Hallo zusammen, seit ein paar tagen öffnet sich eine bestimmte Internetseite auf mein Laptop sehr extrem langsam. Es handelt sich um die online Bildzeitung. Ich hab es schon mit verschieden Browsern "aktuell Firefox 29.0.1" auf meinem Laptop versucht aber genau diese eine seite dauert minutenlang bis sie sich öffnet trotz "glasfaser internet". Auch verschiedene laptops oder mit mein smartphone gibt es diese probleme nicht dieser langsame internetseiten aufbau ist auch ausschlieslich auf mein laptop :-( und nur bei der einen gesagten internetseite. Habe win7! otl hab ich ausgeführt. Wäre sehr nett von euch, wenn mir jemand bitte helfen würde, Danke. Gruß Marco
![]() | #2 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Eine bestimmte Internetseite öffnet sich ganz extrem langsam und das auch noch mit fehlern! hi,
__________________andere Rechner in deinem Netz haben das nicht? Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
![]() | #3 |
![]() ![]() ![]() ![]() | ![]() Eine bestimmte Internetseite öffnet sich ganz extrem langsam und das auch noch mit fehlern! Hallo.
__________________Nein es geht ausschließlich um meinen Laptop. Bei meiner frau ihren Laptop und selbst bei den Smartphone´s öffnet sich diese seite ruck zuck problemlos. hier die gewünschte info´s. Danke schon mal :-) für die Hilfe. FRST Logfile: Code:
![]() | #4 | |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Eine bestimmte Internetseite öffnet sich ganz extrem langsam und das auch noch mit fehlern! welche Seite? Zitat:
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #5 |
![]() ![]() ![]() ![]() | ![]() Eine bestimmte Internetseite öffnet sich ganz extrem langsam und das auch noch mit fehlern! Hallo. die seite ist www.bild.de "Bildzeitung", sie läd und läd und läd, nach 15 min ist sie fehlerhaft aufgebaut, dieses Problem ist nur auf mein rechner und so wie ich mit bekommen hab erst seit paar tagen. Ob andere seiten noch betroffen sind kann ich momentan nicht bestätigen, hab keine weitere gefunden. Adobe? Hm das weis ich nicht, wenn dann wasch ich meine Hände in unschuld, mei Schwager hat was Installiert für meine Frau um Bilder oder so zu bearbeiten da Ihr Rechner nicht die vorraussetzung angeblich "win7" hatte. Diese Installation ist aber bestimmmt schon 2 Jahre her, sie braucht das ab und zu um unsere KinderBilder zu bearbeiten. Was soll ich jetzt machen wegen der besagten seite die sich sehr schlecht und dann noch fehlerhaft aufbaut? Vorab schon mal VielenDanke. Gruß Marco |
![]() | #6 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Eine bestimmte Internetseite öffnet sich ganz extrem langsam und das auch noch mit fehlern! Erstmal das Adobe Photoshop deinstallieren. Das ist illegal und solange das drauf ist gibt es keinen Support.
__________________ --> Eine bestimmte Internetseite öffnet sich ganz extrem langsam und das auch noch mit fehlern! |
![]() | #7 |
![]() ![]() ![]() ![]() | ![]() Eine bestimmte Internetseite öffnet sich ganz extrem langsam und das auch noch mit fehlern! Da killt mich mei Frau, naja ist deinstalliert:-)! Gruß |
![]() | #8 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Eine bestimmte Internetseite öffnet sich ganz extrem langsam und das auch noch mit fehlern! FRST öffnen, Haken setzen bei Additional und scannen, poste bitte beide Logfiles.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #9 |
![]() ![]() ![]() ![]() | ![]() Eine bestimmte Internetseite öffnet sich ganz extrem langsam und das auch noch mit fehlern! Bitteschön. Wobei ich sagen muss das die genannte seite schon etwas schneller nun funktioniert! Code:
Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\wz9o2ng6.default-1385406802750 FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @java.com/DTPlugin,version=10.15.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.15.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DownloadHelper - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\wz9o2ng6.default-1385406802750\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-29] FF Extension: Tabs On Bottom - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\wz9o2ng6.default-1385406802750\Extensions\tabsonbottom@piro.sakura.ne.jp.xpi [2014-05-14] FF HKLM\...\Firefox\Extensions: [url_advisor@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2013-12-25] FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2013-12-25] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2013-12-25] FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Chặn quảng cáo - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2013-12-25] FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2013-12-25] Chrome: ======= CHR HomePage: CHR Extension: (Google Docs) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-24] CHR Extension: (Google Drive) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-24] CHR Extension: (Kaspersky Protection) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\blbkdnmdcafmfhinpmnlhhddbepgkeaa [2014-05-24] CHR Extension: (YouTube) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-24] CHR Extension: (Google Search) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-24] CHR Extension: (Kaspersky URL Advisor) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-05-24] CHR Extension: (Safe Money) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-05-24] CHR Extension: (Dangerous Websites Blocker) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-05-24] CHR Extension: (Virtual Keyboard) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-05-24] CHR Extension: (Google Wallet) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-24] CHR Extension: (Gmail) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-24] CHR Extension: (Anti-Banner) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-05-24] CHR HKLM\...\Chrome\Extension: [blbkdnmdcafmfhinpmnlhhddbepgkeaa] - https://chrome.google.com/webstore/detail/blbkdnmdcafmfhinpmnlhhddbepgkeaa [2014-05-24] CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ========================== Services (Whitelisted) ================= R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] () R2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) R2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [26248 2012-10-19] (EldoS Corporation) R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2013-12-25] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [94304 2014-03-25] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-03-25] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-02-18] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2013-12-25] (Kaspersky Lab ZAO) R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation) R3 MBAMSwissArmy; C:\Windows\system32\drivers\MBAMSwissArmy.sys [110296 2014-05-27] (Malwarebytes Corporation) R3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation) R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] () U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-27 18:57 - 2014-05-27 18:58 - 00015658 _____ () C:\Users\Marco\Desktop\FRST.txt 2014-05-27 18:56 - 2014-05-27 18:56 - 00000000 ____D () C:\Users\Marco\Desktop\FRST-OlderVersion 2014-05-26 19:25 - 2014-05-26 19:25 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\No Company Name 2014-05-25 12:44 - 2014-05-25 12:44 - 00001340 _____ () C:\Users\Marco\Desktop\AdwCleaner[S2]3.txt 2014-05-25 12:41 - 2014-05-25 12:41 - 00001220 _____ () C:\Users\Marco\Desktop\AdwCleaner[S1]2.txt 2014-05-25 12:37 - 2014-05-25 12:37 - 00001582 _____ () C:\Users\Marco\Desktop\AdwCleaner[S0]1.txt 2014-05-25 12:34 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-05-25 12:33 - 2014-05-25 12:45 - 00000000 ____D () C:\AdwCleaner 2014-05-25 12:22 - 2014-05-27 06:10 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-25 12:21 - 2014-05-25 12:21 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-25 12:21 - 2014-05-25 12:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-25 12:21 - 2014-05-25 12:21 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-05-25 12:21 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-25 12:21 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-25 12:21 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-25 11:20 - 2014-05-25 11:20 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Marco\Desktop\mbam-setup- 2014-05-25 11:19 - 2014-05-25 11:19 - 01326389 _____ () C:\Users\Marco\Desktop\adwcleaner_3.210.exe 2014-05-25 11:16 - 2014-05-25 11:16 - 05200426 _____ (Swearware) C:\Users\Marco\Desktop\ComboFix.exe 2014-05-25 08:49 - 2014-05-25 08:49 - 00001226 _____ () C:\Users\Marco\Desktop\Revo Uninstaller.lnk 2014-05-25 08:49 - 2014-05-25 08:49 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-05-25 08:18 - 2014-05-27 18:57 - 00000000 ____D () C:\FRST 2014-05-25 08:14 - 2014-05-27 18:56 - 01056256 _____ (Farbar) C:\Users\Marco\Desktop\FRST.exe 2014-05-25 05:39 - 2014-05-25 05:39 - 453816381 _____ () C:\Windows\MEMORY.DMP 2014-05-25 05:39 - 2014-05-25 05:39 - 00180944 _____ () C:\Windows\Minidump\052514-24180-01.dmp 2014-05-24 20:36 - 2014-05-25 08:16 - 00000000 ____D () C:\Program Files\Google 2014-05-24 20:36 - 2014-05-24 20:37 - 00000000 ____D () C:\Users\Marco\AppData\Local\Google 2014-05-24 20:21 - 2014-05-25 12:43 - 00002684 _____ () C:\Windows\PFRO.log 2014-05-24 20:09 - 2014-05-24 20:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-24 19:37 - 2014-05-24 19:37 - 00000000 __SHD () C:\Users\Marco\AppData\Local\EmieUserList 2014-05-24 19:37 - 2014-05-24 19:37 - 00000000 __SHD () C:\Users\Marco\AppData\Local\EmieSiteList 2014-05-24 07:17 - 2014-05-25 12:44 - 00000336 _____ () C:\Windows\setupact.log 2014-05-24 07:17 - 2014-05-24 07:17 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-15 06:03 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 06:03 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 06:02 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-14 16:52 - 2014-05-09 09:06 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-14 16:52 - 2014-05-09 09:04 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-14 16:52 - 2014-04-12 04:15 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-14 16:52 - 2014-04-12 04:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-14 16:52 - 2014-04-12 04:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-14 16:52 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-14 16:52 - 2014-04-12 04:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-14 16:52 - 2014-04-12 04:11 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-14 16:52 - 2014-04-12 04:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-14 16:52 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2014-05-14 16:52 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-14 16:52 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-14 16:52 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-14 16:51 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-10 13:42 - 2014-05-10 13:42 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-08 06:05 - 2014-05-15 17:00 - 00000000 ___SD () C:\Windows\system32\CompatTel ==================== One Month Modified Files and Folders ======= 2014-05-27 18:58 - 2014-05-27 18:57 - 00015658 _____ () C:\Users\Marco\Desktop\FRST.txt 2014-05-27 18:58 - 2012-02-16 20:09 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-05-27 18:57 - 2014-05-25 08:18 - 00000000 ____D () C:\FRST 2014-05-27 18:56 - 2014-05-27 18:56 - 00000000 ____D () C:\Users\Marco\Desktop\FRST-OlderVersion 2014-05-27 18:56 - 2014-05-25 08:14 - 01056256 _____ (Farbar) C:\Users\Marco\Desktop\FRST.exe 2014-05-27 18:54 - 2012-02-16 19:45 - 01761890 _____ () C:\Windows\WindowsUpdate.log 2014-05-27 06:10 - 2014-05-25 12:22 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-26 19:49 - 2012-02-17 00:20 - 00110824 _____ () C:\Users\Marco\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-26 19:26 - 2012-02-17 18:08 - 00000000 ____D () C:\ProgramData\Adobe 2014-05-26 19:26 - 2012-02-17 18:08 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-05-26 19:25 - 2014-05-26 19:25 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\No Company Name 2014-05-26 19:25 - 2012-02-17 18:08 - 00000000 ____D () C:\Program Files\Adobe 2014-05-25 12:51 - 2009-07-14 06:34 - 00014928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-25 12:51 - 2009-07-14 06:34 - 00014928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-25 12:45 - 2014-05-25 12:33 - 00000000 ____D () C:\AdwCleaner 2014-05-25 12:44 - 2014-05-25 12:44 - 00001340 _____ () C:\Users\Marco\Desktop\AdwCleaner[S2]3.txt 2014-05-25 12:44 - 2014-05-24 07:17 - 00000336 _____ () C:\Windows\setupact.log 2014-05-25 12:44 - 2012-03-20 21:20 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-05-25 12:44 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-25 12:43 - 2014-05-24 20:21 - 00002684 _____ () C:\Windows\PFRO.log 2014-05-25 12:41 - 2014-05-25 12:41 - 00001220 _____ () C:\Users\Marco\Desktop\AdwCleaner[S1]2.txt 2014-05-25 12:37 - 2014-05-25 12:37 - 00001582 _____ () C:\Users\Marco\Desktop\AdwCleaner[S0]1.txt 2014-05-25 12:21 - 2014-05-25 12:21 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-25 12:21 - 2014-05-25 12:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-25 12:21 - 2014-05-25 12:21 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-05-25 11:20 - 2014-05-25 11:20 - 17292760 _____ (Malwarebytes Corporation ) C:\Users\Marco\Desktop\mbam-setup- 2014-05-25 11:19 - 2014-05-25 11:19 - 01326389 _____ () C:\Users\Marco\Desktop\adwcleaner_3.210.exe 2014-05-25 11:16 - 2014-05-25 11:16 - 05200426 _____ (Swearware) C:\Users\Marco\Desktop\ComboFix.exe 2014-05-25 08:49 - 2014-05-25 08:49 - 00001226 _____ () C:\Users\Marco\Desktop\Revo Uninstaller.lnk 2014-05-25 08:49 - 2014-05-25 08:49 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-05-25 08:16 - 2014-05-24 20:36 - 00000000 ____D () C:\Program Files\Google 2014-05-25 05:39 - 2014-05-25 05:39 - 453816381 _____ () C:\Windows\MEMORY.DMP 2014-05-25 05:39 - 2014-05-25 05:39 - 00180944 _____ () C:\Windows\Minidump\052514-24180-01.dmp 2014-05-25 05:39 - 2012-04-09 10:01 - 00000000 ____D () C:\Windows\Minidump 2014-05-24 20:37 - 2014-05-24 20:36 - 00000000 ____D () C:\Users\Marco\AppData\Local\Google 2014-05-24 20:21 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\Performance 2014-05-24 20:09 - 2014-05-24 20:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-24 19:37 - 2014-05-24 19:37 - 00000000 __SHD () C:\Users\Marco\AppData\Local\EmieUserList 2014-05-24 19:37 - 2014-05-24 19:37 - 00000000 __SHD () C:\Users\Marco\AppData\Local\EmieSiteList 2014-05-24 07:17 - 2014-05-24 07:17 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-22 19:57 - 2012-02-18 14:09 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-05-22 19:49 - 2012-02-17 18:57 - 00000969 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-05-22 19:49 - 2012-02-17 18:57 - 00000000 ____D () C:\Program Files\CCleaner 2014-05-22 19:44 - 2014-01-14 21:04 - 00000000 ____D () C:\Users\Marco\Desktop\Bau 2014-05-22 19:44 - 2014-01-03 21:16 - 00000000 ____D () C:\Users\Marco\Desktop\LOGO 2014-05-22 19:44 - 2012-04-21 14:23 - 00000000 ____D () C:\Users\Marco\Desktop\Leni 2014-05-21 19:45 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-05-21 19:07 - 2012-03-31 15:22 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-05-21 19:07 - 2012-02-17 00:35 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-05-15 19:02 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-05-15 17:02 - 2012-05-12 11:35 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-05-15 17:00 - 2014-05-08 06:05 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-15 17:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-05-15 06:09 - 2013-08-15 06:21 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-15 06:07 - 2012-02-16 21:06 - 90547776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-14 19:27 - 2012-02-22 19:58 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-05-14 19:21 - 2013-10-29 18:41 - 00000000 ____D () C:\Users\Marco\AppData\Local\Room Arranger 2014-05-12 07:26 - 2014-05-25 12:21 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-05-25 12:21 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:25 - 2014-05-25 12:21 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-10 13:42 - 2014-05-10 13:42 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-10 13:22 - 2012-02-17 18:54 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\vlc 2014-05-09 09:06 - 2014-05-14 16:52 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 09:04 - 2014-05-14 16:52 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-06 05:25 - 2014-05-15 06:03 - 17382912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 05:07 - 2014-05-15 06:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-06 04:10 - 2014-05-15 06:03 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-04-27 15:14 - 2012-02-27 18:13 - 00000000 ____D () C:\Users\Marco\AppData\Local\Canon Easy-PhotoPrint EX 2014-04-27 13:09 - 2012-02-26 19:41 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\Canon 2014-04-27 12:53 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\system32\FxsTmp Some content of TEMP: ==================== C:\Users\Marco\AppData\Local\Temp\readSTILog.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe [2014-05-14 16:52] - [2014-03-04 11:17] - 0304128 ____A (Microsoft Corporation) 998507B046BA314CE8245364C686FA67 C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-21 19:37 ==================== End Of Log ============================ --- --- --- Geändert von stone1979 (27.05.2014 um 18:11 Uhr) |
Eine bestimmte Internetseite öffnet sich ganz extrem langsam und das auch noch mit fehlern! Downloade Dir bitte
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
Eine bestimmte Internetseite öffnet sich ganz extrem langsam und das auch noch mit fehlern! So, ich hoffe ich hab alles richtig gemacht! Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 29.05.2014 Suchlauf-Zeit: 12:57:57 Logdatei: Malwarebytes Anti-Malware .txt Administrator: Ja Version: Malware Datenbank: v2014.05.29.05 Rootkit Datenbank: v2014.05.21.01 Lizenz: Testversion Malware Schutz: Aktiviert Bösartiger Webseiten Schutz: Aktiviert Self-protection: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x86 Dateisystem: NTFS Benutzer: Marco Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 277624 Verstrichene Zeit: 7 Min, 11 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristics: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (No malicious items detected) Module: 0 (No malicious items detected) Registrierungsschlüssel: 0 (No malicious items detected) Registrierungswerte: 0 (No malicious items detected) Registrierungsdaten: 0 (No malicious items detected) Ordner: 0 (No malicious items detected) Dateien: 0 (No malicious items detected) Physische Sektoren: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v3.211 - Bericht erstellt am 29/05/2014 um 13:14:02 # Aktualisiert 26/05/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (32 bits) # Benutzername : Marco - MARCO-PC # Gestartet von : C:\Users\Marco\Desktop\adwcleaner_3.211.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\blbkdnmdcafmfhinpmnlhhddbepgkeaa ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\blbkdnmdcafmfhinpmnlhhddbepgkeaa Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.17041 -\\ Mozilla Firefox v29.0.1 (de) [ Datei : C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\6dp35kc7.default\prefs.js ] [ Datei : C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\wz9o2ng6.default-1385406802750\prefs.js ] -\\ Google Chrome v [ Datei : C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [1521 octets] - [25/05/2014 12:34:09] AdwCleaner[R1].txt - [1158 octets] - [25/05/2014 12:38:11] AdwCleaner[R2].txt - [1279 octets] - [25/05/2014 12:41:41] AdwCleaner[R3].txt - [1399 octets] - [25/05/2014 12:45:00] AdwCleaner[R4].txt - [1733 octets] - [29/05/2014 13:11:46] AdwCleaner[S0].txt - [1582 octets] - [25/05/2014 12:35:14] AdwCleaner[S1].txt - [1220 octets] - [25/05/2014 12:39:40] AdwCleaner[S2].txt - [1340 octets] - [25/05/2014 12:43:14] AdwCleaner[S3].txt - [1654 octets] - [29/05/2014 13:14:02] ########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1714 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 7 Home Premium x86 Ran by Marco on 29.05.2014 at 13:25:49,28 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ FireFox Emptied folder: C:\Users\Marco\AppData\Roaming\mozilla\firefox\profiles\wz9o2ng6.default-1385406802750\minidumps [22 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 29.05.2014 at 13:30:25,90 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:25-05-2014 02 Ran by Marco (administrator) on MARCO-PC on 29-05-2014 13:38:19 Running from C:\Users\Marco\Desktop Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\Canon\IJPLM\ijplmsvc.exe (Nero AG) C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (Creative Technology Ltd.) C:\Windows\OEM02Mon.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (CANON INC.) C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\wmi32.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [OEM02Mon.exe] => C:\Windows\OEM02Mon.exe [36864 2007-05-09] (Creative Technology Ltd.) HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-06] (Apple Inc.) HKLM\...\Run: [IJNetworkScanUtility] => C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [140640 2010-03-02] (CANON INC.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKU\S-1-5-21-3504130025-3935686371-3975182874-1001\...\Run: [MobileDocuments] => C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.) HKU\S-1-5-21-3504130025-3935686371-3975182874-1001\...\MountPoints2: {28a161f0-f6d1-11e1-a962-001e4ce44100} - "E:\WD SmartWare.exe" autoplay=true HKU\S-1-5-21-3504130025-3935686371-3975182874-1001\...\MountPoints2: {ef947d6c-5982-11e1-9b36-001e4ce44100} - E:\LaunchU3.exe -a Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (No File) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (No File) Startup: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9F6C28D96213CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE SearchScopes: HKLM - DefaultScope value is missing. BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\wz9o2ng6.default-1385406802750 FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @java.com/DTPlugin,version=10.15.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.15.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DownloadHelper - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\wz9o2ng6.default-1385406802750\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-29] FF Extension: Tabs On Bottom - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\wz9o2ng6.default-1385406802750\Extensions\tabsonbottom@piro.sakura.ne.jp.xpi [2014-05-14] FF HKLM\...\Firefox\Extensions: [url_advisor@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2013-12-25] FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2013-12-25] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2013-12-25] FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Chặn quảng cáo - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2013-12-25] FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2013-12-25] Chrome: ======= CHR HomePage: CHR Extension: (Google Docs) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-24] CHR Extension: (Google Drive) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-24] CHR Extension: (No Name) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\blbkdnmdcafmfhinpmnlhhddbepgkeaa [2014-05-24] CHR Extension: (YouTube) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-24] CHR Extension: (Google Search) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-24] CHR Extension: (Kaspersky URL Advisor) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-05-24] CHR Extension: (Safe Money) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-05-24] CHR Extension: (Dangerous Websites Blocker) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-05-24] CHR Extension: (Virtual Keyboard) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-05-24] CHR Extension: (Google Wallet) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-24] CHR Extension: (Gmail) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-24] CHR Extension: (Anti-Banner) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-05-24] CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ========================== Services (Whitelisted) ================= R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] () S2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [26248 2012-10-19] (EldoS Corporation) R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2013-12-25] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [94304 2014-03-25] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-03-25] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-02-18] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2013-12-25] (Kaspersky Lab ZAO) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation) R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] () U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-29 13:38 - 2014-05-29 13:38 - 00014563 _____ () C:\Users\Marco\Desktop\FRST.txt 2014-05-29 13:33 - 2014-05-29 13:34 - 01056256 _____ (Farbar) C:\Users\Marco\Desktop\FRST.exe 2014-05-29 13:31 - 2014-05-29 13:31 - 00000771 _____ () C:\Users\Marco\Desktop\JRT_.txt 2014-05-29 13:21 - 2014-05-29 13:21 - 00000000 ____D () C:\Windows\ERUNT 2014-05-29 13:19 - 2014-05-29 13:20 - 01016261 _____ (Thisisu) C:\Users\Marco\Desktop\JRT.exe 2014-05-29 13:18 - 2014-05-29 13:18 - 00001794 _____ () C:\Users\Marco\Desktop\AdwCleaner[S3].txt 2014-05-29 13:06 - 2014-05-29 13:06 - 00001177 _____ () C:\Users\Marco\Desktop\ Malwarebytes Anti-Malware .txt 2014-05-28 14:25 - 2014-05-28 14:27 - 00000000 ____D () C:\Users\Marco\Desktop\Bad 2014-05-27 18:56 - 2014-05-27 18:56 - 00000000 ____D () C:\Users\Marco\Desktop\FRST-OlderVersion 2014-05-26 19:25 - 2014-05-26 19:25 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\No Company Name 2014-05-25 12:34 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-05-25 12:33 - 2014-05-29 13:14 - 00000000 ____D () C:\AdwCleaner 2014-05-25 12:22 - 2014-05-29 13:36 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-25 12:21 - 2014-05-25 12:21 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-25 12:21 - 2014-05-25 12:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-25 12:21 - 2014-05-25 12:21 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-05-25 12:21 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-25 12:21 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-25 12:21 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-25 08:49 - 2014-05-25 08:49 - 00001226 _____ () C:\Users\Marco\Desktop\Revo Uninstaller.lnk 2014-05-25 08:49 - 2014-05-25 08:49 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-05-25 08:18 - 2014-05-29 13:38 - 00000000 ____D () C:\FRST 2014-05-25 05:39 - 2014-05-25 05:39 - 453816381 _____ () C:\Windows\MEMORY.DMP 2014-05-25 05:39 - 2014-05-25 05:39 - 00180944 _____ () C:\Windows\Minidump\052514-24180-01.dmp 2014-05-24 20:36 - 2014-05-25 08:16 - 00000000 ____D () C:\Program Files\Google 2014-05-24 20:36 - 2014-05-24 20:37 - 00000000 ____D () C:\Users\Marco\AppData\Local\Google 2014-05-24 20:21 - 2014-05-29 13:15 - 00002998 _____ () C:\Windows\PFRO.log 2014-05-24 20:09 - 2014-05-24 20:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-24 19:37 - 2014-05-24 19:37 - 00000000 __SHD () C:\Users\Marco\AppData\Local\EmieUserList 2014-05-24 19:37 - 2014-05-24 19:37 - 00000000 __SHD () C:\Users\Marco\AppData\Local\EmieSiteList 2014-05-24 07:17 - 2014-05-29 13:35 - 00000504 _____ () C:\Windows\setupact.log 2014-05-24 07:17 - 2014-05-24 07:17 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-15 06:03 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 06:03 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 06:02 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-14 16:52 - 2014-05-09 09:06 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-14 16:52 - 2014-05-09 09:04 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-14 16:52 - 2014-04-12 04:15 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-14 16:52 - 2014-04-12 04:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-14 16:52 - 2014-04-12 04:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-14 16:52 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-14 16:52 - 2014-04-12 04:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-14 16:52 - 2014-04-12 04:11 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-14 16:52 - 2014-04-12 04:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-14 16:52 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2014-05-14 16:52 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-14 16:52 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-14 16:52 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-14 16:51 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-10 13:42 - 2014-05-10 13:42 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-08 06:05 - 2014-05-15 17:00 - 00000000 ___SD () C:\Windows\system32\CompatTel ==================== One Month Modified Files and Folders ======= 2014-05-29 13:38 - 2014-05-29 13:38 - 00014563 _____ () C:\Users\Marco\Desktop\FRST.txt 2014-05-29 13:38 - 2014-05-25 08:18 - 00000000 ____D () C:\FRST 2014-05-29 13:38 - 2012-02-16 19:45 - 01804594 _____ () C:\Windows\WindowsUpdate.log 2014-05-29 13:36 - 2014-05-25 12:22 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-29 13:35 - 2014-05-24 07:17 - 00000504 _____ () C:\Windows\setupact.log 2014-05-29 13:35 - 2012-03-20 21:20 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-05-29 13:35 - 2012-02-16 20:09 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-05-29 13:35 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-29 13:34 - 2014-05-29 13:33 - 01056256 _____ (Farbar) C:\Users\Marco\Desktop\FRST.exe 2014-05-29 13:31 - 2014-05-29 13:31 - 00000771 _____ () C:\Users\Marco\Desktop\JRT_.txt 2014-05-29 13:29 - 2009-07-14 06:34 - 00014928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-29 13:29 - 2009-07-14 06:34 - 00014928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-29 13:21 - 2014-05-29 13:21 - 00000000 ____D () C:\Windows\ERUNT 2014-05-29 13:20 - 2014-05-29 13:19 - 01016261 _____ (Thisisu) C:\Users\Marco\Desktop\JRT.exe 2014-05-29 13:18 - 2014-05-29 13:18 - 00001794 _____ () C:\Users\Marco\Desktop\AdwCleaner[S3].txt 2014-05-29 13:16 - 2009-07-14 06:33 - 00421512 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-05-29 13:15 - 2014-05-24 20:21 - 00002998 _____ () C:\Windows\PFRO.log 2014-05-29 13:14 - 2014-05-25 12:33 - 00000000 ____D () C:\AdwCleaner 2014-05-29 13:06 - 2014-05-29 13:06 - 00001177 _____ () C:\Users\Marco\Desktop\ Malwarebytes Anti-Malware .txt 2014-05-29 12:53 - 2012-02-16 19:55 - 01629284 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-28 14:27 - 2014-05-28 14:25 - 00000000 ____D () C:\Users\Marco\Desktop\Bad 2014-05-27 18:56 - 2014-05-27 18:56 - 00000000 ____D () C:\Users\Marco\Desktop\FRST-OlderVersion 2014-05-26 19:49 - 2012-02-17 00:20 - 00110824 _____ () C:\Users\Marco\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-26 19:26 - 2012-02-17 18:08 - 00000000 ____D () C:\ProgramData\Adobe 2014-05-26 19:26 - 2012-02-17 18:08 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-05-26 19:25 - 2014-05-26 19:25 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\No Company Name 2014-05-26 19:25 - 2012-02-17 18:08 - 00000000 ____D () C:\Program Files\Adobe 2014-05-25 12:21 - 2014-05-25 12:21 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-25 12:21 - 2014-05-25 12:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-25 12:21 - 2014-05-25 12:21 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-05-25 08:49 - 2014-05-25 08:49 - 00001226 _____ () C:\Users\Marco\Desktop\Revo Uninstaller.lnk 2014-05-25 08:49 - 2014-05-25 08:49 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-05-25 08:16 - 2014-05-24 20:36 - 00000000 ____D () C:\Program Files\Google 2014-05-25 05:39 - 2014-05-25 05:39 - 453816381 _____ () C:\Windows\MEMORY.DMP 2014-05-25 05:39 - 2014-05-25 05:39 - 00180944 _____ () C:\Windows\Minidump\052514-24180-01.dmp 2014-05-25 05:39 - 2012-04-09 10:01 - 00000000 ____D () C:\Windows\Minidump 2014-05-24 20:37 - 2014-05-24 20:36 - 00000000 ____D () C:\Users\Marco\AppData\Local\Google 2014-05-24 20:21 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\Performance 2014-05-24 20:09 - 2014-05-24 20:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-24 19:37 - 2014-05-24 19:37 - 00000000 __SHD () C:\Users\Marco\AppData\Local\EmieUserList 2014-05-24 19:37 - 2014-05-24 19:37 - 00000000 __SHD () C:\Users\Marco\AppData\Local\EmieSiteList 2014-05-24 07:17 - 2014-05-24 07:17 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-22 19:57 - 2012-02-18 14:09 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-05-22 19:49 - 2012-02-17 18:57 - 00000969 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-05-22 19:49 - 2012-02-17 18:57 - 00000000 ____D () C:\Program Files\CCleaner 2014-05-22 19:44 - 2014-01-14 21:04 - 00000000 ____D () C:\Users\Marco\Desktop\Bau 2014-05-22 19:44 - 2014-01-03 21:16 - 00000000 ____D () C:\Users\Marco\Desktop\LOGO 2014-05-22 19:44 - 2012-04-21 14:23 - 00000000 ____D () C:\Users\Marco\Desktop\Leni 2014-05-21 19:45 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-05-21 19:07 - 2012-03-31 15:22 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-05-21 19:07 - 2012-02-17 00:35 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-05-15 19:02 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-05-15 17:02 - 2012-05-12 11:35 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-05-15 17:00 - 2014-05-08 06:05 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-15 17:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-05-15 06:09 - 2013-08-15 06:21 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-15 06:07 - 2012-02-16 21:06 - 90547776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-14 19:27 - 2012-02-22 19:58 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-05-14 19:21 - 2013-10-29 18:41 - 00000000 ____D () C:\Users\Marco\AppData\Local\Room Arranger 2014-05-12 07:26 - 2014-05-25 12:21 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-05-25 12:21 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:25 - 2014-05-25 12:21 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-10 13:42 - 2014-05-10 13:42 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-10 13:22 - 2012-02-17 18:54 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\vlc 2014-05-09 09:06 - 2014-05-14 16:52 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 09:04 - 2014-05-14 16:52 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-06 05:25 - 2014-05-15 06:03 - 17382912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 05:07 - 2014-05-15 06:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-06 04:10 - 2014-05-15 06:03 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll Some content of TEMP: ==================== C:\Users\Marco\AppData\Local\Temp\Quarantine.exe C:\Users\Marco\AppData\Local\Temp\readSTILog.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe [2014-05-14 16:52] - [2014-03-04 11:17] - 0304128 ____A (Microsoft Corporation) 998507B046BA314CE8245364C686FA67 C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-21 19:37 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:25-05-2014 02 Ran by Marco at 2014-05-29 13:38:55 Running from C:\Users\Marco\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Disabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Internet Security (Disabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Disabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== "Nero SoundTrax Help (Version: - Nero AG) Hidden 7-Zip 4.65 (HKLM\...\7-Zip) (Version: - ) Adobe AIR (HKLM\...\Adobe AIR) (Version: - Adobe Systems Incorporated) Adobe AIR (Version: - Adobe Systems Incorporated) Hidden Adobe Community Help (HKLM\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.) Adobe Community Help (Version: 3.5.23 - Adobe Systems Incorporated.) Hidden Adobe Flash Player 11 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated) Adobe Reader X (10.1.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated) Advertising Center (Version: - Nero AG) Hidden Apple Application Support (HKLM\...\{21FC2093-6E43-460B-B9B0-5F5AA35BBB0F}) (Version: 3.0 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{10E3A6DD-84D8-4D8A-BB11-5E5314BCA7FD}) (Version: - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: - Apple Inc.) Biet-O-Matic v2.8.3 (HKLM\...\Biet-O-Matic v2.8.3) (Version: Biet-O-Matic v2.8.3 - BOM Development Team) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: - Apple Inc.) Canon Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version: - ) Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data (HKLM\...\Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data) (Version: - ) Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data (HKLM\...\Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data) (Version: - ) Canon Easy-PhotoPrint Pro (HKLM\...\Easy-PhotoPrint Pro) (Version: - ) Canon IJ Network Scan Utility (HKLM\...\Canon_IJ_Network_Scan_UTILITY) (Version: - ) Canon IJ Network Tool (HKLM\...\Canon_IJ_Network_UTILITY) (Version: - ) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\...\CANONIJPLM100) (Version: - ) Canon MG6100 series Benutzerregistrierung (HKLM\...\Canon MG6100 series Benutzerregistrierung) (Version: - ) Canon MG6100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6100_series) (Version: - ) Canon MP Navigator EX 4.0 (HKLM\...\MP Navigator EX 4.0) (Version: - ) Canon My Printer (HKLM\...\CanonMyPrinter) (Version: - ) Canon Solution Menu EX (HKLM\...\CanonSolutionMenuEX) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.13 - Piriform) CD-LabelPrint (HKLM\...\MediaNavigation.CDLabelPrint) (Version: - ) DolbyFiles (Version: 2.0 - Nero AG) Hidden iCloud (HKLM\...\{20C6FF70-690B-4DF7-8F5D-269DD3A7FD23}) (Version: - Apple Inc.) ICQ7.7 (HKLM\...\{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE}) (Version: 7.7 - ICQ) ImagXpress (Version: - Nero AG) Hidden iTunes (HKLM\...\{2F21564D-DE05-4C6D-B21E-08B9D313FAB3}) (Version: - Apple Inc.) Java 7 Update 15 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217015FF}) (Version: 7.0.150 - Oracle) Java Auto Updater (Version: - Sun Microsystems, Inc.) Hidden Kaspersky Internet Security (HKLM\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: - Kaspersky Lab) Kaspersky Internet Security (Version: - Kaspersky Lab) Hidden Laptop Integrated Webcam Driver ( (HKLM\...\Creative OEM002) (Version: - ) Malwarebytes Anti-Malware Version (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation) Menu Templates - Starter Kit (Version: - Nero AG) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office Enterprise 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Movie Templates - Starter Kit (Version: - Nero AG) Hidden Mozilla Firefox 29.0.1 (x86 de) (HKLM\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 9 (HKLM\...\{8c5047b4-25e6-438c-bd5d-1a27b02e4360}) (Version: - Nero AG) Nero BurningROM (Version: - Nero AG) Hidden Nero BurnRights (Version: - Nero AG) Hidden Nero ControlCenter (Version: - Nero AG) Hidden Nero ControlCenter (Version: - Nero AG) Hidden Nero CoverDesigner (Version: - Nero AG) Hidden Nero CoverDesigner Help (Version: - Nero AG) Hidden Nero Disc Copy Gadget (Version: - Nero AG) Hidden Nero Disc Copy Gadget Help (Version: - Nero AG) Hidden Nero DiscSpeed (Version: - Nero AG) Hidden Nero DriveSpeed (Version: - Nero AG) Hidden Nero Express (Version: - Nero AG) Hidden Nero InfoTool (Version: - Nero AG) Hidden Nero Installer (Version: - Nero AG) Hidden Nero Live (Version: - Nero AG) Hidden Nero Live Help (Version: - Nero AG) Hidden Nero PhotoSnap (Version: - Nero AG) Hidden Nero PhotoSnap Help (Version: - Nero AG) Hidden Nero Recode (Version: - Nero AG) Hidden Nero Recode Help (Version: - Nero AG) Hidden Nero Rescue Agent (Version: - Nero AG) Hidden Nero RescueAgent Help (Version: - Nero AG) Hidden Nero ShowTime (Version: - Nero AG) Hidden Nero StartSmart (Version: - Nero AG) Hidden Nero StartSmart Help (Version: - Nero AG) Hidden Nero Vision (Version: - Nero AG) Hidden Nero Vision (Version: - Nero AG) Hidden Nero WaveEditor (Version: - Nero AG) Hidden Nero WaveEditor Help (Version: - Nero AG) Hidden NeroBurningROM (Version: - Nero AG) Hidden NeroExpress (Version: - Nero AG) Hidden neroxml (Version: 1.0.0 - Nero AG) Hidden NVIDIA 3D Vision Treiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.65 - NVIDIA Corporation) NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 1.6 - NVIDIA Corporation) NVIDIA Grafiktreiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA PhysX (Version: 9.12.1031 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.12.1031 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (Version: - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.15.2 - NVIDIA Corporation) Hidden OnlineFotoservice (HKLM\...\OnlineFotoservice) (Version: 5.0.4 - CEWE COLOR AG u Co. OHG) PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) RICOH Media Driver ver. (HKLM\...\{2B818257-E6C7-4841-8C29-C5C9A982BCE5}) (Version: - RICOH) RICOH R5U8xx Media Driver ver.3.62.02 (HKLM\...\{59F6A514-9813-47A3-948C-8A155460CC2A}) (Version: 3.62.02 - RICOH) Room Arranger (HKLM\...\Room Arranger) (Version: 7.2.7 - Jan Adamec) SoundTrax (Version: - Nero AG) Hidden System Checkup 3.1 (HKLM\...\{4AC7B4E7-59B7-4E48-A60D-263C486FC33A}_is1) (Version: - iolo technologies, LLC) Tinypic 3.14 (HKLM\...\{E3723A04-A894-4036-A78E-282E18F43C0A}_is1) (Version: Tinypic 3.14 - E. Fiedler) TomTom HOME (HKLM\...\{9017CEAF-BE5A-4F73-8A0E-C87E26971E55}) (Version: 2.9.2 - Ihr Firmenname) TomTom HOME Visual Studio Merge Modules (HKLM\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN) WBFS Manager 4.0 (HKLM\...\{825E9A84-1E03-4526-9F8E-45015C938A7C}) (Version: 4.0 - WBFS) ==================== Restore Points ========================= 26-05-2014 17:21:57 Removed Adobe Photoshop Elements 10. ==================== Hosts content: ========================== 2009-07-14 04:04 - 2012-02-17 20:01 - 00000910 ____A C:\Windows\system32\Drivers\etc\hosts activate.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {0B80A714-C816-43F2-8208-D83769E22425} - System32\Tasks\{9089463B-BC3D-4AE2-9754-397CDA3FE6E2} => C:\Program Files\iTunes\iTunes.exe [2014-02-21] (Apple Inc.) Task: {3C880E32-D4AD-448C-A0D7-33BDF7109133} - System32\Tasks\{71A347FA-DA6D-4F7F-A505-1CE116B0E081} => C:\Program Files\iTunes\iTunes.exe [2014-02-21] (Apple Inc.) Task: {782C0C90-9EFD-4440-9E9A-E029856A9A33} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {976BB46F-94FD-4E27-9453-AC30AD4D35D8} - System32\Tasks\{6C45C0E6-E7A7-4B86-8E17-8262C2424798} => C:\Program Files\iTunes\iTunes.exe [2014-02-21] (Apple Inc.) Task: {9F833874-93AA-4D5D-9941-88BD68E5D61F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-04-17] (Piriform Ltd) Task: {F3EB04F4-70D9-4226-8241-CFD9B7B4E9B5} - System32\Tasks\{7C0516D7-45AE-4268-9C01-3E2E6D6AED04} => C:\Program Files\iTunes\iTunes.exe [2014-02-21] (Apple Inc.) ==================== Loaded Modules (whitelisted) ============= 2013-02-23 17:14 - 2013-10-23 09:19 - 00092448 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-06-17 13:35 - 2013-06-17 13:35 - 00478400 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll 2013-05-08 15:52 - 2013-05-08 15:52 - 01270464 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll 2012-02-18 14:10 - 2010-04-05 12:55 - 00116104 _____ () C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE 2012-02-17 07:20 - 2012-02-17 07:20 - 00006144 _____ () C:\Users\Marco\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V3.5.gadget\CoreTempReader.dll 2012-02-17 07:20 - 2012-02-17 07:20 - 00008704 _____ () C:\Users\Marco\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V3.5.gadget\GetCoreTempInfoNET.dll 2012-02-17 07:20 - 2012-02-17 07:20 - 00007680 _____ () C:\Users\Marco\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V3.5.gadget\SystemInfo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= HKU\S-1-5-21-3504130025-3935686371-3975182874-1001\Software\Classes\.exe: => <===== ATTENTION! ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon MSCONFIG\startupreg: TomTomHOME.exe => "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" ==================== Faulty Device Manager Devices ============= Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= Error: (04/27/2014 09:48:17 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 339 seconds with 300 seconds of active time. This session ended with a crash. Error: (11/29/2013 07:57:04 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 12 seconds with 0 seconds of active time. This session ended with a crash. Error: (11/29/2013 07:56:02 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 3 seconds with 0 seconds of active time. This session ended with a crash. Error: (07/22/2013 10:08:41 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 3 seconds with 0 seconds of active time. This session ended with a crash. Error: (04/24/2013 01:13:37 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error: (04/24/2013 11:21:03 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error: (03/14/2013 06:44:53 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2 seconds with 0 seconds of active time. This session ended with a crash. Error: (03/07/2013 02:00:14 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 63 seconds with 60 seconds of active time. This session ended with a crash. Error: (03/07/2013 00:59:29 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-05-24 14:07:48.901 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.901 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.891 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.881 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.871 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.871 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.851 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.851 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.841 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.831 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 28% Total physical RAM: 3582.06 MB Available physical RAM: 2549.85 MB Total Pagefile: 7162.41 MB Available Pagefile: 5982 MB Total Virtual: 2047.88 MB Available Virtual: 1923.26 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:186.26 GB) (Free:30.66 GB) NTFS ==>[Drive with boot components (obtained from BCD)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 186 GB) (Disk ID: 00000080) Partition 1: (Not Active) - (Size=47 MB) - (Type=DE) Partition 2: (Active) - (Size=186 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? ![]()
Eine bestimmte Internetseite öffnet sich ganz extrem langsam und das auch noch mit fehlern! Hallo ich denke ich hab alles hin bekommen hier die gewünschten Infos: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=a29cd87005420b4394c490ab8ff8a9b2 # engine=18474 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2014-05-30 11:04:32 # local_time=2014-05-30 01:04:32 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Kaspersky Internet Security' # compatibility_mode=1292 16777213 100 100 84554 32922294 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776573 100 94 322735 153079063 0 0 # scanned=175643 # found=2 # cleaned=0 # scan_time=6137 sh=C5DB8386C3A901DD6D4FB8B66685B889FA1099F9 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\AdwCleaner\Quarantine\C\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\6dp35kc7.default\user.js.vir" sh=C5DB8386C3A901DD6D4FB8B66685B889FA1099F9 ft=0 fh=0000000000000000 vn="JS/SecurityDisabler.A.Gen evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Marco\Desktop\Marco alter Laptop\Firefox verschiedene sicherungen\Firefox Profilordner\6dp35kc7.default\user.js" Code:
ATTFilter Results of screen317's Security Check version 0.99.83 Windows 7 Service Pack 1 x86 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Kaspersky Internet Security Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` CCleaner Java 7 Update 15 Java version out of Date! Adobe Flash Player Adobe Reader 10.1.10 Adobe Reader out of Date! Mozilla Firefox (29.0.1) ````````Process Check: objlist.exe by Laurent```````` Kaspersky Lab Kaspersky Internet Security 14.0.0 avp.exe Kaspersky Lab Kaspersky Internet Security 14.0.0 avpui.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version:25-05-2014 02 Ran by Marco (administrator) on MARCO-PC on 30-05-2014 13:15:51 Running from C:\Users\Marco\Desktop Platform: Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files\Canon\IJPLM\ijplmsvc.exe (Nero AG) C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exe (TomTom) C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe (Creative Technology Ltd.) C:\Windows\OEM02Mon.exe (Microsoft Corporation) C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe (CANON INC.) C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe (Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_13_0_0_214.exe (Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\wmi32.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [OEM02Mon.exe] => C:\Windows\OEM02Mon.exe [36864 2007-05-09] (Creative Technology Ltd.) HKLM\...\Run: [GrooveMonitor] => C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe [31016 2006-10-27] (Microsoft Corporation) HKLM\...\Run: [APSDaemon] => C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [43848 2014-02-06] (Apple Inc.) HKLM\...\Run: [IJNetworkScanUtility] => C:\Program Files\Canon\Canon IJ Network Scan Utility\CNMNSUT.exe [140640 2010-03-02] (CANON INC.) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-02-21] (Apple Inc.) HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKU\S-1-5-21-3504130025-3935686371-3975182874-1001\...\Run: [MobileDocuments] => C:\Program Files\Common Files\Apple\Internet Services\ubd.exe [59240 2012-02-23] (Apple Inc.) HKU\S-1-5-21-3504130025-3935686371-3975182874-1001\...\MountPoints2: {28a161f0-f6d1-11e1-a962-001e4ce44100} - "E:\WD SmartWare.exe" autoplay=true HKU\S-1-5-21-3504130025-3935686371-3975182874-1001\...\MountPoints2: {ef947d6c-5982-11e1-9b36-001e4ce44100} - E:\LaunchU3.exe -a Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (No File) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (No File) Startup: C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\DSL-Manager.lnk ShortcutTarget: DSL-Manager.lnk -> C:\Program Files\DSL-Manager\DslMgr.exe (No File) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x9F6C28D96213CD01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE SearchScopes: HKLM - DefaultScope value is missing. BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO) BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll (Microsoft Corporation) BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO) DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Handler: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll (Microsoft Corporation) Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\wz9o2ng6.default-1385406802750 FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @canon.com/EPPEX - C:\Program Files\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.) FF Plugin: @java.com/DTPlugin,version=10.15.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.15.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @nvidia.com/3DVision - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation) FF Plugin: @nvidia.com/3DVisionStreaming - C:\Program Files\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation) FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: DownloadHelper - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\wz9o2ng6.default-1385406802750\Extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d} [2014-03-29] FF Extension: Tabs On Bottom - C:\Users\Marco\AppData\Roaming\Mozilla\Firefox\Profiles\wz9o2ng6.default-1385406802750\Extensions\tabsonbottom@piro.sakura.ne.jp.xpi [2014-05-14] FF HKLM\...\Firefox\Extensions: [url_advisor@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com FF Extension: 卡巴斯基網址顧問 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2013-12-25] FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com FF Extension: 虛擬鍵盤 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2013-12-25] FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com FF Extension: 惡意網站攔截器 - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2013-12-25] FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com FF Extension: Chặn quảng cáo - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2013-12-25] FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2013-12-25] Chrome: ======= CHR HomePage: CHR Extension: (Google Docs) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-05-24] CHR Extension: (Google Drive) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-05-24] CHR Extension: (No Name) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\blbkdnmdcafmfhinpmnlhhddbepgkeaa [2014-05-24] CHR Extension: (YouTube) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-05-24] CHR Extension: (Google Search) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-05-24] CHR Extension: (Kaspersky URL Advisor) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-05-24] CHR Extension: (Safe Money) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-05-24] CHR Extension: (Dangerous Websites Blocker) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-05-24] CHR Extension: (Virtual Keyboard) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-05-24] CHR Extension: (Google Wallet) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-05-24] CHR Extension: (Gmail) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-05-24] CHR Extension: (Anti-Banner) - C:\Users\Marco\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-05-24] CHR HKLM\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17] CHR HKLM\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17] ========================== Services (Whitelisted) ================= R2 AVP; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO) R2 IJPLMSVC; C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] () S2 MBAMScheduler; C:\Program Files\ Malwarebytes Anti-Malware \mbamscheduler.exe [1809720 2014-05-12] (Malwarebytes Corporation) S2 MBAMService; C:\Program Files\ Malwarebytes Anti-Malware \mbamservice.exe [860472 2014-05-12] (Malwarebytes Corporation) ==================== Drivers (Whitelisted) ==================== R1 ElRawDisk; C:\Windows\system32\drivers\ElRawDsk.sys [26248 2012-10-19] (EldoS Corporation) R0 KL1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2013-12-25] (Kaspersky Lab ZAO) S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [94304 2014-03-25] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [576608 2014-03-25] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25184 2014-02-18] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2013-12-25] (Kaspersky Lab ZAO) S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [23256 2014-05-12] (Malwarebytes Corporation) S3 MBAMWebAccessControl; C:\Windows\system32\drivers\mwac.sys [51928 2014-05-12] (Malwarebytes Corporation) R3 yukonw7; C:\Windows\System32\DRIVERS\yk62x86.sys [315392 2009-09-28] () U5 VWiFiFlt; C:\Windows\System32\Drivers\VWiFiFlt.sys [48128 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-05-30 13:14 - 2014-05-30 13:14 - 00000971 _____ () C:\Users\Marco\Desktop\checkup.txt 2014-05-29 13:38 - 2014-05-30 13:16 - 00014890 _____ () C:\Users\Marco\Desktop\FRST.txt 2014-05-29 13:33 - 2014-05-29 13:34 - 01056256 _____ (Farbar) C:\Users\Marco\Desktop\FRST.exe 2014-05-29 13:21 - 2014-05-29 13:21 - 00000000 ____D () C:\Windows\ERUNT 2014-05-29 13:19 - 2014-05-29 13:20 - 01016261 _____ (Thisisu) C:\Users\Marco\Desktop\JRT.exe 2014-05-28 14:25 - 2014-05-28 14:27 - 00000000 ____D () C:\Users\Marco\Desktop\Bad 2014-05-27 18:56 - 2014-05-27 18:56 - 00000000 ____D () C:\Users\Marco\Desktop\FRST-OlderVersion 2014-05-26 19:25 - 2014-05-26 19:25 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\No Company Name 2014-05-25 12:34 - 2010-08-30 08:34 - 00536576 _____ (SQLite Development Team) C:\Windows\system32\sqlite3.dll 2014-05-25 12:33 - 2014-05-29 13:14 - 00000000 ____D () C:\AdwCleaner 2014-05-25 12:22 - 2014-05-29 13:36 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-25 12:21 - 2014-05-25 12:21 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-25 12:21 - 2014-05-25 12:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-25 12:21 - 2014-05-25 12:21 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-05-25 12:21 - 2014-05-12 07:26 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-25 12:21 - 2014-05-12 07:25 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-25 12:21 - 2014-05-12 07:25 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-25 08:49 - 2014-05-25 08:49 - 00001226 _____ () C:\Users\Marco\Desktop\Revo Uninstaller.lnk 2014-05-25 08:49 - 2014-05-25 08:49 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-05-25 08:18 - 2014-05-30 13:15 - 00000000 ____D () C:\FRST 2014-05-25 05:39 - 2014-05-25 05:39 - 453816381 _____ () C:\Windows\MEMORY.DMP 2014-05-25 05:39 - 2014-05-25 05:39 - 00180944 _____ () C:\Windows\Minidump\052514-24180-01.dmp 2014-05-24 20:36 - 2014-05-25 08:16 - 00000000 ____D () C:\Program Files\Google 2014-05-24 20:36 - 2014-05-24 20:37 - 00000000 ____D () C:\Users\Marco\AppData\Local\Google 2014-05-24 20:21 - 2014-05-29 13:15 - 00002998 _____ () C:\Windows\PFRO.log 2014-05-24 20:09 - 2014-05-24 20:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-24 19:37 - 2014-05-24 19:37 - 00000000 __SHD () C:\Users\Marco\AppData\Local\EmieUserList 2014-05-24 19:37 - 2014-05-24 19:37 - 00000000 __SHD () C:\Users\Marco\AppData\Local\EmieSiteList 2014-05-24 07:17 - 2014-05-29 13:35 - 00000504 _____ () C:\Windows\setupact.log 2014-05-24 07:17 - 2014-05-24 07:17 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-15 06:03 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-15 06:03 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-15 06:02 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-14 16:52 - 2014-05-09 09:06 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-14 16:52 - 2014-05-09 09:04 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-14 16:52 - 2014-04-12 04:15 - 00136640 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-14 16:52 - 2014-04-12 04:15 - 00067520 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-14 16:52 - 2014-04-12 04:12 - 00100352 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-14 16:52 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-14 16:52 - 2014-04-12 04:12 - 00015872 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-14 16:52 - 2014-04-12 04:11 - 01059840 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-14 16:52 - 2014-04-12 04:11 - 00022528 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-14 16:52 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\system32\ntkrnlpa.exe 2014-05-14 16:52 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-14 16:52 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00304128 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-14 16:52 - 2014-03-04 11:17 - 00293376 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 16:52 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-14 16:51 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-10 13:42 - 2014-05-10 13:42 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-08 06:05 - 2014-05-15 17:00 - 00000000 ___SD () C:\Windows\system32\CompatTel ==================== One Month Modified Files and Folders ======= 2014-05-30 13:16 - 2014-05-29 13:38 - 00014890 _____ () C:\Users\Marco\Desktop\FRST.txt 2014-05-30 13:15 - 2014-05-25 08:18 - 00000000 ____D () C:\FRST 2014-05-30 13:14 - 2014-05-30 13:14 - 00000971 _____ () C:\Users\Marco\Desktop\checkup.txt 2014-05-30 12:53 - 2012-02-16 19:45 - 01831082 _____ () C:\Windows\WindowsUpdate.log 2014-05-30 11:28 - 2012-02-16 20:09 - 00000000 ____D () C:\ProgramData\Kaspersky Lab 2014-05-29 13:42 - 2009-07-14 06:34 - 00014928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-05-29 13:42 - 2009-07-14 06:34 - 00014928 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-05-29 13:36 - 2014-05-25 12:22 - 00110296 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys 2014-05-29 13:35 - 2014-05-24 07:17 - 00000504 _____ () C:\Windows\setupact.log 2014-05-29 13:35 - 2012-03-20 21:20 - 00000000 ____D () C:\ProgramData\NVIDIA 2014-05-29 13:35 - 2009-07-14 06:53 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-05-29 13:34 - 2014-05-29 13:33 - 01056256 _____ (Farbar) C:\Users\Marco\Desktop\FRST.exe 2014-05-29 13:21 - 2014-05-29 13:21 - 00000000 ____D () C:\Windows\ERUNT 2014-05-29 13:20 - 2014-05-29 13:19 - 01016261 _____ (Thisisu) C:\Users\Marco\Desktop\JRT.exe 2014-05-29 13:16 - 2009-07-14 06:33 - 00421512 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-05-29 13:15 - 2014-05-24 20:21 - 00002998 _____ () C:\Windows\PFRO.log 2014-05-29 13:14 - 2014-05-25 12:33 - 00000000 ____D () C:\AdwCleaner 2014-05-29 12:53 - 2012-02-16 19:55 - 01629284 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-05-28 14:27 - 2014-05-28 14:25 - 00000000 ____D () C:\Users\Marco\Desktop\Bad 2014-05-27 18:56 - 2014-05-27 18:56 - 00000000 ____D () C:\Users\Marco\Desktop\FRST-OlderVersion 2014-05-26 19:49 - 2012-02-17 00:20 - 00110824 _____ () C:\Users\Marco\AppData\Local\GDIPFONTCACHEV1.DAT 2014-05-26 19:26 - 2012-02-17 18:08 - 00000000 ____D () C:\ProgramData\Adobe 2014-05-26 19:26 - 2012-02-17 18:08 - 00000000 ____D () C:\Program Files\Common Files\Adobe 2014-05-26 19:25 - 2014-05-26 19:25 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\No Company Name 2014-05-26 19:25 - 2012-02-17 18:08 - 00000000 ____D () C:\Program Files\Adobe 2014-05-25 12:21 - 2014-05-25 12:21 - 00001064 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-05-25 12:21 - 2014-05-25 12:21 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Malwarebytes Anti-Malware 2014-05-25 12:21 - 2014-05-25 12:21 - 00000000 ____D () C:\Program Files\ Malwarebytes Anti-Malware 2014-05-25 08:49 - 2014-05-25 08:49 - 00001226 _____ () C:\Users\Marco\Desktop\Revo Uninstaller.lnk 2014-05-25 08:49 - 2014-05-25 08:49 - 00000000 ____D () C:\Program Files\VS Revo Group 2014-05-25 08:16 - 2014-05-24 20:36 - 00000000 ____D () C:\Program Files\Google 2014-05-25 05:39 - 2014-05-25 05:39 - 453816381 _____ () C:\Windows\MEMORY.DMP 2014-05-25 05:39 - 2014-05-25 05:39 - 00180944 _____ () C:\Windows\Minidump\052514-24180-01.dmp 2014-05-25 05:39 - 2012-04-09 10:01 - 00000000 ____D () C:\Windows\Minidump 2014-05-24 20:37 - 2014-05-24 20:36 - 00000000 ____D () C:\Users\Marco\AppData\Local\Google 2014-05-24 20:21 - 2009-07-14 06:52 - 00000000 ____D () C:\Windows\Performance 2014-05-24 20:09 - 2014-05-24 20:09 - 00000000 ____D () C:\ProgramData\Malwarebytes 2014-05-24 19:37 - 2014-05-24 19:37 - 00000000 __SHD () C:\Users\Marco\AppData\Local\EmieUserList 2014-05-24 19:37 - 2014-05-24 19:37 - 00000000 __SHD () C:\Users\Marco\AppData\Local\EmieSiteList 2014-05-24 07:17 - 2014-05-24 07:17 - 00000000 _____ () C:\Windows\setuperr.log 2014-05-22 19:57 - 2012-02-18 14:09 - 00000000 ____D () C:\ProgramData\CanonIJPLM 2014-05-22 19:49 - 2012-02-17 18:57 - 00000969 _____ () C:\Users\Public\Desktop\CCleaner.lnk 2014-05-22 19:49 - 2012-02-17 18:57 - 00000000 ____D () C:\Program Files\CCleaner 2014-05-22 19:44 - 2014-01-14 21:04 - 00000000 ____D () C:\Users\Marco\Desktop\Bau 2014-05-22 19:44 - 2014-01-03 21:16 - 00000000 ____D () C:\Users\Marco\Desktop\LOGO 2014-05-22 19:44 - 2012-04-21 14:23 - 00000000 ____D () C:\Users\Marco\Desktop\Leni 2014-05-21 19:45 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\rescache 2014-05-21 19:07 - 2012-03-31 15:22 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-05-21 19:07 - 2012-02-17 00:35 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-05-15 19:02 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\Microsoft.NET 2014-05-15 17:02 - 2012-05-12 11:35 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2014-05-15 17:00 - 2014-05-08 06:05 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-15 17:00 - 2009-07-14 04:37 - 00000000 ____D () C:\Windows\system32\de-DE 2014-05-15 06:09 - 2013-08-15 06:21 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-15 06:07 - 2012-02-16 21:06 - 90547776 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-14 19:27 - 2012-02-22 19:58 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-05-14 19:21 - 2013-10-29 18:41 - 00000000 ____D () C:\Users\Marco\AppData\Local\Room Arranger 2014-05-12 07:26 - 2014-05-25 12:21 - 00051928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mwac.sys 2014-05-12 07:25 - 2014-05-25 12:21 - 00074456 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-05-12 07:25 - 2014-05-25 12:21 - 00023256 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-05-10 13:42 - 2014-05-10 13:42 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2014-05-10 13:22 - 2012-02-17 18:54 - 00000000 ____D () C:\Users\Marco\AppData\Roaming\vlc 2014-05-09 09:06 - 2014-05-14 16:52 - 00369664 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 09:04 - 2014-05-14 16:52 - 00302592 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-06 05:25 - 2014-05-15 06:03 - 17382912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 05:07 - 2014-05-15 06:02 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-06 04:10 - 2014-05-15 06:03 - 00069632 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll Some content of TEMP: ==================== C:\Users\Marco\AppData\Local\Temp\Quarantine.exe C:\Users\Marco\AppData\Local\Temp\readSTILog.dll ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\system32\winlogon.exe [2014-05-14 16:52] - [2014-03-04 11:17] - 0304128 ____A (Microsoft Corporation) 998507B046BA314CE8245364C686FA67 C:\Windows\system32\wininit.exe => MD5 is legit C:\Windows\system32\svchost.exe => MD5 is legit C:\Windows\system32\services.exe => MD5 is legit C:\Windows\system32\User32.dll => MD5 is legit C:\Windows\system32\userinit.exe => MD5 is legit C:\Windows\system32\rpcss.dll => MD5 is legit C:\Windows\system32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-21 19:37 ==================== End Of Log ============================ Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version:25-05-2014 02 Ran by Marco at 2014-05-30 13:16:27 Running from C:\Users\Marco\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886} AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD} ==================== Installed Programs ====================== "Nero SoundTrax Help (Version: - Nero AG) Hidden 7-Zip 4.65 (HKLM\...\7-Zip) (Version: - ) Adobe AIR (HKLM\...\Adobe AIR) (Version: - Adobe Systems Incorporated) Adobe AIR (Version: - Adobe Systems Incorporated) Hidden Adobe Community Help (HKLM\...\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1) (Version: 3.5.23 - Adobe Systems Incorporated.) Adobe Community Help (Version: 3.5.23 - Adobe Systems Incorporated.) Hidden Adobe Flash Player 11 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated) Adobe Reader X (10.1.10) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated) Advertising Center (Version: - Nero AG) Hidden Apple Application Support (HKLM\...\{21FC2093-6E43-460B-B9B0-5F5AA35BBB0F}) (Version: 3.0 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{10E3A6DD-84D8-4D8A-BB11-5E5314BCA7FD}) (Version: - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: - Apple Inc.) Biet-O-Matic v2.8.3 (HKLM\...\Biet-O-Matic v2.8.3) (Version: Biet-O-Matic v2.8.3 - BOM Development Team) Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: - Apple Inc.) Canon Easy-PhotoPrint EX (HKLM\...\Easy-PhotoPrint EX) (Version: - ) Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data (HKLM\...\Canon Easy-PhotoPrint Pro - Pro9000 series Extention Data) (Version: - ) Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data (HKLM\...\Canon Easy-PhotoPrint Pro - Pro9500 series Extention Data) (Version: - ) Canon Easy-PhotoPrint Pro (HKLM\...\Easy-PhotoPrint Pro) (Version: - ) Canon IJ Network Scan Utility (HKLM\...\Canon_IJ_Network_Scan_UTILITY) (Version: - ) Canon IJ Network Tool (HKLM\...\Canon_IJ_Network_UTILITY) (Version: - ) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM\...\CANONIJPLM100) (Version: - ) Canon MG6100 series Benutzerregistrierung (HKLM\...\Canon MG6100 series Benutzerregistrierung) (Version: - ) Canon MG6100 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG6100_series) (Version: - ) Canon MP Navigator EX 4.0 (HKLM\...\MP Navigator EX 4.0) (Version: - ) Canon My Printer (HKLM\...\CanonMyPrinter) (Version: - ) Canon Solution Menu EX (HKLM\...\CanonSolutionMenuEX) (Version: - ) CCleaner (HKLM\...\CCleaner) (Version: 4.13 - Piriform) CD-LabelPrint (HKLM\...\MediaNavigation.CDLabelPrint) (Version: - ) DolbyFiles (Version: 2.0 - Nero AG) Hidden iCloud (HKLM\...\{20C6FF70-690B-4DF7-8F5D-269DD3A7FD23}) (Version: - Apple Inc.) ICQ7.7 (HKLM\...\{77F665FD-3F60-4B0A-AE14-EC124B7A7FCE}) (Version: 7.7 - ICQ) ImagXpress (Version: - Nero AG) Hidden iTunes (HKLM\...\{2F21564D-DE05-4C6D-B21E-08B9D313FAB3}) (Version: - Apple Inc.) Java 7 Update 15 (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F83217015FF}) (Version: 7.0.150 - Oracle) Java Auto Updater (Version: - Sun Microsystems, Inc.) Hidden Kaspersky Internet Security (HKLM\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: - Kaspersky Lab) Kaspersky Internet Security (Version: - Kaspersky Lab) Hidden Laptop Integrated Webcam Driver ( (HKLM\...\Creative OEM002) (Version: - ) Malwarebytes Anti-Malware Version (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: - Malwarebytes Corporation) Menu Templates - Starter Kit (Version: - Nero AG) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (HKLM\...\ENTERPRISE) (Version: 12.0.4518.1014 - Microsoft Corporation) Microsoft Office Enterprise 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Visual C++ 2005 Redistributable (HKLM\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM\...\{6AFCA4E1-9B78-3640-8F72-A7BF33448200}) (Version: 9.0.30729 - Microsoft Corporation) Movie Templates - Starter Kit (Version: - Nero AG) Hidden Mozilla Firefox 29.0.1 (x86 de) (HKLM\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) Nero 9 (HKLM\...\{8c5047b4-25e6-438c-bd5d-1a27b02e4360}) (Version: - Nero AG) Nero BurningROM (Version: - Nero AG) Hidden Nero BurnRights (Version: - Nero AG) Hidden Nero ControlCenter (Version: - Nero AG) Hidden Nero ControlCenter (Version: - Nero AG) Hidden Nero CoverDesigner (Version: - Nero AG) Hidden Nero CoverDesigner Help (Version: - Nero AG) Hidden Nero Disc Copy Gadget (Version: - Nero AG) Hidden Nero Disc Copy Gadget Help (Version: - Nero AG) Hidden Nero DiscSpeed (Version: - Nero AG) Hidden Nero DriveSpeed (Version: - Nero AG) Hidden Nero Express (Version: - Nero AG) Hidden Nero InfoTool (Version: - Nero AG) Hidden Nero Installer (Version: - Nero AG) Hidden Nero Live (Version: - Nero AG) Hidden Nero Live Help (Version: - Nero AG) Hidden Nero PhotoSnap (Version: - Nero AG) Hidden Nero PhotoSnap Help (Version: - Nero AG) Hidden Nero Recode (Version: - Nero AG) Hidden Nero Recode Help (Version: - Nero AG) Hidden Nero Rescue Agent (Version: - Nero AG) Hidden Nero RescueAgent Help (Version: - Nero AG) Hidden Nero ShowTime (Version: - Nero AG) Hidden Nero StartSmart (Version: - Nero AG) Hidden Nero StartSmart Help (Version: - Nero AG) Hidden Nero Vision (Version: - Nero AG) Hidden Nero Vision (Version: - Nero AG) Hidden Nero WaveEditor (Version: - Nero AG) Hidden Nero WaveEditor Help (Version: - Nero AG) Hidden NeroBurningROM (Version: - Nero AG) Hidden NeroExpress (Version: - Nero AG) Hidden neroxml (Version: 1.0.0 - Nero AG) Hidden NVIDIA 3D Vision Treiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 331.65 - NVIDIA Corporation) NVIDIA Display Control Panel (HKLM\...\NVIDIA Display Control Panel) (Version: 1.6 - NVIDIA Corporation) NVIDIA Grafiktreiber 331.65 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 331.65 - NVIDIA Corporation) NVIDIA Install Application (Version: 2.1002.133.889 - NVIDIA Corporation) Hidden NVIDIA PhysX (Version: 9.12.1031 - NVIDIA Corporation) Hidden NVIDIA PhysX-Systemsoftware 9.12.1031 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.1031 - NVIDIA Corporation) NVIDIA Stereoscopic 3D Driver (Version: - NVIDIA Corporation) Hidden NVIDIA Systemsteuerung 331.65 (Version: 331.65 - NVIDIA Corporation) Hidden NVIDIA Update 1.15.2 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.15.2 - NVIDIA Corporation) NVIDIA Update Components (Version: 1.15.2 - NVIDIA Corporation) Hidden OnlineFotoservice (HKLM\...\OnlineFotoservice) (Version: 5.0.4 - CEWE COLOR AG u Co. OHG) PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Revo Uninstaller 1.95 (HKLM\...\Revo Uninstaller) (Version: 1.95 - VS Revo Group) RICOH Media Driver ver. (HKLM\...\{2B818257-E6C7-4841-8C29-C5C9A982BCE5}) (Version: - RICOH) RICOH R5U8xx Media Driver ver.3.62.02 (HKLM\...\{59F6A514-9813-47A3-948C-8A155460CC2A}) (Version: 3.62.02 - RICOH) Room Arranger (HKLM\...\Room Arranger) (Version: 7.2.7 - Jan Adamec) SoundTrax (Version: - Nero AG) Hidden System Checkup 3.1 (HKLM\...\{4AC7B4E7-59B7-4E48-A60D-263C486FC33A}_is1) (Version: - iolo technologies, LLC) Tinypic 3.14 (HKLM\...\{E3723A04-A894-4036-A78E-282E18F43C0A}_is1) (Version: Tinypic 3.14 - E. Fiedler) TomTom HOME (HKLM\...\{9017CEAF-BE5A-4F73-8A0E-C87E26971E55}) (Version: 2.9.2 - Ihr Firmenname) TomTom HOME Visual Studio Merge Modules (HKLM\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden VLC media player 2.1.2 (HKLM\...\VLC media player) (Version: 2.1.2 - VideoLAN) WBFS Manager 4.0 (HKLM\...\{825E9A84-1E03-4526-9F8E-45015C938A7C}) (Version: 4.0 - WBFS) ==================== Restore Points ========================= 26-05-2014 17:21:57 Removed Adobe Photoshop Elements 10. 30-05-2014 09:22:07 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:04 - 2012-02-17 20:01 - 00000910 ____A C:\Windows\system32\Drivers\etc\hosts activate.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {0B80A714-C816-43F2-8208-D83769E22425} - System32\Tasks\{9089463B-BC3D-4AE2-9754-397CDA3FE6E2} => C:\Program Files\iTunes\iTunes.exe [2014-02-21] (Apple Inc.) Task: {3C880E32-D4AD-448C-A0D7-33BDF7109133} - System32\Tasks\{71A347FA-DA6D-4F7F-A505-1CE116B0E081} => C:\Program Files\iTunes\iTunes.exe [2014-02-21] (Apple Inc.) Task: {782C0C90-9EFD-4440-9E9A-E029856A9A33} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {976BB46F-94FD-4E27-9453-AC30AD4D35D8} - System32\Tasks\{6C45C0E6-E7A7-4B86-8E17-8262C2424798} => C:\Program Files\iTunes\iTunes.exe [2014-02-21] (Apple Inc.) Task: {9F833874-93AA-4D5D-9941-88BD68E5D61F} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-04-17] (Piriform Ltd) Task: {F3EB04F4-70D9-4226-8241-CFD9B7B4E9B5} - System32\Tasks\{7C0516D7-45AE-4268-9C01-3E2E6D6AED04} => C:\Program Files\iTunes\iTunes.exe [2014-02-21] (Apple Inc.) ==================== Loaded Modules (whitelisted) ============= 2013-02-23 17:14 - 2013-10-23 09:19 - 00092448 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-06-17 13:35 - 2013-06-17 13:35 - 00478400 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll 2013-05-08 15:52 - 2013-05-08 15:52 - 01270464 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll 2012-02-18 14:10 - 2010-04-05 12:55 - 00116104 _____ () C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE 2012-02-17 07:20 - 2012-02-17 07:20 - 00006144 _____ () C:\Users\Marco\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V3.5.gadget\CoreTempReader.dll 2012-02-17 07:20 - 2012-02-17 07:20 - 00008704 _____ () C:\Users\Marco\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V3.5.gadget\GetCoreTempInfoNET.dll 2012-02-17 07:20 - 2012-02-17 07:20 - 00007680 _____ () C:\Users\Marco\AppData\Local\Microsoft\Windows Sidebar\Gadgets\All_CPU_Meter_V3.5.gadget\SystemInfo.dll 2014-05-10 13:42 - 2014-05-10 13:42 - 03839088 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll 2014-05-21 19:07 - 2014-05-21 19:07 - 16361136 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_13_0_0_214.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= HKU\S-1-5-21-3504130025-3935686371-3975182874-1001\Software\Classes\.exe: => <===== ATTENTION! ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: CanonMyPrinter => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon MSCONFIG\startupreg: CanonSolutionMenuEx => C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE /logon MSCONFIG\startupreg: TomTomHOME.exe => "C:\Program Files\TomTom HOME 2\TomTomHOMERunner.exe" ==================== Faulty Device Manager Devices ============= Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Bluetooth-Peripheriegerät Description: Bluetooth-Peripheriegerät Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (05/30/2014 07:42:14 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4446 Error: (05/30/2014 07:42:14 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 4446 Error: (05/30/2014 07:42:14 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/29/2014 10:41:46 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5086 Error: (05/29/2014 10:41:46 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5086 Error: (05/29/2014 10:41:46 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/29/2014 02:39:13 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 16396 Error: (05/29/2014 02:39:13 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 16396 Error: (05/29/2014 02:39:13 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/29/2014 02:39:03 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 6396 System errors: ============= Error: (05/29/2014 02:39:18 PM) (Source: Microsoft-Windows-HAL) (EventID: 12) (User: ) Description: Der Speicher wurde beim letzten Leistungsübergang des Systems von der Plattformfirmware beschädigt. Überprüfen Sie, ob für Ihr System aktualisierte Firmware verfügbar ist. Microsoft Office Sessions: ========================= Error: (04/27/2014 09:48:17 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 339 seconds with 300 seconds of active time. This session ended with a crash. Error: (11/29/2013 07:57:04 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 12 seconds with 0 seconds of active time. This session ended with a crash. Error: (11/29/2013 07:56:02 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 3 seconds with 0 seconds of active time. This session ended with a crash. Error: (07/22/2013 10:08:41 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 3 seconds with 0 seconds of active time. This session ended with a crash. Error: (04/24/2013 01:13:37 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error: (04/24/2013 11:21:03 AM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. Error: (03/14/2013 06:44:53 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 2 seconds with 0 seconds of active time. This session ended with a crash. Error: (03/07/2013 02:00:14 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 63 seconds with 60 seconds of active time. This session ended with a crash. Error: (03/07/2013 00:59:29 PM) (Source: Microsoft Office 12 Sessions) (EventID: 7001) (User: ) Description: ID: 6, Application Name: Microsoft Office Outlook, Application Version: 12.0.4518.1014, Microsoft Office Version: 12.0.4518.1014. This session lasted 1 seconds with 0 seconds of active time. This session ended with a crash. CodeIntegrity Errors: =================================== Date: 2014-05-24 14:07:48.901 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.901 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.891 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.881 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.871 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.871 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\ELAMBKUP\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.851 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.851 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.841 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2014-05-24 14:07:48.831 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\KLELAMX86\klelam.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Percentage of memory in use: 52% Total physical RAM: 3582.06 MB Available physical RAM: 1697.98 MB Total Pagefile: 7162.41 MB Available Pagefile: 4978.87 MB Total Virtual: 2047.88 MB Available Virtual: 1915.17 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:186.26 GB) (Free:29.71 GB) NTFS ==>[Drive with boot components (obtained from BCD)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 186 GB) (Disk ID: 00000080) Partition 1: (Not Active) - (Size=47 MB) - (Type=DE) Partition 2: (Active) - (Size=186 GB) - (Type=07 NTFS) ==================== End Of Log ============================ PS. ich weis nicht genau, aber ich denke "dieses Problem mit der genannten seite" ist besser geworden. Muss ich da jetzt noch etwas machen, wenn ja was? Und wenn ich doch fertig sein sollte... an was lag das jetzt mit der besagten seite? Danke schon mal :-) Gruß |
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun ![]() Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
