![]() |
| |||||||
Log-Analyse und Auswertung: Fix-Log fuer Windowsverschluesselungs-TrojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #3 |
| | Fix-Log fuer Windowsverschluesselungs-Trojaner Hallo Kira,
__________________Danke erstmal fuer die Hilfestellung. Der Fix ist durchgelaufen und der log ist unten angefuegt. Nach dem Reboot kann ich bereits im normalen Modus weiter arbeiten! Keine WinBlockung & i-net funktiniert auch wieder. *phew* )Werde mich im Laufe des Nachmittags an die weiteren schritte rantasten. vielen lieben Dank schonmal, m Code:
ATTFilter ========== OTL ==========
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully.
HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
HKU\Manuel_ON_F\Software\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully!
HKU\Manuel_ON_F\Software\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry value HKEY_USERS\Manuel_ON_F\Software\Microsoft\Internet Explorer\URLSearchHooks\\ deleted successfully.
Registry value HKEY_USERS\Manuel_ON_F\Software\Microsoft\Internet Explorer\URLSearchHooks\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ not found.
Registry value HKEY_USERS\Manuel_ON_F\Software\Microsoft\Internet Explorer\URLSearchHooks\\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{cc05a3e3-64c3-4af2-bfc1-af0d66b69065}\ deleted successfully.
Registry value HKEY_USERS\Manuel_ON_F\Software\Microsoft\Internet Explorer\URLSearchHooks\\{EEE6C35D-6118-11DC-9C72-001320C79847} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35D-6118-11DC-9C72-001320C79847}\ deleted successfully.
HKU\Manuel_ON_F\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully.
File F:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) not found.
Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully.
File F:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.) not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked deleted successfully.
Registry key HKEY_USERS\Manuel_ON_F\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run not found.
F:\Users\Manuel\AppData\Roaming\Sctbht\7D2CAFBC10AE3BF66E36.exe moved successfully.
Registry key HKEY_USERS\Manuel_ON_F\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run not found.
F:\updates64\395D483BBD1.exe moved successfully.
Registry key HKEY_USERS\LocalService_ON_F\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce not found.
Registry key HKEY_USERS\NetworkService_ON_F\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1addd759-d29e-11df-bdb0-705ab6182a25}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1addd759-d29e-11df-bdb0-705ab6182a25}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{1addd759-d29e-11df-bdb0-705ab6182a25}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{1addd759-d29e-11df-bdb0-705ab6182a25}\ not found.
File F:\LaunchU3.exe -a not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54c30523-c637-11df-90d3-705ab6182a25}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54c30523-c637-11df-90d3-705ab6182a25}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{54c30523-c637-11df-90d3-705ab6182a25}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{54c30523-c637-11df-90d3-705ab6182a25}\ not found.
File E:\LaunchU3.exe -a not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{69bd1dec-3192-11df-8636-705ab6182a25}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69bd1dec-3192-11df-8636-705ab6182a25}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{69bd1dec-3192-11df-8636-705ab6182a25}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69bd1dec-3192-11df-8636-705ab6182a25}\ not found.
File E:\LaunchU3.exe -a not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{69bd1df7-3192-11df-8636-705ab6182a25}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69bd1df7-3192-11df-8636-705ab6182a25}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{69bd1df7-3192-11df-8636-705ab6182a25}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{69bd1df7-3192-11df-8636-705ab6182a25}\ not found.
File G:\LaunchU3.exe -a not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7a33b265-2205-11e0-b53f-705ab6182a25}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7a33b265-2205-11e0-b53f-705ab6182a25}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7a33b265-2205-11e0-b53f-705ab6182a25}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7a33b265-2205-11e0-b53f-705ab6182a25}\ not found.
File E:\LaunchU3.exe -a not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c070afc5-6d4d-11df-bb5e-705ab6182a25}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c070afc5-6d4d-11df-bb5e-705ab6182a25}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{c070afc5-6d4d-11df-bb5e-705ab6182a25}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{c070afc5-6d4d-11df-bb5e-705ab6182a25}\ not found.
File F:\LaunchU3.exe -a not found.
F:\Windows\Tasks\GoogleUpdateTaskMachineCore.job moved successfully.
F:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
ADS F:\ProgramData\Temp:4D066AD2 deleted successfully.
ADS F:\ProgramData\Temp:0B9176C0 deleted successfully.
ADS F:\ProgramData\Temp:4CF61E54 deleted successfully.
ADS F:\ProgramData\Temp:5D7E5A8F deleted successfully.
ADS F:\ProgramData\Temp:E3C56885 deleted successfully.
ADS F:\ProgramData\Temp:ABE89FFE deleted successfully.
ADS F:\ProgramData\Temp:E1F04E8D deleted successfully.
ADS F:\ProgramData\Temp:AB689DEA deleted successfully.
ADS F:\ProgramData\Temp:93DE1838 deleted successfully.
ADS F:\ProgramData\Temp:444C53BA deleted successfully.
========== FILES ==========
File\Folder F:\Users\Manuel\AppData\Roaming\Sctbht\7D2CAFBC10AE3BF66E36.exe not found.
File\Folder F:\updates64\395D483BBD1.exe not found.
< ipconfig /flushdns /c >
Windows IP Configuration
F:\cmd.bat deleted successfully.
F:\cmd.txt deleted successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->Flash cache emptied: 56502 bytes
User: Default User
User: Manuel
->Temp folder emptied: 34295369 bytes
->Temporary Internet Files folder emptied: 268535820 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 112303156 bytes
->Flash cache emptied: 73661 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4018045 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 46374103 bytes
Total Files Cleaned = 444.00 mb
OTLPE by OldTimer - Version 3.1.48.0 log created on 05162012_184656
|
| Themen zu Fix-Log fuer Windowsverschluesselungs-Trojaner |
| alternate, anleitung, conduit, download, fix, freue, google earth, launch, leitung, logfile, mail, nvstor.sys, otlpe, packard bell, plug-in, problem, scan, verschluesselung trojaner windows blockiert, version=1.0, vorgehensweise |