Warum kostenlos registrieren?

Nur als registriertes Mitglied hast Du vollen Zugriff auf alle Funktionen unserer Website. So kannst Du eigene Fragen stellen und hast die volle Übersicht über neue interessante Themen im Forum.
Jetzt kostenlos registrieren.

Login


hab eine cpu auslastung von 100%..hilfe

Warnungen vor Sicherheitslücken und Hilfe beim Enfernen von Viren, Würmern und Trojanern.

hab eine cpu auslastung von 100%..hilfe

Beitragvon arjang am 02.01.2005, 16:19

hallo leute ich bin hier neu im forum..also sorry wenn ich was falsch mache!

ich hab seit einiger zeit immer eine sehr hohe cpu auslastung :

Logfile of HijackThis v1.99.0
Scan saved at 15:12:38, on 25.09.2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\LEXBCES.EXE
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\system32\LEXPPS.EXE
G:\Programme\Softwin\BitDefender8\bdoesrv.exe
G:\Programme\Softwin\BitDefender8\bdswitch.exe
G:\WINDOWS\SOUNDMAN.EXE
G:\Programme\CyberLink\PowerDVD\PDVDServ.exe
G:\WINDOWS\System32\LXSUPMON.EXE
G:\Programme\Messenger\msmsgs.exe
G:\Programme\Windows Media Player\wmplayer.exe
G:\WINDOWS\System32\nvsvc32.exe
G:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe
G:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe
G:\Programme\Softwin\BitDefender8\vsserv.exe
G:\Programme\Softwin\BitDefender8\bdmcon.exe
G:\WINDOWS\explorer.exe
G:\Programme\oDC\oDC.exe
G:\Programme\ICQLite\ICQLite.exe
G:\WINDOWS\System32\wuauclt.exe
G:\Programme\Mozilla Firefox\firefox.exe
G:\Programme\WinRAR\WinRAR.exe
G:\DOKUME~1\jigga\LOKALE~1\Temp\Rar$EX00.282\HijackThis.exe

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - g:\programme\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - G:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - g:\programme\google\googletoolbar1.dll
O4 - HKLM\..\Run: [MS Office32cb Startup] OfficeGUI32cb.exe
O4 - HKLM\..\Run: [RSPC Driver] xcfi.exe
O4 - HKLM\..\Run: [BDMCon] G:\Programme\Softwin\BitDefender8\\bdmcon.exe
O4 - HKLM\..\Run: [BDOESRV] G:\Programme\Softwin\BitDefender8\\bdoesrv.exe
O4 - HKLM\..\Run: [BDNewsAgent] G:\Programme\Softwin\BitDefender8\\bdnagent.exe
O4 - HKLM\..\Run: [BDSwitchAgent] G:\Programme\Softwin\BitDefender8\\bdswitch.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] G:\Programme\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [LXSUPMON] G:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TrojanScanner] G:\Programme\Trojan Remover\Trjscan.exe
O4 - HKLM\..\RunServices: [MS Office32cb Startup] OfficeGUI32cb.exe
O4 - HKLM\..\RunServices: [RSPC Driver] xcfi.exe
O4 - HKCU\..\Run: [MSMSGS] "G:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Scan Spyware] "G:\Programme\ScanSpyware v3.7\Scanner.exe"
O4 - HKCU\..\Run: [RSPC Driver] xcfi.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] G:\Programme\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Microsoft Office.lnk = G:\Programme\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://G:\Programme\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://G:\Programme\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://G:\Programme\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://G:\Programme\Google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - G:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - G:\Programme\ICQLite\ICQLite.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{337E5CD3-5A44-4D1C-BDC3-85C5A3583249}: NameServer = 213.191.92.87 213.191.74.18
O23 - Service: BitDefender Scan Server - Unknown - G:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: LexBce Server - Lexmark International, Inc. - G:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - G:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sandra Data Service - SiSoftware - G:\Programme\SiSoftware\SiSoftware Sandra Professional 2005\RpcDataSrv.exe
O23 - Service: Sandra Service - SiSoftware - G:\Programme\SiSoftware\SiSoftware Sandra Professional 2005\RpcSandraSrv.exe
O23 - Service: BitDefender Virus Shield - Unknown - G:\Programme\Softwin\BitDefender8\vsserv.exe
O23 - Service: BitDefender Communicator - Softwin - G:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe



ich hoffe dass ihrt mir helfen könnt...danke im voraus! :D
Zuletzt geändert von arjang am 02.01.2005, 17:34, insgesamt 1-mal geändert.
arjang
 
Beiträge: 8
Registriert: 02.01.2005, 16:15


Beitragvon arjang am 02.01.2005, 17:25

heh was hat mana denn hier it meinem beitrag gemacht? :shock: :?: :?: :?:
arjang
 
Beiträge: 8
Registriert: 02.01.2005, 16:15

Beitragvon Nikita am 03.01.2005, 13:40

Hallo@arjang

Deaktivieren Wiederherstellung
«XP
http://service1.symantec.com/SUPPORT/IN ... 7105707924
(kannst du nach der Reinigung wieder aktivieren)

#öffne das HijackThis-->> Button "scan" -->> Häkchen setzen -->> Button "Fix checked" -->> PC neustarten


O4 - HKLM\..\Run: [MS Office32cb Startup] OfficeGUI32cb.exe
O4 - HKLM\..\Run: [RSPC Driver] xcfi.exe
O4 - HKLM\..\RunServices: [MS Office32cb Startup] OfficeGUI32cb.exe
O4 - HKLM\..\RunServices: [RSPC Driver] xcfi.exe
O4 - HKCU\..\Run: [RSPC Driver] xcfi.exe

PC neustarten

Lade die Killbox.

KillBox
http://www.bleepingcomputer.com/files/killbox.php

kopiere rein:

G:\WINDOWS\System32\OfficeGUI32cb.exe
G:\WINDOWS\System32\xcfi.exe

<Delete File on Reboot
und klick auf das rote Kreuz,
wenn gefragt wird, ob reboot-> klicke auf "no",und kopiere das naechste rein, erst beim letzten auf "yes"

PC neustarten

http://bilder.informationsarchiv.net/Nikitas_Tools/
Lade: SYS-UP.zip
entpacke und klicke: SysUp.exe (DOS oeffnet sich)
TrendMikro -->scan (poste mir das Log vom Scann)

#eScan
ftp://mwti.matrix.lv/download/tools/
erstelle den Ordner c:\bases
mwav.exe runterladen, die Datei in den Ordner c:\bases (wichtig!) entpacken und danach kavupd.exe (Update- in DOS) ausführen

gehe in den abgesicherten Modus
http://www.tu-berlin.de/www/software/vi ... mode.shtml

und den Scanner mit der "mwav.exe"[oder:MWAVSCAN.COM] starten. Alle Häkchen setzen :
Auswählen: "all files", Memory, Startup-Folders, Registry, System Folders,
Services, Drive/All Local drives, Folder [C:\WINDOWS], Include SubDirectory
-->und "Scan " klicken.

mache bitte folgendes:
nun öffnest du mit dem editor, die mwav.txt und gehst unter bearbeiten -> suchen, hier gibst du infected ein

Bild

jene zeile in der infected steht, markieren, und hier einfügen, weitersuchen usw.
und ganz unten steht die zusammenfassung, diese auch hier posten
:)
+
das neue Log vom HijackThis
+
#Ad-aware SE Personal 1.05 Updated (Scan-Log posten)
http://fileforum.betanews.com/detail/965718306/1
+
Search&Destroy
http://www.safer-networking.org/de/download/index.html
Spybot - Search && Destroy process list report,-->bitte abkopieren und posten
-----------------------------------------------------------------------------------------

#Internet Explorer 6 Service Pack 1
http://www.microsoft.com/downloads/deta ... B602228DE6

#Patches, Service Packs und Tools (XP)-->Lade SP1 oder SP2 (wenn du eine gueltige XP-cdkey hast)
http://www.rz.uni-freiburg.de/pc/sys/winxp/index.php

Sygate-free (Firewall)
http://www.blitzbox-download.com/spf.exe
Nikita
Moderator
 
Beiträge: 11478
Registriert: 07.12.2003, 16:53
Wohnort: Lissabon

Beitragvon arjang am 03.01.2005, 15:25

also erstmal danke für die ausführliche hilfe nikita!

hier ist der log con sysup:



/--------------------------------------------------------------\
| Trend Micro Sysclean Package |
| Copyright 2002, Trend Micro, Inc. |
| http://www.trendmicro.com |
\--------------------------------------------------------------/


2004-09-26, 13:49:50, Auto-clean mode specified.
2004-09-26, 13:49:50, Running scanner "G:\DOKUME~1\JIGGA\DESKTOP\TSC.BIN"...
2004-09-26, 13:50:26, Scanner "G:\DOKUME~1\JIGGA\DESKTOP\TSC.BIN" has finished running.
2004-09-26, 13:50:26, TSC Log:

Damage Cleanup Engine (DCE) 3.8(Build 1019)
Windows XP(Build 2600: )

Start time : So Sep 26 2004 13:49:51

Load Damage Cleanup Template (DCT) "G:\DOKUME~1\JIGGA\DESKTOP\tsc.ptn" (version 477) [success]

Complete time : So Sep 26 2004 13:50:26
Execute pattern count(1644), Virus found count(0), Virus clean count(0), Clean failed count(0)

2004-09-26, 13:58:22, An error was detected on "C:\System Volume Information\*.*": Zugriff verweigert
2004-09-26, 13:59:30, Running scanner "G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN"...
2004-09-26, 14:00:02, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 9/26/2004 13:59:30
VSAPI Engine Version : 7.000-1004
VSCANTM Version : 1.1-1001
Virus Pattern Version : 327 (84373 Patterns) (2005/01/01) (232700)
Command Line: G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=G:\DOKUME~1\JIGGA\DESKTOP

238 files have been read.
238 files have been checked.
162 files have been scanned.
689 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/26/2004 14:00:02
---------*---------*---------*---------*---------*---------*---------*---------*
2004-09-26, 14:00:02, Files Clean:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 9/26/2004 13:59:30
VSAPI Engine Version : 7.000-1004
VSCANTM Version : 1.1-1001
Virus Pattern Version : 327 (84373 Patterns) (2005/01/01) (232700)
Command Line: G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=G:\DOKUME~1\JIGGA\DESKTOP

238 files have been read.
238 files have been checked.
162 files have been scanned.
689 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/26/2004 14:00:02 30 seconds (29.63 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2004-09-26, 14:00:02, Clean Fail:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 9/26/2004 13:59:30
VSAPI Engine Version : 7.000-1004
VSCANTM Version : 1.1-1001
Virus Pattern Version : 327 (84373 Patterns) (2005/01/01) (232700)
Command Line: G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=G:\DOKUME~1\JIGGA\DESKTOP

238 files have been read.
238 files have been checked.
162 files have been scanned.
689 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/26/2004 14:00:02 30 seconds (29.63 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2004-09-26, 14:00:02, Scanner "G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN" has finished running.
2004-09-26, 14:02:09, An error was detected on "F:\System Volume Information\*.*": Zugriff verweigert
2004-09-26, 14:02:09, Running scanner "G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN"...
2004-09-26, 14:02:28, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 9/26/2004 14:02:12
VSAPI Engine Version : 7.000-1004
VSCANTM Version : 1.1-1001
Virus Pattern Version : 327 (84373 Patterns) (2005/01/01) (232700)
Command Line: G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 F:\*.* /P=G:\DOKUME~1\JIGGA\DESKTOP

179 files have been read.
179 files have been checked.
84 files have been scanned.
186 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/26/2004 14:02:28
---------*---------*---------*---------*---------*---------*---------*---------*
2004-09-26, 14:02:28, Files Clean:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 9/26/2004 14:02:12
VSAPI Engine Version : 7.000-1004
VSCANTM Version : 1.1-1001
Virus Pattern Version : 327 (84373 Patterns) (2005/01/01) (232700)
Command Line: G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 F:\*.* /P=G:\DOKUME~1\JIGGA\DESKTOP

179 files have been read.
179 files have been checked.
84 files have been scanned.
186 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/26/2004 14:02:28 15 seconds (15.45 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2004-09-26, 14:02:28, Clean Fail:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 9/26/2004 14:02:12
VSAPI Engine Version : 7.000-1004
VSCANTM Version : 1.1-1001
Virus Pattern Version : 327 (84373 Patterns) (2005/01/01) (232700)
Command Line: G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 F:\*.* /P=G:\DOKUME~1\JIGGA\DESKTOP

179 files have been read.
179 files have been checked.
84 files have been scanned.
186 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/26/2004 14:02:28 15 seconds (15.45 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2004-09-26, 14:02:28, Scanner "G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN" has finished running.
2004-09-26, 14:02:31, An error occurred while scanning file "G:\Dokumente und Einstellungen\jigga\NTUSER.DAT": Zugriff verweigert
2004-09-26, 14:02:31, An error occurred while scanning file "G:\Dokumente und Einstellungen\jigga\ntuser.dat.LOG": Zugriff verweigert
2004-09-26, 14:02:32, An error occurred while scanning file "G:\Dokumente und Einstellungen\jigga\Anwendungsdaten\Mozilla\Firefox\Profiles\t78v4qaw.default\parent.lock": Zugriff verweigert
2004-09-26, 14:04:20, An error occurred while scanning file "G:\Dokumente und Einstellungen\jigga\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat": Zugriff verweigert
2004-09-26, 14:04:20, An error occurred while scanning file "G:\Dokumente und Einstellungen\jigga\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG": Zugriff verweigert
2004-09-26, 14:04:35, An error occurred while scanning file "G:\Dokumente und Einstellungen\LocalService\NTUSER.DAT": Zugriff verweigert
2004-09-26, 14:04:35, An error occurred while scanning file "G:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG": Zugriff verweigert
2004-09-26, 14:04:35, An error occurred while scanning file "G:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat": Zugriff verweigert
2004-09-26, 14:04:35, An error occurred while scanning file "G:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG": Zugriff verweigert
2004-09-26, 14:04:35, An error occurred while scanning file "G:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT": Zugriff verweigert
2004-09-26, 14:04:35, An error occurred while scanning file "G:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG": Zugriff verweigert
2004-09-26, 14:04:35, An error occurred while scanning file "G:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat": Zugriff verweigert
2004-09-26, 14:04:35, An error occurred while scanning file "G:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG": Zugriff verweigert
2004-09-26, 14:09:50, An error was detected on "G:\System Volume Information\*.*": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\ALHLP.EXE-09E4DD4C.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\AUTORUN.EXE-02204536.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\BDLITE.EXE-1C5C3A9F.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\BDMCON.EXE-1E97D168.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\BDSS.EXE-1F227E82.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\CMD.EXE-137A0D53.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\COVERXP.EXE-2A3F4D9F.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\DIVX PLAYER.EXE-0F2332C3.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\DUMPREP.EXE-1C032A1C.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\DWWIN.EXE-002B6E58.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\EMULE.EXE-2900D96A.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\EXPLORER.EXE-05416907.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\FIREFOX.EXE-3425AEB8.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\FKI3.EXE-03A520CC.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\FTP.EXE-0BF597B1.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\HELPCTR.EXE-38BC4EC7.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\HELPSVC.EXE-281F45D0.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\HIJACKTHIS.EXE-2D4DBFD3.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\HIJACKTHIS.EXE-33A43BF3.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\ICQLITE.EXE-27EB5A87.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\IKERNEL.EXE-3480CA12.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\IMAGEREADY.EXE-23C2A9A4.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\IMAPI.EXE-10859813.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\IS-77FLR.TMP-041E4905.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\IS-FPINB.TMP-10A8420E.pf": Zugriff verweigert
2004-09-26, 14:11:20, Could not set file for reading on "G:\WINDOWS\Prefetch\IS-IFBEC.TMP-048610EB.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\IS-RRPH8.TMP-03AAC533.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\IS-U4IIL.TMP-053CD35F.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\KILLBOX.EXE-00319B71.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\Layout.ini": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\LOGON.SCR-075DDDCD.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\LOGONUI.EXE-3164D1CB.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\LXSUPMON.EXE-1303A53C.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\MSCONFIG.EXE-1501BCEB.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\MSIEXEC.EXE-0CCC6E74.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\MSPAINT.EXE-3AA7BA9F.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\NOTEPAD.EXE-08F3A979.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\NOTEPAD.EXE-14D8974C.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\NTVDM.EXE-368D7CDA.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\NVSVC32.EXE-1EE2BBFD.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\ODC.EXE-20D0396F.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\PDVDSERV.EXE-0BE900A6.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\POWERDVD.EXE-31925651.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\REGEDIT.EXE-17A382F4.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\RMVTRJAN.EXE-2A0E3E2B.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\RPCSANDRASRV.EXE-1552211B.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\RUNDLL32.EXE-2E765725.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\RUNDLL32.EXE-41D4F8AC.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\RUNDLL32.EXE-465FC515.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\RUNDLL32.EXE-53FC111E.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\RUNDLL32.EXE-578F11B2.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\RUNDLL32.EXE-5C5FFFE7.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\RUNONCE.EXE-246F7E39.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\SANDRA.EXE-2A3F70F4.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\SCANNER.EXE-346FDFA6.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\SERVICES.EXE-06AC3173.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\SETUP.EXE-1F1F821C.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\SETUP.EXE-21719C8C.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\SETUP.EXE-31AD726C.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\SETUP.EXE-32D4C978.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\SHRINKANDBURN.EXE-23F0CD92.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\SNDVOL32.EXE-1AA68677.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\SVCHOST.EXE-072604B0.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\SYSCLEAN.COM-34211DCD.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\SYSCLEAN.EXE-2BCAB8E8.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\TASKMGR.EXE-20E19D70.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\TFTP.EXE-300450DC.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\TRJSETUP.EXE-07C49618.pf": Zugriff verweigert
2004-09-26, 14:11:21, Could not set file for reading on "G:\WINDOWS\Prefetch\TSC.BIN-0AD66E2A.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\UBIAUTORUN.EXE-136B0906.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\UNINS000.EXE-122178D4.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\UPGREPL.EXE-359F0075.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\VBOXM.DLL-0E1828E6.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\VSCANTM.BIN-35EAFD40.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\VSETUPT.EXE-1BB4B06E.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\VSSERV.EXE-0BC6F303.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\WGET.EXE-0CCE2475.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\WINRAR.EXE-1F2395DA.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\WINSYSCLEAN.EXE-035CB6F2.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\WINTASKS.EXE-164257F0.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\WINTASKSPROTRIAL.EXE-27255A18.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\WINUHA 2.0 BUILD 2003.12.31 B-337B6000.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\WINUHA.EXE-10618194.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\WMIPRVSE.EXE-0E69CB0B.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\WMPLAYER.EXE-06A827DC.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\WORDPAD.EXE-0C383E23.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\WUAUCLT.EXE-12D8E25E.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\XCOMMSVR.EXE-01DB56C7.pf": Zugriff verweigert
2004-09-26, 14:11:22, Could not set file for reading on "G:\WINDOWS\Prefetch\_IU14D2N.TMP-0CC6EC12.pf": Zugriff verweigert
2004-09-26, 14:12:34, An error occurred while scanning file "G:\WINDOWS\system32\config\default": Zugriff verweigert
2004-09-26, 14:12:34, An error occurred while scanning file "G:\WINDOWS\system32\config\default.LOG": Zugriff verweigert
2004-09-26, 14:12:34, An error occurred while scanning file "G:\WINDOWS\system32\config\SAM": Zugriff verweigert
2004-09-26, 14:12:34, An error occurred while scanning file "G:\WINDOWS\system32\config\SAM.LOG": Zugriff verweigert
2004-09-26, 14:12:34, An error occurred while scanning file "G:\WINDOWS\system32\config\SECURITY": Zugriff verweigert
2004-09-26, 14:12:34, An error occurred while scanning file "G:\WINDOWS\system32\config\SECURITY.LOG": Zugriff verweigert
2004-09-26, 14:12:34, An error occurred while scanning file "G:\WINDOWS\system32\config\software": Zugriff verweigert
2004-09-26, 14:12:34, An error occurred while scanning file "G:\WINDOWS\system32\config\software.LOG": Zugriff verweigert
2004-09-26, 14:12:35, An error occurred while scanning file "G:\WINDOWS\system32\config\system": Zugriff verweigert
2004-09-26, 14:12:35, An error occurred while scanning file "G:\WINDOWS\system32\config\system.LOG": Zugriff verweigert
2004-09-26, 14:14:05, Running scanner "G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN"...
2004-09-26, 14:21:26, Files Detected:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 9/26/2004 14:14:07
VSAPI Engine Version : 7.000-1004
VSCANTM Version : 1.1-1001
Virus Pattern Version : 327 (84373 Patterns) (2005/01/01) (232700)
Command Line: G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 G:\*.* /P=G:\DOKUME~1\JIGGA\DESKTOP

17120 files have been read.
17120 files have been checked.
13205 files have been scanned.
14365 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/26/2004 14:21:25
---------*---------*---------*---------*---------*---------*---------*---------*
2004-09-26, 14:21:26, Files Clean:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 9/26/2004 14:14:07
VSAPI Engine Version : 7.000-1004
VSCANTM Version : 1.1-1001
Virus Pattern Version : 327 (84373 Patterns) (2005/01/01) (232700)
Command Line: G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 G:\*.* /P=G:\DOKUME~1\JIGGA\DESKTOP

17120 files have been read.
17120 files have been checked.
13205 files have been scanned.
14365 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/26/2004 14:21:25 7 minutes 17 seconds (437.91 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2004-09-26, 14:21:26, Clean Fail:
Copyright (c) 1990 - 2004 Trend Micro Inc.
Report Date : 9/26/2004 14:14:07
VSAPI Engine Version : 7.000-1004
VSCANTM Version : 1.1-1001
Virus Pattern Version : 327 (84373 Patterns) (2005/01/01) (232700)
Command Line: G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 G:\*.* /P=G:\DOKUME~1\JIGGA\DESKTOP

17120 files have been read.
17120 files have been checked.
13205 files have been scanned.
14365 files have been scanned. (including files in archived)
0 files containing viruses.
Found 0 viruses totally.
Maybe 0 viruses totally.
Stop At : 9/26/2004 14:21:25 7 minutes 17 seconds (437.91 seconds) has elapsed.

---------*---------*---------*---------*---------*---------*---------*---------*
2004-09-26, 14:21:26, Scanner "G:\DOKUME~1\JIGGA\DESKTOP\VSCANTM.BIN" has finished running.
arjang
 
Beiträge: 8
Registriert: 02.01.2005, 16:15

Beitragvon Nikita am 03.01.2005, 15:39

o.k. nun mache noch den ganzen "Rest" ;)
Nikita
Moderator
 
Beiträge: 11478
Registriert: 07.12.2003, 16:53
Wohnort: Lissabon

Beitragvon arjang am 03.01.2005, 16:31

Sun Sep 26 15:02:06 2004 => File G:\WINDOWS\system32\tmp1.com infected by "Worm.Win32.Wilab.b" Virus. Action Taken: File Deleted.

Sun Sep 26 15:15:11 2004 => ***** Checking for specific ITW Viruses *****
Sun Sep 26 15:15:11 2004 => Checking for Welchia Virus...
Sun Sep 26 15:15:11 2004 => Checking for LovGate Virus...
Sun Sep 26 15:15:11 2004 => Checking for CodeRed Virus...
Sun Sep 26 15:15:11 2004 => Checking for OpaServ Virus...
Sun Sep 26 15:15:11 2004 => Checking for Sobig.e Virus...
Sun Sep 26 15:15:11 2004 => Checking for Winupie Virus...
Sun Sep 26 15:15:11 2004 => Checking for Swen Virus...
Sun Sep 26 15:15:11 2004 => Checking for JS.Fortnight Virus...
Sun Sep 26 15:15:11 2004 => Checking for Novarg Virus...

Sun Sep 26 15:15:11 2004 => ***** Scanning complete. *****

Sun Sep 26 15:15:11 2004 => Total Number of Files Scanned: 18344
Sun Sep 26 15:15:11 2004 => Total Number of Virus(es) Found: 2
Sun Sep 26 15:15:11 2004 => Total Number of Disinfected Files: 0
Sun Sep 26 15:15:11 2004 => Total Number of Files Renamed: 0
Sun Sep 26 15:15:11 2004 => Total Number of Deleted Files: 1
Sun Sep 26 15:15:11 2004 => Total Number of Errors: 1
Sun Sep 26 15:15:11 2004 => Time Elapsed: 00:26:25
Sun Sep 26 15:15:11 2004 => Virus Database Date: 2005/01/03
Sun Sep 26 15:15:11 2004 => Virus Database Count: 114611

Sun Sep 26 15:15:11 2004 => Scan Completed.

Sun Sep 26 15:19:32 2004 => Virus Database Date: 2005/01/03
Sun Sep 26 15:19:32 2004 => Virus Database Count: 114611
Sun Sep 26 15:19:37 2004 => AV Library Unloaded (3)...


hijackthis:
Logfile of HijackThis v1.99.0
Scan saved at 15:28:21, on 26.09.2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\Explorer.EXE
G:\WINDOWS\system32\LEXBCES.EXE
G:\WINDOWS\system32\spoolsv.exe
G:\WINDOWS\system32\LEXPPS.EXE
G:\Programme\Softwin\BitDefender8\bdoesrv.exe
G:\Programme\Softwin\BitDefender8\bdswitch.exe
G:\WINDOWS\SOUNDMAN.EXE
G:\Programme\CyberLink\PowerDVD\PDVDServ.exe
G:\WINDOWS\System32\LXSUPMON.EXE
G:\Programme\Messenger\msmsgs.exe
G:\WINDOWS\System32\nvsvc32.exe
G:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe
G:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe
G:\Programme\Softwin\BitDefender8\vsserv.exe
G:\Programme\Mozilla Firefox\firefox.exe
G:\Programme\Windows Media Player\wmplayer.exe
G:\WINDOWS\System32\wuauclt.exe
G:\WINDOWS\system32\NOTEPAD.EXE
G:\Dokumente und Einstellungen\jigga\Desktop\HijackThis.exe

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - g:\programme\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - G:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - g:\programme\google\googletoolbar1.dll
O4 - HKLM\..\Run: [BDMCon] G:\Programme\Softwin\BitDefender8\\bdmcon.exe
O4 - HKLM\..\Run: [BDOESRV] G:\Programme\Softwin\BitDefender8\\bdoesrv.exe
O4 - HKLM\..\Run: [BDNewsAgent] G:\Programme\Softwin\BitDefender8\\bdnagent.exe
O4 - HKLM\..\Run: [BDSwitchAgent] G:\Programme\Softwin\BitDefender8\\bdswitch.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [RemoteControl] G:\Programme\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [LXSUPMON] G:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [TrojanScanner] G:\Programme\Trojan Remover\Trjscan.exe
O4 - HKCU\..\Run: [MSMSGS] "G:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Scan Spyware] "G:\Programme\ScanSpyware v3.7\Scanner.exe"
O4 - Global Startup: Adobe Gamma Loader.lnk = G:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = G:\Programme\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://G:\Programme\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://G:\Programme\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://G:\Programme\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://G:\Programme\Google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: ICQ 4.1 - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - G:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - G:\Programme\ICQLite\ICQLite.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{337E5CD3-5A44-4D1C-BDC3-85C5A3583249}: NameServer = 213.191.92.87 213.191.74.18
O23 - Service: BitDefender Scan Server - Unknown - G:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe
O23 - Service: LexBce Server - Lexmark International, Inc. - G:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - G:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Sandra Data Service - SiSoftware - G:\Programme\SiSoftware\SiSoftware Sandra Professional 2005\RpcDataSrv.exe
O23 - Service: Sandra Service - SiSoftware - G:\Programme\SiSoftware\SiSoftware Sandra Professional 2005\RpcSandraSrv.exe
O23 - Service: BitDefender Virus Shield - Unknown - G:\Programme\Softwin\BitDefender8\vsserv.exe
O23 - Service: BitDefender Communicator - Softwin - G:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe

der est kommt sofort :roll:
arjang
 
Beiträge: 8
Registriert: 02.01.2005, 16:15

Beitragvon arjang am 03.01.2005, 16:35

Ad-Aware SE Build 1.05
Logfile Created on:Sonntag, 26. September 2004 15:29:42
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R24 29.12.2004
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Alexa(TAC index:5):3 total references
Tracking Cookie(TAC index:3):4 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan my Hosts file

Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects


26.09.2004 15:29:42 - Scan started. (Full System Scan)

Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 428
ThreadCreationTime : 26.09.2004 13:20:34
BasePriority : Normal


#:2 [csrss.exe]
FilePath : \??\G:\WINDOWS\system32\
ProcessID : 496
ThreadCreationTime : 26.09.2004 13:20:35
BasePriority : Normal


#:3 [winlogon.exe]
FilePath : \??\G:\WINDOWS\system32\
ProcessID : 520
ThreadCreationTime : 26.09.2004 13:20:36
BasePriority : High


#:4 [services.exe]
FilePath : G:\WINDOWS\system32\
ProcessID : 564
ThreadCreationTime : 26.09.2004 13:20:37
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Betriebssystem Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Anwendung für Dienste und Controller
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFilename : services.exe

#:5 [lsass.exe]
FilePath : G:\WINDOWS\system32\
ProcessID : 576
ThreadCreationTime : 26.09.2004 13:20:37
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe

#:6 [svchost.exe]
FilePath : G:\WINDOWS\system32\
ProcessID : 756
ThreadCreationTime : 26.09.2004 13:20:37
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:7 [svchost.exe]
FilePath : G:\WINDOWS\System32\
ProcessID : 808
ThreadCreationTime : 26.09.2004 13:20:37
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:8 [svchost.exe]
FilePath : G:\WINDOWS\System32\
ProcessID : 904
ThreadCreationTime : 26.09.2004 13:20:38
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:9 [svchost.exe]
FilePath : G:\WINDOWS\System32\
ProcessID : 916
ThreadCreationTime : 26.09.2004 13:20:38
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe

#:10 [explorer.exe]
FilePath : G:\WINDOWS\
ProcessID : 1180
ThreadCreationTime : 26.09.2004 13:20:38
BasePriority : Normal
FileVersion : 6.00.2600.0000 (xpclient.010817-1148)
ProductVersion : 6.00.2600.0000
ProductName : Betriebssystem Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFilename : EXPLORER.EXE

#:11 [lexbces.exe]
FilePath : G:\WINDOWS\system32\
ProcessID : 1216
ThreadCreationTime : 26.09.2004 13:20:39
BasePriority : Normal
FileVersion : 7.4
ProductVersion : 7.4
ProductName : MarkVision for Windows (32 bit)
CompanyName : Lexmark International, Inc.
FileDescription : LexBce Service
InternalName : LexBce Service
LegalCopyright : (C) 1993 - 2002 Lexmark International, Inc.
OriginalFilename : LexBceS.exe

#:12 [spoolsv.exe]
FilePath : G:\WINDOWS\system32\
ProcessID : 1276
ThreadCreationTime : 26.09.2004 13:20:39
BasePriority : Normal
FileVersion : 5.1.2600.0 (XPClient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe

#:13 [lexpps.exe]
FilePath : G:\WINDOWS\system32\
ProcessID : 1284
ThreadCreationTime : 26.09.2004 13:20:39
BasePriority : Normal
FileVersion : 7.4
ProductVersion : 7.4
ProductName : MarkVision for Windows (32 bit)
CompanyName : Lexmark International, Inc.
FileDescription : LEXPPS.EXE
InternalName : LEXPPS
LegalCopyright : (C) 1993 - 2002 Lexmark International, Inc.
OriginalFilename : LEXPPS.EXE
Comments : MarkVision for Windows '95 New P2P Server (32-bit)

#:14 [bdoesrv.exe]
FilePath : G:\Programme\Softwin\BitDefender8\
ProcessID : 1408
ThreadCreationTime : 26.09.2004 13:20:39
BasePriority : Normal


#:15 [bdswitch.exe]
FilePath : G:\Programme\Softwin\BitDefender8\
ProcessID : 1424
ThreadCreationTime : 26.09.2004 13:20:39
BasePriority : Normal


#:16 [soundman.exe]
FilePath : G:\WINDOWS\
ProcessID : 1444
ThreadCreationTime : 26.09.2004 13:20:39
BasePriority : Normal
FileVersion : 5.0.05
ProductVersion : 5.0.05
ProductName : Avance Sound Manager
CompanyName : Avance Logic, Inc.
FileDescription : Avance Sound Manager
InternalName : ALSMTray
LegalCopyright : Copyright (c) 2001-2002 Avance Logic, Inc.
OriginalFilename : ALSMTray.exe
Comments : Avance AC97 Audio Sound Manager

#:17 [pdvdserv.exe]
FilePath : G:\Programme\CyberLink\PowerDVD\
ProcessID : 1452
ThreadCreationTime : 26.09.2004 13:20:39
BasePriority : Normal
FileVersion : 6.00.1027
ProductVersion : 6.00.1027
ProductName : PowerDVD
CompanyName : Cyberlink Corp.
FileDescription : PowerDVD RC Service
InternalName : PowerDVD RC Service
LegalCopyright : Copyright (c) CyberLink Corp. 1997-2004
OriginalFilename : PDVDSERV.EXE

#:18 [lxsupmon.exe]
FilePath : G:\WINDOWS\System32\
ProcessID : 1460
ThreadCreationTime : 26.09.2004 13:20:39
BasePriority : Normal
FileVersion : 3.0.105.1
ProductVersion : 3.0.105.1
ProductName : Lexmark Supplies Monitor
CompanyName : Lexmark International Inc.
FileDescription : Supplies Monitor
InternalName : LXSUPMON
LegalCopyright : Copyright © 2002
OriginalFilename : LXSUPMON.RC

#:19 [msmsgs.exe]
FilePath : G:\Programme\Messenger\
ProcessID : 1484
ThreadCreationTime : 26.09.2004 13:20:40
BasePriority : Normal
FileVersion : 4.0.0155
ProductVersion : Version 4.0
ProductName : Messenger
CompanyName : Microsoft Corporation
FileDescription : Messenger Client
InternalName : msmsgs
LegalCopyright : Copyright (c) Microsoft Corporation 1997-2001
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation in the U.S. and/or other countries.
OriginalFilename : msmsgs.exe

#:20 [nvsvc32.exe]
FilePath : G:\WINDOWS\System32\
ProcessID : 176
ThreadCreationTime : 26.09.2004 13:21:45
BasePriority : Normal
FileVersion : 6.14.10.6693
ProductVersion : 6.14.10.6693
ProductName : NVIDIA Driver Helper Service, Version 66.93
CompanyName : NVIDIA Corporation
FileDescription : NVIDIA Driver Helper Service, Version 66.93
InternalName : NVSVC
LegalCopyright : (C) NVIDIA Corporation. All rights reserved.
OriginalFilename : nvsvc32.exe

#:21 [xcommsvr.exe]
FilePath : G:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\
ProcessID : 252
ThreadCreationTime : 26.09.2004 13:21:45
BasePriority : Normal
FileVersion : 1, 7, 0, 6
ProductVersion : 1, 7, 0, 6
ProductName : Softwin BitDefender Communicator Server
CompanyName : Softwin
FileDescription : BitDefender Communicator Server
InternalName : XCOMMSVR
LegalCopyright : Copyright © 2003-2004 Softwin
OriginalFilename : xcommsvr.exe
Comments : Manages communication between BitDefender components

#:22 [bdss.exe]
FilePath : G:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\
ProcessID : 352
ThreadCreationTime : 26.09.2004 13:21:48
BasePriority : Normal


#:23 [vsserv.exe]
FilePath : G:\Programme\Softwin\BitDefender8\
ProcessID : 644
ThreadCreationTime : 26.09.2004 13:21:49
BasePriority : Normal


#:24 [firefox.exe]
FilePath : G:\Programme\Mozilla Firefox\
ProcessID : 1736
ThreadCreationTime : 26.09.2004 13:22:01
BasePriority : Normal


#:25 [wuauclt.exe]
FilePath : G:\WINDOWS\System32\
ProcessID : 1124
ThreadCreationTime : 26.09.2004 13:23:19
BasePriority : Normal
FileVersion : 5.4.2600.0 (XPClient.010817-1148)
ProductVersion : 5.4.2600.0
ProductName : Betriebssystem Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Client des automatischen Updates von Windows Update
InternalName : wuauclt.exe
LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFilename : wuauclt.exe

#:26 [ad-aware.exe]
FilePath : G:\PROGRA~1\Lavasoft\AD-AWA~1\
ProcessID : 1716
ThreadCreationTime : 26.09.2004 13:29:13
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved

Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 0


Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
Rootkey : HKEY_USERS
Object : .DEFAULT\software\microsoft\internet explorer\extensions\cmdmapping
Value : {c95fe080-8f5d-11d2-a20b-00aa003c157a}

Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
Rootkey : HKEY_USERS
Object : S-1-5-18\software\microsoft\internet explorer\extensions\cmdmapping
Value : {c95fe080-8f5d-11d2-a20b-00aa003c157a}

Alexa Object Recognized!
Type : RegValue
Data :
Category : Data Miner
Comment : "{c95fe080-8f5d-11d2-a20b-00aa003c157a}"
Rootkey : HKEY_USERS
Object : S-1-5-21-823518204-796845957-839522115-1003\software\microsoft\internet explorer\extensions\cmdmapping
Value : {c95fe080-8f5d-11d2-a20b-00aa003c157a}

Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 3
Objects found so far: 3


Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 3


Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»


Tracking Cookie Object Recognized!
Type : IECache Entry
Data : jigga@2o7[2].txt
Category : Data Miner
Comment : Hits:2
Value : Cookie:jigga@2o7.net/
Expires : 30.12.2009 15:40:14
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : jigga@servedby.advertising[2].txt
Category : Data Miner
Comment : Hits:2
Value : Cookie:jigga@servedby.advertising.com/
Expires : 01.02.2005 20:57:48
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : jigga@bravenet[2].txt
Category : Data Miner
Comment : Hits:2
Value : Cookie:jigga@bravenet.com/
Expires : 29.12.2014 14:35:34
LastSync : Hits:2
UseCount : 0
Hits : 2

Tracking Cookie Object Recognized!
Type : IECache Entry
Data : jigga@advertising[1].txt
Category : Data Miner
Comment : Hits:1
Value : Cookie:jigga@advertising.com/
Expires : 01.01.2010 20:57:14
LastSync : Hits:1
UseCount : 0
Hits : 1

Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 4
Objects found so far: 7



Deep scanning and examining files (C:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 7


Deep scanning and examining files (F:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for F:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 7


Deep scanning and examining files (G:)
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Disk Scan Result for G:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 7


Scanning Hosts file......
Hosts file location:"G:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
1 entries scanned.
New critical objects:0
Objects found so far: 7




Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»

Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 7

15:33:32 Scan Complete

Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:03:49.922
Objects scanned:72056
Objects identified:7
Objects ignored:0
New critical objects:7
arjang
 
Beiträge: 8
Registriert: 02.01.2005, 16:15

Beitragvon arjang am 03.01.2005, 16:45

ich glaub das war s jetzt .....

der bericht von spybot:

--- Search result list ---
Advertising.com: Verfolgender Cookie (Internet Explorer: jigga) (Cookie, nothing done)


Advertising.com: Verfolgender Cookie (Internet Explorer: jigga) (Cookie, nothing done)


Alexa Related: What's related link (Datei austauschen, nothing done)
G:\WINDOWS\Web\related.htm

DSO Exploit: Data source object exploit (Registrierungsdatenbank-Änderung, nothing done)
HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registrierungsdatenbank-Änderung, nothing done)
HKEY_USERS\S-1-5-21-823518204-796845957-839522115-1003\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registrierungsdatenbank-Änderung, nothing done)
HKEY_USERS\S-1-5-20\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registrierungsdatenbank-Änderung, nothing done)
HKEY_USERS\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3

DSO Exploit: Data source object exploit (Registrierungsdatenbank-Änderung, nothing done)
HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\0\1004!=W=3


--- Spybot - Search && Destroy version: 1.3 ---
2004-05-12 Includes\Cookies.sbi
2004-05-12 Includes\Dialer.sbi
2004-05-12 Includes\Hijackers.sbi
2004-05-12 Includes\Keyloggers.sbi
2004-05-12 Includes\LSP.sbi
2004-05-12 Includes\Malware.sbi
2004-05-12 Includes\Revision.sbi
2004-05-12 Includes\Security.sbi
2004-05-12 Includes\Spybots.sbi
2004-05-12 Includes\Tracks.uti
2004-05-12 Includes\Trojans.sbi


--- System information ---
Windows XP (Build: 2600)


--- Startup entries list ---
Located: HK_LM:Run, BDMCon
command: G:\Programme\Softwin\BitDefender8\\bdmcon.exe
file: G:\Programme\Softwin\BitDefender8\\bdmcon.exe
size: 311296
MD5: 17fec263011db45f2da505be8fbf1f14

Located: HK_LM:Run, BDNewsAgent
command: G:\Programme\Softwin\BitDefender8\\bdnagent.exe
file: G:\Programme\Softwin\BitDefender8\\bdnagent.exe
size: 4608
MD5: 520e598851b13b9f3244083b9fb46a06

Located: HK_LM:Run, BDOESRV
command: G:\Programme\Softwin\BitDefender8\\bdoesrv.exe
file: G:\Programme\Softwin\BitDefender8\\bdoesrv.exe
size: 86016
MD5: 8610e263f53b5daf2d3cb40ba0fadd3d

Located: HK_LM:Run, BDSwitchAgent
command: G:\Programme\Softwin\BitDefender8\\bdswitch.exe
file: G:\Programme\Softwin\BitDefender8\\bdswitch.exe
size: 53248
MD5: dc1747bc24e4f24be3d25b01950c717f

Located: HK_LM:Run, LXSUPMON
command: G:\WINDOWS\System32\LXSUPMON.EXE RUN
file: G:\WINDOWS\System32\LXSUPMON.EXE
size: 886272
MD5: 64d0b725a5e49c52c3d26edaacd5358d

Located: HK_LM:Run, NvCplDaemon
command: RUNDLL32.EXE G:\WINDOWS\System32\NvCpl.dll,NvStartup
file: G:\WINDOWS\system32\RUNDLL32.EXE
size: 32256
MD5: 3b97edb791fb209017b8864c8e7087f9

Located: HK_LM:Run, RemoteControl
command: G:\Programme\CyberLink\PowerDVD\PDVDServ.exe
file: G:\Programme\CyberLink\PowerDVD\PDVDServ.exe
size: 32768
MD5: 8fb740d758b14b1bc950cc347c21e461

Located: HK_LM:Run, SoundMan
command: SOUNDMAN.EXE
file: G:\WINDOWS\SOUNDMAN.EXE
size: 46592
MD5: 190ee06f2c9d4e0101bceb363614b6f5

Located: HK_LM:Run, TrojanScanner
command: G:\Programme\Trojan Remover\Trjscan.exe
file: G:\Programme\Trojan Remover\Trjscan.exe
size: 280720
MD5: 821707d2fae6cffbda7763176774e7a0

Located: HK_CU:Run, MSMSGS
command: "G:\Programme\Messenger\msmsgs.exe" /background
file: G:\Programme\Messenger\msmsgs.exe
size: 1077277
MD5: 10a98fa310d1b6664f999378efd031ba

Located: HK_CU:Run, Scan Spyware
command: "G:\Programme\ScanSpyware v3.7\Scanner.exe"
file: G:\Programme\ScanSpyware v3.7\Scanner.exe
size: 1273856
MD5: 62c3ad2a7b83c0ac6c5b59e827071151

Located: Startup (allgemein), Adobe Gamma Loader.lnk
command: G:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
file: G:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
size: 113664
MD5: c2ff17734176cd15221c10044ef0ba1a

Located: Startup (allgemein), Microsoft Office.lnk
command: G:\Programme\Microsoft Office\Office10\OSA.EXE
file: G:\Programme\Microsoft Office\Office10\OSA.EXE
size: 83360
MD5: 5bc65464354a9fd3beaa28e18839734a



--- Browser helper object list ---
{53707962-6F74-2D53-2644-206D7942484F} ()
BHO name:
CLSID name:
description: Spybot-S&D IE Browser plugin
classification: Legitimate
known filename: SDHelper.dll
info link: http://spybot.eon.net.au/
info source: Patrick M. Kolla
Path: G:\Programme\Spybot - Search & Destroy\
Long name: SDHelper.dll
Short name:
Date (created): 12.05.2004 01:03:00
Date (last access): 26.09.2004 15:35:00
Date (last write): 12.05.2004 01:03:00
Filesize: 744960
Attributes: archive
MD5: ABF5BA518C6A5ED104496FF42D19AD88
CRC32: 5587736E
Version: 0.1.0.3

{AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
BHO name:
CLSID name: Google Toolbar Helper
description: Google toolbar
classification: Open for discussion
known filename: Googletoolbar.dll
info link: http://toolbar.google.com/
info source: TonyKlein
Path: g:\programme\google\
Long name: GoogleToolbar1.dll
Short name: GOOGLE~1.DLL
Date (created): 24.09.2004 19:07:22
Date (last access): 26.09.2004 15:11:18
Date (last write): 24.09.2004 19:07:22
Filesize: 770048
Attributes: readonly archive
MD5: DE234C6847E0D8FE18B0FFDEC90F119F
CRC32: 7E08326F
Version: 0.2.0.0



--- ActiveX list ---


--- Process list ---
Spybot - Search && Destroy process list report, 26.09.2004 15:44:16

PID: 0 ( 0) [System]
PID: 4 ( 0) System
PID: 176 ( 564) G:\WINDOWS\System32\nvsvc32.exe
PID: 252 ( 564) G:\Programme\Gemeinsame Dateien\Softwin\BitDefender Communicator\xcommsvr.exe
PID: 352 ( 564) G:\Programme\Gemeinsame Dateien\Softwin\BitDefender Scan Server\bdss.exe
PID: 428 ( 4) \SystemRoot\System32\smss.exe
PID: 496 ( 428) csrss.exe
PID: 520 ( 428) \??\G:\WINDOWS\system32\winlogon.exe
PID: 564 ( 520) G:\WINDOWS\system32\services.exe
PID: 576 ( 520) G:\WINDOWS\system32\lsass.exe
PID: 644 ( 564) G:\Programme\Softwin\BitDefender8\vsserv.exe
PID: 756 ( 564) G:\WINDOWS\system32\svchost.exe
PID: 808 ( 564) G:\WINDOWS\System32\svchost.exe
PID: 904 ( 564) svchost.exe
PID: 916 ( 564) svchost.exe
PID: 1124 ( 808) G:\WINDOWS\System32\wuauclt.exe
PID: 1180 (1156) G:\WINDOWS\Explorer.EXE
PID: 1216 ( 564) G:\WINDOWS\system32\LEXBCES.EXE
PID: 1276 ( 564) G:\WINDOWS\system32\spoolsv.exe
PID: 1284 (1216) G:\WINDOWS\system32\LEXPPS.EXE
PID: 1408 (1180) G:\Programme\Softwin\BitDefender8\bdoesrv.exe
PID: 1424 (1180) G:\Programme\Softwin\BitDefender8\bdswitch.exe
PID: 1444 (1180) G:\WINDOWS\SOUNDMAN.EXE
PID: 1452 (1180) G:\Programme\CyberLink\PowerDVD\PDVDServ.exe
PID: 1460 (1180) G:\WINDOWS\System32\LXSUPMON.EXE
PID: 1484 (1180) G:\Programme\Messenger\msmsgs.exe
PID: 1520 ( 468) G:\Programme\Spybot - Search & Destroy\SpybotSD.exe
PID: 1736 (1180) G:\Programme\Mozilla Firefox\firefox.exe


--- Browser start & search pages list ---
Spybot - Search && Destroy browser pages report, 26.09.2004 15:44:16

HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Local Page
G:\WINDOWS\System32\blank.htm
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchUrl\@
http://home.microsoft.com/access/autosearch.asp?p=%s
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Local Page
%SystemRoot%\system32\blank.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Search Page
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Start Page
http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Main\Default_Search_URL
http://www.microsoft.com/isapi/redir.dl ... r=iesearch
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\SearchAssistant
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchasst.htm
HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Search\CustomizeSearch
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm


--- Winsock Layered Service Provider list ---
Protocol 0: MSAFD Tcpip [TCP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]

Protocol 1: MSAFD Tcpip [UDP/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]

Protocol 2: MSAFD Tcpip [RAW/IP]
GUID: {E70F1AA0-AB8B-11CF-8CA3-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP IP protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD Tcpip [*]

Protocol 3: RSVP UDP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 4: RSVP TCP Service Provider
GUID: {9D60A9E0-337A-11D0-BD88-0000C082E69A}
Filename: %SystemRoot%\system32\rsvpsp.dll
Description: Microsoft Windows NT/2k/XP RVSP
DB filename: %SystemRoot%\system32\rsvpsp.dll
DB protocol: RSVP * Service Provider

Protocol 5: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3B4E27FA-2216-450E-9B4B-94F2DBCB8DC2}] SEQPACKET 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 6: MSAFD NetBIOS [\Device\NetBT_Tcpip_{3B4E27FA-2216-450E-9B4B-94F2DBCB8DC2}] DATAGRAM 0
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 7: MSAFD NetBIOS [\Device\NetBT_Tcpip_{13014192-D3B6-4C2C-B700-29EA0644E018}] SEQPACKET 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 8: MSAFD NetBIOS [\Device\NetBT_Tcpip_{13014192-D3B6-4C2C-B700-29EA0644E018}] DATAGRAM 1
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 9: MSAFD NetBIOS [\Device\NetBT_Tcpip_{544CD604-4D68-416D-ABB7-50F3928EEF05}] SEQPACKET 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 10: MSAFD NetBIOS [\Device\NetBT_Tcpip_{544CD604-4D68-416D-ABB7-50F3928EEF05}] DATAGRAM 2
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 11: MSAFD NetBIOS [\Device\NetBT_Tcpip_{40AB333A-A153-4BA4-9882-18FF8B4B843D}] SEQPACKET 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 12: MSAFD NetBIOS [\Device\NetBT_Tcpip_{40AB333A-A153-4BA4-9882-18FF8B4B843D}] DATAGRAM 3
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 13: MSAFD NetBIOS [\Device\NetBT_Tcpip_{337E5CD3-5A44-4D1C-BDC3-85C5A3583249}] SEQPACKET 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Protocol 14: MSAFD NetBIOS [\Device\NetBT_Tcpip_{337E5CD3-5A44-4D1C-BDC3-85C5A3583249}] DATAGRAM 4
GUID: {8D5F1830-C273-11CF-95C8-00805F48A192}
Filename: %SystemRoot%\system32\mswsock.dll
Description: Microsoft Windows NT/2k/XP NetBios protocol
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: MSAFD NetBIOS *

Namespace Provider 0: TCP/IP
GUID: {22059D40-7E9E-11CF-AE5A-00AA00A7112B}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP TCP/IP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: TCP/IP

Namespace Provider 1: NTDS
GUID: {3B2637EE-E580-11CF-A555-00C04FD8D4AC}
Filename: %SystemRoot%\System32\winrnr.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\winrnr.dll
DB protocol: NTDS

Namespace Provider 2: NLA-Namespace
GUID: {6642243A-3BA8-4AA6-BAA5-2E0BD71FDD83}
Filename: %SystemRoot%\System32\mswsock.dll
Description: Microsoft Windows NT/2k/XP name space provider
DB filename: %SystemRoot%\system32\mswsock.dll
DB protocol: NLA-Namespace
arjang
 
Beiträge: 8
Registriert: 02.01.2005, 16:15

Beitragvon Nikita am 04.01.2005, 01:47

Hallo@arjang

Da bist du noch einmal mit einem blauen Auge davongekommen.
Aber solange du die WindowsUpdates nicht machst (SP1 oder SP2 ) und keine Firewall hast, wird es immer probleme geben.........
Nikita
Moderator
 
Beiträge: 11478
Registriert: 07.12.2003, 16:53
Wohnort: Lissabon

Beitragvon arjang am 04.01.2005, 15:22

hi @ nikita

ich glaubedas problem besteht aber immerncoh! woran kann denn das noch liegen? :cry:
arjang
 
Beiträge: 8
Registriert: 02.01.2005, 16:15

Beitragvon Nikita am 04.01.2005, 17:05

Fixe mit dem HijackThis:

O4 - HKCU\..\Run: [Scan Spyware] "G:\Programme\ScanSpyware v3.7\Scanner.exe"

neustarten

deaktiviere den Bitdefender und lade:
#Antivirus (free)
http://www.free-av.de/

warte den Deinstalltions-Scan ab, dann konfiguriere

[X] Speicher
[X] Bootsektor Suchlaufwerke
[ ] Unbekannte Bootsektoren melden
[X] Alle Dateien
[ ] Programmdateien

, gehe in den abgesicherten Modus .
scanne im abgesicherten Modus mit Antivirus und eScan (poste mir beide Logs)
Nikita
Moderator
 
Beiträge: 11478
Registriert: 07.12.2003, 16:53
Wohnort: Lissabon

Beitragvon arjang am 06.01.2005, 21:29

hi nikita:

ich werde in den nächstem tagen windows xp neu installieren(diesmal mit sp2)...ich glaube das problem wird damit nciht gelöst weden abr probieren kann ichs ja...dann meld ich mich nochmal bei dir!

danke für alles bisher :wink:
arjang
 
Beiträge: 8
Registriert: 02.01.2005, 16:15

Beitragvon Nikita am 07.01.2005, 13:13

Ueberpruefe:

G:\WINDOWS\system32\csrss.exe

Jotti's malware scan 2.4 - einzelne "exe" ueberpruefen
http://virusscan.jotti.dhs.org/
poste das Ergebnis
--------------------------------------------------------------------------------------------------
#McAfee FreeScan (Online)
www.mcafee.com/myapps/mfs/default.asp

#Trend-Micro (Online)
http://de.trendmicro-europe.com/enterpr ... ll_pre.php

#Online-Scann <f-secure<
http://support.f-secure.com/enu/home/ols.shtml

Poste mir, was die Online-Scans ergeben haben
Nikita
Moderator
 
Beiträge: 11478
Registriert: 07.12.2003, 16:53
Wohnort: Lissabon



Ähnliche Themen


Zurück zu Online- und PC-Sicherheit

Wer ist online?

Mitglieder in diesem Forum: 0 Mitglieder und 0 Gäste