|  | 
| 
 | |||||||
| Plagegeister aller Art und deren Bekämpfung: Im Browser ist überall WerbungWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. | 
|  | 
|  11.08.2013, 22:30 | #1 | 
|   |   Im Browser ist überall Werbung Hallo ihr Lieben, ich brauche wieder euere Hilfe. Habe auf einmal überall Werbung im Browser. Habe mir den Adblocker runtergeladen und aktiviert, nun sehe ich die Werbung nicht mehr, aber es steht links, rechts und unten immer "ads not by this site" auch auf dieser Seite. Auch werden manche Wörter markiert, die ich anklicken kann, dadurch kann ich auf andere Seiten geleitet werden. Merke auch das der Pc nun teilweise hängt  hoffe mir kann einer helfen, weil ich weiß, dass ich mir was eingefangen habe. Habe mir Malwarebytes Anti-Malware runtergeladen und einen Quick-Scan gemacht. Ein Fund : PUP.Optional.Solimba wurde erfolgreich gelöscht. Habe die Windows 7 Version. Für eure Hilfe wäre ich sehr dankbar! Liebe Grüße Lili Geändert von joycelle (11.08.2013 um 23:24 Uhr) | 
|  12.08.2013, 00:11 | #2 | 
| /// Winkelfunktion /// TB-Süch-Tiger™       |   Im Browser ist überall Werbung Hallo und __________________  Hast du noch weitere Logs (mit Funden)? Malwarebytes und/oder andere Virenscanner, sind die mal fündig geworden? Ich frage deswegen nach => http://www.trojaner-board.de/125889-...tml#post941520 Bitte keine neuen Virenscans machen sondern erst nur schon vorhandene Logs in CODE-Tags posten! Relevant sind nur Logs der letzten 7 Tage bzw. seitdem das Problem besteht! Zudem bitte auch ein Log mit Farbars Tool machen: Scan mit Farbar's Recovery Scan Tool (FRST) Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop:  FRST 32-Bit | FRST   64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen) 
  Lesestoff: Posten in CODE-Tags Die Logfiles anzuhängen oder sogar vorher in ein ZIP, RAR, 7Z-Archive zu packen erschwert mir massiv die Arbeit, es sei denn natürlich die Datei wäre ansonsten zu gross für das Forum. Um die Logfiles in eine CODE-Box zu stellen gehe so vor: 
 
				__________________ | 
|  12.08.2013, 10:33 | #3 | 
|   |   Im Browser ist überall Werbung Hallo lieber cosinus und vielen Dank das du mir helfen möchtest__________________  Habe nur Logdateien vom Anti-Malware und das sind 7 Stück, alle posten? Gestern Abend ist mir beim durchstöbern im Forum etwas aufgefallen. Ich habe komischerweise ein Programm Namens inimet (hoffe das ist richtig geschrieben) auf meinem Rechner gehabt. Habe es natürlich sofort deinstalliert, habe aber hier gelesen das es eine Art Trojaner sein soll. Verstehe nicht wie das auf meinen Rechner kommt  Vll ist es relevant für dich. Auf jeden Fall sind hier die Logfiles FRST Code: 
  ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2013 02 Ran by Lila at 2013-08-12 11:16:13 Running from C:\Users\Lila\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 0.0.0) Acrobat.com (x32 Version: 1.2.443) Adobe Acrobat 9 Pro - English, Français, Deutsch (x32 Version: 9.0.0) Adobe After Effects CS4 Third Party Content (x32 Version: 9) Adobe AIR (x32 Version: 1.1.0.5790) Adobe Anchor Service CS4 (x32 Version: 2.0) Adobe Anchor Service x64 CS4 (Version: 2.0) Adobe Bridge CS4 (x32 Version: 3) Adobe CMaps CS4 (x32 Version: 2.0) Adobe CMaps x64 CS4 (Version: 2.0) Adobe Color - Photoshop Specific CS4 (x32 Version: 2.0) Adobe Color EU Recommended Settings CS4 (x32 Version: 2.0) Adobe Color JA Extra Settings CS4 (x32 Version: 2.0) Adobe Color NA Extra Settings CS4 (x32 Version: 2.0) Adobe Color Video Profiles CS CS4 (x32 Version: 2.0) Adobe Contribute CS4 (x32 Version: 5.0) Adobe Creative Suite 4 Master Collection (x32 Version: 4.0) Adobe CS4 American English Speech Analysis Models (x32 Version: 1) Adobe CSI CS4 (x32 Version: 1) Adobe CSI CS4 x64 (Version: 1) Adobe Default Language CS4 (x32 Version: 2.0) Adobe Dreamweaver CS4 (x32 Version: 10.0) Adobe Drive CS4 x64 (Version: 1) Adobe Dynamiclink Support (x32 Version: 1) Adobe Encore CS4 Codecs (x32 Version: 4) Adobe ExtendScript Toolkit CS4 (x32 Version: 3.0.0) Adobe Extension Manager CS4 (x32 Version: 2.0) Adobe Fireworks CS4 (x32 Version: 10.0) Adobe Flash CS4 (x32 Version: 10.0) Adobe Flash CS4 Extension - Flash Lite STI others (x32 Version: 3.0) Adobe Flash CS4 STI-other (x32 Version: 10.0) Adobe Flash Player 10 ActiveX (x32 Version: 10.3.183.43) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.202) Adobe Fonts All (x32 Version: 2.0) Adobe Fonts All x64 (Version: 2.0) Adobe Illustrator CS4 (x32 Version: 14.0) Adobe InDesign CS4 (x32 Version: 6.0) Adobe InDesign CS4 Application Feature Set Files (Roman) (x32 Version: 6.0) Adobe InDesign CS4 Common Base Files (x32 Version: 6.0) Adobe InDesign CS4 Icon Handler (x32 Version: 6.0) Adobe InDesign CS4 Icon Handler x64 (Version: 6.0) Adobe Linguistics CS4 (x32 Version: 4.0.0) Adobe Linguistics CS4 x64 (Version: 4.0.0) Adobe Media Encoder CS4 (x32 Version: 1.0) Adobe Media Encoder CS4 Additional Exporter (x32 Version: 1.0) Adobe Media Encoder CS4 Dolby (x32 Version: 1.0) Adobe Media Encoder CS4 Exporter (x32 Version: 1.0) Adobe Media Encoder CS4 Importer (x32 Version: 1.0) Adobe Media Player (x32 Version: 0.0.0) Adobe Media Player (x32 Version: 1.1) Adobe Output Module (x32 Version: 2.0) Adobe PDF Library Files CS4 (x32 Version: 9.0) Adobe PDF Library Files x64 CS4 (Version: 9.0) Adobe Photoshop CS4 (64 Bit) (Version: 11.0) Adobe Photoshop CS4 (x32 Version: 11.0) Adobe Photoshop CS4 Support (x32 Version: 11.0) Adobe Premiere Pro CS4 (x32 Version: 4) Adobe Premiere Pro CS4 Functional Content (x32 Version: 4) Adobe Premiere Pro CS4 Third Party Content (x32 Version: 4) Adobe Search for Help (x32 Version: 1.0) Adobe Service Manager Extension (x32 Version: 1.0) Adobe Setup (x32 Version: 2.0) Adobe SGM CS4 (x32 Version: 3.0) Adobe SING CS4 (x32 Version: 2.0) Adobe Soundbooth CS4 Codecs (x32 Version: 2) Adobe Type Support CS4 (x32 Version: 9.0) Adobe Type Support x64 CS4 (Version: 9.0) Adobe Update Manager CS4 (x32 Version: 6.0.0) Adobe WinSoft Linguistics Plugin (x32 Version: 1.1) Adobe WinSoft Linguistics Plugin x64 (Version: 1.1) Adobe XMP Panels CS4 (x32 Version: 2.0) AdobeColorCommonSetCMYK (x32 Version: 2.0) AdobeColorCommonSetRGB (x32 Version: 2.0) AMD Accelerated Video Transcoding (Version: 12.5.100.21219) AMD APP SDK Runtime (Version: 10.0.1084.4) AMD Catalyst Install Manager (Version: 8.0.903.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.71219.1540) Apple Application Support (x32 Version: 2.3) Apple Software Update (x32 Version: 2.1.3.127) Asmedia ASM106x SATA Host Controller Driver (x32 Version: 1.3.1.000) Canon IJ Scan Utility (x32) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32 Version: 4.0.0) Canon MG2200 series Benutzerregistrierung (x32) Canon MG2200 series MP Drivers (Version: 1.00) Canon MG2200 series On-screen Manual (x32 Version: 7.5.0) Canon My Printer (x32 Version: 3.0.0) Canon Quick Menu (x32 Version: 2.0.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485) Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485) CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485) CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485) CCC Help Czech (x32 Version: 2012.1219.1520.27485) CCC Help Danish (x32 Version: 2012.1219.1520.27485) CCC Help Dutch (x32 Version: 2012.1219.1520.27485) CCC Help English (x32 Version: 2012.1219.1520.27485) CCC Help Finnish (x32 Version: 2012.1219.1520.27485) CCC Help French (x32 Version: 2012.1219.1520.27485) CCC Help German (x32 Version: 2012.1219.1520.27485) CCC Help Greek (x32 Version: 2012.1219.1520.27485) CCC Help Hungarian (x32 Version: 2012.1219.1520.27485) CCC Help Italian (x32 Version: 2012.1219.1520.27485) CCC Help Japanese (x32 Version: 2012.1219.1520.27485) CCC Help Korean (x32 Version: 2012.1219.1520.27485) CCC Help Norwegian (x32 Version: 2012.1219.1520.27485) CCC Help Polish (x32 Version: 2012.1219.1520.27485) CCC Help Portuguese (x32 Version: 2012.1219.1520.27485) CCC Help Russian (x32 Version: 2012.1219.1520.27485) CCC Help Spanish (x32 Version: 2012.1219.1520.27485) CCC Help Swedish (x32 Version: 2012.1219.1520.27485) CCC Help Thai (x32 Version: 2012.1219.1520.27485) CCC Help Turkish (x32 Version: 2012.1219.1520.27485) ccc-utility64 (Version: 2012.1219.1521.27485) Connect (x32 Version: 1.0.0.1) DAEMON Tools Lite (x32 Version: 4.46.1.0327) Easy Poster Printer (x32 Version: 6.0.0) ESET Smart Security (Version: 6.0.316.1) Google Chrome (HKCU Version: 28.0.1500.95) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: 1.0.0.35342) Intel(R) Management Engine Components (x32 Version: 8.0.2.1410) Intel(R) OpenCL CPU Runtime (x32) Intel(R) Processor Graphics (x32 Version: 8.15.10.2618) Intel(R) Rapid Storage Technology (x32 Version: 11.0.0.1032) Intel(R) Smart Connect Technology 2.0 x64 (Version: 2.0.1083.0) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.3.214) Intel® Trusted Connect Service Client (Version: 1.23.605.1) kuler (x32 Version: 2.0) LyricsContainer (x32) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Professional Edition 2003 (x32 Version: 11.0.7969.0) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) ock App Charger v1.0.5 PDF Settings CS4 (x32 Version: 9.0) Personal ID (x32 Version: 1.8.5.202) Photoshop Camera Raw (x32 Version: 5.0) Photoshop Camera Raw_x64 (Version: 5.0) Pixel Bender Toolkit (x32 Version: 1.0) Poker 770 (x32) PokerStars.eu (x32) PreFlopper (x32 Version: 2.1.0) QuickTime (x32 Version: 7.73.80.64) Realtek Ethernet Controller Driver (x32 Version: 7.48.823.2011) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6482) Secret City (x32 Version: 1.9.4662) Steam (x32 Version: 1.0.0.0) Suite Shared Configuration CS4 (x32 Version: 1.0) TP-LINK TL-WN821N Driver (x32 Version: 1.2.1) TrackMania Nations Forever (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) UseNeXT by Tangysoft (x32) VIRTU MVP 2.1.110 (Version: 2.1.110) VLC media player 2.0.6 (x32 Version: 2.0.6) Wacom Tablett (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 18-07-2013 14:20:47 Windows Update 25-07-2013 22:40:43 Geplanter Prüfpunkt 02-08-2013 20:07:36 Geplanter Prüfpunkt 07-08-2013 20:28:41 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-03-05 15:25 - 00001173 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 pagead2.googlesyndication.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 activate-sjc0.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {220145D2-20B3-4B48-AE44-52D59DE2FAF6} - System32\Tasks\User_Feed_Synchronization-{AE5A86A8-D88D-40C8-AA45-438AD91DF71B} => C:\Windows\system32\msfeedssync.exe [2013-05-22] (Microsoft Corporation) Task: {28336CC1-56F3-4285-84D2-51E7E572B6E6} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {3A95E0EA-4FEB-4A27-882A-D4A0E9043D22} - System32\Tasks\LyricsContainer Update => C:\Program Files (x86)\LyricsContainer\LrcsCtrUpdr.exe [2013-08-09] () Task: {52DB3FE1-FD35-49AE-A798-A031751E05F0} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {557A4CA9-1E48-4C36-8783-1250F4FA44A3} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {79B1D23E-D9E5-44CA-B2B4-EE322E0F6FB2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {9227EDEB-5C17-43F6-AF4C-1B3E91416116} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {CEA0F661-E4EF-4B0C-8174-747271058321} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {EBD67A4D-F364-42F2-94CA-DEA6B10D73FF} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\LyricsContainer Update.job => C:\Program Files (x86)\LyricsContainer\LrcsCtrUpdr.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/12/2013 11:08:38 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 11:06:52 AM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/12/2013 11:06:51 AM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 11:25:23 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 11:23:37 PM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/11/2013 11:23:36 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 09:18:52 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 09:17:06 PM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/11/2013 09:17:05 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 01:21:47 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (08/12/2013 11:06:51 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 11:23:36 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 11:11:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SProtection" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/11/2013 09:17:05 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 01:20:00 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/09/2013 00:36:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/08/2013 10:56:54 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/08/2013 10:24:42 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/07/2013 10:42:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "ESET Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/07/2013 10:36:39 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Microsoft Office Sessions: ========================= Error: (08/12/2013 11:08:38 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 11:06:52 AM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/12/2013 11:06:51 AM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 11:25:23 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 11:23:37 PM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/11/2013 11:23:36 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 09:18:52 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 09:17:06 PM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/11/2013 09:17:05 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 01:21:47 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 16% Total physical RAM: 16268.42 MB Available physical RAM: 13621.07 MB Total Pagefile: 32535.03 MB Available Pagefile: 29440.16 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.69 GB) (Free:37.81 GB) NTFS (Disk=0 Partition=2) Drive d: (Volume) (Fixed) (Total:931.51 GB) (Free:891.11 GB) NTFS (Disk=1 Partition=1) Drive e: (Ablage) (Fixed) (Total:10 GB) (Free:1.21 GB) NTFS (Disk=2 Partition=1) Drive f: (Datensammlung) (Fixed) (Total:50.01 GB) (Free:44.07 GB) NTFS (Disk=2 Partition=2) Drive g: (Musik) (Fixed) (Total:100.01 GB) (Free:96.2 GB) NTFS (Disk=2 Partition=3) Drive h: (Down) (Fixed) (Total:305.74 GB) (Free:225.94 GB) NTFS (Disk=2 Partition=4) Drive k: (EOS_DIGITAL) (Removable) (Total:14.93 GB) (Free:8.21 GB) FAT32 (Disk=3 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 862E84D4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: E792C529) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 466 GB) (Disk ID: 086D086C) Partition 1: (Active) - (Size=10 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=456 GB) - (Type=05) ======================================================== Disk: 3 (Size: 15 GB) (Disk ID: 00000000) Partition 1: (Active) - (Size=15 GB) - (Type=0C) ==================== End Of Log ============================ Code: 
  ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2013 02 Ran by Lila at 2013-08-12 11:16:13 Running from C:\Users\Lila\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 0.0.0) Acrobat.com (x32 Version: 1.2.443) Adobe Acrobat 9 Pro - English, Français, Deutsch (x32 Version: 9.0.0) Adobe After Effects CS4 Third Party Content (x32 Version: 9) Adobe AIR (x32 Version: 1.1.0.5790) Adobe Anchor Service CS4 (x32 Version: 2.0) Adobe Anchor Service x64 CS4 (Version: 2.0) Adobe Bridge CS4 (x32 Version: 3) Adobe CMaps CS4 (x32 Version: 2.0) Adobe CMaps x64 CS4 (Version: 2.0) Adobe Color - Photoshop Specific CS4 (x32 Version: 2.0) Adobe Color EU Recommended Settings CS4 (x32 Version: 2.0) Adobe Color JA Extra Settings CS4 (x32 Version: 2.0) Adobe Color NA Extra Settings CS4 (x32 Version: 2.0) Adobe Color Video Profiles CS CS4 (x32 Version: 2.0) Adobe Contribute CS4 (x32 Version: 5.0) Adobe Creative Suite 4 Master Collection (x32 Version: 4.0) Adobe CS4 American English Speech Analysis Models (x32 Version: 1) Adobe CSI CS4 (x32 Version: 1) Adobe CSI CS4 x64 (Version: 1) Adobe Default Language CS4 (x32 Version: 2.0) Adobe Dreamweaver CS4 (x32 Version: 10.0) Adobe Drive CS4 x64 (Version: 1) Adobe Dynamiclink Support (x32 Version: 1) Adobe Encore CS4 Codecs (x32 Version: 4) Adobe ExtendScript Toolkit CS4 (x32 Version: 3.0.0) Adobe Extension Manager CS4 (x32 Version: 2.0) Adobe Fireworks CS4 (x32 Version: 10.0) Adobe Flash CS4 (x32 Version: 10.0) Adobe Flash CS4 Extension - Flash Lite STI others (x32 Version: 3.0) Adobe Flash CS4 STI-other (x32 Version: 10.0) Adobe Flash Player 10 ActiveX (x32 Version: 10.3.183.43) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.202) Adobe Fonts All (x32 Version: 2.0) Adobe Fonts All x64 (Version: 2.0) Adobe Illustrator CS4 (x32 Version: 14.0) Adobe InDesign CS4 (x32 Version: 6.0) Adobe InDesign CS4 Application Feature Set Files (Roman) (x32 Version: 6.0) Adobe InDesign CS4 Common Base Files (x32 Version: 6.0) Adobe InDesign CS4 Icon Handler (x32 Version: 6.0) Adobe InDesign CS4 Icon Handler x64 (Version: 6.0) Adobe Linguistics CS4 (x32 Version: 4.0.0) Adobe Linguistics CS4 x64 (Version: 4.0.0) Adobe Media Encoder CS4 (x32 Version: 1.0) Adobe Media Encoder CS4 Additional Exporter (x32 Version: 1.0) Adobe Media Encoder CS4 Dolby (x32 Version: 1.0) Adobe Media Encoder CS4 Exporter (x32 Version: 1.0) Adobe Media Encoder CS4 Importer (x32 Version: 1.0) Adobe Media Player (x32 Version: 0.0.0) Adobe Media Player (x32 Version: 1.1) Adobe Output Module (x32 Version: 2.0) Adobe PDF Library Files CS4 (x32 Version: 9.0) Adobe PDF Library Files x64 CS4 (Version: 9.0) Adobe Photoshop CS4 (64 Bit) (Version: 11.0) Adobe Photoshop CS4 (x32 Version: 11.0) Adobe Photoshop CS4 Support (x32 Version: 11.0) Adobe Premiere Pro CS4 (x32 Version: 4) Adobe Premiere Pro CS4 Functional Content (x32 Version: 4) Adobe Premiere Pro CS4 Third Party Content (x32 Version: 4) Adobe Search for Help (x32 Version: 1.0) Adobe Service Manager Extension (x32 Version: 1.0) Adobe Setup (x32 Version: 2.0) Adobe SGM CS4 (x32 Version: 3.0) Adobe SING CS4 (x32 Version: 2.0) Adobe Soundbooth CS4 Codecs (x32 Version: 2) Adobe Type Support CS4 (x32 Version: 9.0) Adobe Type Support x64 CS4 (Version: 9.0) Adobe Update Manager CS4 (x32 Version: 6.0.0) Adobe WinSoft Linguistics Plugin (x32 Version: 1.1) Adobe WinSoft Linguistics Plugin x64 (Version: 1.1) Adobe XMP Panels CS4 (x32 Version: 2.0) AdobeColorCommonSetCMYK (x32 Version: 2.0) AdobeColorCommonSetRGB (x32 Version: 2.0) AMD Accelerated Video Transcoding (Version: 12.5.100.21219) AMD APP SDK Runtime (Version: 10.0.1084.4) AMD Catalyst Install Manager (Version: 8.0.903.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.71219.1540) Apple Application Support (x32 Version: 2.3) Apple Software Update (x32 Version: 2.1.3.127) Asmedia ASM106x SATA Host Controller Driver (x32 Version: 1.3.1.000) Canon IJ Scan Utility (x32) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32 Version: 4.0.0) Canon MG2200 series Benutzerregistrierung (x32) Canon MG2200 series MP Drivers (Version: 1.00) Canon MG2200 series On-screen Manual (x32 Version: 7.5.0) Canon My Printer (x32 Version: 3.0.0) Canon Quick Menu (x32 Version: 2.0.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485) Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485) CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485) CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485) CCC Help Czech (x32 Version: 2012.1219.1520.27485) CCC Help Danish (x32 Version: 2012.1219.1520.27485) CCC Help Dutch (x32 Version: 2012.1219.1520.27485) CCC Help English (x32 Version: 2012.1219.1520.27485) CCC Help Finnish (x32 Version: 2012.1219.1520.27485) CCC Help French (x32 Version: 2012.1219.1520.27485) CCC Help German (x32 Version: 2012.1219.1520.27485) CCC Help Greek (x32 Version: 2012.1219.1520.27485) CCC Help Hungarian (x32 Version: 2012.1219.1520.27485) CCC Help Italian (x32 Version: 2012.1219.1520.27485) CCC Help Japanese (x32 Version: 2012.1219.1520.27485) CCC Help Korean (x32 Version: 2012.1219.1520.27485) CCC Help Norwegian (x32 Version: 2012.1219.1520.27485) CCC Help Polish (x32 Version: 2012.1219.1520.27485) CCC Help Portuguese (x32 Version: 2012.1219.1520.27485) CCC Help Russian (x32 Version: 2012.1219.1520.27485) CCC Help Spanish (x32 Version: 2012.1219.1520.27485) CCC Help Swedish (x32 Version: 2012.1219.1520.27485) CCC Help Thai (x32 Version: 2012.1219.1520.27485) CCC Help Turkish (x32 Version: 2012.1219.1520.27485) ccc-utility64 (Version: 2012.1219.1521.27485) Connect (x32 Version: 1.0.0.1) DAEMON Tools Lite (x32 Version: 4.46.1.0327) Easy Poster Printer (x32 Version: 6.0.0) ESET Smart Security (Version: 6.0.316.1) Google Chrome (HKCU Version: 28.0.1500.95) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: 1.0.0.35342) Intel(R) Management Engine Components (x32 Version: 8.0.2.1410) Intel(R) OpenCL CPU Runtime (x32) Intel(R) Processor Graphics (x32 Version: 8.15.10.2618) Intel(R) Rapid Storage Technology (x32 Version: 11.0.0.1032) Intel(R) Smart Connect Technology 2.0 x64 (Version: 2.0.1083.0) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.3.214) Intel® Trusted Connect Service Client (Version: 1.23.605.1) kuler (x32 Version: 2.0) LyricsContainer (x32) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Professional Edition 2003 (x32 Version: 11.0.7969.0) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) ock App Charger v1.0.5 PDF Settings CS4 (x32 Version: 9.0) Personal ID (x32 Version: 1.8.5.202) Photoshop Camera Raw (x32 Version: 5.0) Photoshop Camera Raw_x64 (Version: 5.0) Pixel Bender Toolkit (x32 Version: 1.0) Poker 770 (x32) PokerStars.eu (x32) PreFlopper (x32 Version: 2.1.0) QuickTime (x32 Version: 7.73.80.64) Realtek Ethernet Controller Driver (x32 Version: 7.48.823.2011) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6482) Secret City (x32 Version: 1.9.4662) Steam (x32 Version: 1.0.0.0) Suite Shared Configuration CS4 (x32 Version: 1.0) TP-LINK TL-WN821N Driver (x32 Version: 1.2.1) TrackMania Nations Forever (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) UseNeXT by Tangysoft (x32) VIRTU MVP 2.1.110 (Version: 2.1.110) VLC media player 2.0.6 (x32 Version: 2.0.6) Wacom Tablett (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 18-07-2013 14:20:47 Windows Update 25-07-2013 22:40:43 Geplanter Prüfpunkt 02-08-2013 20:07:36 Geplanter Prüfpunkt 07-08-2013 20:28:41 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-03-05 15:25 - 00001173 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 pagead2.googlesyndication.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 activate-sjc0.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {220145D2-20B3-4B48-AE44-52D59DE2FAF6} - System32\Tasks\User_Feed_Synchronization-{AE5A86A8-D88D-40C8-AA45-438AD91DF71B} => C:\Windows\system32\msfeedssync.exe [2013-05-22] (Microsoft Corporation) Task: {28336CC1-56F3-4285-84D2-51E7E572B6E6} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {3A95E0EA-4FEB-4A27-882A-D4A0E9043D22} - System32\Tasks\LyricsContainer Update => C:\Program Files (x86)\LyricsContainer\LrcsCtrUpdr.exe [2013-08-09] () Task: {52DB3FE1-FD35-49AE-A798-A031751E05F0} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {557A4CA9-1E48-4C36-8783-1250F4FA44A3} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {79B1D23E-D9E5-44CA-B2B4-EE322E0F6FB2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {9227EDEB-5C17-43F6-AF4C-1B3E91416116} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {CEA0F661-E4EF-4B0C-8174-747271058321} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {EBD67A4D-F364-42F2-94CA-DEA6B10D73FF} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\LyricsContainer Update.job => C:\Program Files (x86)\LyricsContainer\LrcsCtrUpdr.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/12/2013 11:08:38 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 11:06:52 AM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/12/2013 11:06:51 AM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 11:25:23 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 11:23:37 PM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/11/2013 11:23:36 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 09:18:52 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 09:17:06 PM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/11/2013 09:17:05 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 01:21:47 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (08/12/2013 11:06:51 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 11:23:36 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 11:11:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SProtection" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/11/2013 09:17:05 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 01:20:00 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/09/2013 00:36:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/08/2013 10:56:54 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/08/2013 10:24:42 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/07/2013 10:42:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "ESET Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/07/2013 10:36:39 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Microsoft Office Sessions: ========================= Error: (08/12/2013 11:08:38 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 11:06:52 AM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/12/2013 11:06:51 AM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 11:25:23 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 11:23:37 PM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/11/2013 11:23:36 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 09:18:52 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 09:17:06 PM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/11/2013 09:17:05 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 01:21:47 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 16% Total physical RAM: 16268.42 MB Available physical RAM: 13621.07 MB Total Pagefile: 32535.03 MB Available Pagefile: 29440.16 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.69 GB) (Free:37.81 GB) NTFS (Disk=0 Partition=2) Drive d: (Volume) (Fixed) (Total:931.51 GB) (Free:891.11 GB) NTFS (Disk=1 Partition=1) Drive e: (Ablage) (Fixed) (Total:10 GB) (Free:1.21 GB) NTFS (Disk=2 Partition=1) Drive f: (Datensammlung) (Fixed) (Total:50.01 GB) (Free:44.07 GB) NTFS (Disk=2 Partition=2) Drive g: (Musik) (Fixed) (Total:100.01 GB) (Free:96.2 GB) NTFS (Disk=2 Partition=3) Drive h: (Down) (Fixed) (Total:305.74 GB) (Free:225.94 GB) NTFS (Disk=2 Partition=4) Drive k: (EOS_DIGITAL) (Removable) (Total:14.93 GB) (Free:8.21 GB) FAT32 (Disk=3 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 862E84D4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: E792C529) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 466 GB) (Disk ID: 086D086C) Partition 1: (Active) - (Size=10 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=456 GB) - (Type=05) ======================================================== Disk: 3 (Size: 15 GB) (Disk ID: 00000000) Partition 1: (Active) - (Size=15 GB) - (Type=0C) ==================== End Of Log ============================ Schöne Grüße Lili | 
|  12.08.2013, 10:57 | #4 | |
| /// Winkelfunktion /// TB-Süch-Tiger™       |   Im Browser ist überall WerbungZitat: 
 
				__________________ Logfiles bitte immer in CODE-Tags posten   | 
|  12.08.2013, 11:04 | #5 | 
|   |   Im Browser ist überall Werbung Malware Logs: Code: 
  ATTFilter Malwarebytes Anti-Malware (Test) 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.05.16.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Lila :: LEX [Administrator] Schutz: Aktiviert 16.05.2013 17:25:52 mbam-log-2013-05-16 (17-25-52).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|H:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 379945 Laufzeit: 12 Minute(n), 11 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code: 
  ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.11.06 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 Lila :: LEX [Administrator] 11.08.2013 23:20:20 mbam-log-2013-08-11 (23-20-20).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 219128 Laufzeit: 1 Minute(n), 29 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Lila\Downloads\FLVMPlayer.exe (PUP.Optional.Solimba) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code: 
  ATTFilter 2013/05/16 17:23:54 +0200	LEX	Lila	MESSAGE	Starting protection
2013/05/16 17:23:54 +0200	LEX	Lila	MESSAGE	Protection started successfully
2013/05/16 17:23:54 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/16 17:24:02 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
2013/05/16 17:24:09 +0200	LEX	Lila	MESSAGE	Starting database refresh
2013/05/16 17:24:09 +0200	LEX	Lila	MESSAGE	Stopping IP protection
2013/05/16 17:24:11 +0200	LEX	Lila	MESSAGE	IP Protection stopped successfully
2013/05/16 17:24:12 +0200	LEX	Lila	MESSAGE	Database refreshed successfully
2013/05/16 17:24:12 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/16 17:24:13 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
2013/05/16 17:41:49 +0200	LEX	Lila	MESSAGE	Starting protection
2013/05/16 17:41:49 +0200	LEX	Lila	MESSAGE	Protection started successfully
2013/05/16 17:41:49 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/16 17:41:50 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
2013/05/16 17:46:43 +0200	LEX	Lila	MESSAGE	Starting protection
2013/05/16 17:46:43 +0200	LEX	Lila	MESSAGE	Protection started successfully
2013/05/16 17:46:43 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/16 17:46:44 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
2013/05/16 17:52:06 +0200	LEX	Lila	MESSAGE	Starting protection
2013/05/16 17:52:06 +0200	LEX	Lila	MESSAGE	Protection started successfully
2013/05/16 17:52:06 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/16 17:52:08 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
2013/05/16 18:01:59 +0200	LEX	Lila	IP-BLOCK	208.73.210.29 (Type: outgoing, Port: 49299, Process: firefox.exe)
2013/05/16 18:01:59 +0200	LEX	Lila	IP-BLOCK	208.73.210.29 (Type: outgoing, Port: 49300, Process: firefox.exe)
2013/05/16 18:03:11 +0200	LEX	Lila	IP-BLOCK	208.73.210.29 (Type: outgoing, Port: 49406, Process: firefox.exe)
2013/05/16 18:03:11 +0200	LEX	Lila	IP-BLOCK	208.73.210.29 (Type: outgoing, Port: 49407, Process: firefox.exe)
2013/05/16 18:30:56 +0200	LEX	Lila	MESSAGE	Executing scheduled update:  Daily
2013/05/16 18:30:57 +0200	LEX	Lila	MESSAGE	Database already up-to-date
2013/05/16 22:47:33 +0200	LEX	Lila	IP-BLOCK	88.86.119.182 (Type: outgoing, Port: 51792, Process: firefox.exe)
2013/05/16 22:47:33 +0200	LEX	Lila	IP-BLOCK	88.86.119.182 (Type: outgoing, Port: 51793, Process: firefox.exe)
2013/05/16 22:47:49 +0200	LEX	Lila	IP-BLOCK	88.86.119.182 (Type: outgoing, Port: 51794, Process: firefox.exe)
2013/05/16 22:47:49 +0200	LEX	Lila	IP-BLOCK	88.86.119.182 (Type: outgoing, Port: 51795, Process: firefox.exe)
2013/05/16 23:01:50 +0200	LEX	(null)	MESSAGE	Starting protection
2013/05/16 23:01:50 +0200	LEX	(null)	MESSAGE	Protection started successfully
2013/05/16 23:01:50 +0200	LEX	(null)	MESSAGE	Starting IP protection
2013/05/16 23:01:52 +0200	LEX	(null)	MESSAGE	IP Protection started successfully
2013/05/16 23:15:53 +0200	LEX	Lila	MESSAGE	Starting protection
2013/05/16 23:15:53 +0200	LEX	Lila	MESSAGE	Protection started successfully
2013/05/16 23:15:53 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/16 23:15:55 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
2013/05/16 23:19:41 +0200	LEX	Lila	MESSAGE	Starting protection
2013/05/16 23:19:41 +0200	LEX	Lila	MESSAGE	Protection started successfully
2013/05/16 23:19:41 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/16 23:19:43 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
         Code: 
  ATTFilter 2013/05/18 01:26:48 +0200	LEX	Lila	MESSAGE	Starting protection
2013/05/18 01:26:48 +0200	LEX	Lila	MESSAGE	Protection started successfully
2013/05/18 01:26:48 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/18 01:26:49 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
2013/05/18 01:36:40 +0200	LEX	Lila	IP-BLOCK	208.73.210.29 (Type: outgoing, Port: 49324, Process: firefox.exe)
2013/05/18 01:36:40 +0200	LEX	Lila	IP-BLOCK	208.73.210.29 (Type: outgoing, Port: 49325, Process: firefox.exe)
2013/05/18 01:37:20 +0200	LEX	Lila	IP-BLOCK	208.73.210.29 (Type: outgoing, Port: 49418, Process: firefox.exe)
2013/05/18 01:37:20 +0200	LEX	Lila	IP-BLOCK	208.73.210.29 (Type: outgoing, Port: 49419, Process: firefox.exe)
2013/05/18 01:40:51 +0200	LEX	Lila	MESSAGE	Executing scheduled update:  Daily
2013/05/18 01:40:59 +0200	LEX	Lila	MESSAGE	Scheduled update executed successfully:  database updated from version v2013.05.16.06 to version v2013.05.17.07
2013/05/18 01:40:59 +0200	LEX	Lila	MESSAGE	Starting database refresh
2013/05/18 01:40:59 +0200	LEX	Lila	MESSAGE	Stopping IP protection
2013/05/18 01:40:59 +0200	LEX	Lila	MESSAGE	IP Protection stopped successfully
2013/05/18 01:41:00 +0200	LEX	Lila	MESSAGE	Database refreshed successfully
2013/05/18 01:41:00 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/18 01:41:01 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
2013/05/18 14:45:24 +0200	LEX	Lila	MESSAGE	Starting protection
2013/05/18 14:45:24 +0200	LEX	Lila	MESSAGE	Protection started successfully
2013/05/18 14:45:24 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/18 14:45:26 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
2013/05/18 15:06:21 +0200	LEX	Lila	IP-BLOCK	208.73.210.29 (Type: outgoing, Port: 49632, Process: firefox.exe)
2013/05/18 15:06:21 +0200	LEX	Lila	IP-BLOCK	208.73.210.29 (Type: outgoing, Port: 49633, Process: firefox.exe)
2013/05/18 15:06:53 +0200	LEX	Lila	IP-BLOCK	208.73.210.29 (Type: outgoing, Port: 49691, Process: firefox.exe)
2013/05/18 15:06:53 +0200	LEX	Lila	IP-BLOCK	208.73.210.29 (Type: outgoing, Port: 49692, Process: firefox.exe)
         Code: 
  ATTFilter 2013/05/20 20:56:54 +0200	LEX	Lila	MESSAGE	Starting protection
2013/05/20 20:56:54 +0200	LEX	Lila	MESSAGE	Protection started successfully
2013/05/20 20:56:54 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/20 20:56:55 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
2013/05/20 21:11:15 +0200	LEX	Lila	MESSAGE	Executing scheduled update:  Daily
2013/05/20 21:11:26 +0200	LEX	Lila	MESSAGE	Scheduled update executed successfully:  database updated from version v2013.05.17.07 to version v2013.05.20.07
2013/05/20 21:11:26 +0200	LEX	Lila	MESSAGE	Starting database refresh
2013/05/20 21:11:26 +0200	LEX	Lila	MESSAGE	Stopping IP protection
2013/05/20 21:11:26 +0200	LEX	Lila	MESSAGE	IP Protection stopped successfully
2013/05/20 21:11:28 +0200	LEX	Lila	MESSAGE	Database refreshed successfully
2013/05/20 21:11:28 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/20 21:11:29 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
         Code: 
  ATTFilter 2013/05/21 13:11:29 +0200	LEX	Lila	MESSAGE	Starting protection
2013/05/21 13:11:29 +0200	LEX	Lila	MESSAGE	Protection started successfully
2013/05/21 13:11:29 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/21 13:11:30 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
         Code: 
  ATTFilter 2013/05/22 15:28:28 +0200	LEX	Lila	MESSAGE	Starting protection
2013/05/22 15:28:28 +0200	LEX	Lila	MESSAGE	Protection started successfully
2013/05/22 15:28:28 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/22 15:28:29 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
2013/05/22 15:42:21 +0200	LEX	Lila	MESSAGE	Executing scheduled update:  Daily
2013/05/22 15:42:33 +0200	LEX	Lila	MESSAGE	Scheduled update executed successfully:  database updated from version v2013.05.20.07 to version v2013.05.22.06
2013/05/22 15:42:33 +0200	LEX	Lila	MESSAGE	Starting database refresh
2013/05/22 15:42:33 +0200	LEX	Lila	MESSAGE	Stopping IP protection
2013/05/22 15:42:33 +0200	LEX	Lila	MESSAGE	IP Protection stopped successfully
2013/05/22 15:42:34 +0200	LEX	Lila	MESSAGE	Database refreshed successfully
2013/05/22 15:42:34 +0200	LEX	Lila	MESSAGE	Starting IP protection
2013/05/22 15:42:35 +0200	LEX	Lila	MESSAGE	IP Protection started successfully
2013/05/22 16:02:57 +0200	LEX	Lila	MESSAGE	Stopping IP protection
2013/05/22 16:02:57 +0200	LEX	Lila	MESSAGE	IP Protection stopped successfully
2013/05/22 16:02:57 +0200	LEX	Lila	MESSAGE	Protection stopped
          | 
|  12.08.2013, 11:14 | #6 | 
| /// Winkelfunktion /// TB-Süch-Tiger™       |   Im Browser ist überall WerbungCode: 
  ATTFilter 127.0.0.1 activate.adobe.com
127.0.0.1 practivate.adobe.com
127.0.0.1 ereg.adobe.com
127.0.0.1 activate.wip3.adobe.com
127.0.0.1 wip3.adobe.com
127.0.0.1 3dns-3.adobe.com
127.0.0.1 3dns-2.adobe.com
127.0.0.1 adobe-dns.adobe.com
127.0.0.1 adobe-dns-2.adobe.com
127.0.0.1 adobe-dns-3.adobe.com
127.0.0.1 ereg.wip3.adobe.com
127.0.0.1 activate-sea.adobe.com
127.0.0.1 pagead2.googlesyndication.com
127.0.0.1 wwis-dubc1-vip60.adobe.com
127.0.0.1 activate-sjc0.adobe.com
          Bitte lesen => http://www.trojaner-board.de/95393-c...-software.html Es geht weiter wenn du alles Illegale entfernt hast. Bei wiederholten Crack/Keygen Verstößen behalte ich es mir vor, den Support einzustellen, d.h. Hilfe nur noch bei der Datensicherung und Neuinstallation des Betriebssystems. 
				__________________ --> Im Browser ist überall Werbung | 
|  12.08.2013, 11:41 | #7 | 
|   |   Im Browser ist überall Werbung alles entfernt  | 
|  12.08.2013, 11:47 | #8 | 
| /// Winkelfunktion /// TB-Süch-Tiger™       |   Im Browser ist überall Werbung Wirklich alles? Alles an Bezahlsoftware von Adobe und evtl andere "geklaute" Software sowie noch etwaig vorhandene Cracks/Keygens? Wenn ja bitte frische Logs mit FRST machen 
				__________________ Logfiles bitte immer in CODE-Tags posten   | 
|  12.08.2013, 11:51 | #9 | |
|   |   Im Browser ist überall WerbungZitat: 
 Falls noch weiß da sein sollte, bitte darauf aufmerksam machen. Habe es nach besten Wissen und Gewissen entfernt. FRST Logfile: FRST Logfile: Code: 
  ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-08-2013 02
Ran by Lila (administrator) on 12-08-2013 12:48:35
Running from C:\Users\Lila\Downloads
Windows 7 Professional N Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
() C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Lucidlogix Technologies\VIRTU MVP\MVPControlPanel.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Software Security System) C:\Program Files\Lucidlogix Technologies\VIRTU MVP\EKAG20NT.EXE
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Wacom Technology, Corp.) C:\Windows\system32\WTablet\Wacom_TabletUser.exe
(Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\system32\msiexec.exe
(Google Inc.) C:\Users\Lila\AppData\Local\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Lila\Downloads\FRST64 (1).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor)
HKLM\...\Run: [VIRTU_MVP_AUTORUN] - C:\Program Files\Lucidlogix Technologies\VIRTU MVP\MVPControlPanel.Exe [3010336 2012-02-05] ()
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [6330568 2013-03-21] (ESET)
HKCU\...\Run: [monqt] - "C:\Users\Lila\AppData\Roaming\monqt.exe" -autorun [x]
HKCU\...\Run: [execzswin] - "C:\Users\Lila\AppData\Roaming\execzswin.exe" -autorun [x]
HKCU\...\Run: [Personal ID] - C:\PROGRA~2\COOLSP~1\PERSON~1\PID.EXE [1132984 2013-06-04] (coolspot AG, Düsseldorf)
HKCU\...\Run: [Google Update] - C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [116648 2013-06-12] (Google Inc.)
MountPoints2: {82158879-8593-11e2-bb98-bc5ff46c2d53} - J:\SETUP.EXE /AUTORUN
MountPoints2: {d76096d7-828c-11e2-a2a9-806e6f6e6963} - I:\ASRSetup.exe
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-26] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.)
AppInit_DLLs: C:\Windows\system32\appinit_dll.dll [475424 2012-02-05] (Lucidlogix Inc.)
AppInit_DLLs-x32: C:\Windows\SysWOW64\appinit_dll.dll [429856 2012-02-05] (Lucidlogix Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
SearchScopes: HKLM - DefaultScope value is missing.
BHO-x32: LyricsContainer - {cd5dab32-3ff2-4712-8174-368d25f096bf} - C:\Program Files (x86)\LyricsContainer\126.dll (LyricsContainer)
Handler: msdaipp - No CLSID Value - 
Handler-x32: msdaipp - No CLSID Value - 
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default
FF user.js: detected! => C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default\user.js
FF Homepage: www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Lila\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Lila\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: No Name - C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKCU\...\Firefox\Extensions: [Lyrics@LyricsContainer.co] C:\Program Files (x86)\LyricsContainer\126.xpi
FF Extension: No Name - C:\Program Files (x86)\LyricsContainer\126.xpi
Chrome: 
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\Lila\AppData\Local\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Lila\AppData\Local\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Lila\AppData\Local\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Browser\nppdf32.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Google Update) - C:\Users\Lila\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
CHR Extension: (LyricsContainer) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\abfmigjiaapipflmopkaaooigcjjdojh\1.126_0
CHR Extension: (Google Docs) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.4_0
CHR Extension: (Gmail) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
CHR HKLM-x32\...\Chrome\Extension: [abfmigjiaapipflmopkaaooigcjjdojh] - C:\Program Files (x86)\LyricsContainer\126.crx
==================== Services (Whitelisted) =================
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1341664 2013-03-21] (ESET)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [121344 2012-02-07] ()
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 TabletServiceWacom; C:\Windows\system32\Wacom_Tablet.exe [1908520 2007-09-07] (Wacom Technology, Corp.)
==================== Drivers (Whitelisted) ====================
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-03-05] (DT Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [213416 2013-02-14] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [150616 2013-01-10] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [190232 2013-01-10] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [59440 2013-01-10] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [58416 2013-02-14] (ESET)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [926824 2012-05-14] (Realtek Semiconductor Corporation                           )
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-08-12] ()
S3 cleanhlp; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-12 11:15 - 2013-08-12 11:15 - 00000000 ____D C:\FRST
2013-08-12 11:14 - 2013-08-12 11:14 - 01575246 _____ (Farbar) C:\Users\Lila\Downloads\FRST64.exe
2013-08-11 23:18 - 2013-08-11 23:18 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Lila\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-11 23:18 - 2013-08-11 23:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-11 23:18 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-11 23:11 - 2013-08-11 23:19 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-11 22:58 - 2013-08-12 11:07 - 00000396 _____ C:\Windows\Tasks\LyricsContainer Update.job
2013-08-11 22:58 - 2013-08-11 22:58 - 00003042 _____ C:\Windows\System32\Tasks\LyricsContainer Update
2013-08-11 22:58 - 2013-08-11 22:58 - 00000000 ____D C:\Program Files (x86)\LyricsContainer
2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\ProgramData\ESET
2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\Program Files\ESET
2013-08-07 22:41 - 2013-08-07 22:41 - 01415824 _____ (ESET) C:\Users\Lila\Downloads\eset_smart_security_live_installer.exe
2013-08-07 22:34 - 2013-08-07 22:35 - 187378056 _____ (Emsisoft GmbH                                               ) C:\Users\Lila\Downloads\EmsisoftAntiMalwareSetup (1).exe
2013-07-28 21:31 - 2013-07-28 21:31 - 00819705 _____ C:\Users\Lila\Downloads\wie_gewinne_ich.rar
2013-07-21 22:33 - 2013-07-21 22:59 - 00000000 ____D C:\Users\Lila\Downloads\Treiber
2013-07-14 00:43 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-14 00:43 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-14 00:43 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-14 00:43 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-14 00:43 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-14 00:43 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-14 00:43 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-14 00:43 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-14 00:43 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-14 00:43 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-14 00:43 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-14 00:43 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-14 00:43 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-14 00:43 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-14 00:43 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-14 00:43 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-14 00:43 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-14 00:43 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-14 00:43 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-14 00:43 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-14 00:43 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-14 00:41 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-14 00:41 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-14 00:41 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-14 00:41 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-14 00:41 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-14 00:40 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-14 00:40 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
==================== One Month Modified Files and Folders =======
2013-08-12 12:40 - 2013-03-05 15:15 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-08-12 12:40 - 2013-03-01 20:47 - 00000000 ____D C:\Users\Lila\AppData\Roaming\Adobe
2013-08-12 12:39 - 2013-03-05 15:16 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-08-12 12:39 - 2013-03-01 20:46 - 00000000 ____D C:\ProgramData\Adobe
2013-08-12 12:35 - 2013-03-05 15:15 - 00000000 ____D C:\Users\Lila\AppData\Local\Adobe
2013-08-12 12:32 - 2011-04-12 10:14 - 00653928 _____ C:\Windows\system32\perfh007.dat
2013-08-12 12:32 - 2011-04-12 10:14 - 00129800 _____ C:\Windows\system32\perfc007.dat
2013-08-12 12:32 - 2009-07-14 07:12 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-12 12:23 - 2013-06-12 13:00 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job
2013-08-12 12:23 - 2013-06-12 13:00 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job
2013-08-12 11:18 - 2009-07-14 06:50 - 00020112 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-12 11:18 - 2009-07-14 06:50 - 00020112 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-12 11:15 - 2013-08-12 11:15 - 00000000 ____D C:\FRST
2013-08-12 11:14 - 2013-08-12 11:14 - 01575246 _____ (Farbar) C:\Users\Lila\Downloads\FRST64.exe
2013-08-12 11:07 - 2013-08-11 22:58 - 00000396 _____ C:\Windows\Tasks\LyricsContainer Update.job
2013-08-12 11:07 - 2013-03-01 20:59 - 00000000 ____D C:\Users\Lila\AppData\Roaming\WTablet
2013-08-12 11:07 - 2013-03-01 18:38 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2013-08-12 11:07 - 2013-03-01 18:30 - 01278719 _____ C:\Windows\WindowsUpdate.log
2013-08-12 11:06 - 2013-06-26 02:28 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2013-08-12 11:06 - 2013-03-01 18:40 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2013-08-12 11:06 - 2010-11-21 05:47 - 00083888 _____ C:\Windows\PFRO.log
2013-08-12 11:06 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-12 11:06 - 2009-07-14 06:56 - 00047138 _____ C:\Windows\setupact.log
2013-08-12 00:43 - 2013-03-22 21:17 - 00000000 ____D C:\Users\Lila\AppData\Roaming\UseNeXT
2013-08-11 23:19 - 2013-08-11 23:11 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-11 23:18 - 2013-08-11 23:18 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Lila\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-11 23:18 - 2013-08-11 23:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-11 22:58 - 2013-08-11 22:58 - 00003042 _____ C:\Windows\System32\Tasks\LyricsContainer Update
2013-08-11 22:58 - 2013-08-11 22:58 - 00000000 ____D C:\Program Files (x86)\LyricsContainer
2013-08-11 22:45 - 2013-05-15 20:43 - 00000000 ____D C:\Users\Lila\AppData\Roaming\vlc
2013-08-11 16:26 - 2013-03-01 18:38 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2013-08-11 13:25 - 2013-03-07 20:46 - 00003906 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{AE5A86A8-D88D-40C8-AA45-438AD91DF71B}
2013-08-08 10:25 - 2013-06-27 23:41 - 00000000 ____D C:\Users\Lila\Documents\Anti-Malware
2013-08-08 10:25 - 2013-06-27 23:41 - 00000000 ____D C:\Program Files (x86)\Emsisoft Anti-Malware
2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\ProgramData\ESET
2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\Program Files\ESET
2013-08-07 22:41 - 2013-08-07 22:41 - 01415824 _____ (ESET) C:\Users\Lila\Downloads\eset_smart_security_live_installer.exe
2013-08-07 22:35 - 2013-08-07 22:34 - 187378056 _____ (Emsisoft GmbH                                               ) C:\Users\Lila\Downloads\EmsisoftAntiMalwareSetup (1).exe
2013-08-05 12:29 - 2013-04-06 16:37 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-08-02 01:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-07-28 21:31 - 2013-07-28 21:31 - 00819705 _____ C:\Users\Lila\Downloads\wie_gewinne_ich.rar
2013-07-21 22:59 - 2013-07-21 22:33 - 00000000 ____D C:\Users\Lila\Downloads\Treiber
2013-07-14 14:18 - 2013-05-02 20:01 - 00000000 ____D C:\Users\Lila\AppData\Local\CrashDumps
2013-07-14 11:27 - 2009-07-14 06:50 - 03045624 _____ C:\Windows\system32\FNTCACHE.DAT
2013-07-14 01:23 - 2011-04-12 10:24 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-14 01:23 - 2009-07-14 07:38 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-14 01:23 - 2009-07-14 07:38 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-14 00:44 - 2013-03-01 18:57 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-07-13 12:18 - 2013-06-12 13:00 - 00004084 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA
2013-07-13 12:18 - 2013-06-12 13:00 - 00003688 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-02 15:09
==================== End Of Log ============================
         --- --- --- Code: 
  ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2013 02 Ran by Lila at 2013-08-12 12:53:39 Running from C:\Users\Lila\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 0.0.0) Acrobat.com (x32 Version: 1.2.443) Adobe AIR (x32 Version: 1.1.0.5790) Adobe Flash Player 10 ActiveX (x32 Version: 10.3.183.43) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.202) Adobe Media Player (x32 Version: 0.0.0) Adobe Media Player (x32 Version: 1.1) AMD Accelerated Video Transcoding (Version: 12.5.100.21219) AMD APP SDK Runtime (Version: 10.0.1084.4) AMD Catalyst Install Manager (Version: 8.0.903.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.71219.1540) Apple Application Support (x32 Version: 2.3) Apple Software Update (x32 Version: 2.1.3.127) Asmedia ASM106x SATA Host Controller Driver (x32 Version: 1.3.1.000) Canon IJ Scan Utility (x32) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32 Version: 4.0.0) Canon MG2200 series Benutzerregistrierung (x32) Canon MG2200 series MP Drivers (Version: 1.00) Canon MG2200 series On-screen Manual (x32 Version: 7.5.0) Canon My Printer (x32 Version: 3.0.0) Canon Quick Menu (x32 Version: 2.0.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485) Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485) CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485) CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485) CCC Help Czech (x32 Version: 2012.1219.1520.27485) CCC Help Danish (x32 Version: 2012.1219.1520.27485) CCC Help Dutch (x32 Version: 2012.1219.1520.27485) CCC Help English (x32 Version: 2012.1219.1520.27485) CCC Help Finnish (x32 Version: 2012.1219.1520.27485) CCC Help French (x32 Version: 2012.1219.1520.27485) CCC Help German (x32 Version: 2012.1219.1520.27485) CCC Help Greek (x32 Version: 2012.1219.1520.27485) CCC Help Hungarian (x32 Version: 2012.1219.1520.27485) CCC Help Italian (x32 Version: 2012.1219.1520.27485) CCC Help Japanese (x32 Version: 2012.1219.1520.27485) CCC Help Korean (x32 Version: 2012.1219.1520.27485) CCC Help Norwegian (x32 Version: 2012.1219.1520.27485) CCC Help Polish (x32 Version: 2012.1219.1520.27485) CCC Help Portuguese (x32 Version: 2012.1219.1520.27485) CCC Help Russian (x32 Version: 2012.1219.1520.27485) CCC Help Spanish (x32 Version: 2012.1219.1520.27485) CCC Help Swedish (x32 Version: 2012.1219.1520.27485) CCC Help Thai (x32 Version: 2012.1219.1520.27485) CCC Help Turkish (x32 Version: 2012.1219.1520.27485) ccc-utility64 (Version: 2012.1219.1521.27485) DAEMON Tools Lite (x32 Version: 4.46.1.0327) Easy Poster Printer (x32 Version: 6.0.0) ESET Smart Security (Version: 6.0.316.1) Google Chrome (HKCU Version: 28.0.1500.95) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: 1.0.0.35342) Intel(R) Management Engine Components (x32 Version: 8.0.2.1410) Intel(R) OpenCL CPU Runtime (x32) Intel(R) Processor Graphics (x32 Version: 8.15.10.2618) Intel(R) Rapid Storage Technology (x32 Version: 11.0.0.1032) Intel(R) Smart Connect Technology 2.0 x64 (Version: 2.0.1083.0) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.3.214) Intel® Trusted Connect Service Client (Version: 1.23.605.1) LyricsContainer (x32) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Professional Edition 2003 (x32 Version: 11.0.7969.0) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) ock App Charger v1.0.5 Personal ID (x32 Version: 1.8.5.202) Poker 770 (x32) PokerStars.eu (x32) PreFlopper (x32 Version: 2.1.0) QuickTime (x32 Version: 7.73.80.64) Realtek Ethernet Controller Driver (x32 Version: 7.48.823.2011) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6482) Secret City (x32 Version: 1.9.4662) Steam (x32 Version: 1.0.0.0) TP-LINK TL-WN821N Driver (x32 Version: 1.2.1) TrackMania Nations Forever (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) UseNeXT by Tangysoft (x32) VIRTU MVP 2.1.110 (Version: 2.1.110) VLC media player 2.0.6 (x32 Version: 2.0.6) Wacom Tablett (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 18-07-2013 14:20:47 Windows Update 25-07-2013 22:40:43 Geplanter Prüfpunkt 02-08-2013 20:07:36 Geplanter Prüfpunkt 07-08-2013 20:28:41 Windows Update ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-03-05 15:25 - 00001173 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 pagead2.googlesyndication.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 activate-sjc0.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {220145D2-20B3-4B48-AE44-52D59DE2FAF6} - System32\Tasks\User_Feed_Synchronization-{AE5A86A8-D88D-40C8-AA45-438AD91DF71B} => C:\Windows\system32\msfeedssync.exe [2013-05-22] (Microsoft Corporation) Task: {28336CC1-56F3-4285-84D2-51E7E572B6E6} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {3A95E0EA-4FEB-4A27-882A-D4A0E9043D22} - System32\Tasks\LyricsContainer Update => C:\Program Files (x86)\LyricsContainer\LrcsCtrUpdr.exe [2013-08-09] () Task: {52DB3FE1-FD35-49AE-A798-A031751E05F0} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {557A4CA9-1E48-4C36-8783-1250F4FA44A3} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {79B1D23E-D9E5-44CA-B2B4-EE322E0F6FB2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {9227EDEB-5C17-43F6-AF4C-1B3E91416116} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {CEA0F661-E4EF-4B0C-8174-747271058321} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {EBD67A4D-F364-42F2-94CA-DEA6B10D73FF} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\LyricsContainer Update.job => C:\Program Files (x86)\LyricsContainer\LrcsCtrUpdr.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== Error: (08/12/2013 00:29:03 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontexts für "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest1". Fehler in Manifest- oder Richtliniendatei "C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest2" in Zeile C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest3. Eine für die Anwendung erforderliche Komponentenversion steht in Konflikt mit einer anderen, bereits aktiven Komponentenversion. In Konflikt stehende Komponenten:. Komponente 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest. Komponente 2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest. Error: (08/12/2013 11:08:38 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 11:06:52 AM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/12/2013 11:06:51 AM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 11:25:23 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 11:23:37 PM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/11/2013 11:23:36 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 09:18:52 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 09:17:06 PM) (Source: TabletServiceWacom) (User: ) Description: Could not init tablet driver Error: (08/11/2013 09:17:05 PM) (Source: ISCT Agent) (User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 System errors: ============= Error: (08/12/2013 11:06:51 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 11:23:36 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 11:11:08 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "SProtection" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/11/2013 09:17:05 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/11/2013 01:20:00 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/09/2013 00:36:22 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/08/2013 10:56:54 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/08/2013 10:24:42 AM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Error: (08/07/2013 10:42:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "ESET Service" ist als interaktiver Dienst gekennzeichnet. Das System wurde jedoch so konfiguriert, dass interaktive Dienste nicht möglich sind. Der Dienst wird möglicherweise nicht richtig funktionieren. Error: (08/07/2013 10:36:39 PM) (Source: Microsoft-Windows-WLAN-AutoConfig) (User: NT-AUTORITÄT) Description: Das WLAN-Erweiterungsmodul konnte nicht gestartet werden. Modulpfad: C:\Windows\system32\Rtlihvs.dll Fehlercode: 126 Microsoft Office Sessions: ========================= Error: (08/12/2013 00:29:03 PM) (Source: SideBySide)(User: ) Description: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifestC:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifestF:\Programme\esetsmartinstaller_enu.exe Error: (08/12/2013 11:08:38 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/12/2013 11:06:52 AM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/12/2013 11:06:51 AM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 11:25:23 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 11:23:37 PM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/11/2013 11:23:36 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 Error: (08/11/2013 09:18:52 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (08/11/2013 09:17:06 PM) (Source: TabletServiceWacom)(User: ) Description: Could not init tablet driver Error: (08/11/2013 09:17:05 PM) (Source: ISCT Agent)(User: ) Description: CAgentState::DoPeriodicSuspendResume ****Error in initialize NetDetect, status = 0x2 ==================== Memory info =========================== Percentage of memory in use: 17% Total physical RAM: 16268.42 MB Available physical RAM: 13374.16 MB Total Pagefile: 32535.03 MB Available Pagefile: 29130.22 MB Total Virtual: 8192 MB Available Virtual: 8191.83 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.69 GB) (Free:53.77 GB) NTFS (Disk=0 Partition=2) Drive d: (Volume) (Fixed) (Total:931.51 GB) (Free:891.11 GB) NTFS (Disk=1 Partition=1) Drive e: (Ablage) (Fixed) (Total:10 GB) (Free:1.21 GB) NTFS (Disk=2 Partition=1) Drive f: (Datensammlung) (Fixed) (Total:50.01 GB) (Free:35.01 GB) NTFS (Disk=2 Partition=2) Drive g: (Musik) (Fixed) (Total:100.01 GB) (Free:96.2 GB) NTFS (Disk=2 Partition=3) Drive h: (Down) (Fixed) (Total:305.74 GB) (Free:225.94 GB) NTFS (Disk=2 Partition=4) Drive k: (EOS_DIGITAL) (Removable) (Total:14.93 GB) (Free:8.21 GB) FAT32 (Disk=3 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 862E84D4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: E792C529) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 466 GB) (Disk ID: 086D086C) Partition 1: (Active) - (Size=10 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=456 GB) - (Type=05) ======================================================== Disk: 3 (Size: 15 GB) (Disk ID: 00000000) Partition 1: (Active) - (Size=15 GB) - (Type=0C) ==================== End Of Log ============================ | 
|  12.08.2013, 11:53 | #10 | 
| /// Winkelfunktion /// TB-Süch-Tiger™       |   Im Browser ist überall Werbung Dann bitte jetzt Combofix ausführen: Scan mit Combofix 
 
				__________________ Logfiles bitte immer in CODE-Tags posten   | 
|  12.08.2013, 12:09 | #11 | 
|   |   Im Browser ist überall Werbung so hier nun das Ergebnis von combofix Code: 
  ATTFilter ComboFix 13-08-12.01 - Lila 12.08.2013  12:58:57.1.4 - x64
Microsoft Windows 7 Professional N   6.1.7601.1.1252.49.1031.18.16268.14082 [GMT 2:00]
ausgeführt von:: c:\users\Lila\Desktop\ComboFix.exe
AV: ESET Smart Security 6.0 *Disabled/Updated* {77DEAFED-8149-104B-25A1-21771CA47CD1}
FW: ESET Personal Firewall *Disabled* {4FE52EC8-CB26-1113-0EFE-8842E2773BAA}
SP: ESET Smart Security 6.0 *Disabled/Updated* {CCBF4E09-A773-1FC5-1F11-1A056723366C}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 * Neuer Wiederherstellungspunkt wurde erstellt
.
.
(((((((((((((((((((((((   Dateien erstellt von 2013-07-12 bis 2013-08-12  ))))))))))))))))))))))))))))))
.
.
2013-08-12 11:00 . 2013-08-12 11:00	--------	d-----w-	c:\users\Lila\AppData\Local\temp
2013-08-12 11:00 . 2013-08-12 11:00	--------	d-----w-	c:\users\Default\AppData\Local\temp
2013-08-12 09:15 . 2013-08-12 09:15	--------	d-----w-	C:\FRST
2013-08-11 21:18 . 2013-08-11 21:18	--------	d-----w-	c:\program files (x86)\Malwarebytes' Anti-Malware
2013-08-11 21:18 . 2013-04-04 12:50	25928	----a-w-	c:\windows\system32\drivers\mbam.sys
2013-08-11 20:58 . 2013-08-11 20:58	--------	d-----w-	c:\program files (x86)\LyricsContainer
2013-08-07 20:42 . 2013-08-07 20:42	--------	d-----w-	c:\program files\ESET
2013-08-07 20:28 . 2013-07-02 08:34	9460976	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{175FD02B-84FF-4450-B92D-0E3A769CA8DD}\mpengine.dll
2013-07-13 22:41 . 2013-06-05 03:34	3153920	----a-w-	c:\windows\system32\win32k.sys
2013-07-13 22:41 . 2013-05-06 06:03	1887744	----a-w-	c:\windows\system32\WMVDECOD.DLL
2013-07-13 22:41 . 2013-05-06 04:56	1620480	----a-w-	c:\windows\SysWow64\WMVDECOD.DLL
2013-07-13 22:41 . 2013-06-04 06:00	624128	----a-w-	c:\windows\system32\qedit.dll
2013-07-13 22:41 . 2013-06-04 04:53	509440	----a-w-	c:\windows\SysWow64\qedit.dll
.
.
.
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2013-08-12 09:06 . 2013-06-26 00:28	94656	----a-w-	c:\windows\system32\WPRO_41_2001woem.tmp
2013-08-12 09:06 . 2013-03-01 16:40	34752	----a-w-	c:\windows\system32\drivers\WPRO_41_2001.sys
2013-07-13 22:44 . 2013-03-01 16:57	78185248	----a-w-	c:\windows\system32\MRT.exe
2013-06-04 00:09 . 2013-03-01 18:47	404920	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-05-28 13:49 . 2013-03-01 18:47	692104	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-05-22 14:48 . 2013-05-22 14:48	73728	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2013-05-22 14:48 . 2013-05-22 14:48	719360	----a-w-	c:\windows\SysWow64\mshtmlmedia.dll
2013-05-22 14:48 . 2013-05-22 14:48	61952	----a-w-	c:\windows\SysWow64\tdc.ocx
2013-05-22 14:48 . 2013-05-22 14:48	523264	----a-w-	c:\windows\SysWow64\vbscript.dll
2013-05-22 14:48 . 2013-05-22 14:48	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2013-05-22 14:48 . 2013-05-22 14:48	38400	----a-w-	c:\windows\SysWow64\imgutil.dll
2013-05-22 14:48 . 2013-05-22 14:48	361984	----a-w-	c:\windows\SysWow64\html.iec
2013-05-22 14:48 . 2013-05-22 14:48	226304	----a-w-	c:\windows\system32\elshyph.dll
2013-05-22 14:48 . 2013-05-22 14:48	185344	----a-w-	c:\windows\SysWow64\elshyph.dll
2013-05-22 14:48 . 2013-05-22 14:48	158720	----a-w-	c:\windows\SysWow64\msls31.dll
2013-05-22 14:48 . 2013-05-22 14:48	150528	----a-w-	c:\windows\SysWow64\iexpress.exe
2013-05-22 14:48 . 2013-05-22 14:48	1441280	----a-w-	c:\windows\SysWow64\inetcpl.cpl
2013-05-22 14:48 . 2013-05-22 14:48	138752	----a-w-	c:\windows\SysWow64\wextract.exe
2013-05-22 14:48 . 2013-05-22 14:48	137216	----a-w-	c:\windows\SysWow64\ieUnatt.exe
2013-05-22 14:48 . 2013-05-22 14:48	12800	----a-w-	c:\windows\SysWow64\mshta.exe
2013-05-22 14:48 . 2013-05-22 14:48	110592	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2013-05-22 14:48 . 2013-05-22 14:48	1054720	----a-w-	c:\windows\system32\MsSpellCheckingFacility.exe
2013-05-22 14:48 . 2013-05-22 14:48	97280	----a-w-	c:\windows\system32\mshtmled.dll
2013-05-22 14:48 . 2013-05-22 14:48	92160	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2013-05-22 14:48 . 2013-05-22 14:48	905728	----a-w-	c:\windows\system32\mshtmlmedia.dll
2013-05-22 14:48 . 2013-05-22 14:48	81408	----a-w-	c:\windows\system32\icardie.dll
2013-05-22 14:48 . 2013-05-22 14:48	77312	----a-w-	c:\windows\system32\tdc.ocx
2013-05-22 14:48 . 2013-05-22 14:48	762368	----a-w-	c:\windows\system32\ieapfltr.dll
2013-05-22 14:48 . 2013-05-22 14:48	62976	----a-w-	c:\windows\system32\pngfilt.dll
2013-05-22 14:48 . 2013-05-22 14:48	599552	----a-w-	c:\windows\system32\vbscript.dll
2013-05-22 14:48 . 2013-05-22 14:48	52224	----a-w-	c:\windows\system32\msfeedsbs.dll
2013-05-22 14:48 . 2013-05-22 14:48	51200	----a-w-	c:\windows\system32\imgutil.dll
2013-05-22 14:48 . 2013-05-22 14:48	48640	----a-w-	c:\windows\system32\mshtmler.dll
2013-05-22 14:48 . 2013-05-22 14:48	452096	----a-w-	c:\windows\system32\dxtmsft.dll
2013-05-22 14:48 . 2013-05-22 14:48	441856	----a-w-	c:\windows\system32\html.iec
2013-05-22 14:48 . 2013-05-22 14:48	281600	----a-w-	c:\windows\system32\dxtrans.dll
2013-05-22 14:48 . 2013-05-22 14:48	27648	----a-w-	c:\windows\system32\licmgr10.dll
2013-05-22 14:48 . 2013-05-22 14:48	270848	----a-w-	c:\windows\system32\iedkcs32.dll
2013-05-22 14:48 . 2013-05-22 14:48	247296	----a-w-	c:\windows\system32\webcheck.dll
2013-05-22 14:48 . 2013-05-22 14:48	235008	----a-w-	c:\windows\system32\url.dll
2013-05-22 14:48 . 2013-05-22 14:48	23040	----a-w-	c:\windows\SysWow64\licmgr10.dll
2013-05-22 14:48 . 2013-05-22 14:48	216064	----a-w-	c:\windows\system32\msls31.dll
2013-05-22 14:48 . 2013-05-22 14:48	197120	----a-w-	c:\windows\system32\msrating.dll
2013-05-22 14:48 . 2013-05-22 14:48	173568	----a-w-	c:\windows\system32\ieUnatt.exe
2013-05-22 14:48 . 2013-05-22 14:48	167424	----a-w-	c:\windows\system32\iexpress.exe
2013-05-22 14:48 . 2013-05-22 14:48	1509376	----a-w-	c:\windows\system32\inetcpl.cpl
2013-05-22 14:48 . 2013-05-22 14:48	149504	----a-w-	c:\windows\system32\occache.dll
2013-05-22 14:48 . 2013-05-22 14:48	144896	----a-w-	c:\windows\system32\wextract.exe
2013-05-22 14:48 . 2013-05-22 14:48	1400416	----a-w-	c:\windows\system32\ieapfltr.dat
2013-05-22 14:48 . 2013-05-22 14:48	13824	----a-w-	c:\windows\system32\mshta.exe
2013-05-22 14:48 . 2013-05-22 14:48	136192	----a-w-	c:\windows\system32\iepeers.dll
2013-05-22 14:48 . 2013-05-22 14:48	135680	----a-w-	c:\windows\system32\IEAdvpack.dll
2013-05-22 14:48 . 2013-05-22 14:48	12800	----a-w-	c:\windows\system32\msfeedssync.exe
2013-05-22 14:48 . 2013-05-22 14:48	102912	----a-w-	c:\windows\system32\inseng.dll
2013-05-22 14:48 . 2013-05-22 14:48	9728	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	9728	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	5632	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	5632	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	5632	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	5632	---ha-w-	c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	522752	----a-w-	c:\windows\system32\XpsGdiConverter.dll
2013-05-22 14:48 . 2013-05-22 14:48	465920	----a-w-	c:\windows\system32\WMPhoto.dll
2013-05-22 14:48 . 2013-05-22 14:48	417792	----a-w-	c:\windows\SysWow64\WMPhoto.dll
2013-05-22 14:48 . 2013-05-22 14:48	4096	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	4096	---ha-w-	c:\windows\system32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	3928064	----a-w-	c:\windows\system32\d2d1.dll
2013-05-22 14:48 . 2013-05-22 14:48	364544	----a-w-	c:\windows\SysWow64\XpsGdiConverter.dll
2013-05-22 14:48 . 2013-05-22 14:48	3584	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	3584	---ha-w-	c:\windows\system32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	3072	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	3072	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	3072	---ha-w-	c:\windows\system32\api-ms-win-downlevel-version-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	3072	---ha-w-	c:\windows\system32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	2776576	----a-w-	c:\windows\system32\msmpeg2vdec.dll
2013-05-22 14:48 . 2013-05-22 14:48	2565120	----a-w-	c:\windows\system32\d3d10warp.dll
2013-05-22 14:48 . 2013-05-22 14:48	2560	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	2560	---ha-w-	c:\windows\system32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	2284544	----a-w-	c:\windows\SysWow64\msmpeg2vdec.dll
2013-05-22 14:48 . 2013-05-22 14:48	1682432	----a-w-	c:\windows\system32\XpsPrint.dll
2013-05-22 14:48 . 2013-05-22 14:48	1158144	----a-w-	c:\windows\SysWow64\XpsPrint.dll
2013-05-22 14:48 . 2013-05-22 14:48	10752	---ha-w-	c:\windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	10752	---ha-w-	c:\windows\system32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-05-22 14:48 . 2013-05-22 14:48	648192	----a-w-	c:\windows\system32\d3d10level9.dll
2013-05-22 14:48 . 2013-05-22 14:48	604160	----a-w-	c:\windows\SysWow64\d3d10level9.dll
2013-05-22 14:48 . 2013-05-22 14:48	363008	----a-w-	c:\windows\system32\dxgi.dll
2013-05-22 14:48 . 2013-05-22 14:48	3419136	----a-w-	c:\windows\SysWow64\d2d1.dll
2013-05-22 14:48 . 2013-05-22 14:48	333312	----a-w-	c:\windows\system32\d3d10_1core.dll
2013-05-22 14:48 . 2013-05-22 14:48	296960	----a-w-	c:\windows\system32\d3d10core.dll
2013-05-22 14:48 . 2013-05-22 14:48	249856	----a-w-	c:\windows\SysWow64\d3d10_1core.dll
2013-05-22 14:48 . 2013-05-22 14:48	245248	----a-w-	c:\windows\system32\WindowsCodecsExt.dll
2013-05-22 14:48 . 2013-05-22 14:48	220160	----a-w-	c:\windows\SysWow64\d3d10core.dll
2013-05-22 14:48 . 2013-05-22 14:48	207872	----a-w-	c:\windows\SysWow64\WindowsCodecsExt.dll
2013-05-22 14:48 . 2013-05-22 14:48	194560	----a-w-	c:\windows\system32\d3d10_1.dll
2013-05-22 14:48 . 2013-05-22 14:48	161792	----a-w-	c:\windows\SysWow64\d3d10_1.dll
2013-05-22 14:48 . 2013-05-22 14:48	1238528	----a-w-	c:\windows\system32\d3d10.dll
2013-05-22 14:48 . 2013-05-22 14:48	1175552	----a-w-	c:\windows\system32\FntCache.dll
2013-05-22 14:48 . 2013-05-22 14:48	1080832	----a-w-	c:\windows\SysWow64\d3d10.dll
2013-05-22 14:48 . 2013-05-22 14:48	293376	----a-w-	c:\windows\SysWow64\dxgi.dll
2013-05-22 14:48 . 2013-05-22 14:48	221184	----a-w-	c:\windows\system32\UIAnimation.dll
2013-05-22 14:48 . 2013-05-22 14:48	1988096	----a-w-	c:\windows\SysWow64\d3d10warp.dll
.
.
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
REGEDIT4
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{cd5dab32-3ff2-4712-8174-368d25f096bf}]
2013-08-09 15:16	134656	----a-w-	c:\program files (x86)\LyricsContainer\126.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"Personal ID"="c:\progra~2\COOLSP~1\PERSON~1\PID.EXE" [2013-06-04 1132984]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"IAStorIcon"="c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe" [2011-11-29 284440]
"USB3MON"="c:\program files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe" [2012-01-26 291608]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-12-19 642808]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
"AppInit_DLLs"=c:\windows\SysWOW64\appinit_dll.dll
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 Intel(R) ME Service;Intel(R) ME Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [x]
R3 cleanhlp;cleanhlp;c:\program files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys;c:\program files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [x]
R3 dmvsc;dmvsc;c:\windows\system32\drivers\dmvsc.sys;c:\windows\SYSNATIVE\drivers\dmvsc.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
S0 asahci64;asahci64;c:\windows\system32\DRIVERS\asahci64.sys;c:\windows\SYSNATIVE\DRIVERS\asahci64.sys [x]
S0 epfwwfp;epfwwfp;c:\windows\system32\DRIVERS\epfwwfp.sys;c:\windows\SYSNATIVE\DRIVERS\epfwwfp.sys [x]
S0 iusb3hcs;Intel(R) USB 3.0 Hostcontroller-Switchtreiber;c:\windows\system32\DRIVERS\iusb3hcs.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hcs.sys [x]
S1 AsrAppCharger;AsrAppCharger;c:\windows\system32\DRIVERS\AsrAppCharger.sys;c:\windows\SYSNATIVE\DRIVERS\AsrAppCharger.sys [x]
S1 dtsoftbus01;DAEMON Tools Virtual Bus Driver;c:\windows\system32\DRIVERS\dtsoftbus01.sys;c:\windows\SYSNATIVE\DRIVERS\dtsoftbus01.sys [x]
S1 eamonm;eamonm;c:\windows\system32\DRIVERS\eamonm.sys;c:\windows\SYSNATIVE\DRIVERS\eamonm.sys [x]
S1 ehdrv;ehdrv;c:\windows\system32\DRIVERS\ehdrv.sys;c:\windows\SYSNATIVE\DRIVERS\ehdrv.sys [x]
S1 EpfwLWF;Epfw NDIS LightWeight Filter;c:\windows\system32\DRIVERS\EpfwLWF.sys;c:\windows\SYSNATIVE\DRIVERS\EpfwLWF.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 ekrn;ESET Service;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe;c:\program files\ESET\ESET Smart Security\x86\ekrn.exe [x]
S2 IAStorDataMgrSvc;Intel(R) Rapid Storage Technology;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe;c:\program files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe [x]
S2 Intel(R) Capability Licensing Service Interface;Intel(R) Capability Licensing Service Interface;c:\program files\Intel\iCLS Client\HeciServer.exe;c:\program files\Intel\iCLS Client\HeciServer.exe [x]
S2 ISCTAgent;ISCT Always Updated Agent;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe;c:\program files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [x]
S2 jhi_service;Intel(R) Dynamic Application Loader Host Interface Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [x]
S2 MBAMScheduler;MBAMScheduler;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [x]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [x]
S2 TabletServiceWacom;TabletServiceWacom;c:\windows\system32\Wacom_Tablet.exe;c:\windows\SYSNATIVE\Wacom_Tablet.exe [x]
S2 UNS;Intel(R) Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe;c:\program files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe [x]
S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys;c:\windows\SYSNATIVE\drivers\AtihdW76.sys [x]
S3 ikbevent;Intel Upper keyboard Class Filter Driver;c:\windows\system32\DRIVERS\ikbevent.sys;c:\windows\SYSNATIVE\DRIVERS\ikbevent.sys [x]
S3 imsevent;Intel Upper Mouse Class Filter Driver;c:\windows\system32\DRIVERS\imsevent.sys;c:\windows\SYSNATIVE\DRIVERS\imsevent.sys [x]
S3 IntcDAud;Intel(R) Display-Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 ISCT;Intel(R) Smart Connect Technology Device Driver;c:\windows\system32\DRIVERS\ISCTD64.sys;c:\windows\SYSNATIVE\DRIVERS\ISCTD64.sys [x]
S3 iusb3hub;Intel(R) USB 3.0-Hubtreiber;c:\windows\system32\DRIVERS\iusb3hub.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3hub.sys [x]
S3 iusb3xhc;Intel(R) USB 3.0 eXtensible-Hostcontrollertreiber;c:\windows\system32\DRIVERS\iusb3xhc.sys;c:\windows\SYSNATIVE\DRIVERS\iusb3xhc.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys;c:\windows\SYSNATIVE\drivers\mbam.sys [x]
S3 MBfilt;MBfilt;c:\windows\system32\drivers\MBfilt64.sys;c:\windows\SYSNATIVE\drivers\MBfilt64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 RTL8192cu;300Mbps Wireless USB Adapter;c:\windows\system32\DRIVERS\RTL8192cu.sys;c:\windows\SYSNATIVE\DRIVERS\RTL8192cu.sys [x]
S3 VirtuWDDM;VirtuWDDM;c:\windows\system32\DRIVERS\VirtuWDDM.sys;c:\windows\SYSNATIVE\DRIVERS\VirtuWDDM.sys [x]
S3 WPRO_41_2001;WinPcap Packet Driver (WPRO_41_2001);c:\windows\system32\drivers\WPRO_41_2001.sys;c:\windows\SYSNATIVE\drivers\WPRO_41_2001.sys [x]
.
.
Inhalt des "geplante Tasks" Ordners
.
2013-08-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job
- c:\users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12 11:00]
.
2013-08-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job
- c:\users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12 11:00]
.
2013-08-12 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 12:41]
.
2013-08-11 c:\windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
- c:\program files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25 12:41]
.
2013-08-12 c:\windows\Tasks\LyricsContainer Update.job
- c:\program files (x86)\LyricsContainer\LrcsCtrUpdr.exe [2013-08-09 15:16]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2012-01-12 170264]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2012-01-12 398104]
"Persistence"="c:\windows\system32\igfxpers.exe" [2012-01-12 440600]
"RTHDVCPL"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-10-17 13307496]
"egui"="c:\program files\ESET\ESET Smart Security\egui.exe" [2013-03-21 6330568]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"AppInit_DLLs"=c:\windows\System32\appinit_dll.dll
.
------- Zusätzlicher Suchlauf -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://www.google.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer = 192.168.178.1
FF - ProfilePath - c:\users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default\
FF - prefs.js: browser.startup.homepage - www.google.de/
FF - ExtSQL: 2013-08-11 22:58; Lyrics@LyricsContainer.co; c:\program files (x86)\LyricsContainer\126.xpi
FF - user.js: extensions.autoDisableScopes - 0
FF - user.js: extensions.shownSelectionUI - true
.
.
------- Dateityp-Verknüpfung -------
.
.txt=
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
.
Wow6432Node-HKCU-Run-monqt - c:\users\Lila\AppData\Roaming\monqt.exe
Wow6432Node-HKCU-Run-execzswin - c:\users\Lila\AppData\Roaming\execzswin.exe
SafeBoot-CleanHlp
SafeBoot-CleanHlp.sys
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
HKLM-Run-VIRTU_MVP_AUTORUN - c:\program files (x86)\Lucidlogix Technologies\VIRTU MVP\MVPControlPanel.Exe
.
.
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10zi_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10zi_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10zi.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10zi.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10zi.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10zi.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Zeit der Fertigstellung: 2013-08-12  13:01:48
ComboFix-quarantined-files.txt  2013-08-12 11:01
.
Vor Suchlauf: 10 Verzeichnis(se), 59.033.051.136 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 61.460.643.840 Bytes frei
.
- - End Of File - - D235FC345398072FF3AC0596D9F0DC15
D41D8CD98F00B204E9800998ECF8427E
          | 
|  12.08.2013, 12:27 | #12 | 
| /// Winkelfunktion /// TB-Süch-Tiger™       |   Im Browser ist überall Werbung Adware/Junkware/Toolbars entfernen 1. Schritt: adwCleaner Downloade Dir bitte  AdwCleaner auf deinen Desktop. 
 2. Schritt: JRT - Junkware Removal Tool Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu   vermeiden. 
 3. Schritt: Frisches Log mit FRST Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop:  FRST 32-Bit | FRST   64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen) 
 
				__________________ Logfiles bitte immer in CODE-Tags posten   | 
|  12.08.2013, 12:46 | #13 | 
|   |   Im Browser ist überall Werbung Hier nun die Ergebnisse Code: 
  ATTFilter # AdwCleaner v2.306 - Datei am 12/08/2013 um 13:34:23 erstellt
# Aktualisiert am 19/07/2013 von Xplode
# Betriebssystem : Windows 7 Professional N Service Pack 1 (64 bits)
# Benutzer : Lila - LEX
# Bootmodus : Normal
# Ausgeführt unter : C:\Users\Lila\Desktop\adwcleaner.exe
# Option [Löschen]
**** [Dienste] ****
***** [Dateien / Ordner] *****
Datei Gelöscht : C:\Windows\Tasks\LyricsContainer Update.job
Ordner Gelöscht : C:\Program Files (x86)\LyricsContainer
Ordner Gelöscht : C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\abfmigjiaapipflmopkaaooigcjjdojh
***** [Registrierungsdatenbank] *****
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\LyricsContainer
Schlüssel Gelöscht : HKCU\Software\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{2BF2028E-3F3C-4C05-AB45-B2F1DCFE0759}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{DB538320-D3C5-433C-BCA9-C4081A054FCF}
Schlüssel Gelöscht : HKLM\Software\Iminent
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Iminent_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02054E11-5113-4BE3-8153-AA8DFB5D3761}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\abfmigjiaapipflmopkaaooigcjjdojh
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68B81CCD-A80C-4060-8947-5AE69ED01199}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{E6B969FB-6D33-48D2-9061-8BBD4899EB08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Lyrics@LyricsContainer.co
Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\SearchTheWebARP
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{021B4049-F57D-4565-A693-FD3B04786BFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0362AA09-808D-48E9-B360-FB51A8CBCE09}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{06844020-CD0B-3D3D-A7FE-371153013E49}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{0ADC01BB-303B-3F8E-93DA-12C140E85460}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{10D3722F-23E6-3901-B6C1-FF6567121920}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{1675E62B-F911-3B7B-A046-EB57261212F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{192929F2-9273-3894-91B0-F54671C4C861}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2932897E-3036-43D9-8A64-B06447992065}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{2DE92D29-A042-3C37-BFF8-07C7D8893EFA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{32B80AD6-1214-45F4-994E-78A5D482C000}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{3A8E103F-B2B7-3BEF-B3B0-88E29B2420E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{478CE5D3-D38E-3FFE-8DBE-8C4A0F1C4D8D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{48B7DA4E-69ED-39E3-BAD5-3E3EFF22CFB0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5982F405-44E4-3BBB-BAC4-CF8141CBBC5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{5D8C3CC3-3C05-38A1-B244-924A23115FE9}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{641593AF-D9FD-30F7-B783-36E16F7A2E08}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{711FC48A-1356-3932-94D8-A8B733DBC7E4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{72227B7F-1F02-3560-95F5-592E68BACC0C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{7B5E8CE3-4722-4C0E-A236-A6FF731BEF37}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{890D4F59-5ED0-3CB4-8E0E-74A5A86E7ED0}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8C68913C-AC3C-4494-8B9C-984D87C85003}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{8D019513-083F-4AA5-933F-7D43A6DA82C4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{923F6FB8-A390-370E-A0D2-DD505432481D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{9BBB26EF-B178-35D6-9D3D-B485F4279FE5}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A62DDBE0-8D2A-339A-B089-8CBCC5CD322A}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{A82AD04D-0B8E-3A49-947B-6A69A8A9C96D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ADEB3CC9-A05D-4FCC-BD09-9025456AA3EA}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{B06D4521-D09C-3F41-8E39-9D784CCA2A75}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C06DAD42-6F39-4CE1-83CC-9A8B9105E556}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{C2E799D0-43A5-3477-8A98-FC5F3677F35C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D16107CD-2AD5-46A8-BA59-303B7C32C500}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D25B101F-8188-3B43-9D85-201F372BC205}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D2BA7595-5E44-3F1E-880F-03B3139FA5ED}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D35F5C81-17D9-3E1C-A1FC-4472542E1D25}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{D8FA96CA-B250-312C-AF34-4FF1DD72589D}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DAFC1E63-3359-416D-9BC2-E7DCA6F7B0F3}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{DC5E5C44-80FD-3697-9E65-9F286D92F3E7}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E1B4C9DE-D741-385F-981E-6745FACE6F01}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{E7B623F5-9715-3F9F-A671-D1485A39F8A2}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{ED916A7B-7C68-3198-B87D-2DABC30A5587}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{EFA1BDB2-BB3D-3D9A-8EB5-D0D22E0F64F4}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{F4CBF4DD-F8FE-35BA-BB7E-68304DAAB70B}
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{FC32005D-E27C-32E0-ADFA-152F598B75E7}
***** [Internet Browser] *****
-\\ Internet Explorer v10.0.9200.16635
[OK] Die Registrierungsdatenbank ist sauber.
-\\ Mozilla Firefox v22.0 (de)
Datei : C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default\prefs.js
C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default\user.js ... Gelöscht !
[OK] Die Datei ist sauber.
-\\ Google Chrome v28.0.1500.95
Datei : C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Preferences
[OK] Die Datei ist sauber.
*************************
AdwCleaner[S1].txt - [11006 octets] - [12/08/2013 13:34:23]
########## EOF - C:\AdwCleaner[S1].txt - [11067 octets] ##########
         Code: 
  ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 5.4.4 (08.12.2013:1)
OS: Windows 7 Professional N x64
Ran by Lila on 12.08.2013 at 13:38:50,52
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~ Services
~~~ Registry Values
~~~ Registry Keys
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{cd5dab32-3ff2-4712-8174-368d25f096bf}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{cd5dab32-3ff2-4712-8174-368d25f096bf}
~~~ Files
~~~ Folders
~~~ FireFox
Successfully deleted: [Registry Value] HKEY_CURRENT_USER\Software\Mozilla\Firefox\Extensions\\lyrics@lyricscontainer.co
Emptied folder: C:\Users\Lila\AppData\Roaming\mozilla\firefox\profiles\jraj9lj2.default\minidumps [13 files]
~~~ Event Viewer Logs were cleared
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 12.08.2013 at 13:41:44,99
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
         Code: 
  ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 11-08-2013 02
Ran by Lila (administrator) on 12-08-2013 13:42:16
Running from C:\Users\Lila\Downloads
Windows 7 Professional N Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(Microsoft Corporation) C:\Windows\SYSTEM32\WISPTIS.EXE
(ESET) C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
() C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
(Intel(R) Corporation) C:\Program Files\Intel\iCLS Client\HeciServer.exe
() C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe
() C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files\Lucidlogix Technologies\VIRTU MVP\MVPControlPanel.exe
(ESET) C:\Program Files\ESET\ESET Smart Security\egui.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.exe
(Malwarebytes Corporation) C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Wacom Technology, Corp.) C:\Windows\system32\WTablet\Wacom_TabletUser.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Wacom Technology, Corp.) C:\Windows\system32\Wacom_Tablet.exe
(Software Security System) C:\Program Files\Lucidlogix Technologies\VIRTU MVP\EKAG20NT.EXE
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Microsoft Corporation) C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
(Microsoft Corporation) \\?\C:\Windows\system32\wbem\WMIADAP.EXE
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [RTHDVCPL] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13307496 2011-10-17] (Realtek Semiconductor)
HKLM\...\Run: [VIRTU_MVP_AUTORUN] - C:\Program Files\Lucidlogix Technologies\VIRTU MVP\MVPControlPanel.Exe [3010336 2012-02-05] ()
HKLM\...\Run: [egui] - C:\Program Files\ESET\ESET Smart Security\egui.exe [6330568 2013-03-21] (ESET)
HKCU\...\Run: [Personal ID] - C:\PROGRA~2\COOLSP~1\PERSON~1\PID.EXE [1132984 2013-06-04] (coolspot AG, Düsseldorf)
HKLM-x32\...\Run: [IAStorIcon] - C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [284440 2011-11-29] (Intel Corporation)
HKLM-x32\...\Run: [USB3MON] - C:\Program Files (x86)\Intel\Intel(R) USB 3.0 eXtensible Host Controller Driver\Application\iusb3mon.exe [291608 2012-01-26] (Intel Corporation)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642808 2012-12-19] (Advanced Micro Devices, Inc.)
AppInit_DLLs: C:\Windows\System32\appinit_dll.dll [475424 2012-02-05] (Lucidlogix Inc.)
AppInit_DLLs-x32: C:\Windows\SysWOW64\appinit_dll.dll [429856 2012-02-05] (Lucidlogix Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope value is missing.
Handler: msdaipp - No CLSID Value - 
Handler-x32: msdaipp - No CLSID Value - 
Filter: text/xml - {807553E5-5146-11D5-A672-00B0D022E945} -  No File
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default
FF Homepage: www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_202.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI ipt;version=2.0.59 - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF Plugin-x32: @intel-webapi.intel.com/Intel WebAPI updater - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.0.6 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Lila\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Lila\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF Extension: No Name - C:\Users\Lila\AppData\Roaming\Mozilla\Firefox\Profiles\jraj9lj2.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF HKLM-x32\...\Thunderbird\Extensions: [eplgTb@eset.com] C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
FF Extension: ESET Smart Security Extension - C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird
Chrome: 
=======
CHR DefaultSearchURL: (Google) - {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR DefaultSuggestURL: (Google) - {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Shockwave Flash) - C:\Users\Lila\AppData\Local\Google\Chrome\Application\28.0.1500.95\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Users\Lila\AppData\Local\Google\Chrome\Application\28.0.1500.95\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Users\Lila\AppData\Local\Google\Chrome\Application\28.0.1500.95\pdf.dll ()
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Acrobat 9.0\Acrobat\Browser\nppdf32.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.3) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll (Apple Inc.)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
CHR Plugin: (Intel\u00AE Identity Protection Technology) - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
CHR Plugin: (VLC Web Plugin) - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
CHR Plugin: (Google Update) - C:\Users\Lila\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Shockwave Flash) - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_202.dll ()
CHR Extension: (Google Docs) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0
CHR Extension: (Google Drive) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0
CHR Extension: (YouTube) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0
CHR Extension: (Google Search) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0
CHR Extension: (AdBlock) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.4_0
CHR Extension: (Gmail) - C:\Users\Lila\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0
==================== Services (Whitelisted) =================
R2 ekrn; C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe [1341664 2013-03-21] (ESET)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [140456 2012-03-28] ()
R2 Intel(R) ME Service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\FWService\IntelMeFWService.exe [121344 2012-02-07] ()
R2 ISCTAgent; C:\Program Files\Intel\Intel(R) Smart Connect Technology Agent\iSCTAgent.exe [133632 2012-02-09] ()
R2 jhi_service; C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\DAL\jhi_service.exe [161560 2012-02-07] (Intel Corporation)
R2 MBAMScheduler; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
R2 MBAMService; C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 TabletServiceWacom; C:\Windows\system32\Wacom_Tablet.exe [1908520 2007-09-07] (Wacom Technology, Corp.)
==================== Drivers (Whitelisted) ====================
R0 asahci64; C:\Windows\System32\DRIVERS\asahci64.sys [49760 2011-09-21] (Asmedia Technology)
R1 dtsoftbus01; C:\Windows\System32\DRIVERS\dtsoftbus01.sys [283200 2013-03-05] (DT Soft Ltd)
R1 eamonm; C:\Windows\System32\DRIVERS\eamonm.sys [213416 2013-02-14] (ESET)
R1 ehdrv; C:\Windows\System32\DRIVERS\ehdrv.sys [150616 2013-01-10] (ESET)
R2 epfw; C:\Windows\System32\DRIVERS\epfw.sys [190232 2013-01-10] (ESET)
R1 EpfwLWF; C:\Windows\System32\DRIVERS\EpfwLWF.sys [59440 2013-01-10] (ESET)
R0 epfwwfp; C:\Windows\System32\DRIVERS\epfwwfp.sys [58416 2013-02-14] (ESET)
R3 ikbevent; C:\Windows\System32\DRIVERS\ikbevent.sys [25536 2012-02-09] ()
R3 imsevent; C:\Windows\System32\DRIVERS\imsevent.sys [25536 2012-02-09] ()
R3 ISCT; C:\Windows\System32\DRIVERS\ISCTD64.sys [44992 2012-02-09] ()
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [25928 2013-04-04] (Malwarebytes Corporation)
R3 RTL8192cu; C:\Windows\System32\DRIVERS\RTL8192cu.sys [926824 2012-05-14] (Realtek Semiconductor Corporation                           )
R3 WPRO_41_2001; C:\Windows\System32\drivers\WPRO_41_2001.sys [34752 2013-08-12] ()
S3 cleanhlp; \??\C:\Program Files (x86)\Emsisoft Anti-Malware\cleanhlp64.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2013-08-12 13:38 - 2013-08-12 13:38 - 00000000 ____D C:\Windows\ERUNT
2013-08-12 13:37 - 2013-08-12 13:37 - 00011051 _____ C:\Users\Lila\Desktop\AdwCleaner[S1].txt
2013-08-12 13:34 - 2013-08-12 13:34 - 00011051 _____ C:\AdwCleaner[S1].txt
2013-08-12 13:31 - 2013-08-12 13:31 - 00959697 _____ (Oleg N. Scherbakov) C:\Users\Lila\Desktop\JRT.exe
2013-08-12 13:30 - 2013-08-12 13:30 - 00666633 _____ C:\Users\Lila\Desktop\adwcleaner.exe
2013-08-12 13:01 - 2013-08-12 13:01 - 00024632 _____ C:\ComboFix.txt
2013-08-12 12:58 - 2013-08-12 13:01 - 00000000 ____D C:\Windows\erdnt
2013-08-12 12:58 - 2013-08-12 13:01 - 00000000 ____D C:\Qoobox
2013-08-12 12:58 - 2011-06-26 08:45 - 00256000 _____ C:\Windows\PEV.exe
2013-08-12 12:58 - 2010-11-07 19:20 - 00208896 _____ C:\Windows\MBR.exe
2013-08-12 12:58 - 2009-04-20 06:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2013-08-12 12:58 - 2000-08-31 02:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2013-08-12 12:58 - 2000-08-31 02:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2013-08-12 12:58 - 2000-08-31 02:00 - 00098816 _____ C:\Windows\sed.exe
2013-08-12 12:58 - 2000-08-31 02:00 - 00080412 _____ C:\Windows\grep.exe
2013-08-12 12:58 - 2000-08-31 02:00 - 00068096 _____ C:\Windows\zip.exe
2013-08-12 12:56 - 2013-08-12 12:56 - 05102975 ____R (Swearware) C:\Users\Lila\Desktop\ComboFix.exe
2013-08-12 12:56 - 2013-08-12 12:56 - 05102975 _____ (Swearware) C:\Users\Lila\Downloads\ComboFix (1).exe
2013-08-12 12:53 - 2013-08-12 12:53 - 00017951 _____ C:\Users\Lila\Downloads\Addition.txt
2013-08-12 12:48 - 2013-08-12 12:48 - 01575246 _____ (Farbar) C:\Users\Lila\Downloads\FRST64 (1).exe
2013-08-12 11:15 - 2013-08-12 11:15 - 00000000 ____D C:\FRST
2013-08-12 11:14 - 2013-08-12 11:14 - 01575246 _____ (Farbar) C:\Users\Lila\Downloads\FRST64.exe
2013-08-11 23:18 - 2013-08-11 23:18 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Lila\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-11 23:18 - 2013-08-11 23:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-11 23:18 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2013-08-11 23:11 - 2013-08-11 23:19 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\ProgramData\ESET
2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\Program Files\ESET
2013-08-07 22:41 - 2013-08-07 22:41 - 01415824 _____ (ESET) C:\Users\Lila\Downloads\eset_smart_security_live_installer.exe
2013-08-07 22:34 - 2013-08-07 22:35 - 187378056 _____ (Emsisoft GmbH                                               ) C:\Users\Lila\Downloads\EmsisoftAntiMalwareSetup (1).exe
2013-07-28 21:31 - 2013-07-28 21:31 - 00819705 _____ C:\Users\Lila\Downloads\wie_gewinne_ich.rar
2013-07-21 22:33 - 2013-07-21 22:59 - 00000000 ____D C:\Users\Lila\Downloads\Treiber
2013-07-14 00:43 - 2013-06-12 01:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-07-14 00:43 - 2013-06-12 01:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-07-14 00:43 - 2013-06-12 01:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-07-14 00:43 - 2013-06-12 01:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-07-14 00:43 - 2013-06-12 01:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-07-14 00:43 - 2013-06-12 01:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-07-14 00:43 - 2013-06-12 01:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-07-14 00:43 - 2013-06-12 01:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-07-14 00:43 - 2013-06-12 01:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-07-14 00:43 - 2013-06-12 01:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-07-14 00:43 - 2013-06-12 01:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-07-14 00:43 - 2013-06-12 01:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-07-14 00:43 - 2013-06-12 01:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-07-14 00:43 - 2013-06-12 01:26 - 02241024 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2013-07-14 00:43 - 2013-06-12 01:26 - 01365504 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2013-07-14 00:43 - 2013-06-12 01:26 - 00051712 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2013-07-14 00:43 - 2013-06-12 01:25 - 19238912 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 15404032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 03958784 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 02648576 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00855552 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00603136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00526336 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00136704 _____ (Microsoft Corporation) C:\Windows\system32\iesysprep.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00067072 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2013-07-14 00:43 - 2013-06-12 01:25 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2013-07-14 00:43 - 2013-06-12 00:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-07-14 00:43 - 2013-06-12 00:50 - 00089600 _____ (Microsoft Corporation) C:\Windows\system32\RegisterIEPKEYs.exe
2013-07-14 00:43 - 2013-06-07 05:22 - 02706432 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2013-07-14 00:43 - 2013-06-07 04:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-07-14 00:41 - 2013-06-05 05:34 - 03153920 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2013-07-14 00:41 - 2013-06-04 08:00 - 00624128 _____ (Microsoft Corporation) C:\Windows\system32\qedit.dll
2013-07-14 00:41 - 2013-06-04 06:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qedit.dll
2013-07-14 00:41 - 2013-05-06 08:03 - 01887744 _____ (Microsoft Corporation) C:\Windows\system32\WMVDECOD.DLL
2013-07-14 00:41 - 2013-05-06 06:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WMVDECOD.DLL
2013-07-14 00:40 - 2013-04-10 01:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\DWrite.dll
2013-07-14 00:40 - 2013-04-03 00:51 - 01643520 _____ (Microsoft Corporation) C:\Windows\system32\DWrite.dll
==================== One Month Modified Files and Folders =======
2013-08-12 13:41 - 2013-08-12 13:41 - 00001151 _____ C:\Users\Lila\Desktop\JRT.txt
2013-08-12 13:38 - 2013-08-12 13:38 - 00000000 ____D C:\Windows\ERUNT
2013-08-12 13:38 - 2009-07-14 06:50 - 00020112 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-08-12 13:38 - 2009-07-14 06:50 - 00020112 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-08-12 13:37 - 2013-08-12 13:37 - 00011051 _____ C:\Users\Lila\Desktop\AdwCleaner[S1].txt
2013-08-12 13:36 - 2013-06-26 02:28 - 00094656 _____ (CACE Technologies) C:\Windows\system32\WPRO_41_2001woem.tmp
2013-08-12 13:36 - 2013-03-01 20:59 - 00000000 ____D C:\Users\Lila\AppData\Roaming\WTablet
2013-08-12 13:36 - 2013-03-01 18:40 - 00034752 _____ C:\Windows\system32\Drivers\WPRO_41_2001.sys
2013-08-12 13:36 - 2013-03-01 18:38 - 00000828 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job
2013-08-12 13:36 - 2013-03-01 18:37 - 00064064 _____ C:\Users\Lila\AppData\Local\GDIPFONTCACHEV1.DAT
2013-08-12 13:36 - 2013-03-01 18:30 - 01287398 _____ C:\Windows\WindowsUpdate.log
2013-08-12 13:36 - 2010-11-21 05:47 - 00085674 _____ C:\Windows\PFRO.log
2013-08-12 13:36 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2013-08-12 13:36 - 2009-07-14 06:56 - 00047194 _____ C:\Windows\setupact.log
2013-08-12 13:36 - 2009-07-14 06:50 - 03038176 _____ C:\Windows\system32\FNTCACHE.DAT
2013-08-12 13:34 - 2013-08-12 13:34 - 00011051 _____ C:\AdwCleaner[S1].txt
2013-08-12 13:31 - 2013-08-12 13:31 - 00959697 _____ (Oleg N. Scherbakov) C:\Users\Lila\Desktop\JRT.exe
2013-08-12 13:30 - 2013-08-12 13:30 - 00666633 _____ C:\Users\Lila\Desktop\adwcleaner.exe
2013-08-12 13:23 - 2013-06-12 13:00 - 00001116 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job
2013-08-12 13:01 - 2013-08-12 13:01 - 00024632 _____ C:\ComboFix.txt
2013-08-12 13:01 - 2013-08-12 12:58 - 00000000 ____D C:\Windows\erdnt
2013-08-12 13:01 - 2013-08-12 12:58 - 00000000 ____D C:\Qoobox
2013-08-12 13:01 - 2009-07-14 04:34 - 00000215 _____ C:\Windows\system.ini
2013-08-12 12:56 - 2013-08-12 12:56 - 05102975 ____R (Swearware) C:\Users\Lila\Desktop\ComboFix.exe
2013-08-12 12:56 - 2013-08-12 12:56 - 05102975 _____ (Swearware) C:\Users\Lila\Downloads\ComboFix (1).exe
2013-08-12 12:53 - 2013-08-12 12:53 - 00017951 _____ C:\Users\Lila\Downloads\Addition.txt
2013-08-12 12:48 - 2013-08-12 12:48 - 01575246 _____ (Farbar) C:\Users\Lila\Downloads\FRST64 (1).exe
2013-08-12 12:40 - 2013-03-05 15:15 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-08-12 12:40 - 2013-03-01 20:47 - 00000000 ____D C:\Users\Lila\AppData\Roaming\Adobe
2013-08-12 12:39 - 2013-03-05 15:16 - 00000000 ____D C:\Program Files\Common Files\Adobe
2013-08-12 12:39 - 2013-03-01 20:46 - 00000000 ____D C:\ProgramData\Adobe
2013-08-12 12:35 - 2013-03-05 15:15 - 00000000 ____D C:\Users\Lila\AppData\Local\Adobe
2013-08-12 12:32 - 2011-04-12 10:14 - 00653928 _____ C:\Windows\system32\perfh007.dat
2013-08-12 12:32 - 2011-04-12 10:14 - 00129800 _____ C:\Windows\system32\perfc007.dat
2013-08-12 12:32 - 2009-07-14 07:12 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2013-08-12 12:23 - 2013-06-12 13:00 - 00001064 _____ C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job
2013-08-12 11:15 - 2013-08-12 11:15 - 00000000 ____D C:\FRST
2013-08-12 11:14 - 2013-08-12 11:14 - 01575246 _____ (Farbar) C:\Users\Lila\Downloads\FRST64.exe
2013-08-12 00:43 - 2013-03-22 21:17 - 00000000 ____D C:\Users\Lila\AppData\Roaming\UseNeXT
2013-08-11 23:19 - 2013-08-11 23:11 - 00000898 _____ C:\Windows\SysWOW64\InstallUtil.InstallLog
2013-08-11 23:18 - 2013-08-11 23:18 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Lila\Downloads\mbam-setup-1.75.0.1300.exe
2013-08-11 23:18 - 2013-08-11 23:18 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-08-11 22:45 - 2013-05-15 20:43 - 00000000 ____D C:\Users\Lila\AppData\Roaming\vlc
2013-08-11 16:26 - 2013-03-01 18:38 - 00000830 _____ C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job
2013-08-11 13:25 - 2013-03-07 20:46 - 00003906 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{AE5A86A8-D88D-40C8-AA45-438AD91DF71B}
2013-08-08 10:25 - 2013-06-27 23:41 - 00000000 ____D C:\Users\Lila\Documents\Anti-Malware
2013-08-08 10:25 - 2013-06-27 23:41 - 00000000 ____D C:\Program Files (x86)\Emsisoft Anti-Malware
2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\ProgramData\ESET
2013-08-07 22:42 - 2013-08-07 22:42 - 00000000 ____D C:\Program Files\ESET
2013-08-07 22:41 - 2013-08-07 22:41 - 01415824 _____ (ESET) C:\Users\Lila\Downloads\eset_smart_security_live_installer.exe
2013-08-07 22:35 - 2013-08-07 22:34 - 187378056 _____ (Emsisoft GmbH                                               ) C:\Users\Lila\Downloads\EmsisoftAntiMalwareSetup (1).exe
2013-08-05 12:29 - 2013-04-06 16:37 - 00000000 ____D C:\ProgramData\CanonIJPLM
2013-08-02 01:51 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\system32\NDF
2013-07-28 21:31 - 2013-07-28 21:31 - 00819705 _____ C:\Users\Lila\Downloads\wie_gewinne_ich.rar
2013-07-21 22:59 - 2013-07-21 22:33 - 00000000 ____D C:\Users\Lila\Downloads\Treiber
2013-07-14 14:18 - 2013-05-02 20:01 - 00000000 ____D C:\Users\Lila\AppData\Local\CrashDumps
2013-07-14 01:23 - 2011-04-12 10:24 - 00000000 ____D C:\Program Files\Windows Journal
2013-07-14 01:23 - 2009-07-14 07:38 - 00000000 ____D C:\Program Files\Windows Defender
2013-07-14 01:23 - 2009-07-14 07:38 - 00000000 ____D C:\Program Files (x86)\Windows Defender
2013-07-14 00:44 - 2013-03-01 18:57 - 78185248 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2013-07-13 12:18 - 2013-06-12 13:00 - 00004084 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA
2013-07-13 12:18 - 2013-06-12 13:00 - 00003688 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2013-08-02 15:09
==================== End Of Log ============================
         Code: 
  ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 11-08-2013 02 Ran by Lila at 2013-08-12 13:42:29 Running from C:\Users\Lila\Downloads Boot Mode: Normal ========================================================== ==================== Installed Programs ======================= Acrobat.com (x32 Version: 0.0.0) Acrobat.com (x32 Version: 1.2.443) Adobe AIR (x32 Version: 1.1.0.5790) Adobe Flash Player 10 ActiveX (x32 Version: 10.3.183.43) Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.202) Adobe Media Player (x32 Version: 0.0.0) Adobe Media Player (x32 Version: 1.1) AMD Accelerated Video Transcoding (Version: 12.5.100.21219) AMD APP SDK Runtime (Version: 10.0.1084.4) AMD Catalyst Install Manager (Version: 8.0.903.0) AMD Drag and Drop Transcoding (Version: 2.00.0000) AMD Media Foundation Decoders (Version: 1.0.71219.1540) Apple Application Support (x32 Version: 2.3) Apple Software Update (x32 Version: 2.1.3.127) Asmedia ASM106x SATA Host Controller Driver (x32 Version: 1.3.1.000) Canon IJ Scan Utility (x32) Canon Inkjet Printer/Scanner/Fax Extended Survey Program (x32 Version: 4.0.0) Canon MG2200 series Benutzerregistrierung (x32) Canon MG2200 series MP Drivers (Version: 1.00) Canon MG2200 series On-screen Manual (x32 Version: 7.5.0) Canon My Printer (x32 Version: 3.0.0) Canon Quick Menu (x32 Version: 2.0.0) Catalyst Control Center - Branding (x32 Version: 1.00.0000) Catalyst Control Center (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Graphics Previews Common (x32 Version: 2012.1219.1521.27485) Catalyst Control Center InstallProxy (x32 Version: 2012.1219.1521.27485) Catalyst Control Center Localization All (x32 Version: 2012.1219.1521.27485) CCC Help Chinese Standard (x32 Version: 2012.1219.1520.27485) CCC Help Chinese Traditional (x32 Version: 2012.1219.1520.27485) CCC Help Czech (x32 Version: 2012.1219.1520.27485) CCC Help Danish (x32 Version: 2012.1219.1520.27485) CCC Help Dutch (x32 Version: 2012.1219.1520.27485) CCC Help English (x32 Version: 2012.1219.1520.27485) CCC Help Finnish (x32 Version: 2012.1219.1520.27485) CCC Help French (x32 Version: 2012.1219.1520.27485) CCC Help German (x32 Version: 2012.1219.1520.27485) CCC Help Greek (x32 Version: 2012.1219.1520.27485) CCC Help Hungarian (x32 Version: 2012.1219.1520.27485) CCC Help Italian (x32 Version: 2012.1219.1520.27485) CCC Help Japanese (x32 Version: 2012.1219.1520.27485) CCC Help Korean (x32 Version: 2012.1219.1520.27485) CCC Help Norwegian (x32 Version: 2012.1219.1520.27485) CCC Help Polish (x32 Version: 2012.1219.1520.27485) CCC Help Portuguese (x32 Version: 2012.1219.1520.27485) CCC Help Russian (x32 Version: 2012.1219.1520.27485) CCC Help Spanish (x32 Version: 2012.1219.1520.27485) CCC Help Swedish (x32 Version: 2012.1219.1520.27485) CCC Help Thai (x32 Version: 2012.1219.1520.27485) CCC Help Turkish (x32 Version: 2012.1219.1520.27485) ccc-utility64 (Version: 2012.1219.1521.27485) DAEMON Tools Lite (x32 Version: 4.46.1.0327) Easy Poster Printer (x32 Version: 6.0.0) ESET Smart Security (Version: 6.0.316.1) Google Chrome (HKCU Version: 28.0.1500.95) Intel(R) Control Center (x32 Version: 1.2.1.1007) Intel(R) Manageability Engine Firmware Recovery Agent (x32 Version: 1.0.0.35342) Intel(R) Management Engine Components (x32 Version: 8.0.2.1410) Intel(R) OpenCL CPU Runtime (x32) Intel(R) Processor Graphics (x32 Version: 8.15.10.2618) Intel(R) Rapid Storage Technology (x32 Version: 11.0.0.1032) Intel(R) Smart Connect Technology 2.0 x64 (Version: 2.0.1083.0) Intel(R) USB 3.0 eXtensible Host Controller Driver (x32 Version: 1.0.3.214) Intel® Trusted Connect Service Client (Version: 1.23.605.1) Malwarebytes Anti-Malware Version 1.75.0.1300 (x32 Version: 1.75.0.1300) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319) Microsoft Office Professional Edition 2003 (x32 Version: 11.0.7969.0) Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (Version: 10.0.30319) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219) Mozilla Firefox 22.0 (x86 de) (x32 Version: 22.0) Mozilla Maintenance Service (x32 Version: 22.0) ock App Charger v1.0.5 Personal ID (x32 Version: 1.8.5.202) Poker 770 (x32) PokerStars.eu (x32) PreFlopper (x32 Version: 2.1.0) QuickTime (x32 Version: 7.73.80.64) Realtek Ethernet Controller Driver (x32 Version: 7.48.823.2011) Realtek High Definition Audio Driver (x32 Version: 6.0.1.6482) Secret City (x32 Version: 1.9.4662) Steam (x32 Version: 1.0.0.0) TP-LINK TL-WN821N Driver (x32 Version: 1.2.1) TrackMania Nations Forever (x32) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1) UseNeXT by Tangysoft (x32) VIRTU MVP 2.1.110 (Version: 2.1.110) VLC media player 2.0.6 (x32 Version: 2.0.6) Wacom Tablett (x32) WinRAR 4.20 (64-Bit) (Version: 4.20.0) ==================== Restore Points ========================= 02-08-2013 20:07:36 Geplanter Prüfpunkt 07-08-2013 20:28:41 Windows Update 12-08-2013 10:58:27 ComboFix created restore point ==================== Hosts content: ========================== 2009-07-14 04:34 - 2013-03-05 15:25 - 00001173 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost 127.0.0.1 activate.adobe.com 127.0.0.1 practivate.adobe.com 127.0.0.1 ereg.adobe.com 127.0.0.1 activate.wip3.adobe.com 127.0.0.1 wip3.adobe.com 127.0.0.1 3dns-3.adobe.com 127.0.0.1 3dns-2.adobe.com 127.0.0.1 adobe-dns.adobe.com 127.0.0.1 adobe-dns-2.adobe.com 127.0.0.1 adobe-dns-3.adobe.com 127.0.0.1 ereg.wip3.adobe.com 127.0.0.1 activate-sea.adobe.com 127.0.0.1 pagead2.googlesyndication.com 127.0.0.1 wwis-dubc1-vip60.adobe.com 127.0.0.1 activate-sjc0.adobe.com ==================== Scheduled Tasks (whitelisted) ============= Task: {220145D2-20B3-4B48-AE44-52D59DE2FAF6} - System32\Tasks\User_Feed_Synchronization-{AE5A86A8-D88D-40C8-AA45-438AD91DF71B} => C:\Windows\system32\msfeedssync.exe [2013-05-22] (Microsoft Corporation) Task: {28336CC1-56F3-4285-84D2-51E7E572B6E6} - System32\Tasks\CreateChoiceProcessTask => C:\Windows\System32\browserchoice.exe [2010-02-23] (Microsoft Corporation) Task: {52DB3FE1-FD35-49AE-A798-A031751E05F0} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {694C5397-481C-4398-A94D-41EEC64F746A} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => c:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation) Task: {79B1D23E-D9E5-44CA-B2B4-EE322E0F6FB2} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {9227EDEB-5C17-43F6-AF4C-1B3E91416116} - System32\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe [2011-11-25] (Intel Corporation) Task: {CEA0F661-E4EF-4B0C-8174-747271058321} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe [2013-06-12] (Google Inc.) Task: {EBD67A4D-F364-42F2-94CA-DEA6B10D73FF} - System32\Tasks\Microsoft\Windows\TabletPC\InputPersonalization => C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe [2009-07-14] (Microsoft Corporation) Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000Core.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-2891719752-1434430305-2529905461-1000UA.job => C:\Users\Lila\AppData\Local\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d-Logon.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe Task: C:\Windows\Tasks\ISM-UpdateService-4e00205a-2ab1-4423-8f77-cc25b82cde1d.job => C:\Program Files (x86)\Intel\Intel(R) ME FW Recovery Agent\bin\Bootstrap.exe ==================== Faulty Device Manager Devices ============= ==================== Event log errors: ========================= Application errors: ================== System errors: ============= Microsoft Office Sessions: ========================= ==================== Memory info =========================== Percentage of memory in use: 14% Total physical RAM: 16268.42 MB Available physical RAM: 13925.38 MB Total Pagefile: 32535.03 MB Available Pagefile: 29893.45 MB Total Virtual: 8192 MB Available Virtual: 8191.82 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:111.69 GB) (Free:57.26 GB) NTFS (Disk=0 Partition=2) Drive d: (Volume) (Fixed) (Total:931.51 GB) (Free:891.19 GB) NTFS (Disk=1 Partition=1) Drive e: (Ablage) (Fixed) (Total:10 GB) (Free:1.32 GB) NTFS (Disk=2 Partition=1) Drive f: (Datensammlung) (Fixed) (Total:50.01 GB) (Free:35.01 GB) NTFS (Disk=2 Partition=2) Drive g: (Musik) (Fixed) (Total:100.01 GB) (Free:96.21 GB) NTFS (Disk=2 Partition=3) Drive h: (Down) (Fixed) (Total:305.74 GB) (Free:225.94 GB) NTFS (Disk=2 Partition=4) Drive k: (EOS_DIGITAL) (Removable) (Total:14.93 GB) (Free:8.21 GB) FAT32 (Disk=3 Partition=1) ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 112 GB) (Disk ID: 862E84D4) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=112 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: E792C529) Partition 1: (Not Active) - (Size=932 GB) - (Type=07 NTFS) ======================================================== Disk: 2 (Size: 466 GB) (Disk ID: 086D086C) Partition 1: (Active) - (Size=10 GB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=456 GB) - (Type=05) ======================================================== Disk: 3 (Size: 15 GB) (Disk ID: 00000000) Partition 1: (Active) - (Size=15 GB) - (Type=0C) ==================== End Of Log ============================ | 
|  12.08.2013, 13:27 | #14 | 
| /// Winkelfunktion /// TB-Süch-Tiger™       |   Im Browser ist überall Werbung Sieht ok aus. Wir sollten fast durch sein. Mach bitte zur Kontrolle einen Quickscan mit Malwarebytes Anti-Malware (MBAM) Hinweis: Denk bitte vorher daran, Malwarebytes Anti-Malware über den Updatebutton zu aktualisieren! Anschließend über den OnlineScanner von ESET eine zusätzliche Meinung zu holen ist auch nicht verkehrt: ESET Online Scanner 
 
				__________________ Logfiles bitte immer in CODE-Tags posten   | 
|  12.08.2013, 14:01 | #15 | 
|   |   Im Browser ist überall Werbung hier nun die Logs Code: 
  ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.08.12.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 10.0.9200.16635 Lila :: LEX [Administrator] 12.08.2013 14:42:19 mbam-log-2013-08-12 (14-42-19).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 218266 Laufzeit: 1 Minute(n), 24 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code: 
  ATTFilter ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=c21399f6cd9b614f96a29458e624ef2b
# engine=14746
# end=stopped
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2013-08-12 12:58:19
# local_time=2013-08-12 02:58:19 (+0100, Mitteleuropäische Sommerzeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=5893 16776573 100 94 4287 127942149 0 0
# compatibility_mode=8216 16776701 100 98 404179 126325251 0 0
# scanned=69176
# found=0
# cleaned=0
# scan_time=584
# nod_component=V3 Build:0x30000000
          | 
|  | 
| Themen zu Im Browser ist überall Werbung | 
| ads, ads not by this site, aktiviert, auf einmal, brauche, browser, euere, hoffe, hängt, liebe, lieben, links, merke, nicht mehr, not, rechts, runtergeladen, teilweise, this, werbun, werbung, überall |