|
Plagegeister aller Art und deren Bekämpfung: wurm.P2P gefunden, was soll ich tun?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
13.03.2011, 19:10 | #16 |
| wurm.P2P gefunden, was soll ich tun? Ich weiss nicht warum, aber ich kann das zipArchiev nicht uploaden, anti vir und kaspersky sind ausgeschaltet. ich weiss nicht obs hilfst, aber hier ist jedenfalls das log von OTL: All processes killed ========== OTL ========== HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\AUTO.WAV moved successfully. C:\autoexec.bat moved successfully. E:\autorun.exe moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ee482216-5ea9-11df-b2f6-001b381b7fae}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ee482216-5ea9-11df-b2f6-001b381b7fae}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ee482216-5ea9-11df-b2f6-001b381b7fae}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ee482216-5ea9-11df-b2f6-001b381b7fae}\ not found. File Z:\Autorun.exe not found. C:\found.003\dir0000.chk\tr_TR\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\tr_TR folder moved successfully. C:\found.003\dir0000.chk\tc_TC\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\tc_TC folder moved successfully. C:\found.003\dir0000.chk\sw_SW\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\sw_SW folder moved successfully. C:\found.003\dir0000.chk\sh_SH\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\sh_SH folder moved successfully. C:\found.003\dir0000.chk\ru_RU\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\ru_RU folder moved successfully. C:\found.003\dir0000.chk\ro_RO\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\ro_RO folder moved successfully. C:\found.003\dir0000.chk\po_PO\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\po_PO folder moved successfully. C:\found.003\dir0000.chk\pl_PL\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\pl_PL folder moved successfully. C:\found.003\dir0000.chk\pe_PE\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\pe_PE folder moved successfully. C:\found.003\dir0000.chk\ja_JA\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\ja_JA folder moved successfully. C:\found.003\dir0000.chk\it_IT\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\it_IT folder moved successfully. C:\found.003\dir0000.chk\hb_HB\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\hb_HB folder moved successfully. C:\found.003\dir0000.chk\fr_FR\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\fr_FR folder moved successfully. C:\found.003\dir0000.chk\es_ES\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\es_ES folder moved successfully. C:\found.003\dir0000.chk\el_EL\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\el_EL folder moved successfully. C:\found.003\dir0000.chk\du_DU\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\du_DU folder moved successfully. C:\found.003\dir0000.chk\de_DE\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\de_DE folder moved successfully. C:\found.003\dir0000.chk\cz_CZ\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\cz_CZ folder moved successfully. C:\found.003\dir0000.chk\bg_BG\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\bg_BG folder moved successfully. C:\found.003\dir0000.chk\ar_AR\LC_MESSAGES folder moved successfully. C:\found.003\dir0000.chk\ar_AR folder moved successfully. C:\found.003\dir0000.chk folder moved successfully. C:\found.003 folder moved successfully. C:\ProgramData\6C6C710F0D.sys moved successfully. ========== COMMANDS ========== C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: holger ->Temp folder emptied: 69758654 bytes ->Temporary Internet Files folder emptied: 14642311 bytes ->Java cache emptied: 12317698 bytes ->FireFox cache emptied: 75097368 bytes ->Google Chrome cache emptied: 205755461 bytes ->Flash cache emptied: 1291 bytes User: Mari ->Temp folder emptied: 1091489344 bytes ->Temporary Internet Files folder emptied: 5542097 bytes ->Java cache emptied: 26263654 bytes ->FireFox cache emptied: 90588158 bytes ->Google Chrome cache emptied: 37395739 bytes ->Flash cache emptied: 6969 bytes User: Mariß User: Public User: RPGVX %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 199168 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 37111488 bytes RecycleBin emptied: 81822929 bytes Total Files Cleaned = 1.667,00 mb OTL by OldTimer - Version 3.2.22.3 log created on 03132011_130051 |
13.03.2011, 19:21 | #17 |
/// Winkelfunktion /// TB-Süch-Tiger™ | wurm.P2P gefunden, was soll ich tun? Versuch das ZIP-Archiv hier hochzuladen => File-Upload.net - Ihr kostenloser File Hoster!
__________________und verlinke die Datei hier.
__________________ |
13.03.2011, 19:29 | #18 |
| wurm.P2P gefunden, was soll ich tun? geht auch nicht.
__________________hier wie es abläuft: 1) ich kopiere MovedFiles in das zip archiev , da kommt schon ein fehler; "Kann den Inhalt von C:\_OTL\MovedFiles\03132011_130051\C_found.003\* nicht lesen" 2) es ist trotzdem allees verpackt. also versuch ichs upzuloaden, aber FEHLER... |
14.03.2011, 09:07 | #19 |
/// Winkelfunktion /// TB-Süch-Tiger™ | wurm.P2P gefunden, was soll ich tun? Dann lass es sein. Bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat!
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu wurm.P2P gefunden, was soll ich tun? |
2 infizierte dateien, angezeigt, anti-malware, antworten, bösartige, dateien, desktop, endgültig, explorer, files, gefunde, infizierte, infizierte dateien, local, microsoft, minute, programm, scan, sms, sobald, sofort, software, value, version, verzeichnisse, virus, wiederherstell, worm.p2p, worte, wurm, wurm.p2p |