Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
RKIT/agent.depg.1 in BAcroIEHelpe171.dll gefunden - was tun?
hier nun das log des OTL-Fix.
Hat geklappt diesmal
Beim Versuch, mich ins Netz einzuwählen beschwerte sich Windows, dass die RAS-Verbindungsverwaltung nicht gestartet werden konnte, da der Dienst nicht rechtzeitig gestartet wurde. Hat sich, denke ich, nur verschluckt, Sekunden später ging es dann.
Code:
ATTFilter
All processes killed
========== PROCESSES ==========
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully!
HKEY_USERS\S-1-5-21-2114326357-1576578402-1589539351-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-2114326357-1576578402-1589539351-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
HKU\S-1-5-21-2114326357-1576578402-1589539351-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
File C:\Program Files\Google\Update\1.3.21.111\npGoogleUpdate3.dll not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\Users\***\AppData\Roaming\UAs folder moved successfully.
C:\Users\***\AppData\Roaming\xmldm folder moved successfully.
C:\Users\***\AppData\Roaming\kock folder moved successfully.
C:\Users\***\AppData\Roaming\blckdom.res moved successfully.
C:\Users\***\AppData\Roaming\05001.056\components folder moved successfully.
C:\Users\***\AppData\Roaming\05001.056 folder moved successfully.
C:\Users\***\AppData\Roaming\05001.058\components folder moved successfully.
C:\Users\***\AppData\Roaming\05001.058 folder moved successfully.
C:\Users\***\AppData\Roaming\05001.057\components folder moved successfully.
C:\Users\***\AppData\Roaming\05001.057 folder moved successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\***\Desktop\cmd.bat deleted successfully.
C:\Users\***\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: ***
->Temp folder emptied: 89332098 bytes
->Temporary Internet Files folder emptied: 2862417 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 53688506 bytes
->Google Chrome cache emptied: 8511216 bytes
->Flash cache emptied: 726 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 445830 bytes
RecycleBin emptied: 121202 bytes
Total Files Cleaned = 148,00 mb
[EMPTYFLASH]
User: Administrator
->Flash cache emptied: 0 bytes
User: All Users
User: Default
->Flash cache emptied: 0 bytes
User: Default User
->Flash cache emptied: 0 bytes
User: ***
->Flash cache emptied: 0 bytes
User: Public
Total Flash Files Cleaned = 0,00 mb
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYJAVA]
User: Administrator
User: All Users
User: Default
User: Default User
User: ***
->Java cache emptied: 0 bytes
User: Public
Total Java Files Cleaned = 0,00 mb
Restore point Set: OTL Restore Point
OTL by OldTimer - Version 3.2.54.1 log created on 07262012_164533
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
Themen zu RKIT/agent.depg.1 in BAcroIEHelpe171.dll gefunden - was tun?
Zum Thema RKIT/agent.depg.1 in BAcroIEHelpe171.dll gefunden - was tun? - hier nun das log des OTL-Fix.
Hat geklappt diesmal
Beim Versuch, mich ins Netz einzuwählen beschwerte sich Windows, dass die RAS-Verbindungsverwaltung nicht gestartet werden konnte, da der Dienst nicht rechtzeitig - RKIT/agent.depg.1 in BAcroIEHelpe171.dll gefunden - was tun?...