|
Plagegeister aller Art und deren Bekämpfung: Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...)Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
21.08.2012, 21:52 | #1 |
| Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...) Liebe Trojaner-Boader Ich habe mir vor ein paar Tagen des Kaspersky Antivirus Pure 2.0 heruntergeladen und meinen Windows-Vista PC durchsuchen lassen. Dabei hat er auch eine Upgrade.exe datei gefunden die als schadhaft gekennzeichnet wurde sowie weitere schädliche Dateien, diese hatten aber nur irgendwelche zeichen als Namen. Diese führen jedoch als nach system32.../...Internet files. Ich hab den Mozilla Firefox als Browser. Ich benutze den PC eigentlich nicht oft, ich habe schon vor einiger Zeit auf Mac gewechselt, bin aber jedoch immer noch auf Windows angewiesen. Nach meinem Betriebssystemupdate von Mac funktioniert bei mir nun ein Windows Programm nicht mehr weshalb ich dafür auf den PC zurückgreifen will. Es sind darauf auch keine wichtigen Daten vorhanden, das es nur ein zweit PC ist. Ich möchte aber trotzdem dass er möglichst Virenfrei ist. Ich bin deshalb auch auf diese Seite gestossen und hab auch gleich mal alle schritte abgearbeitet die im Header stehen. Ich hab von Viren null ahnung und weiss auch nicht ob diese Upgrade.exe-Datei ein Maleware ist oder nicht. Das aber irgendwas drauf sein kann vermute ich schon, da ich wegen der seltenen Benutzung nicht immer ein Virenprogramm drauf hatte. Ich habe meine Logs wie beschrieben im Anhang angehängt. Hoffe jemand kann mir helfen und wenns aussichtslos ist nur sagen, dann lohnt sich die mühe nicht mehr. Liebe Grüsse! |
21.08.2012, 23:10 | #2 |
/// Helfer-Team | Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...)Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Ersetze die *** Sternchen wieder in den Benutzernamen zurück! Code:
ATTFilter :OTL SRV - [2012.07.26 19:40:56 | 000,794,560 | ---- | M] (Spigot, Inc.) [Auto | Running] -- C:\Program Files\Application Updater\ApplicationUpdater.exe -- (Application Updater) SRV - [2012.07.11 18:02:04 | 004,419,392 | ---- | M] () [Auto | Running] -- c:\program files\common files\akamai/netsession_win_4f7fccd.dll -- (Akamai) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt) DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp) DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive) IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKCU\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\6.2\pdfforgeToolbarIE.dll (Spigot, Inc.) IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?} IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=14149 IE - HKCU\..\SearchScopes\{6A926439-B41F-492E-B02E-402FF86C8ACE}: "URL" = http://www.google.de/search?q={searchTerms} IE - HKCU\..\SearchScopes\{F81135F2-CEC3-4E71-A7E9-1B900782D7ED}: "URL" = http://ch.search.yahoo.com/search?fr=chr-greentree_ie&ei=utf-8&ilc=12&type=827316&p={searchTerms} IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;127.0.0.1:9421; FF - prefs.js..browser.search.defaultenginename: "Search the web (Babylon)" FF - prefs.js..browser.search.defaulturl: "http://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=14149" FF - prefs.js..browser.search.order.1: "Search the web (Babylon)" FF - prefs.js..browser.search.param.yahoo-fr: "chr-greentree_ff&type=827316&ilc=12" FF - prefs.js..browser.search.selectedEngine: "Google" FF - prefs.js..browser.startup.homepage: "http://www.google.ch/firefox/" FF - prefs.js..extensions.enabledItems: personas@christopher.beard:1.6.1 FF - prefs.js..extensions.enabledItems: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3 FF - prefs.js..extensions.enabledItems: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 FF - prefs.js..extensions.enabledItems: {34EFA911-B536-4C08-BECE-CD5E55C875B0}:1.0 FF - prefs.js..keyword.URL: "http://ch.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=827316&p=" FF - user.js - File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\6.2\pdfforgeToolbarIE.dll (Spigot, Inc.) O2 - BHO: (Java(tm) Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll File not found O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files\pdfforge Toolbar\IE\6.2\pdfforgeToolbarIE.dll (Spigot, Inc.) O4 - HKLM..\Run: [] File not found O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [SearchSettings] C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.) O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\***\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc) O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 149 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 File not found O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ] O33 - MountPoints2\{8e71ef73-dc52-11df-8fd7-001fc638e1b6}\Shell - "" = AutoRun O33 - MountPoints2\{8e71ef73-dc52-11df-8fd7-001fc638e1b6}\Shell\AutoRun\command - "" = "E:\WD SmartWare.exe" autoplay=true [2012.08.20 23:09:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Temp [2012.08.21 18:50:58 | 000,045,056 | ---- | M] () -- C:\Windows\System32\acovcnt.exe @Alternate Data Stream - 171 bytes -> C:\ProgramData\Temp:DFC5A2B2 @Alternate Data Stream - 115 bytes -> C:\ProgramData\Temp:A8ADE5D8 [2012.08.03 19:00:20 | 000,000,000 | ---D | M] (Widgi Toolbar Platform) -- C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM [2012.07.31 19:12:58 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Spigot [2012.07.31 19:12:58 | 000,000,000 | ---D | C] -- C:\Program Files\pdfforge Toolbar :Files ipconfig /flushdns /c :Commands [purity] [emptytemp]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen!
__________________ |
22.08.2012, 18:14 | #3 |
| Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...) Vielen Vielen Dank für die schnelle Antwort. Habe die Anleitung befolgt. Hier das Log-File.
__________________Code:
ATTFilter All processes killed ========== OTL ========== Service Application Updater stopped successfully! Service Application Updater deleted successfully! C:\Program Files\Application Updater\ApplicationUpdater.exe moved successfully. Service Akamai stopped successfully! Service Akamai deleted successfully! c:\program files\common files\akamai/netsession_win_4f7fccd.dll moved successfully. Service NwlnkFwd stopped successfully! Service NwlnkFwd deleted successfully! File system32\DRIVERS\nwlnkfwd.sys not found. Service NwlnkFlt stopped successfully! Service NwlnkFlt deleted successfully! File system32\DRIVERS\nwlnkflt.sys not found. Service IpInIp stopped successfully! Service IpInIp deleted successfully! File system32\DRIVERS\ipinip.sys not found. Service blbdrive stopped successfully! Service blbdrive deleted successfully! File C:\Windows\system32\drivers\blbdrive.sys not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{B922D405-6D13-4A2B-AE89-08A030DA4402} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ deleted successfully. C:\Program Files\pdfforge Toolbar\IE\6.2\pdfforgeToolbarIE.dll moved successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A926439-B41F-492E-B02E-402FF86C8ACE}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A926439-B41F-492E-B02E-402FF86C8ACE}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{F81135F2-CEC3-4E71-A7E9-1B900782D7ED}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F81135F2-CEC3-4E71-A7E9-1B900782D7ED}\ not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! Prefs.js: "Search the web (Babylon)" removed from browser.search.defaultenginename Prefs.js: "hxxp://search.babylon.com/web/{searchTerms}?babsrc=browsersearch&AF=14149" removed from browser.search.defaulturl Prefs.js: "Search the web (Babylon)" removed from browser.search.order.1 Prefs.js: "chr-greentree_ff&type=827316&ilc=12" removed from browser.search.param.yahoo-fr Prefs.js: "Google" removed from browser.search.selectedEngine Prefs.js: "hxxp://www.google.ch/firefox/" removed from browser.startup.homepage Prefs.js: personas@christopher.beard:1.6.1 removed from extensions.enabledItems Prefs.js: {d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}:1.3.3 removed from extensions.enabledItems Prefs.js: {ACAA314B-EEBA-48e4-AD47-84E31C44796C}:1.0.1 removed from extensions.enabledItems Prefs.js: {34EFA911-B536-4C08-BECE-CD5E55C875B0}:1.0 removed from extensions.enabledItems Prefs.js: "hxxp://ch.search.yahoo.com/search?fr=greentree_ff1&ei=utf-8&ilc=12&type=827316&p=" removed from keyword.URL Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ not found. File C:\Program Files\pdfforge Toolbar\IE\6.2\pdfforgeToolbarIE.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DBC80044-A445-435b-BC74-9C25C1C588A9}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{B922D405-6D13-4A2B-AE89-08A030DA4402} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B922D405-6D13-4A2B-AE89-08A030DA4402}\ not found. File C:\Program Files\pdfforge Toolbar\IE\6.2\pdfforgeToolbarIE.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\DivXUpdate deleted successfully. C:\Program Files\DivX\DivX Update\DivXUpdate.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SearchSettings deleted successfully. C:\Program Files\Common Files\Spigot\Search Settings\SearchSettings.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Akamai NetSession Interface deleted successfully. C:\Users\***\AppData\Local\Akamai\netsession_win.exe moved successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully. Registry key HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\MenuExt\Nach Microsoft E&xel exportieren\ deleted successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8e71ef73-dc52-11df-8fd7-001fc638e1b6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e71ef73-dc52-11df-8fd7-001fc638e1b6}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8e71ef73-dc52-11df-8fd7-001fc638e1b6}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e71ef73-dc52-11df-8fd7-001fc638e1b6}\ not found. File "E:\WD SmartWare.exe" autoplay=true not found. C:\ProgramData\Temp folder moved successfully. C:\Windows\System32\acovcnt.exe moved successfully. Unable to delete ADS C:\ProgramData\Temp:DFC5A2B2 . Unable to delete ADS C:\ProgramData\Temp:A8ADE5D8 . C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM\components folder moved successfully. C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM\chrome\content folder moved successfully. C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM\chrome folder moved successfully. C:\PROGRAM FILES\COMMON FILES\SPIGOT\WTXPCOM folder moved successfully. C:\Program Files\Common Files\Spigot\Search Settings\Res folder moved successfully. C:\Program Files\Common Files\Spigot\Search Settings\Lang folder moved successfully. C:\Program Files\Common Files\Spigot\Search Settings folder moved successfully. Folder move failed. C:\Program Files\Common Files\Spigot scheduled to be moved on reboot. C:\Program Files\pdfforge Toolbar\Res\Lang folder moved successfully. C:\Program Files\pdfforge Toolbar\Res folder moved successfully. C:\Program Files\pdfforge Toolbar\IE\6.2 folder moved successfully. Folder move failed. C:\Program Files\pdfforge Toolbar\IE scheduled to be moved on reboot. C:\Program Files\pdfforge Toolbar\FF\chrome folder moved successfully. C:\Program Files\pdfforge Toolbar\FF folder moved successfully. Folder move failed. C:\Program Files\pdfforge Toolbar scheduled to be moved on reboot. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\***\Desktop\cmd.bat deleted successfully. C:\Users\***\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Gast ->Temp folder emptied: 27578114 bytes ->Temporary Internet Files folder emptied: 2692282 bytes ->FireFox cache emptied: 47490298 bytes ->Flash cache emptied: 802 bytes User: *** ->Temp folder emptied: 1806804498 bytes ->Temporary Internet Files folder emptied: 62168638 bytes ->Java cache emptied: 7645069 bytes ->FireFox cache emptied: 62899402 bytes ->Flash cache emptied: 3807241 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 118609430 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 2'041.00 mb OTL by OldTimer - Version 3.2.58.1 log created on 08222012_184642 Files\Folders moved on Reboot... C:\Program Files\Common Files\Spigot\Search Settings folder moved successfully. C:\Program Files\Common Files\Spigot folder moved successfully. C:\Program Files\pdfforge Toolbar\IE\6.2 folder moved successfully. C:\Program Files\pdfforge Toolbar\IE folder moved successfully. C:\Program Files\pdfforge Toolbar folder moved successfully. PendingFileRenameOperations files... Registry entries deleted on Reboot... Liebe Grüsse! |
22.08.2012, 18:23 | #4 |
/// Helfer-Team | Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...) Sehr gut! Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
23.08.2012, 21:56 | #5 |
| Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...) Also lauften tut er Problemlos, nur weiss ja halt nicht ob sich noch was versteckt hat Hab die beiden Schritte wie beschrieben ausgeführt: Maleware: Code:
ATTFilter Malwarebytes Anti-Malware (Test) 1.62.0.1300 www.malwarebytes.org Datenbank Version: v2012.08.23.07 Windows Vista x86 NTFS Internet Explorer 7.0.6000.16982 *** :: HOME-PC [Administrator] Schutz: Deaktiviert 23.08.2012 19:09:43 mbam-log-2012-08-23 (19-09-43).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 364425 Laufzeit: 2 Stunde(n), 43 Minute(n), 52 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Code:
ATTFilter # AdwCleaner v1.801 - Logfile created 08/23/2012 at 22:47:37 # Updated 14/08/2012 by Xplode # Operating system : Windows Vista (TM) Business (32 bits) # User : *** - HOME-PC # Boot Mode : Normal # Running from : C:\Users\***\Downloads\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\***\AppData\LocalLow\BabylonToolbar Folder Found : C:\Users\***\AppData\LocalLow\pdfforge Folder Found : C:\Users\***\AppData\LocalLow\Search Settings Folder Found : C:\Users\Gast\AppData\LocalLow\BabylonToolbar Folder Found : C:\Users\Gast\AppData\LocalLow\Search Settings Folder Found : C:\Users\***\AppData\Roaming\pdfforge Folder Found : C:\Program Files\Application Updater Folder Found : C:\Program Files\Babylon File Found : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml ***** [Registry] ***** Key Found : HKCU\Software\AppDataLow\Software\pdfforge Key Found : HKCU\Software\AppDataLow\Software\Search Settings Key Found : HKCU\Software\pdfforge Key Found : HKCU\Software\Search Settings Key Found : HKCU\Software\Softonic Key Found : HKLM\SOFTWARE\Application Updater Key Found : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Found : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Key Found : HKLM\SOFTWARE\pdfforge Key Found : HKLM\SOFTWARE\Search Settings ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Found : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Key Found : HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC} Key Found : HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} ***** [Internet Browsers] ***** -\\ Internet Explorer v7.0.6000.16982 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\2x7lil33.default\prefs.js Found : user_pref("browser.babylon.HPOnNewTab", "1"); Found : user_pref("extensions.BabylonToolbar.cntry", "CH"); Found : user_pref("extensions.BabylonToolbar.firstRun", false); Found : user_pref("extensions.BabylonToolbar.hdrMd5", "4953C1E051D2B4909093A8811AB47091"); Found : user_pref("extensions.BabylonToolbar.lastActv", "16"); Found : user_pref("extensions.BabylonToolbar.lastDP", 16); Profile name : default File : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\aa6c6zwd.default\prefs.js [OK] File is clean. -\\ Google Chrome v [Unable to get version] File : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [3532 octets] - [23/08/2012 22:47:37] ########## EOF - C:\AdwCleaner[R1].txt - [3660 octets] ########## Gruss! |
24.08.2012, 00:19 | #6 |
/// Helfer-Team | Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...) Sehr gut!
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html
__________________ --> Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...) |
26.08.2012, 18:48 | #7 |
| Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...) So hat zwar ein bisschen gedauert aber hab die Logs jetzt AdwCleaner Code:
ATTFilter # AdwCleaner v1.801 - Logfile created 08/24/2012 at 18:24:02 # Updated 14/08/2012 by Xplode # Operating system : Windows Vista (TM) Business (32 bits) # User : *** - HOME-PC # Boot Mode : Normal # Running from : C:\Users\***\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\***\AppData\LocalLow\BabylonToolbar Folder Deleted : C:\Users\***\AppData\LocalLow\pdfforge Folder Deleted : C:\Users\***\AppData\LocalLow\Search Settings Folder Deleted : C:\Users\Gast\AppData\LocalLow\BabylonToolbar Folder Deleted : C:\Users\Gast\AppData\LocalLow\Search Settings Folder Deleted : C:\Users\***\AppData\Roaming\pdfforge Folder Deleted : C:\Program Files\Application Updater Folder Deleted : C:\Program Files\Babylon File Deleted : C:\Program Files\Mozilla Firefox\searchplugins\babylon.xml ***** [Registry] ***** Key Deleted : HKCU\Software\AppDataLow\Software\pdfforge Key Deleted : HKCU\Software\AppDataLow\Software\Search Settings Key Deleted : HKCU\Software\pdfforge Key Deleted : HKCU\Software\Search Settings Key Deleted : HKCU\Software\Softonic Key Deleted : HKLM\SOFTWARE\Application Updater Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dhkplhfnhceodhffomolpfigojocbpcb Key Deleted : HKLM\SOFTWARE\pdfforge Key Deleted : HKLM\SOFTWARE\Search Settings ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2E9937FC-CF2F-4F56-AF54-5A6A3DD375CC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{741DE825-A6F0-4497-9AA6-8023CF9B0FFF} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{B922D405-6D13-4A2B-AE89-08A030DA4402} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{08858AF6-42AD-4914-95D2-AC3AB0DC8E28} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{B922D405-6D13-4A2B-AE89-08A030DA4402} ***** [Internet Browsers] ***** -\\ Internet Explorer v7.0.6000.16982 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\2x7lil33.default\prefs.js Deleted : user_pref("browser.babylon.HPOnNewTab", "1"); Deleted : user_pref("extensions.BabylonToolbar.cntry", "CH"); Deleted : user_pref("extensions.BabylonToolbar.firstRun", false); Deleted : user_pref("extensions.BabylonToolbar.hdrMd5", "4953C1E051D2B4909093A8811AB47091"); Deleted : user_pref("extensions.BabylonToolbar.lastActv", "16"); Deleted : user_pref("extensions.BabylonToolbar.lastDP", 16); Profile name : default File : C:\Users\Gast\AppData\Roaming\Mozilla\Firefox\Profiles\aa6c6zwd.default\prefs.js [OK] File is clean. -\\ Google Chrome v [Unable to get version] File : C:\Users\***\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R1].txt - [3661 octets] - [23/08/2012 22:47:37] AdwCleaner[S1].txt - [3662 octets] - [24/08/2012 18:24:02] ########## EOF - C:\AdwCleaner[S1].txt - [3790 octets] ########## Anti-Maleware Code:
ATTFilter Emsisoft Anti-Malware - Version 6.6 Letztes Update: 26.08.2012 15:51:11 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\ Archiv Scan: An ADS Scan: An Scan Beginn: 26.08.2012 15:53:01 C:\Users\***\Documents\Meine Websites\Webpage\***Website***\wordpress\wp-content\themes\tribune\tribune\footer.php gefunden: Trojan.PHP.Pakes!E2 C:\Program Files\PDFCreator\Toolbar\pdfforge Toolbar_setup.exe gefunden: Adware.Win32.Toolbar.Dealio.AMN!E1 Gescannt 636391 Gefunden 2 Scan Ende: 26.08.2012 19:14:54 Scan Zeit: 3:21:53 C:\Program Files\PDFCreator\Toolbar\pdfforge Toolbar_setup.exe Quarantäne Adware.Win32.Toolbar.Dealio.AMN!E1 C:\Users\***\Documents\Meine Websites\Webpage\***Website***\wordpress\wp-content\themes\tribune\tribune\footer.php Quarantäne Trojan.PHP.Pakes!E2 Quarantäne 2 Liebe Grüsse! |
27.08.2012, 01:11 | #8 |
/// Helfer-Team | Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...) Sehr gut! Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
27.08.2012, 21:55 | #9 |
| Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...) so wäre auch erledigt: Code:
ATTFilter ESETSmartInstaller@High as downloader log: Can not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internetCan not open internetESETSmartInstaller@High as downloader log: Can not open internet# version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=7c44218b30223d408353f70c8c118f33 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-27 08:41:38 # local_time=2012-08-27 10:41:38 (+0100, Mitteleuropäische Sommerzeit) # country="Switzerland" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=1280 16777215 100 0 600782 600782 0 0 # compatibility_mode=2560 16777215 100 0 0 0 0 0 # compatibility_mode=5892 16776573 100 100 104958 183622002 0 0 # compatibility_mode=8192 67108863 100 0 1700 1700 0 0 # scanned=202240 # found=15 # cleaned=15 # scan_time=10799 C:\Windows\Installer\20367.msi probably a variant of Win32/Toolbar.Widgi application (deleted - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\Search Settings\SearchSettings.exe a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\WTXPCOM\components\WidgiToolbarFF.dll a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\WTXPCOM\components\WidgiToolbarFF.dll.10 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\WTXPCOM\components\WidgiToolbarFF.dll.11 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\WTXPCOM\components\WidgiToolbarFF.dll.12 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\WTXPCOM\components\WidgiToolbarFF.dll.13 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\WTXPCOM\components\WidgiToolbarFF.dll.14 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\WTXPCOM\components\WidgiToolbarFF.dll.15 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\WTXPCOM\components\WidgiToolbarFF.dll.5 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\WTXPCOM\components\WidgiToolbarFF.dll.6 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\WTXPCOM\components\WidgiToolbarFF.dll.7 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\WTXPCOM\components\WidgiToolbarFF.dll.8 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\common files\Spigot\WTXPCOM\components\WidgiToolbarFF.dll.9 a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C C:\_OTL\MovedFiles\08222012_184642\C_Program Files\pdfforge Toolbar\IE\6.2\pdfforgeToolbarIE.dll a variant of Win32/Toolbar.Widgi application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C |
28.08.2012, 17:34 | #10 |
/// Helfer-Team | Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...) Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html Danach poste (kopieren und einfuegen) mir, was du hier angezeigt bekommst: PluginCheck |
13.10.2012, 00:19 | #11 |
/// Helfer-Team | Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...) Fehlende Rückmeldung Gibt es Probleme beim Abarbeiten obiger Anleitung? Um Kapazitäten für andere Hilfesuchende freizumachen, lösche ich dieses Thema aus meinen Benachrichtigungen. Solltest Du weitermachen wollen, schreibe mir eine PN oder eröffne ein neues Thema. http://www.trojaner-board.de/69886-a...-beachten.html Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner sauber ist. |
Themen zu Upgrade.exe Virus + Log-Dateien (Gmer, Defogger, OLT, Maleware...) |
ahnung, anhang, antivirus, datei, dateien, daten, einiger, firefox, funktioniert, gmer, hoffe, kaspersky, mac, maleware, mozilla, nicht mehr, programm, seite, stehe, system, upgrade.exe maleware windows kaspersky, virus, vorhanden, wichtige, zeichen, zweit |