TrojanZbot in ccsetupXXX.exe und Trojan.Generic kommt immer wieder Liebe Experten,
als ich vor einiger Zeit dummerweise einmal einen falschen Download-Button gedrückt habe, habe ich mir eine Infektion eingefangen, die sich offenbar immer wieder selbst reproduziert. Es hätte mir auffallen müssen, weil ich sonst auf solche Dateiendungen sehr sorgfältig achte, ist aber durchgerutscht. Asche auf mein Haupt. Die Datei hieß "tools_v6.1.0.zip.exe". Seitdem funktioniert die Windows Sidebar nicht mehr, und ich habe Trojaner an Bord. Um Euch die Arbeit zu erleichtern, habe ich einige log-Dateien schon erstellt:
FRST.txt: Code:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 22-02-2015
Ran by Chef (administrator) on VOLKER-PC on 22-02-2015 20:39:37
Running from I:\Volker\FRST
Loaded Profiles: Chef & Volker_2 (Available profiles: Ute & Chef & Volker_2 & UpdatusUser & Administrator)
Platform: Windows Vista (TM) Home Premium Service Pack 2 (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 9 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(NVIDIA Corporation) C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlx64.exe
(Microsoft Corporation) C:\Windows\System32\SLsvc.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvxdsync.exe
(NVIDIA Corporation) C:\Windows\System32\nvvsvc.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Foxit Software Inc.) C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\AvkBap64.exe
(G Data Software AG) C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\GdBgInx64.exe
(G Data Software AG) C:\Program Files (x86)\Common Files\G Data\AVKProxy\GDKBFltExe32.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MSASCui.exe
(Microsoft Corporation) C:\Windows\ehome\ehtray.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\ehome\ehmsas.exe
(NVIDIA Corporation) C:\Program Files\NVIDIA Corporation\Display\nvtray.exe
(Microsoft Corporation) C:\Windows\SysWOW64\dllhost.exe
(Microsoft Corporation) C:\Windows\splwow64.exe
(Microsoft Corporation) C:\Windows\System32\conime.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [Windows Defender] => C:\Program Files\Windows Defender\MSASCui.exe [1584184 2008-01-21] (Microsoft Corporation)
HKLM-x32\...\Run: [APSDaemon] => C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [60712 2014-10-11] (Apple Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [157480 2014-10-15] (Apple Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] => C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [508800 2014-12-17] (Oracle Corporation)
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,C:\Program Files (x86)\G Data\AntiVirus\AVKTray\AVKTray.exe,
HKU\S-1-5-19\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-20\...\Run: [WindowsWelcomeCenter] => rundll32.exe oobefldr.dll,ShowWelcomeCenter
HKU\S-1-5-21-110913018-406267621-3491769041-1004\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-12-31] (Garmin Ltd or its subsidiaries)
HKU\S-1-5-21-110913018-406267621-3491769041-1004\...\MountPoints2: {11c5cd71-6e20-11e2-b959-806e6f6e6963} - X:\EASINST.EXE
HKU\S-1-5-21-110913018-406267621-3491769041-1006\...\Run: [ehTray.exe] => C:\Windows\ehome\ehTray.exe [138240 2008-01-21] (Microsoft Corporation)
HKU\S-1-5-21-110913018-406267621-3491769041-1006\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\QTTask.exe [421888 2014-01-17] (Apple Inc.)
HKU\S-1-5-21-110913018-406267621-3491769041-1006\...\MountPoints2: {11c5cd71-6e20-11e2-b959-806e6f6e6963} - X:\EASINST.EXE
HKU\S-1-5-18\...\Run: [GarminExpressTrayApp] => C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [688984 2014-12-31] (Garmin Ltd or its subsidiaries)
Startup: I:\Chef\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\tools v6.1.0.zip.lnk
ShortcutTarget: tools v6.1.0.zip.lnk -> C:\ProgramData\{8d1f463d-88c4-dbf6-8d1f-f463d88c18f6}\tools v6.1.0.zip.exe (No File)
CHR HKLM\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.google.com
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Page_URL =
HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://www.google.com
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Default_Search_URL =
HKU\S-1-5-21-110913018-406267621-3491769041-1004\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
HKU\S-1-5-21-110913018-406267621-3491769041-1004\Software\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.systea.com
HKU\S-1-5-21-110913018-406267621-3491769041-1004\Software\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.systea.com
HKU\S-1-5-21-110913018-406267621-3491769041-1006\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
SearchScopes: HKU\.DEFAULT -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-19 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-20 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
SearchScopes: HKU\S-1-5-21-110913018-406267621-3491769041-1006 -> DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL =
BHO: uNNisales -> {6818c48f-6355-4917-9fe9-98b8ebb118bb} -> C:\Program Files (x86)\uNNisales\1jHFRr0XDLkU3Z.x64.dll No File
BHO: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
BHO: youtubeadblocker -> {e1e67519-a594-4953-8583-b63ab7570ed9} -> C:\Program Files (x86)\youtubeadblocker\zkgtuNJy7Rdibh.x64.dll No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\jp2ssv.dll (Oracle Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.178.1
FireFox:
========
FF ProfilePath: I:\Chef\AppData\Roaming\Mozilla\Firefox\Profiles\ckjilcvh.default
FF Homepage: about:blank
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_16_0_0_235.dll ()
FF Plugin: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_16_0_0_235.dll ()
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/vnd.fdf -> C:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll (Foxit Corporation)
FF Plugin-x32: @java.com/DTPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.31.2 -> C:\Program Files (x86)\Java\jre1.8.0_31\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/WPF,version=3.5 -> c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF Plugin-x32: @nvidia.com/3DVision -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF Plugin-x32: @nvidia.com/3DVisionStreaming -> C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF Plugin-x32: @videolan.org/vlc,version=2.1.3 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: @videolan.org/vlc,version=2.1.5 -> C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF HKLM-x32\...\Firefox\Extensions: [{20a82645-c095-46ed-80e3-08825760534b}] - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension
FF Extension: Microsoft .NET Framework Assistant - C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\DotNetAssistantExtension [2013-02-03]
Chrome:
=======
CHR dev: Chrome dev build detected! <======= ATTENTION
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVKProxy; C:\Program Files (x86)\Common Files\G Data\AVKProxy\AVKProxy.exe [2250360 2014-10-14] (G Data Software AG)
R2 AVKService; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKService.exe [914552 2013-12-19] (G Data Software AG)
R2 AVKWCtl; C:\Program Files (x86)\G Data\AntiVirus\AVK\AVKWCtlX64.exe [2683760 2014-05-20] (G Data Software AG)
R2 FoxitCloudUpdateService; C:\Program Files (x86)\Foxit Software\Foxit Reader\Foxit Cloud\FCUpdateService.exe [244448 2014-10-28] (Foxit Software Inc.)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [451416 2014-12-31] (Garmin Ltd or its subsidiaries)
R3 GDScan; C:\Program Files (x86)\Common Files\G Data\GDScan\GDScan.exe [700536 2014-05-20] (G Data Software AG)
S3 Samsung UPD Service2; C:\Windows\System32\SUPDSvc2.exe [158208 2012-04-06] (Samsung Electronics) [File not signed]
R2 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [383544 2008-01-21] (Microsoft Corporation)
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)
S3 AIDA64Driver; C:\Program Files (x86)\FinalWire\AIDA64 Extreme Edition\kerneld.x64 [31576 2013-03-26] ()
R2 DgiVecp; C:\Windows\system32\Drivers\DgiVecp.sys [53816 2009-03-26] (Samsung Electronics Co., Ltd.)
R0 GDBehave; C:\Windows\System32\drivers\GDBehave.sys [55808 2014-08-13] (G Data Software AG)
R1 GDKBFlt; C:\Windows\system32\drivers\GDKBFlt64.sys [20992 2014-11-01] (G Data Software AG)
R1 GDMnIcpt; C:\Windows\system32\drivers\MiniIcpt.sys [142336 2014-08-13] (G Data Software AG)
R3 GDPkIcpt; C:\Windows\system32\drivers\PktIcpt.sys [64000 2014-07-06] (G Data Software AG)
R1 gdwfpcd; C:\Windows\System32\drivers\gdwfpcd64.sys [64512 2015-02-12] (G Data Software AG)
R1 GRD; C:\Windows\system32\drivers\GRD.sys [106272 2014-11-22] (G Data Software)
R1 HookCentre; C:\Windows\system32\drivers\HookCentre.sys [61440 2014-07-06] (G Data Software AG)
S3 IpInIp; system32\DRIVERS\ipinip.sys [X]
S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [X]
S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)
==================== One Month Created Files and Folders ========
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-22 20:38 - 2015-02-22 20:39 - 00000000 ____D () I:\Volker\FRST
2015-02-22 20:17 - 2015-02-22 20:39 - 00000000 ____D () C:\FRST
2015-02-16 22:16 - 2015-02-16 22:16 - 00000000 ____D () I:\Public\Foxit Software
2015-02-16 22:11 - 2015-02-16 22:12 - 53078632 _____ (Foxit Software Inc. ) I:\Chef\Downloads\FoxitReader708.1216_prom_L10N_Setup.exe
2015-02-16 22:02 - 2015-02-16 22:03 - 93427112 _____ (Oracle Corporation) I:\Chef\Downloads\jre-8u31-windows-x64.exe
2015-02-16 22:02 - 2015-02-16 22:02 - 30431144 _____ (Oracle Corporation) I:\Chef\Downloads\jre-8u31-windows-i586.exe
2015-02-16 21:52 - 2015-01-23 05:07 - 02339840 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2015-02-16 21:52 - 2015-01-23 04:59 - 00816640 _____ (Microsoft Corporation) C:\Windows\system32\jscript.dll
2015-02-16 21:52 - 2015-01-23 04:00 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2015-02-16 21:52 - 2015-01-23 03:51 - 00717824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2015-02-12 23:19 - 2014-12-08 02:59 - 00306176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\scesrv.dll
2015-02-12 23:19 - 2014-12-08 02:37 - 00399360 _____ (Microsoft Corporation) C:\Windows\system32\scesrv.dll
2015-02-12 23:18 - 2015-01-09 01:34 - 02790912 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2015-02-12 23:18 - 2014-11-26 03:05 - 00564224 _____ (Microsoft Corporation) C:\Windows\SysWOW64\oleaut32.dll
2015-02-12 23:18 - 2014-11-26 02:42 - 00847360 _____ (Microsoft Corporation) C:\Windows\system32\oleaut32.dll
2015-02-12 23:08 - 2015-01-13 02:51 - 01209856 _____ (Microsoft Corporation) C:\Windows\system32\WindowsCodecs.dll
2015-02-12 23:08 - 2015-01-13 02:39 - 00974848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2015-02-12 23:07 - 2015-01-15 07:53 - 00077312 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2015-02-12 23:07 - 2015-01-15 05:08 - 00516536 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\ksecdd.sys
2015-02-12 22:47 - 2015-02-12 22:47 - 02112512 _____ () I:\Chef\Downloads\adwcleaner_4.110.exe
2015-02-12 20:23 - 2015-01-14 04:08 - 17878016 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2015-02-12 20:23 - 2015-01-14 03:59 - 10924032 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2015-02-12 20:23 - 2015-01-14 03:59 - 00448512 _____ (Microsoft Corporation) C:\Windows\system32\html.iec
2015-02-12 20:23 - 2015-01-14 03:49 - 01392128 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2015-02-12 20:23 - 2015-01-14 03:49 - 01388032 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2015-02-12 20:23 - 2015-01-14 03:47 - 01494016 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2015-02-12 20:23 - 2015-01-14 03:47 - 00599040 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2015-02-12 20:23 - 2015-01-14 03:47 - 00237056 _____ (Microsoft Corporation) C:\Windows\system32\url.dll
2015-02-12 20:23 - 2015-01-14 03:47 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2015-02-12 20:23 - 2015-01-14 03:46 - 00729088 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2015-02-12 20:23 - 2015-01-14 03:46 - 00173056 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2015-02-12 20:23 - 2015-01-14 03:45 - 02157056 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2015-02-12 20:23 - 2015-01-14 03:45 - 00453120 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2015-02-12 20:23 - 2015-01-14 03:45 - 00282112 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2015-02-12 20:23 - 2015-01-14 03:44 - 02382848 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2015-02-12 20:23 - 2015-01-14 03:44 - 00248320 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2015-02-12 20:23 - 2015-01-14 03:44 - 00096768 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2015-02-12 20:23 - 2015-01-14 03:44 - 00055296 _____ (Microsoft Corporation) C:\Windows\system32\msfeedsbs.dll
2015-02-12 20:23 - 2015-01-14 03:44 - 00012800 _____ (Microsoft Corporation) C:\Windows\system32\mshta.exe
2015-02-12 20:23 - 2015-01-14 03:44 - 00011264 _____ (Microsoft Corporation) C:\Windows\system32\msfeedssync.exe
2015-02-12 20:23 - 2015-01-14 02:51 - 12371456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2015-02-12 20:23 - 2015-01-14 02:49 - 00367104 _____ (Microsoft Corporation) C:\Windows\SysWOW64\html.iec
2015-02-12 20:23 - 2015-01-14 02:46 - 09742336 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2015-02-12 20:23 - 2015-01-14 02:43 - 01139712 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2015-02-12 20:23 - 2015-01-14 02:42 - 01427968 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2015-02-12 20:23 - 2015-01-14 02:42 - 01129472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2015-02-12 20:23 - 2015-01-14 02:41 - 01802752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2015-02-12 20:23 - 2015-01-14 02:41 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2015-02-12 20:23 - 2015-01-14 02:41 - 00421376 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2015-02-12 20:23 - 2015-01-14 02:41 - 00231936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\url.dll
2015-02-12 20:23 - 2015-01-14 02:41 - 00142848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2015-02-12 20:23 - 2015-01-14 02:41 - 00065024 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2015-02-12 20:23 - 2015-01-14 02:40 - 02382848 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2015-02-12 20:23 - 2015-01-14 02:40 - 00353792 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2015-02-12 20:23 - 2015-01-14 02:40 - 00223232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2015-02-12 20:23 - 2015-01-14 02:40 - 00176640 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2015-02-12 20:23 - 2015-01-14 02:40 - 00073216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2015-02-12 20:23 - 2015-01-14 02:40 - 00041472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedsbs.dll
2015-02-12 20:23 - 2015-01-14 02:40 - 00011776 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshta.exe
2015-02-12 20:23 - 2015-01-14 02:40 - 00010752 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeedssync.exe
2015-02-08 19:04 - 2015-02-08 19:04 - 03044736 _____ (Enigma Software Group USA, LLC.) I:\Volker\Downloads\SpyHunter-Installer.exe
2015-02-08 18:51 - 2015-02-08 18:51 - 00000234 _____ () I:\Volker\Documents\G DATA Protokoll ID 1280.txt
2015-01-28 23:07 - 2015-01-28 23:07 - 00000000 ____D () I:\Volker\EPUBDRMRemoval
2015-01-28 23:07 - 2015-01-28 23:07 - 00000000 ____D () I:\Volker\AppData\Roaming\EPUBDRMRemoval
2015-01-28 23:07 - 2015-01-28 23:07 - 00000000 ____D () I:\Volker\AppData\Roaming\.EPUBDRMRemoval
2015-01-28 23:04 - 2015-01-28 23:07 - 00000000 ____D () I:\Chef\AppData\Roaming\.EPUBDRMRemoval
2015-01-28 23:04 - 2015-01-28 23:04 - 00000000 ____D () I:\Chef\EPUBDRMRemoval
2015-01-28 23:04 - 2015-01-28 23:04 - 00000000 ____D () I:\Chef\EPUBDRMRemoval
2015-01-28 23:04 - 2015-01-28 23:04 - 00000000 ____D () I:\Chef\AppData\Roaming\EPUBDRMRemoval
2015-01-28 23:03 - 2015-01-28 23:03 - 00000893 _____ () I:\Public\Desktop\Epubor EPUB DRM Removal.lnk
2015-01-28 23:02 - 2015-01-28 23:03 - 17203268 _____ (Epubor Inc.) I:\Volker\Downloads\epub_drm_removal.exe
2015-01-28 22:51 - 2015-01-28 22:52 - 00000000 ____D () I:\Volker\Downloads\skinny
2015-01-28 21:45 - 2015-01-28 22:58 - 00000000 ____D () I:\Volker\AppData\Roaming\.Ultimate
2015-01-28 21:45 - 2015-01-28 21:45 - 00000000 ____D () I:\Volker\Ultimate
2015-01-28 21:45 - 2015-01-28 21:45 - 00000000 ____D () I:\Volker\AppData\Roaming\Ultimate
2015-01-28 21:45 - 2015-01-28 21:45 - 00000000 ____D () I:\Volker\AppData\Roaming\.Epubor
2015-01-28 21:43 - 2015-01-28 21:43 - 00000000 ____D () I:\Chef\AppData\Roaming\calibre
2015-01-28 21:41 - 2015-01-28 21:44 - 00000000 ____D () I:\Chef\AppData\Roaming\.Ultimate
2015-01-28 21:41 - 2015-01-28 21:41 - 00000000 ____D () I:\Chef\Ultimate
2015-01-28 21:41 - 2015-01-28 21:41 - 00000000 ____D () I:\Chef\Ultimate
2015-01-28 21:41 - 2015-01-28 21:41 - 00000000 ____D () I:\Chef\AppData\Roaming\Ultimate
2015-01-28 21:41 - 2015-01-28 21:41 - 00000000 ____D () I:\Chef\AppData\Roaming\.Epubor
2015-01-28 21:40 - 2015-01-28 23:03 - 00000000 ____D () C:\Program Files (x86)\Epubor
2015-01-28 21:40 - 2015-01-28 21:40 - 00000863 _____ () I:\Public\Desktop\Epubor Ultimate.lnk
2015-01-28 21:36 - 2015-01-28 21:39 - 56219040 _____ (Epubor Inc.) I:\Volker\Downloads\epubor_ultimate.exe
2015-01-28 21:26 - 2015-01-28 21:26 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2015-01-28 20:58 - 2015-01-28 20:59 - 00000123 _____ () I:\Volker\Documents\Sidebar Fehler.txt
2015-01-27 22:24 - 2015-01-27 22:24 - 00000000 ____D () I:\Volker\Documents\Harper, Bob; Critser, Greg
2015-01-25 18:07 - 2014-10-12 17:51 - 00000512 ____H () I:\Volker\Desktop\NIKON001.DSC
2015-01-25 15:41 - 2015-01-25 15:41 - 00000000 ____D () I:\Volker\AppData\Roaming\IrfanView
2015-01-25 15:38 - 2015-01-25 15:38 - 10741384 _____ (Irfan Skiljan) I:\Volker\Downloads\irfanview_plugins_438_setup.exe
2015-01-25 15:27 - 2015-01-25 15:33 - 00000000 ____D () C:\Program Files (x86)\IrfanView
2015-01-25 15:27 - 2015-01-25 15:27 - 00000000 ____D () I:\Chef\AppData\Roaming\IrfanView
2015-01-25 15:26 - 2015-01-25 15:26 - 01898640 _____ (Irfan Skiljan) I:\Volker\Downloads\iview438_setup.exe
2015-01-25 14:55 - 2015-02-12 21:21 - 00000000 ____D () I:\Volker\Documents\Druckertest
2015-01-25 13:40 - 2015-01-25 13:40 - 00000000 ____D () I:\Volker\Downloads\Sidebar_neu_initialisieren
2015-01-25 13:39 - 2015-01-25 13:39 - 00000246 _____ () I:\Volker\Downloads\Sidebar_neu_initialisieren.zip
2015-01-25 13:37 - 2015-01-25 13:37 - 00000265 _____ () I:\Volker\Downloads\Sidebar_neu_registrieren.zip
2015-01-25 13:37 - 2015-01-25 13:37 - 00000000 ____D () I:\Volker\Downloads\Sidebar_neu_registrieren
2015-01-23 00:29 - 2015-01-23 00:11 - 00568617 _____ () I:\Volker\Documents\Der Schatten des Wolfes_ Wie ich eine heimtuckische Krankheit besiegte (German Edition) - Elstner, Kerstin.epub
==================== One Month Modified Files and Folders =======
(If an entry is included in the fixlist, the file\folder will be moved.)
2015-02-22 19:46 - 2008-01-21 12:10 - 01566088 _____ () C:\Windows\system32\PerfStringBackup.INI
2015-02-22 19:46 - 2008-01-21 12:09 - 00673684 _____ () C:\Windows\system32\perfh007.dat
2015-02-22 19:46 - 2008-01-21 12:09 - 00145696 _____ () C:\Windows\system32\perfc007.dat
2015-02-22 19:44 - 2014-09-28 22:10 - 00000000 ____D () I:\Volker\AppData\Local\CrashDumps
2015-02-22 19:44 - 2008-01-21 02:53 - 01181456 _____ () C:\Windows\WindowsUpdate.log
2015-02-22 19:40 - 2006-11-02 16:42 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2015-02-22 19:40 - 2006-11-02 16:22 - 00004112 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
2015-02-22 19:40 - 2006-11-02 16:22 - 00004112 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
2015-02-22 16:13 - 2006-11-02 16:42 - 00032582 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2015-02-22 16:12 - 2014-09-02 08:41 - 00000000 ____D () I:\Ute\AppData\Local\CrashDumps
2015-02-22 15:39 - 2013-02-03 23:53 - 00000000 __SHD () I:\$RECYCLE.BIN\S-1-5-21-110913018-406267621-3491769041-1003
2015-02-22 13:15 - 2014-03-30 12:49 - 00003556 _____ () C:\Windows\System32\Tasks\GarminUpdaterTask
2015-02-22 13:15 - 2013-04-26 10:23 - 00000000 ____D () C:\Program Files (x86)\Garmin
2015-02-22 13:02 - 2008-01-21 04:26 - 00435340 _____ () C:\Windows\PFRO.log
2015-02-22 12:31 - 2012-09-16 16:59 - 00000000 ____D () I:\Volker\Documents\Kontoauszüge Mastercard
2015-02-16 22:07 - 2014-08-17 16:11 - 00111016 _____ (Oracle Corporation) C:\Windows\system32\WindowsAccessBridge-64.dll
2015-02-16 22:07 - 2013-02-03 23:36 - 00000000 ____D () C:\Program Files\Java
2015-02-16 22:04 - 2014-08-17 16:12 - 00098216 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2015-02-16 22:04 - 2013-03-27 19:40 - 00000000 ____D () C:\Program Files (x86)\Java
2015-02-16 22:00 - 2015-01-18 16:08 - 00000000 ____D () I:\Chef\AppData\Local\CrashDumps
2015-02-16 21:40 - 2006-11-02 16:21 - 00436832 _____ () C:\Windows\system32\FNTCACHE.DAT
2015-02-12 23:24 - 2014-04-13 12:49 - 00001733 _____ () I:\Public\Desktop\G DATA ANTIVIRUS.lnk
2015-02-12 23:24 - 2013-02-03 18:38 - 00064512 _____ (G Data Software AG) C:\Windows\system32\Drivers\gdwfpcd64.sys
2015-02-12 23:23 - 2014-04-13 12:48 - 00014590 _____ () C:\Windows\DPINST.LOG
2015-02-12 23:13 - 2014-02-16 19:50 - 01541544 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2015-02-12 23:07 - 2013-08-21 20:27 - 00000000 ____D () C:\Windows\system32\MRT
2015-02-12 23:04 - 2006-11-02 13:35 - 116773704 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2015-02-08 17:55 - 2007-12-16 20:51 - 00000175 _____ () I:\Volker\Desktop\Sidebar_neu_registrieren.bat
2015-02-08 17:54 - 2007-12-16 20:50 - 00000088 _____ () I:\Volker\Desktop\Sidebar_neu_initialisieren.bat
2015-02-08 17:53 - 2012-06-12 22:28 - 00000000 ____D () I:\Volker\Documents\Kontoauszüge Co-Bank
2015-02-01 19:16 - 2006-11-02 16:27 - 00118712 _____ () C:\Windows\setupact.log
2015-01-29 21:57 - 2013-02-03 18:32 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2015-01-28 23:28 - 2015-01-18 15:29 - 00000000 ____D () I:\Volker\Documents\Calibre-Bibliothek
2015-01-28 23:18 - 2013-02-06 21:03 - 00000000 __SHD () I:\$RECYCLE.BIN\S-1-5-21-110913018-406267621-3491769041-1006
2015-01-28 21:25 - 2014-11-23 19:41 - 00000000 ____D () I:\Volker\hob_jportal
2015-01-27 22:21 - 2015-01-18 15:29 - 00000000 ____D () I:\Volker\AppData\Roaming\calibre
2015-01-25 15:00 - 2013-10-03 18:00 - 00011373 _____ () I:\Volker\AppData\Roaming\SmarThruOptions.xml
==================== Files in the root of some directories =======
2014-06-08 19:54 - 2014-06-08 19:54 - 0000068 _____ () I:\Chef\AppData\Roaming\Camdata.ini
2014-06-08 19:54 - 2014-06-08 19:54 - 0000408 _____ () I:\Chef\AppData\Roaming\CamLayout.ini
2014-06-08 19:54 - 2014-06-08 19:54 - 0000408 _____ () I:\Chef\AppData\Roaming\CamShapes.ini
2014-06-08 19:54 - 2014-06-08 19:54 - 0004568 _____ () I:\Chef\AppData\Roaming\CamStudio.cfg
2014-05-10 11:29 - 2014-05-10 11:29 - 0000031 _____ () I:\Chef\AppData\Roaming\DATAMATEC.INI
2013-10-03 17:59 - 2014-08-31 21:09 - 0011339 _____ () I:\Chef\AppData\Roaming\SmarThruOptions.xml
2014-06-08 19:28 - 2014-06-08 19:28 - 0000096 _____ () I:\Chef\AppData\Roaming\version2.xml
2013-02-24 15:25 - 2013-02-24 15:25 - 0000680 _____ () I:\Chef\AppData\Local\d3d9caps.dat
2013-02-24 15:20 - 2013-03-03 13:00 - 0001460 _____ () I:\Chef\AppData\Local\d3d9caps64.dat
Files to move or delete:
====================
I:\Ute\temp.dat
Some content of TEMP:
====================
I:\Chef\AppData\Local\Temp\Foxit Reader Updater.exe
I:\Chef\AppData\Local\Temp\Foxit Updater.exe
I:\Chef\AppData\Local\Temp\FoxitUpdater.exe
I:\Chef\AppData\Local\Temp\install_flashplayer15x32_mssd_aaa_aih.exe
I:\Chef\AppData\Local\Temp\nvStInst.exe
I:\Chef\AppData\Local\Temp\Quarantine.exe
I:\Chef\AppData\Local\Temp\sdanircmdc.exe
I:\Chef\AppData\Local\Temp\sdapskill.exe
I:\Chef\AppData\Local\Temp\sdaspwn.exe
I:\Chef\AppData\Local\Temp\sqlite3.dll
I:\Chef\AppData\Local\Temp\tilgung_i.exe
I:\Chef\AppData\Local\Temp\vlc-2.1.5-win32.exe
I:\Ute\AppData\Local\Temp\03E00FBD.dll
I:\Ute\AppData\Local\Temp\03E13109.dll
I:\Ute\AppData\Local\Temp\03E1C4B6.dll
I:\Ute\AppData\Local\Temp\5F86505F.dll
I:\Ute\AppData\Local\Temp\5F869319.dll
I:\Ute\AppData\Local\Temp\CB7D2D1E.dll
I:\Ute\AppData\Local\Temp\CB7FDF8E.dll
I:\Ute\AppData\Local\Temp\CB802C3D.dll
I:\Ute\AppData\Local\Temp\CB812058.dll
I:\Ute\AppData\Local\Temp\CB864630.dll
I:\Ute\AppData\Local\Temp\CB898723.dll
I:\Ute\AppData\Local\Temp\CB97C013.dll
I:\Ute\AppData\Local\Temp\CB992369.dll
I:\Ute\AppData\Local\Temp\CB998C23.dll
I:\Ute\AppData\Local\Temp\E4C5976A.dll
I:\Ute\AppData\Local\Temp\E4DC6B0C.dll
I:\Ute\AppData\Local\Temp\F73A1EF0.dll
I:\Ute\AppData\Local\Temp\F74671A1.dll
I:\Ute\AppData\Local\Temp\Foxit Reader Updater.exe
I:\Ute\AppData\Local\Temp\Foxit Updater.exe
I:\Volker\AppData\Local\Temp\Foxit Reader Updater.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-02-22 19:46
==================== End Of Log ============================ FRST Addition.txt Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 22-02-2015
Ran by Chef at 2015-02-22 20:40:16
Running from I:\Volker\FRST
Boot Mode: Normal
==========================================================
==================== Security Center ========================
(If an entry is included in the fixlist, it will be removed.)
AV: G DATA ANTIVIRUS (Enabled - Up to date) {545C8713-0744-B079-87F8-349A6D5C8CF0}
AS: G DATA ANTIVIRUS (Enabled - Up to date) {EF3D66F7-217E-BFF7-BD48-0FE816DBC64D}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)
7-Zip 9.20 (x64 edition) (HKLM\...\{23170F69-40C1-2702-0920-000001000000}) (Version: 9.20.00.0 - Igor Pavlov)
Adobe Flash Player 16 NPAPI (HKLM-x32\...\Adobe Flash Player NPAPI) (Version: 16.0.0.235 - Adobe Systems Incorporated)
AIDA64 Extreme Edition v2.85 (HKLM-x32\...\AIDA64 Extreme Edition_is1) (Version: 2.85 - FinalWire Ltd.)
Amazon Kindle (HKLM-x32\...\Amazon Kindle) (Version: - Amazon)
ANT Drivers Installer x64 (Version: 2.3.4 - Garmin Ltd or its subsidiaries) Hidden
Apple Application Support (HKLM-x32\...\{83CAF0DE-8D3B-4C37-A631-2B8F16EC3031}) (Version: 3.1 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{BDD99690-3541-4619-9D2A-3CDDB3E15F9E}) (Version: 8.0.5.6 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
calibre 64bit (HKLM\...\{31ED17F1-B223-404B-9415-C31404A24CE9}) (Version: 2.16.0 - Kovid Goyal)
Camtasia Studio 8 (HKLM-x32\...\{C4E35316-77F1-4EBD-9785-C72E55B1D219}) (Version: 8.4.2.1768 - TechSmith Corporation)
DH Driver Cleaner Professional Edition (HKLM-x32\...\Driver Cleaner Pro) (Version: Version 1.5 - Ruud Ketelaars)
EAS-Laufzeitmodul (HKLM-x32\...\{D3103768-A8FB-11D4-ACDF-00104B58121A}) (Version: 1.0.0.0 - Krämer & Kröll GmbH)
Elevated Installer (x32 Version: 3.2.27.0 - Garmin Ltd or its subsidiaries) Hidden
Epubor EPUB DRM Removal (HKLM-x32\...\Epubor EPUB DRM Removal) (Version: 2.0.9.12 - Epubor Inc.)
Epubor Ultimate (HKLM-x32\...\Epubor Ultimate) (Version: 3.0.4.18 - Epubor Inc.)
Foxit Cloud (HKLM-x32\...\{41914D8B-9D6E-4764-A1F9-BC43FB6782C1}_is1) (Version: 2.3.25.1124 - Foxit Software Inc.)
Foxit Reader (HKLM-x32\...\Foxit Reader_is1) (Version: 7.0.8.1216 - Foxit Software Inc.)
G DATA ANTIVIRUS (HKLM-x32\...\{B9FC0A7D-FA1D-4347-ABED-AD8AD5305633}) (Version: 25.0.2.5 - G DATA Software AG)
Garmin Express (HKLM-x32\...\{855d8086-4275-4bd3-a7a8-b44da3a56d7a}) (Version: 3.2.27.0 - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: 3.2.27.0 - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: 3.2.27.0 - Garmin Ltd or its subsidiaries) Hidden
IrfanView (remove only) (HKLM-x32\...\IrfanView) (Version: 4.38 - Irfan Skiljan)
iTunes (HKLM\...\{2ABBBD91-91E5-4AD7-929A-FE15D1DC0576}) (Version: 12.0.1.26 - Apple Inc.)
Java 8 Update 25 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418025F0}) (Version: 8.0.250 - Oracle Corporation)
Java 8 Update 25 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218025F0}) (Version: 8.0.250 - Oracle Corporation)
Java 8 Update 31 (64-bit) (HKLM\...\{26A24AE4-039D-4CA4-87B4-2F86418031F0}) (Version: 8.0.310 - Oracle Corporation)
Java 8 Update 31 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218031F0}) (Version: 8.0.310 - Oracle Corporation)
Kindle Packages (HKU\S-1-5-21-110913018-406267621-3491769041-1004\...\Kindle Packages) (Version: - ) <==== ATTENTION
LibreOffice 4.2 Help Pack (German) (HKLM-x32\...\{2EC623B7-3559-4058-B4AC-14DC018FC0B7}) (Version: 4.2.6.3 - The Document Foundation)
LibreOffice 4.2.6.3 (HKLM-x32\...\{14DB1822-00B5-4820-86B5-EF893CA46B53}) (Version: 4.2.6.3 - The Document Foundation)
Microsoft .NET Framework 3.5 Language Pack SP1 - DEU (HKLM\...\Microsoft .NET Framework 3.5 Language Pack SP1 - deu) (Version: - Microsoft Corporation)
Microsoft .NET Framework 3.5 SP1 (HKLM\...\Microsoft .NET Framework 3.5 SP1) (Version: - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Deutsch) (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1031) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.2 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.51209 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (HKLM-x32\...\{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 (HKLM\...\{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Visual C++ 2013 Redistributable (x86) - 12.0.21005 (HKLM-x32\...\{ce085a78-074e-4823-8dc1-8a721b94b76d}) (Version: 12.0.21005.1 - Microsoft Corporation)
Mozilla Firefox 35.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 35.0.1 (x86 de)) (Version: 35.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 31.2.0 - Mozilla)
Mozilla Thunderbird 31.4.0 (x86 de) (HKLM-x32\...\Mozilla Thunderbird 31.4.0 (x86 de)) (Version: 31.4.0 - Mozilla)
MSXML 4.0 SP2 (KB927978) (HKLM-x32\...\{37477865-A3F1-4772-AD43-AAFC6BCFF99F}) (Version: 4.20.9841.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
NVIDIA 3D Vision Controller-Treiber 306.97 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB) (Version: 306.97 - NVIDIA Corporation)
NVIDIA 3D Vision Treiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision) (Version: 311.06 - NVIDIA Corporation)
NVIDIA Grafiktreiber 311.06 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 311.06 - NVIDIA Corporation)
NVIDIA PhysX-Systemsoftware 9.12.0604 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.12.0604 - NVIDIA Corporation)
NVIDIA Update 1.11.3 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update) (Version: 1.11.3 - NVIDIA Corporation)
PDF Split And Merge Basic (HKLM-x32\...\{9A40D2F8-9458-458B-95E3-B57797C574E1}) (Version: 2.2.4 - Andrea Vacondio)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Readiris Pro 10 (HKLM-x32\...\{14D08502-FEE4-40E5-90D3-8A967A1D8BA2}) (Version: - )
Samsung Universal Print Driver (HKLM-x32\...\Samsung Universal Print Driver) (Version: 2.03.09.00 - Samsung Electronics Co., Ltd.)
Samsung Universal Scan Driver (HKLM-x32\...\Samsung Universal Scan Driver) (Version: 1.2.6.0 - Samsung Electronics Co., Ltd.)
SmarThru 4 (HKLM-x32\...\{90F1943D-EA4A-4460-B59F-30023F3BA69A}) (Version: - )
SmarThru PC Fax (HKLM-x32\...\SmarThru PC Fax) (Version: - )
Thommi's BauFi Rechner 1.4 (HKLM-x32\...\Thommi's BauFi Rechner) (Version: 1.4 - ThomasBolz.de)
VLC media player (HKLM-x32\...\VLC media player) (Version: 2.1.5 - VideoLAN)
Windows-Treiberpaket - Dynastream Innovations, Inc. ANT LibUSB Drivers (04/11/2012 1.2.40.201) (HKLM\...\F9D2A789F9CFF8CEC36B544F53877C80F1F73C46) (Version: 04/11/2012 1.2.40.201 - Dynastream Innovations, Inc.)
Windows-Treiberpaket - Silicon Labs Software (DSI_SiUSBXp_3_1) USB (02/06/2007 3.1) (HKLM\...\D1506E0025B5A3F9EB8270FE81C1EEDD9388B8A2) (Version: 02/06/2007 3.1 - Silicon Labs Software)
==================== Custom CLSID (selected items): ==========================
(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)
CustomCLSID: HKU\S-1-5-21-110913018-406267621-3491769041-1004_Classes\CLSID\{F28C2F70-47DE-4EA5-8F6D-7D1476CD1EF5}\localserver32 -> I:\Chef\AppData\Local\Temp\c6A84764\temp\tools v6.1.0.zip.exe No File
==================== Restore Points =========================
22-02-2015 13:14:04 Garmin Express
22-02-2015 13:16:06 Garmin Express
22-02-2015 13:17:07 Windows Update
==================== Hosts content: ==========================
(If needed Hosts: directive could be included in the fixlist to reset Hosts.)
2006-11-02 13:34 - 2006-09-18 22:37 - 00000761 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1 localhost
::1 localhost
==================== Scheduled Tasks (whitelisted) =============
(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)
Task: {127CD5D8-6C6D-4412-94F3-580D3DC929DE} - System32\Tasks\GarminUpdaterTask => C:\Program Files (x86)\Garmin\Express Self Updater\ExpressSelfUpdater.exe [2014-12-31] ()
Task: {9222CA07-CA45-4C28-BE13-F235F1A4C87A} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
==================== Loaded Modules (whitelisted) ==============
2013-10-03 17:58 - 2009-05-08 10:53 - 00082432 _____ () C:\Windows\System32\SamFaxPort64.dll
2013-02-03 23:32 - 2011-04-11 06:26 - 00034304 _____ () C:\Windows\System32\spd__l.dll
2013-02-03 23:32 - 2012-09-10 16:07 - 01212928 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\spd__du.dll
2014-05-20 02:38 - 2014-05-20 02:38 - 00340088 ____N () C:\Program Files (x86)\Common Files\G Data\AVKProxy\PktIcpt2x64.dll
2011-01-27 14:28 - 2011-01-27 14:28 - 00706048 _____ () C:\Windows\system32\SnMinDrv.dll
2014-02-12 20:58 - 2014-02-12 20:58 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-10-11 13:05 - 2014-10-11 13:05 - 01044776 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
==================== Alternate Data Streams (whitelisted) =========
(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)
==================== Safe Mode (whitelisted) ===================
(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)
==================== EXE Association (whitelisted) ===============
(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)
==================== Other Areas ============================
(Currently there is no automatic fix for this section.)
HKU\S-1-5-21-110913018-406267621-3491769041-1004\Control Panel\Desktop\\Wallpaper -> C:\windows\Web\Wallpaper\img24.jpg
HKU\S-1-5-21-110913018-406267621-3491769041-1006\Control Panel\Desktop\\Wallpaper -> C:\Windows\Web\Wallpaper\img22.jpg
DNS Servers: 192.168.178.1
==================== MSCONFIG/TASK MANAGER disabled items ==
(Currently there is no automatic fix for this section.)
==================== Accounts: =============================
Administrator (S-1-5-21-110913018-406267621-3491769041-500 - Administrator - Disabled) => I:\Administrator
Chef (S-1-5-21-110913018-406267621-3491769041-1004 - Administrator - Enabled) => I:\Chef
Gast (S-1-5-21-110913018-406267621-3491769041-501 - Limited - Disabled)
UpdatusUser (S-1-5-21-110913018-406267621-3491769041-1007 - Limited - Enabled) => I:\UpdatusUser
Ute (S-1-5-21-110913018-406267621-3491769041-1003 - Limited - Enabled) => I:\Ute
Volker_2 (S-1-5-21-110913018-406267621-3491769041-1006 - Limited - Enabled) => I:\Volker
==================== Faulty Device Manager Devices =============
Name: Atheros AR5005G Wireless Network Adapter
Description: Atheros AR5005G Wireless Network Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Atheros Communications Inc.
Service: athr
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (02/22/2015 07:42:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung sidebar.exe, Version 6.0.6002.18005, Zeitstempel 0x49e035b8, fehlerhaftes Modul OLEAUT32.dll, Version 6.0.6002.19243, Zeitstempel 0x5475302c, Ausnahmecode 0xc0000005, Fehleroffset 0x0000000000001149,
Prozess-ID 0xed0, Anwendungsstartzeit sidebar.exe0.
Error: (02/22/2015 07:41:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/22/2015 04:12:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung iTunes.exe, Version 12.0.1.26, Zeitstempel 0x543e558b, fehlerhaftes Modul ole32.dll, Version 6.0.6002.18277, Zeitstempel 0x4c28d53e, Ausnahmecode 0xc0000005, Fehleroffset 0x00047456,
Prozess-ID 0xfd0, Anwendungsstartzeit iTunes.exe0.
Error: (02/22/2015 04:10:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung iTunes.exe, Version 12.0.1.26, Zeitstempel 0x543e558b, fehlerhaftes Modul ole32.dll, Version 6.0.6002.18277, Zeitstempel 0x4c28d53e, Ausnahmecode 0xc0000005, Fehleroffset 0x00047336,
Prozess-ID 0x1190, Anwendungsstartzeit iTunes.exe0.
Error: (02/22/2015 03:19:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung sidebar.exe, Version 6.0.6002.18005, Zeitstempel 0x49e035b8, fehlerhaftes Modul OLEAUT32.dll, Version 6.0.6002.19243, Zeitstempel 0x5475302c, Ausnahmecode 0xc0000005, Fehleroffset 0x0000000000001149,
Prozess-ID 0x12cc, Anwendungsstartzeit sidebar.exe0.
Error: (02/22/2015 01:04:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/16/2015 10:00:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung sidebar.exe, Version 6.0.6002.18005, Zeitstempel 0x49e035b8, fehlerhaftes Modul OLEAUT32.dll, Version 6.0.6002.19243, Zeitstempel 0x5475302c, Ausnahmecode 0xc0000005, Fehleroffset 0x0000000000001149,
Prozess-ID 0x1114, Anwendungsstartzeit sidebar.exe0.
Error: (02/16/2015 09:43:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Fehlerhafte Anwendung sidebar.exe, Version 6.0.6002.18005, Zeitstempel 0x49e035b8, fehlerhaftes Modul OLEAUT32.dll, Version 6.0.6002.19243, Zeitstempel 0x5475302c, Ausnahmecode 0xc0000005, Fehleroffset 0x0000000000001149,
Prozess-ID 0xe58, Anwendungsstartzeit sidebar.exe0.
Error: (02/16/2015 09:41:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/12/2015 11:07:20 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll8
System errors:
=============
Error: (02/22/2015 07:42:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: NVIDIA Update Service Daemon%%1069
Error: (02/22/2015 07:42:45 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: nvUpdatusService.\UpdatusUser%%1330
Error: (02/22/2015 01:14:32 PM) (Source: volsnap) (EventID: 20) (User: )
Description: Die Schattenkopien von Volume "C:" wurden aufgrund von einem fehlgeschlagenen Rechenvorgang bezüglich verfügbarem Speicher abgebrochen.
Error: (02/22/2015 01:05:27 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: NVIDIA Update Service Daemon%%1069
Error: (02/22/2015 01:05:27 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: nvUpdatusService.\UpdatusUser%%1330
Error: (02/22/2015 01:04:02 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Garmin Core Update Service%%1053
Error: (02/22/2015 01:04:02 PM) (Source: Service Control Manager) (EventID: 7009) (User: )
Description: 30000Garmin Core Update Service
Error: (02/16/2015 10:15:58 PM) (Source: Service Control Manager) (EventID: 7030) (User: )
Description: Foxit Cloud Safe Update Service
Error: (02/16/2015 09:43:45 PM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: NVIDIA Update Service Daemon%%1069
Error: (02/16/2015 09:43:45 PM) (Source: Service Control Manager) (EventID: 7038) (User: )
Description: nvUpdatusService.\UpdatusUser%%1330
Microsoft Office Sessions:
=========================
Error: (02/22/2015 07:42:01 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: sidebar.exe6.0.6002.1800549e035b8OLEAUT32.dll6.0.6002.192435475302cc00000050000000000001149ed001d04ecf26bbafce
Error: (02/22/2015 07:41:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/22/2015 04:12:41 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iTunes.exe12.0.1.26543e558bole32.dll6.0.6002.182774c28d53ec000000500047456fd001d04eb1d430c4b1
Error: (02/22/2015 04:10:55 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: iTunes.exe12.0.1.26543e558bole32.dll6.0.6002.182774c28d53ec000000500047336119001d04eab1cf8ae81
Error: (02/22/2015 03:19:19 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: sidebar.exe6.0.6002.1800549e035b8OLEAUT32.dll6.0.6002.192435475302cc0000005000000000000114912cc01d04eaa767b30f1
Error: (02/22/2015 01:04:02 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/16/2015 10:00:33 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: sidebar.exe6.0.6002.1800549e035b8OLEAUT32.dll6.0.6002.192435475302cc00000050000000000001149111401d04a2b8ea7603f
Error: (02/16/2015 09:43:53 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: sidebar.exe6.0.6002.1800549e035b8OLEAUT32.dll6.0.6002.192435475302cc00000050000000000001149e5801d04a29308a65df
Error: (02/16/2015 09:41:58 PM) (Source: WinMgmt) (EventID: 10) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003
Error: (02/12/2015 11:07:20 PM) (Source: Perflib) (EventID: 1008) (User: )
Description: PNRPsvcC:\Windows\system32\pnrpperf.dll8
CodeIntegrity Errors:
===================================
Date: 2015-02-22 20:39:42.992
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-22 20:39:42.882
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-22 20:39:42.789
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2015-02-22 20:39:42.695
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume1\Windows\System32\drivers\HookCentre.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-11-02 19:01:37.650
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume11\13-01-23.old\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22719_none_11ab004d35078d79\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-11-02 19:01:37.556
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume11\13-01-23.old\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22719_none_11ab004d35078d79\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-11-02 19:01:37.447
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume11\13-01-23.old\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22719_none_11ab004d35078d79\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-11-02 19:01:37.353
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume11\13-01-23.old\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22719_none_11ab004d35078d79\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-11-02 19:01:37.260
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume11\13-01-23.old\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22662_none_116decc535366aa6\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
Date: 2014-11-02 19:01:37.150
Description: Die Abbildintegrität der Datei "\Device\HarddiskVolume11\13-01-23.old\Windows\winsxs\amd64_microsoft-windows-tcpip-binaries_31bf3856ad364e35_6.0.6002.22662_none_116decc535366aa6\tcpip.sys" konnte nicht überprüft werden, da der Satz seitenbezogener Abbildhashes auf dem System nicht gefunden wurde.
==================== Memory info ===========================
Processor: Intel(R) Core(TM)2 Duo CPU E8400 @ 3.00GHz
Percentage of memory in use: 41%
Total physical RAM: 4093.58 MB
Available physical RAM: 2404.11 MB
Total Pagefile: 8402.44 MB
Available Pagefile: 6213.49 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB
==================== Drives ================================
Drive c: (Vista und Programme) (Fixed) (Total:302.01 GB) (Free:247.42 GB) NTFS ==>[Drive with boot components (obtained from BCD)]
Drive e: (Austausch) (Fixed) (Total:151.96 GB) (Free:148.56 GB) NTFS
Drive i: (Daten) (Fixed) (Total:439.2 GB) (Free:97.7 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 931.5 GB) (Disk ID: DBE50493)
Partition 1: (Active) - (Size=302 GB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=439.2 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=38.1 GB) - (Type=05)
Partition 4: (Not Active) - (Size=152 GB) - (Type=07 NTFS)
==================== End Of Log ============================ MBAM.txt: Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 22.02.2015
Suchlauf-Zeit: 21:20:26
Logdatei: mbam.txt
Administrator: Nein
Version: 2.00.4.1028
Malware Datenbank: v2015.02.22.06
Rootkit Datenbank: v2015.02.22.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Selbstschutz: Deaktiviert
Betriebssystem: Windows Vista Service Pack 2
CPU: x64
Dateisystem: NTFS
Benutzer: Volker_2
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 560499
Verstrichene Zeit: 10 Min, 50 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Heuristik: Aktiviert
PUP: Aktiviert
PUM: Aktiviert
Prozesse: 0
(Keine schädliche Elemente erkannt)
Module: 0
(Keine schädliche Elemente erkannt)
Registrierungsschlüssel: 0
(Keine schädliche Elemente erkannt)
Registrierungswerte: 0
(Keine schädliche Elemente erkannt)
Registrierungsdaten: 0
(Keine schädliche Elemente erkannt)
Ordner: 16
PUP.Optional.IncrediMediaBar, I:\\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\chrome, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\components, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\defaults, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\META-INF, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\Plugins, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\searchplugin, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}, Löschen bei Neustart, [0e704cd5dfab4aece1b3880581829868],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\chrome, Löschen bei Neustart, [0e704cd5dfab4aece1b3880581829868],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\components, Löschen bei Neustart, [0e704cd5dfab4aece1b3880581829868],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\defaults, Löschen bei Neustart, [0e704cd5dfab4aece1b3880581829868],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\META-INF, Löschen bei Neustart, [0e704cd5dfab4aece1b3880581829868],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules, Löschen bei Neustart, [0e704cd5dfab4aece1b3880581829868],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\Plugins, Löschen bei Neustart, [0e704cd5dfab4aece1b3880581829868],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\searchplugin, Löschen bei Neustart, [0e704cd5dfab4aece1b3880581829868],
Dateien: 45
PUP.Optional.InstallCore, I:\Chef\AppData\Roaming\0S1F1O2ZtAtB\Kindle Packages\uninstaller.exe, Löschen bei Neustart, [f886e9380387e056e5778f9d3ec4be42],
Trojan.Zbot, I:\Volker\Documents\Downloads\ccsetup131.exe, In Quarantäne, [a5d9859c2268fd39202a19a3bd4413ed],
Trojan.Zbot, I:\Volker\Documents\Downloads\ccsetup132.exe, In Quarantäne, [a9d5bd64b9d1aa8c4505b80405fcb14f],
PUP.Optional.SkyTech.A, I:\Chef\AppData\Local\Temp\2760531\2760531.zipDir\alilog.dll, Löschen bei Neustart, [fd81e43dd2b8a78f3134e41a60a1817f],
PUP.Optional.V9.A, I:\Chef\AppData\Local\Temp\2760531\2760531.zipDir\qSE.exe, Löschen bei Neustart, [daa4b36eddad7db95dd3b099c23edf21],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\chrome.manifest, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\install.rdf, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\version.txt, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\chrome\incredimail_mediabar_2.jar, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\components\ConduitAutoCompleteSearch.js, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\components\ConduitAutoCompleteSearch.xpt, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\defaults\alertSettingsComponent.xml, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\defaults\appContextMenu.xml, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\defaults\fbAlert.js, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\defaults\getAppsContextMenu.xml, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\defaults\postAppsContextMenu.xml, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\defaults\toolbarContextMenu.xml, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\defaults\unsharedAppsContextMenu.xml, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\META-INF\manifest.mf, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\META-INF\zigbert.rsa, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\META-INF\zigbert.sf, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\Chat.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\DataStructures.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\EBEncryption.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\ExternalLibraryLoader.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\HTTP.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\IO.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\Log.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\MainSingleton.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\MD5.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\Notifications.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\ObserversAndEvents.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\Prefs.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\SearchProtector.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\SearchSuggestIO.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\String.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\TEAEncryption.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\Timer.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\Twitter.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\URL.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\WebProgress.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\Windows.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\modules\XML.jsm, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\Plugins\np-mswmp.dll, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
PUP.Optional.IncrediMediaBar, I:\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\6qigmbnp.default\extensions\{d40b90b4-d3b1-4d6b-a5d7-dc041c1b76c0}\searchplugin\conduit.xml, Löschen bei Neustart, [f08ea47d8cfec96d7f15018c8a79e11f],
Physische Sektoren: 0
(Keine schädliche Elemente erkannt)
(end) und zum Schluss noch die Log-Dateien meines G-Data Virenscanners: Code:
1. Die Datei wurde desinfiziert.
Datei: C:\Program Files (x86)\Website and SEO Analysis\Website and SEO Analysis.exe
Virus: Trojan.Generic.12781468 (Engine A)
Der Leerlauf-Scan wird fortgesetzt.
2.Die Datei wurde desinfiziert.
Datei: I:\AdwCleaner\Quarantine\C\Program Files (x86)\uNNisales\1jHFRr0XDLkU3Z.exe.vir
Virus: Trojan.Generic.12781468 (Engine A)
Der Leerlauf-Scan wird fortgesetzt.
3.Die Datei wurde desinfiziert.
Datei: I:\AdwCleaner\Quarantine\C\Program Files (x86)\unnIsealese\unnIsealese.exe.vir
Virus: Trojan.Generic.12781468 (Engine A)
Der Leerlauf-Scan wird fortgesetzt.
4.Datei: I:\AdwCleaner\Quarantine\C\Program Files (x86)\youtubeadblocker\zkgtuNJy7Rdibh.exe.vir
Virus: Trojan.Generic.12781468 (Engine A)
Der Leerlauf-Scan wird fortgesetzt.
5.Leerlauf-Scan wurde erfolgreich durchgefürt:
855906 Dateien überprüft.
8 infizierte Dateien gefunden.
6.Virenprüfung mit G DATA ANTIVIRUS
Version 25.0.2.5 (08.01.2015)
Virensignaturen vom 22.02.2015
Startzeit: 22.02.2015 19:51:46
Engine(s): Engine A (AVA 25.374), Engine B (GD 25.4700)
Heuristik: Ein
Archive: Ein
Systembereiche: Ein
RootKits prüfen: Aus
Prüfung der Systembereiche...
Prüfung folgender Verzeichnisse und Dateien:
I:\AdwCleaner\
Analyse vollständig durchgeführt: 22.02.2015 19:51:54
69 Dateien überprüft
1 infizierte Dateien gefunden
0 verdächtige Dateien gefunden
Objekt: zkgtuNJy7Rdibh.exe.vir
Pfad: I:\AdwCleaner\Quarantine\C\Program Files (x86)\youtubeadblocker
Status: Virus, Datei gelöscht
Virus: Trojan.Generic.12781468 (Engine A)
7.Die Datei wurde gelöscht.
Datei: I:\Chef\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6R0AOUV4\20150121167687[1].exe
Virus: Win32.Adware.InstallMonetizer.N (Engine B)
Der Leerlauf-Scan wird fortgesetzt. Ich hoffe auf Euer geballtes Wissen und Eure Hilfe. Schon jetzt vielen Dank. |