|
Log-Analyse und Auswertung: GVU trojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
09.08.2013, 21:34 | #1 |
| GVU trojaner Hallo zusammen, Please excuse me for writing in English but I can speak and read it. It is no problem if you respond in German to my problem. A GVU trojan has entered into the laptop I use for my self employment business and I need some help to deleting it. When I scanned the internet for solutions, I came across this forum and noticed another person described exactly my problem and was able to solve it with the help of this forum. See the following link for the exact problem description. http://www.trojaner-board.de/138004-...artet-neu.html I used Farbar to compile the logfile in this .TXT attachment. Can someone help me by changing the logfile as it was done for chrisdee? I use windows vista and would really appreciate any help. Gruß, hloy |
09.08.2013, 21:40 | #2 |
/// TB-Ausbilder | GVU trojaner Hi, if you need some translations ... please ask.
__________________!! Hinweis an Mitlesende !! Dieses Thema und die Anweisungen sind nur für diesen speziellen Fall gedacht. Sie könnten andere Computer schwer beschädigen. Öffnet bitte euer eigenes Thema. Ich werde dir bei deinem Problem helfen. Die Bereinigung funktioniert nur, wenn du dich an die folgenden Regeln hälst: Bitte lesen: Regeln für die Bereinigung
Lesestoff: Rootkit-Warnung Dein Computer wurde mit einem besonderen Schädling infiziert, der sich vor herkömmlichen Virenscannern und dem Betriebssystem selbst verstecken kann. Zusätzlich hat so ein Schädling meist auch Backdoor-Funktionalität, reißt also ganz bewußt Löcher durch alle Schutzmaßnahmen, damit er weiteren Schadcode nachladen oder die Daten, die er so sammelt, an die "bösen Jungs" weiterleiten kann. Was heißt das jetzt für dich?
Teile mir also mit, wie du dich entschieden hast. Fix mit FRST Tell how that went and if you can boot. You are still heavy infected.
__________________ |
09.08.2013, 22:55 | #3 |
| GVU trojaner Thanks for responding so fast.
__________________I was able to transfer and install the fixlist.txt as you described. The desktop screen appeared with all of the icons until the computer was completely finished booting. Then the Bildschirm was blocked again. I have attached the Fixlog.txt. |
10.08.2013, 12:31 | #4 |
/// TB-Ausbilder | GVU trojaner Okay you have a very nasty infection. Personally I would recommend to reinstall, but we can still try to unlock. Please check for me if you can boot into safemode with command prompt.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
11.08.2013, 00:42 | #5 |
| GVU trojaner Sorry I could not respond sooner. It would be an absolute tragedy to reinstall everything new. I REALLY appreciate your offer to still help me unlock. It would be best for me to reinstall everything if I could get my system running again and retrieve a backup. Just before my computer was blocked, I noticed that a software was installed without my consent. It is called "Internet Securtity Pro". I was unable to deinstall or stop it. There are several "Benutzerkonten" on my laptop. I can begin "Safe Mode with prompt" but shortly after booting, the monitor is blocked and I come no further. Is this what you mean? Task Manager has been disabled in all of them. If I use Farbar to boot, then I choose "Computer Reparieren" and come to "Systemwiederherstellungsoptionen" and get a prompt with "Eingabeaufforderung". This is no problem and I can see every drive and all directories. |
11.08.2013, 10:03 | #6 |
/// TB-Ausbilder | GVU trojaner Alright - please give me a new FRST logfile from recovery command prompt. It really would be better to reinstall. Fetching your data from the drive before you do so is easy if you use the Kaspersky Rescue Disk to mount your drives and then backup all your data.
__________________ --> GVU trojaner |
11.08.2013, 11:27 | #7 |
| GVU trojaner I can send you the new logfile in about an hour since I am currently in the process of trying to copy my files onto an external hard drive. |
11.08.2013, 11:33 | #8 |
/// TB-Ausbilder | GVU trojaner yeah better back it all up
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
11.08.2013, 12:20 | #9 |
| GVU trojaner Attached is a logfile from today. |
11.08.2013, 12:40 | #10 |
/// TB-Ausbilder | GVU trojaner Alright, please try this frst-fix in the recovery mode - after that ... ONLY boot into safemode with command prompt - do nothing else. Report how it went. Code:
ATTFilter HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,,C:\Program Files\Sony Ericsson\fYbXpvVP.exe C:\Program Files\Sony Ericsson\fYbXpvVP.exe HKU\admin_007\...\Run: [Internet Security] - C:\ProgramData\mcdefender.exe [x] HKU\admin_007\...\Run: [nfofwecd] - C:\Users\admin_007\AppData\Local\VirtualStore\tQkiDMHU.exe [ 2013-08-09] (Microsoft Corporation) C:\Users\admin_007\AppData\Local\VirtualStore\tQkiDMHU.exe HKU\admin_007\...\Run: [DirtyDecrypt] - C:\Users\admin_007\AppData\Roaming\Dirty\DirtyDecrypt.exe [ 2013-08-11] () C:\Users\admin_007\AppData\Roaming\Dirty\DirtyDecrypt.exe HKU\HL Firmenprofil\...\Run: [nfofwecd] - C:\Users\HL Firmenprofil\AppData\Local\VirtualStore\tQkiDMHU.exe [ 2013-08-09] (Microsoft Corporation) C:\Users\HL Firmenprofil\AppData\Local\VirtualStore\tQkiDMHU.exe HKU\HL Firmenprofil\...\Run: [DirtyDecrypt] - C:\Users\HL Firmenprofil\AppData\Roaming\Dirty\DirtyDecrypt.exe [ 2013-08-09] () C:\Users\HL Firmenprofil\AppData\Roaming\Dirty\DirtyDecrypt.exe HKU\HL Firmenprofil\...\Policies\system: [DisableTaskMgr] 1 HKU\Hollis Loy A&NM\...\Run: [nfofwecd] - C:\Users\Hollis Loy A&NM\AppData\Local\Microsoft Games\zCAiiZhi.exe [ 2013-08-09] (Microsoft Corporation) C:\Users\Hollis Loy A&NM\AppData\Local\Microsoft Games\zCAiiZhi.exe HKU\Hollis Loy A&NM\...\Run: [DirtyDecrypt] - C:\Users\Hollis Loy A&NM\AppData\Roaming\Dirty\DirtyDecrypt.exe [ 2013-08-11] () C:\Users\Hollis Loy A&NM\AppData\Roaming\Dirty\DirtyDecrypt.exe HKU\test\...\Run: [nfofwecd] - C:\Users\test\AppData\Local\Microsoft\RjXKWzPZ.exe [ 2013-08-09] (Microsoft Corporation) C:\Users\test\AppData\Local\Microsoft\RjXKWzPZ.exe HKU\test\...\Run: [DirtyDecrypt] - C:\Users\test\AppData\Roaming\Dirty\DirtyDecrypt.exe [ 2013-08-11] () C:\Users\test\AppData\Roaming\Dirty\DirtyDecrypt.exe Startup: C:\Users\admin_007\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fYrZrzEY.exe (Microsoft Corporation) Startup: C:\Users\Hollis Loy A&NM\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fYrZrzEY.exe (Microsoft Corporation) Startup: C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\fYrZrzEY.exe (Microsoft Corporation) 2013-08-09 17:41 - 2013-08-09 17:41 - 00000000 ____D C:\Users\HL Firmenprofil\AppData\Roaming\Dirty 2013-08-09 17:41 - 2013-08-09 17:41 - 00000000 ____D C:\Users\HL Firmenprofil\AppData\Local\ywtSPCwT 2013-08-09 17:41 - 2013-08-09 17:41 - 00000000 ____D C:\Users\HL Firmenprofil\AppData\Local\Dirty 2013-08-09 17:28 - 2013-08-09 17:28 - 00000000 ____D C:\Users\Hollis Loy A&NM\AppData\Roaming\Dirty 2013-08-09 17:28 - 2013-08-09 17:28 - 00000000 ____D C:\Users\Hollis Loy A&NM\AppData\Local\ywtSPCwT 2013-08-09 17:28 - 2013-08-09 17:28 - 00000000 ____D C:\Users\Hollis Loy A&NM\AppData\Local\Dirty 2013-08-09 17:23 - 2013-08-09 17:23 - 00000000 ____D C:\Users\admin_007\AppData\Local\ywtSPCwT 2013-08-09 17:23 - 2013-08-09 17:23 - 00000000 ____D C:\Program Files\Dirty 2013-08-09 17:12 - 2013-08-09 17:12 - 00000000 ____D C:\Users\admin_007\AppData\Roaming\Dirty 2013-08-09 17:12 - 2013-08-09 17:12 - 00000000 ____D C:\Users\admin_007\AppData\Local\qpwMhXYO 2013-08-09 17:12 - 2013-08-09 17:12 - 00000000 ____D C:\Users\admin_007\AppData\Local\Dirty
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
11.08.2013, 13:06 | #11 |
| GVU trojaner I installed the fixlist file and rebooted into the "Safe Mode with command prompt" and have a black window open. What should I do now? |
11.08.2013, 13:13 | #12 |
/// TB-Ausbilder | GVU trojaner Try to run Combofix like this: Computer mit Combofix entsperren Warnung: Diese Anleitung ist nur für diesen speziellen Fall gedacht und kann andere Computer evtl. schwer beschädigen. Zudem darf Combofix nur ausgeführt werden, wenn dies von einem erfahrenen Helfer angewiesen wird!
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
12.08.2013, 11:00 | #13 |
| GVU trojaner I have rebooted as you recommended with "Safe Mode with command prompt". It went well and I now have a black screen. What should I do next? Ignore my last entry. I did not see your latest response. I will get back with you soon after trying your latest suggestion. Thanks a million from the bottom of my heart. My system is running again. At the moment everything appears fine except for data files that were laying on my desktop like Excel and PDF files. When I open them, I get a damaged error message for the PDFs and DirtyDecrypt.exe message for the Excel files. Are you familiar with DirtyDecrypt.exe ? Thank you, thank you, thank you again for your help. |
12.08.2013, 11:03 | #14 |
/// TB-Ausbilder | GVU trojaner We are not finished yet! Please show your combofix logfile here.
__________________ Digitale Freibeuter gegen Malware! Keine Hilfe per PM! |
12.08.2013, 12:06 | #15 |
| GVU trojaner Refer to the attachment. |
Themen zu GVU trojaner |
another, business, english, farbar, forum, gvu trojaner, gvu trojaner entfernen in farbar logfile, hallo zusammen, help, inter, interne, internet, laptop, link, logfile, other, person, problem, scan, solutions, this, troja, trojan, trojane, trojaner, windows vista, zusammen |