![]() |
bitte helft mir!!! Hatte gedacht ich würde selbst damit fertig :(( Windows Adtools bekomme ich nicht weg vom Rechner (win2000) Logfile of HijackThis v1.99.1 Scan saved at 19:33:48, on 20.02.2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\Programme\Sophos\Sophos Anti-Virus\SavService.exe C:\WINNT\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINNT\System32\svchost.exe C:\WINNT\system32\regsvc.exe C:\Programme\Sophos\Sophos Anti-Virus\SAVAdminService.exe C:\WINNT\system32\MSTask.exe C:\Programme\Sophos\AutoUpdate\ALsvc.exe C:\WINNT\system32\stisvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Programme\Trojancheck 6\tcguard.exe C:\Programme\Sophos\AutoUpdate\ALMon.exe C:\Programme\Spybot - Search & Destroy\SpybotSD.exe C:\Dokumente und Einstellungen\name\Desktop\Neuer Ordner\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer bereitgestellt von T-Online International AG R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=www-proxy.t-online.de:80;ftp=ftp-proxy.t-online.de:80 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.t-online.de;localhost;<local> O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {AF53A477-97B1-A265-0790-EF2611BC95C3} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [Trojancheck 6 Guard] C:\Programme\Trojancheck 6\tcguard.exe O4 - Global Startup: AutoUpdate Monitor.lnk = C:\Programme\Sophos\AutoUpdate\ALMon.exe O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm O15 - Trusted Zone: *.05p.com (HKLM) O15 - Trusted Zone: *.awmdabest.com (HKLM) O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM) O15 - Trusted Zone: *.scoobidoo.com (HKLM) O15 - Trusted Zone: *.static.topconverting.com (HKLM) O15 - Trusted IP range: 206.161.125.149 O15 - Trusted IP range: 206.161.125.149 (HKLM) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {505098FD-5D61-4BC2-9B82-F969D0E932A2} - http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1034_EN.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140177548180 O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildApp.cab O18 - Protocol: haufereader - {39198710-62F7-42CD-9458-069843FA5D32} - C:\Programme\Haufe\HaufeReader\HRInstmon.dll O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: Verwaltungsdienst für die Verwaltung logischer Datenträger (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: Sophos Anti-Virus Statusreporter (SAVAdminService) - Sophos plc - C:\Programme\Sophos\Sophos Anti-Virus\SAVAdminService.exe O23 - Service: Sophos Anti-Virus (SAVService) - Sophos plc - C:\Programme\Sophos\Sophos Anti-Virus\SavService.exe O23 - Service: Sophos AutoUpdate Service - Sophos plc - C:\Programme\Sophos\AutoUpdate\ALsvc.exe O23 - Service: Remote Procedure Call (RPC) Helper (%AF夶À¨) - Unknown owner - C:\WINNT\system32\ntem.exe (file missing) |
Hallo sympatie, lade Dir clearprog 1.4.1 final und nimm eine Datenträgerbereinigung vor (Programm starten Häkchen bei "Alles Löschen" und auf "Löschen" klicken). Lösche ebenfalls den Quaratäne-Ordner Deines Antivir-Programmes. Scanne dann Dein System mit Escan . Bitte erst aufmerkam lesen und dann scannen. Teile das Ergebnis mittels der "find.bat" mit. dartus |
Hallo, hoffe ich mach alles richtig find.bat Prog hab ich nicht gefunden, den Rest laut deiner beschreibung schon. Jedoch hat sich das Programm Escan ein wenihg geändert. Hoffe weiter das ich diese Ka** Mailware entliuch entfernt bekommen. Achso, im abgesicherten Modus finden er manchmal nichts, manchmal doch was. Das Ergebnis unten ist nicht im abgesicherten Modus geschossen worde, sind aber meiner Meinung ide gleichen Einträge Tue Feb 21 19:27:17 2006 => ***** Scanning Registry and File system for Adware/Spyware ***** Tue Feb 21 19:27:17 2006 => Loading Spyware Signatures from new External Database (Size: 152537). Tue Feb 21 19:27:17 2006 => Indexed Spyware Databases Successfully Created... Tue Feb 21 19:27:18 2006 => System found infected with searchexe Spyware/Adware ({807553e5-5146-11d5-a672-00b0d022e945})! Action taken: No Action Taken. Tue Feb 21 19:27:18 2006 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Tue Feb 21 19:27:18 2006 => System found infected with overpro Spyware/Adware ({ff65677a-8977-48ca-916a-dff81b037df3})! Action taken: No Action Taken. Tue Feb 21 19:27:23 2006 => Offending file found: C:\WINNT\wildapp.dll Tue Feb 21 19:27:23 2006 => System found infected with overpro Spyware/Adware (wildapp.dll)! Action taken: No Action Taken. Tue Feb 21 19:27:24 2006 => Offending file found: C:\WINNT\system32\ide21201.vxd Tue Feb 21 19:27:24 2006 => System found infected with windupdate Spyware/Adware (ide21201.vxd)! Action taken: No Action Taken. Tue Feb 21 19:27:36 2006 => ***** Scanning Registry for errors created because of Adware/Spyware ***** Tue Feb 21 19:27:38 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".04-05doc". Action Taken: No Action Taken. Tue Feb 21 19:27:38 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".dat". Action Taken: No Action Taken. Tue Feb 21 19:27:38 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".de/". Action Taken: No Action Taken. Tue Feb 21 19:27:38 2006 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".rlg". Action Taken: No Action Taken. Tue Feb 21 19:27:38 2006 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "{09C6BF52-6DBA-4A97-9939-B6C24E4738BF}". Action Taken: No Action Taken. Tue Feb 21 19:27:39 2006 => Entry "HKCR\CLSID\{0192FBE7-B61C-11D4-A9A9-0000C0BEBBDB}" refers to invalid object "C:\PROGRA~1\T-Online\T-ONLI~1\Banking\KONTOS~1.OCX". Action Taken: No Action Taken. Tue Feb 21 19:27:39 2006 => Entry "HKCR\CLSID\{06562BDD-CEF9-11D6-9531-00E02932CC2E}" refers to invalid object "C:\PROGRA~1\T-Online\T-ONLI~1\Banking\UMSATZ~1.OCX". Action Taken: No Action Taken. Tue Feb 21 19:27:39 2006 => Entry "HKCR\CLSID\{0685146D-9DF9-11D5-8F7D-C884722A3053}" refers to invalid object "C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\update_abocfg.dll". Action Taken: No Action Taken. Tue Feb 21 19:27:39 2006 => Entry "HKCR\CLSID\{0685146F-9DF9-11D5-8F7D-C884722A3053}" refers to invalid object "C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\update_abocfg.dll". Action Taken: No Action Taken. Tue Feb 21 19:27:39 2006 => Entry "HKCR\CLSID\{06851471-9DF9-11D5-8F7D-C884722A3053}" refers to invalid object "C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\update_abocfg.dll". Action Taken: No Action Taken. Tue Feb 21 19:27:39 2006 => Entry "HKCR\CLSID\{077102C7-F5CB-11D4-B529-00E0292C0C45}" refers to invalid object "C:\PROGRA~1\T-Online\T-ONLI~1\Banking\GELDKA~1.OCX". Action Taken: No Action Taken. Tue Feb 21 19:27:44 2006 => Entry "HKCR\TypeLib\{C087957C-1EF6-11D6-830A-00E029442B7A}" refers to invalid object "C:\Programme\T-Online\T-Online_Software_5\eMail\Bin\funMailMigrator.dll". Action Taken: No Action Taken. Tue Feb 21 19:27:44 2006 => Entry "HKCR\TypeLib\{CC8C2C86-CF01-11D6-9531-00E02932CC2E}" refers to invalid object "C:\Programme\T-Online\T-Online_Software_5\Banking\MitteilungAddin.ocx". Action Taken: No Action Taken. Tue Feb 21 19:27:44 2006 => Entry "HKCR\TypeLib\{D2843F42-C44C-4210-8067-6AF463A7A89D}" refers to invalid object "C:\DOKUME~1\Rolf\LOKALE~1\Temp\VBE\MSForms.exd". Action Taken: No Action Taken. Tue Feb 21 19:27:44 2006 => Entry "HKCR\TypeLib\{D5772E76-CEFD-11D6-9531-00E02932CC2E}" refers to invalid object "C:\Programme\T-Online\T-Online_Software_5\Banking\AuswertungAddin.ocx". Action Taken: No Action Taken. Tue Feb 21 19:27:44 2006 => Entry "HKCR\TypeLib\{E74C068A-F7E2-4916-A150-0EB49ED8059F}" refers to invalid object "C:\Programme\T-DSL SpeedManager\tsm.dll". Action Taken: No Action Taken. Tue Feb 21 19:27:44 2006 => Entry "HKCR\TypeLib\{F5179D9A-CEFF-11D6-9531-00E02932CC2E}" refers to invalid object "C:\Programme\T-Online\T-Online_Software_5\Banking\SicherungAddin.ocx". Action Taken: No Action Taken. Tue Feb 21 19:27:44 2006 => Entry "HKCR\.pcb" refers to invalid object "PCBFile". Action Taken: No Action Taken. Tue Feb 21 19:27:48 2006 => ***** Scanning complete. ***** Tue Feb 21 19:27:48 2006 => Total Objects Scanned: 20035 Tue Feb 21 19:27:48 2006 => Total Virus(es) Found: 5 Tue Feb 21 19:27:48 2006 => Total Disinfected Files: 0 Tue Feb 21 19:27:48 2006 => Total Files Renamed: 0 Tue Feb 21 19:27:48 2006 => Total Deleted Objects: 0 Tue Feb 21 19:27:48 2006 => Total Errors: 117 Tue Feb 21 19:27:48 2006 => Time Elapsed: 00:01:15 Tue Feb 21 19:27:48 2006 => Virus Database Date: 2006/02/21 Tue Feb 21 19:27:48 2006 => Virus Database Count: 169754 Tue Feb 21 19:27:48 2006 => Scan Completed. Tue Feb 21 19:27:49 2006 => AV Library Unloaded (3)... |
Hab da mal Ordnung reingebracht... ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Infektionsmeldungen ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue Feb 21 19:27:18 2006 => System found infected with searchexe Spyware/Adware ({807553e5-5146-11d5-a672-00b0d022e945})! Action taken: No Action Taken. Tue Feb 21 19:27:18 2006 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Tue Feb 21 19:27:18 2006 => System found infected with overpro Spyware/Adware ({ff65677a-8977-48ca-916a-dff81b037df3})! Action taken: No Action Taken. Tue Feb 21 19:27:23 2006 => System found infected with overpro Spyware/Adware (wildapp.dll)! Action taken: No Action Taken. Tue Feb 21 19:27:24 2006 => System found infected with windupdate Spyware/Adware (ide21201.vxd)! Action taken: No Action Taken. ~~~~~~~~~~~ Dateien ~~~~~~~~~~~ ~~~~ Infected files ~~~~~~~~~~~ ~~~~~~~~~~~ ~~~~ Offending files ~~~~~~~~~~~ Tue Feb 21 19:27:23 2006 => Offending file found: C:\WINNT\wildapp.dll Tue Feb 21 19:27:24 2006 => Offending file found: C:\WINNT\system32\ide21201.vxd ~~~~~~~~~~~ ~~~~ Tagged files ~~~~~~~~~~~ ~~~~~~~~~~~ Ordner ~~~~~~~~~~~ ~~~~~~~~~~~ Registry ~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue Feb 21 19:27:48 2006 => Total Virus(es) Found: 5 Tue Feb 21 19:27:48 2006 => Total Errors: 117 Tue Feb 21 19:27:48 2006 => Time Elapsed: 00:01:15 Tue Feb 21 19:27:48 2006 => Total Objects Scanned: 20035 Tue Feb 21 19:27:48 2006 => Virus Database Date: 2006/02/21 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~ © Haui ;-) ~~~~~~~ ~~~~~~~ Dank an Cidre ~~~~~~~ |
wie gehts weiter ? |
Zitat:
|
@HAZE richtig schon gescannt, hatte nur das falsche Prog downgeloadet!! Ich schrieb : Jedoch hat sich das Programm Escan ein wenihg geändert. Ich hatte Escan gezogen, man muss die Liste bis ganz unten scrollen und dort taucht erst das Program auf. Nun, dann werde ich mal es nochmal versuchen..... bis später |
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Wed Feb 22 18:47:25 2006 => System found infected with searchexe Spyware/Adware ({807553e5-5146-11d5-a672-00b0d022e945})! Action taken: No Action Taken. Wed Feb 22 18:47:25 2006 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Wed Feb 22 18:47:25 2006 => System found infected with overpro Spyware/Adware ({ff65677a-8977-48ca-916a-dff81b037df3})! Action taken: No Action Taken. Wed Feb 22 18:47:27 2006 => System found infected with overpro Spyware/Adware (wildapp.dll)! Action taken: No Action Taken. Wed Feb 22 18:47:28 2006 => System found infected with windupdate Spyware/Adware (ide21201.vxd)! Action taken: No Action Taken. Wed Feb 22 19:01:17 2006 => File C:\info6.cab infected by "Trojan.Win32.Dialer.t" Virus! Action Taken: No Action Taken. Wed Feb 22 19:41:05 2006 => Total Disinfected Objects: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Wed Feb 22 18:48:07 2006 => File C:\WINNT\WildApp.dll tagged as "not-a-virus:AdWare.Win32.MediaTickets.c". Action Taken: No Action Taken. Wed Feb 22 19:01:58 2006 => File C:\Program Files\Preview AdService\PrevAdComm.dll tagged as "not-a-virus:AdWare.Win32.WinAD.ab". Action Taken: No Action Taken. Wed Feb 22 19:25:18 2006 => File C:\WINNT\Downloaded Program Files\HDPlugin1101.dll tagged as "not-a-virus:AdWare.Win32.Gator.1101". Action Taken: No Action Taken. Wed Feb 22 19:40:43 2006 => File C:\WINNT\WildApp.dll tagged as "not-a-virus:AdWare.Win32.MediaTickets.c". Action Taken: No Action Taken. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "offending" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Wed Feb 22 18:47:27 2006 => Offending file found: C:\WINNT\wildapp.dll Wed Feb 22 18:47:28 2006 => Offending file found: C:\WINNT\system32\ide21201.vxd ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Wed Feb 22 19:41:05 2006 => Total Objects Scanned: 32011 Wed Feb 22 19:41:05 2006 => Total Critical Objects: 10 Wed Feb 22 19:41:05 2006 => Total Disinfected Objects: 0 Wed Feb 22 19:41:05 2006 => Total Deleted Objects: 0 Wed Feb 22 19:41:05 2006 => Total Errors: 379 Wed Feb 22 19:41:05 2006 => Time Elapsed: 01:01:56 Wed Feb 22 19:41:05 2006 => Virus Database Date: 2/16/2006 Wed Feb 22 20:04:23 2006 => Virus Database Date: 2/16/2006 |
Lade RegSeeker Sichern vor Löschen anhaken und nur die grünen Funde entfernen! Gehe in die Systemsteuerung->Software und entferne Dir unbekannte Programme. Lade und update Ad-aware sowie Spybot S&D und lasse die Programme laufen. Mit Spybot immunisieren http://www.comsafe.de/download.html http://www.ewido.net/de/download/ Lasse Ewido das System scannen und bereinigen. Poste das Ergebnis des Scans mit ewido. Neues HJT-Logfile. |
@felix1 versteh ich nicht! Hab System gescannt, weiß wo die Trojaner sitzen. Sind allso noch da, was soll ich bitte schön noch mal scannen mit Regseeker? Ich würde mich um eine Anleitung freuen, wie ich diese Dateien löschen kann, oder stapfe ich einfach nur in die Ordner und lösche die wildapp ide21201.vxd info6.cab? |
Hab jetzt Ewito alles entfernen lassen, ermeldet auch keinen Trojaner mehr, selbst bei Neustart. Läßt man aber HJT wieder im abgesicherten Modus laufen, bleibt das gleiche Ergebnis.. Kann ich abgesicherten Modus aus der reg die Einträge einfach löschen? |
Dann poste doch mal ein HJT-Log im Normalmodus. |
Logfile of HijackThis v1.99.1 Scan saved at 20:04:09, on 23.02.2006 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\WINNT\System32\cisvc.exe C:\WINNT\System32\svchost.exe C:\Programme\ewido anti-malware\ewidoctrl.exe C:\Programme\ewido anti-malware\ewidoguard.exe C:\PROGRA~1\GEMEIN~1\MICROW~1\Agent\MWASER.EXE C:\PROGRA~1\GEMEIN~1\MICROW~1\Agent\MWAgent.exe C:\WINNT\system32\regsvc.exe C:\WINNT\System32\locator.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\stisvc.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\svchost.exe C:\WINNT\Explorer.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Programme\Trojancheck 6\tcguard.exe C:\WINNT\system32\wuauclt.exe C:\WINNT\System32\cidaemon.exe C:\Programme\Internet Explorer\IEXPLORE.EXE C:\Dokumente und Einstellungen\name\Desktop\Neuer Ordner\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer bereitgestellt von T-Online International AG R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=www-proxy.t-online.de:80;ftp=ftp-proxy.t-online.de:80 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.t-online.de;localhost;<local> O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: (no name) - {AF53A477-97B1-A265-0790-EF2611BC95C3} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [Trojancheck 6 Guard] C:\Programme\Trojancheck 6\tcguard.exe O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM) O15 - Trusted Zone: *.static.topconverting.com (HKLM) O15 - Trusted IP range: 206.161.125.149 O15 - Trusted IP range: 206.161.125.149 (HKLM) O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=48835 O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab O16 - DPF: {505098FD-5D61-4BC2-9B82-F969D0E932A2} - http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1034_EN.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1140177548180 O16 - DPF: {FF65677A-8977-48CA-916A-DFF81B037DF3} - http://download.overpro.com/WildApp.cab O18 - Protocol: haufereader - {39198710-62F7-42CD-9458-069843FA5D32} - C:\Programme\Haufe\HaufeReader\HRInstmon.dll O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: Verwaltungsdienst für die Verwaltung logischer Datenträger (dmadmin) - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: ewido security suite control - ewido networks - C:\Programme\ewido anti-malware\ewidoctrl.exe O23 - Service: ewido security suite guard - ewido networks - C:\Programme\ewido anti-malware\ewidoguard.exe O23 - Service: MWAgent - MicroWorld Technologies Inc. - C:\PROGRA~1\GEMEIN~1\MICROW~1\Agent\MWASER.EXE |
Du hast meine Anleitung nicht richtig gelesen. Ich finde keine Hinweise dafür, dass Spybot und Ad-adaware ausgeführt wurden. Fixe mit HJT im abgesicherten Modus (siehe meine Signatur): O15 - Trusted Zone: *.frame.crazywinnings.com (HKLM) O15 - Trusted Zone: *.static.topconverting.com (HKLM) O15 - Trusted IP range: 206.161.125.149 O15 - Trusted IP range: 206.161.125.149 (HKLM) O16 - DPF: {505098FD-5D61-4BC2-9B82-F969D0E932A2} - http://akamai.downloadv3.com/binaries/P2EClient/EGAUTH_1034_EN.cab O2 - BHO: (no name) - {AF53A477-97B1-A265-0790-EF2611BC95C3} Führe S&D sowie ad-adaware aus, wie ich es geschrieben habe. Weiterhin Regseeker ausführen. Für Anleitungen zur Funktion und Bedienung des Programmes schaue hier nach: Viele Anleitungen und Hinweise Anschliessend Start im Normalmodus und neues HJT-Log. |
Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Wed Feb 22 18:47:25 2006 => System found infected with searchexe Spyware/Adware ({807553e5-5146-11d5-a672-00b0d022e945})! Action taken: No Action Taken. Wed Feb 22 18:47:25 2006 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Wed Feb 22 18:47:25 2006 => System found infected with overpro Spyware/Adware ({ff65677a-8977-48ca-916a-dff81b037df3})! Action taken: No Action Taken. Wed Feb 22 18:47:27 2006 => System found infected with overpro Spyware/Adware (wildapp.dll)! Action taken: No Action Taken. Wed Feb 22 18:47:28 2006 => System found infected with windupdate Spyware/Adware (ide21201.vxd)! Action taken: No Action Taken. Wed Feb 22 19:01:17 2006 => File C:\info6.cab infected by "Trojan.Win32.Dialer.t" Virus! Action Taken: No Action Taken. Wed Feb 22 19:41:05 2006 => Total Disinfected Objects: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Wed Feb 22 18:48:07 2006 => File C:\WINNT\WildApp.dll tagged as "not-a-virus:AdWare.Win32.MediaTickets.c". Action Taken: No Action Taken. Wed Feb 22 19:01:58 2006 => File C:\Program Files\Preview AdService\PrevAdComm.dll tagged as "not-a-virus:AdWare.Win32.WinAD.ab". Action Taken: No Action Taken. Wed Feb 22 19:25:18 2006 => File C:\WINNT\Downloaded Program Files\HDPlugin1101.dll tagged as "not-a-virus:AdWare.Win32.Gator.1101". Action Taken: No Action Taken. Wed Feb 22 19:40:43 2006 => File C:\WINNT\WildApp.dll tagged as "not-a-virus:AdWare.Win32.MediaTickets.c". Action Taken: No Action Taken. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "offending" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Wed Feb 22 18:47:27 2006 => Offending file found: C:\WINNT\wildapp.dll Wed Feb 22 18:47:28 2006 => Offending file found: C:\WINNT\system32\ide21201.vxd ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Wed Feb 22 19:41:05 2006 => Total Objects Scanned: 32011 Wed Feb 22 19:41:05 2006 => Total Critical Objects: 10 Wed Feb 22 19:41:05 2006 => Total Disinfected Objects: 0 Wed Feb 22 19:41:05 2006 => Total Deleted Objects: 0 Wed Feb 22 19:41:05 2006 => Total Errors: 379 Wed Feb 22 19:41:05 2006 => Time Elapsed: 01:01:56 Wed Feb 22 19:41:05 2006 => Virus Database Date: 2/16/2006 Wed Feb 22 20:04:23 2006 => Virus Database Date: 2/16/2006 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~ © Haui ;-) ~~~~~~~ ~~~~~~~ Dank an Cidre ~~~~~~~ |
Alle Zeitangaben in WEZ +1. Es ist jetzt 00:05 Uhr. |
Copyright ©2000-2025, Trojaner-Board