![]() |
Sfondi Dialer Hallo! Habe mir den Sfondi Dialer eingefangen. Spybot und Ad-aware konnten ihn bis jetzt nicht finden. Genausowenig wie Antivirus. Hat von Euch evtl. jemand eine Lösung? Jetzt habe ich hier gelesen, das man sein System mit Hijackthis scannen soll. Das hab ich eben gemacht. Hier das Log-File: Code: Logfile of HijackThis v1.99.1 Vielen Dank... Peter |
@Buggyboy du hast mehrere unbekannte prozesse im system, überprüfe bitte dein system mit escan http://www.trojaner-board.de/showthread.php?t=17492 chaosman |
Hallo; ich habe warscheinlich so einen Sfondi drauf. Bei mir öffnet sich zu erst einmal ein popup von Sfondi vonwegen Screensavers und dann eine warnuhg von Microsoft die aber keine von Microsoft ist. escan habe ich laufen lassen ich hoffe ich setze den log richtig. File C:\WINDOWS\etb\nt_hide66.dll infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\windows\system32\kalvtnf32.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken. File C:\WINDOWS\etb\pokapoka66.exe infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\windows\system32\elitedrb32.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken. File C:\WINDOWS\etb\pokapoka66.exe infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\windows\system32\kalvtnf32.exe infected by "Trojan.Win32.StartPage.nk" Virus! Action Taken: No Action Taken. Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "StyleXP Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "WhenU.SaveNow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "SpywareNo!/SpySheriff Commercial KeyLogger" found in File System! Action Taken: No Action Taken. Object "SpywareNo!/SpySheriff Commercial KeyLogger" found in File System! Action Taken: No Action Taken. Object "SpywareNo!/SpySheriff Commercial KeyLogger" found in File System! Action Taken: No Action Taken. Object "SpywareNo!/SpySheriff Commercial KeyLogger" found in File System! Action Taken: No Action Taken. Object "SpywareNo!/SpySheriff Commercial KeyLogger" found in File System! Action Taken: No Action Taken. Object "SpywareNo!/SpySheriff Commercial KeyLogger" found in File System! Action Taken: No Action Taken. Object "SpywareNo!/SpySheriff Commercial KeyLogger" found in File System! Action Taken: No Action Taken. Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "kalv Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "WhenU/SaveNow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "bearshare Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "cws.therealsearch Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "istbar Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "RedV Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "roings Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "WhenU.SaveNow Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "SpywareNo!/SpySheriff Commercial KeyLogger" found in File System! Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "H:\Programme\Uninstall.exe". Action Taken: No Action Taken. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".fcp". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "Hunting Unlimited 3". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "NVIDIA". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "NVIDIA nForce Drivers". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "oeupdate". Action Taken: No Action Taken. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "WhenUSaveMsg". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4C071CCC-D80E-4D86-AD9F-CACF95A198A2}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\editLive4common.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4EFA3C5D-DA8E-4A03-82D9-5F0E616B163C}" refers to invalid object "C:\PROGRA~1\GEMEIN~1\Ephox\CJSUIT~1.OCX". Action Taken: No Action Taken. Entry "HKCR\CLSID\{4FF20192-4473-4A40-AA79-CC3579936223}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\editLive4common.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{502C0FCF-C0FC-4167-9B29-0E813382B4E5}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\editLive4common.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{9F95F736-0F62-4214-A4B4-CAA6738D4C07}" refers to invalid object "H:\Programme\BearShare\RunMSC.dll". Action Taken: No Action Taken. Entry "HKCR\CLSID\{A7856B5C-BBC2-4453-A60C-A3F5DF483C95}" refers to invalid object "C:\PROGRA~1\GEMEIN~1\Ephox\CJCOMM~1.OCX". Action Taken: No Action Taken. Entry "HKCR\CLSID\{E76ECE4B-D3C0-4A01-BFFA-E2D6ECD756D5}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\editLive4common.exe". Action Taken: No Action Taken. Entry "HKCR\CLSID\{F8354A1F-4FDE-4A3C-BA0E-81E4A538A640}" refers to invalid object "C:\PROGRA~1\GEMEIN~1\Ephox\CJDOCK~1.OCX". Action Taken: No Action Taken. Entry "HKCR\TypeLib\{C53EC2D9-40D2-4C87-8C51-CB88938C1DA5}" refers to invalid object "C:\WINDOWS\Downloaded Program Files\editLive4common.exe". Action Taken: No Action Taken. Entry "HKCR\.spl" refers to invalid object "ShockwaveFlash.ShockwaveFlash". Action Taken: No Action Taken. Entry "HKCR\.swf" refers to invalid object "ShockwaveFlash.ShockwaveFlash". Action Taken: No Action Taken. Entry "HKCR\ed2k\shell\open\command" refers to invalid object ""H:\Programme\eMule\eMule.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\gnu\shell\open\command" refers to invalid object ""H:\Programme\BearShare\BearShare.exe" --noinstcheck -spawnedfromurl %1". Action Taken: No Action Taken. Entry "HKCR\gnufile\shell\open\command" refers to invalid object ""H:\Programme\BearShare\BearShare.exe" "%1"". Action Taken: No Action Taken. Entry "HKCR\gnutella\shell\open\command" refers to invalid object ""H:\Programme\BearShare\BearShare.exe" -noinstcheck -spawnedfromurl %1". Action Taken: No Action Taken. Entry "HKCR\magnet\shell\open\command" refers to invalid object ""H:\Programme\BearShare\BearShare.exe" -noinstcheck -spawnedfromurl %1". Action Taken: No Action Taken. File C:\Dokumente und Einstellungen\solling5\Eigene Dateien\BSINSTALLDE.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken. File C:\Dokumente und Einstellungen\solling5\Lokale Einstellungen\Temp\393372_1452_2180_3244_66.41.tmp1 infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. File C:\Dokumente und Einstellungen\solling5\Lokale Einstellungen\Temp\iinstall.exe infected by "Trojan-Downloader.Win32.IstBar.lq" Virus! Action Taken: No Action Taken. File C:\Dokumente und Einstellungen\solling5\Lokale Einstellungen\Temp\saveinstwm.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken. File C:\Dokumente und Einstellungen\solling5\Lokale Einstellungen\Temp\temp.fr7397\pokapoka66.exe infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{64B10ED7-4B36-47B7-A21B-ED1CB20BC37F}\RP73\A0005632.dll infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{64B10ED7-4B36-47B7-A21B-ED1CB20BC37F}\RP73\A0005633.dll infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{64B10ED7-4B36-47B7-A21B-ED1CB20BC37F}\RP73\A0005675.dll infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{64B10ED7-4B36-47B7-A21B-ED1CB20BC37F}\RP73\A0005676.dll infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{64B10ED7-4B36-47B7-A21B-ED1CB20BC37F}\RP73\A0005759.exe infected by "Trojan-Dropper.Win32.Agent.kd" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{64B10ED7-4B36-47B7-A21B-ED1CB20BC37F}\RP73\A0005938.dll infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{64B10ED7-4B36-47B7-A21B-ED1CB20BC37F}\RP73\A0005939.dll infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{64B10ED7-4B36-47B7-A21B-ED1CB20BC37F}\RP73\A0005940.exe infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{64B10ED7-4B36-47B7-A21B-ED1CB20BC37F}\RP75\A0005965.dll infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{64B10ED7-4B36-47B7-A21B-ED1CB20BC37F}\RP75\A0005966.dll infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. File C:\System Volume Information\_restore{64B10ED7-4B36-47B7-A21B-ED1CB20BC37F}\RP75\A0005968.exe infected by "Trojan-Downloader.Win32.Agent.tv" Virus! Action Taken: No Action Taken. Verzeiht wenn ich den log falsch gemacht habe..... Bin Blond :headbang: |
@ Hittransporter! Damit wir hier nicht durcheinander kommen: Eröffne einen neuen thread (forum wählen, *click* "Neues thema") und poste ein HJT-Logfile nach Cidres Anweisung! http://www.trojaner-board.de/showthread.php?t=17493 stupormundi |
Alle Zeitangaben in WEZ +1. Es ist jetzt 13:39 Uhr. |
Copyright ©2000-2025, Trojaner-Board