| 
 Irgendwie kann ich es nciht runterladen oder öffnen. Folgendes wird mir angezeigt: Dieses Programm wird nichht häufig runter geladen und kann auf dem Computer Schaden anrichten, dann wird mir nur "Löschen" oder "Programm nicht ausführen" vorgeschlagen 
Okay funtktionierte doch...hihi   
FRST Logfile:  
FRST Logfile:  
FRST Logfile:  
FRST Logfile:  
FRST Logfile:  
FRST Logfile:   Code: 
 Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 29-01-2014 01Ran by Jannene (administrator) on JANNENE-PC on 30-01-2014 23:04:50
 Running from C:\Users\Jannene\Desktop
 Microsoft Windows 7 Ultimate  Service Pack 1 (X86) OS Language: German Standard
 Internet Explorer Version 9
 Boot Mode: Normal
 
 
 
 ==================== Processes (Whitelisted) ===================
 
 (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\sched.exe
 (Samsung Electronics Co., Ltd.) C:\Program Files\Samsung\Kies\KiesTrayAgent.exe
 (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jusched.exe
 (RealNetworks, Inc.) C:\Program Files\Real\RealPlayer\Update\realsched.exe
 (Apple Inc.) C:\Program Files\iTunes\iTunesHelper.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avgnt.exe
 (Samsung) C:\Program Files\Samsung\Kies\Kies.exe
 (Apple Inc.) C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avguard.exe
 (Apple Inc.) C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
 (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
 (Teruten) C:\Windows\System32\FsUsbExService.Exe
 (pdfforge GbR) C:\Program Files\PDF Architect\HelperService.exe
 (pdfforge GbR) C:\Program Files\PDF Architect\ConversionService.exe
 () C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
 (Avira Operations GmbH & Co. KG) C:\Program Files\Avira\AntiVir Desktop\avshadow.exe
 (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
 (Microsoft Corporation) C:\Program Files\Common Files\microsoft shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
 (Sun Microsystems, Inc.) C:\Program Files\Common Files\Java\Java Update\jucheck.exe
 (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
 (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
 (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe
 (Malwarebytes Corporation) C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe
 (Microsoft Corporation) C:\Program Files\Internet Explorer\iexplore.exe
 
 
 ==================== Registry (Whitelisted) ==================
 
 HKLM\...\Run: [BCSSync] - C:\Program Files\Microsoft Office\Office14\BCSSync.exe [91520 2010-03-13] (Microsoft Corporation)
 HKLM\...\Run: [Adobe ARM] - C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959904 2013-11-21] (Adobe Systems Incorporated)
 HKLM\...\Run: [KiesTrayAgent] - C:\Program Files\Samsung\Kies\KiesTrayAgent.exe [311152 2013-12-11] (Samsung Electronics Co., Ltd.)
 HKLM\...\Run: [SunJavaUpdateSched] - C:\Program Files\Common Files\Java\Java Update\jusched.exe [252848 2012-07-03] (Sun Microsystems, Inc.)
 HKLM\...\Run: [TkBellExe] - C:\Program Files\Real\RealPlayer\update\realsched.exe [295512 2013-03-29] (RealNetworks, Inc.)
 HKLM\...\Run: [APSDaemon] - C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-09-13] (Apple Inc.)
 HKLM\...\Run: [QuickTime Task] - C:\Program Files\QuickTime\QTTask.exe [421888 2013-05-01] (Apple Inc.)
 HKLM\...\Run: [iTunesHelper] - C:\Program Files\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.)
 HKLM\...\Run: [YTDownloader] - "C:\Program Files\YTDownloader\YTDownloader.exe" /boot
 HKLM\...\Run: [avgnt] - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe [684600 2013-12-18] (Avira Operations GmbH & Co. KG)
 HKLM\...\RunOnce: [Malwarebytes Anti-Malware] - C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silent [532040 2013-04-04] (Malwarebytes Corporation)
 Winlogon\Notify\ScCertProp: wlnotify.dll [X]
 HKCU\...\Run: [KiesPreload] - C:\Program Files\Samsung\Kies\Kies.exe [1564528 2013-12-11] (Samsung)
 HKCU\...\Run: [KiesAirMessage] - C:\Program Files\Samsung\Kies\KiesAirMessage.exe -startup
 HKCU\...\Run: [] - C:\Program Files\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe [845168 2013-12-11] (Samsung)
 HKCU\...\Run: [iCloudServices] - C:\Program Files\Common Files\Apple\Internet Services\iCloudServices.exe [59720 2013-11-20] (Apple Inc.)
 HKCU\...\Run: [BitTorrent] - C:\Users\Jannene\AppData\Roaming\BitTorrent\BitTorrent.exe [1138776 2014-01-02] (BitTorrent Inc.)
 
 ==================== Internet (Whitelisted) ====================
 
 HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=ecffdf0e-6acc-484f-9b06-581d152674cf&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE210A8F757EBCD01
 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
 HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=ecffdf0e-6acc-484f-9b06-581d152674cf&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
 SearchScopes: HKLM - DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=ecffdf0e-6acc-484f-9b06-581d152674cf&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
 SearchScopes: HKLM - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=ecffdf0e-6acc-484f-9b06-581d152674cf&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
 SearchScopes: HKLM - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL =
 SearchScopes: HKCU - DefaultScope {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=296
 SearchScopes: HKCU - {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.helperbar.com/?publisher=OC&dpid=OC&co=DE&userid=ecffdf0e-6acc-484f-9b06-581d152674cf&affid=111583&searchtype=ds&babsrc=lnkry&q={searchTerms}
 SearchScopes: HKCU - {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9} URL = hxxp://search.conduit.com/Results.aspx?ctid=CT3314958&octid=EB_ORIGINAL_CTID&SearchSource=58&CUI=&UM=2&UP=SPBA7FC3E8-54B5-4FF2-BCA9-A0CBFA294BFE&q={searchTerms}&SSPV=
 SearchScopes: HKCU - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = hxxp://www.bing.com/search?q={searchTerms}&r=296
 SearchScopes: HKCU - {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www2.delta-search.com/?q={searchTerms}&affID=120519&tt=gc_&babsrc=SP_ss&mntrId=74C300166F19BCD5
 BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
 BHO: PDF Architect Helper - {3A2D5EBA-F86D-4BD3-A177-019765996711} - C:\Program Files\PDF Architect\PDFIEHelper.dll (pdfforge GbR)
 BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL (Microsoft Corporation)
 BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
 BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
 BHO: Office Document Cache Handler - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
 BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
 Toolbar: HKLM - PDF Architect Toolbar - {25A3A431-30BB-47C8-AD6A-E1063801134F} - C:\Program Files\PDF Architect\PDFIEPlugin.dll (pdfforge GbR)
 Toolbar: HKLM - No Name - {ae07101b-46d4-4a98-af68-0333ea26e113} -  No File
 Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
 Winsock: Catalog5 08 C:\Program Files\Bonjour\mdnsNSP.dll [121704] (Apple Inc.)
 Tcpip\Parameters: [DhcpNameServer] 192.168.0.1
 
 Chrome:
 =======
 CHR RestoreOnStartup: "sync_promo":{"show_on_first_run_allowed"
 CHR Extension: (RealDownloader) - C:\Users\Jannene\AppData\Local\Google\Chrome\User Data\Default\Extensions\idhngdhcfkoamngbedgpaokgjbnpdiji [2013-03-29]
 CHR HKLM\...\Chrome\Extension: [idhngdhcfkoamngbedgpaokgjbnpdiji] - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Chrome\Ext\realdownloader.crx [2013-03-06]
 
 ========================== Services (Whitelisted) =================
 
 R2 AntiVirSchedulerService; C:\Program Files\Avira\AntiVir Desktop\sched.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
 R2 AntiVirService; C:\Program Files\Avira\AntiVir Desktop\avguard.exe [440376 2013-12-18] (Avira Operations GmbH & Co. KG)
 R2 MBAMScheduler; C:\Program Files\Malwarebytes' Anti-Malware\mbamscheduler.exe [418376 2013-04-04] (Malwarebytes Corporation)
 S2 MBAMService; C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exe [701512 2013-04-04] (Malwarebytes Corporation)
 R2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR)
 R2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR)
 R2 RealNetworks Downloader Resolver Service; C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe [39056 2013-03-06] ()
 
 ==================== Drivers (Whitelisted) ====================
 
 S2 avgntflt; C:\Windows\System32\DRIVERS\avgntflt.sys [90400 2013-12-18] (Avira Operations GmbH & Co. KG)
 R1 avipbb; C:\Windows\System32\DRIVERS\avipbb.sys [135648 2013-12-18] (Avira Operations GmbH & Co. KG)
 R1 avkmgr; C:\Windows\System32\DRIVERS\avkmgr.sys [37352 2013-11-25] (Avira Operations GmbH & Co. KG)
 R3 FsUsbExDisk; C:\Windows\system32\FsUsbExDisk.SYS [37344 2013-02-05] ()
 R3 GTIPCI21; C:\Windows\System32\DRIVERS\gtipci21.sys [88192 2006-09-14] (Texas Instruments)
 S3 MBAMProtector; C:\Windows\system32\drivers\mbam.sys [22856 2013-04-04] (Malwarebytes Corporation)
 S3 MBAMSwissArmy; C:\Windows\system32\drivers\mbamswissarmy.sys [40776 2014-01-30] (Malwarebytes Corporation)
 R3 NETw2v32; C:\Windows\System32\DRIVERS\NETw2v32.sys [2595840 2007-03-06] (Intel® Corporation)
 S1 ssmdrv; C:\Windows\System32\DRIVERS\ssmdrv.sys [28520 2013-12-18] (Avira GmbH)
 S3 vsmraid; C:\Windows\system32\DRIVERS\vsmraid.sys [141904 2009-07-14] ()
 S3 vwifibus; C:\Windows\System32\drivers\vwifibus.sys [19968 2009-07-14] ()
 S3 WacomPen; C:\Windows\system32\DRIVERS\wacompen.sys [21632 2009-07-14] ()
 S3 WANARP; C:\Windows\System32\DRIVERS\wanarp.sys [63488 2010-11-20] ()
 R1 Wanarpv6; C:\Windows\System32\DRIVERS\wanarp.sys [63488 2010-11-20] ()
 S3 Wd; C:\Windows\system32\DRIVERS\wd.sys [19024 2009-07-14] ()
 R0 Wdf01000; C:\Windows\System32\drivers\Wdf01000.sys [527064 2013-06-25] ()
 R1 WfpLwf; C:\Windows\System32\DRIVERS\wfplwf.sys [9728 2009-07-14] ()
 S3 WIMMount; C:\Windows\System32\drivers\wimmount.sys [19008 2009-07-14] ()
 S3 WinUsb; C:\Windows\System32\DRIVERS\WinUsb.sys [35968 2010-11-20] ()
 R3 WmiAcpi; C:\Windows\system32\drivers\wmiacpi.sys [11264 2009-07-14] ()
 S4 ws2ifsl; C:\Windows\system32\drivers\ws2ifsl.sys [16384 2009-07-14] ()
 R3 WudfPf; C:\Windows\System32\drivers\WudfPf.sys [66560 2012-07-26] ()
 S3 WUDFRd; C:\Windows\System32\DRIVERS\WUDFRd.sys [155136 2012-07-26] ()
 U5 4384475d9de5180c; C:\Windows\System32\Drivers\4384475d9de5180c.sys [58880 2014-01-27] ()
 S1 cjijbjti; \??\C:\Windows\system32\drivers\cjijbjti.sys [x]
 S3 dgderdrv; System32\drivers\dgderdrv.sys [x]
 S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x]
 S3 tsusbhub; system32\drivers\tsusbhub.sys [x]
 S3 VGPU; System32\drivers\rdvgkmd.sys [x]
 
 ==================== NetSvcs (Whitelisted) ===================
 
 
 ==================== One Month Created Files and Folders ========
 
 2014-01-30 23:04 - 2014-01-30 23:05 - 00012395 _____ C:\Users\Jannene\Desktop\FRST.txt
 2014-01-30 23:04 - 2014-01-30 23:04 - 00000000 ____D C:\FRST
 2014-01-30 22:32 - 2014-01-30 22:32 - 01137152 _____ (Farbar) C:\Users\Jannene\Desktop\FRST.exe
 2014-01-30 22:28 - 2014-01-30 22:28 - 01137152 _____ (Farbar) C:\Users\Jannene\Downloads\FRST.exe
 2014-01-30 22:24 - 2014-01-30 22:24 - 02079744 _____ (Farbar) C:\Users\Jannene\Downloads\FRST64.exe
 2014-01-30 18:20 - 2014-01-30 18:20 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
 2014-01-30 18:20 - 2014-01-30 18:20 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
 2014-01-30 18:20 - 2014-01-30 18:20 - 00000000 ____D C:\Users\Jannene\AppData\Roaming\Malwarebytes
 2014-01-30 18:20 - 2014-01-30 18:20 - 00000000 ____D C:\ProgramData\Malwarebytes
 2014-01-30 18:19 - 2014-01-30 18:20 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
 2014-01-30 18:19 - 2013-04-04 14:50 - 00022856 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys
 2014-01-30 18:18 - 2014-01-30 18:19 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Jannene\Downloads\mbam-setup-1.75.0.1300.exe
 2014-01-29 17:25 - 2014-01-29 17:25 - 00002012 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
 2014-01-29 17:25 - 2014-01-29 17:25 - 00000000 ____D C:\Users\Jannene\AppData\Roaming\Avira
 2014-01-29 17:24 - 2014-01-29 17:24 - 00000000 ____D C:\ProgramData\Avira
 2014-01-29 17:24 - 2013-12-18 09:32 - 00090400 _____ (Avira Operations GmbH & Co. KG) C:\Windows\system32\Drivers\avgntflt.sys
 2014-01-29 17:24 - 2013-12-18 09:32 - 00028520 _____ (Avira GmbH) C:\Windows\system32\Drivers\ssmdrv.sys
 2014-01-29 17:22 - 2014-01-29 17:23 - 130658432 _____ C:\Users\Jannene\Downloads\avira_free_antivirus_de.exe
 2014-01-29 17:13 - 2014-01-29 17:13 - 03975896 _____ (Avira Operations GmbH & Co. KG) C:\Users\Jannene\Downloads\avira_oe_client_antivirus_de.exe
 2014-01-27 16:45 - 2014-01-27 16:45 - 00058880 _____ C:\Windows\system32\Drivers\4384475d9de5180c.sys
 2014-01-27 08:48 - 2014-01-27 08:50 - 00000000 ____D C:\Users\Jannene\Desktop\Galaxy note
 2014-01-27 08:36 - 2014-01-27 08:36 - 00999883 _____ C:\Users\Jannene\Downloads\Odin_v3.09.zip
 2014-01-22 08:52 - 2014-01-22 08:52 - 00184192 _____ C:\Windows\system32\Drivers\ssudmdm.sys
 2014-01-22 08:52 - 2014-01-22 08:52 - 00088576 _____ C:\Windows\system32\Drivers\ssudbus.sys
 2014-01-15 14:12 - 2014-01-15 14:12 - 01571921 _____ C:\Users\Jannene\Downloads\Email.zip
 2014-01-15 13:30 - 2013-11-27 02:14 - 00258560 _____ C:\Windows\system32\Drivers\usbhub.sys
 2014-01-15 13:30 - 2013-11-27 02:13 - 00284672 _____ C:\Windows\system32\Drivers\usbport.sys
 2014-01-15 13:30 - 2013-11-27 02:13 - 00076288 _____ C:\Windows\system32\Drivers\usbccgp.sys
 2014-01-15 13:30 - 2013-11-27 02:13 - 00043520 _____ C:\Windows\system32\Drivers\usbehci.sys
 2014-01-15 13:30 - 2013-11-27 02:13 - 00024064 _____ C:\Windows\system32\Drivers\usbuhci.sys
 2014-01-15 13:30 - 2013-11-27 02:13 - 00020480 _____ C:\Windows\system32\Drivers\usbohci.sys
 2014-01-15 13:30 - 2013-11-27 02:13 - 00006016 _____ C:\Windows\system32\Drivers\usbd.sys
 2014-01-15 13:30 - 2013-11-26 11:10 - 02349056 _____ C:\Windows\system32\win32k.sys
 2014-01-02 18:08 - 2014-01-02 18:08 - 00000196 _____ C:\Windows\system32\Config.json
 2014-01-02 17:47 - 2014-01-02 18:09 - 00000000 ____D C:\Program Files\ShopperPro
 2014-01-02 17:47 - 2014-01-02 17:51 - 00000000 ____D C:\Users\Jannene\Downloads\(userwunsch) The.Big.Bang.Theory.S06E01-12.German.Dubbed.HDTV.XviD-ITG
 2014-01-02 17:45 - 2014-01-02 17:45 - 00000815 _____ C:\Users\Jannene\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk
 2014-01-02 17:45 - 2014-01-02 17:45 - 00000000 ____D C:\Users\Jannene\AppData\Local\CrashRpt
 2014-01-02 17:44 - 2014-01-30 17:57 - 00000000 ____D C:\Users\Jannene\AppData\Roaming\BitTorrent
 2014-01-02 17:38 - 2014-01-02 17:38 - 01138776 _____ (BitTorrent Inc.) C:\Users\Jannene\Downloads\bittorrent.exe
 
 ==================== One Month Modified Files and Folders =======
 
 2014-01-30 23:05 - 2014-01-30 23:04 - 00012395 _____ C:\Users\Jannene\Desktop\FRST.txt
 2014-01-30 23:04 - 2014-01-30 23:04 - 00000000 ____D C:\FRST
 2014-01-30 22:32 - 2014-01-30 22:32 - 01137152 _____ (Farbar) C:\Users\Jannene\Desktop\FRST.exe
 2014-01-30 22:31 - 2009-07-14 05:34 - 00020704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
 2014-01-30 22:31 - 2009-07-14 05:34 - 00020704 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
 2014-01-30 22:28 - 2014-01-30 22:28 - 01137152 _____ (Farbar) C:\Users\Jannene\Downloads\FRST.exe
 2014-01-30 22:27 - 2013-03-29 11:48 - 00001100 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
 2014-01-30 22:24 - 2014-01-30 22:24 - 02079744 _____ (Farbar) C:\Users\Jannene\Downloads\FRST64.exe
 2014-01-30 22:10 - 2013-01-05 21:42 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
 2014-01-30 18:20 - 2014-01-30 18:20 - 00040776 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamswissarmy.sys
 2014-01-30 18:20 - 2014-01-30 18:20 - 00001067 _____ C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
 2014-01-30 18:20 - 2014-01-30 18:20 - 00000000 ____D C:\Users\Jannene\AppData\Roaming\Malwarebytes
 2014-01-30 18:20 - 2014-01-30 18:20 - 00000000 ____D C:\ProgramData\Malwarebytes
 2014-01-30 18:20 - 2014-01-30 18:19 - 00000000 ____D C:\Program Files\Malwarebytes' Anti-Malware
 2014-01-30 18:19 - 2014-01-30 18:18 - 10285040 _____ (Malwarebytes Corporation                                    ) C:\Users\Jannene\Downloads\mbam-setup-1.75.0.1300.exe
 2014-01-30 17:57 - 2014-01-02 17:44 - 00000000 ____D C:\Users\Jannene\AppData\Roaming\BitTorrent
 2014-01-30 17:40 - 2013-01-05 16:14 - 01652244 _____ C:\Windows\system32\PerfStringBackup.INI
 2014-01-30 17:15 - 2013-03-29 11:48 - 00001096 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
 2014-01-30 17:14 - 2013-08-02 07:52 - 00015082 _____ C:\Windows\setupact.log
 2014-01-30 17:14 - 2009-07-14 05:53 - 00000006 ____H C:\Windows\Tasks\SA.DAT
 2014-01-29 17:27 - 2013-01-05 17:39 - 00209586 _____ C:\Windows\PFRO.log
 2014-01-29 17:25 - 2014-01-29 17:25 - 00002012 _____ C:\Users\Public\Desktop\Avira Control Center.lnk
 2014-01-29 17:25 - 2014-01-29 17:25 - 00000000 ____D C:\Users\Jannene\AppData\Roaming\Avira
 2014-01-29 17:25 - 2013-01-05 16:01 - 01723003 _____ C:\Windows\WindowsUpdate.log
 2014-01-29 17:24 - 2014-01-29 17:24 - 00000000 ____D C:\ProgramData\Avira
 2014-01-29 17:24 - 2013-01-05 16:45 - 00000000 ____D C:\Program Files\Avira
 2014-01-29 17:23 - 2014-01-29 17:22 - 130658432 _____ C:\Users\Jannene\Downloads\avira_free_antivirus_de.exe
 2014-01-29 17:13 - 2014-01-29 17:13 - 03975896 _____ (Avira Operations GmbH & Co. KG) C:\Users\Jannene\Downloads\avira_oe_client_antivirus_de.exe
 2014-01-28 09:36 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET
 2014-01-27 16:45 - 2014-01-27 16:45 - 00058880 _____ C:\Windows\system32\Drivers\4384475d9de5180c.sys
 2014-01-27 08:50 - 2014-01-27 08:48 - 00000000 ____D C:\Users\Jannene\Desktop\Galaxy note
 2014-01-27 08:36 - 2014-01-27 08:36 - 00999883 _____ C:\Users\Jannene\Downloads\Odin_v3.09.zip
 2014-01-25 01:26 - 2013-01-06 12:34 - 00000000 ____D C:\Users\Jannene\AppData\Local\Adobe
 2014-01-25 01:25 - 2013-01-05 21:42 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerApp.exe
 2014-01-25 01:25 - 2013-01-05 21:42 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\system32\FlashPlayerCPLApp.cpl
 2014-01-22 08:52 - 2014-01-22 08:52 - 00184192 _____ C:\Windows\system32\Drivers\ssudmdm.sys
 2014-01-22 08:52 - 2014-01-22 08:52 - 00088576 _____ C:\Windows\system32\Drivers\ssudbus.sys
 2014-01-16 16:37 - 2009-07-14 05:33 - 00408696 _____ C:\Windows\system32\FNTCACHE.DAT
 2014-01-16 09:59 - 2013-01-05 16:45 - 00231584 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe
 2014-01-15 22:59 - 2013-08-14 22:28 - 00000000 ____D C:\Windows\system32\MRT
 2014-01-15 22:57 - 2010-06-24 09:43 - 83425928 _____ (Microsoft Corporation) C:\Windows\system32\mrt.exe
 2014-01-15 14:12 - 2014-01-15 14:12 - 01571921 _____ C:\Users\Jannene\Downloads\Email.zip
 2014-01-02 18:09 - 2014-01-02 17:47 - 00000000 ____D C:\Program Files\ShopperPro
 2014-01-02 18:09 - 2009-07-14 03:37 - 00000000 ____D C:\Program Files\Common Files\System
 2014-01-02 18:08 - 2014-01-02 18:08 - 00000196 _____ C:\Windows\system32\Config.json
 2014-01-02 17:51 - 2014-01-02 17:47 - 00000000 ____D C:\Users\Jannene\Downloads\(userwunsch) The.Big.Bang.Theory.S06E01-12.German.Dubbed.HDTV.XviD-ITG
 2014-01-02 17:45 - 2014-01-02 17:45 - 00000815 _____ C:\Users\Jannene\AppData\Roaming\Microsoft\Windows\Start Menu\BitTorrent.lnk
 2014-01-02 17:45 - 2014-01-02 17:45 - 00000000 ____D C:\Users\Jannene\AppData\Local\CrashRpt
 2014-01-02 17:38 - 2014-01-02 17:38 - 01138776 _____ (BitTorrent Inc.) C:\Users\Jannene\Downloads\bittorrent.exe
 
 Some content of TEMP:
 ====================
 C:\Users\Jannene\AppData\Local\Temp\2dsve2wefd.exe
 C:\Users\Jannene\AppData\Local\Temp\avgnt.exe
 C:\Users\Jannene\AppData\Local\Temp\BlueStacks-SplitInstaller_native.exe
 C:\Users\Jannene\AppData\Local\Temp\busunint.exe
 C:\Users\Jannene\AppData\Local\Temp\nsp1D3.exe
 C:\Users\Jannene\AppData\Local\Temp\nsy68F0.exe
 C:\Users\Jannene\AppData\Local\Temp\nsyEFED.exe
 C:\Users\Jannene\AppData\Local\Temp\OptimizerPro.exe
 C:\Users\Jannene\AppData\Local\Temp\ose00000.exe
 C:\Users\Jannene\AppData\Local\Temp\PCSpeedMaximizer.exe
 C:\Users\Jannene\AppData\Local\Temp\pyiue01c.dll
 C:\Users\Jannene\AppData\Local\Temp\Show-Password_1030-8101.exe
 C:\Users\Jannene\AppData\Local\Temp\stubhelper.dll
 C:\Users\Jannene\AppData\Local\Temp\tu17p84.exe
 C:\Users\Jannene\AppData\Local\Temp\uninst1.exe
 C:\Users\Jannene\AppData\Local\Temp\UpdateCheckerSetup.exe
 C:\Users\Jannene\AppData\Local\Temp\uttEF78.tmp.exe
 C:\Users\Jannene\AppData\Local\Temp\wajam_download.exe
 C:\Users\Jannene\AppData\Local\Temp\ytd_bu10_setup.exe
 
 
 ==================== Bamital & volsnap Check =================
 
 C:\Windows\explorer.exe => MD5 is legit
 C:\Windows\system32\winlogon.exe => MD5 is legit
 C:\Windows\system32\wininit.exe => MD5 is legit
 C:\Windows\system32\svchost.exe => MD5 is legit
 C:\Windows\system32\services.exe => MD5 is legit
 C:\Windows\system32\User32.dll => MD5 is legit
 C:\Windows\system32\userinit.exe => MD5 is legit
 C:\Windows\system32\rpcss.dll => MD5 is legit
 C:\Windows\system32\Drivers\volsnap.sys
 [2013-01-05 18:32] - [2010-11-20 13:30] - 0245632 ____A () D41D8CD98F00B204E9800998ECF8427E
 
 C:\Windows\system32\Drivers\volsnap.sys IS INFECTED. <===== ATTENTION!
 
 
 
 LastRegBack: 2014-01-29 19:56
 
 ==================== End Of Log ============================
 --- --- ---  
--- --- ---  
--- --- ---  
--- --- ---  
--- --- ---  
--- --- ---  
Und hier Addition:    Code: 
 Additional scan result of Farbar Recovery Scan Tool (x86) Version: 29-01-2014 01Ran by Jannene at 2014-01-30 23:05:47
 Running from C:\Users\Jannene\Desktop
 Boot Mode: Normal
 ==========================================================
 
 
 ==================== Security Center ========================
 
 AV: Avira Desktop (Disabled - Up to date) {F67B4DE5-C0B4-6C3F-0EFF-6C83BD5D0C2C}
 AS: Avira Desktop (Disabled - Up to date) {4D1AAC01-E68E-63B1-344F-57F1C6DA4691}
 AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
 
 ==================== Installed Programs ======================
 
 Adobe Flash Player 12 ActiveX (Version: 12.0.0.38 - Adobe Systems Incorporated)
 Adobe Reader XI (11.0.06) - Deutsch (Version: 11.0.06 - Adobe Systems Incorporated)
 Apple Application Support (Version: 2.3.6 - Apple Inc.)
 Apple Mobile Device Support (Version: 7.0.0.117 - Apple Inc.)
 Apple Software Update (Version: 2.1.3.127 - Apple Inc.)
 Avira Free Antivirus (Version: 14.0.2.344 - Avira)
 BitTorrent (HKCU Version: 7.8.2.30445 - BitTorrent Inc.)
 Bonjour (Version: 3.0.0.10 - Apple Inc.)
 Definition Update for Microsoft Office 2010 (KB982726) 32-Bit Edition (Version:  - Microsoft)
 Free Easy Burner V 5.1 (Version: 5.1.0.0 - Koyote soft)
 Google Toolbar for Internet Explorer (Version: 1.0.0 - Google Inc.) Hidden
 Google Toolbar for Internet Explorer (Version: 7.5.4805.320 - Google Inc.)
 Google Update Helper (Version: 1.3.22.3 - Google Inc.) Hidden
 iCloud (Version: 3.1.0.40 - Apple Inc.)
 iFunbox (v2.7.2386.747), iFunbox DevTeam (Version: v2.7.2386.747 - )
 iTunes (Version: 11.1.3.8 - Apple Inc.)
 Java 7 Update 15 (Version: 7.0.150 - Oracle)
 Java Auto Updater (Version: 2.1.9.0 - Sun Microsystems, Inc.) Hidden
 king.com (remove only) (Version:  - Midasplayer Ltd (king.com))
 Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300 - Malwarebytes Corporation)
 Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation)
 Microsoft .NET Framework 4 Client Profile (Version: 4.0.30320 - Microsoft Corporation) Hidden
 Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation)
 Microsoft .NET Framework 4 Client Profile DEU Language Pack (Version: 4.0.30320 - Microsoft Corporation) Hidden
 Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation)
 Microsoft .NET Framework 4 Extended (Version: 4.0.30319 - Microsoft Corporation) Hidden
 Microsoft Office 2010 Service Pack 1 (SP1) (Version:  - Microsoft)
 Microsoft Office 2010 Service Pack 1 (SP1) (Version:  - Microsoft) Hidden
 Microsoft Office Access MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office Excel MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office Groove MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office InfoPath MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office OneNote MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office Outlook MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office PowerPoint MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000 - Microsoft Corporation)
 Microsoft Office Professional Plus 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office Proof (English) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office Proof (French) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office Proof (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office Proof (Italian) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office Proofing (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office Publisher MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office Shared MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Office Word MUI (German) 2010 (Version: 14.0.6029.1000 - Microsoft Corporation) Hidden
 Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219 (Version: 10.0.40219 - Microsoft Corporation)
 Mozilla Maintenance Service (Version: 17.0 - Mozilla)
 Mozilla Thunderbird 17.0 (x86 de) (Version: 17.0 - Mozilla)
 MyFreeCodec (HKCU Version:  - )
 PDF Architect (Version: 1.0.52.8917 - pdfforge)
 PDFCreator (Version: 1.6.2 - pdfforge)
 QuickTime (Version: 7.74.80.86 - Apple Inc.)
 RealDownloader (Version: 1.3.1 - RealNetworks, Inc.) Hidden
 RealNetworks - Microsoft Visual C++ 2008 Runtime (Version: 9.0 - RealNetworks, Inc) Hidden
 RealNetworks - Microsoft Visual C++ 2010 Runtime (Version: 10.0 - RealNetworks, Inc) Hidden
 RealPlayer (Version: 16.0.0 - RealNetworks)
 RealUpgrade 1.1 (Version: 1.1.0 - RealNetworks, Inc.) Hidden
 Samsung Kies (Version: 2.5.1.12123_2 - Samsung Electronics Co., Ltd.)
 Samsung Kies (Version: 2.5.1.12123_2 - Samsung Electronics Co., Ltd.) Hidden
 Samsung Story Album Viewer (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.)
 Samsung Story Album Viewer (Version: 1.0.0.13054_1 - Samsung Electronics Co., Ltd.) Hidden
 SAMSUNG USB Driver for Mobile Phones (Version: 1.5.29.0 - SAMSUNG Electronics Co., Ltd.)
 Texas Instruments PCIxx21/x515/xx12 drivers. (Version: 2.00.0001 - Ihr Firmenname)
 TIPCI (Version: 2.00.0001 - Ihr Firmenname) Hidden
 Update for Microsoft .NET Framework 4 Client Profile (KB2468871) (Version: 1 - Microsoft Corporation)
 Update for Microsoft .NET Framework 4 Client Profile (KB2533523) (Version: 1 - Microsoft Corporation)
 Update for Microsoft .NET Framework 4 Client Profile (KB2600217) (Version: 1 - Microsoft Corporation)
 Update for Microsoft .NET Framework 4 Extended (KB2468871) (Version: 1 - Microsoft Corporation)
 Update for Microsoft .NET Framework 4 Extended (KB2533523) (Version: 1 - Microsoft Corporation)
 Update for Microsoft .NET Framework 4 Extended (KB2600217) (Version: 1 - Microsoft Corporation)
 Update for Microsoft Office 2010 (KB2553065) (Version:  - Microsoft)
 Update for Microsoft Office 2010 (KB2553092) (Version:  - Microsoft)
 Update for Microsoft Office 2010 (KB2553181) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft Office 2010 (KB2553267) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft Office 2010 (KB2553310) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft Office 2010 (KB2553378) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft Office 2010 (KB2566458) (Version:  - Microsoft)
 Update for Microsoft Office 2010 (KB2596964) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft Office 2010 (KB2598242) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft Office 2010 (KB2687503) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft Office 2010 (KB2687509) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft Office 2010 (KB2760631) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft Office 2010 (KB2767886) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft OneNote 2010 (KB2553290) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft Outlook 2010 (KB2597090) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft Outlook 2010 (KB2687623) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft Outlook Social Connector 2010 (KB2553406) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft PowerPoint 2010 (KB2598240) 32-Bit Edition (Version:  - Microsoft)
 Update for Microsoft SharePoint Workspace 2010 (KB2589371) 32-Bit Edition (Version:  - Microsoft)
 VLC media player 2.0.5 (Version: 2.0.5 - VideoLAN)
 WinRAR 4.20 (32-Bit) (Version: 4.20.0 - win.rar GmbH)
 
 ==================== Restore Points  =========================
 
 
 ==================== Hosts content: ==========================
 
 2009-07-14 03:04 - 2009-06-10 22:39 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
 
 ==================== Scheduled Tasks (whitelisted) =============
 
 Task: {05EFF16F-54DC-4A8B-86F1-03EF34E57BAB} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe [2014-01-25] (Adobe Systems Incorporated)
 Task: {24EFE2C8-ACC3-4A70-9071-1E3FEA54631D} - System32\Tasks\AutoKMS => C:\Windows\AutoKMS\AutoKMS.exe [2013-01-05] ()
 Task: {46EBCFD9-479A-43D8-A209-8B942EE22617} - System32\Tasks\RealPlayerRealUpgradeLogonTaskS-1-5-21-770320959-3698567616-4190397953-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-03-06] (RealNetworks, Inc.)
 Task: {5473BF51-FE37-49F5-8E99-7650C44A293D} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-29] (Google Inc.)
 Task: {774823AE-8D1E-4525-8300-B302DFE7CD5C} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
 Task: {794F4AFB-21EF-44A6-994A-4A6459043496} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files\Google\Update\GoogleUpdate.exe [2013-03-29] (Google Inc.)
 Task: {8751F157-358D-436C-97D7-8ECA3828B499} - System32\Tasks\RealDownloaderRealUpgradeScheduledTaskS-1-5-21-770320959-3698567616-4190397953-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2013-03-06] (RealNetworks, Inc.)
 Task: {8B9440E2-1F9C-465F-8192-4283D4E7DF35} - System32\Tasks\RealDownloaderRealUpgradeLogonTaskS-1-5-21-770320959-3698567616-4190397953-1000 => C:\Program Files\RealNetworks\RealDownloader\realupgrade.exe [2013-03-06] (RealNetworks, Inc.)
 Task: {8E1FDE5C-3D8D-4FC4-A37D-2EBD5AD85278} - System32\Tasks\Apple Diagnostics => C:\Program Files\Common Files\Apple\Internet Services\EReporter.exe [2013-11-20] (Apple Inc.)
 Task: {DD8AEFB1-3C8E-476A-9D7F-2F3B7BF8AE3C} - System32\Tasks\RealDownloaderDownloaderScheduledTaskS-1-5-21-770320959-3698567616-4190397953-1000 => C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe [2013-03-06] (RealNetworks, Inc.)
 Task: {F1E1EE7A-1C4D-40CB-980D-78D970580D63} - System32\Tasks\RealPlayerRealUpgradeScheduledTaskS-1-5-21-770320959-3698567616-4190397953-1000 => C:\Program Files\Real\RealUpgrade\RealUpgrade.exe [2013-03-06] (RealNetworks, Inc.)
 Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
 Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files\Google\Update\GoogleUpdate.exe
 
 ==================== Loaded Modules (whitelisted) =============
 
 2011-03-17 00:11 - 2011-03-17 00:11 - 04297568 _____ () C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
 2013-01-28 12:08 - 2013-01-28 12:08 - 00087952 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
 2013-01-28 12:08 - 2013-01-28 12:08 - 01242512 _____ () C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
 2013-12-13 18:30 - 2013-12-13 18:30 - 01952256 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.UI\abbba0f399508efdbeaf78b2e2fa7b03\Kies.UI.ni.dll
 2013-12-13 18:30 - 2013-12-13 18:30 - 00079360 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.MVVM\6f25a20174765872519f821c6c68bfda\Kies.MVVM.ni.dll
 2013-12-13 18:31 - 2013-12-13 18:31 - 00189952 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\891822cfc054262435c02192bb220192\Kies.Common.DeviceServiceLib.Interface.ni.dll
 2013-12-13 18:31 - 2013-12-13 18:31 - 00367104 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePhoto\0cb1ca6d0bc2fbc4225ec8b991eecd07\DevicePhoto.ni.dll
 2013-12-13 18:31 - 2013-12-13 18:31 - 00301568 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceVideo\1f0d8f012eae2b7353c8d594b2a06e9d\DeviceVideo.ni.dll
 2013-12-13 18:31 - 2013-12-13 18:31 - 00616448 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DevicePodcast\3eb0df72e19c269e7ec4dc4a2c130521\DevicePodcast.ni.dll
 2013-12-13 18:31 - 2013-12-13 18:31 - 00307200 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DummyStorePlugin\9e97c3b33aa7fb9d900bca4f6d93ec9e\DummyStorePlugin.ni.dll
 2013-12-13 18:31 - 2013-12-13 18:31 - 14972928 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Theme\642ba04dfd0cf6b5a4bd768ab404eb4f\Kies.Theme.ni.dll
 2013-12-13 18:31 - 2013-12-13 18:31 - 00581632 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\42ab5ed8c70495af14fc9a8e38e5383a\Kies.Common.DeviceServiceLib.FileService.ni.dll
 2013-12-13 18:31 - 2013-12-13 18:31 - 00046592 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\Kies.Common.DeviceS#\fb36527133c6a9e51f53aab9ca2faabe\Kies.Common.DeviceServiceLib.FirmwareUpdate.FirmwareUpdateAgentHelper.ni.dll
 2013-12-13 18:31 - 2013-12-13 18:31 - 01002496 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\DeviceCommonLib\06251528bbadcb3da726d324a41e710f\DeviceCommonLib.ni.dll
 2013-08-15 12:54 - 2013-08-15 12:54 - 00232960 _____ () C:\Windows\assembly\NativeImages_v4.0.30319_32\ASF_cSharpAPI\c5efe841e2998c266e0f5e29bed04b55\ASF_cSharpAPI.ni.dll
 2013-09-14 01:51 - 2013-09-14 01:51 - 00087952 _____ () C:\Program Files\Common Files\Apple\Internet Services\zlib1.dll
 2013-09-14 01:50 - 2013-09-14 01:50 - 01242952 _____ () C:\Program Files\Common Files\Apple\Internet Services\libxml2.dll
 
 ==================== Alternate Data Streams (whitelisted) =========
 
 AlternateDataStreams: C:\ProgramData\TEMP:373E1720
 AlternateDataStreams: C:\ProgramData\TEMP:AD022376
 
 ==================== Safe Mode (whitelisted) ===================
 
 
 ==================== Faulty Device Manager Devices =============
 
 
 ==================== Event log errors: =========================
 
 Application errors:
 ==================
 Error: (01/30/2014 07:08:06 PM) (Source: SideBySide) (User: )
 Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
 Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
 Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
 
 Error: (01/30/2014 07:06:37 PM) (Source: SideBySide) (User: )
 Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"2" in Zeile  Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"3.
 Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
 Verweis: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
 Definition: Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
 Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
 Error: (01/30/2014 07:06:35 PM) (Source: SideBySide) (User: )
 Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"2" in Zeile  Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"3.
 Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
 Verweis: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
 Definition: Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
 Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
 Error: (01/29/2014 07:58:21 PM) (Source: SideBySide) (User: )
 Description: Fehler beim Generieren des Aktivierungskontextes für "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"1".
 Die abhängige Assemblierung "rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"" konnte nicht gefunden werden.
 Verwenden Sie für eine detaillierte Diagnose das Programm "sxstrace.exe".
 
 Error: (01/29/2014 07:55:43 PM) (Source: SideBySide) (User: )
 Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"2" in Zeile  Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"3.
 Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
 Verweis: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
 Definition: Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
 Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
 Error: (01/29/2014 07:55:41 PM) (Source: SideBySide) (User: )
 Description: Fehler beim Generieren des Aktivierungskontextes für "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"1". Fehler in Manifest- oder Richtliniendatei "Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"2" in Zeile  Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"3.
 Die im Manifest gefundene Komponenten-ID stimmt nicht mit der ID der angeforderten Komponente überein.
 Verweis: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
 Definition: Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8".
 Verwenden Sie das Programm "sxstrace.exe" für eine detaillierte Diagnose.
 
 Error: (01/29/2014 05:37:26 PM) (Source: VSS) (User: )
 Description: Volumeschattenkopie-Dienstfehler: Beim Abfragen nach der Schnittstelle "IVssWriterCallback" ist ein unerwarteter Fehler aufgetreten. hr = 0x80070005, Zugriff verweigert
 .
 Die Ursache hierfür ist oft eine falsche Sicherheitseinstellung im Schreib- oder Anfrageprozess.
 
 
 Vorgang:
 Generatordaten werden gesammelt
 
 Kontext:
 Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
 Generatorname: System Writer
 Generatorinstanz-ID: {21a80d97-8b01-46ad-a6f3-f728bb8f3e2b}
 
 Error: (01/27/2014 08:18:19 PM) (Source: Microsoft-Windows-CAPI2) (User: )
 Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
 
 
 Details:
 AddWin32ServiceFiles: Unable to back up image of service syshost32 since QueryServiceConfig API failed
 
 System Error:
 Zugriff verweigert
 .
 
 Error: (01/27/2014 08:18:19 PM) (Source: Microsoft-Windows-CAPI2) (User: )
 Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
 
 
 Details:
 AddWin32ServiceFiles: Unable to back up image of service Windows Update since QueryServiceConfig API failed
 
 System Error:
 Zugriff verweigert
 .
 
 Error: (01/27/2014 08:18:19 PM) (Source: Microsoft-Windows-CAPI2) (User: )
 Description: Fehler beim Kryptografiedienst während der Verarbeitung des "OnIdentity()"-Aufrufobjekts "System Writer".
 
 
 Details:
 AddWin32ServiceFiles: Unable to back up image of service Intelligenter Hintergrundübertragungsdienst since QueryServiceConfig API failed
 
 System Error:
 Zugriff verweigert
 .
 
 
 System errors:
 =============
 Error: (01/30/2014 06:20:58 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "MBAMSwissArmy" wurde aufgrund folgenden Fehlers nicht gestartet:
 %%31
 
 Error: (01/30/2014 06:20:46 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "MBAMSwissArmy" wurde aufgrund folgenden Fehlers nicht gestartet:
 %%31
 
 Error: (01/30/2014 06:20:31 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "MBAMSwissArmy" wurde aufgrund folgenden Fehlers nicht gestartet:
 %%31
 
 Error: (01/30/2014 06:20:29 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "MBAMService" ist vom Dienst "MBAMProtector" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde:
 %%31
 
 Error: (01/30/2014 06:20:29 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "MBAMProtector" wurde aufgrund folgenden Fehlers nicht gestartet:
 %%31
 
 Error: (01/30/2014 06:20:18 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "MBAMSwissArmy" wurde aufgrund folgenden Fehlers nicht gestartet:
 %%31
 
 Error: (01/30/2014 05:16:17 PM) (Source: Service Control Manager) (User: )
 Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
 ssmdrv
 
 Error: (01/30/2014 05:14:36 PM) (Source: Service Control Manager) (User: )
 Description: Der Dienst "avgntflt" wurde aufgrund folgenden Fehlers nicht gestartet:
 %%31
 
 Error: (01/30/2014 05:14:29 PM) (Source: BTHUSB) (User: )
 Description:
 
 Error: (01/29/2014 05:41:11 PM) (Source: Service Control Manager) (User: )
 Description: Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen:
 ssmdrv
 
 
 Microsoft Office Sessions:
 =========================
 Error: (01/30/2014 07:08:06 PM) (Source: SideBySide)(User: )
 Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{EA1FAE0F-2354-4E32-B423-ABAE8E358F91}\recordingmanager.exe
 
 Error: (01/30/2014 07:06:37 PM) (Source: SideBySide)(User: )
 Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"c:\program files\Samsung\Kies\External\firmwareupdate\GT-N7000\DeviceController64.exec:\program files\Samsung\Kies\External\firmwareupdate\GT-N7000\Microsoft.VC90.CRT.MANIFEST11
 
 Error: (01/30/2014 07:06:35 PM) (Source: SideBySide)(User: )
 Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"c:\program files\Samsung\Kies\External\firmwareupdate\GT-I8190\DeviceController64.exec:\program files\Samsung\Kies\External\firmwareupdate\GT-I8190\Microsoft.VC90.CRT.MANIFEST11
 
 Error: (01/29/2014 07:58:21 PM) (Source: SideBySide)(User: )
 Description: rpshellextension.1.0,language="*",type="win32",version="1.0.0.0"C:\Windows\Installer\{EA1FAE0F-2354-4E32-B423-ABAE8E358F91}\recordingmanager.exe
 
 Error: (01/29/2014 07:55:43 PM) (Source: SideBySide)(User: )
 Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"c:\program files\Samsung\Kies\External\firmwareupdate\GT-N7000\DeviceController64.exec:\program files\Samsung\Kies\External\firmwareupdate\GT-N7000\Microsoft.VC90.CRT.MANIFEST11
 
 Error: (01/29/2014 07:55:41 PM) (Source: SideBySide)(User: )
 Description: Microsoft.VC90.CRT,processorArchitecture="amd64",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"Microsoft.VC90.CRT,processorArchitecture="x86",publicKeyToken="1fc8b3b9a1e18e3b",type="win32",version="9.0.21022.8"c:\program files\Samsung\Kies\External\firmwareupdate\GT-I8190\DeviceController64.exec:\program files\Samsung\Kies\External\firmwareupdate\GT-I8190\Microsoft.VC90.CRT.MANIFEST11
 
 Error: (01/29/2014 05:37:26 PM) (Source: VSS)(User: )
 Description: 0x80070005, Zugriff verweigert
 
 
 Vorgang:
 Generatordaten werden gesammelt
 
 Kontext:
 Generatorklassen-ID: {e8132975-6f93-4464-a53e-1050253ae220}
 Generatorname: System Writer
 Generatorinstanz-ID: {21a80d97-8b01-46ad-a6f3-f728bb8f3e2b}
 
 Error: (01/27/2014 08:18:19 PM) (Source: Microsoft-Windows-CAPI2)(User: )
 Description:
 Details:
 AddWin32ServiceFiles: Unable to back up image of service syshost32 since QueryServiceConfig API failed
 
 System Error:
 Zugriff verweigert
 
 Error: (01/27/2014 08:18:19 PM) (Source: Microsoft-Windows-CAPI2)(User: )
 Description:
 Details:
 AddWin32ServiceFiles: Unable to back up image of service Windows Update since QueryServiceConfig API failed
 
 System Error:
 Zugriff verweigert
 
 Error: (01/27/2014 08:18:19 PM) (Source: Microsoft-Windows-CAPI2)(User: )
 Description:
 Details:
 AddWin32ServiceFiles: Unable to back up image of service Intelligenter Hintergrundübertragungsdienst since QueryServiceConfig API failed
 
 System Error:
 Zugriff verweigert
 
 
 ==================== Memory info ===========================
 
 Percentage of memory in use: 83%
 Total physical RAM: 1023.43 MB
 Available physical RAM: 171.72 MB
 Total Pagefile: 2047.43 MB
 Available Pagefile: 530.03 MB
 Total Virtual: 2047.88 MB
 Available Virtual: 1883.88 MB
 
 ==================== Drives ================================
 
 Drive c: () (Fixed) (Total:148.95 GB) (Free:103.57 GB) NTFS
 Drive e: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)]
 
 ==================== MBR & Partition Table ==================
 
 ========================================================
 Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 982B982B)
 Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS)
 Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS)
 
 ==================== End Of Log ============================
 Wann wird es denn weiter gehen? Was ist der nächste Schritt?  
Ein neuer 2. Trojaner scheint hinzu gekommen zu sein...HILFE!!!! Windows Defender hat 2 Stück gefunden und den einen kann er nicht in die Quaratäne verschieben oder das System bereinigen. 
Name Trojaner 1: Win32/Necurs.A 
Name Trojaner 2: WinNT/Necurs.A 
Das hier ist das Ergebnis von Windows Defender. Mein Avira Echtzeitscanner lässt sich einfach nicht mehr aktivieren.  
Kategorie: 
Trojaner  
Beschreibung: 
Dieses Programm ist gefährlich. Es führt Befehle eines Angreifers aus.  
Empfehlung: 
Entfernen Sie diese Software unverzüglich.  
Ressourcen: 
file: 
C:\Windows\system32\drivers\4384475d9de5180c.sys  
hiddendriver: 
4384475d9de5180c  
hiddenfile: 
C:\Windows\System32\Drivers\4384475d9de5180c.sys   
Kann ich das Ding wieder loswerden ohne Platt machen und neu aufspielen? |