![]() |
|
Plagegeister aller Art und deren Bekämpfung: Winfixer 2005 Problem !Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #4 |
![]() | ![]() Winfixer 2005 Problem ! Sry falsche HJT Log, hab ja beim windowsstart paar einträge im Taskmanager beendet!! Hier nochmals die Aktuelle! Logfile of HijackThis v1.99.1 Scan saved at 10:53:30, on 27.11.2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: E:\WINDOWS\System32\smss.exe E:\WINDOWS\system32\winlogon.exe E:\WINDOWS\system32\services.exe E:\WINDOWS\system32\lsass.exe E:\WINDOWS\system32\svchost.exe E:\WINDOWS\System32\svchost.exe E:\WINDOWS\system32\spoolsv.exe E:\WINDOWS\Explorer.EXE C:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe E:\WINDOWS\system32\nvsvc32.exe E:\WINDOWS\system32\svchost.exe E:\WINDOWS\system32\isnotify.exe E:\WINDOWS\system32\RUNDLL32.EXE C:\Programme\Grisoft\AVG Anti-Spyware 7.5\avgas.exe E:\WINDOWS\system32\ctfmon.exe E:\Dokumente und Einstellungen\Soldier\Desktop\Downloads\HJT.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: (no name) - {A6DC560B-9719-4CFB-A31A-8A660D89EFCD} - E:\WINDOWS\system32\khfdd.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - E:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: (no name) - {052b12f7-86fa-4921-8482-26c42316b522} - (no file) O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [LXCCCATS] rundll32 E:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXCCtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbar...tml?p=ZNfox000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Programme\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Programme\Java\jre1.5.0_07\bin\ssv.dll O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - E:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\Programme\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - E:\Programme\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programme\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programme\Messenger\msmsgs.exe (file missing) O20 - AppInit_DLLs: "E:\PROGRA~1\Google\Google Desktop Search\GoogleDesktopNetwork3.dll" O20 - Winlogon Notify: khfdd - E:\WINDOWS\system32\khfdd.dll O20 - Winlogon Notify: wincit32 - E:\WINDOWS\SYSTEM32\wincit32.dll O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe O23 - Service: lxcc_device - Lexmark International, Inc. - E:\WINDOWS\system32\lxcccoms.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe So hab die Datei khfdd.dll gefunden und mal bei Virustotal hochgeladen Hier die log davon! Antivirus Version Update Result AntiVir 7.2.0.46 11.27.2006 TR/Vundo.Gen Authentium 4.93.8 11.24.2006 no virus found Avast 4.7.892.0 11.27.2006 no virus found AVG 386 11.27.2006 no virus found BitDefender 7.2 11.27.2006 no virus found CAT-QuickHeal 8.00 11.25.2006 no virus found ClamAV devel-20060426 11.27.2006 no virus found DrWeb 4.33 11.27.2006 no virus found eSafe 7.0.14.0 11.26.2006 no virus found eTrust-InoculateIT 23.73.68 11.27.2006 no virus found eTrust-Vet 30.3.3217 11.27.2006 no virus found Ewido 4.0 11.26.2006 no virus found Fortinet 2.82.0.0 11.27.2006 suspicious F-Prot 3.16f 11.24.2006 no virus found F-Prot4 4.2.1.29 11.24.2006 no virus found Ikarus 0.2.65.0 11.27.2006 no virus found Kaspersky 4.0.2.24 11.27.2006 no virus found McAfee 4904 11.24.2006 no virus found Microsoft 1.1804 11.27.2006 no virus found NOD32v2 1884 11.27.2006 no virus found Norman 5.80.02 11.27.2006 W32/Vundo.gen3 Panda 9.0.0.4 11.26.2006 Suspicious file Prevx1 V2 11.27.2006 no virus found Sophos 4.11.0 11.16.2006 no virus found TheHacker 6.0.3.124 11.27.2006 no virus found UNA 1.83 11.24.2006 no virus found VBA32 3.11.1 11.26.2006 no virus found Geändert von Lufina (27.11.2006 um 11:33 Uhr) |
Themen zu Winfixer 2005 Problem ! |
appinit_dlls, desktop, drivers, einstellungen, explorer, firefox, google, hijack, hijackthis, internet, internet explorer, log, mozilla, mozilla firefox, nvidia, popup, problem, programme, rundll, schnelle hilfe, security, software, system, taskmanager, temp, urlsearchhook, windows, windows xp |