![]() |
|
Plagegeister aller Art und deren Bekämpfung: Vermute Virus bzw. Wurm auf SystemWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() Vermute Virus bzw. Wurm auf System Hallo, Ich habe die Vermutung das sich auf meinem Notebook ein Virus bzw. ein Wurm oder ähnliches befinden könnte. Ich habe dazu schon einige Beiträge durchgelesen und auch das HijackThis Programm installiert und ausgeführt. Aber leider kam folgende Meldung bei mir und nicht der Text wie in HijackThis Anleitung beschrieben: "For some reason your system deniede write access to the Hosts file. If an hijacked domains are in this file, HijackThis may NOT be able to fix this. If that happens, you need to edit the file yourself. To do this, click Start, Run and type: notepad C:\Windows\System32\drivers\etc\hosts and press Enter. Find the line(s) HijackThis reports and delete them. Save the file as 'hosts.' (with quotes), and reboot. For Vista: simply, exit HijackThis, right click on the HijackThis icon, choose 'Run as administrator'." Ich wollte das Programm dann als Administrator ausführen, aber immer wenn ich rechtsklick mache (habe Vista) erscheint nichts mit Administrator ausführen. Also habe ich es erstmal seingelassen und habe dann mal den BitDefender QuickScan durchlaufen lassen, der mir folgendes mitgeteilt hat: QuickScan Beta 32-bit v0.9.9.18 ------------------------------- Scan date: Sat Apr 24 05:13:46 2010 Machine ID: 88FA0FDB Found 2 infected files! ----------------------- C:\Users\user\AppData\Local\Temp\Pgj.exe --> Gen:Variant.Renos.6 --> Process Pgj.exe (2368) C:\Users\user\AppData\Local\Temp\Pgk.exe --> Gen:Variant.Renos.6 --> Process Pgk.exe (5168) Processes --------- <unsigned> Pgj.exe 2368 C:\Users\user\AppData\Local\Temp\Pgj.exe <unsigned> Pgk.exe 5168 C:\Users\user\AppData\Local\Temp\Pgk.exe <unsigned> UIExec.exe 524 C:\Program Files\Join Air\UIExec.exe <verified> avast! Antivirus 364 C:\Program Files\Alwil Software\Avast4\ashDisp.exe <verified> Betriebssystem Microsoft® Windows® 1432 C:\Program Files\Windows Media Player\wmpnscfg.exe <verified> Betriebssystem Microsoft® Windows® 796 C:\Program Files\Windows Sidebar\sidebar.exe <verified> Betriebssystem Microsoft® Windows® 1912 C:\Windows\Explorer.EXE <verified> Betriebssystem Microsoft® Windows® 1872 C:\Windows\system32\Dwm.exe <verified> Betriebssystem Microsoft® Windows® 2224 C:\Windows\system32\taskeng.exe <verified> Catalyst Control Centre 1976 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe <verified> Catalyst Control Centre 1028 C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.EXE <verified> Firefox 5908 C:\Program Files\Mozilla Firefox\firefox.exe <verified> HD Audio Control Panel 228 C:\Windows\RtHDVCpl.exe <verified> Java(TM) Platform SE Auto Updater 2 0 544 C:\Program Files\Common Files\Java\Java Update\jusched.exe <verified> Microsoft® Windows® Operating System 2540 C:\Windows\ehome\ehmsas.exe <verified> Microsoft® Windows® Operating System 1812 C:\Windows\ehome\ehtray.exe <verified> RAID Event Monitor 376 C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe <verified> SM56 Helper Win32 Utility 372 C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe <verified> Windows Defender 2044 C:\Program Files\Windows Defender\MSASCui.exe <verified> Windows® Internet Explorer 4020 C:\Program Files\Internet Explorer\iexplore.exe <verified> Windows® Internet Explorer 4908 C:\Program Files\Internet Explorer\iexplore.exe <verified> Windows® Internet Explorer 5304 C:\Program Files\Internet Explorer\iexplore.exe <verified> Windows® Internet Explorer 6140 C:\Program Files\Internet Explorer\iexplore.exe Network activity ---------------- Process Pgk.exe (5168) connected on port 80 (HTTP) --> 88.85.73.162 Process Pgk.exe (5168) connected on port 80 (HTTP) --> 88.85.73.155 Process Pgk.exe (5168) connected on port 80 (HTTP) --> 88.85.73.155 Process Pgk.exe (5168) connected on port 80 (HTTP) --> 88.85.73.162 Process Pgk.exe (5168) connected on port 80 (HTTP) --> 78.108.180.141 Process Pgk.exe (5168) connected on port 80 (HTTP) --> 78.108.180.141 Process Pgk.exe (5168) connected on port 80 (HTTP) --> 88.85.82.19 Process Pgk.exe (5168) connected on port 80 (HTTP) --> 88.85.82.19 Process Pgk.exe (5168) connected on port 80 (HTTP) --> 78.108.180.141 Process Pgk.exe (5168) connected on port 80 (HTTP) --> 78.108.180.141 Process firefox.exe (5908) connected on port 1935 --> ns210038.ovh.net Autoruns and critical files --------------------------- <unsigned> Orb C:\Program Files\Winamp Remote\bin\OrbTray.exe <unsigned> Pgj.exe C:\Users\user\AppData\Local\Temp\Pgj.exe <unsigned> Pgk.exe C:\Users\user\AppData\Local\Temp\Pgk.exe <unsigned> UIExec.exe C:\Program Files\Join Air\UIExec.exe <verified> ManyCam Application C:\Program Files\ManyCam 2.4\ManyCam.exe <verified> Adobe Acrobat C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe <verified> Adobe Reader and Acrobat Manager C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe <verified> avast! Antivirus C:\Program Files\Alwil Software\Avast4\ashDisp.exe <verified> Betriebssystem Microsoft® Windows® C:\Program Files\Windows Media Player\wmpnscfg.exe <verified> Betriebssystem Microsoft® Windows® C:\Program Files\Windows Sidebar\sidebar.exe <verified> Betriebssystem Microsoft® Windows® C:\Windows\System32\browseui.dll <verified> Betriebssystem Microsoft® Windows® c:\windows\system32\userinit.exe <verified> CLIStart.exe C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe <verified> Google Update C:\Users\user\AppData\Local\Google\Update\GoogleUpdate.exe <verified> HD Audio Control Panel C:\Windows\RtHDVCpl.exe <verified> Java(TM) Platform SE Auto Updater 2 0 C:\Program Files\Common Files\Java\Java Update\jusched.exe <verified> Microsoft® Windows® Operating System C:\Windows\ehome\ehtray.exe <verified> RAID Event Monitor C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe <verified> Realtek Voice Manager C:\Windows\Skytel.exe <verified> SM56 Helper Win32 Utility C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe <verified> Windows Defender C:\Program Files\Windows Defender\MSASCui.exe <verified> Windows® Internet Explorer C:\Windows\System32\webcheck.dll Browser plugins --------------- <unsigned> Winamp Application Detector C:\Program Files\Mozilla Firefox\plugins\npwachk.dll <verified> AcroIEHelperShim Library C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll <verified> Adobe Acrobat C:\Program Files\Mozilla Firefox\plugins\nppdf32.dll <verified> Adobe® Flash® Player ActiveX C:\Windows\Downloaded Program Files\CONFLICT.1\FP_AX_CAB_INSTALLER.exe <verified> Adobe® Flash® Player ActiveX C:\Windows\Downloaded Program Files\FP_AX_CAB_INSTALLER.exe <verified> Betriebssystem Microsoft® Windows® C:\Windows\System32\mswsock.dll <verified> Betriebssystem Microsoft® Windows® C:\Windows\System32\NapiNSP.dll <verified> Betriebssystem Microsoft® Windows® C:\Windows\System32\pnrpnsp.dll <verified> BitDefender QuickScan C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\79jwbfte.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\components\qscanff.dll <verified> BitDefender QuickScan C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\79jwbfte.default\extensions\{e001c731-5e37-4538-a5cb-8168736a2360}\plugins\npqscan.dll <verified> Java Deployment Toolkit 6.0.190.4 C:\Program Files\Mozilla Firefox\plugins\npdeploytk.dll <verified> Java(TM) Platform SE 6 U19 C:\Program Files\Java\jre6\bin\jp2ssv.dll <verified> libcurl.dll C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\79jwbfte.default\extensions\firefox@tvunetworks.com\plugins\libcurl.dll <verified> libexpatw.dll C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\79jwbfte.default\extensions\firefox@tvunetworks.com\plugins\libexpatw.dll <verified> Microsoft® Visual Studio .NET C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\79jwbfte.default\extensions\firefox@tvunetworks.com\plugins\msvcp71.dll <verified> Microsoft® Visual Studio .NET C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\79jwbfte.default\extensions\firefox@tvunetworks.com\plugins\msvcr71.dll <verified> Microsoft® Windows Media Player Firefox C:\Program Files\Mozilla Firefox\plugins\np-mswmp.dll <verified> Microsoft® Windows® Operating System C:\Windows\System32\nlaapi.dll <verified> Microsoft® Windows® Operating System C:\Windows\System32\winrnr.dll <verified> Mozilla Default Plug-in C:\Program Files\Mozilla Firefox\plugins\npnul32.dll <verified> nppdf32.DEU C:\Program Files\Mozilla Firefox\plugins\nppdf32.DEU <verified> NPSWF32.dll C:\Windows\System32\Macromed\Flash\NPSWF32.dll <verified> The OpenSSL Toolkit C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\79jwbfte.default\extensions\firefox@tvunetworks.com\plugins\libeay32.dll <verified> The OpenSSL Toolkit C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\79jwbfte.default\extensions\firefox@tvunetworks.com\plugins\ssleay32.dll <verified> TVU Web Player for FireFox C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\79jwbfte.default\extensions\firefox@tvunetworks.com\plugins\npTVUAx.dll <verified> Windows Presentation Foundation c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll <verified> Windows® Internet Explorer C:\Windows\System32\ieframe.dll <verified> zlib C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\79jwbfte.default\extensions\firefox@tvunetworks.com\plugins\zlib1.dll Missing files ------------- File not found: C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll referenced in: HLKM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0\"Path" File not found: C:\Windows\system32\drivers\blbdrive.sys referenced in: HKLM\System\ControlSet001\services\blbdrive\"ImagePath" File not found: system32\DRIVERS\ipinip.sys referenced in: HKLM\System\ControlSet001\services\IpInIp\"ImagePath" File not found: system32\DRIVERS\nwlnkflt.sys referenced in: HKLM\System\ControlSet001\services\NwlnkFlt\"ImagePath" File not found: system32\DRIVERS\nwlnkfwd.sys referenced in: HKLM\System\ControlSet001\services\NwlnkFwd\"ImagePath" Scan ---- <unsigned> MD5: 6ca1292225b47a5421e941b3cfef48af C:\Program Files\Alwil Software\Avast4\Aavm4h.dll <unsigned> MD5: f3eac60879ae425d81dba70c3da76d13 C:\Program Files\Alwil Software\Avast4\AavmRpch.dll <unsigned> MD5: 02bd0feacaa1a65f77806a3c3debd046 C:\Program Files\Alwil Software\Avast4\AhRuiMai.dll <unsigned> MD5: 27bb54223d4aaebbeb0e65df776cf6c2 C:\Program Files\Alwil Software\Avast4\ahRuiMes.dll <unsigned> MD5: 99c120153031fbd057d4fa0499fff755 C:\Program Files\Alwil Software\Avast4\AhRuiNS.dll <unsigned> MD5: 9625471205dfc433fb73e231fc9cbb01 C:\Program Files\Alwil Software\Avast4\AhRuiOut.dll <unsigned> MD5: e5c7e4c34e43bfd68de1cf2034fe9af8 C:\Program Files\Alwil Software\Avast4\ahRuiP2P.dll <unsigned> MD5: cb39a7024be54e75e3b696272fdc0987 C:\Program Files\Alwil Software\Avast4\AhRuiStd.dll <unsigned> MD5: 8f933065a585eafd798dd5e49598cdcb C:\Program Files\Alwil Software\Avast4\AhRuiWS.dll <unsigned> MD5: e8b0edd5c8518d9a1f73ac0c54a94d7c C:\Program Files\Alwil Software\Avast4\ashBase.dll <unsigned> MD5: 0b9dbfe71f4eb4355985ee60e6a1dc3f C:\Program Files\Alwil Software\Avast4\ashTask.dll <unsigned> MD5: fce48f51523e38c5e74969766b353d73 C:\Program Files\Alwil Software\Avast4\ashUInt.dll <unsigned> MD5: 8ea778943b7e155991ae9e3c818269ab C:\Program Files\Alwil Software\Avast4\aswAux.dll <unsigned> MD5: f8df17a0090f29ee330b34145152f38a C:\Program Files\Alwil Software\Avast4\aswCmnB.dll <unsigned> MD5: 6d6416fa182fa865d265dffa5a03c3c2 C:\Program Files\Alwil Software\Avast4\aswCmnOS.dll <unsigned> MD5: 7d79cd441ed208d062b326145c7b3aed C:\Program Files\Alwil Software\Avast4\aswCmnS.dll <unsigned> MD5: 68cf2e89bfb303567e78f9ac3482e5e9 C:\Program Files\Alwil Software\Avast4\GERMAN\Base.dll <unsigned> MD5: c37a82cab55ca0cc1df3079ebdfbaff3 C:\Program Files\Alwil Software\Avast4\GERMAN\Lang.dll <unsigned> MD5: 6c08604b5465de19eaac58c6a537d0bf C:\Program Files\Alwil Software\Avast4\XT1922.dll <unsigned> MD5: 3a9f70479a886dcc8e5151326156472d C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll <unsigned> MD5: caa2d58bfc41233a082c8b19d67b458d C:\Program Files\Java\jre6\bin\awt.dll <unsigned> MD5: f2ddab039241c453a7fb9e1d039b154d C:\Program Files\Java\jre6\bin\client\jvm.dll <unsigned> MD5: 5ac803360c5cb072fd089de1ce165386 C:\Program Files\Java\jre6\bin\deploy.dll <unsigned> MD5: b99688c2024fb0813b26beeaaf87615d C:\Program Files\Java\jre6\bin\hpi.dll <unsigned> MD5: 87739b517d98ade82df0e14edcda179e C:\Program Files\Java\jre6\bin\java.dll <unsigned> MD5: 2c6c7ad0e07da4d1f38dab01d1b0fd95 C:\Program Files\Java\jre6\bin\jp2native.dll <unsigned> MD5: 6655a2ecc5e0e99ac20987e668ee3857 C:\Program Files\Java\jre6\bin\net.dll <unsigned> MD5: d34e74f7a9cff2fa42e040312d559a5a C:\Program Files\Java\jre6\bin\nio.dll <unsigned> MD5: 03150330eac52a3a15f006be1ee01d36 C:\Program Files\Java\jre6\bin\regutils.dll <unsigned> MD5: 7605ce091c0b2a32e8bdbd630502fa38 C:\Program Files\Java\jre6\bin\verify.dll <unsigned> MD5: b7863bd54427e4ff1212503a4f270d05 C:\Program Files\Java\jre6\bin\zip.dll <unsigned> MD5: a447361e6156afef47a42ae9e89b2bb3 C:\Program Files\Join Air\AssistantServices.exe <unsigned> MD5: 4ef08a95991555dd2981c09367cca6c8 C:\Program Files\Join Air\UIExec.exe <unsigned> MD5: 26b018758226a5dc06de45496c394d40 C:\Program Files\Mozilla Firefox\freebl3.dll <unsigned> MD5: 9dfb30f203999a3ae0f258a33fa598f9 C:\Program Files\Mozilla Firefox\nssdbm3.dll <unsigned> MD5: 3d50c41f6ac9f395bc77477f14b07194 C:\Program Files\Mozilla Firefox\plugins\npwachk.dll <unsigned> MD5: 1fd6c03c0001a5e1eaf61596c2502f0c C:\Program Files\Mozilla Firefox\softokn3.dll <unsigned> MD5: 5a4cd8c1747b0c5e66f1a7b6a93453eb C:\Program Files\Winamp Remote\bin\OrbTray.exe <unsigned> MD5: e0a7d542b66725fe81eb9f5aeb9b1e82 C:\Program Files\WinRAR\RarExt.dll <unsigned> MD5: 421a25d626e5c2da375e357b1a9f0d80 C:\PROGRA~1\7-PDF\7-PDFM~1\7p.dll <unsigned> MD5: 63d660fe32a72da91af4ce02c1268f7a C:\Users\user\AppData\Local\Temp\Pgj.exe <unsigned> MD5: d18e59c18cffe15bcd76994141c8535a C:\Users\user\AppData\Local\Temp\Pgk.exe <unsigned> MD5: ffb6f6d5dab74e61b47c91245eed5090 C:\Windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.2791.32001__90ba9c70f846762e\CLI.Component.Runtime.Shared.DLL <unsigned> MD5: 3c97e7131026a968c69892a3002f4003 C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\894183c0c47bd4772fbfad4c1a7e3b71\mscorlib.ni.dll <unsigned> MD5: 31d759eb90cccadc5641b6461c8ae180 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\57e722244d3b48cb92b340bc92d7a191\System.Drawing.ni.dll <unsigned> MD5: 4005c194272628cd1362a7ac88b50718 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\425e95df110b77abad261a46fca54e99\System.Windows.Forms.ni.dll <unsigned> MD5: 5ed7722d11473666528dadc758e4edf1 C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\99e7927ccb9099e607035349814d4cf6\System.Xml.ni.dll <unsigned> MD5: 96d9ccdfcbdab436bf49ad0ed15c18e3 C:\Windows\assembly\NativeImages_v2.0.50727_32\System\13cce38e8de5fd54853390e4e98abd0e\System.ni.dll <unsigned> MD5: ecc76d49e38c7a1847a97aaf77d6e33e C:\Windows\System32\dossec.dll <unsigned> MD5: eb638a6775788b474fbf88e8ff3b2cab C:\Windows\System32\Interop.SHDocVw.dll No file uploaded. Scan finished - communication took 1 sec Total traffic - 0.02 MB sent, 0.31 KB recvd Scanned 926 files and modules - 22 seconds Ich hoffe das kann euch schonmal weiterhelfen. Mir sagt es auf jeden Fall das ich 2 Verseuchte Dateien auf meinem Rechner habe, aber kann ich ihn jetzt noch retten !? Mit freundlichen Grüßen Petra |
Themen zu Vermute Virus bzw. Wurm auf System |
32-bit, administrator, adobe, antivirus, assembly, avast, avast!, components, defender, firefox, google, helper, hijack, hijackthis, internet, internet explorer, local\temp, monitor, mozilla, notebook, opera, plug-in, port 80, programm, realtek, software, studio, system, temp, uiexec.exe, virus, vista, visual studio, windows, write, wurm |