jahallotach | 19.01.2014 12:19 | Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist Hallo,
Ich habe eine Fake E-Mail von Vodafone bekommen, leider den link geöffnet und die Datei darin auch gestartet, jetzt schlägt mein Antivirus Programm regelmäßig an.
Nach kurzer Googlesuche habe ich herausgefunden, dass dadurch ein Trojaner in mein System gelangen kann, da ich kaum Ahnung davon habe wäre es nett wenn mir einer Helfen könnte und das ganze überprüft.
Mein System ist ein Windows 7 mit SP1
Hier die Geforderten Log Files:
FRST Additions Logfile: Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-01-2014 03
Ran by Landgraf-Vaio at 2014-01-19 10:45:41
Running from C:\Users\Landgraf-Vaio\Downloads
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Lavasoft Ad-Aware (Enabled - Up to date) {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Lavasoft Ad-Aware (Enabled - Up to date) {5BB89C30-6480-BC7C-9F17-199BD76F557A}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Lavasoft Ad-Aware (Disabled) {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
==================== Installed Programs ======================
Ad-Aware Antivirus (x32 Version: 10.5.3.4405 - Lavasoft)
Ad-Aware Security Add-on (x32 Version: 3.4.0.1 - Lavasoft)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (x32 Version: 11.0.06 - Adobe Systems Incorporated)
Alps Pointing-device for VAIO (Version: - ALPS ELECTRIC CO., LTD.)
ATI Catalyst Install Manager (Version: 3.0.769.0 - ATI Technologies, Inc.)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2010.0920.2143.37117 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Czech (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Danish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Dutch (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help English (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Finnish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help French (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help German (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Greek (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Italian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Japanese (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Korean (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Polish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Russian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Spanish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Swedish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Thai (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Turkish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
ccc-core-static (x32 Version: 2010.0920.2143.37117 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2010.0920.2143.37117 - ATI) Hidden
Cultris II (x32 Version: - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (Version: - Microsoft)
DHTML Editing Component (x32 Version: 6.02.0001 - Microsoft Corporation)
Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.)
Elevated Installer (x32 Version: 2.3.18.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (x32 Version: 2.3.18.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 2.3.18.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 2.3.18.0 - Garmin Ltd or its subsidiaries) Hidden
GUILD WARS (x32 Version: - )
Java 7 Update 51 (x32 Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: 2.1.9.8 - Sun Microsystems, Inc.) Hidden
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
Rossmann Fotowelt Software 4.13 (x32 Version: 4.13 - ORWO Net)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version: - Microsoft) Hidden
Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.)
Spybot - Search & Destroy (x32 Version: 2.1.21 - Safer-Networking Ltd.)
StarMoney (x32 Version: 4.0.1.51 - StarFinanz) Hidden
StarMoney 9.0 (x32 Version: 9.0 - Star Finanz GmbH)
TeamSpeak 3 Client (Version: 3.0.13 - TeamSpeak Systems GmbH)
Turbo Lister 2 (x32 Version: 2.00.0000 - eBay Inc.)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition (Version: - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 64-Bit Edition (Version: - Microsoft)
VAIO Care (x32 Version: 6.4.2.11150 - Sony Corporation) Hidden
VAIO Control Center (x32 Version: 4.3.0.05310 - Sony Corporation)
VAIO Gate (x32 Version: 1.0.0.08050 - Sony Corporation)
WIDCOMM Bluetooth Software (Version: 6.3.0.5600 - Broadcom Corporation)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
WinRAR 5.00 (64-Bit) (Version: 5.00.0 - win.rar GmbH)
==================== Restore Points =========================
03-01-2014 15:20:19 Garmin Express
11-01-2014 10:27:41 Geplanter Prüfpunkt
15-01-2014 13:26:27 Installed Java 7 Update 51
16-01-2014 13:07:58 Windows Update
==================== Hosts content: ==========================
2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {011E21C1-096A-4512-ADBB-B6862B20B18D} - System32\Tasks\SONY\SUS-BCF\Level4Daily => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {08799212-6B94-41FE-91A6-2C6896E110C8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {353D0556-A1CF-4BF8-9EB8-E7E80A0B6284} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation)
Task: {53DCCA7C-F53A-4401-925E-AECFB394629A} - System32\Tasks\SONY\VAIO Power Management\VPM Session Change => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {580F0F58-DB00-41E0-B22F-C7A2C5BF6564} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe [2013-06-13] (Lavasoft Limited)
Task: {6216FDBE-2DE3-4C21-9A74-5BC685FAAA5E} - System32\Tasks\SONY\VAIO Power Management\VPM Logon Start => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {64F5C105-EADC-4468-A682-077344B3B594} - System32\Tasks\SONY\SUS-BCF\Level4Month => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {698549F5-2782-442A-9951-1B399C00C311} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {6F63A80D-96F5-421E-B68E-CBF3E84AC01F} - System32\Tasks\{10182459-CFFA-4D5D-BF1E-E97CF00453CF} => Firefox.exe hxxp://ui.skype.com/ui/0/6.7.0.102/de/abandoninstall?source=lightinstaller&page=tsInstall
Task: {9A88A67C-C08A-4CF4-877A-BDEF50AECC22} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-21] (Adobe Systems Incorporated)
Task: {A65840CB-BD79-4E8E-AC05-DBFD3F191FD0} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2009-08-05] (Sony Corporation)
Task: {B32DCDB0-4212-4368-9F65-4A2D3D39CC71} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation)
Task: {D76F951E-1DEC-419E-B965-743B4FF045D9} - System32\Tasks\SONY\VAIO Power Management\VPM Unlock => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {EB0406D4-B9EB-4ACF-90AA-D8BC7D453F6A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-08-24 13:39 - 2010-08-24 13:39 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2013-09-23 16:16 - 2013-09-23 16:16 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\libcef.dll
2013-09-25 14:19 - 2013-05-16 09:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-09-25 14:19 - 2013-05-16 09:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2013-09-25 14:19 - 2013-05-16 09:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2013-09-25 14:19 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2013-09-25 14:19 - 2012-04-03 16:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2013-10-15 11:40 - 2011-01-13 10:44 - 00232800 _____ () C:\Program Files (x86)\StarMoney 9.0\ouservice\PATCHW32.dll
2013-09-25 14:35 - 2013-12-19 14:07 - 00190752 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libBase64.dll
2013-09-25 14:35 - 2013-12-19 14:07 - 00178464 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libMachoUniv.dll
2013-09-23 16:35 - 2013-12-21 17:49 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\Users\Landgraf-Vaio\Documents\Landgraf ___ MB Massivhaus, u_Z_ 549_12RE.eml:OECustomProperty
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service => ""="Ad-Aware Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ad-Aware Service => ""="Ad-Aware Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBAMSvc => ""="Service"
==================== Faulty Device Manager Devices =============
Name: Microsoft-Adapter für Miniports virtueller WiFis
Description: Microsoft-Adapter für Miniports virtueller WiFis
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
Name: Marvell Yukon 88E8059 PCI-E Gigabit Ethernet Controller
Description: Marvell Yukon 88E8059 PCI-E Gigabit Ethernet Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Marvell
Service: yukonw7
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (01/19/2014 10:25:42 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service) (User: )
Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet.
Details:
Der Inhaltsindexkatalog ist fehlerhaft. 0xc0041801 (0xc0041801)
Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service) (User: )
Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=2350} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben.
Details:
Der Inhaltsindexkatalog ist fehlerhaft. 0xc0041801 (0xc0041801)
Error: (01/18/2014 07:52:30 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/18/2014 06:44:32 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/18/2014 04:51:05 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/18/2014 03:34:04 PM) (Source: Application Hang) (User: )
Description: Programm firefox.exe, Version 26.0.0.5087 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1504
Startzeit: 01cf145a3d53c4fd
Endzeit: 14
Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Berichts-ID: 8bf65b7b-804d-11e3-b0de-18f46af81e57
Error: (01/18/2014 03:07:24 PM) (Source: Application Hang) (User: )
Description: Programm firefox.exe, Version 26.0.0.5087 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 91c
Startzeit: 01cf1455e1d904dd
Endzeit: 31
Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Berichts-ID: d8953a08-8049-11e3-b0de-18f46af81e57
Error: (01/18/2014 11:32:14 AM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005
Error: (01/18/2014 10:37:29 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
System errors:
=============
Error: (01/19/2014 10:25:14 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Garmin Core Update Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (01/19/2014 10:25:14 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Garmin Core Update Service erreicht.
Error: (01/18/2014 11:12:50 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
Error: (01/18/2014 06:42:59 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
Error: (01/18/2014 04:51:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Updating Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (01/18/2014 04:51:33 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Updating Service erreicht.
Error: (01/18/2014 04:49:24 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}
Error: (01/18/2014 10:37:18 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Error: (01/18/2014 10:37:18 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.
Error: (01/18/2014 10:36:48 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Garmin Core Update Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1053
Microsoft Office Sessions:
=========================
Error: (01/19/2014 10:25:42 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service)(User: )
Description:
Details:
Der Inhaltsindexkatalog ist fehlerhaft. 0xc0041801 (0xc0041801)
The catalog is corrupt
Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service)(User: )
Description:
Details:
Der Inhaltsindexkatalog ist fehlerhaft. 0xc0041801 (0xc0041801)
2350
Error: (01/18/2014 07:52:30 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/18/2014 06:44:32 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/18/2014 04:51:05 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (01/18/2014 03:34:04 PM) (Source: Application Hang)(User: )
Description: firefox.exe26.0.0.5087150401cf145a3d53c4fd14C:\Program Files (x86)\Mozilla Firefox\firefox.exe8bf65b7b-804d-11e3-b0de-18f46af81e57
Error: (01/18/2014 03:07:24 PM) (Source: Application Hang)(User: )
Description: firefox.exe26.0.0.508791c01cf1455e1d904dd31C:\Program Files (x86)\Mozilla Firefox\firefox.exed8953a08-8049-11e3-b0de-18f46af81e57
Error: (01/18/2014 11:32:14 AM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005
Error: (01/18/2014 10:37:29 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
==================== Memory info ===========================
Percentage of memory in use: 45%
Total physical RAM: 3950.1 MB
Available physical RAM: 2139.82 MB
Total Pagefile: 7898.38 MB
Available Pagefile: 5538.8 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:465.66 GB) (Free:253.21 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 7A7F4430)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)
==================== End Of Log ============================ --- --- --- Code:
defogger_disable by jpshortstuff (23.02.10.1)
Log created at 10:43 on 19/01/2014 (Landgraf-Vaio)
Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.
Checking for services/drivers...
-=E.O.F=-
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-01-2014 03
Ran by Landgraf-Vaio (administrator) on LANDGRAFVAIO on 19-01-2014 10:45:00
Running from C:\Users\Landgraf-Vaio\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Lavasoft) C:\ProgramData\Search Protection\SearchProtection.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [212480 2010-09-15] (Alps Electric Co., Ltd.)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [SBRegRebootCleaner] - C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-09-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554384 2013-07-15] (Lavasoft)
HKLM-x32\...\Run: [Search Protection] - C:\ProgramData\Search Protection\SearchProtection.exe [943016 2013-06-13] (Lavasoft)
HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries)
HKCU\...\Run: [KB01353482.exe] - "C:\Users\Landgraf-Vaio\AppData\Roaming\KB01353482.exe"
HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
Startup: C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id=adawaretb&v=3_4&ent=hp&u=CAAA82C8C61AAA03D18D225242E3D633
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8E2CB2916DB8CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_4&hsimp=yhs-lavasoft&ent=ch&q={searchTerms}
BHO: AppGraffiti - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\PROGRA~2\APPGRA~1\APPGRA~2.DLL No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1
FireFox:
========
FF ProfilePath: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default
FF NewTab: hxxp://www.searchgol.com/?babsrc=NT_ss&mntrId=E8E118F46AF81E57&affID=119357&tsp=5014
FF SearchEngineOrder.1: Ask Search
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\ask-search.xml
FF SearchPlugin: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\inbox-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\adawaretb.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YouTube Unblocker - C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\Extensions\youtubeunblocker@unblocker.yt [2014-01-16]
FF Extension: Ad-Aware Security Add-on - C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} [2013-09-25]
==================== Services (Whitelisted) =================
R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited)
S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation)
R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH)
==================== Drivers (Whitelisted) ====================
S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-09-25] (GFI Software)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-19 10:45 - 2014-01-19 10:45 - 00012572 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt
2014-01-19 10:44 - 2014-01-19 10:44 - 02076160 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe
2014-01-19 10:44 - 2014-01-19 10:44 - 00000000 ____D C:\FRST
2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log
2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable
2014-01-18 22:02 - 2014-01-18 22:52 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx
2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip
2014-01-18 21:42 - 2014-01-18 21:42 - 01077248 _____ (Zhorn Software) C:\Users\Landgraf-Vaio\Downloads\stickies_setup_7.1e.exe
2014-01-18 17:21 - 2014-01-18 17:22 - 00000280 _____ C:\Windows\wininit.ini
2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe
2014-01-18 16:52 - 2014-01-18 16:53 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-18 15:06 - 2014-01-19 10:40 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B
2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-15 14:27 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-15 14:27 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-15 14:27 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-15 14:27 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-15 14:20 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 14:20 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 14:20 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 14:19 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 14:19 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin
2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin
2014-01-03 16:20 - 2014-01-03 16:21 - 00000000 ____D C:\Program Files (x86)\Garmin
2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-21 12:46 - 2013-12-21 12:47 - 00024576 ___SH C:\Users\Landgraf-Vaio\Documents\Thumbs.db
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\webasto
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Vorlagen
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Steuererklärung
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\saeco
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Robert
2013-12-20 17:56 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Rechnungen
2013-12-20 17:55 - 2014-01-03 16:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Robert
2013-12-20 17:55 - 2014-01-03 16:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ICQ
2013-12-20 17:55 - 2014-01-03 16:52 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Anja
2013-12-20 17:54 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Hausbau
2013-12-20 17:54 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\email
2013-12-20 17:53 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ebooks
2013-12-20 17:53 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Auto
2013-12-20 17:52 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Anja
2013-12-20 17:50 - 2013-02-22 20:30 - 00122300 _____ C:\Users\Landgraf-Vaio\Documents\Landgraf ___ MB Massivhaus, u_Z_ 549_12RE.eml
2013-12-20 17:50 - 2012-05-12 23:57 - 341600159 _____ C:\Users\Landgraf-Vaio\Documents\PerAnhalterdurchdieGalaxis_ep7_anjalandgraf.aax
2013-12-20 14:18 - 2013-12-20 15:55 - 00004419 _____ C:\Users\Landgraf-Vaio\Downloads\config Landgraf AP.dat
2013-12-20 13:37 - 2013-12-20 13:37 - 00273904 _____ C:\Windows\Minidump\122013-18782-01.dmp
2013-12-20 13:16 - 2013-12-20 13:17 - 01892006 _____ C:\Users\Landgraf-Vaio\Downloads\CSL.ML.0726_fwc.bin
==================== One Month Modified Files and Folders =======
2014-01-19 10:45 - 2014-01-19 10:45 - 00012572 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt
2014-01-19 10:44 - 2014-01-19 10:44 - 02076160 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe
2014-01-19 10:44 - 2014-01-19 10:44 - 00000000 ____D C:\FRST
2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log
2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable
2014-01-19 10:43 - 2013-09-23 15:58 - 00000000 ____D C:\Users\Landgraf-Vaio
2014-01-19 10:40 - 2014-01-18 15:06 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B
2014-01-19 10:40 - 2013-09-23 15:58 - 00000000 ___RD C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-19 10:35 - 2013-09-23 19:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-19 10:33 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-19 10:33 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-19 10:30 - 2013-09-23 15:47 - 01428122 _____ C:\Windows\WindowsUpdate.log
2014-01-19 10:27 - 2013-09-23 19:18 - 00003978 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{302D991D-8607-4326-8B9F-1E38889BFE91}
2014-01-19 10:25 - 2013-12-01 17:47 - 00000000 ___RD C:\Users\Landgraf-Vaio\Dropbox
2014-01-19 10:25 - 2013-12-01 17:43 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox
2014-01-19 10:24 - 2013-10-29 21:34 - 00013303 _____ C:\Windows\setupact.log
2014-01-19 10:24 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-18 22:52 - 2014-01-18 22:02 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx
2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip
2014-01-18 21:42 - 2014-01-18 21:42 - 01077248 _____ (Zhorn Software) C:\Users\Landgraf-Vaio\Downloads\stickies_setup_7.1e.exe
2014-01-18 18:43 - 2013-10-31 01:14 - 00003290 _____ C:\Windows\PFRO.log
2014-01-18 17:22 - 2014-01-18 17:21 - 00000280 _____ C:\Windows\wininit.ini
2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe
2014-01-18 16:53 - 2014-01-18 16:52 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-18 14:48 - 2013-09-25 16:56 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Windows Live
2014-01-18 10:37 - 2013-09-25 15:09 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0
2014-01-17 08:14 - 2013-10-01 22:53 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Skype
2014-01-16 19:14 - 2013-12-01 17:45 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-16 19:09 - 2009-07-14 05:45 - 00417024 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-16 14:11 - 2013-09-23 18:39 - 00000000 ____D C:\Windows\system32\MRT
2014-01-16 14:08 - 2013-09-23 18:39 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-15 14:27 - 2013-09-29 20:45 - 00000000 ____D C:\ProgramData\Oracle
2014-01-15 14:27 - 2013-09-29 20:44 - 00000000 ____D C:\Program Files (x86)\Java
2014-01-12 17:14 - 2010-11-21 07:50 - 00654166 _____ C:\Windows\system32\perfh007.dat
2014-01-12 17:14 - 2010-11-21 07:50 - 00130006 _____ C:\Windows\system32\perfc007.dat
2014-01-12 17:14 - 2009-07-14 06:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-12 12:12 - 2013-09-25 14:19 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-01-09 13:19 - 2013-09-25 16:05 - 00000000 ____D C:\Windows\System32\Tasks\Games
2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Robert
2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ICQ
2014-01-03 16:52 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Anja
2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin
2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin
2014-01-03 16:21 - 2014-01-03 16:20 - 00000000 ____D C:\Program Files (x86)\Garmin
2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-31 11:44 - 2013-10-23 09:47 - 00326527 _____ C:\test.xml
2013-12-22 13:03 - 2013-09-25 14:24 - 00000000 ____D C:\ProgramData\Search Protection
2013-12-21 23:36 - 2013-10-03 16:50 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Adobe
2013-12-21 23:36 - 2013-09-23 19:17 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-21 23:36 - 2013-09-23 19:17 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-21 23:36 - 2013-09-23 19:17 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-21 23:06 - 2013-09-26 13:28 - 00000000 ____D C:\andere sachen
2013-12-21 17:49 - 2013-09-23 16:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-21 12:47 - 2013-12-21 12:46 - 00024576 ___SH C:\Users\Landgraf-Vaio\Documents\Thumbs.db
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\webasto
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Vorlagen
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Steuererklärung
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\saeco
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Robert
2013-12-20 18:00 - 2013-12-20 17:56 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Rechnungen
2013-12-20 17:55 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Hausbau
2013-12-20 17:54 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\email
2013-12-20 17:54 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ebooks
2013-12-20 17:53 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Auto
2013-12-20 17:53 - 2013-12-20 17:52 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Anja
2013-12-20 15:55 - 2013-12-20 14:18 - 00004419 _____ C:\Users\Landgraf-Vaio\Downloads\config Landgraf AP.dat
2013-12-20 13:37 - 2013-12-20 13:37 - 00273904 _____ C:\Windows\Minidump\122013-18782-01.dmp
2013-12-20 13:37 - 2013-09-25 08:17 - 363185970 _____ C:\Windows\MEMORY.DMP
2013-12-20 13:37 - 2013-09-25 08:17 - 00000000 ____D C:\Windows\Minidump
2013-12-20 13:17 - 2013-12-20 13:16 - 01892006 _____ C:\Users\Landgraf-Vaio\Downloads\CSL.ML.0726_fwc.bin
Some content of TEMP:
====================
C:\Users\Landgraf-Vaio\AppData\Local\Temp\2cd71744-656a-41f5-8e2f-cf7faa63e1ef.exe
C:\Users\Landgraf-Vaio\AppData\Local\Temp\460a2cca-59e0-4d35-90b2-061ce9b8114e.exe
C:\Users\Landgraf-Vaio\AppData\Local\Temp\APNSetup.exe
C:\Users\Landgraf-Vaio\AppData\Local\Temp\exp15A2.tmp.exe
C:\Users\Landgraf-Vaio\AppData\Local\Temp\install_flashplayer11x32au_mssd_aaa_aih.exe
C:\Users\Landgraf-Vaio\AppData\Local\Temp\jre-7u45-windows-i586-iftw.exe
C:\Users\Landgraf-Vaio\AppData\Local\Temp\jre-7u51-windows-i586-iftw.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-01-09 13:12
==================== End Of Log ============================ --- --- --- Code:
GMER Logfile:
Code:
GMER 2.1.19324 - hxxp://www.gmer.net
Rootkit scan 2014-01-19 11:13:23
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST9500325AS rev.0006SDM2 465,76GB
Running: 0pk01sgw.exe; Driver: C:\Users\LANDGR~1\AppData\Local\Temp\fflcqkod.sys
---- Kernel code sections - GMER 2.1 ----
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528 fffff80002db0000 45 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 574 fffff80002db002e 17 bytes [CE, 01, 00, 00, 00, 00, 00, ...]
.text C:\Windows\System32\win32k.sys!W32pServiceTable fffff96000153e00 7 bytes [00, 96, F3, FF, 01, A1, F0]
.text C:\Windows\System32\win32k.sys!W32pServiceTable + 8 fffff96000153e08 3 bytes [C0, 06, 02]
---- User code sections - GMER 2.1 ----
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread 0000000076f40068 5 bytes JMP 00000001009fd480
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000076f5c4dd 5 bytes JMP 00000001009fd450
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!DeleteSecurityContext 0000000074960bb9 5 bytes JMP 00000001009fd9a0
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!EncryptMessage 000000007496124e 5 bytes JMP 00000001009fdb80
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!DecryptMessage 000000007496129d 5 bytes JMP 00000001009fd9c0
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextW 0000000074961557 5 bytes JMP 00000001009fdc00
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextA 0000000074961590 5 bytes JMP 00000001009fdc90
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075c63918 5 bytes JMP 00000001009fd5d0
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075c64406 5 bytes JMP 00000001009fd800
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!recv 0000000075c66b0e 5 bytes JMP 00000001009fd6f0
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!connect 0000000075c66bdd 5 bytes JMP 00000001009fd970
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!send 0000000075c66f01 5 bytes JMP 00000001009fd8c0
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!WSARecv 0000000075c67089 5 bytes JMP 00000001009fd5f0
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69 0000000074a81465 2 bytes [A8, 74]
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155 0000000074a814bb 2 bytes [A8, 74]
.text ... * 2
.text C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\Crypt32.DLL!PFXImportCertStore 0000000075ad18b8 5 bytes JMP 00000001009fe0e0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread 0000000076f40068 5 bytes JMP 00000001001ed480
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000076f5c4dd 5 bytes JMP 00000001001ed450
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!DeleteSecurityContext 0000000074960bb9 5 bytes JMP 00000001001ed9a0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!EncryptMessage 000000007496124e 5 bytes JMP 00000001001edb80
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!DecryptMessage 000000007496129d 5 bytes JMP 00000001001ed9c0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextW 0000000074961557 5 bytes JMP 00000001001edc00
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextA 0000000074961590 5 bytes JMP 00000001001edc90
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\crypt32.dll!PFXImportCertStore 0000000075ad18b8 5 bytes JMP 00000001001ee0e0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075c63918 5 bytes JMP 00000001001ed5d0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075c64406 5 bytes JMP 00000001001ed800
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!recv 0000000075c66b0e 5 bytes JMP 00000001001ed6f0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!connect 0000000075c66bdd 5 bytes JMP 00000001001ed970
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!send 0000000075c66f01 5 bytes JMP 00000001001ed8c0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!WSARecv 0000000075c67089 5 bytes JMP 00000001001ed5f0
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000074a81465 2 bytes [A8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000074a814bb 2 bytes [A8, 74]
.text ... * 2
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[3000] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000074a81465 2 bytes [A8, 74]
.text C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[3000] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 0000000074a814bb 2 bytes [A8, 74]
.text ... * 2
.text C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074a81465 2 bytes [A8, 74]
.text C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074a814bb 2 bytes [A8, 74]
.text ... * 2
.text C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread 0000000076f40068 5 bytes JMP 00000001000ad480
.text C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000076f5c4dd 5 bytes JMP 00000001000ad450
.text C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!DeleteSecurityContext 0000000074960bb9 5 bytes JMP 00000001000ad9a0
.text C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!EncryptMessage 000000007496124e 5 bytes JMP 00000001000adb80
.text C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!DecryptMessage 000000007496129d 5 bytes JMP 00000001000ad9c0
.text C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextW 0000000074961557 5 bytes JMP 00000001000adc00
.text C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextA 0000000074961590 5 bytes JMP 00000001000adc90
.text C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074a81465 2 bytes [A8, 74]
.text C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074a814bb 2 bytes [A8, 74]
.text ... * 2
.text C:\ProgramData\Search Protection\SearchProtection.exe[3080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074a81465 2 bytes [A8, 74]
.text C:\ProgramData\Search Protection\SearchProtection.exe[3080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074a814bb 2 bytes [A8, 74]
.text ... * 2
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread 0000000076f40068 5 bytes JMP 00000001001dd480
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000076f5c4dd 5 bytes JMP 00000001001dd450
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075c63918 5 bytes JMP 00000001001dd5d0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075c64406 5 bytes JMP 00000001001dd800
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!recv 0000000075c66b0e 5 bytes JMP 00000001001dd6f0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!connect 0000000075c66bdd 5 bytes JMP 00000001001dd970
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!send 0000000075c66f01 5 bytes JMP 00000001001dd8c0
.text C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!WSARecv 0000000075c67089 5 bytes JMP 00000001001dd5f0
.text C:\PROGRA~2\AD-AWA~1\AdAware.exe[4444] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074a81465 2 bytes [A8, 74]
.text C:\PROGRA~2\AD-AWA~1\AdAware.exe[4444] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074a814bb 2 bytes [A8, 74]
.text ... * 2
.text C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread 0000000076f40068 5 bytes JMP 000000010011d480
.text C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000076f5c4dd 5 bytes JMP 000000010011d450
.text C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000074a81465 2 bytes [A8, 74]
.text C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 0000000074a814bb 2 bytes [A8, 74]
.text ... * 2
.text C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075c63918 5 bytes JMP 000000010011d5d0
.text C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075c64406 5 bytes JMP 000000010011d800
.text C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!recv 0000000075c66b0e 5 bytes JMP 000000010011d6f0
.text C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!connect 0000000075c66bdd 5 bytes JMP 000000010011d970
.text C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!send 0000000075c66f01 5 bytes JMP 000000010011d8c0
.text C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!WSARecv 0000000075c67089 5 bytes JMP 000000010011d5f0
.text C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread 0000000076f40068 5 bytes JMP 000000010025d480
.text C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000076f5c4dd 5 bytes JMP 000000010025d450
.text C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075c63918 5 bytes JMP 000000010025d5d0
.text C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075c64406 5 bytes JMP 000000010025d800
.text C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!recv 0000000075c66b0e 5 bytes JMP 000000010025d6f0
.text C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!connect 0000000075c66bdd 5 bytes JMP 000000010025d970
.text C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!send 0000000075c66f01 5 bytes JMP 000000010025d8c0
.text C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!WSARecv 0000000075c67089 5 bytes JMP 000000010025d5f0
.text C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread 0000000076f40068 5 bytes JMP 000000010042d480
.text C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll 0000000076f5c4dd 5 bytes JMP 000000010042d450
.text C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!closesocket 0000000075c63918 5 bytes JMP 000000010042d5d0
.text C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!WSASend 0000000075c64406 5 bytes JMP 000000010042d800
.text C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!recv 0000000075c66b0e 5 bytes JMP 000000010042d6f0
.text C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!connect 0000000075c66bdd 5 bytes JMP 000000010042d970
.text C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!send 0000000075c66f01 5 bytes JMP 000000010042d8c0
.text C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!WSARecv 0000000075c67089 5 bytes JMP 000000010042d5f0
---- Threads - GMER 2.1 ----
Thread C:\Windows\SysWOW64\RunDll32.exe [1584:3296] 000000000011b890
Thread C:\Windows\SysWOW64\RunDll32.exe [1584:4428] 0000000000119480
Thread C:\Windows\SysWOW64\RunDll32.exe [1584:4412] 000000000011c920
---- Registry - GMER 2.1 ----
Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\18f46af81e57
Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\18f46af81e57 (not active ControlSet)
---- EOF - GMER 2.1 ---- --- --- --- Code:
leider weiss ich nicht wie ich die Log-Datei vom Ad-Aware-Antivirus-Programm auslesen kann, Sry
es hat 3x Trojan Win32 Generic! BT und einmal Worm.Win32.Critec.ac(v) gefunden, ich lasse diese dinge noch in der Quarantäne bis ich von ihnen was anderes höre
Vielen dank schon einmal im Voraus |