Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Ich hasse Pferde (aus Griechenland) (https://www.trojaner-board.de/15296-hasse-pferde-griechenland.html)

smiley 12.03.2005 19:11

Ich hasse Pferde (aus Griechenland)
 
Hi Leute, kann mir einer helfen meine ganzen trojaner usw. loszuwerden :heulen: ?

Besten Dank

Hier is mein log:

Logfile of HijackThis v1.99.1
Scan saved at 18:58:17, on 12.03.2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Programme\QuickTime\qttask.exe
C:\Programme\AVPersonal\AVGNT.EXE
C:\Programme\AVPersonal\AVSched32.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Cyber Firewall 2003\SOS.exe
C:\WINDOWS\System32\SPOOLSVU.EXE
C:\WINDOWS\System32\ALG32.EXE
C:\Programme\Internet Explorer\IEXPLORE.EXE
C:\Martins Dateien\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.searchmiracle.com/main/sp.php
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://www.searchmiracle.com/main/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchmiracle.com/main/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchmiracle.com/main/sp.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmx.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.searchmiracle.com/main/sp.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.searchmiracle.com/main/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchmiracle.com/main/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.searchmiracle.com/main/sp.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
F1 - win.ini: run=msinfo.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: SearchAddon - {799A370D-5993-4887-9DF7-0A4756A77D00} - C:\WINDOWS\System32\search.dll
O2 - BHO: HTDP Class - {9E6EC32A-7C19-4409-99E8-FC980BCDAF26} - C:\WINDOWS\htass.dll
O2 - BHO: (no name) - {EC11B58D-B2CA-48C0-9DC4-A4E2021DD2AA} - C:\WINDOWS\System32\naajg.dll (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVSCHED32] C:\Programme\AVPersonal\AVSched32.EXE /min
O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SOS] C:\Programme\Cyber Firewall 2003\SOS.exe /s
O4 - HKCU\..\Run: [SPOOLSVU] C:\WINDOWS\System32\SPOOLSVU.EXE
O4 - HKCU\..\Run: [ALG32] C:\WINDOWS\System32\ALG32.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O12 - Plugin for .spop: C:\Programme\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: ppctlcab - http://ppupdates.ca.com/downloads/scanner/ppctlcab.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://ppupdates.ca.com/downloads/scanner/axscanner.cab
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://www.xxxtoolbar.com/ist/softwa...0006_adult.cab
O16 - DPF: {E0B795B4-FD95-4ABD-A375-27962EFCE8CF} - http://install.serviceurl.de/StarInstall.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{8ED9E806-C6FC-4F04-B689-636EB2C23760}: NameServer = 192.168.120.252,192.168.120.253
O18 - Filter: text/html - {1EE4731C-7883-421C-B777-BCA8B17BA737} - C:\WINDOWS\System32\naajg.dll
O18 - Filter: text/plain - {1EE4731C-7883-421C-B777-BCA8B17BA737} - C:\WINDOWS\System32\naajg.dll
O19 - User stylesheet: (file missing)
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE
O23 - Service: AVM FRITZ!web Routing Service (de_serv) - AVM Berlin - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe

Rene-gad 12.03.2005 19:54

@smiley
Zitat:

Hi Leute, kann mir einer helfen meine ganzen trojaner usw. loszuwerden
Wir nicht, aber...http://www.trojaner-board.com/showthread.php?t=12154
Zitat:

Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Ungepatchtes Windows.
Infolge dessen:
Zitat:

C:\WINDOWS\System32\SPOOLSVU.EXE
C:\WINDOWS\System32\ALG32.EXE
O4 - HKCU\..\Run: [SPOOLSVU] C:\WINDOWS\System32\SPOOLSVU.EXE
O4 - HKCU\..\Run: [ALG32] C:\WINDOWS\System32\ALG32.EXE
http://www.sophos.ch/virusinfo/analy...ojagentcj.html
Zitat:

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = h--p://www.searchmiracle.com/main/sp.php
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = h--p://www.searchmiracle.com/main/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = h--p://www.searchmiracle.com/main/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = h--p://www.searchmiracle.com/main/sp.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = h--p://www.searchmiracle.com/main/sp.php
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = h--p://www.searchmiracle.com/main/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = h--p://www.searchmiracle.com/main/sp.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = h--p://www.searchmiracle.com/main/sp.php
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
Warum wird diese Müllsammlung von HJT-AA als Gut identifiziert? Fixen.
Zitat:

F1 - win.ini: run=msinfo.exe
http://www.liutilities.com/products/...ibrary/msinfo/
Zitat:

C:\WINDOWS\System32\search.dll
http://forum.iamnotageek.com/t-77166.html
Zitat:

O2 - BHO: HTDP Class - {9E6EC32A-7C19-4409-99E8-FC980BCDAF26} - C:\WINDOWS\htass.dll
http://www.sophos.com/virusinfo/anal...ojagentcj.html
Zitat:

O2 - BHO: (no name) - {EC11B58D-B2CA-48C0-9DC4-A4E2021DD2AA} - C:\WINDOWS\System32\naajg.dll (file missing)
O16 - DPF: {386A771C-E96A-421F-8BA7-32F1B706892F} (Installer Class) - http://h--p://www.xxxtoolbar.com/ist...0006_adult.cab
O16 - DPF: {E0B795B4-FD95-4ABD-A375-27962EFCE8CF} - h--p://install.serviceurl.de/StarInstall.ocx
O18 - Filter: text/html - {1EE4731C-7883-421C-B777-BCA8B17BA737} - C:\WINDOWS\System32\naajg.dll
O18 - Filter: text/plain - {1EE4731C-7883-421C-B777-BCA8B17BA737} - C:\WINDOWS\System32\naajg.dll
O19 - User stylesheet: (file missing)
Alles fixen.
Du siehst schon slebst, dass es besser gewesen wäre, dein Win neu aufzuspielen.

Cidre 12.03.2005 21:29

Zitat:

Zitat von Rene-gad
Warum wird diese Müllsammlung von HJT-AA als Gut identifiziert?

Weil die automatische HJT Auswertung von der Aktualisierung bzw. Abgleich der Datenbank lebt.;)


Alle Zeitangaben in WEZ +1. Es ist jetzt 03:06 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131