|
Log-Analyse und Auswertung: Windows 7: Laptop seit wenigen Tagen extrem langsamWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
25.04.2014, 18:16 | #1 |
| Windows 7: Laptop seit wenigen Tagen extrem langsam Hallo liebe Community, versuche hier meiner Mutter zu helfen, ihr Laptop ist seit 2-3 Tagen extrem langsam (Braucht sehr lange zum Hochfahren, zum Öffnen von Webseiten und auch bei den Facebookspielen, die sonst nie länger als 10-15 Sekunden geladen haben, braucht es jetzt Minuten). Wir haben versucht, ihn wieder flott zu machen, habe ihn mit Kaspersky scannen lassen (ohne irgendetwas gefunden zu haben), über Nacht mal defragmentieren lassen und zu guter letzt unnütze Programme deinstalliert. Dabei ist mir dann unter Anderem auch ein Programm namens "Websteroids" von Creative Island Media LLC aufgefallen und nach einer kurzen Websuche habe ich dann herausgefunden, dass es wohl eine Schadsoftware ist. Habe diese dann deinstalliert und irgendwie gehofft, dass es besser wird, aber nichts dergleichen.. Weiß langsam nicht mehr was ich machen soll, darum hoffe ich, dass mir hier jemand helfen kann Hier die gewünschten Logs: FRST.TXT FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-04-2014 01 Ran by Louba (administrator) on LOUBA-PC on 25-04-2014 18:40:45 Running from C:\Users\Louba\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe (NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe (Microsoft Corporation) C:\Windows\system32\WLANExt.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe (Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE (CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (ASUS) C:\Windows\AsScrPro.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Microsoft Corporation) C:\Windows\splwow64.exe (NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-17] (Realtek Semiconductor) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-12] (ELAN Microelectronics Corp.) HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-03] (Intel(R) Corporation) HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs" HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2726728 2010-03-25] (CANON INC.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11855976 2011-05-17] (Realtek Semiconductor) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-18] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-08] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] () HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.) HKLM-x32\...\Run: [ASUS Screen Saver Protector] => C:\Windows\AsScrPro.exe [3058304 2014-02-12] (ASUS) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2938410442-2887813953-4122150277-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler HKU\S-1-5-21-2938410442-2887813953-4122150277-1001\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [6087448 2014-01-21] (Piriform Ltd) AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [226920 2011-05-10] (NVIDIA Corporation) AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [193128 2011-05-10] (NVIDIA Corporation) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323737&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP0F1EF72B-73BD-4353-9A9A-A2B7900C23FD&q={searchTerms}&SSPV= SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323737&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP0F1EF72B-73BD-4353-9A9A-A2B7900C23FD&q={searchTerms}&SSPV= BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner64.dll (Google Inc.) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.) BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO-x32: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll (Google Inc.) BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO-x32: No Name - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} - No File BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 192.168.0.2 FireFox: ======== FF ProfilePath: C:\Users\Louba\AppData\Roaming\Mozilla\Firefox\Profiles\46i6jzyg.default FF NewTab: hxxp://www.google.de/ FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_44.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll () FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Louba\AppData\Roaming\Mozilla\Firefox\Profiles\46i6jzyg.default\searchplugins\conduit-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Louba\AppData\Roaming\Mozilla\Firefox\Profiles\46i6jzyg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-13] FF HKLM-x32\...\Firefox\Extensions: - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-04-24] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-04-24] FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-04-24] FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-04-24] FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-04-24] Chrome: ======= CHR Extension: (Google Docs) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-24] CHR Extension: (Google Drive) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-24] CHR Extension: (YouTube) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-24] CHR Extension: (Adblock Plus) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-24] CHR Extension: (Google-Suche) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-24] CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-04-24] CHR Extension: (Facebook Customizer (by Adblock Plus)) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\deoeenbkoccjaefmmhpmlegngdjohdcm [2014-04-24] CHR Extension: (Sicherer Zahlungsverkehr) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-04-24] CHR Extension: (Modul zum Sperren von gefährlichen Webseiten) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-04-24] CHR Extension: (Virtuelle Tastatur) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-04-24] CHR Extension: (Pic and Click San Francisco) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkpmjmcgjoidcjgdfmeaajknmjcecdii [2014-04-24] CHR Extension: (Google Wallet) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-24] CHR Extension: (Google Mail) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-24] CHR Extension: (Anti-Banner) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-04-24] CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Services (Whitelisted) ================= R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] () S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-03] () ==================== Drivers (Whitelisted) ==================== R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [7717984 2013-10-17] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [112224 2013-06-08] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [620640 2013-10-17] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178784 2013-06-06] (Kaspersky Lab ZAO) R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-17] () ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-04-25 18:40 - 2014-04-25 18:41 - 00019241 _____ () C:\Users\Louba\Downloads\FRST.txt 2014-04-25 18:40 - 2014-04-25 18:40 - 00000000 ____D () C:\FRST 2014-04-25 18:38 - 2014-04-25 18:38 - 02061312 _____ (Farbar) C:\Users\Louba\Downloads\FRST64.exe 2014-04-25 18:35 - 2014-04-25 18:35 - 00000472 _____ () C:\Users\Louba\Downloads\defogger_disable.log 2014-04-25 18:35 - 2014-04-25 18:35 - 00000000 _____ () C:\Users\Louba\defogger_reenable 2014-04-25 18:33 - 2014-04-25 18:33 - 00050477 _____ () C:\Users\Louba\Downloads\Defogger.exe 2014-04-25 18:31 - 2014-04-25 18:31 - 00058016 _____ () C:\Users\Louba\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-25 18:13 - 2014-04-25 18:31 - 00009735 _____ () C:\Windows\WindowsUpdate.log 2014-04-25 17:54 - 2014-04-25 17:54 - 00000000 ____D () C:\ProgramData\ASUS 2014-04-25 17:52 - 2014-04-25 17:52 - 00024576 _____ () C:\Users\Louba\AppData\Local\uninst.tmp 2014-04-25 12:22 - 2014-04-25 12:22 - 00000000 ____D () C:\Users\Louba\Documents\PC Speed Maximizer 2014-04-24 23:06 - 2014-04-24 23:06 - 00067342 _____ () C:\Users\Louba\Documents\cc_20140424_230608.reg 2014-04-24 22:51 - 2014-04-24 22:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2014-04-24 22:51 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2014-04-24 22:50 - 2014-04-24 22:50 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-04-24 22:49 - 2014-04-25 18:10 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-04-24 22:49 - 2014-04-24 22:49 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-04-24 22:49 - 2013-10-17 15:47 - 00620640 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2014-04-24 22:49 - 2013-06-08 20:18 - 00112224 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2014-04-24 22:15 - 2014-04-24 22:15 - 00002253 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-15 22:02 - 2014-04-15 22:02 - 00000000 ____D () C:\ProgramData\CanonIJ 2014-04-15 22:01 - 2014-04-15 22:01 - 00000000 ___HD () C:\ProgramData\CanonIJScan 2014-04-15 22:01 - 2014-04-15 22:01 - 00000000 ____D () C:\Users\Louba\AppData\Roaming\Canon 2014-04-15 22:01 - 2014-04-15 22:01 - 00000000 _____ () C:\Users\Louba\Sti_Trace.log 2014-04-15 15:22 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-15 15:22 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-15 15:22 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-15 15:22 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-04-15 15:22 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-15 15:22 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-15 15:22 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-15 15:22 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-15 15:22 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-15 15:22 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-15 15:22 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-04-15 15:22 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-15 15:22 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-15 15:22 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-15 15:22 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-15 15:22 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-15 15:22 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-15 15:22 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-15 15:22 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-15 15:22 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2014-04-15 15:22 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2014-04-15 15:22 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2014-04-15 15:22 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-15 15:22 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-15 15:22 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2014-04-15 15:22 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2014-04-15 15:22 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2014-04-15 15:22 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2014-04-15 15:22 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-15 15:22 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2014-04-15 15:22 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2014-04-15 15:22 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2014-04-15 15:22 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2014-04-15 15:22 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-15 15:22 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2014-04-15 15:22 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-15 15:22 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2014-04-15 15:22 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2014-04-15 15:22 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-15 15:22 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2014-04-15 15:22 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2014-04-15 15:22 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2014-04-15 15:22 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-15 15:22 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-15 15:22 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-15 15:22 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2014-04-15 15:22 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2014-04-15 15:22 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2014-04-10 10:30 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 10:30 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll 2014-04-10 10:30 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll 2014-04-10 10:30 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll 2014-04-10 10:30 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll 2014-04-10 10:30 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll 2014-04-10 10:30 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll 2014-04-10 10:30 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe 2014-04-10 10:30 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll 2014-04-10 10:30 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe 2014-04-10 10:30 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe 2014-04-10 10:30 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 10:30 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 10:30 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 10:30 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 10:30 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll 2014-04-10 10:30 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-03-27 20:16 - 2014-03-27 20:16 - 00000000 ____D () C:\ProgramData\Mozilla 2014-03-27 20:16 - 2014-03-27 20:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service ==================== One Month Modified Files and Folders ======= 2014-04-25 18:41 - 2014-04-25 18:40 - 00019241 _____ () C:\Users\Louba\Downloads\FRST.txt 2014-04-25 18:40 - 2014-04-25 18:40 - 00000000 ____D () C:\FRST 2014-04-25 18:38 - 2014-04-25 18:38 - 02061312 _____ (Farbar) C:\Users\Louba\Downloads\FRST64.exe 2014-04-25 18:35 - 2014-04-25 18:35 - 00000472 _____ () C:\Users\Louba\Downloads\defogger_disable.log 2014-04-25 18:35 - 2014-04-25 18:35 - 00000000 _____ () C:\Users\Louba\defogger_reenable 2014-04-25 18:35 - 2014-02-10 23:50 - 00000000 ____D () C:\Users\Louba 2014-04-25 18:34 - 2011-04-11 14:05 - 00482258 _____ () C:\Windows\system32\perfh001.dat 2014-04-25 18:34 - 2011-04-11 14:05 - 00098162 _____ () C:\Windows\system32\perfc001.dat 2014-04-25 18:34 - 2011-03-17 13:52 - 00727844 _____ () C:\Windows\system32\perfh019.dat 2014-04-25 18:34 - 2011-03-17 13:52 - 00154232 _____ () C:\Windows\system32\perfc019.dat 2014-04-25 18:34 - 2011-02-19 07:02 - 00395588 _____ () C:\Windows\system32\perfh00D.dat 2014-04-25 18:34 - 2011-02-19 07:02 - 00088148 _____ () C:\Windows\system32\perfc00D.dat 2014-04-25 18:34 - 2011-02-19 06:56 - 00610232 _____ () C:\Windows\system32\perfh008.dat 2014-04-25 18:34 - 2011-02-19 06:56 - 00114518 _____ () C:\Windows\system32\perfc008.dat 2014-04-25 18:34 - 2011-02-19 06:51 - 00409036 _____ () C:\Windows\system32\prfh0404.dat 2014-04-25 18:34 - 2011-02-19 06:51 - 00125534 _____ () C:\Windows\system32\prfc0404.dat 2014-04-25 18:34 - 2011-02-19 06:45 - 00732262 _____ () C:\Windows\system32\prfh0816.dat 2014-04-25 18:34 - 2011-02-19 06:45 - 00156296 _____ () C:\Windows\system32\prfc0816.dat 2014-04-25 18:34 - 2011-02-19 06:40 - 00746742 _____ () C:\Windows\system32\perfh013.dat 2014-04-25 18:34 - 2011-02-19 06:40 - 00156492 _____ () C:\Windows\system32\perfc013.dat 2014-04-25 18:34 - 2011-02-19 06:35 - 00743290 _____ () C:\Windows\system32\perfh010.dat 2014-04-25 18:34 - 2011-02-19 06:35 - 00150236 _____ () C:\Windows\system32\perfc010.dat 2014-04-25 18:34 - 2011-02-19 06:29 - 00748960 _____ () C:\Windows\system32\perfh00C.dat 2014-04-25 18:34 - 2011-02-19 06:29 - 00152970 _____ () C:\Windows\system32\perfc00C.dat 2014-04-25 18:34 - 2011-02-19 06:24 - 00710782 _____ () C:\Windows\system32\perfh007.dat 2014-04-25 18:34 - 2011-02-19 06:24 - 00152972 _____ () C:\Windows\system32\perfc007.dat 2014-04-25 18:34 - 2011-02-19 06:19 - 00748700 _____ () C:\Windows\system32\perfh00A.dat 2014-04-25 18:34 - 2011-02-19 06:19 - 00161864 _____ () C:\Windows\system32\perfc00A.dat 2014-04-25 18:34 - 2009-07-14 07:13 - 09348272 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-25 18:33 - 2014-04-25 18:33 - 00050477 _____ () C:\Users\Louba\Downloads\Defogger.exe 2014-04-25 18:31 - 2014-04-25 18:31 - 00058016 _____ () C:\Users\Louba\AppData\Local\GDIPFONTCACHEV1.DAT 2014-04-25 18:31 - 2014-04-25 18:13 - 00009735 _____ () C:\Windows\WindowsUpdate.log 2014-04-25 18:18 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-04-25 18:18 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-04-25 18:17 - 2011-04-13 04:33 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-25 18:10 - 2014-04-24 22:49 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-04-25 18:10 - 2014-02-10 23:51 - 00045056 _____ () C:\Windows\system32\acovcnt.exe 2014-04-25 18:10 - 2011-04-13 04:33 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-25 18:09 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-04-25 17:54 - 2014-04-25 17:54 - 00000000 ____D () C:\ProgramData\ASUS 2014-04-25 17:54 - 2011-04-13 04:47 - 00000000 ____D () C:\Program Files (x86)\ASUS 2014-04-25 17:52 - 2014-04-25 17:52 - 00024576 _____ () C:\Users\Louba\AppData\Local\uninst.tmp 2014-04-25 17:52 - 2014-02-12 00:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS Utility 2014-04-25 17:49 - 2014-02-13 22:21 - 00000000 ____D () C:\ProgramData\Websteroids 2014-04-25 12:22 - 2014-04-25 12:22 - 00000000 ____D () C:\Users\Louba\Documents\PC Speed Maximizer 2014-04-24 23:55 - 2014-02-11 00:10 - 00000000 ____D () C:\Users\Louba\AppData\Roaming\Skype 2014-04-24 23:14 - 2014-02-11 00:10 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-04-24 23:14 - 2014-02-11 00:10 - 00000000 ____D () C:\ProgramData\Skype 2014-04-24 23:14 - 2014-02-11 00:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-04-24 23:06 - 2014-04-24 23:06 - 00067342 _____ () C:\Users\Louba\Documents\cc_20140424_230608.reg 2014-04-24 23:03 - 2011-04-13 04:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-04-24 22:51 - 2014-04-24 22:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security 2014-04-24 22:50 - 2014-04-24 22:50 - 00000000 ____D () C:\Windows\ELAMBKUP 2014-04-24 22:49 - 2014-04-24 22:49 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab 2014-04-24 22:15 - 2014-04-24 22:15 - 00002253 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-24 22:15 - 2014-02-10 23:53 - 00000000 ____D () C:\Users\Louba\AppData\Local\Google 2014-04-24 22:11 - 2011-04-13 04:33 - 00004120 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2014-04-24 22:11 - 2011-04-13 04:33 - 00003868 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2014-04-17 23:46 - 2014-03-02 13:40 - 00000000 ____D () C:\Users\Louba\AppData\Roaming\SoftGrid Client 2014-04-15 22:04 - 2014-02-25 13:29 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-04-15 22:02 - 2014-04-15 22:02 - 00000000 ____D () C:\ProgramData\CanonIJ 2014-04-15 22:01 - 2014-04-15 22:01 - 00000000 ___HD () C:\ProgramData\CanonIJScan 2014-04-15 22:01 - 2014-04-15 22:01 - 00000000 ____D () C:\Users\Louba\AppData\Roaming\Canon 2014-04-15 22:01 - 2014-04-15 22:01 - 00000000 _____ () C:\Users\Louba\Sti_Trace.log 2014-04-15 19:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\he-IL 2014-04-15 19:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\ar-SA 2014-04-15 19:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\he-IL 2014-04-15 19:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\ar-SA 2014-04-15 19:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions 2014-04-11 00:33 - 2014-02-11 18:15 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-11 00:31 - 2014-02-11 18:14 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-04 10:16 - 2009-07-14 07:08 - 00032542 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-03-31 09:35 - 2014-02-11 00:32 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe 2014-03-28 05:13 - 2014-02-13 21:52 - 00000000 ____D () C:\Users\Louba\AppData\Roaming\vlc 2014-03-28 05:13 - 2014-02-12 00:26 - 00000000 ____D () C:\ProgramData\P4G 2014-03-28 05:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration 2014-03-27 20:16 - 2014-03-27 20:16 - 00000000 ____D () C:\ProgramData\Mozilla 2014-03-27 20:16 - 2014-03-27 20:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-03-27 20:16 - 2014-02-11 00:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2009-07-29 07:04 ==================== End Of Log ============================ Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-04-2014 01 Ran by Louba at 2014-04-25 18:41:45 Running from C:\Users\Louba\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 10.1.85.3 - Adobe Systems Incorporated) Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 12.0.0.44 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated) ASUS AI Recovery (HKLM-x32\...\{38253529-D97D-4901-AE53-5CC9736D3A2E}) (Version: 1.0.13 - ASUS) ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.1.43 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0030 - ASUS) ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.21 - asus) AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.4.617 - ASUSTEK) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0010 - ASUS) Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version: - ) Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: 1.3.5.0 - Canon Inc.) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version: - ) Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version: - ) Canon MP280 series Benutzerregistrierung (HKLM-x32\...\Canon MP280 series Benutzerregistrierung) (Version: - ) Canon MP280 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series) (Version: - ) Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version: - ) Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden ETDWare PS/2-X64 8.0.5.3_WHQL (HKLM\...\Elantech) (Version: 8.0.5.3 - ELAN Microelectronic Corp.) Free YouTube to MP3 Converter version 3.12.20.1230 (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: 3.12.20.1230 - DVDVideoSoft Ltd.) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Gnumeric Spreadsheet 1.7.12-win32-1 (HKCU\...\Gnumeric) (Version: 1.7.12-win32-1 - ) Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.) Google Update Helper (x32 Version: 1.3.23.9 - Google Inc.) Hidden Intel PROSet Wireless (Version: - ) Hidden Intel PROSet Wireless (x32 Version: - ) Hidden Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation) Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation) Intel(R) Turbo Boost Technology Monitor (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.400.4 - Intel) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: 14.0.0.4651 - Kaspersky Lab) Kaspersky Internet Security (x32 Version: 14.0.0.4651 - Kaspersky Lab) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mozilla Firefox 27.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 27.0 (x86 de)) (Version: 27.0 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.4.0 - Mozilla) Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden NVIDIA Control Panel 268.56 (Version: 268.56 - NVIDIA Corporation) Hidden NVIDIA Graphics Driver 268.56 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 268.56 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.265.41.0 - NVIDIA Corporation) Hidden NVIDIA Optimus 1.0.22 (Version: 1.0.22 - NVIDIA Corporation) Hidden NVIDIA Update Components (Version: 1.0.22 - NVIDIA Corporation) Hidden Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.38.113.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6373 - Realtek Semiconductor Corp.) Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10001 - Realtek Semiconductor Corp.) Skype™ 6.13 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.13.104 - Skype Technologies S.A.) Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: 1.0.0.4 - Synopsys ) TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.25942 - TeamViewer) VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.0 - ASUS) Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.19 - ASUS) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Restore Points ========================= 01-04-2014 09:50:29 Windows Update 09-04-2014 09:59:42 Windows Update 10-04-2014 22:30:37 Windows Update 15-04-2014 10:16:06 Windows Update 15-04-2014 13:22:16 Windows Update 22-04-2014 09:36:18 Windows Update 25-04-2014 15:46:54 Removed Fast Boot 25-04-2014 15:51:43 Removed ASUS FancyStart 25-04-2014 15:53:11 Removed ASUS SmartLogon 25-04-2014 15:58:30 Quitado Control ActiveX de Windows Live Mesh para conexiones remotas 25-04-2014 15:59:48 Contrôle ActiveX Windows Live Mesh pour connexions à distance wird entfernt 25-04-2014 16:01:08 Removido Controlo ActiveX do Windows Live Mesh para Ligações Remotas ==================== Hosts content: ========================== 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {13751808-2F01-455B-BC4D-0AC718FA8476} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd) Task: {60F398C6-F009-4FEB-B4EF-955537F134F2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-04-13] (Google Inc.) Task: {7EFAF18E-638B-4CAE-B4BD-70F0D0F5D035} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2010-08-02] (ASUS) Task: {84A77F86-B445-48DE-B57F-B89B693CD5C2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-04-13] (Google Inc.) Task: {F0098D35-FD47-4FAD-A249-EEBAE43133CC} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-18] (ASUS) Task: {F7A615A8-08D6-4927-A379-491F1EA52B63} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-12-02] (ASUS) Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2011-05-02 23:41 - 2011-05-02 23:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll 2014-02-25 13:29 - 2010-04-05 21:55 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE 2010-04-03 05:21 - 2008-10-01 09:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2010-07-15 02:11 - 2010-07-15 02:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll 2011-07-07 08:12 - 2011-01-27 02:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2011-05-02 23:41 - 2011-05-02 23:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll 2010-09-24 02:53 - 2010-09-24 02:53 - 01601536 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe 2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll 2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll 2014-04-24 22:15 - 2014-04-02 03:57 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll 2014-04-24 22:15 - 2014-04-02 03:57 - 00674632 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libglesv2.dll 2014-04-24 22:15 - 2014-04-02 03:57 - 00093000 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libegl.dll 2014-04-24 22:15 - 2014-04-02 03:57 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll 2014-04-24 22:15 - 2014-04-02 03:58 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll 2014-04-24 22:15 - 2014-04-02 03:57 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: BDRegion => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: Setwallpaper => c:\programdata\SetWallpaper.cmd ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 26% Total physical RAM: 8103.77 MB Available physical RAM: 5918.57 MB Total Pagefile: 16205.72 MB Available Pagefile: 13612.97 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:238.47 GB) (Free:177.26 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (DATA) (Fixed) (Total:332.7 GB) (Free:331.95 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: 38601C96) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=238 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=333 GB) - (Type=OF Extended) ==================== End Of Log ============================ Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-04-25 19:11:13 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.JEDO 596,17GB Running: 7tx1ixl4.exe; Driver: C:\Users\Louba\AppData\Local\Temp\ugloapog.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[1908] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075981465 2 bytes [98, 75] .text C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[1908] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000759814bb 2 bytes [98, 75] .text ... * 2 ? C:\Windows\system32\mssprxy.dll [3116] entry point in ".rdata" section 000000006e8d71e6 .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 5 0000000077c511f5 8 bytes {JMP 0xd} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 416 0000000077c51390 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159 0000000077c5143f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 492 0000000077c5158c 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126 0000000077c5191e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 636 0000000077c51b1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 204 0000000077c51bf0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373 0000000077c51d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 691 0000000077c51eb3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31 0000000077c51edf 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!_ui64toa + 84 0000000077c51f64 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 81 0000000077c51fbd 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelf + 7 0000000077c51fd7 8 bytes {JMP 0xb} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 658 0000000077c52272 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 801 0000000077c52301 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 578 0000000077c52792 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16 0000000077c527b0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18 0000000077c527d2 8 bytes {JMP 0x10} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79 0000000077c5282f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 176 0000000077c52890 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 2 .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299 0000000077c52d1b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 367 0000000077c52d5f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text ... * 3 .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlCutoverTimeToSystemTime + 483 0000000077c53023 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523 0000000077c5323b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 912 0000000077c533c0 16 bytes {JMP 0x4e} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318 0000000077c53a5e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403 0000000077c53ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197 0000000077c53b85 8 bytes [10, 6A, F8, 7E, 00, 00, 00, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 611 0000000077c53d23 8 bytes [00, 6A, F8, 7E, 00, 00, 00, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80 0000000077c54190 8 bytes [A0, 69, F8, 7E, 00, 00, 00, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread 0000000077ca1380 8 bytes {JMP QWORD [RIP-0x4d4cf]} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread 0000000077ca1500 8 bytes {JMP QWORD [RIP-0x4d498]} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection 0000000077ca1530 8 bytes {JMP QWORD [RIP-0x4d9b1]} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory 0000000077ca1650 8 bytes {JMP QWORD [RIP-0x4d7a7]} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread 0000000077ca1700 8 bytes {JMP QWORD [RIP-0x4d9e3]} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx 0000000077ca1d30 8 bytes {JMP QWORD [RIP-0x4dba6]} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread 0000000077ca1f80 8 bytes {JMP QWORD [RIP-0x4de55]} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread 0000000077ca27e0 8 bytes {JMP QWORD [RIP-0x4e770]} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312 00000000744d13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471 00000000744d146b 8 bytes {JMP 0xffffffffffffffb0} .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611 00000000744d16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessTerm + 3 00000000744d16e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23 00000000744d19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23 00000000744d19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetInstructionPointer + 23 00000000744d1a1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuNotifyAffinityChange + 3 00000000744d1a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23 00000000744d1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] .text C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessDebugEvent + 3 00000000744d1a6f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...] ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0025d3b2962e Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0025d3b2962e (not active ControlSet) ---- EOF - GMER 2.1 ---- |
25.04.2014, 18:23 | #2 |
/// the machine /// TB-Ausbilder | Windows 7: Laptop seit wenigen Tagen extrem langsam hi,
__________________Scan mit Combofix
__________________ |
25.04.2014, 19:24 | #3 |
| Windows 7: Laptop seit wenigen Tagen extrem langsam Hey,
__________________hab vergessen, den Windows Defender abzustellen, sollte ich das Programm nochmal ausführen? Hier jedenfalls der Log: Code:
ATTFilter ComboFix 14-04-20.01 - Louba 25.04.2014 20:15:19.2.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8104.6540 [GMT 2:00] ausgeführt von:: c:\users\Louba\Downloads\ComboFix.exe AV: Kaspersky Internet Security *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886} FW: Kaspersky Internet Security *Disabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} SP: Kaspersky Internet Security *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . - REDUZIERTER FUNKTIONALITÄTSMODUS - . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\programdata\Roaming c:\windows\msvcr71.dll . . ((((((((((((((((((((((( Dateien erstellt von 2014-03-25 bis 2014-04-25 )))))))))))))))))))))))))))))) . . 2014-04-25 18:17 . 2014-04-25 18:17 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2014-04-25 18:17 . 2014-04-25 18:17 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-04-25 16:40 . 2014-04-25 16:42 -------- d-----w- C:\FRST 2014-04-25 15:54 . 2014-04-25 15:54 -------- d-----w- c:\programdata\ASUS 2014-04-25 15:52 . 2014-04-25 15:52 24576 ----a-w- c:\users\Louba\AppData\Local\uninst.tmp 2014-04-25 08:24 . 2014-04-17 03:31 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{672F737D-38FC-41D8-86E5-A87DA89739B6}\mpengine.dll 2014-04-24 20:51 . 2013-05-06 07:13 110176 ----a-w- c:\windows\system32\klfphc.dll 2014-04-24 20:50 . 2014-04-24 20:50 -------- d-----w- c:\windows\ELAMBKUP 2014-04-24 20:49 . 2014-04-24 20:49 -------- d-----w- c:\program files (x86)\Kaspersky Lab 2014-04-24 20:49 . 2014-04-25 17:12 -------- d-----w- c:\programdata\Kaspersky Lab 2014-04-24 20:49 . 2013-10-17 13:47 620640 ----a-w- c:\windows\system32\drivers\klif.sys 2014-04-24 20:49 . 2013-06-08 18:18 112224 ----a-w- c:\windows\system32\drivers\klflt.sys 2014-04-15 20:02 . 2014-04-15 20:02 -------- d-----w- c:\programdata\CanonIJ 2014-04-15 20:01 . 2014-04-15 20:01 -------- d-----w- c:\users\Louba\AppData\Roaming\Canon 2014-04-10 08:30 . 2014-02-04 02:35 190912 ----a-w- c:\windows\system32\drivers\storport.sys 2014-03-27 18:16 . 2014-03-27 18:16 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-04-25 16:10 . 2014-02-10 21:51 45056 ----a-w- c:\windows\system32\acovcnt.exe 2014-04-10 22:31 . 2014-02-11 16:14 90655440 ----a-w- c:\windows\system32\MRT.exe 2014-03-31 07:35 . 2014-02-10 22:32 270496 ------w- c:\windows\system32\MpSigStub.exe 2014-03-04 09:17 . 2014-04-10 08:30 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2014-02-15 14:53 . 2014-02-15 14:53 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2014-02-15 14:52 . 2014-02-15 14:52 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2014-02-15 14:52 . 2014-02-15 14:52 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2014-02-15 14:52 . 2014-02-15 14:52 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2014-02-15 14:52 . 2014-02-15 14:52 337408 ----a-w- c:\windows\SysWow64\html.iec 2014-02-15 14:52 . 2014-02-15 14:52 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2014-02-15 14:52 . 2014-02-15 14:52 235008 ----a-w- c:\windows\system32\elshyph.dll 2014-02-15 14:52 . 2014-02-15 14:52 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2014-02-15 14:52 . 2014-02-15 14:52 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2014-02-15 14:52 . 2014-02-15 14:52 942592 ----a-w- c:\windows\system32\jsIntl.dll 2014-02-15 14:52 . 2014-02-15 14:52 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2014-02-15 14:52 . 2014-02-15 14:52 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2014-02-15 14:52 . 2014-02-15 14:52 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2014-02-15 14:52 . 2014-02-15 14:52 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2014-02-15 14:52 . 2014-02-15 14:52 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2014-02-15 14:52 . 2014-02-15 14:52 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2014-02-15 14:52 . 2014-02-15 14:52 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2014-02-15 14:52 . 2014-02-15 14:52 247808 ----a-w- c:\windows\system32\msls31.dll 2014-02-15 14:52 . 2014-02-15 14:52 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2014-02-15 14:52 . 2014-02-15 14:52 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2014-02-15 14:52 . 2014-02-15 14:52 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2014-02-15 14:52 . 2014-02-15 14:52 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2014-02-15 14:52 . 2014-02-15 14:52 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2014-02-15 14:52 . 2014-02-15 14:52 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2014-02-15 14:52 . 2014-02-15 14:52 84992 ----a-w- c:\windows\system32\mshtmled.dll 2014-02-15 14:52 . 2014-02-15 14:52 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2014-02-15 14:52 . 2014-02-15 14:52 81408 ----a-w- c:\windows\system32\icardie.dll 2014-02-15 14:52 . 2014-02-15 14:52 774144 ----a-w- c:\windows\system32\jscript.dll 2014-02-15 14:52 . 2014-02-15 14:52 77312 ----a-w- c:\windows\system32\tdc.ocx 2014-02-15 14:52 . 2014-02-15 14:52 62464 ----a-w- c:\windows\system32\pngfilt.dll 2014-02-15 14:52 . 2014-02-15 14:52 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2014-02-15 14:52 . 2014-02-15 14:52 48640 ----a-w- c:\windows\system32\mshtmler.dll 2014-02-15 14:52 . 2014-02-15 14:52 48128 ----a-w- c:\windows\system32\imgutil.dll 2014-02-15 14:52 . 2014-02-15 14:52 413696 ----a-w- c:\windows\system32\html.iec 2014-02-15 14:52 . 2014-02-15 14:52 30208 ----a-w- c:\windows\system32\licmgr10.dll 2014-02-15 14:52 . 2014-02-15 14:52 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2014-02-15 14:52 . 2014-02-15 14:52 243200 ----a-w- c:\windows\system32\webcheck.dll 2014-02-15 14:52 . 2014-02-15 14:52 235520 ----a-w- c:\windows\system32\url.dll 2014-02-15 14:52 . 2014-02-15 14:52 167424 ----a-w- c:\windows\system32\iexpress.exe 2014-02-15 14:52 . 2014-02-15 14:52 147968 ----a-w- c:\windows\system32\occache.dll 2014-02-15 14:52 . 2014-02-15 14:52 143872 ----a-w- c:\windows\system32\wextract.exe 2014-02-15 14:52 . 2014-02-15 14:52 13824 ----a-w- c:\windows\system32\mshta.exe 2014-02-15 14:52 . 2014-02-15 14:52 135680 ----a-w- c:\windows\system32\iepeers.dll 2014-02-15 14:52 . 2014-02-15 14:52 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2014-02-15 14:52 . 2014-02-15 14:52 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2014-02-15 14:52 . 2014-02-15 14:52 105984 ----a-w- c:\windows\system32\iesysprep.dll 2014-02-15 14:52 . 2014-02-15 14:52 101376 ----a-w- c:\windows\system32\inseng.dll 2014-02-11 22:34 . 2014-02-11 22:34 353576 ------w- c:\windows\SysWow64\msvcr71.dll 2014-02-11 22:34 . 2014-02-11 22:34 29480 ------w- c:\windows\SysWow64\msxml3a.dll 2014-02-11 22:34 . 2014-02-11 22:34 505128 ------w- c:\windows\SysWow64\msvcp71.dll 2014-02-11 22:32 . 2014-02-11 22:32 3058304 ----a-w- c:\windows\AsScrPro.exe 2014-02-10 22:08 . 2014-02-10 22:08 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-02-10 22:08 . 2014-02-10 22:08 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-02-10 21:51 . 2010-06-24 18:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2014-02-07 01:23 . 2014-03-12 12:01 3156480 ----a-w- c:\windows\system32\win32k.sys 2014-02-04 02:32 . 2014-03-12 12:00 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2014-02-04 02:32 . 2014-03-12 12:00 624128 ----a-w- c:\windows\system32\qedit.dll 2014-02-04 02:04 . 2014-03-12 12:00 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2014-02-04 02:04 . 2014-03-12 12:00 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2014-01-29 02:32 . 2014-03-12 12:01 484864 ----a-w- c:\windows\system32\wer.dll 2014-01-29 02:06 . 2014-03-12 12:01 381440 ----a-w- c:\windows\SysWow64\wer.dll 2014-01-28 02:32 . 2014-03-12 12:01 228864 ----a-w- c:\windows\system32\wwansvc.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}] 2011-04-13 02:33 433648 ----a-w- c:\programdata\Partner\Partner.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CCleaner"="c:\program files\CCleaner\CCleaner64.exe" [2014-01-21 6087448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-13 2018032] "SonicMasterTray"="c:\program files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe" [2010-07-10 984400] "ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992] "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624] "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-24 1601536] "CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112] "ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2014-02-11 3058304] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe;c:\programdata\Partner\Partner.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTSUVSTOR.sys;c:\windows\SYSNATIVE\Drivers\RTSUVSTOR.sys [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 klflt;klflt;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x] S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x] S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x] S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x] S2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - UGLOAPOG *Deregistered* - ugloapog . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-04-24 20:15 1077576 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-13 02:33] . 2014-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-13 02:33] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}] 2011-04-13 02:33 750064 ----a-w- c:\programdata\Partner\Partner64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-10 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-10 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-10 418328] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-05-17 2226280] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-05-02 1935120] "IntelTBRunOnce"="wscript.exe" [2013-10-12 168960] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2726728] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-05-17 11855976] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://asus.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.0.1 192.168.0.2 FF - ProfilePath - c:\users\Louba\AppData\Roaming\Mozilla\Firefox\Profiles\46i6jzyg.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start Toolbar-Locked - (no file) HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-04-25 20:22:15 ComboFix-quarantined-files.txt 2014-04-25 18:22 . Vor Suchlauf: 11 Verzeichnis(se), 189.571.067.904 Bytes frei Nach Suchlauf: 16 Verzeichnis(se), 189.210.669.056 Bytes frei . - - End Of File - - A0994AD5BA99548E7D399BB9178E0BFF Code:
ATTFilter ComboFix 14-04-20.01 - Louba 25.04.2014 20:50:07.3.8 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.8104.6497 [GMT 2:00] ausgeführt von:: c:\users\Louba\Downloads\ComboFix.exe AV: Kaspersky Internet Security *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886} FW: Kaspersky Internet Security *Disabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} SP: Kaspersky Internet Security *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B} SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\Louba\AppData\Local\uninst.tmp D:\install.exe . . ((((((((((((((((((((((( Dateien erstellt von 2014-03-25 bis 2014-04-25 )))))))))))))))))))))))))))))) . . 2014-04-25 19:01 . 2014-04-25 19:01 -------- d-----w- c:\users\UpdatusUser\AppData\Local\temp 2014-04-25 19:01 . 2014-04-25 19:01 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-04-25 16:40 . 2014-04-25 16:42 -------- d-----w- C:\FRST 2014-04-25 15:54 . 2014-04-25 15:54 -------- d-----w- c:\programdata\ASUS 2014-04-25 08:24 . 2014-04-17 03:31 10651704 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{672F737D-38FC-41D8-86E5-A87DA89739B6}\mpengine.dll 2014-04-24 20:51 . 2013-05-06 07:13 110176 ----a-w- c:\windows\system32\klfphc.dll 2014-04-24 20:50 . 2014-04-24 20:50 -------- d-----w- c:\windows\ELAMBKUP 2014-04-24 20:49 . 2014-04-24 20:49 -------- d-----w- c:\program files (x86)\Kaspersky Lab 2014-04-24 20:49 . 2014-04-25 17:12 -------- d-----w- c:\programdata\Kaspersky Lab 2014-04-24 20:49 . 2013-10-17 13:47 620640 ----a-w- c:\windows\system32\drivers\klif.sys 2014-04-24 20:49 . 2013-06-08 18:18 112224 ----a-w- c:\windows\system32\drivers\klflt.sys 2014-04-15 20:02 . 2014-04-15 20:02 -------- d-----w- c:\programdata\CanonIJ 2014-04-15 20:01 . 2014-04-15 20:01 -------- d-----w- c:\users\Louba\AppData\Roaming\Canon 2014-04-10 08:30 . 2014-02-04 02:35 190912 ----a-w- c:\windows\system32\drivers\storport.sys 2014-03-27 18:16 . 2014-03-27 18:16 -------- d-----w- c:\program files (x86)\Mozilla Maintenance Service . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-04-25 16:10 . 2014-02-10 21:51 45056 ----a-w- c:\windows\system32\acovcnt.exe 2014-04-10 22:31 . 2014-02-11 16:14 90655440 ----a-w- c:\windows\system32\MRT.exe 2014-03-31 07:35 . 2014-02-10 22:32 270496 ------w- c:\windows\system32\MpSigStub.exe 2014-03-04 09:17 . 2014-04-10 08:30 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2014-02-15 14:53 . 2014-02-15 14:53 194048 ----a-w- c:\windows\SysWow64\elshyph.dll 2014-02-15 14:52 . 2014-02-15 14:52 71680 ----a-w- c:\windows\SysWow64\RegisterIEPKEYs.exe 2014-02-15 14:52 . 2014-02-15 14:52 645120 ----a-w- c:\windows\SysWow64\jsIntl.dll 2014-02-15 14:52 . 2014-02-15 14:52 62464 ----a-w- c:\windows\SysWow64\tdc.ocx 2014-02-15 14:52 . 2014-02-15 14:52 337408 ----a-w- c:\windows\SysWow64\html.iec 2014-02-15 14:52 . 2014-02-15 14:52 24576 ----a-w- c:\windows\SysWow64\licmgr10.dll 2014-02-15 14:52 . 2014-02-15 14:52 235008 ----a-w- c:\windows\system32\elshyph.dll 2014-02-15 14:52 . 2014-02-15 14:52 182272 ----a-w- c:\windows\SysWow64\msls31.dll 2014-02-15 14:52 . 2014-02-15 14:52 1051136 ----a-w- c:\windows\SysWow64\mshtmlmedia.dll 2014-02-15 14:52 . 2014-02-15 14:52 942592 ----a-w- c:\windows\system32\jsIntl.dll 2014-02-15 14:52 . 2014-02-15 14:52 86016 ----a-w- c:\windows\SysWow64\iesysprep.dll 2014-02-15 14:52 . 2014-02-15 14:52 86016 ----a-w- c:\windows\system32\RegisterIEPKEYs.exe 2014-02-15 14:52 . 2014-02-15 14:52 74240 ----a-w- c:\windows\SysWow64\SetIEInstalledDate.exe 2014-02-15 14:52 . 2014-02-15 14:52 61952 ----a-w- c:\windows\SysWow64\MshtmlDac.dll 2014-02-15 14:52 . 2014-02-15 14:52 52224 ----a-w- c:\windows\system32\msfeedsbs.dll 2014-02-15 14:52 . 2014-02-15 14:52 48640 ----a-w- c:\windows\SysWow64\mshtmler.dll 2014-02-15 14:52 . 2014-02-15 14:52 36352 ----a-w- c:\windows\SysWow64\imgutil.dll 2014-02-15 14:52 . 2014-02-15 14:52 247808 ----a-w- c:\windows\system32\msls31.dll 2014-02-15 14:52 . 2014-02-15 14:52 151552 ----a-w- c:\windows\SysWow64\iexpress.exe 2014-02-15 14:52 . 2014-02-15 14:52 139264 ----a-w- c:\windows\SysWow64\wextract.exe 2014-02-15 14:52 . 2014-02-15 14:52 13312 ----a-w- c:\windows\SysWow64\mshta.exe 2014-02-15 14:52 . 2014-02-15 14:52 13312 ----a-w- c:\windows\system32\msfeedssync.exe 2014-02-15 14:52 . 2014-02-15 14:52 111616 ----a-w- c:\windows\SysWow64\IEAdvpack.dll 2014-02-15 14:52 . 2014-02-15 14:52 90112 ----a-w- c:\windows\system32\SetIEInstalledDate.exe 2014-02-15 14:52 . 2014-02-15 14:52 84992 ----a-w- c:\windows\system32\mshtmled.dll 2014-02-15 14:52 . 2014-02-15 14:52 83968 ----a-w- c:\windows\system32\MshtmlDac.dll 2014-02-15 14:52 . 2014-02-15 14:52 81408 ----a-w- c:\windows\system32\icardie.dll 2014-02-15 14:52 . 2014-02-15 14:52 774144 ----a-w- c:\windows\system32\jscript.dll 2014-02-15 14:52 . 2014-02-15 14:52 77312 ----a-w- c:\windows\system32\tdc.ocx 2014-02-15 14:52 . 2014-02-15 14:52 62464 ----a-w- c:\windows\system32\pngfilt.dll 2014-02-15 14:52 . 2014-02-15 14:52 616104 ----a-w- c:\windows\system32\ieapfltr.dat 2014-02-15 14:52 . 2014-02-15 14:52 48640 ----a-w- c:\windows\system32\mshtmler.dll 2014-02-15 14:52 . 2014-02-15 14:52 48128 ----a-w- c:\windows\system32\imgutil.dll 2014-02-15 14:52 . 2014-02-15 14:52 413696 ----a-w- c:\windows\system32\html.iec 2014-02-15 14:52 . 2014-02-15 14:52 30208 ----a-w- c:\windows\system32\licmgr10.dll 2014-02-15 14:52 . 2014-02-15 14:52 263376 ----a-w- c:\windows\system32\iedkcs32.dll 2014-02-15 14:52 . 2014-02-15 14:52 243200 ----a-w- c:\windows\system32\webcheck.dll 2014-02-15 14:52 . 2014-02-15 14:52 235520 ----a-w- c:\windows\system32\url.dll 2014-02-15 14:52 . 2014-02-15 14:52 167424 ----a-w- c:\windows\system32\iexpress.exe 2014-02-15 14:52 . 2014-02-15 14:52 147968 ----a-w- c:\windows\system32\occache.dll 2014-02-15 14:52 . 2014-02-15 14:52 143872 ----a-w- c:\windows\system32\wextract.exe 2014-02-15 14:52 . 2014-02-15 14:52 13824 ----a-w- c:\windows\system32\mshta.exe 2014-02-15 14:52 . 2014-02-15 14:52 135680 ----a-w- c:\windows\system32\iepeers.dll 2014-02-15 14:52 . 2014-02-15 14:52 131072 ----a-w- c:\windows\system32\IEAdvpack.dll 2014-02-15 14:52 . 2014-02-15 14:52 1228800 ----a-w- c:\windows\system32\mshtmlmedia.dll 2014-02-15 14:52 . 2014-02-15 14:52 105984 ----a-w- c:\windows\system32\iesysprep.dll 2014-02-15 14:52 . 2014-02-15 14:52 101376 ----a-w- c:\windows\system32\inseng.dll 2014-02-11 22:34 . 2014-02-11 22:34 353576 ------w- c:\windows\SysWow64\msvcr71.dll 2014-02-11 22:34 . 2014-02-11 22:34 29480 ------w- c:\windows\SysWow64\msxml3a.dll 2014-02-11 22:34 . 2014-02-11 22:34 505128 ------w- c:\windows\SysWow64\msvcp71.dll 2014-02-11 22:32 . 2014-02-11 22:32 3058304 ----a-w- c:\windows\AsScrPro.exe 2014-02-10 22:08 . 2014-02-10 22:08 71048 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-02-10 22:08 . 2014-02-10 22:08 692616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-02-10 21:51 . 2010-06-24 18:33 22240 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll 2014-02-07 01:23 . 2014-03-12 12:01 3156480 ----a-w- c:\windows\system32\win32k.sys 2014-02-04 02:32 . 2014-03-12 12:00 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2014-02-04 02:32 . 2014-03-12 12:00 624128 ----a-w- c:\windows\system32\qedit.dll 2014-02-04 02:04 . 2014-03-12 12:00 1230336 ----a-w- c:\windows\SysWow64\WindowsCodecs.dll 2014-02-04 02:04 . 2014-03-12 12:00 509440 ----a-w- c:\windows\SysWow64\qedit.dll 2014-01-29 02:32 . 2014-03-12 12:01 484864 ----a-w- c:\windows\system32\wer.dll 2014-01-29 02:06 . 2014-03-12 12:01 381440 ----a-w- c:\windows\SysWow64\wer.dll 2014-01-28 02:32 . 2014-03-12 12:01 228864 ----a-w- c:\windows\system32\wwansvc.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}] 2011-04-13 02:33 433648 ----a-w- c:\programdata\Partner\Partner.dll . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CCleaner"="c:\program files\CCleaner\CCleaner64.exe" [2014-01-21 6087448] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-13 2018032] "SonicMasterTray"="c:\program files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe" [2010-07-10 984400] "ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992] "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624] "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-24 1601536] "CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112] "ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2014-02-11 3058304] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows] "LoadAppInit_DLLs"=1 (0x1) "AppInit_DLLs"=c:\windows\SysWOW64\nvinit.dll . [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus] "DisableMonitoring"=dword:00000001 . R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x] R3 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe;c:\programdata\Partner\Partner.exe [x] R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x] R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTSUVSTOR.sys;c:\windows\SYSNATIVE\Drivers\RTSUVSTOR.sys [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 klflt;klflt;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x] S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x] S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x] S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x] S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x] S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x] S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x] S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x] S2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x] S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x] S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x] S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x] S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x] S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x] S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x] S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x] . . --- Andere Dienste/Treiber im Speicher --- . *NewlyCreated* - UGLOAPOG *Deregistered* - ugloapog . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}] 2014-04-24 20:15 1077576 ----a-w- c:\program files (x86)\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe . Inhalt des "geplante Tasks" Ordners . 2014-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-13 02:33] . 2014-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job - c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-13 02:33] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}] 2011-04-13 02:33 750064 ----a-w- c:\programdata\Partner\Partner64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-10 167960] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-10 391704] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-10 418328] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-05-17 2226280] "ETDCtrl"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU] "IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-05-02 1935120] "IntelTBRunOnce"="wscript.exe" [2013-10-12 168960] "CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2726728] "RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-05-17 11855976] . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=c:\windows\System32\nvinitx.dll . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://asus.msn.com mLocal Page = c:\windows\SysWOW64\blank.htm TCP: DhcpNameServer = 192.168.0.1 192.168.0.2 FF - ProfilePath - c:\users\Louba\AppData\Roaming\Mozilla\Firefox\Profiles\46i6jzyg.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.10" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}] @Denied: (A 2) (Everyone) @="IFlashBroker4" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-04-25 21:07:09 ComboFix-quarantined-files.txt 2014-04-25 19:07 ComboFix2.txt 2014-04-25 18:22 . Vor Suchlauf: 15 Verzeichnis(se), 189.262.249.984 Bytes frei Nach Suchlauf: 16 Verzeichnis(se), 189.190.410.240 Bytes frei . - - End Of File - - 6118BBBBE126372BE3957A2777344C5A Geändert von rooster (25.04.2014 um 20:10 Uhr) Grund: Hab das Programm nochmal laufen lassen, nachdem ich den Windows Defender abgestellt hab. |
26.04.2014, 15:24 | #4 |
/// the machine /// TB-Ausbilder | Windows 7: Laptop seit wenigen Tagen extrem langsam Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7: Laptop seit wenigen Tagen extrem langsam |
browser, canon, converter, defender, desktop, dvdvideosoft ltd., ebanking, error, flash player, focus, google, home, homepage, kaspersky, langsam, monitor, mozilla, mp3, newtab, realtek, registry, scan, security, services.exe, svchost.exe, system, tastatur, temp, usb, websteroids, windows, wscript.exe |