Trojaner TR/TCPParams.D.2 auf meinem System

Thema ist geschlossen!
Thema ist geschlossen!
#0
19.01.2007, 14:02
...neu hier

Beiträge: 9
#1 Hallo Leute!

AntiVir findet nach jedem Systemstart einen Trojaner namens TR/TCPParams.D.2 auf meinem System. Egal welche Aktion ich ausführe, er kommt nach jedem Systemstart wieder.

Bitte um Hilfe, bin gerade im Ausland und mein System sollte noch für einen Monat ohne Format C:\ durchhalten.

Mein HijackThis log-File:

Logfile of HijackThis v1.99.1
Scan saved at 12:47:27, on 19.01.2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Programme\8Signs Firewall\DFW.exe
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\System32\Ati2evxx.exe
D:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Programme\Belkin\Belkin Wireless Network Utility\WLService.exe
D:\Programme\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\System32\urdvxc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\htpatch.exe
C:\Programme\Synaptics\SynTP\SynTPLpr.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\System32\pctspk.exe
D:\Programme\OmniPageSE2.0\OpwareSE2.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\system33.exe
D:\Programme\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\MSN Messenger\MsnMsgr.Exe
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programme\Outlook Express\msimn.exe
C:\Programme\Messenger\msmsgs.exe
D:\Programme\Mozilla Firefox\firefox.exe
D:\Programme\Winamp\winamp.exe
C:\Programme\AntiVir PersonalEdition Classic\avcenter.exe
C:\Programme\AntiVir PersonalEdition Classic\avscan.exe
E:\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.at/
R3 - URLSearchHook: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Programme\Spybot\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - D:\Programme\FlashFXP\IEFlash.dll
O3 - Toolbar: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - D:\Programme\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [OpwareSE2] "D:\Programme\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Microsoft DLL Verifier] system33.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Programme\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\RunServices: [Microsoft DLL Verifier] system33.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "D:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Acrobat - Schnellstart.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Programme\Gemeinsame Dateien\Autodesk Shared\acstart16.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Programme\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Programme\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Backward &Links - res://C:\Programme\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Programme\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Easy-WebPrint - Drucken - res://D:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - res://D:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint - Vorschau - res://D:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - res://D:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: In vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Programme\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_09\bin\ssv.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://thunder2882.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131142875467
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1131143534654
O16 - DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} (O2C-Player (ELECO Software GmbH)) - http://www.o2c.de/download/o2cplayer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4D7B03FE-0A75-4A60-9CB9-34DEC4C2FDED}: NameServer = 192.168.2.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: 8Signs Firewall (8SignsFirewall) - 8Signs Ltd. - D:\Programme\8Signs Firewall\DFW.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Local Network Service (algs) - Unknown owner - C:\WINDOWS\scvh0st.exe (file missing)
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Programme\Gemeinsame Dateien\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - D:\Programme\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Microsoft Agent - Unknown owner - C:\WINDOWS\System32\dllcache\ffchost.exe (file missing)
O23 - Service: Network Windows Service (MSWindows) - Unknown owner - C:\WINDOWS\System32\urdvxc.exe" /service (file missing)


mfg Günter
Seitenanfang Seitenende
19.01.2007, 14:24
Ehrenmitglied
Avatar Sabina

Beiträge: 29434
#2 thunder2882

««
stelle den CleanUp genauso ein, wie hier angegeben:
http://virus-protect.org/cleanup.html

««
Kopiere diese 6 Textdateien ab . (rechtsklick mit der Maus -> den Text markieren -> kopieren -> einfügen) Sie sind nach Datum geordnet. (kopiere nur die letzten 3 Monate ab)
http://virus-protect.org/datfindbat.html

««
ServiceFilter.zip
http://virus-protect.org/artikel/tools/ServiceFilter.zip

- entzippen
- doppelklick auf die datei ServiceFilter.vbs
- versions-nummer bestätigen
- scannen
- öffnen von wordpad oder editor erlauben
- POST_THIS.TXT abkopieren
__________
MfG Sabina

rund um die PC-Sicherheit
Seitenanfang Seitenende
19.01.2007, 15:27
...neu hier

Themenstarter

Beiträge: 9
#3 Hi Sabrina!

Danke für deine schnelle Antwort!

Hab alle Schritte ausgeführt:

Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: CC4A-F76C

Verzeichnis von C:\WINDOWS\system32

16.01.2007 12:59 2.184 wpa.dbl
31.12.2006 14:36 57.856 .exe
31.12.2006 14:36 57.856 urdvxc.exe
31.12.2006 14:17 70 i
22.11.2006 17:31 14.848 BASSMOD.dll
15.11.2006 16:23 8.891 jupdate-1.5.0_09-b03.log
29.10.2006 17:20 380.548 perfh009.dat
29.10.2006 17:20 52.962 perfc009.dat
29.10.2006 17:20 391.238 perfh007.dat
29.10.2006 17:20 63.778 perfc007.dat
29.10.2006 17:20 897.954 PerfStringBackup.INI
12.10.2006 03:10 127.078 javaws.exe
12.10.2006 03:10 49.265 jpicpl32.cpl
12.10.2006 01:35 53.346 javaw.exe
12.10.2006 01:35 49.248 java.exe
04.10.2006 20:03 9.639.336 MRT.exe
04.10.2006 09:23 668 datFind.bat
02.10.2006 19:04 806.912 divx_xx07.dll
02.10.2006 19:04 806.912 divx_xx0c.dll
02.10.2006 19:04 790.528 divx_xx11.dll
02.10.2006 19:04 635.486 DivX.dll

Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: CC4A-F76C

Verzeichnis von C:\DOKUME~1\GNTER~1\LOKALE~1\Temp

19.01.2007 12:29 1.020 ~ROMFN_00001498
19.01.2007 12:29 8.324 jusched.log
18.01.2007 13:32 0 WER1.tmp
17.01.2007 20:04 832 java_install_reg.log
14.01.2007 22:25 416 MSI84f89.LOG
14.01.2007 19:40 1.156 jinstall.cfg
13.01.2007 17:52 12.936 control.xml
13.01.2007 00:00 0 aaxB7.tmp
12.01.2007 23:55 0 aaxAE.tmp
12.01.2007 23:55 0 aaxAD.tmp
12.01.2007 17:01 59.964 Adobelm_Cleanup.0001
09.01.2007 23:12 691 TWAIN.LOG
09.01.2007 23:12 3 Twain001.Mtx
09.01.2007 23:12 156 Twunk001.MTX
09.01.2007 23:11 0 Twunk002.MTX
09.01.2007 21:06 1.687 hijackthis.log
09.01.2007 21:06 16.384 ~DFE2EF.tmp
09.01.2007 14:40 0 aax3C.tmp
09.01.2007 14:34 0 aax3A.tmp
09.01.2007 14:34 0 aax39.tmp
10.11.2006 18:42 251.656 AutoDL%3FBundleId=10878_b197838c.exe
04.10.2006 09:23 668 datFind.bat

Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: CC4A-F76C

Verzeichnis von C:\WINDOWS

19.01.2007 13:18 625.268 setupapi.log
19.01.2007 12:21 159 wiadebug.log
19.01.2007 12:21 50 wiaservc.log
19.01.2007 12:21 0 0.log
19.01.2007 12:21 2.048 bootstat.dat
18.01.2007 20:31 32.588 SchedLgU.Txt
18.01.2007 13:25 180.472 ntbtlog.txt
13.01.2007 17:52 71.823 wmsetup.log
13.01.2007 15:18 116 NeroDigital.ini
08.01.2007 11:22 179.546 setupact.log
06.01.2007 15:27 1.683.189 WindowsUpdate.log
19.12.2006 14:19 38 AviSplitter.INI
29.11.2006 18:01 169 RtlRack.ini
29.11.2006 16:06 54.156 QTFont.qfn
29.11.2006 16:06 1.409 QTFont.for
12.11.2006 12:43 385.216 DirectX.log
24.10.2006 21:34 702 ie7_main.log
23.10.2006 21:24 0 nsreg.dat
04.10.2006 09:23 668 datFind.bat

Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: CC4A-F76C

Verzeichnis von C:\WINDOWS\Temp

18.01.2007 13:28 16.384 Perflib_Perfdata_8cc.dat
02.01.2007 12:18 0 Upd3.tmp
02.01.2007 12:09 16.384 ~DFF195.tmp
02.01.2007 11:09 16.384 ~DFF13A.tmp
31.12.2006 15:14 16.384 Perflib_Perfdata_a58.dat
31.12.2006 15:13 16.384 ~DFF8EF.tmp
31.12.2006 15:03 16.384 ~DFFEB0.tmp
31.12.2006 13:59 16.384 ~DFF313.tmp
28.12.2006 17:10 16.384 ~DFF6F0.tmp
28.12.2006 11:29 16.384 ~DFF6B8.tmp
28.12.2006 09:21 16.384 ~DFF69A.tmp
27.12.2006 14:42 16.384 Perflib_Perfdata_250.dat
27.12.2006 14:40 16.384 ~DFF561.tmp
27.12.2006 13:50 16.384 ~DFF3CA.tmp
26.12.2006 00:28 16.384 ~DFFAFF.tmp
25.12.2006 23:55 16.384 ~DFFBC9.tmp
25.12.2006 18:34 16.384 ~DFF38C.tmp
25.12.2006 18:22 16.384 ~DFF5AC.tmp
25.12.2006 18:12 16.384 ~DFF584.tmp
25.12.2006 11:54 16.384 ~DFFA13.tmp
24.12.2006 17:17 16.384 ~DFF5E5.tmp
20.12.2006 17:33 16.384 ~DFFDE0.tmp
20.12.2006 16:54 16.384 ~DFEFEC.tmp
19.12.2006 15:23 16.384 ~DFF0F7.tmp
19.12.2006 14:30 16.384 ~DFF3B1.tmp
19.12.2006 14:29 8.192 cch~32e30e081.htp
19.12.2006 14:29 8.192 cch~32e30f355.htp
19.12.2006 14:29 8.192 cch~32de1a9ea.htp
19.12.2006 14:29 8.192 cch~32de16f75.htp
19.12.2006 14:29 8.192 cch~32d8df9d1.htp
19.12.2006 14:29 8.192 cch~32d8deff3.htp
19.12.2006 14:29 8.192 cch~32d8a2283.htp
19.12.2006 14:29 8.192 cch~32d8a1836.htp
19.12.2006 14:29 8.192 cch~32d53387f.htp
19.12.2006 14:29 8.192 cch~32d532bc8.htp
19.12.2006 14:28 8.192 cch~32bbae43d.htp
19.12.2006 14:28 8.192 cch~32bbaed99.htp
19.12.2006 14:28 8.192 cch~32b88ed5e.htp
19.12.2006 14:28 8.192 cch~32b88903c.htp
19.12.2006 12:47 16.384 ~DFF49A.tmp
19.12.2006 12:26 16.384 ~DFF0A2.tmp
19.12.2006 11:49 16.384 Perflib_Perfdata_e04.dat
18.12.2006 17:16 16.384 ~DFF467.tmp
18.12.2006 16:13 16.384 ~DFF967.tmp
18.12.2006 12:15 16.384 ~DFFC7A.tmp
18.12.2006 09:58 16.384 ~DFF4E5.tmp
18.12.2006 08:51 16.384 ~DFF18E.tmp
18.12.2006 08:44 16.384 ~DFEE4C.tmp
13.12.2006 15:11 16.384 ~DFF254.tmp
12.12.2006 07:57 16.384 ~DFF844.tmp
11.12.2006 14:36 16.384 ~DFFAAF.tmp
11.12.2006 10:06 16.384 ~DFF80B.tmp
10.12.2006 17:28 16.384 ~DFF247.tmp
09.12.2006 16:17 16.384 ~DFF2E6.tmp
09.12.2006 16:15 16.384 Perflib_Perfdata_8b8.dat
09.12.2006 16:12 16.384 ~DFF211.tmp
09.12.2006 15:11 16.384 ~DFF0F2.tmp
09.12.2006 14:57 16.384 ~DFF31D.tmp
09.12.2006 14:47 16.384 ~DFF25D.tmp
09.12.2006 14:26 16.384 ~DFF900.tmp
09.12.2006 14:14 16.384 ~DFF80D.tmp
08.12.2006 15:25 16.384 ~DFFA03.tmp
08.12.2006 11:26 16.384 ~DFF7FA.tmp
08.12.2006 01:28 16.384 ~DFF7B3.tmp
07.12.2006 17:59 16.384 ~DFF59C.tmp
06.12.2006 22:32 16.384 ~DFF878.tmp
06.12.2006 09:51 16.384 ~DFF2A4.tmp
06.12.2006 09:50 16.384 Perflib_Perfdata_8f0.dat
06.12.2006 09:48 16.384 ~DFF20D.tmp
05.12.2006 09:34 16.384 ~DFF87E.tmp
04.12.2006 21:57 16.384 ~DFF803.tmp
04.12.2006 16:19 16.384 ~DFFA7C.tmp
04.12.2006 09:53 16.384 ~DFF9DA.tmp
03.12.2006 13:12 16.384 ~DFFA29.tmp
03.12.2006 00:33 16.384 ~DFF463.tmp
02.12.2006 19:18 16.384 ~DFEEA9.tmp
02.12.2006 11:02 16.384 ~DFFCD0.tmp
01.12.2006 15:55 16.384 ~DFF79F.tmp
01.12.2006 11:37 16.384 ~DFF7FB.tmp
30.11.2006 18:35 16.384 ~DFF3DF.tmp
30.11.2006 16:11 16.384 ~DFF1C6.tmp
30.11.2006 16:09 16.384 Perflib_Perfdata_904.dat
30.11.2006 16:07 16.384 ~DFF9C5.tmp
30.11.2006 13:15 16.384 ~DFF215.tmp
30.11.2006 13:13 16.384 Perflib_Perfdata_a1c.dat
30.11.2006 13:07 16.384 ~DFF79D.tmp
29.11.2006 13:59 16.384 ~DFF245.tmp
28.11.2006 09:55 16.384 ~DFFE06.tmp
27.11.2006 18:14 16.384 ~DFF21F.tmp
27.11.2006 18:14 49.658 PRA7.tmp
27.11.2006 18:14 49.844 PRA6.tmp
27.11.2006 18:14 50.760 PRA5.tmp
27.11.2006 18:14 49.438 PRA4.tmp
27.11.2006 18:14 49.867 PRA3.tmp
27.11.2006 18:14 49.864 PRA2.tmp
27.11.2006 18:14 49.412 PRA0.tmp
27.11.2006 18:14 49.617 PR9F.tmp
27.11.2006 18:14 49.911 PRA1.tmp
27.11.2006 18:14 49.690 PR9E.tmp
27.11.2006 18:14 49.663 PR9D.tmp
27.11.2006 18:14 49.864 PR9C.tmp
27.11.2006 18:14 49.690 PR9B.tmp
27.11.2006 18:14 49.898 PR9A.tmp
27.11.2006 18:14 49.247 PR99.tmp
27.11.2006 18:14 46.904 PR98.tmp
27.11.2006 18:14 50.263 PR97.tmp
27.11.2006 18:14 49.645 PR95.tmp
27.11.2006 18:14 49.449 PR94.tmp
27.11.2006 18:14 49.428 PR93.tmp
27.11.2006 18:14 49.228 PR92.tmp
27.11.2006 18:14 49.438 PR96.tmp
27.11.2006 18:14 49.631 PR91.tmp
27.11.2006 18:14 50.070 PR90.tmp
27.11.2006 18:13 49.381 PR8E.tmp
27.11.2006 18:13 49.517 PR8F.tmp
27.11.2006 18:13 49.634 PR8D.tmp
27.11.2006 18:13 49.822 PR8C.tmp
27.11.2006 18:13 49.034 PR8A.tmp
27.11.2006 18:13 49.346 PR8B.tmp
27.11.2006 18:13 49.693 PR89.tmp
27.11.2006 18:13 49.125 PR88.tmp
27.11.2006 18:13 48.818 PR87.tmp
27.11.2006 18:13 48.517 PR86.tmp
27.11.2006 18:13 48.346 PR85.tmp
27.11.2006 18:13 48.206 PR84.tmp
27.11.2006 18:13 48.197 PR83.tmp
27.11.2006 18:13 48.753 PR82.tmp
27.11.2006 18:13 48.528 PR80.tmp
27.11.2006 18:13 49.012 PR7F.tmp
27.11.2006 18:13 48.592 PR81.tmp
27.11.2006 18:13 48.771 PR7E.tmp
27.11.2006 18:13 49.645 PR7D.tmp
27.11.2006 18:13 49.151 PR7C.tmp
27.11.2006 18:13 47.712 PR7B.tmp
27.11.2006 18:13 49.639 PR7A.tmp
27.11.2006 18:13 32.125 PR78.tmp
27.11.2006 18:13 99.009 PR77.tmp
27.11.2006 18:13 687 PR79.tmp
27.11.2006 18:13 112.879 PR76.tmp
27.11.2006 18:13 49.379 PR75.tmp
27.11.2006 18:13 33.294 PR74.tmp
27.11.2006 18:13 68.552 PR73.tmp
27.11.2006 18:13 123.317 PR71.tmp
27.11.2006 18:13 144.370 PR72.tmp
27.11.2006 18:13 8.680 PR70.tmp
27.11.2006 18:13 181 PR6F.tmp
27.11.2006 18:13 2.209 PR6E.tmp
27.11.2006 18:13 249 PR6B.tmp
27.11.2006 18:13 657 PR6D.tmp
27.11.2006 18:13 2.209 PR6A.tmp
27.11.2006 18:13 181 PR69.tmp
27.11.2006 18:13 2.209 PR68.tmp
27.11.2006 18:13 2.209 PR6C.tmp
27.11.2006 18:13 2.209 PR66.tmp
27.11.2006 18:13 181 PR67.tmp
27.11.2006 18:13 181 PR65.tmp
27.11.2006 18:13 2.209 PR64.tmp
27.11.2006 18:13 2.209 PR62.tmp
27.11.2006 18:13 6.937 PR63.tmp
27.11.2006 18:13 453 PR61.tmp
27.11.2006 18:13 214 PR5F.tmp
27.11.2006 18:13 2.209 PR60.tmp
27.11.2006 18:13 147.764 PR5E.tmp
27.11.2006 18:13 49.658 PR5D.tmp
27.11.2006 18:13 49.867 PR59.tmp
27.11.2006 18:13 49.844 PR5C.tmp
27.11.2006 18:13 50.760 PR5B.tmp
27.11.2006 18:13 49.438 PR5A.tmp
27.11.2006 18:13 49.864 PR58.tmp
27.11.2006 18:13 49.911 PR57.tmp
27.11.2006 18:13 49.617 PR55.tmp
27.11.2006 18:13 49.412 PR56.tmp
27.11.2006 18:13 49.690 PR54.tmp
27.11.2006 18:13 49.864 PR52.tmp
27.11.2006 18:13 49.690 PR51.tmp
27.11.2006 18:13 49.663 PR53.tmp
27.11.2006 18:13 49.898 PR50.tmp
27.11.2006 18:13 50.263 PR4D.tmp
27.11.2006 18:13 46.904 PR4E.tmp
27.11.2006 18:13 49.247 PR4F.tmp
27.11.2006 18:13 49.438 PR4C.tmp
27.11.2006 18:13 49.645 PR4B.tmp
27.11.2006 18:13 49.449 PR4A.tmp
27.11.2006 18:13 49.428 PR49.tmp
27.11.2006 18:13 49.228 PR48.tmp
27.11.2006 18:13 49.631 PR47.tmp
27.11.2006 18:13 49.346 PR41.tmp
27.11.2006 18:13 49.634 PR43.tmp
27.11.2006 18:13 49.034 PR40.tmp
27.11.2006 18:13 49.693 PR3F.tmp
27.11.2006 18:13 50.070 PR46.tmp
27.11.2006 18:13 49.517 PR45.tmp
27.11.2006 18:13 49.381 PR44.tmp
27.11.2006 18:13 49.822 PR42.tmp
27.11.2006 18:13 48.818 PR3D.tmp
27.11.2006 18:13 49.125 PR3E.tmp
27.11.2006 18:13 48.517 PR3C.tmp
27.11.2006 18:13 48.206 PR3A.tmp
27.11.2006 18:13 48.346 PR3B.tmp
27.11.2006 18:13 48.197 PR39.tmp
27.11.2006 18:13 48.753 PR38.tmp
27.11.2006 18:13 48.592 PR37.tmp
27.11.2006 18:13 48.528 PR36.tmp
27.11.2006 18:13 49.012 PR35.tmp
27.11.2006 18:13 48.771 PR34.tmp
27.11.2006 18:13 49.645 PR33.tmp
27.11.2006 18:13 49.151 PR32.tmp
27.11.2006 18:13 47.712 PR31.tmp
27.11.2006 18:13 49.639 PR30.tmp
27.11.2006 18:13 687 PR2F.tmp
27.11.2006 18:13 32.125 PR2E.tmp
27.11.2006 18:13 99.009 PR2D.tmp
27.11.2006 18:13 112.879 PR2C.tmp
27.11.2006 18:13 49.379 PR2B.tmp
27.11.2006 18:13 33.294 PR2A.tmp
27.11.2006 18:13 68.552 PR29.tmp
27.11.2006 18:13 144.370 PR28.tmp
27.11.2006 18:13 181 PR25.tmp
27.11.2006 18:13 123.317 PR27.tmp
27.11.2006 18:13 8.680 PR26.tmp
27.11.2006 18:13 2.209 PR24.tmp
27.11.2006 18:13 657 PR23.tmp
27.11.2006 18:13 249 PR21.tmp
27.11.2006 18:13 2.209 PR22.tmp
27.11.2006 18:13 2.209 PR20.tmp
27.11.2006 18:13 181 PR1F.tmp
27.11.2006 18:13 2.209 PR1E.tmp
27.11.2006 18:13 2.209 PR1C.tmp
27.11.2006 18:13 181 PR1D.tmp
27.11.2006 18:13 2.209 PR1A.tmp
27.11.2006 18:13 181 PR1B.tmp
27.11.2006 18:13 2.209 PR18.tmp
27.11.2006 18:13 6.937 PR19.tmp
27.11.2006 18:13 453 PR17.tmp
27.11.2006 18:13 2.209 PR16.tmp
27.11.2006 18:13 147.764 PR15.tmp
27.11.2006 18:13 657 PR14.tmp
27.11.2006 18:13 181 PR13.tmp
27.11.2006 18:13 249 PR12.tmp
27.11.2006 18:13 181 PR10.tmp
27.11.2006 18:13 181 PR11.tmp
27.11.2006 18:13 6.937 PRF.tmp
27.11.2006 18:13 453 PRE.tmp
27.11.2006 18:13 181 PRD.tmp
27.11.2006 18:13 2.209 PRC.tmp
27.11.2006 18:13 2.209 PRB.tmp
27.11.2006 18:13 2.209 PRA.tmp
27.11.2006 18:13 2.209 PR9.tmp
27.11.2006 18:13 2.209 PR8.tmp
27.11.2006 18:13 2.209 PR7.tmp
27.11.2006 18:13 2.209 PR6.tmp
27.11.2006 18:13 214 PR4.tmp
27.11.2006 18:13 2.209 PR5.tmp
27.11.2006 18:13 214 PR3.tmp
27.11.2006 18:12 16.384 Perflib_Perfdata_c74.dat
27.11.2006 18:10 16.384 ~DFF263.tmp
27.11.2006 18:06 16.384 Perflib_Perfdata_208.dat
24.11.2006 12:37 16.384 Perflib_Perfdata_b00.dat
07.11.2006 18:14 16.384 Perflib_Perfdata_ff4.dat

Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: CC4A-F76C

Verzeichnis von C:\WINDOWS\Downloaded Program Files

04.10.2006 09:23 668 datFind.bat

Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: CC4A-F76C

Verzeichnis von C:\

19.01.2007 14:21 0 sys.txt
19.01.2007 14:21 935 down.txt
19.01.2007 14:21 14.674 tmp.txt
19.01.2007 14:21 6.820 system.txt
19.01.2007 14:21 1.413 systemtemp.txt
19.01.2007 14:21 100.855 system32.txt
19.01.2007 12:21 805.306.368 pagefile.sys
18.01.2007 16:38 268 sqmdata00.sqm
18.01.2007 16:38 244 sqmnoopt00.sqm
18.01.2007 13:29 268 sqmdata19.sqm
18.01.2007 13:29 244 sqmnoopt19.sqm
08.01.2007 11:40 145.810 e.exe
07.01.2007 22:09 232 sqmdata18.sqm
07.01.2007 22:09 244 sqmnoopt18.sqm
06.01.2007 14:21 268 sqmdata17.sqm
06.01.2007 14:21 244 sqmnoopt17.sqm
06.01.2007 14:14 244 sqmnoopt15.sqm
06.01.2007 14:14 244 sqmnoopt16.sqm
06.01.2007 14:14 268 sqmdata15.sqm
06.01.2007 14:14 232 sqmdata16.sqm
05.01.2007 20:58 244 sqmnoopt14.sqm
05.01.2007 20:58 268 sqmdata14.sqm
03.01.2007 09:23 268 sqmdata13.sqm
03.01.2007 09:23 244 sqmnoopt13.sqm
02.01.2007 20:18 292 sqmdata12.sqm
02.01.2007 20:18 244 sqmnoopt12.sqm
02.01.2007 16:11 268 sqmdata11.sqm
02.01.2007 16:11 244 sqmnoopt11.sqm
02.01.2007 12:16 268 sqmdata10.sqm
02.01.2007 12:16 244 sqmnoopt10.sqm
02.01.2007 12:14 268 sqmdata09.sqm
02.01.2007 12:14 244 sqmnoopt09.sqm
28.12.2006 13:37 268 sqmdata08.sqm
28.12.2006 13:37 244 sqmnoopt08.sqm
27.12.2006 13:52 268 sqmdata07.sqm
27.12.2006 13:52 244 sqmnoopt07.sqm
26.12.2006 00:33 268 sqmdata06.sqm
26.12.2006 00:33 244 sqmnoopt06.sqm
19.12.2006 17:53 268 sqmdata05.sqm
19.12.2006 17:53 244 sqmnoopt05.sqm
09.12.2006 16:16 268 sqmdata04.sqm
09.12.2006 16:16 244 sqmnoopt04.sqm
08.12.2006 13:06 232 sqmdata03.sqm
08.12.2006 13:06 244 sqmnoopt03.sqm
06.12.2006 09:50 268 sqmdata02.sqm
06.12.2006 09:50 244 sqmnoopt02.sqm
03.12.2006 00:55 268 sqmdata01.sqm
03.12.2006 00:55 244 sqmnoopt01.sqm
04.10.2006 09:23 668 datFind.bat

Mein Post This file:

The script did not recognize the services listed below.
This does not mean that they are a problem.

To copy the entire contents of this document for posting:
At the top of this window click "Edit" then "Select All"
Next click "Edit" again then "Copy"
Now right click in the forum post box then click "Paste"

########################################

ServiceFilter 1.1
by rand1038

Microsoft Windows XP Professional
Version: 5.1.2600
Jän 19, 2007 14:10:46


---> Begin Service Listing <---

Unknown Service # 1
Service Name: 8SignsFirewall
Display Name: 8Signs Firewall
Start Mode: Auto
Start Name: LocalSystem
Description: Controls access to your ...
Service Type: Own Process
Path: d:\programme\8signs firewall\dfw.exe nt_service
State: Running
Process ID: 1616
Started: Wahr
Exit Code: 0
Accept Pause: Falsch
Accept Stop: Wahr

Unknown Service # 2
Service Name: Adobe LM Service
Display Name: Adobe LM Service
Start Mode: Manual
Start Name: LocalSystem
Description: AdobeLM ...
Service Type: Own Process
Path: "c:\programme\gemeinsame dateien\adobe systems shared\service\adobelmsvc.exe"
State: Stopped
Process ID: 0
Started: Falsch
Exit Code: 1077
Accept Pause: Falsch
Accept Stop: Falsch

Unknown Service # 3
Service Name: algs
Display Name: Local Network Service
Start Mode: Auto
Start Name: LocalSystem
Description: Local Network ...
Service Type: Own Process
Path: "c:\windows\scvh0st.exe"
State: Stopped
Process ID: 0
Started: Falsch
Exit Code: 0
Accept Pause: Falsch
Accept Stop: Falsch

Unknown Service # 4
Service Name: AntiVirScheduler
Display Name: AntiVir PersonalEdition Classic Planer
Start Mode: Auto
Start Name: LocalSystem
Description: Dienst zur Steuerung von AntiVir Prüfaufträgen und ...
Service Type: Own Process
Path: c:\programme\antivir personaledition classic\sched.exe
State: Running
Process ID: 1636
Started: Wahr
Exit Code: 0
Accept Pause: Falsch
Accept Stop: Wahr

Unknown Service # 5
Service Name: AntiVirService
Display Name: AntiVir PersonalEdition Classic Guard
Start Mode: Auto
Start Name: LocalSystem
Description: Bietet permanenten Schutz vor Viren und Malware mit der AntiVir ...
Service Type: Own Process
Path: c:\programme\antivir personaledition classic\avguard.exe
State: Running
Process ID: 1732
Started: Wahr
Exit Code: 0
Accept Pause: Falsch
Accept Stop: Wahr

Unknown Service # 6
Service Name: Autodesk Licensing Service
Display Name: Autodesk Licensing Service
Start Mode: Manual
Start Name: LocalSystem
Description: Anchor service for Autodesk products licensed with ...
Service Type: Own Process
Path: "c:\programme\gemeinsame dateien\autodesk shared\service\adskscsrv.exe"
State: Stopped
Process ID: 0
Started: Falsch
Exit Code: 1077
Accept Pause: Falsch
Accept Stop: Falsch

Unknown Service # 7
Service Name: AVG Anti-Spyware Guard
Display Name: AVG Anti-Spyware Guard
Start Mode: Auto
Start Name: LocalSystem
Description: ...
Service Type: Own Process
Path: d:\programme\grisoft\avg anti-spyware 7.5\guard.exe
State: Running
Process ID: 1768
Started: Wahr
Exit Code: 0
Accept Pause: Falsch
Accept Stop: Falsch

Unknown Service # 8
Service Name: Belkin Wireless USB Network Adapter Service
Display Name: Belkin Wireless USB Network Adapter
Start Mode: Auto
Start Name: LocalSystem
Description: Wireless LAN ...
Service Type: Own Process
Path: d:\programme\belkin\belkin wireless network utility\wlservice.exe
State: Running
Process ID: 1796
Started: Wahr
Exit Code: 0
Accept Pause: Wahr
Accept Stop: Wahr

Unknown Service # 9
Service Name: IDriverT
Display Name: InstallDriver Table Manager
Start Mode: Manual
Start Name: LocalSystem
Description: Provides support for the Running Object Table for InstallShield ...
Service Type: Own Process
Path: c:\programme\gemeinsame dateien\installshield\driver\11\intel 32\idrivert.exe
State: Stopped
Process ID: 0
Started: Falsch
Exit Code: 1077
Accept Pause: Falsch
Accept Stop: Falsch

Unknown Service # 10
Service Name: Microsoft Agent
Display Name: Microsoft Agent
Start Mode: Auto
Start Name: LocalSystem
Description: Enable Microsoft Agent ...
Service Type: Own Process
Path: "c:\windows\system32\dllcache\ffchost.exe"
State: Stopped
Process ID: 0
Started: Falsch
Exit Code: 0
Accept Pause: Falsch
Accept Stop: Falsch

Unknown Service # 11
Service Name: MSWindows
Display Name: Network Windows Service
Start Mode: Auto
Start Name: LocalSystem
Description: Network Windows service ...
Service Type: Own Process
Path: "c:\windows\system32\urdvxc.exe" /service
State: Running
Process ID: 1844
Started: Wahr
Exit Code: 0
Accept Pause: Falsch
Accept Stop: Wahr

Unknown Service #12
Service Name: SwPrv
Display Name: MS Software Shadow Copy Provider
Start Mode: Manual
Start Name: LocalSystem
Description: Verwaltet Software-basierte Schattenkopien des Volumeschattenkopie-Dienstes. Software-basierte ...
Service Type: Own Process
Path: c:\windows\system32\dllhost.exe /processid:{c3ab6ae2-3501-4a6b-95b4-8a033c2a177d}
State: Stopped
Process ID: 0
Started: Falsch
Exit Code: 1077
Accept Pause: Falsch
Accept Stop: Falsch

Unknown Service # 13
Service Name: usnsvc
Display Name: Messenger Sharing USN Journal Reader-Service
Start Mode: Manual
Start Name: LocalSystem
Description: Ein von Messenger installierter Service, der Freigabeszenarien ...
Service Type: Own Process
Path: c:\windows\system32\svchost.exe -k usnsvc
State: Stopped
Process ID: 0
Started: Falsch
Exit Code: 1077
Accept Pause: Falsch
Accept Stop: Falsch

---> End Service Listing <---

There are 93 Win32 services on this machine.
13 were unrecognized.

Script Execution Time: 6,25 seconds.

Danke für deine Bemühungen,

mfg Günter
Seitenanfang Seitenende
19.01.2007, 15:45
Ehrenmitglied
Avatar Sabina

Beiträge: 29434
#4 Download Registry Search by Bobbi Flekman
http://virus-protect.org/artikel/tools/regsearch.html
und doppelklicken, um zu starten.
in: "Enter search strings" (reinschreiben oder reinkopieren)

MSWindows

in edit und klicke "Ok".
Notepad wird sich öffnen -- kopiere den Text ab und poste ihn.

in: "Enter search strings" (reinschreiben oder reinkopieren)

Network Windows Service

in edit und klicke "Ok".
Notepad wird sich öffnen -- kopiere den Text ab und poste ihn.

in: "Enter search strings" (reinschreiben oder reinkopieren)

algs

in edit und klicke "Ok".
Notepad wird sich öffnen -- kopiere den Text ab und poste ihn.

in: "Enter search strings" (reinschreiben oder reinkopieren)

Local Network Service

in edit und klicke "Ok".
Notepad wird sich öffnen -- kopiere den Text ab und poste ihn.

in: "Enter search strings" (reinschreiben oder reinkopieren)

Microsoft Agent

in edit und klicke "Ok".
Notepad wird sich öffnen -- kopiere den Text ab und poste ihn.

in: "Enter search strings" (reinschreiben oder reinkopieren)

system33.exe

in edit und klicke "Ok".
Notepad wird sich öffnen -- kopiere den Text ab und poste ihn.

in: "Enter search strings" (reinschreiben oder reinkopieren)

Microsoft DLL Verifier

in edit und klicke "Ok".
Notepad wird sich öffnen -- kopiere den Text ab und poste ihn.

-------------------------------------------------------------------------------------------
ist fuer mich

Zitat

C:\WINDOWS\System32\system33.exe
C:\WINDOWS\System32\urdvxc.exe
C:\WINDOWS\System32\.exe
C:\WINDOWS\System32\i
c:\windows\scvh0st.exe
c:\windows\system32\dllcache\ffchost.exe
C:\e.exe


__________
MfG Sabina

rund um die PC-Sicherheit
Seitenanfang Seitenende
19.01.2007, 16:38
...neu hier

Themenstarter

Beiträge: 9
#5 Hi Sabina!

Die logs:

Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.2.0

; Results at 19.01.2007 15:05:59 for strings:
; 'mswindows'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSWINDOWS]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSWINDOWS\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSWINDOWS\0000]
"Service"="MSWindows"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSWINDOWS\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSWINDOWS\0000\Control]
"ActiveService"="MSWindows"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSWindows]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSWindows\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSWindows\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSWindows\Enum]
"0"="Root\\LEGACY_MSWINDOWS\\0000"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MSWINDOWS]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MSWINDOWS\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MSWINDOWS\0000]
"Service"="MSWindows"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSWindows]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSWindows\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSWINDOWS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSWINDOWS\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSWINDOWS\0000]
"Service"="MSWindows"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSWINDOWS\0000\Control]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSWINDOWS\0000\Control]
"ActiveService"="MSWindows"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSWindows]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSWindows\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSWindows\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSWindows\Enum]
"0"="Root\\LEGACY_MSWINDOWS\\0000"

; End Of The Log...

Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.2.0

; Results at 19.01.2007 15:13:08 for strings:
; 'microsoft agent'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Character.2]
@="Microsoft Agent Character File (HTTP format)"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Character2.2]
@="Microsoft Agent Character File"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Control]
@="Microsoft Agent Control 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Control.1]
@="Microsoft Agent Control 1.5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Control.2]
@="Microsoft Agent Control 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Preview.2]
@="Microsoft Agent Preview File"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Server]
@="Microsoft Agent Server 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Agent.Server.2]
@="Microsoft Agent Server 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0FA9F4D5-A173-11D1-AA62-00C04FA34D72}]
@="Microsoft Agent Voice Command Module Class"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{143A62C8-C33B-11D1-84FE-00C04FA34A14}]
@="Microsoft Agent Character Property Sheet Handler"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{A7B93C92-7B81-11D0-AC5F-00C04FD97575}]
@="Microsoft Agent Server 1.5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{BB64DF2F-88E4-11D0-9E87-00C04FD7081F}]
@="Microsoft Agent DocFile Provider 1.5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480405-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0405"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480406-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0406"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480407-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0407"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480408-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0408"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480409-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0409"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C348040B-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x040b"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C348040C-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x040c"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C348040E-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x040e"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480410-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0410"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480413-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0413"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480414-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0414"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480415-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0415"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480416-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0416"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480419-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0419"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C348041D-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x041d"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C348041F-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x041f"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480816-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0816"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C3480C0A-A7F8-11D1-AA75-00C04FA34D72}]
@="Microsoft Agent International DLL for Language 0x0c0a"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D45FD2FC-5C6E-11D1-9EC1-00C04FD7081F}]
@="Microsoft Agent Server 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D45FD2FF-5C6E-11D1-9EC1-00C04FD7081F}]
@="Microsoft Agent DocFile Provider 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D45FD300-5C6E-11D1-9EC1-00C04FD7081F}]
@="Microsoft Agent File Provider 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D45FD301-5C6E-11D1-9EC1-00C04FD7081F}]
@="Microsoft Agent Flat File Provider 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D45FD31B-5C6E-11D1-9EC1-00C04FD7081F}]
@="Microsoft Agent Control 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{F5BE8BD2-7DE6-11D0-91FE-00C04FD701A5}]
@="Microsoft Agent Control 1.5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{A7B93C73-7B81-11D0-AC5F-00C04FD97575}\2.0]
@="Microsoft Agent Server 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{D6589123-FC70-11D0-AC94-00C04FD97575}\2.0]
@="Microsoft Agent Server Extensions 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F5BE8BC2-7DE6-11D0-91FE-00C04FD701A5}\1.5]
@="Microsoft Agent Control 1.5"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\TypeLib\{F5BE8BC2-7DE6-11D0-91FE-00C04FD701A5}\2.0]
@="Microsoft Agent Control 2.0"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved]
"{143A62C8-C33B-11D1-84FE-00C04FA34A14}"="Microsoft Agent Character Property Sheet Handler"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MICROSOFT_AGENT\0000]
"Service"="Microsoft Agent"
"DeviceDesc"="Microsoft Agent"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Microsoft Agent]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Microsoft Agent]
"DisplayName"="Microsoft Agent"
"Description"="Enable Microsoft Agent Service."

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Microsoft Agent\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Microsoft Agent\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MICROSOFT_AGENT\0000]
"Service"="Microsoft Agent"
"DeviceDesc"="Microsoft Agent"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Microsoft Agent]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Microsoft Agent]
"DisplayName"="Microsoft Agent"
"Description"="Enable Microsoft Agent Service."

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Microsoft Agent\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MICROSOFT_AGENT\0000]
"Service"="Microsoft Agent"
"DeviceDesc"="Microsoft Agent"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Microsoft Agent]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Microsoft Agent]
"DisplayName"="Microsoft Agent"
"Description"="Enable Microsoft Agent Service."

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Microsoft Agent\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Microsoft Agent\Enum]

[HKEY_CURRENT_USER\Software\Microsoft\Microsoft Agent]

; End Of The Log...

Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.2.0

; Results at 19.01.2007 15:08:19 for strings:
; 'network windows service
network windows service
network windows service
network windows service
network windows service'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


; End Of The Log...

Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.2.0

; Results at 19.01.2007 15:09:34 for strings:
; 'algs'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Alg.AlgSetup]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Alg.AlgSetup\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Alg.AlgSetup.1]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Alg.AlgSetup.1\CLSID]

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27D0BCCC-344D-4287-AF37-0C72C161C14C}\ProgID]
@="Alg.AlgSetup.1"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{27D0BCCC-344D-4287-AF37-0C72C161C14C}\VersionIndependentProgID]
@="Alg.AlgSetup"

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{A779AF1A-009A-4C44-B9F0-8F0F4CF2AE49}]
@="IAlgSetup"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALGS]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALGS\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALGS\0000]
"Service"="algs"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\algs]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\algs\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\algs\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\algs\Enum]
"0"="Root\\LEGACY_ALGS\\0000"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALGS]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALGS\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALGS\0000]
"Service"="algs"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\algs]

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\algs\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALGS]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALGS\0000]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALGS\0000]
"Service"="algs"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\algs]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\algs\Security]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\algs\Enum]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\algs\Enum]
"0"="Root\\LEGACY_ALGS\\0000"

; End Of The Log...

Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.2.0

; Results at 19.01.2007 15:11:53 for strings:
; 'local network service'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALGS\0000]
"DeviceDesc"="Local Network Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\algs]
"DisplayName"="Local Network Service"
"Description"="Local Network Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALGS\0000]
"DeviceDesc"="Local Network Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\algs]
"DisplayName"="Local Network Service"
"Description"="Local Network Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALGS\0000]
"DeviceDesc"="Local Network Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\algs]
"DisplayName"="Local Network Service"
"Description"="Local Network Service"

; End Of The Log...

Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.2.0

; Results at 19.01.2007 15:11:53 for strings:
; 'local network service'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALGS\0000]
"DeviceDesc"="Local Network Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\algs]
"DisplayName"="Local Network Service"
"Description"="Local Network Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALGS\0000]
"DeviceDesc"="Local Network Service"

[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\algs]
"DisplayName"="Local Network Service"
"Description"="Local Network Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALGS\0000]
"DeviceDesc"="Local Network Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\algs]
"DisplayName"="Local Network Service"
"Description"="Local Network Service"

; End Of The Log...

Windows Registry Editor Version 5.00

; Registry Search 2.0 by Bobbi Flekman © 2005
; Version: 2.0.2.0

; Results at 19.01.2007 15:19:20 for strings:
; 'microsoft dll verifier'
; Strings excluded from search:
; (None)
; Search in:
; Registry Keys Registry Values Registry Data
; HKEY_LOCAL_MACHINE HKEY_USERS


[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft DLL Verifier"="system33.exe"

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Microsoft DLL Verifier"="system33.exe"

[HKEY_CURRENT_USER\Software\Microsoft\OLE]
"Microsoft DLL Verifier"="system33.exe"

; End Of The Log...

mfg Günter
Seitenanfang Seitenende
19.01.2007, 23:49
Ehrenmitglied
Avatar Sabina

Beiträge: 29434
#6 ««
Den folgenden Text in den Editor (Start - Zubehör - Editor) kopieren und als fixme.reg mit 'Speichern unter' auf dem Desktop. Gebe bei Dateityp 'Alle Dateien' an. Du solltest jetzt auf dem Desktop diese Datei finden. Die Datei "fixme.reg" auf dem Desktop doppelklicken und der Registry mit "ja" oder "yes" beifügen

Zitat

REGEDIT4

[-HKEY_CLASSES_ROOT\CLSID{EDFE42DB-520D-3376-A5C0-CF95929CCC70}]

[-HKEY_CLASSES_ROOT\CLSID{15CB33A0-12D1-0735-FA99-17F9128BA632}]

[-HKEY_CURRENT_USER\Software\Microsoft\Microsoft Agent]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Microsoft DLL Verifier"=-

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunServices]
"Microsoft DLL Verifier"=-

[HKEY_CURRENT_USER\Software\Microsoft\OLE]
"Microsoft DLL Verifier"=-

««
Avenger
http://virus-protect.org/artikel/tools/avenger.html
kopiere rein:

Zitat

registry keys to delete:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSWINDOWS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSWindows
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MSWINDOWS
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSWindows
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSWINDOWS
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSWindows
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MICROSOFT_AGENT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Microsoft Agent
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MICROSOFT_AGENT\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Microsoft Agent
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MICROSOFT_AGENT\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Microsoft Agent
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALGS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\algs
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALGS\0000
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\algs
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALGS\0000
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\algs

Files to delete:
C:\WINDOWS\System32\system33.exe
C:\WINDOWS\System32\urdvxc.exe
C:\WINDOWS\System32\.exe
C:\WINDOWS\System32\i
c:\windows\scvh0st.exe
c:\windows\system32\dllcache\ffchost.exe
C:\e.exe

Klicke die gruene Ampel
das Script wird nun ausgeführt, dann wird der PC automatisch neustarten

»»
poste hier das log vom avenger, was nach neustart erscheint

»»
scanne mit sophos (option 6 - und poste den scanreport)
http://virus-protect.org/artikel/tools/sdfix.html
__________
MfG Sabina

rund um die PC-Sicherheit
Seitenanfang Seitenende
22.01.2007, 16:03
...neu hier

Themenstarter

Beiträge: 9
#7 Hi Sabina!

Die logs:

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\tomhvtao

*******************

Script file located at: \??\C:\WINDOWS\acvogjpv.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MSWINDOWS deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\MSWindows deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MSWINDOWS deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\MSWindows deleted successfully.


Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSWINDOWS not found!
Deletion of registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSWINDOWS failed!

Could not process line:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MSWINDOWS
Status: 0xc0000034



Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSWindows not found!
Deletion of registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSWindows failed!

Could not process line:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\MSWindows
Status: 0xc0000034

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_MICROSOFT_AGENT\0000 deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Microsoft Agent deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_MICROSOFT_AGENT\0000 deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\Microsoft Agent deleted successfully.


Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MICROSOFT_AGENT\0000 not found!
Deletion of registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MICROSOFT_AGENT\0000 failed!

Could not process line:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_MICROSOFT_AGENT\0000
Status: 0xc0000034



Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Microsoft Agent not found!
Deletion of registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Microsoft Agent failed!

Could not process line:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Microsoft Agent
Status: 0xc0000034

Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_ALGS\0000 deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\algs deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Enum\Root\LEGACY_ALGS\0000 deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\algs deleted successfully.


Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALGS\0000 not found!
Deletion of registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALGS\0000 failed!

Could not process line:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_ALGS\0000
Status: 0xc0000034



Registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\algs not found!
Deletion of registry key HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\algs failed!

Could not process line:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\algs
Status: 0xc0000034

File C:\WINDOWS\System32\system33.exe deleted successfully.
File C:\WINDOWS\System32\urdvxc.exe deleted successfully.
File C:\WINDOWS\System32\.exe deleted successfully.
File C:\WINDOWS\System32\i deleted successfully.


File c:\windows\scvh0st.exe not found!
Deletion of file c:\windows\scvh0st.exe failed!

Could not process line:
c:\windows\scvh0st.exe
Status: 0xc0000034



File c:\windows\system32\dllcache\ffchost.exe not found!
Deletion of file c:\windows\system32\dllcache\ffchost.exe failed!

Could not process line:
c:\windows\system32\dllcache\ffchost.exe
Status: 0xc0000034

File C:\e.exe deleted successfully.

Completed script processing.

*******************

Finished! Terminate.

Sophos Anti-Virus
Version 4.13.0 [Win32/Intel]
Virus data version 4.13, January 2007
Includes detection for 209151 viruses, trojans and worms
Copyright (c) 1989-2007 Sophos Plc, www.sophos.com

System time 13:39:12, System date 22 January 2007
Command line qualifiers are: -f -remove -nc -nb --stop-scan

>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AntiVir PersonalEdition Classic\hrwlbrss.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Autodesk\AutoCAD 2005\R16.1\ADLM\xvjlhhbj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\rltwvknv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Anwendungsdaten\Sereniti\Active Security Monitor\ebzbhhet.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Anwendungsdaten\Sereniti\Active Security Monitor\hhbtbbnh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Eigene Dateien\TUG\International\bbkljwxk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Eigene Dateien\TUG\International\Buchungsbest„t_Ryanair2_files\rbxllebk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Eigene Dateien\TUG\International\lwlstnkj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Eigene Dateien\TUG\International\nlwstvwh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Eigene Dateien\TUG\International\qzjwkvjl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Eigene Dateien\TUG\International\rzzexnnz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Eigene Dateien\TUG\International\xlwbcttj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Eigene Dateien\TUG\Projekt Semtech\Berechnungen\Catia\lnetzerk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Lokale Einstellungen\Anwendungsdaten\Autodesk\AutoCAD 2005\R16.1\enu\Template\PTWTemplates\Template2\zjwnekkk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Lokale Einstellungen\Anwendungsdaten\Autodesk\AutoCAD 2005\R16.1\enu\Template\PTWTemplates\Template3\zjwnekkk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Lokale Einstellungen\Anwendungsdaten\Autodesk\AutoCAD 2005\R16.1\enu\Template\PTWTemplates\Template4\zjwnekkk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Lokale Einstellungen\Temporary Internet Files\Content.IE5\5BZ0NFJD\qvrszsek.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Lokale Einstellungen\Temporary Internet Files\Content.IE5\CI9DU92W\ernrbzjh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Lokale Einstellungen\Temporary Internet Files\Content.IE5\OR4N8HG3\bzqejnqt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Dokumente und Einstellungen\Gnter\Lokale Einstellungen\Temporary Internet Files\Content.IE5\R9J7HWUW\rbhzkrjb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\Common\profiler\enscxlzz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\Common\profiler\kslxjbes.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\Common\profiler\llbcjnev.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\Common\profiler\rejjqxsj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\Common\profiler\rhhtvhzh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\Common\profiler\swbbtvsj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\Common\profiler\tqeetsqk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\Common\profiler\xrbkznbb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\InterActual Player\weblinks\default\rxerthtj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\InterActual Player\weblinks\dvdplayer\ejznnjbv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\InterActual Player\weblinks\dvdplayer\hbezvkrz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\InterActual Player\weblinks\dvdplayer\jtjvxrrn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\InterActual Player\weblinks\dvdplayer\krkblrrx.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\InterActual Player\weblinks\dvdplayer\lvkzjhvk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\InterActual Player\weblinks\dvdplayer\snblntlq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Program Files\InterActual\InterActual Player\weblinks\nkhntexs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\bbjjhljs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\bbjrnwns.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\bcknvtrk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\bestrles.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\bjznnxcl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\blthhbnq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\bqljltjh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\bqtnjnnk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\bsvcecsb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\bwjjsbkn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\crbbtlen.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\cxvjessl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ebkrrbrz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ehrhxnbr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ehwcrehs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ejllhksl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ejxjvsnn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ekthssht.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ekzkjrxj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\enrktlke.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\eqtkksns.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ercsebrj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\etwerncb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\hbttvcns.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\hbverjet.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\hczqrzse.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\hjrnbsek.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\hkzbehjl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\hnlsrkqe.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\hsentwwb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\hvqllstj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\hvsjhkks.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\hzljxbhh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\jbrhbtrn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\jbrsbbbb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\jchjrtse.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\jnnrbbvs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\jrlrhekl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\jrsnwxhn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\jslbberh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\jsntkjxj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\knnjlbqh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\kstcrljl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\lhjclszt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\lhrjvkxb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\lhxbklbn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\lkknelvn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\lshbzlre.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\lszrrxwb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ltcrkltj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ltjllrzv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ltjqlbel.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\lvtktbvq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\lwrlwjkw.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\lxnvxqnk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\nbsjbvqn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\nbtbthrs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\nrecrsel.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\nskektlb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\nsnbjrhr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ntbzjhst.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ntlxtsrl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\nwbhsrwx.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\qbkqtqnr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\qhhvejtz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\qhkrwcex.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\qrektqtj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\rberlbnj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\rhcsqhkk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\rlbljhke.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\rltlsztb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\rwerbnxs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\shnnrvrv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\shtbshzk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\snkehxhr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\snrtzbbh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\srhjjzet.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ssbqsjsn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\sstsncrh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\ssttewzk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\swklebtl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\sxblbelh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\sxkkvnvl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\tenekewj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\thsbweev.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\tjekhwbb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\tksjcrjx.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\tnhezbrx.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\tnttcsse.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\tsksekkt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\tvnjxzkk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\twhhwezb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\tzceblth.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\tzejrkeq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\vkjjrwwq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\vlnxnnxk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\vscrbbwb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\vwsttlrt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\vxsszllj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\vxtkhkrj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\wbsltncr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\whjbnlcx.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\whknhkne.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\wkezknsj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\wltlrvre.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\wrshzkls.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\wtljlheq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\wzbbtnkh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\xblknjnz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\xjhhlkrj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\xlwlebhh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\xttwxwsh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\xwsecjqc.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\zsncwteh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\DEU\zweebexh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\bejrkewl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\bhlnvnwj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\bknlntcr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\bnlsbzhj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\brbjelkv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\brrlkjbs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\brwcnjej.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\bsktkllb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\bsrsrxqw.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\bsskrnrb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\btltezbr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\bxllbzev.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\bzbjeben.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\bzlhljcs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\bzllnlez.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\cktnvbjt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\cslzbjhw.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\cwshljtt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\czllnrtv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\czrbeten.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\ebhtwltl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\ehjnhqjn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\ehtjheqt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\ejbtlejc.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\ejrnctje.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\ekhxlcjk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\ekkwnvtt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\eqteclqn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hebhlrnx.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hebklqee.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hhvsccsh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hhzslnew.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hkklrbjl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hlhsznxr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hlrcqkek.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hqlrjsrr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hrnhrzzh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hskcebtt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hslvrhhb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hsschxel.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hvnejvrb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hzblerwn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\hzecstte.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\jbtskesk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\jbxzllzb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\jhshrhzk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\jjbclsnj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\jkllhlse.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\jlbsxbvs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\jrnwqqtt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\jzkbblnw.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\kjbrvcjh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\kjnkwbwq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\kjrkjxhz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\ktvvqtkc.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\ktwwbbks.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\kwhjlxvn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\kzlbnbhn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\lbkenttn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\lhcqhblb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\lnxtbbtl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\lsnenrbn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\nbsnrhht.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\nklvhcnb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\nlneswhx.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\nnhbjrjl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\ntbjtzvz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\ntnneele.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\nvrlbkre.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\nwncwbbs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\nxejzthj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\nzbllzbe.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\nztbllej.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\qeshvjhr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\qklkcnrj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\qrkcknwt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\qskkhnxx.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\qvskejrn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\rbhrcksr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\rbtwtkqh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\rbvrtsrb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\revbxhkv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\rhbslqzw.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\rhlbtcwh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\rjhesqne.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\rlbnkcjz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\rnrxrssj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\rrekqjkh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\rsssbhbl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\serswvnb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\sextwhwn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\sjnebkrc.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\skhrvjjq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\skkzehjv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\slxqkzxv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\snkjernh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\stjtvelk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\stzeqhkl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\sxsjzkrt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\tehkqncr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\tenjlvce.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\tjnlwhwj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\tkjshnnk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\tnncehsn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\tzvnjqnc.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\vbvexsrq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\vjbqlret.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\vtlbeqvv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\wblrshlb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\wsjhslkr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\wtknvhkn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\wxcbctkb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\xtjjrerw.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\xtjqnlle.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\ENU\ztlhhzxj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\belsjltk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\bhlejlhn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\bjzwbhhj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\bnknnsqz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\bsrcelbr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\bxknktbs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\ckrhzntq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\crskxbhz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\ctkrebes.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\cxbzjqbb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\eeteekkz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\enkzexcj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\eqjrhlnb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\esrbjhrs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\esstlchs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\evqcxlbh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\evqkcehz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\eweqbjte.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\hbjvrrqv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\hcsxrjnv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\hnbkewve.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\htesjrxb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\htqejxbt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\hzxhxesq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\hzxwkrzt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\jbjenljt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\jceqnxnq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\jlnbevnk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\jnrbknlb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\jqresnnb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\jqsrzlrb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\jrztssrb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\jwnnklbr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\kehwcrlc.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\kkjnnrnh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\kkxkswjj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\knbshqqb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\knrksjje.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\kqbtxrnz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\ktzhtbks.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\lecwejxl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\lhjstkzl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\lhqwehth.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\ljrsnhsr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\ljvvlnsl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\lkrctxrn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\lltrrnnj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\lrjkshvj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\ltjkwswb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\ltwlrlqr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\nbsrttvn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\nenkklrz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\nhbbbknz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\nhbqqbsn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\njbjvtrs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\njwnjnrj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\nqnblxtk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\nrwhenwj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\nsrxnhwt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\ntcbkets.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\nvsvbbbj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\qkhrszht.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\rbqhcxcn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\resxbrtb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\rhtbbzrk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\rqtjtbxn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\rrkwkxes.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\rthchzle.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\rtnrenxj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\rtvnqhnq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\sbkhqejl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\sjnvneeh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\slejeslw.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\sllhsknt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\sntbcesn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\srceelqb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\srhrnqnj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\srqlcech.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\stnnttnq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\swbvbwnh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\sxtjbshl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\szbltvbl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\szlwbrjl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\tbjkensr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\tbstjjhk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\tebcnsjb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\thklrnht.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\thkshkss.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\tjnhcejt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\tjxjttll.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\tknewjen.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\tltktqxz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\tsxjqknb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\ttnhjlte.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\txntjnsk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\txvbsnjj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\tzjnlstr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\tzntjrkk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\veslcczb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\vlwzeekx.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\vrjncwhr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\vstecesl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\whhxrcle.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\wjhbkben.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\wnnlskln.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\xcbnqlbh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\xekxxstc.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\xjshbktv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\xsrthjhv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\xvblxbrq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\xwlnxlqj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\xzhlslnr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\zhqsbkkb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\zlbrjqrb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\HowTo\FRA\zxksernr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\Acrobat\plug_ins\PictureTasks\HowTo\rzbwjsks.exe
Removal successful
Password protected file C:\Programme\Adobe\Acrobat 7.0\Acrobat\WebSearch\WebSearchENU.pdf
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\rbzezrtt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\vetrhvjc.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Adobe\Acrobat 7.0\zhnnrshz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Autodesk\Autodesk DWF Viewer\eplot\ekjnqtrk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Autodesk\Autodesk DWF Viewer\eplot\elhlqlxe.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Autodesk\Autodesk DWF Viewer\eplot\hzkqvsrh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Autodesk\Autodesk DWF Viewer\eplot\keenesse.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Autodesk\Autodesk DWF Viewer\eplot\rkswelvt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Autodesk\Autodesk DWF Viewer\eplot\srcsnkzr.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Autodesk\Autodesk DWF Viewer\eplot\tcnqshjz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Autodesk\Autodesk DWF Viewer\eplot\wrqzkert.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Autodesk\Autodesk DWF Viewer\eplot\zbhstszl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Autodesk\Autodesk DWF Viewer\knvexbvl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Adobe\Web\brrqnhcz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\beseltss.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\ebjtnqlh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\elsrhrhx.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\hrebxtrt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\hskwkjhj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\jjqncrcs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\knssljer.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\levehkhk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\ljbbknvw.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\ltnberke.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\nehzblkj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\nlxjsejk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\nnnlvnse.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\qzbrbzew.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\rnbxsnhh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\sjnhjbtw.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\slqhbqwh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\tbtjkhsw.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\tclrhtej.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\tqnbsrxb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\ttnxvnlz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\vhbzbnez.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\wjslljnj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\wnsnnvhe.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\wsltttve.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\Stationery\xntrcsxw.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\web server extensions\50\bin\1031\eljcsren.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\web server extensions\50\bin\jbncbbwt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Microsoft Shared\web server extensions\50\bin\tlexnjcj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\Real\Update_OB\UI\xbnsnljx.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Gemeinsame Dateien\System\ado\hcblqbtl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Java\j2re1.4.2_08\javaws\cjllzwkt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Java\j2re1.4.2_08\javaws\jjssblnn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Java\j2re1.4.2_08\javaws\krtelsxs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Java\j2re1.4.2_08\javaws\lqbskjks.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Java\j2re1.4.2_08\javaws\nbhehejt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Java\j2re1.4.2_08\javaws\qtljkltl.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Java\j2re1.4.2_08\javaws\slvtnhvh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Java\j2re1.4.2_08\javaws\tzjzcesk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Java\j2re1.4.2_08\nznnxtjn.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Java\jre1.5.0_03\cljhlsjb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\Java\jre1.5.0_09\krlsjkte.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\MSN\MSNCoreFiles\erserctk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\Programme\NetMeeting\bqcltnjh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\bzehxvnz.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\hwexrtne.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\jbnshhqj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\jjlenkbt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\blkkzrtt.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\cxjclkkc.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\ekwlsjzj.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\ewrlklcs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\hjhecvkh.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\klbvejnk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\knwbcncs.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\kxkzvszq.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\kzerbzks.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\kzkzkjkb.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\lbsbbjlx.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\lhhjrkjk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\lrhwxcwk.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\lwnssrtv.exe
Removal successful
>>> Virus 'Mal/Packer' found in file C:\WINDOWS\Help\Tours\htmlTour\njnrhctz.
Seitenanfang Seitenende
22.01.2007, 16:49
Ehrenmitglied
Avatar Sabina

Beiträge: 29434
#8 thunder2882

Information: Worm.Allaple
http://virus-protect.org/artikel/dienste/microsoftagent.html

------------------------------------------------------------

1.
Arbeitsplatz --> Rechtsklick, dann auf Eigenschaften --> Reiter Systemwiederherstellung --> Häkchen setzen bei Systemwiederherstellung auf allen Laufwerken deaktivieren.

2.
scanne und poste den scanreport
http://virus-protect.org/cureit.html
__________
MfG Sabina

rund um die PC-Sicherheit
Seitenanfang Seitenende
22.01.2007, 18:24
...neu hier

Themenstarter

Beiträge: 9
#9 Hi Sabina!

htpatch.exe c:\windows Tool.Htpatch

SopAdver.exe C:\Dokumente und Einstellungen\Günter\Anwendungsdaten\SopCast\adv Adware.Sopcast

wbk1B.tmp C:\Dokumente und Einstellungen\Günter\Lokale Einstellungen\Temporary Internet Files\Content.IE5\R9J7HWUW Trojan.Bankfraud.272 Gelöscht.

wbk9.tmp C:\Dokumente und Einstellungen\Günter\Lokale Einstellungen\Temporary Internet Files\Content.IE5\R9J7HWUW Trojan.Bankfraud.272 Gelöscht.

Process.exe C:\SDFix\apps Tool.Prockill

htpatch.exe C:\WINDOWS Tool.Htpatch


mfg Günter
Seitenanfang Seitenende
23.01.2007, 00:10
Ehrenmitglied
Avatar Sabina

Beiträge: 29434
#10 1.
Avenger kopiere rein

Zitat

Folders to delete:
C:\Dokumente und Einstellungen\%Username%\Anwendungsdaten\SopCast
C:\Dokumente und Einstellungen\%Username%\Lokale Einstellungen\Temporary Internet Files\Content.IE5\5BZ0NFJD
C:\Dokumente und Einstellungen\%Username%\Lokale Einstellungen\Temporary Internet Files\Content.IE5\R9J7HWUW
C:\Dokumente und Einstellungen\%Username%\Lokale Einstellungen\Temporary Internet Files\Content.IE5\OR4N8HG3
C:\Dokumente und Einstellungen\%Username%\Lokale Einstellungen\Temporary Internet Files\Content.IE5\CI9DU92W
2.
wende an:
F-Prot Antivirus for DOS
und ganz unten ist der link fuer
F-Secure Anti-Virustm for DOS - berichte (poste die scanreporte)
http://virus-protect.org/artikel/tools/fprot.html

3.
poste das neue log vom HijackThis, bitte

4.
poste dieses log
http://virus-protect.org/artikel/tools/combofix.html
__________
MfG Sabina

rund um die PC-Sicherheit
Seitenanfang Seitenende
23.01.2007, 15:46
...neu hier

Themenstarter

Beiträge: 9
#11 Hi Sabina!

Virus scanning report - 23 January 2007 @ 14:31

F-PROT ANTIVIRUS
Program version: 3.12d
Engine version: 3.12.8

VIRUS SIGNATURE FILES
SIGN.DEF created 20 January 2007
SIGN2.DEF created 21 January 2007
MACRO.DEF created 20 January 2007

Search: Local hard disks
Action: Report only
Files: Attempt to identify files
Switches: /NOFLOPPY
No viruses found in memory.
Hard disk boot sectors were not scanned.

Scanning C:
C:\PAGEFILE.SYS Not scanned (in use by another application)
Scanning D:
Scanning E:
Scanning L:

Results of virus scanning:

Files: 8524
MBRs: 0
Boot sectors: 0
Objects scanned: 6924

Time: 4:27

No viruses or suspicious files/boot sectors were found.




Logfile of HijackThis v1.99.1
Scan saved at 14:39:33, on 23.01.2007
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
D:\Programme\8Signs Firewall\DFW.exe
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\WINDOWS\System32\Ati2evxx.exe
D:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe
D:\Programme\Belkin\Belkin Wireless Network Utility\WLService.exe
C:\WINDOWS\System32\svchost.exe
D:\Programme\Belkin\Belkin Wireless Network Utility\WLanCfgG.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programme\Synaptics\SynTP\SynTPLpr.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\Java\jre1.5.0_09\bin\jusched.exe
C:\WINDOWS\System32\pctspk.exe
D:\Programme\OmniPageSE2.0\OpwareSE2.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
D:\Programme\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\WINDOWS\System32\ctfmon.exe
D:\Programme\Skype\Phone\Skype.exe
C:\Programme\MSN Messenger\MsnMsgr.Exe
D:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\Outlook Express\msimn.exe
C:\Programme\Messenger\msmsgs.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\NOTEPAD.EXE
E:\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.at/
R3 - URLSearchHook: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - D:\Programme\Spybot\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_09\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - D:\Programme\FlashFXP\IEFlash.dll
O3 - Toolbar: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar1.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - D:\Programme\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.5.0_09\bin\jusched.exe"
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb04.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [OpwareSE2] "D:\Programme\OmniPageSE2.0\OpwareSE2.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "D:\Programme\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKLM\..\Run: [ijjcujcc] C:\gulefver.bat
O4 - HKLM\..\RunServices: [Microsoft DLL Verifier] system33.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [Skype] "D:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Adobe Acrobat - Schnellstart.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: AutoCAD Startup Accelerator.lnk = C:\Programme\Gemeinsame Dateien\Autodesk Shared\acstart16.exe
O4 - Global Startup: Microsoft Office.lnk = D:\Programme\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google Search - res://C:\Programme\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Ausgewählte Verknüpfungen in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Ausgewählte Verknüpfungen in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Auswahl in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Auswahl in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Backward &Links - res://C:\Programme\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Programme\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Easy-WebPrint - Drucken - res://D:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - res://D:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint - Vorschau - res://D:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - res://D:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: In Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: In vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Programme\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Verknüpfungsziel in Adobe PDF konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Verknüpfungsziel in vorhandene PDF-Datei konvertieren - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_09\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_09\bin\ssv.dll
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://thunder2882.spaces.live.com//PhotoUpload/MsnPUpld.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1131142875467
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1131143534654
O16 - DPF: {B1953AD6-C50E-11D3-B020-00A0C9251384} (O2C-Player (ELECO Software GmbH)) - http://www.o2c.de/download/o2cplayer.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4D7B03FE-0A75-4A60-9CB9-34DEC4C2FDED}: NameServer = 192.168.2.1
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O23 - Service: 8Signs Firewall (8SignsFirewall) - 8Signs Ltd. - D:\Programme\8Signs Firewall\DFW.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Autodesk Licensing Service - Autodesk, Inc. - C:\Programme\Gemeinsame Dateien\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - D:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Belkin Wireless USB Network Adapter (Belkin Wireless USB Network Adapter Service) - Unknown owner - D:\Programme\Belkin\Belkin Wireless Network Utility\WLService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe



ComboFix 07-01-23.2 - Running from: "D:\Programme\Mozilla Firefox"

(((((((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))


C:\INSTALL.LOG


((((((((((((((((((((((((((((((( Files Created from 2006-12-23 to 2007-01-23 ))))))))))))))))))))))))))))))))))


2007-01-23 14:18 <DIR> d-------- C:\fprot
2007-01-23 14:10 60,416 --a------ C:\WINDOWS\system32\drivers\adffeeho.sys
2007-01-23 14:10 126,976 --a------ C:\zip.exe
2007-01-23 14:10 1,080 --a------ C:\gulefver.bat
2007-01-22 16:19 <DIR> d-------- C:\DOKUME~1\GNTER~1\DoctorWeb
2007-01-22 13:38 <DIR> d-------- C:\SAV32CLI
2007-01-22 13:33 <DIR> d-------- C:\SDFix
2007-01-22 13:28 <DIR> d-------- C:\avenger
2007-01-22 02:04 719,901 --a------ C:\SDFix.exe
2007-01-10 19:52 3,968 --a------ C:\WINDOWS\system32\drivers\AvgAsCln.sys
2007-01-09 23:11 <DIR> d-------- C:\DOKUME~1\ALLUSE~1\Anwendungsdaten\ScanSoft
2007-01-06 14:27 20,747 --a------ C:\WINDOWS\system32\drivers\AegisP.sys
2007-01-06 14:26 94,208 --a------ C:\WINDOWS\system32\GTW32N50.dll
2007-01-06 14:26 40,960 --a------ C:\WINDOWS\system32\B11gUSB.dll
2007-01-06 14:26 232,192 --a------ C:\WINDOWS\system32\drivers\rt73.sys
2007-01-06 14:26 15,872 --a------ C:\WINDOWS\system32\GTNDIS5.sys
2007-01-02 12:18 34,304 --a------ C:\WINDOWS\system32\drivers\avgntdd.sys
2007-01-02 12:18 14,848 --a------ C:\WINDOWS\system32\drivers\avgntmgr.sys
2007-01-02 12:18 <DIR> d-------- C:\Programme\AntiVir PersonalEdition Classic
2007-01-02 12:18 <DIR> d-------- C:\DOKUME~1\ALLUSE~1\Anwendungsdaten\AntiVir PersonalEdition Classic


(((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))))


2007-01-23 14:16 -------- d-------- C:\DOKUME~1\GNTER~1\Anwendungsdaten\skype
2006-12-20 17:47 -------- d-------- C:\Programme\Gemeinsame Dateien\is3
2006-12-08 13:22 -------- d-------- C:\DOKUME~1\GNTER~1\Anwendungsdaten\arcsoft
2006-12-02 11:09 -------- d---s---- C:\DOKUME~1\GNTER~1\Anwendungsdaten\microsoft
2006-11-28 00:53 89984 --a------ C:\WINDOWS\system32\drivers\sptd2349.sys
2006-11-27 17:37 -------- d-------- C:\DOKUME~1\GNTER~1\Anwendungsdaten\sereniti


(((((((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))

*Note* empty entries & legit default entries are not shown

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run]
"CTFMON.EXE"="C:\\WINDOWS\\System32\\ctfmon.exe"
"Skype"="\"D:\\Programme\\Skype\\Phone\\Skype.exe\" /nosplash /minimized"
"MsnMsgr"="\"C:\\Programme\\MSN Messenger\\MsnMsgr.Exe\" /background"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run]
"ATIModeChange"="Ati2mdxx.exe"
"ATIPTA"="C:\\Programme\\ATI Technologies\\ATI Control Panel\\atiptaxx.exe"
"SoundMan"="SOUNDMAN.EXE"
"SynTPLpr"="C:\\Programme\\Synaptics\\SynTP\\SynTPLpr.exe"
"SynTPEnh"="C:\\Programme\\Synaptics\\SynTP\\SynTPEnh.exe"
"SunJavaUpdateSched"="\"C:\\Programme\\Java\\jre1.5.0_09\\bin\\jusched.exe\""
"HPDJ Taskbar Utility"="C:\\WINDOWS\\System32\\spool\\drivers\\w32x86\\3\\hpztsb04.exe"
"PCTVOICE"="pctspk.exe"
"OpwareSE2"="\"D:\\Programme\\OmniPageSE2.0\\OpwareSE2.exe\""
"TkBellExe"="\"C:\\Programme\\Gemeinsame Dateien\\Real\\Update_OB\\realsched.exe\" -osboot"
"avgnt"="\"C:\\Programme\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min"
"!AVG Anti-Spyware"="\"D:\\Programme\\Grisoft\\AVG Anti-Spyware 7.5\\avgas.exe\" /minimized"
"ijjcujcc"="C:\\gulefver.bat"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI]
"Installed"="1"
"NoChange"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS]
"Installed"="1"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices]
"Microsoft DLL Verifier"="system33.exe"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run-]
"Acrobat Assistant 7.0"="\"C:\\Programme\\Adobe\\Acrobat 7.0\\Distillr\\Acrotray.exe\""
"QuickTime Task"="\"D:\\Programme\\QuickTime\\qttask.exe\" -atboottime"
"NeroFilterCheck"="C:\\WINDOWS\\system32\\NeroCheck.exe"
"RemoteControl"="D:\\Programme\\PowerDVD\\PDVDServ.exe"
"WinampAgent"="D:\\Programme\\Winamp\\winampa.exe"
"TkBellExe"="\"C:\\Programme\\Gemeinsame Dateien\\Real\\Update_OB\\realsched.exe\" -osboot"

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks]
"{57B86673-276A-48B2-BAE7-C6DBB3020EB8}"="AVG Anti-Spyware 7.5"

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders]
"SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll"


[HKEY_LOCAL_MACHINE\software\Microsoft\Windows NT\CurrentVersion\Svchost]
LocalService REG_MULTI_SZ Alerter\0WebClient\0LmHosts\0RemoteRegistry\0upnphost\0SSDPSRV\0\0
NetworkService REG_MULTI_SZ DnsCache\0\0
rpcss REG_MULTI_SZ RpcSs\0\0
imgsvc REG_MULTI_SZ StiSvc\0\0
termsvcs REG_MULTI_SZ TermService\0\0
Usnsvc REG_MULTI_SZ usnsvc\0\0


Completion time: 07-01-23 14:44:05


Lg Günter
Seitenanfang Seitenende
23.01.2007, 16:17
Ehrenmitglied
Avatar Sabina

Beiträge: 29434
#12 thunder2882

öffne das HijackThis -- Button "scan" -- vor diese Einträge Häkchen setzen -- Button "Fix checked" -- PC neustarten

Zitat

R3 - URLSearchHook: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)

O3 - Toolbar: (no name) - {01E69986-A054-4C52-ABE8-EF63DF1C5211} - (no file)

O4 - HKLM\..\Run: [ijjcujcc] C:\gulefver.bat

O4 - HKLM\..\RunServices: [Microsoft DLL Verifier] system33.exe
PC neustarten

»»
denke ernsthaft ueber die windowsupdates nach - dein Rechner ist voellig ungeschuetzt .
__________
MfG Sabina

rund um die PC-Sicherheit
Seitenanfang Seitenende
23.01.2007, 19:04
...neu hier

Themenstarter

Beiträge: 9
#13 Hi Sabina!

Hast du eine Ahnung, wie ich die Windows CD-Key Abfrage übergehen kann bzw. gibts eine andere Möglichkeit Windows Updates zu machen?

Lg Günter
Seitenanfang Seitenende
24.01.2007, 00:45
Ehrenmitglied
Avatar Sabina

Beiträge: 29434
#14 thunder2882

nein, ich weiss es nicht im moment und wenn ich es wuesste, wuerde ich es ganz bestimmt nicht in einem Sicherheitsforum schreiben, dass mit MS zusammenarbeitet.
was solls - es sind ca. 80 Euronen fuer eine XP-Home-Version....

______

««
http://virus-protect.org/artikel/tools/sdfix.html
boote in den abgesicherten Modus (die Taste F8 drücken, während der Rechner neustartet)

gehe in den Ordner C:\SDFix

RunThis.bat doppelt klicken

schreibe: Y

folge allen Anweisungen, während gescannt wird - dann wird der Rechner neustarten
kopiere mit der rechten Maustaste den Text ab, der erscheint - und in den Beitrag
__________
MfG Sabina

rund um die PC-Sicherheit
Seitenanfang Seitenende
24.01.2007, 13:01
...neu hier

Themenstarter

Beiträge: 9
#15 Hi Sabina!

Der log:

SDFix: Version 1.61

24.01.2007 - 11:51:50,68

Microsoft Windows XP [Version 5.1.2600]

Running From: C:\SDFix

Safe Mode:
Checking Services:

Name:

Path:


Restoring Windows Registry Entries
Restoring Default Hosts File


Rebooting...

Normal Mode:
Checking Files:

No Files Found..




Alternate Streams Check:

C:\WINDOWS\system32
No streams found.

Final Check:

Remaining Services:
------------------


Authorized Application Key Export:

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"D:\\Programme\\PPMate\\PPMate\\ppmate.exe"="D:\\Programme\\PPMate\\PPMate\\ppmate.exe:*:Enabled:pPMate"


Remaining Files:
---------------

Backups Folder: - C:\SDFix\backups\backups.zip


Checking For Files with Hidden Attributes :

C:\NTDETECT.COM
C:\Programme\Autodesk\Autodesk DWF Viewer\_Setupx.dll
C:\Programme\Canon\MP Navigator 2.0\uinstrsc.dll
C:\Programme\Autodesk\Autodesk DWF Viewer\Setup.exe
C:\Programme\Canon\MP Navigator 2.0\Maint.exe
C:\WINDOWS\system32\cdplayer.exe.manifest
C:\WINDOWS\system32\logonui.exe.manifest
C:\IO.SYS
C:\MSDOS.SYS
C:\pagefile.sys
C:\WINDOWS\system32\0B6C309389.sys
C:\Dokumente und Einstellungen\Gnter\Anwendungsdaten\Microsoft\Word\~WRL3994.tmp
C:\Dokumente und Einstellungen\Gnter\Eigene Dateien\TUG\KonstrProj\~WRL2097.tmp
C:\Dokumente und Einstellungen\Gnter\Eigene Dateien\TUG\MOSS4\~WRL3405.tmp
C:\Dokumente und Einstellungen\Gnter\Eigene Dateien\TUG\Projekt Semtech\Doku\~WRL0005.tmp
C:\WINDOWS\LastGood.Tmp\INF\oem23.inf
C:\WINDOWS\LastGood.Tmp\INF\oem23.PNF
C:\WINDOWS\LastGood.Tmp\INF\oem24.inf
C:\WINDOWS\LastGood.Tmp\INF\oem24.PNF
C:\WINDOWS\LastGood.Tmp\INF\oem25.inf
C:\WINDOWS\LastGood.Tmp\INF\oem25.PNF
C:\WINDOWS\LastGood.Tmp\INF\oem26.inf
C:\WINDOWS\LastGood.Tmp\INF\oem26.PNF

Finished

mfg Günter
PS: Sorry,war eine blöde Frage (ignore).
Seitenanfang Seitenende