Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
Der Pc wurde neu gestartet, bevor die Logdatei angezeigt wurde.
Code:
ATTFilter
All processes killed
========== OTL ==========
Service oxser stopped successfully!
Service oxser deleted successfully!
File C:\Windows\system32\drivers\oxser.sys File not found not found.
Service Oxmfuf stopped successfully!
Service Oxmfuf deleted successfully!
File C:\Windows\system32\drivers\oxmfuf.sys File not found not found.
Service gbwihtvn stopped successfully!
Service gbwihtvn deleted successfully!
File C:\Windows\system32\drivers\gbwihtvn.sys File not found not found.
Registry key HKEY_USERS\S-1-5-21-61423327-2382724059-3319696661-1000\Software\Microsoft\Internet Explorer\SearchScopes\{94AEED7F-0923-48CB-8B41-B74BAAA39828}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{94AEED7F-0923-48CB-8B41-B74BAAA39828}\ not found.
Prefs.js: "ICQ Search" removed from browser.search.selectedEngine
Prefs.js: engine@conduit.com:3.2.5.2 removed from extensions.enabledItems
Prefs.js: ffxtlbr@babylon.com:1.1.3 removed from extensions.enabledItems
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-10.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-11.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-12.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-13.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-14.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-15.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-16.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-17.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-18.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-4.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-5.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-6.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-7.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-8.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\icqplugin-9.xml moved successfully.
C:\Users\Alina\AppData\Roaming\mozilla\firefox\profiles\uqkfinzd.default\searchplugins\safesearch.xml moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-61423327-2382724059-3319696661-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Microsoft® Windows Manager deleted successfully.
========== FILES ==========
C:\Users\Alina\AppData\Local\agmrushh moved successfully.
C:\Users\Alina\AppData\Local\lirobujo moved successfully.
C:\Users\Alina\AppData\Local\iavnavhx moved successfully.
C:\Users\Alina\AppData\Local\xucuwgoh moved successfully.
C:\Users\Alina\AppData\Local\cjwfigbc moved successfully.
C:\Users\Alina\AppData\Local\ehwicvmg moved successfully.
C:\Users\Alina\AppData\Local\cshklqnj moved successfully.
File\Folder C:\Program Files\BabylonToolbar not found.
C:\Users\Alina\Documents\Desktop\Desktop\Downloads\DownloadAcceleratorSetup.exe moved successfully.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Alina\Documents\Desktop\Desktop\Downloads\cmd.bat deleted successfully.
C:\Users\Alina\Documents\Desktop\Desktop\Downloads\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: Alina
->Temp folder emptied: 7550466429 bytes
->Temporary Internet Files folder emptied: 107461601 bytes
->Java cache emptied: 31835372 bytes
->FireFox cache emptied: 60372546 bytes
->Google Chrome cache emptied: 6354091 bytes
->Flash cache emptied: 3766712 bytes
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Gast
->Temp folder emptied: 242566 bytes
->Temporary Internet Files folder emptied: 148227 bytes
->FireFox cache emptied: 10248287 bytes
->Flash cache emptied: 1036 bytes
User: Jule
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 65617329 bytes
RecycleBin emptied: 445824089 bytes
Total Files Cleaned = 7.899,00 mb
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
Error: Unble to create default HOSTS file!
OTL by OldTimer - Version 3.2.69.0 log created on 10232012_144931
Files\Folders moved on Reboot...
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
Zum Thema system progressive protection - Der Pc wurde neu gestartet, bevor die Logdatei angezeigt wurde.
Code:
Alles auswählen Aufklappen ATTFilter
All processes killed
========== OTL ==========
Service oxser stopped successfully!
Service oxser deleted successfully!
File - system progressive protection...