Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   versch. TR/... (https://www.trojaner-board.de/14882-versch-tr.html)

Nalle 04.03.2005 15:55

versch. TR/...
 
Hallo zusammen,

ich habe ein problem mit meinem internet-zugang.
ich weiß nicht obs an den verschiedenen versionen von TR/... liegt, die sich auf meinem pc tummeln (TR/StartPage.FH, TR/Dldr.Agent, und Dropper DR/Small.OF.F)oder an CWS, von dem ich eigentlich dachte ich wäre es losgeworden.
deshalb würde ich mich freuen, wenn mir jemand helfen könnte.
hier ist mein hijackThis-log:

Logfile of HijackThis v1.99.0
Scan saved at 15:45:14, on 04.03.2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AVPersonal\AVGUARD.EXE
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\drivers\CDAC11BA.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\ps2.exe
C:\PROGRA~1\0190WA~1\WARN0190.EXE
C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programme\AVPersonal\AVGNT.EXE
C:\Programme\ICQLite\ICQLite.exe
C:\Programme\AVPersonal\INETUPD.EXE
C:\T-Online\Browser\Browser.exe
C:\T-Online\Browser\WsUpdate.exe
C:\Programme\Kazaa Lite K++\Kazaa.kpp
C:\Programme\HijackThis!\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.fs-location.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://adserv.internetfuel.com/cgi-b...82&PID=2&LID=3
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer von Deutsche Telekom Online Service GmbH
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar1.dll
O4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [Microsoft Works Portfolio] C:\Programme\Microsoft Works\WksSb.exe /AllUsers
O4 - HKLM\..\Run: [Microsoft Works Update Detection] C:\Programme\Microsoft Works\WkDetect.exe
O4 - HKLM\..\Run: [RASTimer] C:\Programme\RASTimer\RASTimer.exe
O4 - HKLM\..\Run: [0190 Warner] C:\PROGRA~1\0190WA~1\WARN0190.EXE
O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O8 - Extra context menu item: &Google Search - res://C:\Programme\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Programme\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Programme\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:\Programme\Google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: Recherche-Assistent - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Reference 2001\EROProj.dll
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.t-online.de
O15 - Trusted IP range: 206.161.125.149
O17 - HKLM\System\CCS\Services\Tcpip\..\{203D4B2E-139A-47BB-BB92-61EC9DE1BBE3}: NameServer = 217.237.151.97 217.237.150.33
O17 - HKLM\System\CS1\Services\Tcpip\..\{203D4B2E-139A-47BB-BB92-61EC9DE1BBE3}: NameServer = 217.237.151.97 217.237.150.33
O21 - SSODL: SystemCheck2 - {54645654-2225-4455-44A1-9F4543D34545} - (no file)
O23 - Service: AntiVir Service - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE
O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINDOWS\System32\drivers\CDAC11BA.EXE
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe


Im voraus schon mal vielen dank an jeden der mir helfen kann!!!

chaosman 04.03.2005 17:30

@Nalle

dein problem fängt schon hier an
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

dein system ist völlig veraltet, also system und IE updaten

danach escan downloaden

download
anleitung
überprüfe Deinen Rechner zunächst mit dem eScan: lade den eScan runter, erstelle dafür einen Ordner (=Verzeichnis) c:\bases, update den eScan online und führe ihn offline im abgesicherten Modus aus. Beachte, dass der eScan ab Version 4.5.1 gefundene Malware nicht löscht. Das wird von Hand auf Anweisung durch uns gemacht.

Teile uns dann das Ergebnis des eScan mit: welche Viren wurden auf Deinem Rechner gefunden: "öffne die mwav.log -> Bearbeiten -> Suchen -> infected eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen." (Zitat Cidre)

chaosman

Nalle 11.03.2005 18:06

hier ist mein escan-log:
ich hoffe man kann noch was tun, ohne festplatte zu formatieren!

C:\Programme\MySearch\bar\1.bin\NPMYSRCH.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.f" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP126\A0071231.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP126\A0071236.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP126\A0071246.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP126\A0071249.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP127\A0071275.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP127\A0071285.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP127\A0071288.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP127\A0071338.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP127\A0071340.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP127\A0071373.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP127\A0071384.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP127\A0071392.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.
C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP127\A0071414.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP127\A0071425.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP128\A0071443.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP128\A0071456.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP128\A0071467.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP128\A0071477.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP129\A0072543.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP129\A0072553.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP129\A0072562.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP129\A0072571.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP130\A0075570.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP131\A0076631.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP131\A0076635.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.
C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP131\A0076645.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP131\A0076648.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP131\A0077648.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP131\A0078753.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP131\A0081649.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084725.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084755.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084784.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084786.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084787.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084792.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084793.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084795.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.
C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084796.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084797.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084798.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084799.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084800.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084801.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084803.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084804.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084805.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084806.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084807.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084808.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084817.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.
C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084819.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0084821.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0086719.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken

C:\System Volume Information\_restore{139ED24C-D4CE-416E-8338-2638908E014D}\RP132\A0086720.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken.

C:\WINDOWS\Downloaded Program Files\load.exe infected by "Trojan-Downloader.Win32.Harnig.al" Virus. Action Taken: No Action Taken.

C:\WINDOWS\iconu.exe infected by "not-a-virus:AdWare.Zestyfind" Virus. Action Taken: No Action Taken.

C:\WINDOWS\system32\cmd.ftp infected by "Trojan-Downloader.BAT.Ftp.r" Virus. Action Taken: No Action Taken.

C:\WINDOWS\system32\tmp.exe infected by "not-a-virus:AdWare.ToolBar.Perez.a" Virus. Action Taken: No Action Taken.

C:\WINDOWS\Temp\bw2.exe infected by "not-a-virus:AdWare.Zestyfind" Virus. Action Taken: No Action Taken.

C:\WINDOWS\wlxr.exe infected by "Trojan.Win32.StartPage.kp" Virus. Action Taken: No Action Taken.

Traces of "Welchia" found and cleaned !!!

C:\hp\bin\py152.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.

C:\hp\bin\Terminator.exe tagged as not-a-virus:RiskWare.Tool.KillApp. No Action Taken.

C:\hp\bin\WIN32ALL-125.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.

danke!


Alle Zeitangaben in WEZ +1. Es ist jetzt 21:03 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131