Zurück   Trojaner-Board > Malware entfernen > Log-Analyse und Auswertung

Log-Analyse und Auswertung: WORM Probleme. Bitte um Hilfe ! ! !

Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.

Antwort
Alt 01.01.2006, 13:27   #1
ducmax
 
WORM Probleme. Bitte um Hilfe ! ! ! - Standard

WORM Probleme. Bitte um Hilfe ! ! !



Logfile of HijackThis v1.99.1
Scan saved at 14:23:52, on 01.01.2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programme\Winamp3\winampa.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\System32\hphmon04.exe
C:\Programme\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
C:\Programme\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\fxssvc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\NETGEAR\WG511\Utility\WG511WLU.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temp\Temporäres Verzeichnis 3 für hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://rd.companion.yahoo.com/slv/ycheck/as/*http://search.yahoo.com/search?p=%s
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {1F758D2E-E659-4E2C-8E89-D47BFD6E3544} - blank (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: {9B39AB91-5F9A-4A8D-973E-B86D56B2E55D} - {9B39AB91-5F9A-4A8D-973E-B86D56B2E55D} - blank (file missing)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [RealTray] C:\Programme\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [WinampAgent] "C:\Programme\Winamp3\winampa.exe"
O4 - HKLM\..\Run: [WG511WLU] C:\Programme\NETGEAR\WG511\Utility\WG511WLU.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [HPHmon04] C:\WINDOWS\System32\hphmon04.exe
O4 - HKLM\..\Run: [HPHUPD04] "C:\Programme\HP Photosmart 11\hphinstall\UniPatch\hphupd04.exe"
O4 - HKLM\..\Run: [Share-to-Web Namespace Daemon] C:\Programme\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [dflnl.exe] C:\WINDOWS\System32\dflnl.exe
O4 - HKLM\..\Run: [stnospy] C:\Programme\SinEspias\no-spy.exe /autorun
O4 - HKCU\..\Run: [LDM] C:\Programme\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Windows Registry Repair Pro] C:\Programme\3B Software\Windows Registry Repair Pro\RegistryRepairPro.exe 4
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - Startup: E-Mail.lnk = ?
O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Programme\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE
O12 - Plugin for .mov: C:\Programme\Internet Explorer\PLUGINS\npqtplugin.dll
O12 - Plugin for .mp3: C:\Programme\Internet Explorer\PLUGINS\npqtplugin4.dll
O12 - Plugin for .mpeg: C:\Programme\Internet Explorer\PLUGINS\npqtplugin3.dll
O12 - Plugin for ¸æÄ: C:\Programme\Internet Explorer\PLUGINS\npqtplugin3.dll
O15 - Trusted IP range: 64.127.104.144
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - h**p://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1134694317433
O16 - DPF: {CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E} (VacPro.internazionale_ver15) - h**p://advnt01.com/dialer/internazionale_ver15.CAB
O17 - HKLM\System\CCS\Services\Tcpip\..\{017003C8-C7EB-47E2-9090-E18CA42E68DE}: NameServer = 85.255.115.6,85.255.112.151
O17 - HKLM\System\CCS\Services\Tcpip\..\{0B6DBFD7-AFDB-40CC-A966-86A638AE78FC}: NameServer = 85.255.115.6,85.255.112.151
O17 - HKLM\System\CCS\Services\Tcpip\..\{1CA6D27A-2FF4-4009-9534-FC791B3622A2}: NameServer = 85.255.115.6,85.255.112.151
O17 - HKLM\System\CCS\Services\Tcpip\..\{2A1A6845-BA2F-4D29-9EBA-FEA3FF179CC9}: NameServer = 85.255.115.6,85.255.112.151
O17 - HKLM\System\CCS\Services\Tcpip\..\{6FD7660E-A02B-4F91-A804-A87206C3B7DC}: NameServer = 85.255.115.6,85.255.112.151
O17 - HKLM\System\CCS\Services\Tcpip\..\{7D99A7AC-D504-48E9-AD79-D5D7DAD9030A}: NameServer = 85.255.115.6,85.255.112.151
O17 - HKLM\System\CCS\Services\Tcpip\..\{CB69B95A-D9BC-4773-BC59-A806C90D889F}: NameServer = 85.255.115.6,85.255.112.151
O17 - HKLM\System\CS2\Services\Tcpip\..\{017003C8-C7EB-47E2-9090-E18CA42E68DE}: NameServer = 85.255.115.6,85.255.112.151
O18 - Protocol: bw+0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {B90EF704-8ECA-4271-917D-165072C2AF17} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O20 - Winlogon Notify: f3dsl - lsd_f3.dll (file missing)
O21 - SSODL: System - {D0D0C37A-1A61-42F6-BC77-82EC63AD2E27} - blank (file missing)
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAMME\AVPERSONAL\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE
O23 - Service: PACSPTISVR - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\Pacsptisvr.exe
O23 - Service: Pml Driver HPH11 - HP - C:\WINDOWS\System32\HPHipm11.exe
O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\Sptisrv.exe

Alt 01.01.2006, 14:41   #2
Rene-gad
 
WORM Probleme. Bitte um Hilfe ! ! ! - Standard

WORM Probleme. Bitte um Hilfe ! ! !



@ducmax
Um zu verstehen , dass dein System ungepatcht ist:
Zitat:
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
reicht auch ein Thread aus: http://www.trojaner-board.de/showthread.php?t=25145
Fixe mit HJT alle R- und alle O17-Einträge, dazu noch:
Zitat:
O2 - BHO: (no name) - {1F758D2E-E659-4E2C-8E89-D47BFD6E3544} - blank (file missing)
O4 - HKLM\..\Run: [dflnl.exe] C:\WINDOWS\System32\dflnl.exe
O16 - DPF: {CDCBE0F1-D13A-4F86-A963-3A272D3ABA7E} (VacPro.internazionale_ver15) - h**p://advnt01.com/dialer/internazionale_ver15.CAB
Lösche die Datei C:\WINDOWS\System32\dflnl.exe, am Besten-im Abgesicherten Modus.
Wenn die Bereinigung klappt, bitte das System sofort updaten.
__________________


Alt 01.01.2006, 15:55   #3
ducmax
 
WORM Probleme. Bitte um Hilfe ! ! ! - Standard

WORM Probleme. Bitte um Hilfe ! ! !



Hi,

ich danke für die Hilfe.
Hab grad den AntiVir drüber laufen lassen, jetzt ist der bescheidene Alcra.B immer noch da. :-(
__________________

Alt 01.01.2006, 15:59   #4
hoerni26
 
WORM Probleme. Bitte um Hilfe ! ! ! - Standard

WORM Probleme. Bitte um Hilfe ! ! !



hallo,

mal ganz kurz mache doch mal bitte Hier einen Onlinescan und poste mal das ergebniss.

gruß
__________________


Anleitung Neuaufsetzen des Systems

Anleitung Hijackthis

Virusscan Jotti

Fehler sind Menschlich.....

Das größte Problem eines Rechners sitzt meist 50 cm vorm Bildschirm..

Alt 01.01.2006, 18:44   #5
ducmax
 
WORM Probleme. Bitte um Hilfe ! ! ! - Standard

WORM Probleme. Bitte um Hilfe ! ! !



Also kurz ist gut gesagt, ich hab jetzt für den Online-Scan knapp 2 Stunden gebraucht ! :-)

Hier die nun das Ergebnis:


-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Sunday, January 01, 2006 19:41:34
Operating System: Microsoft Windows XP Home Edition, Service Pack 1 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 1/01/2006
Kaspersky Anti-Virus database records: 158299
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
C:\
D:\

Scan Statistics:
Total number of scanned objects: 69472
Number of viruses found: 13
Number of infected objects: 146
Number of suspicious objects: 0
Duration of the scan process: 5130 sec

Infected Object Name - Virus Name
C:\axexx.chm/on-line.exe Infected: Trojan.Win32.Dialer.by
C:\axexx.chm Infected: Trojan.Win32.Dialer.by
C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\Content.IE5\MTELM3UP\035[1].jpg Infected: Trojan-Downloader.Win32.Small.ccn
C:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\Content.IE5\WHYZOHUJ\052[1].htm Infected: Trojan-Downloader.JS.Phel.d
C:\hiruvim.chm/d_hiruvim.exe Infected: Trojan.Win32.Dialer.by
C:\hiruvim.chm Infected: Trojan.Win32.Dialer.by
C:\Programme\winupdates\a.zip/Setup.exe Infected: Email-Worm.Win32.VB.an
C:\Programme\winupdates\a.zip Infected: Email-Worm.Win32.VB.an
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0102568.exe Infected: Trojan-Downloader.Win32.Agent.abs
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0102575.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0102590.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0102606.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0102606.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0102625.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0102625.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0102644.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0102644.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103644.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103644.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103661.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103661.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103679.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103679.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103698.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103698.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103718.pif:atyann:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103718.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103718.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103756.pif:atyann:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103756.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103756.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103775.pif:atyann:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103775.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0103775.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104775.pif:atyann:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104775.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104775.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104794.pif:atyann:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104794.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104794.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104811.pif:atyann:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104811.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104811.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104834.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104842.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104851.OLD:btldfw:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104866.ini:iagso:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104868.OLD:btldfw:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104874.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104875.dll Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0104988.exe Infected: not-virus:Hoax.Win32.Renos.ae
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0105007.dll Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107063.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107064.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107065.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107066.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107067.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107068.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107069.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107070.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107071.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107072.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107073.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107074.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107075.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107076.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107077.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107078.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107079.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107080.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107081.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107082.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107083.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107084.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107085.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107086.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107087.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107088.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107089.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107090.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107091.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107092.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107093.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107094.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107095.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107096.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107097.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107098.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107100.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107101.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107102.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107103.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107104.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107105.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107106.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107107.exe Infected: Trojan.Win32.Agent.bi
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107108.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107109.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107110.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107111.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107113.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107114.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107115.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107116.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107117.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107118.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107119.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107120.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107121.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107122.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107123.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107124.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107125.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107126.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107127.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107128.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107129.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107130.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107131.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107132.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107133.dll Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107134.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107135.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107136.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107137.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107138.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107139.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107140.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107141.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107142.exe Infected: Trojan-Downloader.Win32.Small.cat
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107143.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107144.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP193\A0107145.exe Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP194\A0107238.exe Infected: Email-Worm.Win32.VB.an
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP199\A0109028.exe Infected: Email-Worm.Win32.VB.an
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP199\A0109032.pif:atyann:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP199\A0109032.pif:qaskan:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP199\A0109032.pif:wyvcr:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP199\A0109033.OLD:btldfw:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP199\A0109034.INI:igywun:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP199\A0109035.ini:iagso:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0DB41782-6ED8-427B-A908-E14FD12BD95A}\RP199\A0109037.exe Infected: Trojan.Win32.Agent.bi
C:\WINDOWS\mstasks1.exe Infected: Trojan-Clicker.Win32.Small.ab
C:\WINDOWS\pss\win.ini.backup:rgmtn:$DATA Infected: Trojan-Downloader.Win32.WinShow.bg
C:\WINDOWS\system32\secure32.txt Infected: Trojan.JS.StartPage.r
C:\WINDOWS\Temp\schwedin_1.exe Infected: not-virus:BadJoke.Win32.Badgame

Scan process completed.


Alt 01.01.2006, 20:37   #6
hoerni26
 
WORM Probleme. Bitte um Hilfe ! ! ! - Standard

WORM Probleme. Bitte um Hilfe ! ! !



hallo,
also machen wir es kurz...
ich würd dir raten dein system neu aufzusetzen..
folge dazu der anleitung in meiner signatur..
ist das sicherste...

gruß
__________________
--> WORM Probleme. Bitte um Hilfe ! ! !

Antwort

Themen zu WORM Probleme. Bitte um Hilfe ! ! !
adobe, antivir, askbar, bho, bitte um hilfe, dateien, desktop, drivers, dsl, einstellungen, excel, explorer, hijack, hijackthis, hotkey, internet, internet explorer, logfile, microsoft, netgear, programme, registry, software, system, temp, urlsearchhook, windows, windows xp



Ähnliche Themen: WORM Probleme. Bitte um Hilfe ! ! !


  1. Worm.Koobface - bitte um Hilfe
    Plagegeister aller Art und deren Bekämpfung - 04.02.2011 (32)
  2. habe einen Worm.Win32.fujack.n, bitte um hilfe (inkl. hijackthis logdatei)
    Log-Analyse und Auswertung - 22.09.2009 (14)
  3. !!! HILFE WORM/Kido.DH gefunden / Bitte dringend HJT-Log prüfen!!!
    Log-Analyse und Auswertung - 12.01.2009 (0)
  4. Benötige bitte Hilfe beim kompletten Entfernen von worm.win32.netbooster
    Plagegeister aller Art und deren Bekämpfung - 01.05.2008 (31)
  5. worm.win32.netsky virus-bitte hilfe ich bin ein noob am pc
    Log-Analyse und Auswertung - 17.03.2008 (28)
  6. Worm.Win32.NetSky Problem! Bitte um Hilfe?
    Plagegeister aller Art und deren Bekämpfung - 04.02.2008 (6)
  7. worm.win32.netsky <- Hilfe bitte.
    Plagegeister aller Art und deren Bekämpfung - 04.02.2008 (1)
  8. Worm/IrcBot.soq//Bitte um Hilfe!!
    Plagegeister aller Art und deren Bekämpfung - 22.11.2007 (18)
  9. Bitte Hilfe bei: VB.CO.Leftover / Fujacks-type Worm / Exe.Corrupted
    Mülltonne - 06.09.2007 (3)
  10. HEUR-DBLEXT/Worm.Gen - Bitte um Hilfe!!
    Plagegeister aller Art und deren Bekämpfung - 26.08.2007 (2)
  11. Heuristischer Treffer(HEUR-DBLEXT/Worm.Gen)den ich nicht löschen kann.Bitte um Hilfe
    Plagegeister aller Art und deren Bekämpfung - 10.03.2007 (8)
  12. Ordner Name Unsichtbar Und Glaube Hab Ein Worm/virus Bitte Hilfe
    Log-Analyse und Auswertung - 21.01.2007 (2)
  13. EMail.Worm.Win32.Sober.Z und haufen andere... BITTE HILFE!
    Log-Analyse und Auswertung - 26.11.2006 (6)
  14. WORM/Alcra.B bitte hilfe
    Log-Analyse und Auswertung - 04.10.2005 (4)
  15. Worm/Gobot.Y bitte um hilfe...
    Plagegeister aller Art und deren Bekämpfung - 11.12.2004 (2)
  16. I-Worm NetSky auf Rechner! Bitte um Hilfe
    Log-Analyse und Auswertung - 13.10.2004 (3)
  17. Hilfe,Hilfe,habe Probleme mit Norton Antivirus bitte helfen!!
    Plagegeister aller Art und deren Bekämpfung - 02.03.2004 (1)

Zum Thema WORM Probleme. Bitte um Hilfe ! ! ! - Logfile of HijackThis v1.99.1 Scan saved at 14:23:52, on 01.01.2006 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe - WORM Probleme. Bitte um Hilfe ! ! !...
Archiv
Du betrachtest: WORM Probleme. Bitte um Hilfe ! ! ! auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.