![]() |
|
Plagegeister aller Art und deren Bekämpfung: Update~1.exeWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #5 |
![]() | ![]() Update~1.exe habe die GMER aufm lapi gespeichert...wie lade ich die hier hoch.... GMER Logfile: Code:
ATTFilter GMER 2.2.19882 - GMER - Rootkit Detector and Remover Rootkit scan 2016-11-12 17:09:32 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD2500BEVT-24A23T0 rev.01.01A02 232,89GB Running: gmer-2.2.19882.exe; Driver: C:\Users\Yep\AppData\Local\Temp\uwldrpow.sys ---- System - GMER 2.2 ---- SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwAdjustPrivilegesToken [0x895410A0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwAlpcConnectPort [0x89541020] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwAlpcSendWaitReceivePort [0x89541030] SSDT \SystemRoot\system3c2\DRIVERS\klhk.sys ZwClose [0x895410C0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwConnectPort [0x89541050] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwCreateSection [0x89541000] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwCreateSymbolicLinkObject [0x895411B0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwCreateThread [0x89541110] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwCreateThreadEx [0x89541040] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwDebugActiveProcess [0x89541150] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwDeviceIoControlFile [0x89541200] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwDuplicateObject [0x89541180] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwLoadDriver [0x89541160] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwMapViewOfSection [0x89541190] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwOpenProcess [0x89541080] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwOpenSection [0x89541070] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwOpenThread [0x89541090] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwPlugPlayControl [0x895411C0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwProtectVirtualMemory [0x895410D0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwQueryIntervalProfile [0x89541490] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwQueueApcThread [0x89541130] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwRequestWaitReplyPort [0x895411F0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwResumeProcess [0x895414B0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwResumeThread [0x895411D0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSecureConnectPort [0x89541060] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSetContextThread [0x89541120] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSetInformationObject [0x895410B0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSetInformationToken [0x89541010] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSetSystemInformation [0x89541170] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSuspendProcess [0x895411E0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSystemDebugControl [0x89541140] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwTerminateProcess [0x895410E0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwTerminateThread [0x895410F0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwUnmapViewOfSection [0x895411A0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwWriteVirtualMemory [0x89541100] ---- Kernel code sections - GMER 2.2 ---- .text ntkrnlpa.exe!ZwRenameKey + 1549 82A89F05 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AC4292 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntkrnlpa.exe!KeRemoveQueueEx + 10D7 82ACB69C 4 Bytes [A0, 10, 54, 89] .text ntkrnlpa.exe!KeRemoveQueueEx + 10FF 82ACB6C4 4 Bytes [20, 10, 54, 89] .text ntkrnlpa.exe!KeRemoveQueueEx + 1143 82ACB708 4 Bytes [30, 10, 54, 89] .text ntkrnlpa.exe!KeRemoveQueueEx + 116F 82ACB734 4 Bytes [C0, 10, 54, 89] .text ntkrnlpa.exe!KeRemoveQueueEx + 1193 82ACB758 4 Bytes [50, 10, 54, 89] .text ... .text C:\Windows\system32\DRIVERS\klif.sys section is writeable [0x8FAA2000, 0x144, 0xC8000040] ---- User code sections - GMER 2.2 ---- ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] C:\Windows\SYSTEM32\ntdll.dll time/date stamp mismatch; .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] ntdll.dll!NtProtectVirtualMemory 77985AE0 5 Bytes JMP 71952AD0 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] C:\Windows\system32\kernel32.dll time/date stamp mismatch; unknown module: webio.dllunknown module: KERNELBASE.dll ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] C:\Windows\system32\ADVAPI32.dll time/date stamp mismatch; unknown module: CRYPTSP.dllunknown module: WINTRUST.dllunknown module: SspiCli.dllunknown module: bcrypt.dllunknown module: pcwum.dllunknown module: KERNELBASE.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] USER32.dll!NotifyWinEvent + 5B2 7629D540 4 Bytes [30, 40, 95, 71] .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] USER32.dll!NotifyWinEvent + 6AE 7629D63C 4 Bytes [E0, 3F, 95, 71] ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] C:\Windows\system32\ole32.dll time/date stamp mismatch; unknown module: CRYPTSP.dllunknown module: MPR.dllunknown module: msiltcfg.dllunknown module: CLBCatQ.DLLunknown module: OLEAUT32.dllunknown module: imagehlp.dllunknown module: KERNELBASE.dll ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] C:\Windows\system32\kernel32.dll time/date stamp mismatch; unknown module: webio.dllunknown module: KERNELBASE.dll ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] C:\Windows\system32\USER32.dll time/date stamp mismatch; unknown module: CFGMGR32.dllunknown module: MSIMG32.dllunknown module: POWRPROF.dllunknown module: WINSTA.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!LockWindowStation + 1BE 76284948 5 Bytes JMP 71954B60 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!GetUserObjectInformationA + 82B 762879D7 5 Bytes JMP 71955020 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!NotifyWinEvent + 5B2 7629D540 4 Bytes [30, 40, 95, 71] .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!NotifyWinEvent + 6AE 7629D63C 4 Bytes [E0, 3F, 95, 71] .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!SetWindowsHookExA + 21 762B6CFD 5 Bytes JMP 71954F90 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!SendMessageTimeoutA + 2A 762B6DA3 5 Bytes JMP 71954AD0 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!GetRawInputDeviceInfoW + 10 762CCA8E 5 Bytes JMP 71954DC0 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!GetRawInputDeviceInfoA + E7 762E3CF8 5 Bytes JMP 71954D30 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll ---- Devices - GMER 2.2 ---- AttachedDevice \Driver\tdx \Device\Tcp kltdi.sys AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 klbackupdisk.sys AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 klbackupdisk.sys AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 klbackupdisk.sys AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 klbackupdisk.sys Device \Driver\BTHUSB \Device\00000080 bthport.sys Device \Driver\BTHUSB \Device\00000082 bthport.sys AttachedDevice \Driver\tdx \Device\Udp kltdi.sys AttachedDevice \Driver\tdx \Device\RawIp kltdi.sys ---- Registry - GMER 2.2 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f07bcbbd7c0a Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f07bcbbd7c0a (not active ControlSet) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CIT\System\Active Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CIT\System\Active@93E0574A 340 ---- EOF - GMER 2.2 ---- GMER Logfile: Code:
ATTFilter GMER 2.2.19882 - hxxp://www.gmer.net Rootkit scan 2016-11-12 17:09:32 Windows 6.1.7601 Service Pack 1 \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP0T0L0-0 WDC_WD2500BEVT-24A23T0 rev.01.01A02 232,89GB Running: gmer-2.2.19882.exe; Driver: C:\Users\Yep\AppData\Local\Temp\uwldrpow.sys ---- System - GMER 2.2 ---- SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwAdjustPrivilegesToken [0x895410A0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwAlpcConnectPort [0x89541020] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwAlpcSendWaitReceivePort [0x89541030] SSDT \SystemRoot\system3c2\DRIVERS\klhk.sys ZwClose [0x895410C0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwConnectPort [0x89541050] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwCreateSection [0x89541000] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwCreateSymbolicLinkObject [0x895411B0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwCreateThread [0x89541110] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwCreateThreadEx [0x89541040] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwDebugActiveProcess [0x89541150] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwDeviceIoControlFile [0x89541200] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwDuplicateObject [0x89541180] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwLoadDriver [0x89541160] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwMapViewOfSection [0x89541190] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwOpenProcess [0x89541080] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwOpenSection [0x89541070] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwOpenThread [0x89541090] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwPlugPlayControl [0x895411C0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwProtectVirtualMemory [0x895410D0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwQueryIntervalProfile [0x89541490] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwQueueApcThread [0x89541130] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwRequestWaitReplyPort [0x895411F0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwResumeProcess [0x895414B0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwResumeThread [0x895411D0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSecureConnectPort [0x89541060] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSetContextThread [0x89541120] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSetInformationObject [0x895410B0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSetInformationToken [0x89541010] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSetSystemInformation [0x89541170] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSuspendProcess [0x895411E0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwSystemDebugControl [0x89541140] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwTerminateProcess [0x895410E0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwTerminateThread [0x895410F0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwUnmapViewOfSection [0x895411A0] SSDT \SystemRoot\system32\DRIVERS\klhk.sys ZwWriteVirtualMemory [0x89541100] ---- Kernel code sections - GMER 2.2 ---- .text ntkrnlpa.exe!ZwRenameKey + 1549 82A89F05 1 Byte [06] .text ntkrnlpa.exe!KiDispatchInterrupt + 5A2 82AC4292 19 Bytes [E0, 0F, BA, F0, 07, 73, 09, ...] {LOOPNZ 0x11; MOV EDX, 0x97307f0; MOV CR4, EAX; OR AL, 0x80; MOV CR4, EAX; RET ; MOV ECX, CR3} .text ntkrnlpa.exe!KeRemoveQueueEx + 10D7 82ACB69C 4 Bytes [A0, 10, 54, 89] .text ntkrnlpa.exe!KeRemoveQueueEx + 10FF 82ACB6C4 4 Bytes [20, 10, 54, 89] .text ntkrnlpa.exe!KeRemoveQueueEx + 1143 82ACB708 4 Bytes [30, 10, 54, 89] .text ntkrnlpa.exe!KeRemoveQueueEx + 116F 82ACB734 4 Bytes [C0, 10, 54, 89] .text ntkrnlpa.exe!KeRemoveQueueEx + 1193 82ACB758 4 Bytes [50, 10, 54, 89] .text ... .text C:\Windows\system32\DRIVERS\klif.sys section is writeable [0x8FAA2000, 0x144, 0xC8000040] ---- User code sections - GMER 2.2 ---- ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] C:\Windows\SYSTEM32\ntdll.dll time/date stamp mismatch; .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] ntdll.dll!NtProtectVirtualMemory 77985AE0 5 Bytes JMP 71952AD0 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] C:\Windows\system32\kernel32.dll time/date stamp mismatch; unknown module: webio.dllunknown module: KERNELBASE.dll ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] C:\Windows\system32\ADVAPI32.dll time/date stamp mismatch; unknown module: CRYPTSP.dllunknown module: WINTRUST.dllunknown module: SspiCli.dllunknown module: bcrypt.dllunknown module: pcwum.dllunknown module: KERNELBASE.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] USER32.dll!NotifyWinEvent + 5B2 7629D540 4 Bytes [30, 40, 95, 71] .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] USER32.dll!NotifyWinEvent + 6AE 7629D63C 4 Bytes [E0, 3F, 95, 71] ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avp.exe[1632] C:\Windows\system32\ole32.dll time/date stamp mismatch; unknown module: CRYPTSP.dllunknown module: MPR.dllunknown module: msiltcfg.dllunknown module: CLBCatQ.DLLunknown module: OLEAUT32.dllunknown module: imagehlp.dllunknown module: KERNELBASE.dll ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] C:\Windows\system32\kernel32.dll time/date stamp mismatch; unknown module: webio.dllunknown module: KERNELBASE.dll ? C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] C:\Windows\system32\USER32.dll time/date stamp mismatch; unknown module: CFGMGR32.dllunknown module: MSIMG32.dllunknown module: POWRPROF.dllunknown module: WINSTA.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!LockWindowStation + 1BE 76284948 5 Bytes JMP 71954B60 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!GetUserObjectInformationA + 82B 762879D7 5 Bytes JMP 71955020 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!NotifyWinEvent + 5B2 7629D540 4 Bytes [30, 40, 95, 71] .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!NotifyWinEvent + 6AE 7629D63C 4 Bytes [E0, 3F, 95, 71] .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!SetWindowsHookExA + 21 762B6CFD 5 Bytes JMP 71954F90 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!SendMessageTimeoutA + 2A 762B6DA3 5 Bytes JMP 71954AD0 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!GetRawInputDeviceInfoW + 10 762CCA8E 5 Bytes JMP 71954DC0 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll .text C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\avpui.exe[3112] USER32.dll!GetRawInputDeviceInfoA + E7 762E3CF8 5 Bytes JMP 71954D30 C:\Program Files\Kaspersky Lab\Kaspersky Internet Security 16.0.1\ushata.dll ---- Devices - GMER 2.2 ---- AttachedDevice \Driver\tdx \Device\Tcp kltdi.sys AttachedDevice \Driver\volmgr \Device\HarddiskVolume1 klbackupdisk.sys AttachedDevice \Driver\volmgr \Device\HarddiskVolume2 klbackupdisk.sys AttachedDevice \Driver\volmgr \Device\HarddiskVolume3 klbackupdisk.sys AttachedDevice \Driver\volmgr \Device\HarddiskVolume4 klbackupdisk.sys Device \Driver\BTHUSB \Device\00000080 bthport.sys Device \Driver\BTHUSB \Device\00000082 bthport.sys AttachedDevice \Driver\tdx \Device\Udp kltdi.sys AttachedDevice \Driver\tdx \Device\RawIp kltdi.sys ---- Registry - GMER 2.2 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\f07bcbbd7c0a Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\f07bcbbd7c0a (not active ControlSet) Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CIT\System\Active Reg HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\CIT\System\Active@93E0574A 340 ---- EOF - GMER 2.2 ---- |
Themen zu Update~1.exe |
.exe, 1.exe, anwendung, frage, inter, interne, internet, internet security, kaspersky, minute, minuten, nicht, schild, security, tagen, unbekannt, update, virus, windows |