|
Log-Analyse und Auswertung: Internet hat ständig HängerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
20.11.2013, 22:21 | #1 |
| Internet hat ständig Hänger Hallo, seit einigen Tagen hat mein Internet alle paar Minuten Aussetzer. Dann geht gar nichts oder alles nur extrem langsam. Ich habe eine DSL 6000er-Leitung von der Telekom und logge mich mit W-Lan ein. Mit dem PC oder dem Handy habe ich diese Probleme nicht, nur mit meinem Laptop. Das beunruhigt mich. Avast und Windows Defender zeigen keine Funde an. MiniToolBox ergibt folgendes: Code:
ATTFilter ch kMiniToolBox by Farbar Version: 13-07-2013 Ran by Moe (administrator) on 20-11-2013 at 22:17:23 Running from "C:\Users\Moe\Downloads" Microsoft Windows 7 Professional Service Pack 1 (X64) Boot Mode: Normal *************************************************************************** ========================= Flush DNS: =================================== Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. ========================= IE Proxy Settings: ============================== Proxy is not enabled. No Proxy Server is set. "Reset IE Proxy Settings": IE Proxy Settings were reset. ========================= FF Proxy Settings: ============================== "network.proxy.type", 0 "Reset FF Proxy Settings": Firefox Proxy settings were reset. ========================= Hosts content: ================================= ========================= IP Configuration: ================================ Intel(R) Centrino(R) Advanced-N 6235 = Drahtlosnetzwerkverbindung (Connected) Bluetooth-Gerät (PAN) = Bluetooth-Netzwerkverbindung (Media disconnected) Microsoft Virtual WiFi Miniport Adapter = Drahtlosnetzwerkverbindung 2 (Media disconnected) Microsoft Virtual WiFi Miniport Adapter = Drahtlosnetzwerkverbindung 3 (Media disconnected) Realtek PCIe GBE Family Controller = LAN-Verbindung (Media disconnected) # ---------------------------------- # IPv4-Konfiguration # ---------------------------------- pushd interface ipv4 reset set global icmpredirects=enabled popd # Ende der IPv4-Konfiguration Windows-IP-Konfiguration Hostname . . . . . . . . . . . . : UltraMoe Prim„res DNS-Suffix . . . . . . . : Knotentyp . . . . . . . . . . . . : Hybrid IP-Routing aktiviert . . . . . . : Nein WINS-Proxy aktiviert . . . . . . : Nein DNS-Suffixsuchliste . . . . . . . : Speedport_W_303V_Typ_A Ethernet-Adapter LAN-Verbindung: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Realtek PCIe GBE Family Controller Physikalische Adresse . . . . . . : E8-03-9A-F0-7F-19 DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja Drahtlos-LAN-Adapter Drahtlosnetzwerkverbindung 3: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter #2 Physikalische Adresse . . . . . . : C4-85-08-C2-8B-D0 DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja Drahtlos-LAN-Adapter Drahtlosnetzwerkverbindung 2: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Microsoft Virtual WiFi Miniport Adapter Physikalische Adresse . . . . . . : C4-85-08-C2-8B-D0 DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja Drahtlos-LAN-Adapter Drahtlosnetzwerkverbindung: Verbindungsspezifisches DNS-Suffix: Speedport_W_303V_Typ_A Beschreibung. . . . . . . . . . . : Intel(R) Centrino(R) Advanced-N 6235 Physikalische Adresse . . . . . . : C4-85-08-C2-8B-CF DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja Verbindungslokale IPv6-Adresse . : fe80::35df:fb1f:d5a7:b1b0%13(Bevorzugt) IPv4-Adresse . . . . . . . . . . : 192.168.2.104(Bevorzugt) Subnetzmaske . . . . . . . . . . : 255.255.255.0 Lease erhalten. . . . . . . . . . : Mittwoch, 20. November 2013 20:57:18 Lease l„uft ab. . . . . . . . . . : Sonntag, 24. November 2013 21:57:16 Standardgateway . . . . . . . . . : 192.168.2.1 DHCP-Server . . . . . . . . . . . : 192.168.2.1 DHCPv6-IAID . . . . . . . . . . . : 230982920 DHCPv6-Client-DUID. . . . . . . . : 00-01-00-01-18-B9-58-70-C4-85-08-C2-8B-CF DNS-Server . . . . . . . . . . . : 192.168.2.1 NetBIOS ber TCP/IP . . . . . . . : Aktiviert Ethernet-Adapter Bluetooth-Netzwerkverbindung: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Bluetooth-Ger„t (PAN) Physikalische Adresse . . . . . . : C4-85-08-C2-8B-D3 DHCP aktiviert. . . . . . . . . . : Ja Autokonfiguration aktiviert . . . : Ja Tunneladapter isatap.{6552E11E-9B5D-4D3A-ABAE-CF155BA25CF1}: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Microsoft-ISATAP-Adapter Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja Tunneladapter isatap.{57D39804-2A73-43D4-9FE9-775C6EC1CCF4}: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Microsoft-ISATAP-Adapter #2 Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja Tunneladapter isatap.{CB9EE0DA-07E2-4CA7-B7A5-FB94A49B83A2}: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Microsoft-ISATAP-Adapter #3 Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja Tunneladapter isatap.Speedport_W_303V_Typ_A: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Speedport_W_303V_Typ_A Beschreibung. . . . . . . . . . . : Microsoft-ISATAP-Adapter #4 Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja Tunneladapter Teredo Tunneling Pseudo-Interface: Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Teredo Tunneling Pseudo-Interface Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja IPv6-Adresse. . . . . . . . . . . : 2001:0:9d38:90d7:2498:1a93:ab58:714a(Bevorzugt) Verbindungslokale IPv6-Adresse . : fe80::2498:1a93:ab58:714a%17(Bevorzugt) Standardgateway . . . . . . . . . : :: NetBIOS ber TCP/IP . . . . . . . : Deaktiviert Tunneladapter isatap.{E03B76E2-77D5-4834-9A71-045B482DA427}: Medienstatus. . . . . . . . . . . : Medium getrennt Verbindungsspezifisches DNS-Suffix: Beschreibung. . . . . . . . . . . : Microsoft-ISATAP-Adapter #5 Physikalische Adresse . . . . . . : 00-00-00-00-00-00-00-E0 DHCP aktiviert. . . . . . . . . . : Nein Autokonfiguration aktiviert . . . : Ja Server: speedport.ip Address: 192.168.2.1 Name: google.com Addresses: 2a00:1450:4016:800::100e 173.194.35.137 173.194.35.135 173.194.35.142 173.194.35.128 173.194.35.133 173.194.35.131 173.194.35.130 173.194.35.136 173.194.35.134 173.194.35.132 173.194.35.129 Ping wird ausgefhrt fr google.com [173.194.35.129] mit 32 Bytes Daten: Antwort von 173.194.35.129: Bytes=32 Zeit=48ms TTL=57 Antwort von 173.194.35.129: Bytes=32 Zeit=47ms TTL=57 Ping-Statistik fr 173.194.35.129: Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust), Ca. Zeitangaben in Millisek.: Minimum = 47ms, Maximum = 48ms, Mittelwert = 47ms Server: speedport.ip Address: 192.168.2.1 Name: yahoo.com Addresses: 206.190.36.45 98.139.183.24 98.138.253.109 Ping wird ausgefhrt fr yahoo.com [98.138.253.109] mit 32 Bytes Daten: Antwort von 98.138.253.109: Bytes=32 Zeit=161ms TTL=52 Antwort von 98.138.253.109: Bytes=32 Zeit=160ms TTL=52 Ping-Statistik fr 98.138.253.109: Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust), Ca. Zeitangaben in Millisek.: Minimum = 160ms, Maximum = 161ms, Mittelwert = 160ms Ping wird ausgefhrt fr 127.0.0.1 mit 32 Bytes Daten: Antwort von 127.0.0.1: Bytes=32 Zeit<1ms TTL=128 Antwort von 127.0.0.1: Bytes=32 Zeit<1ms TTL=128 Ping-Statistik fr 127.0.0.1: Pakete: Gesendet = 2, Empfangen = 2, Verloren = 0 (0% Verlust), Ca. Zeitangaben in Millisek.: Minimum = 0ms, Maximum = 0ms, Mittelwert = 0ms =========================================================================== Schnittstellenliste 16...e8 03 9a f0 7f 19 ......Realtek PCIe GBE Family Controller 15...c4 85 08 c2 8b d0 ......Microsoft Virtual WiFi Miniport Adapter #2 14...c4 85 08 c2 8b d0 ......Microsoft Virtual WiFi Miniport Adapter 13...c4 85 08 c2 8b cf ......Intel(R) Centrino(R) Advanced-N 6235 12...c4 85 08 c2 8b d3 ......Bluetooth-Ger„t (PAN) 1...........................Software Loopback Interface 1 20...00 00 00 00 00 00 00 e0 Microsoft-ISATAP-Adapter 23...00 00 00 00 00 00 00 e0 Microsoft-ISATAP-Adapter #2 39...00 00 00 00 00 00 00 e0 Microsoft-ISATAP-Adapter #3 21...00 00 00 00 00 00 00 e0 Microsoft-ISATAP-Adapter #4 17...00 00 00 00 00 00 00 e0 Teredo Tunneling Pseudo-Interface 22...00 00 00 00 00 00 00 e0 Microsoft-ISATAP-Adapter #5 =========================================================================== IPv4-Routentabelle =========================================================================== Aktive Routen: Netzwerkziel Netzwerkmaske Gateway Schnittstelle Metrik 0.0.0.0 0.0.0.0 192.168.2.1 192.168.2.104 25 127.0.0.0 255.0.0.0 Auf Verbindung 127.0.0.1 306 127.0.0.1 255.255.255.255 Auf Verbindung 127.0.0.1 306 127.255.255.255 255.255.255.255 Auf Verbindung 127.0.0.1 306 192.168.2.0 255.255.255.0 Auf Verbindung 192.168.2.104 281 192.168.2.104 255.255.255.255 Auf Verbindung 192.168.2.104 281 192.168.2.255 255.255.255.255 Auf Verbindung 192.168.2.104 281 224.0.0.0 240.0.0.0 Auf Verbindung 127.0.0.1 306 224.0.0.0 240.0.0.0 Auf Verbindung 192.168.2.104 281 255.255.255.255 255.255.255.255 Auf Verbindung 127.0.0.1 306 255.255.255.255 255.255.255.255 Auf Verbindung 192.168.2.104 281 =========================================================================== St„ndige Routen: Keine IPv6-Routentabelle =========================================================================== Aktive Routen: If Metrik Netzwerkziel Gateway 17 58 ::/0 Auf Verbindung 1 306 ::1/128 Auf Verbindung 17 58 2001::/32 Auf Verbindung 17 306 2001:0:9d38:90d7:2498:1a93:ab58:714a/128 Auf Verbindung 13 281 fe80::/64 Auf Verbindung 17 306 fe80::/64 Auf Verbindung 17 306 fe80::2498:1a93:ab58:714a/128 Auf Verbindung 13 281 fe80::35df:fb1f:d5a7:b1b0/128 Auf Verbindung 1 306 ff00::/8 Auf Verbindung 17 306 ff00::/8 Auf Verbindung 13 281 ff00::/8 Auf Verbindung =========================================================================== St„ndige Routen: Keine ========================= Winsock entries ===================================== Catalog5 01 C:\Windows\SysWOW64\NLAapi.dll [52224] (Microsoft Corporation) Catalog5 02 C:\Windows\SysWOW64\napinsp.dll [52224] (Microsoft Corporation) Catalog5 03 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 04 C:\Windows\SysWOW64\pnrpnsp.dll [65024] (Microsoft Corporation) Catalog5 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog5 06 C:\Windows\SysWOW64\winrnr.dll [20992] (Microsoft Corporation) Catalog5 07 C:\Windows\SysWOW64\wshbth.dll [36352] (Microsoft Corporation) Catalog9 01 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 02 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 03 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 04 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 05 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 06 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 07 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 08 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 09 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 10 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) Catalog9 11 C:\Windows\SysWOW64\mswsock.dll [231424] (Microsoft Corporation) x64-Catalog5 01 C:\Windows\System32\NLAapi.dll [70656] (Microsoft Corporation) x64-Catalog5 02 C:\Windows\System32\napinsp.dll [68096] (Microsoft Corporation) x64-Catalog5 03 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 04 C:\Windows\System32\pnrpnsp.dll [86016] (Microsoft Corporation) x64-Catalog5 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog5 06 C:\Windows\System32\winrnr.dll [28672] (Microsoft Corporation) x64-Catalog5 07 C:\Windows\System32\wshbth.dll [47104] (Microsoft Corporation) x64-Catalog9 01 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 02 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 03 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 04 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 05 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 06 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 07 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 08 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 09 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 10 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) x64-Catalog9 11 C:\Windows\System32\mswsock.dll [327168] (Microsoft Corporation) ========================= Event log errors: =============================== Application errors: ================== Error: (11/20/2013 08:57:13 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] Error: (11/20/2013 08:57:13 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2013 08:57:13 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registered successfully [0] Error: (11/20/2013 09:51:32 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] Error: (11/20/2013 09:51:32 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2013 09:51:32 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registered successfully [0] Error: (11/20/2013 09:16:15 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] Error: (11/20/2013 09:16:14 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2013 09:16:14 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registered successfully [0] Error: (11/20/2013 07:32:27 PM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 System errors: ============= Error: (11/20/2013 07:41:01 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "MAX-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{0EBBC33B-7ECA-48C7-9BCD-E75B95826BD6}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (11/19/2013 07:16:50 PM) (Source: BugCheck) (User: ) Description: 0xdeaddead (0x000000000f00004b, 0x000000000023002c, 0x0000000012a60000, 0x0000000000000000)C:\Windows\MEMORY.DMP111913-8174-01 Error: (11/19/2013 07:16:48 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am ?19.?11.?2013 um 19:16:14 unerwartet heruntergefahren. Error: (11/17/2013 02:47:37 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (11/17/2013 02:47:35 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (11/17/2013 02:47:34 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (11/17/2013 02:47:32 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (11/17/2013 02:47:30 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (11/17/2013 02:47:28 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (11/16/2013 11:41:11 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am ?16.?11.?2013 um 23:39:04 unerwartet heruntergefahren. Microsoft Office Sessions: ========================= **** End of log **** Das Problem konnte auch durch Neustarten, System zurücksetzen auf vor ca 1 Monat und neu installieren der Netzwerktreiber nicht gelöst werden. Wäre über jede Hilfe dankbar! Beste Grüße Moe |
20.11.2013, 23:25 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Internet hat ständig Hänger Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
21.11.2013, 08:11 | #3 |
| Internet hat ständig Hänger Danke für's Helfen!
__________________Andere Logs habe ich nicht. Avast hab ich vor 2 Tagen mal durchlaufen lassen, aber finde den log dazu nicht. (Allgemein weiß ich nicht, wie ich an die Avast-Logs komme). Allerdings gab es auch keinerlei Funde. Auch nicht von Windows Defender gestern. Hier die beiden Logs: FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-11-2013 Ran by Moe (administrator) on ULTRAMOE on 21-11-2013 08:07:46 Running from C:\Users\Moe\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Intel) C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Users\Moe\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe (Dropbox, Inc.) C:\Users\Moe\AppData\Roaming\Dropbox\bin\Dropbox.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe (Intel Corporation) C:\Windows\system32\igfxext.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Intel Corporation) C:\Windows\system32\hkcmd.exe (Intel Corporation) C:\Windows\system32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BTPlayerCtrl.exe (Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2824528 2013-02-23] (ELAN Microelectronics Corp.) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028896 2013-07-27] (NVIDIA Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191312 2012-08-07] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-06] (Realtek Semiconductor) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\Moe\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] () HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-08-30] (AVAST Software) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-04] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) AppInit_DLLs: C:\Program Files\NVIDIA Corporation\NvStreamSrv\rxinput.dll [653600 2013-07-27] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll, C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll [593696 2013-07-27] (NVIDIA Corporation) Startup: C:\Users\Moe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Moe\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank SearchScopes: HKCU - {FFEBBF0A-C22C-4172-89FF-45215A135AC8} URL = hxxp://search.icq.com/search/results.php?q=%s&ch_id=hm&search_mode=web BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 130.83.22.60 130.83.22.63 130.83.56.60 FireFox: ======== FF ProfilePath: C:\Users\Moe\AppData\Roaming\Mozilla\Firefox\Profiles\hl8qa3hb.default FF Homepage: about:blank FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Moe\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Users\Moe\AppData\Roaming\Mozilla\Firefox\Profiles\hl8qa3hb.default\searchplugins\icq.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Block site - C:\Users\Moe\AppData\Roaming\Mozilla\Firefox\Profiles\hl8qa3hb.default\Extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc} FF Extension: Adblock Plus - C:\Users\Moe\AppData\Roaming\Mozilla\Firefox\Profiles\hl8qa3hb.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-07] () R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-02-06] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14984480 2013-07-27] (NVIDIA Corporation) R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] () R3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2012-02-07] (Intel Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39712 2013-05-14] (NVIDIA Corporation) R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8222440 2012-04-06] (Realtek Semiconductor Corp.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-21 08:07 - 2013-11-21 08:07 - 00013387 _____ C:\Users\Moe\Downloads\FRST.txt 2013-11-21 08:07 - 2013-11-21 08:07 - 00000000 ____D C:\FRST 2013-11-21 08:06 - 2013-11-21 08:07 - 01957964 _____ (Farbar) C:\Users\Moe\Downloads\FRST64.exe 2013-11-20 22:41 - 2013-11-20 22:42 - 00000000 ____D C:\Program Files (x86)\QuickTime 2013-11-20 22:41 - 2013-11-20 22:41 - 00000000 ____D C:\ProgramData\Apple Computer 2013-11-20 22:40 - 2013-11-20 22:41 - 41404760 _____ (Apple Inc.) C:\Users\Moe\Downloads\QuickTimeInstaller.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-11-20 22:36 - 2013-11-20 22:36 - 30694824 _____ (Oracle Corporation) C:\Users\Moe\Downloads\jre-7u45-windows-x64.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-11-20 22:17 - 2013-11-20 22:17 - 00018012 _____ C:\Users\Moe\Downloads\Result.txt 2013-11-20 22:16 - 2013-11-20 22:16 - 00760937 _____ (Farbar) C:\Users\Moe\Downloads\MiniToolBox.exe 2013-11-20 21:55 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-20 21:55 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-20 21:55 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-20 21:55 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-20 21:55 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-20 21:55 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-20 21:55 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-20 21:55 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-20 21:55 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-20 21:55 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-20 21:55 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-20 21:55 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-20 21:55 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-20 21:55 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-20 21:55 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-20 21:55 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-20 21:55 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-20 21:55 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-20 21:55 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-20 21:55 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-20 21:55 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-20 21:55 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-20 21:55 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-20 21:55 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-20 21:55 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-20 21:55 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-20 21:55 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-20 21:55 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-20 21:55 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-20 21:55 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-20 21:02 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-20 21:02 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-20 21:02 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-20 21:02 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-20 21:02 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-20 21:02 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-20 21:02 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-20 21:02 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-20 21:02 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-20 21:02 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-20 20:57 - 2013-11-20 20:57 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-11-20 20:53 - 2013-11-20 21:51 - 00000000 ____D C:\Program Files\7-Zip 2013-11-19 20:22 - 2013-11-20 21:51 - 00000000 ____D C:\Program Files (x86)\Opera 2013-11-19 20:22 - 2013-11-19 20:22 - 00000000 ____D C:\Users\Moe\AppData\Roaming\Opera Software 2013-11-19 20:22 - 2013-11-19 20:22 - 00000000 ____D C:\Users\Moe\AppData\Local\Opera Software 2013-11-17 14:26 - 2013-11-20 21:22 - 00000000 ____D C:\Users\Moe\Desktop\STREAM 2013-11-16 18:00 - 2013-11-16 18:16 - 00000000 ____D C:\Users\Moe\Desktop\Playlist 2013-11-02 15:14 - 2013-11-20 21:56 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner 2013-11-01 00:16 - 2013-11-10 22:53 - 00442325 _____ C:\Users\Moe\Downloads\Downloads.rar 2013-10-28 17:46 - 2013-11-09 00:12 - 00000000 ____D C:\Users\Moe\Desktop\Musik 2013-10-22 10:39 - 2013-10-22 10:39 - 00000000 ____D C:\Program Files\Java 2013-10-22 10:33 - 2013-11-20 22:37 - 00000000 ____D C:\ProgramData\Oracle ==================== One Month Modified Files and Folders ======= 2013-11-21 08:07 - 2013-11-21 08:07 - 00013387 _____ C:\Users\Moe\Downloads\FRST.txt 2013-11-21 08:07 - 2013-11-21 08:07 - 00000000 ____D C:\FRST 2013-11-21 08:07 - 2013-11-21 08:06 - 01957964 _____ (Farbar) C:\Users\Moe\Downloads\FRST64.exe 2013-11-21 08:07 - 2013-02-22 13:11 - 01762046 _____ C:\Windows\WindowsUpdate.log 2013-11-21 08:06 - 2013-02-23 22:34 - 00000000 ____D C:\Users\Moe\AppData\Roaming\Dropbox 2013-11-21 08:04 - 2013-02-23 22:35 - 00000000 ___RD C:\Users\Moe\Dropbox 2013-11-21 08:04 - 2013-02-22 19:03 - 00003316 _____ C:\Windows\System32\Tasks\Intel® Rapid Start Technology Manager 2013-11-21 08:03 - 2013-02-22 18:06 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2013-11-21 08:03 - 2013-02-22 17:56 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-21 08:03 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-21 08:03 - 2009-07-14 05:51 - 00063009 _____ C:\Windows\setupact.log 2013-11-20 22:48 - 2013-09-30 22:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-20 22:42 - 2013-11-20 22:41 - 00000000 ____D C:\Program Files (x86)\QuickTime 2013-11-20 22:41 - 2013-11-20 22:41 - 00000000 ____D C:\ProgramData\Apple Computer 2013-11-20 22:41 - 2013-11-20 22:40 - 41404760 _____ (Apple Inc.) C:\Users\Moe\Downloads\QuickTimeInstaller.exe 2013-11-20 22:39 - 2013-02-22 17:56 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-11-20 22:39 - 2013-02-22 17:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-11-20 22:39 - 2013-02-22 17:56 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-11-20 22:38 - 2013-02-23 23:23 - 00000000 ____D C:\Users\Moe\AppData\Local\Adobe 2013-11-20 22:37 - 2013-11-20 22:37 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-11-20 22:37 - 2013-10-22 10:33 - 00000000 ____D C:\ProgramData\Oracle 2013-11-20 22:36 - 2013-11-20 22:36 - 30694824 _____ (Oracle Corporation) C:\Users\Moe\Downloads\jre-7u45-windows-x64.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-11-20 22:35 - 2013-05-05 10:09 - 00000000 ____D C:\Program Files (x86)\Java 2013-11-20 22:30 - 2009-07-14 05:45 - 00022080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-20 22:30 - 2009-07-14 05:45 - 00022080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-20 22:29 - 2011-04-12 08:43 - 00697082 _____ C:\Windows\system32\perfh007.dat 2013-11-20 22:29 - 2011-04-12 08:43 - 00148346 _____ C:\Windows\system32\perfc007.dat 2013-11-20 22:29 - 2009-07-14 06:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-20 22:25 - 2010-11-21 04:47 - 00009902 _____ C:\Windows\PFRO.log 2013-11-20 22:17 - 2013-11-20 22:17 - 00018012 _____ C:\Users\Moe\Downloads\Result.txt 2013-11-20 22:16 - 2013-11-20 22:16 - 00760937 _____ (Farbar) C:\Users\Moe\Downloads\MiniToolBox.exe 2013-11-20 21:56 - 2013-11-02 15:14 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner 2013-11-20 21:56 - 2013-10-04 16:02 - 00000000 ____D C:\Program Files (x86)\HyperCam 3 2013-11-20 21:56 - 2013-08-28 13:10 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-20 21:56 - 2013-08-28 13:10 - 00000000 ____D C:\Users\Moe\AppData\Roaming\Skype 2013-11-20 21:56 - 2013-08-28 13:10 - 00000000 ____D C:\ProgramData\Skype 2013-11-20 21:56 - 2013-08-08 12:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-11-20 21:56 - 2013-03-16 09:42 - 00000000 ____D C:\Users\Moe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-11-20 21:56 - 2013-03-16 09:41 - 00000000 ____D C:\Program Files\WinRAR 2013-11-20 21:56 - 2013-02-25 22:18 - 00000000 ____D C:\Users\Moe\AppData\Roaming\vlc 2013-11-20 21:56 - 2013-02-25 19:52 - 00000000 ____D C:\Users\Moe\Documents\Assassin's Creed III 2013-11-20 21:56 - 2013-02-24 12:26 - 00000000 ____D C:\Users\Moe\AppData\Local\Brice_Lambson 2013-11-20 21:56 - 2013-02-23 11:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-20 21:56 - 2011-04-12 08:54 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-11-20 21:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-20 21:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2013-11-20 21:56 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-11-20 21:51 - 2013-11-20 20:53 - 00000000 ____D C:\Program Files\7-Zip 2013-11-20 21:51 - 2013-11-19 20:22 - 00000000 ____D C:\Program Files (x86)\Opera 2013-11-20 21:22 - 2013-11-17 14:26 - 00000000 ____D C:\Users\Moe\Desktop\STREAM 2013-11-20 21:02 - 2013-02-27 18:53 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-20 21:01 - 2013-08-14 17:51 - 00000000 ____D C:\Windows\system32\MRT 2013-11-20 21:00 - 2013-02-23 11:58 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-20 20:59 - 2013-02-22 13:11 - 00000000 ___RD C:\Users\Moe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-20 20:57 - 2013-11-20 20:57 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-11-20 20:57 - 2013-02-23 13:15 - 00003924 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-20 20:57 - 2013-02-23 13:15 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-11-20 20:57 - 2013-02-22 13:11 - 00000000 ____D C:\Users\Moe 2013-11-20 20:51 - 2013-10-04 16:05 - 00000000 ____D C:\Users\Moe\AppData\Roaming\Solveig Multimedia 2013-11-19 20:22 - 2013-11-19 20:22 - 00000000 ____D C:\Users\Moe\AppData\Roaming\Opera Software 2013-11-19 20:22 - 2013-11-19 20:22 - 00000000 ____D C:\Users\Moe\AppData\Local\Opera Software 2013-11-16 18:16 - 2013-11-16 18:00 - 00000000 ____D C:\Users\Moe\Desktop\Playlist 2013-11-10 22:53 - 2013-11-01 00:16 - 00442325 _____ C:\Users\Moe\Downloads\Downloads.rar 2013-11-09 00:12 - 2013-10-28 17:46 - 00000000 ____D C:\Users\Moe\Desktop\Musik 2013-11-02 15:15 - 2013-02-23 22:24 - 00000000 ___HD C:\Windows\msdownld.tmp 2013-10-22 10:39 - 2013-10-22 10:39 - 00000000 ____D C:\Program Files\Java Some content of TEMP: ==================== C:\Users\Moe\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Moe\AppData\Local\Temp\icqsetup.exe C:\Users\Moe\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Moe\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Moe\AppData\Local\Temp\ose00000.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-20 20:07 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 18-11-2013 Ran by Moe at 2013-11-21 08:08:25 Running from C:\Users\Moe\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {2B2D1395-420B-D5C9-657E-930FE358FC3C} AS: avast! Antivirus (Enabled - Up to date) {904CF271-6431-DA47-5FCE-A87D98DFB681} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.117) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.152) Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05) Amazon MP3-Downloader 1.0.18 (HKCU Version: 1.0.18) Apple Application Support (x32 Version: 2.3.4) Apple Software Update (x32 Version: 2.1.3.127) Assassin's Creed Brotherhood (x32 Version: 1.03) Assassin's Creed(R) III v1.06 (x32 Version: 1.06) Audacity 2.0.4 (x32 Version: 2.0.4) AudibleManager (x32 Version: 2006859006.48.56.36121354) avast! Free Antivirus (x32 Version: 8.0.1497.0) Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (x32) Common (x32 Version: 14.0.0.342) Contents (x32 Version: 14.0.0.342) Corel VideoStudio Pro X4 (x32 Version: 14.0.0.342) DeviceIO (x32 Version: 14.0.0.342) Dropbox (HKCU Version: 2.4.2) Easy Settings (x32 Version: 1.1) ETDWare PS/2-X64 10.7.17.5_WHQL (Version: 10.7.17.5) HyperCam 3 (x32 Version: 3.5.1211.29) ICA (x32 Version: 14.0.0.342) ICQ 8.0 (build 6003, für aktuellen Benutzer) (HKCU Version: 8.0.6003.0) Image Resizer for Windows (64 bit) (Version: 3.0.4442.6002) Image Resizer for Windows (x32 Version: 3.0.4442.6002) Intel PROSet Wireless Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: 1.0.0.35342) Intel(R) Management Engine Components (x32 Version: 8.0.2.1410) Intel(R) OpenCL CPU Runtime (x32) Intel(R) Processor Graphics (x32 Version: 8.15.10.2712) Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (Version: 15.0.0.0059) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (Version: 2.1.0.0140) Intel(R) Rapid Start Technology (x32 Version: 1.0.0.1021) Intel(R) Rapid Storage Technology (x32 Version: 11.0.0.1032) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.1.209) Intel® PROSet/Wireless WiFi-Software (Version: 15.00.0000.0642) Intel® Trusted Connect Service Client (Version: 1.23.605.1) IPM_VS_Pro (x32 Version: 13.0) ISCOM (x32 Version: 14.0.0.342) Java 7 Update 45 (64-bit) (Version: 7.0.450) Java 7 Update 45 (x32 Version: 7.0.450) Java Auto Updater (x32 Version: 2.1.9.8) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft .NET Framework 4 Extended (Version: 4.0.30319) Microsoft .NET Framework 4 Extended DEU Language Pack (Version: 4.0.30319) Microsoft Office 2007 Service Pack 3 (SP3) (x32) Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000) Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014) Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32) Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000) Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (x32 Version: 10.0.30319) Mozilla Firefox 24.0 (x86 de) (x32 Version: 24.0) Mozilla Maintenance Service (x32 Version: 24.0) Mozilla Thunderbird 17.0.8 (x86 de) (x32 Version: 17.0.8) NVIDIA GeForce Experience 1.6 (Version: 1.6) NVIDIA Grafiktreiber 320.49 (Version: 320.49) NVIDIA HD-Audiotreiber 1.3.24.2 (Version: 1.3.24.2) NVIDIA Install Application (Version: 2.1002.131.854) NVIDIA Optimus 7.2.17 (Version: 7.2.17) NVIDIA PhysX (x32 Version: 9.13.0604) NVIDIA PhysX-Systemsoftware 9.13.0604 (Version: 9.13.0604) NVIDIA Systemsteuerung 320.49 (Version: 320.49) NVIDIA Update 7.2.17 (Version: 7.2.17) NVIDIA Update Components (Version: 7.2.17) NVIDIA Virtual Audio 1.2.1 (Version: 1.2.1) PureHD (x32 Version: 14.0.0.342) QuickTime (x32 Version: 7.74.80.86) Realtek Ethernet Controller Driver (x32 Version: 7.50.1123.2011) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6699) Realtek PC Camera (x32 Version: 6.1.7600.154) Setup (x32 Version: 14.0.0.342) Share (x32 Version: 14.0.0.342) Share64 (Version: 14.0.0.342) SHIELD Streaming (Version: 1.05.19) Skype™ 6.7 (x32 Version: 6.7.102) SmartSound Common Data (x32 Version: 1.1.0) SmartSound Quicktracks 5 (x32 Version: 5.1.6) SopCast 3.8.3 (x32 Version: 3.8.3) SUPER © +Recorder.2013.55 (Mar 7, 2013) Version +Recorder.2013. (x32 Version: +Recorder.2013.55) Ubisoft Game Launcher (x32 Version: 1.0.0.0) Update for 2007 Microsoft Office System (KB967642) (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1) Update for Microsoft .NET Framework 4 Extended (KB2836939v3) (x32 Version: 3) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32) Update für Microsoft Office Excel 2007 Help (KB963678) (x32) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32) Update für Microsoft Office Word 2007 Help (KB963665) (x32) VIO (x32 Version: 14.0.0.342) VLC media player 2.0.5 (Version: 2.0.5) VSClassic (x32 Version: 14.0.0.342) VSPro (x32 Version: 14.0.0.342) Windows Media Encoder 9 Series (x32 Version: 9.00.2980) Windows Media Encoder 9 Series (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 25-10-2013 18:40:48 Windows Update 29-10-2013 14:12:51 Windows Update 05-11-2013 17:30:06 Windows Update 12-11-2013 19:35:42 Geplanter Prüfpunkt 14-11-2013 22:49:47 Windows Update 16-11-2013 18:34:11 Gerätetreiber-Paketinstallation: Focusrite Audio-, Video- und Gamecontroller 19-11-2013 18:20:50 Windows Update 20-11-2013 19:53:07 Installed 7-Zip 9.20 (x64 edition) 20-11-2013 20:00:29 Windows Update 20-11-2013 20:50:22 Wiederherstellungsvorgang 20-11-2013 20:55:29 Windows Update 20-11-2013 20:56:01 Wiederherstellungsvorgang 20-11-2013 21:35:02 Installed Java 7 Update 45 20-11-2013 21:36:55 Installed Java 7 Update 45 (64-bit) 20-11-2013 21:41:33 Installed QuickTime ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {0838EC10-0968-42DC-A81D-F9989092B769} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe [2012-04-25] (Samsung Electronics Co., Ltd.) Task: {0E4D408B-553C-4D56-9F96-4457402DD3BC} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe [2012-01-31] (Samsung Electronics) Task: {1DF6C27C-CF29-47EB-953E-FB14E419CF31} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {248943F9-3F6A-421D-99DF-4645361271C0} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Easy Settings\EBM\EasyBatteryMgr4.exe [2011-11-18] (SAMSUNG Electronics co., LTD.) Task: {69C355FD-5199-4A3E-AE4B-25627E824634} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-11-20] (Adobe Systems Incorporated) Task: {85BA981D-AF45-4967-BCB8-CF6E5C6E689A} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {904B5E26-9BF7-4C4D-A6FC-8158863B14D4} - System32\Tasks\Intel® Rapid Start Technology Manager => C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe [2012-02-06] (Intel) Task: {9A37090D-C7A3-4A2B-BF63-15B16E6DA3FF} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2013-08-30] (AVAST Software) Task: {A047C2C4-AF8E-4181-AE9B-4F7DFA6C04C0} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {EDD1C918-BE3F-4083-A435-34C5FB1C4596} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe [2012-05-02] (Samsung Electronics Co., Ltd.) Task: {EDFE7851-4D9D-4B8A-91B2-263C7FDB6780} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Easy Settings\SCCSpeedBoot.exe [2012-03-27] (Samsung Electronics Co., Ltd.) Task: {FA8BEBCF-FD34-48F1-92C9-4CAE3B09FC53} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe [2012-04-03] (Samsung Electronics) Task: {FA9B140E-D2C9-4E32-B43C-2162DFEDF091} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe [2012-05-30] (Samsung Electronics Co., Ltd.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Loaded Modules (whitelisted) ============= 2012-12-14 02:42 - 2012-12-14 02:42 - 00094208 _____ () C:\Windows\system32\IccLibDll_x64.dll 2013-11-21 08:04 - 2013-11-20 22:03 - 02240000 _____ () C:\Program Files\AVAST Software\Avast\defs\13112000\algo.dll 2013-03-13 21:48 - 2013-03-13 21:48 - 24978944 _____ () C:\Users\Moe\AppData\Roaming\Dropbox\bin\libcef.dll 2013-02-23 01:44 - 2011-02-17 01:03 - 00203776 _____ () C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll 2013-02-23 01:44 - 2006-08-12 12:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll 2013-09-30 22:03 - 2013-09-30 22:03 - 03279768 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-02-22 18:05 - 2012-02-07 17:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (11/21/2013 08:03:43 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/21/2013 08:03:39 AM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] Error: (11/21/2013 08:03:38 AM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registered successfully [0] Error: (11/20/2013 10:25:23 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] Error: (11/20/2013 10:25:23 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2013 10:25:22 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registered successfully [0] Error: (11/20/2013 08:57:13 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] Error: (11/20/2013 08:57:13 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (11/20/2013 08:57:13 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcNvVAD endpoint registered successfully [0] Error: (11/20/2013 09:51:32 PM) (Source: NvStreamSvc) (User: ) Description: NvStreamSvcUnregistering VAD endpoint [0] System errors: ============= Error: (11/20/2013 07:41:01 PM) (Source: bowser) (User: ) Description: Der Hauptsuchdienst erhielt eine Serverankündigung vom Computer "MAX-PC", der der Hauptsuchdienst der Domäne für den NetBT_Tcpip_{0EBBC33B-7ECA-48C7-9BCD-E75B95826BD6}-Transport zu sein scheint. Der Hauptsuchdienst wurde beendet oder es wird eine Auswahl erzwungen. Error: (11/19/2013 07:16:50 PM) (Source: BugCheck) (User: ) Description: 0xdeaddead (0x000000000f00004b, 0x000000000023002c, 0x0000000012a60000, 0x0000000000000000)C:\Windows\MEMORY.DMP111913-8174-01 Error: (11/19/2013 07:16:48 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 19.11.2013 um 19:16:14 unerwartet heruntergefahren. Error: (11/17/2013 02:47:37 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (11/17/2013 02:47:35 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (11/17/2013 02:47:34 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (11/17/2013 02:47:32 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (11/17/2013 02:47:30 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (11/17/2013 02:47:28 PM) (Source: cdrom) (User: ) Description: Der Treiber hat einen Controllerfehler auf \Device\CdRom0 gefunden. Error: (11/16/2013 11:41:11 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 16.11.2013 um 23:39:04 unerwartet heruntergefahren. Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 29% Total physical RAM: 7893.54 MB Available physical RAM: 5570.43 MB Total Pagefile: 15785.25 MB Available Pagefile: 13504.94 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:238.37 GB) (Free:138.51 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 238 GB) (Disk ID: 9B6C78B5) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=238 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 22 GB) (Disk ID: 659B7F68) Partition: GPT Partition Type ==================== End Of Log ============================ |
21.11.2013, 11:44 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Internet hat ständig Hänger Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ Logfiles bitte immer in CODE-Tags posten |
21.11.2013, 15:40 | #5 |
| Internet hat ständig Hänger Wurde nichts gefunden, deshalb konnte ich auch nicht "Clean Up" auswählen. Hmm... Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1007 www.malwarebytes.org Database version: v2013.11.21.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16736 Moe :: ULTRAMOE [administrator] 21.11.2013 15:31:10 mbar-log-2013-11-21 (15-31-10).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 259717 Time elapsed: 7 minute(s), 8 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) |
21.11.2013, 16:13 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Internet hat ständig Hänger Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ --> Internet hat ständig Hänger |
21.11.2013, 20:05 | #7 |
| Internet hat ständig HängerCode:
ATTFilter # AdwCleaner v3.012 - Bericht erstellt am 21/11/2013 um 17:43:48 # Updated 11/11/2013 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : Moe - ULTRAMOE # Gestartet von : C:\Users\Moe\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Moe\AppData\Local\Temp\OCS Ordner Gelöscht : C:\Users\Moe\AppData\Roaming\DesktopIconForAmazon Datei Gelöscht : C:\Users\Moe\AppData\Roaming\Mozilla\Firefox\Profiles\hl8qa3hb.default\foxydeal.sqlite ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{FFEBBF0A-C22C-4172-89FF-45215A135AC8} Schlüssel Gelöscht : HKCU\Software\OCS ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16736 -\\ Mozilla Firefox v24.0 (de) [ Datei : C:\Users\Moe\AppData\Roaming\Mozilla\Firefox\Profiles\hl8qa3hb.default\prefs.js ] ************************* AdwCleaner[R0].txt - [1343 octets] - [21/11/2013 17:43:07] AdwCleaner[S0].txt - [1100 octets] - [21/11/2013 17:43:48] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1160 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Professional x64 Ran by Moe on 21.11.2013 at 17:47:41,84 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Moe\AppData\Roaming\mozilla\firefox\profiles\hl8qa3hb.default\minidumps [118 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 21.11.2013 at 17:59:18,75 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 18-11-2013 Ran by Moe (administrator) on ULTRAMOE on 21-11-2013 18:01:25 Running from C:\Users\Moe\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Protexis Inc.) C:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe (Intel) C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\mediasrv.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Users\Moe\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Dropbox, Inc.) C:\Users\Moe\AppData\Roaming\Dropbox\bin\Dropbox.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe (Intel Corporation) C:\Windows\system32\igfxext.exe (Intel Corporation) C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Thisisu) C:\Users\Moe\Desktop\JRT.exe (Microsoft Corporation) C:\Windows\SysWOW64\cmd.exe (Intel Corporation) C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe (Intel Corporation) C:\Windows\system32\hkcmd.exe (Intel Corporation) C:\Windows\system32\igfxpers.exe (Microsoft Corporation) C:\Windows\SysWOW64\notepad.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2824528 2013-02-23] (ELAN Microelectronics Corp.) HKLM\...\Run: [Nvtmru] - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\NvTmru.exe [1028896 2013-07-27] (NVIDIA Corporation) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13191312 2012-08-07] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1215632 2012-08-06] (Realtek Semiconductor) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKCU\...\Run: [AmazonMP3DownloaderHelper] - C:\Users\Moe\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] () HKLM-x32\...\Run: [avast] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [4858968 2013-08-30] (AVAST Software) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-04] (Intel Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] - C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) AppInit_DLLs: C:\Program Files\NVIDIA Corporation\NvStreamSrv\rxinput.dll [653600 2013-07-27] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll, C:\PROGRA~2\NVIDIA~1\NVSTRE~1\rxinput.dll [593696 2013-07-27] (NVIDIA Corporation) Startup: C:\Users\Moe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Moe\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) Toolbar: HKLM-x32 - avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) DPF: HKLM-x32 {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Moe\AppData\Roaming\Mozilla\Firefox\Profiles\hl8qa3hb.default FF Homepage: about:blank FF NetworkProxy: "type", 0 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_152.dll () FF Plugin: @java.com/DTPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @videolan.org/vlc,version=2.0.5 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_152.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Moe\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF Plugin HKCU: ubisoft.com/uplaypc - C:\Program Files (x86)\Ubisoft\Ubisoft Game Launcher\npuplaypc.dll () FF SearchPlugin: C:\Users\Moe\AppData\Roaming\Mozilla\Firefox\Profiles\hl8qa3hb.default\searchplugins\icq.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Block site - C:\Users\Moe\AppData\Roaming\Mozilla\Firefox\Profiles\hl8qa3hb.default\Extensions\{dd3d7613-0246-469d-bc65-2a3cc1668adc} FF Extension: Adblock Plus - C:\Users\Moe\AppData\Roaming\Mozilla\Firefox\Profiles\hl8qa3hb.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [46808 2013-08-30] (AVAST Software) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-07] () R2 irstrtsv; C:\Windows\SysWOW64\irstrtsv.exe [193536 2012-02-06] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () R2 NvStreamSvc; C:\Program Files\NVIDIA Corporation\NvStreamSrv\nvstreamsvc.exe [14984480 2013-07-27] (NVIDIA Corporation) R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== R2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [33400 2013-08-30] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [80816 2013-08-30] (AVAST Software) R1 aswRdr; C:\Windows\System32\Drivers\aswrdr2.sys [72016 2013-08-30] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65336 2013-08-30] () R1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [1030952 2013-08-30] (AVAST Software) R1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [378944 2013-08-30] (AVAST Software) R1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [64288 2013-08-30] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [204880 2013-08-30] () R3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2012-02-07] (Intel Corporation) R3 nvvad_WaveExtensible; C:\Windows\System32\drivers\nvvad64v.sys [39712 2013-05-14] (NVIDIA Corporation) R3 rtsuvc; C:\Windows\System32\DRIVERS\rtsuvc.sys [8222440 2012-04-06] (Realtek Semiconductor Corp.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-11-21 17:59 - 2013-11-21 17:59 - 00000754 _____ C:\Users\Moe\Desktop\JRT.txt 2013-11-21 17:47 - 2013-11-21 17:47 - 00000000 ____D C:\Windows\ERUNT 2013-11-21 17:46 - 2013-11-21 17:46 - 01034531 _____ (Thisisu) C:\Users\Moe\Desktop\JRT.exe 2013-11-21 17:42 - 2013-11-21 17:43 - 00000000 ____D C:\AdwCleaner 2013-11-21 17:42 - 2013-11-21 17:42 - 01085542 _____ C:\Users\Moe\Desktop\adwcleaner.exe 2013-11-21 15:31 - 2013-11-21 15:39 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-11-21 15:31 - 2013-11-21 15:31 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2013-11-21 15:31 - 2013-11-21 15:31 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-21 15:27 - 2013-11-21 15:27 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-21 15:26 - 2013-11-21 15:39 - 00000000 ____D C:\Users\Moe\Desktop\mbar 2013-11-21 15:26 - 2013-11-21 15:26 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Moe\Downloads\mbar-1.07.0.1007.exe 2013-11-21 15:26 - 2013-11-21 15:26 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Moe\Desktop\mbar-1.07.0.1007.exe 2013-11-21 08:43 - 2013-11-21 08:45 - 214434571 _____ C:\Users\Moe\Downloads\No Matter-video.3gp 2013-11-21 08:08 - 2013-11-21 08:08 - 00017272 _____ C:\Users\Moe\Downloads\Addition.txt 2013-11-21 08:07 - 2013-11-21 18:01 - 00013064 _____ C:\Users\Moe\Downloads\FRST.txt 2013-11-21 08:07 - 2013-11-21 08:07 - 00000000 ____D C:\FRST 2013-11-21 08:06 - 2013-11-21 08:07 - 01957964 _____ (Farbar) C:\Users\Moe\Downloads\FRST64.exe 2013-11-20 22:41 - 2013-11-20 22:42 - 00000000 ____D C:\Program Files (x86)\QuickTime 2013-11-20 22:41 - 2013-11-20 22:41 - 00000000 ____D C:\ProgramData\Apple Computer 2013-11-20 22:40 - 2013-11-20 22:41 - 41404760 _____ (Apple Inc.) C:\Users\Moe\Downloads\QuickTimeInstaller.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-11-20 22:36 - 2013-11-20 22:36 - 30694824 _____ (Oracle Corporation) C:\Users\Moe\Downloads\jre-7u45-windows-x64.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-11-20 22:17 - 2013-11-20 22:17 - 00018012 _____ C:\Users\Moe\Downloads\Result.txt 2013-11-20 22:16 - 2013-11-20 22:16 - 00760937 _____ (Farbar) C:\Users\Moe\Downloads\MiniToolBox.exe 2013-11-20 21:55 - 2013-10-12 03:30 - 00830464 _____ (Microsoft Corporation) C:\Windows\system32\nshwfp.dll 2013-11-20 21:55 - 2013-10-12 03:29 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\IKEEXT.DLL 2013-11-20 21:55 - 2013-10-12 03:29 - 00324096 _____ (Microsoft Corporation) C:\Windows\system32\FWPUCLNT.DLL 2013-11-20 21:55 - 2013-10-12 03:03 - 00656896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\nshwfp.dll 2013-11-20 21:55 - 2013-10-12 03:01 - 00216576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FWPUCLNT.DLL 2013-11-20 21:55 - 2013-10-05 21:25 - 01474048 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2013-11-20 21:55 - 2013-10-05 20:57 - 01168384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2013-11-20 21:55 - 2013-10-04 03:28 - 00190464 _____ (Microsoft Corporation) C:\Windows\system32\SmartcardCredentialProvider.dll 2013-11-20 21:55 - 2013-10-04 03:25 - 00197120 _____ (Microsoft Corporation) C:\Windows\system32\credui.dll 2013-11-20 21:55 - 2013-10-04 03:24 - 01930752 _____ (Microsoft Corporation) C:\Windows\system32\authui.dll 2013-11-20 21:55 - 2013-10-04 02:58 - 00152576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SmartcardCredentialProvider.dll 2013-11-20 21:55 - 2013-10-04 02:56 - 01796096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\authui.dll 2013-11-20 21:55 - 2013-10-04 02:56 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credui.dll 2013-11-20 21:55 - 2013-10-03 03:23 - 00404480 _____ (Microsoft Corporation) C:\Windows\system32\gdi32.dll 2013-11-20 21:55 - 2013-10-03 03:00 - 00311808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\gdi32.dll 2013-11-20 21:55 - 2013-09-28 02:09 - 00497152 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\afd.sys 2013-11-20 21:55 - 2013-09-25 03:26 - 00154560 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2013-11-20 21:55 - 2013-09-25 03:26 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2013-11-20 21:55 - 2013-09-25 03:23 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2013-11-20 21:55 - 2013-09-25 03:23 - 00028672 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2013-11-20 21:55 - 2013-09-25 03:23 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2013-11-20 21:55 - 2013-09-25 03:22 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2013-11-20 21:55 - 2013-09-25 03:21 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2013-11-20 21:55 - 2013-09-25 03:21 - 00307200 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2013-11-20 21:55 - 2013-09-25 02:58 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2013-11-20 21:55 - 2013-09-25 02:57 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2013-11-20 21:55 - 2013-09-25 02:57 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2013-11-20 21:55 - 2013-09-25 02:56 - 00220160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2013-11-20 21:55 - 2013-09-25 02:03 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2013-11-20 21:55 - 2013-07-04 13:18 - 00458712 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2013-11-20 21:02 - 2013-10-12 09:45 - 02241536 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-11-20 21:02 - 2013-10-12 09:45 - 01364992 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-11-20 21:02 - 2013-10-12 09:45 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-11-20 21:02 - 2013-10-12 09:43 - 19269632 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 15404544 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 03959808 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-11-20 21:02 - 2013-10-12 09:43 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-11-20 21:02 - 2013-10-12 08:03 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-11-20 21:02 - 2013-10-12 08:03 - 01138176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 14355968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 13761024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 02877952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 02049024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-11-20 21:02 - 2013-10-12 08:02 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-11-20 21:02 - 2013-10-12 07:35 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-11-20 21:02 - 2013-10-12 07:08 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-11-20 21:02 - 2013-10-12 06:44 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-11-20 21:02 - 2013-10-12 06:15 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-11-20 20:57 - 2013-11-20 20:57 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-11-20 20:53 - 2013-11-20 21:51 - 00000000 ____D C:\Program Files\7-Zip 2013-11-19 20:22 - 2013-11-20 21:51 - 00000000 ____D C:\Program Files (x86)\Opera 2013-11-19 20:22 - 2013-11-19 20:22 - 00000000 ____D C:\Users\Moe\AppData\Roaming\Opera Software 2013-11-19 20:22 - 2013-11-19 20:22 - 00000000 ____D C:\Users\Moe\AppData\Local\Opera Software 2013-11-17 14:26 - 2013-11-20 21:22 - 00000000 ____D C:\Users\Moe\Desktop\STREAM 2013-11-16 18:00 - 2013-11-16 18:16 - 00000000 ____D C:\Users\Moe\Desktop\Playlist 2013-11-02 15:14 - 2013-11-20 21:56 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner 2013-11-01 00:16 - 2013-11-10 22:53 - 00442325 _____ C:\Users\Moe\Downloads\Downloads.rar 2013-10-28 17:46 - 2013-11-09 00:12 - 00000000 ____D C:\Users\Moe\Desktop\Musik 2013-10-22 10:39 - 2013-10-22 10:39 - 00000000 ____D C:\Program Files\Java 2013-10-22 10:33 - 2013-11-20 22:37 - 00000000 ____D C:\ProgramData\Oracle ==================== One Month Modified Files and Folders ======= 2013-11-21 18:01 - 2013-11-21 08:07 - 00013064 _____ C:\Users\Moe\Downloads\FRST.txt 2013-11-21 17:59 - 2013-11-21 17:59 - 00000754 _____ C:\Users\Moe\Desktop\JRT.txt 2013-11-21 17:51 - 2009-07-14 05:45 - 00022080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-11-21 17:51 - 2009-07-14 05:45 - 00022080 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-11-21 17:50 - 2011-04-12 08:43 - 00697082 _____ C:\Windows\system32\perfh007.dat 2013-11-21 17:50 - 2011-04-12 08:43 - 00148346 _____ C:\Windows\system32\perfc007.dat 2013-11-21 17:50 - 2009-07-14 06:13 - 01613340 _____ C:\Windows\system32\PerfStringBackup.INI 2013-11-21 17:47 - 2013-11-21 17:47 - 00000000 ____D C:\Windows\ERUNT 2013-11-21 17:47 - 2013-02-23 22:34 - 00000000 ____D C:\Users\Moe\AppData\Roaming\Dropbox 2013-11-21 17:46 - 2013-11-21 17:46 - 01034531 _____ (Thisisu) C:\Users\Moe\Desktop\JRT.exe 2013-11-21 17:45 - 2013-02-23 22:35 - 00000000 ___RD C:\Users\Moe\Dropbox 2013-11-21 17:45 - 2013-02-23 13:15 - 00004182 _____ C:\Windows\System32\Tasks\avast! Emergency Update 2013-11-21 17:45 - 2013-02-22 19:03 - 00003316 _____ C:\Windows\System32\Tasks\Intel® Rapid Start Technology Manager 2013-11-21 17:44 - 2013-02-22 18:06 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2013-11-21 17:44 - 2013-02-22 13:11 - 01811439 _____ C:\Windows\WindowsUpdate.log 2013-11-21 17:44 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-11-21 17:44 - 2009-07-14 05:51 - 00063177 _____ C:\Windows\setupact.log 2013-11-21 17:43 - 2013-11-21 17:42 - 00000000 ____D C:\AdwCleaner 2013-11-21 17:42 - 2013-11-21 17:42 - 01085542 _____ C:\Users\Moe\Desktop\adwcleaner.exe 2013-11-21 17:40 - 2013-02-22 17:56 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-11-21 15:39 - 2013-11-21 15:31 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2013-11-21 15:39 - 2013-11-21 15:26 - 00000000 ____D C:\Users\Moe\Desktop\mbar 2013-11-21 15:31 - 2013-11-21 15:31 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2013-11-21 15:31 - 2013-11-21 15:31 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-11-21 15:27 - 2013-11-21 15:27 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-11-21 15:26 - 2013-11-21 15:26 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Moe\Downloads\mbar-1.07.0.1007.exe 2013-11-21 15:26 - 2013-11-21 15:26 - 12576792 _____ (Malwarebytes Corp.) C:\Users\Moe\Desktop\mbar-1.07.0.1007.exe 2013-11-21 08:45 - 2013-11-21 08:43 - 214434571 _____ C:\Users\Moe\Downloads\No Matter-video.3gp 2013-11-21 08:08 - 2013-11-21 08:08 - 00017272 _____ C:\Users\Moe\Downloads\Addition.txt 2013-11-21 08:07 - 2013-11-21 08:07 - 00000000 ____D C:\FRST 2013-11-21 08:07 - 2013-11-21 08:06 - 01957964 _____ (Farbar) C:\Users\Moe\Downloads\FRST64.exe 2013-11-20 22:48 - 2013-09-30 22:03 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-11-20 22:42 - 2013-11-20 22:41 - 00000000 ____D C:\Program Files (x86)\QuickTime 2013-11-20 22:41 - 2013-11-20 22:41 - 00000000 ____D C:\ProgramData\Apple Computer 2013-11-20 22:41 - 2013-11-20 22:40 - 41404760 _____ (Apple Inc.) C:\Users\Moe\Downloads\QuickTimeInstaller.exe 2013-11-20 22:39 - 2013-02-22 17:56 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-11-20 22:39 - 2013-02-22 17:56 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-11-20 22:39 - 2013-02-22 17:56 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-11-20 22:38 - 2013-02-23 23:23 - 00000000 ____D C:\Users\Moe\AppData\Local\Adobe 2013-11-20 22:37 - 2013-11-20 22:37 - 00312744 _____ (Oracle Corporation) C:\Windows\system32\javaws.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\javaw.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00189352 _____ (Oracle Corporation) C:\Windows\system32\java.exe 2013-11-20 22:37 - 2013-11-20 22:37 - 00108968 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll 2013-11-20 22:37 - 2013-10-22 10:33 - 00000000 ____D C:\ProgramData\Oracle 2013-11-20 22:36 - 2013-11-20 22:36 - 30694824 _____ (Oracle Corporation) C:\Users\Moe\Downloads\jre-7u45-windows-x64.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2013-11-20 22:35 - 2013-11-20 22:35 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2013-11-20 22:35 - 2013-05-05 10:09 - 00000000 ____D C:\Program Files (x86)\Java 2013-11-20 22:25 - 2010-11-21 04:47 - 00009902 _____ C:\Windows\PFRO.log 2013-11-20 22:17 - 2013-11-20 22:17 - 00018012 _____ C:\Users\Moe\Downloads\Result.txt 2013-11-20 22:16 - 2013-11-20 22:16 - 00760937 _____ (Farbar) C:\Users\Moe\Downloads\MiniToolBox.exe 2013-11-20 21:56 - 2013-11-02 15:14 - 00000000 ____D C:\Program Files (x86)\MSI Afterburner 2013-11-20 21:56 - 2013-10-04 16:02 - 00000000 ____D C:\Program Files (x86)\HyperCam 3 2013-11-20 21:56 - 2013-08-28 13:10 - 00000000 ___RD C:\Program Files (x86)\Skype 2013-11-20 21:56 - 2013-08-28 13:10 - 00000000 ____D C:\Users\Moe\AppData\Roaming\Skype 2013-11-20 21:56 - 2013-08-28 13:10 - 00000000 ____D C:\ProgramData\Skype 2013-11-20 21:56 - 2013-08-08 12:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-11-20 21:56 - 2013-03-16 09:42 - 00000000 ____D C:\Users\Moe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR 2013-11-20 21:56 - 2013-03-16 09:41 - 00000000 ____D C:\Program Files\WinRAR 2013-11-20 21:56 - 2013-02-25 22:18 - 00000000 ____D C:\Users\Moe\AppData\Roaming\vlc 2013-11-20 21:56 - 2013-02-25 19:52 - 00000000 ____D C:\Users\Moe\Documents\Assassin's Creed III 2013-11-20 21:56 - 2013-02-24 12:26 - 00000000 ____D C:\Users\Moe\AppData\Local\Brice_Lambson 2013-11-20 21:56 - 2013-02-23 11:48 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-11-20 21:56 - 2011-04-12 08:54 - 00000000 ___RD C:\Users\Public\Recorded TV 2013-11-20 21:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-11-20 21:56 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\registration 2013-11-20 21:56 - 2009-07-14 04:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2013-11-20 21:51 - 2013-11-20 20:53 - 00000000 ____D C:\Program Files\7-Zip 2013-11-20 21:51 - 2013-11-19 20:22 - 00000000 ____D C:\Program Files (x86)\Opera 2013-11-20 21:22 - 2013-11-17 14:26 - 00000000 ____D C:\Users\Moe\Desktop\STREAM 2013-11-20 21:02 - 2013-02-27 18:53 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-11-20 21:01 - 2013-08-14 17:51 - 00000000 ____D C:\Windows\system32\MRT 2013-11-20 21:00 - 2013-02-23 11:58 - 82896128 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-11-20 20:59 - 2013-02-22 13:11 - 00000000 ___RD C:\Users\Moe\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-11-20 20:57 - 2013-11-20 20:57 - 00001922 _____ C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2013-11-20 20:57 - 2013-02-23 13:15 - 00000000 _____ C:\Windows\SysWOW64\config.nt 2013-11-20 20:57 - 2013-02-22 13:11 - 00000000 ____D C:\Users\Moe 2013-11-20 20:51 - 2013-10-04 16:05 - 00000000 ____D C:\Users\Moe\AppData\Roaming\Solveig Multimedia 2013-11-19 20:22 - 2013-11-19 20:22 - 00000000 ____D C:\Users\Moe\AppData\Roaming\Opera Software 2013-11-19 20:22 - 2013-11-19 20:22 - 00000000 ____D C:\Users\Moe\AppData\Local\Opera Software 2013-11-16 18:16 - 2013-11-16 18:00 - 00000000 ____D C:\Users\Moe\Desktop\Playlist 2013-11-10 22:53 - 2013-11-01 00:16 - 00442325 _____ C:\Users\Moe\Downloads\Downloads.rar 2013-11-09 00:12 - 2013-10-28 17:46 - 00000000 ____D C:\Users\Moe\Desktop\Musik 2013-11-02 15:15 - 2013-02-23 22:24 - 00000000 ___HD C:\Windows\msdownld.tmp 2013-10-22 10:39 - 2013-10-22 10:39 - 00000000 ____D C:\Program Files\Java Some content of TEMP: ==================== C:\Users\Moe\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\Moe\AppData\Local\Temp\icqsetup.exe C:\Users\Moe\AppData\Local\Temp\jre-7u25-windows-i586-iftw.exe C:\Users\Moe\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Moe\AppData\Local\Temp\ose00000.exe C:\Users\Moe\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-11-20 20:07 ==================== End Of Log ============================ --- --- --- Übrigens: heute tritt das Problem bisher nicht auf. |
22.11.2013, 00:01 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Internet hat ständig Hänger Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
22.11.2013, 19:55 | #9 |
| Internet hat ständig Hänger Diesmal wurde auch was gefunden: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.11.22.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16736 Moe :: ULTRAMOE [Administrator] 22.11.2013 18:50:40 mbam-log-2013-11-22 (18-50-40).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 235021 Laufzeit: 2 Minute(n), 9 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Moe\AppData\Local\Temp\TlkxmTp9.exe.part (Adware.DomaIQ) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internet# version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=9976b3b8c7d85d41b1ccb7f3c7abac14 # engine=15991 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-11-22 06:50:17 # local_time=2013-11-22 07:50:17 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=774 16777213 85 91 165204 161856089 0 0 # compatibility_mode=5893 16776573 100 94 3775 136776067 0 0 # scanned=146648 # found=0 # cleaned=0 # scan_time=2883 |
23.11.2013, 01:13 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Internet hat ständig Hänger Nur ein Rest in TEMP. Bitte TFC ausführen: TFC - Temp File Cleaner Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
__________________ Logfiles bitte immer in CODE-Tags posten |
24.11.2013, 22:35 | #11 |
| Internet hat ständig Hänger Hey, hab ich gemacht. Und nu? :-) |
25.11.2013, 09:48 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Internet hat ständig Hänger Sieht soweit ok aus Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat. Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie ) Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird. Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Internet hat ständig Hänger |
adapter, administrator, bios, cdrom, computer, defender, dns, drahtlos, dsl, firefox, internet, memory.dmp, neustarten, office, probleme, proxy, proxy server, reset, server, standardgateway, system, system32, telekom, teredo, treiber, win32, windows, winsock, zurücksetzen |