![]() |
|
Plagegeister aller Art und deren Bekämpfung: GVU Trojaner (Trojan.Banker & Trojan.PWS) auf Win7Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
![]() | ![]() GVU Trojaner (Trojan.Banker & Trojan.PWS) auf Win7 Hallo t'john! Long time no see ![]() Auftrag ist ausgeführt. Hier die Log/Textfiles: ADWCLEANER vor dem löschen Code:
ATTFilter # AdwCleaner v1.801 - Logfile created 09/11/2012 at 22:55:18 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : yoshi - ANDI-LAPTOP # Boot Mode : Normal # Running from : C:\Users\yoshi\Desktop\ANTI GVU\adwcleaner.exe # Option [Search] ***** [Services] ***** ***** [Files / Folders] ***** Folder Found : C:\ProgramData\Browser Manager ***** [Registry] ***** ***** [Registre - GUID] ***** Key Found : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} Value Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}] [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} [x64] Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v15.0.1 (de) Profile name : default File : C:\Users\yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\gnprol4w.default\prefs.js [OK] File is clean. ************************* AdwCleaner[R1].txt - [13541 octets] - [02/09/2012 18:22:45] AdwCleaner[S1].txt - [11666 octets] - [02/09/2012 18:24:45] AdwCleaner[R2].txt - [1789 octets] - [11/09/2012 22:55:18] ########## EOF - C:\AdwCleaner[R2].txt - [1917 octets] ########## ADWCLEANER nach dem löschen Code:
ATTFilter # AdwCleaner v1.801 - Logfile created 09/11/2012 at 22:56:01 # Updated 14/08/2012 by Xplode # Operating system : Windows 7 Home Premium Service Pack 1 (64 bits) # User : yoshi - ANDI-LAPTOP # Boot Mode : Normal # Running from : C:\Users\yoshi\Desktop\ANTI GVU\adwcleaner.exe # Option [Delete] ***** [Services] ***** ***** [Files / Folders] ***** Deleted on reboot : C:\ProgramData\Browser Manager ***** [Registry] ***** ***** [Registre - GUID] ***** Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{98889811-442D-49DD-99D7-DC866BE87DBC} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} Value Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar [{98889811-442D-49DD-99D7-DC866BE87DBC}] [x64] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{2EECD738-5844-4A99-B4B6-146BF802613B} [x64] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{97F2FF5B-260C-4CCF-834A-2DDA4E29E39E} [x64] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{98889811-442D-49DD-99D7-DC866BE87DBC} ***** [Internet Browsers] ***** -\\ Internet Explorer v9.0.8112.16421 [OK] Registry is clean. -\\ Mozilla Firefox v15.0.1 (de) Profile name : default File : C:\Users\yoshi\AppData\Roaming\Mozilla\Firefox\Profiles\gnprol4w.default\prefs.js [OK] File is clean. ************************* AdwCleaner[R1].txt - [13541 octets] - [02/09/2012 18:22:45] AdwCleaner[S1].txt - [11666 octets] - [02/09/2012 18:24:45] AdwCleaner[R2].txt - [1912 octets] - [11/09/2012 22:55:18] AdwCleaner[S2].txt - [1870 octets] - [11/09/2012 22:56:01] ########## EOF - C:\AdwCleaner[S2].txt - [1998 octets] ########## und zu guter letzt EMSISOFT ANTI MALWARE Code:
ATTFilter Emsisoft Anti-Malware - Version 6.6 Letztes Update: 11.09.2012 23:08:55 Scan Einstellungen: Scan Methode: Detail Scan Objekte: Rootkits, Speicher, Traces, C:\, D:\ Archiv Scan: An ADS Scan: An Scan Beginn: 11.09.2012 23:09:20 c:\program files (x86)\phenomedia gefunden: Trace.File.moorfrog 1.0!E1 Key: hkey_local_machine\software\trymedia systems gefunden: Trace.Registry.trymedia!E1 Key: hkey_local_machine\software\trymedia systems\activemark software gefunden: Trace.Registry.trymedia!E1 C:\_OTL\MovedFiles\09012012_214614\C_Users\yoshi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\1d47e9f2-149d54f5 -> b4a\b4a.class gefunden: Java.CVE!E2 C:\_OTL\MovedFiles\09012012_214614\C_Users\yoshi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\1d47e9f2-149d54f5 -> b4a\b4d.class gefunden: Exploit.Java.Blacole!E2 C:\_OTL\MovedFiles\09012012_214614\C_Users\yoshi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\1d47e9f2-149d54f5 -> b4a\b4e.class gefunden: Exploit.Java.CVE-2012-4681!E2 C:\_OTL\MovedFiles\09012012_214614\C_Users\yoshi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\1d47e9f2-149d54f5 -> b4a\b4c.class gefunden: Exploit.Java.Blacole!E2 C:\_OTL\MovedFiles\09012012_214614\C_Users\yoshi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\1d47e9f2-149d54f5 -> b4a\b4f.class gefunden: Exploit.Java.Blacole!E2 C:\_OTL\MovedFiles\09012012_214614\C_Users\yoshi\AppData\LocalLow\Sun\Java\Deployment\cache\6.0\50\1d47e9f2-149d54f5 -> b4a\b4b.class gefunden: Exploit.Java.Blacole!E2 C:\Users\yoshi\DriverGenius 11 by CTA\Driver Genius 11 Professional IT\Crack\DriverGenius.exe gefunden: Packed.Win32.EnigmaVBox.AMN!E1 Gescannt 609078 Gefunden 10 Scan Ende: 12.09.2012 00:43:36 Scan Zeit: 1:34:16 Geändert von ddPlr (12.09.2012 um 07:04 Uhr) |
![]() |
Themen zu GVU Trojaner (Trojan.Banker & Trojan.PWS) auf Win7 |
avira, bildschirm, browser, chip.de, downloader, driver genius, error, excel, fehler, flash player, format, google, google earth, helper, home, install.exe, league of legends, mozilla, nvidia update, programm, realtek, registry, richtlinie, rundll, scan, security, server, software, svchost.exe, system error, tcp, trojaner, usb 2.0, usenext, version., visual studio |