![]() |
|
Plagegeister aller Art und deren Bekämpfung: Critical Error RAM memory usage .. HDD ... "Scanner" öffnet sich dauerndWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
| ![]() Critical Error RAM memory usage .. HDD ... "Scanner" öffnet sich dauernd Hier die text Datei ![]() All processes killed ========== OTL ========== No active process named login.exe was found! No active process named win16.exe was found! No active process named user.exe was found! No active process named debug.exe was found! No active process named 3557571.exe was found! No active process named w9czhv522y.exe was found! No active process named drweb.exe was found! No active process named win32.exe was found! No active process named lsass.exe was found! No active process named taskmgr.exe was found! No active process named hrds2.exe was found! No active process named idemoodp0cetka.exe was found! Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\LvtqZkfgoec deleted successfully. C:\Users\pyrooo\AppData\Local\Temp\hrds2.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\LvtqZkfgprc deleted successfully. C:\Users\pyrooo\AppData\Local\Temp\login.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\LvtqZkfgpuc deleted successfully. C:\Users\pyrooo\AppData\Local\Temp\lsass.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\LvtqZkfgsfDh deleted successfully. C:\Users\pyrooo\AppData\Local\Temp\w9czhv522y.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\LvtqZkfgsPc deleted successfully. C:\Users\pyrooo\AppData\Local\Temp\win32.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Mqqoc deleted successfully. C:\Windows\debug.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Mqqsc deleted successfully. C:\Windows\drweb.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Mque deleted successfully. C:\Windows\user.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Mqurb deleted successfully. C:\Windows\taskmgr.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\MqvPc deleted successfully. C:\Windows\win16.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\uPc+nuvfeefnThaGuo deleted successfully. C:\Users\pyrooo\AppData\Local\Temp\q90rj9um.DLL moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\uPc+nuvfeefnvFaXms deleted successfully. C:\Users\pyrooo\AppData\Local\Temp\stta76y.DLL moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ElkTBhTOiqUEWYN.exe deleted successfully. C:\Users\pyrooo\AppData\Local\Temp\ElkTBhTOiqUEWYN.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\LvtqZkfgoec deleted successfully. File C:\Users\pyrooo\AppData\Local\Temp\hrds2.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\LvtqZkfgprc deleted successfully. File C:\Users\pyrooo\AppData\Local\Temp\login.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\LvtqZkfgpuc deleted successfully. File C:\Users\pyrooo\AppData\Local\Temp\lsass.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\LvtqZkfgsfDh deleted successfully. File C:\Users\pyrooo\AppData\Local\Temp\w9czhv522y.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\LvtqZkfgsPc deleted successfully. File C:\Users\pyrooo\AppData\Local\Temp\win32.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Mqqoc deleted successfully. File C:\Windows\debug.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Mqqsc deleted successfully. File C:\Windows\drweb.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Mque deleted successfully. File C:\Windows\user.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Mqurb deleted successfully. File C:\Windows\taskmgr.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MqvPc deleted successfully. File C:\Windows\win16.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\MS Service Manager deleted successfully. C:\Users\pyrooo\AppData\Local\Temp\idemoodp0cetka.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\portwexexe.exe deleted successfully. C:\portwexexe.exe\portwexexe.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uPc+nuvfeefnThaGuo deleted successfully. File C:\Users\pyrooo\AppData\Local\Temp\q90rj9um.DLL not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\uPc+nuvfeefnvFaXms deleted successfully. File C:\Users\pyrooo\AppData\Local\Temp\stta76y.DLL not found. C:\Users\pyrooo\secupdat.dat moved successfully. ========== FILES ========== ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: AppData User: Default User: Default User User: Public User: pyrooo ->Flash cache emptied: 2814439 bytes Total Flash Files Cleaned = 3,00 mb [EMPTYTEMP] User: All Users User: AppData User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: pyrooo ->Temp folder emptied: 435312985 bytes ->Temporary Internet Files folder emptied: 36155566 bytes ->Java cache emptied: 3625214 bytes ->FireFox cache emptied: 56901031 bytes ->Apple Safari cache emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 14113 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 30707584 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50300 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 537,00 mb OTL by OldTimer - Version 3.2.18.0 log created on 12282010_222901 Files\Folders moved on Reboot... C:\Users\pyrooo\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Windows\temp\mcafee_dVDzy1CFj8av1eB not found! File\Folder C:\Windows\temp\mcafee_VejYUk4JfBtBgMs not found! File\Folder C:\Windows\temp\sqlite_8S9KgTJD3N6sLWt not found! File\Folder C:\Windows\temp\sqlite_NaWzhjav4DXmzST not found! Registry entries deleted on Reboot... |
![]() |
Themen zu Critical Error RAM memory usage .. HDD ... "Scanner" öffnet sich dauernd |
64-bit, adobe, autorun, bho, bonjour, c:\windows\system32\rundll32.exe, conduit, defender, ebay, error, excel, firefox.exe, flash player, format, google, home, home premium, iastor.sys, ieframe.dll, install.exe, launch, location, locker, logfile, microsoft office word, monitor.exe, mozilla, mywinlocker, office 2007, oldtimer, otl.exe, plug-in, portwexexe.exe, problem, programdata, programm, realtek, registry, richtlinie, rundll, saver, scan, searchplugins, security, security update, shell32.dll, shortcut, siteadvisor, software, symantec, syswow64, usb 2.0, usbaapl64, webcheck, windows, windows live mesh |