|
Log-Analyse und Auswertung: HilfeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
23.04.2007, 14:35 | #1 |
| Hilfe hi ich brauche eure hilfe bei mir wird dauernd gemeldet das ich irgend einen spywar am start habe den ich aber nihct entfernen kann habe es auch schon mit einigen programmen wie regecleaner oder spwarfigther versucht es hat aber nichts gebracht hier sind meine logs ich hoffe ihr könnt mir helfn danke bei den oben genannten programmen habe ich auch einige sachen entfernt um genau zu sein 68 spywars oder die trojaner dafür habe aber immer noch welche C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe c:\apps\Powercinema\Kernel\TV\CLCapSvc.exe c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe c:\APPS\HIDSERVICE\HIDSERVICE.exe C:\WINDOWS\system32\nvsvc32.exe C:\Apps\Softex\OmniPass\Omniserv.exe C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxWatch.exe C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe c:\apps\Powercinema\Kernel\TV\CLSched.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Programme\Video AX Object\bpmon.exe C:\Programme\Video AX Object\smmon.exe C:\Programme\Java\jre1.5.0_11\bin\jusched.exe C:\WINDOWS\RTHDCPL.EXE C:\apps\Powercinema\PCMService.exe C:\apps\ABoard\ABoard.exe C:\apps\ABoard\AOSD.exe C:\progra~1\softwin\bitdef~1\bdnagent.exe C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Programme\Logitech\Video\LogiTray.exe C:\Programme\D-Link\AirPlus G\AirGCFG.exe C:\Programme\iTunes\iTunesHelper.exe C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe C:\Programme\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Programme\iPod\bin\iPodService.exe C:\Programme\SPYWAREfighter\spfprc.exe C:\Programme\Logitech\Video\FxSvr2.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Mozilla Firefox\firefox.exe C:\Programme\RegCleaner\RegCleanr.exe C:\Programme\RegCleaner\RegCleanr.exe C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe C:\Programme\Softwin\BitDefender8\vsserv.exe c:\progra~1\softwin\bitdef~1\bdmcon.exe C:\Programme\ICQLite\ICQLite.exe C:\Programme\eMule\emule.exe C:\Programme\K-Lite Codec Pack\Media Player Classic\mplayerc.exe C:\WINDOWS\system32\divxsm.exe C:\Programme\K-Lite Codec Pack\Media Player Classic\mplayerc.exe C:\Programme\WinRAR\WinRAR.exe C:\Programme\WinRAR\WinRAR.exe C:\DOKUME~1\Emal\LOKALE~1\Temp\Rar$EX00.297\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://de.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://de.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://de.search.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://de.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=https=ftp=gopher=socks= R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: XTTBPos00 Class - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Programme\ICQToolbar\toolbaru.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Programme\Alcohol Toolbar\v3.1.0.0\Alcohol_Toolbar.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar2.dll O2 - BHO: (no name) - {D34F5D71-99E4-4D96-91CA-F4104F69B8AE} - C:\Programme\Video AX Object\bpvol.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Programme\Alcohol Toolbar\v3.1.0.0\Alcohol_Toolbar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar2.dll O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [AzMixerSel] C:\Programme\Realtek\InstallShield\AzMixerSel.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe O4 - HKLM\..\Run: [PCMService] "c:\apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe O4 - HKLM\..\Run: [BDNewsAgent] "c:\progra~1\softwin\bitdef~1\bdnagent.exe" O4 - HKLM\..\Run: [BDSwitchAgent] C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programme\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AOLDialer] C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programme\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programme\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [spywarefighterguard] C:\Programme\SPYWAREfighter\spftray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programme\Logitech\Video\ManifestEngine.exe boot O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\ger.htm O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programme\Yahoo!\Common\yinsthelper.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll O20 - Winlogon Notify: OPXPGina - C:\WINDOWS\ O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe O23 - Service: AVM IGD CTRL Service - Unknown owner - C:\Programme\FRITZ!DSL\IGDCTRL.EXE (file missing) O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing) O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\apps\Powercinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\apps\Powercinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe O23 - Service: AVM FRITZ!web Routing Service (de_serv) - Unknown owner - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe (file missing) O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxLiveShare.exe O23 - Service: RoxMediaDB - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxMediaDB.exe O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCom\RoxUpnpRenderer.exe O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Programme\Roxio\WinOnCD 8\Digital Home\RoxUpnpServer.exe O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxWatch.exe O23 - Service: SPYWAREfighterRP - SpamFighter APS - C:\Programme\SPYWAREfighter\spfprc.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Programme\Softwin\BitDefender8\vsserv.exe" /service (file missing) O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing) |
23.04.2007, 15:12 | #2 |
| Hilfe Hallo,
__________________1. Es fehlen die Kopfzeilen Deines Logfiles (Systeminformationen). 2. Lies Dir - bei allem gebührenden Respekt - bitte (noch einmal ?) die NUB durch. (Titelwahl des Threads, Formulierung, etc.) Es macht das Lesen eines Threads nicht einfacher, wenn man Interpunktion, Gross- und Kleinschreibung, etc. nicht beachtet, auch beim Reden muss man mal Luft holen...). 3. Nach Beachtung von 1./2. wird sich vielleicht ein Profi melden, ich versuche mich vorrangig als minesweeper, damit die Leute, die wirklich Ahnung haben, sich dann auf das Wesentliche konzentrieren können. LG Joeyblack ________________________________ I am here to serve, not to be served ! |
23.04.2007, 16:03 | #3 |
| Hilfe Logfile of HijackThis v1.99.1
__________________Scan saved at 17:01:09, on 23.04.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe c:\apps\Powercinema\Kernel\TV\CLCapSvc.exe c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe c:\APPS\HIDSERVICE\HIDSERVICE.exe C:\WINDOWS\system32\nvsvc32.exe C:\Apps\Softex\OmniPass\Omniserv.exe C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxWatch.exe C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe c:\apps\Powercinema\Kernel\TV\CLSched.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Programme\Video AX Object\bpmon.exe C:\Programme\Video AX Object\smmon.exe C:\Programme\Java\jre1.5.0_11\bin\jusched.exe C:\WINDOWS\RTHDCPL.EXE C:\apps\Powercinema\PCMService.exe C:\apps\ABoard\ABoard.exe C:\apps\ABoard\AOSD.exe C:\progra~1\softwin\bitdef~1\bdnagent.exe C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Programme\Logitech\Video\LogiTray.exe C:\Programme\D-Link\AirPlus G\AirGCFG.exe C:\Programme\iTunes\iTunesHelper.exe C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe C:\Programme\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Programme\iPod\bin\iPodService.exe C:\Programme\SPYWAREfighter\spfprc.exe C:\Programme\Logitech\Video\FxSvr2.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Mozilla Firefox\firefox.exe C:\Programme\RegCleaner\RegCleanr.exe C:\Programme\RegCleaner\RegCleanr.exe C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe C:\Programme\ICQLite\ICQLite.exe C:\Programme\eMule\emule.exe C:\Programme\K-Lite Codec Pack\Media Player Classic\mplayerc.exe C:\WINDOWS\system32\divxsm.exe C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe C:\Programme\Softwin\BitDefender8\vsserv.exe c:\progra~1\softwin\bitdef~1\bdmcon.exe C:\Programme\WinRAR\WinRAR.exe C:\Programme\WinRAR\WinRAR.exe C:\DOKUME~1\Emal\LOKALE~1\Temp\Rar$EX00.000\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://google.bearshare.com/de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://de.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://de.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://de.search.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://de.yahoo.com R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=https=ftp=gopher=socks= R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: XTTBPos00 Class - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Programme\ICQToolbar\toolbaru.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Programme\Alcohol Toolbar\v3.1.0.0\Alcohol_Toolbar.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar2.dll O2 - BHO: (no name) - {D34F5D71-99E4-4D96-91CA-F4104F69B8AE} - C:\Programme\Video AX Object\bpvol.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Programme\Alcohol Toolbar\v3.1.0.0\Alcohol_Toolbar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar2.dll O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [AzMixerSel] C:\Programme\Realtek\InstallShield\AzMixerSel.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe O4 - HKLM\..\Run: [PCMService] "c:\apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe O4 - HKLM\..\Run: [BDNewsAgent] "c:\progra~1\softwin\bitdef~1\bdnagent.exe" O4 - HKLM\..\Run: [BDSwitchAgent] C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programme\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AOLDialer] C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programme\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programme\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [spywarefighterguard] C:\Programme\SPYWAREfighter\spftray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programme\Logitech\Video\ManifestEngine.exe boot O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\ger.htm O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programme\Yahoo!\Common\yinsthelper.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll O20 - Winlogon Notify: OPXPGina - C:\WINDOWS\ O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe O23 - Service: AVM IGD CTRL Service - Unknown owner - C:\Programme\FRITZ!DSL\IGDCTRL.EXE (file missing) O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing) O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\apps\Powercinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\apps\Powercinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe O23 - Service: AVM FRITZ!web Routing Service (de_serv) - Unknown owner - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe (file missing) O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxLiveShare.exe O23 - Service: RoxMediaDB - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxMediaDB.exe O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCom\RoxUpnpRenderer.exe O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Programme\Roxio\WinOnCD 8\Digital Home\RoxUpnpServer.exe O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxWatch.exe O23 - Service: SPYWAREfighterRP - SpamFighter APS - C:\Programme\SPYWAREfighter\spfprc.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Programme\Softwin\BitDefender8\vsserv.exe" /service (file missing) O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing) jetzt aber habe es neu reingstellt bitte sehr |
23.04.2007, 16:15 | #4 |
Administrator > Competence Manager | Hilfe Arbeite das hier ab: Anleitung SmitfraudFix: Lade dir dieses Tool -> SmitfraudFix -Starte es dann und lass das System durchsuchen. (Option 1) -Poste danach wie in der Anleitung beschrieben, das Ergebnis des Scans Deinstallieren: Start->Systemsteuerung->Software lösche dieses Programm: Video AX Object (sofern vorhanden!) außerdem: Arbeiten mit MWAV (eScan) * Lies dir folgende Anleitung genau durch und arbeite sie ab: -> Anleitung eScan * Wichtig: Poste im Anschluss das Ergebnis mit Hilfe der “find.bat”. (steht alles ganz genau in der Anleitung.) Poste zusätzlich zum eScan-Log nochmal ein neues Hijacklog. Gruß Sunny
__________________ Anfragen per Email, Profil- oder privater Nachricht werden ignoriert! Hilfe gibts NUR im Forum! Stulti est se ipsum sapientem putare. |
23.04.2007, 16:26 | #5 |
| Hilfe danke für die hilfe erstmal das wert ich jetzt machen meld mich dann wieder bei dir |
23.04.2007, 17:07 | #6 |
| Hilfe SmitFraudFix v2.171 Scan done at 17:29:17,98, 23.04.2007 Run from C:\Programme\Mozilla Firefox\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler Before SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SharedTaskScheduler] "{0e4e5110-a772-4c4a-a7dc-137fe10abd6e}"="calocarpum" [HKEY_CLASSES_ROOT\CLSID\{0e4e5110-a772-4c4a-a7dc-137fe10abd6e}\InProcServer32] @="C:\WINDOWS\system32\czxtyx.dll" [HKEY_LOCAL_MACHINE\Software\Classes\CLSID\{0e4e5110-a772-4c4a-a7dc-137fe10abd6e}\InProcServer32] @="C:\WINDOWS\system32\czxtyx.dll" »»»»»»»»»»»»»»»»»»»»»»»» Killing process »»»»»»»»»»»»»»»»»»»»»»»» hosts 127.0.0.1 localhost 127.0.0.1 desktop.kazaa.com 127.0.0.1 www.altnetp2p.com 127.0.0.1 alpha.kazaa.com 127.0.0.1 shop.kazaa.com 127.0.0.1 www.bonzi.com 127.0.0.1 www.brilliantdigital.com 127.0.0.1 www.b3d.com 127.0.0.1 media.altnet.com 127.0.0.1 www.altnet.com 127.0.0.1 dev.bde.com.au 127.0.0.1 update.kazaa.com 127.0.0.1 bravo.kazaa.com 216.239.37.101 www.kazaagold.com 216.239.37.101 kazaagold.com 216.239.37.101 www.k-lite.com 216.239.37.101 www.kazaa-download.de 216.239.37.101 www.mp3downloadhq.com 216.239.37.101 www.easymusicdownload.com 216.239.37.101 easymusicdownload.com 216.239.37.101 www.mp3madeeasy.com 216.239.37.101 www.monstershare.com 216.239.37.101 www.kazaa-plus.net 216.239.37.101 kazaa-plus.net 216.239.37.101 www.kazaa-plus.com 216.239.37.101 www.edonkey.com 216.239.37.101 www.kazaa-file-sharing-downloads.com 216.239.37.101 www.kazaaplatinum.com 216.239.37.101 www.madeformusic.com 216.239.37.101 ikazaa.net 216.239.37.101 www.mp3u.com 216.239.37.101 www.mp3specialty.com 216.239.37.101 music-download-world.com 216.239.37.101 song-download-world.com 216.239.37.101 www.flixs.net 216.239.37.101 www.ishareit.net 216.239.37.101 www.ishareit.com 216.239.37.101 www.download-doctor.com 127.0.0.1 123banners.com 127.0.0.1 ad.adsmart.net 127.0.0.1 ad.ca.doubleclick.net 127.0.0.1 ad.de.doubleclick.net 127.0.0.1 ad.doubleclick.net 127.0.0.1 ad.es.doubleclick.net 127.0.0.1 ad.fr.doubleclick.net 127.0.0.1 ad.free6.com 127.0.0.1 ad.it.doubleclick.net 127.0.0.1 ad.iwin.com 127.0.0.1 ad.jp.doubleclick.net 127.0.0.1 ad.kr.doubleclick.net 127.0.0.1 ad.linkexchange.com 127.0.0.1 ad.linksynergy.com 127.0.0.1 ad.nl.doubleclick.net 127.0.0.1 ad.no.doubleclick.net 127.0.0.1 ad.preferences.com 127.0.0.1 ad.se.doubleclick.net 127.0.0.1 ad.sma.punto.net 127.0.0.1 ad.trafficmp.com 127.0.0.1 ad.uk.doubleclick.net 127.0.0.1 ad.webprovider.com 127.0.0.1 ad08.focalink.com 127.0.0.1 ad1.adcept.net 127.0.0.1 ad1.icorp.net 127.0.0.1 ad1.looksmart.com 127.0.0.1 ad1.peel.com 127.0.0.1 ad2.adcept.net 127.0.0.1 ad2.looksmart.com 127.0.0.1 ad2.peel.com 127.0.0.1 ad3.adcept.net 127.0.0.1 ad3.peel.com 127.0.0.1 ad4.peel.com 127.0.0.1 ad-adex3.flycast.com 127.0.0.1 adcontroller.unicast.com 127.0.0.1 adcreatives.imaginemedia.com 127.0.0.1 addb.looksmart.com 127.0.0.1 adevents.msn.com 127.0.0.1 adex3.flycast.com 127.0.0.1 adfarm.mediaplex.com 127.0.0.1 adforce.ads.imgis.com 127.0.0.1 adforce.imgis.com 127.0.0.1 adfu.blockstackers.com 127.0.0.1 adimage.blm.net 127.0.0.1 adimages.earthweb.com 127.0.0.1 adimages.go.com 127.0.0.1 adimages.imaginemedia.com 127.0.0.1 adimg.egroups.com 127.0.0.1 admedia.xoom.com 127.0.0.1 admonitor.net 127.0.0.1 adpick.switchboard.com 127.0.0.1 adproject.net 127.0.0.1 adremote.pathfinder.com 127.0.0.1 adres.internet.com 127.0.0.1 ads.adflight.com 127.0.0.1 ads.ad-flow.com 127.0.0.1 ads.admaximize.com 127.0.0.1 ads.admonitor.net 127.0.0.1 ads.adroar.com 127.0.0.1 ads.astalavista.us 127.0.0.1 ads.bfast.com 127.0.0.1 ads.box.sk 127.0.0.1 ads.burstnet.com 127.0.0.1 ads.cdfreaks.com 127.0.0.1 ads.chrbanner.com 127.0.0.1 ads.clickagents.com 127.0.0.1 ads.clickhouse.com 127.0.0.1 ads.dai.net 127.0.0.1 ads.datais.com 127.0.0.1 ads.enliven.com 127.0.0.1 ads.eu.msn.com 127.0.0.1 ads.fairfax.com.au 127.0.0.1 ads.fool.com 127.0.0.1 ads.fortunecity.com 127.0.0.1 ads.fortunecity.fr 127.0.0.1 ads.freeze.com 127.0.0.1 ads.freshmeat.net 127.0.0.1 ads.god.co.uk 127.0.0.1 ads.guardianunlimited.co.uk 127.0.0.1 ads.hitcents.com 127.0.0.1 ads.hollywood.com 127.0.0.1 ads.i12.de 127.0.0.1 ads.i33.com 127.0.0.1 ads.ign.com 127.0.0.1 ads.imaginemedia.com 127.0.0.1 ads.indya.com 127.0.0.1 ads.infi.net 127.0.0.1 ads.irover.com 127.0.0.1 ads.ixo.com 127.0.0.1 ads.jpost.com 127.0.0.1 ads.jwtt3.com 127.0.0.1 ads.killerapp.com 127.0.0.1 ads.link4ads.com 127.0.0.1 ads.linksponsor.com 127.0.0.1 ads.looksmart.com 127.0.0.1 ads.lycos.com 127.0.0.1 ads.lycos.de 127.0.0.1 ads.madison.com 127.0.0.1 ads.mediaodyssey.com 127.0.0.1 ads.mediaturf.net 127.0.0.1 ads.msn.com 127.0.0.1 ads.musiccity.com 127.0.0.1 ads.netomia.com 127.0.0.1 ads.netpumper.com 127.0.0.1 ads.newcity.com 127.0.0.1 ads.newcitynet.com 127.0.0.1 ads.ninemsn.com.au 127.0.0.1 ads.rediff.com 127.0.0.1 ads.satyamonline.com 127.0.0.1 ads.seattletimes.com 127.0.0.1 ads.smartclicks.com 127.0.0.1 ads.smartclicks.net 127.0.0.1 ads.sptimes.com 127.0.0.1 ads.startpath.com 127.0.0.1 ads.station.sony.com 127.0.0.1 ads.tiscali.fr 127.0.0.1 ads.tripod.com 127.0.0.1 ads.tucows.com 127.0.0.1 ads.vcommunities.com 127.0.0.1 ads.web.aol.com 127.0.0.1 ads.x10.com 127.0.0.1 ads.xtra.co.nz 127.0.0.1 ads.zdnet.com 127.0.0.1 ads01.focalink.com 127.0.0.1 ads02.focalink.com 127.0.0.1 ads03.focalink.com 127.0.0.1 ads04.focalink.com 127.0.0.1 ads05.focalink.com 127.0.0.1 ads06.focalink.com 127.0.0.1 ads07.focalink.com 127.0.0.1 ads08.focalink.com 127.0.0.1 ads09.focalink.com 127.0.0.1 ads1.activeagent.at 127.0.0.1 ads1.ad-flow.com 127.0.0.1 ads1.speedbit.com 127.0.0.1 ads10.focalink.com 127.0.0.1 ads11.focalink.com 127.0.0.1 ads12.focalink.com 127.0.0.1 ads13.focalink.com 127.0.0.1 ads14.focalink.com 127.0.0.1 ads15.focalink.com 127.0.0.1 ads16.focalink.com 127.0.0.1 ads17.focalink.com 127.0.0.1 ads18.focalink.com 127.0.0.1 ads19.focalink.com 127.0.0.1 ads2.speedbit.com 127.0.0.1 ads2.zdnet.com 127.0.0.1 ads20.focalink.com 127.0.0.1 ads21.focalink.com 127.0.0.1 ads22.focalink.com 127.0.0.1 ads23.focalink.com 127.0.0.1 ads24.focalink.com 127.0.0.1 ads25.focalink.com 127.0.0.1 ads3.speedbit.com 127.0.0.1 ads3.zdnet.com 127.0.0.1 ads4.speedbit.com 127.0.0.1 ads5.gamecity.net 127.0.0.1 ads5.speedbit.com 127.0.0.1 ads6.speedbit.com 127.0.0.1 ads7.speedbit.com 127.0.0.1 ads8.speedbit.com 127.0.0.1 adserv.bravenet.com 127.0.0.1 adserv.bravenet.com 127.0.0.1 adserv.iafrica.com 127.0.0.1 adserv.internetfuel.com 127.0.0.1 adserv.quality-channel.de 127.0.0.1 adserver.adtech.de 127.0.0.1 adserver.affiliation.com 127.0.0.1 adserver.akqa.net 127.0.0.1 adserver.dbusiness.com 127.0.0.1 adserver.directforce.net 127.0.0.1 adserver.garden.com 127.0.0.1 adserver.gorillanation.com 127.0.0.1 adserver.humanux.com 127.0.0.1 adserver.imaginemedia.com 127.0.0.1 adserver.isonews.com 127.0.0.1 adserver.janes.com 127.0.0.1 adserver.lunarpages.com 127.0.0.1 adserver.merc.com 127.0.0.1 adserver.monster.com 127.0.0.1 adserver.track-star.com 127.0.0.1 adserver.tweakers.net 127.0.0.1 adserver.ugo.com 127.0.0.1 adserver.webads.nl 127.0.0.1 adserver1.ogilvy-interactive.de 127.0.0.1 adserver2.imaginemedia.com 127.0.0.1 AdSubstract 127.0.0.1 adsubstract 127.0.0.1 ads-ussj1.focalink.com 127.0.0.1 adtegrity.spinbox.net 127.0.0.1 adulttds.com 127.0.0.1 aglink.mircx.com 127.0.0.1 antfarm-ad.flycast.com 127.0.0.1 asm3.z1.adserver.com 127.0.0.1 au.ads.link4ads.com 127.0.0.1 bach.aureate.com 127.0.0.1 badservant.guj.de 127.0.0.1 banner.50megs.com 127.0.0.1 banner.adverity.com 127.0.0.1 banner.commissionpartner.com 127.0.0.1 banner.de 127.0.0.1 banner.easyspace.com 127.0.0.1 banner.free6.com 127.0.0.1 banner.i-3.de 127.0.0.1 banner.media-system.de 127.0.0.1 banner.orb.net 127.0.0.1 banner.relcom.ru 127.0.0.1 bannerad.ipgnet.com 127.0.0.1 bannerads.de 127.0.0.1 bannerfarm.ace.advertising.com 127.0.0.1 bannerimages.0catch.com 127.0.0.1 bannermaster.geektech.com 127.0.0.1 banner-net.com 127.0.0.1 bannerpower.com 127.0.0.1 banners.adultfriendfinder.com 127.0.0.1 banners.easydns.com 127.0.0.1 banners.free6.com 127.0.0.1 banners.hotlinks.net 127.0.0.1 banners.looksmart.com 127.0.0.1 banners.nextcard.com 127.0.0.1 banners.pennyweb.com 127.0.0.1 banners.valuead.com 127.0.0.1 banners.webmasterplan.com 127.0.0.1 banners.wunderground.com 127.0.0.1 bannervip.webjump.com 127.0.0.1 banzai.moodlogic.com 127.0.0.1 barnesandnoble.bfast.com 127.0.0.1 beseen.com 127.0.0.1 beseen.looksmart.com 127.0.0.1 beseen5.looksmart.com 127.0.0.1 beseenad.looksmart.com 127.0.0.1 beseenad1.looksmart.com 127.0.0.1 beseenad2.looksmart.com 127.0.0.1 beseenad3.looksmart.com 127.0.0.1 beseenadx.looksmart.com 127.0.0.1 bfast.com 127.0.0.1 bins.lop.com 127.0.0.1 bizad.nikkeibp.co.jp 127.0.0.1 bn.bfast.com 127.0.0.1 botw.topbucks.com 127.0.0.1 bsads.looksmart.com 127.0.0.1 by.advertising.com 127.0.0.1 c1.thecounter.com 127.0.0.1 c2.thecounter.com 127.0.0.1 c3.xxxcounter.com 127.0.0.1 califia.imaginemedia.com 127.0.0.1 cash4banner.com 127.0.0.1 cash4banner.de 127.0.0.1 cds.mediaplex.com 127.0.0.1 cgi.sexlist.com 127.0.0.1 click.avenuea.com 127.0.0.1 click.go2net.com 127.0.0.1 click.linksynergy.com 127.0.0.1 clickagents.com 127.0.0.1 clicks.about.com 127.0.0.1 clicks.nastydollars.com 127.0.0.1 clicks.oxcash.com 127.0.0.1 clit5.sextracker.com 127.0.0.1 code02.pbtech.net 127.0.0.1 commonwealth.riddler.com 127.0.0.1 connect.online-dialer.com 127.0.0.1 cookies.cmpnet.com 127.0.0.1 cornflakes.pathfinder.com 127.0.0.1 counter.hitbox.com 127.0.0.1 counter1.sextracker.com 127.0.0.1 counter10.sextracker.com 127.0.0.1 counter11.sextracker.com 127.0.0.1 counter12.sextracker.com 127.0.0.1 counter13.sextracker.com 127.0.0.1 counter14.sextracker.com 127.0.0.1 counter15.sextracker.com 127.0.0.1 counter16.sextracker.com 127.0.0.1 counter2.sextracker.com 127.0.0.1 counter3.sextracker.com 127.0.0.1 counter4.sextracker.com 127.0.0.1 counter5.sextracker.com 127.0.0.1 counter6.sextracker.com 127.0.0.1 counter7.sextracker.com 127.0.0.1 counter8.sextracker.com 127.0.0.1 counter9.sextracker.com 127.0.0.1 crs.akamai.com 127.0.0.1 crux.songline.com 127.0.0.1 ct.iac-online.de 127.0.0.1 ctc.amateurpages.com 127.0.0.1 de.netstatpro.net 127.0.0.1 desktop.grokster.com 127.0.0.1 dialer.offshoreclicks.com 127.0.0.1 doubleclick.net 127.0.0.1 download1.0190-dialer.com 127.0.0.1 download1.libereco.net 127.0.0.1 download2.0190-dialer.com 127.0.0.1 econnect.libereco.net 127.0.0.1 ehg.hitbox.com 127.0.0.1 ehg-commjun.hitbox.com 127.0.0.1 erie.smartage.com 127.0.0.1 etad.telegraph.co.uk 127.0.0.1 everyone.net 127.0.0.1 exchange-it.com 127.0.0.1 exitfuel.com 127.0.0.1 exitmoney.com 127.0.0.1 fast.mediacharger.com 127.0.0.1 focalink.com 127.0.0.1 fp.valueclick.com 127.0.0.1 fragmentserv.iac-online.de 127.0.0.1 free.fuck-portal.com 127.0.0.1 freeadultlottery.com 127.0.0.1 freeasiahardcore.com 127.0.0.1 freebieclub.com 127.0.0.1 freebigcocks.net 127.0.0.1 freecelebnudity.com 127.0.0.1 freefarmpics.com 127.0.0.1 freegaybears.net 127.0.0.1 freegaylottery.com 127.0.0.1 freenaughtyteens.com 127.0.0.1 freepass.elitecities.com 127.0.0.1 fs.dai.net 127.0.0.1 gadgeteer.pdamart.com 127.0.0.1 global.msads.net 127.0.0.1 gm.preferences.com 127.0.0.1 go.ezgreen.com 127.0.0.1 got2goshop.com 127.0.0.1 goto.trafficmultiplier.com 127.0.0.1 gp.dejanews.com 127.0.0.1 hacker-spider.de 127.0.0.1 hc2.humanclick.com 127.0.0.1 hg1.hitbox.com 127.0.0.1 hit.hotlog.ru 127.0.0.1 hitbox.com 127.0.0.1 hitmatic.com 127.0.0.1 hitsfrom.popuprush.com 127.0.0.1 hotfreewebcams.com 127.0.0.1 hypercount.com 127.0.0.1 ifcol.exitfuel.com 127.0.0.1 image.click2net.com 127.0.0.1 image.eimg.com 127.0.0.1 images.sexlist.com 127.0.0.1 images2.nytimes.com 127.0.0.1 imageserv.adtech.de 127.0.0.1 img.lop.com 127.0.0.1 img.mediaplex.com 127.0.0.1 impnl.tradedoubler.com 127.0.0.1 internetfuel.com 127.0.0.1 itn.adbureau.net 127.0.0.1 jcms.cydoor.com 127.0.0.1 jeeves.flycast.com 127.0.0.1 jobkeys.ngadcenter.net 127.0.0.1 kansas.valueclick.com 127.0.0.1 leader.linkexchange.com 127.0.0.1 linkbuddies.com 127.0.0.1 liquidad.narrowcastmedia.com 127.0.0.1 liveadvert.com 127.0.0.1 ln.doubleclick.net 127.0.0.1 looksmartclicks.com 127.0.0.1 lop.com 127.0.0.1 lsads.looksmart.com.au 127.0.0.1 m.doubleclick.net 127.0.0.1 macaddictads.snv.futurenet.com 127.0.0.1 marketing-internet.com 127.0.0.1 maxexp.com 127.0.0.1 maximumcash.com 127.0.0.1 maximumpcads.imaginemedia.com 127.0.0.1 media.carpediem.fr 127.0.0.1 media.expedia.com 127.0.0.1 media.fastclick.net 127.0.0.1 media.popuptraffic.com 127.0.0.1 media.popuptraffic.com 127.0.0.1 media.preferences.com 127.0.0.1 media20.fastclick.net 127.0.0.1 mediacharger.com 127.0.0.1 mediamgr.ugo.com 127.0.0.1 mediaplex.com 127.0.0.1 megacash.de 127.0.0.1 megawebcams.tv 127.0.0.1 mercury.rmuk.co.uk 127.0.0.1 millenium-hitz.com 127.0.0.1 mjxads.internet.com 127.0.0.1 mojofarm.sjc.mediaplex.com 127.0.0.1 monitor.looksmart.com 127.0.0.1 monsterhitz.to 127.0.0.1 musiccity.streamcastnetwork.com 127.0.0.1 n24.de 127.0.0.1 nbc.adbureau.net 127.0.0.1 network.realmedia.com 127.0.0.1 newads.cmpnet.com 127.0.0.1 newsticker.shortnews.de 127.0.0.1 ng3.ads.warnerbros.com 127.0.0.1 ngads.smartage.com 127.0.0.1 nitrous.exitfuel.com 127.0.0.1 nsads.hotwired.com 127.0.0.1 ntbanner.digitalriver.com 127.0.0.1 oad.realmedia.com 127.0.0.1 oas.benchmark.fr 127.0.0.1 onresponse.com 127.0.0.1 onresponse.com 127.0.0.1 oz.valueclick.com 127.0.0.1 p.wtlive.com 127.0.0.1 paycounter.com 127.0.0.1 ph-ad04.focalink.com 127.0.0.1 ph-ad05.focalink.com 127.0.0.1 ph-ad07.focalink.com 127.0.0.1 ph-ad16.focalink.com 127.0.0.1 ph-ad17.focalink.com 127.0.0.1 ph-ad18.focalink.com 127.0.0.1 php.offshoreclicks.com 127.0.0.1 pluto.beseen.com 127.0.0.1 pop.mircx.com 127.0.0.1 popup.found404.com 127.0.0.1 porn-attack.com 127.0.0.1 portal.hostultra.com 127.0.0.1 proxy.ladot.com 127.0.0.1 pub.epiknet.org 127.0.0.1 pub.infiniland.com 127.0.0.1 pub.ketix.com 127.0.0.1 pub.telmedia.fr 127.0.0.1 pub.weborama.fr 127.0.0.1 publish.hometown.aol.co.uk 127.0.0.1 realads.realmedia.com 127.0.0.1 redherring.ngadcenter.net 127.0.0.1 redirect.click2net.com 127.0.0.1 redirect.iac-online.de 127.0.0.1 regio.adlink.de 127.0.0.1 ResponseMedia-ad.flycast.com 127.0.0.1 retaildirect.realmedia.com 127.0.0.1 rmads.eu.msn.com 127.0.0.1 rs.webmasterplan.com 127.0.0.1 s0.bluestreak.com 127.0.0.1 s1.bluestreak.com 127.0.0.1 s2.bluestreak.com 127.0.0.1 s2.focalink.com 127.0.0.1 s3.bluestreak.com 127.0.0.1 s4.bluestreak.com 127.0.0.1 s5.bluestreak.com 127.0.0.1 s6.bluestreak.com 127.0.0.1 s7.bluestreak.com 127.0.0.1 s8.bluestreak.com 127.0.0.1 sbee.com 127.0.0.1 script.weborama.fr 127.0.0.1 search.kazaa.com 127.0.0.1 secserv.imgis.com 127.0.0.1 servedby.advertising.com 127.0.0.1 servedby.advertwizard.com 127.0.0.1 server.hamster.com 127.0.0.1 server-uk.imrworldwide.com 127.0.0.1 sexpromote.com 127.0.0.1 sexpromote.com 127.0.0.1 sextracker.com 127.0.0.1 sh4banner.de 127.0.0.1 sh4sure-images.adbureau.net 127.0.0.1 shop.freepush.com 127.0.0.1 shortwin.de 127.0.0.1 specialoffers.aol.com 127.0.0.1 spezialreporte.de 127.0.0.1 spin.spinbox.net 127.0.0.1 sprinks-clicks.about.com 127.0.0.1 spylog.com 127.0.0.1 srv1.bannercommunity.de 127.0.0.1 srv2.bannercommunity.de 127.0.0.1 srv3.bannercommunity.de 127.0.0.1 static.admaximize.com 127.0.0.1 stats.superstats.com 127.0.0.1 stats3.porntrack.com 127.0.0.1 statse.webtrendslive.com 127.0.0.1 Suissa-ad.flycast.com 127.0.0.1 survey.proactive.nl 127.0.0.1 sview.avenuea.com 127.0.0.1 t0.extreme-dm.com 127.0.0.1 thinknyc.eu-adcenter.net 127.0.0.1 tour01.bangbus.com 127.0.0.1 tpl1.realtracker.com 127.0.0.1 tracker.clicktrade.com 127.0.0.1 trinityacquisitions.com 127.0.0.1 tsms-ad.tsms.com 127.0.0.1 tuerck.de.counted.com 127.0.0.1 twistedhumor.com 127.0.0.1 ugo.eu-adcenter.net 127.0.0.1 UGO.eu-adcenter.net 127.0.0.1 uk1.linksynergy.com 127.0.0.1 uk2.linksynergy.com 127.0.0.1 uk3.linksynergy.com 127.0.0.1 uk4.linksynergy.com 127.0.0.1 uk5.linksynergy.com 127.0.0.1 us.adserver.yahoo.com 127.0.0.1 v0.extreme-dm.com 127.0.0.1 v1.extreme-dm.com 127.0.0.1 valueclick.com 127.0.0.1 van.ads.link4ads.com 127.0.0.1 vant.guj.de 127.0.0.1 venus.goclick.com 127.0.0.1 view.accendo.com 127.0.0.1 view.avenuea.com 127.0.0.1 vis1.sexlist.com 127.0.0.1 vis2.sexlist.com 127.0.0.1 vis3.sexlist.com 127.0.0.1 vis4.sexlist.com 127.0.0.1 vis5.sexlist.com 127.0.0.1 visit.referralware.com 127.0.0.1 visite.weborama.fr 127.0.0.1 VNU.eu-adcenter.net 127.0.0.1 w0.extreme-dm.com 127.0.0.1 w113.hitbox.com 127.0.0.1 w117.hitbox.com 127.0.0.1 w25.hitbox.com 127.0.0.1 web2.deja.com 127.0.0.1 webads.bizservers.com 127.0.0.1 weblist.de 127.0.0.1 webpdp.gator.com 127.0.0.1 webxprod.qualcomm.com 127.0.0.1 www.0190-dialer.com 127.0.0.1 www.12traffic.de 127.0.0.1 www.1for1.com 127.0.0.1 www.3turtles.com 127.0.0.1 www.404errorpage.com 127.0.0.1 www.7adpower.com 127.0.0.1 www.7host.com 127.0.0.1 www.activeannonce.com 127.0.0.1 www.adbucks.com 127.0.0.1 www.adexit.com 127.0.0.1 www.adexit.de 127.0.0.1 www.adforce.com 127.0.0.1 www.admex.com 127.0.0.1 www.adnetz.net 127.0.0.1 www.adserver.com 127.0.0.1 www.adserver.net 127.0.0.1 www.adsmart.com 127.0.0.1 www.adsmart.net 127.0.0.1 www.adultbizvoice.com 127.0.0.1 www.adultclicks.com 127.0.0.1 www.ad-up.com 127.0.0.1 www.adverity.com 127.0.0.1 www.adverlead.com 127.0.0.1 www.adverline.com 127.0.0.1 www.adverline.fr 127.0.0.1 www.advertising.com 127.0.0.1 www.advertwizard.com 127.0.0.1 www.adviews-sponsor.de 127.0.0.1 www.alexchiu.com 127.0.0.1 www.alladvantage.com 127.0.0.1 www.allclicks.com 127.0.0.1 www.amateur-galleries.com 127.0.0.1 www.amazingpops.com 127.0.0.1 www.at-nude-teens.net 127.0.0.1 www.bannerads.de 127.0.0.1 www.beseen.com 127.0.0.1 www.bfast.com 127.0.0.1 www.boonsolutions.com 127.0.0.1 www.brutalextreme.com 127.0.0.1 www.burstnet.com 127.0.0.1 www.cash1x1.de 127.0.0.1 www.cash2002.de 127.0.0.1 www.cash4banner.com 127.0.0.1 www.cash4banner.de 127.0.0.1 www.cashcount.com 127.0.0.1 www.cashfiesta.com 127.0.0.1 www.cashradio.com 127.0.0.1 www.cashsurfers.com 127.0.0.1 www.casinoglamour.com 127.0.0.1 www.cellularphones.com 127.0.0.1 www.cibleclick.com 127.0.0.1 www.cj.com 127.0.0.1 www.click2sexy.com 127.0.0.1 www.click-fr.com 127.0.0.1 www.clickxchange.com 127.0.0.1 www.clictrafic.com 127.0.0.1 www.coinpromo.com 127.0.0.1 www.cometcursor.com 127.0.0.1 www.cometsystems.net 127.0.0.1 www.commission-junction.com 127.0.0.1 www.cr4.com 127.0.0.1 www.crazypopups.com 127.0.0.1 www.crxwarez.net 127.0.0.1 www.cydoor.com 127.0.0.1 www.daz.com 127.0.0.1 www.dgm2.com 127.0.0.1 www.directvalue.nl 127.0.0.1 www.drawnsex.com 127.0.0.1 www.eads.com 127.0.0.1 www.e-bannerx.com 127.0.0.1 www.eclic.net 127.0.0.1 www.fastclick.net 127.0.0.1 www.fastmetasearch.com 127.0.0.1 www.flycast.co.uk 127.0.0.1 www.flycast.com 127.0.0.1 www.found404.com 127.0.0.1 www.fpctraffic.com 127.0.0.1 www.freeadultlottery.com 127.0.0.1 www.freeasiahardcore.com 127.0.0.1 www.free-banners.com 127.0.0.1 www.freebigcocks.net 127.0.0.1 www.freecelebnudity.com 127.0.0.1 www.freefarmpics.com 127.0.0.1 www.freegaybears.net 127.0.0.1 www.freegaylottery.com 127.0.0.1 www.freenaughtyteens.com 127.0.0.1 www.freestats.com 127.0.0.1 www.frontpagecash.com 127.0.0.1 www.fuck-portal.com 127.0.0.1 www.gamingclub.com 127.0.0.1 www.gator.co.uk 127.0.0.1 www.gator.com 127.0.0.1 www.gator.net 127.0.0.1 www.genhit.com 127.0.0.1 www.getsearches.com 127.0.0.1 www.gopopup.com 127.0.0.1 www.greetingwishes.com 127.0.0.1 www.grokster.com 127.0.0.1 www.hardcorepornos.org 127.0.0.1 www.hightrafficads.com 127.0.0.1 www.hit-parade.com 127.0.0.1 www.hitsme.com 127.0.0.1 www.hotfreewebcams.com 127.0.0.1 www.imaginemedia.com 127.0.0.1 www.lastconsole.com 127.0.0.1 www.linkshare.com 127.0.0.1 www.liveadvert.com 127.0.0.1 www.lo-litas.com 127.0.0.1 www.looksmartclicks.com 127.0.0.1 www.lop.com 127.0.0.1 www.lottoforever.com 127.0.0.1 www.mediaplex.com 127.0.0.1 www.megacash.de 127.0.0.1 www.megawebcams.tv 127.0.0.1 www.milfhunter.com 127.0.0.1 www.modchip.com 127.0.0.1 www.mod-chip.com 127.0.0.1 www.money4exit.de 127.0.0.1 www.my-stats.com 127.0.0.1 www.netbroadcaster.com 127.0.0.1 www.netdirect.nl 127.0.0.1 www.netflip.com 127.0.0.1 www.netgravity.com 127.0.0.1 www.newtopsites.com 127.0.0.1 www.nic.co.il 127.0.0.1 www.nudelinkz.com 127.0.0.1 www.oneandonlynetwork.com 127.0.0.1 www.onresponse.com 127.0.0.1 www.paidpopup.de 127.0.0.1 www.paypopup.com 127.0.0.1 www.piratos.de 127.0.0.1 www.popdown.de 127.0.0.1 www.popupad.net 127.0.0.1 www.popuptraffic.com 127.0.0.1 www.PostMasterBannerNet.com 127.0.0.1 www.prepaidliving.com 127.0.0.1 www.qksrv.net 127.0.0.1 www.qualityhitz.com 127.0.0.1 www.qualypromos.com 127.0.0.1 www.radiate.com 127.0.0.1 www.radiofreecash.com 127.0.0.1 www.rankyou.com 127.0.0.1 www.reference-sexe.com 127.0.0.1 www.sbee.com 127.0.0.1 www.sbvr.com 127.0.0.1 www.searchtraffic.com 127.0.0.1 www.service-url.de 127.0.0.1 www.sexfranco.com 127.0.0.1 www.sexfreelist.com 127.0.0.1 www.sexlist.com 127.0.0.1 www.sexpromote.com 127.0.0.1 www.sexpromote.com 127.0.0.1 www.sexspy.com 127.0.0.1 www.sexstudio24.de 127.0.0.1 www.sextracker.com 127.0.0.1 www.sextraffic.org 127.0.0.1 www.sexyfreehost.com 127.0.0.1 www.sexyplugin.com 127.0.0.1 www.simplecounter.net 127.0.0.1 www.slutzoo.com 127.0.0.1 www.sonixwarez.com 127.0.0.1 www.sponsor2002.de 127.0.0.1 www.targetshop.com 127.0.0.1 www.techiwarehouse.com 127.0.0.1 www.teknosurf.com 127.0.0.1 www.teknosurf2.com 127.0.0.1 www.teknosurf3.com 127.0.0.1 www.theadultwire.com 127.0.0.1 www.topwarez-fr.com 127.0.0.1 www.toys-galleries.com 127.0.0.1 www.trafficbox.net 127.0.0.1 www.trafficmonetizer.com 127.0.0.1 www.unionwarez.com 127.0.0.1 www.valueclick.com 127.0.0.1 www.valuesponsor.com 127.0.0.1 www.warez33.com 127.0.0.1 www.warezfield.com 127.0.0.1 www.web3000.co.uk 127.0.0.1 www.web3000.com 127.0.0.1 www.webads.nl 127.0.0.1 www.webferret.com 127.0.0.1 www.webhancer.com 127.0.0.1 www.webhancer.net 127.0.0.1 www.weblist.de 127.0.0.1 www.websitefinancing.com 127.0.0.1 www.wedoo.com 127.0.0.1 www.win24.de 127.0.0.1 www.wingowin.com 127.0.0.1 www.wtlive.com 127.0.0.1 www.xiti.com 127.0.0.1 www.xpostx.com 127.0.0.1 www.xxxdisplay.com 127.0.0.1 www.xxxfreeamateurs.com 127.0.0.1 www.xxxteenclub.de 127.0.0.1 www.youmakemoney.com 127.0.0.1 www.zeloop.net 127.0.0.1 www2.burstnet.com 127.0.0.1 www2.consumercreditusa.com 127.0.0.1 www3.netgravity.com 127.0.0.1 www4.netgravity.com 127.0.0.1 www4.trix.net 127.0.0.1 www80.valueclick.com 127.0.0.1 xads.infospace.com 127.0.0.1 xads.zedo.com 127.0.0.1 xxxfreeamateurs.com 127.0.0.1 z.extreme-dm.com 127.0.0.1 z0.extreme-dm.com 127.0.0.1 z1.extreme-dm.com 127.0.0.1 zac.netgravity.com »»»»»»»»»»»»»»»»»»»»»»»» Generic Renos Fix GenericRenosFix by S!Ri *** An error occured while opening C:\WINDOWS\system32\czxtyx.dll *** »»»»»»»»»»»»»»»»»»»»»»»» Deleting infected files C:\WINDOWS\Tasks\At?.job Deleted Problem while deleting C:\WINDOWS\system32\czxtyx.dll C:\DOKUME~1\ALLUSE~1\STARTM~1\Online Security Guide.url Deleted C:\DOKUME~1\ALLUSE~1\STARTM~1\Security Troubleshooting.url Deleted C:\DOKUME~1\ALLUSE~1\Desktop\Online Security Guide.url Deleted C:\DOKUME~1\ALLUSE~1\Desktop\Security Troubleshooting.url Deleted C:\DOKUME~1\Emal\FAVORI~1\Online Security Test.url Deleted C:\Programme\SpywareLocked 3.5\ Deleted Problem while deleting C:\Programme\Video AX Object\ |
23.04.2007, 17:09 | #7 |
| Hilfe »»»»»»»»»»»»»»»»»»»»»»»» DNS Description: Realtek RTL8139/810x Family Fast Ethernet NIC - Paketplaner-Miniport DNS Server Search Order: 192.168.178.1 HKLM\SYSTEM\CCS\Services\Tcpip\..\{042A0C4A-1B71-4289-9BD6-B13C374AB448}: DhcpNameServer=192.168.178.1 HKLM\SYSTEM\CS1\Services\Tcpip\..\{042A0C4A-1B71-4289-9BD6-B13C374AB448}: DhcpNameServer=192.168.178.1 HKLM\SYSTEM\CS2\Services\Tcpip\..\{042A0C4A-1B71-4289-9BD6-B13C374AB448}: DhcpNameServer=192.168.178.1 HKLM\SYSTEM\CCS\Services\Tcpip\Parameters: DhcpNameServer=192.168.178.1 HKLM\SYSTEM\CS1\Services\Tcpip\Parameters: DhcpNameServer=192.168.178.1 HKLM\SYSTEM\CS2\Services\Tcpip\Parameters: DhcpNameServer=192.168.178.1 »»»»»»»»»»»»»»»»»»»»»»»» Deleting Temp Files »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» Registry Cleaning Registry Cleaning done. »»»»»»»»»»»»»»»»»»»»»»»» SharedTaskScheduler After SmitFraudFix !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» Reboot Problem while deleting C:\WINDOWS\system32\czxtyx.dll Problem while deleting C:\Programme\Video AX Object »»»»»»»»»»»»»»»»»»»»»»»» End ich hoffe es is noch nicht zuspät bei mir werden hier andauernd neue hardcore porno seite geöffnet nur damit ich mehr viren bekomme die werden aber gott sei dank abgewährt |
23.04.2007, 17:21 | #8 |
Administrator > Competence Manager | Hilfe Führe auf jeden Fall noch den eScan aus, und poste das Ergebnis! Nun zum Hauptproblem: Suche folgende Datei -> c:\Windows\System32\drivers\etc\hosts Öffne diese mit dem Editor. Lösche in dieser Hosts-Datei (im Texteditor Modus) alle Zeilen unterhalb von 127.0.0.1 localhost (die Zeilen darüber mit dem "#" auch stehen lassen. Das sind lediglich Kommentare). Also nur "127.0.0.1 localhost" stehen lassen! Also alles was nach: 127.0.0.1 desktop.kazaa.com LÖSCHEN! Danach speichern und das System neu starten! Und wie schon gesagt ein neues Hijacklog. Sunny
__________________ Anfragen per Email, Profil- oder privater Nachricht werden ignoriert! Hilfe gibts NUR im Forum! Stulti est se ipsum sapientem putare. |
23.04.2007, 17:33 | #9 |
| Hilfe Logfile of HijackThis v1.99.1 Scan saved at 18:32:49, on 23.04.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe c:\apps\Powercinema\Kernel\TV\CLCapSvc.exe c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe c:\APPS\HIDSERVICE\HIDSERVICE.exe C:\WINDOWS\system32\nvsvc32.exe C:\Apps\Softex\OmniPass\Omniserv.exe C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxMediaDB.exe C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxWatch.exe C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe c:\apps\Powercinema\Kernel\TV\CLSched.exe C:\Programme\Roxio\WinOnCD 8\Digital Home\RoxUpnpServer.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\NOTEPAD.EXE C:\Programme\Java\jre1.5.0_11\bin\jusched.exe C:\WINDOWS\RTHDCPL.EXE C:\apps\Powercinema\PCMService.exe C:\apps\ABoard\ABoard.exe C:\apps\ABoard\AOSD.exe C:\progra~1\softwin\bitdef~1\bdnagent.exe C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe C:\WINDOWS\system32\LVCOMSX.EXE C:\Programme\Logitech\Video\LogiTray.exe C:\Programme\iTunes\iTunesHelper.exe C:\Programme\SPYWAREfighter\spftray.exe C:\Programme\iPod\bin\iPodService.exe C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe C:\Programme\SPYWAREfighter\spfprc.exe C:\Programme\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Programme\Logitech\Video\FxSvr2.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe C:\Programme\Softwin\BitDefender8\vsserv.exe c:\progra~1\softwin\bitdef~1\bdmcon.exe C:\Programme\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\msiexec.exe C:\DOKUME~1\Emal\LOKALE~1\Temp\Rar$EX00.125\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = http://search.bearshare.com/sidebar.html?src=ssb R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Packard Bell R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=https=ftp=gopher=socks= R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll R3 - URLSearchHook: (no name) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) O2 - BHO: XTTBPos00 Class - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\Programme\ICQToolbar\toolbaru.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_11\bin\ssv.dll O2 - BHO: Alcohol Toolbar Helper - {8126A4A5-BFD3-46FE-BBDF-BFB5CF78E489} - C:\Programme\Alcohol Toolbar\v3.1.0.0\Alcohol_Toolbar.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar2.dll O2 - BHO: (no name) - {D34F5D71-99E4-4D96-91CA-F4104F69B8AE} - C:\Programme\Video AX Object\bpvol.dll (file missing) O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O3 - Toolbar: Alcohol Toolbar - {ED4BD629-C1B6-4399-8A34-02CCAA921DC9} - C:\Programme\Alcohol Toolbar\v3.1.0.0\Alcohol_Toolbar.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar2.dll O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exe O4 - HKLM\..\Run: [AzMixerSel] C:\Programme\Realtek\InstallShield\AzMixerSel.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.5.0_11\bin\jusched.exe" O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [OmniPass] C:\Apps\Softex\OmniPass\scureapp.exe O4 - HKLM\..\Run: [PCMService] "c:\apps\Powercinema\PCMService.exe" O4 - HKLM\..\Run: [ACTIVBOARD] c:\apps\ABoard\ABoard.exe O4 - HKLM\..\Run: [BDMCon] C:\PROGRA~1\Softwin\BITDEF~1\bdmcon.exe O4 - HKLM\..\Run: [BDNewsAgent] "c:\progra~1\softwin\bitdef~1\bdnagent.exe" O4 - HKLM\..\Run: [BDSwitchAgent] C:\PROGRA~1\Softwin\BITDEF~1\bdswitch.exe O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programme\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [AOLDialer] C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLDial.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programme\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programme\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [spywarefighterguard] C:\Programme\SPYWAREfighter\spftray.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKCU\..\Run: [SmpcSys] C:\APPS\SMP\SmpSys.exe O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [LogitechSoftwareUpdate] C:\Programme\Logitech\Video\ManifestEngine.exe boot O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_11\bin\ssv.dll O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=file://C:\APPS\IE\offline\ger.htm O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} - C:\Programme\Yahoo!\Common\yinsthelper.dll O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll sockspy.dll O20 - Winlogon Notify: OPXPGina - C:\WINDOWS\ O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C:\Programme\Gemeinsame Dateien\AOL\ACS\AOLAcsd.exe O23 - Service: AVM IGD CTRL Service - Unknown owner - C:\Programme\FRITZ!DSL\IGDCTRL.EXE (file missing) O23 - Service: BitDefender Scan Server (bdss) - Unknown owner - C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe" /service (file missing) O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - c:\apps\Powercinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - c:\apps\Powercinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - c:\APPS\Powercinema\Kernel\CLML_NTService\CLMLServer.exe O23 - Service: AVM FRITZ!web Routing Service (de_serv) - Unknown owner - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe (file missing) O23 - Service: Generic Service for HID Keyboard Input Collections (GenericHidService) - Unknown owner - c:\APPS\HIDSERVICE\HIDSERVICE.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Softex OmniPass Service (omniserv) - Softex Inc. - C:\Apps\Softex\OmniPass\Omniserv.exe O23 - Service: LiveShare P2P Server (RoxLiveShare) - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxLiveShare.exe O23 - Service: RoxMediaDB - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxMediaDB.exe O23 - Service: RoxUpnpRenderer (RoxUPnPRenderer) - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCom\RoxUpnpRenderer.exe O23 - Service: RoxUpnpServer - Sonic Solutions - C:\Programme\Roxio\WinOnCD 8\Digital Home\RoxUpnpServer.exe O23 - Service: Roxio Hard Drive Watcher (RoxWatch) - Sonic Solutions - C:\Programme\Gemeinsame Dateien\Roxio Shared\SharedCOM8\RoxWatch.exe O23 - Service: SPYWAREfighterRP - SpamFighter APS - C:\Programme\SPYWAREfighter\spfprc.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Programme\Softwin\BitDefender8\vsserv.exe" /service (file missing) O23 - Service: BitDefender Communicator (XCOMM) - Unknown owner - C:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe" /service (file missing) aber die hots datei da finde ich einige aber kann sie nicht so öffnen wie du es mir geschrieben hast |
23.04.2007, 17:46 | #10 |
Administrator > Competence Manager | Hilfe Versuchen wir es anders: Klicke auf -> Start -> Ausführen, kopiere folgenden Text ab und setz ihn beim ausführen ein -> OK Code:
ATTFilter edit c:\windows\system32\drivers\etc\hosts Die Datei muss sich öffnen lassen...
__________________ Anfragen per Email, Profil- oder privater Nachricht werden ignoriert! Hilfe gibts NUR im Forum! Stulti est se ipsum sapientem putare. |
23.04.2007, 18:09 | #11 |
| Hilfe hab es geöffnet aber e scan dauert noch ne weile bis es fertig gedownloaded ist |
23.04.2007, 18:25 | #12 |
Administrator > Competence Manager | Hilfe wenn du geöffnet hast musst du nur noch, so wie ich schon schrieb, alles unterhalb von 127.0.0.1 Localhost löschen! Ja ja, der eScan dauert, ist aber dafür sehr gründlich! Sunny
__________________ Anfragen per Email, Profil- oder privater Nachricht werden ignoriert! Hilfe gibts NUR im Forum! Stulti est se ipsum sapientem putare. |
Themen zu Hilfe |
adobe, appinit_dlls, bho, computer, cyberlink, defender, dsl, entfernen, excel, firefox, ftp, google, hijack, home, igdctrl.exe, internet, internet explorer, mozilla, mozilla firefox, object, realtek, rundll, scan, shortcut, skype.exe, software, system, trojaner, urlsearchhook, virus, windows |