![]() |
|
Log-Analyse und Auswertung: Nach "Security Tools" mega verseucht, tausend PROZESSE und PHISHINGWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
|
![]() | #1 |
/// Malware-holic ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Nach "Security Tools" mega verseucht, tausend PROZESSE und PHISHING du hast ja Malwarebytes genutzt, kannst du unter logdateien schauen und das oder die scanlogs posten? |
![]() | #2 |
![]() | ![]() Nach "Security Tools" mega verseucht, tausend PROZESSE und PHISHING MalwareBytes Scan vom 20.09. (erster scan nachdem ich die ganzen Prozesse entdeckt habe):
__________________Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4645 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 20.09.2010 13:22:30 mbam-log-2010-09-20 (13-22-30).txt Scan type: Quick scan Objects scanned: 144538 Time elapsed: 11 minute(s), 45 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 3 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: HKEY_CURRENT_USER\SOFTWARE\AAK8K3J4FL (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\D9Q071WKGS (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\SOFTWARE\Microsoft\Handle (Malware.Trace) -> Quarantined and deleted successfully. Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Letzter Scan am selben Tag (hab glaub ich 4 Vollscans mit MWB an dem Tag gemacht): Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4645 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 20.09.2010 22:08:13 mbam-log-2010-09-20 (22-08-13).txt Scan type: Quick scan Objects scanned: 144419 Time elapsed: 7 minute(s), 50 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 0 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: (No malicious items detected) Scan von gerade eben: Malwarebytes' Anti-Malware 1.46 www.malwarebytes.org Database version: 4685 Windows 5.1.2600 Service Pack 3 Internet Explorer 6.0.2900.5512 24.09.2010 20:45:31 mbam-log-2010-09-24 (20-45-31).txt Scan type: Full scan (E:\|F:\|) Objects scanned: 428852 Time elapsed: 2 hour(s), 13 minute(s), 30 second(s) Memory Processes Infected: 0 Memory Modules Infected: 0 Registry Keys Infected: 0 Registry Values Infected: 0 Registry Data Items Infected: 0 Folders Infected: 0 Files Infected: 2 Memory Processes Infected: (No malicious items detected) Memory Modules Infected: (No malicious items detected) Registry Keys Infected: (No malicious items detected) Registry Values Infected: (No malicious items detected) Registry Data Items Infected: (No malicious items detected) Folders Infected: (No malicious items detected) Files Infected: E:\Programme\D-Fend Reloaded\Bin\SetInstallerLanguage.exe (P2P.Dropper) -> Quarantined and deleted successfully. F:\System Volume Information\_restore{40BD17F0-2247-4CC8-9722-95DA8067EF1F}\RP1\A0000059.exe (Trojan.Downloader) -> Quarantined and deleted successfully. |
![]() |
Themen zu Nach "Security Tools" mega verseucht, tausend PROZESSE und PHISHING |
adobe, antivir, antivir guard, avira, bho, browser guard, cpu-last, defender, desktop, dll, e-banking, einstellungen, exe, firefox.exe, hijack, hkus\s-1-5-18, internet, internet explorer, mozilla, neustart, nlssrv32.exe, phishing, plug-in, prozesse, rkill.com, rundll, security, security tools, server, software, system, taskmanager, viele prozesse, viele prozessse phishing bank security tool, windows |