|
Log-Analyse und Auswertung: HiJackThis Log auswertungWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
19.02.2005, 13:52 | #1 |
| HiJackThis Log auswertung Hallo an alle, aaa~lso, wenn ich jetzt was falsches gemacht hab tut's mir wirklich leid, aber ich glaub wenn ich hier jetzt meinen hijackthis.log reinposte ist das in Ordnung! Ich hab dieses Problem mit dem Code des agent.ay und es geht mir ganz furchtbar auf die nerven! Dazu muss ich aber sagen, dass ich überhaupt keine Ahnung von PCs habe, zumindest auf gar keinen Fall so wie die meisten von euch hier! Also, hier der log: Logfile of HijackThis v1.99.1 Scan saved at 03:21:38, on 18.02.2005 Platform: Windows ME (Win9x 4.90.3000) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\SYSTEM\STIMON.EXE C:\WINDOWS\TASKMON.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE C:\WINDOWS\LOADQM.EXE C:\PROGRAMME\WINAMP\WINAMPA.EXE C:\PROGRAMME\ICQLITE\ICQLITE.EXE C:\PROGRAMME\AVPERSONAL\AVGCTRL.EXE C:\PROGRAMME\GEMEINSAME DATEIEN\REAL\UPDATE_OB\REALSCHED.EXE C:\PROGRAMME\GEMEINSAME DATEIEN\CMEII\CMESYS.EXE C:\PROGRAMME\MSN MESSENGER\MSNMSGR.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\WINDOWS\TWAIN_32\SCSI600\WATCH.EXE C:\PROGRAMME\FRITZ!\IWATCH.EXE C:\PROGRAMME\GEMEINSAME DATEIEN\GMT\GMT.EXE C:\PROGRAMME\MICROSOFT OFFICE\OFFICE\FINDFAST.EXE C:\MSCAN\MSOFFICE\PANEL.EXE C:\PROGRAMME\PRECISIONTIME\PRECISIONTIME.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\PROGRAMME\MOZILLA FIREFOX\FIREFOX.EXE C:\WINDOWS\EXPLORER.EXE C:\EIGENE DATEIEN\ACROSPIDEREXPLOFRITZ\HIJACKTHIS.EXE R1 - HKCU\Software\Microsoft\Internet Explorer,Search = http://in.webcounter.cc/--/?ydtfs (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://in.webcounter.cc/--/?ydtfs (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer,Search = http://in.webcounter.cc/--/?ydtfs (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://in.webcounter.cc/-/?ydtfs (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://in.webcounter.cc/--/?ydtfs (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://results.dashbar.com/search?c=...U3&ver=2.1.0.0 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://in.webcounter.cc/--/?ydtfs (obfuscated) R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://qing.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.internetcologne.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://in.webcounter.cc/--/?ydtfs (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://in.webcounter.cc/--/?ydtfs (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://in.webcounter.cc/-/?ydtfs about:blank (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://in.webcounter.cc/---/?ydtfs (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://in.webcounter.cc/--/?ydtfs (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://in.webcounter.cc/---/?ydtfs (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://in.webcounter.cc/--/?ydtfs (obfuscated) R3 - URLSearchHook: IncrediFindBHO Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing) O2 - BHO: F1 Organizer Class - {00000EF1-0786-4633-87C6-1AA7A44296DA} - C:\WINDOWS\SYSTEM\ATPART~1.DLL (file missing) O2 - BHO: NavErrRedir Class - {5D60FF48-95BE-4956-B4C6-6BB168A70310} - C:\PROGRA~1\INCRED~1\BHO\INCFIN~1.DLL (file missing) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMME\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O3 - Toolbar: DashBar Toolbar - {CC90CDA0-74A0-45b4-80EF-D89CA8C249B8} - C:\PROGRAMME\DASHBAR\DASHBAR21.DLL O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe O4 - HKLM\..\Run: [PCHealth] C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\Run: [Soundmx] C:\WINDOWS\SYSTEM\soundmx.exe O4 - HKLM\..\Run: [LoadQM] loadqm.exe O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize O4 - HKLM\..\Run: [AVGCtrl] C:\PROGRAMME\AVPERSONAL\AVGCTRL.EXE /min O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [CMESys] "C:\PROGRAMME\GEMEINSAME DATEIEN\CMEII\CMESYS.EXE" O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKLM\..\RunServices: [*StateMgr] C:\WINDOWS\System\Restore\StateMgr.exe O4 - HKLM\..\RunServices: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE O4 - HKCU\..\Run: [msnmsgr] "C:\PROGRAMME\MSN MESSENGER\MSNMSGR.EXE" /background O4 - Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE O4 - Startup: Zahlungserinnerung.lnk = C:\PROFI\wzed.exe O4 - Startup: Watch.lnk = C:\WINDOWS\TWAIN_32\SCSI600\WATCH.EXE O4 - Startup: ISDNWatch.lnk = C:\Programme\FRITZ!\IWatch.exe O4 - Startup: GStartup.lnk = C:\Programme\Gemeinsame Dateien\GMT\GMT.exe O4 - Startup: PrecisionTime.lnk = C:\Programme\PrecisionTime\PrecisionTime.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O12 - Plugin for .spop: C:\PROGRA~1\INTERN~1\Plugins\NPDocBox.dll O16 - DPF: {00000000-CDDC-0704-0B53-2C8830E9FAEC} (IELoaderCtl Class) - http://install.global-netcom.de/ieloader.cab O16 - DPF: {67B15B0B-160C-4579-95AF-858169659092} (IELoaderCtl Class) - http://freeload.cc/secure/ieloader.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...tatsClient.cab O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary...reShowdown.cab O16 - DPF: {E3489C0D-D07D-4281-A4A7-ADA8E9A0893F} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.co...haringctrl.cab O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.imgfarm.com/images/nocache...tup1.0.0.8.cab O16 - DPF: {E0B795B4-FD95-4ABD-A375-27962EFCE8CF} (StarInstall Control) - http://install.stardialer.de/StarInstall.ocx O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} (F1 Organizer Class) - http://www.addictivetechnologies.net...ab/3ojsslg.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/15f41309...dxIE601_de.cab O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary...o.cab32846.cab O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab O16 - DPF: {E6187999-9FEC-46A1-A20F-F4CA977D5643} (ZoneChess Object) - http://messenger.zone.msn.com/binary/Chess.cab31267.cab O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab O16 - DPF: {BD393C14-72AD-4790-A095-76522973D6B8} (CBreakshotControl Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab O17 - HKLM\System\CCS\Services\VxD\MSTCP: NameServer = 192.168.0.1 Ich bin echt sprachlos wenn ihr damit was anfangen könnt! Ich danke schon mal im Vorraus, auch wenn ihr mir nicht weiterhelfen könnt, das bezweifel ich aber ^_~ Hoffe ich hab soweit alles richtig gemacht.. ôO thx
__________________ Nicht die Schönheit entscheidet wen wir lieben, sondern die Liebe entscheidet wen wir schön finden! |
19.02.2005, 14:38 | #2 |
| HiJackThis Log auswertung Hallo,
__________________mach bitte einen escan im abgesicherten Modus genau nach Anleitung: http://www.trojaner-board.de/42731-escan-anleitung.html um zu sehen ob sich es überhaupt noch lohnt dein System zu retten! Gruss |
24.02.2005, 19:28 | #3 |
| HiJackThis Log auswertung Okay, hab das mit dem escan gemacht, war einiges was da kam, tut mir leid, dass ich erst so spät poste, habe momentan nicht so viel Zeit! Hoffe ihr könnt mir nun helfen, danke im Vorraus!
__________________File C:\WINDOWS\hh.htt infected by "Trojan.JS.Zapchast.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\HENTOON_DE[hae-10864,de,].exe infected by "not-a-virus:PornWare.Dialer.Intexdial" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\ATPARTNERS.DLL.VIR infected by "not-a-virus:AdWare.F1Organizer.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\~alstmp.exe_ infected by "not-a-virus:Porn-Dialer.Win32.ALifeDialer" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\GL_B0F0.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\TEMP\GL_E252.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\TEMP\~vis0001\rebootnt.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\TEMP\asmfiles.cab infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\__unin__.exe infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\cd_clint.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMPOR~1\CONTENT.IE5\OHEJ052N\WebCounter[1].jar infected by "Trojan.Java.ClassLoader.Dummy.e" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMPOR~1\CONTENT.IE5\6YHNAGQR\arch22776[1].jar infected by "Trojan.Java.ClassLoader.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMPOR~1\CONTENT.IE5\M7MVADU3\DummyMod[1].class infected by "Trojan.Win32.StartPage.y" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMPOR~1\CONTENT.IE5\RRXJ7X8W\ieloader[1].cab infected by "Trojan-Downloader.Win32.Ladder.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMPOR~1\CONTENT.IE5\RRXJ7X8W\info[1].php infected by "Trojan-Clicker.JS.Linker.c" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\A0105637.CPY infected by "not-a-virus:PornWare.Dialer.Intexdial" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\A0052960.CPY infected by "Trojan.Win32.StartPage.y" Virus. Action Taken: No Action Taken. File C:\_RESTORE\ARCHIVE\FS150.CAB infected by "not-a-virus:AdWare.ToolBar.DashBar" Virus. Action Taken: No Action Taken. File C:\_RESTORE\ARCHIVE\FS149.CAB infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken. File C:\_RESTORE\ARCHIVE\FS148.CAB infected by "not-a-virus:AdWare.Gator.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\ATPARTNERS.DLL.VIR infected by "not-a-virus:AdWare.F1Organizer.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\WEB\tips.ini infected by "Trojan.JS.Zapchast.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\~alstmp.exe_ infected by "not-a-virus:Porn-Dialer.Win32.ALifeDialer" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\GL_B0F0.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\TEMP\GL_E252.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\TEMP\~vis0001\rebootnt.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File C:\WINDOWS\TEMP\asmfiles.cab infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\__unin__.exe infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\cd_clint.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temporary Internet Files\Content.IE5\OHEJ052N\WebCounter[1].jar infected by "Trojan.Java.ClassLoader.Dummy.e" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temporary Internet Files\Content.IE5\6YHNAGQR\arch22776[1].jar infected by "Trojan.Java.ClassLoader.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temporary Internet Files\Content.IE5\M7MVADU3\DummyMod[1].class infected by "Trojan.Win32.StartPage.y" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temporary Internet Files\Content.IE5\RRXJ7X8W\ieloader[1].cab infected by "Trojan-Downloader.Win32.Ladder.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temporary Internet Files\Content.IE5\RRXJ7X8W\info[1].php infected by "Trojan-Clicker.JS.Linker.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temporary Internet Files\Q3567836.exe infected by "Trojan-Downloader.Win32.Small.dq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\hh.htt infected by "Trojan.JS.Zapchast.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\HENTOON_DE[hae-10864,de,].exe infected by "not-a-virus:PornWare.Dialer.Intexdial" Virus. Action Taken: No Action Taken. File C:\Programme\AVPersonal\INFECTED\fntldr.VIR infected by "Trojan.Win32.StartPage.y" Virus. Action Taken: No Action Taken. File C:\Programme\AVPersonal\INFECTED\FD12B98C.394 infected by "Trojan-Downloader.Win32.Keenval.e" Virus. Action Taken: No Action Taken. File C:\Programme\AVPersonal\INFECTED\69589D42.14D infected by "Trojan-Downloader.Win32.Ladder.a" Virus. Action Taken: No Action Taken. File C:\Programme\AVPersonal\INFECTED\335154E4.303 infected by "Trojan-Downloader.Win32.Ladder.a" Virus. Action Taken: No Action Taken. File C:\Programme\AVPersonal\INFECTED\40A2264A.11D infected by "not-a-virus:AdWare.Gator.a" Virus. Action Taken: No Action Taken. File C:\Programme\AVPersonal\INFECTED\36049A76.091 infected by "not-a-virus:AdWare.Gator.a" Virus. Action Taken: No Action Taken.
__________________ |
Themen zu HiJackThis Log auswertung |
adobe, auswertung, danke, dateien, explorer, file missing, firefox, fritz!, hijack, hijackthis, hijackthis log, hijackthis log auswertung, internet, internet explorer, keine ahnung, log, messenger, microsoft, mozilla, mozilla firefox, msn, msn messenger, nerven, obfuscated, object, problem, programme, registry, rundll, software, system, update, urlsearchhook, windows |