![]() |
Ein Virus auf dem Pc ? Hallo ihr Lieben, mein Pc hat unzählige cmd fenster geöffnet mit der Fehlermeldung bat=exe konnte nicht gefunden werden. Ist sicherlich ein Virus. Ich bin euch sehr dankbar, wenn ihr mir helfen könnt. Liebe Grüße |
hi, Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: ![]() (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
|
Hi, dankeschön. Ich hoffe es ist richtig so: # FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 10-09-2014 2. AdditionFRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 10-09-2014 |
Downloade Dir bitte ![]()
Downloade Dir bitte ![]()
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
und ein frisches FRST log bitte. |
Hallo, so, folgendes kam dabei raus: Malwarebytes Anti-Malware www.malwarebytes.org Protection, 13.09.2014 09:22:24, SYSTEM, SARA, Protection, Malware Protection, Starting, Protection, 13.09.2014 09:22:24, SYSTEM, SARA, Protection, Malware Protection, Started, Protection, 13.09.2014 09:22:24, SYSTEM, SARA, Protection, Malicious Website Protection, Starting, Protection, 13.09.2014 09:22:25, SYSTEM, SARA, Protection, Malicious Website Protection, Started, Update, 13.09.2014 09:22:30, SYSTEM, SARA, Manual, Rootkit Database, 2014.2.20.1, 2014.9.12.1, Update, 13.09.2014 09:22:42, SYSTEM, SARA, Manual, Malware Database, 2014.3.4.9, 2014.9.13.1, Protection, 13.09.2014 09:22:43, SYSTEM, SARA, Protection, Refresh, Starting, Protection, 13.09.2014 09:22:43, SYSTEM, SARA, Protection, Malicious Website Protection, Stopping, Protection, 13.09.2014 09:22:43, SYSTEM, SARA, Protection, Malicious Website Protection, Stopped, Protection, 13.09.2014 09:22:47, SYSTEM, SARA, Protection, Refresh, Success, Protection, 13.09.2014 09:22:47, SYSTEM, SARA, Protection, Malicious Website Protection, Starting, Protection, 13.09.2014 09:22:47, SYSTEM, SARA, Protection, Malicious Website Protection, Started, Protection, 13.09.2014 09:46:41, SYSTEM, SARA, Protection, Malware Protection, Starting, Protection, 13.09.2014 09:46:42, SYSTEM, SARA, Protection, Malware Protection, Started, Protection, 13.09.2014 09:46:42, SYSTEM, SARA, Protection, Malicious Website Protection, Starting, Protection, 13.09.2014 09:47:46, SYSTEM, SARA, Protection, Malicious Website Protection, Started, (end) AdwCleaner Logfile: Code: # AdwCleaner v3.310 - Bericht erstellt am 13/09/2014 um 10:03:24 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 6.1.4 (04.06.2014:1) OS: Windows 8.1 x64 Ran by Sara L on 13.09.2014 at 10:19:42,90 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 13.09.2014 at 10:25:11,07 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014 Besten Dank! Viele Grüße |
ESET Online Scanner
Downloade Dir bitte ![]()
und ein frisches FRST log bitte. Noch Probleme? :) |
Hi, C:\Programme\Eset\EsetOnlineScanner\log.txt (bei 64 Bit auch C:\Programme (x86)\Eset\EsetOnlineScanner\log.txt) suchen und mit Deinem Editor öffnen (bebildert). Es will einfach nicht funktionieren??? :wtf: |
was genau? |
Diese Datei existiert nicht. Ich kann somit kein Logfile posten oder ist diese Datei woanders? Auch durch die bebilderte Darstellung finde ich die Datei nicht.:confused: Viele Grüße |
Der ESET Scan wurde aber fertig durchgeführt und ESET wurde noch nicht deinstalliert? Wurde beim Scan was gefunden=? |
Es wurden Bedrohungen gefunden und es wurde nicht deinstalliert. Hi, habe den Eset Scan nochmal gemacht und es kamen keine Bedrohungen mehr. Hier der Security Check: Results of screen317's Security Check version 0.99.87 x64 (UAC is enabled) Internet Explorer 11 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Windows Defender Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Java 7 Update 67 Adobe Reader XI Google Chrome 35.0.1916.153 Google Chrome 36.0.1985.125 ````````Process Check: objlist.exe by Laurent```````` Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbam.exe Avira Antivir avgnt.exe Avira Antivir avguard.exe Malwarebytes Anti-Malware mbamscheduler.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` Neuer FRST: FRST Logfile: FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014 --- --- --- Soll ich Eset jetzt entfernen und darf ich Firewall und Antivirus wieder aktivieren ? |
Ja kannste machen. Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: GroupPolicy: Group Policy on Chrome detected <======= ATTENTION Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Fertig :) Die Reihenfolge ist hier entscheidend.
Falls Du Lob oder Kritik abgeben möchtest kannst Du das hier tun :) Hier noch ein paar Tipps zur Absicherung deines Systems. Ich kann garnicht zu oft erwähnen, wie wichtig es ist, dass dein System Up to Date ist.
Anti- Viren Software
Zusätzlicher Schutz
Sicheres Browsen
Alternative Browser Andere Browser tendieren zu etwas mehr Sicherheit als der IE, da diese keine Active X Elemente verwenden. Diese können von Spyware zur Infektion deines Systems missbraucht werden.
Performance Bereinige regelmäßig deine Temp Files. Ich empfehle hierzu TFC Halte dich fern von jedlichen Registry Cleanern. Diese Schaden deinem System mehr als sie helfen. Hier ein paar ( englishe ) Links Miekemoes Blogspot ( MVP ) Bill Castner ( MVP ) Don'ts
Hinweis: Bitte gib mir eine kurze Rückmeldung wenn alles erledigt ist und keine Fragen mehr vorhanden sind, so das ich diesen Thread aus meinen Abos löschen kann. |
Hallo! Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-09-2014 Ran by Sara L at 2014-09-19 16:02:03 Run:1 Running from C:\Users\Sara L\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** GroupPolicy: Group Policy on Chrome detected <======= ATTENTION ***************** C:\WINDOWS\system32\GroupPolicy\Machine => Moved successfully. C:\WINDOWS\system32\GroupPolicy\GPT.ini => Moved successfully. The system needed a reboot. ==== End of Fixlog ==== Das mit dem Combofix und Defogger findet mein Pc nicht. Was nun? Liebe Grüße Ich habe übrigens immer noch das Problem, mit den unzähligen Fenster mit bat exe. :( |
Das Problem kannst du gar nit haben, weil du meine Frage ob es noch Probleme gitb ignoriert hast ;) FRST öffnen ,Haken setzen bei Addition und scannen, poste bitte beide Logfiles. |
Hi, tut mir sehr Leid. Ich habe es übersehen ^^FRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-09-2014 FRST Logfile: Code: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 12-09-2014 Vielen Dank!!!! |
Drücke bitte die Windowstaste + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code: Task: {0C9AFBC1-164F-46FE-8C9D-FC862494B2AB} - System32\Tasks\opwaya => C:\Users\Sara L\AppData\Local\opwaya.bat [2014-07-03] () Speichere diese bitte als Fixlist.txt auf deinem Desktop (oder dem Verzeichnis in dem sich FRST befindet).
Nochmal frische FRST und Addition.txt bitte. |
Hallo! Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 12-09-2014 Ran by Sara L at 2014-09-21 11:51:46 Run:1 Running from C:\Users\Sara L\Downloads Boot Mode: Normal ============================================== Content of fixlist: ***************** Task: {0C9AFBC1-164F-46FE-8C9D-FC862494B2AB} - System32\Tasks\opwaya => C:\Users\Sara L\AppData\Local\opwaya.bat [2014-07-03] () Task: {0D572472-4FF4-4395-AE66-1FBAF9B4AED5} - System32\Tasks\cnaoto => C:\Users\Sara L\AppData\Local\cnaoto.bat [2014-07-03] () Task: {0FB73119-969C-4AA0-B5C3-CC23C475A767} - System32\Tasks\pjddya => C:\Users\Sara L\AppData\Local\pjddya.bat [2014-07-03] () Task: {1075DC03-3172-4868-9529-F91EF6A7B1A8} - System32\Tasks\hbbve => C:\Users\Sara L\AppData\Local\hbbve.bat [2014-07-03] () Task: {1A32DA29-E8CF-47E0-910B-6E0018EBF0D3} - System32\Tasks\nneekkk => C:\Users\Sara L\AppData\Local\nneekkk.bat [2014-07-03] () Task: {1E898093-1526-4C2E-94AB-88092B5CF8E0} - System32\Tasks\etrhxvec => C:\Users\Sara L\AppData\Local\etrhxvec.bat [2014-07-03] () Task: {26424C53-AACC-481D-9C6C-54E97B9C9ED7} - System32\Tasks\ehijase => C:\Users\Sara L\AppData\Local\ehijase.bat [2014-07-03] () Task: {2A2DF03B-7534-42CE-A15B-A80CECD25509} - System32\Tasks\rxbyc => C:\Users\Sara L\AppData\Local\rxbyc.bat [2014-07-03] () Task: {3A31CE72-DF8E-42F8-8361-6AB948B875D5} - System32\Tasks\nmllk => C:\Users\Sara L\AppData\Local\nmllk.bat [2014-07-03] () Task: {4C82BA33-8CED-46FC-B5D5-5F89981EFA09} - System32\Tasks\capnvsig => C:\Users\Sara L\AppData\Local\capnvsig.bat [2014-07-03] () Task: {4CB19AF2-CDC5-48CD-BDFC-ADE09BA1174B} - System32\Tasks\befbcf => C:\Users\Sara L\AppData\Local\befbcf.bat [2014-07-03] () Task: {4E51DAC4-D3BC-4735-9724-C249AF403556} - System32\Tasks\auadwcvj => C:\Users\Sara L\AppData\Local\auadwcvj.bat [2014-07-03] () Task: {522A60BF-9A26-4B6B-AC0E-B33D4EFE0A32} - System32\Tasks\xhyjb => C:\Users\Sara L\AppData\Local\xhyjb.bat [2014-07-03] () Task: {62E8880D-5ACF-4ABB-A7DC-FD4D76ED4145} - System32\Tasks\crguj => C:\Users\Sara L\AppData\Local\crguj.bat [2014-07-03] () Task: {6F19AF2E-6477-4606-B4B5-4AD98AE256AD} - System32\Tasks\cpdrna => C:\Users\Sara L\AppData\Local\cpdrna.bat [2014-07-03] () Task: {6F5E4BD3-3CD6-4563-BA67-5F0AC149CAF9} - System32\Tasks\mnmtslk => C:\Users\Sara L\AppData\Local\mnmtslk.bat [2014-07-03] () Task: {744E9A75-2ECA-4368-986C-1BEB378407C4} - System32\Tasks\cglyd => C:\Users\Sara L\AppData\Local\cglyd.bat [2014-07-03] () Task: {8211BDBA-1CA8-45B4-9974-97AFA33E82AB} - System32\Tasks\gaslfx => C:\Users\Sara L\AppData\Local\gaslfx.bat [2014-07-03] () Task: {838E7EF4-D326-4503-AD93-7CFE9EE970F7} - System32\Tasks\rvgkdb => C:\Users\Sara L\AppData\Local\rvgkdb.bat [2014-07-03] () Task: {8695D233-FD91-457D-94F8-DF114B563EC5} - System32\Tasks\jfavrnbg => C:\Users\Sara L\AppData\Local\jfavrnbg.bat [2014-07-03] () Task: {8BFF26FA-8447-4A7D-90C0-54E6F1B43FF7} - System32\Tasks\jgkhkhdh => C:\Users\Sara L\AppData\Local\jgkhkhdh.bat [2014-07-03] () Task: {96909E94-8FC4-45C0-AC35-59CA6A5C55A9} - System32\Tasks\etkia => C:\Users\Sara L\AppData\Local\etkia.bat [2014-07-03] () Task: {9BDB6EB2-AC9E-44FE-80CF-8A00B67C039C} - System32\Tasks\hrlmh => C:\Users\Sara L\AppData\Local\hrlmh.bat [2014-07-03] () Task: {A4AB3189-43BD-45C2-8EC8-D13E6D540F17} - System32\Tasks\kpbhd => C:\Users\Sara L\AppData\Local\kpbhd.bat [2014-07-03] () Task: {A8A8D05D-5376-4459-8772-4845B4DADA3C} - System32\Tasks\ylwitfr => C:\Users\Sara L\AppData\Local\ylwitfr.bat [2014-07-03] () Task: {AADF8341-56E0-4738-B806-A9DDB27C5272} - System32\Tasks\jeavr => C:\Users\Sara L\AppData\Local\jeavr.bat [2014-07-03] () Task: {AB45A765-ADA7-4380-89D3-9F16A8C3B8D8} - System32\Tasks\jmimhl => C:\Users\Sara L\AppData\Local\jmimhl.bat [2014-07-03] () Task: {AD03A6B9-A208-4C78-A8AE-92FB622B9197} - System32\Tasks\tcffejx => C:\Users\Sara L\AppData\Local\tcffejx.bat [2014-07-03] () Task: {B418B53C-47DE-4AD6-B534-3C8BB3C4CBF5} - System32\Tasks\sxbhmrv => C:\Users\Sara L\AppData\Local\sxbhmrv.bat [2014-07-03] () Task: {B7751633-DF71-477F-81AE-7F1962C2B60A} - System32\Tasks\dcbwolc => C:\Users\Sara L\AppData\Local\dcbwolc.bat [2014-07-03] () Task: {B937815C-9EE1-490D-89A9-C666D595A2CC} - System32\Tasks\gasst => C:\Users\Sara L\AppData\Local\gasst.bat [2014-07-03] () Task: {C15CE7E7-D9AB-4FA7-A51F-2FF2103C6441} - System32\Tasks\bncpbwk => C:\Users\Sara L\AppData\Local\bncpbwk.bat [2014-07-03] () Task: {C2D49DED-3B05-404C-B892-26B7B2ABB51C} - System32\Tasks\daihvedq => C:\Users\Sara L\AppData\Local\daihvedq.bat [2014-07-03] () Task: {D33B1AF6-3F44-4890-B4F8-A1E3741F411D} - System32\Tasks\qbuei => C:\Users\Sara L\AppData\Local\qbuei.bat [2014-07-03] () Task: {EA4082C9-CC4E-48E2-95B2-00787060402D} - System32\Tasks\cwtod => C:\Users\Sara L\AppData\Local\cwtod.bat [2014-07-03] () Task: {F5336358-898D-41C5-886C-3A8CE6579D59} - System32\Tasks\thkxcjv => C:\Users\Sara L\AppData\Local\thkxcjv.bat [2014-07-03] () Task: {FC16EA7B-476C-4912-9478-0CCA9A1FA7C0} - System32\Tasks\azsmfy => C:\Users\Sara L\AppData\Local\azsmfy.bat [2014-07-03] () Task: {FD380AC2-6EB6-4DA1-9190-F82EAF80F724} - System32\Tasks\gogqa => C:\Users\Sara L\AppData\Local\gogqa.bat [2014-07-03] () C:\Users\Sara L\AppData\Local\*.bat ***************** "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0C9AFBC1-164F-46FE-8C9D-FC862494B2AB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0C9AFBC1-164F-46FE-8C9D-FC862494B2AB}" => Key deleted successfully. C:\Windows\System32\Tasks\opwaya => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\opwaya" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0D572472-4FF4-4395-AE66-1FBAF9B4AED5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0D572472-4FF4-4395-AE66-1FBAF9B4AED5}" => Key deleted successfully. C:\Windows\System32\Tasks\cnaoto => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\cnaoto" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{0FB73119-969C-4AA0-B5C3-CC23C475A767}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{0FB73119-969C-4AA0-B5C3-CC23C475A767}" => Key deleted successfully. C:\Windows\System32\Tasks\pjddya => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\pjddya" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1075DC03-3172-4868-9529-F91EF6A7B1A8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1075DC03-3172-4868-9529-F91EF6A7B1A8}" => Key deleted successfully. C:\Windows\System32\Tasks\hbbve => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\hbbve" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1A32DA29-E8CF-47E0-910B-6E0018EBF0D3}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1A32DA29-E8CF-47E0-910B-6E0018EBF0D3}" => Key deleted successfully. C:\Windows\System32\Tasks\nneekkk => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\nneekkk" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{1E898093-1526-4C2E-94AB-88092B5CF8E0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{1E898093-1526-4C2E-94AB-88092B5CF8E0}" => Key deleted successfully. C:\Windows\System32\Tasks\etrhxvec => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\etrhxvec" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{26424C53-AACC-481D-9C6C-54E97B9C9ED7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{26424C53-AACC-481D-9C6C-54E97B9C9ED7}" => Key deleted successfully. C:\Windows\System32\Tasks\ehijase => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ehijase" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{2A2DF03B-7534-42CE-A15B-A80CECD25509}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{2A2DF03B-7534-42CE-A15B-A80CECD25509}" => Key deleted successfully. C:\Windows\System32\Tasks\rxbyc => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\rxbyc" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{3A31CE72-DF8E-42F8-8361-6AB948B875D5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{3A31CE72-DF8E-42F8-8361-6AB948B875D5}" => Key deleted successfully. C:\Windows\System32\Tasks\nmllk => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\nmllk" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4C82BA33-8CED-46FC-B5D5-5F89981EFA09}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4C82BA33-8CED-46FC-B5D5-5F89981EFA09}" => Key deleted successfully. C:\Windows\System32\Tasks\capnvsig => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\capnvsig" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4CB19AF2-CDC5-48CD-BDFC-ADE09BA1174B}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4CB19AF2-CDC5-48CD-BDFC-ADE09BA1174B}" => Key deleted successfully. C:\Windows\System32\Tasks\befbcf => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\befbcf" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{4E51DAC4-D3BC-4735-9724-C249AF403556}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{4E51DAC4-D3BC-4735-9724-C249AF403556}" => Key deleted successfully. C:\Windows\System32\Tasks\auadwcvj => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\auadwcvj" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{522A60BF-9A26-4B6B-AC0E-B33D4EFE0A32}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{522A60BF-9A26-4B6B-AC0E-B33D4EFE0A32}" => Key deleted successfully. C:\Windows\System32\Tasks\xhyjb => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\xhyjb" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{62E8880D-5ACF-4ABB-A7DC-FD4D76ED4145}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{62E8880D-5ACF-4ABB-A7DC-FD4D76ED4145}" => Key deleted successfully. C:\Windows\System32\Tasks\crguj => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\crguj" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6F19AF2E-6477-4606-B4B5-4AD98AE256AD}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F19AF2E-6477-4606-B4B5-4AD98AE256AD}" => Key deleted successfully. C:\Windows\System32\Tasks\cpdrna => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\cpdrna" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{6F5E4BD3-3CD6-4563-BA67-5F0AC149CAF9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{6F5E4BD3-3CD6-4563-BA67-5F0AC149CAF9}" => Key deleted successfully. C:\Windows\System32\Tasks\mnmtslk => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\mnmtslk" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{744E9A75-2ECA-4368-986C-1BEB378407C4}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{744E9A75-2ECA-4368-986C-1BEB378407C4}" => Key deleted successfully. C:\Windows\System32\Tasks\cglyd => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\cglyd" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8211BDBA-1CA8-45B4-9974-97AFA33E82AB}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8211BDBA-1CA8-45B4-9974-97AFA33E82AB}" => Key deleted successfully. C:\Windows\System32\Tasks\gaslfx => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\gaslfx" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{838E7EF4-D326-4503-AD93-7CFE9EE970F7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{838E7EF4-D326-4503-AD93-7CFE9EE970F7}" => Key deleted successfully. C:\Windows\System32\Tasks\rvgkdb => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\rvgkdb" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8695D233-FD91-457D-94F8-DF114B563EC5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8695D233-FD91-457D-94F8-DF114B563EC5}" => Key deleted successfully. C:\Windows\System32\Tasks\jfavrnbg => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jfavrnbg" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{8BFF26FA-8447-4A7D-90C0-54E6F1B43FF7}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{8BFF26FA-8447-4A7D-90C0-54E6F1B43FF7}" => Key deleted successfully. C:\Windows\System32\Tasks\jgkhkhdh => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jgkhkhdh" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{96909E94-8FC4-45C0-AC35-59CA6A5C55A9}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{96909E94-8FC4-45C0-AC35-59CA6A5C55A9}" => Key deleted successfully. C:\Windows\System32\Tasks\etkia => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\etkia" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{9BDB6EB2-AC9E-44FE-80CF-8A00B67C039C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{9BDB6EB2-AC9E-44FE-80CF-8A00B67C039C}" => Key deleted successfully. C:\Windows\System32\Tasks\hrlmh => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\hrlmh" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A4AB3189-43BD-45C2-8EC8-D13E6D540F17}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A4AB3189-43BD-45C2-8EC8-D13E6D540F17}" => Key deleted successfully. C:\Windows\System32\Tasks\kpbhd => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\kpbhd" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{A8A8D05D-5376-4459-8772-4845B4DADA3C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{A8A8D05D-5376-4459-8772-4845B4DADA3C}" => Key deleted successfully. C:\Windows\System32\Tasks\ylwitfr => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\ylwitfr" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AADF8341-56E0-4738-B806-A9DDB27C5272}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AADF8341-56E0-4738-B806-A9DDB27C5272}" => Key deleted successfully. C:\Windows\System32\Tasks\jeavr => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jeavr" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AB45A765-ADA7-4380-89D3-9F16A8C3B8D8}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB45A765-ADA7-4380-89D3-9F16A8C3B8D8}" => Key deleted successfully. C:\Windows\System32\Tasks\jmimhl => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\jmimhl" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{AD03A6B9-A208-4C78-A8AE-92FB622B9197}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AD03A6B9-A208-4C78-A8AE-92FB622B9197}" => Key deleted successfully. C:\Windows\System32\Tasks\tcffejx => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\tcffejx" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B418B53C-47DE-4AD6-B534-3C8BB3C4CBF5}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B418B53C-47DE-4AD6-B534-3C8BB3C4CBF5}" => Key deleted successfully. C:\Windows\System32\Tasks\sxbhmrv => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\sxbhmrv" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B7751633-DF71-477F-81AE-7F1962C2B60A}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B7751633-DF71-477F-81AE-7F1962C2B60A}" => Key deleted successfully. C:\Windows\System32\Tasks\dcbwolc => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\dcbwolc" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{B937815C-9EE1-490D-89A9-C666D595A2CC}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B937815C-9EE1-490D-89A9-C666D595A2CC}" => Key deleted successfully. C:\Windows\System32\Tasks\gasst => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\gasst" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C15CE7E7-D9AB-4FA7-A51F-2FF2103C6441}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C15CE7E7-D9AB-4FA7-A51F-2FF2103C6441}" => Key deleted successfully. C:\Windows\System32\Tasks\bncpbwk => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\bncpbwk" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{C2D49DED-3B05-404C-B892-26B7B2ABB51C}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2D49DED-3B05-404C-B892-26B7B2ABB51C}" => Key deleted successfully. C:\Windows\System32\Tasks\daihvedq => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\daihvedq" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{D33B1AF6-3F44-4890-B4F8-A1E3741F411D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{D33B1AF6-3F44-4890-B4F8-A1E3741F411D}" => Key deleted successfully. C:\Windows\System32\Tasks\qbuei => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\qbuei" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{EA4082C9-CC4E-48E2-95B2-00787060402D}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{EA4082C9-CC4E-48E2-95B2-00787060402D}" => Key deleted successfully. C:\Windows\System32\Tasks\cwtod => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\cwtod" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{F5336358-898D-41C5-886C-3A8CE6579D59}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{F5336358-898D-41C5-886C-3A8CE6579D59}" => Key deleted successfully. C:\Windows\System32\Tasks\thkxcjv => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\thkxcjv" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FC16EA7B-476C-4912-9478-0CCA9A1FA7C0}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FC16EA7B-476C-4912-9478-0CCA9A1FA7C0}" => Key deleted successfully. C:\Windows\System32\Tasks\azsmfy => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\azsmfy" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Logon\{FD380AC2-6EB6-4DA1-9190-F82EAF80F724}" => Key deleted successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{FD380AC2-6EB6-4DA1-9190-F82EAF80F724}" => Key deleted successfully. C:\Windows\System32\Tasks\gogqa => Moved successfully. "HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\gogqa" => Key deleted successfully. C:\Users\Sara L\AppData\Local\*.bat => Moved successfully. ==== End of Fixlog ==== Task: {0C9AFBC1-164F-46FE-8C9D-FC862494B2AB} - System32\Tasks\opwaya => C:\Users\Sara L\AppData\Local\opwaya.bat [2014-07-03] () Task: {0D572472-4FF4-4395-AE66-1FBAF9B4AED5} - System32\Tasks\cnaoto => C:\Users\Sara L\AppData\Local\cnaoto.bat [2014-07-03] () Task: {0FB73119-969C-4AA0-B5C3-CC23C475A767} - System32\Tasks\pjddya => C:\Users\Sara L\AppData\Local\pjddya.bat [2014-07-03] () Task: {1075DC03-3172-4868-9529-F91EF6A7B1A8} - System32\Tasks\hbbve => C:\Users\Sara L\AppData\Local\hbbve.bat [2014-07-03] () Task: {1A32DA29-E8CF-47E0-910B-6E0018EBF0D3} - System32\Tasks\nneekkk => C:\Users\Sara L\AppData\Local\nneekkk.bat [2014-07-03] () Task: {1E898093-1526-4C2E-94AB-88092B5CF8E0} - System32\Tasks\etrhxvec => C:\Users\Sara L\AppData\Local\etrhxvec.bat [2014-07-03] () Task: {26424C53-AACC-481D-9C6C-54E97B9C9ED7} - System32\Tasks\ehijase => C:\Users\Sara L\AppData\Local\ehijase.bat [2014-07-03] () Task: {2A2DF03B-7534-42CE-A15B-A80CECD25509} - System32\Tasks\rxbyc => C:\Users\Sara L\AppData\Local\rxbyc.bat [2014-07-03] () Task: {3A31CE72-DF8E-42F8-8361-6AB948B875D5} - System32\Tasks\nmllk => C:\Users\Sara L\AppData\Local\nmllk.bat [2014-07-03] () Task: {4C82BA33-8CED-46FC-B5D5-5F89981EFA09} - System32\Tasks\capnvsig => C:\Users\Sara L\AppData\Local\capnvsig.bat [2014-07-03] () Task: {4CB19AF2-CDC5-48CD-BDFC-ADE09BA1174B} - System32\Tasks\befbcf => C:\Users\Sara L\AppData\Local\befbcf.bat [2014-07-03] () Task: {4E51DAC4-D3BC-4735-9724-C249AF403556} - System32\Tasks\auadwcvj => C:\Users\Sara L\AppData\Local\auadwcvj.bat [2014-07-03] () Task: {522A60BF-9A26-4B6B-AC0E-B33D4EFE0A32} - System32\Tasks\xhyjb => C:\Users\Sara L\AppData\Local\xhyjb.bat [2014-07-03] () Task: {62E8880D-5ACF-4ABB-A7DC-FD4D76ED4145} - System32\Tasks\crguj => C:\Users\Sara L\AppData\Local\crguj.bat [2014-07-03] () Task: {6F19AF2E-6477-4606-B4B5-4AD98AE256AD} - System32\Tasks\cpdrna => C:\Users\Sara L\AppData\Local\cpdrna.bat [2014-07-03] () Task: {6F5E4BD3-3CD6-4563-BA67-5F0AC149CAF9} - System32\Tasks\mnmtslk => C:\Users\Sara L\AppData\Local\mnmtslk.bat [2014-07-03] () Task: {744E9A75-2ECA-4368-986C-1BEB378407C4} - System32\Tasks\cglyd => C:\Users\Sara L\AppData\Local\cglyd.bat [2014-07-03] () Task: {8211BDBA-1CA8-45B4-9974-97AFA33E82AB} - System32\Tasks\gaslfx => C:\Users\Sara L\AppData\Local\gaslfx.bat [2014-07-03] () Task: {838E7EF4-D326-4503-AD93-7CFE9EE970F7} - System32\Tasks\rvgkdb => C:\Users\Sara L\AppData\Local\rvgkdb.bat [2014-07-03] () Task: {8695D233-FD91-457D-94F8-DF114B563EC5} - System32\Tasks\jfavrnbg => C:\Users\Sara L\AppData\Local\jfavrnbg.bat [2014-07-03] () Task: {8BFF26FA-8447-4A7D-90C0-54E6F1B43FF7} - System32\Tasks\jgkhkhdh => C:\Users\Sara L\AppData\Local\jgkhkhdh.bat [2014-07-03] () Task: {96909E94-8FC4-45C0-AC35-59CA6A5C55A9} - System32\Tasks\etkia => C:\Users\Sara L\AppData\Local\etkia.bat [2014-07-03] () Task: {9BDB6EB2-AC9E-44FE-80CF-8A00B67C039C} - System32\Tasks\hrlmh => C:\Users\Sara L\AppData\Local\hrlmh.bat [2014-07-03] () Task: {A4AB3189-43BD-45C2-8EC8-D13E6D540F17} - System32\Tasks\kpbhd => C:\Users\Sara L\AppData\Local\kpbhd.bat [2014-07-03] () Task: {A8A8D05D-5376-4459-8772-4845B4DADA3C} - System32\Tasks\ylwitfr => C:\Users\Sara L\AppData\Local\ylwitfr.bat [2014-07-03] () Task: {AADF8341-56E0-4738-B806-A9DDB27C5272} - System32\Tasks\jeavr => C:\Users\Sara L\AppData\Local\jeavr.bat [2014-07-03] () Task: {AB45A765-ADA7-4380-89D3-9F16A8C3B8D8} - System32\Tasks\jmimhl => C:\Users\Sara L\AppData\Local\jmimhl.bat [2014-07-03] () Task: {AD03A6B9-A208-4C78-A8AE-92FB622B9197} - System32\Tasks\tcffejx => C:\Users\Sara L\AppData\Local\tcffejx.bat [2014-07-03] () Task: {B418B53C-47DE-4AD6-B534-3C8BB3C4CBF5} - System32\Tasks\sxbhmrv => C:\Users\Sara L\AppData\Local\sxbhmrv.bat [2014-07-03] () Task: {B7751633-DF71-477F-81AE-7F1962C2B60A} - System32\Tasks\dcbwolc => C:\Users\Sara L\AppData\Local\dcbwolc.bat [2014-07-03] () Task: {B937815C-9EE1-490D-89A9-C666D595A2CC} - System32\Tasks\gasst => C:\Users\Sara L\AppData\Local\gasst.bat [2014-07-03] () Task: {C15CE7E7-D9AB-4FA7-A51F-2FF2103C6441} - System32\Tasks\bncpbwk => C:\Users\Sara L\AppData\Local\bncpbwk.bat [2014-07-03] () Task: {C2D49DED-3B05-404C-B892-26B7B2ABB51C} - System32\Tasks\daihvedq => C:\Users\Sara L\AppData\Local\daihvedq.bat [2014-07-03] () Task: {D33B1AF6-3F44-4890-B4F8-A1E3741F411D} - System32\Tasks\qbuei => C:\Users\Sara L\AppData\Local\qbuei.bat [2014-07-03] () Task: {EA4082C9-CC4E-48E2-95B2-00787060402D} - System32\Tasks\cwtod => C:\Users\Sara L\AppData\Local\cwtod.bat [2014-07-03] () Task: {F5336358-898D-41C5-886C-3A8CE6579D59} - System32\Tasks\thkxcjv => C:\Users\Sara L\AppData\Local\thkxcjv.bat [2014-07-03] () Task: {FC16EA7B-476C-4912-9478-0CCA9A1FA7C0} - System32\Tasks\azsmfy => C:\Users\Sara L\AppData\Local\azsmfy.bat [2014-07-03] () Task: {FD380AC2-6EB6-4DA1-9190-F82EAF80F724} - System32\Tasks\gogqa => C:\Users\Sara L\AppData\Local\gogqa.bat [2014-07-03] () C:\Users\Sara L\AppData\Local\*.batFRST Additions Logfile: Code: Additional scan result of Farbar Recovery Scan Tool (x64) Version: 12-09-2014 |
Noch Probleme? |
Hi, dankeschön !!!!!!!!!!! Es ist endlich weg :) :Boogie: Ganz liebe Grüße |
Gern Geschehen :) |
Alle Zeitangaben in WEZ +1. Es ist jetzt 21:58 Uhr. |
Copyright ©2000-2025, Trojaner-Board