Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Diskussionsforum (https://www.trojaner-board.de/diskussionsforum/)
-   -   Windows 10: Windows Defender Alarm - Trojan:Win32/Occamy.C (https://www.trojaner-board.de/207215-windows-10-windows-defender-alarm-trojan-win32-occamy-c.html)

M-K-D-B 10.08.2023 17:56

Zitat:

Zitat von Piristibulus (Beitrag 1775834)
Vielen Dank für die Hilfe, soll/muss ich sonst noch etwas tun?

Gern geschehen. :)

Lass doch bitte kurz SecurityCheck laufen.



Schritt 1
Führe SecurityCheck (SC) gemäß der bebilderten Anleitung aus und füge die Logdatei als Anhang hinzu.

Piristibulus 10.08.2023 21:31

Danke Dir,
hier das log:

Code:

SecurityCheck by glax24 & Severnyj v.1.4.0.54 [06.12.21]
WebSite: www.safezone.cc
DateLog: 10.08.2023 22:12:47
Path starting: C:\Users\*****\AppData\Local\Temp\SecurityCheck\SecurityCheck.exe
Log directory: C:\SecurityCheck\
IsAdmin: True
User: *****
VersionXML: 10.62is-08.07.2023
___________________________________________________________________________

Windows 10(6.3.19045) (x64) Core Release: 2009 Lang: German(0407)
Installation date OS: 30.11.2020 13:25:30
LicenseStatus: Windows(R), Core edition The machine is permanently activated.
LicenseStatus: Office 16, Office16O365ProPlusR_Grace edition Windows is in Notification mode
Boot Mode: Normal
Default Browser: C:\Program Files\Mozilla Firefox\firefox.exe
SystemDrive: C: FS: [NTFS] Capacity: [237.4 Gb] Used: [217.5 Gb] Free: [19.9 Gb]
------------------------------- [ Windows ] -------------------------------
User Account Control enabled (Level 3)
Security Center (wscsvc) - The service is running
Remote Registry (RemoteRegistry) - The service has stopped
SSDP Discovery (SSDPSRV) - The service is running
Remote Desktop Services (TermService) - The service has stopped
Windows Remote Management (WS-Management) (WinRM) - The service has stopped
---------------------------- [ Antivirus_WMI ] ----------------------------
Windows Defender (enabled and up to date)
Malwarebytes (enabled and up to date)
--------------------------- [ FirewallWindows ] ---------------------------
Windows Defender Firewall (mpssvc) - The service is running
---------------------- [ AntiVirusFirewallInstall ] -----------------------
Malwarebytes version 4.5.34.275 v.4.5.34.275 [+]
--------------------------- [ OtherUtilities ] ----------------------------
Git v.2.41.0 Warning! Download Update
Microsoft 365 Apps for Enterprise - de-de v.16.0.16626.20134 [+]
Microsoft 365 Apps for enterprise - en-us v.16.0.16626.20134 [+]
SumatraPDF v.3.4.6
LibreOffice 7.1.2.2 v.7.1.2.2 Warning! Download Update
Oracle VM VirtualBox 7.0.10 v.7.0.10 [+]
calibre 64bit v.6.24.0 [+]
Steam v.2.10.91.91
Intel® Driver & Support Assistant v.23.3.25.6
------------------------------ [ ArchAndFM ] ------------------------------
7-Zip 23.01 (x64) v.23.01
-------------------------- [ IMAndCollaborate ] ---------------------------
Signal 6.27.0 v.6.27.0 [+]
Cisco Webex Meetings v.41.9.5 Warning! Download Update
Telegram Desktop v.4.8.10 [+]
Skype version 8.100 v.8.100 [+]
Skype 8.100 v.8.100.0.203 [+]
-------------------------------- [ Media ] --------------------------------
VLC media player v.3.0.18
HandBrake 1.6.1 v.1.6.1
--------------------------- [ AdobeProduction ] ---------------------------
Adobe Creative Cloud v.5.11.0.522.1
Adobe Acrobat v.23.003.20269 [+]
------------------------------- [ Browser ] -------------------------------
Mozilla Firefox (x64 de) v.116.0.2 [+]
Microsoft Edge v.115.0.1901.200 [+]
----------------------------- [ EmailClient ] -----------------------------
Mozilla Thunderbird (x64 de) v.115.1.0 [+]
GNU Privacy Guard v.2.4.3
Gpg4win (4.2.0) v.4.2.0 [+]
------------------ [ AntivirusFirewallProcessServices ] -------------------
Malwarebytes Service (MBAMService) - The service is running
C:\Program Files\Malwarebytes\Anti-Malware\MBAMService.exe v.3.2.0.1233
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\MsMpEng.exe v.4.18.23070.1004
C:\ProgramData\Microsoft\Windows Defender\Platform\4.18.23070.1004-0\NisSrv.exe v.4.18.23070.1004
Microsoft Defender Antivirus Service (WinDefend) - The service is running
Microsoft Defender Antivirus Network Inspection Service (WdNisSvc) - The service is running
----------------------------- [ End of Log ] ------------------------------


M-K-D-B 11.08.2023 07:31

Bitte aktualisieren (sofern noch benötigt), ansonsten deinstallieren::
  • Git
  • LibreOffice
  • Cisco Webex Meetings

Die Downloadlinks findest du in der Logdatei von SecurityCheck.



Entfernung der verwendeten Tools
Führe KpRm gemäß der bebilderten Anleitung aus und poste abschließend die Logdatei.

Piristibulus 11.08.2023 11:32

Danke,
alles upgedatet bzw deinstalliert.
Hier ist das Log:

Code:

# Run at 2023-08-11 12:31:06
# KpRm (Kernel-panik) version 2.14.0
# Website https://kernel-panik.me/tool/kprm/
# Run by dbirn from C:\Users\dbirn\OneDrive\Desktop
# Computer Name: DESKTOP-UIULLTJ
# OS: Windows 10 X64 (19045) (10.0.19045.3324)
# Number of passes: 1

- Checked options -

    ~ Delete Tools
    ~ Delete Quarantines

- Delete Tools -


  ## FRST
    [OK] C:\Users\dbirn\Downloads\Addition.txt deleted
    [OK] C:\Users\dbirn\Downloads\FRST.txt deleted
    [OK] C:\FRST deleted

  ## SecurityCheck
    [OK] C:\Users\dbirn\OneDrive\Desktop\SecurityCheck.exe deleted
    [OK] C:\SecurityCheck deleted

-- KPRM finished in 3.17s --


M-K-D-B 11.08.2023 12:26

Gut gemacht. :)

Alles Gute! :daumenhoc


Alle Zeitangaben in WEZ +1. Es ist jetzt 10:17 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129