![]() |
|
Log-Analyse und Auswertung: Virus-ProblemWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
|
![]() | #1 |
![]() | ![]() Virus-Problem Hallo Zusammen, folgendes Problem: Habe Virus/Wurm auf PC. Wenn ich im Google links anklicke werde ich auf völlig andere Seiten geleitet (Werbeseiten). Kann auf keinerlei Virenschutz-Seiten zugreifen (Verbindung unterbrochen). Combofix kann nicht gestartet werden. Tools wie von f-secure, kaspersky, symantec, windows-tool zum entfernen schädlicher software finden nichts. hatte den avast-antivirus drauf kann sich aber seit dem 22.1. nicht mehr aktualisieren und findet auch nichts. windows-tool läuft nur im abgesicherten modus, im normal-modus stürzt es nach ca. 1 min. ab. system fährt nur noch gelegentlich hoch, nach der anmeldung kommt der blaue bildschirm (kein Bluescreen) und nichts geht mehr weiter - abgesicherter modus geht immer. weiß mir keinen rat mehr. nachfolgend log-file: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 15:33:15, on 24.01.2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe C:\Programme\Intel\Wireless\Bin\S24EvMon.exe C:\WINDOWS\System32\WLTRYSVC.EXE C:\WINDOWS\System32\bcmwltry.exe C:\WINDOWS\system32\spoolsv.exe c:\Programme\ActivIdentity\ActivClient\accoca.exe C:\Programme\Intel\Wireless\Bin\EvtEng.exe C:\Programme\Gemeinsame Dateien\GtFlashSwitch\GtFlashSwitch.exe C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe C:\Programme\Intel\Intel Matrix Storage Manager\Iaantmon.exe c:\WINDOWS\system32\ifxspmgt.exe c:\WINDOWS\system32\ifxtcs.exe C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe C:\Programme\LANCOM-Systems\Advanced VPN Client\ncpclcfg.exe C:\Programme\LANCOM-Systems\Advanced VPN Client\ncprwsnt.exe C:\Programme\LANCOM-Systems\Advanced VPN Client\ncpsec.exe c:\WINDOWS\system32\IfxPsdSv.exe C:\Programme\Intel\Wireless\Bin\RegSrvc.exe C:\Programme\LANCOM-Systems\Advanced VPN Client\rwsrsu.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Hewlett-Packard\Shared\hpqwmiex.exe C:\WINDOWS\Explorer.EXE c:\Programme\Hewlett-Packard\IAM\bin\asghost.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\AccelerometerSt.exe C:\WINDOWS\system32\WLTRAY.exe C:\Programme\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe C:\Programme\Hp\HP Software Update\HPWuSchd2.exe C:\Programme\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe C:\Programme\ActivIdentity\ActivClient\accrdsub.exe C:\WINDOWS\system32\igfxsrvc.exe c:\Programme\ActivIdentity\ActivClient\acevents.exe C:\WINDOWS\system32\hkcmd.exe C:\WINDOWS\system32\igfxpers.exe C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe C:\Programme\Intel\Wireless\Bin\ifrmewrk.exe C:\Programme\Intel\Intel Matrix Storage Manager\Iaanotif.exe c:\Programme\Hewlett-Packard\Embedded Security Software\PSDrt.exe C:\Programme\Analog Devices\Core\smax4pnp.exe C:\Programme\Synaptics\SynTP\SynTPEnh.exe C:\Programme\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe C:\Programme\Java\jre1.6.0_07\bin\jusched.exe C:\Programme\Intel\Wireless\Bin\Dot1XCfg.exe C:\Programme\LANCOM-Systems\Advanced VPN Client\ncpbudgt.exe C:\PROGRA~1\HEWLET~1\Shared\HPQTOA~1.EXE C:\Programme\LANCOM-Systems\Advanced VPN Client\ncpmon.exe C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe C:\Programme\Mozilla Firefox\firefox.exe C:\Programme\F-Secure Internet Security\Common\FSM32.EXE C:\Programme\FRISK Software\F-PROT Antivirus for Windows\FProtTray.exe C:\WINDOWS\system32\ctfmon.exe C:\Programme\Microsoft ActiveSync\Wcescomm.exe C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe C:\PROGRA~1\MICROS~3\rapimgr.exe C:\Programme\WIDCOMM\Bluetooth Software\BTTray.exe C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE C:\PROGRA~1\WIDCOMM\BLUETO~1\BTSTAC~1.EXE C:\WINDOWS\system32\msiexec.exe C:\Programme\F-Secure Internet Security\Uninstall\uninstaller.exe C:\Programme\Java\jre1.6.0_07\bin\jucheck.exe C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Kaspersky Lab Setup Files\Kaspersky Anti-Virus 2009\german\setup.exe C:\WINDOWS\system32\msiexec.exe C:\WINDOWS\system32\MsiExec.exe C:\Programme\Microsoft Office\Office12\OUTLOOK.EXE C:\WINDOWS\system32\taskmgr.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\wuauclt.exe C:\Programme\F-Secure Internet Security\FSGUI\PostInstall.exe C:\Programme\F-Secure Internet Security\Uninstall\uninstaller.exe C:\Programme\Trend Micro\HijackThis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:8080 R3 - URLSearchHook: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Programme\Canon\Easy-WebPrint\EWPBrowseLoader.dll O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Programme\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:\Programme\Hewlett-Packard\IAM\Bin\ItIEAddIn.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programme\Canon\Easy-WebPrint\Toolband.dll O4 - HKLM\..\Run: [AccelerometerSysTrayApplet] C:\WINDOWS\system32\AccelerometerSt.exe O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe O4 - HKLM\..\Run: [Cpqset] C:\Programme\Hewlett-Packard\Default Settings\cpqset.exe O4 - HKLM\..\Run: [hpWirelessAssistant] %ProgramFiles%\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe O4 - HKLM\..\Run: [HP Software Update] c:\Programme\Hp\HP Software Update\HPWuSchd2.exe O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start O4 - HKLM\..\Run: [PTHOSTTR] c:\Programme\Hewlett-Packard\HP ProtectTools Security Manager\PTHOSTTR.EXE /Start O4 - HKLM\..\Run: [CognizanceTS] rundll32.exe c:\PROGRA~1\HEWLET~1\IAM\Bin\ASTSVCC.dll,RegisterModule O4 - HKLM\..\Run: [IFXSPMGT] c:\WINDOWS\system32\ifxspmgt.exe /NotifyLogon O4 - HKLM\..\Run: [accrdsub] "c:\Programme\ActivIdentity\ActivClient\accrdsub.exe" O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtray.exe O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exe O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exe O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe" O4 - HKLM\..\Run: [IntelWireless] "C:\Programme\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless O4 - HKLM\..\Run: [IAAnotif] "C:\Programme\Intel\Intel Matrix Storage Manager\Iaanotif.exe" O4 - HKLM\..\Run: [SynTPStart] C:\Programme\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programme\Analog Devices\Core\smax4pnp.exe O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Programme\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [NcpBudget] "C:\Programme\LANCOM-Systems\Advanced VPN Client\ncpbudgt.exe" O4 - HKLM\..\Run: [NcpPopup] "C:\Programme\LANCOM-Systems\Advanced VPN Client\ncppopup.exe" noerrmsg O4 - HKLM\..\Run: [NcpMonitor] "C:\Programme\LANCOM-Systems\Advanced VPN Client\ncpmon.exe" autorun O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programme\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "C:\Programme\Gemeinsame Dateien\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programme\F-Secure Internet Security\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\Programme\F-Secure Internet Security\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programme\Microsoft ActiveSync\Wcescomm.exe" O4 - HKCU\..\Run: [swg] C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe O4 - HKCU\..\Run: [AdobeUpdater] C:\Programme\Gemeinsame Dateien\Adobe\Updater5\AdobeUpdater.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: Microsoft Office Groove.lnk = C:\Programme\Microsoft Office\Office12\GROOVE.EXE O4 - Startup: OneNote 2007 Bildschirmausschnitt- und Startprogramm.lnk = C:\Programme\Microsoft Office\Office12\ONENOTEM.EXE O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: An vorhandenes PDF anfügen - res://C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O8 - Extra context menu item: Dial selected number / URI - C:\Programme\LANCOM\LANCOM Advanced VoIP Client\IEDial.htm O8 - Extra context menu item: Easy-WebPrint - Drucken - res://C:\Programme\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - res://C:\Programme\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint - Vorschau - res://C:\Programme\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - res://C:\Programme\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000 O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra 'Tools' menuitem: Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MICROS~3\INetRepl.dll O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\WIDCOMM\Bluetooth Software\btsendto_ie.htm O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programme\Yahoo!\Common\yinsthelper.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1204628612421 O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL O18 - Protocol: t-mobile - (no CLSID) - (no file) O20 - AppInit_DLLs: APSHook.dll O20 - Winlogon Notify: ackpbsc - c:\WINDOWS\system32\ackpbsc.dll O20 - Winlogon Notify: acunlock - c:\Programme\ActivIdentity\ActivClient\acunlock.dll O20 - Winlogon Notify: DeviceNP - C:\WINDOWS\SYSTEM32\DeviceNP.dll O20 - Winlogon Notify: OneCard - c:\Programme\Hewlett-Packard\IAM\Bin\ASWLNPkg.dll O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - c:\Programme\ActivIdentity\ActivClient\accoca.exe O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Ares Chatroom server (AresChatServer) - Ares Development Group - C:\Programme\Ares\chatServer.exe O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programme\Alwil Software\Avast4\aswUpdSv.exe (file missing) O23 - Service: Autodesk Licensing Service - Autodesk - C:\Programme\Gemeinsame Dateien\Autodesk Shared\Service\AdskScSrv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Programme\Alwil Software\Avast4\ashServ.exe (file missing) O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programme\Alwil Software\Avast4\ashMaiSv.exe (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Programme\Alwil Software\Avast4\ashWebSv.exe (file missing) O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Programme\WIDCOMM\Bluetooth Software\bin\btwdins.exe O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\EvtEng.exe O23 - Service: HP ProtectTools Gerätesperre/Überwachung (FLCDLOCK) - Hewlett-Packard Ltd - C:\WINDOWS\system32\flcdlock.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: GtFlashSwitch - OptionNV - C:\Programme\Gemeinsame Dateien\GtFlashSwitch\GtFlashSwitch.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Programme\Hewlett-Packard\Shared\hpqwmiex.exe O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Programme\Intel\Intel Matrix Storage Manager\Iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: Security Platform Management Service (IFXSpMgtSrv) - Infineon Technologies AG - c:\WINDOWS\system32\ifxspmgt.exe O23 - Service: Trusted Platform Core Service (IFXTCS) - Infineon Technologies AG - c:\WINDOWS\system32\ifxtcs.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe O23 - Service: ncpclcfg - NCP engineering GmbH - C:\Programme\LANCOM-Systems\Advanced VPN Client\ncpclcfg.exe O23 - Service: ncprwsnt - NCP Engineering GmbH - C:\Programme\LANCOM-Systems\Advanced VPN Client\ncprwsnt.exe O23 - Service: NcpSec - Unknown owner - C:\Programme\LANCOM-Systems\Advanced VPN Client\ncpsec.exe O23 - Service: Personal Secure Drive service for encrypted drives (PersonalSecureDriveService) - Infineon Technologies AG - c:\WINDOWS\system32\IfxPsdSv.exe O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\RegSrvc.exe O23 - Service: RwsRsu (rwsrsu) - Unknown owner - C:\Programme\LANCOM-Systems\Advanced VPN Client\rwsrsu.exe O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\S24EvMon.exe O23 - Service: ServiceLayer - Nokia. - C:\Programme\PC Connectivity Solution\ServiceLayer.exe O23 - Service: Broadcom Wireless LAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE -- End of file - 19092 bytes Vielleicht könnt ihr mir helfen - danke! |
![]() | #2 |
![]() | ![]() Virus-Problem Nachtrag:
__________________Konnte escan installieren, hat nichts gefunden! Anti-Malware-Software wie z.B. Spybot u.a. werden nicht gestartet |
![]() | #3 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Virus-Problemhi und ![]() Gebe unter Start/Ausfuehren devmgmt.msc ein und druecke Enter, dann ueber "Ansicht", "Ausgeblendete Geraete anzeigen" waehlen, "nicht-PNP-Treiber" anzeigen lassen und dort den Treiber "TDSSserv.sys" oder aehnlich deaktivieren und neu starten. === Gmer scannen lassen Lade dir Gmer von dieser Seite runter und entpacke es auf deinen Desktop.
__________________ |
![]() | #4 |
![]() | ![]() Virus-Problem hallo schrauber, danke für deine hilfe, alles nach deiner anleitung gemacht, aber das prob ist, mein log hat 216539 zeichen und ich kann hier nur 25000 zeichen posten. was nun? |
![]() | #5 |
/// the machine /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Virus-Problem log aufteilen und posten ![]()
__________________ gruß, schrauber Proud Member of UNITE and ASAP since 2009 Spenden Anleitungen und Hilfestellungen Trojaner-Board Facebook-Seite Keine Hilfestellung via PM! |
![]() | #6 |
![]() | ![]() Virus-Problem GMER 1.0.14.14536 - http://www.gmer.net Rootkit scan 2009-01-25 08:24:50 Windows 5.1.2600 Service Pack 3 ---- System - GMER 1.0.14 ---- SSDT spso.sys ZwCreateKey [0xF73670E0] <-- ROOTKIT !!! SSDT spso.sys ZwEnumerateKey [0xF7385CA2] <-- ROOTKIT !!! SSDT spso.sys ZwEnumerateValueKey [0xF7386030] <-- ROOTKIT !!! SSDT spso.sys ZwOpenKey [0xF73670C0] <-- ROOTKIT !!! SSDT spso.sys ZwQueryKey [0xF7386108] <-- ROOTKIT !!! SSDT spso.sys ZwQueryValueKey [0xF7385F88] <-- ROOTKIT !!! SSDT spso.sys ZwSetValueKey [0xF738619A] <-- ROOTKIT !!! INT 0x62 ? 8B1DABF8 INT 0x63 ? 8B24BBF8 INT 0x63 ? 8A738BF8 INT 0x73 ? 8A738BF8 INT 0x73 ? 8A738BF8 INT 0x73 ? 8A738BF8 INT 0x83 ? 8A738BF8 INT 0x94 ? 8A738BF8 INT 0xA4 ? 8A738BF8 ---- Kernel code sections - GMER 1.0.14 ---- ? spso.sys Das System kann die angegebene Datei nicht finden. ! .text USBPORT.SYS!DllUnload F4F988AC 5 Bytes JMP 8A7381D8 .text a481x64z.SYS F4C50386 35 Bytes [ 00, 00, 00, 00, 00, 00, 20, ... ] .text a481x64z.SYS F4C503AA 24 Bytes [ 00, 00, 00, 00, 00, 00, 00, ... ] .text a481x64z.SYS F4C503C4 3 Bytes [ 00, 70, 02 ] .text a481x64z.SYS F4C503C9 1 Byte [ 2E ] .text a481x64z.SYS F4C503CB 9 Bytes [ 00, 00, 5A, 02, 00, 00, 00, ... ] .text ... ---- User code sections - GMER 1.0.14 ---- .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] kernel32.dll!FindNextFileW 7C80EFCA 13 Bytes [ 58, 68, CA, EF, C5, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] kernel32.dll!ExitProcess 7C81CAFA 7 Bytes [ 58, 68, FA, CA, C6, 02, 50 ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] kernel32.dll!ExitProcess + 8 7C81CB02 5 Bytes [ 09, C0, 5A, 02, C3 ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] kernel32.dll!FindNextFileA 7C834EC9 7 Bytes [ 58, 68, C9, 4E, C8, 02, 50 ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] kernel32.dll!FindNextFileA + 8 7C834ED1 5 Bytes [ 8E, C1, 5A, 02, C3 ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] ADVAPI32.dll!CryptDeriveKey 77DB9FDD 13 Bytes [ 58, 68, DD, 9F, E2, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] ADVAPI32.dll!CryptImportKey 77DBA1D1 13 Bytes [ 58, 68, D1, A1, E2, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] ADVAPI32.dll!CryptGenKey 77DE17D9 13 Bytes [ 58, 68, D9, 17, E5, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] WININET.dll!HttpOpenRequestA 441F4399 13 Bytes [ 58, 68, 99, 43, FA, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] WININET.dll!InternetConnectA 441F49F2 13 Bytes [ 58, 68, F2, 49, FA, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] WININET.dll!HttpOpenRequestW 441F5DBA 13 Bytes [ 58, 68, BA, 5D, FA, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] WININET.dll!InternetReadFile 441FABF4 13 Bytes [ 58, 68, F4, AB, FA, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] WININET.dll!InternetQueryDataAvailable 441FAE35 13 Bytes [ 58, 68, 35, AE, FA, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] WININET.dll!HttpSendRequestA 441FCD78 13 Bytes [ 58, 68, 78, CD, FA, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] WININET.dll!InternetWriteFile 44203675 13 Bytes [ 58, 68, 75, 36, FB, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] WININET.dll!CommitUrlCacheEntryA 4420FC82 13 Bytes [ 58, 68, 82, FC, FB, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] WININET.dll!HttpSendRequestW 4421103D 13 Bytes [ 58, 68, 3D, 10, FC, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] WININET.dll!InternetReadFileExW 442132C6 13 Bytes [ 58, 68, C6, 32, FC, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] WININET.dll!InternetReadFileExA 442132FE 13 Bytes [ 58, 68, FE, 32, FC, 02, 50, ... ] .text C:\Programme\Intel\Wireless\Bin\S24EvMon.exe[240] WININET.dll!InternetErrorDlg 4426C5EB 13 Bytes [ 58, 68, EB, C5, 01, 03, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] kernel32.dll!FindNextFileW 7C80EFCA 13 Bytes [ 58, 68, CA, EF, 01, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] kernel32.dll!ExitProcess 7C81CAFA 7 Bytes [ 58, 68, FA, CA, 02, 01, 50 ] .text C:\WINDOWS\system32\spoolsv.exe[272] kernel32.dll!ExitProcess + 8 7C81CB02 5 Bytes [ 09, C0, BB, 00, C3 ] .text C:\WINDOWS\system32\spoolsv.exe[272] kernel32.dll!FindNextFileA 7C834EC9 7 Bytes [ 58, 68, C9, 4E, 04, 01, 50 ] .text C:\WINDOWS\system32\spoolsv.exe[272] kernel32.dll!FindNextFileA + 8 7C834ED1 5 Bytes [ 8E, C1, BB, 00, C3 ] .text C:\WINDOWS\system32\spoolsv.exe[272] ADVAPI32.dll!CryptDeriveKey 77DB9FDD 13 Bytes [ 58, 68, DD, 9F, 13, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] ADVAPI32.dll!CryptImportKey 77DBA1D1 13 Bytes [ 58, 68, D1, A1, 13, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] ADVAPI32.dll!CryptGenKey 77DE17D9 13 Bytes [ 58, 68, D9, 17, 16, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] wininet.dll!HttpOpenRequestA 441F4399 13 Bytes [ 58, 68, 99, 43, 2B, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] wininet.dll!InternetConnectA 441F49F2 13 Bytes [ 58, 68, F2, 49, 2B, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] wininet.dll!HttpOpenRequestW 441F5DBA 13 Bytes [ 58, 68, BA, 5D, 2B, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] wininet.dll!InternetReadFile 441FABF4 13 Bytes [ 58, 68, F4, AB, 2B, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] wininet.dll!InternetQueryDataAvailable 441FAE35 13 Bytes [ 58, 68, 35, AE, 2B, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] wininet.dll!HttpSendRequestA 441FCD78 13 Bytes [ 58, 68, 78, CD, 2B, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] wininet.dll!InternetWriteFile 44203675 13 Bytes [ 58, 68, 75, 36, 2C, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] wininet.dll!CommitUrlCacheEntryA 4420FC82 13 Bytes [ 58, 68, 82, FC, 2C, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] wininet.dll!HttpSendRequestW 4421103D 13 Bytes [ 58, 68, 3D, 10, 2D, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] wininet.dll!InternetReadFileExW 442132C6 13 Bytes [ 58, 68, C6, 32, 2D, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] wininet.dll!InternetReadFileExA 442132FE 13 Bytes [ 58, 68, FE, 32, 2D, 01, 50, ... ] .text C:\WINDOWS\system32\spoolsv.exe[272] wininet.dll!InternetErrorDlg 4426C5EB 13 Bytes [ 58, 68, EB, C5, 32, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] kernel32.dll!FindNextFileW 7C80EFCA 13 Bytes [ 58, 68, CA, EF, 59, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] kernel32.dll!ExitProcess 7C81CAFA 7 Bytes [ 58, 68, FA, CA, 5A, 01, 50 ] .text C:\WINDOWS\system32\winlogon.exe[732] kernel32.dll!ExitProcess + 8 7C81CB02 5 Bytes [ 09, C0, 40, 01, C3 ] .text C:\WINDOWS\system32\winlogon.exe[732] kernel32.dll!FindNextFileA 7C834EC9 7 Bytes [ 58, 68, C9, 4E, 5C, 01, 50 ] .text C:\WINDOWS\system32\winlogon.exe[732] kernel32.dll!FindNextFileA + 8 7C834ED1 5 Bytes [ 8E, C1, 40, 01, C3 ] .text C:\WINDOWS\system32\winlogon.exe[732] ADVAPI32.dll!CryptDeriveKey 77DB9FDD 13 Bytes [ 58, 68, DD, 9F, 76, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] ADVAPI32.dll!CryptImportKey 77DBA1D1 13 Bytes [ 58, 68, D1, A1, 76, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] ADVAPI32.dll!CryptGenKey 77DE17D9 13 Bytes [ 58, 68, D9, 17, 79, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] wininet.dll!HttpOpenRequestA 441F4399 13 Bytes [ 58, 68, 99, 43, 8E, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] wininet.dll!InternetConnectA 441F49F2 13 Bytes [ 58, 68, F2, 49, 8E, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] wininet.dll!HttpOpenRequestW 441F5DBA 13 Bytes [ 58, 68, BA, 5D, 8E, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] wininet.dll!InternetReadFile 441FABF4 13 Bytes [ 58, 68, F4, AB, 8E, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] wininet.dll!InternetQueryDataAvailable 441FAE35 13 Bytes [ 58, 68, 35, AE, 8E, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] wininet.dll!HttpSendRequestA 441FCD78 13 Bytes [ 58, 68, 78, CD, 8E, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] wininet.dll!InternetWriteFile 44203675 13 Bytes [ 58, 68, 75, 36, 8F, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] wininet.dll!CommitUrlCacheEntryA 4420FC82 13 Bytes [ 58, 68, 82, FC, 8F, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] wininet.dll!HttpSendRequestW 4421103D 13 Bytes [ 58, 68, 3D, 10, 90, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] wininet.dll!InternetReadFileExW 442132C6 13 Bytes [ 58, 68, C6, 32, 90, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] wininet.dll!InternetReadFileExA 442132FE 13 Bytes [ 58, 68, FE, 32, 90, 01, 50, ... ] .text C:\WINDOWS\system32\winlogon.exe[732] wininet.dll!InternetErrorDlg 4426C5EB 13 Bytes [ 58, 68, EB, C5, 95, 01, 50, ... ] .text C:\WINDOWS\system32\savedump.exe[1096] kernel32.dll!FindNextFileW 7C80EFCA 13 Bytes [ 58, 68, CA, EF, D5, 00, 50, ... ] |
![]() |
Themen zu Virus-Problem |
abgesicherten modus, adobe, avast!, bho, bildschirm, bluescree, bluescreen, canon, crypted, einstellungen, encrypted, entfernen, excel, f-secure, firefox, google, helper, hijack, hijackthis, hkus\s-1-5-18, internet, internet explorer, internet security, kaspersky, kein bluescreen, konvertieren, launch, mozilla, object, pdf-datei, pop-up-blocker, problem, registry, rundll, security, senden, software, solution, symantec, t-mobile, windows xp, windows-tool, wireless lan |