![]() |
|
Log-Analyse und Auswertung: 96676 ich kriege es einfach nicht hinWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() 96676 ich kriege es einfach nicht hin Hallo zusammen, ich brauche Hilfe beim Remove von dem Trojaner 96676. Ich kriege den einfach nicht weg. Was muss ich alles entfernen ? Hier mein logfile: Logfile of HijackThis v1.97.7 Scan saved at 10:18:44, on 2004-06-29 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Program\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\winmg.exe C:\WINDOWS\Explorer.EXE C:\Program\Real\RealPlayer\RealPlay.exe C:\WINDOWS\SYSTEM32\qttask.exe C:\Program\Support.com\bin\tgcmd.exe C:\WINDOWS\appem32.exe C:\WINDOWS\System32\rdqkse.exe C:\Program\Java\j2re1.4.2_01\bin\jusched.exe C:\Program\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe C:\Documents and Settings\HP-Auktoriserad kund\Application Data\wrda.exe C:\WINDOWS\System32\NDrv.exe C:\Program\Handelsbanken\Säkerhetslösning\ssrlite.exe C:\Program\iD2\CSP\iD2CertMover.exe C:\Program\Windows Media Components\Encoder\WMENCAGT.EXE C:\Program\Nokia\PC Suite for Nokia 9210i Communicator\ConnectState.exe C:\Program\Nokia\PC Suite for Nokia 9210i Communicator\ECTaskScheduler.exe C:\Program\Nokia\PCSUIT~1\BROADC~1.EXE C:\WINDOWS\System32\svchost.exe C:\Frank\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.iquicksearch.net/search.htm R1 - HKCU\Software\Microsoft\Internet Explorer,Default_Search_URL = http://www.searchnow.ws/search/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wmkro.dll/sp.html#96676 R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = res://wmkro.dll/index.html#96676 R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated) R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated) R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = res://wmkro.dll/index.html#96676 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated) R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\wmkro.dll/sp.html#96676 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = res://wmkro.dll/index.html#96676 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = res://C:\WINDOWS\wmkro.dll/sp.html#96676 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Telenordia Internet Explorer R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated) R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = res://wmkro.dll/index.html#96676 R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Länkar R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = http://homepage.com%00@www.e-finder.cc/search/ (obfuscated) O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file) O2 - BHO: (no name) - {EBC21DD1-18C4-74D7-C935-89E653731491} - C:\WINDOWS\ipnz32.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [RealTray] C:\Program\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime O4 - HKLM\..\Run: [TeliaTGCMD] "C:\Program\Support.com\bin\tgcmd.exe" /server /startmonitor /deaf O4 - HKLM\..\Run: [appem32.exe] C:\WINDOWS\appem32.exe O4 - HKLM\..\Run: [hocvtxlsws] C:\WINDOWS\System32\rdqkse.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program\Java\j2re1.4.2_01\bin\jusched.exe O4 - HKCU\..\Run: [MoneyAgent] "C:\Program\Microsoft Money\System\Money Express.exe" O4 - HKCU\..\Run: [LDM] C:\Program\Logitech\Desktop Messenger\8876480\Program\BackWeb-8876480.exe O4 - HKCU\..\Run: [Rews] C:\Documents and Settings\HP-Auktoriserad kund\Application Data\wrda.exe O4 - HKCU\..\Run: [NDrv] C:\WINDOWS\System32\NDrv.exe O4 - HKLM\..\RunOnce: [winmg.exe] C:\WINDOWS\winmg.exe O4 - Global Startup: Handelsbankens säkerhetsprogram.lnk = ? O4 - Global Startup: iD2 CSP Certificate Utility.lnk = C:\Program\iD2\CSP\iD2CertMover.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = C:\Program\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Encoder Agent.lnk = C:\Program\Windows Media Components\Encoder\WMENCAGT.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Program\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: Anslutning för PC Suite for Nokia 9210i Communicator.lnk = C:\Program\Nokia\PC Suite for Nokia 9210i Communicator\ConnectState.exe O4 - Global Startup: PC Suite for Nokia 9210i Communicator Task Scheduler.lnk = C:\Program\Nokia\PC Suite for Nokia 9210i Communicator\ECTaskScheduler.exe O8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~4\Office10\EXCEL.EXE/3000 O9 - Extra 'Tools' menuitem: Sun Java-konsol (HKLM) O9 - Extra button: Messenger (HKLM) O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM) O12 - Plugin for .avi: C:\Program\Internet Explorer\PLUGINS\npqtplugin.dll O12 - Plugin for .mpe: C:\Program\Internet Explorer\PLUGINS\npqtplugin3.dll O12 - Plugin for .sgn: C:\PROGRAM\INTERN~1\PLUGINS\npSign.dll O12 - Plugin for .wav: C:\Program\Internet Explorer\PLUGINS\npqtplugin.dll O13 - DefaultPrefix: O13 - WWW Prefix: O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab O16 - DPF: {037B3D58-D14A-4C41-BDFD-BD779B0B97BA} (vxiewer control) - http://www.thepaymentcentre.com/build/vxiewer.cab O16 - DPF: {12398DD6-40AA-4C40-A4EC-A42CFC0DE797} (Installer Class) - http://www.xxxtoolbar.com/ist/softwa...06_regular.cab O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) - http://download.macromedia.com/pub/s...irector/sw.cab O16 - DPF: {597C45C2-2D39-11D5-8D53-0050048383FE} (OPUCatalog Class) - http://office.microsoft.com/productu...ntent/opuc.cab O16 - DPF: {78AF2F24-A9C3-11D3-BF8C-0060B0FCC122} (AcDcToday Control) - file://C:\Program Files\AutoCAD LT\AcDcToday.ocx O16 - DPF: {869F3BBC-A812-4D13-A93B-7B3FC816DCD5} (McAfee.com Updater) - http://download.mcafee.com/molbin/cl...an/mcasupd.cab O16 - DPF: {9EB320CE-BE1D-4304-A081-4B4665414BEF} (MediaTicketsInstaller Control) - http://www.mt-download.com/MediaTicketsInstaller.cab O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.co...130.4869097222 O16 - DPF: {AE563720-B4F5-11D4-A415-00108302FDFD} (NOXLATE-BANR) - file://C:\Program Files\AutoCAD LT\InstBanr.ocx O16 - DPF: {C6637286-300D-11D4-AE0A-0010830243BD} (InstaFred) - file://C:\Program Files\AutoCAD LT\InstFred.ocx O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab O16 - DPF: {DF261D07-7E99-11D4-B2C7-009027A1F18A} (DDI Print Control Class v1.2 [ENU]) - https://eredovisning.postgirot.se/dd...k/iedpwenu.cab O16 - DPF: {F281A59C-7B65-11D3-8617-0010830243BD} (AcPreview Control) - file://C:\Program Files\AutoCAD LT\AcPreview.ocx O17 - HKLM\System\CCS\Services\Tcpip\..\{B2174E1E-134A-4CAD-8992-126C71B6B808}: NameServer = 195.67.199.18,195.67.199.19 |
Themen zu 96676 ich kriege es einfach nicht hin |
.com, application, bho, brauche hilfe, button, components, desktop, entfernen, excel, explorer, hijack, hijackthis, hilfe, internet, internet explorer, logfile, messenger, microsoft, monitor, obfuscated, object, realplayer, shockwave, software, start, system, system32, tcpip, trojaner, windows, windows messenger, windows xp |