Zu Punkt 1:
Irgendwie stürzt SystemLook dauernd ab mit dieser Fehlermeldung:
fehler.JPG
Ich kann das Tool zwar starten und den Code von Dir eingeben, aber dann kommt halt die o. a. Fehlermeldung. Habe versucht, das Tool (, das ich ja schon heruntergeladen hatte,) vom Desktop zu starten, es vom Administrator Desktop zu starten und ich habe es auch neu heruntergeladen - immer dieselbe Fehlermeldung.
Zu Punkt 2:
Habe ich gemacht, hier das logfile
Code:
All processes killed
========== PROCESSES ==========
========== OTL ==========
========== SERVICES/DRIVERS ==========
Error: No service named spaq was found to stop!
Service\Driver key spaq not found.
Error: Unable to stop service sptd!
Unable to delete service\driver key sptd.
========== REGISTRY ==========
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\ scheduled to be deleted on reboot.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\ deleted successfully.
========== FILES ==========
File\Folder C:\Programme\DAEMON Tools Lite not found.
========== COMMANDS ==========
C:\WINDOWS\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully
[EMPTYTEMP]
User: Administrator
->Temp folder emptied: 180224 bytes
->Temporary Internet Files folder emptied: 33170 bytes
->FireFox cache emptied: 25497902 bytes
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Florian
->Temp folder emptied: 31919858 bytes
->Temporary Internet Files folder emptied: 641394 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 45712712 bytes
->Flash cache emptied: 456 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 105897 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 99,00 mb
OTL by OldTimer - Version 3.2.39.1 log created on 03232012_094613
Files\Folders moved on Reboot...
Registry entries deleted on Reboot...
Registry delete failed. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\ scheduled to be deleted on reboot.
Sieht für mich so aus, als hätte da irgendwas nicht ganz funktioniert, oder?
Zu Punkt 3:
Erledigo.
Es wurden zwei files gefunden, wobei ich nur bei einem "cure" anordnen konnte. Das andere habe ich auf "skip" gelassen
tdsskiller.JPG
Hier der Report
Code:
10:05:50.0312 1460 TDSS rootkit removing tool 2.7.22.0 Mar 21 2012 17:40:00
10:05:50.0515 1460 ============================================================
10:05:50.0515 1460 Current date / time: 2012/03/23 10:05:50.0515
10:05:50.0515 1460 SystemInfo:
10:05:50.0515 1460
10:05:50.0546 1460 OS Version: 5.1.2600 ServicePack: 3.0
10:05:50.0546 1460 Product type: Workstation
10:05:50.0546 1460 ComputerName: FLO
10:05:50.0578 1460 UserName: Florian
10:05:50.0578 1460 Windows directory: C:\WINDOWS
10:05:50.0578 1460 System windows directory: C:\WINDOWS
10:05:50.0578 1460 Processor architecture: Intel x86
10:05:50.0578 1460 Number of processors: 1
10:05:50.0578 1460 Page size: 0x1000
10:05:50.0578 1460 Boot type: Normal boot
10:05:50.0578 1460 ============================================================
10:05:53.0625 1460 Drive \Device\Harddisk0\DR0 - Size: 0x9516AE000 (37.27 Gb), SectorSize: 0x200, Cylinders: 0x1301, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000050
10:05:53.0671 1460 Drive \Device\Harddisk1\DR2 - Size: 0xE8E0DB6000 (931.51 Gb), SectorSize: 0x200, Cylinders: 0x1DB01, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W'
10:05:53.0687 1460 \Device\Harddisk0\DR0:
10:05:53.0687 1460 MBR used
10:05:53.0687 1460 \Device\Harddisk0\DR0\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x4A852C1
10:05:53.0687 1460 \Device\Harddisk1\DR2:
10:05:53.0687 1460 MBR used
10:05:53.0687 1460 \Device\Harddisk1\DR2\Partition0: MBR, Type 0x7, StartLBA 0x3F, BlocksNum 0x747059C1
10:05:54.0031 1460 Initialize success
10:05:54.0031 1460 ============================================================
Lesezeichen