![]() |
Trojan-Downloader.JS.Iframe.bhy Hab jetzt mein Kaspersky Internet Security über den PC laufen lassen und es hat sich herausgestellt,dass der Trojaner Trojan-Downloader.JS.Iframe.bhy viele exe und htm (noch n paarmehr) infiziert hat und somit die Ausführung vieler Programme unmöglich gemacht hat. Was kann ich dagegen machen? Soll ich alle infizierten Dateien löschen und alles wieder neu installeren? :confused: Bitte um schnelle Hilfe,da mich ein Abgabetermin am 10.Juli drängt... :( |
Hi HyperGumba und :hallo: bitte arbeite, damit dir hier geholfen werden kann, folgende Liste ab: http://www.trojaner-board.de/69886-a...-beachten.html Poste bitte alle anfallenden Logfiles, sowie das Logfile, dass Kaspersky erstellt hat. Gruß Handball10 |
Ich bin soweit gekommen,dass ich mit dem CCleaner alle Schritte durchgeführt habe und mit dem Anti Malware prog alles entfernt habe,sowie ein Logfile erstellt habe. Aber als ich zur endgültigen Säuberung den PC neustarten musste,hat er sich aufgehängt und ich musste ihn resetten. Jetzt kann ich Vista nicht mehr hochfaren,weder normal,noch abgesichert oder sonst was...das einzige was beim Hochfahren passiert ist dass meine Systemfestplatte untersucht wird und bei 60% hängt es sich immer auf...wenn ich die Untersuchung überspringe kommt nur ne Abbruchmeldung und dann tut sich auch nichts mehr...ich bin absolut ratlos...das einzige was mir in den Sinn kommt ist Vista neu zu installieren,aber es erscheint mir auch nicht optimal... Was kann ich noch tun? :( |
Sorry für den Doppelpost,aber ich habe es jetzt irgendwie geschafft,den Rechner im abgesicherten Modus zu starten... Hier schon mal das Logfile,dass ich ja jezt posten kann: " Malwarebytes' Anti-Malware 1.38 Datenbank Version: 2365 Windows 6.0.6001 Service Pack 1 03.07.2009 13:01:21 mbam-log-2009-07-03 (13-01-21).txt Scan-Methode: Vollständiger Scan (C:\|D:\|E:\|G:\|X:\|) Durchsuchte Objekte: 125608 Laufzeit: 5 hour(s), 8 minute(s), 55 second(s) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 8 Infizierte Registrierungswerte: 2 Infizierte Dateiobjekte der Registrierung: 1 Infizierte Verzeichnisse: 0 Infizierte Dateien: 2 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CLASSES_ROOT\imeshmediabar.stockbar (Adware.SoftMate) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{6c380604-92b2-4633-becb-bde03fa45980} (Adware.SoftMate) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{4481c34a-10df-4c96-92a6-0ef31b6b95d6} (Adware.SoftMate) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{f9c23cd1-6da9-4e0b-8367-c6f9f1f78baf} (Adware.SoftMate) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\Stats\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\imeshmediabar.stockbar.1 (Adware.SoftMate) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{eddbb5ee-bb64-4bfc-9dbe-e7c85941335b} (Adware.Zango) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Toolbar\WebBrowser\{b7d3e479-cc68-42b5-a338-938ece35f419} (Adware.SoftMate) -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: HKEY_CLASSES_ROOT\regfile\shell\open\command\(default) (Broken.OpenCommand) -> Bad: ("regedit.exe" "%1") Good: (regedit.exe "%1") -> Quarantined and deleted successfully. Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: X:\Program Files\iMesh Applications\iMesh MediaBar\iMeshMediaBar.dll (Adware.SoftMate) -> Quarantined and deleted successfully. d:\WINDOWS\system32\memman.vxd (Rogue.sysCleanerPro) -> Quarantined and deleted successfully. " Das ist aber noch nicht alles,da ich den Scan nach mehr als 5 Stunden abbrechen musste. Ich hoffe daraus kann schon mal etwas entnommen werden. Ich mache solange mit den Methoden zur Bekämpfung weiter... |
Kann man Beiträge nicht irgendwie editieren? Ich finde keinen Button zum Bearbeiten,also Triplepost :rolleyes: Jedenfalls hab ich den Rest vom Malware Scanner zusammengetragen: "Malwarebytes' Anti-Malware 1.38 Datenbank Version: 2365 Windows 6.0.6001 Service Pack 1 03.07.2009 16:27:30 mbam-log-2009-07-03 (16-27-29).txt Scan-Methode: Vollständiger Scan (C:\|E:\|G:\|X:\|) Durchsuchte Objekte: 609771 Laufzeit: 1 hour(s), 15 minute(s), 25 second(s) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 28 Infizierte Registrierungswerte: 2 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 11 Infizierte Dateien: 32 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CLASSES_ROOT\TypeLib\{03d7ff6e-9781-40b5-bb7f-94291a361604} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{3ceb04ab-08af-45f4-81b4-70d13c1f7b85} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{a7213d71-47e1-4832-92d7-d61dfe9f231f} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{cf82f350-e1c4-4916-ac12-ba73db60afb7} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{abec1835-3181-4abd-8dde-875aec4df6d2} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{0af9a087-0cbf-46b2-9dc9-52d0d16b5ab6} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{69725738-cd68-4f36-8d02-8c43722ee5da} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{69725738-cd68-4f36-8d02-8c43722ee5da} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\TypeLib\{89085678-632d-4deb-bda0-cd912c63203e} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{30b15818-e110-4527-9c05-46ace5a3460d} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{618aad04-921f-44c2-be38-c0818af69861} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{b5d2ed96-62f9-4c2c-956d-e425b1f67337} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{d3a412e8-1e4b-47d2-9b12-f88291f5afbb} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{3788e535-897b-463d-b6d6-fee5b86ec144} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{3788e535-897b-463d-b6d6-fee5b86ec144} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\CLSID\{d3f940ea-4e87-423b-9091-934e1e4fceae} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{d3f940ea-4e87-423b-9091-934e1e4fceae} (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\zangosa (Adware.Zango) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ZangoSA (Adware.Zango) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\zangoax.clientdetector (Adware.Zango) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\zangoax.clientdetector.1 (Adware.Zango) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\zangoax.userprofiles (Adware.Zango) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\zangoax.userprofiles.1 (Adware.Zango) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\wallpaper.wallpapermanager (Adware.Zango) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\wallpaper.wallpapermanager.1 (Adware.Zango) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\srv.coreservices (Adware.Zango) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\srv.coreservices.1 (Adware.Zango) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\zango (Adware.180Solutions) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\zangosa (Adware.180Solutions) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Mozilla\Firefox\Extensions\Zango@Zango.com (Adware.Zango) -> Quarantined and deleted successfully. Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: X:\Program Files\Zango (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0 (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\firefox (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\firefox\extensions (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\firefox\extensions\components (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\firefox\extensions\plugins (Adware.180Solutions) -> Quarantined and deleted successfully. X:\ProgramData\Microsoft\Windows\Start Menu\Programs\Zango (Adware.180Solutions) -> Quarantined and deleted successfully. X:\ProgramData\ZangoSA (Adware.Zango) -> Quarantined and deleted successfully. X:\ProgramData\2ACA5CC3-0F83-453D-A079-1076FE1A8B65 (Adware.Seekmo) -> Quarantined and deleted successfully. x:\Users\Hyper Gumba\AppData\Roaming\Zango (Adware.Zango) -> Delete on reboot. Infizierte Dateien: x:\program files\e2eSoft\VCam\styles\Vista.cjstyles (Trojan.Agent) -> Quarantined and deleted successfully. x:\Users\hyper gumba\downloads\Setup(3).exe (Adware.Zango) -> Quarantined and deleted successfully. x:\Windows\System32\keygen.exe (Trojan.Dropper) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\arrow.ico (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\copyright.txt (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\link.ico (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\Srv.exe (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\Wallpaper.dll (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\WeSkin.dll (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\ZangoSA.exe (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\ZangoSAAX.dll (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\ZangoSADF.exe (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\ZangoSAHook.dll (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\ZangoUninstaller.exe (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\firefox\extensions\chrome.manifest (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\firefox\extensions\install.rdf (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\firefox\extensions\components\npclntax.xpt (Adware.180Solutions) -> Quarantined and deleted successfully. x:\program files\Zango\bin\10.3.84.0\firefox\extensions\plugins\npclntax_ZangoSA.dll (Adware.180Solutions) -> Quarantined and deleted successfully. x:\programdata\microsoft\Windows\start menu\Programs\Zango\Reset Cursor.lnk (Adware.180Solutions) -> Quarantined and deleted successfully. x:\programdata\microsoft\Windows\start menu\Programs\Zango\Weather.lnk (Adware.180Solutions) -> Quarantined and deleted successfully. x:\programdata\microsoft\Windows\start menu\Programs\Zango\Zango Customer Support Center.lnk (Adware.180Solutions) -> Quarantined and deleted successfully. x:\programdata\microsoft\Windows\start menu\Programs\Zango\Zango Games!.lnk (Adware.180Solutions) -> Quarantined and deleted successfully. x:\programdata\microsoft\Windows\start menu\Programs\Zango\Zango Library.lnk (Adware.180Solutions) -> Quarantined and deleted successfully. x:\programdata\microsoft\Windows\start menu\Programs\Zango\Zango Screensavers!.lnk (Adware.180Solutions) -> Quarantined and deleted successfully. x:\programdata\microsoft\Windows\start menu\Programs\Zango\Zango Uninstall Instructions.lnk (Adware.180Solutions) -> Quarantined and deleted successfully. x:\programdata\microsoft\Windows\start menu\Programs\Zango\Zango Videos!.lnk (Adware.180Solutions) -> Quarantined and deleted successfully. x:\programdata\ZangoSA\ZangoSA.dat (Adware.Zango) -> Quarantined and deleted successfully. x:\programdata\ZangoSA\ZangoSAAbout.mht (Adware.Zango) -> Quarantined and deleted successfully. x:\programdata\ZangoSA\ZangoSAau.dat (Adware.Zango) -> Quarantined and deleted successfully. x:\programdata\ZangoSA\ZangoSAEULA.mht (Adware.Zango) -> Quarantined and deleted successfully. x:\programdata\ZangoSA\ZangoSA_hpk.dat (Adware.Zango) -> Quarantined and deleted successfully. x:\programdata\ZangoSA\ZangoSA_kyf.dat (Adware.Zango) -> Quarantined and deleted successfully." Jetzt gehe ich zur letzten Methode über... EDIT(jetzt hab ichs gefunden^^): HJT-Logfile: Code: Logfile of Trend Micro HijackThis v2.0.2 Wäre nett wenn mir n Experte dabei unter die Arme greifen würde ^^" |
Alle Zeitangaben in WEZ +1. Es ist jetzt 15:10 Uhr. |
Copyright ©2000-2025, Trojaner-Board