Dear visitor, welcome to Avira Support Forum. If this is your first visit here, please read the Help. It explains in detail how this page works. To use all features of this page, you should consider registering. Please use the registration form, to register here or read more information about the registration process. If you are already registered, please login here.
Date of registration: Jun 12th 2006
Operating System: Mac - Linux - Windows XP Pro SP3 - PUPPY 4.12 AUFM STICK
Quoted
netsvcs
msconfig
safebootminimal
safebootnetwork
activex
drivers32
/md5start
explorer.exe
lsass.exe
svchost.exe
wininit.exe
winlogon.exe
userinit.exe
/md5stop
%ALLUSERSPROFILE%\Application Data\*.exe /s
%APPDATA%\*.exe /s
%APPDATA%\Adobe\Update\*.*
%APPDATA%\Update\*.*
%APPDATA%\Microsoft\*.*
%ALLUSERSPROFILE%\Favorites\*.*
%ALLUSERSPROFILE%\*.*
%SYSTEMDRIVE%\*.*
%PROGRAMFILES%\*.*
%PROGRAMFILES%\Internet Explorer\*.*
%USERPROFILE%\*.*
%USERPROFILE%\Local Settings\Temp\*.exe
%USERPROFILE%\Local Settings\Temp\*.dll
%USERPROFILE%\Application Data\*.exe
%systemroot%\*. /mp /s
%systemroot%\*.exe /90
%systemroot%\system32\*.dll /lockedfiles
%systemroot%\system32\*.dll /90
%systemroot%\system32\drivers\*.sys /lockedfiles
%systemroot%\system32\drivers\*.sys /90
%systemroot%\system32\*.exe /90
%systemroot%\system32\config\*.sav
%systemroot%\system32\spool\prtprocs\w32x86\*.*
%systemroot%\Tasks\*.job /lockedfiles
%systemroot%\assembly\tmp\*.* /S /MD5
%systemroot%\assembly\GAC_32\*.* /S /MD5
%systemroot%\assembly\GAC_64\*.* /S /MD5
CREATERESTOREPOINT
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
Date of registration: Jun 12th 2006
Operating System: Mac - Linux - Windows XP Pro SP3 - PUPPY 4.12 AUFM STICK
Quoted
:OTL
O4 - HKU\S-1-5-21-2824101744-1166359984-1053670831-1002..\Run: [hjOouWQXnIVMkvP.exe] C:\ProgramData\hjOouWQXnIVMkvP.exe ()
[2012.04.21 14:25:01 | 000,000,184 | -H-- | C] () -- C:\ProgramData\-Gz8XjfWjaERRJDr
[2012.04.21 14:25:01 | 000,000,000 | -H-- | C] () -- C:\ProgramData\-Gz8XjfWjaERRJD
[2012.04.21 14:24:58 | 000,221,184 | -H-- | C] () -- C:\ProgramData\Gz8XjfWjaERRJD.exe
[2012.04.21 14:24:58 | 000,000,256 | -H-- | C] () -- C:\ProgramData\Gz8XjfWjaERRJD
[2012.04.21 14:19:05 | 000,300,032 | -H-- | C] () -- C:\ProgramData\hjOouWQXnIVMkvP.exe
[2012.04.22 21:08:09 | 000,001,106 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012.04.21 22:31:01 | 000,000,940 | -H-- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2824101744-1166359984-1053670831-1002UA.job
[2012.04.21 19:31:00 | 000,000,918 | -H-- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2824101744-1166359984-1053670831-1002Core.job
:Reg
:Files
ipconfig /flushdns /c
:Commands
[emptyflash]
[emptytemp]
[emptyjava]
[Reboot]


This post has been edited 1 times, last edit by "Rajo" (Apr 22nd 2012, 10:53pm)
Date of registration: Jun 12th 2006
Operating System: Mac - Linux - Windows XP Pro SP3 - PUPPY 4.12 AUFM STICK
Date of registration: Jun 12th 2006
Operating System: Mac - Linux - Windows XP Pro SP3 - PUPPY 4.12 AUFM STICK
Gibt es denn eine Möglichkeit die Symbole im Startmenü von Windows wieder herzustellen?




This post has been edited 2 times, last edit by "*Jose83" (Apr 23rd 2012, 1:13am)

Date of registration: Jun 12th 2006
Operating System: Mac - Linux - Windows XP Pro SP3 - PUPPY 4.12 AUFM STICK
Eben habe ich den vollständigen Scan mit Malwarebytes durchgeführt und im Protokoll steht, dass zwei "Trojan.FakeAlert" und ein "PUM.Hijack.StartMenu" (Registry Data) gefunden wurden. Hinter den drei Warnungen im Protokoll steht jeweils: No action taken.
This post has been edited 1 times, last edit by "Rajo" (Apr 24th 2012, 12:03pm)
Date of registration: Jun 12th 2006
Operating System: Mac - Linux - Windows XP Pro SP3 - PUPPY 4.12 AUFM STICK
Bitte postedoch auch mal das LOg - vom Full scan - Malwarebytes Hauptprogamm oben mitte reiterkarte logs
**
Welche ??
Quoted
Ich habe eben die drei Dateien erfolgreich in Quarantäne gesetzt

Date of registration: Jun 12th 2006
Operating System: Mac - Linux - Windows XP Pro SP3 - PUPPY 4.12 AUFM STICK
Date of registration: Jun 12th 2006
Operating System: Mac - Linux - Windows XP Pro SP3 - PUPPY 4.12 AUFM STICK
This post has been edited 1 times, last edit by "Rajo" (Apr 24th 2012, 10:41pm)