|
Log-Analyse und Auswertung: GVU Trojaner W7 64bit HauptbenutzerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
17.08.2012, 14:57 | #1 |
| GVU Trojaner W7 64bit Hauptbenutzer GVU Trojaner ist nun in einem W7 64bit Hauptbenutzer aufgegangen. Folgend die 2 OTL-Dateien mit Scan Mode All users. Ist ein entfernen möglich? Danke für die Hilfe! |
17.08.2012, 15:49 | #2 |
/// Helfer-Team | GVU Trojaner W7 64bit HauptbenutzerFixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\..\SearchScopes,DefaultScope = {25995764-DD59-4F85-A0EB-8062A0E4659A} IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\..\SearchScopes\{2364258D-6A52-4FA2-915F-68AFD2FC2D43}: "URL" = http://go.1und1.de/tb/ie_searchplugin/?su={searchTerms} IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\..\SearchScopes\{25995764-DD59-4F85-A0EB-8062A0E4659A}: "URL" = http://www.google.de/search?q={searchTerms} IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\..\SearchScopes\{3CA0C5DD-A03B-41BE-AC3A-BAFA92BE98DE}: "URL" = http://go.gmx.net/tb/ie_searchplugin/?su={searchTerms} IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\..\SearchScopes\{CF80A181-48AB-4224-AA13-FADE104652AE}: "URL" = http://go.web.de/tb/ie_searchplugin/?su={searchTerms} IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\..\SearchScopes\{DB2EDAA6-B97E-4937-AE9B-2836D2C1B8AA}: "URL" = http://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\..\SearchScopes\{FC742DF6-CB55-4319-B3F6-16BA57CAE50A}: "URL" = http://www.google.de/search?q={searchTerms} IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1004\..\SearchScopes,DefaultScope = {FC742DF6-CB55-4319-B3F6-16BA57CAE50A} IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1004\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1004\..\SearchScopes\{FC742DF6-CB55-4319-B3F6-16BA57CAE50A}: "URL" = http://www.google.de/search?q={searchTerms} IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-500\..\SearchScopes,DefaultScope = {FC742DF6-CB55-4319-B3F6-16BA57CAE50A} IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-500\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-500\..\SearchScopes\{FC742DF6-CB55-4319-B3F6-16BA57CAE50A}: "URL" = http://www.google.de/search?q={searchTerms} IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2160241932-3726806340-4141075853-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local FF - user.js - File not found FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_268.dll File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}: C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox [2012.07.01 19:23:54 | 000,000,000 | ---D | M] O2 - BHO: (no name) - {1ED16E0A-E8C4-40A0-8BC2-79485D21F796} - No CLSID value found. O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [PWMTRV] rundll32 C:\PROGRA~2\ThinkPad\UTILIT~1\PWMTR64V.DLL,PwrMgrBkGndMonitor File not found O4 - HKU\S-1-5-21-2160241932-3726806340-4141075853-1000..\Run: [UpgradeHelper] C:\Users\M\AppData\Roaming\Opera\{1DB914E9-F81A-4D00-83A0-AF01E0BA6E12}\UpgradeHelper.exe File not found O4 - HKU\S-1-5-21-2160241932-3726806340-4141075853-1004..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O7 - HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2160241932-3726806340-4141075853-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O7 - HKU\S-1-5-21-2160241932-3726806340-4141075853-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab (Reg Error: Key error.) O16 - DPF: {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_intel_4.4.24.0.cab (Reg Error: Key error.) O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.) O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O33 - MountPoints2\{3b7ebfcb-8d74-11e0-ba9c-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{3b7ebfcb-8d74-11e0-ba9c-806e6f6e6963}\Shell\AutoRun\command - "" = D:\SETUP.EXE [2012.08.15 10:40:44 | 004,503,728 | ---- | M] () -- C:\ProgramData\ism_0_llatsni.pad :Files ipconfig /flushdns /c :Commands [purity] [emptytemp]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!
__________________ |
20.08.2012, 10:25 | #3 |
| GVU Trojaner W7 64bit HauptbenutzerCode:
ATTFilter All processes killed ========== OTL ========== HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Internet Explorer\SearchScopes\{2364258D-6A52-4FA2-915F-68AFD2FC2D43}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2364258D-6A52-4FA2-915F-68AFD2FC2D43}\ not found. Registry key HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Internet Explorer\SearchScopes\{25995764-DD59-4F85-A0EB-8062A0E4659A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{25995764-DD59-4F85-A0EB-8062A0E4659A}\ not found. Registry key HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Internet Explorer\SearchScopes\{3CA0C5DD-A03B-41BE-AC3A-BAFA92BE98DE}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3CA0C5DD-A03B-41BE-AC3A-BAFA92BE98DE}\ not found. Registry key HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CF80A181-48AB-4224-AA13-FADE104652AE}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF80A181-48AB-4224-AA13-FADE104652AE}\ not found. Registry key HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Internet Explorer\SearchScopes\{DB2EDAA6-B97E-4937-AE9B-2836D2C1B8AA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DB2EDAA6-B97E-4937-AE9B-2836D2C1B8AA}\ not found. Registry key HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Internet Explorer\SearchScopes\{FC742DF6-CB55-4319-B3F6-16BA57CAE50A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC742DF6-CB55-4319-B3F6-16BA57CAE50A}\ not found. HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1004\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1004\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1004\Software\Microsoft\Internet Explorer\SearchScopes\{FC742DF6-CB55-4319-B3F6-16BA57CAE50A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC742DF6-CB55-4319-B3F6-16BA57CAE50A}\ not found. HKU\S-1-5-21-2160241932-3726806340-4141075853-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-2160241932-3726806340-4141075853-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-500\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-500\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-500\Software\Microsoft\Internet Explorer\SearchScopes\{FC742DF6-CB55-4319-B3F6-16BA57CAE50A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{FC742DF6-CB55-4319-B3F6-16BA57CAE50A}\ not found. HKU\S-1-5-21-2160241932-3726806340-4141075853-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\S-1-5-21-2160241932-3726806340-4141075853-500\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@adobe.com/FlashPlayer\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{8AA36F4F-6DC7-4c06-77AF-5035170634FE} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AA36F4F-6DC7-4c06-77AF-5035170634FE}\ not found. C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox\components folder moved successfully. C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox\chrome folder moved successfully. C:\ProgramData\Swiss Academic Software\Citavi Picker\Firefox folder moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{1ED16E0A-E8C4-40A0-8BC2-79485D21F796}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1ED16E0A-E8C4-40A0-8BC2-79485D21F796}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\PWMTRV deleted successfully. Registry value HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1000\Software\Microsoft\Windows\CurrentVersion\Run\\UpgradeHelper deleted successfully. Registry value HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1004\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. Registry value HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-1004\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry value HKEY_USERS\S-1-5-21-2160241932-3726806340-4141075853-500\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Starting removal of ActiveX control {166B1BCA-3F9C-11CF-8075-444553540000} C:\Windows\Downloaded Program Files\swdir.inf moved successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{166B1BCA-3F9C-11CF-8075-444553540000}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{166B1BCA-3F9C-11CF-8075-444553540000}\ not found. Starting removal of ActiveX control {CF84DAC5-A4F5-419E-A0BA-C01FFD71112F} C:\Windows\Downloaded Program Files\SystemRequirementsLab.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CF84DAC5-A4F5-419E-A0BA-C01FFD71112F}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF84DAC5-A4F5-419E-A0BA-C01FFD71112F}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CF84DAC5-A4F5-419E-A0BA-C01FFD71112F}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CF84DAC5-A4F5-419E-A0BA-C01FFD71112F}\ not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} C:\Windows\Downloaded Program Files\gp.inf not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3b7ebfcb-8d74-11e0-ba9c-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3b7ebfcb-8d74-11e0-ba9c-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3b7ebfcb-8d74-11e0-ba9c-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3b7ebfcb-8d74-11e0-ba9c-806e6f6e6963}\ not found. File D:\SETUP.EXE not found. C:\ProgramData\ism_0_llatsni.pad moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\M\Desktop\cmd.bat deleted successfully. C:\Users\M\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Administrator ->Temp folder emptied: 1971341394 bytes ->Temporary Internet Files folder emptied: 78771154 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 18604361 bytes ->Flash cache emptied: 1432 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: M ->Temp folder emptied: 295542227 bytes ->Temporary Internet Files folder emptied: 4470629162 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 70776042 bytes ->Opera cache emptied: 2335060 bytes ->Flash cache emptied: 137517 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 392807494 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 6.963,00 mb OTL by OldTimer - Version 3.2.58.1 log created on 08202012_111230 |
20.08.2012, 13:54 | #4 |
/// Helfer-Team | GVU Trojaner W7 64bit Hauptbenutzer Sehr gut! Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
20.08.2012, 21:38 | #5 |
| GVU Trojaner W7 64bit Hauptbenutzer IE stürzt seit OTL öfter ab und geht dann mit dem abgestürzten Fenster 10-15 Mal auf. Ansonsten nichts ungewönhliches. 1. Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.20.09 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Administrator :: T [Administrator] Schutz: Deaktiviert 20.08.2012 22:17:37 mbam-log-2012-08-20 (22-29-11).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 430414 Laufzeit: 9 Minute(n), 1 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 1 C:\Users\Administrator\Desktop\produkey-1.53_x64\ProduKey.exe (PUP.PSWTool.ProductKey) -> Keine Aktion durchgeführt. (Ende) Code:
ATTFilter # AdwCleaner v1.801 - Logfile created 08/20/2012 at 22:33:32 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Professional Service Pack 1 (64 bits) # User : Administrator - T # Boot Mode : Normal # Running from : C:\Users\M\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** ***** [Registre - GUID] ***** ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\xqgjqu5s.default\prefs.js [OK] File is clean. Profile name : default File : C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\pgbr745h.default\prefs.js [OK] File is clean. ************************* AdwCleaner[R1].txt - [885 octets] - [20/08/2012 22:33:32] ########## EOF - \AdwCleaner[R1].txt - [1012 octets] ########## |
20.08.2012, 21:49 | #6 |
/// Helfer-Team | GVU Trojaner W7 64bit Hauptbenutzer Sehr gut!
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html
__________________ --> GVU Trojaner W7 64bit Hauptbenutzer |
20.08.2012, 22:28 | #7 |
| GVU Trojaner W7 64bit Hauptbenutzer 1. Nach dem Neustart öffnete sich keine Textdatei automatisch. Code:
ATTFilter # AdwCleaner v1.801 - Logfile created 08/20/2012 at 22:54:46 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Professional Service Pack 1 (64 bits) # User : Administrator - T # Boot Mode : Normal # Running from : C:\Users\M\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** ***** [Registry] ***** ***** [Registre - GUID] ***** ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\M\AppData\Roaming\Mozilla\Firefox\Profiles\xqgjqu5s.default\prefs.js [OK] File is clean. Profile name : default File : C:\Users\Administrator\AppData\Roaming\Mozilla\Firefox\Profiles\pgbr745h.default\prefs.js [OK] File is clean. ************************* AdwCleaner[S1].txt - [885 octets] - [20/08/2012 22:54:46] ########## EOF - \AdwCleaner[S1].txt - [1012 octets] ########## Code:
ATTFilter Emsisoft Anti-Malware - Version 6.6 Letztes Update: 20.08.2012 23:04:01 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\ Archiv Scan: An ADS Scan: An Scan Beginn: 20.08.2012 23:04:40 C:\Users\Administrator\Desktop\produkey-1.53_x64\ProduKey.exe gefunden: Riskware.PSWTool.Win64.ProduKey.AMN!E1 C:\Program Files\WinRAR\Zip.SFX gefunden: Trojan-Spy.Win32.Delf!E1 Gescannt 768870 Gefunden 2 Scan Ende: 20.08.2012 23:24:31 Scan Zeit: 0:19:51 |
20.08.2012, 22:48 | #8 |
/// Helfer-Team | GVU Trojaner W7 64bit Hauptbenutzer Sehr gut! Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
21.08.2012, 00:26 | #9 |
| GVU Trojaner W7 64bit HauptbenutzerCode:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=### # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-20 11:23:14 # local_time=2012-08-21 01:23:14 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=## # compatibility_mode=### # compatibility_mode=## # scanned=209659 # found=0 # cleaned=0 # scan_time=5183 |
21.08.2012, 03:18 | #10 |
/// Helfer-Team | GVU Trojaner W7 64bit Hauptbenutzer Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html Danach poste (kopieren und einfuegen) mir, was du hier angezeigt bekommst: PluginCheck |
21.08.2012, 09:27 | #11 |
| GVU Trojaner W7 64bit Hauptbenutzer Verstehe ich nicht. Diese V.7 U.5 ist installiert. Unter den Links ist nur die Java Version V.7 U.5 zu finden. Kein U.6 ... EDIT: Extra komplett deinstalliert und nochmals installiert: 7.0.50 und JavaFX 2.1.1 Es gibt trotzdem nur die Reiter Allgemein, Java, Sicherheit und Erweitert. Kein "Update" Reiter. Einstellungen somit mir nicht möglich. PluginCheck: Internet Explorer 9.0 ist aktuell Flash (11,3,300,271) ist aktuell. Java (1,7,0,5) ist aktuell. Adobe Reader 9,5,2,0 ist veraltet! #Ich habe keinen Reader installiert sondern Acrobat Pro 9.5.2. Aktualisieren Sie bitte auf die neueste Version: 10,1,3 Geändert von amerin (21.08.2012 um 09:56 Uhr) |
21.08.2012, 15:40 | #12 |
/// Helfer-Team | GVU Trojaner W7 64bit Hauptbenutzer Sehr gut! damit bist Du sauber und entlassen! adwCleaner entfernen
Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Systemwiederherstellungen leeren Damit der Rechner nicht mit einer infizierten Systemwiederherstellung erneut infiziert werden kann, muessen wir diese leeren. Dazu schalten wir sie einmal aus und dann wieder ein: Systemwiederherstellung deaktivieren Tutorial fuer Windows XP, Windows Vista, Windows 7 Danach wieder aktivieren. Aufräumen mit CCleaner Lasse mit CCleaner (Download) (Anleitung) Fehler in der
Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html PC wird immer langsamer - was tun? |
21.08.2012, 15:42 | #13 |
| GVU Trojaner W7 64bit Hauptbenutzer Danke! Nur noch die Frage: Warum sind bei mir diese Java-Update-Einstellungen nicht vorhanden? |
21.08.2012, 17:53 | #14 |
/// Helfer-Team | GVU Trojaner W7 64bit Hauptbenutzer Es gibt mehrere Varianten. Du hast wohl die Offline-Version. |
21.08.2012, 18:05 | #15 |
| GVU Trojaner W7 64bit Hauptbenutzer Das heißt die unter dem von Dir genannten Link abrufbare Version ist die Offline-Version? Und welcher Link führt direkt zur Online-Version? EDIT: gelöst: REG_DWORD EnableJavaUpdate mit 1 in In HKLM\Software\JavaSoft\Java Update\Policy. Geändert von amerin (21.08.2012 um 18:14 Uhr) |
Themen zu GVU Trojaner W7 64bit Hauptbenutzer |
64bit, benutzer, entferne, entfernen, gvu trojaner, hilfe!, scan, troja, trojaner |