wie kann ich den tr/monder.346624 tr/monder.92160 tr/vundo.esd.1 löschen |
||
---|---|---|
#0
| ||
11.06.2008, 01:14
...neu hier
Beiträge: 1 |
||
|
||
11.06.2008, 01:27
Moderator
Beiträge: 5694 |
||
|
ich bräuchte dringend hilfe weil ich es mit einem TR/Monder.346624, TR/Monder.92160 und einem TR/Vundo.esd.1 Virus zu tun habe welche sich nicht löschen lassen.die taskleiste meines pc´s verschwindet oft und zugang zum internet gibt es auch nur noch abundzu - die geschwingikeit des pc´s ist auch nicht mehr so wie es mal war
ich wäre sehr sehr dankbar wenn mir jemand damit helfen könnte
hier ist der text vom 09.06.08
[06/09/2008, 4:42:34] - VirtumundoBeGone v1.5 ( "C:\VirtumundoBeGone.exe" )
[06/09/2008, 4:43:12] - Detected System Information:
[06/09/2008, 4:43:12] - Windows Version: 5.1.2600, Service Pack 2
[06/09/2008, 4:43:12] - Current Username: Oye (Admin)
[06/09/2008, 4:43:12] - Windows is in NORMAL mode.
[06/09/2008, 4:43:12] - Searching for Browser Helper Objects:
[06/09/2008, 4:43:12] - BHO 1: {0D9AEF30-1FF3-4965-9FFE-D654F1AD7C86} ()
[06/09/2008, 4:43:12] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 4:43:13] - Checking for HKLM\...\Winlogon\Notify\tuvUMeDU
[06/09/2008, 4:43:13] - Key not found: HKLM\...\Winlogon\Notify\tuvUMeDU, continuing.
[06/09/2008, 4:43:13] - BHO 2: {32341E7E-C319-46DE-91D0-E30BB1A3CABA} ()
[06/09/2008, 4:43:13] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 4:43:13] - Checking for HKLM\...\Winlogon\Notify\vtUmMddA
[06/09/2008, 4:43:13] - Found: HKLM\...\Winlogon\Notify\vtUmMddA - This is probably Virtumundo.
[06/09/2008, 4:43:13] - Assigning {32341E7E-C319-46DE-91D0-E30BB1A3CABA} MSEvents Object
[06/09/2008, 4:43:13] - BHO list has been changed! Starting over...
[06/09/2008, 4:43:14] - BHO 1: {0D9AEF30-1FF3-4965-9FFE-D654F1AD7C86} ()
[06/09/2008, 4:43:14] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 4:43:14] - Checking for HKLM\...\Winlogon\Notify\tuvUMeDU
[06/09/2008, 4:43:14] - Key not found: HKLM\...\Winlogon\Notify\tuvUMeDU, continuing.
[06/09/2008, 4:43:14] - BHO 2: {32341E7E-C319-46DE-91D0-E30BB1A3CABA} (MSEvents Object)
[06/09/2008, 4:43:14] - ALERT: Found MSEvents Object!
[06/09/2008, 4:43:14] - BHO 3: {53707962-6F74-2D53-2644-206D7942484F} ()
[06/09/2008, 4:43:14] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 4:43:14] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[06/09/2008, 4:43:14] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[06/09/2008, 4:43:14] - BHO 4: {7B32571A-7291-4874-B213-BD72F89DA3BA} ()
[06/09/2008, 4:43:14] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 4:43:14] - Checking for HKLM\...\Winlogon\Notify\rqRHbBTl
[06/09/2008, 4:43:14] - Key not found: HKLM\...\Winlogon\Notify\rqRHbBTl, continuing.
[06/09/2008, 4:43:14] - BHO 5: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[06/09/2008, 4:43:14] - BHO 6: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[06/09/2008, 4:43:15] - BHO 7: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[06/09/2008, 4:43:15] - BHO 8: {fe9a5bb8-9bec-4e34-8382-c7be1679634f} ()
[06/09/2008, 4:43:15] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 4:43:15] - Checking for HKLM\...\Winlogon\Notify\nyyndptd
[06/09/2008, 4:43:15] - Key not found: HKLM\...\Winlogon\Notify\nyyndptd, continuing.
[06/09/2008, 4:43:15] - Finished Searching Browser Helper Objects
[06/09/2008, 4:43:15] - *** Detected MSEvents Object
[06/09/2008, 4:43:15] - Trying to remove MSEvents Object...
[06/09/2008, 4:43:16] - Terminating Process: IEXPLORE.EXE
[06/09/2008, 4:43:18] - Terminating Process: RUNDLL32.EXE
[06/09/2008, 4:43:21] - Disabling Automatic Shell Restart
[06/09/2008, 4:43:22] - Terminating Process: EXPLORER.EXE
[06/09/2008, 4:43:24] - Suspending the NT Session Manager System Service
[06/09/2008, 4:43:25] - Terminating Windows NT Logon/Logoff Manager
[06/09/2008, 4:48:29] - Re-enabling Automatic Shell Restart
[06/09/2008, 4:48:30] - File to disable: C:\WINDOWS\system32\vtUmMddA.dll
[06/09/2008, 4:48:30] - Renaming C:\WINDOWS\system32\vtUmMddA.dll -> C:\WINDOWS\system32\vtUmMddA.dll.vir
[06/09/2008, 4:48:31] - ! File rename was unsucessful.
[06/09/2008, 4:48:32] - Attempting to Deny Access to C:\WINDOWS\system32\vtUmMddA.dll
[06/09/2008, 4:48:33] - *** IMPORTANT: Delete/Rename/Move on reboot (like Killbox) MAY NOT work.
[06/09/2008, 4:48:33] - ERROR: Zuordnungen von Kontennamen und Sicherheitskennungen wurden nicht durchgeführt.
[06/09/2008, 4:48:33] - *** IMPORTANT: The file is disabled and will need to be deleted by the user.
[06/09/2008, 4:48:33] - Removing HKLM\...\Browser Helper Objects\{32341E7E-C319-46DE-91D0-E30BB1A3CABA}
[06/09/2008, 4:48:33] - Removing HKCR\CLSID\{32341E7E-C319-46DE-91D0-E30BB1A3CABA}
[06/09/2008, 4:48:34] - Adding Kill Bit for ActiveX for GUID: {32341E7E-C319-46DE-91D0-E30BB1A3CABA}
[06/09/2008, 4:48:34] - Deleting ATLEvents/MSEvents Registry entries
[06/09/2008, 4:48:34] - Removing HKLM\...\Winlogon\Notify\vtUmMddA
[06/09/2008, 4:48:34] - Searching for Browser Helper Objects:
[06/09/2008, 4:48:34] - BHO 1: {0D9AEF30-1FF3-4965-9FFE-D654F1AD7C86} ()
[06/09/2008, 4:48:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 4:48:35] - Checking for HKLM\...\Winlogon\Notify\tuvUMeDU
[06/09/2008, 4:48:35] - Key not found: HKLM\...\Winlogon\Notify\tuvUMeDU, continuing.
[06/09/2008, 4:48:35] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[06/09/2008, 4:48:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 4:48:35] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[06/09/2008, 4:48:35] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[06/09/2008, 4:48:35] - BHO 3: {7B32571A-7291-4874-B213-BD72F89DA3BA} ()
[06/09/2008, 4:48:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 4:48:35] - Checking for HKLM\...\Winlogon\Notify\rqRHbBTl
[06/09/2008, 4:48:35] - Key not found: HKLM\...\Winlogon\Notify\rqRHbBTl, continuing.
[06/09/2008, 4:48:35] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[06/09/2008, 4:48:35] - BHO 5: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[06/09/2008, 4:48:35] - BHO 6: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[06/09/2008, 4:48:35] - BHO 7: {fe9a5bb8-9bec-4e34-8382-c7be1679634f} ()
[06/09/2008, 4:48:35] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 4:48:35] - Checking for HKLM\...\Winlogon\Notify\nyyndptd
[06/09/2008, 4:48:35] - Key not found: HKLM\...\Winlogon\Notify\nyyndptd, continuing.
[06/09/2008, 4:48:35] - Finished Searching Browser Helper Objects
[06/09/2008, 4:48:35] - Finishing up...
[06/09/2008, 4:48:35] - A restart is needed.
[06/09/2008, 4:49:13] - Attempting to Restart via STOP error (Blue Screen!)
[06/09/2008, 5:28:44] - VirtumundoBeGone v1.5 ( "C:\VirtumundoBeGone.exe" )
[06/09/2008, 5:28:47] - Detected System Information:
[06/09/2008, 5:28:47] - Windows Version: 5.1.2600, Service Pack 2
[06/09/2008, 5:28:47] - Current Username: Oye (Admin)
[06/09/2008, 5:28:47] - Windows is in NORMAL mode.
[06/09/2008, 5:28:47] - Searching for Browser Helper Objects:
[06/09/2008, 5:28:47] - BHO 1: {3F32C300-C44F-4A60-AEFC-AD442DE82447} ()
[06/09/2008, 5:28:47] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 5:28:47] - Checking for HKLM\...\Winlogon\Notify\tuvUMeDU
[06/09/2008, 5:28:47] - Key not found: HKLM\...\Winlogon\Notify\tuvUMeDU, continuing.
[06/09/2008, 5:28:47] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[06/09/2008, 5:28:47] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 5:28:47] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[06/09/2008, 5:28:47] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[06/09/2008, 5:28:47] - BHO 3: {7B32571A-7291-4874-B213-BD72F89DA3BA} ()
[06/09/2008, 5:28:47] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 5:28:47] - Checking for HKLM\...\Winlogon\Notify\rqRHbBTl
[06/09/2008, 5:28:47] - Key not found: HKLM\...\Winlogon\Notify\rqRHbBTl, continuing.
[06/09/2008, 5:28:47] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[06/09/2008, 5:28:47] - BHO 5: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[06/09/2008, 5:28:47] - BHO 6: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[06/09/2008, 5:28:47] - BHO 7: {fe9a5bb8-9bec-4e34-8382-c7be1679634f} ()
[06/09/2008, 5:28:47] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/09/2008, 5:28:47] - Checking for HKLM\...\Winlogon\Notify\nyyndptd
[06/09/2008, 5:28:47] - Key not found: HKLM\...\Winlogon\Notify\nyyndptd, continuing.
[06/09/2008, 5:28:47] - Finished Searching Browser Helper Objects
[06/09/2008, 5:28:47] - Finishing up...
[06/09/2008, 5:28:47] - Nothing found! Exiting...
[06/10/2008, 20:14:14] - VirtumundoBeGone v1.5 ( "C:\VirtumundoBeGone.exe" )
[06/10/2008, 20:14:43] - Detected System Information:
[06/10/2008, 20:14:43] - Windows Version: 5.1.2600, Service Pack 2
[06/10/2008, 20:14:43] - Current Username: Oye (Admin)
[06/10/2008, 20:14:43] - Windows is in NORMAL mode.
[06/10/2008, 20:14:43] - Searching for Browser Helper Objects:
[06/10/2008, 20:14:43] - BHO 1: {329A8BA3-21DA-485C-BDFF-EF824EB0E1D7} ()
[06/10/2008, 20:14:43] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/10/2008, 20:14:43] - Checking for HKLM\...\Winlogon\Notify\tuvUMeDU
[06/10/2008, 20:14:43] - Key not found: HKLM\...\Winlogon\Notify\tuvUMeDU, continuing.
[06/10/2008, 20:14:43] - BHO 2: {53707962-6F74-2D53-2644-206D7942484F} ()
[06/10/2008, 20:14:43] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/10/2008, 20:14:43] - Checking for HKLM\...\Winlogon\Notify\SDHelper
[06/10/2008, 20:14:43] - Key not found: HKLM\...\Winlogon\Notify\SDHelper, continuing.
[06/10/2008, 20:14:43] - BHO 3: {7B32571A-7291-4874-B213-BD72F89DA3BA} ()
[06/10/2008, 20:14:43] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/10/2008, 20:14:43] - Checking for HKLM\...\Winlogon\Notify\rqRHbBTl
[06/10/2008, 20:14:43] - Key not found: HKLM\...\Winlogon\Notify\rqRHbBTl, continuing.
[06/10/2008, 20:14:43] - BHO 4: {9030D464-4C02-4ABF-8ECC-5164760863C6} (Windows Live Sign-in Helper)
[06/10/2008, 20:14:43] - BHO 5: {AA58ED58-01DD-4d91-8333-CF10577473F7} (Google Toolbar Helper)
[06/10/2008, 20:14:43] - BHO 6: {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} (Google Toolbar Notifier BHO)
[06/10/2008, 20:14:43] - BHO 7: {fe9a5bb8-9bec-4e34-8382-c7be1679634f} ()
[06/10/2008, 20:14:43] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/10/2008, 20:14:43] - Checking for HKLM\...\Winlogon\Notify\nyyndptd
[06/10/2008, 20:14:43] - Key not found: HKLM\...\Winlogon\Notify\nyyndptd, continuing.
[06/10/2008, 20:14:43] - Finished Searching Browser Helper Objects
[06/10/2008, 20:14:44] - Finishing up...
[06/10/2008, 20:14:44] - Nothing found! Exiting...