![]() |
GVU trojaner Hallo zusammen, Please excuse me for writing in English but I can speak and read it. It is no problem if you respond in German to my problem. A GVU trojan has entered into the laptop I use for my self employment business and I need some help to deleting it. When I scanned the internet for solutions, I came across this forum and noticed another person described exactly my problem and was able to solve it with the help of this forum. See the following link for the exact problem description. http://www.trojaner-board.de/138004-...artet-neu.html I used Farbar to compile the logfile in this .TXT attachment. Can someone help me by changing the logfile as it was done for chrisdee? I use windows vista and would really appreciate any help. Gruß, hloy |
Hi, if you need some translations ... please ask. !! Hinweis an Mitlesende !! Dieses Thema und die Anweisungen sind nur für diesen speziellen Fall gedacht. Sie könnten andere Computer schwer beschädigen. Öffnet bitte euer eigenes Thema. :hallo: Ich werde dir bei deinem Problem helfen. Die Bereinigung funktioniert nur, wenn du dich an die folgenden Regeln hälst: ![]() Regeln für die Bereinigung
![]() Lesestoff: Rootkit-Warnung Dein Computer wurde mit einem besonderen Schädling infiziert, der sich vor herkömmlichen Virenscannern und dem Betriebssystem selbst verstecken kann. Zusätzlich hat so ein Schädling meist auch Backdoor-Funktionalität, reißt also ganz bewußt Löcher durch alle Schutzmaßnahmen, damit er weiteren Schadcode nachladen oder die Daten, die er so sammelt, an die "bösen Jungs" weiterleiten kann. Was heißt das jetzt für dich?
Teile mir also mit, wie du dich entschieden hast. Fix mit FRST Tell how that went and if you can boot. You are still heavy infected. |
Thanks for responding so fast. I was able to transfer and install the fixlist.txt as you described. The desktop screen appeared with all of the icons until the computer was completely finished booting. Then the Bildschirm was blocked again. I have attached the Fixlog.txt. |
Okay you have a very nasty infection. Personally I would recommend to reinstall, but we can still try to unlock. Please check for me if you can boot into safemode with command prompt. |
Sorry I could not respond sooner. It would be an absolute tragedy to reinstall everything new. I REALLY appreciate your offer to still help me unlock. It would be best for me to reinstall everything if I could get my system running again and retrieve a backup. Just before my computer was blocked, I noticed that a software was installed without my consent. It is called "Internet Securtity Pro". I was unable to deinstall or stop it. There are several "Benutzerkonten" on my laptop. I can begin "Safe Mode with prompt" but shortly after booting, the monitor is blocked and I come no further. Is this what you mean? Task Manager has been disabled in all of them. If I use Farbar to boot, then I choose "Computer Reparieren" and come to "Systemwiederherstellungsoptionen" and get a prompt with "Eingabeaufforderung". This is no problem and I can see every drive and all directories. |
Alright - please give me a new FRST logfile from recovery command prompt. It really would be better to reinstall. Fetching your data from the drive before you do so is easy if you use the Kaspersky Rescue Disk to mount your drives and then backup all your data. |
I can send you the new logfile in about an hour since I am currently in the process of trying to copy my files onto an external hard drive. |
yeah better back it all up :) |
Attached is a logfile from today. |
Alright, please try this frst-fix in the recovery mode - after that ... ONLY boot into safemode with command prompt - do nothing else. Report how it went. Code: HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,,C:\Program Files\Sony Ericsson\fYbXpvVP.exe |
I installed the fixlist file and rebooted into the "Safe Mode with command prompt" and have a black window open. What should I do now? |
Try to run Combofix like this: Computer mit Combofix entsperren ![]()
|
I have rebooted as you recommended with "Safe Mode with command prompt". It went well and I now have a black screen. What should I do next? Ignore my last entry. I did not see your latest response. I will get back with you soon after trying your latest suggestion. Thanks a million from the bottom of my heart. My system is running again. At the moment everything appears fine except for data files that were laying on my desktop like Excel and PDF files. When I open them, I get a damaged error message for the PDFs and DirtyDecrypt.exe message for the Excel files. Are you familiar with DirtyDecrypt.exe ? Thank you, thank you, thank you again for your help. |
We are not finished yet! Please show your combofix logfile here. |
Refer to the attachment. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 15:16 Uhr. |
Copyright ©2000-2025, Trojaner-Board