|
Log-Analyse und Auswertung: Totales ChaosWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
29.12.2004, 14:30 | #1 |
| Totales Chaos Ich hab ein ersntes Problem und zwar hat sich mein Desktop in eine HTML file verändernt und massig icons kommen . Auf der HTML file steht irgendwas mit Spybot und blabla und ich hab mir mal das Forum ein bisschen angeschaut und hab mir eScan geloaded jetzt post ich mal den vir log und hoffe das mir einer helfen kann ... thx File C:\DOKUME~1\Chris\ANWEND~1\MICROS~1\sr64\sr32.dll infected by "TrojanProxy.Win32.Agent.x" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\aklsp.dll infected by "TrojanDownloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\child.dll infected by "Backdoor.Thunk.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\msrexe.exe infected by "Backdoor.Jeemp.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\mvvcirt.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\spoolsrv32.exe infected by "Trojan.Win32.Small.cr" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\srpcsrv32.dll infected by "Trojan.Win32.Small.cr" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\systime.exe infected by "Trojan.Win32.StartPage.pu" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\systime.exe infected by "Trojan.Win32.StartPage.pu" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\msrexe.exe infected by "Backdoor.Jeemp.c" Virus. Action Taken: No Action Taken. File C:\Programme\CashBack\bin\cashback.exe infected by "not-a-virus:AdWare.BargainBuddy.j" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\BULLSE~1\bin\bargains.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\spoolsrv32.exe infected by "Trojan.Win32.Small.cr" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\systime.exe infected by "Trojan.Win32.StartPage.pu" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\spoolsrv32.exe infected by "Trojan.Win32.Small.cr" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\angelex.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\msrexe.exe infected by "Backdoor.Jeemp.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\hosts infected by "Trojan.Win32.Qhost.k" Virus. Action Taken: No Action Taken. File C:\WINDOWS\IEMenuExtension.exe infected by "not-a-virus:AdWare.ToolBar.Ucmore" Virus. Action Taken: No Action Taken. File C:\WINDOWS\mstasks2.exe infected by "Trojan.Win32.Favadd.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\mstasks3.exe infected by "Trojan-Downloader.Win32.Small.lx" Virus. Action Taken: No Action Taken. File C:\WINDOWS\nem220.dll infected by "TrojanDownloader.Win32.Dyfuca.gen" Virus. Action Taken: No Action Taken. File C:\WINDOWS\optimize.exe infected by "Trojan-Downloader.Win32.Dyfuca.dk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SSK_B5.EXE infected by "Trojan-Dropper.Win32.SurfSide.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\toolbar.exe infected by "Trojan.Win32.LowZones.y" Virus. Action Taken: No Action Taken. File C:\WINDOWS\VT00.exe infected by "Trojan-Downloader.Win32.Lookme.g" Virus. Action Taken: No Action Taken. File C:\WINDOWS\wsem302.dll infected by "TrojanDownloader.Win32.Dyfuca.dc" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\Afdggj32.dll infected by "Backdoor.Win32.Padodor" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\akcore.dll infected by "not-a-virus:AdWare.Coreak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\aklsp.dll infected by "TrojanDownloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\akrules.dll infected by "TrojanDownloader.Win32.Agent.bt" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\akupd.dll infected by "TrojanDownloader.Win32.Agent.br" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\angelex.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\child.dll infected by "Backdoor.Thunk.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\dktibs.exe infected by "TrojanDownloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\exdl.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\exdl0.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\exdl1.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\exdl3.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\exul.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\exul1.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\Fgdenk32.exe infected by "Backdoor.Win32.Padodor.al" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\guard.tmp infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\instsrv.exe tagged as not-a-virus:RiskWare.Tool.ServiceRunner.f. No Action Taken. File C:\WINDOWS\System32\ioitpki.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\javexulm.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\jtnm0751e.dll infected by "not-a-virus:AdWare.Look2Me.u" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\mac80ex.idf infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\mgsip32.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\mqexdlm.srg infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\msbe.dll infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\mscb.dll infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\msrexe.exe infected by "Backdoor.Jeemp.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\mvvcirt.dll infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\psis80ex.ax infected by "not-a-virus:AdWare.BargainBuddy.l" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\spoolsrv32.exe infected by "Trojan.Win32.Small.cr" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\srpcsrv32.dll infected by "Trojan.Win32.Small.cr" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\systime.exe infected by "Trojan.Win32.StartPage.pu" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\txfdb32.dll infected by "Trojan.Win32.Small.cr" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\WrapperOuter.exe infected by "not-a-virus:AdWare.VirtualBouncer.c" Virus. Action Taken: No Action Taken. File C:\DOKUME~1\Chris\LOKALE~1\Temp\i30.tmp infected by "not-a-virus:AdWare.SurfSide.a" Virus. Action Taken: No Action Taken. File C:\DOKUME~1\Chris\LOKALE~1\Temp\_is34\Java 2 SDK, SE v1.4.2_04.msi tagged as not-a-virus:JavaClass.Chart. No Action Taken. File C:\DOKUME~1\Chris\LOKALE~1\TEMPOR~1\Content.IE5\6UFU3S87\sd9[1].exe tagged as not-a-virus:Porn-Dialer.Win32.Kotu.d. No Action Taken. File C:\DOKUME~1\Chris\LOKALE~1\TEMPOR~1\Content.IE5\DGAXZNAQ\125021[2].exe tagged as not-a-virus:Porn-Downloader.Win32.TibSystems. No Action Taken. File C:\DOKUME~1\Chris\LOKALE~1\TEMPOR~1\Content.IE5\ZDCH6X5S\125021[1].exe tagged as not-a-virus:Porn-Downloader.Win32.TibSystems. No Action Taken. File C:\DOKUME~1\Chris\LOKALE~1\TEMPOR~1\Content.IE5\ZDCH6X5S\t-10761[2].htm infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken. |
29.12.2004, 14:36 | #2 |
| Totales Chaos Chaos,
__________________so kann man das nennen! u.a der hier: http://www.sophos.de/virusinfo/analy...jpadodors.html Do solltest dein System neu aufsetzen,siehe dazu auch: http://www.trojaner-board.de/showpos...28&postcount=2 Zudem hast du massig an Dailern drauf,diese solltest du ggf auf Diskette sichern,damit du was in der Hand hast: File C:\DOKUME~1\Chris\LOKALE~1\TEMPOR~1\Content.IE5\6UFU3S87\sd9[1].exe tagged as not-a-virus:Porn-Dialer.Win32.Kotu.d. No Action Taken. File C:\DOKUME~1\Chris\LOKALE~1\TEMPOR~1\Content.IE5\DGAXZNAQ\125021[2].exe tagged as not-a-virus:Porn-Downloader.Win32.TibSystems. No Action Taken. File C:\DOKUME~1\Chris\LOKALE~1\TEMPOR~1\Content.IE5\ZDCH6X5S\125021[1].exe tagged as not-a-virus:Porn-Downloader.Win32.TibSystems. No Action Taken. Gruss |
29.12.2004, 14:50 | #3 |
| Totales Chaos Ich bin ein Absoluter Anfänger in sowas was soll ich mit der protorz-ide machen?
__________________und das mit dem System neu aufsetzten blick ich auch nicht T_T |
Themen zu Totales Chaos |
.dll, .msi, c:\windows, cashback, content.ie5, desktop, escan, file, forum, helfen, hoffe, hosts, html, icons, infected, java, log, lokale, mac, not-a-virus, problem, programme, spybot, system, system32, temp, verändern, windows |