![]() |
Bitte um Hilfe bei GVU-Virus Liste der Anhänge anzeigen (Anzahl: 4) Hallo, Wie schon in der Überschrift steht, bitte ich um Hilfe mit einem GVU-Virus (oder Trojaner, was auch immer...) auf dem Computer meiner Eltern. Der Virus schaltet sich von selbst nach dem Anmelden in den Vordergrund, mit den bekannten Anschuldigungen und Geldforderungen. Es handelt sich um den bei bka-trojaner.de unter 2.07 gelisteten. Erstmal die Ereignisse chronologisch: Als mein Vater am surfen war, gab Avira eine Warnung über einen Fund heraus, ein paar Augenblicke später erschien das Bild auf dem Monitor. Ich habe dann mit der Kaspersky Rescue Disk den "windowsunlocker" gestartet, das ich meinen BKA-Trojaner auf meinem Rechner damit auch wegbekommen habe. Hat aber nichts geholfen. (Ich weiß, google hätte mir wohl schon vorher verraten, dass es nichts bringt.) Seitdem waren 2 Tage vergangen, ich hab mich heute hier angemeldet und wollte die Checkliste durchgehen. Hab dann den betroffenen PC hochgefahren (ohne Netzwerkstecker) und auf einmal bleibt der GVU-Trojaner weg. Selbes Spiel mit Netzwerkstecker und Inetverbindung. Allerdings kommt beim Hochfahren eine Fehlermeldung (im Anhang sind Bilder zu allen Fehlermeldungen etc.) und Avira Antivir meldet einen Fund. Habe dann Defrogger gestartet und OLT durchlaufen lassen. Danach Avira Echtzeitscanner über das Kontextmenü in der Symbolleiste angehalten. Das Controlcenter ließ sich nämlich nicht mehr öffnen. Windows Firewall auch ausgemacht. Gmer hat unter der Medlung "0lit9qzb.exe funktioniert nicht mehr" abgebrochen. Wollte es dann nochmals versuchen und wurde direkt mit einem Bluescreen beglückt. Nach einem Neustart nochmals versucht, Abbruch an der selben Stelle (siehe Bild im Anhang) Sooo, soweit dazu. Bitte dringend um eure Hilfe, tausend Dank im Vorraus!!! Hier noch ein paar Angaben: -Windows Vista 32bit, 1 Benutzer (Admin) -1 Festplatte, 2 Partitionen: C (Systemfestplatte), D (Recoverypartition, Standard vom Aldi-Medion-Rechner...^^) OTL-Logfile:OTL Logfile: Code: OTL logfile created on: 26.07.2012 15:29:05 - Run 1 |
:hallo: Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :Processes
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
Danke für die schnelle Antwort. Habe alle Schritte bis zum fixen ausgeführt, während dem Fixen kam dann OTL.exe funktioniert nicht mehr. Hab dann über den Taskmanager>Prozesse die explorer.exe wieder gestartet. Hab seit dem letzten Scan den Pc nicht mehr neu gestartet. Evtl mal Neustart und neur Versuch? Gruß schossser |
Ok, versuche es! |
So, nach dem Neustart wurde mir erstmal folgendes Logfile angezeigt: Files\Folders moved on Reboot... File\Folder C:\Windows\temp\JET695C.tmp not found! PendingFileRenameOperations files... File C:\Windows\temp\JET695C.tmp not found! Registry entries deleted on Reboot... Hab dann nochmals OTL laufen lassen, hat dann gefunzt. 2tes Logfile: All processes killed ========== PROCESSES ========== ========== OTL ========== Error: No service named NwlnkFwd was found to stop! Service\Driver key NwlnkFwd not found. File system32\DRIVERS\nwlnkfwd.sys not found. Error: No service named NwlnkFlt was found to stop! Service\Driver key NwlnkFlt not found. File system32\DRIVERS\nwlnkflt.sys not found. Error: No service named IpInIp was found to stop! Service\Driver key IpInIp not found. File system32\DRIVERS\ipinip.sys not found. Error: No service named blbdrive was found to stop! Service\Driver key blbdrive not found. File C:\Windows\system32\drivers\blbdrive.sys not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ not found. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0F13C9BB-EEB3-431A-B132-FD7D3F9A0395}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0F13C9BB-EEB3-431A-B132-FD7D3F9A0395}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{1BFA8F92-833E-46BA-90D1-8FD9D6F848BD}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1BFA8F92-833E-46BA-90D1-8FD9D6F848BD}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{B0156AD4-D543-46CA-8B02-4A18294DFFC3}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{B0156AD4-D543-46CA-8B02-4A18294DFFC3}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{CE83C27B-8C01-4D32-BC24-A0EEB3E819D1}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CE83C27B-8C01-4D32-BC24-A0EEB3E819D1}\ not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! Prefs.js: "hxxp://www.t-online.de/|hxxp://www.google.de/firefox?client=firefox-a&rls=org.mozilla:de:official" removed from browser.startup.homepage Prefs.js: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA}:6.0.31 removed from extensions.enabledItems Prefs.js: foxyproxy@eric.h.jung:3.6.2 removed from extensions.enabledItems Prefs.js: 0 removed from network.proxy.type Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ not found. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Microsoft.com/NpWinExt,version=5.0\ not found. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=\ not found. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ not found. File C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll not found. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ not found. File C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll not found. Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@tools.google.com/Google Update;version=3\ not found. File C:\Users\Yogi\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll not found. Registry key HKEY_CURRENT_USER\Software\MozillaPlugins\@tools.google.com/Google Update;version=9\ not found. File C:\Users\Yogi\AppData\Local\Google\Update\1.3.21.115\npGoogleUpdate3.dll not found. C:\Users\Yogi\AppData\Roaming\mozilla\Extensions folder moved successfully. Folder C:\Users\Yogi\AppData\Roaming\mozilla\Firefox\Profiles\mkvu1idi.default\extensions\ not found. Folder C:\Users\Yogi\AppData\Roaming\mozilla\Firefox\Profiles\mkvu1idi.default\extensions\foxyproxy@eric.h.jung\ not found. Folder C:\Users\Yogi\AppData\Roaming\mozilla\Firefox\Profiles\mkvu1idi.default\extensions\toolbar@ask.com\ not found. File C:\USERS\YOGI\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\MKVU1IDI.DEFAULT\EXTENSIONS\CLIENT@ANONYMOX.NET.XPI not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d2ce3e00-f94a-4740-988e-03dc2f38c34f}\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Programme\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{8dcb7100-df86-4384-8842-8fa844297b3f} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8dcb7100-df86-4384-8842-8fa844297b3f}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Programme\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Programme\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater not found. File C:\Program Files\Ask.com\Updater\Updater.exe not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Bing Bar not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveAutorun not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Extensions\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0B65DCC9-1740-43dc-B19C-4F309FB6A6CA}\ not found. Starting removal of ActiveX control {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8FFBE65D-2C9C-4669-84BD-5829DC0B603C}\ not found. Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! File C:\autoexec.bat not found. File C:\Users\Yogi\Desktop\0lit9qzb.exe not found. File C:\ProgramData\z7_0ytr.pad not found. File C:\Users\Yogi\AppData\Local\d3d9caps.dat not found. File C:\Users\Yogi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk not found. File C:\Windows\tasks\GoogleUpdateTaskMachineCore.job not found. File C:\Users\Yogi\Desktop\Fehlermeldung.JPG not found. File C:\Windows\tasks\GoogleUpdateTaskMachineUA.job not found. File C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-839328200-3665437887-3686338821-1003UA.job not found. File C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-839328200-3665437887-3686338821-1003Core.job not found. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Yogi\Desktop\cmd.bat deleted successfully. C:\Users\Yogi\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public User: Yogi ->Temp folder emptied: 32832 bytes ->Temporary Internet Files folder emptied: 33300 bytes ->Java cache emptied: 0 bytes ->FireFox cache emptied: 25032807 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 456 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 1278332112 bytes RecycleBin emptied: 7093558077 bytes Total Files Cleaned = 8.008,00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Public User: Yogi ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYJAVA] User: All Users User: Default User: Default User User: Public User: Yogi ->Java cache emptied: 0 bytes Total Java Files Cleaned = 0,00 mb OTL by OldTimer - Version 3.2.54.1 log created on 07262012_181107 Files\Folders moved on Reboot... File\Folder C:\Windows\temp\JET85A3.tmp not found! PendingFileRenameOperations files... File C:\Windows\temp\JET85A3.tmp not found! Registry entries deleted on Reboot... |
Sehr gut! :daumenhoc Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
Malwarebyte-Logfile: Malwarebytes Anti-Malware 1.62.0.1300 Malwarebytes : Free anti-malware download Datenbank Version: v2012.07.27.02 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 9.0.8112.16421 Yogi :: YOGI-PC [Administrator] 27.07.2012 07:32:36 mbam-log-2012-07-27 (07-32-36).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 297082 Laufzeit: 1 Stunde(n), 10 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) AdwCleaner-Logfile: # AdwCleaner v1.703 - Logfile created 07/27/2012 at 15:30:39 # Updated 20/07/2012 by Xplode # Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # User : Yogi - YOGI-PC # Running from : C:\Users\Yogi\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\Yogi\AppData\Local\APN Folder Found : C:\Users\Yogi\AppData\Local\AskToolbar Folder Found : C:\Users\Yogi\AppData\LocalLow\AskToolbar Folder Found : C:\Program Files\Ask.com Folder Found : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [Registry] ***** Key Found : HKCU\Software\APN Key Found : HKCU\Software\AppDataLow\Software\AskToolbar Key Found : HKCU\Software\Ask.com Key Found : HKCU\Software\AskToolbar Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Found : HKCU\Software\Softonic Key Found : HKLM\SOFTWARE\APN Key Found : HKLM\SOFTWARE\AskToolbar Key Found : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Found : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Found : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Scheduled Update for Ask Toolbar Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Found : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Found : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Found : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Found : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Found : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v12.0 (de) Profile name : default File : C:\Users\Yogi\AppData\Roaming\Mozilla\Firefox\Profiles\mkvu1idi.default\prefs.js Found : user_pref("extensions.asktb.InstallDir", "C:\\Program Files\\Ask.com\\"); Found : user_pref("extensions.asktb.apn_dbr", "ie_9.0.8112.16421"); Found : user_pref("extensions.asktb.cbid", "LL"); Found : user_pref("extensions.asktb.config-updated", false); Found : user_pref("extensions.asktb.cr-o", "APN10023cr"); Found : user_pref("extensions.asktb.crumb", "2012.03.22+01.17.28-toolbar011iad-DE-U2FhcmJydWNrZW4sR2VybWFueQ[...] Found : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&[...] Found : user_pref("extensions.asktb.dtid", "YYYYYYYYDE"); Found : user_pref("extensions.asktb.fresh-install", false); Found : user_pref("extensions.asktb.guid", "68296c99-a5cc-4f1d-8deb-5988ab14b28b"); Found : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[...] Found : user_pref("extensions.asktb.if", "first"); Found : user_pref("extensions.asktb.l", "dis"); Found : user_pref("extensions.asktb.last-config-req", "1332406911635"); Found : user_pref("extensions.asktb.locale", "de_DE"); Found : user_pref("extensions.asktb.location", "Saarbrucken,Germany"); Found : user_pref("extensions.asktb.notification-shown", true); Found : user_pref("extensions.asktb.o", "APN10023"); Found : user_pref("extensions.asktb.overlay-reloaded-using-restart", true); Found : user_pref("extensions.asktb.qsrc", "2871"); Found : user_pref("extensions.asktb.r", "4"); Found : user_pref("extensions.asktb.sa", "NO"); Found : user_pref("extensions.asktb.save-searches", false); Found : user_pref("extensions.asktb.search-suggestions-enabled", true); Found : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false); Found : user_pref("extensions.asktb.themeid", ""); Found : user_pref("extensions.asktb.timeinstalled", "22.03.2012 09:18:25"); Found : user_pref("extensions.asktb.to", ""); Found : user_pref("extensions.asktb.v", "3.14.1.100010"); Found : user_pref("extensions.asktb.version", "5.14.1.20064"); -\\ Google Chrome v20.0.1132.57 File : C:\Users\Yogi\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R2].txt - [4981 octets] - [27/07/2012 15:30:39] ########## EOF - C:\AdwCleaner[R2].txt - [5109 octets] ########## |
Sehr gut! :daumenhoc
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
Hallo, bei mir gibt es zwei AdwCleaner-Logfiles [S1] und [S2], poste mal beide: S1: # AdwCleaner v1.703 - Logfile created 07/28/2012 at 13:38:34 # Updated 20/07/2012 by Xplode # Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # User : Yogi - YOGI-PC # Running from : C:\Users\Yogi\Desktop\adwcleaner.exe # Option [Delete] S2: # AdwCleaner v1.703 - Logfile created 07/28/2012 at 14:10:24 # Updated 20/07/2012 by Xplode # Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # User : Yogi - YOGI-PC # Running from : C:\Users\Yogi\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\Yogi\AppData\Local\APN Folder Deleted : C:\Users\Yogi\AppData\Local\AskToolbar Folder Deleted : C:\Users\Yogi\AppData\LocalLow\AskToolbar Folder Deleted : C:\Program Files\Ask.com Folder Deleted : C:\Windows\Installer\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [Registry] ***** Key Deleted : HKCU\Software\APN Key Deleted : HKCU\Software\AppDataLow\Software\AskToolbar Key Deleted : HKCU\Software\Ask.com Key Deleted : HKCU\Software\AskToolbar Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Uninstall\{79A765E1-C399-405B-85AF-466F52E918B0} Key Deleted : HKCU\Software\Softonic Key Deleted : HKLM\SOFTWARE\APN Key Deleted : HKLM\SOFTWARE\AskToolbar Key Deleted : HKLM\SOFTWARE\Classes\AppID\GenericAskToolbar.DLL Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd Key Deleted : HKLM\SOFTWARE\Classes\GenericAskToolbar.ToolbarWnd.1 Key Deleted : HKLM\SOFTWARE\Classes\Installer\Features\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Classes\Installer\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\0563B8630D62D75ABBC8AB1E4BDFB5A899B24D43 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Products\A28B4D68DEBAA244EB686953B7074FEF Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{86D4B82A-ABED-442A-BE86-96357B70F4FE} ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\AppID\{9B0CB95C-933A-4B8C-B6D4-EDCD19A43874} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{00000000-6E41-4FD3-8538-502F5495E5FC} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{6C434537-053E-486D-B62A-160059D9D456} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{91CF619A-4686-4CA4-9232-3B2E6B63AA92} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{AC71B60E-94C9-4EDE-BA46-E146747BB67E} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{2996F0E7-292B-4CAE-893F-47B8B1C05B56} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A5AA24EA-11B8-4113-95AE-9ED71DEAF12A} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v12.0 (de) Profile name : default File : C:\Users\Yogi\AppData\Roaming\Mozilla\Firefox\Profiles\mkvu1idi.default\prefs.js Deleted : user_pref("extensions.asktb.InstallDir", "C:\\Program Files\\Ask.com\\"); Deleted : user_pref("extensions.asktb.apn_dbr", "ie_9.0.8112.16421"); Deleted : user_pref("extensions.asktb.cbid", "LL"); Deleted : user_pref("extensions.asktb.config-updated", false); Deleted : user_pref("extensions.asktb.cr-o", "APN10023cr"); Deleted : user_pref("extensions.asktb.crumb", "2012.03.22+01.17.28-toolbar011iad-DE-U2FhcmJydWNrZW4sR2VybWFueQ[...] Deleted : user_pref("extensions.asktb.default-channel-url-mask", "hxxp://de.ask.com/web?q={query}&qsrc={qsrc}&[...] Deleted : user_pref("extensions.asktb.dtid", "YYYYYYYYDE"); Deleted : user_pref("extensions.asktb.fresh-install", false); Deleted : user_pref("extensions.asktb.guid", "68296c99-a5cc-4f1d-8deb-5988ab14b28b"); Deleted : user_pref("extensions.asktb.hxxp-header-whitelist-hosts", "[\"static-dev.en.dev.ask.com\", \"ask.com[...] Deleted : user_pref("extensions.asktb.if", "first"); Deleted : user_pref("extensions.asktb.l", "dis"); Deleted : user_pref("extensions.asktb.last-config-req", "1332406911635"); Deleted : user_pref("extensions.asktb.locale", "de_DE"); Deleted : user_pref("extensions.asktb.location", "Saarbrucken,Germany"); Deleted : user_pref("extensions.asktb.notification-shown", true); Deleted : user_pref("extensions.asktb.o", "APN10023"); Deleted : user_pref("extensions.asktb.overlay-reloaded-using-restart", true); Deleted : user_pref("extensions.asktb.qsrc", "2871"); Deleted : user_pref("extensions.asktb.r", "4"); Deleted : user_pref("extensions.asktb.sa", "NO"); Deleted : user_pref("extensions.asktb.save-searches", false); Deleted : user_pref("extensions.asktb.search-suggestions-enabled", true); Deleted : user_pref("extensions.asktb.silent-upgrade-from-pre-newtabs-build", false); Deleted : user_pref("extensions.asktb.themeid", ""); Deleted : user_pref("extensions.asktb.timeinstalled", "22.03.2012 09:18:25"); Deleted : user_pref("extensions.asktb.to", ""); Deleted : user_pref("extensions.asktb.v", "3.14.1.100010"); Deleted : user_pref("extensions.asktb.version", "5.14.1.20064"); -\\ Google Chrome v20.0.1132.57 File : C:\Users\Yogi\AppData\Local\Google\Chrome\User Data\Default\Preferences [OK] File is clean. ************************* AdwCleaner[R2].txt - [5110 octets] - [27/07/2012 15:30:39] AdwCleaner[S1].txt - [274 octets] - [28/07/2012 13:38:34] AdwCleaner[R3].txt - [5348 octets] - [28/07/2012 14:10:18] AdwCleaner[S2].txt - [5277 octets] - [28/07/2012 14:10:24] ########## EOF - C:\AdwCleaner[S2].txt - [5405 octets] ########## Emisoft Anti-Malware: Emsisoft Anti-Malware - Version 6.6 Letztes Update: 28.07.2012 14:14:42 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, D:\ Archiv Scan: An ADS Scan: An Scan Beginn: 28.07.2012 14:15:08 c:\windows\iwexec.exe gefunden: Trace.File.netpatrol!E1 Gescannt 604337 Gefunden 1 Scan Ende: 28.07.2012 15:30:51 Scan Zeit: 1:15:43 Grüße Schossser |
Sehr gut! :daumenhoc Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
So, das Eset-Log: ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=9e17b381f76c6348a3dd7455abe33f29 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-07-28 03:07:05 # local_time=2012-07-28 05:07:05 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=1792 16777215 100 0 11082596 11082596 0 0 # compatibility_mode=5892 16776573 100 100 5815 181016001 0 0 # compatibility_mode=8192 67108863 100 0 186 186 0 0 # scanned=166862 # found=1 # cleaned=1 # scan_time=4752 D:\TOOLS\Nero Burning ROM 8 Update\Nero-8.2.8.0_deu_update.exe Win32/Toolbar.AskSBar application (cleaned by deleting - quarantined) 00000000000000000000000000000000 C |
Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html |
Hallo nochmal, mit Java bin ich jetzt durch. Gruß Schossser |
Sehr gut! :daumenhoc damit bist Du sauber und entlassen! :) Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Aufräumen mit CCleaner Lasse mit CCleaner (Download) (Anleitung) Fehler in der
Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html |
Alle Zeitangaben in WEZ +1. Es ist jetzt 20:47 Uhr. |
Copyright ©2000-2025, Trojaner-Board