![]() |
|
Log-Analyse und Auswertung: ihavenet TrojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() ihavenet Trojaner Hallo, seit eine Woche habe ich den ihavenet-Trojaner auf meinem Rechner.Ich habe mir die von euch empfohlenen Diagnose-Tool gezogen und eine Log.txt datei erstellt. Nun sende ich diese Datei per kopieren und einfügen. Ich hoffe, jemand kann mir helfen. Ich brauche mein Laptop täglich für die Prüfungsvorbreitung. Ohne Internet bin ich raus. Bitte um Hilfe! Danke im Voraus. xyarar Mein Log-Text: # AdwCleaner v3.001 - Report created 25/08/2013 at 18:24:46 # Updated 24/08/2013 by Xplode # Operating System : Windows 7 Home Premium Service Pack 1 (64 bits) # Username : Yarar-Bolle - MY-PC # Running from : C:\Users\Yarar-Bolle\Downloads\AdwCleaner.exe # Option : Clean ***** [ Services ] ***** [#] Service Deleted : BrowserDefendert ***** [ Files / Folders ] ***** Folder Deleted : C:\ProgramData\Babylon Folder Deleted : C:\ProgramData\BrowserDefender Folder Deleted : C:\ProgramData\Partner Folder Deleted : C:\Program Files (x86)\delta Folder Deleted : C:\Program Files (x86)\Video downloader Folder Deleted : C:\Users\Yarar-Bolle\AppData\Roaming\dvdvideosoftiehelpers Folder Deleted : C:\Users\Yarar-Bolle\AppData\Roaming\Mozilla\Firefox\Profiles\2jesth27.default\Extensions\ffxtlbr@delta.com File Deleted : C:\Users\Yarar-Bolle\AppData\Roaming\Mozilla\Firefox\Profiles\2jesth27.default\searchplugins\Babylon.xml File Deleted : C:\Users\Yarar-Bolle\AppData\Roaming\Mozilla\Firefox\Profiles\2jesth27.default\searchplugins\delta.xml File Deleted : C:\Users\Yarar-Bolle\AppData\Roaming\Mozilla\Firefox\Profiles\2jesth27.default\bprotector_extensions.sqlite File Deleted : C:\Users\Yarar-Bolle\AppData\Roaming\Mozilla\Firefox\Profiles\2jesth27.default\bprotector_prefs.js File Deleted : C:\Users\Yarar-Bolle\AppData\Roaming\Mozilla\Firefox\Profiles\2jesth27.default\user.js File Deleted : C:\Users\Yarar-Bolle\AppData\Local\Google\Chrome\User Data\Default\bProtector Web Data File Deleted : C:\Users\Yarar-Bolle\AppData\Local\Google\Chrome\User Data\Default\bprotectorpreferences File Deleted : C:\Windows\System32\Tasks\EPUpdater ***** [ Shortcuts ] ***** ***** [ Registry ] ***** Value Deleted : HKLM\SOFTWARE\Mozilla\Firefox\Extensions [{ACAA314B-EEBA-48E4-AD47-84E31C44796C}] Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\bProtectSettings Key Deleted : HKLM\SOFTWARE\Classes\AppID\escort.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortApp.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escortEng.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\escorTlbr.DLL Key Deleted : HKLM\SOFTWARE\Classes\AppID\esrv.EXE Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32 Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS Key Deleted : HKCU\Software\522ded0b035ef12 Key Deleted : HKLM\SOFTWARE\522ded0b035ef12 Key Deleted : HKLM\SOFTWARE\Classes\AppID\{09C554C3-109B-483C-A06B-F14172F1A947} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{39CB8175-E224-4446-8746-00566302DF8D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{4E1E9D45-8BF9-4139-915C-9F83CC3D5921} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{B12E99ED-69BD-437C-86BE-C862B9E5444D} Key Deleted : HKLM\SOFTWARE\Classes\AppID\{D7EE8177-D51E-4F89-92B6-83EA2EC40800} Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{2DAC2231-CC35-482B-97C5-CED1D4185080} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F1CD84C-04A3-4EA0-9EA1-7D134FD66C82} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{3F83A9CA-B5F0-44EC-9357-35BB3E84B07F} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{47E520EA-CAD2-4F51-8F30-613B3A1C33EB} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{57C91446-8D81-4156-A70E-624551442DE9} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{70AFB7B2-9FB5-4A70-905B-0E9576142E1D} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{7AD65FD1-79E0-406D-B03C-DD7C14726D69} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{97DD820D-2E20-40AD-B01E-6730B2FCE630} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{B177446D-54A4-4869-BABC-8566110B4BE0} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{D9D1DFC5-502D-43E4-B1BB-4D0B7841489A} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{E0B07188-A528-4F9E-B2F7-C7FDE8680AE4} Key Deleted : HKLM\SOFTWARE\Classes\Interface\{F05B12E1-ADE8-4485-B45B-898748B53C37} Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9} Key Deleted : [x64] HKLM\SOFTWARE\Classes\CLSID\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Key Deleted : [x64] HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{EE932B49-D5C0-4D19-A3DA-CE0849258DE6} Key Deleted : HKCU\Software\BabSolution Key Deleted : HKCU\Software\Delta Key Deleted : HKLM\Software\DataMngr Key Deleted : HKLM\Software\Delta ***** [ Browsers ] ***** -\\ Internet Explorer v10.0.9200.16635 -\\ Mozilla Firefox v23.0.1 (de) [ File : C:\Users\Yarar-Bolle\AppData\Roaming\Mozilla\Firefox\Profiles\2jesth27.default\prefs.js ] Line Deleted : user_pref("browser.newtab.url", "hxxp://www1.delta-search.com/?babsrc=NT_ss&mntrId=9409446D57B772CF&affID=121563&tsp=4942"); Line Deleted : user_pref("browser.search.order.1", "Delta Search"); Line Deleted : user_pref("extensions.delta.admin", false); Line Deleted : user_pref("extensions.delta.aflt", "babsst"); Line Deleted : user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); Line Deleted : user_pref("extensions.delta.autoRvrt", "false"); Line Deleted : user_pref("extensions.delta.dfltLng", "de"); Line Deleted : user_pref("extensions.delta.excTlbr", false); Line Deleted : user_pref("extensions.delta.ffxUnstlRst", true); Line Deleted : user_pref("extensions.delta.id", "9409493c000000000000446d57b772cf"); Line Deleted : user_pref("extensions.delta.instlDay", "15899"); Line Deleted : user_pref("extensions.delta.instlRef", "sst"); Line Deleted : user_pref("extensions.delta.newTab", false); Line Deleted : user_pref("extensions.delta.prdct", "delta"); Line Deleted : user_pref("extensions.delta.prtnrId", "delta"); Line Deleted : user_pref("extensions.delta.rvrt", "false"); Line Deleted : user_pref("extensions.delta.smplGrp", "none"); Line Deleted : user_pref("extensions.delta.tlbrId", "base"); Line Deleted : user_pref("extensions.delta.tlbrSrchUrl", ""); Line Deleted : user_pref("extensions.delta.vrsn", "1.8.21.5"); Line Deleted : user_pref("extensions.delta.vrsnTs", "1.8.21.50:52:40"); Line Deleted : user_pref("extensions.delta.vrsni", "1.8.21.5"); Line Deleted : user_pref("extensions.delta_i.babExt", ""); Line Deleted : user_pref("extensions.delta_i.babTrack", "affID=121563&tsp=4942"); Line Deleted : user_pref("extensions.delta_i.srcExt", "ss"); Line Deleted : user_pref("extensions.installCache", "[{\"name\":\"winreg-app-global\",\"addons\":{\"{ACAA314B-EEBA-48e4-AD47-84E31C44796C}\":{\"descriptor\":\"C:\\\\Program Files (x86)\\\\Common Files\\\\DVDVideoSof[...] -\\ Google Chrome v29.0.1547.57 [ File : C:\Users\Yarar-Bolle\AppData\Local\Google\Chrome\User Data\Default\preferences ] ************************* AdwCleaner[R0].txt - [7411 octets] - [25/08/2013 18:24:13] AdwCleaner[S0].txt - [7309 octets] - [25/08/2013 18:24:46] ########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [7369 octets] ########## |
Themen zu ihavenet Trojaner |
appdata, c:\windows, datei, explorer, firefox, google, hilfe!, home, ihavenet virus trojaner windows, internet, internet explorer, kopieren, laptop, microsoft, mozilla, ohne internet, opera, registry, roaming, services, software, system, system32, trojaner, video, web, windows |