![]() |
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: Task: {0C9AFBC1-164F-46FE-8C9D-FC862494B2AB} - System32\Tasks\opwaya => C:\Users\Sara L\AppData\Local\opwaya.bat [2014-07-03] () Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Nochmal frische FRST und Addition.txt bitte. |
Hallo! Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-09-2014 Ran by Sara L at 2014-09-21 11:51:46 Run:1 Running from C:\Users\Sara L\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {0C9AFBC1-164F-46FE-8C9D-FC862494B2AB} - System32\Tasks\opwaya => C:\Users\Sara L\AppData\Local\opwaya.bat [2014-07-03] () Task: {0D572472-4FF4-4395-AE66-1FBAF9B4AED5} - System32\Tasks\cnaoto => C:\Users\Sara L\AppData\Local\cnaoto.bat [2014-07-03] () Task: {0FB73119-969C-4AA0-B5C3-CC23C475A767} - System32\Tasks\pjddya => C:\Users\Sara L\AppData\Local\pjddya.bat [2014-07-03] () Task: {1075DC03-3172-4868-9529-F91EF6A7B1A8} - System32\Tasks\hbbve => C:\Users\Sara L\AppData\Local\hbbve.bat [2014-07-03] () Task: {1A32DA29-E8CF-47E0-910B-6E0018EBF0D3} - System32\Tasks\nneekkk => C:\Users\Sara L\AppData\Local\nneekkk.bat [2014-07-03] () Task: {1E898093-1526-4C2E-94AB-88092B5CF8E0} - System32\Tasks\etrhxvec => C:\Users\Sara L\AppData\Local\etrhxvec.bat [2014-07-03] () Task: {26424C53-AACC-481D-9C6C-54E97B9C9ED7} - System32\Tasks\ehijase => C:\Users\Sara L\AppData\Local\ehijase.bat [2014-07-03] () Task: {2A2DF03B-7534-42CE-A15B-A80CECD25509} - System32\Tasks\rxbyc => C:\Users\Sara L\AppData\Local\rxbyc.bat [2014-07-03] () Task: {3A31CE72-DF8E-42F8-8361-6AB948B875D5} - System32\Tasks\nmllk => C:\Users\Sara L\AppData\Local\nmllk.bat [2014-07-03] () Task: {4C82BA33-8CED-46FC-B5D5-5F89981EFA09} - System32\Tasks\capnvsig => C:\Users\Sara L\AppData\Local\capnvsig.bat [2014-07-03] () Task: {4CB19AF2-CDC5-48CD-BDFC-ADE09BA1174B} - System32\Tasks\befbcf => C:\Users\Sara L\AppData\Local\befbcf.bat [2014-07-03] () Task: {4E51DAC4-D3BC-4735-9724-C249AF403556} - System32\Tasks\auadwcvj => C:\Users\Sara L\AppData\Local\auadwcvj.bat [2014-07-03] () Task: {522A60BF-9A26-4B6B-AC0E-B33D4EFE0A32} - System32\Tasks\xhyjb => C:\Users\Sara L\AppData\Local\xhyjb.bat [2014-07-03] () Task: {62E8880D-5ACF-4ABB-A7DC-FD4D76ED4145} - System32\Tasks\crguj => C:\Users\Sara L\AppData\Local\crguj.bat [2014-07-03] () Task: {6F19AF2E-6477-4606-B4B5-4AD98AE256AD} - System32\Tasks\cpdrna => C:\Users\Sara L\AppData\Local\cpdrna.bat [2014-07-03] () Task: {6F5E4BD3-3CD6-4563-BA67-5F0AC149CAF9} - System32\Tasks\mnmtslk => C:\Users\Sara L\AppData\Local\mnmtslk.bat [2014-07-03] () Task: {744E9A75-2ECA-4368-986C-1BEB378407C4} - System32\Tasks\cglyd => C:\Users\Sara L\AppData\Local\cglyd.bat [2014-07-03] () Task: {8211BDBA-1CA8-45B4-9974-97AFA33E82AB} - System32\Tasks\gaslfx => C:\Users\Sara L\AppData\Local\gaslfx.bat [2014-07-03] () Task: {838E7EF4-D326-4503-AD93-7CFE9EE970F7} - System32\Tasks\rvgkdb => C:\Users\Sara L\AppData\Local\rvgkdb.bat [2014-07-03] () Task: {8695D233-FD91-457D-94F8-DF114B563EC5} - System32\Tasks\jfavrnbg => C:\Users\Sara L\AppData\Local\jfavrnbg.bat [2014-07-03] () Task: {8BFF26FA-8447-4A7D-90C0-54E6F1B43FF7} - System32\Tasks\jgkhkhdh => C:\Users\Sara L\AppData\Local\jgkhkhdh.bat [2014-07-03] () Task: {96909E94-8FC4-45C0-AC35-59CA6A5C55A9} - System32\Tasks\etkia => C:\Users\Sara L\AppData\Local\etkia.bat [2014-07-03] () Task: {9BDB6EB2-AC9E-44FE-80CF-8A00B67C039C} - System32\Tasks\hrlmh => C:\Users\Sara L\AppData\Local\hrlmh.bat [2014-07-03] () Task: {A4AB3189-43BD-45C2-8EC8-D13E6D540F17} - System32\Tasks\kpbhd => C:\Users\Sara L\AppData\Local\kpbhd.bat [2014-07-03] () Task: {A8A8D05D-5376-4459-8772-4845B4DADA3C} - System32\Tasks\ylwitfr => C:\Users\Sara L\AppData\Local\ylwitfr.bat [2014-07-03] () Task: {AADF8341-56E0-4738-B806-A9DDB27C5272} - System32\Tasks\jeavr => C:\Users\Sara L\AppData\Local\jeavr.bat [2014-07-03] () Task: {AB45A765-ADA7-4380-89D3-9F16A8C3B8D8} - System32\Tasks\jmimhl => C:\Users\Sara L\AppData\Local\jmimhl.bat [2014-07-03] () Task: {AD03A6B9-A208-4C78-A8AE-92FB622B9197} - System32\Tasks\tcffejx => C:\Users\Sara L\AppData\Local\tcffejx.bat [2014-07-03] () Task: {B418B53C-47DE-4AD6-B534-3C8BB3C4CBF5} - System32\Tasks\sxbhmrv => C:\Users\Sara L\AppData\Local\sxbhmrv.bat [2014-07-03] () Task: {B7751633-DF71-477F-81AE-7F1962C2B60A} - System32\Tasks\dcbwolc => C:\Users\Sara L\AppData\Local\dcbwolc.bat [2014-07-03] () Task: {B937815C-9EE1-490D-89A9-C666D595A2CC} - System32\Tasks\gasst => C:\Users\Sara L\AppData\Local\gasst.bat [2014-07-03] () Task: {C15CE7E7-D9AB-4FA7-A51F-2FF2103C6441} - System32\Tasks\bncpbwk => C:\Users\Sara L\AppData\Local\bncpbwk.bat [2014-07-03] () Task: {C2D49DED-3B05-404C-B892-26B7B2ABB51C} - System32\Tasks\daihvedq => C:\Users\Sara L\AppData\Local\daihvedq.bat [2014-07-03] () Task: {D33B1AF6-3F44-4890-B4F8-A1E3741F411D} - System32\Tasks\qbuei => C:\Users\Sara L\AppData\Local\qbuei.bat [2014-07-03] () Task: {EA4082C9-CC4E-48E2-95B2-00787060402D} - System32\Tasks\cwtod => C:\Users\Sara L\AppData\Local\cwtod.bat [2014-07-03] () Task: {F5336358-898D-41C5-886C-3A8CE6579D59} - System32\Tasks\thkxcjv => C:\Users\Sara L\AppData\Local\thkxcjv.bat [2014-07-03] () Task: {FC16EA7B-476C-4912-9478-0CCA9A1FA7C0} - System32\Tasks\azsmfy => C:\Users\Sara L\AppData\Local\azsmfy.bat [2014-07-03] () Task: {FD380AC2-6EB6-4DA1-9190-F82EAF80F724} - System32\Tasks\gogqa => C:\Users\Sara L\AppData\Local\gogqa.bat [2014-07-03] () C:\Users\Sara L\AppData\Local\*.bat ***************** "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0C9AFBC1-164F-46FE-8C9D-FC862494B2AB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0C9AFBC1-164F-46FE-8C9D-FC862494B2AB}" => Key deleted successfully. C:\Windows\System32\Tasks\opwaya => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\opwaya" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0D572472-4FF4-4395-AE66-1FBAF9B4AED5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D572472-4FF4-4395-AE66-1FBAF9B4AED5}" => Key deleted successfully. C:\Windows\System32\Tasks\cnaoto => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\cnaoto" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0FB73119-969C-4AA0-B5C3-CC23C475A767}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0FB73119-969C-4AA0-B5C3-CC23C475A767}" => Key deleted successfully. C:\Windows\System32\Tasks\pjddya => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pjddya" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1075DC03-3172-4868-9529-F91EF6A7B1A8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1075DC03-3172-4868-9529-F91EF6A7B1A8}" => Key deleted successfully. C:\Windows\System32\Tasks\hbbve => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\hbbve" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1A32DA29-E8CF-47E0-910B-6E0018EBF0D3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A32DA29-E8CF-47E0-910B-6E0018EBF0D3}" => Key deleted successfully. C:\Windows\System32\Tasks\nneekkk => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\nneekkk" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1E898093-1526-4C2E-94AB-88092B5CF8E0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1E898093-1526-4C2E-94AB-88092B5CF8E0}" => Key deleted successfully. C:\Windows\System32\Tasks\etrhxvec => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\etrhxvec" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{26424C53-AACC-481D-9C6C-54E97B9C9ED7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26424C53-AACC-481D-9C6C-54E97B9C9ED7}" => Key deleted successfully. C:\Windows\System32\Tasks\ehijase => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ehijase" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2A2DF03B-7534-42CE-A15B-A80CECD25509}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A2DF03B-7534-42CE-A15B-A80CECD25509}" => Key deleted successfully. C:\Windows\System32\Tasks\rxbyc => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\rxbyc" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3A31CE72-DF8E-42F8-8361-6AB948B875D5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3A31CE72-DF8E-42F8-8361-6AB948B875D5}" => Key deleted successfully. C:\Windows\System32\Tasks\nmllk => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\nmllk" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4C82BA33-8CED-46FC-B5D5-5F89981EFA09}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4C82BA33-8CED-46FC-B5D5-5F89981EFA09}" => Key deleted successfully. C:\Windows\System32\Tasks\capnvsig => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\capnvsig" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4CB19AF2-CDC5-48CD-BDFC-ADE09BA1174B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CB19AF2-CDC5-48CD-BDFC-ADE09BA1174B}" => Key deleted successfully. C:\Windows\System32\Tasks\befbcf => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\befbcf" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4E51DAC4-D3BC-4735-9724-C249AF403556}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E51DAC4-D3BC-4735-9724-C249AF403556}" => Key deleted successfully. C:\Windows\System32\Tasks\auadwcvj => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\auadwcvj" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{522A60BF-9A26-4B6B-AC0E-B33D4EFE0A32}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{522A60BF-9A26-4B6B-AC0E-B33D4EFE0A32}" => Key deleted successfully. C:\Windows\System32\Tasks\xhyjb => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\xhyjb" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{62E8880D-5ACF-4ABB-A7DC-FD4D76ED4145}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{62E8880D-5ACF-4ABB-A7DC-FD4D76ED4145}" => Key deleted successfully. C:\Windows\System32\Tasks\crguj => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\crguj" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6F19AF2E-6477-4606-B4B5-4AD98AE256AD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F19AF2E-6477-4606-B4B5-4AD98AE256AD}" => Key deleted successfully. C:\Windows\System32\Tasks\cpdrna => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\cpdrna" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6F5E4BD3-3CD6-4563-BA67-5F0AC149CAF9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F5E4BD3-3CD6-4563-BA67-5F0AC149CAF9}" => Key deleted successfully. C:\Windows\System32\Tasks\mnmtslk => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\mnmtslk" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{744E9A75-2ECA-4368-986C-1BEB378407C4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{744E9A75-2ECA-4368-986C-1BEB378407C4}" => Key deleted successfully. C:\Windows\System32\Tasks\cglyd => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\cglyd" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8211BDBA-1CA8-45B4-9974-97AFA33E82AB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8211BDBA-1CA8-45B4-9974-97AFA33E82AB}" => Key deleted successfully. C:\Windows\System32\Tasks\gaslfx => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\gaslfx" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{838E7EF4-D326-4503-AD93-7CFE9EE970F7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{838E7EF4-D326-4503-AD93-7CFE9EE970F7}" => Key deleted successfully. C:\Windows\System32\Tasks\rvgkdb => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\rvgkdb" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8695D233-FD91-457D-94F8-DF114B563EC5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8695D233-FD91-457D-94F8-DF114B563EC5}" => Key deleted successfully. C:\Windows\System32\Tasks\jfavrnbg => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jfavrnbg" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8BFF26FA-8447-4A7D-90C0-54E6F1B43FF7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8BFF26FA-8447-4A7D-90C0-54E6F1B43FF7}" => Key deleted successfully. C:\Windows\System32\Tasks\jgkhkhdh => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jgkhkhdh" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{96909E94-8FC4-45C0-AC35-59CA6A5C55A9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{96909E94-8FC4-45C0-AC35-59CA6A5C55A9}" => Key deleted successfully. C:\Windows\System32\Tasks\etkia => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\etkia" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9BDB6EB2-AC9E-44FE-80CF-8A00B67C039C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BDB6EB2-AC9E-44FE-80CF-8A00B67C039C}" => Key deleted successfully. C:\Windows\System32\Tasks\hrlmh => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\hrlmh" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A4AB3189-43BD-45C2-8EC8-D13E6D540F17}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4AB3189-43BD-45C2-8EC8-D13E6D540F17}" => Key deleted successfully. C:\Windows\System32\Tasks\kpbhd => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\kpbhd" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A8A8D05D-5376-4459-8772-4845B4DADA3C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A8A8D05D-5376-4459-8772-4845B4DADA3C}" => Key deleted successfully. C:\Windows\System32\Tasks\ylwitfr => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ylwitfr" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AADF8341-56E0-4738-B806-A9DDB27C5272}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AADF8341-56E0-4738-B806-A9DDB27C5272}" => Key deleted successfully. C:\Windows\System32\Tasks\jeavr => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jeavr" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AB45A765-ADA7-4380-89D3-9F16A8C3B8D8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB45A765-ADA7-4380-89D3-9F16A8C3B8D8}" => Key deleted successfully. C:\Windows\System32\Tasks\jmimhl => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jmimhl" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AD03A6B9-A208-4C78-A8AE-92FB622B9197}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AD03A6B9-A208-4C78-A8AE-92FB622B9197}" => Key deleted successfully. C:\Windows\System32\Tasks\tcffejx => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\tcffejx" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B418B53C-47DE-4AD6-B534-3C8BB3C4CBF5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B418B53C-47DE-4AD6-B534-3C8BB3C4CBF5}" => Key deleted successfully. C:\Windows\System32\Tasks\sxbhmrv => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\sxbhmrv" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B7751633-DF71-477F-81AE-7F1962C2B60A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7751633-DF71-477F-81AE-7F1962C2B60A}" => Key deleted successfully. C:\Windows\System32\Tasks\dcbwolc => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\dcbwolc" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B937815C-9EE1-490D-89A9-C666D595A2CC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B937815C-9EE1-490D-89A9-C666D595A2CC}" => Key deleted successfully. C:\Windows\System32\Tasks\gasst => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\gasst" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C15CE7E7-D9AB-4FA7-A51F-2FF2103C6441}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C15CE7E7-D9AB-4FA7-A51F-2FF2103C6441}" => Key deleted successfully. C:\Windows\System32\Tasks\bncpbwk => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bncpbwk" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C2D49DED-3B05-404C-B892-26B7B2ABB51C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2D49DED-3B05-404C-B892-26B7B2ABB51C}" => Key deleted successfully. C:\Windows\System32\Tasks\daihvedq => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\daihvedq" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D33B1AF6-3F44-4890-B4F8-A1E3741F411D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D33B1AF6-3F44-4890-B4F8-A1E3741F411D}" => Key deleted successfully. C:\Windows\System32\Tasks\qbuei => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\qbuei" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EA4082C9-CC4E-48E2-95B2-00787060402D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA4082C9-CC4E-48E2-95B2-00787060402D}" => Key deleted successfully. C:\Windows\System32\Tasks\cwtod => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\cwtod" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F5336358-898D-41C5-886C-3A8CE6579D59}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F5336358-898D-41C5-886C-3A8CE6579D59}" => Key deleted successfully. C:\Windows\System32\Tasks\thkxcjv => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\thkxcjv" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FC16EA7B-476C-4912-9478-0CCA9A1FA7C0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC16EA7B-476C-4912-9478-0CCA9A1FA7C0}" => Key deleted successfully. C:\Windows\System32\Tasks\azsmfy => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\azsmfy" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FD380AC2-6EB6-4DA1-9190-F82EAF80F724}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FD380AC2-6EB6-4DA1-9190-F82EAF80F724}" => Key deleted successfully. C:\Windows\System32\Tasks\gogqa => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\gogqa" => Key deleted successfully. C:\Users\Sara L\AppData\Local\*.bat => Moved successfully. ==== End of Fixlog ==== Task: {0C9AFBC1-164F-46FE-8C9D-FC862494B2AB} - System32\Tasks\opwaya => C:\Users\Sara L\AppData\Local\opwaya.bat [2014-07-03] () Task: {0D572472-4FF4-4395-AE66-1FBAF9B4AED5} - System32\Tasks\cnaoto => C:\Users\Sara L\AppData\Local\cnaoto.bat [2014-07-03] () Task: {0FB73119-969C-4AA0-B5C3-CC23C475A767} - System32\Tasks\pjddya => C:\Users\Sara L\AppData\Local\pjddya.bat [2014-07-03] () Task: {1075DC03-3172-4868-9529-F91EF6A7B1A8} - System32\Tasks\hbbve => C:\Users\Sara L\AppData\Local\hbbve.bat [2014-07-03] () Task: {1A32DA29-E8CF-47E0-910B-6E0018EBF0D3} - System32\Tasks\nneekkk => C:\Users\Sara L\AppData\Local\nneekkk.bat [2014-07-03] () Task: {1E898093-1526-4C2E-94AB-88092B5CF8E0} - System32\Tasks\etrhxvec => C:\Users\Sara L\AppData\Local\etrhxvec.bat [2014-07-03] () Task: {26424C53-AACC-481D-9C6C-54E97B9C9ED7} - System32\Tasks\ehijase => C:\Users\Sara L\AppData\Local\ehijase.bat [2014-07-03] () Task: {2A2DF03B-7534-42CE-A15B-A80CECD25509} - System32\Tasks\rxbyc => C:\Users\Sara L\AppData\Local\rxbyc.bat [2014-07-03] () Task: {3A31CE72-DF8E-42F8-8361-6AB948B875D5} - System32\Tasks\nmllk => C:\Users\Sara L\AppData\Local\nmllk.bat [2014-07-03] () Task: {4C82BA33-8CED-46FC-B5D5-5F89981EFA09} - System32\Tasks\capnvsig => C:\Users\Sara L\AppData\Local\capnvsig.bat [2014-07-03] () Task: {4CB19AF2-CDC5-48CD-BDFC-ADE09BA1174B} - System32\Tasks\befbcf => C:\Users\Sara L\AppData\Local\befbcf.bat [2014-07-03] () Task: {4E51DAC4-D3BC-4735-9724-C249AF403556} - System32\Tasks\auadwcvj => C:\Users\Sara L\AppData\Local\auadwcvj.bat [2014-07-03] () Task: {522A60BF-9A26-4B6B-AC0E-B33D4EFE0A32} - System32\Tasks\xhyjb => C:\Users\Sara L\AppData\Local\xhyjb.bat [2014-07-03] () Task: {62E8880D-5ACF-4ABB-A7DC-FD4D76ED4145} - System32\Tasks\crguj => C:\Users\Sara L\AppData\Local\crguj.bat [2014-07-03] () Task: {6F19AF2E-6477-4606-B4B5-4AD98AE256AD} - System32\Tasks\cpdrna => C:\Users\Sara L\AppData\Local\cpdrna.bat [2014-07-03] () Task: {6F5E4BD3-3CD6-4563-BA67-5F0AC149CAF9} - System32\Tasks\mnmtslk => C:\Users\Sara L\AppData\Local\mnmtslk.bat [2014-07-03] () Task: {744E9A75-2ECA-4368-986C-1BEB378407C4} - System32\Tasks\cglyd => C:\Users\Sara L\AppData\Local\cglyd.bat [2014-07-03] () Task: {8211BDBA-1CA8-45B4-9974-97AFA33E82AB} - System32\Tasks\gaslfx => C:\Users\Sara L\AppData\Local\gaslfx.bat [2014-07-03] () Task: {838E7EF4-D326-4503-AD93-7CFE9EE970F7} - System32\Tasks\rvgkdb => C:\Users\Sara L\AppData\Local\rvgkdb.bat [2014-07-03] () Task: {8695D233-FD91-457D-94F8-DF114B563EC5} - System32\Tasks\jfavrnbg => C:\Users\Sara L\AppData\Local\jfavrnbg.bat [2014-07-03] () Task: {8BFF26FA-8447-4A7D-90C0-54E6F1B43FF7} - System32\Tasks\jgkhkhdh => C:\Users\Sara L\AppData\Local\jgkhkhdh.bat [2014-07-03] () Task: {96909E94-8FC4-45C0-AC35-59CA6A5C55A9} - System32\Tasks\etkia => C:\Users\Sara L\AppData\Local\etkia.bat [2014-07-03] () Task: {9BDB6EB2-AC9E-44FE-80CF-8A00B67C039C} - System32\Tasks\hrlmh => C:\Users\Sara L\AppData\Local\hrlmh.bat [2014-07-03] () Task: {A4AB3189-43BD-45C2-8EC8-D13E6D540F17} - System32\Tasks\kpbhd => C:\Users\Sara L\AppData\Local\kpbhd.bat [2014-07-03] () Task: {A8A8D05D-5376-4459-8772-4845B4DADA3C} - System32\Tasks\ylwitfr => C:\Users\Sara L\AppData\Local\ylwitfr.bat [2014-07-03] () Task: {AADF8341-56E0-4738-B806-A9DDB27C5272} - System32\Tasks\jeavr => C:\Users\Sara L\AppData\Local\jeavr.bat [2014-07-03] () Task: {AB45A765-ADA7-4380-89D3-9F16A8C3B8D8} - System32\Tasks\jmimhl => C:\Users\Sara L\AppData\Local\jmimhl.bat [2014-07-03] () Task: {AD03A6B9-A208-4C78-A8AE-92FB622B9197} - System32\Tasks\tcffejx => C:\Users\Sara L\AppData\Local\tcffejx.bat [2014-07-03] () Task: {B418B53C-47DE-4AD6-B534-3C8BB3C4CBF5} - System32\Tasks\sxbhmrv => C:\Users\Sara L\AppData\Local\sxbhmrv.bat [2014-07-03] () Task: {B7751633-DF71-477F-81AE-7F1962C2B60A} - System32\Tasks\dcbwolc => C:\Users\Sara L\AppData\Local\dcbwolc.bat [2014-07-03] () Task: {B937815C-9EE1-490D-89A9-C666D595A2CC} - System32\Tasks\gasst => C:\Users\Sara L\AppData\Local\gasst.bat [2014-07-03] () Task: {C15CE7E7-D9AB-4FA7-A51F-2FF2103C6441} - System32\Tasks\bncpbwk => C:\Users\Sara L\AppData\Local\bncpbwk.bat [2014-07-03] () Task: {C2D49DED-3B05-404C-B892-26B7B2ABB51C} - System32\Tasks\daihvedq => C:\Users\Sara L\AppData\Local\daihvedq.bat [2014-07-03] () Task: {D33B1AF6-3F44-4890-B4F8-A1E3741F411D} - System32\Tasks\qbuei => C:\Users\Sara L\AppData\Local\qbuei.bat [2014-07-03] () Task: {EA4082C9-CC4E-48E2-95B2-00787060402D} - System32\Tasks\cwtod => C:\Users\Sara L\AppData\Local\cwtod.bat [2014-07-03] () Task: {F5336358-898D-41C5-886C-3A8CE6579D59} - System32\Tasks\thkxcjv => C:\Users\Sara L\AppData\Local\thkxcjv.bat [2014-07-03] () Task: {FC16EA7B-476C-4912-9478-0CCA9A1FA7C0} - System32\Tasks\azsmfy => C:\Users\Sara L\AppData\Local\azsmfy.bat [2014-07-03] () Task: {FD380AC2-6EB6-4DA1-9190-F82EAF80F724} - System32\Tasks\gogqa => C:\Users\Sara L\AppData\Local\gogqa.bat [2014-07-03] () C:\Users\Sara L\AppData\Local\*.batFRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-09-2014 |
Noch Probleme? |
Hi, dankeschön !!!!!!!!!!! Es ist endlich weg :) :Boogie: Ganz liebe Grüße |
Gern Geschehen :) |
Alle Zeitangaben in WEZ +1. Es ist jetzt 21:58 Uhr. |
Copyright ©2000-2025, Trojaner-Board