![]() | ![]() Bundestrojaner sperrt Laptop Hallo zusammen! Mich hat der Bundespolizei Virus erneut erwischt und ich möchte Ihn gerne wieder loswerden! Habe hier diverse Beiträge zu diesem Thema gelesen, in denen immer darauf hingewiesen wird, nicht die gleichen Schritte ohne Aufforderung durchzuführen. Deshalb meine Anfrage, wie ich am Besten vorgehe?! Mein Betriebssystem ist Windows 7 und ich kann leider noch nicht einmal im abgesicherten Modus hochfahren. Nach Eingabe des Paswortes fährt er wieder runter und startet im normal Modus... ![]() Vielen Dank für Eure Hilfe! |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Bundestrojaner sperrt Laptop Hallo QUaterone und
Mein Name ist Leo und ich werde dich durch die Bereinigung deines Rechners begleiten. Eine Bereinigung beinhaltet nebst dem Entfernen von Malware auch das Schliessen von Sicherheitslücken und sollte gründlich durchgeführt werden. Sie erfolgt deshalb in mehreren Schritten und bedeutet einigen Aufwand für dich. Beachte: Das Verschwinden der offensichtlichen Symptome bedeutet nicht, dass das System schon sauber ist. Arbeite daher in deinem eigenen Interesse solange mit, bis du das OK bekommst, dass alles erledigt ist.
Ist das noch derselbe Windows 7 64-bit Rechner wie in deinem letzten Thread Ende 2011? Dann mach Folgendes: Schritt 1 Downloade dir bitte Farbar Recovery Scan Tool 64-Bit und speichere diese auf einen USB Stick (nicht in einen Unterordner!). Schliesse den USB Stick an den infizierten Rechner an. Du musst das System nun in die System Reparatur Option booten: Variante 1 - Über den Boot Manager Wenn du jetzt in den Reparaturoptionen bist, wähle Eingabeaufforderung.
Bitte poste in deiner nächsten Antwort:
![]() | ![]() Bundestrojaner sperrt Laptop Guten morgen!
Ja, es handelt sich noch um den gleichen Rechner, wie 2011. Hier ist das Log File: /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Bundestrojaner sperrt Laptop Hallo, Zitat:
Wenn du es nicht genau so wie in der Anleitung beschrieben gemacht hast, dann wiederhole diesen Schritt bitte entsprechend. (Zusätzliche Frage: Funktioniert denn der "abgesicherte Modus mit Eingabeaufforderung" oder kommst du dort auch nicht rein?)
![]() | ![]() Bundestrojaner sperrt Laptop Nur der funktioniert leider... über den hatte ich es gemacht... Ich versuche es noch einmal ?! Vielen Dank für die Hilfe! |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Bundestrojaner sperrt Laptop Hallo, dieses Tool läuft im abgesicherten Modus nicht korrekt, nur im Reperaturmodus. Versuch nochmals, wie beschrieben in den Reperaturmodus zu kommen und dort den Scan auszuführen. Und wenn das wieder nicht klappt, dann geb ich dir hier eine alternative Anleitung: Schritt 1 Lade dir auf einem Zweitrechner bitte OTL (von Oldtimer) herunter und speichere es auf einen USB-Stick (nicht in einen Unterordner!).
Bitte poste in deiner nächsten Antwort:
__________________ --> Bundestrojaner sperrt Laptop |
![]() | ![]() Bundestrojaner sperrt Laptop ich habe anscheinend keinen lokalen Benutzer... Er zeigt mir nur den Benutzer POSTGRES und USER an... für beide wüsste ich kein Kennwort... Gibt es eine Möglichkeit über den abgesicherten modus mit Eingabeaufforderung?? |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Bundestrojaner sperrt LaptopZitat:
![]() Ich habe oben in meinem letzten Post eine Anleitung über den abgesicherten Modus mit Eingabeaufforderung hingeschrieben.
__________________ cheers, Leo |
![]() | ![]() Bundestrojaner sperrt Laptop Logs von OTL: OTL.txt:OTL Logfile: Code:
Scan result of Farbar Recovery Scan Tool (FRST) (x64) Version: 10-03-2013 01 Ran by SSchreiber at 12-03-2013 06:47:55 Running from D:\ Service Pack 1 (X64) OS Language: German Standard Attention: Could not load system hive. ATTENTION:=====> THE TOOL IS NOT RUN FROM RECOVERY ENVIRONMENT AND WILL NOT FUNCTION PROPERLY. (x86)\wireless_projector\wirelessprojector.exe" = protocol=6 | dir=in | app=c:\program files (x86)\wireless_projector\wirelessprojector.exe | "TCP Query User{6287D875-4F23-4A65-B880-284E2D6902D9}C:\program files (x86)\microsoft office\office14\outlook.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe | "TCP Query User{7065807B-BBB8-4F46-BCE6-E36F3699863A}C:\users\sschreiber\appdata\roaming\koybo\bali.exe" = protocol=6 | dir=in | app=c:\users\sschreiber\appdata\roaming\koybo\bali.exe | "TCP Query User{88B6CFD8-A5AF-4DE4-8253-4AF6FB37A212}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe | "TCP Query User{A109EAF4-3D36-483A-BF02-DE1B1ED63F52}C:\program files (x86)\astaro\astaro ipsec client\ncpmon.exe" = protocol=6 | dir=in | app=c:\program files (x86)\astaro\astaro ipsec client\ncpmon.exe | "TCP Query User{BF624EA3-017F-4ECD-AFA3-38EC1063F821}C:\program files (x86)\openvpn\bin\openvpn.exe" = protocol=6 | dir=in | app=c:\program files (x86)\openvpn\bin\openvpn.exe | "TCP Query User{C5475CA2-7DDF-4F77-86C8-9D7D5A825DD5}C:\users\sschreiber\appdata\roaming\ubewe\ufpu.exe" = protocol=6 | dir=in | app=c:\users\sschreiber\appdata\roaming\ubewe\ufpu.exe | "TCP Query User{D4645416-309C-4E25-ABA4-615E1A19A3DC}C:\users\sschreiber\appdata\roaming\ubewe\ufpu.exe" = protocol=6 | dir=in | app=c:\users\sschreiber\appdata\roaming\ubewe\ufpu.exe | "TCP Query User{E62BA333-5DE1-4DF7-A5FF-391EAA6DB359}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "UDP Query User{276DED22-E3AB-45CA-94B7-835ED148016A}C:\program files (x86)\astaro\astaro ipsec client\ncpmon.exe" = protocol=17 | dir=in | app=c:\program files (x86)\astaro\astaro ipsec client\ncpmon.exe | "UDP Query User{3D721D74-42BA-4A17-8C55-A41C6F870E2E}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe | "UDP Query User{4F8C959E-DD4E-4A76-A0C2-F80D7076E755}C:\program files (x86)\astaro\astaro ipsec client\ncpmon.exe" = protocol=17 | dir=in | app=c:\program files (x86)\astaro\astaro ipsec client\ncpmon.exe | "UDP Query User{6D86CA48-3482-47DF-8368-A652E9B7114D}C:\program files (x86)\wireless_projector\wirelessprojector.exe" = protocol=17 | dir=in | app=c:\program files (x86)\wireless_projector\wirelessprojector.exe | "UDP Query User{818CE850-BDFD-40E6-98D7-733E3047C0AF}C:\users\sschreiber\appdata\roaming\ubewe\ufpu.exe" = protocol=17 | dir=in | app=c:\users\sschreiber\appdata\roaming\ubewe\ufpu.exe | "UDP Query User{81A7B1D5-D9D4-4DDC-8C8D-35C90137F0ED}C:\program files (x86)\microsoft office\office14\outlook.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe | "UDP Query User{87AB361E-7246-46CB-86B0-750132165E0E}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe | "UDP Query User{CB2E4331-722B-4144-A89F-5A7A450E8175}C:\program files (x86)\google\google earth\client\googleearth.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth\client\googleearth.exe | "UDP Query User{DC5923BD-5D96-49C9-A51C-1B9E6089681B}C:\users\sschreiber\appdata\roaming\ubewe\ufpu.exe" = protocol=17 | dir=in | app=c:\users\sschreiber\appdata\roaming\ubewe\ufpu.exe | "UDP Query User{DDF4DFAB-8F6D-41A9-BD11-DA6C5AECD818}C:\program files (x86)\microsoft office\office14\outlook.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe | "UDP Query User{F9A704AB-BFBB-418D-8838-5EFE1E98C38C}C:\users\sschreiber\appdata\roaming\koybo\bali.exe" = protocol=17 | dir=in | app=c:\users\sschreiber\appdata\roaming\koybo\bali.exe | "UDP Query User{FE9EDD58-4726-4AA8-96DF-07729251AAB9}C:\program files (x86)\openvpn\bin\openvpn.exe" = protocol=17 | dir=in | app=c:\program files (x86)\openvpn\bin\openvpn.exe | ========== HKEY_LOCAL_MACHINE Uninstall List ========== 64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{07D618CD-B016-438A-ADC9-A75BD23F85CE}" = Wave Support Software Installer "{0B0A2153-58A6-4244-B458-25EDF5FCD809}" = Private Information Manager "{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes "{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant "{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition) "{25FE5727-76D0-4EDC-A5C6-AA604F1370F1}" = CheckAud FastAnalyzer "{26A24AE4-039D-4CA4-87B4-2F86416024FF}" = Java(TM) 6 Update 24 (64-bit) "{2EECD5EF-5095-467C-B80C-4AB3096EFD60}" = SPBA 5.9 "{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022 "{3A6BE9F4-5FC8-44BB-BE7B-32A29607FEF6}" = Preboot Manager "{3D33F6F0-4D90-484D-A1D9-09AE791CCBD9}" = Eraser "{3DCDFCDB-4D96-4CF0-9BB3-C91DAE9073F3}" = PC-CCID "{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = WIDCOMM Bluetooth Software "{4C1CCA11-0D08-4D5E-8444-2D9FB48BCABF}" = Intel(R) PROSet/Wireless WiFi-Software "{4E60E212-3177-4B16-BCB3-616CCC52357D}" = Upek Touchchip Fingerprint Reader "{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 "{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup "{6AC87FB3-ACFC-4416-890C-8976D5A9B371}" = Trusted Drive Manager "{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64) "{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour "{7206B668-FEE0-455B-BB1F-9B5A2E0EC94A}" = Custom "{75E0B85A-085F-4BA3-B2BF-1995AFD8024D}" = NTRU TCG Software Stack "{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 "{8A6B4FE2-7CC4-4DAC-BC68-D9E170B758FD}" = Dell ControlVault Host Components Installer 64 bit "{8B485965-8EFE-464A-842F-CF8F18C3DFD7}" = iCloud "{8C9B6B1F-0A8E-402A-A60C-110BBB38D67E}" = Intel(R) Network Connections "{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer "{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010 "{90140000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2010 "{91CE5F03-3A2A-4268-935A-04944F058AE9}" = Gemalto "{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting "{975DFE7C-8E56-45BC-A329-401E6B1F8102}" = Dell Backup and Recovery Manager "{9D6DFAD6-09E5-445E-A4B5-A388FEEBD90D}" = RBVirtualFolder64Inst "{9DAED4FC-2B0E-4F3F-8141-F2ABF02CCFCB}" = BioAPI Framework "{9F72EF8B-AEC9-4CA5-B483-143980AFD6FD}" = Dell Touchpad "{ABBA2EA4-740E-4052-902B-9CA70B081E3F}" = Dell Data Protection | Access "{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64) "{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector "{D2DDF40C-552E-4C3D-AE5D-873044B53F7B}" = ESET NOD32 Antivirus "{D5876F0A-B2E9-4376-B9F5-CD47B7B8D820}" = Windows Live Remote Client Resources "{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support "{D930AF5C-5193-4616-887D-B974CEFC4970}" = Windows Live Remote Service Resources "{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter "{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319 "{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client "{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service "{EEAFE1E5-076B-430A-96D9-B567792AFA88}" = EMBASSY Security Center "{F52ABC1D-5EA4-4FDD-8E5F-CA31428570C0}" = Wave Infrastructure Installer "{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile "{F839C6BD-E92E-48FA-9CE6-7BFAF94F7096}" = DellAccess "{FDF509ED-9624-4FDE-9BAA-9566C186AB96}" = Dell System Manager "9512AA21B791B05A54E27065C45BBC417AB282DF" = Windows-Treiberpaket - Dell Inc. PBADRV System (09/11/2009 "Lexmark S300-S400 Series" = Lexmark S300-S400 Series "Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile "PostgreSQL 9.0" = PostgreSQL 9.0 "ProInst" = Intel PROSet Wireless "PROSetDX" = Intel(R) Network Connections "UTAX TA Product Library" = UTAX TA Product Library [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{0481A2EA-DA1D-4D10-A7C3-F8237948F6B5}" = Messenger Companion "{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer "{0CB3B7EE-52C7-4136-AF40-605567D90318}" = O2Micro Flash Memory Card Windows Driver "{1017A80C-6F09-4548-A84D-EDD6AC9525F0}" = Lexmark Symbolleiste "{1DDB95A4-FD7B-4517-B3F1-2BCAA96879E6}" = Windows Live Writer Resources "{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update "{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions "{23EEC842-57ED-4055-A056-9D4185DFB1AA}" = Dell Mobile Broadband Manager "{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}" = TuneUp Utilities 2011 "{246CB06B-308C-4CAE-AD1C-CB8409274261}" = Citrix Receiver(Aero) "{26A24AE4-039D-4CA4-87B4-2F83216024FF}" = Java(TM) 6 Update 24 "{2C43790E-8470-1027-82D3-DF319F3C410F}" = Intel(R) Identity Protection Technology "{2DE9C112-2482-4D27-AA90-1504DFD9F117}" = Citrix Authentication Manager "{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5 "{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}" = CyberLink WaveEditor "{3250260C-7A95-4632-893B-89657EB5545B}" = PhotoShowExpress "{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery "{37B33B16-2535-49E7-8990-32668708A0A3}" = Windows Live UX Platform Language Pack "{3B61FA4C-86D4-4C2E-8517-1D5FB05853DB}" = CyberLink Romance Pack Vol. 2 "{44D66AD9-AE19-4AFD-BE7E-A1B44C856697}" = MSXML4.0 redistributable "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin "{4E4E65EE-C456-45AC-B5AD-C62C3A325BD0}" = Dell Data Protection | Access | Drivers "{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack "{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth "{5D4C60AA-84E6-4E1A-8A68-69970D387BE1}" = TuneUp Utilities Language Pack (de-DE) "{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel(R) Management Engine Components "{655C5545-7974-443F-882F-D745607EBB08}" = Citrix Receiver (DV) "{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3 "{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE "{6C29152D-3FF9-43B2-84E4-9B35FC0BF5C2}" = Vodafone Mobile Broadband "{6F0BBEFE-BE1C-419B-BA1F-D36C9E7915BC}" = Roxio Creator Starter "{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable "{739A6D0C-CA8D-4955-8E3D-58D1847327AC}" = Online Plug-in "{7746BFAA-2B5D-4FFD-A0E8-4558F4668105}" = Roxio Burn "{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update "{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core "{7DC7A026-00B9-4CD5-B752-5ADE5CD79636}" = CheckScan for SAP Systems Version 3.5 Präsentation "{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform "{841CBDD5-4BB5-403E-AEE3-2FADC3890BE8}" = Dell Data Protection | Access | Middleware "{859D4022-B76D-40DE-96EF-C90CDA263F44}" = Windows Live Writer "{87434D51-51DB-4109-B68F-A829ECDCF380}" = AccelerometerP11 "{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight "{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime "{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT "{8E770F99-CF23-4BF9-BF4E-E3A2924FEB27}" = Microsoft redistributable runtime DLLs VS2005 SP1(x86) "{8F8580E9-CDCD-48F4-AE9C-EC464AFC2EB6}" = CheckAud for SAP-Systems Version 3.5 "{90140000-0015-0407-0000-0000000FF1CE}" = Microsoft Office Access MUI (German) 2010 "{90140000-0015-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2010 "{90140000-0016-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2010 "{90140000-0018-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-0019-0407-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (German) 2010 "{90140000-0019-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001A-0407-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (German) 2010 "{90140000-001A-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2010 "{90140000-001B-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2010 "{90140000-001F-0407-0000-0000000FF1CE}_Office14.SingleImage_{65A2328E-FDFB-4CA3-8582-357EA6825FEA}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010 "{90140000-001F-0409-0000-0000000FF1CE}_Office14.SingleImage_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010 "{90140000-001F-040C-0000-0000000FF1CE}_Office14.SingleImage_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2010 "{90140000-001F-0410-0000-0000000FF1CE}_Office14.SingleImage_{C0743197-FFEE-4C19-BAEB-8F7437DC4C8A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0000-1000-0000000FF1CE}_Office14.SingleImage_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002A-0407-1000-0000000FF1CE}_Office14.SingleImage_{594128C9-2CDF-43CE-8103-DC100CF013B6}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2010 "{90140000-002C-0407-0000-0000000FF1CE}_Office14.SingleImage_{4275FB46-ABDF-4456-876C-17CF64294D9A}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-003D-0000-0000-0000000FF1CE}" = Microsoft Office Single Image 2010 "{90140000-003D-0000-0000-0000000FF1CE}_Office14.SingleImage_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2010 "{90140000-006E-0407-0000-0000000FF1CE}_Office14.SingleImage_{98EDFD9F-EA76-40CC-BCE9-92C69413F65B}" = Microsoft Office 2010 Service Pack 1 (SP1) "{90140000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2010 "{90140000-00A1-0407-0000-0000000FF1CE}_Office14.SingleImage_{69E54534-4569-4639-89E9-305B60A11601}" = Microsoft Office 2010 Service Pack 1 (SP1) "{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker "{991057FA-3CA7-42B0-94B6-5B1B2535FBD3}" = Citrix Receiver Inside "{99DF06E4-FE3E-4A74-A3D2-815FD4B79966}" = CheckScan for SAP Systems Version 3.4 "{9A00EC4E-27E1-42C4-98DD-662F32AC8870}" = Sonic CinePlayer Decoder Pack "{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 "{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 "{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail "{9D583F01-A973-4B04-90BD-FB7886779090}" = Dell Wireless HSPA Mini-Card Drivers "{A113003E-8271-4485-ABC1-83FB96BFFF52}" = Citrix Receiver (USB) "{A121EEDE-C68F-461D-91AA-D48BA226AF1C}" = Roxio Activation Module "{A47A9101-6EB5-4314-BDA1-297880FBB908}" = Microsoft redistributable runtime DLLs VS2008 SP1(x86) "{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer "{A7D91856-258D-4C87-8041-B170851CE432}" = Dell Data Protection | Access "{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9.5 "{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper "{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common "{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer "{AC76BA86-7AD7-1031-7B44-AA1000000001}" = Adobe Reader X (10.1.6) - Deutsch "{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint "{ACFBE99B-6981-4513-B17E-A2683CEB9EE5}" = Windows Live Mesh "{AF1F56D9-D0D2-45FE-B454-3BC23A712108}" = CheckScan for SAP Systems Version 3.5 "{AF9E97C1-7431-426D-A8D5-ABE40995C0B1}" = DirectX 9 Runtime "{B113D18C-67B0-4FB7-B329-E89B66194AE6}" = Windows Live Fotogalerie "{B1239994-A850-44E2-BED8-E70A21124E16}" = Windows Live Mail "{B1F0FE76-83C6-47F2-BD0D-40FF96E47508}_is1" = Fahrtenbuch.de Version 10 "{BC728724-882E-4E2D-B3EE-E2C7332DC2F2}" = Citrix Receiver (HDX Flash-Umleitung) "{C2AB7DC4-489E-4BE9-887A-52262FBADBE0}" = Windows Live Photo Common "{C5398A89-516C-4DAF-BA07-EE7949090E56}" = Windows Live Mesh ActiveX control for remote connections "{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari "{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support "{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform "{CEC7A786-A9C8-4EF7-BB59-6518E3B3C878}" = Microsoft redistributable runtime DLLs VS2005 SP1(x86) "{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64 "{D2C5E510-BE6D-42CC-9F61-E4F939078474}" = Lexmark "{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow "{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform "{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh "{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10 "{E4E88B54-4777-4659-967A-2EED1E6AFD83}" = Windows Live Movie Maker "{EF56258E-0326-48C5-A86C-3BAC26FC15DF}" = Roxio Creator Starter "{F06B5C4C-8D2E-4B24-9D43-7A45EEC6C878}" = Roxio Creator Starter "{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU] "{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel(R) Processor Graphics "{F50925A4-753F-40E1-9A48-F56F4674FC6A}" = CheckAud for SAP-Systems Version 3.4 "{F605992E-FD5B-46D7-AFDA-FDB1AB00F829}" = Self-Service Plug-in "{F850707C-B6A0-4B56-8709-F89CF8F9AC6D}" = Eraser "{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel(R) Control Center "{F95E4EE0-0C6E-4273-B6B9-91FD6F071D76}" = Windows Live Essentials "Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX "Air Projection System_is1" = Wireless Projector "CitrixOnlinePluginPackWeb" = Citrix Receiver "Dell Webcam Central" = Dell Webcam Central "EASEUS Partition Master Home Edition_is1" = EASEUS Partition Master 7.0.1 Home Edition "Eraser" = Eraser "Foxit Reader_is1" = Foxit Reader 5.0 "InstallShield_{0CB3B7EE-52C7-4136-AF40-605567D90318}" = O2Micro Flash Memory Card Windows Driver "InstallShield_{2F8BA3FD-1FA9-4279-B696-712ABB12F09F}" = SmartSound Quicktracks 5 "InstallShield_{324F76CC-D8DD-4D87-B77D-D4AF5E1AA7B3}" = CyberLink WaveEditor "InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin "InstallShield_{A8516AC9-AAF1-47F9-9766-03E2D4CDBCF8}" = CyberLink PowerDVD 9.5 "InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector "InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow "Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware Version "Mozilla Firefox 18.0.2 (x86 de)" = Mozilla Firefox 18.0.2 (x86 de) "MozillaMaintenanceService" = Mozilla Maintenance Service "NCP RWS/GA" = Astaro IPsec Client "Office14.SingleImage" = Microsoft Office Home and Business 2010 "OpenVPN" = OpenVPN 2.2.2 "PEPer" = PEPer 4.0 "SAPGUI710" = SAP GUI for Windows 7.20 "TeamViewer 7" = TeamViewer 7 "TrueCrypt" = TrueCrypt "TuneUp Utilities 2011" = TuneUp Utilities 2011 "WinLiveSuite" = Windows Live Essentials ========== HKEY_USERS Uninstall List ========== [HKEY_USERS\S-1-5-21-1214413957-2857192303-383237103-1654\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "ActiveTouchMeetingClient" = WebEx "Europa Casino" = Europa Casino ========== Last 20 Event Log Errors ========== [ Application Events ] Error - 07.03.2013 07:58:01 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = System Restore | ID = 8193 Description = Error - 07.03.2013 09:46:52 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = VmbService | ID = 0 Description = conflictManagerStarted Error - 07.03.2013 09:50:13 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = VmbService | ID = 0 Description = conflictManagerStarted Error - 07.03.2013 10:19:04 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = Application Error | ID = 1000 Description = Name der fehlerhaften Anwendung: OUTLOOK.EXE, Version: 14.0.6131.5000, Zeitstempel: 0x509b1020 Name des fehlerhaften Moduls: OUTLOOK.EXE, Version: 14.0.6131.5000, Zeitstempel: 0x509b1020 Ausnahmecode: 0xc0000005 Fehleroffset: 0x000b2935 ID des fehlerhaften Prozesses: 0x444 Startzeit der fehlerhaften Anwendung: 0x01ce1b3eb7b45336 Pfad der fehlerhaften Anwendung: C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE Pfad des fehlerhaften Moduls: C:\Program Files (x86)\Microsoft Office\Office14\OUTLOOK.EXE Berichtskennung: f666b574-8731-11e2-ae02-028037ec0200 Error - 11.03.2013 03:31:18 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = System Restore | ID = 8193 Description = Error - 11.03.2013 05:51:24 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = System Restore | ID = 8193 Description = Error - 11.03.2013 16:06:49 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = VmbService | ID = 0 Description = GetLoggedOnUser Error - 11.03.2013 16:47:15 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = VmbService | ID = 0 Description = GetLoggedOnUser Error - 11.03.2013 17:01:32 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = VmbService | ID = 0 Description = GetLoggedOnUser Error - 11.03.2013 17:13:25 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = VmbService | ID = 0 Description = GetLoggedOnUser [ System Events ] Error - 12.03.2013 11:48:16 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = Service Control Manager | ID = 7001 Description = Der Dienst "NTRU TSS v1.2.1.34 TCS" ist vom Dienst "TPM-Basisdienste" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%0 Error - 12.03.2013 11:48:16 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Arbeitsstationsdienst" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 12.03.2013 11:48:16 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Anmeldedienst" ist vom Dienst "Arbeitsstationsdienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 12.03.2013 11:48:16 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = Service Control Manager | ID = 7001 Description = Der Dienst "IP-Hilfsdienst" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 12.03.2013 11:48:16 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = Service Control Manager | ID = 7001 Description = Der Dienst "SMB-Miniredirector-Wrapper und -Modul" ist vom Dienst "Umgeleitetes Puffersubsystem" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%31 Error - 12.03.2013 11:48:16 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = Service Control Manager | ID = 7001 Description = Der Dienst "SMB 1.x-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 12.03.2013 11:48:16 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = Service Control Manager | ID = 7001 Description = Der Dienst "SMB 2.0-Miniredirector" ist vom Dienst "SMB-Miniredirector-Wrapper und -Modul" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 12.03.2013 11:48:16 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = Service Control Manager | ID = 7001 Description = Der Dienst "Netzwerkverbindungen" ist vom Dienst "Netzwerkspeicher-Schnittstellendienst" abhängig, der aufgrund folgenden Fehlers nicht gestartet wurde: %%1068 Error - 12.03.2013 11:48:16 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = Service Control Manager | ID = 7026 Description = Das Laden folgender Boot- oder Systemstarttreiber ist fehlgeschlagen: AFD CSC ctxusbm DfsC discache ehdrv NetBIOS NetBT nsiproxy Psched rdbss SMR210 spldr tcpipBM tdx truecrypt vwififlt Wanarpv6 WfpLwf Error - 12.03.2013 11:48:26 | Computer Name = IBS-NB-TT.ibs.hamburg | Source = DCOM | ID = 10005 Description = < End of report > |
![]() | #10 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Bundestrojaner sperrt Laptop Hallo, prima. In Schritt 1 sollte der Sperrbildschirm entfernt werden. Starte danach den Rechner neu auf, versuche wieder in den normalen Modus zu starten und führe die weiteren Schritte dann dort aus. Schritt 1 Erstelle zuerst auf einem Zweitrechner das Fixskript:
Schritt 2 Lade dir Gmer herunter (auf den Button Download EXE drücken) und speichere das Programm auf den Desktop.
Schritt 3 Verschiebe die OTL.exe vom USB-Stick auf deinen Desktop.
Bitte poste in deiner nächsten Antwort:
__________________ cheers, Leo |
![]() | #11 |
![]() | ![]() Bundestrojaner sperrt Laptop Fixlog von OTL: ========== OTL ========== Registry value HKEY_USERS\S-1-5-21-1214413957-2857192303-383237103-1654\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Users\sschreiber\AppData\Roaming\skype.dat deleted successfully. C:\Users\sschreiber\AppData\Roaming\skype.dat moved successfully. C:\Users\sschreiber\AppData\Roaming\skype.ini moved successfully. C:\ProgramData\lsass.exe moved successfully. C:\ProgramData\dsgsdgdsgdsgw.pad moved successfully. OTL by OldTimer - Version log created on 03122013_180111 |
![]() | #12 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Bundestrojaner sperrt Laptop Das scheint geklappt zu haben. Wenn du jetzt wieder normal starten kannst, dann bitte noch die weiteren Schritte abarbeiten.
__________________ cheers, Leo |
![]() | #13 |
![]() | ![]() Bundestrojaner sperrt Laptop Log Gmer: GMER Logfile: Code:
ATTFilter GMER 2.1.19155 - GMER - Rootkit Detector and Remover Rootkit scan 2013-03-12 19:06:54 Windows 6.1.7601 Service Pack 1 x64 \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 ST932042 rev.D005 298,09GB Running: y3jnldy4.exe; Driver: C:\Users\SSCHRE~1\AppData\Local\Temp\pwdoypow.sys ---- User code sections - GMER 2.1 ---- .text C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[2300] C:\Windows\syswow64\kernel32.dll!SetUnhandledExceptionFilter 0000000076cf87b1 4 bytes [C2, 04, 00, 00] .text C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[2300] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075781465 2 bytes [78, 75] .text C:\Program Files\ESET\ESET NOD32 Antivirus\x86\ekrn.exe[2300] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000757814bb 2 bytes [78, 75] .text ... * 2 .text C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe[2832] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075781465 2 bytes [78, 75] .text C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe[2832] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757814bb 2 bytes [78, 75] .text ... * 2 .text C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe[3416] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075781465 2 bytes [78, 75] .text C:\Program Files (x86)\Dell\Dell WWAN\WMCore\mini_WMCore.exe[3416] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757814bb 2 bytes [78, 75] .text ... * 2 .text C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075781465 2 bytes [78, 75] .text C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe[4964] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757814bb 2 bytes [78, 75] .text ... * 2 .text C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe[4496] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075781465 2 bytes [78, 75] .text C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe[4496] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757814bb 2 bytes [78, 75] .text ... * 2 .text C:\Program Files (x86)\Citrix\ICA Client\concentr.exe[4604] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075781465 2 bytes [78, 75] .text C:\Program Files (x86)\Citrix\ICA Client\concentr.exe[4604] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757814bb 2 bytes [78, 75] .text ... * 2 .text C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe[5056] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075781465 2 bytes [78, 75] .text C:\Program Files (x86)\Citrix\ICA Client\Receiver\Receiver.exe[5056] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757814bb 2 bytes [78, 75] .text ... * 2 .text C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe[5180] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 69 0000000075781465 2 bytes [78, 75] .text C:\Program Files (x86)\Citrix\SelfServicePlugin\SelfServicePlugin.exe[5180] C:\Windows\syswow64\psapi.dll!GetModuleInformation + 155 00000000757814bb 2 bytes [78, 75] .text ... * 2 .text C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe[5432] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075781465 2 bytes [78, 75] .text C:\Program Files (x86)\Citrix\ICA Client\wfcrun32.exe[5432] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757814bb 2 bytes [78, 75] .text ... * 2 .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5848] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075781465 2 bytes [78, 75] .text C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe[5848] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757814bb 2 bytes [78, 75] .text ... * 2 .text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[3936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 69 0000000075781465 2 bytes [78, 75] .text C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe[3936] C:\Windows\syswow64\PSAPI.DLL!GetModuleInformation + 155 00000000757814bb 2 bytes [78, 75] .text ... * 2 ---- Registry - GMER 2.1 ---- Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\68a3c4471790 Reg HKLM\SYSTEM\CurrentControlSet\services\BTHPORT\Parameters\Keys\68a3c4471c80 Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\68a3c4471790 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\services\BTHPORT\Parameters\Keys\68a3c4471c80 (not active ControlSet) ---- EOF - GMER 2.1 ---- |
![]() | #14 |
/// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Bundestrojaner sperrt Laptop Ok, nur noch das frische OTL-Log und dann geht's weiter.
__________________ cheers, Leo |
![]() | #15 |
![]() | ![]() Bundestrojaner sperrt Laptop OTL.txtOTL Logfile: Code:
