![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: BOO TDSS M , Rechner und Internet browser langsamerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
| |
| | #1 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | BOO TDSS M , Rechner und Internet browser langsamer Dann lassen wir auch diese Zeile weg, probier mit diesem Text: Code:
ATTFilter :OTL
[2011.08.28 16:41:42 | 000,000,000 | ---D | M] (Search-Results Toolbar) -- C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\llxo0yp0.default\extensions\toolbar@ask.com
O2 - BHO: (Search-Results Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Programme\Ask.com\GenericAskToolbar.dll (Search-Results)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Search-Results)
O4 - HKCU..\Run: [ICQ] "C:\Program Files\ICQ7.4\ICQ.exe" silent loginmode=4 File not found
O4 - HKCU..\Run: [Lan.FS] C:\Program Files\Lan.FS\Lan-fs.exe ()
O4 - HKCU..\RunOnce: [KeApplet] C:\Users\Admin\AppData\Local\Temp\ke64tnkff.exe ()
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009.06.10 23:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - D:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2007.12.25 15:32:25 | 000,000,000 | ---- | M] () - E:\AUTOEXEC.BAT -- [ NTFS ]
O32 - AutoRun File - [2005.05.11 17:34:10 | 000,045,056 | R--- | M] () - K:\Autorun.exe -- [ CDFS ]
O32 - AutoRun File - [2005.05.11 16:49:08 | 000,000,042 | R--- | M] () - K:\Autorun.inf -- [ CDFS ]
[2011.08.28 16:40:06 | 003,383,272 | ---- | C] (Search-Results) -- C:\Users\Admin\Desktop\ApnToolbarInstaller.exe
[2011.08.28 10:35:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Lan.Fs
[2011.08.28 10:35:33 | 000,000,000 | ---D | C] -- C:\Program Files\Lan.FS
[2011.08.27 18:42:25 | 000,000,000 | ---D | C] -- C:\Users\Admin\AppData\Local\Xara
[2011.09.18 20:40:22 | 000,000,471 | ---- | M] () -- C:\Windows\System32\Datei4
[2011.09.18 20:40:22 | 000,000,471 | ---- | M] () -- C:\Windows\System32\Datei2
[2011.09.18 20:40:22 | 000,000,470 | ---- | M] () -- C:\Windows\System32\Datei3
[2011.09.18 20:40:22 | 000,000,470 | ---- | M] () -- C:\Windows\System32\Datei1
[2011.09.18 20:40:22 | 000,000,469 | ---- | M] () -- C:\Windows\System32\Datei7
[2011.09.18 20:40:22 | 000,000,469 | ---- | M] () -- C:\Windows\System32\Datei5
[2011.09.18 20:40:22 | 000,000,468 | ---- | M] () -- C:\Windows\System32\Datei0
[2011.09.18 20:40:22 | 000,000,467 | ---- | M] () -- C:\Windows\System32\Datei9
[2011.09.18 20:40:22 | 000,000,467 | ---- | M] () -- C:\Windows\System32\Datei8
[2011.09.18 20:40:22 | 000,000,467 | ---- | M] () -- C:\Windows\System32\Datei10
[2011.09.18 20:40:22 | 000,000,465 | ---- | M] () -- C:\Windows\System32\Datei6
[2011.09.18 20:25:42 | 000,007,607 | ---- | M] () -- C:\Users\Admin\AppData\Local\Resmon.ResmonCfg
[2011.09.18 20:24:56 | 000,000,302 | -HS- | M] () -- C:\Windows\tasks\Xilv.job
[2011.09.18 20:24:50 | 000,000,304 | -HS- | M] () -- C:\Windows\tasks\Ygwsnc.job
[2011.09.18 20:24:50 | 000,000,302 | -HS- | M] () -- C:\Windows\tasks\XZRDABX.job
[2011.09.19 18:22:12 | 000,054,016 | ---- | C] () -- C:\Windows\System32\drivers\mkwdob.sys
[2011.09.11 11:14:32 | 000,197,120 | ---- | C] () -- C:\Windows\patchw32.dll
[2011.05.17 20:51:33 | 000,012,724 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2011.09.18 20:24:56 | 000,000,302 | -HS- | M] () -- C:\Windows\Tasks\Xilv.job
[2011.09.18 20:24:50 | 000,000,302 | -HS- | M] () -- C:\Windows\Tasks\XZRDABX.job
[2011.09.18 20:24:50 | 000,000,304 | -HS- | M] () -- C:\Windows\Tasks\Ygwsnc.job
[2011.09.21 16:50:31 | 000,000,000 | ---D | M] -- C:\ProgramData\Application Data\ZA_PreservedFiles
:Files
C:\Program Files\Ask.com
:Commands
[emptytemp]
[resethosts]
__________________ Logfiles bitte immer in CODE-Tags posten |
| | #2 |
![]() | BOO TDSS M , Rechner und Internet browser langsamer All processes killed
__________________========== OTL ========== Folder C:\Users\Admin\AppData\Roaming\mozilla\Firefox\Profiles\llxo0yp0.default\extensions\toolbar@ask.com\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. File C:\Programme\Ask.com\GenericAskToolbar.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ApnUpdater deleted successfully. C:\Programme\Ask.com\Updater\Updater.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\ICQ deleted successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Lan.FS deleted successfully. C:\Programme\Lan.FS\Lan-fs.exe moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce\\KeApplet not found. C:\Users\Admin\AppData\Local\Temp\ke64tnkff.exe moved successfully. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! C:\autoexec.bat moved successfully. D:\autoexec.bat moved successfully. E:\AUTOEXEC.BAT moved successfully. File move failed. K:\Autorun.exe scheduled to be moved on reboot. File move failed. K:\Autorun.inf scheduled to be moved on reboot. C:\Users\Admin\Desktop\ApnToolbarInstaller.exe moved successfully. C:\ProgramData\Lan.Fs\Profile\Sound folder moved successfully. C:\ProgramData\Lan.Fs\Profile\Settings folder moved successfully. C:\ProgramData\Lan.Fs\Profile\Emoticons folder moved successfully. C:\ProgramData\Lan.Fs\Profile folder moved successfully. C:\ProgramData\Lan.Fs folder moved successfully. C:\Program Files\Lan.FS folder moved successfully. C:\Users\Admin\AppData\Local\Xara\MAGIX 3D Maker embeded\Updates\ENG folder moved successfully. C:\Users\Admin\AppData\Local\Xara\MAGIX 3D Maker embeded\Updates\DEU folder moved successfully. C:\Users\Admin\AppData\Local\Xara\MAGIX 3D Maker embeded\Updates folder moved successfully. C:\Users\Admin\AppData\Local\Xara\MAGIX 3D Maker embeded folder moved successfully. C:\Users\Admin\AppData\Local\Xara folder moved successfully. C:\Windows\System32\Datei4 moved successfully. C:\Windows\System32\Datei2 moved successfully. C:\Windows\System32\Datei3 moved successfully. C:\Windows\System32\Datei1 moved successfully. C:\Windows\System32\Datei7 moved successfully. C:\Windows\System32\Datei5 moved successfully. C:\Windows\System32\Datei0 moved successfully. C:\Windows\System32\Datei9 moved successfully. C:\Windows\System32\Datei8 moved successfully. C:\Windows\System32\Datei10 moved successfully. C:\Windows\System32\Datei6 moved successfully. C:\Users\Admin\AppData\Local\Resmon.ResmonCfg moved successfully. C:\Windows\Tasks\Xilv.job moved successfully. C:\Windows\Tasks\Ygwsnc.job moved successfully. C:\Windows\Tasks\XZRDABX.job moved successfully. C:\Windows\System32\drivers\mkwdob.sys moved successfully. C:\Windows\patchw32.dll moved successfully. File move failed. C:\Windows\Tasks\SCHEDLGU.TXT scheduled to be moved on reboot. File C:\Windows\Tasks\Xilv.job not found. File C:\Windows\Tasks\XZRDABX.job not found. File C:\Windows\Tasks\Ygwsnc.job not found. C:\ProgramData\Application Data\ZA_PreservedFiles folder moved successfully. ========== FILES ========== C:\Program Files\Ask.com\Updater folder moved successfully. C:\Program Files\Ask.com\assets\oobe folder moved successfully. C:\Program Files\Ask.com\assets folder moved successfully. C:\Program Files\Ask.com folder moved successfully. ========== COMMANDS ========== [EMPTYTEMP] User: Admin ->Temp folder emptied: 2000942757 bytes ->Temporary Internet Files folder emptied: 365869675 bytes ->Java cache emptied: 1635853 bytes ->FireFox cache emptied: 119609388 bytes ->Opera cache emptied: 2311234 bytes ->Flash cache emptied: 166258 bytes User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 56468 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Public %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 54236695 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 2.427,00 mb HOSTS file reset successfully OTL by OldTimer - Version 3.2.29.1 log created on 09222011_164621 Files\Folders moved on Reboot... File move failed. K:\Autorun.exe scheduled to be moved on reboot. File move failed. K:\Autorun.inf scheduled to be moved on reboot. File move failed. C:\Windows\Tasks\SCHEDLGU.TXT scheduled to be moved on reboot. File move failed. C:\Windows\S421F1A66.tmp scheduled to be moved on reboot. Registry entries deleted on Reboot... |
![]() |
| Themen zu BOO TDSS M , Rechner und Internet browser langsamer |
| anfang, antworten, betriebssystem, booten, brauch, browser, dsl, einstellung, festplatte, folge, geschwindigkeit, handys, internet, internet browser, internetbrowser, langsamer, nicht mehr, nichts, opera, platte, problem, rechner, surfen, tdss, trotz, virus, wirklich |