![]() |
system security antivirus und Spyhunter4 Hallo, ich bin heute auf eine Seite gestoßen ,wo die Meldung "Danger Virus was found on your computer, Click "Okay" to install free System Security Antivirus" kam. Anschließend habe ich bei euch im Forum gelesen wie ich dies rückängig mache, aber dumm wie ich bin zuvor "spyhunter4" herunter geladen, weil ich gedacht hatte das es entgültig alles entfernt. Ich habe mit norton einen kompletten symstemscan gemacht mit OTL ebenfalls. CCLEANER habe ich auch durchlaufen lassen. Meine frage wäre nun ob das alles etwas genüzt hat oder ob immer noch viren auf meinem pc sein können , da ich gelesen habe das man oftmals am Anfang nichts mitbekommt das der virus auf dem pc ist. Für Tipps für weiteres Vorgehen wäre ich sehr dankbar :) |
Zitat:
Bitte routinemäßig einen Vollscan mit malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Falls Logs aus älteren Scans mit Malwarebytes vorhanden sind, bitte auch davon alle posten! Poste auch alle anderen vorhanden Logs, die der Virenscanner und die von OTL |
OTL LOG :OTL Logfile: Code: OTL logfile created on: 19.05.2011 12:49:30 - Run 1 OTL Logfile: Code: OTL Extras logfile created on: 19.05.2011 12:49:30 - Run 1 Malwarebytes log folgt |
Malwarebytes' Anti-Malware 1.50.1.1100 Malwarebytes : Free anti-malware, anti-virus and spyware removal download Datenbank Version: 6611 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19048 19.05.2011 15:10:16 mbam-log-2011-05-19 (15-10-16).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Durchsuchte Objekte: 446648 Laufzeit: 1 Stunde(n), 53 Minute(n), 53 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 1 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\Users\Benedikt\AppData\Roaming\logs.dat (Bifrose.Trace) -> Quarantined and deleted successfully. |
War das der erste und einzige Scan mit Malwarebytes? Oder hast du damit schon öfter gescannt? |
ich hatte vorher schonmal einen gemacht aber bevor ich im forum gepostet habe , leider den log nicht gespeichert :( damals wurden 3 Sicherheitsrisiken behoben. |
Öffne Malwarebytes, klick auf Reiter Logdateien - da sind alles Logs zu sehen, diese auch alle posten. |
Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 6611 Windows 6.0.6002 Service Pack 2 Internet Explorer 8.0.6001.19048 19.05.2011 00:14:37 mbam-log-2011-05-19 (00-14-37).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Durchsuchte Objekte: 271565 Laufzeit: 1 Stunde(n), 32 Minute(n), 24 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 1 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 1 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: c:\program files (x86)\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Delete on reboot. Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs\C:\PROGRAM FILES (X86)\COMMON FILES\SPIGOT\WTXPCOM\COMPONENTS\WIDGITOOLBARFF.DLL (Adware.WidgiToolbar) -> Value: WIDGITOOLBARFF.DLL -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: c:\program files (x86)\common files\Spigot\wtxpcom\components\widgitoolbarff.dll (Adware.WidgiToolbar) -> Quarantined and deleted successfully. |
Zitat:
Hm, was willst du mit diesen komischen Toolbars auf dem Rechner? Am besten alles entfernen wo Toolbar steht, was in der Systemsteuerung unter Software bzw. Programme und Funktionen zu sehen ist und bei zukünftigen Programminstallation immer die benutzerdefinierte Methode anklicken, damit man bei der Installation mögliche Toolbars abwählen kann. Deinstalliere bei der Gelegenheit auch alle anderen unnötigen Programme über die Systemsteuerung. |
okay danke :) werde ich machen , ist sonst alles in ordnung? kein virus? |
Deinstallier erst den Kram, dann ein frisches OTL-Log erstellen und posten. |
OTL Logfile: OTL EXTRAS Logfile: Code: OTL logfile created on: 19.05.2011 17:51:55 - Run 1 --- --- --- OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 19.05.2011 17:51:56 - Run 1 |
Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code: :OTL Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. |
so wurde alles gemacht ich habe auf okay geklickt ...pc wurde neu gestartet ...und hier der log ========== OTL ========== HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Secondary_Page_URL| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Page| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{872b5b88-9db5-4310-bdd0-ac189557e5f5} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{9d81af43-de53-48d0-a199-42c2a226b24c} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9d81af43-de53-48d0-a199-42c2a226b24c}\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}\ not found. Prefs.js: "Yahoo" removed from browser.search.defaultenginename Prefs.js: "Softonic Deutsch FF Customized Web Search" removed from browser.search.defaultthis.engineName Prefs.js: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2206084&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl Prefs.js: "Ask" removed from browser.search.order.1 Prefs.js: "chr-greentree_ff&type=937811" removed from browser.search.param.yahoo-fr Prefs.js: "Yahoo" removed from browser.search.selectedEngine Prefs.js: true removed from browser.search.useDBForOrder Prefs.js: "hxxp://search.conduit.com/?ctid=CT2206084&SearchSource=13" removed from browser.startup.homepage Prefs.js: engine@conduit.com:3.2.5.2 removed from extensions.enabledItems Prefs.js: radiobar@toolbar:1.0.0 removed from extensions.enabledItems Prefs.js: "hxxp://de.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&type=937811&p=" removed from keyword.URL Prefs.js: "chrome://browser-region/locale/region.properties" removed from sweetim.toolbar.previous.browser.search.defaultenginename Prefs.js: "hxxp://start.icq.com/" removed from browser.startup.homepage C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\searchplugin folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\lib folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\defaults folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{795828a9-f271-43a8-8536-4484bb991d3d}\searchplugin folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{795828a9-f271-43a8-8536-4484bb991d3d}\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{795828a9-f271-43a8-8536-4484bb991d3d}\lib folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{795828a9-f271-43a8-8536-4484bb991d3d}\defaults folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{795828a9-f271-43a8-8536-4484bb991d3d}\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{795828a9-f271-43a8-8536-4484bb991d3d}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{795828a9-f271-43a8-8536-4484bb991d3d} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\searchplugin folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\lib folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\defaults folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\searchplugin folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\lib folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\defaults folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{930f1200-f5f1-4870-bac6-e233ec8e7023} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{9d81af43-de53-48d0-a199-42c2a226b24c}\searchplugin folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{9d81af43-de53-48d0-a199-42c2a226b24c}\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{9d81af43-de53-48d0-a199-42c2a226b24c}\lib folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{9d81af43-de53-48d0-a199-42c2a226b24c}\defaults folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{9d81af43-de53-48d0-a199-42c2a226b24c}\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{9d81af43-de53-48d0-a199-42c2a226b24c}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{9d81af43-de53-48d0-a199-42c2a226b24c} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\searchplugin folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\lib folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\defaults folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\searchplugin folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\lib folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\defaults folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{b9d63c58-90cc-428b-8d3b-cbb88eb07e7e} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\searchplugin folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\lib folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\defaults folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e84cc2c1-b722-48fc-a39c-edb8b525c777}\searchplugin folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e84cc2c1-b722-48fc-a39c-edb8b525c777}\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e84cc2c1-b722-48fc-a39c-edb8b525c777}\lib folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e84cc2c1-b722-48fc-a39c-edb8b525c777}\defaults folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e84cc2c1-b722-48fc-a39c-edb8b525c777}\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e84cc2c1-b722-48fc-a39c-edb8b525c777}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e84cc2c1-b722-48fc-a39c-edb8b525c777} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\searchplugin folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\lib folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\defaults folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{e9911ec6-1bcc-40b0-9993-e0eea7f6953f} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847} folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\engine@conduit.com\searchplugin folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\engine@conduit.com\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\engine@conduit.com\lib folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\engine@conduit.com\DualPackage folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\engine@conduit.com\defaults folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\engine@conduit.com\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\engine@conduit.com\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\engine@conduit.com folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\radiobar@toolbar\META-INF folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\radiobar@toolbar\components folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\radiobar@toolbar\chrome folder moved successfully. C:\Users\Benedikt\AppData\Roaming\mozilla\Firefox\Profiles\g9q8ziwh.default\extensions\radiobar@toolbar folder moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\ask.xml moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\conduit.xml moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\icqplugin-1.xml moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\icqplugin-2.xml moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\icqplugin-3.xml moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\icqplugin-4.xml moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\icqplugin-5.xml moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\icqplugin-6.xml moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\icqplugin.gif moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\icqplugin.src moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\icqplugin.xml moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\sweetim.xml moved successfully. C:\Users\Benedikt\AppData\Roaming\Mozilla\Firefox\Profiles\g9q8ziwh.default\searchplugins\web-search.xml moved successfully. C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully. C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully. C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully. C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully. C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully. C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully. C:\Program Files (x86)\mozilla firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\content scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\components scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\chrome scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN scheduled to be moved on reboot. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ deleted successfully. C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\ not found. Registry delete failed. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ scheduled to be deleted on reboot. Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ . File move failed. C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll scheduled to be moved on reboot. Registry delete failed. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}\ scheduled to be deleted on reboot. Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}\ . File move failed. C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLL scheduled to be moved on reboot. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}\ deleted successfully. C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found. File C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{5e5ab302-7f65-44cd-8211-c1d4caaccea3} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5e5ab302-7f65-44cd-8211-c1d4caaccea3}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully. Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ . File move failed. C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll scheduled to be moved on reboot. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8dcb7100-df86-4384-8842-8fa844297b3f} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f}\ deleted successfully. File C:\Program Files (x86)\Microsoft\BingBar\BingExt.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b2e293ee-fd7e-4c71-a714-5f4750d8d7b7}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{30F9B915-B755-4826-820B-08FBA6BD249D} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30F9B915-B755-4826-820B-08FBA6BD249D}\ not found. File C:\Program Files (x86)\ConduitEngine\ConduitEngine.dll not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5E5AB302-7F65-44CD-8211-C1D4CAACCEA3}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} deleted successfully. Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA}\ . File move failed. C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll scheduled to be moved on reboot. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B2E293EE-FD7E-4C71-A714-5F4750D8D7B7}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7c74336a-6882-11de-a82a-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7c74336a-6882-11de-a82a-806e6f6e6963}\ not found. File D:\Start.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7c74336a-6882-11de-a82a-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7c74336a-6882-11de-a82a-806e6f6e6963}\ not found. File D:\Start.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f3e0ad12-688b-11de-aed2-00241d16dca0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f3e0ad12-688b-11de-aed2-00241d16dca0}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f3e0ad12-688b-11de-aed2-00241d16dca0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f3e0ad12-688b-11de-aed2-00241d16dca0}\ not found. File I:\pushinst.exe not found. ========== COMMANDS ========== File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. HOSTS file reset successfully OTL by OldTimer - Version 3.2.22.3 log created on 05192011_200514 Files\Folders moved on Reboot... Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\content scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\components scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\chrome scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\content scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\components scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\chrome\skin scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN\chrome scheduled to be moved on reboot. Folder move failed. C:\PROGRAMDATA\NORTON\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.5.0.125\COFFPLGN scheduled to be moved on reboot. File move failed. C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coIEPlg.dll scheduled to be moved on reboot. File move failed. C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\IPS\IPSBHO.DLL scheduled to be moved on reboot. File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. Registry entries deleted on Reboot... Registry delete failed. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ scheduled to be deleted on reboot. Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{602ADB0E-4AFF-4217-8AA1-95DAC4DFA408}\ . Registry delete failed. HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}\ scheduled to be deleted on reboot. Unable to delete registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6D53EC84-6AAE-4787-AEEE-F4628F01010C}\ . |
Bitte nun dieses Tool von Kaspersky ausführen und das Log posten => http://www.trojaner-board.de/82358-t...entfernen.html Das Tool so einstellen wie unten im Bild angegeben - also beide Haken setzen, auf Start scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. http://www.trojaner-board.de/attachm...rnen-start.png Falls du durch die Infektion auf deine Dokumente/Eigenen Dateien nicht zugreifen kannst, bitte unhide ausführen: Downloade dir bitte unhide.exe und speichere diese Datei auf deinem Desktop. Starte das Tool und es sollten alle Dateien und Ordner wieder sichtbar sein. ( Könnte eine Weile dauern ) http://www.trojaner-board.de/images/icons/icon4.gif Vista und 7 User müssen das Tool per Rechtsklick als Administrator ausführen! http://www.trojaner-board.de/images/icons/icon4.gif |
Alle Zeitangaben in WEZ +1. Es ist jetzt 10:22 Uhr. |
Copyright ©2000-2025, Trojaner-Board