![]() |
|
Log-Analyse und Auswertung: Rootkit BOO/TDss.D Bekomme ich nicht mehr weg HELPWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
|
![]() | #1 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Rootkit BOO/TDss.D Bekomme ich nicht mehr weg HELP Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL PRC - [2011.08.09 19:00:00 | 000,414,720 | -H-- | M] () -- C:\ProgramData\P1kAlMiG2Kb7Fz.exe PRC - [2011.08.09 15:59:29 | 000,458,240 | -H-- | M] () -- C:\ProgramData\QcQriuLdiTSqim.exe IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://lenovo.msn.com IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = hxxp://www.lenovo.com/welcome/thinkpad [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = hxxp://www.lenovo.com/welcome/thinkpad [binary data] IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://search.conduit.com?SearchSource=10&ctid=CT2269050 FF - prefs.js..browser.search.defaultthis.engineName: "Search" FF - prefs.js..browser.search.defaulturl: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}" O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found. O4 - HKLM..\Run: [] File not found O4 - HKCU..\Run: [QcQriuLdiTSqim] C:\ProgramData\QcQriuLdiTSqim.exe () O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | -H-- | M] () - C:\autoexec.bat -- [ NTFS ] O32 - AutoRun File - [2008.06.10 18:32:46 | 000,000,049 | -HS- | M] () - Q:\AUTORUN.INF -- [ NTFS ] O33 - MountPoints2\{1c1a95a5-6bf3-11e0-ba19-0026c63983e8}\Shell - "" = AutoRun O33 - MountPoints2\{1c1a95a5-6bf3-11e0-ba19-0026c63983e8}\Shell\AutoRun\command - "" = D:\.\Autorun.exe AUTORUN=1 O33 - MountPoints2\{202b0aa5-b76e-11e0-8869-0c607688b5f7}\Shell - "" = AutoRun O33 - MountPoints2\{202b0aa5-b76e-11e0-8869-0c607688b5f7}\Shell\AutoRun\command - "" = D:\Autorun.exe O33 - MountPoints2\{202b0abb-b76e-11e0-8869-0c607688b5f7}\Shell - "" = AutoRun O33 - MountPoints2\{202b0abb-b76e-11e0-8869-0c607688b5f7}\Shell\AutoRun\command - "" = D:\Autorun.exe O33 - MountPoints2\{55a5e322-d8d8-11de-83d9-806e6f6e6963}\Shell - "" = AutoRun O33 - MountPoints2\{55a5e322-d8d8-11de-83d9-806e6f6e6963}\Shell\AutoRun\command - "" = Q:\LenovoQDrive.exe -- [2009.08.10 23:01:24 | 000,267,576 | -HS- | M] (Lenovo Group Limited) O33 - MountPoints2\{65e34b15-b778-11e0-9589-0c607688b5f7}\Shell - "" = AutoRun O33 - MountPoints2\{65e34b15-b778-11e0-9589-0c607688b5f7}\Shell\AutoRun\command - "" = D:\Autorun.exe O33 - MountPoints2\{84155ecb-9f3b-11df-99e7-0026c63983e8}\Shell - "" = AutoRun O33 - MountPoints2\{84155ecb-9f3b-11df-99e7-0026c63983e8}\Shell\AutoRun\command - "" = "D:\WD SmartWare.exe" autoplay=true O33 - MountPoints2\{da4316f0-f3ee-11df-baf2-ba2d6f2592b6}\Shell - "" = AutoRun O33 - MountPoints2\{da4316f0-f3ee-11df-baf2-ba2d6f2592b6}\Shell\AutoRun\command - "" = D:\LaunchU3.exe -a O33 - MountPoints2\{ea16cf15-b6a1-11e0-b31c-0c607688b5f7}\Shell - "" = AutoRun O33 - MountPoints2\{ea16cf15-b6a1-11e0-b31c-0c607688b5f7}\Shell\AutoRun\command - "" = D:\AutoRun.exe O33 - MountPoints2\{ea16cf24-b6a1-11e0-b31c-0c607688b5f7}\Shell - "" = AutoRun O33 - MountPoints2\{ea16cf24-b6a1-11e0-b31c-0c607688b5f7}\Shell\AutoRun\command - "" = D:\AutoRun.exe O33 - MountPoints2\{ee7aff8b-b899-11e0-9e14-001e101f8ed0}\Shell - "" = AutoRun O33 - MountPoints2\{ee7aff8b-b899-11e0-9e14-001e101f8ed0}\Shell\AutoRun\command - "" = D:\Autorun.exe O33 - MountPoints2\D\Shell - "" = AutoRun O33 - MountPoints2\D\Shell\AutoRun\command - "" = D:\Autorun.exe [2011.08.09 19:00:07 | 000,000,000 | -H-D | C] -- C:\Users\HaukeS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Repair [2011.08.09 19:02:20 | 000,000,392 | -H-- | M] () -- C:\ProgramData\P1kAlMiG2Kb7Fz [2011.08.09 19:00:11 | 000,000,232 | -H-- | M] () -- C:\ProgramData\~P1kAlMiG2Kb7Fz [2011.08.09 19:00:11 | 000,000,168 | -H-- | M] () -- C:\ProgramData\~P1kAlMiG2Kb7Fzr [2011.08.09 19:00:00 | 000,414,720 | -H-- | M] () -- C:\ProgramData\P1kAlMiG2Kb7Fz.exe [2011.08.09 18:54:22 | 000,001,024 | -H-- | M] () -- C:\Users\HaukeS\.rnd [2011.08.09 18:54:22 | 000,001,024 | -H-- | M] () -- C:\.rnd [2011.08.04 17:43:13 | 000,051,222 | -H-- | M] () -- C:\Users\HaukeS\AppData\Roaming\room_v3.dat [2011.08.09 15:59:36 | 000,458,240 | -H-- | C] () -- C:\ProgramData\QcQriuLdiTSqim.exe [2011.08.09 07:59:53 | 000,001,024 | -H-- | C] () -- C:\Users\HaukeS\.rnd [2011.07.29 17:39:14 | 000,051,222 | -H-- | C] () -- C:\Users\HaukeS\AppData\Roaming\room_v3.dat [2010.01.04 15:40:24 | 000,000,000 | -HSD | M] -- C:\$Recycle.Bin [2009.11.24 11:32:01 | 000,000,000 | -H-D | M] -- C:\AuthLog :Files C:\Windows\tasks\*.job :Commands [emptytemp] [purity] [resethosts] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #2 |
![]() | ![]() Rootkit BOO/TDss.D Bekomme ich nicht mehr weg HELP Hier Der OTL Log... hab leider vergessen firefox auszumachen hoffe, dass ist nicht ganz so schlimm.
__________________All processes killed ========== OTL ========== No active process named P1kAlMiG2Kb7Fz.exe was found! No active process named QcQriuLdiTSqim.exe was found! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Secondary_Page_URL| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Secondary Start Pages| /E : value set successfully! HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Prefs.js: "Search" removed from browser.search.defaultthis.engineName Prefs.js: "hxxp://search.conduit.com/ResultsExt.aspx?ctid=CT2269050&SearchSource=3&q={searchTerms}" removed from browser.search.defaulturl Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\QcQriuLdiTSqim not found. File C:\ProgramData\QcQriuLdiTSqim.exe not found. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. Q:\AUTORUN.INF moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1c1a95a5-6bf3-11e0-ba19-0026c63983e8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1c1a95a5-6bf3-11e0-ba19-0026c63983e8}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1c1a95a5-6bf3-11e0-ba19-0026c63983e8}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1c1a95a5-6bf3-11e0-ba19-0026c63983e8}\ not found. File D:\.\Autorun.exe AUTORUN=1 not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{202b0aa5-b76e-11e0-8869-0c607688b5f7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{202b0aa5-b76e-11e0-8869-0c607688b5f7}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{202b0aa5-b76e-11e0-8869-0c607688b5f7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{202b0aa5-b76e-11e0-8869-0c607688b5f7}\ not found. File D:\Autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{202b0abb-b76e-11e0-8869-0c607688b5f7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{202b0abb-b76e-11e0-8869-0c607688b5f7}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{202b0abb-b76e-11e0-8869-0c607688b5f7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{202b0abb-b76e-11e0-8869-0c607688b5f7}\ not found. File D:\Autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55a5e322-d8d8-11de-83d9-806e6f6e6963}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{55a5e322-d8d8-11de-83d9-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{55a5e322-d8d8-11de-83d9-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{55a5e322-d8d8-11de-83d9-806e6f6e6963}\ not found. Q:\LenovoQDrive.exe moved successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{65e34b15-b778-11e0-9589-0c607688b5f7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{65e34b15-b778-11e0-9589-0c607688b5f7}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{65e34b15-b778-11e0-9589-0c607688b5f7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{65e34b15-b778-11e0-9589-0c607688b5f7}\ not found. File D:\Autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{84155ecb-9f3b-11df-99e7-0026c63983e8}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84155ecb-9f3b-11df-99e7-0026c63983e8}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{84155ecb-9f3b-11df-99e7-0026c63983e8}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{84155ecb-9f3b-11df-99e7-0026c63983e8}\ not found. File "D:\WD SmartWare.exe" autoplay=true not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{da4316f0-f3ee-11df-baf2-ba2d6f2592b6}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{da4316f0-f3ee-11df-baf2-ba2d6f2592b6}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{da4316f0-f3ee-11df-baf2-ba2d6f2592b6}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{da4316f0-f3ee-11df-baf2-ba2d6f2592b6}\ not found. File D:\LaunchU3.exe -a not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ea16cf15-b6a1-11e0-b31c-0c607688b5f7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ea16cf15-b6a1-11e0-b31c-0c607688b5f7}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ea16cf15-b6a1-11e0-b31c-0c607688b5f7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ea16cf15-b6a1-11e0-b31c-0c607688b5f7}\ not found. File D:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ea16cf24-b6a1-11e0-b31c-0c607688b5f7}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ea16cf24-b6a1-11e0-b31c-0c607688b5f7}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ea16cf24-b6a1-11e0-b31c-0c607688b5f7}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ea16cf24-b6a1-11e0-b31c-0c607688b5f7}\ not found. File D:\AutoRun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ee7aff8b-b899-11e0-9e14-001e101f8ed0}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ee7aff8b-b899-11e0-9e14-001e101f8ed0}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{ee7aff8b-b899-11e0-9e14-001e101f8ed0}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ee7aff8b-b899-11e0-9e14-001e101f8ed0}\ not found. File D:\Autorun.exe not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ deleted successfully. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\D\ not found. File D:\Autorun.exe not found. C:\Users\HaukeS\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\System Repair folder moved successfully. C:\ProgramData\P1kAlMiG2Kb7Fz moved successfully. C:\ProgramData\~P1kAlMiG2Kb7Fz moved successfully. C:\ProgramData\~P1kAlMiG2Kb7Fzr moved successfully. File C:\ProgramData\P1kAlMiG2Kb7Fz.exe not found. C:\Users\HaukeS\.rnd moved successfully. C:\.rnd moved successfully. C:\Users\HaukeS\AppData\Roaming\room_v3.dat moved successfully. File C:\ProgramData\QcQriuLdiTSqim.exe not found. File C:\Users\HaukeS\.rnd not found. File C:\Users\HaukeS\AppData\Roaming\room_v3.dat not found. C:\$Recycle.Bin\S-1-5-21-310913434-2240896161-1214113473-500 folder moved successfully. C:\$Recycle.Bin\S-1-5-21-310913434-2240896161-1214113473-1004 folder moved successfully. C:\$Recycle.Bin\S-1-5-20 folder moved successfully. C:\$Recycle.Bin folder moved successfully. C:\AuthLog folder moved successfully. ========== FILES ========== C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job moved successfully. C:\Windows\tasks\SystemToolsDailyTest.job moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: HaukeS ->Temp folder emptied: 20988880 bytes ->Temporary Internet Files folder emptied: 21965688 bytes ->Java cache emptied: 49626774 bytes ->FireFox cache emptied: 52281489 bytes ->Flash cache emptied: 2836455 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 73949887 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 211,00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.26.1 log created on 08122011_213011 Files\Folders moved on Reboot... File\Folder C:\Users\HaukeS\AppData\Local\Temp\~DF4410AAF057128CA4.TMP not found! File\Folder C:\Users\HaukeS\AppData\Local\Temp\~DF4904ED2D146BB1DD.TMP not found! File\Folder C:\Users\HaukeS\AppData\Local\Temp\~DF6EF6701886F3E827.TMP not found! C:\Users\HaukeS\AppData\Local\Temp\~DF89B3EAF1A2AE2528.TMP moved successfully. C:\Users\HaukeS\AppData\Local\Temp\~DFAF4C17649FBB8196.TMP moved successfully. File\Folder C:\Users\HaukeS\AppData\Local\Temp\~DFBFF70E30D299A389.TMP not found! File\Folder C:\Users\HaukeS\AppData\Local\Temp\~DFDF4DCF4FC4B061D8.TMP not found! File\Folder C:\Users\HaukeS\AppData\Local\Temp\~DFED1B79B66CE3F107.TMP not found! C:\Users\HaukeS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PXNPD9HL\signin[1].htm moved successfully. C:\Users\HaukeS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\HCUM0W03\link[5].htm moved successfully. C:\Users\HaukeS\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\4790486V\ac3[3].htm moved successfully. Registry entries deleted on Reboot... |
![]() |
Themen zu Rootkit BOO/TDss.D Bekomme ich nicht mehr weg HELP |
5 minuten, antivir, bho, bonjour, boo/tdss.d, c:\windows\system32\rundll32.exe, converter, disabletaskmgr, excel.exe, firefox, help, kaspersky, keine dateien, langsam, lenovo, logfile, malware, malware gefunden, mozilla, mp3, plug-in, problem, programm, registry, rootkit, scan, security, sehr langsam, software, start menu, starten, system, taskmanager, temporär, trojaner, trojaner board, version=1.0, webcheck, windows |