Windows 7: Laptop seit wenigen Tagen extrem langsam

Hallo liebe Community,

versuche hier meiner Mutter zu helfen, ihr Laptop ist seit 2-3 Tagen extrem langsam (Braucht sehr lange zum Hochfahren, zum Öffnen von Webseiten und auch bei den Facebookspielen, die sonst nie länger als 10-15 Sekunden geladen haben, braucht es jetzt Minuten).
Wir haben versucht, ihn wieder flott zu machen, habe ihn mit Kaspersky scannen lassen (ohne irgendetwas gefunden zu haben), über Nacht mal defragmentieren lassen und zu guter letzt unnütze Programme deinstalliert.
Dabei ist mir dann unter Anderem auch ein Programm namens "Websteroids" von Creative Island Media LLC aufgefallen und nach einer kurzen Websuche habe ich dann herausgefunden, dass es wohl eine Schadsoftware ist.
Habe diese dann deinstalliert und irgendwie gehofft, dass es besser wird, aber nichts dergleichen.. Weiß langsam nicht mehr was ich machen soll, darum hoffe ich, dass mir hier jemand helfen kann

Hier die gewünschten Logs:


FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 25-04-2014 01
Ran by Louba (administrator) on LOUBA-PC on 25-04-2014 18:40:45
Running from C:\Users\Louba\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\NvXDSync.exe
(NVIDIA Corporation) C:\Windows\system32\nvvsvc.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ASLDRSrv.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKGFNEX\GFNEXSrv.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControl.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\ATKOSD.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\KBFiltr.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\WDC.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
() C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(ASUS) C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe
(ASUS) C:\Program Files\P4G\BatteryLife.exe
(ASUSTeK) C:\Windows\SysWOW64\ACEngSvr.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version9\TeamViewer_Service.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel(R) Corporation) C:\Program Files\Intel\TurboBoost\TurboBoost.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Program Files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE
(CANON INC.) C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Virage Logic Corporation / Sonic Focus) C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe
(ASUS) C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe
() C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
(CANON INC.) C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
(ASUS) C:\Windows\AsScrPro.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Updatus\daemonu.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [RtHDVBg] => C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [2226280 2011-05-17] (Realtek Semiconductor)
HKLM\...\Run: [ETDCtrl] => C:\Program Files\Elantech\ETDCtrl.exe [2589992 2011-04-12] (ELAN Microelectronics Corp.)
HKLM\...\Run: [IntelPAN] => C:\Program Files\Common Files\Intel\WirelessCommon\iFrmewrk.exe [1935120 2011-05-03] (Intel(R) Corporation)
HKLM\...\Run: [IntelTBRunOnce] => wscript.exe //b //nologo "C:\Program Files\Intel\TurboBoost\RunTBGadgetOnce.vbs"
HKLM\...\Run: [CanonMyPrinter] => C:\Program Files\Canon\MyPrinter\BJMyPrt.exe [2726728 2010-03-25] (CANON INC.)
HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [11855976 2011-05-17] (Realtek Semiconductor)
HKLM-x32\...\Run: [ASUSPRP] => C:\Program Files (x86)\ASUS\APRP\APRP.EXE [2018032 2011-04-13] (ASUSTek Computer Inc.)
HKLM-x32\...\Run: [SonicMasterTray] => C:\Program Files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe [984400 2010-07-10] (Virage Logic Corporation / Sonic Focus)
HKLM-x32\...\Run: [ATKOSD2] => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [5732992 2010-08-18] (ASUS)
HKLM-x32\...\Run: [ATKMEDIA] => C:\Program Files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe [170624 2010-10-08] (ASUS)
HKLM-x32\...\Run: [HControlUser] => C:\Program Files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe [105016 2009-06-19] (ASUS)
HKLM-x32\...\Run: [Wireless Console 3] => C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe [1601536 2010-09-24] ()
HKLM-x32\...\Run: [CanonSolutionMenuEx] => C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE [1185112 2010-04-02] (CANON INC.)
HKLM-x32\...\Run: [ASUS Screen Saver Protector] => C:\Windows\AsScrPro.exe [3058304 2014-02-12] (ASUS)
Winlogon\Notify\igfxcui: C:\Windows\system32\igfxdev.dll (Intel Corporation)
HKU\S-1-5-21-2938410442-2887813953-4122150277-1000\...\Run: [ISUSPM] => C:\ProgramData\FLEXnet\Connect\11\ISUSPM.exe -scheduler
HKU\S-1-5-21-2938410442-2887813953-4122150277-1001\...\Run: [CCleaner] => C:\Program Files\CCleaner\CCleaner64.exe [6087448 2014-01-21] (Piriform Ltd)
AppInit_DLLs: C:\Windows\system32\nvinitx.dll => C:\Windows\system32\nvinitx.dll [226920 2011-05-10] (NVIDIA Corporation)
AppInit_DLLs-x32: C:\Windows\SysWOW64\nvinit.dll => C:\Windows\SysWOW64\nvinit.dll [193128 2011-05-10] (NVIDIA Corporation)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://asus.msn.com
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://asus.msn.com
SearchScopes: HKLM-x32 - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ASUT
SearchScopes: HKCU - DefaultScope {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323737&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP0F1EF72B-73BD-4353-9A9A-A2B7900C23FD&q={searchTerms}&SSPV=
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3323737&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=4&UP=SP0F1EF72B-73BD-4353-9A9A-A2B7900C23FD&q={searchTerms}&SSPV=
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner64.dll (Google Inc.)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\x64\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
BHO-x32: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
BHO-x32: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO-x32: Partner BHO Class - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll (Google Inc.)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO-x32: No Name - {C84D72FE-E17D-4195-BB24-76C02E2E7C4E} -  No File
BHO-x32: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKLM-x32 - Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Louba\AppData\Roaming\Mozilla\Firefox\Profiles\46i6jzyg.default
FF NewTab: hxxp://www.google.de/
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.google.de/
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_44.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_44.dll ()
FF Plugin-x32: @canon.com/EPPEX - C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Louba\AppData\Roaming\Mozilla\Firefox\Profiles\46i6jzyg.default\searchplugins\conduit-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: Adblock Plus - C:\Users\Louba\AppData\Roaming\Mozilla\Firefox\Profiles\46i6jzyg.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-02-13]
FF HKLM-x32\...\Firefox\Extensions:  - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2014-04-24]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2014-04-24]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2014-04-24]
FF HKLM-x32\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2014-04-24]
FF HKLM-x32\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2014-04-24]

CHR Extension: (Google Docs) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2014-04-24]
CHR Extension: (Google Drive) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2014-04-24]
CHR Extension: (YouTube) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2014-04-24]
CHR Extension: (Adblock Plus) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb [2014-04-24]
CHR Extension: (Google-Suche) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2014-04-24]
CHR Extension: (Modul zur Link-Untersuchung) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\dchlnpcodkpfdpacogkljefecpegganj [2014-04-24]
CHR Extension: (Facebook Customizer (by Adblock Plus)) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\deoeenbkoccjaefmmhpmlegngdjohdcm [2014-04-24]
CHR Extension: (Sicherer Zahlungsverkehr) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hakdifolhalapjijoafobooafbilfakh [2014-04-24]
CHR Extension: (Modul zum Sperren von gefährlichen Webseiten) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\hghkgaeecgjhjkannahfamoehjmkjail [2014-04-24]
CHR Extension: (Virtuelle Tastatur) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\jagncdcchgajhfhijbbhecadmaiegcmh [2014-04-24]
CHR Extension: (Pic and Click San Francisco) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nkpmjmcgjoidcjgdfmeaajknmjcecdii [2014-04-24]
CHR Extension: (Google Wallet) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2014-04-24]
CHR Extension: (Google Mail) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2014-04-24]
CHR Extension: (Anti-Banner) - C:\Users\Louba\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjldcfjmnllhmgjclecdnfampinooman [2014-04-24]
CHR HKLM-x32\...\Chrome\Extension: [dchlnpcodkpfdpacogkljefecpegganj] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\urladvisor.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hakdifolhalapjijoafobooafbilfakh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\online_banking_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [hghkgaeecgjhjkannahfamoehjmkjail] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\content_blocker_chrome.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [jagncdcchgajhfhijbbhecadmaiegcmh] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\virtkbd.crx [2013-10-17]
CHR HKLM-x32\...\Chrome\Extension: [pjldcfjmnllhmgjclecdnfampinooman] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\ChromeExt\ab.crx [2013-10-17]
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

R2 AVP; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
R2 IJPLMSVC; C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE [116104 2010-04-05] ()
S3 MyWiFiDHCPDNS; C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe [340240 2011-05-03] ()

==================== Drivers (Whitelisted) ====================

R3 kbfiltr; C:\Windows\System32\DRIVERS\kbfiltr.sys [15416 2009-07-20] ( )
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [7717984 2013-10-17] (Kaspersky Lab ZAO)
S4 klflt; C:\Windows\System32\DRIVERS\klflt.sys [112224 2013-06-08] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [620640 2013-10-17] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [29792 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [29280 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [15456 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [55904 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [178784 2013-06-06] (Kaspersky Lab ZAO)
R2 TurboB; C:\Windows\System32\DRIVERS\TurboB.sys [13832 2010-04-17] ()

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-04-25 18:40 - 2014-04-25 18:41 - 00019241 _____ () C:\Users\Louba\Downloads\FRST.txt
2014-04-25 18:40 - 2014-04-25 18:40 - 00000000 ____D () C:\FRST
2014-04-25 18:38 - 2014-04-25 18:38 - 02061312 _____ (Farbar) C:\Users\Louba\Downloads\FRST64.exe
2014-04-25 18:35 - 2014-04-25 18:35 - 00000472 _____ () C:\Users\Louba\Downloads\defogger_disable.log
2014-04-25 18:35 - 2014-04-25 18:35 - 00000000 _____ () C:\Users\Louba\defogger_reenable
2014-04-25 18:33 - 2014-04-25 18:33 - 00050477 _____ () C:\Users\Louba\Downloads\Defogger.exe
2014-04-25 18:31 - 2014-04-25 18:31 - 00058016 _____ () C:\Users\Louba\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-25 18:13 - 2014-04-25 18:31 - 00009735 _____ () C:\Windows\WindowsUpdate.log
2014-04-25 17:54 - 2014-04-25 17:54 - 00000000 ____D () C:\ProgramData\ASUS
2014-04-25 17:52 - 2014-04-25 17:52 - 00024576 _____ () C:\Users\Louba\AppData\Local\uninst.tmp
2014-04-25 12:22 - 2014-04-25 12:22 - 00000000 ____D () C:\Users\Louba\Documents\PC Speed Maximizer
2014-04-24 23:06 - 2014-04-24 23:06 - 00067342 _____ () C:\Users\Louba\Documents\cc_20140424_230608.reg
2014-04-24 22:51 - 2014-04-24 22:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2014-04-24 22:51 - 2013-05-06 09:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll
2014-04-24 22:50 - 2014-04-24 22:50 - 00000000 ____D () C:\Windows\ELAMBKUP
2014-04-24 22:49 - 2014-04-25 18:10 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-04-24 22:49 - 2014-04-24 22:49 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2014-04-24 22:49 - 2013-10-17 15:47 - 00620640 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2014-04-24 22:49 - 2013-06-08 20:18 - 00112224 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2014-04-24 22:15 - 2014-04-24 22:15 - 00002253 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-15 22:02 - 2014-04-15 22:02 - 00000000 ____D () C:\ProgramData\CanonIJ
2014-04-15 22:01 - 2014-04-15 22:01 - 00000000 ___HD () C:\ProgramData\CanonIJScan
2014-04-15 22:01 - 2014-04-15 22:01 - 00000000 ____D () C:\Users\Louba\AppData\Roaming\Canon
2014-04-15 22:01 - 2014-04-15 22:01 - 00000000 _____ () C:\Users\Louba\Sti_Trace.log
2014-04-15 15:22 - 2014-03-06 12:21 - 23549440 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-04-15 15:22 - 2014-03-06 11:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-04-15 15:22 - 2014-03-06 11:31 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-04-15 15:22 - 2014-03-06 11:19 - 17387008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-04-15 15:22 - 2014-03-06 10:59 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-04-15 15:22 - 2014-03-06 10:57 - 00548352 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-04-15 15:22 - 2014-03-06 10:57 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-04-15 15:22 - 2014-03-06 10:53 - 02767360 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-04-15 15:22 - 2014-03-06 10:40 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-04-15 15:22 - 2014-03-06 10:39 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-04-15 15:22 - 2014-03-06 10:32 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-04-15 15:22 - 2014-03-06 10:32 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-04-15 15:22 - 2014-03-06 10:29 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-04-15 15:22 - 2014-03-06 10:29 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-04-15 15:22 - 2014-03-06 10:28 - 00752640 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-04-15 15:22 - 2014-03-06 10:15 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-04-15 15:22 - 2014-03-06 10:11 - 05784064 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-04-15 15:22 - 2014-03-06 10:09 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-04-15 15:22 - 2014-03-06 10:03 - 00586240 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-04-15 15:22 - 2014-03-06 10:02 - 00455168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-04-15 15:22 - 2014-03-06 10:02 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-04-15 15:22 - 2014-03-06 10:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-04-15 15:22 - 2014-03-06 09:56 - 00038400 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-04-15 15:22 - 2014-03-06 09:48 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-04-15 15:22 - 2014-03-06 09:47 - 02178048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-04-15 15:22 - 2014-03-06 09:46 - 04254720 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-04-15 15:22 - 2014-03-06 09:46 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-04-15 15:22 - 2014-03-06 09:45 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-04-15 15:22 - 2014-03-06 09:42 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-04-15 15:22 - 2014-03-06 09:40 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-04-15 15:22 - 2014-03-06 09:38 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-04-15 15:22 - 2014-03-06 09:36 - 00592896 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-04-15 15:22 - 2014-03-06 09:22 - 00367616 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-04-15 15:22 - 2014-03-06 09:21 - 00628736 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-04-15 15:22 - 2014-03-06 09:13 - 00032256 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-04-15 15:22 - 2014-03-06 09:11 - 02043904 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-04-15 15:22 - 2014-03-06 09:07 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-04-15 15:22 - 2014-03-06 09:01 - 00244224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-04-15 15:22 - 2014-03-06 08:53 - 13551104 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-04-15 15:22 - 2014-03-06 08:46 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-04-15 15:22 - 2014-03-06 08:40 - 01967104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-04-15 15:22 - 2014-03-06 08:36 - 11745792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-04-15 15:22 - 2014-03-06 08:22 - 02260480 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-04-15 15:22 - 2014-03-06 07:58 - 01400832 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-04-15 15:22 - 2014-03-06 07:50 - 00846336 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-04-15 15:22 - 2014-03-06 07:43 - 00704512 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-04-15 15:22 - 2014-03-06 07:41 - 01789440 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-04-15 15:22 - 2014-03-06 07:36 - 01143808 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-04-10 10:30 - 2014-03-04 11:44 - 01163264 _____ (Microsoft Corporation) C:\Windows\system32\kernel32.dll
2014-04-10 10:30 - 2014-03-04 11:44 - 00362496 _____ (Microsoft Corporation) C:\Windows\system32\wow64win.dll
2014-04-10 10:30 - 2014-03-04 11:44 - 00243712 _____ (Microsoft Corporation) C:\Windows\system32\wow64.dll
2014-04-10 10:30 - 2014-03-04 11:44 - 00016384 _____ (Microsoft Corporation) C:\Windows\system32\ntvdm64.dll
2014-04-10 10:30 - 2014-03-04 11:44 - 00013312 _____ (Microsoft Corporation) C:\Windows\system32\wow64cpu.dll
2014-04-10 10:30 - 2014-03-04 11:17 - 00014336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntvdm64.dll
2014-04-10 10:30 - 2014-03-04 11:16 - 01114112 _____ (Microsoft Corporation) C:\Windows\SysWOW64\kernel32.dll
2014-04-10 10:30 - 2014-03-04 11:16 - 00025600 _____ (Microsoft Corporation) C:\Windows\SysWOW64\setup16.exe
2014-04-10 10:30 - 2014-03-04 11:16 - 00005120 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wow32.dll
2014-04-10 10:30 - 2014-03-04 10:09 - 00007680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\instnm.exe
2014-04-10 10:30 - 2014-03-04 10:09 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\user.exe
2014-04-10 10:30 - 2014-02-04 04:35 - 00274880 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\msiscsi.sys
2014-04-10 10:30 - 2014-02-04 04:35 - 00190912 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\storport.sys
2014-04-10 10:30 - 2014-02-04 04:35 - 00027584 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\Diskdump.sys
2014-04-10 10:30 - 2014-02-04 04:28 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\iologmsg.dll
2014-04-10 10:30 - 2014-02-04 04:00 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iologmsg.dll
2014-04-10 10:30 - 2014-01-24 04:37 - 01684928 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ntfs.sys
2014-03-27 20:16 - 2014-03-27 20:16 - 00000000 ____D () C:\ProgramData\Mozilla
2014-03-27 20:16 - 2014-03-27 20:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service

==================== One Month Modified Files and Folders =======

2014-04-25 18:41 - 2014-04-25 18:40 - 00019241 _____ () C:\Users\Louba\Downloads\FRST.txt
2014-04-25 18:40 - 2014-04-25 18:40 - 00000000 ____D () C:\FRST
2014-04-25 18:38 - 2014-04-25 18:38 - 02061312 _____ (Farbar) C:\Users\Louba\Downloads\FRST64.exe
2014-04-25 18:35 - 2014-04-25 18:35 - 00000472 _____ () C:\Users\Louba\Downloads\defogger_disable.log
2014-04-25 18:35 - 2014-04-25 18:35 - 00000000 _____ () C:\Users\Louba\defogger_reenable
2014-04-25 18:35 - 2014-02-10 23:50 - 00000000 ____D () C:\Users\Louba
2014-04-25 18:34 - 2011-04-11 14:05 - 00482258 _____ () C:\Windows\system32\perfh001.dat
2014-04-25 18:34 - 2011-04-11 14:05 - 00098162 _____ () C:\Windows\system32\perfc001.dat
2014-04-25 18:34 - 2011-03-17 13:52 - 00727844 _____ () C:\Windows\system32\perfh019.dat
2014-04-25 18:34 - 2011-03-17 13:52 - 00154232 _____ () C:\Windows\system32\perfc019.dat
2014-04-25 18:34 - 2011-02-19 07:02 - 00395588 _____ () C:\Windows\system32\perfh00D.dat
2014-04-25 18:34 - 2011-02-19 07:02 - 00088148 _____ () C:\Windows\system32\perfc00D.dat
2014-04-25 18:34 - 2011-02-19 06:56 - 00610232 _____ () C:\Windows\system32\perfh008.dat
2014-04-25 18:34 - 2011-02-19 06:56 - 00114518 _____ () C:\Windows\system32\perfc008.dat
2014-04-25 18:34 - 2011-02-19 06:51 - 00409036 _____ () C:\Windows\system32\prfh0404.dat
2014-04-25 18:34 - 2011-02-19 06:51 - 00125534 _____ () C:\Windows\system32\prfc0404.dat
2014-04-25 18:34 - 2011-02-19 06:45 - 00732262 _____ () C:\Windows\system32\prfh0816.dat
2014-04-25 18:34 - 2011-02-19 06:45 - 00156296 _____ () C:\Windows\system32\prfc0816.dat
2014-04-25 18:34 - 2011-02-19 06:40 - 00746742 _____ () C:\Windows\system32\perfh013.dat
2014-04-25 18:34 - 2011-02-19 06:40 - 00156492 _____ () C:\Windows\system32\perfc013.dat
2014-04-25 18:34 - 2011-02-19 06:35 - 00743290 _____ () C:\Windows\system32\perfh010.dat
2014-04-25 18:34 - 2011-02-19 06:35 - 00150236 _____ () C:\Windows\system32\perfc010.dat
2014-04-25 18:34 - 2011-02-19 06:29 - 00748960 _____ () C:\Windows\system32\perfh00C.dat
2014-04-25 18:34 - 2011-02-19 06:29 - 00152970 _____ () C:\Windows\system32\perfc00C.dat
2014-04-25 18:34 - 2011-02-19 06:24 - 00710782 _____ () C:\Windows\system32\perfh007.dat
2014-04-25 18:34 - 2011-02-19 06:24 - 00152972 _____ () C:\Windows\system32\perfc007.dat
2014-04-25 18:34 - 2011-02-19 06:19 - 00748700 _____ () C:\Windows\system32\perfh00A.dat
2014-04-25 18:34 - 2011-02-19 06:19 - 00161864 _____ () C:\Windows\system32\perfc00A.dat
2014-04-25 18:34 - 2009-07-14 07:13 - 09348272 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-04-25 18:33 - 2014-04-25 18:33 - 00050477 _____ () C:\Users\Louba\Downloads\Defogger.exe
2014-04-25 18:31 - 2014-04-25 18:31 - 00058016 _____ () C:\Users\Louba\AppData\Local\GDIPFONTCACHEV1.DAT
2014-04-25 18:31 - 2014-04-25 18:13 - 00009735 _____ () C:\Windows\WindowsUpdate.log
2014-04-25 18:18 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-04-25 18:18 - 2009-07-14 06:45 - 00009696 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-04-25 18:17 - 2011-04-13 04:33 - 00001124 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-04-25 18:10 - 2014-04-24 22:49 - 00000000 ____D () C:\ProgramData\Kaspersky Lab
2014-04-25 18:10 - 2014-02-10 23:51 - 00045056 _____ () C:\Windows\system32\acovcnt.exe
2014-04-25 18:10 - 2011-04-13 04:33 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-04-25 18:09 - 2009-07-14 07:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-04-25 17:54 - 2014-04-25 17:54 - 00000000 ____D () C:\ProgramData\ASUS
2014-04-25 17:54 - 2011-04-13 04:47 - 00000000 ____D () C:\Program Files (x86)\ASUS
2014-04-25 17:52 - 2014-04-25 17:52 - 00024576 _____ () C:\Users\Louba\AppData\Local\uninst.tmp
2014-04-25 17:52 - 2014-02-12 00:06 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS Utility
2014-04-25 17:49 - 2014-02-13 22:21 - 00000000 ____D () C:\ProgramData\Websteroids
2014-04-25 12:22 - 2014-04-25 12:22 - 00000000 ____D () C:\Users\Louba\Documents\PC Speed Maximizer
2014-04-24 23:55 - 2014-02-11 00:10 - 00000000 ____D () C:\Users\Louba\AppData\Roaming\Skype
2014-04-24 23:14 - 2014-02-11 00:10 - 00002699 _____ () C:\Users\Public\Desktop\Skype.lnk
2014-04-24 23:14 - 2014-02-11 00:10 - 00000000 ____D () C:\ProgramData\Skype
2014-04-24 23:14 - 2014-02-11 00:10 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-04-24 23:06 - 2014-04-24 23:06 - 00067342 _____ () C:\Users\Louba\Documents\cc_20140424_230608.reg
2014-04-24 23:03 - 2011-04-13 04:33 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
2014-04-24 22:51 - 2014-04-24 22:51 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Internet Security
2014-04-24 22:50 - 2014-04-24 22:50 - 00000000 ____D () C:\Windows\ELAMBKUP
2014-04-24 22:49 - 2014-04-24 22:49 - 00000000 ____D () C:\Program Files (x86)\Kaspersky Lab
2014-04-24 22:15 - 2014-04-24 22:15 - 00002253 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-04-24 22:15 - 2014-02-10 23:53 - 00000000 ____D () C:\Users\Louba\AppData\Local\Google
2014-04-24 22:11 - 2011-04-13 04:33 - 00004120 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-04-24 22:11 - 2011-04-13 04:33 - 00003868 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-04-17 23:46 - 2014-03-02 13:40 - 00000000 ____D () C:\Users\Louba\AppData\Roaming\SoftGrid Client
2014-04-15 22:04 - 2014-02-25 13:29 - 00000000 ____D () C:\ProgramData\CanonIJPLM
2014-04-15 22:02 - 2014-04-15 22:02 - 00000000 ____D () C:\ProgramData\CanonIJ
2014-04-15 22:01 - 2014-04-15 22:01 - 00000000 ___HD () C:\ProgramData\CanonIJScan
2014-04-15 22:01 - 2014-04-15 22:01 - 00000000 ____D () C:\Users\Louba\AppData\Roaming\Canon
2014-04-15 22:01 - 2014-04-15 22:01 - 00000000 _____ () C:\Users\Louba\Sti_Trace.log
2014-04-15 19:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\he-IL
2014-04-15 19:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\SysWOW64\ar-SA
2014-04-15 19:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\he-IL
2014-04-15 19:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\system32\ar-SA
2014-04-15 19:15 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\PolicyDefinitions
2014-04-11 00:33 - 2014-02-11 18:15 - 00000000 ____D () C:\Windows\system32\MRT
2014-04-11 00:31 - 2014-02-11 18:14 - 90655440 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-04-04 10:16 - 2009-07-14 07:08 - 00032542 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-03-31 09:35 - 2014-02-11 00:32 - 00270496 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-03-28 05:13 - 2014-02-13 21:52 - 00000000 ____D () C:\Users\Louba\AppData\Roaming\vlc
2014-03-28 05:13 - 2014-02-12 00:26 - 00000000 ____D () C:\ProgramData\P4G
2014-03-28 05:12 - 2009-07-14 05:20 - 00000000 ____D () C:\Windows\registration
2014-03-27 20:16 - 2014-03-27 20:16 - 00000000 ____D () C:\ProgramData\Mozilla
2014-03-27 20:16 - 2014-03-27 20:16 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-03-27 20:16 - 2014-02-11 00:04 - 00000000 ____D () C:\Program Files (x86)\Mozilla Thunderbird

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2009-07-29 07:04

==================== End Of Log ============================
--- --- ---


Additional scan result of Farbar Recovery Scan Tool (x64) Version: 25-04-2014 01
Ran by Louba at 2014-04-25 18:41:45
Running from C:\Users\Louba\Downloads
Boot Mode: Normal

==================== Security Center ========================

AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}

==================== Installed Programs ======================

Adobe Flash Player 10 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: - Adobe Systems Incorporated)
Adobe Flash Player 12 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
ASUS AI Recovery (HKLM-x32\...\{38253529-D97D-4901-AE53-5CC9736D3A2E}) (Version: 1.0.13 - ASUS)
ASUS LifeFrame3 (HKLM-x32\...\{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}) (Version: 3.0.20 - ASUS)
ASUS Power4Gear Hybrid (HKLM\...\{9B6239BF-4E85-4590-8D72-51E30DB1A9AA}) (Version: 1.1.43 - ASUS)
ASUS Splendid Video Enhancement Technology (HKLM-x32\...\{0969AF05-4FF6-4C00-9406-43599238DE0D}) (Version: 1.02.0030 - ASUS)
ASUS Virtual Camera (HKLM-x32\...\{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}) (Version: 1.0.21 - asus)
AsusVibe2.0 (HKLM-x32\...\Asus Vibe2.0) (Version: - ASUSTEK)
ATK Package (HKLM-x32\...\{AB5C933E-5C7D-4D30-B314-9C83A49B94BE}) (Version: 1.0.0010 - ASUS)
Canon Easy-PhotoPrint EX (HKLM-x32\...\Easy-PhotoPrint EX) (Version:  - )
Canon Easy-WebPrint EX (HKLM-x32\...\Easy-WebPrint EX) (Version: - Canon Inc.)
Canon Inkjet Printer/Scanner/Fax Extended Survey Program (HKLM-x32\...\CANONIJPLM100) (Version:  - )
Canon MP Navigator EX 4.0 (HKLM-x32\...\MP Navigator EX 4.0) (Version:  - )
Canon MP280 series Benutzerregistrierung (HKLM-x32\...\Canon MP280 series Benutzerregistrierung) (Version:  - )
Canon MP280 series MP Drivers (HKLM\...\{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MP280_series) (Version:  - )
Canon My Printer (HKLM-x32\...\CanonMyPrinter) (Version:  - )
Canon Solution Menu EX (HKLM-x32\...\CanonSolutionMenuEX) (Version:  - )
CCleaner (HKLM\...\CCleaner) (Version: 4.10 - Piriform)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
ETDWare PS/2-X64 (HKLM\...\Elantech) (Version: - ELAN Microelectronic Corp.)
Free YouTube to MP3 Converter version (HKLM-x32\...\Free YouTube to MP3 Converter_is1) (Version: - DVDVideoSoft Ltd.)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galería fotográfica de Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Gnumeric Spreadsheet 1.7.12-win32-1 (HKCU\...\Gnumeric) (Version: 1.7.12-win32-1 - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 34.0.1847.116 - Google Inc.)
Google Update Helper (x32 Version: - Google Inc.) Hidden
Intel PROSet Wireless (Version:  - ) Hidden
Intel PROSet Wireless (x32 Version:  - ) Hidden
Intel(R) Control Center (HKLM-x32\...\{F8A9085D-4C7A-41a9-8A77-C8998A96C421}) (Version: - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: - Intel Corporation)
Intel(R) PROSet/Wireless WiFi Software (HKLM\...\{3C41721F-AF0F-4086-AA1C-4C7F29076228}) (Version: 14.01.1000 - Intel Corporation)
Intel(R) Turbo Boost Technology Monitor (HKLM\...\{39F4C6F9-618A-4E5B-8FB2-6BD661174E32}) (Version: 1.0.400.4 - Intel)
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Kaspersky Internet Security (HKLM-x32\...\InstallWIX_{6F6873E3-5C92-4049-B511-231A138DD090}) (Version: - Kaspersky Lab)
Kaspersky Internet Security (x32 Version: - Kaspersky Lab) Hidden
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2010 (HKLM-x32\...\{95140000-0070-0000-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (HKLM-x32\...\Office14.Click2Run) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Klick-und-Los 2010 (Version: 14.0.4763.1000 - Microsoft Corporation) Hidden
Microsoft Office Starter 2010 - Deutsch (HKLM-x32\...\{90140011-0066-0407-0000-0000000FF1CE}) (Version: 14.0.4763.1000 - Microsoft Corporation)
Microsoft Office Word Viewer 2003 (HKLM-x32\...\{90850407-6000-11D3-8CFE-0150048383C9}) (Version: 11.0.8173.0 - Microsoft Corporation)
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30214.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}) (Version: 8.0.59192 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Firefox 27.0 (x86 de) (HKLM-x32\...\Mozilla Firefox 27.0 (x86 de)) (Version: 27.0 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 24.4.0 - Mozilla)
Mozilla Thunderbird 24.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 24.4.0 (x86 de)) (Version: 24.4.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
NVIDIA Control Panel 268.56 (Version: 268.56 - NVIDIA Corporation) Hidden
NVIDIA Graphics Driver 268.56 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 268.56 - NVIDIA Corporation)
NVIDIA Install Application (Version: - NVIDIA Corporation) Hidden
NVIDIA Optimus 1.0.22 (Version: 1.0.22 - NVIDIA Corporation) Hidden
NVIDIA Update Components (Version: 1.0.22 - NVIDIA Corporation) Hidden
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Realtek Ethernet Controller Driver (HKLM-x32\...\{8833FFB6-5B0C-4764-81AA-06DFEED9A476}) (Version: - Realtek)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: - Realtek Semiconductor Corp.)
Realtek USB 2.0 Reader Driver (HKLM-x32\...\{62BBB2F0-E220-4821-A564-730807D2C34D}) (Version: 6.1.7600.10001 - Realtek Semiconductor Corp.)
Skype™ 6.13 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.13.104 - Skype Technologies S.A.)
Sonic Focus (HKLM-x32\...\{09BCB9CE-964B-4BDA-AE46-B5A0ABEF1D3F}) (Version: - Synopsys )
TeamViewer 9 (HKLM-x32\...\TeamViewer 9) (Version: 9.0.25942 - TeamViewer)
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3508.1109 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Family Safety (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (HKLM-x32\...\{C32CE55C-12BA-4951-8797-0967FDEF556F}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX control for remote connections (HKLM-x32\...\{C5398A89-516C-4DAF-BA07-EE7949090E56}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{C63A1E60-B6A4-440B-89A5-1FC6E4AC1C94}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Messenger (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 影像中心 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live 程式集 (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
WinFlash (HKLM-x32\...\{8F21291E-0444-4B1D-B9F9-4370A73E346D}) (Version: 2.31.0 - ASUS)
Wireless Console 3 (HKLM-x32\...\{20FDF948-C8ED-4543-A539-F7F4AEF5AFA2}) (Version: 3.0.19 - ASUS)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Почта Windows Live (x32 Version: 15.4.3502.0922 - Корпорация Майкрософт) Hidden
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
גלריית התמונות של Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
بريد Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
معرض صور Windows Live (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden

==================== Restore Points  =========================

01-04-2014 09:50:29 Windows Update
09-04-2014 09:59:42 Windows Update
10-04-2014 22:30:37 Windows Update
15-04-2014 10:16:06 Windows Update
15-04-2014 13:22:16 Windows Update
22-04-2014 09:36:18 Windows Update
25-04-2014 15:46:54 Removed Fast Boot
25-04-2014 15:51:43 Removed ASUS FancyStart
25-04-2014 15:53:11 Removed ASUS SmartLogon
25-04-2014 15:58:30 Quitado Control ActiveX de Windows Live Mesh para conexiones remotas
25-04-2014 15:59:48 Contrôle ActiveX Windows Live Mesh pour connexions à distance wird entfernt
25-04-2014 16:01:08 Removido Controlo ActiveX do Windows Live Mesh para Ligações Remotas

==================== Hosts content: ==========================

2009-07-14 04:34 - 2009-06-10 23:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {13751808-2F01-455B-BC4D-0AC718FA8476} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2014-01-21] (Piriform Ltd)
Task: {60F398C6-F009-4FEB-B4EF-955537F134F2} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-04-13] (Google Inc.)
Task: {7EFAF18E-638B-4CAE-B4BD-70F0D0F5D035} - System32\Tasks\ACMON => C:\Program Files (x86)\ASUS\Splendid\ACMON.exe [2010-08-02] (ASUS)
Task: {84A77F86-B445-48DE-B57F-B89B693CD5C2} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-04-13] (Google Inc.)
Task: {F0098D35-FD47-4FAD-A249-EEBAE43133CC} - System32\Tasks\ATKOSD2 => C:\Program Files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe [2010-08-18] (ASUS)
Task: {F7A615A8-08D6-4927-A379-491F1EA52B63} - System32\Tasks\ASUS P4G => C:\Program Files\P4G\BatteryLife.exe [2010-12-02] (ASUS)
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2011-05-02 23:41 - 2011-05-02 23:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\Libeay32.dll
2014-02-25 13:29 - 2010-04-05 21:55 - 00116104 _____ () C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE
2010-04-03 05:21 - 2008-10-01 09:08 - 00011264 _____ () C:\Program Files (x86)\ASUS\Splendid\GLCDdll.dll
2010-07-15 02:11 - 2010-07-15 02:11 - 00031360 _____ () C:\Program Files\P4G\DevMng.dll
2011-07-07 08:12 - 2011-01-27 02:11 - 00094208 _____ () C:\Windows\System32\IccLibDll_x64.dll
2011-05-02 23:41 - 2011-05-02 23:41 - 01501696 _____ () C:\Program Files\Common Files\Intel\WirelessCommon\LIBEAY32.dll
2010-09-24 02:53 - 2010-09-24 02:53 - 01601536 _____ () C:\Program Files (x86)\ASUS\Wireless Console 3\wcourier.exe
2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll
2013-05-08 14:52 - 2013-05-08 14:52 - 01270464 _____ () C:\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 14.0.0\kpcengine.2.3.dll
2014-04-24 22:15 - 2014-04-02 03:57 - 00065352 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\chrome_elf.dll
2014-04-24 22:15 - 2014-04-02 03:57 - 00674632 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libglesv2.dll
2014-04-24 22:15 - 2014-04-02 03:57 - 00093000 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\libegl.dll
2014-04-24 22:15 - 2014-04-02 03:57 - 04081480 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\pdf.dll
2014-04-24 22:15 - 2014-04-02 03:58 - 00390472 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ppGoogleNaClPluginChrome.dll
2014-04-24 22:15 - 2014-04-02 03:57 - 01647432 _____ () C:\Program Files (x86)\Google\Chrome\Application\34.0.1847.116\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

==================== Safe Mode (whitelisted) ===================

==================== Disabled items from MSCONFIG ==============

MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: BDRegion => C:\Program Files (x86)\Cyberlink\Shared files\brs.exe
MSCONFIG\startupreg: CLMLServer => "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
MSCONFIG\startupreg: Setwallpaper => c:\programdata\SetWallpaper.cmd

==================== Faulty Device Manager Devices =============

==================== Event log errors: =========================

Application errors:

System errors:

Microsoft Office Sessions:

==================== Memory info =========================== 

Percentage of memory in use: 26%
Total physical RAM: 8103.77 MB
Available physical RAM: 5918.57 MB
Total Pagefile: 16205.72 MB
Available Pagefile: 13612.97 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:238.47 GB) (Free:177.26 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:332.7 GB) (Free:331.95 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596 GB) (Disk ID: 38601C96)
Partition 1: (Not Active) - (Size=25 GB) - (Type=1C)
Partition 2: (Active) - (Size=238 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=333 GB) - (Type=OF Extended)

==================== End Of Log ============================

GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-04-25 19:11:13
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 Hitachi_ rev.JEDO 596,17GB
Running: 7tx1ixl4.exe; Driver: C:\Users\Louba\AppData\Local\Temp\ugloapog.sys

---- User code sections - GMER 2.1 ----

.text  C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[1908] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69               0000000075981465 2 bytes [98, 75]
.text  C:\Program Files (x86)\Canon\IJPLM\IJPLMSVC.EXE[1908] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155              00000000759814bb 2 bytes [98, 75]
.text  ...                                                                                                                         * 2
?      C:\Windows\system32\mssprxy.dll [3116] entry point in ".rdata" section                                                      000000006e8d71e6
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 5                                   0000000077c511f5 8 bytes {JMP 0xd}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlWalkHeap + 416                                 0000000077c51390 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 159                        0000000077c5143f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlpEnsureBufferSize + 492                        0000000077c5158c 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 126                                0000000077c5191e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlDeleteAce + 636                                0000000077c51b1c 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!_vsnwprintf_s + 204                               0000000077c51bf0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 373                  0000000077c51d75 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlCreateActivationContext + 691                  0000000077c51eb3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!isalpha + 31                                      0000000077c51edf 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!_ui64toa + 84                                     0000000077c51f64 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!_strnicmp + 81                                    0000000077c51fbd 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelf + 7                            0000000077c51fd7 8 bytes {JMP 0xb}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 658                        0000000077c52272 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlImpersonateSelfEx + 801                        0000000077c52301 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlInstallFunctionTableCallback + 578             0000000077c52792 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlIsGenericTableEmptyAvl + 16                    0000000077c527b0 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableAvl + 18                  0000000077c527d2 8 bytes {JMP 0x10}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 79   0000000077c5282f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlEnumerateGenericTableWithoutSplayingAvl + 176  0000000077c52890 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  ...                                                                                                                         * 2
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 299          0000000077c52d1b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlValidRelativeSecurityDescriptor + 367          0000000077c52d5f 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  ...                                                                                                                         * 3
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlCutoverTimeToSystemTime + 483                  0000000077c53023 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 523                      0000000077c5323b 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlQueryRegistryValues + 912                      0000000077c533c0 16 bytes {JMP 0x4e}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 318                                     0000000077c53a5e 16 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!_itow_s + 403                                     0000000077c53ab3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 197         0000000077c53b85 8 bytes [10, 6A, F8, 7E, 00, 00, 00, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlpCheckDynamicTimeZoneInformation + 611         0000000077c53d23 8 bytes [00, 6A, F8, 7E, 00, 00, 00, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!RtlpGetLCIDFromLangInfoNode + 80                  0000000077c54190 8 bytes [A0, 69, F8, 7E, 00, 00, 00, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtSetInformationThread                            0000000077ca1380 8 bytes {JMP QWORD [RIP-0x4d4cf]}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtQueryInformationThread                          0000000077ca1500 8 bytes {JMP QWORD [RIP-0x4d498]}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtMapViewOfSection                                0000000077ca1530 8 bytes {JMP QWORD [RIP-0x4d9b1]}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtWriteVirtualMemory                              0000000077ca1650 8 bytes {JMP QWORD [RIP-0x4d7a7]}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtQueueApcThread                                  0000000077ca1700 8 bytes {JMP QWORD [RIP-0x4d9e3]}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtCreateThreadEx                                  0000000077ca1d30 8 bytes {JMP QWORD [RIP-0x4dba6]}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtGetContextThread                                0000000077ca1f80 8 bytes {JMP QWORD [RIP-0x4de55]}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\ntdll.dll!NtSetContextThread                                0000000077ca27e0 8 bytes {JMP QWORD [RIP-0x4e770]}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 312              00000000744d13cc 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuInitializeStartupContext + 471              00000000744d146b 8 bytes {JMP 0xffffffffffffffb0}
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessInit + 611                           00000000744d16d7 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessTerm + 3                             00000000744d16e3 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuGetStackPointer + 23                        00000000744d19db 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetStackPointer + 23                        00000000744d19fb 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuSetInstructionPointer + 23                  00000000744d1a1b 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuNotifyAffinityChange + 3                    00000000744d1a27 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuFlushInstructionCache + 23                  00000000744d1a63 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]
.text  C:\Users\Louba\Downloads\7tx1ixl4.exe[6696] C:\Windows\SYSTEM32\wow64cpu.dll!CpuProcessDebugEvent + 3                       00000000744d1a6f 8 bytes [0D, F0, AD, BA, DE, C0, AD, ...]

---- Registry - GMER 2.1 ----

Reg    HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\0025d3b2962e                                                 
Reg    HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\0025d3b2962e (not active ControlSet)                             

---- EOF - GMER 2.1 ----
Ich danke schon mal im Vorraus!

/// the machine
/// TB-Ausbilder

Scan mit Combofix
Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!

Downloade dir bitte Combofix vom folgenden Downloadspiegel: Link
  • WICHTIG: Speichere Combofix auf deinem Desktop.
  • Deaktiviere bitte alle deine Antivirensoftware sowie Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören. Combofix meckert auch manchmal trotzdem noch, das kannst du dann ignorieren, mir aber bitte mitteilen.
  • Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.
  • Während Combofix läuft bitte nicht am Computer arbeiten, die Maus bewegen oder ins Combofixfenster klicken!
  • Wenn Combofix fertig ist, wird es ein Logfile erstellen.
  • Bitte poste die C:\Combofix.txt in deiner nächsten Antwort (möglichst in CODE-Tags).
Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.



hab vergessen, den Windows Defender abzustellen, sollte ich das Programm nochmal ausführen?

Hier jedenfalls der Log:

ComboFix 14-04-20.01 - Louba 25.04.2014  20:15:19.2.8 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.8104.6540 [GMT 2:00]
ausgeführt von:: c:\users\Louba\Downloads\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
FW: Kaspersky Internet Security *Disabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
SP: Kaspersky Internet Security *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
(((((((((((((((((((((((   Dateien erstellt von 2014-03-25 bis 2014-04-25  ))))))))))))))))))))))))))))))
2014-04-25 18:17 . 2014-04-25 18:17	--------	d-----w-	c:\users\UpdatusUser\AppData\Local\temp
2014-04-25 18:17 . 2014-04-25 18:17	--------	d-----w-	c:\users\Default\AppData\Local\temp
2014-04-25 16:40 . 2014-04-25 16:42	--------	d-----w-	C:\FRST
2014-04-25 15:54 . 2014-04-25 15:54	--------	d-----w-	c:\programdata\ASUS
2014-04-25 15:52 . 2014-04-25 15:52	24576	----a-w-	c:\users\Louba\AppData\Local\uninst.tmp
2014-04-25 08:24 . 2014-04-17 03:31	10651704	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{672F737D-38FC-41D8-86E5-A87DA89739B6}\mpengine.dll
2014-04-24 20:51 . 2013-05-06 07:13	110176	----a-w-	c:\windows\system32\klfphc.dll
2014-04-24 20:50 . 2014-04-24 20:50	--------	d-----w-	c:\windows\ELAMBKUP
2014-04-24 20:49 . 2014-04-24 20:49	--------	d-----w-	c:\program files (x86)\Kaspersky Lab
2014-04-24 20:49 . 2014-04-25 17:12	--------	d-----w-	c:\programdata\Kaspersky Lab
2014-04-24 20:49 . 2013-10-17 13:47	620640	----a-w-	c:\windows\system32\drivers\klif.sys
2014-04-24 20:49 . 2013-06-08 18:18	112224	----a-w-	c:\windows\system32\drivers\klflt.sys
2014-04-15 20:02 . 2014-04-15 20:02	--------	d-----w-	c:\programdata\CanonIJ
2014-04-15 20:01 . 2014-04-15 20:01	--------	d-----w-	c:\users\Louba\AppData\Roaming\Canon
2014-04-10 08:30 . 2014-02-04 02:35	190912	----a-w-	c:\windows\system32\drivers\storport.sys
2014-03-27 18:16 . 2014-03-27 18:16	--------	d-----w-	c:\program files (x86)\Mozilla Maintenance Service
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
2014-04-25 16:10 . 2014-02-10 21:51	45056	----a-w-	c:\windows\system32\acovcnt.exe
2014-04-10 22:31 . 2014-02-11 16:14	90655440	----a-w-	c:\windows\system32\MRT.exe
2014-03-31 07:35 . 2014-02-10 22:32	270496	------w-	c:\windows\system32\MpSigStub.exe
2014-03-04 09:17 . 2014-04-10 08:30	44032	----a-w-	c:\windows\apppatch\acwow64.dll
2014-02-15 14:53 . 2014-02-15 14:53	194048	----a-w-	c:\windows\SysWow64\elshyph.dll
2014-02-15 14:52 . 2014-02-15 14:52	71680	----a-w-	c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-02-15 14:52 . 2014-02-15 14:52	645120	----a-w-	c:\windows\SysWow64\jsIntl.dll
2014-02-15 14:52 . 2014-02-15 14:52	62464	----a-w-	c:\windows\SysWow64\tdc.ocx
2014-02-15 14:52 . 2014-02-15 14:52	337408	----a-w-	c:\windows\SysWow64\html.iec
2014-02-15 14:52 . 2014-02-15 14:52	24576	----a-w-	c:\windows\SysWow64\licmgr10.dll
2014-02-15 14:52 . 2014-02-15 14:52	235008	----a-w-	c:\windows\system32\elshyph.dll
2014-02-15 14:52 . 2014-02-15 14:52	182272	----a-w-	c:\windows\SysWow64\msls31.dll
2014-02-15 14:52 . 2014-02-15 14:52	1051136	----a-w-	c:\windows\SysWow64\mshtmlmedia.dll
2014-02-15 14:52 . 2014-02-15 14:52	942592	----a-w-	c:\windows\system32\jsIntl.dll
2014-02-15 14:52 . 2014-02-15 14:52	86016	----a-w-	c:\windows\SysWow64\iesysprep.dll
2014-02-15 14:52 . 2014-02-15 14:52	86016	----a-w-	c:\windows\system32\RegisterIEPKEYs.exe
2014-02-15 14:52 . 2014-02-15 14:52	74240	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2014-02-15 14:52 . 2014-02-15 14:52	61952	----a-w-	c:\windows\SysWow64\MshtmlDac.dll
2014-02-15 14:52 . 2014-02-15 14:52	52224	----a-w-	c:\windows\system32\msfeedsbs.dll
2014-02-15 14:52 . 2014-02-15 14:52	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2014-02-15 14:52 . 2014-02-15 14:52	36352	----a-w-	c:\windows\SysWow64\imgutil.dll
2014-02-15 14:52 . 2014-02-15 14:52	247808	----a-w-	c:\windows\system32\msls31.dll
2014-02-15 14:52 . 2014-02-15 14:52	151552	----a-w-	c:\windows\SysWow64\iexpress.exe
2014-02-15 14:52 . 2014-02-15 14:52	139264	----a-w-	c:\windows\SysWow64\wextract.exe
2014-02-15 14:52 . 2014-02-15 14:52	13312	----a-w-	c:\windows\SysWow64\mshta.exe
2014-02-15 14:52 . 2014-02-15 14:52	13312	----a-w-	c:\windows\system32\msfeedssync.exe
2014-02-15 14:52 . 2014-02-15 14:52	111616	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2014-02-15 14:52 . 2014-02-15 14:52	90112	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2014-02-15 14:52 . 2014-02-15 14:52	84992	----a-w-	c:\windows\system32\mshtmled.dll
2014-02-15 14:52 . 2014-02-15 14:52	83968	----a-w-	c:\windows\system32\MshtmlDac.dll
2014-02-15 14:52 . 2014-02-15 14:52	81408	----a-w-	c:\windows\system32\icardie.dll
2014-02-15 14:52 . 2014-02-15 14:52	774144	----a-w-	c:\windows\system32\jscript.dll
2014-02-15 14:52 . 2014-02-15 14:52	77312	----a-w-	c:\windows\system32\tdc.ocx
2014-02-15 14:52 . 2014-02-15 14:52	62464	----a-w-	c:\windows\system32\pngfilt.dll
2014-02-15 14:52 . 2014-02-15 14:52	616104	----a-w-	c:\windows\system32\ieapfltr.dat
2014-02-15 14:52 . 2014-02-15 14:52	48640	----a-w-	c:\windows\system32\mshtmler.dll
2014-02-15 14:52 . 2014-02-15 14:52	48128	----a-w-	c:\windows\system32\imgutil.dll
2014-02-15 14:52 . 2014-02-15 14:52	413696	----a-w-	c:\windows\system32\html.iec
2014-02-15 14:52 . 2014-02-15 14:52	30208	----a-w-	c:\windows\system32\licmgr10.dll
2014-02-15 14:52 . 2014-02-15 14:52	263376	----a-w-	c:\windows\system32\iedkcs32.dll
2014-02-15 14:52 . 2014-02-15 14:52	243200	----a-w-	c:\windows\system32\webcheck.dll
2014-02-15 14:52 . 2014-02-15 14:52	235520	----a-w-	c:\windows\system32\url.dll
2014-02-15 14:52 . 2014-02-15 14:52	167424	----a-w-	c:\windows\system32\iexpress.exe
2014-02-15 14:52 . 2014-02-15 14:52	147968	----a-w-	c:\windows\system32\occache.dll
2014-02-15 14:52 . 2014-02-15 14:52	143872	----a-w-	c:\windows\system32\wextract.exe
2014-02-15 14:52 . 2014-02-15 14:52	13824	----a-w-	c:\windows\system32\mshta.exe
2014-02-15 14:52 . 2014-02-15 14:52	135680	----a-w-	c:\windows\system32\iepeers.dll
2014-02-15 14:52 . 2014-02-15 14:52	131072	----a-w-	c:\windows\system32\IEAdvpack.dll
2014-02-15 14:52 . 2014-02-15 14:52	1228800	----a-w-	c:\windows\system32\mshtmlmedia.dll
2014-02-15 14:52 . 2014-02-15 14:52	105984	----a-w-	c:\windows\system32\iesysprep.dll
2014-02-15 14:52 . 2014-02-15 14:52	101376	----a-w-	c:\windows\system32\inseng.dll
2014-02-11 22:34 . 2014-02-11 22:34	353576	------w-	c:\windows\SysWow64\msvcr71.dll
2014-02-11 22:34 . 2014-02-11 22:34	29480	------w-	c:\windows\SysWow64\msxml3a.dll
2014-02-11 22:34 . 2014-02-11 22:34	505128	------w-	c:\windows\SysWow64\msvcp71.dll
2014-02-11 22:32 . 2014-02-11 22:32	3058304	----a-w-	c:\windows\AsScrPro.exe
2014-02-10 22:08 . 2014-02-10 22:08	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-02-10 22:08 . 2014-02-10 22:08	692616	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2014-02-10 21:51 . 2010-06-24 18:33	22240	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-02-07 01:23 . 2014-03-12 12:01	3156480	----a-w-	c:\windows\system32\win32k.sys
2014-02-04 02:32 . 2014-03-12 12:00	1424384	----a-w-	c:\windows\system32\WindowsCodecs.dll
2014-02-04 02:32 . 2014-03-12 12:00	624128	----a-w-	c:\windows\system32\qedit.dll
2014-02-04 02:04 . 2014-03-12 12:00	1230336	----a-w-	c:\windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04 . 2014-03-12 12:00	509440	----a-w-	c:\windows\SysWow64\qedit.dll
2014-01-29 02:32 . 2014-03-12 12:01	484864	----a-w-	c:\windows\system32\wer.dll
2014-01-29 02:06 . 2014-03-12 12:01	381440	----a-w-	c:\windows\SysWow64\wer.dll
2014-01-28 02:32 . 2014-03-12 12:01	228864	----a-w-	c:\windows\system32\wwansvc.dll
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2011-04-13 02:33	433648	----a-w-	c:\programdata\Partner\Partner.dll
"CCleaner"="c:\program files\CCleaner\CCleaner64.exe" [2014-01-21 6087448]
"ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-13 2018032]
"SonicMasterTray"="c:\program files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe" [2010-07-10 984400]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-24 1601536]
"CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2014-02-11 3058304]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe;c:\programdata\Partner\Partner.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTSUVSTOR.sys;c:\windows\SYSNATIVE\Drivers\RTSUVSTOR.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R4 klflt;klflt;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
--- Andere Dienste/Treiber im Speicher ---
*NewlyCreated* - UGLOAPOG
*Deregistered* - ugloapog
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-04-24 20:15	1077576	----a-w-	c:\program files (x86)\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe
Inhalt des "geplante Tasks" Ordners
2014-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-13 02:33]
2014-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-13 02:33]
--------- X64 Entries -----------
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2011-04-13 02:33	750064	----a-w-	c:\programdata\Partner\Partner64.dll
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-10 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-10 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-10 418328]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-05-17 2226280]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-05-02 1935120]
"IntelTBRunOnce"="wscript.exe" [2013-10-12 168960]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2726728]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-05-17 11855976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
------- Zusätzlicher Suchlauf -------
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://asus.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer =
FF - ProfilePath - c:\users\Louba\AppData\Roaming\Mozilla\Firefox\Profiles\46i6jzyg.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
- - - - Entfernte verwaiste Registrierungseinträge - - - -
Toolbar-Locked - (no file)
HKLM_Wow6432Node-ActiveSetup-{2D46B6DC-2207-486B-B523-A557E6D54B47} - start
Toolbar-Locked - (no file)
HKLM-Run-ETDCtrl - c:\program files (x86)\Elantech\ETDCtrl.exe
--------------------- Gesperrte Registrierungsschluessel ---------------------
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
@Denied: (A 2) (Everyone)
@Denied: (Full) (Everyone)
Zeit der Fertigstellung: 2014-04-25  20:22:15
ComboFix-quarantined-files.txt  2014-04-25 18:22
Vor Suchlauf: 11 Verzeichnis(se), 189.571.067.904 Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 189.210.669.056 Bytes frei
- - End Of File - - A0994AD5BA99548E7D399BB9178E0BFF

ComboFix 14-04-20.01 - Louba 25.04.2014  20:50:07.3.8 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.8104.6497 [GMT 2:00]
ausgeführt von:: c:\users\Louba\Downloads\ComboFix.exe
AV: Kaspersky Internet Security *Disabled/Updated* {179979E8-273D-D14E-0543-2861940E4886}
FW: Kaspersky Internet Security *Disabled* {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
SP: Kaspersky Internet Security *Disabled/Updated* {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
((((((((((((((((((((((((((((((((((((   Weitere Löschungen   ))))))))))))))))))))))))))))))))))))))))))))))))
(((((((((((((((((((((((   Dateien erstellt von 2014-03-25 bis 2014-04-25  ))))))))))))))))))))))))))))))
2014-04-25 19:01 . 2014-04-25 19:01	--------	d-----w-	c:\users\UpdatusUser\AppData\Local\temp
2014-04-25 19:01 . 2014-04-25 19:01	--------	d-----w-	c:\users\Default\AppData\Local\temp
2014-04-25 16:40 . 2014-04-25 16:42	--------	d-----w-	C:\FRST
2014-04-25 15:54 . 2014-04-25 15:54	--------	d-----w-	c:\programdata\ASUS
2014-04-25 08:24 . 2014-04-17 03:31	10651704	----a-w-	c:\programdata\Microsoft\Windows Defender\Definition Updates\{672F737D-38FC-41D8-86E5-A87DA89739B6}\mpengine.dll
2014-04-24 20:51 . 2013-05-06 07:13	110176	----a-w-	c:\windows\system32\klfphc.dll
2014-04-24 20:50 . 2014-04-24 20:50	--------	d-----w-	c:\windows\ELAMBKUP
2014-04-24 20:49 . 2014-04-24 20:49	--------	d-----w-	c:\program files (x86)\Kaspersky Lab
2014-04-24 20:49 . 2014-04-25 17:12	--------	d-----w-	c:\programdata\Kaspersky Lab
2014-04-24 20:49 . 2013-10-17 13:47	620640	----a-w-	c:\windows\system32\drivers\klif.sys
2014-04-24 20:49 . 2013-06-08 18:18	112224	----a-w-	c:\windows\system32\drivers\klflt.sys
2014-04-15 20:02 . 2014-04-15 20:02	--------	d-----w-	c:\programdata\CanonIJ
2014-04-15 20:01 . 2014-04-15 20:01	--------	d-----w-	c:\users\Louba\AppData\Roaming\Canon
2014-04-10 08:30 . 2014-02-04 02:35	190912	----a-w-	c:\windows\system32\drivers\storport.sys
2014-03-27 18:16 . 2014-03-27 18:16	--------	d-----w-	c:\program files (x86)\Mozilla Maintenance Service
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
2014-04-25 16:10 . 2014-02-10 21:51	45056	----a-w-	c:\windows\system32\acovcnt.exe
2014-04-10 22:31 . 2014-02-11 16:14	90655440	----a-w-	c:\windows\system32\MRT.exe
2014-03-31 07:35 . 2014-02-10 22:32	270496	------w-	c:\windows\system32\MpSigStub.exe
2014-03-04 09:17 . 2014-04-10 08:30	44032	----a-w-	c:\windows\apppatch\acwow64.dll
2014-02-15 14:53 . 2014-02-15 14:53	194048	----a-w-	c:\windows\SysWow64\elshyph.dll
2014-02-15 14:52 . 2014-02-15 14:52	71680	----a-w-	c:\windows\SysWow64\RegisterIEPKEYs.exe
2014-02-15 14:52 . 2014-02-15 14:52	645120	----a-w-	c:\windows\SysWow64\jsIntl.dll
2014-02-15 14:52 . 2014-02-15 14:52	62464	----a-w-	c:\windows\SysWow64\tdc.ocx
2014-02-15 14:52 . 2014-02-15 14:52	337408	----a-w-	c:\windows\SysWow64\html.iec
2014-02-15 14:52 . 2014-02-15 14:52	24576	----a-w-	c:\windows\SysWow64\licmgr10.dll
2014-02-15 14:52 . 2014-02-15 14:52	235008	----a-w-	c:\windows\system32\elshyph.dll
2014-02-15 14:52 . 2014-02-15 14:52	182272	----a-w-	c:\windows\SysWow64\msls31.dll
2014-02-15 14:52 . 2014-02-15 14:52	1051136	----a-w-	c:\windows\SysWow64\mshtmlmedia.dll
2014-02-15 14:52 . 2014-02-15 14:52	942592	----a-w-	c:\windows\system32\jsIntl.dll
2014-02-15 14:52 . 2014-02-15 14:52	86016	----a-w-	c:\windows\SysWow64\iesysprep.dll
2014-02-15 14:52 . 2014-02-15 14:52	86016	----a-w-	c:\windows\system32\RegisterIEPKEYs.exe
2014-02-15 14:52 . 2014-02-15 14:52	74240	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2014-02-15 14:52 . 2014-02-15 14:52	61952	----a-w-	c:\windows\SysWow64\MshtmlDac.dll
2014-02-15 14:52 . 2014-02-15 14:52	52224	----a-w-	c:\windows\system32\msfeedsbs.dll
2014-02-15 14:52 . 2014-02-15 14:52	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2014-02-15 14:52 . 2014-02-15 14:52	36352	----a-w-	c:\windows\SysWow64\imgutil.dll
2014-02-15 14:52 . 2014-02-15 14:52	247808	----a-w-	c:\windows\system32\msls31.dll
2014-02-15 14:52 . 2014-02-15 14:52	151552	----a-w-	c:\windows\SysWow64\iexpress.exe
2014-02-15 14:52 . 2014-02-15 14:52	139264	----a-w-	c:\windows\SysWow64\wextract.exe
2014-02-15 14:52 . 2014-02-15 14:52	13312	----a-w-	c:\windows\SysWow64\mshta.exe
2014-02-15 14:52 . 2014-02-15 14:52	13312	----a-w-	c:\windows\system32\msfeedssync.exe
2014-02-15 14:52 . 2014-02-15 14:52	111616	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2014-02-15 14:52 . 2014-02-15 14:52	90112	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2014-02-15 14:52 . 2014-02-15 14:52	84992	----a-w-	c:\windows\system32\mshtmled.dll
2014-02-15 14:52 . 2014-02-15 14:52	83968	----a-w-	c:\windows\system32\MshtmlDac.dll
2014-02-15 14:52 . 2014-02-15 14:52	81408	----a-w-	c:\windows\system32\icardie.dll
2014-02-15 14:52 . 2014-02-15 14:52	774144	----a-w-	c:\windows\system32\jscript.dll
2014-02-15 14:52 . 2014-02-15 14:52	77312	----a-w-	c:\windows\system32\tdc.ocx
2014-02-15 14:52 . 2014-02-15 14:52	62464	----a-w-	c:\windows\system32\pngfilt.dll
2014-02-15 14:52 . 2014-02-15 14:52	616104	----a-w-	c:\windows\system32\ieapfltr.dat
2014-02-15 14:52 . 2014-02-15 14:52	48640	----a-w-	c:\windows\system32\mshtmler.dll
2014-02-15 14:52 . 2014-02-15 14:52	48128	----a-w-	c:\windows\system32\imgutil.dll
2014-02-15 14:52 . 2014-02-15 14:52	413696	----a-w-	c:\windows\system32\html.iec
2014-02-15 14:52 . 2014-02-15 14:52	30208	----a-w-	c:\windows\system32\licmgr10.dll
2014-02-15 14:52 . 2014-02-15 14:52	263376	----a-w-	c:\windows\system32\iedkcs32.dll
2014-02-15 14:52 . 2014-02-15 14:52	243200	----a-w-	c:\windows\system32\webcheck.dll
2014-02-15 14:52 . 2014-02-15 14:52	235520	----a-w-	c:\windows\system32\url.dll
2014-02-15 14:52 . 2014-02-15 14:52	167424	----a-w-	c:\windows\system32\iexpress.exe
2014-02-15 14:52 . 2014-02-15 14:52	147968	----a-w-	c:\windows\system32\occache.dll
2014-02-15 14:52 . 2014-02-15 14:52	143872	----a-w-	c:\windows\system32\wextract.exe
2014-02-15 14:52 . 2014-02-15 14:52	13824	----a-w-	c:\windows\system32\mshta.exe
2014-02-15 14:52 . 2014-02-15 14:52	135680	----a-w-	c:\windows\system32\iepeers.dll
2014-02-15 14:52 . 2014-02-15 14:52	131072	----a-w-	c:\windows\system32\IEAdvpack.dll
2014-02-15 14:52 . 2014-02-15 14:52	1228800	----a-w-	c:\windows\system32\mshtmlmedia.dll
2014-02-15 14:52 . 2014-02-15 14:52	105984	----a-w-	c:\windows\system32\iesysprep.dll
2014-02-15 14:52 . 2014-02-15 14:52	101376	----a-w-	c:\windows\system32\inseng.dll
2014-02-11 22:34 . 2014-02-11 22:34	353576	------w-	c:\windows\SysWow64\msvcr71.dll
2014-02-11 22:34 . 2014-02-11 22:34	29480	------w-	c:\windows\SysWow64\msxml3a.dll
2014-02-11 22:34 . 2014-02-11 22:34	505128	------w-	c:\windows\SysWow64\msvcp71.dll
2014-02-11 22:32 . 2014-02-11 22:32	3058304	----a-w-	c:\windows\AsScrPro.exe
2014-02-10 22:08 . 2014-02-10 22:08	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2014-02-10 22:08 . 2014-02-10 22:08	692616	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2014-02-10 21:51 . 2010-06-24 18:33	22240	----a-w-	c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2014-02-07 01:23 . 2014-03-12 12:01	3156480	----a-w-	c:\windows\system32\win32k.sys
2014-02-04 02:32 . 2014-03-12 12:00	1424384	----a-w-	c:\windows\system32\WindowsCodecs.dll
2014-02-04 02:32 . 2014-03-12 12:00	624128	----a-w-	c:\windows\system32\qedit.dll
2014-02-04 02:04 . 2014-03-12 12:00	1230336	----a-w-	c:\windows\SysWow64\WindowsCodecs.dll
2014-02-04 02:04 . 2014-03-12 12:00	509440	----a-w-	c:\windows\SysWow64\qedit.dll
2014-01-29 02:32 . 2014-03-12 12:01	484864	----a-w-	c:\windows\system32\wer.dll
2014-01-29 02:06 . 2014-03-12 12:01	381440	----a-w-	c:\windows\SysWow64\wer.dll
2014-01-28 02:32 . 2014-03-12 12:01	228864	----a-w-	c:\windows\system32\wwansvc.dll
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2011-04-13 02:33	433648	----a-w-	c:\programdata\Partner\Partner.dll
"CCleaner"="c:\program files\CCleaner\CCleaner64.exe" [2014-01-21 6087448]
"ASUSPRP"="c:\program files (x86)\ASUS\APRP\APRP.EXE" [2011-04-13 2018032]
"SonicMasterTray"="c:\program files (x86)\ASUS\Sonic Focus\SonicFocusTray.exe" [2010-07-10 984400]
"ATKOSD2"="c:\program files (x86)\ASUS\ATK Package\ATKOSD2\ATKOSD2.exe" [2010-08-17 5732992]
"ATKMEDIA"="c:\program files (x86)\ASUS\ATK Package\ATK Media\DMedia.exe" [2010-10-07 170624]
"HControlUser"="c:\program files (x86)\ASUS\ATK Package\ATK Hotkey\HControlUser.exe" [2009-06-19 105016]
"Wireless Console 3"="c:\program files (x86)\ASUS\Wireless Console 3\wcourier.exe" [2010-09-24 1601536]
"CanonSolutionMenuEx"="c:\program files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE" [2010-04-02 1185112]
"ASUS Screen Saver Protector"="c:\windows\AsScrPro.exe" [2014-02-11 3058304]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\KasperskyAntiVirus]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 L1C;NDIS Miniport Driver for Atheros AR8131/AR8132 PCI-E Ethernet Controller (NDIS 6.20);c:\windows\system32\DRIVERS\L1C62x64.sys;c:\windows\SYSNATIVE\DRIVERS\L1C62x64.sys [x]
R3 MyWiFiDHCPDNS;Wireless PAN DHCP Server;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe;c:\program files\Intel\WiFi\bin\PanDhcpDns.exe [x]
R3 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe;c:\programdata\Partner\Partner.exe [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RTSUVSTOR.sys;c:\windows\SYSNATIVE\Drivers\RTSUVSTOR.sys [x]
R3 SiSGbeLH;SiS191/SiS190 Ethernet Device NDIS 6.0 Driver;c:\windows\system32\DRIVERS\SiSG664.sys;c:\windows\SYSNATIVE\DRIVERS\SiSG664.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R4 klflt;klflt;c:\windows\system32\DRIVERS\klflt.sys;c:\windows\SYSNATIVE\DRIVERS\klflt.sys [x]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe;c:\program files\Windows Live\Mesh\wlcrasvc.exe [x]
S0 nvpciflt;nvpciflt;c:\windows\system32\DRIVERS\nvpciflt.sys;c:\windows\SYSNATIVE\DRIVERS\nvpciflt.sys [x]
S1 ATKWMIACPIIO;ATKWMIACPI Driver;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys;c:\program files (x86)\ASUS\ATK Package\ATK WMIACPI\atkwmiacpi64.sys [x]
S1 KLIM6;Kaspersky Anti-Virus NDIS 6 Filter;c:\windows\system32\DRIVERS\klim6.sys;c:\windows\SYSNATIVE\DRIVERS\klim6.sys [x]
S1 klpd;klpd;c:\windows\system32\DRIVERS\klpd.sys;c:\windows\SYSNATIVE\DRIVERS\klpd.sys [x]
S1 kltdi;kltdi;c:\windows\system32\DRIVERS\kltdi.sys;c:\windows\SYSNATIVE\DRIVERS\kltdi.sys [x]
S1 kneps;kneps;c:\windows\system32\DRIVERS\kneps.sys;c:\windows\SYSNATIVE\DRIVERS\kneps.sys [x]
S2 ASMMAP64;ASMMAP64;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys;c:\program files (x86)\ASUS\ATK Package\ATKGFNEX\ASMMAP64.sys [x]
S2 cvhsvc;Client Virtualization Handler;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE;c:\program files (x86)\Common Files\Microsoft Shared\Virtualization Handler\CVHSVC.EXE [x]
S2 sftlist;Application Virtualization Client;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftlist.exe [x]
S2 TeamViewer9;TeamViewer 9;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe;c:\program files (x86)\TeamViewer\Version9\TeamViewer_Service.exe [x]
S2 TurboB;Turbo Boost UI Monitor driver;c:\windows\system32\DRIVERS\TurboB.sys;c:\windows\SYSNATIVE\DRIVERS\TurboB.sys [x]
S2 TurboBoost;Intel(R) Turbo Boost Technology Monitor;c:\program files\Intel\TurboBoost\TurboBoost.exe;c:\program files\Intel\TurboBoost\TurboBoost.exe [x]
S3 ETD;ELAN PS/2 Port Input Device;c:\windows\system32\DRIVERS\ETD.sys;c:\windows\SYSNATIVE\DRIVERS\ETD.sys [x]
S3 IntcDAud;Intel(R) Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys;c:\windows\SYSNATIVE\DRIVERS\IntcDAud.sys [x]
S3 klkbdflt;Kaspersky Lab KLKBDFLT;c:\windows\system32\DRIVERS\klkbdflt.sys;c:\windows\SYSNATIVE\DRIVERS\klkbdflt.sys [x]
S3 klmouflt;Kaspersky Lab KLMOUFLT;c:\windows\system32\DRIVERS\klmouflt.sys;c:\windows\SYSNATIVE\DRIVERS\klmouflt.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys;c:\windows\SYSNATIVE\DRIVERS\Rt64win7.sys [x]
S3 Sftfs;Sftfs;c:\windows\system32\DRIVERS\Sftfslh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftfslh.sys [x]
S3 Sftplay;Sftplay;c:\windows\system32\DRIVERS\Sftplaylh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftplaylh.sys [x]
S3 Sftredir;Sftredir;c:\windows\system32\DRIVERS\Sftredirlh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftredirlh.sys [x]
S3 Sftvol;Sftvol;c:\windows\system32\DRIVERS\Sftvollh.sys;c:\windows\SYSNATIVE\DRIVERS\Sftvollh.sys [x]
S3 sftvsa;Application Virtualization Service Agent;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe;c:\program files (x86)\Microsoft Application Virtualization Client\sftvsa.exe [x]
--- Andere Dienste/Treiber im Speicher ---
*NewlyCreated* - UGLOAPOG
*Deregistered* - ugloapog
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\active setup\installed components\{8A69D345-D564-463c-AFF1-A69D9E530F96}]
2014-04-24 20:15	1077576	----a-w-	c:\program files (x86)\Google\Chrome\Application\34.0.1847.116\Installer\chrmstp.exe
Inhalt des "geplante Tasks" Ordners
2014-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-13 02:33]
2014-04-25 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-04-13 02:33]
--------- X64 Entries -----------
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}]
2011-04-13 02:33	750064	----a-w-	c:\programdata\Partner\Partner64.dll
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-02-10 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-02-10 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-02-10 418328]
"RtHDVBg"="c:\program files\Realtek\Audio\HDA\RAVBg64.exe" [2011-05-17 2226280]
"ETDCtrl"="c:\program files (x86)\Elantech\ETDCtrl.exe" [BU]
"IntelPAN"="c:\program files\Common Files\Intel\WirelessCommon\iFrmewrk.exe" [2011-05-02 1935120]
"IntelTBRunOnce"="wscript.exe" [2013-10-12 168960]
"CanonMyPrinter"="c:\program files\Canon\MyPrinter\BJMyPrt.exe" [2010-03-25 2726728]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2011-05-17 11855976]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
------- Zusätzlicher Suchlauf -------
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://asus.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
TCP: DhcpNameServer =
FF - ProfilePath - c:\users\Louba\AppData\Roaming\Mozilla\Firefox\Profiles\46i6jzyg.default\
FF - prefs.js: browser.search.selectedEngine - Google
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
- - - - Entfernte verwaiste Registrierungseinträge - - - -
Toolbar-Locked - (no file)
--------------------- Gesperrte Registrierungsschluessel ---------------------
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10k.ocx, 1"
@Denied: (A 2) (Everyone)
@Denied: (Full) (Everyone)
Zeit der Fertigstellung: 2014-04-25  21:07:09
ComboFix-quarantined-files.txt  2014-04-25 19:07
ComboFix2.txt  2014-04-25 18:22
Vor Suchlauf: 15 Verzeichnis(se), Bytes frei
Nach Suchlauf: 16 Verzeichnis(se), 189.190.410.240 Bytes frei
- - End Of File - - 6118BBBBE126372BE3957A2777344C5A

Alt 26.04.2014, 15:24   #4
/// the machine
/// TB-Ausbilder

Windows 7: Laptop seit wenigen Tagen extrem langsam - Standard

Windows 7: Laptop seit wenigen Tagen extrem langsam

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

und ein frisches FRST log bitte.

