![]() |
Logfile bitte ansehen - dringend! Hab das Logilfe schon ausgewertet. Bin mir aber nicht sicher welche Programme 100% gelöscht werden müssen. Kann mir da mal einer weiterhelfen. Danke im Vorraus... Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\Explorer.EXE C:\Programme\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\System32\svchost.exe C:\Program Files\mIRC\mirc.exe C:\Programme\Internet Explorer\iexplore.exe C:\Programme\ICQLite\ICQLite.exe C:\Dokumente und Einstellungen\Andreas Peters.PRIVATANDREAS\Desktop\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.vfl-bochum.de/ R3 - Default URLSearchHook is missing O1 - Hosts: 127.37.63.97 www.symantec.com O1 - Hosts: 127.121.161.31 securityresponse.symantec.com O1 - Hosts: 127.199.36.88 www.mcafee.com O1 - Hosts: 127.108.148.53 mcafee.com O1 - Hosts: 127.39.88.53 us.mcafee.com O1 - Hosts: 127.248.194.4 www.sophos.com O1 - Hosts: 127.136.61.185 sophos.com O1 - Hosts: 127.54.92.147 www.viruslist.com O1 - Hosts: 127.121.226.59 viruslist.com O1 - Hosts: 127.22.186.255 f-secure.com O1 - Hosts: 127.227.254.10 www.f-secure.com O1 - Hosts: 127.146.10.99 kaspersky.com O1 - Hosts: 127.42.187.172 www.avp.com O1 - Hosts: 127.220.111.247 www.kaspersky.com O1 - Hosts: 127.134.106.198 avp.com O1 - Hosts: 127.141.23.140 www.networkassociates.com O1 - Hosts: 127.170.35.24 networkassociates.com O1 - Hosts: 127.75.50.12 www.ca.com O1 - Hosts: 127.26.129.17 ca.com O1 - Hosts: 127.149.216.4 my-etrust.com O1 - Hosts: 127.187.235.224 www.my-etrust.com O1 - Hosts: 127.187.53.104 secure.nai.com O1 - Hosts: 127.128.52.21 nai.com O1 - Hosts: 127.45.156.20 www.nai.com O1 - Hosts: 127.76.123.47 trendmicro.com O1 - Hosts: 127.163.75.171 www.trendmicro.com O1 - Hosts: 127.80.138.161 housecall.trendmicro.com O1 - Hosts: 127.209.9.234 www.pandasoftware.com O1 - Hosts: 127.153.39.59 www.bitdefender.com O1 - Hosts: 127.163.228.147 www.ravantivirus.com O1 - Hosts: 127.142.19.255 www3.ca.com O1 - Hosts: 127.43.184.101 v4.windowsupdate.microsoft.com O1 - Hosts: 127.131.179.189 v5.windowsupdate.microsoft.com O1 - Hosts: 127.213.72.239 v5windowsupdate.microsoft.nsatc.net O1 - Hosts: 127.174.141.21 windowsupdate.microsoft.com O1 - Hosts: 127.120.14.28 www.windowsupdate.com O1 - Hosts: 127.44.35.173 windowsupdate.com O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar1.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: MSN Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programme\MSN Toolbar\01.01.1629.0\de\msntb.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar1.dll O4 - HKLM\..\Run: [wdskctl] C:\WINDOWS\wdskctl.exe O4 - HKLM\..\Run: [I/O Controllers] svcnet.exe O4 - HKLM\..\Run: [WinService16] drvinit.exe -services O4 - HKLM\..\Run: [sais] c:\programme\180solutions\sais.exe O4 - HKLM\..\Run: [BullsEye Network] C:\Programme\BullsEye Network\bin\bargains.exe O4 - HKLM\..\Run: [pixofqr] C:\WINDOWS\pixofqr.exe O4 - HKCU\..\Run: [I/O Controllers] svcnet.exe O4 - HKCU\..\Run: [WinService16] drvinit.exe -drivers O4 - HKCU\..\Run: [IPConfig] svcxnv32.exe O4 - HKCU\..\Run: [msnmsgr] "C:\Programme\MSN Messenger\msnmsgr.exe" /background O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot O7 - HKCU\Software\Microsoft\Windows\CurrentVersion\Policies\System, DisableRegedit=1 O8 - Extra context menu item: &Google Search - res://C:\Programme\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Backward &Links - res://C:\Programme\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Programme\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Si&milar Pages - res://C:\Programme\Google\GoogleToolbar1.dll/cmsimilar.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\j2re1.4.2_05\bin\npjpi142_05.dll O9 - Extra button: SideFind - {10E42047-DEB9-4535-A118-B3F6EC39B807} - C:\Programme\SideFind\sidefind.dll O9 - Extra button: concept/design's onlineTV - {2640F16C-8E3A-4E71-A40E-5F7980542CBC} - C:\WINDOWS\System32\shdocvw.dll O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE O15 - Trusted Zone: http://www.winning-eleven.com O15 - Trusted IP range: 192.168.123.254 O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://xxxtrayicon.com/xtrayinst.exe O16 - DPF: {00000EF1-0786-4633-87C6-1AA7A44296DA} (F1 Organizer Class) - http://www.addictivetechnologies.net...ATPartners.cab O16 - DPF: {1230CB21-C88D-11CF-B347-000000000000} - http://www.eingang69.de/EroticAccess/Cabs/1826003.cab O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} - http://www.xxxtoolbar.com/ist/softwa...06_regular.cab O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_fi...271ab95b94951b O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://www.xxxtoolbar.com/ist/softwa...006_cracks.cab O16 - DPF: {469C7080-8EC8-43A6-AD97-45848113743C} - http://akamai.downloadv3.com/binarie...hv32_EN_XP.cab O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} (Installer Class) - http://www.ysbweb.com/ist/softwares/...sb_regular.cab O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - http://www.netvenda.com/sites/games-intl/de/games4.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{53498297-A370-4D91-8A74-24C22F556A4F}: NameServer = 195.50.140.250 145.253.2.11 O18 - Filter: text/html - {FDA6AB77-176E-4DDF-B974-1BBDBB765D57} - C:\Dokumente und Einstellungen\Andreas Peters.PRIVATANDREAS\Lokale Einstellungen\Anwendungsdaten\microsoft\internet explorer\V0.26.dat O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE O23 - Service: Network Authentification - Unknown - C:\WINDOWS\System32\SMGR32.EXE (file missing) O23 - Service: ZESOFT - Unknown - C:\WINDOWS\zeta.exe |
Mal abgesehen,dass das Logfile nicht komplett ist(es fehlen die Angaben zum System etc) kannst du deinen Rechner neu aufsetzen! Grund:MEHRERE gefährliche Trojaner und Würmer mit Backdoor Funktion,lese dazu bitte den Post von Cidre und befolge desen Anleitungen genau! http://trojaner-board.de/showthread.php?t=12154 Gruss |
Alle Zeitangaben in WEZ +1. Es ist jetzt 16:56 Uhr. |
Copyright ©2000-2025, Trojaner-Board