Hi Nikita.
Erstmal vielen Dank für Deine schnelle Hilfe.
Bin absoluter PC-Anfänger (2 linke Hände und alles Daumen), habe mich aber trotzdem durch Deine Anleitung durchgekämpft.
Nachfolgend die Logs, von denen ich glaube, daß Du sie sehen willst :
File C:\WINDOWS\system32\doolsav.dat infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\error32.dat infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
Vielen Dank,
Husen
File C:\WINDOWS\system32\wudupdate.exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\Jan Steinhusen.NOTEBOOK\Lokale Einstellungen\Temp\bundle.exe infected by "not-a-virus:AdWare.Sahat.h" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\00E50E04.zip infected by "Trojan.Java.Needy.c" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\023A3BA4.zip infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\184B61F0 infected by "I-Worm.NetSky.d" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\1FF50918 infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\2C8205F2.data infected by "I-Worm.Torvil.d" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\48043E71 infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\481E4BC8 infected by "not-a-virus:AdWare.WinAD.b" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\4B4835C2.htm infected by "Exploit.VBS.Phel.a" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\573D28D5.zip infected by "Trojan.Java.Needy.c" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\5A3C3389.zip infected by "Trojan.Java.Needy.c" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\6AB93C56.data infected by "I-Worm.Torvil.d" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\6C285431.data infected by "I-Worm.Torvil.d" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\76572455 infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\7895747E.part infected by "I-Worm.Torvil.d" Virus. Action Taken: No Action Taken.
File C:\Norton AntiVirus\Quarantine\7AF379E9.part infected by "I-Worm.Torvil.d" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\NPROTECT\00252215.DLL infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\NPROTECT\00253192.DLL infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\NPROTECT\00253287.DLL infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP306\A0076975.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP306\A0076976.exe infected by "not-a-virus:AdWare.WinAD.b" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP306\A0076978.dll infected by "not-a-virus:AdWare.WinAD.b" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP308\A0077203.EXE infected by "not-a-virus:AdWare.Toolbar.MyWay.b" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP308\A0077204.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.g" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP308\A0077205.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.f" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP308\A0077206.dll infected by "not-a-virus:AdWare.Relevance.b" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP312\A0077377.dll infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP313\A0077424.dll infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP313\A0077442.dll infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP315\A0077898.dll infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP316\A0078409.exe infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP316\A0078410.EXE infected by "not-a-virus:AdWare.WinAD" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP319\A0082950.DLL infected by "not-a-virus:AdWare.Relevance.b" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP319\A0082983.EXE infected by "not-a-virus:AdWare.WinAD.k" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP319\A0082984.EXE infected by "not-a-virus:AdWare.WinAD.m" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP319\A0083412.DLL infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP319\A0084373.dll infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\System Volume Information\_restore{235FF890-CE5A-4131-946C-8926AEC9405B}\RP319\A0084375.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YBUCHOYQ\silent_install[1].exe infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\doolsav.dat infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\error32.dat infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\wudupdate.exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.
File D:\PATCH\ACHKBLUE.EXE infected by "Trojan.DOS.Qrap" Virus. Action Taken: No Action Taken.
File D:\PATCH\ACKPANEL.EXE infected by "Trojan.DOS.Qrap" Virus. Action Taken: No Action Taken.
File D:\PATCH\ADISBLUE.EXE infected by "Trojan.DOS.Qrap" Virus. Action Taken: No Action Taken.
File D:\PATCH\AENBLUE.EXE infected by "Trojan.DOS.Qrap" Virus. Action Taken: No Action Taken.
File D:\Zip-Dateien\Utils\hijackthis\backups\backup-20050112-224147-894.dll infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File D:\Zip-Dateien\Utils\hijackthis\backups\backup-20050113-010127-767.dll infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File D:\Zip-Dateien\Utils\hijackthis\backups\backup-20050113-011415-184.dll infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File D:\Zip-Dateien\Utils\hijackthis\backups\backup-20050113-165043-656.dll infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YBUCHOYQ\silent_install[1].exe infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\doolsav.dat infected by "not-a-virus:AdWare.ToolBat.EliteBar.z" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\error32.dat infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
File C:\WINDOWS\system32\wudupdate.exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.
Thu Jan 13 19:37:31 2005 => Total Files Scanned: 97776
Thu Jan 13 19:37:31 2005 => Total Virus(es) Found: 60
Thu Jan 13 19:37:31 2005 => Total Disinfected Files: 0
Thu Jan 13 19:37:31 2005 => Total Files Renamed: 0
Thu Jan 13 19:37:31 2005 => Total Deleted Files: 0
Thu Jan 13 19:37:31 2005 => Total Errors: 9
Thu Jan 13 19:37:31 2005 => Time Elapsed: 02:25:33
Thu Jan 13 19:37:31 2005 => Virus Database Date: 2005/01/13
Thu Jan 13 19:37:32 2005 => Virus Database Count: 115420
Thu Jan 13 19:37:32 2005 => Scan Completed.
Thu Jan 13 19:37:58 2005 => Virus Database Date: 2005/01/13
Thu Jan 13 19:37:58 2005 => Virus Database Count: 115420
Thu Jan 13 19:38:42 2005 => AV Library Unloaded (3)...
HiJackThis-Log von heute abend:
Logfile of HijackThis v1.99.0
Scan saved at 21:06:18, on 13.01.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\Norton AntiVirus\navapsvc.exe
C:\Norton AntiVirus\AdvTools\NPROTECT.EXE
C:\WINDOWS\system32\RegSrvc.exe
C:\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe
C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programme\Java\j2re1.4.2_04\bin\jusched.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
C:\Programme\Microsoft IntelliPoint\point32.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Internet Explorer\iexplore.exe
D:\Zip-Dateien\Utils\hijackthis\HijackThis.exe
C:\Programme\Messenger\msmsgs.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://www.versatel.de/internet-cd/
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [PRONoMgr.exe] C:\Programme\Intel\PROSetWireless\NCS\PROSet\PRONoMgr.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [URLLSTCK.exe] C:\Norton Internet Security\UrlLstCk.exe
O4 - HKLM\..\Run: [RemoteControl] C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Programme\Microsoft IntelliPoint\point32.exe"
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1\CPLBCL53.EXE
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O8 - Extra context menu item: Nach Microsoft &Excel exportieren -
res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O14 - IERESET.INF: START_PAGE_URL=http://www.versatel.de/internet-cd/
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://v5.windowsupdate.microsoft.com/v ... 4826926312
O18 - Protocol: haufereader - {39198710-62F7-42CD-9458-069843FA5D32} - C:\HaufeReader\HRInstmon.dll
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect-Dienst - Symantec Corporation - C:\Norton AntiVirus\navapsvc.exe
O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\Norton AntiVirus\AdvTools\NPROTECT.EXE
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\system32\RegSrvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe