![]() |
|
Log-Analyse und Auswertung: Virus Bundesministerium f. Internetsicherheit...Zahlung von €100 per paypalWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
|
![]() | #1 |
| ![]() Virus Bundesministerium f. Internetsicherheit...Zahlung von €100 per paypal Hallo t´john, hier schon einmal das log von aswMBR: Code:
ATTFilter aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2013-04-06 15:30:22 ----------------------------- 15:30:22.437 OS Version: Windows 6.0.6002 Service Pack 2 15:30:22.437 Number of processors: 4 586 0xF07 15:30:22.439 ComputerName: BESITZER-PC UserName: Besitzer 15:30:24.754 Initialize success 15:45:02.009 AVAST engine defs: 13040600 15:45:33.630 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP4T0L0-6 15:45:33.632 Disk 0 Vendor: ST3360320AS 3.AAM Size: 343399MB BusType: 3 15:45:33.721 Disk 0 MBR read successfully 15:45:33.723 Disk 0 MBR scan 15:45:33.727 Disk 0 Windows VISTA default MBR code 15:45:33.732 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 323396 MB offset 2048 15:45:33.738 Disk 0 Partition - 00 0F Extended LBA 20001 MB offset 662317056 15:45:33.764 Disk 0 Partition - 00 05 Extended 19994 MB offset 662327820 15:45:33.774 Disk 0 Partition 2 00 0B FAT32 MSDOS5.0 19994 MB offset 662327883 15:45:33.782 Disk 0 scanning sectors +703279104 15:45:33.951 Disk 0 scanning C:\Windows\system32\drivers 15:45:41.704 Service scanning 15:45:58.732 Modules scanning 15:46:03.001 Disk 0 trace - called modules: 15:46:03.024 ntkrnlpa.exe CLASSPNP.SYS disk.sys ataport.SYS hal.dll PCIIDEX.SYS msahci.sys 15:46:03.031 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85057ac8] 15:46:03.038 3 CLASSPNP.SYS[86fa28b3] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP4T0L0-6[0x84d058a0] 15:46:04.448 AVAST engine scan C:\Windows 15:46:08.246 AVAST engine scan C:\Windows\system32 15:48:48.445 AVAST engine scan C:\Windows\system32\drivers 15:49:00.731 AVAST engine scan C:\Users\Besitzer 15:53:36.032 AVAST engine scan C:\ProgramData 15:54:36.951 Scan finished successfully 15:54:56.659 Disk 0 MBR has been saved successfully to "C:\Users\Besitzer\Desktop\MBR.dat" 15:54:56.665 The log file has been saved successfully to "C:\Users\Besitzer\Desktop\aswMBR.txt" und von eset; hier gab es eine infizierte Date!!! Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=9f7153e5f95d3f4cabbf6d04a4a06bb7 # engine=13563 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-04-06 03:18:39 # local_time=2013-04-06 05:18:39 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=5892 16776573 100 100 108938 202794247 0 0 # scanned=134907 # found=1 # cleaned=0 # scan_time=4140 sh=96724E586A7B3ACB2EC8D78A881B9471E6863FE5 ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-0422.DI trojan" ac=I fn="C:\_OTL\MovedFiles\04062013_112845\C_Users\Besitzer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25\14322d9-545795a8" ...und hier noch von SecurityCheck: Code:
ATTFilter Results of screen317's Security Check version 0.99.61 Windows Vista Service Pack 2 x86 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.70.0.1100 CCleaner Java 7 Update 17 Adobe Reader 10.1.6 Adobe Reader out of Date! Google Chrome 25.0.1364.172 Google Chrome 26.0.1410.43 ````````Process Check: objlist.exe by Laurent```````` Windows Defender MSASCui.exe Malwarebytes Anti-Malware mbamservice.exe Malwarebytes Anti-Malware mbamgui.exe Malwarebytes' Anti-Malware mbamscheduler.exe Windows Defender MSASCui.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` |
![]() |
Themen zu Virus Bundesministerium f. Internetsicherheit...Zahlung von €100 per paypal |
administrator, anti-malware, appdata, autostart, conduitsearch, conduitsearch entfernen, dateien, desktop, explorer, explorer.exe, gelöscht, gen, java/exploit.cve-2013-0422.di, microsoft, neustart, paypal, pup.offerbundler.st, quarantäne, roaming, service pack 2, software, speicher, trojan.agent.rns, trojan.fakealert.rre, vista |