Hallo
Bin neu und total ratloß :-(
hier meine log
Zitat:
Malwarebytes' Anti-Malware 1.38
Datenbank Version: 2319
Windows 5.1.2600 Service Pack 3
21.06.2009 20:53:54
mbam-log-2009-06-21 (20-53-54).txt
Scan-Methode: Vollständiger Scan (C:\|D:\|)
Durchsuchte Objekte: 185114
Laufzeit: 27 minute(s), 6 second(s)
Infizierte Speicherprozesse: 3
Infizierte Speichermodule: 2
Infizierte Registrierungsschlüssel: 3
Infizierte Registrierungswerte: 3
Infizierte Dateiobjekte der Registrierung: 0
Infizierte Verzeichnisse: 0
Infizierte Dateien: 22
Infizierte Speicherprozesse:
C:\WINDOWS.0\system32\B.tmp (Trojan.Dropper) -> Failed to unload process.
C:\Dokumente und Einstellungen\egolectro\reader_s.exe (Trojan.FakeAlert) -> Unloaded process successfully.
C:\WINDOWS.0\system32\reader_s.exe (Trojan.FakeAlert) -> Unloaded process successfully.
Infizierte Speichermodule:
C:\WINDOWS.0\system32\iknszg.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\WINDOWS.0\system32\iknszg32.dll (Trojan.FakeAlert) -> Delete on reboot.
Infizierte Registrierungsschlüssel:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\iknszg (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\System\CurrentControlSet\Services\Protect (Rootkit.Agent) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\AGprotect (Malware.Trace) -> Quarantined and deleted successfully.
Infizierte Registrierungswerte:
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_USERS\.DEFAULT\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.FakeAlert) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\reader_s (Trojan.FakeAlert) -> Quarantined and deleted successfully.
Infizierte Dateiobjekte der Registrierung:
(Keine bösartigen Objekte gefunden)
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
C:\WINDOWS.0\system32\iknszg.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\WINDOWS.0\system32\iknszg32.dll (Trojan.FakeAlert) -> Delete on reboot.
C:\WINDOWS.0\system32\B.tmp (Trojan.Dropper) -> Delete on reboot.
C:\Dokumente und Einstellungen\noname\reader_s.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
C:\WINDOWS.0\system32\reader_s.exe (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\dokumente und einstellungen\noname\lokale einstellungen\anwendungsdaten\Mozilla\Firefox\Profiles\pwa7702u.default\Cache\3607235Ad01 (Trojan.Agent) -> Quarantined and deleted successfully.
c:\dokumente und einstellungen\noname\lokale einstellungen\temporary internet files\Content.IE5\HY51FVMX\abb[1].txt (Trojan.FakeAlert) -> Quarantined and deleted successfully.
c:\dokumente und einstellungen\noname\lokale einstellungen\temporary internet files\Content.IE5\ILKYJBYU\em[1].htm (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\WINDOWS.0\system32\5.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\WINDOWS.0\system32\8.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\WINDOWS.0\system32\A5.tmp (Trojan.Dropper) -> Quarantined and deleted successfully.
c:\WINDOWS.0\system32\drivers\protect.sys (Rootkit.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS.0\system32\2.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS.0\system32\3.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS.0\system32\4.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS.0\system32\6.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS.0\system32\7.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS.0\system32\A.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
C:\WINDOWS.0\Temp\BN1.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
c:\WINDOWS.0\Temp\BNB5.tmp (Trojan.Agent) -> Quarantined and deleted successfully.
|
Ich hoffe es ist alles richtig gepostet