AdminBot | 24.01.2012 05:53 | Antivirus Smart Protection entfernen Liste der Anhänge anzeigen (Anzahl: 6) Antivirus Smart Protection entfernen Was ist Antivirus Smart Protection?
Antivirus Smart Protection ist eine weitere Rogue-Malware in Form einer gefälschten Scan-Software, die mittels eines sog. Trojaners in den PC eindringt und dem Benutzer weissmacht, den PC nach Malware abzusuchen. Diese Software (Antivirus Smart Protection) ist ein Fake und selbst eine Schadsoftware und sollte nicht gekauft werden.
Da solche Software wie Antivirus Smart Protection sich gegen jede Entfernung wehren wird und Antivirus Smart Protection oftmals noch Rootkits mitinstalliert, sollte eine Neuinstallation des Systems in Erwägung gezogen werden.
Verbreitet wird Scareware wie Antivirus Smart Protection nicht mehr ausschliesslich über 'dubiose Seiten' für Cracks, KeyGens und Warez, sondern auch seriöse Seiten werden zunehmend für die Verbreitung dieser mißbraucht ( http://www.trojaner-board.de/90880-d...tallation.html).
Der wichtigste Schutz vor einer Infizierung ist ein aktuelles Windows (mit allen Updates) und aktuelle Drittanbietersoftware wie Java oder Adobe Flash! http://www.trojaner-board.de/attachm...1&d=1328505340 http://www.trojaner-board.de/attachm...1&d=1328505340 http://www.trojaner-board.de/attachm...1&d=1328505340 Symptome von Antivirus Smart Protection:- ständige Fake Virenmeldungen von Antivirus Smart Protection
- PC läuft seit Antivirus Smart Protection langsamer als üblich
http://www.trojaner-board.de/attachm...1&d=1328505340 http://www.trojaner-board.de/attachm...1&d=1328505340 http://www.trojaner-board.de/attachm...1&d=1328505340 Fake-Meldungen von Antivirus Smart Protection:%UserProfile%\Recent\cb.dll %UserProfile%\Recent\CLSV.drv %UserProfile%\Recent\CLSV.sys %UserProfile%\Recent\eb.exe %UserProfile%\Recent\exec.drv %UserProfile%\Recent\FS.tmp %UserProfile%\Recent\kernel32.tmp %UserProfile%\Recent\PE.drv %UserProfile%\Recent\PE.sys %UserProfile%\Recent\PE.tmp %UserProfile%\Recent\ppal.tmp %UserProfile%\Recent\runddlkey.exe %UserProfile%\Recent\runddlkey.sys %UserProfile%\Recent\snl2w.sys System Alert Suspicious software which may be malicious has been detected on your PC. Click here to remove this threat immediately using Antivirus Smart Protection. System Alert Antivirus Smart Protectionhas detected potentially harmful software in your system. It is strongly recommended that you register Antivirus Smart Protection to remove all found threats immediately. System Alert Potentially harmful programs have been detected in your system and need to be dealt with immediately. Click here to remove them using Antivirus Smart Protection. Warning! Spambot detected! Attention! A spambot sending viruses to your e-mail contacts has been detected on your PC. Warning! Identity theft attempt detected Recommended: Please click "Remove All" button to erase all infected files and protect your PC. Address space conflict Warning! Access conflict detected An unidentified program is trying to access system process address space. System Message Your PC may still be infected with dangerous viruses. Antivirus Smart Protection protection is needed to prevent data loss and avoid theft of your personal data and credit card details. Click here to activate protection. Warning! Virus Detected Threat Detected: Trojan-Spy.HTML.BankFraud.ra Recommended: Please click "Remove All" button to erase all infected files and protect your PC. Dateien von Antivirus Smart Protection: Code:
%AppData%\Antivirus Smart Protection\
%AppData%\Antivirus Smart Protection\cookies.sqlite
%AppData%\Antivirus Smart Protection\Instructions.ini
%AppData%\Antivirus Smart Protection\ScanDisk_.exe
%AppData%\Microsoft\Internet Explorer\Quick Launch\Antivirus Smart Protection.lnk
%CommonAppData%\79b35\
%CommonAppData%\79b35\ASa76.exe
%CommonAppData%\79b35\ASP.ico
%CommonAppData%\79b35\5162.mof
%CommonAppData%\79b35\mozcrt19.dll
%CommonAppData%\79b35\sqlite3.dll
%CommonAppData%\79b35\BackUp\
%CommonAppData%\79b35\BackUp\Adobe Reader Speed Launch.lnk
%CommonAppData%\79b35\BackUp\Adobe Reader Synchronizer.lnk
%CommonAppData%\79b35\ASPSys\
%CommonAppData%\79b35\Quarantine Items\
%CommonAppData%\ASPHEP\
%CommonAppData%\ASPHEP\ASZNFSJTNP.cfg
%Desktop%\Antivirus Smart Protection.lnk
%UserProfile%\Recent\cb.dll
%UserProfile%\Recent\CLSV.drv
%UserProfile%\Recent\CLSV.sys
%UserProfile%\Recent\eb.exe
%UserProfile%\Recent\exec.drv
%UserProfile%\Recent\FS.tmp
%UserProfile%\Recent\kernel32.tmp
%UserProfile%\Recent\PE.drv
%UserProfile%\Recent\PE.sys
%UserProfile%\Recent\PE.tmp
%UserProfile%\Recent\ppal.tmp
%UserProfile%\Recent\runddlkey.exe
%UserProfile%\Recent\runddlkey.sys
%UserProfile%\Recent\snl2w.sys
%StartMenu%\Antivirus Smart Protection.lnk
%StartMenu%\Programs\Antivirus Smart Protection.lnk Registry-Einträge von Antivirus Smart Protection: Code:
HKEY_CURRENT_USER\Software\3
HKEY_CLASSES_ROOT\CLSID\{3F2BBC05-40DF-11D2-9455-00104BC936FF}
HKEY_CLASSES_ROOT\AS3f2_8046.DocHostUIHandler
HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=8046&q={searchTerms}"
HKEY_CURRENT_USER\Software\Classes\Software\Microsoft\Internet Explorer\SearchScopes "URL" = "http://findgala.com/?&uid=8046&q={searchTerms}"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer "PRS" = "http://127.0.0.1:27777/?inj=%ORIGINAL%"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "RunInvalidSignatures" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "78990148703"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\User Agent\Post Platform "ver:2.08046"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer "DisallowRun" = "1"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "0" = "msseces.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "1" = "MSASCui.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "10" = "avgscanx.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "11" = "avgcfgex.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "12" = "avgemc.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "13" = "avgchsvx.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "14" = "avgcmgr.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "15" = "avgwdsvc.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "2" = "ekrn.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "3" = "egui.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "4" = "avgnt.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "5" = "avcenter.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "6" = "avscan.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "7" = "avgfrw.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "8" = "avgui.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun "9" = "avgtray.exe"
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run "Antivirus Smart Protection"
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Download "CheckExeSignatures" = "no"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avp32.exe = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpcc.exe = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\_avpm.exe = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\aAvgApi.exe = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\adaware.exe = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\agentsvr.exe = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zapsetup3001.exe = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zatutor.exe = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonalm2601.exe = "svchost.exe"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\zonealarm.exe = "svchost.exe"
und viele weitere Einträge! Antivirus Smart Protection im HijackThis-Log: Code:
O4 - HKCU\..\Run: [Antivirus Smart Protection] "%CommonAppData%\79b35\ASa76.exe" /s /d |