![]() |
|
Plagegeister aller Art und deren Bekämpfung: trojan aspx jsWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() trojan aspx js Liebes Team, ich benötige dringend wure Hilfe. Seit ich heute Mittag einen neuen Flash Player heruntergeladen habe, bekomme ich eine Fehlermeldung, dass ich einen Trojaner auf meinem Laptop habe und das Sicherheitscenter meines Laptops deaktviert ist. Der Trojaner heißt: trojan aspx js. Ich habe den rkill durchgeführt, dann den anti mailware durchlaufen lassen, den GMER durchgeführt und den CCleaner This log file is located at C:\rkill.log. Please post this only if requested to by the person helping you. Otherwise you can close this log when you wish. Ran as a on 11.04.2010 at 19:04:28. Processes terminated by Rkill or while it was running: C:\Users\a\AppData\Local\Temp\davclnt.exe \\?\C:\Windows\system32\wbem\WMIADAP.EXE C:\Users\a\Desktop\rkill.com Rkill completed on 11.04.2010 at 19:04:31. GMER 1.0.15.15281 - hxxp://www.gmer.net Rootkit scan 2010-04-11 21:06:32 Windows 6.0.6001 Service Pack 1 Running: zivr35dy.exe; Driver: C:\Users\a\AppData\Local\Temp\fgldrpog.sys ---- Kernel code sections - GMER 1.0.15 ---- .text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8EA02340, 0x3ECA97, 0xE8000020] ---- User code sections - GMER 1.0.15 ---- .text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[3580] kernel32.dll!FindResourceA 769509A5 5 Bytes JMP 0042B440 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.) .text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[3580] kernel32.dll!FindResourceW 769697C7 5 Bytes JMP 0042B480 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.) .text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[3580] USER32.dll!LoadStringA 776A61ED 2 Bytes JMP 0042B710 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.) .text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[3580] USER32.dll!LoadStringA + 3 776A61F0 2 Bytes [D8, 88] .text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[3580] USER32.dll!LoadMenuW 776B3DE3 5 Bytes JMP 0042B600 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.) .text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[3580] USER32.dll!LoadStringW 776B95FB 5 Bytes JMP 0042B660 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.) .text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[3580] USER32.dll!CreateDialogParamA 776C16FD 5 Bytes JMP 0042B4C0 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.) .text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[3580] USER32.dll!CreateDialogParamW 776D1C58 5 Bytes JMP 0042B530 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.) .text C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe[3580] USER32.dll!LoadMenuA 776E7BCF 5 Bytes JMP 0042B5A0 C:\Program Files\Audible\Bin\AudibleDownloadHelper.exe (Download Manager for Audible content/Audible, Inc.) .text C:\Windows\explorer.exe[5692] kernel32.dll!DeleteFileW 7693C5C8 5 Bytes JMP 06BE6600 C:\Program Files\Softex\OmniPass\opfolderext.dll (OpFolderExt/Softex Inc.) .text C:\Windows\explorer.exe[5692] kernel32.dll!CreateFileW 7696CC4E 5 Bytes JMP 06BE5F20 C:\Program Files\Softex\OmniPass\opfolderext.dll (OpFolderExt/Softex Inc.) ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdiplusShutdown] [73F188B4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCloneImage] [73F598A5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDrawImageRectI] [73F1B9D4] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipSetInterpolationMode] [73F0FB47] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdiplusStartup] [73F17A79] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateFromHDC] [73F0EA65] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateBitmapFromStreamICM] [73F4B17D] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipCreateBitmapFromStream] [73F1BC9A] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipGetImageHeight] [73F1074E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipGetImageWidth] [73F106B5] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDisposeImage] [73F071B3] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipLoadImageFromFileICM] [73F9D848] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipLoadImageFromFile] [73F37379] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipDeleteGraphics] [73F0E109] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipFree] [73F0697E] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipAlloc] [73F069A9] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) IAT C:\Windows\explorer.exe[5692] @ C:\Windows\explorer.exe [gdiplus.dll!GdipSetCompositingMode] [73F12465] C:\Windows\WinSxS\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18175_none_9e7bbe54c9c04bca\gdiplus.dll (Microsoft GDI+/Microsoft Corporation) ---- Devices - GMER 1.0.15 ---- AttachedDevice \FileSystem\Ntfs \Ntfs SiWinAcc.sys (Windows Accelerator Driver/Silicon Image, Inc.) AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation) Leider besteht mein Problem nach wie vor und ich bekomme immer noch eine Meldung, dass jemand versicht meinen PC auszuspionieren und der PC versucht ständig ein Programm namens Digital Protection herunterzuladen. Ich bin jetzt echt ein wenig verzweifelt, weil ich nun schon alles durchgespielt habe, was ihr an Hilfelösungen anbietet. Hoffe auf eure Hilfe! |
Themen zu trojan aspx js |
.dll, anti, desktop, digital, digital protection, dringend, explorer.exe, fehlermeldung, file, flash player, gmer, hilfe!, laptop, local\temp, log, log file, neue, nvlddmkm.sys, problem, programm, rkill, scan, sicherheitscenter, system, system32, temp, trojan, trojaner, windows |