|
Log-Analyse und Auswertung: Log, Log ... bitte helfen!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
19.05.2005, 20:54 | #1 |
| Log, Log ... bitte helfen! Liebe Forenmitglieder + Retter, da ich ich nur einen begrenzten Horizont an Ahnung von PC's habe "muss" ich mich an euch wenden und um Hilfe rufen. "HILFE!!!" Hab seit 2 Wochen immer die AntiVir Warunung von so nem "POLLER Virus" und nem "ZPJHVSUJJNM Trojaner"! Da mir das fürchtbar viel sagt und da AntiVir den natürlich auch net komplett löschen kann oder überschreiben, da die beide in System32 sind... und ich die da auch nirgends finde, bin ich verzweifelt und bin, gottseidank, auf das Forum gestoßen und auf die SEHR GUTE Anleitung für eScan... Bin für jede Antwort dankbar - in dem Sinne ANDIMANN P.S. Hier natürlich noch meine Log Daten ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Wed May 11 21:20:21 2005 => File C:\WINDOWS\svcproc.exe infected by "Trojan.Win32.Stervis.c" Virus. Action Taken: No Action Taken. Wed May 11 21:20:23 2005 => System found infected with SideFind Spyware/Adware ({10e42047-deb9-4535-a118-b3f6ec39b807})! Action taken: No Action Taken. Wed May 11 21:20:23 2005 => File System Found infected by "SideFind Spyware/Adware" Virus. Action Taken: No Action Taken. Wed May 11 21:22:13 2005 => File C:\WINDOWS\system32\sfx_webhancer.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Wed May 11 21:24:17 2005 => File C:\DOKUME~1\Andi\LOKALE~1\TEMPOR~1\Content.IE5\19RANQYB\istsvc[1].exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken. Wed May 11 21:24:23 2005 => File C:\DOKUME~1\Andi\LOKALE~1\TEMPOR~1\Content.IE5\YKO6G2DE\sidefind13[1].dll infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken. Wed May 11 21:24:23 2005 => File C:\DOKUME~1\Andi\LOKALE~1\TEMPOR~1\Content.IE5\YKO6G2DE\svcproc[1].exe infected by "Trojan.Win32.Stervis.c" Virus. Action Taken: No Action Taken. Wed May 11 21:31:40 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temporary Internet Files\Content.IE5\19RANQYB\istsvc[1].exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken. Wed May 11 21:31:45 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YKO6G2DE\sidefind13[1].dll infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken. Wed May 11 21:31:45 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YKO6G2DE\svcproc[1].exe infected by "Trojan.Win32.Stervis.c" Virus. Action Taken: No Action Taken. Wed May 11 21:40:50 2005 => File C:\Program Files\Win_whcr\webhancer_winrar.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Wed May 11 21:55:28 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.* Thu May 19 18:27:02 2005 => C:\WINDOWS\svcproc.exe possibly infected and removed by background antivirus package! Thu May 19 18:27:05 2005 => File C:\WINDOWS\svcproc.exe infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken. Thu May 19 18:27:07 2005 => System found infected with SideFind Spyware/Adware ({10e42047-deb9-4535-a118-b3f6ec39b807})! Action taken: No Action Taken. Thu May 19 18:27:07 2005 => File System Found infected by "SideFind Spyware/Adware" Virus. Action Taken: No Action Taken. Thu May 19 18:29:18 2005 => File C:\WINDOWS\system32\sfx_webhancer.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 18:56:55 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.* Thu May 19 18:56:55 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.001 Thu May 19 18:56:55 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.001 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. Thu May 19 18:56:55 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.002 Thu May 19 18:56:55 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.002 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. Thu May 19 18:56:55 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.003 Thu May 19 18:56:56 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.003 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. Thu May 19 18:56:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.004 Thu May 19 18:56:56 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.004 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. Thu May 19 18:56:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.005 Thu May 19 18:56:56 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.005 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. Thu May 19 18:56:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.VIR Thu May 19 18:56:56 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.VIR infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. Thu May 19 18:56:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.001 Thu May 19 18:56:57 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.001 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.002 Thu May 19 18:56:57 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.002 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.003 Thu May 19 18:56:57 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.003 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.004 Thu May 19 18:56:57 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.004 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.005 Thu May 19 18:56:58 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.005 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.006 Thu May 19 18:56:58 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.006 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.007 Thu May 19 18:56:58 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.007 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.008 Thu May 19 18:56:58 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.008 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.009 Thu May 19 18:56:59 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.009 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:59 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.010 Thu May 19 18:56:59 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.010 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:59 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.VIR Thu May 19 18:56:59 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.VIR infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010888.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010889.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010890.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010891.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010901.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010903.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:02 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP75\A0012087.exe infected by "not-a-virus:AdWare.WebHancer.351" Virus. Action Taken: No Action Taken. Thu May 19 19:37:08 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP77\A0012149.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:08 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP77\A0012150.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:10 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP77\A0012173.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:15 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012227.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:15 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012231.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:17 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012287.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:18 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012288.exe infected by "not-a-virus:AdWare.WebHancer.351" Virus. Action Taken: No Action Taken. Thu May 19 19:37:18 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012291.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:18 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012292.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:18 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012294.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 20:54:44 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP96\A0014816.dll infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken. Thu May 19 20:56:14 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP97\A0016058.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 21:14:01 2005 => File C:\WINDOWS\system32\sfx_webhancer.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Wed May 11 21:24:03 2005 => File C:\DOKUME~1\Andi\LOKALE~1\Temp\Temporäres Verzeichnis 1 für radmin22.zip\RADMIN22.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken. Wed May 11 21:27:27 2005 => File C:\Dokumente und Einstellungen\Andi\Eigene Dateien\Downloads\vnc-4.0b5-x86_win32.exe tagged as not-a-virus:RiskWare.RemoteAdmin.WinVNC.4. No Action Taken. Wed May 11 21:31:26 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temp\Temporäres Verzeichnis 1 für radmin22.zip\RADMIN22.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken. Thu May 19 18:31:59 2005 => File C:\DOKUME~1\Andi\LOKALE~1\Temp\Temporäres Verzeichnis 1 für radmin22.zip\RADMIN22.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken. Thu May 19 18:37:31 2005 => File C:\Dokumente und Einstellungen\Andi\Eigene Dateien\Downloads\vnc-4.0b5-x86_win32.exe tagged as not-a-virus:RiskWare.RemoteAdmin.WinVNC.4. No Action Taken. Thu May 19 18:42:41 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temp\Temporäres Verzeichnis 1 für radmin22.zip\RADMIN22.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken. Thu May 19 19:36:40 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0009840.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Wed May 11 21:19:14 2005 => Virus Database Date: 2005/05/05 Thu May 19 18:25:42 2005 => Virus Database Date: 2005/05/05 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~ © Haui ;-) ~~~~~~~ ~~~~~~~ Dank an Cidre ~~~~~~~ |
Themen zu Log, Log ... bitte helfen! |
.dll, 1.exe, adware.betterinternet, adware.webhancer, anleitung, antivir, antivirus, c:\windows, content.ie5, dateien, einstellungen, file, forum, helfen, hilfe!, hilfe!!, hilfe!!!, infected, internet, komplett löschen, log, löschen, not-a-virus, programme, system, system volume information, system32, trojaner, virus, warunung, windows, _restore |