Hallo Andreas,
1. habe "gefixt" und das ist das Ergebnis:
Code:
========== OTL ==========
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\ deleted successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\KernelFaultCheck deleted successfully.
Registry value HKEY_USERS\ArethaFranklin_ON_C\Software\Microsoft\Windows\CurrentVersion\Run\\ECF73699 deleted successfully.
C:\WINDOWS\system32\A0D8512AECF736992381.exe moved successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableTaskMgr deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegedit deleted successfully.
Registry value HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\LocalService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\NetworkService_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\ArethaFranklin_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\\NoDriveTypeAutoRun deleted successfully.
Registry value HKEY_USERS\ArethaFranklin_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegistryTools deleted successfully.
Registry value HKEY_USERS\ArethaFranklin_ON_C\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System\\DisableRegedit deleted successfully.
Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\\UserInit:C:\WINDOWS\system32\A0D8512AECF736992381.exe deleted successfully.
File C:\WINDOWS\system32\A0D8512AECF736992381.exe not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\msconfig.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\regedit.exe\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\taskmgr.exe\ deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Cdrom\\AutoRun|DWORD:1 /E : value set successfully!
========== FILES ==========
File\Folder C:\WINDOWS\system32\A0D8512AECF736992381.exe not found.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc501 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc484 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc483 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc482 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc481 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc480\9482F4B4-E343-43B6-B170-9A65BC822C77 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc480\7971F918-A847-4430-9279-4A52D1EFE18D folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc480 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc479 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc478 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\Install folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\fa3616be5aef51c5afa4f903f59d59d4 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\f8e5b85e759db8d33a682de93dab7d15 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\f86476030c128b80d7d10a4009a41702 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\f10260c6affc20427498eb9420688c4e folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\e3a0ab9bbcc9e88c6d55aa55ced6c0f1 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\b95ce70b2876884aa680fb29449c88f8 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\b79e78f1540bef723b017cc8f023026d folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\9f7a51baff1b338ee54334bd918723e6 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\810d6bd82a7998224a2d12063b8b968f\update folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\810d6bd82a7998224a2d12063b8b968f folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\7ca582372067ce17a1dac51f1d6b6712 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\416bf76f412f479f57ace38837136920 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477\21066b9ccd83f1b5e69be4eaa2b537c7 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc477 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc476\7971f918-a847-4430-9279-4a52d1efe18d folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc476 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc475\Registered folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc475\Default folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc475 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc474 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc473\de folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc473 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1562.log folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1561.log folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1560.log folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1550.log folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1548.log folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1348 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1311 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1310 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1289\Client folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1289 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1285 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1265.4322 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1264.3705 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1254 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1218 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1157.Aindling-erst-im-Finale-geschlagen-id5084611-Dateien folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1141 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1110 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1109\show_data_002 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1109\show_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1109\975_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1109 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1107\show_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1107\975_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1107 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1104\show_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1104\request_data\imp_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1104\request_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1104\iframe_975_data\975_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1104\iframe_975_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1104 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1102\show_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1102\iframe_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1102\977_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1102\975_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1102 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1100\show_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1100\975_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1100 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1098\iframe_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1098\977_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1098\975_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1098\2229_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1098 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1096\975_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1096 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1094\977_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1094\975_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1094\2229_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1094 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1092\977_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1092\975_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1092 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1090\show_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1090\975_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1090\2229_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1090 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1088\iframe_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1088\977_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1088\975_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1088\2229_data folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003\Dc1088 folder moved successfully.
C:\RECYCLER\S-1-5-21-484763869-436374069-839522115-1003 folder moved successfully.
C:\RECYCLER folder moved successfully.
C:\Dokumente und Einstellungen\ArethaFranklin\Anwendungsdaten\Rnenprqatk folder moved successfully.
C:\WINDOWS\System32\winsh320 moved successfully.
C:\WINDOWS\System32\winsh321 moved successfully.
C:\WINDOWS\System32\winsh322 moved successfully.
C:\WINDOWS\System32\winsh323 moved successfully.
C:\WINDOWS\System32\winsh324 moved successfully.
C:\WINDOWS\System32\winsh325 moved successfully.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: LocalService
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: NetworkService
->Temp folder emptied: 1536766 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: ArethaFranklin
->Temp folder emptied: 940253 bytes
->Temporary Internet Files folder emptied: 1508442 bytes
->Java cache emptied: 82310 bytes
->FireFox cache emptied: 49485450 bytes
->Flash cache emptied: 14354 bytes
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 2134333 bytes
%systemroot%\System32 .tmp files removed: 150407 bytes
%systemroot%\System32\dllcache .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 4868145 bytes
Total Files Cleaned = 58.00 mb
OTLPE by OldTimer - Version 3.1.48.0 log created on 04282012_223441
2. Habe den Laptop runtergefahren und neu gestartet (ohne CD). Es hat sich leider nichts geändert, außer einer neu hinzugekommenen Fehlermeldung.
Schicke dir mal das Bild von dem UKash-Trojaner:
Mist, geht schon wieder nicht.... - wenn ich das jpg auswähle und hochladen will, erscheint folgende Fehlermeldung (wie vorher bei den txt Anhängen)
[IO ErrorEvent type="ioError"=false cancelable=false event Phase=2 text="Error#2038"]
Wie kann ich dir den Screenshot zukommen lassen???? Einfaches copy&paste ging auch nicht.
OK, dann schreibe ich dir die "neue" Fehlermeldung:
jusched.exe Datei beschädigt
Exception Processing Message C0000102 Parameters 75b0bf7c 75b0bf7c 75b0bf7c 75b0bf7c
ok
3. nachdem mein Laptop auf standby ging, wollte ich ihn (damit ich die Fehlermeldung abschreiben kann) wieder hochfahren, aber dann ging wieder gar nichts mehr. Keine normaler Windows start, kein Start im Abgesicherten Modus. Es erschien ein weißer Text auf blauem Hintergrund, der besagte, dass ein Datenträger auf Konsistenz überprüft werden müsse, dann lief eine CHKDSK los und überprüfte C und D. Ergebnis: Fehler in irgendeiner Index und es wurden zig Einträge im Index $30 (oder so ähnlich) gelöscht und es lief tonnenweise irgendein Text rasendschnell über den Bildschirm. Ich habe keine Möglichkeit da einzugreifen und keinen Schimmer, was da grad passiert. So, jetzt hat das alles ein Ende, der LT versucht neu zu booten, aber es geht nicht, er fährt nur bis zum DOS mit den Auswahlkriterien in welchem Modus er gestartet werden soll. Habe den LT ausgeschaltet, bevor der Countdown zum Start beendet war. Ich hoffe jetzt nur, dass nicht noch schlimmeres passiert ist.
Gruß Silvi
Lesezeichen