Warum kostenlos registrieren?
Nur als registriertes Mitglied hast Du vollen Zugriff auf alle Funktionen unserer Website. So kannst Du eigene Fragen stellen und hast die volle Übersicht über neue interessante Themen im Forum.
Jetzt kostenlos registrieren.
Login
[Microsoft Update] vpc32.exe
64 Beiträge • Seite 2 von 5 • 1, 2, 3, 4, 5
hallo, hier ist mein log:
Logfile of HijackThis v1.98.2
Scan saved at 08:07:13, on 23.09.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AVPersonal\AVGUARD.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\PGPsdkServ.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\WINDOWS\system32\slserv.exe
C:\Programme\Java\j2re1.4.2_04\bin\jusched.exe
C:\Programme\AVPersonal\AVGNT.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\PGP for Windows XP\PGPtray.exe
C:\Programme\CiDial\CiDial.exe
C:\Programme\Internet Explorer\IEXPLORE.EXE
C:\Dokumente und Einstellungen\*lol* you\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web.de/
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: PGPtray.lnk = ?
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{89353775-3D54-4AB1-838C-E9E1E8BEECB2}: NameServer = 217.237.150.33 217.237.151.161
grüße
Logfile of HijackThis v1.98.2
Scan saved at 08:07:13, on 23.09.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\AVPersonal\AVGUARD.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\PGPsdkServ.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\WINDOWS\system32\slserv.exe
C:\Programme\Java\j2re1.4.2_04\bin\jusched.exe
C:\Programme\AVPersonal\AVGNT.EXE
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\PGP for Windows XP\PGPtray.exe
C:\Programme\CiDial\CiDial.exe
C:\Programme\Internet Explorer\IEXPLORE.EXE
C:\Dokumente und Einstellungen\*lol* you\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web.de/
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: PGPtray.lnk = ?
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{89353775-3D54-4AB1-838C-E9E1E8BEECB2}: NameServer = 217.237.150.33 217.237.151.161
grüße
- panse
- Beiträge: 19
- Registriert: 22.09.2004, 15:44
panse hat geschrieben:11.Gehe in die Registry
Start<Ausfuehren<regedit
Falls dieser Schluessel so existiert:, aendere die N in Y
HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = "N
ich habe bei mir unter diesem key 3 verschiedene werte:
[list=] HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = Y [/list]
[list=] HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = N [/list]
[list=] HKLM\SOFTWARE\Microsoft\Ole\EnableDCOM = N [/list]
ist das so ok, oder muss ich alle 3 in Y umwandeln?
Hast du einfach so in der Registry nachgesehen, oder gab es eine Virenattacke ???
Ich frage, weil dein Log sauber ist.
mfg
Nikita
- Nikita
- Moderator
- Beiträge: 11478
- Registriert: 07.12.2003, 16:53
- Wohnort: Lissabon
ich hatte eine attacke, vpc32.exe war verseucht. habe es nach der obigen anleitung entfernt, und hatte danach immernoch die gleichen probleme. erst nachdem ich sp2 von xp installiert hatte, war es weg.
bzgl. der regeinträge dachte ich halt, dass man ggf. alle 3 schlüßel verändern muss.
grüße
bzgl. der regeinträge dachte ich halt, dass man ggf. alle 3 schlüßel verändern muss.
grüße
- panse
- Beiträge: 19
- Registriert: 22.09.2004, 15:44
@Panse:
Start|Ausführen<dcomcnfg.exe
# Wählen Sie Konsolenstamm|Komponentendienste.
# Öffnen Sie den Unterordner "Computer".
# Klicken Sie mit der rechten Maustaste auf "Arbeitsplatz" und wählen Sie "Eigenschaften".
# Klicken Sie auf die Registerkarte "Standardeigenschaften".
# Setzen Sie das Häkchen für die Option "DCOM (Distributed COM) auf diesem Computer aktivieren". Klicken Sie auf "Übernehmen" und dann auf "OK".
# Starten Sie den Computer neu.
In der Registry wuerde ich nichts verstellen.
mfg
Nikita
Start|Ausführen<dcomcnfg.exe
# Wählen Sie Konsolenstamm|Komponentendienste.
# Öffnen Sie den Unterordner "Computer".
# Klicken Sie mit der rechten Maustaste auf "Arbeitsplatz" und wählen Sie "Eigenschaften".
# Klicken Sie auf die Registerkarte "Standardeigenschaften".
# Setzen Sie das Häkchen für die Option "DCOM (Distributed COM) auf diesem Computer aktivieren". Klicken Sie auf "Übernehmen" und dann auf "OK".
# Starten Sie den Computer neu.
In der Registry wuerde ich nichts verstellen.
mfg
Nikita
- Nikita
- Moderator
- Beiträge: 11478
- Registriert: 07.12.2003, 16:53
- Wohnort: Lissabon
also, Nikita danke schonmal bis jetzt für deine Hilfe. Also ich habe den escan durchlaufen lassen und kam dabei auf 304 viren. Wird also schwer sein die hier zu posten. es sind viele einträge unter dem norton ordner. Ach naja egal, hier sind sie:
File C:\WINDOWS\System32\fbhgkh.dll infected by "Trojan.Win32.StartPage.gv" Virus. Action Taken: File Deleted.
File C:\WINDOWS\preInsTT.exe infected by "not-a-virus:AdvWare.BiSpy.f" Virus. Action Taken: File Renamed.
File C:\WINDOWS\win.exe infected by "Trojan.Win32.StartPage.gh" Virus. Action Taken: File Deleted.
File C:\WINDOWS\win32.bmp infected by "TrojanClicker.JS.Gen" Virus. Action Taken: File Deleted.
File C:\WINDOWS\System32\bH.dll infected by "Trojan.Win32.Revop.c" Virus. Action Taken: File Deleted.
File C:\WINDOWS\System32\calsdr.dll infected by "TrojanDownloader.Win32.Rameh.b" Virus. Action Taken: File Deleted.
File C:\WINDOWS\System32\calsdr.exe infected by "TrojanDropper.Win32.Small.ff" Virus. Action Taken: File Deleted.
File C:\WINDOWS\System32\ClrSchP028.exe infected by "Backdoor.Ruledor.c" Virus. Action Taken: File Renamed.
File C:\WINDOWS\System32\sahagent1018.exe infected by "not-a-virus:AdvWare.Sahat.a" Virus. Action Taken: File Renamed.
File C:\WINDOWS\System32\SHAgentNew.dll infected by "not-a-virus:AdvWare.ShopAtHome.b" Virus. Action Taken: File Renamed.
File C:\WINDOWS\System32\vpc32.exe infected by "Backdoor.Rbot.gen" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\ar3.jar-50c9a229-14d97a34.zip infected by "Trojan.Java.ClassLoader.k" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\archive.jar-18420899-72d131de.zip infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\archive.jar-711d0c90-63e81c57.zip infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\counter.jar-1425fe31-3b7bb22b.zip infected by "Trojan.Java.StartPage.j" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\Counters.jar-21c9a6a9-65d0eedb.zip infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\countr-722616a7-73f726ce.zip infected by "Trojan.Java.Nocheat" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\loaderadv64.jar-a3b08a4-4e09bb36.zip infected by "TrojanDownloader.Java.OpenStream.c" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\loaderadv78.jar-27714795-34dc57bb.zip infected by "TrojanDownloader.Java.OpenStream.c" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Internet Optimizer\optimize.exe infected by "TrojanDownloader.Win32.Dyfuca.ak" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Internet Optimizer\update\actalert.exe infected by "TrojanDownloader.Win32.Dyfuca.ac" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Internet Optimizer\update\install.exe infected by "TrojanDownloader.Win32.Dyfuca.y" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\bundlekillah.exe infected by "TrojanDownloader.Win32.IstBar.dv" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\optimize.exe infected by "TrojanDownloader.Win32.Dyfuca.ak" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\powerscan.exe infected by "not-a-virus:AdvWare.PowerScan.b" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI4FFC.tmp\preInsTT.exe infected by "not-a-virus:AdvWare.BiSpy.f" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI4FFC.tmp\twaintec.cab infected by "Trojan.Win32.KeyHost.e" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI4FFC.tmp\twaintec.dll infected by "Trojan.Win32.KeyHost.e" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI6572.tmp\preInsTT.exe infected by "not-a-virus:AdvWare.BiSpy.f" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI6572.tmp\twaintec.cab infected by "Trojan.Win32.KeyHost.e" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI6572.tmp\twaintec.dll infected by "Trojan.Win32.KeyHost.e" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\whenu.exe infected by "not-a-virus:AdvWare.SaveNow.i" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\_update.dat infected by "TrojanSpy.Win32.Agent.h" Virus. Action Taken: File Deleted.
File C:\Programme\mIRC\mirc.exe tagged as not-a-virus:RiskWare.mIRC.6.03. No Action Taken.
File C:\Programme\mIRC\Weisseradler-Script 1.071\Weisseradler-Script.exe tagged as not-a-virus:RiskWare.mIRC.6.03. No Action Taken.
File C:\Programme\Norton AntiVirus\Quarantine\003B514F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0090617B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\012C6D9C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\015D4D8A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\015F17F8.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\01864A84.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\01934AB7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\02293999.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\028F2FA1.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\03733F52 infected by "Trojan.Java.ClassLoader.a" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\060A1EDA infected by "Trojan.Java.ClassLoader.d" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\063C4023.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\07975FF5.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\08465015.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\08B31CB3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\09392D80.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\097E64AC.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0AE71925.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\0C211D79.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0C981C39.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0CED0989.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0D537F90.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0D5C121F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0E1F6B9F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0E222249.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0EB1426E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\106730D6.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\116600CE.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1205078A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\126650C6.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\12B7257C infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\13116465.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\146470B6.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\147C0CA7 infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\16F340AA.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\17B15978.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\18174F80.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\187D4587.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\18B11088.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\19B0279E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1ADA36FF.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1B5E207D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1BC07E7C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E46596A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E4A0367.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E4D2D63.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E505760.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E54015C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E572B58.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E5A5555.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E5C1065.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E5D7F51.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E61294E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E64534A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E677D46.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E6A2743.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E717B3C.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\1E954914.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E987311.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E9E67B3.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\1E9F4709.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EA27106.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EA51B02.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EA844FF.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EAC6EFB.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EAF18F7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EB242F4.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EB56CF0.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EB916ED.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EBC40E9.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EBF6AE5.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EC314E2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EC63EDE.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EC968DB.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1ECC12D7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1ED03CD3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EE338BE.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EE662BA.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EEA0CB7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EED36B3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EF734A8.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EFA5EA5.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EFD08A1.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1F01329E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1F045C9A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1F070696.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1F295D3B infected by "Backdoor.Rbot.gen" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1FE84916.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\20462B82.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\205A3054.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\20DC2681.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\20F748C8.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2224734A.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\22EA0B15 infected by "Trojan.Java.ClassLoader.i" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\22ED3512 infected by "Trojan.Win32.StartPage.aq" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\2358203C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\23894E33.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\238E641E infected by "Worm.Win32.Lovesan.a" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\23A70B7E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\240E0186.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\244B5432 infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\244E7E2F infected by "Trojan.Win32.StartPage.jr" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\2451282B infected by "Trojan.Java.ClassLoader.h" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\24577034.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2474778D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\248D5857.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\24EF20EE.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2540639C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\25462B72 infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\26543B6F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\26956834.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\26C81715.zip infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\27022B90.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\28ED7A4D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2C113DA7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2C373E73 infected by "Trojan.Java.ClassLoader.d" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\2C506FF3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2CDC390B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2E2E117A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2E864F79.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2F292EF3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3004338C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\30D01F9B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\30FD2C0A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\316E27B9 infected by "Trojan.Java.Nocheat" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\332B2020.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\35F73346.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3659324B infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\378A4217.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\37E40A31.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\381E7E05.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\38393237.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\396205B1.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\399450BE infected by "Worm.Win32.Welchia.b" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\39AA4334 infected by "Trojan.Java.ClassLoader.b" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\3A256E39.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3AC8037B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3AE10B4F infected by "Worm.Win32.Welchia.b" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\3B26205F infected by "Trojan.Java.Femad" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\3B946F8B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3C615B9A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3C771F98 infected by "Trojan.Win32.StartPage.me" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\3D447AA7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3DAB6153 infected by "Trojan.Java.ClassLoader.k" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\3EF90C4D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3F3E5001.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\404240DA infected by "Trojan.Java.ClassLoader.h" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\43B336A7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\452B5BFA.zip infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\45C26137.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\46195E48.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\46A46F75.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\46B97C4F infected by "Trojan.Win32.StartPage.me" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\47252B89.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\47351165.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\48570DA0.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\48903AD9.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4A1E2900.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4A45186B.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\4A63164B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4ACD1921.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4B7B0942.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4D3A3044.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4F8A79B5 infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\4FB10CD4.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4FCE7F0F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4FE36CB5.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4FE848DB.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\505C3BAB.exe infected by "Worm.Win32.Welchia.b" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\50E718D2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\51600B07.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\519F6C30.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\51E97B79.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\52B56788.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\531B5D8F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\53E408BA.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\53E7499E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\545A0240.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\54E458B2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\555E0D0D infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\56471D91.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\566F1D1E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\56D15ED0.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\56F50DB2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\583D5282 infected by "Trojan.Java.Needy.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\58F67778.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\59483B60.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5A49699C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5A7874B7 infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5BF75B72.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5CB20FEA.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5DDF2D7F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5E29744D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5EAC198E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5F78059D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\60680D5C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\608129E2 infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\60BC706C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\60DA1850.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\61CC675F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\626F1222.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\629A2638.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\62D83840.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\62F46707.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\64AF6683.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\65017249.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\66FF65D3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\67036FF4.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\67441BA3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\67895F58.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\679365A7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\684B4D5C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\68DB047A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\696150F4.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6970697E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\69BB7833.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\69D65F85.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6A3C558D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6AF2651D infected by "Trojan.Java.Femad" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\6B08419C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6B1A4A54.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6BE51387.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6C0642B9.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6C0642B9.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\6C510866.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6CC345E8.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6CEC59CA.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6D432B5C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6D435E9A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6DF05C9E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6E646D9F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6E9806B2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6EA53085.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6EA93154.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6F4676D3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6FF566F4.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\70944FB6.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\70DB4A2F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\71345906.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\719C1893.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\71DF6EC2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\75661B84.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\75CC118B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\76987D9A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\788B7815.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\788B7815.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\788F2212.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\79406E55.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\7A7962DB infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\7C1D5B85.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\7CA41197.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\7DA23B53.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\7F091215.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\7F1B6E27.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\PestPatrol\Quarantine\20040331192205473.zip infected by "not-a-virus:AdvWare.NewDotNet" Virus. Action Taken: File Renamed.
File C:\Programme\PestPatrol\Quarantine\20040413133709186.zip infected by "not-a-virus:AdvWare.180solutions" Virus. Action Taken: File Renamed.
File C:\Programme\PestPatrol\Quarantine\20040413134101592.zip infected by "Trojan.Win32.KeyHost.e" Virus. Action Taken: File Deleted.
File C:\Programme\PestPatrol\Quarantine\20040521122359009.zip infected by "TrojanDownloader.Win32.Dyfuca.j" Virus. Action Taken: File Deleted.
File C:\Programme\PestPatrol\Quarantine\407656950 infected by "not-a-virus:AdvWare.Sahat.c" Virus. Action Taken: File Renamed.
File C:\Programme\PestPatrol\Quarantine\407656952 infected by "not-a-virus:AdvWare.Cydoor" Virus. Action Taken: File Renamed.
File C:\RECYCLER\NPROTECT\00028262.exe infected by "Backdoor.Rbot.gen" Virus. Action Taken: File Renamed.
File C:\WINDOWS\Downloaded Program Files\SysUpdContainer.dll infected by "TrojanSpy.Win32.Agent.h" Virus. Action Taken: File Deleted.
File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\TRUGVR3D\WksPatch[1].exe infected by "Worm.Win32.Welchia.b" Virus. Action Taken: File Deleted.
File D:\Programme\DivX Pro 5.0.2\DivX Player Alpha 2.0 - Pro 5.0.2.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File D:\Programme\FlashGet\fgf150.exe infected by "not-a-virus:AdvWare.Cydoor" Virus. Action Taken: File Renamed.
File D:\Programme\hijackthis_198\backups\backup-20040919-162831-651.dll infected by "Trojan.Win32.StartPage.gv" Virus. Action Taken: File Deleted.
File D:\Programme\hijackthis_198\backups\backup-20040923-194519-480.dll infected by "Trojan.Win32.StartPage.gv" Virus. Action Taken: File Deleted.
File D:\RECYCLER\S-1-5-21-1606980848-602609370-725345543-1003\Dd111.exe tagged as not-a-virus:PornWare.Dialer.Holistyc.gen. No Action Taken.
-------------
Und hier von HJT:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated) < Dies hier habe ich schon seit langem und habe es noch immer nicht wegbekommen. war auch der Grund weso ich mir Mozilla angeschafft habe. Das Teil Kriegt man mit nichts weg...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.nightbeast.de/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Programme\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CookiePatrol] C:\Programme\PestPatrol\CookiePatrol.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: Verknüpfung mit YzToolBar.lnk = C:\Programme\Yztoolbar\YzToolBar.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\Wtablet\TabUserW.exe
O8 - Extra context menu item: Alles mit FlashGet laden - C:\Programme\FlashGet\jc_all.htm
O8 - Extra context menu item: Mit FlashGet laden - C:\Programme\FlashGet\jc_link.htm
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE (file missing)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... Client.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3BA10334-6ADC-4F32-83E1-1C17851D140F}: NameServer = 217.237.150.97 217.237.149.161
O18 - Protocol hijack: mhtml -
O18 - Filter: text/html - {A3A26F73-E3D6-47CE-BA01-4BCF672C20AE} - C:\WINDOWS\System32\fbhgkh.dll
O18 - Filter: text/plain - {A3A26F73-E3D6-47CE-BA01-4BCF672C20AE} - C:\WINDOWS\System32\fbhgkh.dll
File C:\WINDOWS\System32\fbhgkh.dll infected by "Trojan.Win32.StartPage.gv" Virus. Action Taken: File Deleted.
File C:\WINDOWS\preInsTT.exe infected by "not-a-virus:AdvWare.BiSpy.f" Virus. Action Taken: File Renamed.
File C:\WINDOWS\win.exe infected by "Trojan.Win32.StartPage.gh" Virus. Action Taken: File Deleted.
File C:\WINDOWS\win32.bmp infected by "TrojanClicker.JS.Gen" Virus. Action Taken: File Deleted.
File C:\WINDOWS\System32\bH.dll infected by "Trojan.Win32.Revop.c" Virus. Action Taken: File Deleted.
File C:\WINDOWS\System32\calsdr.dll infected by "TrojanDownloader.Win32.Rameh.b" Virus. Action Taken: File Deleted.
File C:\WINDOWS\System32\calsdr.exe infected by "TrojanDropper.Win32.Small.ff" Virus. Action Taken: File Deleted.
File C:\WINDOWS\System32\ClrSchP028.exe infected by "Backdoor.Ruledor.c" Virus. Action Taken: File Renamed.
File C:\WINDOWS\System32\sahagent1018.exe infected by "not-a-virus:AdvWare.Sahat.a" Virus. Action Taken: File Renamed.
File C:\WINDOWS\System32\SHAgentNew.dll infected by "not-a-virus:AdvWare.ShopAtHome.b" Virus. Action Taken: File Renamed.
File C:\WINDOWS\System32\vpc32.exe infected by "Backdoor.Rbot.gen" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\ar3.jar-50c9a229-14d97a34.zip infected by "Trojan.Java.ClassLoader.k" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\archive.jar-18420899-72d131de.zip infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\archive.jar-711d0c90-63e81c57.zip infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\counter.jar-1425fe31-3b7bb22b.zip infected by "Trojan.Java.StartPage.j" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\Counters.jar-21c9a6a9-65d0eedb.zip infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\countr-722616a7-73f726ce.zip infected by "Trojan.Java.Nocheat" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\loaderadv64.jar-a3b08a4-4e09bb36.zip infected by "TrojanDownloader.Java.OpenStream.c" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\.jpi_cache\jar\1.0\loaderadv78.jar-27714795-34dc57bb.zip infected by "TrojanDownloader.Java.OpenStream.c" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Internet Optimizer\optimize.exe infected by "TrojanDownloader.Win32.Dyfuca.ak" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Internet Optimizer\update\actalert.exe infected by "TrojanDownloader.Win32.Dyfuca.ac" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Internet Optimizer\update\install.exe infected by "TrojanDownloader.Win32.Dyfuca.y" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\bundlekillah.exe infected by "TrojanDownloader.Win32.IstBar.dv" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\optimize.exe infected by "TrojanDownloader.Win32.Dyfuca.ak" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\powerscan.exe infected by "not-a-virus:AdvWare.PowerScan.b" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI4FFC.tmp\preInsTT.exe infected by "not-a-virus:AdvWare.BiSpy.f" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI4FFC.tmp\twaintec.cab infected by "Trojan.Win32.KeyHost.e" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI4FFC.tmp\twaintec.dll infected by "Trojan.Win32.KeyHost.e" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI6572.tmp\preInsTT.exe infected by "not-a-virus:AdvWare.BiSpy.f" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI6572.tmp\twaintec.cab infected by "Trojan.Win32.KeyHost.e" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI6572.tmp\twaintec.dll infected by "Trojan.Win32.KeyHost.e" Virus. Action Taken: File Deleted.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\whenu.exe infected by "not-a-virus:AdvWare.SaveNow.i" Virus. Action Taken: File Renamed.
File C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\_update.dat infected by "TrojanSpy.Win32.Agent.h" Virus. Action Taken: File Deleted.
File C:\Programme\mIRC\mirc.exe tagged as not-a-virus:RiskWare.mIRC.6.03. No Action Taken.
File C:\Programme\mIRC\Weisseradler-Script 1.071\Weisseradler-Script.exe tagged as not-a-virus:RiskWare.mIRC.6.03. No Action Taken.
File C:\Programme\Norton AntiVirus\Quarantine\003B514F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0090617B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\012C6D9C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\015D4D8A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\015F17F8.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\01864A84.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\01934AB7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\02293999.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\028F2FA1.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\03733F52 infected by "Trojan.Java.ClassLoader.a" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\060A1EDA infected by "Trojan.Java.ClassLoader.d" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\063C4023.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\07975FF5.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\08465015.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\08B31CB3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\09392D80.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\097E64AC.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0AE71925.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\0C211D79.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0C981C39.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0CED0989.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0D537F90.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0D5C121F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0E1F6B9F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0E222249.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\0EB1426E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\106730D6.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\116600CE.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1205078A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\126650C6.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\12B7257C infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\13116465.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\146470B6.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\147C0CA7 infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\16F340AA.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\17B15978.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\18174F80.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\187D4587.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\18B11088.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\19B0279E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1ADA36FF.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1B5E207D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1BC07E7C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E46596A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E4A0367.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E4D2D63.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E505760.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E54015C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E572B58.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E5A5555.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E5C1065.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E5D7F51.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E61294E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E64534A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E677D46.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E6A2743.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E717B3C.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\1E954914.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E987311.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1E9E67B3.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\1E9F4709.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EA27106.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EA51B02.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EA844FF.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EAC6EFB.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EAF18F7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EB242F4.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EB56CF0.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EB916ED.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EBC40E9.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EBF6AE5.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EC314E2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EC63EDE.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EC968DB.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1ECC12D7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1ED03CD3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EE338BE.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EE662BA.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EEA0CB7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EED36B3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EF734A8.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EFA5EA5.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1EFD08A1.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1F01329E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1F045C9A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1F070696.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1F295D3B infected by "Backdoor.Rbot.gen" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\1FE84916.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\20462B82.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\205A3054.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\20DC2681.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\20F748C8.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2224734A.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\22EA0B15 infected by "Trojan.Java.ClassLoader.i" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\22ED3512 infected by "Trojan.Win32.StartPage.aq" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\2358203C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\23894E33.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\238E641E infected by "Worm.Win32.Lovesan.a" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\23A70B7E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\240E0186.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\244B5432 infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\244E7E2F infected by "Trojan.Win32.StartPage.jr" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\2451282B infected by "Trojan.Java.ClassLoader.h" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\24577034.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2474778D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\248D5857.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\24EF20EE.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2540639C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\25462B72 infected by "Trojan.Java.ClassLoader.Dummy.d" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\26543B6F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\26956834.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\26C81715.zip infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\27022B90.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\28ED7A4D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2C113DA7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2C373E73 infected by "Trojan.Java.ClassLoader.d" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\2C506FF3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2CDC390B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2E2E117A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2E864F79.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\2F292EF3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3004338C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\30D01F9B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\30FD2C0A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\316E27B9 infected by "Trojan.Java.Nocheat" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\332B2020.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\35F73346.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3659324B infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\378A4217.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\37E40A31.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\381E7E05.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\38393237.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\396205B1.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\399450BE infected by "Worm.Win32.Welchia.b" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\39AA4334 infected by "Trojan.Java.ClassLoader.b" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\3A256E39.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3AC8037B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3AE10B4F infected by "Worm.Win32.Welchia.b" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\3B26205F infected by "Trojan.Java.Femad" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\3B946F8B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3C615B9A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3C771F98 infected by "Trojan.Win32.StartPage.me" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\3D447AA7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3DAB6153 infected by "Trojan.Java.ClassLoader.k" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\3EF90C4D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\3F3E5001.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\404240DA infected by "Trojan.Java.ClassLoader.h" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\43B336A7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\452B5BFA.zip infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\45C26137.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\46195E48.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\46A46F75.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\46B97C4F infected by "Trojan.Win32.StartPage.me" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\47252B89.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\47351165.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\48570DA0.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\48903AD9.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4A1E2900.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4A45186B.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\4A63164B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4ACD1921.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4B7B0942.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4D3A3044.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4F8A79B5 infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\4FB10CD4.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4FCE7F0F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4FE36CB5.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\4FE848DB.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\505C3BAB.exe infected by "Worm.Win32.Welchia.b" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\50E718D2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\51600B07.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\519F6C30.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\51E97B79.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\52B56788.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\531B5D8F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\53E408BA.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\53E7499E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\545A0240.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\54E458B2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\555E0D0D infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\56471D91.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\566F1D1E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\56D15ED0.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\56F50DB2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\583D5282 infected by "Trojan.Java.Needy.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\58F67778.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\59483B60.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5A49699C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5A7874B7 infected by "Exploit.Java.Bytverify" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5BF75B72.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5CB20FEA.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5DDF2D7F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5E29744D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5EAC198E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\5F78059D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\60680D5C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\608129E2 infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\60BC706C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\60DA1850.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\61CC675F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\626F1222.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\629A2638.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\62D83840.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\62F46707.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\64AF6683.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\65017249.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\66FF65D3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\67036FF4.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\67441BA3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\67895F58.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\679365A7.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\684B4D5C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\68DB047A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\696150F4.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6970697E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\69BB7833.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\69D65F85.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6A3C558D.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6AF2651D infected by "Trojan.Java.Femad" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\6B08419C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6B1A4A54.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6BE51387.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6C0642B9.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6C0642B9.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\6C510866.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6CC345E8.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6CEC59CA.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6D432B5C.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6D435E9A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6DF05C9E.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6E646D9F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6E9806B2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6EA53085.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6EA93154.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6F4676D3.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\6FF566F4.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\70944FB6.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\70DB4A2F.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\71345906.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\719C1893.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\71DF6EC2.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\75661B84.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\75CC118B.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\76987D9A.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\788B7815.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\788B7815.zip infected by "Trojan.Java.ClassLoader.o" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\788F2212.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\79406E55.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\7A7962DB infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: File Deleted.
File C:\Programme\Norton AntiVirus\Quarantine\7C1D5B85.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\7CA41197.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\7DA23B53.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\7F091215.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\Norton AntiVirus\Quarantine\7F1B6E27.htm infected by "Exploit.HTML.Mht" Virus. Action Taken: File Renamed.
File C:\Programme\PestPatrol\Quarantine\20040331192205473.zip infected by "not-a-virus:AdvWare.NewDotNet" Virus. Action Taken: File Renamed.
File C:\Programme\PestPatrol\Quarantine\20040413133709186.zip infected by "not-a-virus:AdvWare.180solutions" Virus. Action Taken: File Renamed.
File C:\Programme\PestPatrol\Quarantine\20040413134101592.zip infected by "Trojan.Win32.KeyHost.e" Virus. Action Taken: File Deleted.
File C:\Programme\PestPatrol\Quarantine\20040521122359009.zip infected by "TrojanDownloader.Win32.Dyfuca.j" Virus. Action Taken: File Deleted.
File C:\Programme\PestPatrol\Quarantine\407656950 infected by "not-a-virus:AdvWare.Sahat.c" Virus. Action Taken: File Renamed.
File C:\Programme\PestPatrol\Quarantine\407656952 infected by "not-a-virus:AdvWare.Cydoor" Virus. Action Taken: File Renamed.
File C:\RECYCLER\NPROTECT\00028262.exe infected by "Backdoor.Rbot.gen" Virus. Action Taken: File Renamed.
File C:\WINDOWS\Downloaded Program Files\SysUpdContainer.dll infected by "TrojanSpy.Win32.Agent.h" Virus. Action Taken: File Deleted.
File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\TRUGVR3D\WksPatch[1].exe infected by "Worm.Win32.Welchia.b" Virus. Action Taken: File Deleted.
File D:\Programme\DivX Pro 5.0.2\DivX Player Alpha 2.0 - Pro 5.0.2.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken.
File D:\Programme\FlashGet\fgf150.exe infected by "not-a-virus:AdvWare.Cydoor" Virus. Action Taken: File Renamed.
File D:\Programme\hijackthis_198\backups\backup-20040919-162831-651.dll infected by "Trojan.Win32.StartPage.gv" Virus. Action Taken: File Deleted.
File D:\Programme\hijackthis_198\backups\backup-20040923-194519-480.dll infected by "Trojan.Win32.StartPage.gv" Virus. Action Taken: File Deleted.
File D:\RECYCLER\S-1-5-21-1606980848-602609370-725345543-1003\Dd111.exe tagged as not-a-virus:PornWare.Dialer.Holistyc.gen. No Action Taken.
-------------
Und hier von HJT:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated) < Dies hier habe ich schon seit langem und habe es noch immer nicht wegbekommen. war auch der Grund weso ich mir Mozilla angeschafft habe. Das Teil Kriegt man mit nichts weg...
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.nightbeast.de/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [IMJPMIG8.1] C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\System32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [Logitech Utility] Logi_MwX.Exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Programme\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CookiePatrol] C:\Programme\PestPatrol\CookiePatrol.exe
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe
O4 - Startup: Verknüpfung mit YzToolBar.lnk = C:\Programme\Yztoolbar\YzToolBar.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: TabUserW.exe.lnk = C:\WINDOWS\system32\Wtablet\TabUserW.exe
O8 - Extra context menu item: Alles mit FlashGet laden - C:\Programme\FlashGet\jc_all.htm
O8 - Extra context menu item: Mit FlashGet laden - C:\Programme\FlashGet\jc_link.htm
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE (file missing)
O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... Client.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{3BA10334-6ADC-4F32-83E1-1C17851D140F}: NameServer = 217.237.150.97 217.237.149.161
O18 - Protocol hijack: mhtml -
O18 - Filter: text/html - {A3A26F73-E3D6-47CE-BA01-4BCF672C20AE} - C:\WINDOWS\System32\fbhgkh.dll
O18 - Filter: text/plain - {A3A26F73-E3D6-47CE-BA01-4BCF672C20AE} - C:\WINDOWS\System32\fbhgkh.dll
- NightBeast
- Beiträge: 10
- Registriert: 22.09.2004, 21:21
Naja, egal. Nutzt nix. Bei mir ist vpc32.exe wieder aufgetaucht...
GIBTS ES DENN KEINE ERLÖSUNG VON DIESEM TEIL! Ich will nicht formatieren!!!!
GIBTS ES DENN KEINE ERLÖSUNG VON DIESEM TEIL! Ich will nicht formatieren!!!!
- NightBeast
- Beiträge: 10
- Registriert: 22.09.2004, 21:21
Hallo @NightBeast
Fixe:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O4 - Startup: Verknüpfung mit YzToolBar.lnk = C:\Programme\Yztoolbar\YzToolBar.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE (file missing)
O18 - Filter: text/html - {A3A26F73-E3D6-47CE-BA01-4BCF672C20AE} - C:\WINDOWS\System32\fbhgkh.dll
O18 - Filter: text/plain - {A3A26F73-E3D6-47CE-BA01-4BCF672C20AE} - C:\WINDOWS\System32\fbhgkh.dll
neustarten
#Windows Explorer -> "Extras/Ordneroptionen" -> "Ansicht" -> Haken entfernen bei "Geschützte Systemdateien ausblenden (empfohlen)" und "Alle Dateien und Ordner anzeigen" aktivieren -> "OK"
#Deinstalliere
< C:\Programme\Yztoolbar\YzToolBar.exe < falls du es nicht unbedingt benoetigst.
<D:\Programme\FlashGet\
Datentraegerbereinigung: und Loeschen der Temporary-Dateien
Disk Cleanup Wizard
1. Start<Ausfuehren<cleanmgr
2. Click Temporary Internet Files, O.K
#Leere die Odner (nicht die Ordner selbst loeschen:
C:\Dokumente und Einstellungen\nightbeast\Cookies\*.*
C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temporary Internet Files\*.*
C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\
z.B:
C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI6572.tmp\preInsTT.exe
#Java-Cache leeren.
C:\Dokumente und Einstellungen\nightbeast\.jpi_cache
#Start<Ausfuehren (reinkopieren)
regsvr32 /u C:\WINDOWS\System32\fbhgkh.dll
<enter<
neustarten
#Loesche:
C:\WINDOWS\System32\fbhgkh.dll
D:\RECYCLER\S-1-5-21-1606980848-602609370-725345543-1003\Dd111.exe
C:\WINDOWS\System32\ClrSchP028.exe
C:\WINDOWS\System32\SHAgentNew.dll
C:\WINDOWS\preInsTT.exe
#Sphj.fix
<.sp.html (obfuscated)<
http://www.rokop-security.de/main/article.php?sid=746
#CWShredder 1.59
http://www.chip.de/downloads/c_downloads_11353799.html
WÄHREND des Scanvorganges müssen ALLE sonstige Anwendungen beendet werden und alle Browserfenster müssen geschlossen sein!.
#AdAware (free)
http://www.lavasoft.de/support/download/
VOR jedem Scanvorgang das Programm Updaten!
WÄHREND des Scanvorganges müssen ALLE sonstige Anwendungen beendet werden und alle Browserfenster müssen geschlossen sein!.
Files, die Adaware findet, können bedenkenlos gelöscht werden.
#Scanne noch mal mit Escan im Normalmodus
#Deaktiviere kurz deinen Virenscanner und lade:
#Antivirus (free)
http://www.free-av.de/
Nach dem Installationsscann konfiguriere.
<Alle Dateien
<Heuristik:mittel
-««und mache im abgesicherten und im Normalmodus einen Komplettscann.
#RegSupreme:
http://www.computerbase.de/downloads/so ... egsupreme/
RegSupreme
Die Sprache kann man im Programm unter Language auf deutsch problemlos umstellen, das Programm muss danach NICHT neu gestartet werden, die sprache wird sofort umgestellt.
Dieses Programm erstellt als erstes eine Sicherungsdatei eurer Registry, diese kann natürlich ne weile dauern. Wenn ihr aufgefordert werdet, einer Datei einen Namen zu vergeben, dann macht ihr das bitte. Nützlich und sinnvoll haben sich bezeichnungen wie: regback_jeweiliges datum u.ä. um die backup datei jederzeit wieder verwenden kann.
Dann poste das neue komplette Log.
mfg
Nikita
Fixe:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated)
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O4 - Startup: Verknüpfung mit YzToolBar.lnk = C:\Programme\Yztoolbar\YzToolBar.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE (file missing)
O18 - Filter: text/html - {A3A26F73-E3D6-47CE-BA01-4BCF672C20AE} - C:\WINDOWS\System32\fbhgkh.dll
O18 - Filter: text/plain - {A3A26F73-E3D6-47CE-BA01-4BCF672C20AE} - C:\WINDOWS\System32\fbhgkh.dll
neustarten
#Windows Explorer -> "Extras/Ordneroptionen" -> "Ansicht" -> Haken entfernen bei "Geschützte Systemdateien ausblenden (empfohlen)" und "Alle Dateien und Ordner anzeigen" aktivieren -> "OK"
#Deinstalliere
< C:\Programme\Yztoolbar\YzToolBar.exe < falls du es nicht unbedingt benoetigst.
<D:\Programme\FlashGet\
Datentraegerbereinigung: und Loeschen der Temporary-Dateien
Disk Cleanup Wizard
1. Start<Ausfuehren<cleanmgr
2. Click Temporary Internet Files, O.K
#Leere die Odner (nicht die Ordner selbst loeschen:
C:\Dokumente und Einstellungen\nightbeast\Cookies\*.*
C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temporary Internet Files\*.*
C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\
z.B:
C:\Dokumente und Einstellungen\nightbeast\Lokale Einstellungen\Temp\THI6572.tmp\preInsTT.exe
#Java-Cache leeren.
C:\Dokumente und Einstellungen\nightbeast\.jpi_cache
#Start<Ausfuehren (reinkopieren)
regsvr32 /u C:\WINDOWS\System32\fbhgkh.dll
<enter<
neustarten
#Loesche:
C:\WINDOWS\System32\fbhgkh.dll
D:\RECYCLER\S-1-5-21-1606980848-602609370-725345543-1003\Dd111.exe
C:\WINDOWS\System32\ClrSchP028.exe
C:\WINDOWS\System32\SHAgentNew.dll
C:\WINDOWS\preInsTT.exe
#Sphj.fix
<.sp.html (obfuscated)<
http://www.rokop-security.de/main/article.php?sid=746
#CWShredder 1.59
http://www.chip.de/downloads/c_downloads_11353799.html
WÄHREND des Scanvorganges müssen ALLE sonstige Anwendungen beendet werden und alle Browserfenster müssen geschlossen sein!.
#AdAware (free)
http://www.lavasoft.de/support/download/
VOR jedem Scanvorgang das Programm Updaten!
WÄHREND des Scanvorganges müssen ALLE sonstige Anwendungen beendet werden und alle Browserfenster müssen geschlossen sein!.
Files, die Adaware findet, können bedenkenlos gelöscht werden.
#Scanne noch mal mit Escan im Normalmodus
#Deaktiviere kurz deinen Virenscanner und lade:
#Antivirus (free)
http://www.free-av.de/
Nach dem Installationsscann konfiguriere.
<Alle Dateien
<Heuristik:mittel
-««und mache im abgesicherten und im Normalmodus einen Komplettscann.
#RegSupreme:
http://www.computerbase.de/downloads/so ... egsupreme/
RegSupreme
Die Sprache kann man im Programm unter Language auf deutsch problemlos umstellen, das Programm muss danach NICHT neu gestartet werden, die sprache wird sofort umgestellt.
Dieses Programm erstellt als erstes eine Sicherungsdatei eurer Registry, diese kann natürlich ne weile dauern. Wenn ihr aufgefordert werdet, einer Datei einen Namen zu vergeben, dann macht ihr das bitte. Nützlich und sinnvoll haben sich bezeichnungen wie: regback_jeweiliges datum u.ä. um die backup datei jederzeit wieder verwenden kann.
Dann poste das neue komplette Log.
mfg
Nikita
- Nikita
- Moderator
- Beiträge: 11478
- Registriert: 07.12.2003, 16:53
- Wohnort: Lissabon
NightBeast hat geschrieben:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = res://C:\WINDOWS\System32\fbhgkh.dll/sp.html (obfuscated) < Dies hier habe ich schon seit langem und habe es noch immer nicht wegbekommen. war auch der Grund weso ich mir Mozilla angeschafft habe. Das Teil Kriegt man mit nichts weg...
Doch. Schau hier.
http://www.trojaner-info.de/anleitungen ... blank.html
@nikita: hallo. *wink*
bin froh, dass du nicht mehr einfach so firewalls vorschlägst sondern darauf achtest, dass unnötige dienste abgestellt werden (dingens, linkblock usw)...
mach weiter so
- *johnny
- Beiträge: 6
- Registriert: 07.05.2004, 19:22
ich kann tollbar und flashget doch nicht einfach deinstallieren. Ich benutze die noch...
danke an johnny, aber der fixer hat nix finden können.
danke an johnny, aber der fixer hat nix finden können.
- NightBeast
- Beiträge: 10
- Registriert: 22.09.2004, 21:21
Hallo,
ich bins schon wieder, nachdem ich den einen wurm endlich weg hatte, habe ich gestern im internet gesurft und plötzlich kam die meldung, dass wegen geänderten systemeinstellungen neugestartet werden muss.
ich hab dann sofort disconnected und hab im taskmanager ein prozess worm.exe (oder so ähnlich) gefunden.
hijack hat aber keinen laufenden prozess gefunden, der verdächtig ist. dann habe ich zwangsläufig neugestartet, und jetzt weiss ich natürlich nicht, ob ich einen wurm habe, oder nicht.
kann mir vielleicht jemand erklären, wie ich verdächtige prozesse in hijackthis erkenne? ich will euch ja nicht jedes mal mit meinem log nerven, trotzdem wäre es nett, wenn ihr nochmal drüber schauen könnt. vielleicht ist ja doch was nicht in ordnung.
hier ist es:
Logfile of HijackThis v1.98.2
Scan saved at 10:01:48, on 24.09.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\AVPersonal\AVGUARD.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\PGPsdkServ.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Programme\Java\j2re1.4.2_04\bin\jusched.exe
C:\Programme\AVPersonal\AVGNT.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Programme\Gemeinsame Dateien\PCSuite\DataLayer\DataLayer.exe
C:\Programme\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Gemeinsame Dateien\PCSuite\Services\ServiceLayer.exe
C:\Programme\CiDial\CiDial.exe
C:\Programme\Opera\opera.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Dokumente und Einstellungen\*lol* you\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web.de/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [DataLayer] C:\Programme\Gemeinsame Dateien\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] REM C:\Programme\Gemeinsame Dateien\Nokia\Tools\NclTray.exe
O4 - HKLM\..\Run: [ElbyCheckElbyCDFL] C:\Programme\CloneCD\ElbyCheck.exe /L ElbyCDFL
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{89353775-3D54-4AB1-838C-E9E1E8BEECB2}: NameServer = 217.237.150.33 217.237.151.161
danke für eure hilfe
ich bins schon wieder, nachdem ich den einen wurm endlich weg hatte, habe ich gestern im internet gesurft und plötzlich kam die meldung, dass wegen geänderten systemeinstellungen neugestartet werden muss.
ich hab dann sofort disconnected und hab im taskmanager ein prozess worm.exe (oder so ähnlich) gefunden.
hijack hat aber keinen laufenden prozess gefunden, der verdächtig ist. dann habe ich zwangsläufig neugestartet, und jetzt weiss ich natürlich nicht, ob ich einen wurm habe, oder nicht.
kann mir vielleicht jemand erklären, wie ich verdächtige prozesse in hijackthis erkenne? ich will euch ja nicht jedes mal mit meinem log nerven, trotzdem wäre es nett, wenn ihr nochmal drüber schauen könnt. vielleicht ist ja doch was nicht in ordnung.
hier ist es:
Logfile of HijackThis v1.98.2
Scan saved at 10:01:48, on 24.09.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\AVPersonal\AVGUARD.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\PGPsdkServ.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\WINDOWS\system32\atiptaxx.exe
C:\Programme\Java\j2re1.4.2_04\bin\jusched.exe
C:\Programme\AVPersonal\AVGNT.EXE
C:\WINDOWS\system32\rundll32.exe
C:\Programme\Gemeinsame Dateien\PCSuite\DataLayer\DataLayer.exe
C:\Programme\Winamp\winampa.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Gemeinsame Dateien\PCSuite\Services\ServiceLayer.exe
C:\Programme\CiDial\CiDial.exe
C:\Programme\Opera\opera.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Dokumente und Einstellungen\*lol* you\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web.de/
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Reader\ActiveX\AcroIEHelper.dll
O3 - Toolbar: (no name) - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - (no file)
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AtiPTA] atiptaxx.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_04\bin\jusched.exe
O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [DataLayer] C:\Programme\Gemeinsame Dateien\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [Nokia Tray Application] REM C:\Programme\Gemeinsame Dateien\Nokia\Tools\NclTray.exe
O4 - HKLM\..\Run: [ElbyCheckElbyCDFL] C:\Programme\CloneCD\ElbyCheck.exe /L ElbyCDFL
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O17 - HKLM\System\CCS\Services\Tcpip\..\{89353775-3D54-4AB1-838C-E9E1E8BEECB2}: NameServer = 217.237.150.33 217.237.151.161
danke für eure hilfe
- panse
- Beiträge: 19
- Registriert: 22.09.2004, 15:44
Hallo @panse
(W32/Doomhunter.32)
Gehe in die Registry:
Start<Ausfuehren<regedit:
Findest du diesen Eintrag ?
<HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Run "DELETE ME" = "worm.exe"
Ueberpruefe bitte, ob du folgendes findest
<HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32 (Default)
<HKCU\Software\magic = 666.
..................................................................................................................
Findest du:
C:\WINNT\SYSTEM32\WORM.EXE ?
edit worm.exe
readme.txt
system requirements.txt
worm1.exe
worm2.exe
1.Scanne mit deinem Antivirus im abgesicherten-und im Normalmodus.
2.Mache einen Virenscann und einen Portscann
#ANTS 2.1
http://www.pcbusiness-online.de/common/ ... ileid=1547
Vor allem auf folgenden Port achten:3127 (TCP)
mfg
Nikita
http://www.esecurityplanet.com/alerts/a ... hp/3312861
(W32/Doomhunter.32)
Gehe in die Registry:
Start<Ausfuehren<regedit:
Findest du diesen Eintrag ?
<HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\
Run "DELETE ME" = "worm.exe"
Ueberpruefe bitte, ob du folgendes findest
<HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32 (Default)
<HKCU\Software\magic = 666.
..................................................................................................................
Findest du:
C:\WINNT\SYSTEM32\WORM.EXE ?
edit worm.exe
readme.txt
system requirements.txt
worm1.exe
worm2.exe
1.Scanne mit deinem Antivirus im abgesicherten-und im Normalmodus.
2.Mache einen Virenscann und einen Portscann
#ANTS 2.1
http://www.pcbusiness-online.de/common/ ... ileid=1547
Vor allem auf folgenden Port achten:3127 (TCP)
mfg
Nikita
http://www.esecurityplanet.com/alerts/a ... hp/3312861
- Nikita
- Moderator
- Beiträge: 11478
- Registriert: 07.12.2003, 16:53
- Wohnort: Lissabon
Hallo,
also unter
<HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run finde ich folgendes:
(standard) REG_SZ (Wert nicht gesetzt)
CTFMON.EXE REG_SZ C:\Windows\system32\ctfmon.exe
unter <HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32 finde ich:
(Standard) REG_EXPAND_SZ %SystemRoot%\System32\webckeck.dll
ThreadingModel REG_SZ Apartment
<HKCU\Software\magic = 666 finde ich nicht.
Die Dateien
C:\WINNT\SYSTEM32\WORM.EXE
edit worm.exe
readme.txt
system requirements.txt
worm1.exe
worm2.exe
finde ich nicht.
ich werd jetzt mal scannen
danke schonmal, ich poste dann die ergebnisse
also unter
<HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run finde ich folgendes:
(standard) REG_SZ (Wert nicht gesetzt)
CTFMON.EXE REG_SZ C:\Windows\system32\ctfmon.exe
unter <HKEY_CLASSES_ROOT\CLSID\{E6FB5E20-DE35-11CF-9C87-00AA005127ED}\InProcServer32 finde ich:
(Standard) REG_EXPAND_SZ %SystemRoot%\System32\webckeck.dll
ThreadingModel REG_SZ Apartment
<HKCU\Software\magic = 666 finde ich nicht.
Die Dateien
C:\WINNT\SYSTEM32\WORM.EXE
edit worm.exe
readme.txt
system requirements.txt
worm1.exe
worm2.exe
finde ich nicht.
ich werd jetzt mal scannen
danke schonmal, ich poste dann die ergebnisse
- panse
- Beiträge: 19
- Registriert: 22.09.2004, 15:44
Einfach nur draufklicken, ohne was einzugeben.
Versuch es mal.
Dann lade diesen DOS-Scanner
CLRAV> Kaspersky
http://www.vsantivirus.com/util-clrav.htm
mfg
Nikita
Versuch es mal.
Dann lade diesen DOS-Scanner
CLRAV> Kaspersky
http://www.vsantivirus.com/util-clrav.htm
mfg
Nikita
- Nikita
- Moderator
- Beiträge: 11478
- Registriert: 07.12.2003, 16:53
- Wohnort: Lissabon
64 Beiträge • Seite 2 von 5 • 1, 2, 3, 4, 5
Ähnliche Themen
| Lovsan/Blaster-Wurm mit falscher Microsoft-Adresse Forum: Online- und PC-Sicherheit Autor: Computerdirk Antworten: |
longhorn os von microsoft Forum: Software-Hilfe Autor: blase hase Antworten: |
Windows Update Server im Netzwerk Forum: Software-Hilfe Autor: Helladmin Antworten: |
Window XP USB Service-Update KB82603 Forum: Software-Hilfe Autor: etzreini Antworten: |
BIOS Update gescheitert? Forum: Hardware-Hilfe Autor: grex Antworten: |
Zurück zu Online- und PC-Sicherheit
Wer ist online?
Mitglieder in diesem Forum: 0 Mitglieder und 0 Gäste