|
Plagegeister aller Art und deren Bekämpfung: Trojaneralarm!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
27.08.2006, 13:27 | #1 |
| Trojaneralarm! Hab ein Problem mit einem Trojaner, ich hoffe das mir jemand helfen kann, da ich nicht wirklich Ahnung von sowas habe. Hab auch schon mit mehreren Programmen gescannt. RegFreeze gibt nach dem Scannen das aus: [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System] "NoDispBackgroundPage"=dword:00000000 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "seekmo"="\"c:\\programme\\seekmo\\seekmo.exe\"" Ewido Antispy meint das der Rechner sauber wäre! Bei Adware wir ein Trojaner namens Win32.Trojaner.Download gefunden. Hab auch schon eine Anleitung hier im Board abgearbeitet, mit CCleaner und Ewido Anti-Spyware, leider hab ich das Problem nicht lösen können. Bitte helft mir! |
27.08.2006, 13:53 | #2 |
| Trojaneralarm! Hi, hier beginnt fast jede Hilfestellung nach einem HJT-Log.
__________________Poste bitte ein Log hier herein. PP |
27.08.2006, 14:16 | #3 |
| Trojaneralarm! Ok dann mal hier der Logfile:
__________________Logfile of HijackThis v1.99.1 Scan saved at 15:14:34, on 27.08.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe C:\Programme\Norton Internet Security\ISSVC.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\Trojanersoftware\Ewido\guard.exe C:\Programme\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\system32\nvsvc32.exe c:\programme\odcb\ohttpd.exe C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\SOUNDMAN.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe C:\Programme\Trojanersoftware\Ewido\ewido.exe C:\PROGRA~1\MOZILL~1\FIREFOX.EXE C:\Programme\Eumex 504PC USB\Capictrl.exe C:\Programme\Microsoft Office\Office\FINDFAST.EXE C:\Programme\Scroll-In-Mouse V2.0\Scroll.exe C:\Programme\Trojanersoftware\RegFreeze\regfreeze.exe C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\system32\wuauclt.exe C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\kernel.exe C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\sc_watch.exe C:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis2\PROFIL~1.EXE C:\PROGRA~1\ICQ\ICQ.exe C:\Programme\Mozilla Firefox\firefox.exe C:\Programme\Trojanersoftware\HijackThis.exe C:\Programme\Messenger\msmsgs.exe O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [PtiuPbmd] Rundll32.exe ptipbm.dll,SetWriteBack O4 - HKLM\..\Run: [EPSON Stylus Photo R200 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S4I0H2.EXE /P30 "EPSON Stylus Photo R200 Series" /O6 "USB001" /M "Stylus Photo R200" O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [routcnf] C:\Programme\Eumex 504PC USB\routcnf.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [seekmo] "c:\programme\seekmo\seekmo.exe" O4 - HKLM\..\Run: [toolsecure] C:\WINDOWS\system32\toolsys16.exe O4 - HKLM\..\Run: [!ewido] "C:\Programme\Trojanersoftware\Ewido\ewido.exe" /minimized O4 - HKCU\..\Run: [toolsecure] C:\WINDOWS\system32\toolsys16.exe O4 - Startup: RegFreeze.lnk = C:\Programme\Trojanersoftware\RegFreeze\regfreeze.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: CAPIControl.lnk = ? O4 - Global Startup: Microsoft-Indexerstellung.lnk = C:\Programme\Microsoft Office\Office\FINDFAST.EXE O4 - Global Startup: Scroll-In-Mouse V2.0.lnk = C:\Programme\Scroll-In-Mouse V2.0\Scroll.exe O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: In vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\j2re1.4.2\bin\npjpi142.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\j2re1.4.2\bin\npjpi142.dll O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{DCF43DAE-CC20-4D1A-95DB-A88A9E442E63}: NameServer = 217.237.149.225 217.237.151.115 O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe O23 - Service: ewido anti-spyware 4.0 guard - Anti-Malware Development a.s. - C:\Programme\Trojanersoftware\Ewido\guard.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Programme\Norton Internet Security\ISSVC.exe O23 - Service: Macromedia Licensing Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: MySql - Unknown owner - E:/Temp/xampp/mysql/bin/mysqld-nt.exe (file missing) O23 - Service: Norton AntiVirus Auto-Protect-Dienst (navapsvc) - Symantec Corporation - C:\Programme\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: OmniHTTPd Professional (OmniHTTPd) - Unknown owner - c:\programme\odcb\ohttpd.exe O23 - Service: SAVScan - Symantec Corporation - C:\Programme\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe Ich kann damit überhauptnix anfangen muss ich sagen! |
27.08.2006, 14:58 | #4 |
| Trojaneralarm! Adware hat mir eben das ausgespuckt: Ad-Aware SE Build 1.06r1 Logfile Created on:Sonntag, 27. August 2006 15:19:49 Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R120 25.08.2006 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» MRU List(TAC index:0):11 total references Win32.Trojan.Downloader(TAC index:10):4 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects 27.08.2006 15:19:49 - Scan started. (Full System Scan) MRU List Object Recognized! Location: : C:\Dokumente und Einstellungen\Jens\recent Description : list of recently opened documents MRU List Object Recognized! Location: : S-1-5-21-1547161642-616249376-839522115-1008\software\macromedia\dreamweaver 6\recent file list Description : list of recently used files in macromedia dreamweaver MRU List Object Recognized! Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct3d MRU List Object Recognized! Location: : software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct X MRU List Object Recognized! Location: : software\microsoft\directdraw\mostrecentapplication Description : most recent application to use microsoft directdraw MRU List Object Recognized! Location: : S-1-5-21-1547161642-616249376-839522115-1008\software\microsoft\mediaplayer\preferences Description : last playlist index loaded in microsoft windows media player MRU List Object Recognized! Location: : S-1-5-21-1547161642-616249376-839522115-1008\software\microsoft\mediaplayer\preferences Description : last playlist loaded in microsoft windows media player MRU List Object Recognized! Location: : S-1-5-21-1547161642-616249376-839522115-1008\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru Description : list of recent programs opened MRU List Object Recognized! Location: : S-1-5-21-1547161642-616249376-839522115-1008\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru Description : list of recently saved files, stored according to file extension MRU List Object Recognized! Location: : S-1-5-21-1547161642-616249376-839522115-1008\software\microsoft\windows\currentversion\explorer\recentdocs Description : list of recent documents opened MRU List Object Recognized! Location: : S-1-5-21-1547161642-616249376-839522115-1008\software\microsoft\windows media\wmsdk\general Description : windows media sdk Listing running processes »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» #:1 [smss.exe] FilePath : \SystemRoot\System32\ ProcessID : 480 ThreadCreationTime : 27.08.2006 13:08:34 BasePriority : Normal #:2 [csrss.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 536 ThreadCreationTime : 27.08.2006 13:08:37 BasePriority : Normal #:3 [winlogon.exe] FilePath : \??\C:\WINDOWS\system32\ ProcessID : 560 ThreadCreationTime : 27.08.2006 13:08:37 BasePriority : High #:4 [services.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 608 ThreadCreationTime : 27.08.2006 13:08:38 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Betriebssystem Microsoft® Windows® CompanyName : Microsoft Corporation FileDescription : Anwendung für Dienste und Controller InternalName : services.exe LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten. OriginalFilename : services.exe #:5 [lsass.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 620 ThreadCreationTime : 27.08.2006 13:08:38 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : LSA Shell (Export Version) InternalName : lsass.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : lsass.exe #:6 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 788 ThreadCreationTime : 27.08.2006 13:08:38 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:7 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 852 ThreadCreationTime : 27.08.2006 13:08:38 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:8 [svchost.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 892 ThreadCreationTime : 27.08.2006 13:08:38 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:9 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 948 ThreadCreationTime : 27.08.2006 13:08:38 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:10 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 976 ThreadCreationTime : 27.08.2006 13:08:39 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:11 [ccproxy.exe] FilePath : C:\Programme\Gemeinsame Dateien\Symantec Shared\ ProcessID : 1008 ThreadCreationTime : 27.08.2006 13:08:39 BasePriority : Normal FileVersion : 103.0.7.2 ProductVersion : 103.0.7.2 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Network Proxy Service InternalName : ccProxy LegalCopyright : Copyright (c) 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccProxy.exe #:12 [ccsetmgr.exe] FilePath : C:\Programme\Gemeinsame Dateien\Symantec Shared\ ProcessID : 1024 ThreadCreationTime : 27.08.2006 13:08:39 BasePriority : Normal FileVersion : 103.0.7.2 ProductVersion : 103.0.7.2 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Settings Manager Service InternalName : ccSetMgr LegalCopyright : Copyright (c) 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccSetMgr.exe #:13 [issvc.exe] FilePath : C:\Programme\Norton Internet Security\ ProcessID : 1080 ThreadCreationTime : 27.08.2006 13:08:39 BasePriority : Normal FileVersion : 8.0.5.14 ProductVersion : 8.0 ProductName : Norton Internet Security CompanyName : Symantec Corporation FileDescription : IS Service InternalName : ISSVC.exe LegalCopyright : Copyright (c) 2004 Symantec Corporation OriginalFilename : ISSVC.exe #:14 [sndsrvc.exe] FilePath : C:\Programme\Gemeinsame Dateien\Symantec Shared\ ProcessID : 1100 ThreadCreationTime : 27.08.2006 13:08:39 BasePriority : Normal FileVersion : 5.5.1.6 ProductVersion : 5.5 ProductName : Symantec Security Drivers CompanyName : Symantec Corporation FileDescription : Network Driver Service InternalName : SndSrvc LegalCopyright : Copyright 2002, 2003, 2004 Symantec Corporation OriginalFilename : SndSrvc.exe #:15 [spbbcsvc.exe] FilePath : C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\ ProcessID : 1124 ThreadCreationTime : 27.08.2006 13:08:40 BasePriority : Normal FileVersion : 1,0,1,47 ProductVersion : 1,0,1,47 ProductName : SPBBC CompanyName : Symantec Corporation FileDescription : SPBBC Service InternalName : SPBBCSvc LegalCopyright : Copyright (c) 2004 Symantec Corporation. All rights reserved. OriginalFilename : SPBBCSvc.exe #:16 [ccevtmgr.exe] FilePath : C:\Programme\Gemeinsame Dateien\Symantec Shared\ ProcessID : 1168 ThreadCreationTime : 27.08.2006 13:08:41 BasePriority : Normal FileVersion : 103.0.7.2 ProductVersion : 103.0.7.2 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec Event Manager Service InternalName : ccEvtMgr LegalCopyright : Copyright (c) 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccEvtMgr.exe #:17 [spoolsv.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1456 ThreadCreationTime : 27.08.2006 13:08:44 BasePriority : Normal FileVersion : 5.1.2600.2696 (xpsp_sp2_gdr.050610-1519) ProductVersion : 5.1.2600.2696 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Spooler SubSystem App InternalName : spoolsv.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : spoolsv.exe #:18 [guard.exe] FilePath : C:\Programme\Trojanersoftware\Ewido\ ProcessID : 1576 ThreadCreationTime : 27.08.2006 13:08:44 BasePriority : Normal FileVersion : 4, 0, 0, 172 ProductVersion : 4, 0, 0, 172 ProductName : ewido anti-spyware CompanyName : Anti-Malware Development a.s. FileDescription : ewido anti-spyware guard InternalName : ewido anti-spywareguard LegalCopyright : Copyright © 2005 Anti-Malware Development a.s. OriginalFilename : guard.exe #:19 [navapsvc.exe] FilePath : C:\Programme\Norton Internet Security\Norton AntiVirus\ ProcessID : 1612 ThreadCreationTime : 27.08.2006 13:08:44 BasePriority : Normal FileVersion : 11.0.16.2 ProductVersion : 11.0.16 ProductName : Norton AntiVirus CompanyName : Symantec Corporation FileDescription : Norton AntiVirus Auto-Protect Service InternalName : NAVAPSVC LegalCopyright : Norton AntiVirus 2005 for Windows 98/ME/2000/XP Copyright © 2004 Symantec Corporation. All rights reserved. OriginalFilename : NAVAPSVC.EXE #:20 [nvsvc32.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1664 ThreadCreationTime : 27.08.2006 13:08:44 BasePriority : Normal FileVersion : 6.14.10.6672 ProductVersion : 6.14.10.6672 ProductName : NVIDIA Driver Helper Service, Version 66.72 CompanyName : NVIDIA Corporation FileDescription : NVIDIA Driver Helper Service, Version 66.72 InternalName : NVSVC LegalCopyright : (C) NVIDIA Corporation. All rights reserved. OriginalFilename : nvsvc32.exe #:21 [ohttpd.exe] FilePath : c:\programme\odcb\ ProcessID : 1684 ThreadCreationTime : 27.08.2006 13:08:44 BasePriority : Normal #:22 [starwindservice.exe] FilePath : C:\Programme\Alcohol Soft\Alcohol 120\StarWind\ ProcessID : 1760 ThreadCreationTime : 27.08.2006 13:08:45 BasePriority : Normal FileVersion : 2.6.1 Build 0x20050401 ProductVersion : 2.6.1 Build 0x20050401 ProductName : StarWind CompanyName : Rocket Division Software FileDescription : StarWind iSCSI Target (Alcohol Edition) InternalName : StarWind LegalCopyright : Copyright (c) Rocket Division Software 2003-2005. All rights reserved. OriginalFilename : StarWind #:23 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1772 ThreadCreationTime : 27.08.2006 13:08:45 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Generic Host Process for Win32 Services InternalName : svchost.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : svchost.exe #:24 [symlcsvc.exe] FilePath : C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\ ProcessID : 1796 ThreadCreationTime : 27.08.2006 13:08:45 BasePriority : Normal FileVersion : 1, 8, 54, 478 ProductVersion : 1, 8, 54, 478 ProductName : Symantec Core Component CompanyName : Symantec Corporation FileDescription : Symantec Core Component InternalName : symlcsvc LegalCopyright : Copyright (C) 2003 OriginalFilename : symlcsvc.exe #:25 [wdfmgr.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1876 ThreadCreationTime : 27.08.2006 13:08:47 BasePriority : Normal FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act) ProductVersion : 5.2.3790.1230 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Windows User Mode Driver Manager InternalName : WdfMgr LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : WdfMgr.exe #:26 [alg.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 1660 ThreadCreationTime : 27.08.2006 13:09:02 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : Application Layer Gateway Service InternalName : ALG.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : ALG.exe #:27 [explorer.exe] FilePath : C:\WINDOWS\ ProcessID : 2160 ThreadCreationTime : 27.08.2006 13:09:04 BasePriority : Normal FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 6.00.2900.2180 ProductName : Betriebssystem Microsoft® Windows® CompanyName : Microsoft Corporation FileDescription : Windows Explorer InternalName : explorer LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten. OriginalFilename : EXPLORER.EXE #:28 [soundman.exe] FilePath : C:\WINDOWS\ ProcessID : 2348 ThreadCreationTime : 27.08.2006 13:09:10 BasePriority : Normal FileVersion : 5.1.0.24 ProductVersion : 5.1.0.24 ProductName : Realtek Sound Manager CompanyName : Realtek Semiconductor Corp. FileDescription : Realtek Sound Manager InternalName : ALSMTray LegalCopyright : Copyright (c) 2001-2003 Realtek Semiconductor Corp. OriginalFilename : ALSMTray.exe Comments : Realtek AC97 Audio Sound Manager #:29 [rundll32.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 2416 ThreadCreationTime : 27.08.2006 13:09:11 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Betriebssystem Microsoft® Windows® CompanyName : Microsoft Corporation FileDescription : Eine DLL-Datei als Anwendung ausführen InternalName : rundll LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten. OriginalFilename : RUNDLL.EXE #:30 [e_s4i0h2.exe] FilePath : C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\ ProcessID : 2464 ThreadCreationTime : 27.08.2006 13:09:12 BasePriority : Normal FileVersion : 3.00 ProductVersion : 3.00 ProductName : EPSON Status Monitor 3 CompanyName : SEIKO EPSON CORPORATION FileDescription : EPSON Status Monitor 3 InternalName : E_S4I0H2 LegalCopyright : Copyright (C) SEIKO EPSON CORP. 2003 OriginalFilename : E_S4I0H2.EXE #:31 [ccapp.exe] FilePath : C:\Programme\Gemeinsame Dateien\Symantec Shared\ ProcessID : 2492 ThreadCreationTime : 27.08.2006 13:09:14 BasePriority : Normal FileVersion : 103.0.7.2 ProductVersion : 103.0.7.2 ProductName : Client and Host Security Platform CompanyName : Symantec Corporation FileDescription : Symantec User Session InternalName : ccApp LegalCopyright : Copyright (c) 2000-2004 Symantec Corporation. All rights reserved. OriginalFilename : ccApp.exe #:32 [ewido.exe] FilePath : C:\Programme\Trojanersoftware\Ewido\ ProcessID : 2596 ThreadCreationTime : 27.08.2006 13:09:17 BasePriority : Normal FileVersion : 4, 0, 0, 172 ProductVersion : 4, 0, 0, 172 ProductName : ewido anti-spyware CompanyName : Anti-Malware Development a.s. FileDescription : ewido anti-spyware InternalName : ewido anti-spyware LegalCopyright : Copyright © 2005 Anti-Malware Development a.s. OriginalFilename : ewido.exe |
27.08.2006, 14:59 | #5 |
| Trojaneralarm! Und das: #:33 [firefox.exe] FilePath : C:\PROGRA~1\MOZILL~1\ ProcessID : 2892 ThreadCreationTime : 27.08.2006 13:09:19 BasePriority : Normal #:34 [capictrl.exe] FilePath : C:\Programme\Eumex 504PC USB\ ProcessID : 2904 ThreadCreationTime : 27.08.2006 13:09:19 BasePriority : Normal FileVersion : 2.14 ProductVersion : 2.0.0.2137 ProductName : CAPIControl Application CompanyName : DeTeWe AG & Co. FileDescription : CAPIControl InternalName : CAPIControl LegalCopyright : Copyright (C) 1999-2004 DeTeWe AG & Co. OriginalFilename : CAPIControl.EXE Comments : RPH/MS/RPH/CTK/DETEWE #:35 [findfast.exe] FilePath : C:\Programme\Microsoft Office\Office\ ProcessID : 2920 ThreadCreationTime : 27.08.2006 13:09:19 BasePriority : Normal FileVersion : 8.0 ProductVersion : 8.0 ProductName : Microsoft® Indexerstellung CompanyName : Microsoft Corporation FileDescription : Microsoft Office-Indexerstellung InternalName : FINDFAST LegalCopyright : Copyright © Microsoft Corp. 1995-1997 OriginalFilename : FINDFAST.EXE #:36 [scroll.exe] FilePath : C:\Programme\Scroll-In-Mouse V2.0\ ProcessID : 2928 ThreadCreationTime : 27.08.2006 13:09:20 BasePriority : Normal FileVersion : 2, 0, 0, 1 ProductVersion : 2, 0, 0, 1 ProductName : AYScroll CompanyName : A. C. FileDescription : AYScroll InternalName : AYScroll LegalCopyright : Copyright (c) 1997-98 OriginalFilename : AYScroll.exe #:37 [regfreeze.exe] FilePath : C:\Programme\Trojanersoftware\RegFreeze\ ProcessID : 2980 ThreadCreationTime : 27.08.2006 13:09:23 BasePriority : Normal FileVersion : 5.5.1.320 ProductVersion : 5.5.1.0 ProductName : RegFreeze CompanyName : ActualResearch.com FileDescription : Anti-spyware and registry monitoring tool. InternalName : regfreeze.exe LegalCopyright : © ActualResearch.com 2001-2006 OriginalFilename : regfreeze.exe #:38 [kernel.exe] FilePath : C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\ ProcessID : 3848 ThreadCreationTime : 27.08.2006 13:11:40 BasePriority : Normal FileVersion : 1.43.0.4 ProductVersion : xx.xx.xx.xxxx ProductName : T-Online Basissoftware CompanyName : T-Online FileDescription : T-Online StartCenter 5.0 InternalName : T-Online Software LegalCopyright : Copyright 2001 OriginalFilename : kernel.exe #:39 [sc_watch.exe] FilePath : C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\ ProcessID : 3864 ThreadCreationTime : 27.08.2006 13:11:52 BasePriority : Normal #:40 [profil~1.exe] FilePath : C:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis2\ ProcessID : 3928 ThreadCreationTime : 27.08.2006 13:12:04 BasePriority : Normal FileVersion : 1.44.00.0002 ProductVersion : 5.00.71.0000 ProductName : T-Online Basissoftware CompanyName : T-Online FileDescription : T-Online Profilverwaltung InternalName : Profilemgr LegalCopyright : Copyright 2001 OriginalFilename : profilemgr.exe #:41 [icq.exe] FilePath : C:\PROGRA~1\ICQ\ ProcessID : 2120 ThreadCreationTime : 27.08.2006 13:12:38 BasePriority : Normal FileVersion : 5,5,6,3916 ProductVersion : 2003b ProductName : ICQ CompanyName : ICQ Inc. FileDescription : ICQ InternalName : ICQ LegalCopyright : Copyright © 1996 - 2001 ICQ Inc. All Rights Reserved. OriginalFilename : ICQ.exe Comments : ICQ V2003b #:42 [wmiprvse.exe] FilePath : C:\WINDOWS\system32\wbem\ ProcessID : 2876 ThreadCreationTime : 27.08.2006 13:12:58 BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating System CompanyName : Microsoft Corporation FileDescription : WMI InternalName : Wmiprvse.exe LegalCopyright : © Microsoft Corporation. All rights reserved. OriginalFilename : Wmiprvse.exe #:43 [firefox.exe] FilePath : C:\Programme\Mozilla Firefox\ ProcessID : 2568 ThreadCreationTime : 27.08.2006 13:13:02 BasePriority : Normal #:44 [ad-aware.exe] FilePath : C:\Programme\Trojanersoftware\Ad-Aware SE Personal\ ProcessID : 1868 ThreadCreationTime : 27.08.2006 13:19:36 BasePriority : Normal FileVersion : 6.2.0.236 ProductVersion : SE 106 ProductName : Lavasoft Ad-Aware SE CompanyName : Lavasoft Sweden FileDescription : Ad-Aware SE Core application InternalName : Ad-Aware.exe LegalCopyright : Copyright © Lavasoft AB Sweden OriginalFilename : Ad-Aware.exe Comments : All Rights Reserved Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 11 Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Win32.Trojan.Downloader Object Recognized! Type : Regkey Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\active setup\installed components\{9b71d88c-c598-4935-c5d1-43aa4db90836} Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 1 Objects found so far: 12 Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 12 Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 12 Deep scanning and examining files (C »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 12 Deep scanning and examining files (E »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Disk Scan Result for E:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 12 Scanning Hosts file...... Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts". »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Hosts file scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» 1 entries scanned. New critical objects:0 Objects found so far: 12 Performing conditional scans... »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Win32.Trojan.Downloader Object Recognized! Type : Regkey Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_CURRENT_USER Object : software\wget Win32.Trojan.Downloader Object Recognized! Type : RegValue Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_CURRENT_USER Object : software\wget Value : plg1 Win32.Trojan.Downloader Object Recognized! Type : Regkey Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\wget Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 3 Objects found so far: 15 15:49:26 Scan Complete Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:29:36.219 Objects scanned:258607 Objects identified:4 Objects ignored:0 New critical objects:4 |
28.08.2006, 19:16 | #6 |
| Trojaneralarm! Kann man mir denn nicht helfen? |
28.08.2006, 19:39 | #7 | |
| Trojaneralarm!Zitat:
Sollte sich die Panikreaktion lediglich auf eine Virenscannermeldung beziehen, bitte Fundort und Name nennen, sowie versuchen die Datei alternativ zu scannen (siehe meine signatur). Gruß Marc
__________________ When you contact tech support, a lot of people feel like they're either talking to an idiot or being treated like one. |
29.08.2006, 06:30 | #9 |
| Trojaneralarm! Was mich dazu veranlaßt hat..hmm, irgendeine Anleitung wie man den Trojaner loswird denk ich mal, hab davon doch keinen Plan. Hier die Ergebnisse: Virus Total meint Your file "toolsys16.exe" is queued in position: 7. Estimated start time is between 57 and 85 seconds. STATUS: QUEUED VirusScan sagt Datei: toolsys16.exe Auslastung: 0% 100% Status: OK (Anmerkung: diese Datei wurde bereits vorher gescannt. Die Scanergebnisse werden daher nicht in der Datenbank gespeichert.) Entdeckte Packprogramme: - AntiVir Keine Viren gefunden ArcaVir Keine Viren gefunden Avast Keine Viren gefunden AVG Antivirus Keine Viren gefunden BitDefender Keine Viren gefunden ClamAV Keine Viren gefunden Dr.Web Keine Viren gefunden F-Prot Antivirus Keine Viren gefunden Fortinet Keine Viren gefunden Kaspersky Anti-Virus Keine Viren gefunden NOD32 Keine Viren gefunden Norman Virus Control Keine Viren gefunden UNA Keine Viren gefunden VirusBuster Keine Viren gefunden VBA32 Keine Viren gefunden |
30.08.2006, 01:33 | #10 |
| Trojaneralarm! hallo erst mal.ich hab seid gestern abend einen trojaner namens TR./Drop.VB...dieser läßt sich ned finden unter der angegeben datei Hb Tools/HBTV/HBTV.exe!!!!!!!!!!!!!!!!! ich habe mehrere durchläufe gemacht mit adaware,u bin auf suche gegangen beim startsymbol u habe alles durchsuchen lassen ...doch mein pc fand die oben genannte datei ned... ich hatte mir ja alles gründlich hier durchgelesen...auch ein neustart brachte nix...jedes mal wenn, ich was anklicke ob systemsteuerung oder sonst wat meldet sich dat blöde pferd ...ich würde gern wissen was i tun kann...auch die suche bei verschiedenen seiten brachte mich ned weiter in bezug ufftz den trojaner keiner fand den wenn ich ihn als suche eingab um mehr über den heraus zu finden... lg u danke für eure hilfe... |
31.08.2006, 08:28 | #11 |
| Trojaneralarm! Und nun weiss niemand mehr Rat? |
31.08.2006, 10:31 | #12 | |
| Trojaneralarm!Zitat:
Gruß Marc
__________________ When you contact tech support, a lot of people feel like they're either talking to an idiot or being treated like one. |
Themen zu Trojaneralarm! |
adware, ahnung, anleitung, antispy, board, ccleaner, helfen, helft, hoffe, mehrere, microsoft, namens, problem, programme, programmen, rechner, sauber, scanne, scannen, software, system, troja, trojaner, trojaneralarm, version, windows, wirklich |