![]() |
Du hast jetzt 4x das OTL-Log aber keine Extras gepostet :confused: |
Hallo Arne, was für extras denn???? hab doch keine ahnung, sorry...lg emmibemmi |
OTL erstellt auch ein anderes Log => Extras.txt Aber gut, das ist nicht so wichtig Trotzdem frage ich mich, was das soll mit den 4x OTL.txt :confused: Ich werd die überflüssigen löschen, ... :rolleyes: |
Hallo Arne, warum das viermal aufgeführt ist weiß ich auch nicht so genau :D sorry...kommt denn jetzt noch mehr auf mich zu oder kann ich davon ausgehen das alles wieder "clean" ist? lg emmibemmi |
So, jetzt steht's nur noch 1x da :pfeiff: Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code: :OTL Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann! |
So Arne ich hoffe ich hab das jetzt richtig gemacht... All processes killed ========== OTL ========== Prefs.js: "ICQ Search" removed from browser.search.defaultenginename Prefs.js: "hxxp://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.3.1&q=" removed from browser.search.defaulturl Prefs.js: "ICQ Search" removed from browser.search.selectedEngine Prefs.js: engine@conduit.com:3.3.3.2 removed from extensions.enabledItems Prefs.js: "hxxp://search.sweetim.com/search.asp?src=2&q=" removed from keyword.URL Prefs.js: "hxxp://search.sweetim.com/search.asp?src=2&q=" removed from sweetim.toolbar.previous.keyword.URL C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\skin folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\tr folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\sk folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\ru folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\it folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\he folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\fr folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\es folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\en-US folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\de folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\cs folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale\bg folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\locale folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content\img folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome\content folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}\chrome folder moved successfully. C:\Users\shortytine\AppData\Roaming\mozilla\Firefox\Profiles\89w409kx.default\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C} folder moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-1.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-10.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-11.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-12.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-13.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-14.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-15.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-2.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-3.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-4.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-5.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-6.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-7.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-8.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin-9.xml moved successfully. C:\Users\shortytine\AppData\Roaming\Mozilla\Firefox\Profiles\89w409kx.default\searchplugins\icqplugin.xml moved successfully. C:\Programme\Mozilla Firefox\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd} folder moved successfully. C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\search_engine folder moved successfully. C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\META-INF folder moved successfully. C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults\preferences folder moved successfully. C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\defaults folder moved successfully. C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\components folder moved successfully. C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\chrome folder moved successfully. C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07} folder moved successfully. C:\Programme\Mozilla Firefox\extensions folder moved successfully. Folder C:\Programme\Mozilla Firefox\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27}\ not found. Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found. Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found. Registry value HKEY_USERS\S-1-5-21-660773486-670838790-555106487-1000\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{DFEFCDEE-CF1A-4FC8-88AD-48514E463B27}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3381b621-db2e-11dd-935e-00216bb399de}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3381b621-db2e-11dd-935e-00216bb399de}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{3381b621-db2e-11dd-935e-00216bb399de}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3381b621-db2e-11dd-935e-00216bb399de}\ not found. File D:\setup.exe AUTORUN=1 not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c4797536-bfaf-11df-8c67-00235a01be7c}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c4797536-bfaf-11df-8c67-00235a01be7c}\ not found. File H:\PMBP_Win.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f92f2c28-6d30-11df-982b-00235a01be7c}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f92f2c28-6d30-11df-982b-00235a01be7c}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{f92f2c28-6d30-11df-982b-00235a01be7c}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{f92f2c28-6d30-11df-982b-00235a01be7c}\ not found. File D:\VTP_Manager.exe not found. ========== FILES ========== C:\Users\shortytine\AppData\Local\{4c75a3fd-734c-0ebb-1676-980fca40e6aa}\L folder moved successfully. C:\Windows\Installer\{4c75a3fd-734c-0ebb-1676-980fca40e6aa}\L folder moved successfully. C:\Users\shortytine\AppData\Local\{4c75a3fd-734c-0ebb-1676-980fca40e6aa}\U folder moved successfully. C:\Windows\Installer\{4c75a3fd-734c-0ebb-1676-980fca40e6aa}\U folder moved successfully. File\Folder C:\Users\shortytine\AppData\Local\{4c75a3fd-734c-0ebb-1676-980fca40e6aa}\n not found. File\Folder C:\Windows\Installer\{4c75a3fd-734c-0ebb-1676-980fca40e6aa}\n not found. C:\Users\shortytine\AppData\Local\{4c75a3fd-734c-0ebb-1676-980fca40e6aa}\@ moved successfully. C:\Windows\Installer\{4c75a3fd-734c-0ebb-1676-980fca40e6aa}\@ moved successfully. C:\Users\shortytine\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Live Security Platinum folder moved successfully. C:\ProgramData\036DFF98FF4F56417C1067A12F3B707C folder moved successfully. C:\Users\shortytine\AppData\Roaming\Ynoh folder moved successfully. C:\Users\shortytine\AppData\Roaming\Puluom folder moved successfully. C:\Users\shortytine\AppData\Roaming\Elagar folder moved successfully. C:\Users\shortytine\AppData\Roaming\xmldm folder moved successfully. C:\Users\shortytine\AppData\Roaming\kock folder moved successfully. File\Folder C:\Users\shortytine\AppData\Roaming\Elagar not found. C:\Users\shortytine\AppData\Roaming\Gutscheinmieze folder moved successfully. C:\Users\shortytine\Downloads\Programme\SweetImSetup (2).exe moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 56586 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Gast ->Temp folder emptied: 138787 bytes ->Temporary Internet Files folder emptied: 985047 bytes ->FireFox cache emptied: 25924433 bytes ->Flash cache emptied: 57237 bytes User: Public User: shortytine ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 4054752 bytes ->Java cache emptied: 51948933 bytes ->FireFox cache emptied: 577439295 bytes ->Google Chrome cache emptied: 0 bytes ->Flash cache emptied: 2853475 bytes %systemdrive% .tmp files removed: 14648 bytes %systemroot% .tmp files removed: 1460478 bytes %systemroot%\System32 .tmp files removed: 2580 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 258113 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 634,00 mb [EMPTYFLASH] User: All Users User: Default ->Flash cache emptied: 0 bytes User: Default User ->Flash cache emptied: 0 bytes User: Gast ->Flash cache emptied: 0 bytes User: Public User: shortytine ->Flash cache emptied: 0 bytes Total Flash Files Cleaned = 0,00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.56.0 log created on 08082012_212236 Files\Folders moved on Reboot... PendingFileRenameOperations files... Registry entries deleted on Reboot... lg emmibemmi |
Die Log sbitte in CODE-Tags posten!!! Bitte nun (im normalen Windows-Modus) dieses Tool von Kaspersky (TDSS-Killer) ausführen und das Log posten Anleitung und Downloadlink hier => http://www.trojaner-board.de/82358-t...entfernen.html Hinweis: Bitte den Virenscanner abstellen bevor du den TDSS-Killer ausführst, denn v.a. Avira meldet im TDSS-Tool oft einen Fehalalrm! Das Tool so einstellen wie unten im Bild angegeben - klick auf change parameters und setze die Haken wie im folgenden Screenshot abgebildet, Dann auf Start Scan klicken und wenn es durch ist auf den Button Report klicken um das Log anzuzeigen. Dieses bitte komplett posten. Wenn du das Log nicht findest oder den Inhalt kopieren und in dein Posting übertragen kannst, dann schau bitte direkt auf deiner Windows-Systempartition (meistens Laufwerk C:) nach, da speichert der TDSS-Killer seine Logs. Hinweis: Bitte nichts voreilig mit dem TDSS-Killer löschen! Falls Objekte vom TDSS-Killer bemängelt werden, alle mit der Aktion "skip" behandeln und hier nur das Log posten! http://saved.im/mtkwmtcxexhp/setting...8_16-25-18.jpg |
Code: 10:17:57.0069 2140 TDSS rootkit removing tool 2.7.48.0 Jul 24 2012 13:16:32 |
Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat! Solltest du nach der Ausführung von Combofix Probleme beim Starten von Anwendungen haben und Meldungen erhalten wie Zitat:
|
Alle Zeitangaben in WEZ +1. Es ist jetzt 14:38 Uhr. |
Copyright ©2000-2025, Trojaner-Board