![]() |
| |||||||
Log-Analyse und Auswertung: Your Privacy is in Danger! Vundo.genWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| |
| | #1 |
| | Your Privacy is in Danger! Vundo.gen 4. Logfile vom Combofix ComboFix 08-05-24.1 - Vivus 2008-05-25 13:24:49.1 - NTFSx86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1031.18.546 [GMT 2:00] ausgeführt von:: C:\Dokumente und Einstellungen\Vivus\Desktop\ComboFix.exe * Neuer Wiederherstellungspunkt wurde erstellt * Resident AV is active . (((((((((((((((((((((((((((((((((((( Weitere L”schungen )))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\cookies.ini C:\WINDOWS\rs.txt C:\WINDOWS\system32\aykartcv.ini C:\WINDOWS\system32\cgrwyxqx.ini C:\WINDOWS\system32\deMlmUvw.ini C:\WINDOWS\system32\deMlmUvw.ini2 C:\WINDOWS\system32\fsoufpov.ini C:\WINDOWS\system32\gwchomwn.ini C:\WINDOWS\system32\mcrh.tmp C:\WINDOWS\system32\pwqqrqan.ini C:\WINDOWS\system32\QtAHNXbc.ini C:\WINDOWS\system32\QtAHNXbc.ini2 C:\WINDOWS\system32\sefpboth.ini C:\WINDOWS\system32\tfkbiymw.ini C:\WINDOWS\system32\tqnxjaqi.ini C:\WINDOWS\system32\uuhabmne.ini C:\WINDOWS\system32\xbewjkjq.ini C:\WINDOWS\system32\XGjjQqru.ini C:\WINDOWS\system32\XGjjQqru.ini2 . ((((((((((((((((((((((((((((((((((((((( Drivers/Services ))))))))))))))))))))))))))))))))))))))))))))))))) . -------\Legacy_IPRIP -------\Legacy_NWSAPAGENT -------\Service_Iprip -------\Service_NwSapAgent ((((((((((((((((((((((( Dateien erstellt von 2008-04-25 bis 2008-05-25 )))))))))))))))))))))))))))))) . 2008-05-25 13:15 . 2008-05-25 13:15 <DIR> d-------- C:\Programme\CCleaner 2008-05-24 22:02 . 2008-05-15 23:22 86,528 --a------ C:\WINDOWS\system32\VACFix.exe 2008-05-24 22:02 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\IEDFix.exe 2008-05-24 22:02 . 2008-05-18 21:40 82,944 --a------ C:\WINDOWS\system32\404Fix.exe 2008-05-24 22:02 . 2008-05-25 12:21 2,944 --a------ C:\WINDOWS\system32\tmp.reg 2008-05-24 21:59 . 2007-09-06 00:22 289,144 --a------ C:\WINDOWS\system32\VCCLSID.exe 2008-05-24 21:59 . 2006-04-27 17:49 288,417 --a------ C:\WINDOWS\system32\SrchSTS.exe 2008-05-24 21:59 . 2003-06-05 21:13 53,248 --a------ C:\WINDOWS\system32\Process.exe 2008-05-24 21:59 . 2004-07-31 18:50 51,200 --a------ C:\WINDOWS\system32\dumphive.exe 2008-05-24 21:59 . 2007-10-04 00:36 25,600 --a------ C:\WINDOWS\system32\WS2Fix.exe 2008-05-24 21:37 . 2008-05-24 21:37 163,353 --a------ C:\WINDOWS\system32\nvapps.xml 2008-05-24 21:36 . 2008-05-24 21:36 <DIR> d-------- C:\WINDOWS\nview 2008-05-24 21:36 . 2007-12-05 02:53 356,352 --a------ C:\WINDOWS\system32\NVUNINST.EXE 2008-05-24 21:36 . 2007-12-05 01:41 356,352 --a------ C:\WINDOWS\system32\nvudisp.exe 2008-05-24 21:36 . 2007-12-05 01:41 17,737 --a------ C:\WINDOWS\system32\nvdisp.nvu 2008-05-24 13:46 . 2008-05-24 13:46 <DIR> d-------- C:\Programme\Trend Micro 2008-04-28 22:05 . 2007-04-03 14:57 100,488 -ra------ C:\WINDOWS\system32\drivers\s116mgmt.sys 2008-04-28 22:05 . 2007-04-03 14:57 99,080 -ra------ C:\WINDOWS\system32\drivers\s116unic.sys 2008-04-28 22:05 . 2007-04-03 14:57 23,176 -ra------ C:\WINDOWS\system32\drivers\s116nd5.sys 2008-04-28 22:05 . 2007-04-03 14:57 11,016 -ra------ C:\WINDOWS\system32\drivers\s116cr.sys 2008-04-28 19:29 . 2007-04-03 14:57 108,680 -ra------ C:\WINDOWS\system32\drivers\s116mdm.sys 2008-04-28 19:29 . 2007-04-03 14:57 98,696 -ra------ C:\WINDOWS\system32\drivers\s116obex.sys 2008-04-28 19:29 . 2007-04-03 14:57 83,336 -ra------ C:\WINDOWS\system32\drivers\s116bus.sys 2008-04-28 19:29 . 2007-04-03 14:57 15,112 -ra------ C:\WINDOWS\system32\drivers\s116mdfl.sys 2008-04-28 19:29 . 2007-04-03 14:57 12,424 -ra------ C:\WINDOWS\system32\drivers\s116whnt.sys 2008-04-28 19:29 . 2007-04-03 14:57 12,424 -ra------ C:\WINDOWS\system32\drivers\s116wh.sys 2008-04-28 19:29 . 2007-04-03 14:57 12,424 -ra------ C:\WINDOWS\system32\drivers\s116cmnt.sys 2008-04-28 19:29 . 2007-04-03 14:57 12,424 -ra------ C:\WINDOWS\system32\drivers\s116cm.sys 2008-04-25 21:06 . 2008-04-25 21:06 <DIR> d-------- C:\Dokumente und Einstellungen\All Users.WINDOWS\Anwendungsdaten\Trymedia 2008-04-25 21:05 . 2008-04-25 21:05 <DIR> d-------- C:\Programme\Capcom 2008-04-25 13:11 . 2008-04-25 13:11 <DIR> d-------- C:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Sony Ericsson 2008-04-25 08:00 . 2008-04-25 08:00 15 --a------ C:\WINDOWS\system32\080fcb4a . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2008-05-24 21:57 --------- d-----w C:\Programme\Steam 2008-05-16 11:34 --------- d-----w C:\Programme\Warcraft III 2008-04-28 19:19 --------- d-----w C:\Dokumente und Einstellungen\Vivus\Anwendungsdaten\dvdcss 2008-04-25 19:13 --------- d-----w C:\Dokumente und Einstellungen\Vivus\Anwendungsdaten\BitTorrent 2008-04-19 23:19 --------- d-----w C:\Dokumente und Einstellungen\All Users.WINDOWS\Anwendungsdaten\Avira 2008-04-19 12:01 --------- d-----w C:\Programme\Alwil Software 2008-04-18 13:45 --------- d-----w C:\Dokumente und Einstellungen\Vivus\Anwendungsdaten\TmpRecentIcons 2008-04-18 12:51 --------- d--h--w C:\Programme\InstallShield Installation Information 2008-04-18 12:51 --------- d-----w C:\Dokumente und Einstellungen\Vivus\Anwendungsdaten\ICQ 2008-04-18 08:18 94,208 ----a-w C:\WINDOWS\npqtsrak.exe 2008-04-18 08:18 81,920 ----a-w C:\WINDOWS\rtqmekwg.exe 2008-04-01 14:17 --------- d-----w C:\Programme\Smallvideosoft 2008-03-25 04:51 621,344 ----a-w C:\WINDOWS\system32\mswstr10.dll 2008-03-25 04:51 187,168 ----a-w C:\WINDOWS\system32\msjint40.dll 2008-03-20 08:03 1,845,376 ----a-w C:\WINDOWS\system32\win32k.sys 2007-04-10 20:39 10,240 --sha-w C:\WINDOWS\rnapxs\rnapxs.dat . (((((((((((((((((((((((((((( Autostart Punkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . REGEDIT4 *Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{05CD83FB-13AF-462F-B595-E0992A2C361A}] C:\WINDOWS\system32\urqQjjGX.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{C6CF5BA3-2D76-40D1-A07F-2A0D18540255}] C:\WINDOWS\lgmxvpatwxm.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{CAE72EC4-7260-4909-ACF3-E134C042CEF3}] C:\WINDOWS\system32\wvUmlMed.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{E705BADA-0612-4F60-A527-671D9B001D59}] C:\WINDOWS\system32\cbXNHAtQ.dll [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe" [2007-12-13 20:10 1688872] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Verknüpfung mit der High Definition Audio-Eigenschaftenseite"="HDAShCut.exe" [2005-01-07 17:07 61952 C:\WINDOWS\system32\HdAShCut.exe] "SunJavaUpdateSched"="C:\Programme\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03 36975] "F-Secure Manager"="C:\Programme\Arcor\Common\FSM32.exe" [2005-10-26 03:51 122929] "F-Secure TNB"="C:\Programme\Arcor\TNB\TNBUtil.exe" [2005-07-18 16:51 700416] "F-Secure Startup Wizard"="C:\Programme\Arcor\FSGUI\FSSW.exe" [2005-10-18 10:29 372736] "News Service"="C:\Programme\Arcor\FSGUI\ispnews.exe" [2005-05-31 14:45 356352] "NBKeyScan"="C:\Programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" [2007-12-03 15:21 2213160] "NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2007-12-05 01:41 8523776] "nwiz"="nwiz.exe" [2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe] "NvMediaCenter"="C:\WINDOWS\system32\NvMcTray.dll" [2007-12-05 01:41 81920] "MSConfig"="C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe" [2004-08-04 14:00 160768] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\CTFMON.EXE" [2004-08-04 14:00 15360] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] "omlbpkaw"= {23DD052C-B48C-4A33-BD03-5A8795F4FDDE} - C:\WINDOWS\omlbpkaw.dll [ ] [HKLM\~\startupfolder\C:^Dokumente und Einstellungen^All Users.WINDOWS^Startmenü^Programme^Autostart^Microsoft Office.lnk] path=C:\Dokumente und Einstellungen\All Users.WINDOWS\Startmenü\Programme\Autostart\Microsoft Office.lnk backup=C:\WINDOWS\pss\Microsoft Office.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\BitTorrent] C:\Programme\BitTorrent\bittorrent.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CTFMON.EXE] --a------ 2004-08-04 14:00 15360 C:\WINDOWS\system32\ctfmon.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] --a------ 2007-03-01 15:57 153136 C:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvCplDaemon] --a------ 2007-12-05 01:41 8523776 C:\WINDOWS\system32\NvCpl.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NvMediaCenter] --a------ 2007-12-05 01:41 81920 C:\WINDOWS\system32\NvMcTray.dll [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\nwiz] --a------ 2007-12-05 01:41 1626112 C:\WINDOWS\system32\nwiz.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] -ra------ 2007-06-13 09:16 528384 C:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile] "EnableFirewall"= 0 (0x0) [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "C:\\Programme\\Steam\\SteamApps\\marcomassiv\\counter-strike source\\hl2.exe"= "C:\\WINDOWS\\system32\\usmt\\migwiz.exe"= "C:\\Programme\\Messenger\\msmsgs.exe"= "C:\\Programme\\Arcor\\backweb\\5141527\\Program\\fspex.exe"= "C:\\Programme\\Steam\\Steam.exe"= "C:\\Programme\\Windows Live\\Messenger\\msnmsgr.exe"= "C:\\Programme\\Windows Live\\Messenger\\livecall.exe"= "C:\\Programme\\Warcraft III\\Warcraft III.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "6112:TCP"= 6112:TCP:192.168.1.35/255.255.255.255:Enabled:Warcraft III "4000:TCP"= 4000:TCP:Warcraft III "4000:UDP"= 4000:UDP:Warcraft III "6112:UDP"= 6112:UDP:Warcraft III "6111:TCP"= 6111:TCP:Warcraft III "6113:TCP"= 6113:TCP:Warcraft III "6114:TCP"= 6114:TCP:Warcraft III "6115:TCP"= 6115:TCP:Warcraft III "61115:TCP"= 61115:TCP:Warcraft III "6116:TCP"= 6116:TCP:Warcraft III "6117:TCP"= 6117:TCP:Warcraft III "6118:TCP"= 6118:TCP:Warcraft III "6119:TCP"= 6119:TCP:Warcraft III "6612:UDP"= 6612:UDP:Warcraft III "6111:UDP"= 6111:UDP:Warcraft III "6113:UDP"= 6113:UDP:Warcraft III "6114:UDP"= 6114:UDP:Warcraft III "6115:UDP"= 6115:UDP:Warcraft III "6116:UDP"= 6116:UDP:Warcraft III "6117:UDP"= 6117:UDP:Warcraft III "6118:UDP"= 6118:UDP:Warcraft III "6119:UDP"= 6119:UDP:Warcraft III [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\IcmpSettings] "AllowInboundEchoRequest"= 1 (0x1) R0 FSFW;F-Secure Firewall Driver;C:\WINDOWS\system32\drivers\fsdfw.sys [2005-11-18 17:04] R2 BackWeb Plug-in - 5141527;Arcor Sicherheitspaket;C:\PROGRA~1\Arcor\backweb\5141527\Program\SERVIC~1.EXE [2007-04-10 22:38] R2 F-Secure Filter;F-Secure File System Filter;C:\Programme\Arcor\Anti-Virus\Win2K\FSfilter.sys [2004-09-10 17:14] R2 F-Secure Gatekeeper;F-Secure Gatekeeper;C:\Programme\Arcor\Anti-Virus\Win2K\FSgk.sys [2008-03-17 15:07] R2 F-Secure Recognizer;F-Secure File System Recognizer;C:\Programme\Arcor\Anti-Virus\Win2K\FSrec.sys [2004-06-01 11:03] S3 p2pgasvc;Peernetzwerk-Gruppenauthentifizierung;C:\WINDOWS\system32\svchost.exe [2004-08-04 14:00] S3 p2pimsvc;Peernetzwerkidentitäts-Manager;C:\WINDOWS\system32\svchost.exe [2004-08-04 14:00] S3 p2psvc;Peernetzwerk;C:\WINDOWS\system32\svchost.exe [2004-08-04 14:00] S3 PNRPSvc;Peer Name Resolution-Protokoll;C:\WINDOWS\system32\svchost.exe [2004-08-04 14:00] S3 s115bus;Sony Ericsson Device 115 driver (WDM);C:\WINDOWS\system32\DRIVERS\s115bus.sys [2007-04-23 16:54] S3 s115mdfl;Sony Ericsson Device 115 USB WMC Modem Filter;C:\WINDOWS\system32\DRIVERS\s115mdfl.sys [2007-04-23 16:54] S3 s115mdm;Sony Ericsson Device 115 USB WMC Modem Driver;C:\WINDOWS\system32\DRIVERS\s115mdm.sys [2007-04-23 16:54] S3 s115mgmt;Sony Ericsson Device 115 USB WMC Device Management Drivers (WDM);C:\WINDOWS\system32\DRIVERS\s115mgmt.sys [2007-04-23 16:54] S3 s115obex;Sony Ericsson Device 115 USB WMC OBEX Interface;C:\WINDOWS\system32\DRIVERS\s115obex.sys [2007-04-23 16:54] S3 ZD1211U(ZyXEL);ZyAIR G-220 IEEE 802.11b+g Wireless LAN Driver (USB)(ZyXEL);C:\WINDOWS\system32\DRIVERS\zd1211u.sys [2004-12-10 10:27] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] p2psvc REG_MULTI_SZ p2psvc p2pimsvc p2pgasvc PNRPSvc . Inhalt des "geplante Tasks" Ordners "2008-05-25 10:00:21 C:\WINDOWS\Tasks\Scheduled scanning task.job" - C:\PROGRA~1\Arcor\ANTI-V~1\fsav.exeW /HARD /ARCHIVE /DISINF /SCHED /NOBREAK /REPORT=C:\PROGRA~1\Arcor\ANTI-V~1\report.txt . ************************************************************************** catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2008-05-25 13:29:49 Windows 5.1.2600 Service Pack 2 NTFS Scanne versteckte Prozesse... Scanne versteckte Autostart Eintr„ge... Scanne versteckte Dateien... Scan erfolgreich abgeschlossen versteckte Dateien: 0 ************************************************************************** . ------------------------ Other Running Processes ------------------------ . C:\Programme\Arcor\Anti-Virus\fsgk32st.exe C:\Programme\Arcor\Anti-Virus\fsgk32.exe C:\Programme\Arcor\backweb\5141527\Program\fsbwsys.exe C:\Programme\Arcor\Anti-Virus\fssm32.exe C:\Programme\Arcor\Common\FSMA32.EXE C:\Programme\Arcor\Common\FSMB32.EXE C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe C:\Programme\Arcor\backweb\5141527\Program\fspex.exe C:\Programme\Arcor\Common\FCH32.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\tcpsvcs.exe C:\Programme\Arcor\Anti-Virus\fsqh.exe C:\Programme\Arcor\Common\FAMEH32.EXE C:\WINDOWS\system32\snmp.exe C:\Programme\Arcor\FSPC\fspc.exe C:\Programme\Arcor\Anti-Virus\FSRW.exe C:\Programme\Arcor\Anti-Virus\FSAV32.exe C:\WINDOWS\system32\rundll32.exe C:\Programme\Arcor\FSPC\fshttps\fshttps.exe C:\Programme\Arcor\FWES\program\fsdfwd.exe C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe C:\PROGRA~1\Arcor\ANTI-S~1\FSAW.exe C:\Programme\Arcor\FSGUI\fsguidll.exe C:\WINDOWS\system32\wscntfy.exe . ************************************************************************** . Zeit der Fertigstellung: 2008-05-25 13:33:21 - machine was rebooted [Vivus] ComboFix-quarantined-files.txt 2008-05-25 11:33:16 15 Verzeichnis(se), 225,327,497,216 Bytes frei 18 Verzeichnis(se), 225,265,696,768 Bytes frei 239 --- E O F --- 2008-05-17 15:01:54 5. Logifle vom Anitmalwarprogramm Malwarebytes' Anti-Malware 1.12 Datenbank Version: 785 Scan Art: Komplett Scan (C:\|D:\|E:\|F:\|G:\|H:\|I:\|J:\|) Objekte gescannt: 105889 Scan Dauer: 35 minute(s), 19 second(s) Infizierte Speicher Prozesse: 0 Infizierte Speicher Module: 0 Infizierte Registrierungsschlüssel: 10 Infizierte Registrierungswerte: 1 Infizierte Datei Objekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 3 Infizierte Speicher Prozesse: (Keine Malware Objekte gefunden) Infizierte Speicher Module: (Keine Malware Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_CLASSES_ROOT\Interface\{8a6be39f-b3ac-4f1f-b837-7cfa378788ff} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{cfd245bd-52ae-4af0-b891-812470b45f78} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{1c8c241e-e292-4f1a-a3dc-87ea8db8b9ca} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Interface\{d086f8da-42df-412b-a966-4fafe548fe4b} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\Typelib\{91aa2bfc-1311-4468-bef7-0c6a5795e764} (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\VirusIsolator (Rogue.VirusIsolator) -> Quarantined and deleted successfully. HKEY_CURRENT_USER\Software\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\affri (Malware.Trace) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\qtvglped.bbnf (Trojan.FakeAlert) -> Quarantined and deleted successfully. HKEY_CLASSES_ROOT\qtvglped.toolbar.1 (Trojan.FakeAlert) -> Quarantined and deleted successfully. Infizierte Registrierungswerte: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\omlbpkaw (Trojan.FakeAlert) -> Quarantined and deleted successfully. Infizierte Datei Objekte der Registrierung: (Keine Malware Objekte gefunden) Infizierte Verzeichnisse: (Keine Malware Objekte gefunden) Infizierte Dateien: C:\System Volume Information\_restore{7F51F3D5-A6A0-4AEB-8C03-8EFD9F5B6237}\RP311\A0139024.dll (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\npqtsrak.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. C:\WINDOWS\rtqmekwg.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully. 6. Logilfe Hijackthis Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 14:15:45, on 25.05.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\Arcor\backweb\5141527\Program\SERVIC~1.EXE C:\Programme\Arcor\Anti-Virus\fsgk32st.exe C:\Programme\Arcor\Anti-Virus\FSGK32.EXE C:\Programme\Arcor\backweb\5141527\program\fsbwsys.exe C:\Programme\Arcor\Anti-Virus\fssm32.exe C:\Programme\Arcor\Common\FSMA32.EXE C:\Programme\Arcor\Common\FSMB32.EXE C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe C:\Programme\Arcor\backweb\5141527\Program\fspex.exe C:\Programme\Arcor\Common\FCH32.EXE C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\system32\tcpsvcs.exe C:\Programme\Arcor\Anti-Virus\fsqh.exe C:\Programme\Arcor\Common\FAMEH32.EXE C:\WINDOWS\System32\snmp.exe C:\Programme\Arcor\FSPC\fspc.exe C:\Programme\Arcor\Anti-Virus\fsrw.exe C:\Programme\Arcor\Anti-Virus\fsav32.exe C:\Programme\Java\jre1.5.0_06\bin\jusched.exe C:\Programme\Arcor\Common\FSM32.EXE C:\Programme\Arcor\FSGUI\ispnews.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe C:\Programme\Arcor\FWES\Program\fsdfwd.exe C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe C:\PROGRA~1\Arcor\ANTI-S~1\fsaw.exe C:\Programme\Arcor\FSGUI\fsguidll.exe C:\WINDOWS\system32\wscntfy.exe C:\Programme\Internet Explorer\IEXPLORE.EXE C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\explorer.exe C:\Programme\Java\jre1.5.0_06\bin\jucheck.exe C:\Programme\Trend Micro\HijackThis\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search O2 - BHO: (no name) - {05CD83FB-13AF-462F-B595-E0992A2C361A} - C:\WINDOWS\system32\urqQjjGX.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: DVA Storm - {C6CF5BA3-2D76-40D1-A07F-2A0D18540255} - C:\WINDOWS\lgmxvpatwxm.dll (file missing) O2 - BHO: (no name) - {CAE72EC4-7260-4909-ACF3-E134C042CEF3} - C:\WINDOWS\system32\wvUmlMed.dll (file missing) O2 - BHO: (no name) - {E705BADA-0612-4F60-A527-671D9B001D59} - C:\WINDOWS\system32\cbXNHAtQ.dll (file missing) O4 - HKLM\..\Run: [Verknüpfung mit der High Definition Audio-Eigenschaftenseite] HDAShCut.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programme\Arcor\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Programme\Arcor\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Programme\Arcor\FSGUI\FSSW.EXE" /reboot O4 - HKLM\..\Run: [News Service] "C:\Programme\Arcor\FSGUI\ispnews.exe" O4 - HKLM\..\Run: [NBKeyScan] "C:\Programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Arcor Sicherheitspaket.lnk = C:\Programme\Arcor\backweb\5141527\Program\fspex.exe O8 - Extra context menu item: Dieses Popup &blockieren - C:\Programme\Arcor\Anti-Spyware\blockpopups.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Webfilter - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programme\Arcor\FSPC\fspcmsie.dll O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Programme\Arcor\FSPC\fspcmsie.dll O9 - Extra 'Tools' menuitem: Webfilter - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Programme\Arcor\FSPC\fspcmsie.dll O9 - Extra button: IE-Schutzschild - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programme\Arcor\Anti-Spyware\ieshield.dll O9 - Extra 'Tools' menuitem: IE-Schutzschild... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programme\Arcor\Anti-Spyware\ieshield.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O23 - Service: Arcor Sicherheitspaket (BackWeb Plug-in - 5141527) - F-Secure Corp. - C:\PROGRA~1\Arcor\backweb\5141527\Program\SERVIC~1.EXE O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Programme\Arcor\Anti-Virus\fsgk32st.exe O23 - Service: FSBWSYS - F-Secure Corp. - C:\Programme\Arcor\backweb\5141527\program\fsbwsys.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Programme\Arcor\FWES\Program\fsdfwd.exe O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Programme\Arcor\FSPC\fshttps\fshttps.exe O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Programme\Arcor\Common\FSMA32.EXE O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 6894 bytes So das ist alles, ich hoffe das ich alles richtig gemacht hab, aber ich kann schon mal sagen das der Destkop Normal ist und sich keine Popups mehr öffnen. Vielen Dank! |
| | #2 |
| /// Winkelfunktion /// TB-Süch-Tiger™ ![]() ![]() ![]() ![]() ![]() ![]() | Your Privacy is in Danger! Vundo.gen Das sieht schon mal etwas besser aus
__________________![]() Diese Einträge bitte mit HijackThis fixen: Code:
ATTFilter O2 - BHO: (no name) - {05CD83FB-13AF-462F-B595-E0992A2C361A} - C:\WINDOWS\system32\urqQjjGX.dll (file missing)
O2 - BHO: DVA Storm - {C6CF5BA3-2D76-40D1-A07F-2A0D18540255} - C:\WINDOWS\lgmxvpatwxm.dll (file missing)
O2 - BHO: (no name) - {CAE72EC4-7260-4909-ACF3-E134C042CEF3} - C:\WINDOWS\system32\wvUmlMed.dll (file missing)
O2 - BHO: (no name) - {E705BADA-0612-4F60-A527-671D9B001D59} - C:\WINDOWS\system32\cbXNHAtQ.dll (file missing)
Danach müssen noch manuell einige Dateien weg. Jedenfalls solche, die ich löschen würde. ![]() Geh dazu so vor: 1.) Lade dir das Tool Avenger und speichere es auf dem Desktop:Mach danach bitte noch ein Logfile mit silentrunners sowie ein ausführliches Fielisting mit diesem script: - Script abspeichern per Rechtsklick, speichern unter auf dem DesktopDiese listing.txt z.B. bei file-upload.net hochladen und hier verlinken, da dieses Logfile zu groß fürs Board ist.
__________________ |
| | #3 |
| | Your Privacy is in Danger! Vundo.gen 1. Logfile vom Avenger
__________________////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Platform: Windows XP (build 2600, Service Pack 2) Sun May 25 16:29:57 2008 16:29:57: Error: Invalid script. A valid script must begin with a command directive. Aborting execution! ////////////////////////////////////////// ////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Platform: Windows XP (build 2600, Service Pack 2) Sun May 25 16:31:39 2008 16:31:39: Error: Invalid script. A valid script must begin with a command directive. Aborting execution! ////////////////////////////////////////// ////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Platform: Windows XP (build 2600, Service Pack 2) Sun May 25 16:32:03 2008 16:32:03: Error: Invalid script. A valid script must begin with a command directive. Aborting execution! ////////////////////////////////////////// ////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Platform: Windows XP (build 2600, Service Pack 2) Sun May 25 16:33:04 2008 16:33:04: Error: Invalid script. A valid script must begin with a command directive. Aborting execution! ////////////////////////////////////////// ////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Platform: Windows XP (build 2600, Service Pack 2) Sun May 25 16:33:09 2008 16:33:09: Error: Invalid script. A valid script must begin with a command directive. Aborting execution! ////////////////////////////////////////// ////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Platform: Windows XP (build 2600, Service Pack 2) Sun May 25 16:33:15 2008 16:33:15: Error: Invalid script. A valid script must begin with a command directive. Aborting execution! ////////////////////////////////////////// ////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Platform: Windows XP (build 2600, Service Pack 2) Sun May 25 16:33:22 2008 16:33:22: Error: Invalid script. A valid script must begin with a command directive. Aborting execution! ////////////////////////////////////////// Logfile of The Avenger Version 2.0, (c) by Swandog46 Swandog46's Public Anti-Malware Tools Platform: Windows XP ******************* Script file opened successfully. Script file read successfully. Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: Rootkit scan active. No rootkits found! File "C:\WINDOWS\system32\VACFix.exe" deleted successfully. File "C:\WINDOWS\system32\IEDFix.exe" deleted successfully. File "C:\WINDOWS\system32\404Fix.exe" deleted successfully. File "C:\WINDOWS\system32\tmp.reg" deleted successfully. File "C:\WINDOWS\system32\VCCLSID.exe" deleted successfully. File "C:\WINDOWS\system32\WS2Fix.exe" deleted successfully. File "C:\WINDOWS\system32\080fcb4a" deleted successfully. Error: file "C:\WINDOWS\npqtsrak.exe" not found! Deletion of file "C:\WINDOWS\npqtsrak.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\rtqmekwg.exe" not found! Deletion of file "C:\WINDOWS\rtqmekwg.exe" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\urqQjjGX.dll" not found! Deletion of file "C:\WINDOWS\system32\urqQjjGX.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\lgmxvpatwxm.dll" not found! Deletion of file "C:\WINDOWS\lgmxvpatwxm.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\wvUmlMed.dll" not found! Deletion of file "C:\WINDOWS\system32\wvUmlMed.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\system32\cbXNHAtQ.dll" not found! Deletion of file "C:\WINDOWS\system32\cbXNHAtQ.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Error: file "C:\WINDOWS\omlbpkaw.dll" not found! Deletion of file "C:\WINDOWS\omlbpkaw.dll" failed! Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND) --> the object does not exist Completed script processing. ******************* Finished! Terminate. 3.Upload vom Listing File-Upload.net - Ihr kostenloser File Hoster! 4. Logfile von HijackThis nach dem Fixen von Datei O2 - BHO: (no name) - {05CD83FB-13AF-462F-B595-E0992A2C361A} - C:\WINDOWS\system32\urqQjjGX.dll (file missing) O2 - BHO: DVA Storm - {C6CF5BA3-2D76-40D1-A07F-2A0D18540255} - C:\WINDOWS\lgmxvpatwxm.dll (file missing) O2 - BHO: (no name) - {CAE72EC4-7260-4909-ACF3-E134C042CEF3} - C:\WINDOWS\system32\wvUmlMed.dll (file missing) Logfile Hijackthis: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 16:51:04, on 25.05.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\Arcor\backweb\5141527\Program\SERVIC~1.EXE C:\Programme\Arcor\Anti-Virus\fsgk32st.exe C:\Programme\Arcor\Anti-Virus\FSGK32.EXE C:\Programme\Arcor\backweb\5141527\program\fsbwsys.exe C:\Programme\Arcor\Common\FSMA32.EXE C:\Programme\Arcor\Common\FSMB32.EXE C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe C:\Programme\Arcor\Anti-Virus\fssm32.exe C:\Programme\Java\jre1.5.0_06\bin\jusched.exe C:\Programme\Arcor\Common\FSM32.EXE C:\Programme\Arcor\FSGUI\ispnews.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe C:\Programme\Arcor\backweb\5141527\Program\fspex.exe C:\Programme\Arcor\Common\FCH32.EXE C:\WINDOWS\system32\nvsvc32.exe C:\Programme\Arcor\Common\FAMEH32.EXE C:\Programme\Arcor\Anti-Virus\fsqh.exe C:\Programme\Arcor\FSPC\fspc.exe C:\Programme\Arcor\Anti-Virus\fsrw.exe C:\WINDOWS\system32\tcpsvcs.exe C:\WINDOWS\System32\snmp.exe C:\Programme\Arcor\Anti-Virus\fsav32.exe C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe C:\Programme\Arcor\FWES\Program\fsdfwd.exe C:\WINDOWS\system32\wscntfy.exe C:\PROGRA~1\Arcor\ANTI-S~1\fsaw.exe C:\Programme\Arcor\FSGUI\fsguidll.exe C:\WINDOWS\system32\taskmgr.exe C:\Programme\Java\jre1.5.0_06\bin\jucheck.exe C:\Programme\Internet Explorer\IEXPLORE.EXE C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WLLoginProxy.exe C:\Programme\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Google R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = MSN.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = Live Search R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = Live Search O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: (no name) - {E705BADA-0612-4F60-A527-671D9B001D59} - C:\WINDOWS\system32\cbXNHAtQ.dll (file missing) O4 - HKLM\..\Run: [Verknüpfung mit der High Definition Audio-Eigenschaftenseite] HDAShCut.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programme\Arcor\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Programme\Arcor\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Programme\Arcor\FSGUI\FSSW.EXE" /reboot O4 - HKLM\..\Run: [News Service] "C:\Programme\Arcor\FSGUI\ispnews.exe" O4 - HKLM\..\Run: [NBKeyScan] "C:\Programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [Sony Ericsson PC Suite] "C:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe" /startoptions O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [BitTorrent] "C:\Programme\BitTorrent\bittorrent.exe" --force_start_minimized O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Arcor Sicherheitspaket.lnk = C:\Programme\Arcor\backweb\5141527\Program\fspex.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE O8 - Extra context menu item: Dieses Popup &blockieren - C:\Programme\Arcor\Anti-Spyware\blockpopups.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Webfilter - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programme\Arcor\FSPC\fspcmsie.dll O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Programme\Arcor\FSPC\fspcmsie.dll O9 - Extra 'Tools' menuitem: Webfilter - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Programme\Arcor\FSPC\fspcmsie.dll O9 - Extra button: IE-Schutzschild - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programme\Arcor\Anti-Spyware\ieshield.dll O9 - Extra 'Tools' menuitem: IE-Schutzschild... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programme\Arcor\Anti-Spyware\ieshield.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll O23 - Service: Arcor Sicherheitspaket (BackWeb Plug-in - 5141527) - F-Secure Corp. - C:\PROGRA~1\Arcor\backweb\5141527\Program\SERVIC~1.EXE O23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Programme\Arcor\Anti-Virus\fsgk32st.exe O23 - Service: FSBWSYS - F-Secure Corp. - C:\Programme\Arcor\backweb\5141527\program\fsbwsys.exe O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Programme\Arcor\FWES\Program\fsdfwd.exe O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Programme\Arcor\FSPC\fshttps\fshttps.exe O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - C:\Programme\Arcor\Common\FSMA32.EXE O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe -- End of file - 7050 bytes Vielen Dank, mal ne Frage am Rande woher wissen Sie das alles, bzw ist es in Beziehung mit Ihrem Beruf, wenn Ihnen die Frage zu privat ist ignorieren Sie sie einfach. |
![]() |
| Themen zu Your Privacy is in Danger! Vundo.gen |
| bho, ctfmon.exe, danger, dateien, desktop, einstellungen, explorer, f-secure, firewall, hijack, hijackthis, hkus\s-1-5-18, internet, internet explorer, logfile, maleware, maleware protection, microsoft, plug-in, popup, privacy protection, privacy protector, programme, server, software, storm, system, temp, unknown file in winsock lsp, vundo.gen, windows, windows xp, your privacy |