![]()  |  
 
  |  |||||||
Log-Analyse und Auswertung: Popupfenster mit Tanabfrage beim Onlinebanking der Deutschen BankWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |  
|    |  #5 | 
|    |    Popupfenster mit Tanabfrage beim Onlinebanking der Deutschen Bank Supi =D      Incoming Logfile: Code: 
   ATTFilter  Zoek.exe Version 4.0.0.2 Updated 30-04-2013
Tool run by *** on 16.05.2013 at 16:40:37,73.
Microsoft Windows 7 Professional  6.1.7600  x86
Running in: Normal Mode No Internet Access Detected
==== Older Logs ======================
C:\zoek-results16.05.2013-1639.log	17858 bytes
==== Deleting CLSID Registry Keys ======================
==== Deleting CLSID Registry Values ======================
==== Registry Fix Code ======================
Windows Registry Editor Version 5.00
[HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] 
"Bouqu"=- 
"IExplorer Util"=- 
==== Deleting Files \ Folders ======================
"C:\Users\***\AppData\Local\WavXMapDrive.bat" not deleted
==== Firefox Extensions ======================
ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\kld8xk1k.default
- WEB.DE MailCheck - %ProfilePath%\extensions\toolbar@web.de
- DVDVideoSoft Menu - %ProfilePath%\extensions\{ACAA314B-EEBA-48e4-AD47-84E31C44796C}
ProfilePath: C:\Users\***\AppData\Roaming\Mozilla\Firefox\Profiles\ebrxyid0.default
- WEB.DE MailCheck - %ProfilePath%\extensions\toolbar@web.de
AppDir: C:\Program Files\Mozilla Firefox
- Default - %AppDir%\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
==== Firefox Plugins ======================
Profilepath: C:\Users\Schwoy\AppData\Roaming\Mozilla\Firefox\Profiles\ebrxyid0.default
E0FF893763BA82BAABB869A351F0C455	- C:\Program Files\Google\Update\1.3.21.135\npGoogleUpdate3.dll -	Google Update
F00A0EF5835E1B96F783D617F1948704	- C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll -	iTunes Application Detector
11EF47BE3D8A4A943E10A63870C1F2C6	- C:\Program Files\Mozilla Firefox\plugins\npqtplugin7.dll -	QuickTime Plug-in 7.7.3
4ACB977AAB250731739302CB45A807B3	- C:\Program Files\Mozilla Firefox\plugins\npqtplugin6.dll -	QuickTime Plug-in 7.7.3
6E7690D2EE4E530DAC8C562CF8CCE70B	- C:\Program Files\Mozilla Firefox\plugins\npqtplugin5.dll -	QuickTime Plug-in 7.7.3
D2E4BDDD297B6A481BAC612C25A1F10A	- C:\Program Files\Mozilla Firefox\plugins\npqtplugin4.dll -	QuickTime Plug-in 7.7.3
7A14B17E24CE74BBB603B824EDA79A72	- C:\Program Files\Mozilla Firefox\plugins\npqtplugin3.dll -	QuickTime Plug-in 7.7.3
2A92F41DCBB5832872D8B0E941746112	- C:\Program Files\Mozilla Firefox\plugins\npqtplugin2.dll -	QuickTime Plug-in 7.7.3
C1FD5EE5FD1F65CE223A5C3AE846DDF6	- C:\Program Files\Mozilla Firefox\plugins\npqtplugin.dll -	QuickTime Plug-in 7.7.3
4CD43010502A7E1337D72E2AD296B239	- C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll -	Adobe Acrobat
E971E06DDE68684CB3957C5D0E133CB0	- C:\Program Files\Google\Google Earth\plugin\npgeplugin.dll -	Google Earth Plugin
3509063A268A4197CF8E713BD22B0978	- C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll -	Windows Live® Photo Gallery
4CD43010502A7E1337D72E2AD296B239	- C:\Program Files\Adobe\Reader 9.0\Reader\AIR\nppdf32.dll -	Adobe Acrobat
4CD43010502A7E1337D72E2AD296B239	- C:\Program Files\Adobe\Reader 9.0\Reader\browser\nppdf32.dll -	Adobe Acrobat
C1FD5EE5FD1F65CE223A5C3AE846DDF6	- C:\Program Files\QuickTime\Plugins\npqtplugin.dll -	QuickTime Plug-in 7.7.3
2A92F41DCBB5832872D8B0E941746112	- C:\Program Files\QuickTime\Plugins\npqtplugin2.dll -	QuickTime Plug-in 7.7.3
7A14B17E24CE74BBB603B824EDA79A72	- C:\Program Files\QuickTime\Plugins\npqtplugin3.dll -	QuickTime Plug-in 7.7.3
D2E4BDDD297B6A481BAC612C25A1F10A	- C:\Program Files\QuickTime\Plugins\npqtplugin4.dll -	QuickTime Plug-in 7.7.3
6E7690D2EE4E530DAC8C562CF8CCE70B	- C:\Program Files\QuickTime\Plugins\npqtplugin5.dll -	QuickTime Plug-in 7.7.3
4ACB977AAB250731739302CB45A807B3	- C:\Program Files\QuickTime\Plugins\npqtplugin6.dll -	QuickTime Plug-in 7.7.3
11EF47BE3D8A4A943E10A63870C1F2C6	- C:\Program Files\QuickTime\Plugins\npqtplugin7.dll -	QuickTime Plug-in 7.7.3
==== Set IE to Default ======================
Old Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.de/"
New Values:
[HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main]
"Start Page"="hxxp://www.google.de/"
==== All HKCU SearchScopes ======================
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes
"DefaultScope"="{6A1806CD-94D4-4689-BA73-E35EA1EA9990}"
{2E5477D5-EE7B-4E9F-97B1-604E9E507E08} 1und1 Suche Url="hxxp://go.1und1.de/tb/ie_searchplugin/?su={searchTerms}"
{2FD1614C-4DA5-4A34-BE62-75EC57D3ACB7} WEB.DE Suche Url="hxxp://go.web.de/tb/ie_searchplugin/?su={searchTerms}"
{4D9042FC-D1C4-4BF2-A8AB-C707A66B0E05} GMX search Url="hxxp://search.gmx.com/web?q={searchTerms}&origin=tb_splugin_ie"
{6A1806CD-94D4-4689-BA73-E35EA1EA9990} Google  Url="hxxp://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}"
{E5F508BA-0E7A-4F2C-9DEE-D3771E9BA685} GMX Suche Url="hxxp://go.gmx.net/tb/ie_searchplugin/?su={searchTerms}"
==== Empty IE Cache ======================
C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\administrator.***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Users\***\AppData\Local\Temp\Low\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\***\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\LocalService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5 emptied successfully
C:\Windows\serviceprofiles\LocalService\AppData\Local\Temp\Temporary Internet Files\Content.IE5 emptied successfully
C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
C:\Windows\serviceprofiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat will be deleted at reboot
==== Empty FireFox Cache ======================
C:\users\***\AppData\Local\Mozilla\Firefox\Profiles\kld8xk1k.default\Cache emptied successfully
C:\users\***\AppData\Local\Mozilla\Firefox\Profiles\ebrxyid0.default\Cache emptied successfully
==== Empty Chrome Cache ======================
No Chrome User Data found
==== Empty All Flash Cache ======================
Flash Cache Emptied Successfully
==== Empty All Java Cache ======================
Java Cache cleared successfully
After Reboot
==== Empty Temp Folders ======================
C:\Windows\Temp successfully emptied
C:\Users\***\AppData\Local\Temp successfully emptied
==== Empty Recycle Bin ======================
C:\$RECYCLE.BIN successfully emptied
==== Deleting Files / Folders ======================
"C:\Users\***\AppData\Local\WavXMapDrive.bat"  not found
"C:\Users\***\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
"C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not found
"C:\Windows\serviceprofiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat" not deleted
          Für einen Laien ist das viel Text ohne viel Bedeutung... ^^ Grüße leemur  |  
| Themen zu Popupfenster mit Tanabfrage beim Onlinebanking der Deutschen Bank | 
| arbeiten, aufsetzen, bild, browser, daten, deutsche, ebanking, erlaubt, gestern, guten, klicke, kunde, kundendaten, morgen, neuer, nichts, nummern, onlinebanking, problem, prozess, ratlos, recht, scan, stelle, system, system neu, tan, versuche, ändern |