|
Plagegeister aller Art und deren Bekämpfung: Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehrWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
01.06.2014, 09:21 | #1 |
| Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehr Seit Tagen versuche ich meine Kiste wieder auf Vordermann zu bringen. Erfolglos mit den mir verfügbaren Mitteln. - Beim booten blärrt das Jingle manchmal - Zu 90 % erscheint nach dem Boot die Meldung "can not create shell nitification icon" - Irgendwann (zwischen 15 min. und 3 Stunden) hängt sich der Firefox auf (keine Rückmeldung) und nichts geht mehr. Kein Runterfahren, kein Affengriff, einfach NIX mehr! FRST: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 01-06-2014 Ran by asus (administrator) on ASUS-PC on 01-06-2014 10:07:01 Running from C:\Users\asus\Downloads Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Crawler.com) C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Spotify Ltd) C:\Users\asus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (ASUS) C:\Windows\AsScrPro.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Crawler.com) C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2189416 2011-03-01] (Realtek Semiconductor) HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324096 2010-08-11] (Alcor Micro Corp.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-13] (ELAN Microelectronics Corp.) HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com) HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] () HKLM-x32\...\Run: [WinampAgent] => C:\Program Files (x86)\Winamp\winampa.exe [74752 2012-06-28] (Nullsoft, Inc.) HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59280 2012-10-11] (Apple Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2012-10-25] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKLM-x32\...\Run: [DivXMediaServer] => C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [3888648 2014-05-26] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2812954037-985756252-1433979443-1000\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-2812954037-985756252-1433979443-1000\...\Run: [Spotify Web Helper] => C:\Users\asus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1176632 2014-05-16] (Spotify Ltd) HKU\S-1-5-21-2812954037-985756252-1433979443-1000\...\Run: [Spotify] => C:\Users\asus\AppData\Roaming\Spotify\spotify.exe [6170168 2014-05-16] (Spotify Ltd) HKU\S-1-5-21-2812954037-985756252-1433979443-1000\...\Run: [TomTomHOME.exe] => C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe [248208 2013-03-22] (TomTom) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com URLSearchHook: HKCU - (No Name) - {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - No File SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKCU - {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = BHO: FTdownloader V4.0 - {11111111-1111-1111-1111-110311551174} - C:\Program Files (x86)\FTdownloader V4.0\FTdownloader V4.0-bho64.dll No File BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Toolbar: HKCU - No Name - {EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} - No File Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\asus\AppData\Roaming\Mozilla\Firefox\Profiles\j10ut53x.default-1349158430390 FF SearchEngineOrder.1: Ask Search FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKCU: @Skype Limited.com/Facebook Video Calling Plugin - C:\Users\asus\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-01-21] FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-01-21] ==================== Services (Whitelisted) ================= R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-05-14] (AVAST Software) S2 Radio.fx; C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe [3673944 2011-11-18] () S2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com) ==================== Drivers (Whitelisted) ==================== R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-05-14] () R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [28504 2012-02-23] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-05-14] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-05-14] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-05-14] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1039096 2014-05-15] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [423240 2014-05-15] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [85328 2014-05-15] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [208416 2014-05-14] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.) R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2014-05-28] (Windows (R) Win 7 DDK provider) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-06-01 09:51 - 2014-06-01 10:07 - 00014249 _____ () C:\Users\asus\Downloads\FRST.txt 2014-06-01 09:51 - 2014-06-01 09:51 - 00000000 ____D () C:\Users\asus\Downloads\FRST-OlderVersion 2014-06-01 09:49 - 2014-06-01 10:06 - 00000470 _____ () C:\Users\asus\Downloads\defogger_disable.log 2014-06-01 09:49 - 2014-06-01 09:49 - 00000000 _____ () C:\Users\asus\defogger_reenable 2014-06-01 09:48 - 2014-06-01 09:48 - 00050477 _____ () C:\Users\asus\Downloads\Defogger.exe 2014-06-01 09:25 - 2014-06-01 09:36 - 00005739 _____ () C:\Users\asus\Downloads\hijackthis.log 2014-06-01 09:07 - 2014-06-01 09:07 - 00388608 _____ (Trend Micro Inc.) C:\Users\asus\Downloads\HiJackThis204.exe 2014-05-31 08:15 - 2014-05-31 08:16 - 00000000 ____D () C:\Users\asus\AppData\Local\{0C71ADA1-65C2-4591-AA7A-8D2E6CC883A5} 2014-05-30 20:14 - 2014-05-30 20:14 - 00000000 ____D () C:\Users\asus\AppData\Local\{D3953CF0-161B-4012-A906-5FB118F4825B} 2014-05-29 21:20 - 2014-05-29 21:21 - 00000000 ____D () C:\Users\asus\AppData\Local\{B83C51A6-A955-45AA-8CEC-283220D68297} 2014-05-29 01:22 - 2014-05-29 01:23 - 00000000 ____D () C:\Users\asus\AppData\Local\{BEE1E00C-9B2E-4AC1-A5DF-61789FB9C898} 2014-05-28 08:30 - 2014-05-29 21:19 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2014-05-28 08:30 - 2014-05-28 08:43 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-05-28 08:30 - 2014-05-28 08:30 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-05-28 08:30 - 2014-05-28 08:30 - 00000000 ____D () C:\Users\asus\AppData\Roaming\Spyware Terminator 2014-05-28 08:30 - 2014-05-28 08:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Terminator 2012 2014-05-27 20:55 - 2014-05-27 20:55 - 00000000 ____D () C:\Users\asus\AppData\Local\{6C63488F-2B88-47FA-A579-E492A6365B06} 2014-05-27 08:15 - 2014-05-27 08:15 - 00000000 ____D () C:\Users\asus\AppData\Local\{B35D7729-885B-4CF0-9AD0-2087590A2F96} 2014-05-27 06:49 - 2014-05-27 06:49 - 00000000 ____D () C:\Users\asus\AppData\Local\{6655094B-0896-45EE-AA24-70CC8D0904CD} 2014-05-26 17:28 - 2014-05-26 17:28 - 00000000 ____D () C:\Users\asus\AppData\Local\{5DEDB503-1FD2-4218-B7AC-9CBD3AD75B25} 2014-05-26 00:42 - 2014-05-26 00:42 - 00000000 ____D () C:\Users\asus\AppData\Local\{8F5E763F-6CBF-48F7-B762-B57CAE995EA5} 2014-05-25 09:46 - 2014-05-25 09:46 - 00000000 ____D () C:\Users\asus\AppData\Local\{0F689E3E-F4BE-4072-894B-74C6EF5E2963} 2014-05-24 14:30 - 2014-05-24 14:30 - 00000000 ____D () C:\Users\asus\AppData\Local\{0827953E-A7EA-489C-A91C-7D851F831D52} 2014-05-24 02:28 - 2014-05-24 02:28 - 00000000 ____D () C:\Users\asus\AppData\Local\{644BCC2A-78F4-4653-8928-630DEFD88337} 2014-05-23 08:36 - 2014-05-23 08:36 - 00000000 ____D () C:\Users\asus\AppData\Local\{684DF0EC-AEF8-4389-87C2-920B8C8E5BF1} 2014-05-22 20:23 - 2014-05-22 20:23 - 00000000 ____D () C:\Users\asus\AppData\Local\{C8D1BE66-42B8-4178-B2A6-1F07A4321058} 2014-05-22 07:39 - 2014-05-22 07:39 - 00000000 ____D () C:\Users\asus\AppData\Local\{34074692-0E0C-4DE5-8731-F01AD752215F} 2014-05-21 17:20 - 2014-05-21 17:20 - 00000000 ____D () C:\Users\asus\AppData\Local\{41C9C300-2DA1-477A-B5ED-53259EFF2E0B} 2014-05-20 23:24 - 2014-05-20 23:24 - 00000000 ____D () C:\Users\asus\AppData\Local\{4673BFBF-1D10-4CBF-9F2D-0BEE948CCFB9} 2014-05-19 21:11 - 2014-05-19 21:11 - 00000000 ____D () C:\Users\asus\AppData\Local\{340769B0-6A52-4728-AD3D-60E6B7DB8A56} 2014-05-18 22:31 - 2014-05-18 22:31 - 00000000 ____D () C:\Users\asus\AppData\Local\{4ED52C07-D4A6-47DD-88C3-6A81F3F17919} 2014-05-17 19:44 - 2014-05-17 19:44 - 00000000 ____D () C:\Users\asus\AppData\Local\{E61C4E76-91A7-48E9-B2F1-CC82BA0F7C8E} 2014-05-17 06:30 - 2014-05-17 06:30 - 00000000 ____D () C:\Users\asus\AppData\Local\{3F4D4A05-8B11-42D0-8E9D-0CBC6734273F} 2014-05-16 18:30 - 2014-05-16 18:30 - 00000000 ____D () C:\Users\asus\AppData\Local\{6B1E1553-2523-4C37-9E6E-CDFD79CC154D} 2014-05-15 13:17 - 2014-05-15 13:18 - 00000000 ____D () C:\Users\asus\AppData\Local\{6A54CAFE-D371-4093-99FC-A4CED42DCB0B} 2014-05-14 22:36 - 2014-05-14 22:36 - 00000000 ____D () C:\Users\asus\AppData\Local\{0A982BB7-CB4E-44FF-9E28-B86F700D4959} 2014-05-14 19:36 - 2014-05-14 19:36 - 00000000 __SHD () C:\Users\asus\AppData\Local\EmieUserList 2014-05-14 19:36 - 2014-05-14 19:36 - 00000000 __SHD () C:\Users\asus\AppData\Local\EmieSiteList 2014-05-14 19:25 - 2014-05-14 19:25 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-05-14 19:25 - 2014-05-14 19:25 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-05-14 01:25 - 2014-05-06 06:40 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-14 01:25 - 2014-05-06 06:17 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-14 01:25 - 2014-05-06 05:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-14 01:25 - 2014-05-06 05:07 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-14 01:25 - 2014-05-06 05:00 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-14 01:25 - 2014-05-06 04:10 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-14 00:50 - 2014-05-09 08:14 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-14 00:50 - 2014-05-09 08:11 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-14 00:50 - 2014-04-12 04:22 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2014-05-14 00:50 - 2014-04-12 04:22 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2014-05-14 00:50 - 2014-04-12 04:19 - 01460736 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2014-05-14 00:50 - 2014-04-12 04:19 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2014-05-14 00:50 - 2014-04-12 04:19 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2014-05-14 00:50 - 2014-04-12 04:19 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2014-05-14 00:50 - 2014-04-12 04:19 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2014-05-14 00:50 - 2014-04-12 04:12 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2014-05-14 00:50 - 2014-04-12 04:10 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2014-05-14 00:50 - 2014-03-25 04:43 - 14175744 _____ (Microsoft Corporation) C:\Windows\system32\shell32.dll 2014-05-14 00:50 - 2014-03-25 04:09 - 12874240 _____ (Microsoft Corporation) C:\Windows\SysWOW64\shell32.dll 2014-05-14 00:50 - 2014-03-04 11:47 - 05550016 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2014-05-14 00:50 - 2014-03-04 11:44 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2014-05-14 00:50 - 2014-03-04 11:44 - 00722944 _____ (Microsoft Corporation) C:\Windows\system32\objsel.dll 2014-05-14 00:50 - 2014-03-04 11:44 - 00424960 _____ (Microsoft Corporation) C:\Windows\system32\KernelBase.dll 2014-05-14 00:50 - 2014-03-04 11:44 - 00340992 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2014-05-14 00:50 - 2014-03-04 11:44 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2014-05-14 00:50 - 2014-03-04 11:44 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2014-05-14 00:50 - 2014-03-04 11:44 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2014-05-14 00:50 - 2014-03-04 11:44 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\wincredprovider.dll 2014-05-14 00:50 - 2014-03-04 11:43 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe 2014-05-14 00:50 - 2014-03-04 11:43 - 00057344 _____ (Microsoft Corporation) C:\Windows\system32\cngprovider.dll 2014-05-14 00:50 - 2014-03-04 11:43 - 00056832 _____ (Microsoft Corporation) C:\Windows\system32\adprovider.dll 2014-05-14 00:50 - 2014-03-04 11:43 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\capiprovider.dll 2014-05-14 00:50 - 2014-03-04 11:43 - 00052736 _____ (Microsoft Corporation) C:\Windows\system32\dpapiprovider.dll 2014-05-14 00:50 - 2014-03-04 11:43 - 00044544 _____ (Microsoft Corporation) C:\Windows\system32\dimsroam.dll 2014-05-14 00:50 - 2014-03-04 11:43 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2014-05-14 00:50 - 2014-03-04 11:20 - 03969984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2014-05-14 00:50 - 2014-03-04 11:20 - 03914176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2014-05-14 00:50 - 2014-03-04 11:17 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2014-05-14 00:50 - 2014-03-04 11:17 - 00538112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\objsel.dll 2014-05-14 00:50 - 2014-03-04 11:17 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2014-05-14 00:50 - 2014-03-04 11:17 - 00247808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2014-05-14 00:50 - 2014-03-04 11:17 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2014-05-14 00:50 - 2014-03-04 11:17 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2014-05-14 00:50 - 2014-03-04 11:17 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cngprovider.dll 2014-05-14 00:50 - 2014-03-04 11:17 - 00049664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adprovider.dll 2014-05-14 00:50 - 2014-03-04 11:17 - 00048128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\capiprovider.dll 2014-05-14 00:50 - 2014-03-04 11:17 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dpapiprovider.dll 2014-05-14 00:50 - 2014-03-04 11:17 - 00036864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dimsroam.dll 2014-05-14 00:50 - 2014-03-04 11:17 - 00035328 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wincredprovider.dll 2014-05-14 00:50 - 2014-03-04 11:17 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2014-05-14 00:50 - 2014-03-04 11:16 - 00274944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\KernelBase.dll 2014-05-13 16:53 - 2014-05-13 16:53 - 00000000 ____D () C:\Users\asus\AppData\Local\{2C31B0B9-08C5-4D9E-93C7-95D7263B7786} 2014-05-12 10:31 - 2014-05-12 10:31 - 00000000 ____D () C:\Users\asus\AppData\Local\{54B34AE9-762B-47B5-89A0-1FFC763E544C} 2014-05-11 22:30 - 2014-05-11 22:30 - 00000000 ____D () C:\Users\asus\AppData\Local\{68A45214-2BC7-4591-9BCE-EAF6C26633F3} 2014-05-11 10:30 - 2014-05-11 10:30 - 00000000 ____D () C:\Users\asus\AppData\Local\{5CC2DBB2-FCD0-4C66-B698-BE1FF35C4524} 2014-05-10 12:28 - 2014-05-10 12:28 - 00000000 ____D () C:\Users\asus\AppData\Local\{6E4CCAD1-440F-4B5D-815E-0885EDA73D2D} 2014-05-10 09:12 - 2014-05-10 09:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-10 00:27 - 2014-05-10 00:27 - 00000000 ____D () C:\Users\asus\AppData\Local\{E6E3EB61-B75F-4D54-9ACD-584E431E7736} 2014-05-09 09:00 - 2014-05-09 09:00 - 00000000 ____D () C:\Users\asus\AppData\Local\{391DBA32-3F8B-469D-885A-5A6562D3361D} 2014-05-08 20:29 - 2014-05-08 20:29 - 00000000 ____D () C:\Users\asus\AppData\Local\{671E9D3D-4623-4680-A10C-A0A6E495B0AB} 2014-05-06 22:55 - 2014-05-06 22:55 - 00000000 ____D () C:\Users\asus\AppData\Local\{58743261-6293-4AA3-995C-8A52CC84136D} 2014-05-06 13:52 - 2014-05-14 06:01 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-06 08:24 - 2014-05-06 08:24 - 00000000 ____D () C:\Users\asus\AppData\Local\{55375590-22C6-4326-A1B7-8643BF2BC706} 2014-05-05 14:04 - 2014-05-05 14:05 - 00000000 ____D () C:\Users\asus\AppData\Local\{DB962EAA-6344-4943-96F9-52AF3AA0D060} 2014-05-05 07:37 - 2014-05-05 07:37 - 00000000 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log 2014-05-04 07:22 - 2014-05-04 07:22 - 00000000 ____D () C:\Users\asus\AppData\Local\{5D9C60A2-5B8F-4C18-BF8F-261D83DBC3C3} 2014-05-03 09:07 - 2014-05-03 09:08 - 00000000 ____D () C:\Users\asus\AppData\Local\{AEBBB777-445B-4954-8678-063E105779A8} 2014-05-02 21:07 - 2014-05-02 21:07 - 00000000 ____D () C:\Users\asus\AppData\Local\{3C74BA62-9505-40D9-B4F3-375CA893B250} 2014-05-02 09:06 - 2014-05-02 09:07 - 00000000 ____D () C:\Users\asus\AppData\Local\{25D788D6-D557-4D41-AE59-A7286CEE88B0} ==================== One Month Modified Files and Folders ======= 2014-06-01 10:07 - 2014-06-01 09:51 - 00014249 _____ () C:\Users\asus\Downloads\FRST.txt 2014-06-01 10:07 - 2013-12-04 10:00 - 00000000 ____D () C:\FRST 2014-06-01 10:07 - 2012-01-12 18:20 - 00000000 ____D () C:\Users\asus\AppData\Local\Temp 2014-06-01 10:06 - 2014-06-01 09:49 - 00000470 _____ () C:\Users\asus\Downloads\defogger_disable.log 2014-06-01 10:03 - 2012-08-22 19:49 - 00000000 ____D () C:\Users\asus\AppData\Roaming\Spotify 2014-06-01 10:03 - 2012-08-22 19:49 - 00000000 ____D () C:\Users\asus\AppData\Local\Spotify 2014-06-01 10:02 - 2012-07-13 20:40 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2014-06-01 10:01 - 2012-01-12 18:20 - 00000000 ___HD () C:\ASUS.DAT 2014-06-01 10:00 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-06-01 09:59 - 2009-07-14 06:51 - 00136961 _____ () C:\Windows\setupact.log 2014-06-01 09:54 - 2012-04-04 16:50 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-06-01 09:51 - 2014-06-01 09:51 - 00000000 ____D () C:\Users\asus\Downloads\FRST-OlderVersion 2014-06-01 09:51 - 2013-12-05 16:15 - 02067456 _____ (Farbar) C:\Users\asus\Downloads\FRST64.exe 2014-06-01 09:49 - 2014-06-01 09:49 - 00000000 _____ () C:\Users\asus\defogger_reenable 2014-06-01 09:49 - 2012-01-12 18:20 - 00000000 ____D () C:\Users\asus 2014-06-01 09:48 - 2014-06-01 09:48 - 00050477 _____ () C:\Users\asus\Downloads\Defogger.exe 2014-06-01 09:36 - 2014-06-01 09:25 - 00005739 _____ () C:\Users\asus\Downloads\hijackthis.log 2014-06-01 09:36 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-06-01 09:36 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-06-01 09:32 - 2011-10-11 11:59 - 01182123 _____ () C:\Windows\WindowsUpdate.log 2014-06-01 09:07 - 2014-06-01 09:07 - 00388608 _____ (Trend Micro Inc.) C:\Users\asus\Downloads\HiJackThis204.exe 2014-05-31 08:16 - 2014-05-31 08:15 - 00000000 ____D () C:\Users\asus\AppData\Local\{0C71ADA1-65C2-4591-AA7A-8D2E6CC883A5} 2014-05-30 20:14 - 2014-05-30 20:14 - 00000000 ____D () C:\Users\asus\AppData\Local\{D3953CF0-161B-4012-A906-5FB118F4825B} 2014-05-30 19:24 - 2012-01-12 18:20 - 00045056 _____ () C:\Windows\system32\acovcnt.exe 2014-05-29 23:51 - 2013-02-26 14:56 - 02174976 ___SH () C:\Users\asus\Desktop\Thumbs.db 2014-05-29 21:21 - 2014-05-29 21:20 - 00000000 ____D () C:\Users\asus\AppData\Local\{B83C51A6-A955-45AA-8CEC-283220D68297} 2014-05-29 21:19 - 2014-05-28 08:30 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2014-05-29 01:23 - 2014-05-29 01:22 - 00000000 ____D () C:\Users\asus\AppData\Local\{BEE1E00C-9B2E-4AC1-A5DF-61789FB9C898} 2014-05-28 19:21 - 2009-07-14 07:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2014-05-28 08:43 - 2014-05-28 08:30 - 00000000 ____D () C:\Program Files (x86)\Spyware Terminator 2014-05-28 08:42 - 2011-10-11 12:10 - 00001372 _____ () C:\Windows\system32\ServiceFilter.ini 2014-05-28 08:41 - 2011-10-11 12:10 - 00002474 _____ () C:\Windows\system32\AutoRunFilter.ini 2014-05-28 08:30 - 2014-05-28 08:30 - 00051496 _____ (Windows (R) Win 7 DDK provider) C:\Windows\system32\Drivers\stflt.sys 2014-05-28 08:30 - 2014-05-28 08:30 - 00000000 ____D () C:\Users\asus\AppData\Roaming\Spyware Terminator 2014-05-28 08:30 - 2014-05-28 08:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spyware Terminator 2012 2014-05-28 08:28 - 2009-07-14 04:34 - 00450712 ____R () C:\Windows\system32\Drivers\etc\hosts.20140529-104806.backup 2014-05-27 20:55 - 2014-05-27 20:55 - 00000000 ____D () C:\Users\asus\AppData\Local\{6C63488F-2B88-47FA-A579-E492A6365B06} 2014-05-27 08:15 - 2014-05-27 08:15 - 00000000 ____D () C:\Users\asus\AppData\Local\{B35D7729-885B-4CF0-9AD0-2087590A2F96} 2014-05-27 06:49 - 2014-05-27 06:49 - 00000000 ____D () C:\Users\asus\AppData\Local\{6655094B-0896-45EE-AA24-70CC8D0904CD} 2014-05-26 17:28 - 2014-05-26 17:28 - 00000000 ____D () C:\Users\asus\AppData\Local\{5DEDB503-1FD2-4218-B7AC-9CBD3AD75B25} 2014-05-26 00:42 - 2014-05-26 00:42 - 00000000 ____D () C:\Users\asus\AppData\Local\{8F5E763F-6CBF-48F7-B762-B57CAE995EA5} 2014-05-25 09:46 - 2014-05-25 09:46 - 00000000 ____D () C:\Users\asus\AppData\Local\{0F689E3E-F4BE-4072-894B-74C6EF5E2963} 2014-05-25 09:45 - 2013-06-27 13:57 - 00000000 ____D () C:\Users\asus\Desktop\Bildergezeuge 2014-05-24 14:30 - 2014-05-24 14:30 - 00000000 ____D () C:\Users\asus\AppData\Local\{0827953E-A7EA-489C-A91C-7D851F831D52} 2014-05-24 02:28 - 2014-05-24 02:28 - 00000000 ____D () C:\Users\asus\AppData\Local\{644BCC2A-78F4-4653-8928-630DEFD88337} 2014-05-23 08:36 - 2014-05-23 08:36 - 00000000 ____D () C:\Users\asus\AppData\Local\{684DF0EC-AEF8-4389-87C2-920B8C8E5BF1} 2014-05-22 20:23 - 2014-05-22 20:23 - 00000000 ____D () C:\Users\asus\AppData\Local\{C8D1BE66-42B8-4178-B2A6-1F07A4321058} 2014-05-22 07:39 - 2014-05-22 07:39 - 00000000 ____D () C:\Users\asus\AppData\Local\{34074692-0E0C-4DE5-8731-F01AD752215F} 2014-05-21 17:20 - 2014-05-21 17:20 - 00000000 ____D () C:\Users\asus\AppData\Local\{41C9C300-2DA1-477A-B5ED-53259EFF2E0B} 2014-05-20 23:24 - 2014-05-20 23:24 - 00000000 ____D () C:\Users\asus\AppData\Local\{4673BFBF-1D10-4CBF-9F2D-0BEE948CCFB9} 2014-05-19 21:11 - 2014-05-19 21:11 - 00000000 ____D () C:\Users\asus\AppData\Local\{340769B0-6A52-4728-AD3D-60E6B7DB8A56} 2014-05-18 22:31 - 2014-05-18 22:31 - 00000000 ____D () C:\Users\asus\AppData\Local\{4ED52C07-D4A6-47DD-88C3-6A81F3F17919} 2014-05-17 19:44 - 2014-05-17 19:44 - 00000000 ____D () C:\Users\asus\AppData\Local\{E61C4E76-91A7-48E9-B2F1-CC82BA0F7C8E} 2014-05-17 06:30 - 2014-05-17 06:30 - 00000000 ____D () C:\Users\asus\AppData\Local\{3F4D4A05-8B11-42D0-8E9D-0CBC6734273F} 2014-05-16 18:30 - 2014-05-16 18:30 - 00000000 ____D () C:\Users\asus\AppData\Local\{6B1E1553-2523-4C37-9E6E-CDFD79CC154D} 2014-05-16 06:07 - 2011-04-13 03:39 - 10457990 _____ () C:\Windows\PFRO.log 2014-05-15 19:25 - 2014-01-11 01:13 - 00085328 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys 2014-05-15 19:25 - 2012-01-21 17:51 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys 2014-05-15 19:25 - 2012-01-21 17:51 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys 2014-05-15 13:18 - 2014-05-15 13:17 - 00000000 ____D () C:\Users\asus\AppData\Local\{6A54CAFE-D371-4093-99FC-A4CED42DCB0B} 2014-05-14 22:36 - 2014-05-14 22:36 - 00000000 ____D () C:\Users\asus\AppData\Local\{0A982BB7-CB4E-44FF-9E28-B86F700D4959} 2014-05-14 20:30 - 2013-09-12 04:16 - 00000000 ____D () C:\Windows\rescache 2014-05-14 19:36 - 2014-05-14 19:36 - 00000000 __SHD () C:\Users\asus\AppData\Local\EmieUserList 2014-05-14 19:36 - 2014-05-14 19:36 - 00000000 __SHD () C:\Users\asus\AppData\Local\EmieSiteList 2014-05-14 19:36 - 2012-01-16 21:44 - 00000000 ____D () C:\Users\asus\AppData\Local\Google 2014-05-14 19:36 - 2011-04-13 04:33 - 00000000 ____D () C:\Program Files (x86)\Google 2014-05-14 19:27 - 2014-04-12 00:10 - 00001968 _____ () C:\Users\Public\Desktop\avast! Free Antivirus.lnk 2014-05-14 19:25 - 2014-05-14 19:25 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr 2014-05-14 19:25 - 2014-05-14 19:25 - 00029208 _____ () C:\Windows\system32\Drivers\aswHwid.sys 2014-05-14 19:25 - 2013-03-24 18:46 - 00208416 _____ () C:\Windows\system32\Drivers\aswVmm.sys 2014-05-14 19:25 - 2013-03-24 18:46 - 00065776 _____ () C:\Windows\system32\Drivers\aswRvrt.sys 2014-05-14 19:25 - 2012-02-26 19:46 - 00093568 _____ (AVAST Software) C:\Windows\system32\Drivers\aswRdr2.sys 2014-05-14 19:25 - 2012-01-21 17:51 - 01039096 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsnx.sys.1400174758572 2014-05-14 19:25 - 2012-01-21 17:51 - 00423240 _____ (AVAST Software) C:\Windows\system32\Drivers\aswsp.sys.1400174758572 2014-05-14 19:25 - 2012-01-21 17:51 - 00334648 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe 2014-05-14 19:25 - 2012-01-21 17:51 - 00079184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys 2014-05-14 19:22 - 2012-02-27 18:16 - 00002441 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk 2014-05-14 17:54 - 2012-04-04 16:50 - 00692400 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-05-14 17:54 - 2012-04-04 16:50 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2014-05-14 17:54 - 2012-01-16 20:58 - 00070832 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-05-14 06:06 - 2012-01-12 18:21 - 00000000 ___RD () C:\Users\asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-05-14 06:06 - 2012-01-12 18:21 - 00000000 ___RD () C:\Users\asus\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools 2014-05-14 06:01 - 2014-05-06 13:52 - 00000000 ___SD () C:\Windows\system32\CompatTel 2014-05-14 01:25 - 2012-10-12 18:51 - 00000000 ____D () C:\ProgramData\Microsoft Help 2014-05-14 01:24 - 2013-08-02 06:27 - 00000000 ____D () C:\Windows\system32\MRT 2014-05-14 01:22 - 2012-01-21 11:22 - 93223848 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-05-13 16:53 - 2014-05-13 16:53 - 00000000 ____D () C:\Users\asus\AppData\Local\{2C31B0B9-08C5-4D9E-93C7-95D7263B7786} 2014-05-12 10:31 - 2014-05-12 10:31 - 00000000 ____D () C:\Users\asus\AppData\Local\{54B34AE9-762B-47B5-89A0-1FFC763E544C} 2014-05-11 22:30 - 2014-05-11 22:30 - 00000000 ____D () C:\Users\asus\AppData\Local\{68A45214-2BC7-4591-9BCE-EAF6C26633F3} 2014-05-11 10:30 - 2014-05-11 10:30 - 00000000 ____D () C:\Users\asus\AppData\Local\{5CC2DBB2-FCD0-4C66-B698-BE1FF35C4524} 2014-05-11 09:00 - 2012-07-16 08:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2014-05-10 12:28 - 2014-05-10 12:28 - 00000000 ____D () C:\Users\asus\AppData\Local\{6E4CCAD1-440F-4B5D-815E-0885EDA73D2D} 2014-05-10 09:12 - 2014-05-10 09:12 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2014-05-10 00:27 - 2014-05-10 00:27 - 00000000 ____D () C:\Users\asus\AppData\Local\{E6E3EB61-B75F-4D54-9ACD-584E431E7736} 2014-05-09 09:00 - 2014-05-09 09:00 - 00000000 ____D () C:\Users\asus\AppData\Local\{391DBA32-3F8B-469D-885A-5A6562D3361D} 2014-05-09 08:14 - 2014-05-14 00:50 - 00477184 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll 2014-05-09 08:11 - 2014-05-14 00:50 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll 2014-05-08 20:29 - 2014-05-08 20:29 - 00000000 ____D () C:\Users\asus\AppData\Local\{671E9D3D-4623-4680-A10C-A0A6E495B0AB} 2014-05-06 22:55 - 2014-05-06 22:55 - 00000000 ____D () C:\Users\asus\AppData\Local\{58743261-6293-4AA3-995C-8A52CC84136D} 2014-05-06 08:24 - 2014-05-06 08:24 - 00000000 ____D () C:\Users\asus\AppData\Local\{55375590-22C6-4326-A1B7-8643BF2BC706} 2014-05-06 06:40 - 2014-05-14 01:25 - 23544320 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2014-05-06 06:17 - 2014-05-14 01:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2014-05-06 05:25 - 2014-05-14 01:25 - 17382912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2014-05-06 05:07 - 2014-05-14 01:25 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2014-05-06 05:00 - 2014-05-14 01:25 - 00084992 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2014-05-06 04:10 - 2014-05-14 01:25 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2014-05-05 14:05 - 2014-05-05 14:04 - 00000000 ____D () C:\Users\asus\AppData\Local\{DB962EAA-6344-4943-96F9-52AF3AA0D060} 2014-05-05 07:43 - 2013-09-21 19:59 - 00000000 ____D () C:\ProgramData\Oracle 2014-05-05 07:37 - 2014-05-05 07:37 - 00000000 _____ () C:\Windows\SysWOW64\jupdate-1.7.0_55-b14.log 2014-05-05 07:37 - 2013-09-21 19:58 - 00000000 ____D () C:\Program Files (x86)\Java 2014-05-04 07:22 - 2014-05-04 07:22 - 00000000 ____D () C:\Users\asus\AppData\Local\{5D9C60A2-5B8F-4C18-BF8F-261D83DBC3C3} 2014-05-03 09:08 - 2014-05-03 09:07 - 00000000 ____D () C:\Users\asus\AppData\Local\{AEBBB777-445B-4954-8678-063E105779A8} 2014-05-02 21:07 - 2014-05-02 21:07 - 00000000 ____D () C:\Users\asus\AppData\Local\{3C74BA62-9505-40D9-B4F3-375CA893B250} 2014-05-02 09:07 - 2014-05-02 09:06 - 00000000 ____D () C:\Users\asus\AppData\Local\{25D788D6-D557-4D41-AE59-A7286CEE88B0} Some content of TEMP: ==================== C:\Users\asus\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe C:\Users\asus\AppData\Local\Temp\jre-7u55-windows-i586-iftw.exe C:\Users\asus\AppData\Local\Temp\ose00000.exe C:\Users\asus\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-05-29 10:32 ==================== End Of Log ============================ Addition Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 01-06-2014 Ran by asus at 2014-06-01 10:11:19 Running from C:\Users\asus\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== Adobe Flash Player 13 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated) Adobe Photoshop Lightroom 2.7 64-bit (HKLM\...\{9B9DBB81-1F48-48B0-8CB3-051311DC73F7}) (Version: 2.7 - Adobe) Adobe Reader X (10.1.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.10 - Adobe Systems Incorporated) Alcor Micro USB Card Reader (HKLM-x32\...\InstallShield_{878CADF7-5BD6-4A29-A6F4-AC51C0CE8068}) (Version: 1.8.17.26026 - Alcor Micro Corp.) Alcor Micro USB Card Reader (x32 Version: 1.8.17.26026 - Alcor Micro Corp.) Hidden Apple Application Support (HKLM-x32\...\{F5266D28-E0B2-4130-BFC5-EE155AD514DC}) (Version: 2.3 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}) (Version: 6.0.0.59 - Apple Inc.) Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) ASUS AI Recovery (HKLM-x32\...\{38253529-D97D-4901-AE53-5CC9736D3A2E}) (Version: 1.0.13 - ASUS) ASUS FancyStart (HKLM-x32\...\{2B81872B-A054-48DA-BE3B-FA5C164C303A}) (Version: 1.1.0 - ASUSTeK Computer Inc.) ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.21 - ASUS) ASUS Live Update (HKLM-x32\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.1.43 - ASUS) ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0011 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0031 - ASUS) ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.21 - asus) ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.84.161 - eCareme Technologies, Inc.) AsusScr_K3 Series_ENG_Basic (HKLM-x32\...\AsusScr_K3 Series_ENG_Basic) (Version: 1.0.0001 - ASUS) AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.4.617 - ASUSTEK) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0008 - ASUS) avast! Free Antivirus (HKLM-x32\...\avast) (Version: 9.0.2018 - Avast Software) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Bookworm Deluxe (HKLM-x32\...\Bookworm Deluxe) (Version: - Oberon Media Inc.) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation) Cooking Dash (HKLM-x32\...\Cooking Dash) (Version: - Oberon Media Inc.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.8 - DivX, LLC) EPSON Photo Print (HKLM-x32\...\{D379964B-685C-44D5-AE46-C953A9FEEA14}) (Version: - ) EPSON Smart Panel (HKLM-x32\...\{6C11D561-620B-47DA-A693-4C597F3CDF40}) (Version: - ) ETDWare PS/2-X64 8.0.5.0_WHQL (HKLM\...\Elantech) (Version: 8.0.5.0 - ELAN Microelectronic Corp.) Facebook Video Calling 1.2.0.159 (HKLM-x32\...\{7CAC6A44-C3DE-4153-ACA6-7524602C789E}) (Version: 1.2.159 - Skype Limited) Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.8 - ASUS) FileZilla Client 3.6.0.2 (HKLM-x32\...\FileZilla Client) (Version: 3.6.0.2 - FileZilla Project) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Park Console (HKLM-x32\...\{E71E60C1-533E-45A5-8D80-E475E88D2B17}_is1) (Version: 6.2.1.1 - Oberon Media, Inc.) Governor of Poker (HKLM-x32\...\Governor of Poker) (Version: - Oberon Media Inc.) Hotel Dash Suite Success (HKLM-x32\...\Hotel Dash Suite Success) (Version: - Oberon Media Inc.) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Jewel Quest 3 (HKLM-x32\...\Jewel Quest 3) (Version: - Oberon Media Inc.) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden K-Lite Codec Pack 7.0.0 (Standard) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 7.0.0 - ) Logitech Harmony Remote Software 7 (HKLM-x32\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech) Logitech Harmony Remote Software 7 (x32 Version: 7.7.0.0 - Logitech) Hidden Luminance HDR 2.3.1 (HKLM\...\{7020FC34-6E04-4858-924D-354B28CB2402}_is1) (Version: - Luminance HDR Dev Team) Luxor 3 (HKLM-x32\...\Luxor 3) (Version: - Oberon Media Inc.) Mahjongg dimensions (HKLM-x32\...\Mahjongg dimensions) (Version: - Oberon Media Inc.) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (DEU) (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Access MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Groove MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Publisher MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden Open Freely (HKLM\...\{1BF14E04-85DE-480C-9A04-EB36744C66C3}_is1) (Version: 1.0 - Download Freely, LLC) P3170P Referenzhandbuch (HKLM-x32\...\P3170P Referenzhandbuch) (Version: - ) Plants vs Zombies (HKLM-x32\...\Plants vs Zombies) (Version: - Oberon Media Inc.) PokerStars.net (HKLM-x32\...\PokerStars.net) (Version: - PokerStars.net) Presto! BizCard 4.1 (Deutsch Version) (HKLM-x32\...\Uninstall Presto! BizCard 4.1 Ger) (Version: - ) QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Ralink RT2860 Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.5.9.0 - Ralink) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6324 - Realtek Semiconductor Corp.) Remote Control USB Driver (HKLM-x32\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - ) ScanToWeb (HKLM-x32\...\{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}) (Version: - ) Spotify (HKCU\...\Spotify) (Version: 0.9.10.14.g578d350b - Spotify AB) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) Spyware Terminator 2012 (HKLM-x32\...\{56736259-613E-4A3B-B428-6235F2E76F44}_is1) (Version: 3.0.0.82 - Crawler.com) syncables desktop SE (HKLM-x32\...\{341697D8-9923-445E-B42A-529E5A99CB7A}) (Version: 5.5.746.11492 - syncables) TomTom HOME (HKLM-x32\...\{EC5F4C1B-F838-4CB7-8561-8F809296428B}) (Version: 2.9.5 - Ihr Firmenname) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{EA54F104-79D2-48CC-9ABC-91A63C43D353}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version: - Microsoft) Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2880505) 32-Bit Edition (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{2720451F-5D04-43EC-AB1F-26D948FD971B}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden WDR RadioRecorder (HKLM-x32\...\Tobit Radio.fx Server 1) (Version: - Tobit.Software) Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKCU\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden Windows Live Messenger (x32 Version: 15.4.3538.0513 - Корпорация Майкрософт) Hidden Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.1 - ASUS) WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.19 - ASUS) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation) بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation) معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Restore Points ========================= 21-05-2014 03:56:53 Windows Update 28-05-2014 17:55:25 Geplanter Prüfpunkt 30-05-2014 17:00:11 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2014-05-28 08:28 - 00450712 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 www.007guard.com 127.0.0.1 007guard.com 127.0.0.1 008i.com 127.0.0.1 www.008k.com 127.0.0.1 008k.com 127.0.0.1 www.00hq.com 127.0.0.1 00hq.com 127.0.0.1 010402.com 127.0.0.1 www.032439.com 127.0.0.1 032439.com 127.0.0.1 www.0scan.com 127.0.0.1 0scan.com 127.0.0.1 1000gratisproben.com 127.0.0.1 www.1000gratisproben.com 127.0.0.1 1001namen.com 127.0.0.1 www.1001namen.com 127.0.0.1 100888290cs.com 127.0.0.1 www.100888290cs.com 127.0.0.1 www.100sexlinks.com 127.0.0.1 100sexlinks.com 127.0.0.1 10sek.com 127.0.0.1 www.10sek.com 127.0.0.1 www.1-2005-search.com 127.0.0.1 1-2005-search.com 127.0.0.1 123fporn.info 127.0.0.1 www.123fporn.info 127.0.0.1 123haustiereundmehr.com 127.0.0.1 www.123haustiereundmehr.com 127.0.0.1 123moviedownload.com There are 1000 more lines. ==================== Scheduled Tasks (whitelisted) ============= Task: {0BDBACB9-AE89-4396-B7CF-D26CDF1760CD} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-05-14] (AVAST Software) Task: {0EB09FD5-EF02-4A15-B525-B0485DEA5CF4} - \DSite No Task File <==== ATTENTION Task: {483EA586-4ED2-4ABD-B6C3-FC551DBDBDB2} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS) Task: {6EE57C04-F5FB-4425-A47D-EBDE175EE10C} - \FTdownloader V4.0-codedownloader No Task File <==== ATTENTION Task: {79A7DAA8-1EF6-4EEF-9964-35390AA24933} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-14] (Adobe Systems Incorporated) Task: {9CBF1336-D2AD-4ED5-AF2B-1C31C0AF0776} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2010-08-02] (ASUS) Task: {A9B48AF5-3398-40FF-838B-1BA7AED37E38} - \BrowserDefendert No Task File <==== ATTENTION Task: {AC252660-F248-4C88-968A-16C755B39611} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {B1E25DF5-067E-4820-B727-872769A82772} - \QtraxPlayer No Task File <==== ATTENTION Task: {C7956B2B-1E10-454D-B957-142B8039715B} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2013-11-21] (Adobe Systems Incorporated) Task: {DD344CF4-2782-462C-9BD8-C3FF7A61AD12} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] () Task: {F1C5BF03-D855-4461-B2AA-59AAC4CA11D6} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-12-02] (ASUS) Task: {FF4DE54B-C03A-4CE2-A939-20FDC8EE74A3} - \DealPly No Task File <==== ATTENTION Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2010-01-02 16:42 - 2010-01-02 16:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2010-04-02 20:21 - 2008-10-01 00:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2011-10-11 12:10 - 2007-11-30 20:20 - 00051768 _____ () C:\PROGRAM FILES (X86)\ASUS\ASUS LIVE UPDATE\ALU.EXE 2010-07-15 01:11 - 2010-07-15 01:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll 2011-05-31 05:23 - 2011-01-27 02:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2010-09-24 01:53 - 2010-09-24 01:53 - 01601536 _____ () C:\PROGRAM FILES (X86)\ASUS\WIRELESS CONSOLE 3\WCOURIER.EXE 2014-06-01 09:41 - 2014-06-01 09:41 - 02259456 _____ () C:\Program Files\AVAST Software\Avast\defs\14060100\algo.dll 2011-10-11 12:10 - 2007-11-30 20:20 - 00051768 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe 2010-09-24 01:53 - 2010-09-24 01:53 - 01601536 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe 2013-12-06 15:32 - 2013-12-06 15:32 - 19336120 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2014-05-10 09:12 - 2014-05-10 09:12 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== ==================== EXE Association (whitelisted) ============= ==================== Disabled items from MSCONFIG ============== MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (05/31/2014 11:07:45 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/31/2014 11:07:44 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 14826397 Error: (05/31/2014 11:07:44 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 14826397 Error: (05/31/2014 11:07:44 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/31/2014 11:07:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 14825383 Error: (05/31/2014 11:07:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 14825383 Error: (05/31/2014 11:07:43 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (05/31/2014 11:07:42 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 14824385 Error: (05/31/2014 11:07:42 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 14824385 Error: (05/31/2014 11:07:42 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (06/01/2014 10:01:29 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SBSD Security Center Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/01/2014 10:01:29 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SBSD Security Center Service erreicht. Error: (06/01/2014 10:00:40 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Radio.fx Server" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/01/2014 10:00:40 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Radio.fx Server erreicht. Error: (06/01/2014 10:00:10 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Apple Mobile Device" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/01/2014 10:00:10 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Apple Mobile Device erreicht. Error: (06/01/2014 09:59:51 AM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 01.06.2014 um 09:58:22 unerwartet heruntergefahren. Error: (06/01/2014 09:29:29 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SBSD Security Center Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (06/01/2014 09:29:29 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SBSD Security Center Service erreicht. Error: (06/01/2014 09:28:46 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Apple Mobile Device" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 46% Total physical RAM: 4008.23 MB Available physical RAM: 2155.07 MB Total Pagefile: 8014.65 MB Available Pagefile: 6002.44 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:40.97 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:153.85 GB) (Free:92.91 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298 GB) (Disk ID: AA9693FE) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=119 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=154 GB) - (Type=OF Extended) ==================== End Of Log ============================ Geändert von J_DRX (01.06.2014 um 09:47 Uhr) |
01.06.2014, 09:29 | #2 |
/// the machine /// TB-Ausbilder | Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehr hi,
__________________So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Scan mit Combofix
__________________ |
02.06.2014, 07:56 | #3 |
| Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehrCode:
ATTFilter ComboFix 14-05-29.01 - asus 01.06.2014 10:54:00.1.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4008.2508 [GMT 2:00] ausgeführt von:: c:\users\asus\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\asus\4.0 c:\windows\IsUn0407.exe . . ((((((((((((((((((((((( Dateien erstellt von 2014-05-01 bis 2014-06-01 )))))))))))))))))))))))))))))) . . 2014-06-01 09:23 . 2014-06-01 09:23 -------- d-----w- c:\users\Default\AppData\Local\temp 2014-06-01 08:40 . 2014-06-01 08:40 75888 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F946EBB4-836B-4EB6-815F-0C460D3685D5}\offreg.dll 2014-05-30 17:01 . 2014-04-30 23:20 10702536 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{F946EBB4-836B-4EB6-815F-0C460D3685D5}\mpengine.dll 2014-05-28 06:30 . 2014-05-28 06:30 51496 ----a-w- c:\windows\system32\drivers\stflt.sys 2014-05-28 06:30 . 2014-05-29 19:19 -------- d-----w- c:\programdata\Spyware Terminator 2014-05-28 06:30 . 2014-05-28 06:30 -------- d-----w- c:\users\asus\AppData\Roaming\Spyware Terminator 2014-05-28 06:30 . 2014-05-28 06:43 -------- d-----w- c:\program files (x86)\Spyware Terminator 2014-05-14 17:36 . 2014-05-14 17:36 -------- d-sh--w- c:\users\asus\AppData\Local\EmieUserList 2014-05-14 17:36 . 2014-05-14 17:36 -------- d-sh--w- c:\users\asus\AppData\Local\EmieSiteList 2014-05-14 17:25 . 2014-05-14 17:25 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys 2014-05-14 17:25 . 2014-05-14 17:25 43152 ----a-w- c:\windows\avastSS.scr 2014-05-13 23:25 . 2014-05-06 04:40 23544320 ----a-w- c:\windows\system32\mshtml.dll 2014-05-13 23:25 . 2014-05-06 03:00 84992 ----a-w- c:\windows\system32\mshtmled.dll 2014-05-13 23:25 . 2014-05-06 04:17 2724864 ----a-w- c:\windows\system32\mshtml.tlb 2014-05-13 23:25 . 2014-05-06 03:07 2724864 ----a-w- c:\windows\SysWow64\mshtml.tlb 2014-05-06 11:52 . 2014-05-14 04:01 -------- d-s---w- c:\windows\system32\CompatTel . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2014-05-30 17:24 . 2012-01-12 16:20 45056 ----a-w- c:\windows\system32\acovcnt.exe 2014-05-15 17:25 . 2014-01-10 23:13 85328 ----a-w- c:\windows\system32\drivers\aswstm.sys 2014-05-15 17:25 . 2012-01-21 15:51 423240 ----a-w- c:\windows\system32\drivers\aswsp.sys 2014-05-15 17:25 . 2012-01-21 15:51 1039096 ----a-w- c:\windows\system32\drivers\aswsnx.sys 2014-05-14 17:25 . 2013-03-24 16:46 208416 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2014-05-14 17:25 . 2013-03-24 16:46 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2014-05-14 17:25 . 2012-01-21 15:51 79184 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2014-05-14 17:25 . 2012-01-21 15:51 334648 ----a-w- c:\windows\system32\aswBoot.exe 2014-05-14 17:25 . 2012-02-26 17:46 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2014-05-14 15:54 . 2012-04-04 14:50 692400 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2014-05-14 15:54 . 2012-01-16 18:58 70832 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2014-05-13 23:22 . 2012-01-21 09:22 93223848 ----a-w- c:\windows\system32\MRT.exe 2014-03-31 20:46 . 2014-03-31 20:46 130712 ----a-w- c:\windows\SysWow64\MSSTDFMT.DLL 2014-03-31 20:46 . 2014-03-31 20:46 1070232 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX 2014-03-31 07:35 . 2012-01-16 15:07 270496 ------w- c:\windows\system32\MpSigStub.exe 2014-03-06 09:31 . 2014-04-23 06:40 4096 ----a-w- c:\windows\system32\ieetwcollectorres.dll 2014-03-06 08:59 . 2014-04-23 06:40 66048 ----a-w- c:\windows\system32\iesetup.dll 2014-03-06 08:57 . 2014-04-23 06:40 548352 ----a-w- c:\windows\system32\vbscript.dll 2014-03-06 08:57 . 2014-04-23 06:40 48640 ----a-w- c:\windows\system32\ieetwproxystub.dll 2014-03-06 08:53 . 2014-04-23 06:40 2767360 ----a-w- c:\windows\system32\iertutil.dll 2014-03-06 08:40 . 2014-04-23 06:40 51200 ----a-w- c:\windows\system32\jsproxy.dll 2014-03-06 08:39 . 2014-04-23 06:40 33792 ----a-w- c:\windows\system32\iernonce.dll 2014-03-06 08:32 . 2014-04-23 06:40 574976 ----a-w- c:\windows\system32\ieui.dll 2014-03-06 08:29 . 2014-04-23 06:40 139264 ----a-w- c:\windows\system32\ieUnatt.exe 2014-03-06 08:29 . 2014-04-23 06:40 111616 ----a-w- c:\windows\system32\ieetwcollector.exe 2014-03-06 08:28 . 2014-04-23 06:40 752640 ----a-w- c:\windows\system32\jscript9diag.dll 2014-03-06 08:15 . 2014-04-23 06:40 940032 ----a-w- c:\windows\system32\MsSpellCheckingFacility.exe 2014-03-06 08:11 . 2014-04-23 06:39 5784064 ----a-w- c:\windows\system32\jscript9.dll 2014-03-06 08:09 . 2014-04-23 06:40 453120 ----a-w- c:\windows\system32\dxtmsft.dll 2014-03-06 08:03 . 2014-04-23 06:40 586240 ----a-w- c:\windows\system32\ie4uinit.exe 2014-03-06 08:02 . 2014-04-23 06:40 61952 ----a-w- c:\windows\SysWow64\iesetup.dll 2014-03-06 08:02 . 2014-04-23 06:40 455168 ----a-w- c:\windows\SysWow64\vbscript.dll 2014-03-06 08:01 . 2014-04-23 06:40 51200 ----a-w- c:\windows\SysWow64\ieetwproxystub.dll 2014-03-06 07:56 . 2014-04-23 06:40 38400 ----a-w- c:\windows\system32\JavaScriptCollectionAgent.dll 2014-03-06 07:48 . 2014-04-23 06:40 195584 ----a-w- c:\windows\system32\msrating.dll 2014-03-06 07:46 . 2014-04-23 06:39 4254720 ----a-w- c:\windows\SysWow64\jscript9.dll 2014-03-06 07:42 . 2014-04-23 06:40 296960 ----a-w- c:\windows\system32\dxtrans.dll 2014-03-06 07:38 . 2014-04-23 06:40 112128 ----a-w- c:\windows\SysWow64\ieUnatt.exe 2014-03-06 07:36 . 2014-04-23 06:40 592896 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2014-03-06 07:21 . 2014-04-23 06:40 628736 ----a-w- c:\windows\system32\msfeeds.dll 2014-03-06 07:13 . 2014-04-23 06:40 32256 ----a-w- c:\windows\SysWow64\JavaScriptCollectionAgent.dll 2014-03-06 07:11 . 2014-04-23 06:39 2043904 ----a-w- c:\windows\system32\inetcpl.cpl 2014-03-06 06:53 . 2014-04-23 06:39 13551104 ----a-w- c:\windows\system32\ieframe.dll 2014-03-06 06:40 . 2014-04-23 06:39 1967104 ----a-w- c:\windows\SysWow64\inetcpl.cpl 2014-03-06 06:22 . 2014-04-23 06:40 2260480 ----a-w- c:\windows\system32\wininet.dll 2014-03-06 05:58 . 2014-04-23 06:40 1400832 ----a-w- c:\windows\system32\urlmon.dll 2014-03-06 05:50 . 2014-04-23 06:40 846336 ----a-w- c:\windows\system32\ieapfltr.dll 2014-03-06 05:41 . 2014-04-23 06:40 1789440 ----a-w- c:\windows\SysWow64\wininet.dll 2014-03-04 09:44 . 2014-04-10 00:16 362496 ----a-w- c:\windows\system32\wow64win.dll 2014-03-04 09:44 . 2014-04-10 00:16 243712 ----a-w- c:\windows\system32\wow64.dll 2014-03-04 09:44 . 2014-04-10 00:16 13312 ----a-w- c:\windows\system32\wow64cpu.dll 2014-03-04 09:44 . 2014-04-10 00:16 16384 ----a-w- c:\windows\system32\ntvdm64.dll 2014-03-04 09:44 . 2014-04-10 00:16 1163264 ----a-w- c:\windows\system32\kernel32.dll 2014-03-04 09:17 . 2014-04-10 00:16 14336 ----a-w- c:\windows\SysWow64\ntvdm64.dll 2014-03-04 09:17 . 2014-04-10 00:16 44032 ----a-w- c:\windows\apppatch\acwow64.dll 2014-03-04 09:16 . 2014-04-10 00:16 25600 ----a-w- c:\windows\SysWow64\setup16.exe 2014-03-04 09:16 . 2014-04-10 00:16 5120 ----a-w- c:\windows\SysWow64\wow32.dll 2014-03-04 08:09 . 2014-04-10 00:16 7680 ----a-w- c:\windows\SysWow64\instnm.exe 2014-03-04 08:09 . 2014-04-10 00:16 2048 ----a-w- c:\windows\SysWow64\user.exe . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "Spotify Web Helper"="c:\users\asus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2014-05-16 1176632] "Spotify"="c:\users\asus\AppData\Roaming\Spotify\spotify.exe" [2014-05-16 6170168] "TomTomHOME.exe"="c:\program files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" [2013-03-22 248208] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-13 2018032] "ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe" [2011-02-23 731472] "ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992] "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624] "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536] "WinampAgent"="c:\program files (x86)\Winamp\winampa.exe" [2012-06-28 74752] "APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-10-11 59280] "QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-10-25 421888] "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2014-05-26 3888648] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe /start [2011-4-13 548528] FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe -d [2012-1-17 12862] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "c:\programdata\Nuance\PDF Reader\Ereg\Ereg.ini" "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" . R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S1 aswKbd;aswKbd; [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x] S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 Radio.fx;Radio.fx Server;c:\program files (x86)\Tobit Radio.fx\Server\rfx-server.exe;c:\program files (x86)\Tobit Radio.fx\Server\rfx-server.exe [x] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [x] S2 sp_rsdrv2;Spyware Terminator Driver Filter;c:\windows\system32\DRIVERS\stflt.sys;c:\windows\SYSNATIVE\DRIVERS\stflt.sys [x] S2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files (x86)\Spyware Terminator\st_rsser64.exe;c:\program files (x86)\Spyware Terminator\st_rsser64.exe [x] S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2014-06-01 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 15:54] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2014-05-14 17:25 290888 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B] @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}" [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}] 2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O] @="{64174815-8D98-4CE6-8646-4C039977D808}" [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}] 2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-03-01 2189416] "AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-08-11 324096] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-31 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-31 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-31 416024] "SpywareTerminatorShield"="c:\program files (x86)\Spyware Terminator\SpywareTerminatorShield.exe" [2013-04-03 2777736] "SpywareTerminatorUpdater"="c:\program files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe" [2013-04-03 3684488] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = about:blank mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\asus\AppData\Roaming\Mozilla\Firefox\Profiles\j10ut53x.default-1349158430390\ FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . URLSearchHooks-{ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - (no file) Toolbar-Locked - (no file) Wow6432Node-HKLM-Run-DivXMediaServer - c:\program files (x86)\DivX\DivX Media Server\DivXMediaServer.exe HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start BHO-{11111111-1111-1111-1111-110311551174} - c:\program files (x86)\FTdownloader V4.0\FTdownloader V4.0-bho64.dll Toolbar-Locked - (no file) WebBrowser-{EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} - (no file) HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe AddRemove-Uninstall Presto! BizCard 4.1 Ger - c:\windows\IsUn0407.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_13_0_0_214_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_13_0_0_214_ActiveX.exe" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.13" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_13_0_0_214.ocx, 1" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}] @Denied: (A 2) (Everyone) @="IFlashBroker5" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2014-06-01 11:31:27 ComboFix-quarantined-files.txt 2014-06-01 09:31 . Vor Suchlauf: 10 Verzeichnis(se), 43.655.528.448 Bytes frei Nach Suchlauf: 16 Verzeichnis(se), 43.568.017.408 Bytes frei . - - End Of File - - C2D47BFA1EEA5E8C54A06BE5D17F5F59 Wars das jetzt? Die shell Meldung kommt nicht mehr. Lappi ist auch schon die ganze Zeit nach dem letzten Scan nicht mehr abgeschmiert. Was sagt der letzte Log denn? Soeben hatte ich wieder die Meldung (Keine Rückmeldung) beim Firefox. Laptop hat sich dann wieder aufgehängt. Problem besteht also immer noch. |
02.06.2014, 19:06 | #4 |
/// the machine /// TB-Ausbilder | Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehr Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
18.02.2015, 09:08 | #5 |
| Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehr Hallo, habe das gleiche Problem wieder. HabeCombofix schon mal ausgeführt und das Logfile kopiert. Code:
ATTFilter ComboFix 15-02-16.01 - asus 18.02.2015 8:16.2.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4008.2465 [GMT 1:00] ausgeführt von:: c:\users\asus\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . . c:\users\asus\AppData\Local\{2FB2C141-F70D-4F1F-BA3E-29CAA6589CEF} c:\windows\msvcr71.dll c:\windows\wininit.ini . . ((((((((((((((((((((((( Dateien erstellt von 2015-01-18 bis 2015-02-18 )))))))))))))))))))))))))))))) . . 2015-02-18 07:51 . 2015-02-18 07:51 -------- d-----w- c:\users\Public\AppData\Local\temp 2015-02-18 07:51 . 2015-02-18 07:51 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-02-18 05:14 . 2015-01-29 09:07 11910896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{43A356C6-8A86-4E8D-A87B-1B8C0DA181CB}\mpengine.dll 2015-02-17 16:55 . 2015-01-09 03:14 91136 ----a-w- c:\windows\system32\wdi.dll 2015-02-17 16:55 . 2015-01-09 03:14 950272 ----a-w- c:\windows\system32\perftrack.dll 2015-02-17 16:55 . 2015-01-09 03:14 29696 ----a-w- c:\windows\system32\powertracker.dll 2015-02-17 16:55 . 2015-01-09 02:48 76800 ----a-w- c:\windows\SysWow64\wdi.dll 2015-02-12 06:54 . 2015-01-23 03:43 620032 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2015-02-12 06:54 . 2015-01-23 03:17 4300800 ----a-w- c:\windows\SysWow64\jscript9.dll 2015-02-12 06:54 . 2015-01-23 04:42 814080 ----a-w- c:\windows\system32\jscript9diag.dll 2015-02-12 06:54 . 2015-01-23 04:41 6041600 ----a-w- c:\windows\system32\jscript9.dll 2015-02-11 07:05 . 2015-01-13 03:10 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2015-02-11 07:04 . 2014-11-26 03:53 861696 ----a-w- c:\windows\system32\oleaut32.dll 2015-02-11 07:03 . 2015-01-09 02:03 3201536 ----a-w- c:\windows\system32\win32k.sys . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-02-18 06:51 . 2012-01-12 16:20 45056 ----a-w- c:\windows\system32\acovcnt.exe 2015-02-11 07:59 . 2012-01-21 09:22 116773704 ----a-w- c:\windows\system32\MRT.exe 2015-02-05 18:54 . 2012-04-04 14:50 701616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2015-02-05 18:54 . 2012-01-16 18:58 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2015-01-15 08:00 . 2012-01-21 15:51 1050432 ----a-w- c:\windows\system32\drivers\aswsnx.sys 2015-01-15 07:59 . 2015-01-15 07:59 364512 ----a-w- c:\windows\system32\aswBoot.exe 2015-01-15 07:59 . 2014-05-14 17:25 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys 2015-01-15 07:59 . 2014-01-10 23:13 116728 ----a-w- c:\windows\system32\drivers\aswstm.sys 2015-01-15 07:59 . 2013-03-24 16:46 267632 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2015-01-15 07:59 . 2013-03-24 16:46 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2015-01-15 07:59 . 2012-02-26 17:46 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2015-01-15 07:59 . 2012-01-21 15:51 436624 ----a-w- c:\windows\system32\drivers\aswsp.sys 2015-01-15 07:59 . 2012-01-21 15:51 83280 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2015-01-15 07:59 . 2015-01-15 07:59 43152 ----a-w- c:\windows\avastSS.scr 2014-12-22 23:41 . 2012-01-16 15:07 298120 ------w- c:\windows\system32\MpSigStub.exe 2014-12-19 03:06 . 2015-01-14 03:16 210432 ----a-w- c:\windows\system32\profsvc.dll 2014-12-19 01:46 . 2015-01-14 03:16 141312 ----a-w- c:\windows\system32\drivers\mrxdav.sys 2014-12-11 17:47 . 2015-01-14 03:16 52736 ----a-w- c:\windows\system32\TSWbPrxy.exe 2014-12-06 04:17 . 2015-01-14 03:16 303616 ----a-w- c:\windows\system32\nlasvc.dll 2014-12-06 03:50 . 2015-01-14 03:16 52224 ----a-w- c:\windows\SysWow64\nlaapi.dll 2014-12-06 03:50 . 2015-01-14 03:16 156672 ----a-w- c:\windows\SysWow64\ncsi.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "Spotify Web Helper"="c:\users\asus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2015-01-05 1676344] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-13 2018032] "ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe" [2011-02-23 731472] "ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992] "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624] "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-01-27 5227112] "Wondershare Helper Compact.exe"="c:\program files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" [2012-03-27 1686528] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe /start [2011-4-13 548528] FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe -d [2012-1-16 12862] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "c:\programdata\Nuance\PDF Reader\Ereg\Ereg.ini" "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" . R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [x] R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S1 aswKbd;aswKbd; [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x] S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 Radio.fx;Radio.fx Server;c:\program files (x86)\Tobit Radio.fx\Server\rfx-server.exe;c:\program files (x86)\Tobit Radio.fx\Server\rfx-server.exe [x] S2 sp_rsdrv2;Spyware Terminator Driver Filter;c:\windows\system32\DRIVERS\stflt.sys;c:\windows\SYSNATIVE\DRIVERS\stflt.sys [x] S2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files (x86)\Spyware Terminator\st_rsser64.exe;c:\program files (x86)\Spyware Terminator\st_rsser64.exe [x] S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2015-02-18 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 18:54] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2015-01-15 07:59 860984 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B] @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}" [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}] 2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O] @="{64174815-8D98-4CE6-8646-4C039977D808}" [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}] 2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-03-01 2189416] "AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-08-11 324096] "ETDCtrl"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-31 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-31 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-31 416024] "SpywareTerminatorShield"="c:\program files (x86)\Spyware Terminator\SpywareTerminatorShield.exe" [2013-04-03 2777736] "SpywareTerminatorUpdater"="c:\program files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe" [2013-04-03 3684488] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.startfenster.de mLocal Page = c:\windows\SysWOW64\blank.htm uInternet Settings,ProxyOverride = *.local IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\asus\AppData\Roaming\Mozilla\Firefox\Profiles\j10ut53x.default-1349158430390\ FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) AddRemove-Uninstall Presto! BizCard 4.1 Ger - c:\windows\IsUn0407.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.16" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2015-02-18 08:58:31 ComboFix-quarantined-files.txt 2015-02-18 07:58 ComboFix2.txt 2014-06-01 09:31 . Vor Suchlauf: 2.939.383.808 Bytes frei Nach Suchlauf: 2.560.143.360 Bytes frei . - - End Of File - - 6722CC44D7A3C38FA97108C4BE14045E |
18.02.2015, 15:02 | #6 |
/// the machine /// TB-Ausbilder | Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehr JOah, wenn man einfach mittem im Thema aufhört.... Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ --> Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehr |
18.02.2015, 17:21 | #7 |
| Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehr FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-02-2015 Ran by asus (administrator) on ASUS-PC on 18-02-2015 17:19:24 Running from C:\Users\asus\Downloads Loaded Profiles: asus (Available profiles: asus) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (ASUSTeK Computer Inc.) C:\Windows\System32\FBAgent.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\AsLdrSrv.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe (ASUS) C:\Program Files (x86)\ASUS\SmartLogon\smartlogon.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe (ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe (ASUS) C:\Program Files\P4G\BatteryLife.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe () C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe (ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe (ASUS) C:\Windows\AsScrPro.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe (Crawler.com) C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe (TomTom) C:\Program Files (x86)\TomTom HOME 2\TomTomHOMEService.exe (Alcor Micro Corp.) C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe (Spotify Ltd) C:\Users\asus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe (ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Mail\wlmail.exe (Microsoft Corporation) C:\Program Files (x86)\Windows Live\Contacts\wlcomm.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Farbar) C:\Users\asus\Downloads\FRST64(1).exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2189416 2011-03-01] (Realtek Semiconductor) HKLM\...\Run: [AmIcoSinglun64] => C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324096 2010-08-11] (Alcor Micro Corp.) HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2587944 2010-12-13] (ELAN Microelectronics Corp.) HKLM\...\Run: [SpywareTerminatorShield] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorShield.exe [2777736 2013-04-03] (Crawler.com) HKLM\...\Run: [SpywareTerminatorUpdater] => C:\Program Files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe [3684488 2013-04-03] (Crawler.com) HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.) HKLM-x32\...\Run: [ASUSWebStorage] => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe [731472 2011-02-23] (ecareme) HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-17] (ASUS) HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-07] (ASUS) HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS) HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] () HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [5227112 2015-01-27] (AVAST Software) HKLM-x32\...\Run: [Wondershare Helper Compact.exe] => C:\Program Files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe [1686528 2012-03-27] (Wondershare) HKLM-x32\...\RunOnce: [20150107] => C:\Program Files\AVAST Software\Avast\setup\emupdate\eddc564a-51a8-41cb-bcfe-c9edee3237d6.exe [183232 2015-02-18] (AVAST Software) Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation) HKU\S-1-5-21-2812954037-985756252-1433979443-1000\...\Run: [SpybotSD TeaTimer] => C:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exe [2260480 2009-03-05] (Safer-Networking Ltd.) HKU\S-1-5-21-2812954037-985756252-1433979443-1000\...\Run: [Spotify Web Helper] => C:\Users\asus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe [1676344 2015-01-05] (Spotify Ltd) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\AsusVibeLauncher.lnk ShortcutTarget: AsusVibeLauncher.lnk -> C:\Program Files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\FancyStart daemon.lnk ShortcutTarget: FancyStart daemon.lnk -> C:\Windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe () ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software) ShellIconOverlayIdentifiers: [AsusWSShellExt_B] -> {6D4133E5-0742-4ADC-8A8C-9303440F7190} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.) ShellIconOverlayIdentifiers: [AsusWSShellExt_O] -> {64174815-8D98-4CE6-8646-4C039977D808} => C:\Program Files (x86)\ASUS\ASUS WebStorage\3.0.84.161\ASUSWSShellExt64.dll (eCareme Technologies, Inc.) CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-2812954037-985756252-1433979443-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-2812954037-985756252-1433979443-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-2812954037-985756252-1433979443-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.startfenster.de SearchScopes: HKLM -> DefaultScope {F78E8F3F-B538-415C-961B-8E5199CEF3D2} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM -> {F78E8F3F-B538-415C-961B-8E5199CEF3D2} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM-x32 -> {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT SearchScopes: HKU\S-1-5-21-2812954037-985756252-1433979443-1000 -> DefaultScope {F78E8F3F-B538-415C-961B-8E5199CEF3D2} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKU\S-1-5-21-2812954037-985756252-1433979443-1000 -> {6A1806CD-94D4-4689-BA73-E35EA1EA9990} URL = SearchScopes: HKU\S-1-5-21-2812954037-985756252-1433979443-1000 -> {F78E8F3F-B538-415C-961B-8E5199CEF3D2} URL = hxxp://www.sm.de/?q={searchTerms} BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software) BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Spybot-S&D IE Protection -> {53707962-6F74-2D53-2644-206D7942484F} -> C:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dll (Safer Networking Limited) BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software) BHO-x32: Windows Live ID-Anmelde-Hilfsprogramm -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - No File Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - No File Tcpip\Parameters: [DhcpNameServer] 192.168.178.1 FireFox: ======== FF ProfilePath: C:\Users\asus\AppData\Roaming\Mozilla\Firefox\Profiles\j10ut53x.default-1349158430390 FF SearchEngineOrder.1: Ask Search FF Homepage: https://www.google.de/ FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_305.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_305.dll () FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> C:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation) FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-2812954037-985756252-1433979443-1000: @Skype Limited.com/Facebook Video Calling Plugin -> C:\Users\asus\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll No File FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npdbplug.dll (DNAML Pty Ltd) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin6.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npqtplugin7.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF FF Extension: Avast Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2012-01-21] Chrome: ======= CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2015-01-15] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2015-01-15] (AVAST Software) R2 Radio.fx; C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe [3673944 2011-11-18] () S2 SBSDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exe [1153368 2009-01-26] (Safer Networking Ltd.) R2 ST2012_Svc; C:\Program Files (x86)\Spyware Terminator\st_rsser64.exe [1149104 2013-04-03] (Crawler.com) R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2015-01-15] () R1 aswKbd; C:\Windows\System32\Drivers\aswKbd.sys [28504 2012-02-23] (AVAST Software) R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [83280 2015-01-15] (AVAST Software) R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2015-01-15] (AVAST Software) R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2015-01-15] () R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1050432 2015-01-15] (AVAST Software) R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [436624 2015-01-15] (AVAST Software) R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [116728 2015-01-15] (AVAST Software) R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [267632 2015-01-15] () R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( ) R2 sp_rsdrv2; C:\Windows\System32\DRIVERS\stflt.sys [51496 2014-05-28] (Windows (R) Win 7 DDK provider) S3 catchme; \??\C:\ComboFix\catchme.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-18 17:18 - 2015-02-18 17:18 - 02085888 _____ (Farbar) C:\Users\asus\Downloads\FRST64(1).exe 2015-02-18 13:35 - 2015-02-18 13:35 - 00000000 ____D () C:\Users\asus\AppData\Local\{4CC3BE61-92B0-49B4-BA9E-E84D46AF655C} 2015-02-18 08:58 - 2015-02-18 08:58 - 00017972 _____ () C:\ComboFix.txt 2015-02-17 20:31 - 2015-02-17 20:31 - 00000000 ____D () C:\Users\asus\AppData\Local\{EE933443-EAE9-4898-8759-C0AEF9E52638} 2015-02-17 17:55 - 2015-01-09 04:14 - 00950272 _____ (Microsoft Corporation) C:\Windows\system32\perftrack.dll 2015-02-17 17:55 - 2015-01-09 04:14 - 00091136 _____ (Microsoft Corporation) C:\Windows\system32\wdi.dll 2015-02-17 17:55 - 2015-01-09 04:14 - 00029696 _____ (Microsoft Corporation) C:\Windows\system32\powertracker.dll 2015-02-17 17:55 - 2015-01-09 03:48 - 00076800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdi.dll 2015-02-17 08:31 - 2015-02-17 08:31 - 00000000 ____D () C:\Users\asus\AppData\Local\{3DC9D1A0-083E-4AC3-A3AD-2E3A6D82BC29} 2015-02-16 20:30 - 2015-02-16 20:31 - 00000000 ____D () C:\Users\asus\AppData\Local\{82E131FC-BAF2-4A52-A86B-4C1C20A8E965} 2015-02-16 08:30 - 2015-02-16 08:30 - 00000000 ____D () C:\Users\asus\AppData\Local\{F37F34F5-7E10-49E7-BCF4-3DEE363E95BB} 2015-02-15 20:13 - 2015-02-15 20:14 - 00000000 ____D () C:\Users\asus\AppData\Local\{3AAD7654-63AF-4743-B2DA-7C1D1BB1B658} 2015-02-15 08:12 - 2015-02-15 08:13 - 00000000 ____D () C:\Users\asus\AppData\Local\{60B03C53-07A8-40AC-9309-D8732E6470E2} 2015-02-14 18:40 - 2015-02-14 18:40 - 00000000 ____D () C:\Users\asus\AppData\Local\{8F4C4C8B-27F6-437B-854E-C12B73B789A3} 2015-02-14 06:39 - 2015-02-14 06:39 - 00000000 ____D () C:\Users\asus\AppData\Local\{97EF3B7A-1775-483C-95C7-786DCCD53A13} 2015-02-13 08:19 - 2015-02-13 08:19 - 00000000 ____D () C:\Users\asus\AppData\Local\{0D3B1573-C86F-443B-BCFF-785B2EB6EA08} 2015-02-12 18:52 - 2015-02-12 18:52 - 00000000 ____D () C:\Users\asus\AppData\Local\{2AE9A8E8-B2EE-47F1-8321-512D9965C1A0} 2015-02-12 07:54 - 2015-01-23 05:42 - 00814080 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll 2015-02-12 07:54 - 2015-01-23 05:41 - 06041600 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll 2015-02-12 07:54 - 2015-01-23 04:43 - 00620032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll 2015-02-12 07:54 - 2015-01-23 04:17 - 04300800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll 2015-02-11 16:59 - 2015-02-11 19:14 - 00000000 ____D () C:\Users\asus\Desktop\Haus 2015-02-11 08:52 - 2015-02-11 08:52 - 00000000 ____D () C:\Users\asus\AppData\Local\{2A8C5E80-A67D-4D04-8C76-0F4331754716} 2015-02-11 08:07 - 2015-01-14 06:09 - 00342712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll 2015-02-11 08:07 - 2015-01-12 04:05 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb 2015-02-11 08:07 - 2015-01-12 03:48 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll 2015-02-11 08:07 - 2015-01-12 03:39 - 00034304 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll 2015-02-11 08:07 - 2015-01-12 03:34 - 00114688 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe 2015-02-11 08:07 - 2015-01-12 03:13 - 00077824 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll 2015-02-11 08:07 - 2015-01-12 03:07 - 00047616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll 2015-02-11 08:07 - 2015-01-12 03:05 - 00064000 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll 2015-02-11 08:07 - 2015-01-12 02:59 - 00030720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll 2015-02-11 08:07 - 2015-01-12 02:48 - 00718848 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe 2015-02-11 08:07 - 2015-01-12 02:40 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll 2015-02-11 08:07 - 2015-01-12 02:35 - 00076288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll 2015-02-11 08:07 - 2015-01-12 01:56 - 01307136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll 2015-02-11 08:07 - 2015-01-10 07:48 - 00728064 _____ (Microsoft Corporation) C:\Windows\system32\kerberos.dll 2015-02-11 08:07 - 2015-01-10 07:48 - 00341504 _____ (Microsoft Corporation) C:\Windows\system32\schannel.dll 2015-02-11 08:07 - 2015-01-10 07:48 - 00314880 _____ (Microsoft Corporation) C:\Windows\system32\msv1_0.dll 2015-02-11 08:07 - 2015-01-10 07:48 - 00309760 _____ (Microsoft Corporation) C:\Windows\system32\ncrypt.dll 2015-02-11 08:07 - 2015-01-10 07:48 - 00210944 _____ (Microsoft Corporation) C:\Windows\system32\wdigest.dll 2015-02-11 08:07 - 2015-01-10 07:48 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll 2015-02-11 08:07 - 2015-01-10 07:48 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll 2015-02-11 08:07 - 2015-01-10 07:27 - 00550912 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kerberos.dll 2015-02-11 08:07 - 2015-01-10 07:27 - 00259584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msv1_0.dll 2015-02-11 08:07 - 2015-01-10 07:27 - 00248832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll 2015-02-11 08:07 - 2015-01-10 07:27 - 00221184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ncrypt.dll 2015-02-11 08:07 - 2015-01-10 07:27 - 00172032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wdigest.dll 2015-02-11 08:07 - 2015-01-10 07:27 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll 2015-02-11 08:07 - 2015-01-10 07:27 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll 2015-02-11 08:06 - 2015-01-14 06:47 - 00389808 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll 2015-02-11 08:06 - 2015-01-12 04:09 - 25056256 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll 2015-02-11 08:06 - 2015-01-12 04:05 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll 2015-02-11 08:06 - 2015-01-12 03:49 - 00066560 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll 2015-02-11 08:06 - 2015-01-12 03:48 - 02885632 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll 2015-02-11 08:06 - 2015-01-12 03:48 - 00584192 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll 2015-02-11 08:06 - 2015-01-12 03:47 - 00088064 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll 2015-02-11 08:06 - 2015-01-12 03:40 - 00054784 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll 2015-02-11 08:06 - 2015-01-12 03:36 - 00633856 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll 2015-02-11 08:06 - 2015-01-12 03:34 - 00144384 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe 2015-02-11 08:06 - 2015-01-12 03:25 - 19740160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll 2015-02-11 08:06 - 2015-01-12 03:25 - 00968704 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe 2015-02-11 08:06 - 2015-01-12 03:21 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb 2015-02-11 08:06 - 2015-01-12 03:21 - 00490496 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll 2015-02-11 08:06 - 2015-01-12 03:08 - 00503296 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll 2015-02-11 08:06 - 2015-01-12 03:08 - 00199680 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll 2015-02-11 08:06 - 2015-01-12 03:07 - 00092160 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll 2015-02-11 08:06 - 2015-01-12 03:07 - 00062464 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll 2015-02-11 08:06 - 2015-01-12 03:04 - 00316928 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll 2015-02-11 08:06 - 2015-01-12 03:02 - 02277888 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll 2015-02-11 08:06 - 2015-01-12 03:00 - 00047104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll 2015-02-11 08:06 - 2015-01-12 02:57 - 00478208 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll 2015-02-11 08:06 - 2015-01-12 02:55 - 00115712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe 2015-02-11 08:06 - 2015-01-12 02:48 - 00801280 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll 2015-02-11 08:06 - 2015-01-12 02:46 - 02125824 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl 2015-02-11 08:06 - 2015-01-12 02:46 - 01359360 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll 2015-02-11 08:06 - 2015-01-12 02:45 - 00418304 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll 2015-02-11 08:06 - 2015-01-12 02:43 - 14401024 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll 2015-02-11 08:06 - 2015-01-12 02:36 - 00168960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll 2015-02-11 08:06 - 2015-01-12 02:33 - 00285696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll 2015-02-11 08:06 - 2015-01-12 02:27 - 02358272 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll 2015-02-11 08:06 - 2015-01-12 02:23 - 02052608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl 2015-02-11 08:06 - 2015-01-12 02:23 - 00688640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll 2015-02-11 08:06 - 2015-01-12 02:22 - 01155072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll 2015-02-11 08:06 - 2015-01-12 02:14 - 12829184 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll 2015-02-11 08:06 - 2015-01-12 02:14 - 01548288 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll 2015-02-11 08:06 - 2015-01-12 02:02 - 00800768 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll 2015-02-11 08:06 - 2015-01-12 02:00 - 01888256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll 2015-02-11 08:06 - 2015-01-12 01:55 - 00710144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll 2015-02-11 08:05 - 2015-01-15 09:14 - 00155072 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecpkg.sys 2015-02-11 08:05 - 2015-01-15 09:14 - 00095680 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys 2015-02-11 08:05 - 2015-01-15 09:09 - 01461760 _____ (Microsoft Corporation) C:\Windows\system32\lsasrv.dll 2015-02-11 08:05 - 2015-01-15 09:09 - 00136192 _____ (Microsoft Corporation) C:\Windows\system32\sspicli.dll 2015-02-11 08:05 - 2015-01-15 09:09 - 00031232 _____ (Microsoft Corporation) C:\Windows\system32\lsass.exe 2015-02-11 08:05 - 2015-01-15 09:09 - 00029184 _____ (Microsoft Corporation) C:\Windows\system32\sspisrv.dll 2015-02-11 08:05 - 2015-01-15 09:09 - 00028160 _____ (Microsoft Corporation) C:\Windows\system32\secur32.dll 2015-02-11 08:05 - 2015-01-15 09:08 - 00064000 _____ (Microsoft Corporation) C:\Windows\system32\auditpol.exe 2015-02-11 08:05 - 2015-01-15 09:06 - 00146432 _____ (Microsoft Corporation) C:\Windows\system32\msaudite.dll 2015-02-11 08:05 - 2015-01-15 09:06 - 00060416 _____ (Microsoft Corporation) C:\Windows\system32\msobjs.dll 2015-02-11 08:05 - 2015-01-15 09:04 - 00686080 _____ (Microsoft Corporation) C:\Windows\system32\adtschema.dll 2015-02-11 08:05 - 2015-01-15 08:42 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\auditpol.exe 2015-02-11 08:05 - 2015-01-15 08:42 - 00022016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll 2015-02-11 08:05 - 2015-01-15 08:41 - 00096768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll 2015-02-11 08:05 - 2015-01-15 08:39 - 00146432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msaudite.dll 2015-02-11 08:05 - 2015-01-15 08:39 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msobjs.dll 2015-02-11 08:05 - 2015-01-15 08:37 - 00686080 _____ (Microsoft Corporation) C:\Windows\SysWOW64\adtschema.dll 2015-02-11 08:05 - 2015-01-15 05:22 - 00458824 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\cng.sys 2015-02-11 08:05 - 2015-01-13 04:10 - 01424384 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll 2015-02-11 08:05 - 2015-01-13 03:49 - 01230336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll 2015-02-11 08:05 - 2014-12-12 06:31 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll 2015-02-11 08:05 - 2014-12-12 06:07 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll 2015-02-11 08:04 - 2015-01-14 07:09 - 05554112 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe 2015-02-11 08:04 - 2015-01-14 07:05 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll 2015-02-11 08:04 - 2015-01-14 07:05 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll 2015-02-11 08:04 - 2015-01-14 07:04 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe 2015-02-11 08:04 - 2015-01-14 06:44 - 03972544 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe 2015-02-11 08:04 - 2015-01-14 06:44 - 03917760 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe 2015-02-11 08:04 - 2015-01-14 06:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll 2015-02-11 08:04 - 2014-12-08 04:09 - 00406528 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll 2015-02-11 08:04 - 2014-12-08 03:46 - 00308224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll 2015-02-11 08:04 - 2014-11-26 04:53 - 00861696 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll 2015-02-11 08:04 - 2014-11-26 04:32 - 00571904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll 2015-02-11 08:04 - 2014-10-04 03:10 - 03722752 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll 2015-02-11 08:04 - 2014-10-04 02:42 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll 2015-02-11 08:04 - 2014-10-04 02:42 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll 2015-02-11 08:03 - 2015-01-09 03:03 - 03201536 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2015-02-10 07:54 - 2015-02-10 07:55 - 00000000 ____D () C:\Users\asus\AppData\Local\{9301AF3B-F96F-4316-8D8D-06406F8ACA75} 2015-02-09 08:17 - 2015-02-09 08:17 - 00000000 ____D () C:\Users\asus\AppData\Local\{198806C5-9429-4D51-80AB-355033729CEA} 2015-02-08 09:09 - 2015-02-08 09:09 - 00000000 ____D () C:\Users\asus\AppData\Local\{E1E520FD-EA91-45EA-9D8F-19D10DBA5014} 2015-02-07 18:35 - 2015-02-07 18:35 - 00000000 ____D () C:\Users\asus\AppData\Local\{B2877DA3-7DB8-4F64-9AAC-5E404149EFD1} 2015-02-06 17:21 - 2015-02-06 17:21 - 00000000 ____D () C:\Users\asus\AppData\Local\{DFF62ED8-1643-4D67-99B3-4DC17D387F08} 2015-02-05 19:56 - 2015-02-05 19:56 - 00000000 ____D () C:\Users\asus\AppData\Local\{DC022A66-74AC-43A6-8494-D6F1D039BDB0} 2015-02-05 07:45 - 2015-02-05 07:45 - 00000000 ____D () C:\Users\asus\AppData\Local\{CC5F34BF-D83D-4656-98A0-EA8ADEF22FD2} 2015-02-04 19:02 - 2015-02-04 19:02 - 00000000 ____D () C:\Users\asus\AppData\Local\{4833237F-75D6-4D82-B6A5-2E3527658548} 2015-02-03 02:16 - 2015-02-03 02:16 - 00000000 ____D () C:\Users\asus\AppData\Local\{19092C7D-0056-4272-8070-F804D0D59C9D} 2015-02-02 08:57 - 2015-02-02 08:58 - 00000000 ____D () C:\Users\asus\AppData\Local\{6D576BD0-9585-4D69-8689-789CB06F4AF1} 2015-02-01 20:57 - 2015-02-01 20:57 - 00000000 ____D () C:\Users\asus\AppData\Local\{BC4C43C6-7B97-4F2A-B469-4B2AAF7AB4F2} 2015-02-01 08:56 - 2015-02-01 08:56 - 00000000 ____D () C:\Users\asus\AppData\Local\{7991E274-DCDB-45EE-A6FC-0BC15AAB6F78} 2015-01-31 17:46 - 2015-01-31 17:46 - 00000000 ____D () C:\Users\asus\AppData\Local\{830C97D1-F3FF-4C3E-99A3-CE1EB12295F6} 2015-01-30 08:24 - 2015-01-30 08:24 - 00000000 ____D () C:\Users\asus\AppData\Local\{50467CDD-2289-4E4F-9C50-1B9A40BD8BB8} 2015-01-29 08:15 - 2015-01-29 08:15 - 00000000 ____D () C:\Users\asus\AppData\Local\{532B44C6-B85A-4F87-A5A7-99ABD3E3EFF2} 2015-01-28 18:44 - 2015-01-28 18:45 - 00000000 ____D () C:\Users\asus\AppData\Local\{DBBD58B8-5EB6-4D07-8B28-4AD76350B553} 2015-01-27 17:17 - 2015-01-27 17:17 - 00000000 ____D () C:\Users\asus\AppData\Local\{89ED9FB3-87D5-4ECC-8166-8C7553A5D592} 2015-01-27 06:21 - 2015-01-27 06:22 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox 2015-01-26 21:31 - 2015-01-26 21:32 - 00000000 ____D () C:\Users\asus\AppData\Local\{DB00317A-59B5-4ADE-8EF2-180B8B0A1A62} 2015-01-26 09:09 - 2015-01-26 09:09 - 00000000 ____D () C:\Users\asus\AppData\Local\{20A01DEF-72BB-4AA8-B6CE-FC4CA25F9E81} 2015-01-25 21:08 - 2015-01-25 21:09 - 00000000 ____D () C:\Users\asus\AppData\Local\{D4266FAB-D98C-4703-9421-D8C15C5FB963} 2015-01-25 09:08 - 2015-01-25 09:08 - 00000000 ____D () C:\Users\asus\AppData\Local\{375E8FFF-8D80-45F7-8016-D02EFD6ED424} 2015-01-24 14:01 - 2015-01-24 14:01 - 00000000 ____D () C:\Users\asus\AppData\Local\{B0AF0178-A61F-478A-AA40-55BC53CD4BDA} 2015-01-23 21:07 - 2015-01-23 21:08 - 00000000 ____D () C:\Users\asus\AppData\Local\{B122B7D3-ACC6-4DAB-9B40-E007DD90BFCD} 2015-01-23 09:07 - 2015-01-23 09:07 - 00000000 ____D () C:\Users\asus\AppData\Local\{B7142C13-F1F9-4F97-8EBD-92D45E3B483B} 2015-01-23 00:13 - 2014-12-12 14:18 - 00000000 ____D () C:\Users\asus\Desktop\The Hard Believer Sessions (2014) 2015-01-23 00:10 - 2015-01-23 00:11 - 49232341 _____ () C:\Users\asus\Downloads\Fink_HBSessions.zip 2015-01-22 03:31 - 2015-01-22 03:31 - 00000000 ____D () C:\Users\asus\AppData\Local\{70048C87-66A0-4371-A6DF-F47060BC260F} 2015-01-21 13:10 - 2015-01-21 13:10 - 00000000 ____D () C:\Users\asus\AppData\Local\{093E93ED-149A-4318-8DC8-9F93056E7235} 2015-01-21 01:10 - 2015-01-21 01:10 - 00000000 ____D () C:\Users\asus\AppData\Local\{163CF2B4-144D-4734-B851-EA67B5780797} 2015-01-20 08:44 - 2015-01-20 08:44 - 00000000 ____D () C:\Users\asus\AppData\Local\{1CA72166-719F-46C5-B1FD-4E988FD36592} 2015-01-19 19:44 - 2015-01-19 19:44 - 00000000 ____D () C:\Users\asus\AppData\Local\{02D64AC2-2237-4DB1-BF0A-AEFA2DB210A3} 2015-01-19 07:43 - 2015-01-19 07:43 - 00000000 ____D () C:\Users\asus\AppData\Local\{DE17230B-9E03-4440-BBCC-5A3AB8AC56FF} ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-02-18 17:19 - 2014-06-01 08:51 - 00015727 _____ () C:\Users\asus\Downloads\FRST.txt 2015-02-18 17:19 - 2013-12-04 09:00 - 00000000 ____D () C:\FRST 2015-02-18 17:11 - 2015-01-15 08:59 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update 2015-02-18 17:11 - 2012-01-12 17:20 - 00045056 _____ () C:\Windows\system32\acovcnt.exe 2015-02-18 17:11 - 2012-01-12 17:20 - 00000000 ___HD () C:\ASUS.DAT 2015-02-18 17:11 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-02-18 17:10 - 2009-07-14 05:51 - 00161683 _____ () C:\Windows\setupact.log 2015-02-18 13:49 - 2011-10-11 10:59 - 01379483 _____ () C:\Windows\WindowsUpdate.log 2015-02-18 13:35 - 2009-07-14 05:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-02-18 13:35 - 2009-07-14 05:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-02-18 13:15 - 2011-04-13 02:39 - 10471930 _____ () C:\Windows\PFRO.log 2015-02-18 08:58 - 2014-06-01 09:50 - 00000000 ____D () C:\Qoobox 2015-02-18 08:54 - 2012-04-04 15:50 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-02-18 08:51 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini 2015-02-18 08:09 - 2014-06-01 09:48 - 05611903 ____R (Swearware) C:\Users\asus\Downloads\ComboFix.exe 2015-02-18 07:49 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\tracing 2015-02-16 19:25 - 2014-05-28 07:30 - 00000000 ____D () C:\ProgramData\Spyware Terminator 2015-02-15 21:12 - 2013-02-26 13:56 - 03149312 ___SH () C:\Users\asus\Desktop\Thumbs.db 2015-02-15 09:51 - 2012-08-22 18:49 - 00000000 ____D () C:\Users\asus\AppData\Roaming\Spotify 2015-02-15 08:53 - 2012-08-22 18:49 - 00000000 ____D () C:\Users\asus\AppData\Local\Spotify 2015-02-11 16:32 - 2009-07-14 05:45 - 00348488 _____ () C:\Windows\system32\FNTCACHE.DAT 2015-02-11 09:06 - 2012-10-12 17:51 - 00000000 ____D () C:\ProgramData\Microsoft Help 2015-02-11 09:04 - 2013-08-02 05:27 - 00000000 ____D () C:\Windows\system32\MRT 2015-02-11 08:59 - 2012-01-21 10:22 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2015-02-10 06:19 - 2011-02-19 05:24 - 00711094 _____ () C:\Windows\system32\perfh007.dat 2015-02-10 06:19 - 2011-02-19 05:24 - 00153542 _____ () C:\Windows\system32\perfc007.dat 2015-02-10 06:19 - 2009-07-14 06:13 - 01651444 _____ () C:\Windows\system32\PerfStringBackup.INI 2015-02-06 07:43 - 2014-02-27 07:44 - 01625724 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI 2015-02-05 19:54 - 2012-04-04 15:50 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-02-05 19:54 - 2012-04-04 15:50 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater 2015-02-05 19:54 - 2012-01-16 19:58 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-01-28 17:02 - 2012-07-16 07:07 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-01-27 17:42 - 2015-01-13 21:57 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox.bak ==================== Files in the root of some directories ======= 2013-06-28 18:06 - 2013-06-28 18:06 - 0000005 _____ () C:\Users\asus\AppData\Roaming\WBPU-TTL.DAT 2012-01-24 20:59 - 2015-01-12 06:25 - 0012800 _____ () C:\Users\asus\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2011-04-13 03:48 - 2010-07-07 00:10 - 0131472 _____ () C:\ProgramData\FullRemove.exe 2011-10-11 11:13 - 2011-10-11 11:13 - 0000105 _____ () C:\ProgramData\{40BF1E83-20EB-11D8-97C5-0009C5020658}.log 2011-10-11 11:12 - 2011-10-11 11:13 - 0000107 _____ () C:\ProgramData\{C59C179C-668D-49A9-B6EA-0121CCFC1243}.log ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-02-13 00:52 ==================== End Of Log ============================ --- --- --- --- --- --- Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-02-2015 Ran by asus at 2015-02-18 17:25:44 Running from C:\Users\asus\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Photoshop Lightroom 2.7 64-bit (HKLM\...\{9B9DBB81-1F48-48B0-8CB3-051311DC73F7}) (Version: 2.7 - Adobe) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Alcor Micro USB Card Reader (HKLM-x32\...\InstallShield_{878CADF7-5BD6-4A29-A6F4-AC51C0CE8068}) (Version: 1.8.17.26026 - Alcor Micro Corp.) Alcor Micro USB Card Reader (x32 Version: 1.8.17.26026 - Alcor Micro Corp.) Hidden ASUS AI Recovery (HKLM-x32\...\{38253529-D97D-4901-AE53-5CC9736D3A2E}) (Version: 1.0.13 - ASUS) ASUS FancyStart (HKLM-x32\...\{2B81872B-A054-48DA-BE3B-FA5C164C303A}) (Version: 1.1.0 - ASUSTeK Computer Inc.) ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.21 - ASUS) ASUS Live Update (HKLM-x32\...\{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}) (Version: 2.5.9 - ASUS) ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.1.43 - ASUS) ASUS SmartLogon (HKLM-x32\...\{64452561-169F-4A36-A2FF-B5E118EC65F5}) (Version: 1.0.0011 - ASUS) ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0031 - ASUS) ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.21 - asus) ASUS WebStorage (HKLM-x32\...\ASUS WebStorage) (Version: 3.0.84.161 - eCareme Technologies, Inc.) AsusScr_K3 Series_ENG_Basic (HKLM-x32\...\AsusScr_K3 Series_ENG_Basic) (Version: 1.0.0001 - ASUS) AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: 2.0.4.617 - ASUSTEK) ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0008 - ASUS) Avast Free Antivirus (HKLM-x32\...\avast) (Version: 10.0.2208 - AVAST Software) Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.) Bookworm Deluxe (HKLM-x32\...\Bookworm Deluxe) (Version: - Oberon Media Inc.) Cisco EAP-FAST Module (HKLM-x32\...\{64BF0187-F3D2-498B-99EA-163AF9AE6EC9}) (Version: 2.2.14 - Cisco Systems, Inc.) Cisco LEAP Module (HKLM-x32\...\{51C7AD07-C3F6-4635-8E8A-231306D810FE}) (Version: 1.0.19 - Cisco Systems, Inc.) Cisco PEAP Module (HKLM-x32\...\{ED5776D5-59B4-46B7-AF81-5F2D94D7C640}) (Version: 1.1.6 - Cisco Systems, Inc.) Control ActiveX de Windows Live Mesh para conexiones remotas (HKLM-x32\...\{04668DF2-D32F-4555-9C7E-35523DCD6544}) (Version: 15.4.5722.2 - Microsoft Corporation) Contrôle ActiveX Windows Live Mesh pour connexions à distance (HKLM-x32\...\{55D003F4-9599-44BF-BA9E-95D060730DD3}) (Version: 15.4.5722.2 - Microsoft Corporation) Controlo ActiveX do Windows Live Mesh para Ligações Remotas (HKLM-x32\...\{E54EEB5D-41ED-40FE-B4A8-8565DB81469B}) (Version: 15.4.5722.2 - Microsoft Corporation) Cooking Dash (HKLM-x32\...\Cooking Dash) (Version: - Oberon Media Inc.) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden DivX-Setup (HKLM-x32\...\DivX Setup) (Version: 2.6.1.8 - DivX, LLC) EPSON Photo Print (HKLM-x32\...\{D379964B-685C-44D5-AE46-C953A9FEEA14}) (Version: - ) EPSON Smart Panel (HKLM-x32\...\{6C11D561-620B-47DA-A693-4C597F3CDF40}) (Version: - ) ETDWare PS/2-X64 8.0.5.0_WHQL (HKLM\...\Elantech) (Version: 8.0.5.0 - ELAN Microelectronic Corp.) Facebook Video Calling 1.2.0.159 (HKLM-x32\...\{7CAC6A44-C3DE-4153-ACA6-7524602C789E}) (Version: 1.2.159 - Skype Limited) Fast Boot (HKLM\...\{13F4A7F3-EABC-4261-AF6B-1317777F0755}) (Version: 1.0.8 - ASUS) FileZilla Client 3.6.0.2 (HKLM-x32\...\FileZilla Client) (Version: 3.6.0.2 - FileZilla Project) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Game Park Console (HKLM-x32\...\{E71E60C1-533E-45A5-8D80-E475E88D2B17}_is1) (Version: 6.2.1.1 - Oberon Media, Inc.) Governor of Poker (HKLM-x32\...\Governor of Poker) (Version: - Oberon Media Inc.) Hotel Dash Suite Success (HKLM-x32\...\Hotel Dash Suite Success) (Version: - Oberon Media Inc.) Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: 1.2.1.1007 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 7.0.0.1118 - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2291 - Intel Corporation) IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.32 - Irfan Skiljan) Java 7 Update 51 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83217040FF}) (Version: 7.0.510 - Oracle) Jewel Quest 3 (HKLM-x32\...\Jewel Quest 3) (Version: - Oberon Media Inc.) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden K-Lite Codec Pack 7.0.0 (Standard) (HKLM-x32\...\KLiteCodecPack_is1) (Version: 7.0.0 - ) Logitech Harmony Remote Software 7 (HKLM-x32\...\{5C6F884D-680C-448B-B4C9-22296EE1B206}) (Version: 7.7.0.0 - Logitech) Luminance HDR 2.3.1 (HKLM\...\{7020FC34-6E04-4858-924D-354B28CB2402}_is1) (Version: - Luminance HDR Dev Team) Luxor 3 (HKLM-x32\...\Luxor 3) (Version: - Oberon Media Inc.) Mahjongg dimensions (HKLM-x32\...\Mahjongg dimensions) (Version: - Oberon Media Inc.) Malwarebytes Anti-Malware Version 2.0.3.1025 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.3.1025 - Malwarebytes Corporation) Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Office Enterprise 2007 (HKLM-x32\...\ENTERPRISE) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM-x32\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0 - Mozilla) Open Freely (HKLM\...\{1BF14E04-85DE-480C-9A04-EB36744C66C3}_is1) (Version: 1.0 - Download Freely, LLC) P3170P Referenzhandbuch (HKLM-x32\...\P3170P Referenzhandbuch) (Version: - ) Plants vs Zombies (HKLM-x32\...\Plants vs Zombies) (Version: - Oberon Media Inc.) PokerStars.net (HKLM-x32\...\PokerStars.net) (Version: - PokerStars.net) Presto! BizCard 4.1 (Deutsch Version) (HKLM-x32\...\Uninstall Presto! BizCard 4.1 Ger) (Version: - ) QuickTime (HKLM-x32\...\{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}) (Version: 7.73.80.64 - Apple Inc.) Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Ralink RT2860 Wireless LAN Card (HKLM-x32\...\{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}) (Version: 1.5.9.0 - Ralink) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6324 - Realtek Semiconductor Corp.) Remote Control USB Driver (HKLM-x32\...\{8471021C-F529-43DE-84DF-3612E10F58C4}) (Version: 2.3.2.317 - ) ScanToWeb (HKLM-x32\...\{EBAE381B-60A6-4863-AA9F-FCAB755BC9E5}) (Version: - ) Spotify (HKU\S-1-5-21-2812954037-985756252-1433979443-1000\...\Spotify) (Version: 0.9.15.27.g87efe634 - Spotify AB) Spybot - Search & Destroy (HKLM-x32\...\{B4092C6D-E886-4CB2-BA68-FE5A88D31DE6}_is1) (Version: 1.6.2 - Safer Networking Limited) Spyware Terminator 2012 (HKLM-x32\...\{56736259-613E-4A3B-B428-6235F2E76F44}_is1) (Version: 3.0.0.82 - Crawler.com) Startfenster (HKLM\...\Startfenster) (Version: - Startfenster) syncables desktop SE (HKLM-x32\...\{341697D8-9923-445E-B42A-529E5A99CB7A}) (Version: 5.5.746.11492 - syncables) TomTom HOME (HKLM-x32\...\{EC5F4C1B-F838-4CB7-8561-8F809296428B}) (Version: 2.9.5 - Ihr Firmenname) TomTom HOME Visual Studio Merge Modules (HKLM-x32\...\{8F3C31C5-9C3A-4AA8-8EFA-71290A7AD533}) (Version: 1.0.2 - TomTom International B.V.) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_ENTERPRISE_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0407-0000-0000000FF1CE}_ENTERPRISE_{F6828576-6F79-470D-AB50-69D1BBADBD30}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_ENTERPRISE_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_ENTERPRISE_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) VC80CRTRedist - 8.0.50727.6195 (x32 Version: 1.2.0 - DivX, Inc) Hidden VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN) WDR RadioRecorder (HKLM-x32\...\Tobit Radio.fx Server 1) (Version: - Tobit.Software) Winamp (HKLM-x32\...\Winamp) (Version: 5.63 - Nullsoft, Inc) Winamp Erkennungs-Plug-in (HKU\S-1-5-21-2812954037-985756252-1433979443-1000\...\Winamp Detect) (Version: 1.0.0.1 - Nullsoft, Inc) Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation) Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation) Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation) WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.1 - ASUS) WinRAR 4.20 (32-Bit) (HKLM-x32\...\WinRAR archiver) (Version: 4.20.0 - win.rar GmbH) Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.19 - ASUS) Wondershare DVD Creator(Build 2.6.5) (HKLM-x32\...\Wondershare DVD Creator_is1) (Version: - Wondershare) Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (HKLM-x32\...\{F665F3B8-01B4-46A9-8E47-FF8DC2208C9F}) (Version: 15.4.5722.2 - Microsoft Corporation) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Элемент управления Windows Live Mesh ActiveX для удаленных подключений (HKLM-x32\...\{BCB0D6F7-7EAB-4009-A6F2-8E0E7F317773}) (Version: 15.4.5722.2 - Microsoft Corporation) גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden פקד ActiveX של Windows Live Mesh עבור חיבורים מרוחקים (HKLM-x32\...\{9D4C7DFA-CBBB-4F06-BDAC-94D831406DF0}) (Version: 15.4.5722.2 - Microsoft Corporation) بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden عنصر تحكم ActiveX الخاص بـ Windows Live Mesh للاتصالات البعيدة (HKLM-x32\...\{E18B30AA-6E2D-480C-B918-AF61009F4010}) (Version: 15.4.5722.2 - Microsoft Corporation) معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden 適用遠端連線的 Windows Live Mesh ActiveX 控制項 (HKLM-x32\...\{622DE1BE-9EDE-49D3-B349-29D64760342A}) (Version: 15.4.5722.2 - Microsoft Corporation) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 11-02-2015 08:03:23 Windows Update 11-02-2015 08:56:32 Windows Update 12-02-2015 09:03:39 Windows Update 18-02-2015 06:04:15 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 03:34 - 2015-02-18 08:51 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {483EA586-4ED2-4ABD-B6C3-FC551DBDBDB2} - System32\Tasks\ASUS SmartLogon Console Sensor => C:\Program Files (x86)\ASUS\SmartLogon\sensorsrv.exe [2010-11-15] (ASUS) Task: {6EE57C04-F5FB-4425-A47D-EBDE175EE10C} - \FTdownloader V4.0-codedownloader No Task File <==== ATTENTION Task: {79A7DAA8-1EF6-4EEF-9964-35390AA24933} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-05] (Adobe Systems Incorporated) Task: {7DEA4888-5A56-42E9-A3A6-7500CB12B602} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {93FE2938-3A2C-4136-93C1-B77AC00CA3E0} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2015-01-15] (AVAST Software) Task: {9CBF1336-D2AD-4ED5-AF2B-1C31C0AF0776} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2010-08-02] (ASUS) Task: {AC252660-F248-4C88-968A-16C755B39611} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-17] (ASUS) Task: {C7956B2B-1E10-454D-B957-142B8039715B} - System32\Tasks\Adobe-Online-Aktualisierungsprogramm => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {DD344CF4-2782-462C-9BD8-C3FF7A61AD12} - System32\Tasks\ASUS Live Update => C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe [2007-11-30] () Task: {F1C5BF03-D855-4461-B2AA-59AAC4CA11D6} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-12-02] (ASUS) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============== 2010-01-02 15:42 - 2010-01-02 15:42 - 00098304 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext_64.dll 2010-04-02 19:21 - 2008-09-30 23:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll 2011-10-11 11:10 - 2007-11-30 19:20 - 00051768 _____ () C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe 2010-07-15 00:11 - 2010-07-15 00:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll 2012-09-27 14:32 - 2011-11-18 13:51 - 03673944 _____ () C:\Program Files (x86)\Tobit Radio.fx\Server\rfx-server.exe 2011-05-31 04:23 - 2011-01-27 01:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2010-09-24 00:53 - 2010-09-24 00:53 - 01601536 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe 2015-02-18 06:06 - 2015-02-18 06:06 - 02911744 _____ () C:\Program Files\AVAST Software\Avast\defs\15021702\algo.dll 2015-02-18 17:11 - 2015-02-18 17:11 - 02911744 _____ () C:\Program Files\AVAST Software\Avast\defs\15021800\algo.dll 2015-01-15 08:59 - 2015-01-15 08:59 - 38562088 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll 2015-01-27 06:21 - 2015-01-27 06:22 - 03925104 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-2812954037-985756252-1433979443-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\asus\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.178.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: ASUS Screen Saver Protector => C:\Windows\AsScrPro.exe MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: RtHDVCpl => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe -s MSCONFIG\startupreg: Spotify => "C:\Users\asus\AppData\Roaming\Spotify\spotify.exe" /uri spotify:autostart MSCONFIG\startupreg: Spotify Web Helper => "C:\Users\asus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" MSCONFIG\startupreg: TomTomHOME.exe => "C:\Program Files (x86)\TomTom HOME 2\TomTomHOMERunner.exe" MSCONFIG\startupreg: WinampAgent => "C:\Program Files (x86)\Winamp\winampa.exe" ==================== Accounts: ============================= Administrator (S-1-5-21-2812954037-985756252-1433979443-500 - Administrator - Disabled) asus (S-1-5-21-2812954037-985756252-1433979443-1000 - Administrator - Enabled) => C:\Users\asus Gast (S-1-5-21-2812954037-985756252-1433979443-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-2812954037-985756252-1433979443-1002 - Limited - Enabled) ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (02/18/2015 08:40:57 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: PEV.exe, Version: 0.0.0.0, Zeitstempel: 0x4e06cfe8 Name des fehlerhaften Moduls: PEV.exe, Version: 0.0.0.0, Zeitstempel: 0x4e06cfe8 Ausnahmecode: 0x40000015 Fehleroffset: 0x0008d1c0 ID des fehlerhaften Prozesses: 0xe30 Startzeit der fehlerhaften Anwendung: 0xPEV.exe0 Pfad der fehlerhaften Anwendung: PEV.exe1 Pfad des fehlerhaften Moduls: PEV.exe2 Berichtskennung: PEV.exe3 Error: (02/18/2015 08:16:43 AM) (Source: Application Error) (EventID: 1000) (User: ) Description: Name der fehlerhaften Anwendung: pev.3XE, Version: 0.0.0.0, Zeitstempel: 0x4e06cfe8 Name des fehlerhaften Moduls: pev.3XE, Version: 0.0.0.0, Zeitstempel: 0x4e06cfe8 Ausnahmecode: 0x40000015 Fehleroffset: 0x0008d1c0 ID des fehlerhaften Prozesses: 0x7d0 Startzeit der fehlerhaften Anwendung: 0xpev.3XE0 Pfad der fehlerhaften Anwendung: pev.3XE1 Pfad des fehlerhaften Moduls: pev.3XE2 Berichtskennung: pev.3XE3 Error: (02/18/2015 07:40:12 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4623168 Error: (02/18/2015 07:40:12 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 4623168 Error: (02/18/2015 07:40:12 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (02/18/2015 06:23:13 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 5086 Error: (02/18/2015 06:23:13 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 5086 Error: (02/18/2015 06:23:13 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (02/18/2015 06:23:12 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 4088 Error: (02/18/2015 06:23:12 AM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 4088 System errors: ============= Error: (02/18/2015 05:11:52 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SBSD Security Center Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (02/18/2015 05:11:52 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SBSD Security Center Service erreicht. Error: (02/18/2015 08:51:34 AM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (02/18/2015 08:50:09 AM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\ComboFix\catchme.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (02/18/2015 08:50:09 AM) (Source: Application Popup) (EventID: 1060) (User: ) Description: Aufgrund der Inkompatibilität mit diesem System wurde \??\C:\ComboFix\catchme.sys nicht geladen. Wenden Sie sich an den Softwarehersteller, um eine kompatible Version des Treibers zu erhalten. Error: (02/18/2015 08:43:34 AM) (Source: Service Control Manager) (EventID: 7030) (User: ) Description: Der Dienst "PEVSystemStart" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (02/18/2015 08:07:56 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Windows Update" wurde nicht richtig gestartet. Error: (02/18/2015 08:02:36 AM) (Source: Service Control Manager) (EventID: 7022) (User: ) Description: Der Dienst "Gemeinsame Nutzung der Internetverbindung" wurde nicht richtig gestartet. Error: (02/18/2015 08:01:13 AM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "SBSD Security Center Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (02/18/2015 08:01:13 AM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst SBSD Security Center Service erreicht. Microsoft Office Sessions: ========================= CodeIntegrity Errors: =================================== Date: 2015-02-18 08:50:09.561 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-18 08:50:09.452 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-18 08:50:09.280 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2015-02-18 08:50:09.187 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-06-01 11:22:40.651 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. Date: 2014-06-01 11:22:40.448 Description: Windows konnte die Abbildintegrität der Datei "\Device\HarddiskVolume2\ComboFix\catchme.sys" nicht überprüfen, weil der Dateihash nicht im System gefunden wurde. Möglicherweise wurde durch eine kürzlich durchgeführte Hardware- oder Softwareänderung eine falsch signierte oder beschädigte Datei oder eine Datei, bei der es sich um schädliche Software aus einer unbekannten Quelle handelt, installiert. ==================== Memory info =========================== Processor: Intel(R) Pentium(R) CPU B950 @ 2.10GHz Percentage of memory in use: 45% Total physical RAM: 4008.23 MB Available physical RAM: 2165.57 MB Total Pagefile: 8014.66 MB Available Pagefile: 5945.28 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:119.24 GB) (Free:2.42 GB) NTFS ==>[System with boot components (obtained from reading drive)] Drive d: (DATA) (Fixed) (Total:153.85 GB) (Free:89.35 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 298.1 GB) (Disk ID: AA9693FE) Partition 1: (Not Active) - (Size=25 GB) - (Type=1C) Partition 2: (Active) - (Size=119.2 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=153.9 GB) - (Type=OF Extended) ==================== End Of Log ============================ Geändert von J_DRX (18.02.2015 um 17:27 Uhr) |
19.02.2015, 06:51 | #8 |
/// the machine /// TB-Ausbilder | Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehr Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
19.02.2015, 08:54 | #9 |
| Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehrCode:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Suchlauf Datum: 19.02.2015 Suchlauf-Zeit: 07:36:20 Logdatei: maleware.txt Administrator: Ja Version: 2.00.4.1028 Malware Datenbank: v2015.02.19.04 Rootkit Datenbank: v2015.02.03.01 Lizenz: Kostenlos Malware Schutz: Deaktiviert Bösartiger Webseiten Schutz: Deaktiviert Selbstschutz: Deaktiviert Betriebssystem: Windows 7 Service Pack 1 CPU: x64 Dateisystem: NTFS Benutzer: asus Suchlauf-Art: Bedrohungs-Suchlauf Ergebnis: Abgeschlossen Durchsuchte Objekte: 359734 Verstrichene Zeit: 27 Min, 21 Sek Speicher: Aktiviert Autostart: Aktiviert Dateisystem: Aktiviert Archive: Aktiviert Rootkits: Deaktiviert Heuristik: Aktiviert PUP: Aktiviert PUM: Aktiviert Prozesse: 0 (Keine schädliche Elemente erkannt) Module: 0 (Keine schädliche Elemente erkannt) Registrierungsschlüssel: 0 (Keine schädliche Elemente erkannt) Registrierungswerte: 0 (Keine schädliche Elemente erkannt) Registrierungsdaten: 0 (Keine schädliche Elemente erkannt) Ordner: 0 (Keine schädliche Elemente erkannt) Dateien: 0 (Keine schädliche Elemente erkannt) Physische Sektoren: 0 (Keine schädliche Elemente erkannt) (end) Code:
ATTFilter # AdwCleaner v4.111 - Bericht erstellt 19/02/2015 um 08:25:52 # Aktualisiert 18/02/2015 von Xplode # Datenbank : 2015-02-18.3 [Server] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64) # Benutzername : asus - ASUS-PC # Gestarted von : C:\Users\asus\Downloads\AdwCleaner_4.111.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17631 -\\ Mozilla Firefox v35.0.1 (x86 de) ************************* AdwCleaner[R0].txt - [10645 Bytes] - [05/12/2013 14:45:00] AdwCleaner[R1].txt - [1209 Bytes] - [16/10/2014 11:33:30] AdwCleaner[R2].txt - [2603 Bytes] - [19/02/2015 08:14:32] AdwCleaner[R3].txt - [1145 Bytes] - [19/02/2015 08:22:50] AdwCleaner[S0].txt - [7613 Bytes] - [05/12/2013 14:49:11] AdwCleaner[S1].txt - [1262 Bytes] - [16/10/2014 11:45:43] AdwCleaner[S2].txt - [2398 Bytes] - [19/02/2015 08:17:31] AdwCleaner[S3].txt - [1068 Bytes] - [19/02/2015 08:25:52] ########## EOF - C:\AdwCleaner\AdwCleaner[S3].txt - [1127 Bytes] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.4.2 (02.02.2015:1) OS: Windows 7 Home Premium x64 Ran by asus on 19.02.2015 at 8:32:21,79 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0068888D-6F79-497B-A430-8B7BE504D4AE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0074BCEC-193E-47AD-AC3E-049F1639A447} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{009F5067-6042-437D-96B6-47979E261BBE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{00D9C104-94CD-4B25-87C2-27476B9FA663} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{01B9D8CA-A1A2-43F4-B808-F2940B0E7C81} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{025BC44D-EAC3-44A0-91B7-143D1C24411A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{02D64AC2-2237-4DB1-BF0A-AEFA2DB210A3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0350BCE0-4027-4172-A7E6-2E9038FD7606} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{03AC2D89-F193-418B-9650-10D83335119E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{045252FE-8868-4761-95EA-4FFB9A8701AE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{045DD4EB-3EF1-4CCB-A199-5C55A71F09AE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0499479E-70FF-4A7F-9C93-CDD45E7779E5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{04C61C45-54F8-454D-A243-E9030A8E9F76} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{04D77C80-26FB-4257-A0EB-D23D0EFAAFFD} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0548A365-9D36-4993-85EB-4C01278E6F14} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0567C4D1-F1E5-4393-932B-121C3B39B94C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{057AB72C-7F0E-4115-94B5-D636228F7092} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0660DC7B-5F2C-4040-B385-60929CCD4509} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{06BE7F76-B9D5-4A4A-BA5B-1732BE31D739} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{072DBD7A-A7AE-4067-833A-7967B88028F0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{076651B8-C1BD-437D-8E7B-C6F346068791} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0827953E-A7EA-489C-A91C-7D851F831D52} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0871886B-DF0B-489D-BF99-418EE3F1035D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{088F0DA9-6BD8-4626-9F75-C9C42C11D5B4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{08E129D4-5143-4340-ADAA-251EE003AC97} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{091544B9-5DA9-43FB-971C-E64737294AB4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{093E93ED-149A-4318-8DC8-9F93056E7235} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{09AE074B-D1B6-419A-BCBA-266D437AAE58} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{09CC2E02-4F61-4F80-AAB2-146353FA700B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{09E7416F-1426-4D66-9186-4860951393B1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0A60289E-4C25-4F44-BDCB-40D4C871D5F1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0A982BB7-CB4E-44FF-9E28-B86F700D4959} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0B6CAAB9-703F-4195-A7FD-3284C45C0A27} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0B720E1D-0EB9-41E7-85B0-2CC14DF72F24} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0B8E0C03-1B5C-4ADC-9EFE-8FFB1D3063A4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0C57CA53-6D04-40A5-A520-384AD8B46124} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0C71ADA1-65C2-4591-AA7A-8D2E6CC883A5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0C9FF887-A958-4A06-A36E-1FD9249536E1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0D0A3476-FF44-472E-AE9F-557D51BE9261} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0D3B1573-C86F-443B-BCFF-785B2EB6EA08} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0D83AB3B-14FC-41D5-A5D3-D3444F5A0720} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0DA95B98-3A25-4149-B0D6-0EA75290CF8B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0DD292F8-DC52-44CE-BECB-3D9DF3F6378E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0E098800-C3DF-42E6-8BBD-AE0B3405FBA9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0EECA131-C217-4CFD-A10F-AF3CC65653DE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0F689E3E-F4BE-4072-894B-74C6EF5E2963} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0F8D8307-E792-4B48-AE78-19602069672D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{0FB89881-7AEB-469C-996E-04D6A38F8EB9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{106B7405-A757-45E7-9554-DD5CC5CDFFBC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{106DFB16-E943-4DE5-9F87-0108BB73E047} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{109DC4BE-8B05-4B9E-9A38-B5DC3FB4078A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{12E77D7A-8B64-4E2E-9C88-6876FCC760A9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{12F7D478-FA90-49A7-8B97-C97EE005D09C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1304A974-8BE1-4966-AE3E-E179C2497483} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{13ABB8F2-092C-4DCA-9DF5-25CFCED68355} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{14BA9123-F62E-40AD-A826-2D58AA438FA0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1525F69D-14FC-42E9-8CBA-51A55760DD05} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{158A84B0-C565-4D5D-9EDB-7755135431FC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{15C68BD2-DED1-435F-A28E-272AA5E74CAC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{15DF906D-0DE9-4B65-8849-9CFD0ECC67A4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{15E1A0AA-FBBF-4C8D-AD12-F58B1400649A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{163CF2B4-144D-4734-B851-EA67B5780797} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{16862B5F-F0A5-4479-BDB9-9AA497F1F0B7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{16DA9550-5A7F-47AA-A8D2-950862AA5C78} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{176149FD-FD9E-4848-AA0E-B22B4A47E075} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1789C5C6-C222-4A3A-8EEE-AC53AED83A49} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1887EAFE-674B-4830-90BC-42127A43808F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{19092C7D-0056-4272-8070-F804D0D59C9D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{198806C5-9429-4D51-80AB-355033729CEA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1999CB37-B6BF-4955-8F25-2FA8566E7CAA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{19E32174-7635-4574-A8FA-9C863DAE895B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1A28BAA9-D363-44A8-A272-9571D2B12791} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1B7C881D-1F08-4ABB-A0D1-A23A53CF4193} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1B7D77B1-B8E6-4C22-B0BE-C7602EFFF0F4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1C74197E-9BC1-4E96-B203-A9BDDC2F72FD} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1CA72166-719F-46C5-B1FD-4E988FD36592} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1CC053A7-BB75-4125-AA59-0C5217E330DE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1DAD2A0C-91DE-4588-BF3B-EDFB272BF14A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1DBF9381-6AD2-4EAF-916A-827499538DE7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1DFFBD45-265C-4B74-9392-EB1DFB6BC63F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1E978679-2BF1-4E7F-9E16-557B041E9F2B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1F0AD8CD-1A9E-4E96-B317-20E73FBB5ACB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1F1CA07B-FAA2-4C04-8D12-F559FA8EB3C1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{1F6BEC78-CFED-4D68-A7D0-F5FBED8061CB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{20A01DEF-72BB-4AA8-B6CE-FC4CA25F9E81} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{20D95E84-7079-48E4-98D5-B1D3A55BA5CF} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{20E9C09D-8B02-4A99-B1BC-1C64EC4BBBAB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{21B68EC5-D2EA-40D6-A61C-60F45B1FBCB9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{22ABC0E4-F78D-4861-9CA7-5196E4E1BE44} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{22ADB75F-E6DE-4670-8911-D702B4A1D7CD} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{237DDCDF-20E1-4CDD-8D1A-BD87B3851F19} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{24C3A23A-3710-414B-845F-CF470491A9BF} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{25A2874B-FD1F-4B00-8544-E79D896F81DD} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{25D788D6-D557-4D41-AE59-A7286CEE88B0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{25DC52A1-55F2-48C0-A237-0CC1825B7DD9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{25E0145C-2449-46E7-A474-BAA247A25261} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{262AAC83-4ACF-42E0-A071-EDF19B5DEA4D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{262F51C5-8032-4BF5-A224-D92EF2DDDAAE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{264AE1C6-8300-48C8-83E8-5D83ADEAD6A5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{268596BC-6CE8-474D-87E3-64444CA55CF4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{26ECE66A-8B92-4F5C-A7DF-2E999A2061C6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{26F17395-BE62-4CB8-A6E9-195D58C5DC51} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{27076DCB-5B82-40D8-B6D0-1BA3F9257C0B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{28522C42-7499-44D5-B4BF-228FFE5A2BAB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{285AEFC8-4E7E-4AE5-A353-5658C222D9B2} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2884847D-9BAE-4645-A768-6EE490C780A6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{29A71C13-ED12-42D7-AA47-1B7552348EA4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{29C19975-FCD0-4BB6-9448-C7C92513487B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2A152A69-8AB9-438C-8919-69052CD14686} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2A243C61-F75B-44E9-A868-8A9848CB1084} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2A62E745-D717-4CDA-B003-1C1914F364E3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2A8C5E80-A67D-4D04-8C76-0F4331754716} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2AE9A8E8-B2EE-47F1-8321-512D9965C1A0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2BD72AFA-D14C-41A4-83DC-89A4707EAB4B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2C31B0B9-08C5-4D9E-93C7-95D7263B7786} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2C4EDEED-5F89-44CC-B337-03514CD2EF25} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2CD35E87-F360-4ED0-A4FE-13AD2298B3F4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2D733D74-B573-4A0B-881B-E9CA22EEA1C7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2D8AA57F-94A3-47D7-AE7E-5BC438D24283} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2DE8B81A-25E0-46C0-992B-122C852D647B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2DF9D342-F9C3-4510-9D8A-936D7607ED0D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2E925ECC-DFC2-46B5-88C2-319137AD52E5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2E9EC414-D380-42ED-AF28-C7BFDDEA5B03} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2EDD202A-3D32-4E47-BBC3-EBFF61B89D4B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2F64F591-8A6B-4ECD-AE49-87651FE15713} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{2F9B65B9-7E80-485C-9977-A17CB8D5BBB4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3077C2F0-80A7-4DE6-805E-6E6E4EA88A9B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{30BE3977-E97E-4811-89CD-656F28829310} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{31442BEF-A75C-4134-B907-C6CBD3982EA2} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{317B4107-32FD-4144-8AFD-D8BE9ED017C0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{320B3EA0-E3DB-4A85-A472-3D256474B8DE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{320FADFC-B619-418A-A784-166839232025} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{32339ED0-0B3B-4900-9922-73AC853F3D59} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{32895F04-5A4E-4E1F-83FC-01430A76854E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{34074692-0E0C-4DE5-8731-F01AD752215F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{340769B0-6A52-4728-AD3D-60E6B7DB8A56} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{34C159E1-EEFD-42FD-8677-50DDB4D0EDB1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3546085B-715E-4346-A615-6822E42DC8BC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{35CD7C9F-22D6-41EA-8919-96DB02E96765} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{36243B74-2A49-4EAD-AE8A-25DB587CDE6E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{36A924F4-20B9-415A-9FBA-8AF382331994} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{36B81143-0A88-4313-BBAF-2E0B73718D49} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{36CBBDA1-A875-46ED-A875-010E59BF72C9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{36D4AAB1-1FD9-4F3E-9D97-914CC36A05B6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{375E8FFF-8D80-45F7-8016-D02EFD6ED424} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{37B80F0D-564E-45AD-9C4A-55F2D1247480} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{37BB0CC4-E918-4E49-B60B-16E283C34357} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{385ACA8E-DD68-412A-823E-571DDF2E018A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{38CAE81E-007F-4D55-AA8D-BD65435AC436} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{39162C82-CD76-4505-A680-D14A4B89CAC6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{391DBA32-3F8B-469D-885A-5A6562D3361D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{39358CFF-DE05-417E-BE53-0A4B1FFC3D69} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3941ADF1-46A8-4D84-82F5-471447BD9690} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3975E159-ECB2-40F5-BD62-A33047461662} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3A5B2C14-E846-40EE-8313-B10779CB144E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3AAD7654-63AF-4743-B2DA-7C1D1BB1B658} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3AF57F9E-032F-42A4-967A-0E7E9EF37D58} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3B2F50AA-B738-4C70-978C-A5FEA244CCC0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3B92CAC2-8B8D-4360-8BA6-653562668349} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3C74BA62-9505-40D9-B4F3-375CA893B250} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3DAEA4B5-D90B-43DA-9A7D-CFF82F9C9D68} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3DC9D1A0-083E-4AC3-A3AD-2E3A6D82BC29} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3E187DBF-DCCF-48C9-8F03-7F0ED3E28A11} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3E427C9F-7733-473A-ACEC-8AB2053ABED3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3F4D4A05-8B11-42D0-8E9D-0CBC6734273F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3F79A569-6676-45E9-9A57-5FB999EF74F1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{3FABFE3A-393E-4FE7-A5B3-6946D8CFB1CA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{40A70290-AF96-4A35-B5EB-D4D0C0827B90} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{40DF1342-4856-4817-9D4B-667ADBE3459B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{411BF894-1437-4A9E-9BAB-27CE637A4CAC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{412FB9EA-88DE-4F8C-9C0D-AA16D70C53E1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{41C9C300-2DA1-477A-B5ED-53259EFF2E0B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{42564FEA-D573-4429-BE0D-17F5941807C0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4292DB89-E106-4B1F-8604-BC03AE233929} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4298F098-49BB-4A40-8107-99818FEBC8D9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{42A64D04-54D3-4363-8A19-9EA2CFC98CF3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{42F6280E-85C7-48EA-823D-0D1B8F5344B5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4314E229-0BBB-4CD0-A459-A72F9D0A910A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4394B2A6-2A59-4A0B-9AB7-62E6AA7A5785} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{43EA84F6-1724-45F3-8E1B-0A7C4620AB9C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{44086B14-7448-46E0-BC2E-6F875627E6B3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{44192D59-4B13-4586-9D95-CA7CF94BB781} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{443F0B47-0C7A-4570-98A1-FA770000590E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{449C7FC8-32C3-4D76-9829-44E5860577C7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{45D2A55F-600A-45B6-814E-06C05B39EE96} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{463C2461-E373-43AD-967B-A8CEDA2176FE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4673BFBF-1D10-4CBF-9F2D-0BEE948CCFB9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4683FA67-972D-4B40-8519-44FFBFCFB7A5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{469E1ECC-9B66-498E-ACD2-27997A05DE31} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{471C3962-65AD-4907-A908-F413D31B1300} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4833237F-75D6-4D82-B6A5-2E3527658548} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4874EADF-B4DF-4C82-BC69-09D1843F3C1C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{49001587-511E-49EE-92F1-9F0C2610EEBC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4948AFDB-E2C7-496E-AF50-D54B13BF55E3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{49905DC3-47B7-436C-9F46-B26E20D82B07} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{49BC82AE-C113-4D84-8B20-1CF85511EFC3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{49D54245-8F95-4754-AA99-C167D18453F6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{49DB707E-38D0-48D6-A8EE-347BC2009982} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4A0D517E-F3DA-49E4-B47F-5BA62632F901} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4A3058A4-26C9-41AC-A326-D92C5BAD1A12} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4B301EA1-9C6D-4518-A2BA-A03C38DF50F9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4CC3BE61-92B0-49B4-BA9E-E84D46AF655C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4D426D50-4E16-4B14-B63D-68D2E3FE3469} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4D73B46B-FA8F-499F-A5FE-CE6EBBDC4163} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4DEA0450-82F0-420D-994A-730718F45D25} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4DF8E9D8-407F-4A1A-BBA6-DD048F515EE4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4ED52C07-D4A6-47DD-88C3-6A81F3F17919} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{4F7353F6-D0F5-4C29-BDAB-FC156209A751} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{502AC7A2-8FFC-45AF-AAD6-6618C3A1AFB0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{50467CDD-2289-4E4F-9C50-1B9A40BD8BB8} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{50655F5C-BB8B-4E68-834B-E257F91F6A10} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{514D772F-5DDD-4E6D-ACE5-032763CC8843} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{51EABB0A-3595-4770-AA1D-79293150158D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{521B3514-D334-41B8-9E33-5131EA4530C7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5265035D-5C32-4DA6-996E-551DDA7B7EC5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{52A7E3AB-B2BE-480D-AF21-22EFB83EA2F1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{532B44C6-B85A-4F87-A5A7-99ABD3E3EFF2} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{536E4D54-8D7C-493A-8999-5724BBC27B41} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{53B39C04-113F-4F54-8DDC-D0D0AED9E010} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{54B34AE9-762B-47B5-89A0-1FFC763E544C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{54F55D23-CD23-4B4F-8716-E2640C798FDA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{55375590-22C6-4326-A1B7-8643BF2BC706} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5572EB98-2382-4DE1-B8A7-C0044736A668} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{558B976E-B5D6-4621-BE7E-242B51720BB5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{55DF6578-DFAF-4E6B-81ED-C0F6E57518CA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{565BBD46-2913-4BBC-90F0-542CF92F5174} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{566CC747-0DB0-4C33-899B-7A80EA29724D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{56BEC0D5-F6AA-4DB1-A765-614BD7588167} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{56EC5039-1EBE-442E-B8D7-BC0DF2DFEE64} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{56ED8CE8-32A5-42E0-BDDD-FEBE9DB4EF88} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{577728CB-C962-4FB5-B5D5-A12BDC7A2222} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5808D502-0076-4AFB-9E80-1A1FCA8786EA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{58743261-6293-4AA3-995C-8A52CC84136D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{58747838-CB9E-469C-9D52-4EE7C0CE40A5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{598A0866-6A79-492F-BC7E-8B2358DDB6F4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5A034A68-C8B1-421C-9EF6-E2669617FDD6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5A97FA89-399E-456F-A6BC-B5249797B6E1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5B59D5F2-2333-4FF0-BFCF-BB6196E054D0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5BC5E25D-8BFF-413A-BBDE-F8C8DB489716} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5CC2DBB2-FCD0-4C66-B698-BE1FF35C4524} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5CFC4B01-A407-4115-88A4-6043267119A6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5D1412F2-F3F6-4BC9-BB61-22F0586E6226} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5D3B17A1-1023-41AD-AA0F-BDE27752E6F0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5D6CE463-6312-4DF6-AA09-E0EA60A0C986} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5D9C60A2-5B8F-4C18-BF8F-261D83DBC3C3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5DA0F557-1910-408B-815E-3CA53C0C3DF0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5DEDB503-1FD2-4218-B7AC-9CBD3AD75B25} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5EC3DCE5-4FBF-49C7-A586-BCA84D185CCC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5EE5D14E-3DA8-43FB-9732-EB91EF21868D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5EED8335-6D04-4928-8B72-E7BFBE8F2D14} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5F49C658-6B9B-4653-8A51-8AD3F5620609} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5F4A1A46-C884-47A7-90A0-2E711E972CF1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{5F8FAE06-CEC2-4415-9C8B-46807676986B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{603C04EE-900A-43A2-8575-D7429F16D548} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{60B03C53-07A8-40AC-9309-D8732E6470E2} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{60C174F3-1710-4D54-A0AD-A505F6263142} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{60D1D941-6310-4C44-B0BF-87BFF0C952AB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{60FF846F-52F3-4482-8B74-27280FAAA579} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{620A805C-2FE0-40CB-BA52-8C6DDDF268AA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{62988B06-CB64-4DB1-BEEE-82EE0EEB59C1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6336B180-802E-4911-B5B4-1C4EA153F447} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6394164E-B4EA-41A9-A520-E4FB0BE5ED02} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{63E95078-2A54-45F0-9998-2E7C46336831} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{644BCC2A-78F4-4653-8928-630DEFD88337} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{649AB448-987C-47CD-B48F-7189092F2EDD} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{658A37AB-6239-460F-AD73-4D27F0127492} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{65F2706F-806B-4F55-9BE8-1EBE26C1E65D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6655094B-0896-45EE-AA24-70CC8D0904CD} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{671E9D3D-4623-4680-A10C-A0A6E495B0AB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6747A8A7-0ECE-41F7-B136-FF0FEAE10557} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{675A3F86-A88F-4379-AB3A-F2ADE416E8E3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6800619D-AEDF-40AD-BA4C-95C6A3CE363B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{684DF0EC-AEF8-4389-87C2-920B8C8E5BF1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{689181D8-F8BB-4447-9001-F0E306AC7599} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{68A45214-2BC7-4591-9BCE-EAF6C26633F3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{68ABF801-0C95-4C48-A67B-82AB611E2992} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{68BCE9F2-83D5-4E41-9A27-D820F9CBA574} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{69162F5B-05D2-4214-BF20-62625FF89D0C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{69E9DBC8-2208-440F-B7E5-0E6A6E383F3F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6A44EE00-A9CE-449D-B193-06114A5EF6E0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6A54CAFE-D371-4093-99FC-A4CED42DCB0B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6A9B6440-FB2D-4924-B165-4F8EDA1CA8F5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6B1E1553-2523-4C37-9E6E-CDFD79CC154D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6B382003-FF8E-436E-92FD-27461B614480} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6B7802B1-4FEB-4E9D-AD9B-20F2385415D4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6BCA2512-311E-4A35-AF2A-DB4D87C20F9C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6BD29280-958D-425C-9A3D-B3B4E4C3285E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6C517CA6-CC9A-4FED-8027-B1C026188C25} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6C63488F-2B88-47FA-A579-E492A6365B06} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6C9FC233-A2BE-43D0-B66B-5BECAFF4D6DC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6CD6377F-28D0-4DEB-B55D-9DC1A282CF8F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6D552883-7D44-4CAA-B203-5E170EBAB061} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6D576BD0-9585-4D69-8689-789CB06F4AF1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6D6B33CB-3B26-4EF1-A729-53BAEDFCF710} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6DAD9A8A-6BA2-41A8-8169-0016E8097D55} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6E17ECD4-D258-4E34-8E78-85B93CB713D3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6E33781E-E50F-4455-B139-58361D8D31E5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6E482508-75D6-4D86-88FE-493F0F280878} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6E4CCAD1-440F-4B5D-815E-0885EDA73D2D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6FA7879F-6082-4B2B-999F-A2A5B09785FF} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{6FF35091-62A0-446C-9E5D-1586F59D3858} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{70048C87-66A0-4371-A6DF-F47060BC260F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7005BD5B-226A-416C-8936-9584ADDA05EE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{709F2A86-2974-4A85-B288-3A9E1B4B32DE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{70C28973-B4E7-460E-B35A-4609FACCDCBB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{72D5902F-2D3C-4E59-9296-EF34423126D3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7330DAA0-1D69-44E8-8D3C-C1F196170229} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{751E07FF-0906-4A72-9560-14B34FA39956} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7563C875-AADD-4AC4-95FB-F77C2706338E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7776B23A-7F00-4B87-8DDE-654CF75F4628} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7831A6ED-41ED-4E9B-A4AD-71460C6BE962} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{78AF3ECE-4869-47FC-AD22-494F7E13A316} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{79371B1A-4D56-4651-9155-840E73EAF2E2} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7991E274-DCDB-45EE-A6FC-0BC15AAB6F78} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{79BE8095-1E5C-4E43-9E94-5A924769F926} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7A82DC3D-73DC-441A-9A41-D48B681B812C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7AAE5F29-B4EF-4440-9425-815EFE8348F6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7B4D1C1B-2700-4139-B897-3ED59ABED954} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7B62863F-320D-45EF-A404-490138D9501E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7C364943-BEA4-449A-8419-975897AC0BAC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7D7AC193-9550-4442-A303-9FD3C6EF528C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7DC941C9-3A11-4E60-8C9F-8CDC1B9078DE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7DD4A43B-122D-4B57-8D70-2DBD59BB9FAC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7E66C054-DF71-4EB5-A1DE-E1463BBBFD2D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7EAD084C-73F9-4C33-81A6-28159715356F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{7F574E23-4084-439B-B9F1-2980907B2AAB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8023FD62-1FA4-44F1-BC7E-AC3D470F55FA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{810E984A-0F58-4F5B-AB75-B11C397D97EF} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{81BF42CC-BFE2-44A5-A3CF-22F7B21CA39B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{81D713FB-602B-444B-A4C3-4A6F78EDB722} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{82438473-E6FF-43A9-87B8-D52061256E73} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{824CDA3F-9012-4474-9E80-66F5CBC9B984} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8288A8B8-7F03-4F03-9A15-817CC7C01298} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{829447C4-38FA-4220-8F71-52C412DF40E9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{82E131FC-BAF2-4A52-A86B-4C1C20A8E965} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{830C97D1-F3FF-4C3E-99A3-CE1EB12295F6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{835C5121-D533-4982-8F67-976A0416483A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8431A76C-5F53-4616-A41D-D3286A780791} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{84EE74FD-A941-43C0-BF23-C592CBE4B1B3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8536E241-005F-48E9-B8DE-1DE49B979004} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{855135D9-7566-428F-A24A-DAA07365BD3C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{859C6EEC-511B-4519-836D-36F2F0ED8BDA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{86B35A10-764C-4B10-B26F-335B78844812} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8708ED30-1D4B-4307-ABCE-BEB66FFB6DA7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{88579DCF-B0E1-4439-BA6E-C796E559497C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8873822F-F711-410D-BDB7-E92CD479B2A3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{89A7E441-E6BF-42C8-8DFB-A796C6B777B0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{89ED9FB3-87D5-4ECC-8166-8C7553A5D592} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{89FB843D-B497-4A50-8278-7C69ECFCD4C2} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8A558AA2-208C-4DC9-8953-379FA9309392} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8AF32CF4-9D56-49FB-91DC-6F117497737E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8B732AA8-8981-45A5-A8BD-411D3BBF6C4E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8BD95165-CF3A-421E-BD52-B4379DE7AA15} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8C03F6E5-F022-4668-99B5-BDE26721D926} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8C803F71-4046-4AC6-AC33-2043D06F95E5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8C89C0C6-7226-475B-9D0F-476865FE9616} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8DE45638-0688-47D2-A274-187F72AFA42D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8EC3DBFE-3139-4ADC-900C-B306375FD689} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8F4C4C8B-27F6-437B-854E-C12B73B789A3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8F5E763F-6CBF-48F7-B762-B57CAE995EA5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{8FF14767-576D-4F02-A174-71213EA43B4D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9027C580-2DA8-4486-9508-47770B20CA64} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{90FC4788-B975-4821-938D-C1137B8F4404} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{91586DF9-E346-4BA2-A130-787F6A928583} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{92027FD0-B40D-448A-95B3-43F7CE65C56B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{923D81D6-59C9-410C-A976-4C1707EC30EA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9301AF3B-F96F-4316-8D8D-06406F8ACA75} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{93268650-A8CD-479F-94FD-AAA0D9D48BF1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9330EA5B-8DAE-4A23-BFE6-750741CDDD74} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{94254F20-2654-44D3-9541-6702868B6444} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{948CFC96-B5E0-4A4B-BBFE-FF4E296FEC90} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{94ACEF11-03EF-4180-9A7E-E28564DE1541} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{962AC885-8D9A-4450-9B47-1E9BAB7253AF} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9707D71E-C2E2-49B7-9991-C60A46F903D2} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9736117D-3BFB-42B9-8CCD-DE0A77B692A4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{97EF3B7A-1775-483C-95C7-786DCCD53A13} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{989A34AF-B121-4E9F-B6BA-ECD5462600F6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9909C4CF-D0FD-449E-AD47-42A523ACBF7E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9917283D-14E2-4EA0-91EA-3647D63B551C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9A60C450-7973-4C91-8297-7961FB30953C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9B34061F-84FE-45F4-89D5-4343725FC314} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9B4953EB-44C8-4A1D-BACF-451AB5E6BF60} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9BA077B8-A3A5-4F9E-A815-15912E112478} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9BDF03CD-3C35-45F1-A777-6117C95E962F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9C06EA6E-A6AC-48F2-AA19-9C38DCC7BED6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9C96BDDD-1C8A-4831-AA71-9BF151E6BD8F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9CAF79E9-7319-4542-ADCF-459C7392535B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9CC2F914-7E40-4C17-A9CA-1B9237EB06DA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9CEB83B1-889C-4E72-B7E4-7F52C6A71363} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9D33508D-0354-4889-BF12-EA7EB2CFF2C4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9E1C04A7-F13A-4CCB-921B-290FE6DCBB24} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9E6614A5-340D-4C97-9DBA-5D91EA4C8D76} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9F6E90DE-3E9A-4F06-AF96-2B315DE95B45} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{9FF111DD-C4CD-491B-83E5-E114AE233FA8} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A0573574-0A0F-4B44-AE6D-0B38A021A52A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A07402E4-8912-4187-99D3-3F78266C7158} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A0C93CF2-68A4-465E-9248-74B0C51BA5EB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A0FA2503-1B85-4CEA-AAB0-4CAF79687E9C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A1572579-DA08-499C-88D4-B2F19CAE5351} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A1B9F6B0-BDC8-4219-BB5F-FBAC4EA0E39C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A1C72D36-547F-4A0D-9596-A728345A98ED} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A2440D02-5AAA-4D6C-B3BA-4D109FA34166} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A25ED646-0E27-4464-AECC-E4A5172BEFEB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A28C0F3F-B1BF-42DF-9EA7-0610B6BA61AD} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A34D9594-4622-4D1C-864A-179B15E28382} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A510B03C-F701-4204-AC9D-17A18EF682CF} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A5C47562-4AC5-4456-8F05-B751FA4AE883} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A5CD53E9-4A3E-4729-B502-33CF88520C1F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A6D08192-CF26-4D89-BDBB-7F9B92055D63} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A707C791-4331-4127-B265-DA2B4F12AC30} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A719D6F5-79AA-41DF-AE2C-936BE34F8642} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A7A42029-6DCF-4C4F-B948-1B15C65CB222} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A8EC245F-473C-454C-BC20-0FC93BDD94D5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{A994EF77-1D0D-40B5-A143-89BA878FE30D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AA39AD22-7F97-4A14-9B26-2A5DEEFD87F1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AA951FF8-B39A-4B2D-857C-8E5AB572B63F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AACC2008-D6B5-4403-9B05-0C5298A76E16} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AB12FEFA-E23A-4743-9B00-BBB4C4212634} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AB1F954D-1A1D-4AAE-8AFF-2A28F4D3ED87} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AB89E618-C6CB-47CB-8DFB-A0053EF7BD08} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AC02140E-7FD5-495C-BA23-3AD60B844147} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AC17D1B9-A7B6-47BF-84E6-24C647E43D75} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AC7BD564-901E-4FAE-835A-E48BFF0B1CC4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{ACDB1597-02B7-428B-8ABB-172B393C8B0D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AD3B2B7A-E052-4306-BF4E-759BC2CE4960} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AD58F3B8-03CE-4F64-ABC2-FF5CBDC20581} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AEBBB777-445B-4954-8678-063E105779A8} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AEC3AAB6-CAF4-4F5E-9443-62F32DCC15BC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AF646A43-747F-400B-A34E-14A4166F22BA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{AFAEE89F-1C81-4ACE-B178-261058BEC1DA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B0608317-BACA-46FE-B7AD-95ADD6337D28} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B0AF0178-A61F-478A-AA40-55BC53CD4BDA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B122B7D3-ACC6-4DAB-9B40-E007DD90BFCD} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B1CDAF02-483E-473F-98A9-6D2180E985B1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B20304EF-BBEF-4321-8B76-63344FED55E1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B23A9B51-061D-48C8-AA86-F29892C25963} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B23DD8BE-4F9E-4A5B-BF4F-EBB05BD80568} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B2766EDA-46F4-47A0-9480-FAFF8549858E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B2877DA3-7DB8-4F64-9AAC-5E404149EFD1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B2C4123A-E84F-47BB-83F8-009BFD291B17} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B35B4B3D-3FBB-4B25-A8DA-346173F237C3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B35D7729-885B-4CF0-9AD0-2087590A2F96} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B36B7B23-F664-4BEA-9618-81769FACBB1A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B37C98DF-2AE6-4C72-9DD7-AD4E07930B73} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B4D0800C-FD68-427D-93AD-A6E8C2EB7648} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B54DE1AB-1B19-475E-B03D-851494BD043F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B5893735-B0E4-431D-8156-2AE6ABEB2464} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B638A614-C886-4B02-A520-083E5E8B3D38} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B7142C13-F1F9-4F97-8EBD-92D45E3B483B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B7794DEE-0864-4489-859F-61AD8B5FCCD6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B788E3FE-7E56-404A-B08D-0CAF7C280E53} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B79D17CF-4EBF-4A80-9221-38C0D98D84F9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B83C51A6-A955-45AA-8CEC-283220D68297} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B84D6718-E8D2-472F-8547-F34C3F31A52E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B8D8D08D-EC2D-4091-BBB1-86403A509C4D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B8E0406C-C296-4ED2-B2E2-FC1CAF64645D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B91F8AA2-7D80-400B-B127-24B6ABE5F8EB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B95BD183-6E21-4D7C-82EC-4B614549399D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{B98C5F40-8217-4D77-8612-7D60579B0B79} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{BA75CACF-A924-4001-89FB-F0AC7801E9FD} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{BAAE0738-4B88-4635-BC83-932D0EB4E108} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{BC17D772-4A8E-4CAC-BF50-CF3EDB07EC39} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{BC4C43C6-7B97-4F2A-B469-4B2AAF7AB4F2} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{BC5EFBAD-41E2-41E2-8CF0-47183CA5432C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{BCDE22C9-6EFF-443B-AAE0-7FAB04969E04} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{BDE28292-2DDE-4394-9338-6E59FE424563} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{BDED3B25-8C73-4CD6-AA6F-F8518F9D26A4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{BE88397F-13ED-46BA-AE84-93FE1534C984} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{BEE1E00C-9B2E-4AC1-A5DF-61789FB9C898} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C09D8F58-1C43-44E6-B504-AFD646CE9D4A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C0ABED28-BAE1-4EA9-B9BA-C5198D311BBA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C15F7553-06DD-4156-9843-BF08FB60295F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C2203BCD-AE1D-4CE3-B2A1-A50309F07B86} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C232BAA2-F2A7-4690-A23B-8FF04E546C7F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C2A59CBC-69F0-41DF-B212-75F60CC019CE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C33742DC-18C2-4E23-B768-51E633BAB85D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C373C950-7038-4A04-9D5C-063E8E422BA8} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C408B96E-3E87-468E-B5E8-3AD1C26465C4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C49B70C7-CA66-4BF3-95CC-4C02C9D179D5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C4CCD52B-5546-47FD-92EE-5F238027DFF5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C4D5D434-DB27-4945-9EB5-10C28A546F34} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C614628C-54B0-4A16-97A5-0FD0C665EA23} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C659DC05-38FD-4D05-A1DA-2897FA197C77} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C66126A4-2755-41AC-A6F6-FA13B29FC2AB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C8159318-2E6F-47CD-8377-4CDEF4735894} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C8A03441-1BED-4E2E-997D-4D0CDD8D7014} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C8D1BE66-42B8-4178-B2A6-1F07A4321058} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C91890F8-2B75-4E6F-9D8F-6011CE3489E1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C94B1133-E146-4E41-BFD5-610B1A894EF5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C9649249-468A-4EEE-9316-B8E4F7261580} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C9A2CF24-B1C8-4919-96D8-4E650F757F88} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{C9B5DEB5-B6D8-44E4-8531-79D694EEF544} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CA0AC9FC-93D7-4111-82AB-780B9FFBDBDF} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CA3AA3E9-7332-4855-AC2D-6051517CE437} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CA62BF94-FA5E-499C-8DF5-BCCD74B7DD1F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CA885883-A348-494B-9BC1-C25437301079} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CBC24BE7-8BBB-4520-9E0C-FE284471D994} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CC5F34BF-D83D-4656-98A0-EA8ADEF22FD2} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CC97DB9E-863D-4915-996B-AA27D397E43C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CC9DCA05-08E9-4E61-8D19-8F5E543AC6A7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CCB97D3D-46C5-475A-BF7E-C8640E81AE62} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CCDEBA88-F96A-4335-8D04-05DBAC176293} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CCEEC443-C400-4DF7-8FD6-53BA46A6C15B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CD434059-BC68-415D-889E-4CC3AF8092A5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CDF99784-77BA-495D-94B2-A7944DD3DA5D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{CF6EDCC7-CB5B-4E9D-9D8A-C12D76BBA6AE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D01CD455-69AE-4A00-8D30-466D6DB38C33} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D0207328-19FE-4062-994A-8435C09383F8} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D0B0C57D-28C7-4055-9970-EDC3D5F14A76} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D0C02A5B-90A6-46C0-BA39-4270DC8A2202} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D0D6DB05-DB6E-4D58-A8B5-5D0407D64FDC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D1023A09-B68A-43E1-B694-FA1C02AF70DE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D1380786-A321-441E-9B84-7DA41D8AFA60} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D152C9A1-34C7-4F17-8169-BE91C48F23A5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D19FCCA0-31AF-49EA-A1F6-46C7B6DCC0F7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D2198B60-5B46-46E8-8BD1-2524F8F1BE31} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D23CAF2B-1680-44DB-953C-CC7044C487EC} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D294ED09-E67A-407C-99DF-86131E85FB29} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D2AC2A88-E08F-459E-8A7B-72A5D75D3F5B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D2C0F245-AFDB-402C-8D42-F1B716458C77} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D2CA1703-8202-49C6-AA5A-F13414B41390} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D2D8122A-0A05-494F-A29F-59E261095039} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D38AA206-DD0F-46F4-B881-43C8BE1C6806} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D3953CF0-161B-4012-A906-5FB118F4825B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D4266FAB-D98C-4703-9421-D8C15C5FB963} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D4490690-B5CC-4091-B1DA-809C799EC84F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D46965F9-69AD-4AEE-918A-4841856A6B29} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D554B114-B6B2-4940-A89E-DDE9A3FEDA56} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D55A987E-B348-4026-B7B3-264B3924F3EF} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D5E7C414-DC5F-4C92-A6B1-70FB51E2DE9A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D66F5C48-3184-494D-B44C-99FA9B044B02} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D769032C-FE11-4DAF-9128-A8F68FD8C78B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D7BCCED9-34E3-4555-8580-C2AD29AA5CEF} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D82BDD1B-0BB3-4E8A-BD7F-F13A491E1037} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D8691B4B-BF7C-42C6-A0CA-62BB9848ECAA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D8C645E8-983A-4597-BE8A-6B8DB0CA0AFD} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D9898259-5CB0-4E39-AE75-AB35A38FA675} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D994AC49-45C9-4A54-8D08-A326285452E0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D9A04480-4295-448E-817A-F27F1E61D10A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{D9ED0C67-D7FF-4C1D-9222-C3101575888A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DA6553EA-AA3C-4600-8103-053CCD055419} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DB00317A-59B5-4ADE-8EF2-180B8B0A1A62} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DB962EAA-6344-4943-96F9-52AF3AA0D060} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DBBD58B8-5EB6-4D07-8B28-4AD76350B553} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DC022A66-74AC-43A6-8494-D6F1D039BDB0} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DC19C3FC-B70A-447E-A3C2-394007080CD6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DD51394F-7DFF-40FF-A84F-295E396F2E83} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DD8B7F49-5E29-4E77-90FF-E7AA6C7244AA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DDB5D79B-9F65-4ADB-9E87-7539DD51F884} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DDCC9211-A040-4B5D-BBBD-FD0380F9E2AF} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DDDF5FF6-0E01-4048-8B5F-432792928E3D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DE0AB4D2-3E4B-4A5D-979B-837AC160186C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DE17230B-9E03-4440-BBCC-5A3AB8AC56FF} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DE4C8509-EE79-4656-96AD-743F91F14AAD} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DE9BAE30-C61D-4703-820F-9480C96B53A3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DECC1F9A-2610-4904-B82F-3FC409EECB25} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DEEED788-00CE-408B-A447-068DE8FD228A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DFCDCD3B-9EDF-461C-8F54-0B37CC0E774D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DFED639D-F39E-4CD7-B384-B626E0A69C7D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{DFF62ED8-1643-4D67-99B3-4DC17D387F08} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E068E7B2-5344-4E71-8B46-C187BB4152ED} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E123BFF2-9533-4287-A34D-F3011F6609B7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E1E520FD-EA91-45EA-9D8F-19D10DBA5014} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E25DE2B3-F48D-490D-B902-2224C9145953} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E28A18D8-EE3F-4D2B-A03B-82F22C5BC5AD} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E2BFB32C-7EAE-42C2-92F6-9E58B453162E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E3D06537-AA14-4003-BA7F-E27A52F008B6} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E410FB90-5B9D-4A25-91E9-FB608F383ADE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E4AD8F5B-6581-4888-9A11-C764FFBD9783} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E509C11A-ADD0-46D1-B4A5-7A48C3009CA2} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E5169F74-D707-4FA0-8847-56543349FAA1} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E57F9B10-2381-4A4F-9FA4-C18387A4956F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E59D0E64-EE41-4981-910F-E81A8B61C33F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E5B32406-031A-452D-9C32-290EB414B25D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E611FB2B-F7CD-44A5-BE31-BEDD55321A2B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E61C4E76-91A7-48E9-B2F1-CC82BA0F7C8E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E65A41FD-2FDF-4636-9237-E47DD7E182E2} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E68A0E86-8B14-4FE7-9399-90B5AF163469} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E6DBBB96-7416-42B2-A804-CC6CFF6B7D9A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E6E3EB61-B75F-4D54-9ACD-584E431E7736} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E74493B6-6070-41A1-8488-85DDACEC2FA5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E74AF5F8-157A-4AFA-ADC0-F9A3C680335C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E751D030-5C81-4266-8E13-0A0D3722C8EA} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E918F44C-760D-4726-828A-A1E571B8301C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{E9E832F6-13CD-4031-9EF1-CE7C87644E31} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EB2FF304-04CA-4D6E-94D2-B07D1DE3AF0F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EB758678-8B1C-46EF-B187-5BCFF02AAEE4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EBC63BC3-CF29-45A8-984A-3523D05453E8} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EC3C5976-E313-41D3-88CF-D89B0CA89CE3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EC4E3D18-872F-4ED3-8992-8E5695755DBB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{ECEEA7CB-A2F5-4EB6-A0E3-E0B3C210C74D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{ED833FFB-3764-4FB2-B2A0-3157C8558EAF} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EDE61F14-22F9-4215-8A26-1D832631E324} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EE933443-EAE9-4898-8759-C0AEF9E52638} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EEB24618-9030-4280-BC59-1C3E9C3C69BB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EF0E4734-4607-4C8F-8456-C869A703331B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EF15CB8B-4372-42BF-8C78-B6E01FD08A41} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EF46C105-B5EE-44B1-9794-BA856E4AC86E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EFBDA3E0-4749-4B6B-82BC-FBC483ACBC6F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EFC33590-2F3B-442B-97DA-72ED31B01A78} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{EFCBC3E8-732C-4742-817F-CC6C6B8F89F2} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F02CD88F-D093-4575-9CDA-DE5392558881} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F0D8D4F5-D439-4475-A58C-DAE9F03746C7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F10DC824-96BB-42FC-8E33-18FC60A02217} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F132000F-547E-4D21-BA84-784E8633D314} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F1D44765-D016-4346-A9B8-452DC798AA60} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F1F1C19A-CFF3-482D-A388-DDDB3262640C} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F259615E-7B5A-4478-A040-980676BEE11F} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F2932ADF-25FF-45FD-BCF8-6CB0C0C025C9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F2C39AA7-C0F5-45F9-A71D-0E407AE1A583} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F2F48047-5BAA-4BED-96F1-EFD4C2089BBB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F33C72D1-B34C-4EB4-AFAA-F8CBB16E6D2D} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F3573109-26BD-44C0-96B3-307650F6D0D5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F37F34F5-7E10-49E7-BCF4-3DEE363E95BB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F413CEAE-71D7-4F45-BD53-EB2B7C74D3D7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F44D859B-B27D-458A-8DB9-2BDA9C1F2725} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F4629DD5-03C7-40FC-9CF2-53940E08D7A8} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F4AA2937-DBA2-46D9-9497-3BA53E11F1D5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F4EBB879-97C1-48B9-96B3-5D80B863C0D5} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F5F732BA-BF6A-4439-9A97-2A1CA7FCB929} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F6CF1EB7-EBAD-4B4F-A220-C241E38BD716} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F6DC15D8-6015-46D5-9233-5ED75BFA1135} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F795C52F-93FB-4401-BFE4-CF9BB93A6DAB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F7C1B022-D68F-4760-A6EB-79C373DE3894} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F7D5B2F2-FDBB-4D06-9DE2-5C34C9795FB7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F8678121-B0B0-4323-B654-723D327ACF2A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F8B608D2-76F1-4CDC-9CCD-8C6E2826DB37} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{F968DE58-A624-4291-A841-70339153C79E} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FA18EC6C-14E5-4436-A82D-60DCBA776626} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FA1DA7CD-2884-4CE8-9C59-491EDD34CBE7} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FA9C73FF-1FC7-4BCD-8312-4B6E72B6C09A} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FAB3D8AA-2350-487B-85C6-5EA98704162B} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FB70711A-B327-4B93-94E7-3B350FE108DB} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FBBE93A4-D058-4652-93B5-3E74ABE11EE4} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FBDC71B0-5FAC-47AB-A5D1-953AABF2F149} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FBFC582F-14B4-4D95-9935-15AAD5036AF9} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FBFD565F-4F47-4EBC-B029-99CA76A574E8} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FC108CBA-DBE3-4B4D-B7C4-D535AE4196E3} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FCCCAC70-1934-4EA6-9AE9-2E5FC4089E72} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FD375ED0-AA80-4122-B02E-9984E947B2DE} Successfully deleted: [Empty Folder] C:\Users\asus\appdata\local\{FFEEA34D-CB3C-4C75-BC6E-E668F79D5FF8} ~~~ FireFox Emptied folder: C:\Users\asus\AppData\Roaming\mozilla\firefox\profiles\j10ut53x.default-1349158430390\minidumps [76 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 19.02.2015 at 8:37:07,65 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Code:
ATTFilter ComboFix 15-02-16.01 - asus 19.02.2015 8:42.3.2 - x64 Microsoft Windows 7 Home Premium 6.1.7601.1.1252.49.1031.18.4008.2668 [GMT 1:00] ausgeführt von:: c:\users\asus\Downloads\ComboFix.exe AV: avast! Antivirus *Disabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B} SP: avast! Antivirus *Disabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736} SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . . ((((((((((((((((((((((( Dateien erstellt von 2015-01-19 bis 2015-02-19 )))))))))))))))))))))))))))))) . . 2015-02-19 07:50 . 2015-02-19 07:50 -------- d-----w- c:\users\Public\AppData\Local\temp 2015-02-19 07:50 . 2015-02-19 07:50 -------- d-----w- c:\users\Default\AppData\Local\temp 2015-02-19 05:08 . 2015-01-29 09:07 11910896 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{65916499-4030-477E-A83A-5D7E61EA1AF5}\mpengine.dll 2015-02-17 16:55 . 2015-01-09 03:14 91136 ----a-w- c:\windows\system32\wdi.dll 2015-02-17 16:55 . 2015-01-09 03:14 950272 ----a-w- c:\windows\system32\perftrack.dll 2015-02-17 16:55 . 2015-01-09 03:14 29696 ----a-w- c:\windows\system32\powertracker.dll 2015-02-17 16:55 . 2015-01-09 02:48 76800 ----a-w- c:\windows\SysWow64\wdi.dll 2015-02-12 06:54 . 2015-01-23 03:43 620032 ----a-w- c:\windows\SysWow64\jscript9diag.dll 2015-02-12 06:54 . 2015-01-23 03:17 4300800 ----a-w- c:\windows\SysWow64\jscript9.dll 2015-02-12 06:54 . 2015-01-23 04:42 814080 ----a-w- c:\windows\system32\jscript9diag.dll 2015-02-12 06:54 . 2015-01-23 04:41 6041600 ----a-w- c:\windows\system32\jscript9.dll 2015-02-11 07:05 . 2015-01-13 03:10 1424384 ----a-w- c:\windows\system32\WindowsCodecs.dll 2015-02-11 07:04 . 2014-11-26 03:53 861696 ----a-w- c:\windows\system32\oleaut32.dll 2015-02-11 07:03 . 2015-01-09 02:03 3201536 ----a-w- c:\windows\system32\win32k.sys . . . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2015-02-19 07:26 . 2012-01-12 16:20 45056 ----a-w- c:\windows\system32\acovcnt.exe 2015-02-19 07:09 . 2014-10-16 08:19 129752 ----a-w- c:\windows\system32\drivers\MBAMSwissArmy.sys 2015-02-11 07:59 . 2012-01-21 09:22 116773704 ----a-w- c:\windows\system32\MRT.exe 2015-02-05 18:54 . 2012-04-04 14:50 701616 ----a-w- c:\windows\SysWow64\FlashPlayerApp.exe 2015-02-05 18:54 . 2012-01-16 18:58 71344 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl 2015-01-15 08:00 . 2012-01-21 15:51 1050432 ----a-w- c:\windows\system32\drivers\aswsnx.sys 2015-01-15 07:59 . 2015-01-15 07:59 364512 ----a-w- c:\windows\system32\aswBoot.exe 2015-01-15 07:59 . 2014-05-14 17:25 29208 ----a-w- c:\windows\system32\drivers\aswHwid.sys 2015-01-15 07:59 . 2014-01-10 23:13 116728 ----a-w- c:\windows\system32\drivers\aswstm.sys 2015-01-15 07:59 . 2013-03-24 16:46 267632 ----a-w- c:\windows\system32\drivers\aswVmm.sys 2015-01-15 07:59 . 2013-03-24 16:46 65776 ----a-w- c:\windows\system32\drivers\aswRvrt.sys 2015-01-15 07:59 . 2012-02-26 17:46 93568 ----a-w- c:\windows\system32\drivers\aswRdr2.sys 2015-01-15 07:59 . 2012-01-21 15:51 436624 ----a-w- c:\windows\system32\drivers\aswsp.sys 2015-01-15 07:59 . 2012-01-21 15:51 83280 ----a-w- c:\windows\system32\drivers\aswMonFlt.sys 2015-01-15 07:59 . 2015-01-15 07:59 43152 ----a-w- c:\windows\avastSS.scr 2014-12-22 23:41 . 2012-01-16 15:07 298120 ------w- c:\windows\system32\MpSigStub.exe 2014-12-19 03:06 . 2015-01-14 03:16 210432 ----a-w- c:\windows\system32\profsvc.dll 2014-12-19 01:46 . 2015-01-14 03:16 141312 ----a-w- c:\windows\system32\drivers\mrxdav.sys 2014-12-11 17:47 . 2015-01-14 03:16 52736 ----a-w- c:\windows\system32\TSWbPrxy.exe 2014-12-06 04:17 . 2015-01-14 03:16 303616 ----a-w- c:\windows\system32\nlasvc.dll 2014-12-06 03:50 . 2015-01-14 03:16 52224 ----a-w- c:\windows\SysWow64\nlaapi.dll 2014-12-06 03:50 . 2015-01-14 03:16 156672 ----a-w- c:\windows\SysWow64\ncsi.dll . . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 . [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SpybotSD TeaTimer"="c:\program files (x86)\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480] "Spotify Web Helper"="c:\users\asus\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2015-01-05 1676344] . [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run] "ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-13 2018032] "ASUSWebStorage"="c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSPanel.exe" [2011-02-23 731472] "ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992] "ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624] "HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016] "Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-23 1601536] "SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336] "AvastUI.exe"="c:\program files\AVAST Software\Avast\AvastUI.exe" [2015-01-27 5227112] "Wondershare Helper Compact.exe"="c:\program files (x86)\Common Files\Wondershare\Wondershare Helper Compact\WSHelper.exe" [2012-03-27 1686528] . c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\ AsusVibeLauncher.lnk - c:\program files (x86)\ASUS\AsusVibe\AsusVibeLauncher.exe /start [2011-4-13 548528] FancyStart daemon.lnk - c:\windows\Installer\{2B81872B-A054-48DA-BE3B-FA5C164C303A}\_94E3CE3704FE82FBF49A6A.exe -d [2012-1-16 12862] . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "ConsentPromptBehaviorAdmin"= 5 (0x5) "ConsentPromptBehaviorUser"= 3 (0x3) "EnableUIADesktopToggle"= 0 (0x0) "SoftwareSASGeneration"= 1 (0x1) . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32] "aux1"=wdmaud.drv . [HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-] "Nuance PDF Reader-reminder"="c:\program files (x86)\Nuance\PDF Reader\Ereg\Ereg.exe" -r "c:\programdata\Nuance\PDF Reader\Ereg\Ereg.ini" "Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" . R2 aswStm;aswStm;c:\windows\system32\drivers\aswStm.sys;c:\windows\SYSNATIVE\drivers\aswStm.sys [x] R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x] R3 AmUStor;AM USB Stroage Driver;c:\windows\system32\drivers\AmUStor.SYS;c:\windows\SYSNATIVE\drivers\AmUStor.SYS [x] R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x] R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x] R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x] R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x] R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x] S0 aswRvrt;avast! Revert; [x] S0 aswVmm;avast! VM Monitor; [x] S1 aswKbd;aswKbd; [x] S1 aswSnx;aswSnx;c:\windows\system32\drivers\aswSnx.sys;c:\windows\SYSNATIVE\drivers\aswSnx.sys [x] S1 aswSP;aswSP;c:\windows\system32\drivers\aswSP.sys;c:\windows\SYSNATIVE\drivers\aswSP.sys [x] S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x] S2 AFBAgent;AFBAgent;c:\windows\system32\FBAgent.exe;c:\windows\SYSNATIVE\FBAgent.exe [x] S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x] S2 aswHwid;avast! HardwareID;c:\windows\system32\drivers\aswHwid.sys;c:\windows\SYSNATIVE\drivers\aswHwid.sys [x] S2 aswMonFlt;aswMonFlt;c:\windows\system32\drivers\aswMonFlt.sys;c:\windows\SYSNATIVE\drivers\aswMonFlt.sys [x] S2 Radio.fx;Radio.fx Server;c:\program files (x86)\Tobit Radio.fx\Server\rfx-server.exe;c:\program files (x86)\Tobit Radio.fx\Server\rfx-server.exe [x] S2 SBSDWSCService;SBSD Security Center Service;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe;c:\program files (x86)\Spybot - Search & Destroy\SDWinSec.exe [x] S2 sp_rsdrv2;Spyware Terminator Driver Filter;c:\windows\system32\DRIVERS\stflt.sys;c:\windows\SYSNATIVE\DRIVERS\stflt.sys [x] S2 ST2012_Svc;Spyware Terminator 2012 Realtime Shield Service;c:\program files (x86)\Spyware Terminator\st_rsser64.exe;c:\program files (x86)\Spyware Terminator\st_rsser64.exe [x] S2 TomTomHOMEService;TomTomHOMEService;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe;c:\program files (x86)\TomTom HOME 2\TomTomHOMEService.exe [x] S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x] S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x] S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x] S3 L1C;NDIS Miniport Driver for Atheros AR813x/AR815x PCI-E Ethernet Controller;c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x] S3 netr28x;Ralink 802.11n Extensible Wireless Driver;c:\windows\system32\DRIVERS\netr28x.sys;c:\windows\SYSNATIVE\DRIVERS\netr28x.sys [x] . . Inhalt des "geplante Tasks" Ordners . 2015-02-19 c:\windows\Tasks\Adobe Flash Player Updater.job - c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2012-04-04 18:54] . . --------- X64 Entries ----------- . . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\00avast] @="{472083B0-C522-11CF-8763-00608CC02F24}" [HKEY_CLASSES_ROOT\CLSID\{472083B0-C522-11CF-8763-00608CC02F24}] 2015-01-15 07:59 860984 ----a-w- c:\program files\AVAST Software\Avast\ashShA64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_B] @="{6D4133E5-0742-4ADC-8A8C-9303440F7190}" [HKEY_CLASSES_ROOT\CLSID\{6D4133E5-0742-4ADC-8A8C-9303440F7190}] 2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\AsusWSShellExt_O] @="{64174815-8D98-4CE6-8646-4C039977D808}" [HKEY_CLASSES_ROOT\CLSID\{64174815-8D98-4CE6-8646-4C039977D808}] 2010-09-02 08:41 220160 ----a-w- c:\program files (x86)\ASUS\ASUS WebStorage\3.0.84.161\AsusWSShellExt64.dll . [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-03-01 2189416] "AmIcoSinglun64"="c:\program files (x86)\AmIcoSingLun\AmIcoSinglun64.exe" [2010-08-11 324096] "ETDCtrl"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU] "IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-08-31 167704] "HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-08-31 392472] "Persistence"="c:\windows\system32\igfxpers.exe" [2011-08-31 416024] "SpywareTerminatorShield"="c:\program files (x86)\Spyware Terminator\SpywareTerminatorShield.exe" [2013-04-03 2777736] "SpywareTerminatorUpdater"="c:\program files (x86)\Spyware Terminator\SpywareTerminatorUpdate.exe" [2013-04-03 3684488] . ------- Zusätzlicher Suchlauf ------- . uLocal Page = c:\windows\system32\blank.htm uStart Page = hxxp://www.google.com mLocal Page = c:\windows\SysWOW64\blank.htm IE: Nach Microsoft E&xel exportieren - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000 TCP: DhcpNameServer = 192.168.178.1 FF - ProfilePath - c:\users\asus\AppData\Roaming\Mozilla\Firefox\Profiles\j10ut53x.default-1349158430390\ FF - prefs.js: browser.startup.homepage - hxxps://www.google.de/ . - - - - Entfernte verwaiste Registrierungseinträge - - - - . Toolbar-Locked - (no file) AddRemove-Uninstall Presto! BizCard 4.1 Ger - c:\windows\IsUn0407.exe . . . --------------------- Gesperrte Registrierungsschluessel --------------------- . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_16_0_0_305_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}] @Denied: (A 2) (Everyone) @="FlashBroker" "LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe,-101" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\Elevation] "Enabled"=dword:00000001 . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\LocalServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_16_0_0_305_ActiveX.exe" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{B019E3BF-E7E5-453C-A2E4-D2C18CA0866F}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Shockwave Flash Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus] @="0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID] @="ShockwaveFlash.ShockwaveFlash.16" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="ShockwaveFlash.ShockwaveFlash" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}] @Denied: (A 2) (Everyone) @="Macromedia Flash Factory Object" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx" "ThreadingModel"="Apartment" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID] @="FlashFactory.FlashFactory.1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32] @="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_16_0_0_305.ocx, 1" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib] @="{D27CDB6B-AE6D-11cf-96B8-444553540000}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version] @="1.0" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID] @="FlashFactory.FlashFactory" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}] @Denied: (A 2) (Everyone) @="IFlashBroker6" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\ProxyStubClsid32] @="{00020424-0000-0000-C000-000000000046}" . [HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{299817DA-1FAC-4CE2-8F48-A108237013BD}\TypeLib] @="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}" "Version"="1.0" . [HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security] @Denied: (Full) (Everyone) . Zeit der Fertigstellung: 2015-02-19 08:53:07 ComboFix-quarantined-files.txt 2015-02-19 07:53 ComboFix2.txt 2015-02-18 07:58 ComboFix3.txt 2014-06-01 09:31 . Vor Suchlauf: 1.986.932.736 Bytes frei Nach Suchlauf: 1.668.304.896 Bytes frei . - - End Of File - - 3B353624C1CC9DF804AB20543D95DCF4 |
19.02.2015, 18:45 | #10 |
/// the machine /// TB-Ausbilder | Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehr Nicht Combofix, FRST ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows7, Bootjingle blärrt, can not create shell notification, Firefox (keine Rückmeldung), danach geht nix mehr |
antivirus, association, bonjour, booten, browser, desktop, downloader, email, error, excel, firefox, flash player, hijack, home, homepage, hängt, kis, mozilla, realtek, registry, safer networking, security, software, spotify web helper, spyware, svchost.exe, system, windows |