|
Log-Analyse und Auswertung: Low.zonesWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
25.08.2005, 16:42 | #1 |
| Low.zones Hallo, habe mir den Trojaner Low.Zones eingefangen. Kenne mich mit der Materie leider nicht gut aus, und habe deshalb erstmal die Foren durchforscht. Darauf hin das Programm "Hijackthis" runtergeladen und laufen lassen. Hier nun der LOG: Benutze übrigens Anrivir Personal Home Edition. Logfile of HijackThis v1.99.1 Scan saved at 17:01:12, on 25.08.2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis1\ToADiMon.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\UsrPrmpt.exe C:\Programme\AVPersonal\AVGNT.EXE C:\WINDOWS\System32\MSLSA32.exe C:\WINDOWS\System32\system.pif C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\WINDOWS\System32\ctfmon.exe C:\Programme\Messenger\msmsgs.exe C:\Programme\MSN Messenger\MsnMsgr.Exe C:\WINDOWS\System32\MSLSA32.exe C:\WINDOWS\System32\updating.pif C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Dokumente und Einstellungen\Tamás\Lokale Einstellungen\Temp\Temporäres Verzeichnis 3 für hijackthis.zip\HijackThis.exe C:\WINDOWS\System32\updating.pif C:\WINDOWS\System32\system.pif R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://windowsupdate.microsoft.com/ O1 - Hosts: 141.225.152.142 onlineaccounts2.abbeynational.co.uk O1 - Hosts: 141.225.152.142 www3.aibgbonline.co.uk O1 - Hosts: 141.225.152.142 www.bank.alliance-leicester.co.uk O1 - Hosts: 141.225.152.142 login.iblogin.com O1 - Hosts: 141.225.152.142 ww2.bankofscotlandhalifax-online.co.uk O1 - Hosts: 141.225.152.142 inet.barclays.co.uk O1 - Hosts: 141.225.152.142 iibank.barclays.co.uk O1 - Hosts: 141.225.152.142 iibank.cahoot.com O1 - Hosts: 141.225.152.142 www3.coventrybuildingsociety.co.uk O1 - Hosts: 141.225.152.142 ww.hsbc.co.uk O1 - Hosts: 141.225.152.142 login.ebank.offshore.hsbc.co.je O1 - Hosts: 141.225.152.142 ww3.online-offshore.lloydstsb.com O1 - Hosts: 141.225.152.142 ww3.online-business.lloydstsb.co.uk O1 - Hosts: 141.225.152.142 ww3.online.lloydstsb.co.uk O1 - Hosts: 141.225.152.142 ww3.online.lloydstsb.co.uk O1 - Hosts: 141.225.152.142 ww3.online-business.lloydstsb.co.uk O1 - Hosts: 141.225.152.142 ob2.nationet.com O1 - Hosts: 141.225.152.142 ww3.onlinebanking.natwestoffshore.com O1 - Hosts: 141.225.152.142 ww1.nwolb.com O1 - Hosts: 141.225.152.142 ww1.onlinebanking.iombank.com O1 - Hosts: 141.225.152.142 ww1.www.rbsdigital.com O1 - Hosts: 141.225.152.142 welcome.smile.co.uk O1 - Hosts: 141.225.152.142 login.365online.com O1 - Hosts: 141.225.152.142 wvw.citizensbankonline.com O1 - Hosts: 141.225.152.142 esecure.regionsnet.com O1 - Hosts: 141.225.152.142 rollb.associatedbank.com O1 - Hosts: 141.225.152.142 upb.unionplanters.com O1 - Hosts: 141.225.152.142 www.onlinebanking.huntington.com O1 - Hosts: 141.225.152.142 inet.southtrustonlinebanking.com O1 - Hosts: 141.225.152.142 logon.personal.wamu.com O1 - Hosts: 141.225.152.142 login.compassweb.com O1 - Hosts: 141.225.152.142 logon.firstmeritib.com O1 - Hosts: 141.225.152.142 login.ccfcuonline.org O1 - Hosts: 141.225.152.142 ww3.etimebanker.bankofthewest.com O1 - Hosts: 141.225.152.142 ww2.onlinebanking.lasallebank.com O1 - Hosts: 141.225.152.142 wvw.totallyfreebanking.com O1 - Hosts: 141.225.152.142 www.online.wellsfargo.com O1 - Hosts: 141.225.152.142 www.onlinebanking.bankofoklahoma.com O1 - Hosts: 141.225.152.142 accounts4.keybank.com O1 - Hosts: 141.225.152.142 logon.bankone.com O1 - Hosts: 141.225.152.142 www.secure.tdbanknorth.com O1 - Hosts: 141.225.152.142 www.secure.mvnt4.com O1 - Hosts: 141.225.152.142 ww.mynfbonline.com O1 - Hosts: 141.225.152.142 login.forumcuonline.com O1 - Hosts: 141.225.152.142 www.eds.usersonlnet.com O1 - Hosts: 141.225.152.142 www.onlineid.bankofamerica.com O1 - Hosts: 141.225.152.142 wvw.e-gold.com O1 - Hosts: 141.225.152.142 pcbs.peoples.com O1 - Hosts: 141.225.152.142 www.global1.onlinebank.com O1 - Hosts: 141.225.152.142 ww2.mybranch.lafcu.com O1 - Hosts: 141.225.152.142 login.webbanking.comerica.com O1 - Hosts: 141.225.152.142 web.banking.firsttennessee.com O1 - Hosts: 141.225.152.142 logon.members1st.org O1 - Hosts: 141.225.152.142 www.cib.ibanking-services.com O1 - Hosts: 141.225.152.142 www.miwebbusbank.ebanking-services.com O1 - Hosts: 141.225.152.142 wvw.paypal.com O1 - Hosts: 141.225.152.142 www.signin.ebay.com O1 - Hosts: 141.225.152.142 wvw.etrade.com O1 - Hosts: 141.225.152.142 ww4.fleethomelink.fleet.com O1 - Hosts: 141.225.152.142 ww3.connect.skyfi.com O1 - Hosts: 141.225.152.142 www6.usbank.com O1 - Hosts: 141.225.152.142 www.bvi.bancodevalencia.es O1 - Hosts: 141.225.152.142 extrant.banesto.es O1 - Hosts: 141.225.152.142 banesnt.banesto.es O1 - Hosts: 141.225.152.142 activia.caixagalicia.es O1 - Hosts: 141.225.152.142 www.bancae.caixapenedes.com O1 - Hosts: 141.225.152.142 login.caixasabadell.net O1 - Hosts: 141.225.152.142 oii.cajamadrid.es O1 - Hosts: 141.225.152.142 login.cajamar.es O1 - Hosts: 141.225.152.142 login.ccm.es O1 - Hosts: 141.225.152.142 ww.unicaja.es O1 - Hosts: 141.225.152.142 www5.bancopopular.es O1 - Hosts: 141.225.152.142 ww3.bbvanet.com O1 - Hosts: 141.225.152.142 ww.bayernlb.de O1 - Hosts: 141.225.152.142 ww2.berliner-volksbank.de O1 - Hosts: 141.225.152.142 ww7.homebanking-berlin.de O1 - Hosts: 141.225.152.142 portal09.commerzbanking.de O1 - Hosts: 141.225.152.142 www.meine.deutsche-bank.de O1 - Hosts: 141.225.152.142 ww2.dresdner-privat.de O1 - Hosts: 141.225.152.142 ww.e-banking.helaba.de O1 - Hosts: 141.225.152.142 ww.hsh-nordbank.de O1 - Hosts: 141.225.152.142 www.my.hypovereinsbank.de O1 - Hosts: 141.225.152.142 ww3.homebanking-berlin.de O1 - Hosts: 141.225.152.142 ww3.homebanking-berlin.de O1 - Hosts: 141.225.152.142 www.banking.lbbw.de O1 - Hosts: 141.225.152.142 lrp.sparkasse-banking.de O1 - Hosts: 141.225.152.142 ww3.homebanking-niedersachsen.de O1 - Hosts: 141.225.152.142 www.onlinebanking.norisbank.de O1 - Hosts: 141.225.152.142 www.banking.postbank.de O1 - Hosts: 141.225.152.142 wvw.internetbanking.gad.de O1 - Hosts: 141.225.152.142 ww1.portal.izb.de O1 - Hosts: 141.225.152.142 wvw.kunden-service.lbs.de O1 - Hosts: 141.225.152.142 ibanking.seb.de O1 - Hosts: 141.225.152.142 bw7.sparkasse-banking.de O1 - Hosts: 141.225.152.142 ww2.homebanking-sparkasse.de O1 - Hosts: 141.225.152.142 ww2.vr-networld-ebanking.de O1 - Hosts: 141.225.152.142 ww.bics.fr O1 - Hosts: 141.225.152.142 www.co.caixabank.fr O1 - Hosts: 141.225.152.142 ww.creditmutuel.fr O1 - Hosts: 141.225.152.142 internetbank.intesabci.it O1 - Hosts: 141.225.152.142 ww.extensive.bancalombarda.it O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Programme\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Microsoft Javascript Class - {6E28339B-7A2A-47B6-AEB2-46BA53782373} - C:\WINDOWS\System32\dllcache\javascript.dll O2 - BHO: Microsoft Update Proxy Class - {6E28339B-7A2A-47B6-AEB2-46BA53782375} - C:\WINDOWS\System32\dllcache\msupdprx.dll (file missing) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\ycomp5_5_7_0.dll O4 - HKLM\..\Run: [ToADiMon.exe] C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis1\ToADiMon.exe -TOnlineAutodialStart O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [Microsoft LSA layer] MSLSA32.exe O4 - HKLM\..\Run: [System Update Service] system.pif O4 - HKLM\..\Run: [Windows Updating Service] updating.pif O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\RunServices: [Microsoft LSA layer] MSLSA32.exe O4 - HKLM\..\RunServices: [System Update Service] system.pif O4 - HKLM\..\RunServices: [Windows Updating Service] updating.pif O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Microsoft LSA layer] MSLSA32.exe O4 - HKCU\..\Run: [System Update Service] system.pif O4 - HKCU\..\Run: [Windows Updating Service] updating.pif O4 - HKCU\..\RunServices: [System Update Service] system.pif O4 - HKCU\..\RunServices: [Windows Updating Service] updating.pif O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE O16 - DPF: {04E214E5-63AF-4236-83C6-A7ADCBF9BD02} (HouseCall Control) - http://housecall60.trendmicro.com/housecall/xscan60.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsu...?1121955459074 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/ms...downloader.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{90E9444C-5541-407F-9F47-F8154C1B313B}: NameServer = 217.237.151.161 217.237.151.33 O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE O23 - Service: ET dll Locator (frepdll.exe) - Unknown owner - C:\WINDOWS\frepdll.exe (file missing) O23 - Service: hexadecimal (HexadecimaRepresentation) - Unknown owner - C:\WINDOWS\Edit.exe (file missing) O23 - Service: Hardware Clock Driver (hwclock) - Unknown owner - C:\WINDOWS\System32\hwclock.exe (file missing) O23 - Service: netinfo - Unknown owner - C:\WINDOWS\netinfo.exe O23 - Service: Remote Procedure Call (RPC) Monitoring (Rpcmon) - Unknown owner - C:\WINDOWS\system32\MSASP32.exe (file missing) O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe O23 - Service: AntiSpyUltra (Zonelaps) - Unknown owner - C:\WINDOWS\vsmom.exe (file missing) Vielen Dank im Vorraus. LTR |
25.08.2005, 17:51 | #2 |
/// Helfer-Team | Low.zones Ein Grund für die Verseuchung ist in der fehlenden Aktualität des Systems zu suchen. Hast Du schon mal was von SP 2 gehört?
__________________Lasse folgende Datei: C:\WINDOWS\System32\MSLSA32.exe hier prüfen http://virusscan.jotti.org/de/ Sollte sich der Verdacht bestätigen: http://www.sophos.com/virusinfo/anal...32rbotakz.html gilt für Dich: http://www.trojaner-board.de/showthread.php?t=17492 |
Themen zu Low.zones |
adobe, adobe reader, alert, antivir, avg, bho, einstellungen, explorer, hijack, hijackthis, home, internet, internet explorer, log, programm, programme, proxy, security, security center, software, symantec, system, t-online, temp, trojaner, windows, windows xp, yahoo |