![]() |
Plagegeister aller Art und deren Bekämpfung: Im Browser ist überall WerbungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
![]() | #1 |
![]() ![]() | ![]() Im Browser ist überall Werbung Hallo ihr Lieben, ich brauche wieder euere Hilfe. Habe auf einmal überall Werbung im Browser. Habe mir den Adblocker runtergeladen und aktiviert, nun sehe ich die Werbung nicht mehr, aber es steht links, rechts und unten immer "ads not by this site" auch auf dieser Seite. Auch werden manche Wörter markiert, die ich anklicken kann, dadurch kann ich auf andere Seiten geleitet werden. Merke auch das der Pc nun teilweise hängt ![]() Habe mir Malwarebytes Anti-Malware runtergeladen und einen Quick-Scan gemacht. Ein Fund : PUP.Optional.Solimba wurde erfolgreich gelöscht. Habe die Windows 7 Version. Für eure Hilfe wäre ich sehr dankbar! Liebe Grüße Lili Geändert von joycelle (11.08.2013 um 23:24 Uhr) |
![]() | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Im Browser ist überall Werbung Hallo und
__________________![]() Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
![]() Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
![]() | #3 |
![]() ![]() | ![]() Im Browser ist überall Werbung Hallo lieber cosinus und vielen Dank das du mir helfen möchtest
__________________![]() Habe nur Logdateien vom Anti-Malware und das sind 7 Stück, alle posten? Gestern Abend ist mir beim durchstöbern im Forum etwas aufgefallen. Ich habe komischerweise ein Programm Namens inimet (hoffe das ist richtig geschrieben) auf meinem Rechner gehabt. Habe es natürlich sofort deinstalliert, habe aber hier gelesen das es eine Art Trojaner sein soll. Verstehe nicht wie das auf meinen Rechner kommt ![]() Vll ist es relevant für dich. Auf jeden Fall sind hier die Logfiles FRST Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2013 02 Ran by Lila at 2013-08-12 11:16:13 Running from C:\Users\Lila\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 0.0.0) Acrobat.com (x32 Version: 1.2.443) Adobe Acrobat 9 Pro - English, Français, Deutsch (x32 Version: 9.0.0) Adobe After Effects CS4 Third Party Content (x32 Version: 9) Adobe AIR (x32 Version: Adobe Anchor Service CS4 (x32 Version: 2.0) Adobe Anchor Service x64 CS4 (Version: 2.0) Adobe Bridge CS4 (x32 Version: 3) Adobe CMaps CS4 (x32 Version: 2.0) Adobe CMaps x64 CS4 (Version: 2.0) Adobe Color - Photoshop Specific CS4 (x32 Version: 2.0) Adobe Color EU Recommended Settings CS4 (x32 Version: 2.0) Adobe Color JA Extra Settings CS4 (x32 Version: 2.0) Adobe Color NA Extra Settings CS4 (x32 Version: 2.0) Adobe Color Video Profiles CS CS4 (x32 Version: 2.0) Adobe Contribute CS4 (x32 Version: 5.0) Adobe Creative Suite 4 Master Collection (x32 Version: 4.0) Adobe CS4 American English Speech Analysis Models (x32 Version: 1) Adobe CSI CS4 (x32 Version: 1) Adobe CSI CS4 x64 (Version: 1) Adobe Default Language CS4 (x32 Version: 2.0) Adobe Dreamweaver CS4 (x32 Version: 10.0) Adobe Drive CS4 x64 (Version: 1) Adobe Dynamiclink Support (x32 Version: 1) Adobe Encore CS4 Codecs (x32 Version: 4) Adobe ExtendScript Toolkit CS4 (x32 Version: 3.0.0) Adobe Extension Manager CS4 (x32 Version: 2.0) Adobe Fireworks CS4 (x32 Version: 10.0) Adobe Flash CS4 (x32 Version: 10.0) Adobe Flash CS4 Extension - Flash Lite STI others (x32 Version: 3.0) Adobe Flash CS4 STI-other (x32 Version: 10.0) Adobe Flash Player 10 ActiveX (x32 Version: Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.202) Adobe Fonts All (x32 Version: 2.0) Adobe Fonts All x64 (Version: 2.0) Adobe Illustrator CS4 (x32 Version: 14.0) Adobe InDesign CS4 (x32 Version: 6.0) Adobe InDesign CS4 Application Feature Set Files (Roman) (x32 Version: 6.0) Adobe InDesign CS4 Common Base Files (x32 Version: 6.0) Adobe InDesign CS4 Icon Handler (x32 Version: 6.0) Adobe InDesign CS4 Icon Handler x64 (Version: 6.0) Adobe Linguistics CS4 (x32 Version: 4.0.0) Adobe Linguistics CS4 x64 (Version: 4.0.0) Adobe Media Encoder CS4 (x32 Version: 1.0) Adobe Media Encoder CS4 Additional Exporter (x32 Version: 1.0) Adobe Media Encoder CS4 Dolby (x32 Version: 1.0) Adobe Media Encoder CS4 Exporter (x32 Version: 1.0) Adobe Media Encoder CS4 Importer (x32 Version: 1.0) Adobe Media Player (x32 Version: 0.0.0) Adobe Media Player (x32 Version: 1.1) Adobe Output Module (x32 Version: 2.0) Adobe PDF Library Files CS4 (x32 Version: 9.0) Adobe PDF Library Files x64 CS4 (Version: 9.0) Adobe Photoshop CS4 (64 Bit) (Version: 11.0) Adobe Photoshop CS4 (x32 Version: 11.0) Adobe Photoshop CS4 Support (x32 Version: 11.0) Adobe Premiere Pro CS4 (x32 Version: 4) Adobe Premiere Pro CS4 Functional Content (x32 Version: 4) Adobe Premiere Pro CS4 Third Party Content (x32 Version: 4) Adobe Search for Help (x32 Version: 1.0) Adobe Service Manager Extension (x32 Version: 1.0) Adobe Setup (x32 Version: 2.0) Adobe SGM CS4 (x32 Version: 3.0) Adobe SING CS4 (x32 Version: 2.0) Adobe Soundbooth CS4 Codecs (x32 Version: 2) Adobe Type Support CS4 (x32 Version: 9.0) Adobe Type Support x64 CS4 (Version: 9.0) Adobe Update Manager CS4 (x32 Version: 6.0.0) Adobe WinSoft Linguistics Plugin (x32 Version: 1.1) Adobe WinSoft Linguistics Plugin x64 (Version: 1.1) Adobe XMP Panels CS4 (x32 Version: 2.0) AdobeColorCommonSetCMYK (x32 Version: 2.0) AdobeColorCommonSetRGB (x32 Version: 2.0) AMD Accelerated Video Transcoding (Version: AMD APP SDK Runtime (Version: 10.0.1084.4) AMD Catalyst Install Manager (Version: 8.0.903.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.71219.1540) Apple Application Support (x32 Version: 2.3) Apple Software Update (x32 Version: Asmedia ASM106x SATA Host Controller Driver (x32 Version: Canon IJ Scan Utility (x32) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32 Version: 4.0.0) Canon MG2200 series Benutzerregistrierung (x32) Canon MG2200 series MP Drivers (Version: 1.00) Canon MG2200 series On-screen Manual (x32 Version: 7.5.0) Canon My Printer (x32 Version: 3.0.0) Canon Quick Menu (x32 Version: 2.0.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485) Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485) CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485) CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485) CCC Help Czech (x32 Version: 2012.1219.1520.27485) CCC Help Danish (x32 Version: 2012.1219.1520.27485) CCC Help Dutch (x32 Version: 2012.1219.1520.27485) CCC Help English (x32 Version: 2012.1219.1520.27485) CCC Help Finnish (x32 Version: 2012.1219.1520.27485) CCC Help French (x32 Version: 2012.1219.1520.27485) CCC Help German (x32 Version: 2012.1219.1520.27485) CCC Help Greek (x32 Version: 2012.1219.1520.27485) CCC Help Hungarian (x32 Version: 2012.1219.1520.27485) CCC Help Italian (x32 Version: 2012.1219.1520.27485) CCC Help Japanese (x32 Version: 2012.1219.1520.27485) CCC Help Korean (x32 Version: 2012.1219.1520.27485) CCC Help Norwegian (x32 Version: 2012.1219.1520.27485) CCC Help Polish (x32 Version: 2012.1219.1520.27485) CCC Help Portuguese (x32 Version: 2012.1219.1520.27485) CCC Help Russian (x32 Version: 2012.1219.1520.27485) CCC Help Spanish (x32 Version: 2012.1219.1520.27485) CCC Help Swedish (x32 Version: 2012.1219.1520.27485) CCC Help Thai (x32 Version: 2012.1219.1520.27485) CCC Help Turkish (x32 Version: 2012.1219.1520.27485) ccc-utility64 (Version: 2012.1219.1521.27485) Connect (x32 Version: DAEMON Tools Lite (x32 Version: Easy Poster Printer (x32 Version: 6.0.0) ESET Smart Security (Version: 6.0.316.1) Google Chrome (HKCU Version: 28.0.1500.95) Intel(R) Control Center (x32 Version: Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: Intel(R) Management Engine Components (x32 Version: Intel(R) OpenCL CPU Runtime (x32) Intel(R) Processor Graphics (x32 Version: Intel(R) Rapid Storage Technology (x32 Version: Intel(R) Smart Connect Technology 2.0 x64 (Version: 2.0.1083.0) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: Intel® Trusted Connect Service Client (Version: 1.23.605.1) kuler (x32 Version: 2.0) LyricsContainer (x32) Malwarebytes Anti-Malware Version (x32 Version: Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Professional Edition 2003 (x32 Version: 11.0.7969.0) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) ock App Charger v1.0.5 PDF Settings CS4 (x32 Version: 9.0) Personal ID (x32 Version: Photoshop Camera Raw (x32 Version: 5.0) Photoshop Camera Raw_x64 (Version: 5.0) Pixel Bender Toolkit (x32 Version: 1.0) Poker 770 (x32) PokerStars.eu (x32) PreFlopper (x32 Version: 2.1.0) QuickTime (x32 Version: Realtek Ethernet Controller Driver (x32 Version: 7.48.823.2011) Realtek High Definition Audio Driver (x32 Version: Secret City (x32 Version: 1.9.4662) Steam (x32 Version: Suite Shared Configuration CS4 (x32 Version: 1.0) TP-LINK TL-WN821N Driver (x32 Version: 1.2.1) TrackMania Nations Forever (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) UseNeXT by Tangysoft (x32) VIRTU MVP 2.1.110 (Version: 2.1.110) VLC media player 2.0.6 (x32 Version: 2.0.6) Wacom Tablett (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 18-07-2013 14:20:47 Windows Update 25-07-2013 22:40:43 Geplanter Prüfpunkt 02-08-2013 20:07:36 Geplanter Prüfpunkt 07-08-2013 20:28:41 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-03-05 15:25 - 00001173 ____A C:\Windows\system32\Drivers\etc\hosts localhost activate.adobe.com practivate.adobe.com ereg.adobe.com activate.wip3.adobe.com wip3.adobe.com 3dns-3.adobe.com 3dns-2.adobe.com adobe-dns.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com ereg.wip3.adobe.com activate-sea.adobe.com pagead2.googlesyndication.com wwis-dubc1-vip60.adobe.com activate-sjc0.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {220145D2-20B3-4B48-AE44-52D59DE2FAF6} - System32\Tasks\User_Feed_Synchronization-{AE5A86A8-D88D-40C8-AA45-438AD91DF71B} => C:\Windows\system32\msfeedssync.exe [2013-05-22] (Microsoft Corporation) Task: {28336CC1-56F3-4285-84D2-51E7E572B6E6} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {3A95E0EA-4FEB-4A27-882A-D4A0E9043D22} - System32\Tasks\LyricsContainer Update => C:\Program Files (x86)\LyricsContainer\LrcsCtrUpdr.exe [2013-08-09] () Task: {52DB3FE1-FD35-49AE-A798-A031751E05F0} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {557A4CA9-1E48-4C36-8783-1250F4FA44A3} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {79B1D23E-D9E5-44CA-B2B4-EE322E0F6FB2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {9227EDEB-5C17-43F6-AF4C-1B3E91416116} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {CEA0F661-E4EF-4B0C-8174-747271058321} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {EBD67A4D-F364-42F2-94CA-DEA6B10D73FF} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\LyricsContainer Update.job => C:\Program Files (x86)\LyricsContainer\LrcsCtrUpdr.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/12/2013 11:08:38 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 11:06:52 AM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/12/2013 11:06:51 AM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 11:25:23 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 11:23:37 PM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/11/2013 11:23:36 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 09:18:52 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 09:17:06 PM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/11/2013 09:17:05 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 01:21:47 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (08/12/2013 11:06:51 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 11:23:36 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 11:11:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SProtection" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/11/2013 09:17:05 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 01:20:00 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/09/2013 00:36:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/08/2013 10:56:54 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/08/2013 10:24:42 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/07/2013 10:42:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "ESET Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/07/2013 10:36:39 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Microsoft Office Sessions: ========================= Error: (08/12/2013 11:08:38 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 11:06:52 AM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/12/2013 11:06:51 AM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 11:25:23 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 11:23:37 PM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/11/2013 11:23:36 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 09:18:52 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 09:17:06 PM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/11/2013 09:17:05 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 01:21:47 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 16% Total physical RAM: 16268.42 MB Available physical RAM: 13621.07 MB Total Pagefile: 32535.03 MB Available Pagefile: 29440.16 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.69 GB) (Free:37.81 GB) NTFS (Disk=0 Partition=2) Drive d: (Volume) (Fixed) (Total:931.51 GB) (Free:891.11 GB) NTFS (Disk=1 Partition=1) Drive e: (Ablage) (Fixed) (Total:10 GB) (Free:1.21 GB) NTFS (Disk=2 Partition=1) Drive f: (Datensammlung) (Fixed) (Total:50.01 GB) (Free:44.07 GB) NTFS (Disk=2 Partition=2) Drive g: (Musik) (Fixed) (Total:100.01 GB) (Free:96.2 GB) NTFS (Disk=2 Partition=3) Drive h: (Down) (Fixed) (Total:305.74 GB) (Free:225.94 GB) NTFS (Disk=2 Partition=4) Drive k: (EOS_DIGITAL) (Removable) (Total:14.93 GB) (Free:8.21 GB) FAT32 (Disk=3 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 862E84D4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: E792C529) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 466 GB) (Disk ID: 086D086C) Partition 1: (Active) - (Size=10 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=456 GB) - (Type=05) ======================================================== Disk: 3 (Size: 15 GB) (Disk ID: 00000000) Partition 1: (Active) - (Size=15 GB) - (Type=0C) ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2013 02 Ran by Lila at 2013-08-12 11:16:13 Running from C:\Users\Lila\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 0.0.0) Acrobat.com (x32 Version: 1.2.443) Adobe Acrobat 9 Pro - English, Français, Deutsch (x32 Version: 9.0.0) Adobe After Effects CS4 Third Party Content (x32 Version: 9) Adobe AIR (x32 Version: Adobe Anchor Service CS4 (x32 Version: 2.0) Adobe Anchor Service x64 CS4 (Version: 2.0) Adobe Bridge CS4 (x32 Version: 3) Adobe CMaps CS4 (x32 Version: 2.0) Adobe CMaps x64 CS4 (Version: 2.0) Adobe Color - Photoshop Specific CS4 (x32 Version: 2.0) Adobe Color EU Recommended Settings CS4 (x32 Version: 2.0) Adobe Color JA Extra Settings CS4 (x32 Version: 2.0) Adobe Color NA Extra Settings CS4 (x32 Version: 2.0) Adobe Color Video Profiles CS CS4 (x32 Version: 2.0) Adobe Contribute CS4 (x32 Version: 5.0) Adobe Creative Suite 4 Master Collection (x32 Version: 4.0) Adobe CS4 American English Speech Analysis Models (x32 Version: 1) Adobe CSI CS4 (x32 Version: 1) Adobe CSI CS4 x64 (Version: 1) Adobe Default Language CS4 (x32 Version: 2.0) Adobe Dreamweaver CS4 (x32 Version: 10.0) Adobe Drive CS4 x64 (Version: 1) Adobe Dynamiclink Support (x32 Version: 1) Adobe Encore CS4 Codecs (x32 Version: 4) Adobe ExtendScript Toolkit CS4 (x32 Version: 3.0.0) Adobe Extension Manager CS4 (x32 Version: 2.0) Adobe Fireworks CS4 (x32 Version: 10.0) Adobe Flash CS4 (x32 Version: 10.0) Adobe Flash CS4 Extension - Flash Lite STI others (x32 Version: 3.0) Adobe Flash CS4 STI-other (x32 Version: 10.0) Adobe Flash Player 10 ActiveX (x32 Version: Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.202) Adobe Fonts All (x32 Version: 2.0) Adobe Fonts All x64 (Version: 2.0) Adobe Illustrator CS4 (x32 Version: 14.0) Adobe InDesign CS4 (x32 Version: 6.0) Adobe InDesign CS4 Application Feature Set Files (Roman) (x32 Version: 6.0) Adobe InDesign CS4 Common Base Files (x32 Version: 6.0) Adobe InDesign CS4 Icon Handler (x32 Version: 6.0) Adobe InDesign CS4 Icon Handler x64 (Version: 6.0) Adobe Linguistics CS4 (x32 Version: 4.0.0) Adobe Linguistics CS4 x64 (Version: 4.0.0) Adobe Media Encoder CS4 (x32 Version: 1.0) Adobe Media Encoder CS4 Additional Exporter (x32 Version: 1.0) Adobe Media Encoder CS4 Dolby (x32 Version: 1.0) Adobe Media Encoder CS4 Exporter (x32 Version: 1.0) Adobe Media Encoder CS4 Importer (x32 Version: 1.0) Adobe Media Player (x32 Version: 0.0.0) Adobe Media Player (x32 Version: 1.1) Adobe Output Module (x32 Version: 2.0) Adobe PDF Library Files CS4 (x32 Version: 9.0) Adobe PDF Library Files x64 CS4 (Version: 9.0) Adobe Photoshop CS4 (64 Bit) (Version: 11.0) Adobe Photoshop CS4 (x32 Version: 11.0) Adobe Photoshop CS4 Support (x32 Version: 11.0) Adobe Premiere Pro CS4 (x32 Version: 4) Adobe Premiere Pro CS4 Functional Content (x32 Version: 4) Adobe Premiere Pro CS4 Third Party Content (x32 Version: 4) Adobe Search for Help (x32 Version: 1.0) Adobe Service Manager Extension (x32 Version: 1.0) Adobe Setup (x32 Version: 2.0) Adobe SGM CS4 (x32 Version: 3.0) Adobe SING CS4 (x32 Version: 2.0) Adobe Soundbooth CS4 Codecs (x32 Version: 2) Adobe Type Support CS4 (x32 Version: 9.0) Adobe Type Support x64 CS4 (Version: 9.0) Adobe Update Manager CS4 (x32 Version: 6.0.0) Adobe WinSoft Linguistics Plugin (x32 Version: 1.1) Adobe WinSoft Linguistics Plugin x64 (Version: 1.1) Adobe XMP Panels CS4 (x32 Version: 2.0) AdobeColorCommonSetCMYK (x32 Version: 2.0) AdobeColorCommonSetRGB (x32 Version: 2.0) AMD Accelerated Video Transcoding (Version: AMD APP SDK Runtime (Version: 10.0.1084.4) AMD Catalyst Install Manager (Version: 8.0.903.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.71219.1540) Apple Application Support (x32 Version: 2.3) Apple Software Update (x32 Version: Asmedia ASM106x SATA Host Controller Driver (x32 Version: Canon IJ Scan Utility (x32) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32 Version: 4.0.0) Canon MG2200 series Benutzerregistrierung (x32) Canon MG2200 series MP Drivers (Version: 1.00) Canon MG2200 series On-screen Manual (x32 Version: 7.5.0) Canon My Printer (x32 Version: 3.0.0) Canon Quick Menu (x32 Version: 2.0.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485) Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485) CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485) CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485) CCC Help Czech (x32 Version: 2012.1219.1520.27485) CCC Help Danish (x32 Version: 2012.1219.1520.27485) CCC Help Dutch (x32 Version: 2012.1219.1520.27485) CCC Help English (x32 Version: 2012.1219.1520.27485) CCC Help Finnish (x32 Version: 2012.1219.1520.27485) CCC Help French (x32 Version: 2012.1219.1520.27485) CCC Help German (x32 Version: 2012.1219.1520.27485) CCC Help Greek (x32 Version: 2012.1219.1520.27485) CCC Help Hungarian (x32 Version: 2012.1219.1520.27485) CCC Help Italian (x32 Version: 2012.1219.1520.27485) CCC Help Japanese (x32 Version: 2012.1219.1520.27485) CCC Help Korean (x32 Version: 2012.1219.1520.27485) CCC Help Norwegian (x32 Version: 2012.1219.1520.27485) CCC Help Polish (x32 Version: 2012.1219.1520.27485) CCC Help Portuguese (x32 Version: 2012.1219.1520.27485) CCC Help Russian (x32 Version: 2012.1219.1520.27485) CCC Help Spanish (x32 Version: 2012.1219.1520.27485) CCC Help Swedish (x32 Version: 2012.1219.1520.27485) CCC Help Thai (x32 Version: 2012.1219.1520.27485) CCC Help Turkish (x32 Version: 2012.1219.1520.27485) ccc-utility64 (Version: 2012.1219.1521.27485) Connect (x32 Version: DAEMON Tools Lite (x32 Version: Easy Poster Printer (x32 Version: 6.0.0) ESET Smart Security (Version: 6.0.316.1) Google Chrome (HKCU Version: 28.0.1500.95) Intel(R) Control Center (x32 Version: Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: Intel(R) Management Engine Components (x32 Version: Intel(R) OpenCL CPU Runtime (x32) Intel(R) Processor Graphics (x32 Version: Intel(R) Rapid Storage Technology (x32 Version: Intel(R) Smart Connect Technology 2.0 x64 (Version: 2.0.1083.0) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: Intel® Trusted Connect Service Client (Version: 1.23.605.1) kuler (x32 Version: 2.0) LyricsContainer (x32) Malwarebytes Anti-Malware Version (x32 Version: Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Professional Edition 2003 (x32 Version: 11.0.7969.0) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) ock App Charger v1.0.5 PDF Settings CS4 (x32 Version: 9.0) Personal ID (x32 Version: Photoshop Camera Raw (x32 Version: 5.0) Photoshop Camera Raw_x64 (Version: 5.0) Pixel Bender Toolkit (x32 Version: 1.0) Poker 770 (x32) PokerStars.eu (x32) PreFlopper (x32 Version: 2.1.0) QuickTime (x32 Version: Realtek Ethernet Controller Driver (x32 Version: 7.48.823.2011) Realtek High Definition Audio Driver (x32 Version: Secret City (x32 Version: 1.9.4662) Steam (x32 Version: Suite Shared Configuration CS4 (x32 Version: 1.0) TP-LINK TL-WN821N Driver (x32 Version: 1.2.1) TrackMania Nations Forever (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) UseNeXT by Tangysoft (x32) VIRTU MVP 2.1.110 (Version: 2.1.110) VLC media player 2.0.6 (x32 Version: 2.0.6) Wacom Tablett (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 18-07-2013 14:20:47 Windows Update 25-07-2013 22:40:43 Geplanter Prüfpunkt 02-08-2013 20:07:36 Geplanter Prüfpunkt 07-08-2013 20:28:41 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-03-05 15:25 - 00001173 ____A C:\Windows\system32\Drivers\etc\hosts localhost activate.adobe.com practivate.adobe.com ereg.adobe.com activate.wip3.adobe.com wip3.adobe.com 3dns-3.adobe.com 3dns-2.adobe.com adobe-dns.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com ereg.wip3.adobe.com activate-sea.adobe.com pagead2.googlesyndication.com wwis-dubc1-vip60.adobe.com activate-sjc0.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {220145D2-20B3-4B48-AE44-52D59DE2FAF6} - System32\Tasks\User_Feed_Synchronization-{AE5A86A8-D88D-40C8-AA45-438AD91DF71B} => C:\Windows\system32\msfeedssync.exe [2013-05-22] (Microsoft Corporation) Task: {28336CC1-56F3-4285-84D2-51E7E572B6E6} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {3A95E0EA-4FEB-4A27-882A-D4A0E9043D22} - System32\Tasks\LyricsContainer Update => C:\Program Files (x86)\LyricsContainer\LrcsCtrUpdr.exe [2013-08-09] () Task: {52DB3FE1-FD35-49AE-A798-A031751E05F0} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {557A4CA9-1E48-4C36-8783-1250F4FA44A3} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {79B1D23E-D9E5-44CA-B2B4-EE322E0F6FB2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {9227EDEB-5C17-43F6-AF4C-1B3E91416116} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {CEA0F661-E4EF-4B0C-8174-747271058321} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {EBD67A4D-F364-42F2-94CA-DEA6B10D73FF} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\LyricsContainer Update.job => C:\Program Files (x86)\LyricsContainer\LrcsCtrUpdr.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/12/2013 11:08:38 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 11:06:52 AM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/12/2013 11:06:51 AM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 11:25:23 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 11:23:37 PM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/11/2013 11:23:36 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 09:18:52 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 09:17:06 PM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/11/2013 09:17:05 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 01:21:47 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (08/12/2013 11:06:51 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 11:23:36 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 11:11:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SProtection" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/11/2013 09:17:05 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 01:20:00 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/09/2013 00:36:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/08/2013 10:56:54 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/08/2013 10:24:42 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/07/2013 10:42:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "ESET Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/07/2013 10:36:39 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Microsoft Office Sessions: ========================= Error: (08/12/2013 11:08:38 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 11:06:52 AM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/12/2013 11:06:51 AM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 11:25:23 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 11:23:37 PM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/11/2013 11:23:36 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 09:18:52 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 09:17:06 PM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/11/2013 09:17:05 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 01:21:47 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 16% Total physical RAM: 16268.42 MB Available physical RAM: 13621.07 MB Total Pagefile: 32535.03 MB Available Pagefile: 29440.16 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.69 GB) (Free:37.81 GB) NTFS (Disk=0 Partition=2) Drive d: (Volume) (Fixed) (Total:931.51 GB) (Free:891.11 GB) NTFS (Disk=1 Partition=1) Drive e: (Ablage) (Fixed) (Total:10 GB) (Free:1.21 GB) NTFS (Disk=2 Partition=1) Drive f: (Datensammlung) (Fixed) (Total:50.01 GB) (Free:44.07 GB) NTFS (Disk=2 Partition=2) Drive g: (Musik) (Fixed) (Total:100.01 GB) (Free:96.2 GB) NTFS (Disk=2 Partition=3) Drive h: (Down) (Fixed) (Total:305.74 GB) (Free:225.94 GB) NTFS (Disk=2 Partition=4) Drive k: (EOS_DIGITAL) (Removable) (Total:14.93 GB) (Free:8.21 GB) FAT32 (Disk=3 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 862E84D4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: E792C529) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 466 GB) (Disk ID: 086D086C) Partition 1: (Active) - (Size=10 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=456 GB) - (Type=05) ======================================================== Disk: 3 (Size: 15 GB) (Disk ID: 00000000) Partition 1: (Active) - (Size=15 GB) - (Type=0C) ==================== End Of Log ============================ Schöne Grüße Lili |
![]() | #4 | |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Im Browser ist überall WerbungZitat:
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #5 |
![]() ![]() | ![]() Im Browser ist überall Werbung Malware Logs: Code:
ATTFilter Malwarebytes Anti-Malware (Test) www.malwarebytes.org Datenbank Version: v2013.05.16.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Lila :: LEX [Administrator] Schutz: Aktiviert 16.05.2013 17:25:52 mbam-log-2013-05-16 (17-25-52).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|H:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 379945 Laufzeit: 12 Minute(n), 11 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2013.08.11.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 Lila :: LEX [Administrator] 11.08.2013 23:20:20 mbam-log-2013-08-11 (23-20-20).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 219128 Laufzeit: 1 Minute(n), 29 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Lila\Downloads\FLVMPlayer.exe (PUP.Optional.Solimba) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter 2013/05/16 17:23:54 +0200 LEX Lila MESSAGE Starting protection 2013/05/16 17:23:54 +0200 LEX Lila MESSAGE Protection started successfully 2013/05/16 17:23:54 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/16 17:24:02 +0200 LEX Lila MESSAGE IP Protection started successfully 2013/05/16 17:24:09 +0200 LEX Lila MESSAGE Starting database refresh 2013/05/16 17:24:09 +0200 LEX Lila MESSAGE Stopping IP protection 2013/05/16 17:24:11 +0200 LEX Lila MESSAGE IP Protection stopped successfully 2013/05/16 17:24:12 +0200 LEX Lila MESSAGE Database refreshed successfully 2013/05/16 17:24:12 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/16 17:24:13 +0200 LEX Lila MESSAGE IP Protection started successfully 2013/05/16 17:41:49 +0200 LEX Lila MESSAGE Starting protection 2013/05/16 17:41:49 +0200 LEX Lila MESSAGE Protection started successfully 2013/05/16 17:41:49 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/16 17:41:50 +0200 LEX Lila MESSAGE IP Protection started successfully 2013/05/16 17:46:43 +0200 LEX Lila MESSAGE Starting protection 2013/05/16 17:46:43 +0200 LEX Lila MESSAGE Protection started successfully 2013/05/16 17:46:43 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/16 17:46:44 +0200 LEX Lila MESSAGE IP Protection started successfully 2013/05/16 17:52:06 +0200 LEX Lila MESSAGE Starting protection 2013/05/16 17:52:06 +0200 LEX Lila MESSAGE Protection started successfully 2013/05/16 17:52:06 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/16 17:52:08 +0200 LEX Lila MESSAGE IP Protection started successfully 2013/05/16 18:01:59 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 49299, Process: firefox.exe) 2013/05/16 18:01:59 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 49300, Process: firefox.exe) 2013/05/16 18:03:11 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 49406, Process: firefox.exe) 2013/05/16 18:03:11 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 49407, Process: firefox.exe) 2013/05/16 18:30:56 +0200 LEX Lila MESSAGE Executing scheduled update: Daily 2013/05/16 18:30:57 +0200 LEX Lila MESSAGE Database already up-to-date 2013/05/16 22:47:33 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 51792, Process: firefox.exe) 2013/05/16 22:47:33 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 51793, Process: firefox.exe) 2013/05/16 22:47:49 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 51794, Process: firefox.exe) 2013/05/16 22:47:49 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 51795, Process: firefox.exe) 2013/05/16 23:01:50 +0200 LEX (null) MESSAGE Starting protection 2013/05/16 23:01:50 +0200 LEX (null) MESSAGE Protection started successfully 2013/05/16 23:01:50 +0200 LEX (null) MESSAGE Starting IP protection 2013/05/16 23:01:52 +0200 LEX (null) MESSAGE IP Protection started successfully 2013/05/16 23:15:53 +0200 LEX Lila MESSAGE Starting protection 2013/05/16 23:15:53 +0200 LEX Lila MESSAGE Protection started successfully 2013/05/16 23:15:53 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/16 23:15:55 +0200 LEX Lila MESSAGE IP Protection started successfully 2013/05/16 23:19:41 +0200 LEX Lila MESSAGE Starting protection 2013/05/16 23:19:41 +0200 LEX Lila MESSAGE Protection started successfully 2013/05/16 23:19:41 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/16 23:19:43 +0200 LEX Lila MESSAGE IP Protection started successfully Code:
ATTFilter 2013/05/18 01:26:48 +0200 LEX Lila MESSAGE Starting protection 2013/05/18 01:26:48 +0200 LEX Lila MESSAGE Protection started successfully 2013/05/18 01:26:48 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/18 01:26:49 +0200 LEX Lila MESSAGE IP Protection started successfully 2013/05/18 01:36:40 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 49324, Process: firefox.exe) 2013/05/18 01:36:40 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 49325, Process: firefox.exe) 2013/05/18 01:37:20 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 49418, Process: firefox.exe) 2013/05/18 01:37:20 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 49419, Process: firefox.exe) 2013/05/18 01:40:51 +0200 LEX Lila MESSAGE Executing scheduled update: Daily 2013/05/18 01:40:59 +0200 LEX Lila MESSAGE Scheduled update executed successfully: database updated from version v2013.05.16.06 to version v2013.05.17.07 2013/05/18 01:40:59 +0200 LEX Lila MESSAGE Starting database refresh 2013/05/18 01:40:59 +0200 LEX Lila MESSAGE Stopping IP protection 2013/05/18 01:40:59 +0200 LEX Lila MESSAGE IP Protection stopped successfully 2013/05/18 01:41:00 +0200 LEX Lila MESSAGE Database refreshed successfully 2013/05/18 01:41:00 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/18 01:41:01 +0200 LEX Lila MESSAGE IP Protection started successfully 2013/05/18 14:45:24 +0200 LEX Lila MESSAGE Starting protection 2013/05/18 14:45:24 +0200 LEX Lila MESSAGE Protection started successfully 2013/05/18 14:45:24 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/18 14:45:26 +0200 LEX Lila MESSAGE IP Protection started successfully 2013/05/18 15:06:21 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 49632, Process: firefox.exe) 2013/05/18 15:06:21 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 49633, Process: firefox.exe) 2013/05/18 15:06:53 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 49691, Process: firefox.exe) 2013/05/18 15:06:53 +0200 LEX Lila IP-BLOCK (Type: outgoing, Port: 49692, Process: firefox.exe) Code:
ATTFilter 2013/05/20 20:56:54 +0200 LEX Lila MESSAGE Starting protection 2013/05/20 20:56:54 +0200 LEX Lila MESSAGE Protection started successfully 2013/05/20 20:56:54 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/20 20:56:55 +0200 LEX Lila MESSAGE IP Protection started successfully 2013/05/20 21:11:15 +0200 LEX Lila MESSAGE Executing scheduled update: Daily 2013/05/20 21:11:26 +0200 LEX Lila MESSAGE Scheduled update executed successfully: database updated from version v2013.05.17.07 to version v2013.05.20.07 2013/05/20 21:11:26 +0200 LEX Lila MESSAGE Starting database refresh 2013/05/20 21:11:26 +0200 LEX Lila MESSAGE Stopping IP protection 2013/05/20 21:11:26 +0200 LEX Lila MESSAGE IP Protection stopped successfully 2013/05/20 21:11:28 +0200 LEX Lila MESSAGE Database refreshed successfully 2013/05/20 21:11:28 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/20 21:11:29 +0200 LEX Lila MESSAGE IP Protection started successfully Code:
ATTFilter 2013/05/21 13:11:29 +0200 LEX Lila MESSAGE Starting protection 2013/05/21 13:11:29 +0200 LEX Lila MESSAGE Protection started successfully 2013/05/21 13:11:29 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/21 13:11:30 +0200 LEX Lila MESSAGE IP Protection started successfully Code:
ATTFilter 2013/05/22 15:28:28 +0200 LEX Lila MESSAGE Starting protection 2013/05/22 15:28:28 +0200 LEX Lila MESSAGE Protection started successfully 2013/05/22 15:28:28 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/22 15:28:29 +0200 LEX Lila MESSAGE IP Protection started successfully 2013/05/22 15:42:21 +0200 LEX Lila MESSAGE Executing scheduled update: Daily 2013/05/22 15:42:33 +0200 LEX Lila MESSAGE Scheduled update executed successfully: database updated from version v2013.05.20.07 to version v2013.05.22.06 2013/05/22 15:42:33 +0200 LEX Lila MESSAGE Starting database refresh 2013/05/22 15:42:33 +0200 LEX Lila MESSAGE Stopping IP protection 2013/05/22 15:42:33 +0200 LEX Lila MESSAGE IP Protection stopped successfully 2013/05/22 15:42:34 +0200 LEX Lila MESSAGE Database refreshed successfully 2013/05/22 15:42:34 +0200 LEX Lila MESSAGE Starting IP protection 2013/05/22 15:42:35 +0200 LEX Lila MESSAGE IP Protection started successfully 2013/05/22 16:02:57 +0200 LEX Lila MESSAGE Stopping IP protection 2013/05/22 16:02:57 +0200 LEX Lila MESSAGE IP Protection stopped successfully 2013/05/22 16:02:57 +0200 LEX Lila MESSAGE Protection stopped |
![]() | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Im Browser ist überall WerbungCode:
ATTFilter activate.adobe.com practivate.adobe.com ereg.adobe.com activate.wip3.adobe.com wip3.adobe.com 3dns-3.adobe.com 3dns-2.adobe.com adobe-dns.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com ereg.wip3.adobe.com activate-sea.adobe.com pagead2.googlesyndication.com wwis-dubc1-vip60.adobe.com activate-sjc0.adobe.com ![]() Bitte lesen => http://www.trojaner-board.de/95393-c...-software.html Es geht weiter wenn du alles Illegale entfernt hast. Bei wiederholten Crack/Keygen Verstößen behalte ich es mir vor, den Support einzustellen, d.h. Hilfe nur noch bei der Datensicherung und Neuinstallation des Betriebssystems.
__________________ --> Im Browser ist überall Werbung |
![]() | #7 |
![]() ![]() | ![]() Im Browser ist überall Werbung alles entfernt |
![]() | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Im Browser ist überall Werbung Wirklich alles? Alles an Bezahlsoftware von Adobe und evtl andere "geklaute" Software sowie noch etwaig vorhandene Cracks/Keygens? Wenn ja bitte frische Logs mit FRST machen
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #9 | |
![]() ![]() | ![]() Im Browser ist überall WerbungZitat:
Falls noch weiß da sein sollte, bitte darauf aufmerksam machen. Habe es nach besten Wissen und Gewissen entfernt. FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-08-2013 02 Ran by Lila (administrator) on 12-08-2013 12:48:35 Running from C:\Users\Lila\Downloads Windows 7 Professional N Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\Program Files\Lucidlogix Technologies\VIRTU MVP\MVPControlPanel.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Software Security System) C:\Program Files\Lucidlogix Technologies\VIRTU MVP\EKAG20NT.EXE (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (Wacom Technology, Corp.) C:\Windows\system32\WTablet\Wacom_TabletUser.exe (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe (Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\system32\msiexec.exe (Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\Lila\Downloads\FRST64 (1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor) HKLM\...\Run: [VIRTU_MVP_AUTORUN] - C:\Program Files\Lucidlogix Technologies\VIRTU MVP\MVPControlPanel.Exe [3010336 2012-02-05] () HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [6330568 2013-03-21] (ESET) HKCU\...\Run: [monqt] - "C:\Users\Lila\AppData\Roaming\monqt.exe" -autorun [x] HKCU\...\Run: [execzswin] - "C:\Users\Lila\AppData\Roaming\execzswin.exe" -autorun [x] HKCU\...\Run: [Personal ID] - C:\PROGRA~2\COOLSP~1\PERSON~1\PID.EXE [1132984 2013-06-04] (coolspot AG, Düsseldorf) HKCU\...\Run: [Google Update] - C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-06-12] (Google Inc.) MountPoints2: {82158879-8593-11e2-bb98-bc5ff46c2d53} - J:\SETUP.EXE /AUTORUN MountPoints2: {d76096d7-828c-11e2-a2a9-806e6f6e6963} - I:\ASRSetup.exe HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-26] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) AppInit_DLLs: C:\Windows\system32\appinit_dll.dll [475424 2012-02-05] (Lucidlogix Inc.) AppInit_DLLs-x32: C:\Windows\SysWOW64\appinit_dll.dll [429856 2012-02-05] (Lucidlogix Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp SearchScopes: HKLM - DefaultScope value is missing. BHO-x32: LyricsContainer - {cd5dab32-3ff2-4712-8174-368d25f096bf} - C:\Program Files (x86)\LyricsContainer\126.dll (LyricsContainer) Handler: msdaipp - No CLSID Value - Handler-x32: msdaipp - No CLSID Value - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default FF user.js: detected! => C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default\user.js FF Homepage: www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Lila\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Lila\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Extension: No Name - C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF HKCU\...\Firefox\Extensions: [Lyrics@LyricsContainer.co] C:\Program Files (x86)\LyricsContainer\126.xpi FF Extension: No Name - C:\Program Files (x86)\LyricsContainer\126.xpi Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Lila\AppData\Local\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Lila\AppData\Local\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Lila\AppData\Local\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Browser\nppdf32.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Google Update) - C:\Users\Lila\AppData\Local\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll () CHR Extension: (LyricsContainer) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\abfmigjiaapipflmopkaaooigcjjdojh\1.126_0 CHR Extension: (Google Docs) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ CHR Extension: (AdBlock) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.4_0 CHR Extension: (Gmail) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKLM-x32\...\Chrome\Extension: [abfmigjiaapipflmopkaaooigcjjdojh] - C:\Program Files (x86)\LyricsContainer\126.crx ==================== Services (Whitelisted) ================= R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1341664 2013-03-21] (ESET) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] () R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [121344 2012-02-07] () R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 TabletServiceWacom; C:\Windows\system32\Wacom_Tablet.exe [1908520 2007-09-07] (Wacom Technology, Corp.) ==================== Drivers (Whitelisted) ==================== R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-03-05] (DT Soft Ltd) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [213416 2013-02-14] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [150616 2013-01-10] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [190232 2013-01-10] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [59440 2013-01-10] (ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [58416 2013-02-14] (ESET) R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] () R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] () R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [926824 2012-05-14] (Realtek Semiconductor Corporation ) R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-08-12] () S3 cleanhlp; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-12 11:15 - 2013-08-12 11:15 - 00000000 ____D C:\FRST 2013-08-12 11:14 - 2013-08-12 11:14 - 01575246 _____ (Farbar) C:\Users\Lila\Downloads\FRST64.exe 2013-08-11 23:18 - 2013-08-11 23:18 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Lila\Downloads\mbam-setup- 2013-08-11 23:18 - 2013-08-11 23:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-11 23:18 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-11 23:11 - 2013-08-11 23:19 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-11 22:58 - 2013-08-12 11:07 - 00000396 _____ C:\Windows\Tasks\LyricsContainer Update.job 2013-08-11 22:58 - 2013-08-11 22:58 - 00003042 _____ C:\Windows\System32\Tasks\LyricsContainer Update 2013-08-11 22:58 - 2013-08-11 22:58 - 00000000 ____D C:\Program Files (x86)\LyricsContainer 2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\ProgramData\ESET 2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\Program Files\ESET 2013-08-07 22:41 - 2013-08-07 22:41 - 01415824 _____ (ESET) C:\Users\Lila\Downloads\eset_smart_security_live_installer.exe 2013-08-07 22:34 - 2013-08-07 22:35 - 187378056 _____ (Emsisoft GmbH ) C:\Users\Lila\Downloads\EmsisoftAntiMalwareSetup (1).exe 2013-07-28 21:31 - 2013-07-28 21:31 - 00819705 _____ C:\Users\Lila\Downloads\wie_gewinne_ich.rar 2013-07-21 22:33 - 2013-07-21 22:59 - 00000000 ____D C:\Users\Lila\Downloads\Treiber 2013-07-14 00:43 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-14 00:43 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-14 00:43 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-14 00:43 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-14 00:43 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-14 00:43 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-14 00:43 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-14 00:43 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-14 00:43 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-14 00:43 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-14 00:43 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-14 00:43 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-14 00:43 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-14 00:43 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-14 00:43 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-14 00:43 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-14 00:43 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-14 00:43 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-14 00:43 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-14 00:43 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-14 00:43 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-14 00:41 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-14 00:41 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-14 00:41 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-14 00:41 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-14 00:41 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-14 00:40 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-14 00:40 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll ==================== One Month Modified Files and Folders ======= 2013-08-12 12:40 - 2013-03-05 15:15 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-08-12 12:40 - 2013-03-01 20:47 - 00000000 ____D C:\Users\Lila\AppData\Roaming\Adobe 2013-08-12 12:39 - 2013-03-05 15:16 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-08-12 12:39 - 2013-03-01 20:46 - 00000000 ____D C:\ProgramData\Adobe 2013-08-12 12:35 - 2013-03-05 15:15 - 00000000 ____D C:\Users\Lila\AppData\Local\Adobe 2013-08-12 12:32 - 2011-04-12 10:14 - 00653928 _____ C:\Windows\system32\perfh007.dat 2013-08-12 12:32 - 2011-04-12 10:14 - 00129800 _____ C:\Windows\system32\perfc007.dat 2013-08-12 12:32 - 2009-07-14 07:12 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-12 12:23 - 2013-06-12 13:00 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job 2013-08-12 12:23 - 2013-06-12 13:00 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job 2013-08-12 11:18 - 2009-07-14 06:50 - 00020112 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-12 11:18 - 2009-07-14 06:50 - 00020112 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-12 11:15 - 2013-08-12 11:15 - 00000000 ____D C:\FRST 2013-08-12 11:14 - 2013-08-12 11:14 - 01575246 _____ (Farbar) C:\Users\Lila\Downloads\FRST64.exe 2013-08-12 11:07 - 2013-08-11 22:58 - 00000396 _____ C:\Windows\Tasks\LyricsContainer Update.job 2013-08-12 11:07 - 2013-03-01 20:59 - 00000000 ____D C:\Users\Lila\AppData\Roaming\WTablet 2013-08-12 11:07 - 2013-03-01 18:38 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2013-08-12 11:07 - 2013-03-01 18:30 - 01278719 _____ C:\Windows\WindowsUpdate.log 2013-08-12 11:06 - 2013-06-26 02:28 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2013-08-12 11:06 - 2013-03-01 18:40 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys 2013-08-12 11:06 - 2010-11-21 05:47 - 00083888 _____ C:\Windows\PFRO.log 2013-08-12 11:06 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-12 11:06 - 2009-07-14 06:56 - 00047138 _____ C:\Windows\setupact.log 2013-08-12 00:43 - 2013-03-22 21:17 - 00000000 ____D C:\Users\Lila\AppData\Roaming\UseNeXT 2013-08-11 23:19 - 2013-08-11 23:11 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-11 23:18 - 2013-08-11 23:18 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Lila\Downloads\mbam-setup- 2013-08-11 23:18 - 2013-08-11 23:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-11 22:58 - 2013-08-11 22:58 - 00003042 _____ C:\Windows\System32\Tasks\LyricsContainer Update 2013-08-11 22:58 - 2013-08-11 22:58 - 00000000 ____D C:\Program Files (x86)\LyricsContainer 2013-08-11 22:45 - 2013-05-15 20:43 - 00000000 ____D C:\Users\Lila\AppData\Roaming\vlc 2013-08-11 16:26 - 2013-03-01 18:38 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2013-08-11 13:25 - 2013-03-07 20:46 - 00003906 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{AE5A86A8-D88D-40C8-AA45-438AD91DF71B} 2013-08-08 10:25 - 2013-06-27 23:41 - 00000000 ____D C:\Users\Lila\Documents\Anti-Malware 2013-08-08 10:25 - 2013-06-27 23:41 - 00000000 ____D C:\Program Files (x86)\Emsisoft Anti-Malware 2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\ProgramData\ESET 2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\Program Files\ESET 2013-08-07 22:41 - 2013-08-07 22:41 - 01415824 _____ (ESET) C:\Users\Lila\Downloads\eset_smart_security_live_installer.exe 2013-08-07 22:35 - 2013-08-07 22:34 - 187378056 _____ (Emsisoft GmbH ) C:\Users\Lila\Downloads\EmsisoftAntiMalwareSetup (1).exe 2013-08-05 12:29 - 2013-04-06 16:37 - 00000000 ____D C:\ProgramData\CanonIJPLM 2013-08-02 01:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-07-28 21:31 - 2013-07-28 21:31 - 00819705 _____ C:\Users\Lila\Downloads\wie_gewinne_ich.rar 2013-07-21 22:59 - 2013-07-21 22:33 - 00000000 ____D C:\Users\Lila\Downloads\Treiber 2013-07-14 14:18 - 2013-05-02 20:01 - 00000000 ____D C:\Users\Lila\AppData\Local\CrashDumps 2013-07-14 11:27 - 2009-07-14 06:50 - 03045624 _____ C:\Windows\system32\FNTCACHE.DAT 2013-07-14 01:23 - 2011-04-12 10:24 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-14 01:23 - 2009-07-14 07:38 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-14 01:23 - 2009-07-14 07:38 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-14 00:44 - 2013-03-01 18:57 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-07-13 12:18 - 2013-06-12 13:00 - 00004084 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA 2013-07-13 12:18 - 2013-06-12 13:00 - 00003688 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-02 15:09 ==================== End Of Log ============================ --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2013 02 Ran by Lila at 2013-08-12 12:53:39 Running from C:\Users\Lila\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 0.0.0) Acrobat.com (x32 Version: 1.2.443) Adobe AIR (x32 Version: Adobe Flash Player 10 ActiveX (x32 Version: Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.202) Adobe Media Player (x32 Version: 0.0.0) Adobe Media Player (x32 Version: 1.1) AMD Accelerated Video Transcoding (Version: AMD APP SDK Runtime (Version: 10.0.1084.4) AMD Catalyst Install Manager (Version: 8.0.903.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.71219.1540) Apple Application Support (x32 Version: 2.3) Apple Software Update (x32 Version: Asmedia ASM106x SATA Host Controller Driver (x32 Version: Canon IJ Scan Utility (x32) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32 Version: 4.0.0) Canon MG2200 series Benutzerregistrierung (x32) Canon MG2200 series MP Drivers (Version: 1.00) Canon MG2200 series On-screen Manual (x32 Version: 7.5.0) Canon My Printer (x32 Version: 3.0.0) Canon Quick Menu (x32 Version: 2.0.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485) Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485) CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485) CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485) CCC Help Czech (x32 Version: 2012.1219.1520.27485) CCC Help Danish (x32 Version: 2012.1219.1520.27485) CCC Help Dutch (x32 Version: 2012.1219.1520.27485) CCC Help English (x32 Version: 2012.1219.1520.27485) CCC Help Finnish (x32 Version: 2012.1219.1520.27485) CCC Help French (x32 Version: 2012.1219.1520.27485) CCC Help German (x32 Version: 2012.1219.1520.27485) CCC Help Greek (x32 Version: 2012.1219.1520.27485) CCC Help Hungarian (x32 Version: 2012.1219.1520.27485) CCC Help Italian (x32 Version: 2012.1219.1520.27485) CCC Help Japanese (x32 Version: 2012.1219.1520.27485) CCC Help Korean (x32 Version: 2012.1219.1520.27485) CCC Help Norwegian (x32 Version: 2012.1219.1520.27485) CCC Help Polish (x32 Version: 2012.1219.1520.27485) CCC Help Portuguese (x32 Version: 2012.1219.1520.27485) CCC Help Russian (x32 Version: 2012.1219.1520.27485) CCC Help Spanish (x32 Version: 2012.1219.1520.27485) CCC Help Swedish (x32 Version: 2012.1219.1520.27485) CCC Help Thai (x32 Version: 2012.1219.1520.27485) CCC Help Turkish (x32 Version: 2012.1219.1520.27485) ccc-utility64 (Version: 2012.1219.1521.27485) DAEMON Tools Lite (x32 Version: Easy Poster Printer (x32 Version: 6.0.0) ESET Smart Security (Version: 6.0.316.1) Google Chrome (HKCU Version: 28.0.1500.95) Intel(R) Control Center (x32 Version: Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: Intel(R) Management Engine Components (x32 Version: Intel(R) OpenCL CPU Runtime (x32) Intel(R) Processor Graphics (x32 Version: Intel(R) Rapid Storage Technology (x32 Version: Intel(R) Smart Connect Technology 2.0 x64 (Version: 2.0.1083.0) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: Intel® Trusted Connect Service Client (Version: 1.23.605.1) LyricsContainer (x32) Malwarebytes Anti-Malware Version (x32 Version: Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Professional Edition 2003 (x32 Version: 11.0.7969.0) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) ock App Charger v1.0.5 Personal ID (x32 Version: Poker 770 (x32) PokerStars.eu (x32) PreFlopper (x32 Version: 2.1.0) QuickTime (x32 Version: Realtek Ethernet Controller Driver (x32 Version: 7.48.823.2011) Realtek High Definition Audio Driver (x32 Version: Secret City (x32 Version: 1.9.4662) Steam (x32 Version: TP-LINK TL-WN821N Driver (x32 Version: 1.2.1) TrackMania Nations Forever (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) UseNeXT by Tangysoft (x32) VIRTU MVP 2.1.110 (Version: 2.1.110) VLC media player 2.0.6 (x32 Version: 2.0.6) Wacom Tablett (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 18-07-2013 14:20:47 Windows Update 25-07-2013 22:40:43 Geplanter Prüfpunkt 02-08-2013 20:07:36 Geplanter Prüfpunkt 07-08-2013 20:28:41 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-03-05 15:25 - 00001173 ____A C:\Windows\system32\Drivers\etc\hosts localhost activate.adobe.com practivate.adobe.com ereg.adobe.com activate.wip3.adobe.com wip3.adobe.com 3dns-3.adobe.com 3dns-2.adobe.com adobe-dns.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com ereg.wip3.adobe.com activate-sea.adobe.com pagead2.googlesyndication.com wwis-dubc1-vip60.adobe.com activate-sjc0.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {220145D2-20B3-4B48-AE44-52D59DE2FAF6} - System32\Tasks\User_Feed_Synchronization-{AE5A86A8-D88D-40C8-AA45-438AD91DF71B} => C:\Windows\system32\msfeedssync.exe [2013-05-22] (Microsoft Corporation) Task: {28336CC1-56F3-4285-84D2-51E7E572B6E6} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {3A95E0EA-4FEB-4A27-882A-D4A0E9043D22} - System32\Tasks\LyricsContainer Update => C:\Program Files (x86)\LyricsContainer\LrcsCtrUpdr.exe [2013-08-09] () Task: {52DB3FE1-FD35-49AE-A798-A031751E05F0} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {557A4CA9-1E48-4C36-8783-1250F4FA44A3} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {79B1D23E-D9E5-44CA-B2B4-EE322E0F6FB2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {9227EDEB-5C17-43F6-AF4C-1B3E91416116} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {CEA0F661-E4EF-4B0C-8174-747271058321} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {EBD67A4D-F364-42F2-94CA-DEA6B10D73FF} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\LyricsContainer Update.job => C:\Program Files (x86)\LyricsContainer\LrcsCtrUpdr.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/12/2013 00:29:03 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (08/12/2013 11:08:38 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 11:06:52 AM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/12/2013 11:06:51 AM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 11:25:23 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 11:23:37 PM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/11/2013 11:23:36 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 09:18:52 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 09:17:06 PM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/11/2013 09:17:05 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 System errors: ============= Error: (08/12/2013 11:06:51 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 11:23:36 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 11:11:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SProtection" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/11/2013 09:17:05 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 01:20:00 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/09/2013 00:36:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/08/2013 10:56:54 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/08/2013 10:24:42 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/07/2013 10:42:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "ESET Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/07/2013 10:36:39 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Microsoft Office Sessions: ========================= Error: (08/12/2013 00:29:03 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestF:\Programme\esetsmartinstaller_enu.exe Error: (08/12/2013 11:08:38 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 11:06:52 AM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/12/2013 11:06:51 AM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 11:25:23 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 11:23:37 PM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/11/2013 11:23:36 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 09:18:52 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 09:17:06 PM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/11/2013 09:17:05 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 ==================== Memory info =========================== Percentage of memory in use: 17% Total physical RAM: 16268.42 MB Available physical RAM: 13374.16 MB Total Pagefile: 32535.03 MB Available Pagefile: 29130.22 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.69 GB) (Free:53.77 GB) NTFS (Disk=0 Partition=2) Drive d: (Volume) (Fixed) (Total:931.51 GB) (Free:891.11 GB) NTFS (Disk=1 Partition=1) Drive e: (Ablage) (Fixed) (Total:10 GB) (Free:1.21 GB) NTFS (Disk=2 Partition=1) Drive f: (Datensammlung) (Fixed) (Total:50.01 GB) (Free:35.01 GB) NTFS (Disk=2 Partition=2) Drive g: (Musik) (Fixed) (Total:100.01 GB) (Free:96.2 GB) NTFS (Disk=2 Partition=3) Drive h: (Down) (Fixed) (Total:305.74 GB) (Free:225.94 GB) NTFS (Disk=2 Partition=4) Drive k: (EOS_DIGITAL) (Removable) (Total:14.93 GB) (Free:8.21 GB) FAT32 (Disk=3 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 862E84D4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: E792C529) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 466 GB) (Disk ID: 086D086C) Partition 1: (Active) - (Size=10 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=456 GB) - (Type=05) ======================================================== Disk: 3 (Size: 15 GB) (Disk ID: 00000000) Partition 1: (Active) - (Size=15 GB) - (Type=0C) ==================== End Of Log ============================ |
![]() | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Im Browser ist überall Werbung Dann bitte jetzt Combofix ausführen: Scan mit Combofix
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #11 |
![]() ![]() | ![]() Im Browser ist überall Werbung so hier nun das Ergebnis von combofix Code:
ATTFilter ComboFix 13-08-12.01 - Lila 12.08.2013 12:58:57.1.4 - x64 Microsoft Windows 7 Professional N 6.1.7601.1.1252.49.1031.18.16268.14082 [GMT 2:00] ausgeführt von:: c:\users\Lila\Desktop\ComboFix.exe AV: ESET Smart Security 6.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1} FW: ESET Personal Firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA} SP: ESET Smart Security 6.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . ((((((((((((((((((((((( Dateien erstellt von 2013-07-12 bis 2013-08-12 )))))))))))))))))))))))))))))) . . 2013-08-12 11:00 . 2013-08-12 11:00 -------- d-----w- c:\users\Lila\AppData\Local\temp 2013-08-12 11:00 . 2013-08-12 11:00 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-08-12 09:15 . 2013-08-12 09:15 -------- d-----w- C:\FRST 2013-08-11 21:18 . 2013-08-11 21:18 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware 2013-08-11 21:18 . 2013-04-04 12:50 25928 ----a-w- c:\windows\system32\drivers\mbam.sys 2013-08-11 20:58 . 2013-08-11 20:58 -------- d-----w- c:\program files (x86)\LyricsContainer 2013-08-07 20:42 . 2013-08-07 20:42 -------- d-----w- c:\program files\ESET 2013-08-07 20:28 . 2013-07-02 08:34 9460976 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{175FD02B-84FF-4450-B92D-0E3A769CA8DD}\mpengine.dll 2013-07-13 22:41 . 2013-06-05 03:34 3153920 ----a-w- c:\windows\system32\win32k.sys 2013-07-13 22:41 . 2013-05-06 06:03 1887744 ----a-w- c:\windows\system32\WMVDECOD.DLL 2013-07-13 22:41 . 2013-05-06 04:56 1620480 ----a-w- c:\windows\SysWow64\WMVDECOD.DLL 2013-07-13 22:41 . 2013-06-04 06:00 624128 ----a-w- c:\windows\system32\qedit.dll 2013-07-13 22:41 . 2013-06-04 04:53 509440 ----a-w- c:\windows\SysWow64\qedit.dll . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2013-08-12 09:06 . 2013-06-26 00:28 94656 ----a-w- c:\windows\system32\WPRO_41_2001woem.tmp 2013-08-12 09:06 . 2013-03-01 16:40 34752 ----a-w- c:\windows\system32\drivers\WPRO_41_2001.sys 2013-07-13 22:44 . 2013-03-01 16:57 78185248 ----a-w- c:\windows\system32\MRT.exe 2013-06-04 00:09 . 2013-03-01 18:47 404920 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2013-05-28 13:49 . 2013-03-01 18:47 692104 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2013-05-22 14:48 . 2013-05-22 14:48 73728 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2013-05-22 14:48 . 2013-05-22 14:48 719360 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2013-05-22 14:48 . 2013-05-22 14:48 61952 ----a-w- c:\windows\SysWow64\tdc.ocx 2013-05-22 14:48 . 2013-05-22 14:48 523264 ----a-w- c:\windows\SysWow64\vbscript.dll 2013-05-22 14:48 . 2013-05-22 14:48 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2013-05-22 14:48 . 2013-05-22 14:48 38400 ----a-w- c:\windows\SysWow64\imgutil.dll 2013-05-22 14:48 . 2013-05-22 14:48 361984 ----a-w- c:\windows\SysWow64\html.iec 2013-05-22 14:48 . 2013-05-22 14:48 226304 ----a-w- c:\windows\system32\elshyph.dll 2013-05-22 14:48 . 2013-05-22 14:48 185344 ----a-w- c:\windows\SysWow64\elshyph.dll 2013-05-22 14:48 . 2013-05-22 14:48 158720 ----a-w- c:\windows\SysWow64\msls31.dll 2013-05-22 14:48 . 2013-05-22 14:48 150528 ----a-w- c:\windows\SysWow64\iexpress.exe 2013-05-22 14:48 . 2013-05-22 14:48 1441280 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2013-05-22 14:48 . 2013-05-22 14:48 138752 ----a-w- c:\windows\SysWow64\wextract.exe 2013-05-22 14:48 . 2013-05-22 14:48 137216 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2013-05-22 14:48 . 2013-05-22 14:48 12800 ----a-w- c:\windows\SysWow64\mshta.exe 2013-05-22 14:48 . 2013-05-22 14:48 110592 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2013-05-22 14:48 . 2013-05-22 14:48 1054720 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2013-05-22 14:48 . 2013-05-22 14:48 97280 ----a-w- c:\windows\system32\mshtmled.dll 2013-05-22 14:48 . 2013-05-22 14:48 92160 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2013-05-22 14:48 . 2013-05-22 14:48 905728 ----a-w- c:\windows\system32\mshtmlmedia.dll 2013-05-22 14:48 . 2013-05-22 14:48 81408 ----a-w- c:\windows\system32\icardie.dll 2013-05-22 14:48 . 2013-05-22 14:48 77312 ----a-w- c:\windows\system32\tdc.ocx 2013-05-22 14:48 . 2013-05-22 14:48 762368 ----a-w- c:\windows\system32\ieapfltr.dll 2013-05-22 14:48 . 2013-05-22 14:48 62976 ----a-w- c:\windows\system32\pngfilt.dll 2013-05-22 14:48 . 2013-05-22 14:48 599552 ----a-w- c:\windows\system32\vbscript.dll 2013-05-22 14:48 . 2013-05-22 14:48 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2013-05-22 14:48 . 2013-05-22 14:48 51200 ----a-w- c:\windows\system32\imgutil.dll 2013-05-22 14:48 . 2013-05-22 14:48 48640 ----a-w- c:\windows\system32\mshtmler.dll 2013-05-22 14:48 . 2013-05-22 14:48 452096 ----a-w- c:\windows\system32\dxtmsft.dll 2013-05-22 14:48 . 2013-05-22 14:48 441856 ----a-w- c:\windows\system32\html.iec 2013-05-22 14:48 . 2013-05-22 14:48 281600 ----a-w- c:\windows\system32\dxtrans.dll 2013-05-22 14:48 . 2013-05-22 14:48 27648 ----a-w- c:\windows\system32\licmgr10.dll 2013-05-22 14:48 . 2013-05-22 14:48 270848 ----a-w- c:\windows\system32\iedkcs32.dll 2013-05-22 14:48 . 2013-05-22 14:48 247296 ----a-w- c:\windows\system32\webcheck.dll 2013-05-22 14:48 . 2013-05-22 14:48 235008 ----a-w- c:\windows\system32\url.dll 2013-05-22 14:48 . 2013-05-22 14:48 23040 ----a-w- c:\windows\SysWow64\licmgr10.dll 2013-05-22 14:48 . 2013-05-22 14:48 216064 ----a-w- c:\windows\system32\msls31.dll 2013-05-22 14:48 . 2013-05-22 14:48 197120 ----a-w- c:\windows\system32\msrating.dll 2013-05-22 14:48 . 2013-05-22 14:48 173568 ----a-w- c:\windows\system32\ieUnatt.exe 2013-05-22 14:48 . 2013-05-22 14:48 167424 ----a-w- c:\windows\system32\iexpress.exe 2013-05-22 14:48 . 2013-05-22 14:48 1509376 ----a-w- c:\windows\system32\inetcpl.cpl 2013-05-22 14:48 . 2013-05-22 14:48 149504 ----a-w- c:\windows\system32\occache.dll 2013-05-22 14:48 . 2013-05-22 14:48 144896 ----a-w- c:\windows\system32\wextract.exe 2013-05-22 14:48 . 2013-05-22 14:48 1400416 ----a-w- c:\windows\system32\ieapfltr.dat 2013-05-22 14:48 . 2013-05-22 14:48 13824 ----a-w- c:\windows\system32\mshta.exe 2013-05-22 14:48 . 2013-05-22 14:48 136192 ----a-w- c:\windows\system32\iepeers.dll 2013-05-22 14:48 . 2013-05-22 14:48 135680 ----a-w- c:\windows\system32\IEAdvpack.dll 2013-05-22 14:48 . 2013-05-22 14:48 12800 ----a-w- c:\windows\system32\msfeedssync.exe 2013-05-22 14:48 . 2013-05-22 14:48 102912 ----a-w- c:\windows\system32\inseng.dll 2013-05-22 14:48 . 2013-05-22 14:48 9728 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 9728 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 5632 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 5632 ---ha-w- c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 522752 ----a-w- c:\windows\system32\XpsGdiConverter.dll 2013-05-22 14:48 . 2013-05-22 14:48 465920 ----a-w- c:\windows\system32\WMPhoto.dll 2013-05-22 14:48 . 2013-05-22 14:48 417792 ----a-w- c:\windows\SysWow64\WMPhoto.dll 2013-05-22 14:48 . 2013-05-22 14:48 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 4096 ---ha-w- c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 3928064 ----a-w- c:\windows\system32\d2d1.dll 2013-05-22 14:48 . 2013-05-22 14:48 364544 ----a-w- c:\windows\SysWow64\XpsGdiConverter.dll 2013-05-22 14:48 . 2013-05-22 14:48 3584 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 3584 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 3072 ---ha-w- c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 2776576 ----a-w- c:\windows\system32\msmpeg2vdec.dll 2013-05-22 14:48 . 2013-05-22 14:48 2565120 ----a-w- c:\windows\system32\d3d10warp.dll 2013-05-22 14:48 . 2013-05-22 14:48 2560 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 2560 ---ha-w- c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 2284544 ----a-w- c:\windows\SysWow64\msmpeg2vdec.dll 2013-05-22 14:48 . 2013-05-22 14:48 1682432 ----a-w- c:\windows\system32\XpsPrint.dll 2013-05-22 14:48 . 2013-05-22 14:48 1158144 ----a-w- c:\windows\SysWow64\XpsPrint.dll 2013-05-22 14:48 . 2013-05-22 14:48 10752 ---ha-w- c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 10752 ---ha-w- c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll 2013-05-22 14:48 . 2013-05-22 14:48 648192 ----a-w- c:\windows\system32\d3d10level9.dll 2013-05-22 14:48 . 2013-05-22 14:48 604160 ----a-w- c:\windows\SysWow64\d3d10level9.dll 2013-05-22 14:48 . 2013-05-22 14:48 363008 ----a-w- c:\windows\system32\dxgi.dll 2013-05-22 14:48 . 2013-05-22 14:48 3419136 ----a-w- c:\windows\SysWow64\d2d1.dll 2013-05-22 14:48 . 2013-05-22 14:48 333312 ----a-w- c:\windows\system32\d3d10_1core.dll 2013-05-22 14:48 . 2013-05-22 14:48 296960 ----a-w- c:\windows\system32\d3d10core.dll 2013-05-22 14:48 . 2013-05-22 14:48 249856 ----a-w- c:\windows\SysWow64\d3d10_1core.dll 2013-05-22 14:48 . 2013-05-22 14:48 245248 ----a-w- c:\windows\system32\WindowsCodecsExt.dll 2013-05-22 14:48 . 2013-05-22 14:48 220160 ----a-w- c:\windows\SysWow64\d3d10core.dll 2013-05-22 14:48 . 2013-05-22 14:48 207872 ----a-w- c:\windows\SysWow64\WindowsCodecsExt.dll 2013-05-22 14:48 . 2013-05-22 14:48 194560 ----a-w- c:\windows\system32\d3d10_1.dll 2013-05-22 14:48 . 2013-05-22 14:48 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll 2013-05-22 14:48 . 2013-05-22 14:48 1238528 ----a-w- c:\windows\system32\d3d10.dll 2013-05-22 14:48 . 2013-05-22 14:48 1175552 ----a-w- c:\windows\system32\FntCache.dll 2013-05-22 14:48 . 2013-05-22 14:48 1080832 ----a-w- c:\windows\SysWow64\d3d10.dll 2013-05-22 14:48 . 2013-05-22 14:48 293376 ----a-w- c:\windows\SysWow64\dxgi.dll 2013-05-22 14:48 . 2013-05-22 14:48 221184 ----a-w- c:\windows\system32\UIAnimation.dll 2013-05-22 14:48 . 2013-05-22 14:48 1988096 ----a-w- c:\windows\SysWow64\d3d10warp.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{cd5dab32-3ff2-4712-8174-368d25f096bf}] 2013-08-09 15:16 134656 ----a-w- c:\program files (x86)\LyricsContainer\126.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584] "Personal ID"="c:\progra~2\COOLSP~1\PERSON~1\PID.EXE" [2013-06-04 1132984] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-11-29 284440] "USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-26 291608] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\appinit_dll.dll . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x] R3 cleanhlp;cleanhlp;c:\program files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys;c:\program files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [x] R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys;c:\windows\SYSNATIVE\DRIVERS\asahci64.sys [x] S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x] S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x] S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AsrAppCharger.sys [x] S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x] S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x] S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x] S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x] S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x] S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x] S2 ISCTAgent;ISCT Always Updated Agent;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [x] S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x] S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x] S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x] S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe;c:\windows\SYSNATIVE\Wacom_Tablet.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 ikbevent;Intel Upper keyboard Class Filter Driver;c:\windows\system32\DRIVERS\ikbevent.sys;c:\windows\SYSNATIVE\DRIVERS\ikbevent.sys [x] S3 imsevent;Intel Upper Mouse Class Filter Driver;c:\windows\system32\DRIVERS\imsevent.sys;c:\windows\SYSNATIVE\DRIVERS\imsevent.sys [x] S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD64.sys [x] S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x] S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x] S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x] S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 RTL8192cu;300Mbps Wireless USB Adapter;c:\windows\system32\DRIVERS\RTL8192cu.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192cu.sys [x] S3 VirtuWDDM;VirtuWDDM;c:\windows\system32\DRIVERS\VirtuWDDM.sys;c:\windows\SYSNATIVE\DRIVERS\VirtuWDDM.sys [x] S3 WPRO_41_2001;WinPcap Packet Driver (WPRO_41_2001);c:\windows\system32\drivers\WPRO_41_2001.sys;c:\windows\SYSNATIVE\drivers\WPRO_41_2001.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2013-08-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job - c:\users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12 11:00] . 2013-08-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job - c:\users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12 11:00] . 2013-08-12 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job - c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 12:41] . 2013-08-11 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job - c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 12:41] . 2013-08-12 c:\windows\Tasks\LyricsContainer Update.job - c:\program files (x86)\LyricsContainer\LrcsCtrUpdr.exe [2013-08-09 15:16] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-12 170264] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-12 398104] "Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-12 440600] "RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496] "egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2013-03-21 6330568] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\appinit_dll.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = FF - ProfilePath - c:\users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default\ FF - prefs.js: browser.startup.homepage - www.google.de/ FF - ExtSQL: 2013-08-11 22:58; Lyrics@LyricsContainer.co; c:\program files (x86)\LyricsContainer\126.xpi FF - user.js: extensions.autoDisableScopes - 0 FF - user.js: extensions.shownSelectionUI - true . . ------- Dateityp-Verknüpfung ------- . .txt= . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Wow6432Node-HKCU-Run-monqt - c:\users\Lila\AppData\Roaming\monqt.exe Wow6432Node-HKCU-Run-execzswin - c:\users\Lila\AppData\Roaming\execzswin.exe SafeBoot-CleanHlp SafeBoot-CleanHlp.sys HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start HKLM-Run-VIRTU_MVP_AUTORUN - c:\program files (x86)\Lucidlogix Technologies\VIRTU MVP\MVPControlPanel.Exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10zi_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10zi_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10zi.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10zi.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10zi.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10zi.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-08-12 13:01:48 ComboFix-quarantined-files.txt 2013-08-12 11:01 . Vor Suchlauf: 10 Verzeichnis(se), Bytes frei Nach Suchlauf: 14 Verzeichnis(se), 61.460.643.840 Bytes frei . - - End Of File - - D235FC345398072FF3AC0596D9F0DC15 D41D8CD98F00B204E9800998ECF8427E |
![]() | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Im Browser ist überall Werbung Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte ![]()
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #13 |
![]() ![]() | ![]() Im Browser ist überall Werbung Hier nun die Ergebnisse Code:
ATTFilter # AdwCleaner v2.306 - Datei am 12/08/2013 um 13:34:23 erstellt # Aktualisiert am 19/07/2013 von Xplode # Betriebssystem : Windows 7 Professional N Service Pack 1 (64 bits) # Benutzer : Lila - LEX # Bootmodus : Normal # Ausgeführt unter : C:\Users\Lila\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Windows\Tasks\LyricsContainer Update.job Ordner Gelöscht : C:\Program Files (x86)\LyricsContainer Ordner Gelöscht : C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\abfmigjiaapipflmopkaaooigcjjdojh ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\LyricsContainer Schlüssel Gelöscht : HKCU\Software\Iminent Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Schlüssel Gelöscht : HKLM\Software\Iminent Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\abfmigjiaapipflmopkaaooigcjjdojh Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Lyrics@LyricsContainer.co Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} ***** [Internet Browser] ***** -\\ Internet Explorer v10.0.9200.16635 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v22.0 (de) Datei : C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default\prefs.js C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default\user.js ... Gelöscht ! [OK] Die Datei ist sauber. -\\ Google Chrome v28.0.1500.95 Datei : C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] Die Datei ist sauber. ************************* AdwCleaner[S1].txt - [11006 octets] - [12/08/2013 13:34:23] ########## EOF - C:\AdwCleaner[S1].txt - [11067 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.4.4 (08.12.2013:1) OS: Windows 7 Professional N x64 Ran by Lila on 12.08.2013 at 13:38:50,52 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cd5dab32-3ff2-4712-8174-368d25f096bf} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{cd5dab32-3ff2-4712-8174-368d25f096bf} ~~~ Files ~~~ Folders ~~~ FireFox Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\\lyrics@lyricscontainer.co Emptied folder: C:\Users\Lila\AppData\Roaming\mozilla\firefox\profiles\jraj9lj2.default\minidumps [13 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12.08.2013 at 13:41:44,99 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-08-2013 02 Ran by Lila (administrator) on 12-08-2013 13:42:16 Running from C:\Users\Lila\Downloads Windows 7 Professional N Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\system32\atiesrxx.exe (AMD) C:\Windows\system32\atieclxx.exe (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE (ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe () C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe () C:\Program Files\Lucidlogix Technologies\VIRTU MVP\MVPControlPanel.exe (ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.exe (Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Wacom Technology, Corp.) C:\Windows\system32\WTablet\Wacom_TabletUser.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.exe (Software Security System) C:\Program Files\Lucidlogix Technologies\VIRTU MVP\EKAG20NT.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe (Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor) HKLM\...\Run: [VIRTU_MVP_AUTORUN] - C:\Program Files\Lucidlogix Technologies\VIRTU MVP\MVPControlPanel.Exe [3010336 2012-02-05] () HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [6330568 2013-03-21] (ESET) HKCU\...\Run: [Personal ID] - C:\PROGRA~2\COOLSP~1\PERSON~1\PID.EXE [1132984 2013-06-04] (coolspot AG, Düsseldorf) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-26] (Intel Corporation) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.) AppInit_DLLs: C:\Windows\System32\appinit_dll.dll [475424 2012-02-05] (Lucidlogix Inc.) AppInit_DLLs-x32: C:\Windows\SysWOW64\appinit_dll.dll [429856 2012-02-05] (Lucidlogix Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope value is missing. Handler: msdaipp - No CLSID Value - Handler-x32: msdaipp - No CLSID Value - Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} - No File Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default FF Homepage: www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll () FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Lila\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Lila\AppData\Local\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Extension: No Name - C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird Chrome: ======= CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding} CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter} CHR Plugin: (Shockwave Flash) - C:\Users\Lila\AppData\Local\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Lila\AppData\Local\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Lila\AppData\Local\Google\Chrome\Application\28.0.1500.95\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Browser\nppdf32.dll No File CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.) CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Google Update) - C:\Users\Lila\AppData\Local\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll () CHR Extension: (Google Docs) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (YouTube) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ CHR Extension: (AdBlock) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.4_0 CHR Extension: (Gmail) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 ==================== Services (Whitelisted) ================= R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1341664 2013-03-21] (ESET) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] () R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [121344 2012-02-07] () R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] () R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation) R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 TabletServiceWacom; C:\Windows\system32\Wacom_Tablet.exe [1908520 2007-09-07] (Wacom Technology, Corp.) ==================== Drivers (Whitelisted) ==================== R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology) R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-03-05] (DT Soft Ltd) R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [213416 2013-02-14] (ESET) R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [150616 2013-01-10] (ESET) R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [190232 2013-01-10] (ESET) R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [59440 2013-01-10] (ESET) R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [58416 2013-02-14] (ESET) R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] () R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] () R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] () R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [926824 2012-05-14] (Realtek Semiconductor Corporation ) R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-08-12] () S3 cleanhlp; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-08-12 13:38 - 2013-08-12 13:38 - 00000000 ____D C:\Windows\ERUNT 2013-08-12 13:37 - 2013-08-12 13:37 - 00011051 _____ C:\Users\Lila\Desktop\AdwCleaner[S1].txt 2013-08-12 13:34 - 2013-08-12 13:34 - 00011051 _____ C:\AdwCleaner[S1].txt 2013-08-12 13:31 - 2013-08-12 13:31 - 00959697 _____ (Oleg N. Scherbakov) C:\Users\Lila\Desktop\JRT.exe 2013-08-12 13:30 - 2013-08-12 13:30 - 00666633 _____ C:\Users\Lila\Desktop\adwcleaner.exe 2013-08-12 13:01 - 2013-08-12 13:01 - 00024632 _____ C:\ComboFix.txt 2013-08-12 12:58 - 2013-08-12 13:01 - 00000000 ____D C:\Windows\erdnt 2013-08-12 12:58 - 2013-08-12 13:01 - 00000000 ____D C:\Qoobox 2013-08-12 12:58 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe 2013-08-12 12:58 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe 2013-08-12 12:58 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-08-12 12:58 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-08-12 12:58 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-08-12 12:58 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe 2013-08-12 12:58 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe 2013-08-12 12:58 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe 2013-08-12 12:56 - 2013-08-12 12:56 - 05102975 ____R (Swearware) C:\Users\Lila\Desktop\ComboFix.exe 2013-08-12 12:56 - 2013-08-12 12:56 - 05102975 _____ (Swearware) C:\Users\Lila\Downloads\ComboFix (1).exe 2013-08-12 12:53 - 2013-08-12 12:53 - 00017951 _____ C:\Users\Lila\Downloads\Addition.txt 2013-08-12 12:48 - 2013-08-12 12:48 - 01575246 _____ (Farbar) C:\Users\Lila\Downloads\FRST64 (1).exe 2013-08-12 11:15 - 2013-08-12 11:15 - 00000000 ____D C:\FRST 2013-08-12 11:14 - 2013-08-12 11:14 - 01575246 _____ (Farbar) C:\Users\Lila\Downloads\FRST64.exe 2013-08-11 23:18 - 2013-08-11 23:18 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Lila\Downloads\mbam-setup- 2013-08-11 23:18 - 2013-08-11 23:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-11 23:18 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2013-08-11 23:11 - 2013-08-11 23:19 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\ProgramData\ESET 2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\Program Files\ESET 2013-08-07 22:41 - 2013-08-07 22:41 - 01415824 _____ (ESET) C:\Users\Lila\Downloads\eset_smart_security_live_installer.exe 2013-08-07 22:34 - 2013-08-07 22:35 - 187378056 _____ (Emsisoft GmbH ) C:\Users\Lila\Downloads\EmsisoftAntiMalwareSetup (1).exe 2013-07-28 21:31 - 2013-07-28 21:31 - 00819705 _____ C:\Users\Lila\Downloads\wie_gewinne_ich.rar 2013-07-21 22:33 - 2013-07-21 22:59 - 00000000 ____D C:\Users\Lila\Downloads\Treiber 2013-07-14 00:43 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-07-14 00:43 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-07-14 00:43 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-07-14 00:43 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-07-14 00:43 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-07-14 00:43 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-07-14 00:43 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-07-14 00:43 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-07-14 00:43 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-07-14 00:43 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-07-14 00:43 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-07-14 00:43 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-07-14 00:43 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-07-14 00:43 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-07-14 00:43 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-07-14 00:43 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-07-14 00:43 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-07-14 00:43 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-07-14 00:43 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-07-14 00:43 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-07-14 00:43 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-07-14 00:43 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-07-14 00:41 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2013-07-14 00:41 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll 2013-07-14 00:41 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll 2013-07-14 00:41 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL 2013-07-14 00:41 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL 2013-07-14 00:40 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll 2013-07-14 00:40 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll ==================== One Month Modified Files and Folders ======= 2013-08-12 13:41 - 2013-08-12 13:41 - 00001151 _____ C:\Users\Lila\Desktop\JRT.txt 2013-08-12 13:38 - 2013-08-12 13:38 - 00000000 ____D C:\Windows\ERUNT 2013-08-12 13:38 - 2009-07-14 06:50 - 00020112 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-08-12 13:38 - 2009-07-14 06:50 - 00020112 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-08-12 13:37 - 2013-08-12 13:37 - 00011051 _____ C:\Users\Lila\Desktop\AdwCleaner[S1].txt 2013-08-12 13:36 - 2013-06-26 02:28 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp 2013-08-12 13:36 - 2013-03-01 20:59 - 00000000 ____D C:\Users\Lila\AppData\Roaming\WTablet 2013-08-12 13:36 - 2013-03-01 18:40 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys 2013-08-12 13:36 - 2013-03-01 18:38 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2013-08-12 13:36 - 2013-03-01 18:37 - 00064064 _____ C:\Users\Lila\AppData\Local\GDIPFONTCACHEV1.DAT 2013-08-12 13:36 - 2013-03-01 18:30 - 01287398 _____ C:\Windows\WindowsUpdate.log 2013-08-12 13:36 - 2010-11-21 05:47 - 00085674 _____ C:\Windows\PFRO.log 2013-08-12 13:36 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-08-12 13:36 - 2009-07-14 06:56 - 00047194 _____ C:\Windows\setupact.log 2013-08-12 13:36 - 2009-07-14 06:50 - 03038176 _____ C:\Windows\system32\FNTCACHE.DAT 2013-08-12 13:34 - 2013-08-12 13:34 - 00011051 _____ C:\AdwCleaner[S1].txt 2013-08-12 13:31 - 2013-08-12 13:31 - 00959697 _____ (Oleg N. Scherbakov) C:\Users\Lila\Desktop\JRT.exe 2013-08-12 13:30 - 2013-08-12 13:30 - 00666633 _____ C:\Users\Lila\Desktop\adwcleaner.exe 2013-08-12 13:23 - 2013-06-12 13:00 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job 2013-08-12 13:01 - 2013-08-12 13:01 - 00024632 _____ C:\ComboFix.txt 2013-08-12 13:01 - 2013-08-12 12:58 - 00000000 ____D C:\Windows\erdnt 2013-08-12 13:01 - 2013-08-12 12:58 - 00000000 ____D C:\Qoobox 2013-08-12 13:01 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini 2013-08-12 12:56 - 2013-08-12 12:56 - 05102975 ____R (Swearware) C:\Users\Lila\Desktop\ComboFix.exe 2013-08-12 12:56 - 2013-08-12 12:56 - 05102975 _____ (Swearware) C:\Users\Lila\Downloads\ComboFix (1).exe 2013-08-12 12:53 - 2013-08-12 12:53 - 00017951 _____ C:\Users\Lila\Downloads\Addition.txt 2013-08-12 12:48 - 2013-08-12 12:48 - 01575246 _____ (Farbar) C:\Users\Lila\Downloads\FRST64 (1).exe 2013-08-12 12:40 - 2013-03-05 15:15 - 00000000 ____D C:\Program Files (x86)\Adobe 2013-08-12 12:40 - 2013-03-01 20:47 - 00000000 ____D C:\Users\Lila\AppData\Roaming\Adobe 2013-08-12 12:39 - 2013-03-05 15:16 - 00000000 ____D C:\Program Files\Common Files\Adobe 2013-08-12 12:39 - 2013-03-01 20:46 - 00000000 ____D C:\ProgramData\Adobe 2013-08-12 12:35 - 2013-03-05 15:15 - 00000000 ____D C:\Users\Lila\AppData\Local\Adobe 2013-08-12 12:32 - 2011-04-12 10:14 - 00653928 _____ C:\Windows\system32\perfh007.dat 2013-08-12 12:32 - 2011-04-12 10:14 - 00129800 _____ C:\Windows\system32\perfc007.dat 2013-08-12 12:32 - 2009-07-14 07:12 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2013-08-12 12:23 - 2013-06-12 13:00 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job 2013-08-12 11:15 - 2013-08-12 11:15 - 00000000 ____D C:\FRST 2013-08-12 11:14 - 2013-08-12 11:14 - 01575246 _____ (Farbar) C:\Users\Lila\Downloads\FRST64.exe 2013-08-12 00:43 - 2013-03-22 21:17 - 00000000 ____D C:\Users\Lila\AppData\Roaming\UseNeXT 2013-08-11 23:19 - 2013-08-11 23:11 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog 2013-08-11 23:18 - 2013-08-11 23:18 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Lila\Downloads\mbam-setup- 2013-08-11 23:18 - 2013-08-11 23:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2013-08-11 22:45 - 2013-05-15 20:43 - 00000000 ____D C:\Users\Lila\AppData\Roaming\vlc 2013-08-11 16:26 - 2013-03-01 18:38 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2013-08-11 13:25 - 2013-03-07 20:46 - 00003906 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{AE5A86A8-D88D-40C8-AA45-438AD91DF71B} 2013-08-08 10:25 - 2013-06-27 23:41 - 00000000 ____D C:\Users\Lila\Documents\Anti-Malware 2013-08-08 10:25 - 2013-06-27 23:41 - 00000000 ____D C:\Program Files (x86)\Emsisoft Anti-Malware 2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\ProgramData\ESET 2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\Program Files\ESET 2013-08-07 22:41 - 2013-08-07 22:41 - 01415824 _____ (ESET) C:\Users\Lila\Downloads\eset_smart_security_live_installer.exe 2013-08-07 22:35 - 2013-08-07 22:34 - 187378056 _____ (Emsisoft GmbH ) C:\Users\Lila\Downloads\EmsisoftAntiMalwareSetup (1).exe 2013-08-05 12:29 - 2013-04-06 16:37 - 00000000 ____D C:\ProgramData\CanonIJPLM 2013-08-02 01:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF 2013-07-28 21:31 - 2013-07-28 21:31 - 00819705 _____ C:\Users\Lila\Downloads\wie_gewinne_ich.rar 2013-07-21 22:59 - 2013-07-21 22:33 - 00000000 ____D C:\Users\Lila\Downloads\Treiber 2013-07-14 14:18 - 2013-05-02 20:01 - 00000000 ____D C:\Users\Lila\AppData\Local\CrashDumps 2013-07-14 01:23 - 2011-04-12 10:24 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-14 01:23 - 2009-07-14 07:38 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-14 01:23 - 2009-07-14 07:38 - 00000000 ____D C:\Program Files (x86)\Windows Defender 2013-07-14 00:44 - 2013-03-01 18:57 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-07-13 12:18 - 2013-06-12 13:00 - 00004084 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA 2013-07-13 12:18 - 2013-06-12 13:00 - 00003688 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-08-02 15:09 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2013 02 Ran by Lila at 2013-08-12 13:42:29 Running from C:\Users\Lila\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 0.0.0) Acrobat.com (x32 Version: 1.2.443) Adobe AIR (x32 Version: Adobe Flash Player 10 ActiveX (x32 Version: Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.202) Adobe Media Player (x32 Version: 0.0.0) Adobe Media Player (x32 Version: 1.1) AMD Accelerated Video Transcoding (Version: AMD APP SDK Runtime (Version: 10.0.1084.4) AMD Catalyst Install Manager (Version: 8.0.903.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.71219.1540) Apple Application Support (x32 Version: 2.3) Apple Software Update (x32 Version: Asmedia ASM106x SATA Host Controller Driver (x32 Version: Canon IJ Scan Utility (x32) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32 Version: 4.0.0) Canon MG2200 series Benutzerregistrierung (x32) Canon MG2200 series MP Drivers (Version: 1.00) Canon MG2200 series On-screen Manual (x32 Version: 7.5.0) Canon My Printer (x32 Version: 3.0.0) Canon Quick Menu (x32 Version: 2.0.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485) Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485) CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485) CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485) CCC Help Czech (x32 Version: 2012.1219.1520.27485) CCC Help Danish (x32 Version: 2012.1219.1520.27485) CCC Help Dutch (x32 Version: 2012.1219.1520.27485) CCC Help English (x32 Version: 2012.1219.1520.27485) CCC Help Finnish (x32 Version: 2012.1219.1520.27485) CCC Help French (x32 Version: 2012.1219.1520.27485) CCC Help German (x32 Version: 2012.1219.1520.27485) CCC Help Greek (x32 Version: 2012.1219.1520.27485) CCC Help Hungarian (x32 Version: 2012.1219.1520.27485) CCC Help Italian (x32 Version: 2012.1219.1520.27485) CCC Help Japanese (x32 Version: 2012.1219.1520.27485) CCC Help Korean (x32 Version: 2012.1219.1520.27485) CCC Help Norwegian (x32 Version: 2012.1219.1520.27485) CCC Help Polish (x32 Version: 2012.1219.1520.27485) CCC Help Portuguese (x32 Version: 2012.1219.1520.27485) CCC Help Russian (x32 Version: 2012.1219.1520.27485) CCC Help Spanish (x32 Version: 2012.1219.1520.27485) CCC Help Swedish (x32 Version: 2012.1219.1520.27485) CCC Help Thai (x32 Version: 2012.1219.1520.27485) CCC Help Turkish (x32 Version: 2012.1219.1520.27485) ccc-utility64 (Version: 2012.1219.1521.27485) DAEMON Tools Lite (x32 Version: Easy Poster Printer (x32 Version: 6.0.0) ESET Smart Security (Version: 6.0.316.1) Google Chrome (HKCU Version: 28.0.1500.95) Intel(R) Control Center (x32 Version: Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: Intel(R) Management Engine Components (x32 Version: Intel(R) OpenCL CPU Runtime (x32) Intel(R) Processor Graphics (x32 Version: Intel(R) Rapid Storage Technology (x32 Version: Intel(R) Smart Connect Technology 2.0 x64 (Version: 2.0.1083.0) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: Intel® Trusted Connect Service Client (Version: 1.23.605.1) Malwarebytes Anti-Malware Version (x32 Version: Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Professional Edition 2003 (x32 Version: 11.0.7969.0) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) ock App Charger v1.0.5 Personal ID (x32 Version: Poker 770 (x32) PokerStars.eu (x32) PreFlopper (x32 Version: 2.1.0) QuickTime (x32 Version: Realtek Ethernet Controller Driver (x32 Version: 7.48.823.2011) Realtek High Definition Audio Driver (x32 Version: Secret City (x32 Version: 1.9.4662) Steam (x32 Version: TP-LINK TL-WN821N Driver (x32 Version: 1.2.1) TrackMania Nations Forever (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) UseNeXT by Tangysoft (x32) VIRTU MVP 2.1.110 (Version: 2.1.110) VLC media player 2.0.6 (x32 Version: 2.0.6) Wacom Tablett (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 02-08-2013 20:07:36 Geplanter Prüfpunkt 07-08-2013 20:28:41 Windows Update 12-08-2013 10:58:27 ComboFix created restore point ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-03-05 15:25 - 00001173 ____A C:\Windows\system32\Drivers\etc\hosts localhost activate.adobe.com practivate.adobe.com ereg.adobe.com activate.wip3.adobe.com wip3.adobe.com 3dns-3.adobe.com 3dns-2.adobe.com adobe-dns.adobe.com adobe-dns-2.adobe.com adobe-dns-3.adobe.com ereg.wip3.adobe.com activate-sea.adobe.com pagead2.googlesyndication.com wwis-dubc1-vip60.adobe.com activate-sjc0.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {220145D2-20B3-4B48-AE44-52D59DE2FAF6} - System32\Tasks\User_Feed_Synchronization-{AE5A86A8-D88D-40C8-AA45-438AD91DF71B} => C:\Windows\system32\msfeedssync.exe [2013-05-22] (Microsoft Corporation) Task: {28336CC1-56F3-4285-84D2-51E7E572B6E6} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {52DB3FE1-FD35-49AE-A798-A031751E05F0} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {694C5397-481C-4398-A94D-41EEC64F746A} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {79B1D23E-D9E5-44CA-B2B4-EE322E0F6FB2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {9227EDEB-5C17-43F6-AF4C-1B3E91416116} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {CEA0F661-E4EF-4B0C-8174-747271058321} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {EBD67A4D-F364-42F2-94CA-DEA6B10D73FF} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 14% Total physical RAM: 16268.42 MB Available physical RAM: 13925.38 MB Total Pagefile: 32535.03 MB Available Pagefile: 29893.45 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.69 GB) (Free:57.26 GB) NTFS (Disk=0 Partition=2) Drive d: (Volume) (Fixed) (Total:931.51 GB) (Free:891.19 GB) NTFS (Disk=1 Partition=1) Drive e: (Ablage) (Fixed) (Total:10 GB) (Free:1.32 GB) NTFS (Disk=2 Partition=1) Drive f: (Datensammlung) (Fixed) (Total:50.01 GB) (Free:35.01 GB) NTFS (Disk=2 Partition=2) Drive g: (Musik) (Fixed) (Total:100.01 GB) (Free:96.21 GB) NTFS (Disk=2 Partition=3) Drive h: (Down) (Fixed) (Total:305.74 GB) (Free:225.94 GB) NTFS (Disk=2 Partition=4) Drive k: (EOS_DIGITAL) (Removable) (Total:14.93 GB) (Free:8.21 GB) FAT32 (Disk=3 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 862E84D4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: E792C529) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 466 GB) (Disk ID: 086D086C) Partition 1: (Active) - (Size=10 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=456 GB) - (Type=05) ======================================================== Disk: 3 (Size: 15 GB) (Disk ID: 00000000) Partition 1: (Active) - (Size=15 GB) - (Type=0C) ==================== End Of Log ============================ |
![]() | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Im Browser ist überall Werbung Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #15 |
![]() ![]() | ![]() Im Browser ist überall Werbung hier nun die Logs Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2013.08.12.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 Lila :: LEX [Administrator] 12.08.2013 14:42:19 mbam-log-2013-08-12 (14-42-19).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 218266 Laufzeit: 1 Minute(n), 24 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=c21399f6cd9b614f96a29458e624ef2b # engine=14746 # end=stopped # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-08-12 12:58:19 # local_time=2013-08-12 02:58:19 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 4287 127942149 0 0 # compatibility_mode=8216 16776701 100 98 404179 126325251 0 0 # scanned=69176 # found=0 # cleaned=0 # scan_time=584 # nod_component=V3 Build:0x30000000 |
![]() |
Themen zu Im Browser ist überall Werbung |
ads, ads not by this site, aktiviert, auf einmal, brauche, browser, euere, hoffe, hängt, liebe, lieben, links, merke, nicht mehr, not, rechts, runtergeladen, teilweise, this, werbun, werbung, überall |