![]()  |  
 
  |  |||||||
Plagegeister aller Art und deren Bekämpfung: newporto.cn - Online Banking Tan AbfrageWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |  
|    |  #1 | 
  ![]()  |    newporto.cn - Online Banking Tan Abfrage Guten Tag,          Seit einigen Tagen zeigt mir Avast Regelmäßig eine Warnung das eine Schädliche Seite geblockt wurde. Hier der Avast log: Code: 
   ATTFilter  28.09.2010  18:25:16  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8448 ) ]
28.09.2010  18:31:41  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8448 ) ]
28.09.2010  18:38:49  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8448 ) ]
28.09.2010  18:46:56  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8448 ) ]
28.09.2010  18:52:36  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8448 ) ]
28.09.2010  19:32:56  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8988 ) ]
28.09.2010  19:38:38  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8988 ) ]
28.09.2010  19:45:47  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8988 ) ]
28.09.2010  19:51:22  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8988 ) ]
28.09.2010  19:58:14  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8988 ) ]
28.09.2010  20:05:15  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8988 ) ]
28.09.2010  20:12:30  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8988 ) ]
28.09.2010  20:54:44  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8304 ) ]
28.09.2010  21:14:53  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/forms.cgi [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8304 ) ]
28.09.2010  21:24:08  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/forms.cgi [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8304 ) ]
28.09.2010  21:25:07  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/forms.cgi [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8304 ) ]
28.09.2010  21:50:01  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=f50dee09 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 3200 ) ]
28.09.2010  22:05:03  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 3200 ) ]
28.09.2010  22:27:46  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/forms.cgi [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 3200 ) ]
29.09.2010  01:43:33  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=f50dee09 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 7292 ) ]
29.09.2010  10:14:53  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/forms.cgi [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 6664 ) ]
29.09.2010  10:35:11  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/forms.cgi [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 6664 ) ]
29.09.2010  11:14:24  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8760 ) ]
29.09.2010  12:22:27  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8840 ) ]
29.09.2010  12:46:42  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/forms.cgi [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8840 ) ]
29.09.2010  13:02:30  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8840 ) ]
29.09.2010  13:32:33  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=f50dee09 [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8840 ) ]
29.09.2010  14:51:33  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/forms.cgi [ C:\Program Files (x86)\Mozilla Firefox 4.0 Beta 1\firefox.exe ( 8840 ) ]
29.09.2010  16:12:43  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=f50dee09 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 5276 ) ]
29.09.2010  16:22:42  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 6940 ) ]
29.09.2010  17:04:08  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/forms.cgi [ C:\Program Files (x86)\Mozilla Firefox\firefox.exe ( 8960 ) ]
29.09.2010  17:25:45  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/forms.cgi [ C:\Program Files (x86)\Mozilla Firefox\firefox.exe ( 8960 ) ]
29.09.2010  17:53:11  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 7088 ) ]
29.09.2010  18:03:27  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=f50dee09 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 6940 ) ]
29.09.2010  18:54:35  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 2968 ) ]
29.09.2010  19:25:20  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=f50dee09 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 7088 ) ]
29.09.2010  19:35:45  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 5276 ) ]
29.09.2010  20:36:09  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 6940 ) ]
29.09.2010  21:06:44  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 5276 ) ]
29.09.2010  21:36:44  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=f50dee09 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 7088 ) ]
29.09.2010  22:17:31  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=f50dee09 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 6940 ) ]
29.09.2010  22:17:35  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox\firefox.exe ( 5132 ) ]
29.09.2010  22:59:13  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/forms.cgi [ C:\Program Files (x86)\Mozilla Firefox\firefox.exe ( 5132 ) ]
29.09.2010  23:08:14  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Mozilla Firefox\firefox.exe ( 5132 ) ]
30.09.2010  02:28:36  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/options.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=f50dee09 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 6940 ) ]
30.09.2010  23:38:54  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/forms.cgi [ C:\Program Files (x86)\Mozilla Firefox\firefox.exe ( 1508 ) ]
01.10.2010  12:46:23  Network Shield: blocked access to malicious site newporto.cn/cgi-bin/cmd.cgi?user%5fid=793048598&version%5fid=3099&passphrase=fkjvhsdvlksdhvlsd&socks=0&version=3099&crc=00000000 [ C:\Program Files (x86)\Internet Explorer\iexplore.exe ( 1488 ) ]
          Heute wurde ich nach dem einloggen beim Online-Banking nach ca. 20 Tans abgefragt. Habe Malwarebytes downgeloadet und habe einen QuickScan gemacht. LOG: Code: 
   ATTFilter  Malwarebytes' Anti-Malware 1.46
www.malwarebytes.org
Database version: 4727
Windows 6.1.7600
Internet Explorer 8.0.7600.16385
01.10.2010 17:56:18
mbam-log-2010-10-01 (17-56-18).txt
Scan type: Quick scan
Objects scanned: 157104
Time elapsed: 4 minute(s), 14 second(s)
Memory Processes Infected: 0
Memory Modules Infected: 0
Registry Keys Infected: 0
Registry Values Infected: 0
Registry Data Items Infected: 1
Folders Infected: 0
Files Infected: 0
Memory Processes Infected:
(No malicious items detected)
Memory Modules Infected:
(No malicious items detected)
Registry Keys Infected:
(No malicious items detected)
Registry Values Infected:
(No malicious items detected)
Registry Data Items Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Internet Explorer\control panel\ConnectionsTab (Hijack.ConnectionControl) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Folders Infected:
(No malicious items detected)
Files Infected:
(No malicious items detected)
          OTL logs liegen als ZIP Archiv bei. Wie soll ich weiter verfahren?? Velen Vielen Dank yasou  |  
| Themen zu newporto.cn - Online Banking Tan Abfrage | 
| 20 tans, anti-malware, avast, code, control, detected, e-banking, einloggen, explorer, firefox, firefox.exe, geblockt, iexplore.exe, infected, internet, internet explorer, log, malwarebytes, microsoft, mozilla, online, online banking, online-banking, seite, software, tan, tan abfrage, tans, warnung |