![]() |
|
Log-Analyse und Auswertung: Problem mit TR/Monderb.aqlWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #4 |
![]() ![]() | ![]() Problem mit TR/Monderb.aql 2.Main Deckard's System Scanner v20071014.68 Run by p***** a****** on 2008-07-29 16:59:37 Computer is in Normal Mode. -------------------------------------------------------------------------------- -- System Restore -------------------------------------------------------------- -- Last 5 Restore Point(s) -- 10: 2008-07-29 14:54:35 UTC - RP436 - Deckard's System Scanner Restore Point 9: 2008-07-29 14:53:27 UTC - RP435 - Last known good configuration 8: 2008-07-29 14:53:14 UTC - RP434 - Entfernt Medieval II Total War 7: 2008-07-29 14:53:14 UTC - RP433 - Last known good configuration 6: 2008-07-29 14:53:13 UTC - RP432 - Systemprüfpunkt -- First Restore Point -- 1: 2008-07-29 14:53:10 UTC - RP427 - Konfiguriert Medieval II Total War Backed up registry hives. Performed disk cleanup. System Drive C: has 1.43 GiB (less than 15%) free. -- HijackThis (run as p***** a******.exe) -------------------------------------- Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:01:03, on 29.07.2008 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\TBPanel.exe C:\Programme\Java\jre1.6.0_07\bin\jusched.exe D:\Programme\DAEMON Tools\daemon.exe C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe C:\Programme\Picasa2\PicasaMediaDetector.exe D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE C:\Programme\Musicmatch\Musicmatch Jukebox\mm_tray.exe C:\Programme\Musicmatch\Musicmatch Jukebox\mmtask.exe C:\WINDOWS\System32\RUNDLL32.EXE C:\Programme\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\System32\Rundll32.exe C:\WINDOWS\System32\ctfmon.exe C:\Programme\FRITZ!DSL\IGDCTRL.EXE C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe D:\Programme\Nokia\Nokia PC Suite 6\PcSync2.exe C:\WINDOWS\System32\nvsvc32.exe C:\Programme\Veoh Networks\Veoh\VeohClient.exe C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe C:\Programme\FRITZ!DSL\StCenter.exe C:\WINDOWS\System32\PnkBstrA.exe C:\WINDOWS\System32\svchost.exe C:\Programme\OpenOffice.org 2.3\program\soffice.exe C:\PROGRA~1\GEMEIN~1\Nokia\MPAPI\MPAPI3s.exe C:\Programme\OpenOffice.org 2.3\program\soffice.BIN C:\Programme\Gemeinsame Dateien\PCSuite\Services\ServiceLayer.exe D:\dss.exe C:\PROGRA~1\TRENDM~1\HIJACK~1\p***** a******.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = fritz.box R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O2 - BHO: (no name) - {140E04E3-8747-492E-9B69-4EE333F9474F} - C:\WINDOWS\System32\fccdcawu.dll O2 - BHO: (no name) - {42BFABD3-B070-4053-9485-30D7E000D3D3} - C:\WINDOWS\system32\rqRJBssp.dll (file missing) O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Programme\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Programme\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\PROGRA~1\ICQTOO~1\toolbaru.dll O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Programme\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [SkyTel] SkyTel.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [DAEMON Tools] "D:\Programme\DAEMON Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Picasa Media Detector] C:\Programme\Picasa2\PicasaMediaDetector.exe O4 - HKLM\..\Run: [PCSuiteTrayApplication] D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.EXE -startup O4 - HKLM\..\Run: [MMTray] "C:\Programme\Musicmatch\Musicmatch Jukebox\mm_tray.exe" O4 - HKLM\..\Run: [mmtask] "C:\Programme\Musicmatch\Musicmatch Jukebox\mmtask.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [BM3b76c9a5] Rundll32.exe "C:\WINDOWS\System32\ghbagkkp.dll",s O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [PcSync] D:\Programme\Nokia\Nokia PC Suite 6\PcSync2.exe /NoDialog O4 - HKCU\..\Run: [Veoh] "C:\Programme\Veoh Networks\Veoh\VeohClient.exe" /VeohHide O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: Adobe Gamma.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Startup: OpenOffice.org 2.3.lnk = C:\Programme\OpenOffice.org 2.3\program\quickstart.exe O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: FRITZ!DSL Startcenter.lnk = C:\Programme\FRITZ!DSL\StCenter.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe (file missing) O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe (file missing) O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe O12 - Plugin for .spop: C:\Programme\Internet Explorer\Plugins\NPDocBox.dll O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1155337172578 O20 - AppInit_DLLs: e1.dll wzcdgwfs.dll O20 - Winlogon Notify: rqRJBssp - rqRJBssp.dll (file missing) O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: AVM IGD CTRL Service - AVM Berlin - C:\Programme\FRITZ!DSL\IGDCTRL.EXE O23 - Service: AVM FRITZ!web Routing Service (de_serv) - AVM Berlin - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exe O23 - Service: ServiceLayer - Nokia. - C:\Programme\Gemeinsame Dateien\PCSuite\Services\ServiceLayer.exe -- End of file - 7676 bytes -- File Associations ----------------------------------------------------------- .reg - regfile - shell\open\command - regedit.exe "%1" %* .scr - scrfile - shell\open\command - "%1" %* -- Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled --------------------- R0 sfdrv01 (StarForce Protection Environment Driver (version 1.x)) - c:\windows\system32\drivers\sfdrv01.sys <Not Verified; Protection Technology (StarForce); SF FrontLine> R0 sfhlp02 (StarForce Protection Helper Driver (version 2.x)) - c:\windows\system32\drivers\sfhlp02.sys <Not Verified; Protection Technology (StarForce); SF FrontLine> R0 sfsync04 (StarForce Protection Synchronization Driver (version 4.x)) - c:\windows\system32\drivers\sfsync04.sys <Not Verified; Protection Technology (StarForce); SF FrontLine> R0 sfvfs02 (StarForce Protection VFS Driver (version 2.x)) - c:\windows\system32\drivers\sfvfs02.sys <Not Verified; Protection Technology; StarForce Protection System> R1 SSHDRV85 - c:\windows\system32\drivers\sshdrv85.sys <Not Verified; ; ProtectCD> R1 ssmdrv - c:\windows\system32\drivers\ssmdrv.sys <Not Verified; AVIRA GmbH; > R2 TBPanel - c:\windows\system32\drivers\tbpanel.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver> S1 InCDPass - c:\windows\system32\drivers\incdpass.sys (file missing) S1 InCDRm (InCD Reader) - c:\windows\system32\drivers\incdrm.sys (file missing) S3 Cardex - c:\windows\system32\drivers\tbpanel.sys <Not Verified; Windows (R) 2000 DDK provider; Windows (R) 2000 DDK driver> S3 TSP - c:\windows\system32\drivers\klif.sys (file missing) S4 InCDFs (InCD File System) - c:\windows\system32\drivers\incdfs.sys (file missing) -- Services: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled -------------------- R2 AntiVirScheduler (AntiVir PersonalEdition Classic Planer) - "c:\programme\antivir personaledition classic\sched.exe" <Not Verified; Avira GmbH; AntiVir Workstation> R2 AVM IGD CTRL Service - c:\programme\fritz!dsl\igdctrl.exe <Not Verified; AVM Berlin; AVM IGD Service> R3 ServiceLayer - "c:\programme\gemeinsame dateien\pcsuite\services\servicelayer.exe" <Not Verified; Nokia.; PC Connectivity Solution> S3 de_serv (AVM FRITZ!web Routing Service) - c:\programme\gemeinsame dateien\avm\de_serv.exe <Not Verified; AVM Berlin; AVM Rocky> -- Device Manager: Disabled ---------------------------------------------------- No disabled devices found. -- Scheduled Tasks ------------------------------------------------------------- 2008-07-25 15:00:52 410 --a------ C:\WINDOWS\Tasks\Norton Security Scan.job -- Files created between 2008-06-29 and 2008-07-29 ----------------------------- 2008-07-29 16:56:02 472497 --ahs---- C:\WINDOWS\System32\uwacdccf.ini2 2008-07-29 10:36:34 91648 -----n--- C:\WINDOWS\System32\ghbagkkp.dll 2008-07-28 19:02:42 0 d-------- C:\Programme\Malwarebytes' Anti-Malware 2008-07-28 18:47:29 0 d-------- C:\Programme\Trend Micro 2008-07-28 14:44:36 0 d-------- C:\VundoFix Backups 2008-07-28 10:37:14 91648 -----n--- C:\WINDOWS\System32\fnugyewx.dll 2008-07-27 10:39:12 105472 --a------ C:\WINDOWS\System32\okubbv.dll 2008-07-27 10:39:11 105472 --a------ C:\WINDOWS\System32\xqywserl.dll 2008-07-27 10:35:28 91648 --a------ C:\WINDOWS\System32\vlfnclan.dll 2008-07-27 01:38:41 314880 -----n--- C:\WINDOWS\System32\fccdcawu.dll 2008-07-27 01:33:30 0 d-------- C:\WINDOWS\System32\kBin19 2008-07-21 19:15:53 0 d-------- C:\Programme\MessengerDiscovery 2008-07-18 14:34:10 0 d-------- C:\NVIDIA 2008-07-18 14:20:15 0 d-------- C:\Programme\SystemRequirementsLab 2008-07-16 19:50:16 0 d-------- C:\Programme\dMSN 2008-07-16 19:49:56 0 d--h----- C:\Programme\Zero G Registry 2008-07-14 19:03:32 0 d-------- C:\Programme\Messenger Plus! Live 2008-07-14 08:49:52 0 d-------- C:\Programme\Musicmatch -- Find3M Report --------------------------------------------------------------- 2008-07-29 16:58:16 0 d-------- C:\Dokumente und Einstellungen\p***** a******\Anwendungsdaten\OpenOffice.org2 2008-07-29 10:33:17 0 d--h----- C:\Programme\InstallShield Installation Information 2008-07-28 20:57:01 0 d-------- C:\Programme\Gemeinsame Dateien\Symantec Shared 2008-07-28 19:02:49 0 d-------- C:\Dokumente und Einstellungen\p***** a******\Anwendungsdaten\Malwarebytes 2008-07-28 16:10:49 0 d-------- C:\Programme\Norton Security Scan 2008-07-28 14:16:04 0 d-------- C:\Programme\ICQToolbar 2008-07-18 17:59:06 0 d-------- C:\Programme\Java 2008-07-14 08:49:52 0 d-------- C:\Dokumente und Einstellungen\p***** a******\Anwendungsdaten\Musicmatch 2008-06-22 14:52:42 0 d-------- C:\Dokumente und Einstellungen\p***** a******\Anwendungsdaten\Mozilla -- Registry Dump --------------------------------------------------------------- *Note* empty entries & legit default entries are not shown [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{140E04E3-8747-492E-9B69-4EE333F9474F}] 27.07.2008 01:38 314880 --------- C:\WINDOWS\System32\fccdcawu.dll [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{42BFABD3-B070-4053-9485-30D7E000D3D3}] C:\WINDOWS\system32\rqRJBssp.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "RTHDCPL"="RTHDCPL.EXE" [01.06.2006 10:48 C:\WINDOWS\RTHDCPL.exe] "SkyTel"="SkyTel.EXE" [16.05.2006 12:04 C:\WINDOWS\SkyTel.exe] "Alcmtr"="ALCMTR.EXE" [03.05.2005 12:43 C:\WINDOWS\Alcmtr.exe] "Gainward"="C:\WINDOWS\TBPanel.exe" [03.01.2006 11:10] "NeroFilterCheck"="C:\WINDOWS\System32\NeroCheck.exe" [09.07.2001 11:50] "SunJavaUpdateSched"="C:\Programme\Java\jre1.6.0_07\bin\jusched.exe" [10.06.2008 04:27] "DAEMON Tools"="D:\Programme\DAEMON Tools\daemon.exe" [10.12.2005 16:57] "avgnt"="C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" [19.07.2008 14:26] "Picasa Media Detector"="C:\Programme\Picasa2\PicasaMediaDetector.exe" [16.06.2007 01:15] "PCSuiteTrayApplication"="D:\PROGRA~1\Nokia\NOKIAP~1\LAUNCH~1.exe" [15.06.2006 12:36] "MMTray"="C:\Programme\Musicmatch\Musicmatch Jukebox\mm_tray.exe" [17.01.2006 13:26] "mmtask"="C:\Programme\Musicmatch\Musicmatch Jukebox\mmtask.exe" [17.01.2006 13:26] "NvCplDaemon"="C:\WINDOWS\System32\NvCpl.dll" [19.04.2007 13:26] "nwiz"="nwiz.exe" [19.04.2007 13:26 C:\WINDOWS\system32\nwiz.exe] "NvMediaCenter"="C:\WINDOWS\System32\NvMcTray.dll" [19.04.2007 13:26] "BM3b76c9a5"="C:\WINDOWS\System32\ghbagkkp.dll" [29.07.2008 10:36] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\WINDOWS\System32\ctfmon.exe" [29.08.2002 14:00] "MsnMsgr"="C:\Programme\Windows Live\Messenger\MsnMsgr.exe" [18.10.2007 12:34] "PcSync"="D:\Programme\Nokia\Nokia PC Suite 6\PcSync2.exe" [19.06.2006 15:59] "Veoh"="C:\Programme\Veoh Networks\Veoh\VeohClient.exe" [01.04.2008 18:35] "@"="" [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks] "{42BFABD3-B070-4053-9485-30D7E000D3D3}"= C:\WINDOWS\system32\rqRJBssp.dll [ ] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\rqRJBssp] rqRJBssp.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\windows] "appinit_dlls"=e1.dll wzcdgwfs.dll [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa] "Authentication Packages"= msv1_0 C:\WINDOWS\System32\fccdcawu [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] SecurityProviders msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll, -- End of Deckard's System Scanner: finished at 2008-07-29 17:01:26 ------------ |
Themen zu Problem mit TR/Monderb.aql |
adobe, antivir, avira, browser, dsl, explorer, firefox, gainward, hijack, hijackthis, hkus\s-1-5-18, infizierte, infizierte dateien, internet, internet explorer, launch, mozilla, mozilla firefox, nvidia, pc infiziert, picasa, plug-in, problem, programme, quara, rundll, scan, schuelervz, security, security scan, software, system, trojaner, urlsearchhook, windows, windows xp |