![]() |
|
Log-Analyse und Auswertung: GVU Trojaner Windows 7Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() GVU Trojaner Windows 7 Servus! Hab mir wohl auch einen GVU Trojaner eingefangen. Nach der Anmeldung kommt ein wießer Bilschirm mit Polizei-Emblem, GVU Emblem etc. Außerdem Zahlungsaufforderung via Paysafe. Kann mir jemand helfen? Hier das FRST Logfile: Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 29-06-2013 01 Ran by SYSTEM on 30-06-2013 18:04:18 Running from G:\ Windows 7 Home Premium (X64) OS Language: German Standard Internet Explorer Version 8 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and an extra Addition.txt log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [AmIcoSinglun64] C:\Program Files (x86)\AmIcoSingLun\AmIcoSinglun64.exe [324608 2010-06-10] (Alcor Micro Corp.) HKLM\...\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe [1842472 2009-09-17] (Synaptics Incorporated) HKLM\...\Run: [PLFSetI] C:\Windows\PLFSetI.exe [206208 2010-06-09] () HKLM\...\Run: [Acer ePower Management] C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerTray.exe [861216 2010-06-11] (Acer Incorporated) HKLM-x32\...\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe" [41056 2013-05-08] (Adobe Systems Incorporated) HKLM-x32\...\Run: [BackupManagerTray] "C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\BackupManagerTray.exe" -h -k [263936 2010-06-28] (NewTech Infosystems, Inc.) HKLM-x32\...\Run: [Camera Assistant Software] "C:\Program Files (x86)\Video Web Camera\traybar.exe" [600688 2010-07-15] (Chicony) HKLM-x32\...\Run: [AppleSyncNotifier] C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe [59240 2011-09-27] (Apple Inc.) HKLM-x32\...\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [958576 2013-04-04] (Adobe Systems Incorporated) HKLM-x32\...\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [59720 2013-01-28] (Apple Inc.) HKLM-x32\...\Run: [ConnectionCenter] "C:\Program Files (x86)\Citrix\ICA Client\concentr.exe" /startup [103768 2009-09-12] (Citrix Systems, Inc.) HKLM-x32\...\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe" [74752 2011-12-09] (Nullsoft, Inc.) HKLM-x32\...\Run: [Panda Security URL Filtering] "C:\ProgramData\Panda Security URL Filtering\Panda_URL_Filtering.exe" [235072 2013-04-11] (Visicom Media Inc.) HKLM-x32\...\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime [421888 2012-10-24] (Apple Inc.) HKLM-x32\...\Run: [PSUAMain] "C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAMain.exe" /LaunchSysTray [32736 2013-05-28] (Panda Security, S.L.) HKLM-x32\...\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe" [152392 2013-02-20] (Apple Inc.) HKU\Default\...\RunOnce: [ScrSav] C:\Program Files (x86)\Packard Bell\Screensaver\run_Packard Bell.exe /default [154144 2010-07-29] () HKU\Default User\...\RunOnce: [ScrSav] C:\Program Files (x86)\Packard Bell\Screensaver\run_Packard Bell.exe /default [154144 2010-07-29] () HKU\Thomas\...\Run: [MobileDocuments] C:\Program Files (x86)\Common Files\Apple\Internet Services\ubd.exe [x] HKU\Thomas\...\Winlogon: [Shell] explorer.exe,C:\Users\Thomas\AppData\Roaming\skype.dat [69632 2011-11-16] () <==== ATTENTION ==================== Services (Whitelisted) ================= S2 ePowerSvc; C:\Program Files\Packard Bell\Packard Bell Power Management\ePowerSvc.exe [868896 2010-06-11] (Acer Incorporated) S3 GameConsoleService; C:\Program Files (x86)\Packard Bell Games\Packard Bell Game Console\GameConsoleService.exe [246520 2010-04-03] (WildTangent, Inc.) S2 GREGService; C:\Program Files (x86)\Packard Bell\Registration\GREGsvc.exe [23584 2010-01-08] (Acer Incorporated) S3 McComponentHostService; C:\Program Files (x86)\McAfee Security Scan\3.0.318\McCHSvc.exe [235216 2013-02-05] (McAfee, Inc.) S2 NanoServiceMain; C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSANHost.exe [140768 2013-05-28] (Panda Security, S.L.) S2 NTI IScheduleSvc; C:\Program Files (x86)\NewTech Infosystems\Packard Bell MyBackup\IScheduleSvc.exe [255744 2010-06-28] (NewTech Infosystems, Inc.) S2 PSUAService; C:\Program Files (x86)\Panda Security\Panda Cloud Antivirus\PSUAService.exe [37344 2013-05-28] (Panda Security, S.L.) S2 Updater Service; C:\Program Files\Packard Bell\Packard Bell Updater\UpdaterService.exe [243232 2010-01-28] (Acer Group) S2 WajamUpdater; C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe [109064 2012-06-14] (Wajam) ==================== Drivers (Whitelisted) ==================== S1 NNSALPC; C:\Windows\System32\DRIVERS\NNSAlpc.sys [91368 2013-05-28] (Panda Security, S.L.) S1 NNSHTTP; C:\Windows\System32\DRIVERS\NNSHttp.sys [122088 2013-05-28] (Panda Security, S.L.) S1 NNSHTTPS; C:\Windows\System32\DRIVERS\NNSHttps.sys [109288 2013-05-28] (Panda Security, S.L.) S1 NNSIDS; C:\Windows\System32\DRIVERS\NNSIds.sys [114920 2013-05-28] (Panda Security, S.L.) S1 NNSNAHSL; C:\Windows\System32\DRIVERS\NNSNAHSL.sys [36584 2013-05-07] (Panda Security, S.L.) S1 NNSPICC; C:\Windows\System32\DRIVERS\NNSPicc.sys [95464 2013-05-28] (Panda Security, S.L.) S1 NNSPIHSW; C:\Windows\System32\DRIVERS\NNSPihsw.sys [69864 2013-05-28] (Panda Security, S.L.) S1 NNSPOP3; C:\Windows\System32\DRIVERS\NNSPop3.sys [119016 2013-05-28] (Panda Security, S.L.) S1 NNSPROT; C:\Windows\System32\DRIVERS\NNSProt.sys [305896 2013-05-28] (Panda Security, S.L.) S1 NNSPRV; C:\Windows\System32\DRIVERS\NNSPrv.sys [118504 2013-05-28] (Panda Security, S.L.) S1 NNSSMTP; C:\Windows\System32\DRIVERS\NNSSmtp.sys [114920 2013-05-28] (Panda Security, S.L.) S1 NNSSTRM; C:\Windows\System32\DRIVERS\NNSStrm.sys [246504 2013-05-28] (Panda Security, S.L.) S1 NNSTLSC; C:\Windows\System32\DRIVERS\NNSTlsc.sys [106216 2013-05-28] (Panda Security, S.L.) S2 PSINAflt; C:\Windows\System32\DRIVERS\PSINAflt.sys [168680 2013-05-28] (Panda Security, S.L.) S2 PSINFile; C:\Windows\System32\DRIVERS\PSINFile.sys [122088 2013-05-28] (Panda Security, S.L.) S1 PSINKNC; C:\Windows\System32\DRIVERS\psinknc.sys [205544 2013-05-28] (Panda Security, S.L.) S2 PSINProc; C:\Windows\System32\DRIVERS\PSINProc.sys [124648 2013-05-28] (Panda Security, S.L.) S2 PSINProt; C:\Windows\System32\DRIVERS\PSINProt.sys [137448 2013-05-29] (Panda Security, S.L.) S3 RimUsb; C:\Windows\System32\Drivers\RimUsb_AMD64.sys [27520 2007-05-14] (Research In Motion Limited) S2 DgiVecp; \??\C:\Windows\system32\Drivers\DgiVecp.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-06-30 18:04 - 2013-06-30 18:04 - 00000000 ____D C:\FRST 2013-06-29 23:39 - 2013-06-29 23:39 - 00524288 __ASH C:\Windows\System32\config\COMPONENTS{94124dbf-e157-11e2-b778-206a8a2183d0}.TMContainer00000000000000000002.regtrans-ms.bug 2013-06-29 23:39 - 2013-06-29 23:39 - 00524288 __ASH C:\Windows\System32\config\COMPONENTS{94124dbf-e157-11e2-b778-206a8a2183d0}.TMContainer00000000000000000001.regtrans-ms.bug 2013-06-29 23:39 - 2013-06-29 23:39 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{94124dbf-e157-11e2-b778-206a8a2183d0}.TM.blf.bug 2013-06-27 09:03 - 2013-06-30 02:54 - 00000004 ____A C:\Users\Thomas\AppData\Roaming\skype.ini 2013-06-26 08:04 - 2013-06-26 13:24 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-06-25 19:48 - 2013-06-27 08:37 - 00524288 __ASH C:\Windows\System32\config\COMPONENTS{30a430d2-de0d-11e2-8002-02f46a0353f5}.TMContainer00000000000000000001.regtrans-ms.bug 2013-06-25 19:48 - 2013-06-27 08:37 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{30a430d2-de0d-11e2-8002-02f46a0353f5}.TM.blf.bug 2013-06-23 02:13 - 2013-06-23 02:13 - 00000000 ____D C:\Users\Thomas\AppData\Local\AAV 2013-06-23 02:13 - 2013-06-23 02:13 - 00000000 ____D C:\ProgramData\AAV 2013-06-22 22:17 - 2013-06-22 22:17 - 00000000 ____D C:\Program Files (x86)\pandasecuritytb 2013-06-01 22:41 - 2013-06-02 00:04 - 00544603 ____A C:\Users\Thomas\Desktop\Babysitze.xlsx 2013-05-31 12:16 - 2013-05-31 12:42 - 00009239 ____A C:\Users\Thomas\Desktop\Kosten.xlsx 2013-05-31 12:07 - 2013-05-31 12:07 - 00000000 ____D C:\Users\Thomas\AppData\Local\Microsoft Help 2013-05-31 12:07 - 2013-05-31 12:07 - 00000000 ____D C:\ProgramData\Microsoft Help 2013-05-31 10:48 - 2013-05-31 12:18 - 00012324 ____A C:\Users\Thomas\Desktop\Geschenke Hochzeit.xlsx ==================== One Month Modified Files and Folders ======= 2013-06-30 18:04 - 2013-06-30 18:04 - 00000000 ____D C:\FRST 2013-06-30 07:57 - 2012-10-24 19:12 - 00031117 ____A C:\Windows\setupact.log 2013-06-30 07:57 - 2009-07-13 21:08 - 00000006 ___AH C:\Windows\Tasks\SA.DAT 2013-06-30 07:45 - 2012-06-08 23:06 - 00001106 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job 2013-06-30 02:54 - 2013-06-27 09:03 - 00000004 ____A C:\Users\Thomas\AppData\Roaming\skype.ini 2013-06-30 02:53 - 2012-12-10 08:44 - 00000000 ____D C:\ProgramData\Panda Security URL Filtering 2013-06-30 02:51 - 2010-11-04 01:51 - 01077381 ____A C:\Windows\WindowsUpdate.log 2013-06-30 02:51 - 2009-07-13 20:45 - 00017376 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-06-30 02:51 - 2009-07-13 20:45 - 00017376 ___AH C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-06-30 02:50 - 2011-01-28 16:04 - 00059096 ____A C:\Users\Thomas\AppData\Local\GDIPFONTCACHEV1.DAT 2013-06-30 02:48 - 2009-07-13 20:45 - 00322504 ____A C:\Windows\System32\FNTCACHE.DAT 2013-06-30 01:31 - 2009-07-13 18:34 - 68681728 ____A C:\Windows\System32\config\SOFTWARE.bug 2013-06-30 01:31 - 2009-07-13 18:34 - 25952256 ____A C:\Windows\System32\config\SYSTEM.bug 2013-06-30 01:31 - 2009-07-13 18:34 - 01048576 ____A C:\Windows\System32\config\DEFAULT.bug 2013-06-30 01:31 - 2009-07-13 18:34 - 00262144 ____A C:\Windows\System32\config\SECURITY.bug 2013-06-30 01:31 - 2009-07-13 18:34 - 00262144 ____A C:\Windows\System32\config\SAM.bug 2013-06-29 23:39 - 2013-06-29 23:39 - 00524288 __ASH C:\Windows\System32\config\COMPONENTS{94124dbf-e157-11e2-b778-206a8a2183d0}.TMContainer00000000000000000002.regtrans-ms.bug 2013-06-29 23:39 - 2013-06-29 23:39 - 00524288 __ASH C:\Windows\System32\config\COMPONENTS{94124dbf-e157-11e2-b778-206a8a2183d0}.TMContainer00000000000000000001.regtrans-ms.bug 2013-06-29 23:39 - 2013-06-29 23:39 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{94124dbf-e157-11e2-b778-206a8a2183d0}.TM.blf.bug 2013-06-29 23:39 - 2009-07-13 18:34 - 31457280 ____A C:\Windows\System32\config\COMPONENTS.bug 2013-06-29 23:38 - 2012-03-30 09:09 - 00000884 ____A C:\Windows\Tasks\Adobe Flash Player Updater.job 2013-06-29 23:36 - 2012-02-07 10:39 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\Dropbox 2013-06-29 23:35 - 2012-02-07 10:42 - 00000000 ___RD C:\Users\Thomas\Dropbox 2013-06-29 12:50 - 2012-06-08 23:06 - 00001110 ____A C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job 2013-06-27 13:15 - 2012-12-10 10:19 - 00032632 ____A C:\Windows\Tasks\SCHEDLGU.TXT 2013-06-27 09:11 - 2013-01-30 11:23 - 00000000 ____A C:\END 2013-06-27 08:37 - 2013-06-25 19:48 - 00524288 __ASH C:\Windows\System32\config\COMPONENTS{30a430d2-de0d-11e2-8002-02f46a0353f5}.TMContainer00000000000000000001.regtrans-ms.bug 2013-06-27 08:37 - 2013-06-25 19:48 - 00065536 __ASH C:\Windows\System32\config\COMPONENTS{30a430d2-de0d-11e2-8002-02f46a0353f5}.TM.blf.bug 2013-06-26 14:01 - 2012-06-24 01:22 - 00000000 ____D C:\Program Files (x86)\Mozilla Maintenance Service 2013-06-26 13:24 - 2013-06-26 08:04 - 00000000 ____D C:\Program Files (x86)\Mozilla Thunderbird 2013-06-26 13:24 - 2012-02-23 13:00 - 00001005 ____A C:\Windows\wininit.ini 2013-06-24 19:45 - 2011-02-12 12:28 - 00000000 ____D C:\Users\Thomas\AppData\Roaming\SoftGrid Client 2013-06-23 02:15 - 2011-05-26 23:51 - 00000072 ____A C:\Users\Public\LMDebug.log 2013-06-23 02:13 - 2013-06-23 02:13 - 00000000 ____D C:\Users\Thomas\AppData\Local\AAV 2013-06-23 02:13 - 2013-06-23 02:13 - 00000000 ____D C:\ProgramData\AAV 2013-06-23 02:13 - 2010-11-04 10:44 - 00654852 ____A C:\Windows\System32\perfh007.dat 2013-06-23 02:13 - 2010-11-04 10:44 - 00130434 ____A C:\Windows\System32\perfc007.dat 2013-06-23 02:13 - 2009-07-13 21:13 - 01500294 ____A C:\Windows\System32\PerfStringBackup.INI 2013-06-22 22:17 - 2013-06-22 22:17 - 00000000 ____D C:\Program Files (x86)\pandasecuritytb 2013-06-22 22:17 - 2012-10-27 23:52 - 00020312 ____A C:\Windows\PFRO.log 2013-06-19 19:59 - 2011-02-12 11:18 - 00000000 ____D C:\Users\Thomas\Desktop\Bilder 2013-06-14 19:38 - 2012-03-30 09:09 - 00692104 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe 2013-06-14 19:38 - 2011-05-16 13:22 - 00071048 ____A (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl 2013-06-13 20:30 - 2011-01-30 13:23 - 75825640 ____A (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-06-02 00:04 - 2013-06-01 22:41 - 00544603 ____A C:\Users\Thomas\Desktop\Babysitze.xlsx 2013-05-31 12:42 - 2013-05-31 12:16 - 00009239 ____A C:\Users\Thomas\Desktop\Kosten.xlsx 2013-05-31 12:18 - 2013-05-31 10:48 - 00012324 ____A C:\Users\Thomas\Desktop\Geschenke Hochzeit.xlsx 2013-05-31 12:07 - 2013-05-31 12:07 - 00000000 ____D C:\Users\Thomas\AppData\Local\Microsoft Help 2013-05-31 12:07 - 2013-05-31 12:07 - 00000000 ____D C:\ProgramData\Microsoft Help Files to move or delete: ==================== C:\Users\Thomas\AppData\Roaming\skype.dat C:\Users\Thomas\AppData\Roaming\skype.ini ==================== Known DLLs (Whitelisted) ================ ==================== Bamital & volsnap Check ================= C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\SysWOW64\wininit.exe => MD5 is legit C:\Windows\explorer.exe => MD5 is legit C:\Windows\SysWOW64\explorer.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\SysWOW64\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\SysWOW64\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\SysWOW64\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-05-28 10:23:07 Restore point made on: 2013-06-01 01:35:12 Restore point made on: 2013-06-04 09:22:24 Restore point made on: 2013-06-07 10:06:53 Restore point made on: 2013-06-12 11:13:06 Restore point made on: 2013-06-13 20:30:15 Restore point made on: 2013-06-18 18:37:08 Restore point made on: 2013-06-21 19:53:33 Restore point made on: 2013-06-25 08:49:22 Restore point made on: 2013-06-29 12:58:00 ==================== Memory info =========================== Percentage of memory in use: 18% Total physical RAM: 3764.5 MB Available physical RAM: 3059.69 MB Total Pagefile: 3762.64 MB Available Pagefile: 3044.39 MB Total Virtual: 8192 MB Available Virtual: 8191.85 MB ==================== Drives ================================ Drive c: (Packard Bell) (Fixed) (Total:285.3 GB) (Free:133.16 GB) NTFS (Disk=0 Partition=3) Drive e: (PQSERVICE) (Fixed) (Total:12.7 GB) (Free:1.23 GB) NTFS (Disk=0 Partition=1) Drive g: () (Removable) (Total:0.96 GB) (Free:0.96 GB) FAT (Disk=1 Partition=1) Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (SYSTEM RESERVED) (Fixed) (Total:0.1 GB) (Free:0.06 GB) NTFS (Disk=0 Partition=2) ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 298 GB) (Disk ID: 8C5A8C5A) Partition 1: (Not Active) - (Size=13 GB) - (Type=27) Partition 2: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 3: (Not Active) - (Size=285 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 981 MB) (Disk ID: 6F20736B) Partition 1: (Not Active) - (Size=544 GB) - (Type=72) Partition 2: (Not Active) - (Size=923 GB) - (Type=65) Partition 3: (Not Active) - (Size=923 GB) - (Type=79) Partition 4: (Not Active) - (Size=-336763289600) - (Type=0D) LastRegBack: 2013-06-08 22:45 ==================== End Of Log ============================ |
Themen zu GVU Trojaner Windows 7 |
.dll, acer, adobe, adobe flash player, antivirus, association, desktop, explorer, explorer.exe, farbar, farbar recovery scan tool, flash player, frst.txt, gvu trojaner windows 7, home, logfile, micro, microsoft, mozilla, packard bell, psuamain.exe, registry, security, services.exe, software, svchost.exe, system, thomas, trojaner, vista, windows, winlogon, winlogon.exe |