![]() |
| |||||||
Log-Analyse und Auswertung: All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxxWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| | #1 |
| | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Hallo! Ich hoffe, ich habe alle Regeln verstanden und poste in der richtigen 'Abteilung'. Mein Musikrechner Win7 (kein Email Zugang) und nur selten Internet aktiv (für Updates) hat einen Trojaner eingefangen. Wie, weiß ich nicht. Jedenfalls wurden alle meine docx, jpg, pdf, txt nicht aber wav und mp3 in *.zzz umbenannt und verschlüsselt. Scheinbar hat sich die Dateigröße auch verändert, den alle Tools, die ich hier fand (Decrypt Helper von Matthias, Avira, Toll von Dr. Web...) funktionieren leider nicht. Angegebene Gründe sind: Unterschiedliche Dateigröße oder Pärchen passen nicht zusammen. Ich habe auch versucht, mit Recovery Tools (Ontrac) die 'ältere' Version von der Festplatte wieder herzustellen. Leider keine Erfolg. Es sind bei mir 2 von 5 Festplatten betroffen. Entweder war ich schneller beim Ausschalten oder der Trojaner verändert nur C: und D:. Meine Sicherung C: ist von Jänner 2015. Aber die von D: ist von September 2014. Zwischen September bis heute wurden 1000 Files neu erstellt und bearbeitet. D.h. wie bei allen betroffenen Personen ein Horror. Vielleicht findet sich eine nette Person und hilft mir bei der Wiederherstellung der Daten, wenn möglich. Herzliches Dankeschön! Oliver ![]() ![]() |
| | #2 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Hi,
__________________Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ |
| | #3 |
| | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Hi!
__________________Danke für Deine Hilfe! Ich verstehe jetzt nicht das '#'. Aber ich poste mal die beiden LOG Files. Nur zur Klärung. Nach dem ich gemerkt habe, dass der Trojaner auf meiner FP sich gemütlich gemacht habe, habe ich sofort Kaspersky installiert und natürlich auch laufen lassen. Jetzt ist die Frage, ob Du mit den beiden LOG FIles noch etwas anfangen kannst. NOCHMALS DANKESCHÖN!!! CODE] FRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version:18-07-2015 01
Ran by music (administrator) on MUSIC-PC on 20-07-2015 13:58:11
Running from J:\
Loaded Profiles: music (Available Profiles: music)
Platform: Windows 7 Enterprise (X64) OS Language: Deutsch (Deutschland)
Internet Explorer Version 8 (Default browser: FF)
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: FRST Tutorial - How to use Farbar Recovery Scan Tool - Geeks to Go Forum
==================== Processes (Whitelisted) =================
(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)
(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avp.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(MOTU Inc.) C:\Program Files (x86)\MOTU\motuDNSResponder.exe
(PACE Anti-Piracy, Inc.) C:\Program Files (x86)\Common Files\PACE\Services\LicenseServices\LDSvc.exe
(Reimage®) C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe
(ASUSTeK Computer Inc.) C:\Program Files (x86)\ASUS\ASUSUpdate\UpdateChecker\UpdateChecker.exe
() C:\Program Files\Reimage\Reimage Protector\ReiSystem.exe
() C:\Program Files (x86)\Tor\tor.exe
(Kaspersky Lab ZAO) C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avpui.exe
(Smartbar) C:\Users\music\AppData\Local\Smartbar\Application\SnapDo.exe
(Cheba) C:\Users\music\AppData\Local\Cheba\Cheba.exe
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Microsoft Corporation) C:\Windows\SysWOW64\rundll32.exe
() C:\Program Files\behringer\behringer_XUF_1394_driver\X-UF 1394 Control Panel.exe
() C:\Program Files (x86)\MOTU\Audio\MFWAKeys.exe
(PixelMetrics) C:\Program Files (x86)\CaptureWiz\Pro\CaptureWiz.exe
(Elaborate Bytes AG) C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe
(Apple Computer, Inc.) C:\Program Files (x86)\QuickTime\qttask.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(Adobe Systems Inc.) C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\acrotray.exe
(Universal Audio, Inc.) C:\Program Files (x86)\Universal Audio\Powered Plugins\UATrayIcon.exe
(NEC Electronics Corporation) C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\Microsoft.NET\Framework64\v3.0\WPF\PresentationFontCache.exe
==================== Registry (Whitelisted) ==================
(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)
HKLM\...\Run: [AdobeAAMUpdater-1.0] => C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe [446392 2012-04-04] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Adobe Reader Speed Launcher] => C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe [35736 2010-11-10] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [VirtualCloneDrive] => C:\Program Files (x86)\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe [85160 2009-06-17] (Elaborate Bytes AG)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [336384 2011-01-04] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [QuickTime Task] => C:\Program Files (x86)\QuickTime\qttask.exe [155648 2011-05-03] (Apple Computer, Inc.)
HKLM-x32\...\Run: [SwitchBoard] => C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [AdobeCS6ServiceManager] => C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe [1073312 2012-03-09] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [] => [X]
HKLM-x32\...\Run: [Adobe Acrobat Speed Launcher] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrobat_sl.exe [36760 2011-09-05] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [Acrobat Assistant 8.0] => C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Acrotray.exe [2904984 2011-09-05] (Adobe Systems Inc.)
HKLM-x32\...\Run: [GrooveMonitor] => C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe [30040 2009-02-26] (Microsoft Corporation)
HKLM-x32\...\Run: [UATrayIcon] => C:\Program Files (x86)\Universal Audio\Powered Plugins\UATrayIcon.exe [1404928 2013-06-03] (Universal Audio, Inc.)
HKLM-x32\...\Run: [NUSB3MON] => C:\Program Files (x86)\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe [106496 2010-01-22] (NEC Electronics Corporation)
Winlogon\Notify\hncvavd: C:\Users\music\AppData\Local\hncvavd.dll [2015-07-17] ()
HKU\S-1-5-21-1233522967-52797685-3324903142-1001\...\Run: [AdobeBridge] => [X]
HKU\S-1-5-21-1233522967-52797685-3324903142-1001\...\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] => "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
HKU\S-1-5-21-1233522967-52797685-3324903142-1001\...\Run: [AmazonMP3DownloaderHelper] => C:\Users\music\AppData\Local\Program Files\Amazon\MP3 Downloader\AmazonMP3DownloaderHelper.exe [400704 2013-05-22] ()
HKU\S-1-5-21-1233522967-52797685-3324903142-1001\...\Run: [Browser Infrastructure Helper] => C:\Users\music\AppData\Local\Smartbar\Application\SnapDo.exe [21536 2013-10-31] (Smartbar)
HKU\S-1-5-21-1233522967-52797685-3324903142-1001\...\Run: [Cheba] => C:\Users\music\AppData\Local\Cheba\Cheba.exe [126976 2015-07-08] (Cheba)
HKU\S-1-5-21-1233522967-52797685-3324903142-1001\...\Run: [hncvavd] => rundll32 "C:\Users\music\AppData\Local\hncvavd.dll",hncvavd <===== ATTENTION
AppInit_DLLs: C:\Users\music\AppData\Local\Cheba\pass64.dll => C:\Users\music\AppData\Local\Cheba\pass64.dll [141312 2015-07-08] (TODO: <Company name>)
AppInit_DLLs-x32: C:\Users\music\AppData\Local\Cheba\pass32.dll => C:\Users\music\AppData\Local\Cheba\pass32.dll [122368 2015-07-08] (TODO: <Company name>)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Behringer X-UF 1394 Control Panel.lnk [2013-05-14]
ShortcutTarget: Behringer X-UF 1394 Control Panel.lnk -> C:\Program Files\behringer\behringer_XUF_1394_driver\X-UF 1394 Control Panel.exe ()
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\MOTU Pedal Service.lnk [2012-12-23]
ShortcutTarget: MOTU Pedal Service.lnk -> C:\Program Files (x86)\MOTU\Audio\MFWAKeys.exe ()
Startup: C:\Users\music\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CaptureWiz.lnk [2013-08-01]
ShortcutTarget: CaptureWiz.lnk -> C:\Program Files (x86)\CaptureWiz\Pro\CaptureWiz.exe (PixelMetrics)
==================== Internet (Whitelisted) ====================
(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)
HKU\S-1-5-21-1233522967-52797685-3324903142-1001\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://feed.snapdo.com/?publisher=Chew&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&barcodeid=162196&installDate=01/01/2014&searchtype=ds&q={searchTerms}
HKU\S-1-5-21-1233522967-52797685-3324903142-1001\Software\Microsoft\Internet Explorer\Main,Start Page = Search
HKU\S-1-5-21-1233522967-52797685-3324903142-1001\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = MSN Österreich - jetzt mit dem Hotmail-Nachfolger Outlook und Skype
HKU\S-1-5-21-1233522967-52797685-3324903142-1001\Software\Microsoft\Internet Explorer\Main,bProtector Start Page = hxxp://isearch.babylon.com/?affID=110824&tt=4712_5&babsrc=HP_ss_Btisdt4&mntrId=1c1fb9b6000000000000bcaec5028bfa
HKU\S-1-5-21-1233522967-52797685-3324903142-1001\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://feed.snapdo.com/?publisher=Chew&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&barcodeid=162196&installDate=01/01/2014&searchtype=ds&q={searchTerms}
SearchScopes: HKLM-x32 -> DefaultScope {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=Chew&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&barcodeid=162196&installDate=01/01/2014&searchtype=ds&q={searchTerms}
SearchScopes: HKLM-x32 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=Chew&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&barcodeid=162196&installDate=01/01/2014&searchtype=ds&q={searchTerms}
SearchScopes: HKU\.DEFAULT -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL =
SearchScopes: HKU\S-1-5-21-1233522967-52797685-3324903142-1001 -> DefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.golsearch.com/?q={searchTerms}&affID=110824&tt=4712_5&babsrc=SP_ss_Btisdt6&mntrId=1c1fb9b6000000000000bcaec5028bfa
SearchScopes: HKU\S-1-5-21-1233522967-52797685-3324903142-1001 -> bProtectorDefaultScope {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
SearchScopes: HKU\S-1-5-21-1233522967-52797685-3324903142-1001 -> {006ee092-9658-4fd6-bd8e-a21a348e59f5} URL = hxxp://feed.snapdo.com/?publisher=Chew&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&barcodeid=162196&installDate=01/01/2014&searchtype=ds&q={searchTerms}
SearchScopes: HKU\S-1-5-21-1233522967-52797685-3324903142-1001 -> {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} URL = hxxp://www.golsearch.com/?q={searchTerms}&affID=110824&tt=4712_5&babsrc=SP_ss_Btisdt6&mntrId=1c1fb9b6000000000000bcaec5028bfa
BHO: Snap.DoEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\system32\mscoree.dll [2009-11-25] (Microsoft Corporation)
BHO: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-17] (Google Inc.)
BHO: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\x64\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Adobe PDF Link Helper -> {18DF081C-E8AD-4283-A596-FA578C2EBDC3} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: Babylon toolbar helper -> {2EECD738-5844-4a99-B4B6-146BF802613B} -> C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.3.8\bh\BabylonToolbar.dll No File
BHO-x32: Snap.DoEngine -> {31ad400d-1b06-4e33-a59a-90c2c140cba0} -> C:\Windows\SysWOW64\mscoree.dll [2009-11-25] (Microsoft Corporation)
BHO-x32: Virtual Keyboard Plugin -> {4A66AD60-A03D-4D01-86F0-5F0F7C0EF1AD} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Groove GFS Browser Helper -> {72853161-30C5-4D22-B7F9-0BBC1D38A37E} -> C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll [2009-02-26] (Microsoft Corporation)
BHO-x32: Content Blocker Plugin -> {93BC2EA7-2F17-4729-948A-D2E03FFB2412} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Google Toolbar Helper -> {AA58ED58-01DD-4d91-8333-CF10577473F7} -> C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-17] (Google Inc.)
BHO-x32: Safe Money Plugin -> {AB379017-4C03-4E00-8EDF-E6D6AF7CCF82} -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\IEExt\ie_plugin.dll [2014-12-23] (Kaspersky Lab ZAO)
BHO-x32: Adobe PDF Conversion Toolbar Helper -> {AE7CD045-E861-484f-8273-0445EE161910} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
BHO-x32: SmartSelect Class -> {F4971EE7-DAA0-4053-9964-665D8EE6A077} -> C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\system32\mscoree.dll [2009-11-25] (Microsoft Corporation)
Toolbar: HKLM - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-17] (Google Inc.)
Toolbar: HKLM-x32 - Babylon Toolbar - {98889811-442D-49dd-99D7-DC866BE87DBC} - C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.8.3.8\BabylonToolbarTlbr.dll No File
Toolbar: HKLM-x32 - Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll [2011-09-05] (Adobe Systems Incorporated)
Toolbar: HKLM-x32 - Snap.Do - {ae07101b-46d4-4a98-af68-0333ea26e113} - C:\Windows\SysWOW64\mscoree.dll [2009-11-25] (Microsoft Corporation)
Toolbar: HKLM-x32 - Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll [2015-07-17] (Google Inc.)
Toolbar: HKU\S-1-5-21-1233522967-52797685-3324903142-1001 -> Google Toolbar - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll [2015-07-17] (Google Inc.)
Toolbar: HKU\S-1-5-21-1233522967-52797685-3324903142-1001 -> No Name - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - No File
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Filter: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-04] (Microsoft Corporation)
Filter-x32: deflate - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-04] (Microsoft Corporation)
Filter: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\system32\urlmon.dll [2010-11-04] (Microsoft Corporation)
Filter-x32: gzip - {8f6b0360-b80d-11d0-a9b3-006097942311} - C:\Windows\SysWOW64\urlmon.dll [2010-11-04] (Microsoft Corporation)
Hosts: There are more than one entry in Hosts. See Hosts section of Addition.txt
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1 192.168.1.1
Tcpip\..\Interfaces\{1E8547B1-3D46-4E0B-8594-61BEE31053E6}: [DhcpNameServer] 192.168.1.1 192.168.1.1
FireFox:
========
FF ProfilePath: C:\Users\music\AppData\Roaming\Mozilla\Firefox\Profiles\6a9izthe.default
FF NewTab: hxxp://feed.snapdo.com/?publisher=Chew&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&barcodeid=162196&installDate=01/01/2014&searchtype=nt
FF SearchEngineOrder.1: Search the web (Babylon)
FF SelectedSearchEngine: Google
FF Homepage: about:home
FF Keyword.URL: hxxp://feed.snapdo.com/?publisher=SnapdoOCYB&dpid=SnapdoOCYB&co=AT&userid=6837a47e-d00e-4242-abcc-b66971505980&searchtype=ds&installDate=02/05/2013&q=
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_18_0_0_209.dll [2015-07-17] ()
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_18_0_0_209.dll [2015-07-17] ()
FF Plugin-x32: @kaspersky.com/content_blocker_663BE84DBCC949E88C7600F63CA7F098 -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\content_blocker@kaspersky.com [2015-07-18] ()
FF Plugin-x32: @kaspersky.com/virtual_keyboard_07402848C2F6470194F131B0F3DE025E -> C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\virtual_keyboard@kaspersky.com [2015-07-18] ()
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.28.1\npGoogleUpdate3.dll [2015-07-17] (Google Inc.)
FF Plugin-x32: Adobe Acrobat -> C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Air\nppdf32.dll [2011-09-05] (Adobe Systems Inc.)
FF Plugin HKU\S-1-5-21-1233522967-52797685-3324903142-1001: amazon.com/AmazonMP3DownloaderPlugin -> C:\Users\music\AppData\Local\Program Files\Amazon\MP3 Downloader\npAmazonMP3DownloaderPlugin10181.dll [2013-05-22] (Amazon.com, Inc.)
FF user.js: detected! => C:\Users\music\AppData\Roaming\Mozilla\Firefox\Profiles\6a9izthe.default\user.js [2015-07-18]
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPOFF12.DLL [2006-10-26] (Microsoft Corporation)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\nppdf32.dll [2011-09-05] (Adobe Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\NPSibelius.dll [2010-04-08] ()
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\PDFNetC.dll [2010-03-31] (PDFTron Systems Inc.)
FF Plugin ProgramFiles/Appdata: C:\Program Files (x86)\mozilla firefox\plugins\ScorchPDFWrapper.dll [2010-04-08] ()
FF SearchPlugin: C:\Users\music\AppData\Roaming\Mozilla\Firefox\Profiles\6a9izthe.default\searchplugins\Web Search.xml [2015-02-03]
FF Extension: Firefox Alt-Svc Store Hotfix - C:\Users\music\AppData\Roaming\Mozilla\Firefox\Profiles\6a9izthe.default\Extensions\firefox-hotfix@mozilla.org [2015-04-14]
FF Extension: Firefox Alt-Svc Store Hotfix - C:\Users\music\AppData\Roaming\Mozilla\Firefox\Profiles\6a9izthe.default\Extensions\firefox-hotfix@mozilla.org.xpi [2015-04-14]
FF HKLM-x32\...\Firefox\Extensions: [web2pdfextension@web2pdf.adobedotcom] - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn
FF Extension: Adobe Acrobat - Create PDF - C:\Program Files (x86)\Adobe\Acrobat 10.0\Acrobat\Browser\WCFirefoxExtn [2013-03-26]
FF HKLM-x32\...\Firefox\Extensions: [content_blocker_663BE84DBCC949E88C7600F63CA7F098@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\content_blocker@kaspersky.com
FF Extension: Dangerous Websites Blocker - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\content_blocker@kaspersky.com [2015-07-18]
FF HKLM-x32\...\Firefox\Extensions: [virtual_keyboard_07402848C2F6470194F131B0F3DE025E@kaspersky.com] - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\virtual_keyboard@kaspersky.com
FF Extension: Virtual Keyboard - C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\FFExt\virtual_keyboard@kaspersky.com [2015-07-18]
Chrome:
=======
CHR HKLM\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
CHR HKLM-x32\...\Chrome\Extension: [dbhjdbfgekjfcfkkfjjmlmojhbllhbho] - https://chrome.google.com/webstore/detail/dbhjdbfgekjfcfkkfjjmlmojhbllhbho
==================== Services (Whitelisted) =================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R2 AVP15.0.2; C:\Program Files (x86)\Kaspersky Lab\Kaspersky Anti-Virus 15.0.2\avp.exe [194000 2015-07-09] (Kaspersky Lab ZAO)
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 MOTU_ZeroConf; C:\Program Files (x86)\MOTU\motuDNSResponder.exe [390544 2012-09-06] (MOTU Inc.)
R2 ReimageRealTimeProtector; C:\Program Files\Reimage\Reimage Protector\ReiGuard.exe [7414256 2015-05-19] (Reimage®)
S3 SwitchBoard; C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [517096 2010-02-19] (Adobe Systems Incorporated) [File not signed]
R2 tor; C:\Program Files (x86)\Tor\tor.exe [3233806 2013-09-02] () [File not signed] <==== ATTENTION
S4 WinDefend; C:\Program Files\Windows Defender\mpsvc.dll [1011712 2009-07-14] (Microsoft Corporation)
S3 NMIndexingService; "C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe" [X]
==================== Drivers (Whitelisted) ====================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
R0 arcm_a64; C:\Windows\System32\drivers\arcm_a64.sys [59936 2010-12-25] (ARECA Technology Corporation)
R1 AsIO; C:\Windows\SysWow64\drivers\AsIO.sys [13440 2009-08-04] ()
R1 AsUpIO; C:\Windows\SysWow64\drivers\AsUpIO.sys [13368 2009-07-06] ()
S3 behringer_avs; C:\Windows\System32\Drivers\behringer_avs_x64.sys [73536 2012-06-28] (Archwave AG)
S3 behringer_xuf_1394; C:\Windows\System32\Drivers\behringer_xuf_1394_x64.sys [197440 2012-06-28] (Archwave AG)
R0 cm_km_w; C:\Windows\System32\DRIVERS\cm_km_w.sys [247016 2015-07-09] (Kaspersky Lab UK Ltd)
R3 hypaudio; C:\Windows\System32\DRIVERS\hypaudio64.sys [1484800 2011-08-31] (Universal Audio, Inc.)
R3 hypkern; C:\Windows\System32\drivers\hypkern64.sys [225792 2011-08-31] ()
R3 iLokDrvr; C:\Windows\System32\DRIVERS\iLokDrvr.sys [25808 2013-04-11] ()
R0 kl1; C:\Windows\System32\DRIVERS\kl1.sys [478392 2015-07-09] (Kaspersky Lab ZAO)
R2 kldisk; C:\Windows\System32\DRIVERS\kldisk.sys [64368 2015-07-09] (Kaspersky Lab ZAO)
R3 klflt; C:\Windows\System32\DRIVERS\klflt.sys [159960 2015-07-09] (Kaspersky Lab ZAO)
R1 klhk; C:\Windows\System32\DRIVERS\klhk.sys [225976 2015-07-09] (Kaspersky Lab ZAO)
R1 KLIF; C:\Windows\System32\DRIVERS\klif.sys [850608 2015-07-09] (Kaspersky Lab ZAO)
R1 KLIM6; C:\Windows\System32\DRIVERS\klim6.sys [39280 2015-07-09] (Kaspersky Lab ZAO)
R3 klkbdflt; C:\Windows\System32\DRIVERS\klkbdflt.sys [40304 2015-07-09] (Kaspersky Lab ZAO)
R3 klmouflt; C:\Windows\System32\DRIVERS\klmouflt.sys [39280 2015-07-09] (Kaspersky Lab ZAO)
R1 klpd; C:\Windows\System32\DRIVERS\klpd.sys [24944 2015-07-09] (Kaspersky Lab ZAO)
R1 kltdi; C:\Windows\System32\DRIVERS\kltdi.sys [65208 2015-07-09] (Kaspersky Lab ZAO)
R1 Klwtp; C:\Windows\System32\DRIVERS\klwtp.sys [85360 2015-07-09] (Kaspersky Lab ZAO)
R1 kneps; C:\Windows\System32\DRIVERS\kneps.sys [190648 2015-07-09] (Kaspersky Lab ZAO)
R3 MFWAMIDI64; C:\Windows\System32\drivers\MFWAMIDI64.sys [32408 2012-09-06] (Mark of the Unicorn)
R3 MFWAWAVE64; C:\Windows\System32\drivers\MFWAWAVE64.sys [82584 2012-09-06] (Mark of the Unicorn)
R3 motubus; C:\Windows\System32\drivers\MotuBus64.sys [29848 2012-09-06] (Mark of the Unicorn)
R3 MotuFWA64; C:\Windows\System32\drivers\Motufwa64.sys [609944 2012-09-06] (Mark of the Unicorn)
R3 motumidi64; C:\Windows\System32\drivers\motumidi64.sys [43672 2012-09-06] (MOTU)
R3 MotuUsb64; C:\Windows\System32\Drivers\MotuUsb64.sys [64664 2012-09-06] (MOTU)
R3 MTsensor; C:\Windows\System32\DRIVERS\ASACPI.sys [15416 2009-07-16] ()
S3 Powercore; C:\Windows\System32\DRIVERS\PCore.sys [371248 2010-07-15] (TC Electronic A/S)
R3 SynUSB64; C:\Windows\System32\DRIVERS\SynUSB64.sys [30352 2009-06-26] (Steinberg Media Technologies GmbH)
R3 UAD2Pcie; C:\Windows\System32\DRIVERS\UAD2Pcie.sys [47616 2013-06-03] (Universal Audio Inc.)
R3 UAD2System; C:\Windows\System32\DRIVERS\UAD2System.sys [89088 2013-06-03] (Universal Audio Inc.)
S3 cpuz134; \??\C:\Users\music\AppData\Local\Temp\cpuz134\cpuz134_x64.sys [X]
S3 MAWGSIF64; system32\drivers\MAWGSIF64.sys [X]
S3 MAWWAVE64; system32\drivers\MAWWAVE64.sys [X]
S3 Motuaw64; system32\drivers\MotuAW64.sys [X]
==================== NetSvcs (Whitelisted) ===================
(If an entry is included in the fixlist, it will be removed from the registry. The file will not be moved unless listed separately.)
==================== One Month Created files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-20 13:58 - 2015-07-20 13:58 - 00000000 ____D C:\FRST
2015-07-18 10:06 - 2015-07-18 10:06 - 00004274 _____ C:\Windows\System32\Tasks\ReimageUpdater
2015-07-18 10:05 - 2015-07-18 10:10 - 00000000 ____D C:\Program Files\Reimage
2015-07-18 10:05 - 2015-07-18 10:06 - 00000000 ____D C:\ProgramData\Reimage Protector
2015-07-18 10:04 - 2015-07-18 10:06 - 00000165 _____ C:\Windows\Reimage.ini
2015-07-18 00:10 - 2015-07-18 10:45 - 00262144 _____ C:\Windows\system32\config\elam
2015-07-18 00:06 - 2015-07-18 00:06 - 00002091 _____ C:\Users\Public\Desktop\Kaspersky Anti-Virus.lnk
2015-07-18 00:06 - 2015-07-18 00:06 - 00000000 ____D C:\Windows\ELAMBKUP
2015-07-18 00:06 - 2015-07-18 00:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Kaspersky Anti-Virus
2015-07-18 00:06 - 2013-05-06 08:13 - 00110176 _____ (Kaspersky Lab ZAO) C:\Windows\system32\klfphc.dll
2015-07-18 00:05 - 2015-07-20 13:56 - 00000000 ____D C:\ProgramData\Kaspersky Lab
2015-07-18 00:05 - 2015-07-18 00:05 - 00000000 ____D C:\Program Files (x86)\Kaspersky Lab
2015-07-18 00:05 - 2015-07-09 19:11 - 00850608 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klif.sys
2015-07-18 00:05 - 2015-07-09 19:11 - 00225976 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klhk.sys
2015-07-18 00:05 - 2015-07-09 19:11 - 00159960 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klflt.sys
2015-07-17 23:37 - 2015-07-17 23:37 - 00000250 _____ C:\Users\music\Documents\Recovery_File_exkdd.txt
2015-07-17 23:09 - 2015-07-17 23:09 - 00000250 _____ C:\Users\music\Documents\Recovery_File_fyplu.txt
2015-07-17 22:52 - 2015-07-17 22:52 - 00031744 _____ C:\Users\music\AppData\Local\hncvavd.dll
2015-07-17 22:52 - 2015-07-17 22:52 - 00000250 _____ C:\Users\music\Documents\Recovery_File_khrng.txt
2015-07-11 01:45 - 2015-07-18 00:08 - 00003420 _____ C:\Windows\System32\Tasks\BitGuard
2015-07-10 22:37 - 2015-07-10 22:37 - 00054156 ____H C:\Windows\QTFont.qfn
2015-07-10 22:37 - 2015-07-10 22:37 - 00001409 _____ C:\Windows\QTFont.for
2015-07-09 19:11 - 2015-07-09 19:11 - 00478392 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kl1.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00247016 _____ (Kaspersky Lab UK Ltd) C:\Windows\system32\Drivers\cm_km_w.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00190648 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kneps.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00085360 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klwtp.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00065208 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kltdi.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00064368 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\kldisk.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00040304 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klkbdflt.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00039280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klmouflt.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00039280 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klim6.sys
2015-07-09 19:11 - 2015-07-09 19:11 - 00024944 _____ (Kaspersky Lab ZAO) C:\Windows\system32\Drivers\klpd.sys
2015-06-27 12:13 - 2015-07-18 01:39 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
2015-06-27 12:13 - 2015-06-27 12:13 - 00001532 _____ C:\Users\Public\Desktop\Free YouTube to MP3 Converter.lnk
2015-06-27 12:13 - 2015-06-27 12:13 - 00001241 _____ C:\Users\Public\Desktop\DVDVideoSoft Free Studio.lnk
2015-06-27 12:13 - 2015-06-27 12:13 - 00001038 _____ C:\Users\Public\Desktop\Best Safe Browser.lnk
2015-06-27 12:13 - 2015-06-27 12:13 - 00000000 ____D C:\Program Files (x86)\FreeCodecPack
2015-06-26 20:19 - 2015-06-26 20:19 - 00060577 _____ C:\Tango Lago Maggiore_GM.mid
2015-06-24 12:15 - 2015-07-14 15:22 - 00003886 _____ C:\Windows\System32\Tasks\Adobe Acrobat Update Task
==================== One Month Modified files and folders ========
(If an entry is included in the fixlist, the file/folder will be moved.)
2015-07-20 13:56 - 2015-04-14 23:32 - 00000306 _____ C:\Windows\Tasks\DOTHMOI.job
2015-07-20 13:56 - 2013-09-02 17:58 - 00132716 _____ C:\Windows\setupact.log
2015-07-20 13:56 - 2010-12-25 11:04 - 00001106 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2015-07-20 13:56 - 2009-07-14 07:08 - 00000006 ____H C:\Windows\Tasks\SA.DAT
2015-07-20 13:56 - 2009-07-14 06:45 - 00019600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2015-07-20 13:56 - 2009-07-14 06:45 - 00019600 ____H C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2015-07-19 12:42 - 2011-02-13 18:29 - 00002186 _____ C:\Windows\wincmd.ini
2015-07-19 12:42 - 2010-12-25 10:29 - 01336403 _____ C:\Windows\WindowsUpdate.log
2015-07-19 12:42 - 2009-07-14 12:49 - 00657438 _____ C:\Windows\system32\perfh007.dat
2015-07-19 12:42 - 2009-07-14 12:49 - 00130810 _____ C:\Windows\system32\perfc007.dat
2015-07-19 12:42 - 2009-07-14 07:13 - 01507170 _____ C:\Windows\system32\PerfStringBackup.INI
2015-07-18 10:47 - 2015-06-09 23:08 - 00000884 _____ C:\Windows\Tasks\Adobe Flash Player Updater.job
2015-07-18 10:47 - 2010-12-25 12:30 - 00074948 _____ C:\Windows\PFRO.log
2015-07-18 10:09 - 2010-12-25 11:04 - 00001110 _____ C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2015-07-18 02:00 - 2010-12-25 21:34 - 00000000 ____D C:\Users\music\AppData\Local\Adobe
2015-07-18 01:39 - 2015-06-01 18:56 - 00000000 ____D C:\Users\music\dwhelper
2015-07-18 01:39 - 2015-04-14 21:55 - 00000000 ____D C:\Users\music\Documents\Eventide
2015-07-18 01:39 - 2015-04-14 21:55 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\H3000 Factory
2015-07-18 01:39 - 2015-02-14 01:24 - 00000000 __HDC C:\ProgramData\{7A86240F-63E1-4D58-83D3-E717B0CCAD94}
2015-07-18 01:39 - 2015-02-14 01:24 - 00000000 ____D C:\Program Files\Native Instruments
2015-07-18 01:39 - 2015-02-11 16:02 - 00000000 ____D C:\Program Files\Relab
2015-07-18 01:39 - 2015-02-09 17:12 - 00000000 ____D C:\Users\Public\Documents\NI Resources
2015-07-18 01:39 - 2015-02-09 17:11 - 00000000 __HDC C:\ProgramData\{E029E712-815A-4E1D-BA1D-7313E45BF6B5}
2015-07-18 01:39 - 2015-02-09 16:51 - 00000000 ____D C:\Program Files\Common Files\Avid
2015-07-18 01:39 - 2015-02-03 21:01 - 00000000 ____D C:\ProgramData\PACE
2015-07-18 01:39 - 2015-02-03 20:57 - 00000000 ____D C:\ProgramData\Apple
2015-07-18 01:39 - 2015-02-03 20:57 - 00000000 ____D C:\Program Files\Bonjour
2015-07-18 01:39 - 2015-02-03 19:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NEC Electronics
2015-07-18 01:39 - 2015-02-03 18:14 - 00000000 ____D C:\ProgramData\Acronis
2015-07-18 01:39 - 2013-11-02 20:10 - 00000000 ____D C:\Users\music\Documents\Amazon MP3
2015-07-18 01:39 - 2013-09-19 20:43 - 00000000 ____D C:\ProgramData\BitGuard
2015-07-18 01:39 - 2013-09-09 16:52 - 00000000 ____D C:\temp
2015-07-18 01:39 - 2013-08-20 15:04 - 00000000 ____D C:\Users\Public\Documents\Adobe
2015-07-18 01:39 - 2013-08-15 16:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wizoo
2015-07-18 01:39 - 2013-08-01 14:28 - 00000000 ____D C:\Users\music\Documents\CaptureWiz
2015-07-18 01:39 - 2013-06-25 00:23 - 00000000 ____D C:\ProgramData\Package Cache
2015-07-18 01:39 - 2013-06-25 00:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\UAD Powered Plug-Ins
2015-07-18 01:39 - 2013-06-25 00:23 - 00000000 ____D C:\Program Files\Universal Audio
2015-07-18 01:39 - 2013-06-10 19:01 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
2015-07-18 01:39 - 2013-05-14 13:47 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Behringer X-UF 1394 Driver V5.25.0
2015-07-18 01:39 - 2013-05-14 13:47 - 00000000 ____D C:\Program Files\behringer
2015-07-18 01:39 - 2013-05-02 17:57 - 00000000 ____D C:\Users\music\Documents\Free Sound Recorder
2015-07-18 01:39 - 2013-03-27 18:55 - 00000000 ___HD C:\ProgramData\CanonBJ
2015-07-18 01:39 - 2013-03-26 20:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
2015-07-18 01:39 - 2013-03-26 20:08 - 00000000 __RHD C:\MSOCache
2015-07-18 01:39 - 2013-03-26 20:08 - 00000000 ____D C:\ProgramData\Microsoft Help
2015-07-18 01:39 - 2013-03-26 20:08 - 00000000 ____D C:\Program Files\Microsoft Office
2015-07-18 01:39 - 2013-03-26 19:57 - 00000000 ____D C:\Users\music\Documents\Adobe
2015-07-18 01:39 - 2013-03-26 19:57 - 00000000 ____D C:\ProgramData\regid.1986-12.com.adobe
2015-07-18 01:39 - 2013-03-26 19:57 - 00000000 ____D C:\ProgramData\PACE Anti-Piracy
2015-07-18 01:39 - 2013-03-26 19:57 - 00000000 ____D C:\Program Files\Common Files\PACE Anti-Piracy
2015-07-18 01:39 - 2013-03-26 19:53 - 00000000 ____D C:\ProgramData\ALM
2015-07-18 01:39 - 2013-03-26 19:51 - 00000000 ____D C:\Users\music\Adobe Flash Builder 4.6
2015-07-18 01:39 - 2013-03-26 19:50 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe LiveCycle ES2
2015-07-18 01:39 - 2013-03-26 19:47 - 00000000 ____D C:\Users\Default\AppData\Roaming\Macromedia
2015-07-18 01:39 - 2013-03-26 19:47 - 00000000 ____D C:\Users\Default User\AppData\Roaming\Macromedia
2015-07-18 01:39 - 2013-03-26 19:46 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Master Collection CS6
2015-07-18 01:39 - 2013-03-26 19:46 - 00000000 ____D C:\Program Files\Common Files\Adobe
2015-07-18 01:39 - 2013-03-26 19:46 - 00000000 ____D C:\Program Files\Adobe
2015-07-18 01:39 - 2013-02-09 16:35 - 00000000 ____D C:\ProgramData\expLauncher
2015-07-18 01:39 - 2012-12-23 15:38 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MOTU
2015-07-18 01:39 - 2012-12-23 15:38 - 00000000 ____D C:\Program Files\MOTU
2015-07-18 01:39 - 2012-11-21 02:01 - 00000000 ____D C:\Users\music\Documents\Cubase Projects
2015-07-18 01:39 - 2012-11-21 01:59 - 00000000 ____D C:\Program Files\Common Files\VST3
2015-07-18 01:39 - 2012-11-21 01:59 - 00000000 ____D C:\Program Files\Common Files\Propellerhead Software
2015-07-18 01:39 - 2012-11-21 00:48 - 00000000 ____D C:\Users\music\JDownloader
2015-07-18 01:39 - 2012-11-21 00:47 - 00000000 ____D C:\ProgramData\Babylon
2015-07-18 01:39 - 2012-11-21 00:20 - 00000000 ____D C:\Program Files\eLicenser
2015-07-18 01:39 - 2012-10-02 22:23 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Wibu Emu
2015-07-18 01:39 - 2012-10-02 22:19 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Algorithmix
2015-07-18 01:39 - 2012-08-05 00:52 - 00000000 ____D C:\Users\music\Documents\Usenet.nl
2015-07-18 01:39 - 2012-08-04 23:31 - 00000000 ____D C:\ProgramData\Mozilla
2015-07-18 01:39 - 2011-07-31 19:34 - 00000000 ____D C:\___FÜR REAKTIVIERUNG
2015-07-18 01:39 - 2011-06-14 22:25 - 00000000 ____D C:\jBridgefürKonvert
2015-07-18 01:39 - 2011-05-03 21:24 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\QuickTime
2015-07-18 01:39 - 2011-05-03 21:24 - 00000000 ____D C:\ProgramData\Apple Computer
2015-07-18 01:39 - 2011-03-27 18:12 - 00000000 __HDC C:\ProgramData\{B895D3F6-931C-4B01-A8AC-DCDBBE28F2F9}
2015-07-18 01:39 - 2011-03-27 18:12 - 00000000 ____D C:\ProgramData\Native Instruments
2015-07-18 01:39 - 2011-02-13 22:21 - 00000000 __HDC C:\ProgramData\{39752E59-CE7D-4919-9B7F-020F8C66116C}
2015-07-18 01:39 - 2011-02-13 22:21 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PCM Native Reverb Bundle
2015-07-18 01:39 - 2011-02-13 22:06 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audio Ease
2015-07-18 01:39 - 2011-02-13 22:06 - 00000000 ____D C:\ProgramData\Audio Ease
2015-07-18 01:39 - 2011-02-13 19:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ProjectSAM Symphobia
2015-07-18 01:39 - 2011-02-13 19:07 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Project SAM Symphobia
2015-07-18 01:39 - 2011-02-13 18:33 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steinberg WaveLab
2015-07-18 01:39 - 2011-02-13 17:12 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments FM7
2015-07-18 01:39 - 2011-02-03 00:00 - 00000000 __HDC C:\ProgramData\{B2E750D8-6229-4554-B170-E8C77EDC1596}
2015-07-18 01:39 - 2011-02-02 23:57 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments FM8
2015-07-18 01:39 - 2011-02-02 23:57 - 00000000 ____D C:\Program Files\Common Files\Digidesign
2015-07-18 01:39 - 2011-02-02 23:26 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KORG
2015-07-18 01:39 - 2011-02-02 23:26 - 00000000 ____D C:\ProgramData\KORG
2015-07-18 01:39 - 2011-01-26 23:12 - 00000000 ____D C:\ProgramData\ATI
2015-07-18 01:39 - 2011-01-26 23:10 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Catalyst Control Center
2015-07-18 01:39 - 2011-01-26 23:09 - 00000000 ____D C:\Program Files\ATI Technologies
2015-07-18 01:39 - 2011-01-26 23:08 - 00000000 ____D C:\ATI
2015-07-18 01:39 - 2011-01-26 22:58 - 00000000 ____D C:\Users\music\Downloads\PC Drivers HeadQuarters
2015-07-18 01:39 - 2011-01-26 22:58 - 00000000 ____D C:\ProgramData\PC Drivers HeadQuarters
2015-07-18 01:39 - 2011-01-26 22:41 - 00000000 ____D C:\Program Files\ATI
2015-07-18 01:39 - 2011-01-23 21:19 - 00000000 ____D C:\Users\music\Documents\TC Electronic
2015-07-18 01:39 - 2011-01-23 17:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ASUS
2015-07-18 01:39 - 2011-01-01 23:08 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Arturia
2015-07-18 01:39 - 2011-01-01 23:08 - 00000000 ____D C:\ProgramData\Arturia
2015-07-18 01:39 - 2011-01-01 22:56 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WaveLab 6
2015-07-18 01:39 - 2011-01-01 22:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ Drums Overkill
2015-07-18 01:39 - 2010-12-30 00:20 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\jBridge
2015-07-18 01:39 - 2010-12-30 00:20 - 00000000 ____D C:\Program Files\JBridge
2015-07-18 01:39 - 2010-12-29 23:58 - 00000000 ____D C:\Users\music\Documents\FXpansion
2015-07-18 01:39 - 2010-12-29 23:54 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\FXpansion
2015-07-18 01:39 - 2010-12-29 23:49 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Antares Audio Technologies
2015-07-18 01:39 - 2010-12-29 21:29 - 00000000 ____D C:\Users\music\Documents\Toontrack
2015-07-18 01:39 - 2010-12-29 21:23 - 00000000 ____D C:\ProgramData\Toontrack
2015-07-18 01:39 - 2010-12-29 00:29 - 00000000 __HDC C:\ProgramData\{FF8E9195-32BC-4C16-AF7B-A1BE466A0B25}
2015-07-18 01:39 - 2010-12-29 00:03 - 00000000 __HDC C:\ProgramData\{8ABB31F1-7D39-4689-BA29-E75D868AB3C8}
2015-07-18 01:39 - 2010-12-28 23:51 - 00000000 __HDC C:\ProgramData\{0B4D9C16-79C4-4275-AE32-0D58B604783C}
2015-07-18 01:39 - 2010-12-28 23:14 - 00000000 __HDC C:\ProgramData\{3342DAE4-E9C8-491C-8DD2-FA5D6CB18DA6}
2015-07-18 01:39 - 2010-12-28 22:46 - 00000000 ____D C:\ProgramData\Temporary
2015-07-18 01:39 - 2010-12-28 22:46 - 00000000 ____D C:\ProgramData\Celemony Software GmbH
2015-07-18 01:39 - 2010-12-28 22:44 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Melodyne 3.2
2015-07-18 01:39 - 2010-12-28 22:22 - 00000000 ____D C:\Users\music\Documents\Native Instruments
2015-07-18 01:39 - 2010-12-28 22:22 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
2015-07-18 01:39 - 2010-12-28 22:19 - 00000000 __HDC C:\ProgramData\{BF329843-149E-4A5A-82A1-0250286442D0}
2015-07-18 01:39 - 2010-12-28 22:18 - 00000000 ____D C:\Program Files\Common Files\Native Instruments
2015-07-18 01:39 - 2010-12-28 22:08 - 00000000 ____D C:\MusicLab
2015-07-18 01:39 - 2010-12-28 21:28 - 00000000 ____D C:\ProgramData\Note
2015-07-18 01:39 - 2010-12-28 21:11 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MusicLab
2015-07-18 01:39 - 2010-12-28 19:11 - 00000000 ____D C:\ProgramData\Spectrasonics
2015-07-18 01:39 - 2010-12-28 00:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Steinberg
2015-07-18 01:39 - 2010-12-28 00:15 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Elaborate Bytes
2015-07-18 01:39 - 2010-12-27 13:16 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Yellow Tools Independence Pro 2.5
2015-07-18 01:39 - 2010-12-26 23:44 - 00000000 ____D C:\Users\music\Documents\Steinberg
2015-07-18 01:39 - 2010-12-25 23:10 - 00000000 ____D C:\ProgramData\Yellow Tools
2015-07-18 01:39 - 2010-12-25 22:42 - 00000000 ____D C:\ProgramData\TC Electronic
2015-07-18 01:39 - 2010-12-25 22:42 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TC Electronic
2015-07-18 01:39 - 2010-12-25 22:39 - 00000000 ____D C:\ProgramData\Universal Audio
2015-07-18 01:39 - 2010-12-25 22:13 - 00000000 ____D C:\Program Files\DIFX
2015-07-18 01:39 - 2010-12-25 22:02 - 00000000 ____D C:\ProgramData\VST3 Presets
2015-07-18 01:39 - 2010-12-25 21:37 - 00000000 ____D C:\Users\music\Documents\VST3 Presets
2015-07-18 01:39 - 2010-12-25 21:35 - 00000000 ____D C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eLicenser
2015-07-18 01:39 - 2010-12-25 21:35 - 00000000 ____D C:\ProgramData\eLicenser
2015-07-18 01:39 - 2010-12-25 21:33 - 00000000 ____D C:\ProgramData\Adobe
2015-07-18 01:39 - 2010-12-25 21:31 - 00000000 ____D C:\ProgramData\McAfee
2015-07-18 01:39 - 2010-12-25 21:28 - 00000000 ____D C:\ProgramData\Syncrosoft
2015-07-18 01:39 - 2010-12-25 21:17 - 00000000 ____D C:\ProgramData\Steinberg
2015-07-18 01:39 - 2010-12-25 21:17 - 00000000 ____D C:\Program Files\Steinberg
2015-07-18 01:39 - 2010-12-25 21:17 - 00000000 ____D C:\Program Files\Common Files\Steinberg
2015-07-18 01:39 - 2010-12-25 21:14 - 00000000 ____D C:\ProgramData\Applications
2015-07-18 01:39 - 2010-12-25 11:04 - 00000000 ____D C:\ProgramData\Google
2015-07-18 01:39 - 2010-12-25 11:04 - 00000000 ____D C:\Program Files\Google
2015-07-18 01:39 - 2010-12-25 10:54 - 00000000 ____D C:\ProgramData\Matrox
2015-07-18 01:39 - 2010-12-25 10:53 - 00000000 ____D C:\mgafold
2015-07-18 01:39 - 2010-12-25 10:28 - 00000000 __SHD C:\Recovery
2015-07-18 01:39 - 2009-07-14 13:07 - 00000000 ____D C:\Program Files\Windows Journal
2015-07-18 01:39 - 2009-07-14 13:06 - 00000000 __RHD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tablet PC
2015-07-18 01:39 - 2009-07-14 13:06 - 00000000 ___RD C:\Users\Public\Recorded TV
2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Sidebar
2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Portable Devices
2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Photo Viewer
2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Windows Defender
2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\Reference Assemblies
2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\MSBuild
2015-07-18 01:39 - 2009-07-14 07:32 - 00000000 ____D C:\Program Files\DVD Maker
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Public\Libraries
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 __RHD C:\Users\Default
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ___RD C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ___RD C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maintenance
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ___RD C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Windows NT
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\System
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\SpeechEngines
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Services
2015-07-18 01:39 - 2009-07-14 05:20 - 00000000 ____D C:\Program Files\Common Files\Microsoft Shared
2015-07-18 00:47 - 2013-06-21 11:07 - 00000000 ____D C:\Users\music\AppData\Roaming\File Scout
2015-07-18 00:14 - 2011-07-31 18:38 - 00000000 ____D C:\Windows\windupdate
2015-07-17 23:02 - 2010-12-25 11:04 - 00004106 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2015-07-17 23:02 - 2010-12-25 11:04 - 00003854 _____ C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2015-07-17 22:53 - 2015-02-14 02:09 - 00954190 _____ C:\Users\music\Desktop\tyros5_en_dl_c0.pdf.zzz
2015-07-17 22:53 - 2012-08-08 00:20 - 00655630 _____ C:\Users\music\Desktop\TYROS4_VoiceList.pdf.zzz
2015-07-17 22:53 - 2011-08-24 20:29 - 00036782 _____ C:\Users\music\Documents\Schatzifoto-MP.doc.zzz
2015-07-17 22:53 - 2011-01-18 16:39 - 01343102 _____ C:\Users\music\Desktop\Marvell9123_Controller_1001036-WHQL.zip.zzz
2015-07-17 22:38 - 2013-03-26 21:33 - 00778416 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2015-07-17 22:38 - 2013-03-26 21:33 - 00142512 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2015-07-11 00:24 - 2013-08-21 00:56 - 00000320 _____ C:\Windows\wcx_ftp.ini
2015-07-10 22:50 - 2010-12-28 13:48 - 00000000 ____D C:\Users\music\AppData\Roaming\vlc
2015-07-10 10:41 - 2013-08-27 17:18 - 00000132 _____ C:\Users\music\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
2015-07-09 23:49 - 2012-08-04 23:31 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service
2015-07-09 23:47 - 2010-12-25 13:46 - 00000000 ____D C:\Program Files (x86)\Mozilla Firefox
2015-07-09 12:44 - 2015-03-17 18:08 - 00000000 ____D C:\Users\music\AppData\Local\Cheba
2015-06-27 12:13 - 2015-02-11 16:24 - 00000000 ____D C:\Program Files (x86)\DVDVideoSoft
2015-06-27 12:13 - 2013-06-04 14:23 - 00000000 ____D C:\Users\music\AppData\Roaming\DVDVideoSoft
2015-06-27 12:02 - 2009-07-14 07:08 - 00032640 _____ C:\Windows\Tasks\SCHEDLGU.TXT
==================== Files in the root of some directories =======
2013-08-20 12:48 - 2013-08-27 22:11 - 0000132 _____ () C:\Users\music\AppData\Roaming\Adobe CS6-GIF-Format - Voreinstellungen
2013-08-27 17:18 - 2015-07-10 10:41 - 0000132 _____ () C:\Users\music\AppData\Roaming\Adobe CS6-PNG-Format - Voreinstellungen
2010-12-26 14:24 - 2012-12-17 01:33 - 0000383 _____ () C:\Users\music\AppData\Roaming\MOTU CueMix Prefs.prefs
2013-08-22 15:08 - 2013-08-28 00:10 - 0001456 _____ () C:\Users\music\AppData\Local\Adobe Für Web speichern 13.0 Prefs
2015-07-17 22:52 - 2015-07-17 22:52 - 0031744 _____ () C:\Users\music\AppData\Local\hncvavd.dll
2010-12-25 17:46 - 2010-12-25 17:46 - 0000017 _____ () C:\Users\music\AppData\Local\resmon.resmoncfg
Some files in TEMP:
====================
C:\Users\music\AppData\Local\Temp\AMPing.exe
C:\Users\music\AppData\Local\Temp\FreeYouTubeDownload.exe
C:\Users\music\AppData\Local\Temp\InstallManager_BAB_BAB.exe
C:\Users\music\AppData\Local\Temp\rad0B252.tmp.exe
C:\Users\music\AppData\Local\Temp\ReimagePackage.exe
==================== Bamital & volsnap Check =================
(There is no automatic fix for files that do not pass verification.)
C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed
LastRegBack: 2015-07-09 17:03
==================== End of log ============================
FRST Additions Logfile: Code:
ATTFilter Additional FRST Logfile: |
| | #4 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Der Rechner ist immer noch total verseucht. Fraglich ob sich die Dateien entschlüsseln lassen. Ich hab das mal weitergeleitet, ich melde mich wieder.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #5 |
| | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Danke nochmals für Deine Mühe. Wir kennen uns nicht und trotzdem nimmst Du Dir die Zeit -> DANKESCHÖN! Wie schon erwähnt, habe ich die FP C: u. D: gewechselt und danach die Sicherungen eingespielt. Damit habe ich noch die beiden verseuchten Platten zur Analyse und hoffentlich zum Wiederherstellen zur Verfügung. Vor allem die nicht mehr lesbaren Dateien auf D: (jpg, xls, docx) bereiten mir Kopfschmerzen. C: ist mir eigentlich nicht so wichtig. Leider konnte ich mit FRST meine D: Platte nicht scannen. Ich glaube das Tool funktioniert nur immer auf der Systemplatte. Viele liebe Grüße, Oliver ![]() ![]() |
| | #6 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Ja das scannt nur Systemplatte. Also ist der Scan jetzt von der alten Platte? Rechner ansich hat frische Platten und frische Daten, also kein Handlungsbedarf in Sachen Malwareentfernung?
__________________ --> All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx |
| | #7 |
| | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Hallo! JA der Scan ist natürlich von der alten Platte! Kein Handlungsbedarf in Sachen Malwareentfernung. Aber sehr großer Handlungsbedarf in unprodected meiner Files von der D: Platte. wo ich auch zwei protected Files als Bsp. 'upgeloaded' habe. Wäre sehr schlimm, wenn es dazu keine Lösung geben würde. DANKESCHÖN! Oliver |
| | #8 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Sieht schlecht aus, aber ist in Arbeit. Das ist übringens kein Cryptowall, sondern die neueste Version von Teslacrypt. Du kannst auf eigene Gefahr den alten Decoder, für die alten Versionen, versuchen. Aber im schlimmsten Fall kann der das nicht und löscht gleichzeitig noch die Key-Dateien auf dem Rechner, dann geht gar nix mehr.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
| | #9 |
| | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx Na toll! Gleich den 'Schlimmsten' erwischt....! Ich glaube die Key Dateien sind schon weg. ICh habe schon versucht mit verschiedenen Recover Tools diese Datein zu finden. Keine Chance. Ich weiß nicht wohin die verschwunden sind. Ich habe nie auf die FP geschrieben sondern nur gelesen. Aber die Key Daten, die für jede Datei angelegt wurden, habe ich in meiner Not mit shift Del gelöscht. Schon einen Tag später wollte ich die gelöschten Daten wieder recovern. Bisher keinen Erfolg, obwohl ich nie, wie schon erwähnt, auf die FP geschrieben habe. Jedenfalls DANKE für Deine Hilfe! |
| | #10 |
| /// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx TeslaDecoder released to decrypt .EXX, .EZZ, .ECC files encrypted by TeslaCrypt - Page 8 - News Lies mal dieses Thema, den dortigen Decoder kannste versuchen, ist aber für die alte Version.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() |
| Themen zu All of your files were protected by a strong encryption with RSA-2048 using CryptoWall 3.0. -> *.xxx |
| *.zzz, aktiv, avira, cryptowall3.0, daten, email, erstellt, festplatte, festplatten, files, funktionieren, helper, internet, jpg, mp3, mprrq, neu, pdf, recovery, regeln, rsa-2048, tckwp, tools, trojaner, updates, version, verändert, win, win7, zugang |