|
Plagegeister aller Art und deren Bekämpfung: Internet total langsamWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
02.07.2013, 17:20 | #1 |
| Internet total langsam Hallo, seit einigen Tagen ist mein Internet total langsam geworden. (über Nacht) Seiten bauen sich sehr langsam auf. Und auf meiner Hauptspieleseite kann ich so gut wie garnicht mehr spielen. Hab schon den CCleaner laufen lassen und hab auch den ADWCleaner benützt, leider ohne Erfolg. Mein Provider hat auch das Modem ausgetauscht. Auch ohne Erfolg. Kann mir bitt e jemand helfen? Gruß Hannes |
02.07.2013, 17:33 | #2 |
/// the machine /// TB-Ausbilder | Internet total langsam hi,
__________________Systemscan mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Start > Computer (Rechtsklick) > Eigenschaften)
__________________ |
02.07.2013, 18:04 | #3 |
| Internet total langsam Hi Schrauber,
__________________hier zuerst der FRST.txt und direkt darauffolgend der Addition.text: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-07-2013 Ran by asus pro 5if (administrator) on 02-07-2013 18:59:27 Running from C:\Users\asus pro 5if\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Windows\AsScrPro.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe (ASUS) C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe () C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (SRS Labs, Inc.) C:\Program Files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe () C:\Program Files (x86)\MyPC Backup\MyPC Backup.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (4G Systems GmbH & Co. KG) C:\Windows\starter4g.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe () C:\Program Files (x86)\XSManager\WTGService.exe (4G Systems GmbH & Co. KG) C:\Windows\service4g.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe (asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe () C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\BM\TMBMSRV.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe (Avira Operations GmbH & Co. KG) C:\program files (x86)\avira\antivir desktop\ipmGui.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe [649608 2010-06-10] (ELAN Microelectronic Corp.) HKLM\...\Run: [ASUS WebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-16] () HKLM\...\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [1022904 2010-02-23] (Trend Micro Inc.) HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-19] () HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1928976 2010-03-05] (Intel(R) Corporation) HKLM\...\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd [x] HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-10-12] (Google Inc.) HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [19604072 2013-06-03] (Skype Technologies S.A.) MountPoints2: {24d81e20-1472-11e1-a18d-806e6f6e6963} - F:\autorun.exe HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" [87336 2009-07-06] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2010-06-25] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [Boingo Wi-Fi] "C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2429 2010-10-12] () HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS) HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-08-12] () HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2011-09-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [starter4g] C:\Windows\starter4g.exe [160992 2010-07-08] (4G Systems GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345144 2013-06-27] (Avira Operations GmbH & Co. KG) HKU\Gast\...\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe [370480 2010-04-05] (syncables, LLC) HKU\Gast\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-10-12] (Google Inc.) Startup: C:\ProgramData\Start Menu\Programs\Startup\FancyStart daemon.lnk ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe () Startup: C:\ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) Startup: C:\ProgramData\Start Menu\Programs\Startup\SRS Premium Sound.lnk ShortcutTarget: SRS Premium Sound.lnk -> C:\Windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe (Acresso Software Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll (Google Inc.) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.) BHO-x32: HomeTab - {ba696155-d96e-4281-b467-0367a0456474} - C:\Users\asus pro 5if\AppData\Roaming\HomeTab\HomeTab.dll No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM-x32 - HomeTab - {ba696155-d96e-4281-b467-0367a0456474} - C:\Users\asus pro 5if\AppData\Roaming\HomeTab\HomeTab.dll No File Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 83.169.184.225 83.169.184.161 Chrome: ======= CHR HomePage: about:newtab?source=home CHR RestoreOnStartup: "about:newtab?source=home" CHR DefaultSearchURL: (Web Search) - hxxp://search.certified-toolbar.com?si=46364&st=bs&tid=3869&ver=3.2&ts=1372699116807.000001&tguid=46364-3869-1372699116807-09CDE1E273FC0271C3DEA1E352C902B3&q={searchTerms} CHR DefaultSuggestURL: (Web Search) - "suggest_url": "" CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll No File CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_169.dll No File CHR Extension: (Plus-HD-2.4) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\hojmbfiljpkaijkdifoaacbpallpfkkf\1.23.9_0 CHR Extension: (Skype Click to Call) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0 CHR Extension: (Amazon 1Button App for Chrome) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam\3.2013.627.0_0 ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG) R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] () R2 ezGOSvc; C:\Windows\SysWOW64\ezGOSvc.dll [80256 2011-08-07] () S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-03-05] () R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] () R2 SfCtlCom; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [859712 2010-10-09] (Trend Micro Inc.) R3 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () R3 TMBMServer; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [570632 2010-02-23] (Trend Micro Inc.) R3 TmProxy; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [917768 2010-02-23] (Trend Micro Inc.) R2 WTGService; C:\Program Files (x86)\XSManager\WTGService.exe [329168 2010-04-12] () R2 XS Stick Service; C:\Windows\service4g.exe [145120 2010-07-08] (4G Systems GmbH & Co. KG) S2 SystemStoreService; "C:\Program Files (x86)\SoftwareUpdater\SystemStore.exe" -displayname "System Store" -servicename "SystemStoreService" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-04-22] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-04-22] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-04-22] (Avira Operations GmbH & Co. KG) S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2011-11-21] (Mobile Connector) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () R2 tmpreflt; C:\Windows\System32\DRIVERS\tmpreflt.sys [42768 2011-07-12] (Trend Micro Inc.) R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [107536 2010-02-23] (Trend Micro Inc.) R2 tmxpflt; C:\Windows\System32\DRIVERS\tmxpflt.sys [342288 2011-07-12] (Trend Micro Inc.) R2 vsapint; C:\Windows\System32\DRIVERS\vsapint.sys [2077456 2011-07-12] (Trend Micro Inc.) S3 ipswuio; System32\DRIVERS\ipswuio.sys [x] U3 tmlwf; U3 tmwfp; ==================== NetSvcs (Whitelisted) =================== NETSVC: ezGOSvc -> C:\Windows\SysWOW64\ezGOSvc.dll () ==================== One Month Created Files and Folders ======== 2013-07-02 18:59 - 2013-07-02 18:59 - 00000000 ____D C:\FRST 2013-07-02 18:57 - 2013-07-02 18:58 - 01933556 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-02 18:56 - 2013-07-02 18:56 - 00095168 ____A C:\Users\asus pro 5if\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-02 14:15 - 2013-07-02 14:15 - 00000000 ____D C:\Program Files (x86)\Covus Freemium 2013-07-02 11:22 - 2013-07-02 11:23 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-01 19:44 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-01 19:44 - 00001070 ____A C:\Users\asus pro 5if\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-01 19:41 - 2013-07-01 19:41 - 00000000 ____D C:\Program Files (x86)\SoftwareUpdater 2013-07-01 19:37 - 2013-07-01 19:40 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:35 - 2013-07-01 19:35 - 00000000 ____D C:\ProgramData\Systweak 2013-07-01 19:35 - 2012-07-25 12:03 - 00016896 ____A C:\Windows\System32\sasnative64.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00129536 ____A C:\Users\Public\AlexaNSISPlugin.1620.dll 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:33 - 2013-07-02 14:18 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-01 19:33 - 2013-07-01 20:32 - 00000298 ____A C:\Windows\Tasks\RegClean Pro_UPDATES.job 2013-07-01 19:33 - 2013-07-01 19:35 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Systweak 2013-07-01 19:33 - 2013-05-27 16:01 - 00020312 ____A (Systweak Inc., (www.systweak.com)) C:\Windows\System32\roboot64.exe 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-02 14:10 - 00001208 ____A C:\Windows\Tasks\Plus-HD-2.4-updater.job 2013-07-01 19:24 - 2013-07-02 14:10 - 00001112 ____A C:\Windows\Tasks\Plus-HD-2.4-enabler.job 2013-07-01 19:24 - 2013-07-02 07:41 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-07-01 19:23 - 2013-07-02 14:10 - 00001918 ____A C:\Windows\Tasks\Plus-HD-2.4-chromeinstaller.job 2013-07-01 19:23 - 2013-07-02 14:10 - 00001212 ____A C:\Windows\Tasks\Plus-HD-2.4-codedownloader.job 2013-07-01 19:23 - 2013-07-01 19:24 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.4 2013-07-01 19:19 - 2013-06-27 07:14 - 00031816 ____A C:\Windows\Launcher.exe 2013-07-01 19:18 - 2013-07-02 14:15 - 00002563 ____A C:\Users\Public\Desktop\Free System Utilities.lnk 2013-07-01 19:18 - 2013-07-01 19:18 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2013-07-01 19:17 - 2013-07-01 19:17 - 00000000 ____D C:\ProgramData\Package Cache 2013-07-01 19:10 - 2013-07-01 19:11 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\DownloadGuide 2013-07-01 19:10 - 2013-07-01 19:10 - 00444408 ____A C:\Users\asus pro 5if\Downloads\free-system-utilities-DE.exe 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 21:59 - 2013-06-27 22:00 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:31 - 2013-06-27 20:31 - 00002257 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-06-27 20:23 - 2013-04-23 22:06 - 00000567 ____A C:\zoek-results23.04.2013-2206.log 2013-06-27 20:07 - 2013-06-27 20:08 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:07 - 2013-06-27 19:42 - 00648201 ____A C:\Users\asus pro 5if\Desktop\adwcleaner2303.exe 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:44 - 2013-06-27 19:45 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:43 - 2013-06-27 19:44 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-20 19:23 - 2013-06-26 08:15 - 00002058 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt ==================== One Month Modified Files and Folders ======= 2013-07-02 18:59 - 2013-07-02 18:59 - 00000000 ____D C:\FRST 2013-07-02 18:59 - 2012-01-09 09:51 - 00000824 ____A C:\Windows\System32\Drivers\etc\tmvsthfud.bin 2013-07-02 18:59 - 2010-10-12 21:19 - 00000824 ____A C:\Windows\System32\Drivers\etc\tmvsthfss.bin 2013-07-02 18:58 - 2013-07-02 18:57 - 01933556 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-02 18:56 - 2013-07-02 18:56 - 00095168 ____A C:\Users\asus pro 5if\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-02 18:44 - 2010-10-12 21:13 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-02 18:15 - 2010-10-12 20:50 - 01212173 ____A C:\Windows\WindowsUpdate.log 2013-07-02 18:10 - 2012-07-02 22:16 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-02 14:19 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-02 14:19 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-02 14:18 - 2013-07-01 19:33 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-02 14:16 - 2009-08-04 11:51 - 00697550 ____A C:\Windows\System32\perfh007.dat 2013-07-02 14:16 - 2009-08-04 11:51 - 00148556 ____A C:\Windows\System32\perfc007.dat 2013-07-02 14:16 - 2009-07-14 07:13 - 01614964 ____A C:\Windows\System32\PerfStringBackup.INI 2013-07-02 14:15 - 2013-07-02 14:15 - 00000000 ____D C:\Program Files (x86)\Covus Freemium 2013-07-02 14:15 - 2013-07-01 19:18 - 00002563 ____A C:\Users\Public\Desktop\Free System Utilities.lnk 2013-07-02 14:11 - 2011-08-03 17:01 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Skype 2013-07-02 14:11 - 2010-10-12 21:13 - 00001120 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-02 14:10 - 2013-07-01 19:24 - 00001208 ____A C:\Windows\Tasks\Plus-HD-2.4-updater.job 2013-07-02 14:10 - 2013-07-01 19:24 - 00001112 ____A C:\Windows\Tasks\Plus-HD-2.4-enabler.job 2013-07-02 14:10 - 2013-07-01 19:23 - 00001918 ____A C:\Windows\Tasks\Plus-HD-2.4-chromeinstaller.job 2013-07-02 14:10 - 2013-07-01 19:23 - 00001212 ____A C:\Windows\Tasks\Plus-HD-2.4-codedownloader.job 2013-07-02 14:10 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-02 11:23 - 2013-07-02 11:22 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-02 07:41 - 2013-07-01 19:24 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl 2013-07-02 07:36 - 2011-08-01 23:49 - 00045056 ____A C:\Windows\System32\acovcnt.exe 2013-07-01 20:34 - 2010-10-12 21:43 - 00001433 ____A C:\Windows\System32\ServiceFilter.ini 2013-07-01 20:32 - 2013-07-01 19:33 - 00000298 ____A C:\Windows\Tasks\RegClean Pro_UPDATES.job 2013-07-01 20:32 - 2010-10-12 21:43 - 00002210 ____A C:\Windows\System32\AutoRunFilter.ini 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-01 19:44 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-01 19:44 - 00001070 ____A C:\Users\asus pro 5if\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-01 19:41 - 2013-07-01 19:41 - 00000000 ____D C:\Program Files (x86)\SoftwareUpdater 2013-07-01 19:40 - 2013-07-01 19:37 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:35 - 2013-07-01 19:35 - 00000000 ____D C:\ProgramData\Systweak 2013-07-01 19:35 - 2013-07-01 19:33 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Systweak 2013-07-01 19:34 - 2013-07-01 19:34 - 00129536 ____A C:\Users\Public\AlexaNSISPlugin.1620.dll 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-07-01 19:24 - 2013-07-01 19:23 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.4 2013-07-01 19:18 - 2013-07-01 19:18 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2013-07-01 19:17 - 2013-07-01 19:17 - 00000000 ____D C:\ProgramData\Package Cache 2013-07-01 19:11 - 2013-07-01 19:10 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\DownloadGuide 2013-07-01 19:10 - 2013-07-01 19:10 - 00444408 ____A C:\Users\asus pro 5if\Downloads\free-system-utilities-DE.exe 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 22:00 - 2013-06-27 21:59 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:31 - 2013-06-27 20:31 - 00002257 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-06-27 20:23 - 2013-04-23 18:49 - 00000393 ____A C:\zoek-results.log 2013-06-27 20:08 - 2013-06-27 20:07 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:04 - 2009-07-29 08:03 - 00000000 ____D C:\Windows\Panther 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:45 - 2013-06-27 19:44 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:44 - 2013-06-27 19:43 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:42 - 2013-06-27 20:07 - 00648201 ____A C:\Users\asus pro 5if\Desktop\adwcleaner2303.exe 2013-06-27 19:29 - 2011-08-03 17:01 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-27 19:29 - 2011-08-03 17:00 - 00000000 ____D C:\ProgramData\Skype 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-27 11:38 - 2013-05-07 15:27 - 00083672 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avnetflt.sys 2013-06-27 07:14 - 2013-07-01 19:19 - 00031816 ____A C:\Windows\Launcher.exe 2013-06-26 08:15 - 2013-06-20 19:23 - 00002058 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt 2013-06-11 20:10 - 2012-07-02 22:16 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-11 20:10 - 2011-10-12 11:51 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-23 00:41 ==================== End Of Log ============================ FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-07-2013 Ran by asus pro 5if at 2013-07-02 19:00:21 Running from C:\Users\asus pro 5if\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 1.6.65) Adobe AIR (x32 Version: 1.5.0.7220) Adobe Flash Player 10 ActiveX (x32 Version: 10.0.42.34) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Reader 9.4.6 MUI (x32 Version: 9.4.6) Advanced System Protector (x32 Version: 2.1.1000.10905) ASUS AI Recovery (x32 Version: 1.0.24) ASUS CopyProtect (x32 Version: 1.0.0015) ASUS Data Security Manager (x32 Version: 1.00.0014) ASUS FancyStart (x32 Version: 1.0.8) ASUS LifeFrame3 (x32 Version: 3.0.20) ASUS Live Update (x32 Version: 2.5.9) ASUS MultiFrame (x32 Version: 1.0.0021) ASUS Power4Gear Hybrid (Version: 1.1.37) ASUS SmartLogon (x32 Version: 1.0.0008) ASUS Splendid Video Enhancement Technology (x32 Version: 1.02.0028) ASUS Video Magic (x32 Version: 6.0.4015) ASUS Virtual Camera (x32 Version: 1.0.20) ASUS WebStorage (x32 Version: 2.0.46.1429) ATK Package (x32 Version: 1.0.0006) AutoCAD 2012 - Deutsch (Version: 18.2.51.0) AutoCAD 2012 Language Pack - Deutsch (Version: 18.2.51.0) Autodesk Content Service (x32 Version: 2.0.90) Autodesk Material Library 2012 (x32 Version: 2.5.0.8) Autodesk Material Library Base Resolution Image Library 2012 (x32 Version: 2.5.0.8) Avira Free Antivirus (x32 Version: 13.0.0.3737) Bing Bar (x32 Version: 7.0.850.0) Boingo Wi-Fi (x32 Version: 1.7.0048) CCleaner (Version: 4.03) Choice Guard (x32 Version: 1.2.87.0) Conexant HD Audio (Version: 4.111.0.63) ControlDeck (x32 Version: 1.0.8) CyberLink LabelPrint (x32 Version: 2.5.1908) CyberLink MediaShow Espresso (x32 Version: 5.0.1606_25588) CyberLink PhotoNow (x32 Version: 1.1.6904) CyberLink Power2Go (x32 Version: 6.1.3602c) CyberLink PowerDirector (x32 Version: 8.0.2609a) CyberLink PowerDVD 9 (x32 Version: 9.0.3009.50) EasyBits GO (HKCU) ETDWare PS/2-x64 7.0.5.13_WHQL (Version: 7.0.5.13) FARO LS 1.1.406.58 (x32 Version: 4.6.58.2) Fast Boot (Version: 1.0.6) FLV-Media Player 1.8 (x32 Version: 1.8) Free System Utilities (x32 Version: 1.1.0.95) Free SystemUtilities (x32 Version: 1.1.0.95) Google Chrome (x32 Version: 27.0.1453.116) Google Toolbar for Internet Explorer (x32 Version: 1.0.0) Google Toolbar for Internet Explorer (x32 Version: 7.5.4209.2358) Google Update Helper (x32 Version: 1.3.21.145) HomeTab 3.7 (x32 Version: 3.7) Iminent (x32 Version: 6.25.21.0) Intel PROSet Wireless Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Graphics Media Accelerator Driver (x32 Version: 8.15.10.2125) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) PROSet/Wireless WiFi Software (Version: 13.02.0000) Intel(R) Wireless Display (Version: 1.2.20.0) JMicron Ethernet Adapter NDIS Driver (x32 Version: 6.0.17.1) JMicron Flash Media Controller Driver (x32 Version: 1.0.33.2) Junk Mail filter update (x32 Version: 14.0.8050.1202) K_Series_ScreenSaver_EN (x32) McAfee Security Scan Plus (x32 Version: 3.0.318.3) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000) Microsoft Silverlight (x32 Version: 4.1.10111.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Sync Framework Runtime Native v1.0 (x86) (x32 Version: 1.0.1215.0) Microsoft Sync Framework Services Native v1.0 (x86) (x32 Version: 1.0.1215.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) MSVCRT (x32 Version: 14.0.1468.721) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) NB Probe (x32) Net4Switch (x32 Version: 1.00.0020) Opera 12.15 (x32 Version: 12.15.1748) Paint.NET v3.5.8 (Version: 3.58.0) Plus-HD-2.4 (x32 Version: 1.27.153.6) Pontifex II (x32 Version: ) RegClean Pro (x32 Version: 6.21) Skype Click to Call (x32 Version: 5.10.9560) Skype™ 6.5 (x32 Version: 6.5.158) syncables desktop SE (x32 Version: 5.5.615.9518) Trend Micro Internet Security (Version: 17.50) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) USB2.0 UVC VGA WebCam (Version: 5.8.54000.207) VLC media player 1.1.11 (x32 Version: 1.1.11) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.6) Windows Live Call (x32 Version: 14.0.8050.1202) Windows Live Communications Platform (x32 Version: 14.0.8050.1202) Windows Live Essentials (x32 Version: 14.0.8050.1202) Windows Live Family Safety (Version: 14.0.8052.1208) Windows Live Fotogalerie (x32 Version: 14.0.8051.1204) Windows Live Mail (x32 Version: 14.0.8050.1202) Windows Live Messenger (x32 Version: 14.0.8050.1202) Windows Live Sync (x32 Version: 14.0.8050.1202) Windows Live Writer (x32 Version: 14.0.8050.1202) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029) WinFlash (x32 Version: 2.30.3) WinRAR 4.20 (32-Bit) (x32 Version: 4.20.0) Wireless Console 3 (x32 Version: 3.0.18) XSManager (x32 Version: 3.0) ==================== Restore Points ========================= 27-06-2013 17:27:49 Installed Skype™ 6.5 01-07-2013 17:17:34 Free System Utilities 01-07-2013 17:29:31 Free System Utilities 01.07.2013 19:29:29 01-07-2013 17:30:43 Free System Utilities 01.07.2013 19:30:42 01-07-2013 17:34:30 RegClean Pro Mo, Jul 01, 13 19:34 ==================== Scheduled Tasks (whitelisted) ============= Task: {0E282B17-D104-4AD2-B82A-32ECF7892786} - System32\Tasks\Browser Updater\Browser Updater => C:\Windows\system32\rundll32.exe [2009-07-14] (Microsoft Corporation) Task: {12DABD06-C8D2-462E-937F-3FBADA8A559B} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] () Task: {24A34CFE-2CBD-4913-9E96-5861F6F5F99C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-05-28] (ATK) Task: {24CC42E7-515E-4C08-8365-D1A50F36E458} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {2B2AA4C6-9B2F-4725-9B63-1BE51240A6A8} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe No File Task: {324E82F7-D064-44D5-BA77-75826922E3CA} - System32\Tasks\ASUSControlDeck => C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe [2010-06-09] (asus) Task: {3951030E-CB71-486D-B3D8-8AF547C9905D} - System32\Tasks\{78ABA6A5-01CC-4830-ABA9-AAEEAAFA3211} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-06-03] (Skype Technologies S.A.) Task: {433DA0EA-37B2-4EB0-A90C-D4008A1BD429} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe No File Task: {52FC4F05-4CEA-4A42-9741-6D0D7BF5A73D} - System32\Tasks\Net4Switch => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe [2009-09-23] (ASUS) Task: {699264D4-0D35-4784-AD7F-8CBF3D5E29A4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {6B60EE87-CF7B-496D-932A-82D77CFB20BC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-11] (Adobe Systems Incorporated) Task: {765D21BA-0C98-45DD-A5A2-C1AD88B0DCEC} - System32\Tasks\{26D6A9BB-3CFC-4286-AB29-46DF1F2FA2DE} => C:\program files (x86)\opera\opera.exe [2013-04-09] (Opera Software) Task: {79492728-14A4-4634-B22B-234AB4A0FEA2} - System32\Tasks\ASPG => C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS) Task: {7CA210CD-3096-4280-A903-23CFFF2FB634} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {80C1B2D2-609C-4064-960D-6C79413850B3} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe No File Task: {80D71377-1C0C-407E-B00E-7E87AD0CFD23} - System32\Tasks\Plus-HD-2.4-updater => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-updater.exe [2013-07-01] (Plus HD) Task: {9BDDC737-37B5-4199-A590-DEB3238974F3} - System32\Tasks\Plus-HD-2.4-chromeinstaller => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-chromeinstaller.exe [2013-07-01] (Plus HD) Task: {A585B730-AA46-4D11-A49C-B597D9067F7A} - System32\Tasks\Software Updater => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe No File Task: {A738714F-FDF5-4018-89D1-C58261B4A148} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {AEF09552-1EC4-473E-9797-E326A4B8D576} - System32\Tasks\RegClean Pro_UPDATES => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe No File Task: {B02BD60F-1E22-4AA8-A1E8-9D11BC6CF3D8} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2009-07-14] (Microsoft Corporation) Task: {B5EF9A3D-9AE9-44A2-9DA7-8088692E5100} - System32\Tasks\Plus-HD-2.4-codedownloader => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-codedownloader.exe [2013-07-01] (Plus HD) Task: {B92D7D8E-825D-4858-B1E5-577192A364A8} - System32\Tasks\AIRecoveryRemind => C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe [2012-03-09] (ASUSTek Computer Inc.) Task: {BFD2AAB0-9059-4444-8B96-E22B494E7A1B} - System32\Tasks\Freemium1ClickMaint => C:\Users\asus pro 5if\Downloads\1Click.exe No File Task: {DC2F45BA-04CC-414C-9B50-10F48095D6FA} - System32\Tasks\Software Updater Ui => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Ui.exe No File Task: {DE2A2A1B-993A-40D5-B08A-2CF845BD02F7} - System32\Tasks\Plus-HD-2.4-enabler => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-enabler.exe [2013-07-01] (Plus HD) Task: {DF45D3D6-E963-44A8-9F0D-D49D1EE068CB} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-07-31] (ASUS) Task: {E2646E39-B340-4208-9607-8789FDC56B85} - System32\Tasks\FinishInstall igdhbblpcellaljokkpfhcjlagemhgjl => C:\Users\asus pro 5if\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl\MinibarChrome.exe [2013-07-01] (Sien SA) Task: {E2B3EB42-00D0-4770-9664-63BE47C60241} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK) Task: {F3CF1967-E129-4FEB-A2A3-B47684F5C8D4} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {F46AB22C-23A3-4EE7-BF5A-C9FA3785801E} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-08-04] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Net4Switch.job => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe Task: C:\Windows\Tasks\Plus-HD-2.4-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-chromeinstaller.exe Task: C:\Windows\Tasks\Plus-HD-2.4-codedownloader.job => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-codedownloader.exe Task: C:\Windows\Tasks\Plus-HD-2.4-enabler.job => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-enabler.exe Task: C:\Windows\Tasks\Plus-HD-2.4-updater.job => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-updater.exe Task: C:\Windows\Tasks\RegClean Pro_UPDATES.job => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/02/2013 02:13:50 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: sllauncher.exe, Version: 4.1.10111.0, Zeitstempel: 0x4f0e1254 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7600.16850, Zeitstempel: 0x4e211485 Ausnahmecode: 0xc00000fd Fehleroffset: 0x0000b9bc ID des fehlerhaften Prozesses: 0x1680 Startzeit der fehlerhaften Anwendung: 0xsllauncher.exe0 Pfad der fehlerhaften Anwendung: sllauncher.exe1 Pfad des fehlerhaften Moduls: sllauncher.exe2 Berichtskennung: sllauncher.exe3 Error: (07/02/2013 11:27:18 AM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: sllauncher.exe, Version: 4.1.10111.0, Zeitstempel: 0x4f0e1254 Name des fehlerhaften Moduls: KERNELBASE.dll, Version: 6.1.7600.16850, Zeitstempel: 0x4e211485 Ausnahmecode: 0xc00000fd Fehleroffset: 0x0000b9bc ID des fehlerhaften Prozesses: 0x17b4 Startzeit der fehlerhaften Anwendung: 0xsllauncher.exe0 Pfad der fehlerhaften Anwendung: sllauncher.exe1 Pfad des fehlerhaften Moduls: sllauncher.exe2 Berichtskennung: sllauncher.exe3 Error: (07/02/2013 08:24:56 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (07/02/2013 08:24:48 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/02/2013 08:24:48 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/02/2013 08:24:48 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/02/2013 08:24:48 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/02/2013 08:24:47 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/01/2013 07:18:46 PM) (Source: Microsoft-Windows-CAPI2) (User: ) Description: Fehler beim Extrahieren der Drittanbieterstammliste aus der automatischen Aktualisierungs-CAB-Datei bei <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab>. Fehler: Ein erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. . Error: (07/01/2013 04:06:16 PM) (Source: Windows Search Service) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) System errors: ============= Error: (07/02/2013 02:11:25 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "System Store" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/02/2013 02:11:14 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computer Backup (MyPC Backup)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/02/2013 02:11:14 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Computer Backup (MyPC Backup) erreicht. Error: (07/02/2013 02:09:56 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am ?02.?07.?2013 um 14:08:30 unerwartet heruntergefahren. Error: (07/02/2013 11:25:46 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "System Store" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/02/2013 11:25:45 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computer Backup (MyPC Backup)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/02/2013 11:25:45 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Computer Backup (MyPC Backup) erreicht. Error: (07/02/2013 07:37:27 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "System Store" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/02/2013 07:37:05 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Computer Backup (MyPC Backup)" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/02/2013 07:37:05 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Computer Backup (MyPC Backup) erreicht. Microsoft Office Sessions: ========================= Error: (07/02/2013 02:13:50 PM) (Source: Application Error)(User: ) Description: sllauncher.exe4.1.10111.04f0e1254KERNELBASE.dll6.1.7600.168504e211485c00000fd0000b9bc168001ce771d86f68fd6C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exeC:\Windows\syswow64\KERNELBASE.dlld9f80175-e310-11e2-83dc-20cf30d033be Error: (07/02/2013 11:27:18 AM) (Source: Application Error)(User: ) Description: sllauncher.exe4.1.10111.04f0e1254KERNELBASE.dll6.1.7600.168504e211485c00000fd0000b9bc17b401ce770645f8db2cC:\Program Files (x86)\Microsoft Silverlight\sllauncher.exeC:\Windows\syswow64\KERNELBASE.dll967c09f7-e2f9-11e2-a6ee-20cf30d033be Error: (07/02/2013 08:24:56 AM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (07/02/2013 08:24:48 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"c:\program files\trend micro\internet security\component\framework\200\UfUpdUi.exe Error: (07/02/2013 08:24:48 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"c:\program files\trend micro\internet security\component\framework\200\UfSeAgnt.exe Error: (07/02/2013 08:24:48 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"c:\program files\trend micro\internet security\component\framework\200\UfNavi.exe Error: (07/02/2013 08:24:48 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"c:\program files\trend micro\internet security\component\framework\200\UfLogUi.exe Error: (07/02/2013 08:24:47 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"c:\program files\trend micro\internet security\component\framework\200\TisScan.exe Error: (07/01/2013 07:18:46 PM) (Source: Microsoft-Windows-CAPI2)(User: ) Description: hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cabEin erforderliches Zertifikat befindet sich nicht im Gültigkeitszeitraum gemessen an der aktuellen Systemzeit oder dem Zeitstempel in der signierten Datei. Error: (07/01/2013 04:06:16 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) ==================== Memory info =========================== Percentage of memory in use: 48% Total physical RAM: 2924.56 MB Available physical RAM: 1507.68 MB Total Pagefile: 5847.26 MB Available Pagefile: 3774.15 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:72.69 GB) (Free:38.89 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:205.87 GB) (Free:203.68 GB) NTFS (Disk=0 Partition=3) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 0237A506) Partition 1: (Not Active) - (Size=20 GB) - (Type=1C) Partition 2: (Active) - (Size=73 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=206 GB) - (Type=OF Extended) ==================== End Of Log ============================ |
02.07.2013, 18:44 | #4 | |
/// the machine /// TB-Ausbilder | Internet total langsamCombofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
02.07.2013, 19:36 | #5 |
| Internet total langsam Hi schrauber, hier die Logdatei von ComboFix: Combofix Logfile: Code:
ATTFilter ComboFix 13-07-02.03 - asus pro 5if 02.07.2013 19:57:29.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7600.0.1252.49.1031.18.2925.1505 [GMT 2:00] ausgeführt von:: c:\users\asus pro 5if\Desktop\ComboFix.exe AV: Avira Desktop *Disabled/Updated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AV: Trend Micro Internet Security *Disabled/Outdated* {68F968AC-2AA0-091D-848C-803E83E35902} SP: Avira Desktop *Disabled/Updated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Trend Micro Internet Security *Disabled/Outdated* {D3988948-0C9A-0693-BE3C-BB4CF86413BF} SP: Windows Defender *Enabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\esupport\eDriver\Software\ASUS\MultiFrame\XP32_Vista32_Vista64_Win7_32_Win7_64_1.0.0021\Desktop_.ini c:\program files (x86)\Common Files\ASPG_icon.ico c:\program files (x86)\Common Files\Net4Switch.ico c:\program files (x86)\Windows Live\Messenger\msacm32.dll c:\users\Public\AlexaNSISPlugin.1620.dll c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe c:\windows\msvcr71.dll . . ((((((((((((((((((((((( Dateien erstellt von 2013-06-02 bis 2013-07-02 )))))))))))))))))))))))))))))) . . 2013-07-02 18:09 . 2013-07-02 18:09 -------- d-----w- c:\users\Gast\AppData\Local\temp 2013-07-02 18:09 . 2013-07-02 18:09 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-07-02 16:59 . 2013-07-02 16:59 -------- d-----w- C:\FRST 2013-07-02 12:15 . 2013-07-02 12:15 -------- d-----w- c:\program files (x86)\Covus Freemium 2013-07-01 17:59 . 2013-07-01 17:59 -------- d-----w- c:\programdata\Uniblue 2013-07-01 17:44 . 2013-07-01 17:44 -------- d-sh--w- c:\windows\ftpcache 2013-07-01 17:44 . 2013-07-01 17:44 -------- d-----w- c:\program files (x86)\FLV-Media Player 2013-07-01 17:41 . 2013-07-01 17:41 -------- d-----w- c:\program files (x86)\SoftwareUpdater 2013-07-01 17:35 . 2013-07-01 17:35 -------- d-----w- c:\programdata\Systweak 2013-07-01 17:35 . 2012-07-25 10:03 16896 ----a-w- c:\windows\system32\sasnative64.exe 2013-07-01 17:34 . 2013-07-01 17:34 -------- d-----w- c:\program files (x86)\Amazon 2013-07-01 17:33 . 2013-07-02 12:18 -------- d-----w- c:\program files (x86)\MyPC Backup 2013-07-01 17:33 . 2013-07-01 17:35 -------- d-----w- c:\users\asus pro 5if\AppData\Roaming\Systweak 2013-07-01 17:33 . 2013-05-27 14:01 20312 ----a-w- c:\windows\system32\roboot64.exe 2013-07-01 17:32 . 2013-07-01 17:32 -------- d-----w- c:\users\asus pro 5if\AppData\Local\Programs 2013-07-01 17:27 . 2013-07-01 17:27 -------- d-----w- c:\users\asus pro 5if\AppData\Local\Freemium 2013-07-01 17:24 . 2013-07-02 05:41 -------- d-----w- c:\users\asus pro 5if\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl 2013-07-01 17:23 . 2013-07-01 17:24 -------- d-----w- c:\program files (x86)\Plus-HD-2.4 2013-07-01 17:19 . 2013-06-27 05:14 31816 ----a-w- c:\windows\Launcher.exe 2013-07-01 17:18 . 2013-07-01 17:18 -------- d-----w- c:\programdata\FreeSystemUtilities 2013-07-01 17:17 . 2013-07-01 17:17 -------- d-----w- c:\programdata\Package Cache 2013-07-01 17:10 . 2013-07-01 17:11 -------- d-----w- c:\users\asus pro 5if\AppData\Local\DownloadGuide 2013-06-27 18:03 . 2013-06-27 18:03 -------- d-----w- c:\program files\CCleaner 2013-06-27 17:29 . 2013-06-27 17:29 -------- d-----w- c:\program files (x86)\Common Files\Skype 2013-06-27 17:25 . 2013-06-27 17:25 -------- d-----w- c:\program files\Skype . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-02 05:36 . 2011-08-01 21:49 45056 ----a-w- c:\windows\system32\acovcnt.exe 2013-06-27 09:38 . 2013-05-07 13:27 83672 ----a-w- c:\windows\system32\drivers\avnetflt.sys 2013-06-11 18:10 . 2012-07-02 20:16 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-06-11 18:10 . 2011-10-12 09:51 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-04-22 19:08 . 2013-04-22 19:23 28600 ----a-w- c:\windows\system32\drivers\avkmgr.sys 2013-04-22 19:08 . 2013-04-22 19:23 130016 ----a-w- c:\windows\system32\drivers\avipbb.sys 2013-04-22 19:08 . 2013-04-22 19:23 100712 ----a-w- c:\windows\system32\drivers\avgntflt.sys 2009-04-08 17:31 . 2009-04-08 17:31 106496 ----a-w- c:\program files (x86)\Common Files\CPInstallAction.dll 2008-08-12 04:45 . 2008-08-12 04:45 155648 ----a-w- c:\program files (x86)\Common Files\MSIactionall.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-02 00:08 143360 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x86\OverlayIconShlExt1.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2010-10-12 39408] "Skype"="c:\program files (x86)\Skype\Phone\Skype.exe" [2013-06-03 19604072] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "RemoteControl9"="c:\program files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" [2009-07-06 87336] "UpdatePSTShortCut"="c:\program files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" [2010-06-24 210216] "UpdateLBPShortCut"="c:\program files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "UpdateP2GoShortCut"="c:\program files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" [2009-05-20 222504] "Boingo Wi-Fi"="c:\program files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2010-10-12 2429] "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-05-03 170624] "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-08-12 1597440] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2011-03-30 937920] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2011-09-07 37296] "starter4g"="c:\windows\starter4g.exe" [2010-07-08 160992] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-06-27 345144] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe -d [2010-10-12 12862] McAfee Security Scan Plus.lnk - c:\program files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe [2013-2-5 272248] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux"=wdmaud.drv . R2 BBSvc;Bing Bar Update Service;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE;c:\program files (x86)\Microsoft\BingBar\BBSvc.EXE [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SystemStoreService;System Store;c:\program files (x86)\SoftwareUpdater\SystemStore.exe -displayname System Store -servicename SystemStoreService;c:\program files (x86)\SoftwareUpdater\SystemStore.exe -displayname System Store -servicename SystemStoreService [x] R3 cmnsusbser;Mobile Connector USB Device for Legacy Serial Communication LCT2053s;c:\windows\system32\DRIVERS\cmnsusbser.sys;c:\windows\SYSNATIVE\DRIVERS\cmnsusbser.sys [x] R3 FLEXnet Licensing Service 64;FLEXnet Licensing Service 64;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe;c:\program files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe [x] R3 ipswuio;ipswuio;c:\windows\system32\DRIVERS\ipswuio.sys;c:\windows\SYSNATIVE\DRIVERS\ipswuio.sys [x] R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe;c:\program files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] S0 lullaby;lullaby;c:\windows\system32\DRIVERS\lullaby.sys;c:\windows\SYSNATIVE\DRIVERS\lullaby.sys [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 Autodesk Content Service;Autodesk Content Service;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe;c:\program files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [x] S2 BBUpdate;BBUpdate;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE;c:\program files (x86)\Microsoft\BingBar\SeaPort.EXE [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 ezGOSvc;Easybits GO Services for Windows;c:\windows\system32\svchost.exe;c:\windows\SYSNATIVE\svchost.exe [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 tmpreflt;tmpreflt;c:\windows\system32\DRIVERS\tmpreflt.sys;c:\windows\SYSNATIVE\DRIVERS\tmpreflt.sys [x] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 WTGService;WTGService;c:\program files (x86)\XSManager\WTGService.exe;c:\program files (x86)\XSManager\WTGService.exe [x] S2 XS Stick Service;XS Stick Service;c:\windows\service4g.exe;c:\windows\service4g.exe [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x] S3 Impcd;Impcd;c:\windows\system32\DRIVERS\Impcd.sys;c:\windows\SYSNATIVE\DRIVERS\Impcd.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 JMCR;JMCR;c:\windows\system32\DRIVERS\jmcr.sys;c:\windows\SYSNATIVE\DRIVERS\jmcr.sys [x] S3 JME;JMicron Ethernet Adapter NDIS6.20 Driver (Amd64 Bits);c:\windows\system32\DRIVERS\JME.sys;c:\windows\SYSNATIVE\DRIVERS\JME.sys [x] S3 NETw5s64;Intel(R) Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys;c:\windows\SYSNATIVE\DRIVERS\NETw5s64.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] S3 TmProxy;Trend Micro Proxy Service;c:\program files\Trend Micro\Internet Security\TmProxy.exe;c:\program files\Trend Micro\Internet Security\TmProxy.exe [x] S3 wdkmd;Intel WiDi KMD;c:\windows\system32\DRIVERS\WDKMD.sys;c:\windows\SYSNATIVE\DRIVERS\WDKMD.sys [x] . . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-06-27 18:31 1165776 ----a-w- c:\program files (x86)\Google\Chrome\Application\27.0.1453.116\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-07-02 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-07-02 18:10] . 2013-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 19:13] . 2013-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12 19:13] . 2011-10-22 c:\windows\Tasks\Net4Switch.job - c:\program files (x86)\ASUS\Net4Switch\Net4Switch.exe [2011-07-27 08:11] . 2013-07-02 c:\windows\Tasks\Plus-HD-2.4-chromeinstaller.job - c:\program files (x86)\Plus-HD-2.4\Plus-HD-2.4-chromeinstaller.exe [2013-07-01 17:23] . 2013-07-02 c:\windows\Tasks\Plus-HD-2.4-codedownloader.job - c:\program files (x86)\Plus-HD-2.4\Plus-HD-2.4-codedownloader.exe [2013-07-01 17:23] . 2013-07-02 c:\windows\Tasks\Plus-HD-2.4-enabler.job - c:\program files (x86)\Plus-HD-2.4\Plus-HD-2.4-enabler.exe [2013-07-01 17:24] . 2013-07-02 c:\windows\Tasks\Plus-HD-2.4-updater.job - c:\program files (x86)\Plus-HD-2.4\Plus-HD-2.4-updater.exe [2013-07-01 17:24] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\ADSMOverlayIcon1] @="{A8D448F4-0431-45AC-9F5E-E1B434AB2249}" [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-01 23:52 159744 ----a-w- c:\program files (x86)\ASUS\ASUS Data Security Manager\ShlExt\x64\OverlayIconShlExt1_64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B] @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}" [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}] 2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O] @="{64174815-8D98-4CE6-8646-4C039977D808}" [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}] 2009-11-26 05:49 70656 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ASUS WebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe" [2010-03-16 1754448] "UfSeAgnt.exe"="c:\program files\Trend Micro\Internet Security\UfSeAgnt.exe" [2010-02-23 1022904] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2010-05-11 161304] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2010-05-11 386584] "Persistence"="c:\windows\system32\igfxpers.exe" [2010-05-11 414744] "SmartAudio"="c:\program files\CONEXANT\SAII\SAIICpl.exe" [2009-11-19 307768] "IntelWireless"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2010-03-05 1928976] . HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Svchost - NetSvcs ezGOSvc . ------- Zusätzlicher Suchlauf ------- . uStart Page = about:newtab uLocal Page = c:\windows\system32\blank.htm uDefault_Search_URL = hxxp://www.google.com mDefault_Search_URL = hxxp://www.google.com mStart Page = about:newtab mLocal Page = c:\windows\SysWOW64\blank.htm mSearch Page = hxxp://www.google.com mSearch Bar = hxxp://www.google.com IE: {{92808042-fb78-4fa0-bb4f-c9a95e0e9c10} - {ba696155-d96e-4281-b467-0367a0456474} - c:\users\asus pro 5if\AppData\Roaming\HomeTab\HomeTab.dll TCP: DhcpNameServer = 83.169.184.225 83.169.184.161 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . BHO-{ba696155-d96e-4281-b467-0367a0456474} - c:\users\asus pro 5if\AppData\Roaming\HomeTab\HomeTab.dll Toolbar-Locked - (no file) Toolbar-{ba696155-d96e-4281-b467-0367a0456474} - c:\users\asus pro 5if\AppData\Roaming\HomeTab\HomeTab.dll c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\SRS Premium Sound.lnk - c:\windows\Installer\{E5CF6B9C-3ABE-43C9-9413-AD5FFC98F049}\NewShortcut5_21C7B668029A47458B27645FE6E4A715.exe /f=srs_premium_sound_nopreset.zip /h Toolbar-Locked - (no file) HKLM-Run-ETDWare - c:\program files (x86)\Elantech\ETDCtrl.exe HKLM-Run-Setwallpaper - c:\programdata\SetWallpaper.cmd AddRemove-00212D92-C5D8-4ff4-AE50-B20F0F85C40A_Systweak_Ad~B9F029BF_is1 - c:\program files (x86)\Advanced System Protector\unins000.exe AddRemove-K_Series_ScreenSaver_EN - c:\windows\system32\K_Series_ScreenSaver_EN.scr AddRemove-RegClean Pro_is1 - c:\program files (x86)\RegClean Pro\unins000.exe AddRemove-{3a4935b3-b7a0-4065-8ccc-0030471b33f1}_is1 - c:\program files (x86)\HomeTab\unins000.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil10d.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\LocalServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\FlashUtil10d.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{19114156-8E9A-4D4E-9EE9-17A0E48D3BBB}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{722b3793-5367-4446-b6bb-db89b05c1f24}\LocalServer32] @DACL=(02 0000) @=expand:"%SystemRoot%\\System32\\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {722b3793-5367-4446-b6bb-db89b05c1f24}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWow64\\Macromed\\Flash\\Flash10d.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}] @Denied: (A 2) (Everyone) @="IFlashBroker3" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{1D4C8A81-B7AC-460A-8C23-98713C41D6B3}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-07-02 20:26:48 ComboFix-quarantined-files.txt 2013-07-02 18:26 . Vor Suchlauf: 9 Verzeichnis(se), 41.612.627.968 Bytes frei Nach Suchlauf: 15 Verzeichnis(se), 41.501.577.216 Bytes frei . - - End Of File - - 15324DC5D5C096F6AA2AFD733B625B50 A36C5E4F47E84449FF07ED3517B43A31 |
03.07.2013, 07:25 | #6 |
/// the machine /// TB-Ausbilder | Internet total langsam Hi, Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST Log bitte.
__________________ --> Internet total langsam |
03.07.2013, 17:43 | #7 |
| Internet total langsam Hi schrauber, hier die Log-Datei des Malwarebytes-Programms: Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.07.03.07 Windows 7 x64 NTFS Internet Explorer 8.0.7600.16385 asus pro 5if :: ASUSPRO5IF-PC [Administrator] Schutz: Aktiviert 03.07.2013 18:34:33 mbam-log-2013-07-03 (18-34-33).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 237281 Laufzeit: 4 Minute(n), 50 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Hi schrauber, hier die Log_Datei des ADWCleaners:AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.304 - Datei am 03/07/2013 um 19:01:25 erstellt # Aktualisiert am 03/07/2013 von Xplode # Betriebssystem : Windows 7 Home Premium (64 bits) # Benutzer : asus pro 5if - ASUSPRO5IF-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\asus pro 5if\Desktop\adwcleaner_2.3.0.4.exe # Option [Löschen] **** [Dienste] **** Gestoppt & Gelöscht : SystemStoreService ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Windows\Tasks\DSite.job Ordner Gelöscht : C:\Program Files (x86)\Covus Freemium Ordner Gelöscht : C:\Program Files (x86)\SoftwareUpdater Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Covus Freemium Ordner Gelöscht : C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiennapmieppnpfhhogglccgepbdajan Ordner Gelöscht : C:\Users\asus pro 5if\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\asus pro 5if\AppData\Roaming\DSite ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\RegClean Pro_is1 ***** [Internet Browser] ***** -\\ Internet Explorer v8.0.7600.16968 [OK] Die Registrierungsdatenbank ist sauber. -\\ Google Chrome v27.0.1453.116 Datei : C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Preferences Gelöscht [l.61] : keyword = "search.certified-toolbar.com", Gelöscht [l.65] : search_url = "hxxp://search.certified-toolbar.com?si=46364&st=bs&tid=3869&ver=3.2&ts=13726991[...] Gelöscht [l.2153] : homepage = "hxxp://www.my-online-search.com/?babsrc=HP_ofln&mntrId=E220001E64563571&cat=delta&dl[...] Gelöscht [l.2486] : urls_to_restore_on_startup = [ "hxxp://www.my-online-search.com/?babsrc=HP_ofln&mntrId=E22000[...] -\\ Opera v12.15.1748.0 Datei : C:\Users\asus pro 5if\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [3505 octets] - [24/04/2013 04:49:33] AdwCleaner[R2].txt - [1095 octets] - [27/06/2013 19:43:42] AdwCleaner[R3].txt - [1215 octets] - [27/06/2013 20:07:57] AdwCleaner[R4].txt - [2871 octets] - [03/07/2013 19:00:23] AdwCleaner[R5].txt - [2931 octets] - [03/07/2013 19:00:55] AdwCleaner[S1].txt - [3567 octets] - [24/04/2013 04:50:29] AdwCleaner[S2].txt - [1158 octets] - [27/06/2013 19:44:31] AdwCleaner[S3].txt - [1294 octets] - [27/06/2013 21:59:31] AdwCleaner[S4].txt - [38089 octets] - [02/07/2013 11:22:42] AdwCleaner[S5].txt - [2736 octets] - [03/07/2013 19:01:25] ########## EOF - C:\AdwCleaner[S5].txt - [2796 octets] ########## Hi schrauber, hier die Log-Datei des JRT:JRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 7 Home Premium x64 Ran by asus pro 5if on 03.07.2013 at 19:07:56,07 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\systweak Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\systweak Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\installer\upgradecodes\f928123a039649549966d4c29d35b1c9 ~~~ Files Successfully deleted: [File] C:\Windows\syswow64\shoB153.tmp ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\systweak" Successfully deleted: [Folder] "C:\Users\asus pro 5if\AppData\Roaming\systweak" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 03.07.2013 at 19:13:34,78 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
03.07.2013, 18:26 | #8 |
/// the machine /// TB-Ausbilder | Internet total langsamESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST Log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.07.2013, 19:47 | #9 |
| Internet total langsam Hi schrauber, hier die Log-Datei von ESET: ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=093e1eadcbe35a4e86b71a75665dae8e # engine=14256 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-07-03 06:39:53 # local_time=2013-07-03 08:39:53 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7600 NT # compatibility_mode=513 16777149 100 97 4830 105958809 0 0 # compatibility_mode=1799 16775165 100 96 6759 143548098 0 0 # compatibility_mode=5893 16776573 100 94 189344 124506643 0 0 # scanned=144457 # found=0 # cleaned=0 # scan_time=3686 Hi schrauber, hier die Fhlermeldung von SecurityCheck: UNSUPPORTED OPERATING SYSTEM! ABORTED! Hi schrauber, hier die Log-Datei von JRT:JRT Logfile: Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 7 Home Premium x64 Ran by asus pro 5if on 03.07.2013 at 20:54:19,05 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 03.07.2013 at 20:59:53,29 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Hi Schrauber, hier die FRST-Log-Datei: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-07-2013 Ran by asus pro 5if (administrator) on 03-07-2013 21:04:24 Running from C:\Users\asus pro 5if\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe () C:\Program Files (x86)\XSManager\WTGService.exe (4G Systems GmbH & Co. KG) C:\Windows\service4g.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (4G Systems GmbH & Co. KG) C:\Windows\starter4g.exe (ASUS) C:\Windows\AsScrPro.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe () C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe () C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Skype Technologies S.A.) C:\Program Files (x86)\Skype\Phone\Skype.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe (asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\cvh.exe () C:\Program Files (x86)\Common Files\microsoft shared\virtualization handler\OfficeVirt.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe [649608 2010-06-10] (ELAN Microelectronic Corp.) HKLM\...\Run: [ASUS WebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-16] () HKLM\...\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [1022904 2010-02-23] (Trend Micro Inc.) HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-19] () HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1928976 2010-03-05] (Intel(R) Corporation) HKLM\...\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd [x] HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-10-12] (Google Inc.) HKCU\...\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun [19604072 2013-06-03] (Skype Technologies S.A.) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" [87336 2009-07-06] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2010-06-25] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [Boingo Wi-Fi] "C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2429 2010-10-12] () HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS) HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-08-12] () HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2011-09-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [starter4g] C:\Windows\starter4g.exe [160992 2010-07-08] (4G Systems GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345144 2013-06-27] (Avira Operations GmbH & Co. KG) HKU\Gast\...\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe [370480 2010-04-05] (syncables, LLC) HKU\Gast\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-10-12] (Google Inc.) Startup: C:\ProgramData\Start Menu\Programs\Startup\FancyStart daemon.lnk ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe () Startup: C:\ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Google HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = Google HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = Google BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll (Google Inc.) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.) BHO-x32: HomeTab - {ba696155-d96e-4281-b467-0367a0456474} - C:\Users\asus pro 5if\AppData\Roaming\HomeTab\HomeTab.dll No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM-x32 - HomeTab - {ba696155-d96e-4281-b467-0367a0456474} - C:\Users\asus pro 5if\AppData\Roaming\HomeTab\HomeTab.dll No File Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 83.169.184.225 83.169.184.161 Chrome: ======= CHR DefaultSearchURL: (My Online Search) - hxxp://www.my-online-search.com/?q={searchTerms}&babsrc=SP_ofln&mntrId=E220001E64563571&cat=delta&dlb=2&affID=119357 CHR DefaultSuggestURL: (My Online Search) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Extension: (Plus-HD-2.4) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\hojmbfiljpkaijkdifoaacbpallpfkkf\1.23.9_0 CHR Extension: (Skype Click to Call) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0 CHR Extension: (Amazon for Chrome) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam\2.2.2012.272_0 ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG) R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] () R2 ezGOSvc; C:\Windows\SysWOW64\ezGOSvc.dll [80256 2011-08-07] () R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-03-05] () R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] () R2 SfCtlCom; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [859712 2010-10-09] (Trend Micro Inc.) R3 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () R3 TMBMServer; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [570632 2010-02-23] (Trend Micro Inc.) R3 TmProxy; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [917768 2010-02-23] (Trend Micro Inc.) R2 WTGService; C:\Program Files (x86)\XSManager\WTGService.exe [329168 2010-04-12] () R2 XS Stick Service; C:\Windows\service4g.exe [145120 2010-07-08] (4G Systems GmbH & Co. KG) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-04-22] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-04-22] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-04-22] (Avira Operations GmbH & Co. KG) S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2011-11-21] (Mobile Connector) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () R2 tmpreflt; C:\Windows\System32\DRIVERS\tmpreflt.sys [42768 2011-07-12] (Trend Micro Inc.) R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [107536 2010-02-23] (Trend Micro Inc.) R2 tmxpflt; C:\Windows\System32\DRIVERS\tmxpflt.sys [342288 2011-07-12] (Trend Micro Inc.) R2 vsapint; C:\Windows\System32\DRIVERS\vsapint.sys [2077456 2011-07-12] (Trend Micro Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 ipswuio; System32\DRIVERS\ipswuio.sys [x] U3 tmlwf; U3 tmwfp; ==================== NetSvcs (Whitelisted) =================== NETSVC: ezGOSvc -> C:\Windows\SysWOW64\ezGOSvc.dll () ==================== One Month Created Files and Folders ======== 2013-07-03 20:59 - 2013-07-03 20:59 - 00000632 ____A C:\Users\asus pro 5if\Desktop\JRT.txt 2013-07-03 20:51 - 2013-07-03 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-03 20:50 - 2013-07-03 20:52 - 00890988 ____A C:\Users\asus pro 5if\Desktop\SecurityCheck.exe 2013-07-03 19:34 - 2013-07-03 19:34 - 02347384 ____A (ESET) C:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe 2013-07-03 19:07 - 2013-07-03 20:54 - 00000000 ____D C:\JRT 2013-07-03 19:07 - 2013-07-03 19:07 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\asus pro 5if\Desktop\JRT.exe 2013-07-03 19:07 - 2013-07-03 19:07 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 19:01 - 2013-07-03 19:01 - 00002865 ____A C:\AdwCleaner[S5].txt 2013-07-03 19:00 - 2013-07-03 19:01 - 00002931 ____A C:\AdwCleaner[R5].txt 2013-07-03 19:00 - 2013-07-03 19:00 - 00002871 ____A C:\AdwCleaner[R4].txt 2013-07-03 18:53 - 2013-07-03 18:53 - 00650027 ____A C:\Users\asus pro 5if\Desktop\adwcleaner_2.3.0.4.exe 2013-07-03 18:48 - 2013-07-03 18:48 - 00001097 ____A C:\Users\asus pro 5if\Desktop\Continue Zip Opener Installation.lnk 2013-07-03 18:47 - 2013-07-03 18:47 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-07-03 18:46 - 2013-07-03 18:47 - 00774592 ____A C:\Users\asus pro 5if\Downloads\ZipOpenerSetup.exe 2013-07-03 18:30 - 2013-07-03 18:30 - 00001111 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-03 18:30 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2013-07-03 18:27 - 2013-07-03 18:27 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\asus pro 5if\Desktop\mbam-setup-1.75.0.1300.exe 2013-07-02 20:32 - 2013-07-03 19:02 - 00000168 ____A C:\Windows\setupact.log 2013-07-02 20:32 - 2013-07-02 20:32 - 00000000 ____A C:\Windows\setuperr.log 2013-07-02 20:31 - 2013-07-02 20:32 - 00358904 ____A C:\Windows\System32\FNTCACHE.DAT 2013-07-02 20:31 - 2013-07-02 20:31 - 00001260 ____A C:\Windows\PFRO.log 2013-07-02 19:55 - 2013-07-02 20:27 - 00000000 ____D C:\ComboFix 2013-07-02 19:55 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-07-02 19:55 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-07-02 19:55 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-07-02 19:54 - 2013-07-02 20:27 - 00000000 ____D C:\Qoobox 2013-07-02 19:54 - 2013-07-02 20:21 - 00000000 ____D C:\Windows\erdnt 2013-07-02 19:49 - 2013-07-02 19:53 - 05084414 ____R (Swearware) C:\Users\asus pro 5if\Desktop\ComboFix.exe 2013-07-02 18:59 - 2013-07-02 18:59 - 00000000 ____D C:\FRST 2013-07-02 18:57 - 2013-07-02 18:58 - 01933556 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-02 18:56 - 2013-07-02 18:56 - 00095168 ____A C:\Users\asus pro 5if\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-02 11:22 - 2013-07-02 11:23 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-01 19:44 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-01 19:44 - 00001070 ____A C:\Users\asus pro 5if\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-01 19:37 - 2013-07-01 19:40 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:35 - 2012-07-25 12:03 - 00016896 ____A C:\Windows\System32\sasnative64.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:33 - 2013-07-02 14:18 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-01 19:33 - 2013-05-27 16:01 - 00020312 ____A (Systweak Inc., (Systweak - Download Software utilities for Windows optimization, Scan & Clean Spyware for Free)) C:\Windows\System32\roboot64.exe 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-03 19:24 - 00001208 ____A C:\Windows\Tasks\Plus-HD-2.4-updater.job 2013-07-01 19:24 - 2013-07-03 19:24 - 00001112 ____A C:\Windows\Tasks\Plus-HD-2.4-enabler.job 2013-07-01 19:24 - 2013-07-02 07:41 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-07-01 19:23 - 2013-07-03 19:24 - 00001212 ____A C:\Windows\Tasks\Plus-HD-2.4-codedownloader.job 2013-07-01 19:23 - 2013-07-03 19:23 - 00001918 ____A C:\Windows\Tasks\Plus-HD-2.4-chromeinstaller.job 2013-07-01 19:23 - 2013-07-01 19:24 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.4 2013-07-01 19:19 - 2013-06-27 07:14 - 00031816 ____A C:\Windows\Launcher.exe 2013-07-01 19:18 - 2013-07-02 14:15 - 00002563 ____A C:\Users\Public\Desktop\Free System Utilities.lnk 2013-07-01 19:18 - 2013-07-01 19:18 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2013-07-01 19:17 - 2013-07-01 19:17 - 00000000 ____D C:\ProgramData\Package Cache 2013-07-01 19:10 - 2013-07-01 19:11 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\DownloadGuide 2013-07-01 19:10 - 2013-07-01 19:10 - 00444408 ____A C:\Users\asus pro 5if\Downloads\free-system-utilities-DE.exe 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 21:59 - 2013-06-27 22:00 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:31 - 2013-06-27 20:31 - 00002257 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-06-27 20:23 - 2013-04-23 22:06 - 00000567 ____A C:\zoek-results23.04.2013-2206.log 2013-06-27 20:07 - 2013-06-27 20:08 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:44 - 2013-06-27 19:45 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:43 - 2013-06-27 19:44 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-20 19:23 - 2013-06-26 08:15 - 00002058 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt ==================== One Month Modified Files and Folders ======= 2013-07-03 20:59 - 2013-07-03 20:59 - 00000632 ____A C:\Users\asus pro 5if\Desktop\JRT.txt 2013-07-03 20:54 - 2013-07-03 19:07 - 00000000 ____D C:\JRT 2013-07-03 20:53 - 2011-07-27 03:26 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Google 2013-07-03 20:52 - 2013-07-03 20:50 - 00890988 ____A C:\Users\asus pro 5if\Desktop\SecurityCheck.exe 2013-07-03 20:51 - 2013-07-03 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-03 20:44 - 2010-10-12 21:13 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-03 20:10 - 2012-07-02 22:16 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-03 19:36 - 2010-10-12 20:50 - 01288493 ____A C:\Windows\WindowsUpdate.log 2013-07-03 19:34 - 2013-07-03 19:34 - 02347384 ____A (ESET) C:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe 2013-07-03 19:24 - 2013-07-01 19:24 - 00001208 ____A C:\Windows\Tasks\Plus-HD-2.4-updater.job 2013-07-03 19:24 - 2013-07-01 19:24 - 00001112 ____A C:\Windows\Tasks\Plus-HD-2.4-enabler.job 2013-07-03 19:24 - 2013-07-01 19:23 - 00001212 ____A C:\Windows\Tasks\Plus-HD-2.4-codedownloader.job 2013-07-03 19:23 - 2013-07-01 19:23 - 00001918 ____A C:\Windows\Tasks\Plus-HD-2.4-chromeinstaller.job 2013-07-03 19:10 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-03 19:10 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-03 19:07 - 2013-07-03 19:07 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\asus pro 5if\Desktop\JRT.exe 2013-07-03 19:07 - 2013-07-03 19:07 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 19:03 - 2010-10-12 21:43 - 00001459 ____A C:\Windows\System32\ServiceFilter.ini 2013-07-03 19:03 - 2010-10-12 21:13 - 00001120 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-03 19:02 - 2013-07-02 20:32 - 00000168 ____A C:\Windows\setupact.log 2013-07-03 19:02 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-03 19:01 - 2013-07-03 19:01 - 00002865 ____A C:\AdwCleaner[S5].txt 2013-07-03 19:01 - 2013-07-03 19:00 - 00002931 ____A C:\AdwCleaner[R5].txt 2013-07-03 19:00 - 2013-07-03 19:00 - 00002871 ____A C:\AdwCleaner[R4].txt 2013-07-03 18:53 - 2013-07-03 18:53 - 00650027 ____A C:\Users\asus pro 5if\Desktop\adwcleaner_2.3.0.4.exe 2013-07-03 18:48 - 2013-07-03 18:48 - 00001097 ____A C:\Users\asus pro 5if\Desktop\Continue Zip Opener Installation.lnk 2013-07-03 18:47 - 2013-07-03 18:47 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-07-03 18:47 - 2013-07-03 18:46 - 00774592 ____A C:\Users\asus pro 5if\Downloads\ZipOpenerSetup.exe 2013-07-03 18:30 - 2013-07-03 18:30 - 00001111 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-03 18:27 - 2013-07-03 18:27 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\asus pro 5if\Desktop\mbam-setup-1.75.0.1300.exe 2013-07-03 06:43 - 2011-08-03 17:01 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Skype 2013-07-02 20:37 - 2009-08-04 11:51 - 00697550 ____A C:\Windows\System32\perfh007.dat 2013-07-02 20:37 - 2009-08-04 11:51 - 00148556 ____A C:\Windows\System32\perfc007.dat 2013-07-02 20:37 - 2009-07-14 07:13 - 01614964 ____A C:\Windows\System32\PerfStringBackup.INI 2013-07-02 20:32 - 2013-07-02 20:32 - 00000000 ____A C:\Windows\setuperr.log 2013-07-02 20:32 - 2013-07-02 20:31 - 00358904 ____A C:\Windows\System32\FNTCACHE.DAT 2013-07-02 20:31 - 2013-07-02 20:31 - 00001260 ____A C:\Windows\PFRO.log 2013-07-02 20:27 - 2013-07-02 19:55 - 00000000 ____D C:\ComboFix 2013-07-02 20:27 - 2013-07-02 19:54 - 00000000 ____D C:\Qoobox 2013-07-02 20:21 - 2013-07-02 19:54 - 00000000 ____D C:\Windows\erdnt 2013-07-02 20:10 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-07-02 19:55 - 2012-01-09 09:51 - 00000824 ____A C:\Windows\System32\Drivers\etc\tmvsthfud.bin 2013-07-02 19:54 - 2010-10-12 21:19 - 00000824 ____A C:\Windows\System32\Drivers\etc\tmvsthfss.bin 2013-07-02 19:53 - 2013-07-02 19:49 - 05084414 ____R (Swearware) C:\Users\asus pro 5if\Desktop\ComboFix.exe 2013-07-02 18:59 - 2013-07-02 18:59 - 00000000 ____D C:\FRST 2013-07-02 18:58 - 2013-07-02 18:57 - 01933556 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-02 18:56 - 2013-07-02 18:56 - 00095168 ____A C:\Users\asus pro 5if\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-02 14:18 - 2013-07-01 19:33 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-02 14:15 - 2013-07-01 19:18 - 00002563 ____A C:\Users\Public\Desktop\Free System Utilities.lnk 2013-07-02 11:23 - 2013-07-02 11:22 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-02 07:41 - 2013-07-01 19:24 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\igdhbblpcellaljokkpfhcjlagemhgjl 2013-07-02 07:36 - 2011-08-01 23:49 - 00045056 ____A C:\Windows\System32\acovcnt.exe 2013-07-01 20:32 - 2010-10-12 21:43 - 00002210 ____A C:\Windows\System32\AutoRunFilter.ini 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-01 19:44 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-01 19:44 - 00001070 ____A C:\Users\asus pro 5if\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-01 19:40 - 2013-07-01 19:37 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-07-01 19:24 - 2013-07-01 19:23 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.4 2013-07-01 19:18 - 2013-07-01 19:18 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2013-07-01 19:17 - 2013-07-01 19:17 - 00000000 ____D C:\ProgramData\Package Cache 2013-07-01 19:11 - 2013-07-01 19:10 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\DownloadGuide 2013-07-01 19:10 - 2013-07-01 19:10 - 00444408 ____A C:\Users\asus pro 5if\Downloads\free-system-utilities-DE.exe 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 22:00 - 2013-06-27 21:59 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:31 - 2013-06-27 20:31 - 00002257 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-06-27 20:23 - 2013-04-23 18:49 - 00000393 ____A C:\zoek-results.log 2013-06-27 20:08 - 2013-06-27 20:07 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:04 - 2009-07-29 08:03 - 00000000 ____D C:\Windows\Panther 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:45 - 2013-06-27 19:44 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:44 - 2013-06-27 19:43 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:29 - 2011-08-03 17:01 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-27 19:29 - 2011-08-03 17:00 - 00000000 ____D C:\ProgramData\Skype 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-27 11:38 - 2013-05-07 15:27 - 00083672 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avnetflt.sys 2013-06-27 07:14 - 2013-07-01 19:19 - 00031816 ____A C:\Windows\Launcher.exe 2013-06-26 08:15 - 2013-06-20 19:23 - 00002058 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt 2013-06-11 20:10 - 2012-07-02 22:16 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-11 20:10 - 2011-10-12 11:51 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-03 08:24 ==================== End Of Log ============================ --- --- --- |
03.07.2013, 20:39 | #10 |
/// the machine /// TB-Ausbilder | Internet total langsam Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
03.07.2013, 20:59 | #11 |
| Internet total langsam Hallo schrauber, meine Internetgeschwindigkeit hat sich etwas gebessert, ja. Aber so wie vorher ist sie bei weitem nicht. In meinem Onlinespiel (www.sauspiel.de) kommt es noch immer zu starken Verzögerungen und die Spielgeschwindigkeit ist eher behäbig. Der Seitenaufbau anderer Seiten ist gleichlangsam geblieben. Weiterhin habe ich nun beim Neustart von Windowas folgende Fehlermeldung, welche ich vorher nicht hatte: RunDLL Problem beim Starten von C:\Program Files (x86)\HomeTab\TBUpdater.dll Das angegebene Modul wurde nicht gefunden. ps: schönen gruß vom wreckingchick, mit der hab ich grad telefoniert :-) |
04.07.2013, 06:40 | #12 | |
/// the machine /// TB-Ausbilder | Internet total langsamZitat:
Lade SystemLook von jpshortstuff von einem der folgenden Spiegel herunter und speichere das Tool auf dem Desktop. SystemLook (64 bit)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.07.2013, 06:56 | #13 |
| Internet total langsam Moin schrauber, hier der Log-Text: SystemLook 30.07.11 by jpshortstuff Log created at 07:44 on 04/07/2013 by asus pro 5if Administrator - Elevation successful ========== filefind ========== Searching for "*Browser Updater*" No files found. -= EOF =- p.s. laut ihrer aussage seit ihr über facebook befreundet (wreckingchick) Bin dann mal weg, arbeiten, bis denne. |
04.07.2013, 07:47 | #14 |
/// the machine /// TB-Ausbilder | Internet total langsam FRST bitte öffnen, Haken bei Additional setzen, scannen. Beide Logs posten. Ahja jetzt weiß ich wen Du meinst
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
04.07.2013, 18:55 | #15 |
| Internet total langsam N´abend schrauber, hier der FRST-Log: FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 02-07-2013 Ran by asus pro 5if (administrator) on 04-07-2013 19:53:09 Running from C:\Users\asus pro 5if\Desktop Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (ASUSTeK Computer Inc.) C:\Windows\system32\FBAgent.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (ATK) C:\Program Files\P4G\BatteryLife.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ASUS) C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe (ATK) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe () C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.21.145\GoogleCrashHandler64.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrl.exe () C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (CyberLink Corp.) C:\Program Files (x86)\CyberLink\PowerDVD9\PDVD9Serv.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Boingo Wireless, Inc.) C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMTray.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (4G Systems GmbH & Co. KG) C:\Windows\starter4g.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (ASUS) C:\Windows\AsScrPro.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe () C:\Program Files (x86)\XSManager\WTGService.exe (4G Systems GmbH & Co. KG) C:\Windows\service4g.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (ASUSTek Computer Inc.) C:\Program Files (x86)\ASUS\ASUS Data Security Manager\ADSMSrv.exe () C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe (ELAN Microelectronic Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe () C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe (asus) C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe (Microsoft Corporation) C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\Internet Security\TmProxy.exe (Trend Micro Inc.) C:\Program Files\Trend Micro\BM\TMBMSRV.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Opera Software) C:\Program Files (x86)\Opera\opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDWare] %ProgramFiles%\Elantech\ETDCtrl.exe [649608 2010-06-10] (ELAN Microelectronic Corp.) HKLM\...\Run: [ASUS WebStorage] C:\Program Files (x86)\ASUS\ASUS WebStorage\SERVICE\AsusWSService.exe [1754448 2010-03-16] () HKLM\...\Run: [UfSeAgnt.exe] "C:\Program Files\Trend Micro\Internet Security\UfSeAgnt.exe" [1022904 2010-02-23] (Trend Micro Inc.) HKLM\...\Run: [SmartAudio] C:\Program Files\CONEXANT\SAII\SAIICpl.exe /t [307768 2009-11-19] () HKLM\...\Run: [IntelWireless] "C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" /tf Intel Wireless Tray [1928976 2010-03-05] (Intel(R) Corporation) HKLM\...\Run: [Setwallpaper] c:\programdata\SetWallpaper.cmd [x] HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-10-12] (Google Inc.) HKCU\...\Policies\system: [DisableRegistryTools] 0 HKCU\...\Policies\system: [DisableTaskMgr] 0 HKLM-x32\...\Run: [RemoteControl9] "C:\Program Files (x86)\Cyberlink\PowerDVD9\PDVD9Serv.exe" [87336 2009-07-06] (CyberLink Corp.) HKLM-x32\...\Run: [UpdatePSTShortCut] "C:\Program Files (x86)\Cyberlink\DVD Suite\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\Cyberlink\DVD Suite" UpdateWithCreateOnce "Software\CyberLink\PowerStarter" [210216 2010-06-25] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0" [222504 2009-05-20] (CyberLink Corp.) HKLM-x32\...\Run: [Boingo Wi-Fi] "C:\Program Files (x86)\Boingo\Boingo Wi-Fi\Boingo.lnk" [2429 2010-10-12] () HKLM-x32\...\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-05-03] (ASUS) HKLM-x32\...\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1597440 2010-08-12] () HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [937920 2011-03-30] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [37296 2011-09-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [starter4g] C:\Windows\starter4g.exe [160992 2010-07-08] (4G Systems GmbH & Co. KG) HKLM-x32\...\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe" /min [345144 2013-06-27] (Avira Operations GmbH & Co. KG) HKU\Gast\...\Run: [Syncables] C:\Program Files (x86)\syncables\syncables desktop\Syncables.exe [370480 2010-04-05] (syncables, LLC) HKU\Gast\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2010-10-12] (Google Inc.) Startup: C:\ProgramData\Start Menu\Programs\Startup\FancyStart daemon.lnk ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_C4A2FC3E3722966204FDD8.exe () Startup: C:\ProgramData\Start Menu\Programs\Startup\McAfee Security Scan Plus.lnk ShortcutTarget: McAfee Security Scan Plus.lnk -> C:\Program Files (x86)\McAfee Security Scan\3.0.318\SSScheduler.exe (McAfee, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:newtab HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com BHO: Windows Live Family Safety Browser Helper Class - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.8313.1002\swg64.dll (Google Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: MSS+ Identifier - {0E8A89AD-95D7-40EB-8D9D-083EF7066A01} - C:\Program Files (x86)\McAfee Security Scan\3.0.318\McAfeeMSS_IE.dll (McAfee, Inc.) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) BHO-x32: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.8313.1002\swg.dll (Google Inc.) BHO-x32: HomeTab - {ba696155-d96e-4281-b467-0367a0456474} - C:\Users\asus pro 5if\AppData\Roaming\HomeTab\HomeTab.dll No File Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKLM-x32 - HomeTab - {ba696155-d96e-4281-b467-0367a0456474} - C:\Users\asus pro 5if\AppData\Roaming\HomeTab\HomeTab.dll No File Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - No File Handler-x32: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~2\WIC4A1~1\MESSEN~1\MSGRAP~1.DLL (Microsoft Corporation) Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 83.169.184.225 83.169.184.161 Chrome: ======= CHR DefaultSearchURL: (My Online Search) - hxxp://www.my-online-search.com/?q={searchTerms}&babsrc=SP_ofln&mntrId=E220001E64563571&cat=delta&dlb=2&affID=119357 CHR DefaultSuggestURL: (My Online Search) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (McAfee Security Scanner +) - C:\Program Files (x86)\McAfee Security Scan\3.0.318\npMcAfeeMss.dll (McAfee, Inc.) CHR Plugin: (Silverlight Plug-In) - C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll ( Microsoft Corporation) CHR Plugin: (Windows Live\u00AE Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll () CHR Extension: (Plus-HD-2.4) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\hojmbfiljpkaijkdifoaacbpallpfkkf\1.23.9_0 CHR Extension: (Skype Click to Call) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\5.10.0.9560_0 CHR Extension: (Amazon 1Button App for Chrome) - C:\Users\asus pro 5if\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbjikboenpfhbbejgkoklgkhjpfogcam\3.2013.627.0_0 ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-06-27] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-06-27] (Avira Operations GmbH & Co. KG) R2 Autodesk Content Service; C:\Program Files (x86)\Autodesk\Content Service\Connect.Service.ContentService.exe [18656 2011-02-02] () R2 ezGOSvc; C:\Windows\SysWOW64\ezGOSvc.dll [80256 2011-08-07] () R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2010-03-05] () R3 RichVideo; C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe [244904 2010-04-06] () R2 SfCtlCom; C:\Program Files\Trend Micro\Internet Security\SfCtlCom.exe [859712 2010-10-09] (Trend Micro Inc.) R3 spmgr; C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe [125496 2007-08-03] () R3 TMBMServer; C:\Program Files\Trend Micro\BM\TMBMSRV.exe [570632 2010-02-23] (Trend Micro Inc.) R3 TmProxy; C:\Program Files\Trend Micro\Internet Security\TmProxy.exe [917768 2010-02-23] (Trend Micro Inc.) R2 WTGService; C:\Program Files (x86)\XSManager\WTGService.exe [329168 2010-04-12] () R2 XS Stick Service; C:\Windows\service4g.exe [145120 2010-07-08] (4G Systems GmbH & Co. KG) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [100712 2013-04-22] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [130016 2013-04-22] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-04-22] (Avira Operations GmbH & Co. KG) S3 cmnsusbser; C:\Windows\System32\DRIVERS\cmnsusbser.sys [117888 2011-11-21] (Mobile Connector) R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R2 ghaio; C:\Program Files\ASUS\NB Probe\SPM\ghaio.sys [17464 2007-08-03] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 SNP2UVC; C:\Windows\System32\DRIVERS\snp2uvc.sys [1800192 2009-08-20] () R2 tmpreflt; C:\Windows\System32\DRIVERS\tmpreflt.sys [42768 2011-07-12] (Trend Micro Inc.) R1 tmtdi; C:\Windows\System32\DRIVERS\tmtdi.sys [107536 2010-02-23] (Trend Micro Inc.) R2 tmxpflt; C:\Windows\System32\DRIVERS\tmxpflt.sys [342288 2011-07-12] (Trend Micro Inc.) R2 vsapint; C:\Windows\System32\DRIVERS\vsapint.sys [2077456 2011-07-12] (Trend Micro Inc.) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 ipswuio; System32\DRIVERS\ipswuio.sys [x] U3 tmlwf; U3 tmwfp; ==================== NetSvcs (Whitelisted) =================== NETSVC: ezGOSvc -> C:\Windows\SysWOW64\ezGOSvc.dll () ==================== One Month Created Files and Folders ======== 2013-07-04 07:44 - 2013-07-04 07:45 - 00000452 ____A C:\Users\asus pro 5if\Desktop\SystemLook.txt 2013-07-04 07:43 - 2013-07-04 07:43 - 00165376 ____A C:\Users\asus pro 5if\Desktop\SystemLook_x64.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 01093032 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00972712 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00000000 ____D C:\Program Files\Java 2013-07-03 20:59 - 2013-07-03 20:59 - 00000632 ____A C:\Users\asus pro 5if\Desktop\JRT.txt 2013-07-03 20:51 - 2013-07-03 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-03 20:50 - 2013-07-03 20:52 - 00890988 ____A C:\Users\asus pro 5if\Desktop\SecurityCheck.exe 2013-07-03 19:34 - 2013-07-03 19:34 - 02347384 ____A (ESET) C:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe 2013-07-03 19:07 - 2013-07-03 20:54 - 00000000 ____D C:\JRT 2013-07-03 19:07 - 2013-07-03 19:07 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\asus pro 5if\Desktop\JRT.exe 2013-07-03 19:07 - 2013-07-03 19:07 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 19:01 - 2013-07-03 19:01 - 00002865 ____A C:\AdwCleaner[S5].txt 2013-07-03 19:00 - 2013-07-03 19:01 - 00002931 ____A C:\AdwCleaner[R5].txt 2013-07-03 19:00 - 2013-07-03 19:00 - 00002871 ____A C:\AdwCleaner[R4].txt 2013-07-03 18:53 - 2013-07-03 18:53 - 00650027 ____A C:\Users\asus pro 5if\Desktop\adwcleaner_2.3.0.4.exe 2013-07-03 18:48 - 2013-07-03 18:48 - 00001097 ____A C:\Users\asus pro 5if\Desktop\Continue Zip Opener Installation.lnk 2013-07-03 18:47 - 2013-07-03 18:47 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-07-03 18:46 - 2013-07-03 18:47 - 00774592 ____A C:\Users\asus pro 5if\Downloads\ZipOpenerSetup.exe 2013-07-03 18:30 - 2013-07-03 18:30 - 00001111 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-03 18:30 - 2013-04-04 14:50 - 00025928 ____A (Malwarebytes Corporation) C:\Windows\System32\Drivers\mbam.sys 2013-07-03 18:27 - 2013-07-03 18:27 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\asus pro 5if\Desktop\mbam-setup-1.75.0.1300.exe 2013-07-02 19:55 - 2013-07-02 20:27 - 00000000 ____D C:\ComboFix 2013-07-02 19:55 - 2011-06-26 08:45 - 00256000 ____A C:\Windows\PEV.exe 2013-07-02 19:55 - 2010-11-07 19:20 - 00208896 ____A C:\Windows\MBR.exe 2013-07-02 19:55 - 2009-04-20 06:56 - 00060416 ____A (NirSoft) C:\Windows\NIRCMD.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00518144 ____A (SteelWerX) C:\Windows\SWREG.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00406528 ____A (SteelWerX) C:\Windows\SWSC.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00098816 ____A C:\Windows\sed.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00080412 ____A C:\Windows\grep.exe 2013-07-02 19:55 - 2000-08-31 02:00 - 00068096 ____A C:\Windows\zip.exe 2013-07-02 19:54 - 2013-07-02 20:27 - 00000000 ____D C:\Qoobox 2013-07-02 19:54 - 2013-07-02 20:21 - 00000000 ____D C:\Windows\erdnt 2013-07-02 19:49 - 2013-07-02 19:53 - 05084414 ____R (Swearware) C:\Users\asus pro 5if\Desktop\ComboFix.exe 2013-07-02 18:59 - 2013-07-02 18:59 - 00000000 ____D C:\FRST 2013-07-02 18:57 - 2013-07-02 18:58 - 01933556 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-02 11:22 - 2013-07-02 11:23 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-01 19:44 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-01 19:44 - 00001070 ____A C:\Users\asus pro 5if\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-01 19:37 - 2013-07-01 19:40 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:35 - 2012-07-25 12:03 - 00016896 ____A C:\Windows\System32\sasnative64.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:33 - 2013-07-02 14:18 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-01 19:33 - 2013-05-27 16:01 - 00020312 ____A (Systweak Inc., (www.systweak.com)) C:\Windows\System32\roboot64.exe 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-04 19:48 - 00001208 ____A C:\Windows\Tasks\Plus-HD-2.4-updater.job 2013-07-01 19:24 - 2013-07-04 19:47 - 00001112 ____A C:\Windows\Tasks\Plus-HD-2.4-enabler.job 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-07-01 19:23 - 2013-07-04 19:47 - 00001918 ____A C:\Windows\Tasks\Plus-HD-2.4-chromeinstaller.job 2013-07-01 19:23 - 2013-07-04 19:47 - 00001212 ____A C:\Windows\Tasks\Plus-HD-2.4-codedownloader.job 2013-07-01 19:23 - 2013-07-01 19:24 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.4 2013-07-01 19:19 - 2013-06-27 07:14 - 00031816 ____A C:\Windows\Launcher.exe 2013-07-01 19:18 - 2013-07-02 14:15 - 00002563 ____A C:\Users\Public\Desktop\Free System Utilities.lnk 2013-07-01 19:18 - 2013-07-01 19:18 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2013-07-01 19:17 - 2013-07-01 19:17 - 00000000 ____D C:\ProgramData\Package Cache 2013-07-01 19:10 - 2013-07-01 19:11 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\DownloadGuide 2013-07-01 19:10 - 2013-07-01 19:10 - 00444408 ____A C:\Users\asus pro 5if\Downloads\free-system-utilities-DE.exe 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 21:59 - 2013-06-27 22:00 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:31 - 2013-07-03 22:17 - 00002257 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-06-27 20:23 - 2013-04-23 22:06 - 00000567 ____A C:\zoek-results23.04.2013-2206.log 2013-06-27 20:07 - 2013-06-27 20:08 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:44 - 2013-06-27 19:45 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:43 - 2013-06-27 19:44 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-20 19:23 - 2013-06-26 08:15 - 00002058 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt ==================== One Month Modified Files and Folders ======= 2013-07-04 19:49 - 2010-10-12 20:50 - 01352137 ____A C:\Windows\WindowsUpdate.log 2013-07-04 19:48 - 2013-07-01 19:24 - 00001208 ____A C:\Windows\Tasks\Plus-HD-2.4-updater.job 2013-07-04 19:47 - 2013-07-01 19:24 - 00001112 ____A C:\Windows\Tasks\Plus-HD-2.4-enabler.job 2013-07-04 19:47 - 2013-07-01 19:23 - 00001918 ____A C:\Windows\Tasks\Plus-HD-2.4-chromeinstaller.job 2013-07-04 19:47 - 2013-07-01 19:23 - 00001212 ____A C:\Windows\Tasks\Plus-HD-2.4-codedownloader.job 2013-07-04 19:47 - 2012-07-02 22:16 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-07-04 19:47 - 2010-10-12 21:13 - 00001124 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-04 12:44 - 2010-10-12 21:13 - 00001120 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-04 07:45 - 2013-07-04 07:44 - 00000452 ____A C:\Users\asus pro 5if\Desktop\SystemLook.txt 2013-07-04 07:43 - 2013-07-04 07:43 - 00165376 ____A C:\Users\asus pro 5if\Desktop\SystemLook_x64.exe 2013-07-04 06:53 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-04 06:53 - 2009-07-14 06:45 - 00010016 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-04 06:45 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-07-04 00:18 - 2011-08-03 17:01 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Skype 2013-07-04 00:04 - 2011-08-01 23:49 - 00045056 ____A C:\Windows\System32\acovcnt.exe 2013-07-03 23:56 - 2011-07-31 07:09 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Adobe 2013-07-03 23:55 - 2012-07-02 22:16 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-07-03 23:55 - 2011-10-12 11:51 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-07-03 22:52 - 2013-07-03 22:52 - 01093032 ____A (Oracle Corporation) C:\Windows\System32\npDeployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00972712 ____A (Oracle Corporation) C:\Windows\System32\deployJava1.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00312232 ____A (Oracle Corporation) C:\Windows\System32\javaws.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00189352 ____A (Oracle Corporation) C:\Windows\System32\javaw.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00188840 ____A (Oracle Corporation) C:\Windows\System32\java.exe 2013-07-03 22:52 - 2013-07-03 22:52 - 00108968 ____A (Oracle Corporation) C:\Windows\System32\WindowsAccessBridge-64.dll 2013-07-03 22:52 - 2013-07-03 22:52 - 00000000 ____D C:\Program Files\Java 2013-07-03 22:38 - 2011-07-27 05:31 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\SoftGrid Client 2013-07-03 22:17 - 2013-06-27 20:31 - 00002257 ____A C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-03 21:33 - 2009-08-04 11:51 - 00697550 ____A C:\Windows\System32\perfh007.dat 2013-07-03 21:33 - 2009-08-04 11:51 - 00148556 ____A C:\Windows\System32\perfc007.dat 2013-07-03 21:33 - 2009-07-14 07:13 - 01614964 ____A C:\Windows\System32\PerfStringBackup.INI 2013-07-03 21:26 - 2011-08-06 07:22 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Paint.NET 2013-07-03 20:59 - 2013-07-03 20:59 - 00000632 ____A C:\Users\asus pro 5if\Desktop\JRT.txt 2013-07-03 20:54 - 2013-07-03 19:07 - 00000000 ____D C:\JRT 2013-07-03 20:53 - 2011-07-27 03:26 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Google 2013-07-03 20:52 - 2013-07-03 20:50 - 00890988 ____A C:\Users\asus pro 5if\Desktop\SecurityCheck.exe 2013-07-03 20:51 - 2013-07-03 20:51 - 00000000 ____D C:\Program Files (x86)\ESET 2013-07-03 19:34 - 2013-07-03 19:34 - 02347384 ____A (ESET) C:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe 2013-07-03 19:07 - 2013-07-03 19:07 - 00545954 ____A (Oleg N. Scherbakov) C:\Users\asus pro 5if\Desktop\JRT.exe 2013-07-03 19:07 - 2013-07-03 19:07 - 00000000 ____D C:\Windows\ERUNT 2013-07-03 19:03 - 2010-10-12 21:43 - 00001459 ____A C:\Windows\System32\ServiceFilter.ini 2013-07-03 19:01 - 2013-07-03 19:01 - 00002865 ____A C:\AdwCleaner[S5].txt 2013-07-03 19:01 - 2013-07-03 19:00 - 00002931 ____A C:\AdwCleaner[R5].txt 2013-07-03 19:00 - 2013-07-03 19:00 - 00002871 ____A C:\AdwCleaner[R4].txt 2013-07-03 18:53 - 2013-07-03 18:53 - 00650027 ____A C:\Users\asus pro 5if\Desktop\adwcleaner_2.3.0.4.exe 2013-07-03 18:48 - 2013-07-03 18:48 - 00001097 ____A C:\Users\asus pro 5if\Desktop\Continue Zip Opener Installation.lnk 2013-07-03 18:47 - 2013-07-03 18:47 - 00000000 ____D C:\Program Files (x86)\OpenIt 2013-07-03 18:47 - 2013-07-03 18:46 - 00774592 ____A C:\Users\asus pro 5if\Downloads\ZipOpenerSetup.exe 2013-07-03 18:30 - 2013-07-03 18:30 - 00001111 ____A C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Users\asus pro 5if\AppData\Roaming\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-07-03 18:30 - 2013-07-03 18:30 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-07-03 18:27 - 2013-07-03 18:27 - 10285040 ____A (Malwarebytes Corporation ) C:\Users\asus pro 5if\Desktop\mbam-setup-1.75.0.1300.exe 2013-07-02 20:27 - 2013-07-02 19:55 - 00000000 ____D C:\ComboFix 2013-07-02 20:27 - 2013-07-02 19:54 - 00000000 ____D C:\Qoobox 2013-07-02 20:21 - 2013-07-02 19:54 - 00000000 ____D C:\Windows\erdnt 2013-07-02 20:10 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini 2013-07-02 19:55 - 2012-01-09 09:51 - 00000824 ____A C:\Windows\System32\Drivers\etc\tmvsthfud.bin 2013-07-02 19:54 - 2010-10-12 21:19 - 00000824 ____A C:\Windows\System32\Drivers\etc\tmvsthfss.bin 2013-07-02 19:53 - 2013-07-02 19:49 - 05084414 ____R (Swearware) C:\Users\asus pro 5if\Desktop\ComboFix.exe 2013-07-02 18:59 - 2013-07-02 18:59 - 00000000 ____D C:\FRST 2013-07-02 18:58 - 2013-07-02 18:57 - 01933556 ____A (Farbar) C:\Users\asus pro 5if\Desktop\FRST64.exe 2013-07-02 14:18 - 2013-07-01 19:33 - 00000000 ____D C:\Program Files (x86)\MyPC Backup 2013-07-02 14:15 - 2013-07-01 19:18 - 00002563 ____A C:\Users\Public\Desktop\Free System Utilities.lnk 2013-07-02 11:23 - 2013-07-02 11:22 - 00038089 ____A C:\AdwCleaner[S4].txt 2013-07-01 20:32 - 2010-10-12 21:43 - 00002210 ____A C:\Windows\System32\AutoRunFilter.ini 2013-07-01 19:59 - 2013-07-01 19:59 - 00000000 ____D C:\ProgramData\Uniblue 2013-07-01 19:44 - 2013-07-01 19:44 - 00001070 ____A C:\Users\Gast\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-01 19:44 - 00001070 ____A C:\Users\asus pro 5if\Desktop\FLV-Media Player.lnk 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 __SHD C:\Windows\ftpcache 2013-07-01 19:44 - 2013-07-01 19:44 - 00000000 ____D C:\Program Files (x86)\FLV-Media Player 2013-07-01 19:40 - 2013-07-01 19:37 - 03393752 ____A C:\Users\asus pro 5if\Downloads\installer_flash_player_Deutsch.exe 2013-07-01 19:34 - 2013-07-01 19:34 - 00000000 ____D C:\Program Files (x86)\Amazon 2013-07-01 19:32 - 2013-07-01 19:32 - 04653664 ____A (Systweak Inc ) C:\Users\asus pro 5if\Downloads\rcpsetupmarm_marm370078065de.exe 2013-07-01 19:27 - 2013-07-01 19:27 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\Freemium 2013-07-01 19:24 - 2013-07-01 19:24 - 00000635 ____A C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-07-01 19:24 - 2013-07-01 19:23 - 00000000 ____D C:\Program Files (x86)\Plus-HD-2.4 2013-07-01 19:18 - 2013-07-01 19:18 - 00000000 ____D C:\ProgramData\FreeSystemUtilities 2013-07-01 19:17 - 2013-07-01 19:17 - 00000000 ____D C:\ProgramData\Package Cache 2013-07-01 19:11 - 2013-07-01 19:10 - 00000000 ____D C:\Users\asus pro 5if\AppData\Local\DownloadGuide 2013-07-01 19:10 - 2013-07-01 19:10 - 00444408 ____A C:\Users\asus pro 5if\Downloads\free-system-utilities-DE.exe 2013-06-27 22:47 - 2013-06-27 22:47 - 21703480 ____A (Mozilla) C:\Users\asus pro 5if\Downloads\Firefox_Setup_22.0.exe 2013-06-27 22:00 - 2013-06-27 21:59 - 00001294 ____A C:\AdwCleaner[S3].txt 2013-06-27 20:23 - 2013-04-23 18:49 - 00000393 ____A C:\zoek-results.log 2013-06-27 20:08 - 2013-06-27 20:07 - 00001215 ____A C:\AdwCleaner[R3].txt 2013-06-27 20:04 - 2009-07-29 08:03 - 00000000 ____D C:\Windows\Panther 2013-06-27 20:03 - 2013-06-27 20:03 - 00000824 ____A C:\Users\Public\Desktop\CCleaner.lnk 2013-06-27 20:03 - 2013-06-27 20:03 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 19:45 - 2013-06-27 19:44 - 00001158 ____A C:\AdwCleaner[S2].txt 2013-06-27 19:44 - 2013-06-27 19:43 - 00001095 ____A C:\AdwCleaner[R2].txt 2013-06-27 19:29 - 2011-08-03 17:01 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-06-27 19:29 - 2011-08-03 17:00 - 00000000 ____D C:\ProgramData\Skype 2013-06-27 19:25 - 2013-06-27 19:25 - 00000000 ____D C:\Program Files\Skype 2013-06-27 11:38 - 2013-05-07 15:27 - 00083672 ____A (Avira Operations GmbH & Co. KG) C:\Windows\System32\Drivers\avnetflt.sys 2013-06-27 07:14 - 2013-07-01 19:19 - 00031816 ____A C:\Windows\Launcher.exe 2013-06-26 08:15 - 2013-06-20 19:23 - 00002058 ____A C:\Users\asus pro 5if\Desktop\nick sprüche.txt ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-03 08:24 ==================== End Of Log ============================ --- --- --- --- --- --- und hier der Addition-Log:FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 02-07-2013 Ran by asus pro 5if at 2013-07-04 19:54:02 Running from C:\Users\asus pro 5if\Desktop Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 1.6.65) Adobe AIR (x32 Version: 1.5.0.7220) Adobe Flash Player 10 ActiveX (x32 Version: 10.0.42.34) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224) Adobe Reader 9.4.6 MUI (x32 Version: 9.4.6) Advanced System Protector (x32 Version: 2.1.1000.10905) ASUS AI Recovery (x32 Version: 1.0.24) ASUS CopyProtect (x32 Version: 1.0.0015) ASUS Data Security Manager (x32 Version: 1.00.0014) ASUS FancyStart (x32 Version: 1.0.8) ASUS LifeFrame3 (x32 Version: 3.0.20) ASUS Live Update (x32 Version: 2.5.9) ASUS MultiFrame (x32 Version: 1.0.0021) ASUS Power4Gear Hybrid (Version: 1.1.37) ASUS SmartLogon (x32 Version: 1.0.0008) ASUS Splendid Video Enhancement Technology (x32 Version: 1.02.0028) ASUS Video Magic (x32 Version: 6.0.4015) ASUS Virtual Camera (x32 Version: 1.0.20) ASUS WebStorage (x32 Version: 2.0.46.1429) ATK Package (x32 Version: 1.0.0006) AutoCAD 2012 - Deutsch (Version: 18.2.51.0) AutoCAD 2012 Language Pack - Deutsch (Version: 18.2.51.0) Autodesk Content Service (x32 Version: 2.0.90) Autodesk Material Library 2012 (x32 Version: 2.5.0.8) Autodesk Material Library Base Resolution Image Library 2012 (x32 Version: 2.5.0.8) Avira Free Antivirus (x32 Version: 13.0.0.3737) Bing Bar (x32 Version: 7.0.850.0) Boingo Wi-Fi (x32 Version: 1.7.0048) CCleaner (Version: 4.03) Choice Guard (x32 Version: 1.2.87.0) Conexant HD Audio (Version: 4.111.0.63) ControlDeck (x32 Version: 1.0.8) CyberLink LabelPrint (x32 Version: 2.5.1908) CyberLink MediaShow Espresso (x32 Version: 5.0.1606_25588) CyberLink PhotoNow (x32 Version: 1.1.6904) CyberLink Power2Go (x32 Version: 6.1.3602c) CyberLink PowerDirector (x32 Version: 8.0.2609a) CyberLink PowerDVD 9 (x32 Version: 9.0.3009.50) EasyBits GO (HKCU) ETDWare PS/2-x64 7.0.5.13_WHQL (Version: 7.0.5.13) FARO LS 1.1.406.58 (x32 Version: 4.6.58.2) Fast Boot (Version: 1.0.6) FLV-Media Player 1.8 (x32 Version: 1.8) Free System Utilities (x32 Version: 1.1.0.95) Free SystemUtilities (x32 Version: 1.1.0.95) Google Chrome (x32 Version: 27.0.1453.116) Google Toolbar for Internet Explorer (x32 Version: 1.0.0) Google Toolbar for Internet Explorer (x32 Version: 7.5.4209.2358) Google Update Helper (x32 Version: 1.3.21.145) HomeTab 3.7 (x32 Version: 3.7) Iminent (x32 Version: 6.25.21.0) Intel PROSet Wireless Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Graphics Media Accelerator Driver (x32 Version: 8.15.10.2125) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) PROSet/Wireless WiFi Software (Version: 13.02.0000) Intel(R) Wireless Display (Version: 1.2.20.0) Java 7 Update 25 (64-bit) (Version: 7.0.250) JMicron Ethernet Adapter NDIS Driver (x32 Version: 6.0.17.1) JMicron Flash Media Controller Driver (x32 Version: 1.0.33.2) Junk Mail filter update (x32 Version: 14.0.8050.1202) K_Series_ScreenSaver_EN (x32) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) McAfee Security Scan Plus (x32 Version: 3.0.318.3) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000) Microsoft Office Klick-und-Los 2010 (x32 Version: 14.0.4763.1000) Microsoft Office Starter 2010 - Deutsch (x32 Version: 14.0.4763.1000) Microsoft Silverlight (x32 Version: 4.1.10111.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Sync Framework Runtime Native v1.0 (x86) (x32 Version: 1.0.1215.0) Microsoft Sync Framework Services Native v1.0 (x86) (x32 Version: 1.0.1215.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) MSVCRT (x32 Version: 14.0.1468.721) MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0) NB Probe (x32) Net4Switch (x32 Version: 1.00.0020) Open It! (x32 Version: 1.1.1) Opera 12.15 (x32 Version: 12.15.1748) Paint.NET v3.5.8 (Version: 3.58.0) Plus-HD-2.4 (x32 Version: 1.27.153.6) Pontifex II (x32 Version: ) Skype Click to Call (x32 Version: 5.10.9560) Skype™ 6.5 (x32 Version: 6.5.158) syncables desktop SE (x32 Version: 5.5.615.9518) Trend Micro Internet Security (Version: 17.50) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Zip Opener (HKCU) USB2.0 UVC VGA WebCam (Version: 5.8.54000.207) VLC media player 1.1.11 (x32 Version: 1.1.11) Windows Live Anmelde-Assistent (x32 Version: 5.000.818.6) Windows Live Call (x32 Version: 14.0.8050.1202) Windows Live Communications Platform (x32 Version: 14.0.8050.1202) Windows Live Essentials (x32 Version: 14.0.8050.1202) Windows Live Family Safety (Version: 14.0.8052.1208) Windows Live Fotogalerie (x32 Version: 14.0.8051.1204) Windows Live Mail (x32 Version: 14.0.8050.1202) Windows Live Messenger (x32 Version: 14.0.8050.1202) Windows Live Sync (x32 Version: 14.0.8050.1202) Windows Live Writer (x32 Version: 14.0.8050.1202) Windows Live-Uploadtool (x32 Version: 14.0.8014.1029) WinFlash (x32 Version: 2.30.3) WinRAR 4.20 (32-Bit) (x32 Version: 4.20.0) Wireless Console 3 (x32 Version: 3.0.18) XSManager (x32 Version: 3.0) ==================== Restore Points ========================= 27-06-2013 17:27:49 Installed Skype™ 6.5 01-07-2013 17:17:34 Free System Utilities 01-07-2013 17:29:31 Free System Utilities 01.07.2013 19:29:29 01-07-2013 17:30:43 Free System Utilities 01.07.2013 19:30:42 01-07-2013 17:34:30 RegClean Pro Mo, Jul 01, 13 19:34 03-07-2013 20:51:55 Installed Java 7 Update 25 (64-bit) ==================== Scheduled Tasks (whitelisted) ============= Task: {12DABD06-C8D2-462E-937F-3FBADA8A559B} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] () Task: {24A34CFE-2CBD-4913-9E96-5861F6F5F99C} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-05-28] (ATK) Task: {24CC42E7-515E-4C08-8365-D1A50F36E458} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {24F12CAF-6C09-4A1B-BF93-51E065361B8D} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {2B2AA4C6-9B2F-4725-9B63-1BE51240A6A8} - System32\Tasks\RegClean Pro => C:\Program Files (x86)\RegClean Pro\RegCleanPro.exe No File Task: {324E82F7-D064-44D5-BA77-75826922E3CA} - System32\Tasks\ASUSControlDeck => C:\Program Files (x86)\ASUS\ControlDeck\ControlDeck.exe [2010-06-09] (asus) Task: {3951030E-CB71-486D-B3D8-8AF547C9905D} - System32\Tasks\{78ABA6A5-01CC-4830-ABA9-AAEEAAFA3211} => C:\Program Files (x86)\Skype\\Phone\Skype.exe [2013-06-03] (Skype Technologies S.A.) Task: {433DA0EA-37B2-4EB0-A90C-D4008A1BD429} - System32\Tasks\Scheduled Update for Ask Toolbar => C:\Program Files (x86)\Ask.com\UpdateTask.exe No File Task: {52FC4F05-4CEA-4A42-9741-6D0D7BF5A73D} - System32\Tasks\Net4Switch => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe [2009-09-23] (ASUS) Task: {699264D4-0D35-4784-AD7F-8CBF3D5E29A4} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2010-10-12] (Google Inc.) Task: {6B60EE87-CF7B-496D-932A-82D77CFB20BC} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-07-03] (Adobe Systems Incorporated) Task: {765D21BA-0C98-45DD-A5A2-C1AD88B0DCEC} - System32\Tasks\{26D6A9BB-3CFC-4286-AB29-46DF1F2FA2DE} => C:\program files (x86)\opera\opera.exe [2013-04-09] (Opera Software) Task: {79492728-14A4-4634-B22B-234AB4A0FEA2} - System32\Tasks\ASPG => C:\Program Files (x86)\ASUS\ASUS CopyProtect\aspg.exe [2009-06-29] (ASUS) Task: {7CA210CD-3096-4280-A903-23CFFF2FB634} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {80C1B2D2-609C-4064-960D-6C79413850B3} - System32\Tasks\Advanced System Protector_startup => C:\Program Files (x86)\Advanced System Protector\AdvancedSystemProtector.exe No File Task: {80D71377-1C0C-407E-B00E-7E87AD0CFD23} - System32\Tasks\Plus-HD-2.4-updater => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-updater.exe [2013-07-01] (Plus HD) Task: {9BDDC737-37B5-4199-A590-DEB3238974F3} - System32\Tasks\Plus-HD-2.4-chromeinstaller => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-chromeinstaller.exe [2013-07-01] (Plus HD) Task: {A585B730-AA46-4D11-A49C-B597D9067F7A} - System32\Tasks\Software Updater => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Bootstrapper.exe No File Task: {A738714F-FDF5-4018-89D1-C58261B4A148} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {B02BD60F-1E22-4AA8-A1E8-9D11BC6CF3D8} - System32\Tasks\Microsoft\Windows\MUI\Lpksetup => C:\Windows\System32\lpksetup.exe [2009-07-14] (Microsoft Corporation) Task: {B5EF9A3D-9AE9-44A2-9DA7-8088692E5100} - System32\Tasks\Plus-HD-2.4-codedownloader => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-codedownloader.exe [2013-07-01] (Plus HD) Task: {B92D7D8E-825D-4858-B1E5-577192A364A8} - System32\Tasks\AIRecoveryRemind => C:\Program Files (x86)\ASUS\AI Recovery\AIRecoveryRemind.exe [2012-03-09] (ASUSTek Computer Inc.) Task: {BFD2AAB0-9059-4444-8B96-E22B494E7A1B} - System32\Tasks\Freemium1ClickMaint => C:\Users\asus pro 5if\Downloads\1Click.exe No File Task: {DC2F45BA-04CC-414C-9B50-10F48095D6FA} - System32\Tasks\Software Updater Ui => C:\Program Files (x86)\SoftwareUpdater\SoftwareUpdater.Ui.exe No File Task: {DE2A2A1B-993A-40D5-B08A-2CF845BD02F7} - System32\Tasks\Plus-HD-2.4-enabler => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-enabler.exe [2013-07-01] (Plus HD) Task: {DF45D3D6-E963-44A8-9F0D-D49D1EE068CB} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2009-07-31] (ASUS) Task: {E2B3EB42-00D0-4770-9664-63BE47C60241} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2009-07-23] (ATK) Task: {F46AB22C-23A3-4EE7-BF5A-C9FA3785801E} - System32\Tasks\Microsoft\Windows\Media Center\mcupdate_scheduled => C:\Windows\ehome\mcupdate.exe [2010-08-04] (Microsoft Corporation) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Net4Switch.job => C:\Program Files (x86)\ASUS\Net4Switch\Net4Switch.exe Task: C:\Windows\Tasks\Plus-HD-2.4-chromeinstaller.job => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-chromeinstaller.exe Task: C:\Windows\Tasks\Plus-HD-2.4-codedownloader.job => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-codedownloader.exe Task: C:\Windows\Tasks\Plus-HD-2.4-enabler.job => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-enabler.exe Task: C:\Windows\Tasks\Plus-HD-2.4-updater.job => C:\Program Files (x86)\Plus-HD-2.4\Plus-HD-2.4-updater.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (07/04/2013 08:23:15 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "assemblyIdentity1". Fehler in Manifest- oder Richtliniendatei "assemblyIdentity2" in Zeile assemblyIdentity3. Der Wert "MAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINOR" des "version"-Attributs im assemblyIdentity-Element ist ungültig. Error: (07/04/2013 08:23:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/04/2013 08:23:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/04/2013 08:23:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/04/2013 08:23:11 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/04/2013 08:23:10 AM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"1". Die abhängige Assemblierung "Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (07/03/2013 09:30:54 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest. Error: (07/03/2013 09:30:39 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest. Error: (07/03/2013 09:30:24 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest. Error: (07/03/2013 09:11:34 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifest. System errors: ============= Microsoft Office Sessions: ========================= Error: (07/04/2013 08:23:15 AM) (Source: SideBySide)(User: ) Description: assemblyIdentityversionMAJOR_VERSION.MINOR_VERSION.BUILD_NUMBER_MAJOR.BUILD_NUMBER_MINORc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dllc:\Program Files (x86)\Common Files\Adobe AIR\Versions\1.0\Adobe AIR.dll3 Error: (07/04/2013 08:23:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"c:\program files\trend micro\internet security\component\framework\200\UfUpdUi.exe Error: (07/04/2013 08:23:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"c:\program files\trend micro\internet security\component\framework\200\UfSeAgnt.exe Error: (07/04/2013 08:23:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"c:\program files\trend micro\internet security\component\framework\200\UfNavi.exe Error: (07/04/2013 08:23:11 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"c:\program files\trend micro\internet security\component\framework\200\UfLogUi.exe Error: (07/04/2013 08:23:10 AM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.MFC,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50727.762"c:\program files\trend micro\internet security\component\framework\200\TisScan.exe Error: (07/03/2013 09:30:54 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifestC:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe Error: (07/03/2013 09:30:39 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifestC:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe Error: (07/03/2013 09:30:24 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifestC:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe Error: (07/03/2013 09:11:34 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_fa62ad231704eab7.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7600.16661_none_420fe3fa2b8113bd.manifestC:\Users\asus pro 5if\Desktop\esetsmartinstaller_enu.exe CodeIntegrity Errors: =================================== Date: 2013-07-02 20:04:39.311 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-07-02 20:04:39.264 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 51% Total physical RAM: 2924.56 MB Available physical RAM: 1419.76 MB Total Pagefile: 5847.26 MB Available Pagefile: 3770.88 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:72.69 GB) (Free:37.18 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)] Drive d: (Data) (Fixed) (Total:205.87 GB) (Free:203.68 GB) NTFS (Disk=0 Partition=3) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: 0237A506) Partition 1: (Not Active) - (Size=20 GB) - (Type=1C) Partition 2: (Active) - (Size=73 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=206 GB) - (Type=OF Extended) ==================== End Of Log ============================ Die Fehlermeldung kommt übrigens beim Rauffahren nimmer. Aber mein Netz is noch ewig langsam. Gruß Hannes |
Themen zu Internet total langsam |
adwcleaner, bauen, ccleaner, garnicht, inter, interne, internet, langsam, laufe, laufen, modem, nacht, provider, sehr langsam, tagen, total |