|
Log-Analyse und Auswertung: All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxxWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
19.07.2015, 18:53 | #1 |
| All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Hallo! Ich hoffe, ich habe alle Regeln verstanden und poste in der richtigen 'Abteilung'. Mein Musikrechner Win7 (kein Email Zugang) und nur selten Internet aktiv (für Updates) hat einen Trojaner eingefangen. Wie, weiß ich nicht. Jedenfalls wurden alle meine docx, jpg, pdf, txt nicht aber wav und mp3 in *.zzz umbenannt und verschlüsselt. Scheinbar hat sich die Dateigröße auch verändert, den alle Tools, die ich hier fand (Decrypt Helper von Matthias, Avira, Toll von Dr. Web...) funktionieren leider nicht. Angegebene Gründe sind: Unterschiedliche Dateigröße oder Pärchen passen nicht zusammen. Ich habe auch versucht, mit Recovery Tools (Ontrac) die 'ältere' Version von der Festplatte wieder herzustellen. Leider keine Erfolg. Es sind bei mir 2 von 5 Festplatten betroffen. Entweder war ich schneller beim Ausschalten oder der Trojaner verändert nur C: und D:. Meine Sicherung C: ist von Jänner 2015. Aber die von D: ist von September 2014. Zwischen September bis heute wurden 1000 Files neu erstellt und bearbeitet. D.h. wie bei allen betroffenen Personen ein Horror. Vielleicht findet sich eine nette Person und hilft mir bei der Wiederherstellung der Daten, wenn möglich. Herzliches Dankeschön! Oliver |
19.07.2015, 20:03 | #2 |
/// the machine /// TB-Ausbilder | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
20.07.2015, 13:25 | #3 |
| All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Hi!
__________________Danke für Deine Hilfe! Ich verstehe jetzt nicht das '#'. Aber ich poste mal die beiden LOG Files. Nur zur Klärung. Nach dem ich gemerkt habe, dass der Trojaner auf meiner FP sich gemütlich gemacht habe, habe ich sofort Kaspersky installiert und natürlich auch laufen lassen. Jetzt ist die Frage, ob Du mit den beiden LOG FIles noch etwas anfangen kannst. NOCHMALS DANKESCHÖN!!! CODE] FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-07-2015 01 Ran by music (administrator) on MUSIC-PC on 20-07-2015 13:58:11 Running from J:\ Loaded Profiles: music (Available Profiles: music) Platform: Windows 7 Enterprise (X64) OS Language: Deutsch (Deutschland) Internet Explorer Version 8 (Default browser: FF) Boot Mode: Normal Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum ==================== Processes (Whitelisted) ================= (If an entry is included in the fixlist, the process will be closed. The file will not be moved.) (AMD) C:\Windows\System32\atiesrxx.exe (AMD) C:\Windows\System32\atieclxx.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avp.exe (Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe (MOTU Inc.) C:\Program Files (x86)\MOTU\motuDNSResponder.exe (PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe (Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe (ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe () C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe () C:\Program Files (x86)\Tor\tor.exe (Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avpui.exe (Smartbar) C:\Users\music\AppData\Local\Smartbar\Application\SnapDo.exe (Cheba) C:\Users\music\AppData\Local\Cheba\Cheba.exe (Microsoft Corporation) C:\Windows\System32\rundll32.exe (Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe () C:\Program Files\behringer\behringer_XUF_1394_driver\X-UF 1394 Control Panel.exe () C:\Program Files (x86)\MOTU\Audio\MFWAKeys.exe (PixelMetrics) C:\Program Files (x86)\CaptureWiz\Pro\CaptureWiz.exe (Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe (Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe (Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe (Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe (Universal Audio, Inc.) C:\Program Files (x86)\Universal Audio\Powered Plugins\UATrayIcon.exe (NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe (ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe (Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe ==================== Registry (Whitelisted) ================== (If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.) HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-10] (Adobe Systems Incorporated) HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [85160 2009-06-17] (Elaborate Bytes AG) HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-01-04] (Advanced Micro Devices, Inc.) HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [155648 2011-05-03] (Apple Computer, Inc.) HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated) HKLM-x32\...\Run: [] => [X] HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated) HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.) HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation) HKLM-x32\...\Run: [UATrayIcon] => C:\Program Files (x86)\Universal Audio\Powered Plugins\UATrayIcon.exe [1404928 2013-06-03] (Universal Audio, Inc.) HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2010-01-22] (NEC Electronics Corporation) Winlogon\Notify\hncvavd: C:\Users\music\AppData\Local\hncvavd.dll [2015-07-17] () HKU\S-1-5-21-1233522967-52797685-3324903142-1001\...\Run: [AdobeBridge] => [X] HKU\S-1-5-21-1233522967-52797685-3324903142-1001\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe" HKU\S-1-5-21-1233522967-52797685-3324903142-1001\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\music\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] () HKU\S-1-5-21-1233522967-52797685-3324903142-1001\...\Run: [Browser Infrastructure Helper] => C:\Users\music\AppData\Local\Smartbar\Application\SnapDo.exe [21536 2013-10-31] (Smartbar) HKU\S-1-5-21-1233522967-52797685-3324903142-1001\...\Run: [Cheba] => C:\Users\music\AppData\Local\Cheba\Cheba.exe [126976 2015-07-08] (Cheba) HKU\S-1-5-21-1233522967-52797685-3324903142-1001\...\Run: [hncvavd] => rundll32 "C:\Users\music\AppData\Local\hncvavd.dll",hncvavd <===== ATTENTION AppInit_DLLs: C:\Users\music\AppData\Local\Cheba\pass64.dll => C:\Users\music\AppData\Local\Cheba\pass64.dll [141312 2015-07-08] (TODO: <Company name>) AppInit_DLLs-x32: C:\Users\music\AppData\Local\Cheba\pass32.dll => C:\Users\music\AppData\Local\Cheba\pass32.dll [122368 2015-07-08] (TODO: <Company name>) Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Behringer X-UF 1394 Control Panel.lnk [2013-05-14] ShortcutTarget: Behringer X-UF 1394 Control Panel.lnk -> C:\Program Files\behringer\behringer_XUF_1394_driver\X-UF 1394 Control Panel.exe () Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MOTU Pedal Service.lnk [2012-12-23] ShortcutTarget: MOTU Pedal Service.lnk -> C:\Program Files (x86)\MOTU\Audio\MFWAKeys.exe () Startup: C:\Users\music\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CaptureWiz.lnk [2013-08-01] ShortcutTarget: CaptureWiz.lnk -> C:\Program Files (x86)\CaptureWiz\Pro\CaptureWiz.exe (PixelMetrics) ==================== Internet (Whitelisted) ==================== (If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.) HKU\S-1-5-21-1233522967-52797685-3324903142-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=Chew&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&barcodeid=162196&installDate=01/01/2014&searchtype=ds&q={searchTerms} HKU\S-1-5-21-1233522967-52797685-3324903142-1001\Software\Microsoft\Internet Explorer\Main,Start Page = Search HKU\S-1-5-21-1233522967-52797685-3324903142-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Österreich - jetzt mit dem Hotmail-Nachfolger Outlook und Skype HKU\S-1-5-21-1233522967-52797685-3324903142-1001\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://isearch.babylon.com/?affID=110824&tt=4712_5&babsrc=HP_ss_Btisdt4&mntrId=1c1fb9b6000000000000bcaec5028bfa HKU\S-1-5-21-1233522967-52797685-3324903142-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=Chew&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&barcodeid=162196&installDate=01/01/2014&searchtype=ds&q={searchTerms} SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=Chew&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&barcodeid=162196&installDate=01/01/2014&searchtype=ds&q={searchTerms} SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=Chew&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&barcodeid=162196&installDate=01/01/2014&searchtype=ds&q={searchTerms} SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = SearchScopes: HKU\S-1-5-21-1233522967-52797685-3324903142-1001 -> DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.golsearch.com/?q={searchTerms}&affID=110824&tt=4712_5&babsrc=SP_ss_Btisdt6&mntrId=1c1fb9b6000000000000bcaec5028bfa SearchScopes: HKU\S-1-5-21-1233522967-52797685-3324903142-1001 -> bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} SearchScopes: HKU\S-1-5-21-1233522967-52797685-3324903142-1001 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=Chew&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&barcodeid=162196&installDate=01/01/2014&searchtype=ds&q={searchTerms} SearchScopes: HKU\S-1-5-21-1233522967-52797685-3324903142-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.golsearch.com/?q={searchTerms}&affID=110824&tt=4712_5&babsrc=SP_ss_Btisdt6&mntrId=1c1fb9b6000000000000bcaec5028bfa BHO: Snap.DoEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\system32\mscoree.dll [2009-11-25] (Microsoft Corporation) BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO) BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO) BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-17] (Google Inc.) BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO) BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05] (Adobe Systems Incorporated) BHO-x32: Babylon toolbar helper -> {2EECD738-5844-4a99-B4B6-146BF802613B} -> C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.3.8\bh\BabylonToolbar.dll No File BHO-x32: Snap.DoEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\SysWOW64\mscoree.dll [2009-11-25] (Microsoft Corporation) BHO-x32: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO) BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation) BHO-x32: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO) BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-17] (Google Inc.) BHO-x32: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO) BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated) BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated) Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll [2009-11-25] (Microsoft Corporation) Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-17] (Google Inc.) Toolbar: HKLM-x32 - Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.3.8\BabylonToolbarTlbr.dll No File Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated) Toolbar: HKLM-x32 - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll [2009-11-25] (Microsoft Corporation) Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-17] (Google Inc.) Toolbar: HKU\S-1-5-21-1233522967-52797685-3324903142-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-17] (Google Inc.) Toolbar: HKU\S-1-5-21-1233522967-52797685-3324903142-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-04] (Microsoft Corporation) Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-04] (Microsoft Corporation) Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-04] (Microsoft Corporation) Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-04] (Microsoft Corporation) Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1 Tcpip\..\Interfaces\{1E8547B1-3D46-4E0B-8594-61BEE31053E6}: [DhcpNameServer] 192.168.1.1 192.168.1.1 FireFox: ======== FF ProfilePath: C:\Users\music\AppData\Roaming\Mozilla\Firefox\Profiles\6a9izthe.default FF NewTab: hxxp://feed.snapdo.com/?publisher=Chew&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&barcodeid=162196&installDate=01/01/2014&searchtype=nt FF SearchEngineOrder.1: Search the web (Babylon) FF SelectedSearchEngine: Google FF Homepage: about:home FF Keyword.URL: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&searchtype=ds&installDate=02/05/2013&q= FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-17] () FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-17] () FF Plugin-x32: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\content_blocker@kaspersky.com [2015-07-18] () FF Plugin-x32: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\virtual_keyboard@kaspersky.com [2015-07-18] () FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.) FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.) FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2011-09-05] (Adobe Systems Inc.) FF Plugin HKU\S-1-5-21-1233522967-52797685-3324903142-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\music\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.) FF user.js: detected! => C:\Users\music\AppData\Roaming\Mozilla\Firefox\Profiles\6a9izthe.default\user.js [2015-07-18] FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2011-09-05] (Adobe Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPSibelius.dll [2010-04-08] () FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\PDFNetC.dll [2010-03-31] (PDFTron Systems Inc.) FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ScorchPDFWrapper.dll [2010-04-08] () FF SearchPlugin: C:\Users\music\AppData\Roaming\Mozilla\Firefox\Profiles\6a9izthe.default\searchplugins\Web Search.xml [2015-02-03] FF Extension: Firefox Alt-Svc Store Hotfix - C:\Users\music\AppData\Roaming\Mozilla\Firefox\Profiles\6a9izthe.default\Extensions\firefox-hotfix@mozilla.org [2015-04-14] FF Extension: Firefox Alt-Svc Store Hotfix - C:\Users\music\AppData\Roaming\Mozilla\Firefox\Profiles\6a9izthe.default\Extensions\firefox-hotfix@mozilla.org.xpi [2015-04-14] FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-03-26] FF HKLM-x32\...\Firefox\Extensions: [content_blocker_663BE84DBCC949E88C7600F63CA7F098@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\content_blocker@kaspersky.com FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\content_blocker@kaspersky.com [2015-07-18] FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard_07402848C2F6470194F131B0F3DE025E@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\virtual_keyboard@kaspersky.com FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\virtual_keyboard@kaspersky.com [2015-07-18] Chrome: ======= CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho ==================== Services (Whitelisted) ================= (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R2 AVP15.0.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avp.exe [194000 2015-07-09] (Kaspersky Lab ZAO) S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed] R2 MOTU_ZeroConf; C:\Program Files (x86)\MOTU\motuDNSResponder.exe [390544 2012-09-06] (MOTU Inc.) R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [7414256 2015-05-19] (Reimage®) S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed] R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-09-02] () [File not signed] <==== ATTENTION S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation) S3 NMIndexingService; "C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe" [X] ==================== Drivers (Whitelisted) ==================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) R0 arcm_a64; C:\Windows\System32\drivers\arcm_a64.sys [59936 2010-12-25] (ARECA Technology Corporation) R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-04] () R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [13368 2009-07-06] () S3 behringer_avs; C:\Windows\System32\Drivers\behringer_avs_x64.sys [73536 2012-06-28] (Archwave AG) S3 behringer_xuf_1394; C:\Windows\System32\Drivers\behringer_xuf_1394_x64.sys [197440 2012-06-28] (Archwave AG) R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [247016 2015-07-09] (Kaspersky Lab UK Ltd) R3 hypaudio; C:\Windows\System32\DRIVERS\hypaudio64.sys [1484800 2011-08-31] (Universal Audio, Inc.) R3 hypkern; C:\Windows\System32\drivers\hypkern64.sys [225792 2011-08-31] () R3 iLokDrvr; C:\Windows\System32\DRIVERS\iLokDrvr.sys [25808 2013-04-11] () R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-07-09] (Kaspersky Lab ZAO) R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [64368 2015-07-09] (Kaspersky Lab ZAO) R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [159960 2015-07-09] (Kaspersky Lab ZAO) R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [225976 2015-07-09] (Kaspersky Lab ZAO) R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [850608 2015-07-09] (Kaspersky Lab ZAO) R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [39280 2015-07-09] (Kaspersky Lab ZAO) R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [40304 2015-07-09] (Kaspersky Lab ZAO) R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [39280 2015-07-09] (Kaspersky Lab ZAO) R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [24944 2015-07-09] (Kaspersky Lab ZAO) R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [65208 2015-07-09] (Kaspersky Lab ZAO) R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [85360 2015-07-09] (Kaspersky Lab ZAO) R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [190648 2015-07-09] (Kaspersky Lab ZAO) R3 MFWAMIDI64; C:\Windows\System32\drivers\MFWAMIDI64.sys [32408 2012-09-06] (Mark of the Unicorn) R3 MFWAWAVE64; C:\Windows\System32\drivers\MFWAWAVE64.sys [82584 2012-09-06] (Mark of the Unicorn) R3 motubus; C:\Windows\System32\drivers\MotuBus64.sys [29848 2012-09-06] (Mark of the Unicorn) R3 MotuFWA64; C:\Windows\System32\drivers\Motufwa64.sys [609944 2012-09-06] (Mark of the Unicorn) R3 motumidi64; C:\Windows\System32\drivers\motumidi64.sys [43672 2012-09-06] (MOTU) R3 MotuUsb64; C:\Windows\System32\Drivers\MotuUsb64.sys [64664 2012-09-06] (MOTU) R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] () S3 Powercore; C:\Windows\System32\DRIVERS\PCore.sys [371248 2010-07-15] (TC Electronic A/S) R3 SynUSB64; C:\Windows\System32\DRIVERS\SynUSB64.sys [30352 2009-06-26] (Steinberg Media Technologies GmbH) R3 UAD2Pcie; C:\Windows\System32\DRIVERS\UAD2Pcie.sys [47616 2013-06-03] (Universal Audio Inc.) R3 UAD2System; C:\Windows\System32\DRIVERS\UAD2System.sys [89088 2013-06-03] (Universal Audio Inc.) S3 cpuz134; \??\C:\Users\music\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X] S3 MAWGSIF64; system32\drivers\MAWGSIF64.sys [X] S3 MAWWAVE64; system32\drivers\MAWWAVE64.sys [X] S3 Motuaw64; system32\drivers\MotuAW64.sys [X] ==================== NetSvcs (Whitelisted) =================== (If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.) ==================== One Month Created files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-20 13:58 - 2015-07-20 13:58 - 00000000 ____D C:\FRST 2015-07-18 10:06 - 2015-07-18 10:06 - 00004274 _____ C:\Windows\System32\Tasks\ReimageUpdater 2015-07-18 10:05 - 2015-07-18 10:10 - 00000000 ____D C:\Program Files\Reimage 2015-07-18 10:05 - 2015-07-18 10:06 - 00000000 ____D C:\ProgramData\Reimage Protector 2015-07-18 10:04 - 2015-07-18 10:06 - 00000165 _____ C:\Windows\Reimage.ini 2015-07-18 00:10 - 2015-07-18 10:45 - 00262144 _____ C:\Windows\system32\config\elam 2015-07-18 00:06 - 2015-07-18 00:06 - 00002091 _____ C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk 2015-07-18 00:06 - 2015-07-18 00:06 - 00000000 ____D C:\Windows\ELAMBKUP 2015-07-18 00:06 - 2015-07-18 00:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus 2015-07-18 00:06 - 2013-05-06 08:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll 2015-07-18 00:05 - 2015-07-20 13:56 - 00000000 ____D C:\ProgramData\Kaspersky Lab 2015-07-18 00:05 - 2015-07-18 00:05 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab 2015-07-18 00:05 - 2015-07-09 19:11 - 00850608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys 2015-07-18 00:05 - 2015-07-09 19:11 - 00225976 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klhk.sys 2015-07-18 00:05 - 2015-07-09 19:11 - 00159960 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys 2015-07-17 23:37 - 2015-07-17 23:37 - 00000250 _____ C:\Users\music\Documents\Recovery_File_exkdd.txt 2015-07-17 23:09 - 2015-07-17 23:09 - 00000250 _____ C:\Users\music\Documents\Recovery_File_fyplu.txt 2015-07-17 22:52 - 2015-07-17 22:52 - 00031744 _____ C:\Users\music\AppData\Local\hncvavd.dll 2015-07-17 22:52 - 2015-07-17 22:52 - 00000250 _____ C:\Users\music\Documents\Recovery_File_khrng.txt 2015-07-11 01:45 - 2015-07-18 00:08 - 00003420 _____ C:\Windows\System32\Tasks\BitGuard 2015-07-10 22:37 - 2015-07-10 22:37 - 00054156 ____H C:\Windows\QTFont.qfn 2015-07-10 22:37 - 2015-07-10 22:37 - 00001409 _____ C:\Windows\QTFont.for 2015-07-09 19:11 - 2015-07-09 19:11 - 00478392 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys 2015-07-09 19:11 - 2015-07-09 19:11 - 00247016 _____ (Kaspersky Lab UK Ltd) C:\Windows\system32\Drivers\cm_km_w.sys 2015-07-09 19:11 - 2015-07-09 19:11 - 00190648 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys 2015-07-09 19:11 - 2015-07-09 19:11 - 00085360 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klwtp.sys 2015-07-09 19:11 - 2015-07-09 19:11 - 00065208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kltdi.sys 2015-07-09 19:11 - 2015-07-09 19:11 - 00064368 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kldisk.sys 2015-07-09 19:11 - 2015-07-09 19:11 - 00040304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys 2015-07-09 19:11 - 2015-07-09 19:11 - 00039280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klmouflt.sys 2015-07-09 19:11 - 2015-07-09 19:11 - 00039280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klim6.sys 2015-07-09 19:11 - 2015-07-09 19:11 - 00024944 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klpd.sys 2015-06-27 12:13 - 2015-07-18 01:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft 2015-06-27 12:13 - 2015-06-27 12:13 - 00001532 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk 2015-06-27 12:13 - 2015-06-27 12:13 - 00001241 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk 2015-06-27 12:13 - 2015-06-27 12:13 - 00001038 _____ C:\Users\Public\Desktop\Best Safe Browser.lnk 2015-06-27 12:13 - 2015-06-27 12:13 - 00000000 ____D C:\Program Files (x86)\FreeCodecPack 2015-06-26 20:19 - 2015-06-26 20:19 - 00060577 _____ C:\Tango Lago Maggiore_GM.mid 2015-06-24 12:15 - 2015-07-14 15:22 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task ==================== One Month Modified files and folders ======== (If an entry is included in the fixlist, the file/folder will be moved.) 2015-07-20 13:56 - 2015-04-14 23:32 - 00000306 _____ C:\Windows\Tasks\DOTHMOI.job 2015-07-20 13:56 - 2013-09-02 17:58 - 00132716 _____ C:\Windows\setupact.log 2015-07-20 13:56 - 2010-12-25 11:04 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2015-07-20 13:56 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT 2015-07-20 13:56 - 2009-07-14 06:45 - 00019600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2015-07-20 13:56 - 2009-07-14 06:45 - 00019600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2015-07-19 12:42 - 2011-02-13 18:29 - 00002186 _____ C:\Windows\wincmd.ini 2015-07-19 12:42 - 2010-12-25 10:29 - 01336403 _____ C:\Windows\WindowsUpdate.log 2015-07-19 12:42 - 2009-07-14 12:49 - 00657438 _____ C:\Windows\system32\perfh007.dat 2015-07-19 12:42 - 2009-07-14 12:49 - 00130810 _____ C:\Windows\system32\perfc007.dat 2015-07-19 12:42 - 2009-07-14 07:13 - 01507170 _____ C:\Windows\system32\PerfStringBackup.INI 2015-07-18 10:47 - 2015-06-09 23:08 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job 2015-07-18 10:47 - 2010-12-25 12:30 - 00074948 _____ C:\Windows\PFRO.log 2015-07-18 10:09 - 2010-12-25 11:04 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2015-07-18 02:00 - 2010-12-25 21:34 - 00000000 ____D C:\Users\music\AppData\Local\Adobe 2015-07-18 01:39 - 2015-06-01 18:56 - 00000000 ____D C:\Users\music\dwhelper 2015-07-18 01:39 - 2015-04-14 21:55 - 00000000 ____D C:\Users\music\Documents\Eventide 2015-07-18 01:39 - 2015-04-14 21:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\H3000 Factory 2015-07-18 01:39 - 2015-02-14 01:24 - 00000000 __HDC C:\ProgramData\{7A86240F-63E1-4D58-83D3-E717B0CCAD94} 2015-07-18 01:39 - 2015-02-14 01:24 - 00000000 ____D C:\Program Files\Native Instruments 2015-07-18 01:39 - 2015-02-11 16:02 - 00000000 ____D C:\Program Files\Relab 2015-07-18 01:39 - 2015-02-09 17:12 - 00000000 ____D C:\Users\Public\Documents\NI Resources 2015-07-18 01:39 - 2015-02-09 17:11 - 00000000 __HDC C:\ProgramData\{E029E712-815A-4E1D-BA1D-7313E45BF6B5} 2015-07-18 01:39 - 2015-02-09 16:51 - 00000000 ____D C:\Program Files\Common Files\Avid 2015-07-18 01:39 - 2015-02-03 21:01 - 00000000 ____D C:\ProgramData\PACE 2015-07-18 01:39 - 2015-02-03 20:57 - 00000000 ____D C:\ProgramData\Apple 2015-07-18 01:39 - 2015-02-03 20:57 - 00000000 ____D C:\Program Files\Bonjour 2015-07-18 01:39 - 2015-02-03 19:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NEC Electronics 2015-07-18 01:39 - 2015-02-03 18:14 - 00000000 ____D C:\ProgramData\Acronis 2015-07-18 01:39 - 2013-11-02 20:10 - 00000000 ____D C:\Users\music\Documents\Amazon MP3 2015-07-18 01:39 - 2013-09-19 20:43 - 00000000 ____D C:\ProgramData\BitGuard 2015-07-18 01:39 - 2013-09-09 16:52 - 00000000 ____D C:\temp 2015-07-18 01:39 - 2013-08-20 15:04 - 00000000 ____D C:\Users\Public\Documents\Adobe 2015-07-18 01:39 - 2013-08-15 16:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wizoo 2015-07-18 01:39 - 2013-08-01 14:28 - 00000000 ____D C:\Users\music\Documents\CaptureWiz 2015-07-18 01:39 - 2013-06-25 00:23 - 00000000 ____D C:\ProgramData\Package Cache 2015-07-18 01:39 - 2013-06-25 00:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UAD Powered Plug-Ins 2015-07-18 01:39 - 2013-06-25 00:23 - 00000000 ____D C:\Program Files\Universal Audio 2015-07-18 01:39 - 2013-06-10 19:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR 2015-07-18 01:39 - 2013-05-14 13:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Behringer X-UF 1394 Driver V5.25.0 2015-07-18 01:39 - 2013-05-14 13:47 - 00000000 ____D C:\Program Files\behringer 2015-07-18 01:39 - 2013-05-02 17:57 - 00000000 ____D C:\Users\music\Documents\Free Sound Recorder 2015-07-18 01:39 - 2013-03-27 18:55 - 00000000 ___HD C:\ProgramData\CanonBJ 2015-07-18 01:39 - 2013-03-26 20:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office 2015-07-18 01:39 - 2013-03-26 20:08 - 00000000 __RHD C:\MSOCache 2015-07-18 01:39 - 2013-03-26 20:08 - 00000000 ____D C:\ProgramData\Microsoft Help 2015-07-18 01:39 - 2013-03-26 20:08 - 00000000 ____D C:\Program Files\Microsoft Office 2015-07-18 01:39 - 2013-03-26 19:57 - 00000000 ____D C:\Users\music\Documents\Adobe 2015-07-18 01:39 - 2013-03-26 19:57 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe 2015-07-18 01:39 - 2013-03-26 19:57 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy 2015-07-18 01:39 - 2013-03-26 19:57 - 00000000 ____D C:\Program Files\Common Files\PACE Anti-Piracy 2015-07-18 01:39 - 2013-03-26 19:53 - 00000000 ____D C:\ProgramData\ALM 2015-07-18 01:39 - 2013-03-26 19:51 - 00000000 ____D C:\Users\music\Adobe Flash Builder 4.6 2015-07-18 01:39 - 2013-03-26 19:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2 2015-07-18 01:39 - 2013-03-26 19:47 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia 2015-07-18 01:39 - 2013-03-26 19:47 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia 2015-07-18 01:39 - 2013-03-26 19:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6 2015-07-18 01:39 - 2013-03-26 19:46 - 00000000 ____D C:\Program Files\Common Files\Adobe 2015-07-18 01:39 - 2013-03-26 19:46 - 00000000 ____D C:\Program Files\Adobe 2015-07-18 01:39 - 2013-02-09 16:35 - 00000000 ____D C:\ProgramData\expLauncher 2015-07-18 01:39 - 2012-12-23 15:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MOTU 2015-07-18 01:39 - 2012-12-23 15:38 - 00000000 ____D C:\Program Files\MOTU 2015-07-18 01:39 - 2012-11-21 02:01 - 00000000 ____D C:\Users\music\Documents\Cubase Projects 2015-07-18 01:39 - 2012-11-21 01:59 - 00000000 ____D C:\Program Files\Common Files\VST3 2015-07-18 01:39 - 2012-11-21 01:59 - 00000000 ____D C:\Program Files\Common Files\Propellerhead Software 2015-07-18 01:39 - 2012-11-21 00:48 - 00000000 ____D C:\Users\music\JDownloader 2015-07-18 01:39 - 2012-11-21 00:47 - 00000000 ____D C:\ProgramData\Babylon 2015-07-18 01:39 - 2012-11-21 00:20 - 00000000 ____D C:\Program Files\eLicenser 2015-07-18 01:39 - 2012-10-02 22:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wibu Emu 2015-07-18 01:39 - 2012-10-02 22:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Algorithmix 2015-07-18 01:39 - 2012-08-05 00:52 - 00000000 ____D C:\Users\music\Documents\Usenet.nl 2015-07-18 01:39 - 2012-08-04 23:31 - 00000000 ____D C:\ProgramData\Mozilla 2015-07-18 01:39 - 2011-07-31 19:34 - 00000000 ____D C:\___FÜR REAKTIVIERUNG 2015-07-18 01:39 - 2011-06-14 22:25 - 00000000 ____D C:\jBridgefürKonvert 2015-07-18 01:39 - 2011-05-03 21:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime 2015-07-18 01:39 - 2011-05-03 21:24 - 00000000 ____D C:\ProgramData\Apple Computer 2015-07-18 01:39 - 2011-03-27 18:12 - 00000000 __HDC C:\ProgramData\{B895D3F6-931C-4B01-A8AC-DCDBBE28F2F9} 2015-07-18 01:39 - 2011-03-27 18:12 - 00000000 ____D C:\ProgramData\Native Instruments 2015-07-18 01:39 - 2011-02-13 22:21 - 00000000 __HDC C:\ProgramData\{39752E59-CE7D-4919-9B7F-020F8C66116C} 2015-07-18 01:39 - 2011-02-13 22:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCM Native Reverb Bundle 2015-07-18 01:39 - 2011-02-13 22:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Ease 2015-07-18 01:39 - 2011-02-13 22:06 - 00000000 ____D C:\ProgramData\Audio Ease 2015-07-18 01:39 - 2011-02-13 19:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProjectSAM Symphobia 2015-07-18 01:39 - 2011-02-13 19:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project SAM Symphobia 2015-07-18 01:39 - 2011-02-13 18:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steinberg WaveLab 2015-07-18 01:39 - 2011-02-13 17:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments FM7 2015-07-18 01:39 - 2011-02-03 00:00 - 00000000 __HDC C:\ProgramData\{B2E750D8-6229-4554-B170-E8C77EDC1596} 2015-07-18 01:39 - 2011-02-02 23:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments FM8 2015-07-18 01:39 - 2011-02-02 23:57 - 00000000 ____D C:\Program Files\Common Files\Digidesign 2015-07-18 01:39 - 2011-02-02 23:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KORG 2015-07-18 01:39 - 2011-02-02 23:26 - 00000000 ____D C:\ProgramData\KORG 2015-07-18 01:39 - 2011-01-26 23:12 - 00000000 ____D C:\ProgramData\ATI 2015-07-18 01:39 - 2011-01-26 23:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center 2015-07-18 01:39 - 2011-01-26 23:09 - 00000000 ____D C:\Program Files\ATI Technologies 2015-07-18 01:39 - 2011-01-26 23:08 - 00000000 ____D C:\ATI 2015-07-18 01:39 - 2011-01-26 22:58 - 00000000 ____D C:\Users\music\Downloads\PC Drivers HeadQuarters 2015-07-18 01:39 - 2011-01-26 22:58 - 00000000 ____D C:\ProgramData\PC Drivers HeadQuarters 2015-07-18 01:39 - 2011-01-26 22:41 - 00000000 ____D C:\Program Files\ATI 2015-07-18 01:39 - 2011-01-23 21:19 - 00000000 ____D C:\Users\music\Documents\TC Electronic 2015-07-18 01:39 - 2011-01-23 17:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS 2015-07-18 01:39 - 2011-01-01 23:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Arturia 2015-07-18 01:39 - 2011-01-01 23:08 - 00000000 ____D C:\ProgramData\Arturia 2015-07-18 01:39 - 2011-01-01 22:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WaveLab 6 2015-07-18 01:39 - 2011-01-01 22:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Drums Overkill 2015-07-18 01:39 - 2010-12-30 00:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jBridge 2015-07-18 01:39 - 2010-12-30 00:20 - 00000000 ____D C:\Program Files\JBridge 2015-07-18 01:39 - 2010-12-29 23:58 - 00000000 ____D C:\Users\music\Documents\FXpansion 2015-07-18 01:39 - 2010-12-29 23:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FXpansion 2015-07-18 01:39 - 2010-12-29 23:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antares Audio Technologies 2015-07-18 01:39 - 2010-12-29 21:29 - 00000000 ____D C:\Users\music\Documents\Toontrack 2015-07-18 01:39 - 2010-12-29 21:23 - 00000000 ____D C:\ProgramData\Toontrack 2015-07-18 01:39 - 2010-12-29 00:29 - 00000000 __HDC C:\ProgramData\{FF8E9195-32BC-4C16-AF7B-A1BE466A0B25} 2015-07-18 01:39 - 2010-12-29 00:03 - 00000000 __HDC C:\ProgramData\{8ABB31F1-7D39-4689-BA29-E75D868AB3C8} 2015-07-18 01:39 - 2010-12-28 23:51 - 00000000 __HDC C:\ProgramData\{0B4D9C16-79C4-4275-AE32-0D58B604783C} 2015-07-18 01:39 - 2010-12-28 23:14 - 00000000 __HDC C:\ProgramData\{3342DAE4-E9C8-491C-8DD2-FA5D6CB18DA6} 2015-07-18 01:39 - 2010-12-28 22:46 - 00000000 ____D C:\ProgramData\Temporary 2015-07-18 01:39 - 2010-12-28 22:46 - 00000000 ____D C:\ProgramData\Celemony Software GmbH 2015-07-18 01:39 - 2010-12-28 22:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Melodyne 3.2 2015-07-18 01:39 - 2010-12-28 22:22 - 00000000 ____D C:\Users\music\Documents\Native Instruments 2015-07-18 01:39 - 2010-12-28 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments 2015-07-18 01:39 - 2010-12-28 22:19 - 00000000 __HDC C:\ProgramData\{BF329843-149E-4A5A-82A1-0250286442D0} 2015-07-18 01:39 - 2010-12-28 22:18 - 00000000 ____D C:\Program Files\Common Files\Native Instruments 2015-07-18 01:39 - 2010-12-28 22:08 - 00000000 ____D C:\MusicLab 2015-07-18 01:39 - 2010-12-28 21:28 - 00000000 ____D C:\ProgramData\Note 2015-07-18 01:39 - 2010-12-28 21:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicLab 2015-07-18 01:39 - 2010-12-28 19:11 - 00000000 ____D C:\ProgramData\Spectrasonics 2015-07-18 01:39 - 2010-12-28 00:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steinberg 2015-07-18 01:39 - 2010-12-28 00:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes 2015-07-18 01:39 - 2010-12-27 13:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yellow Tools Independence Pro 2.5 2015-07-18 01:39 - 2010-12-26 23:44 - 00000000 ____D C:\Users\music\Documents\Steinberg 2015-07-18 01:39 - 2010-12-25 23:10 - 00000000 ____D C:\ProgramData\Yellow Tools 2015-07-18 01:39 - 2010-12-25 22:42 - 00000000 ____D C:\ProgramData\TC Electronic 2015-07-18 01:39 - 2010-12-25 22:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TC Electronic 2015-07-18 01:39 - 2010-12-25 22:39 - 00000000 ____D C:\ProgramData\Universal Audio 2015-07-18 01:39 - 2010-12-25 22:13 - 00000000 ____D C:\Program Files\DIFX 2015-07-18 01:39 - 2010-12-25 22:02 - 00000000 ____D C:\ProgramData\VST3 Presets 2015-07-18 01:39 - 2010-12-25 21:37 - 00000000 ____D C:\Users\music\Documents\VST3 Presets 2015-07-18 01:39 - 2010-12-25 21:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eLicenser 2015-07-18 01:39 - 2010-12-25 21:35 - 00000000 ____D C:\ProgramData\eLicenser 2015-07-18 01:39 - 2010-12-25 21:33 - 00000000 ____D C:\ProgramData\Adobe 2015-07-18 01:39 - 2010-12-25 21:31 - 00000000 ____D C:\ProgramData\McAfee 2015-07-18 01:39 - 2010-12-25 21:28 - 00000000 ____D C:\ProgramData\Syncrosoft 2015-07-18 01:39 - 2010-12-25 21:17 - 00000000 ____D C:\ProgramData\Steinberg 2015-07-18 01:39 - 2010-12-25 21:17 - 00000000 ____D C:\Program Files\Steinberg 2015-07-18 01:39 - 2010-12-25 21:17 - 00000000 ____D C:\Program Files\Common Files\Steinberg 2015-07-18 01:39 - 2010-12-25 21:14 - 00000000 ____D C:\ProgramData\Applications 2015-07-18 01:39 - 2010-12-25 11:04 - 00000000 ____D C:\ProgramData\Google 2015-07-18 01:39 - 2010-12-25 11:04 - 00000000 ____D C:\Program Files\Google 2015-07-18 01:39 - 2010-12-25 10:54 - 00000000 ____D C:\ProgramData\Matrox 2015-07-18 01:39 - 2010-12-25 10:53 - 00000000 ____D C:\mgafold 2015-07-18 01:39 - 2010-12-25 10:28 - 00000000 __SHD C:\Recovery 2015-07-18 01:39 - 2009-07-14 13:07 - 00000000 ____D C:\Program Files\Windows Journal 2015-07-18 01:39 - 2009-07-14 13:06 - 00000000 __RHD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC 2015-07-18 01:39 - 2009-07-14 13:06 - 00000000 ___RD C:\Users\Public\Recorded TV 2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games 2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar 2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Portable Devices 2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer 2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender 2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Reference Assemblies 2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\MSBuild 2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\System 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Services 2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared 2015-07-18 00:47 - 2013-06-21 11:07 - 00000000 ____D C:\Users\music\AppData\Roaming\File Scout 2015-07-18 00:14 - 2011-07-31 18:38 - 00000000 ____D C:\Windows\windupdate 2015-07-17 23:02 - 2010-12-25 11:04 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA 2015-07-17 23:02 - 2010-12-25 11:04 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore 2015-07-17 22:53 - 2015-02-14 02:09 - 00954190 _____ C:\Users\music\Desktop\tyros5_en_dl_c0.pdf.zzz 2015-07-17 22:53 - 2012-08-08 00:20 - 00655630 _____ C:\Users\music\Desktop\TYROS4_VoiceList.pdf.zzz 2015-07-17 22:53 - 2011-08-24 20:29 - 00036782 _____ C:\Users\music\Documents\Schatzifoto-MP.doc.zzz 2015-07-17 22:53 - 2011-01-18 16:39 - 01343102 _____ C:\Users\music\Desktop\Marvell9123_Controller_1001036-WHQL.zip.zzz 2015-07-17 22:38 - 2013-03-26 21:33 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2015-07-17 22:38 - 2013-03-26 21:33 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2015-07-11 00:24 - 2013-08-21 00:56 - 00000320 _____ C:\Windows\wcx_ftp.ini 2015-07-10 22:50 - 2010-12-28 13:48 - 00000000 ____D C:\Users\music\AppData\Roaming\vlc 2015-07-10 10:41 - 2013-08-27 17:18 - 00000132 _____ C:\Users\music\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen 2015-07-09 23:49 - 2012-08-04 23:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2015-07-09 23:47 - 2010-12-25 13:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox 2015-07-09 12:44 - 2015-03-17 18:08 - 00000000 ____D C:\Users\music\AppData\Local\Cheba 2015-06-27 12:13 - 2015-02-11 16:24 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft 2015-06-27 12:13 - 2013-06-04 14:23 - 00000000 ____D C:\Users\music\AppData\Roaming\DVDVideoSoft 2015-06-27 12:02 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT ==================== Files in the root of some directories ======= 2013-08-20 12:48 - 2013-08-27 22:11 - 0000132 _____ () C:\Users\music\AppData\Roaming\Adobe CS6-GIF-Format - Voreinstellungen 2013-08-27 17:18 - 2015-07-10 10:41 - 0000132 _____ () C:\Users\music\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen 2010-12-26 14:24 - 2012-12-17 01:33 - 0000383 _____ () C:\Users\music\AppData\Roaming\MOTU CueMix Prefs.prefs 2013-08-22 15:08 - 2013-08-28 00:10 - 0001456 _____ () C:\Users\music\AppData\Local\Adobe Für Web speichern 13.0 Prefs 2015-07-17 22:52 - 2015-07-17 22:52 - 0031744 _____ () C:\Users\music\AppData\Local\hncvavd.dll 2010-12-25 17:46 - 2010-12-25 17:46 - 0000017 _____ () C:\Users\music\AppData\Local\resmon.resmoncfg Some files in TEMP: ==================== C:\Users\music\AppData\Local\Temp\AMPing.exe C:\Users\music\AppData\Local\Temp\FreeYouTubeDownload.exe C:\Users\music\AppData\Local\Temp\InstallManager_BAB_BAB.exe C:\Users\music\AppData\Local\Temp\rad0B252.tmp.exe C:\Users\music\AppData\Local\Temp\ReimagePackage.exe ==================== Bamital & volsnap Check ================= (There is no automatic fix for files that do not pass verification.) C:\Windows\System32\winlogon.exe => File is digitally signed C:\Windows\System32\wininit.exe => File is digitally signed C:\Windows\SysWOW64\wininit.exe => File is digitally signed C:\Windows\explorer.exe => File is digitally signed C:\Windows\SysWOW64\explorer.exe => File is digitally signed C:\Windows\System32\svchost.exe => File is digitally signed C:\Windows\SysWOW64\svchost.exe => File is digitally signed C:\Windows\System32\services.exe => File is digitally signed C:\Windows\System32\User32.dll => File is digitally signed C:\Windows\SysWOW64\User32.dll => File is digitally signed C:\Windows\System32\userinit.exe => File is digitally signed C:\Windows\SysWOW64\userinit.exe => File is digitally signed C:\Windows\System32\rpcss.dll => File is digitally signed C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed LastRegBack: 2015-07-09 17:03 ==================== End of log ============================ FRST Additions Logfile: Code:
ATTFilter Additional FRST Logfile: |
21.07.2015, 06:54 | #4 |
/// the machine /// TB-Ausbilder | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Der Rechner ist immer noch total verseucht. Fraglich ob sich die Dateien entschlüsseln lassen. Ich hab das mal weitergeleitet, ich melde mich wieder.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
21.07.2015, 10:07 | #5 |
| All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Danke nochmals für Deine Mühe. Wir kennen uns nicht und trotzdem nimmst Du Dir die Zeit -> DANKESCHÖN! Wie schon erwähnt, habe ich die FP C: u. D: gewechselt und danach die Sicherungen eingespielt. Damit habe ich noch die beiden verseuchten Platten zur Analyse und hoffentlich zum Wiederherstellen zur Verfügung. Vor allem die nicht mehr lesbaren Dateien auf D: (jpg, xls, docx) bereiten mir Kopfschmerzen. C: ist mir eigentlich nicht so wichtig. Leider konnte ich mit FRST meine D: Platte nicht scannen. Ich glaube das Tool funktioniert nur immer auf der Systemplatte. Viele liebe Grüße, Oliver |
22.07.2015, 06:38 | #6 |
/// the machine /// TB-Ausbilder | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Ja das scannt nur Systemplatte. Also ist der Scan jetzt von der alten Platte? Rechner ansich hat frische Platten und frische Daten, also kein Handlungsbedarf in Sachen Malwareentfernung?
__________________ --> All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx |
22.07.2015, 09:22 | #7 |
| All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Hallo! JA der Scan ist natürlich von der alten Platte! Kein Handlungsbedarf in Sachen Malwareentfernung. Aber sehr großer Handlungsbedarf in unprodected meiner Files von der D: Platte. wo ich auch zwei protected Files als Bsp. 'upgeloaded' habe. Wäre sehr schlimm, wenn es dazu keine Lösung geben würde. DANKESCHÖN! Oliver |
22.07.2015, 10:10 | #8 |
/// the machine /// TB-Ausbilder | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Sieht schlecht aus, aber ist in Arbeit. Das ist übringens kein Cryptowall, sondern die neueste Version von Teslacrypt. Du kannst auf eigene Gefahr den alten Decoder, für die alten Versionen, versuchen. Aber im schlimmsten Fall kann der das nicht und löscht gleichzeitig noch die Key-Dateien auf dem Rechner, dann geht gar nix mehr.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
23.07.2015, 08:58 | #9 |
| All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Na toll! Gleich den 'Schlimmsten' erwischt....! Ich glaube die Key Dateien sind schon weg. ICh habe schon versucht mit verschiedenen Recover Tools diese Datein zu finden. Keine Chance. Ich weiß nicht wohin die verschwunden sind. Ich habe nie auf die FP geschrieben sondern nur gelesen. Aber die Key Daten, die für jede Datei angelegt wurden, habe ich in meiner Not mit shift Del gelöscht. Schon einen Tag später wollte ich die gelöschten Daten wieder recovern. Bisher keinen Erfolg, obwohl ich nie, wie schon erwähnt, auf die FP geschrieben habe. Jedenfalls DANKE für Deine Hilfe! |
23.07.2015, 12:15 | #10 |
/// the machine /// TB-Ausbilder | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx TeslaDecoder released to decrypt .EXX, .EZZ, .ECC files encrypted by TeslaCrypt - Page 8 - News Lies mal dieses Thema, den dortigen Decoder kannste versuchen, ist aber für die alte Version.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx |
*.zzz, aktiv, avira, cryptowall3.0, daten, email, erstellt, festplatte, festplatten, files, funktionieren, helper, internet, jpg, mp3, mprrq, neu, pdf, recovery, regeln, rsa-2048, tckwp, tools, trojaner, updates, version, verändert, win, win7, zugang |