Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.
woow du hast es echt drauf danke. kann de seiten wieder aufrufen. ansonsten keine symptome mehr bist nen echter lebensretter
Code:
ATTFilter
All processes killed
========== OTL ==========
Service ghpyg stopped successfully!
Service ghpyg deleted successfully!
File File not found not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\javasvr.exe deleted successfully.
D:\Users\Andreas L\AppData\Roaming\javasvr.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\225.exe deleted successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\CCleaner.exe deleted successfully.
D:\Users\Andreas L\AppData\Roaming\gVBwwvzlryQqpGvyqPsXVD\gVBwwvzlryQqpGvyqPsXVD\0.0.0.0\CCleaner.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\javasvr.exe deleted successfully.
File D:\Users\Andreas L\AppData\Roaming\javasvr.exe not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\KPeerNexonEU deleted successfully.
D:\Nexon\NEXON_EU_Downloader\nxEULauncher.exe moved successfully.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\WindowsWelcomeCenter deleted successfully.
File move failed. D:\Windows\System32\oobefldr.dll scheduled to be moved on reboot.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\WMPNSCFG deleted successfully.
File move failed. D:\Programme\Windows Media Player\wmpnscfg.exe scheduled to be moved on reboot.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\younex.exe deleted successfully.
D:\Users\Andreas L\AppData\Local\Temp\younex.exe moved successfully.
C:\autoexec.bat moved successfully.
D:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5ad3646-9f2c-11df-9be3-0024212ad79b}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c5ad3646-9f2c-11df-9be3-0024212ad79b}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c5ad3646-9f2c-11df-9be3-0024212ad79b}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c5ad3646-9f2c-11df-9be3-0024212ad79b}\ not found.
File N:\pushinst.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fd47b4f5-aef4-11df-8e8d-001f3f03fa59}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fd47b4f5-aef4-11df-8e8d-001f3f03fa59}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fd47b4f5-aef4-11df-8e8d-001f3f03fa59}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fd47b4f5-aef4-11df-8e8d-001f3f03fa59}\ not found.
File N:\setup\rsrc\Autorun.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{fd47b4f5-aef4-11df-8e8d-001f3f03fa59}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{fd47b4f5-aef4-11df-8e8d-001f3f03fa59}\ not found.
File N:\Directx\dxsetup.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\K\ not found.
File K:\pushinst.exe not found.
D:\Users\Andreas L\AppData\Roaming\gVBwwvzlryQqpGvyqPsXVD\gVBwwvzlryQqpGvyqPsXVD\0.0.0.0 folder moved successfully.
D:\Users\Andreas L\AppData\Roaming\gVBwwvzlryQqpGvyqPsXVD\gVBwwvzlryQqpGvyqPsXVD folder moved successfully.
D:\Users\Andreas L\AppData\Roaming\gVBwwvzlryQqpGvyqPsXVD folder moved successfully.
D:\Users\Andreas L\AppData\Roaming\lorjIXQzikFhmzwfsSStCP\lorjIXQzikFhmzwfsSStCP\0.0.0.0 folder moved successfully.
D:\Users\Andreas L\AppData\Roaming\lorjIXQzikFhmzwfsSStCP\lorjIXQzikFhmzwfsSStCP folder moved successfully.
D:\Users\Andreas L\AppData\Roaming\lorjIXQzikFhmzwfsSStCP folder moved successfully.
D:\Windows\iun6002.exe moved successfully.
File move failed. D:\Windows\System32\kctoqj.dll scheduled to be moved on reboot.
ADS D:\ProgramData\TEMP:05EE1EEF deleted successfully.
========== FILES ==========
File\Folder D:\Users\Andreas L\AppData\Roaming\gVBwwvzlryQqpGvyqPsXVD not found.
========== COMMANDS ==========
D:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Andreas L
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 3124352 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 76852029 bytes
->Flash cache emptied: 1066 bytes
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 4096 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 824 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 76,00 mb
OTL by OldTimer - Version 3.2.17.3 log created on 12142010_193632
Files\Folders moved on Reboot...
File move failed. D:\Windows\System32\oobefldr.dll scheduled to be moved on reboot.
File move failed. D:\Programme\Windows Media Player\wmpnscfg.exe scheduled to be moved on reboot.
File move failed. D:\Windows\System32\kctoqj.dll scheduled to be moved on reboot.
File move failed. D:\Windows\System32\096E1.tmp scheduled to be moved on reboot.
Registry entries deleted on Reboot...
wars das schon? und wenn ja welche programme soll ich benutzen um meinen rechner bestmöglich sauber zu halten? welche maßnamen? welchen antiviren scanner wäre am besten?
Zum Thema Viren eingefangen, bitte um Hilfe. - woow du hast es echt drauf danke. kann de seiten wieder aufrufen. ansonsten keine symptome mehr bist nen echter lebensretter
Code:
Alles auswählen Aufklappen ATTFilter
All processes killed
========== OTL - Viren eingefangen, bitte um Hilfe....