![]() |
Bundesplizei Trojaner Hallo, mich hats ebenso erwischt wie viele andere. Gestern veränderte sich mein Bildschirm und dann stand da, dass mein Laptop gesperrt sei aufgrund einer Sicherheitskontrolle. Ich hab hier schon ein bißchen gelesen und erhoffe mir nun Unterstützung und Hilfe. Ich bin ein bißchen verzweifelt und ratlos. Ich hoffe ihr könnt mir helfen! ich habe die Malwarebytes software durchlaufen lassen und das kam dabei heraus: Malwarebytes Anti-Malware (Trial) 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.17.05 Windows Vista Service Pack 2 x86 NTFS (Safe Mode/Networking) Internet Explorer 7.0.6002.18005 Icke :: TINA-PC [administrator] Protection: Disabled 17.08.2012 15:08:38 mbam-log-2012-08-17 (15-08-38).txt Scan type: Full scan (C:\|D:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 398359 Time elapsed: 1 hour(s), 12 minute(s), 30 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 1 HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run|ntmeuzdendlkora (Trojan.Ransom) -> Data: C:\ProgramData\ntmeuzde.exe -> Quarantined and deleted successfully. Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 3 C:\Users\Icke\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1X446OUJ\PDFCreator_Stub_5874[1].exe (PUP.Adware.Agent) -> No action taken. C:\ProgramData\ntmeuzde.exe (Trojan.Ransom) -> Quarantined and deleted successfully. C:\Users\Icke\0.5339669088365301.exe (Trojan.Ransom) -> Quarantined and deleted successfully. (end) OTL Logfile: Code: OTL logfile created on: 17.08.2012 16:32:27 - Run 1 OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 17.08.2012 16:32:27 - Run 1 |
:hallo: Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
All processes killed ========== OTL ========== Service NwlnkFwd stopped successfully! Service NwlnkFwd deleted successfully! File system32\DRIVERS\nwlnkfwd.sys File not found not found. Service NwlnkFlt stopped successfully! Service NwlnkFlt deleted successfully! File system32\DRIVERS\nwlnkflt.sys File not found not found. Service IpInIp stopped successfully! Service IpInIp deleted successfully! File system32\DRIVERS\ipinip.sys File not found not found. Error: No service named a7alu80y was found to stop! Service\Driver key a7alu80y not found. File File not found not found. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully. Registry value HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully. C:\Programme\ICQ6Toolbar\ICQToolBar.dll moved successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully! Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6552C7DD-90A4-4387-B795-F8F96747DE19}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{DECA3892-BA8F-44b8-A993-A466AD694AE4}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DECA3892-BA8F-44b8-A993-A466AD694AE4}\ not found. HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyOverride| /E : value set successfully! Prefs.js: "ICQ Search" removed from browser.search.selectedEngine Prefs.js: "hxxp://start.icq.com/" removed from browser.startup.homepage Prefs.js: "ICQ Search" removed from browser.search.defaultenginename Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@Apple.com/iTunes,version=\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{02478D38-C3F9-4efb-9B51-7695ECA05670}\ deleted successfully. C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll moved successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{377C180E-6F0E-4D4C-980F-F45BD3D40CF4}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{377C180E-6F0E-4D4C-980F-F45BD3D40CF4}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35C-6118-11DC-9C72-001320C79847}\ deleted successfully. C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ deleted successfully. File C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{EF99BD32-C1FB-11D2-892F-0090271D4F88} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}\ deleted successfully. File C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\ShellBrowser\\{5CBE3B7C-1E47-477E-A7DD-396DB0476E29} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5CBE3B7C-1E47-477E-A7DD-396DB0476E29}\ deleted successfully. C:\Programme\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\eRecoveryService deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\SweetIM deleted successfully. C:\Programme\SweetIM\Messenger\SweetIM.exe moved successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Sweetpacks Communicator deleted successfully. C:\Programme\SweetIM\Communicator\SweetPacksUpdateManager.exe moved successfully. Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}\ not found. Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. C:\ProgramData\ueskigvqneqbbjh folder moved successfully. C:\ProgramData\SweetIM\Messenger\update folder moved successfully. C:\ProgramData\SweetIM\Messenger\logs folder moved successfully. C:\ProgramData\SweetIM\Messenger\data\packages\FailDialog folder moved successfully. C:\ProgramData\SweetIM\Messenger\data\packages folder moved successfully. C:\ProgramData\SweetIM\Messenger\data\contentdb folder moved successfully. C:\ProgramData\SweetIM\Messenger\data\Bars\Default\400 folder moved successfully. C:\ProgramData\SweetIM\Messenger\data\Bars\Default\200 folder moved successfully. C:\ProgramData\SweetIM\Messenger\data\Bars\Default\100 folder moved successfully. C:\ProgramData\SweetIM\Messenger\data\Bars\Default folder moved successfully. C:\ProgramData\SweetIM\Messenger\data\Bars folder moved successfully. C:\ProgramData\SweetIM\Messenger\data folder moved successfully. C:\ProgramData\SweetIM\Messenger\conf\users folder moved successfully. C:\ProgramData\SweetIM\Messenger\conf folder moved successfully. C:\ProgramData\SweetIM\Messenger folder moved successfully. C:\ProgramData\SweetIM\Communicator\Logs folder moved successfully. C:\ProgramData\SweetIM\Communicator\conf folder moved successfully. C:\ProgramData\SweetIM\Communicator folder moved successfully. C:\ProgramData\SweetIM folder moved successfully. C:\Windows\System32\cnmA971.tmp deleted successfully. C:\ProgramData\twwjhhxdrtpukcp moved successfully. ADS C:\ProgramData\Temp:30C46519 deleted successfully. ADS C:\ProgramData\Temp:E6C58E14 deleted successfully. ADS C:\ProgramData\Temp:7F66BF58 deleted successfully. ADS C:\ProgramData\Temp:DCDE7C60 deleted successfully. ADS C:\ProgramData\Temp:B894C266 deleted successfully. ADS C:\ProgramData\Temp:ABA71843 deleted successfully. ADS C:\ProgramData\Temp:CF2C26D2 deleted successfully. ADS C:\ProgramData\Temp:0651F96C deleted successfully. ADS C:\ProgramData\Temp:765C6A14 deleted successfully. ADS C:\ProgramData\Temp:2FF4577A deleted successfully. ADS C:\ProgramData\Temp:D88D995C deleted successfully. ADS C:\ProgramData\Temp:D05E7A8B deleted successfully. ADS C:\ProgramData\Temp:940ECC98 deleted successfully. ADS C:\ProgramData\Temp:26EE282C deleted successfully. ADS C:\ProgramData\Temp:41C283B2 deleted successfully. ADS C:\ProgramData\Temp:0AE8FC60 deleted successfully. ADS C:\ProgramData\Temp:F878F14A deleted successfully. ADS C:\ProgramData\Temp:13B137AF deleted successfully. ADS C:\ProgramData\Temp:ED45A20F deleted successfully. ADS C:\ProgramData\Temp:B652B720 deleted successfully. ADS C:\ProgramData\Temp:9B0F9E15 deleted successfully. ADS C:\ProgramData\Temp:3F22DA14 deleted successfully. ADS C:\ProgramData\Temp:E55CE2D1 deleted successfully. ADS C:\ProgramData\Temp:C40E212B deleted successfully. ADS C:\ProgramData\Temp:426796C0 deleted successfully. ADS C:\ProgramData\Temp:860D9052 deleted successfully. ADS C:\ProgramData\Temp:9446E8B9 deleted successfully. ADS C:\ProgramData\Temp:5A173E50 deleted successfully. ADS C:\ProgramData\Temp:550179F5 deleted successfully. ADS C:\ProgramData\Temp:50A11A00 deleted successfully. ADS C:\ProgramData\Temp:05816AFA deleted successfully. ADS C:\ProgramData\Temp:EB603FE4 deleted successfully. ADS C:\ProgramData\Temp:F50F1555 deleted successfully. ADS C:\ProgramData\Temp:2FAFBD6A deleted successfully. ADS C:\ProgramData\Temp:0EE601C7 deleted successfully. ADS C:\ProgramData\Temp:CF5C4195 deleted successfully. ADS C:\ProgramData\Temp:9AB338B9 deleted successfully. ADS C:\ProgramData\Temp:8DB5ACDD deleted successfully. ADS C:\ProgramData\Temp:79F970BE deleted successfully. ADS C:\ProgramData\Temp:3B3A35EC deleted successfully. ADS C:\ProgramData\Temp:F65733F1 deleted successfully. ADS C:\ProgramData\Temp:E33D6212 deleted successfully. ADS C:\ProgramData\Temp:8BB2EE92 deleted successfully. ADS C:\ProgramData\Temp:62197B73 deleted successfully. ADS C:\ProgramData\Temp:8F7ECF6A deleted successfully. ADS C:\ProgramData\Temp:8DD623B3 deleted successfully. ADS C:\ProgramData\Temp:0D31DA45 deleted successfully. ADS C:\ProgramData\Temp:FA8B212D deleted successfully. ADS C:\ProgramData\Temp:E71141D2 deleted successfully. ADS C:\ProgramData\Temp:994AEA06 deleted successfully. ADS C:\ProgramData\Temp:87FA5E8A deleted successfully. ADS C:\ProgramData\Temp:77846FFE deleted successfully. ADS C:\ProgramData\Temp:7091055F deleted successfully. ADS C:\ProgramData\Temp:E89EDC52 deleted successfully. ADS C:\ProgramData\Temp:A724744F deleted successfully. ADS C:\ProgramData\Temp:580E04D8 deleted successfully. ADS C:\ProgramData\Temp:4B49E3BC deleted successfully. ADS C:\ProgramData\Temp:20451762 deleted successfully. ADS C:\ProgramData\Temp:9E22BBE8 deleted successfully. ADS C:\ProgramData\Temp:4D066AD2 deleted successfully. ADS C:\ProgramData\Temp:8AB6C1D7 deleted successfully. ADS C:\ProgramData\Temp:0A73A758 deleted successfully. ADS C:\ProgramData\Temp:E36F5B57 deleted successfully. ADS C:\ProgramData\Temp:D26DD363 deleted successfully. ADS C:\ProgramData\Temp:369A9F46 deleted successfully. ADS C:\ProgramData\Temp:A42A9F39 deleted successfully. ADS C:\ProgramData\Temp:273A8657 deleted successfully. ADS C:\ProgramData\Temp:C0A4F645 deleted successfully. ADS C:\ProgramData\Temp:F951183D deleted successfully. ADS C:\ProgramData\Temp:8C458D50 deleted successfully. ADS C:\ProgramData\Temp:72E546C1 deleted successfully. ADS C:\ProgramData\Temp:7079A696 deleted successfully. ADS C:\ProgramData\Temp:1C9565AC deleted successfully. ADS C:\ProgramData\Temp:7C8950EF deleted successfully. ADS C:\ProgramData\Temp:4E903DEB deleted successfully. ADS C:\ProgramData\Temp:B623B5B8 deleted successfully. ADS C:\ProgramData\Temp:567AC0A6 deleted successfully. ADS C:\ProgramData\Temp:A696643D deleted successfully. ADS C:\ProgramData\Temp:8FBE0E9C deleted successfully. ADS C:\ProgramData\Temp:5466F106 deleted successfully. ADS C:\ProgramData\Temp:9A2521F1 deleted successfully. ADS C:\ProgramData\Temp:615435BE deleted successfully. ADS C:\ProgramData\Temp:41099CE9 deleted successfully. ADS C:\ProgramData\Temp:389D51A1 deleted successfully. ADS C:\ProgramData\Temp:4F636E25 deleted successfully. ADS C:\ProgramData\Temp:4CF61E54 deleted successfully. ADS C:\ProgramData\Temp:D8A7F3FF deleted successfully. ADS C:\ProgramData\Temp:2FC9D9C0 deleted successfully. ADS C:\ProgramData\Temp:18AE7C5A deleted successfully. ADS C:\ProgramData\Temp:981349EA deleted successfully. ADS C:\ProgramData\Temp:6A18D1F5 deleted successfully. ADS C:\ProgramData\Temp:588B60C7 deleted successfully. C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\orange folder moved successfully. C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\green folder moved successfully. C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources\blue folder moved successfully. C:\Program Files\SweetIM\Toolbars\Internet Explorer\resources folder moved successfully. C:\Program Files\SweetIM\Toolbars\Internet Explorer\Microsoft.VC90.CRT folder moved successfully. C:\Program Files\SweetIM\Toolbars\Internet Explorer\conf folder moved successfully. C:\Program Files\SweetIM\Toolbars\Internet Explorer folder moved successfully. C:\Program Files\SweetIM\Toolbars folder moved successfully. C:\Program Files\SweetIM\Messenger\resources\sqlite folder moved successfully. C:\Program Files\SweetIM\Messenger\resources\images folder moved successfully. C:\Program Files\SweetIM\Messenger\resources folder moved successfully. C:\Program Files\SweetIM\Messenger folder moved successfully. C:\Program Files\SweetIM\Communicator\resources\sqlite folder moved successfully. C:\Program Files\SweetIM\Communicator\resources folder moved successfully. C:\Program Files\SweetIM\Communicator\Microsoft.VC90.CRT folder moved successfully. C:\Program Files\SweetIM\Communicator folder moved successfully. C:\Program Files\SweetIM folder moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully. C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully. C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3964052105-1468430595-4155204716-1000UA.job moved successfully. C:\Windows\Tasks\Google Software Updater.job moved successfully. C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-3964052105-1468430595-4155204716-1000Core.job moved successfully. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Icke\Desktop\cmd.bat deleted successfully. C:\Users\Icke\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 41 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Icke ->Temp folder emptied: 6421723640 bytes ->Temporary Internet Files folder emptied: 225017795 bytes ->Java cache emptied: 15187202 bytes ->FireFox cache emptied: 115450402 bytes ->Apple Safari cache emptied: 177933312 bytes ->Flash cache emptied: 13150 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 479077736 bytes RecycleBin emptied: 1669529624 bytes Total Files Cleaned = 8.682,00 mb OTL by OldTimer - Version 3.2.57.0 log created on 08172012_211521 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot... Ist es geschafft? haben wir den Trojaner verjagt? Was mus ich jetzt tun? Schon mal vielen vielen Dank, ihr seit super und meine Rettung! |
Sehr gut! :daumenhoc Wie laeuft der Rechner? 1. Schritt Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.danach: 2. Schritt Downloade Dir bitte AdwCleaner auf deinen Desktop.
|
Rechner läuft super bis jetzt! Ich werd noch deine nächsten Schritte ausführen und dann sehen wir weiter! Malwarebytes Anti-Malware (Trial) 1.62.0.1300 www.malwarebytes.org Database version: v2012.08.19.01 Windows Vista Service Pack 2 x86 NTFS Internet Explorer 7.0.6002.18005 Icke :: TINA-PC [administrator] Protection: Disabled 19.08.2012 07:16:09 mbam-log-2012-08-19 (07-16-09).txt Scan type: Full scan (C:\|D:\|) Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 384129 Time elapsed: 1 hour(s), 54 minute(s), 14 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) # AdwCleaner v1.801 - Logfile created 08/19/2012 at 09:13:34 # Updated 14/08/2012 by Xplode # Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # User : Icke - TINA-PC # Boot Mode : Normal # Running from : C:\Users\Icke\Desktop\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\Users\Icke\AppData\Roaming\pdfforge Folder Found : C:\Users\Icke\AppData\Roaming\Mozilla\Firefox\Profiles\k1d3xd16.default\SweetPacksToolbarData Folder Found : C:\Windows\Installer\{0965F857-DAAD-4F93-8054-0E2EC3C8C5B0} Folder Found : C:\Windows\Installer\{5B58EF61-85F2-4977-97A5-84C19F926579} Folder Found : C:\Windows\Installer\{FB697452-8CA4-46B4-98B1-165C922A2EF3} File Found : C:\Users\Icke\AppData\Roaming\Mozilla\Firefox\Profiles\k1d3xd16.default\searchplugins\SweetIm.xml File Found : C:\Users\Icke\AppData\Roaming\Mozilla\Firefox\Profiles\k1d3xd16.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi ***** [Registry] ***** Key Found : HKCU\Software\SweetIm Key Found : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils Key Found : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1 Key Found : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator Key Found : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1 Key Found : HKLM\SOFTWARE\Classes\sim-packages Key Found : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar Key Found : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1 Key Found : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook Key Found : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1 Key Found : HKLM\SOFTWARE\Classes\Toolbar3.sweetie Key Found : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1 Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0965F857-DAAD-4F93-8054-0E2EC3C8C5B0} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5B58EF61-85F2-4977-97A5-84C19F926579} Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FB697452-8CA4-46B4-98B1-165C922A2EF3} Key Found : HKLM\SOFTWARE\SweetIM ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A} Key Found : HKLM\SOFTWARE\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064} Key Found : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289} Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} ***** [Internet Browsers] ***** -\\ Internet Explorer v7.0.6002.18005 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\Icke\AppData\Roaming\Mozilla\Firefox\Profiles\k1d3xd16.default\prefs.js Found : user_pref("keyword.URL", "hxxp://search.sweetim.com/search.asp?src=2&q="); Found : user_pref("sweetim.toolbar.dialogs.0.enable", "true"); Found : user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-h[...] Found : user_pref("sweetim.toolbar.dialogs.0.height", "335"); Found : user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog"); Found : user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;"); Found : user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff.html")[...] Found : user_pref("sweetim.toolbar.dialogs.0.width", "761"); Found : user_pref("sweetim.toolbar.dialogs.1.enable", "true"); Found : user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-h[...] Found : user_pref("sweetim.toolbar.dialogs.1.height", "300"); Found : user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog"); Found : user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog"); Found : user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html"[...] Found : user_pref("sweetim.toolbar.dialogs.1.width", "500"); Found : user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.goog[...] Found : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0"); Found : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7"); Found : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log"); Found : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000"); Found : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7"); Found : user_pref("sweetim.toolbar.mode.debug", "false"); Found : user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://search.icq.com/search/afe_results.php?ch_i[...] Found : user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true"); Found : user_pref("sweetim.toolbar.scripts.0.callback", "simVerification"); Found : user_pref("sweetim.toolbar.scripts.0.domain-blacklist", ""); Found : user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(www.|apps.)?facebook\\.com.*"); Found : user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb"); Found : user_pref("sweetim.toolbar.scripts.0.enable", "true"); Found : user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb"); Found : user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js"); Found : user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "false"); Found : user_pref("sweetim.toolbar.scripts.1.callback", ""); Found : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..[...] Found : user_pref("sweetim.toolbar.scripts.1.domain-whitelist", ""); Found : user_pref("sweetim.toolbar.scripts.1.elementid", "id_predict_include_script"); Found : user_pref("sweetim.toolbar.scripts.1.enable", "false"); Found : user_pref("sweetim.toolbar.scripts.1.id", "id_script_prad"); Found : user_pref("sweetim.toolbar.scripts.1.url", "hxxp://cdn1.predictad.com/scripts/publishers/sweetim/pre[...] Found : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engin[...] Found : user_pref("sweetim.toolbar.search.history.capacity", "10"); Found : user_pref("sweetim.toolbar.searchguard.enable", "true"); Found : user_pref("sweetim.toolbar.simapp_id", "{42C301B3-E5FD-11E1-96D2-001EEC5742BC}"); ************************* AdwCleaner[R1].txt - [7112 octets] - [19/08/2012 09:13:34] ########## EOF - C:\AdwCleaner[R1].txt - [7240 octets] ########## |
Sehr gut! :daumenhoc
danach: Malware-Scan mit Emsisoft Anti-Malware Lade die Gratisversion von => Emsisoft Anti-Malware herunter und installiere das Programm. Lade über Jetzt Updaten die aktuellen Signaturen herunter. Wähle den Freeware-Modus aus. Wähle Detail Scan und starte über den Button Scan die Überprüfung des Computers. Am Ende des Scans nichts loeschen lassen!. Mit Klick auf Bericht speichern das Logfile auf dem Desktop speichern und hier in den Thread posten. Anleitung: http://www.trojaner-board.de/103809-...i-malware.html |
# AdwCleaner v1.801 - Logfile created 08/19/2012 at 18:24:50 # Updated 14/08/2012 by Xplode # Operating system : Windows Vista (TM) Home Premium Service Pack 2 (32 bits) # User : Icke - TINA-PC # Boot Mode : Normal # Running from : C:\Users\Icke\Desktop\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Folder Deleted : C:\Users\Icke\AppData\Roaming\pdfforge Folder Deleted : C:\Users\Icke\AppData\Roaming\Mozilla\Firefox\Profiles\k1d3xd16.default\SweetPacksToolbarData Folder Deleted : C:\Windows\Installer\{0965F857-DAAD-4F93-8054-0E2EC3C8C5B0} Folder Deleted : C:\Windows\Installer\{5B58EF61-85F2-4977-97A5-84C19F926579} Folder Deleted : C:\Windows\Installer\{FB697452-8CA4-46B4-98B1-165C922A2EF3} File Deleted : C:\Users\Icke\AppData\Roaming\Mozilla\Firefox\Profiles\k1d3xd16.default\searchplugins\SweetIm.xml File Deleted : C:\Users\Icke\AppData\Roaming\Mozilla\Firefox\Profiles\k1d3xd16.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi ***** [Registry] ***** Key Deleted : HKCU\Software\SweetIm Key Deleted : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils Key Deleted : HKLM\SOFTWARE\Classes\MediaPlayer.GraphicsUtils.1 Key Deleted : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator Key Deleted : HKLM\SOFTWARE\Classes\MgMediaPlayer.GifAnimator.1 Key Deleted : HKLM\SOFTWARE\Classes\sim-packages Key Deleted : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar Key Deleted : HKLM\SOFTWARE\Classes\SWEETIE.IEToolbar.1 Key Deleted : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook Key Deleted : HKLM\SOFTWARE\Classes\sweetim_urlsearchhook.toolbarurlsearchhook.1 Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.sweetie Key Deleted : HKLM\SOFTWARE\Classes\Toolbar3.sweetie.1 Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SweetIM.exe Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{0965F857-DAAD-4F93-8054-0E2EC3C8C5B0} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{5B58EF61-85F2-4977-97A5-84C19F926579} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{FB697452-8CA4-46B4-98B1-165C922A2EF3} Key Deleted : HKLM\SOFTWARE\SweetIM ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{82AC53B4-164C-4B07-A016-437A8388B81A} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{A4A0CB15-8465-4F58-A7E5-73084EA2A064} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{A439801C-961D-452C-AB42-7848E9CBD289} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C358-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C359-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{EEE6C35A-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F4EBB1E2-21F3-4786-8CF4-16EC5925867F} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{4D3B167E-5FD8-4276-8FD7-9DF19C1E4D19} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{EEE6C35F-6118-11DC-9C72-001320C79847} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{EEE6C367-6118-11DC-9C72-001320C79847} ***** [Internet Browsers] ***** -\\ Internet Explorer v7.0.6002.18005 [OK] Registry is clean. -\\ Mozilla Firefox v14.0.1 (de) Profile name : default File : C:\Users\Icke\AppData\Roaming\Mozilla\Firefox\Profiles\k1d3xd16.default\prefs.js C:\Users\Icke\AppData\Roaming\Mozilla\Firefox\Profiles\k1d3xd16.default\user.js ... Deleted ! Deleted : user_pref("keyword.URL", "hxxp://search.sweetim.com/search.asp?src=2&q="); Deleted : user_pref("sweetim.toolbar.dialogs.0.enable", "true"); Deleted : user_pref("sweetim.toolbar.dialogs.0.handler", "chrome://sim_toolbar_package/content/optionsdialog-h[...] Deleted : user_pref("sweetim.toolbar.dialogs.0.height", "335"); Deleted : user_pref("sweetim.toolbar.dialogs.0.id", "id_options_dialog"); Deleted : user_pref("sweetim.toolbar.dialogs.0.title", "$string.config.label;"); Deleted : user_pref("sweetim.toolbar.dialogs.0.url", "hxxp://www.sweetim.com/simffbar/options_remote_ff.html")[...] Deleted : user_pref("sweetim.toolbar.dialogs.0.width", "761"); Deleted : user_pref("sweetim.toolbar.dialogs.1.enable", "true"); Deleted : user_pref("sweetim.toolbar.dialogs.1.handler", "chrome://sim_toolbar_package/content/exampledialog-h[...] Deleted : user_pref("sweetim.toolbar.dialogs.1.height", "300"); Deleted : user_pref("sweetim.toolbar.dialogs.1.id", "id_example_dialog"); Deleted : user_pref("sweetim.toolbar.dialogs.1.title", "Example (unit-test) dialog"); Deleted : user_pref("sweetim.toolbar.dialogs.1.url", "chrome://sim_toolbar_package/content/exampledialog.html"[...] Deleted : user_pref("sweetim.toolbar.dialogs.1.width", "500"); Deleted : user_pref("sweetim.toolbar.dnscatch.domain-blacklist", ".*.sweetim.com/.*|.*.facebook.com/.*|.*.goog[...] Deleted : user_pref("sweetim.toolbar.highlight.colors", "#FFFF00,#00FFE4,#5AFF00,#0087FF,#FFCC00,#FF00F0"); Deleted : user_pref("sweetim.toolbar.logger.ConsoleHandler.MinReportLevel", "7"); Deleted : user_pref("sweetim.toolbar.logger.FileHandler.FileName", "ff-toolbar.log"); Deleted : user_pref("sweetim.toolbar.logger.FileHandler.MaxFileSize", "200000"); Deleted : user_pref("sweetim.toolbar.logger.FileHandler.MinReportLevel", "7"); Deleted : user_pref("sweetim.toolbar.mode.debug", "false"); Deleted : user_pref("sweetim.toolbar.previous.keyword.URL", "hxxp://search.icq.com/search/afe_results.php?ch_i[...] Deleted : user_pref("sweetim.toolbar.scripts.0.addcontextdiv", "true"); Deleted : user_pref("sweetim.toolbar.scripts.0.callback", "simVerification"); Deleted : user_pref("sweetim.toolbar.scripts.0.domain-blacklist", ""); Deleted : user_pref("sweetim.toolbar.scripts.0.domain-whitelist", "hxxp://(www.|apps.)?facebook\\.com.*"); Deleted : user_pref("sweetim.toolbar.scripts.0.elementid", "id_script_sim_fb"); Deleted : user_pref("sweetim.toolbar.scripts.0.enable", "true"); Deleted : user_pref("sweetim.toolbar.scripts.0.id", "id_script_fb"); Deleted : user_pref("sweetim.toolbar.scripts.0.url", "hxxp://sc.sweetim.com/apps/in/fb/infb.js"); Deleted : user_pref("sweetim.toolbar.scripts.1.addcontextdiv", "false"); Deleted : user_pref("sweetim.toolbar.scripts.1.callback", ""); Deleted : user_pref("sweetim.toolbar.scripts.1.domain-blacklist", ".*.google..*|.*.bing..*|.*.live..*|.*.msn..[...] Deleted : user_pref("sweetim.toolbar.scripts.1.domain-whitelist", ""); Deleted : user_pref("sweetim.toolbar.scripts.1.elementid", "id_predict_include_script"); Deleted : user_pref("sweetim.toolbar.scripts.1.enable", "false"); Deleted : user_pref("sweetim.toolbar.scripts.1.id", "id_script_prad"); Deleted : user_pref("sweetim.toolbar.scripts.1.url", "hxxp://cdn1.predictad.com/scripts/publishers/sweetim/pre[...] Deleted : user_pref("sweetim.toolbar.search.external", "<?xml version=\"1.0\"?><TOOLBAR><EXTERNAL_SEARCH engin[...] Deleted : user_pref("sweetim.toolbar.search.history.capacity", "10"); Deleted : user_pref("sweetim.toolbar.searchguard.enable", "true"); Deleted : user_pref("sweetim.toolbar.simapp_id", "{42C301B3-E5FD-11E1-96D2-001EEC5742BC}"); ************************* AdwCleaner[R1].txt - [7241 octets] - [19/08/2012 09:13:34] AdwCleaner[S1].txt - [7427 octets] - [19/08/2012 18:24:50] ########## EOF - C:\AdwCleaner[S1].txt - [7555 octets] ########## Emsisoft Anti-Malware - Version 6.6 Letztes Update: 22.08.2012 07:40:20 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, D:\ Archiv Scan: An ADS Scan: An Scan Beginn: 22.08.2012 07:42:12 c:\users\icke\appdata\roaming\pogo games\common gefunden: Trace.File.lottso!E1 c:\users\icke\appdata\roaming\pogo games gefunden: Trace.File.lottso!E1 c:\users\icke\appdata\roaming\pogo games\common\cache gefunden: Trace.File.lottso!E1 Value: hkey_current_user\software\gog\bloodties --> inprogress gefunden: Trace.Registry.gamefiesta blood ties!E1 Value: hkey_current_user\software\gog\bloodties\test3d --> recvidmemory gefunden: Trace.Registry.gamefiesta blood ties!E1 Value: hkey_current_user\software\gog\bloodties\test3d --> version gefunden: Trace.Registry.gamefiesta blood ties!E1 Value: hkey_current_user\software\gog\bloodties\test3d --> warning gefunden: Trace.Registry.gamefiesta blood ties!E1 Key: hkey_local_machine\software\trymedia systems gefunden: Trace.Registry.trymedia!E1 Key: hkey_local_machine\software\trymedia systems\activemark software gefunden: Trace.Registry.trymedia!E1 Value: hkey_current_user\software\gog\bloodties\test3d --> failurereason gefunden: Trace.Registry.gamefiesta blood ties!E1 Value: hkey_current_user\software\gog\bloodties\test3d --> minvidmemory gefunden: Trace.Registry.gamefiesta blood ties!E1 Value: hkey_current_user\software\gog\bloodties\test3d --> displayguid gefunden: Trace.Registry.gamefiesta blood ties!E1 C:\Program Files\Yahoo! Games\Zuma Deluxe\Zuma.exe gefunden: Riskware.Crack.Zuma!E2 C:\Program Files\Yahoo! Games\Zuma Deluxe\PopCap Zuma Deluxe! v1.0 (crack).exe gefunden: Adware.Win32.Agent!E1 C:\Program Files\DAEMON Tools Lite\uninst.exe gefunden: Adware.Win32.Toolbar.Shopper.AMN!E1 Gescannt 643118 Gefunden 15 Scan Ende: 22.08.2012 10:58:16 Scan Zeit: 3:16:04 C:\Program Files\DAEMON Tools Lite\uninst.exe Quarantäne Adware.Win32.Toolbar.Shopper.AMN!E1 C:\Program Files\Yahoo! Games\Zuma Deluxe\PopCap Zuma Deluxe! v1.0 (crack).exe Quarantäne Adware.Win32.Agent!E1 C:\Program Files\Yahoo! Games\Zuma Deluxe\Zuma.exe Quarantäne Riskware.Crack.Zuma!E2 Key: hkey_local_machine\software\trymedia systems Quarantäne Trace.Registry.trymedia!E1 Key: hkey_local_machine\software\trymedia systems\activemark software Quarantäne Trace.Registry.trymedia!E1 Value: hkey_current_user\software\gog\bloodties --> inprogress Quarantäne Trace.Registry.gamefiesta blood ties!E1 Value: hkey_current_user\software\gog\bloodties\test3d --> recvidmemory Quarantäne Trace.Registry.gamefiesta blood ties!E1 Value: hkey_current_user\software\gog\bloodties\test3d --> version Quarantäne Trace.Registry.gamefiesta blood ties!E1 Value: hkey_current_user\software\gog\bloodties\test3d --> warning Quarantäne Trace.Registry.gamefiesta blood ties!E1 Value: hkey_current_user\software\gog\bloodties\test3d --> failurereason Quarantäne Trace.Registry.gamefiesta blood ties!E1 Value: hkey_current_user\software\gog\bloodties\test3d --> minvidmemory Quarantäne Trace.Registry.gamefiesta blood ties!E1 Value: hkey_current_user\software\gog\bloodties\test3d --> displayguid Quarantäne Trace.Registry.gamefiesta blood ties!E1 c:\users\icke\appdata\roaming\pogo games\common Quarantäne Trace.File.lottso!E1 c:\users\icke\appdata\roaming\pogo games Quarantäne Trace.File.lottso!E1 c:\users\icke\appdata\roaming\pogo games\common\cache Quarantäne Trace.File.lottso!E1 Quarantäne 15 |
Sehr gut! :daumenhoc Deinstalliere: Emsisoft Anti-Malware ESET Online Scanner Vorbereitung
|
ESETSmartInstaller@High as downloader log: all ok # version=7 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6583 # api_version=3.0.2 # EOSSerial=11fae896eb60b74b92a2001544570609 # end=finished # remove_checked=true # archives_checked=true # unwanted_checked=true # unsafe_checked=false # antistealth_checked=true # utc_time=2012-08-24 09:22:14 # local_time=2012-08-24 11:22:14 (+0100, Mitteleuropäische Sommerzeit) # country="Germany" # lang=1033 # osver=6.0.6002 NT Service Pack 2 # compatibility_mode=770 16774141 100 100 43701660 282072640 0 0 # compatibility_mode=5892 16776573 100 100 1787 183324214 0 0 # compatibility_mode=8192 67108863 100 0 176 176 0 0 # scanned=208495 # found=1 # cleaned=1 # scan_time=8648 C:\_OTL\MovedFiles\08172012_211521\C_ProgramData\ueskigvqneqbbjh\main.html HTML/Ransom.B trojan (cleaned by deleting - quarantined) 00000000000000000000000000000000 C |
Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html Danach poste (kopieren und einfuegen) mir, was du hier angezeigt bekommst: PluginCheck |
hallo, hab alles gemacht, dass kam dabei raus: PluginCheck Der PluginCheck hilft die größten Sicherheitslücken beim Surfen im Internet zu schliessen. Überprüft wird: Browser, Flash, Java und Adobe Reader Version. Firefox 14.0.1 ist aktuell Flash 11,0,1,152 ist veraltet! Aktualisieren Sie bitte auf die neueste Version! Java (1,7,0,6) ist aktuell. Adobe Reader 8,2,0,81 ist veraltet! Aktualisieren Sie bitte auf die neueste Version: 10,1,3 |
Sehr gut! :daumenhoc damit bist Du sauber und entlassen! :) adwCleaner entfernen
Tool-Bereinigung mit OTL Wir werden nun die CleanUp!-Funktion von OTL nutzen, um die meisten Programme, die wir zur Bereinigung installiert haben, wieder von Deinem System zu löschen.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Systemwiederherstellungen leeren Damit der Rechner nicht mit einer infizierten Systemwiederherstellung erneut infiziert werden kann, muessen wir diese leeren. Dazu schalten wir sie einmal aus und dann wieder ein: Systemwiederherstellung deaktivieren Tutorial fuer Windows XP, Windows Vista, Windows 7 Danach wieder aktivieren. Aufräumen mit CCleaner Lasse mit CCleaner (Download) (Anleitung) Fehler in der
Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html PC wird immer langsamer - was tun? |
Alle Zeitangaben in WEZ +1. Es ist jetzt 16:35 Uhr. |
Copyright ©2000-2025, Trojaner-Board