Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Mailde.de sagt virus o.O (https://www.trojaner-board.de/56847-mailde-de-sagt-virus-o-o.html)

jurabe 27.07.2008 21:59

Mailde.de sagt virus o.O
 
Hallo
Ich wollte gerade meinen mailde account auf neue emails überprüfen und habe einen leichten schock bekommen *g*
Da melde ich mich an und es kommt die meldung :

Hinweis! Die von Ihnen genutzte IP-Adresse (//) ist kontaminiert. Sie wurde kürzlich wahrscheinlich von Spammern oder für illegale Aktivitäten missbraucht.

Falls diese Meldung häufiger erscheint prüfen Sie bitte gründlich, ob der Virenschutz Ihres Systems aktuell ist. In manchen Fällen werden die Systeme unserer Nutzer durch Spionageprogramme ferngesteuert und dienen ohne Wissen der Nutzer selbst als Spamversender oder als Zielsystem für Phishing-Versuche!

Ihre IP-Adresse (//) wird wahrscheinlich zum massenweisen Versenden von unerwünschten Werbemails (Spam-Mails) missbraucht! Bitte prüfen Sie, ob Ihr Virenschutz aktuell ist. Möglicherweise wird Ihr System durch Spionagesoftware ferngesteuert und ihr System wäre eine Spam-Quelle!

Nähere Informationen über Ihre IP-Adresse finden Sie hier.

Werbung: Kaspersky Anti-Virus 2009 kostenlos testen

» Weiter
Habe meine ip mal durch // ersetzt weiß nicht ob das sinnvoll ist hoffe mal schon :D

Ist diese "warnung " dort oben ernstgemeint ?
Wenn ja bitte ich dringen um hilfe
mfg Jurabe

cosinus 28.07.2008 08:50

Dein Rechner kann infiziert sein, oder auch nicht.
Solche Meldungen halte ich eher für nutzlos. Ich habeden Eindruck, die wollen damit eher unerfahrene Nutzer zum Kauf von Sicherheitssoftware bewegen, siehst ja gleich die Werbung eines bekannten russischen Virenscanners bei der Warnung. :D

Und selbst wenn "Deine" IP-Adresse verstärkte Spamaktivitäten hatte, muß es nicht Dein PC gewesen sein. Dein Provider vergibt Dir idR die Adressen dynamisch, d.h. Du hast nach jedem Einwählen ins Internet nach einer Trennung wohl wieder eine neue IP-Adresse. Diese konnte vorher ein anderer Internet-Teilnehmer bekommen haben. Und der hatte vllt einen versifften PC.

Deinen PC sollte man trotzdem mal untersuchen. Folge dem DSS-Link in meiner Signatur und poste die Logfiles.

jurabe 28.07.2008 12:00

Also
hab mir das prog runtergeladen und den scan durchgefürht
allerdings ist danach mein internet vokommen abgeschmiert , hatte einen ping von 1800.
Wieder deinstaliert und internet funktioniert wieder .
Villt ein anderes prog mit dem ich die logs posten könnte ?

cosinus 28.07.2008 12:02

Hast Du Dir das richtige Tool (DSS - Deckards System Scanner) besorgt?
Wenn es das war und Du den Durchlauf gemacht hast, hast Du zwei Logfiles bekommen. Und an sich muß DSS nicht installiert werden... :rolleyes:

jurabe 28.07.2008 12:06

wtf
ich hab auf die werbung geklickt :koch:
30- tägige testversion :headbang:

jurabe 28.07.2008 12:08

hab dad jetzt und lass es mal laufen
bg

jurabe 28.07.2008 12:17

also
kurz bevor der durchgelaufen is schmiert er ab und will nen prob bericht an microsoft senden
hat noch ein prog namens hijack this geladen

cosinus 28.07.2008 12:22

Tja... :rolleyes:
Dann poste bitte nicht nur das Logfile von hijackthis, sondern auch eins von silentrunners (siehe Signatur).
Logfile bitte mit Codetags umschlossen posten!!

jurabe 28.07.2008 12:25

"Silent Runners.vbs", revision 58, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"MSMSGS" = ""K:\Programme\Messenger\msmsgs.exe" /background" [MS]
"Veoh" = ""K:\Programme\Veoh Networks\Veoh\VeohClient.exe" /VeohHide" ["Veoh Networks"]
"(Default)" = "(empty string)" [file not found]
"Eraser" = "K:\Programme\Eraser\eraser.exe -hide" ["The Eraser Project"]
"Skype" = ""K:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized" ["Skype Technologies S.A."]
"msnmsgr" = ""K:\Programme\Windows Live\Messenger\msnmsgr.exe" /background" [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ZoneAlarm Client" = ""K:\Programme\Zone Labs\ZoneAlarm\zlclient.exe"" ["Zone Labs, LLC"]
"AVMWlanClient" = "K:\Programme\avmwlanstick\wlangui.exe" ["AVM Berlin"]
"BootSkin Startup Jobs" = ""K:\Programme\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs" [empty string]
"Ashampoo FireWall" = ""K:\Programme\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY" [null data]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{00C6482D-C502-44C8-8409-FCE54AD9C208}\(Default) = (no title provided)
-> {HKLM...CLSID} = "SnagIt Toolbar Loader"
\InProcServer32\(Default) = "K:\Programme\TechSmith\SnagIt 8\SnagItBHO.dll" [file not found]
{19C8E43B-07B3-49CB-BFFC-6777B593E6F8}\(Default) = (no title provided)
-> {HKLM...CLSID} = "Download Manager Browser Helper Object"
\InProcServer32\(Default) = "K:\PROGRA~1\GEMEIN~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL" ["Protect Software GmbH"]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "CPL-Erweiterung für Anzeigeverschiebung"
-> {HKLM...CLSID} = "CPL-Erweiterung für Anzeigeverschiebung"
\InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Erweiterung für HyperTerminal-Icons"
-> {HKLM...CLSID} = "HyperTerminal Icon Ext"
\InProcServer32\(Default) = "K:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
"{5E2121EE-0300-11D4-8D3B-444553540000}" = "Catalyst Context Menu extension"
-> {HKLM...CLSID} = "SimpleShlExt Class"
\InProcServer32\(Default) = "K:\Programme\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll" [null data]
"{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" = "Shell Extension for Malware scanning"
-> {HKLM...CLSID} = "Shell Extension for Malware scanning"
\InProcServer32\(Default) = "K:\Programme\Avira\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"]
"{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
-> {HKLM...CLSID} = "Meine freigegebenen Ordner"
\InProcServer32\(Default) = "K:\Programme\Windows Live\Messenger\fsshext.8.5.1302.1018.dll" [MS]
"{D9872D13-7651-4471-9EEE-F0A00218BEBB}" = "Multiscan"
-> {HKLM...CLSID} = "ZLAVShExt Class"
\InProcServer32\(Default) = "K:\Programme\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]
"{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}" = "SnagIt"
-> {HKLM...CLSID} = "SnagIt"
\InProcServer32\(Default) = "K:\Programme\TechSmith\SnagIt 8\SnagItIEAddin.dll" [file not found]
"{CF74B903-3389-469c-B3B6-0204D204FCBD}" = "SnagIt Shell Extension"
-> {HKLM...CLSID} = "SnagItShellExt Class"
\InProcServer32\(Default) = "K:\Programme\TechSmith\SnagIt 8\SnagItShellExt.dll" [file not found]
"{8BE13461-936F-11D1-A87D-444553540000}" = "Eraser Shell Extension"
-> {HKCU...CLSID} = "ErasextMenu"
\InProcServer32\(Default) = "K:\WINDOWS\system32\erasext.dll" ["-"]
-> {HKLM...CLSID} = "Eraser Shell Extension"
\InProcServer32\(Default) = "K:\WINDOWS\system32\erasext.dll" ["-"]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "K:\Programme\WinRAR\rarext.dll" [null data]
"{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" = "OpenOffice.org Column Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = ""K:\Programme\OpenOffice.org 2.4\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
"{087B3AE3-E237-4467-B8DB-5A38AB959AC9}" = "OpenOffice.org Infotip Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = ""K:\Programme\OpenOffice.org 2.4\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
"{63542C48-9552-494A-84F7-73AA6A7C99C1}" = "OpenOffice.org Property Sheet Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = ""K:\Programme\OpenOffice.org 2.4\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
"{3B092F0C-7696-40E3-A80F-68D74DA84210}" = "OpenOffice.org Thumbnail Viewer"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = ""K:\Programme\OpenOffice.org 2.4\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
"{C9CF278C-460E-4917-BC43-3F75E6E47D3D}" = "fluxDVD Shell Extension"
-> {HKLM...CLSID} = "fluxDVD Shell Information Extractor"
\InProcServer32\(Default) = "K:\PROGRA~1\GEMEIN~1\fluxDVD\Lib\XEB\XEBShell.dll" ["ACE GmbH"]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
-> {HKLM...CLSID} = "WPDShServiceObj Class"
\InProcServer32\(Default) = "K:\WINDOWS\system32\WPDShServiceObj.dll" [MS]

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = "OpenOffice.org Column Handler"
-> {HKLM...CLSID} = (no title provided)
\InProcServer32\(Default) = ""K:\Programme\OpenOffice.org 2.4\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]

HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
-> {HKLM...CLSID} = "Shell Extension for Malware scanning"
\InProcServer32\(Default) = "K:\Programme\Avira\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"]
SnagItMainShellExt\(Default) = "{CF74B903-3389-469c-B3B6-0204D204FCBD}"
-> {HKLM...CLSID} = "SnagItShellExt Class"
\InProcServer32\(Default) = "K:\Programme\TechSmith\SnagIt 8\SnagItShellExt.dll" [file not found]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
-> {HKLM...CLSID} = "WinRAR"
\InProcServer32\(Default) = "K:\Programme\WinRAR\rarext.dll" [null data]
ZLAVShExt\(Default) = "{D9872D13-7651-4471-9EEE-F0A00218BEBB}"
-> {HKLM...CLSID} = "ZLAVShExt Class"
\InProcServer32\(Default) = "K:\Programme\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]


Dad is dad was dabei rausgekommen is

jurabe 28.07.2008 12:26

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 13:26:15, on 28.07.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
K:\WINDOWS\System32\smss.exe
K:\WINDOWS\system32\winlogon.exe
K:\WINDOWS\system32\services.exe
K:\WINDOWS\system32\lsass.exe
K:\WINDOWS\system32\Ati2evxx.exe
K:\WINDOWS\system32\svchost.exe
K:\WINDOWS\System32\svchost.exe
K:\WINDOWS\system32\Ati2evxx.exe
K:\WINDOWS\system32\spoolsv.exe
K:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
K:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
K:\xampp\apache\bin\apache.exe
K:\Programme\avmwlanstick\WlanNetService.exe
K:\Programme\Videoload Manager\ContentManager.exe
K:\xampp\mysql\bin\mysqld-nt.exe
K:\xampp\apache\bin\apache.exe
K:\WINDOWS\Explorer.EXE
K:\Programme\avmwlanstick\wlangui.exe
K:\Programme\Messenger\msmsgs.exe
K:\WINDOWS\system32\wuauclt.exe
K:\Programme\Windows Live\Messenger\usnsvc.exe
K:\PROGRA~1\MOZILL~1\FIREFOX.EXE
K:\Programme\WinRAR\WinRAR.exe
K:\Programme\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - K:\Programme\TechSmith\SnagIt 8\SnagItBHO.dll (file missing)
O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - K:\PROGRA~1\GEMEIN~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - K:\Programme\TechSmith\SnagIt 8\SnagItIEAddin.dll (file missing)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - K:\Programme\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "K:\Programme\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVMWlanClient] K:\Programme\avmwlanstick\wlangui.exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "K:\Programme\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [Ashampoo FireWall] "K:\Programme\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY
O4 - HKCU\..\Run: [MSMSGS] "K:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Veoh] "K:\Programme\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Eraser] K:\Programme\Eraser\eraser.exe -hide
O4 - HKCU\..\Run: [Skype] "K:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "K:\Programme\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] K:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] K:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] K:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] K:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = K:\Programme\OpenOffice.org 2.4\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - K:\Programme\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - K:\Programme\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - K:\Programme\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - K:\Programme\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - K:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - K:\Programme\Messenger\msmsgs.exe
O9 - Extra button: Klicke hier um das Projekt xp-AntiSpy zu unterstützen - {0e921e80-267a-42aa-aee4-60b9a1222a44} - K:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU)
O9 - Extra 'Tools' menuitem: Unterstützung für xp-AntiSpy - {0e921e80-267a-42aa-aee4-60b9a1222a44} - K:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU)
O18 - Protocol: fluxhttp - {8E2D00A0-82C6-4821-90BC-07F290841BB6} - K:\Programme\Gemeinsame Dateien\fluxDVD\Lib\XEB\xebnavigation.ax
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - K:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Personal – Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - K:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - K:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apache2.2 - Apache Software Foundation - K:\xampp\apache\bin\apache.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - K:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - K:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVM WLAN Connection Service - AVM Berlin - K:\Programme\avmwlanstick\WlanNetService.exe
O23 - Service: CaCCProvSP - Unknown owner - K:\Programme\CA\CA Internet Security Suite\ccprovsp.exe (file missing)
O23 - Service: Content Management Service (ContentMgrService) - ACE GmbH - K:\Programme\Videoload Manager\ContentManager.exe
O23 - Service: mysql - Unknown owner - K:\xampp\mysql\bin\mysqld-nt.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - K:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 5391 bytes


Und dad von hick jas oda wie dad heißt

cosinus 28.07.2008 12:30

Bitte genauer die Anweisungen beachten! Ich schrieb doch Du solltest mit Codetags umschlossen posten!

jurabe 28.07.2008 13:13

was sind dad ? >code< oda wie ? :eek:

jurabe 28.07.2008 13:26

[code]-tagsLogfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:25:59, on 28.07.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
K:\WINDOWS\System32\smss.exe
K:\WINDOWS\system32\winlogon.exe
K:\WINDOWS\system32\services.exe
K:\WINDOWS\system32\lsass.exe
K:\WINDOWS\system32\Ati2evxx.exe
K:\WINDOWS\system32\svchost.exe
K:\WINDOWS\System32\svchost.exe
K:\WINDOWS\system32\Ati2evxx.exe
K:\WINDOWS\system32\spoolsv.exe
K:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
K:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
K:\xampp\apache\bin\apache.exe
K:\Programme\avmwlanstick\WlanNetService.exe
K:\Programme\Videoload Manager\ContentManager.exe
K:\xampp\mysql\bin\mysqld-nt.exe
K:\xampp\apache\bin\apache.exe
K:\WINDOWS\Explorer.EXE
K:\Programme\Messenger\msmsgs.exe
K:\WINDOWS\system32\wuauclt.exe
K:\Programme\Windows Live\Messenger\usnsvc.exe
K:\PROGRA~1\MOZILL~1\FIREFOX.EXE
K:\Programme\ICQ6\ICQ.exe
K:\Programme\avmwlanstick\WLanGUI.exe
K:\WINDOWS\system32\wuauclt.exe
K:\Programme\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - K:\Programme\TechSmith\SnagIt 8\SnagItBHO.dll (file missing)
O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - K:\PROGRA~1\GEMEIN~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - K:\Programme\TechSmith\SnagIt 8\SnagItIEAddin.dll (file missing)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - K:\Programme\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "K:\Programme\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVMWlanClient] K:\Programme\avmwlanstick\wlangui.exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "K:\Programme\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [Ashampoo FireWall] "K:\Programme\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY
O4 - HKCU\..\Run: [MSMSGS] "K:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Veoh] "K:\Programme\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Eraser] K:\Programme\Eraser\eraser.exe -hide
O4 - HKCU\..\Run: [Skype] "K:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "K:\Programme\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] K:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] K:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] K:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] K:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = K:\Programme\OpenOffice.org 2.4\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - K:\Programme\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - K:\Programme\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - K:\Programme\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - K:\Programme\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - K:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - K:\Programme\Messenger\msmsgs.exe
O9 - Extra button: Klicke hier um das Projekt xp-AntiSpy zu unterstützen - {0e921e80-267a-42aa-aee4-60b9a1222a44} - K:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU)
O9 - Extra 'Tools' menuitem: Unterstützung für xp-AntiSpy - {0e921e80-267a-42aa-aee4-60b9a1222a44} - K:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU)
O18 - Protocol: fluxhttp - {8E2D00A0-82C6-4821-90BC-07F290841BB6} - K:\Programme\Gemeinsame Dateien\fluxDVD\Lib\XEB\xebnavigation.ax
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - K:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Personal – Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - K:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - K:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apache2.2 - Apache Software Foundation - K:\xampp\apache\bin\apache.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - K:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - K:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVM WLAN Connection Service - AVM Berlin - K:\Programme\avmwlanstick\WlanNetService.exe
O23 - Service: CaCCProvSP - Unknown owner - K:\Programme\CA\CA Internet Security Suite\ccprovsp.exe (file missing)
O23 - Service: Content Management Service (ContentMgrService) - ACE GmbH - K:\Programme\Videoload Manager\ContentManager.exe
O23 - Service: mysql - Unknown owner - K:\xampp\mysql\bin\mysqld-nt.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - K:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 5419 bytes[code]-tags

jurabe 28.07.2008 13:27

so richtig ?

cosinus 28.07.2008 13:31

Hast Du meinen Beitrag nicht gelesen? Die Code-Tags kannst Du über den #-Button einfügen...

Da kommt nicht noch manuell so ein murks rein wie [code]-tags :D
Wer lesen kann ist klr im Vorteil. :blabla:

jurabe 28.07.2008 13:33

doch sicher hab ich dne gelesen
nur wenn ich dann # drücker passiert nichts sondern die raute bleibt einfach so da stehen xD deswegen hab ich ka was ich machen soll

Silent sharK 28.07.2008 13:36

HTML-Code:

[code]Text[/code]
Stell dich bitte nicht komplett dumm. :balla:

cosinus 28.07.2008 13:37

Hast Du überhaupt schonmal einen Text markiert? Man markiert den zu formatierenden Text und drückt dann den jew. Button oben. Erzähl mir nicht daß Dir das zu schwer ist... :rolleyes:

jurabe 28.07.2008 13:37

Code:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 14:25:59, on 28.07.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot mode: Normal

Running processes:
K:\WINDOWS\System32\smss.exe
K:\WINDOWS\system32\winlogon.exe
K:\WINDOWS\system32\services.exe
K:\WINDOWS\system32\lsass.exe
K:\WINDOWS\system32\Ati2evxx.exe
K:\WINDOWS\system32\svchost.exe
K:\WINDOWS\System32\svchost.exe
K:\WINDOWS\system32\Ati2evxx.exe
K:\WINDOWS\system32\spoolsv.exe
K:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
K:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
K:\xampp\apache\bin\apache.exe
K:\Programme\avmwlanstick\WlanNetService.exe
K:\Programme\Videoload Manager\ContentManager.exe
K:\xampp\mysql\bin\mysqld-nt.exe
K:\xampp\apache\bin\apache.exe
K:\WINDOWS\Explorer.EXE
K:\Programme\Messenger\msmsgs.exe
K:\WINDOWS\system32\wuauclt.exe
K:\Programme\Windows Live\Messenger\usnsvc.exe
K:\PROGRA~1\MOZILL~1\FIREFOX.EXE
K:\Programme\ICQ6\ICQ.exe
K:\Programme\avmwlanstick\WLanGUI.exe
K:\WINDOWS\system32\wuauclt.exe
K:\Programme\Trend Micro\HijackThis\HijackThis.exe

O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - K:\Programme\TechSmith\SnagIt 8\SnagItBHO.dll (file missing)
O2 - BHO: Download Manager Browser Helper Object - {19C8E43B-07B3-49CB-BFFC-6777B593E6F8} - K:\PROGRA~1\GEMEIN~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - K:\Programme\TechSmith\SnagIt 8\SnagItIEAddin.dll (file missing)
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - K:\Programme\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [ZoneAlarm Client] "K:\Programme\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [AVMWlanClient] K:\Programme\avmwlanstick\wlangui.exe
O4 - HKLM\..\Run: [BootSkin Startup Jobs] "K:\Programme\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs
O4 - HKLM\..\Run: [Ashampoo FireWall] "K:\Programme\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY
O4 - HKCU\..\Run: [MSMSGS] "K:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Veoh] "K:\Programme\Veoh Networks\Veoh\VeohClient.exe" /VeohHide
O4 - HKCU\..\Run: [Eraser] K:\Programme\Eraser\eraser.exe -hide
O4 - HKCU\..\Run: [Skype] "K:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [msnmsgr] "K:\Programme\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] K:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] K:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] K:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] K:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 2.4.lnk = K:\Programme\OpenOffice.org 2.4\program\quickstart.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - K:\Programme\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - K:\Programme\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - K:\Programme\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - K:\Programme\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - K:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - K:\Programme\Messenger\msmsgs.exe
O9 - Extra button: Klicke hier um das Projekt xp-AntiSpy zu unterstützen - {0e921e80-267a-42aa-aee4-60b9a1222a44} - K:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU)
O9 - Extra 'Tools' menuitem: Unterstützung für xp-AntiSpy - {0e921e80-267a-42aa-aee4-60b9a1222a44} - K:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU)
O18 - Protocol: fluxhttp - {8E2D00A0-82C6-4821-90BC-07F290841BB6} - K:\Programme\Gemeinsame Dateien\fluxDVD\Lib\XEB\xebnavigation.ax
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - K:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O23 - Service: Avira AntiVir Personal – Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - K:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus Guard (AntiVirService) - Avira GmbH - K:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apache2.2 - Apache Software Foundation - K:\xampp\apache\bin\apache.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - K:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - K:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVM WLAN Connection Service - AVM Berlin - K:\Programme\avmwlanstick\WlanNetService.exe
O23 - Service: CaCCProvSP - Unknown owner - K:\Programme\CA\CA Internet Security Suite\ccprovsp.exe (file missing)
O23 - Service: Content Management Service (ContentMgrService) - ACE GmbH - K:\Programme\Videoload Manager\ContentManager.exe
O23 - Service: mysql - Unknown owner - K:\xampp\mysql\bin\mysqld-nt.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - K:\WINDOWS\system32\ZoneLabs\vsmon.exe

--
End of file - 5419 bytes


jurabe 28.07.2008 13:38

so dad war hijackthis und das was jetzt kommt is silent runners

jurabe 28.07.2008 13:40

Code:

"Silent Runners.vbs", revision 58, http://www.silentrunners.org/
Operating System: Windows XP SP2
Output limited to non-default values, except where indicated by "{++}"


Startup items buried in registry:
---------------------------------

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
"MSMSGS" = ""K:\Programme\Messenger\msmsgs.exe" /background" [MS]
"Veoh" = ""K:\Programme\Veoh Networks\Veoh\VeohClient.exe" /VeohHide" ["Veoh Networks"]
"(Default)" = "(empty string)" [file not found]
"Eraser" = "K:\Programme\Eraser\eraser.exe -hide" ["The Eraser Project"]
"Skype" = ""K:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized" ["Skype Technologies S.A."]
"msnmsgr" = ""K:\Programme\Windows Live\Messenger\msnmsgr.exe" /background" [MS]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"ZoneAlarm Client" = ""K:\Programme\Zone Labs\ZoneAlarm\zlclient.exe"" ["Zone Labs, LLC"]
"AVMWlanClient" = "K:\Programme\avmwlanstick\wlangui.exe" ["AVM Berlin"]
"BootSkin Startup Jobs" = ""K:\Programme\Stardock\WinCustomize\BootSkin\BootSkin.exe" /StartupJobs" [empty string]
"Ashampoo FireWall" = ""K:\Programme\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY" [null data]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{00C6482D-C502-44C8-8409-FCE54AD9C208}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "SnagIt Toolbar Loader"
                  \InProcServer32\(Default) = "K:\Programme\TechSmith\SnagIt 8\SnagItBHO.dll" [file not found]
{19C8E43B-07B3-49CB-BFFC-6777B593E6F8}\(Default) = (no title provided)
  -> {HKLM...CLSID} = "Download Manager Browser Helper Object"
                  \InProcServer32\(Default) = "K:\PROGRA~1\GEMEIN~1\fluxDVD\DOWNLO~1\XEBDLH~1.DLL" ["Protect Software GmbH"]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "CPL-Erweiterung für Anzeigeverschiebung"
  -> {HKLM...CLSID} = "CPL-Erweiterung für Anzeigeverschiebung"
                  \InProcServer32\(Default) = "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Erweiterung für HyperTerminal-Icons"
  -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
                  \InProcServer32\(Default) = "K:\WINDOWS\system32\hticons.dll" ["Hilgraeve, Inc."]
"{5E2121EE-0300-11D4-8D3B-444553540000}" = "Catalyst Context Menu extension"
  -> {HKLM...CLSID} = "SimpleShlExt Class"
                  \InProcServer32\(Default) = "K:\Programme\ATI Technologies\ATI.ACE\Core-Static\atiacmxx.dll" [null data]
"{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" = "Shell Extension for Malware scanning"
  -> {HKLM...CLSID} = "Shell Extension for Malware scanning"
                  \InProcServer32\(Default) = "K:\Programme\Avira\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"]
"{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D}" = "Messenger Sharing Folders"
  -> {HKLM...CLSID} = "Meine freigegebenen Ordner"
                  \InProcServer32\(Default) = "K:\Programme\Windows Live\Messenger\fsshext.8.5.1302.1018.dll" [MS]
"{D9872D13-7651-4471-9EEE-F0A00218BEBB}" = "Multiscan"
  -> {HKLM...CLSID} = "ZLAVShExt Class"
                  \InProcServer32\(Default) = "K:\Programme\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]
"{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}" = "SnagIt"
  -> {HKLM...CLSID} = "SnagIt"
                  \InProcServer32\(Default) = "K:\Programme\TechSmith\SnagIt 8\SnagItIEAddin.dll" [file not found]
"{CF74B903-3389-469c-B3B6-0204D204FCBD}" = "SnagIt Shell Extension"
  -> {HKLM...CLSID} = "SnagItShellExt Class"
                  \InProcServer32\(Default) = "K:\Programme\TechSmith\SnagIt 8\SnagItShellExt.dll" [file not found]
"{8BE13461-936F-11D1-A87D-444553540000}" = "Eraser Shell Extension"
  -> {HKCU...CLSID} = "ErasextMenu"
                  \InProcServer32\(Default) = "K:\WINDOWS\system32\erasext.dll" ["-"]
  -> {HKLM...CLSID} = "Eraser Shell Extension"
                  \InProcServer32\(Default) = "K:\WINDOWS\system32\erasext.dll" ["-"]
"{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
  -> {HKLM...CLSID} = "WinRAR"
                  \InProcServer32\(Default) = "K:\Programme\WinRAR\rarext.dll" [null data]
"{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}" = "OpenOffice.org Column Handler"
  -> {HKLM...CLSID} = (no title provided)
                  \InProcServer32\(Default) = ""K:\Programme\OpenOffice.org 2.4\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
"{087B3AE3-E237-4467-B8DB-5A38AB959AC9}" = "OpenOffice.org Infotip Handler"
  -> {HKLM...CLSID} = (no title provided)
                  \InProcServer32\(Default) = ""K:\Programme\OpenOffice.org 2.4\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
"{63542C48-9552-494A-84F7-73AA6A7C99C1}" = "OpenOffice.org Property Sheet Handler"
  -> {HKLM...CLSID} = (no title provided)
                  \InProcServer32\(Default) = ""K:\Programme\OpenOffice.org 2.4\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
"{3B092F0C-7696-40E3-A80F-68D74DA84210}" = "OpenOffice.org Thumbnail Viewer"
  -> {HKLM...CLSID} = (no title provided)
                  \InProcServer32\(Default) = ""K:\Programme\OpenOffice.org 2.4\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]
"{C9CF278C-460E-4917-BC43-3F75E6E47D3D}" = "fluxDVD Shell Extension"
  -> {HKLM...CLSID} = "fluxDVD Shell Information Extractor"
                  \InProcServer32\(Default) = "K:\PROGRA~1\GEMEIN~1\fluxDVD\Lib\XEB\XEBShell.dll" ["ACE GmbH"]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\
"WPDShServiceObj" = "{AAA288BA-9A4C-45B0-95D7-94D524869DB5}"
  -> {HKLM...CLSID} = "WPDShServiceObj Class"
                  \InProcServer32\(Default) = "K:\WINDOWS\system32\WPDShServiceObj.dll" [MS]

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
<<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]

HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
{C52AF81D-F7A0-4AAB-8E87-F80A60CCD396}\(Default) = "OpenOffice.org Column Handler"
  -> {HKLM...CLSID} = (no title provided)
                  \InProcServer32\(Default) = ""K:\Programme\OpenOffice.org 2.4\program\shlxthdl.dll"" ["Sun Microsystems, Inc."]

HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
  -> {HKLM...CLSID} = "Shell Extension for Malware scanning"
                  \InProcServer32\(Default) = "K:\Programme\Avira\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"]
SnagItMainShellExt\(Default) = "{CF74B903-3389-469c-B3B6-0204D204FCBD}"
  -> {HKLM...CLSID} = "SnagItShellExt Class"
                  \InProcServer32\(Default) = "K:\Programme\TechSmith\SnagIt 8\SnagItShellExt.dll" [file not found]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                  \InProcServer32\(Default) = "K:\Programme\WinRAR\rarext.dll" [null data]
ZLAVShExt\(Default) = "{D9872D13-7651-4471-9EEE-F0A00218BEBB}"
  -> {HKLM...CLSID} = "ZLAVShExt Class"
                  \InProcServer32\(Default) = "K:\Programme\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]

HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
SnagItMainShellExt\(Default) = "{CF74B903-3389-469c-B3B6-0204D204FCBD}"
  -> {HKLM...CLSID} = "SnagItShellExt Class"
                  \InProcServer32\(Default) = "K:\Programme\TechSmith\SnagIt 8\SnagItShellExt.dll" [file not found]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                  \InProcServer32\(Default) = "K:\Programme\WinRAR\rarext.dll" [null data]

HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
Erasext\(Default) = "{8BE13461-936F-11D1-A87D-444553540000}"
  -> {HKCU...CLSID} = "ErasextMenu"
                  \InProcServer32\(Default) = "K:\WINDOWS\system32\erasext.dll" ["-"]
  -> {HKLM...CLSID} = "Eraser Shell Extension"
                  \InProcServer32\(Default) = "K:\WINDOWS\system32\erasext.dll" ["-"]
Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
  -> {HKLM...CLSID} = "Shell Extension for Malware scanning"
                  \InProcServer32\(Default) = "K:\Programme\Avira\AntiVir PersonalEdition Classic\shlext.dll" ["Avira GmbH"]
WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
  -> {HKLM...CLSID} = "WinRAR"
                  \InProcServer32\(Default) = "K:\Programme\WinRAR\rarext.dll" [null data]
ZLAVShExt\(Default) = "{D9872D13-7651-4471-9EEE-F0A00218BEBB}"
  -> {HKLM...CLSID} = "ZLAVShExt Class"
                  \InProcServer32\(Default) = "K:\Programme\Zone Labs\ZoneAlarm\zlavscan.dll" ["Zone Labs, LLC"]


Group Policies {policy setting}:
--------------------------------

Note: detected settings may not have any effect.

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\

"shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
{Shutdown: Allow system to be shut down without having to log on}

"undockwithoutlogon" = (REG_DWORD) dword:0x00000001
{Devices: Allow undock without having to log on}


Active Desktop and Wallpaper:
-----------------------------

Active Desktop may be disabled at this entry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
"Wallpaper" = "K:\WINDOWS\web\wallpaper\Grüne Idylle.bmp"

Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
HKCU\Control Panel\Desktop\
"Wallpaper" = "K:\Dokumente und Einstellungen\janusz\Anwendungsdaten\Mozilla\Firefox\Desktop Hintergrund.bmp"


Enabled Screen Saver:
---------------------

HKCU\Control Panel\Desktop\
"SCRNSAVE.EXE" = "K:\WINDOWS\system32\logon.scr" [MS]


Windows Portable Device AutoPlay Handlers
-----------------------------------------

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\

AVSDVDMovieOnArrival\
"Provider" = "AVS DVD Player"
"InvokeProgID" = "DVD"
"InvokeVerb" = "PlayWithAVSDVDPlayer"
HKLM\SOFTWARE\Classes\DVD\shell\PlayWithAVSDVDPlayer\Command\(Default) = ""K:\Programme\AVSMedia\DVDPlayer\AVSDVDPlayer.EXE" "%L"" ["Online Media Technologies Ltd."]

MSWPDShellNamespaceHandler\
"Provider" = "@%SystemRoot%\System32\WPDShextRes.dll,-501"
"CLSID" = "{A55803CC-4D53-404c-8557-FD63DBA95D24}"
"InitCmdLine" = " "
  -> {HKLM...CLSID} = "WPDShextAutoplay"
                  \LocalServer32\(Default) = "K:\WINDOWS\system32\WPDShextAutoplay.exe" [MS]


Startup items in "janusz" & "All Users" startup folders:
--------------------------------------------------------

K:\Dokumente und Einstellungen\janusz\Startmenü\Programme\Autostart
"OpenOffice.org 2.4" -> shortcut to: "K:\Programme\OpenOffice.org 2.4\program\quickstart.exe" [null data]


Winsock2 Service Provider DLLs:
-------------------------------

Namespace Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

Transport Service Providers

HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
K:\Programme\Ashampoo\Ashampoo FireWall\spi.dll [null data], 01 - 05, 16
%SystemRoot%\system32\mswsock.dll [MS], 06 - 15, 17 - 19
%SystemRoot%\system32\rsvpsp.dll [MS], 20 - 21


Toolbars, Explorer Bars, Extensions:
------------------------------------

Toolbars

HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
"{8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3}" = (no title provided)
  -> {HKLM...CLSID} = "SnagIt"
                  \InProcServer32\(Default) = "K:\Programme\TechSmith\SnagIt 8\SnagItIEAddin.dll" [file not found]
"{D0943516-5076-4020-A3B5-AEFAF26AB263}" = "Veoh Browser Plug-in"
  -> {HKLM...CLSID} = "Veoh Browser Plug-in"
                  \InProcServer32\(Default) = "K:\Programme\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll" ["Veoh Networks Inc"]

Extensions (Tools menu items, main toolbar menu buttons)

HKCU\Software\Microsoft\Internet Explorer\Extensions\
{0E921E80-267A-42AA-AEE4-60B9A1222A44}\
"ButtonText" = "Klicke hier um das Projekt xp-AntiSpy zu unterstützen"
"MenuText" = "Unterstützung für xp-AntiSpy"
"Exec" = "K:\Programme\xp-AntiSpy\sponsoring\sponsor.html" [null data]

HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
{08B0E5C0-4FCB-11CF-AAA5-00401C608501}\
"MenuText" = "Sun Java Konsole"
"CLSIDExtension" = "{CAFEEFAC-0015-0000-0000-ABCDEFFEDCBC}"
  -> {HKLM...CLSID} = "Java Plug-in 1.5.0"
                  \InProcServer32\(Default) = "K:\Programme\Java\jre1.5.0\bin\npjpi150.dll" ["Sun Microsystems, Inc."]

{E59EB121-F339-4851-A3BA-FE49C35617C2}\
"ButtonText" = "ICQ6"
"MenuText" = "ICQ6"
"Exec" = "K:\Programme\ICQ6\ICQ.exe" ["ICQ, Inc."]

{FB5F1910-F110-11D2-BB9E-00C04F795683}\
"ButtonText" = "Messenger"
"MenuText" = "Windows Messenger"
"Exec" = "K:\Programme\Messenger\msmsgs.exe" [MS]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

Apache2.2, Apache2.2, ""K:\xampp\apache\bin\apache.exe" -k runservice" ["Apache Software Foundation"]
Ati HotKey Poller, Ati HotKey Poller, "K:\WINDOWS\system32\Ati2evxx.exe" ["ATI Technologies Inc."]
Avira AntiVir Personal – Free Antivirus Guard, AntiVirService, ""K:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe"" ["Avira GmbH"]
Avira AntiVir Personal – Free Antivirus Planer, AntiVirScheduler, ""K:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe"" ["Avira GmbH"]
AVM WLAN Connection Service, AVM WLAN Connection Service, "K:\Programme\avmwlanstick\WlanNetService.exe" ["AVM Berlin"]
Content Management Service, ContentMgrService, "K:\Programme\Videoload Manager\ContentManager.exe" ["ACE GmbH"]
Messenger USN Journal Reader-Service für freigegebene Ordner, usnjsvc, ""K:\Programme\Windows Live\Messenger\usnsvc.exe"" [MS]
mysql, mysql, "K:\xampp\mysql\bin\mysqld-nt.exe --defaults-file=k:\xampp\mysql\bin\my.cnf mysql" [null data]


---------- (launch time: 2008-07-28 13:24:30)
<<!>>: Suspicious data at a malware launch point.

+ This report excludes default entries except where indicated.
+ To see *everywhere* the script checks and *everything* it finds,
  launch it from a command prompt or a shortcut with the -all parameter.
+ To search all directories of local fixed drives for DESKTOP.INI
  DLL launch points, use the -supp parameter or answer "No" at the
  first message box and "Yes" at the second message box.
---------- (total run time: 44 seconds, including 17 seconds for message boxes)

hoffe dad war jetzt richtig so :D

jurabe 28.07.2008 21:51

Hallo?
Wasn jetzt mit dem dings was ich da gepostet hab ?

cosinus 29.07.2008 12:46

Code:

O4 - HKLM\..\Run: [Ashampoo FireWall] "K:\Programme\Ashampoo\Ashampoo FireWall\FireWall.exe" -TRAY
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - K:\WINDOWS\system32\ZoneLabs\vsmon.exe

Wozu gleich zwei PFWs? Oder ist eine deinstalliert?

Code:

O23 - Service: Content Management Service (ContentMgrService) - ACE GmbH - K:\Programme\Videoload Manager\ContentManager.exe
Was ist das für ein Programm? Der PC steht nicht rein zufällig in einem Büro? :rolleyes:
Anzeichen für Befall seh ich jedenfalls nicht.

jurabe 29.07.2008 15:18

also
Zone alarm is seit dem letzten windows update verbuggt , fährt aber bei jedem start mit hoch . Hab vergessen das abzustellen .
Und nein der pc steht nicht in einem büro , warum ?
Das prog is von der seite www.videoload.de bin bei t-online kunde und kann da so direkt bezahlen , is einfach einfacher mit dem ding die filme anzuschauen :P


Alle Zeitangaben in WEZ +1. Es ist jetzt 06:56 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131