|
Log-Analyse und Auswertung: Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nichtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
04.12.2013, 20:07 | #1 |
| Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht Mein Acer Aspire 7741G-374G50BNKK Windows 7 Home Premium lädt schon eine ganze Weile Spiele nur noch sehr langsam oder gar nicht. Habe schon alles mögliche probiert und habe das Gefühl alles nur schlimmer gemacht zu haben. Hab den Autostart schon aufgeräumt und Defraggler durchlaufen lassen, ohne spürbaren Unterschied. Defogger-Log: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 19:23 on 04/12/2013 (Martin) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-12-2013 Ran by Martin (administrator) on MARTIN-PC on 04-12-2013 19:26:23 Running from C:\Users\Martin\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (cake bake) C:\Program Files (x86)\Betcat\WBDesktop.Updater.1.0.0.16.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-23] (Alcor Micro Corp.) HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-02-01] (Egis Technology Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9643552 2009-12-11] (Realtek Semiconductor) HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-04-23] (Acer Incorporated) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated) HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [911160 2012-01-18] (Microsoft Corporation) MountPoints2: {abc20d1c-bae3-11df-91f0-806e6f6e6963} - D:\AUTORUN.EXE HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-02-01] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201512 2009-12-25] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [401192 2009-12-25] (Egis Technology Inc.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-22] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\Gast\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-07] (Google Inc.) AppInit_DLLs-x32: c:\progra~3\bitguard\261673~1.238\{c16c1~1\bitguard.dll [ ] () BootExecute: autocheck autochk /p \??\E:autocheck autochk /p \??\F:autocheck autochk * ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.babylon.com/?affID=119357&babsrc=HP_ss_din2g&mntrId=60535CAC4C04FAE7 HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7741&r=27360111h906l0458z105t4791o183 HKCU\Software\Microsoft\Internet Explorer\Main,ICQ Search = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7741&r=27360111h906l0458z105t4791o183 HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7741&r=27360111h906l0458z105t4791o183 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7741&r=27360111h906l0458z105t4791o183 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7741&r=27360111h906l0458z105t4791o183 URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} URLSearchHook: HKLM-x32 - (No Name) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - No File URLSearchHook: HKCU - (No Name) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - No File StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM-x32 - DefaultScope {AFDBDDAA-5D3F-42EE-B79C-185A7020515B} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157 SearchScopes: HKLM-x32 - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157 SearchScopes: HKCU - DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=60535CAC4C04FAE7&affID=119357&tsp=5016 SearchScopes: HKCU - {0D7562AE-8EF6-416d-A838-AB665251703A} URL = hxxp://start.facemoods.com/?a=ddrnw&s={searchTerms}&f=4 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.searchgol.com/?q={searchTerms}&babsrc=SP_ss&mntrId=60535CAC4C04FAE7&affID=119357&tsp=5016 SearchScopes: HKCU - {6552C7DD-90A4-4387-B795-F8F96747DE19} URL = hxxp://search.icq.com/search/results.php?q={searchTerms}&ch_id=osd SearchScopes: HKCU - {afdbddaa-5d3f-42ee-b79c-185a7020515b} URL = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT2304157 SearchScopes: HKCU - {B822788F-260D-4ED7-BD47-D6CF28F1FC67} URL = hxxp://websearch.ask.com/redirect?client=ie&tb=AVR-3&o=APN10395&src=crm&q={searchTerms}&locale=de_DE&apn_ptnrs=^ABT&apn_dtid=^YYYYYY^YY^DE&apn_uid=0dbfdc31-64ed-4b87-b078-85000e1612b9&apn_sauid=3A710854-A7B1-4B33-B94B-F02030281D6A BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg64.dll (Google Inc.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: SenselessTV Video Plugin - {991D97B8-F0D8-4EA1-9100-7A65EA2D3A63} - C:\Users\Martin\AppData\Roaming\SenselessTV\bho.dll () BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: BHO_HelloWorld.BHO - {cbfb5c65-652c-3e10-9d9a-e586816d9342} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll (APN LLC.) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - No Name - {30F9B915-B755-4826-820B-08FBA6BD249D} - No File Toolbar: HKCU - No Name - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - No File Toolbar: HKCU - No Name - {EEE6C35B-6118-11DC-9C72-001320C79847} - No File Toolbar: HKCU - No Name - {D4027C7F-154A-4066-A1AD-4243D8127440} - No File Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - No File Handler-x32: gcf - No CLSID Value - Tcpip\Parameters: [DhcpNameServer] 168.95.1.1 FireFox: ======== FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default FF user.js: detected! => C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\user.js FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.1.13 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @lightspark.github.com/Lightspark;version=1 - C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll No File FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Martin\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Martin\AppData\Local\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\searchplugins\askcom.xml FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\searchplugins\babylon.xml FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\searchplugins\delta.xml FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\searchplugins\icqplugin.xml FF SearchPlugin: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\searchplugins\sweetim.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\fcmdSrch.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: Conduit Engine - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\engine@conduit.com FF Extension: No Name - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\ffxtlbr@babylon.com FF Extension: Softonic Toolbar - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\ffxtlbra@softonic.com FF Extension: No Name - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\staged FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\toolbar_AVIRA-V7@apn.ask.com FF Extension: DVDVideoSoftTB Community Toolbar - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} FF Extension: DVDVideoSoft Menu - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} FF Extension: ST-de3 Community Toolbar - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} FF Extension: toolbar_AVIRA-V7 - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi FF Extension: stylish - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi FF Extension: No Name - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{6C8B07BF-0F6D-4EA4-B96F-FF1CCBAAE553}.xpi FF Extension: Adblock Plus - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: No Name - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF HKLM-x32\...\Firefox\Extensions: [{000a9d1c-beef-4f90-9363-039d445309b8}] - C:\Program Files (x86)\Google\Google Gears\Firefox\ FF Extension: Google Gears - C:\Program Files (x86)\Google\Google Gears\Firefox\ FF HKLM-x32\...\Firefox\Extensions: [support@Senseless.TV] - C:\Users\Martin\AppData\Roaming\SenselessTV\ffextension FF Extension: SenselessTV Video Plugin - C:\Users\Martin\AppData\Roaming\SenselessTV\ffextension FF HKCU\...\Firefox\Extensions: [{EB132DB0-A4CA-11DF-9732-0E29E0D72085}] - C:\Program Files (x86)\profilinstylin\profilinstylin FF HKCU\...\Firefox\Extensions: [support@Senseless.TV] - C:\Users\Martin\AppData\Roaming\SenselessTV\ffextension FF Extension: SenselessTV Video Plugin - C:\Users\Martin\AppData\Roaming\SenselessTV\ffextension Chrome: ======= CHR HomePage: hxxp://search.babylon.com/?affID=119357&babsrc=HP_ss_din2g&mntrId=60535CAC4C04FAE7 CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.57\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.57\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll No File CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll No File CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) CHR Extension: (Avira SearchFree Toolbar plus Web Protection) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh\25.62088_0 CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Stylish) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe\1.2_0 CHR Extension: (AdBlock) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0 CHR Extension: (AT_Porsche) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg\3_0 CHR Extension: (SenselessTV Video Plugin) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlicihemmeabfjhdckhpkmopojohlkab\1.0_0 CHR Extension: (Google Wallet) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR HKLM-x32\...\Chrome\Extension: [aaaaacalgebmfelllfiaoknifldpngjh] - C:\ProgramData\AskPartnerNetwork\Toolbar\AVIRA-V7\CRX\ToolbarCR.crx CHR HKLM-x32\...\Chrome\Extension: [fmfnfnpmhcllokmkepffndflpnadjmma] - C:\Program Files (x86)\DealPly\DealPly.crx CHR HKLM-x32\...\Chrome\Extension: [ieadcoanfjloocmfafkebdnfefmohngj] - C:\Program Files (x86)\BonanzaDeals\BonanzaDeals.crx CHR HKLM-x32\...\Chrome\Extension: [jlicihemmeabfjhdckhpkmopojohlkab] - C:\Users\Martin\AppData\Roaming\SenselessTV\SenselessTV.crx CHR StartMenuInternet: Google Chrome - C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-05] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-05] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-05] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.) S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-02-01] (Egis Technology Inc.) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75064 2011-07-08] () R2 WebCake Desktop Updater; C:\Program Files (x86)\Betcat\WBDesktop.Updater.1.0.0.16.exe [51992 2013-08-21] (cake bake) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-05] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-05] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-09-01] (Avira Operations GmbH & Co. KG) S1 prodrv06; C:\Windows\SysWow64\drivers\prodrv06.sys [54272 2004-04-08] (Protection Technology) S0 prohlp02; C:\Windows\SysWow64\drivers\prohlp02.sys [70400 2004-04-08] (Protection Technology) S0 prosync1; C:\Windows\SysWow64\drivers\prosync1.sys [6944 2003-09-06] (Protection Technology) S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44032 2011-07-20] (Research in Motion Ltd) S0 sfhlp01; C:\Windows\SysWow64\drivers\sfhlp01.sys [4832 2003-12-01] (Protection Technology) R2 {B154377D-700F-42cc-9474-23858FBDF4BD}; c:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [146928 2010-01-22] (CyberLink Corp.) S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena\safedrv.sys [x] S3 k57nd60a; system32\DRIVERS\k57nd60a.sys [x] S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-04 19:26 - 2013-12-04 19:27 - 00027181 _____ C:\Users\Martin\Downloads\FRST.txt 2013-12-04 19:26 - 2013-12-04 19:26 - 00000000 ____D C:\FRST 2013-12-04 19:25 - 2013-12-04 19:25 - 01959766 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe 2013-12-04 19:23 - 2013-12-04 19:23 - 00000474 _____ C:\Users\Martin\Downloads\defogger_disable.log 2013-12-04 19:23 - 2013-12-04 19:23 - 00000000 _____ C:\Users\Martin\defogger_reenable 2013-12-04 19:18 - 2013-12-04 19:18 - 00050477 _____ C:\Users\Martin\Downloads\Defogger (1).exe 2013-12-04 19:16 - 2013-12-04 19:16 - 00050477 _____ C:\Users\Martin\Downloads\Defogger.exe 2013-12-04 18:25 - 2013-12-04 18:25 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2013-12-04 18:25 - 2013-12-04 18:25 - 00000000 ____D C:\Program Files\Synaptics 2013-12-04 18:24 - 2013-12-04 18:26 - 00005258 _____ C:\Windows\DPINST.LOG 2013-12-04 18:24 - 2009-09-17 20:12 - 00292912 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys 2013-12-04 18:24 - 2009-09-17 20:09 - 00396072 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll 2013-12-04 18:24 - 2009-09-17 20:09 - 00263464 _____ (Synaptics Incorporated) C:\Windows\system32\SynCtrl.dll 2013-12-04 18:24 - 2009-09-17 20:09 - 00206120 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCtrl.dll 2013-12-04 18:24 - 2009-09-17 20:09 - 00205608 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll 2013-12-04 18:24 - 2009-09-17 20:09 - 00169256 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCOM.dll 2013-12-04 18:24 - 2009-09-17 20:09 - 00147752 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo4.dll 2013-12-04 18:24 - 2009-09-17 20:09 - 00107816 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynTPCOM.dll 2013-12-04 18:20 - 2009-09-17 20:09 - 00214312 _____ (Synaptics Incorporated) C:\Users\Martin\Setup.exe 2013-12-04 18:03 - 2013-12-04 18:17 - 30569167 _____ C:\Users\Martin\Downloads\TouchPad_Synaptics_14.0.6.0_W7x86W7x64_A.zip 2013-12-04 17:30 - 2013-12-04 17:30 - 00001054 _____ C:\Windows\PFRO.log 2013-12-03 21:14 - 2013-12-04 19:20 - 00000467 _____ C:\Windows\setupact.log 2013-12-03 21:14 - 2013-12-03 21:14 - 00000000 _____ C:\Windows\setuperr.log 2013-12-03 21:12 - 2013-12-03 21:12 - 00000020 _____ C:\Users\Martin\Desktop\ram.vbe 2013-12-03 20:29 - 2013-12-03 20:29 - 00001728 _____ C:\Users\Public\Desktop\Defraggler.lnk 2013-12-03 20:29 - 2013-12-03 20:29 - 00000000 ____D C:\Program Files\Defraggler 2013-12-03 20:28 - 2013-12-03 20:28 - 04208656 _____ (Piriform Ltd) C:\Users\Martin\Downloads\dfsetup216.exe 2013-12-03 20:13 - 2013-12-03 20:13 - 00029054 _____ C:\Users\Martin\Documents\cc_20131203_201306.reg 2013-12-03 20:13 - 2013-12-03 20:13 - 00000686 _____ C:\Users\Martin\Documents\cc_20131203_201328.reg 2013-12-03 20:12 - 2013-12-03 20:12 - 00320468 _____ C:\Users\Martin\Documents\cc_20131203_201226.reg 2013-12-03 20:09 - 2013-12-03 20:09 - 00614784 _____ C:\Users\Martin\Downloads\Defraggler - CHIP-Downloader.exe 2013-12-03 20:08 - 2013-12-03 20:08 - 00002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-12-03 20:08 - 2013-12-03 20:08 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-12-03 20:08 - 2013-12-03 20:08 - 00000000 ____D C:\Program Files\CCleaner 2013-12-03 20:06 - 2013-12-03 20:06 - 00614784 _____ C:\Users\Martin\Downloads\CCleaner - CHIP-Downloader.exe 2013-12-03 17:07 - 2013-12-03 17:07 - 00001192 _____ C:\Users\Martin\Desktop\FL Studio 10.lnk 2013-12-02 23:46 - 2013-12-02 23:57 - 159401976 _____ (Advanced Micro Devices, Inc.) C:\Users\Martin\Downloads\12-6_vista_win7_64_dd_ccc.exe 2013-12-02 23:12 - 2013-12-02 23:12 - 00000000 ____D C:\Program Files\ATI Technologies 2013-12-02 23:10 - 2013-12-02 23:10 - 00000000 ____D C:\AMD 2013-12-02 20:58 - 2013-12-02 21:01 - 00000000 ____D C:\Users\Martin\Documents\Visual Studio 2005 2013-12-02 20:18 - 2013-12-02 20:20 - 00000000 ____D C:\Users\Martin\AppData\Roaming\LiveTV Wilmaa 2013-12-02 20:18 - 2013-12-02 20:18 - 00000326 _____ C:\Users\Martin\Desktop\LiveTV Sammlung.appref-ms 2013-12-02 20:18 - 2013-12-02 20:18 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LSWARE 2013-12-02 20:17 - 2013-12-02 20:17 - 00567296 _____ () C:\Users\Martin\Desktop\setup.exe 2013-12-02 20:16 - 2013-12-02 20:16 - 00401752 _____ (Softonic ) C:\Users\Martin\Downloads\SoftonicDownloader_fuer_livetv-wilmaa.exe ==================== One Month Modified Files and Folders ======= 2013-12-04 19:27 - 2013-12-04 19:26 - 00027181 _____ C:\Users\Martin\Downloads\FRST.txt 2013-12-04 19:26 - 2013-12-04 19:26 - 00000000 ____D C:\FRST 2013-12-04 19:25 - 2013-12-04 19:25 - 01959766 _____ (Farbar) C:\Users\Martin\Downloads\FRST64.exe 2013-12-04 19:25 - 2010-09-08 11:49 - 00657948 _____ C:\Windows\system32\perfh007.dat 2013-12-04 19:25 - 2010-09-08 11:49 - 00131288 _____ C:\Windows\system32\perfc007.dat 2013-12-04 19:25 - 2010-09-08 02:01 - 01556432 _____ C:\Windows\WindowsUpdate.log 2013-12-04 19:25 - 2009-07-14 06:13 - 01507502 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-04 19:23 - 2013-12-04 19:23 - 00000474 _____ C:\Users\Martin\Downloads\defogger_disable.log 2013-12-04 19:23 - 2013-12-04 19:23 - 00000000 _____ C:\Users\Martin\defogger_reenable 2013-12-04 19:23 - 2011-01-26 15:58 - 00000000 ____D C:\Users\Martin 2013-12-04 19:21 - 2012-02-05 22:46 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2013-12-04 19:21 - 2011-11-29 17:28 - 00000266 _____ C:\Windows\Tasks\AutoKMS.job 2013-12-04 19:21 - 2011-05-21 16:38 - 00000298 _____ C:\Windows\Tasks\Updater.job 2013-12-04 19:21 - 2011-01-26 21:52 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-04 19:21 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-04 19:20 - 2013-12-03 21:14 - 00000467 _____ C:\Windows\setupact.log 2013-12-04 19:18 - 2013-12-04 19:18 - 00050477 _____ C:\Users\Martin\Downloads\Defogger (1).exe 2013-12-04 19:16 - 2013-12-04 19:16 - 00050477 _____ C:\Users\Martin\Downloads\Defogger.exe 2013-12-04 18:54 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-04 18:42 - 2011-02-13 18:09 - 00000000 ____D C:\Users\Martin\Documents\TrackMania 2013-12-04 18:34 - 2009-07-14 05:45 - 00025840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-04 18:34 - 2009-07-14 05:45 - 00025840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-04 18:30 - 2011-07-09 02:06 - 00000000 ____D C:\ProgramData\TrackMania 2013-12-04 18:27 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\tracing 2013-12-04 18:26 - 2013-12-04 18:24 - 00005258 _____ C:\Windows\DPINST.LOG 2013-12-04 18:25 - 2013-12-04 18:25 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2013-12-04 18:25 - 2013-12-04 18:25 - 00000000 ____D C:\Program Files\Synaptics 2013-12-04 18:18 - 2013-06-09 19:15 - 00000290 _____ C:\Windows\Tasks\DSite.job 2013-12-04 18:17 - 2013-12-04 18:03 - 30569167 _____ C:\Users\Martin\Downloads\TouchPad_Synaptics_14.0.6.0_W7x86W7x64_A.zip 2013-12-04 17:57 - 2011-04-16 16:33 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000UA.job 2013-12-04 17:56 - 2011-01-26 21:52 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-04 17:31 - 2009-07-14 05:45 - 00416368 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-04 17:30 - 2013-12-04 17:30 - 00001054 _____ C:\Windows\PFRO.log 2013-12-03 21:14 - 2013-12-03 21:14 - 00000000 _____ C:\Windows\setuperr.log 2013-12-03 21:12 - 2013-12-03 21:12 - 00000020 _____ C:\Users\Martin\Desktop\ram.vbe 2013-12-03 20:50 - 2012-03-19 00:25 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{BFC5884C-E550-49B6-8B94-FD1750F17A22} 2013-12-03 20:29 - 2013-12-03 20:29 - 00001728 _____ C:\Users\Public\Desktop\Defraggler.lnk 2013-12-03 20:29 - 2013-12-03 20:29 - 00000000 ____D C:\Program Files\Defraggler 2013-12-03 20:28 - 2013-12-03 20:28 - 04208656 _____ (Piriform Ltd) C:\Users\Martin\Downloads\dfsetup216.exe 2013-12-03 20:24 - 2011-01-26 15:58 - 00108824 _____ C:\Users\Martin\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-03 20:13 - 2013-12-03 20:13 - 00029054 _____ C:\Users\Martin\Documents\cc_20131203_201306.reg 2013-12-03 20:13 - 2013-12-03 20:13 - 00000686 _____ C:\Users\Martin\Documents\cc_20131203_201328.reg 2013-12-03 20:12 - 2013-12-03 20:12 - 00320468 _____ C:\Users\Martin\Documents\cc_20131203_201226.reg 2013-12-03 20:11 - 2011-02-18 01:02 - 00000000 ____D C:\Users\Martin\Tracing 2013-12-03 20:11 - 2011-01-31 15:23 - 00000000 ____D C:\Program Files\Steam 2013-12-03 20:11 - 2009-07-27 21:41 - 00000000 ____D C:\Windows\Panther 2013-12-03 20:09 - 2013-12-03 20:09 - 00614784 _____ C:\Users\Martin\Downloads\Defraggler - CHIP-Downloader.exe 2013-12-03 20:08 - 2013-12-03 20:08 - 00002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-12-03 20:08 - 2013-12-03 20:08 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-12-03 20:08 - 2013-12-03 20:08 - 00000000 ____D C:\Program Files\CCleaner 2013-12-03 20:06 - 2013-12-03 20:06 - 00614784 _____ C:\Users\Martin\Downloads\CCleaner - CHIP-Downloader.exe 2013-12-03 19:58 - 2011-01-26 23:16 - 00000000 ____D C:\Users\Martin\AppData\Roaming\vlc 2013-12-03 19:57 - 2011-04-16 16:33 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000Core.job 2013-12-03 17:07 - 2013-12-03 17:07 - 00001192 _____ C:\Users\Martin\Desktop\FL Studio 10.lnk 2013-12-03 15:46 - 2011-01-27 00:13 - 00000000 ____D C:\ProgramData\boost_interprocess 2013-12-02 23:57 - 2013-12-02 23:46 - 159401976 _____ (Advanced Micro Devices, Inc.) C:\Users\Martin\Downloads\12-6_vista_win7_64_dd_ccc.exe 2013-12-02 23:12 - 2013-12-02 23:12 - 00000000 ____D C:\Program Files\ATI Technologies 2013-12-02 23:10 - 2013-12-02 23:10 - 00000000 ____D C:\AMD 2013-12-02 21:01 - 2013-12-02 20:58 - 00000000 ____D C:\Users\Martin\Documents\Visual Studio 2005 2013-12-02 20:48 - 2011-11-30 17:44 - 00000000 ____D C:\Users\Martin\AppData\Local\Deployment 2013-12-02 20:27 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-12-02 20:20 - 2013-12-02 20:18 - 00000000 ____D C:\Users\Martin\AppData\Roaming\LiveTV Wilmaa 2013-12-02 20:18 - 2013-12-02 20:18 - 00000326 _____ C:\Users\Martin\Desktop\LiveTV Sammlung.appref-ms 2013-12-02 20:18 - 2013-12-02 20:18 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LSWARE 2013-12-02 20:17 - 2013-12-02 20:17 - 00567296 _____ () C:\Users\Martin\Desktop\setup.exe 2013-12-02 20:16 - 2013-12-02 20:16 - 00401752 _____ (Softonic ) C:\Users\Martin\Downloads\SoftonicDownloader_fuer_livetv-wilmaa.exe 2013-11-24 20:08 - 2011-04-16 16:34 - 00002366 _____ C:\Users\Martin\Desktop\Google Chrome.lnk 2013-11-24 19:52 - 2011-04-16 16:33 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000UA 2013-11-24 19:52 - 2011-04-16 16:33 - 00003704 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000Core 2013-11-24 19:51 - 2011-01-26 21:52 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-11-24 19:51 - 2011-01-26 21:52 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore Files to move or delete: ==================== C:\Users\Martin\Setup.exe Some content of TEMP: ==================== C:\Users\Gast\AppData\Local\Temp\AskSLib.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-03 18:30 ==================== End Of Log ============================ Addition-Log Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 04-12-2013 Ran by Martin at 2013-12-04 19:27:45 Running from C:\Users\Martin\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Acer Backup Manager (x32 Version: 2.0.0.60) Acer Crystal Eye webcam (x32 Version: 1.0.3.5) Acer ePower Management (x32 Version: 5.00.3004) Acer eRecovery Management (x32 Version: 4.05.3011) Acer Registration (x32 Version: 1.03.3003) Acer ScreenSaver (x32 Version: 1.1.0423.2010) Acer Updater (x32 Version: 1.02.3001) Acrobat.com (x32 Version: 1.6.65) Adobe AIR (x32 Version: 1.5.0.7220) Adobe Flash Player 11 ActiveX (x32 Version: 11.6.602.180) Adobe Flash Player 11 Plugin (x32 Version: 11.6.602.180) Adobe Reader 9.5.5 MUI (x32 Version: 9.5.5) Alcor Micro USB Card Reader (x32 Version: 1.5.17.05094) ALPS Touch Pad Driver (Version: 7.105.2015.1107) Apple Application Support (x32 Version: 2.3.6) Apple Mobile Device Support (Version: 7.0.0.117) Apple Software Update (x32 Version: 2.1.3.127) Avira Free Antivirus (x32 Version: 13.0.0.4052) Avira SearchFree Toolbar (x32 Version: 12.6.0.1900) Backup Manager Basic (x32 Version: 2.0.0.60) Bonjour (Version: 3.0.0.10) Call of Duty(R) 4 - Modern Warfare(TM) 1.1 Patch (x32 Version: 1.1) Call of Duty(R) 4 - Modern Warfare(TM) 1.1 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch (x32 Version: 1.2) Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch (x32 Version: 1.3) Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch (x32 Version: 1.4) Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Patch (x32 Version: 1.5) Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (x32 Version: 1.6) Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (x32 Version: 1.7) Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (x32) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Core Implementation (x32 Version: 2010.0122.858.16002) Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0122.858.16002) Catalyst Control Center Graphics Full New (x32 Version: 2010.0122.858.16002) Catalyst Control Center Graphics Light (x32 Version: 2010.0122.858.16002) Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0122.858.16002) Catalyst Control Center InstallProxy (x32 Version: 2010.0122.858.16002) Catalyst Control Center Localization All (x32 Version: 2010.0122.858.16002) CCC Help Chinese Standard (x32 Version: 2010.0122.0857.16002) CCC Help Chinese Traditional (x32 Version: 2010.0122.0857.16002) CCC Help Czech (x32 Version: 2010.0122.0857.16002) CCC Help Danish (x32 Version: 2010.0122.0857.16002) CCC Help Dutch (x32 Version: 2010.0122.0857.16002) CCC Help English (x32 Version: 2010.0122.0857.16002) CCC Help Finnish (x32 Version: 2010.0122.0857.16002) CCC Help French (x32 Version: 2010.0122.0857.16002) CCC Help German (x32 Version: 2010.0122.0857.16002) CCC Help Greek (x32 Version: 2010.0122.0857.16002) CCC Help Hungarian (x32 Version: 2010.0122.0857.16002) CCC Help Italian (x32 Version: 2010.0122.0857.16002) CCC Help Japanese (x32 Version: 2010.0122.0857.16002) CCC Help Korean (x32 Version: 2010.0122.0857.16002) CCC Help Norwegian (x32 Version: 2010.0122.0857.16002) CCC Help Polish (x32 Version: 2010.0122.0857.16002) CCC Help Portuguese (x32 Version: 2010.0122.0857.16002) CCC Help Russian (x32 Version: 2010.0122.0857.16002) CCC Help Spanish (x32 Version: 2010.0122.0857.16002) CCC Help Swedish (x32 Version: 2010.0122.0857.16002) CCC Help Thai (x32 Version: 2010.0122.0857.16002) CCC Help Turkish (x32 Version: 2010.0122.0857.16002) ccc-core-static (x32 Version: 2010.0122.858.16002) ccc-utility64 (Version: 2010.0122.858.16002) CCleaner (Version: 4.08) Counter-Strike 1.6 (x32) CounterStrike 1.6 from VSI (Version 1.02) (x32) Counter-Strike: Source (x32) Counter-Strike: Source Beta (x32) CyberLink PowerDVD 9 (x32 Version: 9.0.2529.50) D3DX10 (x32 Version: 15.4.2368.0902) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition Defraggler (Version: 2.16) DivX-Setup (x32 Version: 2.6.1.8) DotaKeys (x32 Version: ) eBay Worldwide (x32 Version: 2.1.0901) ESI Prüfwerte (x32) ESI[tronic] DEMO_4 (x32) FL Studio 10 (x32) Full Tilt Poker.Eu (x32 Version: 4.63.11.WIN.FullTilt.EU) Google Chrome (HKCU Version: 31.0.1650.57) Google Chrome Frame (HKCU Version: 31.0.1650.57) Google Earth (x32 Version: 7.1.1.1888) Google Gears (x32 Version: 0.5.3600) Google Toolbar for Internet Explorer (x32 Version: 1.0.0) Google Toolbar for Internet Explorer (x32 Version: 7.5.4601.54) Google Update Helper (x32 Version: 1.3.21.165) Haali Media Splitter (x32) Identity Card (x32 Version: 1.00.3003) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) Rapid Storage Technology (x32 Version: 9.6.0.1014) iTunes (Version: 11.1.1.11) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) JDownloader 0.9 (x32 Version: 0.9) Junk Mail filter update (x32 Version: 15.4.3502.0922) KTS (x32 Version: 4.0.0) Launch Manager (x32 Version: 4.0.8) LiveTV Sammlung (HKCU Version: 2.0.2.2) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Outlook Hotmail Connector 64-Bit (Version: 14.0.6123.5001) Microsoft Silverlight (x32 Version: 4.1.10329.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 8.0.1 (x86 de) (x32 Version: 8.0.1) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) MyWinLocker (x32 Version: 3.1.206.0) MyWinLocker Suite (x32 Version: 3.1.206.0) Need for Speed Ultimate Colletion (x32) Need for Speed Underground 2 (x32) Norton Online Backup (x32 Version: 1.2.0.36) NTI Backup Now 5 (x32 Version: 5.1.2.628) NTI Backup Now Standard (x32 Version: 5.1.2.628) NTI Media Maker 8 (x32 Version: 8.0.12.6630) NVIDIA PhysX (x32 Version: 9.10.0513) PokerStars.net (x32) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6000) Samsung Kies (x32 Version: 2.3.0.12035_16) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.6.0) Senseless.TV Video Plugin 1.0 (x32 Version: 1.0) Shredder (Version: 2.0.5.0) Shredder (x32 Version: 2.0.5.0) Steamless Counter Strike Source Pack (x32 Version: 1.0) Synaptics Pointing Device Driver (Version: 14.0.6.0) Team Fortress 2 (x32) TmNationsForever (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition Update for Microsoft Office 2010 (KB2553270) 64-Bit Edition Update for Microsoft Office 2010 (KB2553272) 64-Bit Edition Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2598289) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2589345) 64-Bit Edition Update for Microsoft Outlook 2010 (KB2553248) 64-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) VLC media player 2.0.8 (x32 Version: 2.0.8) Welcome Center (x32 Version: 1.01.3002) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3538.0513) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3538.0513) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Messenger (x32 Version: 15.4.3538.0513) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live Sync (x32 Version: 14.0.8117.416) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8) WinRAR 4.00 (64-Bit) (Version: 4.00.0) ==================== Restore Points ========================= ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {05966E13-F996-4CAD-8D70-89CB35E37C65} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd) Task: {11FCEF4D-60A0-4E78-B94D-0E4A34A1EB4F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000Core => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-17] (Google Inc.) Task: {14365ECD-396D-4CD1-A552-91F376417A29} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3577554524-86806762-3300807997-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {1455E5BC-E812-4B69-BD29-4765674FF1CF} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12] (Oracle Corporation) Task: {25875F78-C8CC-4DD0-A1FA-E43063FA3E0B} - System32\Tasks\DSite => C:\Users\Martin\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE Task: {2C37A929-CFF3-4E0C-975D-50D56C3C1962} - System32\Tasks\{066AA482-CA98-4F6F-9AC9-72A24B653C2F} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {39C6EE68-889A-419C-BCAF-7B156E05D78B} - System32\Tasks\{3A2230D1-5151-48B4-865F-629492CC1E6C} => C:\Program Files (x86)\Skype\\Phone\Skype.exe Task: {3E5DB66E-AECF-4A72-933E-A9C978C59CFB} - System32\Tasks\DealPly => C:\Users\Martin\AppData\Roaming\DealPly\UpdateProc\UpdateTask.exe [2013-02-27] () <==== ATTENTION Task: {5396B8C0-10C7-4513-BC36-1546E34BF455} - System32\Tasks\{58691F48-DEFE-447C-9653-4FEA3F44DA99} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {69D9F157-56A5-45AB-ABAD-C3A1EEEE0E1D} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3577554524-86806762-3300807997-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {6EBC9658-0FBD-427C-9CAD-373F64EDCCA3} - System32\Tasks\{9C96BBA0-298A-4908-8211-7F908E4A874C} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {6F413E5F-0339-4ABF-ACD2-E555618A2D74} - System32\Tasks\Google Updater and Installer => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-17] (Google Inc.) Task: {795B7B6F-54FC-4F95-B903-D9838E9AB65E} - System32\Tasks\{CFF6BE17-13E5-45C9-ACAD-EC746F3C5483} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {7CD06D81-D3D2-4E28-9587-FC2B2EE501C4} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe Task: {7D75482C-99A7-4A5A-BA0F-99061DEA2F9F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-19] (Adobe Systems Incorporated) Task: {8B0CA803-1009-4B89-9A6E-AD1B472E9357} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000UA => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-17] (Google Inc.) Task: {8F10B9FB-B072-428A-B4F5-ABE881860A5C} - System32\Tasks\{20C73931-A81F-4FB3-87E1-A8C7607F90A2} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {9728C1CE-8B34-4CED-BE15-81C09A1CEA29} - System32\Tasks\{1D52CD23-40D4-41F6-BF9F-A93C85CAA1E4} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {984E0A7E-6B23-428F-BCC4-F1AEA54ED1AE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-26] (Google Inc.) Task: {9BA12277-B2E2-4D20-8764-25F50D69EAD6} - System32\Tasks\{50A74122-2781-4251-8DE6-193AF0F8836A} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {A0EC00DB-1A81-48E2-A397-E27D0EBC8C67} - System32\Tasks\Wecker => C:\Users\Martin\Music\Bohse Onkelz\Viva Los Tioz\07 Terpentin.wma Task: {A88EABAE-6282-4936-BC3E-C246E6BE2D13} - System32\Tasks\EPUpdater => C:\Users\Martin\AppData\Roaming\BabSolution\Shared\BabMaint.exe [2013-08-04] () Task: {C0879505-251C-4103-873B-C00601CCC588} - System32\Tasks\{48704270-711D-4189-A349-2DAF880C82C1} => C:\Users\Martin\Desktop\TuneUp Utilities 2013\OneClickStarter.exe Task: {D2A9DC02-60B8-44E2-9553-FD4A8C99B643} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {E4464F39-5ABD-4DF5-A2BA-809381237D04} - System32\Tasks\QtraxPlayer => C:\Program Files (x86)\Microsoft Silverlight\sllauncher.exe [2012-03-29] (Microsoft Corporation) Task: {EA888AAD-E631-4088-9FF7-D19E3B66537B} - System32\Tasks\{094824F9-0398-4B31-A8DD-C8A40D2172DB} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {F1703F32-3150-4584-A4C3-43AC1A4EB838} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-26] (Google Inc.) Task: {F2D39ED2-A91A-447B-9F73-C63F2B34B0C5} - System32\Tasks\Updater => C:\ProgramData\WombatUpdater\WombatUpdater.exe [2013-09-25] () Task: {FAA911BF-D72E-42AB-8FB7-AB7E6B6929D2} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\AutoKMS.job => C:\Windows\AutoKMS\AutoKMS.exe Task: C:\Windows\Tasks\DSite.job => C:\Users\Martin\AppData\Roaming\DSite\UPDATE~1\UPDATE~1.EXE Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000Core.job => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000UA.job => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Updater.job => C:\ProgramData\WombatUpdater\WombatUpdater.exe ==================== Loaded Modules (whitelisted) ============= 2011-03-17 00:07 - 2011-03-17 00:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2011-04-24 01:49 - 2011-03-02 11:40 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll 2010-01-07 13:42 - 2010-01-07 13:42 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-09-08 02:01 - 2010-09-08 02:01 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2013-09-01 10:54 - 2013-09-01 10:29 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2012-11-28 13:13 - 2012-11-28 13:13 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-11-28 13:13 - 2012-11-28 13:13 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2010-03-09 01:18 - 2010-03-09 01:18 - 00465576 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll 2010-03-09 01:13 - 2010-03-09 01:13 - 01081600 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll 2011-03-17 00:11 - 2011-03-17 00:11 - 04297568 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF 2013-11-24 20:08 - 2013-11-14 12:28 - 00702416 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.57\libglesv2.dll 2013-11-24 20:08 - 2013-11-14 12:28 - 00099792 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.57\libegl.dll 2013-11-24 20:08 - 2013-11-14 12:29 - 04055504 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.57\pdf.dll 2013-11-24 20:08 - 2013-11-14 12:29 - 00399312 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.57\ppGoogleNaClPluginChrome.dll 2013-11-24 20:08 - 2013-11-14 12:28 - 01619408 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.57\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:AD022376 ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Ethernet-Controller Description: Ethernet-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (12/04/2013 06:54:45 PM) (Source: Application Error) (User: ) Description: Aus einem der folgenden Gründe kann nicht auf die Datei "" zugegriffen werden: Es besteht ein Problem mit der Netzwerkverbindung, dem Datenträger mit der gespeicherten Datei bzw. den auf dem Computer installierten Speichertreibern, oder der Datenträger fehlt. Das Programm Hostprozess für Windows-Dienste wurde wegen dieses Fehlers geschlossen. Programm: Hostprozess für Windows-Dienste Datei: Der Fehlerwert ist im Abschnitt "Zusätzliche Dateien" aufgelistet. Benutzeraktion 1. Öffnen Sie die Datei erneut. Diese Situation ist eventuell ein temporäres Problem, das selbstständig behoben wird, wenn das Programm erneut ausgeführt wird. 2. Wenn Sie weiterhin nicht auf die Datei zugreifen können und - diese sich im Netzwerk befindet, dann sollte der Netzwerkadministrator überprüfen, dass kein Netzwerkproblem besteht und dass eine Verbindung mit dem Server hergestellt werden kann. - diese sich auf einem Wechseldatenträger, wie z. B. einer Diskette oder einer CD, befindet, überprüfen Sie, ob der Datenträger richtig in den Computer eingelegt ist. 3. Überprüfen und reparieren Sie das Dateisystem, indem Sie CHKDSK ausführen. Klicken Sie dazu im Menü "Start" auf "Ausführen", geben Sie CMD ein, und klicken Sie auf "OK". Geben Sie an der Eingabeaufforderung CHKDSK /F ein, und drücken Sie die EINGABETASTE. 4. Stellen Sie die Datei von einer Sicherungskopie wieder her, wenn das Problem weiterhin besteht. 5. Überprüfen Sie, ob andere Dateien auf demselben Datenträger geöffnet werden können. Falls dies nicht möglich ist, ist der Datenträger eventuell beschädigt. Wenden Sie sich an den Administrator oder den Hersteller der Computerhardware, um weitere Unterstützung zu erhalten, wenn es sich um eine Festplatte handelt. Zusätzliche Daten Fehlerwert: 00000000 Datenträgertyp: 0 Error: (12/04/2013 06:54:45 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: svchost.exe, Version: 6.1.7600.16385, Zeitstempel: 0x4a5bc3c1 Name des fehlerhaften Moduls: rasppp.dll, Version: 6.1.7601.17514, Zeitstempel: 0x4ce7c972 Ausnahmecode: 0xc000001d Fehleroffset: 0x00000000000300e4 ID des fehlerhaften Prozesses: 0x3f0 Startzeit der fehlerhaften Anwendung: 0xsvchost.exe0 Pfad der fehlerhaften Anwendung: svchost.exe1 Pfad des fehlerhaften Moduls: svchost.exe2 Berichtskennung: svchost.exe3 Error: (12/04/2013 06:19:30 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (12/03/2013 08:16:43 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: div26F1.tmp, Version: 2.6.1.8, Zeitstempel: 0x4f3db06c Name des fehlerhaften Moduls: div26F1.tmp, Version: 2.6.1.8, Zeitstempel: 0x4f3db06c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0005724a ID des fehlerhaften Prozesses: 0x1740 Startzeit der fehlerhaften Anwendung: 0xdiv26F1.tmp0 Pfad der fehlerhaften Anwendung: div26F1.tmp1 Pfad des fehlerhaften Moduls: div26F1.tmp2 Berichtskennung: div26F1.tmp3 Error: (12/03/2013 08:16:36 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: div4D1.tmp, Version: 2.6.1.8, Zeitstempel: 0x4f3db06c Name des fehlerhaften Moduls: div4D1.tmp, Version: 2.6.1.8, Zeitstempel: 0x4f3db06c Ausnahmecode: 0xc0000005 Fehleroffset: 0x0005724a ID des fehlerhaften Prozesses: 0x1190 Startzeit der fehlerhaften Anwendung: 0xdiv4D1.tmp0 Pfad der fehlerhaften Anwendung: div4D1.tmp1 Pfad des fehlerhaften Moduls: div4D1.tmp2 Berichtskennung: div4D1.tmp3 Error: (12/03/2013 03:45:35 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 32474135 Error: (12/03/2013 03:45:35 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 32474135 Error: (12/03/2013 03:45:35 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (12/02/2013 11:40:41 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 217996 Error: (12/02/2013 11:40:41 PM) (Source: Bonjour Service) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 217996 System errors: ============= Error: (12/04/2013 07:23:07 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Heimnetzgruppen-Anbieter" ist vom Dienst "Funktionssuchanbieter-Host" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1058 Error: (12/04/2013 07:22:58 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Windows Search" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/04/2013 07:22:58 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows Search erreicht. Error: (12/04/2013 07:22:58 PM) (Source: DCOM) (User: ) Description: 1053WSearch{7D096C5F-AC08-4F1F-BEB7-5C22C517CE39} Error: (12/04/2013 07:22:27 PM) (Source: Service Control Manager) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: prodrv06 prohlp02 prosync1 sfhlp01 Error: (12/04/2013 07:20:46 PM) (Source: Application Popup) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \SystemRoot\SysWow64\drivers\prodrv06.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (12/04/2013 07:20:57 PM) (Source: EventLog) (User: ) Description: Das System wurde zuvor am 04.12.2013 um 19:17:39 unerwartet heruntergefahren. Error: (12/04/2013 07:20:10 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst BITS erreicht. Error: (12/04/2013 07:19:40 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Multimediaklassenplaner" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/04/2013 07:19:40 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Warten auf eine Transaktionsrückmeldung von Dienst MMCSS erreicht. Microsoft Office Sessions: ========================= Error: (12/04/2013 06:54:45 PM) (Source: Application Error)(User: ) Description: Hostprozess für Windows-Dienste000000000 Error: (12/04/2013 06:54:45 PM) (Source: Application Error)(User: ) Description: svchost.exe6.1.7600.163854a5bc3c1rasppp.dll6.1.7601.175144ce7c972c000001d00000000000300e43f001cef1160bb3b4eaC:\Windows\system32\svchost.exeC:\Windows\system32\rasppp.dll28569668-5d0d-11e3-8ed4-bf7d05bf7d02 Error: (12/04/2013 06:19:30 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestC:\Users\Martin\Downloads\SoftonicDownloader_fuer_livetv-wilmaa.exe Error: (12/03/2013 08:16:43 PM) (Source: Application Error)(User: ) Description: div26F1.tmp2.6.1.84f3db06cdiv26F1.tmp2.6.1.84f3db06cc00000050005724a174001cef05c336fffedC:\Users\Martin\AppData\Local\Temp\div26E1.tmp\div26F1.tmpC:\Users\Martin\AppData\Local\Temp\div26E1.tmp\div26F1.tmp7136b9f0-5c4f-11e3-9054-206a8a1661a0 Error: (12/03/2013 08:16:36 PM) (Source: Application Error)(User: ) Description: div4D1.tmp2.6.1.84f3db06cdiv4D1.tmp2.6.1.84f3db06cc00000050005724a119001cef05c2e3d5eb3C:\Users\Martin\AppData\Local\Temp\div4C1.tmp\div4D1.tmpC:\Users\Martin\AppData\Local\Temp\div4C1.tmp\div4D1.tmp6d692720-5c4f-11e3-9054-206a8a1661a0 Error: (12/03/2013 03:45:35 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 32474135 Error: (12/03/2013 03:45:35 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 32474135 Error: (12/03/2013 03:45:35 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (12/02/2013 11:40:41 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 217996 Error: (12/02/2013 11:40:41 PM) (Source: Bonjour Service)(User: ) Description: Task Scheduling Error: m->NextScheduledEvent 217996 CodeIntegrity Errors: =================================== Date: 2011-01-26 23:36:39.687 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\sfvfs02.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2011-01-26 23:36:39.672 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\sfvfs02.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 41% Total physical RAM: 3956.5 MB Available physical RAM: 2317 MB Total Pagefile: 5954.69 MB Available Pagefile: 3837.24 MB Total Virtual: 8192 MB Available Virtual: 8191.78 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:452.48 GB) (Free:226.61 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 1C7B1C7B) Partition 1: (Not Active) - (Size=13 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=452 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19163 - hxxp://www.gmer.net Rootkit scan 2013-12-04 19:45:02 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 WDC_WD50 rev.01.0 465,76GB Running: 2z6ebij6.exe; Driver: C:\Users\Martin\AppData\Local\Temp\agriypow.sys ---- Threads - GMER 2.1 ---- Thread [1644:1660] 0000000076017587 Thread [1644:1668] 00000000738ac59c Thread [1644:1672] 00000000738ac59c Thread [1644:1740] 0000000072c68a80 Thread [1644:1744] 0000000077452e25 Thread [1644:3900] 00000000738ac59c Thread [1644:3916] 00000000738ac41c Thread [1644:3940] 00000000738ac41c Thread [1644:3944] 00000000738ac41c Thread [1644:3948] 00000000738ac41c Thread [1644:3952] 00000000738ac41c Thread [1644:3956] 00000000738ac41c Thread [1644:3960] 00000000738ac41c Thread [1644:3964] 00000000738ac41c Thread [1644:3968] 00000000738ac41c Thread [1644:3972] 00000000738ac41c Thread [1644:3976] 00000000738ac41c Thread [1644:3980] 00000000738ac41c Thread [1644:3984] 00000000738ac41c Thread [1644:3988] 00000000738ac41c Thread [1644:3992] 00000000738ac41c Thread [1644:3996] 00000000738ac41c Thread [1644:4000] 00000000738ac41c Thread [1644:4004] 00000000738ac41c Thread [1644:4008] 00000000738ac59c Thread [1644:4012] 000000006a358bf0 Thread [1644:4016] 000000006a358bf0 Thread [1644:4020] 000000006a358bf0 Thread [1644:4024] 000000006a354090 Thread [1644:4032] 00000000738ac59c Thread [1644:2268] 00000000738ac59c Thread [1644:3016] 00000000738ac59c Thread [1644:5972] 0000000077453e45 ---- EOF - GMER 2.1 ---- |
04.12.2013, 21:51 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht Hallo und
__________________Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
04.12.2013, 22:23 | #3 |
| Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht Hier sind die Antivir Logs von letzte Woche bis heute.
__________________Code:
ATTFilter Exportierte Ereignisse: 03.12.2013 00:00 [System-Scanner] Malware gefunden Die Datei 'C:\Users\Martin\AppData\Local\Temp\is357113909\LyricsFinder.exe' enthielt einen Virus oder unerwünschtes Programm 'ADWARE/Adware.Gen' [adware]. Durchgeführte Aktion(en): Die Datei wurde gelöscht. 02.12.2013 20:46 [System-Scanner] Malware gefunden Die Datei 'C:\Windows\system32\napdrypt.dll' enthielt einen Virus oder unerwünschtes Programm 'TR/Mediyes.Gen6' [trojan]. Durchgeführte Aktion(en): Die Datei wurde gelöscht. 26.11.2013 15:17 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\System32\NAPDRYPT.DLL' wurde ein Virus oder unerwünschtes Programm 'TR/Mediyes.Gen6' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern 26.11.2013 15:17 [Echtzeit-Scanner] Malware gefunden In der Datei 'C:\Windows\System32\NAPDRYPT.DLL' wurde ein Virus oder unerwünschtes Programm 'TR/Mediyes.Gen6' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern |
04.12.2013, 22:44 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht Dann bitte jetzt Combofix ausführen: Scan mit Combofix
__________________ Logfiles bitte immer in CODE-Tags posten |
05.12.2013, 16:14 | #5 |
| Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht Konnte leider keine Log-Datei finden, nachdem das Programm ohne Probleme durchgelaufen ist. Allerdings lief mein Laptop danach ziemlich langsam und wollte ihn dann neustarten und er hat sich dann in der Abmeldung aufgehangen. |
05.12.2013, 16:54 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags). CF erstellt immer das Log
__________________ --> Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht |
05.12.2013, 17:57 | #7 |
| Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht jetzt hat es wohl richtig geklappt Code:
ATTFilter ComboFix 13-12-04.04 - Martin 05.12.2013 17:01:50.1.4 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.3956.2873 [GMT 1:00] ausgeführt von:: c:\users\Martin\Downloads\ComboFix.exe AV: Avira Desktop *Disabled/Outdated* {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} SP: Avira Desktop *Disabled/Outdated* {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} * Neuer Wiederherstellungspunkt wurde erstellt . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . C:\END C:\Install.exe c:\users\Martin\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data c:\users\Martin\AppData\Local\Google\Chrome\User Data\Default\bProtectorPreferences c:\users\Martin\AppData\Roaming\mIRC\logs\status.log c:\users\Martin\Desktop\Search.lnk c:\users\Martin\Desktop\Setup.exe c:\windows\IsUn0407.exe c:\windows\wininit.ini . . ((((((((((((((((((((((( Dateien erstellt von 2013-11-05 bis 2013-12-05 )))))))))))))))))))))))))))))) . . 2013-12-05 16:09 . 2013-12-05 16:09 -------- d-----w- c:\users\Gast\AppData\Local\temp 2013-12-05 16:09 . 2013-12-05 16:09 -------- d-----w- c:\users\Default\AppData\Local\temp 2013-12-04 18:26 . 2013-12-04 18:26 -------- d-----w- C:\FRST 2013-12-04 17:25 . 2013-12-04 17:25 -------- d-----w- c:\program files\Synaptics 2013-12-04 17:24 . 2009-09-17 19:12 292912 ----a-w- c:\windows\system32\drivers\SynTP.sys 2013-12-04 17:24 . 2009-09-17 19:09 107816 ----a-w- c:\windows\SysWow64\SynTPCOM.dll 2013-12-04 17:24 . 2009-09-17 19:09 205608 ----a-w- c:\windows\system32\SynTPAPI.dll 2013-12-04 17:24 . 2009-09-17 19:09 147752 ----a-w- c:\windows\system32\SynTPCo4.dll 2013-12-04 17:24 . 2009-09-17 19:09 263464 ----a-w- c:\windows\system32\SynCtrl.dll 2013-12-04 17:24 . 2009-09-17 19:09 206120 ----a-w- c:\windows\SysWow64\SynCtrl.dll 2013-12-04 17:24 . 2009-09-17 19:09 169256 ----a-w- c:\windows\SysWow64\SynCOM.dll 2013-12-04 17:24 . 2009-09-17 19:09 396072 ----a-w- c:\windows\system32\SynCOM.dll 2013-12-04 17:20 . 2009-09-17 19:09 214312 ----a-w- c:\users\Martin\Setup.exe 2013-12-03 19:29 . 2013-12-03 19:29 -------- d-----w- c:\program files\Defraggler 2013-12-03 19:08 . 2013-12-03 19:08 -------- d-----w- c:\program files\CCleaner 2013-12-02 22:12 . 2013-12-02 22:12 -------- d-----w- c:\program files\ATI Technologies 2013-12-02 22:10 . 2013-12-02 22:10 -------- d-----w- C:\AMD 2013-12-02 19:18 . 2013-12-02 19:20 -------- d-----w- c:\users\Martin\AppData\Roaming\LiveTV Wilmaa . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}] 2013-10-23 19:52 12240 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{cbfb5c65-652c-3e10-9d9a-e586816d9342}] 2010-11-05 01:58 297808 ----a-w- c:\windows\System32\mscoree.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar] "{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport.dll" [2013-10-23 12240] . [HKEY_CLASSES_ROOT\clsid\{41564952-412d-5637-00a7-7a786e7484d7}] . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-02-01 18:03 120176 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x86\PSDProtect.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "OfficeSyncProcess"="c:\program files\Microsoft Office\Office14\MSOSYNC.EXE" [2012-01-18 911160] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "SuiteTray"="c:\program files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe" [2010-02-01 337264] "EgisUpdate"="c:\program files (x86)\EgisTec IPS\EgisUpdate.exe" [2009-12-25 201512] "EgisTecPMMUpdate"="c:\program files (x86)\EgisTec IPS\PmmUpdate.exe" [2009-12-25 401192] "StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-01-22 98304] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-04-04 958576] "avgnt"="c:\program files (x86)\Avira\AntiVir Desktop\avgnt.exe" [2013-09-05 347192] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-03-12 253816] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 0 (0x0) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) "PromptOnSecureDesktop"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon] "Userinit"="userinit.exe" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) . [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager] BootExecute REG_MULTI_SZ autocheck autochk /p \??\e:\0autocheck autochk /p \??\F:\0autocheck autochk * . [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] @="" . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Adobe Reader Speed Launcher"="c:\program files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x] R3 androidusb;SAMSUNG Android Composite ADB Interface Driver;c:\windows\system32\Drivers\ssadadb.sys;c:\windows\SYSNATIVE\Drivers\ssadadb.sys [x] R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssudbus.sys [x] R3 GGSAFERDriver;GGSAFER Driver;c:\program files (x86)\Garena\safedrv.sys;c:\program files (x86)\Garena\safedrv.sys [x] R3 k57nd60a;Broadcom NetLink (TM) Gigabit Ethernet - NDIS 6.0;c:\windows\system32\DRIVERS\k57nd60a.sys;c:\windows\SYSNATIVE\DRIVERS\k57nd60a.sys [x] R3 MWLService;MyWinLocker Service;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe;c:\program files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [x] R3 NTIBackupSvc;NTI Backup Now 5 Backup Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe [x] R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x] R3 ssadbus;SAMSUNG Android USB Composite Device driver (WDM);c:\windows\system32\DRIVERS\ssadbus.sys;c:\windows\SYSNATIVE\DRIVERS\ssadbus.sys [x] R3 ssadmdfl;SAMSUNG Android USB Modem (Filter);c:\windows\system32\DRIVERS\ssadmdfl.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdfl.sys [x] R3 ssadmdm;SAMSUNG Android USB Modem Drivers;c:\windows\system32\DRIVERS\ssadmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssadmdm.sys [x] R3 ssadserd;SAMSUNG Android USB Diagnostic Serial Port (WDM);c:\windows\system32\DRIVERS\ssadserd.sys;c:\windows\SYSNATIVE\DRIVERS\ssadserd.sys [x] R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys;c:\windows\SYSNATIVE\DRIVERS\ssudmdm.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys;c:\windows\SYSNATIVE\Drivers\usbaapl64.sys [x] R3 WatAdminSvc;Windows-Aktivierungstechnologieservice;c:\windows\system32\Wat\WatAdminSvc.exe;c:\windows\SYSNATIVE\Wat\WatAdminSvc.exe [x] S1 avkmgr;avkmgr;c:\windows\system32\DRIVERS\avkmgr.sys;c:\windows\SYSNATIVE\DRIVERS\avkmgr.sys [x] S1 mwlPSDFilter;mwlPSDFilter;c:\windows\system32\DRIVERS\mwlPSDFilter.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDFilter.sys [x] S1 mwlPSDNServ;mwlPSDNServ;c:\windows\system32\DRIVERS\mwlPSDNServ.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDNServ.sys [x] S1 mwlPSDVDisk;mwlPSDVDisk;c:\windows\system32\DRIVERS\mwlPSDVDisk.sys;c:\windows\SYSNATIVE\DRIVERS\mwlPSDVDisk.sys [x] S2 {B154377D-700F-42cc-9474-23858FBDF4BD};Power Control [2010/09/08 03:06];c:\program files (x86)\CyberLink\PowerDVD9\000.fcl;c:\program files (x86)\CyberLink\PowerDVD9\000.fcl [x] S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x] S2 AntiVirSchedulerService;Avira Planer;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe;c:\program files (x86)\Avira\AntiVir Desktop\sched.exe [x] S2 AntiVirWebService;Avira Browser-Schutz;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE;c:\program files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [x] S2 APNMCP;Ask Aktualisierungsdienst;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe;c:\program files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [x] S2 DsiWMIService;Dritek WMI Service;c:\program files (x86)\Launch Manager\dsiwmis.exe;c:\program files (x86)\Launch Manager\dsiwmis.exe [x] S2 ePowerSvc;Acer ePower Service;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe;c:\program files\Acer\Acer ePower Management\ePowerSvc.exe [x] S2 GREGService;GREGService;c:\program files (x86)\Acer\Registration\GREGsvc.exe;c:\program files (x86)\Acer\Registration\GREGsvc.exe [x] S2 NTI IScheduleSvc;NTI IScheduleSvc;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe;c:\program files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [x] S2 NTISchedulerSvc;NTI Backup Now 5 Scheduler Service;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe;c:\program files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [x] S2 UNS;Intel(R) Management & Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S2 Updater Service;Updater Service;c:\program files\Acer\Acer Updater\UpdaterService.exe;c:\program files\Acer\Acer Updater\UpdaterService.exe [x] S2 WebCake Desktop Updater;WebCake Desktop Updater;c:\program files (x86)\Betcat\WBDesktop.Updater.1.0.0.16.exe;c:\program files (x86)\Betcat\WBDesktop.Updater.1.0.0.16.exe [x] S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x] S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2013-09-28 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-19 17:57] . 2013-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-26 20:52] . 2013-12-05 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-01-26 20:52] . 2013-12-04 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000Core.job - c:\users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-16 19:46] . 2013-12-05 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000UA.job - c:\users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-04-16 19:46] . 2013-12-05 c:\windows\Tasks\Updater.job - c:\programdata\WombatUpdater\WombatUpdater.exe [2013-09-25 10:24] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}] 2013-10-23 19:52 13776 ----a-w- c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{41564952-412D-5637-00A7-7A786E7484D7}"= "c:\program files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll" [2013-10-23 13776] . [HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\egisPSDP] @="{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}" [HKEY_CLASSES_ROOT\CLSID\{30A0A3F6-38AC-4C53-BB8B-0D95238E25BA}] 2010-02-01 18:06 137584 ----a-w- c:\program files (x86)\EgisTec MyWinLocker\x64\PSDProtect.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2009-09-22 323584] "mwlDaemon"="c:\program files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe" [2010-02-01 349552] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2009-12-11 9643552] "Acer ePower Management"="c:\program files\Acer\Acer ePower Management\ePowerTray.exe" [2010-04-23 861216] . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://search.babylon.com/?affID=119357&babsrc=HP_ss_din2g&mntrId=60535CAC4C04FAE7 uLocal Page = c:\windows\system32\blank.htm mDefault_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7741&r=27360111h906l0458z105t4791o183 mStart Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7741&r=27360111h906l0458z105t4791o183 mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local mSearchAssistant = IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105 IE: Free YouTube to MP3 Converter - c:\users\Martin\AppData\Roaming\DVDVideoSoftIEHelpers\freeyoutubetomp3converter.htm IE: Google Sidewiki... - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_E11712C84EA7E12B.dll/cmsidewiki.html IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000 LSP: c:\program files (x86)\Avira\AntiVir Desktop\avsda.dll TCP: DhcpNameServer = 168.95.1.1 . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - (no file) Toolbar-Locked - (no file) Toolbar-Locked - (no file) WebBrowser-{30F9B915-B755-4826-820B-08FBA6BD249D} - (no file) WebBrowser-{CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - (no file) HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe AddRemove-ESI Prüfwerte - c:\windows\IsUn0407.exe AddRemove-Steam App 240 - g:\steam\steam.exe AddRemove-Steam App 260 - g:\steam\steam.exe . . . [HKEY_LOCAL_MACHINE\system\ControlSet001\services\{B154377D-700F-42cc-9474-23858FBDF4BD}] "ImagePath"="\??\c:\program files (x86)\CyberLink\PowerDVD9\000.fcl" . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_USERS\S-1-5-21-3577554524-86806762-3300807997-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*m*AƒI] @Class="Shell" . [HKEY_USERS\S-1-5-21-3577554524-86806762-3300807997-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.*m*AƒI\OpenWithList] @Class="Shell" "a"="vlc.exe" "MRUList"="a" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_6_602_180_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.11" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_6_602_180.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings] @Denied: (A) (Users) @Denied: (A) (Everyone) @Allowed: (B 1 2 3 4 5) (S-1-5-20) "BlindDial"=dword:00000000 . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2013-12-05 17:12:09 ComboFix-quarantined-files.txt 2013-12-05 16:12 . Vor Suchlauf: 16 Verzeichnis(se), 242.393.804.800 Bytes frei Nach Suchlauf: 22 Verzeichnis(se), 242.347.737.088 Bytes frei . - - End Of File - - DA0CF3FBDE64A79320B0C6CD7593F4AB |
06.12.2013, 00:31 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ Logfiles bitte immer in CODE-Tags posten |
08.12.2013, 11:07 | #9 |
| Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nichtCode:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1007 www.malwarebytes.org Database version: v2013.12.07.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Martin :: MARTIN-PC [administrator] 07.12.2013 21:40:02 mbar-log-2013-12-07 (21-40-02).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 269120 Time elapsed: 18 minute(s), 3 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 1 HKLM\SOFTWARE\WOW6432NODE\MICROSOFT\WINDOWS\CURRENTVERSION|Start Page (Spyware.Agent) -> Data: hxxp://www.redirecturls.info/ -> Delete on reboot. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 1 C:\Users\Martin\M-1-52-5782-8752-5245 (Trojan.Agent.Gen) -> Delete on reboot. Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1007 www.malwarebytes.org Database version: v2013.12.07.07 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Martin :: MARTIN-PC [administrator] 07.12.2013 22:16:38 mbar-log-2013-12-07 (22-16-38).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 268695 Time elapsed: 8 hour(s), 20 minute(s), 6 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) |
08.12.2013, 17:32 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
10.12.2013, 21:36 | #11 |
| Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht ADW-Cleaner Code:
ATTFilter # AdwCleaner v3.014 - Bericht erstellt am 10/12/2013 um 21:04:44 # Updated 01/12/2013 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Martin - MARTIN-PC # Gestartet von : C:\Users\Martin\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** [#] Dienst Gelöscht : WebCake Desktop Updater ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\ProgramData\BonanzaDealsLive Ordner Gelöscht : C:\ProgramData\boost_interprocess Ordner Gelöscht : C:\ProgramData\DSearchLink Ordner Gelöscht : C:\ProgramData\ICQ\ICQToolbar Ordner Gelöscht : C:\ProgramData\ParetoLogic Ordner Gelöscht : C:\ProgramData\Partner Ordner Gelöscht : C:\ProgramData\Tarma Installer Ordner Gelöscht : C:\Program Files (x86)\Betcat Ordner Gelöscht : C:\Program Files (x86)\BonanzaDeals Ordner Gelöscht : C:\Program Files (x86)\BonanzaDealsLive Ordner Gelöscht : C:\Program Files (x86)\ICQ6Toolbar Ordner Gelöscht : C:\Program Files (x86)\myfree codec Ordner Gelöscht : C:\Program Files (x86)\Web Cake Ordner Gelöscht : C:\Users\Martin\AppData\Local\BonanzaDealsLive Ordner Gelöscht : C:\Users\Martin\AppData\Local\Conduit Ordner Gelöscht : C:\Users\Martin\AppData\Local\PackageAware Ordner Gelöscht : C:\Users\Martin\AppData\Local\Wajam Ordner Gelöscht : C:\Users\Martin\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\Martin\AppData\LocalLow\Delta Ordner Gelöscht : C:\Users\Martin\AppData\LocalLow\facemoods.com Ordner Gelöscht : C:\Users\Martin\AppData\LocalLow\Softonic Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\BabSolution Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Betcat Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\DealPly Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\DriverCure Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\DSite Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\ParetoLogic Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\SenselessTV Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Web Cake Ordner Gelöscht : C:\Users\Martin\Documents\PC Speed Maximizer Ordner Gelöscht : C:\Users\Gast\AppData\Local\AskToolbar Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\facemoods.com Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\PriceGong Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\Softonic Ordner Gelöscht : C:\Users\Gast\AppData\LocalLow\xfirexo Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Conduit Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\ConduitEngine Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\SweetIMToolbarData Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\CT2269050 Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\CT2431245 Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{ACAA314B-EEBA-48E4-AD47-84E31C44796C} Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\engine@conduit.com Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\ffxtlbr@babylon.com Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\ffxtlbra@softonic.com Ordner Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} Ordner Gelöscht : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\jlicihemmeabfjhdckhpkmopojohlkab Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi Datei Gelöscht : C:\Windows\SysWOW64\conduitEngine.tmp Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\.autoreg Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\bProtector_extensions.rdf Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\searchplugins\Askcom.xml Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\searchplugins\Babylon.xml Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\searchplugins\delta.xml Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\searchplugins\fcmdSrch.xml Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\searchplugins\icqplugin.xml Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\searchplugins\SweetIm.xml Datei Gelöscht : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\user.js Datei Gelöscht : C:\Windows\System32\Tasks\Dealply Datei Gelöscht : C:\Windows\System32\Tasks\QtraxPlayer ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [{EB132DB0-A4CA-11DF-9732-0E29E0D72085}] Wert Gelöscht : HKCU\Software\Mozilla\Firefox\Extensions [support@Senseless.TV] Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [support@Senseless.TV] Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\fmfnfnpmhcllokmkepffndflpnadjmma Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\ieadcoanfjloocmfafkebdnfefmohngj Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\jlicihemmeabfjhdckhpkmopojohlkab Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\LowRegistry\ICQ\ICQToolBar Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\protector_dll.protectorbho.1 Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURLs [bProtectTabs] Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\ApnSetup_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\askpartnercobrandingtool_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\AskSLib_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\DEALPL~1_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\DEALPL~1_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoods_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoods_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\facemoodssrv_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic_ggl_1_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic_ggl_1_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic-de3AutoUpdaterHelper_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\softonic-de3AutoUpdaterHelper_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetim_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetimsetup_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\sweetimsetup_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\TaskScheduler_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\UpdateTask_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajamupdater_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajamupdater_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\WebCakeDesktop_RASMANCS Schlüssel Gelöscht : HKCU\Software\5d6dbdab73aed49 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_fl-studio_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_fl-studio_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_free-fire-screensaver_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_free-fire-screensaver_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_icq-portable_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_icq-portable_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_livetv-wilmaa_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_livetv-wilmaa_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_matrix-code-emulator_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_matrix-code-emulator_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_trackmania-nations-forever_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_trackmania-nations-forever_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{5B1881D1-D9C7-46DF-B041-1E593282C7D0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{7ABBFE1C-E485-44AA-8F36-353751B4124D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{991D97B8-F0D8-4EA1-9100-7A65EA2D3A63} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{DF84E609-C3A4-49CB-A160-61767DAF8899} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0AFD55C8-ADF8-4A33-A6E1-DEDB7A36AEB4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C17A0751-580B-466B-8271-5C73EFDC1295} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DF84E609-C3A4-49CB-A160-61767DAF8899} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{F74E6442-E998-4144-AAF2-4D653061239A} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{991D97B8-F0D8-4EA1-9100-7A65EA2D3A63} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{855F3B16-6D32-4FE6-8A56-BBB695989046} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{991D97B8-F0D8-4EA1-9100-7A65EA2D3A63} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{AF6B0594-6008-4327-93E5-608AD710A6FA} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4B80-B5BA-C8DDD434E5C4} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{855F3B16-6D32-4FE6-8A56-BBB695989046} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{A7A6995D-6EE1-4FD1-A258-49395D5BF99C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{AE805869-2E5C-4ED4-8F7B-F1F7851A4497} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0D7562AE-8EF6-416D-A838-AB665251703A} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{AFDBDDAA-5D3F-42EE-B79C-185A7020515B} Wert Gelöscht : HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser [{30F9B915-B755-4826-820B-08FBA6BD249D}] Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks [{855F3B16-6D32-4FE6-8A56-BBB695989046}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{087CDC12-0A11-4D1D-8DCF-44185D7C3496} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{088BF3A9-6AE8-47B9-A3FB-26262F236C79} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{1231839B-064E-4788-B865-465A1B5266FD} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2AC7B9EB-3881-4EB9-8DEE-0A731A309FDE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{349C0469-ACDD-49DF-9B3E-0D82E7C7DC4D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{41226591-6F7A-4082-B63A-67FE4A0CF7A6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{431532BD-0AE1-4ABC-BE8C-919F3D1332E2} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{542FA950-C57A-4E17-B3E1-D935DFE15DEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{55D69CD1-6715-4C40-BF05-9519AC4DC6E6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{5B035F86-41B5-40F1-AAAD-3D219F30244E} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6365AC7B-9920-4D8B-AF5D-3BDFEAC340A8} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66C8FD57-54C4-4D4F-BC95-DCCC763B410A} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{6A934270-717F-4BC3-BA59-BC9BED47A8D2} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{717BAE33-7061-4279-8AE5-6C13BC8AF3F9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{74C012C4-00FB-4F04-9AFB-4AD5449D2018} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{78888F8B-D5E4-43CE-89F5-C8C18223AF64} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{79B13431-CCAC-4097-8889-D0289E5E924F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{84F06F7A-F811-48D7-8B34-3F4145183D8F} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{88F6D55F-AA3F-4003-BE69-4AC1998D6492} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8B8558F6-DC26-4F39-8417-34B8934AA459} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{8C8D5C57-3CAD-4CF9-BCAD-F873678DA883} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{981334CB-7B8B-431F-B86D-67B7426B125B} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A0F66203-1A86-4812-9603-A57E09A4D7A3} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A3A2A5C0-1306-4D1A-A093-9CECA4230002} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{A9379648-F6EB-4F65-A624-1C10411A15D0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{BC39D1B3-4471-41C1-AACA-E097FAF4B7AA} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C17A0751-580B-466B-8271-5C73EFDC1295} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C1C2FC43-F042-4F17-AEDB-C5ABF3B42E4B} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{C8D424EF-CB21-49A0-8659-476FBAB0F8E8} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{DEB85542-1311-4EC6-8A32-5372EB27FC94} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F16AB1DB-15C0-4456-A29E-4DF24FB9E3D2} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{F7EC6286-297C-4981-9DCC-FD7F57BC24C9} Schlüssel Gelöscht : HKCU\Software\BonanzaDealsLive Schlüssel Gelöscht : HKCU\Software\dsiteproducts Schlüssel Gelöscht : HKCU\Software\InstallCore Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKCU\Software\ParetoLogic Schlüssel Gelöscht : HKCU\Software\qtrax Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKCU\Software\YahooPartnerToolbar Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\LyricsFinder Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\ICQ\ICQToolbar Schlüssel Gelöscht : HKLM\Software\ParetoLogic Schlüssel Gelöscht : HKLM\Software\Uniblue Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Senseless.TV Video Plugin Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\DivX\Install\Setup\WizardLayout\ConduitToolbar ***** [ Browser ] ***** -\\ Internet Explorer v8.0.7601.17514 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [ICQ Search] Einstellung Wiederhergestellt : HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls [bProtectTabs] -\\ Mozilla Firefox v8.0.1 (de) [ Datei : C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht : homepage ************************* AdwCleaner[R0].txt - [22171 octets] - [10/12/2013 21:02:43] AdwCleaner[S0].txt - [20600 octets] - [10/12/2013 21:04:44] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [20661 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.0.8 (11.05.2013:1) OS: Windows 7 Home Premium x64 Ran by Martin on 10.12.2013 at 21:12:01,18 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully deleted [Registry Value] HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\AboutURLs\\bProtectTabs ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{41564952-412D-5637-00A7-7A786E7484D7} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{FB684D26-01F4-4D9D-87CB-F486BEBA56DC} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3577554524-86806762-3300807997-1000\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\sweetim Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\LyricsFinderUpdater_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\LyricsFinderUpdater_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\LyricsFinder_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\LyricsFinder_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\softonic-de3ToolbarHelper_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Tracing\softonic-de3ToolbarHelper_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\LyricsFinderUpdater_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\LyricsFinderUpdater_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\LyricsFinder_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\LyricsFinder_RASMANCS Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\softonic-de3ToolbarHelper_RASAPI32 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Tracing\softonic-de3ToolbarHelper_RASMANCS Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{B822788F-260D-4ED7-BD47-D6CF28F1FC67} Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cbfb5c65-652c-3e10-9d9a-e586816d9342} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{cbfb5c65-652c-3e10-9d9a-e586816d9342} ~~~ Files Successfully deleted: [File] "C:\Users\Martin\appdata\locallow\microsoft\silverlight\outofbrowser\index\portal.qtrax.com" ~~~ Folders Successfully deleted: [Folder] "C:\ProgramData\apn" Successfully deleted: [Folder] "C:\Users\Martin\appdata\local\apn" Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{2FC6ADB5-0DA4-41C7-95BA-97A399A71610} Successfully deleted: [Empty Folder] C:\Users\Martin\appdata\local\{CC5983E7-4493-461C-87B3-58DF4CEE5A5E} ~~~ Chrome Successfully deleted: [Folder] C:\Users\Martin\appdata\local\Google\Chrome\User Data\Default\Extensions\aaaaacalgebmfelllfiaoknifldpngjh Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Google\Chrome\Extensions\aaaaacalgebmfelllfiaoknifldpngjh ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 10.12.2013 at 21:18:51,87 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-12-2013 Ran by Martin at 2013-12-10 21:31:20 Running from C:\Users\Martin\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Acer Backup Manager (x32 Version: 2.0.0.60) Acer Crystal Eye webcam (x32 Version: 1.0.3.5) Acer ePower Management (x32 Version: 5.00.3004) Acer eRecovery Management (x32 Version: 4.05.3011) Acer Registration (x32 Version: 1.03.3003) Acer ScreenSaver (x32 Version: 1.1.0423.2010) Acer Updater (x32 Version: 1.02.3001) Acrobat.com (x32 Version: 1.6.65) Adobe AIR (x32 Version: 1.5.0.7220) Adobe Flash Player 11 ActiveX (x32 Version: 11.6.602.180) Adobe Flash Player 11 Plugin (x32 Version: 11.6.602.180) Adobe Reader 9.5.5 MUI (x32 Version: 9.5.5) Alcor Micro USB Card Reader (x32 Version: 1.5.17.05094) ALPS Touch Pad Driver (Version: 7.105.2015.1107) Apple Application Support (x32 Version: 2.3.6) Apple Mobile Device Support (Version: 7.0.0.117) Apple Software Update (x32 Version: 2.1.3.127) Avira Free Antivirus (x32 Version: 13.0.0.4052) Avira SearchFree Toolbar (x32 Version: 12.6.0.1900) Backup Manager Basic (x32 Version: 2.0.0.60) Bonjour (Version: 3.0.0.10) Call of Duty(R) 4 - Modern Warfare(TM) 1.1 Patch (x32 Version: 1.1) Call of Duty(R) 4 - Modern Warfare(TM) 1.1 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch (x32 Version: 1.2) Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch (x32 Version: 1.3) Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch (x32 Version: 1.4) Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Patch (x32 Version: 1.5) Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (x32 Version: 1.6) Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (x32 Version: 1.7) Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (x32) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Core Implementation (x32 Version: 2010.0122.858.16002) Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0122.858.16002) Catalyst Control Center Graphics Full New (x32 Version: 2010.0122.858.16002) Catalyst Control Center Graphics Light (x32 Version: 2010.0122.858.16002) Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0122.858.16002) Catalyst Control Center InstallProxy (x32 Version: 2010.0122.858.16002) Catalyst Control Center Localization All (x32 Version: 2010.0122.858.16002) CCC Help Chinese Standard (x32 Version: 2010.0122.0857.16002) CCC Help Chinese Traditional (x32 Version: 2010.0122.0857.16002) CCC Help Czech (x32 Version: 2010.0122.0857.16002) CCC Help Danish (x32 Version: 2010.0122.0857.16002) CCC Help Dutch (x32 Version: 2010.0122.0857.16002) CCC Help English (x32 Version: 2010.0122.0857.16002) CCC Help Finnish (x32 Version: 2010.0122.0857.16002) CCC Help French (x32 Version: 2010.0122.0857.16002) CCC Help German (x32 Version: 2010.0122.0857.16002) CCC Help Greek (x32 Version: 2010.0122.0857.16002) CCC Help Hungarian (x32 Version: 2010.0122.0857.16002) CCC Help Italian (x32 Version: 2010.0122.0857.16002) CCC Help Japanese (x32 Version: 2010.0122.0857.16002) CCC Help Korean (x32 Version: 2010.0122.0857.16002) CCC Help Norwegian (x32 Version: 2010.0122.0857.16002) CCC Help Polish (x32 Version: 2010.0122.0857.16002) CCC Help Portuguese (x32 Version: 2010.0122.0857.16002) CCC Help Russian (x32 Version: 2010.0122.0857.16002) CCC Help Spanish (x32 Version: 2010.0122.0857.16002) CCC Help Swedish (x32 Version: 2010.0122.0857.16002) CCC Help Thai (x32 Version: 2010.0122.0857.16002) CCC Help Turkish (x32 Version: 2010.0122.0857.16002) ccc-core-static (x32 Version: 2010.0122.858.16002) ccc-utility64 (Version: 2010.0122.858.16002) CCleaner (Version: 4.08) Counter-Strike 1.6 (x32) CounterStrike 1.6 from VSI (Version 1.02) (x32) Counter-Strike: Source (x32) Counter-Strike: Source Beta (x32) CyberLink PowerDVD 9 (x32 Version: 9.0.2529.50) D3DX10 (x32 Version: 15.4.2368.0902) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition Defraggler (Version: 2.16) DivX-Setup (x32 Version: 2.6.1.8) DotaKeys (x32 Version: ) eBay Worldwide (x32 Version: 2.1.0901) ESI Prüfwerte (x32) ESI[tronic] DEMO_4 (x32) FL Studio 10 (x32) Full Tilt Poker.Eu (x32 Version: 4.63.11.WIN.FullTilt.EU) Google Chrome (HKCU Version: 31.0.1650.63) Google Chrome Frame (HKCU Version: 31.0.1650.57) Google Earth (x32 Version: 7.1.1.1888) Google Gears (x32 Version: 0.5.3600) Google Toolbar for Internet Explorer (x32 Version: 1.0.0) Google Toolbar for Internet Explorer (x32 Version: 7.5.4601.54) Google Update Helper (x32 Version: 1.3.21.165) Haali Media Splitter (x32) Identity Card (x32 Version: 1.00.3003) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) Rapid Storage Technology (x32 Version: 9.6.0.1014) iTunes (Version: 11.1.1.11) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) JDownloader 0.9 (x32 Version: 0.9) Junk Mail filter update (x32 Version: 15.4.3502.0922) KTS (x32 Version: 4.0.0) Launch Manager (x32 Version: 4.0.8) LiveTV Sammlung (HKCU Version: 2.0.2.2) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Outlook Hotmail Connector 64-Bit (Version: 14.0.6123.5001) Microsoft Silverlight (x32 Version: 4.1.10329.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 8.0.1 (x86 de) (x32 Version: 8.0.1) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) MyWinLocker (x32 Version: 3.1.206.0) MyWinLocker Suite (x32 Version: 3.1.206.0) Need for Speed Ultimate Colletion (x32) Need for Speed Underground 2 (x32) Norton Online Backup (x32 Version: 1.2.0.36) NTI Backup Now 5 (x32 Version: 5.1.2.628) NTI Backup Now Standard (x32 Version: 5.1.2.628) NTI Media Maker 8 (x32 Version: 8.0.12.6630) NVIDIA PhysX (x32 Version: 9.10.0513) PokerStars.net (x32) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6000) Samsung Kies (x32 Version: 2.3.0.12035_16) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.6.0) Shredder (Version: 2.0.5.0) Shredder (x32 Version: 2.0.5.0) Steamless Counter Strike Source Pack (x32 Version: 1.0) Synaptics Pointing Device Driver (Version: 14.0.6.0) Team Fortress 2 (x32) TmNationsForever (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition Update for Microsoft Office 2010 (KB2553270) 64-Bit Edition Update for Microsoft Office 2010 (KB2553272) 64-Bit Edition Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2598289) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2589345) 64-Bit Edition Update for Microsoft Outlook 2010 (KB2553248) 64-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) VLC media player 2.0.8 (x32 Version: 2.0.8) Welcome Center (x32 Version: 1.01.3002) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3538.0513) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3538.0513) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Messenger (x32 Version: 15.4.3538.0513) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live Sync (x32 Version: 14.0.8117.416) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8) WinRAR 4.00 (64-Bit) (Version: 4.00.0) ==================== Restore Points ========================= 05-12-2013 15:59:18 ComboFix created restore point 07-12-2013 21:09:58 Malwarebytes Anti-Rootkit Restore Point ==================== Hosts content: ========================== 2009-07-14 03:34 - 2013-12-05 17:09 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {05966E13-F996-4CAD-8D70-89CB35E37C65} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd) Task: {11FCEF4D-60A0-4E78-B94D-0E4A34A1EB4F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000Core => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-17] (Google Inc.) Task: {14365ECD-396D-4CD1-A552-91F376417A29} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3577554524-86806762-3300807997-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {1455E5BC-E812-4B69-BD29-4765674FF1CF} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12] (Oracle Corporation) Task: {2C37A929-CFF3-4E0C-975D-50D56C3C1962} - System32\Tasks\{066AA482-CA98-4F6F-9AC9-72A24B653C2F} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {39C6EE68-889A-419C-BCAF-7B156E05D78B} - System32\Tasks\{3A2230D1-5151-48B4-865F-629492CC1E6C} => C:\Program Files (x86)\Skype\\Phone\Skype.exe Task: {3E5DB66E-AECF-4A72-933E-A9C978C59CFB} - \DealPly No Task File Task: {5396B8C0-10C7-4513-BC36-1546E34BF455} - System32\Tasks\{58691F48-DEFE-447C-9653-4FEA3F44DA99} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {69D9F157-56A5-45AB-ABAD-C3A1EEEE0E1D} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3577554524-86806762-3300807997-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {6EBC9658-0FBD-427C-9CAD-373F64EDCCA3} - System32\Tasks\{9C96BBA0-298A-4908-8211-7F908E4A874C} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {6F413E5F-0339-4ABF-ACD2-E555618A2D74} - System32\Tasks\Google Updater and Installer => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-17] (Google Inc.) Task: {795B7B6F-54FC-4F95-B903-D9838E9AB65E} - System32\Tasks\{CFF6BE17-13E5-45C9-ACAD-EC746F3C5483} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {7D75482C-99A7-4A5A-BA0F-99061DEA2F9F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-19] (Adobe Systems Incorporated) Task: {8B0CA803-1009-4B89-9A6E-AD1B472E9357} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000UA => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-17] (Google Inc.) Task: {8F10B9FB-B072-428A-B4F5-ABE881860A5C} - System32\Tasks\{20C73931-A81F-4FB3-87E1-A8C7607F90A2} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {9728C1CE-8B34-4CED-BE15-81C09A1CEA29} - System32\Tasks\{1D52CD23-40D4-41F6-BF9F-A93C85CAA1E4} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {984E0A7E-6B23-428F-BCC4-F1AEA54ED1AE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-26] (Google Inc.) Task: {9BA12277-B2E2-4D20-8764-25F50D69EAD6} - System32\Tasks\{50A74122-2781-4251-8DE6-193AF0F8836A} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {A0EC00DB-1A81-48E2-A397-E27D0EBC8C67} - System32\Tasks\Wecker => C:\Users\Martin\Music\Bohse Onkelz\Viva Los Tioz\07 Terpentin.wma Task: {C0879505-251C-4103-873B-C00601CCC588} - System32\Tasks\{48704270-711D-4189-A349-2DAF880C82C1} => C:\Users\Martin\Desktop\TuneUp Utilities 2013\OneClickStarter.exe Task: {D2A9DC02-60B8-44E2-9553-FD4A8C99B643} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {E4464F39-5ABD-4DF5-A2BA-809381237D04} - \QtraxPlayer No Task File Task: {EA888AAD-E631-4088-9FF7-D19E3B66537B} - System32\Tasks\{094824F9-0398-4B31-A8DD-C8A40D2172DB} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {F1703F32-3150-4584-A4C3-43AC1A4EB838} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-26] (Google Inc.) Task: {F2D39ED2-A91A-447B-9F73-C63F2B34B0C5} - System32\Tasks\Updater => C:\ProgramData\WombatUpdater\WombatUpdater.exe [2013-09-25] () Task: {FAA911BF-D72E-42AB-8FB7-AB7E6B6929D2} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000Core.job => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000UA.job => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Updater.job => C:\ProgramData\WombatUpdater\WombatUpdater.exe ==================== Loaded Modules (whitelisted) ============= 2010-01-07 13:42 - 2010-01-07 13:42 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-09-08 02:01 - 2010-09-08 02:01 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2011-03-17 00:07 - 2011-03-17 00:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2011-04-24 01:49 - 2011-03-02 11:40 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll 2013-09-01 10:54 - 2013-09-01 10:29 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2012-11-28 13:13 - 2012-11-28 13:13 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-11-28 13:13 - 2012-11-28 13:13 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2010-03-09 01:18 - 2010-03-09 01:18 - 00465576 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll 2010-03-09 01:13 - 2010-03-09 01:13 - 01081600 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll 2013-12-07 21:58 - 2013-12-04 03:47 - 00702416 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-07 21:58 - 2013-12-04 03:47 - 00099792 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\libegl.dll 2013-12-07 21:58 - 2013-12-04 03:48 - 04055504 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-07 21:58 - 2013-12-04 03:48 - 00399312 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-07 21:58 - 2013-12-04 03:47 - 01619408 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:AD022376 ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Ethernet-Controller Description: Ethernet-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-12-05 17:09:03.065 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-05 17:09:03.034 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2011-01-26 23:36:39.687 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\sfvfs02.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2011-01-26 23:36:39.672 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\sfvfs02.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 39% Total physical RAM: 3956.5 MB Available physical RAM: 2412.91 MB Total Pagefile: 5954.69 MB Available Pagefile: 3897.93 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:452.48 GB) (Free:224.56 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 1C7B1C7B) Partition 1: (Not Active) - (Size=13 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=452 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-12-2013 Ran by Martin at 2013-12-10 21:31:20 Running from C:\Users\Martin\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Acer Backup Manager (x32 Version: 2.0.0.60) Acer Crystal Eye webcam (x32 Version: 1.0.3.5) Acer ePower Management (x32 Version: 5.00.3004) Acer eRecovery Management (x32 Version: 4.05.3011) Acer Registration (x32 Version: 1.03.3003) Acer ScreenSaver (x32 Version: 1.1.0423.2010) Acer Updater (x32 Version: 1.02.3001) Acrobat.com (x32 Version: 1.6.65) Adobe AIR (x32 Version: 1.5.0.7220) Adobe Flash Player 11 ActiveX (x32 Version: 11.6.602.180) Adobe Flash Player 11 Plugin (x32 Version: 11.6.602.180) Adobe Reader 9.5.5 MUI (x32 Version: 9.5.5) Alcor Micro USB Card Reader (x32 Version: 1.5.17.05094) ALPS Touch Pad Driver (Version: 7.105.2015.1107) Apple Application Support (x32 Version: 2.3.6) Apple Mobile Device Support (Version: 7.0.0.117) Apple Software Update (x32 Version: 2.1.3.127) Avira Free Antivirus (x32 Version: 13.0.0.4052) Avira SearchFree Toolbar (x32 Version: 12.6.0.1900) Backup Manager Basic (x32 Version: 2.0.0.60) Bonjour (Version: 3.0.0.10) Call of Duty(R) 4 - Modern Warfare(TM) 1.1 Patch (x32 Version: 1.1) Call of Duty(R) 4 - Modern Warfare(TM) 1.1 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch (x32 Version: 1.2) Call of Duty(R) 4 - Modern Warfare(TM) 1.2 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch (x32 Version: 1.3) Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch (x32 Version: 1.4) Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Patch (x32 Version: 1.5) Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (x32 Version: 1.6) Call of Duty(R) 4 - Modern Warfare(TM) 1.6 Patch (x32) Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (x32 Version: 1.7) Call of Duty(R) 4 - Modern Warfare(TM) 1.7 Patch (x32) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center Core Implementation (x32 Version: 2010.0122.858.16002) Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0122.858.16002) Catalyst Control Center Graphics Full New (x32 Version: 2010.0122.858.16002) Catalyst Control Center Graphics Light (x32 Version: 2010.0122.858.16002) Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0122.858.16002) Catalyst Control Center InstallProxy (x32 Version: 2010.0122.858.16002) Catalyst Control Center Localization All (x32 Version: 2010.0122.858.16002) CCC Help Chinese Standard (x32 Version: 2010.0122.0857.16002) CCC Help Chinese Traditional (x32 Version: 2010.0122.0857.16002) CCC Help Czech (x32 Version: 2010.0122.0857.16002) CCC Help Danish (x32 Version: 2010.0122.0857.16002) CCC Help Dutch (x32 Version: 2010.0122.0857.16002) CCC Help English (x32 Version: 2010.0122.0857.16002) CCC Help Finnish (x32 Version: 2010.0122.0857.16002) CCC Help French (x32 Version: 2010.0122.0857.16002) CCC Help German (x32 Version: 2010.0122.0857.16002) CCC Help Greek (x32 Version: 2010.0122.0857.16002) CCC Help Hungarian (x32 Version: 2010.0122.0857.16002) CCC Help Italian (x32 Version: 2010.0122.0857.16002) CCC Help Japanese (x32 Version: 2010.0122.0857.16002) CCC Help Korean (x32 Version: 2010.0122.0857.16002) CCC Help Norwegian (x32 Version: 2010.0122.0857.16002) CCC Help Polish (x32 Version: 2010.0122.0857.16002) CCC Help Portuguese (x32 Version: 2010.0122.0857.16002) CCC Help Russian (x32 Version: 2010.0122.0857.16002) CCC Help Spanish (x32 Version: 2010.0122.0857.16002) CCC Help Swedish (x32 Version: 2010.0122.0857.16002) CCC Help Thai (x32 Version: 2010.0122.0857.16002) CCC Help Turkish (x32 Version: 2010.0122.0857.16002) ccc-core-static (x32 Version: 2010.0122.858.16002) ccc-utility64 (Version: 2010.0122.858.16002) CCleaner (Version: 4.08) Counter-Strike 1.6 (x32) CounterStrike 1.6 from VSI (Version 1.02) (x32) Counter-Strike: Source (x32) Counter-Strike: Source Beta (x32) CyberLink PowerDVD 9 (x32 Version: 9.0.2529.50) D3DX10 (x32 Version: 15.4.2368.0902) Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition Defraggler (Version: 2.16) DivX-Setup (x32 Version: 2.6.1.8) DotaKeys (x32 Version: ) eBay Worldwide (x32 Version: 2.1.0901) ESI Prüfwerte (x32) ESI[tronic] DEMO_4 (x32) FL Studio 10 (x32) Full Tilt Poker.Eu (x32 Version: 4.63.11.WIN.FullTilt.EU) Google Chrome (HKCU Version: 31.0.1650.63) Google Chrome Frame (HKCU Version: 31.0.1650.57) Google Earth (x32 Version: 7.1.1.1888) Google Gears (x32 Version: 0.5.3600) Google Toolbar for Internet Explorer (x32 Version: 1.0.0) Google Toolbar for Internet Explorer (x32 Version: 7.5.4601.54) Google Update Helper (x32 Version: 1.3.21.165) Haali Media Splitter (x32) Identity Card (x32 Version: 1.00.3003) Intel(R) Management Engine Components (x32 Version: 6.0.0.1179) Intel(R) Rapid Storage Technology (x32 Version: 9.6.0.1014) iTunes (Version: 11.1.1.11) Java 7 Update 25 (x32 Version: 7.0.250) Java Auto Updater (x32 Version: 2.1.9.5) JDownloader 0.9 (x32 Version: 0.9) Junk Mail filter update (x32 Version: 15.4.3502.0922) KTS (x32 Version: 4.0.0) Launch Manager (x32 Version: 4.0.8) LiveTV Sammlung (HKCU Version: 2.0.2.2) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320) Microsoft Application Error Reporting (Version: 12.0.6015.5000) Microsoft Office 2010 (x32 Version: 14.0.4763.1000) Microsoft Office 2010 Service Pack 1 (SP1) Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Office 32-bit Components 2010 (Version: 14.0.6029.1000) Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000) Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000) Microsoft Outlook Hotmail Connector 64-Bit (Version: 14.0.6123.5001) Microsoft Silverlight (x32 Version: 4.1.10329.0) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (x32 Version: 8.0.50727.4053) Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001) Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570 (Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (x32 Version: 9.0.30729.5570) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 8.0.1 (x86 de) (x32 Version: 8.0.1) MSVCRT (x32 Version: 15.4.2862.0708) MSVCRT_amd64 (x32 Version: 15.4.2862.0708) MyWinLocker (x32 Version: 3.1.206.0) MyWinLocker Suite (x32 Version: 3.1.206.0) Need for Speed Ultimate Colletion (x32) Need for Speed Underground 2 (x32) Norton Online Backup (x32 Version: 1.2.0.36) NTI Backup Now 5 (x32 Version: 5.1.2.628) NTI Backup Now Standard (x32 Version: 5.1.2.628) NTI Media Maker 8 (x32 Version: 8.0.12.6630) NVIDIA PhysX (x32 Version: 9.10.0513) PokerStars.net (x32) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6000) Samsung Kies (x32 Version: 2.3.0.12035_16) SAMSUNG USB Driver for Mobile Phones (Version: 1.5.6.0) Shredder (Version: 2.0.5.0) Shredder (x32 Version: 2.0.5.0) Steamless Counter Strike Source Pack (x32 Version: 1.0) Synaptics Pointing Device Driver (Version: 14.0.6.0) Team Fortress 2 (x32) TmNationsForever (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2473228) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) Update for Microsoft Office 2010 (KB2553065) Update for Microsoft Office 2010 (KB2553092) Update for Microsoft Office 2010 (KB2553181) 64-Bit Edition Update for Microsoft Office 2010 (KB2553267) 64-Bit Edition Update for Microsoft Office 2010 (KB2553270) 64-Bit Edition Update for Microsoft Office 2010 (KB2553272) 64-Bit Edition Update for Microsoft Office 2010 (KB2553310) 64-Bit Edition Update for Microsoft Office 2010 (KB2566458) Update for Microsoft Office 2010 (KB2598289) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2553290) 64-Bit Edition Update for Microsoft OneNote 2010 (KB2589345) 64-Bit Edition Update for Microsoft Outlook 2010 (KB2553248) 64-Bit Edition Update for Microsoft Outlook Social Connector 2010 (KB2553406) 64-Bit Edition VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0) VLC media player 2.0.8 (x32 Version: 2.0.8) Welcome Center (x32 Version: 1.01.3002) Windows Live Communications Platform (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3502.0922) Windows Live Essentials (x32 Version: 15.4.3538.0513) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922) Windows Live ID Sign-in Assistant (Version: 7.250.4232.0) Windows Live Installer (x32 Version: 15.4.3502.0922) Windows Live Language Selector (Version: 15.4.3538.0513) Windows Live Mail (x32 Version: 15.4.3502.0922) Windows Live Messenger (x32 Version: 15.4.3538.0513) Windows Live MIME IFilter (Version: 15.4.3502.0922) Windows Live Movie Maker (x32 Version: 15.4.3502.0922) Windows Live Photo Common (x32 Version: 15.4.3502.0922) Windows Live Photo Gallery (x32 Version: 15.4.3502.0922) Windows Live PIMT Platform (x32 Version: 15.4.3508.1109) Windows Live SOXE (x32 Version: 15.4.3502.0922) Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922) Windows Live Sync (x32 Version: 14.0.8117.416) Windows Live UX Platform (x32 Version: 15.4.3502.0922) Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109) Windows Live Writer (x32 Version: 15.4.3502.0922) Windows Live Writer Resources (x32 Version: 15.4.3502.0922) Windows Media Player Firefox Plugin (x32 Version: 1.0.0.8) WinRAR 4.00 (64-Bit) (Version: 4.00.0) ==================== Restore Points ========================= 05-12-2013 15:59:18 ComboFix created restore point 07-12-2013 21:09:58 Malwarebytes Anti-Rootkit Restore Point ==================== Hosts content: ========================== 2009-07-14 03:34 - 2013-12-05 17:09 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {05966E13-F996-4CAD-8D70-89CB35E37C65} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-11-22] (Piriform Ltd) Task: {11FCEF4D-60A0-4E78-B94D-0E4A34A1EB4F} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000Core => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-17] (Google Inc.) Task: {14365ECD-396D-4CD1-A552-91F376417A29} - System32\Tasks\RealUpgradeLogonTaskS-1-5-21-3577554524-86806762-3300807997-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {1455E5BC-E812-4B69-BD29-4765674FF1CF} - System32\Tasks\Java Update Scheduler => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [2013-03-12] (Oracle Corporation) Task: {2C37A929-CFF3-4E0C-975D-50D56C3C1962} - System32\Tasks\{066AA482-CA98-4F6F-9AC9-72A24B653C2F} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {39C6EE68-889A-419C-BCAF-7B156E05D78B} - System32\Tasks\{3A2230D1-5151-48B4-865F-629492CC1E6C} => C:\Program Files (x86)\Skype\\Phone\Skype.exe Task: {3E5DB66E-AECF-4A72-933E-A9C978C59CFB} - \DealPly No Task File Task: {5396B8C0-10C7-4513-BC36-1546E34BF455} - System32\Tasks\{58691F48-DEFE-447C-9653-4FEA3F44DA99} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {69D9F157-56A5-45AB-ABAD-C3A1EEEE0E1D} - System32\Tasks\RealUpgradeScheduledTaskS-1-5-21-3577554524-86806762-3300807997-1000 => C:\Program Files (x86)\Real\RealUpgrade\RealUpgrade.exe Task: {6EBC9658-0FBD-427C-9CAD-373F64EDCCA3} - System32\Tasks\{9C96BBA0-298A-4908-8211-7F908E4A874C} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {6F413E5F-0339-4ABF-ACD2-E555618A2D74} - System32\Tasks\Google Updater and Installer => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-17] (Google Inc.) Task: {795B7B6F-54FC-4F95-B903-D9838E9AB65E} - System32\Tasks\{CFF6BE17-13E5-45C9-ACAD-EC746F3C5483} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {7D75482C-99A7-4A5A-BA0F-99061DEA2F9F} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-03-19] (Adobe Systems Incorporated) Task: {8B0CA803-1009-4B89-9A6E-AD1B472E9357} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000UA => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [2011-02-17] (Google Inc.) Task: {8F10B9FB-B072-428A-B4F5-ABE881860A5C} - System32\Tasks\{20C73931-A81F-4FB3-87E1-A8C7607F90A2} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {9728C1CE-8B34-4CED-BE15-81C09A1CEA29} - System32\Tasks\{1D52CD23-40D4-41F6-BF9F-A93C85CAA1E4} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {984E0A7E-6B23-428F-BCC4-F1AEA54ED1AE} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-26] (Google Inc.) Task: {9BA12277-B2E2-4D20-8764-25F50D69EAD6} - System32\Tasks\{50A74122-2781-4251-8DE6-193AF0F8836A} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {A0EC00DB-1A81-48E2-A397-E27D0EBC8C67} - System32\Tasks\Wecker => C:\Users\Martin\Music\Bohse Onkelz\Viva Los Tioz\07 Terpentin.wma Task: {C0879505-251C-4103-873B-C00601CCC588} - System32\Tasks\{48704270-711D-4189-A349-2DAF880C82C1} => C:\Users\Martin\Desktop\TuneUp Utilities 2013\OneClickStarter.exe Task: {D2A9DC02-60B8-44E2-9553-FD4A8C99B643} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {E4464F39-5ABD-4DF5-A2BA-809381237D04} - \QtraxPlayer No Task File Task: {EA888AAD-E631-4088-9FF7-D19E3B66537B} - System32\Tasks\{094824F9-0398-4B31-A8DD-C8A40D2172DB} => C:\Users\Martin\Desktop\Games\Rockstar Games\Grand Theft Auto San Andreas\gta_sa.exe [2005-06-07] () Task: {F1703F32-3150-4584-A4C3-43AC1A4EB838} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-01-26] (Google Inc.) Task: {F2D39ED2-A91A-447B-9F73-C63F2B34B0C5} - System32\Tasks\Updater => C:\ProgramData\WombatUpdater\WombatUpdater.exe [2013-09-25] () Task: {FAA911BF-D72E-42AB-8FB7-AB7E6B6929D2} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-04-04] (Adobe Systems Incorporated) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000Core.job => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000UA.job => C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\Updater.job => C:\ProgramData\WombatUpdater\WombatUpdater.exe ==================== Loaded Modules (whitelisted) ============= 2010-01-07 13:42 - 2010-01-07 13:42 - 00016384 ____R () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2010-09-08 02:01 - 2010-09-08 02:01 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2011-03-17 00:07 - 2011-03-17 00:07 - 04297568 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2011-04-24 01:49 - 2011-03-02 11:40 - 00164864 _____ () C:\Program Files\WinRAR\rarext.dll 2013-09-01 10:54 - 2013-09-01 10:29 - 00394824 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll 2012-11-28 13:13 - 2012-11-28 13:13 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2012-11-28 13:13 - 2012-11-28 13:13 - 01242512 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2010-03-09 01:18 - 2010-03-09 01:18 - 00465576 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\sqlite3.dll 2010-03-09 01:13 - 2010-03-09 01:13 - 01081600 _____ () C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\ACE.dll 2013-12-07 21:58 - 2013-12-04 03:47 - 00702416 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-07 21:58 - 2013-12-04 03:47 - 00099792 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\libegl.dll 2013-12-07 21:58 - 2013-12-04 03:48 - 04055504 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-07 21:58 - 2013-12-04 03:48 - 00399312 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-07 21:58 - 2013-12-04 03:47 - 01619408 _____ () C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\Temp:AD022376 ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Ethernet-Controller Description: Ethernet-Controller Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2013-12-05 17:09:03.065 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2013-12-05 17:09:03.034 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2011-01-26 23:36:39.687 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\sfvfs02.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2011-01-26 23:36:39.672 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume3\Windows\System32\drivers\sfvfs02.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Percentage of memory in use: 39% Total physical RAM: 3956.5 MB Available physical RAM: 2412.91 MB Total Pagefile: 5954.69 MB Available Pagefile: 3897.93 MB Total Virtual: 8192 MB Available Virtual: 8191.8 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:452.48 GB) (Free:224.56 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 466 GB) (Disk ID: 1C7B1C7B) Partition 1: (Not Active) - (Size=13 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=452 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
10.12.2013, 21:42 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht Jetzt hast du 2x die additions gepostet von FRST
__________________ Logfiles bitte immer in CODE-Tags posten |
16.12.2013, 20:03 | #13 |
| Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht ooh tut mir Leid. FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-12-2013 02 Ran by Martin (administrator) on MARTIN-PC on 16-12-2013 20:00:34 Running from C:\Users\Martin\Desktop\Rescue Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (APN LLC.) C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Dritek System Inc.) C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Registration\GREGsvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe (NewTech Infosystems, Inc.) C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe () C:\Windows\SysWOW64\PnkBstrA.exe (Acer Group) C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE (Google Inc.) C:\Users\Martin\AppData\Local\Google\Update\1.3.22.3\GoogleCrashHandler.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 9.0\Reader\reader_sl.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerEvent.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avshadow.exe (Avira Operations GmbH & Co. KG) C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Egis Technology Inc.) C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Google Inc.) C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AmIcoSinglun64] - C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [323584 2009-09-23] (Alcor Micro Corp.) HKLM\...\Run: [mwlDaemon] - C:\Program Files (x86)\EgisTec MyWinLocker\x86\mwlDaemon.exe [349552 2010-02-01] (Egis Technology Inc.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [9643552 2009-12-11] (Realtek Semiconductor) HKLM\...\Run: [Acer ePower Management] - C:\Program Files\Acer\Acer ePower Management\ePowerTray.exe [861216 2010-04-23] (Acer Incorporated) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated) HKCU\...\Run: [OfficeSyncProcess] - C:\Program Files\Microsoft Office\Office14\MSOSYNC.EXE [911160 2012-01-18] (Microsoft Corporation) HKCU\...\Run: [Google Update] - C:\Users\Martin\AppData\Local\Google\Update\GoogleUpdate.exe [136176 2011-02-17] (Google Inc.) HKLM-x32\...\Run: [SuiteTray] - C:\Program Files (x86)\EgisTec MyWinLockerSuite\x86\SuiteTray.exe [337264 2010-02-01] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisUpdate] - C:\Program Files (x86)\EgisTec IPS\EgisUpdate.exe [201512 2009-12-25] (Egis Technology Inc.) HKLM-x32\...\Run: [EgisTecPMMUpdate] - C:\Program Files (x86)\EgisTec IPS\PmmUpdate.exe [401192 2009-12-25] (Egis Technology Inc.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2010-01-22] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [avgnt] - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe [347192 2013-09-05] (Avira Operations GmbH & Co. KG) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [253816 2013-03-12] (Oracle Corporation) HKU\Default\...\RunOnce: [ScrSav] - C:\Program Files (x86)\Acer\Screensaver\run_Acer.exe [154144 2010-01-15] () HKU\Gast\...\Run: [swg] - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [39408 2010-05-07] (Google Inc.) BootExecute: autocheck autochk /p \??\E:autocheck autochk /p \??\F:autocheck autochk * ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7741&r=27360111h906l0458z105t4791o183 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7741&r=27360111h906l0458z105t4791o183 HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&m=aspire_7741&r=27360111h906l0458z105t4791o183 URLSearchHook: HKLM-x32 - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg64.dll (Google Inc.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Adobe PDF Link Helper - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll (Adobe Systems Incorporated) BHO-x32: No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) BHO-x32: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - C:\Program Files (x86)\Google\Google Gears\Internet Explorer\0.5.36.0\gears.dll (Google Inc.) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKLM - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) Toolbar: HKLM-x32 - No Name - {41564952-412D-5637-00A7-7A786E7484D7} - No File Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.) Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.) Toolbar: HKCU - Avira SearchFree Toolbar - {41564952-412D-5637-00A7-7A786E7484D7} - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\AVIRA-V7\Passport_x64.dll (APN LLC.) DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Handler: gcf - {9875BFAF-B04D-445E-8A69-BE36838CDE3E} - No File Handler-x32: gcf - No CLSID Value - Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_6_602_180.dll () FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_6_602_180.dll () FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @Google.com/GoogleEarthPlugin - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE - disabled No File FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @real.com/nprpchromebrowserrecordext;version=15.0.1.13 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF Plugin-x32: @real.com/nprphtml5videoshim;version=15.0.4.53 - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.165\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.0.8 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @lightspark.github.com/Lightspark;version=1 - C:\Program Files (x86)\Lightspark 0.5.3-git\nplightsparkplugin.dll No File FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Martin\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Martin\AppData\Local\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\searchplugins\yahoo-de.xml FF Extension: No Name - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\staged FF Extension: Avira SearchFree Toolbar plus Web Protection - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\toolbar_AVIRA-V7@apn.ask.com FF Extension: toolbar_AVIRA-V7 - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\toolbar_AVIRA-V7@apn.ask.com.xpi FF Extension: stylish - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{46551EC9-40F0-4e47-8E18-8E5CF550CFB8}.xpi FF Extension: No Name - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{6C8B07BF-0F6D-4EA4-B96F-FF1CCBAAE553}.xpi FF Extension: Adblock Plus - C:\Users\Martin\AppData\Roaming\Mozilla\Firefox\Profiles\t6rnwsmv.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi FF Extension: Java Console - C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} FF HKLM-x32\...\Firefox\Extensions: [{000a9d1c-beef-4f90-9363-039d445309b8}] - C:\Program Files (x86)\Google\Google Gears\Firefox\ FF Extension: Google Gears - C:\Program Files (x86)\Google\Google Gears\Firefox\ Chrome: ======= CHR HomePage: hxxp://www.google.com CHR DefaultSearchKeyword: google.de CHR DefaultSearchProvider: Google CHR DefaultSearchURL: {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding} CHR DefaultNewTabURL: {google:baseURL}_/chrome/newtab?{google:RLZ}{google:instantExtendedEnabledParameter}{google:ntpIsThemedParameter}ie={inputEncoding} CHR Plugin: (Remoting Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Shockwave Flash) - C:\Users\Martin\AppData\Local\Google\Chrome\Application\31.0.1650.63\gcswf32.dll No File CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll No File CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Java Deployment Toolkit 6.0.310.5) - C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll No File CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File CHR Plugin: (RealPlayer(tm) G2 LiveConnect-Enabled Plug-In (32-bit) ) - C:\Program Files (x86)\Mozilla Firefox\plugins\nppl3260.dll No File CHR Plugin: (RealPlayer Version Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprpjplug.dll No File CHR Plugin: (RealPlayer(tm) HTML5VideoShim Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) CHR Plugin: (RealJukebox NS Plugin) - C:\Program Files (x86)\Mozilla Firefox\plugins\nprjplug.dll No File CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPAUTHZ.DLL (Microsoft Corporation) CHR Plugin: (Microsoft Office 2010) - C:\PROGRA~2\MICROS~4\Office14\NPSPWRAP.DLL (Microsoft Corporation) CHR Plugin: (Google Earth Plugin) - C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) CHR Plugin: (RealNetworks(tm) Chrome Background Extension Plug-In (32-bit) ) - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation) CHR Extension: (YouTube) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (Stylish) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fjnbnpbmkenffdnngjfgmeleoegfcffe\1.2_0 CHR Extension: (AdBlock) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0 CHR Extension: (AT_Porsche) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkclphmapdcppbmekmbkcjfanpmoidpg\3_0 CHR Extension: (Google Wallet) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.5.0_0 CHR Extension: (Gmail) - C:\Users\Martin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 CHR StartMenuInternet: Google Chrome - C:\Users\Martin\AppData\Local\Google\Chrome\Application\chrome.exe ==================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe [84024 2013-09-05] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe [108088 2013-09-05] (Avira Operations GmbH & Co. KG) R2 AntiVirWebService; C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE [815160 2013-09-05] (Avira Operations GmbH & Co. KG) R2 APNMCP; C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe [166352 2013-10-23] (APN LLC.) S3 MWLService; C:\Program Files (x86)\EgisTec MyWinLocker\x86\MWLService.exe [305520 2010-02-01] (Egis Technology Inc.) R2 PnkBstrA; C:\Windows\SysWow64\PnkBstrA.exe [75064 2011-07-08] () ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [105344 2013-09-05] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [132088 2013-09-05] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [28600 2013-09-01] (Avira Operations GmbH & Co. KG) S1 prodrv06; C:\Windows\SysWow64\drivers\prodrv06.sys [54272 2004-04-08] (Protection Technology) S0 prohlp02; C:\Windows\SysWow64\drivers\prohlp02.sys [70400 2004-04-08] (Protection Technology) S0 prosync1; C:\Windows\SysWow64\drivers\prosync1.sys [6944 2003-09-06] (Protection Technology) S3 RimVSerPort; C:\Windows\System32\DRIVERS\RimSerial_AMD64.sys [44032 2011-07-20] (Research in Motion Ltd) S0 sfhlp01; C:\Windows\SysWow64\drivers\sfhlp01.sys [4832 2003-12-01] (Protection Technology) R2 {B154377D-700F-42cc-9474-23858FBDF4BD}; c:\Program Files (x86)\CyberLink\PowerDVD9\000.fcl [146928 2010-01-22] (CyberLink Corp.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) S3 catchme; \??\C:\ComboFix\catchme.sys [x] S3 GGSAFERDriver; \??\C:\Program Files (x86)\Garena\safedrv.sys [x] S3 k57nd60a; system32\DRIVERS\k57nd60a.sys [x] S3 RimUsb; System32\Drivers\RimUsb_AMD64.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-12-10 21:39 - 2013-12-16 20:00 - 00000000 ____D C:\Users\Martin\Desktop\Rescue 2013-12-10 21:27 - 2013-12-10 21:27 - 00000000 ____D C:\Users\Martin\Downloads\FRST-OlderVersion 2013-12-10 21:11 - 2013-12-10 21:11 - 00000000 ____D C:\Windows\ERUNT 2013-12-10 21:02 - 2013-12-10 21:05 - 00000000 ____D C:\AdwCleaner 2013-12-07 21:40 - 2013-12-07 21:40 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-12-07 21:39 - 2013-12-07 22:16 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2013-12-07 21:37 - 2013-12-07 22:15 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-12-05 17:12 - 2013-12-05 17:12 - 00022105 _____ C:\ComboFix.txt 2013-12-05 16:59 - 2013-12-05 17:12 - 00000000 ____D C:\Qoobox 2013-12-05 16:59 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2013-12-05 16:59 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2013-12-05 16:59 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2013-12-05 16:59 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2013-12-05 16:59 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2013-12-05 16:59 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2013-12-05 16:59 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2013-12-05 16:59 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2013-12-05 15:57 - 2013-12-05 17:10 - 00000000 ____D C:\Windows\erdnt 2013-12-04 19:26 - 2013-12-16 20:00 - 00000000 ____D C:\FRST 2013-12-04 19:23 - 2013-12-04 19:23 - 00000000 _____ C:\Users\Martin\defogger_reenable 2013-12-04 18:25 - 2013-12-04 18:25 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2013-12-04 18:25 - 2013-12-04 18:25 - 00000000 ____D C:\Program Files\Synaptics 2013-12-04 18:24 - 2013-12-04 18:26 - 00005258 _____ C:\Windows\DPINST.LOG 2013-12-04 18:24 - 2009-09-17 20:12 - 00292912 _____ (Synaptics Incorporated) C:\Windows\system32\Drivers\SynTP.sys 2013-12-04 18:24 - 2009-09-17 20:09 - 00396072 _____ (Synaptics Incorporated) C:\Windows\system32\SynCOM.dll 2013-12-04 18:24 - 2009-09-17 20:09 - 00263464 _____ (Synaptics Incorporated) C:\Windows\system32\SynCtrl.dll 2013-12-04 18:24 - 2009-09-17 20:09 - 00206120 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCtrl.dll 2013-12-04 18:24 - 2009-09-17 20:09 - 00205608 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPAPI.dll 2013-12-04 18:24 - 2009-09-17 20:09 - 00169256 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynCOM.dll 2013-12-04 18:24 - 2009-09-17 20:09 - 00147752 _____ (Synaptics Incorporated) C:\Windows\system32\SynTPCo4.dll 2013-12-04 18:24 - 2009-09-17 20:09 - 00107816 _____ (Synaptics Incorporated) C:\Windows\SysWOW64\SynTPCOM.dll 2013-12-04 18:20 - 2009-09-17 20:09 - 00214312 _____ (Synaptics Incorporated) C:\Users\Martin\Setup.exe 2013-12-04 18:03 - 2013-12-04 18:17 - 30569167 _____ C:\Users\Martin\Downloads\TouchPad_Synaptics_14.0.6.0_W7x86W7x64_A.zip 2013-12-04 17:30 - 2013-12-07 22:13 - 00001928 _____ C:\Windows\PFRO.log 2013-12-03 21:14 - 2013-12-16 19:56 - 00000803 _____ C:\Windows\setupact.log 2013-12-03 21:14 - 2013-12-03 21:14 - 00000000 _____ C:\Windows\setuperr.log 2013-12-03 21:12 - 2013-12-03 21:12 - 00000020 _____ C:\Users\Martin\Desktop\ram.vbe 2013-12-03 20:29 - 2013-12-03 20:29 - 00001728 _____ C:\Users\Public\Desktop\Defraggler.lnk 2013-12-03 20:29 - 2013-12-03 20:29 - 00000000 ____D C:\Program Files\Defraggler 2013-12-03 20:28 - 2013-12-03 20:28 - 04208656 _____ (Piriform Ltd) C:\Users\Martin\Downloads\dfsetup216.exe 2013-12-03 20:13 - 2013-12-03 20:13 - 00029054 _____ C:\Users\Martin\Documents\cc_20131203_201306.reg 2013-12-03 20:13 - 2013-12-03 20:13 - 00000686 _____ C:\Users\Martin\Documents\cc_20131203_201328.reg 2013-12-03 20:12 - 2013-12-03 20:12 - 00320468 _____ C:\Users\Martin\Documents\cc_20131203_201226.reg 2013-12-03 20:09 - 2013-12-03 20:09 - 00614784 _____ C:\Users\Martin\Downloads\Defraggler - CHIP-Downloader.exe 2013-12-03 20:08 - 2013-12-03 20:08 - 00002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-12-03 20:08 - 2013-12-03 20:08 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-12-03 20:08 - 2013-12-03 20:08 - 00000000 ____D C:\Program Files\CCleaner 2013-12-03 20:06 - 2013-12-03 20:06 - 00614784 _____ C:\Users\Martin\Downloads\CCleaner - CHIP-Downloader.exe 2013-12-03 17:07 - 2013-12-03 17:07 - 00001192 _____ C:\Users\Martin\Desktop\FL Studio 10.lnk 2013-12-02 23:46 - 2013-12-02 23:57 - 159401976 _____ (Advanced Micro Devices, Inc.) C:\Users\Martin\Downloads\12-6_vista_win7_64_dd_ccc.exe 2013-12-02 23:12 - 2013-12-02 23:12 - 00000000 ____D C:\Program Files\ATI Technologies 2013-12-02 23:10 - 2013-12-02 23:10 - 00000000 ____D C:\AMD 2013-12-02 20:58 - 2013-12-02 21:01 - 00000000 ____D C:\Users\Martin\Documents\Visual Studio 2005 2013-12-02 20:18 - 2013-12-02 20:20 - 00000000 ____D C:\Users\Martin\AppData\Roaming\LiveTV Wilmaa 2013-12-02 20:18 - 2013-12-02 20:18 - 00000326 _____ C:\Users\Martin\Desktop\LiveTV Sammlung.appref-ms 2013-12-02 20:18 - 2013-12-02 20:18 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LSWARE 2013-12-02 20:16 - 2013-12-02 20:16 - 00401752 _____ (Softonic ) C:\Users\Martin\Downloads\SoftonicDownloader_fuer_livetv-wilmaa.exe ==================== One Month Modified Files and Folders ======= 2013-12-16 20:00 - 2013-12-10 21:39 - 00000000 ____D C:\Users\Martin\Desktop\Rescue 2013-12-16 20:00 - 2013-12-04 19:26 - 00000000 ____D C:\FRST 2013-12-16 19:57 - 2011-05-21 16:38 - 00000298 _____ C:\Windows\Tasks\Updater.job 2013-12-16 19:57 - 2011-01-26 21:52 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-12-16 19:57 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\tracing 2013-12-16 19:56 - 2013-12-03 21:14 - 00000803 _____ C:\Windows\setupact.log 2013-12-16 19:56 - 2012-02-05 22:46 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2013-12-16 19:56 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2013-12-10 21:40 - 2010-09-08 02:01 - 01587481 _____ C:\Windows\WindowsUpdate.log 2013-12-10 21:27 - 2013-12-10 21:27 - 00000000 ____D C:\Users\Martin\Downloads\FRST-OlderVersion 2013-12-10 21:15 - 2009-07-14 05:45 - 00025840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-12-10 21:15 - 2009-07-14 05:45 - 00025840 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-12-10 21:11 - 2013-12-10 21:11 - 00000000 ____D C:\Windows\ERUNT 2013-12-10 21:11 - 2010-09-08 11:49 - 00657948 _____ C:\Windows\system32\perfh007.dat 2013-12-10 21:11 - 2010-09-08 11:49 - 00131288 _____ C:\Windows\system32\perfc007.dat 2013-12-10 21:11 - 2009-07-14 06:13 - 01507502 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-10 21:10 - 2012-03-19 00:25 - 00003938 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{BFC5884C-E550-49B6-8B94-FD1750F17A22} 2013-12-10 21:05 - 2013-12-10 21:02 - 00000000 ____D C:\AdwCleaner 2013-12-10 21:04 - 2011-01-26 17:34 - 00000000 ____D C:\ProgramData\ICQ 2013-12-10 21:03 - 2011-04-16 16:33 - 00001124 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000UA.job 2013-12-08 10:56 - 2011-01-26 21:52 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-12-08 08:03 - 2011-04-16 16:33 - 00001072 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000Core.job 2013-12-08 07:58 - 2011-04-16 16:33 - 00004100 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000UA 2013-12-08 07:58 - 2011-04-16 16:33 - 00003704 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-3577554524-86806762-3300807997-1000Core 2013-12-07 22:16 - 2013-12-07 21:39 - 00116440 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2013-12-07 22:15 - 2013-12-07 21:37 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2013-12-07 22:13 - 2013-12-04 17:30 - 00001928 _____ C:\Windows\PFRO.log 2013-12-07 22:10 - 2011-01-26 15:58 - 00000000 ____D C:\Users\Martin 2013-12-07 21:58 - 2011-04-16 16:34 - 00002366 _____ C:\Users\Martin\Desktop\Google Chrome.lnk 2013-12-07 21:40 - 2013-12-07 21:40 - 00000000 ____D C:\ProgramData\Malwarebytes 2013-12-05 19:35 - 2011-01-26 23:16 - 00000000 ____D C:\Users\Martin\AppData\Roaming\vlc 2013-12-05 17:52 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-05 17:12 - 2013-12-05 17:12 - 00022105 _____ C:\ComboFix.txt 2013-12-05 17:12 - 2013-12-05 16:59 - 00000000 ____D C:\Qoobox 2013-12-05 17:12 - 2011-11-30 17:44 - 00000000 ____D C:\Users\Martin\AppData\Local\Apps\2.0 2013-12-05 17:12 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2013-12-05 17:10 - 2013-12-05 15:57 - 00000000 ____D C:\Windows\erdnt 2013-12-05 17:09 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2013-12-04 19:23 - 2013-12-04 19:23 - 00000000 _____ C:\Users\Martin\defogger_reenable 2013-12-04 18:42 - 2011-02-13 18:09 - 00000000 ____D C:\Users\Martin\Documents\TrackMania 2013-12-04 18:30 - 2011-07-09 02:06 - 00000000 ____D C:\ProgramData\TrackMania 2013-12-04 18:26 - 2013-12-04 18:24 - 00005258 _____ C:\Windows\DPINST.LOG 2013-12-04 18:25 - 2013-12-04 18:25 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_SynTP_01009.Wdf 2013-12-04 18:25 - 2013-12-04 18:25 - 00000000 ____D C:\Program Files\Synaptics 2013-12-04 18:17 - 2013-12-04 18:03 - 30569167 _____ C:\Users\Martin\Downloads\TouchPad_Synaptics_14.0.6.0_W7x86W7x64_A.zip 2013-12-04 17:31 - 2009-07-14 05:45 - 00416368 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-03 21:14 - 2013-12-03 21:14 - 00000000 _____ C:\Windows\setuperr.log 2013-12-03 21:12 - 2013-12-03 21:12 - 00000020 _____ C:\Users\Martin\Desktop\ram.vbe 2013-12-03 20:29 - 2013-12-03 20:29 - 00001728 _____ C:\Users\Public\Desktop\Defraggler.lnk 2013-12-03 20:29 - 2013-12-03 20:29 - 00000000 ____D C:\Program Files\Defraggler 2013-12-03 20:28 - 2013-12-03 20:28 - 04208656 _____ (Piriform Ltd) C:\Users\Martin\Downloads\dfsetup216.exe 2013-12-03 20:24 - 2011-01-26 15:58 - 00108824 _____ C:\Users\Martin\AppData\Local\GDIPFONTCACHEV1.DAT 2013-12-03 20:13 - 2013-12-03 20:13 - 00029054 _____ C:\Users\Martin\Documents\cc_20131203_201306.reg 2013-12-03 20:13 - 2013-12-03 20:13 - 00000686 _____ C:\Users\Martin\Documents\cc_20131203_201328.reg 2013-12-03 20:12 - 2013-12-03 20:12 - 00320468 _____ C:\Users\Martin\Documents\cc_20131203_201226.reg 2013-12-03 20:11 - 2011-02-18 01:02 - 00000000 ____D C:\Users\Martin\Tracing 2013-12-03 20:11 - 2011-01-31 15:23 - 00000000 ____D C:\Program Files\Steam 2013-12-03 20:11 - 2009-07-27 21:41 - 00000000 ____D C:\Windows\Panther 2013-12-03 20:09 - 2013-12-03 20:09 - 00614784 _____ C:\Users\Martin\Downloads\Defraggler - CHIP-Downloader.exe 2013-12-03 20:08 - 2013-12-03 20:08 - 00002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2013-12-03 20:08 - 2013-12-03 20:08 - 00000826 _____ C:\Users\Public\Desktop\CCleaner.lnk 2013-12-03 20:08 - 2013-12-03 20:08 - 00000000 ____D C:\Program Files\CCleaner 2013-12-03 20:06 - 2013-12-03 20:06 - 00614784 _____ C:\Users\Martin\Downloads\CCleaner - CHIP-Downloader.exe 2013-12-03 17:07 - 2013-12-03 17:07 - 00001192 _____ C:\Users\Martin\Desktop\FL Studio 10.lnk 2013-12-02 23:57 - 2013-12-02 23:46 - 159401976 _____ (Advanced Micro Devices, Inc.) C:\Users\Martin\Downloads\12-6_vista_win7_64_dd_ccc.exe 2013-12-02 23:12 - 2013-12-02 23:12 - 00000000 ____D C:\Program Files\ATI Technologies 2013-12-02 23:10 - 2013-12-02 23:10 - 00000000 ____D C:\AMD 2013-12-02 21:01 - 2013-12-02 20:58 - 00000000 ____D C:\Users\Martin\Documents\Visual Studio 2005 2013-12-02 20:48 - 2011-11-30 17:44 - 00000000 ____D C:\Users\Martin\AppData\Local\Deployment 2013-12-02 20:27 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2013-12-02 20:20 - 2013-12-02 20:18 - 00000000 ____D C:\Users\Martin\AppData\Roaming\LiveTV Wilmaa 2013-12-02 20:18 - 2013-12-02 20:18 - 00000326 _____ C:\Users\Martin\Desktop\LiveTV Sammlung.appref-ms 2013-12-02 20:18 - 2013-12-02 20:18 - 00000000 ____D C:\Users\Martin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LSWARE 2013-12-02 20:16 - 2013-12-02 20:16 - 00401752 _____ (Softonic ) C:\Users\Martin\Downloads\SoftonicDownloader_fuer_livetv-wilmaa.exe 2013-11-24 19:51 - 2011-01-26 21:52 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2013-11-24 19:51 - 2011-01-26 21:52 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore Files to move or delete: ==================== C:\Users\Martin\Setup.exe Some content of TEMP: ==================== C:\Users\Martin\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-03 18:30 ==================== End Of Log ============================ |
16.12.2013, 22:18 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
18.12.2013, 14:21 | #15 |
| Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht MBAM Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.12.18.04 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 Martin :: MARTIN-PC [Administrator] 18.12.2013 14:08:09 mbam-log-2013-12-18 (14-08-09).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 241665 Laufzeit: 9 Minute(n), 14 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Martin\Downloads\SoftonicDownloader_fuer_livetv-wilmaa.exe (PUP.Optional.Softonic.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) |
Themen zu Acer Aspire 7741G - Lädt Spiele sehr langsam oder gar nicht |
acer aspire, adblock, adware/adware.gen, antivir, antivirus, aspire, avira searchfree toolbar, bonjour, branding, browser, computer, desktop, device driver, festplatte, flash player, grand theft auto, iexplore.exe, launch, plug-in, registry, richtlinie, security, software, spyware.agent, svchost.exe, system, tr/mediyes.gen6, trojan.agent.gen, windows, wsearch |