![]() |
| |||||||
| Registrieren | Website Spy | Member List | Spenden | Suche | Die heutige Beiträge | Alle Foren als gelesen markieren | Forum-Regeln |
|
![]() |
| | Thread Tools |
|
#1
| |||
| |||
| Here we go again ![]() Logfile von Trend Micro HijackThis V2.0.2 Scan gespeichert um 11:13:49 am 1/29/2008 Plattform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16574) Boot-Modus: Normal Laufenden Prozesse: C: \ WINDOWS \ System32 \ smss.exe C: \ WINDOWS \ system32 \ winlogon.exe C: \ WINDOWS \ system32 \ services.exe C: \ WINDOWS \ system32 \ lsass.exe C: \ WINDOWS \ system32 \ Ati2evxx.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ System32 \ svchost.exe C: \ Program Files \ Avast4Software \ Avast4 \ aswUpdSv.exe C: \ Program Files \ Avast4Software \ Avast4 \ ashServ.exe C: \ WINDOWS \ system32 \ spoolsv.exe C: \ WINDOWS \ system32 \ brss01a.exe C: \ WINDOWS \ Explorer.EXE C: \ Program Files \ Intel \ Intel Application Accelerator \ iaanotif.exe C: \ Program Files \ Intel \ Modem Event Monitor \ IntelMEM.exe C: \ Program Files \ Creative \ Sound Blaster Live! 24-bit \ Surround Mixer \ CTSysVol.exe C: \ WINDOWS \ system32 \ Rundll32.exe C: \ Program Files \ Dell \ Media Experience \ PCMService.exe C: \ Program Files \ CyberLink \ PowerDVD \ DVDLauncher.exe C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe C: \ PROGRA ~ 1 \ Yahoo! \ Browser \ ybrwicon.exe C: \ Program Files \ BroadJump \ Client Foundation \ CFD.exe C: \ PROGRA ~ 1 \ Yahoo! \ Browser \ ycommon.exe C: \ Program Files \ Adobe \ Photoshop Elements 4.0 \ apdproxy.exe C: \ WINDOWS \ System32 \ spool \ drivers \ w32x86 \ 3 \ E_FATIA JA.EXE C: \ PROGRA ~ 1 \ AVAST4 ~ 1 \ Avast4 \ ashDisp.exe C: \ Program Files \ QuickTime \ qttask.exe C: \ Program Files \ iTunes \ iTunesHelper.exe C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe C: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe C: \ WINDOWS \ system32 \ ctfmon.exe C: \ Program Files \ Linksys EasyLink Advisor \ LinksysAgent.exe C: \ WINDOWS \ SYSTEM32 \ WTablet \ TabUserW.exe C: \ Program Files \ Adobe \ Photoshop Elements 3.0 \ PhotoshopElementsFileAgent.exe C: \ Program Files \ Adobe \ Photoshop Elements 4.0 \ PhotoshopElementsFileAgent.exe C: \ PROGRA ~ 1 \ COMMON ~ 1 \ AOL \ ACS \ acsd.exe C: \ Program Files \ APC \ APC PowerChute Personal Edition \ mainserv.exe C: \ Programme \ Gemeinsame Dateien \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe C: \ Program Files \ Grisoft \ AVG Anti-Spyware 7.5 \ guard.exe C: \ Program Files \ CIFPFiltering \ CIFPLogAggregator.exe C: \ WINDOWS \ system32 \ CTsvcCDA.EXE C: \ Program Files \ CIFPFiltering \ FilterService.exe C: \ Program Files \ Intel \ Intel Application Accelerator \ iaantmon.exe C: \ Program Files \ Common Files \ LightScribe \ LSSrvc.exe C: \ WINDOWS \ system32 \ svchost.exe C: \ WINDOWS \ system32 \ Tablet.exe C: \ WINDOWS \ wanmpsvc.exe C: \ WINDOWS \ system32 \ MsPMSPSv.exe C: \ Program Files \ Avast4Software \ Avast4 \ ashMaiSv.exe C: \ Program Files \ Avast4Software \ Avast4 \ ashWebSv.exe C: \ Program Files \ iPod \ bin \ iPodService.exe C: \ Program Files \ APC \ APC PowerChute Personal Edition \ apcsystray.exe C: \ Program Files \ Avast4Software \ Avast4 \ ashSimpl.exe C: \ Program Files \ Mozilla Firefox \ firefox.exe C: \ Program Files \ Spybot - Search & Destroy \ SpybotSD.exe C: \ Program Files \ Windows NT \ Zubehör \ Wordpad.exe C: \ Dokumente und Einstellungen \ Tatjana Blazevic \ Desktop \ sniper.exe.exe R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.yahoo.com/ R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Settings, ProxyServer = 127.0.0.1:8080 R1 - HKCU \ Software \ Microsoft \ Windows \ CurrentVersion \ Int ernet Settings, ProxyOverride = local N3 - Netscape 7: user_pref ( "browser.startup.homepage", "http://home.netscape.com/bookmark/7_2/home.html"); (C: \ Dokumente und Einstellungen \ TATJANA Blažević \ Application Data \ Mozilla \ Profiles \ default \ mhiwv3o3.slt \ prefs.js) N3 - Netscape 7: user_pref ( "browser.search.defaultengine", "Motor: / / C% 3A% 5CPROGRA% 7E1% 5CNETSCAPE% 5CNETSCAPE% 5Csearchpl ugins% 5CSBWeb_01.src"); (C: \ Dokumente und Einstellungen \ TATJANA Blažević \ Anwendungsdaten \ Mozilla \ Profiles \ default \ mhiwv3o3.slt \ prefs.js) O2 - BHO: AcroIEHlprObj Class - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 6.0 \ Reader \ ActiveX \ AcroIEHelper.dll O2 - BHO: (no name) - (0D5227BF-0C5B-4EA8-833C-FE09F1496F39) - (no file) O2 - BHO: Spybot-S & D IE Protection - (53707962-6F74-2D53-2644-206D7942484F) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll O2 - BHO: (no name) - (549B5CA7-4A86-11D7-A4DF-000874180BB3) - (no file) O2 - BHO: UberButton Class - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc.dll O2 - BHO: DriveLetterAccess - (5CA3D70E-1895-11CF-8E15-001234567890) - C: \ WINDOWS \ system32 \ dla \ tfswshx.dll O2 - BHO: YahooTaggedBM Class - (65D886A2-7CA7-479b-BB95-14D1EFB7946A) - C: \ Program Files \ Yahoo! \ Common \ YIeTagBm.dll O2 - BHO: SidebarAutoLaunch Class - (F2AA9440-6328-4933-B7C9-A6CCDF9CBF6D) - C: \ Program Files \ Yahoo! \ Browser \ YSidebarIEBHO.dll O2 - BHO: (no name) - (FDD3B846-8D59-4ffb-8758-209B6AD74ACC) - (no file) O3 - Toolbar: McAfee VirusScan - (BA52B914-B692-46c4-B683-905236F6F655) - C: \ progra ~ 1 \ mcafee.com \ vso \ mcvsshl.dll O4 - HKLM \ .. \ Run: [IAAnotif] "C: \ Program Files \ Intel \ Intel Application Accelerator \ iaanotif.exe" O4 - HKLM \ .. \ Run: [ATIPTA] "C: \ Program Files \ ATI Technologies \ ATI Control Panel \ atiptaxx.exe" O4 - HKLM \ .. \ Run: [IntelMeM] "C: \ Program Files \ Intel \ Modem Event Monitor \ IntelMEM.exe" O4 - HKLM \ .. \ Run: [CTSysVol] "C: \ Program Files \ Creative \ Sound Blaster Live! 24-bit \ Surround Mixer \ CTSysVol.exe" / r O4 - HKLM \ .. \ Run: [P17Helper] Rundll32 P17.dll, P17Helper O4 - HKLM \ .. \ Run: [PCMService] "C: \ Program Files \ Dell \ Media Experience \ PCMService.exe" O4 - HKLM \ .. \ Run: [DVDLauncher] "C: \ Program Files \ CyberLink \ PowerDVD \ DVDLauncher.exe" O4 - HKLM \ .. \ Run: [UpdateManager] "C: \ Programme \ Gemeinsame Dateien \ Sonic \ Update Manager \ sgtray.exe" / r O4 - HKLM \ .. \ Run: [dla] C: \ WINDOWS \ system32 \ dla \ tfswctrl.exe O4 - HKLM \ .. \ Run: [YBrowser] C: \ PROGRA ~ 1 \ Yahoo! \ Browser \ ybrwicon.exe O4 - HKLM \ .. \ Run: [BJCFD] "C: \ Program Files \ BroadJump \ Client Foundation \ CFD.exe" O4 - HKLM \ .. \ Run: [VSOCheckTask] "c: \ PROGRA ~ 1 \ mcafee.com \ vso \ mcmnhdlr.exe" / checktask O4 - HKLM \ .. \ Run: [Adobe Photo Downloader] "C: \ Program Files \ Adobe \ Photoshop Elements 4.0 \ apdproxy.exe" O4 - HKLM \ .. \ Run: [EPSON Stylus Photo R340 Series] "C: \ WINDOWS \ System32 \ spool \ drivers \ w32x86 \ 3 \ E_FATI AJA.EXE" / P30 "EPSON Stylus Photo R340 Series" / O6 "USB002 "/ M" Stylus Photo R340 " O4 - HKLM \ .. \ Run: [avast!] C: \ PROGRA ~ 1 \ AVAST4 ~ 1 \ Avast4 \ ashDisp.exe O4 - HKLM \ .. \ Run: [! AVG Anti-Spyware] "C: \ Program Files \ Grisoft \ AVG Anti-Spyware 7.5 \ avgas.exe" / minimiert O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime O4 - HKLM \ .. \ Run: [iTunesHelper] "C: \ Program Files \ iTunes \ iTunesHelper.exe" O4 - HKCU \ .. \ Run: [Yahoo! Pager] "C: \ PROGRA ~ 1 \ Yahoo! \ MESSEN ~ 1 \ ypager.exe"-quiet O4 - HKCU \ .. \ Run: [SUPERAntiSpyware] C: \ Program Files \ SUPERAntiSpyware \ SUPERAntiSpyware.exe O4 - HKCU \ .. \ Run: [SpybotSD TeaTimer] C: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe O4 - HKCU \ .. \ Run: [ctfmon.exe] C: \ WINDOWS \ system32 \ ctfmon.exe O4 - HKCU \ .. \ Run: [EasyLinkAdvisor] "C: \ Program Files \ Linksys EasyLink Advisor \ LinksysAgent.exe" / Start O4 - Global Startup: APC UPS Status.lnk =? O4 - Global Startup: TabUserW.exe.lnk = C: \ WINDOWS \ SYSTEM32 \ WTablet \ TabUserW.exe O9 - Extra Knopf: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll O9 - Extra Knopf: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe O9 - Extra 'Tools' menuitem: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) - C: \ WINDOWS \ Network Diagnostic \ xpnetdiag.exe O16 - DPF: (215B8138-A3CF-44C5-803F-8226143CFC0A) (Trend Micro ActiveX Scan Agent 6.6) -- http://prerelease.trendmicro-europe....vex/hcImpl.cab O16 - DPF: (9A9307A0-7DA4-4DAF-B042-5009F29E09E1) -- O16 - DPF: (DBA230D1-8467-4e69-987E-5FAE815A3B45) -- O23 - Service: Adobe Active File Monitor (AdobeActiveFileMonitor) - Unbekannte Eigentümer - C: \ Program Files \ Adobe \ Photoshop Elements 3.0 \ PhotoshopElementsFileAgent.exe O23 - Service: Adobe Active File Monitor V4 (AdobeActiveFileMonitor4.0) - Unbekannte Eigentümer - C: \ Program Files \ Adobe \ Photoshop Elements 4.0 \ PhotoshopElementsFileAgent.exe O23 - Service: AOL Connectivity Service (AOL ACS) - America Online, Inc. - C: \ PROGRA ~ 1 \ COMMON ~ 1 \ AOL \ ACS \ acsd.exe O23 - Service: APC UPS Service - American Power Conversion Corporation - C: \ Program Files \ APC \ APC PowerChute Personal Edition \ mainserv.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C: \ Programme \ Gemeinsame Dateien \ Apple \ Mobile Device Support \ bin \ AppleMobileDeviceService.exe O23 - Service: ASP.NET State Service (aspnet_state) - Unbekannte Eigentümer - C: \ WINDOWS \ Microsoft.NET \ Framework \ v2.0.50727 \ ASPN et_state.exe (file missing) O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C: \ Program Files \ Avast4Software \ Avast4 \ aswUpdSv.exe O23 - Service: Ati HotKey Poller - Unbekannte Eigentümer - C: \ WINDOWS \ system32 \ Ati2evxx.exe O23 - Service: avast! Antivirus - ALWIL Software - C: \ Program Files \ Avast4Software \ Avast4 \ ashServ.exe O23 - Service: avast! Mail Scanner - ALWIL Software - C: \ Program Files \ Avast4Software \ Avast4 \ ashMaiSv.exe O23 - Service: avast! Web Scanner - ALWIL Software - C: \ Program Files \ Avast4Software \ Avast4 \ ashWebSv.exe O23 - Service: AVG Anti-Spyware Guard - GRISOFT sro - C: \ Program Files \ Grisoft \ AVG Anti-Spyware 7.5 \ guard.exe O23 - Service: BrSplService (Brother XP spl Service) - Brother Industries Ltd - C: \ WINDOWS \ system32 \ brsvc01a.exe O23 - Service: CIFPLogAggregator - Unbekannte Eigentümer - C: \ Program Files \ CIFPFiltering \ CIFPLogAggregator.exe O23 - Service: Creative Service für CDROM Access - Creative Technology Ltd - C: \ WINDOWS \ system32 \ CTsvcCDA.EXE O23 - Service: CyclopeInternetFilter - Unbekannte Eigentümer - C: \ Program Files \ CIFPFiltering \ FilterService.exe O23 - Service: IAA Event Monitor (IAANTMon) - Intel Corporation - C: \ Program Files \ Intel \ Intel Application Accelerator \ iaantmon.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Programme \ Gemeinsame Dateien \ InstallShield \ Driver \ 11 \ Intel 32 \ IDriverT.exe O23 - Service: iPod Service - Apple Computer, Inc. - C: \ Program Files \ iPod \ bin \ iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Unbekannte Eigentümer - C: \ Program Files \ Common Files \ LightScribe \ LSSrvc.exe O23 - Service: McAfee.com McShield (McShield) - Unbekannte Eigentümer - C: \ PROGRA ~ 1 \ mcafee.com \ vso \ mcshield.exe O23 - Service: McAfee.com VirusScan Online Realtime Engine (MCVSRte) - Networks Associates Technology, Inc - C: \ PROGRA ~ 1 \ mcafee.com \ vso \ mcvsrte.exe O23 - Service: TabletService - Wacom Technology, Corp - C: \ WINDOWS \ system32 \ Tablet.exe O23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C: \ WINDOWS \ wanmpsvc.exe -- Ende der Datei - 11218 bytes |
|
#2
| |||
| |||
| Öffnen Sie HijackThis, und wählen Sie Führen Sie einen System-Scan nur. Setzen Sie ein Häkchen neben der folgenden Angaben: O2 - BHO: (no name) - (0D5227BF-0C5B-4EA8-833C-FE09F1496F39) - (no file) O2 - BHO: (no name) - (549B5CA7-4A86-11D7-A4DF-000874180BB3) - (no file) O2 - BHO: (no name) - (FDD3B846-8D59-4ffb-8758-209B6AD74ACC) - (no file) Schließen Sie alle Fenster mit Ausnahme von HijackThis, und klicken Sie auf Fix überprüft. Exit hijackthis. ---------- Herunterladen DrWeb CureIt Und speichern Sie sie auf Ihrem Desktop. Scan mit DrWeb-CureIt wie folgt:
---------- Nächste Post Dr. Web log |
|
#3
| |||
| |||
| oki seine Scanning jetzt - es ein Virus gefunden CFd.exe! sieht aus wie seine geht eine Weile dauern? Ich war auf der Suche durch das Forum und woooow gibt es so viele Menschen mit Viren hehe |
|
#4
| |||
| |||
| CFd.exe es sich nicht um einen Virus, aber es kann infiziert von einem, und das wird auch nicht schaden wird entfernt. |
|
#5
| |||
| |||
| sollte ich es manuell entfernen? oder? |
|
#6
| |||
| |||
| Nr. Scanner sorgt für sie. |
|
#7
| |||
| |||
| Fortschritt 27% der Scanner gefunden zwei Dateien ist " -cfd.exe-(Adware) Registerkarte --- unheilbaren löschen>> wird es löschen? -reg-ubp2b Tatjana b.reg (Trojaner Startseite)-Registerkarte-gestrichen |
|
#8
| |||
| |||
| Was bedeutet
|
|
#9
| |||
| |||
| Einfach den Computer neu starten, wenn der Dr. Web nicht machen es für Sie. Wir werden sehen, das Protokoll, um sicherzustellen, dass alles vorbei ist. Es sollte nicht viel mehr heute. |
|
#10
| |||
| |||
| ohh okay, seine bis zu 70% fast fertig |
![]() |
|
| Lesezeichen |
Ähnliche Themen | ||||
| Faden | Thread Starter | Forum | Antworten | Last Post |
| Smitfraud-C Er will nicht sterben! | PlatSpin | Viren, Spyware und Sicherheit | 13 | 19. August 2008 10:24 |
| Smitfraud Virus | PK28 | Viren, Spyware und Sicherheit | 12 | 5. Februar, 2008 16:17 |
| Smitfraudfix.exe - Smitfraud-C.Toolbar888 | Hybr! D | Viren, Spyware und Sicherheit | 1 | 29. Oktober, 2007 11:02 |
| Zlob, Smitfraud-, Pop-ups, rot Wallpaper Änderungen | guccijana | Viren, Spyware und Sicherheit | 20 | 30. Sep 2007 20:26 |
| Thread Tools | |
| |