habe das Problem, das mein IExplorer( den ich nie wieder benutzen werde) dauernd Popups dieses Sexpokermist aufruft. Und verschiedene ungewollte Favoriten hinzugefügt+Startseite nicht mehr veränderbar ist.
Ich sitze schon geschlagene drei Tage an den Problem meinen Rechner wieder sauber zu bekommen, komme aber leider nicht weiter.
Da die Fragen wahrscheinlich hier schon öfter aufgetaucht sind, habe ich erstmal versucht auf eigene Faust Ordnung zu schaffen. Da mit ad-adware, Spybot S&D die Dateien nach Neustart immer wieder neu auftauchen, habe ich dann mit Escan die Dateien manuell gelöscht. Leider - zu spät erst von erfahren habe- habe ich kein Killbox benutzt.
Wahrscheinlich war das der Fehler ....
Habe folgende 3 Dateien einfach so gelöscht
- Code: Alles auswählen
:[00000001] File C:\WINDOWS\System32\connmie.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000660] 21/02/2005 14:58:18:595 :[00000001] File C:\WINDOWS\System32\dxconf.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000660] 21/02/2005 14:59:54:453 :[00000001] File C:\WINDOWS\System32\truettf.exe infected by not-a-virus:AdWare.Msnagent.a
Wie lösche ich die ganzen restlichen Dateien wie z.B unter c:/recycler....
- Code: Alles auswählen
716 :ModuleName = C:\bases\mwavscan.com
[msvLclnt.dll] [0x00000690] 20/02/2005 23:49:57:716 :Registry Key Deleted Properly!!!
[msvLclnt.dll] [0x00000690] 20/02/2005 23:50:03:624 :Options Set by External applications mwavscan.com are 9896960 (0x970400):
[msvLclnt.dll] [0x00000690] 20/02/2005 23:50:03:624 :Mode :PACKED,ARCHIVED,CA,WARNINGS,MAILPLAIN
[msvLclnt.dll] [0x00000690] 20/02/2005 23:50:03:624 :TimeOut : ffffffff
[msvLclnt.dll] [0x00000690] 20/02/2005 23:50:03:624 :Priority : NORMAL
[msvLclnt.dll] [0x00000690] 20/02/2005 23:50:05:297 :VirusCount = 118955 Latest Date = 2005/02/20
[msvLclnt.dll] [0x00000700] 20/02/2005 23:52:19:770 :[00000001] File C:\WINDOWS\System32\sfcman32.dll infected by Trojan.Win32.StartPage.fw
[msvLclnt.dll] [0x00000700] 20/02/2005 23:53:31:233 :[00000001] File C:\WINDOWS\System32\connmie.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 20/02/2005 23:53:47:847 :[00000001] File C:\WINDOWS\System32\dxconf.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 20/02/2005 23:55:31:856 :[00000001] File C:\WINDOWS\System32\truettf.exe infected by not-a-virus:AdWare.Msnagent.a
[msvLclnt.dll] [0x00000700] 20/02/2005 23:58:26:147 :[00000001] File C:\DOKUME~1\Tobse\LOKALE~1\TEMPOR~1\Content.IE5\0Z63JZX7\exploit[1].exe infected by Trojan-Clicker.Win32.Agent.bu
[msvLclnt.dll] [0x00000700] 21/02/2005 00:01:29:711 :[00000001] File C:\DOKUME~1\Tobse\LOKALE~1\TEMPOR~1\Content.IE5\743GRYUR\x[1].chm infected by Trojan-Clicker.Win32.Agent.bu
[msvLclnt.dll] [0x00000700] 21/02/2005 00:07:38:661 :[00000001] File C:\DOKUME~1\Tobse\LOKALE~1\TEMPOR~1\Content.IE5\GT2JSHA3\index[3].htm infected by Exploit.VBS.Phel.a
[msvLclnt.dll] [0x00000700] 21/02/2005 00:08:10:417 :[00000001] File C:\DOKUME~1\Tobse\LOKALE~1\TEMPOR~1\Content.IE5\HF80TNFG\counter[1].htm infected by Exploit.HTML.Mht
[msvLclnt.dll] [0x00000700] 21/02/2005 00:09:30:192 :[00000001] File C:\DOKUME~1\Tobse\LOKALE~1\TEMPOR~1\Content.IE5\Q29OI5HH\EXPLOIT[1].CHM infected by Trojan-Downloader.VBS.Psyme.ac
[msvLclnt.dll] [0x00000700] 21/02/2005 00:20:54:275 :[00000001] File C:\Dokumente und Einstellungen\Tobse\Lokale Einstellungen\Temporary Internet Files\Content.IE5\0Z63JZX7\exploit[1].exe infected by Trojan-Clicker.Win32.Agent.bu
[msvLclnt.dll] [0x00000700] 21/02/2005 00:23:37:440 :[00000001] File C:\Dokumente und Einstellungen\Tobse\Lokale Einstellungen\Temporary Internet Files\Content.IE5\743GRYUR\x[1].chm infected by Trojan-Clicker.Win32.Agent.bu
[msvLclnt.dll] [0x00000700] 21/02/2005 00:29:38:109 :[00000001] File C:\Dokumente und Einstellungen\Tobse\Lokale Einstellungen\Temporary Internet Files\Content.IE5\GT2JSHA3\index[3].htm infected by Exploit.VBS.Phel.a
[msvLclnt.dll] [0x00000700] 21/02/2005 00:30:10:906 :[00000001] File C:\Dokumente und Einstellungen\Tobse\Lokale Einstellungen\Temporary Internet Files\Content.IE5\HF80TNFG\counter[1].htm infected by Exploit.HTML.Mht
[msvLclnt.dll] [0x00000700] 21/02/2005 00:31:56:618 :[00000001] File C:\Dokumente und Einstellungen\Tobse\Lokale Einstellungen\Temporary Internet Files\Content.IE5\Q29OI5HH\EXPLOIT[1].CHM infected by Trojan-Downloader.VBS.Psyme.ac
[msvLclnt.dll] [0x00000700] 21/02/2005 01:40:36:953 :[00000001] File C:\RECYCLER\NPROTECT\00003214.exe infected by Trojan-Clicker.Win32.Agent.bu
[msvLclnt.dll] [0x00000700] 21/02/2005 01:40:37:393 :[00000001] File C:\RECYCLER\NPROTECT\00003228.exe infected by Trojan-Clicker.Win32.Agent.bu
[msvLclnt.dll] [0x00000700] 21/02/2005 01:40:37:664 :[00000001] File C:\RECYCLER\NPROTECT\00003229.exe infected by Trojan.Win32.Dialer.gd
[msvLclnt.dll] [0x00000700] 21/02/2005 01:41:22:518 :[00000001] File C:\RECYCLER\NPROTECT\00003670.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:41:22:688 :[00000001] File C:\RECYCLER\NPROTECT\00003671.exe infected by not-a-virus:AdWare.Msnagent.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:41:22:818 :[00000001] File C:\RECYCLER\NPROTECT\00003672.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:41:22:909 :[00000001] File C:\RECYCLER\NPROTECT\00003673.exe infected by Trojan.Win32.Dialer.gd
[msvLclnt.dll] [0x00000700] 21/02/2005 01:41:22:979 :[00000001] File C:\RECYCLER\NPROTECT\00003676.exe infected by Trojan.Win32.Dialer.gd
[msvLclnt.dll] [0x00000700] 21/02/2005 01:41:31:100 :[00000001] File C:\RECYCLER\NPROTECT\00003953.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:41:31:301 :[00000001] File C:\RECYCLER\NPROTECT\00003954.exe infected by not-a-virus:AdWare.Msnagent.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:41:31:411 :[00000001] File C:\RECYCLER\NPROTECT\00003955.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:41:31:711 :[00000001] File C:\RECYCLER\NPROTECT\00003956.exe infected by Trojan.Win32.Dialer.gd
[msvLclnt.dll] [0x00000700] 21/02/2005 01:41:31:781 :[00000001] File C:\RECYCLER\NPROTECT\00003959.exe infected by Trojan.Win32.Dialer.gd
[msvLclnt.dll] [0x00000700] 21/02/2005 01:42:53:789 :[00000001] File C:\RECYCLER\NPROTECT\00004694.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:42:53:939 :[00000001] File C:\RECYCLER\NPROTECT\00004695.exe infected by not-a-virus:AdWare.Msnagent.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:42:54:020 :[00000001] File C:\RECYCLER\NPROTECT\00004696.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:42:54:110 :[00000001] File C:\RECYCLER\NPROTECT\00004697.exe infected by Trojan.Win32.Dialer.gd
[msvLclnt.dll] [0x00000700] 21/02/2005 01:42:54:170 :[00000001] File C:\RECYCLER\NPROTECT\00004700.exe infected by Trojan.Win32.Dialer.gd
[msvLclnt.dll] [0x00000700] 21/02/2005 01:42:59:958 :[00000001] File C:\RECYCLER\NPROTECT\00004827.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:43:00:138 :[00000001] File C:\RECYCLER\NPROTECT\00004828.exe infected by not-a-virus:AdWare.Msnagent.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:43:00:239 :[00000001] File C:\RECYCLER\NPROTECT\00004829.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:43:00:329 :[00000001] File C:\RECYCLER\NPROTECT\00004830.exe infected by Trojan.Win32.Dialer.gd
[msvLclnt.dll] [0x00000700] 21/02/2005 01:43:00:389 :[00000001] File C:\RECYCLER\NPROTECT\00004833.exe infected by Trojan.Win32.Dialer.gd
[msvLclnt.dll] [0x00000700] 21/02/2005 01:44:05:242 :[00000001] File C:\RECYCLER\S-1-5-21-1801674531-842925246-839522115-1003\Dc46.dll infected by Trojan.Win32.StartPage.fw
[msvLclnt.dll] [0x00000700] 21/02/2005 01:44:05:462 :[00000001] File C:\RECYCLER\S-1-5-21-1801674531-842925246-839522115-1003\Dc48.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:44:05:613 :[00000001] File C:\RECYCLER\S-1-5-21-1801674531-842925246-839522115-1003\Dc49.exe infected by not-a-virus:AdWare.Msnagent.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:44:05:913 :[00000001] File C:\RECYCLER\S-1-5-21-1801674531-842925246-839522115-1003\Dc50.exe infected by Trojan-Clicker.Win32.Agent.bu
[msvLclnt.dll] [0x00000700] 21/02/2005 01:44:06:274 :[00000001] File C:\RECYCLER\S-1-5-21-1801674531-842925246-839522115-1003\Dc53.chm infected by Trojan-Clicker.Win32.Agent.bu
[msvLclnt.dll] [0x00000700] 21/02/2005 01:44:06:364 :[00000001] File C:\RECYCLER\S-1-5-21-1801674531-842925246-839522115-1003\Dc54.htm infected by Exploit.VBS.Phel.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:44:06:754 :[00000001] File C:\RECYCLER\S-1-5-21-1801674531-842925246-839522115-1003\Dc57.htm infected by Exploit.HTML.Mht
[msvLclnt.dll] [0x00000700] 21/02/2005 01:44:06:975 :[00000001] File C:\RECYCLER\S-1-5-21-1801674531-842925246-839522115-1003\Dc58.CHM infected by Trojan-Downloader.VBS.Psyme.ac
[msvLclnt.dll] [0x00000700] 21/02/2005 01:45:02:655 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP18\A0002445.exe infected by Backdoor.Win32.Rbot.gen
[msvLclnt.dll] [0x00000700] 21/02/2005 01:45:06:230 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP18\A0002447.exe infected by Backdoor.Win32.Rbot.gen
[msvLclnt.dll] [0x00000700] 21/02/2005 01:48:04:366 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP26\A0005751.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:48:04:536 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP26\A0005752.exe infected by not-a-virus:AdWare.Msnagent.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:48:04:626 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP26\A0005753.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:48:21:360 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP29\A0005919.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:48:21:511 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP29\A0005920.exe infected by not-a-virus:AdWare.Msnagent.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:48:21:591 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP29\A0005921.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:48:31:475 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP31\A0005963.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:48:31:635 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP31\A0005964.exe infected by not-a-virus:AdWare.Msnagent.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:48:31:715 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP31\A0005965.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:48:34:349 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP31\A0006001.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:48:34:519 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP31\A0006002.exe infected by not-a-virus:AdWare.Msnagent.a
[msvLclnt.dll] [0x00000700] 21/02/2005 01:48:34:619 :[00000001] File C:\System Volume Information\_restore{B3DBCB53-5DD9-4762-AE94-CFAB0E801C74}\RP31\A0006003.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 02:05:49:307 :[00000001] File C:\WINDOWS\system32\connmie.exe infected by not-a-virus:AdWare.FindSpy.a
[msvLclnt.dll] [0x00000700] 21/02/2005 02:12:06:219 :VirusCount = 118955 Latest Date = 2005/02/20
[msvLclnt.dll] [0x00000690] 21/02/2005 02:31:00:981 :VirusCount = 118955 Latest Date = 2005/02/20
[msvLclnt.dll] [0x00000600] 21/02/2005 14:56:08:658 :ModuleName = C:\bases\mwavscan.com
[msvLclnt.dll] [0x00000600] 21/02/2005 14:56:08:678 :Registry Key Deleted Properly!!!
[msvLclnt.dll] [0x00000600] 21/02/2005 14:56:14:717 :Options Set by External applications mwavscan.com are 9896960 (0x970400):
[msvLclnt.dll] [0x00000600] 21/02/2005 14:56:14:717 :Mode :PACKED,ARCHIVED,CA,WARNINGS,MAILPLAIN
Habe jetzt zuletzt versucht mit Hijacker das Problem zu lösen und drei Files schon gelöscht (nämlich die drei o 17 )...Bei den anderen bin ich mir nicht sicher
- Code: Alles auswählen
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Speed Disk\nopdb.exe
C:\Programme\QuickTime\qttask.exe
C:\WINDOWS\System32\ctfmon.exe
C:\PROGRAM FILES\interMute\SpySubtract\SpySub.exe
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\temp\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,(Default) = http://clearsurfing.net/srch.php?qq=%s
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,Default_Search_URL = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: FreshBar - {06ABAA2D-34AB-4902-A326-409BD9B9A7A5} - C:\WINDOWS\System32\iecustom32.dll
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: Norton System Doctor.lnk = C:\Programme\Norton Utilities\SYSDOC32.EXE
O4 - Global Startup: SpySubtract.lnk = C:\PROGRAM FILES\interMute\SpySubtract\SpySub.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O17 - HKLM\System\CCS\Services\Tcpip\..\{20C6D16C-B5F3-406F-9447-E1B7C59B4BFB}: NameServer = 69.50.188.180,195.225.176.31
O17 - HKLM\System\CS1\Services\Tcpip\..\{20C6D16C-B5F3-406F-9447-E1B7C59B4BFB}: NameServer = 69.50.188.180,195.225.176.31
O17 - HKLM\System\CS2\Services\Tcpip\..\{20C6D16C-B5F3-406F-9447-E1B7C59B4BFB}: NameServer = 69.50.188.180,195.225.176.31
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programme\Norton Utilities\NPROTECT.EXE
O23 - Service: Speed Disk service - Symantec Corporation - C:\Programme\Speed Disk\nopdb.exe
Das Problem ist das mein Rechner zu Beginn jedes Neustarts nun ungefähr 10 Minuten lang im Hintergrund rechnet und höllisch langsam ist??
Ich wäre echt dankbar für eure Hilfe