![]() |
|
Plagegeister aller Art und deren Bekämpfung: Interpol TrojanerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Interpol Trojaner hi, Drücke bitte die ![]() Kopiere nun folgenden Text aus der Code-Box in das leere Textdokument Code:
ATTFilter Startup: C:\Users\Krise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eoadmhlatasrbhjqakk.lnk ShortcutTarget: eoadmhlatasrbhjqakk.lnk -> C:\Users\Krise\AppData\Local\Temp\kkaqjhbrsatalhmdaoe.exe () C:\Windows\SysWOW64\nvinit.dll C:\ProgramData\eoadmhlatasrbhjqakk.bat C:\ProgramData\eoadmhlatasrbhjqakk.reg C:\Users\Krise\AppData\Local\Temp\APNStub.exe C:\Users\Krise\AppData\Local\Temp\GenericUninstall.exe C:\Users\Krise\AppData\Local\Temp\kkaqjhbrsatalhmdaoe.exe C:\Users\Krise\AppData\Local\Temp\mgsqlite3.dll C:\Users\Krise\AppData\Local\Temp\MSNA5A4.exe C:\Users\Krise\AppData\Local\Temp\Shortcut_SweetIM_2.exe C:\Users\Krise\AppData\Local\Temp\SimboApp.exe C:\Users\Krise\AppData\Local\Temp\SIMEEIInstaller.exe C:\Users\Krise\AppData\Local\Temp\SmartbarExeInstaller.exe C:\Users\Krise\AppData\Local\Temp\uiofdjml.dll C:\Users\Krise\AppData\Local\Temp\uninstaller.exe C:\Users\Krise\AppData\Local\Temp\x1pcfa3i.dll C:\Users\Krise\AppData\Local\Temp\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}\mgSqlite3.dll C:\Users\Krise\AppData\Local\Temp\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}\VistaCookiesCollector.exe C:\Users\Krise\AppData\Local\Temp\{5F004995-2B5C-496A-BB64-11015FFA0965}\InstallFlashPlayer.exe C:\Users\Krise\AppData\Local\Temp\Temp2_bmp.zip\BMLOADER.EXE C:\Users\Krise\AppData\Local\Temp\Temp1_em.zip\EM.EXE C:\Users\Krise\AppData\Local\Temp\Temp1_Command_and_Conquer_Alarmstufe_Rot.zip\RedAlert1_SovietDisc\RedAlert1_SovietDisc\XP_Patch\RA108USP.EXE C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\bin.dll C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\config.dll C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\DomaIQ.exe C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\DomaIQ10.exe C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\FastColoredTextBox.dll C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\routes.dll C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\software\QuickShare1.exe.exe C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\software\SweetIM_2.exe
Das Tool erstellt eine Fixlog.txt auf deinem USB Stick. Poste den Inhalt bitte hier. Rechner normal starten ![]()
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #2 |
![]() | ![]() Interpol Trojaner Das ging ja fix. Schonmal Danke dafür und hier der Fixlog:
__________________Code:
ATTFilter Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 03-09-2013 01 Ran by SYSTEM at 2013-09-03 11:48:09 Run:1 Running from E:\ Boot Mode: Recovery ============================================== Content of fixlist: ***************** Startup: C:\Users\Krise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eoadmhlatasrbhjqakk.lnk ShortcutTarget: eoadmhlatasrbhjqakk.lnk -> C:\Users\Krise\AppData\Local\Temp\kkaqjhbrsatalhmdaoe.exe () C:\Windows\SysWOW64\nvinit.dll C:\ProgramData\eoadmhlatasrbhjqakk.bat C:\ProgramData\eoadmhlatasrbhjqakk.reg C:\Users\Krise\AppData\Local\Temp\APNStub.exe C:\Users\Krise\AppData\Local\Temp\GenericUninstall.exe C:\Users\Krise\AppData\Local\Temp\kkaqjhbrsatalhmdaoe.exe C:\Users\Krise\AppData\Local\Temp\mgsqlite3.dll C:\Users\Krise\AppData\Local\Temp\MSNA5A4.exe C:\Users\Krise\AppData\Local\Temp\Shortcut_SweetIM_2.exe C:\Users\Krise\AppData\Local\Temp\SimboApp.exe C:\Users\Krise\AppData\Local\Temp\SIMEEIInstaller.exe C:\Users\Krise\AppData\Local\Temp\SmartbarExeInstaller.exe C:\Users\Krise\AppData\Local\Temp\uiofdjml.dll C:\Users\Krise\AppData\Local\Temp\uninstaller.exe C:\Users\Krise\AppData\Local\Temp\x1pcfa3i.dll C:\Users\Krise\AppData\Local\Temp\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}\mgSqlite3.dll C:\Users\Krise\AppData\Local\Temp\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}\VistaCookiesCollector.exe C:\Users\Krise\AppData\Local\Temp\{5F004995-2B5C-496A-BB64-11015FFA0965}\InstallFlashPlayer.exe C:\Users\Krise\AppData\Local\Temp\Temp2_bmp.zip\BMLOADER.EXE C:\Users\Krise\AppData\Local\Temp\Temp1_em.zip\EM.EXE C:\Users\Krise\AppData\Local\Temp\Temp1_Command_and_Conquer_Alarmstufe_Rot.zip\RedAlert1_SovietDisc\RedAlert1_SovietDisc\XP_Patch\RA108USP.EXE C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\bin.dll C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\config.dll C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\DomaIQ.exe C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\DomaIQ10.exe C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\FastColoredTextBox.dll C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\routes.dll C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\software\QuickShare1.exe.exe C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\software\SweetIM_2.exe ***************** C:\Users\Krise\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\eoadmhlatasrbhjqakk.lnk => Moved successfully. C:\Users\Krise\AppData\Local\Temp\kkaqjhbrsatalhmdaoe.exe => Moved successfully. C:\Windows\SysWOW64\nvinit.dll => Moved successfully. C:\ProgramData\eoadmhlatasrbhjqakk.bat => Moved successfully. C:\ProgramData\eoadmhlatasrbhjqakk.reg => Moved successfully. C:\Users\Krise\AppData\Local\Temp\APNStub.exe => Moved successfully. C:\Users\Krise\AppData\Local\Temp\GenericUninstall.exe => Moved successfully. "C:\Users\Krise\AppData\Local\Temp\kkaqjhbrsatalhmdaoe.exe" => File/Directory not found. C:\Users\Krise\AppData\Local\Temp\mgsqlite3.dll => Moved successfully. C:\Users\Krise\AppData\Local\Temp\MSNA5A4.exe => Moved successfully. C:\Users\Krise\AppData\Local\Temp\Shortcut_SweetIM_2.exe => Moved successfully. C:\Users\Krise\AppData\Local\Temp\SimboApp.exe => Moved successfully. C:\Users\Krise\AppData\Local\Temp\SIMEEIInstaller.exe => Moved successfully. C:\Users\Krise\AppData\Local\Temp\SmartbarExeInstaller.exe => Moved successfully. C:\Users\Krise\AppData\Local\Temp\uiofdjml.dll => Moved successfully. C:\Users\Krise\AppData\Local\Temp\uninstaller.exe => Moved successfully. C:\Users\Krise\AppData\Local\Temp\x1pcfa3i.dll => Moved successfully. C:\Users\Krise\AppData\Local\Temp\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}\mgSqlite3.dll => Moved successfully. C:\Users\Krise\AppData\Local\Temp\{A0C9DF2B-89B5-4483-8983-18A68200F1B4}\VistaCookiesCollector.exe => Moved successfully. C:\Users\Krise\AppData\Local\Temp\{5F004995-2B5C-496A-BB64-11015FFA0965}\InstallFlashPlayer.exe => Moved successfully. C:\Users\Krise\AppData\Local\Temp\Temp2_bmp.zip\BMLOADER.EXE => Moved successfully. C:\Users\Krise\AppData\Local\Temp\Temp1_em.zip\EM.EXE => Moved successfully. C:\Users\Krise\AppData\Local\Temp\Temp1_Command_and_Conquer_Alarmstufe_Rot.zip\RedAlert1_SovietDisc\RedAlert1_SovietDisc\XP_Patch\RA108USP.EXE => Moved successfully. C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\bin.dll => Moved successfully. C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\config.dll => Moved successfully. C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\DomaIQ.exe => Moved successfully. C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\DomaIQ10.exe => Moved successfully. C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\FastColoredTextBox.dll => Moved successfully. C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\routes.dll => Moved successfully. C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\software\QuickShare1.exe.exe => Moved successfully. C:\Users\Krise\AppData\Local\Temp\DM\zipper_047\software\SweetIM_2.exe => Moved successfully. ==== End of Fixlog ==== |
![]() |