Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.
OTL Logfileauswertung - Ich habe das ungute Gefühl, dass mein System infiziert ist
Hier das nach dem Fix generierte Logfile
Code:
ATTFilter
All processes killed
========== OTL ==========
C:\Users\***\AppData\Roaming\0ad\logs folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\data\screenshots folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\data folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\config folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\simulation\templates\units folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\simulation\templates\structures folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\simulation\templates\special folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\simulation\templates\gaia folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\simulation\templates folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\simulation\data folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\simulation folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\shaders folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\maps\scenarios folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\maps folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\gui\session_new folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\gui\pregame folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\gui\loading folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\gui\gamesetup folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\gui\common folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\gui folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\audio\attack\weapon folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\audio\attack folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\audio\actor\human\movement folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\audio\actor\human\death folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\audio\actor\human folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\audio\actor folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\audio folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\textures\terrain\types\special folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\textures\terrain\types\grass folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\textures\terrain\types\biome-mediterranean folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\textures\terrain\types\biome-desert folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\textures\terrain\types folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\textures\terrain folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\textures folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\materials folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\units\hellenes folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\units folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\structures\hellenes folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\structures folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\units\weapons folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\units\tools folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\units\shields folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\units\heads folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\units folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\temp folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\structures\hellenes folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\structures\decals folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\structures folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\special\common folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\special folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\flora folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props\fauna folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\props folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\geology folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\flora\trees folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\flora folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors\fauna folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art\actors folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb\art folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\xmb folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\art\meshes\structural folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\art\meshes\skeletal folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\art\meshes\props\shield folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\art\meshes\props\helmet folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\art\meshes\props folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\art\meshes\gaia folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\art\meshes folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\art\animation\quadraped folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\art\animation\female folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\art\animation\biped folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\art\animation folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public\art folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods\public folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache\mods folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\cache folder moved successfully.
C:\Users\***\AppData\Roaming\0ad folder moved successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
D:\AUTOEXEC.BAT moved successfully.
File not found.
File move failed. G:\Autorun.csf scheduled to be moved on reboot.
File move failed. G:\Autorun.exe scheduled to be moved on reboot.
File move failed. G:\autorun.inf scheduled to be moved on reboot.
File not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{88bcfac6-daba-11de-9775-00241d1101a4}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88bcfac6-daba-11de-9775-00241d1101a4}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{88bcfac6-daba-11de-9775-00241d1101a4}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88bcfac6-daba-11de-9775-00241d1101a4}\ not found.
File H:\setup.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{917baf61-5192-11e0-9464-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{917baf61-5192-11e0-9464-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{917baf61-5192-11e0-9464-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{917baf61-5192-11e0-9464-806e6f6e6963}\ not found.
File move failed. G:\Autorun.exe scheduled to be moved on reboot.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{92396f23-dab3-11de-9c64-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92396f23-dab3-11de-9c64-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{92396f23-dab3-11de-9c64-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{92396f23-dab3-11de-9c64-806e6f6e6963}\ not found.
File G:\autorun1.exe /a not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\34D27A2BD4720CD8 deleted successfully.
Prefs.js: "localhost" removed from network.proxy.backup.ftp
Prefs.js: 8080 removed from network.proxy.backup.ftp_port
Prefs.js: "localhost" removed from network.proxy.backup.gopher
Prefs.js: 8080 removed from network.proxy.backup.gopher_port
Prefs.js: "localhost" removed from network.proxy.backup.socks
Prefs.js: 8080 removed from network.proxy.backup.socks_port
Prefs.js: "localhost" removed from network.proxy.backup.ssl
Prefs.js: 8080 removed from network.proxy.backup.ssl_port
Prefs.js: "localhost" removed from network.proxy.ftp
Prefs.js: 8080 removed from network.proxy.ftp_port
Prefs.js: "localhost" removed from network.proxy.gopher
Prefs.js: 8080 removed from network.proxy.gopher_port
Prefs.js: "localhost" removed from network.proxy.http
Prefs.js: 8080 removed from network.proxy.http_port
Prefs.js: true removed from network.proxy.share_proxy_settings
Prefs.js: "localhost" removed from network.proxy.socks
Prefs.js: 8080 removed from network.proxy.socks_port
Prefs.js: "localhost" removed from network.proxy.ssl
Prefs.js: 8080 removed from network.proxy.ssl_port
Prefs.js: 0 removed from network.proxy.type
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyServer| /E : value set successfully!
========== COMMANDS ==========
C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: ***
->Temp folder emptied: 104814 bytes
->Temporary Internet Files folder emptied: 12070556 bytes
->Java cache emptied: 37347594 bytes
->FireFox cache emptied: 95708856 bytes
->Flash cache emptied: 12691 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 1500 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes
RecycleBin emptied: 375071 bytes
Total Files Cleaned = 139,00 mb
OTL by OldTimer - Version 3.2.22.3 log created on 04162011_154007
Files\Folders moved on Reboot...
File move failed. G:\Autorun.csf scheduled to be moved on reboot.
File move failed. G:\Autorun.exe scheduled to be moved on reboot.
File move failed. G:\autorun.inf scheduled to be moved on reboot.
C:\Users\***\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
Registry entries deleted on Reboot...
Themen zu OTL Logfileauswertung - Ich habe das ungute Gefühl, dass mein System infiziert ist
Zum Thema OTL Logfileauswertung - Ich habe das ungute Gefühl, dass mein System infiziert ist - Hier das nach dem Fix generierte Logfile
Code:
Alles auswählen Aufklappen ATTFilter
All processes killed
========== OTL ==========
C:\Users\***\AppData\Roaming\0ad\logs folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\data\screenshots folder moved successfully.
C:\Users\***\AppData\Roaming\0ad\data folder moved successfully.
- OTL Logfileauswertung - Ich habe das ungute Gefühl, dass mein System infiziert ist...