![]() |
| |||||||
Log-Analyse und Auswertung: Bitte um Auswertung bei meinem Scan:Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #6 |
| | Bitte um Auswertung bei meinem Scan: ComboFix 07-10-17.8@ - Bergmann 2007-10-19 10:13:41.1 - FAT32x86 Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1031.18.257 [GMT 2:00] ausgeführt von:: C:\Dokumente und Einstellungen\Bergmann\Desktop\ComboFix.exe * Neuer Wiederherstellungspunkt wurde erstellt . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . C:\WINDOWS\Fonts\acrsecI.fon C:\WINDOWS\regedit.com C:\WINDOWS\system32\taskmgr.com . ((((((((((((((((((((((( Dateien erstellt von 2007-09-19 bis 2007-10-19 )))))))))))))))))))))))))))))) . 2007-10-19 10:12 51,200 --a------ C:\WINDOWS\NirCmd.exe 2007-10-19 09:38 <DIR> d-------- C:\bases_x 2007-10-18 23:31 <DIR> d-a------ C:\WINDOWS\zts2.exe 2007-10-18 23:31 <DIR> d-a------ C:\WINDOWS\system32\vcmgcd32.dll 2007-10-18 23:31 <DIR> d-a------ C:\WINDOWS\system32\systems.txt 2007-10-18 23:31 <DIR> d-a------ C:\WINDOWS\system32\iifgfgf.dll 2007-10-18 23:31 <DIR> d-a------ C:\WINDOWS\rundll16.exe 2007-10-18 23:31 <DIR> d-a------ C:\WINDOWS\rundl132.dll 2007-10-18 23:31 <DIR> d-a------ C:\WINDOWS\logo1_.exe 2007-10-18 23:31 4,201,494 --a------ C:\WINDOWS\REGBK00.ZIP 2007-10-18 23:26 153,600 --a------ C:\WINDOWS\R.COM 2007-10-18 23:26 140,800 --a------ C:\WINDOWS\system32\T.COM 2007-10-13 10:42 584,192 --------- C:\WINDOWS\system32\dllcache\rpcrt4.dll . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2007-08-22 12:56 96,768 ----a-w C:\WINDOWS\system32\dllcache\inseng.dll 2007-08-22 12:56 671,232 ----a-w C:\WINDOWS\system32\dllcache\wininet.dll 2007-08-22 12:56 620,032 ----a-w C:\WINDOWS\system32\dllcache\urlmon.dll 2007-08-22 12:56 55,808 ----a-w C:\WINDOWS\system32\dllcache\extmgr.dll 2007-08-22 12:56 532,480 ----a-w C:\WINDOWS\system32\dllcache\mstime.dll 2007-08-22 12:56 474,624 ----a-w C:\WINDOWS\system32\dllcache\shlwapi.dll 2007-08-22 12:56 449,024 ----a-w C:\WINDOWS\system32\dllcache\mshtmled.dll 2007-08-22 12:56 39,424 ----a-w C:\WINDOWS\system32\dllcache\pngfilt.dll 2007-08-22 12:56 357,888 ----a-w C:\WINDOWS\system32\dllcache\dxtmsft.dll 2007-08-22 12:56 3,085,824 ----a-w C:\WINDOWS\system32\dllcache\mshtml.dll 2007-08-22 12:56 251,904 ----a-w C:\WINDOWS\system32\dllcache\iepeers.dll 2007-08-22 12:56 205,824 ----a-w C:\WINDOWS\system32\dllcache\dxtrans.dll 2007-08-22 12:56 16,384 ----a-w C:\WINDOWS\system32\dllcache\jsproxy.dll 2007-08-22 12:56 152,064 ------w C:\WINDOWS\system32\dllcache\cdfview.dll 2007-08-22 12:56 146,432 ----a-w C:\WINDOWS\system32\dllcache\msrating.dll 2007-08-22 12:56 1,498,112 ----a-w C:\WINDOWS\system32\dllcache\shdocvw.dll 2007-08-22 12:56 1,056,256 ------w C:\WINDOWS\system32\dllcache\danim.dll 2007-08-22 12:56 1,022,976 ----a-w C:\WINDOWS\system32\dllcache\browseui.dll 2007-08-21 10:19 18,432 ----a-w C:\WINDOWS\system32\dllcache\iedw.exe 2007-08-21 06:16 683,520 ----a-w C:\WINDOWS\system32\inetcomm.dll 2007-08-21 06:16 683,520 ------w C:\WINDOWS\system32\dllcache\inetcomm.dll 2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\dllcache\cdm.dll 2007-07-30 17:19 92,504 ----a-w C:\WINDOWS\system32\cdm.dll 2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\wuapi.dll 2007-07-30 17:19 549,720 ----a-w C:\WINDOWS\system32\dllcache\wuapi.dll 2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\wuauclt.exe 2007-07-30 17:19 53,080 ----a-w C:\WINDOWS\system32\dllcache\wuauclt.exe 2007-07-30 17:19 43,352 ----a-w C:\WINDOWS\system32\wups2.dll 2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\wucltui.dll 2007-07-30 17:19 325,976 ----a-w C:\WINDOWS\system32\dllcache\wucltui.dll 2007-07-30 17:19 271,224 ----a-w C:\WINDOWS\system32\mucltui.dll 2007-07-30 17:19 207,736 ----a-w C:\WINDOWS\system32\muweb.dll 2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\wuweb.dll 2007-07-30 17:19 203,096 ----a-w C:\WINDOWS\system32\dllcache\wuweb.dll 2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\wuaueng.dll 2007-07-30 17:19 1,712,984 ----a-w C:\WINDOWS\system32\dllcache\wuaueng.dll 2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\wups.dll 2007-07-30 17:18 33,624 ----a-w C:\WINDOWS\system32\dllcache\wups.dll 2003-01-21 01:00 13,095,560 ----a-r C:\WINDOWS\system32\config\systemprofile\MpSetup.exe 2003-01-21 01:00 13,095,560 ----a-r C:\Dokumente und Einstellungen\Default User\MpSetup.exe 2003-01-21 01:00 13,095,560 ----a-r C:\Dokumente und Einstellungen\Bergmann\MpSetup.exe . (((((((((((((((((((((((((((( Autostart Punkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Eintrage & legitime Standardeintrage werden nicht angezeigt. [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{4E7BD74F-2B8D-469E-90F0-F66AB581A933}] 2005-01-21 15:10 552960 --a------ C:\Programme\INSTAFINK\instafink.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "LaunchApp"="Alaunch" [] "ATIModeChange"="Ati2mdxx.exe" [2001-09-04 16:24 C:\WINDOWS\system32\Ati2mdxx.exe] "ATIPTA"="C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe" [2004-03-22 21:10] "SoundMan"="SOUNDMAN.EXE" [2003-12-19 17:53 C:\WINDOWS\SOUNDMAN.EXE] "SynTPLpr"="C:\Programme\Synaptics\SynTP\SynTPLpr.exe" [2004-01-09 14:09] "SynTPEnh"="C:\Programme\Synaptics\SynTP\SynTPEnh.exe" [2004-01-09 14:09] "SunJavaUpdateSched"="C:\Programme\Java\jre1.5.0_06\bin\jusched.exe" [2005-11-10 13:03] "FreePDF Assistant"="C:\Programme\FreePDF_XP\fpassist.exe" [2004-07-15 22:05] "WD Button Manager"="WDBtnMgr.exe" [2004-12-28 16:15 C:\WINDOWS\system32\WDBtnMgr.exe] "Seticons"="\Programme\WDC\SetIcon.exe" [2004-01-30 09:03] "Easy-PrintToolBox"="C:\Programme\Canon\Easy-PrintToolBox\BJPSMAIN.exe" [2004-01-14 02:10] "LManager"="C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE" [2003-12-15 17:30] "AGRSMMSG"="AGRSMMSG.exe" [2003-07-25 11:22 C:\WINDOWS\AGRSMMSG.exe] "avgnt"="C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" [2007-10-13 11:09] "QuickTime Task"="C:\Programme\QuickTime\qttask.exe" [2005-05-15 15:41] "BluetoothAuthenticationAgent"="bthprops.cpl" [2004-08-04 00:58 C:\WINDOWS\system32\bthprops.cpl] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 00:57] [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "ALUAlert"=C:\Programme\Symantec\LiveUpdate\ALUNotify.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupfolder\C:^Dokumente und Einstellungen^All Users^Startmenü^Programme^Autostart^GStartup.lnk] path=C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\GStartup.lnk backup=C:\WINDOWS\pss\GStartup.lnkCommon Startup [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\LtMoh] C:\Programme\ltmoh\Ltmoh.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroCheck] C:\WINDOWS\system32\NeroCheck.exe [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\P2P Networking] C:\WINDOWS\system32\P2P Networking\P2P Networking.exe /AUTOSTART [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\RemoteControl] C:\Programme\CyberLink\PowerDVD\PDVDServ.exe R0 avgntmgr;avgntmgr;C:\WINDOWS\system32\drivers\avgntmgr.sys R1 avgntdd;avgntdd;C:\WINDOWS\system32\DRIVERS\avgntdd.sys R3 DKbFltr;Dritek HotKey Keyboard Filter Driver;C:\WINDOWS\system32\Drivers\DKbFltr.sys S3 inibtmgr;WD Bridge Controller Driver;C:\WINDOWS\system32\DRIVERS\inibtmgr.sys S3 ss_bus;Samsung Mobile USB Device 1.0 driver (WDM);C:\WINDOWS\system32\DRIVERS\ss_bus.sys S3 ss_mdfl;SAMSUNG Mobile USB Modem 1.0 Filter;C:\WINDOWS\system32\DRIVERS\ss_mdfl.sys S3 ss_mdm;SAMSUNG Mobile USB Modem 1.0 Drivers;C:\WINDOWS\system32\DRIVERS\ss_mdm.sys *Newly Created Service* - CATCHME *Newly Created Service* - HTTPFILTER . ************************************************************************** catchme 0.3.1169 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2007-10-19 10:15:38 Windows 5.1.2600 Service Pack 2 FAT NTAPI Scanne versteckte Prozesse... Scanne versteckte Autostart Einträge... Scanne versteckte Dateien... Scan erfolgreich abgeschlossen versteckte Dateien: 0 ************************************************************************** . Zeit der Fertigstellung: 2007-10-19 10:15:58 . --- E O F --- |
| Themen zu Bitte um Auswertung bei meinem Scan: |
| adobe, antivir, avira, bho, canon, dll, ebay, excel, explorer, helfen, hijack, hijackthis, icq, internet, internet explorer, launch, microsoft, notebook, pdfcreator, programm, programme, rundll, scan, software, system, temp, trojaner, windows, windows xp |