 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Autodesk 2013-07-08 19:51 - 2010-10-12 21:14 - 00000000 ____D C:\Program Files (x86)\ASUS 2013-07-07 21:48 - 2013-07-07 21:48 - 00000000 ____A C:\Windows\setuperr.log 2013-07-07 21:47 - 2013-07-07 21:47 - 00001863 ____A C:\AdwCleaner[S7].txt 2013-07-07 17:13 - 2013-06-20 19:23 - 00002098 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt 2013-07-07 15:56 - 2013-07-06 06:34 - 00000000 ____D C:\Windows\Minidump 2013-07-07 14:49 - 2013-07-02 18:59 - 00000000 ____D C:\FRST 2013-07-07 11:45 - 2013-07-07 11:45 - 00001079 ____A C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\ProgramData\VS Revo Group 2013-07-07 11:45 - 2013-07-07 11:45 - 00000000 ____D C:\Program Files\VS Revo Group 2013-07-07 11:40 - 2010-10-12 21:13 - 00000000 ____D C:\Program Files\Google 2013-07-07 11:40 - 2010-10-12 21:13 - 00000000 ____D C:\Program Files (x86)\Google 2013-07-07 11:38 - 2013-07-04 22:06 - 00448512 ____A (OldTimer Tools) C:\Users\asus pro 5if\Desktop\TFC.exe 2013-07-07 11:22 - 2010-10-12 21:45 - 00000000 ____D C:\Windows\SysWOW64\K_Series_ScreenSaver_EN dir 2013-07-07 11:20 - 2011-07-27 03:26 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Google 2013-07-07 11:20 - 2010-10-12 21:13 - 00000000 ____D C:\ProgramData\Google 2013-07-07 11:12 - 2010-10-12 21:43 - 00000000 ____D C:\Program Files\ASUS 2013-07-06 22:41 - 2013-07-06 22:41 - 00005794 ____A C:\AdwCleaner[S6].txt 2013-07-06 13:37 - 2013-07-06 13:37 - 00000002 ____A C:\AvastSetup.log 2013-07-06 13:36 - 2013-07-06 13:31 - 06604352 ____A (AVAST Software) C:\Users\asus pro 5if\Desktop\avast_free_antivirus_setup_online.exe 2013-07-06 13:01 - 2011-10-22 03:59 - 00000000 ____D C:\ProgramData\Avira 2013-07-06 12:59 - 2011-12-11 13:17 - 00000000 ____D C:\Program Files (x86)\Pontifex II 2013-07-06 10:33 - 2012-07-02 22:16 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-07-06 10:33 - 2011-10-12 11:51 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-07-06 10:33 - 2011-07-31 07:09 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Adobe 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\searchplugins 2013-07-05 18:18 - 2013-07-05 18:18 - 00000000 ____D C:\Windows\SysWOW64\Extensions 2013-07-05 18:16 - 2013-07-05 18:16 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-07-05 18:16 - 2013-07-01 19:44 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-05 18:16 - 2013-07-01 19:44 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-04 22:12 - 2013-07-04 22:11 - 00760775 ____A (Farbar) C:\Users\asus pro 5if\Desktop\MiniToolBox.exe 2013-07-04 22:05 - 2013-07-04 22:05 - 00522216 ____A C:\Users\asus pro 5if\Desktop\Zipper.exe 2013-07-04 20:36 - 2011-08-03 17:01 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Skype 2013-07-04 07:43 - 2013-07-04 07:43 - 00165376 ____A C:\Users\asus pro 5if\Desktop\SystemLook_x64.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 01093032 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00972712 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00000000 ____D C:\Program Files\Java 2013-07-03 22:38 - 2011-07-27 05:31 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\SoftGrid Client 2013-07-03 21:33 - 2009-08-04 11:51 - 00697550 ____A C:\Windows\System32\perfh007.dat 2013-07-03 21:33 - 2009-08-04 11:51 - 00148556 ____A C:\Windows\System32\perfc007.dat 2013-07-03 21:33 - 2009-07-14 07:13 - 01614964 ____A C:\Windows\System32\PerfStringBackup.INI 2013-07-03 21:26 - 2011-08-06 07:22 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Paint.NET 2013-07-03 20:52 - 2013-07-03 20:50 - 00890988 ____A C:\Users\asus pro 5if\Desktop\SecurityCheck.exe 2013-07-03 20:51 - 2013-07-03 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-03 19:34 - 2013-07-03 19:34 - 02347384 ____A (ESET) C:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe 2013-07-03 19:07 - 2013-07-03 19:07 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 19:01 - 2013-07-03 19:01 - 00002865 ____A C:\AdwCleaner[S5].txt 2013-07-03 19:01 - 2013-07-03 19:00 - 00002931 ____A C:\AdwCleaner[R5].txt 2013-07-03 19:00 - 2013-07-03 19:00 - 00002871 ____A C:\AdwCleaner[R4].txt 2013-07-03 18:47 - 2013-07-03 18:47 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-07-03 18:47 - 2013-07-03 18:46 - 00774592 ____A C:\Users\asus pro 5if\Downloads\ZipOpenerSetup.exe 2013-07-03 18:30 - 2013-07-03 18:30 - 00001111 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-03 18:27 - 2013-07-03 18:27 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\asus pro 5if\Desktop\mbam-setup-1.75.0.1300.exe 2013-07-02 20:27 - 2013-07-02 19:55 - 00000000 ____D C:\ComboFix 2013-07-02 20:27 - 2013-07-02 19:54 - 00000000 ____D C:\Qoobox 2013-07-02 20:21 - 2013-07-02 19:54 - 00000000 ____D C:\Windows\erdnt 2013-07-02 20:10 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-07-02 19:53 - 2013-07-02 19:49 - 05084414 ____R (Swearware) C:\Users\asus pro 5if\Desktop\ComboFix.exe 2013-07-02 14:18 - 2013-07-01 19:33 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-02 11:23 - 2013-07-02 11:22 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:40 - 2013-07-01 19:37 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 22:00 - 2013-06-27 21:59 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:23 - 2013-04-23 18:49 - 00000393 ____A C:\zoek-results.log 2013-06-27 20:08 - 2013-06-27 20:07 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:04 - 2009-07-29 08:03 - 00000000 ____D C:\Windows\Panther 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:45 - 2013-06-27 19:44 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:44 - 2013-06-27 19:43 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:29 - 2011-08-03 17:01 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-27 19:29 - 2011-08-03 17:00 - 00000000 ____D C:\ProgramData\Skype 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-27 07:14 - 2013-07-01 19:19 - 00031816 ____A C:\Windows\Launcher.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-03 08:24 ==================== End Of Log ============================ FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 08-07-2013 Ran by asus pro 5if at 2013-07-08 23:15:09 Running from C:\Users\asus pro 5if\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 1.6.65) Adobe AIR (x32 Version: 1.5.0.7220) Adobe Flash Player 10 ActiveX (x32 Version: 10.0.42.34) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Reader 9.4.6 MUI (x32 Version: 9.4.6) ASUS AI Recovery (x32 Version: 1.0.24) ASUS CopyProtect (x32 Version: 1.0.0015) ASUS Data Security Manager (x32 Version: 1.00.0014) ASUS FancyStart (x32 Version: 1.0.8) ASUS LifeFrame3 (x32 Version: 3.0.20) ASUS Live Update (x32 Version: 3.0.3) ASUS MultiFrame (x32 Version: 1.0.0021) ASUS Power4Gear Hybrid (Version: 1.1.37) ASUS SmartLogon (x32 Version: 1.0.0008) ASUS Splendid Video Enhancement Technology (x32 Version: 1.02.0028) ASUS Video Magic (x32 Version: 6.0.4015) ASUS Virtual Camera (x32 Version: 1.0.20) ASUS WebStorage (x32 Version: 2.0.46.1429) ATK Package (x32 Version: 1.0.0006) Choice Guard (x32 Version: 1.2.87.0) Conexant HD Audio (Version: 4.111.0.63) ControlDeck (x32 Version: 1.0.8) CyberLink LabelPrint (x32 Version: 2.5.1908) CyberLink MediaShow Espresso (x32 Version: 5.0.1606_25588) CyberLink PhotoNow (x32 Version: 1.1.6904) CyberLink Power2Go (x32 Version: 6.1.3602c) CyberLink PowerDirector (x32 Version: 8.0.2609a) CyberLink PowerDVD 9 (x32 Version: 9.0.3009.50) eaner (Version: 4.03) ETDWare PS/2-x64 7.0.5.13_WHQL (Version: 7.0.5.13) FLV-Media Player 1.8 (x32 Version: 1.8) Google Chrome (x32 Version: 27.0.1453.116) Google Update Helper (x32 Version: 1.3.21.145) Intel PROSet Wireless Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Graphics Media Accelerator Driver (x32 Version: 8.15.10.2125) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) PROSet/Wireless WiFi Software (Version: 13.02.0000) Intel(R) Wireless Display (Version: 1.2.20.0) Java 7 Update 25 (64-bit) (Version: 7.0.250) JMicron Ethernet Adapter NDIS Driver (x32 Version: 6.0.17.1) JMicron Flash Media Controller Driver (x32 Version: 1.0.33.2) Junk Mail filter update (x32 Version: 14.0.8050.1202) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000) Microsoft Silverlight (x32 Version: 4.1.10111.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Sync Framework Runtime Native v1.0 (x86) (x32 Version: 1.0.1215.0) Microsoft Sync Framework Services Native v1.0 (x86) (x32 Version: 1.0.1215.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) MSVCRT (x32 Version: 14.0.1468.721) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) NB Probe (x32) Net4Switch (x32 Version: 1.00.0020) Open It! (x32 Version: 1.1.1) Opera 12.15 (x32 Version: 12.15.1748) Paint.NET v3.5.8 (Version: 3.58.0) Revo Uninstaller Pro 3.0.5 (Version: 3.0.5) Skype Click to Call (x32 Version: 5.10.9560) Skype™ 6.5 (x32 Version: 6.5.158) syncables desktop SE (x32 Version: 5.5.615.9518) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Zip Opener (HKCU) USB2.0 UVC VGA WebCam (Version: 5.8.54000.207) VLC media player 1.1.11 (x32 Version: 1.1.11) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.6) Windows Live Call (x32 Version: 14.0.8050.1202) Windows Live Communications Platform (x32 Version: 14.0.8050.1202) Windows Live Essentials (x32 Version: 14.0.8050.1202) Windows Live Family Safety (Version: 14.0.8052.1208) Windows Live Fotogalerie (x32 Version: 14.0.8051.1204) Windows Live Mail (x32 Version: 14.0.8050.1202) Windows Live Messenger (x32 Version: 14.0.8050.1202) Windows Live Sync (x32 Version: 14.0.8050.1202) Windows Live Writer (x32 Version: 14.0.8050.1202) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029) WinFlash (x32 Version: 2.30.3) WinRAR 4.20 (32-Bit) (x32 Version: 4.20.0) Wireless Console 3 (x32 Version: 3.0.18) ==================== Restore Points ========================= 03-07-2013 20:51:55 Installed Java 7 Update 25 (64-bit) 07-07-2013 09:12:23 Removed Fast Boot 07-07-2013 09:30:03 Free System Utilities 08-07-2013 17:50:56 Installed ASUS Live Update 08-07-2013 17:54:38 Autodesk Content Service wird entfernt 08-07-2013 17:55:17 Removed Autodesk Material Library 2012. 08-07-2013 17:55:55 Removed Autodesk Material Library Base Resolution Image Library 2012. 08-07-2013 17:59:31 Removed FARO LS 1.1.406.58 08-07-2013 20:27:03 Removed Boingo Wi-Fi ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-07-02 20:09 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {24A34CFE-2CBD-4913-9E96-5861F6F5F99C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-05-28] (ATK) Task: {24CC42E7-515E-4C08-8365-D1A50F36E458} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {2B2AA4C6-9B2F-4725-9B63-1BE51240A6A8} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe No File Task: {324E82F7-D064-44D5-BA77-75826922E3CA} - System32\Tasks\ASUSControlDeck => C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe [2010-06-09] (asus) Task: {3951030E-CB71-486D-B3D8-8AF547C9905D} - System32\Tasks\{78ABA6A5-01CC-4830-ABA9-AAEEAAFA3211} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-06-03] (Skype Technologies S.A.) Task: {433DA0EA-37B2-4EB0-A90C-D4008A1BD429} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe No File Task: {52FC4F05-4CEA-4A42-9741-6D0D7BF5A73D} - System32\Tasks\Net4Switch => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe [2009-09-23] (ASUS) Task: {699264D4-0D35-4784-AD7F-8CBF3D5E29A4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {6B60EE87-CF7B-496D-932A-82D77CFB20BC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-06] (Adobe Systems Incorporated) Task: {765D21BA-0C98-45DD-A5A2-C1AD88B0DCEC} - System32\Tasks\{26D6A9BB-3CFC-4286-AB29-46DF1F2FA2DE} => C:\program files (x86)\opera\opera.exe [2013-04-09] (Opera Software) Task: {79492728-14A4-4634-B22B-234AB4A0FEA2} - System32\Tasks\ASPG => C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS) Task: {7CA210CD-3096-4280-A903-23CFFF2FB634} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {80C1B2D2-609C-4064-960D-6C79413850B3} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe No File Task: {A0F38E3E-94B6-4726-8231-BDCF14CC9C1A} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {A585B730-AA46-4D11-A49C-B597D9067F7A} - System32\Tasks\Software Updater => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe No File Task: {A738714F-FDF5-4018-89D1-C58261B4A148} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {B02BD60F-1E22-4AA8-A1E8-9D11BC6CF3D8} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2009-07-14] (Microsoft Corporation) Task: {B78EE339-3FF1-4668-A11F-58350B88A23F} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\LiveUpdate.exe [2011-07-18] (ASUSTeK Computer Inc.) Task: {B92D7D8E-825D-4858-B1E5-577192A364A8} - System32\Tasks\AIRecoveryRemind => C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe [2012-03-09] (ASUSTek Computer Inc.) Task: {BFD2AAB0-9059-4444-8B96-E22B494E7A1B} - System32\Tasks\Freemium1ClickMaint => C:\Users\asus pro 5if\Downloads\1Click.exe No File Task: {DC2F45BA-04CC-414C-9B50-10F48095D6FA} - System32\Tasks\Software Updater Ui => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Ui.exe No File Task: {DF45D3D6-E963-44A8-9F0D-D49D1EE068CB} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-07-31] (ASUS) Task: {E2B3EB42-00D0-4770-9664-63BE47C60241} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK) Task: {F46AB22C-23A3-4EE7-BF5A-C9FA3785801E} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-08-04] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Net4Switch.job => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-07-02 20:04:39.311 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-07-02 20:04:39.264 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 40% Total physical RAM: 2924.56 MB Available physical RAM: 1729.73 MB Total Pagefile: 5847.26 MB Available Pagefile: 4169.13 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:72.69 GB) (Free:40.87 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:205.87 GB) (Free:205.54 GB) NTFS (Disk=0 Partition=3) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 0237A506) Partition 1: (Not Active) - (Size=20 GB) - (Type=1C) Partition 2: (Active) - (Size=73 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=206 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
09.07.2013, 07:14 | #56 | |
/// the machine /// TB-Ausbilder | Internet total langsamZitat:
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM\...\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd [x] CHR RestoreOnStartup: "urls_to_restore_on_startup": null CHR DefaultSearchURL: (My Online Search) - hxxp://www.my-online-search.com/?q={searchTerms}&babsrc=SP_ofln&mntrId=E220001E64563571&cat=delta&dlb=2&affID=119357 R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2013, 17:18 | #57 |
| Internet total langsam Tach schrauber, Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 08-07-2013 Ran by asus pro 5if at 2013-07-09 18:17:19 Run:2 Running from C:\Users\asus pro 5if\Desktop Boot Mode: Normal ============================================== HKLM\Software\Microsoft\Windows\CurrentVersion\Run\\Setwallpaper => Value deleted successfully. CHR RestoreOnStartup: "urls_to_restore_on_startup": null ==> The Chrome "Settings" can be used to fix the entry. CHR DefaultSearchURL: (My Online Search) - hxxp://www.my-online-search.com/?q={searchTerms}&babsrc=SP_ofln&mntrId=E220001E64563571&cat=delta&dlb=2&affID=119357 ==> The Chrome "Settings" can be used to fix the entry. SNP2UVC => Service deleted successfully. ==== End of Fixlog ==== |
09.07.2013, 17:29 | #58 |
/// the machine /// TB-Ausbilder | Internet total langsam Teste den rechner nochmal.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.07.2013, 17:32 | #59 |
| Internet total langsam Juhuuuuuuuuuuuuu !!!! Es geht wieder! Danke schrauber. Vielen herzlichen Dank ! Ähm dafür dauert jetzt der Startvorgang des Rechners Ewigkeiten. Was soll ich jetzt tun? Ich hab ja keine Virenschutzprogramme mehr drauf, die sollte ich ja deinstallieren. Gruß Hannes |
09.07.2013, 17:36 | #60 |
/// the machine /// TB-Ausbilder | Internet total langsam Installier eines und poste ein frisches FRST Log
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Internet total langsam |
adwcleaner, bauen, ccleaner, garnicht, inter, interne, internet, langsam, laufe, laufen, modem, nacht, provider, sehr langsam, tagen, total |