![]() |
| |||||||
Log-Analyse und Auswertung: antimalware doctor, mich hats erwischt. kriege es nicht runter.....Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #3 |
![]() ![]() | antimalware doctor, mich hats erwischt. kriege es nicht runter..... Hier die Logfile nach dem Fixen:
__________________All processes killed ========== OTL ========== No active process named Gsh.exe was found! No active process named Gsg.exe was found! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully! Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\cleansweep.exe not found. File C:\cleansweep.exe\cleansweep.exe not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Halo2 not found. File C:\Users\Maddin\AppData\Local\Temp\sshnas21.DLL not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\M5T8QL3YW3 not found. File C:\Users\Maddin\AppData\Local\Temp\Gsh.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{37e561d8-6fed-11df-b070-00269e679829}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37e561d8-6fed-11df-b070-00269e679829}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{37e561d8-6fed-11df-b070-00269e679829}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37e561d8-6fed-11df-b070-00269e679829}\ not found. File F:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{37e561dc-6fed-11df-b070-00269e679829}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37e561dc-6fed-11df-b070-00269e679829}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{37e561dc-6fed-11df-b070-00269e679829}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{37e561dc-6fed-11df-b070-00269e679829}\ not found. File F:\AutoRun.exe not found. ========== FILES ========== C:\Program Files (x86)\GoldEsel\Ahead Nero Burning Rom PlugIn Pack 2.0.2 by MadHacker2k4 folder moved successfully. C:\Program Files (x86)\GoldEsel folder moved successfully. File\Folder C:\Users\Maddin\AppData\Local\Temp\Gsh.exe not found. C:\Users\Maddin\AppData\Local\Temp\Gsg.exe moved successfully. C:\Users\Maddin\AppData\Roaming\2535F9D7A9BECF37566CEE2BC1DF8D02 folder moved successfully. File\Folder C:\Windows\tasks\{8C3FDD81-7AE0-4605-A46A-2488B179F2A3}.job not found. File\Folder C:\Windows\tasks\{35DC3473-A719-4d14-B7C1-FD326CA84A0C}.job not found. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 41044 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Maddin ->Temp folder emptied: 806314135 bytes ->Temporary Internet Files folder emptied: 232301021 bytes ->Java cache emptied: 29003 bytes ->FireFox cache emptied: 90925948 bytes ->Flash cache emptied: 2016631 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 67494288 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67698 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 1.144,00 mb OTL by OldTimer - Version 3.2.5.3 log created on 06092010_082617 Files\Folders moved on Reboot... C:\Users\Maddin\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot... |