|
Log-Analyse und Auswertung: Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben AussetzerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
10.01.2014, 09:54 | #1 |
| Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer Hallo, mein Laptop zeigt ein komisches Verhalten: Er ist langsamer geworden, die Internetverbindung wird regelmäßig unterbrochen, die Maus friert ein. Habe bisher folgendes ausgeführt: Dell Diagnoseprogramm - zeigt keinen Fehler Malwarebytes - hat nichts gefunden GDATA Internet Security 2014 - hat nichts gefunden HiJackThis Protokoll: Logfile of Trend Micro HijackThis v2.0.4 Scan saved at 04:53:57, on 10.01.2014 Platform: Windows 7 SP1 (WinNT 6.00.3505) MSIE: Internet Explorer v11.0 (11.00.9600.16428) Boot mode: Normal Running processes: C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe C:\Program Files (x86)\Portrait Displays\PremierColor\DTHtml.exe C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe C:\Users\JULIAN\Downloads\HiJackThis204.exe C:\Windows\sysWow64\SearchProtocolHost.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13-comm.msn.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/p/?LinkId=255141 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :0 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exe, O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll O2 - BHO: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~3\Office14\URLREDIR.DLL O2 - BHO: DVDVideoSoft.WebPageAdjuster - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O4 - HKLM\..\Run: [USB3MON] "C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" O4 - HKLM\..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIconLaunch.exe "C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" 60 O4 - HKLM\..\Run: [DT DL2] C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_startup.exe -DL2 O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe" O4 - HKLM\..\Run: [G Data AntiVirus Tray] C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe O4 - HKLM\..\Run: [GDFirewallTray] C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe O4 - HKCU\..\Run: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe O4 - HKCU\..\Run: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean O4 - HKUS\S-1-5-21-3782054611-1871421019-760726191-1001\..\Run: [AnyDVD] C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe (User '?') O4 - HKUS\S-1-5-21-3782054611-1871421019-760726191-1001\..\Run: [Spybot-S&D Cleaning] "C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe" /autoclean (User '?') O4 - .DEFAULT User Startup: Smart Settings.lnk = C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (User 'Default user') O8 - Extra context menu item: An OneNote s&enden - res://C:\PROGRA~2\MICROS~3\Office14\ONBttnIE.dll/105 O8 - Extra context menu item: Free YouTube Download - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytvdownloader.htm O8 - Extra context menu item: Free YouTube to MP3 Converter - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\freeytmp3downloader.htm O8 - Extra context menu item: Nach Microsoft E&xcel exportieren - res://C:\PROGRA~2\MICROS~3\Office14\EXCEL.EXE/3000 O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll O9 - Extra button: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra 'Tools' menuitem: Verknüpfte &OneNote-Notizen - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll O9 - Extra button: HP Smart Web Printing ein- oder ausblenden - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll O9 - Extra button: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll O9 - Extra 'Tools' menuitem: Free YouTube Download - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL O20 - AppInit_DLLs: C:\Windows\SysWOW64\nvinit.dll O20 - Winlogon Notify: SDWinLogon - SDWinLogon.dll (file missing) O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe O23 - Service: Acronis Nonstop Backup Service (afcdpsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) O23 - Service: G Data AntiVirus Proxy (AVKProxy) - G Data Software AG - C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe O23 - Service: G Data Scheduler (AVKService) - G Data Software AG - C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe O23 - Service: G Data Dateisystem Wächter (AVKWCtl) - G Data Software AG - C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe O23 - Service: Intel(R) Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe O23 - Service: Dell Feature Enhancement Pack Service (DFEPService) - Dell Inc. - C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe O23 - Service: Portrait Displays Display Tune Service (DTSRVC) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing) O23 - Service: EmbassyService - Unknown owner - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: G Data Personal Firewall (GDFwSvc) - G Data Software AG - C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe O23 - Service: G Data Scanner (GDScan) - G Data Software AG - C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe O23 - Service: Google Update-Dienst (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Google Update-Dienst (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe O23 - Service: Intel(R) Rapid Storage Technology (IAStorDataMgrSvc) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe O23 - Service: @%SystemRoot%\system32\ieetwcollectorres.dll,-1000 (IEEtwCollectorService) - Unknown owner - C:\Windows\system32\IEEtwCollector.exe (file missing) O23 - Service: Intel(R) Capability Licensing Service Interface - Intel(R) Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe O23 - Service: Intel(R) PROSet Monitoring Service - Unknown owner - C:\Windows\system32\IProsetMonitor.exe (file missing) O23 - Service: Intel(R) Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: NitroPDFReaderDriverCreatorReadSpool2 (NitroReaderDriverReadSpool2) - Nitro PDF Software - C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) O23 - Service: NVIDIA Update Service Daemon (nvUpdatusService) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe O23 - Service: O2FLASH - Unknown owner - C:\Windows\system32\o2flash.exe (file missing) O23 - Service: O2SDIOAssist - Unknown owner - c:\Windows\SysWOW64\srvany.exe O23 - Service: Portrait Displays SDK Service (PdiService) - Portrait Displays, Inc. - C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: Spybot-S&D 2 Scanner Service (SDScannerService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe O23 - Service: Spybot-S&D 2 Updating Service (SDUpdateService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe O23 - Service: Spybot-S&D 2 Security Center Service (SDWSCService) - Safer-Networking Ltd. - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe O23 - Service: SecureStorageService - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Secure Storage Manager\SecureStorageService.exe O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing) O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe O23 - Service: Acronis Sync Agent Service (syncagentsrv) - Acronis - C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe O23 - Service: NTRU TSS v1.2.1.37 TCS (tcsd_win32.exe) - Unknown owner - C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe O23 - Service: TdmService - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) O23 - Service: Wave Authentication Manager Service - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) O23 - Service: DW WLAN Tray Service (wltrysvc) - Dell Inc. - C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) O23 - Service: WvPCR - Wave Systems Corp. - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe -- End of file - 15541 bytes Bitte um Hilfe Vielen Dank Boarderlion |
10.01.2014, 10:17 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer Hallo und
__________________Lesestoff: Bitte keine Hijackthis-Logfiles posten!!! Zitat:
Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
__________________ |
10.01.2014, 10:51 | #3 |
| Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer Hallo cosinus,
__________________Die beiden logs anbei: FST.txt :[CODE][ FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-01-2014 Ran by JULIAN (administrator) on JULIAN-PC on 10-01-2014 10:28:30 Running from C:\Users\JULIAN\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ATTENTION: If processes are not listed WMI should be repaired. ==================== Processes (Whitelisted) ================= ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [682904 2012-09-20] (Alps Electric Co., Ltd.) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-05-07] (IDT, Inc.) HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE [7469568 2012-01-18] (Dell Inc.) HKLM\...\Run: [TdmNotify] - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe [381296 2011-12-08] (Wave Systems Corp.) HKLM\...\Run: [DFEPApplication] - C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [7077432 2012-08-15] (Dell Inc.) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [403688 2012-06-28] (Acronis) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284480 2012-05-30] (Intel Corporation) HKLM-x32\...\Run: [DT DL2] - C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_Startup.exe [120400 2012-07-23] (Portrait Displays, Inc.) HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5993216 2012-06-28] (Acronis) HKLM-x32\...\Run: [G Data AntiVirus Tray] - C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe [1444472 2013-08-21] (G Data Software AG) HKLM-x32\...\Run: [GDFirewallTray] - C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [1854928 2013-03-22] (G Data Software AG) HKLM-x32\...\Run: [AcronisTimounterMonitor] - C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe [1173712 2012-06-28] (Acronis) HKLM-x32\...\Run: [] - [x] HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\program files (x86)\g data\internetsecurity\avkkid\avkcks.exe Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.) HKCU\...\Run: [AnyDVD] - C:\Program Files (x86)\SlySoft\AnyDVD\AnyDVDtray.exe [7495768 2013-10-25] (SlySoft, Inc.) HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3642312 2013-05-16] (Safer-Networking Ltd.) MountPoints2: {ee80f7c6-1c69-11e3-aab3-d4bed981107b} - G:\LaunchU3.exe -a AppInit_DLLs: C:\Windows\System32\nvinitx.dll [247144 2012-09-18] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll [203112 2012-09-18] (NVIDIA Corporation) Lsa: [Authentication Packages] msv1_0 wvauth Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.) Startup: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.) ==================== Internet (Whitelisted) ==================== ProxyServer: :0 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13-comm.msn.com SearchScopes: HKLM - DefaultScope {1CC45312-6052-4648-81D6-C20B14576A2C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MDDRJS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {1CC45312-6052-4648-81D6-C20B14576A2C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MDDRJS SearchScopes: HKLM-x32 - DefaultScope {1CC45312-6052-4648-81D6-C20B14576A2C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MDDRJS SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM-x32 - {1CC45312-6052-4648-81D6-C20B14576A2C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MDDRJS SearchScopes: HKCU - DefaultScope {1CC45312-6052-4648-81D6-C20B14576A2C} URL = SearchScopes: HKCU - {1CC45312-6052-4648-81D6-C20B14576A2C} URL = BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns64.dll (DVDVideoSoft Ltd.) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: DVDVideoSoft WebPageAdjuster Class - {EE932B49-D5C0-4D19-A3DA-CE0849258DE6} - C:\Program Files (x86)\Common Files\DVDVideoSoft\bin\IEDownloadMenuAndBtns.dll (DVDVideoSoft Ltd.) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\JULIAN\AppData\Roaming\Mozilla\Firefox\Profiles\yx6fcysc.default-1380303922440 FF DefaultSearchEngine: Ask Search FF SearchEngineOrder.1: Ask Search FF SelectedSearchEngine: Ask Search FF Homepage: hxxp://www.sueddeutsche.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF SearchPlugin: C:\Users\JULIAN\AppData\Roaming\Mozilla\Firefox\Profiles\yx6fcysc.default-1380303922440\searchplugins\ask-search.xml FF Extension: WOT - C:\Users\JULIAN\AppData\Roaming\Mozilla\Firefox\Profiles\yx6fcysc.default-1380303922440\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: Ghostery - C:\Users\JULIAN\AppData\Roaming\Mozilla\Firefox\Profiles\yx6fcysc.default-1380303922440\Extensions\firefox@ghostery.com.xpi FF Extension: NoScript - C:\Users\JULIAN\AppData\Roaming\Mozilla\Firefox\Profiles\yx6fcysc.default-1380303922440\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR DefaultSearchKeyword: bing.com CHR DefaultSearchProvider: Bing CHR DefaultSearchURL: hxxp://www.bing.com/search?setmkt=de-DE&q={searchTerms} CHR DefaultNewTabURL: CHR Extension: (Google Docs) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (WOT) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\2.4.5_0 CHR Extension: (YouTube) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (AdBlock) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0 CHR Extension: (Disconnect Search) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmobfennjmjnkdbklhcnnfbhfibedgkk\1.4.0_0 CHR Extension: (Ghostery) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\5.0.0_0 CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.2_0 CHR Extension: (Google Wallet) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1 CHR Extension: (Gmail) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx ==================== Services (Whitelisted) ================= R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [1970296 2013-08-26] (G Data Software AG) R2 AVKService; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [635000 2013-08-21] (G Data Software AG) R2 AVKWCtl; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe [2562208 2013-10-15] (G Data Software AG) R2 DFEPService; C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2280504 2012-08-15] (Dell Inc.) R2 DTSRVC; C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe [136784 2012-07-23] (Portrait Displays, Inc.) R2 EmbassyService; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe [218504 2012-01-17] () R3 GDFwSvc; C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [2942808 2013-10-17] (G Data Software AG) R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [695416 2013-08-22] (G Data Software AG) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-28] (Intel Corporation) S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S4 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NitroReaderDriverReadSpool2; C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [204304 2012-03-25] (Nitro PDF Software) R2 O2FLASH; C:\Windows\system32\o2flash.exe [244328 2011-11-16] (O2Micro International) R2 O2SDIOAssist; c:\Windows\SysWOW64\srvany.exe [8192 2003-04-19] () R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) S3 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1637888 2011-10-09] () R2 Wave Authentication Manager Service; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [1679872 2012-01-05] (Wave Systems Corp.) R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE [48128 2012-01-18] (Dell Inc.) S3 WvPCR; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe [198144 2012-01-16] (Wave Systems Corp.) ==================== Drivers (Whitelisted) ==================== R3 AnyDVD; C:\Windows\System32\Drivers\AnyDVD.sys [139352 2013-07-31] (SlySoft, Inc.) R3 AnyDVD; C:\Windows\SysWow64\Drivers\AnyDVD.sys [139352 2013-07-31] (SlySoft, Inc.) R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [60248 2013-09-28] (G Data Software AG) R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [130392 2013-09-28] (G Data Software AG) R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [63320 2013-09-28] (G Data Software AG) R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64856 2013-10-27] (G Data Software AG) R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2013-10-05] (G Data Software) R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [65368 2013-09-28] (G Data Software AG) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31136 2013-06-14] (REALiX(tm)) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [284008 2012-09-18] (NVIDIA Corporation) R3 ST_ACCEL; C:\Windows\System32\DRIVERS\ST_ACCEL.sys [68208 2011-11-04] (STMicroelectronics) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-10 10:28 - 2014-01-10 10:29 - 00015912 _____ C:\Users\JULIAN\Downloads\FRST.txt 2014-01-10 10:27 - 2014-01-10 10:27 - 00000000 ____D C:\FRST 2014-01-10 10:26 - 2014-01-10 10:26 - 01932166 _____ (Farbar) C:\Users\JULIAN\Downloads\FRST64.exe 2014-01-10 09:23 - 2014-01-10 10:22 - 00000474 _____ C:\Users\JULIAN\Downloads\defogger_disable.log 2014-01-10 09:23 - 2014-01-10 09:23 - 00000000 _____ C:\Users\JULIAN\defogger_reenable 2014-01-10 09:22 - 2014-01-10 09:22 - 00050477 _____ C:\Users\JULIAN\Downloads\Defogger.exe 2014-01-10 06:54 - 2014-01-10 06:57 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-10 06:54 - 2014-01-10 06:54 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2014-01-10 06:52 - 2014-01-10 06:52 - 02365840 _____ C:\Users\JULIAN\Downloads\SecurityTaskManager_Setup (1).exe 2014-01-10 06:47 - 2014-01-10 06:47 - 00015543 _____ C:\Users\JULIAN\Desktop\hijackthis.log 2014-01-10 04:53 - 2014-01-10 04:53 - 00015543 _____ C:\Users\JULIAN\Downloads\hijackthis.log 2014-01-10 04:52 - 2014-01-10 04:52 - 00388608 _____ (Trend Micro Inc.) C:\Users\JULIAN\Downloads\HiJackThis204.exe 2014-01-08 12:32 - 2014-01-09 00:26 - 00000000 ____D C:\Users\JULIAN\Desktop\GeBeP 2014-01-02 06:19 - 2014-01-02 06:19 - 00002735 _____ C:\Users\JULIAN\Desktop\01 Dienstplan Januar 2014_Grayson_Music 20122014 - Verknüpfung.lnk 2013-12-31 12:24 - 2014-01-08 12:25 - 00016230 _____ C:\Users\JULIAN\Desktop\FOTOAPPARAT.xlsx 2013-12-28 15:33 - 2014-01-01 00:09 - 00000000 ____D C:\ProgramData\PMS 2013-12-28 15:29 - 2013-12-28 15:30 - 00000000 ____D C:\Users\JULIAN\Downloads\pms-1.90.1-setup-full 2013-12-28 15:26 - 2013-12-28 15:27 - 107506905 _____ C:\Users\JULIAN\Downloads\pms-1.90.1-setup-full.zip 2013-12-28 05:01 - 2013-12-28 05:01 - 00065979 _____ C:\Users\JULIAN\Downloads\gsmmap-1.01.apk 2013-12-27 05:04 - 2013-12-27 05:04 - 00000041 _____ C:\Users\JULIAN\AppData\Roaming\mbam.context.scan 2013-12-22 03:05 - 2013-12-26 09:54 - 00000000 ____D C:\Users\JULIAN\Desktop\Karten 2013-12-19 20:15 - 2013-12-19 20:16 - 00000000 ____D C:\Users\JULIAN\Desktop\PDFS 2013-12-18 16:42 - 2013-12-18 16:43 - 00000000 ____D C:\Users\JULIAN\Desktop\NTM 2013-12-16 13:43 - 2013-12-16 13:44 - 00000000 ____D C:\Users\JULIAN\Desktop\SYMIO RECHNUNGEN 2013-12-16 08:36 - 2013-12-16 23:57 - 00000000 ____D C:\Users\JULIAN\Desktop\Crazy Eddy 2013-12-13 03:00 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-13 03:00 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-13 03:00 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-13 03:00 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-13 03:00 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-13 03:00 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-13 03:00 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-13 03:00 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-13 03:00 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-13 03:00 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-13 03:00 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-13 03:00 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-13 03:00 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-13 03:00 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-13 03:00 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-13 03:00 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-13 03:00 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-13 03:00 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-13 03:00 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-13 03:00 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-13 03:00 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-13 03:00 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-13 03:00 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-13 03:00 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-13 03:00 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-13 03:00 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-13 03:00 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-13 03:00 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-13 03:00 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-13 03:00 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-13 03:00 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2013-12-11 03:09 - 2013-10-14 18:00 - 00028368 _____ (Microsoft Corporation) C:\Windows\system32\IEUDINIT.EXE 2013-12-11 03:04 - 2013-12-11 03:04 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-11 03:04 - 2013-12-11 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-11 03:04 - 2013-12-11 03:04 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-11 03:04 - 2013-12-11 03:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-11 03:04 - 2013-12-11 03:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-11 03:04 - 2013-12-11 03:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-11 03:04 - 2013-12-11 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-11 03:03 - 2013-12-11 03:03 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-12-11 03:03 - 2013-12-11 03:03 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-12-11 03:03 - 2013-12-11 03:03 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-12-11 03:03 - 2013-12-11 03:03 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-12-11 03:03 - 2013-12-11 03:03 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-12-11 03:03 - 2013-12-11 03:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-12-11 03:02 - 2013-12-11 03:02 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-12-11 03:02 - 2013-12-11 03:02 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-12-11 03:02 - 2013-12-11 03:02 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-12-11 03:02 - 2013-12-11 03:02 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-12-11 03:02 - 2013-12-11 03:02 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll 2013-12-11 03:01 - 2013-12-11 03:09 - 00012105 _____ C:\Windows\IE11_main.log ==================== One Month Modified Files and Folders ======= 2014-01-10 10:29 - 2014-01-10 10:28 - 00015912 _____ C:\Users\JULIAN\Downloads\FRST.txt 2014-01-10 10:27 - 2014-01-10 10:27 - 00000000 ____D C:\FRST 2014-01-10 10:26 - 2014-01-10 10:26 - 01932166 _____ (Farbar) C:\Users\JULIAN\Downloads\FRST64.exe 2014-01-10 10:22 - 2014-01-10 09:23 - 00000474 _____ C:\Users\JULIAN\Downloads\defogger_disable.log 2014-01-10 10:17 - 2013-06-12 09:46 - 00000000 ____D C:\Users\JULIAN\Documents\Outlook-Dateien 2014-01-10 10:15 - 2013-10-03 02:33 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-10 09:23 - 2014-01-10 09:23 - 00000000 _____ C:\Users\JULIAN\defogger_reenable 2014-01-10 09:23 - 2012-12-10 15:43 - 00000000 ____D C:\Users\JULIAN 2014-01-10 09:22 - 2014-01-10 09:22 - 00050477 _____ C:\Users\JULIAN\Downloads\Defogger.exe 2014-01-10 09:20 - 2012-12-02 19:53 - 01767078 _____ C:\Windows\WindowsUpdate.log 2014-01-10 06:57 - 2014-01-10 06:54 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-10 06:54 - 2014-01-10 06:54 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2014-01-10 06:52 - 2014-01-10 06:52 - 02365840 _____ C:\Users\JULIAN\Downloads\SecurityTaskManager_Setup (1).exe 2014-01-10 06:51 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-10 06:51 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-10 06:47 - 2014-01-10 06:47 - 00015543 _____ C:\Users\JULIAN\Desktop\hijackthis.log 2014-01-10 06:44 - 2013-10-03 02:33 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-10 06:44 - 2012-12-02 20:09 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-10 06:44 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-10 06:44 - 2009-07-14 05:51 - 00011706 _____ C:\Windows\setupact.log 2014-01-10 04:53 - 2014-01-10 04:53 - 00015543 _____ C:\Users\JULIAN\Downloads\hijackthis.log 2014-01-10 04:53 - 2012-12-10 15:43 - 00000000 ____D C:\Users\JULIAN\AppData\Local\VirtualStore 2014-01-10 04:52 - 2014-01-10 04:52 - 00388608 _____ (Trend Micro Inc.) C:\Users\JULIAN\Downloads\HiJackThis204.exe 2014-01-09 00:26 - 2014-01-08 12:32 - 00000000 ____D C:\Users\JULIAN\Desktop\GeBeP 2014-01-08 12:25 - 2013-12-31 12:24 - 00016230 _____ C:\Users\JULIAN\Desktop\FOTOAPPARAT.xlsx 2014-01-08 03:59 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2014-01-08 02:18 - 2013-10-03 02:33 - 00002177 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-08 00:14 - 2013-06-14 19:51 - 00000000 ____D C:\Users\JULIAN\AppData\Roaming\Nitro PDF 2014-01-04 20:51 - 2013-08-28 19:37 - 00000000 ____D C:\Users\JULIAN\Documents\Calibre-Bibliothek 2014-01-02 06:19 - 2014-01-02 06:19 - 00002735 _____ C:\Users\JULIAN\Desktop\01 Dienstplan Januar 2014_Grayson_Music 20122014 - Verknüpfung.lnk 2014-01-01 05:22 - 2013-06-14 19:57 - 00000000 ____D C:\Users\JULIAN\Desktop\yyy 2014-01-01 00:09 - 2013-12-28 15:33 - 00000000 ____D C:\ProgramData\PMS 2013-12-28 15:30 - 2013-12-28 15:29 - 00000000 ____D C:\Users\JULIAN\Downloads\pms-1.90.1-setup-full 2013-12-28 15:27 - 2013-12-28 15:26 - 107506905 _____ C:\Users\JULIAN\Downloads\pms-1.90.1-setup-full.zip 2013-12-28 05:01 - 2013-12-28 05:01 - 00065979 _____ C:\Users\JULIAN\Downloads\gsmmap-1.01.apk 2013-12-27 05:04 - 2013-12-27 05:04 - 00000041 _____ C:\Users\JULIAN\AppData\Roaming\mbam.context.scan 2013-12-26 09:54 - 2013-12-22 03:05 - 00000000 ____D C:\Users\JULIAN\Desktop\Karten 2013-12-24 19:45 - 2013-06-12 11:05 - 00000000 ____D C:\Users\JULIAN\AppData\Roaming\vlc 2013-12-22 11:23 - 2013-12-02 10:56 - 00000000 ____D C:\Users\JULIAN\Desktop\AMAZON Bestellungn 2013-12-22 05:11 - 2013-06-12 08:44 - 00000000 ____D C:\Users\JULIAN\AppData\Roaming\Adobe 2013-12-20 06:10 - 2013-06-13 03:20 - 00000000 ____D C:\Users\JULIAN\Desktop\BILDER 2013-12-19 20:16 - 2013-12-19 20:15 - 00000000 ____D C:\Users\JULIAN\Desktop\PDFS 2013-12-18 16:43 - 2013-12-18 16:42 - 00000000 ____D C:\Users\JULIAN\Desktop\NTM 2013-12-16 23:57 - 2013-12-16 08:36 - 00000000 ____D C:\Users\JULIAN\Desktop\Crazy Eddy 2013-12-16 19:35 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-16 13:44 - 2013-12-16 13:43 - 00000000 ____D C:\Users\JULIAN\Desktop\SYMIO RECHNUNGEN 2013-12-15 03:02 - 2013-08-14 22:27 - 00000000 ____D C:\Windows\system32\MRT 2013-12-15 03:00 - 2013-06-15 03:41 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-13 20:25 - 2010-11-21 07:50 - 00700418 _____ C:\Windows\system32\perfh007.dat 2013-12-13 20:25 - 2010-11-21 07:50 - 00149182 _____ C:\Windows\system32\perfc007.dat 2013-12-13 20:25 - 2009-07-14 06:13 - 01621308 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-11 19:47 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\rescache 2013-12-11 08:29 - 2012-12-10 15:44 - 00001423 _____ C:\Users\JULIAN\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk 2013-12-11 08:28 - 2009-07-14 05:45 - 00428848 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-11 06:26 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\PolicyDefinitions 2013-12-11 03:09 - 2013-12-11 03:01 - 00012105 _____ C:\Windows\IE11_main.log 2013-12-11 03:04 - 2013-12-11 03:04 - 01228800 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00942592 _____ (Microsoft Corporation) C:\Windows\system32\jsIntl.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00774144 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00645120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsIntl.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dat 2013-12-11 03:04 - 2013-12-11 03:04 - 00616104 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dat 2013-12-11 03:04 - 2013-12-11 03:04 - 00610304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00523776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00413696 _____ (Microsoft Corporation) C:\Windows\system32\html.iec 2013-12-11 03:04 - 2013-12-11 03:04 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00337408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec 2013-12-11 03:04 - 2013-12-11 03:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00263376 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\msls31.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00244736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00243200 _____ (Microsoft Corporation) C:\Windows\system32\webcheck.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00238288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\url.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00235008 _____ (Microsoft Corporation) C:\Windows\system32\elshyph.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00233472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00208384 _____ (Microsoft Corporation) C:\Windows\SysWOW64\webcheck.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00194048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\elshyph.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00182272 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msls31.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00167424 _____ (Microsoft Corporation) C:\Windows\system32\iexpress.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00151552 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iexpress.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00147968 _____ (Microsoft Corporation) C:\Windows\system32\occache.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00143872 _____ (Microsoft Corporation) C:\Windows\system32\wextract.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wextract.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00135680 _____ (Microsoft Corporation) C:\Windows\system32\iepeers.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00131072 _____ (Microsoft Corporation) C:\Windows\system32\IEAdvpack.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00127488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\occache.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00116736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iepeers.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\IEAdvpack.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00105984 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00101376 _____ (Microsoft Corporation) C:\Windows\system32\inseng.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00090112 _____ (Microsoft Corporation) C:\Windows\system32\SetIEInstalledDate.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00086016 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00083456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inseng.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00081408 _____ (Microsoft Corporation) C:\Windows\system32\icardie.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\tdc.ocx 2013-12-11 03:04 - 2013-12-11 03:04 - 00074240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SetIEInstalledDate.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00069120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\icardie.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdc.ocx 2013-12-11 03:04 - 2013-12-11 03:04 - 00062464 _____ (Microsoft Corporation) C:\Windows\system32\pngfilt.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00056832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\pngfilt.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00052224 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmler.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\mshtmler.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\imgutil.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00040448 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00036352 _____ (Microsoft Corporation) C:\Windows\SysWOW64\imgutil.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00034816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00030208 _____ (Microsoft Corporation) C:\Windows\system32\licmgr10.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00024576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\licmgr10.dll 2013-12-11 03:04 - 2013-12-11 03:04 - 00013824 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe 2013-12-11 03:04 - 2013-12-11 03:04 - 00012800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe 2013-12-11 03:03 - 2013-12-11 03:03 - 05549504 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2013-12-11 03:03 - 2013-12-11 03:03 - 03969472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2013-12-11 03:03 - 2013-12-11 03:03 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2013-12-11 03:03 - 2013-12-11 03:03 - 01732032 _____ (Microsoft Corporation) C:\Windows\system32\ntdll.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 01292192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntdll.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00878080 _____ (Microsoft Corporation) C:\Windows\system32\advapi32.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00859648 _____ (Microsoft Corporation) C:\Windows\system32\tdh.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00640512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\advapi32.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00619520 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tdh.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2013-12-11 03:03 - 2013-12-11 03:03 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2013-12-11 03:03 - 2013-12-11 03:03 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2013-12-11 03:03 - 2013-12-11 03:03 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2013-12-11 03:02 - 2013-12-11 03:02 - 01903552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tcpip.sys 2013-12-11 03:02 - 2013-12-11 03:02 - 01887232 _____ (Microsoft Corporation) C:\Windows\system32\d3d11.dll 2013-12-11 03:02 - 2013-12-11 03:02 - 01505280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll 2013-12-11 03:02 - 2013-12-11 03:02 - 00327168 _____ (Microsoft Corporation) C:\Windows\system32\mswsock.dll 2013-12-11 03:02 - 2013-12-11 03:02 - 00231424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mswsock.dll Some content of TEMP: ==================== C:\Users\JULIAN\AppData\Local\Temp\APNSetup.exe C:\Users\JULIAN\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\JULIAN\AppData\Local\Temp\jna1353708428434231273.dll C:\Users\JULIAN\AppData\Local\Temp\jna1594581219237481159.dll C:\Users\JULIAN\AppData\Local\Temp\jna2256181832525081025.dll C:\Users\JULIAN\AppData\Local\Temp\jna386435848413563746.dll C:\Users\JULIAN\AppData\Local\Temp\jna6307513402642041655.dll C:\Users\JULIAN\AppData\Local\Temp\jna7490730483538363106.dll C:\Users\JULIAN\AppData\Local\Temp\jna8002310201460997212.dll C:\Users\JULIAN\AppData\Local\Temp\MSNA43F.exe C:\Users\JULIAN\AppData\Local\Temp\ose00000.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2013-12-30 00:48 ==================== End Of Log ============================ --- --- --- /CODE] Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-01-2014 Ran by JULIAN at 2014-01-10 10:31:04 Running from C:\Users\JULIAN\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: G Data InternetSecurity 2014 (Enabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0} AS: G Data InternetSecurity 2014 (Enabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} FW: G Data Personal Firewall (Enabled) {6C670636-4D2B-B121-ACA7-9DAF938FCB8B} ==================== Installed Programs ====================== 64 Bit HP CIO Components Installer (Version: 6.2.2 - Hewlett-Packard) Hidden 7500_7600_7700_Help1 (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden 7-Zip 9.20 (x32 Version: - ) Acronis*True*Image*Home 2012 (x32 Version: 15.0.7133 - Acronis) Hidden Adobe AIR (x32 Version: 3.7.0.1530 - Adobe Systems Incorporated) Adobe AIR (x32 Version: 3.7.0.1530 - Adobe Systems Incorporated) Hidden Adobe Flash Player 11 ActiveX (x32 Version: 11.8.800.94 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.8.800.168 - Adobe Systems Incorporated) Adobe Photoshop Elements 8.0 (x32 Version: 8.0 - Adobe Systems Incorporated) Adobe Photoshop Elements 8.0 (x32 Version: 8.0 - Adobe Systems Incorporated) Hidden AnyDVD (x32 Version: 7.3.6.0 - SlySoft) Ashampoo Burning Studio 6 FREE v.6.83 (x32 Version: 6.8.3 - Ashampoo GmbH & Co. KG) BioAPI Framework (Version: 1.0.2 - Dell Inc.) Hidden bpd_scan_Carrier (x32 Version: 3.00.0000 - Hewlett-Packard) Hidden BPDSoftware (x32 Version: 140.0.000.000 - Hewlett-Packard) Hidden BPDSoftware_Ini (x32 Version: 1.00.0000 - Hewlett-Packard) Hidden BufferChm (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden calibre 64bit (Version: 1.3.0 - Kovid Goyal) Cisco EAP-FAST Module (x32 Version: 2.2.14 - Cisco Systems, Inc.) Hidden Cisco LEAP Module (x32 Version: 1.0.19 - Cisco Systems, Inc.) Hidden Cisco PEAP Module (x32 Version: 1.1.6 - Cisco Systems, Inc.) Hidden Custom (Version: 01.00.00.000 - Wave Systems Corp.) Hidden D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Dell Client System Update (x32 Version: 1.2.3 - Dell Inc.) Dell Data Protection | Access (Version: 2.2.00003.009 - Dell Inc.) Dell Edoc Viewer (Version: 1.0.0 - Dell Inc) Dell Feature Enhancement Pack (Version: 2.2.1 - Dell) Dell Touchpad (Version: 8.1200.101.116 - ALPS ELECTRIC CO., LTD.) Dell Webcam Central (x32 Version: 1.40.54 - Creative Technology Ltd) DellAccess (Version: 01.01.00.104 - Wave Systems Corp.) Hidden Destinations (x32 Version: 130.0.0.0 - Hewlett-Packard) Hidden DeviceDiscovery (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden DocProc (x32 Version: 140.0.100.000 - Hewlett-Packard) Hidden DW WLAN Card Utility (Version: 5.100.82.124 - Dell Inc.) EMBASSY Client Core (Version: 01.01.00.036 - Wave Systems Corp.) Hidden Fax (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden Free Studio version 2013 (x32 Version: 6.0.0.128 - DVDVideoSoft Ltd.) Fritz 12 (x32 Version: 12.0.0 - ChessBase) Fritz 12 (x32 Version: 12.0.0 - ChessBase) Hidden G Data InternetSecurity 2014 (x32 Version: 24.0.3.4 - G Data Software AG) Gemalto (Version: 01.64.01.0010 - Wave Systems Corp) Hidden Google Chrome (x32 Version: 32.0.1700.72 - Google Inc.) Google Update Helper (x32 Version: 1.3.22.3 - Google Inc.) Hidden GPBaseService2 (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden HP Customer Participation Program 14.0 (Version: 14.0 - HP) HP Imaging Device Functions 14.0 (Version: 14.0 - HP) HP OfficeJet L7300/L7500/7600/7700 (Version: 14.0 - HP) HP Smart Web Printing 4.60 (Version: 4.60 - HP) HP Solution Center 14.0 (Version: 14.0 - HP) HP Update (x32 Version: 5.002.002.002 - Hewlett-Packard) HPProductAssistant (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden HPSSupply (x32 Version: 140.0.212.000 - Hewlett-Packard) Hidden HWiNFO64 Version 4.18 (Version: 4.18 - Martin Malík - REALiX) IDT Audio (x32 Version: 1.0.6402.0 - IDT) Intel(R) Control Center (x32 Version: 1.2.1.1008 - Intel Corporation) Intel(R) Management Engine Components (x32 Version: 8.0.3.1427 - Intel Corporation) Intel(R) Network Connections 17.2.154.0 (Version: 17.2.154.0 - Intel) Intel(R) Network Connections 17.2.154.0 (Version: 17.2.154.0 - Intel) Hidden Intel(R) Processor Graphics (x32 Version: 8.15.10.2639 - Intel Corporation) Intel(R) Rapid Storage Technology (x32 Version: 11.2.0.1006 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.4.220 - Intel Corporation) Intel® Trusted Connect Service Client (Version: 1.23.605.1 - Intel Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden L7500 (x32 Version: 140.0.000.000 - Hewlett-Packard) Hidden Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300 - Malwarebytes Corporation) MarketResearch (x32 Version: 140.0.214.000 - Hewlett-Packard) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Office 64-bit Components 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Professional 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Proof (English) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Single Image 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (x32 Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (x32 Version: 4.0.50401.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219 - Microsoft Corporation) MPM (x32 Version: 1.00.0000 - Hewlett-Packard) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSXML 4.0 SP2 (KB954430) (x32 Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (x32 Version: 4.20.9876.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0 - Microsoft Corporation) MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0 - Microsoft Corporation) MyPhoneExplorer (x32 Version: 1.8.4 - F.J. Wechselberger) Network64 (Version: 140.0.215.000 - Hewlett-Packard) Hidden Nitro Reader 2 (Version: 2.3.1.2 - Nitro PDF Software) NTRU TCG Software Stack (Version: 2.1.37 - Security Innovation, Inc.) Hidden NVIDIA 3D Vision Treiber 306.68 (Version: 306.68 - NVIDIA Corporation) NVIDIA Grafiktreiber 306.68 (Version: 306.68 - NVIDIA Corporation) NVIDIA HD-Audiotreiber 1.3.18.0 (Version: 1.3.18.0 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.85.551 - NVIDIA Corporation) Hidden NVIDIA nView 136.53 (Version: 136.53 - NVIDIA Corporation) NVIDIA Optimus 1.10.8 (Version: 1.10.8 - NVIDIA Corporation) Hidden NVIDIA PhysX (x32 Version: 9.12.0613 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.12.0613 (Version: 9.12.0613 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (x32 Version: 7.17.13.0668 - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 306.68 (Version: 306.68 - NVIDIA Corporation) Hidden NVIDIA Update Components (Version: 1.10.8 - NVIDIA Corporation) Hidden O2Micro Flash Memory Card Windows Driver (x32 Version: 3.0.07.38 - O2Micro International LTD.) O2Micro Flash Memory Card Windows Driver (x32 Version: 3.0.07.38 - O2Micro International LTD.) Hidden OCR Software by I.R.I.S. 14.0 (Version: 14.0 - HP) PC-CCID (Version: 2.0.0 - Gemalto) Hidden Preboot Manager (Version: 03.03.00.090 - Wave Systems Corp.) Hidden PremierColor (x32 Version: 2.00.053 - Portrait Displays, Inc.) Private Information Manager (Version: 07.01.00.030 - Wave Systems Corp.) Hidden ProductContext (x32 Version: 140.0.000.000 - Hewlett-Packard) Hidden Samsung Kies (x32 Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.) Samsung Kies (x32 Version: 2.5.3.13052_10 - Samsung Electronics Co., Ltd.) Hidden SAMSUNG USB Driver for Mobile Phones (Version: 1.5.24.0 - SAMSUNG Electronics Co., Ltd.) Scan (x32 Version: 140.0.167.000 - Hewlett-Packard) Hidden SDK (x32 Version: 2.31.009 - Portrait Displays, Inc.) Hidden Security Task Manager 1.8g (x32 Version: 1.8g - Neuber Software) Shop for HP Supplies (Version: 14.0 - HP) SmartWebPrinting (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden SolutionCenter (x32 Version: 140.0.214.000 - Hewlett-Packard) Hidden SPBA 5.9 (Version: 5.9.4.6901 - UPEK Inc.) Hidden Spybot - Search & Destroy (x32 Version: 2.1.19 - Safer-Networking Ltd.) ST Microelectronics 3 Axis Digital Accelerometer Solution (x32 Version: 4.10.0022 - ST Microelectronics) Status (x32 Version: 140.0.256.000 - Hewlett-Packard) Hidden Toolbox (x32 Version: 140.0.428.000 - Hewlett-Packard) Hidden toolkit32for64bit (x32 Version: 7.67.47.0000 - Wave Systems Corp) Hidden TrayApp (x32 Version: 140.0.213.000 - Hewlett-Packard) Hidden Trusted Drive Manager (Version: 4.5.0.136 - Wave Systems Corp.) Hidden Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1 - Microsoft Corporation) Upek Touchchip Fingerprint Reader (Version: 1.2.004 - Dell Inc.) Hidden VLC media player 2.0.7 (x32 Version: 2.0.7 - VideoLAN) Wave Crypto Runtime 2.0.7.0 x86 (x32 Version: 02.00.07.0000 - Wave Systems Corp) Hidden Wave Infrastructure Installer (Version: 07.67.60.0020 - Wave Systems Corp) Hidden Wave Support Software Installer (Version: 05.13.00.051 - Wave Systems Corp) Hidden WebReg (x32 Version: 140.0.213.017 - Hewlett-Packard) Hidden Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows-Treiberpaket - Dell Inc. PBADRV System (09/11/2009 1.0.1.6) (Version: 09/11/2009 1.0.1.6 - Dell Inc.) ==================== Restore Points ========================= 20-12-2013 10:58:39 Windows Update 24-12-2013 18:23:38 Windows Update 31-12-2013 12:16:46 Windows Update 03-01-2014 23:46:29 Windows Update 08-01-2014 00:08:36 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {32746D80-ED65-45F7-BF4E-3738FF2F3A56} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-03] (Google Inc.) Task: {6BABEF0E-9B4C-4DEF-BCA1-45F0A699524D} - System32\Tasks\Launch HTC Sync Loader => C:\Program Files (x86)\HTC\HTC Sync 3.0\htcUPCTLoader.exe Task: {CAF6A762-A3BE-4259-87C6-6BAC81CAEE8F} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-10-03] (Google Inc.) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Faulty Device Manager Devices ============= Name: Officejet Pro L7500 Description: Officejet Pro L7500 Class Guid: {6bdd1fc6-810f-11d0-bec7-08002be2092f} Manufacturer: HP Service: StillCam Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Officejet Pro L7500 Description: Officejet Pro L7500 Class Guid: {4d36e971-e325-11ce-bfc1-08002be10318} Manufacturer: HP Service: Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/10/2014 06:44:47 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/10/2014 04:47:47 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/09/2014 05:56:15 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/09/2014 07:37:36 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/08/2014 11:44:56 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/08/2014 02:48:48 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/08/2014 07:36:52 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/07/2014 11:30:32 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/07/2014 08:28:23 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/07/2014 07:26:26 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (01/10/2014 06:44:19 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NTRU TSS v1.2.1.37 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%0 Error: (01/10/2014 04:47:24 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NTRU TSS v1.2.1.37 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%0 Error: (01/09/2014 10:05:50 PM) (Source: Serial) (User: ) Description: Bei der Überprüfung, ob "\Device\Serial0" ein serieller Anschluss ist, war der Inhalt des Divisor-Latch-Registers mit dem Interruptfreigabe- und dem Empfangsregister identisch. Das Gerät wurde nicht als serieller Anschluss erkannt und wird gelöscht. Error: (01/09/2014 06:01:34 PM) (Source: Serial) (User: ) Description: Bei der Überprüfung, ob "\Device\Serial0" ein serieller Anschluss ist, war der Inhalt des Divisor-Latch-Registers mit dem Interruptfreigabe- und dem Empfangsregister identisch. Das Gerät wurde nicht als serieller Anschluss erkannt und wird gelöscht. Error: (01/09/2014 05:56:10 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NTRU TSS v1.2.1.37 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%0 Error: (01/09/2014 07:36:57 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NTRU TSS v1.2.1.37 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%0 Error: (01/09/2014 04:39:49 AM) (Source: Serial) (User: ) Description: Bei der Überprüfung, ob "\Device\Serial0" ein serieller Anschluss ist, war der Inhalt des Divisor-Latch-Registers mit dem Interruptfreigabe- und dem Empfangsregister identisch. Das Gerät wurde nicht als serieller Anschluss erkannt und wird gelöscht. Error: (01/08/2014 11:44:41 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "NTRU TSS v1.2.1.37 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%0 Error: (01/08/2014 06:53:02 PM) (Source: Serial) (User: ) Description: Bei der Überprüfung, ob "\Device\Serial0" ein serieller Anschluss ist, war der Inhalt des Divisor-Latch-Registers mit dem Interruptfreigabe- und dem Empfangsregister identisch. Das Gerät wurde nicht als serieller Anschluss erkannt und wird gelöscht. Error: (01/08/2014 04:42:31 PM) (Source: Serial) (User: ) Description: Bei der Überprüfung, ob "\Device\Serial0" ein serieller Anschluss ist, war der Inhalt des Divisor-Latch-Registers mit dem Interruptfreigabe- und dem Empfangsregister identisch. Das Gerät wurde nicht als serieller Anschluss erkannt und wird gelöscht. Microsoft Office Sessions: ========================= Error: (01/10/2014 06:44:47 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/10/2014 04:47:47 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/09/2014 05:56:15 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/09/2014 07:37:36 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/08/2014 11:44:56 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/08/2014 02:48:48 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/08/2014 07:36:52 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/07/2014 11:30:32 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/07/2014 08:28:23 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/07/2014 07:26:26 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 25% Total physical RAM: 16257.77 MB Available physical RAM: 12190.04 MB Total Pagefile: 32513.71 MB Available Pagefile: 28162.82 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:464.98 GB) (Free:240.77 GB) NTFS Drive d: () (Fixed) (Total:465.76 GB) (Free:102.68 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 466 GB) (Disk ID: BE735E84) Partition 1: (Not Active) - (Size=39 MB) - (Type=DE) Partition 2: (Active) - (Size=752 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=465 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 466 GB) (Disk ID: 2F0BB16B) Partition 1: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Grüße von Boardeline |
10.01.2014, 13:25 | #4 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer Windows und Office Professional seh ich da, ist das ein gewerblich genutztes System?
__________________ Logfiles bitte immer in CODE-Tags posten |
10.01.2014, 13:36 | #5 |
| Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer Hallo cosinus, nein, mein Laptop wird rein privat genutzt. Grüße von boarderlion |
10.01.2014, 13:59 | #6 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer Versteh zwar nicht warum man privat ein MS Office Professional braucht aber naja Malwarebytes Anti-Rootkit (MBAR) Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________ --> Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer |
10.01.2014, 19:12 | #7 |
| Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer cosinus, logfile anbei Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1008 (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 11.0.9600.16476 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 2.691000 GHz Memory total: 17047502848, free: 13288116224 --------------------------------------- Malwarebytes Anti-Rootkit BETA 1.07.0.1008 (c) Malwarebytes Corporation 2011-2012 OS version: 6.1.7601 Windows 7 Service Pack 1 x64 Account is Administrative Internet Explorer version: 11.0.9600.16476 File system is: NTFS Disk drives: C:\ DRIVE_FIXED, D:\ DRIVE_FIXED CPU speed: 2.691000 GHz Memory total: 17047502848, free: 13323563008 Downloaded database version: v2014.01.10.05 Downloaded database version: v2013.12.18.01 ======================================= Initializing... ------------ Kernel report ------------ 01/10/2014 18:34:40 ------------ Loaded modules ----------- \SystemRoot\system32\ntoskrnl.exe \SystemRoot\system32\hal.dll \SystemRoot\system32\kdcom.dll \SystemRoot\system32\mcupdate_GenuineIntel.dll \SystemRoot\system32\PSHED.dll \SystemRoot\system32\CLFS.SYS \SystemRoot\system32\CI.dll \SystemRoot\system32\drivers\Wdf01000.sys \SystemRoot\system32\drivers\WDFLDR.SYS \SystemRoot\system32\drivers\ACPI.sys \SystemRoot\system32\drivers\WMILIB.SYS \SystemRoot\system32\drivers\msisadrv.sys \SystemRoot\system32\drivers\pci.sys \SystemRoot\system32\drivers\vdrvroot.sys \SystemRoot\system32\DRIVERS\iusb3hcs.sys \SystemRoot\system32\DRIVERS\vsflt67.sys \SystemRoot\System32\drivers\partmgr.sys \SystemRoot\system32\DRIVERS\compbatt.sys \SystemRoot\system32\DRIVERS\BATTC.SYS \SystemRoot\system32\drivers\volmgr.sys \SystemRoot\System32\drivers\volmgrx.sys \SystemRoot\System32\drivers\mountmgr.sys \SystemRoot\system32\drivers\iaStor.sys \SystemRoot\system32\drivers\amdxata.sys \SystemRoot\system32\drivers\fltmgr.sys \SystemRoot\system32\drivers\fileinfo.sys \SystemRoot\System32\Drivers\PxHlpa64.sys \SystemRoot\System32\Drivers\Ntfs.sys \SystemRoot\System32\Drivers\msrpc.sys \SystemRoot\System32\Drivers\ksecdd.sys \SystemRoot\System32\Drivers\cng.sys \SystemRoot\System32\drivers\pcw.sys \SystemRoot\System32\Drivers\Fs_Rec.sys \SystemRoot\system32\drivers\ndis.sys \SystemRoot\system32\drivers\NETIO.SYS \SystemRoot\System32\Drivers\ksecpkg.sys \SystemRoot\System32\drivers\tcpip.sys \SystemRoot\System32\drivers\fwpkclnt.sys \SystemRoot\system32\DRIVERS\vididr.sys \SystemRoot\system32\DRIVERS\timntr.sys \SystemRoot\system32\drivers\volsnap.sys \SystemRoot\system32\DRIVERS\stdcfltn.sys \SystemRoot\system32\DRIVERS\tdrpman.sys \SystemRoot\System32\Drivers\spldr.sys \SystemRoot\system32\DRIVERS\snapman.sys \SystemRoot\System32\drivers\rdyboost.sys \SystemRoot\system32\DRIVERS\PBADRV.sys \SystemRoot\system32\DRIVERS\nvpciflt.sys \SystemRoot\System32\Drivers\mup.sys \SystemRoot\System32\drivers\hwpolicy.sys \SystemRoot\system32\drivers\GDBehave.sys \SystemRoot\system32\DRIVERS\fltsrv.sys \SystemRoot\System32\DRIVERS\fvevol.sys \SystemRoot\system32\drivers\disk.sys \SystemRoot\system32\drivers\CLASSPNP.SYS \SystemRoot\system32\DRIVERS\cdrom.sys \??\C:\Windows\system32\drivers\MiniIcpt.sys \??\C:\Windows\system32\drivers\HookCentre.sys \SystemRoot\System32\Drivers\Null.SYS \SystemRoot\System32\Drivers\Beep.SYS \SystemRoot\System32\drivers\vga.sys \SystemRoot\System32\drivers\VIDEOPRT.SYS \SystemRoot\System32\drivers\watchdog.sys \SystemRoot\System32\DRIVERS\RDPCDD.sys \SystemRoot\system32\drivers\rdpencdd.sys \SystemRoot\system32\drivers\rdprefmp.sys \SystemRoot\System32\Drivers\Msfs.SYS \SystemRoot\System32\Drivers\Npfs.SYS \SystemRoot\system32\DRIVERS\tdx.sys \SystemRoot\system32\DRIVERS\TDI.SYS \SystemRoot\system32\drivers\afd.sys \SystemRoot\System32\DRIVERS\netbt.sys \SystemRoot\system32\DRIVERS\wfplwf.sys \SystemRoot\system32\DRIVERS\pacer.sys \SystemRoot\system32\DRIVERS\vwififlt.sys \SystemRoot\system32\DRIVERS\netbios.sys \SystemRoot\system32\DRIVERS\wanarp.sys \SystemRoot\system32\DRIVERS\termdd.sys \SystemRoot\system32\DRIVERS\rdbss.sys \SystemRoot\system32\DRIVERS\nvkflt.sys \SystemRoot\System32\drivers\dxgkrnl.sys \SystemRoot\System32\drivers\dxgmms1.sys \SystemRoot\system32\drivers\nsiproxy.sys \SystemRoot\system32\DRIVERS\mssmbios.sys \??\C:\Windows\system32\drivers\HWiNFO64A.SYS \??\C:\Windows\system32\drivers\GRD.sys \SystemRoot\system32\drivers\gdwfpcd64.sys \SystemRoot\System32\drivers\discache.sys \SystemRoot\system32\drivers\csc.sys \SystemRoot\System32\Drivers\dfsc.sys \SystemRoot\system32\DRIVERS\blbdrive.sys \SystemRoot\system32\DRIVERS\tunnel.sys \SystemRoot\system32\DRIVERS\nvlddmkm.sys \SystemRoot\system32\DRIVERS\igdkmd64.sys \SystemRoot\system32\DRIVERS\iusb3xhc.sys \SystemRoot\system32\DRIVERS\USBD.SYS \SystemRoot\system32\DRIVERS\HECIx64.sys \SystemRoot\system32\DRIVERS\e1c62x64.sys \SystemRoot\system32\drivers\usbehci.sys \SystemRoot\system32\drivers\USBPORT.SYS \SystemRoot\system32\DRIVERS\HDAudBus.sys \SystemRoot\system32\DRIVERS\bcmwl664.sys \SystemRoot\system32\DRIVERS\vwifibus.sys \SystemRoot\system32\DRIVERS\1394ohci.sys \SystemRoot\system32\DRIVERS\SCSIPORT.SYS \SystemRoot\system32\DRIVERS\i8042prt.sys \SystemRoot\system32\DRIVERS\kbdclass.sys \SystemRoot\system32\DRIVERS\Apfiltr.sys \SystemRoot\system32\DRIVERS\mouclass.sys \SystemRoot\system32\DRIVERS\parport.sys \SystemRoot\system32\DRIVERS\ST_ACCEL.sys \SystemRoot\system32\DRIVERS\intelppm.sys \SystemRoot\system32\DRIVERS\wmiacpi.sys \SystemRoot\system32\DRIVERS\CmBatt.sys \SystemRoot\system32\DRIVERS\CompositeBus.sys \SystemRoot\system32\DRIVERS\AgileVpn.sys \SystemRoot\system32\DRIVERS\rasl2tp.sys \SystemRoot\system32\DRIVERS\ndistapi.sys \SystemRoot\system32\DRIVERS\ndiswan.sys \SystemRoot\system32\DRIVERS\raspppoe.sys \SystemRoot\system32\DRIVERS\raspptp.sys \SystemRoot\system32\DRIVERS\rassstp.sys \SystemRoot\system32\DRIVERS\rdpbus.sys \SystemRoot\system32\DRIVERS\swenum.sys \SystemRoot\system32\DRIVERS\ks.sys \SystemRoot\system32\DRIVERS\umbus.sys \SystemRoot\system32\DRIVERS\usbhub.sys \SystemRoot\System32\Drivers\NDProxy.SYS \SystemRoot\system32\DRIVERS\iusb3hub.sys \SystemRoot\system32\DRIVERS\stwrt64.sys \SystemRoot\system32\DRIVERS\portcls.sys \SystemRoot\system32\DRIVERS\drmk.sys \SystemRoot\system32\drivers\ksthunk.sys \SystemRoot\System32\win32k.sys \SystemRoot\System32\drivers\Dxapi.sys \SystemRoot\System32\Drivers\crashdmp.sys \SystemRoot\System32\Drivers\dump_iaStor.sys \SystemRoot\System32\Drivers\dump_dumpfve.sys \SystemRoot\system32\DRIVERS\monitor.sys \SystemRoot\system32\DRIVERS\usbccgp.sys \SystemRoot\System32\Drivers\usbvideo.sys \SystemRoot\system32\DRIVERS\CtClsFlt.sys \SystemRoot\system32\drivers\hidusb.sys \SystemRoot\system32\drivers\HIDCLASS.SYS \SystemRoot\system32\drivers\HIDPARSE.SYS \SystemRoot\system32\DRIVERS\kbdhid.sys \SystemRoot\system32\DRIVERS\mouhid.sys \SystemRoot\System32\TSDDD.dll \SystemRoot\System32\cdd.dll \SystemRoot\system32\drivers\luafv.sys \SystemRoot\system32\drivers\WudfPf.sys \SystemRoot\system32\DRIVERS\lltdio.sys \SystemRoot\system32\DRIVERS\nwifi.sys \SystemRoot\system32\DRIVERS\ndisuio.sys \SystemRoot\system32\DRIVERS\rspndr.sys \SystemRoot\system32\drivers\HTTP.sys \SystemRoot\system32\DRIVERS\bowser.sys \SystemRoot\System32\drivers\mpsdrv.sys \SystemRoot\system32\DRIVERS\mrxsmb.sys \SystemRoot\system32\DRIVERS\mrxsmb10.sys \SystemRoot\system32\DRIVERS\mrxsmb20.sys \SystemRoot\System32\Drivers\fastfat.SYS \SystemRoot\system32\DRIVERS\afcdp.sys \SystemRoot\system32\drivers\peauth.sys \SystemRoot\system32\DRIVERS\o2sdjw7x64.sys \SystemRoot\System32\Drivers\secdrv.SYS \SystemRoot\System32\DRIVERS\srvnet.sys \SystemRoot\System32\drivers\tcpipreg.sys \SystemRoot\System32\DRIVERS\srv2.sys \SystemRoot\System32\DRIVERS\srv.sys \SystemRoot\system32\drivers\BCM42RLY.sys \??\C:\Windows\system32\drivers\PktIcpt.sys \SystemRoot\system32\DRIVERS\asyncmac.sys \SystemRoot\system32\DRIVERS\umpass.sys \??\C:\Windows\system32\drivers\mbamchameleon.sys \??\C:\Windows\system32\drivers\MBAMSwissArmy.sys \Windows\System32\ntdll.dll \Windows\System32\smss.exe \Windows\System32\apisetschema.dll \Windows\System32\autochk.exe \Windows\System32\urlmon.dll \Windows\System32\nsi.dll \Windows\System32\Wldap32.dll \Windows\System32\imagehlp.dll \Windows\System32\advapi32.dll \Windows\System32\comdlg32.dll \Windows\System32\msvcrt.dll \Windows\System32\iertutil.dll \Windows\System32\usp10.dll \Windows\System32\setupapi.dll \Windows\System32\gdi32.dll \Windows\System32\shlwapi.dll \Windows\System32\normaliz.dll \Windows\System32\ole32.dll \Windows\System32\sechost.dll \Windows\System32\kernel32.dll \Windows\System32\user32.dll \Windows\System32\wininet.dll \Windows\System32\difxapi.dll \Windows\System32\lpk.dll \Windows\System32\imm32.dll \Windows\System32\clbcatq.dll \Windows\System32\psapi.dll \Windows\System32\rpcrt4.dll \Windows\System32\oleaut32.dll \Windows\System32\shell32.dll \Windows\System32\msctf.dll \Windows\System32\ws2_32.dll \Windows\System32\KernelBase.dll \Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll \Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll \Windows\System32\cfgmgr32.dll \Windows\System32\comctl32.dll \Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll \Windows\System32\wintrust.dll \Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll \Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll \Windows\System32\crypt32.dll \Windows\System32\devobj.dll \Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll \Windows\System32\msasn1.dll \Windows\SysWOW64\normaliz.dll ----------- End ----------- Done! <<<1>>> Upper Device Name: \Device\Harddisk1\DR1 Upper Device Object: 0xfffffa800fe53060 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IAAStorageDevice-2\ Lower Device Object: 0xfffffa800eaf4050 Lower Device Driver Name: \Driver\iaStor\ <<<1>>> Upper Device Name: \Device\Harddisk0\DR0 Upper Device Object: 0xfffffa800fe52060 Upper Device Driver Name: \Driver\Disk\ Lower Device Name: \Device\Ide\IAAStorageDevice-1\ Lower Device Object: 0xfffffa800eaf0050 Lower Device Driver Name: \Driver\iaStor\ <<<2>>> Physical Sector Size: 512 Drive: 0, DevicePointer: 0xfffffa800fe52060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa800fe52b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa800fe52060, DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa800fc0ee10, DeviceName: Unknown, DriverName: \Driver\vidsflt67\ DevicePointer: 0xfffffa800fc0dcb0, DeviceName: Unknown, DriverName: \Driver\stdcfltn\ DevicePointer: 0xfffffa800eae4040, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xfffffa800eaf0050, DeviceName: \Device\Ide\IAAStorageDevice-1\, DriverName: \Driver\iaStor\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk0\DR0\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Scanning drivers directory: C:\WINDOWS\SYSTEM32\drivers... <<<2>>> <<<3>>> Volume: C: File system type: NTFS SectorSize = 512, ClusterSize = 4096, MFTRecordSize = 1024, MFTIndexSize = 4096 bytes Done! Drive 0 Scanning MBR on drive 0... Inspecting partition table: MBR Signature: 55AA Disk Signature: BE735E84 Partition information: Partition 0 type is Other (0xde) Partition is NOT ACTIVE. Partition starts at LBA: 63 Numsec = 80262 Partition 1 type is Primary (0x7) Partition is ACTIVE. Partition starts at LBA: 81920 Numsec = 1540096 Partition file system is NTFS Partition is bootable Partition 2 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 1622016 Numsec = 975142912 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 500107862016 bytes Sector size: 512 bytes Scanning physical sectors of unpartitioned space on drive 0 (1-62-976753168-976773168)... Done! Physical Sector Size: 512 Drive: 1, DevicePointer: 0xfffffa800fe53060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ --------- Disk Stack ------ DevicePointer: 0xfffffa800fe53b90, DeviceName: Unknown, DriverName: \Driver\partmgr\ DevicePointer: 0xfffffa800fe53060, DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ DevicePointer: 0xfffffa800fc18d40, DeviceName: Unknown, DriverName: \Driver\vidsflt67\ DevicePointer: 0xfffffa800fc17cb0, DeviceName: Unknown, DriverName: \Driver\stdcfltn\ DevicePointer: 0xfffffa800eaede40, DeviceName: Unknown, DriverName: \Driver\ACPI\ DevicePointer: 0xfffffa800eaf4050, DeviceName: \Device\Ide\IAAStorageDevice-2\, DriverName: \Driver\iaStor\ ------------ End ---------- Alternate DeviceName: \Device\Harddisk1\DR1\, DriverName: \Driver\Disk\ Upper DeviceData: 0x0, 0x0, 0x0 Lower DeviceData: 0x0, 0x0, 0x0 Drive 1 Scanning MBR on drive 1... Inspecting partition table: MBR Signature: 55AA Disk Signature: 2F0BB16B Partition information: Partition 0 type is Primary (0x7) Partition is NOT ACTIVE. Partition starts at LBA: 63 Numsec = 976768002 Partition 1 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 2 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Partition 3 type is Empty (0x0) Partition is NOT ACTIVE. Partition starts at LBA: 0 Numsec = 0 Disk Size: 500107862016 bytes Sector size: 512 bytes Done! Scan finished ======================================= Removal queue found; removal started Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\Bootstrap_0_1_81920_i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_0_r.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_i.mbam... Removing C:\ProgramData\Malwarebytes' Anti-Malware (portable)\MBR_1_r.mbam... Removal finished Grüße von Boarderlion |
11.01.2014, 01:32 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer Leider ist das das falsche Log.
__________________ Logfiles bitte immer in CODE-Tags posten |
11.01.2014, 07:21 | #9 |
| Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer cosinus, hier das gewünschte Log: Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.07.0.1008 www.malwarebytes.org Database version: v2014.01.11.01 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 JULIAN :: JULIAN-PC [administrator] 11.01.2014 02:38:25 mbar-log-2014-01-11 (02-38-25).txt Scan type: Quick scan Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken Scan options disabled: Objects scanned: 272355 Time elapsed: 22 minute(s), 29 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) Physical Sectors Detected: 0 (No malicious items detected) (end) Gruß von boarderlion |
12.01.2014, 17:08 | #10 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte AdwCleaner auf deinen Desktop.
2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ Logfiles bitte immer in CODE-Tags posten |
13.01.2014, 00:38 | #11 |
| Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer Hallo cosinus , Die 3 Logfiles : Code:
ATTFilter # AdwCleaner v3.017 - Bericht erstellt am 12/01/2014 um 23:18:12 # Aktualisiert 12/01/2014 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzername : JULIAN - JULIAN-PC # Gestartet von : C:\Users\JULIAN\Downloads\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\apn Ordner Gelöscht : C:\Users\JULIAN\AppData\Local\Temp\apn Ordner Gelöscht : C:\Users\JULIAN\AppData\Roaming\dvdvideosoftiehelpers Datei Gelöscht : C:\Windows\System32\roboot64.exe Datei Gelöscht : C:\Users\JULIAN\AppData\Roaming\Mozilla\Firefox\Profiles\yx6fcysc.default-1380303922440\searchplugins\ask-search.xml ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\secman.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\secman.OutlookSecurityManager.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{4D076AB4-7562-427A-B5D2-BD96E19DEE56} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{826D7151-8D99-434B-8540-082B8C2AE556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{11549FE4-7C5A-4C17-9FC3-56FC5162A994} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8EEE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{66EEF543-A9AC-4A9D-AA3C-1ED148AC8FFE} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v [ Datei : C:\Users\JULIAN\AppData\Roaming\Mozilla\Firefox\Profiles\yx6fcysc.default-1380303922440\prefs.js ] -\\ Google Chrome v32.0.1700.72 [ Datei : C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Professional x64 Ran by JULIAN on 12.01.2014 at 23:28:51,10 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\JULIAN\appdata\local\{3CD9A616-9874-4D7C-82B8-BEBEFD809565} Successfully deleted: [Empty Folder] C:\Users\JULIAN\appdata\local\{5114830C-9CFD-4722-8197-9D187966E3C5} ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 12.01.2014 at 23:43:17,63 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-01-2014 Ran by JULIAN (administrator) on JULIAN-PC on 12-01-2014 23:53:26 Running from C:\Users\JULIAN\Downloads Windows 7 Professional Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe (IDT, Inc.) C:\Program Files\IDT\WDM\stacsv64.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\BCMWLTRY.EXE (UPEK Inc.) C:\Program Files\Common Files\SPBA\upeksvr.exe (Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmService.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\CDP\afcdpsrv.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe (Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DTSRVC.exe () C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe (Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel Corporation) C:\Windows\System32\IPROSetMonitor.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Nitro PDF Software) C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe (O2Micro International) C:\Windows\System32\o2flash.exe () C:\Windows\SysWOW64\srvany.exe (O2Micro.) C:\Windows\SysWOW64\SDIOAssist.exe (Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdisrvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\SyncAgent\syncagentsrv.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\Apoint.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (IDT, Inc.) C:\Program Files\IDT\WDM\sttray64.exe (Dell Inc.) C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE (Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe (Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe (Wave Systems Corp.) C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe (Acronis) C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe (Acronis) C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\GdBgInx64.exe (Dell Inc.) C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Portrait Displays, Inc) C:\Program Files (x86)\Portrait Displays\PremierColor\dthtml.exe (G Data Software AG) C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe (Portrait Displays Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Shared\HookManager.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApMsgFwd.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\hidfind.exe (Alps Electric Co., Ltd.) C:\Program Files\DellTPad\ApntEx.exe (Portrait Displays, Inc.) C:\Program Files (x86)\Common Files\Portrait Displays\Drivers\pdiSDKHelperx64.exe (G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKBap64.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe () C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper.exe () C:\Program Files (x86)\Common Files\Portrait Displays\Plugins\DP\DPHelper64.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\EXCEL.EXE (Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [682904 2012-09-20] (Alps Electric Co., Ltd.) HKLM\...\Run: [SysTrayApp] - C:\Program Files\IDT\WDM\sttray64.exe [1425408 2012-05-07] (IDT, Inc.) HKLM\...\Run: [Broadcom Wireless Manager UI] - C:\Program Files\Dell\DW WLAN Card\WLTRAY.EXE [7469568 2012-01-18] (Dell Inc.) HKLM\...\Run: [TdmNotify] - C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Trusted Drive Manager\TdmNotify.exe [381296 2011-12-08] (Wave Systems Corp.) HKLM\...\Run: [DFEPApplication] - C:\Program Files\Dell\Feature Enhancement Pack\DFEPApplication.exe [7077432 2012-08-15] (Dell Inc.) HKLM\...\Run: [Acronis Scheduler2 Service] - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedhlp.exe [403688 2012-06-28] (Acronis) HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-02-27] (Intel Corporation) HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284480 2012-05-30] (Intel Corporation) HKLM-x32\...\Run: [DT DL2] - C:\Program Files (x86)\Common Files\Portrait Displays\Shared\DT_Startup.exe [120400 2012-07-23] (Portrait Displays, Inc.) HKLM-x32\...\Run: [TrueImageMonitor.exe] - C:\Program Files (x86)\Acronis\TrueImageHome\TrueImageMonitor.exe [5993216 2012-06-28] (Acronis) HKLM-x32\...\Run: [G Data AntiVirus Tray] - C:\Program Files (x86)\G Data\InternetSecurity\AVKTray\AVKTray.exe [1444472 2013-08-21] (G Data Software AG) HKLM-x32\...\Run: [GDFirewallTray] - C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFirewallTray.exe [1854928 2013-03-22] (G Data Software AG) HKLM-x32\...\Run: [AcronisTimounterMonitor] - C:\Program Files (x86)\Acronis\TrueImageHome\TimounterMonitor.exe [1173712 2012-06-28] (Acronis) HKLM-x32\...\Run: [] - [x] HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,c:\program files (x86)\g data\internetsecurity\avkkid\avkcks.exe Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) Winlogon\Notify\spba: C:\Program Files\Common Files\SPBA\homefus2.dll (UPEK Inc.) HKCU\...\Run: [Spybot-S&D Cleaning] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe [3642312 2013-05-16] (Safer-Networking Ltd.) MountPoints2: {ee80f7c6-1c69-11e3-aab3-d4bed981107b} - G:\LaunchU3.exe -a Lsa: [Authentication Packages] msv1_0 wvauth Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.) Startup: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Smart Settings.lnk ShortcutTarget: Smart Settings.lnk -> C:\Program Files\Dell\Feature Enhancement Pack\SmartSettings.exe (Dell Inc.) ==================== Internet (Whitelisted) ==================== ProxyServer: :0 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://dell13-comm.msn.com SearchScopes: HKLM - DefaultScope {1CC45312-6052-4648-81D6-C20B14576A2C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MDDRJS SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKLM - {1CC45312-6052-4648-81D6-C20B14576A2C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MDDRJS SearchScopes: HKLM-x32 - {1CC45312-6052-4648-81D6-C20B14576A2C} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE9TR&src=IE9TR&pc=MDDRJS SearchScopes: HKCU - {1CC45312-6052-4648-81D6-C20B14576A2C} URL = BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_printenhancer.dll (Hewlett-Packard Co.) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\smart web printing\hpswp_BHO.dll (Hewlett-Packard Co.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\JULIAN\AppData\Roaming\Mozilla\Firefox\Profiles\yx6fcysc.default-1380303922440 FF DefaultSearchEngine: Ask Search FF SearchEngineOrder.1: Ask Search FF SelectedSearchEngine: Ask Search FF Homepage: hxxp://www.sueddeutsche.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll () FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll () FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=10.40.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~3\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @nvidia.com/3DVision - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin-x32: @nvidia.com/3DVisionStreaming - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) FF Extension: WOT - C:\Users\JULIAN\AppData\Roaming\Mozilla\Firefox\Profiles\yx6fcysc.default-1380303922440\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} FF Extension: Ghostery - C:\Users\JULIAN\AppData\Roaming\Mozilla\Firefox\Profiles\yx6fcysc.default-1380303922440\Extensions\firefox@ghostery.com.xpi FF Extension: NoScript - C:\Users\JULIAN\AppData\Roaming\Mozilla\Firefox\Profiles\yx6fcysc.default-1380303922440\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 Chrome: ======= CHR DefaultSearchKeyword: bing.com CHR DefaultSearchProvider: Bing CHR DefaultSearchURL: hxxp://www.bing.com/search?setmkt=de-DE&q={searchTerms} CHR DefaultNewTabURL: CHR Extension: (Google Docs) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 CHR Extension: (Google Drive) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 CHR Extension: (WOT) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\2.4.5_0 CHR Extension: (YouTube) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 CHR Extension: (Google Search) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0 CHR Extension: (AdBlock) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.16_0 CHR Extension: (Disconnect Search) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmobfennjmjnkdbklhcnnfbhfibedgkk\1.4.0_0 CHR Extension: (Ghostery) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\mlomiejdfkolichcflejclcbmpeaniij\5.0.0_0 CHR Extension: (DVDVideoSoft Browser Extension) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nikpibnbobmbdbheedjfogjlikpgpnhp\1.0.1.2_0 CHR Extension: (Google Wallet) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.0_1 CHR Extension: (Gmail) - C:\Users\JULIAN\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0 CHR HKCU\...\Chrome\Extension: [nikpibnbobmbdbheedjfogjlikpgpnhp] - C:\Program Files (x86)\Common Files\DVDVideoSoft\plugins\DVDVideoSoftBrowserExtension.crx ==================== Services (Whitelisted) ================= R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [1970296 2013-08-26] (G Data Software AG) R2 AVKService; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKService.exe [635000 2013-08-21] (G Data Software AG) R2 AVKWCtl; C:\Program Files (x86)\G Data\InternetSecurity\AVK\AVKWCtlx64.exe [2562208 2013-10-15] (G Data Software AG) R2 DFEPService; C:\Program Files\Dell\Feature Enhancement Pack\DFEPService.exe [2280504 2012-08-15] (Dell Inc.) R2 DTSRVC; C:\Program Files (x86)\Common Files\Portrait Displays\Shared\dtsrvc.exe [136784 2012-07-23] (Portrait Displays, Inc.) R2 EmbassyService; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\EMBASSY Client Core\EmbassyServer.exe [218504 2012-01-17] () R3 GDFwSvc; C:\Program Files (x86)\G Data\InternetSecurity\Firewall\GDFwSvcx64.exe [2942808 2013-10-17] (G Data Software AG) R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [695416 2013-08-22] (G Data Software AG) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-28] (Intel Corporation) S4 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation) S4 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation) R2 NitroReaderDriverReadSpool2; C:\Program Files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [204304 2012-03-25] (Nitro PDF Software) R2 O2FLASH; C:\Windows\system32\o2flash.exe [244328 2011-11-16] (O2Micro International) R2 O2SDIOAssist; c:\Windows\SysWOW64\srvany.exe [8192 2003-04-19] () R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) S3 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) S2 tcsd_win32.exe; C:\Program Files (x86)\NTRU Cryptosystems\NTRU TCG Software Stack\bin\tcsd_win32.exe [1637888 2011-10-09] () R2 Wave Authentication Manager Service; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Authentication Manager\WaveAMService.exe [1679872 2012-01-05] (Wave Systems Corp.) R2 wltrysvc; C:\Program Files\Dell\DW WLAN Card\WLTRYSVC.EXE [48128 2012-01-18] (Dell Inc.) S3 WvPCR; C:\Program Files\Dell\Dell Data Protection\Access\Advanced\Wave\Common\WvPCR.exe [198144 2012-01-16] (Wave Systems Corp.) ==================== Drivers (Whitelisted) ==================== R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [60248 2013-09-28] (G Data Software AG) R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [130392 2013-09-28] (G Data Software AG) R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [63320 2013-09-28] (G Data Software AG) R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64856 2013-10-27] (G Data Software AG) R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2013-10-05] (G Data Software) R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [65368 2013-09-28] (G Data Software AG) R1 HWiNFO32; C:\Windows\system32\drivers\HWiNFO64A.SYS [31136 2013-06-14] (REALiX(tm)) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation) R1 nvkflt; C:\Windows\System32\DRIVERS\nvkflt.sys [284008 2012-09-18] (NVIDIA Corporation) R3 ST_ACCEL; C:\Windows\System32\DRIVERS\ST_ACCEL.sys [68208 2011-11-04] (STMicroelectronics) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-12 23:43 - 2014-01-12 23:46 - 00000843 _____ C:\Users\JULIAN\Desktop\JRT.txt 2014-01-12 23:28 - 2014-01-12 23:28 - 00000000 ____D C:\Windows\ERUNT 2014-01-12 23:27 - 2014-01-12 23:27 - 01037068 _____ (Thisisu) C:\Users\JULIAN\Downloads\JRT.exe 2014-01-12 23:13 - 2014-01-12 23:18 - 00000000 ____D C:\AdwCleaner 2014-01-12 23:12 - 2014-01-12 23:12 - 01236282 _____ C:\Users\JULIAN\Downloads\adwcleaner.exe 2014-01-12 07:58 - 2014-01-12 07:58 - 00053076 _____ C:\Users\JULIAN\Desktop\cc_20140112_075813.reg 2014-01-12 07:52 - 2014-01-12 07:52 - 00002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-01-12 07:52 - 2014-01-12 07:52 - 00000000 ____D C:\Program Files\CCleaner 2014-01-12 07:49 - 2014-01-12 07:49 - 03571656 _____ (Piriform Ltd) C:\Users\JULIAN\Downloads\ccsetup409_slim.exe 2014-01-11 02:30 - 2014-01-11 06:35 - 00000000 ____D C:\Users\JULIAN\Downloads\mbar 2014-01-10 18:34 - 2014-01-11 06:35 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-01-10 18:34 - 2014-01-11 02:38 - 00117464 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-01-10 18:33 - 2014-01-11 02:30 - 00089304 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-01-10 18:33 - 2014-01-10 18:33 - 00000000 ____D C:\Users\JULIAN\Desktop_Malwarebytes 2014-01-10 18:32 - 2014-01-10 18:32 - 12582688 _____ (Malwarebytes Corp.) C:\Users\JULIAN\Downloads\mbar-1.07.0.1008.exe 2014-01-10 13:17 - 2014-01-10 13:17 - 00000000 ____D C:\Program Files (x86)\Network Security Taskmanager 2014-01-10 13:16 - 2014-01-10 13:16 - 03544440 _____ C:\Users\JULIAN\Downloads\network-taskmanager.exe 2014-01-10 10:31 - 2014-01-10 10:31 - 00025929 _____ C:\Users\JULIAN\Downloads\Addition.txt 2014-01-10 10:28 - 2014-01-12 23:53 - 00020929 _____ C:\Users\JULIAN\Downloads\FRST.txt 2014-01-10 10:27 - 2014-01-10 10:27 - 00000000 ____D C:\FRST 2014-01-10 10:26 - 2014-01-10 10:26 - 01932166 _____ (Farbar) C:\Users\JULIAN\Downloads\FRST64.exe 2014-01-10 09:23 - 2014-01-10 10:22 - 00000474 _____ C:\Users\JULIAN\Downloads\defogger_disable.log 2014-01-10 09:23 - 2014-01-10 09:23 - 00000000 _____ C:\Users\JULIAN\defogger_reenable 2014-01-10 09:22 - 2014-01-10 09:22 - 00050477 _____ C:\Users\JULIAN\Downloads\Defogger.exe 2014-01-10 06:54 - 2014-01-10 13:23 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-10 06:54 - 2014-01-10 06:54 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2014-01-10 06:52 - 2014-01-10 06:52 - 02365840 _____ C:\Users\JULIAN\Downloads\SecurityTaskManager_Setup (1).exe 2014-01-10 06:47 - 2014-01-10 06:47 - 00015543 _____ C:\Users\JULIAN\Desktop\hijackthis.log 2014-01-10 04:53 - 2014-01-10 04:53 - 00015543 _____ C:\Users\JULIAN\Downloads\hijackthis.log 2014-01-10 04:52 - 2014-01-10 04:52 - 00388608 _____ (Trend Micro Inc.) C:\Users\JULIAN\Downloads\HiJackThis204.exe 2014-01-08 12:32 - 2014-01-09 00:26 - 00000000 ____D C:\Users\JULIAN\Desktop\GeBeP 2014-01-02 06:19 - 2014-01-02 06:19 - 00002735 _____ C:\Users\JULIAN\Desktop\01 Dienstplan Januar 2014_Grayson_Music 20122014 - Verknüpfung.lnk 2013-12-31 12:24 - 2014-01-08 12:25 - 00016230 _____ C:\Users\JULIAN\Desktop\FOTOAPPARAT.xlsx 2013-12-28 15:33 - 2014-01-01 00:09 - 00000000 ____D C:\ProgramData\PMS 2013-12-28 15:29 - 2013-12-28 15:30 - 00000000 ____D C:\Users\JULIAN\Downloads\pms-1.90.1-setup-full 2013-12-28 15:26 - 2013-12-28 15:27 - 107506905 _____ C:\Users\JULIAN\Downloads\pms-1.90.1-setup-full.zip 2013-12-28 05:01 - 2013-12-28 05:01 - 00065979 _____ C:\Users\JULIAN\Downloads\gsmmap-1.01.apk 2013-12-27 05:04 - 2013-12-27 05:04 - 00000041 _____ C:\Users\JULIAN\AppData\Roaming\mbam.context.scan 2013-12-22 03:05 - 2014-01-10 13:56 - 00000000 ____D C:\Users\JULIAN\Desktop\Karten 2013-12-19 20:15 - 2013-12-19 20:16 - 00000000 ____D C:\Users\JULIAN\Desktop\PDFS 2013-12-18 16:42 - 2013-12-18 16:43 - 00000000 ____D C:\Users\JULIAN\Desktop\NTM 2013-12-16 13:43 - 2013-12-16 13:44 - 00000000 ____D C:\Users\JULIAN\Desktop\SYMIO RECHNUNGEN 2013-12-16 08:36 - 2013-12-16 23:57 - 00000000 ____D C:\Users\JULIAN\Desktop\Crazy Eddy 2013-12-13 03:00 - 2013-11-26 12:54 - 23183360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2013-12-13 03:00 - 2013-11-26 11:19 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2013-12-13 03:00 - 2013-11-26 11:18 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2013-12-13 03:00 - 2013-11-26 11:11 - 17112576 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2013-12-13 03:00 - 2013-11-26 10:48 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2013-12-13 03:00 - 2013-11-26 10:46 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2013-12-13 03:00 - 2013-11-26 10:41 - 02764288 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2013-12-13 03:00 - 2013-11-26 10:29 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2013-12-13 03:00 - 2013-11-26 10:27 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2013-12-13 03:00 - 2013-11-26 10:23 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2013-12-13 03:00 - 2013-11-26 10:21 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2013-12-13 03:00 - 2013-11-26 10:18 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2013-12-13 03:00 - 2013-11-26 10:18 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2013-12-13 03:00 - 2013-11-26 10:16 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2013-12-13 03:00 - 2013-11-26 09:57 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2013-12-13 03:00 - 2013-11-26 09:38 - 02166784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2013-12-13 03:00 - 2013-11-26 09:38 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2013-12-13 03:00 - 2013-11-26 09:35 - 05769216 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2013-12-13 03:00 - 2013-11-26 09:32 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2013-12-13 03:00 - 2013-11-26 09:28 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2013-12-13 03:00 - 2013-11-26 09:16 - 04243968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2013-12-13 03:00 - 2013-11-26 09:02 - 01995264 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2013-12-13 03:00 - 2013-11-26 08:48 - 12996608 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2013-12-13 03:00 - 2013-11-26 08:32 - 01928192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2013-12-13 03:00 - 2013-11-26 08:26 - 11221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2013-12-13 03:00 - 2013-11-26 08:07 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2013-12-13 03:00 - 2013-11-26 07:40 - 01395200 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2013-12-13 03:00 - 2013-11-26 07:34 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2013-12-13 03:00 - 2013-11-26 07:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2013-12-13 03:00 - 2013-11-26 07:33 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2013-12-13 03:00 - 2013-11-26 07:27 - 01157632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll ==================== One Month Modified Files and Folders ======= 2014-01-12 23:54 - 2014-01-10 10:28 - 00020929 _____ C:\Users\JULIAN\Downloads\FRST.txt 2014-01-12 23:46 - 2014-01-12 23:43 - 00000843 _____ C:\Users\JULIAN\Desktop\JRT.txt 2014-01-12 23:28 - 2014-01-12 23:28 - 00000000 ____D C:\Windows\ERUNT 2014-01-12 23:27 - 2014-01-12 23:27 - 01037068 _____ (Thisisu) C:\Users\JULIAN\Downloads\JRT.exe 2014-01-12 23:27 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-12 23:27 - 2009-07-14 05:45 - 00021088 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-12 23:22 - 2013-06-12 09:46 - 00000000 ____D C:\Users\JULIAN\Documents\Outlook-Dateien 2014-01-12 23:20 - 2013-10-03 02:33 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-12 23:20 - 2012-12-02 20:09 - 00000000 ____D C:\ProgramData\NVIDIA 2014-01-12 23:20 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-12 23:20 - 2009-07-14 05:51 - 00012154 _____ C:\Windows\setupact.log 2014-01-12 23:19 - 2012-12-02 19:53 - 01868611 _____ C:\Windows\WindowsUpdate.log 2014-01-12 23:18 - 2014-01-12 23:13 - 00000000 ____D C:\AdwCleaner 2014-01-12 23:15 - 2013-10-03 02:33 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-12 23:12 - 2014-01-12 23:12 - 01236282 _____ C:\Users\JULIAN\Downloads\adwcleaner.exe 2014-01-12 08:01 - 2013-06-12 09:12 - 00000000 ___RD C:\Users\JULIAN\Desktop\TOOLS 2014-01-12 07:58 - 2014-01-12 07:58 - 00053076 _____ C:\Users\JULIAN\Desktop\cc_20140112_075813.reg 2014-01-12 07:54 - 2013-09-26 20:00 - 00000000 ____D C:\Program Files (x86)\HP 2014-01-12 07:54 - 2013-09-26 19:59 - 00003385 _____ C:\ProgramData\hpzinstall.log 2014-01-12 07:52 - 2014-01-12 07:52 - 00002774 _____ C:\Windows\System32\Tasks\CCleanerSkipUAC 2014-01-12 07:52 - 2014-01-12 07:52 - 00000000 ____D C:\Program Files\CCleaner 2014-01-12 07:49 - 2014-01-12 07:49 - 03571656 _____ (Piriform Ltd) C:\Users\JULIAN\Downloads\ccsetup409_slim.exe 2014-01-11 14:44 - 2013-08-28 19:37 - 00000000 ____D C:\Users\JULIAN\Documents\Calibre-Bibliothek 2014-01-11 06:35 - 2014-01-11 02:30 - 00000000 ____D C:\Users\JULIAN\Downloads\mbar 2014-01-11 06:35 - 2014-01-10 18:34 - 00000000 ____D C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-01-11 02:38 - 2014-01-10 18:34 - 00117464 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-01-11 02:30 - 2014-01-10 18:33 - 00089304 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-01-10 18:33 - 2014-01-10 18:33 - 00000000 ____D C:\Users\JULIAN\Desktop_Malwarebytes 2014-01-10 18:33 - 2012-12-10 15:43 - 00000000 ____D C:\Users\JULIAN 2014-01-10 18:32 - 2014-01-10 18:32 - 12582688 _____ (Malwarebytes Corp.) C:\Users\JULIAN\Downloads\mbar-1.07.0.1008.exe 2014-01-10 13:56 - 2013-12-22 03:05 - 00000000 ____D C:\Users\JULIAN\Desktop\Karten 2014-01-10 13:23 - 2014-01-10 06:54 - 00000000 ____D C:\ProgramData\SecTaskMan 2014-01-10 13:17 - 2014-01-10 13:17 - 00000000 ____D C:\Program Files (x86)\Network Security Taskmanager 2014-01-10 13:16 - 2014-01-10 13:16 - 03544440 _____ C:\Users\JULIAN\Downloads\network-taskmanager.exe 2014-01-10 10:31 - 2014-01-10 10:31 - 00025929 _____ C:\Users\JULIAN\Downloads\Addition.txt 2014-01-10 10:27 - 2014-01-10 10:27 - 00000000 ____D C:\FRST 2014-01-10 10:26 - 2014-01-10 10:26 - 01932166 _____ (Farbar) C:\Users\JULIAN\Downloads\FRST64.exe 2014-01-10 10:22 - 2014-01-10 09:23 - 00000474 _____ C:\Users\JULIAN\Downloads\defogger_disable.log 2014-01-10 09:23 - 2014-01-10 09:23 - 00000000 _____ C:\Users\JULIAN\defogger_reenable 2014-01-10 09:22 - 2014-01-10 09:22 - 00050477 _____ C:\Users\JULIAN\Downloads\Defogger.exe 2014-01-10 06:54 - 2014-01-10 06:54 - 00000000 ____D C:\Program Files (x86)\Security Task Manager 2014-01-10 06:52 - 2014-01-10 06:52 - 02365840 _____ C:\Users\JULIAN\Downloads\SecurityTaskManager_Setup (1).exe 2014-01-10 06:47 - 2014-01-10 06:47 - 00015543 _____ C:\Users\JULIAN\Desktop\hijackthis.log 2014-01-10 04:53 - 2014-01-10 04:53 - 00015543 _____ C:\Users\JULIAN\Downloads\hijackthis.log 2014-01-10 04:53 - 2012-12-10 15:43 - 00000000 ____D C:\Users\JULIAN\AppData\Local\VirtualStore 2014-01-10 04:52 - 2014-01-10 04:52 - 00388608 _____ (Trend Micro Inc.) C:\Users\JULIAN\Downloads\HiJackThis204.exe 2014-01-09 00:26 - 2014-01-08 12:32 - 00000000 ____D C:\Users\JULIAN\Desktop\GeBeP 2014-01-08 12:25 - 2013-12-31 12:24 - 00016230 _____ C:\Users\JULIAN\Desktop\FOTOAPPARAT.xlsx 2014-01-08 03:59 - 2009-07-14 04:20 - 00000000 ____D C:\Windows\system32\NDF 2014-01-08 02:18 - 2013-10-03 02:33 - 00002177 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-08 00:14 - 2013-06-14 19:51 - 00000000 ____D C:\Users\JULIAN\AppData\Roaming\Nitro PDF 2014-01-02 06:19 - 2014-01-02 06:19 - 00002735 _____ C:\Users\JULIAN\Desktop\01 Dienstplan Januar 2014_Grayson_Music 20122014 - Verknüpfung.lnk 2014-01-01 05:22 - 2013-06-14 19:57 - 00000000 ____D C:\Users\JULIAN\Desktop\yyy 2014-01-01 00:09 - 2013-12-28 15:33 - 00000000 ____D C:\ProgramData\PMS 2013-12-28 15:30 - 2013-12-28 15:29 - 00000000 ____D C:\Users\JULIAN\Downloads\pms-1.90.1-setup-full 2013-12-28 15:27 - 2013-12-28 15:26 - 107506905 _____ C:\Users\JULIAN\Downloads\pms-1.90.1-setup-full.zip 2013-12-28 05:01 - 2013-12-28 05:01 - 00065979 _____ C:\Users\JULIAN\Downloads\gsmmap-1.01.apk 2013-12-27 05:04 - 2013-12-27 05:04 - 00000041 _____ C:\Users\JULIAN\AppData\Roaming\mbam.context.scan 2013-12-24 19:45 - 2013-06-12 11:05 - 00000000 ____D C:\Users\JULIAN\AppData\Roaming\vlc 2013-12-22 11:23 - 2013-12-02 10:56 - 00000000 ____D C:\Users\JULIAN\Desktop\AMAZON Bestellungn 2013-12-22 05:11 - 2013-06-12 08:44 - 00000000 ____D C:\Users\JULIAN\AppData\Roaming\Adobe 2013-12-20 06:10 - 2013-06-13 03:20 - 00000000 ____D C:\Users\JULIAN\Desktop\BILDER 2013-12-19 20:16 - 2013-12-19 20:15 - 00000000 ____D C:\Users\JULIAN\Desktop\PDFS 2013-12-18 16:43 - 2013-12-18 16:42 - 00000000 ____D C:\Users\JULIAN\Desktop\NTM 2013-12-16 23:57 - 2013-12-16 08:36 - 00000000 ____D C:\Users\JULIAN\Desktop\Crazy Eddy 2013-12-16 19:35 - 2009-07-14 06:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT 2013-12-16 13:44 - 2013-12-16 13:43 - 00000000 ____D C:\Users\JULIAN\Desktop\SYMIO RECHNUNGEN 2013-12-15 03:02 - 2013-08-14 22:27 - 00000000 ____D C:\Windows\system32\MRT 2013-12-15 03:00 - 2013-06-15 03:41 - 90708896 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2013-12-13 20:25 - 2010-11-21 07:50 - 00700418 _____ C:\Windows\system32\perfh007.dat 2013-12-13 20:25 - 2010-11-21 07:50 - 00149182 _____ C:\Windows\system32\perfc007.dat 2013-12-13 20:25 - 2009-07-14 06:13 - 01621308 _____ C:\Windows\system32\PerfStringBackup.INI Some content of TEMP: ==================== C:\Users\JULIAN\AppData\Local\Temp\APNSetup.exe C:\Users\JULIAN\AppData\Local\Temp\fp_pl_pfs_installer.exe C:\Users\JULIAN\AppData\Local\Temp\jna1353708428434231273.dll C:\Users\JULIAN\AppData\Local\Temp\jna1594581219237481159.dll C:\Users\JULIAN\AppData\Local\Temp\jna2256181832525081025.dll C:\Users\JULIAN\AppData\Local\Temp\jna386435848413563746.dll C:\Users\JULIAN\AppData\Local\Temp\jna6307513402642041655.dll C:\Users\JULIAN\AppData\Local\Temp\jna7490730483538363106.dll C:\Users\JULIAN\AppData\Local\Temp\jna8002310201460997212.dll C:\Users\JULIAN\AppData\Local\Temp\MSNA43F.exe C:\Users\JULIAN\AppData\Local\Temp\ose00000.exe C:\Users\JULIAN\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-12 17:28 ==================== End Of Log ============================ Gruß von Boarderlion |
13.01.2014, 12:10 | #12 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner
__________________ Logfiles bitte immer in CODE-Tags posten |
13.01.2014, 17:45 | #13 |
| Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer Hallo cosinus, die beiden LogFiles: Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.13.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 JULIAN :: JULIAN-PC [Administrator] 13.01.2014 12:14:46 mbam-log-2014-01-13 (12-14-46).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 247304 Laufzeit: 5 Minute(n), 24 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=e9fc1ed3feff7f4a8e4ac6bb4b781ef3 # engine=16628 # end=stopped # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-13 12:33:28 # local_time=2014-01-13 01:33:28 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 244356 141246258 0 0 # scanned=103373 # found=0 # cleaned=0 # scan_time=4207 ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=e9fc1ed3feff7f4a8e4ac6bb4b781ef3 # engine=16631 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-13 02:39:52 # local_time=2014-01-13 03:39:52 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776573 100 94 251940 141253842 0 0 # scanned=213227 # found=0 # cleaned=0 # scan_time=6856 |
13.01.2014, 22:58 | #14 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer TFC - Temp File Cleaner Lade dir TFC (TempFileCleaner von Oldtimer) herunter und speichere es auf den Desktop.
Sieht soweit ok aus Wegen Cookies und anderer Dinge im Web: Um die Pest von vornherein zu blocken (also TrackingCookies, Werbebanner etc.) müsstest du dir mal sowas wie MVPS Hosts File anschauen => Blocking Unwanted Parasites with a Hosts File - sinnvollerweise solltest du alle 4 Wochen mal bei MVPS nachsehen, ob er eine neue Hosts Datei herausgebracht hat. Info: Cookies sind keine Schädlinge direkt, aber es besteht die Gefahr der missbräuchlichen Verwendung (eindeutige Wiedererkennung zB für gezielte Werbung o.ä. => HTTP-Cookie ) Ansonsten gibt es noch gute Cookiemanager, Erweiterungen für den Firefox zB wäre da CookieCuller Wenn du aber damit leben kannst, dich bei jeder Browsersession überall neu einzuloggen (zB Facebook, Ebay, GMX, oder auch Trojaner-Board) dann stell den Browser einfach so ein, dass einfach alles beim Beenden des Browser inkl. Cookies gelöscht wird. Ist dein System nun wieder in Ordnung oder gibt's noch andere Funde oder Probleme?
__________________ Logfiles bitte immer in CODE-Tags posten |
14.01.2014, 13:16 | #15 |
| Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer Hallo cosinus, Habe jetz mal alles getestet. Ich glaube wir haben es geschafft. Internet läuft z.Zt. ohne Unterbrechung.Maus hat keine Aussetzer mehr. Ich bedanke mich für Deine schnelle und kompetente Hilfe. Was denkst Du woran es jetzt lag? Danke für den Rat bzgl. Cookies. Ich benutze z.Zt noch Chrome und habe da permanent die Einstellungen :Speicherung von Daten für alle Websites blockieren / Drittanbieter-Cookies und Websitedaten blockieren eingestellt. Grüße von boarderlion |
Themen zu Laptop wird langsamer,Netwerkverbindungen einschl. WLAN sowie Maus haben Aussetzer |
adobe, antivirus, bho, converter, explorer, firewall, google, hijack, hijackthis, internet explorer, lsass.exe, maus, micro, microsoft, mp3, nvidia, security, senden, software, usb, windows, windows media player, winlogon, wlan, wmp |