![]() |
|
Plagegeister aller Art und deren Bekämpfung: Befallen vom System Care AntivirusWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() Befallen vom System Care Antivirus Hallo, ich habe mir heute irgendwie den System Care Antivirus eingefangen. Nach diversen Foren-Durchforsten habe ich das Programm mit einem Registry-Code aktiviert, um dann OTL durchzuführen. Das Programm ist allerdings immer noch unten rechts in der Leiste, also noch nicht verwunden. Was kann/muss ich tun? Bitte helft mir! Mein System: Windows XP Ich habe folgenden OTL-Log bekommen: All processes killed ========== OTL ========== HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully! HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E : value set successfully! HKLM\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully! Unable to set value : HKU\S-1-5-21-1233179244-515761155-90277447-1005\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E! Unable to set value : HKU\S-1-5-21-1233179244-515761155-90277447-1005\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E! Unable to set value : HKU\S-1-5-21-1233179244-515761155-90277447-1010\SOFTWARE\Microsoft\Internet Explorer\Main\\Default_Page_URL| /E! Unable to set value : HKU\S-1-5-21-1233179244-515761155-90277447-1010\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E! Registry key HKEY_USERS\S-1-5-21-1233179244-515761155-90277447-1010\Software\Microsoft\Internet Explorer\URLSearchHooks not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064}\ not found. Registry key HKEY_USERS\S-1-5-21-1233179244-515761155-90277447-1010\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found. 64bit-Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ not found. Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ not found. Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5C255C8A-E604-49b4-9D64-90988571CECB}\ not found. 64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\Locked not found. Registry key HKEY_USERS\S-1-5-21-1233179244-515761155-90277447-1005\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found. Registry key HKEY_USERS\S-1-5-21-1233179244-515761155-90277447-1010\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2318C2B1-4965-11D4-9B18-009027A5CD4F}\ not found. Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ not found. Registry key HKEY_USERS\S-1-5-21-1233179244-515761155-90277447-1005\Software\Microsoft\Windows\CurrentVersion\Run not found. Registry key HKEY_USERS\S-1-5-21-1233179244-515761155-90277447-1010\Software\Microsoft\Windows\CurrentVersion\Run not found. Registry key HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\RunOnce not found. Registry key HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\RunOnce not found. Registry key HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce not found. Registry key HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce not found. Registry key HKEY_USERS\S-1-5-21-1233179244-515761155-90277447-1010\Software\Microsoft\Windows\CurrentVersion\RunOnce not found. File C:\ProgramData\94F3E4571BE0C07D000094F34F69C677\94F3E4571BE0C07D000094F34F69C677.exe not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ not found. File Protocol\Handler\livecall - No CLSID value found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ not found. File Protocol\Handler\msnim - No CLSID value found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ not found. File Protocol\Handler\skype4com - No CLSID value found not found. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\wlmailhtml\ not found. File Protocol\Handler\wlmailhtml - No CLSID value found not found. 64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully. 64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ deleted successfully. Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8e003894-b227-11df-9dd3-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e003894-b227-11df-9dd3-806e6f6e6963}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8e003894-b227-11df-9dd3-806e6f6e6963}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8e003894-b227-11df-9dd3-806e6f6e6963}\ not found. File D:\AutoRun.exe not found. Folder C:\ProgramData\94F3E4571BE0C07D000094F34F69C677\ not found. File C:\ProgramData\FullRemove.exe not found. ========== FILES ========== < ipconfig /flushdns /c > Windows-IP-Konfiguration Der DNS-Auflösungscache wurde geleert. C:\Dokumente und Einstellungen\Daniel\Desktop\cmd.bat deleted successfully. C:\Dokumente und Einstellungen\Daniel\Desktop\cmd.txt deleted successfully. ========== COMMANDS ========== [EMPTYFLASH] User: Administrator User: Administrator.ARBEITSZIMMER User: Administrator.ARBEITSZIMMER.000 User: All Users User: Daniel ->Flash cache emptied: 291630 bytes User: Default User ->Flash cache emptied: 41620 bytes User: LocalService User: NetworkService Total Flash Files Cleaned = 0,00 mb [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Administrator.ARBEITSZIMMER ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: Administrator.ARBEITSZIMMER.000 ->Temp folder emptied: 2665686 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: All Users User: Daniel ->Temp folder emptied: 400384 bytes ->Temporary Internet Files folder emptied: 10189908 bytes ->Java cache emptied: 11020240 bytes ->FireFox cache emptied: 44014867 bytes ->Flash cache emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes ->Flash cache emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 1368405 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 2573386 bytes %systemroot%\System32 .tmp files removed: 2951 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 14123330 bytes RecycleBin emptied: 18833300 bytes Total Files Cleaned = 100,00 mb OTL by OldTimer - Version 3.2.69.0 log created on 06262013_130123 Files\Folders moved on Reboot... File\Folder C:\Dokumente und Einstellungen\Daniel\Lokale Einstellungen\Temporary Internet Files\Content.IE5\SQVYPCMC\index[2].php not found! C:\Dokumente und Einstellungen\Daniel\Lokale Einstellungen\Temporary Internet Files\Content.IE5\DRC5EL2E\index[3].php moved successfully. File\Folder C:\WINDOWS\temp\ZLT062ba.TMP not found! File\Folder C:\WINDOWS\temp\ZLT0727b.TMP not found! PendingFileRenameOperations files... Registry entries deleted on Reboot... |
Themen zu Befallen vom System Care Antivirus |
antivirus, befallen vom system care antivirus, browser, c:\windows, diverse, dllcache, einstellungen, explorer, internet, internet explorer, ipconfig, programm, pum.disabled.securitycenter, runonce, software, system care, system care antivirus, system32, trojan.spyeyes, version, windows |