Cesipher | 16.05.2014 19:01 | Ok,
wie im ersten Post benannt hier erstmal der Addition-Log Code:
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-05-2014
Ran by Cesipher at 2014-05-16 17:16:06
Running from C:\Users\Cesipher\Desktop
Boot Mode: Normal
==========================================================
==================== Security Center ========================
AV: Avira Desktop (Enabled - Up to date) {4D041356-F94D-285F-8768-AAE50FA36859}
AV: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: Avira Desktop (Enabled - Up to date) {F665F2B2-DF77-27D1-BDD8-9197742422E4}
AS: Windows Defender (Disabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: ZoneAlarm Free Firewall Firewall (Enabled) {E6380B7E-D4B2-19F1-083E-56486607704B}
==================== Installed Programs ======================
Adobe Flash Player 13 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 13.0.0.214 - Adobe Systems Incorporated)
Adobe Reader XI (11.0.06) - Deutsch (HKLM-x32\...\{AC76BA86-7AD7-1031-7B44-AB0000000001}) (Version: 11.0.06 - Adobe Systems Incorporated)
Alcor Micro USB Card Reader (HKLM-x32\...\AmUStor) (Version: 4.8.1245.73583 - Alcor Micro Corp.)
Alcor Micro USB Card Reader (x32 Version: 4.8.1245.73583 - Alcor Micro Corp.) Hidden
Aloha TriPeaks (x32 Version: 2.2.0.98 - WildTangent) Hidden
Amazon 1Button App (HKLM-x32\...\{0A7D6F3C-F2AB-48ED-BE23-99791BFF87D6}) (Version: 1.0.0.4 - Amazon)
Atheros Driver Installation Program (HKLM-x32\...\{C3A32068-8AB1-4327-BB16-BED9C6219DC7}) (Version: 10.0 - Atheros)
Avira (HKLM-x32\...\{70a79d1f-686d-4d5c-962b-07aa1294eae0}) (Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG)
Avira (x32 Version: 1.1.12.20002 - Avira Operations GmbH & Co. KG) Hidden
Avira Free Antivirus (HKLM-x32\...\Avira AntiVir Desktop) (Version: 14.0.3.350 - Avira)
Bejeweled 3 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Chuzzle Deluxe (x32 Version: 2.2.0.95 - WildTangent) Hidden
Company of Heroes 2 (HKLM-x32\...\Steam App 231430) (Version: - Relic Entertainment)
DmC Devil May Cry (HKLM-x32\...\Steam App 220440) (Version: - Ninja Theory)
DTS Sound (HKLM-x32\...\{2DFA9084-CEB3-4A48-B9F7-9038FEF1B8F4}) (Version: 1.01.2700 - DTS, Inc.)
Empress of the Deep - The Darkest Secret (x32 Version: 2.2.0.98 - WildTangent) Hidden
Fallout: New Vegas (HKLM-x32\...\Steam App 22380) (Version: - Obsidian Entertainment)
Grand Theft Auto: Episodes from Liberty City (HKLM-x32\...\Steam App 12220) (Version: - Rockstar North / Toronto)
IDT Audio Driver (HKLM\...\{588A747E-CFF6-46B3-9207-CD754F9473AF}) (Version: 6.10.6491.0 - IDT)
Intel(R) Management Engine Components (HKLM-x32\...\{65153EA5-8B6E-43B6-857B-C6E4FC25798A}) (Version: 9.5.14.1724 - Intel Corporation)
Intel(R) Processor Graphics (HKLM-x32\...\{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}) (Version: 10.18.10.3282 - Intel Corporation)
Intel(R) Rapid Storage Technology (HKLM\...\{409CB30E-E457-4008-9B1A-ED1B9EA21140}) (Version: 12.8.0.1016 - Intel Corporation)
Intel(R) Rapid Storage Technology (Version: 12.8.0.1016 - Intel Corporation) Hidden
Intel® Trusted Connect Service Client (Version: 1.28.487.1 - Intel Corporation) Hidden
Island Tribe (x32 Version: 2.2.0.98 - WildTangent) Hidden
Jewel Quest Solitaire 2 (x32 Version: 2.2.0.98 - WildTangent) Hidden
Jurassic Park: The Game (HKLM-x32\...\Steam App 201830) (Version: - Telltale Games)
LibreOffice 4.1.4.2 (HKLM-x32\...\{94E11973-ED58-47A0-907C-ABF6D95C5DD8}) (Version: 4.1.4.2 - The Document Foundation)
Magic Academy (x32 Version: 2.2.0.98 - WildTangent) Hidden
Mass Effect (HKLM-x32\...\{1B0FBB9A-995D-47cd-87CD-13E68B676E4F}) (Version: 1.00 - Electronic Arts, Inc.)
Mass Effect 2 (HKLM-x32\...\Steam App 24980) (Version: - BioWare)
Mass Effect™ 3 (HKLM-x32\...\{6A9D1594-7791-48f5-9CAA-DE9BCB968320}) (Version: 1.01.0.0 - Electronic Arts)
Microsoft Office (HKLM-x32\...\{90150000-0138-0409-0000-0000000FF1CE}) (Version: 15.0.4454.1510 - Microsoft Corporation)
Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Home and Student 2007 (HKLM-x32\...\HOMESTUDENTR) (Version: 12.0.4518.1014 - Microsoft Corporation)
Microsoft Office Home and Student 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{7299052b-02a4-4627-81f2-1818da5d550d}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{837b34e3-7c30-493c-8f6a-2b0f04e2912c}) (Version: 8.0.59193 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 (HKLM-x32\...\{9A25302D-30C0-39D9-BD6F-21E6EC160475}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219 (HKLM\...\{1D8E6291-B0D5-35EC-8441-6616F567A0F7}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 (HKLM-x32\...\{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}) (Version: 10.0.40219 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x64) - 11.0.50727 (HKLM-x32\...\{15134cb0-b767-4960-a911-f2d16ae54797}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.50727 (HKLM-x32\...\{22154f09-719a-4619-bb71-5b3356999fbf}) (Version: 11.0.50727.1 - Microsoft Corporation)
Microsoft Visual C++ 2012 x64 Additional Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x64 Minimum Runtime - 11.0.50727 (Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.50727 (x32 Version: 11.0.50727 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 Preview Redistributable (x64) - 12.0.20617 (HKLM-x32\...\{448652c1-f5f3-4230-98c6-68c10c88b1fb}) (Version: 12.0.20617.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 Preview Redistributable (x86) - 12.0.20617 (HKLM-x32\...\{1f407217-9aec-4146-8504-e64ac959c534}) (Version: 12.0.20617.1 - Microsoft Corporation)
Microsoft Visual C++ 2013 x64 Additional Runtime - 12.0.20617 (Version: 12.0.20617 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x64 Minimum Runtime - 12.0.20617 (Version: 12.0.20617 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Additional Runtime - 12.0.20617 (x32 Version: 12.0.20617 - Microsoft Corporation) Hidden
Microsoft Visual C++ 2013 x86 Minimum Runtime - 12.0.20617 (x32 Version: 12.0.20617 - Microsoft Corporation) Hidden
Mobogenie (HKLM-x32\...\Mobogenie) (Version: - Mobogenie.com) <==== ATTENTION
Mozilla Firefox 29.0.1 (x86 de) (HKLM-x32\...\Mozilla Firefox 29.0.1 (x86 de)) (Version: 29.0.1 - Mozilla)
Mozilla Maintenance Service (HKLM-x32\...\MozillaMaintenanceService) (Version: 29.0.1 - Mozilla)
NVIDIA GeForce Experience 2.0 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.GFExperience) (Version: 2.0 - NVIDIA Corporation)
NVIDIA Grafiktreiber 335.23 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver) (Version: 335.23 - NVIDIA Corporation)
NVIDIA Install Application (Version: 2.1002.151.1095 - NVIDIA Corporation) Hidden
NVIDIA LED Visualizer 1.0 (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Network Service (Version: 1.0 - NVIDIA Corporation) Hidden
NVIDIA Optimus Update 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden
NVIDIA PhysX (x32 Version: 9.13.1220 - NVIDIA Corporation) Hidden
NVIDIA PhysX-Systemsoftware 9.13.1220 (HKLM\...\{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX) (Version: 9.13.1220 - NVIDIA Corporation)
NVIDIA ShadowPlay 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden
NVIDIA Systemsteuerung 335.23 (Version: 335.23 - NVIDIA Corporation) Hidden
NVIDIA Update 12.4.55 (Version: 12.4.55 - NVIDIA Corporation) Hidden
NVIDIA Update Core (Version: 12.4.55 - NVIDIA Corporation) Hidden
NVIDIA Virtual Audio 1.2.22 (Version: 1.2.22 - NVIDIA Corporation) Hidden
Origin (HKLM-x32\...\Origin) (Version: 9.2.1.4399 - Electronic Arts, Inc.)
Peggle Nights (x32 Version: 2.2.0.98 - WildTangent) Hidden
Plants vs. Zombies - Game of the Year (x32 Version: 2.2.0.98 - WildTangent) Hidden
Polar Bowler (x32 Version: 2.2.0.97 - WildTangent) Hidden
Qualcomm Atheros Bluetooth Suite (64) (HKLM\...\{A84A4FB1-D703-48DB-89E0-68B6499D2801}) (Version: 8.0.1.300 - Qualcomm Atheros)
Qualcomm Atheros Inc.(R) AR81Family Gigabit/Fast Ethernet Driver (HKLM-x32\...\{3108C217-BE83-42E4-AE9E-A56A2A92E549}) (Version: 2.1.0.21 - Qualcomm Atheros Inc.)
S.T.A.L.K.E.R.: Shadow of Chernobyl (HKLM-x32\...\Steam App 4500) (Version: - GSC Game World)
SHIELD Streaming (Version: 1.8.323 - NVIDIA Corporation) Hidden
Spotify (HKLM-x32\...\Spotify) (Version: 0.8.5.1333.g822e0de8 - Spotify AB)
State of Decay (HKLM-x32\...\Steam App 241540) (Version: - Undead Labs)
Steam (HKLM-x32\...\Steam) (Version: - Valve Corporation)
Synaptics Pointing Device Driver (HKLM\...\SynTPDeinstKey) (Version: 17.0.10.1 - Synaptics Incorporated)
The Elder Scrolls V: Skyrim (HKLM-x32\...\Steam App 72850) (Version: - Bethesda Game Studios)
The Walking Dead (HKLM-x32\...\Steam App 207610) (Version: - )
The Walking Dead: Season Two (HKLM-x32\...\Steam App 261030) (Version: - Telltale Games)
TOSHIBA Addendum (HKLM-x32\...\{CE0374A6-B204-4336-8293-63FBB1DADBF4}) (Version: 1.00 - TOSHIBA)
TOSHIBA Addendum (x32 Version: 1.00 - TOSHIBA) Hidden
TOSHIBA Desktop Assist (HKLM\...\{95CCACF0-010D-45F0-82BF-858643D8BC02}) (Version: 1.02.01.6407 - Toshiba Corporation)
TOSHIBA Display Utility (HKLM\...\{84FA4D2D-4273-4C66-BD3D-ADD3FE48DFA2}) (Version: 1.1.5.0 - Toshiba Corporation)
TOSHIBA eco Utility (HKLM\...\{5944B9D4-3C2A-48DE-931E-26B31714A2F7}) (Version: 2.2.0.6404 - Toshiba Corporation)
TOSHIBA Function Key (HKLM\...\{16562A90-71BC-41A0-B890-D91B0C267120}) (Version: 1.1.0001.6403 - Toshiba Corporation)
TOSHIBA Manuals (HKLM-x32\...\{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}) (Version: 10.10 - TOSHIBA)
TOSHIBA Password Utility (HKLM-x32\...\InstallShield_{78931270-BC9E-441A-A52B-73ECD4ACFAB5}) (Version: 3.00.344 - Toshiba Corporation)
TOSHIBA Password Utility (x32 Version: 3.00.344 - Toshiba Corporation) Hidden
TOSHIBA PC Health Monitor (HKLM\...\{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}) (Version: 1.9.09.6400 - Toshiba Corporation)
TOSHIBA Recovery Media Creator (HKLM-x32\...\{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}) (Version: 3.1.02.55065006 - Toshiba Corporation)
TOSHIBA Service Station (HKLM\...\{FBFCEEA5-96EA-4C8E-9262-43CBBEBAE413}) (Version: 2.6.8 - Toshiba Corporation)
TOSHIBA System Driver (HKLM-x32\...\{1E6A96A1-2BAB-43EF-8087-30437593C66C}) (Version: 1.00.0030 - Toshiba Corporation)
TOSHIBA System Settings (HKLM-x32\...\{05A55927-DB9B-4E26-BA44-828EBFF829F0}) (Version: 1.1.2.32001 - Toshiba Corporation)
Toshiba TEMPRO (HKLM-x32\...\{F76F5214-83A8-4030-80C9-1EF57391D72A}) (Version: 4.5.0 - Toshiba Europe GmbH)
TOSHIBA VIDEO PLAYER (HKLM\...\{FF07604E-C860-40E9-A230-E37FA41F103A}) (Version: 5.3.27.102 - Toshiba Corporation)
Trine 2 (HKLM-x32\...\Steam App 35720) (Version: - Frozenbyte)
UltraStar Deluxe (HKLM-x32\...\UltraStar Deluxe) (Version: 1.1 - USDX Team)
Update Installer for WildTangent Games App (x32 Version: - WildTangent) Hidden
Virtual Villagers 4 - The Tree of Life (x32 Version: 2.2.0.98 - WildTangent) Hidden
VLC media player 2.1.3 (HKLM-x32\...\VLC media player) (Version: 2.1.3 - VideoLAN)
Wiggles (HKLM-x32\...\Wiggles) (Version: - )
WildTangent Games (HKLM-x32\...\WildTangent wildgames Master Uninstall) (Version: 1.0.3.0 - WildTangent)
WildTangent Games App (Toshiba Games) (x32 Version: 4.0.9.7 - WildTangent) Hidden
WinRAR archiver (HKLM-x32\...\WinRAR archiver) (Version: - )
World of Tanks (HKLM-x32\...\{1EAC1D02-C6AC-4FA6-9A44-96258C37C812EU}_is1) (Version: - Wargaming.net)
ZoneAlarm Firewall (x32 Version: 12.0.121.000 - Check Point Software Technologies Ltd.) Hidden
ZoneAlarm Free Firewall (HKLM-x32\...\ZoneAlarm Free Firewall) (Version: 12.0.121.000 - Check Point)
ZoneAlarm Security (x32 Version: 12.0.121.000 - Check Point Software Technologies Ltd.) Hidden
==================== Restore Points =========================
21-04-2014 20:31:38 Installed Microsoft Office Home and Student 2007
29-04-2014 20:13:38 Windows Update
03-05-2014 16:44:42 Windows Update
08-05-2014 06:04:51 DirectX wurde installiert
15-05-2014 14:54:30 Windows Modules Installer
16-05-2014 14:22:41 Windows-Sicherung
==================== Hosts content: ==========================
2013-08-22 15:25 - 2013-08-22 15:25 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts
==================== Scheduled Tasks (whitelisted) =============
Task: {05293577-D647-4185-B859-C94839A0B2E3} - System32\Tasks\Microsoft\Windows\SettingSync\NetworkStateChangeTask
Task: {0B545118-B563-42FC-8D07-B78F602FCF34} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList
Task: {11AE63F6-2AC3-4AF7-8602-6F7207351985} - System32\Tasks\Resolution+ Setting Task => C:\Program Files\Toshiba\TOSHIBA Smart View Utility\Plugins\ResolutionPlus\TosRegPermissionChg.exe [2013-08-28] (TODO: <Company name>)
Task: {2085BF56-520D-4951-B7C0-DF34AF90CC6A} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask
Task: {2C9C0C6C-2A74-46F2-858A-4389D253EAD0} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCachePrepopulate
Task: {352E6CA0-7314-4DF4-89C4-682368D80D57} - System32\Tasks\Microsoft\Windows\Workplace Join\Automatic-Workplace-Join => C:\Windows\System32\AutoWorkplace.exe [2013-08-22] (Microsoft Corporation)
Task: {3B6D8A73-F20B-4C93-B8FB-56A154F172D2} - System32\Tasks\Microsoft\Windows\Time Zone\SynchronizeTimeZone => C:\Windows\system32\tzsync.exe [2013-08-22] (Microsoft Corporation)
Task: {49754026-21E1-41FC-94FD-727AFE414FE7} - System32\Tasks\Microsoft\Windows\Sysmain\HybridDriveCacheRebalance
Task: {4ED4E822-8CC9-42A7-A3FD-9DEA8B27411E} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-05-14] (Adobe Systems Incorporated)
Task: {507919C7-6FFD-4A12-A0FA-10D827F62752} - System32\Tasks\Microsoft\Windows\RemovalTools\MRT_HB => C:\Windows\system32\MRT.exe [2014-05-15] (Microsoft Corporation)
Task: {6AA91E8C-DDBD-4979-8464-4062F7681A19} - System32\Tasks\Microsoft\Windows\Plug and Play\Plug and Play Cleanup
Task: {6DFCB649-0769-4F83-BB10-F60F235F6D3D} - System32\Tasks\Microsoft\Windows\SkyDrive\Idle Sync Maintenance Task
Task: {73B1B253-CE67-4501-AE1A-377DD1D68B65} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask
Task: {77F1A442-EDCA-4847-ACA9-DBE86C821EE3} - System32\Tasks\Microsoft\Windows\WindowsUpdate\Scheduled Start With Network => Sc.exe start wuauserv
Task: {77F1D869-6E65-4079-A2A0-E2023408EF97} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState
Task: {7D52E32A-8EC3-44F2-9C6C-72F891BF7C6B} - System32\Tasks\Microsoft\Windows\DiskCleanup\SilentCleanup => C:\Windows\system32\cleanmgr.exe [2014-02-22] (Microsoft Corporation)
Task: {824DD6DD-8034-4883-90DC-758AEDB1AB0D} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Validation
Task: {872D0E53-FD2E-41E3-B431-698AF82882CE} - System32\Tasks\Microsoft\Windows\SkyDrive\Routine Maintenance Task
Task: {8CC813C9-712A-41EF-9512-B233444FC669} - System32\Tasks\Microsoft\Windows\AppxDeploymentClient\Pre-staged app cleanup => Rundll32.exe %windir%\system32\AppxDeploymentClient.dll,AppxPreStageCleanupRunTask
Task: {98F0D9BE-66FD-46CC-80BD-402B533C9877} - System32\Tasks\Toshiba\CommonNotifier => C:\Program Files (x86)\Toshiba TEMPRO\Toshiba.Tempro.UI.CommonNotifier.exe [2013-07-19] (Toshiba Europe GmbH)
Task: {99FD4E9C-DC15-4050-9AD6-CE1319566612} - System32\Tasks\TOSHIBA\Service Station => C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe [2013-07-31] (TOSHIBA Corporation)
Task: {9FF4C139-5234-410C-B7FA-23EE2FD2AB53} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Maintenance Work
Task: {C7F1348C-622C-4BC2-89C6-A7189E060DB0} - System32\Tasks\Microsoft\Windows\WOF\WIM-Hash-Management
Task: {CA9391AB-7CAA-4B09-91F2-F65FE4A151FB} - System32\Tasks\Synaptics TouchPad Enhancements => C:\Program Files\Synaptics\SynTP\SynTPEnh.exe [2013-08-22] (Synaptics Incorporated)
Task: {CFD7C21A-808B-487B-A6EC-8A10E44E8360} - System32\Tasks\Microsoft\Windows\SettingSync\BackupTask
Task: {D88FEC9E-A82A-46F9-87E2-B6B97B301C1A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing
Task: {DA46820F-FF8A-4B5E-A6B2-B12185DCFFFB} - System32\Tasks\Microsoft\Windows\Work Folders\Work Folders Logon Synchronization
Task: {E6D378FA-E068-4BCB-80DE-56D43A249507} - System32\Tasks\Microsoft\Windows\RecoveryEnvironment\VerifyWinRE
Task: {FB93C7DC-FF18-42FC-B9A7-711A1268A93A} - System32\Tasks\Microsoft\Windows\DiskFootprint\Diagnostics
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
==================== Loaded Modules (whitelisted) =============
2013-03-27 22:53 - 2013-03-27 22:53 - 00163168 _____ () C:\Program Files (x86)\TOSHIBA\PasswordUtility\GFNEXSrv.exe
2013-09-10 22:54 - 2013-09-10 22:54 - 00019792 _____ () C:\Program Files (x86)\DTS, Inc\DTS Studio Sound\dts_apo_service.exe
2013-12-12 07:04 - 2014-03-04 16:35 - 00013088 _____ () C:\Program Files\NVIDIA Corporation\CoProcManager\detoured.dll
2013-12-12 07:05 - 2014-03-04 15:05 - 00116056 _____ () C:\Program Files\NVIDIA Corporation\Display\NvSmartMax64.dll
2012-07-19 04:38 - 2012-07-19 04:38 - 00020904 _____ () C:\Program Files\TOSHIBA\Hotkey\SmoothView.dll
2014-01-30 21:28 - 2014-03-03 18:07 - 00768192 _____ () C:\Program Files (x86)\Mobogenie\DaemonProcess.exe
2014-03-05 22:58 - 2014-02-25 12:41 - 00394808 _____ () C:\Program Files (x86)\Avira\AntiVir Desktop\sqlite3.dll
2014-05-05 10:37 - 2014-05-05 10:37 - 00138320 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.NativeCore.dll
2014-05-05 10:37 - 2014-05-05 10:37 - 00065616 _____ () C:\Program Files (x86)\Avira\My Avira\Avira.OE.AvConnectorNative.dll
2013-12-12 06:59 - 2013-09-04 02:52 - 01242584 _____ () C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\ACE.dll
2014-01-30 21:28 - 2014-03-03 18:07 - 00061952 _____ () C:\Program Files (x86)\Mobogenie\Device.dll
2014-01-30 21:28 - 2014-03-03 18:07 - 00471040 _____ () C:\Program Files (x86)\Mobogenie\DCR.dll
2014-03-05 23:02 - 2014-05-05 10:37 - 00049744 _____ () C:\Users\Cesipher\AppData\Local\Temp\avgnt.exe\Avira.OE.ExtApi.dll
2014-01-31 20:03 - 2014-03-04 16:35 - 00014280 _____ () C:\Program Files (x86)\NVIDIA Corporation\CoProcManager\detoured.dll
2014-05-10 07:39 - 2014-05-10 07:40 - 03839088 _____ () C:\Program Files (x86)\Mozilla Firefox\mozjs.dll
==================== Alternate Data Streams (whitelisted) =========
==================== Safe Mode (whitelisted) ===================
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mcpltsvc => ""=""
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefire => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfefirek.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfehidk.sys => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\mfevtp => ""="Driver"
HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\vsmon => ""="Service"
==================== EXE Association (whitelisted) =============
==================== Disabled items from MSCONFIG ==============
==================== Faulty Device Manager Devices =============
Name: Qualcomm Atheros AR956x Wireless Network Adapter
Description: Qualcomm Atheros AR956x Wireless Network Adapter
Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318}
Manufacturer: Qualcomm Atheros Communications Inc.
Service: athr
Problem: : This device is disabled. (Code 22)
Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions.
==================== Event log errors: =========================
Application errors:
==================
Error: (05/16/2014 05:14:56 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST64.exe, Version 15.5.2014.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 1580
Startzeit: 01cf7118b8e79747
Endzeit: 60000
Anwendungspfad: C:\Users\Cesipher\Desktop\FRST64.exe
Berichts-ID: a9affdc3-dd0c-11e3-8273-645a04c1aa59
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (05/16/2014 05:09:38 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: Programm FRST64.exe, Version 15.5.2014.0 kann nicht mehr unter Windows ausgeführt werden und wurde beendet. Überprüfen Sie den Problemverlauf in der Wartungscenter-Systemsteuerung, um nach weiteren Informationen zum Problem zu suchen.
Prozess-ID: 129c
Startzeit: 01cf71185b4a208e
Endzeit: 60000
Anwendungspfad: C:\Users\Cesipher\Desktop\FRST64.exe
Berichts-ID: ebf572c4-dd0b-11e3-8273-645a04c1aa59
Vollständiger Name des fehlerhaften Pakets:
Anwendungs-ID, die relativ zum fehlerhaften Paket ist:
Error: (05/16/2014 05:05:36 PM) (Source: MsiInstaller) (EventID: 1024) (User: Toby1)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011007}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127
Error: (05/16/2014 05:04:03 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: Explorer.EXE, Version: 6.3.9600.17039, Zeitstempel: 0x53156588
Name des fehlerhaften Moduls: fhcpl.dll_unloaded, Version: 6.3.9600.17031, Zeitstempel: 0x53086266
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0000000000007d44
ID des fehlerhaften Prozesses: 0x16b0
Startzeit der fehlerhaften Anwendung: 0xExplorer.EXE0
Pfad der fehlerhaften Anwendung: Explorer.EXE1
Pfad des fehlerhaften Moduls: Explorer.EXE2
Berichtskennung: Explorer.EXE3
Vollständiger Name des fehlerhaften Pakets: Explorer.EXE4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: Explorer.EXE5
Error: (05/16/2014 04:09:55 PM) (Source: MsiInstaller) (EventID: 1024) (User: Toby1)
Description: Produkt: Adobe Reader XI - Deutsch - Update "{AC76BA86-7AD7-0000-2550-7A8C40011007}" konnte nicht installiert werden. Fehlercode 1625. Windows Installer kann Protokolle erstellen, um bei der Problembehandlung betreffend der Installation von Softwarepaketen behilflich zu sein. Verwenden Sie folgenden Link, um Anweisungen zur Aktivierung der Protokollierungsunterstützung zu erhalten: hxxp://go.microsoft.com/fwlink/?LinkId=23127
Error: (05/16/2014 04:08:46 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: zatray.exe, Version: 12.0.121.0, Zeitstempel: 0x52e9d2b7
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17031, Zeitstempel: 0x5308893d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0001f0a3
ID des fehlerhaften Prozesses: 0x70c
Startzeit der fehlerhaften Anwendung: 0xzatray.exe0
Pfad der fehlerhaften Anwendung: zatray.exe1
Pfad des fehlerhaften Moduls: zatray.exe2
Berichtskennung: zatray.exe3
Vollständiger Name des fehlerhaften Pakets: zatray.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: zatray.exe5
Error: (05/15/2014 04:54:20 PM) (Source: System Restore) (EventID: 8193) (User: )
Description: Fehler beim Erstellen des Wiederherstellungspunkts (Prozess = C:\Windows\system32\svchost.exe -k netsvcs; Beschreibung = Windows Update; Fehler = 0x81000101).
Error: (05/15/2014 06:12:50 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: zatray.exe, Version: 12.0.121.0, Zeitstempel: 0x52e9d2b7
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17031, Zeitstempel: 0x5308893d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0001f0a3
ID des fehlerhaften Prozesses: 0xc20
Startzeit der fehlerhaften Anwendung: 0xzatray.exe0
Pfad der fehlerhaften Anwendung: zatray.exe1
Pfad des fehlerhaften Moduls: zatray.exe2
Berichtskennung: zatray.exe3
Vollständiger Name des fehlerhaften Pakets: zatray.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: zatray.exe5
Error: (05/14/2014 06:09:49 AM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: zatray.exe, Version: 12.0.121.0, Zeitstempel: 0x52e9d2b7
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17031, Zeitstempel: 0x5308893d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0001f0a3
ID des fehlerhaften Prozesses: 0x2a4
Startzeit der fehlerhaften Anwendung: 0xzatray.exe0
Pfad der fehlerhaften Anwendung: zatray.exe1
Pfad des fehlerhaften Moduls: zatray.exe2
Berichtskennung: zatray.exe3
Vollständiger Name des fehlerhaften Pakets: zatray.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: zatray.exe5
Error: (05/13/2014 03:31:35 PM) (Source: Application Error) (EventID: 1000) (User: )
Description: Name der fehlerhaften Anwendung: zatray.exe, Version: 12.0.121.0, Zeitstempel: 0x52e9d2b7
Name des fehlerhaften Moduls: ntdll.dll, Version: 6.3.9600.17031, Zeitstempel: 0x5308893d
Ausnahmecode: 0xc0000005
Fehleroffset: 0x0001f0a3
ID des fehlerhaften Prozesses: 0x1208
Startzeit der fehlerhaften Anwendung: 0xzatray.exe0
Pfad der fehlerhaften Anwendung: zatray.exe1
Pfad des fehlerhaften Moduls: zatray.exe2
Berichtskennung: zatray.exe3
Vollständiger Name des fehlerhaften Pakets: zatray.exe4
Anwendungs-ID, die relativ zum fehlerhaften Paket ist: zatray.exe5
System errors:
=============
Error: (05/16/2014 06:21:41 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee AP Service" wurde aufgrund folgenden Fehlers nicht gestartet:
%%2
Error: (05/16/2014 06:21:29 AM) (Source: Service Control Manager) (EventID: 7000) (User: )
Description: Der Dienst "McAfee Inc. mfeapfk" wurde aufgrund folgenden Fehlers nicht gestartet:
%%1243
Error: (05/15/2014 07:14:58 PM) (Source: DCOM) (EventID: 10010) (User: Toby1)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (05/15/2014 07:14:28 PM) (Source: DCOM) (EventID: 10010) (User: Toby1)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (05/15/2014 05:21:17 PM) (Source: DCOM) (EventID: 10010) (User: Toby1)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (05/15/2014 05:20:47 PM) (Source: DCOM) (EventID: 10010) (User: Toby1)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (05/14/2014 09:37:31 PM) (Source: DCOM) (EventID: 10010) (User: Toby1)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Error: (05/14/2014 09:37:00 PM) (Source: DCOM) (EventID: 10010) (User: Toby1)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (05/13/2014 03:44:53 PM) (Source: DCOM) (EventID: 10010) (User: Toby1)
Description: {BF6C1E47-86EC-4194-9CE5-13C15DCB2001}
Error: (05/13/2014 03:44:23 PM) (Source: DCOM) (EventID: 10010) (User: Toby1)
Description: {1B1F472E-3221-4826-97DB-2C2324D389AE}
Microsoft Office Sessions:
=========================
==================== Memory info ===========================
Percentage of memory in use: 20%
Total physical RAM: 12199.95 MB
Available physical RAM: 9697.31 MB
Total Pagefile: 14055.95 MB
Available Pagefile: 11629.94 MB
Total Virtual: 131072 MB
Available Virtual: 131071.8 MB
==================== Drives ================================
Drive c: (TI31204300A) (Fixed) (Total:920.2 GB) (Free:556.75 GB) NTFS
Drive d: (TREKSTOR) (Fixed) (Total:465.65 GB) (Free:89.63 GB) FAT32
Drive f: (Volume) (Fixed) (Total:298.09 GB) (Free:56.14 GB) NTFS
==================== MBR & Partition Table ==================
========================================================
Disk: 0 (Size: 932 GB) (Disk ID: 00000000)
Partition: GPT Partition Type.
========================================================
Disk: 1 (MBR Code: Windows XP) (Size: 298 GB) (Disk ID: 832CD073)
Partition 1: (Not Active) - (Size=298 GB) - (Type=07 NTFS)
========================================================
Disk: 2 (Size: 466 GB) (Disk ID: 4A4E3CA5)
Partition 1: (Not Active) - (Size=466 GB) - (Type=0C)
==================== End Of Log ============================
Dann habe ich den Gmer-Scan durchgeführt. Dort gab es eine Fehlermeldung, dass er auf Win.../system32 nicht zugreifen konnte. Aber er schloss trotzdem den Scan ab. Hier die Logfile: Code:
GMER 2.1.19357 - hxxp://www.gmer.net
Rootkit scan 2014-05-16 17:38:16
Windows 6.2.9200 x64 \Device\Harddisk0\DR0 -> \Device\00000037 TOSHIBA_MQ01ABD100 rev.AX0A4M 931,51GB
Running: the6qm0b.exe; Driver: C:\Users\Cesipher\AppData\Local\Temp\pxddipow.sys
---- User code sections - GMER 2.1 ----
.text C:\Windows\system32\mfevtps.exe[2040] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 506 00007ffd15e7169a 4 bytes [E7, 15, FD, 7F]
.text C:\Windows\system32\mfevtps.exe[2040] C:\Windows\system32\psapi.dll!GetModuleBaseNameA + 514 00007ffd15e716a2 4 bytes [E7, 15, FD, 7F]
.text C:\Windows\system32\mfevtps.exe[2040] C:\Windows\system32\psapi.dll!QueryWorkingSet + 118 00007ffd15e7181a 4 bytes [E7, 15, FD, 7F]
.text C:\Windows\system32\mfevtps.exe[2040] C:\Windows\system32\psapi.dll!QueryWorkingSet + 142 00007ffd15e71832 4 bytes [E7, 15, FD, 7F]
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\KERNEL32.DLL!K32GetModuleInformation 00007ffd160528c0 7 bytes JMP 00007ffe13840260
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\KERNEL32.DLL!RegQueryValueExW 00007ffd160543d8 7 bytes JMP 00007ffe13840298
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\KERNEL32.DLL!RegSetValueExA 00007ffd16101f20 7 bytes JMP 00007ffe13840308
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\KERNEL32.DLL!RegSetValueExW 00007ffd161040b4 7 bytes JMP 00007ffe13840340
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\KERNEL32.DLL!RegDeleteValueW 00007ffd16104510 7 bytes JMP 00007ffe138402d0
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\KERNEL32.DLL!K32EnumProcessModulesEx 00007ffd1612cea0 7 bytes JMP 00007ffe138401f0
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\KERNEL32.DLL!K32GetMappedFileNameW 00007ffd1612cf10 7 bytes JMP 00007ffe13840228
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleW 00007ffd13852300 7 bytes JMP 00007ffe138400d8
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\KERNELBASE.dll!FreeLibrary 00007ffd13855770 5 bytes JMP 00007ffe13840180
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\KERNELBASE.dll!LoadLibraryExW 00007ffd13855860 5 bytes JMP 00007ffe13840148
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\KERNELBASE.dll!GetModuleHandleExW 00007ffd13855a30 5 bytes JMP 00007ffe13840110
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\KERNELBASE.dll!GetModuleFileNameExW 00007ffd138ca3f0 5 bytes JMP 00007ffe138401b8
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\USER32.dll!CreateWindowExW 00007ffd1561b6f4 10 bytes JMP 00007ffe13840420
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 00007ffd156245d8 5 bytes JMP 00007ffe138403e8
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ffd15624750 9 bytes JMP 00007ffe13840378
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 00007ffd15634fc0 5 bytes JMP 00007ffe138403b0
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\GDI32.dll!D3DKMTGetDisplayModeList 00007ffd158b1500 8 bytes JMP 00007ffe13840458
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\system32\GDI32.dll!D3DKMTQueryAdapterInfo 00007ffd158b1750 8 bytes JMP 00007ffe13840490
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\System32\dxgi.dll!CreateDXGIFactory1 00007ffd11537c28 5 bytes JMP 00007ffe11520110
.text C:\Windows\System32\dwm.exe[5048] C:\Windows\System32\dxgi.dll!CreateDXGIFactory 00007ffd11544b84 5 bytes JMP 00007ffe115200d8
.text C:\Windows\system32\nvvsvc.exe[5564] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffd15e7169a 4 bytes [E7, 15, FD, 7F]
.text C:\Windows\system32\nvvsvc.exe[5564] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffd15e716a2 4 bytes [E7, 15, FD, 7F]
.text C:\Windows\system32\nvvsvc.exe[5564] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffd15e7181a 4 bytes [E7, 15, FD, 7F]
.text C:\Windows\system32\nvvsvc.exe[5564] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffd15e71832 4 bytes [E7, 15, FD, 7F]
.text C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe[5248] C:\Windows\system32\KERNEL32.dll!K32GetModuleInformation 00007ffd160528c0 7 bytes JMP 00007ffe13840260
.text C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe[5248] C:\Windows\system32\KERNEL32.dll!RegQueryValueExW 00007ffd160543d8 7 bytes JMP 00007ffe13840298
.text C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe[5248] C:\Windows\system32\KERNEL32.dll!RegSetValueExA 00007ffd16101f20 7 bytes JMP 00007ffe13840308
.text C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe[5248] C:\Windows\system32\KERNEL32.dll!RegSetValueExW 00007ffd161040b4 7 bytes JMP 00007ffe13840340
.text C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe[5248] C:\Windows\system32\KERNEL32.dll!RegDeleteValueW 00007ffd16104510 7 bytes JMP 00007ffe138402d0
.text C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe[5248] C:\Windows\system32\KERNEL32.dll!K32EnumProcessModulesEx 00007ffd1612cea0 7 bytes JMP 00007ffe138401f0
.text C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe[5248] C:\Windows\system32\KERNEL32.dll!K32GetMappedFileNameW 00007ffd1612cf10 7 bytes JMP 00007ffe13840228
.text C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe[5248] C:\Windows\system32\USER32.dll!CreateWindowExW 00007ffd1561b6f4 10 bytes JMP 00007ffe13840420
.text C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe[5248] C:\Windows\system32\USER32.dll!EnumDisplayDevicesW 00007ffd156245d8 5 bytes JMP 00007ffe138403e8
.text C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe[5248] C:\Windows\system32\USER32.dll!DisplayConfigGetDeviceInfo 00007ffd15624750 9 bytes JMP 00007ffe13840378
.text C:\Program Files\TOSHIBA\Toshiba Service Station\ToshibaServiceStation.exe[5248] C:\Windows\system32\USER32.dll!EnumDisplayDevicesA 00007ffd15634fc0 5 bytes JMP 00007ffe138403b0
.text C:\Users\Cesipher\Desktop\FRST64.exe[4764] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ffd05f21f6a 4 bytes [F2, 05, FD, 7F]
.text C:\Users\Cesipher\Desktop\FRST64.exe[4764] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ffd05f21f82 4 bytes [F2, 05, FD, 7F]
.text C:\Users\Cesipher\Desktop\FRST64.exe[4764] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffd15e7169a 4 bytes [E7, 15, FD, 7F]
.text C:\Users\Cesipher\Desktop\FRST64.exe[4764] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffd15e716a2 4 bytes [E7, 15, FD, 7F]
.text C:\Users\Cesipher\Desktop\FRST64.exe[4764] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffd15e7181a 4 bytes [E7, 15, FD, 7F]
.text C:\Users\Cesipher\Desktop\FRST64.exe[4764] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffd15e71832 4 bytes [E7, 15, FD, 7F]
.text C:\Users\Cesipher\Desktop\FRST64.exe[5504] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 194 00007ffd05f21f6a 4 bytes [F2, 05, FD, 7F]
.text C:\Users\Cesipher\Desktop\FRST64.exe[5504] C:\Windows\SYSTEM32\WSOCK32.dll!setsockopt + 218 00007ffd05f21f82 4 bytes [F2, 05, FD, 7F]
.text C:\Users\Cesipher\Desktop\FRST64.exe[5504] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 506 00007ffd15e7169a 4 bytes [E7, 15, FD, 7F]
.text C:\Users\Cesipher\Desktop\FRST64.exe[5504] C:\Windows\system32\PSAPI.DLL!GetModuleBaseNameA + 514 00007ffd15e716a2 4 bytes [E7, 15, FD, 7F]
.text C:\Users\Cesipher\Desktop\FRST64.exe[5504] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 118 00007ffd15e7181a 4 bytes [E7, 15, FD, 7F]
.text C:\Users\Cesipher\Desktop\FRST64.exe[5504] C:\Windows\system32\PSAPI.DLL!QueryWorkingSet + 142 00007ffd15e71832 4 bytes [E7, 15, FD, 7F]
---- Threads - GMER 2.1 ----
Thread C:\Windows\system32\csrss.exe [5652:5832] fffff9600095db90
---- Disk sectors - GMER 2.1 ----
Disk \Device\Harddisk0\DR0 unknown MBR code
---- EOF - GMER 2.1 ---- Hier der Malware-Bericht. Die aufgeführten Funde habe ich dann in die Quarantäne verschoben. Da Avira lief gab es bei dem Registry-Eintrag eine Warnmeldung von Avira. Ich weiß daher nicht, ob der verschoben wurde. Code:
Malwarebytes Anti-Malware
www.malwarebytes.org
Suchlauf Datum: 16.05.2014
Suchlauf-Zeit: 18:22:37
Logdatei: Malwarebytes.txt
Administrator: Ja
Version: 2.00.1.1004
Malware Datenbank: v2014.05.16.11
Rootkit Datenbank: v2014.03.27.01
Lizenz: Kostenlos
Malware Schutz: Deaktiviert
Bösartiger Webseiten Schutz: Deaktiviert
Chameleon: Deaktiviert
Betriebssystem: Windows 8.1
CPU: x64
Dateisystem: NTFS
Benutzer: Cesipher
Suchlauf-Art: Bedrohungs-Suchlauf
Ergebnis: Abgeschlossen
Durchsuchte Objekte: 259079
Verstrichene Zeit: 29 Min, 2 Sek
Speicher: Aktiviert
Autostart: Aktiviert
Dateisystem: Aktiviert
Archive: Aktiviert
Rootkits: Deaktiviert
Shuriken: Aktiviert
PUP: Warnen
PUM: Warnen
Prozesse: 0
(No malicious items detected)
Module: 0
(No malicious items detected)
Registrierungsschlüssel: 0
(No malicious items detected)
Registrierungswerte: 1
PUP.Optional.NextLive.A, HKU\S-1-5-21-1497582622-3190364009-1015214424-1002-{ED1FC765-E35E-4C3D-BF15-2C2B11260CE4}-0\SOFTWARE\MICROSOFT\WINDOWS\CURRENTVERSION\RUN|NextLive, C:\Windows\SysWOW64\rundll32.exe "C:\Users\Cesipher\AppData\Roaming\newnext.me\nengine.dll",EntryPoint -m l, , [d348470b384358de83848aca69984cb4]
Registrierungsdaten: 0
(No malicious items detected)
Ordner: 2
PUP.Optional.NextLive.A, C:\Users\Cesipher\AppData\Roaming\newnext.me, , [1a017fd3681374c243461a580af8916f],
PUP.Optional.NextLive.A, C:\Users\Cesipher\AppData\Roaming\newnext.me\cache, , [1a017fd3681374c243461a580af8916f],
Dateien: 5
PUP.Optional.NextLive.A, C:\Users\Cesipher\AppData\Roaming\newnext.me\nengine.dll, , [d348470b384358de83848aca69984cb4],
PUP.Optional.NextLive.A, C:\Users\Cesipher\AppData\Local\Temp\Mobogenie_Setup_2.1.37_122100041.exe, , [18031d35a8d36bcbc93e7ed6a95825db],
PUP.Optional.NextLive.A, C:\Users\Cesipher\AppData\Local\genienext\nengine.dll, , [70abc58dd2a98bab94739eb646bbc937],
PUP.Optional.NextLive.A, C:\Users\Cesipher\AppData\Roaming\newnext.me\nengine.cookie, , [1a017fd3681374c243461a580af8916f],
PUP.Optional.NextLive.A, C:\Users\Cesipher\AppData\Roaming\newnext.me\cache\spark.bin, , [1a017fd3681374c243461a580af8916f],
Physische Sektoren: 0
(No malicious items detected)
(end)
Der abschließende FRST-Log ist zu lang, den packe ich in den Folgepost. |