16.10.2008, 16:27
|
#3 |
| XP Antispyware 2009 so also ich hab jetzt mal den Terminator und den Doctor durchlaufen lassen
wobei ich beim doctor nix entfernen konnt und au iwie kein logfile bekommen hab
aber hier ist des vom Terminator (Teil 1): Zitat:
Logfile of Spyware Terminator v2.3.0.494 (db:2.010.015.000)
Scan Time: 16.10.2008 16:58:23 length: 1340 s
Platform: WXP (5.1.0.2600)
User: Admin
Boot Mode: Normal
Scan type: Full_Spyware_Scan
Scanned Objects: 378017 (Critical:27)
Filter: No System items, No Safe items, No Invalid items
Running Processes
vsmon.exe [Zone Labs, LLC] : C:\WINDOWS\system32\ZoneLabs\vsmon.exe
sched.exe [Avira GmbH] : E:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
avguard.exe [Avira GmbH] : E:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
DTSRVC.exe : C:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DTSRVC.exe
nvsvc32.exe [NVIDIA Corporation] : C:\WINDOWS\system32\nvsvc32.exe
ehwpivsf.exe : C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ilwpwjsr\ehwpivsf.exe
zlclient.exe [Zone Labs, LLC] : E:\Programme\ZoneAlarm\zlclient.exe
wpctrl.exe [Portrait Displays, Inc.] : C:\Programme\Portrait Displays\Pivot Software\wpctrl.exe
DTHtml.exe [Portrait Displays, Inc] : C:\Programme\Portrait Displays\HP My Display\DTHtml.exe
avgnt.exe [Avira GmbH] : E:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe
brastk.exe : C:\WINDOWS\system32\brastk.exe
TeaTimer.exe [Safer Networking Limited] : E:\Programme\Spybot - Search & Destroy\TeaTimer.exe
qip.exe [The Author of QIP] : E:\Programme\QIP\qip.exe
floater.exe [Portrait Displays, Inc.] : C:\Programme\Portrait Displays\Pivot Software\floater.exe
odercxav.exe : C:\WINDOWS\system32\odercxav.exe
Launchy.exe : E:\Programme\Launchy\Launchy.exe
HookManager.exe [Portrait Displays Inc.] : C:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\HookManager.exe
XP_AntiSpyware.exe : C:\Programme\XP_AntiSpyware\XP_AntiSpyware.exe
Opera.exe [Opera Software] : E:\Programme\Opera\Opera.exe
pctsAuxs.exe [PC Tools] : E:\Programme\Spyware Doctor\pctsAuxs.exe
pctsSvc.exe [PC Tools] : E:\Programme\Spyware Doctor\pctsSvc.exe
pctsTray.exe [PC Tools] : E:\Programme\Spyware Doctor\pctsTray.exe
pctsGui.exe [PC Tools] : E:\Programme\Spyware Doctor\pctsGui.exe
Internet Settings
R - HKLM\Software\Microsoft\Internet Explorer\Main, Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R - HKLM\Software\Microsoft\Internet Explorer\Search, SearchAssistant = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
R - HKLM\Software\Microsoft\Internet Explorer\Search, CustomizeSearch = http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
R - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings, ProxyOverride = localhost;*.local
R - HKLM\System\CurrentControlSet\Services\Tcpip\Parameters, Domain =
R - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Telephony, DomainName =
BHO
02 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - [RealPlayer] : E:\Programme\RealPlayer\rpbrowserrecordplugin.dll
02 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - [Safer Networking Limited] : E:\Programme\Spybot - Search & Destroy\SDHelper.dll
StartUps
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, SpybotSD TeaTimer : [Safer Networking Limited] : E:\Programme\Spybot - Search & Destroy\TeaTimer.exe
04 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, QIP2005 : [The Author of QIP] : E:\Programme\QIP\qip.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ZoneAlarm Client : [Zone Labs, LLC] : E:\Programme\ZoneAlarm\zlclient.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, PivotSoftware : [Portrait Displays, Inc.] : C:\Programme\Portrait Displays\Pivot Software\wpctrl.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, DT HPW : [Portrait Displays, Inc] : C:\Programme\Portrait Displays\HP My Display\DTHtml.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, avgnt : [Avira GmbH] : E:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Adobe Reader Speed Launcher : [Adobe Systems Incorporated] : E:\PROGRAMME\ACROBATREADER\READER\READER_SL.EXE
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, Malwarebytes Anti-Malware (reboot) : [Malwarebytes Corporation] : E:\PROGRAMME\MALWAREBYTES' ANTI-MALWARE\MBAM.EXE
04 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run, ISTray : [PC Tools] : E:\Programme\Spyware Doctor\pctsTray.exe
04 - Startup: %STARTUPALL%\Launchy.lnk : E:\Programme\Launchy\Launchy.exe
Shell Extensions
WinRAR - {B41DB860-8EE4-11D2-9906-E49FADC173CA} - : C:\Programme\WinRAR\rarext.dll
Desktop Explorer - {1CDB2949-8F65-4355-8456-263E7C208A5D} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dll
- {1E9B04FB-F9E5-4718-997B-B8DA88302A47} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dll
nView Desktop Context Menu - {1E9B04FB-F9E5-4718-997B-B8DA88302A48} - [NVIDIA Corporation] : C:\WINDOWS\system32\nvshell.dll
Shell Extension for Malware scanning - {45AC2688-0253-4ED8-97DE-B5370FA7D48A} - [Avira GmbH] : E:\Programme\Avira\AntiVir PersonalEdition Classic\shlext.dll
ZLAVShExt Class - {D9872D13-7651-4471-9EEE-F0A00218BEBB} - [Zone Labs, LLC] : E:\Programme\ZoneAlarm\zlavscan.dll
PDI GUI Engine COM Obj - {654D0431-C930-43C4-B8DA-9AA01BA5B486} - [Portrait Displays, Inc] : C:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\HtmlEngine.dll
VPCHostCopyHook - {8932AEFE-9DB6-4f43-AFB2-5682F55E773A} - [Microsoft Corporation] : E:\Programme\VirtualPC\VPCShExH.DLL
RealOne Player Context Menu Class - {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} - [RealNetworks, Inc.] : E:\Programme\RealPlayer\rpshell.dll
iTunes - {B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} - [Apple Inc.] : E:\Programme\iTunes\iTunesMiniPlayer.dll
Protocol Handler
IEProtocolHandler Class - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - [Skype Technologies] : C:\Programme\Gemeinsame Dateien\Skype\Skype4COM.dll
Services
23 - [Advanced Micro Devices] : C:\WINDOWS\system32\DRIVERS\AmdPPM.sys
23 - [Avira GmbH] : E:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
23 - [Avira GmbH] : E:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
23 - [Atheros Communications, Inc.] : C:\WINDOWS\system32\DRIVERS\l151x86.sys
23 - [Avira GmbH] : E:\Programme\Avira\AntiVir PersonalEdition Classic\avgio.sys
23 - [Avira GmbH] : E:\Programme\Avira\AntiVir PersonalEdition Classic\avgntflt.sys
23 - [Avira GmbH] : C:\WINDOWS\system32\DRIVERS\avipbb.sys
23 - : C:\Programme\Gemeinsame Dateien\Portrait Displays\Shared\DTSRVC.exe
23 - [GEAR Software Inc.] : C:\WINDOWS\system32\Drivers\GEARAspiWDM.sys
23 - : C:\WINDOWS\system32\giveio.sys
23 - [Hauppauge Computer Works, Inc.] : C:\WINDOWS\system32\Drivers\hcw88rc5.sys
23 - [Hauppauge Computer Works, Inc.] : C:\WINDOWS\system32\drivers\hcw88tun.sys
23 - [Hauppauge Computer Works, Inc] : C:\WINDOWS\system32\drivers\hcw88vid.sys
23 - [Hauppauge Computer Works, Inc.] : C:\WINDOWS\system32\drivers\HCW88BAR.sys
23 - [Realtek Semiconductor Corp.] : C:\WINDOWS\system32\drivers\RtkHDAud.sys
23 - : C:\WINDOWS\system32\DRIVERS\ASACPI.sys
23 - [NVIDIA Corporation] : C:\WINDOWS\system32\nvsvc32.exe
23 - [Portrait Displays, Inc.] : C:\WINDOWS\system32\DRIVERS\pdiddcci.sys
23 - [Portrait Displays, Inc.] : C:\WINDOWS\system32\Drivers\PdiPorts.sys
23 - [Portrait Displays, Inc.] : C:\WINDOWS\system32\drivers\pivot.sys
23 - [Protection Technology] : C:\WINDOWS\system32\drivers\sfdrv01.sys
23 - [Protection Technology] : C:\WINDOWS\system32\drivers\sfhlp02.sys
23 - [Protection Technology] : C:\WINDOWS\system32\drivers\sfvfs02.sys
23 - [Windows (R) 2000 DDK provider] : C:\WINDOWS\system32\speedfan.sys
23 - [Zone Labs, LLC] : C:\WINDOWS\system32\ZoneLabs\srescan.sys
23 - [AVIRA GmbH] : C:\WINDOWS\system32\DRIVERS\ssmdrv.sys
23 - [Zone Labs, LLC] : C:\WINDOWS\system32\vsdatant.sys
23 - [PC Tools] : E:\Programme\Spyware Doctor\pctsAuxs.exe
23 - [PC Tools] : E:\Programme\Spyware Doctor\pctsSvc.exe
System Policies
HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableTaskMgr : :
Threat Files
<Trojan.Downloader.Agent.vmh> : E:\installierte Spiele\TmNationsForever\unins000.exe
<Trojan.Downloader.Agent.vmh> : C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\TmNationsForever\TmNationsForever deinstallieren.lnk
<FavoriteMan> : C:\WINDOWS\system32\emesx.dll
<MediaUpdate.SafeSurf> : C:\WINDOWS\system32\ssurf022.dll
<Trojan.Pacer> : C:\WINDOWS\system32\psoft1.exe
<Trojan.Regc> : C:\WINDOWS\system32\regc64.dll
<Vcatch> : C:\WINDOWS\system32\VCatchPI.dll
<Trojan.Adclick> : C:\WINDOWS\system32\vbsys2.dll
<Backdoor.W32.BlueEye.MSV> : C:\WINDOWS\system32\msvchost.exe
<Backdoor.W32.BlueEye.MSV> : C:\WINDOWS\system32\regm64.dll
<Backdoor.W32.BlueEye.MSV> : C:\WINDOWS\system32\ssvchost.exe
<E-Worm.W32.NetSky.QFQ> : C:\WINDOWS\FVProtect.exe
<E-Worm.W32.NetSky.QFQ> : C:\WINDOWS\userconfig9x.dll
<Client-IRC.mIRC.617> : C:\Dokumente und Einstellungen\da_tschaemp\Lokale Einstellungen\Temporary Internet Files\Content.IE5\8IJT3M5X\mirc617[1].exe
<AdTool.WhenU.a> : D:\Eigene Dateien\downloads\BS520DE.exe
<AdTool.WhenU.a> : D:\Eigene Dateien\downloads\BSINSTALLDE52.exe
<Client-IRC.mIRC.617> : D:\Eigene Dateien\downloads\mirc617.exe
<RemoteAdmin.WinVNC.4> : D:\Eigene Dateien\downloads\vnc-4_1_2-x86_win32.exe
<JOKE.ClickOff> : D:\Eigene Dateien\fun\Scherze\click!.exe
<BadJoke.Finger.b> : D:\Eigene Dateien\fun\Scherze\Finger.exe
|
__________________ |