![]() |
Bundestrojaner Ukash Hallo hier mein OTL Log. Ich habe leider schon den 3. Run ich hoffe das geht auch so. Die Extra Datei habe ich auch nicht. Ich habe zu spät von diesem Forum erfahren. Ich habe schon alles mögliche probiert alle gängigen Virenscanner aus dem abgesicherten Modus raus laufen lassen aber keiner hat den Virus entfernt. Desktop Unlocker von Kasperky und Avira haben auch nicht funktioniert, bzw habe sie nicht zum laufen gebracht. Ich hoffe hier wird mir geholfen. DankeOTL Logfile: Code: OTL logfile created on: 08.08.2012 08:10:43 - Run 3 |
:hallo: Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
Wow ich bin echt platt. Es hat funktioniert vielen lieben Danke. Was genau hab ich denn gerade gemacht? Ist der Trojaner jetzt total entfernt, waren noch andere Viren oder Trojaner drauf die ich dadurch entfernt habe. All processes killed ========== OTL ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{47379DEE-6FCC-4A14-8195-6E56AB7E8604}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47379DEE-6FCC-4A14-8195-6E56AB7E8604}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{21E95DEF-69E2-46AD-B455-AAF504D3327B}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{21E95DEF-69E2-46AD-B455-AAF504D3327B}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2A5D8926-4BEF-4668-8978-37C6C42B979D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2A5D8926-4BEF-4668-8978-37C6C42B979D}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{47379DEE-6FCC-4A14-8195-6E56AB7E8604}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47379DEE-6FCC-4A14-8195-6E56AB7E8604}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{92DC3383-EEAC-4245-94F8-F004A51B59DD}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92DC3383-EEAC-4245-94F8-F004A51B59DD}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CC9CCE2D-790C-4B05-9047-D6622F2C45AB}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CC9CCE2D-790C-4B05-9047-D6622F2C45AB}\ not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Prefs.js: "Search the web" removed from browser.search.defaultenginename Prefs.js: "Search the web" removed from browser.search.order.1 Prefs.js: "Search the web" removed from browser.search.selectedEngine Prefs.js: true removed from browser.search.useDBForOrder Prefs.js: "hxxp://www.google.de/" removed from browser.startup.homepage Prefs.js: "hxxp://www.browsersafesearch.com?client=mozilla-firefox&cd=UTF-8&search=1&q=" removed from keyword.URL 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll moved successfully. 127.0.0.1 www.007guard.com removed from HOSTS file successfully 127.0.0.1 008k.com removed from HOSTS file successfully 127.0.0.1 00hq.com removed from HOSTS file successfully Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate deleted successfully. C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\noaffvhujpjdcdy deleted successfully. C:\ProgramData\noaffvhu.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\EPSON Stylus Photo RX585 Series deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\noaffvhujpjdcdy deleted successfully. File C:\ProgramData\noaffvhu.exe not found. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft &Excel exportieren\ deleted successfully. 64bit-Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft E&xel exportieren\ deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft &Excel exportieren\ not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft E&xel exportieren\ not found. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA} 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0016-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{22e970f6-f236-11df-95c1-0024bec68b1b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22e970f6-f236-11df-95c1-0024bec68b1b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{22e970f6-f236-11df-95c1-0024bec68b1b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22e970f6-f236-11df-95c1-0024bec68b1b}\ not found. File C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\Start.hta not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{22e970fb-f236-11df-95c1-0024bec68b1b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22e970fb-f236-11df-95c1-0024bec68b1b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{22e970fb-f236-11df-95c1-0024bec68b1b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{22e970fb-f236-11df-95c1-0024bec68b1b}\ not found. File C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\Start.hta not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8d753ff6-9cd5-11e1-8ae2-0024bebc934c}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8d753ff6-9cd5-11e1-8ae2-0024bebc934c}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8d753ff6-9cd5-11e1-8ae2-0024bebc934c}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8d753ff6-9cd5-11e1-8ae2-0024bebc934c}\ not found. File G:\autorun.exe not found. C:\ProgramData\mbujnipyjkcgjzx folder moved successfully. C:\ProgramData\ntuser.pol moved successfully. C:\ProgramData\ptqegnndbxhhiaf moved successfully. File C:\ProgramData\noaffvhu.exe not found. C:\ProgramData\to_r0tsef.pad moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully. C:\Users\isa\AppData\Local\{ab7eaf32-1dfa-c3b2-a595-2832edd89764}\U\00000001.@ moved successfully. C:\Windows\Installer\{ab7eaf32-1dfa-c3b2-a595-2832edd89764}\U\00000001.@ moved successfully. C:\Windows\Installer\{ab7eaf32-1dfa-c3b2-a595-2832edd89764}\@ moved successfully. C:\Users\isa\AppData\Local\{ab7eaf32-1dfa-c3b2-a595-2832edd89764}\@ moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\isa\Desktop\cmd.bat deleted successfully. C:\Users\isa\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: isa ->Temp folder emptied: 1414361251 bytes ->Temporary Internet Files folder emptied: 175638649 bytes ->Java cache emptied: 24479766 bytes ->FireFox cache emptied: 50765611 bytes ->Flash cache emptied: 59560737 bytes User: Mcx1-ISA-VAIO ->Temp folder emptied: 66532 bytes ->Temporary Internet Files folder emptied: 75817 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 3745828 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 110453448 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1.754,00 mb [EMPTYFLASH] User: All Users User: Default User: Default User User: isa ->Flash cache emptied: 0 bytes User: Mcx1-ISA-VAIO User: Public Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.56.0 log created on 08082012_223822 Files\Folders moved on Reboot... C:\Users\isa\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. PendingFileRenameOperations files... File C:\Users\isa\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found! Registry entries deleted on Reboot... |
Nein, wir sind noch nicht ferig, ich sage bescheid :) Sehr gut! :daumenhoc Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
Hallo hier die beiden Logs: Vielen Danke nochmal Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.10.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 isa :: ISA-VAIO [Administrator] Schutz: Aktiviert 10.08.2012 09:10:53 mbam-log-2012-08-10 (09-10-53).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 363914 Laufzeit: 38 Minute(n), 3 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) # AdwCleaner v1.800 - Logfile created 08/10/2012 at 10:14:35 # Updated 01/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : isa - ISA-VAIO # Running from : C:\Users\isa\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\isa\AppData\LocalLow\boost_interprocess Folder Found : C:\Users\isa\AppData\Roaming\Mozilla\Firefox\Profiles\m6qbdun4.default\extensions\plugin@yontoo.com Folder Found : C:\Users\isa\AppData\Roaming\Mozilla\Firefox\Profiles\m6qbdun4.default\extensions\welcome@toolmin.com Folder Found : C:\ProgramData\Tarma Installer Folder Found : C:\Program Files (x86)\Yontoo Layers Runtime ***** [Registry] ***** Key Found : HKCU\Software\Softonic Key Found : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 Key Found : HKLM\SOFTWARE\DT Soft Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc [x64] Key Found : HKCU\Software\Softonic [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL [x64] Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api [x64] Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 [x64] Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers [x64] Key Found : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 [x64] Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} [x64] Key Found : HKLM\SOFTWARE\Tarma Installer ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Key Found : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Found : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Key Found : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKLM\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-89AF-189327213627} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEFCDEE-CF1A-4FC8-89AF-189327213627} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} [x64] Key Found : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} [x64] Key Found : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} [x64] Key Found : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEFCDEE-CF1A-4FC8-89AF-189327213627} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\isa\AppData\Roaming\Mozilla\Firefox\Profiles\m6qbdun4.default\prefs.js Found : user_pref("browser.search.defaultenginename", "Search the web"); Found : user_pref("browser.search.order.1", "Search the web"); Found : user_pref("browser.search.selectedEngine", "Search the web"); ************************* AdwCleaner[R1].txt - [5139 octets] - [10/08/2012 10:14:35] ########## EOF - C:\AdwCleaner[R1].txt - [5267 octets] ########## |
Sehr gut! :daumenhoc
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
Hier die beiden logs # AdwCleaner v1.800 - Logfile created 08/10/2012 at 13:56:54 # Updated 01/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : isa - ISA-VAIO # Running from : C:\Users\isa\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\isa\AppData\LocalLow\boost_interprocess Folder Deleted : C:\Users\isa\AppData\Roaming\Mozilla\Firefox\Profiles\m6qbdun4.default\extensions\plugin@yontoo.com Folder Deleted : C:\Users\isa\AppData\Roaming\Mozilla\Firefox\Profiles\m6qbdun4.default\extensions\welcome@toolmin.com Folder Deleted : C:\ProgramData\Tarma Installer Folder Deleted : C:\Program Files (x86)\Yontoo Layers Runtime ***** [Registry] ***** Key Deleted : HKCU\Software\Softonic Key Deleted : HKLM\SOFTWARE\Classes\AppID\YontooIEClient.DLL Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Api.1 Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers Key Deleted : HKLM\SOFTWARE\Classes\YontooIEClient.Layers.1 Key Deleted : HKLM\SOFTWARE\DT Soft Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\niapdbllcanepiiimjjndipklodoedlc [x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{889DF117-14D1-44EE-9F31-C5FB5D47F68B} [x64] Key Deleted : HKLM\SOFTWARE\Tarma Installer ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{CFDAFE39-20CE-451D-BD45-A37452F39CF0} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{7E84186E-B5DE-4226-8A66-6E49C6B511B4} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{80922EE0-8A76-46AE-95D5-BD3C3FE0708D} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-89AF-189327213627} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{FE9271F2-6EFD-44B0-A826-84C829536E93} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{D372567D-67C1-4B29-B3F0-159B52B3E967} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DF7770F7-832F-4BDF-B144-100EDDD0C3AE} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{DFEFCDEE-CF1A-4FC8-89AF-189327213627} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{FD72061E-9FDE-484D-A58A-0BAB4151CAD8} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{10DE7085-6A1E-4D41-A7BF-9AF93E351401} [x64] Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1AD27395-1659-4DFF-A319-2CFA243861A5} ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.7601.17514 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\isa\AppData\Roaming\Mozilla\Firefox\Profiles\m6qbdun4.default\prefs.js C:\Users\isa\AppData\Roaming\Mozilla\Firefox\Profiles\m6qbdun4.default\user.js ... Deleted ! Deleted : user_pref("browser.search.defaultenginename", "Search the web"); Deleted : user_pref("browser.search.order.1", "Search the web"); Deleted : user_pref("browser.search.selectedEngine", "Search the web"); ************************* AdwCleaner[R1].txt - [5232 octets] - [10/08/2012 10:14:35] AdwCleaner[R2].txt - [5292 octets] - [10/08/2012 10:25:12] AdwCleaner[S1].txt - [264 octets] - [10/08/2012 10:25:21] AdwCleaner[S2].txt - [264 octets] - [10/08/2012 13:56:34] AdwCleaner[S3].txt - [4295 octets] - [10/08/2012 13:56:55] ########## EOF - C:\AdwCleaner[S3].txt - [4423 octets] ########## Emsisoft Anti-Malware - Version 6.6 Letztes Update: 10.08.2012 14:08:15 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\ Archiv Scan: An ADS Scan: An Scan Beginn: 10.08.2012 14:09:31 C:\_OTL\MovedFiles\08082012_223822\C_ProgramData\noaffvhu.exe gefunden: Trojan.Win32.Weelsof.AMN!E1 C:\_OTL\MovedFiles\08082012_223822\C_Users\isa\AppData\Local\{ab7eaf32-1dfa-c3b2-a595-2832edd89764}\U\00000001.@ gefunden: Trojan.Win32.Agent.AMN!E1 C:\_OTL\MovedFiles\08082012_223822\C_Windows\Installer\{ab7eaf32-1dfa-c3b2-a595-2832edd89764}\U\00000001.@ gefunden: Trojan.Win32.Agent.AMN!E1 C:\Windows\assembly\NativeImages_v2.0.50727_32\Temp\ZAP1BCA.tmp\System.Web.Abstractions.dll gefunden: Trojan-Spy.Win32.Zbot!E2 Gescannt 595556 Gefunden 4 Scan Ende: 10.08.2012 15:20:22 Scan Zeit: 1:10:51 |
Sehr gut! :daumenhoc Lasse die Funde loeschen, dann: Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
Hier der Log, musste ihn 2 mal drüberlaufen lassen hatte beim 1. Mal das Programm deinstalliert und der Log war auch weg. So leider hier der 2.Log.: ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=3758dcc1ea45a4478fe52992755e92b5 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-11 11:51:12 # local_time=2012-08-11 01:51:12 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=5893 16776574 66 94 3438959 96297484 0 0 # compatibility_mode=8192 67108863 100 0 36741 36741 0 0 # scanned=158829 # found=0 # cleaned=0 # scan_time=18239 |
Scan durchfuehren: http://www.trojaner-board.de/114276-...s-remover.html |
Hier der Log C:\Windows\system32\ntoskrnl.exe OK C:\Windows\system32\hal.dll OK C:\Windows\system32\kdcom.dll OK C:\Windows\system32\mcupdate_GenuineIntel.dll OK C:\Windows\system32\PSHED.dll OK C:\Windows\system32\CLFS.SYS OK C:\Windows\system32\CI.dll OK C:\Windows\system32\drivers\Wdf01000.sys OK C:\Windows\system32\drivers\WDFLDR.SYS OK C:\Windows\system32\drivers\ACPI.sys OK C:\Windows\system32\drivers\WMILIB.SYS OK C:\Windows\system32\drivers\msisadrv.sys OK C:\Windows\system32\drivers\pci.sys OK C:\Windows\system32\drivers\vdrvroot.sys OK C:\Windows\System32\drivers\partmgr.sys OK C:\Windows\system32\drivers\compbatt.sys OK C:\Windows\system32\drivers\BATTC.SYS OK C:\Windows\system32\drivers\volmgr.sys OK C:\Windows\System32\drivers\volmgrx.sys OK C:\Windows\System32\drivers\mountmgr.sys OK C:\Windows\system32\drivers\iaStor.sys OK C:\Windows\system32\drivers\amdxata.sys OK C:\Windows\system32\drivers\fltmgr.sys OK C:\Windows\system32\drivers\fileinfo.sys OK C:\Windows\System32\Drivers\PxHlpa64.sys OK C:\Windows\System32\Drivers\Ntfs.sys OK C:\Windows\System32\Drivers\msrpc.sys OK C:\Windows\System32\Drivers\ksecdd.sys OK C:\Windows\System32\Drivers\cng.sys OK C:\Windows\System32\drivers\pcw.sys OK C:\Windows\System32\Drivers\Fs_Rec.sys OK C:\Windows\system32\drivers\ndis.sys OK C:\Windows\system32\drivers\NETIO.SYS OK C:\Windows\System32\Drivers\ksecpkg.sys OK C:\Windows\System32\drivers\tcpip.sys OK C:\Windows\System32\drivers\fwpkclnt.sys OK C:\Windows\system32\drivers\volsnap.sys OK C:\Windows\System32\Drivers\spldr.sys OK C:\Windows\System32\drivers\rdyboost.sys OK C:\Windows\System32\Drivers\mup.sys OK C:\Windows\System32\drivers\hwpolicy.sys OK C:\Windows\System32\DRIVERS\fvevol.sys OK C:\Windows\system32\drivers\disk.sys OK C:\Windows\system32\drivers\CLASSPNP.SYS OK C:\Windows\system32\DRIVERS\dtsoftbus01.sys OK C:\Windows\system32\drivers\cdrom.sys OK C:\Windows\System32\Drivers\Null.SYS OK C:\Windows\System32\Drivers\Beep.SYS OK C:\Windows\System32\drivers\vga.sys OK C:\Windows\System32\drivers\VIDEOPRT.SYS OK C:\Windows\System32\drivers\watchdog.sys OK C:\Windows\System32\DRIVERS\RDPCDD.sys OK C:\Windows\system32\drivers\rdpencdd.sys OK C:\Windows\system32\drivers\rdprefmp.sys OK C:\Windows\System32\Drivers\Msfs.SYS OK C:\Windows\System32\Drivers\Npfs.SYS OK C:\Windows\system32\DRIVERS\tdx.sys OK C:\Windows\system32\DRIVERS\TDI.SYS OK C:\Windows\system32\drivers\afd.sys OK C:\Windows\System32\DRIVERS\netbt.sys OK C:\Windows\system32\DRIVERS\wfplwf.sys OK C:\Windows\system32\DRIVERS\pacer.sys OK C:\Windows\system32\DRIVERS\vwififlt.sys OK C:\Windows\system32\DRIVERS\netbios.sys OK C:\Windows\system32\DRIVERS\wanarp.sys OK C:\Windows\system32\drivers\termdd.sys OK C:\Windows\system32\DRIVERS\rdbss.sys OK C:\Windows\system32\drivers\nsiproxy.sys OK C:\Windows\system32\drivers\mssmbios.sys OK C:\Windows\System32\drivers\discache.sys OK C:\Windows\System32\Drivers\dfsc.sys OK C:\Windows\system32\drivers\blbdrive.sys OK C:\Windows\system32\DRIVERS\tunnel.sys OK C:\Windows\system32\DRIVERS\igdkmd64.sys OK C:\Windows\System32\drivers\dxgkrnl.sys OK C:\Windows\System32\drivers\dxgmms1.sys OK C:\Windows\system32\drivers\HECIx64.sys OK C:\Windows\system32\drivers\usbehci.sys OK C:\Windows\system32\drivers\USBPORT.SYS OK C:\Windows\system32\drivers\HDAudBus.sys OK C:\Windows\system32\DRIVERS\athrx.sys OK C:\Windows\system32\DRIVERS\vwifibus.sys OK C:\Windows\system32\drivers\sdbus.sys OK C:\Windows\system32\drivers\rimssne64.sys OK C:\Windows\system32\drivers\risdsne64.sys OK C:\Windows\system32\DRIVERS\yk62x64.sys OK C:\Windows\system32\drivers\i8042prt.sys OK C:\Windows\system32\drivers\kbdclass.sys OK C:\Windows\system32\drivers\Apfiltr.sys OK C:\Windows\system32\drivers\mouclass.sys OK C:\Windows\system32\drivers\SFEP.sys OK C:\Windows\SysWOW64\drivers\Afc.sys OK C:\Windows\system32\drivers\Impcd.sys OK C:\Windows\system32\drivers\intelppm.sys OK C:\Windows\system32\drivers\CmBatt.sys OK C:\Windows\system32\drivers\CompositeBus.sys OK C:\Windows\system32\DRIVERS\AgileVpn.sys OK C:\Windows\system32\DRIVERS\rasl2tp.sys OK C:\Windows\system32\DRIVERS\ndistapi.sys OK C:\Windows\system32\DRIVERS\ndiswan.sys OK C:\Windows\system32\DRIVERS\raspppoe.sys OK C:\Windows\system32\DRIVERS\raspptp.sys OK C:\Windows\system32\DRIVERS\rassstp.sys OK C:\Windows\system32\DRIVERS\hamachi.sys OK C:\Windows\system32\drivers\swenum.sys OK C:\Windows\system32\drivers\ks.sys OK C:\Windows\system32\drivers\umbus.sys OK C:\Windows\system32\DRIVERS\usbhub.sys OK C:\Windows\System32\Drivers\NDProxy.SYS OK C:\Windows\system32\drivers\RTKVHD64.sys OK C:\Windows\system32\drivers\portcls.sys OK C:\Windows\system32\drivers\drmk.sys OK C:\Windows\system32\drivers\ksthunk.sys OK C:\Windows\system32\DRIVERS\IntcDAud.sys OK C:\Windows\system32\DRIVERS\usbccgp.sys OK C:\Windows\system32\DRIVERS\USBD.SYS OK C:\Windows\System32\win32k.sys OK C:\Windows\System32\drivers\Dxapi.sys OK C:\Windows\System32\Drivers\usbvideo.sys OK C:\Windows\system32\DRIVERS\ArcSoftKsUFilter.sys OK C:\Windows\System32\Drivers\crashdmp.sys OK C:\Windows\System32\Drivers\dump_iaStor.sys Not Found C:\Windows\System32\Drivers\dump_dumpfve.sys Not Found C:\Windows\system32\drivers\hidusb.sys OK C:\Windows\system32\drivers\HIDCLASS.SYS OK C:\Windows\system32\drivers\HIDPARSE.SYS OK C:\Windows\system32\DRIVERS\mouhid.sys OK C:\Windows\system32\DRIVERS\monitor.sys OK C:\Windows\System32\TSDDD.dll OK C:\Windows\System32\cdd.dll OK C:\Windows\system32\drivers\luafv.sys OK C:\Windows\system32\drivers\WudfPf.sys OK C:\Windows\system32\DRIVERS\lltdio.sys OK C:\Windows\system32\DRIVERS\nwifi.sys OK C:\Windows\system32\DRIVERS\ndisuio.sys OK C:\Windows\system32\DRIVERS\rspndr.sys OK C:\Windows\system32\drivers\HTTP.sys OK C:\Windows\System32\DRIVERS\srvnet.sys OK C:\Windows\system32\DRIVERS\bowser.sys OK C:\Windows\system32\DRIVERS\mrxsmb.sys OK C:\Windows\system32\DRIVERS\mrxsmb10.sys OK C:\Windows\system32\DRIVERS\mrxsmb20.sys OK C:\Windows\System32\DRIVERS\srv2.sys OK C:\Windows\System32\DRIVERS\srv.sys OK C:\Windows\system32\DRIVERS\vwifimp.sys OK C:\Windows\system32\drivers\peauth.sys OK C:\Windows\System32\Drivers\secdrv.SYS OK C:\Windows\System32\drivers\tcpipreg.sys OK C:\Windows\system32\drivers\tdtcp.sys OK C:\Windows\System32\DRIVERS\tssecsrv.sys OK C:\Windows\System32\Drivers\RDPWD.SYS OK C:\Windows\system32\DRIVERS\WUDFRd.sys OK C:\Windows\system32\drivers\mbam.sys OK C:\Windows\system32\drivers\spsys.sys OK C:\Windows\system32\drivers\rm.sys Not Found C:\Windows\System32\ntdll.dll OK C:\Windows\System32\smss.exe OK C:\Windows\System32\apisetschema.dll OK C:\Windows\System32\autochk.exe OK C:\Windows\System32\shell32.dll OK C:\Windows\System32\rpcrt4.dll OK C:\Windows\System32\advapi32.dll OK C:\Windows\System32\kernel32.dll OK C:\Windows\System32\wininet.dll OK C:\Windows\System32\imagehlp.dll OK C:\Windows\System32\comdlg32.dll OK C:\Windows\System32\lpk.dll OK C:\Windows\System32\usp10.dll OK C:\Windows\System32\normaliz.dll OK C:\Windows\System32\iertutil.dll OK C:\Windows\System32\psapi.dll OK C:\Windows\System32\shlwapi.dll OK C:\Windows\System32\clbcatq.dll OK C:\Windows\System32\user32.dll OK C:\Windows\System32\gdi32.dll OK C:\Windows\System32\msctf.dll OK C:\Windows\System32\Wldap32.dll OK C:\Windows\System32\setupapi.dll OK C:\Windows\System32\difxapi.dll OK C:\Windows\System32\nsi.dll OK C:\Windows\System32\sechost.dll OK C:\Windows\System32\oleaut32.dll OK C:\Windows\System32\urlmon.dll OK C:\Windows\System32\ws2_32.dll OK C:\Windows\System32\msvcrt.dll OK C:\Windows\System32\imm32.dll OK C:\Windows\System32\ole32.dll OK C:\Windows\System32\crypt32.dll OK C:\Windows\System32\KernelBase.dll OK C:\Windows\System32\comctl32.dll OK C:\Windows\System32\wintrust.dll OK C:\Windows\System32\devobj.dll OK C:\Windows\System32\cfgmgr32.dll OK C:\Windows\System32\msasn1.dll OK C:\Windows\SysWOW64\normaliz.dll OK C:\Windows\system32\basesrv.dll OK C:\Windows\system32\winsrv.dll OK C:\Windows\system32\winsrv.dll OK C:\Windows\system32\sxssrv.dll OK C:\Windows\system32\basesrv.dll OK C:\Windows\system32\winsrv.dll OK C:\Windows\system32\winsrv.dll OK C:\Windows\system32\sxssrv.dll OK {039B2CA5-3B41-4D93-AD77-47D3293FC5CB}\InprocServer32 OK {31261F21-2B16-45EE-BEAB-07C4CFA18B65}\InprocServer32 OK {42481700-CF3C-4D05-8EC6-F9A1C57E8DC0}\InprocServer32 OK {444785F1-DE89-4295-863A-D46C3A781394}\InprocServer32 OK {BB6410D8-F879-4184-9C5C-6A02D16AE0B3}\InprocServer32 OK {CA1073A2-5F3F-4445-8E5E-7109BDCEDDBE}\InprocServer32 OK {CAFEEFAC-0013-0000-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0000-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0000-0005-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0000-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0001-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0001-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0002-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0003-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0004-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0005-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0005-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0006-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0006-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0007-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0007-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0008-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0008-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0009-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0009-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0010-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0010-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0011-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0011-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0012-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0012-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0013-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0013-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0014-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0014-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0015-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0015-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0016-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0016-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0017-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0017-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0018-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0018-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0019-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0019-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0020-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0020-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0021-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0021-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0022-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0022-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0023-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0023-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0024-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0024-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0025-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0025-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0026-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0026-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0027-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0027-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0028-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0028-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0029-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0029-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0013-0001-0030-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0013-0001-0030-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0000-0000-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0000-0002-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0000-0002-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0000-0003-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0000-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0000-0004-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0000-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0003-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0004-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0005-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0005-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0006-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0006-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0001-0007-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0000-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0001-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0001-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0002-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0002-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0003-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0005-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0007-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0007-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0008-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0009-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0009-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0010-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0010-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0011-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0011-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0012-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0012-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0013-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0013-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0014-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0014-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0015-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0015-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0016-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0016-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0017-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0017-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0018-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0018-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0019-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0019-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0020-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0020-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0021-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0021-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0022-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0022-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0023-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0023-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0024-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0024-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0025-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0025-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0026-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0026-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0027-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0027-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0028-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0028-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0029-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0029-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-0030-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0014-0002-0030-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0014-0002-FFFF-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0001-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0002-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0003-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0004-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0005-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0006-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0007-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0008-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0009-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0011-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0012-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0013-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0013-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0013-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0014-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0015-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0016-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0017-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0018-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0018-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0018-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0019-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0019-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0019-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0020-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0020-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0020-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0021-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0022-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0023-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0023-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0023-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0024-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0024-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0024-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0025-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0025-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0025-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0026-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0026-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0026-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0027-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0027-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0027-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0028-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0028-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0028-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0029-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0029-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0029-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-0030-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0015-0000-0030-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0015-0000-0030-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0015-0000-FFFF-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0000-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0001-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0002-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0004-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0005-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0006-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0008-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0008-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0008-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0009-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0009-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0009-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0010-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0011-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0012-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0015-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0016-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0017-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0018-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0019-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0025-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0027-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0028-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0028-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0028-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}\InprocServer32 OK {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBB}\InprocServer32 OK {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBC}\InprocServer32 OK {CAFEEFAC-0016-0000-FFFF-ABCDEFFEDCBA}\InprocServer32 OK {D0D38C6E-BF64-4C42-840D-3E0019D9F7A6}\InprocServer32 OK {D5A55D2D-C59D-42C3-A5BF-4C08EEE74339}\InprocServer32 OK {E19F9331-3110-11D4-991C-005004D3B3DB}\InprocServer32 OK {FB314ED9-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 OK {FB314EDA-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 OK {FB314EDB-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 OK {FB314EDC-A251-47B7-93E1-CDD82E34AF8B}\InprocServer32 OK C:\Windows\system32\services.exe -- EOF -- |
Malware mit Combofix beseitigen Lade Combofix von einem der folgenden Download-Spiegel herunter: BleepingComputer.com - ForoSpyware.com und speichere das Programm auf den Desktop, nicht woanders hin, das ist wichtig! Beachte die ausführliche Original-Anleitung. Zurzeit ist Combofix auf folgenden Windows-Versionen lauffähig:
Vorbereitung und wichtige Hinweise
Combofix nicht auf eigene Faust einsetzen. Wenn keine entsprechende Infektion vorliegt, kann das den Rechner lahmlegen und/oder nachhaltig schädigen! |
hier der Log Combofix Logfile: Code: ComboFix 12-08-10.02 - isa 12.08.2012 8:57.2.4 - x64 |
Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html Danach poste (kopieren und einfuegen) mir, was du hier angezeigt bekommst: PluginCheck |
Hallo Danke. Beim Plugincheck sind alle 4 aktuell und grün, musste adobe aktualisieren, jetzt aber sind alle 4 grün und aktuell. |
Kontrollscan: 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten. |
Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.12.05 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 8.0.7601.17514 isa :: ISA-VAIO [Administrator] 12.08.2012 20:41:58 mbam-log-2012-08-12 (20-41-58).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 365435 Laufzeit: 1 Stunde(n), 30 Minute(n), 42 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
Sehr gut! :daumenhoc damit bist Du entlassen! :) Du solltest trotzdem bald mal Neuaufsetzen. Combofix deinstallieren Bitte vor der folgenden Aktion wieder temporär Antivirus-Programm, evtl. vorhandenes Skript-Blocking (Norton) und Anti-Malware Programme deaktivieren. Start => Ausführen => dort reinschreiben ComboFix /Uninstall => Enter drücken Damit wird Combofix komplett entfernt und der Cache der Systemwiederherstellung geleert, damit auch daraus die Schädlinge verschwinden. Es wird ein neuer Systemwiederherstellungspunkt erstellt. Gleichzeitig setzt Combofix die Zeiteinstellungen wieder auf die Ursprungseinstellungen, und setzt die Systemeinstellungen wieder so zurück, dass Dateierweiterungen und Systemdateien versteckt sind, was Du bei Bedarf im Explorer unter Extras => Ordneroptionen aber wieder ändern bzw. Deinen persönlichen Vorlieben entsprechend anpassen kannst. adwCleaner entfernen
Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Systemwiederherstellungen leeren Damit der Rechner nicht mit einer infizierten Systemwiederherstellung erneut infiziert werden kann, muessen wir diese leeren. Dazu schalten wir sie einmal aus und dann wieder ein: Systemwiederherstellung deaktivieren Tutorial fuer Windows XP, Windows Vista, Windows 7 Danach wieder aktivieren. Aufräumen mit CCleaner Lasse mit CCleaner (Download) (Anleitung) Fehler in der
Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html PC wird immer langsamer - was tun? |
Alle Zeitangaben in WEZ +1. Es ist jetzt 15:09 Uhr. |
Copyright ©2000-2025, Trojaner-Board