Hallo, ich hab mir heute leider das Fake-Antiviren-Programm XP Antispyware eingefangen. Dieses nervt mit Falschmeldungen und verlangsamt meinen PC enorm.
Ich hab mir dann wie in http://www.paules-pc-forum.de/forum/4-pc-sic…-entfernen.html
beschrieben das Programm Malwarebytes Anti-Malware geholt und gescannt hat auch einiges gefunden:
Malwarebytes' Anti-Malware 1.44
Datenbank Version: 3826
Windows 5.1.2600 Service Pack 2
Internet Explorer 7.0.5730.11
05.03.2010 20:21:57
mbam-log-2010-03-05 (20-21-57).txt
Scan-Methode: Vollständiger Scan (C:\|)
Durchsuchte Objekte: 373613
Laufzeit: 2 hour(s), 20 minute(s), 42 second(s)
Infizierte Speicherprozesse: 0
Infizierte Speichermodule: 0
Infizierte Registrierungsschlüssel: 0
Infizierte Registrierungswerte: 1
Infizierte Dateiobjekte der Registrierung: 3
Infizierte Verzeichnisse: 0
Infizierte Dateien: 25
Infizierte Speicherprozesse:
(Keine bösartigen Objekte gefunden)
Infizierte Speichermodule:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungsschlüssel:
(Keine bösartigen Objekte gefunden)
Infizierte Registrierungswerte:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Terminal Server\Install\Software\Microsoft\Windows\CurrentVersion\Run\firewall administrating (Backdoor.IRCBot) -> Quarantined and deleted successfully.
Infizierte Dateiobjekte der Registrierung:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> Quarantined and deleted successfully.
Infizierte Verzeichnisse:
(Keine bösartigen Objekte gefunden)
Infizierte Dateien:
C:\WINDOWS\system32\drivers\svchost.exe (Trojan.Downloader) -> Quarantined and deleted successfully.
C:\Programme\hhrashlp.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\HHWMPrxy.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\HHWMPrxy7.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\MDLL32.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\MumaIpl.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\MumaIplA6.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\MumaIplM6.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\MumaIplP6.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\MumaIplPX.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\MumaIplW7.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\PlayRIpl.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\PlayRIplPX.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\qtmlClient.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\SAMSIG.DLL (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\samsigA6.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\samsigM5.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\samsigM6.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\samsigP5.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\samsigP6.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\samsigPX.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\Programme\samsigW7.dll (Spyware.OnlineGames) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\g.bat (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\system32\g.ftp (Malware.Trace) -> Quarantined and deleted successfully.
C:\WINDOWS\Help\1.ftp (Malware.Trace) -> Quarantined and deleted successfully.
Den Scan hab ich mit einem anderen Benutzer ausgeführt, da ich das Programm auf dem Benutzer, der infiziert ist nicht ausführen kann!
Allerdings scheint es nicht geholfen zu haben, wenn ich mich beim anderen Benutzer einlogge ist der Virus wie gehabt da!
Kann mir jemand helfen?
Danke schon mal.
mfg Timo