Irgendwie kann ich es nciht runterladen oder öffnen. Folgendes wird mir angezeigt: Dieses Programm wird nichht häufig runter geladen und kann auf dem Computer Schaden anrichten, dann wird mir nur "Löschen" oder "Programm nicht ausführen" vorgeschlagen
Okay funtktionierte doch...hihi
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile:
FRST Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-01-2014 01
Ran by Jannene (administrator) on JANNENE-PC on 30-01-2014 23:04:50
Running from C:\Users\Jannene\Desktop
Microsoft Windows 7 Ultimate Service Pack 1 (X86) OS Language: German Standard
Internet Explorer Version 9
Boot Mode: Normal
==================== Processes (Whitelisted) ===================
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
(Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
(RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
(Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
(Samsung) C:\Program Files\Samsung\Kies\Kies.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
(Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Teruten) C:\Windows\System32\FsUsbExService.Exe
(pdfforge GbR) C:\Program Files\PDF Architect\HelperService.exe
(pdfforge GbR) C:\Program Files\PDF Architect\ConversionService.exe
() C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
(Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
(Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
(Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
(Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
==================== Registry (Whitelisted) ==================
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-12-11] (Samsung Electronics Co., Ltd.)
HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-03-29] (RealNetworks, Inc.)
HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
HKLM\...\Run: [YTDownloader] - "C:\Program Files\YTDownloader\YTDownloader.exe" /boot
HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG)
HKLM\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
Winlogon\Notify\ScCertProp: wlnotify.dll [X]
HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-12-11] (Samsung)
HKCU\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
HKCU\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-12-11] (Samsung)
HKCU\...\Run: [iCloudServices] - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
HKCU\...\Run: [BitTorrent] - C:\Users\Jannene\AppData\Roaming\BitTorrent\BitTorrent.exe [1138776 2014-01-02] (BitTorrent Inc.)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=ecffdf0e-6acc-484f-9b06-581d152674cf&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE210A8F757EBCD01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=ecffdf0e-6acc-484f-9b06-581d152674cf&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
SearchScopes: HKLM - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=ecffdf0e-6acc-484f-9b06-581d152674cf&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=ecffdf0e-6acc-484f-9b06-581d152674cf&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
SearchScopes: HKLM - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=296
SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=ecffdf0e-6acc-484f-9b06-581d152674cf&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPBA7FC3E8-54B5-4FF2-BCA9-A0CBFA294BFE&q={searchTerms}&SSPV=
SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=296
SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www2.delta-search.com/?q={searchTerms}&affID=120519&tt=gc_&babsrc=SP_ss&mntrId=74C300166F19BCD5
BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll (pdfforge GbR)
Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} - No File
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
Chrome:
=======
CHR RestoreOnStartup: "sync_promo":{"show_on_first_run_allowed"
CHR Extension: (RealDownloader) - C:\Users\Jannene\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-03-29]
CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-03-06]
========================== Services (Whitelisted) =================
R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-03-06] ()
==================== Drivers (Whitelisted) ====================
S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG)
R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-25] (Avira Operations GmbH & Co. KG)
R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [37344 2013-02-05] ()
R3 GTIPCI21; C:\Windows\System32\DRIVERS\gtipci21.sys [88192 2006-09-14] (Texas Instruments)
S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2014-01-30] (Malwarebytes Corporation)
R3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2595840 2007-03-06] (Intel® Corporation)
S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-18] (Avira GmbH)
S3 vsmraid; C:\Windows\system32\DRIVERS\vsmraid.sys [141904 2009-07-14] ()
S3 vwifibus; C:\Windows\System32\drivers\vwifibus.sys [19968 2009-07-14] ()
S3 WacomPen; C:\Windows\system32\DRIVERS\wacompen.sys [21632 2009-07-14] ()
S3 WANARP; C:\Windows\System32\DRIVERS\wanarp.sys [63488 2010-11-20] ()
R1 Wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [63488 2010-11-20] ()
S3 Wd; C:\Windows\system32\DRIVERS\wd.sys [19024 2009-07-14] ()
R0 Wdf01000; C:\Windows\System32\drivers\Wdf01000.sys [527064 2013-06-25] ()
R1 WfpLwf; C:\Windows\System32\DRIVERS\wfplwf.sys [9728 2009-07-14] ()
S3 WIMMount; C:\Windows\System32\drivers\wimmount.sys [19008 2009-07-14] ()
S3 WinUsb; C:\Windows\System32\DRIVERS\WinUsb.sys [35968 2010-11-20] ()
R3 WmiAcpi; C:\Windows\system32\drivers\wmiacpi.sys [11264 2009-07-14] ()
S4 ws2ifsl; C:\Windows\system32\drivers\ws2ifsl.sys [16384 2009-07-14] ()
R3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [66560 2012-07-26] ()
S3 WUDFRd; C:\Windows\System32\DRIVERS\WUDFRd.sys [155136 2012-07-26] ()
U5 4384475d9de5180c; C:\Windows\System32\Drivers\4384475d9de5180c.sys [58880 2014-01-27] ()
S1 cjijbjti; \??\C:\Windows\system32\drivers\cjijbjti.sys [x]
S3 dgderdrv; System32\drivers\dgderdrv.sys [x]
S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
S3 VGPU; System32\drivers\rdvgkmd.sys [x]
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-01-30 23:04 - 2014-01-30 23:05 - 00012395 _____ C:\Users\Jannene\Desktop\FRST.txt
2014-01-30 23:04 - 2014-01-30 23:04 - 00000000 ____D C:\FRST
2014-01-30 22:32 - 2014-01-30 22:32 - 01137152 _____ (Farbar) C:\Users\Jannene\Desktop\FRST.exe
2014-01-30 22:28 - 2014-01-30 22:28 - 01137152 _____ (Farbar) C:\Users\Jannene\Downloads\FRST.exe
2014-01-30 22:24 - 2014-01-30 22:24 - 02079744 _____ (Farbar) C:\Users\Jannene\Downloads\FRST64.exe
2014-01-30 18:20 - 2014-01-30 18:20 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-01-30 18:20 - 2014-01-30 18:20 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-30 18:20 - 2014-01-30 18:20 - 00000000 ____D C:\Users\Jannene\AppData\Roaming\Malwarebytes
2014-01-30 18:20 - 2014-01-30 18:20 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-30 18:19 - 2014-01-30 18:20 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-30 18:19 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-30 18:18 - 2014-01-30 18:19 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jannene\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-29 17:25 - 2014-01-29 17:25 - 00002012 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2014-01-29 17:25 - 2014-01-29 17:25 - 00000000 ____D C:\Users\Jannene\AppData\Roaming\Avira
2014-01-29 17:24 - 2014-01-29 17:24 - 00000000 ____D C:\ProgramData\Avira
2014-01-29 17:24 - 2013-12-18 09:32 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
2014-01-29 17:24 - 2013-12-18 09:32 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
2014-01-29 17:22 - 2014-01-29 17:23 - 130658432 _____ C:\Users\Jannene\Downloads\avira_free_antivirus_de.exe
2014-01-29 17:13 - 2014-01-29 17:13 - 03975896 _____ (Avira Operations GmbH & Co. KG) C:\Users\Jannene\Downloads\avira_oe_client_antivirus_de.exe
2014-01-27 16:45 - 2014-01-27 16:45 - 00058880 _____ C:\Windows\system32\Drivers\4384475d9de5180c.sys
2014-01-27 08:48 - 2014-01-27 08:50 - 00000000 ____D C:\Users\Jannene\Desktop\Galaxy note
2014-01-27 08:36 - 2014-01-27 08:36 - 00999883 _____ C:\Users\Jannene\Downloads\Odin_v3.09.zip
2014-01-22 08:52 - 2014-01-22 08:52 - 00184192 _____ C:\Windows\system32\Drivers\ssudmdm.sys
2014-01-22 08:52 - 2014-01-22 08:52 - 00088576 _____ C:\Windows\system32\Drivers\ssudbus.sys
2014-01-15 14:12 - 2014-01-15 14:12 - 01571921 _____ C:\Users\Jannene\Downloads\Email.zip
2014-01-15 13:30 - 2013-11-27 02:14 - 00258560 _____ C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 13:30 - 2013-11-27 02:13 - 00284672 _____ C:\Windows\system32\Drivers\usbport.sys
2014-01-15 13:30 - 2013-11-27 02:13 - 00076288 _____ C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 13:30 - 2013-11-27 02:13 - 00043520 _____ C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 13:30 - 2013-11-27 02:13 - 00024064 _____ C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 13:30 - 2013-11-27 02:13 - 00020480 _____ C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 13:30 - 2013-11-27 02:13 - 00006016 _____ C:\Windows\system32\Drivers\usbd.sys
2014-01-15 13:30 - 2013-11-26 11:10 - 02349056 _____ C:\Windows\system32\win32k.sys
2014-01-02 18:08 - 2014-01-02 18:08 - 00000196 _____ C:\Windows\system32\Config.json
2014-01-02 17:47 - 2014-01-02 18:09 - 00000000 ____D C:\Program Files\ShopperPro
2014-01-02 17:47 - 2014-01-02 17:51 - 00000000 ____D C:\Users\Jannene\Downloads\(userwunsch) The.Big.Bang.Theory.S06E01-12.German.Dubbed.HDTV.XviD-ITG
2014-01-02 17:45 - 2014-01-02 17:45 - 00000815 _____ C:\Users\Jannene\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk
2014-01-02 17:45 - 2014-01-02 17:45 - 00000000 ____D C:\Users\Jannene\AppData\Local\CrashRpt
2014-01-02 17:44 - 2014-01-30 17:57 - 00000000 ____D C:\Users\Jannene\AppData\Roaming\BitTorrent
2014-01-02 17:38 - 2014-01-02 17:38 - 01138776 _____ (BitTorrent Inc.) C:\Users\Jannene\Downloads\bittorrent.exe
==================== One Month Modified Files and Folders =======
2014-01-30 23:05 - 2014-01-30 23:04 - 00012395 _____ C:\Users\Jannene\Desktop\FRST.txt
2014-01-30 23:04 - 2014-01-30 23:04 - 00000000 ____D C:\FRST
2014-01-30 22:32 - 2014-01-30 22:32 - 01137152 _____ (Farbar) C:\Users\Jannene\Desktop\FRST.exe
2014-01-30 22:31 - 2009-07-14 05:34 - 00020704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-30 22:31 - 2009-07-14 05:34 - 00020704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-30 22:28 - 2014-01-30 22:28 - 01137152 _____ (Farbar) C:\Users\Jannene\Downloads\FRST.exe
2014-01-30 22:27 - 2013-03-29 11:48 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-01-30 22:24 - 2014-01-30 22:24 - 02079744 _____ (Farbar) C:\Users\Jannene\Downloads\FRST64.exe
2014-01-30 22:10 - 2013-01-05 21:42 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-30 18:20 - 2014-01-30 18:20 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
2014-01-30 18:20 - 2014-01-30 18:20 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
2014-01-30 18:20 - 2014-01-30 18:20 - 00000000 ____D C:\Users\Jannene\AppData\Roaming\Malwarebytes
2014-01-30 18:20 - 2014-01-30 18:20 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-30 18:20 - 2014-01-30 18:19 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
2014-01-30 18:19 - 2014-01-30 18:18 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Jannene\Downloads\mbam-setup-1.75.0.1300.exe
2014-01-30 17:57 - 2014-01-02 17:44 - 00000000 ____D C:\Users\Jannene\AppData\Roaming\BitTorrent
2014-01-30 17:40 - 2013-01-05 16:14 - 01652244 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-30 17:15 - 2013-03-29 11:48 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-01-30 17:14 - 2013-08-02 07:52 - 00015082 _____ C:\Windows\setupact.log
2014-01-30 17:14 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-29 17:27 - 2013-01-05 17:39 - 00209586 _____ C:\Windows\PFRO.log
2014-01-29 17:25 - 2014-01-29 17:25 - 00002012 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
2014-01-29 17:25 - 2014-01-29 17:25 - 00000000 ____D C:\Users\Jannene\AppData\Roaming\Avira
2014-01-29 17:25 - 2013-01-05 16:01 - 01723003 _____ C:\Windows\WindowsUpdate.log
2014-01-29 17:24 - 2014-01-29 17:24 - 00000000 ____D C:\ProgramData\Avira
2014-01-29 17:24 - 2013-01-05 16:45 - 00000000 ____D C:\Program Files\Avira
2014-01-29 17:23 - 2014-01-29 17:22 - 130658432 _____ C:\Users\Jannene\Downloads\avira_free_antivirus_de.exe
2014-01-29 17:13 - 2014-01-29 17:13 - 03975896 _____ (Avira Operations GmbH & Co. KG) C:\Users\Jannene\Downloads\avira_oe_client_antivirus_de.exe
2014-01-28 09:36 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
2014-01-27 16:45 - 2014-01-27 16:45 - 00058880 _____ C:\Windows\system32\Drivers\4384475d9de5180c.sys
2014-01-27 08:50 - 2014-01-27 08:48 - 00000000 ____D C:\Users\Jannene\Desktop\Galaxy note
2014-01-27 08:36 - 2014-01-27 08:36 - 00999883 _____ C:\Users\Jannene\Downloads\Odin_v3.09.zip
2014-01-25 01:26 - 2013-01-06 12:34 - 00000000 ____D C:\Users\Jannene\AppData\Local\Adobe
2014-01-25 01:25 - 2013-01-05 21:42 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
2014-01-25 01:25 - 2013-01-05 21:42 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
2014-01-22 08:52 - 2014-01-22 08:52 - 00184192 _____ C:\Windows\system32\Drivers\ssudmdm.sys
2014-01-22 08:52 - 2014-01-22 08:52 - 00088576 _____ C:\Windows\system32\Drivers\ssudbus.sys
2014-01-16 16:37 - 2009-07-14 05:33 - 00408696 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-16 09:59 - 2013-01-05 16:45 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
2014-01-15 22:59 - 2013-08-14 22:28 - 00000000 ____D C:\Windows\system32\MRT
2014-01-15 22:57 - 2010-06-24 09:43 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
2014-01-15 14:12 - 2014-01-15 14:12 - 01571921 _____ C:\Users\Jannene\Downloads\Email.zip
2014-01-02 18:09 - 2014-01-02 17:47 - 00000000 ____D C:\Program Files\ShopperPro
2014-01-02 18:09 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\System
2014-01-02 18:08 - 2014-01-02 18:08 - 00000196 _____ C:\Windows\system32\Config.json
2014-01-02 17:51 - 2014-01-02 17:47 - 00000000 ____D C:\Users\Jannene\Downloads\(userwunsch) The.Big.Bang.Theory.S06E01-12.German.Dubbed.HDTV.XviD-ITG
2014-01-02 17:45 - 2014-01-02 17:45 - 00000815 _____ C:\Users\Jannene\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk
2014-01-02 17:45 - 2014-01-02 17:45 - 00000000 ____D C:\Users\Jannene\AppData\Local\CrashRpt
2014-01-02 17:38 - 2014-01-02 17:38 - 01138776 _____ (BitTorrent Inc.) C:\Users\Jannene\Downloads\bittorrent.exe
Some content of TEMP:
====================
C:\Users\Jannene\AppData\Local\Temp\2dsve2wefd.exe
C:\Users\Jannene\AppData\Local\Temp\avgnt.exe
C:\Users\Jannene\AppData\Local\Temp\BlueStacks-SplitInstaller_native.exe
C:\Users\Jannene\AppData\Local\Temp\busunint.exe
C:\Users\Jannene\AppData\Local\Temp\nsp1D3.exe
C:\Users\Jannene\AppData\Local\Temp\nsy68F0.exe
C:\Users\Jannene\AppData\Local\Temp\nsyEFED.exe
C:\Users\Jannene\AppData\Local\Temp\OptimizerPro.exe
C:\Users\Jannene\AppData\Local\Temp\ose00000.exe
C:\Users\Jannene\AppData\Local\Temp\PCSpeedMaximizer.exe
C:\Users\Jannene\AppData\Local\Temp\pyiue01c.dll
C:\Users\Jannene\AppData\Local\Temp\Show-Password_1030-8101.exe
C:\Users\Jannene\AppData\Local\Temp\stubhelper.dll
C:\Users\Jannene\AppData\Local\Temp\tu17p84.exe
C:\Users\Jannene\AppData\Local\Temp\uninst1.exe
C:\Users\Jannene\AppData\Local\Temp\UpdateCheckerSetup.exe
C:\Users\Jannene\AppData\Local\Temp\uttEF78.tmp.exe
C:\Users\Jannene\AppData\Local\Temp\wajam_download.exe
C:\Users\Jannene\AppData\Local\Temp\ytd_bu10_setup.exe
==================== Bamital & volsnap Check =================
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\system32\winlogon.exe => MD5 is legit
C:\Windows\system32\wininit.exe => MD5 is legit
C:\Windows\system32\svchost.exe => MD5 is legit
C:\Windows\system32\services.exe => MD5 is legit
C:\Windows\system32\User32.dll => MD5 is legit
C:\Windows\system32\userinit.exe => MD5 is legit
C:\Windows\system32\rpcss.dll => MD5 is legit
C:\Windows\system32\Drivers\volsnap.sys
[2013-01-05 18:32] - [2010-11-20 13:30] - 0245632 ____A () D41D8CD98F00B204E9800998ECF8427E
C:\Windows\system32\Drivers\volsnap.sys IS INFECTED. <===== ATTENTION!
LastRegBack: 2014-01-29 19:56
==================== End Of Log ============================ --- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
--- --- ---
Und hier Addition: Code:
Additional scan result of Farbar Recovery Scan Tool (x86) Version: 29-01-2014 01
Ran by Jannene at 2014-01-30 23:05:47
Running from C:\Users\Jannene\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
==================== Installed Programs ======================
Adobe Flash Player 12 ActiveX (Version: 12.0.0.38 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (Version: 11.0.06 - Adobe Systems Incorporated)
Apple Application Support (Version: 2.3.6 - Apple Inc.)
Apple Mobile Device Support (Version: 7.0.0.117 - Apple Inc.)
Apple Software Update (Version: 2.1.3.127 - Apple Inc.)
Avira Free Antivirus (Version: 14.0.2.344 - Avira)
BitTorrent (HKCU Version: 7.8.2.30445 - BitTorrent Inc.)
Bonjour (Version: 3.0.0.10 - Apple Inc.)
Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (Version: - Microsoft)
Free Easy Burner V 5.1 (Version: 5.1.0.0 - Koyote soft)
Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
Google Toolbar for Internet Explorer (Version: 7.5.4805.320 - Google Inc.)
Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden
iCloud (Version: 3.1.0.40 - Apple Inc.)
iFunbox (v2.7.2386.747), iFunbox DevTeam (Version: v2.7.2386.747 - )
iTunes (Version: 11.1.3.8 - Apple Inc.)
Java 7 Update 15 (Version: 7.0.150 - Oracle)
Java Auto Updater (Version: 2.1.9.0 - Sun Microsystems, Inc.) Hidden
king.com (remove only) (Version: - Midasplayer Ltd (king.com))
Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300 - Malwarebytes Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Office 2010 Service Pack 1 (SP1) (Version: - Microsoft)
Microsoft Office 2010 Service Pack 1 (SP1) (Version: - Microsoft) Hidden
Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
Mozilla Maintenance Service (Version: 17.0 - Mozilla)
Mozilla Thunderbird 17.0 (x86 de) (Version: 17.0 - Mozilla)
MyFreeCodec (HKCU Version: - )
PDF Architect (Version: 1.0.52.8917 - pdfforge)
PDFCreator (Version: 1.6.2 - pdfforge)
QuickTime (Version: 7.74.80.86 - Apple Inc.)
RealDownloader (Version: 1.3.1 - RealNetworks, Inc.) Hidden
RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
RealPlayer (Version: 16.0.0 - RealNetworks)
RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
Samsung Kies (Version: 2.5.1.12123_2 - Samsung Electronics Co., Ltd.)
Samsung Kies (Version: 2.5.1.12123_2 - Samsung Electronics Co., Ltd.) Hidden
Samsung Story Album Viewer (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.)
Samsung Story Album Viewer (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.) Hidden
SAMSUNG USB Driver for Mobile Phones (Version: 1.5.29.0 - SAMSUNG Electronics Co., Ltd.)
Texas Instruments PCIxx21/x515/xx12 drivers. (Version: 2.00.0001 - Ihr Firmenname)
TIPCI (Version: 2.00.0001 - Ihr Firmenname) Hidden
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1 - Microsoft Corporation)
Update for Microsoft Office 2010 (KB2553065) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553092) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2566458) (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition (Version: - Microsoft)
Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (Version: - Microsoft)
VLC media player 2.0.5 (Version: 2.0.5 - VideoLAN)
WinRAR 4.20 (32-Bit) (Version: 4.20.0 - win.rar GmbH)
==================== Restore Points =========================
==================== Hosts content: ==========================
2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {05EFF16F-54DC-4A8B-86F1-03EF34E57BAB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-25] (Adobe Systems Incorporated)
Task: {24EFE2C8-ACC3-4A70-9071-1E3FEA54631D} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2013-01-05] ()
Task: {46EBCFD9-479A-43D8-A209-8B942EE22617} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-770320959-3698567616-4190397953-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-03-06] (RealNetworks, Inc.)
Task: {5473BF51-FE37-49F5-8E99-7650C44A293D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-29] (Google Inc.)
Task: {774823AE-8D1E-4525-8300-B302DFE7CD5C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {794F4AFB-21EF-44A6-994A-4A6459043496} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-29] (Google Inc.)
Task: {8751F157-358D-436C-97D7-8ECA3828B499} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-770320959-3698567616-4190397953-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2013-03-06] (RealNetworks, Inc.)
Task: {8B9440E2-1F9C-465F-8192-4283D4E7DF35} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-770320959-3698567616-4190397953-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2013-03-06] (RealNetworks, Inc.)
Task: {8E1FDE5C-3D8D-4FC4-A37D-2EBD5AD85278} - System32\Tasks\Apple Diagnostics => C:\Program Files\Common Files\Apple\Internet Services\EReporter.exe [2013-11-20] (Apple Inc.)
Task: {DD8AEFB1-3C8E-476A-9D7F-2F3B7BF8AE3C} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-770320959-3698567616-4190397953-1000 => C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe [2013-03-06] (RealNetworks, Inc.)
Task: {F1E1EE7A-1C4D-40CB-980D-78D970580D63} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-770320959-3698567616-4190397953-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-03-06] (RealNetworks, Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
==================== Loaded Modules (whitelisted) =============
2011-03-17 00:11 - 2011-03-17 00:11 - 04297568 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
2013-01-28 12:08 - 2013-01-28 12:08 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
2013-01-28 12:08 - 2013-01-28 12:08 - 01242512 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
2013-12-13 18:30 - 2013-12-13 18:30 - 01952256 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\abbba0f399508efdbeaf78b2e2fa7b03\Kies.UI.ni.dll
2013-12-13 18:30 - 2013-12-13 18:30 - 00079360 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\6f25a20174765872519f821c6c68bfda\Kies.MVVM.ni.dll
2013-12-13 18:31 - 2013-12-13 18:31 - 00189952 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\891822cfc054262435c02192bb220192\Kies.Common.DeviceServiceLib.Interface.ni.dll
2013-12-13 18:31 - 2013-12-13 18:31 - 00367104 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePhoto\0cb1ca6d0bc2fbc4225ec8b991eecd07\DevicePhoto.ni.dll
2013-12-13 18:31 - 2013-12-13 18:31 - 00301568 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceVideo\1f0d8f012eae2b7353c8d594b2a06e9d\DeviceVideo.ni.dll
2013-12-13 18:31 - 2013-12-13 18:31 - 00616448 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePodcast\3eb0df72e19c269e7ec4dc4a2c130521\DevicePodcast.ni.dll
2013-12-13 18:31 - 2013-12-13 18:31 - 00307200 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DummyStorePlugin\9e97c3b33aa7fb9d900bca4f6d93ec9e\DummyStorePlugin.ni.dll
2013-12-13 18:31 - 2013-12-13 18:31 - 14972928 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\642ba04dfd0cf6b5a4bd768ab404eb4f\Kies.Theme.ni.dll
2013-12-13 18:31 - 2013-12-13 18:31 - 00581632 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\42ab5ed8c70495af14fc9a8e38e5383a\Kies.Common.DeviceServiceLib.FileService.ni.dll
2013-12-13 18:31 - 2013-12-13 18:31 - 00046592 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\fb36527133c6a9e51f53aab9ca2faabe\Kies.Common.DeviceServiceLib.FirmwareUpdate.FirmwareUpdateAgentHelper.ni.dll
2013-12-13 18:31 - 2013-12-13 18:31 - 01002496 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceCommonLib\06251528bbadcb3da726d324a41e710f\DeviceCommonLib.ni.dll
2013-08-15 12:54 - 2013-08-15 12:54 - 00232960 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\c5efe841e2998c266e0f5e29bed04b55\ASF_cSharpAPI.ni.dll
2013-09-14 01:51 - 2013-09-14 01:51 - 00087952 _____ () C:\Program Files\Common Files\Apple\Internet Services\zlib1.dll
2013-09-14 01:50 - 2013-09-14 01:50 - 01242952 _____ () C:\Program Files\Common Files\Apple\Internet Services\libxml2.dll
==================== Alternate Data Streams (whitelisted) =========
AlternateDataStreams: C:\ProgramData\TEMP:373E1720
AlternateDataStreams: C:\ProgramData\TEMP:AD022376
==================== Safe Mode (whitelisted) ===================
==================== Faulty Device Manager Devices =============
==================== Event log errors: =========================
Application errors:
==================
Error: (01/30/2014 07:08:06 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/30/2014 07:06:37 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (01/30/2014 07:06:35 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (01/29/2014 07:58:21 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
Error: (01/29/2014 07:55:43 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (01/29/2014 07:55:41 PM) (Source: SideBySide) (User: )
Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"2" in Zeile Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"3.
Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
Verweis: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Definition: Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
Error: (01/29/2014 05:37:26 PM) (Source: VSS) (User: )
Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
.
Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {21a80d97-8b01-46ad-a6f3-f728bb8f3e2b}
Error: (01/27/2014 08:18:19 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddWin32ServiceFiles: Unable to back up image of service syshost32 since QueryServiceConfig API failed
System Error:
Zugriff verweigert
.
Error: (01/27/2014 08:18:19 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddWin32ServiceFiles: Unable to back up image of service Windows Update since QueryServiceConfig API failed
System Error:
Zugriff verweigert
.
Error: (01/27/2014 08:18:19 PM) (Source: Microsoft-Windows-CAPI2) (User: )
Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
Details:
AddWin32ServiceFiles: Unable to back up image of service Intelligenter Hintergrundübertragungsdienst since QueryServiceConfig API failed
System Error:
Zugriff verweigert
.
System errors:
=============
Error: (01/30/2014 06:20:58 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "MBAMSwissArmy" wurde aufgrund folgenden Fehlers nicht gestartet:
%%31
Error: (01/30/2014 06:20:46 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "MBAMSwissArmy" wurde aufgrund folgenden Fehlers nicht gestartet:
%%31
Error: (01/30/2014 06:20:31 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "MBAMSwissArmy" wurde aufgrund folgenden Fehlers nicht gestartet:
%%31
Error: (01/30/2014 06:20:29 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "MBAMService" ist vom Dienst "MBAMProtector" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
%%31
Error: (01/30/2014 06:20:29 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "MBAMProtector" wurde aufgrund folgenden Fehlers nicht gestartet:
%%31
Error: (01/30/2014 06:20:18 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "MBAMSwissArmy" wurde aufgrund folgenden Fehlers nicht gestartet:
%%31
Error: (01/30/2014 05:16:17 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
ssmdrv
Error: (01/30/2014 05:14:36 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "avgntflt" wurde aufgrund folgenden Fehlers nicht gestartet:
%%31
Error: (01/30/2014 05:14:29 PM) (Source: BTHUSB) (User: )
Description:
Error: (01/29/2014 05:41:11 PM) (Source: Service Control Manager) (User: )
Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
ssmdrv
Microsoft Office Sessions:
=========================
Error: (01/30/2014 07:08:06 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{EA1FAE0F-2354-4E32-B423-ABAE8E358F91}\recordingmanager.exe
Error: (01/30/2014 07:06:37 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"c:\program files\Samsung\Kies\External\firmwareupdate\GT-N7000\DeviceController64.exec:\program files\Samsung\Kies\External\firmwareupdate\GT-N7000\Microsoft.VC90.CRT.MANIFEST11
Error: (01/30/2014 07:06:35 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"c:\program files\Samsung\Kies\External\firmwareupdate\GT-I8190\DeviceController64.exec:\program files\Samsung\Kies\External\firmwareupdate\GT-I8190\Microsoft.VC90.CRT.MANIFEST11
Error: (01/29/2014 07:58:21 PM) (Source: SideBySide)(User: )
Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{EA1FAE0F-2354-4E32-B423-ABAE8E358F91}\recordingmanager.exe
Error: (01/29/2014 07:55:43 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"c:\program files\Samsung\Kies\External\firmwareupdate\GT-N7000\DeviceController64.exec:\program files\Samsung\Kies\External\firmwareupdate\GT-N7000\Microsoft.VC90.CRT.MANIFEST11
Error: (01/29/2014 07:55:41 PM) (Source: SideBySide)(User: )
Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"c:\program files\Samsung\Kies\External\firmwareupdate\GT-I8190\DeviceController64.exec:\program files\Samsung\Kies\External\firmwareupdate\GT-I8190\Microsoft.VC90.CRT.MANIFEST11
Error: (01/29/2014 05:37:26 PM) (Source: VSS)(User: )
Description: 0x80070005, Zugriff verweigert
Vorgang:
Generatordaten werden gesammelt
Kontext:
Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
Generatorname: System Writer
Generatorinstanz-ID: {21a80d97-8b01-46ad-a6f3-f728bb8f3e2b}
Error: (01/27/2014 08:18:19 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service syshost32 since QueryServiceConfig API failed
System Error:
Zugriff verweigert
Error: (01/27/2014 08:18:19 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service Windows Update since QueryServiceConfig API failed
System Error:
Zugriff verweigert
Error: (01/27/2014 08:18:19 PM) (Source: Microsoft-Windows-CAPI2)(User: )
Description:
Details:
AddWin32ServiceFiles: Unable to back up image of service Intelligenter Hintergrundübertragungsdienst since QueryServiceConfig API failed
System Error:
Zugriff verweigert
==================== Memory info ===========================
Percentage of memory in use: 83%
Total physical RAM: 1023.43 MB
Available physical RAM: 171.72 MB
Total Pagefile: 2047.43 MB
Available Pagefile: 530.03 MB
Total Virtual: 2047.88 MB
Available Virtual: 1883.88 MB
==================== Drives ================================
Drive c: () (Fixed) (Total:148.95 GB) (Free:103.57 GB) NTFS
Drive e: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 982B982B)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS)
==================== End Of Log ============================ Wann wird es denn weiter gehen? Was ist der nächste Schritt?
Ein neuer 2. Trojaner scheint hinzu gekommen zu sein...HILFE!!!! Windows Defender hat 2 Stück gefunden und den einen kann er nicht in die Quaratäne verschieben oder das System bereinigen.
Name Trojaner 1: Win32/Necurs.A
Name Trojaner 2: WinNT/Necurs.A
Das hier ist das Ergebnis von Windows Defender. Mein Avira Echtzeitscanner lässt sich einfach nicht mehr aktivieren.
Kategorie:
Trojaner
Beschreibung:
Dieses Programm ist gefährlich. Es führt Befehle eines Angreifers aus.
Empfehlung:
Entfernen Sie diese Software unverzüglich.
Ressourcen:
file:
C:\Windows\system32\drivers\4384475d9de5180c.sys
hiddendriver:
4384475d9de5180c
hiddenfile:
C:\Windows\System32\Drivers\4384475d9de5180c.sys
Kann ich das Ding wieder loswerden ohne Platt machen und neu aufspielen? |