![]() |
|
Log-Analyse und Auswertung: Was habe ich mir da eingefangen??Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #16 |
![]() | ![]() Was habe ich mir da eingefangen?? Hier das Malwarebytes Log: ------------------------------------------ Malwarebytes' Anti-Malware 1.11 Datenbank Version: 714 Scan Art: Komplett Scan (C:\|D:\|) Objekte gescannt: 259872 Scan Dauer: 2 hour(s), 29 minute(s), 39 second(s) Infizierte Speicher Prozesse: 0 Infizierte Speicher Module: 3 Infizierte Registrierungsschlüssel: 14 Infizierte Registrierungswerte: 2 Infizierte Datei Objekte der Registrierung: 2 Infizierte Verzeichnisse: 0 Infizierte Dateien: 17 Infizierte Speicher Prozesse: (Keine Malware Objekte gefunden) Infizierte Speicher Module: C:\WINDOWS\system32\twfhxgdv.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\yayyXPHW.dll (Trojan.Vundo) -> Unloaded module successfully. C:\WINDOWS\system32\jkkhhEVp.dll (Trojan.Vundo) -> Unloaded module successfully. Infizierte Registrierungsschlüssel: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{fada46d4-893b-4899-891e-b8d8883199e7} (Trojan.Vundo) -> Delete on reboot. HKEY_CLASSES_ROOT\CLSID\{fada46d4-893b-4899-891e-b8d8883199e7} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\aoprndtws (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affltid (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MS Juan (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{6584c510-924b-486a-a1a0-e380de08c2db} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{6584c510-924b-486a-a1a0-e380de08c2db} (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\jkkhhevp (Trojan.Vundo) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\FCOVM (Trojan.Vundo) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\RemoveRP (Trojan.Vundo) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\BM17610b0c (Trojan.Agent) -> Delete on reboot. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{6584c510-924b-486a-a1a0-e380de08c2db} (Trojan.Vundo) -> Delete on reboot. Infizierte Datei Objekte der Registrierung: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\LSA\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\yayyxphw -> Delete on reboot. HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\Authentication Packages (Trojan.Vundo) -> Data: c:\windows\system32\yayyxphw -> Delete on reboot. Infizierte Verzeichnisse: (Keine Malware Objekte gefunden) Infizierte Dateien: C:\WINDOWS\system32\mjvlrdsp.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\psdrlvjm.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\pmnoMdbc.dll_old (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\cbdMonmp.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\cbdMonmp.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\twfhxgdv.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\vdgxhfwt.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\yayyXPHW.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\WHPXyyay.ini (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\WHPXyyay.ini2 (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Dokumente und Einstellungen\Jörg\Lokale Einstellungen\Temporary Internet Files\Content.IE5\048F37W1\kriv[1] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Dokumente und Einstellungen\Jörg\Lokale Einstellungen\Temporary Internet Files\Content.IE5\M9OBBSWN\idkfa[1] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\Dokumente und Einstellungen\Jörg\Lokale Einstellungen\Temporary Internet Files\Content.IE5\NLAFDOCU\kriv[1] (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\elubmwgs.dll (Trojan.Agent) -> Delete on reboot. C:\WINDOWS\system32\qoMcbaWq.dll (Trojan.Vundo) -> Quarantined and deleted successfully. C:\WINDOWS\system32\jkkhhEVp.dll (Trojan.Vundo) -> Delete on reboot. C:\WINDOWS\system32\iifGwwww.dll (Trojan.Vundo) -> Quarantined and deleted successfully. |
Themen zu Was habe ich mir da eingefangen?? |
appinit_dlls, desktop, drivers, explorer, firewall, google, hijack, hijackthis, hkus\s-1-5-18, ie explorer, internet, internet explorer, log-datei, microsoft, nvidia, object, opera, programme, registry, rundll, security, seiten, shockwave, spyware, syskontroller, system, tuneup.defrag, urlsearchhook, windows, windows xp, yahoo |