|
Log-Analyse und Auswertung: PC extrem langsam, Anwendungen "hängen sich auf", phys. Speicher bei 60% ohne offene ProgrammeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
14.04.2015, 20:32 | #1 |
| PC extrem langsam, Anwendungen "hängen sich auf", phys. Speicher bei 60% ohne offene Programme Hallo liebes TB-Team, ich habe folgendes Problem: Mein Computer ist seit einer Weile ausgesprochen langsam, es dauert lange, bis sich Programme öffnen oder der Computer auf Befehle reagiert. Zudem hängen sich die Programme oft auf. Videos kann ich nicht mehr schauen, auch hier hakt es, das Video bleibt hängen, und nur der Ton läuft weiter und umgekehrt. Mir ist aufgefallen, dass der physikalische Speicher recht hoch ausgelastet scheint, bei ca. 60%. Es laufen, ohne das ich aktiv Programme öffne, ca.75-80 Prozesse, gemäß Taskmanager. Vieles davon sind svchost-Prozesse. Ich nutze ein Samsung Series 5 Ultra mit Windows 7 64-Bit, 4GB RAM, Intel Core i3. Ich hoffe, ich habe alle relevanten Informationen bereits gestellt. Falls nicht, entschuldigen Sie bitte, aber ich kenne mich mit Computern nicht so gut aus. Gemäß der Anleitung habe ich versucht, die Logfiles zu erstellen. Bei FRST hat es nicht funktioniert. 1) Defogger disable: Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 20:14 on 14/04/2015 (Nina) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- 3) GMER: Code:
ATTFilter GMER 2.1.19357 - hxxp://www.gmer.net Rootkit scan 2015-04-14 20:46:51 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-0 Hitachi_ rev.GG2O 465,76GB Running: Gmer-19357.exe; Driver: C:\Users\Nina\AppData\Local\Temp\kxldqpow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtUnmapViewOfSection 00000000779ffc80 5 bytes JMP 000000010075012a .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtTerminateProcess 00000000779ffcb0 5 bytes JMP 0000000100750bc2 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtWriteVirtualMemory 00000000779ffe14 5 bytes JMP 0000000100750048 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtReadVirtualMemory 00000000779ffe90 5 bytes JMP 0000000100750e68 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtOpenEvent 00000000779ffea8 5 bytes JMP 0000000100750594 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtQueueApcThread 00000000779fff24 5 bytes JMP 0000000100750f4a .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtCreateThread 0000000077a00004 5 bytes JMP 0000000100750758 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtProtectVirtualMemory 0000000077a00038 5 bytes JMP 0000000100750ca4 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtResumeThread 0000000077a00068 5 bytes JMP 0000000100750d86 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtTerminateThread 0000000077a00084 5 bytes JMP 0000000100720050 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtAlertResumeThread 0000000077a002e8 5 bytes JMP 000000010075020c .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtCreateMutant 0000000077a0079c 5 bytes JMP 00000001007503d0 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtCreateSymbolicLinkObject 0000000077a0088c 5 bytes JMP 00000001007509fe .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtCreateThreadEx 0000000077a008a4 2 bytes JMP 000000010075091c .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtCreateThreadEx + 3 0000000077a008a7 2 bytes [D5, 88] .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtLoadDriver 0000000077a00df4 5 bytes JMP 0000000100750676 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtQueueApcThreadEx 0000000077a015d4 5 bytes JMP 00000001007502ee .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtSetContextThread 0000000077a01920 5 bytes JMP 000000010075083a .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtSetSystemInformation 0000000077a01be4 5 bytes JMP 0000000100750ae0 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\ntdll.dll!NtSuspendThread 0000000077a01d70 5 bytes JMP 00000001007504b2 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\sechost.dll!SetServiceObjectSecurity + 206 0000000075b0524f 7 bytes JMP 00000001007603d8 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\sechost.dll!ChangeServiceConfigA + 380 0000000075b053d0 7 bytes JMP 0000000100760684 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\sechost.dll!ChangeServiceConfig2W + 149 0000000075b05677 7 bytes JMP 00000001007604bc .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\sechost.dll!CreateServiceA + 542 0000000075b0589a 7 bytes JMP 000000010076012c .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\sechost.dll!CreateServiceW + 382 0000000075b05a1d 7 bytes JMP 000000010076084c .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\sechost.dll!QueryServiceConfigW + 370 0000000075b05c9b 7 bytes JMP 00000001007605a0 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\sechost.dll!ControlServiceExA + 231 0000000075b05d87 7 bytes JMP 0000000100760768 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\SysWOW64\sechost.dll!I_ScBroadcastServiceControlMessage + 123 0000000075b07240 7 bytes JMP 00000001007602f4 .text C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe[5628] C:\windows\syswow64\USER32.dll!RecordShutdownReason + 882 0000000076151492 7 bytes JMP 0000000100760a12 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c485080020c0 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c4850800fd8d Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c4850801bddb Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c4850801e59f Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\c4850867d15c Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c485080020c0 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c4850800fd8d (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c4850801bddb (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c4850801e59f (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\c4850867d15c (not active ControlSet) ---- Disk sectors - GMER 2.1 ---- Disk \Device\Harddisk0\DR0 unknown MBR code ---- EOF - GMER 2.1 ---- 4) Combofix Code:
ATTFilter Combofix Logfile: AdwCleaner Logfile: Code:
ATTFilter # AdwCleaner v4.201 - Bericht erstellt 13/04/2015 um 20:23:55 # Aktualisiert 08/04/2015 von Xplode # Datenbank : 2015-04-08.1 [Server] # Betriebssystem : Windows 7 Home Premium Service Pack 1 (x64) # Benutzername : Nina - NINA-PC # Gestarted von : C:\Users\Nina\Desktop\AdwCleaner_4.201.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\Uniblue ***** [ Geplante Tasks ] ***** ***** [ Verknüpfungen ] ***** Verknüpfung Desinfiziert : C:\Users\Nina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Google\Chrome\Extensions\bopakagnckmlgajfccecajhnimjiiedh Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\driverscanner Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{00B11DA2-75ED-4364-ABA5-9A95B1F5E946} Schlüssel Gelöscht : HKCU\Software\OCS Schlüssel Gelöscht : HKLM\SOFTWARE\Uniblue Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Features\B696D3C37BD0D6C33A65D38BEC459181 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Installer\Products\B696D3C37BD0D6C33A65D38BEC459181 Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\B696D3C37BD0D6C33A65D38BEC459181 ***** [ Internetbrowser ] ***** -\\ Internet Explorer v11.0.9600.17689 -\\ Mozilla Firefox v37.0.1 (x86 de) -\\ Google Chrome v41.0.2272.118 ************************* AdwCleaner[R0].txt - [1712 Bytes] - [13/04/2015 20:17:06] AdwCleaner[S0].txt - [1585 Bytes] - [13/04/2015 20:23:55] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1644 Bytes] ########## Den ganzen Schlamassel habe ich mir eingebrockt, als ich vor 6 Wochen ca. versucht habe, so ein Piraten-MSDosbox Spiel zu installieren von früher. Da hatte ich mir eines Browswer-Hijacker eingefangen - Er hieß Omni...soundso. Eigentlich hatte ich gedacht, dass ich ihn nach einigen Scans und Deinstallation der Browser wieder losgeworden bin, aber ich habe das dumme Gefühl, dem ist nicht so. Ich würde mich freuen, wenn Sie mir helfen können und ich sicher sein kann, dass sich keine Malware auf meinem Computer befindet. Vielen Dank und viele Grüße Nini123 Geändert von Nini123 (14.04.2015 um 20:46 Uhr) |
14.04.2015, 20:37 | #2 |
/// the machine /// TB-Ausbilder | PC extrem langsam, Anwendungen "hängen sich auf", phys. Speicher bei 60% ohne offene Programme Hi,
__________________Logs bitte immer in den Thread posten. Zur Not aufteilen und mehrere Posts nutzen. Ich kann auf Arbeit keine Anhänge öffnen, danke. So funktioniert es: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor:
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
14.04.2015, 21:25 | #3 |
| PC extrem langsam, Anwendungen "hängen sich auf", phys. Speicher bei 60% ohne offene Programme Hallo,
__________________die Logfiles, die ich schon hatte, sind in meinem Ursprungspost. Hier kommen nun noch die Logfiles von Farbar: FRST: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 13-04-2015 Ran by Nina (administrator) on NINA-PC on 14-04-2015 22:15:46 Running from C:\Users\Nina\Desktop Loaded Profiles: Nina (Available profiles: Nina) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\FreedomeService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Mozilla Corporation) C:\Program Files (x86)\mozilla firefox\firefox.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\nis.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\nis.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12480616 2012-04-24] (Realtek Semiconductor) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-04] (Intel Corporation) HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation) HKLM-x32\...\Run: [FreedomeAutoStart] => C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe [2396712 2015-03-17] (F-Secure Corporation) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3300620865-1981299825-1167858846-1000 -> {FC70D870-DB71-49F3-81B9-B961FAFDBD75} URL = https://www.google.com/search?q={searchTerms} BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine64\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\IPS\IPSBHO.DLL [2015-03-05] (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-11-16] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-16] (Oracle Corporation) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation) DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://qtinstall.apple.com/qtactivex/qtplugin.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Nina\AppData\Roaming\Mozilla\Firefox\Profiles\8nu6ee6q.default-1424464495624 FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll No File FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-11-16] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-11-16] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-20] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-20] (Google Inc.) FF Plugin-x32: @videolan.org/vlc,version=2.2.0 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN) FF Plugin HKU\S-1-5-21-3300620865-1981299825-1167858846-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Nina\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.) FF Extension: Adblock Plus - C:\Users\Nina\AppData\Roaming\Mozilla\Firefox\Profiles\8nu6ee6q.default-1424464495624\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-28] FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.1.7\coFFPlgn FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.1.7\coFFPlgn [2015-04-14] Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.google.com" CHR Profile: C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-20] CHR Extension: (Google Docs) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-20] CHR Extension: (Google Drive) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-20] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-02-26] CHR Extension: (YouTube) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-20] CHR Extension: (Google Search) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-20] CHR Extension: (Google Sheets) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-20] CHR Extension: (Google Wallet) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-20] CHR Extension: (Gmail) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-20] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\Exts\Chrome.crx [2015-03-24] CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\Exts\Chrome.crx [2015-03-24] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com) R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-03-30] (Diskeeper Corporation) R2 Freedome Service; C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\FreedomeService.exe [285736 2015-03-17] (F-Secure Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-08] () R2 irstrtsv; C:\windows\SysWOW64\irstrtsv.exe [193536 2012-02-06] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-08] (Intel Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\NIS.exe [276336 2015-03-07] (Symantec Corporation) R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation) R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [File not signed] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5448464 2015-03-30] (TeamViewer GmbH) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation) S3 AVerAF35; C:\Windows\System32\Drivers\AVerAF35.sys [717952 2010-05-31] (AVerMedia TECHNOLOGIES, Inc.) R3 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.1.7\Definitions\BASHDefs\20150321.001\BHDrvx64.sys [1622744 2015-02-03] (Symantec Corporation) R3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1507000.00B\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation) R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-17] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-17] (Symantec Corporation) R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-03-30] (Diskeeper Corporation) R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [95024 2012-03-30] (Diskeeper Corporation) R3 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.1.7\Definitions\IPSDefs\20150413.001\IDSvia64.sys [671448 2015-03-29] (Symantec Corporation) R3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2012-02-07] (Intel Corporation) R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.1.7\Definitions\VirusDefs\20150413.037\ENG64.SYS [129752 2015-01-20] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.1.7\Definitions\VirusDefs\20150413.037\EX64.SYS [2137304 2015-01-20] (Symantec Corporation) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1507000.00B\SRTSP64.SYS [876248 2014-08-26] (Symantec Corporation) R3 SRTSPX; C:\Windows\system32\drivers\NISx64\1507000.00B\SRTSPX64.SYS [37592 2014-08-26] (Symantec Corporation) R3 SymDS; C:\Windows\system32\drivers\NISx64\1507000.00B\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation) R3 SymEFA; C:\Windows\system32\drivers\NISx64\1507000.00B\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation) R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-03-20] (Symantec Corporation) R3 SymIRON; C:\Windows\system32\drivers\NISx64\1507000.00B\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation) R3 SymNetS; C:\Windows\System32\Drivers\NISx64\1507000.00B\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation) S3 clwvd; system32\DRIVERS\clwvd.sys [X] S3 MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-14 22:15 - 2015-04-14 22:16 - 00017545 _____ () C:\Users\Nina\Desktop\FRST.txt 2015-04-14 22:15 - 2015-04-14 22:15 - 00000000 ____D () C:\FRST 2015-04-14 22:14 - 2015-04-14 22:13 - 02096640 _____ (Farbar) C:\Users\Nina\Desktop\FRST64.exe 2015-04-14 22:13 - 2015-04-14 22:13 - 02096640 _____ (Farbar) C:\Users\Nina\Downloads\FRST64.exe 2015-04-14 21:01 - 2015-04-14 21:01 - 00282624 _____ () C:\windows\Minidump\041415-44179-01.dmp 2015-04-14 21:00 - 2015-04-14 21:00 - 1691830815 _____ () C:\windows\MEMORY.DMP 2015-04-14 20:46 - 2015-04-14 20:46 - 00007970 _____ () C:\Users\Nina\Desktop\gmer.txt 2015-04-14 20:37 - 2015-04-14 20:31 - 00380416 _____ () C:\Users\Nina\Desktop\Gmer-19357.exe 2015-04-14 20:30 - 2015-04-14 20:31 - 00380416 _____ () C:\Users\Nina\Downloads\Gmer-19357.exe 2015-04-14 20:15 - 2015-04-14 20:14 - 00000470 _____ () C:\Users\Nina\Desktop\defogger_disable.log 2015-04-14 20:14 - 2015-04-14 20:14 - 00000470 _____ () C:\Users\Nina\Downloads\defogger_disable.log 2015-04-14 20:14 - 2015-04-14 20:14 - 00000000 _____ () C:\Users\Nina\defogger_reenable 2015-04-14 20:12 - 2015-04-14 20:12 - 00050477 _____ () C:\Users\Nina\Downloads\Defogger.exe 2015-04-14 19:07 - 2015-04-14 19:17 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2015-04-14 19:07 - 2015-04-14 19:07 - 00001007 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2015-04-14 19:05 - 2015-04-14 19:05 - 07969808 _____ (TeamViewer GmbH) C:\Users\Nina\Downloads\TeamViewer_Setup_de.exe 2015-04-14 18:34 - 2015-04-14 18:34 - 00010251 _____ () C:\Users\Nina\Downloads\hijackthis.log 2015-04-14 18:32 - 2015-04-14 18:32 - 00388608 _____ (Trend Micro Inc.) C:\Users\Nina\Downloads\hijackthis.exe 2015-04-13 20:50 - 2015-04-13 20:50 - 00000000 ____D () C:\windows\pss 2015-04-13 20:41 - 2015-04-13 20:41 - 01190415 _____ () C:\Users\Nina\Downloads\ProcessExplorer.zip 2015-04-13 20:29 - 2015-04-13 20:29 - 00001728 _____ () C:\Users\Nina\Desktop\AdwCleaner[S0].txt 2015-04-13 20:17 - 2015-04-13 20:24 - 00000000 ____D () C:\AdwCleaner 2015-04-13 20:16 - 2015-04-13 20:16 - 02217984 _____ () C:\Users\Nina\Desktop\AdwCleaner_4.201.exe 2015-04-13 20:15 - 2015-04-13 20:16 - 02217984 _____ () C:\Users\Nina\Downloads\AdwCleaner_4.201.exe 2015-04-13 19:00 - 2015-04-13 19:00 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-04-13 18:59 - 2015-04-13 18:59 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Nina\Downloads\mbam-setup-2.1.4.1018.exe 2015-04-13 18:53 - 2015-04-13 18:53 - 00032058 _____ () C:\ComboFix.txt 2015-04-13 18:38 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe 2015-04-13 18:38 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe 2015-04-13 18:38 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe 2015-04-13 18:38 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe 2015-04-13 18:38 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe 2015-04-13 18:38 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe 2015-04-13 18:38 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe 2015-04-13 18:38 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe 2015-04-13 18:35 - 2015-04-13 18:53 - 00000000 ____D () C:\Qoobox 2015-04-13 18:35 - 2015-04-13 18:49 - 00000000 ____D () C:\windows\erdnt 2015-04-12 17:26 - 2015-04-14 22:10 - 00000560 _____ () C:\windows\setupact.log 2015-04-12 17:26 - 2015-04-14 21:00 - 00003646 _____ () C:\windows\PFRO.log 2015-04-12 17:26 - 2015-04-12 17:26 - 00000000 _____ () C:\windows\setuperr.log 2015-04-12 17:19 - 2015-04-12 17:20 - 00261770 _____ () C:\Users\Nina\Documents\cc_20150412_171949.reg 2015-04-12 17:07 - 2015-04-12 17:07 - 04218880 _____ (Piriform Ltd) C:\Users\Nina\Downloads\ccsetup504_slim.exe 2015-04-12 12:51 - 2015-04-14 20:07 - 00000000 ____D () C:\Users\Nina\AppData\Roaming\vlc 2015-04-12 12:45 - 2015-04-12 12:45 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2015-04-12 12:44 - 2015-04-12 12:44 - 00000000 ____D () C:\Program Files (x86)\VideoLAN 2015-04-12 12:42 - 2015-04-12 12:43 - 28509232 _____ () C:\Users\Nina\Downloads\vlc-2.2.0-win32.exe 2015-04-12 12:42 - 2015-04-12 12:42 - 23003252 _____ () C:\Users\Nina\Downloads\vlc-2.0.8-win32(1).exe 2015-04-12 12:38 - 2015-04-12 12:39 - 23003252 _____ () C:\Users\Nina\Downloads\vlc-2.0.8-win32.exe 2015-04-12 12:33 - 2015-04-14 21:53 - 00000508 _____ () C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 86d158ec-7ced-4148-a5a4-fe3032042980.job 2015-04-12 12:33 - 2015-04-14 18:17 - 00000508 _____ () C:\windows\Tasks\SUPERAntiSpyware Scheduled Task b21ca01a-ff34-493f-9217-990ffdfd1f1e.job 2015-04-12 12:33 - 2015-04-12 12:33 - 00003578 _____ () C:\windows\System32\Tasks\SUPERAntiSpyware Scheduled Task b21ca01a-ff34-493f-9217-990ffdfd1f1e 2015-04-12 12:33 - 2015-04-12 12:33 - 00003504 _____ () C:\windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 86d158ec-7ced-4148-a5a4-fe3032042980 2015-04-11 11:11 - 2015-04-11 11:11 - 00000000 ____D () C:\Users\Nina\AppData\Local\Apple Computer 2015-04-11 09:32 - 2015-04-11 09:32 - 00000000 ___SD () C:\windows\SysWOW64\GWX 2015-04-11 09:32 - 2015-04-11 09:32 - 00000000 ___SD () C:\windows\system32\GWX 2015-04-10 20:04 - 2015-04-10 20:04 - 00000000 ____D () C:\Program Files (x86)\mozilla firefox 2015-03-29 23:18 - 2015-03-29 23:18 - 00000000 ____D () C:\windows\System32\Tasks\Norton Internet Security 2015-03-25 20:11 - 2015-03-11 06:06 - 00943616 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll 2015-03-25 20:11 - 2015-03-11 06:06 - 00760832 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll 2015-03-25 20:11 - 2015-03-11 06:06 - 00677888 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll 2015-03-25 20:11 - 2015-03-11 06:06 - 00414720 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll 2015-03-25 20:11 - 2015-03-11 06:05 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2015-03-25 20:11 - 2015-03-11 06:05 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll 2015-03-25 20:11 - 2015-03-11 06:05 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll 2015-03-25 20:11 - 2015-03-11 06:02 - 01107456 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2015-03-17 23:01 - 2015-03-17 23:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freedome 2015-03-17 22:59 - 2015-03-17 22:59 - 00033832 _____ (The OpenVPN Project) C:\windows\system32\Drivers\tap0901.sys ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-14 22:14 - 2012-07-01 04:20 - 01606486 _____ () C:\windows\WindowsUpdate.log 2015-04-14 22:14 - 2012-06-30 21:53 - 00699342 _____ () C:\windows\system32\perfh007.dat 2015-04-14 22:14 - 2012-06-30 21:53 - 00149450 _____ () C:\windows\system32\perfc007.dat 2015-04-14 22:14 - 2009-07-14 07:13 - 01619284 _____ () C:\windows\system32\PerfStringBackup.INI 2015-04-14 22:10 - 2015-02-20 22:53 - 00001106 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-04-14 22:10 - 2012-06-30 12:25 - 00000828 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2015-04-14 22:10 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2015-04-14 22:06 - 2015-02-20 22:54 - 00001110 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-04-14 21:30 - 2013-05-19 16:58 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2015-04-14 21:29 - 2009-07-14 06:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-14 21:29 - 2009-07-14 06:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-14 21:01 - 2015-02-02 23:08 - 00000000 ____D () C:\windows\Minidump 2015-04-14 20:16 - 2013-05-17 17:07 - 00070368 _____ () C:\Users\Nina\AppData\Local\GDIPFONTCACHEV1.DAT 2015-04-14 20:14 - 2013-05-17 22:43 - 00000000 ____D () C:\Users\Nina 2015-04-14 19:32 - 2009-07-14 06:45 - 00307728 _____ () C:\windows\system32\FNTCACHE.DAT 2015-04-14 19:22 - 2015-02-28 12:02 - 00000000 ____D () C:\ProgramData\F-Secure 2015-04-14 19:22 - 2015-02-28 12:02 - 00000000 ____D () C:\Program Files (x86)\F-Secure 2015-04-14 18:33 - 2013-05-17 22:43 - 00000000 ____D () C:\Users\Nina\AppData\Local\VirtualStore 2015-04-14 18:17 - 2012-06-30 12:25 - 00000830 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2015-04-13 22:59 - 2015-02-20 22:47 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware 2015-04-13 22:27 - 2014-12-28 18:33 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2015-04-13 20:44 - 2013-10-19 12:36 - 00000000 ____D () C:\Program Files (x86)\UBISOFT 2015-04-13 20:44 - 2012-06-30 12:24 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-04-13 20:21 - 2009-07-14 07:08 - 00032588 _____ () C:\windows\Tasks\SCHEDLGU.TXT 2015-04-13 20:09 - 2012-06-30 21:35 - 00000000 ____D () C:\windows\MSetup 2015-04-13 18:53 - 2014-04-23 10:54 - 00000000 ____D () C:\Users\dub_cm_auto 2015-04-13 18:53 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2015-04-13 18:48 - 2009-07-14 04:34 - 00000215 _____ () C:\windows\system.ini 2015-04-12 17:17 - 2013-06-04 20:07 - 00000000 ____D () C:\Users\Nina\AppData\Local\CrashDumps 2015-04-12 17:17 - 2011-02-11 21:57 - 00000000 ____D () C:\windows\Panther 2015-04-12 17:13 - 2015-02-02 20:31 - 00007602 _____ () C:\Users\Nina\AppData\Local\Resmon.ResmonCfg 2015-04-12 12:38 - 2013-05-17 18:58 - 00000000 ____D () C:\Program Files\VideoLAN 2015-04-12 12:33 - 2015-02-20 22:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2015-04-12 00:41 - 2013-07-27 19:04 - 00000000 ____D () C:\Users\Nina\AppData\Local\FreePDF_XP 2015-04-12 00:41 - 2009-07-14 07:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD 2015-04-11 10:26 - 2013-05-17 17:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-03-29 23:13 - 2014-04-01 21:24 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security 2015-03-29 23:13 - 2012-06-30 13:41 - 00003234 _____ () C:\windows\System32\Tasks\Norton WSC Integration 2015-03-29 23:13 - 2012-06-30 13:40 - 00000000 ____D () C:\windows\system32\Drivers\NISx64 2015-03-29 23:09 - 2014-12-10 20:54 - 00000000 ____D () C:\windows\system32\appraiser 2015-03-29 23:09 - 2014-05-13 08:54 - 00000000 ___SD () C:\windows\system32\CompatTel 2015-03-17 22:43 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\SysWOW64\Dism 2015-03-17 22:43 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\Dism 2015-03-15 14:37 - 2013-05-20 19:15 - 00000000 ____D () C:\ProgramData\Microsoft Help ==================== Files in the root of some directories ======= 2014-12-21 16:18 - 2014-12-21 16:18 - 0000000 _____ () C:\Users\Nina\AppData\Roaming\AbsoluteReminder.xml 2015-02-02 20:31 - 2015-04-12 17:13 - 0007602 _____ () C:\Users\Nina\AppData\Local\Resmon.ResmonCfg ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-13 18:03 ==================== End Of Log ============================ --- --- --- Addition: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 13-04-2015 Ran by Nina at 2015-04-14 22:17:27 Running from C:\Users\Nina\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton Internet Security (Disabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66} FW: Norton Internet Security (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) „Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden „Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden „Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden „Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Amazon MP3-Downloader 1.0.18 (HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Easy File Share (HKLM-x32\...\{12F81925-F3C1-40DB-91F7-777817974319}) (Version: 1.2.4 - Samsung Electronics CO., LTD.) Easy Migration (HKLM-x32\...\{EDE7A262-DB20-4432-A630-2ACEE186C416}) (Version: 1.0 - Samsung Electronics CO., LTD.) Easy Settings (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 1.1 - Samsung Electronics CO., LTD.) Easy Software Manager (HKLM-x32\...\{DE256D8B-D971-456D-BC02-CB64DA24F115}) (Version: 1.2.17.12 - Samsung Electronics CO., LTD.) Easy Support Center (HKLM\...\{0738F5F1-8E70-49A6-8692-F5722E1E5A4D}) (Version: 1.2.23 - Samsung Electronics CO., LTD.) ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 14.1.20130301 - Landesfinanzdirektion Thüringen) E-POP (HKLM-x32\...\{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}) (Version: 1.0.1 - Samsung Electronics CO., LTD.) ETDWare PS/2-X64 10.7.13.1_WHQL (HKLM\...\Elantech) (Version: 10.7.13.1 - ELAN Microelectronic Corp.) ExpressCache (HKLM\...\{2EBEFDA8-F905-4C39-AC1C-D5ABE7B3E0AE}) (Version: 1.0.86 - Diskeeper Corporation) Fast Flash Sleep Resume (x32 Version: 1.0.20 - Samsung) Hidden Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden FreeDoko 0.7.11 (HKLM-x32\...\FreeDoko) (Version: 0.7.11 - Borg Enders und Diether Knof) Freedome (HKLM-x32\...\F-Secure Freedome) (Version: 1.0.850.0 - F-Secure Corporation) FreePDF (Remove only) (HKLM-x32\...\FreePDF_XP) (Version: - ) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 41.0.2272.118 - Google Inc.) Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Heroes of Might and Magic IV: Winds of War (HKLM-x32\...\Heroes of Might and Magic IV) (Version: - ) Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.2.1410 - Intel Corporation) Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2618 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\...\{2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C}) (Version: 15.0.0.0059 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{520C4DD4-2BC7-409B-BA48-E1A4F832662D}) (Version: 2.1.0.0140 - Intel Corporation) Intel(R) Rapid Start Technology (HKLM-x32\...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 1.0.0.1021 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.1.209 - Intel Corporation) Intel(R) WiDi (HKLM-x32\...\{93F34C5C-ACAA-48F3-9B26-70359A117F12}) (Version: 3.0.12.0 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel® PROSet/Wireless WiFi Software (HKLM\...\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation) Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Mozilla Firefox 37.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.1 (x86 de)) (Version: 37.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla) Mozilla Thunderbird 31.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.5.0 (x86 de)) (Version: 31.5.0 - Mozilla) Multimedia POP (HKLM-x32\...\{B654E683-93ED-4B4F-BED8-4CE9C0B8D3ED}) (Version: 1.2 - Samsung Electronics CO., LTD.) Norton Internet Security (HKLM-x32\...\NIS) (Version: 21.7.0.11 - Symantec Corporation) Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) Patrician IV Gold (HKLM-x32\...\{CDD92071-5688-493D-9980-540D006B375C}) (Version: 1.0.0.0 - Gaming Minds Studios GmbH) Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.50.1123.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6622 - Realtek Semiconductor Corp.) RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: - ) Samsung Recovery Solution 5 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.2.6 - Samsung Electronics CO., LTD.) Skat 9.0 (HKLM-x32\...\{651CAB7C-9349-487C-BB4E-EEBB4BC67982}) (Version: 9.0.4.45 - Peter Heinlein) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Software Launcher (HKLM-x32\...\{B750B5C2-CC17-4967-905B-29F4EB986131}) (Version: 1.0.2 - Samsung Electronics CO., LTD.) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1170 - SUPERAntiSpyware.com) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.40798 - TeamViewer) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.6 - Samsung Electronics CO., LTD.) VLC media player (HKLM-x32\...\VLC media player) (Version: 2.2.0 - VideoLAN) Windows Live 程式集 (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) WinZip 17.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DD}) (Version: 17.5.10562 - WinZip Computing, S.L. ) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 14-04-2015 19:22:01 Removed F-Secure ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0694B1E5-229B-49F0-9278-910E44DD8557} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe [2012-01-31] (Samsung Electronics) Task: {099BF8B6-7E12-480E-80B3-4D41FC4C21EC} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {0E775827-040E-49A7-B746-87DAC5B1F834} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe [2012-04-03] (Samsung Electronics) Task: {119C10D2-E8AE-40AA-97AE-9242B400F660} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe [2012-05-30] (Samsung Electronics Co., Ltd.) Task: {162DE124-FA0E-409C-9C7E-04D10ECB37E4} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\WSCStub.exe [2015-03-07] (Symantec Corporation) Task: {17B48BD0-EA96-4D07-AE94-D7371372BB6B} - System32\Tasks\SUPERAntiSpyware Scheduled Task 86d158ec-7ced-4148-a5a4-fe3032042980 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {17B5F0B5-5118-4600-B7D8-DA801AA75D01} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {186708A8-F83E-48EE-9C32-AFE07F4C6806} - System32\Tasks\Easy Software Manager Agent => C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe [2012-04-06] (Samsung Electronics CO., LTD.) Task: {322EDC48-F1C2-4C5F-9AF9-158ABE22AE43} - System32\Tasks\Intel® Rapid Start Technology Manager => C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe [2012-02-06] (Intel) Task: {36AE804F-56DD-4AEA-B0BA-618645170FE5} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2012-01-28] (SEC) Task: {440E07DC-43CC-496E-B12F-55EF756EA062} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe [2012-04-25] (Samsung Electronics Co., Ltd.) Task: {44F962C4-1A6E-499D-AE02-C59529D11C4E} - System32\Tasks\EasySupportCenter => C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe [2012-04-19] (Samsung Electronics CO., LTD.) Task: {493F314C-B69D-481E-BE80-2A304F50C071} - System32\Tasks\SUPERAntiSpyware Scheduled Task b21ca01a-ff34-493f-9217-990ffdfd1f1e => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {4F4CA207-F6B5-4682-ACDF-CBEAC7EE1325} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {6AB3F46B-AF18-489A-902D-F197DB0DFCD0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-20] (Google Inc.) Task: {8185FBEA-7825-43ED-A0AD-86F32467089B} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {82E17562-C7D9-498E-A540-A11B74A41223} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-20] (Google Inc.) Task: {8AE2A557-E4C7-4223-A948-5DBC287FDCF9} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {8C59A78E-A3BF-4A4A-99D2-F1A8AD388E43} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation) Task: {907B464B-0B99-457A-B314-B8CFE3C40A6B} - System32\Tasks\{F6B923B9-019D-403F-91BF-B023612EB485} => pcalua.exe -a C:\Users\Nina\AppData\Local\Temp\Temp1_p4-demo-deDE.zip\setup.exe Task: {9272AC0C-23EB-4E22-9390-1BF1D629B6BC} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {9AC751D0-0EEE-451B-84B3-105F4EF8D051} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Easy Settings\EBM\EasyBatteryMgr4.exe [2011-11-18] (SAMSUNG Electronics co., LTD.) Task: {9E6FAB8F-E231-4EB7-AD2D-C4787C668347} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe Task: {C77D8CFB-2771-478C-95FD-E135410FBEE8} - System32\Tasks\FFSRConfigurer => C:\Program Files (x86)\Samsung\Fast Flash Sleep Resume\FFSRConfigurer.exe [2012-03-30] (Samsung) Task: {C8820C70-B05A-4D3E-8AE4-C7B398248FB5} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Easy Settings\SCCSpeedBoot.exe [2012-03-27] (Samsung Electronics Co., Ltd.) Task: {DADCDD57-1A0C-4F21-AA92-F6A8E296EB36} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {DE1D5D99-753B-405D-9A5C-8E0056BABD83} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {EEC1EEAC-66F4-4784-8E63-CA6B8A5BE3F6} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04] (Adobe Systems Incorporated) Task: {FCA25C6C-C152-4065-8F11-D3C72020C215} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe [2012-05-02] (Samsung Electronics Co., Ltd.) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 86d158ec-7ced-4148-a5a4-fe3032042980.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task b21ca01a-ff34-493f-9217-990ffdfd1f1e.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Loaded Modules (whitelisted) ============== 2013-05-27 22:32 - 2010-06-17 20:56 - 00087040 _____ () C:\windows\System32\redmonnt.dll 2012-06-30 12:25 - 2012-02-08 04:03 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 2012-06-30 12:43 - 2012-02-13 08:02 - 00031624 _____ () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe 2012-03-13 04:59 - 2012-01-05 11:24 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00732712 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\libGLESv2.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00049704 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\libEGL.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00882592 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\platforms\qwindows.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00024616 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\imageformats\qsvg.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00019496 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\QtQuick.2\qtquick2plugin.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00733736 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\QtQuick\Controls\qtquickcontrolsplugin.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00019496 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\QtQuick\Window.2\windowplugin.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00061992 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\QtQuick\Layouts\qquicklayoutsplugin.dll 2012-06-30 12:43 - 2011-02-16 18:03 - 00203776 _____ () C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll 2012-06-30 12:43 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll 2012-06-30 12:33 - 2011-09-08 12:40 - 01645056 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll 2012-06-30 12:25 - 2012-02-08 03:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Nina\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: Media is not connected to internet. ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: !SASCORE => 2 MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: AMPPALR3 => 2 MSCONFIG\Services: Bluetooth Device Monitor => 2 MSCONFIG\Services: Bluetooth Media Service => 3 MSCONFIG\Services: Bluetooth OBEX Service => 2 MSCONFIG\Services: bthserv => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: MBAMScheduler => 2 MSCONFIG\Services: MBAMService => 2 MSCONFIG\Services: McComponentHostService => 3 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: WMPNetworkSvc => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup MSCONFIG\startupreg: AmazonMP3DownloaderHelper => C:\Users\Nina\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: BLEServicesCtrl => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe MSCONFIG\startupreg: BTMTrayAgent => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR MSCONFIG\startupreg: ETDCtrl => %ProgramFiles%\Elantech\ETDCtrl.exe MSCONFIG\startupreg: FreePDF Assistant => "C:\Program Files (x86)\FreePDF_XP\fpassist.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Accounts: ============================= Administrator (S-1-5-21-3300620865-1981299825-1167858846-500 - Administrator - Disabled) Gast (S-1-5-21-3300620865-1981299825-1167858846-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3300620865-1981299825-1167858846-1002 - Limited - Enabled) Nina (S-1-5-21-3300620865-1981299825-1167858846-1000 - Administrator - Enabled) => C:\Users\Nina ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/14/2015 10:10:13 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2015 09:01:44 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2015 07:32:31 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2015 10:39:48 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2015 09:39:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2015 09:10:43 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2015 08:28:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2015 08:22:52 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2015 08:10:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2015 07:26:27 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (04/14/2015 10:10:14 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (04/14/2015 09:02:45 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (04/14/2015 09:01:09 PM) (Source: BugCheck) (EventID: 1001) (User: ) Description: 0x00000109 (0xa3a039d8c63d362b, 0xb3b7465f18bb73fd, 0xfffff880009f05c0, 0x0000000000000002)C:\windows\MEMORY.DMP041415-44179-01 Error: (04/14/2015 09:00:59 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 14.04.2015 um 20:59:12 unerwartet heruntergefahren. Error: (04/14/2015 07:38:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows-Fehlerberichterstattungsdienst erreicht. Error: (04/14/2015 07:33:32 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (04/14/2015 06:16:59 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows-Fehlerberichterstattungsdienst erreicht. Error: (04/14/2015 00:03:09 AM) (Source: iaStor) (EventID: 9) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/14/2015 00:03:08 AM) (Source: iaStor) (EventID: 9) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Error: (04/14/2015 00:03:07 AM) (Source: iaStor) (EventID: 9) (User: ) Description: Das Gerät \Device\Ide\iaStor0 hat innerhalb der Fehlerwartezeit nicht geantwortet. Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-2377M CPU @ 1.50GHz Percentage of memory in use: 69% Total physical RAM: 3875.54 MB Available physical RAM: 1187.66 MB Total Pagefile: 7749.27 MB Available Pagefile: 4706.98 MB Total Virtual: 8192 MB Available Virtual: 8191.84 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:443.13 GB) (Free:216.46 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 11B4AA17) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=443.1 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=22.5 GB) - (Type=27) ======================================================== Disk: 1 (Size: 22.4 GB) (Disk ID: 74F02DEA) Partition 1: (Not Active) - (Size=19.4 GB) - (Type=73) Partition 2: (Not Active) - (Size=3 GB) - (Type=84) ==================== End Of Log ============================ |
15.04.2015, 14:13 | #4 |
/// the machine /// TB-Ausbilder | PC extrem langsam, Anwendungen "hängen sich auf", phys. Speicher bei 60% ohne offene Programme Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION S3 clwvd; system32\DRIVERS\clwvd.sys [X] Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
ESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
15.04.2015, 19:22 | #5 |
| PC extrem langsam, Anwendungen "hängen sich auf", phys. Speicher bei 60% ohne offene Programme Hallo Schrauber, vielen Dank schonmal für Ihre Hilfe. Das System kommt mir bereits jetzt viel schneller vor. Nachfolgend die gewünschten Logfiles: 1) Fixlog: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-04-2015 02 Ran by Nina at 2015-04-15 18:04:00 Run:1 Running from C:\Users\Nina\Desktop Loaded Profiles: Nina (Available profiles: Nina) Boot Mode: Normal ============================================== Content of fixlist: ***************** HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Policies\Microsoft\Internet Explorer: Policy restriction <======= ATTENTION S3 clwvd; system32\DRIVERS\clwvd.sys [X] Emptytemp: ***************** "HKLM\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. "HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\SOFTWARE\Policies\Microsoft\Internet Explorer" => Key deleted successfully. clwvd => Service deleted successfully. EmptyTemp: => Removed 152.4 MB temporary data. The system needed a reboot. ==== End of Fixlog 18:04:11 ==== Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # product=EOS # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.7623 # api_version=3.0.2 # EOSSerial=7e81d6c6ce61e64d98859c0325f78495 # engine=23399 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2015-04-15 06:09:11 # local_time=2015-04-15 08:09:11 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode_1='Norton Internet Security' # compatibility_mode=3597 16777213 100 100 380418 191717935 0 0 # compatibility_mode_1='' # compatibility_mode=5893 16776574 100 94 55649700 180751200 0 0 # scanned=191313 # found=5 # cleaned=0 # scan_time=6639 sh=84804915D3F474DFDB365835189E43D4F394E2F2 ft=1 fh=00cce6a385a2a999 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Nina\Downloads\DOSBox - CHIP-Installer.exe" sh=709F1B26473C5C9C08C9A953CC22D303320FE96D ft=1 fh=9bb275e41393891f vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Nina\Downloads\FreeMind - CHIP-Installer.exe" sh=A1F40CED8264EB635EAECB033B05FBA70AE62C01 ft=1 fh=a70331a46f5e8d76 vn="Variante von Win32/DownloadSponsor.C evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Nina\Downloads\VLC media player 64 Bit - CHIP-Installer.exe" sh=B49883F9F0353B15AEE87E3BFA81E3055C3B2363 ft=0 fh=0000000000000000 vn="Variante von Win32/Systweak.L evtl. unerwünschte Anwendung" ac=I fn="C:\Users\Nina\Downloads\wz175-64gev.msi" sh=B49883F9F0353B15AEE87E3BFA81E3055C3B2363 ft=0 fh=0000000000000000 vn="Variante von Win32/Systweak.L evtl. unerwünschte Anwendung" ac=I fn="C:\Windows\Installer\b37728.msi" Code:
ATTFilter Results of screen317's Security Check version 1.00 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Norton Internet Security WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Java 8 Update 25 Java version 32-bit out of Date! Adobe Reader XI Mozilla Firefox (37.0.1) Mozilla Thunderbird (31.5.0) Google Chrome (41.0.2272.101) Google Chrome (41.0.2272.118) ````````Process Check: objlist.exe by Laurent```````` Symantec Norton Online Backup NOBuAgent.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-04-2015 03 Ran by Nina (administrator) on NINA-PC on 15-04-2015 20:18:35 Running from C:\Users\Nina\Desktop Loaded Profiles: Nina (Available profiles: Nina) Platform: Windows 7 Home Premium Service Pack 1 (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 11 (Default browser: IE) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Diskeeper Corporation) C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\FreedomeService.exe (Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation) C:\Windows\SysWOW64\irstrtsv.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\Jhi_service.exe (Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe (TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe (Intel® Corporation) C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Microsoft Corporation) C:\Windows\System32\wlanext.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Intel Corporation) C:\Windows\System32\igfxtray.exe (Intel Corporation) C:\Windows\System32\hkcmd.exe (Intel Corporation) C:\Windows\System32\igfxpers.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe (F-Secure Corporation) C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe (Samsung Electronics CO., LTD.) C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe (Mozilla Corporation) C:\Program Files (x86)\mozilla firefox\firefox.exe (Samsung Electronics) C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe (Intel Corporation) C:\Windows\System32\igfxext.exe (Intel Corporation) C:\Windows\System32\igfxsrvc.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe (Samsung Electronics Co., Ltd.) C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe (Microsoft Corporation) C:\Windows\System32\dllhost.exe (Samsung Electronics CO., LTD.) C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe (Intel(R) Corporation) C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (SEC) C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\nis.exe (Symantec Corporation) C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe (Symantec Corporation) C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\nis.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [12480616 2012-04-24] (Realtek Semiconductor) HKLM-x32\...\Run: [USB3MON] => C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-04] (Intel Corporation) HKLM-x32\...\Run: [Norton Online Backup] => C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuClient.exe [1155928 2010-06-01] (Symantec Corporation) HKLM-x32\...\Run: [FreedomeAutoStart] => C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\Freedome.exe [2396712 2015-03-17] (F-Secure Corporation) Winlogon\Notify\igfxcui: C:\windows\system32\igfxdev.dll (Intel Corporation) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Search Page = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL = www.google.com HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL = www.google.com HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\.DEFAULT\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=msnhome HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ SearchScopes: HKLM-x32 -> {33BB0A4E-99AF-4226-BDF6-49120163DE86} URL = SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = SearchScopes: HKU\S-1-5-21-3300620865-1981299825-1167858846-1000 -> {FC70D870-DB71-49F3-81B9-B961FAFDBD75} URL = https://www.google.com/search?q={searchTerms} BHO: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine64\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation) BHO-x32: Norton Identity Protection -> {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation) BHO-x32: Norton Vulnerability Protection -> {6D53EC84-6AAE-4787-AEEE-F4628F01010C} -> C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\IPS\IPSBHO.DLL [2015-03-05] (Symantec Corporation) BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\ssv.dll [2014-11-16] (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\jp2ssv.dll [2014-11-16] (Oracle Corporation) Toolbar: HKLM - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation) Toolbar: HKLM-x32 - Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\coIEPlg.dll [2015-03-05] (Symantec Corporation) DPF: HKLM-x32 {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://qtinstall.apple.com/qtactivex/qtplugin.cab Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll [2013-02-26] (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\Nina\AppData\Roaming\Mozilla\Firefox\Profiles\8nu6ee6q.default-1424464495624 FF Plugin: @microsoft.com/GENUINE -> disabled No File FF Plugin: @videolan.org/vlc,version=2.0.6 -> C:\Program Files\VideoLAN\VLC\npvlc.dll [2015-02-27] (VideoLAN) FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater -> C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll [2012-01-06] (Intel Corporation) FF Plugin-x32: @java.com/DTPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\dtplugin\npDeployJava1.dll [2014-11-16] (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=11.25.2 -> C:\Program Files (x86)\Java\jre1.8.0_25\bin\plugin2\npjp2.dll [2014-11-16] (Oracle Corporation) FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3538.0513 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll [2011-05-13] (Microsoft Corporation) FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-20] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.26.9\npGoogleUpdate3.dll [2015-02-20] (Google Inc.) FF Plugin HKU\S-1-5-21-3300620865-1981299825-1167858846-1000: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\Nina\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.) FF Extension: Adblock Plus - C:\Users\Nina\AppData\Roaming\Mozilla\Firefox\Profiles\8nu6ee6q.default-1424464495624\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2015-02-28] FF HKLM-x32\...\Firefox\Extensions: [{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}] - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.1.7\coFFPlgn FF Extension: Norton Toolbar - C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.1.7\coFFPlgn [2015-04-15] Chrome: ======= CHR StartupUrls: Default -> "hxxp://www.google.com" CHR Profile: C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default CHR Extension: (Google Slides) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aapocclcgogkmnckokdopfmhonfmgoek [2015-02-20] CHR Extension: (Google Docs) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2015-02-20] CHR Extension: (Google Drive) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2015-02-20] CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2015-02-26] CHR Extension: (YouTube) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2015-02-20] CHR Extension: (Google Search) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2015-02-20] CHR Extension: (Google Sheets) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\felcaaldnbdncclmgdcncolpebgiejap [2015-02-20] CHR Extension: (Google Wallet) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2015-02-20] CHR Extension: (Gmail) - C:\Users\Nina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2015-02-20] CHR HKLM\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx CHR HKLM\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\Exts\Chrome.crx [2015-03-24] CHR HKLM-x32\...\Chrome\Extension: [iikflkcanblccfahdhdonehdalibjnif] - https://clients2.google.com/service/update2/crx CHR HKLM-x32\...\Chrome\Extension: [mkfokfffehpeedafpekjeddnmnjhmcmk] - C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\Exts\Chrome.crx [2015-03-24] ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) S4 !SASCORE; C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE [172344 2014-07-23] (SUPERAntiSpyware.com) R2 ExpressCache; C:\Program Files\Diskeeper Corporation\ExpressCache\ExpressCache.exe [79664 2012-03-30] (Diskeeper Corporation) R2 Freedome Service; C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\FreedomeService.exe [285736 2015-03-17] (F-Secure Corporation) R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [128280 2012-02-08] () R2 irstrtsv; C:\windows\SysWOW64\irstrtsv.exe [193536 2012-02-06] (Intel Corporation) R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-08] (Intel Corporation) S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [273168 2011-12-08] () R2 NIS; C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\NIS.exe [276336 2015-03-07] (Symantec Corporation) R2 NOBU; C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe [2804568 2010-06-01] (Symantec Corporation) R2 SamsungDeviceConfigurationWinService; C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe [31624 2012-02-13] () [File not signed] R2 TeamViewer; C:\Program Files (x86)\TeamViewer\TeamViewer_Service.exe [5448464 2015-03-30] (TeamViewer GmbH) S3 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2013-05-27] (Microsoft Corporation) R2 ZeroConfigService; C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe [594704 2011-12-08] (Intel® Corporation) ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.) U5 AppMgmt; C:\Windows\system32\svchost.exe [27648 2011-03-01] (Microsoft Corporation) S3 AVerAF35; C:\Windows\System32\Drivers\AVerAF35.sys [717952 2010-05-31] (AVerMedia TECHNOLOGIES, Inc.) R3 BHDrvx64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.1.7\Definitions\BASHDefs\20150408.001\BHDrvx64.sys [1639128 2015-04-08] (Symantec Corporation) R3 ccSet_NIS; C:\Windows\system32\drivers\NISx64\1507000.00B\ccSetx64.sys [162392 2013-09-26] (Symantec Corporation) R3 eeCtrl; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys [487216 2014-12-17] (Symantec Corporation) R3 EraserUtilRebootDrv; C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [142640 2014-12-17] (Symantec Corporation) R1 excfs; C:\Windows\System32\DRIVERS\excfs.sys [23344 2012-03-30] (Diskeeper Corporation) R0 excsd; C:\Windows\System32\DRIVERS\excsd.sys [95024 2012-03-30] (Diskeeper Corporation) R3 IDSVia64; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.1.7\Definitions\IPSDefs\20150414.001\IDSvia64.sys [671448 2015-03-29] (Symantec Corporation) R3 irstrtdv; C:\Windows\System32\DRIVERS\irstrtdv.sys [26504 2012-02-07] (Intel Corporation) R3 NAVENG; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.1.7\Definitions\VirusDefs\20150414.041\ENG64.SYS [129752 2015-01-20] (Symantec Corporation) R3 NAVEX15; C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.1.7\Definitions\VirusDefs\20150414.041\EX64.SYS [2137304 2015-01-20] (Symantec Corporation) R1 SASDIFSV; C:\Program Files\SUPERAntiSpyware\SASDIFSV64.SYS [14928 2011-07-22] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R1 SASKUTIL; C:\Program Files\SUPERAntiSpyware\SASKUTIL64.SYS [12368 2011-07-12] (SUPERAdBlocker.com and SUPERAntiSpyware.com) R3 SRTSP; C:\Windows\System32\Drivers\NISx64\1507000.00B\SRTSP64.SYS [876248 2014-08-26] (Symantec Corporation) R3 SRTSPX; C:\Windows\system32\drivers\NISx64\1507000.00B\SRTSPX64.SYS [37592 2014-08-26] (Symantec Corporation) R3 SymDS; C:\Windows\system32\drivers\NISx64\1507000.00B\SYMDS64.SYS [493656 2013-09-10] (Symantec Corporation) R3 SymEFA; C:\Windows\system32\drivers\NISx64\1507000.00B\SYMEFA64.SYS [1148120 2014-03-04] (Symantec Corporation) R3 SymEvent; C:\windows\system32\Drivers\SYMEVENT64x86.SYS [177752 2014-03-20] (Symantec Corporation) R3 SymIRON; C:\Windows\system32\drivers\NISx64\1507000.00B\Ironx64.SYS [266968 2014-08-06] (Symantec Corporation) R3 SymNetS; C:\Windows\System32\Drivers\NISx64\1507000.00B\SYMNETS.SYS [593112 2014-02-18] (Symantec Corporation) S3 MBAMSwissArmy; \??\C:\windows\system32\drivers\MBAMSwissArmy.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.) ==================== One Month Created Files and Folders ======== (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-15 20:18 - 2015-04-15 20:18 - 00017115 _____ () C:\Users\Nina\Desktop\FRST.txt 2015-04-15 20:17 - 2015-04-15 20:17 - 00000908 _____ () C:\Users\Nina\Desktop\security checkup.txt 2015-04-15 18:15 - 2015-04-15 18:15 - 00000000 ____D () C:\Program Files (x86)\ESET 2015-04-15 18:11 - 2015-04-15 18:11 - 00852616 _____ () C:\Users\Nina\Downloads\SecurityCheck.exe 2015-04-15 18:10 - 2015-04-15 18:10 - 02347384 _____ (ESET) C:\Users\Nina\Downloads\esetsmartinstaller_deu.exe 2015-04-15 18:03 - 2015-04-15 20:18 - 02097664 _____ (Farbar) C:\Users\Nina\Desktop\FRST64.exe 2015-04-15 18:03 - 2015-04-15 20:18 - 00000000 ____D () C:\Users\Nina\Desktop\FRST-OlderVersion 2015-04-14 22:50 - 2015-04-14 22:56 - 00000000 ____D () C:\Users\Nina\AppData\Roaming\vlc 2015-04-14 22:49 - 2015-04-14 22:49 - 00000871 _____ () C:\Users\Public\Desktop\VLC media player.lnk 2015-04-14 22:49 - 2015-04-14 22:49 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN 2015-04-14 22:43 - 2015-04-14 22:43 - 01203488 _____ () C:\Users\Nina\Downloads\VLC media player 64 Bit - CHIP-Installer.exe 2015-04-14 22:15 - 2015-04-15 20:18 - 00000000 ____D () C:\FRST 2015-04-14 22:13 - 2015-04-14 22:13 - 02096640 _____ (Farbar) C:\Users\Nina\Downloads\FRST64.exe 2015-04-14 21:01 - 2015-04-14 21:01 - 00282624 _____ () C:\windows\Minidump\041415-44179-01.dmp 2015-04-14 21:00 - 2015-04-14 21:00 - 1691830815 _____ () C:\windows\MEMORY.DMP 2015-04-14 20:37 - 2015-04-14 20:31 - 00380416 _____ () C:\Users\Nina\Desktop\Gmer-19357.exe 2015-04-14 20:30 - 2015-04-14 20:31 - 00380416 _____ () C:\Users\Nina\Downloads\Gmer-19357.exe 2015-04-14 20:14 - 2015-04-14 20:14 - 00000470 _____ () C:\Users\Nina\Downloads\defogger_disable.log 2015-04-14 20:14 - 2015-04-14 20:14 - 00000000 _____ () C:\Users\Nina\defogger_reenable 2015-04-14 20:12 - 2015-04-14 20:12 - 00050477 _____ () C:\Users\Nina\Downloads\Defogger.exe 2015-04-14 19:07 - 2015-04-14 19:17 - 00000000 ____D () C:\Program Files (x86)\TeamViewer 2015-04-14 19:07 - 2015-04-14 19:07 - 00001007 _____ () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 10.lnk 2015-04-14 19:05 - 2015-04-14 19:05 - 07969808 _____ (TeamViewer GmbH) C:\Users\Nina\Downloads\TeamViewer_Setup_de.exe 2015-04-14 18:34 - 2015-04-14 18:34 - 00010251 _____ () C:\Users\Nina\Downloads\hijackthis.log 2015-04-14 18:32 - 2015-04-14 18:32 - 00388608 _____ (Trend Micro Inc.) C:\Users\Nina\Downloads\hijackthis.exe 2015-04-13 20:50 - 2015-04-13 20:50 - 00000000 ____D () C:\windows\pss 2015-04-13 20:41 - 2015-04-13 20:41 - 01190415 _____ () C:\Users\Nina\Downloads\ProcessExplorer.zip 2015-04-13 20:17 - 2015-04-13 20:24 - 00000000 ____D () C:\AdwCleaner 2015-04-13 20:16 - 2015-04-13 20:16 - 02217984 _____ () C:\Users\Nina\Desktop\AdwCleaner_4.201.exe 2015-04-13 20:15 - 2015-04-13 20:16 - 02217984 _____ () C:\Users\Nina\Downloads\AdwCleaner_4.201.exe 2015-04-13 19:00 - 2015-04-13 19:00 - 00000000 ____D () C:\ProgramData\Malwarebytes 2015-04-13 18:59 - 2015-04-13 18:59 - 21540440 _____ (Malwarebytes Corporation ) C:\Users\Nina\Downloads\mbam-setup-2.1.4.1018.exe 2015-04-13 18:53 - 2015-04-13 18:53 - 00032058 _____ () C:\ComboFix.txt 2015-04-13 18:38 - 2011-06-26 08:45 - 00256000 _____ () C:\windows\PEV.exe 2015-04-13 18:38 - 2010-11-07 19:20 - 00208896 _____ () C:\windows\MBR.exe 2015-04-13 18:38 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\windows\NIRCMD.exe 2015-04-13 18:38 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\windows\SWREG.exe 2015-04-13 18:38 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\windows\SWSC.exe 2015-04-13 18:38 - 2000-08-31 02:00 - 00098816 _____ () C:\windows\sed.exe 2015-04-13 18:38 - 2000-08-31 02:00 - 00080412 _____ () C:\windows\grep.exe 2015-04-13 18:38 - 2000-08-31 02:00 - 00068096 _____ () C:\windows\zip.exe 2015-04-13 18:35 - 2015-04-13 18:53 - 00000000 ____D () C:\Qoobox 2015-04-13 18:35 - 2015-04-13 18:49 - 00000000 ____D () C:\windows\erdnt 2015-04-12 17:26 - 2015-04-15 18:06 - 00000672 _____ () C:\windows\setupact.log 2015-04-12 17:26 - 2015-04-14 21:00 - 00003646 _____ () C:\windows\PFRO.log 2015-04-12 17:26 - 2015-04-12 17:26 - 00000000 _____ () C:\windows\setuperr.log 2015-04-12 17:19 - 2015-04-12 17:20 - 00261770 _____ () C:\Users\Nina\Documents\cc_20150412_171949.reg 2015-04-12 17:07 - 2015-04-12 17:07 - 04218880 _____ (Piriform Ltd) C:\Users\Nina\Downloads\ccsetup504_slim.exe 2015-04-12 12:44 - 2015-04-14 22:42 - 00000000 ____D () C:\Program Files (x86)\VideoLAN 2015-04-12 12:42 - 2015-04-12 12:43 - 28509232 _____ () C:\Users\Nina\Downloads\vlc-2.2.0-win32.exe 2015-04-12 12:42 - 2015-04-12 12:42 - 23003252 _____ () C:\Users\Nina\Downloads\vlc-2.0.8-win32(1).exe 2015-04-12 12:38 - 2015-04-12 12:39 - 23003252 _____ () C:\Users\Nina\Downloads\vlc-2.0.8-win32.exe 2015-04-12 12:33 - 2015-04-14 21:53 - 00000508 _____ () C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 86d158ec-7ced-4148-a5a4-fe3032042980.job 2015-04-12 12:33 - 2015-04-14 18:17 - 00000508 _____ () C:\windows\Tasks\SUPERAntiSpyware Scheduled Task b21ca01a-ff34-493f-9217-990ffdfd1f1e.job 2015-04-12 12:33 - 2015-04-12 12:33 - 00003578 _____ () C:\windows\System32\Tasks\SUPERAntiSpyware Scheduled Task b21ca01a-ff34-493f-9217-990ffdfd1f1e 2015-04-12 12:33 - 2015-04-12 12:33 - 00003504 _____ () C:\windows\System32\Tasks\SUPERAntiSpyware Scheduled Task 86d158ec-7ced-4148-a5a4-fe3032042980 2015-04-11 11:11 - 2015-04-11 11:11 - 00000000 ____D () C:\Users\Nina\AppData\Local\Apple Computer 2015-04-11 09:32 - 2015-04-11 09:32 - 00000000 ___SD () C:\windows\SysWOW64\GWX 2015-04-11 09:32 - 2015-04-11 09:32 - 00000000 ___SD () C:\windows\system32\GWX 2015-04-10 20:04 - 2015-04-10 20:04 - 00000000 ____D () C:\Program Files (x86)\mozilla firefox 2015-03-29 23:18 - 2015-03-29 23:18 - 00000000 ____D () C:\windows\System32\Tasks\Norton Internet Security 2015-03-25 20:11 - 2015-03-11 06:06 - 00943616 _____ (Microsoft Corporation) C:\windows\system32\appraiser.dll 2015-03-25 20:11 - 2015-03-11 06:06 - 00760832 _____ (Microsoft Corporation) C:\windows\system32\invagent.dll 2015-03-25 20:11 - 2015-03-11 06:06 - 00677888 _____ (Microsoft Corporation) C:\windows\system32\generaltel.dll 2015-03-25 20:11 - 2015-03-11 06:06 - 00414720 _____ (Microsoft Corporation) C:\windows\system32\devinv.dll 2015-03-25 20:11 - 2015-03-11 06:05 - 00227328 _____ (Microsoft Corporation) C:\windows\system32\aepdu.dll 2015-03-25 20:11 - 2015-03-11 06:05 - 00192000 _____ (Microsoft Corporation) C:\windows\system32\aepic.dll 2015-03-25 20:11 - 2015-03-11 06:05 - 00030720 _____ (Microsoft Corporation) C:\windows\system32\acmigration.dll 2015-03-25 20:11 - 2015-03-11 06:02 - 01107456 _____ (Microsoft Corporation) C:\windows\system32\aeinv.dll 2015-03-17 23:01 - 2015-03-17 23:01 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Freedome 2015-03-17 22:59 - 2015-03-17 22:59 - 00033832 _____ (The OpenVPN Project) C:\windows\system32\Drivers\tap0901.sys ==================== One Month Modified Files and Folders ======= (If an entry is included in the fixlist, the file\folder will be moved.) 2015-04-15 20:06 - 2015-02-20 22:54 - 00001110 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-04-15 19:30 - 2013-05-19 16:58 - 00000884 _____ () C:\windows\Tasks\Adobe Flash Player Updater.job 2015-04-15 19:19 - 2012-07-01 04:20 - 01828541 _____ () C:\windows\WindowsUpdate.log 2015-04-15 18:16 - 2012-06-30 21:53 - 00699342 _____ () C:\windows\system32\perfh007.dat 2015-04-15 18:16 - 2012-06-30 21:53 - 00149450 _____ () C:\windows\system32\perfc007.dat 2015-04-15 18:16 - 2009-07-14 07:13 - 01619284 _____ () C:\windows\system32\PerfStringBackup.INI 2015-04-15 18:13 - 2009-07-14 06:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-04-15 18:13 - 2009-07-14 06:45 - 00028848 ____H () C:\windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-04-15 18:06 - 2015-02-20 22:53 - 00001106 _____ () C:\windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-04-15 18:06 - 2012-06-30 12:25 - 00000828 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job 2015-04-15 18:06 - 2009-07-14 07:08 - 00000006 ____H () C:\windows\Tasks\SA.DAT 2015-04-14 22:48 - 2013-05-17 18:58 - 00000000 ____D () C:\Program Files\VideoLAN 2015-04-14 21:01 - 2015-02-02 23:08 - 00000000 ____D () C:\windows\Minidump 2015-04-14 20:16 - 2013-05-17 17:07 - 00070368 _____ () C:\Users\Nina\AppData\Local\GDIPFONTCACHEV1.DAT 2015-04-14 20:14 - 2013-05-17 22:43 - 00000000 ____D () C:\Users\Nina 2015-04-14 19:32 - 2009-07-14 06:45 - 00307728 _____ () C:\windows\system32\FNTCACHE.DAT 2015-04-14 19:22 - 2015-02-28 12:02 - 00000000 ____D () C:\ProgramData\F-Secure 2015-04-14 19:22 - 2015-02-28 12:02 - 00000000 ____D () C:\Program Files (x86)\F-Secure 2015-04-14 18:33 - 2013-05-17 22:43 - 00000000 ____D () C:\Users\Nina\AppData\Local\VirtualStore 2015-04-14 18:17 - 2012-06-30 12:25 - 00000830 _____ () C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job 2015-04-13 22:59 - 2015-02-20 22:47 - 00000000 ____D () C:\Program Files\SUPERAntiSpyware 2015-04-13 22:27 - 2014-12-28 18:33 - 00000000 ____D () C:\Program Files (x86)\QuickTime 2015-04-13 20:44 - 2013-10-19 12:36 - 00000000 ____D () C:\Program Files (x86)\UBISOFT 2015-04-13 20:44 - 2012-06-30 12:24 - 00000000 ___HD () C:\Program Files (x86)\InstallShield Installation Information 2015-04-13 20:21 - 2009-07-14 07:08 - 00032588 _____ () C:\windows\Tasks\SCHEDLGU.TXT 2015-04-13 20:09 - 2012-06-30 21:35 - 00000000 ____D () C:\windows\MSetup 2015-04-13 18:53 - 2014-04-23 10:54 - 00000000 ____D () C:\Users\dub_cm_auto 2015-04-13 18:53 - 2009-07-14 05:20 - 00000000 __RHD () C:\Users\Default 2015-04-13 18:48 - 2009-07-14 04:34 - 00000215 _____ () C:\windows\system.ini 2015-04-12 17:17 - 2013-06-04 20:07 - 00000000 ____D () C:\Users\Nina\AppData\Local\CrashDumps 2015-04-12 17:17 - 2011-02-11 21:57 - 00000000 ____D () C:\windows\Panther 2015-04-12 17:13 - 2015-02-02 20:31 - 00007602 _____ () C:\Users\Nina\AppData\Local\Resmon.ResmonCfg 2015-04-12 12:33 - 2015-02-20 22:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware 2015-04-12 00:41 - 2013-07-27 19:04 - 00000000 ____D () C:\Users\Nina\AppData\Local\FreePDF_XP 2015-04-12 00:41 - 2009-07-14 07:09 - 00000000 ____D () C:\windows\System32\Tasks\WPD 2015-04-11 10:26 - 2013-05-17 17:01 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service 2015-03-29 23:13 - 2014-04-01 21:24 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Internet Security 2015-03-29 23:13 - 2012-06-30 13:41 - 00003234 _____ () C:\windows\System32\Tasks\Norton WSC Integration 2015-03-29 23:13 - 2012-06-30 13:40 - 00000000 ____D () C:\windows\system32\Drivers\NISx64 2015-03-29 23:09 - 2014-12-10 20:54 - 00000000 ____D () C:\windows\system32\appraiser 2015-03-29 23:09 - 2014-05-13 08:54 - 00000000 ___SD () C:\windows\system32\CompatTel 2015-03-17 22:43 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\SysWOW64\Dism 2015-03-17 22:43 - 2009-07-14 05:20 - 00000000 ____D () C:\windows\system32\Dism ==================== Files in the root of some directories ======= 2014-12-21 16:18 - 2014-12-21 16:18 - 0000000 _____ () C:\Users\Nina\AppData\Roaming\AbsoluteReminder.xml 2015-02-02 20:31 - 2015-04-12 17:13 - 0007602 _____ () C:\Users\Nina\AppData\Local\Resmon.ResmonCfg ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-04-13 18:03 ==================== End Of Log ============================ --- --- --- 5) Addition log: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-04-2015 03 Ran by Nina at 2015-04-15 20:19:26 Running from C:\Users\Nina\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== (If an entry is included in the fixlist, it will be removed.) AV: Norton Internet Security (Enabled - Up to date) {53C7D717-52E2-B95E-FA61-6F32ECC805DB} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Norton Internet Security (Enabled - Up to date) {E8A636F3-74D8-B6D0-C0D1-5440974F4F66} FW: Norton Internet Security (Enabled) {6BFC5632-188D-B806-D13E-C607121B42A0} ==================== Installed Programs ====================== (Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.) „Windows Live Essentials“ (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden „Windows Live Mail“ (x32 Version: 15.4.3502.0922 - „Microsoft Corporation“) Hidden „Windows Live Messenger“ (x32 Version: 15.4.3538.0513 - „Microsoft Corporation“) Hidden „Windows Live“ fotogalerija (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Adobe Flash Player 16 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 16.0.0.305 - Adobe Systems Incorporated) Adobe Reader XI (11.0.10) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.10 - Adobe Systems Incorporated) Amazon MP3-Downloader 1.0.18 (HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\...\Amazon MP3-Downloader) (Version: 1.0.18 - Amazon Services LLC) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Easy File Share (HKLM-x32\...\{12F81925-F3C1-40DB-91F7-777817974319}) (Version: 1.2.4 - Samsung Electronics CO., LTD.) Easy Migration (HKLM-x32\...\{EDE7A262-DB20-4432-A630-2ACEE186C416}) (Version: 1.0 - Samsung Electronics CO., LTD.) Easy Settings (HKLM-x32\...\{17283B95-21A8-4996-97DA-547A48DB266F}) (Version: 1.1 - Samsung Electronics CO., LTD.) Easy Software Manager (HKLM-x32\...\{DE256D8B-D971-456D-BC02-CB64DA24F115}) (Version: 1.2.17.12 - Samsung Electronics CO., LTD.) Easy Support Center (HKLM\...\{0738F5F1-8E70-49A6-8692-F5722E1E5A4D}) (Version: 1.2.23 - Samsung Electronics CO., LTD.) ElsterFormular (HKLM-x32\...\ElsterFormular) (Version: 14.1.20130301 - Landesfinanzdirektion Thüringen) E-POP (HKLM-x32\...\{F06DD8D9-9DC8-430C-835C-C9BF21E05CC1}) (Version: 1.0.1 - Samsung Electronics CO., LTD.) ETDWare PS/2-X64 10.7.13.1_WHQL (HKLM\...\Elantech) (Version: 10.7.13.1 - ELAN Microelectronic Corp.) ExpressCache (HKLM\...\{2EBEFDA8-F905-4C39-AC1C-D5ABE7B3E0AE}) (Version: 1.0.86 - Diskeeper Corporation) Fast Flash Sleep Resume (x32 Version: 1.0.20 - Samsung) Hidden Fotogalerija Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden FreeDoko 0.7.11 (HKLM-x32\...\FreeDoko) (Version: 0.7.11 - Borg Enders und Diether Knof) Freedome (HKLM-x32\...\F-Secure Freedome) (Version: 1.0.850.0 - F-Secure Corporation) FreePDF (Remove only) (HKLM-x32\...\FreePDF_XP) (Version: - ) Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Galerie foto Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Google Chrome (HKLM-x32\...\Google Chrome) (Version: 41.0.2272.118 - Google Inc.) Google Update Helper (x32 Version: 1.3.21.169 - Google Inc.) Hidden Google Update Helper (x32 Version: 1.3.26.9 - Google Inc.) Hidden Heroes of Might and Magic IV: Winds of War (HKLM-x32\...\Heroes of Might and Magic IV) (Version: - ) Intel(R) Manageability Engine Firmware Recovery Agent (HKLM-x32\...\{A6C48A9F-694A-4234-B3AA-62590B668927}) (Version: 1.0.0.35342 - Intel Corporation) Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 8.0.2.1410 - Intel Corporation) Intel(R) OpenCL CPU Runtime (HKLM-x32\...\{FCB3772C-B7D0-4933-B1A9-3707EBACC573}) (Version: - Intel Corporation) Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 8.15.10.2618 - Intel Corporation) Intel(R) PROSet/Wireless for Bluetooth(R) 3.0 + High Speed (HKLM\...\{2C0E6BD4-65B1-4E82-B2AC-43EFFC8F100C}) (Version: 15.0.0.0059 - Intel Corporation) Intel(R) PROSet/Wireless Software for Bluetooth(R) Technology (HKLM\...\{520C4DD4-2BC7-409B-BA48-E1A4F832662D}) (Version: 2.1.0.0140 - Intel Corporation) Intel(R) Rapid Start Technology (HKLM-x32\...\3D073343-CEEB-4ce7-85AC-A69A7631B5D6) (Version: 1.0.0.1021 - Intel Corporation) Intel(R) Rapid Storage Technology (HKLM-x32\...\{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}) (Version: 11.0.0.1032 - Intel Corporation) Intel(R) USB 3.0 eXtensible Host Controller Driver (HKLM-x32\...\{240C3DDD-C5E9-4029-9DF7-95650D040CF2}) (Version: 1.0.1.209 - Intel Corporation) Intel(R) WiDi (HKLM-x32\...\{93F34C5C-ACAA-48F3-9B26-70359A117F12}) (Version: 3.0.12.0 - Intel Corporation) Intel(R) Wireless Display (HKLM\...\{28EF7372-9087-4AC3-9B9F-D9751FCDF830}) (Version: - ) Intel® PROSet/Wireless WiFi Software (HKLM\...\{DF7756DD-656A-45C3-BA71-74673E8259A9}) (Version: 15.00.0000.0642 - Intel Corporation) Intel® Trusted Connect Service Client (HKLM\...\{09536BA1-E498-4CC3-B834-D884A67D7E34}) (Version: 1.23.605.1 - Intel Corporation) Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation) Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation) Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation) Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version: - Microsoft) Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (HKLM\...\{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (HKLM-x32\...\{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation) Mozilla Firefox 37.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 37.0.1 (x86 de)) (Version: 37.0.1 - Mozilla) Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 35.0.1 - Mozilla) Mozilla Thunderbird 31.5.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.5.0 (x86 de)) (Version: 31.5.0 - Mozilla) Multimedia POP (HKLM-x32\...\{B654E683-93ED-4B4F-BED8-4CE9C0B8D3ED}) (Version: 1.2 - Samsung Electronics CO., LTD.) Norton Internet Security (HKLM-x32\...\NIS) (Version: 21.7.0.11 - Symantec Corporation) Norton Online Backup (HKLM-x32\...\{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}) (Version: 2.1.17869 - Symantec Corporation) Patrician IV Gold (HKLM-x32\...\{CDD92071-5688-493D-9980-540D006B375C}) (Version: 1.0.0.0 - Gaming Minds Studios GmbH) Poczta usługi Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Pošta Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: 7.50.1123.2011 - Realtek) Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.6622 - Realtek Semiconductor Corp.) RedMon - Redirection Port Monitor (HKLM\...\Redirection Port Monitor) (Version: - ) Samsung Recovery Solution 5 (HKLM-x32\...\{145DE957-0679-4A2A-BB5C-1D3E9808FAB2}) (Version: 5.0.2.6 - Samsung Electronics CO., LTD.) Skat 9.0 (HKLM-x32\...\{651CAB7C-9349-487C-BB4E-EEBB4BC67982}) (Version: 9.0.4.45 - Peter Heinlein) Skype™ 6.11 (HKLM-x32\...\{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}) (Version: 6.11.102 - Skype Technologies S.A.) Software Launcher (HKLM-x32\...\{B750B5C2-CC17-4967-905B-29F4EB986131}) (Version: 1.0.2 - Samsung Electronics CO., LTD.) SUPERAntiSpyware (HKLM\...\{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}) (Version: 6.0.1170 - SUPERAntiSpyware.com) TeamViewer 10 (HKLM-x32\...\TeamViewer) (Version: 10.0.40798 - TeamViewer) Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{BEC163EC-7A83-48A1-BFB6-3BF47CC2F8CF}) (Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{EA160DA3-E9B5-4D03-A518-21D306665B96}) (Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{38472199-D7B6-4833-A949-10E4EE6365A1}) (Version: - Microsoft) User Guide (HKLM-x32\...\{BAE68339-B0F6-4D33-9554-5A3DB2DFF5DA}) (Version: 1.6 - Samsung Electronics CO., LTD.) VLC media player (HKLM\...\VLC media player) (Version: 2.2.0 - VideoLAN) Windows Live 程式集 (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3538.0513 - Microsoft Corporation) WinRAR 5.01 (64-Bit) (HKLM\...\WinRAR archiver) (Version: 5.01.0 - win.rar GmbH) WinZip 17.5 (HKLM\...\{CD95F661-A5C4-44F5-A6AA-ECDD91C240DD}) (Version: 17.5.10562 - WinZip Computing, S.L. ) Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden ==================== Custom CLSID (selected items): ========================== (If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.) ==================== Restore Points ========================= 14-04-2015 19:22:01 Removed F-Secure ==================== Hosts content: ========================== (If needed Hosts: directive could be included in the fixlist to reset Hosts.) 2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____N C:\windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= (If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.) Task: {0694B1E5-229B-49F0-9278-910E44DD8557} - System32\Tasks\EasySpeedUpManager => C:\Program Files (x86)\Samsung\Easy Settings\EasySpeedUpManager.exe [2012-01-31] (Samsung Electronics) Task: {099BF8B6-7E12-480E-80B3-4D41FC4C21EC} - System32\Tasks\Norton Internet Security\Norton Error Analyzer => C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {0E775827-040E-49A7-B746-87DAC5B1F834} - System32\Tasks\WLANStartup => C:\Program Files (x86)\Samsung\Easy Settings\WLANStartup.exe [2012-04-03] (Samsung Electronics) Task: {119C10D2-E8AE-40AA-97AE-9242B400F660} - System32\Tasks\EasyDisplayMgr => C:\Program Files (x86)\Samsung\Easy Settings\dmhkcore.exe [2012-05-30] (Samsung Electronics Co., Ltd.) Task: {162DE124-FA0E-409C-9C7E-04D10ECB37E4} - System32\Tasks\Norton WSC Integration => C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\WSCStub.exe [2015-03-07] (Symantec Corporation) Task: {17B48BD0-EA96-4D07-AE94-D7371372BB6B} - System32\Tasks\SUPERAntiSpyware Scheduled Task 86d158ec-7ced-4148-a5a4-fe3032042980 => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {17B5F0B5-5118-4600-B7D8-DA801AA75D01} - System32\Tasks\Adobe Acrobat Update Task => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [2014-12-19] (Adobe Systems Incorporated) Task: {186708A8-F83E-48EE-9C32-AFE07F4C6806} - System32\Tasks\Easy Software Manager Agent => C:\Program Files (x86)\Samsung\Easy Software Manager\SWMAgent.exe [2012-04-06] (Samsung Electronics CO., LTD.) Task: {322EDC48-F1C2-4C5F-9AF9-158ABE22AE43} - System32\Tasks\Intel® Rapid Start Technology Manager => C:\Program Files (x86)\Intel\irstrt\RapidStartConfig.exe [2012-02-06] (Intel) Task: {36AE804F-56DD-4AEA-B0BA-618645170FE5} - System32\Tasks\advSRS5 => C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\WCScheduler.exe [2012-01-28] (SEC) Task: {440E07DC-43CC-496E-B12F-55EF756EA062} - System32\Tasks\MovieColorEnhancer => C:\Program Files (x86)\Samsung\Easy Settings\MovieColorEnhancer.exe [2012-04-25] (Samsung Electronics Co., Ltd.) Task: {44F962C4-1A6E-499D-AE02-C59529D11C4E} - System32\Tasks\EasySupportCenter => C:\Program Files\Samsung\Easy Support Center\SamoyedAgent.exe [2012-04-19] (Samsung Electronics CO., LTD.) Task: {493F314C-B69D-481E-BE80-2A304F50C071} - System32\Tasks\SUPERAntiSpyware Scheduled Task b21ca01a-ff34-493f-9217-990ffdfd1f1e => C:\Program Files\SUPERAntiSpyware\SASTask.exe [2013-11-07] (SUPERAdBlocker.com) Task: {4F4CA207-F6B5-4682-ACDF-CBEAC7EE1325} - System32\Tasks\Norton Internet Security\Norton Error Processor => C:\Program Files (x86)\Norton Internet Security\Engine\21.7.0.11\SymErr.exe [2014-01-30] (Symantec Corporation) Task: {6AB3F46B-AF18-489A-902D-F197DB0DFCD0} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-20] (Google Inc.) Task: {8185FBEA-7825-43ED-A0AD-86F32467089B} - System32\Tasks\Microsoft\Windows\Setup\gwx\runappraiser => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {82E17562-C7D9-498E-A540-A11B74A41223} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2015-02-20] (Google Inc.) Task: {8AE2A557-E4C7-4223-A948-5DBC287FDCF9} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxconfig => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {8C59A78E-A3BF-4A4A-99D2-F1A8AD388E43} - System32\Tasks\Microsoft\Windows\Setup\gwx\launchtrayprocess => C:\Windows\system32\GWX\GWX.exe [2015-03-25] (Microsoft Corporation) Task: {907B464B-0B99-457A-B314-B8CFE3C40A6B} - System32\Tasks\{F6B923B9-019D-403F-91BF-B023612EB485} => pcalua.exe -a C:\Users\Nina\AppData\Local\Temp\Temp1_p4-demo-deDE.zip\setup.exe Task: {9272AC0C-23EB-4E22-9390-1BF1D629B6BC} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {9AC751D0-0EEE-451B-84B3-105F4EF8D051} - System32\Tasks\EasyBatteryManager => C:\Program Files (x86)\Samsung\Easy Settings\EBM\EasyBatteryMgr4.exe [2011-11-18] (SAMSUNG Electronics co., LTD.) Task: {9E6FAB8F-E231-4EB7-AD2D-C4787C668347} - System32\Tasks\Abelssoft\Updater scan => C:\Program Files (x86)\CHIP Updater\CHIPUpdater.exe Task: {C77D8CFB-2771-478C-95FD-E135410FBEE8} - System32\Tasks\FFSRConfigurer => C:\Program Files (x86)\Samsung\Fast Flash Sleep Resume\FFSRConfigurer.exe [2012-03-30] (Samsung) Task: {C8820C70-B05A-4D3E-8AE4-C7B398248FB5} - System32\Tasks\SCCSpeedBoot => C:\Program Files (x86)\Samsung\Easy Settings\SCCSpeedBoot.exe [2012-03-27] (Samsung Electronics Co., Ltd.) Task: {DADCDD57-1A0C-4F21-AA92-F6A8E296EB36} - System32\Tasks\Microsoft\Windows\Setup\gwx\refreshgwxcontent => C:\Windows\system32\GWX\GWXConfigManager.exe [2015-03-25] (Microsoft Corporation) Task: {DE1D5D99-753B-405D-9A5C-8E0056BABD83} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {EEC1EEAC-66F4-4784-8E63-CA6B8A5BE3F6} - System32\Tasks\Adobe Flash Player Updater => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2015-02-04] (Adobe Systems Incorporated) Task: {FCA25C6C-C152-4065-8F11-D3C72020C215} - System32\Tasks\SmartSetting => C:\Program Files (x86)\Samsung\Easy Settings\SmartSetting.exe [2012-05-02] (Samsung Electronics Co., Ltd.) Task: C:\windows\Tasks\Adobe Flash Player Updater.job => C:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task 86d158ec-7ced-4148-a5a4-fe3032042980.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe Task: C:\windows\Tasks\SUPERAntiSpyware Scheduled Task b21ca01a-ff34-493f-9217-990ffdfd1f1e.job => C:\Program Files\SUPERAntiSpyware\SASTask.exedC:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Loaded Modules (whitelisted) ============== 2013-05-27 22:32 - 2010-06-17 20:56 - 00087040 _____ () C:\windows\System32\redmonnt.dll 2012-06-30 12:25 - 2012-02-08 04:03 - 00128280 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe 2012-06-30 12:43 - 2012-02-13 08:02 - 00031624 _____ () C:\Program Files (x86)\Samsung\Easy Settings\SamsungDeviceConfiguration.exe 2012-03-13 04:59 - 2012-01-05 11:24 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00732712 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\libGLESv2.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00049704 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\libEGL.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00882592 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\platforms\qwindows.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00024616 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\imageformats\qsvg.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00019496 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\QtQuick.2\qtquick2plugin.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00733736 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\QtQuick\Controls\qtquickcontrolsplugin.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00019496 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\QtQuick\Window.2\windowplugin.dll 2015-03-17 22:59 - 2015-03-17 22:59 - 00061992 _____ () C:\Program Files (x86)\F-Secure\Freedome\Freedome\1.1\QtQuick\Layouts\qquicklayoutsplugin.dll 2012-06-30 12:43 - 2011-02-16 18:03 - 00203776 _____ () C:\Program Files (x86)\Samsung\Easy Settings\WinCRT.dll 2012-06-30 12:43 - 2006-08-12 05:48 - 00049152 _____ () C:\Program Files (x86)\Samsung\Easy Settings\HookDllPS2.dll 2012-06-30 12:33 - 2011-09-08 12:40 - 01645056 _____ () C:\Program Files (x86)\Samsung\Samsung Recovery Solution 5\Resdll.dll 2012-06-30 12:25 - 2012-02-08 03:39 - 01198872 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\ACE.dll ==================== Alternate Data Streams (whitelisted) ========= (If an entry is included in the fixlist, only the Alternate Data Streams will be removed.) ==================== Safe Mode (whitelisted) =================== (If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.) ==================== EXE Association (whitelisted) =============== (If an entry is included in the fixlist, the default will be restored. None default entries will be removed.) ==================== Other Areas ============================ (Currently there is no automatic fix for this section.) HKU\S-1-5-21-3300620865-1981299825-1167858846-1000\Control Panel\Desktop\\Wallpaper -> C:\Users\Nina\AppData\Roaming\Microsoft\Windows\Themes\TranscodedWallpaper.jpg DNS Servers: 192.168.1.1 ==================== MSCONFIG/TASK MANAGER disabled items == (Currently there is no automatic fix for this section.) MSCONFIG\Services: !SASCORE => 2 MSCONFIG\Services: AdobeARMservice => 2 MSCONFIG\Services: AdobeFlashPlayerUpdateSvc => 3 MSCONFIG\Services: AMPPALR3 => 2 MSCONFIG\Services: Bluetooth Device Monitor => 2 MSCONFIG\Services: Bluetooth Media Service => 3 MSCONFIG\Services: Bluetooth OBEX Service => 2 MSCONFIG\Services: bthserv => 3 MSCONFIG\Services: gupdate => 2 MSCONFIG\Services: gupdatem => 3 MSCONFIG\Services: MBAMScheduler => 2 MSCONFIG\Services: MBAMService => 2 MSCONFIG\Services: McComponentHostService => 3 MSCONFIG\Services: MozillaMaintenance => 3 MSCONFIG\Services: WMPNetworkSvc => 2 MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^McAfee Security Scan Plus.lnk => C:\windows\pss\McAfee Security Scan Plus.lnk.CommonStartup MSCONFIG\startupreg: AmazonMP3DownloaderHelper => C:\Users\Nina\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" MSCONFIG\startupreg: BLEServicesCtrl => C:\Program Files (x86)\Intel\Bluetooth\BleServicesCtrl.exe MSCONFIG\startupreg: BTMTrayAgent => rundll32.exe "C:\Program Files (x86)\Intel\Bluetooth\btmshell.dll",TrayApp MSCONFIG\startupreg: CCleaner Monitoring => "C:\Program Files\CCleaner\CCleaner64.exe" /MONITOR MSCONFIG\startupreg: ETDCtrl => %ProgramFiles%\Elantech\ETDCtrl.exe MSCONFIG\startupreg: FreePDF Assistant => "C:\Program Files (x86)\FreePDF_XP\fpassist.exe" MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" MSCONFIG\startupreg: SUPERAntiSpyware => C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe ==================== Accounts: ============================= Administrator (S-1-5-21-3300620865-1981299825-1167858846-500 - Administrator - Disabled) Gast (S-1-5-21-3300620865-1981299825-1167858846-501 - Limited - Disabled) HomeGroupUser$ (S-1-5-21-3300620865-1981299825-1167858846-1002 - Limited - Enabled) Nina (S-1-5-21-3300620865-1981299825-1167858846-1000 - Administrator - Enabled) => C:\Users\Nina ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (04/15/2015 08:10:09 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/15/2015 06:14:59 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/15/2015 06:14:34 PM) (Source: SideBySide) (EventID: 80) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (04/15/2015 06:06:13 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/15/2015 05:56:41 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2015 10:10:13 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2015 09:01:44 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/14/2015 07:32:31 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2015 10:39:48 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (04/13/2015 09:39:03 PM) (Source: WinMgmt) (EventID: 10) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (04/15/2015 06:06:14 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (04/15/2015 05:59:16 PM) (Source: Service Control Manager) (EventID: 7000) (User: ) Description: Der Dienst "Intel(R) Management and Security Application Local Management Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (04/15/2015 05:59:16 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Intel(R) Management and Security Application Local Management Service erreicht. Error: (04/15/2015 05:56:41 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (04/14/2015 10:10:14 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (04/14/2015 09:02:45 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Error: (04/14/2015 09:01:09 PM) (Source: BugCheck) (EventID: 1001) (User: ) Description: 0x00000109 (0xa3a039d8c63d362b, 0xb3b7465f18bb73fd, 0xfffff880009f05c0, 0x0000000000000002)C:\windows\MEMORY.DMP041415-44179-01 Error: (04/14/2015 09:00:59 PM) (Source: EventLog) (EventID: 6008) (User: ) Description: Das System wurde zuvor am 14.04.2015 um 20:59:12 unerwartet heruntergefahren. Error: (04/14/2015 07:38:46 PM) (Source: Service Control Manager) (EventID: 7009) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Windows-Fehlerberichterstattungsdienst erreicht. Error: (04/14/2015 07:33:32 PM) (Source: Service Control Manager) (EventID: 7026) (User: ) Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: cdrom Microsoft Office Sessions: ========================= ==================== Memory info =========================== Processor: Intel(R) Core(TM) i3-2377M CPU @ 1.50GHz Percentage of memory in use: 71% Total physical RAM: 3875.54 MB Available physical RAM: 1113.14 MB Total Pagefile: 7749.27 MB Available Pagefile: 4482.78 MB Total Virtual: 8192 MB Available Virtual: 8191.86 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:443.13 GB) (Free:215.77 GB) NTFS Drive d: (CANON CF) (Removable) (Total:3.81 GB) (Free:3.46 GB) FAT32 ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 465.8 GB) (Disk ID: 11B4AA17) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=443.1 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=22.5 GB) - (Type=27) ======================================================== Disk: 1 (Size: 22.4 GB) (Disk ID: 74F02DEA) Partition 1: (Not Active) - (Size=19.4 GB) - (Type=73) Partition 2: (Not Active) - (Size=3 GB) - (Type=84) ======================================================== Disk: 2 (Size: 3.8 GB) (Disk ID: 00000000) Partition: GPT Partition Type. ==================== End Of Log ============================ Vielen Dank schon einmal im Voraus für Ihre Hilfe. Nini123 |
16.04.2015, 10:39 | #6 |
/// the machine /// TB-Ausbilder | PC extrem langsam, Anwendungen "hängen sich auf", phys. Speicher bei 60% ohne offene Programme Die entfernen wir jetzt. Java updaten,. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter C:\Users\Nina\Downloads\DOSBox - CHIP-Installer.exe C:\Users\Nina\Downloads\FreeMind - CHIP-Installer.exe C:\Users\Nina\Downloads\VLC media player 64 Bit - CHIP-Installer.exe C:\Users\Nina\Downloads\wz175-64gev.msi C:\Windows\Installer\b37728.msi Emptytemp: Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Downloadverhalten überdenken: CHIP-Installer - was ist das? - Anleitungen Cleanup: (Die Reihenfolge ist hier entscheidend) Falls Defogger verwendet wurde: Erneut starten und auf Re-enable klicken. Falls Combofix verwendet wurde: Combofix deinstallieren .
Alle Logs gepostet? Dann lade Dir bitte DelFix herunter.
Hinweis: DelFix entfernt u.a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst. Starte Deinen Rechner abschließend neu. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein, kannst Du diese bedenkenlos löschen. Wenn Du möchtest, kannst Du hier sagen, ob Du mit mir und meiner Hilfe zufrieden warst...und/oder das Forum mit einer kleinen Spende unterstützen. Absicherung: Beim Betriebsystem Windows die automatischen Updates aktivieren. Auch die sicherheitsrelevante Software sollte immer nur in der aktuellsten Version vorliegen: Browser Java Flash-Player PDF-Reader Sicherheitslücken in deren alten Versionen werden dazu ausgenutzt, um beim einfachen Besuch einer manipulierten Website per "Drive-by" Malware zu installieren. Ich empfehle z.B. die Verwendung von Mozilla Firefox statt des Internet Explorers. Zudem lassen sich mit dem Firefox auch PDF-Dokumente öffnen. Aktiviere eine Firewall. Die in Windows integrierte genügt im Normalfall völlig. Verwende ein Antivirusprogramm mit Echtzeitscanner und stets aktueller Signaturendatenbank. Meine Empfehlung: Emsisoft Zusätzlich kannst Du Deinen PC regelmäßig mit Malwarebytes Anti-Malware und ESET scannen. Optional: NoScript verhindert das Ausführen von aktiven Inhalten (Java, JavaScript, Flash,...) für sämtliche Websites. Man kann aber nach dem Prinzip einer Whitelist festlegen, auf welchen Seiten Scripts erlaubt werden sollen. Malwarebytes Anti Exploit: Schützt die Anwendungen des Computers vor der Ausnutzung bekannter Schwachstellen. Lade Software von einem sauberen Portal wie . Wähle beim Installieren von Software immer die benutzerdefinierte Option und entferne den Haken bei allen optional angebotenen Toolbars oder sonstigen, fürs Programm, irrelevanten Ergänzungen. Um Adware wieder los zu werden, empfiehlt sich zunächst die Deinstallation sowie die anschließende Resteentfernung mit Adwarecleaner . Abschließend noch ein paar grundsätzliche Bemerkungen: Ändere regelmäßig Deine wichtigen Online-Passwörter und erstelle regelmäßig Backups Deiner wichtigen Dateien oder des Systems. Der Nutzen von Registry-Cleanern, Optimizern usw. zur Performancesteigerung ist umstritten. Ich empfehle deshalb, die Finger von der Registry zu lassen und lieber die windowseigene Datenträgerbereinigung zu verwenden.
__________________ --> PC extrem langsam, Anwendungen "hängen sich auf", phys. Speicher bei 60% ohne offene Programme |
16.04.2015, 18:06 | #7 |
| PC extrem langsam, Anwendungen "hängen sich auf", phys. Speicher bei 60% ohne offene Programme Hallo Schrauber, anbei das Fixlog wie gewünscht: Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 15-04-2015 03 Ran by Nina at 2015-04-16 18:24:20 Run:2 Running from C:\Users\Nina\Desktop Loaded Profiles: Nina (Available profiles: Nina) Boot Mode: Normal ============================================== Content of fixlist: ***************** C:\Users\Nina\Downloads\DOSBox - CHIP-Installer.exe C:\Users\Nina\Downloads\FreeMind - CHIP-Installer.exe C:\Users\Nina\Downloads\VLC media player 64 Bit - CHIP-Installer.exe C:\Users\Nina\Downloads\wz175-64gev.msi C:\Windows\Installer\b37728.msi Emptytemp: ***************** C:\Users\Nina\Downloads\DOSBox - CHIP-Installer.exe => Moved successfully. C:\Users\Nina\Downloads\FreeMind - CHIP-Installer.exe => Moved successfully. C:\Users\Nina\Downloads\VLC media player 64 Bit - CHIP-Installer.exe => Moved successfully. C:\Users\Nina\Downloads\wz175-64gev.msi => Moved successfully. C:\Windows\Installer\b37728.msi => Moved successfully. EmptyTemp: => Removed 22.1 MB temporary data. The system needed a reboot. ==== End of Fixlog 18:24:25 ==== Derzeit nutze ich Norton als Antiviren-Programm. Ist Emsisoft besser, wenn ja, warum? Ist es aktueller und gründlicher? Vielen Dank für Deine Hilfe! Nichts hängt mehr und der Computer läuft wieder schnell und ruckelfrei. Dankeschön! |
17.04.2015, 06:09 | #8 |
/// the machine /// TB-Ausbilder | PC extrem langsam, Anwendungen "hängen sich auf", phys. Speicher bei 60% ohne offene Programme Ich arbeite bei Emsisoft, daher könnte man denken meine Meinung sei nicht objektiv, daher jetzt mal meine persönliche Meinung: Nach 8 Jahren Malware Removal und 80000 Rechnern gibt es meiner Meinung nach kein schlechteres AV als Norton.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu PC extrem langsam, Anwendungen "hängen sich auf", phys. Speicher bei 60% ohne offene Programme |
aktiv, anleitung, anwendungen, ausgelastet, bleibt hängen, browser, combofix, computer, deinstallation, device driver, folge, forum, gen, hängen, langsam, launch, logfiles, malware, nicht mehr, pc extrem langsam, problem, programm, programme, prozesse, speicher, windows, öffnen |