![]() |
|
Plagegeister aller Art und deren Bekämpfung: Virus wordslife.com/index.phpWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #11 |
![]() ![]() | ![]() Virus wordslife.com/index.php Hi Arne! Ich kann immer wieder nur sagen: Tausend Dank für die Hilfe!!!! Hier das neue logfile vom OTL. Was muss ich als nächstes tun? VG Marc All processes killed ========== OTL ========== File move failed. G:\Autorun.inf scheduled to be moved on reboot. C:\Windows\SysNative\drivers\kgpcpy.cfg moved successfully. ADS C:\ProgramData\TEMP:F35A93AD deleted successfully. ========== COMMANDS ========== File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Marc ->Temp folder emptied: 729819 bytes ->Temporary Internet Files folder emptied: 12919209 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 434 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 3422 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 49621 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 13,00 mb OTL by OldTimer - Version 3.2.14.1 log created on 09282010_115600 Files\Folders moved on Reboot... File move failed. G:\Autorun.inf scheduled to be moved on reboot. File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot. C:\Users\Marc\AppData\Local\Temp\Low\Google Toolbar\GoogleToolbarWelcome.log moved successfully. File\Folder C:\Users\***\AppData\Local\Temp\~DF53A3.tmp not found! File\Folder C:\Users\***\AppData\Local\Temp\~DF542B.tmp not found! File\Folder C:\Users\***\AppData\Local\Temp\~DF962E.tmp not found! File\Folder C:\Users\***\AppData\Local\Temp\~DF9639.tmp not found! File\Folder C:\Users\***\AppData\Local\Temp\~DFEBF7.tmp not found! File\Folder C:\Users\***\AppData\Local\Temp\~DFEF7F.tmp not found! File\Folder C:\Users\***\AppData\Local\Temp\~DFF57C.tmp not found! File\Folder C:\Users\***\AppData\Local\Temp\~DFF90D.tmp not found! C:\Users\Marc\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZXN1AEGU\ofm_style[1].css moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZXN1AEGU\vereinsseite_frameset[1].htm moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\ZXN1AEGU\vereinsseite_menu[1].htm moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PE366T6D\iepngfix[1].htc moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PE366T6D\iepngfix[2].htc moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\PE366T6D\indexCA3OZ8O3.php moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQWWVGOA\91140-virus-wordslife-com-index-php-2[1].html moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQWWVGOA\adsCAPOBDRZ.htm moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQWWVGOA\teaminfo[2].htm moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQWWVGOA\vereinsseite_frameset[1].htm moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQWWVGOA\vereinsseite_kader[1].htm moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQWWVGOA\vereinsseite_menu[1].htm moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\IQWWVGOA\wz_tooltip[1].js moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\849MMWK4\adsCANP4E4F.htm moved successfully. C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\849MMWK4\adsCAO1VFL0.htm moved successfully. Registry entries deleted on Reboot... |
Themen zu Virus wordslife.com/index.php |
64-bit, alternate, antivir, automatisch, avgntflt.sys, c:\windows\system32\rundll32.exe, erkannt, fake, funktioniert, gen, google, home premium, install.exe, internetseite, location, löschen, malware, neu, neuinstallation, nichts, oldtimer, otl logfile, otl.exe, plug-in, programdata, programm, rechner, safer networking, saver, sched.exe, seite, shell32.dll, shortcut, skype.exe, spybot, spybot search and destroy, start menu, system, syswow64, virus, virus eingefangen, vista, vlc media player, web, win, win vista, wordslife, wordslife.com, zufällig |