![]() |
|
Log-Analyse und Auswertung: TR/Vundo.Gen löschen???Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() TR/Vundo.Gen löschen??? Hallo cih bin neu hier und bräuchte Hilfe beim Löschen von TR/Vundo.Gen. Hab mir jetzt HijackThis runtergeladen.... (ehrlich gesagt hab ich so gut wie keine ahnung und bin auf Hilfe angewiese) Hier der Log Logfile of HijackThis v1.99.1 Scan saved at 16:00, on 06-12-05 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe C:\Programme\QuickTime\qttask.exe C:\Programme\Picasa2\PicasaMediaDetector.exe C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe C:\Programme\AntiVir PersonalEdition Classic\sched.exe C:\Programme\AntiVir PersonalEdition Classic\avguard.exe C:\Programme\Securepoint Personal Firewall\driver\spfirewallsvc.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\ISW\alice\signup\alicecnn.exe C:\Programme\Internet Explorer\IEXPLORE.EXE C:\Programme\Internet Explorer\IEXPLORE.EXE C:\Programme\Internet Explorer\IEXPLORE.EXE C:\Programme\WinRAR\WinRAR.exe C:\DOKUME~1\ETM\LOKALE~1\Temp\Rar$EX00.721\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://google.icq.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.alice-dsl.de R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.alice-dsl.de R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O2 - BHO: (no name) - {20D57A66-F7DF-467d-907B-9B7F4A118AB7} - (no file) O2 - BHO: CIEIntegrator Object - {2178F3FB-2560-458F-BDEE-631E2FE0DFE4} - C:\Programme\WinAntiVirus Pro 2006\winpgi.dll O2 - BHO: (no name) - {46A4E9D9-B30E-452A-8157-DBBEC8573B03} - C:\Programme\VSAdd-in\VSAdd-in.dll O2 - BHO: IEFW Object - {B5141620-C2B2-4D95-9F0F-134D99C87AB0} - C:\Programme\WinAntiVirus Pro 2006\IEFWBHO.dll O2 - BHO: MFCOptimizeClass Object - {C25FA7CE-23EA-4271-A66D-06C4D5C22F78} - C:\WINDOWS\System32\opnnn.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programme\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Programme\MyWay\myBar\1.bin\MYBAR.DLL (file missing) O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O3 - Toolbar: Freeprod Toolbar - {77FBF9B8-1D37-4FF2-9CED-192D8E3ABA6F} - C:\Programme\Freeprod Toolbar\freeprod.dll (file missing) O3 - Toolbar: &VSAdd-in - {74DD705D-6834-439C-A735-A6DBE2677452} - C:\Programme\VSAdd-in\VSAdd-in.dll O4 - HKLM\..\Run: [LaunchApp] REM Alaunch O4 - HKLM\..\Run: [IgfxTray] REM C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] REM C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [SoundMan] REM SOUNDMAN.EXE O4 - HKLM\..\Run: [AGRSMMSG] REM AGRSMMSG.exe O4 - HKLM\..\Run: [Apoint] REM C:\Programme\Apoint2K\Apoint.exe O4 - HKLM\..\Run: [LManager] REM C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE O4 - HKLM\..\Run: [CloneCDElbyCDFL] REM "C:\Programme\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL O4 - HKLM\..\Run: [OpenCom 40dsl] REM E:\SETUP.EXE O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Microsoft Auto Protect] task.exe O4 - HKLM\..\Run: [Local Security Authority Service] C:\WINDOWS\System32\lssas.exe O4 - HKLM\..\Run: [Generic Host Process9 System Backup] scvhost9.exe O4 - HKLM\..\Run: [Anti-Virus Update Scheduler] C:\cs.exe O4 - HKLM\..\Run: [kkmc] C:\WINDOWS\System32\kkmc.exe O4 - HKLM\..\Run: [MS Windows System Alert] REM MSWSA32.exe O4 - HKLM\..\Run: [Securepoint Personal Firewall] REM "C:\Programme\Securepoint Personal Firewall\bin\sppfw.exe" O4 - HKLM\..\Run: [Mi7sft sdce] MNSQ.exe O4 - HKLM\..\Run: [Winsock2 driver] XTEHMJJVO.EXE O4 - HKLM\..\Run: [NAMED] C:\WINDOWS\System32\NAMED.exe O4 - HKLM\..\Run: [Secure Network Interface] REM C:\WINDOWS\System32\noeezseg.exe O4 - HKLM\..\Run: [HTTP] REM C:\WINDOWS\System32\HTTP.exe O4 - HKLM\..\Run: [Microsoft MachineUpdatese] tempes.exe O4 - HKLM\..\Run: [Microsoft (R) Windows Update Service] C:\WINDOWS\update\wuauclt.exe O4 - HKLM\..\Run: [MS Domain Name Server Deamon] MSDNSD32.exe O4 - HKLM\..\Run: [Microsoft Machine Script] iexplorersis.exe O4 - HKLM\..\Run: [Windows Security Update] winupdat.exe O4 - HKLM\..\Run: [Microsoft UpdatesSecurity] msnmsgrese.exe O4 - HKLM\..\Run: [WOOZ] C:\WINDOWS\System32\dmserver.exe O4 - HKLM\..\Run: [Win32 Kernel Update] C:\WINDOWS\System32\win32update.exe O4 - HKLM\..\Run: [Windows Core Kernel Update] C:\WINDOWS\System32\win32bootcfg.exe O4 - HKLM\..\Run: [iTunesHelper] REM "C:\Programme\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ICQ Lite] REM "C:\Programme\ICQLite\ICQLite.exe" -minimize O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programme\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [WinAntiVirusPro2006] C:\Programme\WinAntiVirus Pro 2006\winav.exe /min O4 - HKLM\..\RunServices: [Microsoft Auto Protect] task.exe O4 - HKLM\..\RunServices: [Generic Host Process9 System Backup] scvhost9.exe O4 - HKLM\..\RunServices: [MS Windows System Alert] MSWSA32.exe O4 - HKLM\..\RunServices: [services] c:\windows\system32\Microsoft\help\start.bat O4 - HKLM\..\RunServices: [Mi7sft sdce] MNSQ.exe O4 - HKLM\..\RunServices: [System Service] b4db0yz.exe O4 - HKLM\..\RunServices: [Microsoft MachineUpdatese] tempes.exe O4 - HKLM\..\RunServices: [MS Domain Name Server Deamon] MSDNSD32.exe O4 - HKLM\..\RunServices: [Microsoft Machine Script] iexplorersis.exe O4 - HKLM\..\RunServices: [Windows Security Update] winupdat.exe O4 - HKLM\..\RunServices: [Microsoft UpdatesSecurity] msnmsgrese.exe O4 - HKCU\..\Run: [MSMSGS] REM "C:\Programme\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [Microsoft Auto Protect] task.exe O4 - HKCU\..\Run: [Generic Host Process9 System Backup] scvhost9.exe O4 - HKCU\..\Run: [MS Windows System Alert] REM MSWSA32.exe O4 - HKCU\..\Run: [System] REM sysinfo.exe O4 - HKCU\..\Run: [MS Domain Name Server Deamon] MSDNSD32.exe O4 - HKCU\..\Run: [Esat] "C:\Programme\tost\bwto.exe" -vt yazr O4 - HKCU\..\Run: [iwmz] C:\stub_113_4_0_4_0.exe O4 - HKCU\..\Run: [SysProtect Free] "C:\Programme\SysProtect Free\USYP.exe" /min O4 - Startup: OpenOffice.org 1.1.0.lnk = C:\Programme\OpenOffice.org1.1.0\program\quickstart.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: Easy-WebPrint Drucken - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint Schnelldruck - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint Vorschau - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint Zu Druckliste hinzufügen - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O15 - Trusted Zone: http://locator.cdn.imageservr.com O15 - Trusted Zone: *.media-motor.net O15 - Trusted Zone: *.mmohsix.com O15 - Trusted Zone: http://scanner.sysprotect.com O15 - Trusted Zone: http://click.getmirar.com (HKLM) O15 - Trusted Zone: http://click.mirarsearch.com (HKLM) O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM) O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM) O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone O16 - DPF: {11111111-1111-1111-1111-111111111732} - file://c:\progra~1\pl.exe O16 - DPF: {2D2BEE6E-3C9A-4D58-B9EC-458EDB28D0F6} - http://drivecleaner.com/.freeware/installdrivecleanerstart.cab O16 - DPF: {5526B4C6-63D6-41A1-9783-0FABF529859A} - http://cabs.media-motor.net/cabs/joysavsht.cab O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/11282ec7b06bc52f8f05/netzip/RdxIE601_de.cab O16 - DPF: {59136DB4-6CA3-4B40-8F2F-BBF84B6F1E91} (Attachment Upload Control) - https://stream.web.de/mail/activex/mail_upload_11213.cab O16 - DPF: {8A0DCBDB-6E20-489C-9041-C1E8A0352E75} - http://awbeta.net-nucleus.com/FIX/WinATS.cab O16 - DPF: {A1426AC5-8CE5-4A00-B71E-011D35709AC6} (Progetto1.int_ver34) - http://advnt01.com/dialer/int_ver34.CAB O16 - DPF: {F919FBD3-A96B-4679-AF26-F551439BB5FD} - http://locator1.cdn.imagesrvr.com/sites/sysprotect.com/scanner/pages/scanner/SysProtectScannerInstall.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{784AB383-54D0-465E-8310-24B8816393E1}: NameServer = 192.168.69.254 O17 - HKLM\System\CCS\Services\Tcpip\..\{DCD85AB7-A0E2-4E26-AA21-9205FADDF6AF}: NameServer = 213.191.92.86 213.191.74.18 O20 - Winlogon Notify: fanxctrl - fanxctrl.dll (file missing) O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: MS-DOS Emulation - C:\WINDOWS\system32\dnnu0159e.dll (file missing) O20 - Winlogon Notify: opnnn - C:\WINDOWS\System32\opnnn.dll O20 - Winlogon Notify: rqool - rqool.dll (file missing) O20 - Winlogon Notify: Shell Extensions - C:\WINDOWS\system32\dcauth.dll (file missing) O20 - Winlogon Notify: ShellCompatibility - C:\WINDOWS\system32\o0660ajsedo60.dll (file missing) O20 - Winlogon Notify: WRNotifier - WRLogonNTF.dll (file missing) O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: CTF Monitor Service (CTFMN) - Unknown owner - C:\WINDOWS\System32\ctfmsvc.exe (file missing) O23 - Service: Firewall service (FWSvc) - Unknown owner - C:\Programme\WinAntiVirus Pro 2006\FWSvc.exe (file missing) O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: ILT - Unknown owner - C:\WINDOWS\ilt.exe (file missing) O23 - Service: iPodService - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe O23 - Service: Microsoft HTTP Protocol - Unknown owner - C:\WINDOWS\mgsev.exe (file missing) O23 - Service: MsLX32 - Unknown owner - C:\WINDOWS\MsLX32.exe (file missing) O23 - Service: Network Browser (NBSystem) - Unknown owner - C:\WINDOWS\system32\nbsystem.exe (file missing) O23 - Service: Service Hosts (ServiceHost) - Unknown owner - C:\WINDOWS\shost.exe (file missing) O23 - Service: Securepoint Personal Firewall (spfirewallsvc) - Securepoint GmbH - C:\Programme\Securepoint Personal Firewall\driver\spfirewallsvc.exe O23 - Service: Windows Update Service (UpdateSvc) - Unknown owner - C:\WINDOWS\update\wuauclt.exe (file missing) O23 - Service: User Initialization (usrinit32) - Unknown owner - C:\WINDOWS\userinit.exe (file missing) O23 - Service: Win32 Kernel Update (Win32Kernel) - Unknown owner - C:\WINDOWS\win32host.exe (file missing) O23 - Service: Windows System Tray - Unknown owner - C:\WINDOWS\systay.exe (file missing) O23 - Service: Windows User Mode Drivers (WUMD) - Unknown owner - C:\WINDOWS\system32\wumd.exe (file missing) Vielen Dank schon mal |
Themen zu TR/Vundo.Gen löschen??? |
adobe, alert, antivir, antivirus, avg, avira, bho, browser, canon, computer, drivers, explorer, generic host, generic host process, hijack, hijackthis, icqtoolbar, internet, internet explorer, keine ahnung, löschen?, monitor, ms-dos, object, picasa, security, security update, server, software, system, temp, tr/vundo.gen, urlsearchhook, userinit.exe, windows, windows security, windows system, windows xp |