|
Log-Analyse und Auswertung: Bitte um Überprüfung des Logfile vom HijackThisWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
08.12.2004, 18:25 | #1 |
| Bitte um Überprüfung des Logfile vom HijackThis Hallo, da ich mir in letzter Zeit einige Trojaner eingafangen hatte, der AVK aber nichts mehr findet wäre ich sehr dankbar wenn Ihr einmal folgendes Logfile überprüfen könntet und mir sagen was ich tun, bzw fixen soll. Vielen, vielen Dank im Vorraus Vandol Logfile of HijackThis v1.98.2 Scan saved at 18:12:07, on 08.12.2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\AntiVirenKit 2004\AVKService.exe C:\Programme\AntiVirenKit 2004\AVKWCtl.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\LTSMMSG.exe C:\WINDOWS\htpatch.exe C:\WINDOWS\System32\ezSP_Px.exe C:\Programme\Roxio\WinOnCD\DirectCD\DirectCD.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\P2P Networking\P2P Networking.exe C:\Program Files\Windows TaskAd\WinTaskAd.exe C:\Program Files\Windows TaskAd\WinSched.exe C:\WINDOWS\system32\rundll32.exe C:\Tools\WinRar\WinRAR.exe C:\DOKUME~1\Andreas\LOKALE~1\Temp\Rar$EX00.125\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32/left.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmx.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://search.search-exe.com/nph-sea...=sbar1_srchbtn R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.search-exe.com/nph-sea...ook=stmpl1&fw= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.gmx.de/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.123.254 R3 - URLSearchHook: (no name) - {9368D063-44BE-49B9-BD14-BB9663FD38FC} - (no file) O1 - Hosts: 69.20.16.183 auto.search.msn.com O1 - Hosts: 69.20.16.183 search.netscape.com O1 - Hosts: 69.20.16.183 ieautosearch O1 - Hosts: 69.20.16.183 ieautosearch O2 - BHO: CBho404 Object - {087173EF-9829-4F49-8340-A524177D3F60} - C:\WINDOWS\System32\inetp60.dll O2 - BHO: FeaturedResultsBHO Class - {0DDBB570-0396-44C9-986A-8F6F61A51C2F} - C:\WINDOWS\System32\msiefr40.dll O3 - Toolbar: (no name) - {0E1230F8-EA50-42A9-983C-D22ABC2EED3B} - (no file) O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programme\Roxio\WinOnCD\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300" O4 - HKLM\..\Run: [{2CF0B992-5EEB-4143-99C0-5297EF71F444}] rundll32.exe C:\WINDOWS\System32\STLBCL~1.DLL,DllRunMain O4 - HKLM\..\Run: [Rundll32_7] rundll32.exe C:\WINDOWS\System32\msiefr40.dll,DllRunServer O4 - HKLM\..\Run: [Rundll32_8] rundll32.exe C:\WINDOWS\System32\inetp60.dll,DllRunServer O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [Windows TaskAd] C:\Program Files\Windows TaskAd\WinTaskAd.exe O4 - HKLM\..\Run: [VBundleOuterDL] C:\Programme\VBouncer\BundleOuter.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE O8 - Extra context menu item: Web Rebates - file://C:\Programme\Web_Rebates\Sy1150\Tp1150\scri1150a.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O15 - Trusted Zone: *.sony-europe.com O15 - Trusted Zone: *.sonystyle-europe.com O15 - Trusted Zone: *.vaio-link.com O16 - DPF: {02C20140-76F8-4763-83D5-B660107B7A90} - http://63.219.181.7/cax.cab O16 - DPF: {037B3D58-D14A-4C41-BDFD-BD779B0B97BA} - http://www.thepaymentcentre.com/build/vxiewer.cab O16 - DPF: {0B682CC1-FB40-4006-A5DD-99EDD3C9095D} - http://www.thepaymentcentre.com/build/vbiewer.cab O16 - DPF: {14325268-79E0-4D2A-89A4-FFFC6E22741E} - http://akamai.downloadv3.com/binarie...ce_3_EN_XP.cab O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://static.windupdates.com/cab/Cl.../bridge-c2.cab O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) - O16 - DPF: {79849612-A98F-45B8-95E9-4D13C7B6B35C} (Loader2 Control) - http://static.topconverting.com/activex/loader2.ocx O16 - DPF: {E0B795B4-FD95-4ABD-A375-27962EFCE8CF} (StarInstall Control) - http://install.power-url.de/StarInstall.ocx O17 - HKLM\System\CCS\Services\Tcpip\..\{D2A12191-BBB1-450F-B9BF-7E5BDB10B8DD}: NameServer = 192.168.123.254,212.185.252.73 |
08.12.2004, 19:04 | #2 | ||
Administrator, a.D. | Bitte um Überprüfung des Logfile vom HijackThis Hallo,
__________________Zitat:
Zitat:
Lade und scanne mit eScan AntiVirus im abgesicherten Modus wie beschrieben. Poste anschliessend die Virus Log Information von eScan AntiVirus: Öffne die mwav.log -> Bearbeiten -> Suchen -> infected oder tagged eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen.
__________________ |
08.12.2004, 19:43 | #3 |
| Bitte um Überprüfung des Logfile vom HijackThis Hallo Cidre,
__________________erstmal danke für den Tip und schnelle Hilfe, hier die Virus Log Information: Wed Dec 08 19:21:10 2004 => File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Wed Dec 08 19:21:26 2004 => File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Wed Dec 08 19:21:35 2004 => File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Wed Dec 08 19:21:38 2004 => File C:\WINDOWS\ml-uninstall-v10.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Wed Dec 08 19:21:39 2004 => File C:\WINDOWS\p2p[p2p-10220,de].exe tagged as not-a-virus:PornWare.Dialer.Intexdial. No Action Taken. Wed Dec 08 19:21:44 2004 => File C:\WINDOWS\_MSRSTRT.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Wed Dec 08 19:22:12 2004 => File C:\WINDOWS\system32\instsrv.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. Wed Dec 08 19:24:59 2004 => File C:\Drivers\SiSChipsetDriver\AGP\htpatch\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Wed Dec 08 19:25:04 2004 => File C:\holi39143531.exe tagged as not-a-virus:PornWare.Dialer.Holistyc.gen. No Action Taken. Wed Dec 08 19:21:08 2004 => File C:\PROGRA~2\WINDOW~1\WINPRO~1.DLL infected by "not-a-virus:AdWare.WinAD.b" Virus. Action Taken: No Action Taken. Wed Dec 08 19:21:08 2004 => File C:\PROGRA~2\WINDOW~1\WinSched.exe infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 19:21:08 2004 => File C:\PROGRA~2\WINDOW~1\WINTAS~1.EXE infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 19:21:15 2004 => File C:\WINDOWS\System32\msiefr40.dll infected by "not-a-virus:AdWare.Toolbar.Cash" Virus. Action Taken: No Action Taken. Wed Dec 08 19:21:27 2004 => File C:\PROGRA~2\WINDOW~1\WINTAS~1.EXE infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 19:21:45 2004 => File C:\WINDOWS\system32\aklsp.dll infected by "TrojanDownloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. Wed Dec 08 19:22:06 2004 => File C:\WINDOWS\system32\gfkcsp.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:22:25 2004 => File C:\WINDOWS\system32\mphtmler.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:22:28 2004 => File C:\WINDOWS\system32\msiefr40.dll infected by "not-a-virus:AdWare.Toolbar.Cash" Virus. Action Taken: No Action Taken. Wed Dec 08 19:22:33 2004 => File C:\WINDOWS\system32\mt-uninstaller.exe infected by "not-a-virus:AdWare.PurityScan.u" Virus. Action Taken: No Action Taken. Wed Dec 08 19:22:57 2004 => File C:\WINDOWS\system32\sxmsg.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:23:04 2004 => File C:\WINDOWS\system32\vzmdbg.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:23:07 2004 => File C:\WINDOWS\system32\wkweb.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:25:04 2004 => File C:\Program Files\Windows TaskAd\WinProject.dll infected by "not-a-virus:AdWare.WinAD.b" Virus. Action Taken: No Action Taken. Wed Dec 08 19:25:04 2004 => File C:\Program Files\Windows TaskAd\WinSched.exe infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 19:25:05 2004 => File C:\Program Files\Windows TaskAd\WinTaskAd.exe infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 19:31:17 2004 => Total Files Scanned: 15425 Wed Dec 08 19:31:17 2004 => Total Virus(es) Found: 25 Wed Dec 08 19:31:17 2004 => Total Disinfected Files: 0 Wed Dec 08 19:31:17 2004 => Total Files Renamed: 0 Wed Dec 08 19:31:17 2004 => Total Deleted Files: 0 Wed Dec 08 19:31:17 2004 => Total Errors: 3 Wed Dec 08 19:31:17 2004 => Time Elapsed: 00:10:17 Wed Dec 08 19:31:17 2004 => ***** Scanning complete. ***** Wed Dec 08 19:31:17 2004 => Virus Database Date: 2004/12/08 Wed Dec 08 19:31:17 2004 => Virus Database Count: 111920 Wed Dec 08 19:31:17 2004 => Scan Completed. |
08.12.2004, 19:48 | #4 |
Administrator, a.D. | Bitte um Überprüfung des Logfile vom HijackThis Die Virus Log Information ist nicht vollständig, auf deinem Syste befinden sich mehr als 15000 Dateien, oder?! Hast du im abgesicherten Modus gescannt? Hast du die Haken richtig gesetzt? http://www.trojaner-board.de/42731-escan-anleitung.html |
08.12.2004, 20:13 | #5 |
| Bitte um Überprüfung des Logfile vom HijackThis Bin im mom nochmal an scanen, diesmal läuft es langsamer, wenn es fertig ist poste ich die Liste erneut. Aber das scheint noch nen Moment zu dauern. Hoffe Du hast noch nen bissel Zeit. Danke für die Hilfe. |
08.12.2004, 23:03 | #6 |
| Bitte um Überprüfung des Logfile vom HijackThis Hallo Cidre, hier ist nun die vollständige Virus Log Information: Wed Dec 08 19:21:10 2004 => File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Wed Dec 08 19:21:26 2004 => File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Wed Dec 08 19:21:35 2004 => File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Wed Dec 08 19:21:38 2004 => File C:\WINDOWS\ml-uninstall-v10.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Wed Dec 08 19:21:39 2004 => File C:\WINDOWS\p2p[p2p-10220,de].exe tagged as not-a-virus:PornWare.Dialer.Intexdial. No Action Taken. Wed Dec 08 19:21:44 2004 => File C:\WINDOWS\_MSRSTRT.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Wed Dec 08 19:22:12 2004 => File C:\WINDOWS\system32\instsrv.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. Wed Dec 08 19:24:59 2004 => File C:\Drivers\SiSChipsetDriver\AGP\htpatch\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Wed Dec 08 19:25:04 2004 => File C:\holi39143531.exe tagged as not-a-virus:PornWare.Dialer.Holistyc.gen. No Action Taken. Wed Dec 08 19:53:47 2004 => File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Wed Dec 08 19:54:01 2004 => File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Wed Dec 08 19:54:05 2004 => File C:\WINDOWS\ml-uninstall-v10.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Wed Dec 08 19:54:06 2004 => File C:\WINDOWS\p2p[p2p-10220,de].exe tagged as not-a-virus:PornWare.Dialer.Intexdial. No Action Taken. Wed Dec 08 19:54:14 2004 => File C:\WINDOWS\_MSRSTRT.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Wed Dec 08 19:54:59 2004 => File C:\WINDOWS\system32\instsrv.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. Wed Dec 08 19:58:59 2004 => File C:\Drivers\SiSChipsetDriver\AGP\htpatch\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Wed Dec 08 19:59:14 2004 => File C:\holi39143531.exe tagged as not-a-virus:PornWare.Dialer.Holistyc.gen. No Action Taken. Wed Dec 08 20:52:08 2004 => File C:\System Volume Information\_restore{7DCDA70F-8ADA-4E32-865D-08FDE263104C}\RP232\A0236994.exe tagged as not-a-virus:PornWare.Dialer.Holistyc.gen. No Action Taken. Wed Dec 08 20:56:13 2004 => File C:\System Volume Information\_restore{7DCDA70F-8ADA-4E32-865D-08FDE263104C}\RP244\A0241511.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. Wed Dec 08 21:08:54 2004 => File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Wed Dec 08 21:18:36 2004 => File C:\WINDOWS\ml-uninstall-v10.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Wed Dec 08 21:18:39 2004 => File C:\WINDOWS\p2p[p2p-10220,de].exe tagged as not-a-virus:PornWare.Dialer.Intexdial. No Action Taken. Wed Dec 08 21:30:00 2004 => File C:\WINDOWS\system32\instsrv.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. Wed Dec 08 21:32:49 2004 => File C:\WINDOWS\_MSRSTRT.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Wed Dec 08 21:48:38 2004 => File D:\Festplatte_Downloads\Programme\Patches\Maske der Ewigkeit\moe13.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Wed Dec 08 21:49:11 2004 => File D:\Festplatte_Downloads\Programme\Patches\Quake II\Sonstige\REBOOT95.ZIP tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Wed Dec 08 21:49:19 2004 => File D:\Festplatte_Downloads\Programme\Patches\Skout\skout101.zip tagged as not-a-virus:Cracker.AssasinPatch. No Action Taken. Wed Dec 08 21:52:00 2004 => File D:\System Volume Information\_restore{7DCDA70F-8ADA-4E32-865D-08FDE263104C}\RP238\A0240307.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Wed Dec 08 19:21:08 2004 => File C:\PROGRA~2\WINDOW~1\WINPRO~1.DLL infected by "not-a-virus:AdWare.WinAD.b" Virus. Action Taken: No Action Taken. Wed Dec 08 19:21:08 2004 => File C:\PROGRA~2\WINDOW~1\WinSched.exe infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 19:21:08 2004 => File C:\PROGRA~2\WINDOW~1\WINTAS~1.EXE infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 19:21:15 2004 => File C:\WINDOWS\System32\msiefr40.dll infected by "not-a-virus:AdWare.Toolbar.Cash" Virus. Action Taken: No Action Taken. Wed Dec 08 19:21:27 2004 => File C:\PROGRA~2\WINDOW~1\WINTAS~1.EXE infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 19:21:45 2004 => File C:\WINDOWS\system32\aklsp.dll infected by "TrojanDownloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. Wed Dec 08 19:22:06 2004 => File C:\WINDOWS\system32\gfkcsp.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:22:25 2004 => File C:\WINDOWS\system32\mphtmler.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:22:28 2004 => File C:\WINDOWS\system32\msiefr40.dll infected by "not-a-virus:AdWare.Toolbar.Cash" Virus. Action Taken: No Action Taken. Wed Dec 08 19:22:33 2004 => File C:\WINDOWS\system32\mt-uninstaller.exe infected by "not-a-virus:AdWare.PurityScan.u" Virus. Action Taken: No Action Taken. Wed Dec 08 19:22:57 2004 => File C:\WINDOWS\system32\sxmsg.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:23:04 2004 => File C:\WINDOWS\system32\vzmdbg.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:23:07 2004 => File C:\WINDOWS\system32\wkweb.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Fortsetzung folgt |
08.12.2004, 23:04 | #7 |
| Bitte um Überprüfung des Logfile vom HijackThis Hier nun der restliche Teil: Wed Dec 08 19:25:04 2004 => File C:\Program Files\Windows TaskAd\WinProject.dll infected by "not-a-virus:AdWare.WinAD.b" Virus. Action Taken: No Action Taken. Wed Dec 08 19:25:04 2004 => File C:\Program Files\Windows TaskAd\WinSched.exe infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 19:25:05 2004 => File C:\Program Files\Windows TaskAd\WinTaskAd.exe infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 19:53:48 2004 => File C:\PROGRA~2\WINDOW~1\WINTAS~1.EXE infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 19:54:16 2004 => File C:\WINDOWS\system32\aklsp.dll infected by "TrojanDownloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. Wed Dec 08 19:54:49 2004 => File C:\WINDOWS\system32\gfkcsp.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:55:18 2004 => File C:\WINDOWS\system32\mphtmler.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:55:23 2004 => File C:\WINDOWS\system32\msiefr40.dll infected by "not-a-virus:AdWare.Toolbar.Cash" Virus. Action Taken: No Action Taken. Wed Dec 08 19:55:31 2004 => File C:\WINDOWS\system32\mt-uninstaller.exe infected by "not-a-virus:AdWare.PurityScan.u" Virus. Action Taken: No Action Taken. Wed Dec 08 19:56:11 2004 => File C:\WINDOWS\system32\sxmsg.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:56:22 2004 => File C:\WINDOWS\system32\vzmdbg.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:56:28 2004 => File C:\WINDOWS\system32\wkweb.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 19:59:15 2004 => File C:\Program Files\Windows TaskAd\WinProject.dll infected by "not-a-virus:AdWare.WinAD.b" Virus. Action Taken: No Action Taken. Wed Dec 08 19:59:15 2004 => File C:\Program Files\Windows TaskAd\WinSched.exe infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 19:59:15 2004 => File C:\Program Files\Windows TaskAd\WinTaskAd.exe infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Wed Dec 08 20:12:42 2004 => File C:\Programme\PerfectNav\BHO\PerfectNav150c.dll infected by "not-a-virus:AdWare.Perfnav.a" Virus. Action Taken: No Action Taken. Wed Dec 08 20:13:32 2004 => File C:\Programme\RegCleaner\Backups\Mybar.dll infected by "not-a-virus:AdWare.ToolBar.MyWay.g" Virus. Action Taken: No Action Taken. Wed Dec 08 20:14:10 2004 => File C:\Programme\SED\SE.exe infected by "not-a-virus:AdWare.WindowEnhancer" Virus. Action Taken: No Action Taken. Wed Dec 08 20:14:11 2004 => File C:\Programme\SED\SED.exe infected by "not-a-virus:AdWare.Cres" Virus. Action Taken: No Action Taken. Wed Dec 08 20:20:55 2004 => File C:\RECYCLER\S-1-5-21-2919174591-3357591376-1883412291-1005\Dc40.exe infected by "not-a-virus:AdWare.ToolBar.Perez.a" Virus. Action Taken: No Action Taken. Wed Dec 08 20:42:08 2004 => File C:\System Volume Information\_restore{7DCDA70F-8ADA-4E32-865D-08FDE263104C}\RP224\A0206965.exe infected by "not-a-virus:AdWare.Gator.5115" Virus. Action Taken: No Action Taken. Wed Dec 08 20:42:09 2004 => File C:\System Volume Information\_restore{7DCDA70F-8ADA-4E32-865D-08FDE263104C}\RP224\A0206971.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. Action Taken: No Action Taken. Wed Dec 08 20:42:09 2004 => File C:\System Volume Information\_restore{7DCDA70F-8ADA-4E32-865D-08FDE263104C}\RP224\A0206972.dll infected by "not-a-virus:AdWare.Gator.5115" Virus. Action Taken: No Action Taken. Die Restoredateien wieder holen sich mehrmals. Hoffe es ist OK das ich hie abbreche sie aufzulisten um die Liste nicht zu lang zu halten Wed Dec 08 21:26:51 2004 => File C:\WINDOWS\system32\aklsp.dll infected by "TrojanDownloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. Wed Dec 08 21:29:50 2004 => File C:\WINDOWS\system32\gfkcsp.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 21:30:21 2004 => File C:\WINDOWS\system32\mphtmler.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 21:30:26 2004 => File C:\WINDOWS\system32\msiefr40.dll infected by "not-a-virus:AdWare.Toolbar.Cash" Virus. Action Taken: No Action Taken. Wed Dec 08 21:30:36 2004 => File C:\WINDOWS\system32\mt-uninstaller.exe infected by "not-a-virus:AdWare.PurityScan.u" Virus. Action Taken: No Action Taken. Wed Dec 08 21:31:46 2004 => File C:\WINDOWS\system32\sxmsg.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 21:32:01 2004 => File C:\WINDOWS\system32\vzmdbg.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 21:32:15 2004 => File C:\WINDOWS\system32\wkweb.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. Wed Dec 08 21:32:27 2004 => File C:\WINDOWS\Temp\nsdtmp09.dll infected by "not-a-virus:AdWare.MetaDirect.a" Virus. Action Taken: No Action Taken. Wed Dec 08 21:32:34 2004 => File C:\WINDOWS\Temp\WToolsB.dll infected by "not-a-virus:AdWare.Wintol.p" Virus. Action Taken: No Action Taken. Wed Dec 08 21:36:48 2004 => File D:\Festplatte_Downloads\Downloads\backups\backup-20040925-125829-996.dll infected by "not-a-virus:AdWare.Perfnav.a" Virus. Action Taken: No Action Taken. Wed Dec 08 21:36:48 2004 => File D:\Festplatte_Downloads\Downloads\backups\backup-20040925-125830-808.dll infected by "not-a-virus:AdWare.MediaTickets.b" Virus. Action Taken: No Action Taken. Wed Dec 08 21:36:48 2004 => File D:\Festplatte_Downloads\Downloads\backups\backup-20040925-125830-821.dll infected by "not-a-virus:AdWare.Gator.1015" Virus. Action Taken: No Action Taken. Wed Dec 08 21:53:51 2004 => ***** Scanning complete. ***** Wed Dec 08 21:53:51 2004 => Total Files Scanned: 112297 Wed Dec 08 21:53:51 2004 => Total Virus(es) Found: 203 Wed Dec 08 21:53:51 2004 => Total Disinfected Files: 0 Wed Dec 08 21:53:51 2004 => Total Files Renamed: 0 Wed Dec 08 21:53:51 2004 => Total Deleted Files: 0 Wed Dec 08 21:53:51 2004 => Total Errors: 4 Wed Dec 08 21:53:51 2004 => Time Elapsed: 02:00:10 Wed Dec 08 21:53:51 2004 => Virus Database Date: 2004/12/08 Wed Dec 08 21:53:51 2004 => Virus Database Count: 111920 Wed Dec 08 21:53:51 2004 => Scan Completed. Completed. |
08.12.2004, 23:49 | #8 |
Administrator, a.D. | Bitte um Überprüfung des Logfile vom HijackThis Deaktiviere die Systemwiederherstellung -> lösche alle Dateie ausser # -> Neustart -> dein System updaten http://v5.windowsupdate.microsoft.co...r/default.aspx -> IE sicherer konfigurieren und nur noch für das Windows Update benutzen http://www.datenschutzzentrum.de/sel...sie/config.htm oder http://www.blafusel.de/ie.html -> Sichere und komfortablere Browser wie z.B. Mozilla oder Firefox verwenden http://www.mozilla.org -> neues Log-File von HijackThis und die Virus Log Information von eScan posten -> Systemwiederherstellung aktivieren # not-a-virus:Tool.Win32.Reboot und not-a-virus:Tool.Win32.HTPatch.a |
09.12.2004, 00:36 | #9 |
| Bitte um Überprüfung des Logfile vom HijackThis erstmal vielen dank für deine Hilfe, wie kann ich diese Datei löschen? der Zugriff ist gesperrt! C:\System Volume Information\_restore{7DCDA70F-8ADA-4E32-865D-08FDE263104C}\RP244\A0241511.exe |
09.12.2004, 00:39 | #10 |
Administrator, a.D. | Bitte um Überprüfung des Logfile vom HijackThis |
09.12.2004, 00:42 | #11 |
| Bitte um Überprüfung des Logfile vom HijackThis Super. nochmal vielen dank, muss nun aber mal pennen gehn, werd mich morgen dran machen die Schritte durchzuführen. Danke |
09.12.2004, 21:21 | #12 |
| Bitte um Überprüfung des Logfile vom HijackThis So.... hoffe ich hab alles richtig ausgeführt. Hier meine neuen Logfiles von HijackThis und escan. Wäre nett wenn ihr noch mal drüber schauen könntet. Logfile of HijackThis v1.98.2 Scan saved at 19:19:30, on 09.12.2004 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\AntiVirenKit 2004\AVKService.exe C:\Programme\AntiVirenKit 2004\AVKWCtl.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\LTSMMSG.exe C:\WINDOWS\htpatch.exe C:\WINDOWS\System32\ezSP_Px.exe C:\Programme\Roxio\WinOnCD\DirectCD\DirectCD.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE C:\WINDOWS\System32\P2P Networking\P2P Networking.exe C:\Tools\WinRar\WinRAR.exe C:\DOKUME~1\Andreas\LOKALE~1\Temp\Rar$EX00.735\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINDOWS\system32/left.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmx.de/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.gmx.de/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = 192.168.123.254 R3 - Default URLSearchHook is missing O1 - Hosts: 69.20.16.183 auto.search.msn.com O1 - Hosts: 69.20.16.183 search.netscape.com O1 - Hosts: 69.20.16.183 ieautosearch O4 - HKLM\..\Run: [LTSMMSG] LTSMMSG.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe O4 - HKLM\..\Run: [AdaptecDirectCD] "C:\Programme\Roxio\WinOnCD\DirectCD\DirectCD.exe" O4 - HKLM\..\Run: [EPSON Stylus Photo R300 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0F2.EXE /P30 "EPSON Stylus Photo R300 Series" /O6 "USB001" /M "Stylus Photo R300" O4 - HKLM\..\Run: [P2P Networking] C:\WINDOWS\System32\P2P Networking\P2P Networking.exe /AUTOSTART O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O15 - Trusted Zone: *.sony-europe.com O15 - Trusted Zone: *.sonystyle-europe.com O15 - Trusted Zone: *.vaio-link.com O16 - DPF: {14325268-79E0-4D2A-89A4-FFFC6E22741E} - http://akamai.downloadv3.com/binarie...ce_3_EN_XP.cab O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} (Web P2P Installer) - O17 - HKLM\System\CCS\Services\Tcpip\..\{D2A12191-BBB1-450F-B9BF-7E5BDB10B8DD}: NameServer = 192.168.123.254,212.185.252.73 escan: Thu Dec 09 18:52:35 2004 => File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Thu Dec 09 18:52:48 2004 => File C:\WINDOWS\ml-uninstall-v10.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Thu Dec 09 18:52:51 2004 => File C:\WINDOWS\_MSRSTRT.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Thu Dec 09 18:56:36 2004 => File C:\Drivers\SiSChipsetDriver\AGP\htpatch\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. Thu Dec 09 20:56:37 2004 => File D:\Festplatte_Downloads\Patches\Skout\skout101.zip tagged as not-a-virus:Cracker.AssasinPatch. No Action Taken. Thu Dec 09 18:54:40 2004 => File C:\DOKUME~1\Andreas\LOKALE~1\Temp\temp.fr0D62 infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken. Thu Dec 09 19:51:28 2004 => File C:\RECYCLER\S-1-5-21-2919174591-3357591376-1883412291-1005\Dc40.exe infected by "not-a-virus:AdWare.ToolBar.Perez.a" Virus. Action Taken: No Action Taken. Thu Dec 09 20:45:57 2004 => File C:\WINDOWS\Temp\nsdtmp09.dll infected by "not-a-virus:AdWare.MetaDirect.a" Virus. Action Taken: No Action Taken. Thu Dec 09 21:03:42 2004 => ***** Scanning complete. ***** Thu Dec 09 21:03:42 2004 => Total Files Scanned: 102698 Thu Dec 09 21:03:42 2004 => Total Virus(es) Found: 11 Thu Dec 09 21:03:42 2004 => Total Disinfected Files: 0 Thu Dec 09 21:03:42 2004 => Total Files Renamed: 0 Thu Dec 09 21:03:42 2004 => Total Deleted Files: 0 Thu Dec 09 21:03:42 2004 => Total Errors: 45 Thu Dec 09 21:03:42 2004 => Time Elapsed: 01:39:42 Thu Dec 09 21:03:42 2004 => Virus Database Date: 2004/12/08 Thu Dec 09 21:03:42 2004 => Virus Database Count: 111920 Thu Dec 09 21:03:42 2004 => Scan Completed. |
Themen zu Bitte um Überprüfung des Logfile vom HijackThis |
bho, button, dll, drivers, explorer, folge, hijack, hijackthis, internet, internet explorer, logfile, messenger, microsoft, nvcpl.dll, object, p2p, programme, rundll, software, start, system, system32, tcpip, temp, trojaner, urlsearchhook, usb, vielen dank, windows, windows messenger, windows xp |