![]() |
Trojaner Windows Restore Guten Tag zusammen, mir hat vor kurzem der Trojaner Windows Restore den kompletten PC lahmgelegt. Eben mit den typischen Symptomen...Rechner langsamer, alle Dateien und Ordner versteckt/unsichtbar und die ständigen Fehlermeldungen betreffend der Festplatte. Ich habe schon mal in eurem Forum gelesen und bin die Anleitung durchgegangen. Nur bin ich mir nicht ganz sicher ob er wirklich komplett runter ist und ich habe auch Probleme den TDSS Killer auszuführen. Egal ob ich ihn normal oder "Als Administrator ausführen" öffne, das Tool startet nicht. Ich poste folgend mal meine Logfiles...wär super wenn ihr mir noch helfen könntet! :dankeschoen: Markus |
Malware Scan bevor ich mit RKill.exe die Viren entfernt habe. Ich weiß ich hab viele Treffer durch den Refog Key Logger. Den habe ich mal kurze zeit benötigt werde ich aber jetzt wieder deinstallieren. Aber wie man sieht gibt es auch einige Treffer die nichts mit dem KeyLogger zu tun haben. Malwarebytes' Anti-Malware 1.50.1.1100 Malwarebytes : Free anti-malware, anti-virus and spyware removal download Datenbank Version: 6673 Windows 6.0.6002 Service Pack 2 Internet Explorer 7.0.6002.18005 25.05.2011 14:29:13 mbam-log-2011-05-25 (14-29-13).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|H:\|I:\|Q:\|) Durchsuchte Objekte: 267109 Laufzeit: 56 Minute(n), 32 Sekunde(n) Infizierte Speicherprozesse: 1 Infizierte Speichermodule: 2 Infizierte Registrierungsschlüssel: 2 Infizierte Registrierungswerte: 1 Infizierte Dateiobjekte der Registrierung: 3 Infizierte Verzeichnisse: 11 Infizierte Dateien: 109 Infizierte Speicherprozesse: c:\Windows\System32\MPK\MPK.exe (Refog.Keylogger) -> 12 -> Unloaded process successfully. Infizierte Speichermodule: c:\Windows\System32\MPK\Mpk.dll (Refog.Keylogger) -> Delete on reboot. c:\Windows\System32\MPK\sqlite3.dll (Refog.Keylogger) -> Delete on reboot. Infizierte Registrierungsschlüssel: HKEY_CURRENT_USER\SOFTWARE\fcn (Rogue.Residue) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Refog Software (Refog.Keylogger) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\yiMjvSkpKyOa (Trojan.FakeAlert) -> Value: yiMjvSkpKyOa -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Refog.Keylogger) -> Bad: (C:\Windows\system32\MPK\mpk.exe) Good: () -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Userinit (Refog.Keylogger) -> Bad: (c:\windows\system32\userinit.exe,C:\Windows\system32\MPK\mpk.exe) Good: (Userinit.exe) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableTaskMgr (PUM.Hijack.TaskManager) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully. Infizierte Verzeichnisse: c:\programdata\MPK (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\CPDA (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\CPDM (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK (Refog.Keylogger) -> Delete on reboot. c:\Windows\System32\MPK\Help (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang (Refog.Keylogger) -> Quarantined and deleted successfully. Infizierte Dateien: c:\programdata\yimjvskpkyoa.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. c:\programdata\46194424.exe (Trojan.FakeMS) -> Quarantined and deleted successfully. c:\Users\Markus\AppData\Local\Temp\OCS\36\icq ignore checker 1.3 setup.exe (Trojan.Refroso) -> Quarantined and deleted successfully. c:\programdata\MPK\M0000 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\D0000 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40661_3574464352 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40661_3619240046 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40661_3803880671 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40661_3806080787 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40665_8168478356 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40665_8172278588 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40671_5285887153 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40671_5291292824 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\i40671_5293047801 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\1\S0000 (Refog.Keylogger) -> Quarantined and deleted successfully. c:\programdata\MPK\CPDM\cpfm.bin (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\icon.ico (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\icon_1.ico (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\lnkmst.exe (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Mpk.dll (Refog.Keylogger) -> Delete on reboot. c:\Windows\System32\MPK\MPK.exe (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Mpk64.dll (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\MPK64.exe (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\MPKView.exe (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\sqlite3.dll (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\unins000.dat (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\unins000.exe (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\unins000.msg (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\unins001.dat (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\unins001.exe (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\unins001.msg (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\file.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\imhelp.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\need_update_net.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\update.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\English\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\file.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\imhelp.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\need_update_net.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\update.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\German\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\alarms.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\clipboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\computer.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\delivery.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\filters.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\internet.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\invisible.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\keyboard.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\logging.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\log_size.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\password.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\programs.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\screenshot.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\settings_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Help\Spanish\users_node.htm (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\vista_hide.bmp (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Images\xp_hide.bmp (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\brazilian.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\brazilian.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\English.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\French.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\French.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\German.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\German.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Italian.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Italian.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Japanese.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Japanese.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Polish.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Polish.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\portuguese.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\portuguese.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Romanian.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Romanian.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Russian.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Spanish.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Spanish.lng (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Turkish.frc (Refog.Keylogger) -> Quarantined and deleted successfully. c:\Windows\System32\MPK\Lang\Turkish.lng (Refog.Keylogger) -> Quarantined and deleted successfully. |
Malware Scan (aktualisiert) nachdem ich RKill.exe ausgeführt habe: Malwarebytes' Anti-Malware 1.50.1.1100 Malwarebytes : Free anti-malware, anti-virus and spyware removal download Datenbank Version: 6682 Windows 6.0.6002 Service Pack 2 Internet Explorer 7.0.6002.18005 26.05.2011 09:31:18 mbam-log-2011-05-26 (09-31-18).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|F:\|G:\|H:\|I:\|Q:\|) Durchsuchte Objekte: 268466 Laufzeit: 1 Stunde(n), 41 Minute(n), 26 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
OTL Log Datei "Extras.txt"OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 26.05.2011 11:19:28 - Run 1 |
OTL Log Datei "OTL.txt"OTL Logfile: Code: OTL logfile created on: 26.05.2011 11:19:27 - Run 1 |
Alle Zeitangaben in WEZ +1. Es ist jetzt 04:25 Uhr. |
Copyright ©2000-2025, Trojaner-Board