![]() |
|
Log-Analyse und Auswertung: Virencheck nach VirenbefallWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Virencheck nach Virenbefall Hallo liebes Trojaner- Board Team, erstmal tut mir leid wegen dem Titel, aber mir ist leider nichts besseres eingefallen... Jetzt worum es geht: Meine Freundinn hatte mir ihren Laptop gebracht, weil er mit dem Bundeskriminalamt-virus befallen war. ("Dieser Computer wurde gesperrt, weil Kinderpornografischen Material heruntergeladen wurde. Senden sie 100€ an blablabla" so oder so ähnlich hoffe ihr wisst welchen ich meine.) Ich dachte erst nicht, dass es so schlimm ist, weil ich den Virus via msconfig deaktivieren konnte(Dateiname:"ch8l0.exe"). Jetzt zum Fehler meinerseits: Ich habe einen Virenscanner nach dem anderen Installiert und wieder deinstalliert (Spybot, AVG, Norton, Avira, Spyware Terminator). Nachdem er die Viren/Trojaner gefunden hatte. Waren mit Sicherheit 5-10 Trojaner und eben der eine Virus. Den Virus hatte dann AVG gefunden. Ich glaube ich habe jetzt alle. Glauben ist nicht wissen, deshalb bin ich hier ![]() ![]() ![]() DDS.txt: Code:
ATTFilter . DDS (Ver_2011-08-26.01) - NTFSx86 Internet Explorer: 9.0.8112.16421 Run by ***** at 20:27:42 on 2012-04-07 Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.49.1031.18.1919.1283 [GMT 2:00] . SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46} . ============== Running Processes =============== . C:\Windows\system32\wininit.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe -k DcomLaunch C:\Windows\system32\nvvsvc.exe C:\Windows\system32\svchost.exe -k rpcss C:\Windows\System32\svchost.exe -k secsvcs C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted C:\Windows\system32\svchost.exe -k netsvcs C:\Windows\system32\svchost.exe -k GPSvcGroup C:\Windows\system32\SLsvc.exe C:\Windows\system32\svchost.exe -k LocalService C:\Windows\system32\rundll32.exe C:\Windows\system32\svchost.exe -k NetworkService C:\Program Files\ATK Hotkey\ASLDRSrv.exe C:\Program Files\ATKGFNEX\GFNEXSrv.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Windows\System32\spoolsv.exe C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork C:\Windows\system32\taskeng.exe C:\Program Files\ATK Hotkey\Hcontrol.exe C:\Program Files\ATKOSD2\ATKOSD2.exe C:\Program Files\Wireless Console 2\wcourier.exe C:\Program Files\P4G\BatteryLife.exe C:\Windows\system32\taskeng.exe C:\Program Files\Windows Defender\MSASCui.exe C:\Windows\System32\ASUSTPE.exe C:\Windows\system32\svchost.exe -k bthsvcs C:\Program Files\Canon\IJPLM\IJPLMSVC.EXE C:\Program Files\ATK Hotkey\ATKOSD.exe C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted C:\Windows\system32\svchost.exe -k imgsvc C:\Windows\System32\svchost.exe -k WerSvcGroup C:\Windows\system32\SearchIndexer.exe C:\Program Files\ATK Hotkey\KBFiltr.exe C:\Windows\system32\WUDFHost.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\WindowsMobile\wmdSync.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\ehome\ehtray.exe C:\Windows\system32\svchost.exe -k WindowsMobile C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Windows\System32\mobsync.exe C:\Windows\system32\conime.exe C:\Windows\system32\SearchProtocolHost.exe C:\Windows\system32\SearchFilterHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\DllHost.exe C:\Windows\system32\wbem\wmiprvse.exe . ============== Pseudo HJT Report =============== . uSearch Page = hxxp://www.google.com uStart Page = hxxp://www.google.de/ uSearch Bar = hxxp://www.google.com/ie mDefault_Page_URL = hxxp://www.asus.com uURLSearchHooks: H - No File BHO: Adobe PDF Reader: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\program files\common files\adobe\acrobat\activex\AcroIEHelper.dll BHO: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - No File BHO: Office Document Cache Handler: {b4f3a835-0e21-4959-ba22-42b3008e02ff} - c:\progra~1\micros~2\office14\URLREDIR.DLL BHO: Java(tm) Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - c:\program files\java\jre6\bin\jp2ssv.dll TB: {2318C2B1-4965-11D4-9B18-009027A5CD4F} - No File uRun: [Sidebar] c:\program files\windows sidebar\sidebar.exe /autoRun uRun: [ehTray.exe] c:\windows\ehome\ehTray.exe mRun: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide mRun: [ASUSTPE] c:\windows\system32\ASUSTPE.exe mRun: [SynTPEnh] c:\program files\synaptics\syntp\SynTPEnh.exe mRun: [Windows Mobile-based device management] %windir%\WindowsMobile\wmdSync.exe mRun: [NvCplDaemon] RUNDLL32.EXE c:\windows\system32\NvCpl.dll,NvStartup mRun: [Adobe Reader Speed Launcher] "c:\program files\adobe\reader 8.0\reader\Reader_sl.exe" mRun: [Adobe ARM] "c:\program files\common files\adobe\arm\1.0\AdobeARM.exe" mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0) mPolicies-system: EnableUIADesktopToggle = 0 (0x0) IE: An OneNote s&enden - c:\progra~1\micros~2\office14\ONBttnIE.dll/105 IE: E&xport to Microsoft Excel - c:\progra~1\micros~2\office12\EXCEL.EXE/3000 IE: Nach Microsoft &Excel exportieren - c:\progra~1\micros~2\office10\EXCEL.EXE/3000 IE: Nach Microsoft E&xcel exportieren - c:\progra~1\micros~2\office14\EXCEL.EXE/3000 IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - c:\program files\microsoft office\office14\ONBttnIE.dll IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - c:\program files\microsoft office\office14\ONBttnIELinkedNotes.dll TCP: DhcpNameServer = 192.168.2.1 TCP: Interfaces\{0929A8F0-E873-4A54-BC86-664E29B50CCE} : DhcpNameServer = 192.168.2.1 TCP: Interfaces\{3D359373-3EF0-4168-B286-158FF24806A7} : DhcpNameServer = 192.168.2.1 Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - c:\program files\common files\microsoft shared\office14\MSOXMLMF.DLL . ================= FIREFOX =================== . FF - ProfilePath - c:\users\****\appdata\roaming\mozilla\firefox\profiles\9x5xnoar.default\ FF - prefs.js: browser.search.selectedEngine - Google FF - prefs.js: browser.startup.homepage - hxxp://www.t-online.de/# FF - prefs.js: network.proxy.type - 0 FF - plugin: c:\progra~1\micros~2\office14\NPAUTHZ.DLL FF - plugin: c:\progra~1\micros~2\office14\NPSPWRAP.DLL FF - plugin: c:\program files\google\google earth\plugin\npgeplugin.dll FF - plugin: c:\program files\google\update\1.3.21.111\npGoogleUpdate3.dll FF - plugin: c:\program files\java\jre6\bin\new_plugin\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npdeployJava1.dll FF - plugin: c:\program files\mozilla firefox\plugins\npirsviewer.dll FF - plugin: c:\windows\system32\macromed\flash\NPSWF32_11_2_202_228.dll . ---- FIREFOX POLICIES ---- FF - user.js: yahoo.homepage.dontask - true ============= SERVICES / DRIVERS =============== . R2 ACEDRV06;ACEDRV06;c:\windows\system32\drivers\ACEDRV06.sys [2010-7-8 99840] R2 acedrv09;acedrv09;c:\windows\system32\drivers\acedrv09.sys [2007-6-18 373568] R2 acehlp09;acehlp09;c:\windows\system32\drivers\acehlp09.sys [2007-5-30 201696] R2 FontCache;Windows-Dienst für Schriftartencache;c:\windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-6-26 21504] R2 PLCNDIS5;PLCNDIS5 NDIS Protocol Driver;c:\windows\system32\plcndis5.sys [2004-5-17 17280] R3 seehcri;Sony Ericsson seehcri Device Driver;c:\windows\system32\drivers\seehcri.sys [2010-1-17 27632] S2 gupdate;Google Update Service (gupdate);c:\program files\google\update\GoogleUpdate.exe [2010-2-8 135664] S3 A_USBETHMP;USB PowerPacket Network Adapter;c:\windows\system32\drivers\usbethmp.sys [2010-5-31 14342] S3 AdobeFlashPlayerUpdateSvc;Adobe Flash Player Update Service;c:\windows\system32\macromed\flash\FlashPlayerUpdateService.exe [2012-4-4 253600] S3 B-Service;B-Service;c:\users\bauer\downloads\B-Service.exe [2011-5-20 185640] S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;c:\magix\common\database\bin\fbserver.exe [2010-7-8 1527900] S3 gupdatem;Google Update-Dienst (gupdatem);c:\program files\google\update\GoogleUpdate.exe [2010-2-8 135664] S3 osppsvc;Office Software Protection Platform;c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\OSPPSVC.EXE [2010-1-9 4640000] S3 s0016bus;Sony Ericsson Device 0016 driver (WDM);c:\windows\system32\drivers\s0016bus.sys [2009-8-8 89256] S3 s0016mdfl;Sony Ericsson Device 0016 USB WMC Modem Filter;c:\windows\system32\drivers\s0016mdfl.sys [2009-8-8 15016] S3 s0016mdm;Sony Ericsson Device 0016 USB WMC Modem Driver;c:\windows\system32\drivers\s0016mdm.sys [2009-8-8 120744] S3 s0016mgmt;Sony Ericsson Device 0016 USB WMC Device Management Drivers (WDM);c:\windows\system32\drivers\s0016mgmt.sys [2009-8-8 114216] S3 s0016nd5;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (NDIS);c:\windows\system32\drivers\s0016nd5.sys [2009-8-8 25512] S3 s0016obex;Sony Ericsson Device 0016 USB WMC OBEX Interface;c:\windows\system32\drivers\s0016obex.sys [2009-8-8 110632] S3 s0016unic;Sony Ericsson Device 0016 USB Ethernet Emulation SEMC0016 (WDM);c:\windows\system32\drivers\s0016unic.sys [2009-8-8 115752] S3 s0017bus;Sony Ericsson Device 0017 driver (WDM);c:\windows\system32\drivers\s0017bus.sys [2009-8-8 90536] . =============== Created Last 30 ================ . 2012-04-07 12:52:58 -------- d-----w- c:\users\*****\appdata\roaming\Malwarebytes 2012-04-07 12:52:49 -------- d-----w- c:\programdata\Malwarebytes 2012-04-07 09:37:49 -------- d-----w- c:\programdata\Norton 2012-04-07 09:37:30 -------- d-----w- c:\programdata\NortonInstaller 2012-04-06 21:42:30 -------- d-----w- c:\users\bauer\appdata\roaming\AVG2012 2012-04-06 21:40:40 -------- d--h--w- c:\programdata\Common Files 2012-04-06 21:37:42 -------- d-----w- c:\programdata\AVG2012 2012-04-06 21:35:29 -------- d-----w- c:\program files\AVG 2012-04-06 21:31:14 -------- d-----w- c:\programdata\MFAData 2012-04-06 20:10:00 -------- d-----w- c:\programdata\Spybot - Search & Destroy 2012-04-06 20:10:00 -------- d-----w- c:\program files\Spybot - Search & Destroy 2012-04-06 16:45:50 32768 ----a-w- c:\windows\system32\drivers\sp_rsdrv2.sys 2012-04-06 16:12:53 14664 ----a-w- c:\windows\stinger.sys 2012-04-06 16:11:13 -------- d-----w- c:\program files\stinger 2012-04-05 15:36:32 -------- d-----w- c:\windows\pss 2012-04-04 08:06:03 418464 ----a-w- c:\windows\system32\FlashPlayerApp.exe 2012-03-16 18:30:14 19384 ----a-w- c:\program files\mozilla firefox\AccessibleMarshal.dll 2012-03-16 18:30:13 97208 ----a-w- c:\program files\mozilla firefox\components\browsercomps.dll 2012-03-16 18:30:13 2106216 ----a-w- c:\program files\mozilla firefox\D3DCompiler_43.dll 2012-03-16 18:30:13 1998168 ----a-w- c:\program files\mozilla firefox\d3dx9_43.dll 2012-03-16 18:30:13 125880 ----a-w- c:\program files\mozilla firefox\crashreporter.exe 2012-03-16 18:30:12 924600 ----a-w- c:\program files\mozilla firefox\firefox.exe 2012-03-16 18:30:12 592824 ----a-w- c:\program files\mozilla firefox\gkmedias.dll 2012-03-16 18:30:12 44472 ----a-w- c:\program files\mozilla firefox\mozglue.dll 2012-03-16 18:30:12 269240 ----a-w- c:\program files\mozilla firefox\freebl3.dll . ==================== Find3M ==================== . 2012-04-04 08:06:02 70304 ----a-w- c:\windows\system32\FlashPlayerCPLApp.cpl . ============= FINISH: 20:28:55,15 =============== Code:
ATTFilter NLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG. IF REQUESTED, ZIP IT UP & ATTACH IT . DDS (Ver_2011-08-26.01) . Microsoft® Windows Vista™ Home Premium Boot Device: \Device\HarddiskVolume2 Install Date: 13.09.2007 06:41:15 System Uptime: 07.04.2012 20:04:05 (0 hours ago) . Motherboard: ASUSTeK Computer Inc. | | F5N Processor: AMD Athlon(tm) 64 X2 Dual-Core Processor TK-53 | CPU 1 | 800/200mhz . ==== Disk Partitions ========================= . C: is FIXED (NTFS) - 56 GiB total, 10,197 GiB free. D: is FIXED (NTFS) - 49 GiB total, 26,211 GiB free. E: is CDROM () F: is Removable . ==== Disabled Device Manager Items ============= . ==== System Restore Points =================== . . ==== Installed Programs ====================== . Activation Assistant for the 2007 Microsoft Office suites Adobe Flash Player 11 Plugin Adobe Flash Player ActiveX Adobe Reader 8.3.1 - Deutsch ASUS Touch Pad Extra Asus_Camera_ScreenSaver Atheros Driver Installation Program ATK Generic Function Service ATK Hotkey ATK Media ATKOSD2 Canon MP520 series D-Route 2008/2009 Definition update for Microsoft Office 2010 (KB982726) devolo dLAN-Konfigurationsassistent devolo EasyClean devolo EasyShare devolo Informer Firebird SQL Server - MAGIX Edition (D) Google Earth Google Update Helper Hotfix for Microsoft .NET Framework 3.5 SP1 (KB953595) Hotfix for Microsoft .NET Framework 3.5 SP1 (KB958484) Java Auto Updater LightScribe 1.4.142.1 MAGIX Foto Clinic 5.0 (D) MAGIX Foto Manager 2006 (D) MAGIX Music Manager 2006 (D) MAGIX Online Druck Service (D) MAGIX Video deluxe 2006 2007 PLUS (D) Microsoft .NET Framework 3.5 SP1 Microsoft Office Access MUI (German) 2010 Microsoft Office Excel MUI (German) 2010 Microsoft Office Home and Student 2010 Microsoft Office OneNote MUI (German) 2010 Microsoft Office Outlook MUI (German) 2010 Microsoft Office PowerPoint MUI (German) 2010 Microsoft Office Proof (English) 2010 Microsoft Office Proof (French) 2010 Microsoft Office Proof (German) 2010 Microsoft Office Proof (Italian) 2010 Microsoft Office Proofing (German) 2010 Microsoft Office Publisher MUI (German) 2010 Microsoft Office Shared MUI (German) 2010 Microsoft Office Single Image 2010 Microsoft Office Word MUI (German) 2010 Microsoft Outlook Social Connector (KB2289116) ªº§ó·s Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 Microsoft Visual C++ 2005 Redistributable Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148 Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219 Microsoft XML Parser Mozilla Firefox 11.0 (x86 de) MSXML 4.0 SP2 (KB927978) MSXML 4.0 SP2 (KB936181) MSXML 4.0 SP2 (KB954430) MSXML 4.0 SP2 (KB973688) Nero 7 Essentials NVIDIA Drivers NVIDIA PhysX PIXMA Extended Survey Program Power4Gear eXtreme ProtectDisc Helper Driver Realtek USB 2.0 Card Reader Security Update for CAPICOM (KB931906) Security Update for Microsoft .NET Framework 3.5 SP1 (KB2416473) Security Update for Microsoft Office 2010 (KB2289078) Security Update for Microsoft Office 2010 (KB2289161) Security Update for Microsoft Publisher 2010 (KB2409055) Security Update for Microsoft Word 2010 (KB2345000) Siggi Blitz Vorschule 1 Siggi Blitz Vorschule 2 Synaptics Pointing Device Driver TAPPS 1.20 DE Update für Microsoft Outlook Social Connector (KB2289116) Update for Microsoft .NET Framework 3.5 SP1 (KB963707) Update for Microsoft Office 2010 (KB2202188) Update for Microsoft Office 2010 (KB2413186) Update for Microsoft OneNote 2010 (KB2433299) WinFlash Wireless Console 2 . ==== End Of File =========================== Code:
ATTFilter GMER 1.0.15.15641 - hxxp://www.gmer.net Rootkit scan 2012-04-07 22:56:30 Windows 6.0.6002 Service Pack 2 Harddisk0\DR0 -> \Device\Ide\IdeDeviceP2T0L0-3 FUJITSU_MHW2120BH rev.00000012 Running: her7ci38.exe; Driver: C:\Users\****\AppData\Local\Temp\uwldqpow.sys ---- Kernel code sections - GMER 1.0.15 ---- .reloc C:\Windows\system32\drivers\acehlp09.sys section is executable [0x8777D780, 0x28F7A, 0xE0000060] .text C:\Windows\system32\DRIVERS\nvlddmkm.sys section is writeable [0x8BE0A340, 0x3EE1D7, 0xE8000020] .text C:\Windows\system32\drivers\ACEDRV06.sys section is writeable [0x8CD80000, 0x319AA, 0xE8000020] .pklstb C:\Windows\system32\drivers\ACEDRV06.sys entry point in ".pklstb" section [0x8CDC3000] .relo2 C:\Windows\system32\drivers\ACEDRV06.sys unknown last section [0x8CDDE000, 0x8E, 0x42000040] .reloc C:\Windows\system32\drivers\acedrv09.sys section is executable [0x9BEE1000, 0x4E05A, 0xE0000060] ? C:\Users\Bauer\AppData\Local\Temp\mbr.sys Das System kann die angegebene Datei nicht finden. ! ---- Devices - GMER 1.0.15 ---- Device Ntfs.sys (NT-Dateisystemtreiber/Microsoft Corporation) Device fastfat.SYS (Fast FAT File System Driver/Microsoft Corporation) Device InCDFs.sys (InCD File System Driver/Nero AG) AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 Wdf01000.sys (WDF Dynamic/Microsoft Corporation) AttachedDevice fltmgr.sys (Microsoft Dateisystem-Filter-Manager/Microsoft Corporation) ---- Registry - GMER 1.0.15 ---- Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\0018f337f16b Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001986001fd2 Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001986001fd2@001ee2469711 0x38 0xD0 0xB3 0x9C ... Reg HKLM\SYSTEM\CurrentControlSet\Services\BTHPORT\Parameters\Keys\001986001fd2@0024ef7f4734 0xDA 0x33 0xCB 0x6B ... Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\0018f337f16b (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001986001fd2 (not active ControlSet) Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001986001fd2@001ee2469711 0x38 0xD0 0xB3 0x9C ... Reg HKLM\SYSTEM\ControlSet002\Services\BTHPORT\Parameters\Keys\001986001fd2@0024ef7f4734 0xDA 0x33 0xCB 0x6B ... ---- EOF - GMER 1.0.15 ---- |
Themen zu Virencheck nach Virenbefall |
avg, avira, canon, computer, cpu, defender, device driver, document, excel, fehler, firefox, flash player, fontcache, google earth, home, installation, internet, microsoft security, microsoft security essentials, mozilla, plug-in, registry, rojaner gefunden, rundll, scan, security, senden, sicherheit, software, spyware, svchost.exe, system, usb 2.0, virenbefal, windows |