Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Trojaner win32.tdss!IK (https://www.trojaner-board.de/80761-trojaner-win32-tdss-ik.html)

dennis_kami 25.12.2009 20:30

Trojaner win32.tdss!IK
 
Hallo zusammen,

es wäre sehr nett, wenn mir einer helfen könnte! Ich bekomme von a-squared die meldung, dass ich den trojaner win32.tdss!ik habe. nachdem er gelöscht wird, wird dieser aber sofort wieder angezeigt. McAfee Virenscanner wurde automatisch deaktiviert und auch die Systemwiederherstellung geht nicht mehr! Könnt ihr mir bitte helfen, da ich meinen Rechner sehr sehr ungern neu aufbauen möchte!

Vielen Dank schonmal

dennis_kami 25.12.2009 21:51

Anbei die Logfiles von malware:

Malwarebytes' Anti-Malware 1.42
Database version: 3429
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

25.12.2009 21:36:53
mbam-log-2009-12-25.txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 203309
Time elapsed: 23 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 3
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 1
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
\\?\globalroot\systemroot\system32\H8SRTskyiurnbld.dll (Trojan.FakeAlert) -> No action taken.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT (Rootkit.TDSS) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> No action taken.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winzfg32 (Trojan.Dialer) -> No action taken.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowCpl\1 (Malware.Trace) -> No action taken.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\forceclassiccontrolpanel (Hijack.ControlPanelStyle) -> No action taken.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> No action taken.

Folders Infected:
D:\Documents and Settings\All Users\AVP 2009 (Malware.Trace) -> No action taken.

Files Infected:
\\?\globalroot\systemroot\system32\H8SRTskyiurnbld.dll (Trojan.FakeAlert) -> No action taken.
C:\WINDOWS\system32\winzfg32.dll (Trojan.Dialer) -> No action taken.


Und Logfile das Zweite:

Malwarebytes' Anti-Malware 1.42
Database version: 3429
Windows 5.1.2600 Service Pack 2
Internet Explorer 6.0.2900.2180

25.12.2009 21:37:37
mbam-log-2009-12-25 (21-37-37).txt

Scan type: Full Scan (C:\|D:\|)
Objects scanned: 203309
Time elapsed: 23 minute(s), 24 second(s)

Memory Processes Infected: 0
Memory Modules Infected: 1
Registry Keys Infected: 3
Registry Values Infected: 2
Registry Data Items Infected: 1
Folders Infected: 1
Files Infected: 2

Memory Processes Infected:
(No malicious items detected)

Memory Modules Infected:
\\?\globalroot\systemroot\system32\H8SRTskyiurnbld.dll (Trojan.FakeAlert) -> Delete on reboot.

Registry Keys Infected:
HKEY_LOCAL_MACHINE\SOFTWARE\H8SRT (Rootkit.TDSS) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MSSMGR (Trojan.Downloader) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\winzfg32 (Trojan.Dialer) -> Quarantined and deleted successfully.

Registry Values Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowCpl\1 (Malware.Trace) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\forceclassiccontrolpanel (Hijack.ControlPanelStyle) -> Quarantined and deleted successfully.

Registry Data Items Infected:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\DisableRegistryTools (Hijack.Regedit) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.

Folders Infected:
D:\Documents and Settings\All Users\AVP 2009 (Malware.Trace) -> Quarantined and deleted successfully.

Files Infected:
\\?\globalroot\systemroot\system32\H8SRTskyiurnbld.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\winzfg32.dll (Trojan.Dialer) -> Quarantined and deleted successfully.


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:34 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131