![]() |
GVU trojaner Hallo zusammen, Please excuse me for writing in English but I can speak and read it. It is no problem if you respond in German to my problem. A GVU trojan has entered into the laptop I use for my self employment business and I need some help to deleting it. When I scanned the internet for solutions, I came across this forum and noticed another person described exactly my problem and was able to solve it with the help of this forum. See the following link for the exact problem description. http://www.trojaner-board.de/138004-...artet-neu.html I used Farbar to compile the logfile in this .TXT attachment. Can someone help me by changing the logfile as it was done for chrisdee? I use windows vista and would really appreciate any help. Gruß, hloy |
Hi, if you need some translations ... please ask. !! Hinweis an Mitlesende !! Dieses Thema und die Anweisungen sind nur für diesen speziellen Fall gedacht. Sie könnten andere Computer schwer beschädigen. Öffnet bitte euer eigenes Thema. :hallo: Ich werde dir bei deinem Problem helfen. Die Bereinigung funktioniert nur, wenn du dich an die folgenden Regeln hälst: ![]() Regeln für die Bereinigung
![]() Lesestoff: Rootkit-Warnung Dein Computer wurde mit einem besonderen Schädling infiziert, der sich vor herkömmlichen Virenscannern und dem Betriebssystem selbst verstecken kann. Zusätzlich hat so ein Schädling meist auch Backdoor-Funktionalität, reißt also ganz bewußt Löcher durch alle Schutzmaßnahmen, damit er weiteren Schadcode nachladen oder die Daten, die er so sammelt, an die "bösen Jungs" weiterleiten kann. Was heißt das jetzt für dich?
Teile mir also mit, wie du dich entschieden hast. Fix mit FRST Tell how that went and if you can boot. You are still heavy infected. |
Thanks for responding so fast. I was able to transfer and install the fixlist.txt as you described. The desktop screen appeared with all of the icons until the computer was completely finished booting. Then the Bildschirm was blocked again. I have attached the Fixlog.txt. |
Okay you have a very nasty infection. Personally I would recommend to reinstall, but we can still try to unlock. Please check for me if you can boot into safemode with command prompt. |
Sorry I could not respond sooner. It would be an absolute tragedy to reinstall everything new. I REALLY appreciate your offer to still help me unlock. It would be best for me to reinstall everything if I could get my system running again and retrieve a backup. Just before my computer was blocked, I noticed that a software was installed without my consent. It is called "Internet Securtity Pro". I was unable to deinstall or stop it. There are several "Benutzerkonten" on my laptop. I can begin "Safe Mode with prompt" but shortly after booting, the monitor is blocked and I come no further. Is this what you mean? Task Manager has been disabled in all of them. If I use Farbar to boot, then I choose "Computer Reparieren" and come to "Systemwiederherstellungsoptionen" and get a prompt with "Eingabeaufforderung". This is no problem and I can see every drive and all directories. |
Alright - please give me a new FRST logfile from recovery command prompt. It really would be better to reinstall. Fetching your data from the drive before you do so is easy if you use the Kaspersky Rescue Disk to mount your drives and then backup all your data. |
I can send you the new logfile in about an hour since I am currently in the process of trying to copy my files onto an external hard drive. |
yeah better back it all up :) |
Attached is a logfile from today. |
Alright, please try this frst-fix in the recovery mode - after that ... ONLY boot into safemode with command prompt - do nothing else. Report how it went. Code: HKLM\...\Winlogon: [Userinit] C:\Windows\system32\userinit.exe,,C:\Program Files\Sony Ericsson\fYbXpvVP.exe |
I installed the fixlist file and rebooted into the "Safe Mode with command prompt" and have a black window open. What should I do now? |
Try to run Combofix like this: Computer mit Combofix entsperren ![]()
|
I have rebooted as you recommended with "Safe Mode with command prompt". It went well and I now have a black screen. What should I do next? Ignore my last entry. I did not see your latest response. I will get back with you soon after trying your latest suggestion. Thanks a million from the bottom of my heart. My system is running again. At the moment everything appears fine except for data files that were laying on my desktop like Excel and PDF files. When I open them, I get a damaged error message for the PDFs and DirtyDecrypt.exe message for the Excel files. Are you familiar with DirtyDecrypt.exe ? Thank you, thank you, thank you again for your help. |
We are not finished yet! Please show your combofix logfile here. |
Refer to the attachment. |
Okay, we need a double check for this. Schritt 1: (Erinnerung: Antworte mir erst, wenn du alle Schritte abgearbeitet hast!) Scan mit MBAR Downloade dir bitte ![]()
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers Schritt 2: Hinweis: Der Scan kann sehr lange (einige Stunden) dauern! :kaffee: Schritt 3: Scan mit SecurityCheck Downloade Dir bitte ![]()
|
I installed the fixlist and rebooted in "Safe Mode with command prompt". Everything went well. What is the next step? |
I posted them for you ... MBAM, ESET and SecurityCheck |
Sorry, I forgot to go to page 2 where your latest response was posted. I have completed all 3 steps now and attached them as you instructed. |
Here are the bad news ... you HAVE to run ESET again and let it remove the crypted files with Filecoder - there seems to be no way to get them back. Also: Uninstall Java SE and the other Java - install the new Version. Schritt 1: (Erinnerung: Antworte mir erst, wenn du alle Schritte abgearbeitet hast!) Windows Vista Service Pack 2 installieren
Schritt 2: Java Update (Windows XP, Vista, 7) Dein Java ist nicht mehr aktuell. Ältere Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können. Schritt 3: Update: Firefox, Addons und Plugins
Schritt 4: Scan mit SecurityCheck Downloade Dir bitte ![]()
|
I will proceed as you instructed but do you mean that I will not be able to rescue any xls, pdf, doc, etc. files from my C: and D: drives? If so, then my file backup that I did before we began this recovery process is useless. |
It's just the files ESET found as infected. Those are likely to be lost. |
My computer skills are a bit elementary and my questions may be also. Sorry for these questions. I tried to open a pdf file from my backup, on another computer but it would not open. Is the problem or infection in each data file? The ESET scan is currently running so it may be a while before I can give you an update. |
Yes those data files are encrypted by this infektion and useless. There is NO WAY to decrypt them. |
I have attached the newest logfile. How does it look now? |
You should have updated your virusscanner as well and please remove the Java SE Runtime. Otherwise .... Prima! :daumenhoc Damit wären wir fertig. Wir räumen jetzt noch ein wenig auf und dann habe ich am Ende etwas Lesestoff für dich. Schritt 1: Tools deinstallieren Die Reihenfolge ist hier entscheidend.
Schritt 2: Falls du mich jetzt fragen willst, was mit den noch gefundenen Bedrohungen von Eset ist ... lies bitte jetzt nochmal meinen Hinweis zu delfix einige wenige Zeilen weiter oben.Schritt 3: ESET deinstallieren (Optional)
And we are done :) |
Thank you so much for your help. |
Schön, dass wir helfen konnten :abklatsch: Dieses Thema scheint erledigt und wird aus meinen Abos gelöscht. Solltest Du das Thema erneut brauchen schicke mir bitte eine PM. Jeder andere bitte hier klicken und einen eigenen Thread erstellen Falls du noch Lob oder Kritik loswerden möchtest, dann gibt es diesen Bereich hier: Lob, Kritik und Wünsche - Trojaner-Board |
Alle Zeitangaben in WEZ +1. Es ist jetzt 07:57 Uhr. |
Copyright ©2000-2025, Trojaner-Board