![]() |
|
Plagegeister aller Art und deren Bekämpfung: SystemTool 2011 - und nun?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #7 |
![]() | ![]() SystemTool 2011 - und nun? All processes killed ========== OTL ========== Registry value HKEY_USERS\S-1-5-21-4048956899-1286244931-2967521482-1000\Software\Microsoft\Windows\CurrentVersion\RunOnce\\eFjBp01804 deleted successfully. C:\ProgramData\eFjBp01804\eFjBp01804.exe moved successfully. C:\ProgramData\WindowsSearch\MiniDumps folder moved successfully. C:\ProgramData\WindowsSearch folder moved successfully. C:\Users\Brandon\AppData\Roaming\Spyware Terminator\Reports folder moved successfully. C:\Users\Brandon\AppData\Roaming\Spyware Terminator\LanguageAct folder moved successfully. C:\Users\Brandon\AppData\Roaming\Spyware Terminator folder moved successfully. C:\Users\Brandon\AppData\Roaming\skypePM folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_httpfe folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\skypehome\i\production folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\skypehome\i\languages folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\skypehome\i\images\fancybox folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\skypehome\i\images\buttons folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\skypehome\i\images\avatarview folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\skypehome\i\images folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\skypehome\i folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\skypehome folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\pcj\i\js\languages folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\pcj\i\js folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\pcj\i\images\promotions folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\pcj\i\images\buttons folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\pcj\i\images\backgrounds folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\pcj\i\images folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\pcj\i\css folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\pcj\i folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\pcj\assets\promotions folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\pcj\assets folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html\pcj folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_html folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\shared_dynco folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\My Skype Received Files folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\graardor2\voicemail folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\graardor2\httpfe folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\graardor2\chatsync\ff folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\graardor2\chatsync\fe folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\graardor2\chatsync\dc folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\graardor2\chatsync\61 folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\graardor2\chatsync\3e folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\graardor2\chatsync folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype\graardor2 folder moved successfully. C:\Users\Brandon\AppData\Roaming\Skype folder moved successfully. C:\Users\Brandon\AppData\Roaming\Mozilla\Firefox\Profiles\wb3p44e5.default\minidumps folder moved successfully. C:\Users\Brandon\AppData\Roaming\Mozilla\Firefox\Profiles\wb3p44e5.default\extensions folder moved successfully. C:\Users\Brandon\AppData\Roaming\Mozilla\Firefox\Profiles\wb3p44e5.default\chrome folder moved successfully. C:\Users\Brandon\AppData\Roaming\Mozilla\Firefox\Profiles\wb3p44e5.default\bookmarkbackups folder moved successfully. C:\Users\Brandon\AppData\Roaming\Mozilla\Firefox\Profiles\wb3p44e5.default folder moved successfully. C:\Users\Brandon\AppData\Roaming\Mozilla\Firefox\Profiles folder moved successfully. C:\Users\Brandon\AppData\Roaming\Mozilla\Firefox\Crash Reports folder moved successfully. C:\Users\Brandon\AppData\Roaming\Mozilla\Firefox folder moved successfully. C:\Users\Brandon\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384} folder moved successfully. C:\Users\Brandon\AppData\Roaming\Mozilla\Extensions folder moved successfully. C:\Users\Brandon\AppData\Roaming\Mozilla folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Word\STARTUP folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Word folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Templates folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Tool folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Fujitsu Siemens Computers folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\CyberLink PowerDVD folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\System Tools folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu\Programme folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Start Menu folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\SendTo folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Recent folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Printer Shortcuts folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Network Shortcuts folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Cookies\Low folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows\Cookies folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Windows folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\UProof folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Templates folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\SystemCertificates\My\CTLs folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\SystemCertificates\My\CRLs folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\SystemCertificates\My\Certificates folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\SystemCertificates\My folder moved successfully. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\SystemCertificates scheduled to be moved on reboot. C:\Users\Brandon\AppData\Roaming\Microsoft\Protect\S-1-5-21-4048956899-1286244931-2967521482-1000 folder moved successfully. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\Protect scheduled to be moved on reboot. C:\Users\Brandon\AppData\Roaming\Microsoft\Proof folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Outlook folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Office\Recent folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Office folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Internet Explorer folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Installer\{9A3BC157-B94F-4EFD-ABA9-1E56DEB00655} folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Installer folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Document Building Blocks\1031 folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Document Building Blocks folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-4048956899-1286244931-2967521482-1000 folder moved successfully. C:\Users\Brandon\AppData\Roaming\Microsoft\Crypto\RSA folder moved successfully. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\Crypto scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\Credentials scheduled to be moved on reboot. C:\Users\Brandon\AppData\Roaming\Microsoft\AddIns folder moved successfully. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft scheduled to be moved on reboot. C:\Users\Brandon\AppData\Roaming\Media Center Programs folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#www.daredorm.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#s.ytimg.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#mpsnare.iesnare.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#members.livejasmin.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#img.livejasmin.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#img.6waves.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#freeporn.youngleafs.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#chatango.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#cdnbakmi.kaltura.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\macromedia.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\www.daredorm.com\swf\flowplayer\flowplayer.commercial-3.1.1.swf folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\www.daredorm.com\swf\flowplayer folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\www.daredorm.com\swf folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\www.daredorm.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\skype.com\#user folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\skype.com\#ui folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\skype.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\s.ytimg.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\mpsnare.iesnare.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\img.6waves.com\create-my-app\save_banana\game.swf folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\img.6waves.com\create-my-app\save_banana folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\img.6waves.com\create-my-app folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\img.6waves.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\freeporn.youngleafs.com\#kernelteam folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\freeporn.youngleafs.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\chatango.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\cdnbakmi.kaltura.com\p\192572\sp\19257200\flash\kdp3\v3.4.10.1\kdp3.swf folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\cdnbakmi.kaltura.com\p\192572\sp\19257200\flash\kdp3\v3.4.10.1 folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\cdnbakmi.kaltura.com\p\192572\sp\19257200\flash\kdp3 folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\cdnbakmi.kaltura.com\p\192572\sp\19257200\flash folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\cdnbakmi.kaltura.com\p\192572\sp\19257200 folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\cdnbakmi.kaltura.com\p\192572\sp folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\cdnbakmi.kaltura.com\p\192572 folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\cdnbakmi.kaltura.com\p folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW\cdnbakmi.kaltura.com folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects\AF6AGCNW folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player\#SharedObjects folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia\Flash Player folder moved successfully. C:\Users\Brandon\AppData\Roaming\Macromedia folder moved successfully. C:\Users\Brandon\AppData\Roaming\Identities\{E339429E-95C8-4122-ABCE-3B45431A0279} folder moved successfully. C:\Users\Brandon\AppData\Roaming\Identities folder moved successfully. C:\Users\Brandon\AppData\Roaming\ATI\ACE folder moved successfully. C:\Users\Brandon\AppData\Roaming\ATI folder moved successfully. C:\Users\Brandon\AppData\Roaming\Adobe\Flash Player\AssetCache\36AXTJXZ folder moved successfully. C:\Users\Brandon\AppData\Roaming\Adobe\Flash Player\AssetCache folder moved successfully. C:\Users\Brandon\AppData\Roaming\Adobe\Flash Player folder moved successfully. C:\Users\Brandon\AppData\Roaming\Adobe folder moved successfully. Folder move failed. C:\Users\Brandon\AppData\Roaming scheduled to be moved on reboot. Folder C:\ProgramData\eFjBp01804\ not found. C:\Users\Brandon\Desktop\System Tool 2011.lnk moved successfully. ========== FILES ========== ========== COMMANDS ========== [EMPTYFLASH] User: All Users User: Brandon User: Default User: Default User User: Public Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: All Users User: Brandon ->Temp folder emptied: 64549594 bytes ->Temporary Internet Files folder emptied: 42348258 bytes ->FireFox cache emptied: 85994028 bytes ->Google Chrome cache emptied: 6353877 bytes User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 118238874 bytes RecycleBin emptied: 36331389 bytes Total Files Cleaned = 337,00 mb OTL by OldTimer - Version 3.2.20.1 log created on 01092011_201324 Files\Folders moved on Reboot... Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\SystemCertificates scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\Protect scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\Crypto scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\Credentials scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\SystemCertificates scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\Protect scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\Crypto scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\Credentials scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\SystemCertificates scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\Protect scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\Crypto scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft\Credentials scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming\Microsoft scheduled to be moved on reboot. Folder move failed. C:\Users\Brandon\AppData\Roaming scheduled to be moved on reboot. Registry entries deleted on Reboot... Den Rest muss ich mir noch einmal ansehen - was ich da jetzt machen muss... |
Themen zu SystemTool 2011 - und nun? |
abgesicherte, abgesicherten, arbeiten, chip, entfernung, erkennt, firmen, freeware, gefunde, heute, installier, installiert, kamera, komischer, komischer virus, malware, nichts, probiert, programme, stunde, system, systemtools, vermutet, verschiedene, verzweifel, virus, web |