![]() |
Avira-Windowssystem blockiert / BKA-Trojaner :( Hey, Ich hoffe , dass man mir hier irgendwie helfen kann. Seit gestern verdunkelt sich plötzlich mein Bildschirm nach ca. 10 min surfen, dann kommt ein weißes Fenster "Avira - ihr Windowssystem wurde blockiert.." mit einer Zahlungsaufforderung. Da mir das gestern nach diversen Neustarts immer wieder passiert ist , hab ich es mal gegoogelt und schnell rausgefunden dass es sich um diesen BkA- Trojaner handeln muss. Wie kann ich diesen Virus wieder von meinem Laptop jagen?:/ Könnte mir da bitte jemand behilflich sein? Leider bin ich kein großer PC-Profi, sodass es nett wäre, wenn mir das jemand verständlich erklären könnte. Besten Dank schonmal , Julie |
Hi, OTL Lade Dir OTL von Oldtimer herunter (http://filepony.de/download-otl/) und speichere es auf Deinem Desktop
TDSS-Killer Download und Anweisung unter: Wie werden Schadprogramme der Familie Rootkit.Win32.TDSS bekämpft? Entpacke alle Dateien in einem eigenen Verzeichnis (z. B: C:\TDSS)! Aufruf über den Explorer duch Doppelklick auf die TDSSKiller.exe. Stelle den Killer wir folgt ein: http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg Dann den Scan starten durch (Start Scan). Wenn der Scan fertig ist bitte "Report" anwählen (eventuelle Funde erstmal mit Skip übergehen). Es öffnet sich ein Fenster, den Text abkopieren und hier posten... chris |
OTL Logfile: Code: OTL logfile created on: 07.03.2012 23:27:18 - Run 1 |
OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 07.03.2012 23:27:18 - Run 1 |
Ich bedanke mich schonmal recht herzlich ! Muss ich nun noch iwas machen oder beachten? |
Hi, bitte noch das Log vom TDSS-Killer posten... Fix für OTL:
Code:
Malwarebytes Antimalware (MAM) Anleitung&Download hier: http://www.trojaner-board.de/51187-m...i-malware.html Falls der Download nicht klappt, bitte hierüber eine generische Version runterladen: http://filepony.de/download-chameleon/ Danach bitte update der Signaturdateien (Reiter "Aktualisierungen" -> Suche nach Aktualisierungen") Fullscan und alles bereinigen lassen! Log posten. chris |
13:14:34.0375 3416 TDSS rootkit removing tool 2.7.19.0 Mar 5 2012 11:23:39 13:14:35.0781 3416 ============================================================ 13:14:35.0781 3416 Current date / time: 2012/03/08 13:14:35.0781 13:14:35.0781 3416 SystemInfo: 13:14:35.0781 3416 13:14:35.0781 3416 OS Version: 5.1.2600 ServicePack: 3.0 13:14:35.0781 3416 Product type: Workstation 13:14:35.0781 3416 ComputerName: WOLSKI-BCC8AC0E 13:14:35.0781 3416 UserName: Julska 13:14:35.0781 3416 Windows directory: C:\WINDOWS 13:14:35.0781 3416 System windows directory: C:\WINDOWS 13:14:35.0781 3416 Processor architecture: Intel x86 13:14:35.0781 3416 Number of processors: 2 13:14:35.0781 3416 Page size: 0x1000 13:14:35.0781 3416 Boot type: Normal boot 13:14:35.0781 3416 ============================================================ 13:14:37.0437 3416 Drive \Device\Harddisk0\DR0 - Size: 0x25433D6000 (149.05 Gb), SectorSize: 0x200, Cylinders: 0x4C01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000054 13:14:37.0453 3416 \Device\Harddisk0\DR0: 13:14:37.0453 3416 MBR used 13:14:37.0453 3416 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x1D4B139 13:14:37.0453 3416 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1D4B1B7, BlocksNum 0x10CC9A49 13:14:37.0750 3416 Initialize success 13:14:37.0750 3416 ============================================================ 13:14:59.0437 3232 ============================================================ 13:14:59.0437 3232 Scan started 13:14:59.0437 3232 Mode: Manual; SigCheck; TDLFS; 13:14:59.0437 3232 ============================================================ 13:14:59.0734 3232 Abiosdsk - ok 13:14:59.0734 3232 abp480n5 - ok 13:14:59.0781 3232 ACPI (ac407f1a62c3a300b4f2b5a9f1d55b2c) C:\WINDOWS\system32\DRIVERS\ACPI.sys 13:15:00.0703 3232 ACPI - ok 13:15:00.0781 3232 ACPIEC (9e1ca3160dafb159ca14f83b1e317f75) C:\WINDOWS\system32\DRIVERS\ACPIEC.sys 13:15:00.0937 3232 ACPIEC - ok 13:15:00.0953 3232 adpu160m - ok 13:15:00.0984 3232 aec (8bed39e3c35d6a489438b8141717a557) C:\WINDOWS\system32\drivers\aec.sys 13:15:01.0156 3232 aec - ok 13:15:01.0203 3232 AegisP (2c5c22990156a1063e19ad162191dc1d) C:\WINDOWS\system32\DRIVERS\AegisP.sys 13:15:01.0218 3232 AegisP ( UnsignedFile.Multi.Generic ) - warning 13:15:01.0218 3232 AegisP - detected UnsignedFile.Multi.Generic (1) 13:15:01.0265 3232 AF15BDA (ad0565605d67500ca1c25d3a415d3dce) C:\WINDOWS\system32\drivers\AF15BDA.sys 13:15:01.0296 3232 AF15BDA ( UnsignedFile.Multi.Generic ) - warning 13:15:01.0296 3232 AF15BDA - detected UnsignedFile.Multi.Generic (1) 13:15:01.0375 3232 AFD (1e44bc1e83d8fd2305f8d452db109cf9) C:\WINDOWS\System32\drivers\afd.sys 13:15:01.0437 3232 AFD - ok 13:15:01.0453 3232 Aha154x - ok 13:15:01.0453 3232 aic78u2 - ok 13:15:01.0468 3232 aic78xx - ok 13:15:01.0484 3232 AliIde - ok 13:15:01.0531 3232 AmdK8 (22ad3ec1f0486c863d70cdd50b97761b) C:\WINDOWS\system32\DRIVERS\AmdK8.sys 13:15:01.0546 3232 AmdK8 ( UnsignedFile.Multi.Generic ) - warning 13:15:01.0546 3232 AmdK8 - detected UnsignedFile.Multi.Generic (1) 13:15:01.0546 3232 amsint - ok 13:15:01.0578 3232 asc - ok 13:15:01.0578 3232 asc3350p - ok 13:15:01.0593 3232 asc3550 - ok 13:15:01.0640 3232 AsyncMac (b153affac761e7f5fcfa822b9c4e97bc) C:\WINDOWS\system32\DRIVERS\asyncmac.sys 13:15:01.0796 3232 AsyncMac - ok 13:15:01.0890 3232 atapi (9f3a2f5aa6875c72bf062c712cfa2674) C:\WINDOWS\system32\DRIVERS\atapi.sys 13:15:02.0062 3232 atapi - ok 13:15:02.0062 3232 Atdisk - ok 13:15:02.0093 3232 Atmarpc (9916c1225104ba14794209cfa8012159) C:\WINDOWS\system32\DRIVERS\atmarpc.sys 13:15:02.0250 3232 Atmarpc - ok 13:15:02.0328 3232 audstub (d9f724aa26c010a217c97606b160ed68) C:\WINDOWS\system32\DRIVERS\audstub.sys 13:15:02.0468 3232 audstub - ok 13:15:02.0546 3232 avgio (0b497c79824f8e1bf22fa6aacd3de3a0) C:\Programme\Avira\AntiVir Desktop\avgio.sys 13:15:02.0562 3232 avgio - ok 13:15:02.0593 3232 avgntflt (14fe36d8f2c6a2435275338d061a0b66) C:\WINDOWS\system32\DRIVERS\avgntflt.sys 13:15:02.0671 3232 avgntflt - ok 13:15:02.0703 3232 avipbb (6d52060b59e7d79cd2a044b6add1f1ef) C:\WINDOWS\system32\DRIVERS\avipbb.sys 13:15:02.0718 3232 avipbb - ok 13:15:02.0750 3232 Beep (da1f27d85e0d1525f6621372e7b685e9) C:\WINDOWS\system32\drivers\Beep.sys 13:15:02.0906 3232 Beep - ok 13:15:02.0984 3232 cbidf2k (90a673fc8e12a79afbed2576f6a7aaf9) C:\WINDOWS\system32\drivers\cbidf2k.sys 13:15:03.0156 3232 cbidf2k - ok 13:15:03.0250 3232 CCDECODE (0be5aef125be881c4f854c554f2b025c) C:\WINDOWS\system32\DRIVERS\CCDECODE.sys 13:15:03.0421 3232 CCDECODE - ok 13:15:03.0421 3232 cd20xrnt - ok 13:15:03.0484 3232 Cdaudio (c1b486a7658353d33a10cc15211a873b) C:\WINDOWS\system32\drivers\Cdaudio.sys 13:15:03.0640 3232 Cdaudio - ok 13:15:03.0687 3232 Cdfs (c885b02847f5d2fd45a24e219ed93b32) C:\WINDOWS\system32\drivers\Cdfs.sys 13:15:03.0875 3232 Cdfs - ok 13:15:03.0906 3232 Cdrom (1f4260cc5b42272d71f79e570a27a4fe) C:\WINDOWS\system32\DRIVERS\cdrom.sys 13:15:04.0093 3232 Cdrom - ok 13:15:04.0234 3232 CmBatt (0f6c187d38d98f8df904589a5f94d411) C:\WINDOWS\system32\DRIVERS\CmBatt.sys 13:15:04.0390 3232 CmBatt - ok 13:15:04.0406 3232 CmdIde - ok 13:15:04.0468 3232 Compbatt (6e4c9f21f0fae8940661144f41b13203) C:\WINDOWS\system32\DRIVERS\compbatt.sys 13:15:04.0640 3232 Compbatt - ok 13:15:04.0656 3232 Cpqarray - ok 13:15:04.0671 3232 dac2w2k - ok 13:15:04.0687 3232 dac960nt - ok 13:15:04.0703 3232 Disk (044452051f3e02e7963599fc8f4f3e25) C:\WINDOWS\system32\DRIVERS\disk.sys 13:15:04.0921 3232 Disk - ok 13:15:04.0968 3232 dmboot (0dcfc8395a99fecbb1ef771cec7fe4ea) C:\WINDOWS\system32\drivers\dmboot.sys 13:15:05.0187 3232 dmboot - ok 13:15:05.0234 3232 dmio (53720ab12b48719d00e327da470a619a) C:\WINDOWS\system32\drivers\dmio.sys 13:15:05.0421 3232 dmio - ok 13:15:05.0515 3232 dmload (e9317282a63ca4d188c0df5e09c6ac5f) C:\WINDOWS\system32\drivers\dmload.sys 13:15:05.0687 3232 dmload - ok 13:15:05.0734 3232 DMusic (8a208dfcf89792a484e76c40e5f50b45) C:\WINDOWS\system32\drivers\DMusic.sys 13:15:05.0906 3232 DMusic - ok 13:15:05.0906 3232 dpti2o - ok 13:15:05.0953 3232 drmkaud (8f5fcff8e8848afac920905fbd9d33c8) C:\WINDOWS\system32\drivers\drmkaud.sys 13:15:06.0109 3232 drmkaud - ok 13:15:06.0203 3232 EU3_USB (9d38d8cf163c03335ceb28bc391b75e0) C:\WINDOWS\system32\DRIVERS\EU3USB.sys 13:15:06.0281 3232 EU3_USB ( UnsignedFile.Multi.Generic ) - warning 13:15:06.0281 3232 EU3_USB - detected UnsignedFile.Multi.Generic (1) 13:15:06.0375 3232 Fastfat (38d332a6d56af32635675f132548343e) C:\WINDOWS\system32\drivers\Fastfat.sys 13:15:06.0578 3232 Fastfat - ok 13:15:06.0609 3232 Fdc (92cdd60b6730b9f50f6a1a0c1f8cdc81) C:\WINDOWS\system32\drivers\Fdc.sys 13:15:06.0796 3232 Fdc - ok 13:15:06.0875 3232 FET5X86V (e7072827d0b5f9bd99d6961571a38973) C:\WINDOWS\system32\DRIVERS\fetnd5bv.sys 13:15:06.0937 3232 FET5X86V - ok 13:15:06.0968 3232 FETNDIS (e9648254056bce81a85380c0c3647dc4) C:\WINDOWS\system32\DRIVERS\fetnd5.sys 13:15:07.0140 3232 FETNDIS - ok 13:15:07.0234 3232 Fips (b0678a548587c5f1967b0d70bacad6c1) C:\WINDOWS\system32\drivers\Fips.sys 13:15:07.0406 3232 Fips - ok 13:15:07.0421 3232 Flpydisk (9d27e7b80bfcdf1cdd9b555862d5e7f0) C:\WINDOWS\system32\drivers\Flpydisk.sys 13:15:07.0609 3232 Flpydisk - ok 13:15:07.0640 3232 FltMgr (b2cf4b0786f8212cb92ed2b50c6db6b0) C:\WINDOWS\system32\DRIVERS\fltMgr.sys 13:15:07.0828 3232 FltMgr - ok 13:15:07.0843 3232 Fs_Rec (3e1e2bd4f39b0e2b7dc4f4d2bcc2779a) C:\WINDOWS\system32\drivers\Fs_Rec.sys 13:15:08.0046 3232 Fs_Rec - ok 13:15:08.0078 3232 Ftdisk (8f1955ce42e1484714b542f341647778) C:\WINDOWS\system32\DRIVERS\ftdisk.sys 13:15:08.0328 3232 Ftdisk - ok 13:15:08.0406 3232 gagp30kx (3a74c423cf6bcca6982715878f450a3b) C:\WINDOWS\system32\DRIVERS\gagp30kx.sys 13:15:08.0609 3232 gagp30kx - ok 13:15:08.0656 3232 GEARAspiWDM (8182ff89c65e4d38b2de4bb0fb18564e) C:\WINDOWS\system32\DRIVERS\GEARAspiWDM.sys 13:15:08.0687 3232 GEARAspiWDM - ok 13:15:08.0718 3232 Gpc (0a02c63c8b144bd8c86b103dee7c86a2) C:\WINDOWS\system32\DRIVERS\msgpc.sys 13:15:08.0890 3232 Gpc - ok 13:15:08.0906 3232 gtstusbser - ok 13:15:08.0953 3232 HdAudAddService (b93f1aedbe74c100efd4f6b4a27907b2) C:\WINDOWS\system32\drivers\viahduaa.sys 13:15:09.0015 3232 HdAudAddService - ok 13:15:09.0109 3232 HDAudBus (573c7d0a32852b48f3058cfd8026f511) C:\WINDOWS\system32\DRIVERS\HDAudBus.sys 13:15:09.0281 3232 HDAudBus - ok 13:15:09.0296 3232 hpn - ok 13:15:09.0343 3232 HTTP (f80a415ef82cd06ffaf0d971528ead38) C:\WINDOWS\system32\Drivers\HTTP.sys 13:15:09.0406 3232 HTTP - ok 13:15:09.0421 3232 hwdatacard - ok 13:15:09.0437 3232 i2omgmt - ok 13:15:09.0453 3232 i2omp - ok 13:15:09.0484 3232 i8042prt (e283b97cfbeb86c1d86baed5f7846a92) C:\WINDOWS\system32\DRIVERS\i8042prt.sys 13:15:09.0656 3232 i8042prt - ok 13:15:09.0687 3232 Imapi (083a052659f5310dd8b6a6cb05edcf8e) C:\WINDOWS\system32\DRIVERS\imapi.sys 13:15:09.0875 3232 Imapi - ok 13:15:09.0984 3232 ini910u - ok 13:15:10.0000 3232 IntelIde - ok 13:15:10.0031 3232 Ip6Fw (3bb22519a194418d5fec05d800a19ad0) C:\WINDOWS\system32\DRIVERS\Ip6Fw.sys 13:15:10.0218 3232 Ip6Fw - ok 13:15:10.0281 3232 IpFilterDriver (731f22ba402ee4b62748adaf6363c182) C:\WINDOWS\system32\DRIVERS\ipfltdrv.sys 13:15:10.0453 3232 IpFilterDriver - ok 13:15:10.0500 3232 IpInIp (b87ab476dcf76e72010632b5550955f5) C:\WINDOWS\system32\DRIVERS\ipinip.sys 13:15:10.0671 3232 IpInIp - ok 13:15:10.0703 3232 IpNat (cc748ea12c6effde940ee98098bf96bb) C:\WINDOWS\system32\DRIVERS\ipnat.sys 13:15:10.0890 3232 IpNat - ok 13:15:10.0953 3232 IPSec (23c74d75e36e7158768dd63d92789a91) C:\WINDOWS\system32\DRIVERS\ipsec.sys 13:15:11.0125 3232 IPSec - ok 13:15:11.0156 3232 IRENUM (c93c9ff7b04d772627a3646d89f7bf89) C:\WINDOWS\system32\DRIVERS\irenum.sys 13:15:11.0234 3232 IRENUM - ok 13:15:11.0265 3232 isapnp (6dfb88f64135c525433e87648bda30de) C:\WINDOWS\system32\DRIVERS\isapnp.sys 13:15:11.0421 3232 isapnp - ok 13:15:11.0515 3232 Kbdclass (1704d8c4c8807b889e43c649b478a452) C:\WINDOWS\system32\DRIVERS\kbdclass.sys 13:15:11.0703 3232 Kbdclass - ok 13:15:11.0734 3232 kmixer (692bcf44383d056aed41b045a323d378) C:\WINDOWS\system32\drivers\kmixer.sys 13:15:11.0906 3232 kmixer - ok 13:15:11.0937 3232 KSecDD (b467646c54cc746128904e1654c750c1) C:\WINDOWS\system32\drivers\KSecDD.sys 13:15:12.0031 3232 KSecDD - ok 13:15:12.0078 3232 lbrtfdc - ok 13:15:12.0125 3232 massfilter (09721f2c56681a83c93ecdfab8b102a9) C:\WINDOWS\system32\drivers\massfilter.sys 13:15:12.0156 3232 massfilter - ok 13:15:12.0171 3232 mnmdd (4ae068242760a1fb6e1a44bf4e16afa6) C:\WINDOWS\system32\drivers\mnmdd.sys 13:15:12.0343 3232 mnmdd - ok 13:15:12.0390 3232 Modem (6fb74ebd4ec57a6f1781de3852cc3362) C:\WINDOWS\system32\drivers\Modem.sys 13:15:12.0546 3232 Modem - ok 13:15:12.0609 3232 Mouclass (b24ce8005deab254c0251e15cb71d802) C:\WINDOWS\system32\DRIVERS\mouclass.sys 13:15:12.0796 3232 Mouclass - ok 13:15:12.0828 3232 MountMgr (a80b9a0bad1b73637dbcbba7df72d3fd) C:\WINDOWS\system32\drivers\MountMgr.sys 13:15:13.0000 3232 MountMgr - ok 13:15:13.0062 3232 MPE (c0f8e0c2c3c0437cf37c6781896dc3ec) C:\WINDOWS\system32\DRIVERS\MPE.sys 13:15:13.0234 3232 MPE - ok 13:15:13.0296 3232 mraid35x - ok 13:15:13.0312 3232 MRxDAV (11d42bb6206f33fbb3ba0288d3ef81bd) C:\WINDOWS\system32\DRIVERS\mrxdav.sys 13:15:13.0500 3232 MRxDAV - ok 13:15:13.0546 3232 MRxSmb (7d304a5eb4344ebeeab53a2fe3ffb9f0) C:\WINDOWS\system32\DRIVERS\mrxsmb.sys 13:15:14.0265 3232 MRxSmb - ok 13:15:14.0468 3232 Msfs (c941ea2454ba8350021d774daf0f1027) C:\WINDOWS\system32\drivers\Msfs.sys 13:15:14.0656 3232 Msfs - ok 13:15:14.0687 3232 MSKSSRV (d1575e71568f4d9e14ca56b7b0453bf1) C:\WINDOWS\system32\drivers\MSKSSRV.sys 13:15:14.0875 3232 MSKSSRV - ok 13:15:14.0921 3232 MSPCLOCK (325bb26842fc7ccc1fcce2c457317f3e) C:\WINDOWS\system32\drivers\MSPCLOCK.sys 13:15:15.0093 3232 MSPCLOCK - ok 13:15:15.0109 3232 MSPQM (bad59648ba099da4a17680b39730cb3d) C:\WINDOWS\system32\drivers\MSPQM.sys 13:15:15.0296 3232 MSPQM - ok 13:15:15.0328 3232 mssmbios (af5f4f3f14a8ea2c26de30f7a1e17136) C:\WINDOWS\system32\DRIVERS\mssmbios.sys 13:15:15.0500 3232 mssmbios - ok 13:15:15.0546 3232 MSTEE (e53736a9e30c45fa9e7b5eac55056d1d) C:\WINDOWS\system32\drivers\MSTEE.sys 13:15:15.0718 3232 MSTEE - ok 13:15:15.0812 3232 Mup (de6a75f5c270e756c5508d94b6cf68f5) C:\WINDOWS\system32\drivers\Mup.sys 13:15:15.0828 3232 Mup - ok 13:15:15.0843 3232 NABTSFEC (5b50f1b2a2ed47d560577b221da734db) C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys 13:15:16.0015 3232 NABTSFEC - ok 13:15:16.0093 3232 NDIS (1df7f42665c94b825322fae71721130d) C:\WINDOWS\system32\drivers\NDIS.sys 13:15:16.0281 3232 NDIS - ok 13:15:16.0343 3232 NdisIP (7ff1f1fd8609c149aa432f95a8163d97) C:\WINDOWS\system32\DRIVERS\NdisIP.sys 13:15:16.0515 3232 NdisIP - ok 13:15:16.0578 3232 NdisTapi (0109c4f3850dfbab279542515386ae22) C:\WINDOWS\system32\DRIVERS\ndistapi.sys 13:15:16.0625 3232 NdisTapi - ok 13:15:16.0656 3232 Ndisuio (f927a4434c5028758a842943ef1a3849) C:\WINDOWS\system32\DRIVERS\ndisuio.sys 13:15:16.0828 3232 Ndisuio - ok 13:15:16.0859 3232 NdisWan (edc1531a49c80614b2cfda43ca8659ab) C:\WINDOWS\system32\DRIVERS\ndiswan.sys 13:15:17.0046 3232 NdisWan - ok 13:15:17.0093 3232 NDProxy (9282bd12dfb069d3889eb3fcc1000a9b) C:\WINDOWS\system32\drivers\NDProxy.sys 13:15:17.0125 3232 NDProxy - ok 13:15:17.0203 3232 Netaapl (1352e1648213551923a0a822e441553c) C:\WINDOWS\system32\DRIVERS\netaapl.sys 13:15:17.0218 3232 Netaapl - ok 13:15:17.0250 3232 NetBIOS (5d81cf9a2f1a3a756b66cf684911cdf0) C:\WINDOWS\system32\DRIVERS\netbios.sys 13:15:17.0421 3232 NetBIOS - ok 13:15:17.0453 3232 NetBT (74b2b2f5bea5e9a3dc021d685551bd3d) C:\WINDOWS\system32\DRIVERS\netbt.sys 13:15:17.0640 3232 NetBT - ok 13:15:17.0703 3232 nm (1e421a6bcf2203cc61b821ada9de878b) C:\WINDOWS\system32\DRIVERS\NMnt.sys 13:15:17.0890 3232 nm - ok 13:15:17.0968 3232 Npfs (3182d64ae053d6fb034f44b6def8034a) C:\WINDOWS\system32\drivers\Npfs.sys 13:15:18.0125 3232 Npfs - ok 13:15:18.0187 3232 Ntfs (78a08dd6a8d65e697c18e1db01c5cdca) C:\WINDOWS\system32\drivers\Ntfs.sys 13:15:18.0437 3232 Ntfs - ok 13:15:18.0484 3232 Null (73c1e1f395918bc2c6dd67af7591a3ad) C:\WINDOWS\system32\drivers\Null.sys 13:15:18.0656 3232 Null - ok 13:15:18.0734 3232 NwlnkFlt (b305f3fad35083837ef46a0bbce2fc57) C:\WINDOWS\system32\DRIVERS\nwlnkflt.sys 13:15:18.0906 3232 NwlnkFlt - ok 13:15:18.0968 3232 NwlnkFwd (c99b3415198d1aab7227f2c88fd664b9) C:\WINDOWS\system32\DRIVERS\nwlnkfwd.sys 13:15:19.0140 3232 NwlnkFwd - ok 13:15:19.0218 3232 NWUSBModem (4e651808b35656ac88a4dcdaf6cc1169) C:\WINDOWS\system32\DRIVERS\nwusbmdm.sys 13:15:19.0281 3232 NWUSBModem - ok 13:15:19.0312 3232 NWUSBPort (4e651808b35656ac88a4dcdaf6cc1169) C:\WINDOWS\system32\DRIVERS\nwusbser.sys 13:15:19.0343 3232 NWUSBPort - ok 13:15:19.0359 3232 Packet - ok 13:15:19.0406 3232 Parport (f84785660305b9b903fb3bca8ba29837) C:\WINDOWS\system32\drivers\Parport.sys 13:15:19.0578 3232 Parport - ok 13:15:19.0640 3232 PartMgr (beb3ba25197665d82ec7065b724171c6) C:\WINDOWS\system32\drivers\PartMgr.sys 13:15:19.0812 3232 PartMgr - ok 13:15:19.0921 3232 ParVdm (c2bf987829099a3eaa2ca6a0a90ecb4f) C:\WINDOWS\system32\drivers\ParVdm.sys 13:15:20.0078 3232 ParVdm - ok 13:15:20.0109 3232 PCANDIS5 (2f9806b52cb3748b1e49222744b28e3c) C:\WINDOWS\system32\PCANDIS5.SYS 13:15:20.0140 3232 PCANDIS5 ( UnsignedFile.Multi.Generic ) - warning 13:15:20.0140 3232 PCANDIS5 - detected UnsignedFile.Multi.Generic (1) 13:15:20.0171 3232 pccsmcfd (175cc28dcf819f78caa3fbd44ad9e52a) C:\WINDOWS\system32\DRIVERS\pccsmcfd.sys 13:15:20.0218 3232 pccsmcfd - ok 13:15:20.0265 3232 PCI (387e8dedc343aa2d1efbc30580273acd) C:\WINDOWS\system32\DRIVERS\pci.sys 13:15:20.0437 3232 PCI - ok 13:15:20.0500 3232 PCIDump - ok 13:15:20.0546 3232 PCIIde (59ba86d9a61cbcf4df8e598c331f5b82) C:\WINDOWS\system32\DRIVERS\pciide.sys 13:15:20.0703 3232 PCIIde - ok 13:15:20.0765 3232 Pcmcia (a2a966b77d61847d61a3051df87c8c97) C:\WINDOWS\system32\drivers\Pcmcia.sys 13:15:20.0921 3232 Pcmcia - ok 13:15:21.0000 3232 PDCOMP - ok 13:15:21.0015 3232 PDFRAME - ok 13:15:21.0015 3232 PDRELI - ok 13:15:21.0031 3232 PDRFRAME - ok 13:15:21.0046 3232 perc2 - ok 13:15:21.0062 3232 perc2hib - ok 13:15:21.0093 3232 PptpMiniport (efeec01b1d3cf84f16ddd24d9d9d8f99) C:\WINDOWS\system32\DRIVERS\raspptp.sys 13:15:21.0281 3232 PptpMiniport - ok 13:15:21.0343 3232 PRISM_A02 (898890eaadda2892f6237a63f351dd58) C:\WINDOWS\system32\DRIVERS\PRISMA02.sys 13:15:21.0406 3232 PRISM_A02 ( UnsignedFile.Multi.Generic ) - warning 13:15:21.0406 3232 PRISM_A02 - detected UnsignedFile.Multi.Generic (1) 13:15:21.0500 3232 Processor (2cb55427c58679f49ad600fccba76360) C:\WINDOWS\system32\DRIVERS\processr.sys 13:15:21.0671 3232 Processor - ok 13:15:21.0734 3232 PSched (09298ec810b07e5d582cb3a3f9255424) C:\WINDOWS\system32\DRIVERS\psched.sys 13:15:21.0906 3232 PSched - ok 13:15:21.0968 3232 Ptilink (80d317bd1c3dbc5d4fe7b1678c60cadd) C:\WINDOWS\system32\DRIVERS\ptilink.sys 13:15:22.0140 3232 Ptilink - ok 13:15:22.0250 3232 PxHelp20 (e42e3433dbb4cffe8fdd91eab29aea8e) C:\WINDOWS\system32\Drivers\PxHelp20.sys 13:15:22.0265 3232 PxHelp20 - ok 13:15:22.0281 3232 ql1080 - ok 13:15:22.0296 3232 Ql10wnt - ok 13:15:22.0296 3232 ql12160 - ok 13:15:22.0312 3232 ql1240 - ok 13:15:22.0328 3232 ql1280 - ok 13:15:22.0359 3232 RasAcd (fe0d99d6f31e4fad8159f690d68ded9c) C:\WINDOWS\system32\DRIVERS\rasacd.sys 13:15:22.0546 3232 RasAcd - ok 13:15:22.0609 3232 Rasl2tp (11b4a627bc9614b885c4969bfa5ff8a6) C:\WINDOWS\system32\DRIVERS\rasl2tp.sys 13:15:22.0765 3232 Rasl2tp - ok 13:15:22.0828 3232 RasPppoe (5bc962f2654137c9909c3d4603587dee) C:\WINDOWS\system32\DRIVERS\raspppoe.sys 13:15:22.0984 3232 RasPppoe - ok 13:15:23.0015 3232 Raspti (fdbb1d60066fcfbb7452fd8f9829b242) C:\WINDOWS\system32\DRIVERS\raspti.sys 13:15:23.0171 3232 Raspti - ok 13:15:23.0281 3232 Rdbss (7ad224ad1a1437fe28d89cf22b17780a) C:\WINDOWS\system32\DRIVERS\rdbss.sys 13:15:23.0453 3232 Rdbss - ok 13:15:23.0484 3232 RDPCDD (4912d5b403614ce99c28420f75353332) C:\WINDOWS\system32\DRIVERS\RDPCDD.sys 13:15:23.0656 3232 RDPCDD - ok 13:15:23.0734 3232 rdpdr (15cabd0f7c00c47c70124907916af3f1) C:\WINDOWS\system32\DRIVERS\rdpdr.sys 13:15:23.0890 3232 rdpdr - ok 13:15:23.0953 3232 RDPWD (fc105dd312ed64eb66bff111e8ec6eac) C:\WINDOWS\system32\drivers\RDPWD.sys 13:15:23.0984 3232 RDPWD - ok 13:15:24.0062 3232 redbook (ed761d453856f795a7fe056e42c36365) C:\WINDOWS\system32\DRIVERS\redbook.sys 13:15:24.0218 3232 redbook - ok 13:15:24.0359 3232 S3GIGP (7e8f62b62f3b85b88f2fa1b6399b06f2) C:\WINDOWS\system32\DRIVERS\S3gIGPm.sys 13:15:24.0437 3232 S3GIGP - ok 13:15:24.0500 3232 Secdrv (90a3935d05b494a5a39d37e71f09a677) C:\WINDOWS\system32\DRIVERS\secdrv.sys 13:15:24.0562 3232 Secdrv - ok 13:15:24.0609 3232 Serial (cf24eb4f0412c82bcd1f4f35a025e31d) C:\WINDOWS\system32\drivers\Serial.sys 13:15:24.0781 3232 Serial - ok 13:15:24.0843 3232 Sfloppy (8e6b8c671615d126fdc553d1e2de5562) C:\WINDOWS\system32\drivers\Sfloppy.sys 13:15:25.0000 3232 Sfloppy - ok 13:15:25.0015 3232 Simbad - ok 13:15:25.0078 3232 SIS163u (30bed9b9dd98ffeb41af5d5cab972ef7) C:\WINDOWS\system32\DRIVERS\sis163u.sys 13:15:25.0109 3232 SIS163u ( UnsignedFile.Multi.Generic ) - warning 13:15:25.0109 3232 SIS163u - detected UnsignedFile.Multi.Generic (1) 13:15:25.0156 3232 SLIP (866d538ebe33709a5c9f5c62b73b7d14) C:\WINDOWS\system32\DRIVERS\SLIP.sys 13:15:25.0343 3232 SLIP - ok 13:15:25.0390 3232 smserial - ok 13:15:25.0406 3232 Sparrow - ok 13:15:25.0437 3232 splitter (ab8b92451ecb048a4d1de7c3ffcb4a9f) C:\WINDOWS\system32\drivers\splitter.sys 13:15:25.0609 3232 splitter - ok 13:15:25.0718 3232 sptd (d15da1ba189770d93eea2d7e18f95af9) C:\WINDOWS\system32\Drivers\sptd.sys 13:15:25.0718 3232 Suspicious file (NoAccess): C:\WINDOWS\system32\Drivers\sptd.sys. md5: d15da1ba189770d93eea2d7e18f95af9 13:15:25.0718 3232 sptd ( LockedFile.Multi.Generic ) - warning 13:15:25.0718 3232 sptd - detected LockedFile.Multi.Generic (1) 13:15:25.0812 3232 sr (50fa898f8c032796d3b1b9951bb5a90f) C:\WINDOWS\system32\DRIVERS\sr.sys 13:15:25.0890 3232 sr - ok 13:15:25.0953 3232 Srv (47ddfc2f003f7f9f0592c6874962a2e7) C:\WINDOWS\system32\DRIVERS\srv.sys 13:15:26.0000 3232 Srv - ok 13:15:26.0062 3232 ssmdrv (5ec550b8952882ee856b862cf648522d) C:\WINDOWS\system32\DRIVERS\ssmdrv.sys 13:15:26.0093 3232 ssmdrv - ok 13:15:26.0125 3232 streamip (77813007ba6265c4b6098187e6ed79d2) C:\WINDOWS\system32\DRIVERS\StreamIP.sys 13:15:26.0281 3232 streamip - ok 13:15:26.0312 3232 swenum (3941d127aef12e93addf6fe6ee027e0f) C:\WINDOWS\system32\DRIVERS\swenum.sys 13:15:26.0500 3232 swenum - ok 13:15:26.0562 3232 swmidi (8ce882bcc6cf8a62f2b2323d95cb3d01) C:\WINDOWS\system32\drivers\swmidi.sys 13:15:26.0734 3232 swmidi - ok 13:15:26.0750 3232 symc810 - ok 13:15:26.0781 3232 symc8xx - ok 13:15:26.0796 3232 sym_hi - ok 13:15:26.0828 3232 sym_u3 - ok 13:15:26.0859 3232 SynTP (cfb41bf11ae95c26133bae3ec2e334bd) C:\WINDOWS\system32\DRIVERS\SynTP.sys 13:15:26.0906 3232 SynTP - ok 13:15:26.0921 3232 sysaudio (8b83f3ed0f1688b4958f77cd6d2bf290) C:\WINDOWS\system32\drivers\sysaudio.sys 13:15:27.0109 3232 sysaudio - ok 13:15:27.0203 3232 Tcpip (9aefa14bd6b182d61e3119fa5f436d3d) C:\WINDOWS\system32\DRIVERS\tcpip.sys 13:15:27.0296 3232 Tcpip - ok 13:15:27.0359 3232 TDPIPE (6471a66807f5e104e4885f5b67349397) C:\WINDOWS\system32\drivers\TDPIPE.sys 13:15:27.0515 3232 TDPIPE - ok 13:15:27.0578 3232 TDTCP (c56b6d0402371cf3700eb322ef3aaf61) C:\WINDOWS\system32\drivers\TDTCP.sys 13:15:27.0765 3232 TDTCP - ok 13:15:27.0796 3232 TermDD (88155247177638048422893737429d9e) C:\WINDOWS\system32\DRIVERS\termdd.sys 13:15:27.0968 3232 TermDD - ok 13:15:28.0000 3232 TosIde - ok 13:15:28.0046 3232 Udfs (5787b80c2e3c5e2f56c2a233d91fa2c9) C:\WINDOWS\system32\drivers\Udfs.sys 13:15:28.0234 3232 Udfs - ok 13:15:28.0375 3232 UfasoftSnifDriver4 - ok 13:15:28.0546 3232 ultra - ok 13:15:28.0593 3232 Update (402ddc88356b1bac0ee3dd1580c76a31) C:\WINDOWS\system32\DRIVERS\update.sys 13:15:28.0796 3232 Update - ok 13:15:28.0812 3232 upperdev - ok 13:15:28.0843 3232 USBAAPL (83cafcb53201bbac04d822f32438e244) C:\WINDOWS\system32\Drivers\usbaapl.sys 13:15:28.0890 3232 USBAAPL - ok 13:15:28.0921 3232 usbccgp (173f317ce0db8e21322e71b7e60a27e8) C:\WINDOWS\system32\DRIVERS\usbccgp.sys 13:15:29.0093 3232 usbccgp - ok 13:15:29.0125 3232 usbehci (65dcf09d0e37d4c6b11b5b0b76d470a7) C:\WINDOWS\system32\DRIVERS\usbehci.sys 13:15:29.0312 3232 usbehci - ok 13:15:29.0406 3232 usbhub (1ab3cdde553b6e064d2e754efe20285c) C:\WINDOWS\system32\DRIVERS\usbhub.sys 13:15:29.0562 3232 usbhub - ok 13:15:29.0625 3232 usbprint (a717c8721046828520c9edf31288fc00) C:\WINDOWS\system32\DRIVERS\usbprint.sys 13:15:29.0796 3232 usbprint - ok 13:15:29.0859 3232 usbscan (a0b8cf9deb1184fbdd20784a58fa75d4) C:\WINDOWS\system32\DRIVERS\usbscan.sys 13:15:30.0015 3232 usbscan - ok 13:15:30.0078 3232 USBSTOR (a32426d9b14a089eaa1d922e0c5801a9) C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS 13:15:30.0250 3232 USBSTOR - ok 13:15:30.0312 3232 usbuhci (26496f9dee2d787fc3e61ad54821ffe6) C:\WINDOWS\system32\DRIVERS\usbuhci.sys 13:15:30.0468 3232 usbuhci - ok 13:15:30.0562 3232 VgaSave (0d3a8fafceacd8b7625cd549757a7df1) C:\WINDOWS\System32\drivers\vga.sys 13:15:30.0750 3232 VgaSave - ok 13:15:30.0812 3232 ViaIde (3b3efcda263b8ac14fdf9cbdd0791b2e) C:\WINDOWS\system32\DRIVERS\viaide.sys 13:15:30.0968 3232 ViaIde - ok 13:15:30.0984 3232 VolSnap (a5a712f4e880874a477af790b5186e1d) C:\WINDOWS\system32\drivers\VolSnap.sys 13:15:31.0156 3232 VolSnap - ok 13:15:31.0203 3232 Wanarp (e20b95baedb550f32dd489265c1da1f6) C:\WINDOWS\system32\DRIVERS\wanarp.sys 13:15:31.0390 3232 Wanarp - ok 13:15:31.0453 3232 Wdf01000 (d918617b46457b9ac28027722e30f647) C:\WINDOWS\system32\Drivers\wdf01000.sys 13:15:31.0500 3232 Wdf01000 - ok 13:15:31.0562 3232 WDICA - ok 13:15:31.0609 3232 wdmaud (6768acf64b18196494413695f0c3a00f) C:\WINDOWS\system32\drivers\wdmaud.sys 13:15:31.0765 3232 wdmaud - ok 13:15:31.0843 3232 WpdUsb (cf4def1bf66f06964dc0d91844239104) C:\WINDOWS\system32\DRIVERS\wpdusb.sys 13:15:31.0890 3232 WpdUsb - ok 13:15:31.0953 3232 WSTCODEC (c98b39829c2bbd34e454150633c62c78) C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS 13:15:32.0109 3232 WSTCODEC - ok 13:15:32.0187 3232 WudfPf (50eb9e21963b4f06fd010d007d54351b) C:\WINDOWS\system32\DRIVERS\WudfPf.sys 13:15:32.0250 3232 WudfPf - ok 13:15:32.0265 3232 WudfRd (6e209664bdea8a15b5e8e480d6c607c2) C:\WINDOWS\system32\DRIVERS\wudfrd.sys 13:15:32.0312 3232 WudfRd - ok 13:15:32.0359 3232 ZTEusbmdm6k (616b411bfc0e9f535a436759f19b79d8) C:\WINDOWS\system32\DRIVERS\ZTEusbmdm6k.sys 13:15:32.0421 3232 ZTEusbmdm6k - ok 13:15:32.0468 3232 ZTEusbnmea (616b411bfc0e9f535a436759f19b79d8) C:\WINDOWS\system32\DRIVERS\ZTEusbnmea.sys 13:15:32.0500 3232 ZTEusbnmea - ok 13:15:32.0562 3232 ZTEusbser6k (616b411bfc0e9f535a436759f19b79d8) C:\WINDOWS\system32\DRIVERS\ZTEusbser6k.sys 13:15:32.0593 3232 ZTEusbser6k - ok 13:15:32.0640 3232 MBR (0x1B8) (72b8ce41af0de751c946802b3ed844b4) \Device\Harddisk0\DR0 13:15:32.0921 3232 \Device\Harddisk0\DR0 - ok 13:15:32.0937 3232 Boot (0x1200) (135e7e07dd97ba33510f8cf3c9ec9a2c) \Device\Harddisk0\DR0\Partition0 13:15:32.0937 3232 \Device\Harddisk0\DR0\Partition0 - ok 13:15:32.0937 3232 Boot (0x1200) (b1f90405e84a5017dbb87d038baaf6a0) \Device\Harddisk0\DR0\Partition1 13:15:32.0937 3232 \Device\Harddisk0\DR0\Partition1 - ok 13:15:32.0937 3232 ============================================================ 13:15:32.0937 3232 Scan finished 13:15:32.0937 3232 ============================================================ 13:15:33.0046 3436 Detected object count: 8 13:15:33.0046 3436 Actual detected object count: 8 13:15:47.0906 3436 AegisP ( UnsignedFile.Multi.Generic ) - skipped by user 13:15:47.0906 3436 AegisP ( UnsignedFile.Multi.Generic ) - User select action: Skip 13:15:47.0906 3436 AF15BDA ( UnsignedFile.Multi.Generic ) - skipped by user 13:15:47.0906 3436 AF15BDA ( UnsignedFile.Multi.Generic ) - User select action: Skip 13:15:47.0906 3436 AmdK8 ( UnsignedFile.Multi.Generic ) - skipped by user 13:15:47.0906 3436 AmdK8 ( UnsignedFile.Multi.Generic ) - User select action: Skip 13:15:47.0921 3436 EU3_USB ( UnsignedFile.Multi.Generic ) - skipped by user 13:15:47.0921 3436 EU3_USB ( UnsignedFile.Multi.Generic ) - User select action: Skip 13:15:47.0921 3436 PCANDIS5 ( UnsignedFile.Multi.Generic ) - skipped by user 13:15:47.0921 3436 PCANDIS5 ( UnsignedFile.Multi.Generic ) - User select action: Skip 13:15:47.0921 3436 PRISM_A02 ( UnsignedFile.Multi.Generic ) - skipped by user 13:15:47.0921 3436 PRISM_A02 ( UnsignedFile.Multi.Generic ) - User select action: Skip 13:15:47.0921 3436 SIS163u ( UnsignedFile.Multi.Generic ) - skipped by user 13:15:47.0921 3436 SIS163u ( UnsignedFile.Multi.Generic ) - User select action: Skip 13:15:47.0921 3436 sptd ( LockedFile.Multi.Generic ) - skipped by user 13:15:47.0921 3436 sptd ( LockedFile.Multi.Generic ) - User select action: Skip |
All processes killed ========== OTL ========== Service HidServ stopped successfully! Service HidServ deleted successfully! File File not found not found. Service Changer stopped successfully! Service Changer deleted successfully! File File not found not found. Error: No service named a5s6a3a2 was found to stop! Service\Driver key a5s6a3a2 not found. File File not found not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}\ not found. Prefs.js: "Ask.com" removed from browser.search.defaultengine Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{00000000-0000-0000-0000-000000000000} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{00000000-0000-0000-0000-000000000000}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\SkypeM deleted successfully. C:\Dokumente und Einstellungen\Julska\Lokale Einstellungen\Anwendungsdaten\Skype\Skype.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ISUSPM deleted successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Macrovision\FLEXnet Connect\6\ISUSPM.exe moved successfully. D:\AUTORUN.INF moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{14302dfe-37cd-11de-b2a9-a83f90fff454}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14302dfe-37cd-11de-b2a9-a83f90fff454}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{14302dfe-37cd-11de-b2a9-a83f90fff454}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14302dfe-37cd-11de-b2a9-a83f90fff454}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{14302dfe-37cd-11de-b2a9-a83f90fff454}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{14302dfe-37cd-11de-b2a9-a83f90fff454}\ not found. File G:\QsSetup.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b620018-2cee-11de-b264-c717df009952}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2b620018-2cee-11de-b264-c717df009952}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b620018-2cee-11de-b264-c717df009952}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2b620018-2cee-11de-b264-c717df009952}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b620018-2cee-11de-b264-c717df009952}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2b620018-2cee-11de-b264-c717df009952}\ not found. File F:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b620019-2cee-11de-b264-c717df009952}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2b620019-2cee-11de-b264-c717df009952}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b620019-2cee-11de-b264-c717df009952}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2b620019-2cee-11de-b264-c717df009952}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2b620019-2cee-11de-b264-c717df009952}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2b620019-2cee-11de-b264-c717df009952}\ not found. File F:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{841bcd76-2b5c-11de-b25c-cb9ced3e4a52}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{841bcd76-2b5c-11de-b25c-cb9ced3e4a52}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{841bcd76-2b5c-11de-b25c-cb9ced3e4a52}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{841bcd76-2b5c-11de-b25c-cb9ced3e4a52}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{841bcd76-2b5c-11de-b25c-cb9ced3e4a52}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{841bcd76-2b5c-11de-b25c-cb9ced3e4a52}\ not found. File F:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{841bcd79-2b5c-11de-b25c-cb9ced3e4a52}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{841bcd79-2b5c-11de-b25c-cb9ced3e4a52}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{841bcd79-2b5c-11de-b25c-cb9ced3e4a52}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{841bcd79-2b5c-11de-b25c-cb9ced3e4a52}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{841bcd79-2b5c-11de-b25c-cb9ced3e4a52}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{841bcd79-2b5c-11de-b25c-cb9ced3e4a52}\ not found. File F:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{841bcd7b-2b5c-11de-b25c-f1de787bd615}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{841bcd7b-2b5c-11de-b25c-f1de787bd615}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{841bcd7b-2b5c-11de-b25c-f1de787bd615}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{841bcd7b-2b5c-11de-b25c-f1de787bd615}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{841bcd7b-2b5c-11de-b25c-f1de787bd615}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{841bcd7b-2b5c-11de-b25c-f1de787bd615}\ not found. File F:\starter.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad69c822-42f3-11df-b71a-001e33023d1a}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ad69c822-42f3-11df-b71a-001e33023d1a}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad69c822-42f3-11df-b71a-001e33023d1a}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ad69c822-42f3-11df-b71a-001e33023d1a}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ad69c822-42f3-11df-b71a-001e33023d1a}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ad69c822-42f3-11df-b71a-001e33023d1a}\ not found. File F:\NokiaPCIA_Autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{af4a628e-2b5f-11de-b25d-d2de798eaf52}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{af4a628e-2b5f-11de-b25d-d2de798eaf52}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{af4a628e-2b5f-11de-b25d-d2de798eaf52}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{af4a628e-2b5f-11de-b25d-d2de798eaf52}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{af4a628e-2b5f-11de-b25d-d2de798eaf52}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{af4a628e-2b5f-11de-b25d-d2de798eaf52}\ not found. File F:\AutoRun.exe not found. ========== REGISTRY ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\\"FirstRunDisabled" | dword:0x00 /E : value set successfully! ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Julska ->Temp folder emptied: 16706 bytes ->Temporary Internet Files folder emptied: 230528 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 31321075 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 33251 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 30,00 mb OTL by OldTimer - Version 3.2.35.1 log created on 03082012_130017 Files\Folders moved on Reboot... Registry entries deleted on Reboot... |
Hi, bitte das Log von MAM posten... chris |
Alle Zeitangaben in WEZ +1. Es ist jetzt 12:05 Uhr. |
Copyright ©2000-2025, Trojaner-Board