Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   nach SpyBot, AdAware & Co. - endlich alles weg??? (https://www.trojaner-board.de/24941-spybot-adaware-co-endlich-alles-weg.html)

rockscientist01 27.12.2005 12:27

nach SpyBot, AdAware & Co. - endlich alles weg???
 
Hi,

nachdem ich nun noch einige tools hab über meinen Rechner laufen lassen frage ich mich, ob noch wer was findet.
Danke euch wackeren Doktoren :-)

Agent Orange

Logfile of HijackThis v1.99.1
Scan saved at 12:21:31, on 27.12.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\P R O G R A M M E\AntiVir\AntiVir PersonalEdition Classic\sched.exe
D:\P R O G R A M M E\AntiVir\AntiVir PersonalEdition Classic\avguard.exe
e:\Website\AMP installation\Apache\Apache2\bin\Apache.exe
D:\P R O G R A M M E\pc anywhere\awhost32.exe
E:\Website\AMP installation\Apache\Apache2\bin\Apache.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\Explorer.EXE
D:\P R O G R A M M E\MS Powertoys\taskswitch.exe
D:\P R O G R A M M E\AntiVir\AntiVir PersonalEdition Classic\avgnt.exe
D:\P R O G R A M M E\SpamFighter\SFAgent.exe
D:\p r o g r a m m e\activesync\WCESCOMM.EXE
D:\P R O G R A M M E\XDCC Catcher Pro\catcher.exe
D:\P R O G R A M M E\XDCC Catcher Pro\tools\servlite.exe
D:\P R O G R A M M E\Office 2003\OFFICE11\OUTLOOK.EXE
d:\P R O G R A M M E\Office 2003\OFFICE11\WINWORD.EXE
D:\P R O G R A M M E\Firefox\firefox.exe
C:\Documents and Settings\Administrator\Desktop\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = about:blank
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [CoolSwitch] D:\P R O G R A M M E\MS Powertoys\taskswitch.exe
O4 - HKLM\..\Run: [KAVPersonal50] "D:\P R O G R A M M E\Kaspersky\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [avgnt] "D:\P R O G R A M M E\AntiVir\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [SPAMfighter Agent] "D:\P R O G R A M M E\SpamFighter\SFAgent.exe" update delay 60
O4 - HKCU\..\Run: [H/PC Connection Agent] "D:\p r o g r a m m e\activesync\WCESCOMM.EXE"
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Program Files\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\OFFICE~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Mobilen Favoriten erstellen - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - d:\p r o g r a m m e\activesync\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - d:\p r o g r a m m e\activesync\INetRepl.dll
O9 - Extra 'Tools' menuitem: Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - d:\p r o g r a m m e\activesync\INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\OFFICE~1\OFFICE11\REFIEBAR.DLL
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{5B65E222-3411-4391-8E36-6B3BF50DF243}: NameServer = 192.150.151.112
O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll
O20 - Winlogon Notify: RunOnceEx - C:\WINDOWS\system32\f02mlaf11d2.dll (file missing)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - H+BEDV Datentechnik GmbH - D:\P R O G R A M M E\AntiVir\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - H+BEDV Datentechnik GmbH - D:\P R O G R A M M E\AntiVir\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Apache2 - Unknown owner - e:\Website\AMP installation\Apache\Apache2\bin\Apache.exe" -k runservice (file missing)
O23 - Service: pcAnywhere Host Service (awhost32) - Symantec Corporation - D:\P R O G R A M M E\pc anywhere\awhost32.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSec.exe
O23 - Service: kavsvc - Kaspersky Lab - D:\P R O G R A M M E\Kaspersky\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: MySQL - Unknown owner - e:\Website\AMP.exe (file missing)
O23 - Service: Norton Ghost - Symantec Corporation - D:\P R O G R A M M E\norton ghost\Agent\PQV2iSvc.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exe

Weißnicht 28.12.2005 12:35

Dein Log ist soweit sauber lass aber mal zur Sicherheit die Datei taskswitch.exe
findest du unter D:\P R O G R A M M E\MS Powertoys\ bei virusscan.jotti.org/de/ scannen.


Alle Zeitangaben in WEZ +1. Es ist jetzt 21:22 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131