Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML

Alt 19.01.2014, 12:19   #1
Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Standard

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

Ich habe eine Fake E-Mail von Vodafone bekommen, leider den link geöffnet und die Datei darin auch gestartet, jetzt schlägt mein Antivirus Programm regelmäßig an.

Nach kurzer Googlesuche habe ich herausgefunden, dass dadurch ein Trojaner in mein System gelangen kann, da ich kaum Ahnung davon habe wäre es nett wenn mir einer Helfen könnte und das ganze überprüft.

Mein System ist ein Windows 7 mit SP1

Hier die Geforderten Log Files:

FRST Additions Logfile:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 17-01-2014 03
Ran by Landgraf-Vaio at 2014-01-19 10:45:41
Running from C:\Users\Landgraf-Vaio\Downloads
Boot Mode: Normal

==================== Security Center ========================

AV: Lavasoft Ad-Aware (Enabled - Up to date) {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Lavasoft Ad-Aware (Enabled - Up to date) {5BB89C30-6480-BC7C-9F17-199BD76F557A}
AS: Spybot - Search and Destroy (Enabled - Up to date) {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
FW: Lavasoft Ad-Aware (Disabled) {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}

==================== Installed Programs ======================

Ad-Aware Antivirus (x32 Version: - Lavasoft)
Ad-Aware Security Add-on (x32 Version: - Lavasoft)
Adobe Flash Player 11 ActiveX (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Flash Player 11 Plugin (x32 Version: 11.9.900.170 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (x32 Version: 11.0.06 - Adobe Systems Incorporated)
Alps Pointing-device for VAIO (Version:  - ALPS ELECTRIC CO., LTD.)
ATI Catalyst Install Manager (Version: 3.0.769.0 - ATI Technologies, Inc.)
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2010.0920.2143.37117 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2010.0920.2143.37117 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Czech (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Danish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Dutch (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help English (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Finnish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help French (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help German (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Greek (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Italian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Japanese (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Korean (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Norwegian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Polish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Russian (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Spanish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Swedish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Thai (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
CCC Help Turkish (x32 Version: 2010.0920.2142.37117 - ATI) Hidden
ccc-core-static (x32 Version: 2010.0920.2143.37117 - Ihr Firmenname) Hidden
ccc-utility64 (Version: 2010.0920.2143.37117 - ATI) Hidden
Cultris II (x32 Version:  - )
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Definition Update for Microsoft Office 2010 (KB982726) 64-Bit Edition (Version:  - Microsoft)
DHTML Editing Component (x32 Version: 6.02.0001 - Microsoft Corporation)
Dropbox (HKCU Version: 2.4.11 - Dropbox, Inc.)
Elevated Installer (x32 Version: - Garmin Ltd or its subsidiaries) Hidden
Garmin Express (x32 Version: - Garmin Ltd or its subsidiaries)
Garmin Express (x32 Version: - Garmin Ltd or its subsidiaries) Hidden
Garmin Express Tray (x32 Version: - Garmin Ltd or its subsidiaries) Hidden
GUILD WARS (x32 Version:  - )
Java 7 Update 51 (x32 Version: 7.0.510 - Oracle)
Java Auto Updater (x32 Version: - Sun Microsystems, Inc.) Hidden
Junk Mail filter update (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation)
Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30319 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office Access MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Groove MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 32-bit Components 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 32-bit MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2010 (Version: 14.0.7015.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (Version: 5.1.20913.0 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148 (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (Version: 9.0.30729.6161 - Microsoft Corporation)
Mozilla Firefox 26.0 (x86 de) (x32 Version: 26.0 - Mozilla)
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT110 (x32 Version: 16.4.1108.0727 - Microsoft) Hidden
MSVCRT110_amd64 (Version: 16.4.1109.0912 - Microsoft) Hidden
Rossmann Fotowelt Software 4.13 (x32 Version: 4.13 - ORWO Net)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version:  - Microsoft)
Service Pack 2 for Microsoft Office 2010 (KB2687455) 64-Bit Edition (Version:  - Microsoft) Hidden
Skype™ 6.11 (x32 Version: 6.11.102 - Skype Technologies S.A.)
Spybot - Search & Destroy (x32 Version: 2.1.21 - Safer-Networking Ltd.)
StarMoney (x32 Version: - StarFinanz) Hidden
StarMoney 9.0  (x32 Version: 9.0 - Star Finanz GmbH)
TeamSpeak 3 Client (Version: 3.0.13 - TeamSpeak Systems GmbH)
Turbo Lister 2 (x32 Version: 2.00.0000 - eBay Inc.)
Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939) (x32 Version: 1 - Microsoft Corporation)
Update for Microsoft .NET Framework 4 Client Profile (KB2836939v3) (x32 Version: 3 - Microsoft Corporation)
Update for Microsoft Access 2010 (KB2553446) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Filter Pack 2.0 (KB2810071) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589298) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589352) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2589375) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2597087) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760598) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2760631) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2794737) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2825640) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2826026) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Office 2010 (KB2850079) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft OneNote 2010 (KB2810072) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft PowerPoint 2010 (KB2553145) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Visio Viewer 2010 (KB2810066) 64-Bit Edition (Version:  - Microsoft)
Update for Microsoft Word 2010 (KB2837593) 64-Bit Edition (Version:  - Microsoft)
VAIO Care (x32 Version: - Sony Corporation) Hidden
VAIO Control Center (x32 Version: - Sony Corporation)
VAIO Gate (x32 Version: - Sony Corporation)
WIDCOMM Bluetooth Software (Version: - Broadcom Corporation)
Windows Live Communications Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4311.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 16.4.3505.0912 - Microsoft Corporation) Hidden
WinRAR 5.00 (64-Bit) (Version: 5.00.0 - win.rar GmbH)

==================== Restore Points  =========================

03-01-2014 15:20:19 Garmin Express
11-01-2014 10:27:41 Geplanter Prüfpunkt
15-01-2014 13:26:27 Installed Java 7 Update 51
16-01-2014 13:07:58 Windows Update

==================== Hosts content: ==========================

2009-07-14 03:34 - 2009-06-10 22:00 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts

==================== Scheduled Tasks (whitelisted) =============

Task: {011E21C1-096A-4512-ADBB-B6862B20B18D} - System32\Tasks\SONY\SUS-BCF\Level4Daily => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {08799212-6B94-41FE-91A6-2C6896E110C8} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Scan the system => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDScan.exe
Task: {353D0556-A1CF-4BF8-9EB8-E7E80A0B6284} - System32\Tasks\Sony Corporation\VAIO Care\VCOneClick => C:\Program Files\Sony\VAIO Care\VCOneClick.exe [2011-02-16] (Sony Corporation)
Task: {53DCCA7C-F53A-4401-925E-AECFB394629A} - System32\Tasks\SONY\VAIO Power Management\VPM Session Change => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {580F0F58-DB00-41E0-B22F-C7A2C5BF6564} - System32\Tasks\Ad-Aware Antivirus Scheduled Scan => C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher.exe [2013-06-13] (Lavasoft Limited)
Task: {6216FDBE-2DE3-4C21-9A74-5BC685FAAA5E} - System32\Tasks\SONY\VAIO Power Management\VPM Logon Start => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {64F5C105-EADC-4468-A682-077344B3B594} - System32\Tasks\SONY\SUS-BCF\Level4Month => C:\Program Files (x86)\Sony\Setting Utility Series\WBCBatteryCare.exe [2010-07-26] (Sony Corporation)
Task: {698549F5-2782-442A-9951-1B399C00C311} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Check for updates => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe
Task: {6F63A80D-96F5-421E-B68E-CBF3E84AC01F} - System32\Tasks\{10182459-CFFA-4D5D-BF1E-E97CF00453CF} => Firefox.exe hxxp://ui.skype.com/ui/0/
Task: {9A88A67C-C08A-4CF4-877A-BDEF50AECC22} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-12-21] (Adobe Systems Incorporated)
Task: {A65840CB-BD79-4E8E-AC05-DBFD3F191FD0} - System32\Tasks\SONY\VAIO Gate\VAIO Gate => C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe [2009-08-05] (Sony Corporation)
Task: {B32DCDB0-4212-4368-9F65-4A2D3D39CC71} - System32\Tasks\Sony Corporation\VAIO Care\VAIO Care => C:\Program Files\Sony\VAIO Care\VCsystray.exe [2011-02-16] (Sony Corporation)
Task: {D76F951E-1DEC-419E-B965-743B4FF045D9} - System32\Tasks\SONY\VAIO Power Management\VPM Unlock => C:\Program Files\Sony\VAIO Power Management\SPMgr.exe [2010-06-21] (Sony Corporation)
Task: {EB0406D4-B9EB-4ACF-90AA-D8BC7D453F6A} - System32\Tasks\Safer-Networking\Spybot - Search and Destroy\Refresh immunization => C:\Program Files (x86)\Spybot - Search & Destroy 2\SDImmunize.exe
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe

==================== Loaded Modules (whitelisted) =============

2013-09-05 00:17 - 2013-09-05 00:17 - 04300456 _____ () C:\Program Files\Common Files\Microsoft Shared\OFFICE14\Cultures\OFFICE.ODF
2010-08-24 13:39 - 2010-08-24 13:39 - 00016384 _____ () C:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2013-09-23 16:16 - 2013-09-23 16:16 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2013-10-19 00:55 - 2013-10-19 00:55 - 25100288 _____ () C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\libcef.dll
2013-09-25 14:19 - 2013-05-16 09:55 - 00113496 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl
2013-09-25 14:19 - 2013-05-16 09:55 - 00416600 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl
2013-09-25 14:19 - 2013-05-16 09:55 - 00161112 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl
2013-09-25 14:19 - 2012-08-23 09:38 - 00574840 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\sqlite3.dll
2013-09-25 14:19 - 2012-04-03 16:06 - 00565640 _____ () C:\Program Files (x86)\Spybot - Search & Destroy 2\av\BDSmartDB.dll
2013-10-15 11:40 - 2011-01-13 10:44 - 00232800 _____ () C:\Program Files (x86)\StarMoney 9.0\ouservice\PATCHW32.dll
2013-09-25 14:35 - 2013-12-19 14:07 - 00190752 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libBase64.dll
2013-09-25 14:35 - 2013-12-19 14:07 - 00178464 _____ () C:\Program Files (x86)\Ad-Aware Antivirus\Definitions\libMachoUniv.dll
2013-09-23 16:35 - 2013-12-21 17:49 - 03559024 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
2013-09-05 00:14 - 2013-09-05 00:14 - 04300456 _____ () C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF

==================== Alternate Data Streams (whitelisted) =========

AlternateDataStreams: C:\Users\Landgraf-Vaio\Documents\Landgraf ___ MB Massivhaus, u_Z_ 549_12RE.eml:OECustomProperty

==================== Safe Mode (whitelisted) ===================

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service => ""="Ad-Aware Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\SBAMSvc => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Ad-Aware Service => ""="Ad-Aware Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MSIServer => ""="Service"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\SBAMSvc => ""="Service"

==================== Faulty Device Manager Devices =============

Name: Microsoft-Adapter für Miniports virtueller WiFis
Description: Microsoft-Adapter für Miniports virtueller WiFis
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Microsoft
Service: vwifimp
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

Name: Marvell Yukon 88E8059 PCI-E Gigabit Ethernet Controller
Description: Marvell Yukon 88E8059 PCI-E Gigabit Ethernet Controller
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Marvell
Service: yukonw7
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.

==================== Event log errors: =========================

Application errors:
Error: (01/19/2014 10:25:42 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service) (User: )
Description: Windows Search wird aufgrund eines Problems bei der Indizierung The catalog is corrupt beendet.

	Der Inhaltsindexkatalog ist fehlerhaft.   0xc0041801 (0xc0041801)

Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service) (User: )
Description: Vom Suchdienst wurden beschädigte Datendateien im Index {id=2350} erkannt. Vom Dienst wird versucht, dieses Problem durch Neuerstellung des Indexes automatisch zu beheben.

	Der Inhaltsindexkatalog ist fehlerhaft.   0xc0041801 (0xc0041801)

Error: (01/18/2014 07:52:30 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 06:44:32 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 04:51:05 PM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 03:34:04 PM) (Source: Application Hang) (User: )
Description: Programm firefox.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 1504

Startzeit: 01cf145a3d53c4fd

Endzeit: 14

Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID: 8bf65b7b-804d-11e3-b0de-18f46af81e57

Error: (01/18/2014 03:07:24 PM) (Source: Application Hang) (User: )
Description: Programm firefox.exe, Version kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.

Prozess-ID: 91c

Startzeit: 01cf1455e1d904dd

Endzeit: 31

Anwendungspfad: C:\Program Files (x86)\Mozilla Firefox\firefox.exe

Berichts-ID: d8953a08-8049-11e3-b0de-18f46af81e57

Error: (01/18/2014 11:32:14 AM) (Source: Customer Experience Improvement Program) (User: )
Description: 80004005

Error: (01/18/2014 10:37:29 AM) (Source: WinMgmt) (User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

System errors:
Error: (01/19/2014 10:25:14 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Garmin Core Update Service" wurde aufgrund folgenden Fehlers nicht gestartet: 

Error: (01/19/2014 10:25:14 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Garmin Core Update Service erreicht.

Error: (01/18/2014 11:12:50 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (01/18/2014 06:42:59 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (01/18/2014 04:51:33 PM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Updating Service" wurde aufgrund folgenden Fehlers nicht gestartet: 

Error: (01/18/2014 04:51:33 PM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Updating Service erreicht.

Error: (01/18/2014 04:49:24 PM) (Source: DCOM) (User: )
Description: {F9717507-6651-4EDB-BFF7-AE615179BCCF}

Error: (01/18/2014 10:37:18 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Spybot-S&D 2 Scanner Service" wurde aufgrund folgenden Fehlers nicht gestartet: 

Error: (01/18/2014 10:37:18 AM) (Source: Service Control Manager) (User: )
Description: Das Zeitlimit (30000 ms) wurde beim Verbindungsversuch mit dem Dienst Spybot-S&D 2 Scanner Service erreicht.

Error: (01/18/2014 10:36:48 AM) (Source: Service Control Manager) (User: )
Description: Der Dienst "Garmin Core Update Service" wurde aufgrund folgenden Fehlers nicht gestartet: 

Microsoft Office Sessions:
Error: (01/19/2014 10:25:42 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service)(User: )
	Der Inhaltsindexkatalog ist fehlerhaft.   0xc0041801 (0xc0041801)
The catalog is corrupt

Error: (01/18/2014 10:16:09 PM) (Source: Windows Search Service)(User: )
	Der Inhaltsindexkatalog ist fehlerhaft.   0xc0041801 (0xc0041801)

Error: (01/18/2014 07:52:30 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 06:44:32 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 04:51:05 PM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

Error: (01/18/2014 03:34:04 PM) (Source: Application Hang)(User: )
Description: firefox.exe26.0.0.5087150401cf145a3d53c4fd14C:\Program Files (x86)\Mozilla Firefox\firefox.exe8bf65b7b-804d-11e3-b0de-18f46af81e57

Error: (01/18/2014 03:07:24 PM) (Source: Application Hang)(User: )
Description: firefox.exe26.0.0.508791c01cf1455e1d904dd31C:\Program Files (x86)\Mozilla Firefox\firefox.exed8953a08-8049-11e3-b0de-18f46af81e57

Error: (01/18/2014 11:32:14 AM) (Source: Customer Experience Improvement Program)(User: )
Description: 80004005

Error: (01/18/2014 10:37:29 AM) (Source: WinMgmt)(User: )
Description: //./root/CIMV2SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 990x80041003

==================== Memory info =========================== 

Percentage of memory in use: 45%
Total physical RAM: 3950.1 MB
Available physical RAM: 2139.82 MB
Total Pagefile: 7898.38 MB
Available Pagefile: 5538.8 MB
Total Virtual: 8192 MB
Available Virtual: 8191.81 MB

==================== Drives ================================

Drive c: () (Fixed) (Total:465.66 GB) (Free:253.21 GB) NTFS

==================== MBR & Partition Table ==================

Disk: 0 (MBR Code: Windows 7 or 8) (Size: 466 GB) (Disk ID: 7A7F4430)
Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
Partition 2: (Not Active) - (Size=466 GB) - (Type=07 NTFS)

==================== End Of Log ============================
--- --- ---

defogger_disable by jpshortstuff (
Log created at 10:43 on 19/01/2014 (Landgraf-Vaio)

Checking for autostart values...
HKCU\~\Run values retrieved.
HKLM\~\Run values retrieved.

Checking for services/drivers...


FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 17-01-2014 03
Ran by Landgraf-Vaio (administrator) on LANDGRAFVAIO on 19-01-2014 10:45:00
Running from C:\Users\Landgraf-Vaio\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(Microsoft Corporation) C:\Windows\System32\StikyNot.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Lavasoft) C:\ProgramData\Search Protection\SearchProtection.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe
(Safer-Networking Ltd.) C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [212480 2010-09-15] (Alps Electric Co., Ltd.)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [SBRegRebootCleaner] - C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-09-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SDTray] - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe [5624784 2013-07-25] (Safer-Networking Ltd.)
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554384 2013-07-15] (Lavasoft)
HKLM-x32\...\Run: [Search Protection] - C:\ProgramData\Search Protection\SearchProtection.exe [943016 2013-06-13] (Lavasoft)
HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
Winlogon\Notify\SDWinLogon-x32: SDWinLogon.dll [X]
HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries)
HKCU\...\Run: [KB01353482.exe] - "C:\Users\Landgraf-Vaio\AppData\Roaming\KB01353482.exe"
HKCU\...\Run: [RESTART_STICKY_NOTES] - C:\Windows\System32\StikyNot.exe [427520 2009-07-14] (Microsoft Corporation)
Startup: C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id=adawaretb&v=3_4&ent=hp&u=CAAA82C8C61AAA03D18D225242E3D633
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8E2CB2916DB8CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
SearchScopes: HKCU - {3BD44F0E-0596-4008-AEE0-45D47E3A8F0E} URL = hxxp://securedsearch2.lavasoft.com/results.php?pr=vmn&id=adawaretb&v=3_4&hsimp=yhs-lavasoft&ent=ch&q={searchTerms}
BHO: AppGraffiti - {6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} - C:\PROGRA~2\APPGRA~1\APPGRA~2.DLL No File
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM-x32 - Ad-Aware Security Add-on - {6c97a91e-4524-4019-86af-2aa2d567bf5c} - C:\Program Files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll ()
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default
FF NewTab: hxxp://www.searchgol.com/?babsrc=NT_ss&mntrId=E8E118F46AF81E57&affID=119357&tsp=5014
FF SearchEngineOrder.1: Ask Search
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\ask-search.xml
FF SearchPlugin: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\inbox-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\adawaretb.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YouTube Unblocker - C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\Extensions\youtubeunblocker@unblocker.yt [2014-01-16]
FF Extension: Ad-Aware Security Add-on - C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\Extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c} [2013-09-25]

==================== Services (Whitelisted) =================

R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited)
S2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation)
R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software)
R2 SDScannerService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe [1817560 2013-05-16] (Safer-Networking Ltd.)
R2 SDUpdateService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe [1033688 2013-05-16] (Safer-Networking Ltd.)
R2 SDWSCService; C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe [171928 2013-05-15] (Safer-Networking Ltd.)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH)

==================== Drivers (Whitelisted) ====================

S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-09-25] (GFI Software)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-01-19 10:45 - 2014-01-19 10:45 - 00012572 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt
2014-01-19 10:44 - 2014-01-19 10:44 - 02076160 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe
2014-01-19 10:44 - 2014-01-19 10:44 - 00000000 ____D C:\FRST
2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log
2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable
2014-01-18 22:02 - 2014-01-18 22:52 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx
2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip
2014-01-18 21:42 - 2014-01-18 21:42 - 01077248 _____ (Zhorn Software) C:\Users\Landgraf-Vaio\Downloads\stickies_setup_7.1e.exe
2014-01-18 17:21 - 2014-01-18 17:22 - 00000280 _____ C:\Windows\wininit.ini
2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe
2014-01-18 16:52 - 2014-01-18 16:53 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-18 15:06 - 2014-01-19 10:40 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B
2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-15 14:27 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-15 14:27 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-15 14:27 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-15 14:27 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-15 14:20 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 14:20 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 14:20 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 14:19 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 14:19 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin
2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin
2014-01-03 16:20 - 2014-01-03 16:21 - 00000000 ____D C:\Program Files (x86)\Garmin
2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-21 12:46 - 2013-12-21 12:47 - 00024576 ___SH C:\Users\Landgraf-Vaio\Documents\Thumbs.db
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\webasto
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Vorlagen
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Steuererklärung
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\saeco
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Robert
2013-12-20 17:56 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Rechnungen
2013-12-20 17:55 - 2014-01-03 16:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Robert
2013-12-20 17:55 - 2014-01-03 16:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ICQ
2013-12-20 17:55 - 2014-01-03 16:52 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Anja
2013-12-20 17:54 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Hausbau
2013-12-20 17:54 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\email
2013-12-20 17:53 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ebooks
2013-12-20 17:53 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Auto
2013-12-20 17:52 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Anja
2013-12-20 17:50 - 2013-02-22 20:30 - 00122300 _____ C:\Users\Landgraf-Vaio\Documents\Landgraf ___ MB Massivhaus, u_Z_ 549_12RE.eml
2013-12-20 17:50 - 2012-05-12 23:57 - 341600159 _____ C:\Users\Landgraf-Vaio\Documents\PerAnhalterdurchdieGalaxis_ep7_anjalandgraf.aax
2013-12-20 14:18 - 2013-12-20 15:55 - 00004419 _____ C:\Users\Landgraf-Vaio\Downloads\config Landgraf AP.dat
2013-12-20 13:37 - 2013-12-20 13:37 - 00273904 _____ C:\Windows\Minidump\122013-18782-01.dmp
2013-12-20 13:16 - 2013-12-20 13:17 - 01892006 _____ C:\Users\Landgraf-Vaio\Downloads\CSL.ML.0726_fwc.bin

==================== One Month Modified Files and Folders =======

2014-01-19 10:45 - 2014-01-19 10:45 - 00012572 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt
2014-01-19 10:44 - 2014-01-19 10:44 - 02076160 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe
2014-01-19 10:44 - 2014-01-19 10:44 - 00000000 ____D C:\FRST
2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log
2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable
2014-01-19 10:43 - 2013-09-23 15:58 - 00000000 ____D C:\Users\Landgraf-Vaio
2014-01-19 10:40 - 2014-01-18 15:06 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B
2014-01-19 10:40 - 2013-09-23 15:58 - 00000000 ___RD C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-19 10:35 - 2013-09-23 19:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-19 10:33 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-19 10:33 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-19 10:30 - 2013-09-23 15:47 - 01428122 _____ C:\Windows\WindowsUpdate.log
2014-01-19 10:27 - 2013-09-23 19:18 - 00003978 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{302D991D-8607-4326-8B9F-1E38889BFE91}
2014-01-19 10:25 - 2013-12-01 17:47 - 00000000 ___RD C:\Users\Landgraf-Vaio\Dropbox
2014-01-19 10:25 - 2013-12-01 17:43 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox
2014-01-19 10:24 - 2013-10-29 21:34 - 00013303 _____ C:\Windows\setupact.log
2014-01-19 10:24 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-18 22:52 - 2014-01-18 22:02 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx
2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip
2014-01-18 21:42 - 2014-01-18 21:42 - 01077248 _____ (Zhorn Software) C:\Users\Landgraf-Vaio\Downloads\stickies_setup_7.1e.exe
2014-01-18 18:43 - 2013-10-31 01:14 - 00003290 _____ C:\Windows\PFRO.log
2014-01-18 17:22 - 2014-01-18 17:21 - 00000280 _____ C:\Windows\wininit.ini
2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe
2014-01-18 16:53 - 2014-01-18 16:52 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-18 14:48 - 2013-09-25 16:56 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Windows Live
2014-01-18 10:37 - 2013-09-25 15:09 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0
2014-01-17 08:14 - 2013-10-01 22:53 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Skype
2014-01-16 19:14 - 2013-12-01 17:45 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-16 19:09 - 2009-07-14 05:45 - 00417024 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-16 14:11 - 2013-09-23 18:39 - 00000000 ____D C:\Windows\system32\MRT
2014-01-16 14:08 - 2013-09-23 18:39 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-15 14:27 - 2013-09-29 20:45 - 00000000 ____D C:\ProgramData\Oracle
2014-01-15 14:27 - 2013-09-29 20:44 - 00000000 ____D C:\Program Files (x86)\Java
2014-01-12 17:14 - 2010-11-21 07:50 - 00654166 _____ C:\Windows\system32\perfh007.dat
2014-01-12 17:14 - 2010-11-21 07:50 - 00130006 _____ C:\Windows\system32\perfc007.dat
2014-01-12 17:14 - 2009-07-14 06:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-12 12:12 - 2013-09-25 14:19 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-01-09 13:19 - 2013-09-25 16:05 - 00000000 ____D C:\Windows\System32\Tasks\Games
2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Robert
2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ICQ
2014-01-03 16:52 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Anja
2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin
2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin
2014-01-03 16:21 - 2014-01-03 16:20 - 00000000 ____D C:\Program Files (x86)\Garmin
2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache
2013-12-31 11:44 - 2013-10-23 09:47 - 00326527 _____ C:\test.xml
2013-12-22 13:03 - 2013-09-25 14:24 - 00000000 ____D C:\ProgramData\Search Protection
2013-12-21 23:36 - 2013-10-03 16:50 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Adobe
2013-12-21 23:36 - 2013-09-23 19:17 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2013-12-21 23:36 - 2013-09-23 19:17 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2013-12-21 23:36 - 2013-09-23 19:17 - 00003822 _____ C:\Windows\System32\Tasks\Adobe Flash Player Updater
2013-12-21 23:06 - 2013-09-26 13:28 - 00000000 ____D C:\andere sachen
2013-12-21 17:49 - 2013-09-23 16:35 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2013-12-21 12:47 - 2013-12-21 12:46 - 00024576 ___SH C:\Users\Landgraf-Vaio\Documents\Thumbs.db
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\webasto
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Vorlagen
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Steuererklärung
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\saeco
2013-12-20 18:00 - 2013-12-20 18:00 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Robert
2013-12-20 18:00 - 2013-12-20 17:56 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Rechnungen
2013-12-20 17:55 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Hausbau
2013-12-20 17:54 - 2013-12-20 17:54 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\email
2013-12-20 17:54 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ebooks
2013-12-20 17:53 - 2013-12-20 17:53 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Auto
2013-12-20 17:53 - 2013-12-20 17:52 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Anja
2013-12-20 15:55 - 2013-12-20 14:18 - 00004419 _____ C:\Users\Landgraf-Vaio\Downloads\config Landgraf AP.dat
2013-12-20 13:37 - 2013-12-20 13:37 - 00273904 _____ C:\Windows\Minidump\122013-18782-01.dmp
2013-12-20 13:37 - 2013-09-25 08:17 - 363185970 _____ C:\Windows\MEMORY.DMP
2013-12-20 13:37 - 2013-09-25 08:17 - 00000000 ____D C:\Windows\Minidump
2013-12-20 13:17 - 2013-12-20 13:16 - 01892006 _____ C:\Users\Landgraf-Vaio\Downloads\CSL.ML.0726_fwc.bin

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2014-01-09 13:12

==================== End Of Log ============================
--- --- ---

GMER Logfile:
GMER 2.1.19324 - hxxp://www.gmer.net
Rootkit scan 2014-01-19 11:13:23
Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 ST9500325AS rev.0006SDM2 465,76GB
Running: 0pk01sgw.exe; Driver: C:\Users\LANDGR~1\AppData\Local\Temp\fflcqkod.sys

---- Kernel code sections - GMER 2.1 ----

INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 528                                                                       fffff80002db0000 45 bytes [00, 00, 15, 02, 46, 69, 6C, ...]
INITKDBG  C:\Windows\system32\ntoskrnl.exe!ExDeleteNPagedLookasideList + 574                                                                       fffff80002db002e 17 bytes [CE, 01, 00, 00, 00, 00, 00, ...]
.text     C:\Windows\System32\win32k.sys!W32pServiceTable                                                                                          fffff96000153e00 7 bytes [00, 96, F3, FF, 01, A1, F0]
.text     C:\Windows\System32\win32k.sys!W32pServiceTable + 8                                                                                      fffff96000153e08 3 bytes [C0, 06, 02]

---- User code sections - GMER 2.1 ----

.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                        0000000076f40068 5 bytes JMP 00000001009fd480
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                            0000000076f5c4dd 5 bytes JMP 00000001009fd450
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!DeleteSecurityContext               0000000074960bb9 5 bytes JMP 00000001009fd9a0
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!EncryptMessage                      000000007496124e 5 bytes JMP 00000001009fdb80
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!DecryptMessage                      000000007496129d 5 bytes JMP 00000001009fd9c0
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextW          0000000074961557 5 bytes JMP 00000001009fdc00
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextA          0000000074961590 5 bytes JMP 00000001009fdc90
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!closesocket                          0000000075c63918 5 bytes JMP 00000001009fd5d0
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!WSASend                              0000000075c64406 5 bytes JMP 00000001009fd800
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!recv                                 0000000075c66b0e 5 bytes JMP 00000001009fd6f0
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!connect                              0000000075c66bdd 5 bytes JMP 00000001009fd970
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!send                                 0000000075c66f01 5 bytes JMP 00000001009fd8c0
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\WS2_32.dll!WSARecv                              0000000075c67089 5 bytes JMP 00000001009fd5f0
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 69             0000000074a81465 2 bytes [A8, 74]
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\Psapi.dll!GetModuleInformation + 155            0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe[2412] C:\Windows\syswow64\Crypt32.DLL!PFXImportCertStore                  0000000075ad18b8 5 bytes JMP 00000001009fe0e0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                         0000000076f40068 5 bytes JMP 00000001001ed480
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                             0000000076f5c4dd 5 bytes JMP 00000001001ed450
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!DeleteSecurityContext                0000000074960bb9 5 bytes JMP 00000001001ed9a0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!EncryptMessage                       000000007496124e 5 bytes JMP 00000001001edb80
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!DecryptMessage                       000000007496129d 5 bytes JMP 00000001001ed9c0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextW           0000000074961557 5 bytes JMP 00000001001edc00
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextA           0000000074961590 5 bytes JMP 00000001001edc90
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\crypt32.dll!PFXImportCertStore                   0000000075ad18b8 5 bytes JMP 00000001001ee0e0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!closesocket                           0000000075c63918 5 bytes JMP 00000001001ed5d0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!WSASend                               0000000075c64406 5 bytes JMP 00000001001ed800
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!recv                                  0000000075c66b0e 5 bytes JMP 00000001001ed6f0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!connect                               0000000075c66bdd 5 bytes JMP 00000001001ed970
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!send                                  0000000075c66f01 5 bytes JMP 00000001001ed8c0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\WS2_32.dll!WSARecv                               0000000075c67089 5 bytes JMP 00000001001ed5f0
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69              0000000074a81465 2 bytes [A8, 74]
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe[2904] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155             0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[3000] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69             0000000074a81465 2 bytes [A8, 74]
.text     C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe[3000] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155            0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69   0000000074a81465 2 bytes [A8, 74]
.text     C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe[2248] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155  0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                             0000000076f40068 5 bytes JMP 00000001000ad480
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                 0000000076f5c4dd 5 bytes JMP 00000001000ad450
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!DeleteSecurityContext                    0000000074960bb9 5 bytes JMP 00000001000ad9a0
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!EncryptMessage                           000000007496124e 5 bytes JMP 00000001000adb80
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!DecryptMessage                           000000007496129d 5 bytes JMP 00000001000ad9c0
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextW               0000000074961557 5 bytes JMP 00000001000adc00
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\SspiCli.dll!InitializeSecurityContextA               0000000074961590 5 bytes JMP 00000001000adc90
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                  0000000074a81465 2 bytes [A8, 74]
.text     C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe[2792] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                 0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\ProgramData\Search Protection\SearchProtection.exe[3080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                      0000000074a81465 2 bytes [A8, 74]
.text     C:\ProgramData\Search Protection\SearchProtection.exe[3080] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                     0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                      0000000076f40068 5 bytes JMP 00000001001dd480
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                          0000000076f5c4dd 5 bytes JMP 00000001001dd450
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!closesocket                        0000000075c63918 5 bytes JMP 00000001001dd5d0
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!WSASend                            0000000075c64406 5 bytes JMP 00000001001dd800
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!recv                               0000000075c66b0e 5 bytes JMP 00000001001dd6f0
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!connect                            0000000075c66bdd 5 bytes JMP 00000001001dd970
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!send                               0000000075c66f01 5 bytes JMP 00000001001dd8c0
.text     C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe[2556] C:\Windows\syswow64\WS2_32.dll!WSARecv                            0000000075c67089 5 bytes JMP 00000001001dd5f0
.text     C:\PROGRA~2\AD-AWA~1\AdAware.exe[4444] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                           0000000074a81465 2 bytes [A8, 74]
.text     C:\PROGRA~2\AD-AWA~1\AdAware.exe[4444] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                          0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                                      0000000076f40068 5 bytes JMP 000000010011d480
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                                          0000000076f5c4dd 5 bytes JMP 000000010011d450
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69                                           0000000074a81465 2 bytes [A8, 74]
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155                                          0000000074a814bb 2 bytes [A8, 74]
.text     ...                                                                                                                                      * 2
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!closesocket                                                        0000000075c63918 5 bytes JMP 000000010011d5d0
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!WSASend                                                            0000000075c64406 5 bytes JMP 000000010011d800
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!recv                                                               0000000075c66b0e 5 bytes JMP 000000010011d6f0
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!connect                                                            0000000075c66bdd 5 bytes JMP 000000010011d970
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!send                                                               0000000075c66f01 5 bytes JMP 000000010011d8c0
.text     C:\Windows\SysWOW64\RunDll32.exe[1584] C:\Windows\syswow64\WS2_32.dll!WSARecv                                                            0000000075c67089 5 bytes JMP 000000010011d5f0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                 0000000076f40068 5 bytes JMP 000000010025d480
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                     0000000076f5c4dd 5 bytes JMP 000000010025d450
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!closesocket                   0000000075c63918 5 bytes JMP 000000010025d5d0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!WSASend                       0000000075c64406 5 bytes JMP 000000010025d800
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!recv                          0000000075c66b0e 5 bytes JMP 000000010025d6f0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!connect                       0000000075c66bdd 5 bytes JMP 000000010025d970
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!send                          0000000075c66f01 5 bytes JMP 000000010025d8c0
.text     C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe[3632] C:\Windows\syswow64\WS2_32.dll!WSARecv                       0000000075c67089 5 bytes JMP 000000010025d5f0
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\SysWOW64\ntdll.dll!NtResumeThread                                          0000000076f40068 5 bytes JMP 000000010042d480
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\SysWOW64\ntdll.dll!LdrLoadDll                                              0000000076f5c4dd 5 bytes JMP 000000010042d450
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!closesocket                                            0000000075c63918 5 bytes JMP 000000010042d5d0
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!WSASend                                                0000000075c64406 5 bytes JMP 000000010042d800
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!recv                                                   0000000075c66b0e 5 bytes JMP 000000010042d6f0
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!connect                                                0000000075c66bdd 5 bytes JMP 000000010042d970
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!send                                                   0000000075c66f01 5 bytes JMP 000000010042d8c0
.text     C:\Program Files\Sony\VAIO Care\listener.exe[4180] C:\Windows\syswow64\WS2_32.dll!WSARecv                                                0000000075c67089 5 bytes JMP 000000010042d5f0

---- Threads - GMER 2.1 ----

Thread    C:\Windows\SysWOW64\RunDll32.exe [1584:3296]                                                                                             000000000011b890
Thread    C:\Windows\SysWOW64\RunDll32.exe [1584:4428]                                                                                             0000000000119480
Thread    C:\Windows\SysWOW64\RunDll32.exe [1584:4412]                                                                                             000000000011c920

---- Registry - GMER 2.1 ----

Reg       HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\18f46af81e57                                                              
Reg       HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\18f46af81e57 (not active ControlSet)                                          

---- EOF - GMER 2.1 ----
--- --- ---
leider weiss ich nicht wie ich die Log-Datei vom Ad-Aware-Antivirus-Programm auslesen kann, Sry
es hat 3x Trojan Win32 Generic! BT und einmal Worm.Win32.Critec.ac(v) gefunden, ich lasse diese dinge noch in der Quarantäne bis ich von ihnen was anderes höre
Vielen dank schon einmal im Voraus

Alt 19.01.2014, 14:21   #2
/// the machine
/// TB-Ausbilder

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Standard

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

Combofix sollte ausschließlich ausgeführt werden, wenn dies von einem Teammitglied angewiesen wurde!
Downloade dir bitte Combofix vom folgenden Downloadspiegel

Link 1

WICHTIG - Speichere Combofix auf deinem Desktop
  • Deaktiviere bitte all deine Anti Viren sowie Anti Malware/Spyware Scanner. Diese können Combofix bei der Arbeit stören.
Starte die Combofix.exe und folge den Anweisungen auf dem Bildschirm.

Wenn Combofix fertig ist, wird es eine Logfile erstellen. Bitte poste die C:\Combofix.txt in deiner nächsten Antwort.

Hinweis: Solltest du nach dem Neustart folgende Fehlermeldung erhalten
Es wurde versucht, einen Registrierungsschlüssel einem ungültigen Vorgang zu unterziehen, der zum Löschen markiert wurde.
starte den Rechner einfach neu. Dies sollte das Problem beheben.


Alt 19.01.2014, 20:35   #3
Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Standard

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

Hallo, hier das ergebnis der Log-Datei:

Combofix Logfile:
ComboFix 14-01-16.03 - Landgraf-Vaio 19.01.2014  20:26:21.2.4 - x64
Microsoft Windows 7 Home Premium   6.1.7601.1.1252.49.1031.18.3950.2333 [GMT 1:00]
ausgeführt von:: c:\users\Landgraf-Vaio\Desktop\ComboFix.exe
AV: Lavasoft Ad-Aware *Disabled/Updated* {E0D97DD4-42BA-B3F2-A5A7-22E9ACE81FC7}
FW: Lavasoft Ad-Aware *Disabled* {D8E2FCF1-08D5-B2AA-8EF8-8BDC523B58BC}
SP: Lavasoft Ad-Aware *Disabled/Updated* {5BB89C30-6480-BC7C-9F17-199BD76F557A}
SP: Spybot - Search and Destroy *Disabled/Updated* {9BC38DF1-3CCA-732D-A930-C1CA5F20A4B0}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
(((((((((((((((((((((((   Dateien erstellt von 2013-12-19 bis 2014-01-19  ))))))))))))))))))))))))))))))
2014-01-19 19:30 . 2014-01-19 19:30	--------	d-----w-	c:\users\Default\AppData\Local\temp
2014-01-19 19:30 . 2014-01-19 19:30	--------	d-----w-	c:\users\Administrator\AppData\Local\temp
2014-01-19 09:44 . 2014-01-19 09:44	--------	d-----w-	C:\FRST
2014-01-18 14:06 . 2014-01-19 09:40	--------	d--h--w-	c:\users\Landgraf-Vaio\AppData\Roaming\34295F2B
2014-01-15 13:27 . 2013-12-18 20:09	96168	----a-w-	c:\windows\SysWow64\WindowsAccessBridge-32.dll
2014-01-15 13:20 . 2013-11-27 01:41	53248	----a-w-	c:\windows\system32\drivers\usbehci.sys
2014-01-15 13:20 . 2013-11-27 01:41	325120	----a-w-	c:\windows\system32\drivers\usbport.sys
2014-01-15 13:20 . 2013-11-27 01:41	343040	----a-w-	c:\windows\system32\drivers\usbhub.sys
2014-01-15 13:19 . 2013-11-27 01:41	99840	----a-w-	c:\windows\system32\drivers\usbccgp.sys
2014-01-15 13:19 . 2013-11-27 01:41	25600	----a-w-	c:\windows\system32\drivers\usbohci.sys
2014-01-15 13:19 . 2013-11-27 01:41	30720	----a-w-	c:\windows\system32\drivers\usbuhci.sys
2014-01-15 13:19 . 2013-11-27 01:41	7808	----a-w-	c:\windows\system32\drivers\usbd.sys
2014-01-15 13:19 . 2013-11-26 10:32	3156480	----a-w-	c:\windows\system32\win32k.sys
2014-01-15 13:19 . 2013-11-26 11:40	376768	----a-w-	c:\windows\system32\drivers\netio.sys
2014-01-03 15:22 . 2014-01-03 15:22	--------	d-----w-	c:\users\Landgraf-Vaio\AppData\Roaming\Garmin
2014-01-03 15:21 . 2014-01-03 15:21	--------	d-----w-	c:\users\Landgraf-Vaio\AppData\Local\Garmin
2014-01-03 15:21 . 2014-01-03 15:21	--------	d-----w-	c:\programdata\Garmin
2014-01-03 15:20 . 2014-01-03 15:21	--------	d-----w-	c:\program files (x86)\Garmin
2014-01-03 15:20 . 2014-01-03 15:20	--------	d-----w-	c:\programdata\Package Cache
((((((((((((((((((((((((((((((((((((   Find3M Bericht   ))))))))))))))))))))))))))))))))))))))))))))))))))))))
2014-01-16 13:08 . 2013-09-23 17:39	86054176	----a-w-	c:\windows\system32\MRT.exe
2013-12-21 22:36 . 2013-09-23 18:17	71048	----a-w-	c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2013-12-21 22:36 . 2013-09-23 18:17	692616	----a-w-	c:\windows\SysWow64\FlashPlayerApp.exe
2013-11-26 11:54 . 2013-12-11 18:25	23183360	----a-w-	c:\windows\system32\mshtml.dll
2013-11-26 10:19 . 2013-12-11 18:25	2724864	----a-w-	c:\windows\system32\mshtml.tlb
2013-11-26 10:18 . 2013-12-11 18:25	4096	----a-w-	c:\windows\system32\ieetwcollectorres.dll
2013-11-26 09:48 . 2013-12-11 18:25	66048	----a-w-	c:\windows\system32\iesetup.dll
2013-11-26 09:46 . 2013-12-11 18:25	48640	----a-w-	c:\windows\system32\ieetwproxystub.dll
2013-11-26 09:41 . 2013-12-11 18:25	2764288	----a-w-	c:\windows\system32\iertutil.dll
2013-11-26 09:29 . 2013-12-11 18:25	53760	----a-w-	c:\windows\system32\jsproxy.dll
2013-11-26 09:27 . 2013-12-11 18:25	33792	----a-w-	c:\windows\system32\iernonce.dll
2013-11-26 09:23 . 2013-12-11 18:25	2724864	----a-w-	c:\windows\SysWow64\mshtml.tlb
2013-11-26 09:21 . 2013-12-11 18:25	574976	----a-w-	c:\windows\system32\ieui.dll
2013-11-26 09:18 . 2013-12-11 18:25	139264	----a-w-	c:\windows\system32\ieUnatt.exe
2013-11-26 09:18 . 2013-12-11 18:25	111616	----a-w-	c:\windows\system32\ieetwcollector.exe
2013-11-26 09:16 . 2013-12-11 18:25	708608	----a-w-	c:\windows\system32\jscript9diag.dll
2013-11-26 08:57 . 2013-12-11 18:25	218624	----a-w-	c:\windows\system32\ie4uinit.exe
2013-11-26 08:35 . 2013-12-11 18:25	5769216	----a-w-	c:\windows\system32\jscript9.dll
2013-11-26 08:28 . 2013-12-11 18:25	553472	----a-w-	c:\windows\SysWow64\jscript9diag.dll
2013-11-26 08:16 . 2013-12-11 18:25	4243968	----a-w-	c:\windows\SysWow64\jscript9.dll
2013-11-26 08:02 . 2013-12-11 18:25	1995264	----a-w-	c:\windows\system32\inetcpl.cpl
2013-11-26 07:48 . 2013-12-11 18:25	12996608	----a-w-	c:\windows\system32\ieframe.dll
2013-11-26 07:32 . 2013-12-11 18:25	1928192	----a-w-	c:\windows\SysWow64\inetcpl.cpl
2013-11-26 07:07 . 2013-12-11 18:25	2334208	----a-w-	c:\windows\system32\wininet.dll
2013-11-26 06:40 . 2013-12-11 18:25	1395200	----a-w-	c:\windows\system32\urlmon.dll
2013-11-26 06:34 . 2013-12-11 18:25	817664	----a-w-	c:\windows\system32\ieapfltr.dll
2013-11-26 06:33 . 2013-12-11 18:25	1820160	----a-w-	c:\windows\SysWow64\wininet.dll
2013-11-23 18:26 . 2013-12-11 13:30	417792	----a-w-	c:\windows\SysWow64\WMPhoto.dll
2013-11-23 17:47 . 2013-12-11 13:30	465920	----a-w-	c:\windows\system32\WMPhoto.dll
2013-11-21 08:40 . 2013-11-21 08:40	940032	----a-w-	c:\windows\system32\MsSpellCheckingFacility.exe
2013-11-21 08:40 . 2013-11-21 08:40	194048	----a-w-	c:\windows\SysWow64\elshyph.dll
2013-11-21 08:40 . 2013-11-21 08:40	235008	----a-w-	c:\windows\system32\elshyph.dll
2013-11-21 08:40 . 2013-11-21 08:40	645120	----a-w-	c:\windows\SysWow64\jsIntl.dll
2013-11-21 08:40 . 2013-11-21 08:40	71680	----a-w-	c:\windows\SysWow64\RegisterIEPKEYs.exe
2013-11-21 08:40 . 2013-11-21 08:40	182272	----a-w-	c:\windows\SysWow64\msls31.dll
2013-11-21 08:39 . 2013-11-21 08:39	34816	----a-w-	c:\windows\SysWow64\JavaScriptCollectionAgent.dll
2013-11-21 08:39 . 2013-11-21 08:39	62464	----a-w-	c:\windows\SysWow64\tdc.ocx
2013-11-21 08:39 . 2013-11-21 08:39	337408	----a-w-	c:\windows\SysWow64\html.iec
2013-11-21 08:39 . 2013-11-21 08:39	61952	----a-w-	c:\windows\SysWow64\iesetup.dll
2013-11-21 08:39 . 2013-11-21 08:39	24576	----a-w-	c:\windows\SysWow64\licmgr10.dll
2013-11-21 08:39 . 2013-11-21 08:39	1051136	----a-w-	c:\windows\SysWow64\mshtmlmedia.dll
2013-11-21 08:39 . 2013-11-21 08:39	139264	----a-w-	c:\windows\SysWow64\wextract.exe
2013-11-21 08:39 . 2013-11-21 08:39	454656	----a-w-	c:\windows\SysWow64\vbscript.dll
2013-11-21 08:39 . 2013-11-21 08:39	151552	----a-w-	c:\windows\SysWow64\iexpress.exe
2013-11-21 08:39 . 2013-11-21 08:39	112128	----a-w-	c:\windows\SysWow64\ieUnatt.exe
2013-11-21 08:39 . 2013-11-21 08:39	61952	----a-w-	c:\windows\SysWow64\MshtmlDac.dll
2013-11-21 08:39 . 2013-11-21 08:39	51200	----a-w-	c:\windows\SysWow64\ieetwproxystub.dll
2013-11-21 08:39 . 2013-11-21 08:39	36352	----a-w-	c:\windows\SysWow64\imgutil.dll
2013-11-21 08:39 . 2013-11-21 08:39	13312	----a-w-	c:\windows\SysWow64\mshta.exe
2013-11-21 08:39 . 2013-11-21 08:39	111616	----a-w-	c:\windows\SysWow64\IEAdvpack.dll
2013-11-21 08:39 . 2013-11-21 08:39	74240	----a-w-	c:\windows\SysWow64\SetIEInstalledDate.exe
2013-11-21 08:39 . 2013-11-21 08:39	48640	----a-w-	c:\windows\SysWow64\mshtmler.dll
2013-11-21 08:39 . 2013-11-21 08:39	942592	----a-w-	c:\windows\system32\jsIntl.dll
2013-11-21 08:39 . 2013-11-21 08:39	86016	----a-w-	c:\windows\SysWow64\iesysprep.dll
2013-11-21 08:39 . 2013-11-21 08:39	86016	----a-w-	c:\windows\system32\RegisterIEPKEYs.exe
2013-11-21 08:39 . 2013-11-21 08:39	247808	----a-w-	c:\windows\system32\msls31.dll
2013-11-21 08:39 . 2013-11-21 08:39	52224	----a-w-	c:\windows\system32\msfeedsbs.dll
2013-11-21 08:39 . 2013-11-21 08:39	195584	----a-w-	c:\windows\system32\msrating.dll
2013-11-21 08:39 . 2013-11-21 08:39	13312	----a-w-	c:\windows\system32\msfeedssync.exe
2013-11-21 08:39 . 2013-11-21 08:39	131072	----a-w-	c:\windows\system32\IEAdvpack.dll
2013-11-21 08:39 . 2013-11-21 08:39	90112	----a-w-	c:\windows\system32\SetIEInstalledDate.exe
2013-11-21 08:39 . 2013-11-21 08:39	77312	----a-w-	c:\windows\system32\tdc.ocx
2013-11-21 08:39 . 2013-11-21 08:39	48640	----a-w-	c:\windows\system32\mshtmler.dll
2013-11-21 08:39 . 2013-11-21 08:39	105984	----a-w-	c:\windows\system32\iesysprep.dll
2013-11-21 08:39 . 2013-11-21 08:39	453120	----a-w-	c:\windows\system32\dxtmsft.dll
2013-11-21 08:39 . 2013-11-21 08:39	413696	----a-w-	c:\windows\system32\html.iec
2013-11-21 08:39 . 2013-11-21 08:39	40448	----a-w-	c:\windows\system32\JavaScriptCollectionAgent.dll
2013-11-21 08:39 . 2013-11-21 08:39	296960	----a-w-	c:\windows\system32\dxtrans.dll
2013-11-21 08:39 . 2013-11-21 08:39	81408	----a-w-	c:\windows\system32\icardie.dll
2013-11-21 08:39 . 2013-11-21 08:39	616104	----a-w-	c:\windows\system32\ieapfltr.dat
2013-11-21 08:39 . 2013-11-21 08:39	30208	----a-w-	c:\windows\system32\licmgr10.dll
2013-11-21 08:39 . 2013-11-21 08:39	263376	----a-w-	c:\windows\system32\iedkcs32.dll
2013-11-21 08:39 . 2013-11-21 08:39	243200	----a-w-	c:\windows\system32\webcheck.dll
2013-11-21 08:39 . 2013-11-21 08:39	235520	----a-w-	c:\windows\system32\url.dll
2013-11-21 08:39 . 2013-11-21 08:39	1228800	----a-w-	c:\windows\system32\mshtmlmedia.dll
2013-11-21 08:39 . 2013-11-21 08:39	84992	----a-w-	c:\windows\system32\mshtmled.dll
2013-11-21 08:39 . 2013-11-21 08:39	167424	----a-w-	c:\windows\system32\iexpress.exe
2013-11-21 08:39 . 2013-11-21 08:39	143872	----a-w-	c:\windows\system32\wextract.exe
2013-11-21 08:39 . 2013-11-21 08:39	101376	----a-w-	c:\windows\system32\inseng.dll
2013-11-21 08:39 . 2013-11-21 08:39	626176	----a-w-	c:\windows\system32\msfeeds.dll
2013-11-21 08:39 . 2013-11-21 08:39	548352	----a-w-	c:\windows\system32\vbscript.dll
2013-11-21 08:39 . 2013-11-21 08:39	62464	----a-w-	c:\windows\system32\pngfilt.dll
2013-11-21 08:39 . 2013-11-21 08:39	147968	----a-w-	c:\windows\system32\occache.dll
2013-11-21 08:39 . 2013-11-21 08:39	13824	----a-w-	c:\windows\system32\mshta.exe
2013-11-21 08:39 . 2013-11-21 08:39	83968	----a-w-	c:\windows\system32\MshtmlDac.dll
2013-11-21 08:39 . 2013-11-21 08:39	774144	----a-w-	c:\windows\system32\jscript.dll
2013-11-21 08:39 . 2013-11-21 08:39	48128	----a-w-	c:\windows\system32\imgutil.dll
2013-11-21 08:39 . 2013-11-21 08:39	135680	----a-w-	c:\windows\system32\iepeers.dll
2013-11-12 02:23 . 2013-12-11 13:30	2048	----a-w-	c:\windows\system32\tzres.dll
2013-11-12 02:07 . 2013-12-11 13:30	2048	----a-w-	c:\windows\SysWow64\tzres.dll
2013-10-30 02:32 . 2013-12-11 13:30	335360	----a-w-	c:\windows\system32\msieftp.dll
2013-10-30 02:19 . 2013-12-11 13:30	301568	----a-w-	c:\windows\SysWow64\msieftp.dll
2013-10-24 07:50 . 2013-10-24 07:50	163504	----a-w-	c:\programdata\Microsoft\Windows\Sqm\Manifest\Sqm10145.bin
((((((((((((((((((((((((((((   Autostartpunkte der Registrierung   ))))))))))))))))))))))))))))))))))))))))
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\~\Browser Helper Objects\{6c97a91e-4524-4019-86af-2aa2d567bf5c}]
2013-08-09 14:50	91536	----a-w-	c:\program files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar]
"{6c97a91e-4524-4019-86af-2aa2d567bf5c}"= "c:\program files (x86)\Lavasoft\AdAware SecureSearch Toolbar\adawareDx.dll" [2013-08-09 91536]
2013-09-10 23:54	131248	----a-w-	c:\users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
2013-09-10 23:54	131248	----a-w-	c:\users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
2013-09-10 23:54	131248	----a-w-	c:\users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\DropboxExt.22.dll
"Sidebar"="c:\program files\Windows Sidebar\sidebar.exe" [2010-11-21 1475584]
"GarminExpressTrayApp"="c:\program files (x86)\Garmin\Express Tray\ExpressTray.exe" [2013-12-30 1095000]
"Ad-Aware Antivirus"="c:\program files (x86)\Ad-Aware Antivirus\AdAwareLauncher --windows-run" [X]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2010-09-20 102400]
"Ad-Aware Browsing Protection"="c:\programdata\Ad-Aware Browsing Protection\adawarebp.exe" [2013-07-15 554384]
"Search Protection"="c:\programdata\Search Protection\SearchProtection.exe" [2013-06-13 943016]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2013-07-02 254336]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2013-11-21 959904]
c:\users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dropbox.lnk - c:\users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe /systemstartup [2014-1-3 30714328]
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Bluetooth.lnk - c:\program files\WIDCOMM\Bluetooth Software\BTTray.exe [2010-6-8 1128224]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\windows]
"LoadAppInit_DLLs"=1 (0x1)
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Ad-Aware Service]
@="Ad-Aware Service"
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [x]
R2 SkypeUpdate;Skype Updater;c:\program files (x86)\Skype\Updater\Updater.exe;c:\program files (x86)\Skype\Updater\Updater.exe [x]
R3 gfiark;gfiark;c:\windows\system32\drivers\gfiark.sys;c:\windows\SYSNATIVE\drivers\gfiark.sys [x]
R3 IEEtwCollectorService;Internet Explorer ETW Collector Service;c:\windows\system32\IEEtwCollector.exe;c:\windows\SYSNATIVE\IEEtwCollector.exe [x]
R3 ose64;Office 64 Source Engine;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE;c:\program files\Common Files\Microsoft Shared\Source Engine\OSE.EXE [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys;c:\windows\SYSNATIVE\drivers\rdpvideominiport.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys;c:\windows\SYSNATIVE\drivers\tsusbflt.sys [x]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys;c:\windows\SYSNATIVE\drivers\TsUsbGD.sys [x]
R3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys;c:\windows\SYSNATIVE\DRIVERS\yk62x64.sys [x]
S0 gfibto;gfibto;c:\windows\system32\drivers\gfibto.sys;c:\windows\SYSNATIVE\drivers\gfibto.sys [x]
S2 Ad-Aware Service;Ad-Aware Service;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe;c:\program files (x86)\Ad-Aware Antivirus\AdAwareService.exe [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe;c:\windows\SYSNATIVE\atiesrxx.exe [x]
S2 Garmin Core Update Service;Garmin Core Update Service;c:\program files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe;c:\program files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [x]
S2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimssne64.sys;c:\windows\SYSNATIVE\DRIVERS\rimssne64.sys [x]
S2 risdsnpe;risdsnpe;c:\windows\system32\DRIVERS\risdsne64.sys;c:\windows\SYSNATIVE\DRIVERS\risdsne64.sys [x]
S2 SampleCollector;VAIO Care Performance Service;c:\program files\Sony\VAIO Care\VCPerfService.exe;c:\program files\Sony\VAIO Care\VCPerfService.exe [x]
S2 SBAMSvc;Ad-Aware;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe;c:\program files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [x]
S2 sbapifs;sbapifs;c:\windows\system32\DRIVERS\sbapifs.sys;c:\windows\SYSNATIVE\DRIVERS\sbapifs.sys [x]
S2 StarMoney 9.0 OnlineUpdate;StarMoney 9.0 OnlineUpdate;c:\program files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe;c:\program files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [x]
S2 VAIO Power Management;VAIO Power Management;c:\program files\Sony\VAIO Power Management\SPMService.exe;c:\program files\Sony\VAIO Power Management\SPMService.exe [x]
S3 btwampfl;Bluetooth AMP USB Filter;c:\windows\system32\drivers\btwampfl.sys;c:\windows\SYSNATIVE\drivers\btwampfl.sys [x]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys;c:\windows\SYSNATIVE\DRIVERS\btwl2cap.sys [x]
S3 HECIx64;Intel(R) Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys;c:\windows\SYSNATIVE\DRIVERS\HECIx64.sys [x]
S3 SFEP;Sony Firmware Extension Parser;c:\windows\system32\DRIVERS\SFEP.sys;c:\windows\SYSNATIVE\DRIVERS\SFEP.sys [x]
S3 VCService;VCService;c:\program files\Sony\VAIO Care\VCService.exe;c:\program files\Sony\VAIO Care\VCService.exe [x]
Inhalt des "geplante Tasks" Ordners
2014-01-19 c:\windows\Tasks\Adobe Flash Player Updater.job
- c:\windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2013-09-23 22:36]
--------- X64 Entries -----------
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}]
c:\progra~2\APPGRA~1\APPGRA~2.DLL [BU]
2013-09-10 23:54	164016	----a-w-	c:\users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
2013-09-10 23:54	164016	----a-w-	c:\users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
2013-09-10 23:54	164016	----a-w-	c:\users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
2013-09-10 23:54	164016	----a-w-	c:\users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\DropboxExt64.22.dll
"Apoint"="c:\program files (x86)\Apoint\Apoint.exe" [BU]
"BCSSync"="c:\program files\Microsoft Office\Office14\BCSSync.exe" [2012-11-05 108144]
"SBRegRebootCleaner"="c:\program files (x86)\Ad-Aware Antivirus\SBRC.exe" [2012-09-20 201608]
------- Zusätzlicher Suchlauf -------
uLocal Page = c:\windows\system32\blank.htm
uStart Page = hxxp://securedsearch2.lavasoft.com/index.php?pr=vmn&id=adawaretb&v=3_4&ent=hp&u=CAAA82C8C61AAA03D18D225242E3D633
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: An OneNote s&enden - c:\progra~1\MICROS~2\Office14\ONBttnIE.dll/105
IE: Nach Microsoft E&xcel exportieren - c:\progra~1\MICROS~2\Office14\EXCEL.EXE/3000
TCP: DhcpNameServer =
FF - ProfilePath - c:\users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\
FF - prefs.js: browser.startup.homepage - about:home
"ImagePath"="\"c:\program files\Sony\VAIO Care\VCPerfService.exe\" \"/service\" \"/sstates\" \"/sampleinterval=5000\" \"/procinterval=5\" \"/dllinterval=120\" \"/counter=\Processor(_Total)\% Processor Time:1/counter=\PhysicalDisk(_Total)\Disk Bytes/sec:1\" \"/counter=\Network Interface(*)\Bytes Total/sec:1\" \"/expandcounter=\Processor Information(*)\Processor Frequency:1\" \"/expandcounter=\Processor(*)\% Idle Time:1\" \"/expandcounter=\Processor(*)\% C1 Time:1\" \"/expandcounter=\Processor(*)\% C2 Time:1\" \"/expandcounter=\Processor(*)\% C3 Time:1\" \"/expandcounter=\Processor(*)\% Processor Time:1\" \"/directory=c:\programdata\Sony Corporation\VAIO Care\inteldata\""
--------------------- Gesperrte Registrierungsschluessel ---------------------
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_9_900_170.ocx, 1"
@Denied: (A 2) (Everyone)
@Denied: (Full) (Everyone)
Zeit der Fertigstellung: 2014-01-19  20:32:21
ComboFix-quarantined-files.txt  2014-01-19 19:32
ComboFix2.txt  2014-01-19 19:17
Vor Suchlauf: 13 Verzeichnis(se), 273.641.766.912 Bytes frei
Nach Suchlauf: 14 Verzeichnis(se), 273.577.816.064 Bytes frei
- - End Of File - - 5D23D374A72B0D2171402D81D31803CB
--- --- --- A36C5E4F47E84449FF07ED3517B43A31

Alt 20.01.2014, 21:57   #4
/// the machine
/// TB-Ausbilder

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Standard

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

Downloade Dir bitte Malwarebytes Anti-Malware
  • Installiere das Programm in den vorgegebenen Pfad. (Bebilderte Anleitung zu MBAM)
  • Starte Malwarebytes' Anti-Malware (MBAM).
  • Klicke im Anschluss auf Scannen, wähle den Bedrohungssuchlauf aus und klicke auf Suchlauf starten.
  • Lass am Ende des Suchlaufs alle Funde (falls vorhanden) in die Quarantäne verschieben. Klicke dazu auf Auswahl entfernen.
  • Lass deinen Rechner ggf. neu starten, um die Bereinigung abzuschließen.
  • Starte MBAM, klicke auf Verlauf und dann auf Anwendungsprotokolle.
  • Wähle das neueste Scan-Protokoll aus und klicke auf Export. Wähle Textdatei (.txt) aus und speichere die Datei als mbam.txt auf dem Desktop ab. Das Logfile von MBAM findest du hier.
  • Füge den Inhalt der mbam.txt mit deiner nächsten Antwort hinzu.

Downloade Dir bitte AdwCleaner Logo Icon AdwCleaner auf deinen Desktop.
  • Schließe alle offenen Programme und Browser. Bebilderte Anleitung zu AdwCleaner.
  • Starte die AdwCleaner.exe mit einem Doppelklick.
  • Stimme den Nutzungsbedingungen zu.
  • Klicke auf Optionen und vergewissere dich, dass die folgenden Punkte ausgewählt sind:
    • "Tracing" Schlüssel löschen
    • Winsock Einstellungen zurücksetzen
    • Proxy Einstellungen zurücksetzen
    • Internet Explorer Richtlinien zurücksetzen
    • Chrome Richtlinien zurücksetzen
    • Stelle sicher, dass alle 5 Optionen wie hier dargestellt, ausgewählt sind
  • Klicke auf Suchlauf und warte bis dieser abgeschlossen ist.
  • Klicke nun auf Löschen und bestätige auftretende Hinweise mit Ok.
  • Dein Rechner wird automatisch neu gestartet. Nach dem Neustart öffnet sich eine Textdatei. Poste mir deren Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner\AdwCleaner[Cx].txt. (x = fortlaufende Nummer).

Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade Junkware Removal Tool auf Deinen Desktop

  • Starte das Tool mit Doppelklick. Ab Windows Vista (oder höher) bitte mit Rechtsklick "als Administrator ausführen" starten.
  • Drücke eine beliebige Taste, um das Tool zu starten.
  • Je nach System kann der Scan eine Weile dauern.
  • Wenn das Tool fertig ist wird das Logfile (JRT.txt) auf dem Desktop gespeichert und automatisch geöffnet.
  • Bitte poste den Inhalt der JRT.txt in Deiner nächsten Antwort.

und ein frisches FRST log bitte.

Proud Member of UNITE and ASAP since 2009

Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 21.01.2014, 18:29   #5
Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Standard

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

Hallo, hier die geforderten Log´s

Malwarebytes Anti-Malware

Datenbank Version: v2014.01.21.05

Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 11.0.9600.16476
Landgraf-Vaio :: LANDGRAFVAIO [Administrator]

21.01.2014 16:36:52
mbam-log-2014-01-21 (16-36-52).txt

Art des Suchlaufs: Vollständiger Suchlauf (C:\|)
Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM
Deaktivierte Suchlaufeinstellungen: P2P
Durchsuchte Objekte: 370584
Laufzeit: 1 Stunde(n), 17 Minute(n), 21 Sekunde(n)

Infizierte Speicherprozesse: 1
C:\ProgramData\Search Protection\SearchProtection.exe (PUP.Optional.SearchProtection.A) -> 2500 -> Löschen bei Neustart.

Infizierte Speichermodule: 0
(Keine bösartigen Objekte gefunden)

Infizierte Registrierungsschlüssel: 7
HKCR\AppID\{D616A4A2-7B38-4DBC-9093-6FE7A4A21B17} (PUP.Optional.Wajam.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCR\CLSID\{CCB69577-088B-4004-9ED8-FF5BCC83A039} (PUP.Optional.RebateInformer.A) -> Löschen bei Neustart.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039} (PUP.Optional.RebateInformer.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF} (PUP.Optional.AppGraffiti.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8} (PUP.Optional.InboxToolBar.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\Software\InstallCore\1I1T1Q1S (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\SOFTWARE\INSTALLCORE (PUP.Optional.InstallCore.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Registrierungswerte: 2
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|Search Protection (PUP.Optional.SearchProtection.A) -> Daten: C:\ProgramData\Search Protection\SearchProtection.exe -> Erfolgreich gelöscht und in Quarantäne gestellt.
HKCU\Software\InstallCore|tb (PUP.Optional.InstallCore.A) -> Daten: 0Z1N1J -> Erfolgreich gelöscht und in Quarantäne gestellt.

Infizierte Dateiobjekte der Registrierung: 0
(Keine bösartigen Objekte gefunden)

Infizierte Verzeichnisse: 0
(Keine bösartigen Objekte gefunden)

Infizierte Dateien: 2
C:\ProgramData\DSearchLink\DSearchLink.exe (PUP.Optional.Delta.A) -> Erfolgreich gelöscht und in Quarantäne gestellt.
C:\ProgramData\Search Protection\SearchProtection.exe (PUP.Optional.SearchProtection.A) -> Löschen bei Neustart.

AdwCleaner Logfile:
# AdwCleaner v3.017 - Bericht erstellt am 21/01/2014 um 18:14:40
# Aktualisiert 12/01/2014 von Xplode
# Betriebssystem : Windows 7 Home Premium Service Pack 1 (64 bits)
# Benutzername : Landgraf-Vaio - LANDGRAFVAIO
# Gestartet von : C:\Users\Landgraf-Vaio\Desktop\adwcleaner.exe
# Option : Löschen

***** [ Dienste ] *****

***** [ Dateien / Ordner ] *****

Ordner Gelöscht : C:\ProgramData\apn
Ordner Gelöscht : C:\ProgramData\blekko toolbars
Ordner Gelöscht : C:\ProgramData\DSearchLink
Ordner Gelöscht : C:\ProgramData\Search Protection
Ordner Gelöscht : C:\Program Files (x86)\Toolbar Cleaner
Ordner Gelöscht : C:\Users\Landgraf-Vaio\AppData\LocalLow\adawaretb
Ordner Gelöscht : C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\adawaretb
Datei Gelöscht : C:\Program Files (x86)\Mozilla Firefox\browser\searchplugins\adawaretb.xml
Datei Gelöscht : C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\ask-search.xml

***** [ Verknüpfungen ] *****

***** [ Registrierungsdatenbank ] *****

Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_download_RASAPI32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_download_RASMANCS
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajam_install_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajamupdater_rasapi32
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\wajamupdater_rasmancs
Schlüssel Gelöscht : HKLM\SOFTWARE\ee8bd8b739bf10
Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{8736C681-37A0-40C6-A0F0-4C083409151C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D7E97865-918F-41E4-9CD0-25AB1C574CE8}
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{D3D233D5-9F6D-436C-B6C7-E63F77503B30}
Schlüssel Gelöscht : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}
Wert Gelöscht : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{6C97A91E-4524-4019-86AF-2AA2D567BF5C}]
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{AF808758-C780-404C-A4EE-4526323FD9B6}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CC99A798-FD3D-4AB4-969E-6071612524F9}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\CLSID\{CCB69577-088B-4004-9ED8-FF5BCC83A039}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Schlüssel Gelöscht : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6F6A5334-78E9-4D9B-8182-8B41EA8C39EF}
Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\adawaretb
Schlüssel Gelöscht : HKLM\Software\adawaretb
Schlüssel Gelöscht : HKLM\Software\DataMngr
Schlüssel Gelöscht : HKLM\Software\Toolbar Cleaner
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\adawaretb
Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Toolbar Cleaner

***** [ Browser ] *****

-\\ Internet Explorer v11.0.9600.16428

-\\ Mozilla Firefox v26.0 (de)

[ Datei : C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\prefs.js ]

Zeile gelöscht : user_pref("browser.newtab.url", "hxxp://www.searchgol.com/?babsrc=NT_ss&mntrId=E8E118F46AF81E57&affID=119357&tsp=5014");


AdwCleaner[R0].txt - [4856 octets] - [21/01/2014 18:05:30]
AdwCleaner[S0].txt - [4645 octets] - [21/01/2014 18:14:40]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [4705 octets] ##########
--- --- ---


Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.0 (01.07.2014:1)
OS: Windows 7 Home Premium x64
Ran by Landgraf-Vaio on 21.01.2014 at 18:17:26,98

~~~ Services

~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3802158637-1547946212-584559868-1000\Software\Microsoft\Internet Explorer\Main\\Start Page

~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\AppDataLow\software\adawarebp
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\InternetRegistry\REGISTRY\USER\S-1-5-21-3802158637-1547946212-584559868-1000\Software\sweetim

~~~ Files

~~~ Folders

Successfully deleted: [Folder] "C:\Users\Landgraf-Vaio\appdata\local\adawarebp"

~~~ FireFox

Successfully deleted: [Folder] C:\Users\Landgraf-Vaio\AppData\Roaming\mozilla\firefox\profiles\jomifivw.default\extensions\{87934c42-161d-45bc-8cef-ef18abe2a30c}
Emptied folder: C:\Users\Landgraf-Vaio\AppData\Roaming\mozilla\firefox\profiles\jomifivw.default\minidumps [110 files]

~~~ Event Viewer Logs were cleared

Scan was completed on 21.01.2014 at 18:24:14,22
End of JRT log

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-01-2014
Ran by Landgraf-Vaio (administrator) on LANDGRAFVAIO on 21-01-2014 18:24:54
Running from C:\Users\Landgraf-Vaio\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe
(Star Finanz-Software Entwicklung und Vertriebs GmbH) C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [212480 2010-09-15] (Alps Electric Co., Ltd.)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [SBRegRebootCleaner] - C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-09-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554384 2013-07-15] (Lavasoft)
HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries)
Startup: C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8E2CB2916DB8CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default
FF SearchEngineOrder.1: Ask Search
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\inbox-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YouTube Unblocker - C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\Extensions\youtubeunblocker@unblocker.yt [2014-01-16]

==================== Services (Whitelisted) =================

R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation)
R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software)
R2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH)

==================== Drivers (Whitelisted) ====================

S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-09-25] (GFI Software)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-01-21 18:24 - 2014-01-21 18:24 - 00010077 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt
2014-01-21 18:24 - 2014-01-21 18:24 - 00002031 _____ C:\Users\Landgraf-Vaio\Desktop\JRT.txt
2014-01-21 18:24 - 2014-01-21 18:24 - 00000000 ____D C:\Users\Landgraf-Vaio\Downloads\FRST-OlderVersion
2014-01-21 18:17 - 2014-01-21 18:17 - 00000000 ____D C:\Windows\ERUNT
2014-01-21 18:16 - 2014-01-21 18:16 - 00004809 _____ C:\Users\Landgraf-Vaio\Desktop\AdwCleaner[S0].txt
2014-01-21 18:05 - 2014-01-21 18:14 - 00000000 ____D C:\AdwCleaner
2014-01-21 18:04 - 2012-12-17 22:29 - 05552942 _____ C:\Users\Landgraf-Vaio\Desktop\com.mojang.minecraftpe.4005.apk
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Malwarebytes
2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-21 16:34 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-21 16:33 - 2014-01-21 16:33 - 01236282 _____ C:\Users\Landgraf-Vaio\Downloads\adwcleaner.exe
2014-01-21 16:33 - 2014-01-21 16:33 - 01037068 _____ (Thisisu) C:\Users\Landgraf-Vaio\Downloads\JRT.exe
2014-01-21 16:32 - 2014-01-21 16:32 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Landgraf-Vaio\Downloads\mbam-setup-
2014-01-19 20:32 - 2014-01-19 20:32 - 00026558 _____ C:\ComboFix.txt
2014-01-19 20:25 - 2014-01-19 20:32 - 00000000 ____D C:\ComboFix
2014-01-19 20:07 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2014-01-19 20:07 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2014-01-19 20:07 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-01-19 20:07 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-01-19 20:07 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-01-19 20:07 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2014-01-19 20:07 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2014-01-19 20:07 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2014-01-19 20:06 - 2014-01-19 20:32 - 00000000 ____D C:\Qoobox
2014-01-19 20:06 - 2014-01-19 20:16 - 00000000 ____D C:\Windows\erdnt
2014-01-19 20:04 - 2014-01-19 20:04 - 05167985 ____R (Swearware) C:\Users\Landgraf-Vaio\Downloads\ComboFix.exe
2014-01-19 10:45 - 2014-01-19 10:46 - 00026464 _____ C:\Users\Landgraf-Vaio\Downloads\Addition.txt
2014-01-19 10:45 - 2014-01-19 10:45 - 00379904 _____ C:\Users\Landgraf-Vaio\Downloads\0pk01sgw.exe
2014-01-19 10:44 - 2014-01-21 18:24 - 02077184 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe
2014-01-19 10:44 - 2014-01-21 18:24 - 00000000 ____D C:\FRST
2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log
2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable
2014-01-18 22:02 - 2014-01-18 22:52 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx
2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip
2014-01-18 17:21 - 2014-01-19 20:25 - 00000330 _____ C:\Windows\wininit.ini
2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe
2014-01-18 16:52 - 2014-01-18 16:53 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-18 15:06 - 2014-01-19 10:40 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B
2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-15 14:27 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-15 14:27 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-15 14:27 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-15 14:27 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-15 14:20 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 14:20 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 14:20 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 14:19 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 14:19 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin
2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin
2014-01-03 16:20 - 2014-01-03 16:21 - 00000000 ____D C:\Program Files (x86)\Garmin
2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache

==================== One Month Modified Files and Folders =======

2014-01-21 18:25 - 2014-01-21 18:24 - 00010077 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt
2014-01-21 18:24 - 2014-01-21 18:24 - 00002031 _____ C:\Users\Landgraf-Vaio\Desktop\JRT.txt
2014-01-21 18:24 - 2014-01-21 18:24 - 00000000 ____D C:\Users\Landgraf-Vaio\Downloads\FRST-OlderVersion
2014-01-21 18:24 - 2014-01-19 10:44 - 02077184 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe
2014-01-21 18:24 - 2014-01-19 10:44 - 00000000 ____D C:\FRST
2014-01-21 18:23 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-21 18:23 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-21 18:17 - 2014-01-21 18:17 - 00000000 ____D C:\Windows\ERUNT
2014-01-21 18:17 - 2013-12-01 17:47 - 00000000 ___RD C:\Users\Landgraf-Vaio\Dropbox
2014-01-21 18:17 - 2013-12-01 17:43 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox
2014-01-21 18:17 - 2013-09-23 19:18 - 00003978 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{302D991D-8607-4326-8B9F-1E38889BFE91}
2014-01-21 18:16 - 2014-01-21 18:16 - 00004809 _____ C:\Users\Landgraf-Vaio\Desktop\AdwCleaner[S0].txt
2014-01-21 18:15 - 2013-10-29 21:34 - 00014492 _____ C:\Windows\setupact.log
2014-01-21 18:15 - 2013-09-23 15:47 - 01504041 _____ C:\Windows\WindowsUpdate.log
2014-01-21 18:15 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-21 18:14 - 2014-01-21 18:05 - 00000000 ____D C:\AdwCleaner
2014-01-21 18:01 - 2013-10-31 01:14 - 00007316 _____ C:\Windows\PFRO.log
2014-01-21 18:00 - 2010-11-21 07:50 - 00654166 _____ C:\Windows\system32\perfh007.dat
2014-01-21 18:00 - 2010-11-21 07:50 - 00130006 _____ C:\Windows\system32\perfc007.dat
2014-01-21 18:00 - 2009-07-14 06:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-21 17:54 - 2013-09-25 16:56 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Windows Live
2014-01-21 17:43 - 2013-10-23 09:47 - 00391453 _____ C:\test.xml
2014-01-21 17:35 - 2013-09-23 19:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Malwarebytes
2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-21 16:33 - 2014-01-21 16:33 - 01236282 _____ C:\Users\Landgraf-Vaio\Downloads\adwcleaner.exe
2014-01-21 16:33 - 2014-01-21 16:33 - 01037068 _____ (Thisisu) C:\Users\Landgraf-Vaio\Downloads\JRT.exe
2014-01-21 16:32 - 2014-01-21 16:32 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Landgraf-Vaio\Downloads\mbam-setup-
2014-01-21 16:29 - 2013-09-25 15:09 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0
2014-01-19 20:38 - 2013-09-25 14:19 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-01-19 20:32 - 2014-01-19 20:32 - 00026558 _____ C:\ComboFix.txt
2014-01-19 20:32 - 2014-01-19 20:25 - 00000000 ____D C:\ComboFix
2014-01-19 20:32 - 2014-01-19 20:06 - 00000000 ____D C:\Qoobox
2014-01-19 20:30 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2014-01-19 20:25 - 2014-01-18 17:21 - 00000330 _____ C:\Windows\wininit.ini
2014-01-19 20:17 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default
2014-01-19 20:16 - 2014-01-19 20:06 - 00000000 ____D C:\Windows\erdnt
2014-01-19 20:04 - 2014-01-19 20:04 - 05167985 ____R (Swearware) C:\Users\Landgraf-Vaio\Downloads\ComboFix.exe
2014-01-19 10:46 - 2014-01-19 10:45 - 00026464 _____ C:\Users\Landgraf-Vaio\Downloads\Addition.txt
2014-01-19 10:45 - 2014-01-19 10:45 - 00379904 _____ C:\Users\Landgraf-Vaio\Downloads\0pk01sgw.exe
2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log
2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable
2014-01-19 10:43 - 2013-09-23 15:58 - 00000000 ____D C:\Users\Landgraf-Vaio
2014-01-19 10:40 - 2014-01-18 15:06 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B
2014-01-19 10:40 - 2013-09-23 15:58 - 00000000 ___RD C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-18 22:52 - 2014-01-18 22:02 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx
2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip
2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe
2014-01-18 16:53 - 2014-01-18 16:52 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-17 08:14 - 2013-10-01 22:53 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Skype
2014-01-16 19:14 - 2013-12-01 17:45 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-16 19:09 - 2009-07-14 05:45 - 00417024 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-16 14:11 - 2013-09-23 18:39 - 00000000 ____D C:\Windows\system32\MRT
2014-01-16 14:08 - 2013-09-23 18:39 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-15 14:27 - 2013-09-29 20:45 - 00000000 ____D C:\ProgramData\Oracle
2014-01-15 14:27 - 2013-09-29 20:44 - 00000000 ____D C:\Program Files (x86)\Java
2014-01-09 13:19 - 2013-09-25 16:05 - 00000000 ____D C:\Windows\System32\Tasks\Games
2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Robert
2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ICQ
2014-01-03 16:52 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Anja
2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin
2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin
2014-01-03 16:21 - 2014-01-03 16:20 - 00000000 ____D C:\Program Files (x86)\Garmin
2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2014-01-20 18:14

==================== End Of Log ============================
--- --- ---


Alt 22.01.2014, 12:17   #6
/// the machine
/// TB-Ausbilder

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Standard

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

ESET Online Scanner

  • Hier findest du eine bebilderte Anleitung zu ESET Online Scanner
  • Lade und starte Eset Online Scanner
  • Setze einen Haken bei Ja, ich bin mit den Nutzungsbedingungen einverstanden und klicke auf Starten.
  • Aktiviere die "Erkennung von eventuell unerwünschten Anwendungen" und wähle folgende Einstellungen.
  • Klicke auf Starten.
  • Die Signaturen werden heruntergeladen, der Scan beginnt automatisch.
  • Klicke am Ende des Suchlaufs auf Fertig stellen.
  • Schließe das Fenster von ESET.
  • Explorer öffnen.
  • C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert).
  • Logfile hier posten.
  • Deinstallation: Systemsteuerung => Software / Programme deinstallieren => Eset Online Scanner V3 entfernen.
  • Manuell folgenden Ordner löschen und Papierkorb leeren => C:\Programme\Eset

Downloade Dir bitte SecurityCheck und:

  • Speichere es auf dem Desktop.
  • Starte SecurityCheck.exe und folge den Anweisungen in der DOS-Box.
  • Wenn der Scan beendet wurde sollte sich ein Textdokument (checkup.txt) öffnen.
Poste den Inhalt bitte hier.

und ein frisches FRST log bitte. Noch Probleme?
--> Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

Alt 22.01.2014, 19:04   #7
Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Standard

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

hat alles geklappt:

ESETSmartInstaller@High as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=
# OnlineScanner.ocx=
# api_version=3.0.2
# EOSSerial=e295e0fc9f85ac41877ea5635ee993f3
# engine=16754
# end=finished
# remove_checked=false
# archives_checked=true
# unwanted_checked=false
# unsafe_checked=false
# antistealth_checked=true
# utc_time=2014-01-22 05:52:02
# local_time=2014-01-22 06:52:02 (+0100, Mitteleuropäische Zeit)
# country="Germany"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=1023 16777215 0 0 0 0 0 0
# compatibility_mode=5893 16776574 100 94 10372304 142042972 0 0
# scanned=160351
# found=0
# cleaned=0
# scan_time=3393
 Results of screen317's Security Check version 0.99.79  
 Windows 7 Service Pack 1 x64 (UAC is enabled)  
 Internet Explorer 11  
``````````````Antivirus/Firewall Check:`````````````` 
Lavasoft Ad-Aware   
 Antivirus up to date!  (On Access scanning disabled!) 
`````````Anti-malware/Other Utilities Check:````````` 
 Malwarebytes Anti-Malware Version  
 Java 7 Update 51  
 Adobe Flash Player 11.9.900.170  
 Adobe Reader XI  
 Mozilla Firefox (26.0) 
````````Process Check: objlist.exe by Laurent````````  
 Ad-Aware AAWService.exe is disabled! 
 Ad-Aware AAWTray.exe is disabled! 
 Ad-Aware Antivirus AdAwareService.exe   
 Ad-Aware Antivirus SBAMSvc.exe   
`````````````````System Health check````````````````` 
 Total Fragmentation on Drive C:  
````````````````````End of Log``````````````````````

FRST Logfile:
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 21-01-2014
Ran by Landgraf-Vaio (administrator) on LANDGRAFVAIO on 22-01-2014 19:00:45
Running from C:\Users\Landgraf-Vaio\Downloads
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\Apoint.exe
(Microsoft Corporation) C:\Program Files\Windows Sidebar\sidebar.exe
(Garmin Ltd or its subsidiaries) C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
(Dropbox, Inc.) C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe
(Lavasoft) C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Lavasoft Limited) C:\Program Files (x86)\Ad-Aware Antivirus\AdAware.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Gate\VAIO Gate.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(GFI Software) C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApMsgFwd.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BTStackServer.exe
(Broadcom Corporation.) C:\Program Files\WIDCOMM\Bluetooth Software\BluetoothHeadsetProxy.exe
(Alps Electric Co., Ltd.) C:\Program Files\Apoint\ApntEx.exe
(ALPS) C:\Program Files\Apoint\Apvfb.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCPerfService.exe
(Sony of America Corporation) C:\Program Files\Sony\VAIO Care\listener.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Power Management\SPMService.exe
(Microsoft Corporation) C:\Program Files (x86)\Internet Explorer\ielowutil.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCsystray.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCService.exe
(Sony Corporation) C:\Program Files\Sony\VAIO Care\VCAgent.exe
(Microsoft Corporation) C:\Windows\System32\vds.exe
(Mozilla Corporation) C:\Program Files (x86)\Mozilla Firefox\firefox.exe

==================== Registry (Whitelisted) ==================

HKLM\...\Run: [Apoint] - C:\Program Files\Apoint\Apoint.exe [212480 2010-09-15] (Alps Electric Co., Ltd.)
HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [108144 2012-11-05] (Microsoft Corporation)
HKLM\...\Run: [SBRegRebootCleaner] - C:\Program Files (x86)\Ad-Aware Antivirus\SBRC.exe [201608 2012-09-20] (GFI Software)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [102400 2010-09-20] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Ad-Aware Browsing Protection] - C:\ProgramData\Ad-Aware Browsing Protection\adawarebp.exe [554384 2013-07-15] (Lavasoft)
HKLM-x32\...\Run: [Ad-Aware Antivirus] - "C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareLauncher" --windows-run
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
HKCU\...\Run: [GarminExpressTrayApp] - C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe [1095000 2013-12-30] (Garmin Ltd or its subsidiaries)
Startup: C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
ShortcutTarget: Dropbox.lnk -> C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x8E2CB2916DB8CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: Microsoft-Konto-Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer]

FF ProfilePath: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default
FF SearchEngineOrder.1: Ask Search
FF Homepage: about:home
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_11_9_900_170.dll ()
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_9_900_170.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=10.51.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 - c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/OfficeAuthz,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/SharePoint,version=14.0 - C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\searchplugins\inbox-search.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: YouTube Unblocker - C:\Users\Landgraf-Vaio\AppData\Roaming\Mozilla\Firefox\Profiles\jomifivw.default\Extensions\youtubeunblocker@unblocker.yt [2014-01-16]

==================== Services (Whitelisted) =================

R2 Ad-Aware Service; C:\Program Files (x86)\Ad-Aware Antivirus\AdAwareService.exe [1236336 2013-06-13] (Lavasoft Limited)
R2 Garmin Core Update Service; C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [250712 2013-12-30] (Garmin Ltd or its subsidiaries)
R2 SampleCollector; C:\Program Files\Sony\VAIO Care\VCPerfService.exe [259192 2011-01-29] (Sony Corporation)
R2 SBAMSvc; C:\Program Files (x86)\Ad-Aware Antivirus\SBAMSvc.exe [3677000 2012-09-20] (GFI Software)
S2 StarMoney 9.0 OnlineUpdate; C:\Program Files (x86)\StarMoney 9.0\ouservice\StarMoneyOnlineUpdate.exe [663184 2013-10-11] (Star Finanz-Software Entwicklung und Vertriebs GmbH)

==================== Drivers (Whitelisted) ====================

S3 gfiark; C:\Windows\System32\drivers\gfiark.sys [41032 2013-05-23] (ThreatTrack Security)
R0 gfibto; C:\Windows\System32\drivers\gfibto.sys [14456 2013-09-25] (GFI Software)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================

==================== One Month Created Files and Folders ========

2014-01-22 18:59 - 2014-01-22 18:59 - 00000978 _____ C:\Users\Landgraf-Vaio\Desktop\checkup.txt
2014-01-22 06:33 - 2014-01-22 06:33 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\adawarebp
2014-01-21 18:24 - 2014-01-22 19:00 - 00010173 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt
2014-01-21 18:24 - 2014-01-21 18:24 - 00000000 ____D C:\Users\Landgraf-Vaio\Downloads\FRST-OlderVersion
2014-01-21 18:17 - 2014-01-21 18:17 - 00000000 ____D C:\Windows\ERUNT
2014-01-21 18:05 - 2014-01-21 18:14 - 00000000 ____D C:\AdwCleaner
2014-01-21 18:04 - 2012-12-17 22:29 - 05552942 _____ C:\Users\Landgraf-Vaio\Desktop\com.mojang.minecraftpe.4005.apk
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Malwarebytes
2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-21 16:34 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
2014-01-21 16:32 - 2014-01-21 16:32 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Landgraf-Vaio\Downloads\mbam-setup-
2014-01-19 20:32 - 2014-01-19 20:32 - 00026558 _____ C:\ComboFix.txt
2014-01-19 20:25 - 2014-01-19 20:32 - 00000000 ____D C:\ComboFix
2014-01-19 20:07 - 2011-06-26 07:45 - 00256000 _____ C:\Windows\PEV.exe
2014-01-19 20:07 - 2010-11-07 18:20 - 00208896 _____ C:\Windows\MBR.exe
2014-01-19 20:07 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-01-19 20:07 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-01-19 20:07 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-01-19 20:07 - 2000-08-31 01:00 - 00098816 _____ C:\Windows\sed.exe
2014-01-19 20:07 - 2000-08-31 01:00 - 00080412 _____ C:\Windows\grep.exe
2014-01-19 20:07 - 2000-08-31 01:00 - 00068096 _____ C:\Windows\zip.exe
2014-01-19 20:06 - 2014-01-19 20:32 - 00000000 ____D C:\Qoobox
2014-01-19 20:06 - 2014-01-19 20:16 - 00000000 ____D C:\Windows\erdnt
2014-01-19 10:45 - 2014-01-19 10:46 - 00026464 _____ C:\Users\Landgraf-Vaio\Downloads\Addition.txt
2014-01-19 10:45 - 2014-01-19 10:45 - 00379904 _____ C:\Users\Landgraf-Vaio\Downloads\0pk01sgw.exe
2014-01-19 10:44 - 2014-01-21 18:24 - 02077184 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe
2014-01-19 10:44 - 2014-01-21 18:24 - 00000000 ____D C:\FRST
2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log
2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable
2014-01-18 22:02 - 2014-01-18 22:52 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx
2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip
2014-01-18 17:21 - 2014-01-19 20:25 - 00000330 _____ C:\Windows\wininit.ini
2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe
2014-01-18 16:52 - 2014-01-18 16:53 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-18 15:06 - 2014-01-19 10:40 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B
2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-15 14:27 - 2013-12-18 21:09 - 00096168 _____ (Oracle Corporation) C:\Windows\SysWOW64\WindowsAccessBridge-32.dll
2014-01-15 14:27 - 2013-12-18 21:04 - 00264616 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaws.exe
2014-01-15 14:27 - 2013-12-18 21:04 - 00175016 _____ (Oracle Corporation) C:\Windows\SysWOW64\javaw.exe
2014-01-15 14:27 - 2013-12-18 21:03 - 00174504 _____ (Oracle Corporation) C:\Windows\SysWOW64\java.exe
2014-01-15 14:20 - 2013-11-27 02:41 - 00343040 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbhub.sys
2014-01-15 14:20 - 2013-11-27 02:41 - 00325120 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbport.sys
2014-01-15 14:20 - 2013-11-27 02:41 - 00053248 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbehci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00099840 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbccgp.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00030720 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbuhci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00025600 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbohci.sys
2014-01-15 14:19 - 2013-11-27 02:41 - 00007808 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\usbd.sys
2014-01-15 14:19 - 2013-11-26 12:40 - 00376768 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\netio.sys
2014-01-15 14:19 - 2013-11-26 11:32 - 03156480 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin
2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin
2014-01-03 16:20 - 2014-01-03 16:21 - 00000000 ____D C:\Program Files (x86)\Garmin
2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache

==================== One Month Modified Files and Folders =======

2014-01-22 19:01 - 2014-01-21 18:24 - 00010173 _____ C:\Users\Landgraf-Vaio\Downloads\FRST.txt
2014-01-22 18:59 - 2014-01-22 18:59 - 00000978 _____ C:\Users\Landgraf-Vaio\Desktop\checkup.txt
2014-01-22 18:47 - 2013-09-23 15:47 - 01533687 _____ C:\Windows\WindowsUpdate.log
2014-01-22 18:35 - 2013-09-23 19:17 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-01-22 17:38 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-01-22 17:38 - 2009-07-14 05:45 - 00022336 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-01-22 17:34 - 2013-09-23 19:18 - 00003978 _____ C:\Windows\System32\Tasks\User_Feed_Synchronization-{302D991D-8607-4326-8B9F-1E38889BFE91}
2014-01-22 17:30 - 2013-12-01 17:47 - 00000000 ___RD C:\Users\Landgraf-Vaio\Dropbox
2014-01-22 17:30 - 2013-12-01 17:43 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Dropbox
2014-01-22 17:30 - 2009-07-14 06:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2014-01-22 17:29 - 2013-10-29 21:34 - 00014660 _____ C:\Windows\setupact.log
2014-01-22 06:43 - 2013-09-25 16:56 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Windows Live
2014-01-22 06:33 - 2014-01-22 06:33 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\adawarebp
2014-01-21 18:24 - 2014-01-21 18:24 - 00000000 ____D C:\Users\Landgraf-Vaio\Downloads\FRST-OlderVersion
2014-01-21 18:24 - 2014-01-19 10:44 - 02077184 _____ (Farbar) C:\Users\Landgraf-Vaio\Downloads\FRST64.exe
2014-01-21 18:24 - 2014-01-19 10:44 - 00000000 ____D C:\FRST
2014-01-21 18:17 - 2014-01-21 18:17 - 00000000 ____D C:\Windows\ERUNT
2014-01-21 18:14 - 2014-01-21 18:05 - 00000000 ____D C:\AdwCleaner
2014-01-21 18:01 - 2013-10-31 01:14 - 00007316 _____ C:\Windows\PFRO.log
2014-01-21 18:00 - 2010-11-21 07:50 - 00654166 _____ C:\Windows\system32\perfh007.dat
2014-01-21 18:00 - 2010-11-21 07:50 - 00130006 _____ C:\Windows\system32\perfc007.dat
2014-01-21 18:00 - 2009-07-14 06:13 - 01498506 _____ C:\Windows\system32\PerfStringBackup.INI
2014-01-21 17:43 - 2013-10-23 09:47 - 00391453 _____ C:\test.xml
2014-01-21 16:35 - 2014-01-21 16:35 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Malwarebytes
2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\ProgramData\Malwarebytes
2014-01-21 16:34 - 2014-01-21 16:34 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-21 16:32 - 2014-01-21 16:32 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Landgraf-Vaio\Downloads\mbam-setup-
2014-01-21 16:29 - 2013-09-25 15:09 - 00000000 ____D C:\Program Files (x86)\StarMoney 9.0
2014-01-19 20:38 - 2013-09-25 14:19 - 00000000 ____D C:\Program Files (x86)\Spybot - Search & Destroy 2
2014-01-19 20:32 - 2014-01-19 20:32 - 00026558 _____ C:\ComboFix.txt
2014-01-19 20:32 - 2014-01-19 20:25 - 00000000 ____D C:\ComboFix
2014-01-19 20:32 - 2014-01-19 20:06 - 00000000 ____D C:\Qoobox
2014-01-19 20:30 - 2009-07-14 03:34 - 00000215 _____ C:\Windows\system.ini
2014-01-19 20:25 - 2014-01-18 17:21 - 00000330 _____ C:\Windows\wininit.ini
2014-01-19 20:17 - 2009-07-14 04:20 - 00000000 __RHD C:\Users\Default
2014-01-19 20:16 - 2014-01-19 20:06 - 00000000 ____D C:\Windows\erdnt
2014-01-19 10:46 - 2014-01-19 10:45 - 00026464 _____ C:\Users\Landgraf-Vaio\Downloads\Addition.txt
2014-01-19 10:45 - 2014-01-19 10:45 - 00379904 _____ C:\Users\Landgraf-Vaio\Downloads\0pk01sgw.exe
2014-01-19 10:43 - 2014-01-19 10:43 - 00000488 _____ C:\Users\Landgraf-Vaio\Downloads\defogger_disable.log
2014-01-19 10:43 - 2014-01-19 10:43 - 00000000 _____ C:\Users\Landgraf-Vaio\defogger_reenable
2014-01-19 10:43 - 2013-09-23 15:58 - 00000000 ____D C:\Users\Landgraf-Vaio
2014-01-19 10:40 - 2014-01-18 15:06 - 00000000 ___HD C:\Users\Landgraf-Vaio\AppData\Roaming\34295F2B
2014-01-19 10:40 - 2013-09-23 15:58 - 00000000 ___RD C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
2014-01-18 22:52 - 2014-01-18 22:02 - 00010396 _____ C:\Users\Landgraf-Vaio\Documents\Geocache.xlsx
2014-01-18 21:45 - 2014-01-18 21:45 - 19192342 _____ C:\Users\Landgraf-Vaio\Downloads\Windows_7_TOP50Gadgets.zip
2014-01-18 17:00 - 2014-01-18 17:00 - 00050477 _____ C:\Users\Landgraf-Vaio\Downloads\Defogger.exe
2014-01-18 16:53 - 2014-01-18 16:52 - 01069512 _____ (Solid State Networks) C:\Users\Landgraf-Vaio\Downloads\install_flashplayer12x32au_mssd_aaa_aih.exe
2014-01-17 08:14 - 2013-10-01 22:53 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Skype
2014-01-16 19:14 - 2013-12-01 17:45 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox
2014-01-16 19:09 - 2009-07-14 05:45 - 00417024 _____ C:\Windows\system32\FNTCACHE.DAT
2014-01-16 14:11 - 2013-09-23 18:39 - 00000000 ____D C:\Windows\system32\MRT
2014-01-16 14:08 - 2013-09-23 18:39 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-15 14:27 - 2014-01-15 14:27 - 00005327 _____ C:\Windows\SysWOW64\jupdate-1.7.0_51-b13.log
2014-01-15 14:27 - 2013-09-29 20:45 - 00000000 ____D C:\ProgramData\Oracle
2014-01-15 14:27 - 2013-09-29 20:44 - 00000000 ____D C:\Program Files (x86)\Java
2014-01-09 13:19 - 2013-09-25 16:05 - 00000000 ____D C:\Windows\System32\Tasks\Games
2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Robert
2014-01-03 16:53 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\ICQ
2014-01-03 16:52 - 2013-12-20 17:55 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Kontoauszug Anja
2014-01-03 16:25 - 2014-01-03 16:25 - 00000000 ____D C:\Users\Landgraf-Vaio\Documents\Garmin
2014-01-03 16:22 - 2014-01-03 16:22 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Roaming\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\Users\Landgraf-Vaio\AppData\Local\Garmin
2014-01-03 16:21 - 2014-01-03 16:21 - 00000000 ____D C:\ProgramData\Garmin
2014-01-03 16:21 - 2014-01-03 16:20 - 00000000 ____D C:\Program Files (x86)\Garmin
2014-01-03 16:20 - 2014-01-03 16:20 - 00000000 ____D C:\ProgramData\Package Cache

Some content of TEMP:

==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit

LastRegBack: 2014-01-20 18:14

==================== End Of Log ============================
--- --- ---


Alt 23.01.2014, 16:19   #8
/// the machine
/// TB-Ausbilder

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Standard

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist


Falls Du Lob oder Kritik loswerden möchtest kannst Du das hier tun

Die Reihenfolge ist hier entscheidend.
  1. Falls Defogger benutzt wurde: Defogger nochmal starten und auf re-enable klicken.
  2. Falls Combofix benutzt wurde: (Alternativ in uninstall.exe umbenennen und starten)
    • Windowstaste + R > Combofix /Uninstall (eingeben) > OK
    • Alternative: Combofix.exe in uninstall.exe umbenennen und starten
    • Combofix wird jetzt starten, sich evtl updaten und dann alle Reste von sich selbst entfernen.
  3. Downloade Dir bitte auf jeden Fall DelFix Download DelFix auf deinen Desktop:
    • Schließe alle offenen Programme.
    • Starte die delfix.exe mit einem Doppelklick.
    • Setze vor jede Funktion ein Häkchen.
    • Klicke auf Start.
    • Hinweis: DelFix entfernt u. a. alle verwendeten Programme, die Quarantäne unserer Scanner, den Java-Cache und löscht sich abschließend selbst.
    • Starte deinen Rechner abschließend neu.
  4. Sollten jetzt noch Programme aus unserer Bereinigung übrig sein kannst du sie bedenkenlos löschen.

Hier noch ein paar Tipps zur Absicherung deines Systems.

Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
  • Bitte überprüfe ob dein System Windows Updates automatisch herunter lädt
  • Windows Updates
    • Windows XP: Start --> Systemsteuerung --> Doppelklick auf Automatische Updates
    • Windows Vista / 7: Start --> Systemsteuerung --> System und Sicherheit --> Automatische Updates aktivieren oder deaktivieren
  • Gehe sicher das die automatischen Updates aktiviert sind.
  • Software Updates
    Installierte Software kann ebenfalls Sicherheitslücken haben, welche Malware nutzen kann, um dein System zu infizieren.
    Um deine Installierte Software up to date zu halten, empfehle ich dir Secunia Online Software.

Anti- Viren Software
  • Gehe sicher immer eine Anti Viren Software installiert zu haben und das diese auch up to date ist. Es ist nämlich nutzlos wenn diese out of date sind.

Zusätzlicher Schutz
  • MalwareBytes Anti Malware
    Dies ist eines der besten Anti-Malware Tools auf dem Markt. Es ist ein On- Demond Scan Tool welches viele aktuelle Malware erkennt und auch entfernt.
    Update das Tool und lass es einmal in der Woche laufen. Die Kaufversion biete zudem noch einen Hintergrundwächter.
    Ein Tutorial zur Verwendung findest Du hier.
  • WinPatrol
    Diese Software macht einen Snapshot deines Systems und warnt dich vor eventuellen Änderungen. Downloade dir die Freeware Version von hier.

Sicheres Browsen
  • SpywareBlaster
    Eine kurze Einführung findest du Hier
  • MVPs hosts file
    Ein Tutorial findest Du hier. Leider habe ich bis jetzt kein deutschsprachiges gefunden.
  • WOT (Web of trust)
    Dieses AddOn warnt Dich bevor Du eine als schädlich gemeldete Seite besuchst.

Alternative Browser

Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
  • Opera
  • Mozilla Firefox.
    • Hinweis: Für diesen Browser habe ich hier ein paar nützliche Add Ons
    • NoScript
      Dieses AddOn blockt JavaScript, Java and Flash und andere Plugins. Sie werden nur dann ausgeführt wenn Du es bestätigst.
    • AdblockPlus
      Dieses AddOn blockt die meisten Werbung von selbst. Ein Rechtsklick auf den Banner um diesen zu AdBlockPlus hinzu zu fügen reicht und dieser wird nicht mehr geladen.
      Es spart ausserdem Downloadkapazität.

Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC
Halte dich fern von jedlichen Registry Cleanern.
Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links
Miekemoes Blogspot ( MVP )
Bill Castner ( MVP )

  • Klicke nicht auf alles nur weil es Dich dazu auffordert und schön bunt ist.
  • verwende keine peer to peer oder Filesharing Software (Emule, uTorrent,..)
  • Lass die Finger von Cracks, Keygens, Serials oder anderer illegaler Software.
  • Öffne keine Anhänge von Dir nicht bekannten Emails. Achte vor allem auf die Dateiendung wie zb deinFoto.jpg.exe
Nun bleibt mir nur noch dir viel Spass beim sicheren Surfen zu wünschen.

Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.

Proud Member of UNITE and ASAP since 2009

Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!

Alt 24.01.2014, 13:28   #9
Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Standard

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

vielen lieben dank für die schnelle Hilfe

Alt 25.01.2014, 11:52   #10
/// the machine
/// TB-Ausbilder

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Standard

Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

Gern Geschehen

Proud Member of UNITE and ASAP since 2009

Anleitungen und Hilfestellungen
Trojaner-Board Facebook-Seite

Keine Hilfestellung via PM!


Themen zu Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist
4d36e972-e325-11ce-bfc1-08002be10318, ad-aware, branding, browser, e-mail, error, excel, flash player, help, home, homepage, link geöffnet, log-datei, minidump, newtab, ntdll.dll, pup.optional.appgraffiti.a, pup.optional.delta.a, pup.optional.inboxtoolbar.a, pup.optional.installcore.a, pup.optional.rebateinformer.a, pup.optional.wajam.a, refresh, registry, rundll, security, software, svchost.exe, system, trojaner, unlock, vista, windows

Ähnliche Themen: Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist

  1. Windows 10: Fake-Paypal-Mail erhalten und versehentlich Anhang geöffnet …
    Plagegeister aller Art und deren Bekämpfung - 22.08.2015 (8)
  2. Windows 7: vodafone-Rechung Anhang geöffnet Trojaner/Viren
    Log-Analyse und Auswertung - 14.12.2014 (13)
  3. Zwei PDF Rechnung links in emails (vodafone, telekom) geöffnet..
    Log-Analyse und Auswertung - 12.12.2014 (11)
  4. Fake Telekom Rechnung geöffnet
    Log-Analyse und Auswertung - 01.12.2014 (29)
  5. Fake Telekom Rechnung leider downgeloadet und geöffnet
    Plagegeister aller Art und deren Bekämpfung - 28.11.2014 (5)
  6. Telekom Fake-Rechnung: Anhang geöffnet
    Log-Analyse und Auswertung - 17.11.2014 (7)
  7. Telekom Fake Rechnung geöffnet!
    Log-Analyse und Auswertung - 27.07.2014 (19)
  8. Windows 7: Anhang in Fake Telekom-Mail (Rechnung) geöffnet - Trojaner TR/Kryptik.vnyz gefunden
    Log-Analyse und Auswertung - 06.07.2014 (9)
  9. eventuell vodafone fake rechnung geöffnet
    Plagegeister aller Art und deren Bekämpfung - 19.06.2014 (13)
  10. Vodafone Fake-Rechnungs-Mail geöffnet
    Plagegeister aller Art und deren Bekämpfung - 13.06.2014 (13)
  11. Windows Vista: Zip Anhang einer Email von einer falschen Rechnung geöffnet-Angst vor Virus
    Plagegeister aller Art und deren Bekämpfung - 23.01.2014 (5)
  12. Fake Vodafone-Rechnung Link geöffnet
    Plagegeister aller Art und deren Bekämpfung - 21.01.2014 (3)
  13. Win 7: Anhang von Fake Telekom-Rechnung geöffnet. Trojanerinfektion
    Log-Analyse und Auswertung - 19.01.2014 (9)
  14. Anhang von Fake-Rechnung geöffnet
    Plagegeister aller Art und deren Bekämpfung - 17.03.2013 (2)
  15. Anhang von Fake-Rechnung.zip geöffnet - Trojaner und Worms
    Log-Analyse und Auswertung - 15.03.2013 (15)
  16. Fake Vodafone Rechnung PDF geöffnet. Trojaner?
    Plagegeister aller Art und deren Bekämpfung - 20.11.2012 (3)
  17. Gefälschte Vodafone Rechnung geöffnet, bin ich jetzt mit duqu Virus infiziert???
    Plagegeister aller Art und deren Bekämpfung - 13.03.2012 (12)

Zum Thema Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist - Hallo, Ich habe eine Fake E-Mail von Vodafone bekommen, leider den link geöffnet und die Datei darin auch gestartet, jetzt schlägt mein Antivirus Programm regelmäßig an. Nach kurzer Googlesuche habe - Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist...
Du betrachtest: Windows 7: versehentlich Fake Vodafone Rechnung geöffnet, jetzt hab ich Angst das ein Trojaner da ist auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.