|
Log-Analyse und Auswertung: 01 - Einträge lassen sich nicht fixen!!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
25.01.2005, 21:31 | #16 |
| 01 - Einträge lassen sich nicht fixen!! Tue Jan 25 17:35:33 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\HFF1VXZ4\*.* Tue Jan 25 17:35:33 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\HFF1VXZ4\Place=popup1&transactionID=1083930222468&Site=wettercom&SubSite=wetter&SubSubSite=deutschlandwetter&SubSubSubSite=home&flas hversion=7&tpic=0n1y2y3y&ttempmin Tue Jan 25 17:35:33 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:33 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\HFF1VXZ4\Place=popup1&transactionID=1083930222468&Site=wettercom&SubSite=wetter&SubSubSite=deutschlandwetter&SubSubSubSite=home&flas hversion=7&tpic=0n1y2y3y&ttempmin possibly infected and removed by background antivirus package! Tue Jan 25 17:35:33 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\HFF1VXZ4\Place=squarebutton1&transactionID=1084009418109&Site=wettercom&SubSite=home&SubSubSite=home&SubSubSubSite=home&flashversion =7&sowefo_ausschluss=powerlayer_p Tue Jan 25 17:35:33 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:33 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\HFF1VXZ4\Place=squarebutton1&transactionID=1084009418109&Site=wettercom&SubSite=home&SubSubSite=home&SubSubSubSite=home&flashversion =7&sowefo_ausschluss=powerlayer_p possibly infected and removed by background antivirus package! Tue Jan 25 17:35:33 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\IJMVMF2L\*.* Tue Jan 25 17:35:34 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\IJMVMF2L\Place=fullbanner2&transactionID=1083930256687&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&tp ic=0y1n2y3n&ttempmin=1n2n3n4y5n6n Tue Jan 25 17:35:34 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:34 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\IJMVMF2L\Place=fullbanner2&transactionID=1083930256687&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&tp ic=0y1n2y3n&ttempmin=1n2n3n4y5n6n possibly infected and removed by background antivirus package! Tue Jan 25 17:35:34 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\IJMVMF2L\Place=fullbanner2&transactionID=1085217188609&Site=pro7de&SubSite=programmguide&SubSubSite=home&flashversion=7&windowheight =429&windowwidth=761&adsize=468x6 Tue Jan 25 17:35:34 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:34 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\IJMVMF2L\Place=fullbanner2&transactionID=1085217188609&Site=pro7de&SubSite=programmguide&SubSubSite=home&flashversion=7&windowheight =429&windowwidth=761&adsize=468x6 possibly infected and removed by background antivirus package! Tue Jan 25 17:35:34 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\IJMVMF2L\Place=rectangle2&transactionID=1085907836875&Site=sat1de&SubSite=home&SubSubSite=home&SubSubSubSite=home&flashversion=7&win dowheight=1&windowwidth=761&sowef Tue Jan 25 17:35:34 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:34 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\IJMVMF2L\Place=rectangle2&transactionID=1085907836875&Site=sat1de&SubSite=home&SubSubSite=home&SubSubSubSite=home&flashversion=7&win dowheight=1&windowwidth=761&sowef possibly infected and removed by background antivirus package! Tue Jan 25 17:35:34 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Tue Jan 25 17:35:34 2005 => Result: ERROR!!! File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat: Scanning Failure!!! Tue Jan 25 17:35:34 2005 => ERROR!!! ScanFile fails for C:\DOKUME~1\Hosna\LOKALE~1\TEMPOR~1\Content.IE5\index.dat Tue Jan 25 17:35:34 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\K32FU54Z\*.* Tue Jan 25 17:35:34 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\K32FU54Z\Place=fullbanner2&transactionID=1083930265140&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&tp ic=0n1y2n3n&ttempmin=1n2n3n4n5y6n Tue Jan 25 17:35:34 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:34 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\K32FU54Z\Place=fullbanner2&transactionID=1083930265140&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&tp ic=0n1y2n3n&ttempmin=1n2n3n4n5y6n possibly infected and removed by background antivirus package! Tue Jan 25 17:35:34 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\K32FU54Z\Place=squarebutton1&transactionID=1083930238875&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast& flashversion=7&tpic=0y1y2y3n&ttem Tue Jan 25 17:35:34 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:34 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\K32FU54Z\Place=squarebutton1&transactionID=1083930238875&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast& flashversion=7&tpic=0y1y2y3n&ttem possibly infected and removed by background antivirus package! Tue Jan 25 17:35:34 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\K32FU54Z\Place=squarebutton1&transactionID=1084009433578&Site=wettercom&SubSite=reise&SubSubSite=reisewetter&SubSubSubSite=home&flas hversion=7&sowefo_ausschluss=powe Tue Jan 25 17:35:34 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:34 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\K32FU54Z\Place=squarebutton1&transactionID=1084009433578&Site=wettercom&SubSite=reise&SubSubSite=reisewetter&SubSubSubSite=home&flas hversion=7&sowefo_ausschluss=powe possibly infected and removed by background antivirus package! Tue Jan 25 17:35:34 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KD2B8XIJ\*.* Tue Jan 25 17:35:34 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KD2B8XIJ\Place=fullbanner1&transactionID=1085907836875&Site=sat1de&SubSite=home&SubSubSite=home&SubSubSubSite=home&flashversion=7&wi ndowheight=1&windowwidth=761&sowe Tue Jan 25 17:35:34 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:34 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KD2B8XIJ\Place=fullbanner1&transactionID=1085907836875&Site=sat1de&SubSite=home&SubSubSite=home&SubSubSubSite=home&flashversion=7&wi ndowheight=1&windowwidth=761&sowe possibly infected and removed by background antivirus package! Tue Jan 25 17:35:35 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KD2B8XIJ\Place=squarebutton1&transactionID=1083930230500&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=current&f lashversion=7&sowefo_ausschluss=p Tue Jan 25 17:35:35 2005 => ERROR!!! MS_ScanAndClean return ffffffff |
25.01.2005, 21:32 | #17 |
| 01 - Einträge lassen sich nicht fixen!! TUT MIR LEID; ES SIND SO VIELE GEWESEN:
__________________Tue Jan 25 17:35:35 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KD2B8XIJ\Place=squarebutton1&transactionID=1083930230500&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=current&f lashversion=7&sowefo_ausschluss=p possibly infected and removed by background antivirus package! Tue Jan 25 17:35:35 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KD2B8XIJ\Place=squarebutton1&transactionID=1083930269656&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast& flashversion=7&tpic=0n1n2y3n&ttem Tue Jan 25 17:35:35 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:35 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KD2B8XIJ\Place=squarebutton1&transactionID=1083930269656&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast& flashversion=7&tpic=0n1n2y3n&ttem possibly infected and removed by background antivirus package! Tue Jan 25 17:35:35 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KD2B8XIJ\Place=squarebutton1&transactionID=1085217188609&Site=pro7de&SubSite=programmguide&SubSubSite=home&flashversion=7&windowheig ht=429&windowwidth=761&sowefo_aus Tue Jan 25 17:35:35 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:35 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KD2B8XIJ\Place=squarebutton1&transactionID=1085217188609&Site=pro7de&SubSite=programmguide&SubSubSite=home&flashversion=7&windowheig ht=429&windowwidth=761&sowefo_aus possibly infected and removed by background antivirus package! Tue Jan 25 17:35:35 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KHUZ4PAN\*.* Tue Jan 25 17:35:35 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KHUZ4PAN\Place=fullbanner2&transactionID=1083930270640&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&tp ic=0n1n2y3n&ttempmin=1n2n3n4n5y6n Tue Jan 25 17:35:35 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:35 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KHUZ4PAN\Place=fullbanner2&transactionID=1083930270640&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&tp ic=0n1n2y3n&ttempmin=1n2n3n4n5y6n possibly infected and removed by background antivirus package! Tue Jan 25 17:35:35 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KP2VKX2Z\*.* Tue Jan 25 17:35:35 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KP2VKX2Z\Place=fullbanner2&transactionID=1084009435375&Site=wettercom&SubSite=reise&SubSubSite=reisewetter&SubSubSubSite=home&tpic=0 y1y2n3n&ttempmin=1n2n3n4n5y6y7n8n Tue Jan 25 17:35:35 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:35 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KP2VKX2Z\Place=fullbanner2&transactionID=1084009435375&Site=wettercom&SubSite=reise&SubSubSite=reisewetter&SubSubSubSite=home&tpic=0 y1y2n3n&ttempmin=1n2n3n4n5y6y7n8n possibly infected and removed by background antivirus package! Tue Jan 25 17:35:35 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KP2VKX2Z\Place=popup1&transactionID=1085217188609&Site=pro7de&SubSite=programmguide&SubSubSite=home&flashversion=7&windowheight=429& windowwidth=761&sowefo_ausschluss Tue Jan 25 17:35:35 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:35 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\KP2VKX2Z\Place=popup1&transactionID=1085217188609&Site=pro7de&SubSite=programmguide&SubSubSite=home&flashversion=7&windowheight=429& windowwidth=761&sowefo_ausschluss possibly infected and removed by background antivirus package! Tue Jan 25 17:35:35 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LO8NLXST\*.* Tue Jan 25 17:35:36 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LO8NLXST\Place=fullbanner2&transactionID=1083930233921&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&tp ic=0y1y2y3n&ttempmin=1n2n3n4y5n6n Tue Jan 25 17:35:36 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:36 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LO8NLXST\Place=fullbanner2&transactionID=1083930233921&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&tp ic=0y1y2y3n&ttempmin=1n2n3n4y5n6n possibly infected and removed by background antivirus package! Tue Jan 25 17:35:36 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LO8NLXST\Place=fullbanner2&transactionID=1084009431437&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=home&adsize =468x60&tagheight=60&tagwidth=468 Tue Jan 25 17:35:36 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:36 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LO8NLXST\Place=fullbanner2&transactionID=1084009431437&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=home&adsize =468x60&tagheight=60&tagwidth=468 possibly infected and removed by background antivirus package! Tue Jan 25 17:35:36 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LO8NLXST\Place=popup1&transactionID=1083930230500&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=current&flashver sion=7&tpic=0n1y2n3n&ttempmin=1n2 Tue Jan 25 17:35:36 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:36 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LO8NLXST\Place=popup1&transactionID=1083930230500&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=current&flashver sion=7&tpic=0n1y2n3n&ttempmin=1n2 possibly infected and removed by background antivirus package! Tue Jan 25 17:35:36 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LO8NLXST\Place=popup1&transactionID=1085217183500&Site=pro7de&SubSite=home&SubSubSite=home&flashversion=7&windowheight=429&windowwid th=761&sowefo_ausschluss=powerlay Tue Jan 25 17:35:36 2005 => ERROR!!! MS_ScanAndClean return ffffffff |
25.01.2005, 21:32 | #18 |
| 01 - Einträge lassen sich nicht fixen!! Tue Jan 25 17:35:36 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\LO8NLXST\Place=popup1&transactionID=1085217183500&Site=pro7de&SubSite=home&SubSubSite=home&flashversion=7&windowheight=429&windowwid th=761&sowefo_ausschluss=powerlay possibly infected and removed by background antivirus package!
__________________Tue Jan 25 17:35:37 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\PXLJYUBA\Place=fullbanner1&transactionID=1085217188609&Site=pro7de&SubSite=programmguide&SubSubSite=home&flashversion=7&windowheight =429&windowwidth=761&sowefo_aussc Tue Jan 25 17:35:37 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:37 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\PXLJYUBA\Place=fullbanner1&transactionID=1085217188609&Site=pro7de&SubSite=programmguide&SubSubSite=home&flashversion=7&windowheight =429&windowwidth=761&sowefo_aussc possibly infected and removed by background antivirus package! Tue Jan 25 17:35:37 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\UDJ858V2\*.* Tue Jan 25 17:35:37 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\UDJ858V2\Place=popup1&transactionID=1083930255515&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&flashve rsion=7&tpic=0y1n2y3n&ttempmin=1n Tue Jan 25 17:35:37 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:37 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\UDJ858V2\Place=popup1&transactionID=1083930255515&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&flashve rsion=7&tpic=0y1n2y3n&ttempmin=1n possibly infected and removed by background antivirus package! Tue Jan 25 17:35:37 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\UDJ858V2\Place=squarebutton1&transactionID=1084009421953&Site=wettercom&SubSite=wetter&SubSubSite=home&SubSubSubSite=home&flashversi on=7&sowefo_ausschluss=powerlayer Tue Jan 25 17:35:37 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:37 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\UDJ858V2\Place=squarebutton1&transactionID=1084009421953&Site=wettercom&SubSite=wetter&SubSubSite=home&SubSubSubSite=home&flashversi on=7&sowefo_ausschluss=powerlayer possibly infected and removed by background antivirus package! Tue Jan 25 17:35:37 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\VKTL5HFL\*.* Tue Jan 25 17:35:37 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\VKTL5HFL\desktop.ini Tue Jan 25 17:35:38 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\VYJ9GOW5\*.* Tue Jan 25 17:35:38 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\VYJ9GOW5\Place=popup1&transactionID=1083930225234&Site=wettercom&SubSite=wetter&SubSubSite=deutschlandwetter&SubSubSubSite=home&flas hversion=7&tpic=0n1n2y3y&ttempmin Tue Jan 25 17:35:38 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:38 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\VYJ9GOW5\Place=popup1&transactionID=1083930225234&Site=wettercom&SubSite=wetter&SubSubSite=deutschlandwetter&SubSubSubSite=home&flas hversion=7&tpic=0n1n2y3y&ttempmin possibly infected and removed by background antivirus package! Tue Jan 25 17:35:38 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\W1Y3GTEJ\*.* Tue Jan 25 17:35:38 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\W1Y3GTEJ\member;dcopt=ist;kw=snoopy+gifs;h=misc;sz=468x60;!category=adult;!category=sexualovertones;!category=gaming;!category=tobac co;!category=adult;!category=sexu Tue Jan 25 17:35:38 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:38 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\W1Y3GTEJ\member;dcopt=ist;kw=snoopy+gifs;h=misc;sz=468x60;!category=adult;!category=sexualovertones;!category=gaming;!category=tobac co;!category=adult;!category=sexu possibly infected and removed by background antivirus package! Tue Jan 25 17:35:38 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\W1Y3GTEJ\member;dcopt=ist;kw=snoopy+gifs;h=misc;sz=468x60;!category=adult;!category=sexualovertones;!category=gaming;!category=tobac co;!category=adult;!category=sexu Tue Jan 25 17:35:38 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:38 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\W1Y3GTEJ\member;dcopt=ist;kw=snoopy+gifs;h=misc;sz=468x60;!category=adult;!category=sexualovertones;!category=gaming;!category=tobac co;!category=adult;!category=sexu possibly infected and removed by background antivirus package! |
25.01.2005, 21:33 | #19 |
| 01 - Einträge lassen sich nicht fixen!! Tue Jan 25 17:35:38 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\W1Y3GTEJ\Place=fullbanner2&transactionID=1083930245812&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&tp ic=0y1n2n3y&ttempmin=1n2n3n4n5y6n Tue Jan 25 17:35:38 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:38 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\W1Y3GTEJ\Place=fullbanner2&transactionID=1083930245812&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&tp ic=0y1n2n3y&ttempmin=1n2n3n4n5y6n possibly infected and removed by background antivirus package! Tue Jan 25 17:35:38 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\W1Y3GTEJ\Place=fullbanner2&transactionID=1084009425359&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=home&adsize =468x60&tagheight=60&tagwidth=468 Tue Jan 25 17:35:38 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:38 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\W1Y3GTEJ\Place=fullbanner2&transactionID=1084009425359&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=home&adsize =468x60&tagheight=60&tagwidth=468 possibly infected and removed by background antivirus package! Tue Jan 25 17:35:38 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\WTMJCPMB\*.* Tue Jan 25 17:35:38 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\WTMJCPMB\Place=fullbanner2&transactionID=1083930224312&Site=wettercom&SubSite=wetter&SubSubSite=deutschlandwetter&SubSubSubSite=home &tpic=0n1y2y3y&ttempmin=1n2n3n4y5 Tue Jan 25 17:35:38 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:38 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\WTMJCPMB\Place=fullbanner2&transactionID=1083930224312&Site=wettercom&SubSite=wetter&SubSubSite=deutschlandwetter&SubSubSubSite=home &tpic=0n1y2y3y&ttempmin=1n2n3n4y5 possibly infected and removed by background antivirus package! Tue Jan 25 17:35:38 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\WTMJCPMB\Place=fullbanner2&transactionID=1083930239843&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&tp ic=0y1y2y3n&ttempmin=1n2n3n4n5y6n Tue Jan 25 17:35:38 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:38 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\WTMJCPMB\Place=fullbanner2&transactionID=1083930239843&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast&tp ic=0y1y2y3n&ttempmin=1n2n3n4n5y6n possibly infected and removed by background antivirus package! Tue Jan 25 17:35:38 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\Y8AX7L88\*.* Tue Jan 25 17:35:39 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\Y8AX7L88\Place=squarebutton1&transactionID=1083930252328&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast& flashversion=7&tpic=0y1n2y3n&ttem Tue Jan 25 17:35:39 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:39 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\Y8AX7L88\Place=squarebutton1&transactionID=1083930252328&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=forecast& flashversion=7&tpic=0y1n2y3n&ttem possibly infected and removed by background antivirus package! Tue Jan 25 17:35:39 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YNKBN4XO\*.* Tue Jan 25 17:35:39 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YNKBN4XO\Place=squarebutton1&transactionID=1084009426406&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=home&flas hversion=7&sowefo_ausschluss=powe Tue Jan 25 17:35:39 2005 => ERROR!!! MS_ScanAndClean return ffffffff Tue Jan 25 17:35:39 2005 => C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YNKBN4XO\Place=squarebutton1&transactionID=1084009426406&Site=wettercom&SubSite=wetter&SubSubSite=weltwetter&SubSubSubSite=home&flas hversion=7&sowefo_ausschluss=powe possibly infected and removed by background antivirus package! Tue Jan 25 17:35:39 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Temporary Internet Files\desktop.ini Tue Jan 25 17:35:39 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Verlauf\*.* Tue Jan 25 17:35:39 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Verlauf\desktop.ini Tue Jan 25 17:35:39 2005 => Scanning Folder: C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Verlauf\History.IE5\*.* Tue Jan 25 17:35:39 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Verlauf\History.IE5\desktop.ini Tue Jan 25 17:35:39 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Verlauf\History.IE5\index.dat Tue Jan 25 17:35:39 2005 => Result: ERROR!!! File C:\Dokumente und Einstellungen\Hosna\Lokale Einstellungen\Verlauf\History.IE5\index.dat: Scanning Failure!!! Tue Jan 25 17:35:39 2005 => ERROR!!! ScanFile fails for C:\DOKUME~1\Hosna\LOKALE~1\Verlauf\History.IE5\index.dat Tue Jan 25 17:35:41 2005 => *** File C:\Dokumente und Einstellungen\Hosna\NTUSER.DAT having Size Restriction *** Tue Jan 25 17:35:41 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\NTUSER.DAT [**] Tue Jan 25 17:35:41 2005 => Scanning File C:\Dokumente und Einstellungen\Hosna\ntuser.dat.LOG Tue Jan 25 17:35:41 2005 => Result: ERROR!!! File C:\Dokumente und Einstellungen\Hosna\ntuser.dat.LOG: Scanning Failure!!! Tue Jan 25 17:35:41 2005 => ERROR!!! ScanFile fails for C:\DOKUME~1\Hosna\NTUSER~1.LOG Tue Jan 25 17:35:59 2005 => File C:\ntdetect.hta infected by "Trojan-Dropper.VBS.Inor.cj" Virus. Action Taken: File Deleted. Tue Jan 25 17:36:36 2005 => File C:\Programme\AVPersonal\INFECTED\IPSSNU.DLL.001 infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: File Deleted. Tue Jan 25 17:36:36 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\IPSSNU.DLL.VIR Tue Jan 25 17:36:36 2005 => File C:\Programme\AVPersonal\INFECTED\IPSSNU.DLL.VIR infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: File Deleted. Tue Jan 25 17:45:14 2005 => File C:\Programme\Microsoft AntiSpyware\Quarantine\C3080566-B9AF-4D2A-8E06-0916A9\8C0EC249-5F14-4592-9E7C-F8E364 infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: File Deleted. HOFFE DAS HILFT!!! |
25.01.2005, 21:38 | #20 |
Administrator, a.D. | 01 - Einträge lassen sich nicht fixen!! Hallo, lade DllCompare. Doppelklick auf DllCompare.exe -> Run locate.com -> wenn der Scan erfolgt ist "Compare" klicken -> wenn auch dieser Scan fertig ist "Make a Log of what was found" klicken -> Inhalt des Logs posten |
25.01.2005, 21:38 | #21 |
| 01 - Einträge lassen sich nicht fixen!! Kareena: Bitte so vorgehen: (Öffne die mwav.log -> Bearbeiten -> Suchen -> infected eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen) Nicht das scanning log, sondern das Ergebnis wie beschrieben.
__________________ --> 01 - Einträge lassen sich nicht fixen!! |
25.01.2005, 21:46 | #22 |
| 01 - Einträge lassen sich nicht fixen!! Hi, das habe ich auch Und zwar inklusive der errors, denn dort stand auch infected drin. Das ganze log wär noch länger gewesen. Aber hier nur die infected: Tue Jan 25 17:35:59 2005 => File C:\ntdetect.hta infected by "Trojan-Dropper.VBS.Inor.cj" Virus. Action Taken: File Deleted. Tue Jan 25 17:36:36 2005 => File C:\Programme\AVPersonal\INFECTED\IPSSNU.DLL.001 infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: File Deleted. Tue Jan 25 17:45:14 2005 => File C:\Programme\Microsoft AntiSpyware\Quarantine\C3080566-B9AF-4D2A-8E06-0916A9\8C0EC249-5F14-4592-9E7C-F8E364 infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: File Deleted. Tue Jan 25 17:10:21 2005 => File C:\WINDOWS\iewww.exe infected by "Trojan.Win32.StartPage.oh" Virus. Action Taken: File Deleted. Tue Jan 25 17:11:04 2005 => File C:\WINDOWS\System32\EG_AUTH.dll infected by "Trojan.Win32.P2E.as" Virus. Action Taken: File Deleted. Tue Jan 25 17:11:29 2005 => File C:\WINDOWS\System32\luxxam.exe infected by "Trojan-Downloader.Win32.Qoologic.d" Virus. Action Taken: File Deleted. Wie gesagt, jetzt habe ich wieder alles drauf!! |
25.01.2005, 21:48 | #23 |
| 01 - Einträge lassen sich nicht fixen!! Hallo Cidre, hier ist er: * DLLCompare Log version() Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ C:\WINDOWS\SYSTEM32\derpsetu.dll Tue 25 Jan 2005 13:14:16 ..S.R 228.866 223,50 K C:\WINDOWS\SYSTEM32\dokquota.dll Tue 25 Jan 2005 17:07:56 ..S.R 232.198 226,75 K C:\WINDOWS\SYSTEM32\drghelp.dll Tue 25 Jan 2005 17:13:34 ..S.R 228.415 223,06 K C:\WINDOWS\SYSTEM32\dxnhpast.dll Tue 25 Jan 2005 14:56:00 ..S.R 231.146 225,73 K C:\WINDOWS\SYSTEM32\ihetcomm.dll Tue 25 Jan 2005 14:27:28 ..S.R 229.793 224,41 K C:\WINDOWS\SYSTEM32\ir22l5~1.dll Tue 25 Jan 2005 8:20:32 ..S.R 228.812 223,45 K C:\WINDOWS\SYSTEM32\jtlq07~1.dll Tue 25 Jan 2005 18:50:46 ..S.R 229.640 224,26 K C:\WINDOWS\SYSTEM32\k608lg~1.dll Tue 25 Jan 2005 17:16:28 ..S.R 229.103 223,73 K C:\WINDOWS\SYSTEM32\khdlv1.dll Tue 25 Jan 2005 18:50:46 ..S.R 229.103 223,73 K C:\WINDOWS\SYSTEM32\notaud~1.dll Mon 24 Jan 2005 2:15:42 ..S.R 229.736 224,35 K ________________________________________________ 1.439 items found: 1.439 files (10 H/S), 0 directories. Total of file sizes: 315.934.413 bytes 301,30 M Administrator Account = Wahr --------------------End log--------------------- DANKE!!! |
25.01.2005, 22:13 | #25 |
| 01 - Einträge lassen sich nicht fixen!! diese drei dateien wollten sich nicht löschen lassen: C:\WINDOWS\SYSTEM32\jtlq07~1.dll Tue 25 Jan 2005 18:50:46 ..S.R 229.640 224,26 K C:\WINDOWS\SYSTEM32\k608lg~1.dll Tue 25 Jan 2005 17:16:28 ..S.R 229.103 223,73 K C:\WINDOWS\SYSTEM32\khdlv1.dll Tue 25 Jan 2005 18:50:46 ..S.R Bei denen gab es bei escan auch einen error. Die guard.tmp existiert in windows/system32 nicht, Hier ist der neue log: * DLLCompare Log version(1.0.0.127) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ C:\WINDOWS\SYSTEM32\khdlv1.dll Tue 25 Jan 2005 18:50:46 ..S.R 229.103 223,73 K ________________________________________________ 1.432 items found: 1.432 files (1 H/S), 0 directories. Total of file sizes: 314.325.447 bytes 299,76 M Administrator Account = Wahr --------------------End log--------------------- DANKE NOCHMAL!! |
25.01.2005, 22:18 | #26 |
Administrator, a.D. | 01 - Einträge lassen sich nicht fixen!! Versuchs noch einmal aber mit der Option "Delete on Reboot". Führe dann einen Neustart deines Systems aus und poste nochmal das Log. |
25.01.2005, 22:25 | #27 |
| 01 - Einträge lassen sich nicht fixen!! das habe ich gemacht und hier ist der log: * DLLCompare Log version(1.0.0.127) Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ O^E says: "There were no files found " ________________________________________________ 1.429 items found: 1.429 files, 0 directories. Total of file sizes: 313.637.601 bytes 299,11 M Administrator Account = Wahr --------------------End log--------------------- Ich habe es aber immernoch drin. Hier mein HijackThis log: Logfile of HijackThis v1.99.0 Scan saved at 22:26:22, on 25.01.2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\TBPanel.exe C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE C:\Programme\Microsoft AntiSpyware\gcasServ.exe C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe C:\Programme\AVPersonal\AVGNT.EXE C:\Programme\Microsoft AntiSpyware\gcasDtServ.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe C:\Program Files\interMute\SpySubtract\SpySub.exe C:\Programme\AVPersonal\AVGUARD.EXE C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe C:\Programme\AVPersonal\AVWUPSRV.EXE C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe C:\WINDOWS\System32\wuauclt.exe C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\kernel.exe C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\sc_watch.exe C:\PROGRA~1\T-Online\T-ONLI~1\BASIS-~1\Basis2\PROFIL~1.EXE C:\Programme\Mozilla Firefox\firefox.exe C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis2\tonchkml32.exe C:\Programme\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer O1 - Hosts: 69.20.16.183 auto.search.msn.com O1 - Hosts: 69.20.16.183 search.netscape.com O1 - Hosts: 69.20.16.183 ieautosearch O1 - Hosts: 69.20.16.183 ieautosearch O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\system32\msdxm.ocx O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Gainward] C:\WINDOWS\TBPanel.exe /A O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [gcasServ] "C:\Programme\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP O4 - HKLM\..\Run: [AVG7_EMC] C:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe O4 - HKCU\..\Run: [Yahoo! Pager] C:\Programme\Yahoo!\Messenger\ypager.exe -quiet O4 - Global Startup: SpySubtract.lnk = C:\Program Files\interMute\SpySubtract\SpySub.exe O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra button: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\PROGRA~1\Yahoo!\MESSEN~1\YPager.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE O12 - Plugin for .spop: C:\Programme\Internet Explorer\Plugins\NPDocBox.dll O17 - HKLM\System\CCS\Services\Tcpip\..\{4633D25C-BE6C-4B03-BB73-55D8341B080D}: NameServer = 217.237.149.161 217.237.151.225 O23 - Service: AntiVir Service - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE O23 - Service: EPSON Printer Status Agent2 - SEIKO EPSON CORPORATION - C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\SAgent2.exe O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: TuneUp WinStyler Theme Service - TuneUp Software GmbH - C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe O23 - Service: Ulead Burning Helper - Ulead Systems, Inc. - C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe |
25.01.2005, 22:46 | #28 |
Administrator, a.D. | 01 - Einträge lassen sich nicht fixen!! Fixe jetzt die O1 Einträge nochmal. Arbeite danach die Punkte 1,3,4 und 5 vom Link in meiner Sig ab und dies http://www.netzwerktotal.de/tdslwinxp.htm ebenso. |
25.01.2005, 22:49 | #29 |
| 01 - Einträge lassen sich nicht fixen!! also ich werde da system nicht wieder aufspielen, weil hier zu viel wichtiges ist und ich net weiß, ob ich alles wieder so haben werde wie ich will, denn es hat lange gedauert bis alles perfekt war ich habe in der hosts file die einträge geköscht und gespeichert, nochmal gefixt und dann hat spybot sowie HijackThis nichts mehr gefunden. Bis jetzt kam es nicht wieder. Waren mit deinen Punkten die Neuinstallation gemeint? Ach, und würdest du SP2 empfehlen??? |
25.01.2005, 22:53 | #30 |
Administrator, a.D. | 01 - Einträge lassen sich nicht fixen!! Du sollst dein System ja nicht neu aufsetzen sondern zur Erhöhung deiner eigenen Sicherheit die von mir genannten Punkte abarbeiten. Das ist ein kleiner feiner Unterschied. Das SP2 ist im Punkt 3 inbegriffen. |
Themen zu 01 - Einträge lassen sich nicht fixen!! |
antispyware, antivir, antivir update, auswerten, avgnt.exe, dateien, dll, explorer, firefox, gainward, helfen, helper, hijack, hijackthis, icq, internet, internet explorer, log, mein log, messenger, microsoft, mozilla, mozilla firefox, nvcpl.dll, nvidia, programme, rundll, software, system, t-online, tcpip, träge, tuneup utilities, windows, windows xp, yahoo |