Die beiden "rundll Viren" sind weg...jetzt kommt nach jedem Start ein RUNDLL Fehler.
Die anderen beiden sind mit Explorer verbunden und deswegen kann ich die nicht löschen-.-.
Ich versuch jetzt mal mittels der Engines auf der Virustotal Seite: Also lad ich mir mal die programme runter die was erkannt haben.
Edit: Und jetzt grade geht Firefox aber wieder, da verzichte ich auf Rundll oder hol mir die Original Dateien vom meinem bruder
. Achja ein rundll32.exe läuft noch, das richtige^^Ok und jetzt scan ich grad mit McAffe Demo Version.
McAffe ist scheiße.
Hier mal ein Programm speziell für die Vundo viren. Es heißt VirtumundoBeGone.
Hier ein txt.file:
[06/19/2008, 19:24:13] - VirtumundoBeGone v1.5 ( "C:\Dokumente und Einstellungen\Tobi\Desktop\VirtumundoBeGone.exe" )
[06/19/2008, 19:24:19] - Detected System Information:
[06/19/2008, 19:24:19] - Windows Version: 5.1.2600, Service Pack 2
[06/19/2008, 19:24:19] - Current Username: Tobi (Admin)
[06/19/2008, 19:24:19] - Windows is in NORMAL mode.
[06/19/2008, 19:24:19] - Searching for Browser Helper Objects:
[06/19/2008, 19:24:19] - BHO 1: {13F20E4F-F379-41EA-8F80-CCAAE787362A} ()
[06/19/2008, 19:24:19] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/19/2008, 19:24:19] - Checking for HKLM\...\Winlogon\Notify\hgGyyxXp
[06/19/2008, 19:24:19] - Found: HKLM\...\Winlogon\Notify\hgGyyxXp - This is probably Virtumundo.
[06/19/2008, 19:24:19] - Assigning {13F20E4F-F379-41EA-8F80-CCAAE787362A} MSEvents Object
[06/19/2008, 19:24:19] - BHO list has been changed! Starting over...
[06/19/2008, 19:24:19] - BHO 1: {13F20E4F-F379-41EA-8F80-CCAAE787362A} (MSEvents Object)
[06/19/2008, 19:24:19] - ALERT: Found MSEvents Object!
[06/19/2008, 19:24:19] - BHO 2: {210AF1EC-596A-4848-9C4F-7EA64FA3AB5B} ()
[06/19/2008, 19:24:19] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/19/2008, 19:24:19] - Checking for HKLM\...\Winlogon\Notify\byXNdawv
[06/19/2008, 19:24:19] - Key not found: HKLM\...\Winlogon\Notify\byXNdawv, continuing.
[06/19/2008, 19:24:19] - BHO 3: {320e69a3-3b48-486f-889e-12eedd8e84b1} ()
[06/19/2008, 19:24:19] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/19/2008, 19:24:19] - Checking for HKLM\...\Winlogon\Notify\cngantst
[06/19/2008, 19:24:19] - Key not found: HKLM\...\Winlogon\Notify\cngantst, continuing.
[06/19/2008, 19:24:19] - BHO 4: {638F60C3-3D85-4FEE-B5C8-AB2131E54167} ()
[06/19/2008, 19:24:19] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/19/2008, 19:24:19] - Checking for HKLM\...\Winlogon\Notify\cbXoMcAs
[06/19/2008, 19:24:19] - Key not found: HKLM\...\Winlogon\Notify\cbXoMcAs, continuing.
[06/19/2008, 19:24:19] - BHO 5: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[06/19/2008, 19:24:19] - Finished Searching Browser Helper Objects
[06/19/2008, 19:24:19] - *** Detected MSEvents Object
[06/19/2008, 19:24:19] - Trying to remove MSEvents Object...
[06/19/2008, 19:24:20] - Terminating Process: IEXPLORE.EXE
[06/19/2008, 19:24:20] - Terminating Process: RUNDLL32.EXE
[06/19/2008, 19:24:21] - Disabling Automatic Shell Restart
[06/19/2008, 19:24:21] - Terminating Process: EXPLORER.EXE
[06/19/2008, 19:24:21] - Suspending the NT Session Manager System Service
[06/19/2008, 19:24:21] - Terminating Windows NT Logon/Logoff Manager
[06/19/2008, 19:24:21] - Re-enabling Automatic Shell Restart
[06/19/2008, 19:24:21] - File to disable: C:\WINDOWS\system32\hgGyyxXp.dll
[06/19/2008, 19:24:21] - Renaming C:\WINDOWS\system32\hgGyyxXp.dll -> C:\WINDOWS\system32\hgGyyxXp.dll.vir
[06/19/2008, 19:24:21] - File successfully renamed!
[06/19/2008, 19:24:21] - Removing HKLM\...\Browser Helper Objects\{13F20E4F-F379-41EA-8F80-CCAAE787362A}
[06/19/2008, 19:24:22] - Removing HKCR\CLSID\{13F20E4F-F379-41EA-8F80-CCAAE787362A}
[06/19/2008, 19:24:22] - Adding Kill Bit for ActiveX for GUID: {13F20E4F-F379-41EA-8F80-CCAAE787362A}
[06/19/2008, 19:24:22] - Deleting ATLEvents/MSEvents Registry entries
[06/19/2008, 19:24:22] - Removing HKLM\...\Winlogon\Notify\hgGyyxXp
[06/19/2008, 19:24:22] - Searching for Browser Helper Objects:
[06/19/2008, 19:24:22] - BHO 1: {210AF1EC-596A-4848-9C4F-7EA64FA3AB5B} ()
[06/19/2008, 19:24:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/19/2008, 19:24:22] - Checking for HKLM\...\Winlogon\Notify\byXNdawv
[06/19/2008, 19:24:22] - Key not found: HKLM\...\Winlogon\Notify\byXNdawv, continuing.
[06/19/2008, 19:24:22] - BHO 2: {320e69a3-3b48-486f-889e-12eedd8e84b1} ()
[06/19/2008, 19:24:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/19/2008, 19:24:22] - Checking for HKLM\...\Winlogon\Notify\cngantst
[06/19/2008, 19:24:22] - Key not found: HKLM\...\Winlogon\Notify\cngantst, continuing.
[06/19/2008, 19:24:22] - BHO 3: {638F60C3-3D85-4FEE-B5C8-AB2131E54167} ()
[06/19/2008, 19:24:22] - WARNING: BHO has no default name. Checking for Winlogon reference.
[06/19/2008, 19:24:22] - Checking for HKLM\...\Winlogon\Notify\cbXoMcAs
[06/19/2008, 19:24:22] - Key not found: HKLM\...\Winlogon\Notify\cbXoMcAs, continuing.
[06/19/2008, 19:24:22] - BHO 4: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} (SSVHelper Class)
[06/19/2008, 19:24:22] - Finished Searching Browser Helper Objects
[06/19/2008, 19:24:22] - Finishing up...
[06/19/2008, 19:24:22] - A restart is needed.
[06/19/2008, 19:24:35] - Attempting to Restart via STOP error (Blue Screen!)
Und es erstellen sich wohl immer wieder dlls nach einem neustart die sich als rundll ausgeben wenn ich diese lösche geht firefox immer^^
auch wenn ich mittlerweile nach jedem neustart "angebliche"(vorsichtig gesagt)rundll fehlermeldungen bekomme.
Was muss ich nun machen?
. Bin zwar schon am verzweifeln. ich glaub ich brenn mal meine Daten und dann naja neues Windows >.< . bin aber nicht zufrieden damit... Ich gedulde mich jetzt noch ca. 1Tag wenn ich es bis dahin nicht geschafft habe => neues XP