|
Log-Analyse und Auswertung: Windows PC Defender und was noch?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
08.10.2009, 16:42 | #1 |
| Windows PC Defender und was noch? Hallo, seit heute öffnet sich eine "infektionsmeldung" des Windows PC Defender auf meinem Rechner (Meldung = "21 infizierte Viren"). Zudem hat sich McAffe ausgeschaltet und Antivir lässt sich nicht installieren. Hier kommt das HiJack File...es wäre super, wenn da mal jemand reinschauen könnte. Es ist mein Arbeitsrechner (auf der Arbeit). Danke!!! Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 5:34:00 PM, on 10/8/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\eEBSVC.exe C:\Programme\Cisco Systems\VPN Client\cvpnd.exe C:\WINDOWS\SYSTEM32\DNTUS26.EXE C:\WINDOWS\system32\hpb2ksrv.exe C:\WINDOWS\system32\hpbhksrv.exe C:\Programme\Java\jre6\bin\jqs.exe C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe C:\Programme\McAfee\Common Framework\FrameworkService.exe C:\Programme\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\WINDOWS\Explorer.EXE C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe C:\Programme\Winamp\winampa.exe C:\Programme\McAfee\Common Framework\UdaterUI.exe C:\Programme\Java\jre6\bin\jusched.exe C:\Programme\McAfee\Common Framework\McTray.exe C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\e35dc97\WPe35d.exe C:\Programme\Messenger\msmsgs.exe C:\Programme\Google\Google Talk\googletalk.exe C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Programme\Java\jre6\bin\jucheck.exe C:\Programme\Avira\AntiVir Desktop\avguard.exe C:\Programme\Avira\AntiVir Desktop\sched.exe C:\Programme\Internet Explorer\iexplore.exe C:\Programme\Real\RealPlayer\RealPlay.exe C:\Programme\Mozilla Firefox\firefox.exe C:\Dokumente und Einstellungen\puuh\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ep4.rub.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = hxxp://odysseus.ep4.ruhr-uni-bochum.de/proxy.pac O1 - Hosts: 74.125.45.100 4-open-davinci.com O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com O1 - Hosts: 74.125.45.100 privatesecuredpayments.com O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com O1 - Hosts: 74.125.45.100 getantivirusplusnow.com O1 - Hosts: 74.125.45.100 secure-plus-payments.com O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com O1 - Hosts: 74.125.45.100 www.getavplusnow.com O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com O1 - Hosts: 74.125.45.100 paysoftbillsolution.com O1 - Hosts: 64.86.16.97 google.ae O1 - Hosts: 64.86.16.97 google.as O1 - Hosts: 64.86.16.97 google.at O1 - Hosts: 64.86.16.97 google.az O1 - Hosts: 64.86.16.97 google.ba O1 - Hosts: 64.86.16.97 google.be O1 - Hosts: 64.86.16.97 google.bg O1 - Hosts: 64.86.16.97 google.bs O1 - Hosts: 64.86.16.97 google.ca O1 - Hosts: 64.86.16.97 google.cd O1 - Hosts: 64.86.16.97 google.com.gh O1 - Hosts: 64.86.16.97 google.com.hk O1 - Hosts: 64.86.16.97 google.com.jm O1 - Hosts: 64.86.16.97 google.com.mx O1 - Hosts: 64.86.16.97 google.com.my O1 - Hosts: 64.86.16.97 google.com.na O1 - Hosts: 64.86.16.97 google.com.nf O1 - Hosts: 64.86.16.97 google.com.ng O1 - Hosts: 64.86.16.97 google.ch O1 - Hosts: 64.86.16.97 google.com.np O1 - Hosts: 64.86.16.97 google.com.pr O1 - Hosts: 64.86.16.97 google.com.qa O1 - Hosts: 64.86.16.97 google.com.sg O1 - Hosts: 64.86.16.97 google.com.tj O1 - Hosts: 64.86.16.97 google.com.tw O1 - Hosts: 64.86.16.97 google.dj O1 - Hosts: 64.86.16.97 google.de O1 - Hosts: 64.86.16.97 google.dk O1 - Hosts: 64.86.16.97 google.dm O1 - Hosts: 64.86.16.97 google.ee O1 - Hosts: 64.86.16.97 google.fi O1 - Hosts: 64.86.16.97 google.fm O1 - Hosts: 64.86.16.97 google.fr O1 - Hosts: 64.86.16.97 google.ge O1 - Hosts: 64.86.16.97 google.gg O1 - Hosts: 64.86.16.97 google.gm O1 - Hosts: 64.86.16.97 google.gr O1 - Hosts: 64.86.16.97 google.ht O1 - Hosts: 64.86.16.97 google.ie O1 - Hosts: 64.86.16.97 google.im O1 - Hosts: 64.86.16.97 google.in O1 - Hosts: 64.86.16.97 google.it O1 - Hosts: 64.86.16.97 google.ki O1 - Hosts: 64.86.16.97 google.la O1 - Hosts: 64.86.16.97 google.li O1 - Hosts: 64.86.16.97 google.lv O1 - Hosts: 64.86.16.97 google.ma O1 - Hosts: 64.86.16.97 google.ms O1 - Hosts: 64.86.16.97 google.mu O1 - Hosts: 64.86.16.97 google.mw O1 - Hosts: 64.86.16.97 google.nl O1 - Hosts: 64.86.16.97 google.no O1 - Hosts: 64.86.16.97 google.nr O1 - Hosts: 64.86.16.97 google.nu O1 - Hosts: 64.86.16.97 google.pl O1 - Hosts: 64.86.16.97 google.pn O1 - Hosts: 64.86.16.97 google.pt O1 - Hosts: 64.86.16.97 google.ro O1 - Hosts: 64.86.16.97 google.ru O1 - Hosts: 64.86.16.97 google.rw O1 - Hosts: 64.86.16.97 google.sc O1 - Hosts: 64.86.16.97 google.se O1 - Hosts: 64.86.16.97 google.sh O1 - Hosts: 64.86.16.97 google.si O1 - Hosts: 64.86.16.97 google.sm O1 - Hosts: 64.86.16.97 google.sn O1 - Hosts: 64.86.16.97 google.st O1 - Hosts: 64.86.16.97 google.tl O1 - Hosts: 64.86.16.97 google.tm O1 - Hosts: 64.86.16.97 google.tt O1 - Hosts: 64.86.16.97 google.us O1 - Hosts: 64.86.16.97 google.vu O1 - Hosts: 64.86.16.97 google.ws O1 - Hosts: 64.86.16.97 google.co.ck O1 - Hosts: 64.86.16.97 google.co.id O1 - Hosts: 64.86.16.97 google.co.il O1 - Hosts: 64.86.16.97 google.co.in O1 - Hosts: 64.86.16.97 google.co.jp O1 - Hosts: 64.86.16.97 google.co.kr O1 - Hosts: 64.86.16.97 google.co.ls O1 - Hosts: 64.86.16.97 google.co.ma O1 - Hosts: 64.86.16.97 google.co.nz O1 - Hosts: 64.86.16.97 google.co.tz O1 - Hosts: 64.86.16.97 google.co.ug O1 - Hosts: 64.86.16.97 google.co.uk O1 - Hosts: 64.86.16.97 google.co.za O1 - Hosts: 64.86.16.97 google.co.zm O1 - Hosts: 64.86.16.97 google.com O1 - Hosts: 64.86.16.97 google.com.af O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\McAfee\VirusScan Enterprise\scriptcl.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ShStatEXE] "C:\Programme\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Programme\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [Windows PC Defender] "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\e35dc97\WPe35d.exe" /s /d O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ccleaner] "c:\Programme\ccleaner\CCleaner.exe" /AUTO O4 - HKCU\..\Run: [googletalk] "C:\Programme\Google\Google Talk\googletalk.exe" /autostart O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Acrobat Assistant.lnk = C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: VPN Client.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programme\Yahoo!\Common\yinsthelper.dll O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ep4.ruhr-uni-bochum.de O17 - HKLM\Software\..\Telephony: DomainName = ep4.ruhr-uni-bochum.de O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ep4.ruhr-uni-bochum.de O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\avguard.exe O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programme\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: DameWare NT Utilities 2.6 (DNTUS26) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DNTUS26.EXE O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\eEBSVC.exe O23 - Service: HP Status - Hewlett-Packard Company - C:\WINDOWS\system32\hpb2ksrv.exe O23 - Service: HP Status Print - Hewlett-Packard Company - C:\WINDOWS\system32\hpbhksrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Programme\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Programme\McAfee\VirusScan Enterprise\Mcshield.exe O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Programme\McAfee\VirusScan Enterprise\VsTskMgr.exe O23 - Service: PsExec (PSEXESVC) - Sysinternals - C:\WINDOWS\PSEXESVC.EXE O23 - Service: Trend NT Realtime Service (Tmntsrv) - Unknown owner - C:\Programme\Trend Micro\PC-cillin 2002\Tmntsrv.exe (file missing) -- End of file - 11938 bytes |
08.10.2009, 17:02 | #2 |
| Windows PC Defender und was noch? Hallo,
__________________ich habe MBAM drüber laufen lassen. Hier kommen die log files (749 Infektionen). Hier der Link zu den MBAM Files hxxp://rapidshare.com/files/290328638/MBAM_Files.rar.html und hier nochmal ein hijack log file Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 6:04:08 PM, on 10/8/2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\Avira\AntiVir Desktop\sched.exe C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\eEBSVC.exe C:\Programme\Avira\AntiVir Desktop\avguard.exe C:\Programme\Cisco Systems\VPN Client\cvpnd.exe C:\WINDOWS\SYSTEM32\DNTUS26.EXE C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\hpb2ksrv.exe C:\WINDOWS\system32\hpbhksrv.exe C:\Programme\Java\jre6\bin\jqs.exe C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe C:\Programme\Winamp\winampa.exe C:\Programme\McAfee\Common Framework\UdaterUI.exe C:\Programme\Java\jre6\bin\jusched.exe C:\Programme\Avira\AntiVir Desktop\avgnt.exe C:\Programme\McAfee\Common Framework\McTray.exe C:\Programme\Messenger\msmsgs.exe C:\Programme\Google\Google Talk\googletalk.exe C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe C:\Programme\McAfee\Common Framework\FrameworkService.exe C:\Programme\McAfee\VirusScan Enterprise\Mcshield.exe C:\Programme\McAfee\VirusScan Enterprise\VsTskMgr.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wbem\wmiapsrv.exe C:\Programme\Java\jre6\bin\jucheck.exe C:\Programme\Real\RealPlayer\RealPlay.exe C:\Dokumente und Einstellungen\puuh\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ep4.rub.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = hxxp://odysseus.ep4.ruhr-uni-bochum.de/proxy.pac O1 - Hosts: 74.125.45.100 4-open-davinci.com O1 - Hosts: 74.125.45.100 securitysoftwarepayments.com O1 - Hosts: 74.125.45.100 privatesecuredpayments.com O1 - Hosts: 74.125.45.100 secure.privatesecuredpayments.com O1 - Hosts: 74.125.45.100 getantivirusplusnow.com O1 - Hosts: 74.125.45.100 secure-plus-payments.com O1 - Hosts: 74.125.45.100 www.getantivirusplusnow.com O1 - Hosts: 74.125.45.100 www.secure-plus-payments.com O1 - Hosts: 74.125.45.100 www.getavplusnow.com O1 - Hosts: 74.125.45.100 www.securesoftwarebill.com O1 - Hosts: 74.125.45.100 secure.paysecuresystem.com O1 - Hosts: 74.125.45.100 paysoftbillsolution.com O1 - Hosts: 64.86.16.97 google.ae O1 - Hosts: 64.86.16.97 google.as O1 - Hosts: 64.86.16.97 google.at O1 - Hosts: 64.86.16.97 google.az O1 - Hosts: 64.86.16.97 google.ba O1 - Hosts: 64.86.16.97 google.be O1 - Hosts: 64.86.16.97 google.bg O1 - Hosts: 64.86.16.97 google.bs O1 - Hosts: 64.86.16.97 google.ca O1 - Hosts: 64.86.16.97 google.cd O1 - Hosts: 64.86.16.97 google.com.gh O1 - Hosts: 64.86.16.97 google.com.hk O1 - Hosts: 64.86.16.97 google.com.jm O1 - Hosts: 64.86.16.97 google.com.mx O1 - Hosts: 64.86.16.97 google.com.my O1 - Hosts: 64.86.16.97 google.com.na O1 - Hosts: 64.86.16.97 google.com.nf O1 - Hosts: 64.86.16.97 google.com.ng O1 - Hosts: 64.86.16.97 google.ch O1 - Hosts: 64.86.16.97 google.com.np O1 - Hosts: 64.86.16.97 google.com.pr O1 - Hosts: 64.86.16.97 google.com.qa O1 - Hosts: 64.86.16.97 google.com.sg O1 - Hosts: 64.86.16.97 google.com.tj O1 - Hosts: 64.86.16.97 google.com.tw O1 - Hosts: 64.86.16.97 google.dj O1 - Hosts: 64.86.16.97 google.de O1 - Hosts: 64.86.16.97 google.dk O1 - Hosts: 64.86.16.97 google.dm O1 - Hosts: 64.86.16.97 google.ee O1 - Hosts: 64.86.16.97 google.fi O1 - Hosts: 64.86.16.97 google.fm O1 - Hosts: 64.86.16.97 google.fr O1 - Hosts: 64.86.16.97 google.ge O1 - Hosts: 64.86.16.97 google.gg O1 - Hosts: 64.86.16.97 google.gm O1 - Hosts: 64.86.16.97 google.gr O1 - Hosts: 64.86.16.97 google.ht O1 - Hosts: 64.86.16.97 google.ie O1 - Hosts: 64.86.16.97 google.im O1 - Hosts: 64.86.16.97 google.in O1 - Hosts: 64.86.16.97 google.it O1 - Hosts: 64.86.16.97 google.ki O1 - Hosts: 64.86.16.97 google.la O1 - Hosts: 64.86.16.97 google.li O1 - Hosts: 64.86.16.97 google.lv O1 - Hosts: 64.86.16.97 google.ma O1 - Hosts: 64.86.16.97 google.ms O1 - Hosts: 64.86.16.97 google.mu O1 - Hosts: 64.86.16.97 google.mw O1 - Hosts: 64.86.16.97 google.nl O1 - Hosts: 64.86.16.97 google.no O1 - Hosts: 64.86.16.97 google.nr O1 - Hosts: 64.86.16.97 google.nu O1 - Hosts: 64.86.16.97 google.pl O1 - Hosts: 64.86.16.97 google.pn O1 - Hosts: 64.86.16.97 google.pt O1 - Hosts: 64.86.16.97 google.ro O1 - Hosts: 64.86.16.97 google.ru O1 - Hosts: 64.86.16.97 google.rw O1 - Hosts: 64.86.16.97 google.sc O1 - Hosts: 64.86.16.97 google.se O1 - Hosts: 64.86.16.97 google.sh O1 - Hosts: 64.86.16.97 google.si O1 - Hosts: 64.86.16.97 google.sm O1 - Hosts: 64.86.16.97 google.sn O1 - Hosts: 64.86.16.97 google.st O1 - Hosts: 64.86.16.97 google.tl O1 - Hosts: 64.86.16.97 google.tm O1 - Hosts: 64.86.16.97 google.tt O1 - Hosts: 64.86.16.97 google.us O1 - Hosts: 64.86.16.97 google.vu O1 - Hosts: 64.86.16.97 google.ws O1 - Hosts: 64.86.16.97 google.co.ck O1 - Hosts: 64.86.16.97 google.co.id O1 - Hosts: 64.86.16.97 google.co.il O1 - Hosts: 64.86.16.97 google.co.in O1 - Hosts: 64.86.16.97 google.co.jp O1 - Hosts: 64.86.16.97 google.co.kr O1 - Hosts: 64.86.16.97 google.co.ls O1 - Hosts: 64.86.16.97 google.co.ma O1 - Hosts: 64.86.16.97 google.co.nz O1 - Hosts: 64.86.16.97 google.co.tz O1 - Hosts: 64.86.16.97 google.co.ug O1 - Hosts: 64.86.16.97 google.co.uk O1 - Hosts: 64.86.16.97 google.co.za O1 - Hosts: 64.86.16.97 google.co.zm O1 - Hosts: 64.86.16.97 google.com O1 - Hosts: 64.86.16.97 google.com.af O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\McAfee\VirusScan Enterprise\scriptcl.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ShStatEXE] "C:\Programme\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONE O4 - HKLM\..\Run: [McAfeeUpdaterUI] "C:\Programme\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKey O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [ Malwarebytes Anti-Malware (reboot)] "C:\Programme\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscript O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [ccleaner] "c:\Programme\ccleaner\CCleaner.exe" /AUTO O4 - HKCU\..\Run: [googletalk] "C:\Programme\Google\Google Talk\googletalk.exe" /autostart O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Acrobat Assistant.lnk = C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: EPSON Status Monitor 3 Environment Check.lnk = C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: VPN Client.lnk = ? O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Programme\Yahoo!\Common\yinsthelper.dll O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = ep4.ruhr-uni-bochum.de O17 - HKLM\Software\..\Telephony: DomainName = ep4.ruhr-uni-bochum.de O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = ep4.ruhr-uni-bochum.de O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\sched.exe O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir Desktop\avguard.exe O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programme\Cisco Systems\VPN Client\cvpnd.exe O23 - Service: DameWare NT Utilities 2.6 (DNTUS26) - DameWare Development LLC - C:\WINDOWS\SYSTEM32\DNTUS26.EXE O23 - Service: EpsonBidirectionalService - Unknown owner - C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\eEBSVC.exe O23 - Service: HP Status - Hewlett-Packard Company - C:\WINDOWS\system32\hpb2ksrv.exe O23 - Service: HP Status Print - Hewlett-Packard Company - C:\WINDOWS\system32\hpbhksrv.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\MATLAB6p5\webserver\bin\win32\matlabserver.exe O23 - Service: McAfee Framework Service (McAfeeFramework) - McAfee, Inc. - C:\Programme\McAfee\Common Framework\FrameworkService.exe O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Programme\McAfee\VirusScan Enterprise\Mcshield.exe O23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - C:\Programme\McAfee\VirusScan Enterprise\VsTskMgr.exe O23 - Service: PsExec (PSEXESVC) - Sysinternals - C:\WINDOWS\PSEXESVC.EXE O23 - Service: Trend NT Realtime Service (Tmntsrv) - Unknown owner - C:\Programme\Trend Micro\PC-cillin 2002\Tmntsrv.exe (file missing) -- End of file - 11875 bytes |
16.10.2009, 09:40 | #3 |
| Windows PC Defender und was noch? Hallo,
__________________hat da niemand eine Idee? Ist jetzt alles in Ordnung? beste grüße, psychoaki |
Themen zu Windows PC Defender und was noch? |
adobe, antivir, antivir guard, avgnt, avgnt.exe, avira, bho, defender, desktop, einstellungen, excel, firefox, google, helper, hijack, hijackthis, hkus\s-1-5-18, infizierte, internet, internet explorer, logfile, monitor, mozilla, pc defender, plug-in, software, super, system, viren, windows, windows xp |