|
Mülltonne: PureMorph gefunden. Was macht der, wie bekomm ich den weg?Windows 7 Beiträge, die gegen unsere Regeln verstoßen haben, solche, die die Welt nicht braucht oder sonstiger Müll landet hier in der Mülltonne... |
30.10.2008, 13:40 | #1 |
| PureMorph gefunden. Was macht der, wie bekomm ich den weg? Hallo alle zusammen. Meine Virensoftware hat einen Trojaner gefunden. Kann mir jemand helfen, den los zu werden? Bin mit HJT drüber und habe folgende Logfile bekommen: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 13:36:41, on 30.10.2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16735) Boot mode: Normal Running processes: C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\PROGRA~1\meinberg\NTP_TI~1\mbgtsmon.exe C:\Programme\ScanSoft\PaperPort\pptd40nt.exe C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe C:\WINDOWS\system32\oodtray.exe C:\Programme\OO Software\CleverCache\ooccctrl.exe C:\Programme\G DATA InternetSecurity\AVKTray\AVKTray.exe C:\Programme\COPA-DATA\zenOn 6.21 SP1\zenDbSrv.exe C:\WINDOWS\system32\ctfmon.exe C:\Programme\GE Fanuc\Proficy iFIX\fix.exe C:\Programme\FRITZ!\IWatch.exe C:\Programme\UltraVnc\winvnc.exe C:\Programme\Neuhaus\TAINY ComPortClient\CpcConf.exe C:\Programme\Brother\Brmfcmon\BrMfimon.exe C:\Programme\Windows Desktop Search\WindowsSearch.exe C:\Programme\GE Fanuc\Proficy iFIX\NNTABLE.EXE C:\Programme\COPA-DATA\zenOn 6.21 SP1\ZenSysSrv.exe C:\Programme\GE Fanuc\Proficy iFIX\SYSALERTQMGR.EXE C:\PROGRAMME\GE FANUC\PROFICY IFIX\WSACTASK.EXE C:\PROGRAMME\GE FANUC\PROFICY IFIX\IOCNTRL.EXE C:\PROGRAMME\GE FANUC\PROFICY IFIX\MB1SPOLL.EXE C:\PROGRAMME\GE FANUC\PROFICY IFIX\SM2SPOLL.EXE C:\PROGRA~1\GEFANU~1\PROFIC~2\MB1DRV.EXE C:\PROGRA~1\G DATA InternetSecurity\GUI\AVKIS.exe C:\Programme\Mozilla Firefox\firefox.exe C:\Programme\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.google.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.google.de/ O2 - BHO: G DATA WebFilter Class - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Programme\G DATA InternetSecurity\Webfilter\AVKWebIE.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O3 - Toolbar: G DATA WebFilter - {0124123D-61B4-456f-AF86-78C53A0790C5} - C:\Programme\G DATA InternetSecurity\Webfilter\AVKWebIE.dll O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Meinberg Time Server Monitor] C:\PROGRA~1\meinberg\NTP_TI~1\mbgtsmon.exe -minimize O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot O4 - HKLM\..\Run: [PaperPort PTD] "C:\Programme\ScanSoft\PaperPort\pptd40nt.exe" O4 - HKLM\..\Run: [IndexSearch] "C:\Programme\ScanSoft\PaperPort\IndexSearch.exe" O4 - HKLM\..\Run: [PPort11reminder] "C:\Programme\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini O4 - HKLM\..\Run: [BrMfcWnd] C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN O4 - HKLM\..\Run: [ControlCenter3] C:\Programme\Brother\ControlCenter3\brctrcen.exe /autorun O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [OODefragTray] C:\WINDOWS\system32\oodtray.exe O4 - HKLM\..\Run: [ooccctrl.exe] C:\Programme\OO Software\CleverCache\ooccctrl.exe /tasktray O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [AVKTray] "C:\Programme\G DATA InternetSecurity\AVKTray\AVKTray.exe" O4 - HKLM\..\Run: [COPA-DATA Database Connection] "C:\Programme\COPA-DATA\zenOn 6.21 SP1\zenDbSrv.exe" O4 - HKLM\..\RunOnce: [InstallShieldSetup] C:\PROGRA~1\INSTAL~1\{EBC48410-C292-412D-A72A-4F2855988D55}\setup.exe -rebootC:\PROGRA~1\INSTAL~1\{EBC48410-C292-412D-A72A-4F2855988D55}\reboot.ini -l0x7 O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: iFix_Start.lnk = C:\Programme\GE Fanuc\Proficy iFIX\launch.exe O4 - Global Startup: ISDNWatch.lnk = C:\Programme\FRITZ!\IWatch.exe O4 - Global Startup: Run server as application.lnk = C:\Programme\UltraVnc\winvnc.exe O4 - Global Startup: TAINY ComPortClient.lnk = C:\Programme\Neuhaus\TAINY ComPortClient\CpcConf.exe O4 - Global Startup: Windows Search.lnk = C:\Programme\Windows Desktop Search\WindowsSearch.exe O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{6C3012C0-608E-4C57-BC55-7E6F32F6DDEA}: NameServer = 192.168.178.1 O20 - Winlogon Notify: sudown - C:\WINDOWS\SYSTEM32\sudown.dll O23 - Service: AEClientHostService - GE Fanuc Automation Americas - C:\Programme\GE Fanuc\Alarm Viewer\Host\AEClientHostService.exe O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe O23 - Service: G DATA AntiVirus Proxy (AVKProxy) - G DATA Software AG - C:\Programme\Gemeinsame Dateien\G DATA\AVKProxy\AVKProxy.exe O23 - Service: G DATA Scheduler (AVKService) - G DATA Software AG - C:\Programme\G DATA InternetSecurity\AVK\AVKService.exe O23 - Service: AntiVirus Wächter (AVKWCtl) - G DATA Software AG - C:\Programme\G DATA InternetSecurity\AVK\AVKWCtl.exe O23 - Service: Proficy Licensing (CCFLIC0) - GE Fanuc Automation Americas - C:\Programme\GE Fanuc\Proficy Common\Proficy Common Licensing\CCFLIC0.exe O23 - Service: Proficy HMI/SCADA iFIX server (FIX) - GE Fanuc Automation Americas, Inc. - C:\Programme\GE Fanuc\Proficy iFIX\fixsrv.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: M1 Licensing Helper (iLicenseSvc) - GE Fanuc Automation Americas, Inc. - C:\WINDOWS\Intellution\iLicenseSvc.exe O23 - Service: Network Time Protocol Daemon (NTP) - Unknown owner - C:\Programme\NTP\bin\ntpd.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: O&O CleverCache Agent (OOCleverCacheAgent) - O&O Software GmbH - C:\Programme\OO Software\CleverCache\ooccag.exe O23 - Service: OpcEnum - OPC Foundation - C:\WINDOWS\system32\OpcEnum.exe O23 - Service: tsc (tsc01c93a804634f370) - Unknown owner - C:\Programme\Neuhaus\TAINY ModemServer Kernel\otp\erts-5.3\bin\erlsrv.exe O23 - Service: umsrvcc - Landis+Gyr AG - C:\WINDOWS\system32\umsrvcc.exe O23 - Service: zenAdminSrv - COPA-DATA GmbH - C:\Programme\Gemeinsame Dateien\COPA-DATA\zenAdminSrv\zenAdminSrv.exe -- End of file - 7885 bytes Danke für eure Hilfe. Gruß Helix |
Themen zu PureMorph gefunden. Was macht der, wie bekomm ich den weg? |
antivirus, bho, controlcenter, desktop, einstellungen, explorer, firefox, fritz!, g data, helfen, hijack, hijackthis, hkus\s-1-5-18, hotkey, internet, internet explorer, jusched.exe, logfile, microsoft, monitor, mozilla, programme, proxy, security, server, software, system, trojaner, virensoftware, windows, windows xp, windows xp sp3, winlogon, xp sp3 |