|
Log-Analyse und Auswertung: Troj.gen.zlob in C:\windows\system32\asfar.exe"Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
03.01.2013, 00:11 | #1 |
| Troj.gen.zlob in C:\windows\system32\asfar.exe" Malwarebytes' Anti-Malware 1.50.1.1100 www.malwarebytes.org Datenbank Version: 913010210 Windows 6.1.7601 Service Pack 1 Internet Explorer 9.0.8112.16421 02.01.2013 23:59:30 mbam-log-2013-01-02 (23-59-30).txt Art des Suchlaufs: Quick-Scan Durchsuchte Objekte: 231027 Laufzeit: 3 Minute(n), 3 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 87 Infizierte Registrierungswerte: 9 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 2 Infizierte Dateien: 2 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CLASSES_ROOT\CLSID\{147A976F-EEE1-4377-8EA7-4716E4CDD239} (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\CLSID\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Not selected for removal. HKEY_CLASSES_ROOT\funmoods.funmoodsHlpr.1 (PUP.FunMoods) -> Not selected for removal. HKEY_CLASSES_ROOT\funmoods.funmoodsHlpr (PUP.FunMoods) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} (PUP.FunMoods) -> Not selected for removal. HKEY_CLASSES_ROOT\CLSID\{965B9DBE-B104-44AC-950A-8A5F97AFF439} (PUP.Funmoods) -> Not selected for removal. HKEY_CLASSES_ROOT\CLSID\{A4730EBE-43A6-443e-9776-36915D323AD3} (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\CLSID\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Not selected for removal. HKEY_CLASSES_ROOT\funmoods.dskBnd.1 (PUP.Funmoods) -> Not selected for removal. HKEY_CLASSES_ROOT\funmoods.dskBnd (PUP.Funmoods) -> Not selected for removal. HKEY_CLASSES_ROOT\CLSID\{A9DB719C-7156-415E-B49D-BAD039DE4F13} (PUP.Funmoods) -> Not selected for removal. HKEY_CLASSES_ROOT\funmoodsApp.appCore.1 (PUP.Funmoods) -> Not selected for removal. HKEY_CLASSES_ROOT\funmoodsApp.appCore (PUP.Funmoods) -> Not selected for removal. HKEY_CLASSES_ROOT\CLSID\{F03FD9D0-4F2B-497C-8A71-DD41D70B07D9} (PUP.Funmoods) -> Not selected for removal. HKEY_CLASSES_ROOT\f (PUP.Funmoods) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{59C7FC09-1C83-4648-B3E6-003D2BBC7481} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{68AF847F-6E91-45dd-9B68-D6A12C30E5D7} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{9170B96C-28D4-4626-8358-27E6CAEEF907} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{D1A71FA0-FF48-48dd-9B6D-7A13A3E42127} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{DDB1968E-EAD6-40fd-8DAE-FF14757F60C7} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{F138D901-86F0-4383-99B6-9CDD406036DA} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{56256A51-B582-467e-B8D4-7786EDA79AE0} (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{07B18EAB-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{1D4DB7D2-6EC9-47a3-BD87-1E41684E07BB} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{25560540-9571-4D7B-9389-0F166788785A} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3DC201FB-E9C9-499C-A11F-23C360D7C3F8} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3E720452-B472-4954-B7AA-33069EB53906} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{63D0ED2C-B45B-4458-8B3B-60C69BBBD83C} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{7473D294-B7BB-4f24-AE82-7E2CE94BB6A9} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{98D9753D-D73B-42D5-8C85-4469CDA897AB} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{9FF05104-B030-46FC-94B8-81276E4E27DF} (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{E79DFBCA-5697-4fbd-94E5-5B2A9C7C1612} (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.DataControl (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.DataControl.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.HistoryKillerScheduler.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.HistorySwatterControlBar.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.HTMLMenu.2 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.IECookiesManager.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.KillerObjManager.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterBarButton.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\FunWebProducts.PopSwatterSettingsControl.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.ChatSessionPlugin.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.HTMLPanel.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.MultipleButton.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.OutlookAddin.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.PseudoTransparentPlugin.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.SkinLauncher (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.SkinLauncher.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.SkinLauncherSettings (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.SkinLauncherSettings.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.ThirdPartyInstaller (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.ThirdPartyInstaller.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearch.UrlAlertButton.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearchToolBar.SettingsPlugin.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\MyWebSearchToolBar.ToolbarPlugin.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller (PUP.MyWebSearch) -> Not selected for removal. HKEY_CLASSES_ROOT\ScreenSaverControl.ScreenSaverInstaller.1 (PUP.MyWebSearch) -> Not selected for removal. HKEY_CURRENT_USER\SOFTWARE\MyWebSearch (PUP.MyWebSearch) -> Not selected for removal. HKEY_CURRENT_USER\Software\AppDataLow\Software\MyWebSearch (PUP.MyWebsearch) -> Not selected for removal. HKEY_CURRENT_USER\Software\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\FocusInteractive (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Fun Web Products (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\MyWebSearch (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Google\Chrome\Extensions\cjpglkicenollcignonpgiafdgfeehoj (PUP.FunMoods) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Google\chrome\Extensions\fdloijijlkoblmigdofommgnheckmaki (PUP.Funmoods) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\RunDll32Policy\f3ScrCtr.dll (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Multimedia\WMPlayer\Schemes\f3pss (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Outlook\Addins\MyWebSearch.OutlookAddin (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Office\Word\Addins\MyWebSearch.OutlookAddin (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\MozillaPlugins\@mywebsearch.com/Plugin (PUP.MyWebSearch) -> Not selected for removal. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MyWebSearchService (PUP.MyWebSearch) -> Not selected for removal. Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Value: {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} -> Not selected for removal. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D} (PUP.MyWebSearch) -> Value: {00A6FAF6-072E-44cf-8957-5838F569A31D} -> Not selected for removal. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\URLSearchHooks\{00A6FAF6-072E-44cf-8957-5838F569A31D} (PUP.MyWebSearch) -> Value: {00A6FAF6-072E-44cf-8957-5838F569A31D} -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{07B18EA9-A523-4961-B6BB-170DE4475CCA} (PUP.MyWebSearch) -> Value: {07B18EA9-A523-4961-B6BB-170DE4475CCA} -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} (PUP.Funmoods) -> Value: {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media\WMSDK\Sources\f3PopularScreensavers (PUP.MyWebSearch) -> Value: f3PopularScreensavers -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\User Agent\Post Platform\FunWebProducts (PUP.MyWebSearch) -> Value: FunWebProducts -> Not selected for removal. HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\m3ffxtbr@mywebsearch.com (PUP.MyWebSearch) -> Value: m3ffxtbr@mywebsearch.com -> Not selected for removal. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: c:\Windows\System32\config\systemprofile\AppData\LocalLow\Funmoods (PUP.FunMoods) -> Not selected for removal. c:\Windows\System32\config\systemprofile\AppData\LocalLow\Funmoods\Funmoods (PUP.FunMoods) -> Not selected for removal. Infizierte Dateien: c:\Users\daniela meier\AppData\Local\funmoods.crx (PUP.Funmoods) -> Not selected for removal. c:\Users\daniela meier\AppData\Local\Google\Chrome\user data\Default\local storage\chrome-extension_cjpglkicenollcignonpgiafdgfeehoj_0.localstorage (PUP.FunMoods) -> Not selected for removal. |
03.01.2013, 10:33 | #2 | |
/// TB-Ausbilder | Troj.gen.zlob in C:\windows\system32\asfar.exe"Ich werde dir bei deinem Problem helfen. Eine Bereinigung ist mitunter mit viel Arbeit für Dich (und mich) verbunden. Bevor es los geht, habe ich etwas Lesestoff für dich. Gelesen und verstanden? Schritt 1: Deinstallation von Programmen
Schritt 2: AdwCleaner: Werbeprogramme suchen und löschen
Schritt 3: Temporäre Dateien löschen mit TFC
Schritt 4: Scan mit DDS (+ attach) Downloade dir bitte DDS (von sUBs) von einem der folgenden Downloadspiegel und speichere die Datei auf deinem Desktop. Schritt 2: AdwCleaner: Werbeprogramme suchen und löschen
Schritt 3: Temporäre Dateien löschen mit TFC
Schritt 4: Scan mit DDS (+ attach) Downloade dir bitte DDS (von sUBs) von einem der folgenden Downloadspiegel und speichere die Datei auf deinem Desktop.
__________________ |
05.01.2013, 12:30 | #3 |
/// TB-Ausbilder | Troj.gen.zlob in C:\windows\system32\asfar.exe" Fehlende Rückmeldung
__________________Dieses Thema wurde aus den Abos gelöscht. Somit bekomm ich keine Benachrichtigung über neue Antworten. PM an mich falls Du denoch weiter machen willst. Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner schon sauber ist. Jeder andere bitte hier klicken und einen eigenen Thread erstellen
__________________ |
Themen zu Troj.gen.zlob in C:\windows\system32\asfar.exe" |
agent, anti-malware, appdatalow, browser, c:\windows, config, dateien, dll, explorer, firefox, google, helper, malwarebytes, microsoft, not, office, plugin, rundll, service, services, software, system, system32, troj.gen.zlob in c:\windows\system32\asfar.exe", trojan.vundo, user agent, version, windows |