|
Plagegeister aller Art und deren Bekämpfung: BKA-Trojaner Version 2.07 mit PaySafeCard + UKashWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
02.09.2012, 10:48 | #1 |
| BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Hallo! Nachdem es auch unseren Laptop erwischt hat, haben wir schon folgendes durchgeführt: 1) Anmeldung mit anderen Benutzer 2) Virusscan: kein Treffer 3) Malwarebytes: 2 Treffer gesäubert und in Quarantäne verbracht 4) 2. Scan Malwarebytes: 1 Treffer in der Registry (Verweis auf den unter 3) gesäuberten Treffer - auch gesäubert 5) Suche nach Dateien mit "lock" am Beginn: nichts gefunden 6) Defrogger - siehe Datei 7) OTL-Scan - siehe angefügte Dateien Wie geht's weiter? Vielen Dank schon mal im Voraus für die Unterstützung Werner |
02.09.2012, 14:37 | #2 | |
/// Helfer-Team | BKA-Trojaner Version 2.07 mit PaySafeCard + UKashZitat:
Wo sind die Logs, warum sind die nicht dabei?
__________________ |
02.09.2012, 21:06 | #3 |
| BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Hallo,
__________________sorry, dass ich diese Logs nicht angefügt habe. Anbei diese als Nachlieferung: Zu 3) mbam-log-2012-09-01 (21-31-51)xxx.txt Der Programmabbruch war nicht beabsichtigt. Daher der nochmalige Durchlauf. Zu 4) mbam-log-2012-09-01 (23-07-53)xxx.txt Ich hoffe, damit konnte ich weiter helfen... Werner |
03.09.2012, 19:30 | #4 |
/// Helfer-Team | BKA-Trojaner Version 2.07 mit PaySafeCard + UKashFixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Ersetze die *** Sternchen wieder in den Benutzernamen zurück! Code:
ATTFilter :OTL SRV - [2012.08.21 15:33:16 | 001,019,328 | ---- | M] (Enigma Software Group USA, LLC.) [Auto | Running] -- C:\Programme\Enigma Software Group\SpyHunter\SH4Service.exe -- (SpyHunter 4 Service) IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1017960685-4153148592-2611499656-1176\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKU\S-1-5-21-1017960685-4153148592-2611499656-1176\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-1017960685-4153148592-2611499656-1176\..\SearchScopes\{B98786F0-7062-488A-892A-0BBBB4FC655F}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=kw&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=6069CF9B-3533-4757-AE8C-0A40A05F1596&apn_sauid=0DF6A4FA-31B3-449A-8DF9-8828B7E0A4D0 IE - HKU\S-1-5-21-1017960685-4153148592-2611499656-1176\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - prefs.js..browser.search.defaultengine: "Google" FF - prefs.js..browser.search.defaultenginename: "Google" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "about:home" FF - prefs.js..network.proxy.type: 0 FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_4_402_265.dll File not found O4 - HKU\S-1-5-21-1017960685-4153148592-2611499656-1176..\Run: [] File not found O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\S-1-5-21-1017960685-4153148592-2611499656-1176\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255 O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.5.1) O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner) O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 1.6.0_31) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_31-windows-i586.cab (Java Plug-in 10.5.1) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2002.10.17 04:56:50 | 000,000,036 | RH-- | M] () - F:\autorun.inf -- [ NTFS ] O33 - MountPoints2\{2f3c37f9-be8c-11e1-a83d-d4bed91bb2eb}\Shell - "" = AutoRun O33 - MountPoints2\{2f3c37f9-be8c-11e1-a83d-d4bed91bb2eb}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\{2f3c3803-be8c-11e1-a83d-d4bed91bb2eb}\Shell - "" = AutoRun O33 - MountPoints2\{2f3c3803-be8c-11e1-a83d-d4bed91bb2eb}\Shell\AutoRun\command - "" = G:\AutoRun.exe O33 - MountPoints2\G\Shell - "" = AutoRun O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\AutoRun.exe :Files C:\Users\xxxx\AppData\Local\{*} C:\ProgramData\*.exe C:\ProgramData\TEMP C:\Users\xxxx\AppData\Local\Temp\*.exe C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache %APPDATA%\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk %SystemRoot%\System32\*.tmp %SystemRoot%\SysWOW64\*.tmp ipconfig /flushdns /c :Commands [purity] [emptytemp]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
04.09.2012, 01:27 | #5 |
| BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Hallo!! So nach der ganzen Arbeit nun noch den Scan mit Fix ausgeführt. Übrigens: Der Virenscanner lies sich leider nicht deaktivieren. Zumindest das Symbol verblieb noch die ganze Zeit bis zum Reboot... Anbei das Protokoll des Scans. Bis hierher schon mal BESTEN DANK und wie geht's nun weiter? Werner Code:
ATTFilter All processes killed ========== OTL ========== Service SpyHunter 4 Service stopped successfully! Service SpyHunter 4 Service deleted successfully! C:\Programme\Enigma Software Group\SpyHunter\SH4Service.exe moved successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKEY_USERS\S-1-5-21-1017960685-4153148592-2611499656-1176\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-1017960685-4153148592-2611499656-1176\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_USERS\S-1-5-21-1017960685-4153148592-2611499656-1176\Software\Microsoft\Internet Explorer\SearchScopes\{B98786F0-7062-488A-892A-0BBBB4FC655F}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B98786F0-7062-488A-892A-0BBBB4FC655F}\ not found. HKU\S-1-5-21-1017960685-4153148592-2611499656-1176\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Prefs.js: "Google" removed from browser.search.defaultengine Prefs.js: "Google" removed from browser.search.defaultenginename Prefs.js: "Ask.com" removed from browser.search.order.1 Prefs.js: "Google" removed from browser.search.selectedEngine Prefs.js: "about:home" removed from browser.startup.homepage Prefs.js: 0 removed from network.proxy.type 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. Registry value HKEY_USERS\S-1-5-21-1017960685-4153148592-2611499656-1176\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. Registry value HKEY_USERS\S-1-5-21-1017960685-4153148592-2611499656-1176\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} C:\Windows\Downloaded Program Files\DellSystemLite.INF moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_USERS\.DEFAULT\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! F:\autorun.inf moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2f3c37f9-be8c-11e1-a83d-d4bed91bb2eb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2f3c37f9-be8c-11e1-a83d-d4bed91bb2eb}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2f3c37f9-be8c-11e1-a83d-d4bed91bb2eb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2f3c37f9-be8c-11e1-a83d-d4bed91bb2eb}\ not found. File G:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2f3c3803-be8c-11e1-a83d-d4bed91bb2eb}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2f3c3803-be8c-11e1-a83d-d4bed91bb2eb}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2f3c3803-be8c-11e1-a83d-d4bed91bb2eb}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2f3c3803-be8c-11e1-a83d-d4bed91bb2eb}\ not found. File G:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found. File G:\AutoRun.exe not found. ========== FILES ========== C:\Users\xxxx\AppData\Local\{0007759E-1AD1-4385-8D1C-0FF7AE23C7FE} folder moved successfully. C:\Users\xxxx\AppData\Local\{00306204-36CB-48A1-8C0A-CC806FF3048E} folder moved successfully. C:\Users\xxxx\AppData\Local\{0336F359-0FDB-4CF6-A1CD-BEE20D69E5F7} folder moved successfully. C:\Users\xxxx\AppData\Local\{07157028-BAA3-4DC3-8BE3-EC95E8AD2EEF} folder moved successfully. C:\Users\xxxx\AppData\Local\{0771A6B5-13A1-4FFE-94DA-35B137A8B53E} folder moved successfully. C:\Users\xxxx\AppData\Local\{084CD918-6C10-49B6-8463-ADD043DC5120} folder moved successfully. C:\Users\xxxx\AppData\Local\{09A3771C-B78C-4498-98CB-543B28BE740A} folder moved successfully. C:\Users\xxxx\AppData\Local\{0D56021F-9E42-4B85-B31C-A3DD36A4BB64} folder moved successfully. C:\Users\xxxx\AppData\Local\{0DFACE19-F3CD-410F-A191-584D497776B2} folder moved successfully. C:\Users\xxxx\AppData\Local\{10413ED5-2123-429F-A248-10745159017B} folder moved successfully. C:\Users\xxxx\AppData\Local\{112A3968-3286-49FD-A103-7C53D4375DE2} folder moved successfully. C:\Users\xxxx\AppData\Local\{119C8AFB-8F57-44EB-857D-38C346CDA230} folder moved successfully. C:\Users\xxxx\AppData\Local\{11BA858C-3E45-49FE-88F8-64C502465F33} folder moved successfully. C:\Users\xxxx\AppData\Local\{11BEE4EA-7ADF-4233-83C0-5277E01BC963} folder moved successfully. C:\Users\xxxx\AppData\Local\{1368D261-2303-488F-92C9-AA3ED0E0FDD3} folder moved successfully. C:\Users\xxxx\AppData\Local\{13CC9495-E01A-49E8-996A-4A9037C18A11} folder moved successfully. C:\Users\xxxx\AppData\Local\{13E305B9-2695-472A-A6A3-E28FA332D5C3} folder moved successfully. C:\Users\xxxx\AppData\Local\{160318E4-7708-49DB-90BD-378DBB4E5688} folder moved successfully. C:\Users\xxxx\AppData\Local\{16108598-FB36-4609-95A3-BD432DD7D605} folder moved successfully. C:\Users\xxxx\AppData\Local\{1645C397-78E9-4413-B96C-618B67545CA6} folder moved successfully. C:\Users\xxxx\AppData\Local\{173E1CE3-11A4-4986-81AA-B71CF740A06B} folder moved successfully. C:\Users\xxxx\AppData\Local\{17499C79-7E9A-43F8-81FA-F764D3B7078F} folder moved successfully. C:\Users\xxxx\AppData\Local\{17D314B0-CABA-439F-81DA-71A005480E0D} folder moved successfully. C:\Users\xxxx\AppData\Local\{17FD2379-ADAE-4F21-853C-B2D357502309} folder moved successfully. C:\Users\xxxx\AppData\Local\{1AD2FDEF-E9F6-4B55-87F5-45B84A3ADF90} folder moved successfully. C:\Users\xxxx\AppData\Local\{1B50E73D-9EC9-4AC4-B8C8-56A66C99D715} folder moved successfully. C:\Users\xxxx\AppData\Local\{1B8ABC04-11D1-4600-A908-D58DDE7E61AC} folder moved successfully. C:\Users\xxxx\AppData\Local\{1E53504E-3896-4D96-A3C1-C86677C0F5EC} folder moved successfully. C:\Users\xxxx\AppData\Local\{1F305725-EABA-4DDE-A1AC-C66B11EAF50F} folder moved successfully. C:\Users\xxxx\AppData\Local\{20E02E86-666B-4957-A789-9705D5441924} folder moved successfully. C:\Users\xxxx\AppData\Local\{20F11E19-4F65-4DA0-821F-A91C6C1A5D2A} folder moved successfully. C:\Users\xxxx\AppData\Local\{225582F6-A685-4E90-9DA4-34087D8C8D68} folder moved successfully. C:\Users\xxxx\AppData\Local\{22DE95D2-FF6F-4A0F-BB24-5CFB3BF519FA} folder moved successfully. C:\Users\xxxx\AppData\Local\{22EE8215-E2A8-4FCB-A6C0-00ACFA460C86} folder moved successfully. C:\Users\xxxx\AppData\Local\{249115D2-283C-430B-B1AF-FED24AD46E1B} folder moved successfully. C:\Users\xxxx\AppData\Local\{26DD3BAE-97A4-4C68-A5D7-5F7381B7B8A8} folder moved successfully. C:\Users\xxxx\AppData\Local\{2903350F-1326-473F-8846-DA8330D1ED8C} folder moved successfully. C:\Users\xxxx\AppData\Local\{2BAF3A7E-2FF6-4CDB-8B92-7C9C236D7795} folder moved successfully. C:\Users\xxxx\AppData\Local\{2E5A56B2-D58D-40A6-9D8A-A5BD03D7A72A} folder moved successfully. C:\Users\xxxx\AppData\Local\{2EAE979F-6368-4762-B5F8-AD5769AAAC6B} folder moved successfully. C:\Users\xxxx\AppData\Local\{2F7EF9FB-15EB-4CDB-B147-AABE7A996100} folder moved successfully. C:\Users\xxxx\AppData\Local\{3066FD50-F0F6-4310-A3A8-BEF6DFF40373} folder moved successfully. C:\Users\xxxx\AppData\Local\{30917DED-2259-4223-800C-42BC8C70899A} folder moved successfully. C:\Users\xxxx\AppData\Local\{31C78FE0-1268-4966-A2A9-E276A0B07251} folder moved successfully. C:\Users\xxxx\AppData\Local\{33E833DF-67BB-4D77-BFB1-53578BE2E45A} folder moved successfully. C:\Users\xxxx\AppData\Local\{345C1EC9-1AC0-4FAC-A621-61ABEE03919E} folder moved successfully. C:\Users\xxxx\AppData\Local\{34D9DB65-88B8-4C67-B9E9-7E5DE49C65AE} folder moved successfully. C:\Users\xxxx\AppData\Local\{350FCAC8-167F-4BF2-B28F-972E91B39813} folder moved successfully. C:\Users\xxxx\AppData\Local\{356534DC-C22A-468D-8BE9-E2D995209161} folder moved successfully. C:\Users\xxxx\AppData\Local\{35CB8539-2DFE-424F-B37E-0EA9729E02B2} folder moved successfully. C:\Users\xxxx\AppData\Local\{36028805-E4D2-49A5-A4F3-8D32A01CEB0E} folder moved successfully. C:\Users\xxxx\AppData\Local\{36C213E6-8D08-4C10-80BC-FC58EB12E5D7} folder moved successfully. C:\Users\xxxx\AppData\Local\{378BEF6A-16D7-4E65-B340-597EE0838D22} folder moved successfully. C:\Users\xxxx\AppData\Local\{38E66B55-3816-470D-B3A4-E33A3814369D} folder moved successfully. C:\Users\xxxx\AppData\Local\{391BF266-EDDF-4988-B5AF-A9D0427CD3EB} folder moved successfully. C:\Users\xxxx\AppData\Local\{3A0FE728-82AC-4403-B667-A874A7407572} folder moved successfully. C:\Users\xxxx\AppData\Local\{3BBB5861-6846-43DE-B708-AF0CF8B500D1} folder moved successfully. C:\Users\xxxx\AppData\Local\{3C318EE7-EF48-472C-8DAA-046B930F87D2} folder moved successfully. C:\Users\xxxx\AppData\Local\{3CCE9DE4-F310-404A-93F1-F6CF8E9C5461} folder moved successfully. C:\Users\xxxx\AppData\Local\{3E85FFC4-0A21-4110-BF75-8629AADE154E} folder moved successfully. C:\Users\xxxx\AppData\Local\{3ED53C52-D935-49C2-BA87-FDBBC3CC8E41} folder moved successfully. C:\Users\xxxx\AppData\Local\{3FFBE344-969B-468B-8D41-22E794D12D38} folder moved successfully. C:\Users\xxxx\AppData\Local\{40E5EAD1-8710-4A63-BE3D-3F98377220C7} folder moved successfully. C:\Users\xxxx\AppData\Local\{410064C0-7A2C-4B1D-9265-B56B0AE9279E} folder moved successfully. C:\Users\xxxx\AppData\Local\{41DEFF66-D087-4EA2-BE29-F69F10BAACAD} folder moved successfully. C:\Users\xxxx\AppData\Local\{41E8D704-23B3-4BE2-971D-58A1CF8CD88A} folder moved successfully. C:\Users\xxxx\AppData\Local\{43114C04-6D74-44C6-BA64-98DA20EE427D} folder moved successfully. C:\Users\xxxx\AppData\Local\{43FA2C76-50E2-4C56-AD5A-284C2F65C222} folder moved successfully. C:\Users\xxxx\AppData\Local\{446B6DAC-C999-4C41-A4A0-81E1EA8C7169} folder moved successfully. C:\Users\xxxx\AppData\Local\{44B52D26-C8F5-465A-9876-DA92DD54AAB8} folder moved successfully. C:\Users\xxxx\AppData\Local\{455BBCAC-18EA-499C-AC8E-558A5907816C} folder moved successfully. C:\Users\xxxx\AppData\Local\{4588DDBD-CD33-46AA-89EF-2DFAF55C8AA4} folder moved successfully. C:\Users\xxxx\AppData\Local\{462E6F37-50A8-4FCF-B15A-B4ED22B072F9} folder moved successfully. C:\Users\xxxx\AppData\Local\{4944FDB7-F14F-4ED8-A364-0B9640D61E5C} folder moved successfully. C:\Users\xxxx\AppData\Local\{4B4615B7-85E1-4F99-BBE8-C4D7A996B5D1} folder moved successfully. C:\Users\xxxx\AppData\Local\{4C8459CA-8873-45AC-8BE2-47341AF16C4F} folder moved successfully. C:\Users\xxxx\AppData\Local\{4D4E4814-0BB3-4633-A000-424B2830E0FA} folder moved successfully. C:\Users\xxxx\AppData\Local\{4DC03E12-D1E7-4B05-9DCF-CC452F8DB72E} folder moved successfully. C:\Users\xxxx\AppData\Local\{4E43EDAE-BAA9-4FFE-B243-0F1BC2836615} folder moved successfully. C:\Users\xxxx\AppData\Local\{4F1699A6-9167-4DEC-918F-FDC80CD6655E} folder moved successfully. C:\Users\xxxx\AppData\Local\{50A7CF6F-FA5F-4096-A21A-F957916D0499} folder moved successfully. C:\Users\xxxx\AppData\Local\{50C7A2C0-193C-4656-A269-05B4DE58AEF9} folder moved successfully. C:\Users\xxxx\AppData\Local\{50E679F3-596B-4FEB-92CB-0D633225B154} folder moved successfully. C:\Users\xxxx\AppData\Local\{5172026E-07E6-4B80-B1B0-04846673EA29} folder moved successfully. C:\Users\xxxx\AppData\Local\{52128488-1342-43AF-8CD4-18FB719FF680} folder moved successfully. C:\Users\xxxx\AppData\Local\{5357F7C4-061A-49CF-8159-BC40A355C1B2} folder moved successfully. C:\Users\xxxx\AppData\Local\{53714989-5D9D-4C33-A02A-DA67FEE1272D} folder moved successfully. C:\Users\xxxx\AppData\Local\{53A69E20-CFB4-411F-95FB-137080ECB3C4} folder moved successfully. C:\Users\xxxx\AppData\Local\{53FE0F2B-7012-44FA-98C6-4BCBA963FB76} folder moved successfully. C:\Users\xxxx\AppData\Local\{55B10D27-19A9-4D4E-A0E1-71AF7CF0867E} folder moved successfully. C:\Users\xxxx\AppData\Local\{55BAE8F2-4FDB-47E6-9F1B-774931F77772} folder moved successfully. C:\Users\xxxx\AppData\Local\{5627AB7D-CE0E-48CE-8DFF-C904F4BB7905} folder moved successfully. C:\Users\xxxx\AppData\Local\{5640686B-1C2F-49A6-A67C-3C0F4BEA00E2} folder moved successfully. C:\Users\xxxx\AppData\Local\{567BF2D4-BC03-4A62-B2D4-D169F969E3A2} folder moved successfully. C:\Users\xxxx\AppData\Local\{573C1A10-89D5-4BFB-8D4D-F08438AD59F1} folder moved successfully. C:\Users\xxxx\AppData\Local\{578D2E2C-4C45-4599-AE05-F24C26CC6E3D} folder moved successfully. C:\Users\xxxx\AppData\Local\{57C9874A-53FA-45BD-B650-6BA224209523} folder moved successfully. C:\Users\xxxx\AppData\Local\{5816D97D-D944-4177-8E12-89405645E015} folder moved successfully. C:\Users\xxxx\AppData\Local\{58DC3172-BC68-4632-9116-64D94F94DB3D} folder moved successfully. C:\Users\xxxx\AppData\Local\{591E190A-AAD4-4A9F-A22F-93664A0C2E8D} folder moved successfully. C:\Users\xxxx\AppData\Local\{59B2B36C-E495-4839-A2BE-8AAA68B9E17C} folder moved successfully. C:\Users\xxxx\AppData\Local\{5A5BD1B8-037D-4124-9049-2EC934C79439} folder moved successfully. C:\Users\xxxx\AppData\Local\{5B13A29A-DE22-4FED-94D5-4B2AD70EF121} folder moved successfully. C:\Users\xxxx\AppData\Local\{5BD3330C-4046-4664-BBBF-9FAEF94F42B7} folder moved successfully. C:\Users\xxxx\AppData\Local\{5C8EBA92-7BF3-4B72-A389-73748E70B592} folder moved successfully. C:\Users\xxxx\AppData\Local\{5D8A2457-94A3-4272-82CD-D43EFDB2ACB0} folder moved successfully. C:\Users\xxxx\AppData\Local\{5D9C6F7A-EAEB-4652-9089-F10C5940D75B} folder moved successfully. C:\Users\xxxx\AppData\Local\{5EE81445-9BB6-4165-9AC9-914325CB4A56} folder moved successfully. C:\Users\xxxx\AppData\Local\{5FAEEC6F-7060-41EB-A97D-160177E58799} folder moved successfully. C:\Users\xxxx\AppData\Local\{60EE2572-72AB-4642-82F0-E6FD01678CCE} folder moved successfully. C:\Users\xxxx\AppData\Local\{61654517-7FC6-4C8E-8C48-C6E95C613CBB} folder moved successfully. C:\Users\xxxx\AppData\Local\{644A4DCC-A0B8-47E1-8EEB-4A49F539DF6A} folder moved successfully. C:\Users\xxxx\AppData\Local\{645586C4-A428-4A29-83BD-9EE285B73EC9} folder moved successfully. C:\Users\xxxx\AppData\Local\{645DE292-DD69-4543-9834-FF5EF9B4452E} folder moved successfully. C:\Users\xxxx\AppData\Local\{64E6186F-57B3-4F93-A636-AAB5F6E3C1D7} folder moved successfully. C:\Users\xxxx\AppData\Local\{653FCC16-60DA-406E-9D73-BFCBD6EF5462} folder moved successfully. C:\Users\xxxx\AppData\Local\{66BF0241-DA1B-4420-968F-E2ECFE5710B3} folder moved successfully. C:\Users\xxxx\AppData\Local\{66D16DAE-DB05-4295-A84C-79D6464959DC} folder moved successfully. C:\Users\xxxx\AppData\Local\{6854EB81-195C-47EE-8625-1982572DA9DD} folder moved successfully. C:\Users\xxxx\AppData\Local\{6B40A652-5D5B-408C-AC09-85B59B81EF58} folder moved successfully. C:\Users\xxxx\AppData\Local\{6D865ACE-3CC4-4457-AA81-99546169435E} folder moved successfully. C:\Users\xxxx\AppData\Local\{6E2324A5-EEC7-4273-B60C-A7C6F00DDB50} folder moved successfully. C:\Users\xxxx\AppData\Local\{6F37F825-E503-4F9B-BC60-DDA9634922D7} folder moved successfully. C:\Users\xxxx\AppData\Local\{6F78AD62-DF91-4333-AB0B-B8A0A8DBAEF7} folder moved successfully. C:\Users\xxxx\AppData\Local\{6FFD9FA2-CB24-456E-BA8A-324ED9457CDA} folder moved successfully. C:\Users\xxxx\AppData\Local\{707F5445-683F-42AC-A6C0-4A7F441C72BF} folder moved successfully. C:\Users\xxxx\AppData\Local\{70C1CA01-2CFB-4DF5-95EC-05B1B3466215} folder moved successfully. C:\Users\xxxx\AppData\Local\{71E05716-46C2-4A99-9EF3-335133BBF766} folder moved successfully. C:\Users\xxxx\AppData\Local\{75527362-54B7-4D96-9AD1-DDDC72ED2C77} folder moved successfully. C:\Users\xxxx\AppData\Local\{75CF12CA-D0EB-4E88-B740-AEC873F8EA8F} folder moved successfully. C:\Users\xxxx\AppData\Local\{7706C301-7C4F-4689-BD7C-661D488CEFD9} folder moved successfully. C:\Users\xxxx\AppData\Local\{7805F575-8219-4D00-89A8-23ED7C111B22} folder moved successfully. C:\Users\xxxx\AppData\Local\{7860D1F6-A6B1-4672-AF36-C0DF00DA88CC} folder moved successfully. C:\Users\xxxx\AppData\Local\{7CAE350F-FB43-42C7-8624-24600D20B3B0} folder moved successfully. C:\Users\xxxx\AppData\Local\{7DC945EB-0338-4BFB-B768-4D32168FF771} folder moved successfully. C:\Users\xxxx\AppData\Local\{801FCA45-EADC-4F70-8FEF-93FB3FC08926} folder moved successfully. C:\Users\xxxx\AppData\Local\{807EE096-C205-4110-827B-4DA5BFED6EAD} folder moved successfully. C:\Users\xxxx\AppData\Local\{80C242D8-3532-4714-8FA4-535ABA85DE98} folder moved successfully. C:\Users\xxxx\AppData\Local\{81C07C12-B0D4-4842-87A7-A0C0974DF891} folder moved successfully. C:\Users\xxxx\AppData\Local\{82E0073E-4891-4280-BBE3-210966502318} folder moved successfully. C:\Users\xxxx\AppData\Local\{846E948A-45CB-4E28-AAF1-5AA6F30D6807} folder moved successfully. C:\Users\xxxx\AppData\Local\{86EFF1ED-F932-45C2-AF96-2CD0BE3D5037} folder moved successfully. C:\Users\xxxx\AppData\Local\{8882490F-F623-4495-A5D4-D7F2FFDA1AD0} folder moved successfully. C:\Users\xxxx\AppData\Local\{8920156E-9E0B-41C8-91A5-F64D45A90197} folder moved successfully. C:\Users\xxxx\AppData\Local\{89B49850-862D-47DF-9DE1-E67BF5B7A5C4} folder moved successfully. C:\Users\xxxx\AppData\Local\{8B0584AB-F56A-4C49-927A-11EE210557BB} folder moved successfully. C:\Users\xxxx\AppData\Local\{8C6082E8-8175-44BD-9BB4-8F38EF0A85D7} folder moved successfully. C:\Users\xxxx\AppData\Local\{8E818C49-E2D5-4992-A025-9273F1EFE6C0} folder moved successfully. C:\Users\xxxx\AppData\Local\{90020A9C-70B7-4A73-A234-D8FF200F2330} folder moved successfully. C:\Users\xxxx\AppData\Local\{90898BA9-F389-40AA-A810-5128BF090989} folder moved successfully. C:\Users\xxxx\AppData\Local\{914BB025-B9DA-4652-80B4-847D82B4A407} folder moved successfully. C:\Users\xxxx\AppData\Local\{915BABB7-6EC8-4EBD-9E23-84F38E1C11A4} folder moved successfully. C:\Users\xxxx\AppData\Local\{91B27611-95F7-431B-8F9E-8E20122A3BA4} folder moved successfully. C:\Users\xxxx\AppData\Local\{92331D61-1AF3-4A03-84A3-62305FC97E08} folder moved successfully. C:\Users\xxxx\AppData\Local\{92C1A64E-FD3C-4A37-9A84-40003344644C} folder moved successfully. C:\Users\xxxx\AppData\Local\{92EAD28F-11A3-4624-9771-6A830DB79266} folder moved successfully. C:\Users\xxxx\AppData\Local\{9360E6C3-E347-4954-876B-AD78ADBCF079} folder moved successfully. C:\Users\xxxx\AppData\Local\{9367F47B-5BEF-4F56-BB59-6F4FFD6981D9} folder moved successfully. C:\Users\xxxx\AppData\Local\{937183BE-BD4F-4FF2-99B5-065306BD2872} folder moved successfully. C:\Users\xxxx\AppData\Local\{961CE6F4-1E3F-4EA1-9BBD-8C7A90090DA7} folder moved successfully. C:\Users\xxxx\AppData\Local\{972E1C3A-F676-487C-A755-64578DDD725B} folder moved successfully. C:\Users\xxxx\AppData\Local\{98E3699C-91CA-4FCA-937D-D79A8985B630} folder moved successfully. C:\Users\xxxx\AppData\Local\{9B62748E-DCDA-43F8-8DCF-0ECDEBE1A68D} folder moved successfully. C:\Users\xxxx\AppData\Local\{9D466C6B-6712-47BA-8D81-4914881EEC23} folder moved successfully. C:\Users\xxxx\AppData\Local\{A00A4AAC-C04B-495E-B74A-B7A142B9049B} folder moved successfully. C:\Users\xxxx\AppData\Local\{A2417884-7600-4153-A645-C8EA3401D87C} folder moved successfully. C:\Users\xxxx\AppData\Local\{A34A521D-93CA-408E-AE0B-BA1A9951910A} folder moved successfully. C:\Users\xxxx\AppData\Local\{A379C2E7-5AE5-413D-89D6-903BBD85114D} folder moved successfully. C:\Users\xxxx\AppData\Local\{A3D3B538-B4F1-4E0E-AFBB-DEDE473D2802} folder moved successfully. C:\Users\xxxx\AppData\Local\{A58B18EA-0728-4D71-8FE5-A7D9DAA35A9D} folder moved successfully. C:\Users\xxxx\AppData\Local\{A5E247D3-C42B-49F8-A03C-C0EBA90001B1} folder moved successfully. C:\Users\xxxx\AppData\Local\{A6426CA9-41D7-4A32-B76A-FA6CD794E74D} folder moved successfully. C:\Users\xxxx\AppData\Local\{A68B2F84-B4E7-45CF-958C-BE5B5428EA63} folder moved successfully. C:\Users\xxxx\AppData\Local\{A7353F4A-C698-45D6-A9D7-4D6A8CCF9B5D} folder moved successfully. C:\Users\xxxx\AppData\Local\{A76DC4C5-2BA2-4404-8940-0E9AC124E530} folder moved successfully. C:\Users\xxxx\AppData\Local\{A9DB4A07-583D-47AC-A5C4-BFCD263561F2} folder moved successfully. C:\Users\xxxx\AppData\Local\{AAA1835C-C9C5-4BA8-B9BA-33D22390C6B2} folder moved successfully. C:\Users\xxxx\AppData\Local\{AAE7BF60-0108-4CC3-A133-8A3694557DD0} folder moved successfully. C:\Users\xxxx\AppData\Local\{ABDC87A4-1F10-4794-86EB-D1E79FC74EDB} folder moved successfully. C:\Users\xxxx\AppData\Local\{AD56B45A-25A6-4B34-B06F-92A9CAF2ABD7} folder moved successfully. C:\Users\xxxx\AppData\Local\{ADB06C9D-CEE0-4731-9D45-5809B046DC89} folder moved successfully. C:\Users\xxxx\AppData\Local\{AF418F43-A533-4784-A793-FEEDF48C6C7C} folder moved successfully. C:\Users\xxxx\AppData\Local\{AFDCBCCE-84F0-477D-9F53-4D2F96DE7110} folder moved successfully. C:\Users\xxxx\AppData\Local\{B071C033-5563-4E6E-B684-63F276620202} folder moved successfully. C:\Users\xxxx\AppData\Local\{B209EA23-F7A0-4F20-8559-E78C04F76607} folder moved successfully. C:\Users\xxxx\AppData\Local\{B58C3A10-84E9-444A-8B45-FBF52A0472AE} folder moved successfully. C:\Users\xxxx\AppData\Local\{B675FB9C-7D75-4E0C-B34F-B44D9D1871B3} folder moved successfully. C:\Users\xxxx\AppData\Local\{B8D2E548-0E0E-4853-9E7C-77F332D66C20} folder moved successfully. C:\Users\xxxx\AppData\Local\{BA5D24C7-4F20-4329-9004-7601A4D792B3} folder moved successfully. C:\Users\xxxx\AppData\Local\{BA66D5F0-9766-4521-8FEB-06A1BB7F9E21} folder moved successfully. C:\Users\xxxx\AppData\Local\{BC214277-D140-496C-8BA9-03FC95C7EE91} folder moved successfully. C:\Users\xxxx\AppData\Local\{BCAFE03E-B3EC-4752-93C6-1BF9804A958B} folder moved successfully. C:\Users\xxxx\AppData\Local\{BD38AA02-8146-4BF5-8B91-86896ADAC358} folder moved successfully. C:\Users\xxxx\AppData\Local\{BD5DDA9E-35D0-42DF-AC76-301E44343000} folder moved successfully. C:\Users\xxxx\AppData\Local\{BDCF12EE-F9F1-454C-9705-EBB02B6972C0} folder moved successfully. C:\Users\xxxx\AppData\Local\{BE2A38D9-00F9-40C4-ACFE-32C92C2DC2E0} folder moved successfully. C:\Users\xxxx\AppData\Local\{BE5214ED-5FCD-46D0-BE06-6106188B2A87} folder moved successfully. C:\Users\xxxx\AppData\Local\{C0E050F8-6FD4-480D-A08C-0F9801174C3E} folder moved successfully. C:\Users\xxxx\AppData\Local\{C2560555-85E7-4A68-896E-E070EE992EBE} folder moved successfully. C:\Users\xxxx\AppData\Local\{C3F0C20B-92DF-4698-B760-7ACDBCFE3B3B} folder moved successfully. C:\Users\xxxx\AppData\Local\{C40EC5AA-35E3-498C-ACA2-0E16968A374A} folder moved successfully. C:\Users\xxxx\AppData\Local\{C43CE8F1-0B57-478A-A738-65E25E6E1270} folder moved successfully. C:\Users\xxxx\AppData\Local\{C660A3CA-F2EE-423E-9313-2A8C89C39B69} folder moved successfully. C:\Users\xxxx\AppData\Local\{C7041C06-7AB2-421E-8F91-FCC0334D4DBA} folder moved successfully. C:\Users\xxxx\AppData\Local\{C8177D73-5620-48DA-AD95-E1CA8D933BD8} folder moved successfully. C:\Users\xxxx\AppData\Local\{C889CDC2-9EEC-4738-9589-68D8176975CD} folder moved successfully. C:\Users\xxxx\AppData\Local\{C92B0A0D-2217-406F-9D37-3752AA2C5D3E} folder moved successfully. C:\Users\xxxx\AppData\Local\{C9495A0F-8D47-46B9-80DE-D4FBD5296E9B} folder moved successfully. C:\Users\xxxx\AppData\Local\{C98FFC2A-66A3-44CD-84EC-3C950D87D7CF} folder moved successfully. C:\Users\xxxx\AppData\Local\{CCD7C82F-2996-44B0-8BFA-4EBE56C1F890} folder moved successfully. C:\Users\xxxx\AppData\Local\{CF1D33E3-9120-42D0-81AD-FA2002CEC7C4} folder moved successfully. C:\Users\xxxx\AppData\Local\{CFEFCFA9-072D-4163-AB6D-3B4DA7F14584} folder moved successfully. C:\Users\xxxx\AppData\Local\{D2F5A8DB-1596-4AB2-96F7-F8A9B823621C} folder moved successfully. C:\Users\xxxx\AppData\Local\{D3562EB7-D947-4793-A061-48BAFB374F0C} folder moved successfully. C:\Users\xxxx\AppData\Local\{D380F8E7-7613-4A40-83BB-1A561FC2841D} folder moved successfully. C:\Users\xxxx\AppData\Local\{D4E47779-F117-4E3F-BF91-89CA267EC54A} folder moved successfully. C:\Users\xxxx\AppData\Local\{D4E90461-8BD6-4DB6-8963-2158A9264991} folder moved successfully. C:\Users\xxxx\AppData\Local\{D582E7D1-3BC3-4CAD-9F7C-0C9DD4458E7E} folder moved successfully. C:\Users\xxxx\AppData\Local\{D61CE211-CDDD-4F88-B1B8-B52354A53164} folder moved successfully. C:\Users\xxxx\AppData\Local\{D62906C1-9448-4D1A-9C53-D3FB4B61BE9C} folder moved successfully. C:\Users\xxxx\AppData\Local\{D65EB766-BC2E-4E02-A3E0-4593C6A756FE} folder moved successfully. C:\Users\xxxx\AppData\Local\{D6C8A382-4B7B-483A-A884-4F82EF227C37} folder moved successfully. C:\Users\xxxx\AppData\Local\{D6F8BF70-8584-4D0C-98C5-117BDDC74C2B} folder moved successfully. C:\Users\xxxx\AppData\Local\{D8656328-D49D-4813-BF6A-AF924A8BC3E7} folder moved successfully. C:\Users\xxxx\AppData\Local\{D89546C7-D034-44A7-B888-1D15BEE595BB} folder moved successfully. C:\Users\xxxx\AppData\Local\{D90346ED-B7DD-4886-A679-30EC7A899CD5} folder moved successfully. C:\Users\xxxx\AppData\Local\{DA142758-0484-450E-A5AA-B356CE2169D3} folder moved successfully. C:\Users\xxxx\AppData\Local\{DA4AD86E-D62D-4283-AD29-E6359F4958C1} folder moved successfully. C:\Users\xxxx\AppData\Local\{DD20DFF2-CC62-4C04-98B3-707C7F35DF97} folder moved successfully. C:\Users\xxxx\AppData\Local\{DDCC194D-6157-41AB-80B1-28ADFD2BA454} folder moved successfully. C:\Users\xxxx\AppData\Local\{DDFDAB7C-4315-4D0F-9E6D-BC91D70455FB} folder moved successfully. C:\Users\xxxx\AppData\Local\{DE61E16F-9A55-4129-916A-8A7284EAC726} folder moved successfully. C:\Users\xxxx\AppData\Local\{E1C208DB-7DF2-4C00-BAD9-5B25581AA97A} folder moved successfully. C:\Users\xxxx\AppData\Local\{E25298B0-7697-47AD-9930-124324627EC6} folder moved successfully. C:\Users\xxxx\AppData\Local\{E2BB8F2E-90CB-43F8-AC11-B76F454A197C} folder moved successfully. C:\Users\xxxx\AppData\Local\{E668C12D-335E-4994-BB72-039B74516546} folder moved successfully. C:\Users\xxxx\AppData\Local\{E7A93495-7D63-46D0-9D04-BD172FDA7D58} folder moved successfully. C:\Users\xxxx\AppData\Local\{E806DC06-A5D3-4185-977C-D26C6FE23890} folder moved successfully. C:\Users\xxxx\AppData\Local\{E8792948-D424-4D2F-8672-48BDB797CFCE} folder moved successfully. C:\Users\xxxx\AppData\Local\{EA01EE6A-D77D-4545-8FB7-B538D9D86D53} folder moved successfully. C:\Users\xxxx\AppData\Local\{EC8CB339-00AE-4F11-BB05-2E1827F8F2DD} folder moved successfully. C:\Users\xxxx\AppData\Local\{ED9A7D5D-3A9B-4CA5-AB08-E52DBDC49D63} folder moved successfully. C:\Users\xxxx\AppData\Local\{EE132BEE-0BCF-4E1A-8F47-FD8E6C1203F0} folder moved successfully. C:\Users\xxxx\AppData\Local\{EE4D4FE7-03C6-4FA7-A7BE-11FFEB43C772} folder moved successfully. C:\Users\xxxx\AppData\Local\{EF15F1E7-FD3E-49C6-8510-74ECEA180424} folder moved successfully. C:\Users\xxxx\AppData\Local\{EF36D160-0315-4DAE-ABA7-B87ED8759C8B} folder moved successfully. C:\Users\xxxx\AppData\Local\{F06C4923-CF65-4983-924F-11BF6A63AEBC} folder moved successfully. C:\Users\xxxx\AppData\Local\{F28704C2-FB8D-46D6-8E8A-3B904143DB59} folder moved successfully. C:\Users\xxxx\AppData\Local\{F30C19C0-5AAB-4CFC-BF37-B9696AD348FE} folder moved successfully. C:\Users\xxxx\AppData\Local\{F4DE33BD-1966-48B0-A8FA-279855AEA666} folder moved successfully. C:\Users\xxxx\AppData\Local\{F7A2CA16-1FFC-49A5-9C53-47CDE6747420} folder moved successfully. C:\Users\xxxx\AppData\Local\{F99EE42D-8098-4895-A6E9-83241E5C35C6} folder moved successfully. File\Folder C:\ProgramData\*.exe not found. File\Folder C:\ProgramData\TEMP not found. C:\Users\xxxx\AppData\Local\Temp\ApnStub.exe moved successfully. C:\Users\xxxx\AppData\Local\Temp\DataCard_Setup64.exe moved successfully. C:\Users\xxxx\AppData\Local\Temp\jre-7u3-windows-i586-iftw.exe moved successfully. C:\Users\xxxx\AppData\Local\Temp\jre-7u5-windows-i586-iftw.exe moved successfully. C:\Users\xxxx\AppData\Local\Temp\ResetDevice.exe moved successfully. C:\Users\xxxx\AppData\Local\Temp\SkypeSetup.exe moved successfully. C:\Users\xxxx\AppData\Local\Temp\vlc-2.0.2-win32.exe moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully. C:\Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully. File/Folder C:\Users\xxxx\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk not found. File/Folder C:\Windows\System32\*.tmp not found. File/Folder C:\Windows\SysWOW64\*.tmp not found. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\xxxx\Desktop\cmd.bat deleted successfully. C:\Users\xxxx\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 36118278 bytes ->Temporary Internet Files folder emptied: 9566309 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 492 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: xxxy ->Temp folder emptied: 93102332 bytes ->Temporary Internet Files folder emptied: 56888131 bytes User: xxxz ->Temp folder emptied: 355018732 bytes ->Temporary Internet Files folder emptied: 1156225 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 16879145 bytes User: xxxx ->Temp folder emptied: 596825228 bytes ->Temporary Internet Files folder emptied: 10478480 bytes ->FireFox cache emptied: 79471084 bytes ->Flash cache emptied: 894 bytes User: Public User: xxxa ->Temp folder emptied: 67227 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 492 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 190063 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 312140573 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67832 bytes RecycleBin emptied: 531680630 bytes Total Files Cleaned = 2.002,00 mb OTL by OldTimer - Version 3.2.59.1 log created on 09042012_015845 Files\Folders moved on Reboot... C:\Users\xxxx\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File move failed. C:\Windows\temp\TmpFile1 scheduled to be moved on reboot. File move failed. C:\Windows\temp\tm_icrcL_A606D985_38CA_41ab_BCD9_60F771CF800D scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... |
04.09.2012, 18:16 | #6 |
/// Helfer-Team | BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Sehr gut! Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
__________________ --> BKA-Trojaner Version 2.07 mit PaySafeCard + UKash |
05.09.2012, 06:58 | #7 |
| BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Guten Morgen, der Rechner läuft soweit sehr gut. Was ich allerdings bemerkt habe, ist die Tatsache, dass meine Emailadresse von vielen meiner Emailempfänger auf eine Spam-Blacklist gesetzt wurde. Ob nun Zufall oder nicht, kann ich nicht sagen.... Das heißt jetzt, überall anrufen und die Empfänger bitten, meine Mailadresse wieder von der Blacklist zu nehmen.... Anbei das Logfile von Malwarebytes: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.09.04.11 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 xxxx :: xxxx [Administrator] Schutz: Aktiviert 05.09.2012 04:25:56 mbam-log-2012-09-05 (04-25-56).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|F:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 962697 Laufzeit: 3 Stunde(n), 7 Minute(n), 37 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter # AdwCleaner v2.000 - Datei am 09/05/2012 um 07:42:33 erstellt # Aktualisiert am 30/08/2012 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzer : xxxx - xxxx # Normaler Modus : Normal # Ausgeführt unter : C:\Users\xxxx\Desktop\adwcleaner.exe # Option [Suche] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gefunden : C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\4kohwi3a.default\searchplugins\Askcom.xml Ordner Gefunden : C:\ProgramData\Ask ***** [Registrierungsdatenbank] ***** Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Schlüssel Gefunden : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Schlüssel Gefunden : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Die Registrierungsdatenbank ist sauber. -\\ Mozilla Firefox v15.0 (de) Profilname : default Datei : C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\4kohwi3a.default\prefs.js [OK] Die Datei ist sauber. Profilname : default Datei : C:\Users\xxxy\AppData\Roaming\Mozilla\Firefox\Profiles\ffm5uxyi.default\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [1457 octets] - [05/09/2012 07:42:33] ########## EOF - C:\AdwCleaner[R1].txt - [1517 octets] ########## Werner |
06.09.2012, 00:36 | #8 |
/// Helfer-Team | BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Sehr gut!
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
06.09.2012, 05:59 | #9 |
| BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Guten Morgen, beide Programme sind durchgelaufen. Anbei die Logfiles: AdwCleaner: Code:
ATTFilter # AdwCleaner v2.000 - Datei am 09/06/2012 um 01:45:37 erstellt # Aktualisiert am 30/08/2012 von Xplode # Betriebssystem : Windows 7 Professional Service Pack 1 (64 bits) # Benutzer : xxxx - xxxx # Normaler Modus : Normal # Ausgeführt unter : C:\Users\xxxx\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\4kohwi3a.default\searchplugins\Askcom.xml Ordner Gelöscht : C:\ProgramData\Ask ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{813A22E0-3E2B-4188-9BDA-ECA9878B8D48} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5} ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16421 Wiederhergestellt : [HKCU\Software\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Wiederhergestellt : [HKCU\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Wiederhergestellt : [HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Wiederhergestellt : [HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Wiederhergestellt : [HKU\S-1-5-18\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Wiederhergestellt : [HKU\S-1-5-19\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] Wiederhergestellt : [HKU\S-1-5-20\Software\Microsoft\Internet Explorer\SearchScopes - DefaultScope] -\\ Mozilla Firefox v15.0 (de) Profilname : default Datei : C:\Users\xxxx\AppData\Roaming\Mozilla\Firefox\Profiles\4kohwi3a.default\prefs.js [OK] Die Datei ist sauber. Profilname : default Datei : C:\Users\xxxy\AppData\Roaming\Mozilla\Firefox\Profiles\ffm5uxyi.default\prefs.js [OK] Die Datei ist sauber. ************************* AdwCleaner[R1].txt - [1582 octets] - [05/09/2012 07:42:33] AdwCleaner[S1].txt - [2176 octets] - [06/09/2012 01:45:37] ########## EOF - C:\AdwCleaner[S1].txt - [2236 octets] ########## Code:
ATTFilter Emsisoft Anti-Malware - Version 6.6 Letztes Update: 06.09.2012 01:56:39 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, D:\, F:\ Archiv Scan: An ADS Scan: An Scan Beginn: 06.09.2012 01:57:18 C:\_OTL\MovedFiles\09042012_015845\C_Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\6a800636-548394c0 -> yyyspgcfbuehecyketwr\navcldpkkecwwhwejwmmdg.class gefunden: JAVA.Agent!E2 F:\Dell\DATENxxx\Bedarf\Cryptload\CryptLoad_1.1.6.rar -> CryptLoad_1.1.6\router\FRITZ!Box\nc.exe gefunden: not-a-virus:RemoteAdmin.Win32.NetCat!E2 Gescannt 1139271 Gefunden 2 Scan Ende: 06.09.2012 06:11:57 Scan Zeit: 4:14:39 Was ist als nächstes zu tun? Werner |
06.09.2012, 18:04 | #10 |
/// Helfer-Team | BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Sehr gut! Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
07.09.2012, 05:45 | #11 |
| BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Guten Morgen, alles erledigt. Anbei das Logfile. Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=911c095941308a4683c944a966e8bd0d # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-09-07 03:25:26 # local_time=2012-09-07 05:25:26 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=512 16777215 100 0 14810427 14810427 0 0 # compatibility_mode=5893 16776573 100 94 12207 98594649 0 0 # compatibility_mode=8192 67108863 100 0 97 97 0 0 # scanned=688669 # found=1 # cleaned=1 # scan_time=23526 C:\_OTL\MovedFiles\09042012_015845\C_Users\xxxx\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54\6a800636-548394c0 Java/Exploit.CVE-2012-4681.G trojan (deleted - quarantined) 00000000000000000000000000000000 C Wie geht es in dieser Sache weiter? Bis hierher nochmals tausend Dank! Werner |
07.09.2012, 17:51 | #12 |
/// Helfer-Team | BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Wie lautet diese eMail-Adresse? Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html Danach poste (kopieren und einfuegen) mir, was du hier angezeigt bekommst: PluginCheck Java deaktivieren Aufgrund derezeitigen Sicherheitsluecke: http://www.trojaner-board.de/122961-...ktivieren.html Danach poste mir (kopieren und einfuegen), was du hier angezeigt bekommst: PluginCheck |
07.09.2012, 22:39 | #13 |
| BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Hallo t'John, das Mailen geht schon wieder - habe heute von einem Empfänger eine Empfangsbestätigung bekommen, dessen Mail eigentlich als gesperrt zurück kam... Anbei der PlugIn-Check 1: Code:
ATTFilter PluginCheck Der PluginCheck hilft die größten Sicherheitslücken beim Surfen im Internet zu schliessen. Überprüft wird: Browser, Flash, Java und Adobe Reader Version. Firefox 15.0.1 ist aktuell Flash ist nicht installiert oder aktiviert. Java (1,7,0,7) ist aktuell. Adobe Reader 10,1,4,38 ist aktuell. Code:
ATTFilter PluginCheck Der PluginCheck hilft die größten Sicherheitslücken beim Surfen im Internet zu schliessen. Überprüft wird: Browser, Flash, Java und Adobe Reader Version. Firefox 15.0.1 ist aktuell Flash ist nicht installiert oder aktiviert. Java ist Installiert aber nicht aktiviert. Adobe Reader 10,1,4,38 ist aktuell. Und die anderen Programme wieder deinstalliert werden - sofern das nicht schon auf Anweisung erfolgt ist? Ist die Bereinigung eigentlich nun komplett? Vielen tausend Dank für die Hilfe! Werner |
09.09.2012, 02:20 | #14 |
/// Helfer-Team | BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Sehr gut! damit bist Du sauber und entlassen! adwCleaner entfernen
Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Systemwiederherstellungen leeren Damit der Rechner nicht mit einer infizierten Systemwiederherstellung erneut infiziert werden kann, muessen wir diese leeren. Dazu schalten wir sie einmal aus und dann wieder ein: Systemwiederherstellung deaktivieren Tutorial fuer Windows XP, Windows Vista, Windows 7 Danach wieder aktivieren. Aufräumen mit CCleaner Lasse mit CCleaner (Download) (Anleitung) Fehler in der
Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html PC wird immer langsamer - was tun? |
09.09.2012, 08:56 | #15 |
| BKA-Trojaner Version 2.07 mit PaySafeCard + UKash Hallo t'John und Helferteam! Tausend Dank abschließend für die Unterstützung. Was würden wir alle ohne Euch tun. Werner |
Themen zu BKA-Trojaner Version 2.07 mit PaySafeCard + UKash |
andere, anderen, anmeldung, bka-trojaner, dateien, durchgeführt, erwischt, folge, folgendes, gefunde, gesäubert, laptop, malwarebytes, meldung, nichts, otl-scan, paysafecard, quarantäne, registry, suche, ukash, version, version 2.07, virusscan |