|
Log-Analyse und Auswertung: Trojaner/Wurm? Firefox verschlingt 40%meiner Cpu und will als server agierenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
24.07.2007, 10:22 | #1 |
| Trojaner/Wurm? Firefox verschlingt 40%meiner Cpu und will als server agieren Hallo an alle, Seit kurzem habe ich bemerkt, dass mein Firefox etwas länger zum starten braucht als sonst, und auch meine Firewall (ZAfree) bringt beim starten von Firefox seit kurzem die Meldung: Firefox möchte als server fungiern (oder so ähnlich). Nachdem ich dies einmalig erlaubt habe, hat Firefox zwischen 30 und 40 Prozent meiner CPU benötigt (core2duo T7200). Hab dann Antivir laufen lassen-nichts gefunden. Spybot im Suchmodus auch nichts gefunden, hab dann im Spybot bei den Tools unter Systemstart einen Eintrag entdeckt mit der Beschreibung: added by AGOBOT-KU Worm. Hier noch mein Hijack-log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:18:15, on 24.07.2007 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16473) Boot mode: Normal Running processes: C:\Windows\system32\taskeng.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Windows Defender\MSASCui.exe C:\Program Files\Apoint\Apoint.exe C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe C:\Program Files\Sony\ISB Utility\ISBMgr.exe C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe C:\Windows\System32\igfxtray.exe C:\Windows\System32\hkcmd.exe C:\Windows\System32\igfxpers.exe C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe C:\Windows\system32\taskeng.exe C:\Program Files\Protector Suite QL\psqltray.exe C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE C:\Program Files\Apoint\ApMsgFwd.exe C:\Program Files\Apoint\Apntex.exe C:\Program Files\Infineon\Security Platform Software\PSDrt.exe C:\Program Files\Infineon\Security Platform Software\SpTna.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosAVRC.exe C:\Windows\system32\IfxUAGUI.exe C:\Program Files\Cisco Systems\VPN Client\vpngui.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\Program Files\Mozilla Thunderbird\thunderbird.exe C:\Windows\system32\taskmgr.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe D:\Downies\HiJackThis202.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://partnerpage.google.com/eu.sony.com/de R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:4001 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhost O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\PROGRA~1\GOOGLE~1\BAE.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint\Apoint.exe O4 - HKLM\..\Run: [DRCU] "C:\Program Files\Sony\DRCU\DRCU.exe" O4 - HKLM\..\Run: [VAIOCameraUtility] "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" O4 - HKLM\..\Run: [ISBMgr.exe] "C:\Program Files\Sony\ISB Utility\ISBMgr.exe" O4 - HKLM\..\Run: [PSQLLauncher] "C:\Program Files\Protector Suite QL\launcher.exe" /startup O4 - HKLM\..\Run: [avgnt] "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [IFXSPMGT] C:\Windows\system32\IFXSPMGT.exe /NotifyLogon O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST') O4 - Startup: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: Adobe Acrobat - Schnellstart.lnk = ? O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe O4 - Global Startup: Bluetooth Manager.lnk = ? O4 - Global Startup: VPN Client.lnk = ? O8 - Extra context menu item: An vorhandenes PDF anfügen - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: RSS-Support-Site zu VAIO Information FLOW hinzufügen - C:\Program Files\Sony\VAIO Information FLOW\aiesc.html O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0\bin\npjpi160.dll O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLL O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exe O13 - Gopher Prefix: O17 - HKLM\System\CCS\Services\Tcpip\..\{105751BB-2E28-48A7-AC27-E0B686414C6B}: Domain = ub.uni-heidelberg.de O17 - HKLM\System\CCS\Services\Tcpip\..\{105751BB-2E28-48A7-AC27-E0B686414C6B}: NameServer = 129.206.100.126,129.206.210.127 O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = ub.uni-heidelberg.de O17 - HKLM\System\CS1\Services\Tcpip\..\{105751BB-2E28-48A7-AC27-E0B686414C6B}: Domain = ub.uni-heidelberg.de O17 - HKLM\System\CS1\Services\Tcpip\..\{105751BB-2E28-48A7-AC27-E0B686414C6B}: NameServer = 129.206.100.126,129.206.210.127 O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = ub.uni-heidelberg.de O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing) O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - C:\Windows\system32\IFXSPMGT.exe O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - C:\Windows\system32\IFXTCS.exe O23 - Service: lxbc_device - - C:\Windows\system32\lxbccoms.exe O23 - Service: MSCSPTISRV - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: PACSPTISVR - Unknown owner - C:\Program Files\Common Files\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: Personal Secure Drive-Dienst (PersonalSecureDriveService) - Infineon Technologies AG - C:\Windows\system32\IfxPsdSv.exe O23 - Service: SonicStage Back-End Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SsBeSvc.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AVLib\SPTISRV.exe O23 - Service: SonicStage SCSI Service (SSScsiSV) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\AvLib\SSScsiSV.exe O23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe O23 - Service: VAIO Entertainment TV Device Arbitration Service - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCs\VzHardwareResourceManager\VzHardwareResourceManager.exe O23 - Service: VAIO Event Service - Sony Corporation - C:\Program Files\Sony\VAIO Event Service\VESMgr.exe O23 - Service: VAIO Media Integrated Server (VAIOMediaPlatform-IntegratedServer-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\VMISrv.exe O23 - Service: VAIO Media Integrated Server (HTTP) (VAIOMediaPlatform-IntegratedServer-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe O23 - Service: VAIO Media Integrated Server (UPnP) (VAIOMediaPlatform-IntegratedServer-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Media Gateway Server (VAIOMediaPlatform-Mobile-Gateway) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\VmGateway.exe O23 - Service: VAIO Media Content Collection (VAIOMediaPlatform-UCLS-AppServer) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\UCLS.exe O23 - Service: VAIO Media Content Collection (HTTP) (VAIOMediaPlatform-UCLS-HTTP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\SV_Httpd.exe O23 - Service: VAIO Media Content Collection (UPnP) (VAIOMediaPlatform-UCLS-UPnP) - Sony Corporation - C:\Program Files\Sony\VAIO Media Integrated Server\Platform\UPnPFramework.exe O23 - Service: VAIO Entertainment UPnP Client Adapter (Vcsw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe O23 - Service: VAIO Entertainment Database Service (VzCdbSvc) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe O23 - Service: VAIO Entertainment File Import Service (VzFw) - Sony Corporation - C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe -- End of file - 14342 bytes Hoffe ihr könnt mir weiterhelfen und dank im Voraus smuorudi |
24.07.2007, 10:35 | #2 | |
/// Helfer-Team | Trojaner/Wurm? Firefox verschlingt 40%meiner Cpu und will als server agieren Hallo.
__________________Zitat:
__________________ |
24.07.2007, 12:14 | #3 |
| Trojaner/Wurm? Firefox verschlingt 40%meiner Cpu und will als server agieren es steht nur unter schlüssel: HK_LM:Run, die Felder unter Wert und Kommandozeile sind bei diesem eintrag leer.
__________________Ich poste hier mal ein Teil des Logs von Spybot: --- Search result list --- --- System information --- Unknown Windows version 6.0 (Build: 6000) / MSXML4SP2: FIX: ASP stops responding when calling Response.Redirect to another server using msxml4 sp2 --- Startup entries list --- Located: HK_LM:Run, command: file: Located: HK_LM:Run, Acrobat Assistant 8.0 command: "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" file: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe size: 620152 MD5: a21e70b4f972ca396a80013d0d436350 Located: HK_LM:Run, Adobe Reader Speed Launcher command: "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" file: C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe size: 40048 MD5: 66d4456c920e21bd2188f8cc33680df5 Located: HK_LM:Run, Apoint command: C:\Program Files\Apoint\Apoint.exe file: C:\Program Files\Apoint\Apoint.exe size: 118784 MD5: a50bb4ffb1498327facc0e844039bdf2 Located: HK_LM:Run, avgnt command: "C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe" /min file: C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe size: 327720 MD5: ffc52645ca868e6fe125eb14018e2166 Located: HK_LM:Run, DRCU command: "C:\Program Files\Sony\DRCU\DRCU.exe" file: C:\Program Files\Sony\DRCU\DRCU.exe size: 61440 MD5: 4331b8ad09144e9063f9f2e08105b92d Located: HK_LM:Run, HotKeysCmds command: C:\Windows\system32\hkcmd.exe file: C:\Windows\system32\hkcmd.exe size: 106496 MD5: f8664c1c3314cc3338bdf7502a7e0e8c Located: HK_LM:Run, IFXSPMGT command: C:\Windows\system32\IFXSPMGT.exe /NotifyLogon file: C:\Windows\system32\IFXSPMGT.exe size: 661024 MD5: 694aa4b7b0a1de626c8155cb69604c16 Located: HK_LM:Run, IgfxTray command: C:\Windows\system32\igfxtray.exe file: C:\Windows\system32\igfxtray.exe size: 98304 MD5: fc8c506d32e6f2eaa02d987ab4ca7d4e Located: HK_LM:Run, ISBMgr.exe command: "C:\Program Files\Sony\ISB Utility\ISBMgr.exe" file: C:\Program Files\Sony\ISB Utility\ISBMgr.exe size: 43128 MD5: b11accf18d36af74543ae92538c2e06f Located: HK_LM:Run, NvCplDaemon command: RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup file: C:\Windows\system32\RUNDLL32.EXE size: 44544 MD5: 4b555106290bd117334e9a08761c035a Located: HK_LM:Run, NvMediaCenter command: RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit file: C:\Windows\system32\RUNDLL32.EXE size: 44544 MD5: 4b555106290bd117334e9a08761c035a Located: HK_LM:Run, Persistence command: C:\Windows\system32\igfxpers.exe file: C:\Windows\system32\igfxpers.exe size: 81920 MD5: e4f095f1f8752cf8b6c37de28a78edcb Located: HK_LM:Run, PSQLLauncher command: "C:\Program Files\Protector Suite QL\launcher.exe" /startup file: C:\Program Files\Protector Suite QL\launcher.exe size: 49168 MD5: ac270380c4a64701cf6a7d59fb9d085c Located: HK_LM:Run, VAIOCameraUtility command: "C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe" file: C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe size: 411768 MD5: c97d27f1f0a3a235ecdd92eb26439f77 Located: HK_LM:Run, Windows Defender command: %ProgramFiles%\Windows Defender\MSASCui.exe -hide file: Located: HK_LM:Run, ZoneAlarm Client command: "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" file: C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe size: 959976 MD5: d5b16b68c915074abbb37dd7ed86a07c Located: HK_CU:Run, Sidebar command: C:\Program Files\Windows Sidebar\sidebar.exe /autoRun file: Located: HK_CU:Run, SpybotSD TeaTimer command: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe file: C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe size: 1415824 MD5: 70496eee0ddbe485f658693826f44d38 Located: Startup (allgemein), Adobe Acrobat - Schnellstart.lnk command: C:\Windows\Installer\{AC76BA86-1033-F400-BA7E-000000000003}\_SC_Acrobat.exe file: C:\Windows\Installer\{AC76BA86-1033-F400-BA7E-000000000003}\_SC_Acrobat.exe size: 295606 MD5: 21638d0e7f02d6cb855b76243521f409 Located: Startup (allgemein), Adobe Reader Synchronizer.lnk command: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe file: C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exe size: 734872 MD5: 169c293ce9460a05646d17dc6aa2fb2c Located: Startup (allgemein), Bluetooth Manager.lnk command: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe file: C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe size: 2752512 MD5: ec690a15477cd5fbc14c8189693cd940 Located: Startup (allgemein), VPN Client.lnk command: C:\Windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico file: C:\Windows\Installer\{CCBAA1F7-E5E1-48B2-9ED9-A79C6A37CE78}\Icon3E5562ED7.ico size: 6144 MD5: 85ab6c3089bee58999b434e114e8a64c Located: Startup (Benutzer), OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk command: C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE file: C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE size: 98632 MD5: d91afb6d2a0da7539b74fb5838775d94 Located: WinLogon, igfxcui command: igfxdev.dll file: igfxdev.dll Located: WinLogon, psfus command: C:\Windows\system32\psqlpwd.dll file: C:\Windows\system32\psqlpwd.dll size: 90112 MD5: 8cee602a12031a9686da9a6967dc378d Located: WinLogon, VESWinlogon command: VESWinlogon.dll file: VESWinlogon.dll --- Process list --- PID: 536 ( 4) \SystemRoot\System32\smss.exe PID: 652 ( 640) C:\Windows\system32\csrss.exe size: 7680 MD5: 117B7C8A8B026A5DCE5E3180ED05E823 PID: 692 ( 640) C:\Windows\system32\wininit.exe size: 95744 MD5: D4385B03E8CCCEE6F0EE249F827C1F3E PID: 704 ( 684) C:\Windows\system32\csrss.exe size: 7680 MD5: 117B7C8A8B026A5DCE5E3180ED05E823 PID: 736 ( 692) C:\Windows\system32\services.exe size: 279552 MD5: 329CF3C97CE4C19375C8ABCABAE258B0 PID: 748 ( 692) C:\Windows\system32\lsass.exe size: 7680 MD5: 6A0E382E74280E4CC0DF17FE2661D003 PID: 756 ( 692) C:\Windows\system32\lsm.exe size: 210944 MD5: 77F52395637906269B91264FFE576B51 PID: 844 ( 684) C:\Windows\system32\winlogon.exe size: 308224 MD5: 9F75392B9128A91ABAFB044EA350BAAD PID: 956 ( 736) C:\Windows\system32\svchost.exe size: 22016 MD5: 10DA15933D582D2FEDCF705EFE394B09 PID: 1016 ( 736) C:\Windows\system32\svchost.exe size: 22016 MD5: 10DA15933D582D2FEDCF705EFE394B09 PID: 1052 ( 736) C:\Windows\System32\svchost.exe size: 22016 MD5: 10DA15933D582D2FEDCF705EFE394B09 PID: 1144 ( 736) C:\Windows\System32\svchost.exe size: 22016 MD5: 10DA15933D582D2FEDCF705EFE394B09 PID: 1224 ( 736) C:\Windows\System32\svchost.exe size: 22016 MD5: 10DA15933D582D2FEDCF705EFE394B09 PID: 1244 ( 736) C:\Windows\system32\svchost.exe size: 22016 MD5: 10DA15933D582D2FEDCF705EFE394B09 PID: 1360 ( 736) C:\Windows\system32\SLsvc.exe size: 2605568 MD5: A1DCD30534835CB67733AD00175125A6 PID: 1396 ( 736) C:\Windows\system32\svchost.exe size: 22016 MD5: 10DA15933D582D2FEDCF705EFE394B09 PID: 1544 ( 736) C:\Windows\system32\svchost.exe size: 22016 MD5: 10DA15933D582D2FEDCF705EFE394B09 PID: 1596 ( 736) C:\Windows\System32\ZoneLabs\vsmon.exe size: 79400 MD5: A00304590A37660D9C57F64FF7AAB4B1 PID: 1644 (1092) C:\Program Files\Protector Suite QL\upeksvr.exe size: 21504 MD5: 1C72FC98B737D7A697E586247730A785 PID: 296 ( 736) C:\Windows\System32\spoolsv.exe size: 124928 MD5: DA612EF2556776DF2630B68BF2D48935 PID: 624 ( 736) C:\Program Files\AntiVir PersonalEdition Classic\avguard.exe size: 204840 MD5: 9E2CBEF5D6FE51D55AABF22F4EDC8AB3 PID: 640 ( 736) C:\Windows\system32\svchost.exe size: 22016 MD5: 10DA15933D582D2FEDCF705EFE394B09 PID: 1288 ( 736) C:\Program Files\AntiVir PersonalEdition Classic\sched.exe size: 57896 MD5: 25C11F08FBA4DBFA6741DEC9ABA779F2 PID: 856 ( 736) C:\Program Files\Cisco Systems\VPN Client\cvpnd.exe size: 1516584 MD5: 08D8FA119F2AD6AC0377FB667523482E PID: 2080 ( 736) C:\Windows\system32\IFXSPMGT.exe size: 661024 MD5: 694AA4B7B0A1DE626C8155CB69604C16 PID: 2176 ( 736) C:\Windows\system32\IFXTCS.exe size: 824864 MD5: F5518BDC73E67CF2E0F88796A0F3BCD5 PID: 2268 ( 736) C:\Windows\system32\lxbccoms.exe size: 537520 MD5: 31E0CCB891B94056E062886CB69174D2 PID: 2304 ( 736) C:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe size: 29178224 MD5: D07C9575726797B0E9069E1108A1C483 PID: 2340 ( 736) C:\Windows\system32\IfxPsdSv.exe size: 136736 MD5: 219E225E6663B478DA5DC396ACA75548 PID: 2368 ( 736) C:\Windows\system32\svchost.exe size: 22016 MD5: 10DA15933D582D2FEDCF705EFE394B09 PID: 2408 ( 736) C:\Program Files\Microsoft SQL Server\90\Shared\sqlbrowser.exe size: 242544 MD5: D2B096CD2F56FAC6EEEED9A77DDF6DC8 PID: 2420 ( 736) C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe size: 89968 MD5: 54902536AAD0E9B99BC65F89C0CAF93F PID: 2456 ( 736) C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exe size: 90112 MD5: ACF85E15E147826A8869D78C937ACF09 PID: 2612 ( 736) C:\Windows\system32\svchost.exe size: 22016 MD5: 10DA15933D582D2FEDCF705EFE394B09 PID: 2632 ( 736) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe size: 77824 MD5: 76148C3159718B701252F87B067904A6 PID: 2656 ( 736) C:\Program Files\Sony\VAIO Event Service\VESMgr.exe size: 182392 MD5: 3587947466E8E9256DB05ABE3A9D398F PID: 2692 ( 736) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VCSW\VCSW.exe size: 274432 MD5: 4D6644132F26EF055A1F754B1C38C084 PID: 2708 ( 736) C:\Windows\System32\svchost.exe size: 22016 MD5: 10DA15933D582D2FEDCF705EFE394B09 PID: 2772 ( 736) C:\Windows\system32\SearchIndexer.exe size: 287744 MD5: 5DE40982E3AE45DC00586A93637B351B PID: 2848 ( 736) C:\Windows\system32\DRIVERS\xaudio.exe size: 386560 MD5: 28DC5D626E036A75A572556F0A6EB1F6 PID: 2956 (1224) C:\Windows\system32\WUDFHost.exe size: 143360 MD5: 8D5DE07842A2B50D8B20EA1CD44AC97F PID: 3124 ( 736) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzCdbSvc.exe size: 172032 MD5: 5FEB20D9ED9A2BD4F234222B0A3BB855 PID: 3236 ( 736) C:\Program Files\Common Files\Sony Shared\VAIO Entertainment Platform\VzCdb\VzFw.exe size: 135168 MD5: 3757DFD3C07896EF660D4060366E7B4E PID: 3288 (2656) C:\Program Files\Sony\VAIO Event Service\VESMgrSub.exe size: 100472 MD5: B0C84CEA4FE07231BA87A054AF95984D PID: 3628 (1244) C:\Windows\system32\taskeng.exe size: 166400 MD5: 1226E9FAE5B8508801EC974E3C9D9C14 PID: 2732 (1244) C:\Windows\system32\taskeng.exe size: 166400 MD5: 1226E9FAE5B8508801EC974E3C9D9C14 PID: 3140 (1224) C:\Windows\system32\Dwm.exe size: 83456 MD5: E87B968F3D49117445893EB0503FE34F PID: 2496 (2540) C:\Windows\Explorer.EXE size: 2923520 MD5: FD8C53FB002217F6F888BCF6F5D7084D PID: 2332 (2496) C:\Program Files\Windows Defender\MSASCui.exe size: 1006264 MD5: 9AD9E2FB2811123DA13DE84CC154AB77 PID: 2120 (2496) C:\Program Files\Apoint\Apoint.exe size: 118784 MD5: A50BB4FFB1498327FACC0E844039BDF2 PID: 4068 (2496) C:\Program Files\Sony\VAIO Camera Utility\VCUServe.exe size: 411768 MD5: C97D27F1F0A3A235ECDD92EB26439F77 PID: 2740 (2496) C:\Program Files\Sony\ISB Utility\ISBMgr.exe size: 43128 MD5: B11ACCF18D36AF74543AE92538C2E06F PID: 3200 (2496) C:\Program Files\AntiVir PersonalEdition Classic\avgnt.exe size: 327720 MD5: FFC52645CA868E6FE125EB14018E2166 PID: 3576 (2496) C:\Windows\System32\igfxtray.exe size: 98304 MD5: FC8C506D32E6F2EAA02D987AB4CA7D4E PID: 948 (2496) C:\Windows\System32\hkcmd.exe size: 106496 MD5: F8664C1C3314CC3338BDF7502A7E0E8C PID: 3768 (2496) C:\Windows\System32\igfxpers.exe size: 81920 MD5: E4F095F1F8752CF8B6C37DE28A78EDCB PID: 4112 (2496) C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe size: 620152 MD5: A21E70B4F972CA396A80013D0D436350 PID: 4176 (2496) C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe size: 959976 MD5: D5B16B68C915074ABBB37DD7ED86A07C PID: 4204 (2496) C:\Program Files\Windows Sidebar\sidebar.exe size: 1196032 MD5: 43632977504B323F8A41BF7A9965C453 PID: 4224 (2496) C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe size: 1415824 MD5: 70496EEE0DDBE485F658693826F44D38 PID: 4232 ( 956) C:\Windows\system32\igfxext.exe size: 122880 MD5: 0521491E9AC49B78E1F2A55AD147B40A PID: 4276 ( 956) C:\Windows\system32\igfxsrvc.exe size: 196608 MD5: 3E1295FD7E79153BB8B8BA2EABE078CB PID: 4348 (4012) C:\Program Files\Protector Suite QL\psqltray.exe size: 54288 MD5: A9DEE7CCAA5E1BF1374B08C27E60093B PID: 4376 (3288) C:\Program Files\Sony\VAIO Power Management\SPMgr.exe size: 923768 MD5: C33EA41BFCF11DCA958831CA05DFB1A9 PID: 4420 (2496) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe size: 2752512 MD5: EC690A15477CD5FBC14C8189693CD940 PID: 4472 (2496) C:\Program Files\Microsoft Office\Office12\ONENOTEM.EXE size: 98632 MD5: D91AFB6D2A0DA7539B74FB5838775D94 PID: 4544 (1244) C:\Windows\system32\taskeng.exe size: 166400 MD5: 1226E9FAE5B8508801EC974E3C9D9C14 PID: 4592 (4544) C:\Program Files\Sony\Wireless Switch Setting Utility\Switcher.exe size: 465016 MD5: 83E9CD075F8D80D19609AB0FF6EAF5D6 PID: 4600 (4544) C:\Program Files\Sony\VAIO Update 3\VAIOUpdt.exe size: 546936 MD5: 6FB6057066E2AC3434AFD6152C471840 PID: 5080 (3212) C:\Program Files\Infineon\Security Platform Software\PSDrt.exe size: 173600 MD5: 5C26414D48936162D779AA2348499513 PID: 5112 (3212) C:\Program Files\Infineon\Security Platform Software\SpTna.exe size: 656928 MD5: D7BB0BCF753D6B450ED7ED7604FE0DBA PID: 5792 (2120) C:\Program Files\Apoint\ApMsgFwd.exe size: 42544 MD5: 7890A95BBA6EE9EB0E4539F5270A6201 PID: 6052 (4420) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe size: 278528 MD5: A7B50F4EE28D7AA1F8AC981C2F2980B1 PID: 684 (4420) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe size: 69632 MD5: 2C92B17E820094F37037B6CE114BEB69 PID: 2952 (1656) C:\Program Files\Apoint\Apntex.exe size: 40960 MD5: 99A7B10500920E5CC79B700927B18BC1 PID: 4456 (4420) C:\Program Files\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe size: 270336 MD5: 8C35DB52F07A78E8DF230D76F141FD29 PID: 2760 ( 736) C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe size: 654848 MD5: 227846995AFEEFA70D328BF5334A86A5 PID: 5444 (2496) C:\Program Files\Mozilla Firefox\firefox.exe size: 7644008 MD5: BFFC1C8951A31B17ECF30D510A07CC33 PID: 452 ( 736) C:\Program Files\Windows Media Player\wmpnetwk.exe size: 895488 MD5: ACB2E63D50157E3EA7140F29D9E76A48 PID: 1568 (5736) C:\Program Files\AntiVir PersonalEdition Classic\avnotify.exe size: 139304 MD5: CFF7EAEA9722ECB3232E444C82012CB7 PID: 5284 ( 956) C:\Windows\system32\wbem\wmiprvse.exe size: 245248 MD5: CD8A7F4847DD181903E6B2F1924E723E PID: 4244 (4224) C:\Program Files\Spybot - Search & Destroy\SpybotSD.exe size: 4393096 MD5: 09CA174A605B480318731E691DC98539 PID: 0 ( 0) [System Process] PID: 4 ( 0) System PID: 1312 (1144) audiodg.exe PID: 3932 ( 956) C:\Windows\System32\mobsync.exe size: 95232 MD5: 9C632DC0F1B6D79B05F46A4A5349CEF4 |
24.07.2007, 12:34 | #4 | |
/// Helfer-Team | Trojaner/Wurm? Firefox verschlingt 40%meiner Cpu und will als server agieren Hm. Es gab hier im Board vor einiger Zeit einen vergleichbaren Fall, der sich als Fehlalarm entpuppte. Allerdings erklärt das nicht das Verhalten des Firefox. Bitte poste ein Log von Silentrunners nach dieser Anleitung: Zitat:
__________________ Alle Tipps und Anleitungen ohne Gewähr |
24.07.2007, 14:42 | #5 |
| Trojaner/Wurm? Firefox verschlingt 40%meiner Cpu und will als server agieren Also ich bin kein Experte. Aber soweit ich weiss, ist es normal, dass Firefox als Server fungieren will. War bei mir schon seit der Erstinstallation vor Ewigkeiten so. Aber wie gesagt, ich bin da kein Profi. |
Themen zu Trojaner/Wurm? Firefox verschlingt 40%meiner Cpu und will als server agieren |
add-on, adobe, agobot-ku, antivir, avg, avira, bho, browser, cpu, defender, drivers, error, excel, firefox, hijackthis, internet, internet explorer, konvertieren, monitor, mozilla, mozilla firefox, mozilla thunderbird, pdf-datei, rundll, security, senden, server, software, starten, symantec, toolbars, trend micro, vista, windows, windows defender, windows sidebar, windows\system32\drivers |