|
Plagegeister aller Art und deren Bekämpfung: Problem mit GUV Trojaner 2.11 auf Windows 7 LaptopWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
05.05.2013, 08:26 | #1 |
| Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop Hallo zusammen, ich habe mir auf meinem Laptop leider den GUV Trojaner 2.11 eingefangen. Mein Betriebssystem ist Windows 7. Ich habe bereits versucht, den Virus mit dem Kaspersky WindowsUnlocker zu entfernen, was leider nicht funktioniert hat. Die Besonderheit ist, dass das Laptop derzeit nicht gesperrt ist. In der kurzen Zeit nach dem Hochfahren und der Bildschirmsperre habe ich rein zufällig Outlook geöffnet, was zur Folge hatte, dass ich nun mit dem Rechner arbeiten kann (ich bin nicht sicher, ob dies tatsächlich mit Outllook oder evtl. auch mit dem Unlocker zusammenhängt) Allerdings kann ich seitdem in Outlook keine emails mehr abrufen, die Testfunktion in Outlook ist positiv, ich kann auch emails versenden, aber nicht mehr abrufen. Einen Neustart möchte ich nicht durchführen, da der Laptop sonst vermutlich wieder gesperrt wird. Es wäre nett, wenn mir jemand helfen könnte. Vielen Dank schonmal. |
05.05.2013, 08:39 | #2 |
/// Helfer-Team | Problem mit GUV Trojaner 2.11 auf Windows 7 LaptopDownloade Dir bitte Malwarebytes Anti-Malware
dann: Systemscan mit OTL (bebilderte Anleitung) Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden)- Doppelklick auf die OTL.exe
__________________ |
09.05.2013, 10:47 | #3 |
| Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop Hallo und vielen Dank für Deine Hilfe, hier das erste Logfile:
__________________Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.05.09.01 Windows 7 x64 NTFS Internet Explorer 9.0.8112.16421 Doris :: DORIS-PC [Administrator] 09.05.2013 06:56:49 mbam-log-2013-05-09 (06-56-49).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|H:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 461118 Laufzeit: 2 Stunde(n), 6 Minute(n), 5 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 7 C:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\U\00000004.@ (Trojan.0Access) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\U\00000008.@ (Trojan.0Access) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\U\000000cb.@ (Trojan.0Access) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\U\80000032.@ (Trojan.0Access) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\U\80000064.@ (Trojan.0Access) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Doris\AppData\Roaming\Emfai\inuku.exe (Spyware.Zbot.USBV) -> Erfolgreich gelöscht und in Quarantäne gestellt. C:\Users\Doris\AppData\Roaming\msconfig.ini (Trojan.Agent) -> Erfolgreich gelöscht und in Quarantäne gestellt. (Ende) Hier das File von OTL: OTL Logfile: Code:
ATTFilter OTL logfile created on: 09.05.2013 11:50:53 - Run 1 OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Doris\Desktop 64bit- Home Premium Edition (Version = 6.1.7600) - Type = NTWorkstation Internet Explorer (Version = 9.0.8112.16421) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 3,60 Gb Total Physical Memory | 1,35 Gb Available Physical Memory | 37,40% Memory free 7,21 Gb Paging File | 4,33 Gb Available in Paging File | 60,05% Paging File free Paging file location(s): ?:\pagefile.sys [binary data] %SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86) Drive C: | 38,96 Gb Total Space | 2,77 Gb Free Space | 7,11% Space Free | Partition Type: NTFS Drive D: | 259,03 Gb Total Space | 42,99 Gb Free Space | 16,60% Space Free | Partition Type: NTFS Drive H: | 465,65 Gb Total Space | 125,01 Gb Free Space | 26,85% Space Free | Partition Type: FAT32 Computer Name: DORIS-PC | User Name: Doris | Logged in as Administrator. Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 90 Days ========== Processes (SafeList) ========== PRC - C:\Users\Doris\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe (Malwarebytes Corporation) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) PRC - C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.) PRC - D:\Program Files (x86)\Microsoft Office\OFFICE11\WINWORD.EXE (Microsoft Corporation) PRC - D:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLOOK.EXE (Microsoft Corporation) ========== Modules (No Company Name) ========== MOD - C:\Program Files (x86)\Java\jre6\bin\jp2iexp.dll () MOD - C:\Program Files (x86)\Java\jre6\bin\jp2native.dll () MOD - D:\Program Files (x86)\Microsoft Office\OFFICE11\OUTLCTL.DLL () ========== Services (SafeList) ========== SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD) SRV:64bit: - (AMD FUEL Service) -- c:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe (Advanced Micro Devices, Inc.) SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated) SRV - (wlidsvc) -- C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corp.) SRV - (AntiVirSchedulerService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG) SRV - (AntiVirService) -- C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG) SRV - (becldr3Service) -- C:\Program Files (x86)\BCL Technologies\easyConverter SDK 3\Common\becldr.exe () SRV - (IconMan_R) -- C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.) SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation) SRV - (AERTFilters) -- C:\Programme\Realtek\Audio\HDA\AERTSr64.exe (Andrea Electronics Corporation) SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV:64bit: - (avipbb) -- C:\Windows\SysNative\drivers\avipbb.sys (Avira GmbH) DRV:64bit: - (avgntflt) -- C:\Windows\SysNative\drivers\avgntflt.sys (Avira GmbH) DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation) DRV:64bit: - (avkmgr) -- C:\Windows\SysNative\drivers\avkmgr.sys (Avira GmbH) DRV:64bit: - (SynTP) -- C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated) DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.) DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices) DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.) DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.) DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Atheros Communications, Inc.) DRV:64bit: - (amd_sata) -- C:\Windows\SysNative\drivers\amd_sata.sys (Advanced Micro Devices) DRV:64bit: - (amd_xata) -- C:\Windows\SysNative\drivers\amd_xata.sys (Advanced Micro Devices) DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices) DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices) DRV:64bit: - (RSPCIESTOR) -- C:\Windows\SysNative\drivers\RtsPStor.sys (Realtek Semiconductor Corp.) DRV:64bit: - (usbfilter) -- C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices) DRV:64bit: - (amdiox64) -- C:\Windows\SysNative\drivers\amdiox64.sys (Advanced Micro Devices) DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.) DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation) DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company) DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology) DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation) DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation) DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation) DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.) DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.) DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A} IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = hxxp://www.bing.com/search?q={searchTerms}&FORM=IE8SRC IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/ IE - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp IE - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de IE - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 4B F7 98 A5 9F B1 CC 01 [binary data] IE - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000\..\URLSearchHook: {ebd898f8-fcf6-4694-bc3b-eabc7271eeb1} - No CLSID value found IE - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000\..\SearchScopes,DefaultScope = {6BC7BF22-BFCA-4EB6-B0BC-18CD7FAEF99B} IE - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000\..\SearchScopes\{6BC7BF22-BFCA-4EB6-B0BC-18CD7FAEF99B}: "URL" = hxxp://www.google.de/search?q={searchTerms} IE - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000\..\SearchScopes\{F0E081C6-AAB2-490A-93C4-10BB6F3C41B9}: "URL" = hxxp://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3196716 IE - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local ========== FireFox ========== FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: D:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll () FF - HKLM\Software\MozillaPlugins\@foxitsoftware.com/Foxit Reader Plugin,version=1.0,application/pdf: D:\Program Files (x86)\Foxit Software\Foxit Reader\plugins\npFoxitReaderPlugin.dll File not found FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=12.0.1.669: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nppl3260.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprjplug;version=12.0.1.669: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpchromebrowserrecordext;version=12.0.1.669: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprphtml5videoshim;version=12.0.1.669: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=12.0.1.669: C:\Program Files (x86)\Real\RealPlayer\Netscape6\nprpjplug.dll (RealNetworks, Inc.) FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011.12.03 13:50:43 | 000,000,000 | ---D | M] O1 HOSTS File: ([2009.06.10 23:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts O2:64bit: - BHO: (Windows Live ID Sign-in Helper) - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.) O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer) O2 - BHO: (Java(tm) Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.) O3 - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000\..\Toolbar\WebBrowser: (no name) - {EBD898F8-FCF6-4694-BC3B-EABC7271EEB1} - No CLSID value found. O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RtkNGUI64.exe (Realtek Semiconductor) O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.) O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG) O4 - HKLM..\Run: [ControlCenter3] C:\Program Files (x86)\Brother\ControlCenter3\brctrcen.exe (Brother Industries, Ltd.) O4 - HKLM..\Run: [PDFPrint] C:\Program Files (x86)\PDF24\pdf24.exe (Geek Software GmbH) O4 - HKLM..\Run: [StartCCC] c:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.) O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.) O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.) O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation) O4 - HKLM..\RunOnce: [ Malwarebytes Anti-Malware ] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation) O4 - HKLM..\RunOnce: [ Malwarebytes Anti-Malware (cleanup)] C:\ProgramData\Malwarebytes\Malwarebytes' Anti-Malware\cleanup.dll (Malwarebytes Corporation) O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found O4 - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000..\RunOnce: [FlashPlayerUpdate] C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe (Adobe Systems Incorporated) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O8:64bit: - Extra context menu item: Nach Microsoft &Excel exportieren - D:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation) O8 - Extra context menu item: Nach Microsoft &Excel exportieren - D:\Program Files (x86)\Microsoft Office\OFFICE11\EXCEL.EXE (Microsoft Corporation) O9 - Extra Button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\Program Files (x86)\Microsoft Office\OFFICE11\REFIEBAR.DLL (Microsoft Corporation) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Programme\Bonjour\mdnsNSP.dll (Apple Inc.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000008 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Programme\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL (Microsoft Corp.) O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000009 - mmswsock.dll File not found O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000010 - mmswsock.dll File not found O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.) O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000009 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found O10 - Protocol_Catalog9\Catalog_Entries\000000000010 - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WLIDNSP.DLL File not found O1364bit: - gopher Prefix: missing O13 - gopher Prefix: missing O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} hxxp://appldnld.apple.com.edgesuite.net/content.info.apple.com/QuickTime/qtactivex/qtplugin.cab (QuickTime Plugin Control) O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1D11838F-BEBE-48F8-B12D-7978CEAE674B}: DhcpNameServer = 192.168.0.1 O18:64bit: - Protocol\Handler\msdaipp - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\0x00000001 - No CLSID value found O18:64bit: - Protocol\Handler\msdaipp\oledb - No CLSID value found O18:64bit: - Protocol\Handler\mso-offdap - No CLSID value found O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found O18 - Protocol\Handler\msdaipp\0x00000001 {E1D2BF42-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\msdaipp\oledb {E1D2BF40-A96B-11d1-9C6B-0000F875AC61} - C:\Program Files (x86)\Common Files\SYSTEM\OLE DB\msdaipp.dll (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap {3D9F03FA-7A94-11D3-BE81-0050048385D1} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\10\OWC10.DLL (Microsoft Corporation) O18 - Protocol\Handler\mso-offdap11 {32505114-5902-49B2-880A-1F7738E5A384} - C:\PROGRA~2\COMMON~1\MICROS~1\WEBCOM~1\11\OWC11.DLL (Microsoft Corporation) O18:64bit: - Protocol\Filter\text/xml - No CLSID value found O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation) O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation) O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation) O20 - HKU\S-1-5-21-2010919023-3803081666-3125430051-1000 Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation) O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found. O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2012.05.20 10:46:10 | 000,000,000 | ---D | M] - D:\Automatisch zu iTunes hinzufügen -- [ NTFS ] O34 - HKLM BootExecute: (autocheck autochk *) O35:64bit: - HKLM\..comfile [open] -- "%1" %* O35:64bit: - HKLM\..exefile [open] -- "%1" %* O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %* O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3) O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2) O38 - SubSystems\\Windows: (ServerDll=sxssrv,4) ========== Files/Folders - Created Within 90 Days ========== [2013.05.09 11:48:12 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Doris\Desktop\OTL.exe [2013.05.09 06:54:11 | 000,000,000 | ---D | C] -- C:\Users\Doris\AppData\Roaming\Malwarebytes [2013.05.09 06:53:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware [2013.05.09 06:53:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes [2013.05.09 06:53:36 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2013.05.09 06:53:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware [2013.05.09 06:53:20 | 000,000,000 | ---D | C] -- C:\Users\Doris\AppData\Local\Programs [2013.05.09 06:52:46 | 010,285,040 | ---- | C] (Malwarebytes Corporation ) -- C:\Users\Doris\Desktop\mbam-setup-1.75.0.1300.exe [2013.05.05 15:35:18 | 000,000,000 | ---D | C] -- C:\Users\Doris\Desktop\Neuer Ordner [2013.04.25 20:03:49 | 000,000,000 | ---D | C] -- C:\Users\Doris\AppData\Roaming\Windows Live Writer [2013.04.25 20:03:49 | 000,000,000 | ---D | C] -- C:\Users\Doris\AppData\Local\Windows Live Writer [2013.04.15 17:49:39 | 000,000,000 | ---D | C] -- C:\Program Files\Windows Live [2013.04.15 17:48:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Windows Live [2013.04.15 17:45:43 | 000,000,000 | ---D | C] -- C:\Users\Doris\AppData\Local\Windows Live [2013.04.15 17:45:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Windows Live [2013.03.10 22:04:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF24 [2013.03.08 15:29:17 | 000,000,000 | ---D | C] -- C:\Users\Doris\Desktop\Neuer Ordner (2) [2013.03.01 21:35:19 | 000,000,000 | ---D | C] -- C:\Users\Doris\Desktop\Klausi [2013.02.25 21:16:16 | 000,000,000 | ---D | C] -- C:\Users\Doris\AppData\Roaming\Emfai [2013.02.25 21:16:16 | 000,000,000 | ---D | C] -- C:\Users\Doris\AppData\Roaming\Egiko [2013.02.16 08:45:16 | 000,096,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll [2013.02.16 08:45:16 | 000,073,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll [2013.02.16 08:45:12 | 000,248,320 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll [2013.02.16 08:45:12 | 000,176,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll [2013.02.16 08:45:11 | 000,173,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe [2013.02.16 08:45:11 | 000,142,848 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe [2013.02.16 08:45:10 | 000,237,056 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\url.dll [2013.02.16 08:45:10 | 000,231,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\url.dll [2013.02.16 08:45:08 | 001,494,528 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl [2013.02.16 08:45:08 | 001,427,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl [2013.02.16 08:45:07 | 002,312,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll [2013.02.16 08:45:07 | 000,729,088 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll [2013.02.16 08:45:01 | 000,816,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript.dll [2013.02.16 08:45:01 | 000,717,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript.dll [2013.02.16 08:45:01 | 000,599,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll [2013.02.13 19:53:59 | 005,500,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe [2013.02.13 19:53:57 | 003,957,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe [2013.02.13 19:53:57 | 003,902,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe [2013.02.13 19:53:55 | 001,161,216 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\kernel32.dll [2013.02.13 19:53:55 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll [2013.02.13 19:53:55 | 000,362,496 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64win.dll [2013.02.13 19:53:55 | 000,338,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\conhost.exe [2013.02.13 19:53:55 | 000,215,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winsrv.dll [2013.02.13 19:53:54 | 000,243,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64.dll [2013.02.13 19:53:54 | 000,025,600 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\setup16.exe [2013.02.13 19:53:54 | 000,016,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntvdm64.dll [2013.02.13 19:53:54 | 000,014,336 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntvdm64.dll [2013.02.13 19:53:54 | 000,007,680 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\instnm.exe [2013.02.13 19:53:54 | 000,005,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wow32.dll [2013.02.13 19:53:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll [2013.02.13 19:53:54 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll [2013.02.13 19:53:53 | 000,013,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wow64cpu.dll [2013.02.13 19:53:53 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll [2013.02.13 19:53:53 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll [2013.02.13 19:53:53 | 000,005,120 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll [2013.02.13 19:53:53 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll [2013.02.13 19:53:53 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll [2013.02.13 19:53:53 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll [2013.02.13 19:53:53 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll [2013.02.13 19:53:53 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll [2013.02.13 19:53:53 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll [2013.02.13 19:53:53 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll [2013.02.13 19:53:53 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll [2013.02.13 19:53:52 | 000,006,144 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll [2013.02.13 19:53:52 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll [2013.02.13 19:53:52 | 000,004,608 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll [2013.02.13 19:53:52 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll [2013.02.13 19:53:52 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll [2013.02.13 19:53:52 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll [2013.02.13 19:53:52 | 000,004,096 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,584 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll [2013.02.13 19:53:52 | 000,003,072 | -H-- | C] (Microsoft Corporation) -- C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll [2013.02.13 19:53:52 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\user.exe [2013.02.13 19:53:49 | 000,287,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\FWPKCLNT.SYS [2013.02.10 08:48:15 | 000,000,000 | ---D | C] -- C:\Users\Doris\Desktop\Sonstiges [2013.02.10 08:47:27 | 000,000,000 | ---D | C] -- C:\Users\Doris\Desktop\Schule [2013.02.10 08:44:28 | 000,000,000 | ---D | C] -- C:\Users\Doris\Desktop\Urlaub [2011.12.26 11:48:21 | 005,274,776 | ---- | C] (Canneverbe Limited ) -- C:\Users\Doris\cdbxp_setup_4.4.0.2838.exe ========== Files - Modified Within 90 Days ========== [2013.05.09 11:53:03 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job [2013.05.09 11:48:13 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Doris\Desktop\OTL.exe [2013.05.09 06:53:39 | 000,001,113 | ---- | M] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.05.09 06:52:50 | 010,285,040 | ---- | M] (Malwarebytes Corporation ) -- C:\Users\Doris\Desktop\mbam-setup-1.75.0.1300.exe [2013.05.05 15:40:27 | 001,498,568 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI [2013.05.05 15:40:27 | 000,654,400 | ---- | M] () -- C:\Windows\SysNative\perfh007.dat [2013.05.05 15:40:27 | 000,616,242 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat [2013.05.05 15:40:27 | 000,130,240 | ---- | M] () -- C:\Windows\SysNative\perfc007.dat [2013.05.05 15:40:27 | 000,106,622 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat [2013.05.02 12:22:39 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat [2013.04.14 11:54:15 | 000,093,467 | ---- | M] () -- C:\Users\Doris\Desktop\kit16runningordermitss.jpg [2013.04.04 14:50:32 | 000,025,928 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys [2013.03.13 19:53:23 | 000,693,976 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe [2013.03.13 19:53:23 | 000,073,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl [2013.03.12 18:52:30 | 000,018,784 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 [2013.03.12 18:52:30 | 000,018,784 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 [2013.03.12 18:46:19 | 095,023,320 | ---- | M] () -- C:\ProgramData\0.pad [2013.03.12 18:44:20 | 2902,646,784 | -HS- | M] () -- C:\hiberfil.sys [2013.03.10 22:04:56 | 000,001,872 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk [2013.03.10 22:04:56 | 000,001,857 | ---- | M] () -- C:\Users\Public\Desktop\PDF24 Fax.lnk [2013.03.02 19:10:52 | 000,032,561 | ---- | M] () -- C:\Users\Doris\Desktop\kreator_golden_age.gp3 [2013.02.26 08:28:52 | 000,003,461 | ---- | M] () -- C:\ProgramData\0.js [2013.02.26 08:28:52 | 000,000,147 | ---- | M] () -- C:\ProgramData\0.reg [2013.02.26 08:28:52 | 000,000,090 | ---- | M] () -- C:\ProgramData\0.bat [2013.02.25 20:10:00 | 003,515,540 | R--- | M] () -- C:\Users\Doris\Desktop\Kreator Golden Age.mp3 [2013.02.16 10:24:20 | 000,357,776 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT [2013.02.13 20:16:03 | 000,474,839 | ---- | M] () -- C:\Users\Doris\Desktop\Reiserücktritt.PDF ========== Files Created - No Company Name ========== [2013.05.09 06:53:39 | 000,001,113 | ---- | C] () -- C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk [2013.04.15 17:50:32 | 000,001,458 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Windows Live Mail.lnk [2013.04.14 11:54:22 | 000,093,467 | ---- | C] () -- C:\Users\Doris\Desktop\kit16runningordermitss.jpg [2013.03.10 22:04:56 | 000,001,872 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Editor.lnk [2013.03.10 22:04:56 | 000,001,857 | ---- | C] () -- C:\Users\Public\Desktop\PDF24 Fax.lnk [2013.03.02 19:10:52 | 000,032,561 | ---- | C] () -- C:\Users\Doris\Desktop\kreator_golden_age.gp3 [2013.02.26 08:28:52 | 000,003,461 | ---- | C] () -- C:\ProgramData\0.js [2013.02.26 08:28:52 | 000,000,147 | ---- | C] () -- C:\ProgramData\0.reg [2013.02.26 08:28:52 | 000,000,090 | ---- | C] () -- C:\ProgramData\0.bat [2013.02.26 08:28:47 | 095,023,320 | ---- | C] () -- C:\ProgramData\0.pad [2013.02.25 20:10:00 | 003,515,540 | R--- | C] () -- C:\Users\Doris\Desktop\Kreator Golden Age.mp3 [2013.02.13 20:16:53 | 000,474,839 | ---- | C] () -- C:\Users\Doris\Desktop\Reiserücktritt.PDF [2012.08.03 20:54:26 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat [2012.04.28 08:05:39 | 000,000,416 | ---- | C] () -- C:\Windows\BRWMARK.INI [2012.04.28 08:05:39 | 000,000,034 | ---- | C] () -- C:\Windows\SysWow64\BD7030.DAT [2012.04.28 08:04:02 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\BRTCPCON.DLL [2012.04.28 08:04:00 | 000,000,114 | ---- | C] () -- C:\Windows\SysWow64\BRLMW03A.INI [2012.01.22 16:13:35 | 000,032,256 | ---- | C] () -- C:\Windows\SysWow64\AVSredirect.dll [2012.01.15 19:19:25 | 000,107,520 | RHS- | C] () -- C:\Windows\SysWow64\TAKDSDecoder.dll [2011.12.26 11:39:54 | 000,120,979 | ---- | C] () -- C:\Users\Doris\Bestellung drucken.mht [2011.12.03 11:57:41 | 000,000,400 | ---- | C] () -- C:\Windows\ODBC.INI [2011.12.02 18:09:15 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin [2011.08.20 04:26:18 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll [2011.07.05 12:47:06 | 000,059,904 | ---- | C] () -- C:\Windows\SysWow64\OVDecode.dll ========== ZeroAccess Check ========== [2009.07.14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini [HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] [HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64 "ThreadingModel" = Both "" = C:\$Recycle.Bin\S-1-5-21-2010919023-3803081666-3125430051-1000\$cca091b872fa1517e84ac33cd656dfc8\n. -- File not found [HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64 "" = C:\Windows\SysNative\shell32.dll -- [2012.06.09 07:30:56 | 014,165,504 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] "" = %SystemRoot%\system32\shell32.dll -- [2012.06.09 06:46:56 | 012,868,608 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Apartment [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64 "" = C:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\n -- File not found "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] "" = %systemroot%\system32\wbem\fastprox.dll -- [2009.07.14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Free [HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64 "" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009.07.14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation) "ThreadingModel" = Both [HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] < End of report > |
09.05.2013, 16:18 | #4 |
/// Helfer-Team | Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop Du hast einen Rookit auf dem Rechner! Die Bereinigung besteht aus mehreren Schritten, die ausgefuehrt werden muessen. Diese Nacheinander abarbeiten und die 3 Logs, die dabei erstellt werden bitte in deine naechste Antwort einfuegen. Sollte der OTL-FIX nicht richig durchgelaufen sein. Fahre nicht fort, sondern melde dies bitte. 1. Schritt Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL [2013.03.12 18:46:19 | 095,023,320 | ---- | M] () -- C:\ProgramData\0.pad [2013.02.26 08:28:52 | 000,003,461 | ---- | M] () -- C:\ProgramData\0.js [2013.02.26 08:28:52 | 000,000,147 | ---- | M] () -- C:\ProgramData\0.reg [2013.02.26 08:28:52 | 000,000,090 | ---- | M] () -- C:\ProgramData\0.bat :Files C:\ProgramData\*.exe C:\ProgramData\*.dll C:\ProgramData\*.tmp C:\ProgramData\TEMP C:\Users\Doris\*.tmp C:\Users\Doris\AppData\*.dll C:\Users\Doris\AppData\*.exe C:\Users\Doris\AppData\Local\Temp\*.exe C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache ipconfig /flushdns /c :Commands [emptytemp]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! 2. Schritt Downloade dir bitte Malwarebytes Anti-Rootkit und speichere es auf deinem Desktop.
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers danach: 3. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
10.05.2013, 07:43 | #5 |
| Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop Hallo, OTL fordert (wie in Deinem Post erwähnt) einen Neustart, besteht die Gefahr, dass nach dem Neustart mein Desktop wieder durch den GVU-Trojaner gesperrt wird? |
10.05.2013, 15:09 | #6 |
/// Helfer-Team | Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop Nein, der OTL Fix sorgt dafuer, das die SPerre entfernt wird und dann muessen wird deinen Rechner absichern. Bitte die Anweisungen durchfuehren.
__________________ --> Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop |
10.05.2013, 17:37 | #7 |
| Problem mit GUV Trojaner 2.11 auf Windows 7 LaptopCode:
ATTFilter All processes killed ========== OTL ========== C:\ProgramData\0.pad moved successfully. C:\ProgramData\0.js moved successfully. C:\ProgramData\0.reg moved successfully. C:\ProgramData\0.bat moved successfully. ========== FILES ========== File\Folder C:\ProgramData\*.exe not found. File\Folder C:\ProgramData\*.dll not found. File\Folder C:\ProgramData\*.tmp not found. File\Folder C:\ProgramData\TEMP not found. File\Folder C:\Users\Doris\*.tmp not found. File\Folder C:\Users\Doris\AppData\*.dll not found. File\Folder C:\Users\Doris\AppData\*.exe not found. C:\Users\Doris\AppData\Local\Temp\InstallFlashPlayer.exe moved successfully. C:\Users\Doris\AppData\Local\Temp\pdf24-creator-update.exe moved successfully. C:\Users\Doris\AppData\Local\Temp\taskmanger.exe moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully. C:\Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Doris\Desktop\cmd.bat deleted successfully. C:\Users\Doris\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Doris ->Temp folder emptied: 118427808 bytes ->Temporary Internet Files folder emptied: 510089334 bytes ->Flash cache emptied: 15734649 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 335927850 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 36028471 bytes RecycleBin emptied: 16892362461 bytes Total Files Cleaned = 17.079,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 05102013_083749 Files\Folders moved on Reboot... File\Folder C:\Users\Doris\AppData\Local\Temp\hsperfdata_Doris\11884 not found! C:\Users\Doris\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. File\Folder C:\Users\Doris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\W5RLTL52\134499-problem-guv-trojaner-2-11-windows-7-laptop[1].htm not found! File\Folder C:\Users\Doris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MJXSVY00\si[1].htm not found! File\Folder C:\Users\Doris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\MJXSVY00\si[2].htm not found! File\Folder C:\Users\Doris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H5QO4DBW\ads[3].htm not found! File\Folder C:\Users\Doris\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4RT6LAM4\ads[2].htm not found! PendingFileRenameOperations files... Registry entries deleted on Reboot... |
10.05.2013, 18:59 | #8 |
/// Helfer-Team | Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop Schritt 2 und 3? |
11.05.2013, 08:15 | #9 |
| Problem mit GUV Trojaner 2.11 auf Windows 7 LaptopCode:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.05.0.1001 www.malwarebytes.org Database version: v2013.05.10.06 Windows 7 x64 NTFS Internet Explorer 9.0.8112.16421 Doris :: DORIS-PC [administrator] 10.05.2013 18:58:33 mbar-log-2013-05-10 (18-58-33).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 28756 Time elapsed: 14 minute(s), 50 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\SOFTWARE\CLASSES\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9} (Hijack.Trojan.Siredef.C) -> Delete on reboot. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 3 HKCU\SOFTWARE\CLASSES\CLSID\{FBEB8A05-BEEE-4442-804E-409D6C4515E9}\INPROCSERVER32| (Trojan.0Access) -> Bad: (C:\$Recycle.Bin\S-1-5-21-2010919023-3803081666-3125430051-1000\$cca091b872fa1517e84ac33cd656dfc8\n.) Good: (shell32.dll) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\INPROCSERVER32| (Trojan.0Access) -> Bad: (C:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\n.) Good: (fastprox.dll) -> Delete on reboot. HKLM\SOFTWARE\CLASSES\CLSID\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\INPROCSERVER32| (Hijack.Trojan.Siredef.C) -> Bad: (C:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\n.) Good: (%systemroot%\system32\wbem\fastprox.dll) -> Delete on reboot. Folders Detected: 6 c:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\U (Trojan.Siredef.C) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-21-2010919023-3803081666-3125430051-1000\$cca091b872fa1517e84ac33cd656dfc8\U (Trojan.Siredef.C) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\L (Trojan.Siredef.C) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-21-2010919023-3803081666-3125430051-1000\$cca091b872fa1517e84ac33cd656dfc8\L (Trojan.Siredef.C) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8 (Trojan.Siredef.C) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-21-2010919023-3803081666-3125430051-1000\$cca091b872fa1517e84ac33cd656dfc8 (Trojan.Siredef.C) -> Delete on reboot. Files Detected: 12 c:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\@ (Trojan.Siredef.C) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\n (Trojan.0Access) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-21-2010919023-3803081666-3125430051-1000\$cca091b872fa1517e84ac33cd656dfc8\@ (Trojan.Siredef.C) -> Delete on reboot. c:\Windows\assembly\GAC_32\Desktop.ini (Rootkit.0access) -> Delete on reboot. c:\Windows\assembly\GAC_64\Desktop.ini (Rootkit.0access) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\U\00000004.@ (Trojan.Siredef.C) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\U\00000008.@ (Trojan.Siredef.C) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\U\000000cb.@ (Trojan.Siredef.C) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\U\80000000.@ (Trojan.Siredef.C) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\U\80000032.@ (Trojan.Siredef.C) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\U\80000064.@ (Trojan.Siredef.C) -> Delete on reboot. c:\$Recycle.Bin\S-1-5-18\$cca091b872fa1517e84ac33cd656dfc8\L\00000004.@ (Trojan.Siredef.C) -> Delete on reboot. (end) Hier auch noch das zweite File von mbar: Code:
ATTFilter Malwarebytes Anti-Rootkit BETA 1.05.0.1001 www.malwarebytes.org Database version: v2013.05.10.07 Windows 7 x64 NTFS Internet Explorer 9.0.8112.16421 Doris :: DORIS-PC [administrator] 10.05.2013 19:24:51 mbar-log-2013-05-10 (19-24-51).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 28665 Time elapsed: 18 minute(s), 3 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 1 HKCU\SOFTWARE\CLASSES\CLSID\{FBEB8A05-BEEE-4442-804E-409D6C4515E9} (Hijack.Trojan.Siredef.C) -> Delete on reboot. Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) Code:
ATTFilter # AdwCleaner v2.300 - Datei am 11/05/2013 um 09:20:22 erstellt # Aktualisiert am 28/04/2013 von Xplode # Betriebssystem : Windows 7 Home Premium (64 bits) # Benutzer : Doris - DORIS-PC # Bootmodus : Normal # Ausgeführt unter : C:\Users\Doris\Desktop\adwcleaner.exe # Option [Löschen] **** [Dienste] **** Gestoppt & Gelöscht : InstallBrainService ***** [Dateien / Ordner] ***** Datei Gelöscht : C:\user.js Ordner Gelöscht : C:\Program Files (x86)\Conduit Ordner Gelöscht : C:\ProgramData\Babylon Ordner Gelöscht : C:\Users\Doris\AppData\Local\Babylon Ordner Gelöscht : C:\Users\Doris\AppData\Local\Conduit Ordner Gelöscht : C:\Users\Doris\AppData\LocalLow\BabylonToolbar Ordner Gelöscht : C:\Users\Doris\AppData\LocalLow\Conduit Ordner Gelöscht : C:\Users\Doris\AppData\LocalLow\PriceGong Ordner Gelöscht : C:\Users\Doris\AppData\Roaming\Babylon Ordner Gelöscht : C:\Users\Doris\AppData\Roaming\OpenCandy ***** [Registrierungsdatenbank] ***** Schlüssel Gelöscht : HKCU\Software\APN PIP Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\ConduitSearchScopes Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\Crossrider Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\PriceGong Schlüssel Gelöscht : HKCU\Software\AppDataLow\Software\SmartBar Schlüssel Gelöscht : HKCU\Software\Cr_Installer Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Schlüssel Gelöscht : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKLM\Software\Babylon Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\{BDB69379-802F-4EAF-B541-F8DE92DD98DB} Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\AppID\escort.DLL Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\bbylntlbr.bbylntlbrHlpr.1 Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Prod.cap Schlüssel Gelöscht : HKLM\SOFTWARE\Classes\Toolbar.CT3196716 Schlüssel Gelöscht : HKLM\Software\Conduit Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\MyBabylontb_RASMANCS Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Savings Sidekick_RASAPI32 Schlüssel Gelöscht : HKLM\SOFTWARE\Microsoft\Tracing\Savings Sidekick_RASMANCS Schlüssel Gelöscht : HKLM\Software\PIP Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{2EECD738-5844-4A99-B4B6-146BF802613B} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{3C471948-F874-49F5-B338-4F214A2EE0B1} Schlüssel Gelöscht : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{E46C8196-B634-44A1-AF6E-957C64278AB1} ***** [Internet Browser] ***** -\\ Internet Explorer v9.0.8112.16464 [OK] Die Registrierungsdatenbank ist sauber. ************************* AdwCleaner[R1].txt - [3208 octets] - [11/05/2013 09:19:45] AdwCleaner[S1].txt - [3152 octets] - [11/05/2013 09:20:22] ########## EOF - C:\AdwCleaner[S1].txt - [3212 octets] ########## |
11.05.2013, 11:12 | #10 |
/// Helfer-Team | Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop Sehr gut! Downloade dir bitte aswMBR.exe und speichere die Datei auf deinem Desktop.
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). danach: ESET Online Scanner
danach: Downloade Dir bitte SecurityCheck und:
|
12.05.2013, 08:15 | #11 |
| Problem mit GUV Trojaner 2.11 auf Windows 7 LaptopCode:
ATTFilter aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2013-05-11 12:20:53 ----------------------------- 12:20:53.525 OS Version: Windows x64 6.1.7601 Service Pack 1 12:20:53.525 Number of processors: 2 586 0x100 12:20:53.540 ComputerName: DORIS-PC UserName: Doris 12:20:55.412 Initialize success 12:37:05.073 AVAST engine defs: 13051100 08:52:10.487 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\0000005e 08:52:10.487 Disk 0 Vendor: ST320LT0 0001 Size: 305245MB BusType: 11 08:52:10.861 Disk 0 MBR read successfully 08:52:10.877 Disk 0 MBR scan 08:52:11.095 Disk 0 Windows 7 default MBR code 08:52:11.111 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 100 MB offset 2048 08:52:11.173 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 39900 MB offset 206848 08:52:11.204 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 265243 MB offset 81922048 08:52:11.470 Disk 0 scanning C:\Windows\system32\drivers 08:52:52.083 Service scanning 08:54:20.175 Modules scanning 08:54:20.207 Disk 0 trace - called modules: 08:54:20.238 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys ACPI.sys storport.sys hal.dll amd_sata.sys 08:54:20.753 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8004112060] 08:54:20.753 3 CLASSPNP.SYS[fffff880018c943f] -> nt!IofCallDriver -> [0xfffffa8003f488c0] 08:54:20.768 5 amd_xata.sys[fffff88001127a1d] -> nt!IofCallDriver -> [0xfffffa8003f46620] 08:54:20.784 7 ACPI.sys[fffff88000f4b7a1] -> nt!IofCallDriver -> \Device\0000005e[0xfffffa8003f24540] 08:54:27.663 AVAST engine scan C:\Windows 08:54:37.507 AVAST engine scan C:\Windows\system32 09:07:04.342 AVAST engine scan C:\Windows\system32\drivers 09:07:34.659 AVAST engine scan C:\Users\Doris 09:12:05.591 AVAST engine scan C:\ProgramData 09:12:45.826 Scan finished successfully 09:14:14.419 Disk 0 MBR has been saved successfully to "C:\Users\Doris\Desktop\MBR.dat" 09:14:14.435 The log file has been saved successfully to "C:\Users\Doris\Desktop\aswMBR.txt" |
12.05.2013, 11:35 | #12 |
/// Helfer-Team | Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop Hast du schon die restlichen Logs? |
14.05.2013, 06:52 | #13 |
| Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop Hallo, die anderen beiden kommen heute Abend, sorry für die Verzögerung. |
14.05.2013, 11:12 | #14 |
/// Helfer-Team | Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop Kein Problem. Alles klar. |
15.05.2013, 06:24 | #15 |
| Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop Ich habe ESET nachts laufen lassen, am Morgen war das Programm geschlossen, ich hoffe das Logfile passt so: Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=0048f5dfd03a52498d03c86605c64bb7 # engine=13811 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-05-12 11:01:07 # local_time=2013-05-12 01:01:07 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 99 88696 233776157 81465 0 # compatibility_mode=5893 16776573 100 94 11932 119986317 0 0 # scanned=263355 # found=7 # cleaned=0 # scan_time=7974 sh=193FE9E4B4DA909200D1FF0E37725B831B50C83F ft=0 fh=0000000000000000 vn="JS/Agent.NID trojan" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_ProgramData\0.js" sh=0505C649116B44BCEBA5B3B07126A148AD4C8DA8 ft=1 fh=ff66942ea3788043 vn="Win32/Sirefef.EV trojan" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_Users\Doris\AppData\Local\Temp\taskmanger.exe" sh=58C5B7C92DCC85CD1D20390674E65B40F130F2DA ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\d24bc10-19bcd900" sh=4957545AD458D628F52DC84B4B60D133A72D59A4 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\2e57a4d6-74434165" sh=C9A2F45813060C92D72E58A902BEB5866EE445C4 ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.NNK trojan" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\4638ecd7-3dd3a9c2" sh=CE67EBA7F8B48105CC8B2CC46CEF5C2E2811B529 ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.NPK trojan" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\3edb7cdb-32ee2194" sh=E5E7E6939C21AF7939DC6A68C45ED59A62A45679 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-1723.JT trojan" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\835bee1-22162378" ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=0048f5dfd03a52498d03c86605c64bb7 # engine=13823 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-05-14 10:11:52 # local_time=2013-05-15 12:11:52 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.1.7601 NT Service Pack 1 # compatibility_mode=1799 16775165 100 99 215334 233989202 208097 0 # compatibility_mode=5893 16776573 100 94 224977 120199362 0 0 # scanned=265768 # found=7 # cleaned=0 # scan_time=58967 sh=193FE9E4B4DA909200D1FF0E37725B831B50C83F ft=0 fh=0000000000000000 vn="JS/Agent.NID trojan" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_ProgramData\0.js" sh=0505C649116B44BCEBA5B3B07126A148AD4C8DA8 ft=1 fh=ff66942ea3788043 vn="Win32/Sirefef.EV trojan" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_Users\Doris\AppData\Local\Temp\taskmanger.exe" sh=58C5B7C92DCC85CD1D20390674E65B40F130F2DA ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16\d24bc10-19bcd900" sh=4957545AD458D628F52DC84B4B60D133A72D59A4 ft=0 fh=0000000000000000 vn="multiple threats" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22\2e57a4d6-74434165" sh=C9A2F45813060C92D72E58A902BEB5866EE445C4 ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.NNK trojan" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23\4638ecd7-3dd3a9c2" sh=CE67EBA7F8B48105CC8B2CC46CEF5C2E2811B529 ft=0 fh=0000000000000000 vn="Java/Exploit.Agent.NPK trojan" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27\3edb7cdb-32ee2194" sh=E5E7E6939C21AF7939DC6A68C45ED59A62A45679 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2012-1723.JT trojan" ac=I fn="C:\_OTL\MovedFiles\05102013_083749\C_Users\Doris\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33\835bee1-22162378" Code:
ATTFilter Results of screen317's Security Check version 0.99.63 Windows 7 Service Pack 1 x64 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` Avira Desktop Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java(TM) 6 Update 30 Java version out of Date! ````````Process Check: objlist.exe by Laurent```````` Avira Antivir avgnt.exe Avira Antivir avguard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: ````````````````````End of Log`````````````````````` |
Themen zu Problem mit GUV Trojaner 2.11 auf Windows 7 Laptop |
betriebssystem, bildschirmsperre, entfernen, funktioniert, gesperrt, hallo zusammen, hijack.trojan.siredef.c, hochfahren, java/exploit.agent.nnk, java/exploit.agent.npk, java/exploit.cve-2012-1723.jt, js/agent.nid, outlook, rootkit.0access, spyware.zbot.usbv, trojan.0access, trojan.agent, trojan.siredef.c, trojaner, win32/sirefef.ev, windows, windows 7, zusammen |