![]() |
|
Plagegeister aller Art und deren Bekämpfung: Worm/SdBot.AA.14176 attack - hilfe!!!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() |
|
![]() | #1 |
![]() | ![]() Worm/SdBot.AA.14176 attack - hilfe!!! hallo! wie kriege ich den wurm Worm/SdBot.AA.14176 weg??? vielleicht kann ja jemand helfen... danke, lisa |
![]() | #2 |
![]() ![]() ![]() | ![]() Worm/SdBot.AA.14176 attack - hilfe!!! Hallo,
__________________wo wird der Wurm von welchem AV (ich vermute AniVir) gefunden? |
![]() | #3 |
![]() ![]() ![]() ![]() | ![]() Worm/SdBot.AA.14176 attack - hilfe!!! Der einfachste weg ist ein AV
__________________![]() anderenfalls kannst du einen Wurm auch einfach manuell entfernen. dazu würd ich dir empfehlen, HiJackThis runter zu laden und den Log hier zu posten. grüsse, ...
__________________ |
![]() | #4 |
![]() | ![]() Worm/SdBot.AA.14176 attack - hilfe!!! wurde von antiVir gefunden. ich weiß nicht genau wo. habe schonmal einen eScan gemacht, kann aber aus irgendeinem grund den log nicht posten (wegen überschreitung des zeitlimits). echt seltsam. |
![]() | #5 |
![]() ![]() ![]() | ![]() Worm/SdBot.AA.14176 attack - hilfe!!! Wenn du eScan nach Anleitung ausgeführt hast (nach c:\bases_x entpackt), mach bitte folgendes: Speichere diese Datei mittels Rechtsklick-> "Ziel speichern unter..." auf deiner Festplatte. Führe sie aus (Doppelklick). Danach solltest du die Datei c:\eScan_neu.txt auf deiner Festplatte finden. Den Inhalt dieser Datei postest du dann bitte in diesen Thread. |
![]() | #6 |
![]() | ![]() Worm/SdBot.AA.14176 attack - hilfe!!! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue May 17 13:42:50 2005 => File C:\WINDOWS\system32\nvms.dll infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. Tue May 17 13:43:01 2005 => File c:\windows\180ax.exe infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken. Tue May 17 13:43:01 2005 => File C:\Programme\NaviSearch\bin\nls.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. Tue May 17 13:43:03 2005 => File C:\WINDOWS\wdankl.exe infected by "not-a-virus:AdWare.180Solutions.e" Virus. Action Taken: No Action Taken. Tue May 17 13:43:15 2005 => File C:\WINDOWS\system32\angelex.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. Tue May 17 13:43:22 2005 => File C:\WINDOWS\zeta.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. Tue May 17 13:43:22 2005 => System found infected with MyBar Spyware/Adware ({0494d0d9-f8e0-41ad-92a3-14154ece70ac})! Action taken: No Action Taken. Tue May 17 13:43:22 2005 => File System Found infected by "MyBar Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:22 2005 => System found infected with bullseye network Spyware/Adware! Action taken: No Action Taken. Tue May 17 13:43:22 2005 => File System Found infected by "bullseye network Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:22 2005 => System found infected with exactutil Spyware/Adware! Action taken: No Action Taken. Tue May 17 13:43:22 2005 => File System Found infected by "exactutil Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:22 2005 => System found infected with text/html Spyware/Adware! Action taken: No Action Taken. Tue May 17 13:43:22 2005 => File System Found infected by "text/html Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:22 2005 => System found infected with KAZAA Spyware/Adware! Action taken: No Action Taken. Tue May 17 13:43:22 2005 => File System Found infected by "KAZAA Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:22 2005 => System found infected with PERFECTNAV Spyware/Adware! Action taken: No Action Taken. Tue May 17 13:43:22 2005 => File System Found infected by "PERFECTNAV Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:22 2005 => System found infected with ezula Spyware/Adware (exul.exe)! Action taken: No Action Taken. Tue May 17 13:43:22 2005 => File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:22 2005 => System found infected with ezula Spyware/Adware (angelex.exe)! Action taken: No Action Taken. Tue May 17 13:43:22 2005 => File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:23 2005 => System found infected with ezula Spyware/Adware (instsrv.exe)! Action taken: No Action Taken. Tue May 17 13:43:23 2005 => File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:23 2005 => System found infected with ezula Spyware/Adware (msexreg.exe)! Action taken: No Action Taken. Tue May 17 13:43:23 2005 => File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:23 2005 => System found infected with ezula Spyware/Adware (exdl.exe)! Action taken: No Action Taken. Tue May 17 13:43:23 2005 => File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:23 2005 => System found infected with ezula Spyware/Adware (bbchk.exe)! Action taken: No Action Taken. Tue May 17 13:43:23 2005 => File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:23 2005 => System found infected with ezula Spyware/Adware (mqexdlm.srg)! Action taken: No Action Taken. Tue May 17 13:43:23 2005 => File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:23 2005 => System found infected with ezula Spyware/Adware (vx0.nls)! Action taken: No Action Taken. Tue May 17 13:43:23 2005 => File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:23 2005 => System found infected with ezula Spyware/Adware (exclean.exe)! Action taken: No Action Taken. Tue May 17 13:43:23 2005 => File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:23 2005 => System found infected with ezula Spyware/Adware (netut80ex.vxd)! Action taken: No Action Taken. Tue May 17 13:43:23 2005 => File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:43:23 2005 => System found infected with ezula Spyware/Adware (javexulm.vxd)! Action taken: No Action Taken. Tue May 17 13:43:23 2005 => File System Found infected by "ezula Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 17 13:45:46 2005 => File C:\WINDOWS\180axhook.dll infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken. Tue May 17 13:45:47 2005 => File C:\WINDOWS\ahnls.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. Tue May 17 13:45:47 2005 => File C:\WINDOWS\autoheal.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. Tue May 17 13:45:49 2005 => File C:\WINDOWS\GrussProfi.exe41.exe infected by "not-a-virus:Porn-Dialer.Win32.Intexdial" Virus. Action Taken: No Action Taken. Tue May 17 13:45:50 2005 => File C:\WINDOWS\hausaufgaben.exe.exe infected by "not-a-virus:Porn-Dialer.Win32.Intexdial" Virus. Action Taken: No Action Taken. Tue May 17 13:45:50 2005 => File C:\WINDOWS\hausaufgaben.exe41.exe infected by "not-a-virus:Porn-Dialer.Win32.Intexdial" Virus. Action Taken: No Action Taken. Tue May 17 13:45:53 2005 => File C:\WINDOWS\NDNuninstall4_85.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Tue May 17 13:45:53 2005 => File C:\WINDOWS\NDNuninstall5_64.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Tue May 17 13:45:53 2005 => File C:\WINDOWS\NDNuninstall6_10.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Tue May 17 13:45:53 2005 => File C:\WINDOWS\NDNuninstall6_22.exe infected by "not-a-virus:AdWare.NewDotNet" Virus. Action Taken: No Action Taken. Tue May 17 13:45:55 2005 => File C:\WINDOWS\radiofox.exe.exe infected by "not-a-virus:Porn-Dialer.Win32.Intexdial" Virus. Action Taken: No Action Taken. Tue May 17 13:46:00 2005 => File C:\WINDOWS\Wetter-Basis.exe.exe infected by "not-a-virus:Porn-Dialer.Win32.Intexdial" Virus. Action Taken: No Action Taken. Tue May 17 13:46:37 2005 => File C:\WINDOWS\system32\exdl.exe infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. Tue May 17 13:46:37 2005 => File C:\WINDOWS\system32\exdl0.exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. Tue May 17 13:46:37 2005 => File C:\WINDOWS\system32\exdl2.exe infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. Tue May 17 13:46:37 2005 => File C:\WINDOWS\system32\exul.exe infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. Tue May 17 13:46:37 2005 => File C:\WINDOWS\system32\exul2.exe infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. Tue May 17 13:46:53 2005 => File C:\WINDOWS\system32\javex80.vxd infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. Tue May 17 13:46:54 2005 => File C:\WINDOWS\system32\javexulm.vxd infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. Tue May 17 13:47:14 2005 => File C:\WINDOWS\system32\mqexdlm.srg infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. Tue May 17 13:47:30 2005 => File C:\WINDOWS\system32\netut80ex.vxd infected by "not-a-virus:AdWare.BargainBuddy.q" Virus. Action Taken: No Action Taken. Tue May 17 14:20:21 2005 => File C:\DOKUME~1\lisa\LOKALE~1\TEMPOR~1\Content.IE5\O7XN2YV1\nls8034[1].exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. Tue May 17 14:36:44 2005 => File C:\Dokumente und Einstellungen\lisa\Lokale Einstellungen\Anwendungsdaten\Microsoft\Internet Explorer\V0.26.dat infected by "Trojan.Win32.Dialer.fy" Virus. Action Taken: No Action Taken. Tue May 17 15:08:29 2005 => File C:\Dokumente und Einstellungen\lisa\Lokale Einstellungen\Temporary Internet Files\Content.IE5\O7XN2YV1\nls8034[1].exe infected by "not-a-virus:AdWare.BargainBuddy.n" Virus. Action Taken: No Action Taken. Tue May 17 15:30:37 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.* Tue May 17 15:30:37 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\A0001101.EXE.VIR Tue May 17 15:30:38 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\A0001102.EXE.VIR Tue May 17 15:30:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\A0001847.EXE.VIR Tue May 17 15:30:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\A0002075.EXE.VIR Tue May 17 15:30:59 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\A0007978.EXE.VIR Tue May 17 15:30:59 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\A0007979.EXE.VIR Tue May 17 15:31:01 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\A0007980.EXE.VIR Tue May 17 15:31:03 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\A0009469.EXE.VIR Tue May 17 15:31:04 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\APYF.EXE.TMP.VIR Tue May 17 15:31:04 2005 => File C:\Programme\AVPersonal\INFECTED\APYF.EXE.TMP.VIR infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken. Tue May 17 15:31:04 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\BCNKHSR.EXE.TMP.VIR Tue May 17 15:31:04 2005 => File C:\Programme\AVPersonal\INFECTED\BCNKHSR.EXE.TMP.VIR infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken. Tue May 17 15:31:05 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\BJORK_PC.EXE.001 Tue May 17 15:31:06 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\BJORK_PC.EXE.VIR Tue May 17 15:31:07 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\CZEHGXWR.EXE.TMP.VIR Tue May 17 15:31:07 2005 => File C:\Programme\AVPersonal\INFECTED\CZEHGXWR.EXE.TMP.VIR infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken. Tue May 17 15:31:07 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\DIVX_311ALPHA.EXE.VIR Tue May 17 15:31:08 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\DQZ.EXE.TMP.VIR Tue May 17 15:31:08 2005 => File C:\Programme\AVPersonal\INFECTED\DQZ.EXE.TMP.VIR infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken. Tue May 17 15:31:08 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\DUMMY[1].CLASS.VIR [**] Tue May 17 15:31:08 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\EDOW_AS2.EXE.VIR Tue May 17 15:31:08 2005 => File C:\Programme\AVPersonal\INFECTED\EDOW_AS2.EXE.VIR infected by "Trojan-Downloader.Win32.QDown.m" Virus. Action Taken: No Action Taken. Tue May 17 15:31:08 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\EELS_SOULJACKER.EXE.VIR Tue May 17 15:31:09 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ILEXCD.EXE.TMP.VIR Tue May 17 15:31:09 2005 => File C:\Programme\AVPersonal\INFECTED\ILEXCD.EXE.TMP.VIR infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken. Tue May 17 15:31:09 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\NKJ.EXE.TMP.VIR Tue May 17 15:31:09 2005 => File C:\Programme\AVPersonal\INFECTED\NKJ.EXE.TMP.VIR infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken. Tue May 17 15:31:09 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\OJQBOVKZ.EXE.TMP.VIR Tue May 17 15:31:09 2005 => File C:\Programme\AVPersonal\INFECTED\OJQBOVKZ.EXE.TMP.VIR infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken. Tue May 17 15:31:09 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\QUICKTIME 7.2 (NEW).EXE.VIR Tue May 17 15:31:09 2005 => File C:\Programme\AVPersonal\INFECTED\QUICKTIME 7.2 (NEW).EXE.VIR infected by "P2P-Worm.Win32.SdDrop.d" Virus. Action Taken: No Action Taken. Tue May 17 15:31:09 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\SEARCH.VBS.VIR [**] Tue May 17 15:31:09 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\TGPYPGD.EXE.TMP.VIR Tue May 17 15:31:09 2005 => File C:\Programme\AVPersonal\INFECTED\TGPYPGD.EXE.TMP.VIR infected by "not-a-virus:AdWare.180Solutions" Virus. Action Taken: No Action Taken. Tue May 17 15:31:09 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\WHEZCB.EXE.TMP.VIR |
![]() |
Themen zu Worm/SdBot.AA.14176 attack - hilfe!!! |
attack, hilfe!, hilfe!!, hilfe!!!, kriege, wurm |