Plagegeister aller Art und deren Bekämpfung: VLC von der falschen Seite geladen..Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
VLC von der falschen Seite geladen.. Hallo zusammen, ich bin auch mal wieder hier. Ich habe mir vor einigen Tagen VLC von VLC.de runtergeladen. Nun ist mir aufgefallen, dass auf meinem Desktop ein Symbol Startseite ist. (Ab und an habe ich diese Seite auch mal im Browser gesehen, aber irgendwie hat mich das nicht weiter verwundert) Eigentlich wollte ich das ganze einfach deinstallieren, habe dann beim googlen aber gesehen, dass es sich dabei wohl auch um Trojaner oder ähnliches handeln kann. Kann mir vielleicht jemand helfen, wie ich das Zeug wieder weg bekomme? (Dabei hatte ich gerade erst Windows 8 neu installiert und war froh endlich mal 100% sicher sein zu können, dass nicht böses drauf ist.. nun ja) Ich hab in einem anderen Thread gelesen, dass man OTL laufen lassen sollte, also habe ich das schon mal gemacht falls es euch hilft. Vielen vielen Dank schonmal! LG
VLC von der falschen Seite geladen.. hi,
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
![]() | ![]() VLC von der falschen Seite geladen.. Hallo,
2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\sru 2014-01-15 10:53 - 2013-08-24 16:38 - 00001130 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-15 10:39 - 2014-01-15 10:31 - 00048596 _____ C:\Users\Prinzessin\Desktop\Extras.Txt 2014-01-15 10:32 - 2014-01-15 10:31 - 00133010 _____ C:\Users\Prinzessin\Desktop\OTL.Txt 2014-01-15 10:10 - 2014-01-15 10:10 - 00602112 _____ (OldTimer Tools) C:\Users\Prinzessin\Desktop\OTL.exe 2014-01-15 10:08 - 2013-08-15 14:22 - 00003598 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3751189097-2915931777-4004511958-1001 2014-01-15 10:04 - 2013-08-22 17:46 - 00000000 ___RD C:\Users\Prinzessin\Documents\Dropbox 2014-01-15 10:04 - 2013-08-22 17:42 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Dropbox 2014-01-15 10:03 - 2013-08-24 16:38 - 00001126 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-15 10:03 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\AUInstallAgent 2014-01-13 17:49 - 2012-07-26 11:27 - 00715482 _____ C:\Windows\system32\perfh007.dat 2014-01-13 17:49 - 2012-07-26 11:27 - 00148046 _____ C:\Windows\system32\perfc007.dat 2014-01-13 17:49 - 2012-07-26 08:28 - 01654648 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-11 21:21 - 2014-01-11 21:21 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\vlc 2014-01-11 21:19 - 2014-01-11 21:19 - 00000871 _____ C:\Users\Public\Desktop\VLC media player.lnk 2014-01-11 21:19 - 2014-01-11 21:19 - 00000000 ____D C:\Program Files\VideoLAN 2014-01-11 21:18 - 2014-01-11 21:18 - 00001196 _____ C:\Users\Prinzessin\Desktop\Startfenster.lnk 2014-01-11 21:18 - 2014-01-11 21:18 - 00001196 _____ C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk 2014-01-11 21:15 - 2013-09-24 18:47 - 00000000 ____D C:\Users\Prinzessin\AppData\Local\Microsoft Help 2014-01-11 21:02 - 2014-01-11 21:01 - 24738792 _____ C:\Users\Prinzessin\Downloads\vlc-2.1.2-win64.exe 2014-01-09 12:16 - 2012-07-26 08:21 - 00017735 _____ C:\Windows\setupact.log 2014-01-06 20:39 - 2014-01-06 20:39 - 00518875 _____ C:\Users\Prinzessin\Downloads\HA_Statistic.zip 2014-01-06 20:39 - 2014-01-06 20:39 - 00000000 ____D C:\Users\Prinzessin\Downloads\HA_Statistic 2014-01-04 18:41 - 2013-08-24 10:56 - 00000000 ____D C:\Program Files (x86)\Nightly.bak 2014-01-04 18:41 - 2013-08-15 18:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-04 15:47 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-04 15:46 - 2012-07-26 06:26 - 00524288 ___SH C:\Windows\system32\config\BBI 2014-01-04 15:32 - 2014-01-04 15:24 - 00004928 _____ C:\Windows\DPINST.LOG 2014-01-04 15:25 - 2014-01-04 15:25 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_Apfiltr_01009.Wdf 2014-01-04 15:25 - 2014-01-04 15:25 - 00000000 ____D C:\Program Files\DellTPad 2014-01-04 15:24 - 2014-01-04 15:24 - 00000000 ____D C:\ProgramData\Dell 2014-01-04 15:24 - 2014-01-04 15:18 - 69095472 _____ (Dell Inc.) C:\Users\Prinzessin\Downloads\Input_Driver_FGG85_WN_8.1200.101.214_A02.EXE 2014-01-04 15:16 - 2014-01-04 15:16 - 10121992 _____ C:\Users\Prinzessin\Downloads\Tocuhpad treiber.exe 2014-01-01 21:47 - 2014-01-01 21:47 - 00000000 ____D C:\Program Files (x86)\Nightly 2014-01-01 21:00 - 2013-12-01 21:33 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\FileZilla 2014-01-01 18:53 - 2014-01-01 18:43 - 00000000 ____D C:\Users\Prinzessin\Documents\Kiwilicious 2014-01-01 18:45 - 2013-12-28 19:51 - 00000000 ____D C:\Users\Prinzessin\Documents\XAMPP 2014-01-01 18:42 - 2014-01-01 18:42 - 00000676 _____ C:\Users\Prinzessin\Documents\cookie.html 2014-01-01 18:42 - 2014-01-01 18:42 - 00000512 _____ C:\Users\Prinzessin\Documents\.htaccess 2013-12-29 20:21 - 2013-12-29 20:21 - 00000000 ____D C:\Users\Prinzessin\Desktop\uploads 2013-12-29 14:34 - 2013-12-29 14:34 - 00322096 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-28 23:53 - 2013-12-28 23:53 - 21850807 _____ C:\Users\Prinzessin\Downloads\4725693899_2dbf489d5e_o.psd 2013-12-28 23:53 - 2013-12-28 23:53 - 21850807 _____ C:\Users\Prinzessin\Downloads\4725693899_2dbf489d5e_o (1).psd 2013-12-28 19:30 - 2013-12-28 19:30 - 00055224 _____ C:\Users\Prinzessin\Downloads\backerinchen.wordpress.2013-12-28.xml 2013-12-28 19:24 - 2013-12-28 19:24 - 00162710 _____ C:\Users\Prinzessin\Downloads\kiwilicious.wordpress.2013-12-28.xml 2013-12-28 19:15 - 2013-12-28 19:15 - 00000000 ____D C:\Users\Prinzessin\Downloads\wordpress-3.8 2013-12-28 19:13 - 2013-12-28 19:12 - 06367550 _____ C:\Users\Prinzessin\Downloads\wordpress-3.8.zip 2013-12-28 18:59 - 2013-12-28 18:59 - 00003217 _____ C:\Users\Prinzessin\Downloads\wp-config.php 2013-12-28 18:56 - 2013-12-27 20:56 - 00003495 _____ C:\Users\Prinzessin\Desktop\wp-config1.php 2013-12-28 17:42 - 2013-12-28 16:50 - 00000000 ____D C:\Program Files\XAMPP 2013-12-28 17:41 - 2013-12-28 17:41 - 03026171 _____ C:\Users\Prinzessin\Downloads\localhost.sql 2013-12-28 16:48 - 2013-12-28 16:47 - 123794144 _____ (BitNami) C:\Users\Prinzessin\Downloads\xampp-win32-1.8.3-2-VC11-installer.exe 2013-12-28 16:43 - 2013-12-28 16:38 - 00000961 _____ C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TextPad.lnk 2013-12-28 16:38 - 2013-12-28 16:38 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Helios 2013-12-28 16:38 - 2013-12-28 16:38 - 00000000 ____D C:\Program Files\TextPad 7 2013-12-28 16:37 - 2013-12-28 16:37 - 00000000 ____D C:\Users\Prinzessin\Downloads\txpdeu710 2013-12-28 16:22 - 2013-12-28 16:22 - 02842038 _____ C:\Users\Prinzessin\Downloads\bueno.zip 2013-12-28 16:21 - 2013-12-28 16:21 - 05173196 _____ C:\Users\Prinzessin\Downloads\irresistible.zip 2013-12-27 23:45 - 2013-12-27 23:45 - 00000071 _____ C:\Users\Prinzessin\Desktop\index.html 2013-12-27 22:36 - 2013-12-27 22:36 - 01621358 _____ C:\Users\Prinzessin\Downloads\customizr.3.1.5.zip 2013-12-27 21:54 - 2013-12-27 21:54 - 01651587 _____ C:\Users\Prinzessin\Downloads\hueman.1.2.7.zip 2013-12-27 21:54 - 2013-12-27 21:54 - 00000000 ____D C:\Users\Prinzessin\Downloads\hueman.1.2.7 2013-12-27 21:46 - 2013-12-27 21:46 - 00000000 ____D C:\Users\Prinzessin\Downloads\schatzhatskaputtgemacht 2013-12-27 21:45 - 2013-12-27 21:45 - 00029708 _____ C:\Users\Prinzessin\Downloads\schatzhatskaputtgemacht.zip 2013-12-27 21:10 - 2013-12-27 21:06 - 00000000 ____D C:\Users\Prinzessin\Desktop\Kiwilicious Backup 27.12 2013-12-27 21:06 - 2013-12-28 18:07 - 00000512 _____ C:\Users\Prinzessin\Desktop\.htaccess.backup 2013-12-23 12:38 - 2013-09-24 18:47 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-12-23 12:19 - 2013-12-23 12:19 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-12-23 12:19 - 2013-12-23 12:18 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-12-23 12:19 - 2013-12-23 12:18 - 00000000 ____D C:\Program Files\iTunes 2013-12-23 12:19 - 2013-12-23 12:18 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-12-23 12:18 - 2013-12-23 12:18 - 00000000 ____D C:\Program Files\iPod 2013-12-18 22:01 - 2013-08-15 14:16 - 00000000 ___RD C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2013-12-18 22:00 - 2013-08-22 17:46 - 00000994 _____ C:\Users\Prinzessin\Desktop\Dropbox.lnk 2013-12-18 22:00 - 2013-08-22 17:44 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox Some content of TEMP: ==================== C:\Users\Prinzessin\AppData\Local\Temp\ose00000.exe C:\Users\Prinzessin\AppData\Local\Temp\PrefJsonCpp.exe C:\Users\Prinzessin\AppData\Local\Temp\sqlite3.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-13 18:01 ==================== End Of Log ============================ Addition.txt Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x64) Version: 15-01-2014 Ran by Prinzessin at 2014-01-15 11:45:31 Running from C:\Users\Prinzessin\Desktop Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} ==================== Installed Programs ====================== Adobe Reader XI (11.0.05) - Deutsch (x32 Version: 11.0.05 - Adobe Systems Incorporated) Apple Application Support (x32 Version: 2.3.6 - Apple Inc.) Apple Mobile Device Support (Version: - Apple Inc.) Apple Software Update (x32 Version: - Apple Inc.) Bonjour (Version: - Apple Inc.) Bonjour-Druckdienste (Version: - Apple Inc.) Dell Touchpad (Version: 8.1200.101.214 - ALPS ELECTRIC CO., LTD.) Dropbox (HKCU Version: 2.4.10 - Dropbox, Inc.) FileZilla Client 3.7.3 (x32 Version: 3.7.3 - Tim Kosse) FortiClient (Version: - Fortinet Inc) Google Chrome (x32 Version: 31.0.1650.63 - Google Inc.) Google Update Helper (x32 Version: - Google Inc.) Hidden iCloud (Version: - Apple Inc.) iTunes (Version: - Apple Inc.) JabRef 2.9.2 (x32 Version: 2.9.2 - JabRef Team) Java 7 Update 45 (x32 Version: 7.0.450 - Oracle) Java Auto Updater (x32 Version: - Sun Microsystems, Inc.) Hidden Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Excel MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office File Validation Add-In (x32 Version: 14.0.5130.5003 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Microsoft Office Home and Student 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Live Add-in 1.5 (x32 Version: 2.0.4024.1 - Microsoft Corporation) Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office OneNote MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office PowerPoint MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proof (Italian) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Proofing (German) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version: - Microsoft) Hidden Microsoft Office Shared 64-bit MUI (German) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Shared MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Office Word MUI (German) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (x32 Version: 9.0.21022 - Microsoft Corporation) Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (x32 Version: 9.0.30729.6161 - Microsoft Corporation) MiKTeX 2.9 (x32 Version: 2.9 - MiKTeX.org) Mozilla Maintenance Service (x32 Version: 29.0a1 - Mozilla) Nightly 29.0a1 (x86 en-US) (x32 Version: 29.0a1 - Mozilla) PDF24 Creator 5.7.0 (x32 Version: - PDF24.org) RailsInstaller 2.2.2 (HKCU Version: 2.2.2 - RailsInstaller Team) RICOH Media Driver ver. (x32 Version: - RICOH) Sublime Text 2.0.2 (Version: - ) TeXnicCenter Version 2.02 Stable (x32 Version: 2.02 Stable - The TeXnicCenter Team) TextPad 7 (Version: 7.1.0 - Helios) Update for 2007 Microsoft Office System (KB967642) (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2687493) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (x32 Version: - Microsoft) Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (x32 Version: - Microsoft) Update für Microsoft Office Excel 2007 Help (KB963678) (x32 Version: - Microsoft) Update für Microsoft Office Powerpoint 2007 Help (KB963669) (x32 Version: - Microsoft) Update für Microsoft Office Word 2007 Help (KB963665) (x32 Version: - Microsoft) VLC media player 2.1.2 (Version: 2.1.2 - VideoLAN) XAMPP (x32 Version: 1.8.3-2 - BitNami) ==================== Restore Points ========================= 28-12-2013 15:37:39 Installed TextPad 7. 06-01-2014 20:34:35 Geplanter Prüfpunkt 14-01-2014 19:39:41 Geplanter Prüfpunkt ==================== Hosts content: ========================== 2012-07-26 06:26 - 2012-07-26 06:26 - 00000824 ____A C:\Windows\system32\Drivers\etc\hosts ==================== Scheduled Tasks (whitelisted) ============= Task: {1AAFF332-5C62-4558-9991-DAA649C4C9C5} - System32\Tasks\Microsoft\Windows\Sysmain\WsSwapAssessmentTask => Rundll32.exe sysmain.dll,PfSvWsSwapAssessmentTask Task: {23A5D8BE-9196-40EB-BD89-794398B2B073} - System32\Tasks\Microsoft\Windows\WS\WSRefreshBannedAppsListTask => Rundll32.exe WSClient.dll,RefreshBannedAppsList Task: {56B273B0-6F12-48C3-9F32-AE2F82709198} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-24] (Google Inc.) Task: {7F03450C-90B3-4689-97A2-25047A3BCB5A} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2013-08-24] (Google Inc.) Task: {82EC5401-92A6-4D8A-860A-215AA77AB561} - System32\Tasks\Microsoft\Windows\Setup\Pre-staged GDR Notification => C:\Windows\system32\NotificationUI.exe [2013-08-16] (Microsoft Corporation) Task: {9D912DB4-DC92-4C77-9299-4075563CAB6D} - System32\Tasks\Apple Diagnostics => C:\Program Files (x86)\Common Files\Apple\Internet Services\EReporter.exe [2013-11-20] (Apple Inc.) Task: {A72208BF-7A49-4FB8-B684-252375F3443A} - System32\Tasks\Microsoft\Windows\WS\License Validation => Rundll32.exe WSClient.dll,WSpTLR licensing Task: {C6A88F2D-53D2-4805-9D69-443738A1847C} - System32\Tasks\Microsoft\Windows\ApplicationData\CleanupTemporaryState => Rundll32.exe Windows.Storage.ApplicationData.dll,CleanupTemporaryState Task: {EBF06DEC-4228-4813-AC0C-62821AE4E330} - System32\Tasks\Microsoft\Windows\Application Experience\StartupAppTask => Rundll32.exe Startupscan.dll,SusRunTask Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-08-16 15:14 - 2013-08-16 15:14 - 00175008 _____ () C:\Program Files\WindowsApps\microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe\ModernShared\ErrorReporting\ErrorReporting.dll 2012-08-14 16:05 - 2012-08-14 16:05 - 00323584 _____ () C:\Program Files (x86)\Fortinet\FortiClient\sqlite3.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll 2013-04-21 20:44 - 2013-04-21 20:44 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll 2013-09-14 00:51 - 2013-09-14 00:51 - 00087952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\zlib1.dll 2013-09-14 00:50 - 2013-09-14 00:50 - 01242952 _____ () C:\Program Files (x86)\Common Files\Apple\Internet Services\libxml2.dll 2013-08-23 20:01 - 2013-08-23 20:01 - 25100288 _____ () C:\Users\Prinzessin\AppData\Roaming\Dropbox\bin\libcef.dll 2013-07-10 17:07 - 2013-07-10 17:07 - 00756888 _____ () C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE12\MSPTLS.DLL 2012-09-23 19:43 - 2012-09-23 19:43 - 00313992 _____ () C:\Program Files (x86)\Adobe\Reader 11.0\Reader\sqlite.dll 2013-08-07 20:25 - 2013-08-07 20:25 - 00093696 _____ () C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll 2013-12-05 21:55 - 2013-12-04 03:47 - 00702416 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libglesv2.dll 2013-12-05 21:55 - 2013-12-04 03:47 - 00099792 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\libegl.dll 2013-12-05 21:55 - 2013-12-04 03:48 - 04055504 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-05 21:55 - 2013-12-04 03:48 - 00399312 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-05 21:55 - 2013-12-04 03:47 - 01619408 _____ () C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\Wdf01000.sys => ""="Driver" ==================== Faulty Device Manager Devices ============= Name: Broadcom NetLink (TM)-Gigabit-Ethernet Description: Broadcom NetLink (TM)-Gigabit-Ethernet Class Guid: {4d36e972-e325-11ce-bfc1-08002be10318} Manufacturer: Broadcom Service: k57nd60a Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. Name: Description: Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. ==================== Event log errors: ========================= Could not start eventlog service, could not read events. Der angeforderte Dienst wurde bereits gestartet. Sie erhalten weitere Hilfe, wenn Sie NET HELPMSG 2182 eingeben. ==================== Memory info =========================== Percentage of memory in use: 51% Total physical RAM: 4060.86 MB Available physical RAM: 1986.84 MB Total Pagefile: 4764.86 MB Available Pagefile: 2514.81 MB Total Virtual: 8192 MB Available Virtual: 8191.77 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:931.17 GB) (Free:800.83 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 932 GB) (Disk ID: F4501180) Partition 1: (Active) - (Size=350 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=931 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() VLC von der falschen Seite geladen.. Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | ![]() VLC von der falschen Seite geladen.. Sorry, dass ich mich jetzt erst wieder melde. Ich konnte leider die letzten zwei Tage mit dem PC nicht ins Internet. Also hier die Logs: Code:
ATTFilter Malwarebytes Anti-Malware www.malwarebytes.org Datenbank Version: v2014.01.18.02 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16750 Prinzessin :: LILLI [Administrator] 18.01.2014 13:12:52 mbam-log-2014-01-18 (13-12-52).txt Art des Suchlaufs: Quick-Scan Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 205828 Laufzeit: 6 Minute(n), 34 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Prinzessin\Downloads\SFInstaller_SFFZ_filezilla_8992693_.exe (PUP.Optional.Spigot.A) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Code:
ATTFilter # AdwCleaner v3.017 - Bericht erstellt am 18/01/2014 um 13:27:13 # Aktualisiert 12/01/2014 von Xplode # Betriebssystem : Windows 8 Pro (64 bits) # Benutzername : Prinzessin - LILLI # Gestartet von : C:\Users\Prinzessin\Desktop\adwcleaner.exe # Option : Löschen ***** [ Dienste ] ***** ***** [ Dateien / Ordner ] ***** Datei Gelöscht : C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Startfenster.lnk Datei Gelöscht : C:\Users\Prinzessin\Desktop\Startfenster.lnk ***** [ Verknüpfungen ] ***** ***** [ Registrierungsdatenbank ] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\TypeLib\{A8E5842E-102B-4289-9D57-3B3F5B5E15D3} ***** [ Browser ] ***** -\\ Internet Explorer v10.0.9200.16537 Einstellung Wiederhergestellt : HKCU\Software\Microsoft\Internet Explorer\Main [Start Page] -\\ Mozilla Firefox v [ Datei : C:\Users\Prinzessin\AppData\Roaming\Mozilla\Firefox\Profiles\jp8va1ae.default\prefs.js ] Zeile gelöscht : user_pref("browser.startup.homepage", "hxxp://www.startfenster.de"); -\\ Google Chrome v31.0.1650.63 [ Datei : C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [1369 octets] - [18/01/2014 13:25:19] AdwCleaner[S0].txt - [1270 octets] - [18/01/2014 13:27:13] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [1330 octets] ########## Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.0 (01.07.2014:1) OS: Windows 8 Pro x64 Ran by Prinzessin on 18.01.2014 at 13:33:11,39 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files Successfully deleted: [File] "C:\Users\Prinzessin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\user pinned\taskbar\startfenster.lnk" ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 18.01.2014 at 13:42:06,11 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: FRST Logfile: FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 15-01-2014 Ran by Prinzessin (administrator) on LILLI on 18-01-2014 13:47:12 Running from C:\Users\Prinzessin\Desktop Windows 8 Pro (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\scheduler.exe (Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\FCDBLog.exe (brother Industries Ltd) C:\Windows\SysWOW64\BRSVC01A.EXE (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (brother Industries Ltd) C:\Windows\SysWOW64\BRSS01A.EXE (Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\FCHelper.exe (Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\FortiTray.exe (Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Dropbox, Inc.) C:\Users\Prinzessin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [682904 2012-09-20] (Alps Electric Co., Ltd.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.) Startup: C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Prinzessin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE3CA919EFC03CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE SearchScopes: HKLM - DefaultScope {20B1356B-8C0D-4BA9-907C-B5A739CC1D05} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM - {20B1356B-8C0D-4BA9-907C-B5A739CC1D05} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKCU - {20B1356B-8C0D-4BA9-907C-B5A739CC1D05} URL = hxxp://www.sm.de/?q={searchTerms} BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Prinzessin\AppData\Roaming\Mozilla\Firefox\Profiles\jp8va1ae.default FF NetworkProxy: "http", "proxy.fh-brandenburg.de" FF NetworkProxy: "http_port", 3128 FF NetworkProxy: "type", 4 FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Nightly\firefox.exe Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Extension: (Google Docs) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0 [2013-08-24] CHR Extension: (Google Drive) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0 [2013-08-24] CHR Extension: (YouTube) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0 [2013-08-24] CHR Extension: (Google Search) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\ [2013-08-24] CHR Extension: (iCloud Bookmarks) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah\1.2.12_0 [2013-12-14] CHR Extension: (Hola Better Internet) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio\1.2.395_0 [2014-01-15] CHR Extension: (Google Wallet) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\ [2013-12-26] CHR Extension: (Gmail) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_1 [2013-08-24] ==================== Services (Whitelisted) ================= U2 Brother XP spl Service; C:\Windows\SysWOW64\brsvc01a.exe [57344 2004-06-13] (brother Industries Ltd) U2 FA_Scheduler; C:\Program Files (x86)\Fortinet\FortiClient\scheduler.exe [73746 2012-08-14] (Fortinet Inc.) U2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== U3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation) U3 fortiapd; C:\Windows\System32\drivers\fortiapd.sys [15656 2012-08-14] (Fortinet Inc) U1 FortiFilter; C:\Windows\system32\DRIVERS\FortiFilter.sys [23928 2011-09-09] (Fortinet Inc) U3 Fortips; C:\Windows\System32\drivers\fortips.sys [126760 2012-08-14] (Fortinet Inc) U3 FortiRdr; C:\Windows\System32\drivers\FortiRdr2.sys [46888 2012-08-14] (Fortinet Inc) U3 ft_vnic; C:\Windows\system32\DRIVERS\ftvnic.sys [16928 2011-03-21] (Fortinet Inc.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-18 13:42 - 2014-01-18 13:46 - 00000769 _____ C:\Users\Prinzessin\Desktop\JRT.txt 2014-01-18 13:33 - 2014-01-18 13:33 - 00000000 ____D C:\Windows\ERUNT 2014-01-18 13:31 - 2014-01-18 13:31 - 01037068 _____ (Thisisu) C:\Users\Prinzessin\Desktop\JRT.exe 2014-01-18 13:30 - 2014-01-18 13:30 - 00001410 _____ C:\Users\Prinzessin\Desktop\AdwCleaner[S0].txt 2014-01-18 13:25 - 2014-01-18 13:27 - 00000000 ____D C:\AdwCleaner 2014-01-18 13:09 - 2014-01-18 13:09 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-18 13:09 - 2014-01-18 13:09 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Malwarebytes 2014-01-18 13:09 - 2014-01-18 13:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-18 13:09 - 2014-01-18 13:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-18 13:09 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-18 13:08 - 2014-01-18 13:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Prinzessin\Downloads\mbam-setup- 2014-01-18 13:08 - 2014-01-18 13:08 - 01236282 _____ C:\Users\Prinzessin\Desktop\adwcleaner.exe 2014-01-15 11:45 - 2014-01-15 11:45 - 00011156 _____ C:\Users\Prinzessin\Desktop\Addition.txt 2014-01-15 11:44 - 2014-01-18 13:47 - 00009180 _____ C:\Users\Prinzessin\Desktop\FRST.txt 2014-01-15 11:44 - 2014-01-15 11:44 - 00000000 ____D C:\FRST 2014-01-15 11:43 - 2014-01-15 11:43 - 02076160 _____ (Farbar) C:\Users\Prinzessin\Desktop\FRST64.exe 2014-01-15 11:08 - 2013-12-07 07:37 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2014-01-15 11:08 - 2013-12-07 07:37 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-01-15 11:08 - 2013-12-07 06:15 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2014-01-15 11:08 - 2013-12-07 06:15 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-01-15 11:08 - 2013-10-31 06:56 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll 2014-01-15 11:08 - 2013-10-31 06:56 - 00758784 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll 2014-01-15 11:08 - 2013-10-31 05:01 - 00550400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll 2014-01-15 11:08 - 2013-10-31 04:42 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys 2014-01-15 11:08 - 2013-10-28 06:50 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2014-01-15 11:08 - 2013-10-28 05:05 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2014-01-15 11:08 - 2013-10-13 21:49 - 00100696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys 2014-01-15 11:08 - 2013-08-27 06:21 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2014-01-15 11:08 - 2013-08-27 06:19 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2014-01-15 11:08 - 2013-08-26 23:29 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2014-01-15 11:08 - 2013-08-26 23:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2014-01-15 10:31 - 2014-01-15 10:39 - 00048596 _____ C:\Users\Prinzessin\Desktop\Extras.Txt 2014-01-15 10:31 - 2014-01-15 10:32 - 00133010 _____ C:\Users\Prinzessin\Desktop\OTL.Txt 2014-01-15 10:10 - 2014-01-15 10:10 - 00602112 _____ (OldTimer Tools) C:\Users\Prinzessin\Desktop\OTL.exe 2014-01-11 21:21 - 2014-01-11 21:21 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\vlc 2014-01-11 21:19 - 2014-01-11 21:19 - 00000871 _____ C:\Users\Public\Desktop\VLC media player.lnk 2014-01-11 21:19 - 2014-01-11 21:19 - 00000000 ____D C:\Program Files\VideoLAN 2014-01-11 21:01 - 2014-01-11 21:02 - 24738792 _____ C:\Users\Prinzessin\Downloads\vlc-2.1.2-win64.exe 2014-01-06 20:39 - 2014-01-06 20:39 - 00518875 _____ C:\Users\Prinzessin\Downloads\HA_Statistic.zip 2014-01-06 20:39 - 2014-01-06 20:39 - 00000000 ____D C:\Users\Prinzessin\Downloads\HA_Statistic 2014-01-04 15:25 - 2014-01-04 15:25 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_Apfiltr_01009.Wdf 2014-01-04 15:25 - 2014-01-04 15:25 - 00000000 ____D C:\Program Files\DellTPad 2014-01-04 15:24 - 2014-01-04 15:32 - 00004928 _____ C:\Windows\DPINST.LOG 2014-01-04 15:24 - 2014-01-04 15:24 - 00000000 ____D C:\ProgramData\Dell 2014-01-04 15:24 - 2012-09-19 06:46 - 00447864 _____ (Alps Electric Co., Ltd.) C:\Windows\system32\Drivers\Apfiltr.sys 2014-01-04 15:24 - 2012-05-17 14:08 - 00113048 _____ (Alps Electric Co., Ltd.) C:\Windows\system32\Vxdif.dll 2014-01-04 15:24 - 2009-07-14 09:51 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-01-04 15:18 - 2014-01-04 15:24 - 69095472 _____ (Dell Inc.) C:\Users\Prinzessin\Downloads\Input_Driver_FGG85_WN_8.1200.101.214_A02.EXE 2014-01-04 15:16 - 2014-01-04 15:16 - 10121992 _____ C:\Users\Prinzessin\Downloads\Tocuhpad treiber.exe 2014-01-01 21:47 - 2014-01-01 21:47 - 00000000 ____D C:\Program Files (x86)\Nightly 2014-01-01 18:43 - 2014-01-01 18:53 - 00000000 ____D C:\Users\Prinzessin\Documents\Kiwilicious 2014-01-01 18:42 - 2014-01-01 18:42 - 00000676 _____ C:\Users\Prinzessin\Documents\cookie.html 2014-01-01 18:42 - 2014-01-01 18:42 - 00000512 _____ C:\Users\Prinzessin\Documents\.htaccess 2013-12-29 20:21 - 2013-12-29 20:21 - 00000000 ____D C:\Users\Prinzessin\Desktop\uploads 2013-12-29 14:34 - 2013-12-29 14:34 - 00322096 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-28 23:53 - 2013-12-28 23:53 - 21850807 _____ C:\Users\Prinzessin\Downloads\4725693899_2dbf489d5e_o.psd 2013-12-28 23:53 - 2013-12-28 23:53 - 21850807 _____ C:\Users\Prinzessin\Downloads\4725693899_2dbf489d5e_o (1).psd 2013-12-28 19:51 - 2014-01-01 18:45 - 00000000 ____D C:\Users\Prinzessin\Documents\XAMPP 2013-12-28 19:30 - 2013-12-28 19:30 - 00055224 _____ C:\Users\Prinzessin\Downloads\backerinchen.wordpress.2013-12-28.xml 2013-12-28 19:24 - 2013-12-28 19:24 - 00162710 _____ C:\Users\Prinzessin\Downloads\kiwilicious.wordpress.2013-12-28.xml 2013-12-28 19:15 - 2013-12-28 19:15 - 00000000 ____D C:\Users\Prinzessin\Downloads\wordpress-3.8 2013-12-28 19:12 - 2013-12-28 19:13 - 06367550 _____ C:\Users\Prinzessin\Downloads\wordpress-3.8.zip 2013-12-28 18:59 - 2013-12-28 18:59 - 00003217 _____ C:\Users\Prinzessin\Downloads\wp-config.php 2013-12-28 18:07 - 2013-12-27 21:06 - 00000512 _____ C:\Users\Prinzessin\Desktop\.htaccess.backup 2013-12-28 17:41 - 2013-12-28 17:41 - 03026171 _____ C:\Users\Prinzessin\Downloads\localhost.sql 2013-12-28 16:50 - 2013-12-28 17:42 - 00000000 ____D C:\Program Files\XAMPP 2013-12-28 16:47 - 2013-12-28 16:48 - 123794144 _____ (BitNami) C:\Users\Prinzessin\Downloads\xampp-win32-1.8.3-2-VC11-installer.exe 2013-12-28 16:38 - 2013-12-28 16:43 - 00000961 _____ C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TextPad.lnk 2013-12-28 16:38 - 2013-12-28 16:38 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Helios 2013-12-28 16:38 - 2013-12-28 16:38 - 00000000 ____D C:\Program Files\TextPad 7 2013-12-28 16:37 - 2013-12-28 16:37 - 00000000 ____D C:\Users\Prinzessin\Downloads\txpdeu710 2013-12-28 16:22 - 2013-12-28 16:22 - 02842038 _____ C:\Users\Prinzessin\Downloads\bueno.zip 2013-12-28 16:21 - 2013-12-28 16:21 - 05173196 _____ C:\Users\Prinzessin\Downloads\irresistible.zip 2013-12-27 23:45 - 2013-12-27 23:45 - 00000071 _____ C:\Users\Prinzessin\Desktop\index.html 2013-12-27 22:36 - 2013-12-27 22:36 - 01621358 _____ C:\Users\Prinzessin\Downloads\customizr.3.1.5.zip 2013-12-27 21:54 - 2013-12-27 21:54 - 01651587 _____ C:\Users\Prinzessin\Downloads\hueman.1.2.7.zip 2013-12-27 21:54 - 2013-12-27 21:54 - 00000000 ____D C:\Users\Prinzessin\Downloads\hueman.1.2.7 2013-12-27 21:46 - 2013-12-27 21:46 - 00000000 ____D C:\Users\Prinzessin\Downloads\schatzhatskaputtgemacht 2013-12-27 21:45 - 2013-12-27 21:45 - 00029708 _____ C:\Users\Prinzessin\Downloads\schatzhatskaputtgemacht.zip 2013-12-27 21:06 - 2013-12-27 21:10 - 00000000 ____D C:\Users\Prinzessin\Desktop\Kiwilicious Backup 27.12 2013-12-27 20:56 - 2013-12-28 18:56 - 00003495 _____ C:\Users\Prinzessin\Desktop\wp-config1.php 2013-12-23 12:19 - 2013-12-23 12:19 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-12-23 12:18 - 2013-12-23 12:19 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-12-23 12:18 - 2013-12-23 12:19 - 00000000 ____D C:\Program Files\iTunes 2013-12-23 12:18 - 2013-12-23 12:19 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-12-23 12:18 - 2013-12-23 12:18 - 00000000 ____D C:\Program Files\iPod ==================== One Month Modified Files and Folders ======= 2014-01-18 13:47 - 2014-01-15 11:44 - 00009180 _____ C:\Users\Prinzessin\Desktop\FRST.txt 2014-01-18 13:46 - 2014-01-18 13:42 - 00000769 _____ C:\Users\Prinzessin\Desktop\JRT.txt 2014-01-18 13:46 - 2013-08-15 14:22 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3751189097-2915931777-4004511958-1001 2014-01-18 13:36 - 2013-08-22 17:42 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Dropbox 2014-01-18 13:33 - 2014-01-18 13:33 - 00000000 ____D C:\Windows\ERUNT 2014-01-18 13:31 - 2014-01-18 13:31 - 01037068 _____ (Thisisu) C:\Users\Prinzessin\Desktop\JRT.exe 2014-01-18 13:31 - 2013-08-22 17:46 - 00000000 ___RD C:\Users\Prinzessin\Documents\Dropbox 2014-01-18 13:30 - 2014-01-18 13:30 - 00001410 _____ C:\Users\Prinzessin\Desktop\AdwCleaner[S0].txt 2014-01-18 13:29 - 2013-08-24 16:38 - 00001126 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-18 13:29 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-18 13:28 - 2012-07-26 06:26 - 00524288 ___SH C:\Windows\system32\config\BBI 2014-01-18 13:27 - 2014-01-18 13:25 - 00000000 ____D C:\AdwCleaner 2014-01-18 13:22 - 2013-08-15 14:15 - 01262771 _____ C:\Windows\WindowsUpdate.log 2014-01-18 13:22 - 2013-08-15 14:04 - 00004044 _____ C:\Windows\PFRO.log 2014-01-18 13:11 - 2013-08-22 17:46 - 00000994 _____ C:\Users\Prinzessin\Desktop\Dropbox.lnk 2014-01-18 13:11 - 2013-08-22 17:44 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-18 13:11 - 2013-08-15 14:16 - 00000000 ___RD C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-18 13:09 - 2014-01-18 13:09 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-18 13:09 - 2014-01-18 13:09 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Malwarebytes 2014-01-18 13:09 - 2014-01-18 13:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-18 13:09 - 2014-01-18 13:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-18 13:08 - 2014-01-18 13:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Prinzessin\Downloads\mbam-setup- 2014-01-18 13:08 - 2014-01-18 13:08 - 01236282 _____ C:\Users\Prinzessin\Desktop\adwcleaner.exe 2014-01-18 13:04 - 2013-08-15 18:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-17 17:01 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\sru 2014-01-17 15:54 - 2013-08-24 16:38 - 00001130 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-15 12:21 - 2013-09-24 18:47 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-15 12:18 - 2013-08-15 18:20 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-15 12:18 - 2013-08-15 18:20 - 00000000 ____D C:\Windows\system32\MRT 2014-01-15 12:18 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\WinStore 2014-01-15 11:45 - 2014-01-15 11:45 - 00011156 _____ C:\Users\Prinzessin\Desktop\Addition.txt 2014-01-15 11:44 - 2014-01-15 11:44 - 00000000 ____D C:\FRST 2014-01-15 11:43 - 2014-01-15 11:43 - 02076160 _____ (Farbar) C:\Users\Prinzessin\Desktop\FRST64.exe 2014-01-15 10:39 - 2014-01-15 10:31 - 00048596 _____ C:\Users\Prinzessin\Desktop\Extras.Txt 2014-01-15 10:32 - 2014-01-15 10:31 - 00133010 _____ C:\Users\Prinzessin\Desktop\OTL.Txt 2014-01-15 10:10 - 2014-01-15 10:10 - 00602112 _____ (OldTimer Tools) C:\Users\Prinzessin\Desktop\OTL.exe 2014-01-15 10:03 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\AUInstallAgent 2014-01-13 17:49 - 2012-07-26 11:27 - 00715482 _____ C:\Windows\system32\perfh007.dat 2014-01-13 17:49 - 2012-07-26 11:27 - 00148046 _____ C:\Windows\system32\perfc007.dat 2014-01-13 17:49 - 2012-07-26 08:28 - 01654648 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-11 21:21 - 2014-01-11 21:21 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\vlc 2014-01-11 21:19 - 2014-01-11 21:19 - 00000871 _____ C:\Users\Public\Desktop\VLC media player.lnk 2014-01-11 21:19 - 2014-01-11 21:19 - 00000000 ____D C:\Program Files\VideoLAN 2014-01-11 21:15 - 2013-09-24 18:47 - 00000000 ____D C:\Users\Prinzessin\AppData\Local\Microsoft Help 2014-01-11 21:02 - 2014-01-11 21:01 - 24738792 _____ C:\Users\Prinzessin\Downloads\vlc-2.1.2-win64.exe 2014-01-09 12:16 - 2012-07-26 08:21 - 00017735 _____ C:\Windows\setupact.log 2014-01-09 09:02 - 2013-11-20 11:36 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-01-09 09:02 - 2013-11-20 11:36 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-06 20:39 - 2014-01-06 20:39 - 00518875 _____ C:\Users\Prinzessin\Downloads\HA_Statistic.zip 2014-01-06 20:39 - 2014-01-06 20:39 - 00000000 ____D C:\Users\Prinzessin\Downloads\HA_Statistic 2014-01-04 18:41 - 2013-08-24 10:56 - 00000000 ____D C:\Program Files (x86)\Nightly.bak 2014-01-04 15:32 - 2014-01-04 15:24 - 00004928 _____ C:\Windows\DPINST.LOG 2014-01-04 15:25 - 2014-01-04 15:25 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_Apfiltr_01009.Wdf 2014-01-04 15:25 - 2014-01-04 15:25 - 00000000 ____D C:\Program Files\DellTPad 2014-01-04 15:24 - 2014-01-04 15:24 - 00000000 ____D C:\ProgramData\Dell 2014-01-04 15:24 - 2014-01-04 15:18 - 69095472 _____ (Dell Inc.) C:\Users\Prinzessin\Downloads\Input_Driver_FGG85_WN_8.1200.101.214_A02.EXE 2014-01-04 15:16 - 2014-01-04 15:16 - 10121992 _____ C:\Users\Prinzessin\Downloads\Tocuhpad treiber.exe 2014-01-01 21:47 - 2014-01-01 21:47 - 00000000 ____D C:\Program Files (x86)\Nightly 2014-01-01 21:00 - 2013-12-01 21:33 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\FileZilla 2014-01-01 18:53 - 2014-01-01 18:43 - 00000000 ____D C:\Users\Prinzessin\Documents\Kiwilicious 2014-01-01 18:45 - 2013-12-28 19:51 - 00000000 ____D C:\Users\Prinzessin\Documents\XAMPP 2014-01-01 18:42 - 2014-01-01 18:42 - 00000676 _____ C:\Users\Prinzessin\Documents\cookie.html 2014-01-01 18:42 - 2014-01-01 18:42 - 00000512 _____ C:\Users\Prinzessin\Documents\.htaccess 2013-12-29 20:21 - 2013-12-29 20:21 - 00000000 ____D C:\Users\Prinzessin\Desktop\uploads 2013-12-29 14:34 - 2013-12-29 14:34 - 00322096 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-28 23:53 - 2013-12-28 23:53 - 21850807 _____ C:\Users\Prinzessin\Downloads\4725693899_2dbf489d5e_o.psd 2013-12-28 23:53 - 2013-12-28 23:53 - 21850807 _____ C:\Users\Prinzessin\Downloads\4725693899_2dbf489d5e_o (1).psd 2013-12-28 19:30 - 2013-12-28 19:30 - 00055224 _____ C:\Users\Prinzessin\Downloads\backerinchen.wordpress.2013-12-28.xml 2013-12-28 19:24 - 2013-12-28 19:24 - 00162710 _____ C:\Users\Prinzessin\Downloads\kiwilicious.wordpress.2013-12-28.xml 2013-12-28 19:15 - 2013-12-28 19:15 - 00000000 ____D C:\Users\Prinzessin\Downloads\wordpress-3.8 2013-12-28 19:13 - 2013-12-28 19:12 - 06367550 _____ C:\Users\Prinzessin\Downloads\wordpress-3.8.zip 2013-12-28 18:59 - 2013-12-28 18:59 - 00003217 _____ C:\Users\Prinzessin\Downloads\wp-config.php 2013-12-28 18:56 - 2013-12-27 20:56 - 00003495 _____ C:\Users\Prinzessin\Desktop\wp-config1.php 2013-12-28 17:42 - 2013-12-28 16:50 - 00000000 ____D C:\Program Files\XAMPP 2013-12-28 17:41 - 2013-12-28 17:41 - 03026171 _____ C:\Users\Prinzessin\Downloads\localhost.sql 2013-12-28 16:48 - 2013-12-28 16:47 - 123794144 _____ (BitNami) C:\Users\Prinzessin\Downloads\xampp-win32-1.8.3-2-VC11-installer.exe 2013-12-28 16:43 - 2013-12-28 16:38 - 00000961 _____ C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TextPad.lnk 2013-12-28 16:38 - 2013-12-28 16:38 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Helios 2013-12-28 16:38 - 2013-12-28 16:38 - 00000000 ____D C:\Program Files\TextPad 7 2013-12-28 16:37 - 2013-12-28 16:37 - 00000000 ____D C:\Users\Prinzessin\Downloads\txpdeu710 2013-12-28 16:22 - 2013-12-28 16:22 - 02842038 _____ C:\Users\Prinzessin\Downloads\bueno.zip 2013-12-28 16:21 - 2013-12-28 16:21 - 05173196 _____ C:\Users\Prinzessin\Downloads\irresistible.zip 2013-12-27 23:45 - 2013-12-27 23:45 - 00000071 _____ C:\Users\Prinzessin\Desktop\index.html 2013-12-27 22:36 - 2013-12-27 22:36 - 01621358 _____ C:\Users\Prinzessin\Downloads\customizr.3.1.5.zip 2013-12-27 21:54 - 2013-12-27 21:54 - 01651587 _____ C:\Users\Prinzessin\Downloads\hueman.1.2.7.zip 2013-12-27 21:54 - 2013-12-27 21:54 - 00000000 ____D C:\Users\Prinzessin\Downloads\hueman.1.2.7 2013-12-27 21:46 - 2013-12-27 21:46 - 00000000 ____D C:\Users\Prinzessin\Downloads\schatzhatskaputtgemacht 2013-12-27 21:45 - 2013-12-27 21:45 - 00029708 _____ C:\Users\Prinzessin\Downloads\schatzhatskaputtgemacht.zip 2013-12-27 21:10 - 2013-12-27 21:06 - 00000000 ____D C:\Users\Prinzessin\Desktop\Kiwilicious Backup 27.12 2013-12-27 21:06 - 2013-12-28 18:07 - 00000512 _____ C:\Users\Prinzessin\Desktop\.htaccess.backup 2013-12-23 12:38 - 2013-09-24 18:47 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-12-23 12:19 - 2013-12-23 12:19 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-12-23 12:19 - 2013-12-23 12:18 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-12-23 12:19 - 2013-12-23 12:18 - 00000000 ____D C:\Program Files\iTunes 2013-12-23 12:19 - 2013-12-23 12:18 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-12-23 12:18 - 2013-12-23 12:18 - 00000000 ____D C:\Program Files\iPod Some content of TEMP: ==================== C:\Users\Prinzessin\AppData\Local\Temp\ose00000.exe C:\Users\Prinzessin\AppData\Local\Temp\PrefJsonCpp.exe C:\Users\Prinzessin\AppData\Local\Temp\Quarantine.exe C:\Users\Prinzessin\AppData\Local\Temp\sqlite3.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-17 10:43 ==================== End Of Log ============================ --- --- --- --- --- --- Vielen Dank ![]() |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() VLC von der falschen Seite geladen..ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? ![]()
__________________ --> VLC von der falschen Seite geladen.. |
![]() | ![]() VLC von der falschen Seite geladen.. Puh, endlich alles gescannt. Hier die Logs. Probleme hab ich eigentlich keine. Die Startfenster Geschichten sind alle weg. Eine Frage hätt ich allerdings noch. Muss bzw soll ich den "falschen" VLC Player deinstallieren oder kann der bleiben? Eset log: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe= # OnlineScanner.ocx= # api_version=3.0.2 # EOSSerial=1a5f6564626fe14681c3925b99680853 # engine=16709 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2014-01-19 09:58:07 # local_time=2014-01-19 10:58:07 (+0100, Mitteleuropäische Zeit) # country="Germany" # lang=1033 # osver=6.2.9200 NT # compatibility_mode=5893 16776573 100 94 38406 17452162 0 0 # scanned=232511 # found=0 # cleaned=0 # scan_time=36013 Code:
ATTFilter Results of screen317's Security Check version 0.99.79 x64 (UAC is enabled) Internet Explorer 10 Out of date! ``````````````Antivirus/Firewall Check:`````````````` Windows Defender WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version Java 7 Update 45 Java version out of Date! Adobe Reader XI Google Chrome 31.0.1650.63 Google Chrome 32.0.1700.76 ````````Process Check: objlist.exe by Laurent```````` Windows Defender MSMpEng.exe Windows Defender MsMpEng.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 19-01-2014 04 Ran by Prinzessin (administrator) on LILLI on 19-01-2014 23:21:15 Running from C:\Users\Prinzessin\Desktop Windows 8 Pro (X64) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Normal ==================== Processes (Whitelisted) ================= (Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\scheduler.exe (Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\FCDBLog.exe (brother Industries Ltd) C:\Windows\SysWOW64\BRSVC01A.EXE (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (Microsoft Corporation) C:\Windows\System32\dasHost.exe (Microsoft Corporation) C:\Program Files\Windows Defender\MsMpEng.exe (brother Industries Ltd) C:\Windows\SysWOW64\BRSS01A.EXE (Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler.exe (Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\FCHelper.exe (Google Inc.) C:\Program Files (x86)\Google\Update\\GoogleCrashHandler64.exe () C:\Program Files (x86)\Google\Update\Install\{FC8C7E33-1531-4429-9F23-3BB717CE4201}\32.0.1700.76_31.0.1650.63_chrome_updater.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\31.0.1650.63\Installer\setup.exe (Fortinet Inc.) C:\Program Files (x86)\Fortinet\FortiClient\FortiTray.exe (Microsoft Corporation) C:\Program Files\WindowsApps\microsoft.windowscommunicationsapps_17.0.1119.516_x64__8wekyb3d8bbwe\LiveComm.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Dropbox, Inc.) C:\Users\Prinzessin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Oracle Corporation) C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe (Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Internet Services\APSDaemon.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe (Microsoft Corporation) C:\Windows\System32\WWAHost.exe (Microsoft Corporation) C:\Windows\System32\SnippingTool.exe (Microsoft Corporation) C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation) C:\Windows\splwow64.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AcroRd32.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Microsoft Corporation) C:\Windows\System32\WWAHost.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe ==================== Registry (Whitelisted) ================== HKLM\...\Run: [Apoint] - C:\Program Files\DellTPad\Apoint.exe [682904 2012-09-20] (Alps Electric Co., Ltd.) HKLM-x32\...\Run: [APSDaemon] - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe [59720 2013-04-21] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [958576 2013-05-11] (Adobe Systems Incorporated) HKLM-x32\...\Run: [PDFPrint] - C:\Program Files (x86)\PDF24\pdf24.exe [162856 2013-07-22] (Geek Software GmbH) HKLM-x32\...\Run: [SunJavaUpdateSched] - C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe [254336 2013-07-02] (Oracle Corporation) HKLM-x32\...\Run: [iTunesHelper] - C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2013-11-02] (Apple Inc.) HKCU\...\Run: [ApplePhotoStreams] - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe [59720 2013-11-20] (Apple Inc.) Startup: C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk ShortcutTarget: Dropbox.lnk -> C:\Users\Prinzessin\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.) ==================== Internet (Whitelisted) ==================== HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://t.de.msn.com/ HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 0xE3CA919EFC03CF01 HKCU\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de-DE SearchScopes: HKLM - DefaultScope {20B1356B-8C0D-4BA9-907C-B5A739CC1D05} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKLM - {20B1356B-8C0D-4BA9-907C-B5A739CC1D05} URL = hxxp://www.sm.de/?q={searchTerms} SearchScopes: HKCU - {20B1356B-8C0D-4BA9-907C-B5A739CC1D05} URL = hxxp://www.sm.de/?q={searchTerms} BHO-x32: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation) BHO-x32: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation) Tcpip\Parameters: [DhcpNameServer] FireFox: ======== FF ProfilePath: C:\Users\Prinzessin\AppData\Roaming\Mozilla\Firefox\Profiles\jp8va1ae.default FF NetworkProxy: "http", "proxy.fh-brandenburg.de" FF NetworkProxy: "http_port", 3128 FF NetworkProxy: "type", 4 FF Plugin: @videolan.org/vlc,version=2.1.2 - C:\Program Files\VideoLAN\VLC\npvlc.dll (VideoLAN) FF Plugin-x32: @Apple.com/iTunes,version=1.0 - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF Plugin-x32: @java.com/DTPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation) FF Plugin-x32: @java.com/JavaPlugin,version=10.45.2 - C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation) FF Plugin-x32: @microsoft.com/OfficeLive,version=1.5 - C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll (Microsoft Corp.) FF Plugin-x32: @tools.google.com/Google Update;version=3 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll (Google Inc.) FF Plugin-x32: Adobe Reader - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) FF StartMenuInternet: FIREFOX.EXE - C:\Program Files (x86)\Nightly\firefox.exe Chrome: ======= CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\PepperFlash\pepflashplayer.dll () CHR Plugin: (Chrome Remote Desktop Viewer) - internal-remoting-viewer CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\ppGoogleNaClPluginChrome.dll () CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\32.0.1700.76\pdf.dll () CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.) CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\\npGoogleUpdate3.dll No File CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () CHR Extension: (Google Docs) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake [2013-08-24] CHR Extension: (Google Drive) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf [2013-08-24] CHR Extension: (YouTube) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2013-08-24] CHR Extension: (Google-Suche) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2013-08-24] CHR Extension: (iCloud-Lesezeichen) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkepacicchenbjecpbpbclokcabebhah [2013-11-09] CHR Extension: (Hola Besseres Internet) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio [2013-09-24] CHR Extension: (Google Wallet) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-24] CHR Extension: (Google Mail) - C:\Users\Prinzessin\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2013-08-24] ==================== Services (Whitelisted) ================= U2 Brother XP spl Service; C:\Windows\SysWOW64\brsvc01a.exe [57344 2004-06-13] (brother Industries Ltd) U2 FA_Scheduler; C:\Program Files (x86)\Fortinet\FortiClient\scheduler.exe [73746 2012-08-14] (Fortinet Inc.) U2 WinDefend; C:\Program Files\Windows Defender\MsMpEng.exe [16048 2013-07-02] (Microsoft Corporation) ==================== Drivers (Whitelisted) ==================== U3 BCM43XX; C:\Windows\system32\DRIVERS\bcmwl63a.sys [5139968 2012-06-02] (Broadcom Corporation) U3 fortiapd; C:\Windows\System32\drivers\fortiapd.sys [15656 2012-08-14] (Fortinet Inc) U1 FortiFilter; C:\Windows\system32\DRIVERS\FortiFilter.sys [23928 2011-09-09] (Fortinet Inc) U3 Fortips; C:\Windows\System32\drivers\fortips.sys [126760 2012-08-14] (Fortinet Inc) U3 FortiRdr; C:\Windows\System32\drivers\FortiRdr2.sys [46888 2012-08-14] (Fortinet Inc) U3 ft_vnic; C:\Windows\system32\DRIVERS\ftvnic.sys [16928 2011-03-21] (Fortinet Inc.) ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2014-01-19 23:21 - 2014-01-19 23:21 - 00000000 ____D C:\Users\Prinzessin\Desktop\FRST-OlderVersion 2014-01-19 23:20 - 2014-01-19 23:20 - 00000917 _____ C:\Users\Prinzessin\Desktop\checkup.txt 2014-01-19 23:18 - 2014-01-19 23:18 - 00987425 _____ C:\Users\Prinzessin\Desktop\SecurityCheck.exe 2014-01-19 12:55 - 2014-01-19 12:55 - 02347384 _____ (ESET) C:\Users\Prinzessin\Downloads\esetsmartinstaller_enu.exe 2014-01-18 13:42 - 2014-01-18 13:46 - 00000769 _____ C:\Users\Prinzessin\Desktop\JRT.txt 2014-01-18 13:33 - 2014-01-18 13:33 - 00000000 ____D C:\Windows\ERUNT 2014-01-18 13:31 - 2014-01-18 13:31 - 01037068 _____ (Thisisu) C:\Users\Prinzessin\Desktop\JRT.exe 2014-01-18 13:30 - 2014-01-18 13:30 - 00001410 _____ C:\Users\Prinzessin\Desktop\AdwCleaner[S0].txt 2014-01-18 13:25 - 2014-01-18 13:27 - 00000000 ____D C:\AdwCleaner 2014-01-18 13:09 - 2014-01-18 13:09 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-18 13:09 - 2014-01-18 13:09 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Malwarebytes 2014-01-18 13:09 - 2014-01-18 13:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-18 13:09 - 2014-01-18 13:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-18 13:09 - 2013-04-04 14:50 - 00025928 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\mbam.sys 2014-01-18 13:08 - 2014-01-18 13:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Prinzessin\Downloads\mbam-setup- 2014-01-18 13:08 - 2014-01-18 13:08 - 01236282 _____ C:\Users\Prinzessin\Desktop\adwcleaner.exe 2014-01-15 11:45 - 2014-01-15 11:45 - 00011156 _____ C:\Users\Prinzessin\Desktop\Addition.txt 2014-01-15 11:44 - 2014-01-19 23:21 - 00010552 _____ C:\Users\Prinzessin\Desktop\FRST.txt 2014-01-15 11:44 - 2014-01-19 23:21 - 00000000 ____D C:\FRST 2014-01-15 11:43 - 2014-01-19 23:21 - 02076672 _____ (Farbar) C:\Users\Prinzessin\Desktop\FRST64.exe 2014-01-15 11:08 - 2013-12-07 07:37 - 00688640 _____ (Microsoft Corporation) C:\Windows\system32\WSShared.dll 2014-01-15 11:08 - 2013-12-07 07:37 - 00163840 _____ (Microsoft Corporation) C:\Windows\system32\Windows.ApplicationModel.Store.TestingFramework.dll 2014-01-15 11:08 - 2013-12-07 06:15 - 00562688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WSShared.dll 2014-01-15 11:08 - 2013-12-07 06:15 - 00124928 _____ (Microsoft Corporation) C:\Windows\SysWOW64\Windows.ApplicationModel.Store.TestingFramework.dll 2014-01-15 11:08 - 2013-10-31 06:56 - 00915968 _____ (Microsoft Corporation) C:\Windows\system32\MPSSVC.dll 2014-01-15 11:08 - 2013-10-31 06:56 - 00758784 _____ (Microsoft Corporation) C:\Windows\system32\FirewallAPI.dll 2014-01-15 11:08 - 2013-10-31 05:01 - 00550400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\FirewallAPI.dll 2014-01-15 11:08 - 2013-10-31 04:42 - 00074752 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\mpsdrv.sys 2014-01-15 11:08 - 2013-10-28 06:50 - 00588288 _____ (Microsoft Corporation) C:\Windows\system32\SHCore.dll 2014-01-15 11:08 - 2013-10-28 05:05 - 00452608 _____ (Microsoft Corporation) C:\Windows\SysWOW64\SHCore.dll 2014-01-15 11:08 - 2013-10-13 21:49 - 00100696 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\disk.sys 2014-01-15 11:08 - 2013-08-27 06:21 - 00227840 _____ (Microsoft Corporation) C:\Windows\system32\WebClnt.dll 2014-01-15 11:08 - 2013-08-27 06:19 - 00104448 _____ (Microsoft Corporation) C:\Windows\system32\davclnt.dll 2014-01-15 11:08 - 2013-08-26 23:29 - 00199168 _____ (Microsoft Corporation) C:\Windows\SysWOW64\WebClnt.dll 2014-01-15 11:08 - 2013-08-26 23:28 - 00086016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\davclnt.dll 2014-01-15 10:31 - 2014-01-15 10:39 - 00048596 _____ C:\Users\Prinzessin\Desktop\Extras.Txt 2014-01-15 10:31 - 2014-01-15 10:32 - 00133010 _____ C:\Users\Prinzessin\Desktop\OTL.Txt 2014-01-15 10:10 - 2014-01-15 10:10 - 00602112 _____ (OldTimer Tools) C:\Users\Prinzessin\Desktop\OTL.exe 2014-01-11 21:21 - 2014-01-19 16:02 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\vlc 2014-01-11 21:19 - 2014-01-11 21:19 - 00000871 _____ C:\Users\Public\Desktop\VLC media player.lnk 2014-01-11 21:19 - 2014-01-11 21:19 - 00000000 ____D C:\Program Files\VideoLAN 2014-01-11 21:01 - 2014-01-11 21:02 - 24738792 _____ C:\Users\Prinzessin\Downloads\vlc-2.1.2-win64.exe 2014-01-06 20:39 - 2014-01-06 20:39 - 00518875 _____ C:\Users\Prinzessin\Downloads\HA_Statistic.zip 2014-01-06 20:39 - 2014-01-06 20:39 - 00000000 ____D C:\Users\Prinzessin\Downloads\HA_Statistic 2014-01-04 15:25 - 2014-01-04 15:25 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_Apfiltr_01009.Wdf 2014-01-04 15:25 - 2014-01-04 15:25 - 00000000 ____D C:\Program Files\DellTPad 2014-01-04 15:24 - 2014-01-04 15:32 - 00004928 _____ C:\Windows\DPINST.LOG 2014-01-04 15:24 - 2014-01-04 15:24 - 00000000 ____D C:\ProgramData\Dell 2014-01-04 15:24 - 2012-09-19 06:46 - 00447864 _____ (Alps Electric Co., Ltd.) C:\Windows\system32\Drivers\Apfiltr.sys 2014-01-04 15:24 - 2012-05-17 14:08 - 00113048 _____ (Alps Electric Co., Ltd.) C:\Windows\system32\Vxdif.dll 2014-01-04 15:24 - 2009-07-14 09:51 - 01721576 _____ (Microsoft Corporation) C:\Windows\system32\WdfCoInstaller01009.dll 2014-01-04 15:18 - 2014-01-04 15:24 - 69095472 _____ (Dell Inc.) C:\Users\Prinzessin\Downloads\Input_Driver_FGG85_WN_8.1200.101.214_A02.EXE 2014-01-04 15:16 - 2014-01-04 15:16 - 10121992 _____ C:\Users\Prinzessin\Downloads\Tocuhpad treiber.exe 2014-01-01 21:47 - 2014-01-01 21:47 - 00000000 ____D C:\Program Files (x86)\Nightly 2014-01-01 18:43 - 2014-01-01 18:53 - 00000000 ____D C:\Users\Prinzessin\Documents\Kiwilicious 2014-01-01 18:42 - 2014-01-01 18:42 - 00000676 _____ C:\Users\Prinzessin\Documents\cookie.html 2014-01-01 18:42 - 2014-01-01 18:42 - 00000512 _____ C:\Users\Prinzessin\Documents\.htaccess 2013-12-29 20:21 - 2013-12-29 20:21 - 00000000 ____D C:\Users\Prinzessin\Desktop\uploads 2013-12-29 14:34 - 2013-12-29 14:34 - 00322096 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-28 23:53 - 2013-12-28 23:53 - 21850807 _____ C:\Users\Prinzessin\Downloads\4725693899_2dbf489d5e_o.psd 2013-12-28 23:53 - 2013-12-28 23:53 - 21850807 _____ C:\Users\Prinzessin\Downloads\4725693899_2dbf489d5e_o (1).psd 2013-12-28 19:51 - 2014-01-01 18:45 - 00000000 ____D C:\Users\Prinzessin\Documents\XAMPP 2013-12-28 19:30 - 2013-12-28 19:30 - 00055224 _____ C:\Users\Prinzessin\Downloads\backerinchen.wordpress.2013-12-28.xml 2013-12-28 19:24 - 2013-12-28 19:24 - 00162710 _____ C:\Users\Prinzessin\Downloads\kiwilicious.wordpress.2013-12-28.xml 2013-12-28 19:15 - 2013-12-28 19:15 - 00000000 ____D C:\Users\Prinzessin\Downloads\wordpress-3.8 2013-12-28 19:12 - 2013-12-28 19:13 - 06367550 _____ C:\Users\Prinzessin\Downloads\wordpress-3.8.zip 2013-12-28 18:59 - 2013-12-28 18:59 - 00003217 _____ C:\Users\Prinzessin\Downloads\wp-config.php 2013-12-28 18:07 - 2013-12-27 21:06 - 00000512 _____ C:\Users\Prinzessin\Desktop\.htaccess.backup 2013-12-28 17:41 - 2013-12-28 17:41 - 03026171 _____ C:\Users\Prinzessin\Downloads\localhost.sql 2013-12-28 16:50 - 2013-12-28 17:42 - 00000000 ____D C:\Program Files\XAMPP 2013-12-28 16:47 - 2013-12-28 16:48 - 123794144 _____ (BitNami) C:\Users\Prinzessin\Downloads\xampp-win32-1.8.3-2-VC11-installer.exe 2013-12-28 16:38 - 2013-12-28 16:43 - 00000961 _____ C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TextPad.lnk 2013-12-28 16:38 - 2013-12-28 16:38 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Helios 2013-12-28 16:38 - 2013-12-28 16:38 - 00000000 ____D C:\Program Files\TextPad 7 2013-12-28 16:37 - 2013-12-28 16:37 - 00000000 ____D C:\Users\Prinzessin\Downloads\txpdeu710 2013-12-28 16:22 - 2013-12-28 16:22 - 02842038 _____ C:\Users\Prinzessin\Downloads\bueno.zip 2013-12-28 16:21 - 2013-12-28 16:21 - 05173196 _____ C:\Users\Prinzessin\Downloads\irresistible.zip 2013-12-27 23:45 - 2013-12-27 23:45 - 00000071 _____ C:\Users\Prinzessin\Desktop\index.html 2013-12-27 22:36 - 2013-12-27 22:36 - 01621358 _____ C:\Users\Prinzessin\Downloads\customizr.3.1.5.zip 2013-12-27 21:54 - 2013-12-27 21:54 - 01651587 _____ C:\Users\Prinzessin\Downloads\hueman.1.2.7.zip 2013-12-27 21:54 - 2013-12-27 21:54 - 00000000 ____D C:\Users\Prinzessin\Downloads\hueman.1.2.7 2013-12-27 21:46 - 2013-12-27 21:46 - 00000000 ____D C:\Users\Prinzessin\Downloads\schatzhatskaputtgemacht 2013-12-27 21:45 - 2013-12-27 21:45 - 00029708 _____ C:\Users\Prinzessin\Downloads\schatzhatskaputtgemacht.zip 2013-12-27 21:06 - 2013-12-27 21:10 - 00000000 ____D C:\Users\Prinzessin\Desktop\Kiwilicious Backup 27.12 2013-12-27 20:56 - 2013-12-28 18:56 - 00003495 _____ C:\Users\Prinzessin\Desktop\wp-config1.php 2013-12-23 12:19 - 2013-12-23 12:19 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-12-23 12:18 - 2013-12-23 12:19 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-12-23 12:18 - 2013-12-23 12:19 - 00000000 ____D C:\Program Files\iTunes 2013-12-23 12:18 - 2013-12-23 12:19 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-12-23 12:18 - 2013-12-23 12:18 - 00000000 ____D C:\Program Files\iPod ==================== One Month Modified Files and Folders ======= 2014-01-19 23:21 - 2014-01-19 23:21 - 00000000 ____D C:\Users\Prinzessin\Desktop\FRST-OlderVersion 2014-01-19 23:21 - 2014-01-15 11:44 - 00010552 _____ C:\Users\Prinzessin\Desktop\FRST.txt 2014-01-19 23:21 - 2014-01-15 11:44 - 00000000 ____D C:\FRST 2014-01-19 23:21 - 2014-01-15 11:43 - 02076672 _____ (Farbar) C:\Users\Prinzessin\Desktop\FRST64.exe 2014-01-19 23:20 - 2014-01-19 23:20 - 00000917 _____ C:\Users\Prinzessin\Desktop\checkup.txt 2014-01-19 23:18 - 2014-01-19 23:18 - 00987425 _____ C:\Users\Prinzessin\Desktop\SecurityCheck.exe 2014-01-19 23:13 - 2013-08-22 17:42 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Dropbox 2014-01-19 23:00 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\system32\sru 2014-01-19 22:53 - 2013-08-24 16:38 - 00001130 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2014-01-19 21:53 - 2013-08-24 16:38 - 00001126 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2014-01-19 16:02 - 2014-01-11 21:21 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\vlc 2014-01-19 13:46 - 2013-08-15 14:15 - 01364415 _____ C:\Windows\WindowsUpdate.log 2014-01-19 12:55 - 2014-01-19 12:55 - 02347384 _____ (ESET) C:\Users\Prinzessin\Downloads\esetsmartinstaller_enu.exe 2014-01-18 20:50 - 2012-07-26 11:27 - 00715482 _____ C:\Windows\system32\perfh007.dat 2014-01-18 20:50 - 2012-07-26 11:27 - 00148046 _____ C:\Windows\system32\perfc007.dat 2014-01-18 20:50 - 2012-07-26 08:28 - 01654648 _____ C:\Windows\system32\PerfStringBackup.INI 2014-01-18 18:54 - 2013-08-24 16:39 - 00002175 _____ C:\Users\Public\Desktop\Google Chrome.lnk 2014-01-18 17:53 - 2013-08-15 14:22 - 00003600 _____ C:\Windows\System32\Tasks\Optimize Start Menu Cache Files-S-1-5-21-3751189097-2915931777-4004511958-1001 2014-01-18 17:39 - 2013-08-22 17:46 - 00000000 ___RD C:\Users\Prinzessin\Documents\Dropbox 2014-01-18 13:46 - 2014-01-18 13:42 - 00000769 _____ C:\Users\Prinzessin\Desktop\JRT.txt 2014-01-18 13:33 - 2014-01-18 13:33 - 00000000 ____D C:\Windows\ERUNT 2014-01-18 13:31 - 2014-01-18 13:31 - 01037068 _____ (Thisisu) C:\Users\Prinzessin\Desktop\JRT.exe 2014-01-18 13:30 - 2014-01-18 13:30 - 00001410 _____ C:\Users\Prinzessin\Desktop\AdwCleaner[S0].txt 2014-01-18 13:29 - 2012-07-26 08:22 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2014-01-18 13:28 - 2012-07-26 06:26 - 00524288 ___SH C:\Windows\system32\config\BBI 2014-01-18 13:27 - 2014-01-18 13:25 - 00000000 ____D C:\AdwCleaner 2014-01-18 13:22 - 2013-08-15 14:04 - 00004044 _____ C:\Windows\PFRO.log 2014-01-18 13:11 - 2013-08-22 17:46 - 00000994 _____ C:\Users\Prinzessin\Desktop\Dropbox.lnk 2014-01-18 13:11 - 2013-08-22 17:44 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Dropbox 2014-01-18 13:11 - 2013-08-15 14:16 - 00000000 ___RD C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup 2014-01-18 13:09 - 2014-01-18 13:09 - 00001113 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2014-01-18 13:09 - 2014-01-18 13:09 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Malwarebytes 2014-01-18 13:09 - 2014-01-18 13:09 - 00000000 ____D C:\ProgramData\Malwarebytes 2014-01-18 13:09 - 2014-01-18 13:09 - 00000000 ____D C:\Program Files (x86)\Malwarebytes' Anti-Malware 2014-01-18 13:08 - 2014-01-18 13:08 - 10285040 _____ (Malwarebytes Corporation ) C:\Users\Prinzessin\Downloads\mbam-setup- 2014-01-18 13:08 - 2014-01-18 13:08 - 01236282 _____ C:\Users\Prinzessin\Desktop\adwcleaner.exe 2014-01-18 13:04 - 2013-08-15 18:33 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2014-01-15 12:21 - 2013-09-24 18:47 - 00000000 ____D C:\ProgramData\Microsoft Help 2014-01-15 12:20 - 2013-08-15 18:20 - 00000000 ____D C:\Windows\system32\MRT 2014-01-15 12:18 - 2013-08-15 18:20 - 86054176 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe 2014-01-15 12:18 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\WinStore 2014-01-15 11:45 - 2014-01-15 11:45 - 00011156 _____ C:\Users\Prinzessin\Desktop\Addition.txt 2014-01-15 10:39 - 2014-01-15 10:31 - 00048596 _____ C:\Users\Prinzessin\Desktop\Extras.Txt 2014-01-15 10:32 - 2014-01-15 10:31 - 00133010 _____ C:\Users\Prinzessin\Desktop\OTL.Txt 2014-01-15 10:10 - 2014-01-15 10:10 - 00602112 _____ (OldTimer Tools) C:\Users\Prinzessin\Desktop\OTL.exe 2014-01-15 10:03 - 2012-07-26 09:12 - 00000000 ____D C:\Windows\AUInstallAgent 2014-01-11 21:19 - 2014-01-11 21:19 - 00000871 _____ C:\Users\Public\Desktop\VLC media player.lnk 2014-01-11 21:19 - 2014-01-11 21:19 - 00000000 ____D C:\Program Files\VideoLAN 2014-01-11 21:15 - 2013-09-24 18:47 - 00000000 ____D C:\Users\Prinzessin\AppData\Local\Microsoft Help 2014-01-11 21:02 - 2014-01-11 21:01 - 24738792 _____ C:\Users\Prinzessin\Downloads\vlc-2.1.2-win64.exe 2014-01-09 12:16 - 2012-07-26 08:21 - 00017735 _____ C:\Windows\setupact.log 2014-01-09 09:02 - 2013-11-20 11:36 - 00694240 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2014-01-09 09:02 - 2013-11-20 11:36 - 00078296 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2014-01-06 20:39 - 2014-01-06 20:39 - 00518875 _____ C:\Users\Prinzessin\Downloads\HA_Statistic.zip 2014-01-06 20:39 - 2014-01-06 20:39 - 00000000 ____D C:\Users\Prinzessin\Downloads\HA_Statistic 2014-01-04 18:41 - 2013-08-24 10:56 - 00000000 ____D C:\Program Files (x86)\Nightly.bak 2014-01-04 15:32 - 2014-01-04 15:24 - 00004928 _____ C:\Windows\DPINST.LOG 2014-01-04 15:25 - 2014-01-04 15:25 - 00000000 ____H C:\Windows\system32\Drivers\Msft_Kernel_Apfiltr_01009.Wdf 2014-01-04 15:25 - 2014-01-04 15:25 - 00000000 ____D C:\Program Files\DellTPad 2014-01-04 15:24 - 2014-01-04 15:24 - 00000000 ____D C:\ProgramData\Dell 2014-01-04 15:24 - 2014-01-04 15:18 - 69095472 _____ (Dell Inc.) C:\Users\Prinzessin\Downloads\Input_Driver_FGG85_WN_8.1200.101.214_A02.EXE 2014-01-04 15:16 - 2014-01-04 15:16 - 10121992 _____ C:\Users\Prinzessin\Downloads\Tocuhpad treiber.exe 2014-01-01 21:47 - 2014-01-01 21:47 - 00000000 ____D C:\Program Files (x86)\Nightly 2014-01-01 21:00 - 2013-12-01 21:33 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\FileZilla 2014-01-01 18:53 - 2014-01-01 18:43 - 00000000 ____D C:\Users\Prinzessin\Documents\Kiwilicious 2014-01-01 18:45 - 2013-12-28 19:51 - 00000000 ____D C:\Users\Prinzessin\Documents\XAMPP 2014-01-01 18:42 - 2014-01-01 18:42 - 00000676 _____ C:\Users\Prinzessin\Documents\cookie.html 2014-01-01 18:42 - 2014-01-01 18:42 - 00000512 _____ C:\Users\Prinzessin\Documents\.htaccess 2013-12-29 20:21 - 2013-12-29 20:21 - 00000000 ____D C:\Users\Prinzessin\Desktop\uploads 2013-12-29 14:34 - 2013-12-29 14:34 - 00322096 _____ C:\Windows\system32\FNTCACHE.DAT 2013-12-28 23:53 - 2013-12-28 23:53 - 21850807 _____ C:\Users\Prinzessin\Downloads\4725693899_2dbf489d5e_o.psd 2013-12-28 23:53 - 2013-12-28 23:53 - 21850807 _____ C:\Users\Prinzessin\Downloads\4725693899_2dbf489d5e_o (1).psd 2013-12-28 19:30 - 2013-12-28 19:30 - 00055224 _____ C:\Users\Prinzessin\Downloads\backerinchen.wordpress.2013-12-28.xml 2013-12-28 19:24 - 2013-12-28 19:24 - 00162710 _____ C:\Users\Prinzessin\Downloads\kiwilicious.wordpress.2013-12-28.xml 2013-12-28 19:15 - 2013-12-28 19:15 - 00000000 ____D C:\Users\Prinzessin\Downloads\wordpress-3.8 2013-12-28 19:13 - 2013-12-28 19:12 - 06367550 _____ C:\Users\Prinzessin\Downloads\wordpress-3.8.zip 2013-12-28 18:59 - 2013-12-28 18:59 - 00003217 _____ C:\Users\Prinzessin\Downloads\wp-config.php 2013-12-28 18:56 - 2013-12-27 20:56 - 00003495 _____ C:\Users\Prinzessin\Desktop\wp-config1.php 2013-12-28 17:42 - 2013-12-28 16:50 - 00000000 ____D C:\Program Files\XAMPP 2013-12-28 17:41 - 2013-12-28 17:41 - 03026171 _____ C:\Users\Prinzessin\Downloads\localhost.sql 2013-12-28 16:48 - 2013-12-28 16:47 - 123794144 _____ (BitNami) C:\Users\Prinzessin\Downloads\xampp-win32-1.8.3-2-VC11-installer.exe 2013-12-28 16:43 - 2013-12-28 16:38 - 00000961 _____ C:\Users\Prinzessin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TextPad.lnk 2013-12-28 16:38 - 2013-12-28 16:38 - 00000000 ____D C:\Users\Prinzessin\AppData\Roaming\Helios 2013-12-28 16:38 - 2013-12-28 16:38 - 00000000 ____D C:\Program Files\TextPad 7 2013-12-28 16:37 - 2013-12-28 16:37 - 00000000 ____D C:\Users\Prinzessin\Downloads\txpdeu710 2013-12-28 16:22 - 2013-12-28 16:22 - 02842038 _____ C:\Users\Prinzessin\Downloads\bueno.zip 2013-12-28 16:21 - 2013-12-28 16:21 - 05173196 _____ C:\Users\Prinzessin\Downloads\irresistible.zip 2013-12-27 23:45 - 2013-12-27 23:45 - 00000071 _____ C:\Users\Prinzessin\Desktop\index.html 2013-12-27 22:36 - 2013-12-27 22:36 - 01621358 _____ C:\Users\Prinzessin\Downloads\customizr.3.1.5.zip 2013-12-27 21:54 - 2013-12-27 21:54 - 01651587 _____ C:\Users\Prinzessin\Downloads\hueman.1.2.7.zip 2013-12-27 21:54 - 2013-12-27 21:54 - 00000000 ____D C:\Users\Prinzessin\Downloads\hueman.1.2.7 2013-12-27 21:46 - 2013-12-27 21:46 - 00000000 ____D C:\Users\Prinzessin\Downloads\schatzhatskaputtgemacht 2013-12-27 21:45 - 2013-12-27 21:45 - 00029708 _____ C:\Users\Prinzessin\Downloads\schatzhatskaputtgemacht.zip 2013-12-27 21:10 - 2013-12-27 21:06 - 00000000 ____D C:\Users\Prinzessin\Desktop\Kiwilicious Backup 27.12 2013-12-27 21:06 - 2013-12-28 18:07 - 00000512 _____ C:\Users\Prinzessin\Desktop\.htaccess.backup 2013-12-23 12:38 - 2013-09-24 18:47 - 00000000 ____D C:\Program Files (x86)\Microsoft Office 2013-12-23 12:19 - 2013-12-23 12:19 - 00001783 _____ C:\Users\Public\Desktop\iTunes.lnk 2013-12-23 12:19 - 2013-12-23 12:18 - 00000000 ____D C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69 2013-12-23 12:19 - 2013-12-23 12:18 - 00000000 ____D C:\Program Files\iTunes 2013-12-23 12:19 - 2013-12-23 12:18 - 00000000 ____D C:\Program Files (x86)\iTunes 2013-12-23 12:18 - 2013-12-23 12:18 - 00000000 ____D C:\Program Files\iPod Some content of TEMP: ==================== C:\Users\Prinzessin\AppData\Local\Temp\ose00000.exe C:\Users\Prinzessin\AppData\Local\Temp\PrefJsonCpp.exe C:\Users\Prinzessin\AppData\Local\Temp\Quarantine.exe C:\Users\Prinzessin\AppData\Local\Temp\sqlite3.exe ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\rpcss.dll => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit LastRegBack: 2014-01-17 10:43 ==================== End Of Log ============================ |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() VLC von der falschen Seite geladen.. Der kann bleiben ![]() Fertig ![]() Falls Du Lob oder Kritik loswerden möchtest kannst Du das hier tun ![]() Die Reihenfolge ist hier entscheidend.
Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | ![]() VLC von der falschen Seite geladen.. Alles erledigt. Vielen vielen Dank nochmal für die tolle und schnelle Hilfe ![]() |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() VLC von der falschen Seite geladen.. Gern Geschehen ![]()
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
