|
Log-Analyse und Auswertung: Bundespolizei UkashWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
24.07.2012, 09:39 | #1 | |||
| Bundespolizei Ukash Hallo gestern abend kam bei mir, wie bei vielen anderen auch wie ich sehe, die "Meldung" der Bundespolizei und Ukash und 100 €...nach viel lesen und schauen habe ich Malwarebytes im abgesicherten Modus laufen lassen, das Ergebnis: Zitat:
Zitat:
Zitat:
Gruß Stephan |
25.07.2012, 02:27 | #2 |
/// Helfer-Team | Bundespolizei UkashFixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL SRV - (vToolbarUpdater11.2.0) -- C:\Programme\Gemeinsame Dateien\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe () SRV - (AVG Security Toolbar Service) -- C:\Programme\AVG\AVG10\Toolbar\ToolbarBroker.exe () DRV - (WDICA) -- File not found DRV - (PDRFRAME) -- File not found DRV - (PDRELI) -- File not found DRV - (PDFRAME) -- File not found DRV - (PDCOMP) -- File not found DRV - (PCIDump) -- File not found DRV - (lbrtfdc) -- File not found DRV - (i2omgmt) -- File not found DRV - (Changer) -- File not found IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}:{referrer:source?}&ie={inputEncoding}&oe={output Encoding}&sourceid=ie7 IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg-chrome&type=yahoo_avg_hs2-tb-web_chrome_us&p={searchTerms} FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Programme\DivX\DivX Player\npDivxPlayerPlugin.dll File not found FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Programme\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found. O4 - HKLM..\Run: [DivXUpdate] C:\Programme\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [esffewbiqydcsso] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe () O4 - HKLM..\Run: [HF_G_Jul] C:\Programme\AVG Secure Search\HF_G_Jul.exe () O4 - HKLM..\Run: [vProt] C:\Programme\AVG Secure Search\vprot.exe () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O32 - HKLM CDRom: AutoRun - 1 [2012.07.23 23:46:52 | 000,057,344 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe [2012.07.23 23:46:57 | 000,057,344 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe [2011.06.05 10:50:45 | 000,000,088 | RHS- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\D11D56C05D.sys [2012.07.10 18:05:00 | 000,003,728 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\avg-secure-search.xml [2012.03.25 12:02:14 | 000,001,105 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml [2012.03.25 12:02:14 | 000,001,178 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml [2012.03.25 12:02:14 | 000,006,805 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml [2012.03.25 12:02:14 | 000,001,153 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\eBay-de.xml [2012.03.25 12:02:14 | 000,002,252 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\bing.xml [2012.03.25 12:02:14 | 000,001,392 | ---- | M] () -- C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml [2012.07.24 01:52:36 | 000,000,500 | ---- | M] () -- C:\WINDOWS\tasks\Automatische Problemsuche.job [2012.07.24 01:52:36 | 000,000,500 | ---- | M] () -- C:\WINDOWS\Tasks\Automatische Problemsuche.job [2012.07.24 01:50:06 | 000,001,086 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job [2012.07.23 23:46:56 | 000,000,000 | ---D | C] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\zfznmnjqqtwfdon [2012.07.23 23:46:52 | 000,057,344 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe [2012.07.23 23:46:57 | 000,057,344 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe [2012.07.23 23:46:52 | 000,000,051 | ---- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\cxvefshvikfgylv [2012.07.23 23:46:58 | 000,000,000 | ---D | M] -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\zfznmnjqqtwfdon [2012.07.23 23:47:00 | 000,000,051 | ---- | M] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\cxvefshvikfgylv [2012.07.23 23:35:02 | 000,001,090 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job [2011.06.05 10:50:45 | 000,000,088 | RHS- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\D11D56C05D.sys [2011.06.05 10:50:44 | 000,002,828 | -HS- | C] () -- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\KGyGaAvL.sys :Files C:\Programme\Gemeinsame Dateien\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe C:\Programme\AVG\AVG10\Toolbar\ToolbarBroker.exe C:\Programme\mozilla firefox\searchplugins\avg-secure-search.xml C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml C:\Programme\mozilla firefox\searchplugins\eBay-de.xml C:\Programme\mozilla firefox\searchplugins\bing.xml C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml C:\Programme\DivX\DivX Update\DivXUpdate.exe C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe C:\Programme\AVG Secure Search\HF_G_Jul.exe C:\Programme\AVG Secure Search\vprot.exe C:\WINDOWS\tasks\Automatische Problemsuche.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\D11D56C05D.sys C:\WINDOWS\Tasks\Automatische Problemsuche.job ipconfig /flushdns /c :Commands [purity] [emptytemp] [emptyflash] [resethosts]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!
__________________ |
25.07.2012, 09:18 | #3 |
| Bundespolizei Ukash Hallo t'john, vielen Dank das du dich meiner annimmst
__________________Das Ergebnis des OTL Fixes ist: Code:
ATTFilter All processes killed ========== OTL ========== Service vToolbarUpdater11.2.0 stopped successfully! Service vToolbarUpdater11.2.0 deleted successfully! C:\Programme\Gemeinsame Dateien\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe moved successfully. Service AVG Security Toolbar Service stopped successfully! Service AVG Security Toolbar Service deleted successfully! C:\Programme\AVG\AVG10\Toolbar\ToolbarBroker.exe moved successfully. Service WDICA stopped successfully! Service WDICA deleted successfully! File File not found not found. Service PDRFRAME stopped successfully! Service PDRFRAME deleted successfully! File File not found not found. Service PDRELI stopped successfully! Service PDRELI deleted successfully! File File not found not found. Service PDFRAME stopped successfully! Service PDFRAME deleted successfully! File File not found not found. Service PDCOMP stopped successfully! Service PDCOMP deleted successfully! File File not found not found. Service PCIDump stopped successfully! Service PCIDump deleted successfully! File File not found not found. Service lbrtfdc stopped successfully! Service lbrtfdc deleted successfully! File File not found not found. Service i2omgmt stopped successfully! Service i2omgmt deleted successfully! File File not found not found. Service Changer stopped successfully! Service Changer deleted successfully! File File not found not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Search\\SearchAssistant| /E : value set successfully! HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully. C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully. File C:\Programme\Google\Update\1.3.21.115\npGoogleUpdate3.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate deleted successfully. C:\Programme\DivX\DivX Update\DivXUpdate.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\esffewbiqydcsso deleted successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\HF_G_Jul deleted successfully. C:\Programme\AVG Secure Search\HF_G_Jul.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\vProt deleted successfully. C:\Programme\AVG Secure Search\vprot.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\HonorAutoRunSetting deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe not found. File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe not found. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\D11D56C05D.sys moved successfully. C:\Programme\Mozilla Firefox\searchplugins\avg-secure-search.xml moved successfully. C:\Programme\Mozilla Firefox\searchplugins\yahoo-de.xml moved successfully. C:\Programme\Mozilla Firefox\searchplugins\wikipedia-de.xml moved successfully. C:\Programme\Mozilla Firefox\searchplugins\leo_ende_de.xml moved successfully. C:\Programme\Mozilla Firefox\searchplugins\eBay-de.xml moved successfully. C:\Programme\Mozilla Firefox\searchplugins\bing.xml moved successfully. C:\Programme\Mozilla Firefox\searchplugins\amazondotcom-de.xml moved successfully. C:\WINDOWS\tasks\Automatische Problemsuche.job moved successfully. File C:\WINDOWS\Tasks\Automatische Problemsuche.job not found. C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job moved successfully. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\zfznmnjqqtwfdon folder moved successfully. File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe not found. File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe not found. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\cxvefshvikfgylv moved successfully. Folder C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\zfznmnjqqtwfdon\ not found. File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\cxvefshvikfgylv not found. C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job moved successfully. File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\D11D56C05D.sys not found. C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\KGyGaAvL.sys moved successfully. ========== FILES ========== File\Folder C:\Programme\Gemeinsame Dateien\AVG Secure Search\vToolbarUpdater\11.2.0\ToolbarUpdater.exe not found. File\Folder C:\Programme\AVG\AVG10\Toolbar\ToolbarBroker.exe not found. File\Folder C:\Programme\mozilla firefox\searchplugins\avg-secure-search.xml not found. File\Folder C:\Programme\mozilla firefox\searchplugins\yahoo-de.xml not found. File\Folder C:\Programme\mozilla firefox\searchplugins\wikipedia-de.xml not found. File\Folder C:\Programme\mozilla firefox\searchplugins\leo_ende_de.xml not found. File\Folder C:\Programme\mozilla firefox\searchplugins\eBay-de.xml not found. File\Folder C:\Programme\mozilla firefox\searchplugins\bing.xml not found. File\Folder C:\Programme\mozilla firefox\searchplugins\amazondotcom-de.xml not found. File\Folder C:\Programme\DivX\DivX Update\DivXUpdate.exe not found. File\Folder C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe not found. File\Folder C:\Programme\AVG Secure Search\HF_G_Jul.exe not found. File\Folder C:\Programme\AVG Secure Search\vprot.exe not found. File\Folder C:\WINDOWS\tasks\Automatische Problemsuche.job not found. File\Folder C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job not found. File\Folder C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job not found. File\Folder C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\D11D56C05D.sys not found. File\Folder C:\WINDOWS\Tasks\Automatische Problemsuche.job not found. < ipconfig /flushdns /c > Windows-IP-Konfiguration Ein interner Fehler ist aufgetreten: Die Anforderung wird nicht unterstützt. Wenden Sie sich an den Microsoft Software Service, um weitere Hilfe zu erhalten. Zusätzliche Informationen: Der Hostname konnte nicht abgefragt werden. C:\Dokumente und Einstellungen\Administrator\Desktop\cmd.bat deleted successfully. C:\Dokumente und Einstellungen\Administrator\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: All Users User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33237 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33263 bytes User: Bianca ->Temp folder emptied: 5483303711 bytes ->Temporary Internet Files folder emptied: 1024727074 bytes ->Java cache emptied: 74182395 bytes ->FireFox cache emptied: 456432599 bytes ->Flash cache emptied: 3137715 bytes User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 54742561 bytes RecycleBin emptied: 88312 bytes Total Files Cleaned = 6.768,00 mb [EMPTYFLASH] User: Default User User: All Users User: NetworkService User: LocalService User: Bianca ->Flash cache emptied: 0 bytes User: Administrator Total Flash Files Cleaned = 0,00 mb C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.54.1 log created on 07252012_110258 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot... |
25.07.2012, 16:15 | #4 |
/// Helfer-Team | Bundespolizei Ukash Sehr gut! Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
25.07.2012, 17:05 | #5 |
| Bundespolizei Ukash Der Rechner läuft sehr gut, auf jeden Fall schon mal schneller als vorher und vor allem ohne "Hinweis der Bundespolizei" Malwarebytes lieferte mir: Code:
ATTFilter Malwarebytes Anti-Malware 1.62.0.1300 www.malwarebytes.org Database version: v2012.07.25.05 Windows XP Service Pack 2 x86 FAT32 Internet Explorer 8.0.6001.18702 Bianca :: BIS [administrator] 25.07.2012 18:25:27 mbam-log-2012-07-25 (18-25-27).txt Scan type: Full scan (C:\|D:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 240711 Time elapsed: 29 minute(s), 56 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 2 C:\System Volume Information\_restore{ACA3513C-5B7F-4B7E-A490-D3ED3EDA4876}\RP524\A0083939.exe (Trojan.Winlock.P) -> Quarantined and deleted successfully. C:\_OTL\MovedFiles\07252012_110258\C_Dokumente und Einstellungen\All Users\Anwendungsdaten\esffewbi.exe (Trojan.Winlock.P) -> Quarantined and deleted successfully. (end) Code:
ATTFilter # AdwCleaner v1.703 - Logfile created 07/25/2012 at 18:59:32 # Updated 20/07/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 2 (32 bits) # User : Bianca - BIS # Running from : C:\Dokumente und Einstellungen\Bianca\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Dokumente und Einstellungen\Bianca\Anwendungsdaten\AVG Secure Search Folder Found : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AVG Secure Search Folder Found : C:\Programme\AVG Secure Search Folder Found : C:\Programme\Gemeinsame Dateien\AVG Secure Search ***** [Registry] ***** Key Found : HKCU\Software\AVG Secure Search Key Found : HKLM\SOFTWARE\AVG Secure Search Key Found : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Found : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Key Found : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Key Found : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Found : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Found : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Found : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Value Found : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Found : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Found : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A3F2A195-0D11-463b-96BB-D2FF1B7490A1} Key Found : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Found : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Found : HKLM\SOFTWARE\Classes\CLSID\{ECD0ECC6-DCA4-4013-A915-12355AB70999} Key Found : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Found : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Found : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Found : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://isearch.avg.com/tab?cid={023027E9-F915-4E0F-BF4E-3919881107C0}&mid=8f855343984dd632004cf0d1860b96bd-0&lang=de&ds=AVG&pr=fr&d=2012-06-06 18:04:01&v=11.1.0.12&sap=nt ************************* AdwCleaner[R1].txt - [4088 octets] - [25/07/2012 18:59:32] ########## EOF - C:\AdwCleaner[R1].txt - [4216 octets] ########## |
25.07.2012, 17:20 | #6 |
/// Helfer-Team | Bundespolizei Ukash Sehr gut!
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html
__________________ --> Bundespolizei Ukash |
25.07.2012, 17:41 | #7 |
| Bundespolizei Ukash So, AdwCleaner ist durch, das Ergebnis: Code:
ATTFilter # AdwCleaner v1.703 - Logfile created 07/25/2012 at 19:32:09 # Updated 20/07/2012 by Xplode # Operating system : Microsoft Windows XP Service Pack 2 (32 bits) # User : Bianca - BIS # Running from : C:\Dokumente und Einstellungen\Bianca\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Dokumente und Einstellungen\Bianca\Anwendungsdaten\AVG Secure Search Folder Deleted : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AVG Secure Search Folder Deleted : C:\Programme\AVG Secure Search Folder Deleted : C:\Programme\Gemeinsame Dateien\AVG Secure Search ***** [Registry] ***** Key Deleted : HKCU\Software\AVG Secure Search Key Deleted : HKLM\SOFTWARE\AVG Secure Search Key Deleted : HKLM\SOFTWARE\Classes\AppID\ScriptHelper.EXE Key Deleted : HKLM\SOFTWARE\Classes\AppID\ViProtocol.DLL Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.BrowserWndAPI.1 Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj Key Deleted : HKLM\SOFTWARE\Classes\AVG Secure Search.PugiObj.1 Key Deleted : HKLM\SOFTWARE\Classes\PROTOCOLS\Handler\viprotocol Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi Key Deleted : HKLM\SOFTWARE\Classes\ScriptHelper.ScriptHelperApi.1 Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE Key Deleted : HKLM\SOFTWARE\Classes\ViProtocol.ViProtocolOLE.1 Key Deleted : HKLM\SOFTWARE\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [Avg@toolbar] ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{1FDFF5A2-7BB1-48E1-8081-7236812B12B2} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BB711CB0-C70B-482E-9852-EC05EBD71DBB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A3F2A195-0D11-463b-96BB-D2FF1B7490A1} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{B658800C-F66E-4EF3-AB85-6C0C227862A9} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{CC5AD34C-6F10-4CB3-B74A-C2DD4D5060A3} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{ECD0ECC6-DCA4-4013-A915-12355AB70999} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{74FB6AFD-DD77-4CEB-83BD-AB2B63E63C93} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{C2AC8A0E-E48E-484B-A71C-C7A937FAAB94} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{95B7759C-8C7F-4BF1-B163-73684A933233} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{C6FDD0C3-266A-4DC3-B459-28C697C44CDC} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{F25AF245-4A81-40DC-92F9-E9021F207706} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{95B7759C-8C7F-4BF1-B163-73684A933233} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{95B7759C-8C7F-4BF1-B163-73684A933233}] ***** [Internet Browsers] ***** -\\ Internet Explorer v8.0.6001.18702 Replaced : [HKLM\SOFTWARE\Microsoft\Internet Explorer\AboutURls - Tabs] = hxxp://isearch.avg.com/tab?cid={023027E9-F915-4E0F-BF4E-3919881107C0}&mid=8f855343984dd632004cf0d1860b96bd-0&lang=de&ds=AVG&pr=fr&d=2012-06-06 18:04:01&v=11.1.0.12&sap=nt --> hxxp://www.google.com ************************* AdwCleaner[R1].txt - [4217 octets] - [25/07/2012 18:59:32] AdwCleaner[S1].txt - [285 octets] - [25/07/2012 19:02:22] AdwCleaner[S2].txt - [4328 octets] - [25/07/2012 19:32:09] ########## EOF - C:\AdwCleaner[S2].txt - [4456 octets] ########## |
25.07.2012, 17:46 | #8 |
/// Helfer-Team | Bundespolizei Ukash Warum wurde es nie installiert? Jetzt installieren und mit Emsisoft fortfahren. |
26.07.2012, 01:23 | #9 |
| Bundespolizei Ukash Ich glaube das nicht installieren des SP3 hatte etwas mit der Funktion von Adobe Premiere 6 zu tun das auf dem Laptop hier mal von meiner Freundin betrieben wurde, bin mir aber nicht sicher und natürlich weiss sie es auch nicht mehr. So, jetzt endlich auch noch der Emsisoft Bericht: Code:
ATTFilter Emsisoft Anti-Malware - Version 6.6 Letztes Update: 26.07.2012 00:27:16 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, D:\ Archiv Scan: An ADS Scan: An Scan Beginn: 26.07.2012 00:29:12 Gescannt 522813 Gefunden 0 Scan Ende: 26.07.2012 02:04:53 Scan Zeit: 1:35:41 |
26.07.2012, 10:55 | #10 |
/// Helfer-Team | Bundespolizei Ukash Sehr gut! Lasse die Funde loeschen, dann: Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
26.07.2012, 13:24 | #11 |
| Bundespolizei Ukash Es ist unfassbar, mit jedem Scanner noch ein Fund...das ist langsam beängstigend. Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=4df5a5dfbbc2254988b3894079b8411e # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-07-26 01:14:32 # local_time=2012-07-26 03:14:32 (+0100, Westeuropäische Sommerzeit) # country="Germany" # lang=1031 # osver=5.1.2600 NT Service Pack 3 # compatibility_mode=1024 16777175 100 0 89747570 89747570 0 0 # compatibility_mode=8192 67108863 100 0 204 204 0 0 # scanned=59621 # found=1 # cleaned=1 # scan_time=7496 C:\_OTL\MovedFiles\07252012_110258\C_Dokumente und Einstellungen\All Users\Anwendungsdaten\zfznmnjqqtwfdon\main.html HTML/Ransom.B Trojaner (Gesäubert durch Löschen - in Quarantäne kopiert) 00000000000000000000000000000000 C |
26.07.2012, 14:54 | #12 |
/// Helfer-Team | Bundespolizei Ukash Der ist OK, das ist die Muelltonne von OTL Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html |
26.07.2012, 15:26 | #13 |
| Bundespolizei Ukash So, Java Update ist ausgeführt, alles ist eingestellt...jetzt ist Windows ganz aufgeregt weil es 64 Updates für mich hat |
26.07.2012, 15:40 | #14 |
/// Helfer-Team | Bundespolizei Ukash Alle einspielen! Dann wieder melden! |
26.07.2012, 16:09 | #15 |
| Bundespolizei Ukash So, damit ist alles auf dem aktuellen Stand. |
Themen zu Bundespolizei Ukash |
.dll, 32 bit, adobe flash player, avg, avg secure search, avg security toolbar, bho, browser, downloader, error, explorer, firefox, flash player, fontcache, format, helper, logfile, malwarebytes, microsoft, object, plug-in, realtek, registry, rundll, searchscopes, secure, secure search, security, software, temp, udp, vodafone, vtoolbarupdater, windows internet, winlogon |