![]() |
|
Log-Analyse und Auswertung: Windowssystem gesperrt - VirusWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
|
![]() | #1 |
![]() | ![]() Windowssystem gesperrt - VirusCode:
ATTFilter Malwarebytes Anti-Malware 1.60.0.1800 www.malwarebytes.org Datenbank Version: v2012.01.07.04 Windows Vista x86 NTFS Internet Explorer 8.0.6001.18904 Fabi :: FABI-PC [Administrator] 08.01.2012 15:22:09 mbam-log-2012-01-08 (15-22-09).txt Art des Suchlaufs: Vollständiger Suchlauf Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 409760 Laufzeit: 4 Stunde(n), 3 Minute(n), 34 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) |
![]() | #2 | ||||||
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windowssystem gesperrt - Virus hast Du ganz schön einiges zu tun..alte Infektion auch noch drauf...
__________________![]() 1. Deinstalliere unter `Start→ Systemsteuereung→ Ändern/Entfernen...` Code:
ATTFilter Favorit - Adware - Gehe in den abgesicherten Modus [F8] (drücke beim Hochfahren des Rechners [F8] solange, bis du eine Auswahlmöglichkeit hast, da "abgesicherten Modus " wählen) und versuche von dort die Deinstallation durchführen 2. Deine Javaversion ist nicht aktuell! → Downloade nun die Offline-Version von Java Version 6 Update 30 von Oracle herunter Achte darauf, eventuell angebotene Toolbars abwählen (den Haken bei der Toolbar entfernen)! 3. Die alte Java-Versionen verbleiben auf dem PC...aus Sicherheitsgründen müssen entfernt werden,auch in Zukunft darauf achten! 4. Adobe Reader aktualisieren : - Bei Installation aufpassen/mitlesen!: Wenn irgendeine Software, Toolbar etc angeboten wird, bitte abwählen! - (z.B "McAfee Security Scan Plus") Adobe Reader Oder: Adobe starten-> gehe auf "Hilfe"-> "Nach Update suchen..." 5. absolut unnötig, kann deinstalliert werden: Zitat:
Zitat:
7. Code:
ATTFilter eMule Zitat:
Ausserdem nicht nur trojanische Pferde oder andere Virentypen eine direkt Verbindung brauchen, sondern der Verwendung von µtorrent & Co, "telefonieren auch nach Hause", wenn auch noch keine Beweise vorliegen (zumindest teilweise nicht) und solchen Clients erlaubt, würde ich nicht empfehlen! ![]() Solange du solche Programme auf dein PC hast, wirst Du Dich laufend mit etwas Problematik konfrontieren müssen! 8. reinige dein System mit CCleaner:
9. Zitat:
Code:
ATTFilter :OTL IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/ IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.medion.com/ IE - HKCU\..\URLSearchHook: - No CLSID value found IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0: C:\Program Files\Picasa2\npPicasa2.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Picasa2\npPicasa3.dll (Google, Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.) CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll CHR - plugin: QuickTime Plug-in 7.6.6 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll CHR - plugin: Google Updater (Enabled) = C:\Program Files\Google\Google Updater\2.4.1908.5032\npCIDetect14.dll CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - No CLSID value found. O2 - BHO: (Turnabout Helper) - {87FF76F0-BCA9-40DC-B1E5-254062EEE8F4} - C:\Programme\Reify Software\Turnabout\turnabout.dll (Reify Software, Inc.) O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll (Google Inc.) O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKLM\..\Toolbar: (Reify Toolbar) - {B99F805C-F0B1-48EA-8C8B-753BFCBED912} - C:\Programme\Reify Software\Turnabout\turnabout.dll (Reify Software, Inc.) O3 - HKCU\..\Toolbar\WebBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ) O3 - HKCU\..\Toolbar\WebBrowser: (Reify Toolbar) - {B99F805C-F0B1-48EA-8C8B-753BFCBED912} - C:\Programme\Reify Software\Turnabout\turnabout.dll (Reify Software, Inc.) O4 - HKLM..\Run: [toolbar_eula_launcher] C:\Program Files\GoogleEULA\EULALauncher.exe File not found O4 - HKCU..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe" File not found O8 - Extra context menu item: Add to Windows &Live Favorites - hxxp://favorites.live.com/quickadd.aspx File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2007.11.06 19:01:24 | 000,000,076 | ---- | M] () - D:\AUTORUN.INF -- [ FAT32 ] O33 - MountPoints2\{0255f92b-796d-11df-8600-001583122a35}\Shell - "" = AutoRun O33 - MountPoints2\{0255f92b-796d-11df-8600-001583122a35}\Shell\AutoRun\command - "" = F:\Startme.exe O33 - MountPoints2\{79750547-bcbc-11df-b95a-001583122a35}\Shell\AutoRun\command - "" = G:\setupSNK.exe O33 - MountPoints2\{f5ff8de1-996f-11df-ae43-001583122a35}\Shell\AutoRun\command - "" = C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Autostart.exe [2012.01.07 22:57:00 | 000,000,868 | ---- | M] () -- C:\Windows\tasks\Google Software Updater.job [2012.01.07 22:51:00 | 000,001,098 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.01.07 22:51:00 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2011.02.08 22:24:35 | 000,006,371 | ---- | C] () -- C:\Users\Fabi\AppData\Local\rebur_navps.dat [2011.02.08 22:24:34 | 000,234,193 | ---- | C] () -- C:\Users\Fabi\AppData\Local\rebur_nav.dat [2011.02.08 22:24:34 | 000,003,390 | ---- | C] () -- C:\Users\Fabi\AppData\Local\rebur.dat [2011.02.04 22:23:50 | 000,000,087 | ---- | C] () -- C:\Users\Fabi\AppData\Local\wgqzcsc.bat [2010.07.19 17:22:55 | 000,000,089 | ---- | C] () -- C:\Users\Fabi\AppData\Local\dqgvrfuc.bat [2010.04.02 12:33:07 | 000,003,415 | ---- | C] () -- C:\Users\Fabi\AppData\Local\amylxk_navps.dat [2008.10.09 21:36:33 | 000,000,090 | ---- | C] () -- C:\Users\Fabi\AppData\Local\cfvro.bat @Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:8643C5BE @Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:551E1CB4 @Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:2FF4577A @Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:08993BCD @Alternate Data Stream - 151 bytes -> C:\ProgramData\TEMP:77846FFE @Alternate Data Stream - 150 bytes -> C:\ProgramData\TEMP:A08FFD4D @Alternate Data Stream - 148 bytes -> C:\ProgramData\TEMP:41C283B2 @Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:E6683E95 @Alternate Data Stream - 146 bytes -> C:\ProgramData\TEMP:CBEB737E @Alternate Data Stream - 145 bytes -> C:\ProgramData\TEMP:002640E3 @Alternate Data Stream - 143 bytes -> C:\ProgramData\TEMP:F791B5EF @Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:FD444D31 @Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:273A8657 @Alternate Data Stream - 138 bytes -> C:\ProgramData\TEMP:38317199 @Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:51A22C60 @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:A23D24E7 @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:74B502CB @Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:7079A696 @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:F62CAE78 @Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:E1F04E8D @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:AD171C9E @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:895798AD @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:4C509008 @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:26946BE8 @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:F50F1555 @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:EB603FE4 @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:CBCE0A92 @Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:79F970BE @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:87FA5E8A @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:30C46519 @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:1941675B @Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:128A6DC9 @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:4F58D818 @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:25005EFA @Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:0EE601C7 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:F86CC73E @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:DCDE7C60 @Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:76986D86 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:FD6B3FC3 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:E54FA796 @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:8FBE0E9C @Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:226A6E31 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:BDB40AA4 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:B54102AD @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:95B7F1EC @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:7091055F @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:666FB4AA @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:5711EF65 @Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:00C31200 @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:D66B5EAE @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:6DD87D86 @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:3A925163 @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:3612C9BE @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:05816AFA @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:A696643D @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:93DE1838 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:42228396 @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:1C9565AC @Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:158CC5FF @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:A94968B5 @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:A4AD016E @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:81ED9272 @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:75F5C19E @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:43AA121F @Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:052A05A1 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:E6B9E5A3 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:E36F5B57 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:5C270C64 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:20B17557 @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:0B61DB9F @Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:0651F96C @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:F264BECE @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:E5AFE07D @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:D26DD363 @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:BB8F0982 @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:B723C5EF @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:776E54F2 @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:710F4DBF @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:5466F106 @Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:3780BCC3 @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:EA2FBCA1 @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:CDFF58FE @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:9FE30AB2 @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:36B6EC9F @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:33553E61 @Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:162E02F7 @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:DAFD38AE @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:700CD00E @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:6C491D31 @Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:1AF93AF4 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:F02F4882 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:AD79E1D8 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:9B52F176 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:4E903DEB @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:3B00070D @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:38849DE5 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:34FC1C45 @Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:2B4E9D93 @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:D8A7F3FF @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:D61069DE @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:AA004D25 @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:7DFDF9DF @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:426796C0 @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:3447AB86 @Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:3214A283 @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:B14B4A95 @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:93C494CA @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:588B60C7 @Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:558C8E0A @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:91973ED2 @Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:5C07C19F @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:DFC5A2B2 @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:949483BD @Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:6641B59F @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:FA5F15C4 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:A42A9F39 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:9A7901A9 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:943D6A82 @Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:07536DA3 @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:E71141D2 @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:4D7FCCD3 @Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:21745EE1 @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:ADE16379 @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:997E6AF4 @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:61E5F0F7 @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:48F0FFF8 @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:375E3FC4 @Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:27AD48A5 @Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:77F07255 @Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:4F636E25 @Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:30376ACC @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:54BAC9A7 @Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:2B8FEE50 @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:5EBA4934 @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:492679C1 @Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:1CB8D545 @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:E1982A23 @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:6F1F1DBC @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:41099CE9 @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:345E21F6 @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:1CB3187E @Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:1B1330FD @Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:F951183D @Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:CE7C61DF @Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:A69F57F3 @Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:3064D21D @Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:CF5C4195 @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:D690C7F7 @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:BB48E5A3 @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:9335E3B6 @Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:6A18D1F5 @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:F5BB3657 @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:ABE89FFE @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:9AB338B9 @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:9A221D63 @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:765C6A14 @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:37CE0F2E @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:126591AF @Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:0207B271 @Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:B6FA1F20 @Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:87E0E06D @Alternate Data Stream - 103 bytes -> C:\ProgramData\TEMP:7FC64998 @Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:DF2EA4BB @Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:615435BE @Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:567AC0A6 @Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:12A8EFF7 @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:919B0931 @Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:6A97C459 :Reg "TCP Query User{0F5DA350-6BA4-4B87-AB29-DC7802FDB098}C:\program files\emule\emule.exe" =- "TCP Query User{A0B0E0E5-04EC-44CD-A7C6-846D7810BB31}C:\program files\emule\emule.exe" =- "UDP Query User{AC0ED212-C3CF-4A96-9402-1ED730BAF584}C:\program files\emule\emule.exe" =- "UDP Query User{FE6EE0E9-D6C8-4AA6-9A17-1C52C54A7F9A}C:\program files\emule\emule.exe" =- [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "cfvro" =- :Commands [purity] [emptytemp]
10.
11. Auch auf USB-Sticks, selbstgebrannten Datenträgern, externen Festplatten und anderen Datenträgern können Viren transportiert werden. Man muss daher durch regelmäßige Prüfungen auf Schäden, die durch Malware ("Worm.Win32.Autorun") verursacht worden sein können, überwacht werden. Hierfür sind ser gut geegnet und empfohlen, die auf dem Speichermedium gesicherten Daten, mit Hilfe des kostenlosen Online Scanners zu prüfen. Schließe jetzt alle externe Datenträgeran (USB Sticks etc) Deinen Rechner an, dabei die Hochstell-Taste [Shift-Taste] gedrückt halten, damit die Autorun-Funktion nicht ausgeführt wird. (So verhindest Du die Ausführung der AUTORUN-Funktion) - Man kann die AUTORUN-Funktion aber auch generell abschalten.►Anleitung 12. -> Führe dann einen Komplett-Systemcheck mit Eset Online Scanner (NOD32)Kostenlose Online Scanner durch Achtung!: >>Du sollst nicht die Antivirus-Sicherheitssoftware installieren, sondern dein System nur online scannen<< ► Empfehlungen/Vorschläge: 13. An deiner Stelle würde ich aus dem Autostart folgende Programme rausnehmen: Beim Hochfahren von Windows werden einige Programme mit gestartet, die sich (mit oder ohne Zustimmung des Users) im Autostart eingetragen haben Je mehr Programme hier aufgeführt sind, umso langsamer startet Windows. Deshalb kann es sinnvoll sein, Software die man nicht unbedingt immer benötigt, aus dem Autostart zu entfernen.- Bei allem Häkchen weg was nicht starten soll. Die Programme bleiben dabei erhalten, falls man braucht, kann jederzeit manuell gestartet werden! Code:
ATTFilter Du solltest nie deaktivieren : Grafiktreibers Firewall Antivirenprogramm Sound [U]um den Autostart von Windows XP zu verwalten: ► "Start -> Alle Programme-> Zubehör-> Ausführen" .. und gibst Du "msconfig" (ohne "") ein ->OK Zitat:
Code:
ATTFilter O4 - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.) O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.) O4 - HKLM..\Run: [Google Updater] C:\Program Files\Google\Google Updater\GoogleUpdater.exe (Google) O4 - HKLM..\Run: [ISTray] C:\Program Files\Spyware Doctor\pctsTray.exe (PC Tools) O4 - HKLM..\Run: [LaunchAp] C:\Program Files\Launch Manager\LaunchAp.exe () O4 - HKLM..\Run: [LMgrOSD] C:\Program Files\Launch Manager\OSD.exe (Wistron Corp.) O4 - HKLM..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\FirstStart.exe (OLYMPUS IMAGING CORP.) O4 - HKLM..\Run: [QuickFinder Scheduler] C:\Program Files\WordPerfect Office X3\Programs\QFSCHD130.EXE (Corel Corporation) O4 - HKLM..\Run: [TkBellExe] C:\Program Files\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [Wbutton] C:\Program Files\Launch Manager\Wbutton.exe () O4 - HKCU..\Run: [OM2_Monitor] C:\Program Files\OLYMPUS\OLYMPUS Master 2\MMonitor.exe (OLYMPUS IMAGING CORP.) O4 - HKCU..\Run: [Sony Ericsson PC Companion] C:\Program Files\Sony Ericsson\Sony Ericsson PC Companion\PCCompanion.exe (Sony Ericsson Mobile Communications AB) O4 - HKCU..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\wmpnscfg.exe (Microsoft Corporation) Für die aufgelisteten Programme gelten zusätzlich, dass man nach Aktualisierung (AfterUpdate) erneut unter Start und Dienste nachkontrollieren muss! 14. erneut einen Scan mit OTL:
Zitat:
__________________ |
![]() | #3 |
![]() | ![]() Windowssystem gesperrt - Virus ich hab bei programme und funktionen kein adware gefunden.. wie soll ich das deinstallieren?
__________________ |
![]() | #4 |
![]() | ![]() Windowssystem gesperrt - Virus emule habe ich auch nicht gefunden.. wo muss ich das löschen? |
![]() | #5 |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Windowssystem gesperrt - Virus zu Punkt 7. : unter Systemsteuerung existiert "eMule" nicht mehr..wir machen das schon alle andere Schritte bitte erledigen, dann sehen wir weiter ![]()
__________________ Warnung!: Vorsicht beim Rechnungen per Email mit ZIP-Datei als Anhang! Kann mit einen Verschlüsselungs-Trojaner infiziert sein! Anhang nicht öffnen, in unserem Forum erst nachfragen! Sichere regelmäßig deine Daten, auf CD/DVD, USB-Sticks oder externe Festplatten, am besten 2x an verschiedenen Orten! Bitte diese Warnung weitergeben, wo Du nur kannst! |
![]() | #6 |
![]() | ![]() Windowssystem gesperrt - Virus 9. OTL.exe Code:
ATTFilter All processes killed ========== OTL ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully! Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully. C:\Programme\ICQ6Toolbar\ICQToolBar.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@google.com/npPicasa2,version=2.0.0\ deleted successfully. C:\Program Files\Picasa2\npPicasa2.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0\ deleted successfully. C:\Program Files\Picasa2\npPicasa3.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully. C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully. File C:\Program Files\Google\Update\1.3.21.79\npGoogleUpdate3.dll not found. C:\Program Files\QuickTime\plugins\npqtplugin.dll moved successfully. C:\Program Files\QuickTime\plugins\npqtplugin2.dll moved successfully. C:\Program Files\QuickTime\plugins\npqtplugin3.dll moved successfully. C:\Program Files\QuickTime\plugins\npqtplugin4.dll moved successfully. C:\Program Files\QuickTime\plugins\npqtplugin5.dll moved successfully. C:\Program Files\QuickTime\plugins\npqtplugin6.dll moved successfully. File C:\Program Files\Google\Google Updater\2.4.1908.5032\npCIDetect14.dll not found. File C:\Program Files\Google\Update\1.3.21.69\npGoogleUpdate3.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7E853D72-626A-48EC-A868-BA8D5E23E045}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{87FF76F0-BCA9-40DC-B1E5-254062EEE8F4}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{87FF76F0-BCA9-40DC-B1E5-254062EEE8F4}\ deleted successfully. C:\Programme\Reify Software\Turnabout\turnabout.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\ deleted successfully. C:\Programme\Google\GoogleToolbarNotifier\5.7.7018.1622\swg.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found. File C:\Programme\ICQ6Toolbar\ICQToolBar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{B99F805C-F0B1-48EA-8C8B-753BFCBED912} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B99F805C-F0B1-48EA-8C8B-753BFCBED912}\ deleted successfully. File C:\Programme\Reify Software\Turnabout\turnabout.dll not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{855F3B16-6D32-4FE6-8A56-BBB695989046} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4FE6-8A56-BBB695989046}\ not found. File C:\Programme\ICQ6Toolbar\ICQToolBar.dll not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{B99F805C-F0B1-48EA-8C8B-753BFCBED912} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B99F805C-F0B1-48EA-8C8B-753BFCBED912}\ not found. File C:\Programme\Reify Software\Turnabout\turnabout.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\toolbar_eula_launcher not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA} not found. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Add to Windows &Live Favorites\ deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! D:\AUTORUN.INF moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0255f92b-796d-11df-8600-001583122a35}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0255f92b-796d-11df-8600-001583122a35}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{0255f92b-796d-11df-8600-001583122a35}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0255f92b-796d-11df-8600-001583122a35}\ not found. File F:\Startme.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{79750547-bcbc-11df-b95a-001583122a35}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{79750547-bcbc-11df-b95a-001583122a35}\ not found. File G:\setupSNK.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f5ff8de1-996f-11df-ae43-001583122a35}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f5ff8de1-996f-11df-ae43-001583122a35}\ not found. File C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL F:\Autostart.exe not found. C:\Windows\Tasks\Google Software Updater.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully. C:\Users\Fabi\AppData\Local\rebur_navps.dat moved successfully. C:\Users\Fabi\AppData\Local\rebur_nav.dat moved successfully. C:\Users\Fabi\AppData\Local\rebur.dat moved successfully. C:\Users\Fabi\AppData\Local\wgqzcsc.bat moved successfully. C:\Users\Fabi\AppData\Local\dqgvrfuc.bat moved successfully. C:\Users\Fabi\AppData\Local\amylxk_navps.dat moved successfully. C:\Users\Fabi\AppData\Local\cfvro.bat moved successfully. ADS C:\ProgramData\TEMP:8643C5BE deleted successfully. ADS C:\ProgramData\TEMP:551E1CB4 deleted successfully. ADS C:\ProgramData\TEMP:2FF4577A deleted successfully. ADS C:\ProgramData\TEMP:08993BCD deleted successfully. ADS C:\ProgramData\TEMP:77846FFE deleted successfully. ADS C:\ProgramData\TEMP:A08FFD4D deleted successfully. ADS C:\ProgramData\TEMP:41C283B2 deleted successfully. ADS C:\ProgramData\TEMP:E6683E95 deleted successfully. ADS C:\ProgramData\TEMP:CBEB737E deleted successfully. ADS C:\ProgramData\TEMP:002640E3 deleted successfully. ADS C:\ProgramData\TEMP:F791B5EF deleted successfully. ADS C:\ProgramData\TEMP:FD444D31 deleted successfully. ADS C:\ProgramData\TEMP:273A8657 deleted successfully. ADS C:\ProgramData\TEMP:38317199 deleted successfully. ADS C:\ProgramData\TEMP:51A22C60 deleted successfully. ADS C:\ProgramData\TEMP:A23D24E7 deleted successfully. ADS C:\ProgramData\TEMP:74B502CB deleted successfully. ADS C:\ProgramData\TEMP:7079A696 deleted successfully. ADS C:\ProgramData\TEMP:F62CAE78 deleted successfully. ADS C:\ProgramData\TEMP:E1F04E8D deleted successfully. ADS C:\ProgramData\TEMP:AD171C9E deleted successfully. ADS C:\ProgramData\TEMP:895798AD deleted successfully. ADS C:\ProgramData\TEMP:4C509008 deleted successfully. ADS C:\ProgramData\TEMP:26946BE8 deleted successfully. ADS C:\ProgramData\TEMP:F50F1555 deleted successfully. ADS C:\ProgramData\TEMP:EB603FE4 deleted successfully. ADS C:\ProgramData\TEMP:CBCE0A92 deleted successfully. ADS C:\ProgramData\TEMP:79F970BE deleted successfully. ADS C:\ProgramData\TEMP:87FA5E8A deleted successfully. ADS C:\ProgramData\TEMP:30C46519 deleted successfully. ADS C:\ProgramData\TEMP:1941675B deleted successfully. ADS C:\ProgramData\TEMP:128A6DC9 deleted successfully. ADS C:\ProgramData\TEMP:4F58D818 deleted successfully. ADS C:\ProgramData\TEMP:25005EFA deleted successfully. ADS C:\ProgramData\TEMP:0EE601C7 deleted successfully. ADS C:\ProgramData\TEMP:F86CC73E deleted successfully. ADS C:\ProgramData\TEMP:DCDE7C60 deleted successfully. ADS C:\ProgramData\TEMP:76986D86 deleted successfully. ADS C:\ProgramData\TEMP:FD6B3FC3 deleted successfully. ADS C:\ProgramData\TEMP:E54FA796 deleted successfully. ADS C:\ProgramData\TEMP:8FBE0E9C deleted successfully. ADS C:\ProgramData\TEMP:226A6E31 deleted successfully. ADS C:\ProgramData\TEMP:BDB40AA4 deleted successfully. ADS C:\ProgramData\TEMP:B54102AD deleted successfully. ADS C:\ProgramData\TEMP:95B7F1EC deleted successfully. ADS C:\ProgramData\TEMP:7091055F deleted successfully. ADS C:\ProgramData\TEMP:666FB4AA deleted successfully. ADS C:\ProgramData\TEMP:5711EF65 deleted successfully. ADS C:\ProgramData\TEMP:00C31200 deleted successfully. ADS C:\ProgramData\TEMP:D66B5EAE deleted successfully. ADS C:\ProgramData\TEMP:6DD87D86 deleted successfully. ADS C:\ProgramData\TEMP:3A925163 deleted successfully. ADS C:\ProgramData\TEMP:3612C9BE deleted successfully. ADS C:\ProgramData\TEMP:05816AFA deleted successfully. ADS C:\ProgramData\TEMP:A696643D deleted successfully. ADS C:\ProgramData\TEMP:93DE1838 deleted successfully. ADS C:\ProgramData\TEMP:42228396 deleted successfully. ADS C:\ProgramData\TEMP:1C9565AC deleted successfully. ADS C:\ProgramData\TEMP:158CC5FF deleted successfully. ADS C:\ProgramData\TEMP:A94968B5 deleted successfully. ADS C:\ProgramData\TEMP:A4AD016E deleted successfully. ADS C:\ProgramData\TEMP:81ED9272 deleted successfully. ADS C:\ProgramData\TEMP:75F5C19E deleted successfully. ADS C:\ProgramData\TEMP:43AA121F deleted successfully. ADS C:\ProgramData\TEMP:052A05A1 deleted successfully. ADS C:\ProgramData\TEMP:E6B9E5A3 deleted successfully. ADS C:\ProgramData\TEMP:E36F5B57 deleted successfully. ADS C:\ProgramData\TEMP:5C270C64 deleted successfully. ADS C:\ProgramData\TEMP:20B17557 deleted successfully. ADS C:\ProgramData\TEMP:0B61DB9F deleted successfully. ADS C:\ProgramData\TEMP:0651F96C deleted successfully. ADS C:\ProgramData\TEMP:F264BECE deleted successfully. ADS C:\ProgramData\TEMP:E5AFE07D deleted successfully. ADS C:\ProgramData\TEMP:D26DD363 deleted successfully. ADS C:\ProgramData\TEMP:BB8F0982 deleted successfully. ADS C:\ProgramData\TEMP:B723C5EF deleted successfully. ADS C:\ProgramData\TEMP:776E54F2 deleted successfully. ADS C:\ProgramData\TEMP:710F4DBF deleted successfully. ADS C:\ProgramData\TEMP:5466F106 deleted successfully. ADS C:\ProgramData\TEMP:3780BCC3 deleted successfully. ADS C:\ProgramData\TEMP:EA2FBCA1 deleted successfully. ADS C:\ProgramData\TEMP:CDFF58FE deleted successfully. ADS C:\ProgramData\TEMP:9FE30AB2 deleted successfully. ADS C:\ProgramData\TEMP:36B6EC9F deleted successfully. ADS C:\ProgramData\TEMP:33553E61 deleted successfully. ADS C:\ProgramData\TEMP:162E02F7 deleted successfully. ADS C:\ProgramData\TEMP:DAFD38AE deleted successfully. ADS C:\ProgramData\TEMP:700CD00E deleted successfully. ADS C:\ProgramData\TEMP:6C491D31 deleted successfully. ADS C:\ProgramData\TEMP:1AF93AF4 deleted successfully. ADS C:\ProgramData\TEMP:F02F4882 deleted successfully. ADS C:\ProgramData\TEMP:AD79E1D8 deleted successfully. ADS C:\ProgramData\TEMP:9B52F176 deleted successfully. ADS C:\ProgramData\TEMP:4E903DEB deleted successfully. ADS C:\ProgramData\TEMP:3B00070D deleted successfully. ADS C:\ProgramData\TEMP:38849DE5 deleted successfully. ADS C:\ProgramData\TEMP:34FC1C45 deleted successfully. ADS C:\ProgramData\TEMP:2B4E9D93 deleted successfully. ADS C:\ProgramData\TEMP:D8A7F3FF deleted successfully. ADS C:\ProgramData\TEMP:D61069DE deleted successfully. ADS C:\ProgramData\TEMP:AA004D25 deleted successfully. ADS C:\ProgramData\TEMP:7DFDF9DF deleted successfully. ADS C:\ProgramData\TEMP:426796C0 deleted successfully. ADS C:\ProgramData\TEMP:3447AB86 deleted successfully. ADS C:\ProgramData\TEMP:3214A283 deleted successfully. ADS C:\ProgramData\TEMP:B14B4A95 deleted successfully. ADS C:\ProgramData\TEMP:93C494CA deleted successfully. ADS C:\ProgramData\TEMP:588B60C7 deleted successfully. ADS C:\ProgramData\TEMP:558C8E0A deleted successfully. ADS C:\ProgramData\TEMP:91973ED2 deleted successfully. ADS C:\ProgramData\TEMP:5C07C19F deleted successfully. ADS C:\ProgramData\TEMP:DFC5A2B2 deleted successfully. ADS C:\ProgramData\TEMP:949483BD deleted successfully. ADS C:\ProgramData\TEMP:6641B59F deleted successfully. ADS C:\ProgramData\TEMP:FA5F15C4 deleted successfully. ADS C:\ProgramData\TEMP:A42A9F39 deleted successfully. ADS C:\ProgramData\TEMP:9A7901A9 deleted successfully. ADS C:\ProgramData\TEMP:943D6A82 deleted successfully. ADS C:\ProgramData\TEMP:07536DA3 deleted successfully. ADS C:\ProgramData\TEMP:E71141D2 deleted successfully. ADS C:\ProgramData\TEMP:4D7FCCD3 deleted successfully. ADS C:\ProgramData\TEMP:21745EE1 deleted successfully. ADS C:\ProgramData\TEMP:ADE16379 deleted successfully. ADS C:\ProgramData\TEMP:997E6AF4 deleted successfully. ADS C:\ProgramData\TEMP:61E5F0F7 deleted successfully. ADS C:\ProgramData\TEMP:48F0FFF8 deleted successfully. ADS C:\ProgramData\TEMP:375E3FC4 deleted successfully. ADS C:\ProgramData\TEMP:27AD48A5 deleted successfully. ADS C:\ProgramData\TEMP:77F07255 deleted successfully. ADS C:\ProgramData\TEMP:4F636E25 deleted successfully. ADS C:\ProgramData\TEMP:30376ACC deleted successfully. ADS C:\ProgramData\TEMP:54BAC9A7 deleted successfully. ADS C:\ProgramData\TEMP:2B8FEE50 deleted successfully. ADS C:\ProgramData\TEMP:5EBA4934 deleted successfully. ADS C:\ProgramData\TEMP:492679C1 deleted successfully. ADS C:\ProgramData\TEMP:1CB8D545 deleted successfully. ADS C:\ProgramData\TEMP:E1982A23 deleted successfully. ADS C:\ProgramData\TEMP:6F1F1DBC deleted successfully. ADS C:\ProgramData\TEMP:41099CE9 deleted successfully. ADS C:\ProgramData\TEMP:345E21F6 deleted successfully. ADS C:\ProgramData\TEMP:1CB3187E deleted successfully. ADS C:\ProgramData\TEMP:1B1330FD deleted successfully. ADS C:\ProgramData\TEMP:F951183D deleted successfully. ADS C:\ProgramData\TEMP:CE7C61DF deleted successfully. ADS C:\ProgramData\TEMP:A69F57F3 deleted successfully. ADS C:\ProgramData\TEMP:3064D21D deleted successfully. ADS C:\ProgramData\TEMP:CF5C4195 deleted successfully. ADS C:\ProgramData\TEMP:D690C7F7 deleted successfully. ADS C:\ProgramData\TEMP:BB48E5A3 deleted successfully. ADS C:\ProgramData\TEMP:9335E3B6 deleted successfully. ADS C:\ProgramData\TEMP:6A18D1F5 deleted successfully. ADS C:\ProgramData\TEMP:F5BB3657 deleted successfully. ADS C:\ProgramData\TEMP:ABE89FFE deleted successfully. ADS C:\ProgramData\TEMP:9AB338B9 deleted successfully. ADS C:\ProgramData\TEMP:9A221D63 deleted successfully. ADS C:\ProgramData\TEMP:765C6A14 deleted successfully. ADS C:\ProgramData\TEMP:37CE0F2E deleted successfully. ADS C:\ProgramData\TEMP:126591AF deleted successfully. ADS C:\ProgramData\TEMP:0207B271 deleted successfully. ADS C:\ProgramData\TEMP:B6FA1F20 deleted successfully. ADS C:\ProgramData\TEMP:87E0E06D deleted successfully. ADS C:\ProgramData\TEMP:7FC64998 deleted successfully. ADS C:\ProgramData\TEMP:DF2EA4BB deleted successfully. ADS C:\ProgramData\TEMP:615435BE deleted successfully. ADS C:\ProgramData\TEMP:567AC0A6 deleted successfully. ADS C:\ProgramData\TEMP:12A8EFF7 deleted successfully. ADS C:\ProgramData\TEMP:919B0931 deleted successfully. ADS C:\ProgramData\TEMP:6A97C459 deleted successfully. ========== REGISTRY ========== Registry key Invalid\\"TCP Query User{0F5DA350-6BA4-4B87-AB29-DC7802FDB098}C:\program files\emule\emule.exe" \ not found. Registry key Invalid\\"TCP Query User{A0B0E0E5-04EC-44CD-A7C6-846D7810BB31}C:\program files\emule\emule.exe" \ not found. Registry key Invalid\\"UDP Query User{AC0ED212-C3CF-4A96-9402-1ED730BAF584}C:\program files\emule\emule.exe" \ not found. Registry key Invalid\\"UDP Query User{FE6EE0E9-D6C8-4AA6-9A17-1C52C54A7F9A}C:\program files\emule\emule.exe" \ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\\cfvro not found. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Fabi ->Temp folder emptied: 43316497 bytes ->Temporary Internet Files folder emptied: 4401742 bytes ->Java cache emptied: 3965190 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 2875511 bytes User: Gast ->Temp folder emptied: 79772 bytes ->Temporary Internet Files folder emptied: 209733 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 123650 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 52,00 mb Error: Unable to interpret < und füge es hier ein: > in the current context! OTL by OldTimer - Version 3.2.31.0 log created on 01102012_173136 Files\Folders moved on Reboot... Registry entries deleted on Reboot... |
![]() | #7 |
![]() | ![]() Windowssystem gesperrt - Virus 10.: Code:
ATTFilter SUPERAntiSpyware Scan Log hxxp://www.superantispyware.com Generated 01/10/2012 at 07:31 PM Application Version : 5.0.1142 Core Rules Database Version : 8118 Trace Rules Database Version: 5930 Scan type : Complete Scan Total Scan Time : 01:40:02 Operating System Information Windows Vista Home Premium 32-bit (Build 6.00.6000) UAC On - Limited User (Administrator User) Memory items scanned : 702 Memory threats detected : 0 Registry items scanned : 37495 Registry threats detected : 5 File items scanned : 42918 File threats detected : 2 Registry Cleaner Trial HKCR\Install.Install HKCR\Install.Install\CLSID HKCR\Install.Install\CurVer HKCR\Install.Install.1 HKCR\Install.Install.1\CLSID Adware.Tracking Cookie C:\USERS\FABI\AppData\Roaming\Microsoft\Windows\Cookies\Low\fabi@doubleclick[2].txt [ Cookie:fabi@doubleclick.net/ ] Trojan.Agent/Gen-Autoit C:\PROGRAM FILES\SONY ERICSSON\SONY ERICSSON PC SUITE\PC SUITE LOG.EXE |
![]() |
Themen zu Windowssystem gesperrt - Virus |
32bit, abend, abgesicherte, abgesicherten, abgesicherten modus, bezahlung, euro, freischalten, freue, gesperrt, gmer, konnte, könntet, laptop, loszuwerden, mehrfach, meldung, modus, neustart, nichts, scan, schonmal, sicherheitsgründen, virus, windowssystem gesperrt, windowssystem gesperrt virus bezahlen entfernen, würde |