|
Plagegeister aller Art und deren Bekämpfung: Polizeivirus in ÖWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
23.05.2013, 13:48 | #1 |
| Polizeivirus in Ö Hallo, der Polizevirus hat auch bei mir zugeschlagen (den hatte ich schon mal, diesmal habe ich aber nichts in Autostart gefunden und kriege ihn nicht weg). Nach dem Polizei-Schirm konnte ich aber den Vorgang des Abmeldens einleiten [Strg Alt Entf] und dann mit zahlreichen Tastenkombinationen Strg-C's das runter fahren mit [ Abbrechen ] abbrechen. Ich bin also "normal" im System; nur kommt der Polizei-Schirm nach jederm Neustart wieder. Habe also nach Lesung der Beiträge hier OTL gestartet und die beiden Logs gernriert -> 2 Anhänge. Ich bitte um Hilfe und danke im Voraus. |
23.05.2013, 13:51 | #2 |
/// Helfer-Team | Polizeivirus in ÖDie Bereinigung besteht aus mehreren Schritten, die ausgefuehrt werden muessen. Diese Nacheinander abarbeiten und die 3 Logs, die dabei erstellt werden bitte in deine naechste Antwort einfuegen. Sollte der OTL-FIX nicht richig durchgelaufen sein. Fahre nicht fort, sondern melde dies bitte. 1. Schritt Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL O4:64bit: - HKLM..\Run: [JAVA] C:\Windows\java.vbs () O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0 O20 - HKCU Winlogon: Shell - (C:\Users\Leo\AppData\Roaming\skype.dat) - C:\Users\Leo\AppData\Roaming\skype.dat () [2012/09/22 12:21:45 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\ProgramData\lsass.exe [2013/05/23 13:00:52 | 000,000,004 | ---- | M] () -- C:\Users\Leo\AppData\Roaming\skype.ini @Alternate Data Stream - 140 bytes -> C:\ProgramData\Temp:054203E4 @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:7631EA83 [2012/09/22 12:21:52 | 083,023,306 | ---- | C] () -- C:\ProgramData\dsgsdgdsgdsgw.pad [2012/12/22 20:24:39 | 000,001,725 | ---- | C] () -- C:\Users\Leo\save_e.cmd [2012/09/01 11:49:11 | 004,503,728 | ---- | C] () -- C:\ProgramData\ism_0_llatsni.pad [2012/01/11 00:00:38 | 000,098,304 | ---- | C] () -- C:\Users\Leo\AppData\Roaming\skype.dat :Files C:\ProgramData\*.exe C:\ProgramData\*.dll C:\ProgramData\*.tmp C:\ProgramData\TEMP C:\Users\Leo\*.tmp C:\Users\Leo\AppData\*.dll C:\Users\Leo\AppData\*.exe C:\Users\Leo\AppData\Local\Temp\*.exe C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache ipconfig /flushdns /c :Commands [emptytemp]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! 2. Schritt Downloade Dir bitte Malwarebytes Anti-Malware
danach: 3. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
__________________ |
23.05.2013, 14:07 | #3 |
| Polizeivirus in Ö Danke.
__________________Melde Schritt 1 durchgelaufen ... Code:
ATTFilter All processes killed ========== OTL ========== 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\JAVA deleted successfully. C:\Windows\java.vbs moved successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\PromptOnSecureDesktop deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell:C:\Users\Leo\AppData\Roaming\skype.dat deleted successfully. C:\Users\Leo\AppData\Roaming\skype.dat moved successfully. C:\ProgramData\lsass.exe moved successfully. C:\Users\Leo\AppData\Roaming\skype.ini moved successfully. ADS C:\ProgramData\Temp:054203E4 deleted successfully. ADS C:\ProgramData\Temp:7631EA83 deleted successfully. C:\ProgramData\dsgsdgdsgdsgw.pad moved successfully. C:\Users\Leo\save_e.cmd moved successfully. C:\ProgramData\ism_0_llatsni.pad moved successfully. File C:\Users\Leo\AppData\Roaming\skype.dat not found. ========== FILES ========== File\Folder C:\ProgramData\*.exe not found. File\Folder C:\ProgramData\*.dll not found. File\Folder C:\ProgramData\*.tmp not found. C:\ProgramData\Temp\{E3D04529-6EDB-11D8-A372-0050BAE317E1} folder moved successfully. C:\ProgramData\Temp\{C59C179C-668D-49A9-B6EA-0121CCFC1243} folder moved successfully. C:\ProgramData\Temp\{AB770FDE-8087-4C98-9A85-BD64262C104C} folder moved successfully. C:\ProgramData\Temp\{5DB1DF0C-AABC-4362-8A6D-CEFDFB036E41} folder moved successfully. C:\ProgramData\Temp\{40BF1E83-20EB-11D8-97C5-0009C5020658} folder moved successfully. C:\ProgramData\Temp folder moved successfully. File\Folder C:\Users\Leo\*.tmp not found. File\Folder C:\Users\Leo\AppData\*.dll not found. File\Folder C:\Users\Leo\AppData\*.exe not found. C:\Users\Leo\AppData\Local\Temp\detectionui_r.exe moved successfully. C:\Users\Leo\AppData\Local\Temp\EBU365B.EXE moved successfully. C:\Users\Leo\AppData\Local\Temp\GLF1B1.tmp.ConduitEngineSetup.exe moved successfully. C:\Users\Leo\AppData\Local\Temp\IZArcSetup.exe moved successfully. C:\Users\Leo\AppData\Local\Temp\MyBabylonTB_google_20120807.exe moved successfully. C:\Users\Leo\AppData\Local\Temp\SkypeSetup.exe moved successfully. C:\Users\Leo\AppData\Local\Temp\TerraTec_Home_Cinema_6.15.11.exe moved successfully. C:\Users\Leo\AppData\Local\Temp\UpdateCheckerSetup.exe moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully. C:\Users\Leo\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Leo\Documents\Downloads\cmd.bat deleted successfully. C:\Users\Leo\Documents\Downloads\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 57472 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Gast ->Temp folder emptied: 51811 bytes ->Temporary Internet Files folder emptied: 322302 bytes ->Flash cache emptied: 56502 bytes User: Leo ->Temp folder emptied: 5375503 bytes ->Temporary Internet Files folder emptied: 295476242 bytes ->FireFox cache emptied: 359922158 bytes ->Google Chrome cache emptied: 6992447 bytes ->Flash cache emptied: 260276 bytes User: Public User: Sandra ->Temp folder emptied: 57277 bytes ->Temporary Internet Files folder emptied: 327805 bytes ->FireFox cache emptied: 12145249 bytes ->Google Chrome cache emptied: 6447726 bytes ->Flash cache emptied: 57174 bytes User: Sophie ->Temp folder emptied: 2517947 bytes ->Temporary Internet Files folder emptied: 4188145 bytes ->FireFox cache emptied: 389850527 bytes ->Flash cache emptied: 58328 bytes User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56466 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 998556477 bytes %systemroot%\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 8693460 bytes %systemroot%\system32\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 753 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 305278 bytes %systemroot%\sysnative\config\systemprofile\AppData\LocalLow\Sun\Java\Deployment folder emptied: 749 bytes RecycleBin emptied: 64087207 bytes Total Files Cleaned = 2,056.00 mb OTL by OldTimer - Version 3.2.69.0 log created on 05232013_145843 ======================================== Melde mich nach dem Reboot zurück. Nennenswertes Vorkommnis: Nach auffällig langem "Hinunterfahren" kam ein Blue Screen mit "... DRIVER_POWER_STATE_FAILURE ..." Windows konnte danach aber normal gestartet werden. ... und der Polizeischirm ist weg. Nachtrag Erweiterung Log nach Reboot: Code:
ATTFilter ... OTL by OldTimer - Version 3.2.69.0 log created on 05232013_145843 Files\Folders moved on Reboot... C:\Users\Leo\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully. C:\Users\Leo\AppData\Local\Mozilla\Firefox\Profiles\vstmda8p.default\Cache\_CACHE_001_ moved successfully. C:\Users\Leo\AppData\Local\Mozilla\Firefox\Profiles\vstmda8p.default\Cache\_CACHE_002_ moved successfully. C:\Users\Leo\AppData\Local\Mozilla\Firefox\Profiles\vstmda8p.default\Cache\_CACHE_003_ moved successfully. C:\Users\Leo\AppData\Local\Mozilla\Firefox\Profiles\vstmda8p.default\Cache\_CACHE_MAP_ moved successfully. C:\Users\Leo\AppData\Local\Mozilla\Firefox\Profiles\vstmda8p.default\_CACHE_CLEAN_ moved successfully. File\Folder C:\Windows\temp\hsperfdata_LEO-PC$\2500 not found! File\Folder C:\Windows\temp\~bd4CD6.tmp not found! PendingFileRenameOperations files... Registry entries deleted on Reboot... Geändert von leowie (23.05.2013 um 14:44 Uhr) |
25.08.2013, 20:17 | #4 |
/// Helfer-Team | Polizeivirus in Ö Schrit 2 und 3? |
Themen zu Polizeivirus in Ö |
abbrechen, autostart, beiträge, bitte um hilfe, fahren, gefunde, gestartet, konnte, kriege, leiten, neustart, nichts, polizeivirus, runter, strg, strg alt entf, system, taste, tastenkombinationen, vorgang |