Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Trojaner TR/DLDR.Agent bzw. TR/small (https://www.trojaner-board.de/25278-trojaner-tr-dldr-agent-bzw-tr-small.html)

Willyviper 03.01.2006 13:15

Trojaner TR/DLDR.Agent bzw. TR/small
 
Hallo,

habe hier ein Problem mit ein paar Trojanern, die ich nich los werde.

Also Antivir meldet als Trojaner TR/DLDR.Agent.TD52 und 66, außerdem TR/Agent.BI.98 und TR/Small.GA.7

Trotz scannen mit Spybot und Ad-Aware auch im abgesicherten Modus tauchen die Teile immer wieder auf. Wer kann mir Helfen, habe hier mal das HJT Log und davon nicht die geringste Ahnung, die Kiste scheint nur ziemlich verbaselt zu sein.

Logfile of HijackThis v1.99.1
Scan saved at 12:05:15, on 03.01.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AVPersonal\AVGUARD.EXE
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\msyk.exe
C:\Programme\Java\jre1.5.0\bin\jusched.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programme\Synaptics\SynTP\SynTPLpr.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\HP\HP Software Update\HPWuSchd2.exe
C:\Programme\Winamp\winampa.exe
C:\DOKUME~1\***\LOKALE~1\Temp\1F5.tmp.exe
C:\Programme\Logitech\MouseWare\system\em_exec.exe
C:\Programme\AVPersonal\AVGNT.EXE
C:\WINDOWS\system32\atljh32.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programme\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Programme\HP\Digital Imaging\Product Assistant\bin\hprblog.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\msiexec.exe
C:\WINDOWS\system32\wuauclt.exe
C:\WINDOWS\system32\wuauclt.exe
C:\hijack\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\system32\mtpou.dll/sp.html#53142%resultposition.net
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: Class - {054FA522-3449-3E70-B480-5C8348478A0A} - C:\WINDOWS\javand32.dll (file missing)
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Class - {084856A6-8EE9-94CD-77C3-FF8257705B80} - C:\WINDOWS\system32\mfcyc.dll
O2 - BHO: Class - {091DD5A2-BCF3-5ABD-CDB0-DEE71178B028} - C:\WINDOWS\sdklk32.dll (file missing)
O2 - BHO: Class - {402AEE94-BB1D-D3EA-410F-95DE07E61963} - C:\WINDOWS\atlkx32.dll
O2 - BHO: Class - {CA00AEE9-F0FC-9BB6-7C51-5ABAC98D7A70} - C:\WINDOWS\system32\ntzq32.dll
O2 - BHO: Class - {EDA38CC9-B865-78BD-C1A5-843DCC6547D9} - C:\WINDOWS\mfcir32.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0\bin\jusched.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Programme\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe
O4 - HKLM\..\Run: [1DE.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\1DE.tmp.exe
O4 - HKLM\..\Run: [WinHound] C:\Programme\WinHound\WinHound.exe
O4 - HKLM\..\Run: [NAVNet] "C:\Dokumente und Einstellungen\***\Startmenü\Programme\Autostart\ms.exe" /m
O4 - HKLM\..\Run: [javajv.exe] C:\WINDOWS\system32\javajv.exe
O4 - HKLM\..\Run: [1F5.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\1F5.tmp.exe
O4 - HKLM\..\Run: [1F6.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\1F6.tmp.exe
O4 - HKLM\..\Run: [1F5.tmp.exe] C:\DOKUME~1\***\LOKALE~1\Temp\1F5.tmp.exe
O4 - HKLM\..\Run: [1F6.tmp.exe] C:\DOKUME~1\***\LOKALE~1\Temp\1F6.tmp.exe
O4 - HKLM\..\Run: [1FD.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\1FD.tmp.exe
O4 - HKLM\..\Run: [1FD.tmp.exe] C:\DOKUME~1\***\LOKALE~1\Temp\1FD.tmp.exe
O4 - HKLM\..\Run: [netti32.exe] C:\WINDOWS\system32\netti32.exe
O4 - HKLM\..\Run: [204.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\204.tmp.exe
O4 - HKLM\..\Run: [204.tmp.exe] C:\DOKUME~1\***\LOKALE~1\Temp\204.tmp.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [atljh32.exe] C:\WINDOWS\system32\atljh32.exe
O4 - HKLM\..\RunOnce: [msyk.exe] C:\WINDOWS\msyk.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [LDM] \Program\
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programme\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - h**p://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - h**p://w*w.johannrain-softwareentwicklung.de/scan/Msie/bitdefender.cab
O18 - Protocol: bw+0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {CEA2A406-CE56-4C96-9E6F-5376F83AA9D0} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Network Security Service ( 11Fßä#·ºÄÖ`I) - Unknown owner - C:\WINDOWS\system32\apiai32.exe (file missing)
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe

cosinus 03.01.2006 13:24

Nur ein Auszug:

Zitat:

O4 - HKLM\..\Run: [1F5.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\1F5.tmp.exe
O4 - HKLM\..\Run: [1F6.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\1F6.tmp.exe
O4 - HKLM\..\Run: [1F5.tmp.exe] C:\DOKUME~1\***\LOKALE~1\Temp\1F5.tmp.exe
O4 - HKLM\..\Run: [1F6.tmp.exe] C:\DOKUME~1\***\LOKALE~1\Temp\1F6.tmp.exe
O4 - HKLM\..\Run: [1FD.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\1FD.tmp.exe
O4 - HKLM\..\Run: [1FD.tmp.exe] C:\DOKUME~1\***\LOKALE~1\Temp\1FD.tmp.exe
O4 - HKLM\..\Run: [netti32.exe] C:\WINDOWS\system32\netti32.exe
O4 - HKLM\..\Run: [204.tmp] C:\DOKUME~1\***\LOKALE~1\Temp\204.tmp.exe
O4 - HKLM\..\Run: [204.tmp.exe] C:\DOKUME~1\***\LOKALE~1\Temp\204.tmp.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [atljh32.exe] C:\WINDOWS\system32\atljh32.exe
O4 - HKLM\..\RunOnce: [msyk.exe] C:\WINDOWS\msyk.exe
Ich glaube, da bleibt nur das Neuaufsetzen über...

hoerni26 03.01.2006 13:25

hallo,

also ich sehe direkt einige sachen bei denen ich nicht weiss was ich davon halten soll...
ich bitte dich darum einen onlinescan Hier zu machen und das ergebniss hier zu posten...
damit wir sicher wissen ob fixen und löschen ausreicht oder eventuell doch neu aufgesetzt werden muss..

Willyviper 03.01.2006 16:31

KASPERSKY ON-LINE SCANNER REPORT
Tuesday, January 03, 2006 16:30:28
Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 3/01/2006
Kaspersky Anti-Virus database records: 158551
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 69025
Number of viruses found: 6
Number of infected objects: 144
Number of suspicious objects: 0
Duration of the scan process: 8039 sec

Infected Object Name - Virus Name
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[Fro ... /[From "Horst-Dieter Ge ... /[F ... /[From "Patncree" <patncree@ev1.net>][Date Tue, 31 May 2005 15: ... /02_05_2005.exe Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[Fro ... /[From "Horst-Dieter Ge ... /[F ... /[From "Patncree" <patncree@ev1.net>][Date Tue, 31 May 2005 15:20:49 - ... /UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[Fro ... /[From "Horst-Dieter Ge ... /[F ... /[From "Patncree" <patncree@ev1.net>][Date Tue, 31 May 2005 15:20:49 -0300]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[Fro ... /[From "Horst-Dieter Ge ... /[From Team Vectra <Team.Vectra@de.opel.com>][Date Tue, 31 May 2005 11:43:43 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[Fro ... /[From "Horst-Dieter Geuting" <horst-dieter.geuting@w.fh-giessen.de>][Date Thu, 26 May 2005 09:20:29 +0200 (CEST)]/text Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO ... ... /[F ... /[From "Sebastian Brehmer" <sebastian_brehmer@web.de>][Date Mon, 23 May 2005 16:25:42 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO ... ... /[From .. ... /[From "WiWi-Online.de" <schmid@wiwi-online.de>][Date Fri, 20 May 2005 14:20:28 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO ... ... /[From ... /[From "Martin Pfe ... /[From <leonardo-tutor@web.de>][Date Fri, 20 May 2005 09:17:24 +0200]/text Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO ... ... /[From ... /[From "Martin Pfeiffer" <mail@Martin-Pfeiffer.de>][Date Thu, 19 May 2005 16:24:02 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO ... ... /[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Thu, 19 May 2005 15:00:41 +0100]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO ... /[From "bestellbestaetigung@amazon.de" <bestellbestaetigung@amazon.de>][Date 19 May 2005 00:55:47 -0700]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-885 ... .. ... /[From "Susanne Weber" <Susanne.Weber@w.fh-giessen.de>][Date Fri, 29 Apr 2005 11:12:03 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-885 ... ... /[ ... /[From "Julia Mengel" <julia.mengel@gmx.de>][Date Thu, 28 Apr 2005 08:58:49 +0200 (MEST)]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-885 ... ... /[From "Dr. Martin Schmidt" <Martin.Schmidt@w.fh-giessen.de>][Date Wed, 13 Apr 2005 18:46:58 +0200]/text Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-885 ... /[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 12 Apr 2005 15:00:35 +0100]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-8859-1?b ... /[Fr ... /[From "Schlueter, Ursula" <u.schlueter@ukh.de>][Date Tue, 12 Apr 2005 08:20:21 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-8859-1?b ... /[From "Dr ... /[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 11 Apr 2005 14:48:47 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-8859-1?b ... /[From "Dr. Martin Schmidt" <Martin.Schmidt@w.fh-giessen.de>][Date Mon, 4 Apr 2005 09:28:11 +0200]/text Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-8859-1?b?Ik1pY2hhZ ... /[From "Benjamin Hermann" <b.hermann@coreto.de>][Date Fri, 1 Apr 2005 16:48:08 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 . ... /[From =?ISO-8859-1?b?Ik1pY2hhZWwgR/Z0eiwgQS1KdW5pb3JlbiI=?= <510060784089-0001@T-Online.de>][Date 31 Mar 2005 14:07 GMT]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 ... /[From =?ISO-8859 ... /[From ... /[From =?iso-8859-1?Q?Lena_Sch=FCtz?= <les@vds.ag>][Date Tue, 29 Mar 2005 12:40:27 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 ... /[From =?ISO-8859 ... /[From "dany.eberhart@t-online.de" <dany.eberhart@t-online.de>][Date Thu, 24 Mar 2005 12:44:56 +0100]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12 ... /[From =?ISO-8859-1?Q?=22Sabrina_Hillg=E4rtner=22?= <sabrina.hillgaertner@gmx.de>][Date Mon, 21 Mar 2005 20:52:46 +0100 (MET)]/text Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12:16:37 +0100 (MET)]/UNNAMED/[From ... /[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 14:44:30 +0100 (MET)]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12:16:37 +0100 (MET)]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12:21:31 +0100 (MET)]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED/[From "Nicole Heller" <nicoleheller@gmx.net>][Date Mon, 21 Mar 2005 12:16:37 +0100 (MET)]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED/[From "Amazon.de" <promotion5@amazon.de>][Date 20 Mar 2005 19:38:37 -0800]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED/[From "INFODIENST FB Wirtschaft" <webmaster@w.fh-giessen.de>][Date Tue, 08 Mar 2005 15:00:59 +0100]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox/[From "Lale Kleinschmidt" <Laleluis@gmx.de>][Date Tue, 8 Mar 2005 11:59:56 +0100 (MET)]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Inbox Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 J ... ... ... /[From "Patncree" <patncree@ev1.net>][Date Tue, 31 May 2005 15: ... /02_05_2005.exe Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 J ... ... ... /[From "Patncree" <patncree@ev1.net>][Date Tue, 31 May 2005 15:20:49 - ... /UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 J ... ... ... /[From "Patncree" <patncree@ev1.net>][Date Tue, 31 May 2005 15:20:49 -0300]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 J ... ... /[From *** Ecke <***.Ecke@gmx.de>][Date Sun, 07 Aug 2005 10:54:32 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 J ... ... /[From *** Ecke <***.Ecke@gmx.de>][Date Fri, 05 Aug 2005 18:12:33 +0200]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 J ... /[From "Martin Pfeiffer" <mail@Martin-Pfeiffer.de>][Date Tue, 2 Aug 2005 12:33:34 +0200]/text Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text/[From "Weber, Volker, B" <weber@ovag.de>][Date Mon, 6 Jun 2005 15:11:07 +0200]/text Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text/[From "GMX Spamschutz" <mailings@gmx.net>][Date Sun, 05 Jun 2005 11:13:03 +0000]/text Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED/[From r.k.betriebsmanagment@freenet.de][Date Fri, 3 Jun 2005 15:29:12 +0200]/text Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text/[From GMX Best Price <mailings@gmx.net>][Date Thu, 02 Jun 2005 10:33:12 GMT]/UNNAMED Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash/[From "GMX Spamschutz" <mailings@gmx.net>][Date Thu, 02 Jun 2005 14:29:38 +0000]/text Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Anwendungsdaten\Thunderbird\Profiles\02w47hit.default\Mail\Local Folders\Trash Infected: Email-Worm.Win32.Bagle.bo
C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\1F5.tmp Infected: not-virus:Hoax.Win32.SpyWare.a
C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\1F5.tmp.exe Infected: not-virus:Hoax.Win32.SpyWare.a

Willyviper 03.01.2006 16:37

C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\1F6.tmp Infected: Trojan.Win32.Small.ga
C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\1F6.tmp.exe Infected: Trojan.Win32.Small.ga
C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\1F8.tmp Infected: not-virus:Hoax.Win32.SpyWare.a
C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\1FC.tmp Infected: not-virus:Hoax.Win32.SpyWare.a
C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\203.tmp Infected: not-virus:Hoax.Win32.SpyWare.a
C:\Programme\AVPersonal\INFECTED\1FD.tmp.VIR Infected: Trojan.Win32.Small.ga
C:\Programme\AVPersonal\INFECTED\1FD.tmp.VIR00 Infected: Trojan.Win32.Small.ga
C:\Programme\AVPersonal\INFECTED\JAVAJV.EXE.VIR Infected: Trojan-Downloader.Win32.Agent.td
C:\Programme\AVPersonal\INFECTED\NETTI32.EXE.VIR Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP110\A0016203.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP110\A0016221.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016248.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016256.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016256.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016256.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016261.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.tdC:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016261.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016261.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016280.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016280.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0016280.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0032393.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0032393.pif:ijoyz:$DATA Infected:
Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP111\A0032393.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032524.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032524.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032524.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032533.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032533.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032533.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032537.ini:reuhkk:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032615.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032615.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP112\A0032615.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP113\A0032623.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032624.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032778.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032786.INI:sqiatj:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032787.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032787.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032787.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP114\A0032800.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP115\A0032804.INI:sqiatj:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP115\A0032805.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP115\A0032805.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP115\A0032805.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP115\A0032839.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP115\A0032846.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032864.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032872.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032882.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032886.INI:sqiatj:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032887.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032887.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\System Volume Information\_restore{6B916A41-8485-4A6A-BC69-669605E696B1}\RP116\A0032887.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\addln.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\atlkx32.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\Blaue Spitzen 16.bmp:mmkwxa:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\clock.avi:emccrc:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\clock.avi:tczzza:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\control.ini:vttvsy:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\FaxSetup.log:xvxnol:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\iene.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\ipyn.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\KB887742.log:encjhr:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\KB890046.log:wnuwbb:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\KB904706.log:hjsojr:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\mfcir32.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\mozver.dat:zdbtih:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\msdn32.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\mstf32.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\msuz.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\msyk.exe Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\netcb32.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\ntcd32.exe Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\ntme32.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\orun32.isu:ttyyk:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\sdkrq.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\sdksi.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\sessmgr.setup.log:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\setupact.log:ruagh:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\system32\apilf.exe Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\system32\appno.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\system32\atljh32.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\system32\crua32.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\system32\d3ev32.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\system32\javaeb.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\system32\javaoo.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\system32\mfcyc.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\system32\netsq.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\system32\ntbh.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\system32\ntzq32.dll Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\system32\systh.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\system32\sysxb.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\system32\wincs.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\WINCMD.INI:sqiatj:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\winjx32.exe Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\_default.pif:hjsojr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\WINDOWS\_default.pif:ijoyz:$DATA Infected: Trojan-Downloader.Win32.Agent.bc
C:\WINDOWS\_default.pif:pihjhh:$DATA Infected: Trojan.Win32.Agent.bi

Scan process completed.

hoerni26 03.01.2006 19:56

hallo,

alsonach dem logfile vom onlinescan kommt nur noch das neuaufsetzen in frage..
anleitung dazu im link meiner signatur..

Willyviper 03.01.2006 21:26

O.K. Danke, dachte ich käme irgendwie um die Arbeit rum.

Schöne Grüße
Christian

cosinus 04.01.2006 00:37

Die Arbeit bzw. Zeit ersparst Du Dir mit regelmäßigen Backups, z. B. Acronis True Image. Kannste direkt nachdem Neuaufsetzen ein Image Deines Systems auf externe Datenträger ziehen und bei Bedarf wieder einspielen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 05:13 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131