![]() |
|
Plagegeister aller Art und deren Bekämpfung: BDS/Agent.AYWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() BDS/Agent.AY Hi, mein AntiVir hat heute bei mir das Backdorrprogram BDS/Agent.AY gefunden. Ich hoffe es kann mir hier jemand erklären wie ich es wieder los werde. Logfile of HijackThis v1.98.2 Scan saved at 10:46:46, on 22.09.2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\system32\slserv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\htpatch.exe C:\WINDOWS\System32\khooker.exe C:\PROGRA~1\T-DSLS~1\SpeedMgr.exe C:\Programme\AVPersonal\AVGNT.EXE C:\Programme\Gemeinsame Dateien\CMEII\CMESys.exe C:\WINDOWS\System32\ctfmon.exe C:\Programme\Gemeinsame Dateien\GMT\GMT.exe C:\Programme\T-DSL SpeedManager\tsmsvc.exe C:\Programme\AVPersonal\AVGUARD.EXE C:\Dokumente und Einstellungen\MD\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe O4 - HKLM\..\Run: [T-DSL SpeedMgr] "C:\PROGRA~1\T-DSLS~1\SpeedMgr.exe" O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min O4 - HKLM\..\Run: [WinampAgent] "C:\Programme\Winamp\Winampa.exe" O4 - HKLM\..\Run: [CMESys] "C:\Programme\Gemeinsame Dateien\CMEII\CMESys.exe" O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - Global Startup: Adobe Gamma Loader.lnk = ? O4 - Global Startup: GStartup.lnk = C:\Programme\Gemeinsame Dateien\GMT\GMT.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Programme\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\Programme\ICQ\ICQ.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm Hier die Ergebnisse von eScan: Wed Sep 22 11:55:06 2004 => Scanning Folder: C:\WINDOWS\WinSxS\Manifests\*.* Wed Sep 22 11:55:07 2004 => Scanning Folder: C:\WINDOWS\WinSxS\Policies\*.* Wed Sep 22 11:55:07 2004 => Scanning Folder: C:\WINDOWS\WinSxS\Policies\x86_policy.1.0.Microsoft.Windows.GdiPlus_6595b64144ccf1df_x-ww_4e8510ac\*.* Wed Sep 22 11:55:07 2004 => Scanning Folder: C:\WINDOWS\WinSxS\Policies\x86_policy.6.0.Microsoft.Windows.Common-Controls_6595b64144ccf1df_x-ww_5ddad775\*.* Wed Sep 22 11:55:07 2004 => Scanning Folder: C:\WINDOWS\WinSxS\Policies\x86_policy.7.0.Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_x-ww_a317e4b3\*.* Wed Sep 22 11:55:07 2004 => Scanning Folder: C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2R_6bd6b9abf345378f_4.0.2.0_x-ww_e6d36d6b\*.* Wed Sep 22 11:55:07 2004 => Scanning Folder: C:\WINDOWS\WinSxS\x86_Microsoft.MSXML2_6bd6b9abf345378f_4.0.2.0_x-ww_702998db\*.* Wed Sep 22 11:55:07 2004 => Scanning Folder: C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries.Resources_6595b64144ccf1df_6.0.0.0_de-DE_b5f95279\*.* Wed Sep 22 11:55:07 2004 => Scanning Folder: C:\WINDOWS\WinSxS\x86_Microsoft.Tools.VisualCPlusPlus.Runtime-Libraries_6595b64144ccf1df_6.0.0.0_x-ww_ff9986d7\*.* Wed Sep 22 11:55:08 2004 => Scanning Folder: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.0.0_x-ww_1382d70a\*.* Wed Sep 22 11:55:08 2004 => Scanning Folder: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805\*.* Wed Sep 22 11:55:08 2004 => Scanning Folder: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.0.0_x-ww_2726e76a\*.* Wed Sep 22 11:55:08 2004 => Scanning Folder: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.CPlusPlusRuntime_6595b64144ccf1df_7.0.10.0_x-ww_d8862ba3\*.* Wed Sep 22 11:55:09 2004 => Scanning Folder: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.0.0_x-ww_8d353f13\*.* Wed Sep 22 11:55:09 2004 => Scanning Folder: C:\WINDOWS\WinSxS\x86_Microsoft.Windows.GdiPlus_6595b64144ccf1df_1.0.10.0_x-ww_712befd8\*.* Wed Sep 22 11:55:09 2004 => Scanning Folder: C:\WLAN-PC-Card\*.* Wed Sep 22 11:55:10 2004 => Scanning Folder: C:\WUTemp\*.* Wed Sep 22 11:55:10 2004 => ***** Checking for specific ITW Viruses ***** Wed Sep 22 11:55:10 2004 => Checking for Welchia Virus... Wed Sep 22 11:55:10 2004 => Checking for LovGate Virus... Wed Sep 22 11:55:10 2004 => Checking for CodeRed Virus... Wed Sep 22 11:55:10 2004 => Checking for OpaServ Virus... Wed Sep 22 11:55:10 2004 => Checking for Sobig.e Virus... Wed Sep 22 11:55:10 2004 => Checking for Winupie Virus... Wed Sep 22 11:55:10 2004 => Checking for Swen Virus... Wed Sep 22 11:55:10 2004 => Checking for JS.Fortnight Virus... Wed Sep 22 11:55:10 2004 => Checking for Novarg Virus... Wed Sep 22 11:55:10 2004 => Checking for Pagabot Virus... Wed Sep 22 11:55:10 2004 => Checking for Parite.b Virus... Wed Sep 22 11:55:10 2004 => Checking for Parite.a Virus... Wed Sep 22 11:55:10 2004 => ***** Scanning complete. ***** Wed Sep 22 11:55:10 2004 => Total Number of Files Scanned: 45661 Wed Sep 22 11:55:10 2004 => Total Number of Virus(es) Found: 24 Wed Sep 22 11:55:10 2004 => Total Number of Disinfected Files: 0 Wed Sep 22 11:55:10 2004 => Total Number of Files Renamed: 20 Wed Sep 22 11:55:10 2004 => Total Number of Deleted Files: 0 Wed Sep 22 11:55:10 2004 => Total Number of Errors: 6 Wed Sep 22 11:55:10 2004 => Time Elapsed: 01:05:33 Wed Sep 22 11:55:10 2004 => Virus Database Date: 2004/09/22 Wed Sep 22 11:55:10 2004 => Virus Database Count: 104407 Wed Sep 22 11:55:10 2004 => Scan Completed. File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. File C:\PROGRA~1\GEMEIN~1\CMEII\CMESys.exe infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\PROGRA~1\GEMEIN~1\GMT\GMT.exe infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. File C:\Dokumente und Einstellungen\MD\Eigene Dateien\Installationsdateien\DivXPro511Adware.exe infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\Programme\AVPersonal\INFECTED\ECLAMMTCR.EXE.001 infected by "Backdoor.Agent.ay" Virus. Action Taken: File Renamed. File C:\Programme\AVPersonal\INFECTED\ECLAMMTCR.EXE.VIR infected by "Backdoor.Agent.ay" Virus. Action Taken: File Renamed. File C:\Programme\AVPersonal\INFECTED\TALRMLLL.EXE.001 infected by "Backdoor.Agent.ay" Virus. Action Taken: File Renamed. File C:\Programme\AVPersonal\INFECTED\TALRMLLL.EXE.VIR infected by "Backdoor.Agent.ay" Virus. Action Taken: File Renamed. File C:\Programme\Gemeinsame Dateien\GMT\EGGCEngine.dll infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\Programme\Gemeinsame Dateien\GMT\EGIEProcess.dll infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\Programme\Gemeinsame Dateien\GMT\EGNSEngine.dll infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\Programme\Gemeinsame Dateien\GMT\GatorStubSetup.exe infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\Programme\Gemeinsame Dateien\GMT\gtrawbm.fil infected by "Backdoor.Agent.ay" Virus. Action Taken: File Renamed. File C:\System Volume Information\_restore{641CBEE9-67C4-4A3F-8137-7BEADDCC9247}\RP61\A0031031.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\System Volume Information\_restore{641CBEE9-67C4-4A3F-8137-7BEADDCC9247}\RP61\A0031032.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. File C:\System Volume Information\_restore{641CBEE9-67C4-4A3F-8137-7BEADDCC9247}\RP76\A0035841.exe infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\System Volume Information\_restore{641CBEE9-67C4-4A3F-8137-7BEADDCC9247}\RP76\A0035842.exe infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\System Volume Information\_restore{641CBEE9-67C4-4A3F-8137-7BEADDCC9247}\RP76\A0035843.dll infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\System Volume Information\_restore{641CBEE9-67C4-4A3F-8137-7BEADDCC9247}\RP76\A0035844.dll infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\System Volume Information\_restore{641CBEE9-67C4-4A3F-8137-7BEADDCC9247}\RP76\A0035845.dll infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\System Volume Information\_restore{641CBEE9-67C4-4A3F-8137-7BEADDCC9247}\RP76\A0035846.exe infected by "not-a-virus:AdvWare.Gator" Virus. Action Taken: File Renamed. File C:\WINDOWS\htpatch.exe tagged as not-a-virus:Tool.Win32.HTPatch.a. No Action Taken. |
Themen zu BDS/Agent.AY |
1.exe, adobe, antivir, avg, button, dateien, desktop, einstellungen, escan, explorer, hijack, hijackthis, icq, internet, internet explorer, links, microsoft, not-a-virus, programme, software, start, system, system volume information, system32, windows, windows xp |