![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: infizierten Rechner im Netz gehabt. Verdacht auf Malware auf eigenen Laptop.Könnt ihr mir weiterhelfen?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
| | #15 | |
![]() ![]() | infizierten Rechner im Netz gehabt. Verdacht auf Malware auf eigenen Laptop.Könnt ihr mir weiterhelfen? Alles klar. FRST.txt FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 04-03-2014
Ran by Ursula (administrator) on URSULA-PC on 04-03-2014 18:08:04
Running from C:\Users\Ursula\Desktop
Windows 7 Home Premium Service Pack 1 (X64) OS Language: German Standard
Internet Explorer Version 11
Boot Mode: Normal
The only official download link for FRST:
Download link for 32-Bit version: Downloading Farbar Recovery Scan Tool
Download link for 64-Bit Version: Downloading Farbar Recovery Scan Tool
Download link from any site other than Bleeping Computer is unpermitted or outdated.
See tutorial for FRST: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forums
==================== Processes (Whitelisted) =================
(AMD) C:\Windows\system32\atiesrxx.exe
(AMD) C:\Windows\system32\atieclxx.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastUI.exe
==================== Registry (Whitelisted) ==================
HKLM-x32\...\Run: [AvastUI.exe] - C:\Program Files\AVAST Software\Avast\AvastUI.exe [3767096 2014-03-01] (AVAST Software)
==================== Internet (Whitelisted) ====================
HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = Sign In
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0x7722CEA4CCD4CE01
HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
BHO: avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO-x32: avast! Online Security - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
Toolbar: HKLM-x32 - avast! Online Security - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\Ursula\AppData\Roaming\Mozilla\Firefox\Profiles\s3akhn5s.default
FF Plugin: @adobe.com/FlashPlayer - C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll ()
FF Plugin-x32: @adobe.com/FlashPlayer - C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF Plugin-x32: @google.com/npPicasa3,version=3.0.0 - C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.)
FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\amazondotcom-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\eBay-de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\leo_ende_de.xml
FF SearchPlugin: C:\Program Files (x86)\mozilla firefox\browser\searchplugins\yahoo-de.xml
FF Extension: NoScript - C:\Users\Ursula\AppData\Roaming\Mozilla\Firefox\Profiles\s3akhn5s.default\Extensions\{73a6fe31-595d-460b-a920-fcc0f8843232}.xpi [2014-01-03]
FF Extension: Adblock Plus - C:\Users\Ursula\AppData\Roaming\Mozilla\Firefox\Profiles\s3akhn5s.default\Extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi [2014-01-19]
FF Extension: BetterPrivacy - C:\Users\Ursula\AppData\Roaming\Mozilla\Firefox\Profiles\s3akhn5s.default\Extensions\{d40f5e7b-d2cf-4856-b441-cc613eeffbe3}.xpi [2014-01-03]
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2013-11-23]
==================== Services (Whitelisted) =================
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-03-01] (AVAST Software)
==================== Drivers (Whitelisted) ====================
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [78648 2014-03-01] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [92544 2013-11-23] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2013-11-23] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1038072 2014-03-01] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [421704 2014-03-01] (AVAST Software)
R3 aswStm; C:\Windows\system32\drivers\aswStm.sys [80184 2014-03-01] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [207904 2014-01-02] ()
S3 mbamchameleon; C:\Windows\system32\drivers\mbamchameleon.sys [91352 2013-11-05] (Malwarebytes Corporation)
R3 MTsensor; C:\Windows\System32\DRIVERS\ATK64AMD.sys [13680 2007-08-09] ()
S3 Serial; C:\Windows\system32\DRIVERS\serial.sys [94208 2009-07-14] (Brother Industries Ltd.)
U5 AppMgmt; C:\Windows\system32\svchost.exe [27136 2009-07-14] (Microsoft Corporation)
==================== NetSvcs (Whitelisted) ===================
==================== One Month Created Files and Folders ========
2014-03-04 18:08 - 2014-03-04 18:08 - 00005880 _____ () C:\Users\Ursula\Desktop\FRST.txt
2014-03-04 18:07 - 2014-03-04 18:07 - 00000000 ____D () C:\Users\Ursula\Desktop\FRST-OlderVersion
2014-03-02 20:47 - 2014-03-02 20:48 - 00000000 ____D () C:\Users\Ursula\Desktop\Lisa
2014-03-02 20:45 - 2014-03-02 20:46 - 00000000 ____D () C:\Users\Ursula\Desktop\wg. Bank
2014-03-01 16:15 - 2014-03-01 16:16 - 00027940 _____ () C:\Users\Ursula\Downloads\FRST (2).txt
2014-03-01 16:14 - 2014-03-01 16:14 - 00000000 ____D () C:\Users\Ursula\Downloads\FRST-OlderVersion
2014-03-01 16:13 - 2014-03-01 16:13 - 00000863 _____ () C:\Users\Ursula\Downloads\w.txt
2014-03-01 15:53 - 2014-03-01 15:53 - 00987425 _____ () C:\Users\Ursula\Downloads\SecurityCheck.exe
2014-03-01 15:47 - 2014-03-01 15:47 - 00000826 _____ () C:\Windows\PFRO.log
2014-03-01 15:34 - 2014-03-01 15:34 - 00001966 _____ () C:\Users\Ursula\avast! Free Antivirus.lnk
2014-03-01 14:20 - 2014-03-01 14:20 - 02347384 _____ (ESET) C:\Users\Ursula\Downloads\esetsmartinstaller_enu.exe
2014-02-24 22:27 - 2014-02-24 22:27 - 00001237 _____ () C:\Users\Ursula\Ashampoo Home Designer.lnk
2014-02-24 22:27 - 2014-02-24 22:27 - 00000554 _____ () C:\Windows\KB893803v2.log
2014-02-24 22:26 - 2014-02-24 22:26 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-02-24 22:26 - 2008-05-07 16:03 - 00290816 _____ (Cygnicon GmbH) C:\Windows\SysWOW64\cyviewer.ocx
2014-02-24 22:15 - 2014-02-24 22:24 - 173500560 _____ (Creative Amadeo GmbH ) C:\Users\Ursula\Downloads\ashampoo_home_designer_1.0.0_7591.exe
2014-02-18 16:35 - 2014-02-18 16:36 - 00024828 _____ () C:\Users\Ursula\Downloads\FRST.txt
2014-02-18 16:34 - 2014-03-04 18:07 - 02156544 _____ (Farbar) C:\Users\Ursula\Desktop\FRST64.exe
2014-02-18 16:30 - 2014-02-18 16:30 - 00000758 _____ () C:\Users\Ursula\Downloads\JRT.txt
2014-02-18 16:21 - 2014-02-18 16:21 - 00000000 ____D () C:\Windows\ERUNT
2014-02-18 16:17 - 2014-02-18 16:17 - 01037530 _____ (Thisisu) C:\Users\Ursula\Downloads\JRT.exe
2014-02-18 15:59 - 2014-02-18 16:13 - 00000000 ____D () C:\AdwCleaner
2014-02-18 15:58 - 2014-02-18 15:58 - 01241834 _____ () C:\Users\Ursula\Downloads\adwcleaner.exe
2014-02-18 14:54 - 2014-03-04 17:17 - 00003463 _____ () C:\Windows\setupact.log
2014-02-18 14:54 - 2014-02-18 14:54 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-16 14:18 - 2014-02-18 14:42 - 01592864 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-16 14:05 - 2013-12-21 10:53 - 00548864 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-02-16 14:05 - 2013-12-21 09:56 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-02-16 14:04 - 2014-02-06 13:16 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-16 14:04 - 2014-02-06 12:30 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-16 14:04 - 2014-02-06 12:30 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-16 14:04 - 2014-02-06 12:12 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-16 14:04 - 2014-02-06 12:07 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-16 14:04 - 2014-02-06 12:06 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-16 14:04 - 2014-02-06 11:57 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-16 14:04 - 2014-02-06 11:56 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-16 14:04 - 2014-02-06 11:52 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-16 14:04 - 2014-02-06 11:49 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-16 14:04 - 2014-02-06 11:48 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-16 14:04 - 2014-02-06 11:48 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-16 14:04 - 2014-02-06 11:32 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-16 14:04 - 2014-02-06 11:20 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-16 14:04 - 2014-02-06 11:17 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-16 14:04 - 2014-02-06 11:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-16 14:04 - 2014-02-06 11:00 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-16 14:04 - 2014-02-06 10:57 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-16 14:04 - 2014-02-06 10:57 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-16 14:04 - 2014-02-06 10:52 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-16 14:04 - 2014-02-06 10:52 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-16 14:04 - 2014-02-06 10:50 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-16 14:04 - 2014-02-06 10:49 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-16 14:04 - 2014-02-06 10:47 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-16 14:04 - 2014-02-06 10:46 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-16 14:04 - 2014-02-06 10:25 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-16 14:04 - 2014-02-06 10:24 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-16 14:04 - 2014-02-06 10:22 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-16 14:04 - 2014-02-06 10:13 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-16 14:04 - 2014-02-06 10:09 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-16 14:04 - 2014-02-06 09:55 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-16 14:04 - 2014-02-06 09:41 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-16 14:04 - 2014-02-06 09:40 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-16 14:04 - 2014-02-06 09:36 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-16 14:04 - 2014-02-06 09:34 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-02-16 14:03 - 2014-02-06 11:38 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-16 14:03 - 2014-02-06 11:11 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-16 14:03 - 2014-02-06 10:25 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-16 14:03 - 2014-02-06 10:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-16 14:01 - 2014-01-01 00:05 - 00420008 _____ () C:\Windows\SysWOW64\locale.nls
2014-02-16 14:01 - 2014-01-01 00:04 - 00420008 _____ () C:\Windows\system32\locale.nls
2014-02-16 14:01 - 2013-12-25 00:09 - 01987584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d3d10warp.dll
2014-02-16 14:01 - 2013-12-24 23:48 - 02565120 _____ (Microsoft Corporation) C:\Windows\system32\d3d10warp.dll
2014-02-16 14:01 - 2013-12-06 03:30 - 01882112 _____ (Microsoft Corporation) C:\Windows\system32\msxml3.dll
2014-02-16 14:01 - 2013-12-06 03:30 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\msxml3r.dll
2014-02-16 14:01 - 2013-12-06 03:02 - 01237504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3.dll
2014-02-16 14:01 - 2013-12-06 03:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msxml3r.dll
2014-02-16 14:01 - 2013-11-26 09:16 - 03419136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\d2d1.dll
2014-02-16 14:01 - 2013-11-22 23:48 - 03928064 _____ (Microsoft Corporation) C:\Windows\system32\d2d1.dll
2014-02-15 19:42 - 2014-02-15 19:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-15 19:15 - 2013-12-04 03:27 - 00488448 _____ (Microsoft Corporation) C:\Windows\system32\secproc.dll
2014-02-15 19:15 - 2013-12-04 03:27 - 00485888 _____ (Microsoft Corporation) C:\Windows\system32\secproc_isv.dll
2014-02-15 19:15 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp_isv.dll
2014-02-15 19:15 - 2013-12-04 03:27 - 00123392 _____ (Microsoft Corporation) C:\Windows\system32\secproc_ssp.dll
2014-02-15 19:15 - 2013-12-04 03:26 - 00528384 _____ (Microsoft Corporation) C:\Windows\system32\msdrm.dll
2014-02-15 19:15 - 2013-12-04 03:16 - 00658432 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_isv.exe
2014-02-15 19:15 - 2013-12-04 03:16 - 00626176 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate.exe
2014-02-15 19:15 - 2013-12-04 03:16 - 00553984 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp.exe
2014-02-15 19:15 - 2013-12-04 03:16 - 00552960 _____ (Microsoft Corporation) C:\Windows\system32\RMActivate_ssp_isv.exe
2014-02-15 19:15 - 2013-12-04 03:03 - 00428032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc.dll
2014-02-15 19:15 - 2013-12-04 03:03 - 00423936 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_isv.dll
2014-02-15 19:15 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp_isv.dll
2014-02-15 19:15 - 2013-12-04 03:03 - 00087040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\secproc_ssp.dll
2014-02-15 19:15 - 2013-12-04 03:02 - 00390144 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdrm.dll
2014-02-15 19:15 - 2013-12-04 02:54 - 00594944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_isv.exe
2014-02-15 19:15 - 2013-12-04 02:54 - 00572416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate.exe
2014-02-15 19:15 - 2013-12-04 02:54 - 00510976 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp.exe
2014-02-15 19:15 - 2013-12-04 02:54 - 00508928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\RMActivate_ssp_isv.exe
2014-02-15 18:56 - 2014-02-15 18:56 - 00000000 ____D () C:\d81c342dbcd877fd82
2014-02-13 11:40 - 2014-03-04 18:04 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-02-13 11:40 - 2014-02-22 21:05 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-11 16:44 - 2014-02-11 16:44 - 00014372 _____ () C:\ComboFix.txt
2014-02-11 16:34 - 2014-02-11 16:44 - 00000000 ____D () C:\Qoobox
2014-02-11 16:34 - 2014-02-11 16:42 - 00000000 ____D () C:\Windows\erdnt
2014-02-11 16:34 - 2011-06-26 07:45 - 00256000 _____ () C:\Windows\PEV.exe
2014-02-11 16:34 - 2010-11-07 18:20 - 00208896 _____ () C:\Windows\MBR.exe
2014-02-11 16:34 - 2009-04-20 05:56 - 00060416 _____ (NirSoft) C:\Windows\NIRCMD.exe
2014-02-11 16:34 - 2000-08-31 01:00 - 00518144 _____ (SteelWerX) C:\Windows\SWREG.exe
2014-02-11 16:34 - 2000-08-31 01:00 - 00406528 _____ (SteelWerX) C:\Windows\SWSC.exe
2014-02-11 16:34 - 2000-08-31 01:00 - 00098816 _____ () C:\Windows\sed.exe
2014-02-11 16:34 - 2000-08-31 01:00 - 00080412 _____ () C:\Windows\grep.exe
2014-02-11 16:34 - 2000-08-31 01:00 - 00068096 _____ () C:\Windows\zip.exe
2014-02-11 16:31 - 2014-02-11 16:31 - 05180278 ____R (Swearware) C:\Users\Ursula\Desktop\ComboFix.exe
==================== One Month Modified Files and Folders =======
2014-03-04 18:08 - 2014-03-04 18:08 - 00005880 _____ () C:\Users\Ursula\Desktop\FRST.txt
2014-03-04 18:08 - 2013-11-06 13:22 - 00000000 ____D () C:\FRST
2014-03-04 18:07 - 2014-03-04 18:07 - 00000000 ____D () C:\Users\Ursula\Desktop\FRST-OlderVersion
2014-03-04 18:07 - 2014-02-18 16:34 - 02156544 _____ (Farbar) C:\Users\Ursula\Desktop\FRST64.exe
2014-03-04 18:04 - 2014-02-13 11:40 - 00000884 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-03-04 17:27 - 2014-01-09 18:04 - 02006763 _____ () C:\Windows\WindowsUpdate.log
2014-03-04 17:24 - 2009-07-14 05:45 - 00015952 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-03-04 17:24 - 2009-07-14 05:45 - 00015952 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-03-04 17:17 - 2014-02-18 14:54 - 00003463 _____ () C:\Windows\setupact.log
2014-03-04 17:17 - 2013-11-23 13:56 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-03-04 17:17 - 2009-07-14 06:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-03-02 20:48 - 2014-03-02 20:47 - 00000000 ____D () C:\Users\Ursula\Desktop\Lisa
2014-03-02 20:47 - 2009-07-14 18:58 - 00699348 _____ () C:\Windows\system32\perfh007.dat
2014-03-02 20:47 - 2009-07-14 18:58 - 00149456 _____ () C:\Windows\system32\perfc007.dat
2014-03-02 20:47 - 2009-07-14 06:13 - 01619312 _____ () C:\Windows\system32\PerfStringBackup.INI
2014-03-02 20:46 - 2014-03-02 20:45 - 00000000 ____D () C:\Users\Ursula\Desktop\wg. Bank
2014-03-01 16:16 - 2014-03-01 16:15 - 00027940 _____ () C:\Users\Ursula\Downloads\FRST (2).txt
2014-03-01 16:14 - 2014-03-01 16:14 - 00000000 ____D () C:\Users\Ursula\Downloads\FRST-OlderVersion
2014-03-01 16:13 - 2014-03-01 16:13 - 00000863 _____ () C:\Users\Ursula\Downloads\w.txt
2014-03-01 15:53 - 2014-03-01 15:53 - 00987425 _____ () C:\Users\Ursula\Downloads\SecurityCheck.exe
2014-03-01 15:47 - 2014-03-01 15:47 - 00000826 _____ () C:\Windows\PFRO.log
2014-03-01 15:39 - 2013-10-29 18:26 - 00000000 ____D () C:\Users\Ursula
2014-03-01 15:34 - 2014-03-01 15:34 - 00001966 _____ () C:\Users\Ursula\avast! Free Antivirus.lnk
2014-03-01 15:34 - 2014-01-02 11:11 - 00080184 _____ (AVAST Software) C:\Windows\system32\Drivers\aswstm.sys
2014-03-01 15:34 - 2013-11-23 13:56 - 01038072 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSnx.sys
2014-03-01 15:34 - 2013-11-23 13:56 - 00421704 _____ (AVAST Software) C:\Windows\system32\Drivers\aswSP.sys
2014-03-01 15:34 - 2013-11-23 13:56 - 00078648 _____ (AVAST Software) C:\Windows\system32\Drivers\aswMonFlt.sys
2014-03-01 15:34 - 2013-11-23 13:56 - 00043152 _____ (AVAST Software) C:\Windows\avastSS.scr
2014-03-01 15:34 - 2013-10-29 18:44 - 00334136 _____ (AVAST Software) C:\Windows\system32\aswBoot.exe
2014-03-01 14:20 - 2014-03-01 14:20 - 02347384 _____ (ESET) C:\Users\Ursula\Downloads\esetsmartinstaller_enu.exe
2014-02-28 14:37 - 2014-01-17 17:29 - 00000000 ____D () C:\Users\Public\Documents\VR-NetWorld
2014-02-27 18:42 - 2013-10-31 07:53 - 00000000 ____D () C:\Users\Ursula\AppData\Local\Microsoft Help
2014-02-24 22:31 - 2013-10-29 18:26 - 00000000 ____D () C:\Users\Ursula\AppData\Local\VirtualStore
2014-02-24 22:27 - 2014-02-24 22:27 - 00001237 _____ () C:\Users\Ursula\Ashampoo Home Designer.lnk
2014-02-24 22:27 - 2014-02-24 22:27 - 00000554 _____ () C:\Windows\KB893803v2.log
2014-02-24 22:26 - 2014-02-24 22:26 - 00000000 ____D () C:\Program Files (x86)\Ashampoo
2014-02-24 22:24 - 2014-02-24 22:15 - 173500560 _____ (Creative Amadeo GmbH ) C:\Users\Ursula\Downloads\ashampoo_home_designer_1.0.0_7591.exe
2014-02-22 21:05 - 2014-02-13 11:40 - 00003822 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-02-22 21:05 - 2013-10-31 17:28 - 00692616 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-02-22 21:05 - 2013-10-31 17:28 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-02-18 22:06 - 2009-07-14 04:20 - 00000000 ____D () C:\Windows\rescache
2014-02-18 16:36 - 2014-02-18 16:35 - 00024828 _____ () C:\Users\Ursula\Downloads\FRST.txt
2014-02-18 16:30 - 2014-02-18 16:30 - 00000758 _____ () C:\Users\Ursula\Downloads\JRT.txt
2014-02-18 16:21 - 2014-02-18 16:21 - 00000000 ____D () C:\Windows\ERUNT
2014-02-18 16:17 - 2014-02-18 16:17 - 01037530 _____ (Thisisu) C:\Users\Ursula\Downloads\JRT.exe
2014-02-18 16:13 - 2014-02-18 15:59 - 00000000 ____D () C:\AdwCleaner
2014-02-18 15:58 - 2014-02-18 15:58 - 01241834 _____ () C:\Users\Ursula\Downloads\adwcleaner.exe
2014-02-18 14:54 - 2014-02-18 14:54 - 00000000 _____ () C:\Windows\setuperr.log
2014-02-18 14:42 - 2014-02-16 14:18 - 01592864 _____ () C:\Windows\SysWOW64\PerfStringBackup.INI
2014-02-16 21:30 - 2013-10-31 20:22 - 00000000 ____D () C:\Users\Ursula\AppData\Roaming\Skype
2014-02-16 14:24 - 2013-10-29 19:34 - 00000000 ____D () C:\Windows\system32\MRT
2014-02-16 14:22 - 2013-10-29 19:34 - 88567024 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-02-15 21:53 - 2014-01-03 10:41 - 00000000 ____D () C:\Program Files (x86)\Mozilla Maintenance Service
2014-02-15 19:42 - 2014-02-15 19:42 - 00000000 ____D () C:\Program Files (x86)\Mozilla Firefox
2014-02-15 19:15 - 2013-11-13 19:46 - 00000000 ____D () C:\Windows\Minidump
2014-02-15 18:56 - 2014-02-15 18:56 - 00000000 ____D () C:\d81c342dbcd877fd82
2014-02-11 16:44 - 2014-02-11 16:44 - 00014372 _____ () C:\ComboFix.txt
2014-02-11 16:44 - 2014-02-11 16:34 - 00000000 ____D () C:\Qoobox
2014-02-11 16:42 - 2014-02-11 16:34 - 00000000 ____D () C:\Windows\erdnt
2014-02-11 16:41 - 2009-07-14 03:34 - 00000215 _____ () C:\Windows\system.ini
2014-02-11 16:31 - 2014-02-11 16:31 - 05180278 ____R (Swearware) C:\Users\Ursula\Desktop\ComboFix.exe
2014-02-06 20:31 - 2009-07-14 06:08 - 00032632 _____ () C:\Windows\Tasks\SCHEDLGU.TXT
2014-02-06 13:16 - 2014-02-16 14:04 - 23170048 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-02-06 12:30 - 2014-02-16 14:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-02-06 12:30 - 2014-02-16 14:04 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-02-06 12:12 - 2014-02-16 14:04 - 02765824 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-02-06 12:07 - 2014-02-16 14:04 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-02-06 12:06 - 2014-02-16 14:04 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-02-06 11:57 - 2014-02-16 14:04 - 00053760 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-02-06 11:56 - 2014-02-16 14:04 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-02-06 11:52 - 2014-02-16 14:04 - 00574976 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-02-06 11:49 - 2014-02-16 14:04 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-02-06 11:48 - 2014-02-16 14:04 - 00708608 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-02-06 11:48 - 2014-02-16 14:04 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-02-06 11:38 - 2014-02-16 14:03 - 17103872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-02-06 11:32 - 2014-02-16 14:04 - 00218624 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-02-06 11:20 - 2014-02-16 14:04 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-02-06 11:17 - 2014-02-16 14:04 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-02-06 11:11 - 2014-02-16 14:03 - 05768704 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-02-06 11:01 - 2014-02-16 14:04 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-02-06 11:00 - 2014-02-16 14:04 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-02-06 10:57 - 2014-02-16 14:04 - 02168320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-02-06 10:57 - 2014-02-16 14:04 - 00627200 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-02-06 10:52 - 2014-02-16 14:04 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-02-06 10:52 - 2014-02-16 14:04 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-02-06 10:50 - 2014-02-16 14:04 - 02041856 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-02-06 10:49 - 2014-02-16 14:04 - 00440832 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-02-06 10:47 - 2014-02-16 14:04 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-02-06 10:46 - 2014-02-16 14:04 - 00553472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-02-06 10:25 - 2014-02-16 14:04 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-02-06 10:25 - 2014-02-16 14:03 - 04244480 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-02-06 10:24 - 2014-02-16 14:04 - 02334208 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-02-06 10:22 - 2014-02-16 14:04 - 13051392 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-02-06 10:13 - 2014-02-16 14:04 - 00524288 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-02-06 10:09 - 2014-02-16 14:04 - 01964032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-02-06 10:03 - 2014-02-16 14:03 - 11266048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-02-06 09:55 - 2014-02-16 14:04 - 01393664 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-02-06 09:41 - 2014-02-16 14:04 - 01820160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-02-06 09:40 - 2014-02-16 14:04 - 00817664 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-02-06 09:36 - 2014-02-16 14:04 - 01156096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-02-06 09:34 - 2014-02-16 14:04 - 00703488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
Some content of TEMP:
====================
C:\Users\Ursula\AppData\Local\Temp\Quarantine.exe
==================== Bamital & volsnap Check =================
C:\Windows\System32\winlogon.exe => MD5 is legit
C:\Windows\System32\wininit.exe => MD5 is legit
C:\Windows\SysWOW64\wininit.exe => MD5 is legit
C:\Windows\explorer.exe => MD5 is legit
C:\Windows\SysWOW64\explorer.exe => MD5 is legit
C:\Windows\System32\svchost.exe => MD5 is legit
C:\Windows\SysWOW64\svchost.exe => MD5 is legit
C:\Windows\System32\services.exe => MD5 is legit
C:\Windows\System32\User32.dll => MD5 is legit
C:\Windows\SysWOW64\User32.dll => MD5 is legit
C:\Windows\System32\userinit.exe => MD5 is legit
C:\Windows\SysWOW64\userinit.exe => MD5 is legit
C:\Windows\System32\rpcss.dll => MD5 is legit
C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit
LastRegBack: 2014-02-18 21:59
==================== End Of Log ============================
Addition.txt: Zitat:
|
| Themen zu infizierten Rechner im Netz gehabt. Verdacht auf Malware auf eigenen Laptop.Könnt ihr mir weiterhelfen? |
| allgemein, angst, avast, einfach, gemeldet, heute, infizierte, infizierten, inter, interne, laptop, malware, programme, programmen, rechner, sache, sauber, scanner, schädling, verdacht, weiterhelfen, wissen, woche, wochen, wurm.erkennung, würde, zuhause |