|
Log-Analyse und Auswertung: GVU Trojaner - Win7Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
04.08.2012, 15:35 | #1 |
| GVU Trojaner - Win7 huhu, hab mir vorhin diesen ollen gvu-trojaner eingefangen. nach anfänglichem schock hab ich dann hierher gefunden und hoffe dass ihr mir helfen könnt. habe das programm otl geladen und mal durchlaufen lassen. die logs hab ich angehangen. habe meinen wlan-stick rausgezogen, damit ich den pc weiter nutzen kann. anders wusste ich mir nich zu helfen,nachdem ich mich ein bisschen schlau gemacht hatte. zum download weiterer programme steht mir ein weiterer pc zur verfügung. oder ich krieg n tipp, wie ich mit meinem pc und dem trojaner drauf mein inet weiter nutzen kann ^^ Geändert von lilli21 (04.08.2012 um 15:41 Uhr) |
04.08.2012, 16:06 | #2 |
/// Helfer-Team | GVU Trojaner - Win7Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\rdvgkmd.sys -- (VGPU) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\drivers\tsusbhub.sys -- (tsusbhub) DRV - File not found [Kernel | On_Demand | Stopped] -- System32\drivers\synth3dvsc.sys -- (Synth3dVsc) DRV - File not found [Kernel | On_Demand | Stopped] -- D:\NTIOLib.sys -- (NTIOLib_1_0_C) IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKLM\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=GRfox000&ptb=4z5zzD9OFqJHH7SVUd9MaA&ind=2010071314&ptnrS=GRfox000&si=&n=77cf4112&psa=&st=sb&searchfor={searchTerms} IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1 IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = Alice:80 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 1 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = Alice:80 IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\SearchScopes,DefaultScope = {56256A51-B582-467e-B8D4-7786EDA79AE0} IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}: "URL" = http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=GRfox000&ptb=4z5zzD9OFqJHH7SVUd9MaA&ind=2010071314&ptnrS=GRfox000&si=&n=77cf4112&psa=&st=sb&searchfor={searchTerms} IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms} IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9}: "URL" = http://www.daemon-search.com/search?q={searchTerms} IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\SearchScopes\{AE8BC07D-3D59-40FF-98B1-253537917C60}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=LOL&o=16439&src=crm&q={searchTerms}&locale=&apn_ptnrs=OY&apn_dtid=YYYYYYYYDE&apn_uid=2F447C74-9EE8-4B1F-8245-EEA94DD3E6EC&apn_sauid=A2D8D642-A247-4AE2-BDD1-EAC817C5DDE1 IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = alice:80 FF - prefs.js..browser.search.defaultengine: "Ask.com" FF - prefs.js..browser.search.defaultenginename: "Ask.com" FF - prefs.js..browser.search.order.1: "Ask.com" FF - prefs.js..browser.search.order.2: "1und1 Suche" FF - prefs.js..browser.search.order.3: "amazon.de" FF - prefs.js..browser.search.order.4: "WEB.DE Suche" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.search.useDBForOrder: true FF - prefs.js..browser.startup.homepage: "http://www.facebook.com/" FF - prefs.js..extensions.enabledItems: toolbar@ask.com:3.11.0.100005 FF - prefs.js..keyword.URL: "http://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=GRfox000&ptb=4z5zzD9OFqJHH7SVUd9MaA&ind=2010071314&ptnrS=GRfox000&si=&n=77cf4112&psa=&st=kwd&searchfor=" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found O3 - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\Toolbar\WebBrowser: (no name) - {32099AAC-C132-4136-9E9A-4E364A424E17} - No CLSID value found. O3 - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\..\Toolbar\WebBrowser: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found. O4 - HKLM..\Run: [snpstd3] C:\Windows\vsnpstd3.exe () O4 - HKLM..\Run: [tsnpstd3] C:\Windows\tsnpstd3.exe () O4 - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000..\Run: [Facebook Update] C:\Users\EiLa\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2009.04.29 11:02:01 | 000,000,055 | R--- | M] () - D:\autorun.inf -- [ CDFS ] O33 - MountPoints2\{2bd15933-c88f-11de-b488-fc97f4fd9540}\Shell - "" = AutoRun O33 - MountPoints2\{674b2118-9933-11e1-8427-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{674b2118-9933-11e1-8427-806e6f6e6963}\Shell\AutoRun\command - "" = D:\DVDSetup.exe O33 - MountPoints2\{911558e3-a3ba-11df-9a4f-db38cce6354e}\Shell - "" = AutoRun O33 - MountPoints2\{911558e3-a3ba-11df-9a4f-db38cce6354e}\Shell\AutoRun\command - "" = F:\autorun.exe O33 - MountPoints2\{98140266-b736-11e0-8aaa-a4d2f637f396}\Shell - "" = AutoRun O33 - MountPoints2\{98140266-b736-11e0-8aaa-a4d2f637f396}\Shell\AutoRun\command - "" = E:\LaunchU3.exe -a O33 - MountPoints2\{c65d2c29-c815-11de-b497-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{c65d2c29-c815-11de-b497-806e6f6e6963}\Shell\AutoRun\command - "" = D:\autorun.exe [2012.08.04 15:57:49 | 004,503,728 | ---- | M] () -- C:\ProgramData\ras_0oed.pad [2012.08.04 15:14:40 | 004,503,728 | ---- | M] () -- C:\ProgramData\23lldnur.pad [2012.08.04 15:08:26 | 000,001,883 | ---- | M] () -- C:\Users\EiLa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk @Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:D1B5B4F1 [2010.03.15 21:58:11 | 000,000,000 | ---D | M] (Update Notifier) -- C:\Program Files\Mozilla Firefox\extensions\{95f24680-9e31-11da-a746-0800200c9a66} [2010.03.15 21:58:11 | 000,000,000 | ---D | M] (WEB.DE Firefox Addon) -- C:\Program Files\Mozilla Firefox\extensions\{a82d0125-000a-4a57-abbc-5d4b0dbaab54} [2012.08.04 16:19:17 | 000,001,094 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job [2012.08.04 16:08:27 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2012.08.04 15:58:11 | 000,001,090 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job [2012.08.04 15:59:45 | 000,010,288 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2012.08.04 15:59:45 | 000,010,288 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2012.08.03 19:42:01 | 000,001,134 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1398726743-2837821600-1242578985-1000UA.job [2012.07.22 22:42:01 | 000,001,112 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1398726743-2837821600-1242578985-1000Core.job :Files ipconfig /flushdns /c :Commands [purity] [emptytemp] [emptyflash]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!
__________________ |
04.08.2012, 16:33 | #3 |
| GVU Trojaner - Win7 danke für die schnelle antwort.
__________________mit deinem fix hats geklappt. hier kommt der log. Code:
ATTFilter All processes killed ========== OTL ========== Service VGPU stopped successfully! Service VGPU deleted successfully! File System32\drivers\rdvgkmd.sys not found. Service tsusbhub stopped successfully! Service tsusbhub deleted successfully! File system32\drivers\tsusbhub.sys not found. Service Synth3dVsc stopped successfully! Service Synth3dVsc deleted successfully! File System32\drivers\synth3dvsc.sys not found. Service NTIOLib_1_0_C stopped successfully! Service NTIOLib_1_0_C deleted successfully! File D:\NTIOLib.sys not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56256A51-B582-467e-B8D4-7786EDA79AE0}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! HKEY_USERS\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_USERS\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{56256A51-B582-467e-B8D4-7786EDA79AE0}\ not found. Registry key HKEY_USERS\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}\ not found. Registry key HKEY_USERS\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB9}\ not found. Registry key HKEY_USERS\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Internet Explorer\SearchScopes\{AE8BC07D-3D59-40FF-98B1-253537917C60}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{AE8BC07D-3D59-40FF-98B1-253537917C60}\ not found. HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! Prefs.js: "Ask.com" removed from browser.search.defaultengine Prefs.js: "Ask.com" removed from browser.search.defaultenginename Prefs.js: "Ask.com" removed from browser.search.order.1 Prefs.js: "1und1 Suche" removed from browser.search.order.2 Prefs.js: "amazon.de" removed from browser.search.order.3 Prefs.js: "WEB.DE Suche" removed from browser.search.order.4 Prefs.js: "Google" removed from browser.search.selectedEngine Prefs.js: true removed from browser.search.useDBForOrder Prefs.js: "hxxp://www.facebook.com/" removed from browser.startup.homepage Prefs.js: toolbar@ask.com:3.11.0.100005 removed from extensions.enabledItems Prefs.js: "hxxp://search.mywebsearch.com/mywebsearch/GGmain.jhtml?id=GRfox000&ptb=4z5zzD9OFqJHH7SVUd9MaA&ind=2010071314&ptnrS=GRfox000&si=&n=77cf4112&psa=&st=kwd&searchfor=" removed from keyword.URL Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin\ deleted successfully. Registry value HKEY_USERS\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{32099AAC-C132-4136-9E9A-4E364A424E17} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{32099AAC-C132-4136-9E9A-4E364A424E17}\ not found. Registry value HKEY_USERS\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\snpstd3 deleted successfully. C:\Windows\vsnpstd3.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\tsnpstd3 deleted successfully. C:\Windows\tsnpstd3.exe moved successfully. Registry value HKEY_USERS\S-1-5-21-1398726743-2837821600-1242578985-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Facebook Update deleted successfully. C:\Users\EiLa\AppData\Local\Facebook\Update\FacebookUpdate.exe moved successfully. Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot. Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. Registry value HKEY_USERS\S-1-5-21-1398726743-2837821600-1242578985-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. File move failed. D:\autorun.inf scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2bd15933-c88f-11de-b488-fc97f4fd9540}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2bd15933-c88f-11de-b488-fc97f4fd9540}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{674b2118-9933-11e1-8427-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{674b2118-9933-11e1-8427-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{674b2118-9933-11e1-8427-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{674b2118-9933-11e1-8427-806e6f6e6963}\ not found. File D:\DVDSetup.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{911558e3-a3ba-11df-9a4f-db38cce6354e}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{911558e3-a3ba-11df-9a4f-db38cce6354e}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{911558e3-a3ba-11df-9a4f-db38cce6354e}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{911558e3-a3ba-11df-9a4f-db38cce6354e}\ not found. File F:\autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{98140266-b736-11e0-8aaa-a4d2f637f396}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98140266-b736-11e0-8aaa-a4d2f637f396}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{98140266-b736-11e0-8aaa-a4d2f637f396}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{98140266-b736-11e0-8aaa-a4d2f637f396}\ not found. File E:\LaunchU3.exe -a not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c65d2c29-c815-11de-b497-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c65d2c29-c815-11de-b497-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c65d2c29-c815-11de-b497-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c65d2c29-c815-11de-b497-806e6f6e6963}\ not found. File D:\autorun.exe not found. C:\ProgramData\ras_0oed.pad moved successfully. C:\ProgramData\23lldnur.pad moved successfully. File C:\Users\EiLa\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk not found. ADS C:\ProgramData\TEMP:D1B5B4F1 deleted successfully. C:\Program Files\Mozilla Firefox\extensions\{95f24680-9e31-11da-a746-0800200c9a66}\defaults\preferences folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{95f24680-9e31-11da-a746-0800200c9a66}\defaults folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{95f24680-9e31-11da-a746-0800200c9a66}\components folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{95f24680-9e31-11da-a746-0800200c9a66}\chrome folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{95f24680-9e31-11da-a746-0800200c9a66} folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{a82d0125-000a-4a57-abbc-5d4b0dbaab54}\defaults\preferences folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{a82d0125-000a-4a57-abbc-5d4b0dbaab54}\defaults folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{a82d0125-000a-4a57-abbc-5d4b0dbaab54}\chrome\locale\de-DE folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{a82d0125-000a-4a57-abbc-5d4b0dbaab54}\chrome\locale folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{a82d0125-000a-4a57-abbc-5d4b0dbaab54}\chrome\content folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{a82d0125-000a-4a57-abbc-5d4b0dbaab54}\chrome folder moved successfully. C:\Program Files\Mozilla Firefox\extensions\{a82d0125-000a-4a57-abbc-5d4b0dbaab54} folder moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully. C:\Windows\Tasks\Adobe Flash Player Updater.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully. C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 moved successfully. C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 moved successfully. C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1398726743-2837821600-1242578985-1000UA.job moved successfully. C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1398726743-2837821600-1242578985-1000Core.job moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\EiLa\Desktop\cmd.bat deleted successfully. C:\Users\EiLa\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: EiLa ->Temp folder emptied: 227372740 bytes ->Temporary Internet Files folder emptied: 56979999 bytes ->Java cache emptied: 11644177 bytes ->FireFox cache emptied: 1171032819 bytes ->Google Chrome cache emptied: 6666014 bytes ->Flash cache emptied: 12824 bytes User: Gast ->Temp folder emptied: 53791 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 3460339 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 608872 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1.409,00 mb [EMPTYFLASH] User: Administrator User: All Users User: Default User: Default User User: EiLa ->Flash cache emptied: 0 bytes User: Gast User: Public Total Flash Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.43.0 log created on 08042012_174011 Files\Folders moved on Reboot... File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot. File move failed. D:\autorun.inf scheduled to be moved on reboot. File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot. Registry entries deleted on Reboot... Geändert von lilli21 (04.08.2012 um 16:53 Uhr) |
04.08.2012, 17:55 | #4 |
/// Helfer-Team | GVU Trojaner - Win7 Sehr gut! Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
04.08.2012, 22:40 | #5 |
| GVU Trojaner - Win7 läuft wieder. vielen dank! die logs sind im anhang. |
05.08.2012, 01:14 | #6 |
/// Helfer-Team | GVU Trojaner - Win7 Sehr gut!
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html
__________________ --> GVU Trojaner - Win7 |
05.08.2012, 13:48 | #7 |
| GVU Trojaner - Win7 also mein pc scheint sauber zu sein nach dem letzten malware-scan. da is nur iwas auf der externen von meinem freund, die ich grad dran hab. die logs wieder anbei. |
05.08.2012, 13:54 | #8 |
/// Helfer-Team | GVU Trojaner - Win7 Sehr gut! Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
05.08.2012, 17:21 | #9 |
| GVU Trojaner - Win7 das ganze is aber auch echt zeitintensiv ^^ |
05.08.2012, 20:24 | #10 |
/// Helfer-Team | GVU Trojaner - Win7 Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html |
05.08.2012, 21:08 | #11 |
| GVU Trojaner - Win7 vielen dank! wäre damit alles erledigt, was die trojaner-beseitigung angeht? |
06.08.2012, 02:41 | #12 |
/// Helfer-Team | GVU Trojaner - Win7 Sehr gut! damit bist Du sauber und entlassen! Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Aufräumen mit CCleaner Lasse mit CCleaner (Download) (Anleitung) Fehler in der
Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html |
06.08.2012, 09:20 | #13 |
| GVU Trojaner - Win7 alles erledigt. vielen vielen dank für die hilfe. ihr seid meine helden Geändert von lilli21 (06.08.2012 um 09:29 Uhr) |
Themen zu GVU Trojaner - Win7 |
cftmon.lnk, gefunde, geladen, go_0molg.pad, gvu trojaner, gvu trojaner 2.07, gvu trojaner entfernen, gvu trojaner mit webcam, gvu-trojaner, hoffe, programm, reveton.c, troja, trojaner, webcam gvu trojaner, webcamfenster, win, win7, wlan-stick |