Hallo,
ich habe mir gestern Abend leider einen Trojaner eingefangen.
Es handelt sich um den Windows7 Antwi- Virus. Dieser startet automatisch, wenn ich den Computer starte. Nach ein paar Minuten öffnet sich dann ein neues Fenster und mit wird angezeigt, dass sich ein anderer Computer per Remote zugeschaltet hat.
Ich habe schon einmal einen Virenscna mit Malewarebyte durchgeführt:
Zitat:
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 3
Infizierte Dateien: 20
Infizierte Speicherprozesse:
c:\Users\xxx\AppData\Roaming\antivirus_antispyware_2011\antivirus antispyware.exe (Rogue.AntiVirusAntiSpyware2011) -> 2240 -> Unloaded process successfully.
c:\Users\xxx\AppData\Roaming\antivirus_antispyware_2011\securitymanager.exe (Trojan.FakeAlert) -> 2216 -> Unloaded process successfully.
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiVirus_AntiSpyware_2011 (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Software\AntiVirus_AntiSpyware_2011 (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AntiVirus_AntiSpyware_2011 (Rogue.AntiVirusAntiSpyware2011) -> Value: AntiVirus_AntiSpyware_2011 -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AntiVirus AntiSpyware 2011 Security (Trojan.FakeAlert) -> Value: AntiVirus AntiSpyware 2011 Security -> Quarantined and deleted successfully.
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
c:\Users\xxx\AppData\Roaming\42379122 (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\antivirus_antispyware_2011 (Rogue.AV) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\microsoft\Windows\start menu\Programs\antivirus_antispyware_2011 (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
Infizierte Dateien:
c:\Users\xxx\AppData\Roaming\antivirus_antispyware_2011\antivirus antispyware.exe (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\antivirus_antispyware_2011\securitymanager.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Local\Temp\0.9049510574294725.exe (Heuristics.Shuriken) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\42379122\3093000.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\antivirus_antispyware_2011\securityhelper.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\microsoft\Windows\start menu\Programs\antivirus_antispyware_2011.lnk (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
c:\Users\xxx\Desktop\antivirus_antispyware_2011.lnk (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\microsoft\internet explorer\quick launch\antivirus_antispyware_2011.lnk (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Local\Temp\ppddfcfux.exxe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Local\Temp\w32rim_mem.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Local\Temp\wrfwe_di.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\42379122\101000.exe (Rogue.Multiple) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\antivirus_antispyware_2011\icoactivate.ico (Rogue.AV) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\antivirus_antispyware_2011\IcoHelp.ico (Rogue.AV) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\antivirus_antispyware_2011\IcoMain.ico (Rogue.AV) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\antivirus_antispyware_2011\icouninstall.ico (Rogue.AV) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\microsoft\Windows\start menu\Programs\antivirus_antispyware_2011\activate antivirus_antispyware_2011.lnk (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\microsoft\Windows\start menu\Programs\antivirus_antispyware_2011\antivirus_antispyware_2011.lnk (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\microsoft\Windows\start menu\Programs\antivirus_antispyware_2011\help antivirus_antispyware_2011.lnk (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
c:\Users\xxx\AppData\Roaming\microsoft\Windows\start menu\Programs\antivirus_antispyware_2011\how to activate antivirus_antispyware_2011.lnk (Rogue.AntiVirusAntiSpyware2011) -> Quarantined and deleted successfully.
|
Danach habe ich dann OTL Durchgeführt
Jetzt weiß ich nicht mehr weiter und ich hoffe ihr könnt mir helfen
Danke schonmal im vorraus