|
Log-Analyse und Auswertung: Problem mit IE HiJackerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
03.05.2005, 16:22 | #16 |
/// Helfer-Team | Problem mit IE HiJacker Den ersten Mist solltest Du damit wegbekommen: http://www.trojaner-info.de/anleitun...out_blank.html |
03.05.2005, 17:37 | #17 | |
| Problem mit IE HiJackerZitat:
der greift nicht irgendwie auf die windows such funktion zurück oder ?? und hier ist das escan log habe nur das gepostet was übrig blieb nachdem ich die find.bat drüber laufen ließ... ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue Apr 26 22:03:46 2005 => System found infected with gain Spyware/Adware! Action taken: No Action Taken. Tue Apr 26 22:03:46 2005 => File System Found infected by "gain Spyware/Adware" Virus. Action Taken: No Action Taken. Tue Apr 26 22:04:08 2005 => Total Disinfected Files: 0 Mon May 02 19:25:45 2005 => System found infected with gain Spyware/Adware! Action taken: No Action Taken. Mon May 02 19:25:45 2005 => File System Found infected by "gain Spyware/Adware" Virus. Action Taken: No Action Taken. Mon May 02 19:25:53 2005 => File C:\WINDOWS\sysini.ini infected by "Trojan-Spy.Win32.Tofger.ini" Virus. Action Taken: No Action Taken. Mon May 02 19:25:54 2005 => File C:\WINDOWS\ieky.dll infected by "Trojan-Downloader.Win32.Agent.lz" Virus. Action Taken: No Action Taken. Mon May 02 19:25:55 2005 => File C:\WINDOWS\msin32.dll infected by "Trojan-Spy.Win32.Tofger.f" Virus. Action Taken: No Action Taken. Mon May 02 19:26:04 2005 => File C:\WINDOWS\System32\msin32.dll infected by "Trojan-Spy.Win32.Tofger.f" Virus. Action Taken: No Action Taken. Mon May 02 19:26:42 2005 => File C:\WINDOWS\System32\cmd.ftp infected by "Trojan-Downloader.BAT.Ftp.r" Virus. Action Taken: No Action Taken. Mon May 02 19:27:02 2005 => File C:\DOKUME~1\Home\LOKALE~1\Temp\sp.dll infected by "not-a-virus:AdWare.SearchPage" Virus. Action Taken: No Action Taken. Mon May 02 19:32:06 2005 => Scanning File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\QTTI7UP8\oppinfected[1].gif Mon May 02 19:33:12 2005 => Scanning File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\HJZFXXKE\infected[1].gif Mon May 02 19:41:06 2005 => File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\WVZJI8XX\index2[2].htm infected by "Trojan-Dropper.Win32.RunMe" Virus. Action Taken: No Action Taken. Mon May 02 19:48:50 2005 => File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\CHY7SXUJ\hpp[1].hta infected by "Trojan-Downloader.VBS.Wipup" Virus. Action Taken: No Action Taken. Mon May 02 19:50:42 2005 => File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\0LQROL2J\dn[1].hta infected by "Trojan-Downloader.VBS.Iwill.q" Virus. Action Taken: No Action Taken. Mon May 02 19:50:42 2005 => File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\0LQROL2J\3[1].jpg infected by "Trojan-Proxy.Win32.Mitglieder.f" Virus. Action Taken: No Action Taken. Mon May 02 19:55:20 2005 => File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\GVPBYEZ5\connect[1].htm infected by "Exploit.HTML.CodeBaseExec" Virus. Action Taken: No Action Taken. Mon May 02 19:55:20 2005 => File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\GVPBYEZ5\connect[2].htm infected by "Exploit.HTML.CodeBaseExec" Virus. Action Taken: No Action Taken. Mon May 02 19:57:04 2005 => File C:\WINDOWS\system32\msin32.dll infected by "Trojan-Spy.Win32.Tofger.f" Virus. Action Taken: No Action Taken. Mon May 02 19:57:56 2005 => File C:\WINDOWS\system32\cmd.ftp infected by "Trojan-Downloader.BAT.Ftp.r" Virus. Action Taken: No Action Taken. Mon May 02 20:00:47 2005 => File C:\WINDOWS\sysini.ini infected by "Trojan-Spy.Win32.Tofger.ini" Virus. Action Taken: No Action Taken. Mon May 02 20:00:47 2005 => File C:\WINDOWS\ieky.dll infected by "Trojan-Downloader.Win32.Agent.lz" Virus. Action Taken: No Action Taken. Mon May 02 20:01:34 2005 => File C:\WINDOWS\msin32.dll infected by "Trojan-Spy.Win32.Tofger.f" Virus. Action Taken: No Action Taken. Mon May 02 20:02:02 2005 => File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temp\sp.dll infected by "not-a-virus:AdWare.SearchPage" Virus. Action Taken: No Action Taken. Mon May 02 20:07:07 2005 => Scanning File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temporary Internet Files\Content.IE5\QTTI7UP8\oppinfected[1].gif Mon May 02 20:08:09 2005 => Scanning File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temporary Internet Files\Content.IE5\HJZFXXKE\infected[1].gif Mon May 02 20:16:00 2005 => File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temporary Internet Files\Content.IE5\WVZJI8XX\index2[2].htm infected by "Trojan-Dropper.Win32.RunMe" Virus. Action Taken: No Action Taken. Mon May 02 20:23:45 2005 => File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temporary Internet Files\Content.IE5\CHY7SXUJ\hpp[1].hta infected by "Trojan-Downloader.VBS.Wipup" Virus. Action Taken: No Action Taken. Mon May 02 20:25:37 2005 => File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temporary Internet Files\Content.IE5\0LQROL2J\dn[1].hta infected by "Trojan-Downloader.VBS.Iwill.q" Virus. Action Taken: No Action Taken. Mon May 02 20:25:37 2005 => File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temporary Internet Files\Content.IE5\0LQROL2J\3[1].jpg infected by "Trojan-Proxy.Win32.Mitglieder.f" Virus. Action Taken: No Action Taken. Mon May 02 20:30:04 2005 => File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temporary Internet Files\Content.IE5\GVPBYEZ5\connect[1].htm infected by "Exploit.HTML.CodeBaseExec" Virus. Action Taken: No Action Taken. Mon May 02 20:30:04 2005 => File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temporary Internet Files\Content.IE5\GVPBYEZ5\connect[2].htm infected by "Exploit.HTML.CodeBaseExec" Virus. Action Taken: No Action Taken. Mon May 02 20:40:53 2005 => File C:\System Volume Information\_restore{7E21E3DE-D839-423F-A518-3742D6371361}\RP441\A0028844.exe infected by "Trojan-Downloader.Win32.Zlob.g" Virus. Action Taken: No Action Taken. Mon May 02 20:41:03 2005 => File C:\System Volume Information\_restore{7E21E3DE-D839-423F-A518-3742D6371361}\RP449\A0029143.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. Mon May 02 20:41:03 2005 => File C:\System Volume Information\_restore{7E21E3DE-D839-423F-A518-3742D6371361}\RP449\A0029144.exe infected by "Trojan-Downloader.Win32.Agent.bq" Virus. Action Taken: No Action Taken. Mon May 02 20:41:03 2005 => File C:\System Volume Information\_restore{7E21E3DE-D839-423F-A518-3742D6371361}\RP449\A0029146.exe infected by "Trojan-Downloader.Win32.Small.aru" Virus. Action Taken: No Action Taken. Mon May 02 20:41:05 2005 => File C:\System Volume Information\_restore{7E21E3DE-D839-423F-A518-3742D6371361}\RP450\A0029235.EXE infected by "Trojan-Proxy.Win32.Mitglieder.f" Virus. Action Taken: No Action Taken. Mon May 02 20:45:46 2005 => File D:\Downloads\Tools\CloneCD\CloneCD 4[1].0.0.zip infected by "Trojan-Downloader.Win32.Small.aiv" Virus. Action Taken: No Action Taken. Mon May 02 21:05:50 2005 => Total Disinfected Files: 0 Tue May 03 17:21:34 2005 => System found infected with gain Spyware/Adware! Action taken: No Action Taken. Tue May 03 17:21:34 2005 => File System Found infected by "gain Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 03 17:21:34 2005 => System found infected with sw Spyware/Adware! Action taken: No Action Taken. Tue May 03 17:21:34 2005 => File System Found infected by "sw Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 03 17:21:34 2005 => System found infected with se Spyware/Adware! Action taken: No Action Taken. Tue May 03 17:21:34 2005 => File System Found infected by "se Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 03 17:21:34 2005 => System found infected with hsa Spyware/Adware! Action taken: No Action Taken. Tue May 03 17:21:34 2005 => File System Found infected by "hsa Spyware/Adware" Virus. Action Taken: No Action Taken. Tue May 03 17:21:42 2005 => File C:\WINDOWS\sysini.ini infected by "Trojan-Spy.Win32.Tofger.ini" Virus. Action Taken: No Action Taken. Tue May 03 17:21:42 2005 => File C:\WINDOWS\ieky.dll infected by "Trojan-Downloader.Win32.Agent.lz" Virus. Action Taken: No Action Taken. Tue May 03 17:21:44 2005 => File C:\WINDOWS\msin32.dll infected by "Trojan-Spy.Win32.Tofger.f" Virus. Action Taken: No Action Taken. Tue May 03 17:21:55 2005 => File C:\WINDOWS\System32\msin32.dll infected by "Trojan-Spy.Win32.Tofger.f" Virus. Action Taken: No Action Taken. Tue May 03 17:22:57 2005 => File C:\WINDOWS\System32\cmd.ftp infected by "Trojan-Downloader.BAT.Ftp.r" Virus. Action Taken: No Action Taken. Tue May 03 17:23:24 2005 => File C:\DOKUME~1\Home\LOKALE~1\Temp\sp.dll infected by "not-a-virus:AdWare.SearchPage" Virus. Action Taken: No Action Taken. Tue May 03 17:29:43 2005 => Scanning File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\QTTI7UP8\oppinfected[1].gif Tue May 03 17:31:02 2005 => Scanning File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\HJZFXXKE\infected[1].gif Tue May 03 17:41:11 2005 => File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\WVZJI8XX\index2[2].htm infected by "Trojan-Dropper.Win32.RunMe" Virus. Action Taken: No Action Taken. Tue May 03 17:51:41 2005 => File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\CHY7SXUJ\hpp[1].hta infected by "Trojan-Downloader.VBS.Wipup" Virus. Action Taken: No Action Taken. Tue May 03 17:54:10 2005 => File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\0LQROL2J\dn[1].hta infected by "Trojan-Downloader.VBS.Iwill.q" Virus. Action Taken: No Action Taken. Tue May 03 18:00:10 2005 => File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\GVPBYEZ5\connect[1].htm infected by "Exploit.HTML.CodeBaseExec" Virus. Action Taken: No Action Taken. Tue May 03 18:00:10 2005 => File C:\DOKUME~1\Home\LOKALE~1\TEMPOR~1\Content.IE5\GVPBYEZ5\connect[2].htm infected by "Exploit.HTML.CodeBaseExec" Virus. Action Taken: No Action Taken. Tue May 03 18:02:35 2005 => File C:\WINDOWS\system32\msin32.dll infected by "Trojan-Spy.Win32.Tofger.f" Virus. Action Taken: No Action Taken. Tue May 03 18:03:54 2005 => File C:\WINDOWS\system32\cmd.ftp infected by "Trojan-Downloader.BAT.Ftp.r" Virus. Action Taken: No Action Taken. Tue May 03 18:09:08 2005 => File C:\WINDOWS\sysini.ini infected by "Trojan-Spy.Win32.Tofger.ini" Virus. Action Taken: No Action Taken. Tue May 03 18:09:09 2005 => File C:\WINDOWS\ieky.dll infected by "Trojan-Downloader.Win32.Agent.lz" Virus. Action Taken: No Action Taken. Tue May 03 18:10:28 2005 => File C:\WINDOWS\msin32.dll infected by "Trojan-Spy.Win32.Tofger.f" Virus. Action Taken: No Action Taken. Tue May 03 18:11:01 2005 => File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temp\sp.dll infected by "not-a-virus:AdWare.SearchPage" Virus. Action Taken: No Action Taken. Tue May 03 18:17:41 2005 => Scanning File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temporary Internet Files\Content.IE5\QTTI7UP8\oppinfected[1].gif Tue May 03 18:19:05 2005 => Scanning File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temporary Internet Files\Content.IE5\HJZFXXKE\infected[1].gif Tue May 03 18:29:36 2005 => File C:\Dokumente und Einstellungen\Home\Lokale Einstellungen\Temporary Internet Files\Content.IE5\WVZJI8XX\index2[2].htm infected by "Trojan-Dropper.Win32.RunMe" Virus. Action Taken: No Action Taken. Tue May 03 18:35:05 2005 => Total Disinfected Files: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Mon May 02 19:55:45 2005 => File C:\sd\EBD.CAB tagged as not-a-virus:Tool.DOS.Restart. No Action Taken. Mon May 02 20:44:25 2005 => File D:\Downloads\Tools\ARISetup0621.exe tagged as not-a-virus:RiskWare.Tool.PsExec.13. No Action Taken. Mon May 02 20:47:16 2005 => File D:\Games\Counter Strike\hltv.exe tagged as not-a-virus:RiskWare.Proxy.Hltv. No Action Taken. Mon May 02 20:47:59 2005 => File D:\Sicherung\Martin Möller\Lokale Einstellungen\Temporary Internet Files\Content.IE5\456J8XYN\loader[1].cab tagged as not-a-virus:RiskWare.Downloader.Comb. No Action Taken. Mon May 02 20:57:36 2005 => File D:\Sicherung\Programme\Martin.exe tagged as not-a-virus:Simulator.Win16.Sheep. No Action Taken. Tue May 03 18:00:44 2005 => File C:\sd\EBD.CAB tagged as not-a-virus:Tool.DOS.Restart. No Action Taken. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue Apr 26 22:04:08 2005 => Total Virus(es) Found: 1 Mon May 02 21:05:50 2005 => Total Virus(es) Found: 36 Tue May 03 18:35:05 2005 => Total Virus(es) Found: 23 Tue Apr 26 22:04:08 2005 => Total Errors: 4469 Mon May 02 21:05:50 2005 => Total Errors: 38 Tue May 03 18:35:05 2005 => Total Errors: 31 Tue Apr 26 22:04:08 2005 => Time Elapsed: 02:00:17 Mon May 02 21:05:50 2005 => Time Elapsed: 01:40:35 Tue May 03 18:35:05 2005 => Time Elapsed: 01:13:56 Tue Apr 26 22:04:08 2005 => Total Objects Scanned: 3417 Mon May 02 21:05:50 2005 => Total Objects Scanned: 270921 Tue May 03 18:35:05 2005 => Total Objects Scanned: 152199 Tue Apr 26 22:04:08 2005 => Virus Database Date: 2005/04/25 Tue Apr 26 22:04:18 2005 => Virus Database Date: 2005/04/25 Mon May 02 19:24:21 2005 => Virus Database Date: 2005/04/25 Mon May 02 21:05:50 2005 => Virus Database Date: 2005/04/25 Mon May 02 21:40:01 2005 => Virus Database Date: 2005/04/25 Tue May 03 17:20:50 2005 => Virus Database Date: 2005/04/25 Tue May 03 18:35:04 2005 => Virus Database Date: 2005/04/25 Tue May 03 18:36:00 2005 => Virus Database Date: 2005/04/25 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~ © Haui ;-) ~~~~~~~ ~~~~~~~ Dank an Cidre ~~~~~~~ |
03.05.2005, 17:40 | #18 |
/// Helfer-Team | Problem mit IE HiJacker__________________ |
03.05.2005, 17:49 | #19 |
| Problem mit IE HiJacker der link funktioniert schon nur wenn ich bei dem programm auf "säubern" klicke passiert rein gar nix ... oder muß ich da auch erst irgendwas umstellen ... steht ja leider nix im text also bin ich von ausgegangen das das so geht |
03.05.2005, 19:45 | #20 |
/// Helfer-Team | Problem mit IE HiJacker Wenn Du es im normalen Modus ausgeführt hast, versuche es mal im abgesicherten. Ansonsten umgekehrt, ich kam selbst noch nicht in die Situation, ihn anzuwenden :aplaus: |
04.05.2005, 14:11 | #21 |
/// Helfer-Team | Problem mit IE HiJacker Lese Dir das mal durch: http://www.trojaner-board.com/showthread.php?t=14366 |
Themen zu Problem mit IE HiJacker |
adobe, beim starten, bho, computer, desktop, einstellungen, excel, explorer, firewall, helfen, hijack, hijackthis, home, internet, internet explorer, log, monitor, officescan, problem, programme, senden, software, starten, system, temp, trend micro, urlsearchhook, windows, windows xp, windows\temp |