Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   pc gesperrt, nichts funktioniert mehr (https://www.trojaner-board.de/121149-pc-gesperrt-nichts-funktioniert-mehr.html)

sil86 07.08.2012 08:47

LOGFILE Text

sil86 07.08.2012 10:15

alles super gelaufen, vielen vielen dank!! funktioniert wieder einwandfrei..

nur beim starten kommt immer eine fehlermeldung, dass das modul nicht ausgewählt werden kann??

was heißt das??

t'john 07.08.2012 13:19

Wo ist das Logfile vom Fix?
(siehe Anleitung)

sil86 07.08.2012 14:59

ich habe eigentlich gedacht, dass ich das schon reinkopiert habe, aber irgendwie ... wohl nicht!

Kann ich das noch nachträglich machen?

und bitte antwort auf meine frage! :-)

t'john 07.08.2012 15:05

Nachträglich kannst Du das Logfile hier einsehen => C:\_OTL\MovedFiles\<datum_nummer.log>

darum kuemmern wir uns noch, alles der Reihe nach.

Mit dem Rechner nicht rumsurfen!

sil86 07.08.2012 15:46

ist das ok?

hab grad gesehen, dass da eine fehlermeldung kommt, deshalb kann ich es nicht hochladen!!

ungültige datei steht da!!

t'john 07.08.2012 15:53

Hast du es gefunden?

sil86 08.08.2012 14:09

was sollen wir jetzt machen?

t'john 08.08.2012 14:49

Oeffne die Datei mit dem Editor und fuege es in deinen Beitrag ein!

sil86 09.08.2012 10:46

All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_USERS\S-1-5-21-3065508809-3451257884-3724154575-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3065508809-3451257884-3724154575-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-3065508809-3451257884-3724154575-1000\Software\Microsoft\Internet Explorer\SearchScopes\{274BB8D1-AAF3-49D8-A9A0-61F18F09D9F7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{274BB8D1-AAF3-49D8-A9A0-61F18F09D9F7}\ not found.
HKU\S-1-5-21-3065508809-3451257884-3724154575-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings\\ProxyEnable|dword:0 /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\Software\MozillaPlugins\@microsoft.com/GENUINE\ deleted successfully.
Registry value HKEY_USERS\S-1-5-21-3065508809-3451257884-3724154575-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Userinit deleted successfully.
Registry value HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot.
Registry value HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\RunOnce\\mctadmin deleted successfully.
File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorAdmin deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\ConsentPromptBehaviorUser deleted successfully.
Starting removal of ActiveX control {8AD9C840-044E-11D1-B3E9-00805F499D93}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{8AD9C840-044E-11D1-B3E9-00805F499D93}\ not found.
Starting removal of ActiveX control {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA}\ not found.
Starting removal of ActiveX control {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
C:\Windows\Downloaded Program Files\gp.inf not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Code Store Database\Distribution Units\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Active Setup\Installed Components\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E2883E8F-472F-4FB0-9522-AC9BF37916A7}\ not found.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\VMApplet:/pagefile deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\\WebCheck deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\ not found.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
C:\autoexec.bat moved successfully.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4f5d73d0-a7c4-11e0-92b2-806e6f6e6963}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4f5d73d0-a7c4-11e0-92b2-806e6f6e6963}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{4f5d73d0-a7c4-11e0-92b2-806e6f6e6963}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{4f5d73d0-a7c4-11e0-92b2-806e6f6e6963}\ not found.
File D:\setup.exe not found.
C:\ProgramData\zak_lo0i7g.pad moved successfully.
C:\Users\Alexander\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.lnk moved successfully.
C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job moved successfully.
File C:\Users\Alexander\AppData\Roaming\BAcroIEHelpe153.dll not found.
C:\Users\Alexander\AppData\Roaming\blckdom.res moved successfully.
C:\Users\Alexander\AppData\Roaming\kock folder moved successfully.
C:\Users\Alexander\AppData\Roaming\UAs folder moved successfully.
C:\Users\Alexander\AppData\Roaming\xmldm folder moved successfully.
========== FILES ==========
C:\Users\ALEXAN~1\AppData\Local\Temp\g7i0ol_kaz.exe moved successfully.
< ipconfig /flushdns /c >
Windows-IP-Konfiguration
Der DNS-Aufl”sungscache wurde geleert.
C:\Users\Alexander\Desktop\cmd.bat deleted successfully.
C:\Users\Alexander\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: Alexander
->Temp folder emptied: 346060532 bytes
->Temporary Internet Files folder emptied: 1635205008 bytes
->Java cache emptied: 3280074 bytes
->Google Chrome cache emptied: 13597289 bytes
->Flash cache emptied: 20093 bytes

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 349095687 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 2.239,00 mb


[EMPTYFLASH]

User: Alexander
->Flash cache emptied: 0 bytes

User: All Users

User: Default

User: Default User

User: Public

Total Flash Files Cleaned = 0,00 mb


OTL by OldTimer - Version 3.2.55.0 log created on 08072012_092947

Files\Folders moved on Reboot...
File move failed. C:\Windows\System32\mctadmin.exe scheduled to be moved on reboot.

PendingFileRenameOperations files...
[2009.07.14 03:14:23 | 000,093,696 | ---- | M] (Microsoft Corporation) C:\Windows\System32\mctadmin.exe : MD5=BBA1A5B86134F496B926DDAF247DB871

Registry entries deleted on Reboot...

t'john 09.08.2012 10:53

Sehr gut! :daumenhoc

Wie laeuft der Rechner?

1. Schritt
Bitte einen Vollscan mit Malwarebytes Anti-Malware machen und Log posten.
Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss!

Malwarebytes Anti-Malware
- Anwendbar auf Windows 2000, XP, Vista und 7.
- Installiere das Programm in den vorgegebenen Pfad.
- Aktualisiere die Datenbank!
- Aktiviere "Komplett Scan durchführen" => Scan.
- Wähle alle verfügbaren Laufwerke (ausser CD/DVD) aus und starte den Scan.
- Funde bitte löschen lassen oder in Quarantäne.
- Wenn der Scan beendet ist, klicke auf "Zeige Resultate".
danach:

2. Schritt

Downloade Dir bitte AdwCleaner auf deinen Desktop.

  • Starte die adwcleaner.exe mit einem Doppelklick.
  • Klicke auf Search.
  • Nach Ende des Suchlaufs öffnet sich eine Textdatei.
  • Poste mir den Inhalt mit deiner nächsten Antwort.
  • Die Logdatei findest du auch unter C:\AdwCleaner[R1].txt.

sil86 09.08.2012 12:07

# AdwCleaner v1.800 - Logfile created 08/09/2012 at 13:05:30
# Updated 01/08/2012 by Xplode
# Operating system : Windows 7 Professional Service Pack 1 (32 bits)
# User : Alexander - ALEXANDER-PC
# Running from : C:\Users\Alexander\Downloads\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****


***** [Registry] *****


***** [Registre - GUID] *****


***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16421

[OK] Registry is clean.

-\\ Google Chrome v21.0.1180.60

File : C:\Users\Alexander\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [687 octets] - [09/08/2012 13:05:30]

########## EOF - C:\AdwCleaner[R1].txt - [814 octets] ##########

t'john 09.08.2012 12:10

Bitte das Malwarebytes Log posten

sil86 09.08.2012 14:35

2012/08/09 12:12:42 +0200 ALEXANDER-PC Alexander MESSAGE Starting protection
2012/08/09 12:12:44 +0200 ALEXANDER-PC Alexander MESSAGE Protection started successfully
2012/08/09 12:12:47 +0200 ALEXANDER-PC Alexander MESSAGE Starting IP protection
2012/08/09 12:12:49 +0200 ALEXANDER-PC Alexander MESSAGE IP Protection started successfully
2012/08/09 12:12:56 +0200 ALEXANDER-PC Alexander MESSAGE Starting database refresh
2012/08/09 12:12:56 +0200 ALEXANDER-PC Alexander MESSAGE Stopping IP protection
2012/08/09 12:13:10 +0200 ALEXANDER-PC Alexander MESSAGE Executing scheduled update: Daily
2012/08/09 12:13:12 +0200 ALEXANDER-PC Alexander MESSAGE Database already up-to-date
2012/08/09 12:15:10 +0200 ALEXANDER-PC Alexander MESSAGE IP Protection stopped
2012/08/09 12:15:11 +0200 ALEXANDER-PC Alexander MESSAGE Database refreshed successfully
2012/08/09 12:15:11 +0200 ALEXANDER-PC Alexander MESSAGE Starting IP protection
2012/08/09 12:15:14 +0200 ALEXANDER-PC Alexander MESSAGE IP Protection started successfully
2012/08/09 12:58:46 +0200 ALEXANDER-PC Alexander MESSAGE Starting protection
2012/08/09 12:58:48 +0200 ALEXANDER-PC Alexander MESSAGE Protection started successfully
2012/08/09 12:58:51 +0200 ALEXANDER-PC Alexander MESSAGE Starting IP protection
2012/08/09 12:58:53 +0200 ALEXANDER-PC Alexander MESSAGE IP Protection started successfully

t'john 10.08.2012 13:36

Malwarebytes aufmachen und Reiter Logdateien das Log doppelklicken und hier posten.


Alle Zeitangaben in WEZ +1. Es ist jetzt 01:04 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131