|
Log-Analyse und Auswertung: Windows 7 starter: Leistung des PC hat deutlich nachgelassen.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
05.05.2014, 16:29 | #1 |
| Windows 7 starter: Leistung des PC hat deutlich nachgelassen. Hi ich bin neu im Forum und mein PC hat einiges an Leistung eingebüßt, seit ich ihn vor gut einem Jahr gekauft habe. Seiten werden langsamer aufgebaut und browser laden Seiten immer langsamer. Es wäre super wenn mir hier geholfen werden könnte. Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 16:34 on 05/05/2014 (Mattis) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:04-05-2014 Ran by Mattis (administrator) on MATTIS-PC on 05-05-2014 16:38:03 Running from C:\Users\Mattis\Downloads Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Dritek System Inc.) C:\Program Files\Launch Manager\LMutilps32.exe (Acer Incorporated) C:\Program Files\Acer\Registration\GREGsvc.exe (Realsil Microelectronics Inc.) C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Acer Incorporated) C:\Program Files\Acer\Acer Updater\UpdaterService.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe () C:\Users\Mattis\Downloads\Defogger.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v3.0\WPF\PresentationFontCache.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-14] (Avira Operations GmbH & Co. KG) HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-1721124258-729016498-1291491334-1000\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-1721124258-729016498-1291491334-1000\...\MountPoints2: D - D:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1721124258-729016498-1291491334-1000\...\MountPoints2: {f5db789e-21f7-11e2-a480-047d7b212096} - D:\HTC_Sync_Manager_PC.exe Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/androidnews/ SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPFFC80E91-6DFF-4F5F-85F0-04FAA67167E7&q={searchTerms} SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPFFC80E91-6DFF-4F5F-85F0-04FAA67167E7&q={searchTerms} Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 80.69.103.78 80.69.102.158 FireFox: ======== FF ProfilePath: C:\Users\Mattis\AppData\Roaming\Mozilla\Firefox\Profiles\rmcw9yxc.default FF DefaultSearchEngine: user_pref("browser.search.defaultenginename", ""); FF SelectedSearchEngine: user_pref("browser.search.selectedEngine", ""); FF Homepage: www.google.de FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Mattis\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: pricealarm - C:\Users\Mattis\AppData\Roaming\Mozilla\Firefox\Profiles\rmcw9yxc.default\Extensions\EFGLQA@78ETGYN-0W7FN789T87.COM [2014-01-28] FF Extension: Lavasoft Search Plugin - C:\Users\Mattis\AppData\Roaming\Mozilla\Firefox\Profiles\rmcw9yxc.default\Extensions\jid1-yZwVFzbsyfMrqQ@jetpack [2013-04-11] FF Extension: Adblock Plus - C:\Users\Mattis\AppData\Roaming\Mozilla\Firefox\Profiles\rmcw9yxc.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-04-24] FF HKLM\...\Firefox\Extensions: [webbooster@iminent.com] - C:\Program Files\Iminent\webbooster@iminent.com Chrome: ======= CHR Extension: (Google Wallet) - C:\Users\Mattis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-05] CHR HKLM\...\Chrome\Extension: [mkcedibhemacmilmkpndpkoidlnmgngg] - C:\Users\Mattis\ChromeExtensions\mkcedibhemacmilmkpndpkoidlnmgngg\amazon.crx [2013-12-18] ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-02-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-14] (Avira Operations GmbH & Co. KG) S3 EgisTec Ticket Service; C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe [173424 2011-06-21] (Egis Technology Inc. ) R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [739944 2011-08-02] (Acer Incorporated) R2 GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [36456 2011-05-30] (Acer Incorporated) R2 IconMan_R; C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe [1755136 2011-03-07] (Realsil Microelectronics Inc.) R2 Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [255376 2012-04-05] (Acer Incorporated) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2014-02-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2014-02-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-02-14] (Avira Operations GmbH & Co. KG) S3 btwampfl; C:\Windows\system32\drivers\btwampfl.sys [525352 2011-08-30] (Broadcom Corporation.) S3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [76328 2011-08-30] (Broadcom Corporation.) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-04-11] (GFI Software) R1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [21600 2011-12-16] (Egis Technology Inc.) R1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16936 2011-12-16] (Egis Technology Inc.) R1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [62240 2011-12-16] (Egis Technology Inc.) R3 RSPCIESTOR; C:\Windows\System32\DRIVERS\RtsPStor.sys [254056 2011-05-30] (Realtek Semiconductor Corp.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-02-14] (Avira GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-05 16:38 - 2014-05-05 16:38 - 00009631 _____ () C:\Users\Mattis\Desktop\FRST.txt 2014-05-05 16:37 - 2014-05-05 16:38 - 00000000 ____D () C:\FRST 2014-05-05 16:37 - 2014-05-05 16:37 - 01051648 _____ (Farbar) C:\Users\Mattis\Desktop\FRST.exe 2014-05-05 16:34 - 2014-05-05 16:35 - 00000474 _____ () C:\Users\Mattis\Desktop\defogger_disable.log 2014-05-05 16:34 - 2014-05-05 16:34 - 00050477 _____ () C:\Users\Mattis\Desktop\Defogger.exe 2014-05-05 16:34 - 2014-05-05 16:34 - 00000000 _____ () C:\Users\Mattis\defogger_reenable 2014-05-05 16:18 - 2014-05-05 16:18 - 00448512 _____ (OldTimer Tools) C:\Users\Mattis\Desktop\TFC.exe 2014-05-05 15:17 - 2014-05-05 15:18 - 00144328 _____ () C:\Windows\Minidump\050514-18673-01.dmp 2014-05-05 15:17 - 2014-05-05 15:17 - 150675529 _____ () C:\Windows\MEMORY.DMP 2014-05-05 15:17 - 2014-05-05 15:17 - 00000614 _____ () C:\Windows\PFRO.log 2014-05-05 14:49 - 2014-05-05 15:17 - 00000112 _____ () C:\Windows\setupact.log 2014-05-05 14:49 - 2014-05-05 14:49 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-05 13:17 - 2014-05-05 13:17 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-05 13:16 - 2014-05-05 13:16 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-05 13:16 - 2014-05-05 13:16 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-05 13:16 - 2014-05-05 13:16 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-05-05 13:16 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-05 13:16 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-05 13:16 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-05 13:15 - 2014-05-05 13:15 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Mattis\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-05 12:01 - 2014-05-05 12:01 - 00000000 ____D () C:\Windows\pss 2014-05-02 19:43 - 2014-05-02 19:43 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-30 10:49 - 2014-04-14 04:11 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-30 10:49 - 2014-04-14 04:07 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-29 17:32 - 2014-04-29 17:32 - 00002197 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-29 17:32 - 2014-04-29 17:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-04-29 17:31 - 2014-05-05 16:36 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-29 17:31 - 2014-05-05 15:18 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-29 17:31 - 2014-04-29 17:31 - 00000000 ____D () C:\Program Files\Google 2014-04-29 17:20 - 2014-04-29 17:20 - 00884688 _____ (Google Inc.) C:\Users\Mattis\Downloads\ChromeSetup.exe 2014-04-26 17:15 - 2014-04-26 17:16 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-04-24 14:12 - 2014-04-27 22:57 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-04-24 14:12 - 2014-04-24 14:12 - 00000000 ____D () C:\ProgramData\Mozilla 2014-04-24 10:32 - 2014-04-24 10:32 - 00000000 __SHD () C:\Users\Mattis\AppData\Local\EmieUserList 2014-04-24 10:32 - 2014-04-24 10:32 - 00000000 __SHD () C:\Users\Mattis\AppData\Local\EmieSiteList 2014-04-24 00:23 - 2014-04-24 00:23 - 00007607 _____ () C:\Users\Mattis\AppData\Local\Resmon.ResmonCfg 2014-04-16 22:21 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-16 22:21 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-16 22:21 - 2014-03-06 10:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-16 22:21 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-16 22:21 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-16 22:21 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-16 22:21 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-16 22:21 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-16 22:21 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-16 22:21 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-16 22:21 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-16 22:21 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-16 22:21 - 2014-03-06 09:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-16 22:21 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-16 22:21 - 2014-03-06 09:28 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-16 22:21 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-16 22:21 - 2014-03-06 09:18 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-16 22:21 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-16 22:21 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-16 22:21 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-16 22:21 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-16 22:21 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-16 22:21 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-16 22:21 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-16 22:21 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-16 22:21 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-10 10:10 - 2014-03-04 11:17 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 10:10 - 2014-02-04 04:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 10:10 - 2014-02-04 04:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 10:10 - 2014-02-04 04:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 10:10 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 10:10 - 2014-01-24 04:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 14:08 - 2014-04-09 14:08 - 00003442 _____ () C:\Users\Mattis\Downloads\Fusions.zip 2014-04-08 22:32 - 2014-04-08 22:32 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-04-08 22:32 - 2014-04-08 22:32 - 00000000 ____D () C:\Users\Mattis\AppData\Local\Skype 2014-04-08 22:32 - 2014-04-08 22:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-04-08 22:32 - 2014-04-08 22:32 - 00000000 ____D () C:\Program Files\Common Files\Skype ==================== One Month Modified Files and Folders ======= 2014-05-05 16:38 - 2014-05-05 16:38 - 00009631 _____ () C:\Users\Mattis\Desktop\FRST.txt 2014-05-05 16:38 - 2014-05-05 16:37 - 00000000 ____D () C:\FRST 2014-05-05 16:37 - 2014-05-05 16:37 - 01051648 _____ (Farbar) C:\Users\Mattis\Desktop\FRST.exe 2014-05-05 16:36 - 2014-04-29 17:31 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-05 16:35 - 2014-05-05 16:34 - 00000474 _____ () C:\Users\Mattis\Desktop\defogger_disable.log 2014-05-05 16:34 - 2014-05-05 16:34 - 00050477 _____ () C:\Users\Mattis\Desktop\Defogger.exe 2014-05-05 16:34 - 2014-05-05 16:34 - 00000000 _____ () C:\Users\Mattis\defogger_reenable 2014-05-05 16:34 - 2012-07-14 11:00 - 00000000 ____D () C:\Users\Mattis 2014-05-05 16:18 - 2014-05-05 16:18 - 00448512 _____ (OldTimer Tools) C:\Users\Mattis\Desktop\TFC.exe 2014-05-05 15:26 - 2009-07-14 06:34 - 00016160 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-05 15:26 - 2009-07-14 06:34 - 00016160 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-05 15:22 - 2014-03-27 20:51 - 00939806 _____ () C:\Windows\WindowsUpdate.log 2014-05-05 15:18 - 2014-05-05 15:17 - 00144328 _____ () C:\Windows\Minidump\050514-18673-01.dmp 2014-05-05 15:18 - 2014-04-29 17:31 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-05 15:17 - 2014-05-05 15:17 - 150675529 _____ () C:\Windows\MEMORY.DMP 2014-05-05 15:17 - 2014-05-05 15:17 - 00000614 _____ () C:\Windows\PFRO.log 2014-05-05 15:17 - 2014-05-05 14:49 - 00000112 _____ () C:\Windows\setupact.log 2014-05-05 15:17 - 2012-10-18 13:37 - 00000000 ____D () C:\Windows\Minidump 2014-05-05 15:17 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-05 14:49 - 2014-05-05 14:49 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-05 13:17 - 2014-05-05 13:17 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-05 13:16 - 2014-05-05 13:16 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-05 13:16 - 2014-05-05 13:16 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-05 13:16 - 2014-05-05 13:16 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-05-05 13:15 - 2014-05-05 13:15 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Mattis\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-05 13:01 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-05-05 12:01 - 2014-05-05 12:01 - 00000000 ____D () C:\Windows\pss 2014-05-02 19:43 - 2014-05-02 19:43 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-29 17:32 - 2014-04-29 17:32 - 00002197 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-29 17:32 - 2014-04-29 17:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-04-29 17:32 - 2012-07-14 11:42 - 00000000 ____D () C:\Users\Mattis\AppData\Local\Google 2014-04-29 17:31 - 2014-04-29 17:31 - 00000000 ____D () C:\Program Files\Google 2014-04-29 17:20 - 2014-04-29 17:20 - 00884688 _____ (Google Inc.) C:\Users\Mattis\Downloads\ChromeSetup.exe 2014-04-29 17:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-04-29 11:14 - 2010-11-20 23:01 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-27 23:31 - 2013-07-09 00:34 - 00000000 ____D () C:\Users\Mattis\AppData\Roaming\vlc 2014-04-27 22:57 - 2014-04-24 14:12 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-04-26 17:16 - 2014-04-26 17:15 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-04-24 14:12 - 2014-04-24 14:12 - 00000000 ____D () C:\ProgramData\Mozilla 2014-04-24 13:22 - 2012-09-19 21:00 - 00000000 ____D () C:\Users\Mattis\AppData\Roaming\Skype 2014-04-24 13:13 - 2012-07-26 11:13 - 00000000 ____D () C:\Users\Mattis\AppData\Local\Adobe 2014-04-24 13:12 - 2012-08-21 14:06 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-04-24 13:12 - 2011-12-16 11:55 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-04-24 13:12 - 2011-12-16 11:23 - 00000000 ____D () C:\ProgramData\McAfee 2014-04-24 12:26 - 2013-04-29 16:18 - 00000000 ____D () C:\Users\Mattis\Documents\BIWI 2014-04-24 10:32 - 2014-04-24 10:32 - 00000000 __SHD () C:\Users\Mattis\AppData\Local\EmieUserList 2014-04-24 10:32 - 2014-04-24 10:32 - 00000000 __SHD () C:\Users\Mattis\AppData\Local\EmieSiteList 2014-04-24 00:23 - 2014-04-24 00:23 - 00007607 _____ () C:\Users\Mattis\AppData\Local\Resmon.ResmonCfg 2014-04-17 10:20 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-04-15 23:28 - 2013-04-29 16:19 - 00000000 ____D () C:\Users\Mattis\Documents\Sport 2014-04-14 04:11 - 2014-04-30 10:49 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-14 04:07 - 2014-04-30 10:49 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-11 12:01 - 2013-08-21 23:56 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-11 11:55 - 2012-07-14 15:06 - 88028728 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 14:08 - 2014-04-09 14:08 - 00003442 _____ () C:\Users\Mattis\Downloads\Fusions.zip 2014-04-09 10:24 - 2013-11-04 12:06 - 00000000 ____D () C:\Users\Mattis\Documents\Englisch 2014-04-08 22:32 - 2014-04-08 22:32 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-04-08 22:32 - 2014-04-08 22:32 - 00000000 ____D () C:\Users\Mattis\AppData\Local\Skype 2014-04-08 22:32 - 2014-04-08 22:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-04-08 22:32 - 2014-04-08 22:32 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-04-08 22:32 - 2012-09-19 20:58 - 00000000 ___RD () C:\Program Files\Skype 2014-04-08 22:32 - 2011-12-16 11:22 - 00000000 ____D () C:\ProgramData\Skype Some content of TEMP: ==================== C:\Users\Mattis\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2014-05-05 17:08:36 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 WDC_WD32 rev.01.0 298,09GB Running: Gmer-19357.exe; Driver: C:\Users\Mattis\AppData\Local\Temp\axdiypow.sys ---- System - GMER 2.1 ---- SSDT 8B1F0A26 ZwCreateSection SSDT 8B1F0A30 ZwRequestWaitReplyPort SSDT 8B1F0A2B ZwSetContextThread SSDT 8B1F0A35 ZwSetSecurityObject SSDT 8B1F0A3A ZwSystemDebugControl SSDT 8B1F09C7 ZwTerminateProcess ---- Kernel code sections - GMER 2.1 ---- .text ntkrnlpa.exe!ZwRollbackEnlistment + 142D 82077A15 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 820B1212 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntkrnlpa.exe!KeRemoveQueueEx + 11F7 820B858C 4 Bytes [26, 0A, 1F, 8B] .text ntkrnlpa.exe!KeRemoveQueueEx + 1553 820B88E8 4 Bytes [30, 0A, 1F, 8B] .text ntkrnlpa.exe!KeRemoveQueueEx + 1597 820B892C 4 Bytes [2B, 0A, 1F, 8B] .text ntkrnlpa.exe!KeRemoveQueueEx + 1613 820B89A8 4 Bytes [35, 0A, 1F, 8B] .text ntkrnlpa.exe!KeRemoveQueueEx + 1667 820B89FC 4 Bytes [3A, 0A, 1F, 8B] .text ... ? System32\drivers\sbwlnvba.sys Das System kann den angegebenen Pfad nicht finden. ! ---- Devices - GMER 2.1 ---- AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 Wdf01000.sys ---- Processes - GMER 2.1 ---- Library C:\Windows\system32\dnssd.dll (*** hidden *** ) @ C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe [372] 0x71BD0000 Library C:\Program Files\Bonjour\mdnsNSP.dll (*** hidden *** ) @ C:\Windows\System32\spoolsv.exe [1460] 0x716E0000 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\60d819e89cf8 Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\60d819e89cf8 (not active ControlSet) ---- EOF - GMER 2.1 ---- |
05.05.2014, 17:09 | #2 |
/// the machine /// TB-Ausbilder | Windows 7 starter: Leistung des PC hat deutlich nachgelassen. hi,
__________________Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ |
05.05.2014, 20:51 | #3 |
| Windows 7 starter: Leistung des PC hat deutlich nachgelassen. Hier die neuen Log-Dateien.
__________________FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:05-05-2014 02 Ran by Mattis (administrator) on MATTIS-PC on 05-05-2014 21:23:03 Running from C:\Users\Mattis\Desktop Microsoft Windows 7 Starter Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Dritek System Inc.) C:\Program Files\Launch Manager\dsiwmis.exe (Dritek System Inc.) C:\Program Files\Launch Manager\LMworker.exe (Acer Incorporated) C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe (Dritek System Inc.) C:\Program Files\Launch Manager\LMutilps32.exe (Acer Incorporated) C:\Program Files\Acer\Registration\GREGsvc.exe (Realsil Microelectronics Inc.) C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe () C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe (Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Intel Corporation) C:\Program Files\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\PmmUpdate.exe (Egis Technology Inc.) C:\Program Files\EgisTec IPS\EgisUpdate.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [avgnt] => C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [689744 2014-02-14] (Avira Operations GmbH & Co. KG) HKU\.DEFAULT\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-19\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-20\...\RunOnce: [IsMyWinLockerReboot] - msiexec.exe /qn /x{voidguid} HKU\S-1-5-21-1721124258-729016498-1291491334-1000\...\Policies\Explorer: [DisallowRun] 1 HKU\S-1-5-21-1721124258-729016498-1291491334-1000\...\MountPoints2: D - D:\HTC_Sync_Manager_PC.exe HKU\S-1-5-21-1721124258-729016498-1291491334-1000\...\MountPoints2: {f5db789e-21f7-11e2-a480-047d7b212096} - D:\HTC_Sync_Manager_PC.exe Lsa: [Notification Packages] scecli C:\Program Files\WIDCOMM\Bluetooth Software\BtwProximityCP.dll ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://acer.msn.com HKCU\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.giga.de/androidnews/ SearchScopes: HKLM - DefaultScope value is missing. Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 80.69.103.78 80.69.102.158 FireFox: ======== FF ProfilePath: C:\Users\Mattis\AppData\Roaming\Mozilla\Firefox\Profiles\gc8syzt9.default-1399302690413 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_182.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.23.9\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.0.7 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @WildTangent.com/GamesAppPresenceDetector,Version=1.0 - C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: amazon.com/AmazonMP3DownloaderPlugin - C:\Users\Mattis\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll (Amazon.com, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: Adblock Plus - C:\Users\Mattis\AppData\Roaming\Mozilla\Firefox\Profiles\gc8syzt9.default-1399302690413\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-05-05] Chrome: ======= CHR HomePage: CHR Extension: (Google Wallet) - C:\Users\Mattis\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-05] ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440400 2014-02-14] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440400 2014-02-14] (Avira Operations GmbH & Co. KG) S3 EgisTec Ticket Service; C:\Program Files\Common Files\EgisTec\Services\EgisTicketService.exe [173424 2011-06-21] (Egis Technology Inc. ) R2 ePowerSvc; C:\Program Files\Acer\Acer ePower Management\ePowerSvc.exe [739944 2011-08-02] (Acer Incorporated) R2 GREGService; C:\Program Files\Acer\Registration\GREGsvc.exe [36456 2011-05-30] (Acer Incorporated) R2 IconMan_R; C:\Program Files\Realtek\Realtek PCIE Card Reader\RIconMan.exe [1755136 2011-03-07] (Realsil Microelectronics Inc.) S2 Live Updater Service; C:\Program Files\Acer\Acer Updater\UpdaterService.exe [255376 2012-04-05] (Acer Incorporated) R2 PassThru Service; C:\Program Files\HTC\Internet Pass-Through\PassThruSvr.exe [166912 2012-10-08] () R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [260640 2010-01-30] (Acer Incorporated) ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2014-02-14] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2014-02-14] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2014-02-14] (Avira Operations GmbH & Co. KG) S3 btwampfl; C:\Windows\system32\drivers\btwampfl.sys [525352 2011-08-30] (Broadcom Corporation.) S3 BTWDPAN; C:\Windows\System32\DRIVERS\btwdpan.sys [76328 2011-08-30] (Broadcom Corporation.) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [13560 2013-04-11] (GFI Software) R1 mwlPSDFilter; C:\Windows\System32\DRIVERS\mwlPSDFilter.sys [21600 2011-12-16] (Egis Technology Inc.) R1 mwlPSDNServ; C:\Windows\System32\DRIVERS\mwlPSDNServ.sys [16936 2011-12-16] (Egis Technology Inc.) R1 mwlPSDVDisk; C:\Windows\System32\DRIVERS\mwlPSDVDisk.sys [62240 2011-12-16] (Egis Technology Inc.) R3 RSPCIESTOR; C:\Windows\System32\DRIVERS\RtsPStor.sys [254056 2011-05-30] (Realtek Semiconductor Corp.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2014-02-14] (Avira GmbH) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-05 21:17 - 2014-05-05 21:23 - 00008371 _____ () C:\Users\Mattis\Desktop\FRST.txt 2014-05-05 21:15 - 2014-05-05 21:15 - 00000000 ____D () C:\Users\Mattis\Desktop\FRST-OlderVersion 2014-05-05 19:36 - 2014-05-05 19:36 - 00000730 _____ () C:\Users\Mattis\Desktop\JRT.txt 2014-05-05 19:28 - 2014-05-05 19:28 - 00000000 ____D () C:\Windows\ERUNT 2014-05-05 19:26 - 2014-05-05 19:26 - 00000630 _____ () C:\Users\Mattis\Mattis - Verknüpfung.lnk 2014-05-05 19:02 - 2014-05-05 19:03 - 00008050 _____ () C:\Users\Mattis\Desktop\AdwCleaner[S0].txt 2014-05-05 18:57 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-05-05 18:55 - 2014-05-05 19:27 - 00000000 ____D () C:\AdwCleaner 2014-05-05 18:55 - 2014-05-05 18:55 - 01016261 _____ (Thisisu) C:\Users\Mattis\Desktop\JRT.exe 2014-05-05 18:53 - 2014-05-05 18:53 - 01316991 _____ () C:\Users\Mattis\Desktop\adwcleaner.exe 2014-05-05 17:08 - 2014-05-05 17:08 - 00004709 _____ () C:\Users\Mattis\Desktop\gmer.txt 2014-05-05 16:44 - 2014-05-05 16:44 - 00380416 _____ () C:\Users\Mattis\Desktop\Gmer-19357.exe 2014-05-05 16:39 - 2014-05-05 16:40 - 00027204 _____ () C:\Users\Mattis\Desktop\Addition.txt 2014-05-05 16:37 - 2014-05-05 21:23 - 00000000 ____D () C:\FRST 2014-05-05 16:37 - 2014-05-05 21:15 - 01053184 _____ (Farbar) C:\Users\Mattis\Desktop\FRST.exe 2014-05-05 16:34 - 2014-05-05 16:35 - 00000474 _____ () C:\Users\Mattis\Desktop\defogger_disable.log 2014-05-05 16:34 - 2014-05-05 16:34 - 00050477 _____ () C:\Users\Mattis\Desktop\Defogger.exe 2014-05-05 16:34 - 2014-05-05 16:34 - 00000000 _____ () C:\Users\Mattis\defogger_reenable 2014-05-05 16:18 - 2014-05-05 16:18 - 00448512 _____ (OldTimer Tools) C:\Users\Mattis\Desktop\TFC.exe 2014-05-05 15:17 - 2014-05-05 19:04 - 00001488 _____ () C:\Windows\PFRO.log 2014-05-05 15:17 - 2014-05-05 15:18 - 00144328 _____ () C:\Windows\Minidump\050514-18673-01.dmp 2014-05-05 15:17 - 2014-05-05 15:17 - 150675529 _____ () C:\Windows\MEMORY.DMP 2014-05-05 14:49 - 2014-05-05 19:04 - 00000224 _____ () C:\Windows\setupact.log 2014-05-05 14:49 - 2014-05-05 14:49 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-05 13:17 - 2014-05-05 13:17 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-05 13:16 - 2014-05-05 13:16 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-05 13:16 - 2014-05-05 13:16 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-05 13:16 - 2014-05-05 13:16 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-05-05 13:16 - 2014-04-03 09:51 - 00073432 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-05 13:16 - 2014-04-03 09:51 - 00051416 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-05 13:16 - 2014-04-03 09:50 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-05 13:15 - 2014-05-05 13:15 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Mattis\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-05 12:01 - 2014-05-05 12:01 - 00000000 ____D () C:\Windows\pss 2014-05-02 19:43 - 2014-05-02 19:43 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-30 10:49 - 2014-04-14 04:11 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-30 10:49 - 2014-04-14 04:07 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-29 17:32 - 2014-04-29 17:32 - 00002197 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-29 17:32 - 2014-04-29 17:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-04-29 17:31 - 2014-05-05 20:36 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-04-29 17:31 - 2014-05-05 19:04 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-04-29 17:31 - 2014-04-29 17:31 - 00000000 ____D () C:\Program Files\Google 2014-04-29 17:20 - 2014-04-29 17:20 - 00884688 _____ (Google Inc.) C:\Users\Mattis\Downloads\ChromeSetup.exe 2014-04-26 17:15 - 2014-04-26 17:16 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-04-24 14:12 - 2014-04-27 22:57 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-04-24 14:12 - 2014-04-24 14:12 - 00000000 ____D () C:\ProgramData\Mozilla 2014-04-24 10:32 - 2014-04-24 10:32 - 00000000 __SHD () C:\Users\Mattis\AppData\Local\EmieUserList 2014-04-24 10:32 - 2014-04-24 10:32 - 00000000 __SHD () C:\Users\Mattis\AppData\Local\EmieSiteList 2014-04-24 00:23 - 2014-04-24 00:23 - 00007607 _____ () C:\Users\Mattis\AppData\Local\Resmon.ResmonCfg 2014-04-16 22:21 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-04-16 22:21 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-04-16 22:21 - 2014-03-06 10:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2014-04-16 22:21 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2014-04-16 22:21 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2014-04-16 22:21 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2014-04-16 22:21 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2014-04-16 22:21 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2014-04-16 22:21 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2014-04-16 22:21 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2014-04-16 22:21 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2014-04-16 22:21 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2014-04-16 22:21 - 2014-03-06 09:38 - 00108032 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2014-04-16 22:21 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2014-04-16 22:21 - 2014-03-06 09:28 - 00646144 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2014-04-16 22:21 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2014-04-16 22:21 - 2014-03-06 09:18 - 00575488 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2014-04-16 22:21 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2014-04-16 22:21 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2014-04-16 22:21 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2014-04-16 22:21 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2014-04-16 22:21 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2014-04-16 22:21 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2014-04-16 22:21 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2014-04-16 22:21 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2014-04-16 22:21 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2014-04-10 10:10 - 2014-03-04 11:17 - 00868352 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll 2014-04-10 10:10 - 2014-02-04 04:07 - 00234432 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys 2014-04-10 10:10 - 2014-02-04 04:07 - 00149440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys 2014-04-10 10:10 - 2014-02-04 04:07 - 00027072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys 2014-04-10 10:10 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll 2014-04-10 10:10 - 2014-01-24 04:18 - 01212352 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys 2014-04-09 14:08 - 2014-04-09 14:08 - 00003442 _____ () C:\Users\Mattis\Downloads\Fusions.zip 2014-04-08 22:32 - 2014-04-08 22:32 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-04-08 22:32 - 2014-04-08 22:32 - 00000000 ____D () C:\Users\Mattis\AppData\Local\Skype 2014-04-08 22:32 - 2014-04-08 22:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-04-08 22:32 - 2014-04-08 22:32 - 00000000 ____D () C:\Program Files\Common Files\Skype ==================== One Month Modified Files and Folders ======= 2014-05-05 21:23 - 2014-05-05 21:17 - 00008371 _____ () C:\Users\Mattis\Desktop\FRST.txt 2014-05-05 21:23 - 2014-05-05 16:37 - 00000000 ____D () C:\FRST 2014-05-05 21:15 - 2014-05-05 21:15 - 00000000 ____D () C:\Users\Mattis\Desktop\FRST-OlderVersion 2014-05-05 21:15 - 2014-05-05 16:37 - 01053184 _____ (Farbar) C:\Users\Mattis\Desktop\FRST.exe 2014-05-05 20:36 - 2014-04-29 17:31 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-05-05 19:36 - 2014-05-05 19:36 - 00000730 _____ () C:\Users\Mattis\Desktop\JRT.txt 2014-05-05 19:28 - 2014-05-05 19:28 - 00000000 ____D () C:\Windows\ERUNT 2014-05-05 19:27 - 2014-05-05 18:55 - 00000000 ____D () C:\AdwCleaner 2014-05-05 19:26 - 2014-05-05 19:26 - 00000630 _____ () C:\Users\Mattis\Mattis - Verknüpfung.lnk 2014-05-05 19:26 - 2012-07-14 11:00 - 00000000 ____D () C:\Users\Mattis 2014-05-05 19:12 - 2009-07-14 06:34 - 00016160 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-05 19:12 - 2009-07-14 06:34 - 00016160 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-05 19:09 - 2014-03-27 20:51 - 00956804 _____ () C:\Windows\WindowsUpdate.log 2014-05-05 19:04 - 2014-05-05 15:17 - 00001488 _____ () C:\Windows\PFRO.log 2014-05-05 19:04 - 2014-05-05 14:49 - 00000224 _____ () C:\Windows\setupact.log 2014-05-05 19:04 - 2014-04-29 17:31 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-05-05 19:04 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-05 19:03 - 2014-05-05 19:02 - 00008050 _____ () C:\Users\Mattis\Desktop\AdwCleaner[S0].txt 2014-05-05 18:55 - 2014-05-05 18:55 - 01016261 _____ (Thisisu) C:\Users\Mattis\Desktop\JRT.exe 2014-05-05 18:53 - 2014-05-05 18:53 - 01316991 _____ () C:\Users\Mattis\Desktop\adwcleaner.exe 2014-05-05 18:17 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\LogFiles 2014-05-05 17:08 - 2014-05-05 17:08 - 00004709 _____ () C:\Users\Mattis\Desktop\gmer.txt 2014-05-05 16:44 - 2014-05-05 16:44 - 00380416 _____ () C:\Users\Mattis\Desktop\Gmer-19357.exe 2014-05-05 16:40 - 2014-05-05 16:39 - 00027204 _____ () C:\Users\Mattis\Desktop\Addition.txt 2014-05-05 16:35 - 2014-05-05 16:34 - 00000474 _____ () C:\Users\Mattis\Desktop\defogger_disable.log 2014-05-05 16:34 - 2014-05-05 16:34 - 00050477 _____ () C:\Users\Mattis\Desktop\Defogger.exe 2014-05-05 16:34 - 2014-05-05 16:34 - 00000000 _____ () C:\Users\Mattis\defogger_reenable 2014-05-05 16:18 - 2014-05-05 16:18 - 00448512 _____ (OldTimer Tools) C:\Users\Mattis\Desktop\TFC.exe 2014-05-05 15:18 - 2014-05-05 15:17 - 00144328 _____ () C:\Windows\Minidump\050514-18673-01.dmp 2014-05-05 15:17 - 2014-05-05 15:17 - 150675529 _____ () C:\Windows\MEMORY.DMP 2014-05-05 15:17 - 2012-10-18 13:37 - 00000000 ____D () C:\Windows\Minidump 2014-05-05 14:49 - 2014-05-05 14:49 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-05 13:17 - 2014-05-05 13:17 - 00107736 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-05 13:16 - 2014-05-05 13:16 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-05 13:16 - 2014-05-05 13:16 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-05 13:16 - 2014-05-05 13:16 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-05-05 13:15 - 2014-05-05 13:15 - 17305616 _____ (Malwarebytes Corporation ) C:\Users\Mattis\Downloads\mbam-setup-2.0.1.1004.exe 2014-05-05 12:01 - 2014-05-05 12:01 - 00000000 ____D () C:\Windows\pss 2014-05-02 19:43 - 2014-05-02 19:43 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-04-29 17:32 - 2014-04-29 17:32 - 00002197 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-04-29 17:32 - 2014-04-29 17:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome 2014-04-29 17:32 - 2012-07-14 11:42 - 00000000 ____D () C:\Users\Mattis\AppData\Local\Google 2014-04-29 17:31 - 2014-04-29 17:31 - 00000000 ____D () C:\Program Files\Google 2014-04-29 17:20 - 2014-04-29 17:20 - 00884688 _____ (Google Inc.) C:\Users\Mattis\Downloads\ChromeSetup.exe 2014-04-29 17:16 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-04-29 11:14 - 2010-11-20 23:01 - 01619284 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-04-27 23:31 - 2013-07-09 00:34 - 00000000 ____D () C:\Users\Mattis\AppData\Roaming\vlc 2014-04-27 22:57 - 2014-04-24 14:12 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-04-26 17:16 - 2014-04-26 17:15 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-04-24 14:12 - 2014-04-24 14:12 - 00000000 ____D () C:\ProgramData\Mozilla 2014-04-24 13:22 - 2012-09-19 21:00 - 00000000 ____D () C:\Users\Mattis\AppData\Roaming\Skype 2014-04-24 13:13 - 2012-07-26 11:13 - 00000000 ____D () C:\Users\Mattis\AppData\Local\Adobe 2014-04-24 13:12 - 2012-08-21 14:06 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-04-24 13:12 - 2011-12-16 11:55 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-04-24 13:12 - 2011-12-16 11:23 - 00000000 ____D () C:\ProgramData\McAfee 2014-04-24 12:26 - 2013-04-29 16:18 - 00000000 ____D () C:\Users\Mattis\Documents\BIWI 2014-04-24 10:32 - 2014-04-24 10:32 - 00000000 __SHD () C:\Users\Mattis\AppData\Local\EmieUserList 2014-04-24 10:32 - 2014-04-24 10:32 - 00000000 __SHD () C:\Users\Mattis\AppData\Local\EmieSiteList 2014-04-24 00:23 - 2014-04-24 00:23 - 00007607 _____ () C:\Users\Mattis\AppData\Local\Resmon.ResmonCfg 2014-04-17 10:20 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-04-15 23:28 - 2013-04-29 16:19 - 00000000 ____D () C:\Users\Mattis\Documents\Sport 2014-04-14 04:11 - 2014-04-30 10:49 - 00361984 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-04-14 04:07 - 2014-04-30 10:49 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-04-11 12:01 - 2013-08-21 23:56 - 00000000 ____D () C:\Windows\system32\MRT 2014-04-11 11:55 - 2012-07-14 15:06 - 88028728 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-04-09 14:08 - 2014-04-09 14:08 - 00003442 _____ () C:\Users\Mattis\Downloads\Fusions.zip 2014-04-09 10:24 - 2013-11-04 12:06 - 00000000 ____D () C:\Users\Mattis\Documents\Englisch 2014-04-08 22:32 - 2014-04-08 22:32 - 00002687 _____ () C:\Users\Public\Desktop\Skype.lnk 2014-04-08 22:32 - 2014-04-08 22:32 - 00000000 ____D () C:\Users\Mattis\AppData\Local\Skype 2014-04-08 22:32 - 2014-04-08 22:32 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype 2014-04-08 22:32 - 2014-04-08 22:32 - 00000000 ____D () C:\Program Files\Common Files\Skype 2014-04-08 22:32 - 2012-09-19 20:58 - 00000000 ___RD () C:\Program Files\Skype 2014-04-08 22:32 - 2011-12-16 11:22 - 00000000 ____D () C:\ProgramData\Skype Some content of TEMP: ==================== C:\Users\Mattis\AppData\Local\Temp\avgnt.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe => MD5 is legit C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-04-29 17:00 ==================== End Of Log ============================ Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Starter x86 Ran by Mattis on 05.05.2014 at 19:28:35,81 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\Mattis\appdata\local\{B75921FB-CCE3-429F-AAE8-E00E62B5BF06} ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 05.05.2014 at 19:36:12,20 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter # AdwCleaner v3.207 - Bericht erstellt am 05/05/2014 um 19:02:53 # Aktualisiert 05/05/2014 von Xplode # Betriebssystem : Windows 7 Starter Service Pack 1 (32 bits) # Benutzername : Mattis - MATTIS-PC # Gestartet von : C:\Users\Mattis\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\blekko toolbars Ordner Gelöscht : C:\Program Files\adawaretb Ordner Gelöscht : C:\Program Files\Red Sky Ordner Gelöscht : C:\Program Files\Toolbar Cleaner Ordner Gelöscht : C:\Windows\system32\SearchProtect Ordner Gelöscht : C:\Users\Mattis\AppData\Local\DownTango Ordner Gelöscht : C:\Users\Mattis\AppData\LocalLow\adawaretb Ordner Gelöscht : C:\Users\Mattis\AppData\Roaming\dvdvideosoftiehelpers Ordner Gelöscht : C:\Users\Mattis\AppData\Roaming\Windows Net Data Datei Gelöscht : C:\END ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Wert Gelöscht : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [webbooster@iminent.com] Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\mkcedibhemacmilmkpndpkoidlnmgngg Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\adawarebp_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\adawarebp_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\privitizevpn_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_divx-plus_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\SoftonicDownloader_fuer_divx-plus_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{C007DADD-132A-624C-088E-59EE6CF0711F} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{628F3201-34D0-49C0-BB9A-82A26AEFB291} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} Schlüssel Gelöscht : HKCU\Software\Softonic Schlüssel Gelöscht : HKLM\Software\adawaretb Schlüssel Gelöscht : HKLM\Software\Toolbar Cleaner Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\0238BBE24EA3A70408B81E4BB89C15E5 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\08121C32A9C319F4CB0C11FF059552A4 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\29799DE249E7DBC459FC6C8F07EB8375 Schlüssel Gelöscht : HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\F7652513C62FF63448CFF05163719DB7 ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17041 -\\ Mozilla Firefox v28.0 (de) [ Datei : C:\Users\Mattis\AppData\Roaming\Mozilla\Firefox\Profiles\gc8syzt9.default-1399302690413\prefs.js ] -\\ Google Chrome v34.0.1847.131 [ Datei : C:\Users\Mattis\AppData\Local\Google\Chrome\User Data\Default\preferences ] Gelöscht [Extension] : mkcedibhemacmilmkpndpkoidlnmgngg ************************* AdwCleaner[R0].txt - [7989 octets] - [05/05/2014 18:55:56] AdwCleaner[S0].txt - [7910 octets] - [05/05/2014 19:02:53] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7970 octets] ########## [/CODE] |
06.05.2014, 16:30 | #4 |
/// the machine /// TB-Ausbilder | Windows 7 starter: Leistung des PC hat deutlich nachgelassen.ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
07.05.2014, 17:55 | #5 |
| Windows 7 starter: Leistung des PC hat deutlich nachgelassen. Ja es läuft deutlich flüssiger!! vielen dank! Muss ich trotzdem alle log files posten oder erübrigt sich das? die dienste haben beide nichts gefunden. |
08.05.2014, 10:42 | #6 |
/// the machine /// TB-Ausbilder | Windows 7 starter: Leistung des PC hat deutlich nachgelassen. Ja bitte
__________________ --> Windows 7 starter: Leistung des PC hat deutlich nachgelassen. |
Themen zu Windows 7 starter: Leistung des PC hat deutlich nachgelassen. |
akamai, antivir, antivirus, avira, browser, converter, defender, desktop, device driver, dvdvideosoft ltd., error, explorer, firefox, flash player, helper, homepage, langsam, launch, leistung, mozilla, msiexec.exe, pmmupdate.exe, programm, realtek, registry, security, services.exe, software, super, svchost.exe, system, temp, trojaner, virus, windows |