Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: GEMA Trojaner - OTL.txt erstellt - brauche Hilfe!

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML.

 
Alt 01.04.2012, 14:29   #1
kurzer01
 
GEMA Trojaner - OTL.txt erstellt - brauche Hilfe! - Standard

GEMA Trojaner - OTL.txt erstellt - brauche Hilfe!



Hallo zusammen,
auch mich hat der Gema-Trojaner erwischt.
Ich habe wie hier im Forum beschrieben, OTLPE auf einen USB-Stick gemacht,
mein Notebook von USB gebootet und eine OTL.txt Datei erstellt:

Zitat:
OTL logfile created on: 4/1/2012 8:37:14 PM - Run
OTLPE by OldTimer - Version 3.1.48.0 Folder = X:\Programs\OTLPE
Windows 7 Ultimate Service Pack 1 (Version = 6.1.7601) - Type = System
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy

2.00 Gb Total Physical Memory | 2.00 Gb Available Physical Memory | 87.00% Memory free
2.00 Gb Paging File | 2.00 Gb Available in Paging File | 97.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 48.82 Gb Total Space | 24.28 Gb Free Space | 49.73% Space Free | Partition Type: NTFS
Drive D: | 208.01 Gb Total Space | 206.58 Gb Free Space | 99.31% Space Free | Partition Type: NTFS
Drive E: | 208.92 Gb Total Space | 169.63 Gb Free Space | 81.19% Space Free | Partition Type: NTFS
Drive X: | 3.69 Gb Total Space | 3.29 Gb Free Space | 89.10% Space Free | Partition Type: FAT

Computer Name: REATOGO | User Name: SYSTEM
Boot Mode: Normal | Scan Mode: All users
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
Using ControlSet: ControlSet001

========== Win32 Services (SafeList) ==========

SRV - [2012/01/03 09:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2011/10/27 05:34:30 | 000,718,384 | ---- | M] (Nokia) [On_Demand] -- C:\Program Files\PC Connectivity Solution\ServiceLayer.exe -- (ServiceLayer)
SRV - [2011/07/25 17:18:46 | 000,028,672 | ---- | M] (Lenovo Group Limited) [Auto] -- C:\Program Files\Lenovo\System Update\SUService.exe -- (SUService)
SRV - [2011/07/03 21:02:00 | 000,292,200 | ---- | M] (Lenovo.) [On_Demand] -- C:\Program Files\ThinkPad\Utilities\DOZESVC.EXE -- (DozeSvc)
SRV - [2011/07/03 21:02:00 | 000,148,840 | ---- | M] (Lenovo Group Limited) [Auto] -- C:\Program Files\ThinkPad\Utilities\PWMEWSVC.exe -- (PwmEWSvc)
SRV - [2011/07/03 21:02:00 | 000,083,304 | ---- | M] (Lenovo) [On_Demand] -- C:\Program Files\ThinkPad\Utilities\PWMDBSVC.EXE -- (Power Manager DBC Service)
SRV - [2011/05/20 07:46:16 | 001,523,008 | ---- | M] (TuneUp Software) [Auto] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesService32.exe -- (TuneUp.UtilitiesSvc)
SRV - [2011/05/20 07:43:18 | 000,029,504 | ---- | M] (TuneUp Software) [Auto] -- C:\Windows\System32\uxtuneup.dll -- (UxTuneUp)
SRV - [2011/04/27 09:39:26 | 000,208,944 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe -- (NisSrv)
SRV - [2011/04/27 09:39:26 | 000,011,736 | ---- | M] (Microsoft Corporation) [Auto] -- C:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe -- (MsMpSvc)
SRV - [2011/04/20 04:04:40 | 000,130,920 | ---- | M] (Lenovo Group Limited) [Auto] -- C:\Program Files\Lenovo\HOTKEY\tphkload.exe -- (TPHKLOAD)
SRV - [2011/04/14 07:22:28 | 000,263,528 | ---- | M] (Lenovo) [Disabled] -- C:\Program Files\Lenovo\Access Connections\AcSvc.exe -- (AcSvc)
SRV - [2011/04/14 07:22:26 | 000,124,264 | ---- | M] (Lenovo) [Disabled] -- C:\Program Files\Lenovo\Access Connections\AcPrfMgrSvc.exe -- (AcPrfMgrSvc)
SRV - [2011/04/04 04:27:20 | 000,045,496 | ---- | M] (Lenovo Group Limited) [Auto] -- C:\Program Files\Lenovo\HOTKEY\micmute.exe -- (LENOVO.MICMUTE)
SRV - [2011/03/29 07:41:08 | 000,064,952 | ---- | M] (Lenovo Group Limited) [Auto] -- C:\Program Files\Lenovo\HOTKEY\TPHKSVC.exe -- (TPHKSVC)
SRV - [2010/12/17 08:22:40 | 000,936,208 | ---- | M] (Intel(R) Corporation) [Auto] -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe -- (EvtEng) Intel(R)
SRV - [2010/12/17 08:08:40 | 000,477,456 | ---- | M] (Intel(R) Corporation) [Auto] -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe -- (RegSrvc) Intel(R)
SRV - [2010/04/07 08:37:38 | 000,093,032 | ---- | M] (Lenovo Group Limited) [Auto] -- C:\Program Files\Lenovo\VIRTSCRL\lvvsst.exe -- (Lenovo.VIRTSCRLSVC)
SRV - [2009/07/13 21:16:13 | 000,025,088 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\sensrsvc.dll -- (SensrSvc)
SRV - [2009/07/13 21:16:12 | 001,004,544 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Windows\System32\PeerDistSvc.dll -- (PeerDistSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | ---- | M] (Microsoft Corporation) [On_Demand] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2008/07/15 11:09:52 | 000,090,112 | ---- | M] (Andrea Electronics Corporation) [Auto] -- C:\Windows\System32\AEADISRV.EXE -- (AEADIFilters)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand] -- -- (XDva393)
DRV - File not found [Kernel | On_Demand] -- -- (VGPU)
DRV - File not found [Kernel | On_Demand] -- -- (tsusbhub)
DRV - File not found [Kernel | On_Demand] -- -- (Synth3dVsc)
DRV - File not found [Kernel | On_Demand] -- -- (PcdrNdisuio)
DRV - [2011/08/17 08:03:58 | 000,137,472 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nmwcdnsu.sys -- (nmwcdnsu)
DRV - [2011/08/17 08:03:50 | 000,008,576 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\nmwcdnsuc.sys -- (nmwcdnsuc)
DRV - [2011/08/17 07:56:32 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbser_lowerfltj.sys -- (UsbserFilt)
DRV - [2011/08/17 07:56:30 | 000,008,192 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\usbser_lowerflt.sys -- (upperdev)
DRV - [2011/08/17 07:56:26 | 000,023,168 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ccdcmbo.sys -- (nmwcdc)
DRV - [2011/08/17 07:56:22 | 000,018,176 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\ccdcmb.sys -- (nmwcd)
DRV - [2011/07/03 21:02:00 | 000,025,968 | ---- | M] (Lenovo.) [Kernel | Boot] -- C:\Windows\System32\drivers\DOZEHDD.SYS -- (DozeHDD)
DRV - [2011/07/03 21:02:00 | 000,013,424 | ---- | M] (Lenovo Group Limited) [Kernel | System] -- C:\Windows\System32\drivers\TPPWR32V.SYS -- (TPPWRIF)
DRV - [2011/04/27 09:25:24 | 000,065,024 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2011/04/26 09:30:20 | 000,010,064 | ---- | M] (TuneUp Software) [Kernel | On_Demand] -- C:\Program Files\TuneUp Utilities 2011\TuneUpUtilitiesDriver32.sys -- (TuneUpUtilitiesDrv)
DRV - [2011/04/18 07:18:50 | 000,043,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\MpNWMon.sys -- (MpNWMon)
DRV - [2011/03/29 13:14:08 | 000,122,992 | ---- | M] (Lenovo.) [Kernel | Boot] -- C:\Windows\System32\drivers\ApsX86.sys -- (Shockprf)
DRV - [2011/03/29 13:12:16 | 000,020,592 | ---- | M] (Lenovo.) [Kernel | Boot] -- C:\Windows\System32\drivers\ApsHM86.sys -- (TPDIGIMN)
DRV - [2010/11/20 08:30:15 | 000,175,360 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\vmbus.sys -- (vmbus)
DRV - [2010/11/20 08:30:15 | 000,040,704 | ---- | M] (Microsoft Corporation) [Kernel | Boot] -- C:\Windows\System32\drivers\vmstorfl.sys -- (storflt)
DRV - [2010/11/20 08:30:15 | 000,028,032 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\storvsc.sys -- (storvsc)
DRV - [2010/11/20 06:24:41 | 000,052,224 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV - [2010/11/20 06:21:14 | 000,015,872 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV - [2010/11/20 05:59:44 | 000,035,968 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\winusb.sys -- (WinUsb)
DRV - [2010/11/20 05:14:45 | 000,017,920 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\VMBusHID.sys -- (VMBusHID)
DRV - [2010/11/20 05:14:41 | 000,005,632 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\system32\drivers\vms3cap.sys -- (s3cap)
DRV - [2010/10/06 22:11:38 | 006,639,616 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\NETwLv32.sys -- (NETwLv32) Intel(R)
DRV - [2010/09/07 08:09:06 | 000,013,680 | ---- | M] (Lenovo Group Limited) [Kernel | System] -- C:\Windows\System32\drivers\smiif32.sys -- (lenovo.smi)
DRV - [2009/07/13 19:12:52 | 000,030,720 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\tpm.sys -- (TPM)
DRV - [2009/07/13 18:02:51 | 004,231,168 | ---- | M] (Intel Corporation) [Kernel | On_Demand] -- C:\Windows\System32\drivers\netw5v32.sys -- (netw5v32) Intel(R)
DRV - [2008/08/26 05:26:12 | 000,018,816 | ---- | M] (Nokia) [Kernel | On_Demand] -- C:\Windows\System32\drivers\pccsmcfd.sys -- (pccsmcfd)
DRV - [2007/02/19 01:56:46 | 000,021,376 | ---- | M] (Lenovo (United States) Inc.) [Kernel | On_Demand] -- C:\Windows\System32\drivers\psadd.sys -- (psadd)
DRV - [2006/11/27 11:44:52 | 000,008,192 | ---- | M] (Conexant Systems, Inc.) [Kernel | Auto] -- C:\Windows\System32\drivers\XAudio.sys -- (XAudio)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========



IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\Det_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.de/
IE - HKU\Det_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = hxxp://de.msn.com/?ocid=iehp
IE - HKU\Det_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = de
IE - HKU\Det_ON_C\Software\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 5F 17 BC 8A 8E CC 01 [binary data]
IE - HKU\Det_ON_C\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0




========== FireFox ==========

FF - prefs.js..browser.search.update: false
FF - prefs.js..browser.startup.homepage: "www.google.de"


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\System32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\System32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Det\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Det\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Det\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/11/11 15:39:25 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\fe_7.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Bookmarks Connector\FirefoxExtension_7.0 [2011/12/27 09:40:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2012/01/06 15:12:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\te_7.0@nokia.com: C:\Program Files\Nokia\Nokia Suite\Connectors\Thunderbird Connector\ThunderbirdExtension_7.0 [2011/12/27 09:40:59 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2011/11/11 15:39:25 | 000,000,000 | ---D | M]

[2011/10/19 16:28:01 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Det\AppData\Roaming\Mozilla\Extensions
[2012/01/06 13:24:02 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Det\AppData\Roaming\Mozilla\Firefox\Profiles\2aky7lsv.default\extensions
[2012/01/06 15:12:11 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions
File not found (No name found) --
() (No name found) -- C:\USERS\DET\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\2AKY7LSV.DEFAULT\EXTENSIONS\{D10D0BF8-F5B5-C8B4-A8B2-2B9879E08C5D}.XPI
[2012/01/06 15:12:09 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/01/06 15:12:05 | 000,001,392 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\amazondotcom-de.xml
[2012/01/06 15:12:05 | 000,002,252 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2012/01/06 15:12:05 | 000,001,153 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\eBay-de.xml
[2012/01/06 15:12:05 | 000,006,805 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\leo_ende_de.xml
[2012/01/06 15:12:05 | 000,001,178 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\wikipedia-de.xml
[2012/01/06 15:12:05 | 000,001,105 | ---- | M] () -- C:\Program Files\mozilla firefox\searchplugins\yahoo-de.xml

O1 HOSTS File: ([2009/06/10 17:39:37 | 000,000,824 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AcWin7Hlpr] C:\Program Files\Lenovo\Access Connections\AcTBenabler.exe (Lenovo)
O4 - HKLM..\Run: [gema] C:\Windows\System32\gema.exe ()
O4 - HKLM..\Run: [gema.] C:\ProgramData\gema\gema.exe ()
O4 - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [PWMTRV] C:\Program Files\ThinkPad\Utilities\PWMTR32V.DLL (Lenovo Group Limited)
O4 - HKU\Det_ON_C..\Run: [] File not found
O4 - HKU\Det_ON_C..\Run: [gema] C:\Users\Det\AppData\Roaming\gema\gema.exe ()
O4 - HKU\LocalService_ON_C..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O4 - HKU\NetworkService_ON_C..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKU\Det_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoInternetOpenWith = 1
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_29-windows-i586.cab (Java Plug-in 1.6.0_29)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKU\Det_ON_C Winlogon: Shell - (C:\Users\Det\AppData\Roaming\gema\gema.exe) - C:\Users\Det\AppData\Roaming\gema\gema.exe ()
O20 - HKU\Det_ON_C Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2006/03/24 13:06:42 | 000,000,053 | ---- | M] () - X:\AUTORUN.INF -- [ FAT ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*

========== Files/Folders - Created Within 30 Days ==========

[2012/04/01 11:03:08 | 000,000,000 | ---D | C] -- C:\Kaspersky Rescue Disk 10.0
[2012/03/24 13:43:12 | 000,000,000 | ---D | C] -- C:\Users\Det\AppData\Roaming\gema
[2012/03/24 13:43:12 | 000,000,000 | ---D | C] -- C:\ProgramData\gema
[2012/03/23 15:03:44 | 000,000,000 | ---D | C] -- C:\Windows\System32\Adobe
[2012/03/23 14:29:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\alaplaya
[2012/03/23 14:24:58 | 000,000,000 | ---D | C] -- C:\Program Files\alaplaya
[2012/03/23 14:14:59 | 593,954,668 | ---- | C] (InstallShield Software Corporation) -- C:\Users\Det\Desktop\S4League.exe
[2012/03/23 09:39:33 | 000,000,000 | ---D | C] -- C:\Users\Det\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\LIMBO
[2012/03/18 15:18:07 | 000,000,000 | ---D | C] -- C:\Users\Det\AppData\Roaming\Unity
[2012/03/18 15:16:14 | 000,000,000 | ---D | C] -- C:\Users\Det\AppData\Local\Unity

========== Files - Modified Within 30 Days ==========

[2012/04/01 09:34:27 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/04/01 09:34:21 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/04/01 09:34:21 | 000,014,016 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/04/01 09:33:06 | 1603,084,288 | -HS- | M] () -- C:\hiberfil.sys
[2012/04/01 08:52:32 | 000,656,266 | ---- | M] () -- C:\Windows\System32\perfh007.dat
[2012/04/01 08:52:32 | 000,618,108 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/04/01 08:52:32 | 000,131,006 | ---- | M] () -- C:\Windows\System32\perfc007.dat
[2012/04/01 08:52:32 | 000,107,388 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/04/01 08:26:32 | 000,012,288 | ---- | M] () -- C:\Windows\System32\umstartup.etl
[2012/04/01 08:20:16 | 000,000,620 | ---- | M] () -- C:\Windows\tasks\SymInstallStub.job
[2012/03/24 13:43:11 | 000,243,712 | ---- | M] () -- C:\Windows\System32\gema.exe
[2012/03/23 15:04:29 | 000,002,284 | ---- | M] () -- C:\Users\Det\Desktop\SymInstallStub.lnk
[2012/03/23 14:38:44 | 000,001,768 | ---- | M] () -- C:\Users\Public\Desktop\S4League.lnk
[2012/03/23 14:29:09 | 000,000,000 | ---D | M] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\alaplaya
[2012/03/23 14:23:39 | 593,954,668 | ---- | M] (InstallShield Software Corporation) -- C:\Users\Det\Desktop\S4League.exe
[2012/03/10 15:33:28 | 000,000,528 | ---- | M] () -- C:\Windows\tasks\PCDoctorBackgroundMonitorTask.job

========== Files Created - No Company Name ==========

[2012/04/01 08:11:13 | 000,243,712 | ---- | C] () -- C:\Windows\System32\gema.exe
[2012/03/23 15:04:29 | 000,002,314 | ---- | C] () -- C:\Users\Det\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SymInstallStub.lnk
[2012/03/23 15:04:29 | 000,002,284 | ---- | C] () -- C:\Users\Det\Desktop\SymInstallStub.lnk
[2012/03/23 15:04:29 | 000,000,620 | ---- | C] () -- C:\Windows\tasks\SymInstallStub.job
[2012/03/23 14:38:44 | 000,001,768 | ---- | C] () -- C:\Users\Public\Desktop\S4League.lnk
[2011/11/11 15:47:54 | 000,000,731 | ---- | C] () -- C:\Windows\hpwmdl12.dat.temp
[2011/11/11 15:35:17 | 000,248,168 | ---- | C] () -- C:\Windows\hpwins12.dat
[2011/11/11 15:35:17 | 000,000,731 | ---- | C] () -- C:\Windows\hpwmdl12.dat
[2011/10/20 12:48:23 | 000,007,648 | ---- | C] () -- C:\Users\Det\AppData\Local\Resmon.ResmonCfg
[2011/10/19 17:10:04 | 000,080,896 | ---- | C] () -- C:\Windows\System32\RDVGHelper.exe
[2011/10/19 17:09:13 | 000,252,928 | ---- | C] () -- C:\Windows\System32\DShowRdpFilter.dll
[2011/10/19 17:05:44 | 000,066,048 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2009/07/14 04:47:43 | 000,656,266 | ---- | C] () -- C:\Windows\System32\perfh007.dat
[2009/07/14 04:47:43 | 000,295,922 | ---- | C] () -- C:\Windows\System32\perfi007.dat
[2009/07/14 04:47:43 | 000,131,006 | ---- | C] () -- C:\Windows\System32\perfc007.dat
[2009/07/14 04:47:43 | 000,038,104 | ---- | C] () -- C:\Windows\System32\perfd007.dat
[2009/07/14 00:57:37 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/14 00:33:53 | 000,293,368 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2009/07/13 22:05:48 | 000,618,108 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2009/07/13 22:05:48 | 000,291,294 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2009/07/13 22:05:48 | 000,107,388 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2009/07/13 22:05:48 | 000,031,548 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2009/07/13 22:05:05 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2009/07/13 22:04:11 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2009/07/13 19:55:01 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 19:51:43 | 000,073,728 | ---- | C] () -- C:\Windows\System32\BthpanContextHandler.dll
[2009/07/13 19:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\System32\BWContextHandler.dll
[2009/06/10 17:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2008/01/04 09:13:58 | 000,073,728 | ---- | C] () -- C:\Windows\System32\DEVMAN.DLL

========== LOP Check ==========

[2012/03/24 13:43:12 | 000,000,000 | ---D | M] -- C:\Users\Det\AppData\Roaming\gema
[2011/12/27 09:54:12 | 000,000,000 | ---D | M] -- C:\Users\Det\AppData\Roaming\Nokia
[2011/12/27 09:54:13 | 000,000,000 | ---D | M] -- C:\Users\Det\AppData\Roaming\Nokia Suite
[2011/10/24 05:42:31 | 000,000,000 | ---D | M] -- C:\Users\Det\AppData\Roaming\OpenOffice.org
[2011/10/20 16:28:49 | 000,000,000 | ---D | M] -- C:\Users\Det\AppData\Roaming\Opera
[2012/01/05 12:36:27 | 000,000,000 | ---D | M] -- C:\Users\Det\AppData\Roaming\PC Suite
[2011/10/19 15:28:49 | 000,000,000 | ---D | M] -- C:\Users\Det\AppData\Roaming\PCDr
[2011/10/19 15:14:13 | 000,000,000 | ---D | M] -- C:\Users\Det\AppData\Roaming\PwrMgr
[2011/10/23 08:13:34 | 000,000,000 | ---D | M] -- C:\Users\Det\AppData\Roaming\TuneUp Software
[2012/03/18 15:18:07 | 000,000,000 | ---D | M] -- C:\Users\Det\AppData\Roaming\Unity
[2011/10/19 14:05:05 | 000,000,000 | -HSD | M] -- C:\ProgramData\Anwendungsdaten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Application Data
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Desktop
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Documents
[2011/10/19 14:05:05 | 000,000,000 | -HSD | M] -- C:\ProgramData\Dokumente
[2011/10/19 14:05:05 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favoriten
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Favorites
[2012/03/24 13:43:12 | 000,000,000 | ---D | M] -- C:\ProgramData\gema
[2011/11/01 11:34:02 | 000,000,000 | ---D | M] -- C:\ProgramData\Intenium
[2011/10/19 15:05:52 | 000,000,000 | ---D | M] -- C:\ProgramData\Lenovo
[2011/12/27 09:40:41 | 000,000,000 | ---D | M] -- C:\ProgramData\Nokia
[2011/12/27 09:38:00 | 000,000,000 | ---D | M] -- C:\ProgramData\NokiaInstallerCache
[2011/12/27 09:41:53 | 000,000,000 | ---D | M] -- C:\ProgramData\PC Suite
[2011/10/19 14:59:04 | 000,000,000 | ---D | M] -- C:\ProgramData\PC-Doctor for Windows
[2011/10/20 15:09:11 | 000,000,000 | ---D | M] -- C:\ProgramData\PCDr
[2011/10/19 15:05:02 | 000,000,000 | ---D | M] -- C:\ProgramData\Roaming
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Start Menu
[2011/10/19 14:05:05 | 000,000,000 | -HSD | M] -- C:\ProgramData\Startmenü
[2009/07/14 00:53:55 | 000,000,000 | -HSD | M] -- C:\ProgramData\Templates
[2011/10/23 08:14:21 | 000,000,000 | ---D | M] -- C:\ProgramData\TuneUp Software
[2011/10/19 14:05:05 | 000,000,000 | -HSD | M] -- C:\ProgramData\Vorlagen
[2011/10/23 08:12:09 | 000,000,000 | -HSD | M] -- C:\ProgramData\{24036256-BFDB-4CD3-BE8A-A3D6160F2E16}
[2012/03/10 15:33:28 | 000,000,528 | ---- | M] () -- C:\Windows\Tasks\PCDoctorBackgroundMonitorTask.job
[2009/07/14 00:53:46 | 000,005,920 | ---- | M] () -- C:\Windows\Tasks\SCHEDLGU.TXT
[2012/04/01 08:20:16 | 000,000,620 | ---- | M] () -- C:\Windows\Tasks\SymInstallStub.job
[2011/10/23 08:51:07 | 000,000,466 | ---- | M] () -- C:\Windows\Tasks\SystemToolsDailyTest.job
[2011/11/23 14:35:07 | 000,000,228 | ---- | M] () -- C:\Windows\Tasks\TuneUpUtilities_Task_BkGndMaintenance2011.job

========== Purity Check ==========


< End of report >
Was muss ich nun machen?

 

Themen zu GEMA Trojaner - OTL.txt erstellt - brauche Hilfe!
adobe, autorun, cdrom, defender, desktop, explorer, explorer.exe, firefox, format, hotkey, ics, kaspersky, langs, lenovo, logfile, microsoft, microsoft security, notebook, plug-in, registry, scan, security, software, system32, trojaner, update, version=1.0, win32, winlogon




Ähnliche Themen: GEMA Trojaner - OTL.txt erstellt - brauche Hilfe!


  1. Hilfe! GVU/BKA Trojaner eingefangen, ich brauche Hilfe dabei den Mist von meinem Lappi runter zu bekommen!
    Log-Analyse und Auswertung - 27.11.2012 (1)
  2. Virus oder Trojaner erstellt eigenes Windows an, brauche dringend Hilfe
    Plagegeister aller Art und deren Bekämpfung - 26.11.2012 (1)
  3. GEMA-Trojaner 2.08, bereits OTLPE-Logfile erstellt
    Log-Analyse und Auswertung - 26.10.2012 (2)
  4. Gema trojaner,bite um hilfe
    Log-Analyse und Auswertung - 04.04.2012 (4)
  5. Gema Trojaner, bitte um Hilfe
    Plagegeister aller Art und deren Bekämpfung - 02.04.2012 (3)
  6. GEMA-Trojaner - OTL.txt erstellt
    Log-Analyse und Auswertung - 01.04.2012 (3)
  7. Gema-Trojaner, bitte um Hilfe bei Entfernung
    Plagegeister aller Art und deren Bekämpfung - 30.03.2012 (11)
  8. GEMA Trojaner - OTLPE Logs erstellt - wie geht es weiter?
    Plagegeister aller Art und deren Bekämpfung - 28.03.2012 (11)
  9. GEMA-Trojaner, Hilfe mit OTLPE
    Log-Analyse und Auswertung - 07.03.2012 (42)
  10. GEMA 100 € Virus - brauche nun ein Script..Vielen Dank!
    Log-Analyse und Auswertung - 28.02.2012 (1)
  11. GEMA Trojaner - Bitte um Hilfe
    Plagegeister aller Art und deren Bekämpfung - 26.02.2012 (16)
  12. GEMA - Trojaner ...shell.text bereits erstellt
    Plagegeister aller Art und deren Bekämpfung - 10.01.2012 (91)
  13. Gema-Trojaner bzw. Gema Meldung mit blockiertem Rechner
    Log-Analyse und Auswertung - 09.01.2012 (13)
  14. Gema-Trojaner bzw. Gema Meldung mit blockiertem Rechner
    Plagegeister aller Art und deren Bekämpfung - 04.12.2011 (9)
  15. Gema/BKA UKASH Trojaner Brauche dringend Fix.txt
    Log-Analyse und Auswertung - 02.11.2011 (1)
  16. hilfe!! trojaner.w32.looksky brauche hilfe
    Plagegeister aller Art und deren Bekämpfung - 25.07.2007 (7)
  17. Trojaner gefunden und Log erstellt. Brauche Hilfe !
    Plagegeister aller Art und deren Bekämpfung - 26.11.2004 (15)

Zum Thema GEMA Trojaner - OTL.txt erstellt - brauche Hilfe! - Hallo zusammen, auch mich hat der Gema-Trojaner erwischt. Ich habe wie hier im Forum beschrieben, OTLPE auf einen USB-Stick gemacht, mein Notebook von USB gebootet und eine OTL.txt Datei erstellt: - GEMA Trojaner - OTL.txt erstellt - brauche Hilfe!...
Archiv
Du betrachtest: GEMA Trojaner - OTL.txt erstellt - brauche Hilfe! auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.