![]() |
Virus?liveupdate.exe dateien verschwinden Hallo Ihr Lieben, ich habe ein arges Problem welches mir gerad bisschen Sorgen macht und hoffe ihr könnt mir helfen :wtf: Schätzungsweise letzte Woche habe ich ganz normal im Netz gegoogled und auf einmal schlug AntiVir bei mir Alarm, es war schon eine Tortur die Fenster wieder zu schließen die sich mir auftaten... Laut Virenprogrammen hat sich wohl irgendwas an Liveupdate.exe eingeschlichen und dieses Etwas hat mir im System32 was angerichtet (habe nicht wirklich viel Plan davon) Ich poste mal die Funde von Antivir: Die Datei 'C:\Program Files\MyWebSearch\bar\2.bin\NPMYWEBS.DLL' enthielt einen Virus oder unerwünschtes Programm 'TR/Trash.Gen' [trojan Die Datei 'C:\Program Files\MyWebSearch\bar\2.bin\M3PLUGIN.DLL' enthielt einen Virus oder unerwünschtes Programm 'TR/Trash.Gen' [trojan]. In der Datei 'C:\Users\Krissy\AppData\Local\Mozilla\Firefox\Profiles\tx1u8grj.default\Cache\53FF5DCDd01' wurde ein Virus oder unerwünschtes Programm 'ADSPY/AdSpy.Gen2' [adware] gefunden. Ausgeführte Aktion: Zugriff erlauben (((Ich habe jdfls keinen Zugriff erlaubt, kann aber auch sein, dass jemand anderes an meinem Netbook war))) Die Datei 'C:\Users\Krissy\AppData\Local\Mozilla\Firefox\Profiles\tx1u8grj.default\Cache\53FF5DCDd01' enthielt einen Virus oder unerwünschtes Programm 'ADSPY/AdSpy.Gen2' [adware]. In der Datei 'C:\Users\Krissy\AppData\Local\Temp\InternetExplorerUpdate.exe' wurde ein Virus oder unerwünschtes Programm 'TR/Crypt.EPACK.Gen2' [trojan] gefunden. In der Datei 'C:\Users\Krissy\Downloads\VLCSetup.exe' wurde ein Virus oder unerwünschtes Programm 'ADSPY/AdSpy.Gen2' [adware] gefunden. Die Datei 'C:\Users\Krissy\Downloads\gamin16.rar' enthielt einen Virus oder unerwünschtes Programm 'TR/Patched.Gen' [trojan]. In der Datei 'C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL' wurde ein Virus oder unerwünschtes Programm 'TR/Drop.Softomat.AN' [trojan] gefunden Die Datei 'C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL' enthielt einen Virus oder unerwünschtes Programm 'TR/Drop.Softomat.AN' [trojan]. Durchgeführte Aktion(en): Beim Versuch eine Sicherungskopie der Datei anzulegen ist ein Fehler aufgetreten und die Datei wurde nicht gelöscht. Fehlernummer: 26003. Die Datei konnte nicht gelöscht werden! Es wird versucht die Aktion mit Hilfe der ARK Library durchzuführen. Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '516defff.qua' verschoben! Und tagelang kommt im 10-Minuten-Takt die Meldung: In der Datei 'C:\Program Files\MyWebSearch\bar\2.bin\MWSBAR.DLL' wurde ein Virus oder unerwünschtes Programm 'TR/Drop.Softomat.AN' [trojan] gefunden. Ausgeführte Aktion: Zugriff verweigern Die Reportdatei :stirn: Avira AntiVir Personal Erstellungsdatum der Reportdatei: Samstag, 9. April 2011 15:59 Es wird nach 2537417 Virenstämmen gesucht. Das Programm läuft als uneingeschränkte Vollversion. Online-Dienste stehen zur Verfügung. Lizenznehmer : Avira AntiVir Personal - FREE Antivirus Seriennummer : 0000149996-ADJIE-0000001 Plattform : Windows 7 Windowsversion : (plain) [6.1.7600] Boot Modus : Normal gebootet Benutzername : SYSTEM Computername : KRISSY-NETBOOK Versionsinformationen: BUILD.DAT : 10.0.0.635 31822 Bytes 07.03.2011 12:02:00 AVSCAN.EXE : 10.0.3.5 435368 Bytes 10.01.2011 13:22:56 AVSCAN.DLL : 10.0.3.0 56168 Bytes 10.01.2011 13:23:14 LUKE.DLL : 10.0.3.2 104296 Bytes 10.01.2011 13:23:03 LUKERES.DLL : 10.0.0.0 13672 Bytes 14.01.2010 10:59:47 VBASE000.VDF : 7.10.0.0 19875328 Bytes 06.11.2009 08:05:36 VBASE001.VDF : 7.11.0.0 13342208 Bytes 14.12.2010 13:23:11 VBASE002.VDF : 7.11.3.0 1950720 Bytes 09.02.2011 10:26:21 VBASE003.VDF : 7.11.5.225 1980416 Bytes 07.04.2011 19:28:46 VBASE004.VDF : 7.11.5.226 2048 Bytes 07.04.2011 19:28:46 VBASE005.VDF : 7.11.5.227 2048 Bytes 07.04.2011 19:28:46 VBASE006.VDF : 7.11.5.228 2048 Bytes 07.04.2011 19:28:46 VBASE007.VDF : 7.11.5.229 2048 Bytes 07.04.2011 19:28:47 VBASE008.VDF : 7.11.5.230 2048 Bytes 07.04.2011 19:28:47 VBASE009.VDF : 7.11.5.231 2048 Bytes 07.04.2011 19:28:47 VBASE010.VDF : 7.11.5.232 2048 Bytes 07.04.2011 19:28:47 VBASE011.VDF : 7.11.5.233 2048 Bytes 07.04.2011 19:28:47 VBASE012.VDF : 7.11.5.234 2048 Bytes 07.04.2011 19:28:48 VBASE013.VDF : 7.11.5.235 2048 Bytes 07.04.2011 19:28:48 VBASE014.VDF : 7.11.5.236 2048 Bytes 07.04.2011 19:28:48 VBASE015.VDF : 7.11.5.237 2048 Bytes 07.04.2011 19:28:48 VBASE016.VDF : 7.11.5.238 2048 Bytes 07.04.2011 19:28:48 VBASE017.VDF : 7.11.5.239 2048 Bytes 07.04.2011 19:28:48 VBASE018.VDF : 7.11.5.240 2048 Bytes 07.04.2011 19:28:49 VBASE019.VDF : 7.11.5.241 2048 Bytes 07.04.2011 19:28:49 VBASE020.VDF : 7.11.5.242 2048 Bytes 07.04.2011 19:28:49 VBASE021.VDF : 7.11.5.243 2048 Bytes 07.04.2011 19:28:49 VBASE022.VDF : 7.11.5.244 2048 Bytes 07.04.2011 19:28:49 VBASE023.VDF : 7.11.5.245 2048 Bytes 07.04.2011 19:28:49 VBASE024.VDF : 7.11.5.246 2048 Bytes 07.04.2011 19:28:50 VBASE025.VDF : 7.11.5.247 2048 Bytes 07.04.2011 19:28:50 VBASE026.VDF : 7.11.5.248 2048 Bytes 07.04.2011 19:28:50 VBASE027.VDF : 7.11.5.249 2048 Bytes 07.04.2011 19:28:50 VBASE028.VDF : 7.11.5.250 2048 Bytes 07.04.2011 19:28:50 VBASE029.VDF : 7.11.5.251 2048 Bytes 07.04.2011 19:28:50 VBASE030.VDF : 7.11.5.252 2048 Bytes 07.04.2011 19:28:50 VBASE031.VDF : 7.11.6.19 95744 Bytes 08.04.2011 19:27:14 Engineversion : 8.2.4.206 AEVDF.DLL : 8.1.2.1 106868 Bytes 10.01.2011 13:22:51 AESCRIPT.DLL : 8.1.3.58 1266042 Bytes 05.04.2011 06:37:44 AESCN.DLL : 8.1.7.2 127349 Bytes 10.01.2011 13:22:49 AESBX.DLL : 8.1.3.2 254324 Bytes 10.01.2011 13:22:49 AERDL.DLL : 8.1.9.9 639347 Bytes 26.03.2011 00:58:17 AEPACK.DLL : 8.2.6.0 549237 Bytes 07.04.2011 19:30:06 AEOFFICE.DLL : 8.1.1.20 205177 Bytes 05.04.2011 06:37:42 AEHEUR.DLL : 8.1.2.97 3428726 Bytes 07.04.2011 19:29:59 AEHELP.DLL : 8.1.16.1 246134 Bytes 12.02.2011 10:26:24 AEGEN.DLL : 8.1.5.4 397684 Bytes 05.04.2011 06:37:36 AEEMU.DLL : 8.1.3.0 393589 Bytes 10.01.2011 13:22:42 AECORE.DLL : 8.1.20.2 196982 Bytes 07.04.2011 19:28:53 AEBB.DLL : 8.1.1.0 53618 Bytes 10.01.2011 13:22:41 AVWINLL.DLL : 10.0.0.0 19304 Bytes 10.01.2011 13:22:56 AVPREF.DLL : 10.0.0.0 44904 Bytes 10.01.2011 13:22:55 AVREP.DLL : 10.0.0.8 62209 Bytes 17.06.2010 13:26:53 AVREG.DLL : 10.0.3.2 53096 Bytes 10.01.2011 13:22:55 AVSCPLR.DLL : 10.0.3.2 84328 Bytes 10.01.2011 13:22:56 AVARKT.DLL : 10.0.22.6 231784 Bytes 10.01.2011 13:22:51 AVEVTLOG.DLL : 10.0.0.8 203112 Bytes 10.01.2011 13:22:54 SQLITE3.DLL : 3.6.19.0 355688 Bytes 17.06.2010 13:27:02 AVSMTP.DLL : 10.0.0.17 63848 Bytes 10.01.2011 13:22:56 NETNT.DLL : 10.0.0.0 11624 Bytes 17.06.2010 13:27:01 RCIMAGE.DLL : 10.0.0.26 2550120 Bytes 28.01.2010 12:10:08 RCTEXT.DLL : 10.0.58.0 98152 Bytes 10.01.2011 13:23:15 Konfiguration für den aktuellen Suchlauf: Job Name..............................: avguard_async_scan Konfigurationsdatei...................: C:\ProgramData\Avira\AntiVir Desktop\TEMP\AVGUARD_4db769ca\guard_slideup.avp Protokollierung.......................: hoch Primäre Aktion........................: reparieren Sekundäre Aktion......................: quarantäne Durchsuche Masterbootsektoren.........: ein Durchsuche Bootsektoren...............: aus Durchsuche aktive Programme...........: ein Durchsuche Registrierung..............: aus Suche nach Rootkits...................: aus Integritätsprüfung von Systemdateien..: aus Datei Suchmodus.......................: Alle Dateien Durchsuche Archive....................: ein Rekursionstiefe einschränken..........: 20 Archiv Smart Extensions...............: ein Makrovirenheuristik...................: ein Dateiheuristik........................: hoch Abweichende Gefahrenkategorien........: +PFS, Erweiterte Sucheinstellungen..........: 0x08000000 Erweiterte Sucheinstellungen..........: 0x00300002 Beginn des Suchlaufs: Samstag, 9. April 2011 15:59 Die Reparatur von Rootkits ist nur im interaktiven Modus möglich! Der Suchlauf über gestartete Prozesse wird begonnen: Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\svchost.exe> Durchsuche Prozess 'avscan.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Avira\AntiVir Desktop\avscan.exe> Durchsuche Prozess 'SearchProtocolHost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\SearchProtocolHost.exe> Durchsuche Prozess 'firefox.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Mozilla Firefox\firefox.exe> Durchsuche Prozess 'taskmgr.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\taskmgr.exe> Durchsuche Prozess 'taskhost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\taskhost.exe> Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\svchost.exe> Durchsuche Prozess 'iPodService.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\iPod\bin\iPodService.exe> Durchsuche Prozess 'uTorrent.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\uTorrent\uTorrent.exe> Durchsuche Prozess 'sidebar.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Windows Sidebar\sidebar.exe> Durchsuche Prozess 'veohwebplayer.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Veoh Networks\VeohWebPlayer\veohwebplayer.exe> Durchsuche Prozess 'PCBoostTray.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\PGWARE\PCBoost\PCBoostTray.exe> Durchsuche Prozess 'avgnt.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Avira\AntiVir Desktop\avgnt.exe> Durchsuche Prozess 'wmpnetwk.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Windows Media Player\wmpnetwk.exe> Durchsuche Prozess 'DivXUpdate.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\DivX\DivX Update\DivXUpdate.exe> Durchsuche Prozess 'DDMService.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe> Durchsuche Prozess 'jusched.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Common Files\Java\Java Update\jusched.exe> Durchsuche Prozess 'iTunesHelper.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\iTunes\iTunesHelper.exe> Durchsuche Prozess 'Boingo Wi-Fi.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Boingo\Boingo Wi-Fi\Boingo Wi-Fi.exe> Durchsuche Prozess 'RtHDVCpl.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe> Durchsuche Prozess 'igfxsrvc.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\igfxsrvc.exe> Durchsuche Prozess 'igfxpers.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\igfxpers.exe> Durchsuche Prozess 'wmiprvse.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\wbem\WmiPrvSE.exe> Durchsuche Prozess 'hkcmd.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\hkcmd.exe> Durchsuche Prozess 'AsAgent.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\ASUS\EPC\EeeSplendid\AsAgent.exe> Durchsuche Prozess 'LiveUpdate.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\ASUS\LiveUpdate\LiveUpdate.exe> Durchsuche Prozess 'AsScrPro.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\AsScrPro.exe> Durchsuche Prozess 'HotkeyService.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\EeePC\HotkeyService\HotkeyService.exe> Durchsuche Prozess 'SynTPHelper.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Synaptics\SynTP\SynTPHelper.exe> Durchsuche Prozess 'HotKeyMon.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\EeePC\HotkeyService\HotKeyMon.exe> Durchsuche Prozess 'SynAsusAcpi.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Synaptics\SynTP\SynAsusAcpi.exe> Durchsuche Prozess 'SuperHybridEngine.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\EeePC\SHE\SuperHybridEngine.exe> Durchsuche Prozess 'Eee Docking.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\ASUS\Eee Docking\Eee Docking.exe> Durchsuche Prozess 'SynTPEnh.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Synaptics\SynTP\SynTPEnh.exe> Durchsuche Prozess 'IAAnotif.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe> Durchsuche Prozess 'WLIDSvcM.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVCM.EXE> Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\svchost.exe> Durchsuche Prozess 'SearchIndexer.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\SearchIndexer.exe> Durchsuche Prozess 'IAANTMon.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTmon.exe> Durchsuche Prozess 'WLIDSVC.EXE' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Common Files\microsoft shared\Windows Live\WLIDSVC.EXE> Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\svchost.exe> Durchsuche Prozess 'SeaPort.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe> Durchsuche Prozess 'conhost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\conhost.exe> Durchsuche Prozess 'avshadow.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Avira\AntiVir Desktop\avshadow.exe> Durchsuche Prozess 'OberonGameConsoleService.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\ASUS\Game Park\GameConsole\OberonGameConsoleService.exe> Durchsuche Prozess 'mwssvc.exe' - '1' Modul(e) wurden durchsucht Modul ist infiziert -> <C:\Program Files\MyWebSearch\bar\2.bin\MWSSVC.EXE> [FUND] Ist das Trojanische Pferd TR/Trash.Gen Durchsuche Prozess 'AsusService.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\AsusService.exe> Durchsuche Prozess 'AppleMobileDeviceService.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe> Durchsuche Prozess 'Explorer.EXE' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\explorer.exe> Durchsuche Prozess 'avguard.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Avira\AntiVir Desktop\avguard.exe> Durchsuche Prozess 'Dwm.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\dwm.exe> Durchsuche Prozess 'taskhost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\taskhost.exe> Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\svchost.exe> Durchsuche Prozess 'sched.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Program Files\Avira\AntiVir Desktop\sched.exe> Durchsuche Prozess 'spoolsv.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\spoolsv.exe> Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\svchost.exe> Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\svchost.exe> Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\svchost.exe> Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\svchost.exe> Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\svchost.exe> Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\svchost.exe> Durchsuche Prozess 'svchost.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\svchost.exe> Durchsuche Prozess 'lsm.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\lsm.exe> Durchsuche Prozess 'lsass.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\lsass.exe> Durchsuche Prozess 'services.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\services.exe> Durchsuche Prozess 'winlogon.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\winlogon.exe> Durchsuche Prozess 'wininit.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\wininit.exe> Durchsuche Prozess 'csrss.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\csrss.exe> Durchsuche Prozess 'csrss.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\csrss.exe> Durchsuche Prozess 'smss.exe' - '1' Modul(e) wurden durchsucht Modul ist OK -> <C:\Windows\System32\smss.exe> Der Suchlauf über die ausgewählten Dateien wird begonnen: Beginne mit der Suche in 'C:\Program Files\MyWebSearch\bar\2.bin\NPMYWEBS.DLL' C:\Program Files\MyWebSearch\bar\2.bin\ NPMYWEBS.DLL [FUND] Ist das Trojanische Pferd TR/Trash.Gen [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '49b9c78e.qua' verschoben! Beginne mit der Suche in 'C:\Program Files\MyWebSearch\bar\2.bin\M3PLUGIN.DLL' C:\Program Files\MyWebSearch\bar\2.bin\ M3PLUGIN.DLL [FUND] Ist das Trojanische Pferd TR/Trash.Gen [HINWEIS] Die Datei wurde ins Quarantäneverzeichnis unter dem Namen '5133e804.qua' verschoben! Ende des Suchlaufs: Samstag, 9. April 2011 16:00 Benötigte Zeit: 00:35 Minute(n) Der Suchlauf wurde vollständig durchgeführt. 0 Verzeichnisse wurden überprüft 72 Dateien wurden geprüft 3 Viren bzw. unerwünschte Programme wurden gefunden 0 Dateien wurden als verdächtig eingestuft 0 Dateien wurden gelöscht 0 Viren bzw. unerwünschte Programme wurden repariert 2 Dateien wurden in die Quarantäne verschoben 0 Dateien wurden umbenannt 0 Dateien konnten nicht durchsucht werden 69 Dateien ohne Befall 0 Archive wurden durchsucht 0 Warnungen 2 Hinweise Die Suchergebnisse werden an den Guard übermittelt. Zudem sind meine Eigenen Ordner "leer". Rechtsklick Eigenschaften verrät mir allerdings, dass dort meine paar GB noch abgespeichert sind aber mir wird nix angezeigt. Auch Dokumente vom Desktop sind nicht mehr sichtbar oder gelöscht, die wichtig waren...Wiederherstellungszeitpunkt gibt es nur den 1.4.2011 obwohl regelmäßig erstellt worden ist...und am 1.4.2011 trat das Problem auf...die Dateien verschwanden aber erst nach und nach. Wiederherstellung trotzdem gemacht aber mein Netbook sagt mir "Leck mich dat hat nix gebracht...." :headbang: Ich hoffe jemand kann mir anhand der Informationen helfen.... Glg Krissy |
na sicher können wir :-) Systemscan mit OTL download otl: http://filepony.de/download-otl/ Doppelklick auf die OTL.exe (user von Windows 7 und Vista: Rechtsklick als Administrator ausführen) 1. Oben findest Du ein Kästchen mit Output. Wähle bitte Minimal Output 2. Hake an "scan all users" 3. Unter "Extra Registry wähle: "Use Safelist" "LOP Check" "Purity Check" 4. Kopiere in die Textbox: netsvcs msconfig safebootminimal safebootnetwork activex drivers32 %ALLUSERSPROFILE%\Application Data\*. %ALLUSERSPROFILE%\Application Data\*.exe /s %APPDATA%\*. %APPDATA%\*.exe /s %SYSTEMDRIVE%\*.exe /md5start userinit.exe eventlog.dll scecli.dll netlogon.dll cngaudit.dll ws2ifsl.sys sceclt.dll ntelogon.dll winlogon.exe logevent.dll user32.DLL explorer.exe iaStor.sys nvstor.sys atapi.sys IdeChnDr.sys viasraid.sys AGP440.sys vaxscsi.sys nvatabus.sys viamraid.sys nvata.sys nvgts.sys iastorv.sys ViPrt.sys eNetHook.dll ahcix86.sys KR10N.sys nvstor32.sys ahcix86s.sys /md5stop %systemroot%\system32\drivers\*.sys /lockedfiles %systemroot%\System32\config\*.sav %systemroot%\*. /mp /s %systemroot%\system32\*.dll /lockedfiles CREATERESTOREPOINT 5. Klicke "Scan" 6. 2 reporte werden erstellt: OTL.Txt Extras.Txt beide posten. |
Erstmal danke für das rasche Feedback :) Das hat mein Netbook für Euch per OTL ausgespuckt....bin gespannt :/ OTL Logfile: OTL EXTRAS Logfile: Code: OTL logfile created on: 4/11/2011 4:59:26 PM - Run 1 --- --- --- OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 4/11/2011 4:59:26 PM - Run 1 glg Krissy |
lade dir unhide.exe http://filepony.de/download-unhide/ rechtsklick, als admin starten. lass das programm durchlaufen und prüfe ob dateien sichtbar werden. |
Ich danke dir, das hat schon einiges geholfen - jedenfalls sind die Dateien wieder sichtbar :taenzer: Jedoch hat sich das ja alles so nach und nach entwickelt, mir ist ein wenig Bange, dass in den nächsten Tagen der ganze Mist von vorne losgeht weil irgendwat muss sich mein PC doch eingefangen haben, dass der so rumspukt :daumenrunter: :wtf: Hab ich keine Möglichkeit herauszufinden was es ist und wie ich's wegbekomme? Die Wirkung hab ich ja nicht anhaltend bekämpft aber die Ursache schlummert hier ja noch rum :confused: |
immer mit der ruhe. poste mir bitte alle malwarebytes logs die du hast. zu finden unter malwarebytes, logdateien. |
Wollte dich auch nicht stressen :abklatsch: Der Refog Keylogger war gewollt, nicht dass du dich deswegen wunderst :crazy: Hier die Logdatei Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 6280 Windows 6.1.7600 Internet Explorer 8.0.7600.16385 05.04.2011 21:52:59 mbam-log-2011-04-05 (21-52-59).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 156470 Laufzeit: 15 Minute(n), 41 Sekunde(n) Infizierte Speicherprozesse: 1 Infizierte Speichermodule: 7 Infizierte Registrierungsschlüssel: 135 Infizierte Registrierungswerte: 12 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 29 Infizierte Dateien: 565 Infizierte Speicherprozesse: c:\program files\mywebsearch\bar\2.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> 1388 -> Unloaded process successfully. Infizierte Speichermodule: c:\program files\mywebsearch\bar\2.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Delete on reboot. c:\program files\windows live\messenger\msimg32.dll (PUP.FunWebProducts) -> Not selected for removal. c:\program files\mywebsearch\bar\2.bin\F3REPROX.DLL (PUP.FunWebProducts) -> Not selected for removal. c:\program files\mywebsearch\bar\2.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Delete on reboot. c:\program files\mywebsearch\bar\2.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Delete on reboot. c:\program files\mywebsearch\bar\2.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Delete on reboot. c:\program files\mywebsearch\bar\2.bin\F3HTMLMU.DLL (PUP.FunWebProducts) -> Not selected for removal. Infizierte Registrierungsschlüssel: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{D518921A-4A03-425E-9873-B9A71756821E} (PUP.FunWebProducts) -> Not selected for removal. HKEY_CLASSES_ROOT\Interface\{CF54BE1C-9359-4395-8533-1657CF209CFE} (PUP.FunWebProducts) -> Not selected for removal. HKEY_CLASSES_ROOT\CLSID\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA1-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{07B18EA0-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{07B18EAA-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MyWebSearch bar Uninstall (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.2 (PUP.FunWebProducts) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu (PUP.FunWebProducts) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.FunWebProducts) -> Not selected for removal. HKEY_CLASSES_ROOT\TypeLib\{E47CAEE0-DEEA-464A-9326-3F2801535A4D} (PUP.FunWebProducts) -> Not selected for removal. HKEY_CLASSES_ROOT\Interface\{3E1656ED-F60E-4597-B6AA-B6A58E171495} (PUP.FunWebProducts) -> Not selected for removal. HKEY_CLASSES_ROOT\CLSID\{00A6FAF1-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{00A6FAF1-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Settings\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{0F8ECF4F-3646-4C3A-8881-8E138FFCAF70} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{8CA01F0E-987C-49C3-B852-2F1AC4A7094C} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{1093995A-BA37-41D2-836E-091067C4AD17} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{1E0DE227-5CE4-4ea3-AB0C-8B03E1AA76BC} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{C8CECDE3-1AE1-4C4A-AD82-6D5B00212144} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{17DE5E5E-BFE3-4E83-8E1F-8755795359EC} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.DataControl.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.DataControl (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{3E720450-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3E720451-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{53CED2D0-5E9A-4761-9005-648404E6F7E5} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{8E6F1830-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{63D0ED2B-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{7473D292-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{7473D290-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{7473D291-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4F24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{7473D296-B7BB-4f24-AE82-7E2CE94BB6A9} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{84DA4FDF-A1CF-4195-8688-3E961F505983} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{8E6F1832-9607-4440-8530-13BE7C4B1D14} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{938AA51A-996C-4884-98CE-80DD16A5C9DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{29D67D3C-509A-4544-903F-C8C1B8236554} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{2E3537FC-CF2F-4F56-AF54-5A6A3DD375CC} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{A9571378-68A1-443d-B082-284F960C6D17} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{ADB01E81-3C79-4272-A0F1-7B2BE7A782DC} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{B813095C-81C0-4E40-AA14-67520372B987} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{C9D7BE3E-141A-4C85-8CD6-32461F3DF2C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{CFF4CE82-3AA2-451F-9B77-7165605FB835} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{D9FFFB27-D62A-4D64-8CEC-1FF006528805} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{0D26BC71-A633-4E71-AD31-EADC3A1B6A3A} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{E342AF55-B78A-4CD0-A2BB-DA7F52D9D25E} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{E79DFBC0-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{72EE7F04-15BD-4845-A005-D6711144D86A} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4FBD-94E5-5B2A9C7C1612} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{F42228FB-E84E-479E-B922-FBBD096E792C} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{6E74766C-4D93-4CC0-96D1-47B8E07FF9CA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.ThirdPartyInstaller (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.ThirdPartyInstaller.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton.1 (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Refog Software (Refog.Keylogger) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{819FFE22-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{819FFE20-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{819FFE21-35C7-4925-8CDA-4E0E2DB94302} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{8FFDF636-0D87-4B33-B9E9-79A53F6E1DAE} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{01947140-417F-46B6-8751-A3A2B8345E1A} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{799391D3-EB86-4bac-9BD3-CBFEA58A0E15} (Adware.MyWebSearch) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{D858DAFC-9573-4811-B323-7011A3AA7E61} (Adware.MyWebSearch) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\MyWebSearch Email Plugin (Adware.MyWebSearch) -> Value: MyWebSearch Email Plugin -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\My Web Search Bar Search Scope Monitor (Adware.MyWebSearch) -> Value: My Web Search Bar Search Scope Monitor -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44CF-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44CF-8957-5838F569A31D} -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D} (Adware.MyWebSearch) -> Value: {00A6FAF6-072E-44cf-8957-5838F569A31D} -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (Adware.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Onehepiguyor (Trojan.Agent.U) -> Value: Onehepiguyor -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Kfujigoreyesub (Trojan.Agent.U) -> Value: Kfujigoreyesub -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (Adware.MyWebSearch) -> Value: f3PopularScreensavers -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (Adware.MyWebSearch) -> Value: FunWebProducts -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: c:\programdata\MPK (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\CPDA (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\CPDM (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\refog personal monitor (Refog.Keylogger) -> Quarantined and deleted successfully. c:\program files\funwebproducts (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\funwebproducts\screensaver\Images (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch (Adware.MyWebSearch) -> Delete on reboot. c:\program files\mywebsearch\bar (Adware.MyWebSearch) -> Delete on reboot. c:\program files\mywebsearch\bar\1.bin (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\chrome (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin (Adware.MyWebSearch) -> Delete on reboot. c:\program files\mywebsearch\bar\2.bin\chrome (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Avatar (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Game (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\History (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Overlay (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Settings (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\Windows\System32\MPK (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang (Refog.Keylogger) -> Quarantined and deleted successfully. Infizierte Dateien: c:\program files\mywebsearch\bar\2.bin\MWSOESTB.DLL (Adware.MyWebSearch) -> Delete on reboot. c:\Program Files\MyWebSearch\bar\2.bin\MWSSVC.EXE (Adware.MyWebSearch) -> Delete on reboot. c:\program files\mywebsearch\bar\2.bin\MWSOEMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\windows live\messenger\msimg32.dll (PUP.FunWebProducts) -> Not selected for removal. c:\program files\mywebsearch\bar\2.bin\F3REPROX.DLL (PUP.FunWebProducts) -> Not selected for removal. c:\program files\mywebsearch\bar\2.bin\NPMYWEBS.DLL (Adware.MyWebSearch) -> Delete on reboot. c:\program files\mywebsearch\bar\2.bin\M3PLUGIN.DLL (Adware.MyWebSearch) -> Delete on reboot. c:\program files\mywebsearch\bar\2.bin\MWSBAR.DLL (Adware.MyWebSearch) -> Delete on reboot. c:\program files\mywebsearch\bar\2.bin\F3HTMLMU.DLL (PUP.FunWebProducts) -> Not selected for removal. c:\program files\mywebsearch\bar\2.bin\M3SRCHMN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\MWSSRCAS.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3HISTSW.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3DTACTL.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3HTML.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3POPSWT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3SKIN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3CJPEG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3SCRCTR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3OUTLCN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3HTTPCT.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3MSG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\MWSOEPLG.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\programdata\35446536.exe (Rogue.FakeHDD) -> Quarantined and deleted successfully. c:\Windows\System32\f3PSSavr.scr (PUP.FunWebProducts) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\xowermcnas.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\tmp1104.tmp (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup104210064.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup1122799688.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup1616803616.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup1658197920.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup1994244452.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup2024106000.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup2485476116.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\ptu505_tmp.exe (PUP.Casino) -> Not selected for removal. c:\Users\Krissy\AppData\Local\Temp\CC96.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\D6D2.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\D701.tmp (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\ocamsxewnr.exe (Trojan.Hiloti.Gen) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\err.log113828594 (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup4007255760.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup2654415980.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup2909314912.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup3030965844.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup3292206952.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup348659576.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup349743944.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup3504067900.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Local\Temp\setup3540841432.exe (Rootkit.TDSS) -> Quarantined and deleted successfully. c:\Users\Krissy\downloads\setupcasino_957b0d_de.exe (PUP.Casino) -> Quarantined and deleted successfully. c:\Users\Krissy\downloads\smileycentralpfsetup2.3.76.6.sa.hp.znfox000.exe (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\Users\Krissy\downloads\europasetup_9e702b_de.exe (PUP.Casino) -> Quarantined and deleted successfully. c:\Users\Krissy\downloads\europasetup_2a6cf0_de.exe (PUP.Casino) -> Quarantined and deleted successfully. c:\Users\Krissy\downloads\pantsoff.exe (PUP.PSWFinder) -> Not selected for removal. c:\Users\Krissy\downloads\europasetup_25bd16_de.exe (PUP.Casino) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Roaming\Adobe\plugs\kb113833492.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\Users\Krissy\AppData\Roaming\Adobe\plugs\kb113833633.exe (Trojan.Agent) -> Quarantined and deleted successfully. c:\programdata\MPK\M0000 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\refog personal monitor.lnk (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\S0000 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\D0000 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1467941667 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1502251736 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1536971875 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1571781366 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1606416898 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1641247801 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1675862153 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1710584954 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1745307870 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1780030671 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1814753935 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1849476273 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1918922106 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1953645023 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_1988367940 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2057813542 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2092536458 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2127259375 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2161982060 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2196704977 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2231427199 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2266150810 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2300873495 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2335596644 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2370319444 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2405041667 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2439764931 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2509210301 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2543933681 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2648102199 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2682825116 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2752270833 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2786993866 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2925885069 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_2960608102 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3099499306 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3134222569 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3168945255 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3203668403 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3238391088 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3273172454 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3307835995 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3342559606 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3377282755 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3412011806 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3446728009 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3481450347 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_3550896296 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_7578748843 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_7613649769 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_7648194444 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_7682917361 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_7717756944 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_7752362616 (Refog.Keylogger) -> Not selected for removal. c:\programdata\MPK\1\i40573_7787566088 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_7821809028 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_7856531134 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_7891254745 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_7925976968 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_7960701389 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_7995422801 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8030145255 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8064868056 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_2023090972 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_2717548032 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_3516175926 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8099594097 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8967662384 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0564988773 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1155206944 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1953832870 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2544120949 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3759421181 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_6915276736 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9580777546 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0275234954 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_1108583796 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2522098264 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3635671643 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6318910417 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8136060069 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8169037153 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8203760185 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8342651852 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8377373843 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8586256829 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8620433796 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8655157870 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8689880787 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8724602778 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8759325810 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8794048843 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8828771875 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8863494676 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8898236343 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_8932940162 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9002740162 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9037108681 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9071835532 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9106554861 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9141277315 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9176000231 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9210723032 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9246012268 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9280169213 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9315053704 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9349615509 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9384337268 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9419172107 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9453783449 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9488506829 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9523229167 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9557951389 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9592674884 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9627397685 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9662120255 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9696843056 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9731565972 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9766288657 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9801011690 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9835741667 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9870457523 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9905180440 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9939903125 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40573_9974625463 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0009348843 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0044071875 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0148586227 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0182963310 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0217686227 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0252409028 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0287131597 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0321854051 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0356577431 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0391300694 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0426023148 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0460745602 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0495468750 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0530434954 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0599640741 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0634386111 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0669087384 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0703810069 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0738532176 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0773255671 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0807978819 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0842701620 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0877424190 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0912178241 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0946869560 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_0981592245 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1016314931 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1051038657 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1085760764 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1120483449 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1189929977 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1224651968 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1259375810 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1467712616 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1502435532 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1537157986 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1571881019 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1606604977 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1641328935 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1676049769 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1745496065 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1780218750 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1814942361 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1849664236 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1884386574 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1919110417 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_1988555324 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2023278819 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2058002083 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2092725579 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2127446991 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2162170139 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2196892708 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2231615625 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2266338426 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2301060764 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2335783912 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2370506829 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2405230324 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2439952778 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2474675810 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2509398727 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2578843750 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2613567593 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2648290509 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2683012269 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2717735301 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_2752458796 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3169132523 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3203855671 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3238578704 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3273301968 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3308023727 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3585806944 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3620564931 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3655253009 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3689976042 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3724699074 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3794144329 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3828867245 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3863591435 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3898313426 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3933035301 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_3967758565 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_4002481019 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_4037205671 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_6533331944 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_6568049306 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_6602771065 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_6637494213 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_6776385648 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_6811107870 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_6845831250 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_6880553125 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_6950043056 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_6984722454 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_7019445139 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_7054168287 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_7088891204 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_7123614699 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_7158336690 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_7193058912 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_7401396759 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9336988426 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9372440393 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9407163657 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9441885880 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9476609144 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9511333449 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9546056250 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9615500926 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9650223148 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9684946181 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9719668750 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9754392824 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9789114699 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9823837037 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9858560301 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9893283681 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9928006250 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9962728588 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40574_9997571412 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0032175231 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0309957407 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0344680903 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0379403472 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0414127431 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0448849074 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0483573148 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0518294792 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0553017940 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0587740741 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0622463889 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0657186458 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0830801389 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0865522917 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_0900246644 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_1039137963 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_1073860417 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_1143306366 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2001255903 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2035978819 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2070701042 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2105424769 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2140147338 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2175165046 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2209672685 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2244632176 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2279038194 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2313762037 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2348485185 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2383206944 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2417930324 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2452653125 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2487375926 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_2556821644 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3114824653 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3149547338 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3184314815 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3219029745 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3253716551 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3288459606 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3323162384 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3357924884 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3392607407 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3427330903 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3462053935 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3496776157 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3531499653 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3566222454 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3600944676 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3670394792 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3705117130 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3739839931 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3774564815 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3809285880 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3844009722 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_3878731018 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6006357060 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6041080440 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6075802778 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6110553588 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6145248611 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6180025232 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6214694907 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6249418056 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6284203009 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6353751389 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6388417361 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6423321181 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6457755208 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6492477083 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6527288079 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6562138079 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40575_6596646644 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_1892591782 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_1927333102 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_1961973727 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_1996530324 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_2031257639 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_2066348495 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_2100654514 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_2135376620 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_2170308796 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_2204822917 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_2239546181 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_2552051273 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_5427796296 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40576_5462533912 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\CPDM\cpfm.bin (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\refog personal monitor\jetzt bestellen!.lnk (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\refog personal monitor\refog personal monitor im internet.lnk (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\refog personal monitor\refog personal monitor.lnk (Refog.Keylogger) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3FFTBPR.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\M3PATCH.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\1.bin\chrome\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3SPACER.WMV (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\chrome.manifest (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3BKGERR.JPG (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3HKSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3IMSTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3PSSAVR.SCR (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3REGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3RESTUB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3SCHMON.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3WALLPP.DAT (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\F3WPHOOK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\FWPBUDDY.PNG (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\INSTALL.RDF (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3AUXSTB.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3DLGHK.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3HIGHIN.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3IDLE.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3IMPIPE.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3MEDINT.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3SKPLAY.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3SLSRCH.EXE (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\M3TPINST.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\MWSMLBTN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\MWSUABTN.DLL (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\2.bin\chrome\M3FFXTBR.JAR (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Avatar\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Game\CHECKERS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Game\CHESS.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Game\REVERSI.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons\CM.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons\MFC.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons\PSS.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons\SMILEY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons\WB.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\icons\ZWINKY.ICO (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Message\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\DOG.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\FISH.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\KUNGFU.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\LIFEGARD.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\MAID.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\MAILBOX.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\OPERA.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\ROBOT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\SEDUCT.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Notifier\SURFER.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Overlay\COMMON.F3S (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\program files\mywebsearch\bar\Settings\s_pid.dat (Adware.MyWebSearch) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\icon_1.ico (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\key.bin (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\libeay32.dll (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\lnkmst.exe (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\logstart.vbs (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\loguninstall.vbs (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Mpk.dll (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Mpk64.dll (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\sqlite3.dll (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\ssleay32.dll (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\trial_pro.ini (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\unins000.dat (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\unins000.exe (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\unins000.msg (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\update_info.bin (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\zlib1.dll (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\file.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\imhelp.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\need_update_net.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\update.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\file.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\imhelp.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\need_update_net.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_german.gif (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_em_english.gif (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_em_english.swf (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_em_german.gif (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_em_german.swf (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_em_spanish.gif (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_em_spanish.swf (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_english.gif (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_english.swf (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_german.swf (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_pm_english.gif (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_pm_english.swf (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_pm_german.gif (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_pm_german.swf (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_pm_spanish.gif (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_pm_spanish.swf (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_russian.gif (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_spanish.gif (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\banner_spanish.swf (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\english.gif (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\german.gif (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\upgrade_aeu.png (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\upgrade_aus.png (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\upgrade_eu.png (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\upgrade_us.png (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\vista_hide.bmp (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\xp_hide.bmp (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\brazilian.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\brazilian.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\English.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\French.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\French.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\German.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\German.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Italian.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Italian.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Japanese.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Japanese.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Polish.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\portuguese.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\portuguese.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Romanian.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Romanian.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Russian.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Spanish.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Spanish.lng (Refog.Keylogger) -> Quarantined and deleted successfully. |
ich fühlte mich nicht gestresst, ich meinte, immer mit der ruhe, wir bekommen das hin. bitte erstelle und poste ein combofix log. Ein Leitfaden und Tutorium zur Nutzung von ComboFix |
So,das hat ein wenig mehr Zeit in Anspruch genommen...und weiter gehts mit dem Log: Combofix Logfile: Code: ComboFix 11-04-10.04 - Krissy 11.04.2011 19:36:44.1.2 - x86 |
start programme zubehör editor, kopiere rein: killal:: rootkit:: c:\users\Krissy\AppData\Local\Ujowocesofih.bin datei speichern unter, ort dort wo sich combofix.exe befindet, typ alle dateien, name: cfscript.txt ziehe cfscript auf combofix, programm startet log posten. |
Gesagt, getan... Combofix Logfile: Code: ComboFix 11-04-10.04 - Krissy 11.04.2011 20:27:49.2.2 - x86 |
klicke mal auf computer, auf c: dort öffne den ordner qoobox. dort rechtsklick auf quarantain, und mit winrar oder zip packen. dann hochladen: dateiupload: http://www.trojaner-board.de/54791-a...ner-board.html |
Hab ich gemacht, ist hoffentlich richtig hochgeladen worden! |
nö, ist vllt zu groß lad mal bei File-Upload.net - Ihr kostenloser File Hoster! hoch und sende mir den link als private nachicht. |
Die rar-datei hat eine größe von 503 mb...das max beträgt bei file upload auch 100mb... lade jetzt die datei auf file savr hoch, da gehts bis 2gb...und dann schick ich dir den link,ok? |
o, na das erklärt einiges :d öffne mal qoobox, Quarantine c:\windows\system32\ dort ist eine userinit.exe .vir diese mal im upload channel hochladen. |
Das erklärt einiges? Das macht mir schon fast Angst :confused: Hab's erfolgreich hochgeladen... |
na das erklärt auf jeden fall warums sich nicht hochladen lies, wenns 500 mb groß ist, das meinte ich. ok danke. |
ok diese datei ist in ordnung. lade den ccleaner slim: Piriform - Builds falls der ccleaner bereits instaliert, überspringen. instalieren, öffnen, extras, liste der instalierten programme, als txt speichern. öffnen. hinter, jedes von dir benötigte programm, schreibe notwendig. hinter, jedes, von dir nicht benötigte, unnötig. hinter, dir unbekannte, unbekannt. liste posten. |
Adobe Flash Player 10 ActiveX Adobe Systems Incorporated 12.12.2010 6,00MB 10.1.102.64 notwendig Adobe Flash Player 10 Plugin Adobe Systems Incorporated 25.03.2011 6,00MB 10.2.153.1 notwendig Adobe Reader X (10.0.1) - Deutsch Adobe Systems Incorporated 19.02.2011 115,6MB 10.0.1 notwendig Apple Application Support Apple Inc. 07.07.2010 42,8MB 1.3.0 unnötig Apple Mobile Device Support Apple Inc. 07.07.2010 19,9MB 3.1.0.62 unnötig Apple Software Update Apple Inc. 07.07.2010 2,26MB 2.1.2.120 unnötig ASUS VIBE Ecareme, Inc. 28.06.2010 1.0.187 notwendig ASUSUpdate for Eee PC ASUSTeK Computer Inc. 03.05.2010 1.03.06 notwendig Atheros Client Installation Program Atheros 05.01.2010 7.0 notwendig Atheros Communications Inc.(R) AR81Family Gigabit/Fast Ethernet Driver Atheros Communications Inc. 05.01.2010 1.0.0.10 notwendig Avira AntiVir Personal - Free Antivirus Avira GmbH 16.03.2011 67,7MB 10.0.0.635 notwendi Azureus 11.03.2011 2.5.0.4 unnötig Boingo Wi-Fi Boingo Wireless, Inc. 02.05.2010 25,4MB 1.7.0048 notwendig CCleaner Piriform 11.04.2011 3.05 notwendig Chicken Invaders 2 Oberon Media 03.05.2010 unbekannt Compatibility Pack für 2007 Office System Microsoft Corporation 10.11.2010 127,4MB 12.0.6425.1000 notwendi DivX-Setup DivX, LLC 21.01.2011 2.3.0.20 notwendig E-Cam 03.05.2010 2.0.2.3 notwendig ebi.BookReader3J eBOOK Initiative Japan Co., Ltd. 10.05.2010 18,7MB 3.75.14 unnötig Eee Docking 3.6.0 ASUSTek Computer Inc. 05.01.2010 3.6.0 notwendig EeeSplendid ASUS 05.01.2010 5.1.2.0008 notwendig FontResizer ASUSTek 05.01.2010 2,12MB 1.01.0011 notwendig Game Park Console Oberon Media, Inc. 05.01.2010 5.2.1.4 unbekannt Google Chrome Google Inc. 13.01.2011 10.0.648.204 unnötig Google Earth Google 22.02.2011 84,4MB 6.0.1.2032 unnötig Hotkey Service AsusTek Computer 05.01.2010 1.15 notwendig ICQ7.4 ICQ 04.04.2011 7.4 notwendig Intel(R) Graphics Media Accelerator Driver Intel Corporation 03.05.2010 54,3MB 8.14.10.1929 notwendig Intel® Matrix Storage Manager Intel Corporation 03.05.2010 notwendig iTunes Apple Inc. 07.07.2010 160,8MB 9.2.0.61 unnötig Java(TM) 6 Update 22 Oracle 06.10.2010 94,9MB 6.0.220 notwendig LiveUpdate Asus 05.01.2010 15,1MB 1.19 unbekannt LocaleMe ASUS 05.01.2010 14,7MB 1.3 notwendig MahJong Suite 2011 v8.1 TreeCardGames 20.02.2011 unnötig Malwarebytes' Anti-Malware Malwarebytes Corporation 04.04.2011 10,5MB notwendig Microsoft .NET Framework 4 Client Profile Microsoft Corporation 25.06.2010 38,8MB 4.0.30319 notwendig Microsoft .NET Framework 4 Client Profile DEU Language Pack Microsoft Corporation 25.06.2010 2,94MB 4.0.30319 notwendig Microsoft Office Home and Student 2007 Microsoft Corporation 03.05.2010 12.0.6425.1000 notwendig Microsoft Office Language Pack 2007 - Dutch/Nederlands Microsoft Corporation 03.05.2010 12.0.6425.1000 unnötig Microsoft Office Language Pack 2007 - French/Français Microsoft Corporation 03.05.2010 12.0.6425.1000 unnötig Microsoft Office Language Pack 2007 - German/Deutsch Microsoft Corporation 03.05.2010 12.0.6425.1000 notwendig Microsoft Office Language Pack 2007 - Italian/Italiano Microsoft Corporation 03.05.2010 12.0.6425.1000 unnötig Microsoft Office Live Add-in 1.5 Microsoft Corporation 02.06.2010 0,50MB 2.0.4024.1 unbekannt Microsoft Office PowerPoint Viewer 2007 (German) Microsoft Corporation 10.11.2010 96,9MB 12.0.6425.1000 notwendig Microsoft Office Suite Activation Assistant Microsoft Corporation 05.01.2010 8,37MB 2.9 unbekannt Microsoft Silverlight Microsoft Corporation 17.02.2011 108,5MB 4.0.60129.0 unbekannt Microsoft SQL Server 2005 Compact Edition [ENU] Microsoft Corporation 02.05.2010 1,72MB 3.1.0000 unbekannt Microsoft Sync Framework Runtime Native v1.0 (x86) Microsoft Corporation 02.05.2010 0,61MB 1.0.1215.0 unbekannt Microsoft Sync Framework Services Native v1.0 (x86) Microsoft Corporation 05.02.2011 1,45MB 1.0.1215.0 unbekannt Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Corporation 11.02.2011 0,58MB 9.0.30729.4148 unbekannt Microsoft Works Microsoft Corporation 18.12.2010 500MB 9.7.0621 notwendig Mozilla Firefox (3.6.16) Mozilla 24.03.2011 3.6.16 (de) notwendig MSXML 4.0 SP2 (KB973688) Microsoft Corporation 05.01.2010 1,34MB 4.20.9876.0 unbekannt MSXML 4.0 SP3 Parser (KB973685) Microsoft Corporation 05.01.2010 1,53MB 4.30.2107.0 unbekannt Opera 11.01 Opera Software ASA 18.03.2011 28,1MB 11.01 unnötig PantsOff 2.0 Christoph Bünger Software 03.02.2011 2.0 unnötig PC SECURITY TEST 2009 AxBx 08.02.2011 unnötig PCBoost PGWARE LLC 11.02.2011 12,1MB 4.12.20.2010 unnötig PokerStars.net PokerStars.net 20.05.2010 notwendig QuickTime Apple Inc. 07.07.2010 73,8MB 7.66.73.0 notwendig Ralink RT2860 Wireless LAN Card Ralink 05.01.2010 1.2.0.1 notwendig Realtek High Definition Audio Driver Realtek Semiconductor Corp. 03.05.2010 6.0.1.5948 notwendig Super Hybrid Engine AsusTek Computer 05.01.2010 2.10 notwendig Synaptics Pointing Device Driver Synaptics Incorporated 05.01.2010 13.2.6.1 notwendig Trillian 09.12.2010 unnötig TVgenial 4.10 25.12.2010 unnötig TVUPlayer 2.5.3.1 TVU networks 19.02.2011 2.5.3.1 unnötig Veoh Web Player Veoh Networks, Inc. 11.12.2010 1.1.2.0000 notwendig WebcamMax 11.02.2011 7.2.2.2.MultiLanguage unnötig Windows Driver Package - Broadcom Bluetooth (07/17/2009 6.2.0.9403) Broadcom 03.05.2010 07/17/2009 6.2.0.9403 unbekannt Windows Driver Package - Broadcom Bluetooth (07/29/2009 6.1.7100.0) Broadcom 03.05.2010 07/29/2009 6.1.7100.0 unbekannt Windows Driver Package - Broadcom HIDClass (07/28/2009 6.2.0.9800) Broadcom 03.05.2010 07/28/2009 6.2.0.9800 unbekannt Windows Live Essentials Microsoft Corporation 05.02.2011 14.0.8117.0416 notwendig Windows Live ID-Anmelde-Assistent Microsoft Corporation 02.06.2010 5,52MB 6.500.3165.0 notwendig Windows Live Sync Microsoft Corporation 05.02.2011 2,79MB 14.0.8117.416 unbekannt Windows Live-Uploadtool Microsoft Corporation 02.05.2010 0,22MB 14.0.8014.1029 notwendig WinRAR 11.05.2010 notwendig Zattoo4 4.0.5 Zattoo Inc. 20.05.2010 4.0.5 notwendig Zuma Deluxe Oberon Media 02.05.2010 unnötig µTorrent 11.03.2011 2.2.1 notwendig |
deinstaliere: alles von apple. Azureus Chicken Invaders ebi.BookReader3J Google Chrome Google Earth iTunes Java(TM) 6 Update 22 hohle die neueste version von hier: Java SE Downloads klicke dazu auf "download jre" deinstaliere: MahJong Microsoft Office Language Pack alle außer Microsoft Office Language Pack 2007 - German/Deutsch Microsoft Silverlight Microsoft SQL Mozilla Firefox öffnen, auf hilfe, update klicken, version 4 ist draußen Opera 11.01 würde ich persönlich eher benutzen, ist schneller und sicherer als ff falls er dir nicht gefällt, deinstalieren. PantsOff PC SECURITY TEST PCBoost Trillian TVgenial TVUPlayer 2.5.3.1 WebcamMax Windows Live Sync Zuma bereinige mit dem ccleaner dateien + registry. wie läuft der pc jetzt? |
Alle Zeitangaben in WEZ +1. Es ist jetzt 18:41 Uhr. |
Copyright ©2000-2025, Trojaner-Board