|
Plagegeister aller Art und deren Bekämpfung: HILFE Trojaner Dldr.VB.Em.2Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
01.04.2005, 12:58 | #1 |
| HILFE Trojaner Dldr.VB.Em.2 Mein Antivir gibt mir die Nachricht, dass sich folgender Trojaner auf meinem Rechner befindet: Dldr.VB.Em.2 Die Dateien können aber nicht gelöscht werden. Habe Antivir schon mehrmals durchlaufen lassen und er findet den Trojaner immer wieder Kann mir einer sagen wie ich diesen nerfigen Trojaner loswerde und mit welchem Programm das funktioniert? Ich hab nämlich gar keine Ahnung. Thx |
01.04.2005, 13:02 | #2 | |
Administrator, a.D. | HILFE Trojaner Dldr.VB.Em.2 Hallo,
__________________Zitat:
__________________ |
01.04.2005, 13:04 | #3 |
| HILFE Trojaner Dldr.VB.Em.2 c:\WINNT\system32\wnwdwc.exe
__________________die .exe dateien verändern sich immer |
01.04.2005, 13:15 | #4 |
Administrator, a.D. | HILFE Trojaner Dldr.VB.Em.2 Lade und scanne mit eScan AntiVirus im abgesicherten Modus wie beschrieben. Poste anschliessend die Virus Log Information von eScan AntiVirus: Öffne die mwav.log im Ordner C:\bases -> Bearbeiten -> Suchen -> infected oder tagged eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen. |
01.04.2005, 13:34 | #5 |
| HILFE Trojaner Dldr.VB.Em.2 Ich gaube dass ist es was du meinst: File C:\WINNT\Pynix.dll infected by "not-a-virus:AdWare.DlMax.a" Virus. Action Taken: No Action Taken. File C:\WINNT\system32\lmf32v.dll infected by "not-a-virus:AdWare.Suggestor.g" Virus. Action Taken: No Action Taken. File C:\Programme\eSyndicate\esyn.dll infected by "not-a-virus:AdWare.Esyndic.a" Virus. Action Taken: No Action Taken. File C:\WINNT\system32\docprop6.exe infected by "not-a-virus:AdWare.AdSrve.b" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\TVMEDI~1\Tvm.exe infected by "not-a-virus:AdWare.TotalVelocity.al" Virus. Action Taken: No Action Taken. File C:\WINNT\system32\MftR.exe infected by "Trojan-Downloader.Win32.VB.em" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\ezula\mmod.exe infected by "not-a-virus:AdWare.EZula.z" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "Alexa Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "Gator Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "180Solutions Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "VX2 Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eSyndicate Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "Adintelligence.AproposToolbar Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "eZmmod Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "gator.com Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "precisiontime Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "xhrmy Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "text/html Spyware/Adware" Virus. Action Taken: No Action Taken. File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. File C:\WINNT\eZinstall.exe infected by "not-a-virus:AdWare.EZula.ak" Virus. Action Taken: No Action Taken. File C:\WINNT\woinstall.exe infected by "not-a-virus:AdWare.EZula.ak" Virus. Action Taken: No Action Taken. File C:\WINNT\system32\ddrawex6.exe infected by "not-a-virus:AdWare.AdSrve.c" Virus. Action Taken: No Action Taken. File C:\WINNT\system32\DdiZ64.exe infected by "Trojan-Downloader.Win32.VB.em" Virus. Action Taken: No Action Taken. File C:\WINNT\system32\ezstub.exe infected by "not-a-virus:AdWare.EZula.ap" Virus. Action Taken: No Action Taken. File C:\WINNT\system32\HcswrR5U.exe infected by "Trojan-Downloader.Win32.VB.em" Virus. Action Taken: No Action Taken. File C:\WINNT\system32\WxtK7.exe infected by "Trojan-Downloader.Win32.VB.em" Virus. Action Taken: No Action Taken. File C:\WINNT\system32\Scr2WJi.exe infected by "Trojan-Downloader.Win32.VB.em" Virus. Action Taken: No Action Taken. File C:\WINNT\system32\PreUninstall.exe infected by "not-a-virus:AdWare.Suggestor.g" Virus. Action Taken: No Action Taken. |
01.04.2005, 13:41 | #6 |
| HILFE Trojaner Dldr.VB.Em.2 So hab das damit auch noch mal gemacht: Logfile of HijackThis v1.99.1 Scan saved at 14:40:44, on 01.04.2005 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\Ati2evxx.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\Programme\AVPersonal\AVWUPSRV.EXE C:\WINNT\System32\svchost.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\stisvc.exe C:\WINNT\system32\mspmspsv.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\Ati2evxx.exe C:\WINNT\Explorer.EXE C:\WINNT\Mixer.exe C:\Programme\ICQLite\ICQLite.exe C:\WINNT\Twain_32\FlatBed\HotKey.exe C:\Programme\ATI Technologies\ATI.ACE\cli.exe C:\Programme\D-Tools\daemon.exe C:\WINNT\system32\docprop6.exe C:\WINNT\system32\utilass.exe C:\WINNT\system32\internat.exe C:\Dokumente und Einstellungen\Mania1\Anwendungsdaten\q???.exe C:\PROGRA~1\ezula\mmod.exe C:\PROGRA~1\Web Offer\wo.exe C:\WINNT\system32\usbmxs.exe C:\Programme\ATI Technologies\ATI.ACE\CLI.exe C:\Programme\PrecisionTime\PrecisionTime.exe C:\Programme\Gemeinsame Dateien\GMT\GMT.exe C:\Programme\Internet Explorer\IEXPLORE.EXE C:\Programme\CxtPls\CxtPls.exe C:\Programme\Windows NT\Zubehör\WORDPAD.EXE C:\WINNT\system32\WxtK7.exe C:\WINNT\system32\HcswrR5U.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\DOKUME~1\Mania1\LOKALE~1\Temp\Rar$EX00.313\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = file://C:\WINNT\system32\SearchBar.htm R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fussballmanager-online.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = kaas.homeip.net:8080 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {20EC3D2D-33C1-4C9D-BC37-C2D500688DA2} - C:\Programme\TV Media\TvmBho.dll O2 - BHO: PynixObj Class - {00000000-DD60-0064-6EC2-6E0100000000} - C:\WINNT\Pynix.dll O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Programme\CxtPls\cxtpls.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: LinkTracker Class - {6A6E50DC-BFA8-4B40-AB1B-159E03E829FD} - C:\WINNT\system32\lmf32v.dll O2 - BHO: Band Class - {CC378B83-9577-44D0-B4F8-0DD965E176FC} - C:\Programme\eSyndicate\esyn.dll O3 - Toolbar: @msdxmLC.dll,-1@1031,&Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize O4 - HKLM\..\Run: [HotKey] C:\WINNT\Twain_32\FlatBed\HotKey.exe O4 - HKLM\..\Run: [ATICCC] "C:\Programme\ATI Technologies\ATI.ACE\cli.exe" runtime O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programme\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [70eb2297b5db] C:\WINNT\system32\docprop6.exe O4 - HKLM\..\Run: [TV Media] C:\Programme\TV Media\Tvm.exe O4 - HKLM\..\Run: [07oT3nQ] utilass.exe O4 - HKLM\..\Run: [3JAJY5H3ZBFHEC] C:\WINNT\system32\PgpXq.exe O4 - HKCU\..\Run: [internat.exe] internat.exe O4 - HKCU\..\Run: [Hpur] C:\Dokumente und Einstellungen\Mania1\Anwendungsdaten\q???.exe O4 - HKCU\..\Run: [TV Media] C:\Programme\TV Media\Tvm.exe O4 - HKCU\..\Run: [eZmmod] C:\PROGRA~1\ezula\mmod.exe O4 - HKCU\..\Run: [eZWO] C:\PROGRA~1\Web Offer\wo.exe O4 - HKCU\..\Run: [Hw73RhcFT] usbmxs.exe O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: ATI CATALYST System Tray.lnk = C:\Programme\ATI Technologies\ATI.ACE\CLI.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check(3).lnk = C:\WINNT\system32\spool\drivers\w32x86\3\E_SRCV03.EXE O4 - Global Startup: PrecisionTime.lnk = C:\Programme\PrecisionTime\PrecisionTime.exe O4 - Global Startup: GStartup.lnk = C:\Programme\Gemeinsame Dateien\GMT\GMT.exe O9 - Extra button: (no name) - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\system32\maxspeed.exe (file missing) O9 - Extra 'Tools' menuitem: MaxSpeed - {120E090D-9136-4b78-8258-F0B44B4BD2AC} - C:\WINNT\system32\maxspeed.exe (file missing) O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm O16 - DPF: {25365FF3-2746-4230-9DA7-163CCA318309} (GTDownloaderCtrl Class) - http://inst.c-wss.com/82/html/gtdownlr.cab O16 - DPF: {FE4BBEA8-1EFD-4B8A-BD1B-341CCDBEEAA6} - http://ads.dealhelper.com/updates/DealHelperNew.cab O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} (WMService Class) - http://download.overpro.com/WildApp.cab O18 - Filter: text/html - {DFAA31C8-A356-4313-9D95-5EDAB46C5070} - C:\WINNT\system32\lmf32v.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINNT\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINNT\system32\ati2sgag.exe O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE O23 - Service: Verwaltungsdienst für die Verwaltung logischer Datenträger (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe |
Themen zu HILFE Trojaner Dldr.VB.Em.2 |
antivir, befindet, dateien, folge, folgender, funktionier, funktioniert, gelöscht, hilfe trojaner, mehrmals, nachricht, programm, rechner, troja, trojaner, welchem |