|
Log-Analyse und Auswertung: Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da istWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
19.01.2014, 12:19 | #1 |
| Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist Hallo, Ich habe eine Fake E-Mail von Vodafone bekommen, leider den link geöffnet und die Datei darin auch gestartet, jetzt schlägt mein Antivirus Programm regelmäßig an. Nach kurzer Googlesuche habe ich herausgefunden, dass dadurch ein Trojaner in mein System gelangen kann, da ich kaum Ahnung davon habe wäre es nett wenn mir einer Helfen könnte und das ganze überprüft. Mein System ist ein Windows 7 mit SP1 Hier die Geforderten Log Files: FRST Additions Logfile: Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-01-2014 03 Ran by Landgraf-Vaio at 2014-01-19 10:45:41 Running from C:\Users\Landgraf-Vaio\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Lavasoft Ad-Aware (Enabled - Up to date) {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7} AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Lavasoft Ad-Aware (Enabled - Up to date) {5BB89C30-6480-BC7C-9F17-199BD76F557A} AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0} FW: Lavasoft Ad-Aware (Disabled) {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC} ==================== Installed Programs ====================== Ad-Aware Antivirus (x32 Version: 10.5.3.4405 - Lavasoft) Ad-Aware Security Add-on (x32 Version: 3.4.0.1 - Lavasoft) Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader XI (11.0.06) - Deutsch (x32 Version: 11.0.06 - Adobe Systems Incorporated) Alps Pointing-device for VAIO (Version: - ALPS ELECTRIC CO., LTD.) ATI Catalyst Install Manager (Version: 3.0.769.0 - ATI Technologies, Inc.) Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Core Implementation (x32 Version: 2010.0920.2143.37117 - ATI) Hidden Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0920.2143.37117 - ATI) Hidden Catalyst Control Center Graphics Full New (x32 Version: 2010.0920.2143.37117 - ATI) Hidden Catalyst Control Center Graphics Light (x32 Version: 2010.0920.2143.37117 - ATI) Hidden Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0920.2143.37117 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0920.2143.37117 - ATI) Hidden Catalyst Control Center InstallProxy (x32 Version: 2010.0920.2143.37117 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (x32 Version: 2010.0920.2143.37117 - ATI) Hidden CCC Help Chinese Standard (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Chinese Traditional (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Czech (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Danish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Dutch (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help English (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Finnish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help French (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help German (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Greek (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Hungarian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Italian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Japanese (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Korean (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Norwegian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Polish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Portuguese (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Russian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Spanish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Swedish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Thai (x32 Version: 2010.0920.2142.37117 - ATI) Hidden CCC Help Turkish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden ccc-core-static (x32 Version: 2010.0920.2143.37117 - Ihr Firmenname) Hidden ccc-utility64 (Version: 2010.0920.2143.37117 - ATI) Hidden Cultris II (x32 Version: - ) D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (Version: - Microsoft) DHTML Editing Component (x32 Version: 6.02.0001 - Microsoft Corporation) Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.) Elevated Installer (x32 Version: 2.3.18.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express (x32 Version: 2.3.18.0 - Garmin Ltd or its subsidiaries) Garmin Express (x32 Version: 2.3.18.0 - Garmin Ltd or its subsidiaries) Hidden Garmin Express Tray (x32 Version: 2.3.18.0 - Garmin Ltd or its subsidiaries) Hidden GUILD WARS (x32 Version: - ) Java 7 Update 51 (x32 Version: 7.0.510 - Oracle) Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla) MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden Rossmann Fotowelt Software 4.13 (x32 Version: 4.13 - ORWO Net) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.) Spybot - Search & Destroy (x32 Version: 2.1.21 - Safer-Networking Ltd.) StarMoney (x32 Version: 4.0.1.51 - StarFinanz) Hidden StarMoney 9.0 (x32 Version: 9.0 - Star Finanz GmbH) TeamSpeak 3 Client (Version: 3.0.13 - TeamSpeak Systems GmbH) Turbo Lister 2 (x32 Version: 2.00.0000 - eBay Inc.) Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation) Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation) Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (Version: - Microsoft) Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition (Version: - Microsoft) Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition (Version: - Microsoft) Update for Microsoft Word 2010 (KB2837593) 64-Bit Edition (Version: - Microsoft) VAIO Care (x32 Version: 6.4.2.11150 - Sony Corporation) Hidden VAIO Control Center (x32 Version: 4.3.0.05310 - Sony Corporation) VAIO Gate (x32 Version: 1.0.0.08050 - Sony Corporation) WIDCOMM Bluetooth Software (Version: 6.3.0.5600 - Broadcom Corporation) Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Mail (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live MIME IFilter (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden Windows Live Writer Resources (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden WinRAR 5.00 (64-Bit) (Version: 5.00.0 - win.rar GmbH) ==================== Restore Points ========================= 03-01-2014 15:20:19 Garmin Express 11-01-2014 10:27:41 Geplanter Prüfpunkt 15-01-2014 13:26:27 Installed Java 7 Update 51 16-01-2014 13:07:58 Windows Update ==================== Hosts content: ========================== 2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {011E21C1-096A-4512-ADBB-B6862B20B18D} - System32\Tasks\SONY\SUS-BCF\Level4Daily => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation) Task: {08799212-6B94-41FE-91A6-2C6896E110C8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe Task: {353D0556-A1CF-4BF8-9EB8-E7E80A0B6284} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation) Task: {53DCCA7C-F53A-4401-925E-AECFB394629A} - System32\Tasks\SONY\VAIO Power Management\VPM Session Change => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation) Task: {580F0F58-DB00-41E0-B22F-C7A2C5BF6564} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe [2013-06-13] (Lavasoft Limited) Task: {6216FDBE-2DE3-4C21-9A74-5BC685FAAA5E} - System32\Tasks\SONY\VAIO Power Management\VPM Logon Start => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation) Task: {64F5C105-EADC-4468-A682-077344B3B594} - System32\Tasks\SONY\SUS-BCF\Level4Month => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation) Task: {698549F5-2782-442A-9951-1B399C00C311} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe Task: {6F63A80D-96F5-421E-B68E-CBF3E84AC01F} - System32\Tasks\{10182459-CFFA-4D5D-BF1E-E97CF00453CF} => Firefox.exe hxxp://ui.skype.com/ui/0/6.7.0.102/de/abandoninstall?source=lightinstaller&page=tsInstall Task: {9A88A67C-C08A-4CF4-877A-BDEF50AECC22} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-21] (Adobe Systems Incorporated) Task: {A65840CB-BD79-4E8E-AC05-DBFD3F191FD0} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2009-08-05] (Sony Corporation) Task: {B32DCDB0-4212-4368-9F65-4A2D3D39CC71} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation) Task: {D76F951E-1DEC-419E-B965-743B4FF045D9} - System32\Tasks\SONY\VAIO Power Management\VPM Unlock => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation) Task: {EB0406D4-B9EB-4ACF-90AA-D8BC7D453F6A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe ==================== Loaded Modules (whitelisted) ============= 2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF 2010-08-24 13:39 - 2010-08-24 13:39 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll 2013-09-23 16:16 - 2013-09-23 16:16 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll 2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\libcef.dll 2013-09-25 14:19 - 2013-05-16 09:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl 2013-09-25 14:19 - 2013-05-16 09:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl 2013-09-25 14:19 - 2013-05-16 09:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl 2013-09-25 14:19 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll 2013-09-25 14:19 - 2012-04-03 16:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll 2013-10-15 11:40 - 2011-01-13 10:44 - 00232800 _____ () C:\Program Files (x86)\StarMoney 9.0\ouservice\PATCHW32.dll 2013-09-25 14:35 - 2013-12-19 14:07 - 00190752 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libBase64.dll 2013-09-25 14:35 - 2013-12-19 14:07 - 00178464 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libMachoUniv.dll 2013-09-23 16:35 - 2013-12-21 17:49 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll 2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\Users\Landgraf-Vaio\Documents\Landgraf ___ MB Massivhaus, u_Z_ 549_12RE.eml:OECustomProperty ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service => ""="Ad-Aware Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ad-Aware Service => ""="Ad-Aware Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBAMSvc => ""="Service" ==================== Faulty Device Manager Devices ============= Name: Microsoft-Adapter für Miniports virtueller WiFis Description: Microsoft-Adapter für Miniports virtueller WiFis Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Microsoft Service: vwifimp Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Marvell Yukon 88E8059 PCI-E Gigabit Ethernet Controller Description: Marvell Yukon 88E8059 PCI-E Gigabit Ethernet Controller Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Marvell Service: yukonw7 Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (01/19/2014 10:25:42 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service) (User: ) Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet. Details: Der Inhaltsindexkatalog ist fehlerhaft. 0xc0041801 (0xc0041801) Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service) (User: ) Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=2350} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben. Details: Der Inhaltsindexkatalog ist fehlerhaft. 0xc0041801 (0xc0041801) Error: (01/18/2014 07:52:30 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2014 06:44:32 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2014 04:51:05 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2014 03:34:04 PM) (Source: Application Hang) (User: ) Description: Programm firefox.exe, Version 26.0.0.5087 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 1504 Startzeit: 01cf145a3d53c4fd Endzeit: 14 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: 8bf65b7b-804d-11e3-b0de-18f46af81e57 Error: (01/18/2014 03:07:24 PM) (Source: Application Hang) (User: ) Description: Programm firefox.exe, Version 26.0.0.5087 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen. Prozess-ID: 91c Startzeit: 01cf1455e1d904dd Endzeit: 31 Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe Berichts-ID: d8953a08-8049-11e3-b0de-18f46af81e57 Error: (01/18/2014 11:32:14 AM) (Source: Customer Experience Improvement Program) (User: ) Description: 80004005 Error: (01/18/2014 10:37:29 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 System errors: ============= Error: (01/19/2014 10:25:14 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Garmin Core Update Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/19/2014 10:25:14 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Garmin Core Update Service erreicht. Error: (01/18/2014 11:12:50 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (01/18/2014 06:42:59 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (01/18/2014 04:51:33 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Updating Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/18/2014 04:51:33 PM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Updating Service erreicht. Error: (01/18/2014 04:49:24 PM) (Source: DCOM) (User: ) Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF} Error: (01/18/2014 10:37:18 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (01/18/2014 10:37:18 AM) (Source: Service Control Manager) (User: ) Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht. Error: (01/18/2014 10:36:48 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Garmin Core Update Service" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Microsoft Office Sessions: ========================= Error: (01/19/2014 10:25:42 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. 0xc0041801 (0xc0041801) The catalog is corrupt Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. 0xc0041801 (0xc0041801) 2350 Error: (01/18/2014 07:52:30 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2014 06:44:32 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2014 04:51:05 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2014 03:34:04 PM) (Source: Application Hang)(User: ) Description: firefox.exe26.0.0.5087150401cf145a3d53c4fd14C:\Program Files (x86)\Mozilla Firefox\firefox.exe8bf65b7b-804d-11e3-b0de-18f46af81e57 Error: (01/18/2014 03:07:24 PM) (Source: Application Hang)(User: ) Description: firefox.exe26.0.0.508791c01cf1455e1d904dd31C:\Program Files (x86)\Mozilla Firefox\firefox.exed8953a08-8049-11e3-b0de-18f46af81e57 Error: (01/18/2014 11:32:14 AM) (Source: Customer Experience Improvement Program)(User: ) Description: 80004005 Error: (01/18/2014 10:37:29 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 ==================== Memory info =========================== Percentage of memory in use: 45% Total physical RAM: 3950.1 MB Available physical RAM: 2139.82 MB Total Pagefile: 7898.38 MB Available Pagefile: 5538.8 MB Total Virtual: 8192 MB Available Virtual: 8191.81 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:465.66 GB) (Free:253.21 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 7A7F4430) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS) ==================== End Of Log ============================ Code:
ATTFilter defogger_disable by jpshortstuff (23.02.10.1) Log created at 10:43 on 19/01/2014 (Landgraf-Vaio) Checking for autostart values... HKCU\~\Run values retrieved. HKLM\~\Run values retrieved. Checking for services/drivers... -=E.O.F=- FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-01-2014 03 Ran by Landgraf-Vaio (administrator) on LANDGRAFVAIO on 19-01-2014 10:45:00 Running from C:\Users\Landgraf-Vaio\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Microsoft Corporation) C:\Windows\System32\StikyNot.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Dropbox, Inc.) C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe (Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Lavasoft) C:\ProgramData\Search Protection\SearchProtection.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [212480 2010-09-15] (Alps Electric Co., Ltd.) HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [SBRegRebootCleaner] - C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-09-20] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.) HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554384 2013-07-15] (Lavasoft) HKLM-x32\...\Run: [Search Protection] - C:\ProgramData\Search Protection\SearchProtection.exe [943016 2013-06-13] (Lavasoft) HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X] HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries) HKCU\...\Run: [KB01353482.exe] - "C:\Users\Landgraf-Vaio\AppData\Roaming\KB01353482.exe" HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation) Startup: C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id=adawaretb&v=3_4&ent=hp&u=CAAA82C8C61AAA03D18D225242E3D633 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8E2CB2916DB8CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_4&hsimp=yhs-lavasoft&ent=ch&q={searchTerms} BHO: AppGraffiti - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\PROGRA~2\APPGRA~1\APPGRA~2.DLL No File BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll () BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM-x32 - Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll () Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default FF NewTab: hxxp://www.searchgol.com/?babsrc=NT_ss&mntrId=E8E118F46AF81E57&affID=119357&tsp=5014 FF SearchEngineOrder.1: Ask Search FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\ask-search.xml FF SearchPlugin: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\inbox-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\adawaretb.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: YouTube Unblocker - C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\Extensions\youtubeunblocker@unblocker.yt [2014-01-16] FF Extension: Ad-Aware Security Add-on - C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} [2013-09-25] ==================== Services (Whitelisted) ================= R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited) S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software) R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.) R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.) R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH) ==================== Drivers (Whitelisted) ==================== S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-09-25] (GFI Software) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-19 10:45 - 2014-01-19 10:45 - 00012572 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt 2014-01-19 10:44 - 2014-01-19 10:44 - 02076160 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe 2014-01-19 10:44 - 2014-01-19 10:44 - 00000000 ____D C:\FRST 2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log 2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable 2014-01-18 22:02 - 2014-01-18 22:52 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx 2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip 2014-01-18 21:42 - 2014-01-18 21:42 - 01077248 _____ (Zhorn Software) C:\Users\Landgraf-Vaio\Downloads\stickies_setup_7.1e.exe 2014-01-18 17:21 - 2014-01-18 17:22 - 00000280 _____ C:\Windows\wininit.ini 2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe 2014-01-18 16:52 - 2014-01-18 16:53 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe 2014-01-18 15:06 - 2014-01-19 10:40 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B 2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-15 14:27 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-01-15 14:27 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-01-15 14:27 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-01-15 14:27 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-01-15 14:20 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 14:20 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 14:20 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 14:19 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 14:19 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 14:19 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 14:19 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 14:19 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 14:19 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin 2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin 2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin 2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin 2014-01-03 16:20 - 2014-01-03 16:21 - 00000000 ____D C:\Program Files (x86)\Garmin 2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache 2013-12-21 12:46 - 2013-12-21 12:47 - 00024576 ___SH C:\Users\Landgraf-Vaio\Documents\Thumbs.db 2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\webasto 2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Vorlagen 2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Steuererklärung 2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\saeco 2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Robert 2013-12-20 17:56 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Rechnungen 2013-12-20 17:55 - 2014-01-03 16:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Robert 2013-12-20 17:55 - 2014-01-03 16:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ICQ 2013-12-20 17:55 - 2014-01-03 16:52 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Anja 2013-12-20 17:54 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Hausbau 2013-12-20 17:54 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\email 2013-12-20 17:53 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ebooks 2013-12-20 17:53 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Auto 2013-12-20 17:52 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Anja 2013-12-20 17:50 - 2013-02-22 20:30 - 00122300 _____ C:\Users\Landgraf-Vaio\Documents\Landgraf ___ MB Massivhaus, u_Z_ 549_12RE.eml 2013-12-20 17:50 - 2012-05-12 23:57 - 341600159 _____ C:\Users\Landgraf-Vaio\Documents\PerAnhalterdurchdieGalaxis_ep7_anjalandgraf.aax 2013-12-20 14:18 - 2013-12-20 15:55 - 00004419 _____ C:\Users\Landgraf-Vaio\Downloads\config Landgraf AP.dat 2013-12-20 13:37 - 2013-12-20 13:37 - 00273904 _____ C:\Windows\Minidump\122013-18782-01.dmp 2013-12-20 13:16 - 2013-12-20 13:17 - 01892006 _____ C:\Users\Landgraf-Vaio\Downloads\CSL.ML.0726_fwc.bin ==================== One Month Modified Files and Folders ======= 2014-01-19 10:45 - 2014-01-19 10:45 - 00012572 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt 2014-01-19 10:44 - 2014-01-19 10:44 - 02076160 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe 2014-01-19 10:44 - 2014-01-19 10:44 - 00000000 ____D C:\FRST 2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log 2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable 2014-01-19 10:43 - 2013-09-23 15:58 - 00000000 ____D C:\Users\Landgraf-Vaio 2014-01-19 10:40 - 2014-01-18 15:06 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B 2014-01-19 10:40 - 2013-09-23 15:58 - 00000000 ___RD C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-19 10:35 - 2013-09-23 19:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-19 10:33 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-19 10:33 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-19 10:30 - 2013-09-23 15:47 - 01428122 _____ C:\Windows\WindowsUpdate.log 2014-01-19 10:27 - 2013-09-23 19:18 - 00003978 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{302D991D-8607-4326-8B9F-1E38889BFE91} 2014-01-19 10:25 - 2013-12-01 17:47 - 00000000 ___RD C:\Users\Landgraf-Vaio\Dropbox 2014-01-19 10:25 - 2013-12-01 17:43 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox 2014-01-19 10:24 - 2013-10-29 21:34 - 00013303 _____ C:\Windows\setupact.log 2014-01-19 10:24 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-18 22:52 - 2014-01-18 22:02 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx 2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip 2014-01-18 21:42 - 2014-01-18 21:42 - 01077248 _____ (Zhorn Software) C:\Users\Landgraf-Vaio\Downloads\stickies_setup_7.1e.exe 2014-01-18 18:43 - 2013-10-31 01:14 - 00003290 _____ C:\Windows\PFRO.log 2014-01-18 17:22 - 2014-01-18 17:21 - 00000280 _____ C:\Windows\wininit.ini 2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe 2014-01-18 16:53 - 2014-01-18 16:52 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe 2014-01-18 14:48 - 2013-09-25 16:56 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Windows Live 2014-01-18 10:37 - 2013-09-25 15:09 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0 2014-01-17 08:14 - 2013-10-01 22:53 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Skype 2014-01-16 19:14 - 2013-12-01 17:45 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-16 19:09 - 2009-07-14 05:45 - 00417024 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-16 14:11 - 2013-09-23 18:39 - 00000000 ____D C:\Windows\system32\MRT 2014-01-16 14:08 - 2013-09-23 18:39 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-15 14:27 - 2013-09-29 20:45 - 00000000 ____D C:\ProgramData\Oracle 2014-01-15 14:27 - 2013-09-29 20:44 - 00000000 ____D C:\Program Files (x86)\Java 2014-01-12 17:14 - 2010-11-21 07:50 - 00654166 _____ C:\Windows\system32\perfh007.dat 2014-01-12 17:14 - 2010-11-21 07:50 - 00130006 _____ C:\Windows\system32\perfc007.dat 2014-01-12 17:14 - 2009-07-14 06:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-12 12:12 - 2013-09-25 14:19 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-01-09 13:19 - 2013-09-25 16:05 - 00000000 ____D C:\Windows\System32\Tasks\Games 2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Robert 2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ICQ 2014-01-03 16:52 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Anja 2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin 2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin 2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin 2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin 2014-01-03 16:21 - 2014-01-03 16:20 - 00000000 ____D C:\Program Files (x86)\Garmin 2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache 2013-12-31 11:44 - 2013-10-23 09:47 - 00326527 _____ C:\test.xml 2013-12-22 13:03 - 2013-09-25 14:24 - 00000000 ____D C:\ProgramData\Search Protection 2013-12-21 23:36 - 2013-10-03 16:50 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Adobe 2013-12-21 23:36 - 2013-09-23 19:17 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-12-21 23:36 - 2013-09-23 19:17 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-12-21 23:36 - 2013-09-23 19:17 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater 2013-12-21 23:06 - 2013-09-26 13:28 - 00000000 ____D C:\andere sachen 2013-12-21 17:49 - 2013-09-23 16:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2013-12-21 12:47 - 2013-12-21 12:46 - 00024576 ___SH C:\Users\Landgraf-Vaio\Documents\Thumbs.db 2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\webasto 2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Vorlagen 2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Steuererklärung 2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\saeco 2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Robert 2013-12-20 18:00 - 2013-12-20 17:56 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Rechnungen 2013-12-20 17:55 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Hausbau 2013-12-20 17:54 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\email 2013-12-20 17:54 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ebooks 2013-12-20 17:53 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Auto 2013-12-20 17:53 - 2013-12-20 17:52 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Anja 2013-12-20 15:55 - 2013-12-20 14:18 - 00004419 _____ C:\Users\Landgraf-Vaio\Downloads\config Landgraf AP.dat 2013-12-20 13:37 - 2013-12-20 13:37 - 00273904 _____ C:\Windows\Minidump\122013-18782-01.dmp 2013-12-20 13:37 - 2013-09-25 08:17 - 363185970 _____ C:\Windows\MEMORY.DMP 2013-12-20 13:37 - 2013-09-25 08:17 - 00000000 ____D C:\Windows\Minidump 2013-12-20 13:17 - 2013-12-20 13:16 - 01892006 _____ C:\Users\Landgraf-Vaio\Downloads\CSL.ML.0726_fwc.bin Some content of TEMP: ==================== C:\Users\Landgraf-Vaio\AppData\Local\Temp\2cd71744-656a-41f5-8e2f-cf7faa63e1ef.exe C:\Users\Landgraf-Vaio\AppData\Local\Temp\460a2cca-59e0-4d35-90b2-061ce9b8114e.exe C:\Users\Landgraf-Vaio\AppData\Local\Temp\APNSetup.exe C:\Users\Landgraf-Vaio\AppData\Local\Temp\exp15A2.tmp.exe C:\Users\Landgraf-Vaio\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih.exe C:\Users\Landgraf-Vaio\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe C:\Users\Landgraf-Vaio\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-09 13:12 ==================== End Of Log ============================ Code:
ATTFilter GMER Logfile: Code:
ATTFilter leider weiss ich nicht wie ich die Log-Datei vom Ad-Aware-Antivirus-Programm auslesen kann, Sry es hat 3x Trojan Win32 Generic! BT und einmal Worm.Win32.Critec.ac(v) gefunden, ich lasse diese dinge noch in der Quarantäne bis ich von ihnen was anderes höre |
19.01.2014, 14:21 | #2 | |
/// the machine /// TB-Ausbilder | Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist hi,
__________________Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!Downloade dir bitte Combofix vom folgenden Downloadspiegel Link 1 WICHTIG - Speichere Combofix auf deinem Desktop
Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort. Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten Zitat:
__________________ |
19.01.2014, 20:35 | #3 |
| Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist Hallo, hier das ergebnis der Log-Datei:
__________________Code:
ATTFilter Combofix Logfile: |
20.01.2014, 21:57 | #4 |
/// the machine /// TB-Ausbilder | Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.01.2014, 18:29 | #5 |
| Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist Hallo, hier die geforderten Log´s Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.21.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 11.0.9600.16476 Landgraf-Vaio :: LANDGRAFVAIO [Administrator] 21.01.2014 16:36:52 mbam-log-2014-01-21 (16-36-52).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 370584 Laufzeit: 1 Stunde(n), 17 Minute(n), 21 Sekunde(n) Infizierte Speicherprozesse: 1 C:\ProgramData\Search Protection\SearchProtection.exe (PUP.Optional.SearchProtection.A) -> 2500 -> Löschen bei Neustart. Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 7 HKCR\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} (PUP.Optional.Wajam.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCR\CLSID\{CCB69577-088B-4004-9ED8-FF5BCC83A039} (PUP.Optional.RebateInformer.A) -> Löschen bei Neustart. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039} (PUP.Optional.RebateInformer.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} (PUP.Optional.AppGraffiti.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} (PUP.Optional.InboxToolBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\InstallCore\1I1T1Q1S (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Registrierungswerte: 2 HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Search Protection (PUP.Optional.SearchProtection.A) -> Daten: C:\ProgramData\Search Protection\SearchProtection.exe -> Erfolgreich gelöscht und in Quarantäne gestellt. HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0Z1N1J -> Erfolgreich gelöscht und in Quarantäne gestellt. Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 2 C:\ProgramData\DSearchLink\DSearchLink.exe (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\ProgramData\Search Protection\SearchProtection.exe (PUP.Optional.SearchProtection.A) -> Löschen bei Neustart. (Ende) Code:
ATTFilter # AdwCleaner v3.017 - Bericht erstellt am 21/01/2014 um 18:14:40 # Aktualisiert 12/01/2014 von Xplode # Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits) # Benutzername : Landgraf-Vaio - LANDGRAFVAIO # Gestartet von : C:\Users\Landgraf-Vaio\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Ordner Gelöscht : C:\ProgramData\apn Ordner Gelöscht : C:\ProgramData\blekko toolbars Ordner Gelöscht : C:\ProgramData\DSearchLink Ordner Gelöscht : C:\ProgramData\Search Protection Ordner Gelöscht : C:\Program Files (x86)\Toolbar Cleaner Ordner Gelöscht : C:\Users\Landgraf-Vaio\AppData\LocalLow\adawaretb Ordner Gelöscht : C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\adawaretb Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\adawaretb.xml Datei Gelöscht : C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\ask-search.xml ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_download_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_download_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajamupdater_rasapi32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajamupdater_rasmancs Schlüssel Gelöscht : HKLM\SOFTWARE\ee8bd8b739bf10 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6C97A91E-4524-4019-86AF-2AA2D567BF5C} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30} Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}] Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AF808758-C780-404C-A4EE-4526323FD9B6} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB69577-088B-4004-9ED8-FF5BCC83A039} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5} Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\adawaretb Schlüssel Gelöscht : HKLM\Software\adawaretb Schlüssel Gelöscht : HKLM\Software\DataMngr Schlüssel Gelöscht : HKLM\Software\Toolbar Cleaner Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner ***** [ Browser ] ***** -\\ Internet Explorer v11.0.9600.16428 -\\ Mozilla Firefox v26.0 (de) [ Datei : C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\prefs.js ] Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://www.searchgol.com/?babsrc=NT_ss&mntrId=E8E118F46AF81E57&affID=119357&tsp=5014"); ************************* AdwCleaner[R0].txt - [4856 octets] - [21/01/2014 18:05:30] AdwCleaner[S0].txt - [4645 octets] - [21/01/2014 18:14:40] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4705 octets] ########## [/CODE] Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 7 Home Premium x64 Ran by Landgraf-Vaio on 21.01.2014 at 18:17:26,98 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3802158637-1547946212-584559868-1000\Software\Microsoft\Internet Explorer\Main\\Start Page ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3802158637-1547946212-584559868-1000\Software\sweetim ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Users\Landgraf-Vaio\appdata\local\adawarebp" ~~~ FireFox Successfully deleted: [Folder] C:\Users\Landgraf-Vaio\AppData\Roaming\mozilla\firefox\profiles\jomifivw.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} Emptied folder: C:\Users\Landgraf-Vaio\AppData\Roaming\mozilla\firefox\profiles\jomifivw.default\minidumps [110 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 21.01.2014 at 18:24:14,22 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-01-2014 Ran by Landgraf-Vaio (administrator) on LANDGRAFVAIO on 21-01-2014 18:24:54 Running from C:\Users\Landgraf-Vaio\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Dropbox, Inc.) C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe (Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [212480 2010-09-15] (Alps Electric Co., Ltd.) HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [SBRegRebootCleaner] - C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-09-20] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554384 2013-07-15] (Lavasoft) HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries) Startup: C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8E2CB2916DB8CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default FF SearchEngineOrder.1: Ask Search FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\inbox-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: YouTube Unblocker - C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\Extensions\youtubeunblocker@unblocker.yt [2014-01-16] ==================== Services (Whitelisted) ================= R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited) R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software) R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH) ==================== Drivers (Whitelisted) ==================== S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-09-25] (GFI Software) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-21 18:24 - 2014-01-21 18:24 - 00010077 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt 2014-01-21 18:24 - 2014-01-21 18:24 - 00002031 _____ C:\Users\Landgraf-Vaio\Desktop\JRT.txt 2014-01-21 18:24 - 2014-01-21 18:24 - 00000000 ____D C:\Users\Landgraf-Vaio\Downloads\FRST-OlderVersion 2014-01-21 18:17 - 2014-01-21 18:17 - 00000000 ____D C:\Windows\ERUNT 2014-01-21 18:16 - 2014-01-21 18:16 - 00004809 _____ C:\Users\Landgraf-Vaio\Desktop\AdwCleaner[S0].txt 2014-01-21 18:05 - 2014-01-21 18:14 - 00000000 ____D C:\AdwCleaner 2014-01-21 18:04 - 2012-12-17 22:29 - 05552942 _____ C:\Users\Landgraf-Vaio\Desktop\com.mojang.minecraftpe.4005.apk 2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Malwarebytes 2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-21 16:34 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-21 16:33 - 2014-01-21 16:33 - 01236282 _____ C:\Users\Landgraf-Vaio\Downloads\adwcleaner.exe 2014-01-21 16:33 - 2014-01-21 16:33 - 01037068 _____ (Thisisu) C:\Users\Landgraf-Vaio\Downloads\JRT.exe 2014-01-21 16:32 - 2014-01-21 16:32 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Landgraf-Vaio\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-19 20:32 - 2014-01-19 20:32 - 00026558 _____ C:\ComboFix.txt 2014-01-19 20:25 - 2014-01-19 20:32 - 00000000 ____D C:\ComboFix 2014-01-19 20:07 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-19 20:07 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-19 20:07 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-19 20:07 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-19 20:07 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-19 20:07 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-19 20:07 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-19 20:07 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-19 20:06 - 2014-01-19 20:32 - 00000000 ____D C:\Qoobox 2014-01-19 20:06 - 2014-01-19 20:16 - 00000000 ____D C:\Windows\erdnt 2014-01-19 20:04 - 2014-01-19 20:04 - 05167985 ____R (Swearware) C:\Users\Landgraf-Vaio\Downloads\ComboFix.exe 2014-01-19 10:45 - 2014-01-19 10:46 - 00026464 _____ C:\Users\Landgraf-Vaio\Downloads\Addition.txt 2014-01-19 10:45 - 2014-01-19 10:45 - 00379904 _____ C:\Users\Landgraf-Vaio\Downloads\0pk01sgw.exe 2014-01-19 10:44 - 2014-01-21 18:24 - 02077184 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe 2014-01-19 10:44 - 2014-01-21 18:24 - 00000000 ____D C:\FRST 2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log 2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable 2014-01-18 22:02 - 2014-01-18 22:52 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx 2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip 2014-01-18 17:21 - 2014-01-19 20:25 - 00000330 _____ C:\Windows\wininit.ini 2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe 2014-01-18 16:52 - 2014-01-18 16:53 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe 2014-01-18 15:06 - 2014-01-19 10:40 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B 2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-15 14:27 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-01-15 14:27 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-01-15 14:27 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-01-15 14:27 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-01-15 14:20 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 14:20 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 14:20 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 14:19 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 14:19 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 14:19 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 14:19 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 14:19 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 14:19 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin 2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin 2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin 2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin 2014-01-03 16:20 - 2014-01-03 16:21 - 00000000 ____D C:\Program Files (x86)\Garmin 2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache ==================== One Month Modified Files and Folders ======= 2014-01-21 18:25 - 2014-01-21 18:24 - 00010077 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt 2014-01-21 18:24 - 2014-01-21 18:24 - 00002031 _____ C:\Users\Landgraf-Vaio\Desktop\JRT.txt 2014-01-21 18:24 - 2014-01-21 18:24 - 00000000 ____D C:\Users\Landgraf-Vaio\Downloads\FRST-OlderVersion 2014-01-21 18:24 - 2014-01-19 10:44 - 02077184 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe 2014-01-21 18:24 - 2014-01-19 10:44 - 00000000 ____D C:\FRST 2014-01-21 18:23 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-21 18:23 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-21 18:17 - 2014-01-21 18:17 - 00000000 ____D C:\Windows\ERUNT 2014-01-21 18:17 - 2013-12-01 17:47 - 00000000 ___RD C:\Users\Landgraf-Vaio\Dropbox 2014-01-21 18:17 - 2013-12-01 17:43 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox 2014-01-21 18:17 - 2013-09-23 19:18 - 00003978 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{302D991D-8607-4326-8B9F-1E38889BFE91} 2014-01-21 18:16 - 2014-01-21 18:16 - 00004809 _____ C:\Users\Landgraf-Vaio\Desktop\AdwCleaner[S0].txt 2014-01-21 18:15 - 2013-10-29 21:34 - 00014492 _____ C:\Windows\setupact.log 2014-01-21 18:15 - 2013-09-23 15:47 - 01504041 _____ C:\Windows\WindowsUpdate.log 2014-01-21 18:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-21 18:14 - 2014-01-21 18:05 - 00000000 ____D C:\AdwCleaner 2014-01-21 18:01 - 2013-10-31 01:14 - 00007316 _____ C:\Windows\PFRO.log 2014-01-21 18:00 - 2010-11-21 07:50 - 00654166 _____ C:\Windows\system32\perfh007.dat 2014-01-21 18:00 - 2010-11-21 07:50 - 00130006 _____ C:\Windows\system32\perfc007.dat 2014-01-21 18:00 - 2009-07-14 06:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-21 17:54 - 2013-09-25 16:56 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Windows Live 2014-01-21 17:43 - 2013-10-23 09:47 - 00391453 _____ C:\test.xml 2014-01-21 17:35 - 2013-09-23 19:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Malwarebytes 2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-21 16:33 - 2014-01-21 16:33 - 01236282 _____ C:\Users\Landgraf-Vaio\Downloads\adwcleaner.exe 2014-01-21 16:33 - 2014-01-21 16:33 - 01037068 _____ (Thisisu) C:\Users\Landgraf-Vaio\Downloads\JRT.exe 2014-01-21 16:32 - 2014-01-21 16:32 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Landgraf-Vaio\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-21 16:29 - 2013-09-25 15:09 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0 2014-01-19 20:38 - 2013-09-25 14:19 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-01-19 20:32 - 2014-01-19 20:32 - 00026558 _____ C:\ComboFix.txt 2014-01-19 20:32 - 2014-01-19 20:25 - 00000000 ____D C:\ComboFix 2014-01-19 20:32 - 2014-01-19 20:06 - 00000000 ____D C:\Qoobox 2014-01-19 20:30 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-19 20:25 - 2014-01-18 17:21 - 00000330 _____ C:\Windows\wininit.ini 2014-01-19 20:17 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-19 20:16 - 2014-01-19 20:06 - 00000000 ____D C:\Windows\erdnt 2014-01-19 20:04 - 2014-01-19 20:04 - 05167985 ____R (Swearware) C:\Users\Landgraf-Vaio\Downloads\ComboFix.exe 2014-01-19 10:46 - 2014-01-19 10:45 - 00026464 _____ C:\Users\Landgraf-Vaio\Downloads\Addition.txt 2014-01-19 10:45 - 2014-01-19 10:45 - 00379904 _____ C:\Users\Landgraf-Vaio\Downloads\0pk01sgw.exe 2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log 2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable 2014-01-19 10:43 - 2013-09-23 15:58 - 00000000 ____D C:\Users\Landgraf-Vaio 2014-01-19 10:40 - 2014-01-18 15:06 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B 2014-01-19 10:40 - 2013-09-23 15:58 - 00000000 ___RD C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-18 22:52 - 2014-01-18 22:02 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx 2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip 2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe 2014-01-18 16:53 - 2014-01-18 16:52 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe 2014-01-17 08:14 - 2013-10-01 22:53 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Skype 2014-01-16 19:14 - 2013-12-01 17:45 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-16 19:09 - 2009-07-14 05:45 - 00417024 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-16 14:11 - 2013-09-23 18:39 - 00000000 ____D C:\Windows\system32\MRT 2014-01-16 14:08 - 2013-09-23 18:39 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-15 14:27 - 2013-09-29 20:45 - 00000000 ____D C:\ProgramData\Oracle 2014-01-15 14:27 - 2013-09-29 20:44 - 00000000 ____D C:\Program Files (x86)\Java 2014-01-09 13:19 - 2013-09-25 16:05 - 00000000 ____D C:\Windows\System32\Tasks\Games 2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Robert 2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ICQ 2014-01-03 16:52 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Anja 2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin 2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin 2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin 2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin 2014-01-03 16:21 - 2014-01-03 16:20 - 00000000 ____D C:\Program Files (x86)\Garmin 2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache Some content of TEMP: ==================== C:\Users\Landgraf-Vaio\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-20 18:14 ==================== End Of Log ============================ [/CODE] |
22.01.2014, 12:17 | #6 |
/// the machine /// TB-Ausbilder | Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da istESET Online Scanner
Downloade Dir bitte SecurityCheck und:
und ein frisches FRST log bitte. Noch Probleme?
__________________ --> Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist |
22.01.2014, 19:04 | #7 |
| Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist hat alles geklappt: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=e295e0fc9f85ac41877ea5635ee993f3 # engine=16754 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-22 05:52:02 # local_time=2014-01-22 06:52:02 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1023 16777215 0 0 0 0 0 0 # compatibility_mode=5893 16776574 100 94 10372304 142042972 0 0 # scanned=160351 # found=0 # cleaned=0 # scan_time=3393 Code:
ATTFilter Results of screen317's Security Check version 0.99.79 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Lavasoft Ad-Aware Antivirus up to date! (On Access scanning disabled!) `````````Anti-malware/Other Utilities Check:````````` Ad-Aware Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 51 Adobe Flash Player 11.9.900.170 Adobe Reader XI Mozilla Firefox (26.0) ````````Process Check: objlist.exe by Laurent```````` Ad-Aware AAWService.exe is disabled! Ad-Aware AAWTray.exe is disabled! Ad-Aware Antivirus AdAwareService.exe Ad-Aware Antivirus SBAMSvc.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-01-2014 Ran by Landgraf-Vaio (administrator) on LANDGRAFVAIO on 22-01-2014 19:00:45 Running from C:\Users\Landgraf-Vaio\Downloads Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard Internet Explorer Version 11 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe (Dropbox, Inc.) C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe (Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE (GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe (Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe (ALPS) C:\Program Files\Apoint\Apvfb.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe (Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe (Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe (Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe (Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe (Microsoft Corporation) C:\Windows\System32\vds.exe (Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [212480 2010-09-15] (Alps Electric Co., Ltd.) HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation) HKLM\...\Run: [SBRegRebootCleaner] - C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-09-20] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554384 2013-07-15] (Lavasoft) HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated) HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries) Startup: C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8E2CB2916DB8CE01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 FireFox: ======== FF ProfilePath: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default FF SearchEngineOrder.1: Ask Search FF Homepage: about:home FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll () FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation) FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation) FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF SearchPlugin: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\inbox-search.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: YouTube Unblocker - C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\Extensions\youtubeunblocker@unblocker.yt [2014-01-16] ==================== Services (Whitelisted) ================= R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited) R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries) R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation) R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software) S2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH) ==================== Drivers (Whitelisted) ==================== S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security) R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-09-25] (GFI Software) U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-22 18:59 - 2014-01-22 18:59 - 00000978 _____ C:\Users\Landgraf-Vaio\Desktop\checkup.txt 2014-01-22 06:33 - 2014-01-22 06:33 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\adawarebp 2014-01-21 18:24 - 2014-01-22 19:00 - 00010173 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt 2014-01-21 18:24 - 2014-01-21 18:24 - 00000000 ____D C:\Users\Landgraf-Vaio\Downloads\FRST-OlderVersion 2014-01-21 18:17 - 2014-01-21 18:17 - 00000000 ____D C:\Windows\ERUNT 2014-01-21 18:05 - 2014-01-21 18:14 - 00000000 ____D C:\AdwCleaner 2014-01-21 18:04 - 2012-12-17 22:29 - 05552942 _____ C:\Users\Landgraf-Vaio\Desktop\com.mojang.minecraftpe.4005.apk 2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Malwarebytes 2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-21 16:34 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-21 16:32 - 2014-01-21 16:32 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Landgraf-Vaio\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-19 20:32 - 2014-01-19 20:32 - 00026558 _____ C:\ComboFix.txt 2014-01-19 20:25 - 2014-01-19 20:32 - 00000000 ____D C:\ComboFix 2014-01-19 20:07 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe 2014-01-19 20:07 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe 2014-01-19 20:07 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-19 20:07 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-19 20:07 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-19 20:07 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe 2014-01-19 20:07 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe 2014-01-19 20:07 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe 2014-01-19 20:06 - 2014-01-19 20:32 - 00000000 ____D C:\Qoobox 2014-01-19 20:06 - 2014-01-19 20:16 - 00000000 ____D C:\Windows\erdnt 2014-01-19 10:45 - 2014-01-19 10:46 - 00026464 _____ C:\Users\Landgraf-Vaio\Downloads\Addition.txt 2014-01-19 10:45 - 2014-01-19 10:45 - 00379904 _____ C:\Users\Landgraf-Vaio\Downloads\0pk01sgw.exe 2014-01-19 10:44 - 2014-01-21 18:24 - 02077184 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe 2014-01-19 10:44 - 2014-01-21 18:24 - 00000000 ____D C:\FRST 2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log 2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable 2014-01-18 22:02 - 2014-01-18 22:52 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx 2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip 2014-01-18 17:21 - 2014-01-19 20:25 - 00000330 _____ C:\Windows\wininit.ini 2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe 2014-01-18 16:52 - 2014-01-18 16:53 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe 2014-01-18 15:06 - 2014-01-19 10:40 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B 2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-15 14:27 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll 2014-01-15 14:27 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe 2014-01-15 14:27 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe 2014-01-15 14:27 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe 2014-01-15 14:20 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys 2014-01-15 14:20 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys 2014-01-15 14:20 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys 2014-01-15 14:19 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys 2014-01-15 14:19 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys 2014-01-15 14:19 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys 2014-01-15 14:19 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys 2014-01-15 14:19 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys 2014-01-15 14:19 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys 2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin 2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin 2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin 2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin 2014-01-03 16:20 - 2014-01-03 16:21 - 00000000 ____D C:\Program Files (x86)\Garmin 2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache ==================== One Month Modified Files and Folders ======= 2014-01-22 19:01 - 2014-01-21 18:24 - 00010173 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt 2014-01-22 18:59 - 2014-01-22 18:59 - 00000978 _____ C:\Users\Landgraf-Vaio\Desktop\checkup.txt 2014-01-22 18:47 - 2013-09-23 15:47 - 01533687 _____ C:\Windows\WindowsUpdate.log 2014-01-22 18:35 - 2013-09-23 19:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-22 17:38 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-22 17:38 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-22 17:34 - 2013-09-23 19:18 - 00003978 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{302D991D-8607-4326-8B9F-1E38889BFE91} 2014-01-22 17:30 - 2013-12-01 17:47 - 00000000 ___RD C:\Users\Landgraf-Vaio\Dropbox 2014-01-22 17:30 - 2013-12-01 17:43 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox 2014-01-22 17:30 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-22 17:29 - 2013-10-29 21:34 - 00014660 _____ C:\Windows\setupact.log 2014-01-22 06:43 - 2013-09-25 16:56 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Windows Live 2014-01-22 06:33 - 2014-01-22 06:33 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\adawarebp 2014-01-21 18:24 - 2014-01-21 18:24 - 00000000 ____D C:\Users\Landgraf-Vaio\Downloads\FRST-OlderVersion 2014-01-21 18:24 - 2014-01-19 10:44 - 02077184 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe 2014-01-21 18:24 - 2014-01-19 10:44 - 00000000 ____D C:\FRST 2014-01-21 18:17 - 2014-01-21 18:17 - 00000000 ____D C:\Windows\ERUNT 2014-01-21 18:14 - 2014-01-21 18:05 - 00000000 ____D C:\AdwCleaner 2014-01-21 18:01 - 2013-10-31 01:14 - 00007316 _____ C:\Windows\PFRO.log 2014-01-21 18:00 - 2010-11-21 07:50 - 00654166 _____ C:\Windows\system32\perfh007.dat 2014-01-21 18:00 - 2010-11-21 07:50 - 00130006 _____ C:\Windows\system32\perfc007.dat 2014-01-21 18:00 - 2009-07-14 06:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-21 17:43 - 2013-10-23 09:47 - 00391453 _____ C:\test.xml 2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Malwarebytes 2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-21 16:32 - 2014-01-21 16:32 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Landgraf-Vaio\Downloads\mbam-setup-1.75.0.1300.exe 2014-01-21 16:29 - 2013-09-25 15:09 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0 2014-01-19 20:38 - 2013-09-25 14:19 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2 2014-01-19 20:32 - 2014-01-19 20:32 - 00026558 _____ C:\ComboFix.txt 2014-01-19 20:32 - 2014-01-19 20:25 - 00000000 ____D C:\ComboFix 2014-01-19 20:32 - 2014-01-19 20:06 - 00000000 ____D C:\Qoobox 2014-01-19 20:30 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini 2014-01-19 20:25 - 2014-01-18 17:21 - 00000330 _____ C:\Windows\wininit.ini 2014-01-19 20:17 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default 2014-01-19 20:16 - 2014-01-19 20:06 - 00000000 ____D C:\Windows\erdnt 2014-01-19 10:46 - 2014-01-19 10:45 - 00026464 _____ C:\Users\Landgraf-Vaio\Downloads\Addition.txt 2014-01-19 10:45 - 2014-01-19 10:45 - 00379904 _____ C:\Users\Landgraf-Vaio\Downloads\0pk01sgw.exe 2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log 2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable 2014-01-19 10:43 - 2013-09-23 15:58 - 00000000 ____D C:\Users\Landgraf-Vaio 2014-01-19 10:40 - 2014-01-18 15:06 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B 2014-01-19 10:40 - 2013-09-23 15:58 - 00000000 ___RD C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-18 22:52 - 2014-01-18 22:02 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx 2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip 2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe 2014-01-18 16:53 - 2014-01-18 16:52 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe 2014-01-17 08:14 - 2013-10-01 22:53 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Skype 2014-01-16 19:14 - 2013-12-01 17:45 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-16 19:09 - 2009-07-14 05:45 - 00417024 _____ C:\Windows\system32\FNTCACHE.DAT 2014-01-16 14:11 - 2013-09-23 18:39 - 00000000 ____D C:\Windows\system32\MRT 2014-01-16 14:08 - 2013-09-23 18:39 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log 2014-01-15 14:27 - 2013-09-29 20:45 - 00000000 ____D C:\ProgramData\Oracle 2014-01-15 14:27 - 2013-09-29 20:44 - 00000000 ____D C:\Program Files (x86)\Java 2014-01-09 13:19 - 2013-09-25 16:05 - 00000000 ____D C:\Windows\System32\Tasks\Games 2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Robert 2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ICQ 2014-01-03 16:52 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Anja 2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin 2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin 2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin 2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin 2014-01-03 16:21 - 2014-01-03 16:20 - 00000000 ____D C:\Program Files (x86)\Garmin 2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache Some content of TEMP: ==================== C:\Users\Landgraf-Vaio\AppData\Local\Temp\Quarantine.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-20 18:14 ==================== End Of Log ============================ [/CODE] |
23.01.2014, 16:19 | #8 |
/// the machine /// TB-Ausbilder | Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist Fertig Falls Du Lob oder Kritik loswerden möchtest kannst Du das hier tun Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
24.01.2014, 13:28 | #9 |
| Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist vielen lieben dank für die schnelle Hilfe |
25.01.2014, 11:52 | #10 |
/// the machine /// TB-Ausbilder | Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist Gern Geschehen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist |
4d36e972-e325-11ce-bfc1-08002be10318, ad-aware, branding, browser, e-mail, error, excel, flash player, help, home, homepage, link geöffnet, log-datei, minidump, newtab, ntdll.dll, pup.optional.appgraffiti.a, pup.optional.delta.a, pup.optional.inboxtoolbar.a, pup.optional.installcore.a, pup.optional.rebateinformer.a, pup.optional.wajam.a, refresh, registry, rundll, security, software, svchost.exe, system, trojaner, unlock, vista, windows |