|
Log-Analyse und Auswertung: Bitte Um HilfeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
08.02.2005, 10:44 | #1 |
| Bitte Um Hilfe Ich kann kaum noch Internetseiten öffnen , oder es wird unterbrochen. Hier mein Hijack: Logfile of HijackThis v1.99.0 Scan saved at 10:35:54, on 08.02.05 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\EXPLORER.EXE C:\PROGRAMME\WINZIP\WINZIP32.EXE C:\WINDOWS\TEMP\HIJACKTHIS.EXE R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer bereitgestellt von T-Online International AG O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O4 - HKLM\..\Run: [T-DSL SpeedMgr] "C:\PROGRAMME\T-DSL SPEEDMANAGER\SPEEDMGR.EXE" O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [AVGCtrl] C:\PROGRAMME\AVPERSONAL\AVGCTRL.EXE /min O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKCU\..\Run: [WashAndGo - Cleanup of old Backupfiles] C:\Programme\Purgatio Pro\checker.exe /check O4 - HKCU\..\RunServices: [WashAndGo - Cleanup of old Backupfiles] C:\Programme\Purgatio Pro\checker.exe /check O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm Hier mein Escan: Tue Feb 08 09:39:09 2005 => File C:\WINDOWS\TEMP\backups\backup-20050201-193104-363.dll infected by "not-a-virus:AdWare.PurityScan.ak" Virus. Action Taken: No Action Taken. Tue Feb 08 09:57:28 2005 => File C:\WINDOWS\TEMP\backups\backup-20050201-193104-363.dll infected by "not-a-virus:AdWare.PurityScan.ak" Virus. Action Taken: No Action Taken. Tue Feb 08 10:03:19 2005 => File C:\WINDOWS\Anwendungsdaten\setm.exe infected by "not-a-virus:AdWare.PurityScan.v" Virus. Action Taken: No Action Take. Tue Feb 08 10:09:46 2005 => C:\RECYCLED\DC24\ABF_LL possibly infected and removed by background antivirus package! Tue Feb 08 10:09:46 2005 => File C:\RECYCLED\DC24\ABF_LL infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken. Tue Feb 08 10:09:46 2005 => C:\RECYCLED\DC24\T_REN possibly infected and removed by background antivirus package! Tue Feb 08 10:09:46 2005 => File C:\RECYCLED\DC24\T_REN infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken. Tue Feb 08 10:09:46 2005 => C:\RECYCLED\DC24\T_RE possibly infected and removed by background antivirus package! Tue Feb 08 10:09:46 2005 => File C:\RECYCLED\DC24\T_RE infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken. Tue Feb 08 10:09:46 2005 => C:\RECYCLED\DC25\N_HM possibly infected and removed by background antivirus package! Tue Feb 08 10:09:46 2005 => File C:\RECYCLED\DC25\N_HM infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken. Tue Feb 08 10:09:46 2005 => C:\RECYCLED\DC22\GL_HB possibly infected and removed by background antivirus package! Tue Feb 08 10:09:46 2005 => File C:\RECYCLED\DC22\GL_HB infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken. Tue Feb 08 10:09:47 2005 => C:\RECYCLED\DC2\K_HLIN possibly infected and removed by background antivirus package! Tue Feb 08 10:09:47 2005 => File C:\RECYCLED\DC2\K_HLIN infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken. Tue Feb 08 10:09:47 2005 => C:\RECYCLED\DC2\ABF_LL possibly infected and removed by background antivirus package! Tue Feb 08 10:09:47 2005 => File C:\RECYCLED\DC2\ABF_LL infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken. Tue Feb 08 10:15:09 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.* Tue Feb 08 10:22:55 2005 => File C:\program files\Windows AdService\WinAdMaster.dll infected by "not-a-virus:AdWare.WinAD.d" Virus. Action Taken: No Action Taken. Tue Feb 08 10:22:55 2005 => Scanning File C:\program files\Windows AdService\WinAdinfected by "not-a-virus:AdWare.WinAD.b" Virus. Action Taken: No Action Taken. Tue Feb 08 10:24:02 2005 => ***** Scanning complete. ***** Tue Feb 08 10:24:02 2005 => Total Files Scanned: 23053 Tue Feb 08 10:24:02 2005 => Total Virus(es) Found: 15 Tue Feb 08 10:24:02 2005 => Total Disinfected Files: 0 Tue Feb 08 10:24:02 2005 => Total Files Renamed: 0 Tue Feb 08 10:24:02 2005 => Total Deleted Files: 0 Tue Feb 08 10:24:03 2005 => Total Errors: 122 Tue Feb 08 10:24:03 2005 => Time Elapsed: 00:46:44 Tue Feb 08 10:24:03 2005 => Virus Database Date: 2005/01/28 Tue Feb 08 10:24:03 2005 => Virus Database Count: 117012 Tue Feb 08 10:24:03 2005 => Scan Completed. Kann mir bitte jemand helfen ? Viel Grüße |
08.02.2005, 21:34 | #2 |
| Bitte Um Hilfe @kaejen...
__________________konfiguriere (....nicht fixen!!!) O4 - HKLM\..\Run: [T-DSL SpeedMgr] "C:\PROGRAMME\T-DSL SPEEDMANAGER\SPEEDMGR.EXE"...also deinen Speed-Manager... oder probiere es mal mit... http://www.zdnet.de/downloads/prg/b/p/de0DBP-wc.html dein log scheint sauber zu sein, vermutlich hast du ein DFÜ-Problem und überprüfe daher mal deine MTU-Werte mit o.a. link und stelle sie nach den dort vorgebenen Werten ein... ps: dein BS ist nicht mehr uptodate...bitte patchen!! lg Tom59
__________________ Geändert von Tom59 (08.02.2005 um 21:36 Uhr) Grund: Zusatz |
Themen zu Bitte Um Hilfe |
antivirus, bho, bitte um hilfe, button, escan, explorer, helfen, hijack, hijackthis, infected, internet explorer, internetseite, links, m.exe, microsoft, not-a-virus, programme, registry, rundll, rundll32.exe, seite, seiten, software, spybot, system, t-online, temp, windows, windows\temp |