Ok, also hier ist dann glaub ich alles:
Sun Jan 15 22:30:29 2006 => File C:\WINDOWS\System32\mqexdlm.srg tagged as not-a-virus:AdWare.Win32.BargainBuddy.q. No Action Taken.
Sun Jan 15 22:33:24 2006 => File C:\Dokumente und Einstellungen\Administrator\Eigene Dateien\BSINSTALLDE.exe tagged as not-a-virus:AdWare.Win32.SaveNow.bo. No Action Taken.
Sun Jan 15 22:40:34 2006 => File C:\mc-110-12-0000181.exe tagged as not-a-virus:AdWare.Win32.Maxifiles.u. No Action Taken.
Sun Jan 15 22:43:22 2006 => File C:\Programme\BearShare\Installer\BSINSTALLDE.exe tagged as not-a-virus:AdWare.Win32.SaveNow.bo. No Action Taken.
Sun Jan 15 22:43:52 2006 => File C:\Programme\Gemeinsame Dateien\Download\freeprodtb.exe tagged as not-a-virus:AdWare.Win32.Maxifiles.u. No Action Taken.
Sun Jan 15 22:43:53 2006 => File C:\Programme\Gemeinsame Dateien\Download\mc-110-12-0000181.exe tagged as not-a-virus:AdWare.Win32.Maxifiles.u. No Action Taken.
Sun Jan 15 22:43:53 2006 => File C:\Programme\Gemeinsame Dateien\Download\mc-110-12-0000182.exe tagged as not-a-virus:AdWare.Win32.Maxifiles.u. No Action Taken.
Sun Jan 15 22:44:28 2006 => File C:\Programme\Gemeinsame Dateien\Windows\services32.exe tagged as not-a-virus:AdWare.Win32.Maxifiles.h. No Action Taken.
Sun Jan 15 22:45:46 2006 => File C:\Programme\Save\Save.exe tagged as not-a-virus:AdWare.Win32.SaveNow.bv. No Action Taken.
Sun Jan 15 22:45:47 2006 => File C:\Programme\Save\SaveUninst.exe tagged as not-a-virus:AdWare.Win32.SaveNow.bt. No Action Taken.
Sun Jan 15 23:00:47 2006 => File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KBC12V2F\mc-110-12-0000182[1].exe tagged as not-a-virus:AdWare.Win32.Maxifiles.u. No Action Taken.
Sun Jan 15 23:10:25 2006 => File C:\WINDOWS\system32\mqexdlm.srg tagged as not-a-virus:AdWare.Win32.BargainBuddy.q. No Action Taken.
Sun Jan 15 23:27:42 2006 => File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KBC12V2F\mc-110-12-0000181[2].exe tagged as not-a-virus:AdWare.Win32.Maxifiles.u. No Action Taken.
Sun Jan 15 23:27:43 2006 => File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KBC12V2F\mc-110-12-0000182[1].exe tagged as not-a-virus:AdWare.Win32.Maxifiles.u. No Action Taken.
Sun Jan 15 23:37:19 2006 => File C:\WINDOWS\system32\mqexdlm.srg tagged as not-a-virus:AdWare.Win32.BargainBuddy.q. No Action Taken.
Sun Jan 15 22:28:10 2006 => *** SOFTWARE\Microsoft\Windows\CurrentVersion\Run has RunningProcess defined as C:\WINDOWS\system32\ccApp.exe (which is infected)!
Sun Jan 15 22:28:10 2006 => *** Reg Value
SOFTWARE\Microsoft\Windows\CurrentVersion\Run\Service deleted because it is infected by a Virus
Sun Jan 15 22:28:14 2006 => File C:\PROGRA~1\GEMEIN~1\Windows\MC-110~1.EXE infected by "Trojan-Dropper.Win32.Agent.aac" Virus. Action Taken: File Deleted.
Sun Jan 15 22:28:30 2006 => File C:\WINDOWS\system32\shell32.exe infected by "Backdoor.Win32.Aimbot.bo" Virus. Action Taken: File Renamed.
Sun Jan 15 22:28:30 2006 => *** SYSTEM\CurrentControlSet\Services\Shell32Extender has RunningProcess defined as C:\WINDOWS\system32\shell32.exe (which is infected)!
Sun Jan 15 22:28:30 2006 => *** Reg Value SYSTEM\CurrentControlSet\Services\Shell32Extender\ImagePath deleted because it is infected by a Virus
Sun Jan 15 22:28:31 2006 => *** Reg Key SYSTEM\CurrentControlSet\Services\Shell32Extender deleted because ImagePath file infected by a Virus
Sun Jan 15 22:29:51 2006 => File C:\WINDOWS\System32\i infected by "Trojan-Downloader.BAT.Ftp.ab" Virus. Action Taken: File Deleted.
Sun Jan 15 22:32:42 2006 => File C:\alg.exe infected by "Trojan.Win32.LowZones.bb" Virus. Action Taken: File Deleted.
Sun Jan 15 22:40:34 2006 => File C:\msdcom.exe infected by "Trojan.Win32.LowZones.be" Virus. Action Taken: File Deleted.
Sun Jan 15 22:40:34 2006 => File C:\msvc32.exe infected by "Trojan.Win32.LowZones.bh" Virus. Action Taken: File Deleted.
Sun Jan 15 22:43:03 2006 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.*
Sun Jan 15 22:43:03 2006 => Scanning File C:\Programme\AVPersonal\INFECTED\aim.VIR
Sun Jan 15 22:43:04 2006 => File C:\Programme\AVPersonal\INFECTED\aim.VIR infected by "Backdoor.Win32.Rbot.aeu" Virus. Action Taken: File Renamed.
Sun Jan 15 22:43:04 2006 => Scanning File C:\Programme\AVPersonal\INFECTED\aim.VIR00
Sun Jan 15 22:43:06 2006 => File C:\Programme\AVPersonal\INFECTED\aim.VIR00 infected by "Backdoor.Win32.Rbot.aeu" Virus. Action Taken: File Renamed.
Sun Jan 15 22:43:54 2006 => File C:\Programme\Gemeinsame Dateien\InetGet\mc-110-12-0000181.exe infected by "Trojan-Dropper.Win32.Agent.aac" Virus. Action Taken: File Deleted.
Sun Jan 15 22:43:55 2006 => File C:\Programme\Gemeinsame Dateien\InetGet\mc-110-12-0000182.exe infected by "Trojan-Dropper.Win32.Agent.aac" Virus. Action Taken: File Deleted.
Sun Jan 15 22:44:28 2006 => File C:\Programme\Gemeinsame Dateien\Windows\mc-110-12-0000181.exe infected by "Trojan-Dropper.Win32.Agent.aac" Virus. Action Taken: File Deleted.
Sun Jan 15 23:00:45 2006 => File C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\ABEN016H\director_install[5].exe infected by "Trojan-Dropper.Win32.Agent.aac" Virus. Action Taken: File Deleted.
Sun Jan 15 23:41:26 2006 => ***** Scanning complete. *****
Sun Jan 15 23:41:26 2006 => Total Number of Files Scanned: 28578
Sun Jan 15 23:41:26 2006 => Total Number of Virus(es) Found: 29
Sun Jan 15 23:41:26 2006 => Total Number of Disinfected Files: 0
Sun Jan 15 23:41:26 2006 => Total Number of Files Renamed: 4
Sun Jan 15 23:41:26 2006 => Total Number of Deleted Files: 9
Sun Jan 15 23:41:26 2006 => Total Number of Errors: 3
Sun Jan 15 23:41:26 2006 => Time Elapsed: 01:13:05
Sun Jan 15 23:41:26 2006 => Virus Database Date: 2006/01/15
Sun Jan 15 23:41:26 2006 => Virus Database Count: 171499
Sun Jan 15 23:41:26 2006 => Scan Completed.
Mein neues Logfile:
Code:
Logfile of HijackThis v1.99.1
Scan saved at 13:16:52, on 16.01.2006
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2600.0000)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\iTunes\iTunesHelper.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\BearShare\BearShare.exe
C:\Programme\Network\network.exe
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\MSN Messenger\MsnMsgr.Exe
C:\Programme\Microsoft Office\Office\FINDFAST.EXE
C:\Programme\Microsoft Office\Office\OSA.EXE
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\System32\svchost.exe
C:\Programme\iPod\bin\iPodService.exe
C:\WINDOWS\ISW\netcol.dsl\signup\Tray.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\WINDOWS\explorer.exe
C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temp\Temporäres Verzeichnis 1 für hijackthis_199.zip\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.internetcologne.de/
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [iTunesHelper] C:\Programme\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinDSL MTU-Adjust] WinDSL_MTU.exe
O4 - HKLM\..\Run: [messenger] aim.exe
O4 - HKLM\..\Run: [BearShare] "C:\Programme\BearShare\BearShare.exe" /pause
O4 - HKLM\..\Run: [Network] C:\Programme\Network\network.exe
O4 - HKLM\..\RunServices: [messenger] aim.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background
O4 - Global Startup: Microsoft-Indexerstellung.lnk = C:\Programme\Microsoft Office\Office\FINDFAST.EXE
O4 - Global Startup: Office-Start.lnk = C:\Programme\Microsoft Office\Office\OSA.EXE
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C99373E8-2084-480B-940F-73E327FC8666}: NameServer = 213.168.112.60 81.173.194.68
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe