Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Hilfe (https://www.trojaner-board.de/16035-hilfe.html)

VirenMutterschiff 29.03.2005 23:40

Hilfe
 
Hallo,
erstmal sorry für den nichtssagenden Titel, aber mir fiel nix genaueres ein...
Mein Problem ist folgendes:

Ich war über Ostern im Urlaub und wärend ich abwesend war hat sich wohl irgendjemand intelligentes an meinem Rechner zuschaffen gemacht. Ergebnis diverse Viren und Trojaner...
Einige haben sich relativ leicht mit AVG entfernen lassen, allerdings leider nicht alle.
se.dll hab ich inzwischen auch über bestehende Posts in diesem Forum entfernen können.
Dennoch existieren aktuell noch folgende Probleme:
1. Ich kann den Desktophintergrund nicht ändern, stattdessen steht da ein Text von wegen: DANGER SPYWARE FOUND ON YOUR SYSTEM! (sowie einige Zeilen unwichtiges Blabla)Wenn ich versuche den Desktophintergrund zu ändern erhalte ich einen Fatalerror.
2. Ich kann keine Datei bzw. aufm Desktop, und im Explorer nicht rechtsklicken. IE rechtsklickt funktioniert hingegen.

Zitat:

HijackThis Log:
Logfile of HijackThis v1.99.1
Scan saved at 00:45:09, on 30.03.2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AVPersonal\AVGUARD.EXE
C:\WINDOWS\asuskbservice.exe
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\devldr32.exe
C:\HijackThis.exe
C:\Programme\Internet Explorer\IEXPLORE.EXE
C:\Programme\ICQ\Icq.exe
C:\Programme\AVPersonal\AVWIN.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Programme\IrfanView\Ebay\Ebay.htm
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE
O23 - Service: ASUSKeyboardService - ASUSTeK COMPUTER INC. - C:\WINDOWS\asuskbservice.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE
O23 - Service: Visual Studio Debugger Proxy Service (DbgProxy) - Unknown owner - C:\Programme\Microsoft Visual Studio.NET\Common7\Packages\Debugger\dbgproxy.exe (file missing)
O23 - Service: %NVSVC.name% (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
Was kann ich aktuell noch tun um um eine komplette Neuinstallation herumzukommen?

cronos 30.03.2005 00:00

Escan durchführen.

Bitte genau an die Anleitung halten, die in o.g. Link beschrieben ist:

Zur Sicherheit nochmal

Ecan muss in den Ordner c:\bases entpackt werden.Ordner musst du selbst erstellen.
Danach updaten.

Einstellungen wie folgt:
http://www.trojaner-info.de/hijacker/bilder/escan2.jpg


Scannen im abgesicherten Modusbei deaktivierter Systemwiederherstellung:
http://www.systemwiederherstellung-d...indows-xp.html

neu booten und uns die Ergebnisse mitteilen:

öffne die mwav.log -> Bearbeiten -> Suchen -> infected eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen." (Zitat Cidre)

VirenMutterschiff 30.03.2005 14:28

Zitat:

Wed Mar 30 14:26:29 2005 => File C:\WINDOWS\System32\x3yy\gdkeehkl.exe infected by "Trojan-Downloader.Win32.Small.aph" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:26:47 2005 => System found infected with IstBAR Spyware/Adware ({0985c112-2562-46f2-8da6-92648ba4630f})! Action taken: No Action Taken.
Wed Mar 30 14:26:47 2005 => File System Found infected by "IstBAR Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => System found infected with IstBAR Spyware/Adware ({67907b3c-a6ef-4a01-99ad-3fcd5f526429})! Action taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => File System Found infected by "IstBAR Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => System found infected with Alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => File System Found infected by "Alexa Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => System found infected with Gator Spyware/Adware ({21FFB6C0-0DA1-11D5-A9D5-00500413153C})! Action taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => File System Found infected by "Gator Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => System found infected with 180Solutions Spyware/Adware ({30d02401-6a81-11d0-8274-00c04fd5ae38})! Action taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => File System Found infected by "180Solutions Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => System found infected with VX2 Spyware/Adware ({0E5CBF21-D15F-11D0-8301-00AA005B4383})! Action taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => File System Found infected by "VX2 Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => System found infected with AltnetBDE Spyware/Adware (adm4.adm4)! Action taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => File System Found infected by "AltnetBDE Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => System found infected with AltnetBDE Spyware/Adware (adm25.adm25)! Action taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => File System Found infected by "AltnetBDE Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => System found infected with cydoor Spyware/Adware! Action taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => File System Found infected by "cydoor Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => System found infected with myway Spyware/Adware! Action taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => File System Found infected by "myway Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => System found infected with Web_Rebates Spyware/Adware! Action taken: No Action Taken.
Wed Mar 30 14:26:48 2005 => File System Found infected by "Web_Rebates Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:29:46 2005 => System found infected with AltnetBDE Spyware/Adware (altnet signing module.exe)! Action taken: No Action Taken.
Wed Mar 30 14:29:46 2005 => File System Found infected by "AltnetBDE Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:29:46 2005 => System found infected with AltnetBDE Spyware/Adware (adm.exe)! Action taken: No Action Taken.
Wed Mar 30 14:29:46 2005 => File System Found infected by "AltnetBDE Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:29:46 2005 => System found infected with WindUpdate Spyware/Adware (ide21201.vxd)! Action taken: No Action Taken.
Wed Mar 30 14:29:46 2005 => File System Found infected by "WindUpdate Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:29:48 2005 => File C:\WINDOWS\desktop.html infected by "Trojan-Clicker.Win32.Spywad.b" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:29:50 2005 => File C:\WINDOWS\ms1.exe infected by "Trojan-Downloader.Win32.Small.api" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:29:50 2005 => File C:\WINDOWS\ms2.exe infected by "Trojan-Clicker.Win32.Spywad.b" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:29:50 2005 => File C:\WINDOWS\ms3.exe infected by "Backdoor.Win32.Haxdoor.cn" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:29:51 2005 => File C:\WINDOWS\popup.html infected by "Trojan-Clicker.Win32.Spywad.b" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:29:56 2005 => File C:\WINDOWS\System32\Apv.exe infected by "Trojan-Clicker.Win32.Spywad.b" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:29:59 2005 => File C:\WINDOWS\System32\cd_clint.dll infected by "not-a-virus:AdWare.Cydoor" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:30:13 2005 => File C:\WINDOWS\System32\Ere.exe infected by "Trojan-Clicker.Win32.Spywad.b" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:30:46 2005 => File C:\WINDOWS\System32\ntddetect.exe infected by "Trojan-Proxy.Win32.Agent.eh" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:31:12 2005 => File C:\WINDOWS\System32\tksrv99.exe infected by "Trojan-Downloader.Win32.Esepor.y" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:31:14 2005 => File C:\WINDOWS\System32\unic2_32.dll infected by "Trojan-Downloader.Win32.Small.aph" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:40:53 2005 => File C:\DOKUME~1\thomas\LOKALE~1\TEMPOR~1\Content.IE5\JY4J7X4T\adv156[1].htm infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:40:53 2005 => File C:\DOKUME~1\thomas\LOKALE~1\TEMPOR~1\Content.IE5\JY4J7X4T\adv157[1].htm infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken.
Wed Mar 30 14:41:23 2005 => File C:\DOKUME~1\thomas\LOKALE~1\TEMPOR~1\Content.IE5\JY4J7X4T\loadadv157[1].exe infected by "Trojan-Downloader.Win32.Small.vg" Virus. Action Taken: No Action Taken.

Wed Mar 30 14:58:19 2005 => Total Objects Scanned: 61317
Wed Mar 30 14:58:19 2005 => Total Virus(es) Found: 31
Wed Mar 30 14:58:19 2005 => Total Disinfected Files: 0
Wed Mar 30 14:58:19 2005 => Total Files Renamed: 0
Wed Mar 30 14:58:19 2005 => Total Deleted Objects: 0
Wed Mar 30 14:58:19 2005 => Total Errors: 6
Wed Mar 30 14:58:19 2005 => Time Elapsed: 00:32:27
Wed Mar 30 14:58:19 2005 => Virus Database Date: 2005/03/28
Wed Mar 30 14:58:19 2005 => Virus Database Count: 123733
Sieht offensichtlich relativ besch...en aus.
Komme ich noch um eine komplette Neuinstallation herum?


Alle Zeitangaben in WEZ +1. Es ist jetzt 15:22 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131