Hallo nikita.
Ich habe versucht deine anweisungen zu befolgen aber das hat leider nur bedingt geklappt.
die C:\WINDOWS\System32\wvsvc.exe kann ich auf dem computer leider nicht mehr finden habe mit der suche funktion alles sowohl im abgesicherten als auch im normalen modus abgesucht. allerdings habe ich sie auch schon nach deinem ersten post gelöscht weil du es da empfohlen hattest. sie scheint nicht wieder auf den PC gelangt zu sein. trotsdem taucht sie sowohl in der log von hjthis als auch von mwav auf wie du unten sehen kannst. das einzige was ich finden konnte ist die datei:
C:\WINDOWS\Prefetch\WVSVC.EXE-3AED53B6.pf
diese habe ich vorsorglich mit den onlinescanneren gescannt. der eine hat nix gefunden und das ergebniss vom anderen sowie die los von hjthis und mwav sind folgende
INTERNETSCANN:
Service load: 0% 100%
File: WVSVC.EXE-3AED53B6.pf
Status: OK
Packers detected: None
AntiVir No viruses found (1.22 seconds taken)
Avast No viruses found (4.61 seconds taken)
BitDefender No viruses found (2.54 seconds taken)
ClamAV No viruses found (6.69 seconds taken)
Dr.Web No viruses found (4.37 seconds taken)
F-Prot Antivirus No viruses found (0.35 seconds taken)
Kaspersky Anti-Virus No viruses found (3.97 seconds taken)
mks_vir No viruses found (1.60 seconds taken)
NOD32 No viruses found (2.20 seconds taken)
Norman Virus Control No viruses found (1.08 seconds taken)
Statistics
Last piece of malware found was TrojanDownloader.Win32.Swizzor.bo in ElseBird.exe, detected by:
Scanner Malware name Time taken
AntiVir X 1.25 seconds
Avast X 3.09 seconds
BitDefender X 3.13 seconds
ClamAV X 6.95 seconds
Dr.Web X 4.20 seconds
F-Prot Antivirus X 0.41 seconds
Kaspersky Anti-Virus TrojanDownloader.Win32.Swizzor.bo 4.02 seconds
mks_vir Win32.4 1.46 seconds
NOD32 X 2.23 seconds
Norman Virus Control X 1.01 seconds
Service statistics:
3302 files (2459 of those unique) have been uploaded & scanned since 30/09/2004, the day of the last database purge.
799 of those 2459 files contained a virus or any other form of malware.
This page has been visited 8515 times in this time period.
This service managed to spot 42 pieces of malware no vendor used knew about at the time of uploading.
The service also warned against 298 suspicious files without any help from scanner results.
However, 24 files reported to be OK were found out to be malware later (this is checked daily).
As far as can be told, all this together makes this service 99.02% accurate. However, since it is very well possible malware has been uploaded no scanner knows about at this time, this number is to be taken with a proper amount of skepticism.
Most popular malware:
Rank Malware name Uploaded Last known filename
1 tr/exploit.ms04-28 36 times crck.tmp
2 backdoor.sdbot.gen 22 times asa.exe
3 backdoor.win32.rbot.gen 15 times chs.exe
4 backdoor.agobot.3.gen 13 times spooles32.exe
5 trojandropper.win32.small.lx 12 times MSMSGSVC.exe
6 win32:trojan-gen. {other} 11 times i_xplogger.exe
7 exploit.crashsos 11 times AP4.jpg
8 worm/bagle.o 11 times winupd.exe
9 bds/picharad 11 times WINSET32.EXE.001
10 dr/bridge.a.2 9 times Beyond Compare v2.2.7.build.227 5 Kb [09.09.04] - d227bcoa.zip
11 win32.p2p.spybot.gen 9 times McAfee AntiVirus 2005 Gold Edition.exe
12 backdoor.hackarmy.1.gen 9 times David Beckham.zip
13 modification of backdoor.generic.112 8 times tory.exe
14 vbs:malware 7 times counter[1].htm.Vir
15 tr/dldr.krepper.3 7 times pvxatg.exe
AKTUELLE HJTHIS LOG
Logfile of HijackThis v1.97.7
Scan saved at 18:04:24, on 10.10.2004
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\SYSTEM32\logonui.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\SYSTEM32\GEARSEC.EXE
C:\Programme\Norton AntiVirus\navapsvc.exe
C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programme\ICQLite\ICQLite.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\WINDOWS\System32\wvsvc.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\WinZip\WZQKPICK.EXE
C:\Programme\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\kernel.exe
C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\sc_watch.exe
C:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis2\PROFIL~1.EXE
C:\PROGRAMME\T-ONLINE\T-ONLINE_SOFTWARE_5\BROWSER\BROWSER.EXE
C:\WINDOWS\system32\NOTEPAD.EXE
C:\WINDOWS\System32\svchost.exe
D:\Tarek\Cracks und Programme\Antivir\hjt\HijackThis.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [nForce Tray Options] sstray.exe /r
O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [Starting up] wvsvc.exe
O4 - HKLM\..\RunServices: [Starting up] wvsvc.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Starting up] wvsvc.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programme\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Nach Microsoft &Excel exportieren -
res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O9 - Extra button: ICQ 4.1 (HKLM)
O9 - Extra 'Tools' menuitem: ICQ Lite (HKLM)
O16 - DPF: {8EB3FF4E-86A1-4717-884D-7BA2D38272CB} (F-Secure Online Scanner) -
http://support.f-secure.com/ols/fscax.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{CB531FF0-FF37-4066-9C10-B54D62FE0A04}: NameServer = 217.237.150.97 217.237.149.161
INFIZIERTE FILES LAUT MWAV
Sun Oct 10 17:03:16 2004 => File C:\WINDOWS\SYSTEM32\wvsvc.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:03:17 2004 => File C:\WINDOWS\SYSTEM32\wvsvc.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:03:18 2004 => File C:\WINDOWS\SYSTEM32\wvsvc.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:04:50 2004 => File C:\WINDOWS\System32\wvsvc.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:05:34 2004 => File C:\Dokumente und Einstellungen\Tarek\Lokale Einstellungen\Temp\dhbh.dat infected by "TrojanDropper.Win32.Small.ja" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:05:35 2004 => File C:\Dokumente und Einstellungen\Tarek\Lokale Einstellungen\Temp\installer.exe infected by "not-a-virus:AdvWare.PurityScan.u" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:06:21 2004 => Scanning Folder: C:\Programme\Buhl\Virus Killer\Infected\*.*
Sun Oct 10 17:06:21 2004 => Scanning File C:\Programme\Buhl\Virus Killer\Infected\commando.exe
Sun Oct 10 17:06:21 2004 => File C:\Programme\Buhl\Virus Killer\Infected\commando.exe tagged as not-a-virus:RiskWare.Tool.HideWindows. No Action Taken.
Sun Oct 10 17:06:21 2004 => Scanning File C:\Programme\Buhl\Virus Killer\Infected\index.exe
Sun Oct 10 17:06:21 2004 => File C:\Programme\Buhl\Virus Killer\Infected\index.exe infected by "TrojanDownloader.Win32.Agent.dn" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:06:21 2004 => Scanning File C:\Programme\Buhl\Virus Killer\Infected\msbb.exe
Sun Oct 10 17:06:21 2004 => File C:\Programme\Buhl\Virus Killer\Infected\msbb.exe infected by "not-a-virus:AdvWare.180Solutions" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:06:21 2004 => Scanning File C:\Programme\Buhl\Virus Killer\Infected\YEA.REG
Sun Oct 10 17:06:21 2004 => File C:\Programme\Buhl\Virus Killer\Infected\YEA.REG infected by "Trojan.WinREG.LowZones.a" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:14:10 2004 => File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LD0XDSLY\silent_install[1].exe infected by "not-a-virus:AdvWare.ToolBar.EliteBar.m" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:14:10 2004 => File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LD0XDSLY\silent_install[2].exe infected by "not-a-virus:AdvWare.ToolBar.EliteBar.m" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:14:11 2004 => File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\SL6PFPBD\silent_install[1].exe infected by "not-a-virus:AdvWare.ToolBar.EliteBar.m" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:19:39 2004 => File C:\WINDOWS\system32\wvsvc.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:22:27 2004 => File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LD0XDSLY\silent_install[1].exe infected by "not-a-virus:AdvWare.ToolBar.EliteBar.m" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:22:27 2004 => File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LD0XDSLY\silent_install[2].exe infected by "not-a-virus:AdvWare.ToolBar.EliteBar.m" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:22:27 2004 => File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\SL6PFPBD\silent_install[1].exe infected by "not-a-virus:AdvWare.ToolBar.EliteBar.m" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:23:47 2004 => File C:\WINDOWS\system32\wvsvc.exe infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.
Sun Oct 10 17:23:48 2004 => Total Disinfected Files: 0
wie gehts weiter kannste dier erklären warum die datei immerwieder gescannt wird ich sie aber nicht finden kann? was mache ich nun? soll ich die datei C:\WINDOWS\Prefetch\WVSVC.EXE-3AED53B6.pf löschen?