![]() |
|
Diskussionsforum: nodejs-Malware: FireHooker/DownloadProtectWindows 7 Hier sind ausschließlich fachspezifische Diskussionen erwünscht. Bitte keine Log-Files, Hilferufe oder ähnliches posten. Themen zum "Trojaner entfernen" oder "Malware Probleme" dürfen hier nur diskutiert werden. Bereinigungen von nicht ausgebildeten Usern sind hier untersagt. Wenn du dir einen Virus doer Trojaner eingefangen hast, eröffne ein Thema in den Bereinigungsforen oben. |
![]() | #11 |
/// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | ![]() nodejs-Malware: FireHooker/DownloadProtect Hab eben nochmal meine Windows8-VM mit dem Audcity von audacity.de infiziert. Es kommt neben dem Müll (Javascript-Malware), die nodejs benötigt auch Schwachsinn von Lavasoft rein. Hier mal eine Datei und Regsuche mit FRST nach der Infektion: Code:
ATTFilter ================== Datei-Suche: "Findfolder: nodejs;lavasoft;webcompanion nodejs;lavasoft;webcompanion;node.exe" ============= 2020-10-08 18:54 - 2020-10-08 18:54 _____ C:\Users\root\AppData\Roaming\Lavasoft 2020-10-08 18:54 - 2020-10-08 18:54 _____ C:\Users\root\AppData\Local\Lavasoft 2020-10-08 18:54 - 2020-10-08 18:54 _____ C:\ProgramData\Lavasoft 2020-10-08 18:54 - 2020-10-08 18:54 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft 2020-10-08 18:54 - 2020-10-08 18:54 _____ C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion 2020-10-08 18:54 - 2020-10-08 18:54 _____ C:\ProgramData\Lavasoft\Web Companion\Logs\Webcompanion 2020-10-08 18:54 - 2020-10-08 18:54 _____ C:\Program Files (x86)\Lavasoft 2020-10-08 18:54 - 2020-10-08 18:55 _____ C:\Program Files (x86)\nodejs ====== Ende von Suche ====== Code:
ATTFilter ===================== Suchergebnis für "lavasoft" ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\UFH\ARP] "1"="Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall {06b277c4-f364-4096-9b06-eac13192309c} C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanionInstaller.exe --uninstall" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Lavasoft] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{06b277c4-f364-4096-9b06-eac13192309c}] "Publisher"="Lavasoft" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{06b277c4-f364-4096-9b06-eac13192309c}] "DisplayIcon"="C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanionIcon.ico" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{06b277c4-f364-4096-9b06-eac13192309c}] "URLInfoAbout"="http://www.lavasoft.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{06b277c4-f364-4096-9b06-eac13192309c}] "Contact"="support@lavasoft.com" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{06b277c4-f364-4096-9b06-eac13192309c}] "UninstallString"="C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanionInstaller.exe --uninstall" [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WCAssistantService] "ImagePath"="C:\Program Files (x86)\Lavasoft\Web Companion\Application\Lavasoft.WCAssistant.WinService.exe" [HKEY_USERS\S-1-5-21-3617739728-3715507493-3568001795-1004\Software\Lavasoft] [HKEY_USERS\S-1-5-21-3617739728-3715507493-3568001795-1004\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}] "FaviconPath"="C:\ProgramData\Lavasoft\Web Companion\Icons\bing.ico" [HKEY_USERS\S-1-5-21-3617739728-3715507493-3568001795-1004\Software\Microsoft\Windows\CurrentVersion\Run] "Web Companion"="C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize " [HKEY_USERS\S-1-5-21-3617739728-3715507493-3568001795-1004\Software\Microsoft\Windows\CurrentVersion\UFH\SHC] "0"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion\Web Companion.lnk C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --startmenu" ===================== Suchergebnis für "webcompanion" ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\UFH\ARP] "1"="Software\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall {06b277c4-f364-4096-9b06-eac13192309c} C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanionInstaller.exe --uninstall" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\WebCompanionInstaller_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\WebCompanionInstaller_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\WebCompanion_RASAPI32] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Tracing\WebCompanion_RASMANCS] [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{06b277c4-f364-4096-9b06-eac13192309c}] "DisplayIcon"="C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanionIcon.ico" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{06b277c4-f364-4096-9b06-eac13192309c}] "UninstallString"="C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanionInstaller.exe --uninstall" [HKEY_USERS\S-1-5-21-3617739728-3715507493-3568001795-1004\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\webcompanion.com] [HKEY_USERS\S-1-5-21-3617739728-3715507493-3568001795-1004\Software\Microsoft\Windows\CurrentVersion\Run] "Web Companion"="C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --minimize " [HKEY_USERS\S-1-5-21-3617739728-3715507493-3568001795-1004\Software\Microsoft\Windows\CurrentVersion\UFH\SHC] "0"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft\WebCompanion\Web Companion.lnk C:\Program Files (x86)\Lavasoft\Web Companion\Application\WebCompanion.exe --startmenu" ===================== Suchergebnis für "node.exe" ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UserData\S-1-5-18\Components\246E4976B601AE8598C1F02B985905ED] "27AC50E0DD8DF2342ACC8800434A5877"="C:\Program Files (x86)\nodejs\node.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{77754e9b-264b-4d8d-b981-e4135c1ecb0c}] "ResourceFileName"="C:\Program Files (x86)\nodejs\node.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WINEVT\Publishers\{77754e9b-264b-4d8d-b981-e4135c1ecb0c}] "MessageFileName"="C:\Program Files (x86)\nodejs\node.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{793c9b44-3d6b-4f57-b5d7-4ff80adcf9a2}] "ApplicationIdentity"="C:\Program Files (x86)\nodejs\node.exe" [HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\Perflib\_V2Providers\{793c9b44-3d6b-4f57-b5d7-4ff80adcf9a2}] "ApplicationIdentity"="C:\Program Files (x86)\nodejs\node.exe" [HKEY_USERS\S-1-5-21-3617739728-3715507493-3568001795-1004\Software\Microsoft\Windows\CurrentVersion\UFH\SHC] "2"="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Node.js\Node.js.lnk C:\Program Files (x86)\nodejs\node.exe " ====== Ende von Suche ======
__________________ Logfiles bitte immer in CODE-Tags posten ![]() |
Themen zu nodejs-Malware: FireHooker/DownloadProtect |
tr/ad.firehooker.bu |