|
Log-Analyse und Auswertung: Bitte auswerten! HILFE!!!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
21.05.2005, 18:54 | #1 |
| Bitte auswerten! HILFE!!! Liebe Forenmitglieder + Retter, da ich ich nur einen begrenzten Horizont an Ahnung von PC's habe "muss" ich mich an euch wenden und um Hilfe rufen. "HILFE!!!" Hab seit 2 Wochen immer die AntiVir Warunung von so nem "POLLER Virus" und nem "ZPJHVSUJJNM Trojaner"! Da mir das fürchtbar viel sagt und da AntiVir den natürlich auch net komplett löschen kann oder überschreiben, da die beide in System32 sind... und ich die da auch nirgends finde, bin ich verzweifelt und bin, gottseidank, auf das Forum gestoßen und auf die SEHR GUTE Anleitung für eScan... Bin für jede Antwort dankbar - in dem Sinne ANDIMANN P.S. Hier natürlich noch meine Log Daten ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Wed May 11 21:20:21 2005 => File C:\WINDOWS\svcproc.exe infected by "Trojan.Win32.Stervis.c" Virus. Action Taken: No Action Taken. Wed May 11 21:20:23 2005 => System found infected with SideFind Spyware/Adware ({10e42047-deb9-4535-a118-b3f6ec39b807})! Action taken: No Action Taken. Wed May 11 21:20:23 2005 => File System Found infected by "SideFind Spyware/Adware" Virus. Action Taken: No Action Taken. Wed May 11 21:22:13 2005 => File C:\WINDOWS\system32\sfx_webhancer.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Wed May 11 21:24:17 2005 => File C:\DOKUME~1\Andi\LOKALE~1\TEMPOR~1\Content.IE5\19R ANQYB\istsvc[1].exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken. Wed May 11 21:24:23 2005 => File C:\DOKUME~1\Andi\LOKALE~1\TEMPOR~1\Content.IE5\YKO 6G2DE\sidefind13[1].dll infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken. Wed May 11 21:24:23 2005 => File C:\DOKUME~1\Andi\LOKALE~1\TEMPOR~1\Content.IE5\YKO 6G2DE\svcproc[1].exe infected by "Trojan.Win32.Stervis.c" Virus. Action Taken: No Action Taken. Wed May 11 21:31:40 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temporary Internet Files\Content.IE5\19RANQYB\istsvc[1].exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken. Wed May 11 21:31:45 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YKO6G2DE\sidefind13[1].dll infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken. Wed May 11 21:31:45 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YKO6G2DE\svcproc[1].exe infected by "Trojan.Win32.Stervis.c" Virus. Action Taken: No Action Taken. Wed May 11 21:40:50 2005 => File C:\Program Files\Win_whcr\webhancer_winrar.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Wed May 11 21:55:28 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.* Thu May 19 18:27:02 2005 => C:\WINDOWS\svcproc.exe possibly infected and removed by background antivirus package! Thu May 19 18:27:05 2005 => File C:\WINDOWS\svcproc.exe infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken. Thu May 19 18:27:07 2005 => System found infected with SideFind Spyware/Adware ({10e42047-deb9-4535-a118-b3f6ec39b807})! Action taken: No Action Taken. Thu May 19 18:27:07 2005 => File System Found infected by "SideFind Spyware/Adware" Virus. Action Taken: No Action Taken. Thu May 19 18:29:18 2005 => File C:\WINDOWS\system32\sfx_webhancer.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 18:56:55 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.* Thu May 19 18:56:55 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.001 Thu May 19 18:56:55 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.001 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. Thu May 19 18:56:55 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.002 Thu May 19 18:56:55 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.002 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. Thu May 19 18:56:55 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.003 Thu May 19 18:56:56 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.003 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. Thu May 19 18:56:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.004 Thu May 19 18:56:56 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.004 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. Thu May 19 18:56:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.005 Thu May 19 18:56:56 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.005 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. Thu May 19 18:56:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.VIR Thu May 19 18:56:56 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.VIR infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken. Thu May 19 18:56:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 01 Thu May 19 18:56:57 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 01 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 02 Thu May 19 18:56:57 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 02 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 03 Thu May 19 18:56:57 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 03 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 04 Thu May 19 18:56:57 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 04 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 05 Thu May 19 18:56:58 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 05 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 06 Thu May 19 18:56:58 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 06 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 07 Thu May 19 18:56:58 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 07 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 08 Thu May 19 18:56:58 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 08 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 09 Thu May 19 18:56:59 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 09 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:59 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 10 Thu May 19 18:56:59 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 10 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 18:56:59 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.V IR Thu May 19 18:56:59 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.V IR infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken. Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010888.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010889.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010890.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010891.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010901.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010903.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:02 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP75\A0012087.exe infected by "not-a-virus:AdWare.WebHancer.351" Virus. Action Taken: No Action Taken. Thu May 19 19:37:08 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP77\A0012149.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:08 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP77\A0012150.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:10 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP77\A0012173.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:15 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012227.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:15 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012231.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:17 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012287.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:18 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012288.exe infected by "not-a-virus:AdWare.WebHancer.351" Virus. Action Taken: No Action Taken. Thu May 19 19:37:18 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012291.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:18 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012292.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 19:37:18 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012294.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 20:54:44 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP96\A0014816.dll infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken. Thu May 19 20:56:14 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP97\A0016058.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. Thu May 19 21:14:01 2005 => File C:\WINDOWS\system32\sfx_webhancer.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Wed May 11 21:24:03 2005 => File C:\DOKUME~1\Andi\LOKALE~1\Temp\Temporäres Verzeichnis 1 für radmin22.zip\RADMIN22.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken. Wed May 11 21:27:27 2005 => File C:\Dokumente und Einstellungen\Andi\Eigene Dateien\Downloads\vnc-4.0b5-x86_win32.exe tagged as not-a-virus:RiskWare.RemoteAdmin.WinVNC.4. No Action Taken. Wed May 11 21:31:26 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temp\Temporäres Verzeichnis 1 für radmin22.zip\RADMIN22.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken. Thu May 19 18:31:59 2005 => File C:\DOKUME~1\Andi\LOKALE~1\Temp\Temporäres Verzeichnis 1 für radmin22.zip\RADMIN22.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken. Thu May 19 18:37:31 2005 => File C:\Dokumente und Einstellungen\Andi\Eigene Dateien\Downloads\vnc-4.0b5-x86_win32.exe tagged as not-a-virus:RiskWare.RemoteAdmin.WinVNC.4. No Action Taken. Thu May 19 18:42:41 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temp\Temporäres Verzeichnis 1 für radmin22.zip\RADMIN22.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken. Thu May 19 19:36:40 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0009840.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken. |
21.05.2005, 19:12 | #2 |
Administrator, a.D. | Bitte auswerten! HILFE!!! Hallo Andimann,
__________________deaktiviere die Systemwiederherstellung und wechsle anschließend in den abgesicherten Modus. Leere nun den Infected und den TIF Ordner [1] und lösche die restliche verbliebene Malware mit KillBox. Erstelle mit Hilfe dieser bebilderten Anleitung ein HiJackThis Log-File und poste es. Beachte die Hinweise! [1] Rechtsklick auf IE -> Eigenschaften -> Reiter 'Allgemein' und unter Temporäre Internetdateien -> Dateien löschen -> 'Alle Offlineinhalte löschen' anhaken -> OK
__________________ |
Themen zu Bitte auswerten! HILFE!!! |
.dll, 1.exe, adware.betterinternet, adware.webhancer, anleitung, antivir, antivirus, auswerten, bitte auswerten, c:\windows, content.ie5, dateien, einstellungen, file, forum, hilfe!, hilfe!!, hilfe!!!, infected, internet, komplett löschen, log, löschen, not-a-virus, programme, system, system volume information, system32, trojaner, virus, warunung, windows |