|
Plagegeister aller Art und deren Bekämpfung: C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.AWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
19.01.2005, 21:44 | #1 |
| C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.A ... zeigt AntiVir immer wieder an. Mein Internet ist dadurch auch total lahm geworden. Ich weis nich was ich machen soll. Hab zwar schon einiges probiert, aber so die Ahnung hab ich auch nicht und igendwie komm ich net voran ! Würde mich sehr über Hilfe freuen ! MFG |
19.01.2005, 22:20 | #2 | |
| C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.AZitat:
Poste ein HijackThis Logfile: kurze Beschreibung ausführliche Beschreibung |
25.01.2005, 10:41 | #3 |
| C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.A Logfile of HijackThis v1.99.0
__________________Scan saved at 10:38:25, on 25.01.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WIN-XP\System32\smss.exe C:\WIN-XP\system32\winlogon.exe C:\WIN-XP\system32\services.exe C:\WIN-XP\system32\lsass.exe C:\WIN-XP\system32\svchost.exe C:\WIN-XP\System32\svchost.exe C:\WIN-XP\system32\spoolsv.exe C:\Programme\AVPersonal\AVGUARD.EXE C:\Programme\AVPersonal\AVWUPSRV.EXE C:\WIN-XP\system32\drivers\CDAC11BA.EXE C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe C:\WIN-XP\System32\nvsvc32.exe C:\WIN-XP\Explorer.EXE C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe C:\PROGRA~1\PANICW~1\POP-UP~2\dpps2.exe C:\Programme\iTunes\iTunesHelper.exe C:\Programme\QuickTime\qttask.exe C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis1\ToADiMon.exe C:\Programme\iPod\bin\iPodService.exe C:\Program Files\Win Comm\WinComm.exe C:\Program Files\Windows AdControl\WinAdCtl.exe C:\Programme\MSN Apps\Updater\01.02.3000.1001\de\msnappau.exe C:\Program Files\Windows ControlAd\WinCtlAd.exe C:\WIN-XP\isrvs\desktop.exe C:\Program Files\Windows ControlAd\WinCtlAdAlt.exe C:\Program Files\Admilli Service\AdmilliServ.exe C:\Program Files\Windows ServeAd\WinServAd.exe C:\Programme\AVPersonal\AVGNT.EXE C:\WIN-XP\system32\ctfmon.exe C:\Program Files\Admilli Service\AdmilliKeep.exe C:\Program Files\Windows ServeAd\WinServSuit.exe C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\kernel.exe C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\sc_watch.exe C:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis2\PROFIL~1.EXE C:\unzipped\hijackthis199\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.isearch.com/index.php?app...DQ6NTo5&Terms= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://g.msn.de/0SEDEDE/SAOS01 R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.isearch.com/index.php?app...DQ6NTo5&Terms= R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://i-lookup.com/ R3 - URLSearchHook: (no name) - {1C78AB3F-A857-482e-80C0-3A1E5238A565} - (no file) O2 - BHO: NavErrRedir Class - {00D6A7E7-4A97-456f-848A-3B75BF7554D7} - (no file) O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\Programme\MyWay\myBar\1.bin\MYBAR.DLL O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Search Relevancy - {1D7E3B41-23CE-469B-BE1B-A64B877923E1} - C:\PROGRA~1\SEARCH~1\SEARCH~2.DLL O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WIN-XP\isrvs\sysupd.dll O2 - BHO: ST - {9394EDE7-C8B5-483E-8773-474BF36AF6E4} - C:\Programme\MSN Apps\ST\01.02.3000.1002\en-xu\stmain.dll O2 - BHO: MSNToolBandBHO - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programme\MSN Apps\MSN Toolbar\01.02.3000.1001\de\msntb.dll O3 - Toolbar: (no name) - {FA3E9B99-962B-4881-8BC1-E2C99DD17A64} - (no file) O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programme\MSN Apps\MSN Toolbar\01.02.3000.1001\de\msntb.dll O3 - Toolbar: My &Search Bar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\Programme\MyWay\myBar\1.bin\MYBAR.DLL O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WIN-XP\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [updmgr] C:\Programme\Common files\updmgr\updmgr.exe O4 - HKLM\..\Run: [iexppress.exe] C:\WIN-XP\system32\iexppress.exe O4 - HKLM\..\Run: [Pop-Up Stopper] "C:\PROGRA~1\PANICW~1\POP-UP~2\dpps2.exe" O4 - HKLM\..\Run: [iTunesHelper] C:\Programme\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WebRebates0] "C:\Programme\Web_Rebates\WebRebates0.exe" O4 - HKLM\..\Run: [UsbD] C:\WIN-XP\system32\iexplore32.exe O4 - HKLM\..\Run: [Winad Client] C:\Program Files\Winad Client\Winad.exe O4 - HKLM\..\Run: [ToADiMon.exe] C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis1\ToADiMon.exe -TOnlineAutodialStart O4 - HKLM\..\Run: [Win Comm] C:\Program Files\Win Comm\WinComm.exe O4 - HKLM\..\Run: [Windows AdControl] C:\Program Files\Windows AdControl\WinAdCtl.exe O4 - HKLM\..\Run: [msnappau] "C:\Programme\MSN Apps\Updater\01.02.3000.1001\de\msnappau.exe" O4 - HKLM\..\Run: [Windows ControlAd] C:\Program Files\Windows ControlAd\WinCtlAd.exe O4 - HKLM\..\Run: [Desktop Search] C:\WIN-XP\isrvs\desktop.exe O4 - HKLM\..\Run: [ffis] C:\WIN-XP\isrvs\ffisearch.exe O4 - HKLM\..\Run: [Admilli Service] C:\Program Files\Admilli Service\AdmilliServ.exe O4 - HKLM\..\Run: [Windows ServeAd] C:\Program Files\Windows ServeAd\WinServAd.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min O4 - HKCU\..\Run: [ctfmon.exe] C:\WIN-XP\system32\ctfmon.exe O4 - Global Startup: AutoStart IR.lnk = C:\Programme\WinTV\ir.exe O4 - Global Startup: LimeWire 4.0.7.lnk = C:\Programme\LimeWire\LimeWire 4.0.7\LimeWire.exe O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MI1933~1\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WIN-XP\system32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WIN-XP\system32\msjava.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Programme\AIM95\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O16 - DPF: {15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://public.windupdates.com/get_fi...43a6e253a2dae7 O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - http://toolbar.isearch.com/general/drm.cab O16 - DPF: {1D6711C8-7154-40BB-8380-3DEA45B69CBF} - O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/021e0f24...dxIE601_de.cab O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} (Installer Class) - http://www.ysbweb.com/ist/softwares/...sb_regular.cab O16 - DPF: {99802379-7362-40E2-9D28-8A3B9AF880B7} - http://hotsearchbar.com/toolbar2/winhot32.cab O16 - DPF: {B020B534-4AA2-4B99-BD6D-5F6EE286DF5C} (Symantec Download Bridge) - http://www2.service.t-online.de/dyn/...5/2334156.html O16 - DPF: {FE1A240F-B247-4E06-A600-30E28F5AF3A0} - file://C:\install.cab O17 - HKLM\System\CCS\Services\Tcpip\..\{ED267571-7341-49CC-AB71-622FC87C9616}: NameServer = 217.237.151.225 217.237.150.225 O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WIN-XP\isrvs\mfiltis.dll O23 - Service: AntiVir Service - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WIN-XP\system32\drivers\CDAC11BA.EXE O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WIN-XP\System32\nvsvc32.exe O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe |
25.01.2005, 12:32 | #4 |
| C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.A Hi sgd_support, Du hast u.a. den hier drauf http://www.sophos.de/virusinfo/analyses/w32sdbotjy.html. Da hilft nur noch "format c:". Verfahre so wie hier beschrieben: http://www.trojaner-info.de/report_i...nleitung.shtml. dartus |
25.01.2005, 13:54 | #5 |
| C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.A Willst du mich verarschen ? Es muss doch noch irgend ne andere Möglichkeit geben , oder ? |
25.01.2005, 14:25 | #6 | |
C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.A Du kannst Dir die 'Meinung' eines 2. Virenscanners einholen. Scanne mal mit eScan (siehe Signatur). Aber ich fürchte, dartus hat Recht. Zitat:
__________________ --> C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.A |
12.02.2005, 13:18 | #7 |
| C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.A Hallo ich habe das selbe problem. hier mein logfile: Logfile of HijackThis v1.99.0 Scan saved at 13:12:46, on 12.02.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\svqqluf.exe C:\WINDOWS\isrvs\desktop.exe C:\WINDOWS\system32\ctfmon.exe D:\Valve\Steam\Steam.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe D:\Programme\Norton AntiVirus\navapsvc.exe D:\Programme\Spy\SpySub.exe C:\WINDOWS\System32\nvsvc32.exe D:\Programme\ICQ\ICQ.exe D:\Programme\Norton AntiVirus\SAVScan.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe C:\WINDOWS\system32\wuauclt.exe C:\Programme\Internet Explorer\iexplore.exe D:\Programme\GetRight\GETRIGHT.EXE C:\Programme\Messenger\msmsgs.exe D:\PROGRA~1\WINZIP\winzip32.exe D:\Programme\hijackthis199\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ O2 - BHO: (no name) - {000020DD-C72E-4113-AF77-DD56626C6C42} - (no file) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Var1Helper Class - {1C4DA27D-4D52-4465-A089-98E01BB725CA} - C:\WINDOWS\System32\inetdctr.dll O2 - BHO: IE Update Class - {5B4AB8E2-6DC5-477A-B637-BF3C1A2E5993} - C:\WINDOWS\isrvs\sysupd.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar1.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - D:\Programme\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - D:\Programme\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar1.dll O4 - HKLM\..\Run: [Mirabilis ICQ] D:\Programme\ICQ\ICQNet.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [I-Services] C:\WINDOWS\System32\os2\svchost.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [dlr] C:\WINDOWS\netstat.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [RunDLL] rundll32.exe "C:\WINDOWS\System32\bridge.dll",Load O4 - HKLM\..\Run: [intdctrr] C:\WINDOWS\System32\idctup20.exe O4 - HKLM\..\Run: [QuickTime Task] "D:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [gnlyokqvkoy] C:\WINDOWS\System32\svqqluf.exe O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe O4 - HKLM\..\Run: [Desktop Search] C:\WINDOWS\isrvs\desktop.exe O4 - HKLM\..\Run: [ffis] C:\WINDOWS\isrvs\ffisearch.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [PrivacyScanner] C:\Programme\Privacy Champion\pscan.exe O4 - HKCU\..\Run: [Steam] D:\Valve\Steam\\Steam.exe -silent O4 - HKCU\..\RunOnce: [ICQ] D:\Programme\ICQ\ICQ.exe -trayboot O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE O4 - Global Startup: SpySubtract.lnk = D:\Programme\Spy\SpySub.exe O8 - Extra context menu item: &Google Search - res://c:\programme\google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: Download with GetRight - D:\Programme\GetRight\GRdownload.htm O8 - Extra context menu item: Im Cache gespeicherte Seite - res://c:\programme\google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Open with GetRight Browser - D:\Programme\GetRight\GRbrowse.htm O8 - Extra context menu item: Verweisseiten - res://c:\programme\google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Ähnliche Seiten - res://c:\programme\google\GoogleToolbar1.dll/cmsimilar.html O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Programme\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - D:\Programme\ICQ\ICQ.exe O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - D:\Programme\AIM95\aim.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/tech...a/LSSupCtl.cab O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/...eInstaller.exe O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-17.cab O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...a/SymAData.cab O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - C:\WINDOWS\isrvs\mfiltis.dll O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe O23 - Service: ISEXEng - Unknown - C:\WINDOWS\system32\angelex.exe (file missing) O23 - Service: Norton AntiVirus Auto-Protect-Dienst - Symantec Corporation - D:\Programme\Norton AntiVirus\navapsvc.exe O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SAVScan - Symantec Corporation - D:\Programme\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe könnt ihr mir da auch weiterhelfen? wäre wirklich sehr nett! |
12.02.2005, 13:27 | #8 |
| C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.A @Marius lade escan download anleitung überprüfe Deinen Rechner zunächst mit dem eScan: lade den eScan runter, erstelle dafür einen Ordner (=Verzeichnis) c:\bases, update den eScan online und führe ihn offline im abgesicherten Modus aus. Beachte, dass der eScan ab Version 4.5.1 gefundene Malware nicht löscht. Das wird von Hand auf Anweisung durch uns gemacht. Teile uns dann das Ergebnis des eScan mit: welche Viren wurden auf Deinem Rechner gefunden: "öffne die mwav.log -> Bearbeiten -> Suchen -> infected eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen." (Zitat Cidre) chaosman
__________________ Bonus vir semper tiro |
12.02.2005, 13:49 | #9 |
| C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.A danke. führe gerade die updates online durch. das programm danach offline im abgesicherten modus ausführen. wie führe ich es im abgesicherten modus aus? danke! mfg Marius |
12.02.2005, 16:08 | #10 |
| C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.A so escan ist abgeschlossen im normalen windows modus... (ist das ein problem?) [EDIT] Sat Feb 12 15:05:32 2005 => ********************************************************** Sat Feb 12 15:05:32 2005 => eScan AntiVirus Toolkit Utility. Sat Feb 12 15:05:32 2005 => Copyright © 2003-2004, MicroWorld Technologies Inc. Sat Feb 12 15:05:32 2005 => ********************************************************** Sat Feb 12 15:05:32 2005 => Version 4.8.7 (C:\bases\mwavscan.com) Sat Feb 12 15:05:32 2005 => Log File: C:\bases\MWAV.LOG Sat Feb 12 15:05:32 2005 => Latest Date of files inside MWAV: 12 Feb 2005 14:40:12. Sat Feb 12 15:05:33 2005 => AV Library Loaded... Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\kavss.exe Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\Getvlist.exe Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\kavss.dll Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\kavssdi.dll Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\kavssi.dll Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\kavvlg.dll Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\msvlclnt.dll Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\ipc.dll Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\main.avi Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\virus.avi Sat Feb 12 15:05:34 2005 => Virus Database Date: 2005/02/12 Sat Feb 12 15:05:34 2005 => Virus Database Count: 118054 Sat Feb 12 15:06:05 2005 => ********************************************************** Sat Feb 12 15:06:05 2005 => eScan AntiVirus Toolkit Utility. Sat Feb 12 15:06:05 2005 => Copyright © 2003-2004, MicroWorld Technologies Inc. Sat Feb 12 15:06:05 2005 => Sat Feb 12 15:06:05 2005 => Support: support@mwti.net Sat Feb 12 15:06:05 2005 => Web: http://www.mwti.net Sat Feb 12 15:06:05 2005 => ********************************************************** Sat Feb 12 15:06:05 2005 => Version 4.8.7 (C:\bases\mwavscan.com) Sat Feb 12 15:06:05 2005 => Log File: C:\bases\MWAV.LOG Sat Feb 12 15:06:05 2005 => Windows Root Folder: C:\WINDOWS Sat Feb 12 15:06:05 2005 => Windows Sys32 Folder: C:\WINDOWS\system32 Sat Feb 12 15:06:05 2005 => OS: Windows NT Sat Feb 12 15:06:05 2005 => Latest Date of files inside MWAV: 12 Feb 2005 14:40:12. Sat Feb 12 15:06:05 2005 => Options Selected by User: Sat Feb 12 15:06:05 2005 => Memory Check: Enabled Sat Feb 12 15:06:05 2005 => Registry Check: Enabled Sat Feb 12 15:06:05 2005 => StartUp Folder Check: Enabled Sat Feb 12 15:06:05 2005 => System Folder Check: Enabled Sat Feb 12 15:06:05 2005 => System Area Check: Disabled Sat Feb 12 15:06:05 2005 => Services Check: Enabled Sat Feb 12 15:06:05 2005 => Drive Check: Disabled Sat Feb 12 15:06:05 2005 => All Drive Check :Enabled Sat Feb 12 15:06:05 2005 => Folder Check: Disabled Sat Feb 12 15:06:05 2005 => ***** Scanning Memory Files ***** Sat Feb 12 15:06:05 2005 => Scanning File C:\WINDOWS\System32\smss.exe etc... [EDIT ende] File C:\WINDOWS\System32\bridge.dll infected by "Trojan-Spy.Win32.Briss.h" Virus. Action Taken: No Action Taken. File C:\WINDOWS\isrvs\desktop.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\isrvs\mfiltis.dll infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\inetdctr.dll infected by "not-a-virus:AdWare.SafeSurfing.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\commcoss.dll infected by "not-a-virus:AdWare.SafeSurfing.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\inetdctr.dll infected by "not-a-virus:AdWare.SafeSurfing.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\netstat.exe infected by "not-a-virus:PornWare.Dialer.RzDialer" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\idctup20.exe infected by "not-a-virus:AdWare.SafeSurfing.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\isrvs\desktop.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\drivers\delprot.sys infected by "Trojan.Win32.Delprot.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\twaintec.dll infected by "not-a-virus:AdWare.BiSpy.t" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\bridge.dll infected by "Trojan-Spy.Win32.Briss.h" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\commcoss.dll infected by "not-a-virus:AdWare.SafeSurfing.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\inst\3p1.exe infected by "Trojan-Downloader.Win32.Agent.hw" Virus. Action Taken: No Action Taken. File C:\WINDOWS\inst\3p2.exe infected by "Trojan-Downloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken. File C:\WINDOWS\isrvs\delprot.sys infected by "Trojan.Win32.Delprot.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\isrvs\mfiltis.dll infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\bridge.dll infected by "Trojan-Spy.Win32.Briss.h" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\commcoss.dll infected by "not-a-virus:AdWare.SafeSurfing.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\Temp\lol.bat infected by "IRC-Worm.Win32.Fedix.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\twaintec.dll infected by "not-a-virus:AdWare.BiSpy.t" Virus. Action Taken: No Action Taken. File D:\Programm\DivX\DivX Player 2.1\uninstall.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File D:\Programme\mIRC\mirc.exe tagged as not-a-virus:RiskWare.mIRC.6.03. No Action Taken. File D:\Util\DivXPro501GAINBundle.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File D:\Util\DivXPro5GAINBundle.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File D:\Util\getrt45d.exe infected by "not-a-virus:AdWare.Gator.1050" Virus. Action Taken: No Action Taken. File D:\Util\girc30.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Geändert von Marius (12.02.2005 um 17:18 Uhr) |
13.02.2005, 11:22 | #11 |
| C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.A so ich habe nach diversen verschiedenen antispy/virusprogrammausführungen nun nochmal escan laufen lassen mit diesem ergebnis: Sat Feb 12 15:05:32 2005 => ********************************************************** Sat Feb 12 15:05:32 2005 => eScan AntiVirus Toolkit Utility. Sat Feb 12 15:05:32 2005 => Copyright © 2003-2004, MicroWorld Technologies Inc. Sat Feb 12 15:05:32 2005 => ********************************************************** Sat Feb 12 15:05:32 2005 => Version 4.8.7 (C:\bases\mwavscan.com) Sat Feb 12 15:05:32 2005 => Log File: C:\bases\MWAV.LOG Sat Feb 12 15:05:32 2005 => Latest Date of files inside MWAV: 12 Feb 2005 14:40:12. Sat Feb 12 15:05:33 2005 => AV Library Loaded... Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\kavss.exe Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\Getvlist.exe Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\kavss.dll Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\kavssdi.dll Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\kavssi.dll Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\kavvlg.dll Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\msvlclnt.dll Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\ipc.dll Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\main.avi Sat Feb 12 15:05:33 2005 => Scanning File C:\bases\virus.avi Sat Feb 12 15:05:34 2005 => Virus Database Date: 2005/02/12 Sat Feb 12 15:05:34 2005 => Virus Database Count: 118054 Sat Feb 12 15:06:05 2005 => ********************************************************** Sat Feb 12 15:06:05 2005 => eScan AntiVirus Toolkit Utility. Sat Feb 12 15:06:05 2005 => Copyright © 2003-2004, MicroWorld Technologies Inc. Sat Feb 12 15:06:05 2005 => Sat Feb 12 15:06:05 2005 => Support: support@mwti.net Sat Feb 12 15:06:05 2005 => Web: http://www.mwti.net Sat Feb 12 15:06:05 2005 => ********************************************************** Sat Feb 12 15:06:05 2005 => Version 4.8.7 (C:\bases\mwavscan.com) Sat Feb 12 15:06:05 2005 => Log File: C:\bases\MWAV.LOG Sat Feb 12 15:06:05 2005 => Windows Root Folder: C:\WINDOWS Sat Feb 12 15:06:05 2005 => Windows Sys32 Folder: C:\WINDOWS\system32 Sat Feb 12 15:06:05 2005 => OS: Windows NT Sat Feb 12 15:06:05 2005 => Latest Date of files inside MWAV: 12 Feb 2005 14:40:12. Sat Feb 12 15:06:05 2005 => Options Selected by User: Sat Feb 12 15:06:05 2005 => Memory Check: Enabled Sat Feb 12 15:06:05 2005 => Registry Check: Enabled Sat Feb 12 15:06:05 2005 => StartUp Folder Check: Enabled Sat Feb 12 15:06:05 2005 => System Folder Check: Enabled Sat Feb 12 15:06:05 2005 => System Area Check: Disabled Sat Feb 12 15:06:05 2005 => Services Check: Enabled Sat Feb 12 15:06:05 2005 => Drive Check: Disabled Sat Feb 12 15:06:05 2005 => All Drive Check :Enabled Sat Feb 12 15:06:05 2005 => Folder Check: Disabled Sat Feb 12 15:06:05 2005 => ***** Scanning Memory Files ***** . . . File C:\WINDOWS\system32\commcoss.dll infected by "not-a-virus:AdWare.SafeSurfing.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\inetdctr.dll infected by "not-a-virus:AdWare.SafeSurfing.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\commcoss.dll infected by "not-a-virus:AdWare.SafeSurfing.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\drivers\delprot.sys infected by "Trojan.Win32.Delprot.a" Virus. Action Taken: No Action Taken. File C:\WINDOWS\system32\inetdctr.dll infected by "not-a-virus:AdWare.SafeSurfing.a" Virus. Action Taken: No Action Taken. File D:\Programm\DivX\DivX Player 2.1\uninstall.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File D:\Programme\mIRC\mirc.exe tagged as not-a-virus:RiskWare.mIRC.6.03. No Action Taken. File D:\Programme\Norton AntiVirus\Quarantine\0C9C53EE infected by "Email-Worm.Win32.NetSky.d" Virus. Action Taken: No Action Taken. File D:\Programme\Norton AntiVirus\Quarantine\0CA97BE0 infected by "Email-Worm.Win32.NetSky.d" Virus. Action Taken: No Action Taken. File D:\Programme\Norton AntiVirus\Quarantine\0CB94DCE infected by "Email-Worm.Win32.NetSky.d" Virus. Action Taken: No Action Taken. File D:\Programme\Norton AntiVirus\Quarantine\1A291103 infected by "Email-Worm.Win32.NetSky.d" Virus. Action Taken: No Action Taken. File D:\Programme\Norton AntiVirus\Quarantine\20900564 infected by "Email-Worm.Win32.NetSky.d" Virus. Action Taken: No Action Taken. File D:\Programme\Norton AntiVirus\Quarantine\20C17B2E infected by "Email-Worm.Win32.NetSky.d" Virus. Action Taken: No Action Taken. File D:\Programme\Norton AntiVirus\Quarantine\29EB743D infected by "Email-Worm.Win32.NetSky.d" Virus. Action Taken: No Action Taken. File D:\Programme\Norton AntiVirus\Quarantine\48454EDC infected by "Email-Worm.Win32.NetSky.d" Virus. Action Taken: No Action Taken. File D:\Programme\Norton AntiVirus\Quarantine\48D84B93.exe infected by "Trojan-Dropper.Win32.Delf.z" Virus. Action Taken: No Action Taken. File D:\Programme\Norton AntiVirus\Quarantine\4C9C33CD.exe infected by "Trojan-Dropper.Win32.Delf.z" Virus. Action Taken: No Action Taken. File D:\Programme\Norton AntiVirus\Quarantine\79BC3A6C infected by "Email-Worm.Win32.NetSky.d" Virus. Action Taken: No Action Taken. File D:\Util\DivXPro501GAINBundle.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File D:\Util\DivXPro5GAINBundle.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. File D:\Util\getrt45d.exe infected by "not-a-virus:AdWare.Gator.1050" Virus. Action Taken: No Action Taken. File D:\Util\girc30.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. es sind wohl nur die ersten 5 interessant kann man da noch was machen? danke für eure hilfe!!! |
Themen zu C:\WIN-XP\ISRVS\SYSUPD.DLL Ist das Trojanische Pferd TR/Dldr.Ieser.A |
ahnung, antivir, freue, immer wieder, inter, interne, internet, lahm, pferd, probiert, total, troja, trojanische, trojanische pferd |