Logfile of HijackThis v1.99.1
Scan saved at 21:02:42, on 07.06.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AVPersonal\AVGUARD.EXE
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\Programme\Executive Software\Diskeeper\DkService.exe
C:\Programme\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\TELES\skyDSL\Proxy\craxy.exe
C:\Programme\TELES\skyDSL\tskymtpc.exe
C:\Programme\TELES\skyDSL\tkpsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programme\Winamp\winampa.exe
C:\WINDOWS\system32\RunDll32.exe
C:\Programme\AVPersonal\AVGNT.EXE
C:\Programme\Intuwave\Shared\mRouterRunTime\mRouterConfig.exe
C:\Programme\Intuwave\Shared\mRouterRunTime\mRouterRuntime.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\TELES\skyDSL\tskyclnt.exe
C:\Programme\Opera\opera.exe
C:\Programme\WEBDE\SmartSurfer2.31\SmartSurfer.exe
C:\Programme\Winamp\winamp.exe
C:\Programme\ICQLite\ICQLite.exe
C:\Programme\Outlook Express\msimn.exe
C:\Programme\WinAce\WinAce.exe
C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\~AceTemp\hijackthis\HijackThis.exe
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Programme\FlashFXP\IEFlash.dll
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [mRouterConfig for Siemens Data Suite SX1] C:\Programme\Intuwave\Shared\mRouterRunTime\mRouterConfig.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "C:\Programme\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: GetRight - Tray Icon.lnk = C:\Programme\GetRight\getright.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Download with GetRight - C:\Programme\GetRight\GRdownload.htm
O8 - Extra context menu item: Download with NetPumper - C:\Programme\NetPumper\AddUrl.htm
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Open with GetRight Browser - C:\Programme\GetRight\GRbrowse.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\j2re1.4.2_04\bin\npjpi142_04.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: skyDSL++ - {F7522CA2-3DDA-11d3-8560-0060977792B1} - C:\Programme\TELES\skyDSL\sky2sky.exe
O9 - Extra button: skyDSL- - - {F7522CA8-3DDA-11d3-8560-0060977792B1} - C:\Programme\TELES\skyDSL\sky2fon.exe
O10 - Unknown file in Winsock LSP: c:\windows\system32\skysocks.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\skysocks.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\skysocks.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\skysocks.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\skysocks.dll
O10 - Unknown file in Winsock LSP: c:\windows\system32\skysocks.dll
O14 - IERESET.INF: START_PAGE_URL=about:blank
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v ... 5425703589
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/So ... b31267.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{7AACBCCB-464F-447A-BB33-696EB017E806}: NameServer = 213.20.255.35 193.189.244.205
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE
O23 - Service: Diskeeper - Executive Software International, Inc. - C:\Programme\Executive Software\Diskeeper\DkService.exe
O23 - Service: InCD File System Service (InCDsrv) - AHEAD Software - C:\Programme\Ahead\InCD\InCDsrv.exe
O23 - Service: Macromedia Licensing Service - Macromedia - C:\Programme\Gemeinsame Dateien\Macromedia Shared\Service\Macromedia Licensing.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programme\Sygate\SPF\smc.exe
O23 - Service: skyDSL-Proxy (tntcraxy) - Unknown owner - C:\Programme\TELES\skyDSL\Proxy\craxy.exe" service (file missing)
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe
--------------------------------------------------
-------------------- INFECTED --------------------
--------------------------------------------------
1: Wed Jun 08 18:48:57 2005 => System found infected with eZula Spyware/Adware (instsrv.exe)! Action taken: No Action Taken.
2: Wed Jun 08 19:00:36 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.*
3: Wed Jun 08 19:02:42 2005 => File C:\Programme\B5APPZ\0061\CrackSearcher.exe infected by "HackTool.Win32.CrackSearch.a" Virus! Action Taken: No Action Taken.
4: Wed Jun 08 19:30:52 2005 => File C:\System Volume Information\_restore{602D783D-0B4F-4BF6-BA77-ADDD8FEF65F7}\RP77\A0018492.exe infected by "Trojan-Downloader.Win32.INService.gen" Virus! Action Taken: No Action Taken.
5: Wed Jun 08 19:44:54 2005 => Scanning File E:\musik\metal\Agoraphobic Nosebleed\agoraphobic nosebleed & converge - the poacher diaries split\agoraphobic nosebleed - 09 - infected womb.mp3 [**]
6: Wed Jun 08 19:45:15 2005 => Scanning File E:\musik\metal\Carcass\1989 - Symphonies Of Sickness\Carcass-07.Swarminginfectedmassofinfectedvirulency.mp3 [**]
7: Wed Jun 08 19:45:36 2005 => Scanning File E:\musik\metal\Disgorge\Digorge(Netherlands)\2001 - Gorge this(EP)\disgorge (hol) - gorge this - 08 - infected.mp3 [**]
8: Wed Jun 08 19:46:25 2005 => Scanning File E:\musik\metal\Krisiun\2004 - Bloodshed\krisiun - 11 infected core.mp3 [**]
9: Wed Jun 08 19:51:05 2005 => File E:\Net Tools\Service Pack 2\Microsoft_Windows_2003_and_XP_Anti_Product_Activation_Crack_v1.6.2.zip infected by "Trojan-Downloader.Win32.IstBar.er" Virus! Action Taken: No Action Taken.
--------------------------------------------------
--------------------- TAGGED ---------------------
--------------------------------------------------
1: Wed Jun 08 18:52:10 2005 => File C:\WINDOWS\system32\instsrv.exe tagged as not-a-virus:Tool.Win32.ServiceRunner.g. No Action Taken.
2: Wed Jun 08 18:52:54 2005 => File C:\WINDOWS\system32\psexec.exe tagged as not-a-virus:Tool.Win32.PsExec.153. No Action Taken.
3: Wed Jun 08 18:58:14 2005 => File C:\Program Files\mIRC\mirc.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.16. No Action Taken.
4: Wed Jun 08 19:00:38 2005 => File C:\Programme\B5APPZ\0002\Patch.exe tagged as not-a-virus:Tool.Win32.TPE.a. No Action Taken.
5: Wed Jun 08 19:00:38 2005 => File C:\Programme\B5APPZ\0004\0004.exe tagged as not-a-virus:Tool.Win32.ServiceRunner.d. No Action Taken.
6: Wed Jun 08 19:00:38 2005 => File C:\Programme\B5APPZ\0004\BulletProof.FTP.Server.v2.30.15.WinAll.Cracked\AddOns\G6Service.exe tagged as not-a-virus:Tool.Win32.ServiceRunner.d. No Action Taken.
7: Wed Jun 08 19:01:25 2005 => File C:\Programme\B5APPZ\0031\setup.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
8: Wed Jun 08 19:02:40 2005 => File C:\Programme\B5APPZ\0061\Cracks\J\A\Jasc_Paint_Shop_Pro_v8.01_by_LasH.zip tagged as not-a-virus:Tool.Win32.TPE.a. No Action Taken.
9: Wed Jun 08 19:02:40 2005 => File C:\Programme\B5APPZ\0061\Cracks\J\A\Jasc_Paint_Shop_Pro_v8.10.zip tagged as not-a-virus:CrackTool.Win32.AssasinPatch. No Action Taken.
10: Wed Jun 08 19:19:48 2005 => File C:\Programme\TightVNC\VNCHooks.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.b. No Action Taken.
11: Wed Jun 08 19:19:52 2005 => File C:\Programme\TightVNC\WinVNC.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.h. No Action Taken.
12: Wed Jun 08 19:21:18 2005 => File C:\System Volume Information\_restore{602D783D-0B4F-4BF6-BA77-ADDD8FEF65F7}\RP13\A0003709.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.16. No Action Taken.
13: Wed Jun 08 19:25:41 2005 => File C:\System Volume Information\_restore{602D783D-0B4F-4BF6-BA77-ADDD8FEF65F7}\RP2\A0001244.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.h. No Action Taken.
14: Wed Jun 08 19:29:27 2005 => File C:\System Volume Information\_restore{602D783D-0B4F-4BF6-BA77-ADDD8FEF65F7}\RP68\A0017759.exe tagged as not-a-virus:Tool.Win32.ServiceRunner.d. No Action Taken.
15: Wed Jun 08 19:41:35 2005 => File C:\WINDOWS\system32\instsrv.exe tagged as not-a-virus:Tool.Win32.ServiceRunner.g. No Action Taken.
16: Wed Jun 08 19:42:31 2005 => File C:\WINDOWS\system32\psexec.exe tagged as not-a-virus:Tool.Win32.PsExec.153. No Action Taken.
--------------------------------------------------
--------------------- ERRORS ---------------------
--------------------------------------------------
1: Wed Jun 08 18:47:05 2005 => ERROR!!! Invalid Entry \??\C:\WINDOWS\system32\drivers\EagleNT.sys in SYSTEM\CurrentControlSet\Services\EagleNT...
2: Wed Jun 08 18:49:27 2005 => Entry "HKCR\CLSID\{0DED49D5-A8B7-4d5d-97A1-12B0C195874D}" refers to invalid object "BdaPlgin.ax". Action Taken: No Action Taken.
3: Wed Jun 08 18:49:40 2005 => Entry "HKCR\CLSID\{B0693766-5278-4ec6-B9E1-3CE40560EF5A}" refers to invalid object "CaPlgin.ax". Action Taken: No Action Taken.
4: Wed Jun 08 18:49:46 2005 => Entry "HKCR\CLSID\{FD0A5AF3-B41D-11d2-9C95-00C04F7971E0}" refers to invalid object "BdaPlgin.ax". Action Taken: No Action Taken.
5: Wed Jun 08 18:57:57 2005 => Result: ERROR!!! File C:\My Shared Folder\Grand-Theft-Auto-2.sis is Not Scanned
6: Wed Jun 08 19:02:39 2005 => Result: ERROR!!! File C:\Programme\B5APPZ\0061\Cracks\J\A\Jasc_Animation_Shop_v2.00.zip is Not Scanned
7: Wed Jun 08 19:43:54 2005 => Result: ERROR!!! File E:\E-Books\FAQ's\Zips\batch_fuer_einsteiger-.rar is Not Scanned
8: Wed Jun 08 19:50:12 2005 => Result: ERROR!!! File E:\Net Tools\Handy\Grand-Theft-Auto-2.sis is Not Scanned
9: Wed Jun 08 19:51:05 2005 => Result: ERROR!!! File E:\Net Tools\Photoshop 8.0 CS\crckap.cab is Not Scanned
--------------------------------------------------
-------- DATEIEN ZUM LÖSCHEN HINZUGEFÜGT ---------
--------------------------------------------------
1: C:\WINDOWS\system32\instsrv.exe => tagged:Tool.Win32.ServiceRunner.g.
2: C:\WINDOWS\system32\psexec.exe => tagged:Tool.Win32.PsExec.153.
3: C:\Program Files\mIRC\mirc.exe => tagged:Client-IRC.Win32.mIRC.16.
4: C:\Programme\B5APPZ\0002\Patch.exe => tagged:Tool.Win32.TPE.a.
5: C:\Programme\B5APPZ\0004\0004.exe => tagged:Tool.Win32.ServiceRunner.d.
6: C:\Programme\B5APPZ\0004\BulletProof.FTP.Server.v2.30.15.WinAll.Cracked\AddOns\G6Service.exe => tagged:Tool.Win32.ServiceRunner.d.
7: C:\Programme\B5APPZ\0031\setup.exe => tagged:Tool.Win32.Reboot.
8: C:\Programme\B5APPZ\0061\Cracks\J\A\Jasc_Paint_Shop_Pro_v8.01_by_LasH.zip => tagged:Tool.Win32.TPE.a.
9: C:\Programme\B5APPZ\0061\Cracks\J\A\Jasc_Paint_Shop_Pro_v8.10.zip => tagged:CrackTool.Win32.AssasinPatch.
10: C:\Programme\B5APPZ\0061\CrackSearcher.exe => HackTool.Win32.CrackSearch.a
11: C:\Programme\TightVNC\VNCHooks.dll => tagged:RemoteAdmin.Win32.WinVNC-based.b.
12: C:\Programme\TightVNC\WinVNC.exe => tagged:RemoteAdmin.Win32.WinVNC-based.h.
13: C:\System Volume Information\_restore{602D783D-0B4F-4BF6-BA77-ADDD8FEF65F7}\RP13\A0003709.exe => tagged:Client-IRC.Win32.mIRC.16.
14: C:\System Volume Information\_restore{602D783D-0B4F-4BF6-BA77-ADDD8FEF65F7}\RP2\A0001244.exe => tagged:RemoteAdmin.Win32.WinVNC-based.h.
15: C:\System Volume Information\_restore{602D783D-0B4F-4BF6-BA77-ADDD8FEF65F7}\RP68\A0017759.exe => tagged:Tool.Win32.ServiceRunner.d.
16: C:\System Volume Information\_restore{602D783D-0B4F-4BF6-BA77-ADDD8FEF65F7}\RP77\A0018492.exe => Trojan-Downloader.Win32.INService.gen
17: E:\musik\metal\Agoraphobic Nosebleed\agoraphobic nosebleed & converge - the poacher diaries split\agoraphobic nosebleed - 09 - =>
18: E:\musik\metal\Krisiun\2004 - Bloodshed\krisiun - 11 =>
19: E:\Net Tools\Service Pack 2\Microsoft_Windows_2003_and_XP_Anti_Product_Activation_Crack_v1.6.2.zip => Trojan-Downloader.Win32.IstBar.er
--------------------------------------------------
-------------------- Statistik -------------------
--------------------------------------------------
Wed Jun 08 19:51:29 2005 => Total Objects Scanned: 93226
Wed Jun 08 19:51:29 2005 => Total Virus(es) Found: 21
Wed Jun 08 19:51:29 2005 => Total Errors: 9
Wed Jun 08 19:51:29 2005 => Virus Database Date: 2005/06/08
Wed Jun 08 19:51:30 2005 => Virus Database Count: 134000

REGEDIT4
; RegSrch.vbs © Bill James
; Registry search results for string "EagleNT" 09.06.2005 17:12:48
; NOTE: This file will be deleted when you close WordPad.
; You must manually save this file to a new location if you want to refer to it again later.
; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_EAGLENT]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_EAGLENT\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_EAGLENT\0000]
"Service"="EagleNT"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_EAGLENT\0000]
"DeviceDesc"="EagleNT"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_EAGLENT\0000\Control]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EagleNT]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EagleNT]
"DisplayName"="EagleNT"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EagleNT\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EagleNT\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\EagleNT\Enum]
"0"="Root\\LEGACY_EAGLENT\\0000"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_EAGLENT]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_EAGLENT\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_EAGLENT\0000]
"Service"="EagleNT"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_EAGLENT\0000]
"DeviceDesc"="EagleNT"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\EagleNT]
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\EagleNT]
"DisplayName"="EagleNT"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\EagleNT\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_EAGLENT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_EAGLENT\0000]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_EAGLENT\0000]
"Service"="EagleNT"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_EAGLENT\0000]
"DeviceDesc"="EagleNT"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_EAGLENT\0000\Control]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EagleNT]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EagleNT]
"DisplayName"="EagleNT"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EagleNT\Security]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EagleNT\Enum]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\EagleNT\Enum]
"0"="Root\\LEGACY_EAGLENT\\0000"
Mitglieder in diesem Forum: 0 Mitglieder und 0 Gäste