|
Plagegeister aller Art und deren Bekämpfung: Gvu Trojaner verhindert mein Pc startWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
14.07.2013, 17:35 | #1 |
| Gvu Trojaner verhindert mein Pc start Hallo Seid 2 Tagen hab ich dieses Gvu Trojaner Virus auf meinem Laptop und weiss nicht was ich machen kann. Hab schon alles mögliche versucht aber geht trotzdem nicht. Hab ein Toshiba Laptop mit Windows 7 und ist 32 bit. Wen ich immer mein Laptop starte und auf meine Seite gehe kommt wieder dieses Virus. Ich kann die 3 Modus leider nicht benutzen , weil wen ich immer da rein gehe , dan wird mein Laptop AUTOMATISCH runtergefahren und somit bittee ich euch mir zu helfen ♥ hab quch windows xp cds |
14.07.2013, 17:48 | #2 |
/// the machine /// TB-Ausbilder | Gvu Trojaner verhindert mein Pc start hi,
__________________Scan mit Farbar's Recovery Scan Tool (Recovery Mode - Windows Vista, 7, 8) Hinweise für Windows 8-Nutzer: Anleitung 1 (FRST-Variante) und Anleitung 2 (zweiter Teil)
__________________ |
14.07.2013, 19:23 | #3 |
| Gvu Trojaner verhindert mein Pc startFRST Logfile: Code:
ATTFilter Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 14-07-2013 Ran by SYSTEM on 14-07-2013 20:16:11 Running from F:\ Windows 7 Ultimate (X86) OS Language: German Standard Internet Explorer Version 10 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> FRST is updated to run from normal or Safe mode to produce a full FRST.txt log and Addition.txt log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [VDownloader] - C:\Program Files\VDownloader\VDownloader.exe /silent [x] HKLM\...\RunOnce: [*Restore] - C:\Windows\system32\rstrui.exe /RUNONCE [262656 2010-11-20] (Microsoft Corporation) HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe HKU\Bilgin\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\Users\Bilgin\AppData\Local\Temp\eqepamocnwfopqwut.exe [ 2013-07-12] (NVIDIA Corporation) <===== ATTENTION HKU\Bilgin\...\Winlogon: [Shell] cmd.exe [ 2010-11-20] (Microsoft Corporation) <==== ATTENTION HKU\Bilgin\...\Command Processor: "C:\Users\Bilgin\AppData\Local\Temp\eqepamocnwfopqwut.exe" <===== ATTENTION! HKU\Default\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [ 2009-07-14] (Microsoft Corporation) HKU\Default User\...\RunOnce: [mctadmin] - C:\Windows\System32\mctadmin.exe [ 2009-07-14] (Microsoft Corporation) HKU\Gast\...\Run: [Google Update] - "C:\Users\Gast\AppData\Local\Google\Update\GoogleUpdate.exe" /c [ 2012-03-25] (Google Inc.) ========================== Services (Whitelisted) ================= S2 BrowserDefendert; C:\ProgramData\BrowserDefender\2.6.1339.144\{c16c1ccb-7046-4e5c-a2f3-533ad2fec8e8}\BrowserDefender.exe [2827728 2013-05-23] () S2 MsMpSvc; c:\Program Files\Microsoft Security Client\MsMpEng.exe [20456 2013-01-27] (Microsoft Corporation) S3 NisSrv; c:\Program Files\Microsoft Security Client\NisSrv.exe [295232 2013-01-27] (Microsoft Corporation) S3 npggsvc; C:\Windows\system32\GameMon.des [3948024 2012-08-28] (INCA Internet Co., Ltd.) S2 TemproMonitoringService; C:\Program Files\Toshiba TEMPRO\TemproSvc.exe [112080 2011-02-10] (Toshiba Europe GmbH) ==================== Drivers (Whitelisted) ==================== S3 apf003; C:\Windows\system32\apf003.sys [13232 2013-04-13] () S0 MpFilter; C:\Windows\System32\DRIVERS\MpFilter.sys [195296 2013-01-20] (Microsoft Corporation) S2 npf; C:\Windows\System32\drivers\npf.sys [50704 2010-01-27] (CACE Technologies, Inc.) S3 ss_bbus; C:\Windows\System32\DRIVERS\ss_bbus.sys [98432 2009-09-19] (MCCI) S3 ss_bmdfl; C:\Windows\System32\DRIVERS\ss_bmdfl.sys [14848 2009-09-19] (MCCI Corporation) S3 ss_bmdm; C:\Windows\System32\DRIVERS\ss_bmdm.sys [123648 2009-09-19] (MCCI Corporation) S3 tap0901; C:\Windows\System32\DRIVERS\tap0901.sys [34016 2013-01-10] (The OpenVPN Project) S3 EagleNT; \??\C:\Windows\system32\drivers\EagleNT.sys [x] S3 EagleXNt; \??\C:\Windows\system32\drivers\EagleXNt.sys [x] S3 Synth3dVsc; System32\drivers\synth3dvsc.sys [x] S3 TKCtrl; \??\C:\Windows\system32\TKCtrl2k.sys [x] S3 TKFsAvM; \??\C:\Windows\system32\TKFsAv.sys [x] S3 TkFsFtM; system32\TKFsFt.sys [x] S1 TKFWFV; system32\TKFWFV.sys [x] S3 TKFWVT; \??\C:\Windows\system32\TKFWVT.sys [x] S3 TkIdsVt; \??\C:\Windows\system32\TkIdsVt.sys [x] S3 TKPcFt; \??\C:\Windows\system32\TKPcFtCb.sys [x] S3 tsusbhub; system32\drivers\tsusbhub.sys [x] S3 VGPU; System32\drivers\rdvgkmd.sys [x] S3 vproiah; system32\DRIVERS\vproiah.sys [x] S3 WinRing0_1_2_0; \??\C:\Program Files\IObit\Game Booster 3\Driver\WinRing0.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-07-14 20:15 - 2013-07-14 20:15 - 00000000 ____D C:\FRST 2013-07-13 12:49 - 2013-07-13 12:49 - 00003416 ____N C:\bootsqm.dat 2013-07-12 22:59 - 2013-07-12 22:59 - 00003566 _____ C:\Windows\PFRO.log 2013-07-12 22:57 - 2013-07-12 22:57 - 01084736 _____ C:\ProgramData\2433f433 2013-07-12 22:57 - 2013-07-12 22:57 - 01084724 _____ C:\Users\Bilgin\AppData\Local\2433f433 2013-07-12 22:57 - 2013-07-12 22:57 - 01084659 _____ C:\Users\Bilgin\AppData\Roaming\2433f433 2013-07-12 22:05 - 2013-07-12 22:05 - 21052340 _____ C:\Users\Bilgin\Desktop\8 Minute Arms.mp4 2013-07-12 21:52 - 2013-07-12 21:52 - 25732607 _____ C:\Users\Bilgin\Desktop\Saj Zaman Make 6 six pack abs within shortest time ever possible.....mp4 2013-07-12 21:39 - 2013-07-12 21:39 - 00000000 ____D C:\Users\Bilgin\AppData\Roaming\BabSolution 2013-07-12 21:39 - 2013-07-12 21:39 - 00000000 ____D C:\ProgramData\BrowserDefender 2013-07-12 21:39 - 2013-07-12 21:39 - 00000000 ____D C:\Program Files\Delta 2013-07-12 21:38 - 2013-07-12 21:38 - 00000000 ____D C:\Program Files\LyricsWoofer 2013-07-12 21:36 - 2013-07-12 22:05 - 00000000 ____D C:\Users\Bilgin\AppData\Roaming\VDownloader 2013-07-12 21:36 - 2013-07-12 21:37 - 00000000 ____D C:\Users\Bilgin\AppData\Local\VDownloader 2013-07-12 21:36 - 2013-07-12 21:36 - 00001839 _____ C:\Users\Public\Desktop\VDownloader.lnk 2013-07-12 21:36 - 2013-07-12 21:36 - 00000000 ____D C:\Program Files\WinPcap 2013-07-12 21:36 - 2010-01-26 09:11 - 00444283 _____ C:\Program Files\Common Files\WinPcapNmap.exe 2013-07-11 15:32 - 2013-06-12 00:43 - 14329856 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-07-11 15:32 - 2013-06-12 00:43 - 02877440 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-07-11 15:32 - 2013-06-12 00:43 - 01767936 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-07-11 15:32 - 2013-06-12 00:43 - 01141248 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-07-11 15:32 - 2013-06-12 00:43 - 00690688 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-07-11 15:32 - 2013-06-12 00:43 - 00493056 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-07-11 15:32 - 2013-06-12 00:43 - 00042496 _____ (Microsoft Corporation) C:\Windows\System32\ie4uinit.exe 2013-07-11 15:32 - 2013-06-12 00:43 - 00039424 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-07-11 15:32 - 2013-06-12 00:42 - 13760512 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-07-11 15:32 - 2013-06-12 00:42 - 02046976 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-07-11 15:32 - 2013-06-12 00:42 - 00391168 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-07-11 15:32 - 2013-06-12 00:42 - 00109056 _____ (Microsoft Corporation) C:\Windows\System32\iesysprep.dll 2013-07-11 15:32 - 2013-06-12 00:42 - 00061440 _____ (Microsoft Corporation) C:\Windows\System32\iesetup.dll 2013-07-11 15:32 - 2013-06-12 00:42 - 00033280 _____ (Microsoft Corporation) C:\Windows\System32\iernonce.dll 2013-07-11 15:32 - 2013-06-11 23:51 - 00071680 _____ (Microsoft Corporation) C:\Windows\System32\RegisterIEPKEYs.exe 2013-07-11 15:32 - 2013-06-07 03:37 - 02706432 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-07-11 11:58 - 2013-06-05 04:05 - 02347520 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-07-11 11:58 - 2013-06-04 05:53 - 00509440 _____ (Microsoft Corporation) C:\Windows\System32\qedit.dll 2013-07-11 11:58 - 2013-05-06 05:56 - 01620480 _____ (Microsoft Corporation) C:\Windows\System32\WMVDECOD.DLL 2013-07-11 11:58 - 2013-04-10 00:34 - 01247744 _____ (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-07-10 13:43 - 2013-07-11 20:26 - 00000187 _____ C:\Users\Bilgin\Desktop\Setting.ini 2013-07-10 13:43 - 2013-07-10 13:43 - 00664838 _____ C:\Users\Bilgin\Desktop\64-Bit+Injektor.exe 2013-07-10 13:42 - 2013-07-10 13:42 - 00111616 _____ C:\Users\Bilgin\Desktop\Switch-Bot.dll 2013-07-07 20:43 - 2013-07-07 20:43 - 00065664 _____ C:\Users\Bilgin\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-07 19:24 - 2013-07-14 18:36 - 00002184 _____ C:\Windows\setupact.log 2013-07-07 19:24 - 2013-07-11 15:39 - 00307272 _____ C:\Windows\System32\FNTCACHE.DAT 2013-07-07 19:24 - 2013-07-07 19:24 - 00000000 _____ C:\Windows\setuperr.log 2013-07-07 14:06 - 2013-07-07 14:07 - 00000000 ____D C:\Users\Bilgin\Desktop\siwtcher 2013-07-01 13:57 - 2013-07-11 12:25 - 00000000 ____D C:\Users\Bilgin\Desktop\Shiro2 Client 2013-06-30 21:06 - 2013-06-30 21:06 - 00001754 _____ C:\Users\Public\Desktop\Crashday.lnk 2013-06-30 21:02 - 2013-06-30 21:02 - 00000000 ____D C:\Users\Bilgin\Desktop\textures 2013-06-30 21:02 - 2013-06-30 21:02 - 00000000 ____D C:\Users\Bilgin\Desktop\sounds 2013-06-30 21:02 - 2013-06-30 21:02 - 00000000 ____D C:\Users\Bilgin\Desktop\loc 2013-06-30 21:02 - 2013-06-30 21:02 - 00000000 ____D C:\Program Files\ValuSoft 2013-06-30 21:00 - 2009-04-25 17:46 - 00000000 ____D C:\Users\Bilgin\Desktop\CRASHDAY_1.2 SK 2013-06-15 22:15 - 2013-06-15 22:27 - 00000000 ____D C:\Program Files\Dragonheart-Network ==================== One Month Modified Files and Folders ======= 2013-07-14 20:15 - 2013-07-14 20:15 - 00000000 ____D C:\FRST 2013-07-14 18:36 - 2013-07-07 19:24 - 00002184 _____ C:\Windows\setupact.log 2013-07-14 17:14 - 2009-07-14 05:34 - 00014016 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0 2013-07-14 17:14 - 2009-07-14 05:34 - 00014016 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0 2013-07-14 15:32 - 2013-04-14 09:21 - 01954466 _____ C:\Windows\WindowsUpdate.log 2013-07-13 19:23 - 2009-07-14 05:34 - 00021504 _____ C:\Windows\System32\umstartup.etl 2013-07-13 18:38 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\LogFiles 2013-07-13 12:49 - 2013-07-13 12:49 - 00003416 ____N C:\bootsqm.dat 2013-07-12 22:59 - 2013-07-12 22:59 - 00003566 _____ C:\Windows\PFRO.log 2013-07-12 22:57 - 2013-07-12 22:57 - 01084736 _____ C:\ProgramData\2433f433 2013-07-12 22:57 - 2013-07-12 22:57 - 01084724 _____ C:\Users\Bilgin\AppData\Local\2433f433 2013-07-12 22:57 - 2013-07-12 22:57 - 01084659 _____ C:\Users\Bilgin\AppData\Roaming\2433f433 2013-07-12 22:05 - 2013-07-12 22:05 - 21052340 _____ C:\Users\Bilgin\Desktop\8 Minute Arms.mp4 2013-07-12 22:05 - 2013-07-12 21:36 - 00000000 ____D C:\Users\Bilgin\AppData\Roaming\VDownloader 2013-07-12 22:05 - 2012-01-10 13:12 - 00000000 ___RD C:\Users\Bilgin\Desktop 2013-07-12 21:52 - 2013-07-12 21:52 - 25732607 _____ C:\Users\Bilgin\Desktop\Saj Zaman Make 6 six pack abs within shortest time ever possible.....mp4 2013-07-12 21:51 - 2009-07-14 03:37 - 00000000 __RHD C:\Users\Public\Desktop 2013-07-12 21:39 - 2013-07-12 21:39 - 00000000 ____D C:\Users\Bilgin\AppData\Roaming\BabSolution 2013-07-12 21:39 - 2013-07-12 21:39 - 00000000 ____D C:\ProgramData\BrowserDefender 2013-07-12 21:39 - 2013-07-12 21:39 - 00000000 ____D C:\Program Files\Delta 2013-07-12 21:39 - 2012-03-17 16:15 - 00000000 ____D C:\Users\Bilgin\AppData\Local\CrashDumps 2013-07-12 21:38 - 2013-07-12 21:38 - 00000000 ____D C:\Program Files\LyricsWoofer 2013-07-12 21:37 - 2013-07-12 21:36 - 00000000 ____D C:\Users\Bilgin\AppData\Local\VDownloader 2013-07-12 21:36 - 2013-07-12 21:36 - 00001839 _____ C:\Users\Public\Desktop\VDownloader.lnk 2013-07-12 21:36 - 2013-07-12 21:36 - 00000000 ____D C:\Program Files\WinPcap 2013-07-12 21:36 - 2012-05-11 16:19 - 00000000 ____D C:\Users\Bilgin\AppData\Roaming\OpenCandy 2013-07-12 20:48 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\Microsoft.NET 2013-07-11 20:26 - 2013-07-10 13:43 - 00000187 _____ C:\Users\Bilgin\Desktop\Setting.ini 2013-07-11 15:39 - 2013-07-07 19:24 - 00307272 _____ C:\Windows\System32\FNTCACHE.DAT 2013-07-11 15:39 - 2010-02-09 20:45 - 00000000 ____D C:\Windows\Panther 2013-07-11 15:37 - 2012-10-17 19:35 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-07-11 15:37 - 2009-07-14 09:56 - 00000000 ____D C:\Program Files\Windows Journal 2013-07-11 15:37 - 2009-07-14 05:52 - 00000000 ____D C:\Program Files\Windows Defender 2013-07-11 15:34 - 2010-02-09 20:56 - 01634476 _____ C:\Windows\System32\PerfStringBackup.INI 2013-07-11 15:29 - 2010-02-09 21:01 - 75699896 _____ (Microsoft Corporation) C:\Windows\System32\MRT.exe 2013-07-11 12:25 - 2013-07-01 13:57 - 00000000 ____D C:\Users\Bilgin\Desktop\Shiro2 Client 2013-07-10 13:43 - 2013-07-10 13:43 - 00664838 _____ C:\Users\Bilgin\Desktop\64-Bit+Injektor.exe 2013-07-10 13:42 - 2013-07-10 13:42 - 00111616 _____ C:\Users\Bilgin\Desktop\Switch-Bot.dll 2013-07-10 13:33 - 2012-11-16 18:00 - 00000000 ____D C:\Users\Bilgin\Desktop\32Bit Injector 2013-07-07 20:43 - 2013-07-07 20:43 - 00065664 _____ C:\Users\Bilgin\AppData\Local\GDIPFONTCACHEV1.DAT 2013-07-07 19:24 - 2013-07-07 19:24 - 00000000 _____ C:\Windows\setuperr.log 2013-07-07 14:07 - 2013-07-07 14:06 - 00000000 ____D C:\Users\Bilgin\Desktop\siwtcher 2013-07-04 17:57 - 2012-08-17 18:41 - 00000000 ____D C:\Windows\pss 2013-07-04 17:55 - 2013-04-15 14:33 - 00000000 ____D C:\Program Files\Optimizer Pro 2013-06-30 21:06 - 2013-06-30 21:06 - 00001754 _____ C:\Users\Public\Desktop\Crashday.lnk 2013-06-30 21:02 - 2013-06-30 21:02 - 00000000 ____D C:\Users\Bilgin\Desktop\textures 2013-06-30 21:02 - 2013-06-30 21:02 - 00000000 ____D C:\Users\Bilgin\Desktop\sounds 2013-06-30 21:02 - 2013-06-30 21:02 - 00000000 ____D C:\Users\Bilgin\Desktop\loc 2013-06-30 21:02 - 2013-06-30 21:02 - 00000000 ____D C:\Program Files\ValuSoft 2013-06-28 10:59 - 2013-04-13 15:30 - 00000000 ____D C:\Users\Bilgin\AppData\Local\Akamai 2013-06-27 12:04 - 2013-05-02 11:26 - 00000000 ____D C:\Program Files\Pando Networks 2013-06-26 19:58 - 2013-05-25 16:10 - 00000000 ____D C:\Program Files\Fifa Online 2 2013-06-26 19:58 - 2012-03-12 14:55 - 00001168 _____ C:\Windows\FOE2.ini 2013-06-26 19:06 - 2012-03-02 20:24 - 00000000 ____D C:\Log 2013-06-25 20:52 - 2013-04-15 14:27 - 00000000 ____D C:\Users\Bilgin\Documents\gegl-0.0 2013-06-18 11:50 - 2009-07-14 03:37 - 00000000 ____D C:\Windows\System32\NDF 2013-06-17 14:37 - 2012-04-29 08:56 - 00692104 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerApp.exe 2013-06-17 14:37 - 2012-01-12 18:24 - 00071048 _____ (Adobe Systems Incorporated) C:\Windows\System32\FlashPlayerCPLApp.cpl 2013-06-15 22:27 - 2013-06-15 22:15 - 00000000 ____D C:\Program Files\Dragonheart-Network ==================== Known DLLs (Whitelisted) ============ ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= Restore point made on: 2013-06-30 21:02:01 Restore point made on: 2013-06-30 21:02:50 Restore point made on: 2013-07-01 15:56:02 Restore point made on: 2013-07-05 14:17:41 Restore point made on: 2013-07-09 11:44:39 Restore point made on: 2013-07-11 15:25:03 ==================== Memory info =========================== Percentage of memory in use: 12% Total physical RAM: 3963.99 MB Available physical RAM: 3466.2 MB Total Pagefile: 3962.27 MB Available Pagefile: 3474.86 MB Total Virtual: 2047.88 MB Available Virtual: 1926.67 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:148.95 GB) (Free:88.85 GB) NTFS Drive f: (KINGSTON) (Removable) (Total:7.2 GB) (Free:7.2 GB) FAT32 Drive x: (Boot) (Fixed) (Total:0.03 GB) (Free:0.03 GB) NTFS Drive y: (System-reserviert) (Fixed) (Total:0.1 GB) (Free:0.07 GB) NTFS ==>[System with boot components (obtained from reading drive)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or 8) (Size: 149 GB) (Disk ID: 11AB0935) Partition 1: (Active) - (Size=100 MB) - (Type=07 NTFS) Partition 2: (Not Active) - (Size=149 GB) - (Type=07 NTFS) ======================================================== Disk: 1 (Size: 7 GB) (Disk ID: 72005B26) Partition 1: (Active) - (Size=7 GB) - (Type=0B) LastRegBack: 2013-07-04 20:39 ==================== End Of Log ============================ und dan kamm wieder sowas in der art glaubig soll ich es zu machen oda offen lassen? |
14.07.2013, 21:34 | #4 |
/// the machine /// TB-Ausbilder | Gvu Trojaner verhindert mein Pc start Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\Bilgin\...\Run: [qcgce2mrvjq91kk1e7pnbb19m52fx] - C:\Users\Bilgin\AppData\Local\Temp\eqepamocnwfopqwut.exe [ 2013-07-12] (NVIDIA Corporation) <===== ATTENTION HKU\Bilgin\...\Winlogon: [Shell] cmd.exe [ 2010-11-20] (Microsoft Corporation) <==== ATTENTION HKU\Bilgin\...\Command Processor: "C:\Users\Bilgin\AppData\Local\Temp\eqepamocnwfopqwut.exe" <===== ATTENTION! 2013-07-12 22:57 - 2013-07-12 22:57 - 01084736 _____ C:\ProgramData\2433f433 2013-07-12 22:57 - 2013-07-12 22:57 - 01084724 _____ C:\Users\Bilgin\AppData\Local\2433f433 2013-07-12 22:57 - 2013-07-12 22:57 - 01084659 _____ C:\Users\Bilgin\AppData\Roaming\2433f433 C:\Users\Bilgin\AppData\Local\Temp\eqepamocnwfopqwut.exe
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier. neu booten, freuen
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
14.07.2013, 22:18 | #5 |
| Gvu Trojaner verhindert mein Pc startCode:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 14-07-2013 Ran by SYSTEM at 2013-07-14 23:17:24 Run:1 Running from F:\ Boot Mode: Recovery ============================================== HKU\Bilgin\Software\Microsoft\Windows\CurrentVersion\Run\\qcgce2mrvjq91kk1e7pnbb19m52fx => Value deleted successfully. HKU\Bilgin\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully. HKU\Bilgin\Software\Microsoft\Command Processor\\AutoRun => Value deleted successfully. C:\ProgramData\2433f433 => Moved successfully. C:\Users\Bilgin\AppData\Local\2433f433 => Moved successfully. C:\Users\Bilgin\AppData\Roaming\2433f433 => Moved successfully. C:\Users\Bilgin\AppData\Local\Temp\eqepamocnwfopqwut.exe => Moved successfully. ==== End of Fixlog ==== |
15.07.2013, 08:01 | #6 |
/// the machine /// TB-Ausbilder | Gvu Trojaner verhindert mein Pc start Na?
__________________ --> Gvu Trojaner verhindert mein Pc start |
15.07.2013, 10:57 | #7 |
| Gvu Trojaner verhindert mein Pc start Geht immer noch nicht Was soll ich den neu booten ? |
15.07.2013, 11:35 | #8 |
/// the machine /// TB-Ausbilder | Gvu Trojaner verhindert mein Pc start Du sollst versuchen den Rechner ganz normal neu zu starten und normal in Windows zu booten. Das sollte gehen jetzt.
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
17.07.2013, 18:53 | #9 |
| Gvu Trojaner verhindert mein Pc start Danke für deine Hilfe*-* alles geht wieder und jetzt hab ich ein neues problem das mein Bildschrim beim Zocken einfriert *-* Also alles friert für paar sekunden ein und dan wird es wieder Flüssig ( beim einfrieren des bildschirms kann ich mein Maus bewegen) kann nix mehr benutzen beim einfrieren Hilfste mir ?? |
18.07.2013, 07:34 | #10 |
/// the machine /// TB-Ausbilder | Gvu Trojaner verhindert mein Pc start Wir sind ja auch noch nit fertig Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Gvu Trojaner verhindert mein Pc start |
automatisch, gvu trojaner, gvu trojaner virus, kommt wieder, laptop, modus, mögliche, seite, start, starte, tagen, toshiba, troja, trojaner, trojaner virus, verhindert, versuch, versucht, virus, windows, windows 7, windows xp |