![]() |
Polizeitrojaer eingefangen Hallo, hab mir gestern leider einen Polizeitrojaer eingefangen! Hab jetzt eine Systemwiederherstellung gemacht und es funktioniert auch alles!!! Ist der Virus jetzt weg??? Hab jetzt den Computer mit Maleware gescannt: Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Datenbank Version: v2013.05.05.03 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16540 Acer :: MEDIA [Administrator] 05.05.2013 12:52:31 mbam-log-2013-05-05 (12-52-31).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|) Aktivierte Suchlaufeinstellungen: Speicher | Autostart | Registrierung | Dateisystem | Heuristiks/Extra | HeuristiKs/Shuriken | PUP | PUM Deaktivierte Suchlaufeinstellungen: P2P Durchsuchte Objekte: 478362 Laufzeit: 56 Minute(n), 12 Sekunde(n) Infizierte Speicherprozesse: 0 (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: 0 (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: 0 (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: 0 (Keine bösartigen Objekte gefunden) Infizierte Dateien: 0 (Keine bösartigen Objekte gefunden) (Ende) Ist der Virus jetzt entfernt??? Danke sehr!!! mfg |
:hallo: Systemscan mit OTL (bebilderte Anleitung) Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop ( falls noch nicht vorhanden)- Doppelklick auf die OTL.exe
|
Hallo!!!! Hab jetzt mit OTL gescannt:OTL Logfile: Code: OTL logfile created on: 05.05.2013 17:11:41 - Run 1 Wie gehts jetzt weiter???? Danke euch, mfg Patrick Sorry, hab den zweiten Logfile vergessen:OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 05.05.2013 17:11:41 - Run 1 Danke im Voraus!!! mfg |
Die Bereinigung besteht aus mehreren Schritten, die ausgefuehrt werden muessen. Diese Nacheinander abarbeiten und die 3 Logs, die dabei erstellt werden bitte in deine naechste Antwort einfuegen. Sollte der OTL-FIX nicht richig durchgelaufen sein. Fahre nicht fort, sondern melde dies bitte. 1. Schritt Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code: :OTL
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! 2. Schritt Downloade dir bitte ![]()
Starte keine andere Datei in diesem Ordner ohne Anweisung eines Helfers danach: 3. Schritt Downloade Dir bitte ![]()
|
Schritt 1: Fixen mit OTL All processes killed ========== OTL ========== C:\ProgramData\fr30.pad moved successfully. File move failed. C:\ProgramData\DP45977C.lfl scheduled to be moved on reboot. ========== FILES ========== File\Folder C:\ProgramData\*.exe not found. File\Folder C:\ProgramData\*.dll not found. File\Folder C:\ProgramData\*.tmp not found. C:\ProgramData\Temp\{EBA33CAD-E071-48d5-A168-FBA4EEB42E93} folder moved successfully. C:\ProgramData\Temp\{E3739848-5329-48E3-8D28-5BBD6E8BE384} folder moved successfully. C:\ProgramData\Temp\{35DA427D-BB23-49B8-9AFD-CFFCFE3B708D} folder moved successfully. C:\ProgramData\Temp folder moved successfully. File\Folder C:\Users\Acer\*.tmp not found. File\Folder C:\Users\Acer\AppData\*.dll not found. File\Folder C:\Users\Acer\AppData\*.exe not found. C:\Users\Acer\AppData\Local\Temp\COMAP.EXE moved successfully. C:\Users\Acer\AppData\Local\Temp\fp_pl_pfs_installer.exe moved successfully. C:\Users\Acer\AppData\Local\Temp\jre-7u10-windows-i586-iftw.exe moved successfully. C:\Users\Acer\AppData\Local\Temp\jre-7u11-windows-i586-iftw.exe moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\tmp folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\muffin folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\host folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\9 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\8 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\7 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\63 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\62 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\61 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\60 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\6 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\59 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\57 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\56 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\55 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\54 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\53 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\52 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\51 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\5 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\49 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\48 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\47 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\45 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\44 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\43 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\42 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\41 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\40 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\4 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\39 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\38 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\37 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\36 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\35 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\34 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\33 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\32 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\31 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\30 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\3 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\29 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\28 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\27 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\26 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\25 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\24 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\23 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\22 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\21 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\20 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\2 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\19 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\18 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\17 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\16 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\15 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\14 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\13 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\12 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\11 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\10 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\1 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\0 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0 folder moved successfully. C:\Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache folder moved successfully. < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Aufl”sungscache wurde geleert. C:\Users\Acer\Desktop\cmd.bat deleted successfully. C:\Users\Acer\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Acer ->Temp folder emptied: 1489969813 bytes ->Temporary Internet Files folder emptied: 651205705 bytes ->FireFox cache emptied: 27678261 bytes ->Flash cache emptied: 41104 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Public User: UpdatusUser ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 141568614 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 128 bytes RecycleBin emptied: 100742405 bytes Total Files Cleaned = 2*300,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 05052013_201534 Files\Folders moved on Reboot... C:\ProgramData\DP45977C.lfl moved successfully. C:\Users\Acer\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully. File move failed. C:\Windows\temp\lm\Acer\aipflib.log scheduled to be moved on reboot. File move failed. C:\Windows\temp\lm\Acer\LMutilps32.log scheduled to be moved on reboot. File move failed. C:\Windows\temp\lm\dsiwmis.log scheduled to be moved on reboot. PendingFileRenameOperations files... Registry entries deleted on Reboot... Schritt 2: Malwarebytes Anti-Rootkit: Malwarebytes Anti-Rootkit BETA 1.05.0.1001 Malwarebytes : Free anti-malware download Database version: v2013.05.05.05 Windows 8 x64 NTFS Internet Explorer 10.0.9200.16540 Acer :: MEDIA [administrator] 05.05.2013 20:40:12 mbar-log-2013-05-05 (20-40-12).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM | P2P Scan options disabled: Objects scanned: 7686 Time elapsed: 12 minute(s), 9 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end) Schritt 3: Adwcleaner:AdwCleaner Logfile: Code: # AdwCleaner v2.300 - Datei am 05/05/2013 um 20:44:48 erstellt Danke schon mal!!! mfg |
Sehr gut! :daumenhoc Downloade dir bitte ![]()
Wichtig: Drücke keinesfalls einen der Fix Buttons ohne Anweisung Hinweis: Sollte der Scan Button ausgeblendet sein, schließe das Tool und starte es erneut. Sollte der Scan abbrechen und das Programm abstürzen, dann teile mir das mit und wähle unter AV Scan die Einstellung (none). danach: ESET Online Scanner
danach: Downloade Dir bitte ![]()
|
sodala, hier der Logfile von aswMBR: aswMBR version 0.9.9.1771 Copyright(c) 2011 AVAST Software Run date: 2013-05-05 21:18:37 ----------------------------- 21:18:37.496 OS Version: Windows x64 6.2.9200 21:18:37.496 Number of processors: 4 586 0x3A09 21:18:37.497 ComputerName: MEDIA UserName: Acer 21:18:37.674 Initialze error 1 21:21:58.194 AVAST engine defs: 13050500 21:22:33.440 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000038 21:22:33.440 Disk 0 Vendor: TOSHIBA_MQ01ABD100 AX003J Size: 953869MB BusType: 11 21:22:33.456 Disk 0 MBR read successfully 21:22:33.456 Disk 0 MBR scan 21:22:33.456 Disk 0 unknown MBR code 21:22:33.456 Disk 0 Partition 1 00 EE GPT 2097151 MB offset 1 21:22:33.471 Disk 0 scanning C:\Windows\system32\drivers 21:22:33.471 Service scanning 21:22:34.002 Modules scanning 21:22:34.002 Disk 0 trace - called modules: 21:22:34.002 ntoskrnl.exe CLASSPNP.SYS disk.sys storport.sys hal.dll iaStorA.sys 21:22:34.018 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa80099e3060] 21:22:34.018 3 CLASSPNP.SYS[fffff88001d11fea] -> nt!IofCallDriver -> \Device\00000038[0xfffffa800810e7f0] 21:22:34.033 AVAST engine scan C:\Windows 21:22:34.033 AVAST engine scan C:\Windows\system32 21:22:34.049 AVAST engine scan C:\Windows\system32\drivers 21:22:34.049 AVAST engine scan C:\Users\Acer 21:22:34.049 AVAST engine scan C:\ProgramData 21:22:34.065 Scan finished successfully 21:23:09.448 Disk 0 MBR has been saved successfully to "C:\Users\Acer\Desktop\MBR.dat" 21:23:09.448 The log file has been saved successfully to "C:\Users\Acer\Desktop\aswMBR.txt" |
ESET und Securitycheck? |
ESET Online Scanner: ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=0d4c025ce7260142a505b16e425d90e6 # engine=13759 # end=finished # remove_checked=false # archives_checked=true # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-05-05 09:15:29 # local_time=2013-05-05 11:15:29 (+0100, Mitteleuropäische Sommerzeit) # country="Austria" # lang=1033 # osver=6.2.9200 NT # compatibility_mode=5893 16776573 100 94 37416 8377628 0 0 # scanned=244092 # found=3 # cleaned=0 # scan_time=6415 sh=21A3F8B9EF43C10255BF3C69BA4674B72EB7D609 ft=0 fh=0000000000000000 vn="Java/Agent.FI trojan" ac=I fn="C:\_OTL\MovedFiles\05052013_201534\C_Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\46\778b056e-142d9d23" sh=7295BCEEAEF79F82C5C69C255D0473E45CEC38AA ft=0 fh=0000000000000000 vn="a variant of Java/Exploit.CVE-2013-0422.CD trojan" ac=I fn="C:\_OTL\MovedFiles\05052013_201534\C_Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\2ab406b2-3a62e16a" sh=B1412234CAAA952CC9787536C264D53F06FE4D43 ft=0 fh=0000000000000000 vn="Java/Exploit.CVE-2013-0422.CD trojan" ac=I fn="C:\_OTL\MovedFiles\05052013_201534\C_Users\Acer\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\58\105a2dba-3e1ea91b" Security Check: Results of screen317's Security Check version 0.99.63 x64 (UAC is enabled) Internet Explorer 9 ``````````````Antivirus/Firewall Check:`````````````` Windows Defender WMI entry may not exist for antivirus; attempting automatic update. `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 13 Java version out of Date! Adobe Flash Player 11.6.602.180 Adobe Reader XI Mozilla Firefox (20.0.1) ````````Process Check: objlist.exe by Laurent```````` Windows Defender MSMpEng.exe Windows Defender MsMpEng.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C: % ````````````````````End of Log`````````````````````` Wie gehts dann weiter?? Danke, mfg Patrick |
Java aktualisieren Dein Java ist nicht mehr aktuell. Älter Versionen enthalten Sicherheitslücken, die von Malware missbraucht werden können.
Dann so einstellen: http://www.trojaner-board.de/105213-...tellungen.html Danach poste (kopieren und einfuegen) mir, was du hier angezeigt bekommst: PluginCheck Java deaktivieren Aufgrund derezeitigen Sicherheitsluecke: http://www.trojaner-board.de/122961-...ktivieren.html Danach poste mir (kopieren und einfuegen), was du hier angezeigt bekommst: PluginCheck |
PluginCheck Der PluginCheck hilft die größten Sicherheitslücken beim Surfen im Internet zu schliessen. Überprüft wird: Browser, Flash, Java und Adobe Reader Version. Firefox 20.0 ist aktuell Flash (11,6,602,180) ist aktuell. Java (1,7,0,21) ist aktuell. Adobe Reader 11,0,1,36 ist aktuell. Zurück Tools: StartSeite PluginCheck Secunia Online Scan Weiterführendes: Java Updaten und Einstellen JAVA aktiviert: Secunia Personal Software Inspector (PSI) Family: TR/Agent |
Sehr gut! :daumenhoc damit bist Du sauber und entlassen! :) adwCleaner entfernen
Tool-Bereinigung Die Reihenfolge ist hier entscheidend.
Zurücksetzen der Sicherheitszonen Lasse die Sicherheitszonen wieder zurücksetzen, da diese manipuliert wurden um den Browser für weitere Angriffe zu öffnen. Gehe dabei so vor: http://www.trojaner-board.de/111805-...ecksetzen.html Systemwiederherstellungen leeren Damit der Rechner nicht mit einer infizierten Systemwiederherstellung erneut infiziert werden kann, muessen wir diese leeren. Dazu schalten wir sie einmal aus und dann wieder ein: Systemwiederherstellung deaktivieren Tutorial fuer Windows XP, Windows Vista, Windows 7 Danach wieder aktivieren. Lektuere zum abarbeiten: http://www.trojaner-board.de/90880-d...tallation.html http://www.trojaner-board.de/105213-...tellungen.html PluginCheck http://www.trojaner-board.de/96344-a...-rechners.html Secunia Online Software Inspector http://www.trojaner-board.de/71715-k...iendungen.html http://www.trojaner-board.de/83238-a...sschalten.html http://www.trojaner-board.de/109844-...ren-seite.html PC wird immer langsamer - was tun? |
JAVA deaktiviert: PluginCheck Der PluginCheck hilft die größten Sicherheitslücken beim Surfen im Internet zu schliessen. Überprüft wird: Browser, Flash, Java und Adobe Reader Version. Firefox 20.0 ist aktuell Flash (11,6,602,180) ist aktuell. Java ist Installiert aber nicht aktiviert. Adobe Reader 11,0,1,36 ist aktuell. Zurück Tools: StartSeite PluginCheck Secunia Online Scan Weiterführendes: Java Updaten und Einstellen Secunia Personal Software Inspector (PSI) Family: TR/Agent He voll lässig!!!! 1000 Danke!!! Ihr seids die besten!!!! mfg Patrick |
|
Alle Zeitangaben in WEZ +1. Es ist jetzt 19:24 Uhr. |
Copyright ©2000-2025, Trojaner-Board