Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: FRST Logfile Auswertung

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 06.02.2014, 16:35   #1
Keckrem
 
FRST Logfile Auswertung - Standard

FRST Logfile Auswertung



Hallo,
habe einen Kontrollscan mit FRST gemacht und wollte nachfragen, ob ihr etwas (verseuchtes) erkennen könnt. Ich konnte beim leienhaften drüberschauen nichts schlimmes erkennen.

Code:
ATTFilter
Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-02-2014
Ran by Gideon (administrator) on HOME on 06-02-2014 16:20:40
Running from C:\Users\Gideon\Downloads
Windows 8 (X64) OS Language: German Standard
Internet Explorer Version 10
Boot Mode: Normal

The only official download link for FRST:
Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ 
Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ 
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe
(Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe
(Microsoft Corporation) C:\Windows\System32\dasHost.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe
(McAfee, Inc.) C:\Program Files\mcafee\AppStats\MfeASUM.exe
(McAfee, Inc.) C:\Windows\System32\mfevtps.exe
(McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe
(ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe
(Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe
(Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe
(Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe
() C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe
(Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe
(Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe
(Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe
(McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\mcsvchost\McSvHost.exe
(McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Farbar) C:\Users\Gideon\Downloads\FRST64 (1).exe


==================== Registry (Whitelisted) ==================

HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2890640 2013-04-22] (ELAN Microelectronics Corp.)
HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13519432 2013-04-09] (Realtek Semiconductor)
HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1278024 2013-03-08] (Realtek Semiconductor)
HKLM-x32\...\Run: [mcpltui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [537512 2013-09-24] (McAfee, Inc.)
HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642816 2013-06-03] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation)
HKLM\...\Policies\Explorer: [NoControlPanel] 0
HKU\S-1-5-21-2058586743-3979093847-619797469-1001\...\Run: [Spotify Web Helper] - C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1193176 2013-09-28] ()

==================== Internet (Whitelisted) ====================

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - DefaultScope {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKLM - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM - {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKLM-x32 - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKLM-x32 - {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS
SearchScopes: HKCU - DefaultScope {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = 
SearchScopes: HKCU - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms}
SearchScopes: HKCU - {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = 
BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations)
BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
Tcpip\Parameters: [DhcpNameServer] 192.168.2.1

Chrome: 
=======
CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.1.377\_platform_specific\win_x86\widevinecdmadapter.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\PepperFlash\pepflashplayer.dll ()
CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll ()
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\pdf.dll ()
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.)
CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
CHR Plugin: (Java(TM) Platform SE 7 U45) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
CHR Plugin: (WildTangent Games App V2 Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
CHR Plugin: (McAfee SecurityCenter) - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
CHR Extension: (Google Docs) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-25]
CHR Extension: (Google Drive) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-25]
CHR Extension: (YouTube) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-25]
CHR Extension: (Google-Suche) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-25]
CHR Extension: (SiteAdvisor) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2013-12-29]
CHR Extension: (AdBlock) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-25]
CHR Extension: (Google Wallet) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-25]
CHR Extension: (Google Mail) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-25]
CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2013-12-28]

==================== Services (Whitelisted) =================

S2 0115761391277686mcinstcleanup; C:\Windows\TEMP\011576~1.EXE [834664 2013-07-30] (McAfee, Inc.)
R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227968 2013-02-28] (Qualcomm Atheros Commnucations)
R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-27] (Acer Incorporated)
R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [660040 2013-01-18] (Acer Incorporated)
R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100752 2013-04-22] (ELAN Microelectronics Corp.)
R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-04-26] (Acer Incorporate)
R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [121616 2013-10-02] (McAfee, Inc.)
R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178048 2013-11-28] (McAfee, Inc.)
S3 McAWFwk; C:\Program Files\Common Files\mcafee\actwiz\McAWFwk.exe [334760 2012-12-21] (McAfee, Inc.)
R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.)
S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
R2 MfeASUM; C:\Program Files\McAfee\AppStats\MfeASUM.exe [335216 2013-12-26] (McAfee, Inc.)
R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1025232 2013-12-11] (McAfee, Inc.)
R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-12-05] (McAfee, Inc.)
R2 mfevtp; C:\Windows\system32\mfevtps.exe [184800 2013-12-05] (McAfee, Inc.)
R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.)
S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation)
S3 NOBU; No ImagePath

==================== Drivers (Whitelisted) ====================

R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [37472 2013-02-14] (Advanced Micro Devices, Inc.)
R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [219360 2013-04-18] (AppEx Networks Corporation)
R3 AthrSdSrv; C:\Windows\system32\DRIVERS\athrsd.sys [43520 2013-03-12] (Qualcomm Atheros, Inc.)
R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98744 2013-04-23] (Advanced Micro Devices)
S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation)
S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-02-28] (Qualcomm Atheros)
S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation)
R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-12-05] (McAfee, Inc.)
S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.)
R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated)
R2 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179792 2013-12-05] (McAfee, Inc.)
R1 MfeASKM; C:\Program Files\McAfee\AppStats\MfeASKM.sys [31408 2013-12-26] (McAfee, Inc.)
R2 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311120 2013-12-05] (McAfee, Inc.)
U3 mfeavfk01; No ImagePath
S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69344 2013-12-05] (McAfee, Inc.)
R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519576 2013-12-05] (McAfee, Inc.)
R2 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [782616 2013-12-05] (McAfee, Inc.)
U3 mfehidk01; No ImagePath
R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [411944 2013-11-26] (McAfee, Inc.)
U3 mfencbdc01; No ImagePath
S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96112 2013-11-26] (McAfee, Inc.)
R2 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343696 2013-12-05] (McAfee, Inc.)
S3 QRDCIO; C:\Windows\System32\drivers\QRDCIO.sys [9728 2009-10-20] (QUANTA)
R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated)
U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-21] (Microsoft Corporation)

==================== NetSvcs (Whitelisted) ===================


==================== One Month Created Files and Folders ========

2014-02-06 16:19 - 2014-02-06 16:20 - 02082304 _____ (Farbar) C:\Users\Gideon\Downloads\FRST64 (1).exe
2014-02-05 13:34 - 2014-02-05 13:45 - 163606685 _____ () C:\Users\Gideon\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe
2014-02-05 07:44 - 2014-02-05 07:46 - 00000000 ____D () C:\Users\Gideon\AppData\Local\Adobe
2014-02-04 13:37 - 2014-02-04 13:38 - 02347384 _____ (ESET) C:\Users\Gideon\Downloads\esetsmartinstaller_enu (1).exe
2014-02-04 13:33 - 2014-02-04 13:33 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-02-04 13:32 - 2014-02-04 13:32 - 02347384 _____ (ESET) C:\Users\Gideon\Downloads\esetsmartinstaller_enu.exe
2014-02-03 13:05 - 2014-02-03 13:05 - 00000000 ___RD () C:\Users\Gideon\Documents\Notes
2014-02-01 19:07 - 2013-09-23 13:49 - 00197704 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys
2014-02-01 09:11 - 2014-02-01 09:11 - 00777528 _____ () C:\Windows\Minidump\020114-44429-01.dmp
2014-02-01 09:10 - 2014-02-01 09:10 - 339248834 _____ () C:\Windows\MEMORY.DMP
2014-01-26 13:44 - 2014-01-26 14:03 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-01-26 13:39 - 2014-01-26 14:03 - 00000000 ____D () C:\Users\Gideon\Desktop\mbar
2014-01-26 13:39 - 2014-01-26 13:44 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-01-26 13:36 - 2014-01-26 13:39 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Gideon\Downloads\mbar-1.07.0.1009.exe
2014-01-25 20:18 - 2014-01-25 20:19 - 02181948 _____ () C:\Users\Gideon\Downloads\LineApp.xlsm
2014-01-24 18:51 - 2014-01-24 18:51 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-01-24 18:27 - 2014-01-24 18:27 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-01-23 21:58 - 2014-01-23 21:58 - 00000000 ____D () C:\Users\Gideon\PicStream
2014-01-23 21:57 - 2014-01-23 22:42 - 00000000 ____D () C:\Users\Gideon\AppData\Local\clear.fi
2014-01-23 21:57 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Public\OEM
2014-01-23 21:57 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Gideon\Documents\clear.fi
2014-01-22 14:18 - 2014-01-22 14:18 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-20 14:59 - 2014-01-20 14:59 - 00000000 ___HD () C:\Users\Gideon\Desktop\.updtmp
2014-01-19 16:11 - 2014-01-19 16:11 - 00000000 ____D () C:\Users\Gideon\AppData\Local\fabi.me
2014-01-19 16:10 - 2013-09-24 11:14 - 00179200 _____ (fabi.me) C:\Users\Gideon\Desktop\SpeedAutoClicker.exe
2014-01-19 16:09 - 2014-01-19 16:09 - 00094899 _____ () C:\Users\Gideon\Downloads\SpeedAutoClicker.zip
2014-01-15 16:56 - 2013-12-07 07:37 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll
2014-01-15 16:56 - 2013-12-07 07:37 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 16:56 - 2013-12-07 06:15 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll
2014-01-15 16:56 - 2013-12-07 06:15 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll
2014-01-15 16:56 - 2013-10-31 06:56 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll
2014-01-15 16:56 - 2013-10-31 06:56 - 00758784 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll
2014-01-15 16:56 - 2013-10-31 05:01 - 00550400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll
2014-01-15 16:56 - 2013-10-31 04:42 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys
2014-01-15 16:56 - 2013-10-28 06:50 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll
2014-01-15 16:56 - 2013-10-28 05:05 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll
2014-01-15 16:56 - 2013-10-13 21:49 - 00100696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys
2014-01-15 16:56 - 2013-08-27 06:21 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll
2014-01-15 16:56 - 2013-08-27 06:19 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll
2014-01-15 16:56 - 2013-08-26 23:29 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll
2014-01-15 16:56 - 2013-08-26 23:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll
2014-01-10 21:53 - 2014-01-19 13:48 - 00004535 _____ () C:\Users\Gideon\Desktop\Neues Textdokument (2).txt
2014-01-10 20:55 - 2014-01-10 20:56 - 00000178 _____ () C:\Users\Gideon\Desktop\Logfiles Combofix.zip.zip
2014-01-10 20:41 - 2014-02-01 09:10 - 00011872 _____ () C:\Windows\PFRO.log
2014-01-10 20:35 - 2014-01-10 20:35 - 00131944 _____ () C:\ComboFix.txt
2014-01-10 20:22 - 2014-01-10 20:35 - 00000000 ____D () C:\Qoobox
2014-01-10 20:22 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-01-10 20:22 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-01-10 20:22 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-01-10 20:22 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-01-10 20:22 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-01-10 20:22 - 2000-08-31 01:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe
2014-01-10 20:22 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-01-10 20:22 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-01-10 20:22 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-01-10 20:21 - 2014-01-10 20:32 - 00000000 ____D () C:\Windows\erdnt
2014-01-09 16:06 - 2014-01-09 16:08 - 00023994 _____ () C:\Users\Gideon\Downloads\Addition.txt
2014-01-09 16:02 - 2014-02-06 16:20 - 00016694 _____ () C:\Users\Gideon\Downloads\FRST.txt
2014-01-09 16:02 - 2014-02-06 16:20 - 00000000 ____D () C:\FRST
2014-01-09 16:00 - 2014-01-09 16:00 - 01931770 _____ (Farbar) C:\Users\Gideon\Downloads\FRST64.exe
2014-01-08 18:25 - 2014-01-08 18:26 - 00001211 _____ () C:\Users\Gideon\Downloads\SHK.bat
2014-01-07 20:46 - 2014-01-07 20:46 - 00001050 _____ () C:\Users\Gideon\Desktop\VirtualDJ Home FREE.lnk
2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\Users\Gideon\Documents\VirtualDJ
2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\Users\Gideon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\ProgramData\APN
2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\Program Files (x86)\VirtualDJ
2014-01-07 20:45 - 2013-06-06 21:41 - 00489392 _____ (Ask Partner Network) C:\Users\Gideon\Documents\APNSetup.exe
2014-01-07 20:38 - 2014-01-07 20:42 - 39178560 _____ (Atomix Productions) C:\Users\Gideon\Downloads\install_virtualdj_home_v7.4.1.exe

==================== One Month Modified Files and Folders =======

2014-02-06 16:21 - 2014-01-09 16:02 - 00016694 _____ () C:\Users\Gideon\Downloads\FRST.txt
2014-02-06 16:20 - 2014-02-06 16:19 - 02082304 _____ (Farbar) C:\Users\Gideon\Downloads\FRST64 (1).exe
2014-02-06 16:20 - 2014-01-09 16:02 - 00000000 ____D () C:\FRST
2014-02-06 16:00 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru
2014-02-06 15:37 - 2013-12-25 20:26 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-02-06 13:18 - 2014-01-06 21:14 - 01565122 _____ () C:\Windows\WindowsUpdate.log
2014-02-06 13:10 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\NDF
2014-02-05 20:37 - 2013-12-25 20:26 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-02-05 15:33 - 2013-09-29 05:32 - 00753134 _____ () C:\Windows\system32\perfh007.dat
2014-02-05 15:33 - 2013-09-29 05:32 - 00155826 _____ () C:\Windows\system32\perfc007.dat
2014-02-05 15:33 - 2012-07-26 08:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-02-05 15:15 - 2013-12-25 20:13 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2058586743-3979093847-619797469-1001
2014-02-05 13:45 - 2014-02-05 13:34 - 163606685 _____ () C:\Users\Gideon\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe
2014-02-05 07:46 - 2014-02-05 07:44 - 00000000 ____D () C:\Users\Gideon\AppData\Local\Adobe
2014-02-04 13:41 - 2013-12-25 20:29 - 00002179 _____ () C:\Users\Public\Desktop\Google Chrome.lnk
2014-02-04 13:38 - 2014-02-04 13:37 - 02347384 _____ (ESET) C:\Users\Gideon\Downloads\esetsmartinstaller_enu (1).exe
2014-02-04 13:33 - 2014-02-04 13:33 - 00000000 ____D () C:\Program Files (x86)\ESET
2014-02-04 13:32 - 2014-02-04 13:32 - 02347384 _____ (ESET) C:\Users\Gideon\Downloads\esetsmartinstaller_enu.exe
2014-02-04 08:08 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\AUInstallAgent
2014-02-03 13:05 - 2014-02-03 13:05 - 00000000 ___RD () C:\Users\Gideon\Documents\Notes
2014-02-01 20:32 - 2013-12-26 00:56 - 00000000 ____D () C:\Users\Gideon\AppData\Roaming\.minecraft
2014-02-01 19:01 - 2013-08-02 16:58 - 00000000 ____D () C:\Program Files\Common Files\mcafee
2014-02-01 19:01 - 2012-07-26 09:12 - 00000000 ___HD () C:\Windows\ELAMBKUP
2014-02-01 19:00 - 2013-08-02 16:58 - 00000000 ____D () C:\Program Files (x86)\McAfee
2014-02-01 19:00 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM
2014-02-01 10:05 - 2014-01-05 22:36 - 05244132 _____ () C:\Users\Gideon\Downloads\generator.zip
2014-02-01 09:11 - 2014-02-01 09:11 - 00777528 _____ () C:\Windows\Minidump\020114-44429-01.dmp
2014-02-01 09:11 - 2014-01-05 12:30 - 00000000 ____D () C:\Windows\Minidump
2014-02-01 09:11 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-02-01 09:10 - 2014-02-01 09:10 - 339248834 _____ () C:\Windows\MEMORY.DMP
2014-02-01 09:10 - 2014-01-10 20:41 - 00011872 _____ () C:\Windows\PFRO.log
2014-01-30 22:10 - 2013-12-29 00:18 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-01-30 22:10 - 2013-12-29 00:18 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-01-26 14:03 - 2014-01-26 13:44 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable)
2014-01-26 14:03 - 2014-01-26 13:39 - 00000000 ____D () C:\Users\Gideon\Desktop\mbar
2014-01-26 13:44 - 2014-01-26 13:39 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys
2014-01-26 13:39 - 2014-01-26 13:36 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Gideon\Downloads\mbar-1.07.0.1009.exe
2014-01-25 20:19 - 2014-01-25 20:18 - 02181948 _____ () C:\Users\Gideon\Downloads\LineApp.xlsm
2014-01-24 19:14 - 2013-12-29 00:46 - 00000000 ____D () C:\Windows\CD09642E061D4844BA37ED1480916404.TMP
2014-01-24 19:11 - 2013-09-28 20:26 - 00000000 ____D () C:\ProgramData\Symantec
2014-01-24 19:01 - 2013-09-28 20:25 - 00000000 ____D () C:\Program Files (x86)\Norton Online Backup ARA
2014-01-24 18:51 - 2014-01-24 18:51 - 00000000 ____D () C:\ProgramData\boost_interprocess
2014-01-24 18:27 - 2014-01-24 18:27 - 00000000 ____D () C:\Windows\SysWOW64\Adobe
2014-01-23 22:42 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Gideon\AppData\Local\clear.fi
2014-01-23 21:58 - 2014-01-23 21:58 - 00000000 ____D () C:\Users\Gideon\PicStream
2014-01-23 21:58 - 2013-12-25 20:05 - 00000000 ____D () C:\Users\Gideon
2014-01-23 21:57 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Public\OEM
2014-01-23 21:57 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Gideon\Documents\clear.fi
2014-01-22 14:18 - 2014-01-22 14:18 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk
2014-01-22 14:18 - 2014-01-06 18:02 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware
2014-01-20 14:59 - 2014-01-20 14:59 - 00000000 ___HD () C:\Users\Gideon\Desktop\.updtmp
2014-01-19 16:11 - 2014-01-19 16:11 - 00000000 ____D () C:\Users\Gideon\AppData\Local\fabi.me
2014-01-19 16:09 - 2014-01-19 16:09 - 00094899 _____ () C:\Users\Gideon\Downloads\SpeedAutoClicker.zip
2014-01-19 13:48 - 2014-01-10 21:53 - 00004535 _____ () C:\Users\Gideon\Desktop\Neues Textdokument (2).txt
2014-01-18 19:17 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\rescache
2014-01-18 17:56 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\BBI
2014-01-18 17:54 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\WinStore
2014-01-15 17:50 - 2013-12-27 13:23 - 00000000 ____D () C:\Windows\system32\MRT
2014-01-15 17:47 - 2013-12-27 13:23 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-01-10 20:56 - 2014-01-10 20:55 - 00000178 _____ () C:\Users\Gideon\Desktop\Logfiles Combofix.zip.zip
2014-01-10 20:42 - 2014-01-05 12:30 - 00283416 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-01-10 20:35 - 2014-01-10 20:35 - 00131944 _____ () C:\ComboFix.txt
2014-01-10 20:35 - 2014-01-10 20:22 - 00000000 ____D () C:\Qoobox
2014-01-10 20:32 - 2014-01-10 20:21 - 00000000 ____D () C:\Windows\erdnt
2014-01-10 20:31 - 2012-07-26 06:26 - 00000215 _____ () C:\Windows\system.ini
2014-01-09 16:08 - 2014-01-09 16:06 - 00023994 _____ () C:\Users\Gideon\Downloads\Addition.txt
2014-01-09 16:00 - 2014-01-09 16:00 - 01931770 _____ (Farbar) C:\Users\Gideon\Downloads\FRST64.exe
2014-01-08 18:26 - 2014-01-08 18:25 - 00001211 _____ () C:\Users\Gideon\Downloads\SHK.bat
2014-01-07 20:46 - 2014-01-07 20:46 - 00001050 _____ () C:\Users\Gideon\Desktop\VirtualDJ Home FREE.lnk
2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\Users\Gideon\Documents\VirtualDJ
2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\Users\Gideon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ
2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\ProgramData\APN
2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\Program Files (x86)\VirtualDJ
2014-01-07 20:42 - 2014-01-07 20:38 - 39178560 _____ (Atomix Productions) C:\Users\Gideon\Downloads\install_virtualdj_home_v7.4.1.exe

Some content of TEMP:
====================
C:\Users\Gideon\AppData\Local\temp\SCC.dll


==================== Bamital & volsnap Check =================

C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit


LastRegBack: 2014-01-27 11:53

==================== End Of Log ============================
         
Danke schonmal.

LG Keckrem

 

Themen zu FRST Logfile Auswertung
administrator, auswertung, explorer.exe, iexplore.exe, launch, logfile auswertung, malwarebytes, minidump, mobogenie, mobogenie entfernen, services.exe, siteadvisor, spotify web helper, svchost.exe, widevinecdmadapter.dll, wildtangent games, win32/bundled.toolbar.ask.d, win32/bundled.toolbar.ask.e, win32/bundled.toolbar.google.d, win32/mobogenie.a, win32/nextlive.a, winlogon.exe




Ähnliche Themen: FRST Logfile Auswertung


  1. FRST Log Auswertung?
    Log-Analyse und Auswertung - 10.10.2015 (4)
  2. FRST Logfile auswertung?
    Log-Analyse und Auswertung - 03.08.2015 (1)
  3. WIN7 Laptop extrem langsam; FRST#1 logfile im Post
    Plagegeister aller Art und deren Bekämpfung - 12.04.2015 (16)
  4. FRST Auswertung, ist alles in Ordnung?
    Log-Analyse und Auswertung - 18.09.2014 (5)
  5. FRST Auswertung, alles Ok?
    Log-Analyse und Auswertung - 24.08.2014 (11)
  6. FRST-Auswertung: Langsames Arbeiten/Surfen mit Notebook
    Plagegeister aller Art und deren Bekämpfung - 29.06.2014 (42)
  7. FRST Log - Auswertung (ohne Anfangsverdacht)
    Log-Analyse und Auswertung - 27.05.2014 (2)
  8. Windows 7 FRST Auswertung
    Log-Analyse und Auswertung - 16.04.2014 (9)
  9. GMER, FRST, ADWCleaner Auswertung. Festplatte defekt. Neustart
    Log-Analyse und Auswertung - 19.11.2013 (7)
  10. FRST Logfile analysieren, nach BKA Trojaner, weißer Bildschirm etc
    Log-Analyse und Auswertung - 03.11.2013 (3)
  11. KOBIK-Trojaner eingefangen.. FRST-Logfile bereits vorhanden
    Plagegeister aller Art und deren Bekämpfung - 03.10.2013 (12)
  12. FRST.txt und Addition.txt auswertung
    Log-Analyse und Auswertung - 30.09.2013 (62)
  13. Auswertung der FRST Logdatei :)
    Log-Analyse und Auswertung - 18.09.2013 (7)
  14. Windows XP - Nach System-Start weißer Screen - FRST Logfile
    Log-Analyse und Auswertung - 13.08.2013 (13)
  15. Interpol Trojaner - FRST Logfile includiert
    Plagegeister aller Art und deren Bekämpfung - 13.08.2013 (13)
  16. GVU Trojaner Logfile bereits mit frst erstellt
    Log-Analyse und Auswertung - 30.07.2013 (1)
  17. Weißer Bildschirm win7 Frst. log gemacht bitte um Auswertung
    Plagegeister aller Art und deren Bekämpfung - 18.07.2013 (12)

Zum Thema FRST Logfile Auswertung - Hallo, habe einen Kontrollscan mit FRST gemacht und wollte nachfragen, ob ihr etwas (verseuchtes) erkennen könnt. Ich konnte beim leienhaften drüberschauen nichts schlimmes erkennen. Code: Alles auswählen Aufklappen ATTFilter Scan - FRST Logfile Auswertung...
Archiv
Du betrachtest: FRST Logfile Auswertung auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.