Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Verdacht eines Keyloggers

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 25.02.2010, 18:43   #1
Alex1994
 
Verdacht  eines Keyloggers - Standard

Verdacht eines Keyloggers



Hi
Habe einen Verdacht: Es kann sein, dass auf meinem PC ein Keylogger ist. Bin mir jedoch nicht sicher. Möchte Klarheit haben. Mit welchem Programm kann an ihn aufspüren bzw löschen?
Mein Antivirenprogramm G Data findet nichts.

Alt 25.02.2010, 21:03   #2
Alex1994
 
Verdacht  eines Keyloggers - Standard

Verdacht eines Keyloggers



Ich habe mal den KL Detector drüberlaufen lassen: KL-Detector: detect keylogger on your computer! (it is a keylogger detector - NOT a keylogger remover)
Log:
Code:
ATTFilter
No suspicious files were found in your hard disk :)


You MAY want to take a look at:
C:\Users\Alex\
C:\Windows\Temp\
C:\Windows\
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\
C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\
         
Code:
ATTFilter
Below are some file operations that were done during the monitoring process.
Review them carefully and check for suspicious files.


C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Logs\Scheduler.log
was modified.

C:\Users\Alex\ntuser.dat.LOG1
was modified.

C:\Users\Alex\NTUSER.DAT
was modified.

C:\Users\Alex\NTUSER.DAT
was modified.

C:\Windows\Temp\TMP00000042B25A8B2102BE3CBD
was created.

C:\Windows\Temp\TMP00000042B25A8B2102BE3CBD
was modified.

C:\Windows\Temp\TMP00000042B25A8B2102BE3CBD
was removed.

C:\Users\Alex\ntuser.dat.LOG1
was modified.

C:\Windows\Temp
was modified.

C:\Users\Alex\NTUSER.DAT
was modified.

C:\Users\Alex\NTUSER.DAT
was modified.

C:\Windows\Prefetch\WORDPAD.EXE-D7FD7414.pf
was created.

C:\Windows\Prefetch
was modified.

C:\Windows\Prefetch\WORDPAD.EXE-D7FD7414.pf
was modified.

C:\Users\Alex\ntuser.dat.LOG1
was modified.

C:\Users\Alex\NTUSER.DAT
was modified.

C:\Users\Alex\NTUSER.DAT
was modified.

C:\Users\Alex\ntuser.dat.LOG1
was modified.

C:\Users\Alex\NTUSER.DAT
was modified.

C:\Users\Alex\NTUSER.DAT
was modified.

C:\Windows\Temp\TMP000000436DD8529EF694CE29
was created.

C:\Windows\Temp\TMP000000436DD8529EF694CE29
was modified.

C:\Windows\Temp\TMP000000436DD8529EF694CE29
was removed.

C:\Users\Alex\ntuser.dat.LOG1
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Prefetch\MSPAINT.EXE-76E10B24.pf
was created.

C:\Windows\Prefetch\MSPAINT.EXE-76E10B24.pf
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\parent.lock
was created.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default
was modified.

C:\Users\Alex\AppData\Local\Mozilla\Firefox\Mozilla Firefox\update.test
was created.

C:\Users\Alex\AppData\Local\Mozilla\Firefox\Mozilla Firefox
was modified.

C:\Users\Alex\AppData\Local\Mozilla\Firefox\Mozilla Firefox
was modified.

C:\Program Files (x86)\Mozilla Firefox
was modified.

C:\Users\Alex\AppData\Local\Mozilla\Firefox\Profiles\doj45035.default\XUL.mfl
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\cookies.sqlite-journal
was created.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default
was modified.

C:\Windows\Temp\AvkHttp62394689.tmp
was created.

C:\Windows\Temp
was modified.

C:\ProgramData\G DATA\ISDB
was modified.

C:\ProgramData\G DATA\ISDB\avS.isdb.tmp
was modified.

C:\ProgramData\G DATA\ISDB
was modified.

C:\ProgramData\G DATA\ISDB
was modified.

C:\ProgramData\G DATA\ISDB\avSU.isdb.tmp
was modified.

C:\ProgramData\G DATA\ISDB
was modified.

C:\ProgramData\G DATA\ISDB
was modified.

C:\Windows\Temp\AvkHttp62394689.tmp
was removed.

C:\Users\Alex\ntuser.dat.LOG1
was modified.

C:\Users\Alex\NTUSER.DAT
was modified.

C:\Users\Alex\NTUSER.DAT
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\urlclassifierkey3.txt
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\urlclassifierkey3.txt
was modified.

C:\Users\Alex\AppData\Local\Mozilla\Firefox\Profiles\doj45035.default\urlclassifier3.sqlite-journal
was removed.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\sessionstore.js
was created.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\sessionstore.js
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp\AvkHttp62396049.tmp
was renamed to
C:\Windows\Temp\AvkHttp62396049.gz

C:\Windows\Temp\AvkHttp62396049.gz
was removed.

C:\Windows\Temp\AvkHttp62396049.tmp
was removed.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp\AvkHttp62396049.tmp
was renamed to
C:\Windows\Temp\AvkHttp62396049.gz

C:\Windows\Temp\AvkHttp62396049.tmp
was removed.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp\AvkHttp62396049.tmp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp\AvkHttp62396049.tmp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp\AvkHttp62396049.tmp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp\AvkHttp62396049.tmp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp\AvkHttp62396049.tmp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was removed.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp\AvkHttp62396049.tmp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp\AvkHttp62396049.tmp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62396049.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62394689.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62394689.tmp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62394689.gz
was removed.

C:\Windows\Temp\AvkHttp62394689.tmp
was removed.

C:\Users\Alex\AppData\Local\Mozilla\Firefox\Profiles\doj45035.default
was modified.

C:\Users\Alex\AppData\Local\Mozilla\Firefox\Profiles\doj45035.default\Cache\45B62A9Dd01
was modified.

C:\Windows\Temp\AvkHttp62394689.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62386529.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Prefetch\FIREFOX.EXE-18ACFCFF.pf
was modified.

C:\Windows\Prefetch\FIREFOX.EXE-18ACFCFF.pf
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\downloads.sqlite-journal
was created.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\sessionstore-1.js
was created.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default
was modified.

C:\Windows\Temp\AvkHttp62394689.tmp
was created.

C:\Windows\Temp\AvkHttp62394689.tmp
was renamed to
C:\Windows\Temp\AvkHttp62394689.gz

C:\Windows\Temp\AvkHttp62394689.tmp
was removed.

C:\Windows\Temp\AvkHttp62392649.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62385849.tmp
was created.

C:\Windows\Temp\AvkHttp62385849.tmp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62394689.tmp
was created.

C:\Windows\Temp\AvkHttp62394689.tmp
was renamed to
C:\Windows\Temp\AvkHttp62394689.gz

C:\Windows\Temp\AvkHttp62394689.gz
was removed.

C:\Windows\Temp\AvkHttp62394689.tmp
was removed.

C:\Windows\Temp\AvkHttp62394689.tmp
was created.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62392649.tmp
was created.

C:\Windows\Temp\AvkHttp62392649.tmp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62385849.tmp
was created.

C:\Windows\Temp\AvkHttp62385849.tmp
was modified.

C:\Windows\Temp
was modified.

C:\Windows\Temp\AvkHttp62392649.tmp
was created.

C:\Windows\Temp\AvkHttp62394689.tmp
was renamed to
C:\Windows\Temp\AvkHttp62394689.gz

C:\Windows\Temp\AvkHttp62394689.tmp
was removed.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\places.sqlite-journal
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\places.sqlite-journal
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\places.sqlite-journal
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\sessionstore-1.js
was created.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\formhistory.sqlite-journal
was created.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\prefs-1.js
was created.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\places.sqlite-journal
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\places.sqlite-journal
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default\parent.lock
was removed.

C:\Windows\Temp
was modified.

C:\Users\Alex\AppData\Roaming\Mozilla\Firefox\Profiles\doj45035.default
was modified.
         
__________________


Alt 28.02.2010, 14:07   #3
Alex1994
 
Verdacht  eines Keyloggers - Standard

Verdacht eines Keyloggers



Kann mir jemand helfen?
__________________

Alt 28.02.2010, 17:20   #4
rainboww
 
Verdacht  eines Keyloggers - Standard

Verdacht eines Keyloggers






mhm.... hol dir mal pc spyware doctor mit neusten updates und zeige danach die logfiles und schreib mich mal an nachdem du die logfiles gepostet hast

Alt 02.03.2010, 16:03   #5
Alex1994
 
Verdacht  eines Keyloggers - Standard

Verdacht eines Keyloggers



habs jetz mal da runtergeladen: http://www.chip.de/downloads/Spyware-Doctor-2010_16990636.html
Finde aber keine Log File


Alt 02.03.2010, 18:46   #6
rainboww
 
Verdacht  eines Keyloggers - Standard

Verdacht eines Keyloggers



Zitat:
Zitat von Alex1994 Beitrag anzeigen
habs jetz mal da runtergeladen: http://www.chip.de/downloads/Spyware-Doctor-2010_16990636.html
Finde aber keine Log File
oh ja sry fürs lange off sein

das logfile posten heißt die threats die er gefunden hat hier posten bitte 1 zu 1

Alt 03.03.2010, 17:33   #7
Alex1994
 
Verdacht  eines Keyloggers - Standard

Verdacht eines Keyloggers



Wie gesagt. Das Programm gibt mir kein LogFile
Aber hier eij Bild:

Alt 07.03.2010, 16:19   #8
Alex1994
 
Verdacht  eines Keyloggers - Standard

Verdacht eines Keyloggers



Kann mir jemand weiterhelfen?

Alt 08.03.2010, 16:40   #9
rainboww
 
Verdacht  eines Keyloggers - Standard

Verdacht eines Keyloggers



ok hol dir mal Dr.webcureit

ausführen und danach restart

Antwort

Themen zu Verdacht eines Keyloggers
antivirenprogramm, data, g data, keylogger, löschen, nichts, programm, verdacht, welchem



Ähnliche Themen: Verdacht eines Keyloggers


  1. Vermutung eines Trojaners!
    Plagegeister aller Art und deren Bekämpfung - 11.04.2015 (44)
  2. Empfänger von Mails eines Keyloggers.
    Diskussionsforum - 06.03.2014 (4)
  3. Wieder mal eine Auswertung eines OTLPE-Logs eines GVU/GEMA Trojaner infizierten Systems
    Log-Analyse und Auswertung - 29.06.2013 (10)
  4. Verdacht auf Trojaner / Datenspionage eines Stalkers
    Log-Analyse und Auswertung - 18.05.2012 (3)
  5. RegClean Pro - Rogue Verdacht nach Öffnen eines Fake-Facebookvideos
    Plagegeister aller Art und deren Bekämpfung - 12.03.2012 (27)
  6. Bin ich opfer eines Botnetzes ?
    Log-Analyse und Auswertung - 31.03.2011 (1)
  7. Verdacht eines Virus o.Ä.
    Log-Analyse und Auswertung - 12.09.2009 (1)
  8. Nach Entfernung eines Keyloggers + Trojaners
    Plagegeister aller Art und deren Bekämpfung - 11.09.2009 (39)
  9. Opfer eines Hacker
    Alles rund um Windows - 27.01.2009 (1)
  10. Werk eines Virus?
    Mülltonne - 07.12.2008 (0)
  11. Funktionsweise eines Trojaners
    Plagegeister aller Art und deren Bekämpfung - 30.08.2006 (3)
  12. Signatur eines Exploits
    Plagegeister aller Art und deren Bekämpfung - 02.12.2005 (19)
  13. Tagebuch eines Umsteigers
    Alles rund um Mac OSX & Linux - 16.10.2005 (63)
  14. Problem eines Laien
    Log-Analyse und Auswertung - 30.03.2005 (13)
  15. Probleme eines Newbies
    Plagegeister aller Art und deren Bekämpfung - 09.10.2004 (15)

Zum Thema Verdacht eines Keyloggers - Hi Habe einen Verdacht: Es kann sein, dass auf meinem PC ein Keylogger ist. Bin mir jedoch nicht sicher. Möchte Klarheit haben. Mit welchem Programm kann an ihn aufspüren bzw - Verdacht eines Keyloggers...
Archiv
Du betrachtest: Verdacht eines Keyloggers auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.