![]() |
WIN32.Mazocker.A in C\windows\system32\helpefan.dll Hilfe ! bekomme im 15 sek. Takt diese Meldung auf den Schirm: "WIN32.Mazocker.A' in C\windows\system32\helpefan.dll" Weder Ad Aware no Spybot konnten irgendetwas finden, auch Trojan Hunter etc. finden nichts. Wer weiss wie ich diesen Plagegeist erledige? Hier die Details: Logfile of HijackThis v1.99.0 Scan saved at 19:48:01, on 20.12.2004 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINDOWS\System32\RunDll32.exe C:\PROGRA~1\CA\ETRUST~1\realmon.exe C:\Programme\Medion Home Cinema XL II\PowerCinema\PCMService.exe C:\WINDOWS\System32\PRISMSTA.EXE C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe C:\Programme\Java\j2re1.4.2_03\bin\jusched.exe C:\Programme\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe C:\WINDOWS\System32\helpefa\sychost.exe C:\PROGRA~1\HEWLET~1\HPSHAR~1\hpgs2wnf.exe C:\PROGRA~1\GMX\GMXSMS~1\SMSMngr.exe C:\Programme\Microsoft ActiveSync\WCESCOMM.EXE C:\Programme\BySoft FreeRAM\FreeRAM.exe C:\Programme\Hewlett-Packard\AiO\hp officejet 5100 series\Bin\hpocyp07.exe C:\WINDOWS\CNYHKey.exe C:\Programme\USB Sharing\usbshare.exe C:\PROGRA~1\HEWLET~1\AiO\Shared\Bin\hpoevm07.exe C:\Programme\Mozilla Firefox\firefox.exe C:\WINDOWS\System32\alg.exe C:\Programme\CA\eTrust Antivirus\InoRpc.exe C:\Programme\CA\eTrust Antivirus\InoRT.exe C:\Programme\CA\eTrust Antivirus\InoTask.exe C:\Programme\CA\SharedComponents\CA_LIC\LogWatNT.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\svchost.exe C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe C:\WINDOWS\System32\wuauclt.exe C:\Programme\Medion Home Cinema XL II\PowerCinema\PCM2.exe C:\Dokumente und Einstellungen\Heiko\Lokale Einstellungen\Temp\Temporäres Verzeichnis 1 für hijackthis199.zip\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://fastsearchweb.com/srh.php?q=%s R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.aldi.com R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: FreshBar - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - C:\WINDOWS\System32\iecust.dll O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s O4 - HKLM\..\Run: [PCMService] "C:\Programme\Medion Home Cinema XL II\PowerCinema\PCMService.exe" O4 - HKLM\..\Run: [PRISMSTA.EXE] PRISMSTA.EXE START O4 - HKLM\..\Run: [Gnetmous] C:\Programme\KYE\Wireless WebScroll+ NB Eye Mouse\gnetmous.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programme\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [helpefa] C:\WINDOWS\System32\helpefa\sychost.exe O4 - HKCU\..\Run: [SMS-Manager] C:\PROGRA~1\GMX\GMXSMS~1\SMSMngr.exe O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programme\Microsoft ActiveSync\WCESCOMM.EXE" O4 - HKCU\..\Run: [BySoft FreeRAM] C:\Programme\BySoft FreeRAM\FreeRAM.exe O4 - Startup: PowerReg Scheduler.exe O4 - Startup: Registration-InstantCopy.lnk = C:\Programme\Pinnacle\Shared Files\InstantCDDVD\Pixie\RegTool.exe O4 - Global Startup: HPAiODevice(hp officejet 5100 series) - 1.lnk = C:\Programme\Hewlett-Packard\AiO\hp officejet 5100 series\Bin\hpocyp07.exe O4 - Global Startup: Kontrollfeld für die kabellose Tastatur.lnk = C:\WINDOWS\CNYHKey.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: USB Sharing.lnk = ? O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: Mobilen Favoriten erstellen - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INETREPL.DLL O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INETREPL.DLL O9 - Extra 'Tools' menuitem: Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INETREPL.DLL O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll O9 - Extra button: Preispiraten 2.02 - {86DE8B3B-1EB7-4386-84BD-EBE94348A913} - C:\Programme\Preispiraten 2.0b\preispiraten2.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\System32\Shdocvw.dll O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Programme\IrfanView\Ebay\Ebay.htm O9 - Extra button: MedionShop - {84FAA847-1400-4400-BC93-D338EF03127B} - http://www.medionshop.de/ (file missing) (HKCU) O12 - Plugin for .mid: C:\Programme\Internet Explorer\PLUGINS\npqtplugin2.dll O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com O15 - Trusted Zone: http://*.search-soft.net O16 - DPF: {26CBF141-7D0F-46E1-AA06-718958B6E4D2} - http://download.ebay.com/turbo_lister/DE/install.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{6E389B76-1702-43B0-8FFF-07046F351EFA}: NameServer = 217.237.151.33 217.237.149.225 O23 - Service: CA-Lizenz-Client - Computer Associates - C:\Programme\CA\SharedComponents\CA_LIC\lic98rmt.exe O23 - Service: CA-Lizenzserver - Computer Associates - C:\Programme\CA\SharedComponents\CA_LIC\lic98rmtd.exe O23 - Service: eTrust Antivirus RPC Server - Computer Associates International, Inc. - C:\Programme\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server - Computer Associates International, Inc. - C:\Programme\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server - Computer Associates International, Inc. - C:\Programme\CA\eTrust Antivirus\InoTask.exe O23 - Service: Ereignisprotokoll-Überwachung - Computer Associates - C:\Programme\CA\SharedComponents\CA_LIC\LogWatNT.exe O23 - Service: Macromedia Licensing Service - Unknown - C:\Programme\Gemeinsame Dateien\Macromedia Shared\Service\Macromedia Licensing.exe O23 - Service: Ulead Burning Helper - Ulead Systems, Inc. - C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe O23 - Service: X10 Device Network Service - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe :headbang: :headbang: :headbang: :headbang: |
@familyforum der hier ist im system http://securityresponse.symantec.com...lw.leox.b.html lade dir escan download anleitung mache es genauso wie beschrieben EscanErgebnis Teile uns das Ergebnis des eScan mit: "öffne die mwav.log -> Bearbeiten -> Suchen -> infected eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen." chaosman |
Mon Dec 20 21:29:26 2004 => File C:\WINDOWS\System32\helpefa\sychost.exe infected by "TrojanProxy.Win32.Agent.ag" Virus. Action Taken: No Action Taken. Mon Dec 20 21:29:26 2004 => File C:\WINDOWS\System32\helpefav.dll infected by "TrojanSpy.Win32.Small.bf" Virus. Action Taken: No Action Taken. Mon Dec 20 21:29:36 2004 => File C:\WINDOWS\System32\helpefa\sychost.exe infected by "TrojanProxy.Win32.Agent.ag" Virus. Action Taken: No Action Taken. Mon Dec 20 21:29:46 2004 => File C:\WINDOWS\telnet.exe infected by "Trojan-Downloader.Win32.Agent.fw" Virus. Action Taken: No Action Taken. Mon Dec 20 21:30:03 2004 => File C:\WINDOWS\System32\hdih.dll infected by "HackTool.Win32.Hidd.c" Virus. Action Taken: No Action Taken. Mon Dec 20 21:30:03 2004 => Scanning File C:\WINDOWS\System32\hdqp.dll Mon Dec 20 21:30:03 2004 => File C:\WINDOWS\System32\hdqp.dll infected by "HackTool.Win32.Hidd.c" Virus. Action Taken: No Action Taken. Mon Dec 20 21:30:03 2004 => Scanning File C:\WINDOWS\System32\hdut.dll Mon Dec 20 21:30:03 2004 => File C:\WINDOWS\System32\hdut.dll infected by "HackTool.Win32.Hidd.c" Virus. Action Taken: No Action Taken. Mon Dec 20 21:30:03 2004 => Scanning File C:\WINDOWS\System32\hdwwiz.cpl Mon Dec 20 21:30:03 2004 => Scanning File C:\WINDOWS\System32\hdxw.dll Mon Dec 20 21:30:03 2004 => File C:\WINDOWS\System32\hdxw.dll infected by "HackTool.Win32.Hidd.c" Virus. Action Taken: No Action Taken. Mon Dec 20 21:30:03 2004 => File C:\WINDOWS\System32\helpefas.dll infected by "TrojanSpy.Win32.Agent.w" Virus. Action Taken: No Action Taken. Mon Dec 20 21:30:03 2004 => Scanning File C:\WINDOWS\System32\helpefav.dll Mon Dec 20 21:30:03 2004 => File C:\WINDOWS\System32\helpefav.dll infected by "TrojanSpy.Win32.Small.bf" Virus. Action Taken: No Action Taken. Mon Dec 20 21:30:05 2004 => Scanning File C:\WINDOWS\System32\iecust.exe Mon Dec 20 21:30:05 2004 => File C:\WINDOWS\System32\iecust.exe infected by "Trojan-Dropper.Win32. Mon Dec 20 21:30:20 2004 => File C:\WINDOWS\System32\mstu.dll infected by "Trojan-Downloader.Win32.Agent.fy" Virus. Action Taken: No Action Taken. Zitat:
|
Die infizierten Dateien manuell im abg. Modus löschen. Anschließend bitte ein neues HijackThis-Log posten. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 00:56 Uhr. |
Copyright ©2000-2025, Trojaner-Board