|
Plagegeister aller Art und deren Bekämpfung: trojaner u. würmerWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
07.06.2005, 21:28 | #1 |
| trojaner u. würmer hallo habe hier ein problem, habe heute av laufen lassen es hat 15 vieren/trojaner/würmer gefunden. z.B. 12.01.2002,20:52:53 [WARNUNG] Enthält Signatur des Wurmes Worm/RBot.352112! C:\XZ.EXE 12.01.2002,20:53:08 [WARNUNG] Enthält Signatur des Wurmes Worm/RBot.352112! C:\XZ.EXE 12.01.2002,20:53:13 [WARNUNG] Enthält Signatur des Wurmes Worm/RBot.352112! C:\XZ.EXE 12.01.2002,20:50:50 [WARNUNG] Enthält Signatur des Wurmes Worm/RBot.352112! C:\XZ.EXE 12.01.2002,20:53:26 [WARNUNG] Ist das Trojanische Pferd TR/Dldr.Agent.JN.2! C:\DOKUME~1\FUJITS~1\LOKALE~1\TEMP\IXP000.TMP\REBATES.EXE ich kann die ordner nicht löschen. im abgesicherten finde ich die order nicht trotz alle dateien anzeigen. vielen dank für eure hilfe Logfile of HijackThis v1.99.1 Scan saved at 22:11:25, on 12.01.2002 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Programme\AVPersonal\AVGUARD.EXE C:\WINDOWS\System32\Ati2evxx.exe C:\Programme\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\system32\slserv.exe C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Programme\ICQLite\ICQLite.exe C:\Programme\Winamp\Winampa.exe C:\Programme\Elaborate Bytes\CloneCD\CloneCDTray.exe C:\Programme\NETGEAR\WG511SCU\Utility\Gear511.exe C:\Programme\AVPersonal\AVGNT.EXE C:\WINDOWS\System32\alg.exe C:\WINDOWS\system32\ctfmon.exe C:\Programme\Microsoft ActiveSync\WCESCOMM.EXE C:\Programme\Spybot - Search & Destroy\TeaTimer.exe C:\PROGRA~1\FlashGet\flashget.exe C:\Programme\Spybot - Search & Destroy\SpybotSD.exe C:\Programme\Internet Explorer\iexplore.exe C:\Programme\WinRAR\WinRAR.exe C:\Programme\WinRAR\WinRAR.exe C:\DOKUME~1\FUJITS~1\LOKALE~1\Temp\Rar$EX54.610\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ R3 - Default URLSearchHook is missing O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll O3 - Toolbar: ISTbar - {FAA356E4-D317-42a6-AB41-A3021C6E7D52} - C:\Programme\ISTbar\istbarcm.dll (file missing) O3 - Toolbar: (no name) - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - (no file) O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize O4 - HKLM\..\Run: [WinampAgent] "C:\Programme\Winamp\Winampa.exe" O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Programme\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL O4 - HKLM\..\Run: [CloneCDTray] "C:\Programme\Elaborate Bytes\CloneCD\CloneCDTray.exe" O4 - HKLM\..\Run: [AS00_Gear511] C:\Programme\NETGEAR\WG511SCU\Utility\Gear511.exe -hide O4 - HKLM\..\Run: [winupdate] C:\Programme\winupdate\winupdate.exe /auto O4 - HKLM\..\Run: [xSc6e] C:\WINDOWS\jpkiyx.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [KAVPersonal50] "C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programme\Microsoft ActiveSync\WCESCOMM.EXE" O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: Alles mit FlashGet laden - C:\PROGRA~1\FlashGet\jc_all.htm O8 - Extra context menu item: Mit FlashGet laden - C:\PROGRA~1\FlashGet\jc_link.htm O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Mobilen Favoriten erstellen - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INETREPL.DLL O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INETREPL.DLL O9 - Extra 'Tools' menuitem: Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INETREPL.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra button: Klicke hier um das Projekt xp-AntiSpy zu unterstützen - {A2D0D03E-83A8-4C49-AC36-E3502BCCB48F} - C:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU) O9 - Extra 'Tools' menuitem: Unterstützung für xp-AntiSpy - {A2D0D03E-83A8-4C49-AC36-E3502BCCB48F} - C:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU) O15 - Trusted Zone: http://ny.contentmatch.net (HKLM) O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE O23 - Service: kavsvc - Kaspersky Lab - C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe |
07.06.2005, 21:35 | #2 |
Administrator, a.D. | trojaner u. würmer Hallo,
__________________in letzter Zeit häufen sich leider die Fehlalarme von AntiVir, scanne deshalb mit eScan AntiVirus im abgesicherten Modus und poste uns die Virus Log Information. Sollte sich auch hier der Backdoor Rbot.gen bestätigen, dann ist ein Neuaufsetzen deines System unumgänglich. btw: Hast du KAV tatsächlich gegen AntiVir ausgewechselt?
__________________ |
07.06.2005, 22:36 | #3 |
| trojaner u. würmer hallo
__________________eScan AntiVirus meldet folgendeshoffe ich habe das richtig gemacht) habe auch AntiVir und KAV laufen KAV funktioniert z.Z. nicht ********************************************************** Sat Jan 12 23:15:34 2002 => ***** Scanning Registry and File system for Adware/Spyware ***** Sat Jan 12 23:15:36 2002 => System found infected with BearShare Spyware/Adware ({905d0df2-3a0a-4d94-853c-54a12a745905})! Action taken: No Action Taken. Sat Jan 12 23:15:36 2002 => Object "BearShare Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:15:36 2002 => System found infected with BearShare Spyware/Adware ({9f95f736-0f62-4214-a4b4-caa6738d4c07})! Action taken: No Action Taken. Sat Jan 12 23:15:36 2002 => Object "BearShare Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:15:36 2002 => System found infected with BearShare Spyware/Adware ({558ec983-bedb-9168-b2de-31dbf0ee543e})! Action taken: No Action Taken. Sat Jan 12 23:15:36 2002 => Object "BearShare Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:15:36 2002 => System found infected with BearShare Spyware/Adware ({5f95e1af-2620-4f15-bdf9-7fdce4607e17})! Action taken: No Action Taken. Sat Jan 12 23:15:36 2002 => Object "BearShare Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:15:36 2002 => System found infected with SideFind Spyware/Adware ({10e42047-deb9-4535-a118-b3f6ec39b807})! Action taken: No Action Taken. Sat Jan 12 23:15:36 2002 => Object "SideFind Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:15:40 2002 => Offending Folder C:\PROGRA~1\sidefind present... Sat Jan 12 23:15:40 2002 => Object "sidefind Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:15:52 2002 => Offending value found in HKCU\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\power scan !!! Sat Jan 12 23:15:52 2002 => Object "Power scan Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:15:52 2002 => Offending value found in HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\istbar !!! Sat Jan 12 23:15:52 2002 => Offending value found in HKLM\Software\istbar !!! Sat Jan 12 23:15:52 2002 => Object "istbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:15:56 2002 => Offending value found in HKLM\Software\avenue media !!! Sat Jan 12 23:15:56 2002 => Object "180Solutions Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:15:59 2002 => Offending value found in HKLM\Software\microsoft\downloadmanager !!! Sat Jan 12 23:15:59 2002 => Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:16:12 2002 => Offending value found in HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\bearshare !!! Sat Jan 12 23:16:12 2002 => Offending value found in HKCU\appevents\schemes\apps\bearshare !!! Sat Jan 12 23:16:12 2002 => Offending value found in HKLM\Software\magnet\handlers\bearshare !!! Sat Jan 12 23:16:12 2002 => Offending value found in HKLM\Software\bearshare !!! Sat Jan 12 23:16:12 2002 => Offending Folder C:\PROGRA~1\BEARSH~1 present... Sat Jan 12 23:16:12 2002 => Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:16:17 2002 => Offending value found in HKCU\appevents\eventlabels\bearsharechatnotifymsg !!! Sat Jan 12 23:16:17 2002 => Object "bearsharechatnotifymsg Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:16:30 2002 => Offending value found in HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\whenusavemsg !!! Sat Jan 12 23:16:30 2002 => Object "WhenU Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:16:30 2002 => Offending value found in HKCU\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\WhenU !!! Sat Jan 12 23:16:30 2002 => Offending Folder C:\DOKUME~1\FUJITS~1\STARTM~1\PROGRA~1\WhenU present... Sat Jan 12 23:16:30 2002 => Object "WhenU Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:16:31 2002 => Offending Folder C:\PROGRA~1\save present... Sat Jan 12 23:16:31 2002 => Object "WhenU Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:16:31 2002 => Offending Folder C:\DOKUME~1\FUJITS~1\FAVORI~1\Living present... Sat Jan 12 23:16:31 2002 => Object "ISearchTech.ISTdownloader Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:16:33 2002 => System found infected with eZula Spyware/Adware (exclean.exe)! Action taken: No Action Taken. Sat Jan 12 23:16:33 2002 => Object "eZula Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:16:37 2002 => System found infected with BearShare Spyware/Adware (bearshare.lnk)! Action taken: No Action Taken. Sat Jan 12 23:16:37 2002 => Object "BearShare Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jan 12 23:16:38 2002 => ***** Scanning Registry for errors created because of Adware/Spyware ***** Sat Jan 12 23:16:38 2002 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccVrTrst.dll". Action Taken: No Action Taken. Sat Jan 12 23:16:39 2002 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\MSXML3A.DLL". Action Taken: No Action Taken. Sat Jan 12 23:16:39 2002 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\AWINDIS3.VXD". Action Taken: No Action Taken. Sat Jan 12 23:16:52 2002 => Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken. Sat Jan 12 23:16:52 2002 => Entry "HKCR\CLSID\{88E729D6-BDC1-11D1-BD2A-00C04FB9603F}" refers to invalid object "fde.dll". Action Taken: No Action Taken. Sat Jan 12 23:16:53 2002 => Entry "HKCR\CLSID\{9EFBF860-5685-11D3-AA3D-00C04F4C5275}" refers to invalid object "cdooff.dll". Action Taken: No Action Taken. Sat Jan 12 23:16:58 2002 => Entry "HKCR\CLSID\{DC341F1B-EC77-47BE-8F58-96E83861CC5A}" refers to invalid object "C:\Programme\ISTbar\cmctl.dll". Action Taken: No Action Taken. Sat Jan 12 23:16:59 2002 => Entry "HKCR\CLSID\{E409CC3A-CA4F-4DDC-B251-AF1E1D38BB33}" refers to invalid object "C:\PROGRA~1\GEMEIN~1\SYMANT~1\SymLTCOM.dll". Action Taken: No Action Taken. Sat Jan 12 23:17:01 2002 => Entry "HKCR\CLSID\{FAA356E4-D317-42a6-AB41-A3021C6E7D52}" refers to invalid object "C:\Programme\ISTbar\istbarcm.dll". Action Taken: No Action Taken. Sat Jan 12 23:17:04 2002 => Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Sat Jan 12 23:17:04 2002 => Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Sat Jan 12 23:17:12 2002 => Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken. Sat Jan 12 23:17:12 2002 => Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Sat Jan 12 23:17:12 2002 => Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Sat Jan 12 23:17:18 2002 => Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Sat Jan 12 23:17:18 2002 => Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Sat Jan 12 23:17:19 2002 => Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Sat Jan 12 23:17:19 2002 => Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Sat Jan 12 23:17:22 2002 => Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Sat Jan 12 23:17:22 2002 => Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Sat Jan 12 23:17:22 2002 => ***** Checking for specific ITW Viruses ***** Sat Jan 12 23:17:22 2002 => Checking for Welchia Virus... Sat Jan 12 23:17:22 2002 => Checking for LovGate Virus... Sat Jan 12 23:17:22 2002 => Checking for CodeRed Virus... Sat Jan 12 23:17:22 2002 => Checking for OpaServ Virus... Sat Jan 12 23:17:22 2002 => Checking for Sobig.e Virus... Sat Jan 12 23:17:22 2002 => Checking for Winupie Virus... Sat Jan 12 23:17:22 2002 => Checking for Swen Virus... Sat Jan 12 23:17:22 2002 => Checking for JS.Fortnight Virus... Sat Jan 12 23:17:22 2002 => Checking for Novarg Virus... Sat Jan 12 23:17:22 2002 => Checking for Pagabot Virus... Sat Jan 12 23:17:22 2002 => Checking for Parite.b Virus... Sat Jan 12 23:17:22 2002 => Checking for Parite.a Virus... Sat Jan 12 23:17:22 2002 => Checking for Adware.SeekSeek Virus... Sat Jan 12 23:17:22 2002 => ***** Scanning complete. ***** Sat Jan 12 23:17:22 2002 => Total Objects Scanned: 9636 Sat Jan 12 23:17:22 2002 => Total Virus(es) Found: 19 Sat Jan 12 23:17:22 2002 => Total Disinfected Files: 0 Sat Jan 12 23:17:22 2002 => Total Files Renamed: 0 Sat Jan 12 23:17:22 2002 => Total Deleted Objects: 0 Sat Jan 12 23:17:22 2002 => Total Errors: 23 Sat Jan 12 23:17:22 2002 => Time Elapsed: 00:02:29 |
07.06.2005, 22:45 | #4 |
Administrator, a.D. | trojaner u. würmer Du hast eScan trotz Anleitung nicht richtig ausgeführt. Die Scan-Zeit von 2:29 Min. ist etwas mager... |
Themen zu trojaner u. würmer |
adobe, antivir, antivir update, bho, dateien, excel, explorer, file missing, hijack, hijackthis, hotkey, internet, internet explorer, kaspersky, microsoft, netgear, ordner, problem, programme, skype.exe, software, system, temp, trojaner, urlsearchhook, warnung, windows, windows messenger, windows xp, winupdate.exe |