![]() |
| |||||||
Plagegeister aller Art und deren Bekämpfung: winlog.exe ist Backdoor.Agobot.LF?Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
| |
| | #1 | ||
![]() ![]() | winlog.exe ist Backdoor.Agobot.LF?Zitat:
Zitat:
Müsste ich diese Prozedur auch machen, wenn ich Neuinstalliere? Ich weiß, ich strapaziere deine Geduld, aber ich wüsste gerne meine Möglichkeiten kennen |
| | #2 | |||
![]() ![]() ![]() ![]() | winlog.exe ist Backdoor.Agobot.LF?Zitat:
Zitat:
Falls du nicht genügend Steckplätze hast, es gibt direkt im Anschluss einen zweiten ComboFix-Lauf. Da kommen die nächsten dran. Zitat:
Der durfte gleich dreimal Neuinstallieren. ciao, andreas
__________________ |
| | #3 |
![]() ![]() | winlog.exe ist Backdoor.Agobot.LF? So, hab alles angesteckt und das ComboFix laufen lassen.
__________________Hier kommt das Log: ComboFix 09-09-04.02 - ** 05.09.2009 14:16.1.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.49.1031.18.511.267 [GMT 2:00] ausgeführt von:: d:\desktop\cofi.exe . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . c:\windows\system32\404Fix.exe c:\windows\system32\Agent.OMZ.Fix.exe c:\windows\system32\dumphive.exe c:\windows\system32\IEDFix.C.exe c:\windows\system32\IEDFix.exe c:\windows\system32\o4Patch.exe c:\windows\system32\Process.exe c:\windows\system32\SrchSTS.exe c:\windows\system32\VACFix.exe c:\windows\system32\VCCLSID.exe c:\windows\system32\WS2Fix.exe . ((((((((((((((((((((((( Dateien erstellt von 2009-08-05 bis 2009-09-05 )))))))))))))))))))))))))))))) . 2009-09-03 21:22 . 2009-09-03 21:22 -------- d-----w- C:\rsit 2009-09-03 20:53 . 2009-09-03 20:53 -------- d-----w- c:\dokumente und einstellungen\**\Anwendungsdaten\Malwarebytes 2009-09-03 20:53 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-03 20:52 . 2009-09-03 20:52 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes 2009-09-03 20:52 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-09-03 20:52 . 2009-09-03 20:53 -------- d-----w- c:\programme\Malwarebytes' Anti-Malware 2009-09-03 20:12 . 2009-09-03 20:12 -------- d-----w- c:\programme\CCleaner 2009-09-03 17:16 . 2009-09-03 17:16 23 --sha-w- c:\windows\system32\edacded0.dat 2009-09-03 17:15 . 2009-09-03 17:16 -------- d-----w- c:\programme\PowerTools Lite 2009-09-03 16:44 . 2009-09-03 16:44 -------- d-----w- c:\programme\Unlocker 2009-08-21 22:35 . 2009-08-28 18:03 -------- d-----w- c:\dokumente und einstellungen\**\Anwendungsdaten\Apple Computer 2009-08-21 22:34 . 2009-03-19 14:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-08-21 22:34 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll 2009-08-21 22:34 . 2009-08-21 22:34 -------- d-----w- c:\programme\iPod 2009-08-21 22:33 . 2009-08-21 22:34 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-08-21 22:33 . 2009-08-26 20:26 -------- d-----w- c:\programme\iTunes 2009-08-21 22:31 . 2009-08-21 22:31 -------- d-----w- c:\programme\Bonjour 2009-08-21 22:30 . 2009-08-21 22:31 -------- d-----w- c:\programme\QuickTime 2009-08-21 22:30 . 2009-08-21 22:33 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Apple Computer 2009-08-21 22:29 . 2009-08-21 22:29 -------- d-----w- c:\dokumente und einstellungen\**\Lokale Einstellungen\Anwendungsdaten\Apple 2009-08-21 22:29 . 2009-08-21 22:29 -------- d-----w- c:\programme\Apple Software Update 2009-08-21 22:28 . 2009-08-21 22:34 -------- d-----w- c:\programme\Gemeinsame Dateien\Apple 2009-08-21 22:28 . 2009-08-21 22:28 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Apple 2009-08-21 22:27 . 2009-08-21 22:35 -------- d-----w- c:\dokumente und einstellungen\**\Lokale Einstellungen\Anwendungsdaten\Apple Computer 2009-08-16 17:18 . 2009-08-16 17:18 552 ----a-w- c:\windows\system32\d3d8caps.dat . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-09-01 16:13 . 2009-04-01 14:08 664 ----a-w- c:\windows\system32\d3d9caps.dat 2009-08-26 22:43 . 2009-04-02 19:01 -------- d-----w- c:\dokumente und einstellungen\**\Anwendungsdaten\Audacity 2009-08-17 09:19 . 2009-05-23 13:40 -------- d-----w- c:\dokumente und einstellungen\**\Anwendungsdaten\gtk-2.0 2009-08-05 11:41 . 2009-08-05 11:40 249856 ------w- c:\windows\Setup1.exe 2009-08-05 11:41 . 2009-08-05 11:40 73216 ----a-w- c:\windows\ST6UNST.EXE 2009-07-28 15:15 . 2009-07-28 14:37 -------- d-----w- c:\programme\Intel 2009-07-28 14:38 . 2009-07-28 14:38 17801 ----a-w- c:\windows\system32\drivers\AegisP.sys 2009-07-23 05:43 . 2009-07-23 05:43 -------- d-----w- c:\programme\Huawei technologies 2009-07-23 05:43 . 2009-03-29 19:31 -------- d--h--w- c:\programme\InstallShield Installation Information 2009-07-23 05:42 . 2009-03-29 19:31 -------- d-----w- c:\programme\Gemeinsame Dateien\InstallShield 2009-06-11 11:11 . 2009-03-29 17:57 76936 ----a-w- c:\dokumente und einstellungen\**\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT 2008-12-13 17:31 . 2009-03-29 20:06 1660419 ----a-w- c:\programme\SmitfraudFix.exe 2008-09-16 19:17 . 2009-03-29 14:17 968704 ----a-w- c:\programme\WinRAR.exe . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\programme\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] "MSMSGS"="c:\programme\Messenger\msmsgs.exe" [2004-08-03 1667584] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "TkBellExe"="c:\programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" [2009-04-02 198160] "ZCfgSvc.exe"="c:\windows\system32\ZCfgSvc.exe" [2006-08-03 639040] "PRONoMgr.exe"="c:\programme\Intel\NCS\PROSet\PRONoMgr.exe" [2005-07-07 135168] "QuickTime Task"="c:\programme\QuickTime\qttask.exe" [2009-05-26 413696] "iTunesHelper"="c:\programme\iTunes\iTunesHelper.exe" [2009-07-13 292128] [HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="c:\windows\System32\CTFMON.EXE" [2004-08-03 15360] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring] 2006-08-03 01:20 188482 ----a-w- c:\windows\system32\LgNotify.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "midi1"=xgusb.cpl [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-] "SunJavaUpdateSched"="c:\programme\Java\jre6\bin\jusched.exe" [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Programme\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Programme\\Windows Live\\Messenger\\livecall.exe"= "c:\\Programme\\Bonjour\\mDNSResponder.exe"= "c:\\Programme\\iTunes\\iTunes.exe"= [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List] "11954:TCP"= 11954:TCP:BitComet 11954 TCP "11954:UDP"= 11954:UDP:BitComet 11954 UDP R3 NeroCd2k;NeroCd2k;c:\windows\system32\drivers\NeroCD2k.sys [16.04.2001 06:54 44227] S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14.05.2007 10:26 508288] . Inhalt des "geplante Tasks" Ordners 2009-09-04 c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job - c:\programme\Spybot - Search & Destroy\SpybotSD.exe [2009-04-22 13:31] . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = *.local IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, h**p://www.gmer.net Rootkit scan 2009-09-05 14:26 Windows 5.1.2600 Service Pack 2 NTFS Scanne versteckte Prozesse... Scanne versteckte Autostarteinträge... Scanne versteckte Dateien... Scan erfolgreich abgeschlossen versteckte Dateien: 0 ************************************************************************** . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- - - - - - - - > 'winlogon.exe'(864) c:\windows\system32\LgNotify.dll . Zeit der Fertigstellung: 2009-09-05 14:28 ComboFix-quarantined-files.txt 2009-09-05 12:28 Vor Suchlauf: 3.465.428.992 Bytes frei Nach Suchlauf: 3.452.440.576 Bytes frei WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe [boot loader] timeout=2 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /fastdetect /NoExecute=OptIn 136 |
| | #4 |
![]() ![]() ![]() ![]() | winlog.exe ist Backdoor.Agobot.LF? Gut, dann waren die anderen Datenträger zum Glück sauber. Warum hast du mit Smitfraudfix gearbeitet? ciao, andreas
__________________ Kein Support per PN! Das ist hier ein Forum und keine Privatbetreuung! Für alle NeuenPrivatbetreuung nur gegen Bezahlung und ich koste sehr teuer. ![]() Anleitungen Virenscanner Kompromittierung unvermeidbar? |
| | #5 |
![]() ![]() | winlog.exe ist Backdoor.Agobot.LF? Ich hatte einen vor einiger Zeit einen Befall, bei dem mir dieses Programm empfohlen wurde, und hab es (meines Wissens) auch gelöst bekommen. Ich weiß auch nicht mehr genau warum, nach dem letzten Neuaufsetzen hab ich es dann wieder abgespeichert, für den Fall der Fälle. Ich wette es ist unnötig, aber aus den Augen, aus dem Sinn... |
| | #6 |
![]() ![]() ![]() ![]() | winlog.exe ist Backdoor.Agobot.LF? Jetzt kannst du die Geräte anhängen, die beim ersten Lauf nicht angehängt waren. Die anderen kannst du abziehen. Hast du Spybot nicht deinstalliert? Scripten mit Combofix
Code:
ATTFilter KILLALL::
Registry::
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"11954:TCP"=-
"11954:UDP"=-
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\Programme\\Bonjour\\mDNSResponder.exe"=-
[-HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"=-
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"TkBellExe"=-
"QuickTime Task"=-
"iTunesHelper"=-
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"=-
Folder::
c:\Programme\Bonjour
File::
c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job
c:\programme\SmitfraudFix.exe
DirLook::
![]()
Hinweis: Das obige Script ist nur für diesen einen User in dieser Situtation erstellt worden. Es ist auf keinen anderen Rechner portierbar und darf nicht anderweitig verwandt werden, da es das System nachhaltig schädigen kann. ciao, andreas
__________________ --> winlog.exe ist Backdoor.Agobot.LF? |
| | #7 |
![]() ![]() | winlog.exe ist Backdoor.Agobot.LF? Ist sich mit den Steckplätzen schon ausgegangen ![]() Das mit Spybot hab ich übersehen, hab es aber vorhin gleich deinstalliert. Log: ComboFix 09-09-04.02 - ** 05.09.2009 15:19.2.1 - NTFSx86 Microsoft Windows XP Professional 5.1.2600.2.1252.49.1031.18.511.251 [GMT 2:00] ausgeführt von:: d:\desktop\cofi.exe Benutzte Befehlsschalter :: d:\desktop\cfscript.txt FILE :: "c:\programme\SmitfraudFix.exe" "c:\windows\Tasks\Spybot - Search & Destroy - Scheduled Task.job" . (((((((((((((((((((((((((((((((((((( Weitere Löschungen )))))))))))))))))))))))))))))))))))))))))))))))) . c:\programme\Bonjour c:\programme\Bonjour\About Bonjour.rtf c:\programme\Bonjour\mdnsNSP.dll c:\programme\Bonjour\mDNSResponder.exe c:\programme\SmitfraudFix.exe . ((((((((((((((((((((((( Dateien erstellt von 2009-08-05 bis 2009-09-05 )))))))))))))))))))))))))))))) . 2009-09-03 21:22 . 2009-09-03 21:22 -------- d-----w- C:\rsit 2009-09-03 20:53 . 2009-09-03 20:53 -------- d-----w- c:\dokumente und einstellungen\**\Anwendungsdaten\Malwarebytes 2009-09-03 20:53 . 2009-08-03 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys 2009-09-03 20:52 . 2009-09-03 20:52 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes 2009-09-03 20:52 . 2009-08-03 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys 2009-09-03 20:52 . 2009-09-03 20:53 -------- d-----w- c:\programme\Malwarebytes' Anti-Malware 2009-09-03 20:12 . 2009-09-03 20:12 -------- d-----w- c:\programme\CCleaner 2009-09-03 17:16 . 2009-09-03 17:16 23 --sha-w- c:\windows\system32\edacded0.dat 2009-09-03 17:15 . 2009-09-03 17:16 -------- d-----w- c:\programme\PowerTools Lite 2009-09-03 16:44 . 2009-09-05 13:13 -------- d-----w- c:\programme\Unlocker 2009-08-21 22:35 . 2009-08-28 18:03 -------- d-----w- c:\dokumente und einstellungen\**\Anwendungsdaten\Apple Computer 2009-08-21 22:34 . 2009-03-19 14:32 23400 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys 2009-08-21 22:34 . 2008-04-17 10:12 107368 ----a-w- c:\windows\system32\GEARAspi.dll 2009-08-21 22:34 . 2009-08-21 22:34 -------- d-----w- c:\programme\iPod 2009-08-21 22:33 . 2009-08-21 22:34 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\{8CD7F5AF-ECFA-4793-BF40-D8F42DBFF906} 2009-08-21 22:33 . 2009-08-26 20:26 -------- d-----w- c:\programme\iTunes 2009-08-21 22:30 . 2009-08-21 22:31 -------- d-----w- c:\programme\QuickTime 2009-08-21 22:30 . 2009-08-21 22:33 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Apple Computer 2009-08-21 22:29 . 2009-08-21 22:29 -------- d-----w- c:\dokumente und einstellungen\**\Lokale Einstellungen\Anwendungsdaten\Apple 2009-08-21 22:28 . 2009-08-21 22:34 -------- d-----w- c:\programme\Gemeinsame Dateien\Apple 2009-08-21 22:28 . 2009-08-21 22:28 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Apple 2009-08-21 22:27 . 2009-08-21 22:35 -------- d-----w- c:\dokumente und einstellungen\**\Lokale Einstellungen\Anwendungsdaten\Apple Computer 2009-08-16 17:18 . 2009-08-16 17:18 552 ----a-w- c:\windows\system32\d3d8caps.dat . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-09-05 13:13 . 2009-04-22 14:11 -------- d-----w- c:\programme\Spybot - Search & Destroy 2009-09-05 13:13 . 2009-04-22 14:11 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy 2009-09-01 16:13 . 2009-04-01 14:08 664 ----a-w- c:\windows\system32\d3d9caps.dat 2009-08-26 22:43 . 2009-04-02 19:01 -------- d-----w- c:\dokumente und einstellungen\**\Anwendungsdaten\Audacity 2009-08-17 09:19 . 2009-05-23 13:40 -------- d-----w- c:\dokumente und einstellungen\**\Anwendungsdaten\gtk-2.0 2009-08-05 11:41 . 2009-08-05 11:40 249856 ------w- c:\windows\Setup1.exe 2009-08-05 11:41 . 2009-08-05 11:40 73216 ----a-w- c:\windows\ST6UNST.EXE 2009-07-28 15:15 . 2009-07-28 14:37 -------- d-----w- c:\programme\Intel 2009-07-28 14:38 . 2009-07-28 14:38 17801 ----a-w- c:\windows\system32\drivers\AegisP.sys 2009-07-23 05:43 . 2009-07-23 05:43 -------- d-----w- c:\programme\Huawei technologies 2009-07-23 05:43 . 2009-03-29 19:31 -------- d--h--w- c:\programme\InstallShield Installation Information 2009-07-23 05:42 . 2009-03-29 19:31 -------- d-----w- c:\programme\Gemeinsame Dateien\InstallShield 2009-06-11 11:11 . 2009-03-29 17:57 76936 ----a-w- c:\dokumente und einstellungen\**\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT 2008-09-16 19:17 . 2009-03-29 14:17 968704 ----a-w- c:\programme\WinRAR.exe . ((((((((((((((((((((((((((((( SnapShot@2009-09-05_12.26.49 ))))))))))))))))))))))))))))))))))))))))) . + 2009-09-05 13:34 . 2009-09-05 13:34 16384 c:\windows\temp\Perflib_Perfdata_18c.dat . (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "msnmsgr"="c:\programme\Windows Live\Messenger\MsnMsgr.Exe" [2007-10-18 5724184] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ZCfgSvc.exe"="c:\windows\system32\ZCfgSvc.exe" [2006-08-03 639040] "PRONoMgr.exe"="c:\programme\Intel\NCS\PROSet\PRONoMgr.exe" [2005-07-07 135168] [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\Sebring] 2006-08-03 01:20 188482 ----a-w- c:\windows\system32\LgNotify.dll [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32] "midi1"=xgusb.cpl [HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List] "%windir%\\system32\\sessmgr.exe"= "%windir%\\Network Diagnostic\\xpnetdiag.exe"= "c:\\Programme\\Windows Live\\Messenger\\msnmsgr.exe"= "c:\\Programme\\Windows Live\\Messenger\\livecall.exe"= "c:\\Programme\\iTunes\\iTunes.exe"= R3 NeroCd2k;NeroCd2k;c:\windows\system32\drivers\NeroCD2k.sys [16.04.2001 06:54 44227] S3 PAC207;Trust WB-1400T Webcam;c:\windows\system32\drivers\PFC027.SYS [14.05.2007 10:26 508288] . Inhalt des "geplante Tasks" Ordners . . ------- Zusätzlicher Suchlauf ------- . uStart Page = hxxp://www.google.com/ uInternet Settings,ProxyOverride = *.local IE: Nach Microsoft &Excel exportieren - c:\progra~1\MICROS~2\Office10\EXCEL.EXE/3000 DPF: DirectAnimation Java Classes - file://c:\windows\Java\classes\dajava.cab DPF: Microsoft XML Parser for Java - file://c:\windows\Java\classes\xmldso.cab . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-09-05 15:35 Windows 5.1.2600 Service Pack 2 NTFS Scanne versteckte Prozesse... Scanne versteckte Autostarteinträge... Scanne versteckte Dateien... Scan erfolgreich abgeschlossen versteckte Dateien: 0 ************************************************************************** . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- - - - - - - - > 'winlogon.exe'(872) c:\windows\system32\LgNotify.dll - - - - - - - > 'explorer.exe'(3360) c:\progra~1\WINDOW~2\wmpband.dll . ------------------------ Weitere laufende Prozesse ------------------------ . c:\windows\system32\S24EvMon.exe c:\programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe c:\programme\Java\jre6\bin\jqs.exe c:\windows\system32\RegSrvc.exe c:\programme\Analog Devices\SoundMAX\SMAgent.exe c:\windows\system32\wdfmgr.exe c:\windows\system32\wbem\wmiapsrv.exe c:\windows\system32\1XConfig.exe c:\windows\system32\wscntfy.exe . ************************************************************************** . Zeit der Fertigstellung: 2009-09-05 15:42 - PC wurde neu gestartet ComboFix-quarantined-files.txt 2009-09-05 13:42 ComboFix2.txt 2009-09-05 12:28 Vor Suchlauf: 3.594.731.520 Bytes frei Nach Suchlauf: 3.565.912.064 Bytes frei 133 |
![]() |
| Themen zu winlog.exe ist Backdoor.Agobot.LF? |
| aufsetzen, auswertung, dll, einstellungen, fehlermeldung, frage, google, hijack, hijackthis, laptop, logfile, microsoft, namen, nicht vorhanden, problem, prozess, registry, scan, schnelle hilfe, spybot, system, temp, usb-stick, verbindung, virenscanner, win xp, öffnen |