PDA

View Full Version : Hijack.this-log



newbie6413
2007-04-24, 00:20
I already posted my log file on hijack.this-forum...
unfortuantely after they told me everything seemed ok i finally still found Zlob.trojan-downloader on my computer with a different.
and spybot did not find it. g-data standalone remover finally found it... now i wonder if there is more...

maybe you guys can have another look?
thx
fabs

Logfile of HijackThis v1.99.1
Scan saved at 02:56:12, on 16.04.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5700.0007)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Ahead\InCD\InCDsrv.exe
C:\Programme\Sygate\SPF\smc.exe
C:\WINDOWS\system32\spoolsv.exe
c:\programme\gemeinsame dateien\logitech\lvmvfm\LVPrcSrv.exe
C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
C:\Programme\Alwil Software\Avast4\ashServ.exe
C:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe
C:\Programme\Cisco Systems\VPN Client\cvpnd.exe
C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
C:\Programme\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\snmp.exe
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Alwil Software\Avast4\ashMaiSv.exe
C:\Programme\Alwil Software\Avast4\ashWebSv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\Rundll32.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\Synaptics\SynTP\SynTPLpr.exe
C:\WINDOWS\system32\keyhook.exe
E:\weitere programme\regprot\regprot.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Programme\Java\jre1.5.0_06\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\iFinger\iFinger.exe
C:\Programme\eMule\emule.exe
C:\Programme\Grisoft\AVG Anti-Spyware 7.5\avgas.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Dokumente und Einstellungen\Fabs\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.ffaabbiiaann.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=54729
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=55245&clcid={SUB_CLCID}
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: iFinger - {1624F640-49AC-11D3-8ABD-00C04FA95EE0} - C:\Programme\iFinger\iFingerBHO.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SiSPower] Rundll32.exe SiSPower.dll,ModeAgent
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SiS Windows KeyHook] C:\WINDOWS\system32\keyhook.exe
O4 - HKLM\..\Run: [RegProt] e:\weitere programme\regprot\regprot.exe /start
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SmcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_06\bin\jusched.exe
O4 - HKLM\..\Run: [!AVG Anti-Spyware] "C:\Programme\Grisoft\AVG Anti-Spyware 7.5\avgas.exe" /minimized
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Cisco Systems VPN Client.lnk = C:\Programme\Cisco Systems\VPN Client\vpngui.exe
O4 - Global Startup: iFinger.lnk = C:\Programme\iFinger\iFinger.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert to existing PDF - res://C:\Programme\Adobe\Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Easy-WebPrint - Drucken - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint - Vorschau - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Run WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra 'Tools' menuitem: Launch WinHTTrack - {36ECAF82-3300-8F84-092E-AFF36D6C7040} - C:\Programme\WinHTTrack\WinHTTrackIEBar.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: iFinger - {936E5D60-596C-11D3-BB96-00600816DF55} - C:\WINDOWS\system32\SHDOCVW.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O11 - Options group: [INTERNATIONAL] International*
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF987D75-8371-4F91-845C-C09202A85D44}: NameServer = 80.58.61.250,80.58.61.254
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Programme\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - Unknown owner - C:\Programme\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - Unknown owner - C:\Programme\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing)
O23 - Service: avast! Web Scanner - Unknown owner - C:\Programme\Alwil Software\Avast4\ashWebSv.exe" /service (file missing)
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - C:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programme\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - Unknown owner - C:\MAGIX\Common\Database\bin\fbserver.exe (file missing)
O23 - Service: GhostStartService - Symantec Corporation - C:\PROGRA~1\Symantec\NORTON~1\GHOSTS~2.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programme\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: Logitech Process Monitor (LVPrcSrv) - Logitech Inc. - c:\programme\gemeinsame dateien\logitech\lvmvfm\LVPrcSrv.exe
O23 - Service: LVSrvLauncher - Logitech Inc. - C:\Programme\Gemeinsame Dateien\Logitech\SrvLnch\SrvLnch.exe
O23 - Service: MySql - Unknown owner - C:/xampplite/mysql/bin/mysqld-nt.exe (file missing)
O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programme\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Programme\Sygate\SPF\smc.exe
O23 - Service: Speed Disk service - Symantec Corporation - C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe

newbie6413
2007-04-24, 00:21
and here the filelist.bat results:

Verzeichnis von C:\

16.04.2007 03:14 502.714.368 hiberfil.sys
16.04.2007 03:14 754.974.720 pagefile.sys
16.04.2007 02:48 301.985 scancode.txt
16.04.2007 02:33 164.938 asmruntime.log
16.03.2007 19:48 9.634 VIDPIDDiagnostic.log
28.01.2007 01:26 0 error_log_20070128.txt



Verzeichnis von C:\WINDOWS\system32

16.04.2007 03:17 1.158 wpa.dbl
16.04.2007 02:49 10.752 BASSMOD.dll
13.04.2007 20:29 55.454 perfc009.dat
13.04.2007 20:29 386.364 perfh009.dat
13.04.2007 20:29 398.422 perfh007.dat
13.04.2007 20:29 66.754 perfc007.dat
13.04.2007 20:29 916.188 PerfStringBackup.INI
12.04.2007 04:41 215.264 FNTCACHE.DAT
03.04.2007 22:48 13.511.640 MRT.exe
17.03.2007 15:44 293.376 winsrv.dll
09.03.2007 12:24 123.392 xpsp3res.dll
08.03.2007 17:36 40.960 mf3216.dll
08.03.2007 17:36 579.072 user32.dll
08.03.2007 17:36 281.600 gdi32.dll
08.03.2007 17:32 1.843.712 win32k.sys
28.02.2007 18:02 2.182.656 ntoskrnl.exe



Verzeichnis von C:\WINDOWS\Prefetch

16.04.2007 03:17 88.286 FIREFOX.EXE-1D57670A.pf
16.04.2007 03:17 12.794 FIND.EXE-0EC32F1E.pf
16.04.2007 03:17 12.614 CMD.EXE-087B4001.pf
16.04.2007 03:17 117.006 WMIPRVSE.EXE-28F301A9.pf
16.04.2007 03:17 42.900 WGATRAY.EXE-0ED38BED.pf
16.04.2007 03:17 25.546 SETUP.OVR-10EB9DE2.pf
16.04.2007 03:17 25.376 VERCLSID.EXE-3667BD89.pf
16.04.2007 03:17 32.468 ALG.EXE-0F138680.pf
16.04.2007 03:17 20.744 IFINGER.EXE-2DD68857.pf
16.04.2007 03:17 24.154 IMAPI.EXE-0BF740A4.pf
16.04.2007 03:17 43.738 WSCNTFY.EXE-1B24F5EB.pf
16.04.2007 03:17 35.612 WUAUCLT.EXE-399A8E72.pf
16.04.2007 03:17 1.472.812 NTOSBOOT-B00DFAAD.pf
16.04.2007 03:12 23.710 LOGONUI.EXE-0AF22957.pf
16.04.2007 03:11 67.138 ACROBATINFO.EXE-2A2FB9E7.pf
16.04.2007 02:56 17.918 NOTEPAD.EXE-336351A9.pf
16.04.2007 02:55 16.170 HIJACKTHIS.EXE-05B066ED.pf
16.04.2007 02:54 76.528 WINRAR.EXE-3588DFE8.pf
16.04.2007 02:54 26.666 BAZOOKASETUP.EXE-37FAD614.pf
16.04.2007 02:53 42.508 SPYWAREBLASTER.EXE-2A13080F.pf
16.04.2007 02:53 21.186 IS-JOQJI.TMP-34DBE288.pf
16.04.2007 02:53 15.750 SPYWAREBLASTERSETUP351.EXE-24B01DD6.pf
16.04.2007 02:52 15.456 PLUGININSTALLER.EXE-12227174.pf
16.04.2007 02:52 15.028 WGAPLUGININSTALL.EXE-145FE4E0.pf
16.04.2007 02:52 16.806 AVGARKT.EXE-36D0BE99.pf
16.04.2007 02:52 9.998 62FU.EXE-0473102B.pf
16.04.2007 02:52 17.962 AVGARKT-SETUP-1.1.0.42.EXE-04309F97.pf
16.04.2007 02:50 15.074 KEYGEN.EXE-2BEB7F6A.pf
16.04.2007 02:50 59.178 UPDATEWIZARD.EXE-13F4E8AB.pf
16.04.2007 02:50 66.264 INTEGRATOR.EXE-3967D297.pf
16.04.2007 02:49 17.122 TUNEUP.UTILITIES.07.6.X.XXXX.-0437F9B7.pf
16.04.2007 02:49 13.888 REGEDIT.EXE-1B606482.pf
16.04.2007 02:43 90.294 THUNDERBIRD.EXE-031A6371.pf
16.04.2007 02:40 10.722 ADOBELM_CLEANUP.0001-24BB484E.pf
16.04.2007 02:40 14.022 ADOBELMSVC.EXE-0665217B.pf
16.04.2007 02:38 31.816 ACROBAT.EXE-02E9AE67.pf
16.04.2007 02:33 70.482 WSFTPGUI.EXE-37EEA383.pf
16.04.2007 02:33 52.174 WSFTPPRO.EXE-052BD3AF.pf
16.04.2007 00:38 89.756 AVAST.SETUP-2B043760.pf
15.04.2007 09:39 67.222 HELPSVC.EXE-2878DDA2.pf
15.04.2007 09:38 499.060 Layout.ini
15.04.2007 01:21 19.648 RUNDLL32.EXE-38C18C8E.pf
15.04.2007 01:20 14.234 RUNDLL32.EXE-451FC2C0.pf
14.04.2007 20:42 17.712 RUNDLL32.EXE-229F48D0.pf
14.04.2007 20:40 112.886 AVGAS.EXE-093B2849.pf
14.04.2007 20:40 13.392 AVG_ANTI_SPYWARE_V75_PROPER_P-0296F139.pf
14.04.2007 20:39 69.862 GUARD.EXE-21B6C22B.pf
14.04.2007 20:38 33.740 AVGAS-SETUP-7.5.0.50.EXE-1C3C46E8.pf
14.04.2007 20:38 44.572 ASHQUICK.EXE-13F2975D.pf
14.04.2007 20:37 9.928 KEYGEN.EXE-307BE7E6.pf
14.04.2007 20:37 9.876 KEYGEN.EXE-0E030814.pf
14.04.2007 20:35 13.574 AVG_ANTI_SPYWARE_V75_PROPER_P-1336B270.pf
14.04.2007 20:35 13.460 AVG_ANTI_SPYWARE_V75_PROPER_P-02737EC0.pf
14.04.2007 20:35 16.620 DAMNNF~1.EXE-1DD13C30.pf
14.04.2007 20:30 14.536 CRD.EXE-1B3FE369.pf
14.04.2007 20:28 15.604 AVG_ANTI_SPYWARE_V75_PROPER_P-034D2340.pf
14.04.2007 20:28 21.076 TASKMGR.EXE-20256C55.pf
14.04.2007 18:53 40.784 RUNDLL32.EXE-45B133BC.pf
14.04.2007 18:50 15.020 KEYGEN.EXE-1C9A2F3D.pf
14.04.2007 18:49 11.180 CORE10K.EXE-2CAB8A96.pf
14.04.2007 18:48 9.590 AVG ANTIVIRUS SYSTEM 7.0. KEY-3010B868.pf
14.04.2007 18:47 28.854 EDITPLUS.EXE-35BC3090.pf
14.04.2007 13:45 61.536 SOFTWAREUPDATE.EXE-1E90DF1F.pf
13.04.2007 20:51 74.240 EMULE.EXE-184A63F1.pf
13.04.2007 20:49 83.120 REGISTRYDEFRAG.EXE-3B4122CA.pf
13.04.2007 20:49 34.642 CTFMON.EXE-0E17969B.pf
13.04.2007 20:49 49.588 VPNGUI.EXE-10986A0F.pf
13.04.2007 20:49 7.796 REGPROT.EXE-06F636EB.pf
13.04.2007 20:49 22.922 ASHDISP.EXE-0B874892.pf
13.04.2007 20:48 10.958 KEYHOOK.EXE-0860E166.pf
13.04.2007 20:48 46.070 SMC.EXE-0B61F84B.pf
13.04.2007 20:48 9.910 SYNTPLPR.EXE-0AB61C3B.pf
13.04.2007 20:48 18.226 SYNTPENH.EXE-3967AE36.pf
13.04.2007 20:48 32.910 RUNDLL32.EXE-2C2091C4.pf
13.04.2007 20:48 62.432 EXPLORER.EXE-082F38A9.pf
13.04.2007 20:48 30.988 USERINIT.EXE-30B18140.pf
13.04.2007 20:29 33.796 WMIADAP.EXE-2DF425B2.pf
13.04.2007 20:23 26.334 REGISTRYDEFRAGHELPER.EXE-09545FD2.pf
13.04.2007 18:52 78.732 REGISTRYCLEANER.EXE-17B6D63B.pf
13.04.2007 18:51 60.072 SYSTEMOPTIMIZER.EXE-2D3174F1.pf
13.04.2007 18:12 41.836 SETUP.EXE-0F958850.pf
13.04.2007 18:12 17.448 THUNDERBIRD SETUP 2.0.0.0 RC -32CEE647.pf
13.04.2007 17:35 28.362 NTVDM.EXE-1A10A423.pf
13.04.2007 17:33 46.070 ONECLICKMAINTENANCE.EXE-05D14B98.pf
13.04.2007 17:33 21.228 ACCESS.EXE-31D75C78.pf
13.04.2007 17:33 59.346 MSIEXEC.EXE-2F8A8CAE.pf
13.04.2007 17:30 9.900 SYMUNDO.EXE-26C2E5FB.pf
13.04.2007 17:30 37.648 OBC.EXE-1502E0C1.pf
13.04.2007 17:23 20.402 MSI1B8.TMP-16A67A90.pf
13.04.2007 17:23 58.016 TU2007TRIALDE.EXE-27BFA100.pf
13.04.2007 17:04 27.800 WINHTTRACK.EXE-14DEB520.pf
13.04.2007 09:05 73.174 DFRGNTFS.EXE-269967DF.pf
13.04.2007 09:05 50.108 DEFRAG.EXE-273F131E.pf
12.04.2007 16:04 15.644 NOTEPAD.EXE-189578DA.pf
12.04.2007 16:03 17.710 _REGDLL.TMP-00C44BA2.pf
12.04.2007 16:03 20.612 IS-GBVJJ.TMP-17580010.pf
12.04.2007 16:03 15.822 HTTRACK-3.41-2.EXE-095760E4.pf
12.04.2007 16:03 4.708 SISUSBRG.EXE-1A6118D0.pf
12.04.2007 15:48 34.014 AVGAS-SETUP-7.5.0.50.EXE-2322884A.pf
12.04.2007 15:46 23.382 WINDOWS-KB890830-V1.28-DELTA.-017E77B8.pf
12.04.2007 15:46 57.386 MRT.EXE-1B4A8D49.pf
12.04.2007 15:46 51.826 MRTSTUB.EXE-062ACC70.pf
12.04.2007 04:46 43.708 RUNDLL32.EXE-2576181F.pf
12.04.2007 04:46 8.890 SSSTARS.SCR-2D6FC20D.pf
12.04.2007 04:07 47.648 PHOTOSHOP.EXE-2E1C999E.pf
12.04.2007 04:07 17.744 RUNDLL32.EXE-2AE6C217.pf
11.04.2007 02:32 162.544 VLC.EXE-29851A71.pf
107 Datei(en) 5.737.344 Bytes
0 Verzeichnis(se), 2.131.730.432 Bytes frei


Verzeichnis von C:\WINDOWS

16.04.2007 03:16 0 0.log
16.04.2007 03:15 315 wiadebug.log
16.04.2007 03:15 50 wiaservc.log
16.04.2007 03:14 2.048 bootstat.dat
16.04.2007 03:13 32.266 SchedLgU.Txt
16.04.2007 03:12 1.285.378 WindowsUpdate.log
12.04.2007 01:49 176.670 iis6.log
12.04.2007 01:49 177.734 comsetup.log
12.04.2007 01:49 245.423 ntdtcsetup.log
12.04.2007 01:49 455.327 tsoc.log
12.04.2007 01:49 64.214 ocmsn.log
12.04.2007 01:49 1.374 imsins.log
12.04.2007 01:49 14.258 KB931784.log
12.04.2007 01:49 253.692 ocgen.log
12.04.2007 01:49 58.294 msgsocm.log
12.04.2007 01:49 1.165.313 FaxSetup.log
12.04.2007 01:49 851.484 setupapi.log
12.04.2007 01:49 1.374 imsins.BAK
12.04.2007 01:49 12.217 KB931261.log
12.04.2007 01:48 12.532 KB930178.log
12.04.2007 01:48 82.219 updspapi.log
12.04.2007 01:48 12.386 KB932168.log
11.04.2007 02:31 116 NeroDigital.ini
07.04.2007 16:21 192 winamp.ini
06.04.2007 18:39 12.273 KB925902.log
29.03.2007 19:54 2.396 setupact.log
27.03.2007 18:56 54.156 QTFont.qfn
27.03.2007 17:12 1.464 cdPlayer.ini
21.03.2007 00:19 1.454 COM+.log
21.03.2007 00:16 639.488 fpuninst.exe
20.03.2007 23:43 39 MB.ini
20.03.2007 23:42 220 Buhl.ini
20.03.2007 23:00 253 wiso.ini
20.03.2007 04:49 1.409 QTFont.for
16.03.2007 20:03 12.653 KB929399.log
16.03.2007 20:01 14.995 KB929338.log
01.03.2007 12:37 117.350 spupdsvc.log
01.03.2007 12:33 25.331 WgaNotify.log



Verzeichnis von C:\WINDOWS\tasks

16.04.2007 03:14 6 SA.DAT
14.04.2007 13:45 276 AppleSoftwareUpdate.job
13.04.2007 17:33 394 1-Klick-Wartung.job
13.04.2007 17:30 270 Norton SystemWorks One Button Checkup.job



Verzeichnis von C:\WINDOWS\temp

16.04.2007 03:17 409 WGANotify.settings
16.04.2007 03:15 255 WGAErrLog.txt
12.04.2007 16:00 16.384 Perflib_Perfdata_41c.dat
10.04.2007 20:54 16.384 Perflib_Perfdata_47c.dat
06.04.2007 18:41 16.384 Perflib_Perfdata_418.dat
06.04.2007 18:32 16.384 Perflib_Perfdata_40c.dat
27.03.2007 08:29 16.384 Perflib_Perfdata_408.dat
24.03.2007 06:57 52.302 dneinst.log
19.03.2007 21:40 16.384 Perflib_Perfdata_400.dat
19.03.2007 20:52 34.426 PQ_DEBUG.TXT
19.03.2007 20:52 1.121 PQ_BATCH.PQB
19.03.2007 20:46 16.384 Perflib_Perfdata_514.dat
19.03.2007 20:46 16.384 Perflib_Perfdata_32c.dat
19.03.2007 20:22 5.211 PQ_DEBUG.001
19.03.2007 20:04 20.179 PQ_DEBUG.002
19.03.2007 20:04 1.157 PQ_BATCH.002
19.03.2007 05:50 16.384 Perflib_Perfdata_3a0.dat
19.03.2007 05:44 20.182 PQ_DEBUG.003
19.03.2007 05:44 1.157 PQ_BATCH.003
19.03.2007 05:43 7.657 PQ_DEBUG.004
16.03.2007 21:26 16.384 Perflib_Perfdata_3f4.dat
15.03.2007 05:07 16.874 PQ_DEBUG.005
15.03.2007 05:06 902 PQ_BATCH.005
15.03.2007 04:17 16.384 Perflib_Perfdata_480.dat
15.03.2007 00:36 16.384 Perflib_Perfdata_7d8.dat
13.03.2007 15:05 16.384 Perflib_Perfdata_3f8.dat
09.03.2007 16:57 16.384 Perflib_Perfdata_3ac.dat
06.03.2007 23:32 16.384 Perflib_Perfdata_694.dat
06.03.2007 23:19 16.384 Perflib_Perfdata_764.dat
01.03.2007 12:37 16.384 Perflib_Perfdata_230.dat



Verzeichnis von C:\DOKUME~1\Fabs\LOKALE~1\Temp

16.04.2007 03:18 0 tmp-1.xpi
16.04.2007 03:18 170.611 tmp.xpi
16.04.2007 03:18 162.556 filelist.txt
16.04.2007 02:39 59.964 Adobelm_Cleanup.0001
16.04.2007 02:37 16.384.000 programas.rar
16.04.2007 02:31 0 fla33.tmp
16.04.2007 02:06 4.344.888 antispyware.rar
15.04.2007 11:19 41.352 java_install_reg.log
13.04.2007 20:58 77.688 jusched.log
13.04.2007 20:19 0 fla1FA.tmp
13.04.2007 19:24 0 fla1F2.tmp
13.04.2007 19:21 0 fla1EF.tmp
13.04.2007 19:10 0 fla1E8.tmp
12.04.2007 04:07 1.308 TWAIN.LOG
12.04.2007 04:07 5 Twain001.Mtx
12.04.2007 04:07 156 Twunk001.MTX
12.04.2007 04:04 0 fla75.tmp
12.04.2007 03:57 0 fla73.tmp
12.04.2007 02:00 0 fla68.tmp
11.04.2007 02:31 1.392 wmplog13.sqm
10.04.2007 22:21 0 fla22.tmp
10.04.2007 22:02 0 fla17.tmp
10.04.2007 10:52 122 8A56EAB7.TMP
10.04.2007 07:12 1.360 wmplog12.sqm
10.04.2007 07:07 49.152 ~DFA787.tmp
10.04.2007 07:01 0 fla17B.tmp
10.04.2007 06:56 0 fla179.tmp
10.04.2007 06:19 0 fla165.tmp
10.04.2007 06:16 0 fla162.tmp
10.04.2007 06:12 0 fla15B.tmp
10.04.2007 06:08 0 fla159.tmp
10.04.2007 06:00 0 fla157.tmp
10.04.2007 05:59 0 fla155.tmp
10.04.2007 05:50 0 fla152.tmp
10.04.2007 05:29 0 fla14B.tmp
10.04.2007 05:29 0 fla149.tmp
10.04.2007 05:18 0 fla146.tmp
10.04.2007 05:17 0 fla144.tmp
10.04.2007 05:17 0 fla143.tmp
10.04.2007 05:17 0 fla141.tmp
10.04.2007 05:13 0 fla12E.tmp
10.04.2007 05:12 0 fla12C.tmp
10.04.2007 05:12 0 fla12A.tmp
10.04.2007 05:12 0 fla128.tmp
10.04.2007 03:59 0 fla122.tmp
10.04.2007 03:49 0 fla11E.tmp
10.04.2007 03:44 49.152 ~DF58E9.tmp
10.04.2007 02:45 0 fla10D.tmp
10.04.2007 01:47 0 flaF7.tmp
10.04.2007 01:16 0 flaE4.tmp
10.04.2007 01:13 0 flaE2.tmp
10.04.2007 00:56 0 flaE0.tmp
10.04.2007 00:56 0 flaDE.tmp
10.04.2007 00:37 0 flaD9.tmp
10.04.2007 00:36 0 flaD7.tmp
10.04.2007 00:34 0 flaD4.tmp
10.04.2007 00:34 0 flaD2.tmp
10.04.2007 00:33 0 flaD0.tmp
10.04.2007 00:33 0 flaCE.tmp
10.04.2007 00:31 0 flaCC.tmp
10.04.2007 00:31 0 flaCA.tmp
10.04.2007 00:30 0 flaC8.tmp
10.04.2007 00:30 0 flaC6.tmp
10.04.2007 00:30 0 flaC4.tmp

tashi
2007-04-24, 00:51
Hello.

http://forum.hijackthis.de/showthread.php?t=22625

It appears you are still in dialogue with karl83?


deine Logs sehen gut aus mit einer Einschränkung: Die Javaversion auf deinem Rechner ist nicht mehr ganz aktuell. Die muß aktualisiert werden. Dazu in Systemsteuerung -> Software die alte Version deinstallieren, von Java Update die aktuelle "Java Runtime Environment (JRE) 6u1" runterladen und installieren.
Sun Microsystems~Java. Security vunerability in older versions left on system (http://forums.spybot.info/showpost.php?p=12880&postcount=2 )


FYI: The procedure for this forum: "BEFORE you POST" Mandatory Steps Before Requesting Assistance (http://forums.spybot.info/showthread.php?t=288)

newbie6413
2007-04-24, 06:39
i am still in contact with karl83, but as he told me my system seemed ok and i found something afterwards, I thought i might ask here, as u guys also specialize in this for years already...
btw: spybot did not find the infection of zlob trojan downloader, which was in a dll-file from "music-brainz picard"....
the g-data standalone scanner found it though...
now i am quite worried there might be a lot more somewhere...

tashi
2007-05-03, 21:01
This topic has been archived.