Hallo!
zu 1.: Kontiki ist Sygate stimmt's? Das hatte ich irgendwann mal runtergeladen aber nie installiert... Ist jetzt auch noch drin.
zu 2.: alles gelöscht, bis auf \Dea;jlpr.dll und \dhbrwsr.exe. Die gab's nicht
zu 3. ok...
zu 4. 165 Dinger gelöscht! Unglaublich...
zu 5.:
File C:\WINDOWS\dhp2.dll infected by "not-a-virus:AdvWare.DealHelper.j" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\Annika\Desktop\Fun\SHEEP.EXE tagged as not-a-virus:Simulator.Win16.Sheep. No Action Taken.
File C:\Dokumente und Einstellungen\Annika\Desktop\Uni\Gru - Päd\Gru - Päd\SHEEP.EXE tagged as not-a-virus:Simulator.Win16.Sheep. No Action Taken.
File C:\Dokumente und Einstellungen\Annika\Desktop\Uni\U-Materialien\neu\Datenauszug aus Dokument ''...'.shs infected by "BkCln.Unknown" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\Hildegard\Lokale Einstellungen\Temporary Internet Files\Content.IE5\1SCB9T89\keywords;cat=11450;cat=9816;cat=13029;cat=54515;tile=1;sz=468x60;list=stores;kw=joop-+prada-+gabbana-+dkny-+sixty-+versace-+bogner-+escada-+sander-+hech_ infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\Hildegard\Lokale Einstellungen\Temporary Internet Files\Content.IE5\1SCB9T89\keywords;cat=11450;cat=9816;cat=13029;tile=1;sz=468x60;list=stores;kw=joop-+prada-+gabbana-+dkny-+sixty-+versace-+bogner-+escada-+sander-+hechter-+kenzo_ infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\Hildegard\Lokale Einstellungen\Temporary Internet Files\Content.IE5\GTEZC1QV\keywords;cat=11450;cat=9816;cat=13045;cat=54352;tile=1;sz=468x60;list=stores;kw=joop-+prada-+gabbana-+dkny-+sixty-+versace-+bogner-+escada-+sander-+hech_ infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\Hildegard\Lokale Einstellungen\Temporary Internet Files\Content.IE5\K1UJK9UN\keywords;cat=11450;cat=9816;cat=13021;tile=1;sz=468x60;list=stores;kw=prada-+gucci-+joop-+boss-+lauren-+hilfiger-+max-+dolce-+karan-+sander;ord=10950932_ infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\Hildegard\Lokale Einstellungen\Temporary Internet Files\Content.IE5\K1UJK9UN\keywords;cat=11450;cat=9816;cat=13021;tile=1;sz=468x60;list=stores;kw=prada-+gucci-+joop-+boss-+lauren-+hilfiger-+max-+dolce-+karan-+sander;ord=10950933_ infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\Hildegard\Lokale Einstellungen\Temporary Internet Files\Content.IE5\O5YJGLIN\keywords;cat=11450;cat=9816;cat=13029;cat=54515;tile=1;sz=468x60;list=stores;kw=joop-+prada-+gabbana-+dkny-+sixty-+versace-+bogner-+escada-+sander-+hech_ infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\Hildegard\Lokale Einstellungen\Temporary Internet Files\Content.IE5\UVQRYT67\keywords;cat=11450;cat=9816;cat=13045;cat=54352;tile=1;sz=468x60;list=stores;kw=joop-+prada-+gabbana-+dkny-+sixty-+versace-+bogner-+escada-+sander-+hech_ infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\Hildegard\Lokale Einstellungen\Temporary Internet Files\Content.IE5\UVQRYT67\keywords;cat=11450;cat=9816;tile=1;sz=468x60;list=stores;kw=joop-+prada-+gabbana-+dkny-+sixty-+versace-+bogner-+escada-+sander-+hechter-+kenzo-+maraedel_ infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\Hildegard\Lokale Einstellungen\Temporary Internet Files\Content.IE5\W1MFO9AR\keywords;cat=11450;cat=9816;tile=1;sz=468x60;list=stores;kw=joop-+prada-+gabbana-+dkny-+sixty-+versace-+bogner-+escada-+sander-+hechter-+kenzo-+maraedel_ infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\Hildegard\Lokale Einstellungen\Temporary Internet Files\Content.IE5\WL45IVK9\keywords;cat=11450;cat=9816;cat=13021;tile=1;sz=468x60;list=stores;kw=prada-+gucci-+joop-+boss-+lauren-+hilfiger-+max-+dolce-+karan-+sander;ord=10950932_ infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\Hildegard\Lokale Einstellungen\Temporary Internet Files\Content.IE5\WL45IVK9\keywords;cat=11450;cat=9816;cat=13045;tile=1;sz=468x60;list=stores;kw=joop-+prada-+gabbana-+dkny-+sixty-+versace-+bogner-+escada-+sander-+hechter-+kenzo_ infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-329068152-117609710-725345543-1007\Dc369.exe infected by "not-a-virus:AdvWare.DealHelper.b" Virus. Action Taken: File Renamed.
File C:\RECYCLER\S-1-5-21-329068152-117609710-725345543-1007\Dc371.exe infected by "not-a-virus:AdvWare.DealHelper.p" Virus. Action Taken: File Renamed.
File C:\RECYCLER\S-1-5-21-329068152-117609710-725345543-1007\Dc372.exe infected by "not-a-virus:AdvWare.DealHelper.f" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{787A0B5F-9E07-4388-AC8D-BD054A949231}\RP62\A0005387.dll infected by "not-a-virus:AdvWare.DealHelper.j" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{787A0B5F-9E07-4388-AC8D-BD054A949231}\RP62\A0005388.dll infected by "not-a-virus:AdvWare.DealHelper.j" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{787A0B5F-9E07-4388-AC8D-BD054A949231}\RP62\A0005389.exe infected by "not-a-virus:AdvWare.DealHelper.b" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{787A0B5F-9E07-4388-AC8D-BD054A949231}\RP62\A0005390.exe infected by "not-a-virus:AdvWare.DealHelper.o" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{787A0B5F-9E07-4388-AC8D-BD054A949231}\RP63\A0005423.dll infected by "not-a-virus:AdvWare.DealHelper.p" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{787A0B5F-9E07-4388-AC8D-BD054A949231}\RP63\A0005424.dll infected by "not-a-virus:AdvWare.DealHelper.p" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{787A0B5F-9E07-4388-AC8D-BD054A949231}\RP82\A0010341.dll infected by "not-a-virus:AdvWare.DealHelper.o" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{787A0B5F-9E07-4388-AC8D-BD054A949231}\RP82\A0010345.dll infected by "not-a-virus:AdvWare.Winad" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{787A0B5F-9E07-4388-AC8D-BD054A949231}\RP82\A0010350.dll infected by "not-a-virus:AdvWare.DealHelper.j" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{787A0B5F-9E07-4388-AC8D-BD054A949231}\RP82\A0010351.exe infected by "not-a-virus:AdvWare.DealHelper.b" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{787A0B5F-9E07-4388-AC8D-BD054A949231}\RP82\A0010352.exe infected by "not-a-virus:AdvWare.DealHelper.p" Virus. Action Taken: File Renamed.
File C:\System Volume Information\_restore{787A0B5F-9E07-4388-AC8D-BD054A949231}\RP82\A0010353.exe infected by "not-a-virus:AdvWare.DealHelper.f" Virus. Action Taken: File Renamed.
Oh mann...
Und noch Hijack:
Logfile of HijackThis v1.98.2
Scan saved at 16:43:02, on 19.09.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\F-Secure\Common\FSMA32.EXE
C:\Programme\F-Secure\Common\FSMB32.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\Programme\F-Secure\Common\FCH32.EXE
C:\Programme\F-Secure\Common\FAMEH32.EXE
C:\Programme\F-Secure\Common\FSGK32.EXE
C:\Programme\F-Secure\Common\FNRB32.EXE
C:\Programme\F-Secure\Common\FIH32.EXE
C:\Programme\F-Secure\Anti-Virus\fsav32.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis1\ToADiMon.exe
C:\Programme\F-Secure\Common\FSM32.EXE
C:\WINDOWS\kdx\KHost.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\InterVideo\Common\Bin\WinCinemaMgr.exe
C:\WINDOWS\system32\ntvdm.exe
C:\WINDOWS\system32\wuauclt.exe
C:\DOKUME~1\Annika\LOKALE~1\Temp\Temporäres Verzeichnis 1 für hijackthis.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://www.web.de/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar1.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [ToADiMon.exe] C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis1\ToADiMon.exe -TOnlineAutodialStart
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programme\F-Secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [kdx] C:\WINDOWS\kdx\KHost.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Programme\InterVideo\Common\Bin\WinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search -
res://C:\Programme\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Im Cache gespeicherte Seite -
res://C:\Programme\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Nach Microsoft &Excel exportieren -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Verweisseiten -
res://C:\Programme\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Ähnliche Seiten -
res://C:\Programme\Google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) -
http://software-dl.real.com/13f751e45db ... xIE601.cab
O16 - DPF: {F54C1137-5E34-4B95-95A5-BA56D4D8D743} (Secure Delivery) -
http://www.gamespot.com/KDX22/download/kdx.cab
Was ist überhaupt DealHelper? Ein Virus?
Danke!! *Annika*