Meinen Log-File bitte anschauen Hallo! Ich weis nicht, ob ich mir etwas eingefangen habe... könntet ihr euch den log mal anschauen, pls?!? DANKE!!! :bussi: _______________ Logfile of HijackThis v1.99.1 Scan saved at 20:11:36, on 12.11.2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe C:\WINDOWS\Explorer.EXE C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\Programme\Synaptics\SynTP\SynTPLpr.exe C:\Programme\Synaptics\SynTP\SynTPEnh.exe C:\WINDOWS\AGRSMMSG.exe C:\Programme\ltmoh\Ltmoh.exe C:\Programme\Launch Manager\LaunchAp.exe C:\Programme\Launch Manager\PowerKey.exe C:\Programme\Launch Manager\HotkeyApp.exe C:\Programme\Launch Manager\CtrlVol.exe C:\Programme\Launch Manager\Wbutton.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe C:\Programme\ClemosDateien\Norton SystemWorks 2004 Professional\Norton Ghost\GhostStartTrayApp.exe C:\WINDOWS\System32\ctfmon.exe C:\WINDOWS\System32\Ati2evxx.exe C:\Programme\ClemosDateien\Norton SystemWorks 2004 Professional\Norton Ghost\GhostStartService.exe C:\Programme\ClemosDateien\Norton SystemWorks 2004 Professional\Norton Antivirus\navapsvc.exe C:\PROGRA~1\CLEMOS~1\NORTON~1\NORTON~2\NPROTECT.EXE C:\PROGRA~1\CLEMOS~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE F:\!GAMES!\Programme\Alcohol120%\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\svchost.exe C:\DOKUME~1\CLEMENS\LOKALE~1\TEMP\_VWUPSRV.EXE C:\WINDOWS\System32\UAService7.exe C:\Programme\ClemosDateien\Norton SystemWorks 2004 Professional\Norton Antivirus\SAVScan.exe F:\!GAMES!\Programme\WinAmp\Winamp\winamp.exe F:\!GAMES!\Programme\ICQLite\ICQLite.exe F:\!GAMES!\Programme\Firefox\firefox.exe C:\Programme\Messenger\msmsgs.exe F:\!GAMES!\Programme\HJT\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://global.acer.com R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://global.acer.com/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\!GAMES!\Programme\Adobe\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\ClemosDateien\Norton SystemWorks 2004 Professional\Norton Antivirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\ClemosDateien\Norton SystemWorks 2004 Professional\Norton Antivirus\NavShExt.dll O4 - HKLM\..\Run: [LaunchApp] LaunApp O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe O4 - HKLM\..\Run: [LtMoh] C:\Programme\ltmoh\Ltmoh.exe O4 - HKLM\..\Run: [LaunchAp] C:\Programme\Launch Manager\LaunchAp.exe O4 - HKLM\..\Run: [PowerKey] "C:\Programme\Launch Manager\PowerKey.exe" O4 - HKLM\..\Run: [HotkeyApp] C:\Programme\Launch Manager\HotkeyApp.exe O4 - HKLM\..\Run: [CtrlVol] C:\Programme\Launch Manager\CtrlVol.exe O4 - HKLM\..\Run: [Wbutton] "C:\Programme\Launch Manager\Wbutton.exe" O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [GhostStartTrayApp] C:\Programme\ClemosDateien\Norton SystemWorks 2004 Professional\Norton Ghost\GhostStartTrayApp.exe O4 - HKLM\..\Run: [AcctMgr] C:\Programme\ClemosDateien\Norton SystemWorks 2004 Professional\Password Manager\AcctMgr.exe /startup O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKCU\..\Run: [Compliant] ikwfqdqpc.exe O4 - HKCU\..\Run: [ChkMail] 89‹ O4 - HKCU\..\RunOnce: [ICQ Lite] F:\!GAMES!\Programme\ICQLite\ICQLite.exe -trayboot O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Microsoft Office.lnk = F:\!GAMES!\Programme\Microsoft Office 2000 Professional\Office\OSA9.EXE O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\!GAMES!\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - F:\!GAMES!\Programme\ICQLite\ICQLite.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe O23 - Service: AVM FRITZ!web Routing Service (de_serv) - AVM Berlin - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe O23 - Service: GBPoll - Unknown owner - C:\Programme\ClemosDateien\Norton SystemWorks\Norton GoBack\GBPoll.exe (file missing) O23 - Service: GhostStartService - Symantec Corporation - C:\Programme\ClemosDateien\Norton SystemWorks 2004 Professional\Norton Ghost\GhostStartService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Norton AntiVirus Auto-Protect-Dienst (navapsvc) - Symantec Corporation - C:\Programme\ClemosDateien\Norton SystemWorks 2004 Professional\Norton Antivirus\navapsvc.exe O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\PROGRA~1\CLEMOS~1\NORTON~1\NORTON~2\NPROTECT.EXE O23 - Service: NT Services - Symantec Corporation - (no file) O23 - Service: SAVScan - Symantec Corporation - C:\Programme\ClemosDateien\Norton SystemWorks 2004 Professional\Norton Antivirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\CLEMOS~1\NORTON~1\NORTON~2\SPEEDD~1\NOPDB.EXE O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - F:\!GAMES!\Programme\Alcohol120%\Alcohol 120\StarWind\StarWindService.exe O23 - Service: AntiVir Update Temp (TmpUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\DOKUME~1\CLEMENS\LOKALE~1\TEMP\_VWUPSRV.EXE O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - C:\WINDOWS\System32\UAService7.exe |
Hallo mensClem, lade Dir clearprog 1.4.1 final und nimm eine Datenträgerbereinigung vor (Programm starten Häckchen bei "Alles Löschen" und auf "Löschen" klicken). Lösche ebenfalls den Quaratäne-Ordener Deines Antivir-Programmes. Scanne dann Dein System mit Escan . Bitte erst aufmerkam lesen und dann scannen. Teile das Ergebnis mittels der "find.bat" mit. dartus |
eScan fertig Hier ist mein eScan... Hab alles so gemacht wie beschrieben, hier die escan_neu. txt: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Sun Nov 13 09:57:23 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Sun Nov 13 09:57:23 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Sun Nov 13 09:57:24 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Sun Nov 13 09:57:29 2005 => System found infected with cydoor.topicks.a Spyware/Adware (settings.dat)! Action taken: No Action Taken. Sun Nov 13 09:57:30 2005 => System found infected with powerreg scheduler Spyware/Adware (norton disk doctor.lnk)! Action taken: No Action Taken. Sun Nov 13 09:57:30 2005 => System found infected with powerreg scheduler Spyware/Adware (norton disk doctor.lnk)! Action taken: No Action Taken. Sun Nov 13 10:09:25 2005 => Total Disinfected Files: 0 Sun Nov 13 10:12:06 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Sun Nov 13 10:12:06 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Sun Nov 13 10:12:06 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Sun Nov 13 10:12:13 2005 => System found infected with cydoor.topicks.a Spyware/Adware (settings.dat)! Action taken: No Action Taken. Sun Nov 13 10:12:14 2005 => System found infected with powerreg scheduler Spyware/Adware (norton disk doctor.lnk)! Action taken: No Action Taken. Sun Nov 13 10:12:14 2005 => System found infected with powerreg scheduler Spyware/Adware (norton disk doctor.lnk)! Action taken: No Action Taken. Sun Nov 13 10:35:28 2005 => File C:\Programme\ClemosDateien\Norton SystemWorks 2004 Professional\Norton Antivirus\Quarantine\401E6B30 infected by "Trojan-Downloader.BAT.Ftp.c" Virus! Action Taken: No Action Taken. Sun Nov 13 10:57:24 2005 => Total Disinfected Files: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "offending" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Sun Nov 13 09:57:25 2005 => Offending Key found: HKLM\Software\edonkey2000 !!! Sun Nov 13 09:57:29 2005 => Offending file found: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\symantec\common client\settings.dat Sun Nov 13 09:57:30 2005 => Offending file found: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\norton systemworks\norton utilities\norton disk doctor.lnk Sun Nov 13 09:57:30 2005 => Offending file found: C:\Dokumente und Einstellungen\All Users\Startmenü\programme\norton systemworks\norton utilities\norton disk doctor.lnk Sun Nov 13 10:12:08 2005 => Offending Key found: HKLM\Software\edonkey2000 !!! Sun Nov 13 10:12:13 2005 => Offending file found: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\symantec\common client\settings.dat Sun Nov 13 10:12:14 2005 => Offending file found: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\norton systemworks\norton utilities\norton disk doctor.lnk Sun Nov 13 10:12:14 2005 => Offending file found: C:\Dokumente und Einstellungen\All Users\Startmenü\programme\norton systemworks\norton utilities\norton disk doctor.lnk ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Sun Nov 13 10:09:25 2005 => Total Virus(es) Found: 7 Sun Nov 13 10:57:24 2005 => Total Virus(es) Found: 8 Sun Nov 13 10:09:25 2005 => Total Errors: 219 Sun Nov 13 10:57:24 2005 => Total Errors: 222 Sun Nov 13 10:09:25 2005 => Time Elapsed: 00:13:10 Sun Nov 13 10:57:24 2005 => Time Elapsed: 00:46:11 Sun Nov 13 10:09:25 2005 => Total Objects Scanned: 31823 Sun Nov 13 10:57:24 2005 => Total Objects Scanned: 69060 Sun Nov 13 09:55:17 2005 => Virus Database Date: 2005/11/11 Sun Nov 13 10:09:25 2005 => Virus Database Date: 2005/11/11 Sun Nov 13 10:09:29 2005 => Virus Database Date: 2005/11/11 Sun Nov 13 10:11:04 2005 => Virus Database Date: 2005/11/11 Sun Nov 13 10:57:24 2005 => Virus Database Date: 2005/11/11 Sun Nov 13 11:11:36 2005 => Virus Database Date: 2005/11/11 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~ © Haui ;-) ~~~~~~~ ~~~~~~~ Dank an Cidre ~~~~~~~ |
Alle Zeitangaben in WEZ +1. Es ist jetzt 14:21 Uhr. |
Copyright ©2000-2024, Trojaner-Board