![]() |
| |||||||
Log-Analyse und Auswertung: Win32/Adload.DAWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| |
| | #1 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Win32/Adload.DAFixen mit OTL
Code:
ATTFilter :OTL
FF - user.js - File not found
IE - HKU\S-1-5-21-2010877881-1813204234-2256430691-1003\..\SearchScopes\{8A793537-AB4C-4276-BCFD-C754B2B5224C}: "URL" = http://websearch.ask.com/redirect?client=ie&tb=ORJ&o=&src=crm&q={searchTerms}&locale=&apn_ptnrs=&apn_dtid=OSJ000&apn_uid=753A6270-3B55-4C89-9B3B-578F42D7C22D&apn_sauid=4986CC23-FD9B-499F-BC18-FC6BE31087F6
IE - HKU\S-1-5-21-2010877881-1813204234-2256430691-1003\..\SearchScopes\{ECC1A7DF-0348-405F-9E68-A24B75EC4A68}: "URL" = http://rover.ebay.com/rover/1/707-37276-16609-0/4?satitle={searchTerms}
[2013.03.01 20:00:17 | 000,000,512 | ---- | M] () -- C:\Users\***\Desktop\MBR.dat
@Alternate Data Stream - 184 bytes -> C:\ProgramData\TEMP:D3A96964
@Alternate Data Stream - 102 bytes -> C:\ProgramData\TEMP:D287FACF
:Files
ipconfig /flushdns /c
:Commands
[purity]
[emptytemp]
[resethosts]
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #2 |
| | Win32/Adload.DA Hallo Cosinus,
__________________wie immer: Vielen Dank! Der gewünschte Text: Code:
ATTFilter All processes killed
========== OTL ==========
Registry key HKEY_USERS\S-1-5-21-2010877881-1813204234-2256430691-1003\Software\Microsoft\Internet Explorer\SearchScopes\{8A793537-AB4C-4276-BCFD-C754B2B5224C}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8A793537-AB4C-4276-BCFD-C754B2B5224C}\ not found.
Registry key HKEY_USERS\S-1-5-21-2010877881-1813204234-2256430691-1003\Software\Microsoft\Internet Explorer\SearchScopes\{ECC1A7DF-0348-405F-9E68-A24B75EC4A68}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ECC1A7DF-0348-405F-9E68-A24B75EC4A68}\ not found.
C:\Users\***\Desktop\MBR.dat moved successfully.
ADS C:\ProgramData\TEMP:D3A96964 deleted successfully.
ADS C:\ProgramData\TEMP:D287FACF deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\***\Desktop\cmd.bat deleted successfully.
C:\Users\***\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: ***
->Temp folder emptied: 212568022 bytes
->Temporary Internet Files folder emptied: 8796233 bytes
->Java cache emptied: 7795321 bytes
->FireFox cache emptied: 76168908 bytes
->Flash cache emptied: 800 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
User: *****
->Temp folder emptied: 1467445418 bytes
->Temporary Internet Files folder emptied: 814984755 bytes
->Java cache emptied: 25275774 bytes
->FireFox cache emptied: 70604767 bytes
->Flash cache emptied: 8114652 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 140087860 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 308049 bytes
RecycleBin emptied: 3469706 bytes
Total Files Cleaned = 2.704,00 mb
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
OTL by OldTimer - Version 3.2.69.0 log created on 03042013_175554
Files\Folders moved on Reboot...
C:\Users\***\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
Stefan 46 |
![]() |
| Themen zu Win32/Adload.DA |
| absturz, bho, booten, converter, dringend, ebanking, error, excel, firefox, flash player, helper, hilfreich, home, homepage, logfile, microsoft office 2003, minidump, mp3, ntdll.dll, office 2007, plug-in, realtek, scan, security, server, software, svchost.exe, symantec, system, trojaner, win32/adload.da, windows, wma |