![]() |
| |||||||
Log-Analyse und Auswertung: Adware reste OTL LOG auswertenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| |
| | #1 |
![]() | Adware reste OTL LOG auswertenCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 11-03-2015
Ran by MC-Necro at 2015-03-16 17:02:50 Run:1
Running from D:\
Loaded Profiles: MC-Necro (Available profiles: MC-Necro)
Boot Mode: Normal
==============================================
Content of fixlist:
*****************
start
CloseProcesses:
Task: {13EBD2DA-AB6A-4748-BEA1-1A16C286D536} - \Driver Booster Startup No Task File <==== ATTENTION
Task: {27048078-ECBC-4121-B0E3-58D09D8965BB} - System32\Tasks\vTTqXYNrbiacuyp => C:\Users\MC-Necro\AppData\Roaming\7eTwD7u\uF47zLL.exe
C:\Users\MC-Necro\AppData\Roaming\7eTwD7u
Task: {281FEDF8-E9B3-4E17-A770-1F07BFCBA58B} - \Driver Booster Scan No Task File <==== ATTENTION
Task: {63B44105-BC0A-4115-B4D3-63C7EBBC364C} - \Driver Booster Update No Task File <==== ATTENTION
Task: {EB1F3EBE-0784-4E32-89CE-1E828DBF5E88} - System32\Tasks\uUQqUdnfXquU7Cu => C:\Users\MC-Necro\AppData\Roaming\lz5X1XA\lPnXGIY.exe [2015-03-15] ( )
C:\Users\MC-Necro\AppData\Roaming\lz5X1XA
Task: {EC75BAE2-2EDF-4E74-96F1-390BAC79E6EE} - \Driver Booster SkipUAC (MC-Necro) No Task File <==== ATTENTION
Task: {EC9DAD29-33FE-4E22-858E-AE28C6EF66C9} - \Optimize Start Menu Cache Files-S-1-5-21-3114231556-3272972307-1787784662-1001 No Task File <==== ATTENTION
Task: {F53111B1-3A68-4028-BCBC-A28B86269BD8} - System32\Tasks\OpBYzDpilE2DECl => C:\Users\MC-Necro\AppData\Roaming\oVy5zhI\v8YTFf5.exe
C:\Users\MC-Necro\AppData\Roaming\oVy5zhI
C:\ProgramData\DP45977C.lfl
C:\Users\MC-Necro\AppData\Roaming\XRNF
C:\Users\MC-Necro\AppData\Roaming\DNDQ
C:\Users\MC-Necro\AppData\Roaming\CZWL
C:\ProgramData\atjs
C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7
C:\Users\MC-Necro\AppData\Roaming\03D40274-1426448862-05BB-1406-590700080009
C:\Users\MC-Necro\Downloads\SpyHunter4.exe
EmptyTemp:
end
*****************
Processes closed successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{13EBD2DA-AB6A-4748-BEA1-1A16C286D536}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{13EBD2DA-AB6A-4748-BEA1-1A16C286D536}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Startup" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{27048078-ECBC-4121-B0E3-58D09D8965BB}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{27048078-ECBC-4121-B0E3-58D09D8965BB}" => Key deleted successfully.
C:\Windows\System32\Tasks\vTTqXYNrbiacuyp => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\vTTqXYNrbiacuyp" => Key deleted successfully.
C:\Users\MC-Necro\AppData\Roaming\7eTwD7u => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{281FEDF8-E9B3-4E17-A770-1F07BFCBA58B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{281FEDF8-E9B3-4E17-A770-1F07BFCBA58B}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Scan" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{63B44105-BC0A-4115-B4D3-63C7EBBC364C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{63B44105-BC0A-4115-B4D3-63C7EBBC364C}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster Update" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EB1F3EBE-0784-4E32-89CE-1E828DBF5E88}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EB1F3EBE-0784-4E32-89CE-1E828DBF5E88}" => Key deleted successfully.
C:\Windows\System32\Tasks\uUQqUdnfXquU7Cu => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\uUQqUdnfXquU7Cu" => Key deleted successfully.
C:\Users\MC-Necro\AppData\Roaming\lz5X1XA => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EC75BAE2-2EDF-4E74-96F1-390BAC79E6EE}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC75BAE2-2EDF-4E74-96F1-390BAC79E6EE}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Driver Booster SkipUAC (MC-Necro)" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Plain\{EC9DAD29-33FE-4E22-858E-AE28C6EF66C9}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EC9DAD29-33FE-4E22-858E-AE28C6EF66C9}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Optimize Start Menu Cache Files-S-1-5-21-3114231556-3272972307-1787784662-1001" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F53111B1-3A68-4028-BCBC-A28B86269BD8}" => Key deleted successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F53111B1-3A68-4028-BCBC-A28B86269BD8}" => Key deleted successfully.
C:\Windows\System32\Tasks\OpBYzDpilE2DECl => Moved successfully.
"HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\OpBYzDpilE2DECl" => Key deleted successfully.
C:\Users\MC-Necro\AppData\Roaming\oVy5zhI => Moved successfully.
C:\ProgramData\DP45977C.lfl => Moved successfully.
C:\Users\MC-Necro\AppData\Roaming\XRNF => Moved successfully.
C:\Users\MC-Necro\AppData\Roaming\DNDQ => Moved successfully.
C:\Users\MC-Necro\AppData\Roaming\CZWL => Moved successfully.
C:\ProgramData\atjs => Moved successfully.
C:\Windows\SysWOW64\029B560A371F4E00AB32838EBC01B9E7 => Moved successfully.
C:\Users\MC-Necro\AppData\Roaming\03D40274-1426448862-05BB-1406-590700080009 => Moved successfully.
C:\Users\MC-Necro\Downloads\SpyHunter4.exe => Moved successfully.
EmptyTemp: => Removed 252.4 MB temporary data.
The system needed a reboot.
==== End of Fixlog 17:02:51 ====
|
| | #2 | |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Adware reste OTL LOG auswertenZitat:
Ich hab gesehen, dass du den FRST-Fix vom Laufwerk D:\ und nicht vom Desktop ausgeführt hast... |
| | #3 |
![]() | Adware reste OTL LOG auswerten Hat auch nicht funktioniert
__________________ |
| | #4 |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Adware reste OTL LOG auswerten Du machst schon einen Rechtsklick auf den Ordner und wählst "Senden an" -> zip komprimierter Ordner? Versuch es mal mit einer .rar-Datei. |
| | #5 |
![]() | Adware reste OTL LOG auswerten Da kommt das C:\Users\MC-Necro\Desktop\Quarantine.rar: Konnte C:\Users\MC-Necro\Desktop\Quarantine\C\Windows\System32\Tasks\OpBYzDpilE2DECl.xBAD nicht öffnen. ! Zugriff verweigert C:\Users\MC-Necro\Desktop\Quarantine.rar: Konnte C:\Users\MC-Necro\Desktop\Quarantine\C\Windows\System32\Tasks\uUQqUdnfXquU7Cu.xBAD nicht öffnen. ! Zugriff verweigert C:\Users\MC-Necro\Desktop\Quarantine.rar: Konnte C:\Users\MC-Necro\Desktop\Quarantine\C\Windows\System32\Tasks\vTTqXYNrbiacuyp.xBAD nicht öffnen. ! Zugriff verweigert Aber das Archiv ist da |
| | #6 |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Adware reste OTL LOG auswerten Servus, ok, lade mal hoch, was an Archiv da ist. Ich guck mir das dann an. Dann weiter mit dem FRST-Kontrollscan:
|
| | #7 |
![]() | Adware reste OTL LOG auswerten Da kommt das aber das Archiv ist da C:\Users\MC-Necro\Desktop\Quarantine.rar: Konnte C:\Users\MC-Necro\Desktop\Quarantine\C\Windows\System32\Tasks\OpBYzDpilE2DECl.xBAD nicht öffnen. ! Zugriff verweigert C:\Users\MC-Necro\Desktop\Quarantine.rar: Konnte C:\Users\MC-Necro\Desktop\Quarantine\C\Windows\System32\Tasks\uUQqUdnfXquU7Cu.xBAD nicht öffnen. ! Zugriff verweigert C:\Users\MC-Necro\Desktop\Quarantine.rar: Konnte C:\Users\MC-Necro\Desktop\Quarantine\C\Windows\System32\Tasks\vTTqXYNrbiacuyp.xBAD nicht öffnen. ! Zugriff verweigert |
| | #8 | |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Adware reste OTL LOG auswertenZitat:
ok, lade mal hoch, was an Archiv da ist. Ich guck mir das dann an. Dann weiter mit dem FRST-Kontrollscan:
|
![]() |
| Themen zu Adware reste OTL LOG auswerten |
| abend, adware, auswerten, bluestacks, driver booster, frage, fragen, gestern, install.exe, installier, installiert, kmspico, könntet, launch, log, log auswerten, nennt, neu, nicht sicher, otl log, programm, refresh, reste, revo uninstaller, scan, software |