Hallo RM.
Slowly proceeding. habe OTL laufen lassen. dummer Fehler: beim ersten Mal nicht mit rechtsklick => Als admin.
das dann beim Zweiten Mal.
OTL wollte neustart, hat er bekommen, windows fährt dann normal hoch und danach habe ich immer noch den BKA-Bildschirm.
Nachstehende Logfiles habe ich dann im abgesicherten Modus rausgefischt (zuerst das älterem erste, dann das jüngere)
Code:
All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
HKEY_USERS\S-1-5-21-2809486971-3141557241-1330619740-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-2809486971-3141557241-1330619740-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-2809486971-3141557241-1330619740-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_USERS\S-1-5-21-2809486971-3141557241-1330619740-1000\Software\Microsoft\Internet Explorer\SearchScopes\{A0848ED8-6520-461A-AA96-87E95BD88061}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0848ED8-6520-461A-AA96-87E95BD88061}\ not found.
Registry key HKEY_USERS\S-1-5-21-2809486971-3141557241-1330619740-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ not found.
Registry value HKEY_USERS\S-1-5-21-2809486971-3141557241-1330619740-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Userinit deleted successfully.
C:\Users\Kathi\AppData\Roaming\appconf32.exe moved successfully.
========== FILES ==========
C:\Users\Kathi\AppData\Roaming\xmldm folder moved successfully.
C:\Users\Kathi\AppData\Roaming\kock folder moved successfully.
File\Folder C:\Users\Kathi\AppData\Roaming\appconf32.exe not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 33170 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Kathi
->Temp folder emptied: 344201710 bytes
->Temporary Internet Files folder emptied: 99229696 bytes
->Java cache emptied: 13208450 bytes
->FireFox cache emptied: 218243222 bytes
->Google Chrome cache emptied: 6379992 bytes
->Opera cache emptied: 8843974 bytes
->Flash cache emptied: 25181 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 24796957 bytes
RecycleBin emptied: 467786348 bytes
Total Files Cleaned = 1.128,00 mb
OTL by OldTimer - Version 3.2.54.0 log created on 07212012_200729
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
Code:
All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
HKEY_USERS\S-1-5-21-2809486971-3141557241-1330619740-1000\Software\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-2809486971-3141557241-1330619740-1000\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_USERS\S-1-5-21-2809486971-3141557241-1330619740-1000\Software\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_USERS\S-1-5-21-2809486971-3141557241-1330619740-1000\Software\Microsoft\Internet Explorer\SearchScopes\{A0848ED8-6520-461A-AA96-87E95BD88061}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A0848ED8-6520-461A-AA96-87E95BD88061}\ not found.
Registry key HKEY_USERS\S-1-5-21-2809486971-3141557241-1330619740-1000\Software\Microsoft\Internet Explorer\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}\ not found.
Registry value HKEY_USERS\S-1-5-21-2809486971-3141557241-1330619740-1000\Software\Microsoft\Windows\CurrentVersion\Run\\Userinit not found.
File C:\Users\Kathi\AppData\Roaming\appconf32.exe not found.
========== FILES ==========
File\Folder C:\Users\Kathi\AppData\Roaming\xmldm not found.
File\Folder C:\Users\Kathi\AppData\Roaming\kock not found.
File\Folder C:\Users\Kathi\AppData\Roaming\appconf32.exe not found.
========== COMMANDS ==========
[EMPTYTEMP]
User: All Users
User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
User: Kathi
->Temp folder emptied: 1119756 bytes
->Temporary Internet Files folder emptied: 33882 bytes
->Java cache emptied: 0 bytes
->FireFox cache emptied: 0 bytes
->Google Chrome cache emptied: 0 bytes
->Opera cache emptied: 0 bytes
->Flash cache emptied: 0 bytes
User: Public
%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 0 bytes
RecycleBin emptied: 0 bytes
Total Files Cleaned = 1,00 mb
OTL by OldTimer - Version 3.2.54.0 log created on 07212012_203435
Files\Folders moved on Reboot...
PendingFileRenameOperations files...
Registry entries deleted on Reboot...
So, und jetzt ziehe ich malwarebytes auf den infizierten rechner.
Logfile folgt dann im nächsten Post.
Gruss,
Supertschack
Lesezeichen