![]() |
|
Log-Analyse und Auswertung: FRST Logfile AuswertungWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() ![]() | ![]() FRST Logfile Auswertung Hallo, habe einen Kontrollscan mit FRST gemacht und wollte nachfragen, ob ihr etwas (verseuchtes) erkennen könnt. Ich konnte beim leienhaften drüberschauen nichts schlimmes erkennen. Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 05-02-2014 Ran by Gideon (administrator) on HOME on 06-02-2014 16:20:40 Running from C:\Users\Gideon\Downloads Windows 8 (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal The only official download link for FRST: Download link for 32-Bit version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/81/ Download link for 64-Bit Version: hxxp://www.bleepingcomputer.com/download/farbar-recovery-scan-tool/dl/82/ Download link from any site other than Bleeping Computer is unpermitted or outdated. See tutorial for FRST: hxxp://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/ ==================== Processes (Whitelisted) ================= (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Qualcomm Atheros Commnucations) C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\AdminService.exe (Acer Incorporated) C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDService.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe (McAfee, Inc.) C:\Program Files\mcafee\AppStats\MfeASUM.exe (McAfee, Inc.) C:\Windows\System32\mfevtps.exe (McAfee, Inc.) C:\Program Files\mcafee\msc\McAPExe.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDTouch.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler.exe (ELAN Microelectronics Corp.) C:\Program Files\Elantech\ETDCtrlHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Update\1.3.22.3\GoogleCrashHandler64.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMEvent.exe (Dolby Laboratories Inc.) C:\Dolby PCEE4\pcee4.exe (Acer Incorporate) C:\Program Files\Acer\Acer Launch Manager\LMTray.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe () C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerTray.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe (Acer Incorporated) C:\Program Files\Acer\Acer Power Management\ePowerEvent.exe (Nero AG) C:\Program Files (x86)\Nero\Update\NASvc.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\systemcore\mfefire.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\AMCore\mcshield.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\McUICnt.exe (McAfee, Inc.) C:\Program Files\Common Files\mcafee\platform\mcsvchost\McSvHost.exe (McAfee, Inc.) C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Farbar) C:\Users\Gideon\Downloads\FRST64 (1).exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [ETDCtrl] - C:\Program Files\Elantech\ETDCtrl.exe [2890640 2013-04-22] (ELAN Microelectronics Corp.) HKLM\...\Run: [RtHDVCpl] - C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [13519432 2013-04-09] (Realtek Semiconductor) HKLM\...\Run: [RtHDVBg_Dolby] - C:\Program Files\Realtek\Audio\HDA\RAVBg64.exe [1278024 2013-03-08] (Realtek Semiconductor) HKLM-x32\...\Run: [mcpltui_exe] - C:\Program Files\McAfee.com\Agent\mcagent.exe [537512 2013-09-24] (McAfee, Inc.) HKLM-x32\...\Run: [StartCCC] - C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [642816 2013-06-03] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM\...\Policies\Explorer: [NoControlPanel] 0 HKU\S-1-5-21-2058586743-3979093847-619797469-1001\...\Run: [Spotify Web Helper] - C:\Program Files (x86)\Spotify\Data\SpotifyWebHelper.exe [1193176 2013-09-28] () ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe SearchScopes: HKLM - DefaultScope {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS SearchScopes: HKLM - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKLM - {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS SearchScopes: HKLM-x32 - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKLM-x32 - {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = hxxp://www.bing.com/search?q={searchTerms}&form=IE10TR&src=IE10TR&pc=MAARJS SearchScopes: HKCU - DefaultScope {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = SearchScopes: HKCU - {AA9A4890-4262-4441-8977-E2FFCBFB706C} URL = hxxp://de.yhs4.search.yahoo.com/yhs/search?hspart=acer&hsimp=yhs-acer_001&p={searchTerms} SearchScopes: HKCU - {ABC09333-689F-47B3-8CC3-1DFFC3C27B88} URL = BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO: CIESpeechBHO Class - {8D10F6C4-0E01-4BD4-8601-11AC1FDF8126} - C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\IEPlugIn.dll (Qualcomm Atheros Commnucations) BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Toolbar: HKLM - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Toolbar: HKLM-x32 - McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.) Handler-x32: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Handler-x32: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - C:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.) Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.) Filter-x32: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - C:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.) Tcpip\Parameters: [DhcpNameServer] 192.168.2.1 Chrome: ======= CHR Plugin: (Widevine Content Decryption Module) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\WidevineCDM\1.4.1.377\_platform_specific\win_x86\widevinecdmadapter.dll () CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.107\pdf.dll () CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.22.3\npGoogleUpdate3.dll (Google Inc.) CHR Plugin: (Java Deployment Toolkit 7.0.450.18) - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) CHR Plugin: (Java(TM) Platform SE 7 U45) - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) CHR Plugin: (McAfee SiteAdvisor) - C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.) CHR Plugin: (WildTangent Games App V2 Presence Detector) - C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll () CHR Plugin: (Shockwave for Director) - C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.) CHR Plugin: (McAfee SecurityCenter) - c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL () CHR Extension: (Google Docs) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-12-25] CHR Extension: (Google Drive) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-12-25] CHR Extension: (YouTube) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-12-25] CHR Extension: (Google-Suche) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-12-25] CHR Extension: (SiteAdvisor) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\fheoggkfdfchfphceeifdbepaooicaho [2013-12-29] CHR Extension: (AdBlock) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom [2013-12-25] CHR Extension: (Google Wallet) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-12-25] CHR Extension: (Google Mail) - C:\Users\Gideon\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-12-25] CHR HKLM-x32\...\Chrome\Extension: [fheoggkfdfchfphceeifdbepaooicaho] - C:\Program Files (x86)\McAfee\SiteAdvisor\McChPlg.crx [2013-12-28] ==================== Services (Whitelisted) ================= S2 0115761391277686mcinstcleanup; C:\Windows\TEMP\011576~1.EXE [834664 2013-07-30] (McAfee, Inc.) R2 AtherosSvc; C:\Program Files (x86)\Qualcomm Atheros\Bluetooth Suite\adminservice.exe [227968 2013-02-28] (Qualcomm Atheros Commnucations) R2 CCDMonitorService; C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe [2615368 2013-02-27] (Acer Incorporated) R3 ePowerSvc; C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe [660040 2013-01-18] (Acer Incorporated) R2 ETDService; C:\Program Files\Elantech\ETDService.exe [100752 2013-04-22] (ELAN Microelectronics Corp.) R2 HomeNetSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 LMSvc; C:\Program Files\Acer\Acer Launch Manager\LMSvc.exe [431656 2013-04-26] (Acer Incorporate) R2 McAfee SiteAdvisor Service; C:\Program Files (x86)\McAfee\SiteAdvisor\mcsacore.exe [121616 2013-10-02] (McAfee, Inc.) R2 McAPExe; C:\Program Files\McAfee\MSC\McAPExe.exe [178048 2013-11-28] (McAfee, Inc.) S3 McAWFwk; C:\Program Files\Common Files\mcafee\actwiz\McAWFwk.exe [334760 2012-12-21] (McAfee, Inc.) R2 McMPFSvc; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McNaiAnn; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S3 McODS; C:\Program Files\mcafee\VirusScan\mcods.exe [602944 2013-08-02] (McAfee, Inc.) S4 McOobeSv2; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 mcpltsvc; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 McProxy; C:\Program Files\Common Files\mcafee\platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) R2 MfeASUM; C:\Program Files\McAfee\AppStats\MfeASUM.exe [335216 2013-12-26] (McAfee, Inc.) R2 mfecore; C:\Program Files\Common Files\McAfee\AMCore\mcshield.exe [1025232 2013-12-11] (McAfee, Inc.) R2 mfefire; C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe [219272 2013-12-05] (McAfee, Inc.) R2 mfevtp; C:\Windows\system32\mfevtps.exe [184800 2013-12-05] (McAfee, Inc.) R2 MSK80Service; C:\Program Files\Common Files\McAfee\Platform\McSvcHost\McSvHost.exe [328928 2013-07-30] (McAfee, Inc.) S3 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) S3 NOBU; No ImagePath ==================== Drivers (Whitelisted) ==================== R0 amdkmpfd; C:\Windows\System32\drivers\amdkmpfd.sys [37472 2013-02-14] (Advanced Micro Devices, Inc.) R2 APXACC; C:\Windows\system32\DRIVERS\appexDrv.sys [219360 2013-04-18] (AppEx Networks Corporation) R3 AthrSdSrv; C:\Windows\system32\DRIVERS\athrsd.sys [43520 2013-03-12] (Qualcomm Atheros, Inc.) R3 AtiHDAudioService; C:\Windows\system32\drivers\AtihdW86.sys [98744 2013-04-23] (Advanced Micro Devices) S3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation) S3 BTATH_LWFLT; C:\Windows\system32\DRIVERS\btath_lwflt.sys [77464 2013-02-28] (Qualcomm Atheros) S3 BthLEEnum; C:\Windows\system32\DRIVERS\BthLEEnum.sys [202752 2012-07-26] (Microsoft Corporation) R3 cfwids; C:\Windows\System32\drivers\cfwids.sys [70112 2013-12-05] (McAfee, Inc.) S3 HipShieldK; C:\Windows\System32\drivers\HipShieldK.sys [197704 2013-09-23] (McAfee, Inc.) R3 LMDriver; C:\Windows\System32\drivers\LMDriver.sys [21360 2013-01-10] (Acer Incorporated) R2 mfeapfk; C:\Windows\System32\drivers\mfeapfk.sys [179792 2013-12-05] (McAfee, Inc.) R1 MfeASKM; C:\Program Files\McAfee\AppStats\MfeASKM.sys [31408 2013-12-26] (McAfee, Inc.) R2 mfeavfk; C:\Windows\System32\drivers\mfeavfk.sys [311120 2013-12-05] (McAfee, Inc.) U3 mfeavfk01; No ImagePath S0 mfeelamk; C:\Windows\System32\drivers\mfeelamk.sys [69344 2013-12-05] (McAfee, Inc.) R3 mfefirek; C:\Windows\System32\drivers\mfefirek.sys [519576 2013-12-05] (McAfee, Inc.) R2 mfehidk; C:\Windows\System32\drivers\mfehidk.sys [782616 2013-12-05] (McAfee, Inc.) U3 mfehidk01; No ImagePath R3 mfencbdc; C:\Windows\system32\DRIVERS\mfencbdc.sys [411944 2013-11-26] (McAfee, Inc.) U3 mfencbdc01; No ImagePath S3 mfencrk; C:\Windows\system32\DRIVERS\mfencrk.sys [96112 2013-11-26] (McAfee, Inc.) R2 mfewfpk; C:\Windows\System32\drivers\mfewfpk.sys [343696 2013-12-05] (McAfee, Inc.) S3 QRDCIO; C:\Windows\System32\drivers\QRDCIO.sys [9728 2009-10-20] (QUANTA) R3 RadioShim; C:\Windows\System32\drivers\RadioShim.sys [15704 2013-01-10] (Acer Incorporated) U5 AppMgmt; C:\Windows\system32\svchost.exe [29696 2013-04-21] (Microsoft Corporation) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-02-06 16:19 - 2014-02-06 16:20 - 02082304 _____ (Farbar) C:\Users\Gideon\Downloads\FRST64 (1).exe 2014-02-05 13:34 - 2014-02-05 13:45 - 163606685 _____ () C:\Users\Gideon\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe 2014-02-05 07:44 - 2014-02-05 07:46 - 00000000 ____D () C:\Users\Gideon\AppData\Local\Adobe 2014-02-04 13:37 - 2014-02-04 13:38 - 02347384 _____ (ESET) C:\Users\Gideon\Downloads\esetsmartinstaller_enu (1).exe 2014-02-04 13:33 - 2014-02-04 13:33 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-02-04 13:32 - 2014-02-04 13:32 - 02347384 _____ (ESET) C:\Users\Gideon\Downloads\esetsmartinstaller_enu.exe 2014-02-03 13:05 - 2014-02-03 13:05 - 00000000 ___RD () C:\Users\Gideon\Documents\Notes 2014-02-01 19:07 - 2013-09-23 13:49 - 00197704 _____ (McAfee, Inc.) C:\Windows\system32\Drivers\HipShieldK.sys 2014-02-01 09:11 - 2014-02-01 09:11 - 00777528 _____ () C:\Windows\Minidump\020114-44429-01.dmp 2014-02-01 09:10 - 2014-02-01 09:10 - 339248834 _____ () C:\Windows\MEMORY.DMP 2014-01-26 13:44 - 2014-01-26 14:03 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-01-26 13:39 - 2014-01-26 14:03 - 00000000 ____D () C:\Users\Gideon\Desktop\mbar 2014-01-26 13:39 - 2014-01-26 13:44 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-01-26 13:36 - 2014-01-26 13:39 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Gideon\Downloads\mbar-1.07.0.1009.exe 2014-01-25 20:18 - 2014-01-25 20:19 - 02181948 _____ () C:\Users\Gideon\Downloads\LineApp.xlsm 2014-01-24 18:51 - 2014-01-24 18:51 - 00000000 ____D () C:\ProgramData\boost_interprocess 2014-01-24 18:27 - 2014-01-24 18:27 - 00000000 ____D () C:\Windows\SysWOW64\Adobe 2014-01-23 21:58 - 2014-01-23 21:58 - 00000000 ____D () C:\Users\Gideon\PicStream 2014-01-23 21:57 - 2014-01-23 22:42 - 00000000 ____D () C:\Users\Gideon\AppData\Local\clear.fi 2014-01-23 21:57 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Public\OEM 2014-01-23 21:57 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Gideon\Documents\clear.fi 2014-01-22 14:18 - 2014-01-22 14:18 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-20 14:59 - 2014-01-20 14:59 - 00000000 ___HD () C:\Users\Gideon\Desktop\.updtmp 2014-01-19 16:11 - 2014-01-19 16:11 - 00000000 ____D () C:\Users\Gideon\AppData\Local\fabi.me 2014-01-19 16:10 - 2013-09-24 11:14 - 00179200 _____ (fabi.me) C:\Users\Gideon\Desktop\SpeedAutoClicker.exe 2014-01-19 16:09 - 2014-01-19 16:09 - 00094899 _____ () C:\Users\Gideon\Downloads\SpeedAutoClicker.zip 2014-01-15 16:56 - 2013-12-07 07:37 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2014-01-15 16:56 - 2013-12-07 07:37 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-01-15 16:56 - 2013-12-07 06:15 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2014-01-15 16:56 - 2013-12-07 06:15 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-01-15 16:56 - 2013-10-31 06:56 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll 2014-01-15 16:56 - 2013-10-31 06:56 - 00758784 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll 2014-01-15 16:56 - 2013-10-31 05:01 - 00550400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll 2014-01-15 16:56 - 2013-10-31 04:42 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys 2014-01-15 16:56 - 2013-10-28 06:50 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2014-01-15 16:56 - 2013-10-28 05:05 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2014-01-15 16:56 - 2013-10-13 21:49 - 00100696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys 2014-01-15 16:56 - 2013-08-27 06:21 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2014-01-15 16:56 - 2013-08-27 06:19 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2014-01-15 16:56 - 2013-08-26 23:29 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2014-01-15 16:56 - 2013-08-26 23:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2014-01-10 21:53 - 2014-01-19 13:48 - 00004535 _____ () C:\Users\Gideon\Desktop\Neues Textdokument (2).txt 2014-01-10 20:55 - 2014-01-10 20:56 - 00000178 _____ () C:\Users\Gideon\Desktop\Logfiles Combofix.zip.zip 2014-01-10 20:41 - 2014-02-01 09:10 - 00011872 _____ () C:\Windows\PFRO.log 2014-01-10 20:35 - 2014-01-10 20:35 - 00131944 _____ () C:\ComboFix.txt 2014-01-10 20:22 - 2014-01-10 20:35 - 00000000 ____D () C:\Qoobox 2014-01-10 20:22 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe 2014-01-10 20:22 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe 2014-01-10 20:22 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe 2014-01-10 20:22 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe 2014-01-10 20:22 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe 2014-01-10 20:22 - 2000-08-31 01:00 - 00212480 _____ (SteelWerX) C:\Windows\SWXCACLS.exe 2014-01-10 20:22 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe 2014-01-10 20:22 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe 2014-01-10 20:22 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe 2014-01-10 20:21 - 2014-01-10 20:32 - 00000000 ____D () C:\Windows\erdnt 2014-01-09 16:06 - 2014-01-09 16:08 - 00023994 _____ () C:\Users\Gideon\Downloads\Addition.txt 2014-01-09 16:02 - 2014-02-06 16:20 - 00016694 _____ () C:\Users\Gideon\Downloads\FRST.txt 2014-01-09 16:02 - 2014-02-06 16:20 - 00000000 ____D () C:\FRST 2014-01-09 16:00 - 2014-01-09 16:00 - 01931770 _____ (Farbar) C:\Users\Gideon\Downloads\FRST64.exe 2014-01-08 18:25 - 2014-01-08 18:26 - 00001211 _____ () C:\Users\Gideon\Downloads\SHK.bat 2014-01-07 20:46 - 2014-01-07 20:46 - 00001050 _____ () C:\Users\Gideon\Desktop\VirtualDJ Home FREE.lnk 2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\Users\Gideon\Documents\VirtualDJ 2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\Users\Gideon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ 2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\ProgramData\APN 2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\Program Files (x86)\VirtualDJ 2014-01-07 20:45 - 2013-06-06 21:41 - 00489392 _____ (Ask Partner Network) C:\Users\Gideon\Documents\APNSetup.exe 2014-01-07 20:38 - 2014-01-07 20:42 - 39178560 _____ (Atomix Productions) C:\Users\Gideon\Downloads\install_virtualdj_home_v7.4.1.exe ==================== One Month Modified Files and Folders ======= 2014-02-06 16:21 - 2014-01-09 16:02 - 00016694 _____ () C:\Users\Gideon\Downloads\FRST.txt 2014-02-06 16:20 - 2014-02-06 16:19 - 02082304 _____ (Farbar) C:\Users\Gideon\Downloads\FRST64 (1).exe 2014-02-06 16:20 - 2014-01-09 16:02 - 00000000 ____D () C:\FRST 2014-02-06 16:00 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\sru 2014-02-06 15:37 - 2013-12-25 20:26 - 00001120 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-02-06 13:18 - 2014-01-06 21:14 - 01565122 _____ () C:\Windows\WindowsUpdate.log 2014-02-06 13:10 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\system32\NDF 2014-02-05 20:37 - 2013-12-25 20:26 - 00001116 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-02-05 15:33 - 2013-09-29 05:32 - 00753134 _____ () C:\Windows\system32\perfh007.dat 2014-02-05 15:33 - 2013-09-29 05:32 - 00155826 _____ () C:\Windows\system32\perfc007.dat 2014-02-05 15:33 - 2012-07-26 08:28 - 01745416 _____ () C:\Windows\system32\PerfStringBackup.INI 2014-02-05 15:15 - 2013-12-25 20:13 - 00003598 _____ () C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-2058586743-3979093847-619797469-1001 2014-02-05 13:45 - 2014-02-05 13:34 - 163606685 _____ () C:\Users\Gideon\Downloads\Apache_OpenOffice_4.0.1_Win_x86_install_de.exe 2014-02-05 07:46 - 2014-02-05 07:44 - 00000000 ____D () C:\Users\Gideon\AppData\Local\Adobe 2014-02-04 13:41 - 2013-12-25 20:29 - 00002179 _____ () C:\Users\Public\Desktop\Google Chrome.lnk 2014-02-04 13:38 - 2014-02-04 13:37 - 02347384 _____ (ESET) C:\Users\Gideon\Downloads\esetsmartinstaller_enu (1).exe 2014-02-04 13:33 - 2014-02-04 13:33 - 00000000 ____D () C:\Program Files (x86)\ESET 2014-02-04 13:32 - 2014-02-04 13:32 - 02347384 _____ (ESET) C:\Users\Gideon\Downloads\esetsmartinstaller_enu.exe 2014-02-04 08:08 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\AUInstallAgent 2014-02-03 13:05 - 2014-02-03 13:05 - 00000000 ___RD () C:\Users\Gideon\Documents\Notes 2014-02-01 20:32 - 2013-12-26 00:56 - 00000000 ____D () C:\Users\Gideon\AppData\Roaming\.minecraft 2014-02-01 19:01 - 2013-08-02 16:58 - 00000000 ____D () C:\Program Files\Common Files\mcafee 2014-02-01 19:01 - 2012-07-26 09:12 - 00000000 ___HD () C:\Windows\ELAMBKUP 2014-02-01 19:00 - 2013-08-02 16:58 - 00000000 ____D () C:\Program Files (x86)\McAfee 2014-02-01 19:00 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\ELAM 2014-02-01 10:05 - 2014-01-05 22:36 - 05244132 _____ () C:\Users\Gideon\Downloads\generator.zip 2014-02-01 09:11 - 2014-02-01 09:11 - 00777528 _____ () C:\Windows\Minidump\020114-44429-01.dmp 2014-02-01 09:11 - 2014-01-05 12:30 - 00000000 ____D () C:\Windows\Minidump 2014-02-01 09:11 - 2012-07-26 08:22 - 00000006 ____H () C:\Windows\Tasks\SA.DAT 2014-02-01 09:10 - 2014-02-01 09:10 - 339248834 _____ () C:\Windows\MEMORY.DMP 2014-02-01 09:10 - 2014-01-10 20:41 - 00011872 _____ () C:\Windows\PFRO.log 2014-01-30 22:10 - 2013-12-29 00:18 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-01-30 22:10 - 2013-12-29 00:18 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-26 14:03 - 2014-01-26 13:44 - 00000000 ____D () C:\ProgramData\Malwarebytes' Anti-Malware (portable) 2014-01-26 14:03 - 2014-01-26 13:39 - 00000000 ____D () C:\Users\Gideon\Desktop\mbar 2014-01-26 13:44 - 2014-01-26 13:39 - 00091352 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbamchameleon.sys 2014-01-26 13:39 - 2014-01-26 13:36 - 12589848 _____ (Malwarebytes Corp.) C:\Users\Gideon\Downloads\mbar-1.07.0.1009.exe 2014-01-25 20:19 - 2014-01-25 20:18 - 02181948 _____ () C:\Users\Gideon\Downloads\LineApp.xlsm 2014-01-24 19:14 - 2013-12-29 00:46 - 00000000 ____D () C:\Windows\CD09642E061D4844BA37ED1480916404.TMP 2014-01-24 19:11 - 2013-09-28 20:26 - 00000000 ____D () C:\ProgramData\Symantec 2014-01-24 19:01 - 2013-09-28 20:25 - 00000000 ____D () C:\Program Files (x86)\Norton Online Backup ARA 2014-01-24 18:51 - 2014-01-24 18:51 - 00000000 ____D () C:\ProgramData\boost_interprocess 2014-01-24 18:27 - 2014-01-24 18:27 - 00000000 ____D () C:\Windows\SysWOW64\Adobe 2014-01-23 22:42 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Gideon\AppData\Local\clear.fi 2014-01-23 21:58 - 2014-01-23 21:58 - 00000000 ____D () C:\Users\Gideon\PicStream 2014-01-23 21:58 - 2013-12-25 20:05 - 00000000 ____D () C:\Users\Gideon 2014-01-23 21:57 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Public\OEM 2014-01-23 21:57 - 2014-01-23 21:57 - 00000000 ____D () C:\Users\Gideon\Documents\clear.fi 2014-01-22 14:18 - 2014-01-22 14:18 - 00001113 _____ () C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-22 14:18 - 2014-01-06 18:02 - 00000000 ____D () C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-20 14:59 - 2014-01-20 14:59 - 00000000 ___HD () C:\Users\Gideon\Desktop\.updtmp 2014-01-19 16:11 - 2014-01-19 16:11 - 00000000 ____D () C:\Users\Gideon\AppData\Local\fabi.me 2014-01-19 16:09 - 2014-01-19 16:09 - 00094899 _____ () C:\Users\Gideon\Downloads\SpeedAutoClicker.zip 2014-01-19 13:48 - 2014-01-10 21:53 - 00004535 _____ () C:\Users\Gideon\Desktop\Neues Textdokument (2).txt 2014-01-18 19:17 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\rescache 2014-01-18 17:56 - 2012-07-26 06:26 - 00262144 ___SH () C:\Windows\system32\config\BBI 2014-01-18 17:54 - 2012-07-26 09:12 - 00000000 ____D () C:\Windows\WinStore 2014-01-15 17:50 - 2013-12-27 13:23 - 00000000 ____D () C:\Windows\system32\MRT 2014-01-15 17:47 - 2013-12-27 13:23 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-10 20:56 - 2014-01-10 20:55 - 00000178 _____ () C:\Users\Gideon\Desktop\Logfiles Combofix.zip.zip 2014-01-10 20:42 - 2014-01-05 12:30 - 00283416 _____ () C:\Windows\system32\FNTCACHE.DAT 2014-01-10 20:35 - 2014-01-10 20:35 - 00131944 _____ () C:\ComboFix.txt 2014-01-10 20:35 - 2014-01-10 20:22 - 00000000 ____D () C:\Qoobox 2014-01-10 20:32 - 2014-01-10 20:21 - 00000000 ____D () C:\Windows\erdnt 2014-01-10 20:31 - 2012-07-26 06:26 - 00000215 _____ () C:\Windows\system.ini 2014-01-09 16:08 - 2014-01-09 16:06 - 00023994 _____ () C:\Users\Gideon\Downloads\Addition.txt 2014-01-09 16:00 - 2014-01-09 16:00 - 01931770 _____ (Farbar) C:\Users\Gideon\Downloads\FRST64.exe 2014-01-08 18:26 - 2014-01-08 18:25 - 00001211 _____ () C:\Users\Gideon\Downloads\SHK.bat 2014-01-07 20:46 - 2014-01-07 20:46 - 00001050 _____ () C:\Users\Gideon\Desktop\VirtualDJ Home FREE.lnk 2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\Users\Gideon\Documents\VirtualDJ 2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\Users\Gideon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\VirtualDJ 2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\ProgramData\APN 2014-01-07 20:46 - 2014-01-07 20:46 - 00000000 ____D () C:\Program Files (x86)\VirtualDJ 2014-01-07 20:42 - 2014-01-07 20:38 - 39178560 _____ (Atomix Productions) C:\Users\Gideon\Downloads\install_virtualdj_home_v7.4.1.exe Some content of TEMP: ==================== C:\Users\Gideon\AppData\Local\temp\SCC.dll ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-27 11:53 ==================== End Of Log ============================ LG Keckrem |