Guten Abend,
Ich melde mich, weil ein Freund von mir (eher unerfahrener PC User) dummerweise einen link, den er über den instant messenger ICQ von jemanden aus seiner Kontaktliste erhalten hat, geöffnet hat, und die angebliche Bilddatei (in Wirklichkeit wars eine .scr)
Ich selbst habe auch den link erhalten, bin allerdings bei der dateiendung misstrauisch geworden und hab erst mal unseren Freund google gefragt.
Ich denke, dass es sich dabei um einen Trojaner handelt, da das nette Kerlchen automatisch den Link an Leute aus der Kontaktliste des Betroffenen weiterschickt.
Leider gibt es genügend Leute die solchen links dann auch folgen

der link war übrigens folgender:
*** MALWARE-LINK ENTFERNT ****
ich hab ihm mal geraten ein HJT log zu machen.
das hab ich hier:
Zitat:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21:38:56, on 15.04.2010
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.18904)
Boot mode: Normal
Running processes:
C:..Program Files..McAfee..Managed VirusScan..Agent..myAgtTry.exe
C:..windows..system32..taskeng.exe
C:..windows..system32..Dwm.exe
C:..windows..Explorer.EXE
c:..Program Files..Hewlett-Packard..IAM..Bin..AsGHost.exe
C:..Program Files..Intel..Intel Matrix Storage Manager..IAAnotif.exe
C:..Program Files..ActivIdentity..ActivClient..accrdsub.exe
C:..Program Files..Hewlett-Packard..HP ProtectTools Security Manager..pthosttr.exe
C:..Program Files..Synaptics..SynTP..SynTPEnh.exe
C:..Program Files..Hewlett-Packard..HP Wireless Assistant..HPWAMain.exe
C:..Program Files..SiteAdvisor..6173..SiteAdv.exe
C:..Program Files..Hewlett-Packard..File Sanitizer..CoreShredder.exe
C:..Program Files..Hewlett-Packard..HP Quick Launch Buttons..QLBCTRL.exe
C:..Program Files..HP..HP Software Update..hpwuSchd2.exe
C:..Program Files..Analog Devices..Core..smax4pnp.exe
C:..Program Files..SweetIM..Messenger..SweetIM.exe
C:..Program Files..Java..jre6..bin..jusched.exe
C:..Program Files..iTunes..iTunesHelper.exe
C:..Program Files..Windows Sidebar..sidebar.exe
C:..Program Files..Common Files..LightScribe..LightScribeControlPanel.exe
C:..Program Files..WIDCOMM..Bluetooth Software..BTTray.exe
C:..Program Files..Hewlett-Packard..HP wireless Assistant..WiFiMsg.EXE
C:..Program Files..OpenOffice.org 2.3..program..soffice.exe
C:..Program Files..Hewlett-Packard..Shared..HpqToaster.exe
C:..Program Files..ATI Technologies..ATI.ACE..Core-Static..MOM.exe
C:..Program Files..OpenOffice.org 2.3..program..soffice.BIN
C:..Program Files..Hewlett-Packard..HP Quick Launch Buttons..VolCtrl.exe
c:..Program Files..ActivIdentity..ActivClient..acevents.exe
C:..Program Files..MSN Messenger..msnmsgr.exe
C:..Program Files..WIDCOMM..Bluetooth Software..BtStackServer.exe
C:..Program Files..ICQ7.0..ICQ.exe
C:..Program Files..ATI Technologies..ATI.ACE..Core-Static..CCC.exe
C:..Program Files..Synaptics..SynTP..SynTPHelper.exe
C:..Program Files..Mozilla Firefox..firefox.exe
C:..Users..Public..dlll.exe
C:..windows..system32..SearchFilterHost.exe
C:..Program Files..Trend Micro..HijackThis..HijackThis.exe
R1 - HKCU..Software..Microsoft..Internet Explorer..Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome
&locale=de_de&c=83&bd=all&pf=cmnb
R1 - HKCU..Software..Microsoft..Internet Explorer..Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU..Software..Microsoft..Internet Explorer..Main,Start Page = hxxp://start.icq.com/
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Page_URL = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome
&locale=de_de&c=83&bd=all&pf=cmnb
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Default_Search_URL = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM..Software..Microsoft..Internet Explorer..Main,Search Page = hxxp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM..Software..Microsoft..Internet Explorer..Main,Start Page = hxxp://home.sweetim.com
R0 - HKLM..Software..Microsoft..Internet Explorer..Search,SearchAssistant =
R0 - HKLM..Software..Microsoft..Internet Explorer..Search,CustomizeSearch =
R1 - HKCU..Software..Microsoft..Windows..CurrentVersion
..Internet Settings,ProxyOverride = *.local
R0 - HKCU..Software..Microsoft..Internet Explorer..Toolbar,LinksFolderName =
R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:..Program Files..ICQ6Toolbar..ICQToolBar.dll
R3 - URLSearchHook: (no name) - - (no file)
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:..Program Files..SweetIM..Toolbars..Internet Explorer..mgHelper.dll
R3 - URLSearchHook: DVDVideoSoft Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:..Program Files..DVDVideoSoft..tbDVDV.dll
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:..Program Files..Adobe..Acrobat 7.0..ActiveX..AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:..Program Files..SiteAdvisor..6173..SiteAdv.dll
O2 - BHO: AskBar BHO - {201f27d4-3704-41d6-89c1-aa35e39143ed} - C:..Program Files..AskBarDis..bar..bin..askBar.dll
O2 - BHO: BHO_Startup - {3134413B-49B4-425C-98A5-893C1F195601} - C:..Program Files..Hewlett-Packard..File Sanitizer..IEBHO.dll
O2 - BHO: AOL Toolbar BHO - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:..Program Files..AOL..AOL Toolbar 5.0..aoltb.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:..Program Files..Google..GoogleToolbarNotifier..5.1.1309.357
2..swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:..Program Files..Java..jre6..bin..jp2ssv.dll
O2 - BHO: Credential Manager for HP ProtectTools - {DF21F1DB-80C6-11D3-9483-B03D0EC10000} - c:..Program Files..Hewlett-Packard..IAM..Bin..ItIEAddIn.dll
O2 - BHO: DVDVideoSoft Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:..Program Files..DVDVideoSoft..tbDVDV.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:..Program Files..SweetIM..Toolbars..Internet Explorer..mgToolbarIE.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:..Program Files..SiteAdvisor..6173..SiteAdv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:..Program Files..AOL..AOL Toolbar 5.0..aoltb.dll
O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:..Program Files..ICQ6Toolbar..ICQToolBar.dll
O3 - Toolbar: Ask Toolbar - {3041d03e-fd4b-44e0-b742-2d9b88305f98} - C:..Program Files..AskBarDis..bar..bin..askBar.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:..Program Files..SweetIM..Toolbars..Internet Explorer..mgToolbarIE.dll
O3 - Toolbar: DVDVideoSoft Toolbar - {e9911ec6-1bcc-40b0-9993-e0eea7f6953f} - C:..Program Files..DVDVideoSoft..tbDVDV.dll
O4 - HKLM......Run: [Windows Defender] %ProgramFiles%..Windows Defender..MSASCui.exe -hide
O4 - HKLM......Run: [IAAnotif] C:..Program Files..Intel..Intel Matrix Storage Manager..iaanotif.exe
O4 - HKLM......Run: [accrdsub] "c:..Program Files..ActivIdentity..ActivClient..accrdsub.exe"
O4 - HKLM......Run: [PTHOSTTR] c:..Program Files..Hewlett-Packard..HP ProtectTools Security Manager..PTHOSTTR.EXE /Start
O4 - HKLM......Run: [CognizanceTS] rundll32.exe c:..PROGRA~1..HEWLET~1..IAM..Bin..ASTSVCC.dll,Regi
sterModule
O4 - HKLM......Run: [PDF Complete] C:..Program Files..PDF Complete..pdfsty.exe
O4 - HKLM......Run: [SynTPEnh] C:..Program Files..Synaptics..SynTP..SynTPEnh.exe
O4 - HKLM......Run: [hpWirelessAssistant] C:..Program Files..Hewlett-Packard..HP Wireless Assistant..HPWAMain.exe
O4 - HKLM......Run: [HP Health Check Scheduler] c:..Program Files..Hewlett-Packard..HP Health Check..HPHC_Scheduler.exe
O4 - HKLM......Run: [MVS Splash] C:..Program Files..McAfee..Managed VirusScan..Agent..Splash.exe
O4 - HKLM......Run: [McAfee Managed Services Tray] C:..Program Files..McAfee..Managed VirusScan..Agent..StartMyAgtTry.Exe
O4 - HKLM......Run: [SiteAdvisor] C:..Program Files..SiteAdvisor..6173..SiteAdv.exe
O4 - HKLM......Run: [File Sanitizer] C:..Program Files..Hewlett-Packard..File Sanitizer..CoreShredder.exe
O4 - HKLM......Run: [QlbCtrl.exe] C:..Program Files..Hewlett-Packard..HP Quick Launch Buttons..QlbCtrl.exe /Start
O4 - HKLM......Run: [WatchDog] C:..Program Files..InterVideo..DVD Check..DVDCheck.exe
O4 - HKLM......Run: [HP Software Update] c:..Program Files..Hp..HP Software Update..HPWuSchd2.exe
O4 - HKLM......Run: [SoundMAX] C:..Program Files..Analog Devices..SoundMAX..soundmax.exe /tray
O4 - HKLM......Run: [StartCCC] "C:..Program Files..ATI Technologies..ATI.ACE..Core-Static..CLIStart.exe"
O4 - HKLM......Run: [SoundMAXPnP] C:..Program Files..Analog Devices..Core..smax4pnp.exe
O4 - HKLM......Run: [SweetIM] C:..Program Files..SweetIM..Messenger..SweetIM.exe
O4 - HKLM......Run: [AppleSyncNotifier] C:..Program Files..Common Files..Apple..Mobile Device Support..AppleSyncNotifier.exe
O4 - HKLM......Run: [NeroCheck] C:..windows..system32..NeroCheck.exe
O4 - HKLM......Run: [SunJavaUpdateSched] "C:..Program Files..Java..jre6..bin..jusched.exe"
O4 - HKLM......Run: [QuickTime Task] "C:..Program Files..QuickTime..QTTask.exe" -atboottime
O4 - HKLM......Run: [iTunesHelper] "C:..Program Files..iTunes..iTunesHelper.exe"
O4 - HKCU......Run: [Sidebar] C:..Program Files..Windows Sidebar..sidebar.exe /autoRun
O4 - HKCU......Run: [LightScribe Control Panel] C:..Program Files..Common Files..LightScribe..LightScribeControlPanel.exe -hidden
O4 - HKCU......Run: [msnmsgr] ~"C:..Program Files..MSN Messenger..msnmsgr.exe" /background
O4 - HKCU......Run: [EA Core] "C:..Program Files..Electronic Arts..EADM..Core.exe" -silent
O4 - HKCU......Run: [Windows System Guard] C:..Users..Public..dlll.exe
O4 - HKUS..S-1-5-19......Run: [Sidebar] %ProgramFiles%..Windows Sidebar..Sidebar.exe /detectMem (User 'LOKALER DIENST')
O4 - HKUS..S-1-5-19......Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
O4 - HKUS..S-1-5-20......Run: [Sidebar] %ProgramFiles%..Windows Sidebar..Sidebar.exe /detectMem (User 'NETZWERKDIENST')
O4 - Startup: OpenOffice.org 2.3.lnk = C:..Program Files..OpenOffice.org 2.3..program..quickstart.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:..Program Files..Adobe..Acrobat 7.0..Reader..reader_sl.exe
O4 - Global Startup: BTTray.lnk = ?
O4 - Global Startup: DVD Check.lnk = C:..Program Files..InterVideo..DVD Check..DVDCheck.exe
O8 - Extra context menu item: &AOL Toolbar-Suche - C:..ProgramData..AOL..ieToolbar..resources..de-DE.
.local..search.html
O8 - Extra context menu item: Bild an &Bluetooth-Gerät senden... - C:..Program Files..WIDCOMM..Bluetooth Software..btsendto_ie_ctx.htm
O8 - Extra context menu item: Seite an &Bluetooth-Gerät senden... - C:..Program Files..WIDCOMM..Bluetooth Software..btsendto_ie.htm
O9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:..Program Files..ICQ7.0..ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:..Program Files..ICQ7.0..ICQ.exe
O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:..Program Files..WIDCOMM..Bluetooth Software..btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:..Program Files..WIDCOMM..Bluetooth Software..btsendto_ie.htm
O13 - Gopher Prefix:
O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - hxxp://icq.oberon-media.com/Gameshell/GameHost/1.0
/OberonGameHost.cab
O20 - AppInit_DLLs: APSHook.dll
O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - c:..Program Files..ActivIdentity..ActivClient..accoca.exe
O23 - Service: Andrea ADI Filters Service (AEADIFilters) - Andrea Electronics Corporation - C:..windows..system32..AEADISRV.EXE
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:..Windows..system32..agrsmsvc.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:..Program Files..Common Files..Apple..Mobile Device Support..AppleMobileDeviceService.exe
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:..windows..system32..Ati2evxx.exe
O23 - Service: Dienst "Bonjour" (Bonjour Service) - Apple Inc. - C:..Program Files..Bonjour..mDNSResponder.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, L.P. - C:..Program Files..Hewlett-Packard..HP Quick Launch Buttons..Com4QLBEx.exe
O23 - Service: EngineServer - McAfee, Inc. - C:..PROGRA~1..McAfee..MANAGE~1..VScan..ENGINE~1.EX
E
O23 - Service: Google Update Service (gupdate1c998dca84d0a10) (gupdate1c998dca84d0a10) - Google Inc. - C:..Program Files..Google..Update..GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:..Program Files..Google..Common..Google Updater..GoogleUpdaterService.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:..Program Files..Hewlett-Packard..HP Health Check..hphc_service.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, L.P - c:..Program Files..Hewlett-Packard..HP ProtectTools Security Manager..PTChangeFilterService.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - SafeBoot International - c:..Program Files..Hewlett-Packard..Drive Encryption..HpFkCrypt.exe
O23 - Service: File Sanitizer for HP ProtectTools (HPFSService) - Hewlett-Packard - C:..Program Files..Hewlett-Packard..File Sanitizer..HPFSService.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:..Program Files..Hewlett-Packard..Shared..hpqwmiex.exe
O23 - Service: HP Service (hpsrv) - Hewlett-Packard Corporation - C:..windows..system32..Hpservice.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:..Program Files..Intel..Intel Matrix Storage Manager..IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:..Program Files..Common Files..InstallShield..Driver..1050..Intel 32..IDriverT.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:..Program Files..iPod..bin..iPodService.exe
O23 - Service: IviRegMgr - InterVideo - C:..Program Files..Common Files..InterVideo..RegMgr..iviRegMgr.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:..Program Files..Common Files..LightScribe..LSSrvc.exe
O23 - Service: McAfee HackerWatch Service - McAfee, Inc. - C:..Program Files..Common Files..McAfee..HackerWatch..HWAPI.exe
O23 - Service: McShield - McAfee, Inc. - C:..PROGRA~1..McAfee..MANAGE~1..VScan..McShield.ex
e
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:..Program Files..McAfee..MPF..MPFSrv.exe
O23 - Service: McAfee Virus and Spyware Protection Service (myAgtSvc) - McAfee, Inc. - C:..Program Files..McAfee..Managed VirusScan..Agent..myAgtSvc.Exe
O23 - Service: PDF Document Manager (pdfcDispatcher) - PDF Complete Inc - C:..Program Files..PDF Complete..pdfsvc.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:..Program Files..Common Files..Roxio Shared..10.0..SharedCOM..RoxMediaDB10.exe
O23 - Service: rpcnetp - Unknown owner - C:..windows..System32..rpcnetp.exe (file missing)
O23 - Service: SiteAdvisor Service - Unknown owner - C:..Program Files..SiteAdvisor..6173..SAService.exe
O23 - Service: stllssvr - MicroVision Development, Inc. - c:..Program Files..Common Files..SureThing Shared..stllssvr.exe
--
End of file - 14259 bytes
|
ich würde mich freuen, wenn mir jemand dabei weiterhelfen könnte.
Danke im vorraus
Knerdi