![]() |
| |||||||
Log-Analyse und Auswertung: OTL - Logfiles MalwareWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #8 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | OTL - Logfiles Malware Mach einen OTL-Fix, beende alle evtl. geöffneten Programme, auch Virenscanner deaktivieren (!), starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code:
ATTFilter :OTL
SRV - (TOSHIBA Bluetooth Service) -- File not found
SRV - (OMSI download service) -- File not found
SRV - (mysql) -- File not found
SRV - (Apache2.2) -- File not found
SRV - (AMService) -- File not found
SRV - (ICQ Service) -- C:\Programme\ICQ6Toolbar\ICQ Service.exe ()
SRV - (SearchAnonymizer) -- C:\Users\Tobbi\AppData\Roaming\OCS\SM\SearchAnonymizerHelper.exe ()
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://de.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://de.search.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://de.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://de.search.yahoo.com
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com
IE - HKLM\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKLM\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKLM\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: - Reg Error: Key error. File not found
IE - HKCU\..\URLSearchHook: {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Programme\Freecorder\tbFree.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
IE - HKCU\..\URLSearchHook: {9CB65206-89C4-402c-BA80-02D8C59F9B1D} - File not found
IE - HKCU\..\URLSearchHook: {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgHelper.dll (SweetIM Technologies Ltd.)
FF - prefs.js..browser.search.defaultenginename: "ICQ Search"
FF - prefs.js..browser.search.defaulturl: "http://search.live.com/results.aspx?FORM=IEFM1&q="
FF - prefs.js..browser.search.selectedEngine: "ICQ Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..keyword.URL: "http://search.icq.com/search/afe_results.php?ch_id=afex&tb_ver=1.1.7&q="
[2008.01.01 18:03:23 | 000,000,000 | ---D | M] (Freecorder Toolbar) -- C:\Users\Tobbi\AppData\Roaming\mozilla\Firefox\Profiles\rrvwok9c.default\extensions\{1392b8d2-5c05-419f-a8f6-b9f15a596612}(102)
[2011.03.08 14:55:13 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Users\Tobbi\AppData\Roaming\mozilla\Firefox\Profiles\rrvwok9c.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2011.03.08 14:55:12 | 000,000,000 | ---D | M] (Yahoo! Toolbar) -- C:\Users\Tobbi\AppData\Roaming\mozilla\Firefox\Profiles\rrvwok9c.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2010.11.15 15:09:30 | 000,000,000 | ---D | M] ("ICQ Toolbar") -- C:\Users\Tobbi\AppData\Roaming\mozilla\Firefox\Profiles\rrvwok9c.default\extensions\{800b5000-a755-47e1-992b-48a1c1357f07}
[2008.09.29 17:33:36 | 000,000,000 | ---D | M] ("Ask Toolbar for Firefox") -- C:\Users\Tobbi\AppData\Roaming\mozilla\Firefox\Profiles\rrvwok9c.default\extensions\{E9A1DEE0-C623-4439-8932-001E7D17607D}
[2011.03.08 14:54:42 | 000,000,000 | ---D | M] ("DAEMON Tools Toolbar") -- C:\Users\Tobbi\AppData\Roaming\mozilla\Firefox\Profiles\rrvwok9c.default\extensions\DTToolbar@toolbarnet.com
[2008.03.28 12:56:30 | 000,000,000 | ---D | M] (OpenTaal woordenlijst) -- C:\Users\Tobbi\AppData\Roaming\mozilla\Firefox\Profiles\rrvwok9c.default\extensions\nl_NL@opentaal.org
[2010.05.01 17:27:00 | 000,001,067 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-1.xml
[2010.05.01 17:27:00 | 000,001,067 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-10.xml
[2010.11.26 18:26:53 | 000,000,950 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-11.xml
[2011.03.09 22:45:32 | 000,000,950 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-12.xml
[2011.03.31 21:30:06 | 000,000,950 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-13.xml
[2010.05.01 17:27:00 | 000,001,067 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-2.xml
[2010.05.01 17:27:00 | 000,001,067 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-3.xml
[2010.05.01 17:27:00 | 000,001,067 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-4.xml
[2010.05.01 17:27:00 | 000,001,067 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-5.xml
[2010.05.01 17:27:00 | 000,001,067 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-6.xml
[2010.05.01 17:27:00 | 000,001,067 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-7.xml
[2010.05.01 17:27:00 | 000,001,067 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-8.xml
[2010.05.01 17:27:00 | 000,001,067 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin-9.xml
[2010.11.15 15:09:30 | 000,000,168 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin.gif
[2010.11.15 15:09:30 | 000,000,618 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin.src
[2010.06.21 17:35:24 | 000,001,042 | ---- | M] () -- C:\Users\Tobbi\AppData\Roaming\Mozilla\Firefox\Profiles\rrvwok9c.default\searchplugins\icqplugin.xml
O2 - BHO: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Programme\Freecorder\tbFree.dll (Conduit Ltd.)
O2 - BHO: (PDF Suite Helper) - {1AD61D5B-58A3-4592-9B34-DC84688FF805} - C:\Programme\PDF Suite\PDFIEHelper.dll (Interactive Brands)
O2 - BHO: (AskBar BHO) - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:\Programme\AskBarDis\bar\bin\askBar.dll (Ask.com)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - File not found
O2 - BHO: (Ask Search Assistant BHO) - {9CB65201-89C4-402c-BA80-02D8C59F9B1D} - File not found
O2 - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\Programme\Google\GoogleToolbar1.dll (Google Germany GmbH)
O2 - BHO: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
O2 - BHO: (SweetIM Toolbar Helper) - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O2 - BHO: (SMTTB2009 Class) - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - File not found
O2 - BHO: (Ask Toolbar BHO) - {FE063DB1-4EC0-403e-8DD8-394C54984B2C} - File not found
O3 - HKLM\..\Toolbar: (Freecorder Toolbar) - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Programme\Freecorder\tbFree.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (PDF Suite Toolbar) - {261F6A8B-7AAF-4BF5-8552-6610F4D67819} - C:\Programme\PDF Suite\PDFIEPlugin.dll (Interactive Brands)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:\Programme\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Programme\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKLM\..\Toolbar: (HyperCam Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - File not found
O3 - HKLM\..\Toolbar: (ICQToolBar) - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKLM\..\Toolbar: (@msdxmLC.dll,-1@1033,&Radio) - {8E718888-423F-11D2-876E-00A0C9082467} - C:\Windows\System32\Msdxm6.ocx (Microsoft Corporation)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - File not found
O3 - HKLM\..\Toolbar: (softonic-de3 Toolbar) - {cc05a3e3-64c3-4af2-bfc1-af0d66b69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {FE063DB9-4EC0-403e-8DD8-394C54984B2C} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Freecorder Toolbar) - {1392B8D2-5C05-419F-A8F6-B9F15A596612} - C:\Programme\Freecorder\tbFree.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (&Google) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - c:\Programme\Google\GoogleToolbar1.dll (Google Germany GmbH)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {3041D03E-FD4B-44E0-B742-2D9B88305F98} - C:\Programme\AskBarDis\bar\bin\askBar.dll (Ask.com)
O3 - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Programme\DAEMON Tools Toolbar\DTToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (HyperCam Toolbar) - {338B4DFE-2E2C-4338-9E41-E176D497299E} - File not found
O3 - HKCU\..\Toolbar\WebBrowser: (ICQToolBar) - {855F3B16-6D32-4FE6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll (ICQ)
O3 - HKCU\..\Toolbar\WebBrowser: (softonic-de3 Toolbar) - {CC05A3E3-64C3-4AF2-BFC1-AF0D66B69065} - C:\Programme\softonic-de3\tbsoft.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (SweetIM Toolbar for Internet Explorer) - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\Programme\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll (SweetIM Technologies Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {FE063DB9-4EC0-403E-8DD8-394C54984B2C} - File not found
O4 - HKLM..\Run: [QuickTime Task] File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006.09.18 23:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O32 - AutoRun File - [2007.04.18 19:37:34 | 000,000,029 | R--- | M] () - D:\AUTORUN.INF -- [ CDFS ]
O33 - MountPoints2\{4f877a83-55d7-11df-8521-0016d4b37dc6}\Shell - "" = AutoRun
O33 - MountPoints2\{4f877a83-55d7-11df-8521-0016d4b37dc6}\Shell\AutoRun\command - "" = E:\feprog.exe
O33 - MountPoints2\{7926035b-948a-11dc-a710-806e6f6e6963}\Shell - "" = AutoRun
O33 - MountPoints2\{7926035b-948a-11dc-a710-806e6f6e6963}\Shell\AutoRun\command - "" = D:\EPSetup.exe -- [2009.12.11 07:02:00 | 000,129,000 | R--- | M] (Seiko Epson Corporation)
[2011.04.18 09:46:13 | 000,000,000 | ---D | C] -- C:\Programme\iqbfuljh
[2011.04.16 09:34:49 | 000,000,000 | ---D | C] -- C:\Users\Tobbi\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Windows Recovery
[2011.03.26 11:32:16 | 000,000,000 | -HSD | C] -- C:\Users\Tobbi\AppData\Roaming\wyUpdate AU
[2011.04.16 09:34:53 | 000,000,160 | -H-- | C] () -- C:\ProgramData\~34725640r
[2011.04.16 09:34:52 | 000,000,120 | -H-- | C] () -- C:\ProgramData\~34725640
[2011.04.16 09:34:43 | 000,000,384 | -H-- | C] () -- C:\ProgramData\34725640
[2009.01.28 21:54:06 | 000,380,944 | -H-- | C] () -- C:\ProgramData\Bows Cake Cake.4nvgj3u
[2009.01.28 21:32:02 | 000,036,880 | -H-- | C] () -- C:\ProgramData\Bows Cake Cake.lx81nh
[2009.01.28 21:10:04 | 000,344,080 | -H-- | C] () -- C:\ProgramData\Bows Cake Cake.xbitq
[2009.01.02 13:15:44 | 000,315,408 | -H-- | C] () -- C:\ProgramData\acid loud meow.fpen6
[2009.01.02 13:15:38 | 000,315,408 | -H-- | C] () -- C:\ProgramData\Bows Cake Cake.ta4pck
[2009.01.02 13:15:38 | 000,245,776 | -H-- | C] () -- C:\ProgramData\Bows Cake Cake.qixnu
[2008.12.26 23:42:29 | 000,237,584 | -H-- | C] () -- C:\ProgramData\start software cake.ue1rax
[2008.12.26 23:42:12 | 000,057,360 | -H-- | C] () -- C:\ProgramData\Bows Cake Cake.4s5co5
[2008.12.17 14:41:08 | 000,311,312 | -H-- | C] () -- C:\ProgramData\Bows Cake Cake.qmsz66q
[2008.10.23 19:14:38 | 000,077,840 | -H-- | C] () -- C:\ProgramData\Meal Ace Base.me7jd
[2008.10.23 19:13:56 | 000,180,240 | -H-- | C] () -- C:\ProgramData\Bows Cake Cake.vk4otw6
[2008.10.01 12:49:45 | 000,094,224 | -H-- | C] () -- C:\ProgramData\Bows Cake Cake.io9x1
[2008.09.14 18:53:02 | 000,364,560 | -H-- | C] () -- C:\ProgramData\Bows Cake Cake.3sfreb9
:Commands
[purity]
[resethosts]
[emptytemp]
Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. Die mit diesem Script gefixten Einträge, Dateien und Ordner werden zur Sicherheit nicht vollständig gelöscht, es wird eine Sicherheitskopie auf der Systempartition im Ordner "_OTL" erstellt.
__________________ Logfiles bitte immer in CODE-Tags posten |
| Themen zu OTL - Logfiles Malware |
| antivir, beiträge, folge, folgendes, forum, hochgefahren, hoffe, logfiles, malwar, malware, malwarebytes, programm, recovery, rkill, scan, schonmal, sekunden, starte, viren, virus, windows, windows recovery, zwischen |