![]() |
|
Plagegeister aller Art und deren Bekämpfung: Suspicious.Cloud.7.EPWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Suspicious.Cloud.7.EP Also irgendwie hat das nicht geklappt. ![]() Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): Code:
ATTFilter :reg [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system] "DisableClock"=- "DisableTaskMgr"=- [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "LWA"=- "LWB"=- "LWC"=- "LWD"=- "LWE"=- "LWF"=- "LWG"=- "LWH"=- "LWI"=- "LWJ"=- "LWK"=- "LWL"=- "LWM"=- "LWN"=- "LWO"=- "LWP"=- "LWQ"=- "LWR"=- "LWS"=- "LWT"=- "LWU"=- "LWV"=- "LWW"=- "LWX"=- :Commands [purity] [emptytemp] [emptyflash] [resethosts] Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt. Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann!
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
![]() | #2 |
![]() ![]() ![]() | ![]() Suspicious.Cloud.7.EP ok bin fertig , hier das Log:
__________________Code:
ATTFilter All processes killed ========== REGISTRY ========== Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system\\DisableClock deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\system\\DisableTaskMgr deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWA deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWB deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWC deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWD deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWE deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWF deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWG deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWH deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWI deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWJ deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWK deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWL deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWM deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWN deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWO deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWP deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWQ deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWR deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWS deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWT deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWU deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWV deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWW deleted successfully. Registry value HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\\LWX deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] User: All Users User: Default ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Gerhard ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Gerrit ->Temp folder emptied: 2398 bytes ->Temporary Internet Files folder emptied: 34552 bytes ->FireFox cache emptied: 0 bytes ->Google Chrome cache emptied: 327602474 bytes ->Flash cache emptied: 1311 bytes User: Public ->Temp folder emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 0 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50501 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 313,00 mb [EMPTYFLASH] User: All Users User: Default User: Default User User: Gerhard User: Gerrit ->Flash cache emptied: 0 bytes User: Public Total Flash Files Cleaned = 0,00 mb C:\Windows\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully OTL by OldTimer - Version 3.2.39.2 log created on 03292012_211340 Files\Folders moved on Reboot... C:\Users\Gerrit\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully. Registry entries deleted on Reboot... der taskmanager ist immer noch deaktiv, das könnte mein vater gemacht haben ... Mein Vater versuchte jetzt auch den Taskmanager zu deaktivieren bisher ohne Erfolg Geändert von aloabi (29.03.2012 um 20:51 Uhr) |
![]() |
Themen zu Suspicious.Cloud.7.EP |
allgemein, babylon toolbar, compu, computer, dateisystem, device driver, gefährlich, googel, heuristiks/extra, heuristiks/shuriken, nicht mehr, nochmals, norton, office 2007, origin, scans, schlimm, schnell, smartbar, sofort, software, spybot, stelle, super, suspicous.cloud.7.ep, troja, trojaner, trojaner-board, usb 2.0, visual studio, windows 7 home, windows 7 home premium, wissen, woche, wochen |