Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   HILFE, ich habe einige Trojaner - bitte um Eure Hilfe (https://www.trojaner-board.de/24151-hilfe-habe-einige-trojaner-bitte-um-hilfe.html)

flaemmchen 01.12.2005 19:00

HILFE, ich habe einige Trojaner - bitte um Eure Hilfe
 
Hi alle :huepp:!

Ich habe --> glaub ich --> mehrere Probleme :crazy: :crazy: :crazy: :

Zunächst mal die Auswertung meines Virenscanners *heul*

"Virensuche","2005/12/01","FLAEMMCHEN"
"Zeit","Ereignis","Quelltyp","Virenname","Dateiname","Erste Aktion","Zweite Aktion"
"14:08","Echtzeitsuche","Datei","TROJ_DLOADER.AFS","\Device\HarddiskVolumeShadowCopy1\Dokumente und Einstellungen\manu\Lokale Einstellungen\Temp\1213.4516","Quarantäne Fehlgeschlagen",""
"14:08","Echtzeitsuche","Datei","TROJ_DLOADER.ASP","\Device\HarddiskVolumeShadowCopy1\Dokumente und Einstellungen\manu\Lokale Einstellungen\Temp\5.qtdfmp","Quarantäne Fehlgeschlagen",""
"14:08","Echtzeitsuche","Datei","TROJ_DLOADER.AJP","\Device\HarddiskVolumeShadowCopy1\Dokumente und Einstellungen\manu\Lokale Einstellungen\Temp\6.qtdfmp","Quarantäne Fehlgeschlagen",""
"14:08","Echtzeitsuche","Datei","TROJ_DLOADER.ASO","\Device\HarddiskVolumeShadowCopy1\Dokumente und Einstellungen\manu\Lokale Einstellungen\Temp\7.qtdfmp","Quarantäne Fehlgeschlagen",""
"14:09","Echtzeitsuche","Datei","TROJ_DLOADER.AFS","\Device\HarddiskVolumeShadowCopy1\Dokumente und Einstellungen\manu\Lokale Einstellungen\Temp\qvxt3.game","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_SMALL.AWE","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0001070.exe","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_SMALL.AVC","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0001072.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_SPABOT.K","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0001073.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.AFS","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0001081.exe","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_SMALL.AWE","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0001074.exe","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_AGENT.AGW","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0001082.exe","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","ADW_CRAMTOOLB.A","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002016.dll","Zugriff verweigern",""
"14:25","Echtzeitsuche","Datei","ADW_CRAMTOOLB.A","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002017.dll","Zugriff verweigern",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.APK","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002043.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.APK","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002044.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.APK","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002045.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.APK","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002046.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.APK","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002047.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.APK","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002048.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.APK","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002049.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.APK","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002050.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.AFS","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002055.exe","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.AFS","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002057.exe","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_SMALL.AWE","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002059.exe","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.ASP","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002062.exe","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.AUD","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002066.exe","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_SMALL.AWE","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002067.exe","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.APK","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002069.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_SMALL.AVC","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002070.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_SPABOT.K","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002071.dll","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.AJP","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002072.exe","Quarantäne Fehlgeschlagen",""
"14:25","Echtzeitsuche","Datei","TROJ_DLOADER.ASO","\Device\HarddiskVolumeShadowCopy1\System Volume Information\_restore{F974E174-8380-48D2-9CF0-5DE6FAFE9559}\RP1\A0002073.exe","Quarantäne Fehlgeschlagen",""


Hier das Logfile:

Logfile of HijackThis v1.99.1
Scan saved at 18:49:10, on 01.12.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\SYSTEM32\SVCHOST.EXE
C:\WINDOWS\SYSTEM32\SPOOLSV.EXE
C:\WINDOWS\explorer.exe
C:\Programme\FreePDF_XP\fpassist.exe
C:\Programme\Java\jre1.5.0_04\bin\jusched.exe
C:\Programme\MessengerPlus! 3\MsgPlus.exe
C:\Programme\Trend Micro\Internet Security 14\pccguide.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Programme\MSI\Live Update 3\LMonitor.exe
C:\WINDOWS\system32\ctfmon.exe
C:\PROGRAMME\MSN MESSENGER\MSNMSGR.EXE
C:\Programme\Internet Explorer\iexplore.exe
C:\PROGRA~1\INTERN~1\IEXPLORE.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\PCCTLCOM.EXE
C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
C:\PROGRA~1\TRENDM~1\INTERN~2\TMPROXY.EXE
C:\PROGRA~1\TRENDM~1\INTERN~2\TMPFW.EXE
C:\PROGRAMME\SKYPE\PHONE\SKYPE.EXE
C:\PROGRAMME\MOZILLA FIREFOX\FIREFOX.EXE
C:\Programme\Trojancheck 6\tcguard.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\DOKUME~1\manuela\LOKALE~1\Temp\Temporäres Verzeichnis 2 für hijackthis.zip\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.aqsofrwhcdjvxhiqiniftovqq.com/7BE4bhb4_zfdJ/_NZuPyT5o7xOM4JJPQSzO8k_sh7wpiyqfy5mGuoigq2fC1xjkN.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.at/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://home.deu.chello.at/ssi/welcome/welcome.php?url=home
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer bereitgestellt von chello broadband n.v.
F2 - REG:system.ini: Shell=explorer.exe
O4 - HKLM\..\Run: [ChelloDesktop] C:\Programme\chello\ChelloDesktop.exe
O4 - HKLM\..\Run: [ChelloBackground] C:\Programme\chello\ChelloMessenger.exe
O4 - HKLM\..\Run: [FreePDF Assistant] C:\Programme\FreePDF_XP\fpassist.exe
O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_04\bin\jusched.exe
O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programme\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [flagbrowseglobalplay] C:\Dokumente und Einstellungen\All Users.WINDOWS\Anwendungsdaten\LIVE LOAD FLAG BROWSE\chic thunk.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Programme\Trend Micro\Internet Security 14\pccguide.exe"
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LiveMonitor] C:\Programme\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [activecopy] C:\DOKUME~1\manuela\ANWEND~1\STUPID~1\DefyMess.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_04\bin\npjpi150_04.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://home.deu.chello.at/ssi/welcome/welcome.php?url=home
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1133380246500
O17 - HKLM\System\CCS\Services\Tcpip\..\{A109938B-4A13-4A6E-9D07-9B43A392A9E5}: NameServer = 195.34.133.21,195.34.133.22
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - AppInit_DLLs: MsgPlusLoader.dll
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: Trend Micro Central Control Component (PcCtlCom) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\PcCtlCom.exe
O23 - Service: Trend Micro Real-time Service (Tmntsrv) - Trend Micro Incorporated. - C:\PROGRA~1\TRENDM~1\INTERN~2\Tmntsrv.exe
O23 - Service: Trend Micro Personal Firewall (TmPfw) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\TmPfw.exe
O23 - Service: Trend Micro Proxy Service (tmproxy) - Trend Micro Inc. - C:\PROGRA~1\TRENDM~1\INTERN~2\tmproxy.exe

Ich bin Euch für Eure Hilfe sehr dankbar und DANKE allen im Voraus!!!!

Liebe Grüße

manu

cacatoa 01.12.2005 21:39

Hi,
lade Dir mal clearprog und clicke an:
"alles löschen", wenn fertig auf beenden.
Dann Systemwiederherstellung ausschalten, Rechner aus, Rechner an, Systemwiederherstellung wieder anschalten; neu scannen, sollte alles weg sein.
cacatoa

Haui45 01.12.2005 21:45

Hi flaemmchen &cacatoa,

wenn ich mir die Sammlung [1] so anschaue, würde ich eher zum Neuaufsetzen [2] raten.

[1]
Zitat:

TROJ_DLOADER.AFS, TROJ_DLOADER.ASP, TROJ_DLOADER.AJP, TROJ_DLOADER.AFS, usw...
TROJ_SMALL.AWE, TROJ_SMALL.AWE, usw...
TROJ_SPABOT.K
ADW_CRAMTOOLB.A"
TROJ_AGENT.AGW
.
.
.
[2] http://www.trojaner-board.de/showpos...28&postcount=2


Gruß Haui


Alle Zeitangaben in WEZ +1. Es ist jetzt 02:43 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131