|
Log-Analyse und Auswertung: hilfe bei trojaner (log file)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
21.05.2005, 03:30 | #1 |
| hilfe bei trojaner (log file) hab mir beim surfen irgendwas eingefangen, keine ahnung was. bin dann bei google auf diesen post (http://www.trojaner-board.de/archive...p/t-14593.html) gestoßen und hab alles gemacht, was da stand. hab eigentlich noch den eScan log, der war aber zu lang. falls der benoetigt wird, kann ich den auch noch anders schicken (z.B. email). hijackthis log: Logfile of HijackThis v1.99.1 Scan saved at 21:52:59, on 20.5.2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.exe C:\WINDOWS\System32\kernels32.exe C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\vxh8jkdq6.exe C:\WINDOWS\System32\vxh8jkdq7.exe C:\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://www.t-online.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = h**p://www.websearch.com/ie.aspx?tb_id=50162 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = h**p://www.websearch.com/ie.aspx?tb_id=50162 R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = res://C:\PROGRA~1\Toolbar\toolbar.dll/sa R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - Default URLSearchHook is missing F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\System32\kernels32.exe O2 - BHO: (no name) - {016235BE-59D4-4CEB-ADD5-E2378282A1D9} - C:\Programme\CxtPls\cxtpls.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: Loader Class - {2E246FAE-8420-11D9-870D-000C2917DE7F} - C:\WINDOWS\SYSTEM\Loader.dll O2 - BHO: (no name) - {87766247-311C-43B4-8499-3D5FEC94A183} - C:\PROGRA~1\GEMEIN~1\WinTools\WToolsB.dll O2 - BHO: (no name) - {8952A998-1E7E-4716-B23D-3DBE03910972} - C:\Programme\Toolbar\toolbar.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar2.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\System32\msbe.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar2.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: UCmore XP - The Search Accelerator - {44BE0690-5429-47f0-85BB-3FFD8020233E} - C:\Programme\TheSearchAccelerator\UCMTSAIE.dll (file missing) O3 - Toolbar: &Search Toolbar - {339BB23F-A864-48C0-A59F-29EA915965EC} - C:\Programme\Toolbar\toolbar.dll O4 - HKLM\..\Run: [CloneCDElbyCDFL] "C:\Programme\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [System] C:\WINDOWS\System32\kernels32.exe O4 - HKLM\..\Run: [WindowsUpdate] C:\RECYCLER\svchost.exe /s O4 - HKLM\..\Run: [saap] c:\program files\180search assistant\saap.exe O4 - HKLM\..\Run: [WinTools] C:\PROGRA~1\GEMEIN~1\WinTools\WToolsA.exe O4 - HKLM\..\Run: [gtwfmp] C:\WINDOWS\gtwfmp.exe O4 - HKLM\..\Run: [BullsEye Network] C:\Programme\BullsEye Network\bin\bargains.exe O4 - HKLM\..\Run: [4F3S3mO] jvimebuf.exe O4 - HKLM\..\Run: [lc2s899k] C:\WINDOWS\System32\lc2s899k.exe O4 - HKLM\..\Run: [AutoUpdater] "C:\Program Files\AutoUpdate\AutoUpdate.exe" O4 - HKLM\..\Run: [TBPS] C:\PROGRA~1\Toolbar\TBPS.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE O8 - Extra context menu item: &Download with &DAP - C:\PROGRA~1\DAP\dapextie.htm O8 - Extra context menu item: Download &all with DAP - D:\PROGRA~1\DAP\dapextie2.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP provider 'xfire_lsp_10908.dll' missing O15 - Trusted Zone: *.blazefind.com (HKLM) O15 - Trusted Zone: *.clickspring.net (HKLM) O15 - Trusted Zone: *.flingstone.com (HKLM) O15 - Trusted Zone: *.mt-download.com (HKLM) O15 - Trusted Zone: *.my-internet.info (HKLM) O15 - Trusted Zone: *.searchbarcash.com (HKLM) O15 - Trusted Zone: *.searchmiracle.com (HKLM) O15 - Trusted Zone: *.skoobidoo.com (HKLM) O15 - Trusted Zone: *.slotch.com (HKLM) O15 - Trusted Zone: *.slotchbar.com (HKLM) O15 - Trusted Zone: *.windupdates.com (HKLM) O15 - Trusted Zone: *.xxxtoolbar.com (HKLM) O15 - Trusted Zone: *.ysbweb.com (HKLM) O15 - Trusted IP range: 67.19.178.84 (HKLM) O18 - Protocol: tpro - {FF76A5DA-6158-4439-99FF-EDC1B3FE100C} - C:\Programme\Toolbar\toolbar.dll O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe O23 - Service: Norton AntiVirus Auto-Protect-Dienst (navapsvc) - Symantec Corporation - C:\Programme\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Unerase Protection (NProtectService) - Symantec Corporation - C:\Programme\Norton AntiVirus\AdvTools\NPROTECT.EXE O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SAVScan - Symantec Corporation - C:\Programme\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe O23 - Service: ZESOFT - Unknown owner - C:\WINDOWS\zeta.exe vielen dank schonmal an euch^^ _____________ Anm. Aktive Links editiert! Beachte die Hinweise dieser Anleitung: HiJackThis LG Cidre S-Mod TB Geändert von Cidre (21.05.2005 um 22:59 Uhr) |
21.05.2005, 10:07 | #2 |
| hilfe bei trojaner (log file) @slade
__________________hab eigentlich noch den eScan log, der war aber zu lang. poste bitte folgendes EscanErgebnis Teile uns das Ergebnis des eScan mit: "öffne die mwav.log -> Bearbeiten -> Suchen -> infected oder tagged eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen." chaosman
__________________ |
21.05.2005, 14:10 | #3 |
| hilfe bei trojaner (log file) jaja ich weiß, deswegen wollte ich ja auch die mwXface.log senden, weil da nur die infected sachen stehen. aber die ist zu groß und euer forum laesst mich die nich abschicken. da kommt immer ein fehler vonwegen 30 sek und so.die log is 187 kb groß. deswegen wollte ich sie auch anders schicken.
__________________ |
21.05.2005, 14:15 | #4 |
| hilfe bei trojaner (log file) Dann teile dein Ergebnis in mehrere Antworten auf.
__________________ Only cronos endures |
21.05.2005, 15:05 | #5 |
| hilfe bei trojaner (log file) [msvLclnt.dll] [0x000004f0] 20/05/2005 21:55:22:126 :ModuleName = C:\bases\mwavscan.com [msvLclnt.dll] [0x000004f0] 20/05/2005 21:55:22:126 :Registry Key Deleted Properly!!! [msvLclnt.dll] [0x000004f0] 20/05/2005 21:55:26:853 :Options Set by External applications mwavscan.com are 9896960 (0x970400): [msvLclnt.dll] [0x000004f0] 20/05/2005 21:55:26:853 :Mode :PACKED,ARCHIVED,CA,WARNINGS,MAILPLAIN [msvLclnt.dll] [0x000004f0] 20/05/2005 21:55:26:853 :TimeOut : ffffffff [msvLclnt.dll] [0x000004f0] 20/05/2005 21:55:26:853 :Priority : NORMAL [msvLclnt.dll] [0x000004f0] 20/05/2005 21:55:30:558 :VirusCount = 130890 Latest Date = 2005/05/20 [msvLclnt.dll] [0x00000564] 20/05/2005 21:56:30:765 :[00000001] File C:\WINDOWS\System32\kernels32.exe infected by Trojan-Downloader.Win32.Small.agq [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:14:708 :[00000001] File C:\WINDOWS\System32\bre.dll infected by Trojan-Downloader.Win32.Small.ajp [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:14:808 :[00000001] File C:\WINDOWS\System32\vxh8jkdq6.exe infected by Trojan-Downloader.Win32.Small.aux [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:17:532 :[00000001] File C:\WINDOWS\SYSTEM\Loader.dll infected by Trojan-Downloader.Win32.Agent.li [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:17:632 :[00000001] File C:\PROGRA~1\GEMEIN~1\WinTools\WToolsB.dll infected by not-a-virus:AdWare.Wintol.y [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:17:733 :[00000001] File C:\WINDOWS\System32\msbe.dll infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:17:843 :[00000001] File C:\WINDOWS\System32\bre.dll infected by Trojan-Downloader.Win32.Small.ajp [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:29:770 :[00000001] File C:\WINDOWS\System32\kernels32.exe infected by Trojan-Downloader.Win32.Small.agq [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:29:830 :[00000001] File C:\RECYCLER\svchost.exe infected by Trojan-Dropper.Win32.Agent.kz [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:30:020 :[00000001] File C:\PROGRA~1\GEMEIN~1\WinTools\WToolsA.exe infected by not-a-virus:AdWare.Wintol.aa [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:30:110 :[00000001] File C:\WINDOWS\gtwfmp.exe infected by not-a-virus:AdWare.180Solutions [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:30:992 :[00000001] File C:\PROGRA~2\AUTOUP~1\AUTOUP~1.EXE infected by Trojan-Downloader.Win32.Apropo.g [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:31:162 :[00000001] File C:\PROGRA~1\Toolbar\TBPS.exe infected by not-a-virus:AdWare.WebSearch.aj [msvLclnt.dll] [0x00000564] 20/05/2005 21:57:41:977 :[00000001] File C:\WINDOWS\zeta.exe infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 21:58:24:158 :[00000001] File C:\WINDOWS\cxtpls_loader.exe infected by Trojan-Downloader.Win32.Apropo.ab [msvLclnt.dll] [0x00000564] 20/05/2005 21:58:24:308 :[00000001] File C:\WINDOWS\desktop.html infected by Trojan-Clicker.Win32.Spywad.b [msvLclnt.dll] [0x00000564] 20/05/2005 21:58:25:220 :[00000001] File C:\WINDOWS\installer_SIAC.exe infected by Trojan-Downloader.Win32.Adload.a [msvLclnt.dll] [0x00000564] 20/05/2005 21:58:33:121 :[00000001] File C:\WINDOWS\optimize.exe infected by Trojan-Downloader.Win32.Dyfuca.dk [msvLclnt.dll] [0x00000564] 20/05/2005 21:58:44:007 :[00000001] File C:\WINDOWS\System32\angelex.exe infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 21:59:41:740 :[00000001] File C:\WINDOWS\System32\exdl.exe infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 21:59:41:850 :[00000001] File C:\WINDOWS\System32\exdl0.exe infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 21:59:41:940 :[00000001] File C:\WINDOWS\System32\exdl1.exe infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 21:59:42:991 :[00000001] File C:\WINDOWS\System32\exul.exe infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 22:00:04:703 :[00000001] File C:\WINDOWS\System32\instsrv.exe infected by not-a-virus:RiskWare.Tool.ServiceRunner.f [msvLclnt.dll] [0x00000564] 20/05/2005 22:00:12:674 :[00000001] File C:\WINDOWS\System32\javexulm.vxd infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 22:00:31:411 :[00000001] File C:\WINDOWS\System32\mac80ex.idf infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 22:00:47:805 :[00000001] File C:\WINDOWS\System32\mqexdlm.srg infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 22:01:28:163 :[00000001] File C:\WINDOWS\System32\netut80ex.vxd infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 22:03:28:956 :[00000001] File C:\WINDOWS\System32\thun32.dll infected by Trojan-Proxy.Win32.Small.bk [msvLclnt.dll] [0x00000564] 20/05/2005 22:03:42:285 :[00000001] File C:\WINDOWS\System32\vxgame1.exe infected by Trojan-Dropper.Win32.Small.wv [msvLclnt.dll] [0x00000564] 20/05/2005 22:03:42:376 :[00000001] File C:\WINDOWS\System32\vxgamet1.exe infected by Trojan-Downloader.Win32.Small.aqt [msvLclnt.dll] [0x00000564] 20/05/2005 22:03:42:436 :[00000001] File C:\WINDOWS\System32\vxgamet2.exe infected by Trojan.Win32.LowZones.y [msvLclnt.dll] [0x00000564] 20/05/2005 22:03:42:566 :[00000001] File C:\WINDOWS\System32\vxh8jkdq1.exe infected by Trojan-Dropper.Win32.Small.wp [msvLclnt.dll] [0x00000564] 20/05/2005 22:03:42:706 :[00000001] File C:\WINDOWS\System32\vxh8jkdq6.exe infected by Trojan-Downloader.Win32.Small.aux [msvLclnt.dll] [0x00000564] 20/05/2005 22:03:42:826 :[00000001] File C:\WINDOWS\System32\vxh8jkdq8.exe infected by Trojan-Dropper.Win32.Small.wp [msvLclnt.dll] [0x00000564] 20/05/2005 22:07:23:263 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Anwendungsdaten\{35A3A4F2-B792-11D6-A78A-00B0D0142030}\Java 2 SDK, SE v1.4.2_03.msi infected by not-a-virus:JavaClass.Chart [msvLclnt.dll] [0x00000564] 20/05/2005 22:07:43:222 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\1.qtdfmp infected by Trojan-Dropper.Win32.Small.wp [msvLclnt.dll] [0x00000564] 20/05/2005 22:07:43:653 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\180sainstaller.exe infected by not-a-virus:AdWare.180Solutions.b [msvLclnt.dll] [0x00000564] 20/05/2005 22:07:45:435 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\5.qtdfmp infected by Trojan-Downloader.Win32.Small.fo [msvLclnt.dll] [0x00000564] 20/05/2005 22:07:45:485 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\6.qtdfmp infected by Trojan-Downloader.Win32.Small.aux [msvLclnt.dll] [0x00000564] 20/05/2005 22:07:47:478 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\AutoUpdate0\auto_update_install.exe infected by Trojan-Downloader.Win32.Apropo.u [msvLclnt.dll] [0x00000564] 20/05/2005 22:07:55:299 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\cln26D.tmp infected by Trojan-Downloader.Win32.Dyfuca.dk [msvLclnt.dll] [0x00000564] 20/05/2005 22:08:11:322 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\OUIHI95S.dll infected by not-a-virus:AdWare.Sahat.w [msvLclnt.dll] [0x00000564] 20/05/2005 22:08:11:593 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\res25F.tmp infected by not-a-virus:AdWare.180Solutions.b [msvLclnt.dll] [0x00000564] 20/05/2005 22:26:41:198 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\vx1.game infected by Trojan-Dropper.Win32.Small.wv [msvLclnt.dll] [0x00000564] 20/05/2005 22:26:41:258 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\vx2.game infected by Trojan-Dropper.Win32.Agent.kz [msvLclnt.dll] [0x00000564] 20/05/2005 22:26:41:369 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\vxt1.game infected by Trojan-Downloader.Win32.Small.aqt [msvLclnt.dll] [0x00000564] 20/05/2005 22:26:41:449 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\vxt2.game infected by Trojan.Win32.LowZones.y [msvLclnt.dll] [0x00000564] 20/05/2005 22:26:41:959 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temp\xwxload.exe infected by Trojan-Downloader.Win32.Small.fo [msvLclnt.dll] [0x00000564] 20/05/2005 22:27:11:322 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temporary Internet Files\Content.IE5\24DVH1UY\Toolbar3[1].cab infected by not-a-virus:RiskWare.Tool.Exporun [msvLclnt.dll] [0x00000564] 20/05/2005 22:27:12:974 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temporary Internet Files\Content.IE5\24DVH1UY\vxxv[1].php infected by Trojan-Clicker.JS.Linker.j [msvLclnt.dll] [0x00000564] 20/05/2005 22:27:13:224 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temporary Internet Files\Content.IE5\24DVH1UY\WinTS[1].cab infected by Trojan-Downloader.Win32.Wintool.f [msvLclnt.dll] [0x00000564] 20/05/2005 22:27:33:163 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temporary Internet Files\Content.IE5\48SHZNAB\sploit[1].anr infected by Trojan-Downloader.Win32.Ani.c [msvLclnt.dll] [0x00000564] 20/05/2005 22:28:01:394 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temporary Internet Files\Content.IE5\CQZ3GSDM\vxxv[1].php infected by Trojan-Clicker.JS.Linker.j [msvLclnt.dll] [0x00000564] 20/05/2005 22:28:27:491 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temporary Internet Files\Content.IE5\OJP7UQZD\1[1].htm infected by Exploit.HTML.Mht [msvLclnt.dll] [0x00000564] 20/05/2005 22:28:41:551 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temporary Internet Files\Content.IE5\OJP7UQZD\mtrslib2[1].js infected by Trojan-Downloader.JS.Small.ag [msvLclnt.dll] [0x00000564] 20/05/2005 22:28:43:064 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temporary Internet Files\Content.IE5\OJP7UQZD\package_adp_SIAC[1].exe infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 22:29:19:286 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temporary Internet Files\Content.IE5\UTV0TKJM\win32[1].exe infected by Trojan-Downloader.Win32.Small.agq [msvLclnt.dll] [0x00000564] 20/05/2005 22:29:26:296 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temporary Internet Files\Content.IE5\VTH4KUIA\AutoUpdaterInstaller[1].exe infected by Trojan-Downloader.Win32.Apropo.g [msvLclnt.dll] [0x00000564] 20/05/2005 22:29:51:242 :[00000001] File C:\Dokumente und Einstellungen\Tim\Lokale Einstellungen\Temporary Internet Files\Content.IE5\X8CRD9S1\count[1].jar infected by Exploit.Java.ByteVerify [msvLclnt.dll] [0x00000564] 20/05/2005 22:30:33:502 :[00000001] File C:\j2sdk1.4.2_03\demo\applets\BarChart\BarChart.class infected by not-a-virus:JavaClass.Chart [msvLclnt.dll] [0x00000564] 20/05/2005 22:31:03:055 :[00000001] File C:\j2sdk1.4.2_03\demo\plugin\applets\BarChart\BarChart.class infected by not-a-virus:JavaClass.Chart [msvLclnt.dll] [0x00000564] 20/05/2005 22:36:27:331 :[00000001] File C:\Programme\BullsEye Network\bin\adv.exe infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 22:36:27:371 :[00000001] File C:\Programme\BullsEye Network\bin\adx.exe infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 22:40:25:594 :[00000001] File C:\Programme\Gemeinsame Dateien\Java\Update\Base Images\j2sdk1.4.2-b28\demos.zip infected by not-a-virus:JavaClass.Chart [msvLclnt.dll] [0x00000564] 20/05/2005 22:44:08:905 :[00000001] File C:\Programme\Gemeinsame Dateien\WinTools\WSup.exe infected by not-a-virus:AdWare.Wintol.aa [msvLclnt.dll] [0x00000564] 20/05/2005 22:44:09:195 :[00000001] File C:\Programme\Gemeinsame Dateien\WinTools\WToolsS.exe infected by Trojan-Downloader.Win32.Wintool.f [msvLclnt.dll] [0x00000564] 20/05/2005 22:58:58:294 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\032B3A42 infected by Email-Worm.Win32.Sober.i [msvLclnt.dll] [0x00000564] 20/05/2005 22:58:58:444 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\03F56563 infected by Email-Worm.Win32.Sober.i [msvLclnt.dll] [0x00000564] 20/05/2005 22:58:58:804 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\0EC02583 infected by Email-Worm.Win32.Sober.i [msvLclnt.dll] [0x00000564] 20/05/2005 22:58:59:015 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\106C21AC infected by Email-Worm.Win32.Sober.i [msvLclnt.dll] [0x00000564] 20/05/2005 22:58:59:235 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\110F54F9 infected by Email-Worm.Win32.Sober.i [msvLclnt.dll] [0x00000564] 20/05/2005 22:58:59:435 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\14856A90 infected by Email-Worm.Win32.Sober.i [msvLclnt.dll] [0x00000564] 20/05/2005 22:58:59:916 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\55ED41AE.EXE infected by Email-Worm.Win32.Sober.i [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:00:136 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\7CE4092A infected by Email-Worm.Win32.Sober.i [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:00:347 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\7D02030A infected by Email-Worm.Win32.Sober.i [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:00:537 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\7FED11D3.EXE infected by Email-Worm.Win32.Sober.i [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:00:627 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP0.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:00:707 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP0.game infected by Trojan-Downloader.Win32.Agent.ho [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:00:757 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP1.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:00:827 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP1.game infected by Trojan-Downloader.Win32.Agent.ho [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:00:877 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP10.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:00:927 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP100.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:008 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP1000.exe infected by Trojan-Downloader.Win32.Agent.ho [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:048 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP101.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:098 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP102.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:138 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP103.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:188 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP104.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:228 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP105.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:278 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP106.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:318 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP107.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:368 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP108.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:408 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP109.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:468 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP11.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:518 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP110.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:558 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP111.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:598 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP112.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:648 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP113.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:689 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP114.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:739 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP115.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:769 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP116.exe infected by Net-Worm.Win32.Padobot.m [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:01:819 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP117.exe infected by Net-Worm.Win32.Padobot.m |
21.05.2005, 15:07 | #6 |
| hilfe bei trojaner (log file) jetz kommt ewig ( glaub 700 zeilen) der eintrag mit: [msvLclnt.dll] [0x00000564] 20/05/2005 22:59:02:119 :[00000001] File C:\Programme\Norton AntiVirus\Quarantine\Incoming\AP122.exe infected by Net-Worm.Win32.Padobot.m |
21.05.2005, 15:09 | #7 |
| hilfe bei trojaner (log file) [msvLclnt.dll] [0x00000564] 20/05/2005 23:01:30:192 :[00000001] File C:\Programme\TGTSoft\StyleXP\Boot\74111.exe infected by not-a-virus:AdWare.ToolBar.Quick.a [msvLclnt.dll] [0x00000564] 20/05/2005 23:02:57:167 :[00000001] File C:\Programme\TGTSoft\StyleXP\Style XP Theme Pack 1337\Style XP Themes\Longhorn 4\Longhorn 4 Setup.exe infected by not-a-virus:Tool.Win32.Reboot [msvLclnt.dll] [0x00000564] 20/05/2005 23:04:11:804 :[00000001] File C:\Programme\Toolbar\common.dll infected by not-a-virus:AdWare.WebSearch.aj [msvLclnt.dll] [0x00000564] 20/05/2005 23:04:11:905 :[00000001] File C:\Programme\Toolbar\IExploreSkins.exe infected by not-a-virus:RiskWare.Tool.Exporun [msvLclnt.dll] [0x00000564] 20/05/2005 23:04:12:125 :[00000001] File C:\Programme\Toolbar\PIB.exe infected by not-a-virus:AdWare.WebSearch.aj [msvLclnt.dll] [0x00000564] 20/05/2005 23:04:12:395 :[00000001] File C:\Programme\Toolbar\TBPS.exe infected by not-a-virus:AdWare.WebSearch.aj [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:42:928 :[00000001] File C:\RECYCLER\NPROTECT\00101393.EXE infected by Trojan-Downloader.Win32.Small.fo [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:43:048 :[00000001] File C:\RECYCLER\NPROTECT\00101394.exe infected by Trojan-Dropper.Win32.Small.wv [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:43:128 :[00000001] File C:\RECYCLER\NPROTECT\00101397.exe infected by Trojan-Dropper.Win32.Agent.kz [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:43:228 :[00000001] File C:\RECYCLER\NPROTECT\00101406.exe infected by Trojan-Dropper.Win32.Agent.kz [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:43:439 :[00000001] File C:\RECYCLER\NPROTECT\00101408.cab infected by not-a-virus:AdWare.180Solutions.b [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:43:749 :[00000001] File C:\RECYCLER\NPROTECT\00101413.exe infected by Trojan-Downloader.Win32.Dyfuca.dk [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:43:829 :[00000001] File C:\RECYCLER\NPROTECT\00101414.dll infected by not-a-virus:AdWare.180Solutions [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:44:500 :[00000001] File C:\RECYCLER\NPROTECT\00101424.EXE infected by Trojan-Downloader.Win32.Agent.ex [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:44:610 :[00000001] File C:\RECYCLER\NPROTECT\00101426.dll infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:44:921 :[00000001] File C:\RECYCLER\NPROTECT\00101428.exe infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:45:011 :[00000001] File C:\RECYCLER\NPROTECT\00101429.exe infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:45:442 :[00000001] File C:\RECYCLER\NPROTECT\00101430.EXE infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:45:532 :[00000001] File C:\RECYCLER\NPROTECT\00101431.exe infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:45:652 :[00000001] File C:\RECYCLER\NPROTECT\00101432.dll infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:46:583 :[00000001] File C:\RECYCLER\NPROTECT\00101446.EXE infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:50:078 :[00000001] File C:\RECYCLER\NPROTECT\00101631.EXE infected by Trojan-Downloader.Win32.Small.fo [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:50:178 :[00000001] File C:\RECYCLER\NPROTECT\00101633.exe infected by Trojan-Downloader.Win32.Small.aqt [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:50:309 :[00000001] File C:\RECYCLER\NPROTECT\00101635.exe infected by Trojan-Dropper.Win32.Small.wv [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:50:409 :[00000001] File C:\RECYCLER\NPROTECT\00101636.exe infected by Trojan.Win32.LowZones.y [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:51:160 :[00000001] File C:\RECYCLER\NPROTECT\00101650.EXE infected by Trojan-Downloader.Win32.Agent.ex [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:51:230 :[00000001] File C:\RECYCLER\NPROTECT\00101653.exe infected by Trojan-Dropper.Win32.Agent.kz [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:51:310 :[00000001] File C:\RECYCLER\NPROTECT\00101654.dll infected by Trojan-Proxy.Win32.Agent.ex [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:51:831 :[00000001] File C:\RECYCLER\NPROTECT\00101676.exe infected by Trojan-Downloader.Win32.Small.aqt [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:51:941 :[00000001] File C:\RECYCLER\NPROTECT\00101677.exe infected by Trojan-Dropper.Win32.Small.wv [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:52:502 :[00000001] File C:\RECYCLER\NPROTECT\00101691.EXE infected by Trojan-Downloader.Win32.Agent.ex [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:52:582 :[00000001] File C:\RECYCLER\NPROTECT\00101692.exe infected by Trojan-Dropper.Win32.Agent.kz [msvLclnt.dll] [0x00000564] 20/05/2005 23:07:53:233 :[00000001] File C:\RECYCLER\svchost.dll infected by Trojan-Proxy.Win32.Agent.ex [msvLclnt.dll] [0x00000564] 20/05/2005 23:08:39:079 :[00000001] File C:\WINDOWS\cxtpls_loader.exe infected by Trojan-Downloader.Win32.Apropo.ab [msvLclnt.dll] [0x00000564] 20/05/2005 23:08:39:670 :[00000001] File C:\WINDOWS\desktop.html infected by Trojan-Clicker.Win32.Spywad.b [msvLclnt.dll] [0x00000564] 20/05/2005 23:08:39:980 :[00000001] File C:\WINDOWS\Downloaded Program Files\clientax.dll infected by not-a-virus:AdWare.180Solutions.b [msvLclnt.dll] [0x00000564] 20/05/2005 23:18:22:127 :[00000001] File C:\WINDOWS\installer_SIAC.exe infected by Trojan-Downloader.Win32.Adload.a [msvLclnt.dll] [0x00000564] 20/05/2005 23:24:06:192 :[00000001] File C:\WINDOWS\optimize.exe infected by Trojan-Downloader.Win32.Dyfuca.dk [msvLclnt.dll] [0x00000564] 20/05/2005 23:26:47:073 :[00000001] File C:\WINDOWS\system\svchost.dll infected by Trojan-Proxy.Win32.Agent.ex [msvLclnt.dll] [0x00000564] 20/05/2005 23:26:47:143 :[00000001] File C:\WINDOWS\system\svchost.exe infected by Trojan-Dropper.Win32.Agent.kz [msvLclnt.dll] [0x00000564] 20/05/2005 23:26:53:052 :[00000001] File C:\WINDOWS\system32\angelex.exe infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 23:35:59:798 :[00000001] File C:\WINDOWS\system32\exdl.exe infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 23:35:59:908 :[00000001] File C:\WINDOWS\system32\exdl0.exe infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 23:36:00:008 :[00000001] File C:\WINDOWS\system32\exdl1.exe infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 23:36:01:340 :[00000001] File C:\WINDOWS\system32\exul.exe infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 23:36:34:598 :[00000001] File C:\WINDOWS\system32\instsrv.exe infected by not-a-virus:RiskWare.Tool.ServiceRunner.f [msvLclnt.dll] [0x00000564] 20/05/2005 23:36:42:750 :[00000001] File C:\WINDOWS\system32\javexulm.vxd infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 23:37:02:278 :[00000001] File C:\WINDOWS\system32\mac80ex.idf infected by not-a-virus:AdWare.BargainBuddy.n [msvLclnt.dll] [0x00000564] 20/05/2005 23:37:19:723 :[00000001] File C:\WINDOWS\system32\mqexdlm.srg infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 23:38:01:894 :[00000001] File C:\WINDOWS\system32\netut80ex.vxd infected by not-a-virus:AdWare.BargainBuddy.q [msvLclnt.dll] [0x00000564] 20/05/2005 23:40:56:625 :[00000001] File C:\WINDOWS\system32\thun32.dll infected by Trojan-Proxy.Win32.Small.bk [msvLclnt.dll] [0x00000564] 20/05/2005 23:41:15:422 :[00000001] File C:\WINDOWS\system32\vxgame1.exe infected by Trojan-Dropper.Win32.Small.wv [msvLclnt.dll] [0x00000564] 20/05/2005 23:41:15:512 :[00000001] File C:\WINDOWS\system32\vxgamet1.exe infected by Trojan-Downloader.Win32.Small.aqt [msvLclnt.dll] [0x00000564] 20/05/2005 23:41:15:592 :[00000001] File C:\WINDOWS\system32\vxgamet2.exe infected by Trojan.Win32.LowZones.y [msvLclnt.dll] [0x00000564] 20/05/2005 23:41:15:672 :[00000001] File C:\WINDOWS\system32\vxh8jkdq1.exe infected by Trojan-Dropper.Win32.Small.wp [msvLclnt.dll] [0x00000564] 20/05/2005 23:41:15:802 :[00000001] File C:\WINDOWS\system32\vxh8jkdq6.exe infected by Trojan-Downloader.Win32.Small.aux [msvLclnt.dll] [0x00000564] 20/05/2005 23:41:15:923 :[00000001] File C:\WINDOWS\system32\vxh8jkdq8.exe infected by Trojan-Dropper.Win32.Small.wp [msvLclnt.dll] [0x00000564] 21/05/2005 01:12:23:304 :[00000001] File E:\N64\N64 Games\Neue CD\gcmod0[1].1a.exe infected by not-a-virus:Tool.Win32.Reboot [msvLclnt.dll] [0x00000564] 21/05/2005 01:25:04:649 :[00000001] File E:\Q3\Check for Quake III Arena Updates.exe infected by not-a-virus:Tool.Win32.Reboot [msvLclnt.dll] [0x00000564] 21/05/2005 01:25:16:977 :[00000001] File E:\Q3\Extras\WorldNet\PCVKIT.EXE infected by not-a-virus:Tool.Win32.Reboot [msvLclnt.dll] [0x00000564] 21/05/2005 02:59:19:390 :[00000001] File F:\games\hl mods\svencoop30full.exe infected by not-a-virus:Tool.Win32.Reboot [msvLclnt.dll] [0x00000564] 21/05/2005 03:35:50:421 :[00000001] File F:\software\Style Xp Theme Pack 1337.ace infected by not-a-virus:Tool.Win32.Reboot [msvLclnt.dll] [0x00000564] 21/05/2005 03:38:19:305 :VirusCount = 130890 Latest Date = 2005/05/20 [msvLclnt.dll] [0x000004f0] 21/05/2005 03:40:46:266 :VirusCount = 130890 Latest Date = 2005/05/20 |
21.05.2005, 15:10 | #8 |
| hilfe bei trojaner (log file) es wuerde mir schon helfen, wenn nen einfaches format c: reichen wuerde. |
21.05.2005, 16:42 | #9 |
| hilfe bei trojaner (log file) @slade bei dieser menge ist neuafsetzen schneller als versuchen zu reparieren. hier eine anleitung http://www.trojaner-board.de/showpos...28&postcount=2 chaosman
__________________ Bonus vir semper tiro |
Themen zu hilfe bei trojaner (log file) |
adobe, antivirus, bho, ctfmon.exe, dll, download, email, explorer, file, file missing, google, hilfe bei trojaner, internet, internet explorer, keine ahnung, log, log file, nvidia, programme, rundll, security, security center, settings manager, software, surfen, symantec, system, trojaner, urlsearchhook, windows, windows messenger, windows xp |