|
Log-Analyse und Auswertung: Hijack Logfile- es wäe sehr nett!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
17.04.2005, 15:27 | #1 |
| Hijack Logfile- es wäe sehr nett! Hallo Leute, auch mich hat der bläde Special-AGent BDX erwischt! Dank der super ANleitung habe ich esacan gemacht und nun fände ich es super wenn ihr euch das mal anschauen könntet! Vielen Dank schonmal im voraus! ri Apr 15 23:47:28 2005 => ********************************************************** Fri Apr 15 23:47:28 2005 => eScan AntiVirus Toolkit Utility. Fri Apr 15 23:47:28 2005 => Copyright © 2003-2004, MicroWorld Technologies Inc. Fri Apr 15 23:47:28 2005 => ********************************************************** Fri Apr 15 23:47:28 2005 => Version 4.8.8 (C:\DOKUME~1\Susanne\LOKALE~1\Temp\mwavscan.com) Fri Apr 15 23:47:28 2005 => Log File: C:\DOKUME~1\Susanne\LOKALE~1\Temp\MWAV.LOG Fri Apr 15 23:47:28 2005 => Last Scan Date and Time: 15.04.2005 23:17:02 Fri Apr 15 23:47:28 2005 => Command Line Options Given: /s Fri Apr 15 23:47:28 2005 => Latest Date of files inside MWAV: 14 Feb 2005 06:35:53. Fri Apr 15 23:47:35 2005 => AV Library Loaded... Fri Apr 15 23:47:36 2005 => ********************************************************** Fri Apr 15 23:47:36 2005 => eScan AntiVirus Toolkit Utility. Fri Apr 15 23:47:36 2005 => Copyright © 2003-2004, MicroWorld Technologies Inc. Fri Apr 15 23:47:36 2005 => Fri Apr 15 23:47:36 2005 => Support: support@mwti.net Fri Apr 15 23:47:36 2005 => Web: http://www.mwti.net Fri Apr 15 23:47:36 2005 => ********************************************************** Fri Apr 15 23:47:36 2005 => Version 4.8.8 (C:\DOKUME~1\Susanne\LOKALE~1\Temp\mwavscan.com) Fri Apr 15 23:47:36 2005 => Log File: C:\DOKUME~1\Susanne\LOKALE~1\Temp\MWAV.LOG Fri Apr 15 23:47:36 2005 => Windows Root Folder: C:\WINDOWS Fri Apr 15 23:47:36 2005 => Windows Sys32 Folder: C:\WINDOWS\system32 Fri Apr 15 23:47:36 2005 => OS: Windows NT Fri Apr 15 23:47:36 2005 => Latest Date of files inside MWAV: 14 Feb 2005 06:35:53. Fri Apr 15 23:47:36 2005 => Options Selected by User: Fri Apr 15 23:47:36 2005 => Memory Check: Enabled Fri Apr 15 23:47:36 2005 => Registry Check: Enabled Fri Apr 15 23:47:36 2005 => StartUp Folder Check: Enabled Fri Apr 15 23:47:36 2005 => System Folder Check: Enabled Fri Apr 15 23:47:36 2005 => System Area Check: Disabled Fri Apr 15 23:47:36 2005 => Services Check: Enabled Fri Apr 15 23:47:36 2005 => Drive Check Option Disabled Fri Apr 15 23:47:36 2005 => Folder Check: Disabled Fri Apr 15 23:47:36 2005 => ***** Scanning Memory Files ***** Fri Apr 15 23:47:36 2005 => Scanning File C:\WINDOWS\System32\smss.exe Fri Apr 15 23:47:36 2005 => Scanning File C:\WINDOWS\system32\ntdll.dll Fri Apr 15 23:47:36 2005 => Scanning File C:\WINDOWS\SYSTEM32\CSRSS.EXE Fri Apr 15 23:47:36 2005 => Scanning File C:\WINDOWS\system32\CSRSRV.dll Fri Apr 15 23:47:36 2005 => Scanning File C:\WINDOWS\system32\basesrv.dll Fri Apr 15 23:47:36 2005 => Scanning File C:\WINDOWS\system32\winsrv.dll Fri Apr 15 23:47:36 2005 => Scanning File C:\WINDOWS\system32\GDI32.dll Fri Apr 15 23:47:36 2005 => Scanning File C:\WINDOWS\system32\KERNEL32.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\USER32.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\sxs.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\ADVAPI32.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\RPCRT4.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\Apphelp.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\VERSION.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\SYSTEM32\WINLOGON.EXE Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\AUTHZ.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\msvcrt.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\CRYPT32.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\MSASN1.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\NDdeApi.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\PROFMAP.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\NETAPI32.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\USERENV.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\PSAPI.DLL Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\REGAPI.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\Secur32.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\SETUPAPI.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\WINSTA.dll Fri Apr 15 23:47:37 2005 => Scanning File C:\WINDOWS\system32\WINTRUST.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\IMAGEHLP.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\WS2_32.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\WS2HELP.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\MSGINA.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\SHELL32.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\SHLWAPI.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\COMCTL32.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\ODBC32.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\comdlg32.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2180_x-ww_a84f1ff9\comctl32.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\odbcint.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\SHSVCS.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\sfc.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\sfc_os.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\ole32.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\WINSCARD.DLL Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\WTSAPI32.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\uxtheme.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\WINMM.dll Fri Apr 15 23:47:38 2005 => Scanning File C:\WINDOWS\system32\Ati2evxx.dll Fri Apr 15 23:47:39 2005 => Scanning File C:\WINDOWS\system32\rsaenh.dll Fri Apr 15 23:47:39 2005 => Scanning File C:\WINDOWS\system32\cscdll.dll Fri Apr 15 23:47:39 2005 => Scanning File C:\WINDOWS\system32\WlNotify.dll Fri Apr 15 23:47:39 2005 => Scanning File C:\WINDOWS\system32\WINSPOOL.DRV Fri Apr 15 23:47:39 2005 => Scanning File C:\WINDOWS\system32\MPR.dll Fri Apr 15 23:47:39 2005 => Scanning File C:\WINDOWS\system32\SAMLIB.dll Fri Apr 15 23:47:39 2005 => Scanning File C:\WINDOWS\system32\msv1_0.dll Fri Apr 15 23:47:39 2005 => Scanning File C:\WINDOWS\system32\iphlpapi.dll Fri Apr 15 23:47:39 2005 => Scanning File C:\WINDOWS\system32\cscui.dll Fri Apr 15 23:47:39 2005 => Scanning File C:\WINDOWS\system32\wdmaud.drv Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\msacm32.drv Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\MSACM32.dll Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\midimap.dll Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\MPRAPI.dll Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\ACTIVEDS.dll Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\adsldpc.dll Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\WLDAP32.dll Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\ATL.DLL Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\OLEAUT32.dll Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\rtutils.dll Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\NTMARTA.DLL Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\services.exe Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\SCESRV.dll Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\umpnpmgr.dll Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\NCObjAPI.DLL Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\MSVCP60.dll Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\system32\ShimEng.dll Fri Apr 15 23:47:40 2005 => Scanning File C:\WINDOWS\AppPatch\AcGenral.DLL Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\eventlog.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\lsass.exe Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\LSASRV.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\NTDSAPI.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\DNSAPI.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\SAMSRV.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\cryptdll.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\msprivs.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\kerberos.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\netlogon.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\w32time.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\schannel.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\wdigest.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\scecli.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\System32\Ati2evxx.exe Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\svchost.exe Fri Apr 15 23:47:41 2005 => Scanning File c:\windows\system32\rpcss.dll Fri Apr 15 23:47:41 2005 => Scanning File C:\WINDOWS\system32\xpsp2res.dll Fri Apr 15 23:47:42 2005 => Scanning File C:\WINDOWS\system32\CLBCATQ.DLL Fri Apr 15 23:47:42 2005 => Scanning File C:\WINDOWS\system32\COMRes.dll Fri Apr 15 23:47:42 2005 => Scanning File C:\WINDOWS\system32\mswsock.dll Fri Apr 15 23:47:42 2005 => Scanning File C:\WINDOWS\system32\hnetcfg.dll Fri Apr 15 23:47:42 2005 => Scanning File C:\WINDOWS\System32\wshtcpip.dll Fri Apr 15 23:47:42 2005 => Scanning File C:\WINDOWS\System32\winrnr.dll Fri Apr 15 23:47:42 2005 => Scanning File C:\Programme\T-Online\T-Online_Software_5\Basis-Software\Basis1\AdHndCnt.dll Fri Apr 15 23:47:42 2005 => Scanning File c:\windows\system32\dhcpcsvc.dll Fri Apr 15 23:47:42 2005 => Scanning File c:\windows\system32\wzcsvc.dll Fri Apr 15 23:47:43 2005 => Scanning File c:\windows\system32\WMI.dll Fri Apr 15 23:47:43 2005 => Scanning File c:\windows\system32\ESENT.dll Fri Apr 15 23:47:43 2005 => Scanning File C:\WINDOWS\System32\rastls.dll Fri Apr 15 23:47:43 2005 => Scanning File C:\WINDOWS\system32\CRYPTUI.dll Fri Apr 15 23:47:43 2005 => Scanning File C:\WINDOWS\system32\WININET.dll Fri Apr 15 23:47:43 2005 => Scanning File C:\WINDOWS\System32\RASAPI32.dll Fri Apr 15 23:47:43 2005 => Scanning File C:\WINDOWS\System32\rasman.dll Fri Apr 15 23:47:43 2005 => Scanning File C:\WINDOWS\System32\TAPI32.dll Fri Apr 15 23:47:43 2005 => Scanning File C:\WINDOWS\System32\raschap.dll Fri Apr 15 23:47:43 2005 => Scanning File c:\windows\system32\schedsvc.dll Fri Apr 15 23:47:43 2005 => Scanning File C:\WINDOWS\System32\MSIDLE.DLL Fri Apr 15 23:47:43 2005 => Scanning File c:\windows\system32\audiosrv.dll Fri Apr 15 23:47:43 2005 => Scanning File c:\windows\system32\wkssvc.dll Fri Apr 15 23:47:43 2005 => Scanning File C:\WINDOWS\System32\actxprxy.dll Fri Apr 15 23:47:44 2005 => Scanning File c:\windows\system32\dnsrslvr.dll Fri Apr 15 23:47:44 2005 => Scanning File c:\windows\system32\lmhsvc.dll Fri Apr 15 23:47:44 2005 => Scanning File C:\WINDOWS\system32\spoolsv.exe Fri Apr 15 23:47:44 2005 => Scanning File C:\WINDOWS\system32\SPOOLSS.DLL Fri Apr 15 23:47:44 2005 => Scanning File C:\WINDOWS\system32\localspl.dll Fri Apr 15 23:47:45 2005 => Scanning File C:\WINDOWS\system32\cnbjmon.dll Fri Apr 15 23:47:45 2005 => Scanning File C:\WINDOWS\system32\hpzlnt06.dll Fri Apr 15 23:47:46 2005 => Scanning File C:\WINDOWS\system32\pjlmon.dll Fri Apr 15 23:47:46 2005 => Scanning File C:\WINDOWS\system32\tcpmon.dll Fri Apr 15 23:47:46 2005 => Scanning File C:\WINDOWS\system32\usbmon.dll Fri Apr 15 23:47:46 2005 => Scanning File C:\WINDOWS\system32\win32spl.dll Fri Apr 15 23:47:46 2005 => Scanning File C:\WINDOWS\system32\NETRAP.dll Fri Apr 15 23:47:46 2005 => Scanning File C:\WINDOWS\system32\inetpp.dll Fri Apr 15 23:47:46 2005 => Scanning File C:\WINDOWS\system32\MSCTF.dll Fri Apr 15 23:47:46 2005 => Scanning File C:\WINDOWS\system32\userinit.exe Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\Explorer.EXE Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\system32\BROWSEUI.dll Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\system32\SHDOCVW.dll Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\System32\themeui.dll Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\System32\MSIMG32.dll Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\System32\msutb.dll Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\system32\LINKINFO.dll Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\system32\ntshrui.dll Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\system32\urlmon.dll Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\system32\NETSHELL.dll Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\system32\credui.dll Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\system32\msi.dll Fri Apr 15 23:47:47 2005 => Scanning File C:\WINDOWS\system32\MSISIP.DLL Fri Apr 15 23:47:48 2005 => Scanning File C:\WINDOWS\System32\wshext.dll Fri Apr 15 23:47:48 2005 => Scanning File C:\WINDOWS\system32\MFC42.DLL Fri Apr 15 23:47:48 2005 => Scanning File C:\WINDOWS\system32\MFC42LOC.DLL Fri Apr 15 23:47:48 2005 => Scanning File C:\WINDOWS\System32\wshDE.DLL Fri Apr 15 23:47:48 2005 => Scanning File C:\PROGRA~1\MICROS~2\Office10\MCPS.DLL Fri Apr 15 23:47:48 2005 => Scanning File C:\WINDOWS\System32\webcheck.dll Fri Apr 15 23:47:48 2005 => Scanning File C:\WINDOWS\System32\WSOCK32.dll Fri Apr 15 23:47:48 2005 => Scanning File C:\WINDOWS\System32\stobject.dll Fri Apr 15 23:47:48 2005 => Scanning File C:\WINDOWS\System32\BatMeter.dll Fri Apr 15 23:47:48 2005 => Scanning File C:\WINDOWS\System32\POWRPROF.dll Fri Apr 15 23:47:48 2005 => Scanning File C:\WINDOWS\system32\PROMon.exe Fri Apr 15 23:47:48 2005 => Scanning File C:\WINDOWS\system32\NMSAPI.DLL Fri Apr 15 23:47:49 2005 => Scanning File C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb06.exe Fri Apr 15 23:47:50 2005 => Scanning File C:\WINDOWS\System32\spool\drivers\w32x86\3\HPZR3206.DLL Fri Apr 15 23:47:57 2005 => Scanning File C:\Programme\ICQLite\ICQLite.exe Fri Apr 15 23:47:59 2005 => Scanning File C:\Programme\ICQLite\ICQRT.dll Fri Apr 15 23:47:59 2005 => Scanning File C:\Programme\ICQLite\LiteSkinUtils.dll Fri Apr 15 23:47:59 2005 => Scanning File C:\WINDOWS\system32\OLEPRO32.DLL Fri Apr 15 23:47:59 2005 => Scanning File C:\WINDOWS\system32\Icmp.dll Fri Apr 15 23:48:00 2005 => Scanning File C:\Programme\ICQLite\LiteRes.dll Fri Apr 15 23:48:00 2005 => Scanning File C:\WINDOWS\system32\RICHED32.DLL Fri Apr 15 23:48:00 2005 => Scanning File C:\WINDOWS\system32\RICHED20.dll Fri Apr 15 23:48:00 2005 => Scanning File C:\Programme\ICQLite\actskin4.ocx Fri Apr 15 23:48:00 2005 => Scanning File C:\WINDOWS\system32\P2PNET~1\P2PNET~1.EXE Fri Apr 15 23:48:01 2005 => Scanning File C:\PROGRA~2\Altnet\POINTS~1\POINTS~1.EXE Fri Apr 15 23:48:04 2005 => Scanning File C:\WINDOWS\system32\oledlg.dll Fri Apr 15 23:48:05 2005 => Scanning File C:\WINDOWS\system32\cryptnet.dll Fri Apr 15 23:48:05 2005 => Scanning File C:\WINDOWS\system32\WINHTTP.dll Fri Apr 15 23:48:06 2005 => Scanning File C:\WINDOWS\system32\SensApi.dll Fri Apr 15 23:48:06 2005 => Scanning File C:\WINDOWS\system32\Cabinet.dll Fri Apr 15 23:48:07 2005 => Scanning File C:\WINDOWS\System32\shdoclc.dll Fri Apr 15 23:48:11 2005 => Scanning File C:\WINDOWS\System32\mshtml.dll Fri Apr 15 23:48:14 2005 => Scanning File C:\WINDOWS\System32\msls31.dll Fri Apr 15 23:48:15 2005 => Scanning File C:\WINDOWS\system32\MLANG.dll Fri Apr 15 23:48:16 2005 => Scanning File C:\PROGRA~2\Altnet\DOWNLO~1\asmps.dll Fri Apr 15 23:48:20 2005 => File C:\PROGRA~2\Altnet\DOWNLO~1\asmps.dll infected by |
17.04.2005, 16:45 | #2 |
Administrator, a.D. | Hijack Logfile- es wäe sehr nett! Hallo,
__________________dein gepostetes Log-File lässt keine Analyse zu. Poste deshalb diese Teil: Öffne die mwav.log im Ordner C:\bases_x -> Bearbeiten -> Suchen -> infected oder tagged eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen.
__________________ |
Themen zu Hijack Logfile- es wäe sehr nett! |
.com, altnet, anleitung, antivirus, check, crypt, drivers, email, escan, file, hijack, infected, log file, office, p2p, programme, promo, registry, secur, services, software, super, system, t-online, temp, w32, web, windows |