so den ersten scan habe ich bereits fertig, hier das ergebnis:
Zitat:
Malwarebytes' Anti-Malware 1.25
Datenbank Version: 1076
Windows 6.0.6000
15:16:11 22.08.2008
mbam-log-08-22-2008 (15-16-11).txt
Scan-Methode: Vollständiger Scan (C:\|D:\|)
Durchsuchte Objekte: 175784
Laufzeit: 59 minute(s), 43 second(s)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 8
Infizierte Registrierungswerte: 5
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 4
Infizierte Dateien: 35
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
HKEY_CLASSES_ROOT\Installer\UpgradeCodes\2dda3201767c34b46a72671d26d39178 (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\UpgradeCodes\2dda3201767c34b46a72671d26d39178 (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\antispywarebotsrv (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\antispywarebotsrv (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\antispywarebotsrv (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\rdfa (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\MS Juan (Trojan.Vundo) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\contim (Trojan.Vundo) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c:\program files\antispywarebot\ (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders\c:\programdata\microsoft\windows\start menu\programs\antispywarebot\ (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\lphcae5j0e79j (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\originalwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
HKEY_CURRENT_USER\Control Panel\Desktop\convertedwallpaper (Hijack.Wallpaper) -> Quarantined and deleted successfully.
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
C:\Users\David\AppData\Roaming\AntispywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Roaming\AntispywareBot\Log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Program Files\AntiSpywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntiSpywareBot (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
Infizierte Dateien:
C:\Program Files\GALA-NET\Rappelz_USA\Launcher.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\David\Launcher.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\oitxyrfl.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\nfdxckeh.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\nlcpkqlo.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\nseblslj.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\nwlnuacr.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\yqmrwfly.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\sngmfeae.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\jkkHXNeF.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\lxhiimle.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\cfyxltag.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\cwtwggqc.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\tmp0000cc05 (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\tmp0001191b (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\unvhubhm.dll (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\Temp\qxcokoxd.exe (Trojan.Vundo) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\VirtualStore\Program Files\GALA-NET\Rappelz_USA\Launcher.exe.new (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Local\VirtualStore\Program Files\gPotato.eu\Rappelz\Launcher.exe.new (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Roaming\AntispywareBot\Log\2008 Aug 20 - 10_08_41 PM_862.log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Roaming\AntispywareBot\Log\2008 Aug 20 - 10_09_21 PM_467.log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Roaming\AntispywareBot\Log\2008 Aug 20 - 10_09_35 PM_406.log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Roaming\AntispywareBot\Log\2008 Aug 20 - 10_13_26 PM_363.log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Users\David\AppData\Roaming\AntispywareBot\Log\2008 Aug 20 - 10_14_14 PM_477.log (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Program Files\AntiSpywareBot\AntispywareBot.exe (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Program Files\AntiSpywareBot\AntispywareBot.srv.exe (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Program Files\AntiSpywareBot\AntispywareBot.url (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Program Files\AntiSpywareBot\DataBase.ref (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Program Files\AntiSpywareBot\SpyCleaner.dll (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Program Files\AntiSpywareBot\TCL.dll (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Program Files\AntiSpywareBot\vistaCPtasks.xml (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Program Files\AntiSpywareBot\zlib.dll (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntiSpywareBot\AntispywareBot on the Web.lnk (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AntiSpywareBot\AntispywareBot.lnk (Rogue.AntiSpywareBot) -> Quarantined and deleted successfully.
C:\Users\Public\Desktop\AntispywareBot.lnk (Rogue.Antispyware) -> Quarantined and deleted successfully.
|
zum zweiten mit combofix , also ich habe gelesen das man das wenn man vista hat , mit der recovery cd machen muss. und da kommt dann schon mein nächstes problem, und zwar will mein pc seit einer weile keinen treiber mehr für mein cd/dvd rw erkennen. kann man das auch irgendwie anders machen eventuell ?
danke schonmal für die hilfen , werde jetzt den
CCleaner starten