|
Log-Analyse und Auswertung: Windows7 Home: Fedpol-TrojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
27.10.2013, 16:13 | #1 |
| Windows7 Home: Fedpol-Trojaner Liebes Trojaner-Board, Ich habe mir vor ein paar Tagen den Fedpol-Trojaner eingefangen. Wenn ich den PC (Windows 7 Home Premium) starte, kommt immer das bekannte Bild. Mittels F8 kann ich den Windows im abgesichterten Modus starten. Nach ein paar Sekunden fährt sich der PC runter und startet neu (mit dem Fedpol-Trojaner-Bild). Ich habe nach eurer Anleitung das frst.txt erstellt (s. unten). Wie muss ich weiter vorgehen, damit ich den Trojaner loswerde und welches Tool verhindert eine zukünftige "Infektion"? Besten Dank im Voraus für eure Hilfe. ---------------------------------------------------------------------------------------------------------------- FRST-Scan: Scan result of Farbar Recovery Scan Tool (FRST) (x86) Version: 26-10-2013 01 Ran by SYSTEM on MINWINPC on 27-10-2013 14:24:46 Running from L:\ Windows Vista (TM) Home Premium Service Pack 1 (X86) OS Language: German Standard Internet Explorer Version 9 Boot Mode: Recovery The current controlset is ControlSet001 ATTENTION!:=====> If the system is bootable FRST could be run from normal or Safe mode to create a complete log. ==================== Registry (Whitelisted) ================== HKLM\...\Run: [] - [x] Winlogon\Notify\GoToAssist: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.) Winlogon\Notify\SDWinLogon: C:\Program Files\Citrix\GoToAssist\514\G2AWinLogon.dll (Citrix Online, a division of Citrix Systems, Inc.) HKU\foa\...\Winlogon: [Shell] explorer.exe,C:\Users\foa\AppData\Roaming\Other.res [ 2013-07-09] () <==== ATTENTION Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation) BootExecute: autocheck autochk * sdnclean.exe ========================== Services (Whitelisted) ================= S2 AERTFilters; C:\Windows\system32\AERTSrv.exe [73728 2008-07-18] (Andrea Electronics Corporation) S2 avast! Antivirus; C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [45248 2013-03-07] (AVAST Software) S2 Creative Labs Licensing Service; C:\Program Files\Common Files\Creative Labs Shared\Service\CreativeLicensing.exe [72704 2009-03-30] (Creative Labs) S2 Creative Service for CDROM Access; C:\Windows\system32\CTsvcCDA.exe [44032 2008-07-28] (Creative Technology Ltd) S2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2008-09-23] (Stardock Corporation) S3 FirebirdServerMAGIXInstance; C:\Program Files\Common\Database\bin\fbserver.exe [1527900 2005-11-17] (MAGIX®) S2 Garmin Core Update Service; C:\Program Files\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe [185688 2013-03-27] (Garmin Ltd or its subsidiaries) S2 NMSAccess; C:\Program Files\CDBurnerXP\NMSAccessU.exe [71096 2010-03-04] () S2 PDF Architect Helper Service; C:\Program Files\PDF Architect\HelperService.exe [1324104 2013-01-09] (pdfforge GbR) S2 PDF Architect Service; C:\Program Files\PDF Architect\ConversionService.exe [795208 2013-01-09] (pdfforge GbR) S2 recvrsvc.exe; C:\Program Files\NETGEAR\NETGEAR Digital Entertainer für Windows\recvrsvc.exe [173040 2007-05-25] (NETGEAR, Inc.) S2 SDScannerService; C:\Program Files\_Tools\Spybot\Spybot - Search & Destroy 2\SDFSSvc.exe [1103392 2012-11-13] (Safer-Networking Ltd.) S2 SDUpdateService; C:\Program Files\_Tools\Spybot\Spybot - Search & Destroy 2\SDUpdSvc.exe [1369624 2012-11-13] (Safer-Networking Ltd.) S2 SDWSCService; C:\Program Files\_Tools\Spybot\Spybot - Search & Destroy 2\SDWSCSvc.exe [168384 2012-11-13] (Safer-Networking Ltd.) S2 sprtsvc_DellSupportCenter; C:\Program Files\Dell Support Center\bin\sprtsvc.exe [201968 2008-10-04] (SupportSoft, Inc.) ==================== Drivers (Whitelisted) ==================== S2 aswFsBlk; C:\Windows\System32\Drivers\aswFsBlk.sys [29816 2013-03-07] (AVAST Software) S2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [66336 2013-03-07] (AVAST Software) S1 aswRdr; C:\Windows\System32\Drivers\aswRdr.sys [49760 2013-03-07] (AVAST Software) S0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [49248 2013-03-07] () S1 aswSnx; C:\Windows\System32\Drivers\aswSnx.sys [765736 2013-03-07] (AVAST Software) S1 aswSP; C:\Windows\System32\Drivers\aswSP.sys [368176 2013-03-07] (AVAST Software) S1 aswTdi; C:\Windows\System32\Drivers\aswTdi.sys [62376 2013-03-07] (AVAST Software) S3 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [164736 2013-03-07] () S3 imvad_multi; C:\Windows\System32\drivers\imvad.sys [22856 2007-05-25] (Windows (R) 2000 DDK provider) S2 npf; C:\Windows\System32\drivers\npf.sys [35088 2011-02-11] (CACE Technologies, Inc.) S2 RtNdPt60; C:\Windows\System32\DRIVERS\RtNdPt60.sys [27648 2008-07-21] (Windows (R) Codename Longhorn DDK provider) S3 StarOpen; C:\Windows\System32\Drivers\StarOpen.sys [7168 2009-11-12] () S1 UimBus; C:\Windows\System32\DRIVERS\UimBus.sys [45240 2011-11-17] (Windows (R) 2000 DDK provider) S1 Uim_IM; C:\Windows\System32\Drivers\Uim_IM.sys [441608 2011-11-17] (Paragon) S1 Uim_Vim; C:\Windows\System32\Drivers\Uim_Vim.sys [277576 2011-11-17] (Paragon) S3 USB28xxBGA; C:\Windows\System32\DRIVERS\emBDA.sys [530944 2008-03-06] (eMPIA Technology, Inc.) S3 USB28xxOEM; C:\Windows\System32\DRIVERS\emOEM.sys [45696 2007-04-25] (eMPIA Technology, Inc.) S3 esgiguard; \??\C:\Program Files\Enigma Software Group\SpyHunter\esgiguard.sys [x] S3 IpInIp; system32\DRIVERS\ipinip.sys [x] S3 NwlnkFlt; system32\DRIVERS\nwlnkflt.sys [x] S3 NwlnkFwd; system32\DRIVERS\nwlnkfwd.sys [x] ==================== NetSvcs (Whitelisted) =================== ==================== One Month Created Files and Folders ======== 2013-10-27 14:24 - 2013-10-27 14:24 - 00000000 ____D C:\FRST 2013-10-19 12:58 - 2013-10-19 15:33 - 00000000 ____D C:\Windows\DB847E94446B49E0AC5DC5627EC8B0C0.TMP 2013-10-19 12:58 - 2013-10-19 12:58 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-10-19 12:58 - 2013-10-19 12:58 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-10-19 12:45 - 2013-10-19 12:47 - 00000000 ____D C:\AdwCleaner 2013-10-12 06:32 - 2013-09-22 11:29 - 12336128 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.dll 2013-10-12 06:32 - 2013-09-22 11:22 - 09739264 _____ (Microsoft Corporation) C:\Windows\System32\ieframe.dll 2013-10-12 06:32 - 2013-09-22 11:22 - 01800704 _____ (Microsoft Corporation) C:\Windows\System32\jscript9.dll 2013-10-12 06:32 - 2013-09-22 11:14 - 01427968 _____ (Microsoft Corporation) C:\Windows\System32\inetcpl.cpl 2013-10-12 06:32 - 2013-09-22 11:13 - 01129472 _____ (Microsoft Corporation) C:\Windows\System32\wininet.dll 2013-10-12 06:32 - 2013-09-22 11:13 - 01104896 _____ (Microsoft Corporation) C:\Windows\System32\urlmon.dll 2013-10-12 06:32 - 2013-09-22 11:12 - 00231936 _____ (Microsoft Corporation) C:\Windows\System32\url.dll 2013-10-12 06:32 - 2013-09-22 11:09 - 00065024 _____ (Microsoft Corporation) C:\Windows\System32\jsproxy.dll 2013-10-12 06:32 - 2013-09-22 11:08 - 00142848 _____ (Microsoft Corporation) C:\Windows\System32\ieUnatt.exe 2013-10-12 06:32 - 2013-09-22 11:07 - 00717824 _____ (Microsoft Corporation) C:\Windows\System32\jscript.dll 2013-10-12 06:32 - 2013-09-22 11:06 - 00420864 _____ (Microsoft Corporation) C:\Windows\System32\vbscript.dll 2013-10-12 06:32 - 2013-09-22 11:05 - 00607744 _____ (Microsoft Corporation) C:\Windows\System32\msfeeds.dll 2013-10-12 06:32 - 2013-09-22 11:03 - 02382848 _____ (Microsoft Corporation) C:\Windows\System32\mshtml.tlb 2013-10-12 06:32 - 2013-09-22 11:03 - 01796096 _____ (Microsoft Corporation) C:\Windows\System32\iertutil.dll 2013-10-12 06:32 - 2013-09-22 11:03 - 00073216 _____ (Microsoft Corporation) C:\Windows\System32\mshtmled.dll 2013-10-12 06:32 - 2013-09-22 10:59 - 00176640 _____ (Microsoft Corporation) C:\Windows\System32\ieui.dll 2013-10-11 23:02 - 2013-08-27 03:47 - 01029120 _____ (Microsoft Corporation) C:\Windows\System32\d3d10.dll 2013-10-11 23:02 - 2013-08-27 03:47 - 00219648 _____ (Microsoft Corporation) C:\Windows\System32\d3d10_1core.dll 2013-10-11 23:02 - 2013-08-27 03:47 - 00189952 _____ (Microsoft Corporation) C:\Windows\System32\d3d10core.dll 2013-10-11 23:02 - 2013-08-27 03:47 - 00160768 _____ (Microsoft Corporation) C:\Windows\System32\d3d10_1.dll 2013-10-11 23:02 - 2013-08-27 02:52 - 01172480 _____ (Microsoft Corporation) C:\Windows\System32\d3d10warp.dll 2013-10-11 23:02 - 2013-08-27 02:50 - 00486400 _____ (Microsoft Corporation) C:\Windows\System32\d3d10level9.dll 2013-10-11 23:02 - 2013-08-27 02:32 - 00683008 _____ (Microsoft Corporation) C:\Windows\System32\d2d1.dll 2013-10-11 23:02 - 2013-08-27 02:28 - 01069056 _____ (Microsoft Corporation) C:\Windows\System32\DWrite.dll 2013-10-11 23:02 - 2013-08-27 02:28 - 00798208 _____ (Microsoft Corporation) C:\Windows\System32\FntCache.dll 2013-10-11 23:02 - 2013-08-01 04:16 - 00638400 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\dxgkrnl.sys 2013-10-11 23:02 - 2013-08-01 03:49 - 00037376 _____ (Microsoft Corporation) C:\Windows\System32\cdd.dll 2013-10-11 23:01 - 2013-08-29 08:36 - 02050048 _____ (Microsoft Corporation) C:\Windows\System32\win32k.sys 2013-10-11 23:01 - 2013-07-20 11:44 - 00102608 _____ (Microsoft Corporation) C:\Windows\System32\PresentationCFFRasterizerNative_v0300.dll 2013-10-11 22:59 - 2013-07-12 10:04 - 00073344 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\USBAUDIO.sys 2013-10-11 22:59 - 2013-06-29 03:07 - 00226304 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbport.sys 2013-10-11 22:59 - 2013-06-29 03:07 - 00197632 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbhub.sys 2013-10-11 22:59 - 2013-06-29 03:07 - 00073216 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbccgp.sys 2013-10-11 22:59 - 2013-06-29 03:06 - 00006016 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbd.sys 2013-10-11 22:59 - 2011-05-05 14:54 - 00039936 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbehci.sys 2013-10-11 22:59 - 2011-05-05 14:54 - 00023552 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbuhci.sys 2013-10-11 22:58 - 2013-06-27 00:01 - 00527064 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\Wdf01000.sys 2013-10-11 22:58 - 2013-06-27 00:01 - 00047720 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\WdfLdr.sys 2013-10-11 22:58 - 2013-06-27 00:01 - 00009728 _____ (Microsoft Corporation) C:\Windows\System32\Wdfres.dll 2013-10-11 22:58 - 2013-06-04 05:16 - 00034304 _____ (Adobe Systems) C:\Windows\System32\atmlib.dll 2013-10-11 22:58 - 2013-06-04 02:49 - 00293376 _____ (Adobe Systems Incorporated) C:\Windows\System32\atmfd.dll 2013-10-11 22:57 - 2013-07-04 05:21 - 00532480 _____ (Microsoft Corporation) C:\Windows\System32\comctl32.dll 2013-10-11 22:57 - 2013-07-03 03:33 - 00035328 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\usbscan.sys 2013-10-11 22:57 - 2013-07-03 03:10 - 00025472 _____ (Microsoft Corporation) C:\Windows\System32\Drivers\hidparse.sys 2013-10-05 12:28 - 2013-10-05 12:28 - 00000000 ____D C:\Program Files\Mozilla Firefox ==================== One Month Modified Files and Folders ======= 2013-10-27 14:24 - 2013-10-27 14:24 - 00000000 ____D C:\FRST 2013-10-27 13:57 - 2013-05-15 23:26 - 01652668 _____ C:\Windows\WindowsUpdate.log 2013-10-27 13:57 - 2010-01-17 00:11 - 00000012 _____ C:\Windows\bthservsdp.dat 2013-10-27 13:57 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0 2013-10-27 13:57 - 2006-11-02 13:47 - 00003744 ____H C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0 2013-10-27 13:49 - 2008-01-21 08:16 - 01445546 _____ C:\Windows\System32\PerfStringBackup.INI 2013-10-20 22:26 - 2006-11-02 13:47 - 00399304 _____ C:\Windows\System32\FNTCACHE.DAT 2013-10-19 15:44 - 2009-04-04 01:48 - 00129024 _____ C:\Users\foa\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini 2013-10-19 15:38 - 2010-08-16 23:00 - 00000000 ____D C:\Program Files\_SYS 2013-10-19 15:33 - 2013-10-19 12:58 - 00000000 ____D C:\Windows\DB847E94446B49E0AC5DC5627EC8B0C0.TMP 2013-10-19 15:31 - 2010-03-07 15:45 - 00000000 ____D C:\Users\foa\AppData\Roaming\Skype 2013-10-19 15:31 - 2010-03-07 15:45 - 00000000 ____D C:\ProgramData\Skype 2013-10-19 15:26 - 2013-04-27 15:52 - 00000000 ____D C:\Program Files\Common Files\DVDVideoSoft 2013-10-19 15:26 - 2009-04-04 01:30 - 00000000 ____D C:\Program Files\_Tools 2013-10-19 15:21 - 2010-08-12 20:55 - 00000000 ____D C:\Users\foa\AppData\Roaming\uTorrent 2013-10-19 14:26 - 2013-04-07 23:08 - 00000000 ____D C:\ProgramData\Freemake 2013-10-19 14:25 - 2013-04-07 23:08 - 00000000 ____D C:\Program Files\Freemake 2013-10-19 12:58 - 2013-10-19 12:58 - 00000000 ____D C:\Program Files\Enigma Software Group 2013-10-19 12:58 - 2013-10-19 12:58 - 00000000 ____D C:\Program Files\Common Files\Wise Installation Wizard 2013-10-19 12:48 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\tracing 2013-10-19 12:47 - 2013-10-19 12:45 - 00000000 ____D C:\AdwCleaner 2013-10-19 12:47 - 2013-03-05 20:38 - 00000000 ____D C:\Users\foa\AppData\Roaming\Uniblue 2013-10-19 12:47 - 2013-03-05 20:38 - 00000000 ____D C:\Program Files\Uniblue 2013-10-19 12:28 - 2013-05-15 22:20 - 00001019 _____ C:\Users\Public\Desktop\ Malwarebytes Anti-Malware .lnk 2013-10-17 21:49 - 2008-01-21 08:15 - 00000000 ____D C:\Windows\WindowsMobile 2013-10-17 21:40 - 2013-03-29 14:42 - 00000000 ____D C:\ProgramData\Spybot - Search & Destroy 2013-10-14 23:36 - 2013-04-20 15:02 - 00000000 ____D C:\Users\foa\AppData\Roaming\vlc 2013-10-13 15:32 - 2011-01-17 21:37 - 00000630 _____ C:\Windows\BRWMARK.INI 2013-10-13 08:45 - 2006-11-02 12:18 - 00000000 ____D C:\Windows\Microsoft.NET 2013-10-12 07:00 - 2009-03-30 20:21 - 00000000 ____D C:\Program Files\Microsoft Silverlight 2013-10-12 06:36 - 2013-08-14 02:07 - 00000000 ____D C:\Windows\System32\MRT 2013-10-12 06:34 - 2006-11-02 11:24 - 78106760 _____ (Microsoft Corporation) C:\Windows\System32\mrt.exe 2013-10-06 21:58 - 2012-05-03 01:51 - 00000000 ____D C:\Program Files\Mozilla Maintenance Service 2013-10-05 12:28 - 2013-10-05 12:28 - 00000000 ____D C:\Program Files\Mozilla Firefox Files to move or delete: ==================== C:\Users\foa\AppData\Roaming\desktop.ini C:\ProgramData\ot2o1.pad Some content of TEMP: ==================== C:\Users\foa\AppData\Local\Temp\buesxdkhjtrigseeojleorxgqxleicw.exe C:\Users\foa\AppData\Local\Temp\Quarantine.exe C:\Users\foa\AppData\Local\Temp\SHSetup.exe ==================== Known DLLs (Whitelisted) ============ ==================== Bamital & volsnap Check ================= C:\Windows\explorer.exe => MD5 is legit C:\Windows\System32\winlogon.exe => MD5 is legit C:\Windows\System32\wininit.exe => MD5 is legit C:\Windows\System32\svchost.exe => MD5 is legit C:\Windows\System32\services.exe => MD5 is legit C:\Windows\System32\User32.dll => MD5 is legit C:\Windows\System32\userinit.exe => MD5 is legit C:\Windows\System32\Drivers\volsnap.sys => MD5 is legit ==================== EXE ASSOCIATION ===================== HKLM\...\.exe: exefile => OK HKLM\...\exefile\DefaultIcon: %1 => OK HKLM\...\exefile\open\command: "%1" %* => OK ==================== Restore Points ========================= ==================== Memory info =========================== Percentage of memory in use: 9% Total physical RAM: 4094.26 MB Available physical RAM: 3722.48 MB Total Pagefile: 3959.85 MB Available Pagefile: 3807.71 MB Total Virtual: 2047.88 MB Available Virtual: 1965.82 MB ==================== Drives ================================ Drive c: (OS) (Fixed) (Total:108.24 GB) (Free:28.04 GB) NTFS ==>[Drive with boot components (obtained from BCD)] Drive d: (DATA) (Fixed) (Total:98.15 GB) (Free:25.41 GB) NTFS Drive e: (MEDIA) (Fixed) (Total:374.69 GB) (Free:190.95 GB) NTFS Drive l: (FOA_2) (Removable) (Total:3.83 GB) (Free:3.83 GB) FAT32 Drive x: (RECOVERY) (Fixed) (Total:15 GB) (Free:8.68 GB) NTFS ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (MBR Code: Windows 7 or Vista) (Size: 596 GB) (Disk ID: 60000000) Partition 1: (Not Active) - (Size=86 MB) - (Type=DE) Partition 2: (Not Active) - (Size=15 GB) - (Type=07 NTFS) Partition 3: (Active) - (Size=108 GB) - (Type=07 NTFS) Partition 4: (Not Active) - (Size=473 GB) - (Type=OF Extended) ======================================================== Disk: 5 (Size: 4 GB) (Disk ID: 00000000) Partition 1: (Active) - (Size=4 GB) - (Type=0B) LastRegBack: 2013-10-27 13:48 ==================== End Of Log ============================ |
27.10.2013, 17:32 | #2 |
/// the machine /// TB-Ausbilder | Windows7 Home: Fedpol-Trojaner hi,
__________________Drücke bitte die + R Taste und schreibe notepad in das Ausführen Fenster. Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter HKU\foa\...\Winlogon: [Shell] explorer.exe,C:\Users\foa\AppData\Roaming\Other.res [ 2013-07-09] () <==== ATTENTION C:\Users\foa\AppData\Roaming\desktop.ini C:\ProgramData\ot2o1.pad C:\Users\foa\AppData\Local\Temp\buesxdkhjtrigseeojleorxgqxleicw.exe C:\Users\foa\AppData\Local\Temp\Quarantine.exe C:\Users\foa\AppData\Local\Temp\SHSetup.exe C:\Users\foa\AppData\Roaming\Other.res
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier. Rechner normal starten.
__________________ |
28.10.2013, 23:43 | #3 |
| Windows7 Home: Fedpol-Trojaner Hallo schrauber,
__________________danke für deine schnelle Antwort. Alles hat funktioniert, PC hat normal gestartet und ich habe die fixlist.txt erstellt: Fix result of Farbar Recovery Tool (FRST written by Farbar) (x86) Version: 26-10-2013 01 Ran by SYSTEM at 2013-10-28 23:35:02 Run:1 Running from L:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** HKU\foa\...\Winlogon: [Shell] explorer.exe,C:\Users\foa\AppData\Roaming\Other.res [ 2013-07-09] () <==== ATTENTION C:\Users\foa\AppData\Roaming\desktop.ini C:\ProgramData\ot2o1.pad C:\Users\foa\AppData\Local\Temp\buesxdkhjtrigseeojleorxgqxleicw.exe C:\Users\foa\AppData\Local\Temp\Quarantine.exe C:\Users\foa\AppData\Local\Temp\SHSetup.exe C:\Users\foa\AppData\Roaming\Other.res ***************** HKU\foa\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\\Shell => Value deleted successfully. C:\Users\foa\AppData\Roaming\desktop.ini => Moved successfully. C:\ProgramData\ot2o1.pad => Moved successfully. C:\Users\foa\AppData\Local\Temp\buesxdkhjtrigseeojleorxgqxleicw.exe => Moved successfully. C:\Users\foa\AppData\Local\Temp\Quarantine.exe => Moved successfully. C:\Users\foa\AppData\Local\Temp\SHSetup.exe => Moved successfully. "C:\Users\foa\AppData\Roaming\Other.res" => File/Directory not found. ==== End of Fixlog ==== |
29.10.2013, 14:01 | #4 |
/// the machine /// TB-Ausbilder | Windows7 Home: Fedpol-Trojaner Dann ab jetzt alles im normalen Modus: Downloade Dir bitte Malwarebytes Anti-Malware
Downloade Dir bitte AdwCleaner auf deinen Desktop.
Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
Bitte lade dir die passende Version von Farbar's Recovery Scan Tool auf deinen Desktop: FRST 32-Bit | FRST 64-Bit (Wenn du nicht sicher bist: Lade beide Versionen oder unter Start > Computer (Rechtsklick) > Eigenschaften nachschauen)
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
Themen zu Windows7 Home: Fedpol-Trojaner |
.dll, adobe, antivirus, association, avast, cdburnerxp, desktop, explorer, farbar, farbar recovery scan tool, fedpol-trojaner, helper, home, installation, microsoft, mozilla, netgear, neu, pdf, registry, sekunden, services.exe, software, svchost.exe, system, temp, usb, vista, windows, windows7, winlogon.exe |