Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 19.01.2014, 12:19   #1
jahallotach
 
Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Standard

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist



Hallo,
Ich habe eine Fake E-Mail von Vodafone bekommen, leider den link geöffnet und die Datei darin auch gestartet, jetzt schlägt mein Antivirus Programm regelmäßig an.

Nach kurzer Googlesuche habe ich herausgefunden, dass dadurch ein Trojaner in mein System gelangen kann, da ich kaum Ahnung davon habe wäre es nett wenn mir einer Helfen könnte und das ganze überprüft.

Mein System ist ein Windows 7 mit SP1

Hier die Geforderten Log Files:

FRST Additions Logfile:
Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-01-2014 03
Ran by Landgraf-Vaio at 2014-01-19 10:45:41
Running from C:\Users\Landgraf-Vaio\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

AV: Lavasoft Ad-Aware (Enabled - Up to date) {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Lavasoft Ad-Aware (Enabled - Up to date) {5BB89C30-6480-BC7C-9F17-199BD76F557A}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Lavasoft Ad-Aware (Disabled) {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}

==================== Installed Programs ======================

Ad-Aware Antivirus (x32 Version: 10.5.3.4405 - Lavasoft)
Ad-Aware Security Add-on (x32 Version: 3.4.0.1 - Lavasoft)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (x32 Version: 11.0.06 - Adobe Systems Incorporated)
Alps Pointing-device for VAIO (Version:  - ALPS ELECTRIC CO., LTD.)
ATI Catalyst Install Manager (Version: 3.0.769.0 - ATI Technologies, Inc.)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2010.0920.2143.37117 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Czech (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Danish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Dutch (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help English (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Finnish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help French (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help German (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Greek (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Italian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Japanese (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Korean (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Polish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Russian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Spanish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Swedish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Thai (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Turkish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
ccc-core-static (x32 Version: 2010.0920.2143.37117 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2010.0920.2143.37117 - ATI) Hidden
Cultris II (x32 Version:  - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (Version:  - Microsoft)
DHTML Editing Component (x32 Version: 6.02.0001 - Microsoft Corporation)
Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.)
Elevated Installer (x32 Version: 2.3.18.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (x32 Version: 2.3.18.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 2.3.18.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 2.3.18.0 - Garmin Ltd or its subsidiaries) Hidden
GUILD WARS (x32 Version:  - )
Java 7 Update 51 (x32 Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
Rossmann Fotowelt Software 4.13 (x32 Version: 4.13 - ORWO Net)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version:  - Microsoft) Hidden
Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.)
Spybot - Search & Destroy (x32 Version: 2.1.21 - Safer-Networking Ltd.)
StarMoney (x32 Version: 4.0.1.51 - StarFinanz) Hidden
StarMoney 9.0  (x32 Version: 9.0 - Star Finanz GmbH)
TeamSpeak 3 Client (Version: 3.0.13 - TeamSpeak Systems GmbH)
Turbo Lister 2 (x32 Version: 2.00.0000 - eBay Inc.)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 64-Bit Edition (Version:  - Microsoft)
VAIO Care (x32 Version: 6.4.2.11150 - Sony Corporation) Hidden
VAIO Control Center (x32 Version: 4.3.0.05310 - Sony Corporation)
VAIO Gate (x32 Version: 1.0.0.08050 - Sony Corporation)
WIDCOMM Bluetooth Software (Version: 6.3.0.5600 - Broadcom Corporation)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
WinRAR 5.00 (64-Bit) (Version: 5.00.0 - win.rar GmbH)

==================== Restore Points  =========================

03-01-2014 15:20:19 Garmin Express
11-01-2014 10:27:41 Geplanter Prüfpunkt
15-01-2014 13:26:27 Installed Java 7 Update 51
16-01-2014 13:07:58 Windows Update

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {011E21C1-096A-4512-ADBB-B6862B20B18D} - System32\Tasks\SONY\SUS-BCF\Level4Daily => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {08799212-6B94-41FE-91A6-2C6896E110C8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {353D0556-A1CF-4BF8-9EB8-E7E80A0B6284} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation)
Task: {53DCCA7C-F53A-4401-925E-AECFB394629A} - System32\Tasks\SONY\VAIO Power Management\VPM Session Change => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {580F0F58-DB00-41E0-B22F-C7A2C5BF6564} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe [2013-06-13] (Lavasoft Limited)
Task: {6216FDBE-2DE3-4C21-9A74-5BC685FAAA5E} - System32\Tasks\SONY\VAIO Power Management\VPM Logon Start => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {64F5C105-EADC-4468-A682-077344B3B594} - System32\Tasks\SONY\SUS-BCF\Level4Month => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {698549F5-2782-442A-9951-1B399C00C311} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {6F63A80D-96F5-421E-B68E-CBF3E84AC01F} - System32\Tasks\{10182459-CFFA-4D5D-BF1E-E97CF00453CF} => Firefox.exe hxxp://ui.skype.com/ui/0/6.7.0.102/de/abandoninstall?source=lightinstaller&page=tsInstall
Task: {9A88A67C-C08A-4CF4-877A-BDEF50AECC22} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-21] (Adobe Systems Incorporated)
Task: {A65840CB-BD79-4E8E-AC05-DBFD3F191FD0} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2009-08-05] (Sony Corporation)
Task: {B32DCDB0-4212-4368-9F65-4A2D3D39CC71} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation)
Task: {D76F951E-1DEC-419E-B965-743B4FF045D9} - System32\Tasks\SONY\VAIO Power Management\VPM Unlock => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {EB0406D4-B9EB-4ACF-90AA-D8BC7D453F6A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-08-24 13:39 - 2010-08-24 13:39 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2013-09-23 16:16 - 2013-09-23 16:16 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\libcef.dll
2013-09-25 14:19 - 2013-05-16 09:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-09-25 14:19 - 2013-05-16 09:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2013-09-25 14:19 - 2013-05-16 09:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2013-09-25 14:19 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2013-09-25 14:19 - 2012-04-03 16:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2013-10-15 11:40 - 2011-01-13 10:44 - 00232800 _____ () C:\Program Files (x86)\StarMoney 9.0\ouservice\PATCHW32.dll
2013-09-25 14:35 - 2013-12-19 14:07 - 00190752 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libBase64.dll
2013-09-25 14:35 - 2013-12-19 14:07 - 00178464 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libMachoUniv.dll
2013-09-23 16:35 - 2013-12-21 17:49 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Users\Landgraf-Vaio\Documents\Landgraf ___ MB Massivhaus, u_Z_ 549_12RE.eml:OECustomProperty

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service => ""="Ad-Aware Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ad-Aware Service => ""="Ad-Aware Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBAMSvc => ""="Service"

==================== Faulty Device Manager Devices =============

Name: Microsoft-Adapter für Miniports virtueller WiFis
Description: Microsoft-Adapter für Miniports virtueller WiFis
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Marvell Yukon 88E8059 PCI-E Gigabit Ethernet Controller
Description: Marvell Yukon 88E8059 PCI-E Gigabit Ethernet Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Marvell
Service: yukonw7
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.


==================== Event log errors: =========================

Application errors:
==================
Error: (01/19/2014 10:25:42 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service) (User: )
Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet.


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.   0xc0041801 (0xc0041801)

Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service) (User: )
Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=2350} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben.


Details:
	Der Inhaltsindexkatalog ist fehlerhaft.   0xc0041801 (0xc0041801)

Error: (01/18/2014 07:52:30 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 06:44:32 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 04:51:05 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 03:34:04 PM) (Source: Application Hang) (User: )
Description: Programm firefox.exe, Version 26.0.0.5087 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1504

Startzeit: 01cf145a3d53c4fd

Endzeit: 14

Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID: 8bf65b7b-804d-11e3-b0de-18f46af81e57

Error: (01/18/2014 03:07:24 PM) (Source: Application Hang) (User: )
Description: Programm firefox.exe, Version 26.0.0.5087 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 91c

Startzeit: 01cf1455e1d904dd

Endzeit: 31

Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID: d8953a08-8049-11e3-b0de-18f46af81e57

Error: (01/18/2014 11:32:14 AM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005

Error: (01/18/2014 10:37:29 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (01/19/2014 10:25:14 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Garmin Core Update Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (01/19/2014 10:25:14 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Garmin Core Update Service erreicht.

Error: (01/18/2014 11:12:50 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (01/18/2014 06:42:59 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (01/18/2014 04:51:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Updating Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (01/18/2014 04:51:33 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Updating Service erreicht.

Error: (01/18/2014 04:49:24 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (01/18/2014 10:37:18 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053

Error: (01/18/2014 10:37:18 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.

Error: (01/18/2014 10:36:48 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Garmin Core Update Service" wurde aufgrund folgenden Fehlers nicht gestartet: 
%%1053


Microsoft Office Sessions:
=========================
Error: (01/19/2014 10:25:42 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service)(User: )
Description: 
Details:
	Der Inhaltsindexkatalog ist fehlerhaft.   0xc0041801 (0xc0041801)
The catalog is corrupt

Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service)(User: )
Description: 
Details:
	Der Inhaltsindexkatalog ist fehlerhaft.   0xc0041801 (0xc0041801)
2350

Error: (01/18/2014 07:52:30 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 06:44:32 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 04:51:05 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 03:34:04 PM) (Source: Application Hang)(User: )
Description: firefox.exe26.0.0.5087150401cf145a3d53c4fd14C:\Program Files (x86)\Mozilla Firefox\firefox.exe8bf65b7b-804d-11e3-b0de-18f46af81e57

Error: (01/18/2014 03:07:24 PM) (Source: Application Hang)(User: )
Description: firefox.exe26.0.0.508791c01cf1455e1d904dd31C:\Program Files (x86)\Mozilla Firefox\firefox.exed8953a08-8049-11e3-b0de-18f46af81e57

Error: (01/18/2014 11:32:14 AM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005

Error: (01/18/2014 10:37:29 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


==================== Memory info =========================== 

Percentage of memory in use: 45%
Total physical RAM: 3950.1 MB
Available physical RAM: 2139.82 MB
Total Pagefile: 7898.38 MB
Available Pagefile: 5538.8 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:253.21 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 7A7F4430)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
--- --- ---


Code:
ATTFilter
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 10:43 on 19/01/2014 (Landgraf-Vaio)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


-=E.O.F=-
         

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-01-2014 03
Ran by Landgraf-Vaio (administrator) on LANDGRAFVAIO on 19-01-2014 10:45:00
Running from C:\Users\Landgraf-Vaio\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal


==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Lavasoft) C:\ProgramData\Search Protection\SearchProtection.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [212480 2010-09-15] (Alps Electric Co., Ltd.)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [SBRegRebootCleaner] - C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-09-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554384 2013-07-15] (Lavasoft)
HKLM-x32\...\Run: [Search Protection] - C:\ProgramData\Search Protection\SearchProtection.exe [943016 2013-06-13] (Lavasoft)
HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries)
HKCU\...\Run: [KB01353482.exe] - "C:\Users\Landgraf-Vaio\AppData\Roaming\KB01353482.exe"
HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
Startup: C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id=adawaretb&v=3_4&ent=hp&u=CAAA82C8C61AAA03D18D225242E3D633
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8E2CB2916DB8CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_4&hsimp=yhs-lavasoft&ent=ch&q={searchTerms}
BHO: AppGraffiti - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\PROGRA~2\APPGRA~1\APPGRA~2.DLL No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

FireFox:
========
FF ProfilePath: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default
FF NewTab: hxxp://www.searchgol.com/?babsrc=NT_ss&mntrId=E8E118F46AF81E57&affID=119357&tsp=5014
FF SearchEngineOrder.1: Ask Search
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\ask-search.xml
FF SearchPlugin: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\inbox-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\adawaretb.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YouTube Unblocker - C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\Extensions\youtubeunblocker@unblocker.yt [2014-01-16]
FF Extension: Ad-Aware Security Add-on - C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} [2013-09-25]

==================== Services (Whitelisted) =================

R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited)
S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation)
R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH)

==================== Drivers (Whitelisted) ====================

S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-09-25] (GFI Software)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-01-19 10:45 - 2014-01-19 10:45 - 00012572 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt
2014-01-19 10:44 - 2014-01-19 10:44 - 02076160 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe
2014-01-19 10:44 - 2014-01-19 10:44 - 00000000 ____D C:\FRST
2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log
2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable
2014-01-18 22:02 - 2014-01-18 22:52 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx
2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip
2014-01-18 21:42 - 2014-01-18 21:42 - 01077248 _____ (Zhorn Software) C:\Users\Landgraf-Vaio\Downloads\stickies_setup_7.1e.exe
2014-01-18 17:21 - 2014-01-18 17:22 - 00000280 _____ C:\Windows\wininit.ini
2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe
2014-01-18 16:52 - 2014-01-18 16:53 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-18 15:06 - 2014-01-19 10:40 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B
2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-15 14:27 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-15 14:27 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-15 14:27 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-15 14:27 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-15 14:20 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 14:20 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 14:20 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 14:19 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 14:19 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin
2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin
2014-01-03 16:20 - 2014-01-03 16:21 - 00000000 ____D C:\Program Files (x86)\Garmin
2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-21 12:46 - 2013-12-21 12:47 - 00024576 ___SH C:\Users\Landgraf-Vaio\Documents\Thumbs.db
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\webasto
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Vorlagen
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Steuererklärung
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\saeco
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Robert
2013-12-20 17:56 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Rechnungen
2013-12-20 17:55 - 2014-01-03 16:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Robert
2013-12-20 17:55 - 2014-01-03 16:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ICQ
2013-12-20 17:55 - 2014-01-03 16:52 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Anja
2013-12-20 17:54 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Hausbau
2013-12-20 17:54 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\email
2013-12-20 17:53 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ebooks
2013-12-20 17:53 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Auto
2013-12-20 17:52 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Anja
2013-12-20 17:50 - 2013-02-22 20:30 - 00122300 _____ C:\Users\Landgraf-Vaio\Documents\Landgraf ___ MB Massivhaus, u_Z_ 549_12RE.eml
2013-12-20 17:50 - 2012-05-12 23:57 - 341600159 _____ C:\Users\Landgraf-Vaio\Documents\PerAnhalterdurchdieGalaxis_ep7_anjalandgraf.aax
2013-12-20 14:18 - 2013-12-20 15:55 - 00004419 _____ C:\Users\Landgraf-Vaio\Downloads\config Landgraf AP.dat
2013-12-20 13:37 - 2013-12-20 13:37 - 00273904 _____ C:\Windows\Minidump\122013-18782-01.dmp
2013-12-20 13:16 - 2013-12-20 13:17 - 01892006 _____ C:\Users\Landgraf-Vaio\Downloads\CSL.ML.0726_fwc.bin

==================== One Month Modified Files and Folders =======

2014-01-19 10:45 - 2014-01-19 10:45 - 00012572 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt
2014-01-19 10:44 - 2014-01-19 10:44 - 02076160 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe
2014-01-19 10:44 - 2014-01-19 10:44 - 00000000 ____D C:\FRST
2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log
2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable
2014-01-19 10:43 - 2013-09-23 15:58 - 00000000 ____D C:\Users\Landgraf-Vaio
2014-01-19 10:40 - 2014-01-18 15:06 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B
2014-01-19 10:40 - 2013-09-23 15:58 - 00000000 ___RD C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-19 10:35 - 2013-09-23 19:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-19 10:33 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-19 10:33 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-19 10:30 - 2013-09-23 15:47 - 01428122 _____ C:\Windows\WindowsUpdate.log
2014-01-19 10:27 - 2013-09-23 19:18 - 00003978 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{302D991D-8607-4326-8B9F-1E38889BFE91}
2014-01-19 10:25 - 2013-12-01 17:47 - 00000000 ___RD C:\Users\Landgraf-Vaio\Dropbox
2014-01-19 10:25 - 2013-12-01 17:43 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox
2014-01-19 10:24 - 2013-10-29 21:34 - 00013303 _____ C:\Windows\setupact.log
2014-01-19 10:24 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-18 22:52 - 2014-01-18 22:02 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx
2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip
2014-01-18 21:42 - 2014-01-18 21:42 - 01077248 _____ (Zhorn Software) C:\Users\Landgraf-Vaio\Downloads\stickies_setup_7.1e.exe
2014-01-18 18:43 - 2013-10-31 01:14 - 00003290 _____ C:\Windows\PFRO.log
2014-01-18 17:22 - 2014-01-18 17:21 - 00000280 _____ C:\Windows\wininit.ini
2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe
2014-01-18 16:53 - 2014-01-18 16:52 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-18 14:48 - 2013-09-25 16:56 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Windows Live
2014-01-18 10:37 - 2013-09-25 15:09 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0
2014-01-17 08:14 - 2013-10-01 22:53 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Skype
2014-01-16 19:14 - 2013-12-01 17:45 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-16 19:09 - 2009-07-14 05:45 - 00417024 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-16 14:11 - 2013-09-23 18:39 - 00000000 ____D C:\Windows\system32\MRT
2014-01-16 14:08 - 2013-09-23 18:39 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-15 14:27 - 2013-09-29 20:45 - 00000000 ____D C:\ProgramData\Oracle
2014-01-15 14:27 - 2013-09-29 20:44 - 00000000 ____D C:\Program Files (x86)\Java
2014-01-12 17:14 - 2010-11-21 07:50 - 00654166 _____ C:\Windows\system32\perfh007.dat
2014-01-12 17:14 - 2010-11-21 07:50 - 00130006 _____ C:\Windows\system32\perfc007.dat
2014-01-12 17:14 - 2009-07-14 06:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-12 12:12 - 2013-09-25 14:19 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-01-09 13:19 - 2013-09-25 16:05 - 00000000 ____D C:\Windows\System32\Tasks\Games
2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Robert
2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ICQ
2014-01-03 16:52 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Anja
2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin
2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin
2014-01-03 16:21 - 2014-01-03 16:20 - 00000000 ____D C:\Program Files (x86)\Garmin
2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-31 11:44 - 2013-10-23 09:47 - 00326527 _____ C:\test.xml
2013-12-22 13:03 - 2013-09-25 14:24 - 00000000 ____D C:\ProgramData\Search Protection
2013-12-21 23:36 - 2013-10-03 16:50 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Adobe
2013-12-21 23:36 - 2013-09-23 19:17 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-21 23:36 - 2013-09-23 19:17 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-21 23:36 - 2013-09-23 19:17 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-21 23:06 - 2013-09-26 13:28 - 00000000 ____D C:\andere sachen
2013-12-21 17:49 - 2013-09-23 16:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-21 12:47 - 2013-12-21 12:46 - 00024576 ___SH C:\Users\Landgraf-Vaio\Documents\Thumbs.db
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\webasto
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Vorlagen
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Steuererklärung
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\saeco
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Robert
2013-12-20 18:00 - 2013-12-20 17:56 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Rechnungen
2013-12-20 17:55 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Hausbau
2013-12-20 17:54 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\email
2013-12-20 17:54 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ebooks
2013-12-20 17:53 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Auto
2013-12-20 17:53 - 2013-12-20 17:52 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Anja
2013-12-20 15:55 - 2013-12-20 14:18 - 00004419 _____ C:\Users\Landgraf-Vaio\Downloads\config Landgraf AP.dat
2013-12-20 13:37 - 2013-12-20 13:37 - 00273904 _____ C:\Windows\Minidump\122013-18782-01.dmp
2013-12-20 13:37 - 2013-09-25 08:17 - 363185970 _____ C:\Windows\MEMORY.DMP
2013-12-20 13:37 - 2013-09-25 08:17 - 00000000 ____D C:\Windows\Minidump
2013-12-20 13:17 - 2013-12-20 13:16 - 01892006 _____ C:\Users\Landgraf-Vaio\Downloads\CSL.ML.0726_fwc.bin

Some content of TEMP:
====================
C:\Users\Landgraf-Vaio\AppData\Local\Temp\2cd71744-656a-41f5-8e2f-cf7faa63e1ef.exe
C:\Users\Landgraf-Vaio\AppData\Local\Temp\460a2cca-59e0-4d35-90b2-061ce9b8114e.exe
C:\Users\Landgraf-Vaio\AppData\Local\Temp\APNSetup.exe
C:\Users\Landgraf-Vaio\AppData\Local\Temp\exp15A2.tmp.exe
C:\Users\Landgraf-Vaio\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih.exe
C:\Users\Landgraf-Vaio\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Landgraf-Vaio\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-09 13:12

==================== End Of Log ============================
         
--- --- ---


Code:
ATTFilter
GMER Logfile:
Code:
ATTFilter
GMER 2.1.19324 - hxxp://www.gmer.net
Rootkit scan 2014-01-19 11:13:23
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST9500325AS rev.0006SDM2 465,76GB
Running: 0pk01sgw.exe; Driver: C:\Users\LANDGR~1\AppData\Local\Temp\fflcqkod.sys


---- Kernel code sections - GMER 2.1 ----

INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                                                                       fffff80002db0000 45 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 574                                                                       fffff80002db002e 17 bytes [CE, 01, 00, 00, 00, 00, 00, ...]
.text     C:\Windows\System32\win32k.sys!W32pServiceTable                                                                                          fffff96000153e00 7 bytes [00, 96, F3, FF, 01, A1, F0]
.text     C:\Windows\System32\win32k.sys!W32pServiceTable + 8                                                                                      fffff96000153e08 3 bytes [C0, 06, 02]

---- User code sections - GMER 2.1 ----

.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                        0000000076f40068 5 bytes JMP 00000001009fd480
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                            0000000076f5c4dd 5 bytes JMP 00000001009fd450
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!DeleteSecurityContext               0000000074960bb9 5 bytes JMP 00000001009fd9a0
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!EncryptMessage                      000000007496124e 5 bytes JMP 00000001009fdb80
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!DecryptMessage                      000000007496129d 5 bytes JMP 00000001009fd9c0
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextW          0000000074961557 5 bytes JMP 00000001009fdc00
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextA          0000000074961590 5 bytes JMP 00000001009fdc90
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!closesocket                          0000000075c63918 5 bytes JMP 00000001009fd5d0
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!WSASend                              0000000075c64406 5 bytes JMP 00000001009fd800
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!recv                                 0000000075c66b0e 5 bytes JMP 00000001009fd6f0
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!connect                              0000000075c66bdd 5 bytes JMP 00000001009fd970
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!send                                 0000000075c66f01 5 bytes JMP 00000001009fd8c0
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!WSARecv                              0000000075c67089 5 bytes JMP 00000001009fd5f0
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69             0000000074a81465 2 bytes [A8, 74]
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155            0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\Crypt32.DLL!PFXImportCertStore                  0000000075ad18b8 5 bytes JMP 00000001009fe0e0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                         0000000076f40068 5 bytes JMP 00000001001ed480
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                             0000000076f5c4dd 5 bytes JMP 00000001001ed450
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!DeleteSecurityContext                0000000074960bb9 5 bytes JMP 00000001001ed9a0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!EncryptMessage                       000000007496124e 5 bytes JMP 00000001001edb80
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!DecryptMessage                       000000007496129d 5 bytes JMP 00000001001ed9c0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextW           0000000074961557 5 bytes JMP 00000001001edc00
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextA           0000000074961590 5 bytes JMP 00000001001edc90
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\crypt32.dll!PFXImportCertStore                   0000000075ad18b8 5 bytes JMP 00000001001ee0e0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!closesocket                           0000000075c63918 5 bytes JMP 00000001001ed5d0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!WSASend                               0000000075c64406 5 bytes JMP 00000001001ed800
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!recv                                  0000000075c66b0e 5 bytes JMP 00000001001ed6f0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!connect                               0000000075c66bdd 5 bytes JMP 00000001001ed970
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!send                                  0000000075c66f01 5 bytes JMP 00000001001ed8c0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!WSARecv                               0000000075c67089 5 bytes JMP 00000001001ed5f0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69              0000000074a81465 2 bytes [A8, 74]
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155             0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[3000] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69             0000000074a81465 2 bytes [A8, 74]
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[3000] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155            0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69   0000000074a81465 2 bytes [A8, 74]
.text     C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155  0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                             0000000076f40068 5 bytes JMP 00000001000ad480
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                 0000000076f5c4dd 5 bytes JMP 00000001000ad450
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!DeleteSecurityContext                    0000000074960bb9 5 bytes JMP 00000001000ad9a0
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!EncryptMessage                           000000007496124e 5 bytes JMP 00000001000adb80
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!DecryptMessage                           000000007496129d 5 bytes JMP 00000001000ad9c0
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextW               0000000074961557 5 bytes JMP 00000001000adc00
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextA               0000000074961590 5 bytes JMP 00000001000adc90
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                  0000000074a81465 2 bytes [A8, 74]
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                 0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\ProgramData\Search Protection\SearchProtection.exe[3080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                      0000000074a81465 2 bytes [A8, 74]
.text     C:\ProgramData\Search Protection\SearchProtection.exe[3080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                     0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                      0000000076f40068 5 bytes JMP 00000001001dd480
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                          0000000076f5c4dd 5 bytes JMP 00000001001dd450
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!closesocket                        0000000075c63918 5 bytes JMP 00000001001dd5d0
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!WSASend                            0000000075c64406 5 bytes JMP 00000001001dd800
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!recv                               0000000075c66b0e 5 bytes JMP 00000001001dd6f0
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!connect                            0000000075c66bdd 5 bytes JMP 00000001001dd970
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!send                               0000000075c66f01 5 bytes JMP 00000001001dd8c0
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!WSARecv                            0000000075c67089 5 bytes JMP 00000001001dd5f0
.text     C:\PROGRA~2\AD-AWA~1\AdAware.exe[4444] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                           0000000074a81465 2 bytes [A8, 74]
.text     C:\PROGRA~2\AD-AWA~1\AdAware.exe[4444] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                          0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                                      0000000076f40068 5 bytes JMP 000000010011d480
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                          0000000076f5c4dd 5 bytes JMP 000000010011d450
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                           0000000074a81465 2 bytes [A8, 74]
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                          0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!closesocket                                                        0000000075c63918 5 bytes JMP 000000010011d5d0
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!WSASend                                                            0000000075c64406 5 bytes JMP 000000010011d800
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!recv                                                               0000000075c66b0e 5 bytes JMP 000000010011d6f0
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!connect                                                            0000000075c66bdd 5 bytes JMP 000000010011d970
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!send                                                               0000000075c66f01 5 bytes JMP 000000010011d8c0
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!WSARecv                                                            0000000075c67089 5 bytes JMP 000000010011d5f0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                 0000000076f40068 5 bytes JMP 000000010025d480
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                     0000000076f5c4dd 5 bytes JMP 000000010025d450
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!closesocket                   0000000075c63918 5 bytes JMP 000000010025d5d0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!WSASend                       0000000075c64406 5 bytes JMP 000000010025d800
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!recv                          0000000075c66b0e 5 bytes JMP 000000010025d6f0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!connect                       0000000075c66bdd 5 bytes JMP 000000010025d970
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!send                          0000000075c66f01 5 bytes JMP 000000010025d8c0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!WSARecv                       0000000075c67089 5 bytes JMP 000000010025d5f0
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                          0000000076f40068 5 bytes JMP 000000010042d480
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                              0000000076f5c4dd 5 bytes JMP 000000010042d450
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!closesocket                                            0000000075c63918 5 bytes JMP 000000010042d5d0
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!WSASend                                                0000000075c64406 5 bytes JMP 000000010042d800
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!recv                                                   0000000075c66b0e 5 bytes JMP 000000010042d6f0
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!connect                                                0000000075c66bdd 5 bytes JMP 000000010042d970
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!send                                                   0000000075c66f01 5 bytes JMP 000000010042d8c0
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!WSARecv                                                0000000075c67089 5 bytes JMP 000000010042d5f0

---- Threads - GMER 2.1 ----

Thread    C:\Windows\SysWOW64\RunDll32.exe [1584:3296]                                                                                             000000000011b890
Thread    C:\Windows\SysWOW64\RunDll32.exe [1584:4428]                                                                                             0000000000119480
Thread    C:\Windows\SysWOW64\RunDll32.exe [1584:4412]                                                                                             000000000011c920

---- Registry - GMER 2.1 ----

Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\18f46af81e57                                                              
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\18f46af81e57 (not active ControlSet)                                          

---- EOF - GMER 2.1 ----
         
--- --- ---
Code:
ATTFilter
leider weiss ich nicht wie ich die Log-Datei vom Ad-Aware-Antivirus-Programm auslesen kann, Sry
es hat 3x Trojan Win32 Generic! BT und einmal Worm.Win32.Critec.ac(v) gefunden, ich lasse diese dinge noch in der Quarantäne bis ich von ihnen was anderes höre
         
Vielen dank schon einmal im Voraus

 

Themen zu Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist
4d36e972-e325-11ce-bfc1-08002be10318, ad-aware, branding, browser, e-mail, error, excel, flash player, help, home, homepage, link geöffnet, log-datei, minidump, newtab, ntdll.dll, pup.optional.appgraffiti.a, pup.optional.delta.a, pup.optional.inboxtoolbar.a, pup.optional.installcore.a, pup.optional.rebateinformer.a, pup.optional.wajam.a, refresh, registry, rundll, security, software, svchost.exe, system, trojaner, unlock, vista, windows




Ähnliche Themen: Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist


  1. Windows 10: Fake-Paypal-Mail erhalten und versehentlich Anhang geöffnet …
    Plagegeister aller Art und deren Bekämpfung - 22.08.2015 (8)
  2. Windows 7: vodafone-Rechung Anhang geöffnet Trojaner/Viren
    Log-Analyse und Auswertung - 14.12.2014 (13)
  3. Zwei PDF Rechnung links in emails (vodafone, telekom) geöffnet..
    Log-Analyse und Auswertung - 12.12.2014 (11)
  4. Fake Telekom Rechnung geöffnet
    Log-Analyse und Auswertung - 01.12.2014 (29)
  5. Fake Telekom Rechnung leider downgeloadet und geöffnet
    Plagegeister aller Art und deren Bekämpfung - 28.11.2014 (5)
  6. Telekom Fake-Rechnung: Anhang geöffnet
    Log-Analyse und Auswertung - 17.11.2014 (7)
  7. Telekom Fake Rechnung geöffnet!
    Log-Analyse und Auswertung - 27.07.2014 (19)
  8. Windows 7: Anhang in Fake Telekom-Mail (Rechnung) geöffnet - Trojaner TR/Kryptik.vnyz gefunden
    Log-Analyse und Auswertung - 06.07.2014 (9)
  9. eventuell vodafone fake rechnung geöffnet
    Plagegeister aller Art und deren Bekämpfung - 19.06.2014 (13)
  10. Vodafone Fake-Rechnungs-Mail geöffnet
    Plagegeister aller Art und deren Bekämpfung - 13.06.2014 (13)
  11. Windows Vista: Zip Anhang einer Email von einer falschen Rechnung geöffnet-Angst vor Virus
    Plagegeister aller Art und deren Bekämpfung - 23.01.2014 (5)
  12. Fake Vodafone-Rechnung Link geöffnet
    Plagegeister aller Art und deren Bekämpfung - 21.01.2014 (3)
  13. Win 7: Anhang von Fake Telekom-Rechnung geöffnet. Trojanerinfektion
    Log-Analyse und Auswertung - 19.01.2014 (9)
  14. Anhang von Fake-Rechnung geöffnet
    Plagegeister aller Art und deren Bekämpfung - 17.03.2013 (2)
  15. Anhang von Fake-Rechnung.zip geöffnet - Trojaner und Worms
    Log-Analyse und Auswertung - 15.03.2013 (15)
  16. Fake Vodafone Rechnung PDF geöffnet. Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 20.11.2012 (3)
  17. Gefälschte Vodafone Rechnung geöffnet, bin ich jetzt mit duqu Virus infiziert???
    Plagegeister aller Art und deren Bekämpfung - 13.03.2012 (12)

Zum Thema Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Hallo, Ich habe eine Fake E-Mail von Vodafone bekommen, leider den link geöffnet und die Datei darin auch gestartet, jetzt schlägt mein Antivirus Programm regelmäßig an. Nach kurzer Googlesuche habe - Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist...
Archiv
Du betrachtest: Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.