Aah ja.
Dann mal ohne Worte :
ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=7b4fd24618286d4383e4511fe444a540
# engine=16742
# end=finished
# remove_checked=false
# archives_checked=false
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-01-22 12:17:02
# local_time=2014-01-22 01:17:02 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.0.6001 NT Service Pack 1
# compatibility_mode=5892 16776573 100 100 26241 227882550 0 0
# scanned=136404
# found=0
# cleaned=0
# scan_time=3414
HIER DAS ERGEBNIS VON SECURITY CHECK :
Results of screen317's Security Check version 0.99.79
Windows Vista Service Pack 1 x86 (UAC is enabled)
Out of date service pack!!
Internet Explorer 7
Out of date! ``````````````Antivirus/Firewall Check:``````````````
Kaspersky Internet Security
Antivirus up to date! (On Access scanning
disabled!)
`````````Anti-malware/Other Utilities Check:`````````
Java(TM) 6 Update 31
Java version out of Date!
Adobe Flash Player 11.9.900.170
Mozilla Firefox (26.0)
````````Process Check: objlist.exe by Laurent````````
Kaspersky Lab Kaspersky Internet Security 14.0.0 avp.exe
Kaspersky Lab Kaspersky Internet Security 14.0.0 avpui.exe
Kaspersky Lab Kaspersky Internet Security 14.0.0 wmi32.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: %
````````````````````End of Log``````````````````````
DAS IST DAS NEUE FRST
FRST Logfile:
FRST Logfile:
Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 23-01-2014
Ran by Oliver B (administrator) on OLIVERB-PC on 23-01-2014 00:08:36
Running from C:\Users\Oliver B\Downloads
Microsoft® Windows Vista™ Home Premium Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 7
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(Validity Sensors, Inc.) C:\Windows\System32\vfsFPService.exe
(Arachnoid Biometrics Identification Group Corp.) C:\Program Files\Acer\Acer Bio Protection\CompPtcVUI.exe
(Microsoft Corporation) C:\Windows\System32\wlanext.exe
(Agere Systems) C:\Windows\System32\agrsmsvc.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe
(NewTech Infosystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe
() C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe
(Egis Incorporated) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
() C:\Program Files\Acer\Empowering Technology\Service\ETService.exe
(Intel(R) Corporation) C:\Program Files\Intel\WiFi\bin\EvtEng.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe
() C:\Program Files\Acer\Acer Bio Protection\BASVC.exe
(Hewlett-Packard Company) C:\Program Files\Common Files\LightScribe\LSSrvc.exe
() C:\ACER\Mobility Center\MobilityService.exe
(NewTech InfoSystems, Inc.) C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe
() C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe
(Intel(R) Corporation) C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
() C:\Program Files\Cyberlink\Shared files\RichVideo.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\RS_Service.exe
(Kaspersky Lab ZAO) C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avpui.exe
(Intel Corporation) C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
(Realtek Semiconductor) C:\Windows\RtHDVCpl.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
(Egis Incorporated) C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSLoader.exe
() C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
(Arachnoid Biometrics Identification Group Corp.) C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe
() C:\Windows\PLFSetI.exe
(Dritek System Inc.) C:\Program Files\Launch Manager\LManager.exe
(Acer Inc.) C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe
(Acer Incorporated) C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe
(CyberLink Corp.) C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe
(CyberLink) C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe
(Acer Corp.) C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(Google Inc.) C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer VCM\AcerVCM.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Realtek Semiconductor Corp.) C:\Users\Oliver B\AppData\Local\temp\RtkBtMnt.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(Microsoft Corporation) C:\Windows\System32\wbem\unsecapp.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
(Acer Inc.) C:\Program Files\Acer\Acer VCM\acp2HID.exe
(Synaptics, Inc.) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework\v4.0.30319\WPF\WPFFontCache_v0400.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\firefox.exe
(Microsoft Corporation) C:\Windows\System32\wuauclt.exe
(acer) C:\Program Files\Acer\Empowering Technology\NotificationCenter\Framework.NotificationCenter.exe
(Google) C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
(Mozilla Corporation) C:\Program Files\Mozilla Firefox\plugin-container.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Adobe Systems, Inc.) C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_9_900_170.exe
(Farbar) C:\Users\Oliver B\Downloads\FRST(2).exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [IAAnotif] - C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe [182808 2008-07-20] (Intel Corporation)
HKLM\...\Run: [RtHDVCpl] - C:\Windows\RtHDVCpl.exe [6139904 2008-05-07] (Realtek Semiconductor)
HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1037608 2008-04-04] (Synaptics, Inc.)
HKLM\...\Run: [eDataSecurity Loader] - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDSloader.exe [526896 2008-07-29] (Egis Incorporated)
HKLM\...\Run: [BkupTray] - C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTray.exe [28672 2008-04-25] ()
HKLM\...\Run: [NvCplDaemon] - C:\Windows\system32\NvCpl.dll [13548064 2008-08-01] (NVIDIA Corporation)
HKLM\...\Run: [NvMediaCenter] - C:\Windows\system32\NvMcTray.dll [92704 2008-08-01] (NVIDIA Corporation)
HKLM\...\Run: [WarReg_PopUp] - C:\Program Files\Acer\WR_PopUp\WarReg_PopUp.exe [303104 2008-01-29] (Acer Incorporated)
HKLM\...\Run: [Google Desktop Search] - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [24064 2011-11-10] (Google)
HKLM\...\Run: [ZPdtWzdVitaKey MC3000] - C:\Program Files\Acer\Acer Bio Protection\PdtWzd.exe [3719680 2011-11-10] (Arachnoid Biometrics Identification Group Corp.)
HKLM\...\Run: [PLFSetI] - C:\Windows\PLFSetI.exe [200704 2008-06-30] ()
HKLM\...\Run: [LManager] - C:\Program Files\Launch Manager\LManager.exe [809480 2008-06-16] (Dritek System Inc.)
HKLM\...\Run: [ePower_DMC] - C:\Program Files\Acer\Empowering Technology\ePower\ePower_DMC.exe [405504 2008-08-01] (Acer Inc.)
HKLM\...\Run: [eAudio] - C:\Program Files\Acer\Empowering Technology\eAudio\eAudio.exe [544768 2008-05-30] (Acer Incorporated)
HKLM\...\Run: [ArcadeDeluxeAgent] - C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\ArcadeDeluxeAgent.exe [147456 2008-07-24] (CyberLink Corp.)
HKLM\...\Run: [CLMLServer] - C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvc.exe [167936 2008-07-24] (CyberLink)
HKLM\...\Run: [PlayMovie] - C:\Program Files\Acer Arcade Deluxe\PlayMovie\PMVService.exe [167936 2008-07-18] (Acer Corp.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [254696 2012-01-18] (Sun Microsystems, Inc.)
Winlogon\Notify\AWinNotifyVitaKey MC3000: C:\Program Files\Acer\Acer Bio Protection\WinNotify.dll (Arachnoid Biometrics Identification Group Corp.)
HKCU\...\Run: [swg] - C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe [68856 2011-11-10] (Google Inc.)
HKCU\...\Run: [ehTray.exe] - C:\Windows\ehome\ehTray.exe [125952 2008-01-21] (Microsoft Corporation)
HKU\Default\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2008-01-21] (Microsoft Corporation)
HKU\Default\...\RunOnce: [AcerScrSav] -
HKU\Default User\...\Run: [WindowsWelcomeCenter] - C:\Windows\system32\oobefldr.dll [ 2008-01-21] (Microsoft Corporation)
HKU\Default User\...\RunOnce: [AcerScrSav] -
AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~1\GoogleDesktopNetwork3.dll => C:\Program Files\Google\Google Desktop Search\GoogleDesktopNetwork3.dll [113664 2011-11-10] (Google)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1111&m=aspire_8930
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://global.acer.com
HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://homepage.acer.com/rdr.aspx?b=ACAW&l=0407&s=2&o=vp32&d=1111&m=aspire_8930
SearchScopes: HKLM - DefaultScope value is missing.
SearchScopes: HKLM - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW
SearchScopes: HKCU - DefaultScope {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_deDE457
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search
SearchScopes: HKCU - {67A2568C-7A0A-4EED-AECC-B5405DE63B64} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7ACAW_deDE457
BHO: Content Blocker Plugin - {5564CC73-EFA7-4CBF-918A-5CF7FBBFFF4F} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\ContentBlocker\ie_content_blocker_plugin.dll (Kaspersky Lab ZAO)
BHO: Virtual Keyboard Plugin - {73455575-E40C-433C-9784-C78DC7761455} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\VirtualKeyboard\ie_virtual_keyboard_plugin.dll (Kaspersky Lab ZAO)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
BHO: ShowBarObj Class - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ActiveToolBand.dll (Egis)
BHO: Safe Money Plugin - {9E6D0D23-3D72-4A94-AE1F-2D167624E3D9} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\OnlineBanking\online_banking_bho.dll (Kaspersky Lab ZAO)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.9012.1008\swg.dll (Google Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll (Sun Microsystems, Inc.)
BHO: URL Advisor Plugin - {E33CF602-D945-461A-83F0-819F76A199F8} - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\IEExt\UrlAdvisor\klwtbbho.dll (Kaspersky Lab ZAO)
Toolbar: HKLM - Acer eDataSecurity Management - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Handler: ms-itss - {0A9007C0-4076-11D3-8789-0000F8105754} - c:\Program Files\Common Files\Microsoft Shared\Information Retrieval\msitss.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 83.169.184.161 83.169.184.225
FireFox:
========
FF ProfilePath: C:\Users\Oliver B\AppData\Roaming\Mozilla\Firefox\Profiles\fu6c9nmz.default
FF Homepage: hxxp://www.google.de
FF NetworkProxy: "type", 0
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin: @adobe.com/ShockwavePlayer - C:\Windows\system32\Adobe\Director\np32dsw_1200112.dll (Adobe Systems, Inc.)
FF Plugin: @java.com/JavaPlugin - C:\Program Files\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - C:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin: @microsoft.com/WPF,version=3.5 - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
FF Extension: Anti-Banner - C:\Program Files\Mozilla Firefox\extensions\KavAntiBanner@kaspersky.ru_bak2 [2013-12-10]
FF Extension: Modul zur Link-Untersuchung - C:\Program Files\Mozilla Firefox\extensions\linkfilter@kaspersky.ru_bak2 [2013-12-10]
FF HKLM\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension\ []
FF HKLM\...\Firefox\Extensions: - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com
FF Extension: Kaspersky URL Advisor - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\url_advisor@kaspersky.com [2013-11-08]
FF HKLM\...\Firefox\Extensions: [virtual_keyboard@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\virtual_keyboard@kaspersky.com [2013-11-08]
FF HKLM\...\Firefox\Extensions: [content_blocker@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\content_blocker@kaspersky.com [2013-11-08]
FF HKLM\...\Firefox\Extensions: [anti_banner@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com
FF Extension: Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\anti_banner@kaspersky.com [2013-11-08]
FF HKLM\...\Firefox\Extensions: [online_banking@kaspersky.com] - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com
FF Extension: Safe Money - C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\FFExt\online_banking@kaspersky.com [2013-11-08]
========================== Services (Whitelisted) =================
R2 avp; C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\avp.exe [214512 2013-10-17] (Kaspersky Lab ZAO)
R2 CLHNService; C:\Program Files\Acer Arcade Deluxe\HomeMedia\Kernel\DMP\CLHNService.exe [81504 2008-01-16] ()
R2 ETService; C:\Program Files\Acer\Empowering Technology\Service\ETService.exe [24576 2008-06-02] ()
S3 GoogleDesktopManager-080708-050100; C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe [24064 2011-11-10] (Google)
R2 IGBASVC; C:\Program Files\Acer\Acer Bio Protection\BASVC.exe [3520512 2011-11-10] ()
R2 MobilityService; C:\Acer\Mobility Center\MobilityService.exe [110592 2007-12-06] ()
R2 NTISchedulerSvc; C:\Program Files\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe [131072 2008-04-25] ()
R2 RichVideo; C:\Program Files\Cyberlink\Shared files\RichVideo.exe [272024 2007-01-09] ()
R2 RS_Service; C:\Program Files\Acer\Acer VCM\RS_Service.exe [233472 2008-01-10] (Acer Incorporated)
==================== Drivers (Whitelisted) ====================
R0 AlfaFF; C:\Windows\System32\Drivers\AlfaFF.sys [43184 2011-11-10] (Alfa Corporation)
R1 DritekPortIO; C:\Program Files\Launch Manager\DPortIO.sys [20112 2006-11-02] (Dritek System Inc.)
R3 itecir; C:\Windows\System32\DRIVERS\itecir.sys [54784 2007-12-18] (ITE Tech. Inc. )
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [135776 2013-11-08] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [574560 2013-12-19] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [25696 2013-10-17] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [14432 2013-04-12] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [45024 2013-05-14] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [144992 2013-12-19] (Kaspersky Lab ZAO)
R3 L1E; C:\Windows\System32\DRIVERS\L1E60x86.sys [47104 2008-05-19] (Atheros Communications, Inc.)
R2 {49DE1C67-83F8-4102-99E0-C16DCC7EEC796}; C:\Program Files\Acer Arcade Deluxe\PlayMovie\000.fcl [61424 2008-07-18] (Cyberlink Corp.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [21504 2008-01-21] (Microsoft Corporation)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]
S3 IpInIp; system32\DRIVERS\ipinip.sys [x]
U5 klflt; C:\Windows\System32\Drivers\klflt.sys [94304 2013-06-08] (Kaspersky Lab ZAO)
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-23 00:08 - 2014-01-23 00:08 - 01222144 _____ (Farbar) C:\Users\Oliver B\Downloads\FRST(2).exe
2014-01-22 23:57 - 2014-01-22 23:58 - 00987425 _____ C:\Users\Oliver B\Downloads\SecurityCheck.exe
2014-01-22 00:18 - 2014-01-22 23:44 - 00000000 ____D C:\Program Files\ESET
2014-01-22 00:10 - 2014-01-22 00:10 - 02347384 _____ (ESET) C:\Users\Oliver B\Downloads\esetsmartinstaller_enu.exe
2014-01-20 08:51 - 2014-01-22 16:55 - 00002276 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-19 23:47 - 2014-01-19 23:47 - 01221120 _____ (Farbar) C:\Users\Oliver B\Downloads\FRST(1).exe
2014-01-19 23:37 - 2014-01-19 23:37 - 00001089 _____ C:\Users\Oliver B\Desktop\JRT.txt
2014-01-19 23:28 - 2014-01-19 23:28 - 00000000 ____D C:\Windows\ERUNT
2014-01-19 23:24 - 2014-01-19 23:24 - 01037068 _____ (Thisisu) C:\Users\Oliver B\Downloads\JRT.exe
2014-01-19 23:13 - 2014-01-19 23:16 - 00000000 ____D C:\AdwCleaner
2014-01-19 23:12 - 2014-01-19 23:12 - 01236282 _____ C:\Users\Oliver B\Downloads\AdwCleaner(1).exe
2014-01-15 22:32 - 2014-01-15 22:32 - 01236282 _____ C:\Users\Oliver B\Downloads\AdwCleaner.exe
2014-01-15 21:54 - 2014-01-15 21:54 - 00000000 ____D C:\Users\Oliver B\AppData\Roaming\Malwarebytes
2014-01-15 21:49 - 2014-01-15 21:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-15 21:37 - 2014-01-15 21:39 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\Oliver B\Downloads\mbam-setup.exe
2014-01-15 01:22 - 2014-01-15 01:22 - 00066126 _____ C:\Combo Fix text.txt
2014-01-15 01:13 - 2014-01-15 01:13 - 00066126 _____ C:\ComboFix.txt
2014-01-15 00:46 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2014-01-15 00:46 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2014-01-15 00:46 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-01-15 00:46 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-01-15 00:46 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-01-15 00:46 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2014-01-15 00:46 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2014-01-15 00:46 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2014-01-15 00:44 - 2014-01-15 01:13 - 00000000 ____D C:\Qoobox
2014-01-15 00:43 - 2014-01-15 01:10 - 00000000 ____D C:\Windows\erdnt
2014-01-15 00:41 - 2014-01-15 00:42 - 05165717 ____R (Swearware) C:\Users\Oliver B\Downloads\ComboFix.exe
2014-01-12 10:11 - 2014-01-20 00:11 - 00017675 _____ C:\Users\Oliver B\Downloads\Addition.txt
2014-01-12 10:10 - 2014-01-23 00:09 - 00018163 _____ C:\Users\Oliver B\Downloads\FRST.txt
2014-01-12 10:09 - 2014-01-12 10:09 - 00000000 ____D C:\FRST
2014-01-12 10:06 - 2014-01-12 10:06 - 01220096 _____ (Farbar) C:\Users\Oliver B\Downloads\FRST.exe
2014-01-11 20:00 - 2014-01-11 20:00 - 00000000 _____ C:\Windows\setuperr.log
2014-01-11 20:00 - 2014-01-11 20:00 - 00000000 _____ C:\Windows\setupact.log
2014-01-10 21:00 - 2014-01-10 21:00 - 00011799 _____ C:\Users\Oliver B\Downloads\hijackthis.log
2014-01-06 14:29 - 2014-01-06 14:41 - 00000000 ____D C:\Users\Oliver B\2014-01-06 EXILIM ROT
2013-12-29 22:19 - 2013-12-29 22:19 - 01995098 _____ C:\Users\Oliver B\Downloads\video-2010-08-17-23-07-49(2).3gp
==================== One Month Modified Files and Folders =======
2014-01-23 00:09 - 2014-01-12 10:10 - 00018163 _____ C:\Users\Oliver B\Downloads\FRST.txt
2014-01-23 00:08 - 2014-01-23 00:08 - 01222144 _____ (Farbar) C:\Users\Oliver B\Downloads\FRST(2).exe
2014-01-23 00:04 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-23 00:04 - 2006-11-02 13:47 - 00003216 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-22 23:58 - 2014-01-22 23:57 - 00987425 _____ C:\Users\Oliver B\Downloads\SecurityCheck.exe
2014-01-22 23:55 - 2013-06-30 22:12 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-22 23:44 - 2014-01-22 00:18 - 00000000 ____D C:\Program Files\ESET
2014-01-22 23:27 - 2012-01-08 20:20 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-22 22:32 - 2012-11-09 09:47 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2014-01-22 21:23 - 2011-11-09 23:50 - 01920414 _____ C:\Windows\WindowsUpdate.log
2014-01-22 20:11 - 2008-01-21 08:16 - 01445310 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-22 20:05 - 2012-01-08 20:20 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-22 20:05 - 2011-11-10 00:19 - 00000000 _____ C:\Windows\system32\LogConfigTemp.xml
2014-01-22 20:05 - 2001-01-08 15:47 - 00000147 _____ C:\Windows\system32\agent.log
2014-01-22 20:04 - 2008-01-21 03:47 - 03718782 _____ C:\Windows\PFRO.log
2014-01-22 20:04 - 2006-11-02 14:01 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-22 16:55 - 2014-01-20 08:51 - 00002276 _____ C:\Windows\Tasks\SCHEDLGU.TXT
2014-01-22 16:55 - 2013-07-28 18:06 - 00000012 _____ C:\Windows\bthservsdp.dat
2014-01-22 01:25 - 2011-11-20 20:40 - 00008704 _____ C:\Users\Oliver B\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
2014-01-22 00:10 - 2014-01-22 00:10 - 02347384 _____ (ESET) C:\Users\Oliver B\Downloads\esetsmartinstaller_enu.exe
2014-01-20 00:26 - 2001-01-08 16:06 - 00002721 _____ C:\Users\Public\Desktop\eSobi v2.lnk
2014-01-20 00:11 - 2014-01-12 10:11 - 00017675 _____ C:\Users\Oliver B\Downloads\Addition.txt
2014-01-19 23:47 - 2014-01-19 23:47 - 01221120 _____ (Farbar) C:\Users\Oliver B\Downloads\FRST(1).exe
2014-01-19 23:37 - 2014-01-19 23:37 - 00001089 _____ C:\Users\Oliver B\Desktop\JRT.txt
2014-01-19 23:28 - 2014-01-19 23:28 - 00000000 ____D C:\Windows\ERUNT
2014-01-19 23:24 - 2014-01-19 23:24 - 01037068 _____ (Thisisu) C:\Users\Oliver B\Downloads\JRT.exe
2014-01-19 23:16 - 2014-01-19 23:13 - 00000000 ____D C:\AdwCleaner
2014-01-19 23:12 - 2014-01-19 23:12 - 01236282 _____ C:\Users\Oliver B\Downloads\AdwCleaner(1).exe
2014-01-16 21:42 - 2001-01-08 15:49 - 00000000 ____D C:\ProgramData\Microsoft Help
2014-01-16 21:41 - 2013-07-26 07:20 - 00000000 ____D C:\Windows\system32\MRT
2014-01-16 21:26 - 2006-11-02 11:24 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-01-16 21:16 - 2013-09-15 20:37 - 00001356 _____ C:\Users\Oliver B\AppData\Local\d3d9caps.dat
2014-01-15 22:32 - 2014-01-15 22:32 - 01236282 _____ C:\Users\Oliver B\Downloads\AdwCleaner.exe
2014-01-15 21:54 - 2014-01-15 21:54 - 00000000 ____D C:\Users\Oliver B\AppData\Roaming\Malwarebytes
2014-01-15 21:49 - 2014-01-15 21:49 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-15 21:39 - 2014-01-15 21:37 - 10284816 _____ (Malwarebytes Corporation ) C:\Users\Oliver B\Downloads\mbam-setup.exe
2014-01-15 01:22 - 2014-01-15 01:22 - 00066126 _____ C:\Combo Fix text.txt
2014-01-15 01:13 - 2014-01-15 01:13 - 00066126 _____ C:\ComboFix.txt
2014-01-15 01:13 - 2014-01-15 00:44 - 00000000 ____D C:\Qoobox
2014-01-15 01:13 - 2006-11-02 12:18 - 00000000 __RHD C:\Users\Default
2014-01-15 01:13 - 2006-11-02 12:18 - 00000000 ___RD C:\Users\Public
2014-01-15 01:10 - 2014-01-15 00:43 - 00000000 ____D C:\Windows\erdnt
2014-01-15 01:07 - 2006-11-02 11:23 - 00000215 _____ C:\Windows\system.ini
2014-01-15 01:05 - 2006-11-02 11:22 - 42467328 _____ C:\Windows\system32\config\SYSTEM.bak
2014-01-15 01:05 - 2006-11-02 11:22 - 38273024 _____ C:\Windows\system32\config\COMPON~2.bak
2014-01-15 01:05 - 2006-11-02 11:22 - 34865152 _____ C:\Windows\system32\config\SOFTWARE.bak
2014-01-15 01:05 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\SECURITY.bak
2014-01-15 01:05 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\SAM.bak
2014-01-15 01:05 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\DEFAULT.bak
2014-01-15 00:42 - 2014-01-15 00:41 - 05165717 ____R (Swearware) C:\Users\Oliver B\Downloads\ComboFix.exe
2014-01-12 10:09 - 2014-01-12 10:09 - 00000000 ____D C:\FRST
2014-01-12 10:06 - 2014-01-12 10:06 - 01220096 _____ (Farbar) C:\Users\Oliver B\Downloads\FRST.exe
2014-01-11 20:00 - 2014-01-11 20:00 - 00000000 _____ C:\Windows\setuperr.log
2014-01-11 20:00 - 2014-01-11 20:00 - 00000000 _____ C:\Windows\setupact.log
2014-01-10 23:00 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\Msdtc
2014-01-10 22:59 - 2011-11-10 00:05 - 00000000 ____D C:\Program Files\Google
2014-01-10 22:59 - 2011-11-10 00:04 - 00000000 ____D C:\Users\Oliver B
2014-01-10 22:59 - 2006-11-02 13:37 - 00000000 ___RD C:\Users\Public\Recorded TV
2014-01-10 22:59 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\system32\spool
2014-01-10 22:59 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\registration
2014-01-10 22:59 - 2006-11-02 11:22 - 42467328 _____ C:\Windows\system32\config\system_previous
2014-01-10 22:59 - 2006-11-02 11:22 - 38273024 _____ C:\Windows\system32\config\components_previous
2014-01-10 22:59 - 2006-11-02 11:22 - 34865152 _____ C:\Windows\system32\config\software_previous
2014-01-10 22:59 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\security_previous
2014-01-10 22:59 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\sam_previous
2014-01-10 22:59 - 2006-11-02 11:22 - 00262144 _____ C:\Windows\system32\config\default_previous
2014-01-10 21:00 - 2014-01-10 21:00 - 00011799 _____ C:\Users\Oliver B\Downloads\hijackthis.log
2014-01-10 20:58 - 2011-11-10 00:04 - 00000000 ____D C:\Users\Oliver B\AppData\Local\VirtualStore
2014-01-10 00:30 - 2011-11-10 00:10 - 00000000 ____D C:\Users\Oliver B\AppData\Local\Google
2014-01-10 00:30 - 2011-11-10 00:06 - 00000000 ____D C:\ProgramData\Google
2014-01-06 14:41 - 2014-01-06 14:29 - 00000000 ____D C:\Users\Oliver B\2014-01-06 EXILIM ROT
2013-12-29 22:19 - 2013-12-29 22:19 - 01995098 _____ C:\Users\Oliver B\Downloads\video-2010-08-17-23-07-49(2).3gp
Some content of TEMP:
====================
C:\Users\Oliver B\AppData\Local\temp\RtkBtMnt.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll
[2011-11-10 03:29] - [2009-03-03 05:39] - 0551424 ____A (Microsoft Corporation) 301AE00E12408650BADDC04DBC832830
ATTENTION ======> If the system is having audio adware rpcss.dll is patched. Google the MD5, if the MD5 is unique the file is infected.
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-22 20:10
==================== End Of Log ============================
--- --- ---
--- --- ---
:FRST Additions Logfile:
Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-01-2014
Ran by Oliver B at 2014-01-23 00:09:46
Running from C:\Users\Oliver B\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Kaspersky Internet Security (Enabled - Up to date) {179979E8-273D-D14E-0543-2861940E4886}
AS: Kaspersky Internet Security (Enabled - Up to date) {ACF8980C-0107-DEC0-3FF3-1313EF89023B}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: Kaspersky Internet Security (Enabled) {2FA2F8CD-6D52-D016-2E1C-81546ADD0FFD}
==================== Installed Programs ======================
AAV 6.0.00.15 (Version: - )
Acer Arcade Deluxe (Version: 2.1.5529 - CyberLink Corp.)
Acer Arcade Deluxe (Version: 2.1.5529 - CyberLink Corp.) Hidden
Acer Bio Protection
Acer Crystal Eye Webcam 3.0.6.3 (Version: 3.0.6.3 - SuYin)
Acer eAudio Management (Version: 3.0.3008 - CyberLink Corp.)
Acer eDataSecurity Management (Version: 3.0.3065 - Egis Inc.)
Acer Empowering Technology (Version: 3.0.3009 - Acer Incorporated)
Acer ePower Management (Version: 3.0.3014 - Acer Incorporated)
Acer eRecovery Management (Version: 3.0.3014 - Acer Incorporated)
Acer eSettings Management (Version: 3.0.3007 - Acer Incorporated)
Acer GameZone Console 2.0.1.1 (Version: - Oberon Media, Inc.)
Acer GridVista (Version: 2.72.317 - )
Acer Mobility Center Plug-In (Version: 3.0.3000 - Acer Inc.)
Acer VCM (Version: 3.1.3000 - Acer Incorporated)
Activation Assistant for the 2007 Microsoft Office suites (Version: - Microsoft Corporation)
Activation Assistant for the 2007 Microsoft Office suites (Version: 1.0 - Microsoft Corporation) Hidden
Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (Version: 12.0.0.112 - Adobe Systems, Inc.)
Agatha Christie Death on the Nile (Version: - Oberon Media)
Agere Systems HDA Modem (Version: - Agere Systems)
Alice Greenfingers (Version: - Oberon Media)
Atheros Communications Inc.(R) AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver (Version: 1.0.0.30 - Atheros Communications Inc.)
Azada (Version: - Oberon Media)
Backspin Billiards (Version: - Oberon Media)
Big Kahuna Reef (Version: - Oberon Media)
Bricks of Egypt (Version: - Oberon Media)
Cake Mania (Version: - Oberon Media)
Chicken Invaders 3 (Version: - Oberon Media)
Chuzzle (Version: - Oberon Media)
CyberLink PowerDirector (Version: 6.5.3023d - CyberLink Corp.)
CyberLink PowerDirector (Version: 6.5.3023d - CyberLink Corp.) Hidden
Diner Dash Flo on the Go (Version: - Oberon Media)
eSobi v2 (Version: 2.0.3.000201 - esobi Inc.)
eSobi v2 (Version: 2.0.3.000201 - esobi Inc.) Hidden
Google Desktop (Version: 5.7.0808.07150 - Google)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (Version: 7.5.4805.320 - Google Inc.)
Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden
Intel PROSet Wireless (Version: - ) Hidden
Intel(R) PROSet/Wireless WiFi-Software (Version: 12.00.0004 - Intel(R) Corporation)
Intel® Matrix Storage Manager (Version: - Intel Corporation)
ITECIR (Version: 1.6 - ITE)
Java Auto Updater (Version: 2.0.7.1 - Sun Microsystems, Inc.) Hidden
Java(TM) 6 Update 31 (Version: 6.0.310 - Oracle)
Jewel Quest Solitaire (Version: - Oberon Media)
JMicron JMB38X Flash Media Controller (Version: 1.00.12.07 - JMicron Technology Corp.)
Kaspersky Internet Security (Version: 14.0.0.4651 - Kaspersky Lab)
Kaspersky Internet Security (Version: 14.0.0.4651 - Kaspersky Lab) Hidden
Launch Manager (Version: - )
LightScribe 1.4.142.1 (Version: 1.4.142.1 - hxxp://www.lightscribe.com) Hidden
Mahjong Escape Ancient China (Version: - Oberon Media)
Mahjongg Artifacts (Version: - Oberon Media)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 Language Pack SP1 - deu (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 3.5 SP1 (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (Version: 3.5.30729 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden
Microsoft Office Excel MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Live Add-in 1.5 (Version: 2.0.4024.1 - Microsoft Corporation)
Microsoft Office OneNote MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (Version: - Microsoft) Hidden
Microsoft Office Shared MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Works (Version: 08.05.0822 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 en-US) (Version: 26.0 - Mozilla)
Mozilla Maintenance Service (Version: 26.0 - Mozilla)
MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation)
Mystery Case Files - Huntsville (Version: - Oberon Media)
Mystery Solitaire - Secret Island (Version: - Oberon Media)
NTI Backup Now 5 (Version: 5.1.2.606 - NewTech Infosystems)
NTI Backup Now Standard (Version: 5.1.2.606 - NewTech Infosystems) Hidden
NTI Media Maker 8 (Version: 8.0.2.6329 - NewTech Infosystems)
NTI Media Maker 8 (Version: 8.0.2.6329 - NewTech Infosystems) Hidden
NVIDIA Drivers (Version: - )
Orion (Version: 2.0.1 - Convesoft)
PhotoNow! (Version: 1.1.4619 - CyberLink Corp.)
Realtek High Definition Audio Driver (Version: 6.0.1.5618 - Realtek Semiconductor Corp.)
swMSM (Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
Synaptics Pointing Device Driver (Version: 10.2.4.1 - Synaptics)
Turbo Pizza (Version: - Oberon Media)
Update for 2007 Microsoft Office System (KB967642) (Version: - Microsoft)
Update for Microsoft .NET Framework 3.5 SP1 (KB963707) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (Version: - Microsoft)
Update für Microsoft Office Excel 2007 Help (KB963678) (Version: - Microsoft)
Update für Microsoft Office Powerpoint 2007 Help (KB963669) (Version: - Microsoft)
Update für Microsoft Office Word 2007 Help (KB963665) (Version: - Microsoft)
Validity Sensors software (Version: 2.7.44 - Validity Sensors, Inc.)
WIDCOMM Bluetooth Software 6.0.1.5000 (Version: 6.0.1.5000 - Broadcom Corporation)
Zuma Deluxe (Version: - Oberon Media)
==================== Restore Points =========================
10-01-2014 21:27:38 Wiederherstellungsvorgang
10-01-2014 21:36:37 Windows Update
10-01-2014 21:52:19 01.11.2013
10-01-2014 21:56:47 Wiederherstellungsvorgang
10-01-2014 22:15:28 Windows Update
11-01-2014 20:16:43 Geplanter Prüfpunkt
13-01-2014 22:58:32 Geplanter Prüfpunkt
14-01-2014 08:05:48 Windows Update
14-01-2014 21:58:53 Geplanter Prüfpunkt
16-01-2014 20:25:11 Windows Update
17-01-2014 17:17:21 Windows Update
18-01-2014 08:46:00 Geplanter Prüfpunkt
19-01-2014 00:14:07 Geplanter Prüfpunkt
20-01-2014 22:01:41 Geplanter Prüfpunkt
21-01-2014 17:29:11 Windows Update
==================== Hosts content: ==========================
2006-11-02 11:23 - 2014-01-15 01:07 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
==================== Scheduled Tasks (whitelisted) =============
Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM
Task: {309C3123-9C5F-4AD1-A10A-0539B0743B77} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-01-08] (Google Inc.)
Task: {320124A7-D70F-41DE-A9D1-D5E8E19D5D91} - System32\Tasks\Microsoft\Windows\NetworkAccessProtection\NAPStatus UI
Task: {3BCDF251-CA5C-4045-A1FC-8FCEF9FBDC93} - System32\Tasks\Microsoft\Windows\Shell\CrawlStartPages
Task: {44980BEE-7809-44A9-AC24-D6E578A3B7DF} - System32\Tasks\Microsoft\Windows\RAC\RACAgent => C:\Windows\system32\RacAgent.exe [2008-01-21] (Microsoft Corporation)
Task: {6A9676D2-D97A-4B2D-8625-0A9BAE1C9D10} - System32\Tasks\Microsoft\Windows\RestartManager\{29ADE984-D219-4336-A2AE-C52CF1DDA4E1} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation)
Task: {96D03B48-B5BA-44CA-95FD-DD42FEBF252B} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-11] (Adobe Systems Incorporated)
Task: {C4317DF5-F2DE-47B5-B311-B82BA4AF9B50} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2012-01-08] (Google Inc.)
Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs [2008-01-21] ()
Task: {E54AB7A8-E3DB-4AF3-82BC-D8B3CF2B5D80} - System32\Tasks\Microsoft\Windows\RestartManager\{5E20EA28-F9AC-455e-B340-A36405C25743} => C:\Windows\system32\rmclient.exe [2006-11-02] (Microsoft Corporation)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2013-06-17 12:35 - 2013-06-17 12:35 - 00478400 _____ () C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 14.0.0\dblite.dll
2001-01-08 15:28 - 2008-06-11 10:21 - 00204800 _____ () C:\Windows\System32\SysHook.dll
2007-04-24 18:44 - 2007-04-24 18:44 - 00126976 _____ () C:\Program Files\WIDCOMM\Bluetooth Software\btkeyind.dll
2008-07-29 17:52 - 2008-07-29 17:52 - 00227888 _____ () C:\Program Files\Acer\Empowering Technology\eDataSecurity\x86\ShowErrMsg.dll
2008-04-28 09:49 - 2008-04-28 09:49 - 00003072 _____ () C:\Program Files\NewTech Infosystems\NTI Backup Now 5\BkupTrayLOC.dll
2001-01-08 23:32 - 2003-06-07 06:30 - 00057344 _____ () C:\Program Files\Launch Manager\PowerUtl.dll
2011-11-10 00:18 - 2011-11-10 00:18 - 00036864 _____ () C:\Windows\assembly\GAC_MSIL\Framework.Utility\3.0.3009.0__4df5dcab8860d239\Framework.Utility.dll
2011-11-10 00:18 - 2011-11-10 00:18 - 00061440 _____ () C:\Windows\assembly\GAC_MSIL\Framework.Library\3.0.3009.0__3036420f80dd6947\Framework.Library.dll
2011-11-10 00:18 - 2011-11-10 00:18 - 00009216 _____ () C:\Windows\assembly\GAC_MSIL\Framework.Model.ControllerInterface\3.0.3009.0__d842b71b4d6ed079\Framework.Model.ControllerInterface.dll
2008-07-24 15:54 - 2008-07-24 15:54 - 00757760 ____N () C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMediaLibrary.dll
2008-07-24 15:54 - 2008-07-24 15:54 - 00007680 ____N () C:\Program Files\Acer Arcade Deluxe\Acer Arcade Deluxe\Kernel\CLML\CLMLSvcPS.dll
2011-11-10 01:04 - 2007-09-11 11:12 - 00475136 _____ () C:\Program Files\Acer\Acer VCM\AcerControl.dll
2007-04-24 18:32 - 2007-04-24 18:32 - 00389120 _____ () C:\Windows\system32\btwhidcs.DLL
2013-12-10 22:30 - 2013-12-10 22:30 - 03559024 _____ () C:\Program Files\Mozilla Firefox\mozjs.dll
2011-11-10 00:05 - 2011-11-10 00:06 - 00034816 _____ () C:\Program Files\Google\Google Desktop Search\gzlib.dll
2013-12-11 15:55 - 2013-12-11 15:55 - 16242056 _____ () C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Users\Oliver B\Downloads\OriginalMail.eml:OECustomProperty
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/22/2014 08:05:12 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/22/2014 01:53:50 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/22/2014 10:06:37 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/21/2014 06:23:14 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/21/2014 08:47:05 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/20/2014 07:52:55 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/20/2014 08:51:30 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/19/2014 11:40:32 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (01/22/2014 08:04:57 PM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (01/22/2014 01:53:34 PM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (01/22/2014 10:06:24 AM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (01/21/2014 06:22:59 PM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (01/21/2014 08:46:47 AM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (01/20/2014 07:52:35 PM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (01/20/2014 08:51:16 AM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Error: (01/19/2014 11:40:08 PM) (Source: HTTP) (User: )
Description: \Device\Http\ReqQueueKerberos
Microsoft Office Sessions:
=========================
CodeIntegrity Errors:
===================================
Date: 2014-01-23 00:09:03.174
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-01-23 00:09:02.983
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-01-23 00:09:02.791
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-01-23 00:09:02.598
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-01-23 00:09:02.391
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-01-23 00:09:02.198
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-01-23 00:09:01.991
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-01-23 00:09:01.790
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-01-23 00:08:57.317
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\kneps.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-01-23 00:08:57.115
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume2\Windows\System32\drivers\kneps.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Percentage of memory in use: 56%
Total physical RAM: 3068.04 MB
Available physical RAM: 1326.22 MB
Total Pagefile: 6337.07 MB
Available Pagefile: 4436.68 MB
Total Virtual: 2047.88 MB
Available Virtual: 1923.08 MB
==================== Drives ================================
Drive c: (ACER) (Fixed) (Total:144.04 GB) (Free:88.83 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive d: (DATA) (Fixed) (Total:139.5 GB) (Free:138.95 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 298 GB) (Disk ID: 72888339)
Partition 1: (Not Active) - (Size=11 GB) - (Type=27)
Partition 2: (Active) - (Size=144 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=140 GB) - (Type=07 NTFS)
Partition 4: (Not Active) - (Size=4 GB) - (Type=12)
==================== End Of Log ============================
--- --- ---
ESET habe ich wieder gelöscht wie in der Anleitung, ich kann es mit dem Explorer bei "Programme" noch finden, aber es steht dann dort "der Ordner ist leer". Ist das ok ?
Während des Security Check habe ich Kaspersky ausgeschalten, war das korrekt ?
War mir von der Beschreibung her nicht sicher, ob ich das Virusprogramm nach beendetem Eset wieder aktivieren soll.
JRT ist noch auf dem Laptop, soll das bleiben ?
War der MBAM Test oben vollständig, oder soll ich da nochmal etwas durchführen ?
***Vielen Dank und Grüße ***