danke für deine Hilfe, und entschuldige, dass ich mich erst jetzt melde. Ich war zwischenzeitig im Urlaub.
Ich hab alles durchgeführt, hier jetzt die erbetenen Logs:
Ad-Aware SE Build 1.05 Logfile Created on:Montag, 10. Januar 2005 14:55:17 Created with Ad-Aware SE Personal, free for private use. Using definitions file:SE1R24 29.12.2004 »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» MRU List(TAC index:0):2 total references Windows(TAC index:3):1 total references »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings =========================== Set : Search for negligible risk entries Set : Safe mode (always request confirmation) Set : Scan active processes Set : Scan registry Set : Deep-scan registry Set : Scan my IE Favorites for banned URLs Set : Scan within archives Set : Scan my Hosts file
Extended Ad-Aware SE Settings =========================== Set : Unload recognized processes & modules during scan Set : Scan registry for all users instead of current user only Set : Always try to unload modules before deletion Set : During removal, unload Explorer and IE if necessary Set : Let Windows remove files in use at next reboot Set : Delete quarantined objects after restoring Set : Include basic Ad-Aware settings in log file Set : Include additional Ad-Aware settings in log file Set : Include reference summary in log file Set : Include alternate data stream details in log file Set : Play sound at scan completion if scan locates critical objects
10.01.2005 14:55:17 - Scan started. (Full System Scan)
MRU List Object Recognized! Location: : S-1-5-21-1547161642-115176313-839522115-1003\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru Description : list of recent programs opened
MRU List Object Recognized! Location: : C:\Dokumente und Einstellungen\Willow.AEON\recent Description : list of recently opened documents
#:18 [mdm.exe] FilePath : C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\ ProcessID : 468 ThreadCreationTime : 10.01.2005 13:33:34 BasePriority : Normal FileVersion : 7.00.9064.9150 ProductVersion : 7.00.9064.9150 ProductName : Microsoft Development Environment CompanyName : Microsoft Corporation FileDescription : Machine Debug Manager InternalName : mdm.exe LegalCopyright : Copyright (C) Microsoft Corp. 1997-2000 OriginalFilename : mdm.exe
#:19 [msdtc.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 688 ThreadCreationTime : 10.01.2005 13:33:37 BasePriority : Normal FileVersion : 2001.12.4414.258 ProductVersion : 03.01.00.4414 ProductName : Microsoft Distributed Transaction Coordinator CompanyName : Microsoft Corporation FileDescription : MS DTC console program InternalName : MSDTC.EXE LegalCopyright : Copyright (C) Microsoft Corp. 1995-1998 LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows(TM) is a trademark of Microsoft Corporation
#:24 [mspmspsv.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 2244 ThreadCreationTime : 10.01.2005 13:33:43 BasePriority : Normal FileVersion : 7.00.00.1956 ProductVersion : 7.00.00.1956 ProductName : Microsoft (R) DRM CompanyName : Microsoft Corporation FileDescription : WMDM PMSP Service InternalName : MSPMSPSV.EXE LegalCopyright : Copyright (C) Microsoft Corp. 1981-2000 OriginalFilename : MSPMSPSV.EXE
#:25 [mqsvc.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 2476 ThreadCreationTime : 10.01.2005 13:33:48 BasePriority : Normal FileVersion : 5.01.1108 ProductVersion : 5.01.1108 ProductName : Microsoft Message Queue CompanyName : Microsoft Corporation FileDescription : Message Queuing Service LegalCopyright : Copyright (C) Microsoft Corporation. 1981-2000 LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows NT(TM) is a trademark of Microsoft Corporation OriginalFilename : MQSVC.EXE
#:26 [mqtgsvc.exe] FilePath : C:\WINDOWS\System32\ ProcessID : 2784 ThreadCreationTime : 10.01.2005 13:33:53 BasePriority : Normal FileVersion : 5.01.1108 ProductVersion : 5.01.1108 ProductName : Microsoft Message Queue CompanyName : Microsoft Corporation FileDescription : Windows NT MSMQ Trigger Service LegalCopyright : Copyright (C) Microsoft Corporation. 1981-2000 LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows NT(TM) is a trademark of Microsoft Corporation OriginalFilename : QMTGSVC.EXE
Memory scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 2
Started registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Windows Object Recognized! Type : RegData Data : Category : Vulnerability Comment : Possible virus infection, REG file extension compromised Rootkey : HKEY_CLASSES_ROOT Object : regfile\shell\open\command Value : Data :
Registry Scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 1 Objects found so far: 3
Started deep registry scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 3
Started Tracking Cookie scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking cookie scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 3
Deep scanning and examining files (C »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\ »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 3
Conditional scan result: »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» New critical objects: 0 Objects found so far: 3
15:12:28 Scan Complete
Summary Of This Scan »»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»» Total scanning time:00:17:11.32 Objects scanned:155743 Objects identified:1 Objects ignored:0 New critical objects:1
Mon Jan 10 15:26:48 2005 => File C:\WINDOWS\system32\KILLAPPS.EXE tagged as not-a-virus:RiskWare.Tool.KillApp.b. No Action Taken.
Mon Jan 10 15:39:05 2005 => File C:\Dokumente und Einstellungen\Willow.AEON\.jpi_cache\jar\1.0\javainstaller.jar-4514e5ea-398dbb50.zip infected by "Trojan-Downloader.Java.OpenStream.t" Virus. Action Taken: No Action Taken.
Mon Jan 10 15:40:14 2005 => File C:\Dokumente und Einstellungen\Willow.AEON\Anwendungsdaten\ACD Systems\Catalogs\Backup\BKID_000000\BKUP_000000002560 infected by "not-a-virus:AdWare.ToolBar.Quick.a" Virus. Action Taken: No Action Taken.
Mon Jan 10 15:45:37 2005 => File C:\Dokumente und Einstellungen\Willow.AEON\Eigene Dateien\Eigene Downloads\hijackthis\backups\backup-20050102-202934-357.dll infected by "TrojanDownloader.Win32.Swizzor.bo" Virus. Action Taken: No Action Taken.
Mon Jan 10 15:57:36 2005 => File C:\Programme\C2Media\Setup.exe infected by "Trojan-Downloader.Win32.Swizzor.cg" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:08 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP122\A0011916.dll infected by "not-a-virus:AdWare.Altnet.c" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:31 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP123\A0011981.EXE infected by "not-a-virus:AdWare.Toolbar.MyWay.b" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:31 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP123\A0011982.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.f" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP124\A0012027.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP124\A0012028.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:47 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP124\A0012033.exe infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:59 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP124\A0012086.DLL infected by "not-a-virus:AdWare.Toolbar.MyWay.c" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:44 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036147.exe infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:45 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036150.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:45 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036152.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:45 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036155.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036169.dll infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036170.exe infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036172.exe infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:59:32 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP246\A0044637.exe infected by "not-a-virus:AdWare.Gator.3202" Virus. Action Taken: No Action Taken.
Mon Jan 10 17:46:16 2005 => ***** Checking for specific ITW Viruses ***** Mon Jan 10 17:46:16 2005 => Checking for Welchia Virus... Mon Jan 10 17:46:16 2005 => Checking for LovGate Virus... Mon Jan 10 17:46:16 2005 => Checking for CodeRed Virus... Mon Jan 10 17:46:16 2005 => Checking for OpaServ Virus... Mon Jan 10 17:46:16 2005 => Checking for Sobig.e Virus... Mon Jan 10 17:46:16 2005 => Checking for Winupie Virus... Mon Jan 10 17:46:16 2005 => Checking for Swen Virus... Mon Jan 10 17:46:16 2005 => Checking for JS.Fortnight Virus... Mon Jan 10 17:46:16 2005 => Checking for Novarg Virus... Mon Jan 10 17:46:16 2005 => Checking for Pagabot Virus... Mon Jan 10 17:46:16 2005 => Checking for Parite.b Virus... Mon Jan 10 17:46:16 2005 => Checking for Parite.a Virus...
Mon Jan 10 17:46:16 2005 => ***** Scanning complete. *****
Mon Jan 10 17:46:16 2005 => Total Files Scanned: 108027 Mon Jan 10 17:46:16 2005 => Total Virus(es) Found: 27 Mon Jan 10 17:46:16 2005 => Total Disinfected Files: 0 Mon Jan 10 17:46:16 2005 => Total Files Renamed: 0 Mon Jan 10 17:46:16 2005 => Total Deleted Files: 0 Mon Jan 10 17:46:16 2005 => Total Errors: 165 Mon Jan 10 17:46:16 2005 => Time Elapsed: 02:26:45 Mon Jan 10 17:46:16 2005 => Virus Database Date: 2005/01/10 Mon Jan 10 17:46:16 2005 => Virus Database Count: 115105
*********************************************************** Hijack log neu ( der is aber anders, da ich gestern software für meinen neuen Handheld installiert hab)
Logfile of HijackThis v1.99.0 Scan saved at 17:48:28, on 10.01.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
danke für deine Hilfe, und entschuldige, dass ich mich erst jetzt melde. Ich war zwischenzeitig im Urlaub.
Ich hab alles durchgeführt, hier jetzt die erbetenen Logs:
Ad-Aware SE Build 1.05
Logfile Created on:Montag, 10. Januar 2005 14:55:17
Created with Ad-Aware SE Personal, free for private use.
Using definitions file:SE1R24 29.12.2004
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
References detected during the scan:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
MRU List(TAC index:0):2 total references
Windows(TAC index:3):1 total references
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Ad-Aware SE Settings
===========================
Set : Search for negligible risk entries
Set : Safe mode (always request confirmation)
Set : Scan active processes
Set : Scan registry
Set : Deep-scan registry
Set : Scan my IE Favorites for banned URLs
Set : Scan within archives
Set : Scan my Hosts file
Extended Ad-Aware SE Settings
===========================
Set : Unload recognized processes & modules during scan
Set : Scan registry for all users instead of current user only
Set : Always try to unload modules before deletion
Set : During removal, unload Explorer and IE if necessary
Set : Let Windows remove files in use at next reboot
Set : Delete quarantined objects after restoring
Set : Include basic Ad-Aware settings in log file
Set : Include additional Ad-Aware settings in log file
Set : Include reference summary in log file
Set : Include alternate data stream details in log file
Set : Play sound at scan completion if scan locates critical objects
10.01.2005 14:55:17 - Scan started. (Full System Scan)
MRU List Object Recognized!
Location: : S-1-5-21-1547161642-115176313-839522115-1003\software\microsoft\windows\currentversion\explorer\comdlg32\lastvisitedmru
Description : list of recent programs opened
MRU List Object Recognized!
Location: : C:\Dokumente und Einstellungen\Willow.AEON\recent
Description : list of recently opened documents
Listing running processes
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
#:1 [smss.exe]
FilePath : \SystemRoot\System32\
ProcessID : 892
ThreadCreationTime : 10.01.2005 13:33:27
BasePriority : Normal
#:2 [csrss.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 956
ThreadCreationTime : 10.01.2005 13:33:28
BasePriority : Normal
#:3 [winlogon.exe]
FilePath : \??\C:\WINDOWS\system32\
ProcessID : 980
ThreadCreationTime : 10.01.2005 13:33:29
BasePriority : High
#:4 [services.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1048
ThreadCreationTime : 10.01.2005 13:33:30
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Betriebssystem Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Anwendung für Dienste und Controller
InternalName : services.exe
LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFilename : services.exe
#:5 [lsass.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1060
ThreadCreationTime : 10.01.2005 13:33:30
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : LSA Shell (Export Version)
InternalName : lsass.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : lsass.exe
#:6 [ati2evxx.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1216
ThreadCreationTime : 10.01.2005 13:33:30
BasePriority : Normal
#:7 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1228
ThreadCreationTime : 10.01.2005 13:33:30
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:8 [svchost.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1324
ThreadCreationTime : 10.01.2005 13:33:31
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:9 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1420
ThreadCreationTime : 10.01.2005 13:33:31
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:10 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1468
ThreadCreationTime : 10.01.2005 13:33:31
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:11 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1512
ThreadCreationTime : 10.01.2005 13:33:31
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:12 [spoolsv.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 2020
ThreadCreationTime : 10.01.2005 13:33:33
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Spooler SubSystem App
InternalName : spoolsv.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : spoolsv.exe
#:13 [nhksrv.exe]
FilePath : C:\WINDOWS\
ProcessID : 288
ThreadCreationTime : 10.01.2005 13:33:34
BasePriority : Normal
#:14 [avguard.exe]
FilePath : C:\Programme\AVPersonal\
ProcessID : 260
ThreadCreationTime : 10.01.2005 13:33:34
BasePriority : Normal
#:15 [avwupsrv.exe]
FilePath : C:\Programme\AVPersonal\
ProcessID : 340
ThreadCreationTime : 10.01.2005 13:33:34
BasePriority : Normal
#:16 [ctsvccda.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 352
ThreadCreationTime : 10.01.2005 13:33:34
BasePriority : Normal
FileVersion : 1.0.1.0
ProductVersion : 1.0.0.0
ProductName : Creative Service for CDROM Access
CompanyName : Creative Technology Ltd
FileDescription : Creative Service for CDROM Access
InternalName : CTsvcCDAEXE
LegalCopyright : Copyright (c) Creative Technology Ltd., 1999. All rights reserved.
OriginalFilename : CTsvcCDA.EXE
#:17 [inetinfo.exe]
FilePath : C:\WINDOWS\System32\inetsrv\
ProcessID : 404
ThreadCreationTime : 10.01.2005 13:33:34
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Internet-Informationsdienste
CompanyName : Microsoft Corporation
FileDescription : Internet-Informationsdienste
InternalName : INETINFO.EXE
LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFilename : INETINFO.EXE
#:18 [mdm.exe]
FilePath : C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\
ProcessID : 468
ThreadCreationTime : 10.01.2005 13:33:34
BasePriority : Normal
FileVersion : 7.00.9064.9150
ProductVersion : 7.00.9064.9150
ProductName : Microsoft Development Environment
CompanyName : Microsoft Corporation
FileDescription : Machine Debug Manager
InternalName : mdm.exe
LegalCopyright : Copyright (C) Microsoft Corp. 1997-2000
OriginalFilename : mdm.exe
#:19 [msdtc.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 688
ThreadCreationTime : 10.01.2005 13:33:37
BasePriority : Normal
FileVersion : 2001.12.4414.258
ProductVersion : 03.01.00.4414
ProductName : Microsoft Distributed Transaction Coordinator
CompanyName : Microsoft Corporation
FileDescription : MS DTC console program
InternalName : MSDTC.EXE
LegalCopyright : Copyright (C) Microsoft Corp. 1995-1998
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows(TM) is a trademark of Microsoft Corporation
#:20 [tcpsvcs.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1240
ThreadCreationTime : 10.01.2005 13:33:40
BasePriority : Normal
FileVersion : 5.1.2600.0 (xpclient.010817-1148)
ProductVersion : 5.1.2600.0
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : TCP/IP Services Application
InternalName : TCPSVCS.EXE
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : TCPSVCS.EXE
#:21 [snmp.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1544
ThreadCreationTime : 10.01.2005 13:33:41
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Betriebssystem Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : SNMP-Dienst
InternalName : snmp.exe
LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFilename : snmp.exe
#:22 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 1756
ThreadCreationTime : 10.01.2005 13:33:41
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:23 [wdfmgr.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1984
ThreadCreationTime : 10.01.2005 13:33:42
BasePriority : Normal
FileVersion : 5.2.3790.1230 built by: DNSRV(bld4act)
ProductVersion : 5.2.3790.1230
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Windows User Mode Driver Manager
InternalName : WdfMgr
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : WdfMgr.exe
#:24 [mspmspsv.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2244
ThreadCreationTime : 10.01.2005 13:33:43
BasePriority : Normal
FileVersion : 7.00.00.1956
ProductVersion : 7.00.00.1956
ProductName : Microsoft (R) DRM
CompanyName : Microsoft Corporation
FileDescription : WMDM PMSP Service
InternalName : MSPMSPSV.EXE
LegalCopyright : Copyright (C) Microsoft Corp. 1981-2000
OriginalFilename : MSPMSPSV.EXE
#:25 [mqsvc.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2476
ThreadCreationTime : 10.01.2005 13:33:48
BasePriority : Normal
FileVersion : 5.01.1108
ProductVersion : 5.01.1108
ProductName : Microsoft Message Queue
CompanyName : Microsoft Corporation
FileDescription : Message Queuing Service
LegalCopyright : Copyright (C) Microsoft Corporation. 1981-2000
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows NT(TM) is a trademark of Microsoft Corporation
OriginalFilename : MQSVC.EXE
#:26 [mqtgsvc.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2784
ThreadCreationTime : 10.01.2005 13:33:53
BasePriority : Normal
FileVersion : 5.01.1108
ProductVersion : 5.01.1108
ProductName : Microsoft Message Queue
CompanyName : Microsoft Corporation
FileDescription : Windows NT MSMQ Trigger Service
LegalCopyright : Copyright (C) Microsoft Corporation. 1981-2000
LegalTrademarks : Microsoft(R) is a registered trademark of Microsoft Corporation. Windows NT(TM) is a trademark of Microsoft Corporation
OriginalFilename : QMTGSVC.EXE
#:27 [alg.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 3356
ThreadCreationTime : 10.01.2005 13:34:02
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Application Layer Gateway Service
InternalName : ALG.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : ALG.exe
#:28 [svchost.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 820
ThreadCreationTime : 10.01.2005 13:34:11
BasePriority : Normal
FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 5.1.2600.2180
ProductName : Microsoft® Windows® Operating System
CompanyName : Microsoft Corporation
FileDescription : Generic Host Process for Win32 Services
InternalName : svchost.exe
LegalCopyright : © Microsoft Corporation. All rights reserved.
OriginalFilename : svchost.exe
#:29 [ati2evxx.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 1876
ThreadCreationTime : 10.01.2005 13:38:12
BasePriority : Normal
#:30 [explorer.exe]
FilePath : C:\WINDOWS\
ProcessID : 800
ThreadCreationTime : 10.01.2005 13:38:12
BasePriority : Normal
FileVersion : 6.00.2900.2180 (xpsp_sp2_rtm.040803-2158)
ProductVersion : 6.00.2900.2180
ProductName : Betriebssystem Microsoft® Windows®
CompanyName : Microsoft Corporation
FileDescription : Windows Explorer
InternalName : explorer
LegalCopyright : © Microsoft Corporation. Alle Rechte vorbehalten.
OriginalFilename : EXPLORER.EXE
#:31 [ctsysvol.exe]
FilePath : C:\Programme\Creative\SBAudigy2\Surround Mixer\
ProcessID : 2128
ThreadCreationTime : 10.01.2005 13:38:14
BasePriority : Normal
FileVersion : 1.0.9.0
ProductVersion : 1.0.0.0
ProductName : Creative Volume Control
CompanyName : Creative Technology Ltd
FileDescription : CTSysVol.exe
LegalCopyright : Copyright (c) Creative Technology Ltd., 2002. All rights reserved.
OriginalFilename : CTSysVol.exe
#:32 [ctdvddet.exe]
FilePath : C:\Programme\Creative\SBAudigy2\DVDAudio\
ProcessID : 2112
ThreadCreationTime : 10.01.2005 13:38:14
BasePriority : Normal
FileVersion : 1.0.2.0
ProductVersion : 1.0.2.0
ProductName : CTDVDDET
CompanyName : Creative Technology Ltd
FileDescription : CTDVDDET
InternalName : CTDVDDET
LegalCopyright : Copyright (c) Creative Technology Ltd., 2002. All rights reserved.
OriginalFilename : CTDVDDET.EXE
#:33 [cthelper.exe]
FilePath : C:\WINDOWS\system32\
ProcessID : 3672
ThreadCreationTime : 10.01.2005 13:38:14
BasePriority : Normal
FileVersion : 1, 0, 0, 10
ProductVersion : 1, 0, 0, 10
ProductName : CtHelper Application
CompanyName : Creative Technology Ltd
FileDescription : CtHelper MFC Application
InternalName : CtHelper
LegalCopyright : Copyright (C) 2002
OriginalFilename : CtHelper.EXE
#:34 [dellmmkb.exe]
FilePath : C:\WINDOWS\
ProcessID : 2508
ThreadCreationTime : 10.01.2005 13:38:14
BasePriority : Normal
FileVersion : 2.0.0
ProductVersion : 2.0.0
ProductName : Netropa Hot Key
CompanyName : Netropa Corp.
FileDescription : Netropa(tm) Hot Key
InternalName : Netropa Hot Key
LegalCopyright : Copyright © 2000-2001 Netropa Corp.
OriginalFilename : nhk.exe
#:35 [jusched.exe]
FilePath : C:\Programme\Java\j2re1.4.2_06\bin\
ProcessID : 2640
ThreadCreationTime : 10.01.2005 13:38:14
BasePriority : Normal
#:36 [ituneshelper.exe]
FilePath : C:\Programme\iTunes\
ProcessID : 2660
ThreadCreationTime : 10.01.2005 13:38:14
BasePriority : Normal
FileVersion : 4.7.0.42
ProductVersion : 4.7.0.42
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iTunesHelper Module
InternalName : iTunesHelper
LegalCopyright : © 2003-2004 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iTunesHelper.exe
#:37 [ipodservice.exe]
FilePath : C:\Programme\iPod\bin\
ProcessID : 2692
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Normal
FileVersion : 4.7.0.42
ProductVersion : 4.7.0.42
ProductName : iTunes
CompanyName : Apple Computer, Inc.
FileDescription : iPodService Module
InternalName : iPodService
LegalCopyright : © 2003-2004 Apple Computer, Inc. All Rights Reserved.
OriginalFilename : iPodService.exe
#:38 [logitray.exe]
FilePath : C:\Programme\Logitech\Video\
ProcessID : 2460
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Normal
FileVersion : 8.1.1.1100
ProductVersion : 8.1.1.1100
ProductName : Logitech QuickCam
CompanyName : Logitech Inc.
FileDescription : ImageStudio Tray Application
InternalName : LogiTray.exe
LegalCopyright : (c) 1996-2003 Logitech. All rights reserved.
OriginalFilename : LogiTray.exe
#:39 [qttask.exe]
FilePath : C:\Programme\QuickTime\
ProcessID : 2868
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Normal
FileVersion : 6.5.1
ProductVersion : QuickTime 6.5.1
ProductName : QuickTime
CompanyName : Apple Computer, Inc.
InternalName : QuickTime Task
LegalCopyright : © Apple Computer, Inc. 2001-2004
OriginalFilename : QTTask.exe
#:40 [lvcomsx.exe]
FilePath : C:\WINDOWS\System32\
ProcessID : 2884
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Normal
FileVersion : 8.3.0.1096
ProductVersion : 8.3.0.1096
ProductName : Logitech QuickCam
CompanyName : Logitech Inc.
FileDescription : LVCom Server
InternalName : LVComS.exe
LegalCopyright : (c) 1996-2004 Logitech. All rights reserved.
OriginalFilename : LVComS.exe
#:41 [avgnt.exe]
FilePath : C:\Programme\AVPersonal\
ProcessID : 1052
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Normal
#:42 [teatimer.exe]
FilePath : C:\Programme\Spybot - Search & Destroy\
ProcessID : 2116
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Idle
FileVersion : 1, 3, 0, 12
ProductVersion : 1, 3, 0, 12
ProductName : Spybot - Search & Destroy
CompanyName : Safer Networking Limited
FileDescription : System settings protector
InternalName : TeaTimer
LegalCopyright : © 2000-2004 Patrick M. Kolla / Safer Networking Limited. Alle Rechte vorbehalten.
LegalTrademarks : "Spybot" und "Spybot - Search & Destroy" sind registrierte Warenzeichen.
OriginalFilename : TeaTimer.exe
Comments : Schützt Systemeinstellungen vor ungewollten Änderungen.
#:43 [wcescomm.exe]
FilePath : C:\Programme\Microsoft ActiveSync\
ProcessID : 3072
ThreadCreationTime : 10.01.2005 13:38:15
BasePriority : Normal
FileVersion : 3.8.0.5004
ProductVersion : 3.8.5004
ProductName : Microsoft ActiveSync
CompanyName : Microsoft Corporation
FileDescription : ActiveSync Connection Manager
InternalName : wcescomm
LegalCopyright : Copyright © 1995-2004 Microsoft Corp. Alle Rechte vorbehalten.
LegalTrademarks : Microsoft® and Windows® are registered trademarks of Microsoft Corporation.
OriginalFilename : WCESCOMM.EXE
#:44 [osd.exe]
FilePath : C:\Programme\Netropa\
ProcessID : 316
ThreadCreationTime : 10.01.2005 13:38:17
BasePriority : Normal
FileVersion : 2.02
ProductVersion : 2.02
ProductName : Onscreen Display
CompanyName : Netropa Corp.
FileDescription : Netropa(r) Onscreen Display
InternalName : OSD
LegalCopyright : Copyright © 1997-2001 Netropa Corp.
OriginalFilename : osd.exe
#:45 [acrotray.exe]
FilePath : C:\Programme\Adobe\Acrobat 6.0\Distillr\
ProcessID : 3268
ThreadCreationTime : 10.01.2005 13:38:17
BasePriority : Normal
FileVersion : 6.0.0.2003051500
ProductVersion : 6.0.0.0
ProductName : AcroTray - Adobe Acrobat Distiller helper application.
CompanyName : Adobe Systems Inc.
FileDescription : AcroTray
InternalName : AcroTray
LegalCopyright : Copyright 1984-2003 Adobe Systems Incorporated and its licensors. All rights reserved.
OriginalFilename : AcroTray.exe
#:46 [boinc_gui.exe]
FilePath : C:\Programme\BOINC\
ProcessID : 2944
ThreadCreationTime : 10.01.2005 13:38:17
BasePriority : Normal
FileVersion : 4.13
ProductVersion : 4.13
ProductName : BOINC Core Client
CompanyName : Space Sciences Laboratory
FileDescription : boinc_gui
InternalName : boinc_gui
LegalCopyright : Copyright © 2004 University of California
OriginalFilename : boinc_gui.exe
#:47 [setiathome_4.08_windows_intelx86.exe]
FilePath : C:\Programme\BOINC\projects\setiathome.berkeley.edu\
ProcessID : 3316
ThreadCreationTime : 10.01.2005 13:38:17
BasePriority : Idle
#:48 [firefox.exe]
FilePath : C:\Programme\Mozilla Firefox\
ProcessID : 3628
ThreadCreationTime : 10.01.2005 13:46:09
BasePriority : Normal
#:49 [ad-aware.exe]
FilePath : C:\Programme\Lavasoft\Ad-Aware SE Personal\
ProcessID : 2848
ThreadCreationTime : 10.01.2005 13:54:51
BasePriority : Normal
FileVersion : 6.2.0.206
ProductVersion : VI.Second Edition
ProductName : Lavasoft Ad-Aware SE
CompanyName : Lavasoft Sweden
FileDescription : Ad-Aware SE Core application
InternalName : Ad-Aware.exe
LegalCopyright : Copyright © Lavasoft Sweden
OriginalFilename : Ad-Aware.exe
Comments : All Rights Reserved
Memory scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 2
Started registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Windows Object Recognized!
Type : RegData
Data :
Category : Vulnerability
Comment : Possible virus infection, REG file extension compromised
Rootkey : HKEY_CLASSES_ROOT
Object : regfile\shell\open\command
Value :
Data :
Registry Scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 1
Objects found so far: 3
Started deep registry scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Deep registry scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 3
Started Tracking Cookie scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Tracking cookie scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 3
Deep scanning and examining files (C
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Disk Scan Result for C:\
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 3
Scanning Hosts file......
Hosts file location:"C:\WINDOWS\system32\drivers\etc\hosts".
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Hosts file scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
2 entries scanned.
New critical objects:0
Objects found so far: 3
Performing conditional scans...
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Conditional scan result:
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
New critical objects: 0
Objects found so far: 3
15:12:28 Scan Complete
Summary Of This Scan
»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»»
Total scanning time:00:17:11.32
Objects scanned:155743
Objects identified:1
Objects ignored:0
New critical objects:1
**************************************************
mwav log
Mon Jan 10 15:26:48 2005 => File C:\WINDOWS\system32\KILLAPPS.EXE tagged as not-a-virus:RiskWare.Tool.KillApp.b. No Action Taken.
Mon Jan 10 15:39:05 2005 => File C:\Dokumente und Einstellungen\Willow.AEON\.jpi_cache\jar\1.0\javainstaller.jar-4514e5ea-398dbb50.zip infected by "Trojan-Downloader.Java.OpenStream.t" Virus. Action Taken: No Action Taken.
Mon Jan 10 15:40:14 2005 => File C:\Dokumente und Einstellungen\Willow.AEON\Anwendungsdaten\ACD Systems\Catalogs\Backup\BKID_000000\BKUP_000000002560 infected by "not-a-virus:AdWare.ToolBar.Quick.a" Virus. Action Taken: No Action Taken.
Mon Jan 10 15:45:37 2005 => File C:\Dokumente und Einstellungen\Willow.AEON\Eigene Dateien\Eigene Downloads\hijackthis\backups\backup-20050102-202934-357.dll infected by "TrojanDownloader.Win32.Swizzor.bo" Virus. Action Taken: No Action Taken.
Mon Jan 10 15:57:36 2005 => File C:\Programme\C2Media\Setup.exe infected by "Trojan-Downloader.Win32.Swizzor.cg" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:08 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP122\A0011916.dll infected by "not-a-virus:AdWare.Altnet.c" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:31 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP123\A0011981.EXE infected by "not-a-virus:AdWare.Toolbar.MyWay.b" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:31 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP123\A0011982.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.f" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP124\A0012027.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP124\A0012028.dll infected by "not-a-virus:AdWare.Altnet.a" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:47 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP124\A0012033.exe infected by "not-a-virus:AdWare.Altnet.b" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:27:59 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP124\A0012086.DLL infected by "not-a-virus:AdWare.Toolbar.MyWay.c" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:44 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036147.exe infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:45 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036150.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:45 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036152.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:45 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036155.dll infected by "not-a-virus:AdWare.Gator.6051" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036169.dll infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036170.exe infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:48:46 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP228\A0036172.exe infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken.
Mon Jan 10 16:59:32 2005 => File C:\System Volume Information\_restore{130E3863-E153-4AD7-8B87-CE9245B2F91C}\RP246\A0044637.exe infected by "not-a-virus:AdWare.Gator.3202" Virus. Action Taken: No Action Taken.
Mon Jan 10 17:46:16 2005 => ***** Checking for specific ITW Viruses *****
Mon Jan 10 17:46:16 2005 => Checking for Welchia Virus...
Mon Jan 10 17:46:16 2005 => Checking for LovGate Virus...
Mon Jan 10 17:46:16 2005 => Checking for CodeRed Virus...
Mon Jan 10 17:46:16 2005 => Checking for OpaServ Virus...
Mon Jan 10 17:46:16 2005 => Checking for Sobig.e Virus...
Mon Jan 10 17:46:16 2005 => Checking for Winupie Virus...
Mon Jan 10 17:46:16 2005 => Checking for Swen Virus...
Mon Jan 10 17:46:16 2005 => Checking for JS.Fortnight Virus...
Mon Jan 10 17:46:16 2005 => Checking for Novarg Virus...
Mon Jan 10 17:46:16 2005 => Checking for Pagabot Virus...
Mon Jan 10 17:46:16 2005 => Checking for Parite.b Virus...
Mon Jan 10 17:46:16 2005 => Checking for Parite.a Virus...
Mon Jan 10 17:46:16 2005 => ***** Scanning complete. *****
Mon Jan 10 17:46:16 2005 => Total Files Scanned: 108027
Mon Jan 10 17:46:16 2005 => Total Virus(es) Found: 27
Mon Jan 10 17:46:16 2005 => Total Disinfected Files: 0
Mon Jan 10 17:46:16 2005 => Total Files Renamed: 0
Mon Jan 10 17:46:16 2005 => Total Deleted Files: 0
Mon Jan 10 17:46:16 2005 => Total Errors: 165
Mon Jan 10 17:46:16 2005 => Time Elapsed: 02:26:45
Mon Jan 10 17:46:16 2005 => Virus Database Date: 2005/01/10
Mon Jan 10 17:46:16 2005 => Virus Database Count: 115105
Mon Jan 10 17:46:16 2005 => Scan Completed.
Mon Jan 10 17:47:17 2005 => Virus Database Date: 2005/01/10
Mon Jan 10 17:47:17 2005 => Virus Database Count: 115105
Mon Jan 10 17:47:21 2005 => AV Library Unloaded (3)...
Mon Jan 10 17:59:52 2005 => **********************************************************
Mon Jan 10 17:59:52 2005 => eScan AntiVirus Toolkit Utility.
Mon Jan 10 17:59:52 2005 => Copyright © 2003-2004, MicroWorld Technologies Inc.
Mon Jan 10 17:59:52 2005 => **********************************************************
Mon Jan 10 17:59:52 2005 => Version 4.7.7 (C:\bases\mwavscan.com)
Mon Jan 10 17:59:52 2005 => Log File: C:\bases\mwav.log
Mon Jan 10 17:59:52 2005 => Latest Date of files inside MWAV: 10 Jan 2005 12:00:47.
Mon Jan 10 17:59:53 2005 => AV Library Loaded...
Mon Jan 10 17:59:53 2005 => Scanning File C:\bases\kavss.exe
Mon Jan 10 17:59:53 2005 => Scanning File C:\bases\Getvlist.exe
Mon Jan 10 17:59:53 2005 => Scanning File C:\bases\kavss.dll
Mon Jan 10 17:59:53 2005 => Scanning File C:\bases\kavssdi.dll
Mon Jan 10 17:59:53 2005 => Scanning File C:\bases\kavssi.dll
Mon Jan 10 17:59:53 2005 => Scanning File C:\bases\kavvlg.dll
Mon Jan 10 17:59:54 2005 => Scanning File C:\bases\msvlclnt.dll
Mon Jan 10 17:59:54 2005 => Scanning File C:\bases\ipc.dll
Mon Jan 10 17:59:54 2005 => Scanning File C:\bases\main.avi
Mon Jan 10 17:59:54 2005 => Scanning File C:\bases\virus.avi
Mon Jan 10 17:59:54 2005 => Virus Database Date: 2005/01/10
Mon Jan 10 17:59:54 2005 => Virus Database Count: 115105
***********************************************************
Hijack log neu ( der is aber anders, da ich gestern software für meinen neuen Handheld installiert hab)
Logfile of HijackThis v1.99.0
Scan saved at 17:48:28, on 10.01.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Nhksrv.exe
C:\Programme\AVPersonal\AVGUARD.EXE
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\CTsvcCDA.exe
C:\WINDOWS\System32\inetsrv\inetinfo.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe
C:\WINDOWS\System32\tcpsvcs.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\MsPMSPSv.exe
C:\WINDOWS\System32\mqsvc.exe
C:\WINDOWS\System32\mqtgsvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
C:\Programme\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
C:\WINDOWS\system32\CTHELPER.EXE
C:\WINDOWS\DELLMMKB.EXE
C:\Programme\Java\j2re1.4.2_06\bin\jusched.exe
C:\Programme\iTunes\iTunesHelper.exe
C:\Programme\iPod\bin\iPodService.exe
C:\Programme\Logitech\Video\LogiTray.exe
C:\Programme\QuickTime\qttask.exe
C:\WINDOWS\System32\LVCOMSX.EXE
C:\Programme\AVPersonal\AVGNT.EXE
C:\Programme\Microsoft ActiveSync\WCESCOMM.EXE
C:\Programme\Netropa\OSD.exe
C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Programme\BOINC\boinc_gui.exe
C:\Programme\BOINC\projects\einstein.phys.uwm.edu\einstein_4.65_windows_intelx86.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Dokumente und Einstellungen\Willow.AEON\Eigene Dateien\Eigene Downloads\hijackthis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web.de/
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: IE PopUp-Killer ; Neikeisoft - {49E0E0F0-5C30-11D4-945D-000000000003} - C:\PROGRA~1\Ashampoo\ASHAMP~1\PopUp.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IeCatch2 Class - {A5366673-E8CA-11D3-9CD9-0090271D075B} - C:\PROGRA~1\FlashGet\jccatch.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: FlashGet Bar - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\fgiebar.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [CTSysVol] C:\Programme\Creative\SBAudigy2\Surround Mixer\CTSysVol.exe
O4 - HKLM\..\Run: [CTDVDDet] C:\Programme\Creative\SBAudigy2\DVDAudio\CTDVDDet.EXE
O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\UpdReg.EXE
O4 - HKLM\..\Run: [DellTouch] C:\WINDOWS\DELLMMKB.EXE
O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_06\bin\jusched.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [iTunesHelper] C:\Programme\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Programme\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Programme\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\System32\LVCOMSX.EXE
O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Programme\Microsoft ActiveSync\WCESCOMM.EXE"
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: BOINC.lnk = C:\Programme\BOINC\boinc_gui.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: Alles mit FlashGet laden - C:\Programme\FlashGet\jc_all.htm
O8 - Extra context menu item: Mit FlashGet laden - C:\Programme\FlashGet\jc_link.htm
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MI1933~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll
O9 - Extra button: Mobilen Favoriten erstellen - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra 'Tools' menuitem: Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Programme\Microsoft ActiveSync\INETREPL.DLL
O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra 'Tools' menuitem: &FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\PROGRA~1\FlashGet\flashget.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) -
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) -
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Plug-in 1.4.2_06) -
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) -
O16 - DPF: {A8658086-E6AC-4957-BC8E-7D54A7E8A78D} (DoomCln Object) -
O16 - DPF: {A8658086-E6AC-4957-BC8E-8D54A7E8A790} (GDIChk Object) -
O16 - DPF: {CAFEEFAC-0014-0000-0001-ABCDEFFEDCBA} (Java Plug-in 1.4.0_01) -
O16 - DPF: {CAFEEFAC-0014-0001-0002-ABCDEFFEDCBA} (Java Plug-in 1.4.1_02) -
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} (Java Plug-in 1.4.2_04) -
O16 - DPF: {CAFEEFAC-0014-0002-0006-ABCDEFFEDCBA} (Java Plug-in 1.4.2_06) -
O16 - DPF: {FB48C7B0-EB66-4BE6-A1C5-9DDF3C37249A} (MCSendMessageHandler Class) -
O23 - Service: AntiVir Service - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: Netropa NHK Server - Unknown - C:\WINDOWS\Nhksrv.exe
O23 - Service: Intel(R) NMS - Intel Corporation - C:\WINDOWS\System32\NMSSvc.exe
So, ich bedanke schonmal im Vorraus für deine Hilfe. Ich hoffe das ist bald alles geklärt.
Gruß,
Simon