|
Plagegeister aller Art und deren Bekämpfung: NewDotNetWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
11.04.2005, 14:22 | #1 |
| NewDotNet Ich habe ein Problem mit dem Programm NewDotNet. Ich habe dieses Programm keineswegs freiwilig und mit meiner Zustimmung installiert. Das Programm "produziert" bei mir Spyware. Den Ordner des Programms mit der Datei newdotnet6_38.dll lässt sich zwar finden, aber nicht entfernen. Ich habe AntiVir, XPclean, ad-aware und Zone-Alarm als die jeweiligen neusten Versionen, diese Programme helfen jedoch nicht dabei das Programm NewDotNet zu entfernen. Die Spywaredateien habe ich schon mehrfach gelöscht, treten aber logischerweise immer wieder auf. Kann mir jemand weiterhelfen ? MfG Gravedigger |
11.04.2005, 14:26 | #2 |
| NewDotNet @gravedigger1980
__________________NewDotNet lade spybot download installiere und update es. lade LSP-Fix download deinstalliere unter systemsteuerung, software, NewdotNet NewNet oder ähnliches. lasse danach spybot scannen, lösche was es vorschlägt. wenn danach dein Internetverbindung nicht geht, dann mit LSP-Fix reparieren. danach ein HJT logfile hier posten direktdownload anleitung chaosman
__________________ |
11.04.2005, 14:45 | #3 |
| NewDotNet Hätte ich NewDotNet unter Systemsteuerung/Software gefunden hätte ich es natürlich schon deinstalliert, aber ich finde dort eben nichts von NewDotNet,NewNet oder ähnlichem.
__________________Logfile of HijackThis v1.99.1 Scan saved at 15:42:14, on 11.04.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programme\TGTSoft\StyleXP\StyleXPService.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\NVIDIA Corporation\NvMixer\NVMixerTray.exe C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe C:\Programme\ICQLite\ICQLite.exe C:\Programme\Java\jre1.5.0_02\bin\jusched.exe C:\Programme\Winamp\winampa.exe C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE C:\Programme\Browser MOUSE\mouse32a.exe C:\Programme\Office keyboard utility\1.4\OFFICEKB.exe C:\Programme\AVPersonal\AVGNT.EXE C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\ctfmon.exe C:\Programme\MSN Messenger\MsnMsgr.Exe C:\Programme\Office keyboard utility\1.4\MMKEYB.EXE C:\Programme\Office keyboard utility\1.4\TrayMon.exe C:\Programme\Office keyboard utility\1.4\osd.exe C:\Programme\Office keyboard utility\1.4\nhksrv.exe C:\Programme\AVPersonal\AVGUARD.EXE C:\Programme\AVPersonal\AVWUPSRV.EXE C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\explorer.exe C:\Programme\Internet Explorer\IEXPLORE.EXE C:\Programme\Spybot - Search & Destroy\SpybotSD.exe G:\Dokumente und Einstellungen\Sebbo\Eigene Dateien\Sebastian\Setups & Updates\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar1.dll O2 - BHO: TGTSoft Explorer Toolbar Changer - {C333CF63-767F-4831-94AC-E683D962C63C} - C:\Programme\TGTSoft\StyleXP\TGT_BHO.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar1.dll O4 - HKLM\..\Run: [NVMixerTray] "C:\Programme\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [Zone Labs Client] "C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_02\bin\jusched.exe O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [EPSON Stylus C42 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S10IC2.EXE /P23 "EPSON Stylus C42 Series" /O6 "USB001" /M "Stylus C42" O4 - HKLM\..\Run: [Epson Registrierungserinnerung] "C:\WINDOWS\temp\NavBrowser.exe" /r /i "C:\WINDOWS\temp\NavLoad.ini" O4 - HKLM\..\Run: [FLMOFFICE4DMOUSE] C:\Programme\Browser MOUSE\mouse32a.exe O4 - HKLM\..\Run: [FLMOFFICEKEYBOARD] C:\Programme\Office keyboard utility\1.4\OFFICEKB.exe O4 - HKLM\..\Run: [AVGCtrl] C:\Programme\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s O4 - HKLM\..\RunOnce: [SpybotSnD] "C:\Programme\Spybot - Search & Destroy\SpybotSD.exe" /autocheck O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [STYLEXP] C:\Programme\TGTSoft\StyleXP\StyleXP.exe -Hide O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Google Search - res://C:\Programme\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Im Cache gespeicherte Seite - res://C:\Programme\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Verweisseiten - res://C:\Programme\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Ähnliche Seiten - res://C:\Programme\Google\GoogleToolbar1.dll/cmsimilar.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe (file missing) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe (file missing) O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O10 - Hijacked Internet access by New.Net O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1112811154078 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE O23 - Service: EPSON Printer Status Agent2 (EPSONStatusAgent2) - SEIKO EPSON CORPORATION - C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\SAgent2.exe O23 - Service: Netropa NHK Server (nhksrv) - Unknown owner - C:\Programme\Office keyboard utility\1.4\nhksrv.exe O23 - Service: StyleXPService - Unknown owner - C:\Programme\TGTSoft\StyleXP\StyleXPService.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe |
11.04.2005, 14:55 | #4 |
| NewDotNet @gravedigger1980 scheint aber doch was aktiv zu sein O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL,NewDotNetStartup -s lade escan download anleitung EscanErgebnis Teile uns das Ergebnis des eScan mit: "öffne die mwav.log -> Bearbeiten -> Suchen -> infected oder tagged eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen." chaosman
__________________ Bonus vir semper tiro |
11.04.2005, 15:09 | #5 |
| NewDotNet File C:\Programme\NewDotNet\newdotnet6_38.dll infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. File C:\WINDOWS\NDNuninstall6_38.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. |
11.04.2005, 15:18 | #6 |
| NewDotNet Hallo gravedigger1980, hast Du Scan im abgesicherten Modus mit den Optionen "All Local Drives" und "Scan all" durchgeführt? Falls nein, wiederhole es bitte. dartus
__________________ --> NewDotNet |
11.04.2005, 17:13 | #7 | |
Administrator, a.D. | NewDotNetZitat:
|
11.04.2005, 17:38 | #8 | |
| NewDotNet Also..... Ich hatte gerade den Scan im abgesicherten Modus gemacht, mit all den erforderlichen Optionen, aber ich befürchte ich muss ihn nochmal machen, denn ich habe etwas falsch gemacht, sodass ich nun die Treffer nicht posten kann, den Log view vom Scan habe ich allerdings noch. Ich mach es einfach nochmal Zitat:
|
11.04.2005, 18:01 | #9 |
| NewDotNet Bevor ich das mache kann mir vielleicht noch einmal jemand genau erklären, was ich wie zu machen habe. |
11.04.2005, 18:06 | #10 | |
| NewDotNetZitat:
|
11.04.2005, 18:14 | #11 | |
| NewDotNetZitat:
Das hilft mir nicht. Über Systemsteuerung/Software ist NewDotNet bei mir nicht vorzufinden. Meine Aussage bezog sich darauf, wie ich mit e-scan den scan so mache, dass ich dann das posten kann, was euch hilft, um mir zu helfen. Geändert von gravedigger1980 (11.04.2005 um 18:20 Uhr) |
11.04.2005, 18:23 | #12 |
Administrator, a.D. | NewDotNet Es steht doch alles hier beschrieben -> http://www.trojaner-board.de/42731-escan-anleitung.html Danach -> Öffne die mwav.log im Ordner C:\bases -> Bearbeiten -> Suchen -> infected oder tagged eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen. |
11.04.2005, 20:33 | #13 |
| NewDotNet Also das ist die “Virus Log Information”, die etwa mittig im Fenster von eScan angegeben ist: File C:\Programme\NewDotNet\newdotnet6_38.dll infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. File C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. File C:\WINDOWS\NDNuninstall6_38.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. File C:\Programme\NewDotNet\newdotnet6_38.dll infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP13\A0010118.EXE infected by "not-a-virus:AdWare.Toolbar.MyWay.b" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0000355.exe infected by "not-a-virus:AdWare.Gator.3103" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001408.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001409.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001411.dll infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001413.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001416.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001419.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001420.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001422.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001425.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001426.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001427.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001428.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001433.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001434.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.f" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001439.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001440.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. File C:\WINDOWS\NDNuninstall6_38.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. File G:\Dokumente und Einstellungen\Sebbo\Eigene Dateien\Sebastian\My Games\All Microsoft Software Key_gen (Nearly All) Windows (98,Me,2000,2kserver,Xp,2003 Server) Office (2000,Xp,2003), Picture It, Fron serials cracks.zip infected by "Backdoor.Win32.Bionet.405" Virus. Action Taken: No Action Taken. File G:\Dokumente und Einstellungen\Sebbo\Eigene Dateien\Sebastian\Setups & Updates\2936.exe infected by "not-a-virus:AdWare.Gator.3103" Virus. Action Taken: No Action Taken. Das sind die Dateien aus der View Log, also der Editor Textdokumentdatei MWAV.LOG die das Wort „infected“ beinhalten: Mon Apr 11 16:05:32 2005 => File C:\Programme\NewDotNet\newdotnet6_38.dll infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 16:05:38 2005 => File C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 16:05:47 2005 => File C:\WINDOWS\NDNuninstall6_38.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 16:30:25 2005 => File C:\Programme\NewDotNet\newdotnet6_38.dll infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 16:31:05 2005 => File C:\WINDOWS\NDNuninstall6_38.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken Mon Apr 11 16:38:30 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.* Mon Apr 11 16:47:59 2005 => File C:\Programme\NewDotNet\newdotnet6_38.dll infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 16:52:16 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP13\A0010118.EXE infected by "not-a-virus:AdWare.Toolbar.MyWay.b" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:18 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0000355.exe infected by "not-a-virus:AdWare.Gator.3103" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:32 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001408.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:33 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001409.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:33 2005 => Scanning File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001410.dll Mon Apr 11 16:53:33 2005 => Scanning File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001411.dll Mon Apr 11 16:53:33 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001411.dll infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:35 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001413.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:35 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001416.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:36 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001419.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:36 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001420.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:38 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001426.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:38 2005 => Scanning File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001427.dll Mon Apr 11 16:53:38 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001427.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:38 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001425.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:38 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001428.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:39 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001433.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:39 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001434.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.f" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:39 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001439.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 16:53:39 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001440.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 17:00:45 2005 => File C:\WINDOWS\NDNuninstall6_38.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 19:38:30 2005 => File C:\Programme\NewDotNet\newdotnet6_38.dll infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 19:38:37 2005 => File C:\PROGRA~1\NEWDOT~1\NEWDOT~1.DLL infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 19:39:09 2005 => File C:\WINDOWS\NDNuninstall6_38.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 19:44:46 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.* Mon Apr 11 19:50:29 2005 => File C:\Programme\NewDotNet\newdotnet6_38.dll infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 19:52:55 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP13\A0010118.EXE infected by "not-a-virus:AdWare.Toolbar.MyWay.b" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:33 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0000355.exe infected by "not-a-virus:AdWare.Gator.3103" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:36 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001408.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:36 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001408.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:36 2005 => Scanning File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001409.dll Mon Apr 11 19:53:37 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001409.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:37 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001411.dll infected by "not-a-virus:AdWare.Gator.5017" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:37 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001413.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:37 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001416.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:37 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001419.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:37 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001420.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:38 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001422.dll infected by "not-a-virus:AdWare.Gator.6041" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:38 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001425.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:38 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001426.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:38 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001427.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:38 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001428.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:38 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001433.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:38 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001434.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.f" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:38 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001439.exe infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:53:39 2005 => File C:\System Volume Information\_restore{42B50295-841E-413B-A041-C3855E2C91A9}\RP8\A0001440.dll infected by "not-a-virus:AdWare.Gator.3124" Virus. Action Taken: No Action Taken. Mon Apr 11 19:58:16 2005 => File C:\WINDOWS\NDNuninstall6_38.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Mon Apr 11 20:27:21 2005 => File G:\Dokumente und Einstellungen\Sebbo\Eigene Dateien\Sebastian\My Games\All Microsoft Software Key_gen (Nearly All) Windows (98,Me,2000,2kserver,Xp,2003 Server) Office (2000,Xp,2003), Picture It, Fron serials cracks.zip infected by "Backdoor.Win32.Bionet.405" Virus. Action Taken: No Action Taken. Mon Apr 11 20:56:17 2005 => File G:\Dokumente und Einstellungen\Sebbo\Eigene Dateien\Sebastian\Setups & Updates\2936.exe infected by "not-a-virus:AdWare.Gator.3103" Virus. Action Taken: No Action Taken. Total Objects Scanned: 62093 Total Virus(es) Found: 25 Total Disinfected Files: 0 Total Deleted Objects: 0 Total Files Renamed: 0 Total Errors: 22 |
11.04.2005, 21:17 | #14 | |
| NewDotNet @gravedigger1980 Vor dem Start von eScan mach bitte noch Folgendes: 1.Systemwiederherstellung abschalten 2.Temporary Internet Files -Ordner leeren: Start/Einstellungen/Systemsteuerung/Internetoptionen/Dateien löschen/Alle Offlineinhalte löschen... 3. Papierkorb leeren. 4. Infected-Ordner vom Antivirus-Programm und, ggf. Spybot Search & Destroy, Ad-Aware und Co. , leeren. Zitat:
|
11.04.2005, 21:52 | #15 | |
| NewDotNetZitat:
"All Microsoft Software Key_gen (Nearly All) Windows (98,Me,2000,2kserver,Xp,2003 Server) Office (2000,Xp,2003), Picture It, Fron serials cracks.zip" habe ich ebenfalls gelöscht. Ich soll jetzt also noch einmal einen Scan mit eScan machen ? |
Themen zu NewDotNet |
.dll, ad-aware, antivir, datei, entferne, gelöscht, helfen, immer wieder, installier, mehrfach, neuste, newdot, newdotnet, ordner, problem, programm, programme, versionen, weiterhelfen, xpclean |