Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Sophosmeldung: Troj/ZbotMem-B im Memory

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Antwort
Alt 09.07.2013, 09:57   #16
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



poste mal noch ein frisches FRST log.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.07.2013, 10:09   #17
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Lieber Schrauber,

hier ist das FRST Log:

FRST Logfile:
Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 09-07-2013
Ran by Daniel (administrator) on 09-07-2013 11:03:39
Running from C:\Users\Daniel\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: English(US)
Internet Explorer Version 10
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe
(Microsoft Corporation) C:\Windows\system32\WLANExt.exe
(Atheros) C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\adminservice.exe
(Microsoft Corporation) C:\Windows\SysWOW64\svchost.exe
(Sony Corporation) c:\Program Files (x86)\Sony\PMB\PMBDeviceInfoProvider.exe
(Samsung Electronics Co., Ltd.) C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft\BingBar\SeaPort.EXE
(Secunia) C:\Program Files (x86)\Secunia\PSI\PSIA.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgr.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Sony Corporation) C:\Program Files (x86)\Sony\VAIO Event Service\VESMgrSub.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Microsoft Corporation) C:\Windows\SysWOW64\DllHost.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
(Conexant Systems, Inc.) C:\Program Files\CONEXANT\cAudioFilterAgent\cAudioFilterAgent64.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe
(Atheros Commnucations) C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe
(Intel Corporation) C:\Windows\System32\igfxtray.exe
(Intel Corporation) C:\Windows\System32\hkcmd.exe
(Intel Corporation) C:\Windows\System32\igfxpers.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
() C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe
(Google Inc.) C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apntex.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
(VoipBuster) C:\Program Files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Hewlett-Packard Co.) C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
(Secunia) C:\Program Files (x86)\Secunia\PSI\psi_tray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe
(Sony Corporation) C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe
(Sony Corporation) C:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe
(Hewlett-Packard) C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SmarThru Office\BackUpSvr.exe
(Samsung Electronics Co., Ltd.) C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe
(Sophos Limited) C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Geek Software GmbH) C:\Program Files (x86)\PDF24\pdf24.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Dropbox, Inc.) C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe
(OpenOffice.org) C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Smart Network\VSNClient.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Thunderbird\thunderbird.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorDataMgrSvc.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Update\VUAgent.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(ArcSoft, Inc.) C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe
(Intel Corporation) C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE
(Microsoft Corporation) C:\Windows\splwow64.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\Admload.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
(Adobe Systems, Inc.) C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerPlugin_11_7_700_224.exe
(Oracle Corporation) C:\Program Files (x86)\Java\jre7\bin\jp2launcher.exe
(Oracle Corporation) C:\Program Files (x86)\Java\jre7\bin\java.exe
(Hewlett-Packard Co.) C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPNetworkCommunicator.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [cAudioFilterAgent] C:\Program Files\Conexant\cAudioFilterAgent\cAudioFilterAgent64.exe [518784 2011-03-29] (Conexant Systems, Inc.)
HKLM\...\Run: [AtherosBtStack] "C:\Program Files (x86)\Bluetooth Suite\BtvStack.exe" [790688 2011-04-29] (Atheros Commnucations)
HKLM\...\Run: [AthBtTray] "C:\Program Files (x86)\Bluetooth Suite\AthBtTray.exe" [657568 2011-04-29] (Atheros Commnucations)
HKLM\...\Run: [Apoint] %ProgramFiles%\Apoint\Apoint.exe [226672 2011-02-17] (Alps Electric Co., Ltd.)
HKLM\...\Run: [CDAServer] C:\Program Files\Common Files\Common Desktop Agent\CDASrv.exe [438784 2010-12-17] ()
HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,
HKCU\...\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [39408 2012-03-27] (Google Inc.)
HKCU\...\Run: [HP Photosmart 5510 series (NET)] "C:\Program Files\HP\HP Photosmart 5510 series\Bin\ScanToPCActivationApp.exe" -deviceID "CN175050KX05NR:NW" -scfn "HP Photosmart 5510 series (NET)" -AutoStart 1 [2676584 2011-09-16] (Hewlett-Packard Co.)
HKCU\...\Run: [VoipBuster] "C:\Program Files (x86)\VoipBuster.com\VoipBuster\voipbuster.exe" -nosplash -minimized [19378496 2013-06-25] (VoipBuster)
HKCU\...\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun [1475584 2010-11-21] (Microsoft Corporation)
HKCU\...\Policies\system: [DisableRegistryTools] 0
HKLM-x32\...\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel(R) Rapid Storage Technology\IAStorIcon.exe [283160 2010-09-13] (Intel Corporation)
HKLM-x32\...\Run: [ISBMgr.exe] "C:\Program Files (x86)\Sony\ISB Utility\ISBMgr.exe" [2757312 2011-02-15] (Sony Corporation)
HKLM-x32\...\Run: [PMBVolumeWatcher] c:\Program Files (x86)\Sony\PMB\PMBVolumeWatcher.exe [648032 2010-11-27] (Sony Corporation)
HKLM-x32\...\Run: []  [x]
HKLM-x32\...\Run: [HP Software Update] C:\Program Files (x86)\Hp\HP Software Update\HPWuSchd2.exe [49208 2011-03-24] (Hewlett-Packard)
HKLM-x32\...\Run: [STO Backup Service] C:\Program Files (x86)\SmarThru Office\BackUpSvr.exe [199760 2012-01-13] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [STO Launcher Service] C:\Program Files (x86)\SmarThru Office\x64\LegacyLauncher.exe /autorun [405584 2012-01-13] (Samsung Electronics Co., Ltd.)
HKLM-x32\...\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe [929272 2013-04-03] (Sophos Limited)
HKLM-x32\...\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-03-20] (Geek Software GmbH)
HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-05-11] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" [253816 2013-03-12] (Oracle Corporation)
AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~2\sophos_detoured_x64.dll [218256 2013-04-03] (Sophos Limited)
AppInit_DLLs-x32: C:\PROGRA~2\Sophos\SOPHOS~2\sophos_detoured.dll [221840 2013-04-03] (Sophos Limited)
Startup: C:\ProgramData\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk
ShortcutTarget: HP Digital Imaging Monitor.lnk -> C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe (Hewlett-Packard Co.)
Startup: C:\ProgramData\Start Menu\Programs\Startup\Secunia PSI Tray.lnk
ShortcutTarget: Secunia PSI Tray.lnk -> C:\Program Files (x86)\Secunia\PSI\psi_tray.exe (Secunia)
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Daniel\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
Startup: C:\Users\Daniel\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.1.lnk
ShortcutTarget: OpenOffice.org 3.4.1.lnk -> C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
BootExecute: autocheck autochk * sdnclean64.exe

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.wikipedia.org/
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
SearchScopes: HKCU - {623BD34C-6486-4770-B994-92555203C850} URL = hxxp://rover.ebay.com/rover/1/710-42480-16445-33/4?mpre=hxxp://shop.ebay.co.uk/?oemInLn=ieSrch-Q311&_nkw={searchTerms}
SearchScopes: HKCU - {8C1B1A63-658F-4F07-BDC0-B7765C458695} URL = hxxp://services.zinio.com/search?s={searchTerms}&rf=sonyslices
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
BHO-x32: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll (Hewlett-Packard Co.)
BHO-x32: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
BHO-x32: SwissAcademic.Citavi.Picker.IEPicker - {609D670F-B735-4da7-AC6D-F3BD358E325E} - C:\Windows\\SysWOW64\mscoree.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Bluetooth Suite\IEPlugIn.dll (Atheros Commnucations)
BHO-x32: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
BHO-x32: Skype Browser Helper - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
BHO-x32: Bing Bar Helper - {d2ce3e00-f94a-4740-988e-03dc2f38c34f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll (Hewlett-Packard Co.)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKLM-x32 - Bing Bar - {8dcb7100-df86-4384-8842-8fa844297b3f} - C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll (Microsoft Corporation.)
Toolbar: HKLM-x32 - Freecorder 6 - {6B34ACCF-1B63-4E1A-8633-461917C75544} - C:\Program Files (x86)\Freecorder 6\tbcore3.dll ()
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
Toolbar: HKCU - Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
Toolbar: HKCU - No Name - {6B34ACCF-1B63-4E1A-8633-461917C75544} -  No File
DPF: HKLM-x32 {1ABA5FAC-1417-422B-BA82-45C35E2C908B} hxxp://kitchenplanner.ikea.com/DE/Core/Player/2020PlayerAX_IKEA_Win32.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} -  No File
Handler-x32: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL (Skype Technologies)
Winsock: Catalog9 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9 20 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp.dll [88128] (Sophos Limited)
Winsock: Catalog9-x64 01 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 02 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 03 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 04 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 05 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 06 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 07 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 08 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Winsock: Catalog9-x64 20 C:\ProgramData\Sophos\Web Intelligence\swi_ifslsp_64.dll [132088] (Sophos Limited)
Tcpip\Parameters: [DhcpNameServer] 141.2.22.74 141.2.149.10
Tcpip\..\Interfaces\{F6BFC1EA-082D-4450-A95B-BF5334CE4940}: [NameServer]141.2.22.74,141.2.149.10

FireFox:
========
FF ProfilePath: C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default
FF NewTab: www.bl.uk
FF SelectedSearchEngine: Google
FF Homepage: hxxp://www.bl.uk/
FF Keyword.URL: hxxp://www.google.com/search?q=
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll ()
FF Plugin: @java.com/DTPlugin,version=10.9.2 - C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF Plugin: @microsoft.com/GENUINE - disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.25.2 - C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.25.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE - disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @videolan.org/vlc,version=2.0.7 - C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin HKCU: @talk.google.com/GoogleTalkPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF Plugin HKCU: @talk.google.com/O1DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF Plugin HKCU: @talk.google.com/O3DPlugin - C:\Users\Daniel\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF Plugin HKCU: @tools.google.com/Google Update;version=3 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Plugin HKCU: @tools.google.com/Google Update;version=9 - C:\Users\Daniel\AppData\Local\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF Extension: Visualisateur 3D de 20-20 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\2020Player_IKEA@2020Technologies.com
FF Extension: Deutsches Wörterbuch - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\de-DE@dictionaries.addons.mozilla.org
FF Extension: Freecorder 6 - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{132E58DE-22BF-44CA-A061-7FCE1E8BA1EC}
FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{37E4D8EA-8BDA-4831-8EA1-89053939A250}.xpi
FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}.xpi
FF Extension: No Name - C:\Users\Daniel\AppData\Roaming\Mozilla\Firefox\Profiles\16xncyrs.default\Extensions\{e8f509f0-b677-11de-8a39-0800200c9a66}.xpi
FF Extension: Skype Click to Call - C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
FF Extension: Default - C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
FF HKLM-x32\...\Firefox\Extensions: [quickprint@hp.com] C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF Extension: SmartPrintButton - C:\Program Files (x86)\Hewlett-Packard\SmartPrint\QPExtension
FF HKLM-x32\...\Firefox\Extensions: [{8AA36F4F-6DC7-4c06-77AF-5035170634FE}] C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF Extension: Citavi Picker - C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox
FF HKLM-x32\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF HKCU\...\Firefox\Extensions: [smartwebprinting@hp.com] C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3
FF Extension: HP Smart Web Printing - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3

==================== Services (Whitelisted) =================

S3 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 Atheros Bt&Wlan Coex Agent; C:\Program Files (x86)\Bluetooth Suite\Ath_CoexAgent.exe [146592 2011-04-29] (Atheros)
S3 DCDhcpService; C:\Program Files\Sony\VAIO Smart Network\WFDA\DCDhcpService.exe [104096 2011-07-19] (Atheros Communication Inc.)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation)
R2 Samsung Network Fax Server; C:\Windows\system32\spool\drivers\x64\3\NetFaxServer64.exe [231936 2012-03-22] (Samsung Electronics Co., Ltd.)
R2 SAVAdminService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe [217592 2013-04-03] (Sophos Limited)
R2 SAVService; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe [159296 2013-04-03] (Sophos Limited)
S3 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.)
R3 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.)
S3 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.)
R2 Secunia PSI Agent; C:\Program Files (x86)\Secunia\PSI\PSIA.exe [1227800 2013-04-18] (Secunia)
S2 Secunia Update Agent; C:\Program Files (x86)\Secunia\PSI\sua.exe [659992 2013-04-18] (Secunia)
R2 Sophos AutoUpdate Service; C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe [237048 2013-04-03] (Sophos Limited)
R2 Sophos Web Control Service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe [357400 2013-04-03] (Sophos Limited)
R2 swi_service; C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe [2890232 2013-04-03] (Sophos Limited)
S2 swi_update_64; C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe [2010688 2013-04-03] (Sophos Limited)
R2 uCamMonitor; C:\Program Files (x86)\ArcSoft\Magic-i Visual Effects 2\uCamMonitor.exe [105024 2011-02-23] (ArcSoft, Inc.)
R3 VUAgent; C:\Program Files\Sony\VAIO Update\VUAgent.exe [1359408 2013-03-26] (Sony Corporation)

==================== Drivers (Whitelisted) ====================

R3 ArcSoftKsUFilter; C:\Windows\System32\DRIVERS\ArcSoftKsUFilter.sys [19968 2009-05-26] (ArcSoft, Inc.)
R3 PSI; C:\Windows\System32\DRIVERS\psi_mf_amd64.sys [18456 2013-04-18] (Secunia)
R1 SAVOnAccess; C:\Windows\System32\DRIVERS\savonaccess.sys [154952 2013-04-03] (Sophos Limited)
S3 sdcfilter; C:\Windows\System32\DRIVERS\sdcfilter.sys [36640 2013-04-03] (Sophos Limited)
S3 Serial; C:\Windows\system32\drivers\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
S4 SophosBootDriver; C:\Windows\System32\DRIVERS\SophosBootDriver.sys [25608 2013-04-03] (Sophos Plc)
S3 catchme; \??\C:\ComboFix\catchme.sys [x]

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2013-07-09 11:03 - 2013-07-09 11:03 - 00000000 ____D C:\FRST
2013-07-09 11:01 - 2013-07-09 11:01 - 01776219 ____A (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2013-07-07 10:04 - 2013-07-07 10:03 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-07-07 10:04 - 2013-07-07 10:03 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-07-07 10:04 - 2013-07-07 10:03 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-07-07 10:04 - 2013-07-07 10:03 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-07-07 09:56 - 2013-07-07 09:56 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-07-07 09:54 - 2013-07-07 09:54 - 00903080 ____A (Oracle Corporation) C:\Users\Daniel\Desktop\jxpiinstall.exe
2013-07-05 11:17 - 2013-07-05 11:17 - 00001075 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-05 11:16 - 2013-07-05 11:16 - 00002521 ____A C:\Users\Public\Desktop\Skype.lnk
2013-07-05 11:04 - 2013-07-05 11:04 - 00000000 ____D C:\Users\Daniel\AppData\Local\Secunia PSI
2013-07-05 11:04 - 2013-07-05 11:04 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-07-05 11:03 - 2013-07-05 11:03 - 03270960 ____A (Secunia) C:\Users\Daniel\Desktop\PSISetup7009.exe
2013-07-04 23:09 - 2013-07-04 23:09 - 00000000 ____D C:\ProgramData\Qualcomm Atheros
2013-07-04 22:58 - 2013-07-04 22:58 - 00000032 ____A C:\Windows\SysWOW64\setup.log
2013-07-04 22:57 - 2013-07-04 22:57 - 00000000 ____D C:\Program Files (x86)\Atheros WiFi Driver Installation
2013-07-04 22:57 - 2011-06-29 17:46 - 00066623 ____A C:\Windows\System32\athrextx.cat
2013-07-04 22:57 - 2011-06-21 01:03 - 02753536 ____A (Atheros Communications, Inc.) C:\Windows\System32\Drivers\athrx.sys
2013-07-04 22:57 - 2011-06-21 01:03 - 02753536 ____A (Atheros Communications, Inc.) C:\Windows\System32\athrx.sys
2013-07-04 22:54 - 2013-07-04 22:54 - 00005808 ____A C:\Windows\DPINST.LOG
2013-07-04 22:49 - 2013-07-04 22:49 - 00000000 ____D C:\Program Files (x86)\Realtek
2013-07-04 22:49 - 2012-03-12 06:08 - 09888872 ____A (Realtek Semiconductor Corp.) C:\Windows\SysWOW64\RtsPStorIcon.dll
2013-07-04 22:49 - 2012-03-12 06:08 - 00340072 ____A (Realtek Semiconductor Corp.) C:\Windows\System32\Drivers\RtsPStor.sys
2013-07-04 22:10 - 2012-08-23 16:13 - 00243200 ____A (Microsoft Corporation) C:\Windows\System32\rdpudd.dll
2013-07-04 22:10 - 2012-08-23 16:10 - 00019456 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\rdpvideominiport.sys
2013-07-04 22:10 - 2012-08-23 16:08 - 00030208 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbGD.sys
2013-07-04 22:10 - 2012-08-23 16:07 - 00057856 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\TsUsbFlt.sys
2013-07-04 22:10 - 2012-08-23 15:47 - 00046592 ____A (Microsoft Corporation) C:\Windows\SysWOW64\MsRdpWebAccess.dll
2013-07-04 22:10 - 2012-08-23 15:46 - 00016896 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wksprtPS.dll
2013-07-04 22:10 - 2012-08-23 15:41 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyControl.exe
2013-07-04 22:10 - 2012-08-23 15:40 - 00013312 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbRedirectionGroupPolicyExtension.dll
2013-07-04 22:10 - 2012-08-23 15:24 - 00015360 ____A (Microsoft Corporation) C:\Windows\System32\RdpGroupPolicyExtension.dll
2013-07-04 22:10 - 2012-08-23 15:20 - 00054272 ____A (Microsoft Corporation) C:\Windows\System32\MsRdpWebAccess.dll
2013-07-04 22:10 - 2012-08-23 15:18 - 00037376 ____A (Microsoft Corporation) C:\Windows\SysWOW64\tsgqec.dll
2013-07-04 22:10 - 2012-08-23 15:17 - 00018432 ____A (Microsoft Corporation) C:\Windows\System32\wksprtPS.dll
2013-07-04 22:10 - 2012-08-23 15:06 - 00043520 ____A (Microsoft Corporation) C:\Windows\System32\TsUsbGDCoInstaller.dll
2013-07-04 22:10 - 2012-08-23 14:52 - 00044032 ____A (Microsoft Corporation) C:\Windows\System32\tsgqec.dll
2013-07-04 22:10 - 2012-08-23 13:20 - 00062976 ____A (Microsoft Corporation) C:\Windows\System32\TSWbPrxy.exe
2013-07-04 22:10 - 2012-08-23 13:15 - 00269312 ____A (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2013-07-04 22:10 - 2012-08-23 13:14 - 00384000 ____A (Microsoft Corporation) C:\Windows\System32\wksprt.exe
2013-07-04 22:10 - 2012-08-23 13:12 - 00192000 ____A (Microsoft Corporation) C:\Windows\SysWOW64\rdpendp_winip.dll
2013-07-04 22:10 - 2012-08-23 12:54 - 00322560 ____A (Microsoft Corporation) C:\Windows\System32\aaclient.dll
2013-07-04 22:10 - 2012-08-23 12:51 - 00228864 ____A (Microsoft Corporation) C:\Windows\System32\rdpendp_winip.dll
2013-07-04 22:10 - 2012-08-23 12:39 - 01048064 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2013-07-04 22:10 - 2012-08-23 12:22 - 01123840 ____A (Microsoft Corporation) C:\Windows\System32\mstsc.exe
2013-07-04 22:10 - 2012-08-23 11:51 - 03174912 ____A (Microsoft Corporation) C:\Windows\System32\rdpcorets.dll
2013-07-04 22:10 - 2012-08-23 10:19 - 04916224 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2013-07-04 22:10 - 2012-08-23 10:13 - 05773824 ____A (Microsoft Corporation) C:\Windows\System32\mstscax.dll
2013-07-04 22:09 - 2012-08-24 20:13 - 00154480 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\ksecpkg.sys
2013-07-04 22:09 - 2012-08-24 20:09 - 00458712 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\cng.sys
2013-07-04 22:09 - 2012-08-24 20:05 - 00340992 ____A (Microsoft Corporation) C:\Windows\System32\schannel.dll
2013-07-04 22:09 - 2012-08-24 20:03 - 01448448 ____A (Microsoft Corporation) C:\Windows\System32\lsasrv.dll
2013-07-04 22:09 - 2012-08-24 18:57 - 00247808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\schannel.dll
2013-07-04 22:09 - 2012-08-24 18:57 - 00022016 ____A (Microsoft Corporation) C:\Windows\SysWOW64\secur32.dll
2013-07-04 22:09 - 2012-08-24 18:53 - 00096768 ____A (Microsoft Corporation) C:\Windows\SysWOW64\sspicli.dll
2013-07-04 22:09 - 2012-05-04 13:00 - 00366592 ____A (Microsoft Corporation) C:\Windows\System32\qdvd.dll
2013-07-04 22:09 - 2012-05-04 11:59 - 00514560 ____A (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2013-07-04 18:44 - 2013-07-04 23:26 - 00000000 ____D C:\Update
2013-07-04 18:28 - 2013-07-04 18:31 - 00001398 ____A C:\DelFix.txt
2013-07-04 18:24 - 2013-07-04 19:48 - 00000000 ___SD C:\ComboFix
2013-07-04 06:47 - 2013-07-04 08:58 - 00074277 ____A C:\Users\Daniel\Desktop\Problems of the historical and literary classification of.pptx
2013-07-03 11:11 - 2013-07-04 18:29 - 00000000 ____D C:\Windows\ERUNT
2013-07-03 10:50 - 2013-07-08 10:23 - 00039146 ____A C:\Windows\PFRO.log
2013-07-02 19:40 - 2013-07-02 19:51 - 00000000 ____D C:\Windows\erdnt
2013-07-02 16:04 - 2013-07-02 16:04 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-07-02 16:02 - 2013-07-02 16:03 - 04396440 ____A (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup403.exe
2013-07-01 15:40 - 2013-07-01 15:47 - 00001434 ____A C:\Users\Daniel\Downloads\Antrag auf Ausstellung einer Bescheinigung für den Lohnsteuerabzug 2013.xml
2013-06-26 14:28 - 2013-06-26 16:02 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-06-25 14:34 - 2013-06-25 14:34 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
2013-06-21 11:47 - 2013-06-21 11:47 - 00150406 ____A C:\Users\Daniel\Documents\1662.ppsx
2013-06-19 08:07 - 2013-06-19 08:08 - 00004802 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log
2013-06-17 23:38 - 2013-06-17 23:42 - 00084339 ____A C:\Users\Daniel\Desktop\Briefvorlage-Birnstiel.dotx
2013-06-16 12:36 - 2013-06-08 16:08 - 01365504 ____A (Microsoft Corporation) C:\Windows\System32\urlmon.dll
2013-06-16 12:36 - 2013-06-08 16:07 - 19233792 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.dll
2013-06-16 12:36 - 2013-06-08 16:06 - 15404544 ____A (Microsoft Corporation) C:\Windows\System32\ieframe.dll
2013-06-16 12:36 - 2013-06-08 16:06 - 02648064 ____A (Microsoft Corporation) C:\Windows\System32\iertutil.dll
2013-06-16 12:36 - 2013-06-08 16:06 - 00526336 ____A (Microsoft Corporation) C:\Windows\System32\ieui.dll
2013-06-16 12:36 - 2013-06-08 14:28 - 02706432 ____A (Microsoft Corporation) C:\Windows\System32\mshtml.tlb
2013-06-16 12:36 - 2013-06-08 13:42 - 01141248 ____A (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2013-06-16 12:36 - 2013-06-08 13:40 - 14327808 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2013-06-16 12:36 - 2013-06-08 13:40 - 13760512 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2013-06-16 12:36 - 2013-06-08 13:40 - 02046976 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2013-06-16 12:36 - 2013-06-08 13:40 - 00391168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2013-06-16 12:36 - 2013-06-08 13:13 - 02706432 ____A (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2013-06-14 10:17 - 2013-06-20 15:13 - 00016101 ____A C:\Users\Daniel\Documents\Korrespondenztabelle.xlsx
2013-06-12 17:54 - 2013-06-20 10:32 - 00011854 ____A C:\Users\Daniel\Desktop\PruefungstermineSoSe2013.xlsx
2013-06-12 09:49 - 2013-05-17 03:25 - 02877440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 01767936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00690688 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jscript.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00493056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00109056 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesysprep.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00061440 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00039424 ____A (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2013-06-12 09:49 - 2013-05-17 03:25 - 00033280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2013-06-12 09:49 - 2013-05-17 02:59 - 02241024 ____A (Microsoft Corporation) C:\Windows\System32\wininet.dll
2013-06-12 09:49 - 2013-05-17 02:59 - 00051712 ____A (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe
2013-06-12 09:49 - 2013-05-17 02:58 - 03958784 ____A (Microsoft Corporation) C:\Windows\System32\jscript9.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00855552 ____A (Microsoft Corporation) C:\Windows\System32\jscript.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00603136 ____A (Microsoft Corporation) C:\Windows\System32\msfeeds.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00136704 ____A (Microsoft Corporation) C:\Windows\System32\iesysprep.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00067072 ____A (Microsoft Corporation) C:\Windows\System32\iesetup.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00053248 ____A (Microsoft Corporation) C:\Windows\System32\jsproxy.dll
2013-06-12 09:49 - 2013-05-17 02:58 - 00039936 ____A (Microsoft Corporation) C:\Windows\System32\iernonce.dll
2013-06-12 09:49 - 2013-05-14 14:23 - 00089600 ____A (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe
2013-06-12 09:49 - 2013-05-14 10:40 - 00071680 ____A (Microsoft Corporation) C:\Windows\SysWOW64\RegisterIEPKEYs.exe
2013-06-12 01:28 - 2013-05-13 07:51 - 01464320 ____A (Microsoft Corporation) C:\Windows\System32\crypt32.dll
2013-06-12 01:28 - 2013-05-13 07:51 - 00184320 ____A (Microsoft Corporation) C:\Windows\System32\cryptsvc.dll
2013-06-12 01:28 - 2013-05-13 07:51 - 00139776 ____A (Microsoft Corporation) C:\Windows\System32\cryptnet.dll
2013-06-12 01:28 - 2013-05-13 07:50 - 00052224 ____A (Microsoft Corporation) C:\Windows\System32\certenc.dll
2013-06-12 01:28 - 2013-05-13 06:45 - 01160192 ____A (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2013-06-12 01:28 - 2013-05-13 06:45 - 00140288 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2013-06-12 01:28 - 2013-05-13 06:45 - 00103936 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptnet.dll
2013-06-12 01:28 - 2013-05-13 05:43 - 01192448 ____A (Microsoft Corporation) C:\Windows\System32\certutil.exe
2013-06-12 01:28 - 2013-05-13 05:08 - 00903168 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certutil.exe
2013-06-12 01:28 - 2013-05-13 05:08 - 00043008 ____A (Microsoft Corporation) C:\Windows\SysWOW64\certenc.dll
2013-06-12 01:28 - 2013-05-10 07:49 - 00030720 ____A (Microsoft Corporation) C:\Windows\System32\cryptdlg.dll
2013-06-12 01:28 - 2013-05-10 05:20 - 00024576 ____A (Microsoft Corporation) C:\Windows\SysWOW64\cryptdlg.dll
2013-06-12 01:28 - 2013-05-08 08:39 - 01910632 ____A (Microsoft Corporation) C:\Windows\System32\Drivers\tcpip.sys
2013-06-12 01:28 - 2013-04-26 07:51 - 00751104 ____A (Microsoft Corporation) C:\Windows\System32\win32spl.dll
2013-06-12 01:28 - 2013-04-26 06:55 - 00492544 ____A (Microsoft Corporation) C:\Windows\SysWOW64\win32spl.dll
2013-06-12 01:28 - 2013-04-26 01:30 - 01505280 ____A (Microsoft Corporation) C:\Windows\SysWOW64\d3d11.dll
2013-06-12 01:28 - 2013-04-17 09:02 - 01230336 ____A (Microsoft Corporation) C:\Windows\SysWOW64\WindowsCodecs.dll
2013-06-12 01:28 - 2013-04-17 08:24 - 01424384 ____A (Microsoft Corporation) C:\Windows\System32\WindowsCodecs.dll
2013-06-12 01:28 - 2013-04-01 00:52 - 01887232 ____A (Microsoft Corporation) C:\Windows\System32\d3d11.dll
2013-06-11 22:38 - 2013-07-09 08:57 - 00012952 ____A C:\Windows\setupact.log
2013-06-11 22:38 - 2013-06-11 22:38 - 00000000 ____A C:\Windows\setuperr.log
2013-06-11 15:06 - 2013-06-11 15:06 - 00000165 ___AH C:\Users\Daniel\Desktop\~$pruefungen.xlsx
2013-06-10 18:25 - 2013-06-13 10:16 - 00012345 ____A C:\Users\Daniel\Desktop\pruefungen.xlsx
2013-06-10 16:58 - 2013-06-10 16:58 - 00000000 ____D C:\Users\Daniel\Documents\maiko_doc

==================== One Month Modified Files and Folders =======

2013-07-09 11:03 - 2013-07-09 11:03 - 00000000 ____D C:\FRST
2013-07-09 11:01 - 2013-07-09 11:01 - 01776219 ____A (Farbar) C:\Users\Daniel\Desktop\FRST64.exe
2013-07-09 11:01 - 2012-04-06 15:34 - 00000258 ____A C:\Windows\Tasks\HP Photo Creations Messager.job
2013-07-09 10:51 - 2013-01-21 11:26 - 00000830 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job
2013-07-09 10:38 - 2012-03-27 19:43 - 00000898 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2013-07-09 10:16 - 2012-04-04 15:20 - 00000912 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job
2013-07-09 09:38 - 2012-03-27 19:43 - 00000894 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2013-07-09 09:08 - 2012-02-06 14:45 - 01168361 ____A C:\Windows\WindowsUpdate.log
2013-07-09 08:57 - 2013-06-11 22:38 - 00012952 ____A C:\Windows\setupact.log
2013-07-09 08:54 - 2012-03-26 14:58 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Dropbox
2013-07-09 08:33 - 2009-07-14 06:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2013-07-09 08:33 - 2009-07-14 06:45 - 00021200 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2013-07-09 08:26 - 2012-03-26 15:06 - 00000000 ___RD C:\Users\Daniel\Dropbox
2013-07-09 08:24 - 2009-07-14 07:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT
2013-07-09 06:33 - 2012-04-04 15:20 - 00000860 ____A C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job
2013-07-08 12:24 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\System32\NDF
2013-07-08 12:17 - 2012-03-25 16:55 - 00000000 ____D C:\Users\Daniel\AppData\Local\CrashDumps
2013-07-08 10:31 - 2012-11-22 16:29 - 00000099 ____A C:\Users\Public\LMDebug.log
2013-07-08 10:23 - 2013-07-03 10:50 - 00039146 ____A C:\Windows\PFRO.log
2013-07-07 10:03 - 2013-07-07 10:04 - 00263592 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2013-07-07 10:03 - 2013-07-07 10:04 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2013-07-07 10:03 - 2013-07-07 10:04 - 00175016 ____A (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2013-07-07 10:03 - 2013-07-07 10:04 - 00096168 ____A (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2013-07-07 10:03 - 2012-12-07 17:18 - 00867240 ____A (Oracle Corporation) C:\Windows\SysWOW64\npDeployJava1.dll
2013-07-07 10:03 - 2012-02-06 14:56 - 00789416 ____A (Oracle Corporation) C:\Windows\SysWOW64\deployJava1.dll
2013-07-07 09:57 - 2012-03-25 21:18 - 00000000 ____D C:\Users\Daniel\AppData\Local\Adobe
2013-07-07 09:56 - 2013-07-07 09:56 - 00002019 ____A C:\Users\Public\Desktop\Adobe Reader XI.lnk
2013-07-07 09:56 - 2012-02-06 15:09 - 00000000 ____D C:\ProgramData\Adobe
2013-07-07 09:56 - 2012-02-06 15:09 - 00000000 ____D C:\Program Files (x86)\Adobe
2013-07-07 09:54 - 2013-07-07 09:54 - 00903080 ____A (Oracle Corporation) C:\Users\Daniel\Desktop\jxpiinstall.exe
2013-07-05 12:44 - 2012-04-15 21:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Skype
2013-07-05 11:45 - 2013-05-16 23:36 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-07-05 11:45 - 2012-04-24 23:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2013-07-05 11:17 - 2013-07-05 11:17 - 00001075 ____A C:\Users\Public\Desktop\Mozilla Firefox.lnk
2013-07-05 11:16 - 2013-07-05 11:16 - 00002521 ____A C:\Users\Public\Desktop\Skype.lnk
2013-07-05 11:16 - 2012-02-06 15:24 - 00000000 ___RD C:\Program Files (x86)\Skype
2013-07-05 11:16 - 2012-02-06 15:24 - 00000000 ____D C:\ProgramData\Skype
2013-07-05 11:13 - 2012-02-06 14:56 - 00000000 ____D C:\Program Files (x86)\Java
2013-07-05 11:10 - 2012-02-06 14:56 - 00000000 ____D C:\Program Files\Java
2013-07-05 11:04 - 2013-07-05 11:04 - 00000000 ____D C:\Users\Daniel\AppData\Local\Secunia PSI
2013-07-05 11:04 - 2013-07-05 11:04 - 00000000 ____D C:\Program Files (x86)\Secunia
2013-07-05 11:03 - 2013-07-05 11:03 - 03270960 ____A (Secunia) C:\Users\Daniel\Desktop\PSISetup7009.exe
2013-07-05 00:33 - 2012-02-06 14:48 - 00000000 ___HD C:\Program Files (x86)\InstallShield Installation Information
2013-07-05 00:16 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\rescache
2013-07-04 23:26 - 2013-07-04 18:44 - 00000000 ____D C:\Update
2013-07-04 23:25 - 2012-02-06 14:59 - 00000000 ____D C:\Documentation
2013-07-04 23:22 - 2012-03-12 21:10 - 00000000 ____D C:\Users\Daniel\Documents\Bluetooth Folder
2013-07-04 23:11 - 2012-02-06 14:56 - 00000000 ____D C:\Program Files (x86)\Sony
2013-07-04 23:11 - 2012-02-06 14:44 - 00000000 ____D C:\ProgramData\Sony Corporation
2013-07-04 23:11 - 2012-02-06 14:40 - 00000000 ____D C:\Program Files\Sony
2013-07-04 23:09 - 2013-07-04 23:09 - 00000000 ____D C:\ProgramData\Qualcomm Atheros
2013-07-04 22:58 - 2013-07-04 22:58 - 00000032 ____A C:\Windows\SysWOW64\setup.log
2013-07-04 22:57 - 2013-07-04 22:57 - 00000000 ____D C:\Program Files (x86)\Atheros WiFi Driver Installation
2013-07-04 22:56 - 2012-02-06 15:29 - 00000000 ____D C:\ProgramData\Atheros
2013-07-04 22:54 - 2013-07-04 22:54 - 00005808 ____A C:\Windows\DPINST.LOG
2013-07-04 22:49 - 2013-07-04 22:49 - 00000000 ____D C:\Program Files (x86)\Realtek
2013-07-04 22:49 - 2012-02-06 14:53 - 00000000 ____D C:\Windows\SysWOW64\sda
2013-07-04 22:15 - 2009-07-14 05:20 - 00000000 ____D C:\Windows\PolicyDefinitions
2013-07-04 22:04 - 2011-02-11 01:03 - 00764746 ____A C:\Windows\SysWOW64\PerfStringBackup.INI
2013-07-04 22:03 - 2009-07-14 07:13 - 00764746 ____A C:\Windows\System32\PerfStringBackup.INI
2013-07-04 19:48 - 2013-07-04 18:24 - 00000000 ___SD C:\ComboFix
2013-07-04 18:31 - 2013-07-04 18:28 - 00001398 ____A C:\DelFix.txt
2013-07-04 18:29 - 2013-07-03 11:11 - 00000000 ____D C:\Windows\ERUNT
2013-07-04 18:20 - 2012-03-12 21:09 - 00000000 ____D C:\users\Daniel
2013-07-04 09:17 - 2013-02-22 22:33 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\vlc
2013-07-04 08:58 - 2013-07-04 06:47 - 00074277 ____A C:\Users\Daniel\Desktop\Problems of the historical and literary classification of.pptx
2013-07-03 10:27 - 2009-07-14 04:34 - 00000215 ____A C:\Windows\system.ini
2013-07-03 10:22 - 2013-03-28 21:55 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy
2013-07-02 19:53 - 2009-07-14 05:20 - 00000000 __RHD C:\users\Default
2013-07-02 19:51 - 2013-07-02 19:40 - 00000000 ____D C:\Windows\erdnt
2013-07-02 16:04 - 2013-07-02 16:04 - 00000822 ____A C:\Users\Public\Desktop\CCleaner.lnk
2013-07-02 16:03 - 2013-07-02 16:02 - 04396440 ____A (Piriform Ltd) C:\Users\Daniel\Downloads\ccsetup403.exe
2013-07-02 16:03 - 2012-06-13 23:11 - 00000000 ____D C:\Program Files\CCleaner
2013-07-02 15:42 - 2013-05-02 00:35 - 00000000 ____D C:\Users\Daniel\Documents\shamela-r1
2013-07-02 15:42 - 2012-03-29 01:43 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\shamela
2013-07-01 15:47 - 2013-07-01 15:40 - 00001434 ____A C:\Users\Daniel\Downloads\Antrag auf Ausstellung einer Bescheinigung für den Lohnsteuerabzug 2013.xml
2013-06-28 16:48 - 2012-03-24 20:21 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\Mozilla
2013-06-27 08:44 - 2013-05-28 12:59 - 00177947 ____A C:\test.xml
2013-06-26 16:02 - 2013-06-26 14:28 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird
2013-06-26 13:54 - 2012-04-26 19:34 - 00000000 ____D C:\Users\Daniel\Documents\Citavi 3
2013-06-26 00:00 - 2012-07-25 18:26 - 00000000 ____D C:\Users\Daniel\Documents\Calibre Library
2013-06-25 14:34 - 2013-06-25 14:34 - 00001070 ____A C:\Users\Public\Desktop\VLC media player.lnk
2013-06-25 09:17 - 2012-03-27 19:42 - 00000000 ____D C:\Users\Daniel\AppData\Local\Google
2013-06-21 16:32 - 2012-07-07 22:14 - 00000000 ____D C:\Users\Daniel\AppData\Roaming\dvdcss
2013-06-21 11:47 - 2013-06-21 11:47 - 00150406 ____A C:\Users\Daniel\Documents\1662.ppsx
2013-06-20 15:13 - 2013-06-14 10:17 - 00016101 ____A C:\Users\Daniel\Documents\Korrespondenztabelle.xlsx
2013-06-20 10:32 - 2013-06-12 17:54 - 00011854 ____A C:\Users\Daniel\Desktop\PruefungstermineSoSe2013.xlsx
2013-06-19 08:08 - 2013-06-19 08:07 - 00004802 ____A C:\Windows\SysWOW64\jupdate-1.7.0_25-b16.log
2013-06-17 23:42 - 2013-06-17 23:38 - 00084339 ____A C:\Users\Daniel\Desktop\Briefvorlage-Birnstiel.dotx
2013-06-13 10:16 - 2013-06-10 18:25 - 00012345 ____A C:\Users\Daniel\Desktop\pruefungen.xlsx
2013-06-12 17:51 - 2012-04-30 21:30 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-06-12 17:51 - 2012-04-30 21:30 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-06-12 12:44 - 2011-02-11 00:48 - 00000000 ____D C:\Windows\Panther
2013-06-12 09:49 - 2012-03-24 18:57 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe
2013-06-11 22:38 - 2013-06-11 22:38 - 00000000 ____A C:\Windows\setuperr.log
2013-06-11 20:26 - 2009-07-14 07:08 - 00032620 ____A C:\Windows\Tasks\SCHEDLGU.TXT
2013-06-11 15:06 - 2013-06-11 15:06 - 00000165 ___AH C:\Users\Daniel\Desktop\~$pruefungen.xlsx
2013-06-10 16:58 - 2013-06-10 16:58 - 00000000 ____D C:\Users\Daniel\Documents\maiko_doc

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2013-07-03 20:07

==================== End Of Log ============================
         
--- --- ---


Hier auch noch das Addition Log:

Code:
ATTFilter
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 09-07-2013
Ran by Daniel at 2013-07-09 11:04:56
Running from C:\Users\Daniel\Desktop
Boot Mode: Normal
==========================================================


==================== Installed Programs =======================

   
 Update for Microsoft Office 2007 (KB2508958) (x32)
6000E609_eDocs (x32 Version: 1.00.0000)
6000E609_Help (x32 Version: 1.00.0000)
6000E609a (x32 Version: 140.0.000.000)
64 Bit HP CIO Components Installer (Version: 6.2.2)
7-Zip 9.20 (x64 edition) (Version: 9.20.00.0)
ActiveX контрола на Windows Live Mesh за отдалечени връзки (x32 Version: 15.4.5722.2)
ActiveX-kontroll för fjärranslutningar för Windows Live Mesh (x32 Version: 15.4.5722.2)
Adobe AIR (x32 Version: 3.7.0.2090)
Adobe Flash Player 11 ActiveX (x32 Version: 11.7.700.224)
Adobe Flash Player 11 Plugin (x32 Version: 11.7.700.224)
Adobe Reader XI (11.0.03) (x32 Version: 11.0.03)
Alps Pointing-device for VAIO
Amazon MP3 Downloader 1.0.9 (x32)
Amazon MP3-Downloader 1.0.9 (x32)
A-PDF Number freeware 1.3 (x32)
ArcSoft Magic-i Visual Effects 2 (x32 Version: 2.0.1.142)
ArcSoft WebCam Companion 4 (x32 Version: 4.0.21.392)
Atheros WiFi Driver Installation (x32 Version: 3.0)
BBC iPlayer Desktop (x32 Version: 3.0.11)
Bing Bar (x32 Version: 7.0.610.0)
Bluetooth Win7 Suite (64) (Version: 7.3.0.100)
BPDSoftware (x32 Version: 140.0.000.000)
BPDSoftware_Ini (x32 Version: 1.00.0000)
BufferChm (x32 Version: 140.0.213.000)
calibre (x32 Version: 0.9.29)
Citavi (x32 Version: 3.4.0.2)
Common Desktop Agent (Version: 1.53.0)
Conexant HD Audio (Version: 8.54.0.53)
Control ActiveX Windows Live Mesh pentru conexiuni la distanță (x32 Version: 15.4.5722.2)
Contrôle ActiveX Windows Live Mesh pour connexions à distance (x32 Version: 15.4.5722.2)
Controlo ActiveX do Windows Live Mesh para Ligações Remotas (x32 Version: 15.4.5722.2)
Coptic Unicode (Version: 1.0.3.40)
D3DX10 (x32 Version: 15.4.2368.0902)
Deutsch (Orientalistik) (Version: 1.0.3.40)
DeviceDiscovery (x32 Version: 140.0.213.000)
Dropbox (HKCU Version: 2.0.22)
eaner (Version: 4.03)
Formant ActiveX programu Windows Live Mesh odpowiedzialny za obsługę połączeń zdalnych (x32 Version: 15.4.5722.2)
Free Audio CD to MP3 Converter version 1.3.12.1228 (x32 Version: 1.3.12.1228)
Free YouTube to MP3 Converter version 3.11.22.508 (x32 Version: 3.11.22.508)
Freecorder 6 (x32 Version: 2.1.10)
Freecorder 6 Add-on for Firefox (x32 Version: 2.1.9)
Freecorder 6 Applications (6.0.0.36) (x32 Version: 6.0.0.36)
Galeria de Fotografias do Windows Live (x32 Version: 15.4.3502.0922)
Galeria fotografii usługi Windows Live (x32 Version: 15.4.3502.0922)
Galerie de photos Windows Live (x32 Version: 15.4.3502.0922)
Galerie foto Windows Live (x32 Version: 15.4.3502.0922)
Google Talk Plugin (x32 Version: 4.1.3.13728)
Google Toolbar for Internet Explorer (x32 Version: 1.0.0)
Google Toolbar for Internet Explorer (x32 Version: 7.5.4209.2358)
Google Update Helper (x32 Version: 1.3.21.149)
GPBaseService2 (x32 Version: 140.0.212.000)
HP Customer Participation Program 14.0 (Version: 14.0)
HP Imaging Device Functions 14.0 (Version: 14.0)
HP Officejet 6000 E609 Series (Version: 14.0)
HP Photo Creations (x32 Version: 1.0.0.5192)
HP Photosmart 5510 series Basic Device Software (Version: 25.0.621.0)
HP Photosmart 5510 series Help (x32 Version: 140.0.2.2)
HP Photosmart 5510 series Product Improvement Study (Version: 25.0.621.0)
HP Smart Web Printing 4.60 (Version: 4.60)
HP Solution Center 14.0 (Version: 14.0)
HP Update (x32 Version: 5.003.000.004)
HPProductAssistant (x32 Version: 140.0.213.000)
HPSSupply (x32 Version: 140.0.212.000)
iDRS(tm) OCR Software by I.R.I.S (x32 Version: 1.00.13.00)
Intel(R) Control Center (x32 Version: 1.2.1.1007)
Intel(R) Management Engine Components (x32 Version: 7.0.0.1144)
Intel(R) Processor Graphics (x32 Version: 8.15.10.2291)
Intel(R) Rapid Storage Technology (x32 Version: 10.0.0.1046)
Java 7 Update 25 (x32 Version: 7.0.250)
Java Auto Updater (x32 Version: 2.1.9.5)
Junk Mail filter update (x32 Version: 15.4.3502.0922)
MarketResearch (x32 Version: 140.0.214.000)
Media Gallery (Version: 1.5.0.16020)
Mesh Runtime (x32 Version: 15.4.5722.2)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319)
Microsoft .NET Framework 4 Extended (Version: 4.0.30319)
Microsoft Application Error Reporting (Version: 12.0.6015.5000)
Microsoft Office 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000)
Microsoft Office OneNote MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014)
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32)
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000)
Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000)
Microsoft Silverlight (Version: 5.1.20125.0)
Microsoft SQL Server 2005 Compact Edition [ENU] (x32 Version: 3.1.0000)
Microsoft Visual C++ 2005 Redistributable (x32 Version: 8.0.61001)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.59192)
Microsoft Visual C++ 2005 Redistributable (x64) (Version: 8.0.61000)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (x32 Version: 9.0.30729)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 (x32 Version: 9.0.30729.4148)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (x32 Version: 10.0.40219)
Mozilla Firefox 22.0 (x86 en-GB) (x32 Version: 22.0)
Mozilla Maintenance Service (x32 Version: 22.0)
Mozilla Thunderbird 17.0.7 (x86 en-US) (x32 Version: 17.0.7)
MSVCRT (x32 Version: 15.4.2862.0708)
MSVCRT_amd64 (x32 Version: 15.4.2862.0708)
MSXML 4.0 SP3 Parser (KB2721691) (x32 Version: 4.30.2114.0)
MSXML 4.0 SP3 Parser (KB2758694) (x32 Version: 4.30.2117.0)
MSXML 4.0 SP3 Parser (KB973685) (x32 Version: 4.30.2107.0)
MSXML 4.0 SP3 Parser (x32 Version: 4.30.2100.0)
Network64 (Version: 140.0.215.000)
OpenOffice.org 3.4.1 (x32 Version: 3.41.9593)
Ovládací prvek ActiveX platformy Windows Live Mesh pro vzdálená připojení (x32 Version: 15.4.5722.2)
Ovládací prvok ActiveX programu Windows Live Mesh pre vzdialené pripojenia (x32 Version: 15.4.5722.2)
PDF24 Creator 5.4.0 (x32)
PlayMemories Home Plug-in (Version: 2.0.00.14170)
PlayMemories Home/PMB VAIO Edition Plug-in Ver.2.2 Upgrade Program (x32 Version: 2.2.00.18250)
PMB (x32 Version: 5.5.02.12220)
PMB VAIO Edition Plug-in (x32 Version: 1.6.00.06010)
Poczta usługi Windows Live (x32 Version: 15.4.3502.0922)
Podstawowe programy Windows Live (x32 Version: 15.4.3502.0922)
ProductContext (x32 Version: 140.0.000.000)
Qualcomm Atheros Direct Connect (x32 Version: 3.0)
Raccolta foto di Windows Live (x32 Version: 15.4.3502.0922)
Realtek PCIE Card Reader (x32 Version: 6.1.7601.92)
Remote Keyboard (x32 Version: 1.1.1.07060)
Remote Play with PlayStation 3 (x32 Version: 1.1.0.15070)
Samsung Easy Printer Manager (x32 Version: 1.02.06.10)
Samsung Network PC Fax (x32 Version: 1.05.29.00)
Samsung Printer Live Update (x32 Version: 1.01.00:04(2013-04-22))
Samsung Scan Assistant (x32 Version: 1.04.45.00)
Samsung SCX-3400 Series (x32 Version: 1.08 (07/05/2012))
Secunia PSI (3.0.0.7009) (x32 Version: 3.0.0.7009)
SetIP (x32 Version: 1.05.03.00)
Shared Add-in Extensibility Update for Microsoft .NET Framework 2.0 (KB908002) (x32 Version: 1.0.0)
Shared Add-in Support Update for Microsoft .NET Framework 2.0 (KB908002) (x32 Version: 1.0.0)
Shop for HP Supplies (Version: 14.0)
Skype Click to Call (x32 Version: 5.9.9216)
Skype™ 6.3 (x32 Version: 6.3.105)
SmarThru Office (x32 Version: 2.08.018)
SmartWebPrinting (x32 Version: 140.0.213.000)
SolutionCenter (x32 Version: 140.0.214.000)
Sony Corporation (Version: 1.0.0)
Sophos Anti-Virus (x32 Version: 10.2.8)
Sophos AutoUpdate (x32 Version: 2.9.0.344)
Sophos Virus Removal Tool (x32 Version: 2.3)
Spybot - Search & Destroy (x32 Version: 2.0.12)
SSLx64 (Version: 1.0.0)
SSLx86 (x32 Version: 1.0.0)
Status (x32 Version: 140.0.256.000)
Toolbox (x32 Version: 140.0.428.000)
TrayApp (x32 Version: 140.0.213.000)
Update for 2007 Microsoft Office System (KB967642) (x32)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2468871) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2533523) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2600217) (x32 Version: 1)
Update for Microsoft .NET Framework 4 Extended (KB2836939) (x32 Version: 1)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (x32)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596660) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2596848) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32)
Update for Microsoft Office Excel 2007 Help (KB963678) (x32)
Update for Microsoft Office OneNote 2007 Help (KB963670) (x32)
Update for Microsoft Office Powerpoint 2007 Help (KB963669) (x32)
Update for Microsoft Office Script Editor Help (KB963671) (x32)
Update for Microsoft Office Word 2007 Help (KB963665) (x32)
Uzak Bağlantılar İçin Windows Live Mesh ActiveX Denetimi (x32 Version: 15.4.5722.2)
VAIO - Media Gallery (x32 Version: 1.5.0.16020)
VAIO - PlayMemories Home Plug-in (x32 Version: 2.2.00.18250)
VAIO - PMB VAIO Edition Guide (x32 Version: 1.6.00.06030)
VAIO - Remote Keyboard (x32 Version: 1.1.0.07060)
VAIO - Remote Play with PlayStation®3 (x32 Version: 1.1.0.15070)
VAIO Care (x32 Version: 6.4.2.11150)
VAIO Control Center (x32 Version: 4.5.0.03040)
VAIO Data Restore Tool (x32 Version: 1.6.0.13140)
VAIO Easy Connect (x32 Version: 1.1.2.01120)
VAIO Event Service (x32 Version: 5.5.0.03040)
VAIO Gate (x32 Version: 2.3.0.11090)
VAIO Gate Default (x32 Version: 2.4.0.03240)
VAIO Hardware Diagnostics (x32 Version: 4.2.0.14280)
VAIO Hero Screensaver - Summer 2011 Screensaver (x32)
VAIO Improvement (x32 Version: 1.0.0.14150)
VAIO Improvement Validation (Version: 1.0.4.01190)
VAIO Manual (x32 Version: 2.0.0.02250)
VAIO Quick Web Access (x32 Version: 1.4.5.3)
VAIO Sample Contents (x32 Version: 1.4.2.09010)
VAIO Smart Network (x32 Version: 3.8.0.08120)
VAIO Transfer Support (x32 Version: 1.4.0.14230)
VAIO Update (x32 Version: 6.2.1.03260)
VCCx86 (x32 Version: 1.0.0)
VESx64 (Version: 1.0.0)
VESx86 (x32 Version: 1.0.0)
VIx64 (Version: 1.0.0)
VIx86 (x32 Version: 1.0.0)
VLC media player 2.0.7 (x32 Version: 2.0.7)
VoipBuster (x32 Version: 4.12 build 689)
VSNx64 (Version: 1.0.0)
VSNx86 (x32 Version: 1.0.0)
VU5x64 (Version: 1.1.0)
VU5x86 (x32 Version: 1.1.0)
VWSTx86 (x32 Version: 1.0.0)
WebReg (x32 Version: 140.0.213.017)
Willi 2.120 (x32)
WinDjView 2.0.2 (Version: 2.0.2)
Windows Live Communications Platform (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3502.0922)
Windows Live Essentials (x32 Version: 15.4.3508.1109)
Windows Live Fotogaléria (x32 Version: 15.4.3502.0922)
Windows Live Fotogalerie (x32 Version: 15.4.3502.0922)
Windows Live Fotogalleri (x32 Version: 15.4.3502.0922)
Windows Live Fotoğraf Galerisi (x32 Version: 15.4.3502.0922)
Windows Live Fotótár (x32 Version: 15.4.3502.0922)
Windows Live ID Sign-in Assistant (Version: 7.250.4225.0)
Windows Live Installer (x32 Version: 15.4.3502.0922)
Windows Live Language Selector (Version: 15.4.3508.1109)
Windows Live Mail (x32 Version: 15.4.3502.0922)
Windows Live Mesh - ActiveX-besturingselement voor externe verbindingen (x32 Version: 15.4.5722.2)
Windows Live Mesh (x32 Version: 15.4.3502.0922)
Windows Live Mesh ActiveX Control for Remote Connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX control for remote connections (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-objekt til fjernforbindelser (x32 Version: 15.4.5722.2)
Windows Live Mesh ActiveX-vezérlő távoli kapcsolatokhoz (x32 Version: 15.4.5722.2)
Windows Live Meshin etäyhteyksien ActiveX-komponentti (x32 Version: 15.4.5722.2)
Windows Live Messenger (x32 Version: 15.4.3502.0922)
Windows Live MIME IFilter (Version: 15.4.3502.0922)
Windows Live Movie Maker (x32 Version: 15.4.3502.0922)
Windows Live Photo Common (x32 Version: 15.4.3502.0922)
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922)
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109)
Windows Live Remote Client (Version: 15.4.5722.2)
Windows Live Remote Client Resources (Version: 15.4.5722.2)
Windows Live Remote Service (Version: 15.4.5722.2)
Windows Live Remote Service Resources (Version: 15.4.5722.2)
Windows Live SOXE (x32 Version: 15.4.3502.0922)
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922)
Windows Live Temel Parçalar (x32 Version: 15.4.3502.0922)
Windows Live UX Platform (x32 Version: 15.4.3502.0922)
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109)
Windows Live Writer (x32 Version: 15.4.3502.0922)
Windows Live Writer Resources (x32 Version: 15.4.3502.0922)
Windows Liven asennustyökalu (x32 Version: 15.4.3502.0922)
Windows Liven sähköposti (x32 Version: 15.4.3502.0922)
Windows Liven valokuvavalikoima (x32 Version: 15.4.3502.0922)
XMind 2012 (v3.3.1) (x32 Version: 3.3.1.201212250029)
Στοιχείο ελέγχου ActiveX του Windows Live Mesh για απομακρυσμένες συνδέσεις (x32 Version: 15.4.5722.2)
Συλλογή φωτογραφιών του Windows Live (x32 Version: 15.4.3502.0922)
Елемент керування Windows Live Mesh ActiveX для віддалених підключень (x32 Version: 15.4.5722.2)
Основи Windows Live (x32 Version: 15.4.3502.0922)
Основные компоненты Windows Live (x32 Version: 15.4.3502.0922)
Почта Windows Live (x32 Version: 15.4.3502.0922)
Фотоальбом Windows Live (x32 Version: 15.4.3502.0922)
Фотогалерия на Windows Live (x32 Version: 15.4.3502.0922)
Фотоколекція Windows Live (x32 Version: 15.4.3502.0922)
Элемент управления Windows Live Mesh ActiveX для удаленных подключений (x32 Version: 15.4.5722.2)

==================== Restore Points  =========================

04-07-2013 16:29:08 End of disinfection
04-07-2013 16:52:51 Removed VAIO Update 5
04-07-2013 16:53:57 Installed VAIO Update
04-07-2013 19:57:05 Windows Update
04-07-2013 20:09:51 Windows Update
04-07-2013 20:48:51 Installed Realtek PCIE Card Reader
04-07-2013 20:50:03 Installed VAIO Easy Connect
04-07-2013 20:51:00 Installed PMB VAIO Edition Plug-in Update Program
04-07-2013 20:51:49 Removed VAIO Care
04-07-2013 20:53:01 Installed VAIO Care
04-07-2013 20:55:45 Installed Qriocity
04-07-2013 20:56:31 Installed Atheros WiFi Driver Installation
04-07-2013 21:09:17 Installed Qualcomm Atheros Direct Connect
04-07-2013 22:29:58 Installed PlayMemories Home/PMB VAIO Edition Plug-in Ver.2.2 UpgǾ慴疘ࠈဏ愆А
07-07-2013 08:03:43 Installed Java 7 Update 25

==================== Hosts content: ==========================

2009-07-14 04:34 - 2013-07-03 10:27 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

Task: {007BF961-35D6-4997-8668-9B21A46AB1EA} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe No File
Task: {0F00A5B5-10B7-4CB4-BDC0-0E943EEBE9C4} - System32\Tasks\Sony Corporation\VAIO Improvement\VAIOImprovementUploader => C:\Program Files\Sony\VAIO Improvement\viuploader.exe [2011-02-15] (Sony Corporation)
Task: {12C233F7-78E0-49C1-884C-7C7C3AA6E686} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27] (Google Inc.)
Task: {193F5D68-B659-45B1-B9B3-13053757E9B7} - System32\Tasks\{79AE494A-B00F-4E51-9D02-806671315170} => C:\DISK1\_MSSETUP.EXE No File
Task: {20433116-3838-4598-A8C8-32E3CE8F5A33} - System32\Tasks\Microsoft\Windows Live\SOXE\Extractor Definitions Update Task
Task: {2356794B-C110-452E-A8F4-657696B28605} - System32\Tasks\Microsoft\Windows Defender\MP Scheduled Scan => C:\program files\windows defender\MpCmdRun.exe [2009-07-14] (Microsoft Corporation)
Task: {2D38F468-16AA-4749-B2A4-1D9F42DC868A} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update => C:\Program Files\Sony\VAIO Update\VAIOUpdt.exe [2013-03-26] (Sony Corporation)
Task: {3813C30A-E783-4F16-839B-37BF74D535C0} - System32\Tasks\{C8099E57-DB19-44A3-9811-99FF52A6DB76} => C:\DISK1\SETUP.EXE No File
Task: {3ACA6A05-8F03-4CFA-BCD3-93F38BF86D27} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation)
Task: {3F4DD9FF-74EB-45B0-9B17-DB32709EB2AA} - System32\Tasks\Sony Corporation\VAIO Smart Network\VSN Logon Start => C:\Program Files\Sony\VAIO Smart Network\VSNClient No File
Task: {400EC6C2-FB40-444D-8F2C-92DC643BC27A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe No File
Task: {4140F79D-C63D-41AD-A02D-12BA3CE145D9} - System32\Tasks\{A23A174C-68F5-40CA-B941-FDC1289EB290} => C:\DISK1\SETUP.EXE No File
Task: {506A37A0-548C-4545-9782-20845E993604} - System32\Tasks\{379DF08F-7A5B-40E4-A6C9-BF55B02B91FA} => C:\DISK1\SETUP.EXE No File
Task: {5483E0E3-3A4F-48EA-8175-582EBDB71603} - System32\Tasks\Sony Corporation\VAIO Improvement Validation\VAIO Improvement Validation => C:\Program Files\Sony\VAIO Improvement Validation\viv.exe [2011-01-20] (Sony Corporation)
Task: {59FFB27E-68A5-46AB-9334-ADE36FD089D3} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-06-12] (Adobe Systems Incorporated)
Task: {69B5207D-6704-4205-AAD9-78074959E958} - System32\Tasks\{0819DC4F-BECD-4FDA-B9E0-B16466E48BF5} => C:\DISK1\_MSSETUP.EXE No File
Task: {6FD03CBD-0AF3-4D88-B06F-D9DC145AF713} - System32\Tasks\{0754E513-E313-47B3-B55E-F56D009DB678} => C:\DISK1\SETUP.EXE No File
Task: {726180E2-6A8E-42AC-B602-40066AFEE225} - System32\Tasks\{BC3BFA7F-7C59-413D-9DA1-B7D3F9A5CCA8} => C:\DISK1\SETUP.EXE No File
Task: {8BD68BAD-AB09-4ABB-BB6E-34870347EF75} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation)
Task: {952F479D-6606-43BA-9F59-F073D5B3BA16} - System32\Tasks\{22A55328-89D4-43AA-9BD6-97C07E551919} => C:\DISK1\SETUP.EXE No File
Task: {9CDA80ED-4A92-4A36-8374-5A4452287999} - System32\Tasks\{019D57EB-6012-42C2-B389-E900B529DED9} => C:\DISK1\SETUP.EXE No File
Task: {A389D2A1-B14E-4975-BC69-515565B77A59} - System32\Tasks\SONY\VAIO Gate\StartExecuteProxy => C:\Program Files\Sony\VAIO Gate\ExecutionProxy.exe [2010-11-16] (Sony Corporation)
Task: {A4573A20-64C3-48F9-823C-A35856C347D4} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-28] (Google Inc.)
Task: {AC899129-C248-4F9C-89A1-599035721B77} - System32\Tasks\HP Photo Creations Messager => C:\ProgramData\HP Photo Creations\MessageCheck.exe [2011-02-15] ()
Task: {C4AE742F-5E88-468C-915D-D354017594D2} - System32\Tasks\{5CE0363D-A773-4F22-986E-E5749604663D} => C:\DISK1\SETUP.EXE No File
Task: {C70B2CF8-D882-4075-94B1-0A64FA67997D} - System32\Tasks\{5F4BD8CD-A5F6-4489-BA38-BDEA07419348} => C:\DISK1\SETUP.EXE No File
Task: {CB65759A-6A9E-4176-A807-B58ABD497F64} - System32\Tasks\CCleanerSkipUAC => C:\Program Files\CCleaner\CCleaner.exe [2013-06-19] (Piriform Ltd)
Task: {D24C2055-9D96-4E63-910F-B86BDA8DB7CF} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe No File
Task: {D3F7629C-0745-4E82-9309-2CECD6619BA2} - System32\Tasks\User_Feed_Synchronization-{5C497AA6-8DA4-4F51-9231-255D2BE41896} => C:\Windows\system32\msfeedssync.exe [2013-05-31] (Microsoft Corporation)
Task: {D45A9D9B-2AAC-4113-B249-779F7C7823C6} - System32\Tasks\User_Feed_Synchronization-{F8F9D594-1F59-4874-8B7E-773D45408B09} => C:\Windows\system32\msfeedssync.exe [2013-05-31] (Microsoft Corporation)
Task: {D5914D9C-1ADC-4FFE-9159-E933F7B7BD34} - System32\Tasks\Sony Corporation\VAIO Update\VAIO Update Self Repair => C:\Program Files\Sony\VAIO Update\VUSR.exe [2013-03-26] (Sony Corporation)
Task: {DF4D8943-C503-473F-835B-F61D9227C79C} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2012-03-27] (Google Inc.)
Task: {EC433C01-59C3-4645-A5CD-942EE01664F4} - System32\Tasks\HPCustParticipation HP Photosmart 5510 series => C:\Program Files\HP\HP Photosmart 5510 series\Bin\HPCustPartic.exe [2011-09-16] (Hewlett-Packard Co.)
Task: {ECB25488-1BEF-461F-9480-51C9C7FE112E} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2010-11-16] (Sony Corporation)
Task: {F831395A-A7F0-4603-9820-68D2996C9E95} - System32\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe [2012-03-28] (Google Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000Core.job => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1777987527-2813828370-3523153149-1000UA.job => C:\Users\Daniel\AppData\Local\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\HP Photo Creations Messager.job => C:\ProgramData\HP Photo Creations\MessageCheck.exe

==================== Faulty Device Manager Devices =============

Name: Officejet 6000 E609a
Description: Officejet 6000 E609a
Class Guid: 
Manufacturer: 
Service: 
Problem: : The drivers for this device are not installed. (Code 28)
Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard.


==================== Event log errors: =========================

Application errors:
==================
Error: (07/09/2013 08:25:41 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/08/2013 07:25:07 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/08/2013 04:14:12 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/08/2013 00:20:20 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/08/2013 00:17:32 PM) (Source: Application Error) (User: )
Description: Faulting application name: firefox.exe, version: 22.0.0.4917, time stamp: 0x51c06b1b
Faulting module name: xul.dll, version: 22.0.0.4917, time stamp: 0x51c06a5b
Exception code: 0xc0000005
Fault offset: 0x00173668
Faulting process id: 0x1fd4
Faulting application start time: 0xfirefox.exe0
Faulting application path: firefox.exe1
Faulting module path: firefox.exe2
Report Id: firefox.exe3

Error: (07/08/2013 00:17:04 PM) (Source: Application Error) (User: )
Description: Faulting application name: services.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc10e
Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e
Exception code: 0xc0000005
Fault offset: 0x0000000000016ecf
Faulting process id: 0x244
Faulting application start time: 0xservices.exe0
Faulting application path: services.exe1
Faulting module path: services.exe2
Report Id: services.exe3

Error: (07/08/2013 10:25:23 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (07/06/2013 10:35:21 PM) (Source: Application Error) (User: )
Description: Faulting application name: Explorer.EXE, version: 6.1.7601.17567, time stamp: 0x4d672ee4
Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e
Exception code: 0xc0000005
Fault offset: 0x0000000000020a4a
Faulting process id: 0x1020
Faulting application start time: 0xExplorer.EXE0
Faulting application path: Explorer.EXE1
Faulting module path: Explorer.EXE2
Report Id: Explorer.EXE3

Error: (07/06/2013 09:52:17 AM) (Source: Application Error) (User: )
Description: Faulting application name: svchost.exe, version: 6.1.7600.16385, time stamp: 0x4a5bc3c1
Faulting module name: ntdll.dll, version: 6.1.7601.17725, time stamp: 0x4ec4aa8e
Exception code: 0xc0000005
Fault offset: 0x0000000000020a4a
Faulting process id: 0x3fc
Faulting application start time: 0xsvchost.exe0
Faulting application path: svchost.exe1
Faulting module path: svchost.exe2
Report Id: svchost.exe3

Error: (07/05/2013 00:42:57 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003


System errors:
=============
Error: (07/09/2013 08:57:28 AM) (Source: BTHUSB) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (07/09/2013 08:25:19 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYSYSTEMS-1-5-18LocalHost (Using LRPC)

Error: (07/09/2013 08:25:16 AM) (Source: DCOM) (User: NT AUTHORITY)
Description: application-specificLocalLaunch{C97FCC79-E628-407D-AE68-A06AD6D8B4D1}{344ED43D-D086-4961-86A6-1106F4ACAD9B}NT AUTHORITYLOCAL SERVICES-1-5-19LocalHost (Using LRPC)

Error: (07/09/2013 08:25:05 AM) (Source: Service Control Manager) (User: )
Description: The Windows Search service failed to start due to the following error: 
%%1053

Error: (07/09/2013 08:25:05 AM) (Source: Service Control Manager) (User: )
Description: A timeout was reached (30000 milliseconds) while waiting for the Windows Search service to connect.

Error: (07/09/2013 08:25:05 AM) (Source: DCOM) (User: )
Description: 1053WSearch{9E175B6D-F52A-11D8-B9A5-505054503030}

Error: (07/09/2013 08:23:59 AM) (Source: BTHUSB) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (07/09/2013 06:26:02 AM) (Source: BTHUSB) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (07/08/2013 10:18:29 PM) (Source: BTHUSB) (User: )
Description: The local Bluetooth adapter has failed in an undetermined manner and will not be used. The driver has been unloaded.

Error: (07/08/2013 07:28:42 PM) (Source: Service Control Manager) (User: )
Description: The VAIO Care Performance Service service hung on starting.


Microsoft Office Sessions:
=========================
Error: (09/02/2012 05:32:29 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 5308 seconds with 1020 seconds of active time.  This session ended with a crash.

Error: (07/17/2012 09:38:23 PM) (Source: Microsoft Office 12 Sessions)(User: )
Description: ID: 0, Application Name: Microsoft Office Word, Application Version: 12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 17791 seconds with 5040 seconds of active time.  This session ended with a crash.


CodeIntegrity Errors:
===================================
  Date: 2013-07-03 10:27:34.458
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-07-03 10:27:34.395
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-07-03 10:27:34.349
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-07-03 10:27:34.302
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-07-02 19:51:09.694
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-07-02 19:51:09.648
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info =========================== 

Percentage of memory in use: 42%
Total physical RAM: 8139.86 MB
Available physical RAM: 4664.88 MB
Total Pagefile: 16277.9 MB
Available Pagefile: 13051.25 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:452.18 GB) (Free:351.36 GB) NTFS (Disk=0 Partition=3)

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: A920C8D1)
Partition 1: (Not Active) - (Size=13 GB) - (Type=27)
Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=452 GB) - (Type=07 NTFS)

==================== End Of Log ============================
         
Ich habe allerding defogger zuvor nicht durchgeführt gehabt.

Besten Dank und Grüße,

Piristibulus
__________________


Alt 09.07.2013, 10:47   #18
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Hi,

Downloade dir bitte Malwarebytes Anti-Rootkit Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
  • Starte bitte die mbar.exe.
  • Folge den Anweisungen auf deinem Bildschirm gemäß Anleitung zu Malwarebytes Anti-Rootkit
  • Aktualisiere unbedingt die Datenbank und erlaube dem Tool, dein System zu scannen.
  • Klicke auf den CleanUp Button und erlaube den Neustart.
  • Während dem Neustart wird MBAR die gefundenen Objekte entfernen, also bleib geduldig.
  • Nach dem Neustart starte die mbar.exe erneut.
  • Sollte nochmal was gefunden werden, wiederhole den CleanUp Prozess.
Das Tool wird im erstellten Ordner eine Logfile ( mbar-log-<Jahr-Monat-Tag>.txt ) erzeugen. Bitte poste diese hier.

Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers
__________________
__________________

Alt 09.07.2013, 11:29   #19
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Hallo Schrauber,

der Scan ist gelaufen, die Meldung kam, es sei nichts gefunden worden. Entsprechend wurde auch kein Clean-Up gestartet und kein Neustart durch den PC durchgeführt:

Code:
ATTFilter
Malwarebytes Anti-Rootkit BETA 1.06.0.1004
www.malwarebytes.org

Database version: v2013.07.09.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16618
Daniel :: SOFERMAHIR [administrator]

09/07/2013 11:57:05
mbar-log-2013-07-09 (11-57-05).txt

Scan type: Quick scan
Scan options enabled: Anti-Rootkit | Drivers | MBR | Physical Sectors | Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUM | P2P
Scan options disabled: PUP
Objects scanned: 246240
Time elapsed: 15 minute(s), 10 second(s)

Memory Processes Detected: 0
(No malicious items detected)

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 0
(No malicious items detected)

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 0
(No malicious items detected)

Physical Sectors Detected: 0
(No malicious items detected)

(end)
         
Vielen Dank und beste Grüße,

Piristibulus

Alt 09.07.2013, 11:31   #20
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Meckert Sophos immer noch?

__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.07.2013, 11:33   #21
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Nö, anscheinend nicht.

Gestern kam ja auch die Warnmeldung nicht von Sophos, sondern vom "Action Center" in der Systemsteuerung.
Sophos konnte da nichts finden ...

LG,
Piristibulus

Alt 09.07.2013, 11:45   #22
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Strange. beobachte das mal.

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.


Hier noch ein paar Tipps zur Absicherung deines Systems.


Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.


Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.


Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.


Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.


Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Performance
Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )



Don'ts
  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.07.2013, 11:54   #23
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



super, alles klar.
ich werde es im Auge behalten und wenn es noch mal Probleme macht, dann eröffne ich einen neuen Thread.

Noch mal vielen herzlichen Dank!

Piristibulus

Alt 09.07.2013, 11:55   #24
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Meld dich einfach in diesem Thread nochmal
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.07.2013, 12:07   #25
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Alles klar!

Danke noch mal!

Piristibulus

Alt 09.07.2013, 12:16   #26
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Gern Geschehen
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 09.07.2013, 13:04   #27
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



komisch, während des Ausführens von DelFix meldete das Programm, es könne eine Datei unter Windows/ERUNT nicht gelöscht werden. Also eine Datei, die zu Delfix selbst gehört.

2 Minuten später schlug Sophos Alarm, und zwar gerade als DelFix fertig wurde. Es sei "HIPS/RegMod-009" gefunden worden und in die Quarantäne verschoben, aber als ich die Infos dort aufrufen wollte, hat Sophos bereits die Sache wieder aus dem Quarantänemanager entfernt gehabt.

pühhh. Fehlalarm? Lags am DelFix?

Alt 09.07.2013, 13:23   #28
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Fehlalarm. Delfix neu laden laufen lassen, Sophos dabei deaktivieren.
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 07.08.2013, 11:06   #29
Piristibulus
 
Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Hallo, lieber Schrauber,

die Fehlermeldung mit dem "Win32/Small.CA" ist erneut aufgetaucht.

Heute morgen tauchte erneut die Fehlermeldung im Windows Action Center auf.
Nach diesen Angaben, müsste der Virus gestern Abend um 21:04 "aufgetreten" sein, es kam aber definitiv zu diesem Zeitpunkt keine Meldung.

Zuvor kam allerdings die Meldung "KRITISCHER FEHLER - Es ist ein kritischer Fehler aufgetreten. Windows wird in einer Minute heruntergefahren. Speichern Sie Ihre Daten" (bzw. auf Englisch, da mein Betriebssystem auf Englisch läuft) und der Computer startete sich neu.

Dieser Fehler ist in den letzten Wochen öfters aufgetreten, allerdings niemals mit Virusmeldung.

Heute morgen dann kam die Virusmeldung, zugleich konnte ich sehen, dass in der Sophos-Konfiguration auf einmal "on-access"-Scanning ausgeschaltet wurde und gleich die Meldung vom Windows-Action-Center kam, dass alle Sicherheitssoftware deaktiviert sei. Darauf startete Windows erneut neu, aber ohne Fehlermeldung. Sophos war danach wieder aktiv. Windows Defender nicht.

Irgendwas ist also nicht ganz sauber, wie mir scheint.

Ich habe daraufhin Sophos, Malewarebytes und Windows-Defender laufen lassen. (Malewarebytes noch mal upgedatet, danach WLAN ausgeschaltet).

Es wurde aber nichts gefunden. Hier sind die Logs:

1) Malewarebytes:

Code:
ATTFilter
Malwarebytes Anti-Malware 1.75.0.1300
www.malwarebytes.org

Datenbank Version: v2013.08.07.03

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 10.0.9200.16635
Daniel :: SOFERMAHIR [Administrator]

07/08/2013 08:50:46
mbam-log-2013-08-07 (08-50-46).txt

Art des Suchlaufs: Quick-Scan
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 225861
Laufzeit: 21 Minute(n), 10 Sekunde(n)

Infizierte Speicherprozesse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungswerte: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 0
(Keine bösartigen Objekte gefunden)

(Ende)
         
2) Sophos:

Code:
ATTFilter
20130801 065706	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130801 070301	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130801 070302	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5362977 items.
20130801 070302	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130801 090228	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130801 090228	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363003 items.
20130801 090228	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130801 130227	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130801 130228	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363013 items.
20130801 130228	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130801 163646	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363013 items.
20130801 163646	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130801 164228	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130801 164229	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363019 items.
20130801 164229	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130801 192536	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363019 items.
20130801 192536	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130801 193150	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130801 193151	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363045 items.
20130801 193151	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130801 220216	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130801 220217	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363055 items.
20130801 220217	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130802 054517	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130802 054518	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363070 items.
20130802 054518	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130802 084330	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363070 items.
20130802 084331	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130802 084928	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130802 084929	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363082 items.
20130802 084930	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130802 220635	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363082 items.
20130802 220635	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130802 221233	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130802 221234	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363129 items.
20130802 221234	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130803 094248	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130803 094249	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363137 items.
20130803 094249	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130803 211249	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130803 211251	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363140 items.
20130803 211251	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130804 104401	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130804 104402	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363156 items.
20130804 104402	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130804 164349	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130804 164350	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363163 items.
20130804 164350	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130804 205054	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130804 205055	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363169 items.
20130804 205055	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130805 052837	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130805 052838	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363182 items.
20130805 052838	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130805 083531	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130805 083532	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363196 items.
20130805 083532	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130805 110925	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363196 items.
20130805 110925	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130805 121459	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130805 121500	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363204 items.
20130805 121500	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130805 141446	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130805 141447	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363215 items.
20130805 141447	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130805 191907	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363215 items.
20130805 191909	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130805 202215	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130805 202216	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363234 items.
20130805 202216	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130806 061330	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130806 061331	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363244 items.
20130806 061331	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130806 083042	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130806 083043	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363252 items.
20130806 083043	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130806 105720	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363252 items.
20130806 105720	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130806 110322	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130806 110323	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363274 items.
20130806 110323	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130806 154343	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363274 items.
20130806 154343	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130806 154935	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130806 154936	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363289 items.
20130806 154936	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
20130806 185144	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363289 items.
20130806 185144	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130807 064144	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363348 items.
20130807 064144	User (NT AUTHORITY\LOCAL SERVICE) has started on-access scanning for this machine.
20130807 064658	Scan 'Scan my computer' started.
20130807 075004	Scan 'Scan my computer' completed.
20130807 075004	Summary of results for scan 'Scan my computer':
		Items scanned: 166999
		Errors: 0
		Items quarantined: 0
		Items dealt with: 0
20130807 094714	User (NT AUTHORITY\SYSTEM) has stopped on-access scanning for this machine.
20130807 094715	Using detection data version 4.91G (detection engine 3.45.0). This version can detect 5363355 items.
20130807 094715	User (NT AUTHORITY\SYSTEM) has started on-access scanning for this machine.
         
Was tun?
Soll ich evtl. Windows komplett neu aufspielen? Allerdings bin ich mir nicht sicher, wie ich das mache, da mein Vaio ohne Installationsdiskette kam. Ich habe allerdings einen Produktkey bekommen.

Beste Grüße und vielen Dank,

Piristibulus

Alt 07.08.2013, 19:20   #30
schrauber
/// the machine
/// TB-Ausbilder
 

Sophosmeldung: Troj/ZbotMem-B im Memory - Standard

Sophosmeldung: Troj/ZbotMem-B im Memory



Schau dich mal im Forum um, komischerweise haben alle Leute mit diesem "Fehler" Sophod installiert
__________________
gruß,
schrauber

Proud Member of UNITE and ASAP since 2009

Spenden
Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Antwort

Themen zu Sophosmeldung: Troj/ZbotMem-B im Memory
administrator, anleitung, anzeige, anzeigen, befall, beste grüße, bestimmte, cmd, defogger, desktop, detected, doppelt, entfernen, firefox, guten, log, meldung, problem, programme, scan, seite, sophos, strg, suche, troj/zbotmem-b, webseite, win, zeichen




Ähnliche Themen: Sophosmeldung: Troj/ZbotMem-B im Memory


  1. Troj.TR/Crypt.Zpack.151493+Troj.TR/Crypt.Xpack.138980 entfernen+daten entschlüsseln
    Log-Analyse und Auswertung - 27.08.2015 (27)
  2. Troj/ZbotMem-B
    Plagegeister aller Art und deren Bekämpfung - 04.01.2015 (13)
  3. Windows 7: Troj/ZbotMem-B Befall?
    Log-Analyse und Auswertung - 04.01.2015 (17)
  4. Troj/ZbotMem-B fund von Sophos, manuelle Reinigung erforderlich / Windows 7
    Log-Analyse und Auswertung - 15.12.2013 (11)
  5. troj/zbotmem-b in der Sophos Quarantaene und nur manuell zu bereinigen
    Log-Analyse und Auswertung - 28.11.2013 (23)
  6. Troj/ZbotMem-B, Sophos Quarantäne-Manager fordert manuelle Bereinigung
    Log-Analyse und Auswertung - 06.02.2013 (3)
  7. Troj/ZbotMem-B // gefunden mit Sophos
    Plagegeister aller Art und deren Bekämpfung - 28.12.2012 (13)
  8. Sophos meldet im Speicher: Troj/ZbotMem-B
    Plagegeister aller Art und deren Bekämpfung - 27.11.2012 (10)
  9. Habe ich Troj/zbotmem-b vollständig entfernt?
    Plagegeister aller Art und deren Bekämpfung - 07.11.2012 (1)
  10. Troj/ZbotMem-B bei Scan entdeckt, nach Sophos Meldung HIPS/RegMod-014 - Was tun?
    Plagegeister aller Art und deren Bekämpfung - 24.08.2012 (16)
  11. Troj/ExpJS-EG / Troj/ZbotMem-B / Trojan.Phex.THAGen6 - BA-BA-BA-BA-BANKÜBERFALL 2012
    Plagegeister aller Art und deren Bekämpfung - 19.08.2012 (19)
  12. Windows verschlüsselungstrojaner: out of memory?
    Log-Analyse und Auswertung - 21.06.2012 (1)
  13. Trojaner Troj/ZbotMem-B Zugriff auf Bankendaten - wie bereinigen?
    Log-Analyse und Auswertung - 10.08.2011 (6)
  14. program too big to fit in memory
    Log-Analyse und Auswertung - 01.02.2010 (1)
  15. Hijackthis = out of memory???
    Mülltonne - 12.08.2008 (0)
  16. mIRC wurm und Troj LADDER.A /Troj RAS.DLDR
    Plagegeister aller Art und deren Bekämpfung - 24.12.2004 (1)
  17. TROJ PROCKILLA / TROJ TARNO.A
    Plagegeister aller Art und deren Bekämpfung - 06.01.2004 (3)

Zum Thema Sophosmeldung: Troj/ZbotMem-B im Memory - poste mal noch ein frisches FRST log. - Sophosmeldung: Troj/ZbotMem-B im Memory...
Archiv
Du betrachtest: Sophosmeldung: Troj/ZbotMem-B im Memory auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.