Hallo,
Code:
Alles auswählen Aufklappen ATTFilter
HitmanPro 3.7.6.201
www.hitmanpro.com
Computer name . . . . : UTE-PC5
Windows . . . . . . . : 6.2.0.9200.X86/2
User name . . . . . . : UTE-PC5\Ute
UAC . . . . . . . . . : Enabled
License . . . . . . . : Free
Scan date . . . . . . : 2013-07-31 19:44:11
Scan mode . . . . . . : Normal
Scan duration . . . . : 3m 44s
Disk access mode . . : Direct disk access (SRB)
Cloud . . . . . . . . : Internet
Reboot . . . . . . . : No
Threats . . . . . . . : 13
Traces . . . . . . . : 1021
Objects scanned . . . : 947.671
Files scanned . . . . : 20.258
Remnants scanned . . : 376.594 files / 550.819 keys
Malware _____________________________________________________________________
C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\00KF923G\WebCakesetup[1].exe
Size . . . . . . . : 1.212.288 bytes
Age . . . . . . . : 6.0 days (2013-07-25 19:48:08)
Entropy . . . . . : 8.0
SHA-256 . . . . . : 02E10E9B754D5C283066180E5D651335A1706841362C6F7721A6C50CFD73B7A2
Product . . . . . : WebCake
Publisher . . . . : WebCake LLC
Description . . . : Installer
Version . . . . . : 2013.6.20.1708
Copyright . . . . : Copyright (c) 2013 WebCake LLC. All rights reserved.
RSA Key Size . . . : 2048
Source URL . . . . : hxxp://dl-cdn.getwebcake.com/install/v8/WebCakesetup.exe
Authenticode . . . : Valid
> Ikarus . . . . . . : AdWare.Yontoo!IK
Fuzzy . . . . . . : 103.0
Forensic Cluster
-3.0s C:\Users\Ute\AppData\Local\Temp\132-08C0.exe
-2.5s C:\Users\Ute\AppData\Local\Temp\132-08C0.log
-2.5s C:\Users\Ute\AppData\Local\Temp\132-08C0.log
-2.5s C:\Users\Ute\AppData\Local\Temp\132-08C0.log
-0.7s C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K5AGFMJU\a[1].txt
0.0s C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\00KF923G\WebCakesetup[1].exe
4.3s C:\Users\Ute\AppData\Local\Temp\wc-0EDC.exe
5.3s C:\Users\Ute\AppData\Local\Temp\wc-0EDC.log
5.3s C:\Users\Ute\AppData\Local\Temp\wc-0EDC.log
5.6s C:\Users\Ute\AppData\Local\Temp\810E91B5\
5.6s C:\Users\Ute\AppData\Local\Temp\810E91B5\_Setup.dll
5.6s C:\Users\Ute\AppData\Local\Temp\810E91B5\_Setup.dll
6.1s C:\Users\Ute\AppData\Local\Temp\810E91B5\Setup.ico
6.1s C:\Users\Ute\AppData\Local\Temp\810E91B5\_Setupx.dll
8.6s C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\QVYI4SHG\Meh[1].json
8.6s C:\Users\Ute\AppData\Local\Temp\810E91B5\m.eh
9.2s C:\Users\Ute\AppData\Local\Temp\plugtmp-4\
9.9s C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K2DJGNMQ\a[1].txt
9.9s C:\Users\Ute\AppData\Local\Temp\810E91B5\Check.txt
9.9s C:\Windows\Prefetch\132-08C0.EXE-36113990.pf
10.2s C:\$Recycle.Bin\S-1-5-21-533882140-3980523968-1356160843-1009\$REL3BZQ\
10.2s C:\$Recycle.Bin\S-1-5-21-533882140-3980523968-1356160843-1009\$REL3BZQ\Setup.exe
10.3s C:\$Recycle.Bin\S-1-5-21-533882140-3980523968-1356160843-1009\$REL3BZQ\_Setup.dll
10.3s C:\$Recycle.Bin\S-1-5-21-533882140-3980523968-1356160843-1009\$REL3BZQ\Setup.ico
10.4s C:\$Recycle.Bin\S-1-5-21-533882140-3980523968-1356160843-1009\$REL3BZQ\_Setupx.dll
10.4s C:\$Recycle.Bin\S-1-5-21-533882140-3980523968-1356160843-1009\$REL3BZQ\Cache\
10.5s C:\Users\Ute\AppData\Local\Temp\810E91B5\x86\
10.5s C:\Users\Ute\AppData\Local\Temp\810E91B5\x86\regsvr32.exe
10.5s C:\Users\Ute\AppData\Local\Temp\810E91B5\x64\
10.5s C:\Users\Ute\AppData\Local\Temp\810E91B5\x64\regsvr32.exe
10.5s C:\Users\Ute\AppData\Local\Temp\810E91B5\x64\regsvr32.exe
10.5s C:\Users\Ute\AppData\Local\Temp\810E91B5\WebCakeFFClient.xpi
10.5s C:\Users\Ute\AppData\Local\Temp\810E91B5\WebCakeFFClient.xpi
10.6s C:\Users\Ute\AppData\Local\Temp\810E91B5\7za.exe
11.0s C:\$Recycle.Bin\S-1-5-21-533882140-3980523968-1356160843-1009\$RVN09IO.exe
11.3s C:\Users\Ute\AppData\Local\Temp\810E91B5\WebCakeIEClient.dll
11.3s C:\Users\Ute\AppData\Local\Temp\810E91B5\WebCakeIEClient.dll
11.3s C:\Users\Ute\AppData\Local\Temp\810E91B5\WebCakeIEClient.dll
11.3s C:\Users\Ute\AppData\Local\Temp\810E91B5\WebCakeIEClient.dll
11.8s C:\Users\Ute\AppData\Local\Temp\810E91B5\webcake.xml
11.9s C:\$Recycle.Bin\S-1-5-21-533882140-3980523968-1356160843-1009\$RMEZT7U.dll
11.9s C:\$Recycle.Bin\S-1-5-21-533882140-3980523968-1356160843-1009\$RMEZT7U.dll
12.3s C:\Windows\Prefetch\RESIZE.EXE-BEFFDFA0.pf
12.3s C:\Windows\Prefetch\RESIZE.EXE-BEFFDFA0.pf
12.4s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\localstore-1.rdf
12.6s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\
12.8s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome.manifest
12.8s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\install.rdf
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\content\
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\content\obviousideaaddon.js
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\content\obviousideaaddon.xul
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\content\poweraddon.js
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\icon16.png
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\icon32.png
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item1.png
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item10.png
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item11.png
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item12.png
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item2.png
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item3.png
12.9s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item4.png
13.0s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item5.png
13.0s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item6.png
13.0s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item6.png
13.0s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item7.png
13.0s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item8.png
13.0s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\item9.png
13.0s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\chrome\skin\overlay.css
13.0s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\defaults\
13.0s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\defaults\preferences\
13.0s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\defaults\preferences\obviousideaaddon.js
13.0s C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\extensions\toolbarbutton@obviousidea.us\defaults\preferences\obviousideaaddon.js
13.5s C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K5AGFMJU\a[1].js
13.5s C:\Users\Ute\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\K5AGFMJU\a[1].js
16.0s C:\Users\Ute\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7B8944BA8AD0EFDF0E01A43EF62BECD0_538D903C0A81D46E90DBA469E6311D92
16.0s C:\Users\Ute\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_538D903C0A81D46E90DBA469E6311D92
16.0s C:\Users\Ute\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7B8944BA8AD0EFDF0E01A43EF62BECD0_538D903C0A81D46E90DBA469E6311D92
19.6s C:\Users\Ute\AppData\Local\Microsoft\Windows\Caches\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000033.db
Cookies _____________________________________________________________________
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ad.360yield.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ad.ad-srv.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ad.adc-serv.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ad.adnet.de
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ad.adserver01.de
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ad.dyntracker.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ad.dyntracker.de
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ad.movad.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ad.sevenads.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ad.yieldmanager.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ad.zanox.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ads.adk2.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ads.audience2media.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ads.creative-serving.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ads.p161.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ads.pubmatic.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ads.traveladshop.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ads.undertone.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:adserver1.mokono.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:adtech.de
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:adtechus.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:advertising.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:adviva.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:aka-cdn-ns.adtech.de
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:aok.122.2o7.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:apmebf.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:atdmt.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:autoscout24.112.2o7.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:bs.serving-sys.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:burstnet.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:casalemedia.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:content.yieldmanager.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:de.sitestat.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:doubleclick.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:eas.apm.emediate.eu
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:eas4.emediate.eu
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:fastclick.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:fl01.ct2.comclick.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:gmeurope.112.2o7.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:in.getclicky.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:invitemedia.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:kqv.112.2o7.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:media6degrees.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:mediaplex.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:oms.122.2o7.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:paypal.112.2o7.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:pool-eu-ie.creative-serving.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:questionmarket.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:revsci.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ru4.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:serving-sys.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:smartadserver.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:specificclick.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:stat.dealtime.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:statcounter.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:stats.paypal.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:statse.webtrendslive.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:track.adform.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:track.effiliation.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:track.webtrekk.de
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:tradedoubler.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:tribalfusion.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:warnerbros.112.2o7.net
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:webetico2.solution.weborama.fr
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:weborama.fr
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:weboramaitdata.solution.weborama.fr
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:weboramaitdatas2.solution.weborama.fr
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:ww251.smartadserver.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:www.etracker.de
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:www.googleadservices.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:www4.smartadserver.com
C:\Users\Ute\AppData\Roaming\Mozilla\Firefox\Profiles\15gsmenk.default\cookies.sqlite:xiti.com