![]() |
|
Plagegeister aller Art und deren Bekämpfung: Virus: Computerkriminalität des criminal Inteligence Service /BPD Einheit 5.2Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
/// Helfer-Team ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Virus: Computerkriminalität des criminal Inteligence Service /BPD Einheit 5.2![]() Fixen mit OTL Lade (falls noch nicht vorhanden) OTL von Oldtimer herunter und speichere es auf Deinem Desktop (nicht woanders hin).
Code:
ATTFilter :OTL IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 IE - HKU\Michael_ON_D\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT2269050 IE - HKU\Michael_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3: D:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) FF - HKLM\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9: D:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) O4:64bit: - HKLM..\Run: [Logitech Download Assistant] D:\Windows\System32\LogiLDA.dll (Logitech, Inc.) O4 - HKLM..\Run: [PC Suite for Smartphones] D:\Program Files (x86)\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe () O4 - HKU\Michael_ON_D..\Run: [] D:\Users\Michael\AppData\Local\Temp\rgnygtgcuex.exe () O4 - HKU\Michael_ON_D..\Run: [{27D8AA53-36EE-7F65-C61D-A702705856CA}] File not found O4 - HKU\Michael_ON_D..\Run: [Canaveral] File not found O4 - HKU\Michael_ON_D..\Run: [EA Core] File not found O4 - HKU\Michael_ON_D..\Run: [msnmsgr] File not found O4 - HKU\Michael_ON_D..\Run: [Update] D:\Users\Michael\AppData\Roaming\rool0_pk.exe () O4 - HKU\Michael_ON_D..\Run: [VaultSysUi] File not found O4 - HKU\LocalService_ON_D..\RunOnce: [mctadmin] File not found O4 - HKU\NetworkService_ON_D..\RunOnce: [mctadmin] File not found O4 - Startup: Error locating startup folders. O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5 O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3 O18:64bit: - Protocol\Handler\grooveLocalGWS {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - CLSID or File not found. O32 - HKLM CDRom: AutoRun - 1 O34 - HKLM BootExecute: (autocheck autochk *) - File not found 64bit: O35 - HKLM\..comfile [open] -- "%1" %* File not found 64bit: O35 - HKLM\..exefile [open] -- "%1" %* File not found [15 D:\Windows\SysWow64\*.tmp files -> D:\Windows\SysWow64\*.tmp -> ] @Alternate Data Stream - 24 bytes -> D:\Windows:C6458A5A33C16FD5 :Files D:\Users\Michael\AppData\Local\Temp\rgnygtgcuex.exe D:\Users\Michael\AppData\Roaming\rool0_pk.exe D:\Users\Michael\AppData\Roaming\hellomoto D:\Windows\tasks\GoogleUpdateTaskMachineCore.job D:\Windows\tasks\GoogleUpdateTaskMachineUA.job ipconfig /flushdns /c :Commands [purity] [emptytemp] [emptyflash]
Hinweis für Mitleser: Obiges OTL-Script ist ausschließlich für diesen User in dieser Situtation erstellt worden. Auf keinen Fall auf anderen Rechnern anwenden, das kann andere Systeme nachhaltig schädigen! |
![]() | #2 |
| ![]() Virus: Computerkriminalität des criminal Inteligence Service /BPD Einheit 5.2 Wünderschönen Guten Morgen,
__________________vielen herzlichen Dank!, ich bin begeistert! ![]() mein Urlaub scheint gerettet zu sein, pc bootet einwandfrei, ohne Fehlermeldung. jetzt kann ich endlich das neu gekaufte logitech g 27 wieder in Verwendung nehmen ![]() Da ich meinen Computer mitleirweile schon wieder etliche Zeit besitze und außer dem Freeware Antivir Guard kaum Antivirensoftware verwende, möchte ich noch fragen, sollte ich noch weitere Schritte machen um den Computer zu bereinigen ? freundliche Grüße aus Wien anbei noch der logfile: Code:
ATTFilter ========== OTL ========== HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! HKU\Michael_ON_D\Software\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKU\Michael_ON_D\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=3\ deleted successfully. File D:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) not found. Registry key HKEY_LOCAL_MACHINE\Software\Wow6432Node\MozillaPlugins\@tools.google.com/Google Update;version=9\ deleted successfully. File D:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.) not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\Logitech Download Assistant deleted successfully. File D:\Windows\System32\LogiLDA.dll not found. Registry value HKEY_LOCAL_MACHINE\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run\\PC Suite for Smartphones deleted successfully. D:\Program Files (x86)\Sony Ericsson\Mobile4\Application Launcher\Application Launcher.exe moved successfully. Registry key HKEY_USERS\Michael_ON_D\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run not found. D:\Users\Michael\AppData\Local\Temp\rgnygtgcuex.exe moved successfully. Registry key HKEY_USERS\Michael_ON_D\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27D8AA53-36EE-7F65-C61D-A702705856CA}\ not found. Registry key HKEY_USERS\Michael_ON_D\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run not found. Registry key HKEY_USERS\Michael_ON_D\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run not found. Registry key HKEY_USERS\Michael_ON_D\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run not found. Registry key HKEY_USERS\Michael_ON_D\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run not found. D:\Users\Michael\AppData\Roaming\rool0_pk.exe moved successfully. Registry key HKEY_USERS\Michael_ON_D\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Run not found. Registry key HKEY_USERS\LocalService_ON_D\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce not found. Registry key HKEY_USERS\NetworkService_ON_D\Software\Wow6432Node\Microsoft\Windows\CurrentVersion\RunOnce not found. File Error locating startup folders. not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktop deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoActiveDesktopChanges deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\grooveLocalGWS\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{88FED34C-F0CA-4636-A375-3CB6248B04CD}\ not found. File {88FED34C-F0CA-4636-A375-3CB6248B04CD} - Reg Error: Key error. File not found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{314111c7-a502-11d2-bbca-00c04f8ec294}\ not found. File {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{03C514A3-1EFB-4856-9F99-10D7BE1653C0}\ not found. File {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully! Registry value HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Control\Session manager\\BootExecute:autocheck autochk * deleted successfully. D:\Windows\SysWow64\tmp13F5.tmp deleted successfully. D:\Windows\SysWow64\tmp1425.tmp deleted successfully. D:\Windows\SysWow64\tmp345F.tmp deleted successfully. D:\Windows\SysWow64\tmp3470.tmp deleted successfully. D:\Windows\SysWow64\tmp368C.tmp deleted successfully. D:\Windows\SysWow64\tmp3768.tmp deleted successfully. D:\Windows\SysWow64\tmp53B0.tmp deleted successfully. D:\Windows\SysWow64\tmp7477.tmp deleted successfully. D:\Windows\SysWow64\tmp74E5.tmp deleted successfully. D:\Windows\SysWow64\tmp8EA8.tmp deleted successfully. D:\Windows\SysWow64\tmp8F06.tmp deleted successfully. D:\Windows\SysWow64\tmpBA9A.tmp deleted successfully. D:\Windows\SysWow64\tmpBD1B.tmp deleted successfully. D:\Windows\SysWow64\tmpE289.tmp deleted successfully. D:\Windows\SysWow64\tmpE2AA.tmp deleted successfully. ADS D:\Windows:C6458A5A33C16FD5 deleted successfully. ========== FILES ========== File\Folder D:\Users\Michael\AppData\Local\Temp\rgnygtgcuex.exe not found. File\Folder D:\Users\Michael\AppData\Roaming\rool0_pk.exe not found. D:\Users\Michael\AppData\Roaming\hellomoto folder moved successfully. D:\Windows\tasks\GoogleUpdateTaskMachineCore.job moved successfully. D:\Windows\tasks\GoogleUpdateTaskMachineUA.job moved successfully. < ipconfig /flushdns /c > Windows IP Configuration An internal error occurred: The system cannot find the file specified. Please contact Microsoft Product Support Services for further help. Additional information: Unable to open registry key for tcpip. D:\cmd.bat deleted successfully. D:\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYTEMP] Empty user temp failed. Cannot find local settings folders. Empty user temp failed. Cannot find local settings folders. Empty user temp failed. Cannot find local settings folders. Empty user temp failed. Cannot find local settings folders. Empty user temp failed. Cannot find local settings folders. Empty user temp failed. Cannot find local settings folders. %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 200704 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32 (64bit) .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 814187343 bytes %systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 50434 bytes Total Files Cleaned = 777.00 mb [EMPTYFLASH] Empty user temp failed. Cannot find local settings folders. Empty user temp failed. Cannot find local settings folders. Empty user temp failed. Cannot find local settings folders. Empty user temp failed. Cannot find local settings folders. Empty user temp failed. Cannot find local settings folders. Empty user temp failed. Cannot find local settings folders. Total Flash Files Cleaned = 0.00 mb OTLPE by OldTimer - Version 3.1.48.0 log created on 07242012_102502 |
![]() |
Themen zu Virus: Computerkriminalität des criminal Inteligence Service /BPD Einheit 5.2 |
antivir, autorun, avira, b 5.2, bho, bildschirm, bpd einheit 5.2, browser, cdburnerxp, criminal intelligence service, defender, desktop, enigma, error, euro, explorer, fiese, firefox, format, google earth, langs, logfile, mozilla, nvidia, object, plug-in, poweriso, realtek, registry, scan, software, temp, trojaner, virus, windows |