|
Plagegeister aller Art und deren Bekämpfung: Pop-up: Bundesamt für Sicherheit in der Informaionstechnik, evtl Symstembefall!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.01.2014, 17:22 | #1 |
| Pop-up: Bundesamt für Sicherheit in der Informaionstechnik, evtl Symstembefall! Hallo miteinander, heute Vormittag hat sich nach dem Schließen(!) eines Pop-Up Fensters in Firefox, ein weites Fenster geöffnet. Der Inhalt dürfte mittlerweile allzu bekannt sein: "Bundesamt für Sicherheit in der Informationstechnik - Computer gesperrt...". Das Fenster ließ sich auch nach Beenden und erneutem Ausführen von Firefox nicht schließen und es tat sich die Meldung auf, ob man die Seite wirklich verlassen möchte. Erst nach dem Lauf von CCleaner war das Fenster weg. Suchläufe von Avira und AdwCleaner zeigten keine Funde an. Lediglich Malwarebytes zeigte PUP.Optional.Spigot.A an. Ich schätze aber der Fund hängt nicht mit der oben beschriebenen Situation zusammen. Das System (Win 7/32 bit) läuft ansonsten normal (keine verdächtigen Prozesse im Taskmanager, hoch- und runterfahren ist kein problem, etc.). Beim Surfen danach ist mir nichts weiter aufgefallen. Kann ich mir ganz sicher sein, dass mein System nicht befallen ist? Bzw was hat es mit dem Fund unter Malewarebytes auf sich. Anbei die log-files von Malewarebytes, bei Bedarf kann ich die files der anderen Programme noch anhängen. Danke im voraus Gruß pan_der Code:
ATTFilter Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2014.01.22.06 Windows 7 Service Pack 1 x86 NTFS Internet Explorer 10.0.9200.16721 TOSHIBA :: *** [Administrator] 22.01.2014 11:58:23 MBAM-log-2014-01-22 (12-13-14).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 213468 Laufzeit: 11 Minute(n), 29 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\$RECYCLE.BIN\S-1-5-21-660848808-223659081-3074705962-1000\$RKFDZ0Q.exe (PUP.Optional.Spigot.A) -> Keine Aktion durchgeführt. (Ende) |
22.01.2014, 18:47 | #2 |
/// the machine /// TB-Ausbilder | Pop-up: Bundesamt für Sicherheit in der Informaionstechnik, evtl Symstembefall! hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
22.01.2014, 19:53 | #3 |
| Pop-up: Bundesamt für Sicherheit in der Informaionstechnik, evtl Symstembefall! hi,
__________________hier die files. FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 22-01-2014 01 Ran by TOSHIBA (administrator) on *** on 22-01-2014 19:27:55 Running from C:\Users\TOSHIBA\Downloads Microsoft Windows 7 Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) =================== (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (TOSHIBA) C:\Program Files\Toshiba\TOSHIBA Web Camera Application\TWebCameraSrv.exe () C:\Windows\System32\PnkBstrA.exe (TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA DVD PLAYER\TNaviSrv.exe (TOSHIBA Corporation) C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\TECO\TecoService.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE (TOSHIBA Corporation) C:\Program Files\Toshiba\TPHM\TPCHSrv.exe (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPEnh.exe (TOSHIBA Corporation.) C:\Program Files\Toshiba\HDMICtrlMan\HDMICtrlMan.exe (TOSHIBA CORPORATION) C:\Program Files\Toshiba\Utilities\KeNotify.exe (TOSHIBA Corporation) C:\Windows\System32\ThpSrv.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosSENotify.exe (Nullsoft, Inc.) C:\Program Files\Winamp\winampa.exe (Synaptics Incorporated) C:\Program Files\Synaptics\SynTP\SynTPHelper.exe (Adobe Systems Incorporated) C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe (Geek Software GmbH) C:\Program Files\PDF24\pdf24.exe (Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (TOSHIBA Corporation) C:\Program Files\Toshiba\TOSHIBA Service Station\TMachInfo.exe (Microsoft Corporation) C:\Windows\System32\wuauclt.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files\Adobe\Reader 10.0\Reader\AcroRd32.exe () C:\Program Files\gretl\gretl.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe (Opera Software) C:\Program Files\Opera\18.0.1284.68\opera.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe [7625248 2009-07-28] (Realtek Semiconductor) HKLM\...\Run: [SynTPEnh] - C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [1451304 2009-03-20] (Synaptics Incorporated) HKLM\...\Run: [HDMICtrlMan] - C:\Program Files\TOSHIBA\HDMICtrlMan\HDMICtrlMan.exe [811008 2009-04-07] (TOSHIBA Corporation.) HKLM\...\Run: [HWSetup] - C:\Program Files\TOSHIBA\Utilities\HWSetup.exe [421888 2007-04-16] (TOSHIBA Electronics, Inc.) HKLM\...\Run: [KeNotify] - C:\Program Files\TOSHIBA\Utilities\KeNotify.exe [34088 2009-01-13] (TOSHIBA CORPORATION) HKLM\...\Run: [SVPWUTIL] - C:\Program Files\TOSHIBA\Utilities\SVPWUTIL.exe [438272 2008-11-21] (TOSHIBA) HKLM\...\Run: [ThpSrv] - C:\Windows\system32\thpsrv /logon HKLM\...\Run: [ToshibaServiceStation] - C:\Program Files\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe [1295736 2011-02-11] (TOSHIBA Corporation) HKLM\...\Run: [TosSENotify] - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe [1011712 2009-04-23] (TOSHIBA Corporation) HKLM\...\Run: [TRCMan] - C:\Program Files\TOSHIBA\TRCMan\TRCMan.exe HKLM\...\Run: [TWebCamera] - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe [2513472 2009-04-16] (TOSHIBA) HKLM\...\Run: [WinampAgent] - C:\Program Files\Winamp\winampa.exe [37888 2010-01-12] (Nullsoft, Inc.) HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-04-04] (Adobe Systems Incorporated) HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-12] (Avira Operations GmbH & Co. KG) HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.) HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKLM\...\Run: [PDFPrint] - C:\Program Files\PDF24\pdf24.exe [186408 2013-12-12] (Geek Software GmbH) HKCU\...\Run: [] - [x] HKCU\...\Run: [Skype] - C:\Program Files\Skype\Phone\Skype.exe [18642024 2013-02-28] (Skype Technologies S.A.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = https://www.google.de/ HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm URLSearchHook: HKLM - Default Value = {855F3B16-6D32-4fe6-8A56-BBB695989046} SearchScopes: HKLM - DefaultScope value is missing. SearchScopes: HKLM - {A110B866-9FEB-49D5-AA7E-19ABACD600D3} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEG; SearchScopes: HKCU - {A110B866-9FEB-49D5-AA7E-19ABACD600D3} URL = hxxp://www.google.com/search?sourceid=ie7&q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={outputEncoding}&rlz=1I7TSEG_deDE384 BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corporation) DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab DPF: {CAFEEFAC-0017-0000-0006-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_06-windows-i586.cab Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) ShellExecuteHooks: - {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No File [ ] Winsock: Catalog5 09 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 Tcpip\..\Interfaces\{4D8BE774-C10C-40A1-9459-256965FA7FBD}: [NameServer]212.23.115.132 212.23.115.148 Tcpip\..\Interfaces\{535896A9-98D5-4DEC-948D-6A8D2BED7FAE}: [NameServer]212.23.115.132 212.23.115.148 Tcpip\..\Interfaces\{A9551BD9-7567-4399-AAAF-8D2768E1B569}: [NameServer]212.23.115.132 212.23.115.148 FireFox: ======== FF ProfilePath: C:\Users\TOSHIBA\AppData\Roaming\Mozilla\Firefox\Profiles\yxwy7rjj.default-1363438730494 FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF32_11_9_900_170.dll () FF Plugin: @Apple.com/iTunes,version=1.0 - C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin: @google.com/npPicasa2,version=2.0.0 - C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.) FF Plugin: @google.com/npPicasa3,version=3.0.0 - C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.) FF Plugin: @java.com/DTPlugin,version=10.6.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation) FF Plugin: @java.com/JavaPlugin,version=10.6.2 - C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin: @microsoft.com/GENUINE - disabled No File FF Plugin: @nokia.com/EnablerPlugin - C:\Program Files\Nokia\Nokia Suite\npNokiaSuiteEnabler.dll ( ) FF Plugin: @tools.google.com/Google Update;version=3 - C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File FF Plugin: @tools.google.com/Google Update;version=9 - C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll No File FF Plugin: Adobe Reader - C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\nppdf32.dll (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin2.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin3.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin4.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npqtplugin5.dll (Apple Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files\mozilla firefox\plugins\npwachk.dll (Nullsoft, Inc.) FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\amazondotcom-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\eBay-de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\leo_ende_de.xml FF SearchPlugin: C:\Program Files\mozilla firefox\browser\searchplugins\yahoo-de.xml FF Extension: WOT - C:\Users\TOSHIBA\AppData\Roaming\Mozilla\Firefox\Profiles\yxwy7rjj.default-1363438730494\Extensions\{a0d7ccb3-214d-498b-b4aa-0e8fda9a7bf7} [2014-01-14] FF Extension: Ghostery - C:\Users\TOSHIBA\AppData\Roaming\Mozilla\Firefox\Profiles\yxwy7rjj.default-1363438730494\Extensions\firefox@ghostery.com.xpi [2014-01-14] FF Extension: NoScript - C:\Users\TOSHIBA\AppData\Roaming\Mozilla\Firefox\Profiles\yxwy7rjj.default-1363438730494\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-22] FF Extension: Adblock Plus - C:\Users\TOSHIBA\AppData\Roaming\Mozilla\Firefox\Profiles\yxwy7rjj.default-1363438730494\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-14] ========================== Services (Whitelisted) ================= R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-12] (Avira Operations GmbH & Co. KG) R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-11-19] (Avira Operations GmbH & Co. KG) R2 camsvc; C:\Program Files\Toshiba\TOSHIBA Web Camera Application\TWebCameraSrv.exe [20544 2009-04-16] (TOSHIBA) R2 PnkBstrA; C:\Windows\system32\PnkBstrA.exe [76888 2012-02-25] () R3 TMachInfo; C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe [54136 2011-02-11] (TOSHIBA Corporation) R2 TOSHIBA eco Utility Service; C:\Program Files\TOSHIBA\TECO\TecoService.exe [176128 2009-04-24] (TOSHIBA Corporation) R2 TOSHIBA HDD SSD Alert Service; C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe [73728 2009-03-17] (TOSHIBA Corporation) R2 TPCHSrv; C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe [656752 2009-04-15] (TOSHIBA Corporation) S2 gupdate; "C:\Program Files\Google\Update\GoogleUpdate.exe" /svc [x] S3 gupdatem; "C:\Program Files\Google\Update\GoogleUpdate.exe" /medsvc [x] S3 gusvc; "C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe" [x] ==================== Drivers (Whitelisted) ==================== R2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-12] (Avira Operations GmbH & Co. KG) R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-12] (Avira Operations GmbH & Co. KG) R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-19] (Avira Operations GmbH & Co. KG) S3 enecirhid; C:\Windows\System32\DRIVERS\enecirhid.sys [11264 2008-04-29] (ENE TECHNOLOGY INC.) S3 enecirhidma; C:\Windows\System32\DRIVERS\enecirhidma.sys [5632 2008-04-25] (ENE TECHNOLOGY INC.) S3 hamachi; C:\Windows\System32\DRIVERS\hamachi.sys [26176 2009-03-18] (LogMeIn, Inc.) R0 hotcore3; C:\Windows\System32\DRIVERS\hotcore3.sys [40560 2010-01-28] (Paragon Software Group) R3 PGEffect; C:\Windows\System32\DRIVERS\pgeffect.sys [22272 2009-03-18] (TOSHIBA Corporation) R3 RTHDMIAzAudService; C:\Windows\System32\drivers\RtHDMIV.sys [157536 2009-05-20] (Realtek Semiconductor Corp.) R1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-06-02] (Avira GmbH) R2 TVALZFL; C:\Windows\System32\DRIVERS\TVALZFL.sys [12920 2009-03-20] (TOSHIBA Corporation) U5 AppMgmt; C:\Windows\system32\svchost.exe [20992 2009-07-14] (Microsoft Corporation) S3 cmnsusbser; system32\DRIVERS\cmnsusbser.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-22 19:27 - 2014-01-22 19:28 - 00014086 _____ C:\Users\TOSHIBA\Downloads\FRST.txt 2014-01-22 19:27 - 2014-01-22 19:27 - 01221632 _____ (Farbar) C:\Users\TOSHIBA\Downloads\FRST.exe 2014-01-22 19:27 - 2014-01-22 19:27 - 00000000 ____D C:\FRST 2014-01-22 18:40 - 2014-01-22 18:40 - 00001372 _____ C:\Users\TOSHIBA\AppData\Local\recently-used.xbel 2014-01-22 15:47 - 2014-01-22 15:47 - 00027642 _____ C:\Users\TOSHIBA\Desktop\AVSCAN-20140122-130519-3658BB5A.LOG 2014-01-22 11:57 - 2014-01-22 11:57 - 00001032 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-14 17:23 - 2014-01-22 12:19 - 00000000 ____D C:\AdwCleaner 2014-01-14 17:22 - 2014-01-14 17:23 - 01236282 _____ C:\Users\TOSHIBA\Downloads\adwcleaner.exe 2014-01-14 09:57 - 2014-01-14 09:57 - 00000000 ____D C:\Users\TOSHIBA\AppData\Roaming\Opera Software 2014-01-14 09:57 - 2014-01-14 09:57 - 00000000 ____D C:\Users\TOSHIBA\AppData\Local\Opera Software 2014-01-14 09:57 - 2014-01-14 09:57 - 00000000 ____D C:\Program Files\Opera 2014-01-14 09:50 - 2014-01-14 09:52 - 33803296 _____ (Opera Software ASA) C:\Users\TOSHIBA\Downloads\Opera_18.0.1284.68_Setup.exe 2014-01-14 09:48 - 2014-01-14 09:48 - 00000000 ____D C:\Program Files\Mozilla Firefox 2014-01-11 20:49 - 2014-01-22 18:40 - 00000000 ____D C:\Users\TOSHIBA\AppData\Local\gtk-2.0 2014-01-11 20:48 - 2014-01-22 19:04 - 00000000 ____D C:\Users\TOSHIBA\Documents\gretl 2014-01-11 20:48 - 2014-01-22 19:04 - 00000000 ____D C:\Users\TOSHIBA\AppData\Roaming\gretl 2014-01-11 20:48 - 2014-01-11 20:48 - 00000000 ____D C:\Program Files\gretl 2014-01-08 05:36 - 2014-01-08 05:36 - 00000000 ____D C:\Users\TOSHIBA\AppData\Local\PDF24 2014-01-08 05:31 - 2014-01-08 05:31 - 00000000 ____D C:\Program Files\PDF24 2014-01-05 20:10 - 2014-01-12 18:31 - 00000000 ____D C:\Users\TOSHIBA\Desktop\Neuer Ordner 2014-01-05 16:49 - 2014-01-22 19:16 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-04 14:33 - 2014-01-04 14:33 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_netaapl_01009.Wdf 2013-12-28 12:51 - 2013-12-28 12:51 - 00000892 _____ C:\Users\TOSHIBA\Downloads\TRCMan - Verknüpfung.lnk ==================== One Month Modified Files and Folders ======= 2014-01-22 19:28 - 2014-01-22 19:27 - 00014086 _____ C:\Users\TOSHIBA\Downloads\FRST.txt 2014-01-22 19:27 - 2014-01-22 19:27 - 01221632 _____ (Farbar) C:\Users\TOSHIBA\Downloads\FRST.exe 2014-01-22 19:27 - 2014-01-22 19:27 - 00000000 ____D C:\FRST 2014-01-22 19:22 - 2013-07-04 11:00 - 01378776 _____ C:\Windows\WindowsUpdate.log 2014-01-22 19:16 - 2014-01-05 16:49 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2014-01-22 19:05 - 2010-07-18 20:07 - 00001098 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-22 19:04 - 2014-01-11 20:48 - 00000000 ____D C:\Users\TOSHIBA\Documents\gretl 2014-01-22 19:04 - 2014-01-11 20:48 - 00000000 ____D C:\Users\TOSHIBA\AppData\Roaming\gretl 2014-01-22 18:44 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\tracing 2014-01-22 18:40 - 2014-01-22 18:40 - 00001372 _____ C:\Users\TOSHIBA\AppData\Local\recently-used.xbel 2014-01-22 18:40 - 2014-01-11 20:49 - 00000000 ____D C:\Users\TOSHIBA\AppData\Local\gtk-2.0 2014-01-22 15:47 - 2014-01-22 15:47 - 00027642 _____ C:\Users\TOSHIBA\Desktop\AVSCAN-20140122-130519-3658BB5A.LOG 2014-01-22 12:28 - 2010-06-14 18:39 - 00011424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2014-01-22 12:28 - 2010-06-14 18:39 - 00011424 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2014-01-22 12:22 - 2010-11-20 23:10 - 00000000 ____D C:\Users\TOSHIBA\AppData\Roaming\Skype 2014-01-22 12:21 - 2013-11-16 18:33 - 00065536 _____ C:\Windows\system32\Ikeext.etl 2014-01-22 12:21 - 2013-11-04 10:48 - 00379885 _____ C:\Windows\setupact.log 2014-01-22 12:21 - 2010-07-18 20:07 - 00001094 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-22 12:21 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-22 12:20 - 2013-12-07 11:55 - 00001862 _____ C:\Windows\PFRO.log 2014-01-22 12:19 - 2014-01-14 17:23 - 00000000 ____D C:\AdwCleaner 2014-01-22 11:57 - 2014-01-22 11:57 - 00001032 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-22 11:57 - 2012-08-22 22:22 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware 2014-01-17 13:07 - 2013-05-23 20:20 - 00000000 ____D C:\Program Files\VideoLAN 2014-01-14 17:30 - 2010-12-05 15:00 - 00000000 ____D C:\Users\TOSHIBA\Downloads\Installs 2014-01-14 17:27 - 2012-08-27 22:42 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2014-01-14 17:23 - 2014-01-14 17:22 - 01236282 _____ C:\Users\TOSHIBA\Downloads\adwcleaner.exe 2014-01-14 09:57 - 2014-01-14 09:57 - 00000000 ____D C:\Users\TOSHIBA\AppData\Roaming\Opera Software 2014-01-14 09:57 - 2014-01-14 09:57 - 00000000 ____D C:\Users\TOSHIBA\AppData\Local\Opera Software 2014-01-14 09:57 - 2014-01-14 09:57 - 00000000 ____D C:\Program Files\Opera 2014-01-14 09:52 - 2014-01-14 09:50 - 33803296 _____ (Opera Software ASA) C:\Users\TOSHIBA\Downloads\Opera_18.0.1284.68_Setup.exe 2014-01-14 09:50 - 2010-12-05 14:29 - 00000000 ____D C:\Users\TOSHIBA\AppData\Local\Opera 2014-01-14 09:49 - 2010-12-05 14:29 - 00000000 ____D C:\Users\TOSHIBA\AppData\Roaming\Opera 2014-01-14 09:48 - 2014-01-14 09:48 - 00000000 ____D C:\Program Files\Mozilla Firefox 2014-01-13 21:39 - 2010-06-16 22:51 - 00281872 _____ C:\Windows\system32\PnkBstrB.xtr 2014-01-13 21:39 - 2010-06-14 21:44 - 00281872 _____ C:\Windows\system32\PnkBstrB.exe 2014-01-13 21:39 - 2010-06-14 21:44 - 00139280 _____ C:\Windows\system32\Drivers\PnkBstrK.sys 2014-01-13 21:38 - 2010-06-14 21:44 - 00111928 _____ C:\Windows\system32\PnkBstrB.ex0 2014-01-13 16:43 - 2012-12-02 23:08 - 00001505 _____ C:\Users\TOSHIBA\Desktop\TO DO.txt 2014-01-13 15:10 - 2012-10-17 18:27 - 00000000 ____D C:\Users\TOSHIBA\Desktop\UNI 2014-01-13 14:37 - 2010-06-26 19:19 - 00000000 ____D C:\Program Files\Steam 2014-01-12 18:31 - 2014-01-05 20:10 - 00000000 ____D C:\Users\TOSHIBA\Desktop\Neuer Ordner 2014-01-11 20:48 - 2014-01-11 20:48 - 00000000 ____D C:\Program Files\gretl 2014-01-08 05:36 - 2014-01-08 05:36 - 00000000 ____D C:\Users\TOSHIBA\AppData\Local\PDF24 2014-01-08 05:31 - 2014-01-08 05:31 - 00000000 ____D C:\Program Files\PDF24 2014-01-05 17:16 - 2012-08-28 18:32 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe 2014-01-05 17:16 - 2012-08-28 18:32 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl 2014-01-04 14:33 - 2014-01-04 14:33 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_netaapl_01009.Wdf 2013-12-31 13:36 - 2010-06-14 19:03 - 01501000 _____ C:\Windows\system32\PerfStringBackup.INI 2013-12-29 18:11 - 2010-06-26 19:19 - 00000000 ____D C:\Program Files\Common Files\Steam 2013-12-29 17:58 - 2010-06-21 22:59 - 00000000 ____D C:\Users\TOSHIBA\AppData\Local\Microsoft Games 2013-12-28 12:51 - 2013-12-28 12:51 - 00000892 _____ C:\Users\TOSHIBA\Downloads\TRCMan - Verknüpfung.lnk 2013-12-26 14:10 - 2010-12-05 15:03 - 00000000 ____D C:\Users\TOSHIBA\Desktop\Privat Some content of TEMP: ==================== C:\Users\TOSHIBA\AppData\Local\temp\avgnt.exe C:\Users\TOSHIBA\AppData\Local\temp\Quarantine.exe C:\Users\TOSHIBA\AppData\Local\temp\SpotifyUninstall.exe ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-19 14:22 ==================== End Of Log ============================ --- --- --- --- --- --- [/CODE] Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 22-01-2014 01 Ran by TOSHIBA at 2014-01-22 19:28:14 Running from C:\Users\TOSHIBA\Downloads Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Avira Desktop (Enabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C} AS: Avira Desktop (Enabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691} AS: Windows Defender (Enabled - Out of date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Flash Player 11 ActiveX (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Flash Player 11 Plugin (Version: 11.9.900.170 - Adobe Systems Incorporated) Adobe Reader X (10.1.8) - Deutsch (Version: 10.1.8 - Adobe Systems Incorporated) Alien Swarm (Version: - Valve) Any Video Converter 3.2.0 (Version: - Any-Video-Converter.com) APB Reloaded (Version: - ) Apple Application Support (Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (Version: 7.0.0.117 - Apple Inc.) Apple Software Update (Version: 2.1.3.127 - Apple Inc.) ATI Catalyst Install Manager (Version: 3.0.723.0 - ATI Technologies, Inc.) Audacity 1.2.6 (Version: - ) Avira Free Antivirus (Version: 14.0.2.286 - Avira) BioShock (Version: 2.62.0000 - 2K Games) Bluetooth Stack for Windows by Toshiba (Version: v6.40.00(T) - TOSHIBA CORPORATION) Bonjour (Version: 3.0.0.10 - Apple Inc.) Call of Duty(R) - World at War(TM) (Version: 1.0 - Activision) Hidden Call of Duty(R) - World at War(TM) (Version: 1.7 - Activision) Call of Duty(R) - World at War(TM) 1.1 Patch (Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.1 Patch (Version: 1.1 - Activision) Hidden Call of Duty(R) - World at War(TM) 1.2 Patch (Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.2 Patch (Version: 1.2 - Activision) Hidden Call of Duty(R) - World at War(TM) 1.3 Patch (Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.3 Patch (Version: 1.3 - Activision) Hidden Call of Duty(R) - World at War(TM) 1.4 Patch (Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.4 Patch (Version: 1.4 - Activision) Hidden Call of Duty(R) - World at War(TM) 1.5 Patch (Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.5 Patch (Version: 1.5 - Activision) Hidden Call of Duty(R) - World at War(TM) 1.6 Patch (Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.6 Patch (Version: 1.6 - Activision) Hidden Call of Duty(R) - World at War(TM) 1.7 Patch (Version: - ) Hidden Call of Duty(R) - World at War(TM) 1.7 Patch (Version: 1.7 - Activision) Hidden Call of Duty: Black Ops - Multiplayer (Version: - Treyarch) Call of Duty: Black Ops (Version: - Treyarch) Call of Duty: Modern Warfare 2 - Multiplayer (Version: - Infinity Ward) Call of Duty: Modern Warfare 2 (Version: - Infinity Ward) Catalyst Control Center - Branding (Version: 1.00.0000 - ATI) Hidden Catalyst Control Center Core Implementation (Version: 2009.0421.2132.36832 - ATI) Hidden Catalyst Control Center Graphics Full Existing (Version: 2009.0421.2132.36832 - ATI) Hidden Catalyst Control Center Graphics Full New (Version: 2009.0421.2132.36832 - ATI) Hidden Catalyst Control Center Graphics Light (Version: 2009.0421.2132.36832 - ATI) Hidden Catalyst Control Center Graphics Previews Vista (Version: 2009.0421.2132.36832 - ATI) Hidden Catalyst Control Center InstallProxy (Version: 2009.0421.2132.36832 - ATI Technologies, Inc.) Hidden Catalyst Control Center Localization All (Version: 2009.0421.2132.36832 - ATI) Hidden CCC Help Chinese Standard (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Chinese Traditional (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Czech (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Danish (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Dutch (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help English (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Finnish (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help French (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help German (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Greek (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Hungarian (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Italian (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Japanese (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Korean (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Norwegian (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Polish (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Portuguese (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Russian (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Spanish (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Swedish (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Thai (Version: 2009.0421.2131.36832 - ATI) Hidden CCC Help Turkish (Version: 2009.0421.2131.36832 - ATI) Hidden ccc-core-static (Version: 2009.0421.2132.36832 - Ihr Firmenname) Hidden ccc-utility (Version: 2009.0421.2132.36832 - ATI) Hidden CCleaner (Version: 3.22 - Piriform) CDBurnerXP (Version: 4.4.0.2971 - CDBurnerXP) Compatibility Pack für 2007 Office System (Version: 12.0.6514.5001 - Microsoft Corporation) Counter-Strike: Condition Zero (Version: - Valve) Counter-Strike: Source (Version: - Valve) Crysis(R) (Version: 1.00.0000 - Electronic Arts) Dead Space™ (Version: 1.0.222.0 - Electronic Arts) EE-ZDE (Version: - ) Empire Earth (Version: - ) Eufloria - Demo (Version: - ) Fallout 3 (Version: 1.00.0000 - Bethesda Softworks) GameSpy Arcade (Version: - ) GIMP 2.8.4 (Version: 2.8.4 - The GIMP Team) Google Update Helper (Version: 1.3.21.115 - Google Inc.) Hidden Grand Theft Auto IV (Version: 1.0.0011.131 - Rockstar Games Inc.) Hidden Grand Theft Auto IV (Version: 1.0.0013.131 - Rockstar Games Inc.) Hidden Grand Theft Auto IV (Version: 1.00.0000 - Rockstar Games) Grand Theft Auto San Andreas (Version: 1.00.00001 - Rockstar Games) Grand Theft Auto Vice City (Version: 1.00.000 - ) gretl version 1.9.14 (Version: 1.9.14 - The gretl team) GTAIII (Version: - ) Half-Life 2 (Version: - Valve) Half-Life 2: Deathmatch (Version: - Valve) Half-Life 2: Episode One (Version: - Valve) Half-Life 2: Episode Two (Version: - Valve) HDMI Control Manager (Version: 1.9 - TOSHIBA) ICQ7.5 (Version: 7.5 - ICQ) Intel® Matrix Storage Manager (Version: - Intel Corporation) IsoBuster 2.8.5 (Version: 2.8.5 - Smart Projects) iTunes (Version: 11.1.3.8 - Apple Inc.) Java 7 Update 6 (Version: 7.0.60 - Oracle) Java Auto Updater (Version: 2.1.9.0 - Sun Microsystems, Inc.) Hidden LAME v3.98.2 for Audacity (Version: - ) Left 4 Dead 2 (Version: - Valve) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300 - Malwarebytes Corporation) Metal Drift - Demo (Version: - ) Microsoft .NET Framework 1.1 (Version: - ) Microsoft .NET Framework 1.1 (Version: 1.1.4322 - Microsoft) Hidden Microsoft .NET Framework 1.1 German Language Pack (Version: 1.1.4322 - Microsoft) Microsoft Age of Empires II (Version: - ) Microsoft Age of Empires II: The Conquerors Expansion (Version: - ) Microsoft Games for Windows - LIVE Redistributable (Version: 3.5.92.0 - Microsoft Corporation) Microsoft Games for Windows Marketplace (Version: 3.5.50.0 - Microsoft Corporation) Microsoft Office Word Viewer 2003 (Version: 11.0.8173.0 - Microsoft Corporation) Microsoft PowerPoint Viewer (Version: 14.0.4763.1000 - Microsoft Corporation) Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (Version: 8.0.50727.4053 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.56336 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.59193 - Microsoft Corporation) Microsoft Visual C++ 2005 Redistributable (Version: 8.0.61001 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570 (Version: 9.0.30729.5570 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation) Microsoft Visual J# .NET Redistributable Package 1.1 (Version: 1.1.4322 - Microsoft) Microsoft_VC100_CRT_SP1_x86 (Version: 10.0.40219.1 - Nokia) Hidden Mobile Partner (Version: 16.001.06.03.52 - Huawei Technologies Co.,Ltd) Mozilla Firefox 26.0 (x86 de) (Version: 26.0 - Mozilla) Mozilla Maintenance Service (Version: 26.0 - Mozilla) MSVC80_x86_v2 (Version: 1.0.3.0 - Nokia) Hidden MSVC90_x86 (Version: 1.0.1.2 - Nokia) Hidden MSXML 4.0 SP2 (KB941833) (Version: 4.20.9849.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB954430) (Version: 4.20.9870.0 - Microsoft Corporation) MSXML 4.0 SP2 (KB973688) (Version: 4.20.9876.0 - Microsoft Corporation) Nokia Connectivity Cable Driver (Version: 7.1.92.0 - Nokia) Nokia Suite (Version: 3.6.36.0 - Nokia) Nokia Suite (Version: 3.6.36.0 - Nokia) Hidden Notepad++ (Version: 5.8.6 - ) NVIDIA PhysX (Version: 9.10.0512 - NVIDIA Corporation) OpenOffice 4.0.1 (Version: 4.01.9714 - Apache Software Foundation) Opera Stable 18.0.1284.68 (Version: 18.0.1284.68 - Opera Software ASA) Paragon Backup & Recovery™ 10 Free Edition (Version: 90.00.0003 - Paragon Software) PC Connectivity Solution (Version: 12.0.48.0 - Nokia) PDF24 Creator 6.2.0 (Version: - PDF24.org) PDFCreator (Version: 1.3.2 - Frank Heindörfer, Philip Chinery) Picasa 3 (Version: 3.8 - Google, Inc.) PlayReady PC runtime (Version: 1 - Microsoft Corporation) Portal (Version: - Valve) Project64 1.6 (Version: 1.6 - Project64) PunkBuster Services (Version: 0.993 - Even Balance, Inc.) QuickTime (Version: 7.74.80.86 - Apple Inc.) Realtek 8136 8168 8169 Ethernet Driver (Version: 1.00.0004 - Realtek) Realtek High Definition Audio Driver (Version: 6.0.1.5904 - Realtek Semiconductor Corp.) Skins (Version: 2009.0421.2132.36832 - ATI) Hidden Skype™ 6.3 (Version: 6.3.105 - Skype Technologies S.A.) Steam (Version: 1.0.0.0 - Valve Corporation) Streamripper (Remove only) (Version: - ) Stronghold Crusader Extreme (Version: 1.20.0000 - Firefly Studios) SUPER © +Recorder.2013.55 (Mar 7, 2013) Version +Recorder.2013. (Version: +Recorder.2013.55 - eRightSoft) Synaptics Pointing Device Driver (Version: 12.2.11.0 - Synaptics Incorporated) Team Fortress 2 (Version: - Valve) TOSHIBA Assist (Version: 2.01.10 - TOSHIBA) TOSHIBA Benutzerhandbücher (Version: 7.40 - TOSHIBA) TOSHIBA DVD PLAYER (Version: 3.00.1.04-A - TOSHIBA Corporation) TOSHIBA eco Utility (Version: 1.0.3.0 - TOSHIBA Corporation) TOSHIBA eco Utility (Version: 1.0.3.0 - TOSHIBA Corporation) Hidden TOSHIBA Extended Tiles for Windows Mobility Center (Version: 1.01.00 - Toshiba) TOSHIBA Extended Tiles for Windows Mobility Center (Version: 1.01.00 - Toshiba) Hidden TOSHIBA Face Recognition (Version: 3.0.5.32 - TOSHIBA Corporation) TOSHIBA Face Recognition (Version: 3.0.5.32 - TOSHIBA Corporation) Hidden TOSHIBA Flash Cards Support Utility (Version: 1.63.0.3C - TOSHIBA CORPORATION) TOSHIBA Flash Cards Support Utility (Version: 1.63.0.3C - TOSHIBA CORPORATION) Hidden TOSHIBA Hardware Setup (Version: 1.63.0.6C - TOSHIBA CORPORATION) TOSHIBA Hardware Setup (Version: 1.63.0.6C - TOSHIBA CORPORATION) Hidden TOSHIBA HDD Protection (Version: 2.2.0.1 - TOSHIBA Corporation) TOSHIBA HDD/SSD Alert (Version: 3.0.0.1 - TOSHIBA Corporation) TOSHIBA HDD/SSD Alert (Version: 3.0.0.1 - TOSHIBA Corporation) Hidden Toshiba Online Product Information (Version: 2.06.0000 - TOSHIBA) TOSHIBA PC Health Monitor (Version: 1.3.2.0 - TOSHIBA Corporation) TOSHIBA Recovery Disc Creator (Version: 2.0.0.2 - TOSHIBA) TOSHIBA Recovery Disk Creator Reminder (Version: 1.00.0017 - TOSHIBA) TOSHIBA Recovery Disk Creator Reminder (Version: 1.00.0017 - TOSHIBA) Hidden TOSHIBA Remote Control Manager (Version: 2.5.0.0 - TOSHIBA) TOSHIBA SD Memory Utilities (Version: 1.8.1.6 - TOSHIBA) TOSHIBA Service Station (Version: 2.2.9 - TOSHIBA) TOSHIBA Supervisor Password (Version: 1.63.0.3C - TOSHIBA CORPORATION) Hidden TOSHIBA Supervisorkennwort (Version: 1.63.0.3C - TOSHIBA CORPORATION) TOSHIBA USB Sleep and Charge Utility (Version: 1.2.1.0 - TOSHIBA Corporation) TOSHIBA Value Added Package (Version: 1.2.8 - TOSHIBA Corporation) TOSHIBA Value Added Package (Version: 1.2.8 - TOSHIBA Corporation) Hidden TOSHIBA Web Camera Application (Version: 1.0.1.8 - TOSHIBA Corporation) TRORDCLauncher (Version: 1.0.0.6 - TOSHIBA) TRORDCLauncher (Version: 1.0.0.6 - TOSHIBA) Hidden Utility Common Driver (Version: 1.0.50.22C - TOSHIBA) Hidden VirtualDJ Home FREE (Version: 7.0.4 - Atomix Productions) Winamp (Version: 5.572 - Nullsoft, Inc) Winamp Anwendungserkennung (HKCU Version: 1.0.0.1 - Nullsoft, Inc) Windows Live ID Sign-in Assistant (Version: 6.500.3165.0 - Microsoft Corporation) Windows-Treiberpaket - Nokia pccsmcfd “LegacyDriver” (05/31/2012 7.1.2.0) (Version: 05/31/2012 7.1.2.0 - Nokia) WinRAR (Version: - ) WinZip 14.5 (Version: 14.5.9095 - WinZip Computing, S.L. ) ==================== Restore Points ========================= 16-01-2014 14:42:37 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2006-11-02 11:23 - 2012-08-22 21:42 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: {0D1FC177-A004-4BE2-8CD9-F1D32198CDCB} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe Task: {11694A52-BBB8-4241-AA19-34963C723630} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe Task: {1CC81347-6204-4B83-900C-01E02F50F067} - System32\Tasks\Microsoft\Windows\MobilePC\TMM Task: {3587B403-046C-4E8D-8A9D-264B92405192} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2012-08-22] (Piriform Ltd) Task: {561375CB-FF5A-417B-B297-BA73DE149581} - System32\Tasks\Microsoft\Windows\Wired\GatherWiredInfo => C:\Windows\system32\gatherWiredInfo.vbs Task: {7512A71D-AB3F-4F56-84CE-15FC6DD33145} - System32\Tasks\{B10BD201-E7C3-47B7-9564-DDEBD4D344E0} => C:\Program Files\Skype\\Phone\Skype.exe [2013-02-28] (Skype Technologies S.A.) Task: {7C93706E-046D-4F1B-93BB-881CE0B4126E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-05] (Adobe Systems Incorporated) Task: {B21E30F2-427B-4E2B-8B1C-6F964D0E00CC} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.) Task: {E5150B95-F9B4-4D5D-95A2-7EC1ACBA95F8} - System32\Tasks\Microsoft\Windows\Wireless\GatherWirelessInfo => C:\Windows\system32\gatherWirelessInfo.vbs Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2010-06-24 21:45 - 2010-02-10 17:10 - 00141824 _____ () C:\Program Files\WinRAR\rarext.dll 2010-11-08 16:15 - 2010-11-08 16:15 - 00296448 _____ () C:\Program Files\Notepad++\NppShell_04.dll 2009-01-30 21:11 - 2009-01-30 21:11 - 00073728 _____ () C:\Program Files\Toshiba\TOSHIBA HDD SSD Alert\TosIPCWraper.dll 2011-09-27 07:23 - 2011-09-27 07:23 - 00087912 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll 2011-09-27 07:22 - 2011-09-27 07:22 - 01242472 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll 2011-04-05 00:44 - 2013-10-27 12:10 - 09489408 _____ () C:\Users\TOSHIBA\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_rdlang32.deu 2013-09-03 14:53 - 2013-09-03 14:53 - 00305520 _____ () C:\Program Files\Adobe\Reader 10.0\Reader\sqlite.dll 2011-05-04 17:58 - 2013-10-27 12:12 - 00014336 _____ () C:\Users\TOSHIBA\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_Updater.DEU 2011-04-05 00:44 - 2013-10-27 12:11 - 03065856 _____ () C:\Users\TOSHIBA\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_Annots.DEU 2011-07-14 19:43 - 2013-10-28 17:21 - 00012800 _____ () C:\Users\TOSHIBA\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_PDDom.DEU 2011-05-12 20:17 - 2013-10-27 12:11 - 00100352 _____ () C:\Users\TOSHIBA\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_EScript.DEU 2011-07-14 19:42 - 2013-10-27 12:13 - 00045568 _____ () C:\Users\TOSHIBA\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_weblink.DEU 2011-05-12 20:17 - 2013-10-27 12:11 - 01180160 _____ () C:\Users\TOSHIBA\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_PPKLite.DEU 2011-05-12 20:17 - 2013-10-27 12:11 - 01319424 _____ () C:\Users\TOSHIBA\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_AcroForm.DEU 2011-05-12 20:17 - 2013-10-27 12:11 - 00316416 _____ () C:\Users\TOSHIBA\AppData\Local\Adobe\Acrobat\10.0\Cache\RdLang_DigSig.DEU 2014-01-11 20:48 - 2013-11-21 18:14 - 01832960 _____ () C:\Program Files\gretl\libgretl.dll 2014-01-11 20:48 - 2013-11-19 09:37 - 00060416 _____ () C:\Program Files\gretl\libprob.dll 2014-01-11 20:48 - 2012-01-25 17:01 - 00268174 _____ () C:\Program Files\gretl\libblas-3.dll 2014-01-11 20:48 - 2012-06-14 16:36 - 00340354 _____ () C:\Program Files\gretl\libcurl-4.dll 2014-01-11 20:48 - 2010-08-20 09:18 - 00100352 _____ () C:\Program Files\gretl\zlib1.dll 2014-01-11 20:48 - 2007-09-07 00:37 - 00854528 _____ () C:\Program Files\gretl\libfftw3-3.dll 2014-01-11 20:48 - 2009-05-02 18:12 - 00228864 _____ () C:\Program Files\gretl\libgmp-3.dll 2014-01-11 20:48 - 2012-01-25 17:02 - 01586850 _____ () C:\Program Files\gretl\liblapack-3.dll 2014-01-11 20:48 - 2004-05-02 09:43 - 00014710 _____ () C:\Program Files\gretl\mingwm10.dll 2014-01-11 20:48 - 2013-04-18 13:24 - 01081566 _____ () C:\Program Files\gretl\libxml2-2.dll 2014-01-11 20:48 - 2013-05-05 17:23 - 01278141 _____ () C:\Program Files\gretl\libcairo-2.dll 2014-01-11 20:48 - 2010-08-17 14:38 - 00230529 _____ () C:\Program Files\gretl\libpng14-14.dll 2014-01-11 20:48 - 2013-04-14 16:18 - 00039347 _____ () C:\Program Files\gretl\libffi-6.dll 2014-01-11 20:48 - 2013-04-18 14:45 - 00557198 _____ () C:\Program Files\gretl\libgtksourceview-2.0-0.dll 2014-01-11 20:48 - 2013-07-01 17:01 - 00100310 _____ () C:\Program Files\gretl\lib\gtk-2.0\2.10.0\engines\libwimp.dll 2014-01-14 09:57 - 2013-12-12 10:16 - 00886624 _____ () C:\Program Files\Opera\18.0.1284.68\libglesv2.dll 2014-01-14 09:57 - 2013-12-12 10:16 - 00108896 _____ () C:\Program Files\Opera\18.0.1284.68\libegl.dll 2014-01-14 09:57 - 2013-12-12 10:16 - 00879968 _____ () C:\Program Files\Opera\18.0.1284.68\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= AlternateDataStreams: C:\ProgramData\TEMP:A8ADE5D8 AlternateDataStreams: C:\ProgramData\TEMP:DFC5A2B2 ==================== Safe Mode (whitelisted) =================== ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Application errors: ================== Error: (01/22/2014 00:56:21 PM) (Source: Application Error) (User: ) Description: Name der fehlerhaften Anwendung: opera.exe, Version: 18.0.1284.68, Zeitstempel: 0x52a9118e Name des fehlerhaften Moduls: opera.exe, Version: 18.0.1284.68, Zeitstempel: 0x52a9118e Ausnahmecode: 0xc0000005 Fehleroffset: 0x00beb1d2 ID des fehlerhaften Prozesses: 0x9d0 Startzeit der fehlerhaften Anwendung: 0xopera.exe0 Pfad der fehlerhaften Anwendung: opera.exe1 Pfad des fehlerhaften Moduls: opera.exe2 Berichtskennung: opera.exe3 Error: (01/22/2014 00:22:47 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/22/2014 08:55:15 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/21/2014 09:11:40 PM) (Source: SideBySide) (User: ) Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"1". Die abhängige Assemblierung "Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"" konnte nicht gefunden werden. Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe". Error: (01/21/2014 09:30:57 AM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/20/2014 00:32:27 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2014 03:19:22 PM) (Source: WinMgmt) (User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2014 03:19:10 PM) (Source: Windows Search Service) (User: ) Description: Der Index kann nicht initialisiert werden. Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (01/18/2014 03:19:10 PM) (Source: Windows Search Service) (User: ) Description: Die Anwendung kann nicht initialisiert werden. Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (01/18/2014 03:19:10 PM) (Source: Windows Search Service) (User: ) Description: Das Gatherer-Objekt kann nicht initialisiert werden. Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) System errors: ============= Error: (01/22/2014 00:23:47 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Google Update Service (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/22/2014 00:22:51 PM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (01/22/2014 00:21:07 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (01/22/2014 00:21:07 PM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (01/22/2014 08:56:11 AM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Google Update Service (gupdate)" wurde aufgrund folgenden Fehlers nicht gestartet: %%2 Error: (01/22/2014 08:55:20 AM) (Source: DCOM) (User: NT-AUTORITÄT) Description: AnwendungsspezifischLokalStart{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT-AUTORITÄTSYSTEMS-1-5-18LocalHost (unter Verwendung von LRPC) Error: (01/22/2014 08:53:30 AM) (Source: atikmdag) (User: ) Description: Display is not active Error: (01/22/2014 08:53:30 AM) (Source: atikmdag) (User: ) Description: CPLIB :: General - Invalid Parameter Error: (01/21/2014 08:03:05 PM) (Source: atikmdag) (User: ) Description: Display is not active Error: (01/21/2014 02:30:32 PM) (Source: atikmdag) (User: ) Description: Display is not active Microsoft Office Sessions: ========================= Error: (01/22/2014 00:56:21 PM) (Source: Application Error)(User: ) Description: opera.exe18.0.1284.6852a9118eopera.exe18.0.1284.6852a9118ec000000500beb1d29d001cf1768f4df4de5C:\Program Files\Opera\18.0.1284.68\opera.exeC:\Program Files\Opera\18.0.1284.68\opera.exe3530d165-835c-11e3-b698-002622301121 Error: (01/22/2014 00:22:47 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/22/2014 08:55:15 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/21/2014 09:11:40 PM) (Source: SideBySide)(User: ) Description: Microsoft.VC80.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="8.0.50608.0"c:\program files\Toshiba\toshiba usb sleep and charge utility\SetupProp64.exe Error: (01/21/2014 09:30:57 AM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/20/2014 00:32:27 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2014 03:19:22 PM) (Source: WinMgmt)(User: ) Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003 Error: (01/18/2014 03:19:10 PM) (Source: Windows Search Service)(User: ) Description: Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (01/18/2014 03:19:10 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) Error: (01/18/2014 03:19:10 PM) (Source: Windows Search Service)(User: ) Description: Kontext: Windows Anwendung, SystemIndex Katalog Details: Der Inhaltsindexkatalog ist fehlerhaft. (HRESULT : 0xc0041801) (0xc0041801) ==================== Memory info =========================== Percentage of memory in use: 56% Total physical RAM: 3036.87 MB Available physical RAM: 1311.14 MB Total Pagefile: 6072.02 MB Available Pagefile: 3921.52 MB Total Virtual: 2047.88 MB Available Virtual: 1870.76 MB ==================== Drives ================================ Drive c: (Vista) (Fixed) (Total:232.42 GB) (Free:19.99 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive e: (Data) (Fixed) (Total:231.87 GB) (Free:136.61 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 1077BD84) Partition 1: (Not Active) - (Size=1 GB) - (Type=27) Partition 2: (Active) - (Size=232 GB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=232 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
23.01.2014, 16:23 | #4 |
/// the machine /// TB-Ausbilder | Pop-up: Bundesamt für Sicherheit in der Informaionstechnik, evtl Symstembefall! Alles gut
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.01.2014, 16:56 | #5 |
| Pop-up: Bundesamt für Sicherheit in der Informaionstechnik, evtl Symstembefall! Das ist eine gute Nachricht Vielen Dank für die Hilfe! |
24.01.2014, 09:47 | #6 |
/// the machine /// TB-Ausbilder | Pop-up: Bundesamt für Sicherheit in der Informaionstechnik, evtl Symstembefall! Gern Geschehen
__________________ --> Pop-up: Bundesamt für Sicherheit in der Informaionstechnik, evtl Symstembefall! |
Themen zu Pop-up: Bundesamt für Sicherheit in der Informaionstechnik, evtl Symstembefall! |
administrator, anti-malware, autostart, avira, beenden, ccleaner, code, computer, dateien, explorer, firefox, hängt, malwarebytes, problem, programme, prozesse, runterfahren, schließen, seite, sicherheit, speicher, surfen, system, taskmanager, win |