|
Plagegeister aller Art und deren Bekämpfung: Laptop plötzlich total langsam..Funde durch adwCleanerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
25.07.2013, 12:30 | #1 |
| Laptop plötzlich total langsam..Funde durch adwCleaner Hallo, nachdem mein Laptop plötzlich immer langsamer wurde,habe ich mal adwCleaner drüberlaufen lassen. Nachdem ich die Funde gelöscht hatte,lief das Laptop zwar sofort wieder besser aber das muss ja nicht heissen,das es jetzt wirklich sauber ist. Ich habe deshalb heute mal ein FRST erstellt,wäre nett wenn sich das mal jemand anschauen könnte. Ich füge hier auch noch das Logfile von adwCleaner mit ein. adwCleaner Code:
ATTFilter # AdwCleaner v2.306 - Datei am 22/07/2013 um 23:42:49 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits) # Benutzer : Engelchen - ENGELCHEN-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Engelchen\Documents\adwcleaner06.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Windows\system32\roboot.exe Ordner Gelöscht : C:\ProgramData\Trymedia ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider Schlüssel Gelöscht : HKCU\Software\Cr_Installer Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Giant Savings_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Giant Savings_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\1b7bca932e8e58197c81aef12b0aeb51 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\26ed81d02d19bddcfba0aacf4ff5833e Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\3ab02f88e33a1e9528bb7e73b02cbfe3 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\5ef51b22ce2229392927af76f69d8b7c Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\7efeb9935159a92ad4e101276c2a02bb Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\f0f6700c4c9b31d495f856d81d17adcf Schlüssel Gelöscht : HKLM\Software\systweak ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16635 [OK] Die Registrierungsdatenbank ist sauber. -\\ Google Chrome v28.0.1500.72 Datei : C:\Users\Engelchen\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. -\\ Opera v12.16.1860.0 Datei : C:\Users\Engelchen\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [2120 octets] - [22/07/2013 23:40:20] AdwCleaner[S1].txt - [2053 octets] - [22/07/2013 23:42:49] ########## EOF - C:\AdwCleaner[S1].txt - [2113 octets] ########## FRST Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-07-2013 Ran by Engelchen (administrator) on 25-07-2013 11:58:47 Running from C:\Users\Engelchen\Downloads Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Lenovo.) C:\Windows\system32\ibmpmsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVM Berlin) C:\Program Files\avmwlanstick\WlanNetService.exe (Microsoft Corporation) C:\Windows\system32\CISVC.EXE (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVM Berlin) C:\Program Files\avmwlanstick\WLanGUI.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Lenovo.) C:\Windows\System32\TpShocks.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Opera Software) C:\Program Files\Opera\opera.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM\...\Run: [AVMWlanClient] - C:\Program Files\avmwlanstick\wlangui.exe [1904640 2009-05-07] (AVM Berlin) HKLM\...\Run: [] - [x] HKLM\...\Run: [TpShocks] - TpShocks.exe [x] HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2379504 2013-04-24] (Synaptics Incorporated) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) Winlogon\Notify\AtiExtEvent: Ati2evxx.dll [X] HKCU\...\Run: [Easy Driver Pro] - C:\Program Files\Probit Software\Easy Driver Pro\DPLauncher.exe [x] MountPoints2: E - E:\pushinst.exe MountPoints2: {95ea50cb-1127-11e2-a4c2-001641129737} - E:\pushinst.exe HKU\Default\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] HKU\Default User\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== ProxyServer: :0 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp SearchScopes: HKLM - DefaultScope value is missing. BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\28.0.1500.72\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U10) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll No File CHR Plugin: (Windows Activation Technologies) - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.100.18) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Extension: (Google Docs) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Love Smoke) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgibfhhccaknggplelmbaepoikkcnllb\1_0 CHR Extension: (Gmail) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ========================== Services (Whitelisted) ================= S4 Ati External Event Utility; C:\Windows\system32\atiesrxx.exe [172032 2009-07-15] (AMD) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 AVM WLAN Connection Service; C:\Program Files\avmwlanstick\WlanNetService.exe [368640 2009-05-07] (AVM Berlin) S4 Ati HotKey Poller; %SystemRoot%\system32\Ati2evxx.exe [x] ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [61680 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [770344 2013-06-27] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [369584 2013-06-27] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [175176 2013-06-27] () S3 ati2mtag; C:\Windows\System32\DRIVERS\ati2mtag.sys [1273856 2006-01-21] (ATI Technologies Inc.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2007-01-26] (AVM Berlin) R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [265088 2007-01-26] (AVM GmbH) S3 SynthVid; C:\Windows\System32\DRIVERS\VMBusVideoM.sys [19456 2010-11-20] (Microsoft Corporation) R3 VSTHWICH; C:\Windows\System32\DRIVERS\VSTICH3.SYS [242176 2009-07-14] (Conexant Systems, Inc.) S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013\WNt500x86\Sandra.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-25 11:58 - 2013-07-25 11:58 - 00000000 ____D C:\FRST 2013-07-25 11:56 - 2013-07-25 11:56 - 01220306 _____ (Farbar) C:\Users\Engelchen\Downloads\FRST.exe 2013-07-25 11:37 - 2013-07-25 11:37 - 00268272 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-25 11:37 - 2013-07-25 11:37 - 00001056 _____ C:\Windows\PFRO.log 2013-07-25 11:37 - 2013-07-25 11:37 - 00000056 _____ C:\Windows\setupact.log 2013-07-25 11:37 - 2013-07-25 11:37 - 00000000 _____ C:\Windows\setuperr.log 2013-07-25 11:35 - 2013-07-25 11:35 - 00001761 _____ C:\AdwCleaner[S2].txt 2013-07-25 11:34 - 2013-07-25 11:35 - 00001699 _____ C:\AdwCleaner[R7].txt 2013-07-25 11:29 - 2013-07-25 11:31 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Mipony 2013-07-25 11:14 - 2013-07-25 11:15 - 00001353 _____ C:\AdwCleaner[R6].txt 2013-07-23 18:58 - 2013-07-23 18:59 - 00001293 _____ C:\AdwCleaner[R5].txt 2013-07-23 17:14 - 2013-07-23 17:22 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-07-23 11:49 - 2013-07-23 11:49 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-23 11:49 - 2013-07-23 11:49 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-23 11:47 - 2013-07-23 11:47 - 00001775 _____ C:\Users\Public\Desktop\Opera.lnk 2013-07-23 11:45 - 2013-07-23 11:45 - 00000000 ____D C:\Program Files\Common Files\Java 2013-07-23 11:45 - 2013-07-23 11:44 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-07-23 11:44 - 2013-07-23 11:44 - 00000000 ____D C:\Program Files\Java 2013-07-22 23:42 - 2013-07-22 23:43 - 00002182 _____ C:\AdwCleaner[S1].txt 2013-07-22 23:39 - 2013-07-22 23:39 - 00666633 _____ C:\Users\Engelchen\Documents\adwcleaner06.exe 2013-07-22 21:26 - 2013-07-25 11:36 - 00141666 _____ C:\Windows\WindowsUpdate.log 2013-07-21 11:35 - 2013-07-21 11:35 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Macromedia 2013-07-21 11:34 - 2013-07-21 11:34 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Mozilla 2013-07-21 11:33 - 2013-07-21 11:33 - 00000000 ____D C:\ProgramData\Mozilla 2013-07-20 21:23 - 2013-07-20 21:23 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Opera Software 2013-07-20 21:23 - 2013-07-20 21:23 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Opera Software 2013-07-12 12:15 - 2013-07-12 12:21 - 00000000 ____D C:\Windows\system32\MRT 2013-07-10 12:04 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-10 12:04 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-10 12:04 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-10 12:04 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-10 12:03 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-10 12:03 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-10 11:39 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-10 11:39 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-10 11:39 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 11:39 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-06-27 22:33 - 2013-06-27 22:33 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-06-26 20:58 - 2013-06-27 22:33 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-06-26 20:58 - 2013-06-27 22:33 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum ==================== One Month Modified Files and Folders ======= 2013-07-25 11:58 - 2013-07-25 11:58 - 00000000 ____D C:\FRST 2013-07-25 11:58 - 2012-10-08 11:12 - 00000000 ___RD C:\Users\Engelchen\Desktop 2013-07-25 11:56 - 2013-07-25 11:56 - 01220306 _____ (Farbar) C:\Users\Engelchen\Downloads\FRST.exe 2013-07-25 11:44 - 2009-07-14 06:34 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-25 11:44 - 2009-07-14 06:34 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-25 11:43 - 2013-01-11 13:33 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-25 11:43 - 2013-01-11 13:33 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-25 11:41 - 2013-07-22 21:26 - 00141666 _____ C:\Windows\WindowsUpdate.log 2013-07-25 11:37 - 2013-07-25 11:37 - 00268272 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-25 11:37 - 2013-07-25 11:37 - 00001056 _____ C:\Windows\PFRO.log 2013-07-25 11:37 - 2013-07-25 11:37 - 00000056 _____ C:\Windows\setupact.log 2013-07-25 11:37 - 2013-07-25 11:37 - 00000000 _____ C:\Windows\setuperr.log 2013-07-25 11:37 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-25 11:35 - 2013-07-25 11:35 - 00001761 _____ C:\AdwCleaner[S2].txt 2013-07-25 11:35 - 2013-07-25 11:34 - 00001699 _____ C:\AdwCleaner[R7].txt 2013-07-25 11:31 - 2013-07-25 11:29 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Mipony 2013-07-25 11:15 - 2013-07-25 11:14 - 00001353 _____ C:\AdwCleaner[R6].txt 2013-07-23 22:15 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Sidebar 2013-07-23 20:55 - 2012-10-08 13:22 - 00007596 _____ C:\Users\ENGELC~1\AppData\Local\resmon.resmoncfg 2013-07-23 18:59 - 2013-07-23 18:58 - 00001293 _____ C:\AdwCleaner[R5].txt 2013-07-23 17:23 - 2012-11-05 23:14 - 00000079 _____ C:\Windows\WININIT.INI 2013-07-23 17:23 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Desktop 2013-07-23 17:22 - 2013-07-23 17:14 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-07-23 11:49 - 2013-07-23 11:49 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-23 11:49 - 2013-07-23 11:49 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-23 11:47 - 2013-07-23 11:47 - 00001775 _____ C:\Users\Public\Desktop\Opera.lnk 2013-07-23 11:47 - 2013-05-23 14:44 - 00000000 ____D C:\Program Files\Opera 2013-07-23 11:45 - 2013-07-23 11:45 - 00000000 ____D C:\Program Files\Common Files\Java 2013-07-23 11:44 - 2013-07-23 11:45 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-07-23 11:44 - 2013-07-23 11:44 - 00000000 ____D C:\Program Files\Java 2013-07-23 11:44 - 2012-10-08 20:27 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-07-23 11:44 - 2012-10-08 20:27 - 00789416 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-07-22 23:43 - 2013-07-22 23:42 - 00002182 _____ C:\AdwCleaner[S1].txt 2013-07-22 23:39 - 2013-07-22 23:39 - 00666633 _____ C:\Users\Engelchen\Documents\adwcleaner06.exe 2013-07-22 17:21 - 2012-10-08 20:33 - 00000000 ____D C:\Windows\system32\appmgmt 2013-07-22 11:55 - 2009-07-14 04:04 - 00002577 _____ C:\Windows\system32\config.nt 2013-07-22 11:39 - 2012-10-08 11:30 - 00002075 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-07-22 11:33 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\wfp 2013-07-22 11:32 - 2012-10-24 12:14 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Winamp 2013-07-22 11:32 - 2012-10-08 12:31 - 00000000 ____D C:\Windows\system32\Macromed 2013-07-22 11:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\DriverStore 2013-07-22 11:32 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-07-22 11:31 - 2012-10-08 11:25 - 00000000 ____D C:\ProgramData\AVAST Software 2013-07-22 11:31 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration 2013-07-22 11:30 - 2012-10-08 11:25 - 00000000 ____D C:\Program Files\AVAST Software 2013-07-21 22:31 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\LogFiles 2013-07-21 11:35 - 2013-07-21 11:35 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Macromedia 2013-07-21 11:34 - 2013-07-21 11:34 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Mozilla 2013-07-21 11:33 - 2013-07-21 11:33 - 00000000 ____D C:\ProgramData\Mozilla 2013-07-21 11:30 - 2012-12-26 14:17 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Adobe 2013-07-20 21:23 - 2013-07-20 21:23 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Opera Software 2013-07-20 21:23 - 2013-07-20 21:23 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Opera Software 2013-07-18 14:09 - 2012-10-08 11:23 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\PCToolsFirewallPlus 2013-07-13 10:59 - 2013-01-11 13:38 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-12 12:21 - 2013-07-12 12:15 - 00000000 ____D C:\Windows\system32\MRT 2013-07-11 12:16 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-10 17:11 - 2012-10-08 12:01 - 00000000 ____D C:\Windows\Panther 2013-07-10 12:14 - 2011-04-12 03:39 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-10 12:14 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-10 12:08 - 2010-11-20 23:01 - 01528948 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-05 11:44 - 2012-10-08 18:37 - 00000965 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-07-05 11:44 - 2012-10-08 11:36 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 22:33 - 2013-06-27 22:33 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-06-27 22:33 - 2013-06-26 20:58 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-06-27 22:33 - 2013-06-26 20:58 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-06-27 22:33 - 2013-03-06 16:38 - 00175176 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-06-27 22:33 - 2012-10-08 11:29 - 00369584 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-06-27 22:33 - 2012-10-08 11:27 - 00770344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-11 17:25 ==================== End Of Log ============================ HTML-Code: Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-07-2013 Ran by Engelchen at 2013-07-25 12:00:29 Running from C:\Users\Engelchen\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 7-Zip 9.20 Adobe Flash Player 11 Plugin (Version: 11.8.800.94) Adobe Reader XI (11.0.03) - Deutsch (Version: 11.0.03) ATI Catalyst Install Manager (Version: 3.0.736.0) ATI Display Driver (Version: 8.163.1.1.1-060121a-030334C) avast! Free Antivirus (Version: 8.0.1489.0) AVM FRITZ!WLAN CCleaner (Version: 4.03) Google Chrome (Version: 28.0.1500.72) Google Update Helper (Version: 1.3.21.153) HD Tune 2.55 Intel(R) Graphics Media Accelerator Driver Java 7 Update 25 (Version: 7.0.250) Java Auto Updater (Version: 2.1.9.5) Lenovo Patch Utility (Version: 1.3.0.9) Lenovo Power Management Driver (Version: 1.67.00.02) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729) Opera 12.16 (Version: 12.16.1860) ThinkPad UltraNav Driver (Version: 16.2.19.7) ThinkVantage System für aktiven Festplattenschutz (Version: 1.77.0.9) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (Version: 1) Winamp (Version: 5.63 ) Winamp Erkennungs-Plug-in (HKCU Version: 1.0.0.1) ==================== Restore Points ========================= 22-07-2013 15:17:54 Removed Java 7 Update 25 22-07-2013 16:44:08 Removed Java 7 Update 25 23-07-2013 09:43:45 Installed Java 7 Update 25 23-07-2013 18:27:50 Windows Modules Installer ==================== Hosts content: ========================== 2009-07-14 04:04 - 2009-06-10 23:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0927766D-E973-4410-ABD4-BF1858866E4B} - System32\Tasks\{A9ADCC41-6D6F-4A6A-91E3-72EE43EFFB3D} => C:\Users\Engelchen\Eigene Spiele\Spiele\Delicious 6 - Emilys Childhood Memories Premium Edition\GHDeliciousEmilysChildhoodMemories.exe No File Task: {10FC761B-4177-4F2E-9F42-F981F006EB11} - System32\Tasks\{4AA1E15F-92C7-412D-A25D-BDEA44EB51F5} => C:\Users\Engelchen\Eigene Spiele\Spiele\Delicious 6 - Emilys Childhood Memories Premium Edition\GHDeliciousEmilysChildhoodMemories.exe No File Task: {13D2352D-0B71-4394-B945-96DF014CCAD4} - System32\Tasks\{32848FE3-6EB7-43FE-A2AB-603AAB03C094} => C:\Users\Engelchen\Eigene Spiele\Spiele\Delicious 4 - Emilys Taste of Fame\delicious4.exe [2009-06-01] (GameHouse, Inc.) Task: {22D24AE2-04B4-4B93-9FF3-9B9D596CB63D} - System32\Tasks\{3973F255-5ACE-4514-A9B8-A807CFE1D2CC} => C:\Users\Engelchen\Eigene Spiele\Spiele\Delicious 4 - Emilys Taste of Fame\delicious4.exe [2009-06-01] (GameHouse, Inc.) Task: {2FFE8CE0-85C2-4969-94CC-5F3B13B3BBDB} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3978639292-2544425347-965840320-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe No File Task: {3818573F-CBFB-4295-8665-7E00C5040500} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd) Task: {94D566BE-18F0-4496-98F0-CD5F6146BC30} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-11] (Google Inc.) Task: {D3A33A1B-F1E9-4F72-BB1F-F6969E43A117} - System32\Tasks\{EFA1F600-B79B-49D4-80DC-F85708F77793} => C:\Users\Engelchen\Eigene Spiele\Spiele\Delicious 4 - Emilys Taste of Fame\delicious4.exe [2009-06-01] (GameHouse, Inc.) Task: {DC0E9FC7-11DD-4C2A-BAF9-E1A35B4D94BF} - System32\Tasks\{AD01D64B-FA72-42C6-9118-11BAF3CAFB9D} => C:\Users\Engelchen\Eigene Spiele\Spiele\Delicious 6 - Emilys Childhood Memories Premium Edition\GHDeliciousEmilysChildhoodMemories.exe No File Task: {E7BFFFB1-08CB-4C06-99B8-BADDA24B2FE9} - System32\Tasks\{DF27F8B8-AA40-436D-A5EA-F14DD8B9FEB2} => C:\Users\Engelchen\Eigene Spiele\Spiele\Delicious 4 - Emilys Taste of Fame\delicious4.exe [2009-06-01] (GameHouse, Inc.) Task: {E9EA1176-0D8B-43D4-96B5-405F616566AD} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-01-11] (Google Inc.) Task: {EFD4D578-B9ED-4BFB-BC34-6DD548AFCD83} - System32\Tasks\DSite => C:\Users\ENGELC~1\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE No File Task: {F271E3A2-B99B-4CB7-9EA2-0B067C6A4817} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {F5554A65-B0AE-4565-BA6A-2F5FE8A6B1A0} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3978639292-2544425347-965840320-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe No File Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (07/25/2013 11:38:52 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/25/2013 11:37:39 AM) (Source: ESENT) (User: ) Description: taskhost (1628) WebCacheLocal: Fehler -1811 beim Öffnen von Protokolldatei C:\Users\Engelchen\AppData\Local\Microsoft\Windows\WebCache\V010005B.log. Error: (07/25/2013 11:28:52 AM) (Source: MsiInstaller) (User: Engelchen-PC) Description: Produkt: ATI Catalyst Install Manager -- Fehler 1706. Für das Produkt ATI Catalyst Install Manager wurde kein Installationspaket gefunden. Wiederholen Sie die Installation und verwenden Sie dabei eine gültige Kopie des Installationspakets "ATICatalystInstallManager.msi". Error: (07/25/2013 11:23:40 AM) (Source: MsiInstaller) (User: Engelchen-PC) Description: Produkt: ATI Catalyst Install Manager -- Fehler 1706. Für das Produkt ATI Catalyst Install Manager wurde kein Installationspaket gefunden. Wiederholen Sie die Installation und verwenden Sie dabei eine gültige Kopie des Installationspakets "ATICatalystInstallManager.msi". Error: (07/25/2013 11:12:47 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/24/2013 05:17:02 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/24/2013 00:51:20 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/24/2013 00:30:01 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/23/2013 10:19:00 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/23/2013 05:28:22 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (07/23/2013 05:20:06 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (07/23/2013 05:20:06 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Error: (07/23/2013 11:14:00 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597 (Definition 1.155.565.0) Error: (07/22/2013 05:15:54 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Ati HotKey Poller" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/22/2013 01:23:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Ati HotKey Poller" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/22/2013 00:00:57 PM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597 (Definition 1.155.311.0) Error: (07/22/2013 11:54:43 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (User: NT-AUTORITÄT) Description: Installationsfehler: Die Installation des folgenden Updates ist mit Fehler 0x80070643 fehlgeschlagen: Definition Update for Windows Defender - KB915597 (Definition 1.155.311.0) Error: (07/22/2013 11:41:45 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Ati HotKey Poller" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/22/2013 11:33:36 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Ati HotKey Poller" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (07/22/2013 11:10:28 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Ati HotKey Poller" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Microsoft Office Sessions: ========================= Error: (07/25/2013 11:38:52 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/25/2013 11:37:39 AM) (Source: ESENT)(User: ) Description: taskhost1628WebCacheLocal: C:\Users\Engelchen\AppData\Local\Microsoft\Windows\WebCache\V010005B.log-1811 Error: (07/25/2013 11:28:52 AM) (Source: MsiInstaller)(User: Engelchen-PC) Description: Produkt: ATI Catalyst Install Manager -- Fehler 1706. Für das Produkt ATI Catalyst Install Manager wurde kein Installationspaket gefunden. Wiederholen Sie die Installation und verwenden Sie dabei eine gültige Kopie des Installationspakets "ATICatalystInstallManager.msi".(NULL)(NULL)(NULL)(NULL)(NULL) Error: (07/25/2013 11:23:40 AM) (Source: MsiInstaller)(User: Engelchen-PC) Description: Produkt: ATI Catalyst Install Manager -- Fehler 1706. Für das Produkt ATI Catalyst Install Manager wurde kein Installationspaket gefunden. Wiederholen Sie die Installation und verwenden Sie dabei eine gültige Kopie des Installationspakets "ATICatalystInstallManager.msi".(NULL)(NULL)(NULL)(NULL)(NULL) Error: (07/25/2013 11:12:47 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/24/2013 05:17:02 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/24/2013 00:51:20 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/24/2013 00:30:01 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/23/2013 10:19:00 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (07/23/2013 05:28:22 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 78% Total physical RAM: 1014.49 MB Available physical RAM: 217.14 MB Total Pagefile: 1514.49 MB Available Pagefile: 717.37 MB Total Virtual: 2047.88 MB Available Virtual: 1915.73 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:55.79 GB) (Free:8.45 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 56 GB) (Disk ID: C2CA789A) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=56 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Gruss Speedy |
25.07.2013, 12:36 | #2 | |
/// the machine /// TB-Ausbilder | Laptop plötzlich total langsam..Funde durch adwCleaner hi,
__________________Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ |
25.07.2013, 13:36 | #3 |
| Laptop plötzlich total langsam..Funde durch adwCleaner Hallo Schrauber,
__________________erstmal danke für deine Hilfe.Habe jetzt ComboFix wie angegeben ausgeführt. Combofix Logfile: Code:
ATTFilter ComboFix 13-07-24.03 - Engelchen 25.07.2013 14:00:29.1.1 - x86 Microsoft Windows 7 Professional 6.1.7601.1.1252.49.1031.18.1014.494 [GMT 2:00] ausgeführt von:: c:\users\Engelchen\Desktop\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C} SP: avast! Antivirus *Disabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\windows\wininit.ini . . ((((((((((((((((((((((( Dateien erstellt von 2013-06-25 bis 2013-07-25 )))))))))))))))))))))))))))))) . . 2013-07-25 12:16 . 2013-07-25 12:16 -------- d-----w- c:\users\Engelchen\AppData\Local\temp 2013-07-25 12:16 . 2013-07-25 12:16 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-07-25 09:58 . 2013-07-25 09:58 -------- d-----w- C:\FRST 2013-07-25 09:29 . 2013-07-25 09:31 -------- d-----w- c:\users\Engelchen\AppData\Roaming\Mipony 2013-07-23 15:14 . 2013-07-23 15:22 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2013-07-23 09:49 . 2013-07-23 09:49 71048 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl 2013-07-23 09:49 . 2013-07-23 09:49 692104 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2013-07-23 09:45 . 2013-07-23 09:45 -------- d-----w- c:\program files\Common Files\Java 2013-07-23 09:44 . 2013-07-23 09:44 94632 ----a-w- c:\windows\system32\WindowsAccessBridge.dll 2013-07-23 09:44 . 2013-07-23 09:44 -------- d-----w- c:\program files\Java 2013-07-23 09:12 . 2013-07-15 01:34 7143960 ------w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{A4CC6645-6A47-4BB0-9C66-5368AD025151}\mpengine.dll 2013-07-21 09:35 . 2013-07-21 09:35 -------- d-----w- c:\users\Engelchen\AppData\Local\Macromedia 2013-07-21 09:34 . 2013-07-21 09:34 -------- d-----w- c:\users\Engelchen\AppData\Local\Mozilla 2013-07-20 19:23 . 2013-07-20 19:23 -------- d-----w- c:\users\Engelchen\AppData\Local\Opera Software 2013-07-20 19:23 . 2013-07-20 19:23 -------- d-----w- c:\users\Engelchen\AppData\Roaming\Opera Software 2013-07-12 10:15 . 2013-07-12 10:21 -------- d-----w- c:\windows\system32\MRT 2013-07-10 09:39 . 2013-04-09 23:34 1247744 ----a-w- c:\windows\system32\DWrite.dll 2013-07-10 09:39 . 2013-05-06 04:56 1620480 ----a-w- c:\windows\system32\WMVDECOD.DLL 2013-07-10 09:39 . 2013-06-04 04:53 509440 ----a-w- c:\windows\system32\qedit.dll 2013-07-10 09:39 . 2013-06-05 03:05 2347520 ----a-w- c:\windows\system32\win32k.sys 2013-07-10 09:39 . 2013-04-10 05:03 936448 ----a-w- c:\program files\Common Files\Microsoft Shared\ink\journal.dll 2013-07-10 09:39 . 2013-04-10 05:03 988672 ----a-w- c:\program files\Windows Journal\JNTFiltr.dll 2013-07-10 09:39 . 2013-04-10 05:03 969216 ----a-w- c:\program files\Windows Journal\JNWDRV.dll 2013-07-10 09:39 . 2013-04-10 05:04 1221632 ----a-w- c:\program files\Windows Journal\NBDoc.DLL 2013-07-10 09:38 . 2013-05-27 04:57 680960 ----a-w- c:\program files\Windows Defender\MpSvc.dll 2013-07-10 09:38 . 2013-05-27 04:57 392704 ----a-w- c:\program files\Windows Defender\MpClient.dll 2013-07-10 09:38 . 2013-05-27 04:57 224768 ----a-w- c:\program files\Windows Defender\MpCommu.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-07-23 09:44 . 2012-10-08 18:27 867240 ----a-w- c:\windows\system32\npDeployJava1.dll 2013-07-23 09:44 . 2012-10-08 18:27 789416 ----a-w- c:\windows\system32\deployJava1.dll 2013-06-27 20:33 . 2013-03-06 14:38 175176 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2013-06-27 20:33 . 2012-10-08 09:29 369584 ----a-w- c:\windows\system32\drivers\aswSP.sys 2013-06-27 20:33 . 2012-10-08 09:27 770344 ----a-w- c:\windows\system32\drivers\aswSnx.sys 2013-05-13 04:45 . 2013-06-12 09:43 1160192 ----a-w- c:\windows\system32\crypt32.dll 2013-05-13 04:45 . 2013-06-12 09:43 140288 ----a-w- c:\windows\system32\cryptsvc.dll 2013-05-13 04:45 . 2013-06-12 09:43 103936 ----a-w- c:\windows\system32\cryptnet.dll 2013-05-13 03:08 . 2013-06-12 09:43 903168 ----a-w- c:\windows\system32\certutil.exe 2013-05-13 03:08 . 2013-06-12 09:43 43008 ----a-w- c:\windows\system32\certenc.dll 2013-05-10 03:20 . 2013-06-12 09:43 24576 ----a-w- c:\windows\system32\cryptdlg.dll 2013-05-09 08:59 . 2013-03-06 14:38 49376 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2013-05-09 08:59 . 2012-10-08 09:28 61680 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2013-05-09 08:59 . 2012-10-08 09:27 56080 ----a-w- c:\windows\system32\drivers\aswTdi.sys 2013-05-09 08:59 . 2012-10-08 09:26 66336 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2013-05-09 08:59 . 2012-10-08 09:30 29816 ----a-w- c:\windows\system32\drivers\aswFsBlk.sys 2013-05-09 08:58 . 2012-10-08 09:25 41664 ----a-w- c:\windows\avastSS.scr 2013-05-09 08:58 . 2012-10-08 09:25 229648 ----a-w- c:\windows\system32\aswBoot.exe 2013-05-08 05:38 . 2013-06-12 09:42 1293672 ----a-w- c:\windows\system32\drivers\tcpip.sys 2013-05-06 05:06 . 2013-06-12 09:42 3913576 ----a-w- c:\windows\system32\ntoskrnl.exe 2013-05-06 05:06 . 2013-06-12 09:42 3968872 ----a-w- c:\windows\system32\ntkrnlpa.exe 2013-05-02 00:06 . 2012-10-09 10:43 238872 ------w- c:\windows\system32\MpSigStub.exe 2013-04-28 04:52 . 2013-04-28 04:52 60712 ----a-w- c:\windows\system32\ibmpmctl.exe 2013-04-28 04:52 . 2013-04-28 04:52 52008 ----a-w- c:\windows\system32\ibmpmsvc.exe 2013-04-28 04:52 . 2013-04-28 04:52 37248 ----a-w- c:\windows\system32\drivers\ibmpmdrv.sys 2013-04-28 04:52 . 2013-04-28 04:52 36648 ----a-w- c:\windows\system32\tpinspm.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2013-05-09 08:58 121968 ----a-w- c:\program files\AVAST Software\Avast\ashShell.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "avast"="c:\program files\AVAST Software\Avast\avastUI.exe" [2013-05-09 4858968] "AVMWlanClient"="c:\program files\avmwlanstick\wlangui.exe" [2009-05-07 1904640] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2007-01-13 131072] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2007-01-13 163840] "Persistence"="c:\windows\system32\igfxpers.exe" [2007-01-13 135168] "TpShocks"="TpShocks.exe" [2012-09-20 186248] "Adobe ARM"="c:\program files\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "SynTPEnh"="c:\program files\Synaptics\SynTP\SynTPEnh.exe" [2013-04-23 2379504] "SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk *\0\0sdnclean.exe HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\AtiTrayTools . [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\ATIModeChange] 2006-01-21 20:39 25088 ----a-w- c:\windows\System32\Ati2mdxx.exe . R3 avmeject;AVM Eject;c:\windows\system32\drivers\avmeject.sys [2007-01-25 4352] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys [2010-11-20 62464] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 14848] R3 SynthVid;SynthVid;c:\windows\system32\DRIVERS\VMBusVideoM.sys [2010-11-20 19456] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 49664] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2012-08-23 27136] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe [2012-11-14 1343400] S0 aswRvrt;aswRvrt; [x] S0 aswVmm;aswVmm; [x] S0 TPDIGIMN;TPDIGIMN;c:\windows\System32\DRIVERS\ApsHM86.sys [2011-12-28 22344] S1 aswSnx;aswSnx; [x] S1 aswSP;aswSP; [x] S2 aswFsBlk;aswFsBlk; [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys [2013-05-09 66336] S3 FWLANUSB;AVM FRITZ!WLAN;c:\windows\system32\DRIVERS\fwlanusb.sys [2007-01-25 265088] S3 VST_DPV;VST_DPV;c:\windows\system32\DRIVERS\VSTDPV3.SYS [2009-07-13 980992] S3 VSTHWICH;VSTHWICH;c:\windows\system32\DRIVERS\VSTICH3.SYS [2009-07-13 242176] . . [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2013-07-13 08:44 1173456 ----a-w- c:\program files\Google\Chrome\Application\28.0.1500.72\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2013-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files\Google\Update\GoogleUpdate.exe [2013-01-11 11:33] . 2013-07-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files\Google\Update\GoogleUpdate.exe [2013-01-11 11:33] . . ------- Zusätzlicher Suchlauf ------- . uInternet Settings,ProxyOverride = fritz.box IE: Mit Mipony herunterladen - file://c:\program files\MiPony\Browser\IEContext.htm . - - - - Entfernte verwaiste Registrierungseinträge - - - - . HKCU-Run-Easy Driver Pro - c:\program files\Probit Software\Easy Driver Pro\DPLauncher.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-07-25 14:18:36 ComboFix-quarantined-files.txt 2013-07-25 12:18 . Vor Suchlauf: 9.227.071.488 Bytes frei Nach Suchlauf: 9.152.102.400 Bytes frei . - - End Of File - - 530B384B1BE7C66EDEB029B37E027F95 A36C5E4F47E84449FF07ED3517B43A31 [/HTML] Gruss Speedy |
26.07.2013, 07:24 | #4 |
/// the machine /// TB-Ausbilder | Laptop plötzlich total langsam..Funde durch adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
26.07.2013, 10:59 | #5 |
| Laptop plötzlich total langsam..Funde durch adwCleaner So dann mal los... AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v2.306 - Datei am 26/07/2013 um 11:27:34 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (32 bits) # Benutzer : Engelchen - ENGELCHEN-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Engelchen\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\InstallCore ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16635 [OK] Die Registrierungsdatenbank ist sauber. -\\ Google Chrome v28.0.1500.72 Datei : C:\Users\Engelchen\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. -\\ Opera v12.16.1860.0 Datei : C:\Users\Engelchen\AppData\Roaming\Opera\Opera\operaprefs.ini [OK] Die Datei ist sauber. ************************* AdwCleaner[R5].txt - [1293 octets] - [23/07/2013 18:58:25] AdwCleaner[R6].txt - [1353 octets] - [25/07/2013 11:14:54] AdwCleaner[R7].txt - [1699 octets] - [25/07/2013 11:34:45] AdwCleaner[R8].txt - [1341 octets] - [25/07/2013 21:38:40] AdwCleaner[S1].txt - [2182 octets] - [22/07/2013 23:42:49] AdwCleaner[S2].txt - [1761 octets] - [25/07/2013 11:35:36] AdwCleaner[S3].txt - [1270 octets] - [26/07/2013 11:27:34] ########## EOF - C:\AdwCleaner[S3].txt - [1330 octets] ########## JRT HTML-Code: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.2.3 (07.25.2013:1) OS: Windows 7 Professional x86 Ran by Engelchen on 26.07.2013 at 11:34:26,87 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\big fish games" Successfully deleted: [Folder] "C:\Users\Engelchen\AppData\Roaming\systweak" ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 26.07.2013 at 11:36:37,43 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-07-2013 Ran by Engelchen (administrator) on 26-07-2013 11:52:15 Running from C:\Users\Engelchen\Desktop Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Lenovo.) C:\Windows\system32\ibmpmsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVM Berlin) C:\Program Files\avmwlanstick\WLanGUI.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Lenovo.) C:\Windows\System32\TpShocks.exe (AVM Berlin) C:\Program Files\avmwlanstick\WlanNetService.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Microsoft Corporation) C:\Windows\system32\CISVC.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Opera Software) C:\Program Files\Opera\opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM\...\Run: [AVMWlanClient] - C:\Program Files\avmwlanstick\wlangui.exe [1904640 2009-05-07] (AVM Berlin) HKLM\...\Run: [TpShocks] - C:\Windows\System32\TpShocks.exe [186248 2012-09-20] (Lenovo.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2379504 2013-04-24] (Synaptics Incorporated) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) Winlogon\Notify\AtiExtEvent: Ati2evxx.dll [X] HKU\Default\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] HKU\Default User\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== ProxyServer: :0 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - "C:\Program Files\Internet Explorer\iexplore.exe" SearchScopes: HKLM - DefaultScope value is missing. BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\28.0.1500.72\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U10) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll No File CHR Plugin: (Windows Activation Technologies) - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.100.18) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Extension: (Google Docs) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Love Smoke) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgibfhhccaknggplelmbaepoikkcnllb\1_0 CHR Extension: (Gmail) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ========================== Services (Whitelisted) ================= S4 Ati External Event Utility; C:\Windows\system32\atiesrxx.exe [172032 2009-07-15] (AMD) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 AVM WLAN Connection Service; C:\Program Files\avmwlanstick\WlanNetService.exe [368640 2009-05-07] (AVM Berlin) S4 Ati HotKey Poller; %SystemRoot%\system32\Ati2evxx.exe [x] ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [61680 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [770344 2013-06-27] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [369584 2013-06-27] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [175176 2013-06-27] () S3 ati2mtag; C:\Windows\System32\DRIVERS\ati2mtag.sys [1273856 2006-01-21] (ATI Technologies Inc.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2007-01-26] (AVM Berlin) R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [265088 2007-01-26] (AVM GmbH) S3 SynthVid; C:\Windows\System32\DRIVERS\VMBusVideoM.sys [19456 2010-11-20] (Microsoft Corporation) R3 VSTHWICH; C:\Windows\System32\DRIVERS\VSTICH3.SYS [242176 2009-07-14] (Conexant Systems, Inc.) S3 catchme; \??\C:\Users\ENGELC~1\AppData\Local\Temp\catchme.sys [x] S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013\WNt500x86\Sandra.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-26 11:50 - 2013-07-26 11:50 - 01220112 _____ (Farbar) C:\Users\Engelchen\Desktop\FRST.exe 2013-07-26 11:36 - 2013-07-26 11:36 - 00000773 _____ C:\Users\Engelchen\Desktop\JRT.txt 2013-07-26 11:34 - 2013-07-26 11:34 - 00000000 ____D C:\Windows\ERUNT 2013-07-26 11:32 - 2013-07-26 11:32 - 00561140 _____ (Oleg N. Scherbakov) C:\Users\Engelchen\Desktop\JRT.exe 2013-07-26 11:31 - 2013-07-26 11:31 - 00001399 _____ C:\Users\Engelchen\Documents\AdwCleaner[S3].txt 2013-07-26 11:29 - 2013-07-26 11:47 - 00000112 _____ C:\Windows\setupact.log 2013-07-26 11:29 - 2013-07-26 11:29 - 00268272 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-26 11:29 - 2013-07-26 11:29 - 00000000 _____ C:\Windows\setuperr.log 2013-07-26 11:27 - 2013-07-26 11:27 - 00001399 _____ C:\AdwCleaner[S3].txt 2013-07-26 11:25 - 2013-07-26 11:25 - 00666633 _____ C:\Users\Engelchen\Desktop\adwcleaner.exe 2013-07-25 21:38 - 2013-07-25 21:39 - 00001341 _____ C:\AdwCleaner[R8].txt 2013-07-25 14:18 - 2013-07-25 14:18 - 00010385 _____ C:\ComboFix.txt 2013-07-25 13:58 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-07-25 13:58 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-07-25 13:58 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-07-25 13:58 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-07-25 13:58 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-07-25 13:58 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-07-25 13:58 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-07-25 13:58 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-07-25 13:57 - 2013-07-25 14:18 - 00000000 ____D C:\Qoobox 2013-07-25 13:57 - 2013-07-25 14:17 - 00000000 ____D C:\Windows\erdnt 2013-07-25 13:50 - 2013-07-25 13:50 - 05094311 ____R (Swearware) C:\Users\Engelchen\Desktop\ComboFix.exe 2013-07-25 11:58 - 2013-07-25 11:58 - 00000000 ____D C:\FRST 2013-07-25 11:35 - 2013-07-25 11:35 - 00001761 _____ C:\AdwCleaner[S2].txt 2013-07-25 11:34 - 2013-07-25 11:35 - 00001699 _____ C:\AdwCleaner[R7].txt 2013-07-25 11:29 - 2013-07-25 11:31 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Mipony 2013-07-25 11:14 - 2013-07-25 11:15 - 00001353 _____ C:\AdwCleaner[R6].txt 2013-07-23 18:58 - 2013-07-23 18:59 - 00001293 _____ C:\AdwCleaner[R5].txt 2013-07-23 17:14 - 2013-07-23 17:22 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-07-23 11:49 - 2013-07-23 11:49 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-23 11:49 - 2013-07-23 11:49 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-23 11:47 - 2013-07-23 11:47 - 00001775 _____ C:\Users\Public\Desktop\Opera.lnk 2013-07-23 11:45 - 2013-07-23 11:45 - 00000000 ____D C:\Program Files\Common Files\Java 2013-07-23 11:45 - 2013-07-23 11:44 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-07-23 11:44 - 2013-07-23 11:44 - 00000000 ____D C:\Program Files\Java 2013-07-22 23:42 - 2013-07-22 23:43 - 00002182 _____ C:\AdwCleaner[S1].txt 2013-07-22 21:26 - 2013-07-26 11:45 - 00177836 _____ C:\Windows\WindowsUpdate.log 2013-07-21 11:35 - 2013-07-21 11:35 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Macromedia 2013-07-21 11:34 - 2013-07-21 11:34 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Mozilla 2013-07-21 11:33 - 2013-07-21 11:33 - 00000000 ____D C:\ProgramData\Mozilla 2013-07-20 21:23 - 2013-07-20 21:23 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Opera Software 2013-07-20 21:23 - 2013-07-20 21:23 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Opera Software 2013-07-12 12:15 - 2013-07-12 12:21 - 00000000 ____D C:\Windows\system32\MRT 2013-07-10 12:04 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-10 12:04 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-10 12:04 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-10 12:04 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-10 12:03 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-10 12:03 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-10 11:39 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-10 11:39 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-10 11:39 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 11:39 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-06-27 22:33 - 2013-06-27 22:33 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-06-26 20:58 - 2013-06-27 22:33 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-06-26 20:58 - 2013-06-27 22:33 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum ==================== One Month Modified Files and Folders ======= 2013-07-26 11:50 - 2013-07-26 11:50 - 01220112 _____ (Farbar) C:\Users\Engelchen\Desktop\FRST.exe 2013-07-26 11:50 - 2013-07-22 21:26 - 00177836 _____ C:\Windows\WindowsUpdate.log 2013-07-26 11:50 - 2012-10-08 11:12 - 00000000 ___RD C:\Users\Engelchen\Desktop 2013-07-26 11:47 - 2013-07-26 11:29 - 00000112 _____ C:\Windows\setupact.log 2013-07-26 11:47 - 2013-01-11 13:33 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-26 11:47 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-26 11:43 - 2013-01-11 13:33 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-26 11:37 - 2009-07-14 06:34 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-26 11:37 - 2009-07-14 06:34 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-26 11:36 - 2013-07-26 11:36 - 00000773 _____ C:\Users\Engelchen\Desktop\JRT.txt 2013-07-26 11:34 - 2013-07-26 11:34 - 00000000 ____D C:\Windows\ERUNT 2013-07-26 11:32 - 2013-07-26 11:32 - 00561140 _____ (Oleg N. Scherbakov) C:\Users\Engelchen\Desktop\JRT.exe 2013-07-26 11:31 - 2013-07-26 11:31 - 00001399 _____ C:\Users\Engelchen\Documents\AdwCleaner[S3].txt 2013-07-26 11:29 - 2013-07-26 11:29 - 00268272 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-26 11:29 - 2013-07-26 11:29 - 00000000 _____ C:\Windows\setuperr.log 2013-07-26 11:27 - 2013-07-26 11:27 - 00001399 _____ C:\AdwCleaner[S3].txt 2013-07-26 11:25 - 2013-07-26 11:25 - 00666633 _____ C:\Users\Engelchen\Desktop\adwcleaner.exe 2013-07-25 21:39 - 2013-07-25 21:38 - 00001341 _____ C:\AdwCleaner[R8].txt 2013-07-25 14:18 - 2013-07-25 14:18 - 00010385 _____ C:\ComboFix.txt 2013-07-25 14:18 - 2013-07-25 13:57 - 00000000 ____D C:\Qoobox 2013-07-25 14:18 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public 2013-07-25 14:17 - 2013-07-25 13:57 - 00000000 ____D C:\Windows\erdnt 2013-07-25 14:16 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini 2013-07-25 13:50 - 2013-07-25 13:50 - 05094311 ____R (Swearware) C:\Users\Engelchen\Desktop\ComboFix.exe 2013-07-25 11:58 - 2013-07-25 11:58 - 00000000 ____D C:\FRST 2013-07-25 11:35 - 2013-07-25 11:35 - 00001761 _____ C:\AdwCleaner[S2].txt 2013-07-25 11:35 - 2013-07-25 11:34 - 00001699 _____ C:\AdwCleaner[R7].txt 2013-07-25 11:31 - 2013-07-25 11:29 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Mipony 2013-07-25 11:15 - 2013-07-25 11:14 - 00001353 _____ C:\AdwCleaner[R6].txt 2013-07-23 22:15 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Sidebar 2013-07-23 20:55 - 2012-10-08 13:22 - 00007596 _____ C:\Users\ENGELC~1\AppData\Local\resmon.resmoncfg 2013-07-23 18:59 - 2013-07-23 18:58 - 00001293 _____ C:\AdwCleaner[R5].txt 2013-07-23 17:23 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Desktop 2013-07-23 17:22 - 2013-07-23 17:14 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-07-23 11:49 - 2013-07-23 11:49 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-23 11:49 - 2013-07-23 11:49 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-23 11:47 - 2013-07-23 11:47 - 00001775 _____ C:\Users\Public\Desktop\Opera.lnk 2013-07-23 11:47 - 2013-05-23 14:44 - 00000000 ____D C:\Program Files\Opera 2013-07-23 11:45 - 2013-07-23 11:45 - 00000000 ____D C:\Program Files\Common Files\Java 2013-07-23 11:44 - 2013-07-23 11:45 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-07-23 11:44 - 2013-07-23 11:44 - 00000000 ____D C:\Program Files\Java 2013-07-23 11:44 - 2012-10-08 20:27 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-07-23 11:44 - 2012-10-08 20:27 - 00789416 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-07-22 23:43 - 2013-07-22 23:42 - 00002182 _____ C:\AdwCleaner[S1].txt 2013-07-22 17:21 - 2012-10-08 20:33 - 00000000 ____D C:\Windows\system32\appmgmt 2013-07-22 11:55 - 2009-07-14 04:04 - 00002577 _____ C:\Windows\system32\config.nt 2013-07-22 11:39 - 2012-10-08 11:30 - 00002075 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-07-22 11:33 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\wfp 2013-07-22 11:32 - 2012-10-24 12:14 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Winamp 2013-07-22 11:32 - 2012-10-08 12:31 - 00000000 ____D C:\Windows\system32\Macromed 2013-07-22 11:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\DriverStore 2013-07-22 11:32 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-07-22 11:31 - 2012-10-08 11:25 - 00000000 ____D C:\ProgramData\AVAST Software 2013-07-22 11:31 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration 2013-07-22 11:30 - 2012-10-08 11:25 - 00000000 ____D C:\Program Files\AVAST Software 2013-07-21 22:31 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\LogFiles 2013-07-21 11:35 - 2013-07-21 11:35 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Macromedia 2013-07-21 11:34 - 2013-07-21 11:34 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Mozilla 2013-07-21 11:33 - 2013-07-21 11:33 - 00000000 ____D C:\ProgramData\Mozilla 2013-07-21 11:30 - 2012-12-26 14:17 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Adobe 2013-07-20 21:23 - 2013-07-20 21:23 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Opera Software 2013-07-20 21:23 - 2013-07-20 21:23 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Opera Software 2013-07-18 14:09 - 2012-10-08 11:23 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\PCToolsFirewallPlus 2013-07-13 10:59 - 2013-01-11 13:38 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-12 12:21 - 2013-07-12 12:15 - 00000000 ____D C:\Windows\system32\MRT 2013-07-11 12:16 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-10 17:11 - 2012-10-08 12:01 - 00000000 ____D C:\Windows\Panther 2013-07-10 12:14 - 2011-04-12 03:39 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-10 12:14 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-10 12:08 - 2010-11-20 23:01 - 01528948 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-05 11:44 - 2012-10-08 18:37 - 00000965 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-07-05 11:44 - 2012-10-08 11:36 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 22:33 - 2013-06-27 22:33 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-06-27 22:33 - 2013-06-26 20:58 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-06-27 22:33 - 2013-06-26 20:58 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-06-27 22:33 - 2013-03-06 16:38 - 00175176 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-06-27 22:33 - 2012-10-08 11:29 - 00369584 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-06-27 22:33 - 2012-10-08 11:27 - 00770344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-11 17:25 ==================== End Of Log ============================ --- --- --- --- --- --- Gruss Speedy |
26.07.2013, 12:52 | #6 |
/// the machine /// TB-Ausbilder | Laptop plötzlich total langsam..Funde durch adwCleaner Supi ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Laptop plötzlich total langsam..Funde durch adwCleaner |
26.07.2013, 19:05 | #7 |
| Laptop plötzlich total langsam..Funde durch adwCleaner So..weiter gehts... ESET HTML-Code: ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=c3cfcb722fb5cf42bfff8affab8d355a # engine=14542 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-07-26 05:31:48 # local_time=2013-07-26 07:31:48 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 93 373394 151569780 0 0 # compatibility_mode=5893 16776574 100 94 172610 126491099 0 0 # scanned=79718 # found=0 # cleaned=0 # scan_time=2065 HTML-Code: Results of screen317's Security Check version 0.99.70 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 10 [b][u]``````````````Antivirus/Firewall Check:``````````````[/u][/b][u][/u] avast! Antivirus Antivirus up to date! [b][u]`````````Anti-malware/Other Utilities Check:`````````[/u][/b][u][/u] Malwarebytes Anti-Malware Version 1.75.0.1300 CCleaner Java 7 Update 25 Adobe Flash Player 11.8.800.94 Adobe Reader XI Google Chrome 28.0.1500.71 Google Chrome 28.0.1500.72 [b][u]````````Process Check: objlist.exe by Laurent````````[/u][/b][u][/u] AVAST Software Avast AvastSvc.exe AVAST Software Avast AvastUI.exe [b][u]`````````````````System Health check`````````````````[/u][/b][u][/u] Total Fragmentation on Drive C: [b][u]````````````````````End of Log``````````````````````[/u][/b][u][/u] FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 25-07-2013 Ran by Engelchen (administrator) on 26-07-2013 19:52:28 Running from C:\Users\Engelchen\Desktop Microsoft Windows 7 Professional Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Lenovo.) C:\Windows\system32\ibmpmsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVM Berlin) C:\Program Files\avmwlanstick\WlanNetService.exe (Microsoft Corporation) C:\Windows\system32\CISVC.EXE (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVM Berlin) C:\Program Files\avmwlanstick\WLanGUI.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Lenovo.) C:\Windows\System32\TpShocks.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Oracle Corporation) C:\Program Files\Common Files\Java\Java Update\jusched.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPLpr.exe (Opera Software) C:\Program Files\Opera\opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) HKLM\...\Run: [AVMWlanClient] - C:\Program Files\avmwlanstick\wlangui.exe [1904640 2009-05-07] (AVM Berlin) HKLM\...\Run: [TpShocks] - C:\Windows\System32\TpShocks.exe [186248 2012-09-20] (Lenovo.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2379504 2013-04-24] (Synaptics Incorporated) HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) Winlogon\Notify\AtiExtEvent: Ati2evxx.dll [X] HKU\Default\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] HKU\Default User\...\Run: [Sidebar] - %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun [x] BootExecute: autocheck autochk * sdnclean.exe ==================== Internet (Whitelisted) ==================== ProxyServer: :0 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - "C:\Program Files\Internet Explorer\iexplore.exe" SearchScopes: HKLM - DefaultScope value is missing. BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files\Google\Chrome\Application\28.0.1500.72\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files\Google\Chrome\Application\28.0.1500.72\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files\Google\Chrome\Application\28.0.1500.72\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files\Google\Update\1.3.21.124\npGoogleUpdate3.dll No File CHR Plugin: (Java(TM) Platform SE 7 U10) - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (Shockwave Flash) - C:\Windows\system32\Macromed\Flash\NPSWF32_11_5_502_146.dll No File CHR Plugin: (Windows Activation Technologies) - C:\Windows\system32\Wat\npWatWeb.dll (Microsoft Corporation) CHR Plugin: (Java Deployment Toolkit 7.0.100.18) - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) CHR Extension: (Google Docs) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Love Smoke) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\jgibfhhccaknggplelmbaepoikkcnllb\1_0 CHR Extension: (Gmail) - C:\Users\ENGELC~1\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ========================== Services (Whitelisted) ================= S4 Ati External Event Utility; C:\Windows\system32\atiesrxx.exe [172032 2009-07-15] (AMD) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 AVM WLAN Connection Service; C:\Program Files\avmwlanstick\WlanNetService.exe [368640 2009-05-07] (AVM Berlin) S4 Ati HotKey Poller; %SystemRoot%\system32\Ati2evxx.exe [x] ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [61680 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49376 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [770344 2013-06-27] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [369584 2013-06-27] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [56080 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [175176 2013-06-27] () S3 ati2mtag; C:\Windows\System32\DRIVERS\ati2mtag.sys [1273856 2006-01-21] (ATI Technologies Inc.) S3 avmeject; C:\Windows\System32\drivers\avmeject.sys [4352 2007-01-26] (AVM Berlin) R3 FWLANUSB; C:\Windows\System32\DRIVERS\fwlanusb.sys [265088 2007-01-26] (AVM GmbH) S3 SynthVid; C:\Windows\System32\DRIVERS\VMBusVideoM.sys [19456 2010-11-20] (Microsoft Corporation) R3 VSTHWICH; C:\Windows\System32\DRIVERS\VSTICH3.SYS [242176 2009-07-14] (Conexant Systems, Inc.) S3 catchme; \??\C:\Users\ENGELC~1\AppData\Local\Temp\catchme.sys [x] S3 SANDRA; \??\C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2013\WNt500x86\Sandra.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-26 19:38 - 2013-07-26 19:38 - 00891062 _____ C:\Users\Engelchen\Desktop\SecurityCheck.exe 2013-07-26 18:47 - 2013-07-26 18:47 - 00000000 ____D C:\Program Files\ESET 2013-07-26 11:50 - 2013-07-26 11:50 - 01220112 _____ (Farbar) C:\Users\Engelchen\Desktop\FRST.exe 2013-07-26 11:34 - 2013-07-26 11:34 - 00000000 ____D C:\Windows\ERUNT 2013-07-26 11:32 - 2013-07-26 11:32 - 00561140 _____ (Oleg N. Scherbakov) C:\Users\Engelchen\Desktop\JRT.exe 2013-07-26 11:25 - 2013-07-26 11:25 - 00666633 _____ C:\Users\Engelchen\Desktop\adwcleaner.exe 2013-07-25 13:58 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-07-25 13:58 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-07-25 13:58 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-07-25 13:58 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-07-25 13:58 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-07-25 13:58 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-07-25 13:58 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-07-25 13:58 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-07-25 13:57 - 2013-07-25 14:18 - 00000000 ____D C:\Qoobox 2013-07-25 13:57 - 2013-07-25 14:17 - 00000000 ____D C:\Windows\erdnt 2013-07-25 13:50 - 2013-07-25 13:50 - 05094311 ____R (Swearware) C:\Users\Engelchen\Desktop\ComboFix.exe 2013-07-25 11:58 - 2013-07-25 11:58 - 00000000 ____D C:\FRST 2013-07-25 11:29 - 2013-07-25 11:31 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Mipony 2013-07-23 17:14 - 2013-07-23 17:22 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-07-23 11:49 - 2013-07-23 11:49 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-23 11:49 - 2013-07-23 11:49 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-23 11:47 - 2013-07-23 11:47 - 00001775 _____ C:\Users\Public\Desktop\Opera.lnk 2013-07-23 11:45 - 2013-07-23 11:45 - 00000000 ____D C:\Program Files\Common Files\Java 2013-07-23 11:45 - 2013-07-23 11:44 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-07-23 11:44 - 2013-07-23 11:44 - 00000000 ____D C:\Program Files\Java 2013-07-22 21:26 - 2013-07-26 19:32 - 00182128 _____ C:\Windows\WindowsUpdate.log 2013-07-21 11:35 - 2013-07-21 11:35 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Macromedia 2013-07-21 11:34 - 2013-07-21 11:34 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Mozilla 2013-07-21 11:33 - 2013-07-21 11:33 - 00000000 ____D C:\ProgramData\Mozilla 2013-07-20 21:23 - 2013-07-20 21:23 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Opera Software 2013-07-20 21:23 - 2013-07-20 21:23 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Opera Software 2013-07-12 12:15 - 2013-07-12 12:21 - 00000000 ____D C:\Windows\system32\MRT 2013-07-10 12:04 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-10 12:04 - 2013-06-12 01:43 - 00042496 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-10 12:04 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-10 12:04 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-10 12:04 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-10 12:04 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-10 12:03 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-10 12:03 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-10 11:39 - 2013-06-05 05:05 - 02347520 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-10 11:39 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-10 11:39 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-10 11:39 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-06-27 22:33 - 2013-06-27 22:33 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-06-26 20:58 - 2013-06-27 22:33 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-06-26 20:58 - 2013-06-27 22:33 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum ==================== One Month Modified Files and Folders ======= 2013-07-26 19:43 - 2013-01-11 13:33 - 00001104 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-07-26 19:38 - 2013-07-26 19:38 - 00891062 _____ C:\Users\Engelchen\Desktop\SecurityCheck.exe 2013-07-26 19:38 - 2012-10-08 11:12 - 00000000 ___RD C:\Users\Engelchen\Desktop 2013-07-26 19:32 - 2013-07-22 21:26 - 00182128 _____ C:\Windows\WindowsUpdate.log 2013-07-26 18:47 - 2013-07-26 18:47 - 00000000 ____D C:\Program Files\ESET 2013-07-26 17:21 - 2009-07-14 06:34 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-26 17:21 - 2009-07-14 06:34 - 00021904 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-26 17:14 - 2013-01-11 13:33 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-07-26 17:13 - 2009-07-14 06:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-07-26 17:05 - 2012-11-04 13:18 - 00000000 ____D C:\Users\Engelchen\Eigene Spiele 2013-07-26 11:50 - 2013-07-26 11:50 - 01220112 _____ (Farbar) C:\Users\Engelchen\Desktop\FRST.exe 2013-07-26 11:34 - 2013-07-26 11:34 - 00000000 ____D C:\Windows\ERUNT 2013-07-26 11:32 - 2013-07-26 11:32 - 00561140 _____ (Oleg N. Scherbakov) C:\Users\Engelchen\Desktop\JRT.exe 2013-07-26 11:25 - 2013-07-26 11:25 - 00666633 _____ C:\Users\Engelchen\Desktop\adwcleaner.exe 2013-07-25 14:18 - 2013-07-25 13:57 - 00000000 ____D C:\Qoobox 2013-07-25 14:18 - 2009-07-14 04:37 - 00000000 ___RD C:\Users\Public 2013-07-25 14:17 - 2013-07-25 13:57 - 00000000 ____D C:\Windows\erdnt 2013-07-25 14:16 - 2009-07-14 04:04 - 00000215 _____ C:\Windows\system.ini 2013-07-25 13:50 - 2013-07-25 13:50 - 05094311 ____R (Swearware) C:\Users\Engelchen\Desktop\ComboFix.exe 2013-07-25 11:58 - 2013-07-25 11:58 - 00000000 ____D C:\FRST 2013-07-25 11:31 - 2013-07-25 11:29 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Mipony 2013-07-23 22:15 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Sidebar 2013-07-23 20:55 - 2012-10-08 13:22 - 00007596 _____ C:\Users\ENGELC~1\AppData\Local\resmon.resmoncfg 2013-07-23 17:23 - 2009-07-14 04:37 - 00000000 __RHD C:\Users\Public\Desktop 2013-07-23 17:22 - 2013-07-23 17:14 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-07-23 11:49 - 2013-07-23 11:49 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2013-07-23 11:49 - 2013-07-23 11:49 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2013-07-23 11:47 - 2013-07-23 11:47 - 00001775 _____ C:\Users\Public\Desktop\Opera.lnk 2013-07-23 11:47 - 2013-05-23 14:44 - 00000000 ____D C:\Program Files\Opera 2013-07-23 11:45 - 2013-07-23 11:45 - 00000000 ____D C:\Program Files\Common Files\Java 2013-07-23 11:44 - 2013-07-23 11:45 - 00263592 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00175016 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-07-23 11:44 - 2013-07-23 11:44 - 00094632 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge.dll 2013-07-23 11:44 - 2013-07-23 11:44 - 00000000 ____D C:\Program Files\Java 2013-07-23 11:44 - 2012-10-08 20:27 - 00867240 _____ (Oracle Corporation) C:\Windows\system32\npDeployJava1.dll 2013-07-23 11:44 - 2012-10-08 20:27 - 00789416 _____ (Oracle Corporation) C:\Windows\system32\deployJava1.dll 2013-07-22 17:21 - 2012-10-08 20:33 - 00000000 ____D C:\Windows\system32\appmgmt 2013-07-22 11:55 - 2009-07-14 04:04 - 00002577 _____ C:\Windows\system32\config.nt 2013-07-22 11:39 - 2012-10-08 11:30 - 00002075 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-07-22 11:33 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\wfp 2013-07-22 11:32 - 2012-10-24 12:14 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Winamp 2013-07-22 11:32 - 2012-10-08 12:31 - 00000000 ____D C:\Windows\system32\Macromed 2013-07-22 11:32 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\DriverStore 2013-07-22 11:32 - 2009-07-14 04:37 - 00000000 ____D C:\Program Files\Common Files\microsoft shared 2013-07-22 11:31 - 2012-10-08 11:25 - 00000000 ____D C:\ProgramData\AVAST Software 2013-07-22 11:31 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\registration 2013-07-22 11:30 - 2012-10-08 11:25 - 00000000 ____D C:\Program Files\AVAST Software 2013-07-21 22:31 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\system32\LogFiles 2013-07-21 11:35 - 2013-07-21 11:35 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Macromedia 2013-07-21 11:34 - 2013-07-21 11:34 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Mozilla 2013-07-21 11:33 - 2013-07-21 11:33 - 00000000 ____D C:\ProgramData\Mozilla 2013-07-21 11:30 - 2012-12-26 14:17 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Adobe 2013-07-20 21:23 - 2013-07-20 21:23 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\Opera Software 2013-07-20 21:23 - 2013-07-20 21:23 - 00000000 ____D C:\Users\ENGELC~1\AppData\Local\Opera Software 2013-07-18 14:09 - 2012-10-08 11:23 - 00000000 ____D C:\Users\Engelchen\AppData\Roaming\PCToolsFirewallPlus 2013-07-13 10:59 - 2013-01-11 13:38 - 00002129 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-07-12 12:21 - 2013-07-12 12:15 - 00000000 ____D C:\Windows\system32\MRT 2013-07-11 12:16 - 2009-07-14 04:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-10 17:11 - 2012-10-08 12:01 - 00000000 ____D C:\Windows\Panther 2013-07-10 12:14 - 2011-04-12 03:39 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-10 12:14 - 2009-07-14 06:52 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-10 12:08 - 2010-11-20 23:01 - 01528948 _____ C:\Windows\system32\PerfStringBackup.INI 2013-07-05 11:44 - 2012-10-08 18:37 - 00000965 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-07-05 11:44 - 2012-10-08 11:36 - 00000000 ____D C:\Program Files\CCleaner 2013-06-27 22:33 - 2013-06-27 22:33 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-06-27 22:33 - 2013-06-26 20:58 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-06-27 22:33 - 2013-06-26 20:58 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-06-27 22:33 - 2013-03-06 16:38 - 00175176 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-06-27 22:33 - 2012-10-08 11:29 - 00369584 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-06-27 22:33 - 2012-10-08 11:27 - 00770344 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-06-11 17:25 ==================== End Of Log ============================ --- --- --- --- --- --- --- --- --- --- --- --- Laptop läuft wieder wie immer,kann keinerlei probleme mehr feststellen. Großes für deine Hilfe. Gruss Speedy |
27.07.2013, 10:57 | #8 |
/// the machine /// TB-Ausbilder | Laptop plötzlich total langsam..Funde durch adwCleaner Fertig Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
27.07.2013, 13:41 | #9 |
| Laptop plötzlich total langsam..Funde durch adwCleaner Hallo Schrauber, ist alles erledigt,und fragen habe ich auch keine mehr. Nochmals danke für deine schnelle Hilfe. Gruss Speedy |
27.07.2013, 17:51 | #10 |
/// the machine /// TB-Ausbilder | Laptop plötzlich total langsam..Funde durch adwCleaner Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Laptop plötzlich total langsam..Funde durch adwCleaner |
administrator, adobe, antivirus, appdatalow, avast, browser, desktop, driver pro, explorer, farbar, farbar recovery scan tool, fehler, festplatte, flash player, google, internet, internet browser, internet explorer, logfile, msiinstaller, plug-in, registrierungsdatenbank, registry, scan, schutz, security, services.exe, software, stick, svchost.exe, usb, windows, winlogon.exe |