|
Log-Analyse und Auswertung: Trojaner TR/DLDR.Agent bzw. TR/smallWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
03.01.2006, 13:15 | #1 |
| Trojaner TR/DLDR.Agent bzw. TR/small Hallo, habe hier ein Problem mit ein paar Trojanern, die ich nich los werde. Also Antivir meldet als Trojaner TR/DLDR.Agent.TD52 und 66, außerdem TR/Agent.BI.98 und TR/Small.GA.7 Trotz scannen mit Spybot und Ad-Aware auch im abgesicherten Modus tauchen die Teile immer wieder auf. Wer kann mir Helfen, habe hier mal das HJT Log und davon nicht die geringste Ahnung, die Kiste scheint nur ziemlich verbaselt zu sein. Logfile of HijackThis v1.99.1 Scan saved at 12:05:15, on 03.01.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\Programme\AVPersonal\AVGUARD.EXE C:\Programme\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\system32\slserv.exe C:\WINDOWS\msyk.exe C:\Programme\Java\jre1.5.0\bin\jusched.exe C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Programme\Synaptics\SynTP\SynTPLpr.exe C:\Programme\Synaptics\SynTP\SynTPEnh.exe C:\Programme\HP\HP Software Update\HPWuSchd2.exe C:\Programme\Winamp\winampa.exe C:\DOKUME~1\***\LOKALE~1\Temp\1F5.tmp.exe C:\Programme\Logitech\MouseWare\system\em_exec.exe C:\Programme\AVPersonal\AVGNT.EXE C:\WINDOWS\system32\atljh32.exe C:\WINDOWS\system32\ctfmon.exe C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe C:\Programme\HP\Digital Imaging\bin\hpqSTE08.exe C:\Programme\HP\Digital Imaging\Product Assistant\bin\hprblog.exe C:\Programme\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\wuauclt.exe C:\hijack\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R3 - Default URLSearchHook is missing O2 - BHO: Class - {054FA522-3449-3E70-B480-5C8348478A0A} - C:\WINDOWS\javand32.dll (file missing) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Class - {084856A6-8EE9-94CD-77C3-FF8257705B80} - C:\WINDOWS\system32\mfcyc.dll O2 - BHO: Class - {091DD5A2-BCF3-5ABD-CDB0-DEE71178B028} - C:\WINDOWS\sdklk32.dll (file missing) O2 - BHO: Class - {402AEE94-BB1D-D3EA-410F-95DE07E61963} - C:\WINDOWS\atlkx32.dll O2 - BHO: Class - {CA00AEE9-F0FC-9BB6-7C51-5ABAC98D7A70} - C:\WINDOWS\system32\ntzq32.dll O2 - BHO: Class - {EDA38CC9-B865-78BD-C1A5-843DCC6547D9} - C:\WINDOWS\mfcir32.dll O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0\bin\jusched.exe O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [HP Software Update] C:\Programme\HP\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKLM\..\Run: [1DE.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\1DE.tmp.exe O4 - HKLM\..\Run: [WinHound] C:\Programme\WinHound\WinHound.exe O4 - HKLM\..\Run: [NAVNet] "C:\Dokumente und Einstellungen\***\Startmenü\Programme\Autostart\ms.exe" /m O4 - HKLM\..\Run: [javajv.exe] C:\WINDOWS\system32\javajv.exe O4 - HKLM\..\Run: [1F5.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\1F5.tmp.exe O4 - HKLM\..\Run: [1F6.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\1F6.tmp.exe O4 - HKLM\..\Run: [1F5.tmp.exe] C:\DOKUME~1\***\LOKALE~1\Temp\1F5.tmp.exe O4 - HKLM\..\Run: [1F6.tmp.exe] C:\DOKUME~1\***\LOKALE~1\Temp\1F6.tmp.exe O4 - HKLM\..\Run: [1FD.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\1FD.tmp.exe O4 - HKLM\..\Run: [1FD.tmp.exe] C:\DOKUME~1\***\LOKALE~1\Temp\1FD.tmp.exe O4 - HKLM\..\Run: [netti32.exe] C:\WINDOWS\system32\netti32.exe O4 - HKLM\..\Run: [204.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\204.tmp.exe O4 - HKLM\..\Run: [204.tmp.exe] C:\DOKUME~1\***\LOKALE~1\Temp\204.tmp.exe O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min O4 - HKLM\..\Run: [atljh32.exe] C:\WINDOWS\system32\atljh32.exe O4 - HKLM\..\RunOnce: [msyk.exe] C:\WINDOWS\msyk.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [LDM] \Program\ O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programme\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0\bin\npjpi150.dll O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - h**p://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - h**p://w*w.johannrain-softwareentwicklung.de/scan/Msie/bitdefender.cab O18 - Protocol: bw+0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw+0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw-0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw00s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw10s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw20s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw30s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw40s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw50s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw60s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw70s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw80s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bw90s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwa0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwb0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwc0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwd0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwe0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwf0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: bwg0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwg0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwh0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwi0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwj0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwk0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwl0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwm0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwn0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwo0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwp0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwq0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwr0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bws0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwt0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwu0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwv0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bww0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwx0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwy0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: bwz0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O18 - Protocol: offline-8876480 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\apiai32.exe (file missing) O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe |
03.01.2006, 13:24 | #2 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojaner TR/DLDR.Agent bzw. TR/small Nur ein Auszug:
__________________Zitat:
__________________ |
03.01.2006, 13:25 | #3 |
| Trojaner TR/DLDR.Agent bzw. TR/small hallo,
__________________also ich sehe direkt einige sachen bei denen ich nicht weiss was ich davon halten soll... ich bitte dich darum einen onlinescan Hier zu machen und das ergebniss hier zu posten... damit wir sicher wissen ob fixen und löschen ausreicht oder eventuell doch neu aufgesetzt werden muss..
__________________ |
03.01.2006, 16:31 | #4 |
| Trojaner TR/DLDR.Agent bzw. TR/small KASPERSKY ON-LINE SCANNER REPORT Tuesday, January 03, 2006 16:30:28 Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version: 5.0.67.0 Kaspersky Anti-Virus database last update: 3/01/2006 Kaspersky Anti-Virus database records: 158551 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ Scan Statistics: Total number of scanned objects: 69025 Number of viruses found: 6 Number of infected objects: 144 Number of suspicious objects: 0 Duration of the scan process: 8039 sec Infected Object Name - Virus Name C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[Fro ... /[From "Horst-Dieter Ge ... /[F ... /[From "Patncree" <patncree@ev1.net>][Date Tue, 31 May 2005 15: ... /02_05_2005.exe Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[Fro ... /[From "Horst-Dieter Ge ... /[F ... /[From "Patncree" <patncree@ev1.net>][Date Tue, 31 May 2005 15:20:49 - ... /UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[Fro ... /[From "Horst-Dieter Ge ... /[F ... /[From "Patncree" <patncree@ev1.net>][Date Tue, 31 May 2005 15:20:49 -0300]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[Fro ... /[From "Horst-Dieter Ge ... /[From Team Vectra <Team.Vectra@de.opel.com>][Date Tue, 31 May 2005 11:43:43 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[Fro ... /[From "Horst-Dieter Geuting" <horst-dieter.geuting@w.fh-giessen.de>][Date Thu, 26 May 2005 09:20:29 +0200 (CEST)]/text Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO ... ... /[F ... /[From "Sebastian Brehmer" <sebastian_brehmer@web.de>][Date Mon, 23 May 2005 16:25:42 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO ... ... /[From .. ... /[From "WiWi-Online.de" <schmid@wiwi-online.de>][Date Fri, 20 May 2005 14:20:28 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO ... ... /[From ... /[From "Martin Pfe ... /[From <leonardo-tutor@web.de>][Date Fri, 20 May 2005 09:17:24 +0200]/text Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO ... ... /[From ... /[From "Martin Pfeiffer" <mail@Martin-Pfeiffer.de>][Date Thu, 19 May 2005 16:24:02 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO ... ... /[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Thu, 19 May 2005 15:00:41 +0100]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO ... /[From "bestellbestaetigung@amazon.de" <bestellbestaetigung@amazon.de>][Date 19 May 2005 00:55:47 -0700]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-885 ... .. ... /[From "Susanne Weber" <Susanne.Weber@w.fh-giessen.de>][Date Fri, 29 Apr 2005 11:12:03 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-885 ... ... /[ ... /[From "Julia Mengel" <julia.mengel@gmx.de>][Date Thu, 28 Apr 2005 08:58:49 +0200 (MEST)]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-885 ... ... /[From "Dr. Martin Schmidt" <Martin.Schmidt@w.fh-giessen.de>][Date Wed, 13 Apr 2005 18:46:58 +0200]/text Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-885 ... /[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 12 Apr 2005 15:00:35 +0100]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-8859-1?b ... /[Fr ... /[From "Schlueter, Ursula" <u.schlueter@ukh.de>][Date Tue, 12 Apr 2005 08:20:21 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-8859-1?b ... /[From "Dr ... /[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 11 Apr 2005 14:48:47 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-8859-1?b ... /[From "Dr. Martin Schmidt" <Martin.Schmidt@w.fh-giessen.de>][Date Mon, 4 Apr 2005 09:28:11 +0200]/text Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-8859-1?b?Ik1pY2hhZ ... /[From "Benjamin Hermann" <b.hermann@coreto.de>][Date Fri, 1 Apr 2005 16:48:08 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-8859-1?b?Ik1pY2hhZWwgR/Z0eiwgQS1KdW5pb3JlbiI=?= <510060784089-0001@T-Online.de>][Date 31 Mar 2005 14:07 GMT]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 ... /[From =?ISO-8859 ... /[From ... /[From =?iso-8859-1?Q?Lena_Sch=FCtz?= <les@vds.ag>][Date Tue, 29 Mar 2005 12:40:27 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 ... /[From =?ISO-8859 ... /[From "dany.eberhart@t-online.de" <dany.eberhart@t-online.de>][Date Thu, 24 Mar 2005 12:44:56 +0100]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 ... /[From =?ISO-8859-1?Q?=22Sabrina_Hillg=E4rtner=22?= <sabrina.hillgaertner@gmx.de>][Date Mon, 21 Mar 2005 20:52:46 +0100 (MET)]/text Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12:16:37 +0100 (MET)]/UNNAMED/[From ... /[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 14:44:30 +0100 (MET)]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12:16:37 +0100 (MET)]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12:21:31 +0100 (MET)]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12:16:37 +0100 (MET)]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 J ... ... ... /[From "Patncree" <patncree@ev1.net>][Date Tue, 31 May 2005 15: ... /02_05_2005.exe Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 J ... ... ... /[From "Patncree" <patncree@ev1.net>][Date Tue, 31 May 2005 15:20:49 - ... /UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 J ... ... ... /[From "Patncree" <patncree@ev1.net>][Date Tue, 31 May 2005 15:20:49 -0300]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 J ... ... /[From *** Ecke <***.Ecke@gmx.de>][Date Sun, 07 Aug 2005 10:54:32 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 J ... ... /[From *** Ecke <***.Ecke@gmx.de>][Date Fri, 05 Aug 2005 18:12:33 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 J ... /[From "Martin Pfeiffer" <mail@Martin-Pfeiffer.de>][Date Tue, 2 Aug 2005 12:33:34 +0200]/text Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 Jun 2005 15:11:07 +0200]/text Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash Infected: Email-Worm.Win32.Bagle.bo C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\1F5.tmp Infected: not-virus:Hoax.Win32.SpyWare.a C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\1F5.tmp.exe Infected: not-virus:Hoax.Win32.SpyWare.a |
03.01.2006, 16:37 | #5 |
| Trojaner TR/DLDR.Agent bzw. TR/small C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\1F6.tmp Infected: Trojan.Win32.Small.ga C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\1F6.tmp.exe Infected: Trojan.Win32.Small.ga C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\1F8.tmp Infected: not-virus:Hoax.Win32.SpyWare.a C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\1FC.tmp Infected: not-virus:Hoax.Win32.SpyWare.a C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\203.tmp Infected: not-virus:Hoax.Win32.SpyWare.a C:\Programme\AVPersonal\INFECTED\1FD.tmp.VIR Infected: Trojan.Win32.Small.ga C:\Programme\AVPersonal\INFECTED\1FD.tmp.VIR00 Infected: Trojan.Win32.Small.ga C:\Programme\AVPersonal\INFECTED\JAVAJV.EXE.VIR Infected: Trojan-Downloader.Win32.Agent.td C:\Programme\AVPersonal\INFECTED\NETTI32.EXE.VIR Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP110\A0016203.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP110\A0016221.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016248.dll Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016256.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016256.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016256.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016261.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.tdC:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016261.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016261.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016280.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016280.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016280.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0032393.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0032393.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0032393.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032524.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032524.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032524.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032533.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032533.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032533.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032537.ini:reuhkk:$DATA Infected: Trojan.Win32.Agent.bi C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032615.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032615.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032615.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP113\A0032623.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032624.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032778.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032786.INI:sqiatj:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032787.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032787.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032787.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032800.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP115\A0032804.INI:sqiatj:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP115\A0032805.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP115\A0032805.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP115\A0032805.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP115\A0032839.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP115\A0032846.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032864.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032872.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032882.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032886.INI:sqiatj:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032887.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032887.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032887.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi C:\WINDOWS\addln.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\atlkx32.dll Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\Blaue Spitzen 16.bmp:mmkwxa:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\clock.avi:emccrc:$DATA Infected: Trojan.Win32.Agent.bi C:\WINDOWS\clock.avi:tczzza:$DATA Infected: Trojan.Win32.Agent.bi C:\WINDOWS\control.ini:vttvsy:$DATA Infected: Trojan.Win32.Agent.bi C:\WINDOWS\FaxSetup.log:xvxnol:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\iene.dll Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\ipyn.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\KB887742.log:encjhr:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\KB890046.log:wnuwbb:$DATA Infected: Trojan.Win32.Agent.bi C:\WINDOWS\KB904706.log:hjsojr:$DATA Infected: Trojan.Win32.Agent.bi C:\WINDOWS\mfcir32.dll Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\mozver.dat:zdbtih:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\msdn32.dll Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\mstf32.dll Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\msuz.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\msyk.exe Infected: Trojan.Win32.Agent.bi C:\WINDOWS\netcb32.dll Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\ntcd32.exe Infected: Trojan.Win32.Agent.bi C:\WINDOWS\ntme32.dll Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\orun32.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\sdkrq.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\sdksi.dll Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\sessmgr.setup.log:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi C:\WINDOWS\setupact.log:ruagh:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\system32\apilf.exe Infected: Trojan.Win32.Agent.bi C:\WINDOWS\system32\appno.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\system32\atljh32.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\system32\crua32.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\system32\d3ev32.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\system32\javaeb.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\system32\javaoo.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\system32\mfcyc.dll Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\system32\netsq.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\system32\ntbh.dll Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\system32\ntzq32.dll Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\system32\systh.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\system32\sysxb.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\system32\wincs.exe Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\WINCMD.INI:sqiatj:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\winjx32.exe Infected: Trojan.Win32.Agent.bi C:\WINDOWS\_default.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td C:\WINDOWS\_default.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc C:\WINDOWS\_default.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi Scan process completed. |
03.01.2006, 19:56 | #6 |
| Trojaner TR/DLDR.Agent bzw. TR/small hallo, alsonach dem logfile vom onlinescan kommt nur noch das Neuaufsetzen in frage.. anleitung dazu im link meiner signatur..
__________________ --> Trojaner TR/DLDR.Agent bzw. TR/small |
03.01.2006, 21:26 | #7 |
| Trojaner TR/DLDR.Agent bzw. TR/small O.K. Danke, dachte ich käme irgendwie um die Arbeit rum. Schöne Grüße Christian |
04.01.2006, 00:37 | #8 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Trojaner TR/DLDR.Agent bzw. TR/small Die Arbeit bzw. Zeit ersparst Du Dir mit regelmäßigen Backups, z. B. Acronis True Image. Kannste direkt nachdem Neuaufsetzen ein Image Deines Systems auf externe Datenträger ziehen und bei Bedarf wieder einspielen.
__________________ Logfiles bitte immer in CODE-Tags posten |
Themen zu Trojaner TR/DLDR.Agent bzw. TR/small |
abgesicherten modus, ad-aware, adobe, antivir, antivir meldet, bho, desktop, einstellungen, excel, explorer, firefox, helfen, hijack, hijackthis, immer wieder, internet, internet explorer, kis, mozilla, mozilla firefox, ms.exe, problem, scan, security, software, system, temp, tr/dldr.agent, trojaner, urlsearchhook, windows, windows xp |