![]() |
|
Log-Analyse und Auswertung: Gema Virus od. TrojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #7 |
| ![]() Gema Virus od. Trojaner ========== OTL ========== Registry value HKEY_USERS\Chri_ON_C\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. Registry value HKEY_USERS\Chri_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\{47792B40-170F-B24A-9238-4253CDFACE6A} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47792B40-170F-B24A-9238-4253CDFACE6A}\ not found. Registry value HKEY_USERS\Chri_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\EA Core deleted successfully. Registry value HKEY_USERS\Chri_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\Firewall Administrating deleted successfully. Registry value HKEY_USERS\Chri_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\KeApplet deleted successfully. C:\Dokumente und Einstellungen\Chri\Anwendungsdaten\Skype\{3DA63AF9-6672-4922-B9E9-63252B523F9F}\LicenseValidator.exe moved successfully. Registry value HKEY_USERS\Chri_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\vasja deleted successfully. Registry value HKEY_USERS\Chri_ON_C\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\Load:C:\DOKUME~1\Chri\LOKALE~1\Temp\71577B5E54A420DA63F5.exe deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\HonorAutoRunSetting deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegedit deleted successfully. Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_USERS\Chri_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_USERS\Chri_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully. Registry value HKEY_USERS\Chri_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegedit deleted successfully. Registry value HKEY_USERS\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_USERS\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\WINDOWS\system32\E3ACF07154A420DAA1C3.exe deleted successfully. C:\WINDOWS\system32\E3ACF07154A420DAA1C3.exe moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\ deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\AUTOEXEC.BAT moved successfully. C:\Dokumente und Einstellungen\Chri\Anwendungsdaten\Cyicbo folder moved successfully. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTLPE by OldTimer - Version 3.1.48.0 log created on 03262012_220347 die movedfile.zip - Datei habe ich nun auch hochgeladen ! Ich kann zudem meine Icons auf dem Desktop nicht bewegen ): |
Themen zu Gema Virus od. Trojaner |
.dll, 0x00000001, alternate, antivir, avira, bonjour, converter, desktop, device driver, disabletaskmgr, einstellungen, explorer, firefox, format, logfile, mp3, realtek, registry, rundll, scan, software, stick, temp, trojane, trojaner, usb, version=1.0, virus, windows, windows xp |