|
Plagegeister aller Art und deren Bekämpfung: zsys.sys zapchast eScan beendet->Log file help plzWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
30.12.2004, 01:27 | #1 |
| zsys.sys zapchast eScan beendet->Log file help plz lol muss das log dritteln weils so groß is: 1te seite: File C:\WINDOWS\sysml.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\child.dll infected by "Backdoor.Thunk.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\velyx.dll infected by "Trojan-Dropper.Win32.Small.nz" Virus. Action Taken: No Action Taken. File C:\WINDOWS\yxedaxkn.dll infected by "Trojan-Dropper.Win32.Small.nz" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\ianuua.dll infected by "Trojan-Downloader.Win32.Agent.gl" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\DRIVERS\ZSYS.SYS infected by "Trojan.Win32.Zapchast" Virus. Action Taken: No Action Taken. File C:\WINDOWS\hosts infected by "Trojan.Win32.Qhost.k" Virus. Action Taken: No Action Taken. File C:\WINDOWS\iehndl.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\mstasks3.exe infected by "Trojan-Downloader.Win32.Small.lx" Virus. Action Taken: No Action Taken. File C:\WINDOWS\sysml.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\WINDOWS\toolbar.exe infected by "Trojan.Win32.LowZones.y" Virus. Action Taken: No Action Taken. File C:\WINDOWS\velyx.dll infected by "Trojan-Dropper.Win32.Small.nz" Virus. Action Taken: No Action Taken. File C:\WINDOWS\yxedaxkn.dll infected by "Trojan-Dropper.Win32.Small.nz" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\child.dll infected by "Backdoor.Thunk.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\ianuua.dll infected by "Trojan-Downloader.Win32.Agent.gl" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\oopuyal.dll infected by "Trojan-Downloader.Win32.Agent.gl" Virus. Action Taken: No Action Taken. File C:\ps.exe infected by "Backdoor.Win32.Banger.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0002428.exe infected by "Trojan-Dropper.Win32.Small.oy" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0002429.exe infected by "Backdoor.Thunk.d" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0002434.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0002444.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0003444.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0003445.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0004444.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0005444.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0005445.sys infected by "Trojan.Win32.Zapchast" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0005453.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0005461.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0005472.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0005478.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0005484.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0005488.sys infected by "Trojan.Win32.Zapchast" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0006484.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0006490.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0006491.sys infected by "Trojan.Win32.Zapchast" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0006499.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0006505.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0006511.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0006515.sys infected by "Trojan.Win32.Zapchast" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0007511.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. |
30.12.2004, 01:28 | #2 |
| zsys.sys zapchast eScan beendet->Log file help plz 2te seite:
__________________File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008511.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008515.sys infected by "Trojan.Win32.Zapchast" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008520.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008526.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008532.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008533.sys infected by "Trojan.Win32.Zapchast" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008539.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008545.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008547.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008553.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008559.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008561.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008562.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0008563.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0009559.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0009561.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0010559.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0011559.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0011563.sys infected by "Trojan.Win32.Zapchast" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0012559.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0013559.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0013567.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0013568.sys infected by "Trojan.Win32.Zapchast" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0013574.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0013581.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0014581.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0015581.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0015587.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0015593.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0015597.sys infected by "Trojan.Win32.Zapchast" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP22\A0015602.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0015649.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0015664.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. |
30.12.2004, 01:29 | #3 |
| zsys.sys zapchast eScan beendet->Log file help plz 3te seite :
__________________File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0015665.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0015672.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0016672.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0016678.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0016680.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0016681.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0016682.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0016687.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0017687.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0017694.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0017701.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0017708.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0017712.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0017718.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0018718.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0018724.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{4E045425-B0C0-4C7F-807C-9CD0B58F0D54}\RP24\A0018728.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\load.exe infected by "TrojanDownloader.Win32.Small.yx" Virus. Action Taken: No Action Taken. File C:\WINDOWS\hosts infected by "Trojan.Win32.Qhost.k" Virus. Action Taken: No Action Taken. File C:\WINDOWS\iehndl.dll infected by "Backdoor.Win32.Banger.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\mstasks3.exe infected by "Trojan-Downloader.Win32.Small.lx" Virus. Action Taken: No Action Taken. File C:\WINDOWS\sysml.dll infected by "Trojan-Downloader.Win32.Small.acp" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\child.dll infected by "Backdoor.Thunk.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\drivers\zsys.sys infected by "Trojan.Win32.Zapchast" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\ianuua.dll infected by "Trojan-Downloader.Win32.Agent.gl" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\oopuyal.dll infected by "Trojan-Downloader.Win32.Agent.gl" Virus. Action Taken: No Action Taken. File C:\WINDOWS\toolbar.exe infected by "Trojan.Win32.LowZones.y" Virus. Action Taken: No Action Taken. File C:\WINDOWS\velyx.dll infected by "Trojan-Dropper.Win32.Small.nz" Virus. Action Taken: No Action Taken. File C:\WINDOWS\yxedaxkn.dll infected by "Trojan-Dropper.Win32.Small.nz" Virus. Action Taken: No Action Taken. |
30.12.2004, 02:35 | #4 | |
| zsys.sys zapchast eScan beendet->Log file help plz @ HAte-Trojans Zitat:
Dein System ist kompromittiert und möglicherweise in der Hand Dritter. Die Trojaner und Viren, die Du auf Deinem System hast, erfordern dass du Deinen Rechner formatierst, entsprechend dem Rat von Cidre: Setze das System neu auf, da dies nicht mehr vertrauenswürdig ist. http://oschad.de/wiki/index.php/Kompromittierung http://faq.underflow.de/#SECTION000120000000000000000 Nach dem Neuaufsetzen und vor der ersten Internet Verbindung solltest du folgende Punkte abarbeiten: 1. Eingeschränktes Benutzerkonto erstellen und zum Surfen benutzen http://freenet.meome.de/app/fn/artco...sp?catId=79426 2. Internetverbindungsfirewall aktivieren http://www.computerhilfe-euskirchen....xp/tipp16.html 3. Das System updaten und stets aktuell halten http://v5.windowsupdate.microsoft.co...r/default.aspx 4. NT-Dienste sicher konfigurieren http://www.ntsvcfg.de/ oder www.dingens.org 5. IE sicherer konfigurieren und nur noch für das Windows Update benutzen http://www.datenschutzzentrum.de/se...msie/config.htm oder http://www.blafusel.de/ie.html 6. Sichere und komfortablere Browser wie z.B. Mozilla oder Firefox verwenden http://www.mozilla.org/ 7. MS Outlook und Outlook Express sicherer konfigurieren http://www.fz-juelich.de/zam/net/sec...ok-config.html oder http://www.datenschutz-bremen.de/tip...riffe/mail.htm Besser wäre es, sichere eMail Clients wie Thunderbird einzusetzen http://www.thunderbird-mail.de/ 8. Deine Passwörter ändern 9. Image der Systempartition erstellen mit z.B. Acronis True Image 7 10. Surfverhalten überdenken Info zur Installation von Win XP findest du hier: http://8ung.at/chemikers-home/SETUP.html und http://chip-faq.rufisplanet.ch/installation.html Für die Zukunft: http://www.mathematik.uni-marburg.de...ompromise.html und beachte den Rat von Lutz zur Datensicherung SD |
30.12.2004, 03:49 | #5 |
| zsys.sys zapchast eScan beendet->Log file help plz na nun bin ich voll am arsch...in 3 h geht mein zug und dass is net mein pc |
Themen zu zsys.sys zapchast eScan beendet->Log file help plz |
.exe, action, c:\windows, drivers, escan, file, formation, help, help plz, hosts, infected, information, log, log file, restore, seite, system, system volume information, system32, taken, troja, volume, windows, windows\system32\drivers, _restore |