|
Plagegeister aller Art und deren Bekämpfung: Habe TR/Vundo.Gen... brauche Hilfe!!!!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
22.04.2008, 19:30 | #1 |
| Habe TR/Vundo.Gen... brauche Hilfe!!!! hi, also auch auf die gefahr hin gelächter zu ernten werde ich mal mein problem schildern. im klartext : ich weiß nicht wie ich "TR/Vundo.Gen" runtebekomme ich habe auch keine ahnung wie ich logfiles erstelle geschweige denn was sie sind *g* ich habe mir die themen über das vorhandene problem durchgelesen doch gucke ich da wie ein "schwein ins uhrwerk" vielleicht hat ja jemand mal zeit mir anfängerfreundliche ratschläge zu geben oder einen link zu einem newbieguide *g* vielen dank für eure zeit braucheHilfe |
22.04.2008, 20:13 | #2 |
Gast | Habe TR/Vundo.Gen... brauche Hilfe!!!! Hallo und Herzlich Willkommen
__________________Bitte erstelle als erstes ein HijackThis Logfiel. Den Link und die genaue Beschreibung dazu findest du in meiner Signatur |
22.04.2008, 22:30 | #3 |
| Habe TR/Vundo.Gen... brauche Hilfe!!!! Hier der logfile
__________________Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 20:36:17, on 22.04.2008 Platform: Windows Vista (WinNT 6.00.1904) MSIE: Internet Explorer v7.00 (7.00.6000.16643) Boot mode: Normal Running processes: C:\Windows\System32\smss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\csrss.exe C:\Windows\system32\wininit.exe C:\Windows\system32\services.exe C:\Windows\system32\winlogon.exe C:\Windows\system32\lsass.exe C:\Windows\system32\lsm.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\System32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\svchost.exe C:\Windows\system32\SLsvc.exe C:\Windows\system32\Ati2evxx.exe C:\Windows\system32\svchost.exe C:\Windows\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Windows\system32\WLANExt.exe C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe C:\Program Files\ATK Hotkey\ASLDRSrv.exe C:\Program Files\ATKGFNEX\GFNEXSrv.exe C:\Windows\System32\spoolsv.exe C:\Windows\system32\Dwm.exe C:\Windows\Explorer.EXE C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe C:\Program Files\ATK Hotkey\Hcontrol.exe C:\Program Files\ATKOSD2\ATKOSD2.exe C:\Program Files\Nero\Nero 7\InCD\InCD.exe C:\Program Files\Wireless Console 2\wcourier.exe C:\Program Files\ASUS\Splendid\ACMON.exe C:\Program Files\P4G\BatteryLife.exe C:\Windows\system32\taskeng.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Windows\system32\svchost.exe C:\Windows\System32\ACEngSvr.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE C:\Windows\RtHDVCpl.exe C:\Program Files\ATK Hotkey\ATKOSD.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\Program Files\ASUS\ATK Media\DMedia.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANOTIF.EXE C:\Program Files\ATK Hotkey\KBFiltr.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe C:\Windows\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe C:\Program Files\Intel\Wireless\Bin\EvtEng.exe C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe C:\Program Files\Common Files\LightScribe\LSSrvc.exe C:\Windows\system32\PnkBstrA.exe C:\Windows\system32\svchost.exe C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe D:\SpyDoctor\Spyware Doctor\pctsAuxs.exe D:\SpyDoctor\Spyware Doctor\pctsSvc.exe C:\Program Files\SpywareDetector\SDService.exe D:\SpyDoctor\Spyware Doctor\pctsTray.exe C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe C:\Windows\system32\svchost.exe C:\Windows\System32\svchost.exe C:\Windows\system32\SearchIndexer.exe C:\Windows\system32\taskeng.exe C:\Program Files\ASUS\ASUS Live Update\ALU.exe C:\Windows\system32\wbem\wmiprvse.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Windows\ASScrPro.exe C:\Windows\system32\wbem\unsecapp.exe C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Programme\Winamp\winampa.exe C:\Program Files\iTunes\iTunesHelper.exe C:\Program Files\Windows Sidebar\sidebar.exe C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe C:\Program Files\Skype\Phone\Skype.exe C:\Windows\ehome\ehtray.exe C:\Program Files\MySpace\IM\MySpaceIM.exe C:\Program Files\Veoh Networks\Veoh\VeohClient.exe C:\Program Files\Windows Media Player\wmpnscfg.exe C:\Windows\ehome\ehmsas.exe C:\Program Files\Windows Media Player\wmpnetwk.exe C:\Program Files\WinZip\WZQKPICK.EXE C:\Program Files\iPod\bin\iPodService.exe C:\Program Files\Skype\Plugin Manager\skypePM.exe C:\Program Files\MySpace\IM\MySpaceIM.exe C:\Windows\system32\svchost.exe C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Program Files\Mozilla Firefox\firefox.exe D:\Hijack\HijackThis.exe C:\Windows\system32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ebay.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.asus.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O2 - BHO: XTTBPos00 - {055FD26D-3A88-4e15-963D-DC8493744B1D} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-D42A53123C75} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\NppBho.dll O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file) |
22.04.2008, 22:31 | #4 |
| Habe TR/Vundo.Gen... brauche Hilfe!!!! O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: Show Norton Toolbar - {90222687-F593-4738-B738-FBEE9C7B26DF} - C:\Program Files\Common Files\Symantec Shared\coShared\Browser\1.5\UIBHO.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe O4 - HKLM\..\Run: [InCD] C:\Program Files\Nero\Nero 7\InCD\InCD.exe O4 - HKLM\..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe O4 - HKLM\..\Run: [Skytel] Skytel.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files\ASUS\ATK Media\DMEDIA.EXE O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe O4 - HKLM\..\Run: [IaNvSrv] C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\ASScrProlog.exe O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [ISTray] "D:\SpyDoctor\Spyware Doctor\pctsTray.exe" O4 - HKLM\..\Run: [SD_Tips] iexplore http://www.spywaredetector.net/tips_vista.htm O4 - HKLM\..\Run: [SystemTraySD] C:\Program Files\SpywareDetector\SDSystemTray.exe -AUTO O4 - HKLM\..\Run: [SDAutoLiveupdate] C:\Program Files\SpywareDetector\LiveUpdateSD.exe -AUTO O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe O4 - HKCU\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe O4 - HKCU\..\Run: [Orb] "C:\Program Files\Winamp Remote\bin\OrbTray.exe" /background O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe O4 - HKCU\..\Run: [MSServer] rundll32.exe C:\Users\Joe\AppData\Local\Temp\mlJYqPgf.dll,#1 O4 - HKCU\..\Run: [AntiSpyware] C:\Program Files\AntiSpywareApp\AntiSpyware.exe O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST') O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user') O4 - Global Startup: WinZip Quick Pick.lnk = C:\Program Files\WinZip\WZQKPICK.EXE O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing) O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programs\PartyGaming\PartyPoker\RunApp.exe (file missing) O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe O13 - Gopher Prefix: O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe O23 - Service: AntiSpyware Scanning Engine (AntiSpywareSrv) - Unknown owner - C:\Program Files\AntiSpywareApp\AntiSpyware.srv.exe O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files\ATK Hotkey\ASLDRSrv.exe O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe O23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: COM Host (comHost) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\VAScanner\comHost.exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Nero\Nero 7\InCD\InCDsrv.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: Symantec IS Password Validation (ISPwdSvc) - Symantec Corporation - C:\Program Files\Norton Internet Security\isPwdSvc.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe O23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate Notice Ex) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe O23 - Service: LiveUpdate Notice Service - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}\PIFSvc.exe O23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\SpyDoctor\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\SpyDoctor\Spyware Doctor\pctsSvc.exe O23 - Service: SDService - Max Secure Software - C:\Program Files\SpywareDetector\SDService.exe O23 - Service: spmgr - Unknown owner - C:\Program Files\ASUS\NB Probe\SPM\spmgr.exe O23 - Service: SpyHunter3 Service - Unknown owner - C:\Program Files\Enigma Software Group\SpyHunter\SHService.exe (file missing) O23 - Service: Symantec Core LC - Unknown owner - C:\Program Files\Common Files\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: Symantec AppCore Service (SymAppCore) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\AppCore\AppSvc32.exe O23 - Service: UPnPService - Magix AG - C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe -- End of file - 15939 bytes |
22.04.2008, 22:32 | #5 |
| Habe TR/Vundo.Gen... brauche Hilfe!!!! Hi und ...hier ist auch noch ComboFix ComboFix 08-04-20.5 - Joe 2008-04-22 22:39:30.1 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6000.0.1252.1.1031.18.1155 [GMT 2:00] ausgeführt von:: C:\Users\Joe\Desktop\ComboFix.exe * Neuer Wiederherstellungspunkt wurde erstellt . ((((((((((((((((((((((( Dateien erstellt von 2008-03-22 bis 2008-04-22 )))))))))))))))))))))))))))))) . Keine neuen Dateien erstellt in diesem Zeitraum . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-04-22 20:34 --------- d---a-w C:\ProgramData\TEMP 2008-04-22 20:33 --------- d-----w C:\Users\Joe\AppData\Roaming\Skype 2008-04-22 20:31 --------- d-----w C:\Program Files\SpywareDetector 2008-04-22 20:23 --------- d-----w C:\Users\Joe\AppData\Roaming\Winamp 2008-04-22 20:23 --------- d-----w C:\ProgramData\P4G 2008-04-22 20:23 --------- d-----w C:\ProgramData\Microsoft Help 2008-04-22 20:23 --------- d-----w C:\ProgramData\{623D32E9-0C62-4453-AD44-98B31F52A5E 1} 2008-04-22 20:23 --------- d-----w C:\Program Files\Microsoft Works 2008-04-22 20:23 --------- d-----w C:\Program Files\ICQToolbar 2008-04-22 20:23 --------- d-----w C:\Program Files\Google 2008-04-22 20:23 --------- d-----w C:\Program Files\Common Files\Symantec Shared 2008-04-22 20:23 --------- d-----w C:\Program Files\Common Files\Skype 2008-04-22 20:23 --------- d-----w C:\Program Files\Common Files\PX Storage Engine 2008-04-22 18:51 --------- d-----w C:\Users\Joe\AppData\Roaming\skypePM 2008-04-22 18:12 --------- d-----w C:\Program Files\AntiSpywareApp 2008-04-22 18:10 --------- d-----w C:\Users\Joe\AppData\Roaming\Antispyware 2008-04-22 16:57 22,328 ----a-w C:\Windows\system32\drivers\PnkBstrK.sys 2008-04-21 11:34 --------- d-----w C:\Program Files\Enigma Software Group 2008-04-21 11:29 --------- d-----w C:\Program Files\Anti-Spy.Info 2008-04-20 11:55 --------- d-----w C:\Users\Joe\AppData\Roaming\Babylon 2008-04-20 11:55 --------- d-----w C:\ProgramData\Babylon 2008-04-16 12:34 --------- d-----w C:\Users\Joe\AppData\Roaming\PC Tools 2008-04-12 11:12 --------- d-----w C:\Users\Joe\AppData\Roaming\Apple Computer 2008-04-09 11:24 --------- d-----w C:\Program Files\Windows Mail 2008-04-08 10:04 --------- d--h--w C:\Program Files\InstallShield Installation Information 2008-04-05 20:58 --------- d-----w C:\Program Files\Safari 2008-04-05 20:52 --------- d-----w C:\ProgramData\Apple Computer 2008-04-05 20:52 --------- d-----w C:\Program Files\iTunes 2008-04-05 20:52 --------- d-----w C:\Program Files\iPod 2008-04-05 20:50 --------- d-----w C:\Program Files\Common Files\Apple 2008-04-05 20:36 --------- d-----w C:\Program Files\QuickTime 2008-04-04 08:36 --------- d-----w C:\Program Files\Common Files\Blizzard Entertainment 2008-04-03 06:46 --------- d-----w C:\Program Files\Common Files\NSV 2008-04-02 09:47 --------- d-----w C:\ProgramData\WinZip 2008-04-02 09:42 --------- d-----w C:\Program Files\AbiSuite2 2008-04-01 19:58 --------- d-----w C:\Program Files\Common Files\Adobe 2008-03-25 08:08 --------- d-----w C:\ProgramData\Symantec 2008-03-22 15:08 --------- d-----w C:\Users\Joe\AppData\Roaming\mIRC 2008-03-22 14:53 --------- d-----w C:\Program Files\mIRC 2008-03-14 17:29 --------- d-----w C:\Users\Joe\AppData\Roaming\Audacity 2008-03-14 17:22 --------- d-----w C:\Program Files\Audacity 1.3 Beta (Unicode) 2008-03-11 13:48 --------- d-----w C:\Program Files\Norton Internet Security 2008-03-08 02:14 148,992 ----a-w C:\Windows\system32\drivers\ks.sys 2008-03-07 12:40 13,035 ----a-w C:\Windows\system32\drivers\SymRedir.cat 2008-03-07 12:40 1,358 ----a-w C:\Windows\system32\drivers\SymRedir.inf 2008-03-07 12:39 39,984 ----a-w C:\Windows\system32\drivers\symids.sys 2008-03-07 12:39 37,936 ----a-w C:\Windows\system32\drivers\symndisv.sys 2008-03-07 12:39 27,696 ----a-w C:\Windows\system32\drivers\symredrv.sys 2008-03-07 12:39 191,536 ----a-w C:\Windows\system32\drivers\symtdi.sys 2008-03-07 12:39 145,968 ----a-w C:\Windows\system32\drivers\symfw.sys 2008-03-07 12:39 12,848 ----a-w C:\Windows\system32\drivers\symdns.sys 2008-03-06 20:32 706 ----a-w C:\Windows\system32\drivers\COH_Mon.inf 2008-03-06 20:32 23,904 ----a-w C:\Windows\system32\drivers\COH_Mon.sys 2008-03-06 20:32 10,537 ----a-w C:\Windows\system32\drivers\COH_Mon.cat 2008-03-04 08:37 --------- d-----w C:\ProgramData\Avira 2008-03-04 08:37 --------- d-----w C:\Program Files\Avira 2008-02-28 21:58 --------- d-----w C:\Program Files\Veoh Networks 2008-02-26 19:48 --------- d-----w C:\ProgramData\OrbNetworks 2008-02-26 19:47 --------- d-----w C:\Program Files\Winamp Remote 2008-02-23 11:32 --------- d-----w C:\Program Files\DivX 2008-02-21 04:43 52,736 ----a-w C:\Windows\AppPatch\iebrshim.dll 2008-02-13 21:41 537,600 ----a-w C:\Windows\AppPatch\AcLayers.dll 2008-02-13 21:41 449,536 ----a-w C:\Windows\AppPatch\AcSpecfc.dll 2008-02-13 21:41 2,560 ----a-w C:\Windows\AppPatch\AcRes.dll 2008-02-13 21:41 2,144,256 ----a-w C:\Windows\AppPatch\AcGenral.dll 2008-02-13 21:41 173,056 ----a-w C:\Windows\AppPatch\AcXtrnal.dll 2007-12-24 14:08 22,328 ----a-w C:\Users\Joe\AppData\Roaming\PnkBstrK.sys 2007-12-12 16:26 32 ----a-w C:\ProgramData\ezsid.dat 2007-12-12 14:59 174 --sha-w C:\Program Files\desktop.ini . (((((((((((((((((((((((((((( Autostart Punkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt. [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shel liconoverlayidentifiers\ADSMOverlayIcon1] @={A8D448F4-0431-45AC-9F5E-E1B434AB2249} [HKEY_CLASSES_ROOT\CLSID\{A8D448F4-0431-45AC-9F5E-E1B434AB2249}] 2007-06-02 02:08 143360 --a------ C:\Program Files\ASUS\ASUS Data Security Manager\OverlayIconShlExt1.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Sidebar"="C:\Program Files\Windows Sidebar\sidebar.exe" [2008-01-10 11:27 1232896] "swg"="C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe" [2007-12-12 16:03 171448] "Skype"="C:\Program Files\Skype\Phone\Skype.exe" [2008-02-01 17:22 21898024] "ehTray.exe"="C:\Windows\ehome\ehTray.exe" [2006-11-02 14:35 125440] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 22:32 8699904] "Orb"="C:\Program Files\Winamp Remote\bin\OrbTray.exe" [2008-01-07 22:02 495616] "Veoh"="C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" [2008-04-01 18:35 3587120] "WMPNSCFG"="C:\Program Files\Windows Media Player\WMPNSCFG.exe" [2006-11-02 14:36 201728] "AntiSpyware"="C:\Program Files\AntiSpywareApp\AntiSpyware.exe" [2008-04-21 22:17 19887352] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "SMSERIAL"="C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe" [2006-11-22 11:31 630784] "NeroFilterCheck"="C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe" [2007-03-26 21:12 161328] "InCD"="C:\Program Files\Nero\Nero 7\InCD\InCD.exe" [2007-03-26 20:42 1057328] "StartCCC"="C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2006-11-10 21:35 90112] "RtHDVCpl"="RtHDVCpl.exe" [2007-07-06 05:06 4669440 C:\Windows\RtHDVCpl.exe] "Skytel"="Skytel.exe" [2007-06-15 10:45 1826816 C:\Windows\SkyTel.exe] "ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 23:58 115816] "ATKMEDIA"="C:\Program Files\ASUS\ATK Media\DMEDIA.EXE" [2006-11-02 17:27 61440] "IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe" [2007-07-24 12:02 174616] "IaNvSrv"="C:\Program Files\Intel\Intel Matrix Storage Manager\OROM\IaNvSrv\IaNvSrv.exe" [2007-07-24 12:02 33304] "JMB36X IDE Setup"="C:\Windows\RaidTool\xInsIDE.exe" [2007-03-20 08:36 36864] "SynTPEnh"="C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" [2007-03-01 15:24 857648] "ASUS Screen Saver Protector"="C:\Windows\ASScrPro.exe" [2007-10-24 06:51 33136] "ASUS Camera ScreenSaver"="C:\Windows\ASScrProlog.exe" [2007-10-24 06:51 37232] "VirtualCloneDrive"="C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" [2006-04-29 15:21 94208] "SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 02:11 132496] "avgnt"="C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" [2008-04-15 15:08 262401] "Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2008-01-11 22:16 39792] "WinampAgent"="C:\Programme\Winamp\winampa.exe" [2008-04-01 20:49 36352] "QuickTime Task"="C:\Program Files\QuickTime\QTTask.exe" [2008-03-28 23:37 413696] "iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2008-03-30 10:36 267048] "SD_Tips"="iexplore http://www.spywaredetector.net/tips_vista.htm" [] "SystemTraySD"="C:\Program Files\SpywareDetector\SDSystemTray.exe" [2008-03-19 10:16 714192] "SDAutoLiveupdate"="C:\Program Files\SpywareDetector\LiveUpdateSD.exe" [2008-03-19 10:16 423376] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "MySpaceIM"="C:\Program Files\MySpace\IM\MySpaceIM.exe" [2008-02-01 22:32 8699904] C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\ WinZip Quick Pick.lnk - C:\Program Files\WinZip\WZQKPICK.EXE [2008-02-08 11:10:00 394856] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\SDNotify] C:\Program Files\SpywareDetector\SDNotify.dll 2008-03-05 10:55 167936 C:\Program Files\SpywareDetector\SDNotify.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "msacm.ac3acm"= ac3acm.acm "msacm.lameacm"= lameACM.acm [HKEY_LOCAL_MACHINE\software\microsoft\security center] "UacDisableNotify"=dword:00000001 "InternetSettingsDisableNotify"=dword:00000001 "AutoUpdateDisableNotify"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\DomainProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{7E481CCD-A80C-49DE-803E-9A3A1F073047}"= TCP:6004|C:\Program Files\Microsoft Office\Office12\outlook.exe:Microsoft Office Outlook "{3223124B-0094-43D7-8FB1-CE354B8D6369}"= UDP:C:\Windows\System32\PnkBstrA.exeZunge raus nkBstrA "{EF2568CD-4DE2-4114-B674-E42D118420EC}"= TCP:C:\Windows\System32\PnkBstrA.exeZunge raus nkBstrA "{D9728A33-6C22-4958-A8BD-E56B35C78E2C}"= UDP:C:\Windows\System32\PnkBstrB.exeZunge raus nkBstrB "{E434316B-3665-4D26-966B-C51733F0D148}"= TCP:C:\Windows\System32\PnkBstrB.exeZunge raus nkBstrB "{B2AC6193-F126-4CA6-A04A-7CE09BE39E24}"= UDPgroßes Grinsen :\Spiele\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM) "{FED735A5-95F3-446D-A743-F832E693950B}"= TCPgroßes Grinsen :\Spiele\Call of Duty 4 - Modern Warfare\iw3mp.exe:Call of Duty(R) 4 - Modern Warfare(TM) "{EA4E4DC9-B309-4E7E-8663-4CF4DDACE7FF}"= C:\Program Files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{2FEC44EE-F823-4EC3-B518-55AA3F3D17CD}"= UDP:C:\Program Files\Winamp Remote\bin\Orb.exerotes Gesicht rb "{CFBB8103-2F2E-46A6-9226-903BF1C85601}"= TCP:C:\Program Files\Winamp Remote\bin\Orb.exerotes Gesicht rb "{A691A897-9823-43B4-911E-A73B7E08B991}"= UDP:C:\Program Files\Winamp Remote\bin\OrbTray.exerotes Gesicht rbTray "{44F19541-9ABC-4198-839C-B324D689348F}"= TCP:C:\Program Files\Winamp Remote\bin\OrbTray.exerotes Gesicht rbTray "{A5216EA5-4E4E-46DC-AA1E-F8311FF9C5D0}"= UDP:C:\Program Files\Winamp Remote\bin\OrbIR.exerotes Gesicht rbIR "{8A40EE2F-725E-4FE0-8C1E-36DC66AF03A1}"= TCP:C:\Program Files\Winamp Remote\bin\OrbIR.exerotes Gesicht rbIR "{995444F3-25BE-4761-8A25-C115E6325837}"= UDP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exerotes Gesicht rb Stream Client "{A293F6A3-5E46-42E2-987C-E46F3D6CD057}"= TCP:C:\Program Files\Winamp Remote\bin\OrbStreamerClient.exerotes Gesicht rb Stream Client "{53791E3D-41AA-4F15-A5E8-8731F43E6A2A}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{5292E0E2-E871-4318-9B3C-5D41E5971CCD}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes "{EB11EA61-B291-4B5A-8C68-E490FF480943}"= UDP:C:\Program Files\iTunes\iTunes.exe:iTunes "{BC409461-3AA2-4F04-ACF5-363A4861FE4B}"= TCP:C:\Program Files\iTunes\iTunes.exe:iTunes [HKLM\~\services\sharedaccess\parameters\firewallpolicy\PublicProfile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\RestrictedServices\ Static\System] "DFSR-1"= RPort=5722|UDP:%SystemRoot%\system32\svchost.exe|Svc=DFSR:Allow inbound TCP traffic| [HKLM\~\services\sharedaccess\parameters\firewallpolicy\StandardProfile] "EnableFirewall"= 0 (0x0) R0 iaNvStor;Intel(R) Turbo Memory Controller;C:\Windows\system32\DRIVERS\iaNvStor.sys [2007-07-09 07:28] R1 IDSvix86;Symantec Intrusion Prevention Driver;C:\PROGRA~2\Symantec\DEFINI~1\SymcData\idsdefs\20080305.002\IDSvix86 .sys [2008-02-13 18:18] R2 acedrv10;acedrv10;C:\Windows\system32\drivers\acedrv10.sys [2007-07-27 10:13] R2 acehlp10;acehlp10;C:\Windows\system32\drivers\acehlp10.sys [2007-07-27 12:46] R3 AtcL001;NDIS Miniport Driver for Attansic L1 Gigabit Ethernet Controller;C:\Windows\system32\DRIVERS\atl01v32.sys [2007-03-15 08:41] R3 atikmdag;atikmdag;C:\Windows\system32\DRIVERS\atikmdag.sys [2007-06-13 09:28] R3 SYMNDISV;SYMNDISV;C:\Windows\system32\Drivers\SYMNDISV.SYS [2008-03-07 14:39] S2 AntiSpywareSrv;AntiSpyware Scanning Engine;"C:\Program Files\AntiSpywareApp\AntiSpyware.srv.exe" [2008-04-21 22:17] S2 SpyHunter3 Service;SpyHunter3 Service;"C:\Program Files\Enigma Software Group\SpyHunter\SHService.exe" [] S3 FirebirdServerMAGIXInstance;Firebird Server - MAGIX Instance;C:\Program Files\MAGIX\Common\Database\bin\fbserver.exe [2005-11-17 16:18] S3 UPnPService;UPnPService;C:\Program Files\Common Files\MAGIX Shared\UPnPService\UPnPService.exe [2006-12-14 18:00] S3 w200bus;Sony Ericsson W200 driver (WDM);C:\Windows\system32\DRIVERS\w200bus.sys [2006-11-07 10:42] S3 w200mdfl;Sony Ericsson W200 USB WMC Modem Filter;C:\Windows\system32\DRIVERS\w200mdfl.sys [2006-11-07 10:42] S3 w200mdm;Sony Ericsson W200 USB WMC Modem Driver;C:\Windows\system32\DRIVERS\w200mdm.sys [2006-11-07 10:42] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] bthsvcs REG_MULTI_SZ BthServ [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mount points2\{5e1de9b3-a8c2-11dc-bff0-001d60df84d5}] \shell\Auto\command - G:\fun.xls.exe \shell\AutoRun\command - C:\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\fun.xls.exe *Newly Created Service* - CATCHME *Newly Created Service* - COMHOST . Inhalt des "geplante Tasks" Ordners "2008-04-22 18:44:15 C:\Windows\Tasks\Antispyware Scheduled Scan.job" - C:\Program Files\AntiSpywareApp\AntiSpyware.ex - C:\Program Files\AntiSpywareApp "2008-04-21 21:51:18 C:\Windows\Tasks\Norton Internet Security - Run Full System Scan - Joe.job" - C:\Program Files\Norton Internet Security\Norton AntiVirus\Navw32.exeB/TASK: "2008-04-22 21:00:27 C:\Windows\Tasks\User_Feed_Synchronization-{25C090C9-A96B-4D0D-BE04-466B72A EBDEF}.job" - C:\Windows\system32\msfeedssync.exe . ************************************************************************** catchme 0.3.1353 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-04-22 22:58:35 Windows 6.0.6000 NTFS Scanne versteckte Prozesse... Scanne versteckte Autostart Einträge... Scanne versteckte Dateien... C:\ADSM_PData_0150 Scan erfolgreich abgeschlossen versteckte Dateien: 1 ************************************************************************** . Zeit der Fertigstellung: 2008-04-22 23:01:09 ComboFix-quarantined-files.txt 2008-04-22 21:01:02 Das System hat keinen Meldungstext für die Meldungsnummer 0x2379 in der Meldungsdatei Application gefunden. Das System hat keinen Meldungstext für die Meldungsnummer 0x2379 in der Meldungsdatei Application gefunden. 220 --- E O F --- 2008-04-09 10:56:35 |
Themen zu Habe TR/Vundo.Gen... brauche Hilfe!!!! |
ahnung, brauche, brauche hilfe, erstelle, gefahr, hilfe!, hilfe!!, hilfe!!!, keine ahnung, link, logfiles, ratschläge, theme, themen, tr/vundo.gen |