Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   "Das System wird aus Sicherheitsgründen heruntergefahren...." (https://www.trojaner-board.de/105957-system-sicherheitsgruenden-heruntergefahren.html)

Babalou001 08.12.2011 11:53

"Das System wird aus Sicherheitsgründen heruntergefahren...."
 
Hallo zusammen,

nun hat es mich auch erwischt. Nach 5 Minuten Arbeit erscheint das berühmte Bild "Das System wird aus Sicherheitsgründen blockiert", zahlen Sie 50 Euro.....
Für Hilfe bin ich dankbar.
Das Bild lässt sich nicht schliessen, sieht aber so aus als würde der PC im Hintergrund "normal" arbeiten........
Dateien habe ich angehängt.

markusg 08.12.2011 13:32

dieses script sowie evtl. folgende scripts sind nur für den jeweiligen user.
wenn ihr probleme habt, eröffnet eigene topics und wartet auf, für euch angepasste scripts.


• Starte bitte die OTL.exe
• Kopiere nun das Folgende in die Textbox.



Code:

:OTL
O4 - HKCU..\Run: [{C28B241D-D64A-11E0-8CF9-806D6172696F}] C:\Dokumente und Einstellungen\Meister\Anwendungsdaten\Microsoft\svhcost.exe (Mozilla Foundation)
O33 - MountPoints2\{270294bb-f5a8-11e0-ad45-00301bba403e}\Shell\AutoRun\command - "" = RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{270294bb-f5a8-11e0-ad45-00301bba403e}\Shell\explore\Command - "" = RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{270294bb-f5a8-11e0-ad45-00301bba403e}\Shell\open\command - "" = RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{2c39e466-f671-11e0-ad46-00301bba403e}\Shell\AutoRun\command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{2c39e466-f671-11e0-ad46-00301bba403e}\Shell\explore\Command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{2c39e466-f671-11e0-ad46-00301bba403e}\Shell\open\command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{30d11c93-dc80-11e0-ad27-00301bba403e}\Shell\AutoRun\command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{30d11c93-dc80-11e0-ad27-00301bba403e}\Shell\explore\Command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{30d11c93-dc80-11e0-ad27-00301bba403e}\Shell\open\command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{673cbff2-d63c-11e0-ad1e-a8cbc6247538}\Shell - "" = AutoRun
O33 - MountPoints2\{673cbff2-d63c-11e0-ad1e-a8cbc6247538}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{673cbff2-d63c-11e0-ad1e-a8cbc6247538}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE  .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{673cbff3-d63c-11e0-ad1e-a8cbc6247538}\Shell - "" = AutoRun
O33 - MountPoints2\{673cbff3-d63c-11e0-ad1e-a8cbc6247538}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{673cbff3-d63c-11e0-ad1e-a8cbc6247538}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE  .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{673cbff9-d63c-11e0-ad1e-a8cbc6247538}\Shell\AutoRun\command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{673cbff9-d63c-11e0-ad1e-a8cbc6247538}\Shell\explore\Command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{673cbff9-d63c-11e0-ad1e-a8cbc6247538}\Shell\open\command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{8727c358-e077-11e0-ad2a-00301bba403e}\Shell\AutoRun\command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{8727c358-e077-11e0-ad2a-00301bba403e}\Shell\explore\Command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{8727c358-e077-11e0-ad2a-00301bba403e}\Shell\open\command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{99ec7a75-edaa-11e0-ad3c-00301bba403e}\Shell\AutoRun\command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{99ec7a75-edaa-11e0-ad3c-00301bba403e}\Shell\explore\Command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{99ec7a75-edaa-11e0-ad3c-00301bba403e}\Shell\open\command - "" = E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{9dd2c989-0956-11e1-ad5c-00301bba403e}\Shell - "" = AutoRun
O33 - MountPoints2\{9dd2c989-0956-11e1-ad5c-00301bba403e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{9dd2c989-0956-11e1-ad5c-00301bba403e}\Shell\AutoRun\command - "" = E:\DIYWriter.exe
O33 - MountPoints2\{e0d88a03-02e8-11e1-ad55-00301bba403e}\Shell - "" = AutoRun
O33 - MountPoints2\{e0d88a03-02e8-11e1-ad55-00301bba403e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e0d88a03-02e8-11e1-ad55-00301bba403e}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE      .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{e0d88a04-02e8-11e1-ad55-00301bba403e}\Shell\AutoRun\command - "" = F:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{e0d88a04-02e8-11e1-ad55-00301bba403e}\Shell\explore\Command - "" = F:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{e0d88a04-02e8-11e1-ad55-00301bba403e}\Shell\open\command - "" = F:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{e0d88a05-02e8-11e1-ad55-00301bba403e}\Shell - "" = AutoRun
O33 - MountPoints2\{e0d88a05-02e8-11e1-ad55-00301bba403e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e0d88a05-02e8-11e1-ad55-00301bba403e}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE      .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{e0d88a08-02e8-11e1-ad55-00301bba403e}\Shell - "" = AutoRun
O33 - MountPoints2\{e0d88a08-02e8-11e1-ad55-00301bba403e}\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\{e0d88a08-02e8-11e1-ad55-00301bba403e}\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE      .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
O33 - MountPoints2\{e0d88a09-02e8-11e1-ad55-00301bba403e}\Shell\AutoRun\command - "" = G:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{e0d88a09-02e8-11e1-ad55-00301bba403e}\Shell\explore\Command - "" = G:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\{e0d88a09-02e8-11e1-ad55-00301bba403e}\Shell\open\command - "" = G:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe
O33 - MountPoints2\E\Shell - "" = AutoRun
O33 - MountPoints2\E\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\E\Shell\AutoRun\command - "" = E:\DIYWriter.exe
O33 - MountPoints2\G\Shell - "" = AutoRun
O33 - MountPoints2\G\Shell\AutoRun - "" = Auto&Play
O33 - MountPoints2\G\Shell\AutoRun\command - "" = C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE  .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn
[2011.12.01 16:56:41 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\5052
[2011.11.29 15:55:00 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\5051
[2011.11.25 17:57:14 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\5050
[2011.11.24 17:23:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\5049
[2011.11.23 16:53:05 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\5048
[2011.11.22 16:41:45 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\5047
[2011.11.21 16:55:25 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\5045
[2011.11.20 14:05:21 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\5044
[2011.11.18 20:09:44 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\5043
[2011.11.17 16:04:36 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\5042
[2011.11.16 11:18:04 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\5041
[2011.11.15 14:11:02 | 000,000,000 | ---D | C] -- C:\WINDOWS\System32\5040
:Files
C:\Dokumente und Einstellungen\Meister\Anwendungsdaten\Microsoft\svhcost.exe
:Commands
[purity]
[EMPTYFLASH]
[emptytemp]
[Reboot]



• Schliesse bitte nun alle Programme.
• Klicke nun bitte auf den Fix Button.
• OTL kann gegebenfalls einen Neustart verlangen. Bitte dies zulassen.
• Nach dem Neustart findest Du ein Textdokument, dessen inhalt in deiner nächsten antwort hier reinkopieren.
starte in den normalen modus.

falls du keine symbole hast, dann rechtsklick, ansicht, desktop symbole einblenden

öffne computer, öffne C: dann _OTL
dort rechtsklick auf moved files
wähle zu moved files.rar oder zip hinzufügen.
folge dem link, und lade das archiv im upload channel hoch
http://www.trojaner-board.de/54791-a...ner-board.html

Babalou001 08.12.2011 16:54

All processes killed
========== OTL ==========
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\{C28B241D-D64A-11E0-8CF9-806D6172696F} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C28B241D-D64A-11E0-8CF9-806D6172696F}\ not found.
C:\Dokumente und Einstellungen\Meister\Anwendungsdaten\Microsoft\svhcost.exe moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{270294bb-f5a8-11e0-ad45-00301bba403e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{270294bb-f5a8-11e0-ad45-00301bba403e}\ not found.
File C:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{270294bb-f5a8-11e0-ad45-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{270294bb-f5a8-11e0-ad45-00301bba403e}\ not found.
File C:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{270294bb-f5a8-11e0-ad45-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{270294bb-f5a8-11e0-ad45-00301bba403e}\ not found.
File C:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2c39e466-f671-11e0-ad46-00301bba403e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2c39e466-f671-11e0-ad46-00301bba403e}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2c39e466-f671-11e0-ad46-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2c39e466-f671-11e0-ad46-00301bba403e}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2c39e466-f671-11e0-ad46-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2c39e466-f671-11e0-ad46-00301bba403e}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30d11c93-dc80-11e0-ad27-00301bba403e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30d11c93-dc80-11e0-ad27-00301bba403e}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30d11c93-dc80-11e0-ad27-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30d11c93-dc80-11e0-ad27-00301bba403e}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{30d11c93-dc80-11e0-ad27-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{30d11c93-dc80-11e0-ad27-00301bba403e}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{673cbff2-d63c-11e0-ad1e-a8cbc6247538}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673cbff2-d63c-11e0-ad1e-a8cbc6247538}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{673cbff2-d63c-11e0-ad1e-a8cbc6247538}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673cbff2-d63c-11e0-ad1e-a8cbc6247538}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{673cbff2-d63c-11e0-ad1e-a8cbc6247538}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673cbff2-d63c-11e0-ad1e-a8cbc6247538}\ not found.
File C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{673cbff3-d63c-11e0-ad1e-a8cbc6247538}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673cbff3-d63c-11e0-ad1e-a8cbc6247538}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{673cbff3-d63c-11e0-ad1e-a8cbc6247538}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673cbff3-d63c-11e0-ad1e-a8cbc6247538}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{673cbff3-d63c-11e0-ad1e-a8cbc6247538}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673cbff3-d63c-11e0-ad1e-a8cbc6247538}\ not found.
File C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{673cbff9-d63c-11e0-ad1e-a8cbc6247538}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673cbff9-d63c-11e0-ad1e-a8cbc6247538}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{673cbff9-d63c-11e0-ad1e-a8cbc6247538}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673cbff9-d63c-11e0-ad1e-a8cbc6247538}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{673cbff9-d63c-11e0-ad1e-a8cbc6247538}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{673cbff9-d63c-11e0-ad1e-a8cbc6247538}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8727c358-e077-11e0-ad2a-00301bba403e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8727c358-e077-11e0-ad2a-00301bba403e}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8727c358-e077-11e0-ad2a-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8727c358-e077-11e0-ad2a-00301bba403e}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{8727c358-e077-11e0-ad2a-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8727c358-e077-11e0-ad2a-00301bba403e}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{99ec7a75-edaa-11e0-ad3c-00301bba403e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99ec7a75-edaa-11e0-ad3c-00301bba403e}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{99ec7a75-edaa-11e0-ad3c-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99ec7a75-edaa-11e0-ad3c-00301bba403e}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{99ec7a75-edaa-11e0-ad3c-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{99ec7a75-edaa-11e0-ad3c-00301bba403e}\ not found.
File E:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9dd2c989-0956-11e1-ad5c-00301bba403e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9dd2c989-0956-11e1-ad5c-00301bba403e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9dd2c989-0956-11e1-ad5c-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9dd2c989-0956-11e1-ad5c-00301bba403e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9dd2c989-0956-11e1-ad5c-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9dd2c989-0956-11e1-ad5c-00301bba403e}\ not found.
File E:\DIYWriter.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a03-02e8-11e1-ad55-00301bba403e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a03-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a03-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a03-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a03-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a03-02e8-11e1-ad55-00301bba403e}\ not found.
File C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a04-02e8-11e1-ad55-00301bba403e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a04-02e8-11e1-ad55-00301bba403e}\ not found.
File F:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a04-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a04-02e8-11e1-ad55-00301bba403e}\ not found.
File F:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a04-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a04-02e8-11e1-ad55-00301bba403e}\ not found.
File F:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a05-02e8-11e1-ad55-00301bba403e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a05-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a05-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a05-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a05-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a05-02e8-11e1-ad55-00301bba403e}\ not found.
File C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a08-02e8-11e1-ad55-00301bba403e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a08-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a08-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a08-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a08-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a08-02e8-11e1-ad55-00301bba403e}\ not found.
File C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RuNdLl32.EXE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a09-02e8-11e1-ad55-00301bba403e}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a09-02e8-11e1-ad55-00301bba403e}\ not found.
File G:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a09-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a09-02e8-11e1-ad55-00301bba403e}\ not found.
File G:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{e0d88a09-02e8-11e1-ad55-00301bba403e}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{e0d88a09-02e8-11e1-ad55-00301bba403e}\ not found.
File G:\RECYCLER\S-1-5-21-2214276341-3544434524-6043330-4321\update.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\E\ not found.
File E:\DIYWriter.exe not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\G\ not found.
File C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL RUNdLl32.ExE .\RECYCLER\S-5-3-42-2819952290-8240758988-879315005-3665\jwgkvsq.vmx,ahaezedrn not found.
C:\WINDOWS\System32\5052\components folder moved successfully.
C:\WINDOWS\System32\5052 folder moved successfully.
C:\WINDOWS\System32\5051\components folder moved successfully.
C:\WINDOWS\System32\5051 folder moved successfully.
C:\WINDOWS\System32\5050\components folder moved successfully.
C:\WINDOWS\System32\5050 folder moved successfully.
C:\WINDOWS\System32\5049\components folder moved successfully.
C:\WINDOWS\System32\5049 folder moved successfully.
C:\WINDOWS\System32\5048\components folder moved successfully.
C:\WINDOWS\System32\5048 folder moved successfully.
C:\WINDOWS\System32\5047\components folder moved successfully.
C:\WINDOWS\System32\5047 folder moved successfully.
C:\WINDOWS\System32\5045\components folder moved successfully.
C:\WINDOWS\System32\5045 folder moved successfully.
C:\WINDOWS\System32\5044\components folder moved successfully.
C:\WINDOWS\System32\5044 folder moved successfully.
C:\WINDOWS\System32\5043\components folder moved successfully.
C:\WINDOWS\System32\5043 folder moved successfully.
C:\WINDOWS\System32\5042\components folder moved successfully.
C:\WINDOWS\System32\5042 folder moved successfully.
C:\WINDOWS\System32\5041\components folder moved successfully.
C:\WINDOWS\System32\5041 folder moved successfully.
C:\WINDOWS\System32\5040\components folder moved successfully.
C:\WINDOWS\System32\5040 folder moved successfully.
========== FILES ==========
File\Folder C:\Dokumente und Einstellungen\Meister\Anwendungsdaten\Microsoft\svhcost.exe not found.
========== COMMANDS ==========

[EMPTYFLASH]

User: All Users

User: Default User

User: LocalService

User: Meister
->Flash cache emptied: 2197 bytes

User: NetworkService

Total Flash Files Cleaned = 0,00 mb


[EMPTYTEMP]

User: All Users

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 392978 bytes

User: Meister
->Temp folder emptied: 12423447 bytes
->Temporary Internet Files folder emptied: 278729 bytes
->Java cache emptied: 41140 bytes
->FireFox cache emptied: 69755407 bytes
->Flash cache emptied: 0 bytes

User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 1119608 bytes
%systemroot%\System32 .tmp files removed: 24103 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 49152 bytes
RecycleBin emptied: 51043 bytes

Total Files Cleaned = 80,00 mb


OTL by OldTimer - Version 3.2.31.0 log created on 12082011_164516

Files\Folders moved on Reboot...

Registry entries deleted on Reboot...

Babalou001 08.12.2011 16:55

Ober der Inhalt der Textdatei, die moved-files habe ich über den upload-Channel hochgeladen. Danke.

markusg 08.12.2011 17:08

man dankt.
du scheinst infizierte wechseldatenträger (usb sticks) zb zu haben.
deaktiviere autorun:
Tipparchiv - Autorun/Autoplay gezielt für Laufwerkstypen oder -buchstaben abschalten - WinTotal.de
wie viele wechseldatenträger hast du im moment und kannst du einige davon formatieren? damit sparen wir evtl. zeit :-)

Babalou001 09.12.2011 13:28

Hallo. Hm, es sind schon einige USB-Sticks die ich im Einsatz habe, viele mit Musik fürs Auto und einige mit Filmen für den DVD-Player. Weiterhin sind noch 3 x 1 Terabyte externe Festplatten wechselnd im Einsatz. Die Meldung ist jedoch seit gestern verschwunden und das System lief problemlos 2 Stunden durch. Trotzdem werde ich die USB-Sticks mal formatieren. Wenn autoplay/autorun deaktiviert ist kann ich die Dateien ja "problemlos" kopieren und die autorun.inf "killen"...... (Wobei: Zum Zeitpunkt der ersten Erscheinung dieser netten Meldung waren keine USB-Sticks an den Rechner angeschlossen...)

markusg 09.12.2011 14:09

die meldung und deine infizierten sticks sind zwei paar schuhe.
wir sind sowieso noch nicht durch, davon mal ganz abgesehen.
formatiere mal alle wechseldatenträger, bei denen das geht, zb sticks fürs auto etc, die kann man ja neu bespielen, die andern können wir dann prüfen

Babalou001 09.12.2011 14:34

Alles klar, werde ich mal in Angriff nehmen. :-)
Sobald ich diese Wechseldazenträger formatiert habe
sage ich Bescheid. Danke.

Babalou001 12.12.2011 12:49

Hallo. So, alle USB-Sticks und Speicherkarten sind formatiert, ein Stick hatte bei der autorun.inf - laut Virnscanner - eine "Infektion".

markusg 12.12.2011 15:32

sehr gut.
autorun bleibt in zukunft aus, das ist nämlich ne infektionsquelle wie du gesehen hast.

malwarebytes:
Downloade Dir bitte Malwarebytes
  • Installiere
    das Programm in den vorgegebenen Pfad.
    Vista und Win7 User mit Rechtsklick "als Administrator starten"
  • Starte Malwarebytes, klicke auf Aktualisierung --> Suche
    nach Aktualisierung
  • Wenn das Update beendet wurde, aktiviere vollständiger Scan durchführen und drücke auf Scannen.
  • Wenn der Scan beendet
    ist, klicke auf Ergebnisse anzeigen.
  • Versichere Dich, dass alle Funde markiert sind und drücke Entferne Auswahl.
  • Poste
    das Logfile, welches sich in Notepad öffnet, hier in den Thread.
  • Nachträglich kannst du den Bericht unter "Log Dateien" finden.

Babalou001 14.12.2011 09:12

Hallo. Danke für die Info. Werde das Programm laden und wie beschrieben ausführen. Melde mich dann wieder. Danke.

Babalou001 14.12.2011 09:14

Hallo. Danke für die Info. Ja, autorun bleibt aus. ;-)
Ich lade mir das Programm runter und führe es wie beschrieben aus. Danke.
Ich melde mich dann wieder...


Alle Zeitangaben in WEZ +1. Es ist jetzt 07:23 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129