|
Plagegeister aller Art und deren Bekämpfung: Irgendwas eingefangen. Lahme Browser ...Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
24.01.2015, 21:14 | #1 |
| Irgendwas eingefangen. Lahme Browser ... Hallo zusammen, ich glaube ich habe mir irgendein Virus oder so eingefangen. Seit Tagen laden Websites nicht richtig, teilweise erst nach 1 2 3 mal akzualisieren, oder brauchen sehr lange. Am Internet an sich kann es nicht liegen, da vom Iphone aus per WLAN alles geht. Kann mir hier bitte jemand helfen? Vielen Dank Gruß Pramox |
24.01.2015, 21:16 | #2 |
/// the machine /// TB-Ausbilder | Irgendwas eingefangen. Lahme Browser ... hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
26.01.2015, 16:43 | #3 |
| Irgendwas eingefangen. Lahme Browser ...FRST Logfile: [CODE]Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 24-01-2015 01 Ran by PramoxLaptop (administrator) on PRAMOXLAPTOP-PC on 26-01-2015 16:34:10 Running from C:\Users\PramoxLaptop\Desktop Loaded Profiles: PramoxLaptop (Available profiles: PramoxLaptop) Platform: Microsoft® Windows Vista™ Home Premium Service Pack 2 (X86) OS Language: Deutsch (Deutschland) Internet Explorer Version 9 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Emsisoft GmbH) C:\Program Files\Emsisoft Anti-Malware\a2service.exe (NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe (Microsoft Corporation) C:\Windows\System32\SLsvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Agere Systems) C:\Windows\System32\agrsmsvc.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (devolo AG) C:\Program Files\devolo\dlan\devolonetsvc.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe (AlcorMicro Co., Ltd.) C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe (SEIKO EPSON CORPORATION) C:\Program Files\epson\MyEpson Portal\mepService.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Symantec Corporation) C:\Program Files\Norton 360\Engine\21.6.0.32\n360.exe (SEIKO EPSON CORPORATION) C:\Program Files\epson\MyEpson Portal\mep.exe (NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe () C:\Windows\PLFSetI.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (Acer Incorporated) C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe (Realtek Semiconductor Corp.) C:\Users\PramoxLaptop\AppData\Local\Temp\RtkBtMnt.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe () C:\Program Files\DivX\DivX Update\DivXUpdate.exe (Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe (Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Microsoft Corporation) C:\Windows\ehome\ehtray.exe (Microsoft Corporation) C:\Windows\ehome\ehmsas.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIHLE.EXE (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIHLE.EXE (Microsoft Corporation) C:\Program Files\Windows Media Player\wmpnscfg.exe (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIHLE.EXE (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIHLE.EXE (SEIKO EPSON CORPORATION) C:\Windows\System32\spool\drivers\w32x86\3\E_FATIHLE.EXE (Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe () C:\Program Files\Air Mouse\Air Mouse\Air Mouse.exe (Symantec Corporation) C:\Program Files\Norton 360\Engine\21.6.0.32\n360.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (RPA Technology) C:\Program Files\Air Mouse\Air Mouse\Mobile Mouse Service.exe (Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe (Microsoft Corporation) C:\Windows\System32\conime.exe (Microsoft Corporation) C:\Windows\System32\WerFault.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1008184 2008-01-21] (Microsoft Corporation) HKLM\...\Run: [NvCplDaemon] => RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup HKLM\...\Run: [NvMediaCenter] => RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit HKLM\...\Run: [AmIcoSinglun] => C:\Program Files\AmIcoSingLun\AmIcoSinglun.exe [237568 2008-10-24] (AlcorMicro Co., Ltd.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [6957600 2009-03-11] (Realtek Semiconductor) HKLM\...\Run: [Skytel] => C:\Program Files\Realtek\Audio\HDA\Skytel.exe [1833504 2009-03-11] (Realtek Semiconductor Corp.) HKLM\...\Run: [PLFSetI] => C:\Windows\PLFSetI.exe [200704 2013-11-24] () HKLM\...\Run: [SynTPEnh] => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1410344 2008-12-05] (Synaptics, Inc.) HKLM\...\Run: [BackupManagerTray] => C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe [249600 2009-03-20] (NewTech Infosystems, Inc.) HKLM\...\Run: [Acer ePower Management] => C:\Program Files\Acer\Acer PowerSmart Manager\ePowerTray.exe [715296 2009-03-11] (Acer Incorporated) HKLM\...\Run: [DivXMediaServer] => C:\Program Files\DivX\DivX Media Server\DivXMediaServer.exe [450560 2014-02-14] (DivX, LLC) HKLM\...\Run: [Adobe ARM] => C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated) HKLM\...\Run: [DivXUpdate] => C:\Program Files\DivX\DivX Update\DivXUpdate.exe [1861968 2014-01-10] () HKLM\...\Run: [PDFPrint] => C:\Program Files\PDF24\pdf24.exe [189480 2014-02-06] (Geek Software GmbH) HKLM\...\Run: [iTunesHelper] => C:\Program Files\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.) HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter HKU\S-1-5-21-1096382573-999743387-1970358641-1000\...\Run: [ProductReg] => C:\Program Files\Acer\WR_PopUp\ProductReg.exe [135168 2008-11-17] (Acer) HKU\S-1-5-21-1096382573-999743387-1970358641-1000\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-1096382573-999743387-1970358641-1000\...\Run: [EPLTarget\P0000000000000001] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHLE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1096382573-999743387-1970358641-1000\...\Run: [EPLTarget\P0000000000000002] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHLE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1096382573-999743387-1970358641-1000\...\Run: [WMPNSCFG] => C:\Program Files\Windows Media Player\WMPNSCFG.exe [202240 2008-01-21] (Microsoft Corporation) HKU\S-1-5-21-1096382573-999743387-1970358641-1000\...\Run: [EPLTarget\P0000000000000003] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHLE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1096382573-999743387-1970358641-1000\...\Run: [iPhone PC Suite] => C:\Program Files\NetDragon\91 Mobile\iPhone\iPhone PC Suite.exe /start HKU\S-1-5-21-1096382573-999743387-1970358641-1000\...\Run: [EPLTarget\P0000000000000005] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHLE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION) HKU\S-1-5-21-1096382573-999743387-1970358641-1000\...\Run: [EPLTarget\P0000000000000006] => C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATIHLE.EXE [249440 2012-02-29] (SEIKO EPSON CORPORATION) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Acer VCM.lnk ShortcutTarget: Acer VCM.lnk -> C:\Program Files\Acer\Acer VCM\AcerVCM.exe (Acer Incorporated) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Air Mouse.lnk ShortcutTarget: Air Mouse.lnk -> C:\Program Files\Air Mouse\Air Mouse\Air Mouse.exe () ShellIconOverlayIdentifiers: [OverlayExcluded] -> {4433A54A-1AC8-432F-90FC-85F045CF383C} => C:\Program Files\Norton 360\Engine\21.6.0.32\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: [OverlayPending] -> {F17C0B1E-EF8E-4AD4-8E1B-7D7E8CB23225} => C:\Program Files\Norton 360\Engine\21.6.0.32\buShell.dll (Symantec Corporation) ShellIconOverlayIdentifiers: [OverlayProtected] -> {476D0EA3-80F9-48B5-B70B-05E677C9C148} => C:\Program Files\Norton 360\Engine\21.6.0.32\buShell.dll (Symantec Corporation) CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1096382573-999743387-1970358641-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.bing.com HKU\S-1-5-21-1096382573-999743387-1970358641-1000\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com SearchScopes: HKLM -> DefaultScope value is missing. SearchScopes: HKU\S-1-5-21-1096382573-999743387-1970358641-1000 -> {012E1000-F331-11DB-8314-0800200C9A66} URL = hxxp://www.google.com/search?q={searchTerms} BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files\Norton 360\Engine\21.6.0.32\coIEPlg.dll (Symantec Corporation) BHO: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files\Norton 360\Engine\21.6.0.32\IPS\IPSBHO.DLL (Symantec Corporation) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton 360\Engine\21.6.0.32\coIEPlg.dll (Symantec Corporation) Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Acer\Acer VCM\Skype4COM.dll (Skype Technologies) Winsock: Catalog5 07 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.0.1 FireFox: ======== FF ProfilePath: C:\Users\PramoxLaptop\AppData\Roaming\Mozilla\Firefox\Profiles\et5cxbr7.default-1405707576517 FF NewTab: hxxp://www.google.com/ FF DefaultSearchUrl: hxxp://www.google.com/search?btnG=Google+Search&q= FF SearchEngineOrder.1: Google FF SelectedSearchEngine: Google FF Homepage: hxxp://www.google.com FF Keyword.URL: hxxp://www.google.com/search?btnG=Google+Search&q= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF32_16_0_0_296.dll () FF Plugin: @Apple.com/iTunes,version=1.0 -> C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @divx.com/DivX VOD Helper,version=1.0.0 -> C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.) FF Plugin: @divx.com/DivX Web Player Plug-In,version=1.0.0 -> C:\Program Files\DivX\DivX Web Player\npdivx32.dll (DivX, LLC) FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.31211.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeLive,version=1.5 -> C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation) FF Plugin: @tools.google.com/Google Update;version=3 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @tools.google.com/Google Update;version=9 -> C:\Program Files\Google\Update\1.3.25.11\npGoogleUpdate3.dll (Google Inc.) FF Plugin: @videolan.org/vlc,version=2.1.3 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: @videolan.org/vlc,version=2.1.5 -> C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin: Adobe Reader -> C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1096382573-999743387-1970358641-1000: @citrixonline.com/appdetectorplugin -> C:\Users\PramoxLaptop\AppData\Local\Citrix\Plugins\104\npappdetector.dll (Citrix Online) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\PramoxLaptop\AppData\Roaming\Mozilla\Firefox\Profiles\et5cxbr7.default-1405707576517\searchplugins\google-images.xml FF SearchPlugin: C:\Users\PramoxLaptop\AppData\Roaming\Mozilla\Firefox\Profiles\et5cxbr7.default-1405707576517\searchplugins\google-maps.xml FF SearchPlugin: C:\Users\PramoxLaptop\AppData\Roaming\Mozilla\Firefox\Profiles\et5cxbr7.default-1405707576517\searchplugins\safesearch.xml FF Extension: Cliqz Beta - C:\Users\PramoxLaptop\AppData\Roaming\Mozilla\Firefox\Profiles\et5cxbr7.default-1405707576517\Extensions\cliqz@cliqz.com.xpi [2014-11-20] FF Extension: TinEye Reverse Image Search - C:\Users\PramoxLaptop\AppData\Roaming\Mozilla\Firefox\Profiles\et5cxbr7.default-1405707576517\Extensions\tineye@ideeinc.com.xpi [2014-12-27] FF Extension: NoScript - C:\Users\PramoxLaptop\AppData\Roaming\Mozilla\Firefox\Profiles\et5cxbr7.default-1405707576517\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-07-22] FF Extension: Adblock Edge - C:\Users\PramoxLaptop\AppData\Roaming\Mozilla\Firefox\Profiles\et5cxbr7.default-1405707576517\Extensions\{fe272bd1-5f76-4ea4-8501-a05d35d823fc}.xpi [2014-07-22] FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension FF Extension: Microsoft .NET Framework Assistant - c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-11-29] FF HKLM\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_21.1.0.18\coFFPlgn [2015-01-26] FF HKU\S-1-5-21-1096382573-999743387-1970358641-1000\...\Firefox\Extensions: [cliqz@cliqz.com] - C:\Users\PramoxLaptop\AppData\Roaming\Mozilla\Firefox\Profiles\et5cxbr7.default-1405707576517\extensions\cliqz@cliqz.com Chrome: ======= CHR Profile: C:\Users\PramoxLaptop\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Docs) - C:\Users\PramoxLaptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-06-13] CHR Extension: (Google Drive) - C:\Users\PramoxLaptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-06-13] CHR Extension: (YouTube) - C:\Users\PramoxLaptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-06-13] CHR Extension: (Google Search) - C:\Users\PramoxLaptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-06-13] CHR Extension: (Google Wallet) - C:\Users\PramoxLaptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-06-13] CHR Extension: (Gmail) - C:\Users\PramoxLaptop\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-06-13] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - No Path CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files\Norton 360\Engine\21.6.0.32\Exts\Chrome.crx [2014-10-05] ========================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) R2 a2AntiMalware; C:\Program Files\Emsisoft Anti-Malware\a2service.exe [4161512 2013-12-04] (Emsisoft GmbH) R2 DevoloNetworkService; C:\Program Files\devolo\dlan\devolonetsvc.exe [3526136 2013-08-27] (devolo AG) R2 ePowerSvc; C:\Program Files\Acer\Acer PowerSmart Manager\ePowerSvc.exe [666144 2009-03-11] (Acer Incorporated) R2 MyEpson Portal Service; C:\Program Files\EPSON\MyEpson Portal\mepService.exe [703984 2014-09-22] (SEIKO EPSON CORPORATION) R2 N360; C:\Program Files\Norton 360\Engine\21.6.0.32\N360.exe [265040 2014-09-21] (Symantec Corporation) S2 NTI IScheduleSvc; C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe [44800 2009-03-20] (NewTech Infosystems, Inc.) R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [144632 2008-09-23] (NewTech Infosystems, Inc.) R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [237568 2008-11-27] (Acer Incorporated) [File not signed] S2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [272952 2008-01-21] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S3 a2acc; C:\PROGRAM FILES\EMSISOFT ANTI-MALWARE\a2accx86.sys [57944 2013-08-24] (Emsisoft GmbH) R1 A2DDA; C:\Program Files\Emsisoft Anti-Malware\a2ddax86.sys [22056 2013-03-28] (Emsisoft GmbH) R1 a2injectiondriver; C:\Program Files\Emsisoft Anti-Malware\a2dix86.sys [38248 2013-09-30] (Emsisoft GmbH) R1 a2util; C:\Program Files\Emsisoft Anti-Malware\a2util32.sys [14432 2013-03-28] (Emsisoft GmbH) R1 BHDrvx86; C:\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150106.001\BHDrvx86.sys [1164504 2015-01-06] (Symantec Corporation) R1 ccSet_N360; C:\Windows\system32\drivers\N360\1506000.020\ccSetx86.sys [127064 2013-09-26] (Symantec Corporation) S3 cleanhlp; C:\Program Files\Emsisoft Anti-Malware\cleanhlp32.sys [50200 2013-12-04] (Emsisoft GmbH) R1 eeCtrl; C:\Program Files\Common Files\Symantec Shared\EENGINE\eeCtrl.sys [378672 2014-12-11] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [111408 2014-12-11] (Symantec Corporation) R2 FPSensor; C:\Windows\System32\Drivers\FPSensor.sys [26928 2008-12-24] (Egis) R3 hidshim; C:\Windows\System32\DRIVERS\hidshim.sys [5632 2008-10-08] (Windows (R) Codename Longhorn DDK provider) R1 IDSVix86; C:\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\IPSDefs\20150123.001\IDSvix86.sys [503000 2015-01-14] (Symantec Corporation) R3 NAVENG; C:\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150124.003\NAVENG.SYS [95704 2015-01-23] (Symantec Corporation) R3 NAVEX15; C:\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\VirusDefs\20150124.003\NAVEX15.SYS [1636696 2015-01-23] (Symantec Corporation) R2 NPF_devolo; C:\Windows\system32\drivers\npf_devolo.sys [35840 2013-08-21] (CACE Technologies) [File not signed] R3 nuvotonhidgeneric; C:\Windows\System32\DRIVERS\nuvotonhidgeneric.sys [22528 2008-10-08] (Nuvoton Technology Corporation) R3 SRTSP; C:\Windows\System32\Drivers\N360\1506000.020\SRTSP.SYS [664792 2014-08-26] (Symantec Corporation) R1 SRTSPX; C:\Windows\system32\drivers\N360\1506000.020\SRTSPX.SYS [32984 2014-08-26] (Symantec Corporation) R0 SymDS; C:\Windows\System32\drivers\N360\1506000.020\SYMDS.SYS [367704 2013-09-10] (Symantec Corporation) R0 SymEFA; C:\Windows\System32\drivers\N360\1506000.020\SYMEFA.SYS [936152 2014-03-04] (Symantec Corporation) R3 SymEvent; C:\Windows\system32\Drivers\SYMEVENT.SYS [142936 2014-01-22] (Symantec Corporation) R1 SymIRON; C:\Windows\system32\drivers\N360\1506000.020\Ironx86.SYS [209624 2014-08-06] (Symantec Corporation) R1 SYMTDIv; C:\Windows\System32\Drivers\N360\1506000.020\SYMTDIV.SYS [384728 2014-02-18] (Symantec Corporation) S2 int15; \??\c:\Windows\system32\drivers\int15.sys [X] S3 IpInIp; system32\DRIVERS\ipinip.sys [X] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X] U5 TMUSB; C:\Windows\System32\DRIVERS\TMUSBXP.SYS [49408 2013-09-06] (Seiko Epson Corporation) ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-26 16:34 - 2015-01-26 16:34 - 00019935 _____ () C:\Users\PramoxLaptop\Desktop\FRST.txt 2015-01-26 16:31 - 2015-01-26 16:34 - 00000000 ____D () C:\FRST 2015-01-26 16:31 - 2015-01-26 16:31 - 01120768 _____ (Farbar) C:\Users\PramoxLaptop\Desktop\FRST.exe 2015-01-26 16:21 - 2015-01-26 16:23 - 00000000 ____D () C:\Users\PramoxLaptop\Desktop\Geocaching 2015-01-24 21:15 - 2015-01-24 21:15 - 00000680 _____ () C:\Users\PramoxLaptop\AppData\Local\d3d9caps.dat 2015-01-14 21:47 - 2015-01-14 21:48 - 00000000 ____D () C:\Program Files\Mozilla Firefox 2015-01-14 18:57 - 2014-12-19 01:25 - 00115200 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mrxdav.sys 2015-01-14 18:52 - 2014-12-06 04:14 - 00174080 _____ (Microsoft Corporation) C:\Windows\system32\nlasvc.dll 2015-01-14 18:52 - 2014-12-06 04:14 - 00093184 _____ (Microsoft Corporation) C:\Windows\system32\ncsi.dll 2015-01-14 18:52 - 2014-12-06 04:14 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\nlaapi.dll 2015-01-14 18:51 - 2014-12-06 04:14 - 00153600 _____ (Microsoft Corporation) C:\Windows\system32\profsvc.dll 2014-12-27 18:41 - 2014-12-27 18:41 - 00000000 ____D () C:\Users\PramoxLaptop\AppData\Local\CrypTool2 2014-12-27 18:40 - 2014-12-27 18:40 - 00000000 ____D () C:\Users\PramoxLaptop\Documents\CrypTool 2 Projects 2014-12-27 18:40 - 2014-12-27 18:40 - 00000000 ____D () C:\Users\PramoxLaptop\AppData\Local\Distributed_Systems_Group ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-01-26 16:33 - 2014-06-08 12:25 - 00000863 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2015-01-26 16:30 - 2014-05-14 13:55 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-01-26 16:30 - 2014-03-06 19:09 - 00000604 _____ () C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1096382573-999743387-1970358641-1000.job 2015-01-26 16:29 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2015-01-26 16:29 - 2006-11-02 13:47 - 00003616 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2015-01-26 16:26 - 2014-06-12 05:37 - 00000000 ____D () C:\Program Files\Mozilla Thunderbird 2015-01-26 16:26 - 2014-05-14 13:55 - 00001098 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-01-26 16:23 - 2013-11-24 13:46 - 01334328 _____ () C:\Windows\WindowsUpdate.log 2015-01-26 16:19 - 2013-11-29 20:46 - 00098588 _____ () C:\ProgramData\nvModes.001 2015-01-26 16:17 - 2014-05-14 13:55 - 00001094 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-01-26 16:17 - 2013-11-29 19:30 - 00098588 _____ () C:\ProgramData\nvModes.dat 2015-01-26 16:17 - 2006-11-02 14:01 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2015-01-25 00:17 - 2006-11-02 14:01 - 00032534 _____ () C:\Windows\Tasks\SCHEDLGU.TXT 2015-01-24 22:30 - 2013-12-08 13:33 - 00701616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2015-01-24 22:30 - 2013-12-08 13:33 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2015-01-24 21:31 - 2014-05-14 13:55 - 00001967 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2015-01-24 21:07 - 2014-04-07 17:21 - 00000000 ____D () C:\Users\PramoxLaptop\AppData\Local\CrashDumps 2015-01-24 20:39 - 2008-01-21 03:47 - 00899880 _____ () C:\Windows\PFRO.log 2015-01-16 06:58 - 2013-11-24 16:26 - 00000000 ____D () C:\Program Files\Mozilla Maintenance Service 2015-01-14 18:57 - 2013-11-30 13:23 - 00000000 ____D () C:\Windows\system32\MRT 2015-01-14 18:52 - 2006-11-02 11:24 - 110348472 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe 2015-01-12 21:15 - 2014-11-18 19:50 - 00860736 _____ () C:\Users\PramoxLaptop\Downloads\hexedit602.zip 2015-01-05 06:58 - 2006-11-02 11:33 - 01566076 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-12-30 19:19 - 2014-03-12 15:24 - 00000000 ____D () C:\Users\PramoxLaptop\Desktop\Fotos 2014-12-29 20:54 - 2014-06-08 12:26 - 00000000 ____D () C:\Users\PramoxLaptop\AppData\Roaming\vlc ==================== Files in the root of some directories ======= 2015-01-24 21:15 - 2015-01-24 21:15 - 0000680 _____ () C:\Users\PramoxLaptop\AppData\Local\d3d9caps.dat 2014-01-15 18:17 - 2014-11-03 19:29 - 0008704 _____ () C:\Users\PramoxLaptop\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2014-08-26 18:36 - 2014-08-26 18:36 - 0004096 ____H () C:\Users\PramoxLaptop\AppData\Local\keyfile3.drm 2013-11-24 14:15 - 2013-11-24 15:52 - 0008156 _____ () C:\Users\PramoxLaptop\AppData\Local\MyWinLockerInstaller.txt-20131124.log 2009-03-12 04:26 - 2013-11-24 14:19 - 0004789 _____ () C:\ProgramData\ArcadeDeluxe2.log 2013-11-29 20:46 - 2015-01-26 16:19 - 0098588 _____ () C:\ProgramData\nvModes.001 2013-11-29 19:30 - 2015-01-26 16:17 - 0098588 _____ () C:\ProgramData\nvModes.dat 2013-11-24 16:02 - 2013-11-24 16:03 - 0000090 _____ () C:\ProgramData\PS.log Some content of TEMP: ==================== C:\Users\PramoxLaptop\AppData\Local\Temp\RtkBtMnt.exe C:\Users\PramoxLaptop\AppData\Local\Temp\vlc-2.1.5-win32.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\explorer.exe => File is digitally signed C:\Windows\system32\winlogon.exe => File is digitally signed C:\Windows\system32\wininit.exe => File is digitally signed C:\Windows\system32\svchost.exe => File is digitally signed C:\Windows\system32\services.exe => File is digitally signed C:\Windows\system32\User32.dll => File is digitally signed C:\Windows\system32\userinit.exe => File is digitally signed C:\Windows\system32\rpcss.dll => File is digitally signed C:\Windows\system32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-01-26 16:23 FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 24-01-2015 01 Ran by PramoxLaptop at 2015-01-26 16:34:53 Running from C:\Users\PramoxLaptop\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton 360 (Disabled - Up to date) {D87FA2C0-F526-77B1-D6EC-0EDF3936CEDB} AS: Norton 360 (Enabled - Up to date) {631E4324-D31C-783F-EC5C-35AD42B18466} AS: Windows Defender (Disabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} FW: Norton 360 (Disabled) {E04423E5-BF49-76E9-FDB3-A7EAC7E589A0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) 7-Zip 9.22beta (HKLM\...\7-Zip) (Version: - ) AC3Filter 2.6.0b (HKLM\...\AC3Filter_is1) (Version: 2.6.0b - Alexander Vigovsky) Acer Backup Manager (HKLM\...\InstallShield_{72B776E5-4530-4C4B-9453-751DF87D9D93}) (Version: 1.0.0.50 - NewTech Infosystems) Acer Crystal Eye webcam Ver:1.1.79.326 (HKLM\...\{D0ACE89D-EC7F-470F-80BE-4C98ED366B32}) (Version: 1.1.79.326 - Chicony Electronics Co.,Ltd.) Acer eRecovery Management (HKLM\...\{7F811A54-5A09-4579-90E1-C93498E230D9}) (Version: 4.00.3005 - Acer Incorporated) Acer GridVista (HKLM\...\GridVista) (Version: 2.72.317 - ) Acer PowerSmart Manager (HKLM\...\{3DB0448D-AD82-4923-B305-D001E521A964}) (Version: 4.01.3006 - Acer Incorporated) Acer Product Registration (HKLM\...\{DA20E1A8-07CB-4EE7-9B72-A7E28C953F0E}) (Version: 3.0.0.10 - Acer Incorporated) Acer ScreenSaver (HKLM\...\Acer Screensaver) (Version: - Acer) Acer VCM (HKLM\...\{047F790A-7A2A-4B6A-AD02-38092BA63DAC}) (Version: 4.00.3004 - Acer Incorporated) Adobe Flash Player 16 ActiveX (HKLM\...\Adobe Flash Player ActiveX) (Version: 16.0.0.296 - Adobe Systems Incorporated) Adobe Flash Player 16 NPAPI (HKLM\...\Adobe Flash Player NPAPI) (Version: 16.0.0.296 - Adobe Systems Incorporated) Adobe Reader X (10.1.12) - Deutsch (HKLM\...\{AC76BA86-7AD7-1031-7B44-AA1000000001}) (Version: 10.1.12 - Adobe Systems Incorporated) Agere Systems HDA Modem (HKLM\...\Agere Systems Soft Modem) (Version: - Agere Systems) AmIcoSingLun (HKLM\...\InstallShield_{BF91B300-EEBC-4223-96F3-0FCBF7241B50}) (Version: 1.2.117.1 - Alcor Micro Co., Ltd.) AmIcoSingLun (Version: 1.2.117.1 - Alcor Micro Co., Ltd.) Hidden Apple Application Support (HKLM\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.) Apple Mobile Device Support (HKLM\...\{C0CC75CD-F5B7-46AD-B016-17C0F5171718}) (Version: 8.0.0.23 - Apple Inc.) Apple Software Update (HKLM\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.) Backup Manager Basic (Version: 1.0.0.50 - NewTech Infosystems) Hidden Bonjour (HKLM\...\{79155F2B-9895-49D7-8612-D92580E0DE5B}) (Version: 3.0.0.10 - Apple Inc.) Broadcom Gigabit NetLink Controller (HKLM\...\{9AF0B106-56F1-461B-A270-95BC1682E282}) (Version: 11.34.02 - Broadcom Corporation) Cliqz (HKLM\...\{5A0C0737-6AFE-4DC6-A8B4-6DFE509ACD75}_is1) (Version: 0.5.31 - Cliqz.com) Compatibility Pack für 2007 Office System (HKLM\...\{90120000-0020-0407-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation) devolo dLAN Cockpit (HKLM\...\dlancockpit) (Version: 4.1.3.0 - devolo AG) DivX-Setup (HKLM\...\DivX Setup) (Version: 2.6.1.100 - DivX, LLC) Druckerdeinstallation für EPSON SX235 Series (HKLM\...\EPSON SX235 Series) (Version: - SEIKO EPSON Corporation) Emsisoft Anti-Malware (HKLM\...\{BC30E5E7-047D-4232-A7E8-F2CB7CC7B2E0}_is1) (Version: 8.1 - Emsisoft GmbH) EPSON Scan (HKLM\...\EPSON Scanner) (Version: - Seiko Epson Corporation) EpsonNet Config V4 (HKLM\...\{08013FB5-DF8B-4D29-9B5E-B3DE88EBA6CA}) (Version: 4.4.1 - SEIKO EPSON CORPORATION) Free DVD Video Converter version 2.0.20.623 (HKLM\...\Free DVD Video Converter_is1) (Version: 2.0.20.623 - DVDVideoSoft Ltd.) Free MP4 Video Converter version 5.0.44.623 (HKLM\...\Free MP4 Video Converter_is1) (Version: 5.0.44.623 - DVDVideoSoft Ltd.) Google Chrome (HKLM\...\Google Chrome) (Version: 40.0.2214.91 - Google Inc.) Google Update Helper (Version: 1.3.25.11 - Google Inc.) Hidden GoToMeeting 6.4.11.2273 (HKU\S-1-5-21-1096382573-999743387-1970358641-1000\...\GoToMeeting) (Version: 6.4.11.2273 - CitrixOnline) GSAK 8.4.0.0 (HKLM\...\GSAK_is1) (Version: - CWE computer services) Hex-Editor MX (HKLM\...\{7FC7AD70-1DF3-4B84-9AA2-4FB680F45572}_is1) (Version: 6.0 - NEXT-Soft) IrfanView (remove only) (HKLM\...\IrfanView) (Version: 4.37 - Irfan Skiljan) iTunes (HKLM\...\{F32DC846-4457-40A8-BECA-BCC0E960BC53}) (Version: 11.4.0.18 - Apple Inc.) Launch Manager (HKLM\...\LManager) (Version: 2.0.01 - Acer Inc.) Malwarebytes Anti-Malware Version 2.0.2.1012 (HKLM\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation) Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation) Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office File Validation Add-In (HKLM\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Live Add-in 1.5 (HKLM\...\{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}) (Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Professional Edition 2003 (HKLM\...\{91E30407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.31211.0 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation) Mobile Mouse Server (HKLM\...\{895FE43E-71C2-4FEA-94EF-B88D111495FC}) (Version: 2.7.0 - RPA Tech, Inc) Mozilla Firefox 35.0 (x86 de) (HKLM\...\Mozilla Firefox 35.0 (x86 de)) (Version: 35.0 - Mozilla) Mozilla Maintenance Service (HKLM\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla) Mozilla Thunderbird 24.6.0 (x86 de) (HKLM\...\Mozilla Thunderbird 24.6.0 (x86 de)) (Version: 24.6.0 - Mozilla) MP4Joiner v2.1.2 (HKLM\...\MP4Joiner_is1) (Version: - ) MSXML 4.0 SP2 (KB954430) (HKLM\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (HKLM\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation) MyEpson Portal (HKLM\...\MyEpson Portal) (Version: - SEIKO EPSON Corporation) MyEpson Portal (Version: 1.1.1.0 - SEIKO EPSON CORPORATION) Hidden Norton 360 (HKLM\...\N360) (Version: 21.6.0.32 - Symantec Corporation) NTI Backup Now 5 (HKLM\...\InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}) (Version: 5.1.2.616 - NewTech Infosystems) NTI Backup Now Standard (Version: 5.1.2.616 - NewTech Infosystems) Hidden NTI Media Maker 8 (HKLM\...\InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}) (Version: 8.0.2.6509 - NewTech Infosystems) NTI Media Maker 8 (Version: 8.0.2.6509 - NewTech Infosystems) Hidden Nuvoton EC Generic HID Driver (HKLM\...\{302E9B7B-2B6A-4C29-9A02-9F2110649779}) (Version: 7.80.5000 - Nuvoton Technology Corporation) NVIDIA Drivers (HKLM\...\NVIDIA Drivers) (Version: 1.3 - NVIDIA Corporation) PDF24 Creator 6.3.2 (HKLM\...\{81A6F461-0DBA-4F12-B56F-0E977EC10576}_is1) (Version: - PDF24.org) Realtek High Definition Audio Driver (HKLM\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5807 - Realtek Semiconductor Corp.) SpywareBlaster 5.0 (HKLM\...\SpywareBlaster_is1) (Version: 5.0.0 - BrightFort LLC) Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 12.1.0.0 - Synaptics) VC80CRTRedist - 8.0.50727.6195 (Version: 1.2.0 - DivX, Inc) Hidden VLC media player (HKLM\...\VLC media player) (Version: 2.1.5 - VideoLAN) XnView 2.25 (HKLM\...\XnView_is1) (Version: 2.25 - Gougelet Pierre-e) ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) CustomCLSID: HKU\S-1-5-21-1096382573-999743387-1970358641-1000_Classes\CLSID\{84B5A313-CD5D-4904-8BA2-AFDC81C1B309}\InprocServer32 -> C:\Users\PramoxLaptop\AppData\Local\Citrix\GoToMeeting\1312\G2MOutlookAddin.dll (Citrix Online, a division of Citrix Systems, Inc.) ==================== Restore Points ========================= 25-10-2014 23:29:17 Geplanter Prüfpunkt 03-11-2014 19:34:12 Installed MyEpson Portal 13-11-2014 06:29:48 Windows Update 19-11-2014 17:17:07 Windows Update 26-11-2014 23:11:50 Geplanter Prüfpunkt 02-12-2014 18:34:54 Geplanter Prüfpunkt 06-12-2014 18:25:46 Geplanter Prüfpunkt 10-12-2014 07:33:21 Windows Update 10-12-2014 19:38:33 Geplanter Prüfpunkt 17-12-2014 16:08:11 Windows Update 14-01-2015 18:50:19 Windows Update ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2006-11-02 11:23 - 2014-03-12 18:12 - 00000763 ____N C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ::1 localhost ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {07BB548C-C299-488D-BB20-6AF1662E2688} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-05-14] (Google Inc.) Task: {6F42816F-C4A7-4DD5-93AB-44B18FC1AE0E} - System32\Tasks\Norton WSC Integration => C:\Program Files\Norton 360\Engine\21.6.0.32\WSCStub.exe [2014-09-21] (Symantec Corporation) Task: {7B268E13-A8CF-400D-A18C-060AAB5F0A85} - System32\Tasks\Norton 360\Norton Error Analyzer => C:\Program Files\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {7C6B35B5-4D1F-4FBA-9170-460EBE595467} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2015-01-24] (Adobe Systems Incorporated) Task: {9B1091E8-5AF9-4125-AC97-20BBE0BACD0B} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2014-05-14] (Google Inc.) Task: {A9912F57-2A8C-4385-820F-6297FD7EF97D} - System32\Tasks\Norton 360\Norton Error Processor => C:\Program Files\Norton 360\Engine\21.6.0.32\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {D536E162-18C6-4752-9338-48B1FC17AD2D} - System32\Tasks\G2MUpdateTask-S-1-5-21-1096382573-999743387-1970358641-1000 => C:\Users\PramoxLaptop\AppData\Local\Citrix\GoToMeeting\2273\g2mupdate.exe [2015-01-25] (Citrix Online, a division of Citrix Systems, Inc.) Task: {FA6BD5BE-CC57-43FE-826E-C9A67CF648E7} - System32\Tasks\Acer\Burn Notification => C:\Program Files\Acer\Acer eRecovery Management\NotificationCenter\Notification.exe [2009-02-05] (Acer) (If an entry is included in the fixlist, the task (.job) file will be moved. The file which is running by the task will not be moved.) Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\G2MUpdateTask-S-1-5-21-1096382573-999743387-1970358641-1000.job => C:\Users\PramoxLaptop\AppData\Local\Citrix\GoToMeeting\2273\g2mupdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2014-07-03 12:20 - 2014-07-03 12:20 - 00073544 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2014-07-03 12:19 - 2014-07-03 12:19 - 01044808 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2013-11-24 14:08 - 2013-11-24 14:07 - 00200704 _____ () C:\Windows\PLFSetI.exe 2014-01-10 06:26 - 2014-01-10 06:26 - 01861968 _____ () C:\Program Files\DivX\DivX Update\DivXUpdate.exe 2014-01-10 06:28 - 2014-01-10 06:28 - 00100688 _____ () C:\Program Files\DivX\DivX Update\DivXUpdateCheck.dll 2012-09-23 19:44 - 2012-09-23 19:44 - 01600512 _____ () C:\Program Files\Air Mouse\Air Mouse\Air Mouse.exe 2011-06-14 13:19 - 2011-06-14 13:19 - 00025600 _____ () C:\Program Files\Air Mouse\Air Mouse\BonjourService.dll 2015-01-14 21:47 - 2015-01-14 21:48 - 03925104 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) AlternateDataStreams: C:\ProgramData\Temp:5C321E34 AlternateDataStreams: C:\Users\PramoxLaptop\Desktop\Spartacus.mp4:TOC.WMV ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver" ==================== EXE Association (whitelisted) ============= (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== MSCONFIG/TASK MANAGER disabled items ========= (Currently there is no automatic fix for this section.) ========================= Accounts: ========================== Administrator (S-1-5-21-1096382573-999743387-1970358641-500 - Administrator - Disabled) Gast (S-1-5-21-1096382573-999743387-1970358641-501 - Limited - Disabled) PramoxLaptop (S-1-5-21-1096382573-999743387-1970358641-1000 - Administrator - Enabled) => C:\Users\PramoxLaptop ==================== Faulty Device Manager Devices ============= Name: 6TO4 Adapter Description: Microsoft-6zu4-Adapter Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: tunnel Problem: : This device cannot start. (Code10) Resolution: Device failed to start. Click "Update Driver" to update the drivers for this device. On the "General Properties" tab of the device, click "Troubleshoot" to start the troubleshooting wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (01/26/2015 04:33:39 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: Programm FRST.exe, Version 24.1.2015.1 arbeitet nicht mehr mit Windows zusammen und wurde beendet. Überprüfen Sie den Problemverlauf im Applet "Lösungen für Probleme" in der Systemsteuerung, um nach weiteren Informationen über das Problem zu suchen. Prozess-ID: 360 Anfangszeit: 01d0397d1f61032a Zeitpunkt der Beendigung: 15 Error: (01/26/2015 04:17:20 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/26/2015 04:17:14 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (01/26/2015 04:17:08 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Die abhängige Assemblierung "Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (01/24/2015 09:15:47 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 52354 Error: (01/24/2015 09:15:47 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 52354 Error: (01/24/2015 09:15:47 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (01/24/2015 09:15:31 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 37097 Error: (01/24/2015 09:15:31 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 37097 Error: (01/24/2015 09:15:31 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second System errors: ============= Error: (01/26/2015 04:18:09 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT-AUTORITÄTLOKALER DIENSTS-1-5-19LocalHost (unter Verwendung von LRPC) Error: (01/26/2015 04:18:07 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (01/26/2015 04:17:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: NTI IScheduleSvc%%14001 Error: (01/26/2015 04:17:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: int15%%2 Error: (01/26/2015 04:17:21 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Error: (01/24/2015 08:41:16 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT-AUTORITÄTLOKALER DIENSTS-1-5-19LocalHost (unter Verwendung von LRPC) Error: (01/24/2015 08:41:16 PM) (Source: DCOM) (EventID: 10016) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (01/24/2015 08:40:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: NTI IScheduleSvc%%14001 Error: (01/24/2015 08:40:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: int15%%2 Error: (01/24/2015 08:40:51 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Parallel port driver%%1058 Microsoft Office Sessions: ========================= Error: (01/26/2015 04:33:39 PM) (Source: Application Hang) (EventID: 1002) (User: ) Description: FRST.exe24.1.2015.136001d0397d1f61032a15 Error: (01/26/2015 04:17:20 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/26/2015 04:17:14 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files\NewTech Infosystems\Acer Backup Manager\BackupManagerTray.exe Error: (01/26/2015 04:17:08 PM) (Source: SideBySide) (EventID: 33) (User: ) Description: Microsoft.VC90.MFC,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"C:\Program Files\NewTech Infosystems\Acer Backup Manager\IScheduleSvc.exe Error: (01/24/2015 09:15:47 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 52354 Error: (01/24/2015 09:15:47 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 52354 Error: (01/24/2015 09:15:47 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second Error: (01/24/2015 09:15:31 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledSPRetry 37097 Error: (01/24/2015 09:15:31 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: m->NextScheduledEvent 37097 Error: (01/24/2015 09:15:31 PM) (Source: Bonjour Service) (EventID: 100) (User: ) Description: Task Scheduling Error: Continuously busy for more than a second CodeIntegrity Errors: =================================== Date: 2015-01-26 16:34:32.114 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-26 16:34:31.833 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-26 16:34:31.630 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-26 16:34:31.365 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-26 16:34:19.681 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150106.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-26 16:34:19.509 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150106.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-26 16:34:19.322 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150106.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-26 16:34:19.150 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Program Files\Norton 360\NortonData\21.1.0.18\Definitions\BASHDefs\20150106.001\BHDrvx86.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-26 16:33:30.699 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. Date: 2015-01-26 16:33:30.543 Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\SYMEVENT.SYS" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde. ==================== Memory info =========================== Processor: Intel(R) Core(TM)2 Quad CPU Q9000 @ 2.00GHz Percentage of memory in use: 46% Total physical RAM: 3065.89 MB Available physical RAM: 1632.59 MB Total Pagefile: 6340.81 MB Available Pagefile: 4637.35 MB Total Virtual: 2047.88 MB Available Virtual: 1896.27 MB ==================== Drives ================================ Drive c: (ACER) (Fixed) (Total:452.99 GB) (Free:277.75 GB) NTFS ==>[Drive with boot components (obtained from BCD)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 6F050EC2) Partition 1: (Not Active) - (Size=9.8 GB) - (Type=27) Partition 2: (Active) - (Size=453 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=3 GB) - (Type=12) ==================== End Of Log ============================ --- --- --- |
26.01.2015, 18:29 | #4 |
/// the machine /// TB-Ausbilder | Irgendwas eingefangen. Lahme Browser ... Deaktiviere Norton komplett, teste die Browser nochmal.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
09.02.2015, 20:39 | #5 |
| Irgendwas eingefangen. Lahme Browser ... Sorry für die späte Antwort, war in Urlaub. Leider löst dies das Problem nicht. Manche Websites werden trotzdem erst nach 15-30 Sekunden geladen! |
10.02.2015, 07:01 | #6 |
/// the machine /// TB-Ausbilder | Irgendwas eingefangen. Lahme Browser ... In allen Browsern? Und nur auf deinem Rechner? Andere im Netzwerk haben das Problem nicht? Definiere mal manche Websites, welche genau?
__________________ --> Irgendwas eingefangen. Lahme Browser ... |
11.02.2015, 23:22 | #7 |
| Irgendwas eingefangen. Lahme Browser ... Gefühlt ist es beim Firefox länger als beim IE, aber bei beiden kommt es zu verzögerungen. Das kann auf jeder Website sein, zum Beispiel www.bild.de Der Bildschirm bleibt weiss, unten steht "Daten werden geladen" und nach 15 Sekunden, kommen dann die Artikel. Wir gehen auch mit 2 Iphones und einem Ipad in das Netzwerk, jetzt wo ich so direkt gefragt werde: Manchmal stockt es auch hier. Teilweise mehr, wenn wir mit 2 Geräten parallel drinne sind! |
12.02.2015, 18:26 | #8 |
/// the machine /// TB-Ausbilder | Irgendwas eingefangen. Lahme Browser ... Router auf Werkseinstellungen zurück setzen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Irgendwas eingefangen. Lahme Browser ... |
brauche, browser, glaube, hallo zusammen, inter, interne, internet, iphone, laden, richtig, tagen, teilweise, virus, websites, wlan, zusammen |