|
Plagegeister aller Art und deren Bekämpfung: Nach Virus funktioniert Internet nicht mehr richtigWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
06.08.2013, 10:54 | #1 |
| Nach Virus funktioniert Internet nicht mehr richtig Ahoi! Ich habe seit dem letzten Abend leider folgendes Problem: Ich hatte einen Virus (kann leider nicht sagen welchen, jedoch war bei dem Schwierigkeitsgrad "Hoch" angegeben) und habe ihn mit avast! (free) bekämpft. Nun funktionieren seitdem nur noch die Internetseiten "Facebook" und "Google" bei Chrome und Firefox. Selbst Steam funktioniert nicht richtig: Die Spiele schon, doch der Shop und die jeweilige Werbung in den Servern nicht.. Selbst nach neuem Installieren von Chrome funktioniert es immernoch nicht. Wäre super, wenn mir jemand helfen könnte. Betriebssystem: Windows 8 Geändert von Bathory (06.08.2013 um 11:26 Uhr) |
06.08.2013, 12:29 | #2 |
/// the machine /// TB-Ausbilder | Nach Virus funktioniert Internet nicht mehr richtig hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
06.08.2013, 16:51 | #3 |
| Nach Virus funktioniert Internet nicht mehr richtig FRST
__________________FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-08-2013 Ran by Nano (administrator) on 06-08-2013 17:44:46 Running from F:\ Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\PROGRA~2\AVG\AVG2013\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Spotify Ltd) C:\Users\Nano\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Valve Corporation) C:\Program Files (x86)\Steam\Steam.exe (Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe (Dropbox, Inc.) C:\Users\Nano\AppData\Roaming\Dropbox\bin\Dropbox.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Valve Corporation) C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Spotify Ltd) C:\Users\Nano\AppData\Roaming\Spotify\spotify.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor) HKLM\...\Run: [BtPreLoad] - C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe [65152 2012-08-07] () HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-29] (Synaptics Incorporated) HKLM-x32\...\Runonce: [Del20781579] - cmd.exe /Q /D /c del "C:\Users\Nano\AppData\Local\Temp\0.del" [x] HKCU\...\Run: [Spotify Web Helper] - C:\Users\Nano\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-05] (Spotify Ltd) HKCU\...\Run: [Spotify] - C:\Users\Nano\AppData\Roaming\Spotify\spotify.exe [4640768 2013-07-05] (Spotify Ltd) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1807272 2013-07-27] (Valve Corporation) HKCU\...\Run: [RoboForm] - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [96056 2013-08-05] (Siber Systems) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [CLVirtualDrive] - C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491320 2012-07-26] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [580512 2012-07-09] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2012-06-20] (Nullsoft, Inc.) HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2013\avgui.exe [3147384 2012-12-11] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) Startup: C:\Users\Nano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Nano\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Nano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM13/10 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM13/10 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM13/10 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM13/10 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM13/10 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM13/10 SearchScopes: HKLM - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMNTDFJS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMNTDFJS SearchScopes: HKLM - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKLM - {3D997360-C236-438F-95A0-27066D3656BF} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMNTDFJS SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMNTDFJS SearchScopes: HKLM-x32 - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKLM-x32 - {3D997360-C236-438F-95A0-27066D3656BF} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM-x32 - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMNTDFJS SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMNTDFJS SearchScopes: HKCU - {2fa28606-de77-4029-af96-b231e3b8f827} URL = hxxp://eu.ask.com/web?q={searchterms}&l=dis&o=CMNTDF SearchScopes: HKCU - {3D997360-C236-438F-95A0-27066D3656BF} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKCU - {b7fca997-d0fb-4fe0-8afd-255e89cf9671} URL = hxxp://de.search.yahoo.com/search?p={searchTerms}&ei={inputEncoding}&fr=chr-hp-psg&type=CMNTDF SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: avast! EasyPass Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: avast! EasyPass Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (AVAST Software) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM - avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - avast! EasyPass Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Nano\AppData\Roaming\Mozilla\Firefox\Profiles\mw0q4kht.default FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFFPlgn\ FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Norton Identity Safe) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.0.10_0\npcoplgn.dll (Symantec Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave for Director) - C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) CHR Extension: (Docs) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.0.0.6_0 CHR Extension: (Google Drive) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.2_0 CHR Extension: (YouTube) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0 CHR Extension: (Google Search) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0 CHR Extension: (Norton Identity Protection) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.0.10_0 CHR Extension: (Gmail) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\Exts\Chrome.crx CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211072 2012-08-07] (Qualcomm Atheros Commnucations) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [137960 2013-05-09] (AVAST Software) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [5814904 2012-11-15] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [196664 2012-10-22] (AVG Technologies CZ, s.r.o.) R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation) R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-08-07] (Atheros) ==================== Drivers (Whitelisted) ==================== R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [199008 2012-06-23] (AppEx Networks Corporation) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R1 aswFW; C:\Windows\system32\drivers\aswFW.sys [131232 2013-05-09] (AVAST Software) R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswNdisFlt; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [276992 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-05] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-05] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-08-05] () R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-07-17] (Advanced Micro Devices) S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20912 2012-10-26] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [154464 2012-10-22] (AVG Technologies CZ, s.r.o. ) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [63328 2012-10-15] (AVG Technologies CZ, s.r.o. ) R1 Avgldx64; C:\Windows\system32\DRIVERS\avgldx64.sys [185696 2012-10-02] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [225120 2012-09-21] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [111968 2012-11-15] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40800 2012-09-14] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [208736 2012-11-26] (AVG Technologies CZ, s.r.o.) R3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\BASHDefs\20130502.001\BHDrvx64.sys [1390680 2013-04-13] (Symantec Corporation) R3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\BASHDefs\20130502.001\BHDrvx64.sys [1390680 2013-04-13] (Symantec Corporation) R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-08-07] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-17] (Symantec Corporation) R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-17] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-03-17] (Symantec Corporation) R3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\IPSDefs\20130515.001\IDSvia64.sys [513184 2013-03-13] (Symantec Corporation) R3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\IPSDefs\20130515.001\IDSvia64.sys [513184 2013-03-13] (Symantec Corporation) S3 lehidmini; C:\Windows\System32\drivers\leath_hid.sys [39704 2012-08-07] (Atheros) S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20130516.003\ENG64.SYS [126192 2013-03-17] (Symantec Corporation) S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20130516.003\ENG64.SYS [126192 2013-03-17] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20130516.003\EX64.SYS [2087664 2013-03-17] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20130516.003\EX64.SYS [2087664 2013-03-17] (Symantec Corporation) R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-29] (Synaptics Incorporated) S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-29] (Synaptics Incorporated) S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation) R3 SRTSPX; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation) R3 SymDS; C:\Windows\system32\drivers\NISx64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation) R3 SymEFA; C:\Windows\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation) S4 SymELAM; C:\Windows\system32\drivers\NISx64\1404000.028\SymELAM.sys [23448 2012-06-20] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-19] (Symantec Corporation) R3 SymIRON; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation) R3 SymNetS; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20288 2012-08-03] (Hewlett-Packard Development Company, L.P.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-06 17:30 - 2013-08-06 17:30 - 00002638 _____ C:\Windows\System32\Tasks\DigitalSite 2013-08-06 17:30 - 2013-08-06 17:30 - 00000300 _____ C:\Windows\Tasks\DigitalSite.job 2013-08-06 17:30 - 2013-08-06 17:30 - 00000000 ____D C:\Users\Nano\AppData\Roaming\DigitalSite 2013-08-06 11:47 - 2013-08-06 11:47 - 00000000 ___RD C:\Users\Nano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-08-06 11:41 - 2013-08-06 11:41 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-06 11:41 - 2013-08-06 11:41 - 00000000 ____D C:\Users\Nano\AppData\Roaming\Mozilla 2013-08-06 11:41 - 2013-08-06 11:41 - 00000000 ____D C:\Users\Nano\AppData\Local\Mozilla 2013-08-06 11:40 - 2013-08-06 11:40 - 00000000 ____D C:\ProgramData\Mozilla 2013-08-06 11:40 - 2013-08-06 11:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-06 11:40 - 2013-08-06 11:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-06 11:37 - 2013-08-06 11:38 - 22268584 _____ (Mozilla) C:\Users\Nano\Downloads\Firefox_Setup_23.0.exe 2013-08-06 11:33 - 2013-08-06 11:33 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-06 11:32 - 2013-08-06 17:37 - 00000906 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-06 11:32 - 2013-08-06 11:45 - 00000902 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-06 11:32 - 2013-08-06 11:32 - 00003878 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-06 11:32 - 2013-08-06 11:32 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-06 11:26 - 2013-08-06 11:27 - 34992280 _____ (Google Inc.) C:\Users\Nano\Downloads\ChromeStandaloneSetup_28.0b1500.95.exe 2013-08-06 00:24 - 2013-05-09 10:59 - 00131232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFW.sys 2013-08-06 00:23 - 2013-05-09 10:59 - 00276992 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys 2013-08-06 00:23 - 2013-05-09 10:59 - 00022600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2013-08-06 00:20 - 2013-08-06 00:20 - 00001922 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk 2013-08-05 22:46 - 2013-08-05 22:46 - 00000000 ___RD C:\Users\Nano\Documents\Notes 2013-08-05 20:23 - 2013-08-05 20:23 - 00003484 _____ C:\Windows\System32\Tasks\Run RoboForm TaskBar Icon 2013-08-05 20:23 - 2013-08-05 20:23 - 00000000 ____D C:\Users\Nano\AppData\Roaming\RoboForm 2013-08-05 20:21 - 2013-08-05 20:21 - 00000000 ____D C:\ProgramData\RoboForm 2013-08-05 20:20 - 2013-08-05 20:20 - 00000000 ____D C:\Users\Nano\Documents\My Avast EasyPass Data 2013-08-05 20:20 - 2013-08-05 20:20 - 00000000 ____D C:\Program Files (x86)\Siber Systems 2013-08-05 20:17 - 2013-08-05 20:16 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-08-05 20:16 - 2013-08-06 17:15 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-08-05 20:16 - 2013-08-06 00:23 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-08-05 20:16 - 2013-08-05 20:16 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-05 20:16 - 2013-08-05 20:16 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-05 20:16 - 2013-08-05 20:16 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-05 20:16 - 2013-08-05 20:16 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-08-05 20:16 - 2013-08-05 20:16 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-08-05 20:16 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-08-05 20:16 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-08-05 20:16 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-08-05 20:16 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-08-05 20:16 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-08-05 20:16 - 2013-05-09 10:58 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-08-05 20:14 - 2013-08-05 20:14 - 00000000 ____D C:\Program Files\AVAST Software 2013-08-05 20:14 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-08-05 20:12 - 2013-08-05 20:14 - 00000000 ____D C:\ProgramData\AVAST Software 2013-08-05 20:00 - 2013-08-05 20:00 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\ATI 2013-08-05 20:00 - 2013-08-05 20:00 - 00000000 ____D C:\Users\Jinan\AppData\Local\ATI 2013-08-05 20:00 - 2013-08-05 20:00 - 00000000 ____D C:\Users\Jinan\AppData\Local\AMD 2013-08-05 19:59 - 2013-08-05 19:59 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\Synaptics 2013-08-05 19:59 - 2013-08-05 19:59 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\AVG2013 2013-08-05 19:59 - 2013-08-05 19:59 - 00000000 ____D C:\Users\Jinan\AppData\Local\Avg2013 2013-08-05 19:58 - 2013-08-05 19:58 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\Adobe 2013-08-05 19:57 - 2013-08-05 19:57 - 00000000 ____D C:\Users\Jinan\AppData\Local\VirtualStore 2013-08-05 19:48 - 2013-08-05 19:53 - 117478104 _____ C:\Users\Nano\Downloads\avast_free_antivirus_setup_8.0.1489.300.exe 2013-07-22 03:27 - 2013-06-01 13:54 - 00194816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2013-07-22 03:27 - 2013-06-01 13:54 - 00125184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2013-07-22 03:27 - 2013-06-01 13:34 - 02391280 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-07-22 03:27 - 2013-06-01 13:33 - 02233600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-22 03:27 - 2013-06-01 13:29 - 00337152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2013-07-22 03:27 - 2013-06-01 13:29 - 00213248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS 2013-07-22 03:27 - 2013-06-01 13:26 - 06987008 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-07-22 03:27 - 2013-06-01 13:26 - 00327936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2013-07-22 03:27 - 2013-06-01 12:24 - 02106176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2013-07-22 03:27 - 2013-06-01 11:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-07-22 03:27 - 2013-06-01 11:25 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2013-07-22 03:27 - 2013-06-01 11:24 - 01453568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2013-07-22 03:27 - 2013-06-01 11:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll 2013-07-22 03:27 - 2013-06-01 11:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2013-07-22 03:27 - 2013-06-01 11:23 - 01842176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2013-07-22 03:27 - 2013-06-01 11:23 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe 2013-07-22 03:27 - 2013-06-01 11:22 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-22 03:27 - 2013-06-01 11:22 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-07-22 03:27 - 2013-06-01 11:22 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll 2013-07-22 03:27 - 2013-06-01 11:22 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe 2013-07-22 03:27 - 2013-06-01 11:21 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2013-07-22 03:27 - 2013-06-01 11:21 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2013-07-22 03:27 - 2013-06-01 11:20 - 02219520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2013-07-22 03:27 - 2013-06-01 11:20 - 01527808 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2013-07-22 03:27 - 2013-06-01 11:20 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll 2013-07-22 03:27 - 2013-06-01 11:20 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2013-07-22 03:27 - 2013-06-01 11:19 - 00785408 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2013-07-22 03:27 - 2013-06-01 11:19 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll 2013-07-22 03:27 - 2013-06-01 05:08 - 00037632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthAvrcpTg.sys 2013-07-22 03:27 - 2013-05-25 00:09 - 01403296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2013-07-22 03:27 - 2013-05-25 00:09 - 01271584 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-07-22 03:27 - 2013-05-25 00:09 - 01217352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2013-07-22 03:27 - 2013-05-25 00:09 - 01093904 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-07-22 03:27 - 2013-05-20 02:08 - 00386642 _____ C:\Windows\system32\ApnDatabase.xml 2013-07-20 19:25 - 2013-06-17 00:41 - 00997632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-07-20 00:58 - 2013-07-20 00:58 - 00307904 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-19 23:39 - 2013-04-12 00:30 - 01421312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-19 23:39 - 2013-04-12 00:22 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-19 23:38 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-19 23:38 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-19 23:38 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-19 23:38 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-19 23:38 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-19 23:38 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-19 23:38 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-19 23:38 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-19 23:38 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-19 23:38 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-19 23:38 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-19 23:38 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-19 23:38 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-19 23:38 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-19 23:38 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-19 23:38 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-19 23:38 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-19 23:30 - 2013-05-31 01:14 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-19 23:24 - 2013-06-01 11:25 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-19 23:24 - 2013-06-01 11:21 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-19 23:09 - 2013-05-04 08:59 - 02842112 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-19 23:09 - 2013-05-04 06:57 - 02620928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-19 23:00 - 2013-05-16 00:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll 2013-07-18 18:51 - 2013-07-18 18:52 - 00383040 _____ C:\Windows\Minidump\071813-99279-01.dmp 2013-07-16 09:53 - 2013-07-16 09:53 - 00382872 _____ C:\Windows\Minidump\071613-44616-01.dmp 2013-07-10 10:42 - 2013-07-10 10:42 - 00383336 _____ C:\Windows\Minidump\071013-80387-01.dmp 127 ==================== One Month Modified Files and Folders ======= 2013-08-06 17:42 - 2013-04-06 21:57 - 00000000 ____D C:\Users\Nano\AppData\Roaming\Spotify 2013-08-06 17:37 - 2013-08-06 17:37 - 00000000 ____D C:\FRST 2013-08-06 17:37 - 2013-08-06 11:32 - 00000906 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-06 17:33 - 2013-03-17 11:56 - 01229005 _____ C:\Windows\WindowsUpdate.log 2013-08-06 17:30 - 2013-08-06 17:30 - 00002638 _____ C:\Windows\System32\Tasks\DigitalSite 2013-08-06 17:30 - 2013-08-06 17:30 - 00000300 _____ C:\Windows\Tasks\DigitalSite.job 2013-08-06 17:30 - 2013-08-06 17:30 - 00000000 ____D C:\Users\Nano\AppData\Roaming\DigitalSite 2013-08-06 17:18 - 2013-06-11 15:49 - 00000000 ____D C:\ProgramData\MFAData 2013-08-06 17:15 - 2013-08-05 20:16 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-08-06 17:13 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-08-06 11:55 - 2013-03-17 12:08 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1458673497-1914164762-889707888-1003 2013-08-06 11:48 - 2013-05-28 16:59 - 00000000 ___RD C:\Users\Nano\Dropbox 2013-08-06 11:48 - 2013-05-28 16:51 - 00000000 ____D C:\Users\Nano\AppData\Roaming\Dropbox 2013-08-06 11:47 - 2013-08-06 11:47 - 00000000 ___RD C:\Users\Nano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-08-06 11:47 - 2013-06-24 01:27 - 00000000 ____D C:\Program Files (x86)\Steam 2013-08-06 11:45 - 2013-08-06 11:32 - 00000902 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-06 11:44 - 2012-08-04 00:23 - 00020688 _____ C:\Windows\PFRO.log 2013-08-06 11:44 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-06 11:41 - 2013-08-06 11:41 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-06 11:41 - 2013-08-06 11:41 - 00000000 ____D C:\Users\Nano\AppData\Roaming\Mozilla 2013-08-06 11:41 - 2013-08-06 11:41 - 00000000 ____D C:\Users\Nano\AppData\Local\Mozilla 2013-08-06 11:40 - 2013-08-06 11:40 - 00000000 ____D C:\ProgramData\Mozilla 2013-08-06 11:40 - 2013-08-06 11:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-06 11:40 - 2013-08-06 11:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-06 11:38 - 2013-08-06 11:37 - 22268584 _____ (Mozilla) C:\Users\Nano\Downloads\Firefox_Setup_23.0.exe 2013-08-06 11:34 - 2012-08-17 21:13 - 00830120 _____ C:\Windows\system32\perfh007.dat 2013-08-06 11:34 - 2012-08-17 21:13 - 00188224 _____ C:\Windows\system32\perfc007.dat 2013-08-06 11:34 - 2012-07-26 09:28 - 01949368 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-06 11:33 - 2013-08-06 11:33 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-06 11:32 - 2013-08-06 11:32 - 00003878 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-06 11:32 - 2013-08-06 11:32 - 00003642 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-06 11:32 - 2013-03-17 12:07 - 00000000 ____D C:\Program Files (x86)\Google 2013-08-06 11:30 - 2013-03-29 10:44 - 00439296 ___SH C:\Users\Nano\Downloads\Thumbs.db 2013-08-06 11:27 - 2013-08-06 11:26 - 34992280 _____ (Google Inc.) C:\Users\Nano\Downloads\ChromeStandaloneSetup_28.0b1500.95.exe 2013-08-06 11:19 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\NDF 2013-08-06 10:12 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-08-06 00:23 - 2013-08-05 20:16 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-08-06 00:20 - 2013-08-06 00:20 - 00001922 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk 2013-08-06 00:00 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI 2013-08-05 23:46 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\ELAM 2013-08-05 22:46 - 2013-08-05 22:46 - 00000000 ___RD C:\Users\Nano\Documents\Notes 2013-08-05 20:23 - 2013-08-05 20:23 - 00003484 _____ C:\Windows\System32\Tasks\Run RoboForm TaskBar Icon 2013-08-05 20:23 - 2013-08-05 20:23 - 00000000 ____D C:\Users\Nano\AppData\Roaming\RoboForm 2013-08-05 20:21 - 2013-08-05 20:21 - 00000000 ____D C:\ProgramData\RoboForm 2013-08-05 20:20 - 2013-08-05 20:20 - 00000000 ____D C:\Users\Nano\Documents\My Avast EasyPass Data 2013-08-05 20:20 - 2013-08-05 20:20 - 00000000 ____D C:\Program Files (x86)\Siber Systems 2013-08-05 20:16 - 2013-08-05 20:17 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-08-05 20:16 - 2013-08-05 20:16 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-05 20:16 - 2013-08-05 20:16 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-05 20:16 - 2013-08-05 20:16 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-05 20:16 - 2013-08-05 20:16 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-08-05 20:16 - 2013-08-05 20:16 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-08-05 20:14 - 2013-08-05 20:14 - 00000000 ____D C:\Program Files\AVAST Software 2013-08-05 20:14 - 2013-08-05 20:12 - 00000000 ____D C:\ProgramData\AVAST Software 2013-08-05 20:09 - 2013-03-17 12:02 - 00000000 ____D C:\Users\Nano\Documents\Bluetooth Folder 2013-08-05 20:00 - 2013-08-05 20:00 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\ATI 2013-08-05 20:00 - 2013-08-05 20:00 - 00000000 ____D C:\Users\Jinan\AppData\Local\ATI 2013-08-05 20:00 - 2013-08-05 20:00 - 00000000 ____D C:\Users\Jinan\AppData\Local\AMD 2013-08-05 19:59 - 2013-08-05 19:59 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\Synaptics 2013-08-05 19:59 - 2013-08-05 19:59 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\AVG2013 2013-08-05 19:59 - 2013-08-05 19:59 - 00000000 ____D C:\Users\Jinan\AppData\Local\Avg2013 2013-08-05 19:58 - 2013-08-05 19:58 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\Adobe 2013-08-05 19:58 - 2013-06-30 17:13 - 00000000 ____D C:\Users\Jinan\AppData\Local\Packages 2013-08-05 19:58 - 2013-03-17 12:01 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-08-05 19:58 - 2013-03-17 11:51 - 00000000 ____D C:\Users\Jinan 2013-08-05 19:57 - 2013-08-05 19:57 - 00000000 ____D C:\Users\Jinan\AppData\Local\VirtualStore 2013-08-05 19:53 - 2013-08-05 19:48 - 117478104 _____ C:\Users\Nano\Downloads\avast_free_antivirus_setup_8.0.1489.300.exe 2013-08-05 14:40 - 2013-04-06 21:58 - 00000000 ____D C:\Users\Nano\AppData\Local\Spotify 2013-08-02 01:21 - 2013-05-05 22:40 - 00101376 ___SH C:\Users\Nano\Desktop\Thumbs.db 2013-07-25 23:53 - 2013-06-24 23:21 - 00014336 ___SH C:\Users\Nano\Documents\Thumbs.db 2013-07-24 12:10 - 2013-03-30 10:01 - 00000000 ____D C:\Users\Nano\Documents\Major 2013-07-20 19:01 - 2013-03-18 18:07 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-07-20 00:58 - 2013-07-20 00:58 - 00307904 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-20 00:56 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing 2013-07-20 00:52 - 2012-07-26 09:52 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-20 00:51 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe 2013-07-18 18:52 - 2013-07-18 18:51 - 00383040 _____ C:\Windows\Minidump\071813-99279-01.dmp 2013-07-18 18:51 - 2013-06-13 16:00 - 00000000 ____D C:\Windows\Minidump 2013-07-18 18:51 - 2013-06-13 15:59 - 430290099 _____ C:\Windows\MEMORY.DMP 2013-07-16 09:53 - 2013-07-16 09:53 - 00382872 _____ C:\Windows\Minidump\071613-44616-01.dmp 2013-07-10 19:45 - 2013-04-13 21:51 - 00000000 ____D C:\Users\Nano\AppData\Roaming\vlc 2013-07-10 10:42 - 2013-07-10 10:42 - 00383336 _____ C:\Windows\Minidump\071013-80387-01.dmp ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-31 11:45 ==================== End Of Log ============================ --- --- --- Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 05-08-2013 Ran by Nano at 2013-08-06 17:46:40 Running from F:\ Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= 2013 (Version: 2013.0.2904) Adobe AIR (x32 Version: 3.7.0.1860) Adobe Shockwave Player 11.6 (x32 Version: 11.6.4.634) AMD APP SDK Runtime (Version: 10.0.938.2) AMD Catalyst Install Manager (Version: 8.0.881.0) AMD Fuel (Version: 2012.0806.1156.19437) AMD Quick Stream (Version: 3.3.26.0) AMD VISION Engine Control Center (x32 Version: 2012.0806.1156.19437) avast! EasyPass (x32 Version: 7-7-8-128) avast! Internet Security (x32 Version: 8.0.1489.0) AVG 2013 (Version: 13.0.2904) AVG 2013 (Version: 13.0.3209) Batch PDF Merger (x32 Version: 2.6) Bonjour (Version: 3.0.0.10) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.0806.1156.19437) Catalyst Control Center InstallProxy (x32 Version: 2012.0806.1156.19437) Catalyst Control Center Localization All (x32 Version: 2012.0806.1156.19437) CCC Help Chinese Standard (x32 Version: 2012.0806.1155.19437) CCC Help Chinese Traditional (x32 Version: 2012.0806.1155.19437) CCC Help Czech (x32 Version: 2012.0806.1155.19437) CCC Help Danish (x32 Version: 2012.0806.1155.19437) CCC Help Dutch (x32 Version: 2012.0806.1155.19437) CCC Help English (x32 Version: 2012.0806.1155.19437) CCC Help Finnish (x32 Version: 2012.0806.1155.19437) CCC Help French (x32 Version: 2012.0806.1155.19437) CCC Help German (x32 Version: 2012.0806.1155.19437) CCC Help Greek (x32 Version: 2012.0806.1155.19437) CCC Help Hungarian (x32 Version: 2012.0806.1155.19437) CCC Help Italian (x32 Version: 2012.0806.1155.19437) CCC Help Japanese (x32 Version: 2012.0806.1155.19437) CCC Help Korean (x32 Version: 2012.0806.1155.19437) CCC Help Norwegian (x32 Version: 2012.0806.1155.19437) CCC Help Polish (x32 Version: 2012.0806.1155.19437) CCC Help Portuguese (x32 Version: 2012.0806.1155.19437) CCC Help Russian (x32 Version: 2012.0806.1155.19437) CCC Help Spanish (x32 Version: 2012.0806.1155.19437) CCC Help Swedish (x32 Version: 2012.0806.1155.19437) CCC Help Thai (x32 Version: 2012.0806.1155.19437) CCC Help Turkish (x32 Version: 2012.0806.1155.19437) ccc-utility64 (Version: 2012.0806.1156.19437) continuetosave (x32 Version: ) Counter-Strike (x32) CyberLink LabelPrint (x32 Version: 2.5.1.5407) CyberLink Media Suite 10 (x32 Version: 10.0.1.1916) CyberLink Power2Go 8 (x32 Version: 8.0.1.1926) CyberLink PowerDVD (x32 Version: 10.0.6.4319) CyberLink YouCam (x32 Version: 3.5.4.5527) D3DX10 (x32 Version: 15.4.2368.0902) Day of Defeat (x32) Die Sims™ 3 (x32 Version: 1.50.56) Die Sims™ 3 Traumkarrieren (x32 Version: 4.10.1) Dropbox (HKCU Version: 2.0.22) Energy Star (Version: 1.0.8) Google Chrome (x32 Version: 28.0.1500.95) Google Update Helper (x32 Version: 1.3.21.115) Hewlett-Packard ACLM.NET v1.2.0.0 (x32 Version: 1.00.0000) HP Customer Experience Enhancements (x32 Version: 6.0.1.7) HP Documentation (x32 Version: 1.1.0.0) HP Postscript Converter (Version: 3.1.3554) HP Quick Launch (x32 Version: 3.0.3) HP Recovery Manager (x32 Version: 7.00) HP Registration Service (Version: 1.0.5976.4186) HP Software Framework (x32 Version: 4.6.8.1) HP Support Assistant (x32 Version: 7.0.32.44) HP Utility Center (x32 Version: 1.0.7) HP Wireless Button Driver (x32 Version: 1.0.5.1) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office (x32 Version: 14.0.6120.5004) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.56336) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.59193) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Microsoft WSE 3.0 Runtime (x32 Version: 3.0.5305.0) Mozilla Firefox 23.0 (x86 de) (x32 Version: 23.0) Mozilla Maintenance Service (x32 Version: 23.0) MSVCRT (x32 Version: 15.4.2862.0708) Norton Internet Security (x32 Version: 20.4.0.40) OpenOffice.org 3.4.1 (x32 Version: 3.41.9593) Origin (x32 Version: 9.1.13.85) PDFCreator (x32 Version: 1.7.0) PeaZip 4.9 (x32) Qualcomm Atheros Bluetooth Suite (64) (Version: 8.0.0.206) Qualcomm Atheros Driver Installation Program (x32 Version: 10.0) Realtek Ethernet Controller Driver (x32 Version: 8.2.612.2012) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6662) Realtek PCIE Card Reader (x32 Version: 6.2.8400.29029) Spotify (HKCU Version: 0.9.1.57.ge7405149) Star Wars: The Old Republic (x32 Version: 1.00) Steam (x32 Version: 1.0.0.0) swMSM (x32 Version: 12.0.0.1) Synaptics Pointing Device Driver (Version: 16.2.10.12) Update for Zip Opener (HKCU) Visual Studio 2010 x64 Redistributables (Version: 13.0.0.1) VLC media player 2.0.6 (x32 Version: 2.0.6) Winamp (x32 Version: 5.63 ) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3555.0308) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3555.0308) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) ==================== Restore Points ========================= 19-07-2013 21:51:52 Windows Update 27-07-2013 14:47:22 Installiert The Sims 3 05-08-2013 13:52:01 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2012-07-26 07:26 - 2012-07-26 07:26 - 00000824 ____N C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {02E57BDD-784E-4E1D-A0FE-4364FB1610B0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-06] (Google Inc.) Task: {10D85952-E3F6-47A1-96CF-5E1C2D874EA6} - System32\Tasks\Microsoft\Windows\SystemRestore\SR => C:\Windows\system32\srtasks.exe [2012-07-26] (Microsoft Corporation) Task: {10F1DA31-582A-4E33-9011-2DF2F3E16B40} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {13A2AC02-B682-48CC-9155-2E2673580117} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Critical Task: {15F83FEE-D861-4C77-8046-E2F6719C8AC2} - System32\Tasks\WPD\SqmUpload_S-1-5-21-1458673497-1914164762-889707888-1003 => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {17644F17-DC4C-4AC8-9444-7AAA52EB5CDC} - System32\Tasks\Microsoft\Windows\NetCfg\BindingWorkItemQueueHandler Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {1DB7C2F1-876C-4F24-AD17-8428211113F9} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\ProcessMemoryDiagnosticEvents Task: {214B24F4-FEB4-4C59-AF1F-70136065199C} - System32\Tasks\Microsoft\Windows\Shell\IndexerAutomaticMaintenance Task: {23700E5C-0E77-499D-908A-415D5C6252F4} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Group Policy Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {2C6B9EA8-7F5A-4ABA-BF96-8D352D02A743} - System32\Tasks\Microsoft\Windows\Device Setup\Metadata Refresh Task: {2C792D01-90C7-45E0-B149-6C21EDCED361} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\WSCStub.exe [2013-06-04] (Symantec Corporation) Task: {2C939698-A8C0-44FC-9B91-6FE86C6C3599} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\SymErr.exe [2013-06-04] (Symantec Corporation) Task: {2E030FA7-3D7C-4E1D-8CFE-56ADB26FD402} - System32\Tasks\Microsoft\Windows\PI\Sqm-Tasks Task: {3054485A-F517-4E95-9977-4DD827B1E9B3} - System32\Tasks\Microsoft\Windows\WS\Badge Update Task: {30BB9C70-8610-4AFC-AC7F-364EB94DB5D8} - System32\Tasks\Run RoboForm TaskBar Icon => C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [2013-08-05] (Siber Systems) Task: {37414BAA-C650-4B39-8802-5FEDC5B403FF} - System32\Tasks\MirageAgent => C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe [2012-07-27] (CyberLink) Task: {378401BA-A703-444A-A79C-3C47AD2DC5B6} - System32\Tasks\Microsoft\Windows\TaskScheduler\Maintenance Configurator Task: {39C93026-D0E7-4198-81F4-4A4794F0F676} - System32\Tasks\WPD\SqmUpload_S-1-5-21-1458673497-1914164762-889707888-1002 => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {3AE164E7-30CD-40BC-9422-3EC7A5618965} - System32\Tasks\Microsoft\Windows\WS\WSTask Task: {3C490ABD-D849-41AF-9AC4-87DD759B0996} - System32\Tasks\Microsoft\Windows\Power Efficiency Diagnostics\AnalyzeSystem Task: {3DACA30C-4C90-4747-99E6-D7DDF6683695} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task Task: {4073C1B3-6E16-4AA8-B7F3-C6A6D35D5071} - System32\Tasks\Microsoft\Windows\TPM\Tpm-Maintenance Task: {44B3F1B8-5943-4072-8D8C-A9484676AC44} - System32\Tasks\Microsoft\Windows\Live\Roaming\SynchronizeWithStorage Task: {4810B636-6906-469C-8224-FF4235C4B241} - System32\Tasks\Hewlett-Packard\HP Support Assistant\HP Support Assistant Quick Start => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-08-10] (Hewlett-Packard Company) Task: {483A8F5C-5D26-44B5-B49E-AF6741D1BBEB} - System32\Tasks\Microsoft\Windows\Mobile Broadband Accounts\MNO Metadata Parser => C:\Windows\System32\MbaeParserTask.exe [2013-06-01] (Microsoft Corporation) Task: {4B7C8354-7A5D-4BAF-B2DF-1F08F648E533} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1458673497-1914164762-889707888-1003 Task: {4B952129-9AE9-41A3-BE2B-8AD2E06F66B6} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskLogon Task: {529026E0-F302-4850-9E96-57D2D4FA1081} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-05-09] (AVAST Software) Task: {5755E746-D7ED-4C20-A472-66C11834CDE4} - System32\Tasks\Microsoft\Windows\TaskScheduler\Manual Maintenance Task: {586F2F11-4409-4B01-BAF3-426F6014C8B5} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUScheduledInstall Task: {59DBEFBC-8261-482B-B9D3-59709A1AFC5F} - System32\Tasks\Hewlett-Packard\HP Support Assistant\Update Check => C:\ProgramData\Hewlett-Packard\HP Support Framework\Resources\Updater7\HPSFUpdater.exe [2012-08-07] (Hewlett-Packard Company) Task: {5C4EFB77-EFA6-45DF-A373-D795C0725BFF} - System32\Tasks\Microsoft\Windows\Plug and Play\Device Install Reboot Required Task: {60B99EA7-CBFC-4EE5-9402-1879C1F44DAE} - System32\Tasks\Hewlett-Packard\HP Support Assistant\PC Health Analysis => C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe [2012-08-10] (Hewlett-Packard Company) Task: {627441F3-8526-4B62-BF9A-1A3EA414E71A} - System32\Tasks\Microsoft\Windows\SpacePort\SpaceAgentTask => C:\Windows\system32\SpaceAgent.exe [2012-07-26] (Microsoft Corporation) Task: {6AC85F5A-090D-4D1A-8A86-39974A1A296B} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-06] (Google Inc.) Task: {6E9DE125-5583-4031-B572-FEE48F25CFFF} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyMonitor => C:\Windows\System32\wpcmon.exe [2012-09-20] (Microsoft Corporation) Task: {6FDDEA7C-6310-428D-AEB2-54FFC72811EF} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Task: {704E08FD-CB67-4695-8668-7F27C83ECE09} - System32\Tasks\Microsoft\Windows\Servicing\StartComponentCleanup Task: {74096F94-B654-4DB0-96F5-3C3408B92FE3} - System32\Tasks\Microsoft\Windows\PI\Secure-Boot-Update Task: {7D9A9A1C-499C-40A6-8F8A-5BCC4CC9A87C} - System32\Tasks\Microsoft\Windows\TaskScheduler\Regular Maintenance Task: {845CB020-68B5-4C6B-9876-7BEC7B3E27AC} - System32\Tasks\Microsoft\Windows\TaskScheduler\Idle Maintenance Task: {87354DAA-66DF-4B41-9346-15958D96E1D2} - System32\Tasks\Microsoft\Windows\FileHistory\File History (maintenance mode) Task: {8C36624A-9035-4702-9637-BE2964052151} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUFirmwareInstall Task: {921A1D4E-32FB-46D7-B6C0-6F467884074D} - System32\Tasks\Microsoft\Windows\WS\Sync Licenses Task: {9372E794-6243-4507-B98E-E0D1C306CBF8} - System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1458673497-1914164762-889707888-500 Task: {9479EF8E-11D4-41B3-9783-CC65070D592D} - System32\Tasks\Microsoft\Windows\Time Synchronization\ForceSynchronizeTime Task: {94DCF254-64FB-4C4E-8E12-5F4055C10C2A} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 64 Task: {989A7C6D-BE82-4C3C-AF96-6116039E336B} - System32\Tasks\Microsoft\Windows\MemoryDiagnostic\RunFullMemoryDiagnostic Task: {9C0F1C57-10C0-431B-B7F7-88D7F49CE666} - System32\Tasks\Microsoft\Windows\WindowsUpdate\AUSessionConnect Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => C:\Windows\System32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {A800277E-E202-4492-AD38-3312641CBC04} - System32\Tasks\Microsoft\Windows\Live\Roaming\MaintenanceTask Task: {AB62FA47-2C99-44B1-A5D0-D4161423BE43} - System32\Tasks\Microsoft\Windows\Shell\FamilySafetyRefresh Task: {AC6259DE-AC59-459E-849E-6ADFFD1ADE63} - System32\Tasks\Microsoft\Windows\Shell\CreateObjectTask Task: {AEB0B5BD-B9E5-458A-898A-E559BD9EB51B} - System32\Tasks\Microsoft\Windows\SettingSync\BackgroundUploadTask Task: {AF549BD8-337C-4BF7-8681-36A182E30507} - System32\Tasks\Microsoft\Windows\Chkdsk\ProactiveScan Task: {BC76AEF7-2CF0-4EB6-B65B-A8803E0B5E12} - System32\Tasks\Microsoft\Windows\AppID\SmartScreenSpecific Task: {BF0C796B-6ED7-48BB-A0E2-4246F3503EBF} - System32\Tasks\DigitalSite => C:\Users\Nano\AppData\Roaming\DIGITA~1\UPDATE~1\UPDATE~1.EXE [2013-04-12] () Task: {C1ACCD1E-4385-4FB2-B5E4-7F2A57A626A2} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan Task: {C463FD1E-31C7-4C20-AB65-08E514CA152D} - System32\Tasks\Microsoft\Windows\IME\SQM data sender Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {CD1054FF-8005-4904-8B9C-436EAB1E2021} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTaskNetwork Task: {DBCF6E1B-CE0A-441E-B7A5-219C8BE50C65} - System32\Tasks\Microsoft\Windows\.NET Framework\.NET Framework NGEN v4.0.30319 Critical Task: {DECE5921-598D-454B-9A04-B2DE95EFC1B3} - System32\Tasks\Microsoft\Windows\Data Integrity Scan\Data Integrity Scan for Crash Recovery Task: {E4DFE66F-E089-4CC3-A70F-957223D565F4} - System32\Tasks\Microsoft\Windows\SoftwareProtectionPlatform\SvcRestartTask Task: {E8DAA09B-DF2A-4951-9134-6FA9587793F9} - System32\Tasks\Microsoft\Windows\Plug and Play\Sysprep Generalize Drivers => C:\Windows\System32\drvinst.exe [2012-09-20] (Microsoft Corporation) Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => C:\Windows\system32\rundll32.exe [2012-07-26] (Microsoft Corporation) Task: {ED0C1F69-C3A2-41EA-B8C3-3F0D83A1F6C0} - System32\Tasks\Microsoft\Windows\Customer Experience Improvement Program\BthSQM Task: {F861902D-D3BF-45EA-8CEE-D727B42FD054} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start => C:\Windows\system32\sc.exe [2012-07-26] (Microsoft Corporation) Task: {FE616BCE-9726-49F4-9157-DF98446584EC} - System32\Tasks\CLMLSvc_P2G8 => C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe [2012-06-08] (CyberLink) Task: C:\Windows\Tasks\DigitalSite.job => ? Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/06/2013 10:57:01 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2496 Error: (08/06/2013 10:57:01 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2496 Error: (08/06/2013 10:57:01 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/06/2013 07:52:54 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15568 Error: (08/06/2013 07:52:54 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15568 Error: (08/06/2013 07:52:54 AM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/06/2013 00:12:13 AM) (Source: Application Hang) (User: ) Description: Programm AvastUI.exe, Version 8.0.1489.300 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1420 Startzeit: 01ce92278139640e Endzeit: 60000 Anwendungspfad: C:\Program Files\AVAST Software\Avast\AvastUI.exe Berichts-ID: e85121c6-fe1b-11e2-be99-20689d21637b Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (08/05/2013 11:10:44 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80070005 Error: (08/05/2013 10:42:25 PM) (Source: Application Hang) (User: ) Description: Programm taskmgr.exe, Version 6.2.9200.16465 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 37c8 Startzeit: 01ce921baa17f68f Endzeit: 31 Anwendungspfad: C:\Windows\system32\taskmgr.exe Berichts-ID: 7fa88b95-fe0f-11e2-be97-20689d21637b Vollständiger Name des fehlerhaften Pakets: Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Error: (08/05/2013 08:41:18 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 150307 System errors: ============= Error: (08/06/2013 11:47:21 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1070 Error: (08/06/2013 11:47:21 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde nicht richtig gestartet. Error: (08/06/2013 11:45:59 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuche-Ressourcenveröffentlichung" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1070 Error: (08/06/2013 11:45:59 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SSDP-Suche" wurde nicht richtig gestartet. Error: (08/06/2013 11:45:48 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Funktionssuche-Ressourcenveröffentlichung" wurde nicht richtig gestartet. Error: (08/06/2013 11:44:50 AM) (Source: Service Control Manager) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen: %%5 Error: (08/06/2013 11:44:50 AM) (Source: Service Control Manager) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen: %%5 Error: (08/06/2013 11:44:04 AM) (Source: Microsoft-Windows-Kernel-General) (User: NT-AUTORITÄT) Description: 0xc000014d0 Error: (08/06/2013 11:43:15 AM) (Source: Service Control Manager) (User: ) Description: Der Aufruf "ScRegSetValueExW" ist für "FailureActions" aufgrund folgenden Fehlers fehlgeschlagen: %%5 Error: (08/06/2013 00:27:07 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst AtherosSvc erreicht. Microsoft Office Sessions: ========================= Error: (08/06/2013 10:57:01 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 2496 Error: (08/06/2013 10:57:01 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 2496 Error: (08/06/2013 10:57:01 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/06/2013 07:52:54 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 15568 Error: (08/06/2013 07:52:54 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 15568 Error: (08/06/2013 07:52:54 AM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (08/06/2013 00:12:13 AM) (Source: Application Hang)(User: ) Description: AvastUI.exe8.0.1489.300142001ce92278139640e60000C:\Program Files\AVAST Software\Avast\AvastUI.exee85121c6-fe1b-11e2-be99-20689d21637b Error: (08/05/2013 11:10:44 PM) (Source: Customer Experience Improvement Program)(User: ) Description: 80070005 Error: (08/05/2013 10:42:25 PM) (Source: Application Hang)(User: ) Description: taskmgr.exe6.2.9200.1646537c801ce921baa17f68f31C:\Windows\system32\taskmgr.exe7fa88b95-fe0f-11e2-be97-20689d21637b Error: (08/05/2013 08:41:18 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 150307 ==================== Memory info =========================== Percentage of memory in use: 42% Total physical RAM: 3674.25 MB Available physical RAM: 2126.78 MB Total Pagefile: 7386.25 MB Available Pagefile: 5353.96 MB Total Virtual: 8192 MB Available Virtual: 8191.77 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:450.71 GB) (Free:340.22 GB) NTFS (Disk=0 Partition=4) ==>[System with boot components (obtained from reading drive)] Drive d: (RECOVERY) (Fixed) (Total:14.29 GB) (Free:1.88 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive f: (KINGSTON) (Removable) (Total:7.22 GB) (Free:3.8 GB) FAT32 (Disk=1 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: 37DACB8A) Partition: GPT Partition Type ======================================================== Disk: 1 (Size: 7 GB) (Disk ID: 04030201) Partition 1: (Not Active) - (Size=7 GB) - (Type=0C) ==================== End Of Log ============================ |
06.08.2013, 18:07 | #4 |
/// the machine /// TB-Ausbilder | Nach Virus funktioniert Internet nicht mehr richtig Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
06.08.2013, 19:42 | #5 |
| Nach Virus funktioniert Internet nicht mehr richtig Da ich keine infizierten Objekte mehr hatte, gab es bei dem Anti-Malware die Option "Ergebnisse anzeigen" nicht und somit war da auch nichts zu markieren und entfernen.. Das kam dabei raus Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.06.05 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16635 Nano :: FRIDA [Administrator] Schutz: Aktiviert 06.08.2013 19:36:49 mbam-log-2013-08-06 (19-36-49).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 275482 Laufzeit: 14 Minute(n), 34 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) ADW-Cleaner Code:
ATTFilter # AdwCleaner v2.306 - Datei am 06/08/2013 um 19:55:35 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows 8 (64 bits) # Benutzer : Nano - FRIDA # Bootmodus : Normal # Ausgeführt unter : F:\adwcleaner.exe # Option [Lِschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelِscht : C:\Users\Public\Desktop\eBay.lnk Ordner Gelِscht : C:\ProgramData\continuetosave Ordner Gelِscht : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\continuetosave Ordner Gelِscht : C:\Users\Nano\AppData\Roaming\pdfforge ***** [Registrierungsdatenbank] ***** Schlüssel Gelِscht : HKCU\Software\InstallCore Schlüssel Gelِscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gelِscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Schlüssel Gelِscht : HKLM\SOFTWARE\Classes\TypeLib\{E2343056-CC08-46AC-B898-BFC7ACF4E755} Schlüssel Gelِscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Schlüssel Gelِscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gelِscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} Schlüssel Gelِscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{C1C6816E-CBB3-A748-85F9-A8B47B68985B} Schlüssel Gelِscht : HKLM\SOFTWARE\Classes\Interface\{31E3BC75-2A09-4CFF-9C92-8D0ED8D1DC0F} Schlüssel Gelِscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827} Schlüssel Gelِscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B7FCA997-D0FB-4FE0-8AFD-255E89CF9671} ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16537 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v23.0 (de) Datei : C:\Users\Nano\AppData\Roaming\Mozilla\Firefox\Profiles\mw0q4kht.default\prefs.js [OK] Die Datei ist sauber. -\\ Google Chrome v28.0.1500.95 Datei : C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [2262 octets] - [06/08/2013 19:55:35] ########## EOF - C:\AdwCleaner[S1].txt - [2322 octets] ########## JRT Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.3.4 (08.06.2013:1) OS: Windows 8 x64 Ran by Nano on 06.08.2013 at 20:07:40,23 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{3D997360-C236-438F-95A0-27066D3656BF} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{3D997360-C236-438F-95A0-27066D3656BF} ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 06.08.2013 at 20:35:32,31 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Und hier das frische FRST FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-08-2013 Ran by Nano (administrator) on 06-08-2013 20:36:43 Running from F:\FRST Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AVG Technologies CZ, s.r.o.) C:\PROGRA~2\AVG\AVG2013\avgrsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgcsrva.exe (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\afwServ.exe (Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe (Advanced Micro Devices, Inc.) C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Microsoft Corporation) C:\Windows\system32\dashost.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgnsa.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgemca.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe (CyberLink) C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe (CyberLink) C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Spotify Ltd) C:\Users\Nano\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (Qualcomm Atheros) C:\Program Files (x86)\Bluetooth Suite\BtTray.exe (Atheros Communications) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe (Siber Systems) C:\Program Files (x86)\Siber Systems\AI RoboForm\robotaskbaricon.exe (Dropbox, Inc.) C:\Users\Nano\AppData\Roaming\Dropbox\bin\Dropbox.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (Hewlett-Packard Development Company, L.P.) C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (AVG Technologies CZ, s.r.o.) C:\Program Files (x86)\AVG\AVG2013\avgui.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (Synaptics Incorporated) C:\PROGRAM FILES\SYNAPTICS\SYNTP\SYNTPHELPER.EXE (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe (Hewlett-Packard Company) C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe (Realsil Microelectronics Inc.) C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe (Advanced Micro Devices, Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MMLoadDrv.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe [6548112 2012-06-12] (Realtek Semiconductor) HKLM\...\Run: [BtPreLoad] - C:\Program Files (x86)\Bluetooth Suite\BtPreLoad.exe [65152 2012-08-07] () HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2916152 2012-08-29] (Synaptics Incorporated) HKCU\...\Run: [Spotify Web Helper] - C:\Users\Nano\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1104384 2013-07-05] (Spotify Ltd) HKCU\...\Run: [Spotify] - C:\Users\Nano\AppData\Roaming\Spotify\spotify.exe [4640768 2013-07-05] (Spotify Ltd) HKCU\...\Run: [Steam] - C:\Program Files (x86)\Steam\Steam.exe [1807272 2013-07-27] (Valve Corporation) HKCU\...\Run: [RoboForm] - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboTaskBarIcon.exe [96056 2013-08-05] (Siber Systems) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642216 2012-08-06] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [CLVirtualDrive] - C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe [491320 2012-07-26] (CyberLink Corp.) HKLM-x32\...\Run: [RemoteControl10] - C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe [91432 2012-03-28] (CyberLink Corp.) HKLM-x32\...\Run: [HP Quick Launch] - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe [580512 2012-07-09] (Hewlett-Packard Development Company, L.P.) HKLM-x32\...\Run: [WinampAgent] - C:\Program Files (x86)\Winamp\winampa.exe [74752 2012-06-20] (Nullsoft, Inc.) HKLM-x32\...\Run: [AVG_UI] - C:\Program Files (x86)\AVG\AVG2013\avgui.exe [3147384 2012-12-11] (AVG Technologies CZ, s.r.o.) HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\avastUI.exe [4858968 2013-05-09] (AVAST Software) Startup: C:\Users\Nano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Nano\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) Startup: C:\Users\Nano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM13/10 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM13/10 HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM13/10 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM13/10 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://g.uk.msn.com/HPCOM13/10 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://g.uk.msn.com/HPCOM13/10 SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMNTDFJS SearchScopes: HKLM - {3D997360-C236-438F-95A0-27066D3656BF} URL = hxxp://www.amazon.de/s/ref=azs_osd_ieade?ie=UTF-8&tag=hp-de2-vsb-21&link%5Fcode=qs&index=aps&field-keywords={searchTerms} SearchScopes: HKLM - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMNTDFJS SearchScopes: HKLM-x32 - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=CMNTDFJS SearchScopes: HKCU - {D944BB61-2E34-4DBF-A683-47E505C587DC} URL = hxxp://rover.ebay.com/rover/1/707-154345-12128-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword={searchTerms} BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: avast! EasyPass Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software) BHO-x32: Norton Identity Protection - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) BHO-x32: Norton Vulnerability Protection - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\IPS\IPSBHO.DLL (Symantec Corporation) BHO-x32: avast! EasyPass Toolbar Helper - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (AVAST Software) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard) Toolbar: HKLM - avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\coIEPlg.dll (Symantec Corporation) Toolbar: HKLM-x32 - avast! EasyPass Toolbar - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\Program Files (x86)\Siber Systems\AI RoboForm\roboform.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) Toolbar: HKCU - avast! EasyPass Toolbar - {724D43A0-0D85-11D4-9908-00400523E39A} - C:\Program Files (x86)\Siber Systems\AI RoboForm\RoboForm-x64.dll (AVAST Software) Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\Nano\AppData\Roaming\Mozilla\Firefox\Profiles\mw0q4kht.default FF Plugin-x32: @adobe.com/ShockwavePlayer - C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn\ FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\coFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [{BBDA0591-3099-440a-AA10-41764D9DB4DB}] C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFFPlgn\ FF Extension: Norton Vulnerability Protection - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\IPSFFPlgn\ FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Norton Identity Safe) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.0.10_0\npcoplgn.dll (Symantec Corporation) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Windows Live\u0099 Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (Shockwave for Director) - C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.) CHR Extension: (Google Docs) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Norton Identity Protection) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2013.4.0.10_0 CHR Extension: (Gmail) - C:\Users\Nano\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\Exts\Chrome.crx CHR StartMenuInternet: Google Chrome - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AMD FUEL Service; C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [361984 2012-08-06] (Advanced Micro Devices, Inc.) R2 AtherosSvc; C:\Program Files (x86)\Bluetooth Suite\adminservice.exe [211072 2012-08-07] (Qualcomm Atheros Commnucations) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-05-09] (AVAST Software) R2 avast! Firewall; C:\Program Files\AVAST Software\Avast\afwServ.exe [137960 2013-05-09] (AVAST Software) R2 AVGIDSAgent; C:\Program Files (x86)\AVG\AVG2013\avgidsagent.exe [5814904 2012-11-15] (AVG Technologies CZ, s.r.o.) R2 avgwd; C:\Program Files (x86)\AVG\AVG2013\avgwdsvc.exe [196664 2012-10-22] (AVG Technologies CZ, s.r.o.) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\20.4.0.40\ccSvcHst.exe [144368 2013-05-21] (Symantec Corporation) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [14920 2013-01-29] (Microsoft Corporation) R2 ZAtheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [323584 2012-08-07] (Atheros) ==================== Drivers (Whitelisted) ==================== R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [199008 2012-06-23] (AppEx Networks Corporation) R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-05-09] (AVAST Software) R1 aswFW; C:\Windows\system32\drivers\aswFW.sys [131232 2013-05-09] (AVAST Software) R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [22600 2013-05-09] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-05-09] (AVAST Software) R1 aswNdisFlt; C:\Windows\system32\DRIVERS\aswNdisFlt.sys [276992 2013-05-09] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-05-09] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-05-09] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-05] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-05] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-05-09] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [189936 2013-08-05] () R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98472 2012-07-17] (Advanced Micro Devices) S0 Avgboota; C:\Windows\System32\DRIVERS\avgboota.sys [20912 2012-10-26] (AVG Technologies CZ, s.r.o.) R1 AVGIDSDriver; C:\Windows\system32\DRIVERS\avgidsdrivera.sys [154464 2012-10-22] (AVG Technologies CZ, s.r.o. ) R0 AVGIDSHA; C:\Windows\System32\DRIVERS\avgidsha.sys [63328 2012-10-15] (AVG Technologies CZ, s.r.o. ) R1 Avgldx64; C:\Windows\system32\DRIVERS\avgldx64.sys [185696 2012-10-02] (AVG Technologies CZ, s.r.o.) R0 Avgloga; C:\Windows\System32\DRIVERS\avgloga.sys [225120 2012-09-21] (AVG Technologies CZ, s.r.o.) R0 Avgmfx64; C:\Windows\System32\DRIVERS\avgmfx64.sys [111968 2012-11-15] (AVG Technologies CZ, s.r.o.) R0 Avgrkx64; C:\Windows\System32\DRIVERS\avgrkx64.sys [40800 2012-09-14] (AVG Technologies CZ, s.r.o.) R1 Avgwfpa; C:\Windows\system32\DRIVERS\avgwfpa.sys [208736 2012-11-26] (AVG Technologies CZ, s.r.o.) R3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\BASHDefs\20130502.001\BHDrvx64.sys [1390680 2013-04-13] (Symantec Corporation) R3 BHDrvx64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\BASHDefs\20130502.001\BHDrvx64.sys [1390680 2013-04-13] (Symantec Corporation) R3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [76952 2012-08-07] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1404000.028\ccSetx64.sys [169048 2013-04-16] (Symantec Corporation) R1 CLVirtualDrive; C:\Windows\system32\DRIVERS\CLVirtualDrive.sys [92536 2012-06-25] (CyberLink) R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-17] (Symantec Corporation) R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [484512 2013-03-17] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [138912 2013-03-17] (Symantec Corporation) R3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\IPSDefs\20130515.001\IDSvia64.sys [513184 2013-03-13] (Symantec Corporation) R3 IDSVia64; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\IPSDefs\20130515.001\IDSvia64.sys [513184 2013-03-13] (Symantec Corporation) S3 lehidmini; C:\Windows\System32\drivers\leath_hid.sys [39704 2012-08-07] (Atheros) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20130516.003\ENG64.SYS [126192 2013-03-17] (Symantec Corporation) S3 NAVENG; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20130516.003\ENG64.SYS [126192 2013-03-17] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20130516.003\EX64.SYS [2087664 2013-03-17] (Symantec Corporation) S3 NAVEX15; C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_20.0.0.136\Definitions\VirusDefs\20130516.003\EX64.SYS [2087664 2013-03-17] (Symantec Corporation) R3 RSP2STOR; C:\Windows\system32\DRIVERS\RtsP2Stor.sys [269968 2012-07-04] (Realtek Semiconductor Corp.) S3 SmbDrv; C:\Windows\System32\drivers\Smb_driver_AMDASF.sys [41272 2012-08-29] (Synaptics Incorporated) S3 SmbDrvI; C:\Windows\System32\drivers\Smb_driver_Intel.sys [43832 2012-08-29] (Synaptics Incorporated) S3 SRTSP; C:\Windows\System32\Drivers\NISx64\1404000.028\SRTSP64.SYS [796760 2013-05-16] (Symantec Corporation) R3 SRTSPX; C:\Windows\system32\drivers\NISx64\1404000.028\SRTSPX64.SYS [36952 2013-03-05] (Symantec Corporation) R3 SymDS; C:\Windows\system32\drivers\NISx64\1404000.028\SYMDS64.SYS [493656 2013-05-21] (Symantec Corporation) R3 SymEFA; C:\Windows\system32\drivers\NISx64\1404000.028\SYMEFA64.SYS [1139800 2013-05-23] (Symantec Corporation) S4 SymELAM; C:\Windows\system32\drivers\NISx64\1404000.028\SymELAM.sys [23448 2012-06-20] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT64x86.SYS [177312 2013-06-19] (Symantec Corporation) R3 SymIRON; C:\Windows\system32\drivers\NISx64\1404000.028\Ironx64.SYS [224416 2013-03-05] (Symantec Corporation) R3 SymNetS; C:\Windows\System32\Drivers\NISx64\1404000.028\SYMNETS.SYS [433752 2013-04-25] (Symantec Corporation) R3 WirelessButtonDriver; C:\Windows\System32\drivers\WirelessButtonDriver64.sys [20288 2012-08-03] (Hewlett-Packard Development Company, L.P.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-06 20:07 - 2013-08-06 20:07 - 00000000 ____D C:\Windows\ERUNT 2013-08-06 20:03 - 2013-08-06 20:03 - 00000000 ___RD C:\Users\Nano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-08-06 19:55 - 2013-08-06 19:56 - 00002381 _____ C:\AdwCleaner[S1].txt 2013-08-06 19:33 - 2013-08-06 19:33 - 00000000 ____D C:\Users\Nano\AppData\Roaming\Malwarebytes 2013-08-06 19:32 - 2013-08-06 19:33 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-06 19:32 - 2013-08-06 19:32 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-06 19:32 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-06 17:37 - 2013-08-06 17:37 - 00000000 ____D C:\FRST 2013-08-06 17:30 - 2013-08-06 20:30 - 00000300 _____ C:\Windows\Tasks\DigitalSite.job 2013-08-06 17:30 - 2013-08-06 17:30 - 00002638 _____ C:\Windows\System32\Tasks\DigitalSite 2013-08-06 17:30 - 2013-08-06 17:30 - 00000000 ____D C:\Users\Nano\AppData\Roaming\DigitalSite 2013-08-06 11:41 - 2013-08-06 11:41 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-06 11:41 - 2013-08-06 11:41 - 00000000 ____D C:\Users\Nano\AppData\Roaming\Mozilla 2013-08-06 11:41 - 2013-08-06 11:41 - 00000000 ____D C:\Users\Nano\AppData\Local\Mozilla 2013-08-06 11:40 - 2013-08-06 11:40 - 00000000 ____D C:\ProgramData\Mozilla 2013-08-06 11:40 - 2013-08-06 11:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-06 11:40 - 2013-08-06 11:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-06 11:37 - 2013-08-06 11:38 - 22268584 _____ (Mozilla) C:\Users\Nano\Downloads\Firefox_Setup_23.0.exe 2013-08-06 11:33 - 2013-08-06 11:33 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-06 11:32 - 2013-08-06 20:24 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-06 11:32 - 2013-08-06 20:00 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-06 11:32 - 2013-08-06 18:19 - 00004090 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-06 11:32 - 2013-08-06 18:19 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-06 11:26 - 2013-08-06 11:27 - 34992280 _____ (Google Inc.) C:\Users\Nano\Downloads\ChromeStandaloneSetup_28.0b1500.95.exe 2013-08-06 00:24 - 2013-05-09 10:59 - 00131232 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFW.sys 2013-08-06 00:23 - 2013-05-09 10:59 - 00276992 _____ (AVAST Software) C:\Windows\system32\Drivers\aswNdisFlt.sys 2013-08-06 00:23 - 2013-05-09 10:59 - 00022600 _____ (AVAST Software) C:\Windows\system32\Drivers\aswKbd.sys 2013-08-06 00:20 - 2013-08-06 00:20 - 00001922 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk 2013-08-05 22:46 - 2013-08-05 22:46 - 00000000 ___RD C:\Users\Nano\Documents\Notes 2013-08-05 20:23 - 2013-08-05 20:23 - 00003484 _____ C:\Windows\System32\Tasks\Run RoboForm TaskBar Icon 2013-08-05 20:23 - 2013-08-05 20:23 - 00000000 ____D C:\Users\Nano\AppData\Roaming\RoboForm 2013-08-05 20:21 - 2013-08-05 20:21 - 00000000 ____D C:\ProgramData\RoboForm 2013-08-05 20:20 - 2013-08-05 20:20 - 00000000 ____D C:\Users\Nano\Documents\My Avast EasyPass Data 2013-08-05 20:20 - 2013-08-05 20:20 - 00000000 ____D C:\Program Files (x86)\Siber Systems 2013-08-05 20:17 - 2013-08-05 20:16 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-08-05 20:16 - 2013-08-06 20:03 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-08-05 20:16 - 2013-08-06 00:23 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-08-05 20:16 - 2013-08-05 20:16 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-05 20:16 - 2013-08-05 20:16 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-05 20:16 - 2013-08-05 20:16 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-05 20:16 - 2013-08-05 20:16 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-08-05 20:16 - 2013-08-05 20:16 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-08-05 20:16 - 2013-05-09 10:59 - 00080816 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2013-08-05 20:16 - 2013-05-09 10:59 - 00072016 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2013-08-05 20:16 - 2013-05-09 10:59 - 00065336 _____ C:\Windows\system32\Drivers\aswRvrt.sys 2013-08-05 20:16 - 2013-05-09 10:59 - 00064288 _____ (AVAST Software) C:\Windows\system32\Drivers\aswTdi.sys 2013-08-05 20:16 - 2013-05-09 10:59 - 00033400 _____ (AVAST Software) C:\Windows\system32\Drivers\aswFsBlk.sys 2013-08-05 20:16 - 2013-05-09 10:58 - 00287840 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2013-08-05 20:14 - 2013-08-05 20:14 - 00000000 ____D C:\Program Files\AVAST Software 2013-08-05 20:14 - 2013-05-09 10:58 - 00041664 _____ (AVAST Software) C:\Windows\avastSS.scr 2013-08-05 20:12 - 2013-08-05 20:14 - 00000000 ____D C:\ProgramData\AVAST Software 2013-08-05 20:00 - 2013-08-05 20:00 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\ATI 2013-08-05 20:00 - 2013-08-05 20:00 - 00000000 ____D C:\Users\Jinan\AppData\Local\ATI 2013-08-05 20:00 - 2013-08-05 20:00 - 00000000 ____D C:\Users\Jinan\AppData\Local\AMD 2013-08-05 19:59 - 2013-08-05 19:59 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\Synaptics 2013-08-05 19:59 - 2013-08-05 19:59 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\AVG2013 2013-08-05 19:59 - 2013-08-05 19:59 - 00000000 ____D C:\Users\Jinan\AppData\Local\Avg2013 2013-08-05 19:58 - 2013-08-05 19:58 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\Adobe 2013-08-05 19:57 - 2013-08-05 19:57 - 00000000 ____D C:\Users\Jinan\AppData\Local\VirtualStore 2013-08-05 19:48 - 2013-08-05 19:53 - 117478104 _____ C:\Users\Nano\Downloads\avast_free_antivirus_setup_8.0.1489.300.exe 2013-07-22 03:27 - 2013-06-01 13:54 - 00194816 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\sdbus.sys 2013-07-22 03:27 - 2013-06-01 13:54 - 00125184 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\dumpsd.sys 2013-07-22 03:27 - 2013-06-01 13:34 - 02391280 _____ (Microsoft Corporation) C:\Windows\explorer.exe 2013-07-22 03:27 - 2013-06-01 13:33 - 02233600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-07-22 03:27 - 2013-06-01 13:29 - 00337152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\USBXHCI.SYS 2013-07-22 03:27 - 2013-06-01 13:29 - 00213248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\UCX01000.SYS 2013-07-22 03:27 - 2013-06-01 13:26 - 06987008 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-07-22 03:27 - 2013-06-01 13:26 - 00327936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\volsnap.sys 2013-07-22 03:27 - 2013-06-01 12:24 - 02106176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\explorer.exe 2013-07-22 03:27 - 2013-06-01 11:25 - 00364544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\XpsGdiConverter.dll 2013-07-22 03:27 - 2013-06-01 11:25 - 00067584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\samlib.dll 2013-07-22 03:27 - 2013-06-01 11:24 - 01453568 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfcore.dll 2013-07-22 03:27 - 2013-06-01 11:24 - 00850944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfasfsrcsnk.dll 2013-07-22 03:27 - 2013-06-01 11:24 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscms.dll 2013-07-22 03:27 - 2013-06-01 11:23 - 01842176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dwmcore.dll 2013-07-22 03:27 - 2013-06-01 11:23 - 00680960 _____ (Microsoft Corporation) C:\Windows\system32\vds.exe 2013-07-22 03:27 - 2013-06-01 11:22 - 00523264 _____ (Microsoft Corporation) C:\Windows\system32\XpsGdiConverter.dll 2013-07-22 03:27 - 2013-06-01 11:22 - 00446976 _____ (Microsoft Corporation) C:\Windows\system32\wwansvc.dll 2013-07-22 03:27 - 2013-06-01 11:22 - 00190976 _____ (Microsoft Corporation) C:\Windows\system32\vdsutil.dll 2013-07-22 03:27 - 2013-06-01 11:22 - 00080896 _____ (Microsoft Corporation) C:\Windows\system32\MbaeParserTask.exe 2013-07-22 03:27 - 2013-06-01 11:21 - 00729600 _____ (Microsoft Corporation) C:\Windows\system32\samsrv.dll 2013-07-22 03:27 - 2013-06-01 11:21 - 00106496 _____ (Microsoft Corporation) C:\Windows\system32\samlib.dll 2013-07-22 03:27 - 2013-06-01 11:20 - 02219520 _____ (Microsoft Corporation) C:\Windows\system32\dwmcore.dll 2013-07-22 03:27 - 2013-06-01 11:20 - 01527808 _____ (Microsoft Corporation) C:\Windows\system32\mfcore.dll 2013-07-22 03:27 - 2013-06-01 11:20 - 01048576 _____ (Microsoft Corporation) C:\Windows\system32\mfasfsrcsnk.dll 2013-07-22 03:27 - 2013-06-01 11:20 - 00583168 _____ (Microsoft Corporation) C:\Windows\system32\mscms.dll 2013-07-22 03:27 - 2013-06-01 11:19 - 00785408 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll 2013-07-22 03:27 - 2013-06-01 11:19 - 00207872 _____ (Microsoft Corporation) C:\Windows\system32\DeviceSetupManager.dll 2013-07-22 03:27 - 2013-06-01 05:08 - 00037632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\BthAvrcpTg.sys 2013-07-22 03:27 - 2013-05-25 00:09 - 01403296 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi 2013-07-22 03:27 - 2013-05-25 00:09 - 01271584 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe 2013-07-22 03:27 - 2013-05-25 00:09 - 01217352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi 2013-07-22 03:27 - 2013-05-25 00:09 - 01093904 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe 2013-07-22 03:27 - 2013-05-20 02:08 - 00386642 _____ C:\Windows\system32\ApnDatabase.xml 2013-07-20 19:25 - 2013-06-17 00:41 - 00997632 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ndis.sys 2013-07-20 00:58 - 2013-07-20 00:58 - 00307904 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-19 23:39 - 2013-04-12 00:30 - 01421312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-19 23:39 - 2013-04-12 00:22 - 01838080 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll 2013-07-19 23:38 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-19 23:38 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-19 23:38 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-19 23:38 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-19 23:38 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-19 23:38 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-19 23:38 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-19 23:38 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-19 23:38 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-19 23:38 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-19 23:38 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-19 23:38 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-19 23:38 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-19 23:38 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-19 23:38 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-19 23:38 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-19 23:38 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-19 23:30 - 2013-05-31 01:14 - 04036096 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-19 23:24 - 2013-06-01 11:25 - 00496640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-19 23:24 - 2013-06-01 11:21 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-19 23:09 - 2013-05-04 08:59 - 02842112 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-19 23:09 - 2013-05-04 06:57 - 02620928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-19 23:00 - 2013-05-16 00:35 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\tssdisai.dll 2013-07-18 18:51 - 2013-07-18 18:52 - 00383040 _____ C:\Windows\Minidump\071813-99279-01.dmp 2013-07-16 09:53 - 2013-07-16 09:53 - 00382872 _____ C:\Windows\Minidump\071613-44616-01.dmp 2013-07-10 10:42 - 2013-07-10 10:42 - 00383336 _____ C:\Windows\Minidump\071013-80387-01.dmp 134 ==================== One Month Modified Files and Folders ======= 2013-08-06 20:35 - 2013-08-06 20:35 - 00000904 _____ C:\Users\Nano\Desktop\JRT.txt 2013-08-06 20:30 - 2013-08-06 17:30 - 00000300 _____ C:\Windows\Tasks\DigitalSite.job 2013-08-06 20:24 - 2013-08-06 11:32 - 00001118 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-08-06 20:19 - 2013-06-11 15:49 - 00000000 ____D C:\ProgramData\MFAData 2013-08-06 20:07 - 2013-08-06 20:07 - 00000000 ____D C:\Windows\ERUNT 2013-08-06 20:03 - 2013-08-06 20:03 - 00000000 ___RD C:\Users\Nano\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BT Devices 2013-08-06 20:03 - 2013-08-05 20:16 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-08-06 20:03 - 2013-05-28 16:51 - 00000000 ____D C:\Users\Nano\AppData\Roaming\Dropbox 2013-08-06 20:02 - 2013-06-24 01:27 - 00000000 ____D C:\Program Files (x86)\Steam 2013-08-06 20:02 - 2013-05-28 16:59 - 00000000 ___RD C:\Users\Nano\Dropbox 2013-08-06 20:00 - 2013-08-06 11:32 - 00001114 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-08-06 20:00 - 2012-07-26 09:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-06 19:58 - 2013-03-17 11:56 - 01340558 _____ C:\Windows\WindowsUpdate.log 2013-08-06 19:56 - 2013-08-06 19:55 - 00002381 _____ C:\AdwCleaner[S1].txt 2013-08-06 19:33 - 2013-08-06 19:33 - 00000000 ____D C:\Users\Nano\AppData\Roaming\Malwarebytes 2013-08-06 19:33 - 2013-08-06 19:32 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-06 19:32 - 2013-08-06 19:32 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-08-06 19:02 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\sru 2013-08-06 18:19 - 2013-08-06 11:32 - 00004090 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-08-06 18:19 - 2013-08-06 11:32 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2013-08-06 17:48 - 2013-04-06 21:57 - 00000000 ____D C:\Users\Nano\AppData\Roaming\Spotify 2013-08-06 17:37 - 2013-08-06 17:37 - 00000000 ____D C:\FRST 2013-08-06 17:30 - 2013-08-06 17:30 - 00002638 _____ C:\Windows\System32\Tasks\DigitalSite 2013-08-06 17:30 - 2013-08-06 17:30 - 00000000 ____D C:\Users\Nano\AppData\Roaming\DigitalSite 2013-08-06 11:55 - 2013-03-17 12:08 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-1458673497-1914164762-889707888-1003 2013-08-06 11:44 - 2012-08-04 00:23 - 00020688 _____ C:\Windows\PFRO.log 2013-08-06 11:41 - 2013-08-06 11:41 - 00001147 _____ C:\Users\Public\Desktop\Mozilla Firefox.lnk 2013-08-06 11:41 - 2013-08-06 11:41 - 00000000 ____D C:\Users\Nano\AppData\Roaming\Mozilla 2013-08-06 11:41 - 2013-08-06 11:41 - 00000000 ____D C:\Users\Nano\AppData\Local\Mozilla 2013-08-06 11:40 - 2013-08-06 11:40 - 00000000 ____D C:\ProgramData\Mozilla 2013-08-06 11:40 - 2013-08-06 11:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-08-06 11:40 - 2013-08-06 11:40 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-08-06 11:38 - 2013-08-06 11:37 - 22268584 _____ (Mozilla) C:\Users\Nano\Downloads\Firefox_Setup_23.0.exe 2013-08-06 11:34 - 2012-08-17 21:13 - 00830120 _____ C:\Windows\system32\perfh007.dat 2013-08-06 11:34 - 2012-08-17 21:13 - 00188224 _____ C:\Windows\system32\perfc007.dat 2013-08-06 11:34 - 2012-07-26 09:28 - 01949368 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-06 11:33 - 2013-08-06 11:33 - 00002255 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2013-08-06 11:32 - 2013-03-17 12:07 - 00000000 ____D C:\Program Files (x86)\Google 2013-08-06 11:30 - 2013-03-29 10:44 - 00439296 ___SH C:\Users\Nano\Downloads\Thumbs.db 2013-08-06 11:27 - 2013-08-06 11:26 - 34992280 _____ (Google Inc.) C:\Users\Nano\Downloads\ChromeStandaloneSetup_28.0b1500.95.exe 2013-08-06 11:19 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\system32\NDF 2013-08-06 10:12 - 2012-07-26 10:12 - 00000000 ____D C:\Windows\AUInstallAgent 2013-08-06 00:23 - 2013-08-05 20:16 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-08-06 00:20 - 2013-08-06 00:20 - 00001922 _____ C:\Users\Public\Desktop\avast! Internet Security.lnk 2013-08-06 00:00 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\BBI 2013-08-05 23:46 - 2012-07-26 07:26 - 00262144 ___SH C:\Windows\system32\config\ELAM 2013-08-05 22:46 - 2013-08-05 22:46 - 00000000 ___RD C:\Users\Nano\Documents\Notes 2013-08-05 20:23 - 2013-08-05 20:23 - 00003484 _____ C:\Windows\System32\Tasks\Run RoboForm TaskBar Icon 2013-08-05 20:23 - 2013-08-05 20:23 - 00000000 ____D C:\Users\Nano\AppData\Roaming\RoboForm 2013-08-05 20:21 - 2013-08-05 20:21 - 00000000 ____D C:\ProgramData\RoboForm 2013-08-05 20:20 - 2013-08-05 20:20 - 00000000 ____D C:\Users\Nano\Documents\My Avast EasyPass Data 2013-08-05 20:20 - 2013-08-05 20:20 - 00000000 ____D C:\Program Files (x86)\Siber Systems 2013-08-05 20:16 - 2013-08-05 20:17 - 00000175 _____ C:\Windows\system32\Drivers\aswVmm.sys.sum 2013-08-05 20:16 - 2013-08-05 20:16 - 01030952 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys 2013-08-05 20:16 - 2013-08-05 20:16 - 00378944 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys 2013-08-05 20:16 - 2013-08-05 20:16 - 00189936 _____ C:\Windows\system32\Drivers\aswVmm.sys 2013-08-05 20:16 - 2013-08-05 20:16 - 00000175 _____ C:\Windows\system32\Drivers\aswSP.sys.sum 2013-08-05 20:16 - 2013-08-05 20:16 - 00000175 _____ C:\Windows\system32\Drivers\aswSnx.sys.sum 2013-08-05 20:14 - 2013-08-05 20:14 - 00000000 ____D C:\Program Files\AVAST Software 2013-08-05 20:14 - 2013-08-05 20:12 - 00000000 ____D C:\ProgramData\AVAST Software 2013-08-05 20:09 - 2013-03-17 12:02 - 00000000 ____D C:\Users\Nano\Documents\Bluetooth Folder 2013-08-05 20:00 - 2013-08-05 20:00 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\ATI 2013-08-05 20:00 - 2013-08-05 20:00 - 00000000 ____D C:\Users\Jinan\AppData\Local\ATI 2013-08-05 20:00 - 2013-08-05 20:00 - 00000000 ____D C:\Users\Jinan\AppData\Local\AMD 2013-08-05 19:59 - 2013-08-05 19:59 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\Synaptics 2013-08-05 19:59 - 2013-08-05 19:59 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\AVG2013 2013-08-05 19:59 - 2013-08-05 19:59 - 00000000 ____D C:\Users\Jinan\AppData\Local\Avg2013 2013-08-05 19:58 - 2013-08-05 19:58 - 00000000 ____D C:\Users\Jinan\AppData\Roaming\Adobe 2013-08-05 19:58 - 2013-06-30 17:13 - 00000000 ____D C:\Users\Jinan\AppData\Local\Packages 2013-08-05 19:58 - 2013-03-17 12:01 - 00000000 ____D C:\Windows\System32\Tasks\WPD 2013-08-05 19:58 - 2013-03-17 11:51 - 00000000 ____D C:\Users\Jinan 2013-08-05 19:57 - 2013-08-05 19:57 - 00000000 ____D C:\Users\Jinan\AppData\Local\VirtualStore 2013-08-05 19:53 - 2013-08-05 19:48 - 117478104 _____ C:\Users\Nano\Downloads\avast_free_antivirus_setup_8.0.1489.300.exe 2013-08-05 14:40 - 2013-04-06 21:58 - 00000000 ____D C:\Users\Nano\AppData\Local\Spotify 2013-08-02 01:21 - 2013-05-05 22:40 - 00101376 ___SH C:\Users\Nano\Desktop\Thumbs.db 2013-07-25 23:53 - 2013-06-24 23:21 - 00014336 ___SH C:\Users\Nano\Documents\Thumbs.db 2013-07-24 12:10 - 2013-03-30 10:01 - 00000000 ____D C:\Users\Nano\Documents\Major 2013-07-20 19:01 - 2013-03-18 18:07 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-07-20 00:58 - 2013-07-20 00:58 - 00307904 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-20 00:56 - 2012-07-26 07:37 - 00000000 ____D C:\Windows\servicing 2013-07-20 00:52 - 2012-07-26 09:52 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-20 00:51 - 2012-07-26 07:38 - 00000000 ____D C:\Windows\system32\oobe 2013-07-18 18:52 - 2013-07-18 18:51 - 00383040 _____ C:\Windows\Minidump\071813-99279-01.dmp 2013-07-18 18:51 - 2013-06-13 16:00 - 00000000 ____D C:\Windows\Minidump 2013-07-18 18:51 - 2013-06-13 15:59 - 430290099 _____ C:\Windows\MEMORY.DMP 2013-07-16 09:53 - 2013-07-16 09:53 - 00382872 _____ C:\Windows\Minidump\071613-44616-01.dmp 2013-07-10 19:45 - 2013-04-13 21:51 - 00000000 ____D C:\Users\Nano\AppData\Roaming\vlc 2013-07-10 10:42 - 2013-07-10 10:42 - 00383336 _____ C:\Windows\Minidump\071013-80387-01.dmp ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-07-31 11:45 ==================== End Of Log ============================ --- --- --- |
07.08.2013, 03:54 | #6 |
/// the machine /// TB-Ausbilder | Nach Virus funktioniert Internet nicht mehr richtigESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Nach Virus funktioniert Internet nicht mehr richtig |
Themen zu Nach Virus funktioniert Internet nicht mehr richtig |
avast, chrome, folge, folgendes, free, funktionieren, funktioniert, funktioniert nicht, google, immernoch, installieren, interne, internet, internetseite, internetseiten, neuem, nicht mehr, problem, richtig, seite, seiten, server, spiele, steam, super, virus, werbung |