![]() |
|
Plagegeister aller Art und deren Bekämpfung: Ich Brauche Hilfe beim Entfernen von VIren!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() Ich Brauche Hilfe beim Entfernen von VIren! Hallo.. Ich bräuchte Hilfe beim Löschen von Viren, die ich beim eScan entdeckt habe.... eins vorweg: ich habe keine große Ahnung von Computern, bin aber lernfähig ![]() Ich hab mir aufgrund einiger Postings hier jetzt mal den escan runtergeladen und meine festplatte gescannt: heraus kam folgendes: (es wurden 28 viren gefunden) ( ich hab jetzt mal die stellen aus dem log des escans zusammengestellt, die "infected" beinhalten..) Ich danke euch schon jetzt! Liebe Grüße Daniel Sat Jun 18 12:43:34 2005 => ***** Scanning Registry and File system for Adware/Spyware ***** Sat Jun 18 12:43:35 2005 => System found infected with IstBAR Spyware/Adware ({0985c112-2562-46f2-8da6-92648ba4630f})! Action taken: No Action Taken. Sat Jun 18 12:43:35 2005 => Object "IstBAR Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:35 2005 => System found infected with IstBAR Spyware/Adware ({67907b3c-a6ef-4a01-99ad-3fcd5f526429})! Action taken: No Action Taken. Sat Jun 18 12:43:35 2005 => Object "IstBAR Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:35 2005 => System found infected with SideFind Spyware/Adware ({58634367-d62b-4c2c-86be-5aac45cdb671})! Action taken: No Action Taken. Sat Jun 18 12:43:35 2005 => Object "SideFind Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:35 2005 => System found infected with SideFind Spyware/Adware ({d0288a41-9855-4a9b-8316-babe243648da})! Action taken: No Action Taken. Sat Jun 18 12:43:35 2005 => Object "SideFind Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:35 2005 => System found infected with SideFind Spyware/Adware ({339d8aff-0b42-4260-ad82-78ce605a9543})! Action taken: No Action Taken. Sat Jun 18 12:43:35 2005 => Object "SideFind Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:35 2005 => System found infected with SideFind Spyware/Adware ({a36a5936-cfd9-4b41-86bd-319a1931887f})! Action taken: No Action Taken. Sat Jun 18 12:43:35 2005 => Object "SideFind Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:35 2005 => System found infected with SideFind Spyware/Adware ({10e42047-deb9-4535-a118-b3f6ec39b807})! Action taken: No Action Taken. Sat Jun 18 12:43:35 2005 => Object "SideFind Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:35 2005 => System found infected with Bargain Buddy Spyware/Adware ({4eb7bbe8-2e15-424b-9ddb-2cdb9516b2c3})! Action taken: No Action Taken. Sat Jun 18 12:43:35 2005 => Object "Bargain Buddy Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:35 2005 => System found infected with Bargain Buddy Spyware/Adware ({c6906a23-4717-4e1f-b6fd-f06ebed15678})! Action taken: No Action Taken. Sat Jun 18 12:43:35 2005 => Object "Bargain Buddy Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:35 2005 => System found infected with Bargain Buddy Spyware/Adware ({8eee58d5-130e-4cbd-9c83-35a0564e5678})! Action taken: No Action Taken. Sat Jun 18 12:43:35 2005 => Object "Bargain Buddy Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:35 2005 => System found infected with MyBar Spyware/Adware ({0494d0d9-f8e0-41ad-92a3-14154ece70ac})! Action taken: No Action Taken. Sat Jun 18 12:43:35 2005 => Object "MyBar Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:35 2005 => Offending value found in HKCU\Software\Microsoft\Windows\CurrentVersion\policies\ameopt !!! Sat Jun 18 12:43:35 2005 => Object "ameopt Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:36 2005 => Offending value found in HKCU\Software\policies\avenue media !!! Sat Jun 18 12:43:36 2005 => Object "180Solutions Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:36 2005 => Offending value found in HKLM\Software\microsoft\downloadmanager !!! Sat Jun 18 12:43:36 2005 => Object "AltNet Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:36 2005 => Offending value found in HKLM\Software\myway !!! Sat Jun 18 12:43:36 2005 => Object "myway Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:36 2005 => Offending Folder C:\DOKUME~1\BRCKNE~1\FAVORI~1\Living present... Sat Jun 18 12:43:36 2005 => Object "ISearchTech.ISTdownloader Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:36 2005 => System found infected with eZula Spyware/Adware (bbchk.exe)! Action taken: No Action Taken. Sat Jun 18 12:43:36 2005 => Object "eZula Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:56 2005 => System found infected with ISTsvc Spyware/Adware (shortcuts.txt)! Action taken: No Action Taken. Sat Jun 18 12:43:56 2005 => Object "ISTsvc Spyware/Adware" found in File System! Action Taken: No Action Taken. Sat Jun 18 12:43:56 2005 => ***** Scanning Registry for errors created because of Adware/Spyware ***** Sat Jun 18 12:43:56 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Downloaded Program Files\AdToolsX.dll". Action Taken: No Action Taken. Sat Jun 18 12:43:56 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\ModuleUsage" refers to invalid object "C:\WINDOWS\Ole32ws.dll". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-dan.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-cht.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-nld.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-fra.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-ita.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-jpn.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-kor.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-nor.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-ptg.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-rus.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-esp.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-sve.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-fin.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-ptb.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-chs.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-plk.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-csy.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-sky.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-slv.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-hun.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\coverdesigner\covered-tha.nls". Action Taken: No Action Taken. Sat Jun 18 12:43:58 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Gemeinsame Dateien\Adobe\Fonts\Reqrd\Base\AdobeFnt.lst". Action Taken: No Action Taken. Sat Jun 18 12:43:59 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Ole32ws.dll". Action Taken: No Action Taken. Sat Jun 18 12:43:59 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Adobe\Photoshop Album\Kataloge\My Catalog.psa". Action Taken: No Action Taken. Sat Jun 18 12:44:00 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\Downloaded Program Files\AdToolsX.dll". Action Taken: No Action Taken. Sat Jun 18 12:44:04 2005 => Entry "HKCR\CLSID\{6248A698-5ECC-B3DE-E2DF-171B6C2E5C87}" refers to invalid object "C:\Dokumente und Einstellungen\Brückner\Eigene Dateien\FSI.dll". Action Taken: No Action Taken. Sat Jun 18 12:44:04 2005 => Entry "HKCR\CLSID\{685562BB-30A2-E3D5-2355-29E7AE620BE4}" refers to invalid object "C:\Dokumente und Einstellungen\Brückner\Eigene Dateien\FSI.dll". Action Taken: No Action Taken. Sat Jun 18 12:44:04 2005 => Entry "HKCR\CLSID\{7D7AC7AF-ABD0-48AA-3F6B-73ABE65E22D0}" refers to invalid object "C:\Dokumente und Einstellungen\Brückner\Eigene Dateien\FSI.dll". Action Taken: No Action Taken. Sat Jun 18 12:44:04 2005 => Entry "HKCR\CLSID\{83D4679F-B6D7-11D2-BF36-00C04FB90A03}" refers to invalid object "C:\PROGRA~1\MESSEN~1\rtcimsp.dll". Action Taken: No Action Taken. Sat Jun 18 12:44:04 2005 => Entry "HKCR\CLSID\{88E729D6-BDC1-11D1-BD2A-00C04FB9603F}" refers to invalid object "fde.dll". Action Taken: No Action Taken. Sat Jun 18 12:44:05 2005 => Entry "HKCR\CLSID\{B5DD9A64-5C4B-4a48-BE56-97C1A8F85708}" refers to invalid object "C:\WINDOWS\system32\fastvideoplayer.dll". Action Taken: No Action Taken. Sat Jun 18 12:44:05 2005 => Entry "HKCR\CLSID\{B7156514-A76C-4545-9D5B-A4E1D02C7AEC}" refers to invalid object "C:\Programme\Kazaa\Topsearch.dll". Action Taken: No Action Taken. Sat Jun 18 12:44:08 2005 => Entry "HKCR\AdToolsX.Installer" refers to invalid object "{15AD4789-CDB4-47E1-A9DA-992EE8E6BAD6}". Action Taken: No Action Taken. Sat Jun 18 12:44:08 2005 => Entry "HKCR\Alg.AlgSetup" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Sat Jun 18 12:44:08 2005 => Entry "HKCR\Alg.AlgSetup.1" refers to invalid object "{27D0BCCC-344D-4287-AF37-0C72C161C14C}". Action Taken: No Action Taken. Sat Jun 18 12:44:08 2005 => Entry "HKCR\CDDBControlApple.CddbFullName.1" refers to invalid object "{63338267-37c4-44cf-8e46-756fbe9c8fdc}". Action Taken: No Action Taken. Sat Jun 18 12:44:08 2005 => Entry "HKCR\CDDBControlApple.FullName" refers to invalid object "{63338267-37c4-44cf-8e46-756fbe9c8fdc}". Action Taken: No Action Taken. Sat Jun 18 12:44:08 2005 => Entry "HKCR\DSP.DSP" refers to invalid object "{9C123EA9-AEC9-4f75-BBC0-7565FA1398966}". Action Taken: No Action Taken. Sat Jun 18 12:44:09 2005 => Entry "HKCR\DSP.DSPDMOProp_Chorus.1" refers to invalid object "{6F63B172-5543-4593-91CE-EDBA65B9FACDB}". Action Taken: No Action Taken. Sat Jun 18 12:44:09 2005 => Entry "HKCR\MailFileAtt" refers to invalid object "{00020D05-0000-0000-C000-000000000046}". Action Taken: No Action Taken. Sat Jun 18 12:44:09 2005 => Entry "HKCR\mapifvbx.object" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Sat Jun 18 12:44:09 2005 => Entry "HKCR\mapifvbx.object.1" refers to invalid object "{41116C00-8B90-101B-96CD-00AA003B14FC}". Action Taken: No Action Taken. Sat Jun 18 12:44:10 2005 => Entry "HKCR\MyWayToolBar.SettingsPlugin" refers to invalid object "{0494D0DB-F8E0-41ad-92A3-14154ECE70AC}". Action Taken: No Action Taken. Sat Jun 18 12:44:10 2005 => Entry "HKCR\MyWayToolBar.SettingsPlugin.1" refers to invalid object "{0494D0DB-F8E0-41ad-92A3-14154ECE70AC}". Action Taken: No Action Taken. Sat Jun 18 12:44:10 2005 => Entry "HKCR\Plenoptic.Plenoptic" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Sat Jun 18 12:44:10 2005 => Entry "HKCR\Plenoptic.Plenoptic.1" refers to invalid object "{607C27E9-AB27-11d3-A116-A0EA50C10801}". Action Taken: No Action Taken. Sat Jun 18 12:44:10 2005 => Entry "HKCR\RTCCore.RTCClient" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Sat Jun 18 12:44:10 2005 => Entry "HKCR\RTCCore.RTCClient.1" refers to invalid object "{7a42ea29-a2b7-40c4-b091-f6f024aa89be}". Action Taken: No Action Taken. Sat Jun 18 12:44:11 2005 => Entry "HKCR\TestContentMatchControl1.ContentMatchTag" refers to invalid object "{DC341F1B-EC77-47BE-8F58-96E83861CC5A}". Action Taken: No Action Taken. Sat Jun 18 12:44:11 2005 => Entry "HKCR\WEBInstaller.CExecute" refers to invalid object "{C0EF89EE-EEC7-4535-A041-F1EBF79560A7}". Action Taken: No Action Taken. Sat Jun 18 12:44:11 2005 => Entry "HKCR\WEBInstaller.CExecute.1" refers to invalid object "{C0EF89EE-EEC7-4535-A041-F1EBF79560A7}". Action Taken: No Action Taken. Sat Jun 18 12:44:11 2005 => Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Sat Jun 18 12:44:11 2005 => Entry "HKCR\WMPPublsihCntr.WMPPublsihCntr.1" refers to invalid object "{939438A9-CF0F-44d8-9140-599736F0D3A2}". Action Taken: No Action Taken. Sat Jun 18 12:44:11 2005 => Entry "HKCR\Zb.ZbCmdProcessRawImages" refers to invalid object "{4DCADFA0-556A-4288-AB68-833C51A2CF6B}". Action Taken: No Action Taken. Sat Jun 18 12:44:11 2005 => Entry "HKCR\Zb.ZbCmdProcessRawImages.1" refers to invalid object "{4DCADFA0-556A-4288-AB68-833C51A2CF6B}". Action Taken: No Action Taken. Sat Jun 18 12:44:11 2005 => Entry "HKCR\Zb.ZbCmdRemoteCapture" refers to invalid object "{7D5BAFEE-5A7D-4BB0-B709-A17422EEB658}". Action Taken: No Action Taken. Sat Jun 18 12:44:11 2005 => Entry "HKCR\Zb.ZbCmdRemoteCapture.1" refers to invalid object "{7D5BAFEE-5A7D-4BB0-B709-A17422EEB658}". Action Taken: No ----------------------------------------------------------------------- C:\DOKUME~1\BRCKNE~1\LOKALE~1\Temp\iinstall.exe infected by "Trojan-Downloader.Win32.IstBar.kb" Virus! Action Taken: No Action Taken. ------------------------------------- C:\DOKUME~1\BRCKNE~1\LOKALE~1\Temp\optimize.exe infected by "Trojan-Downloader.Win32.Dyfuca.ei" Virus! Action Taken: No Action Taken. -------------------------------------- C:\DOKUME~1\BRCKNE~1\LOKALE~1\Temp\sidefind.exe infected by "Trojan-Downloader.Win32.IstBar.jm" Virus! Action Taken: No Action Taken. -------------------------------------- |
Themen zu Ich Brauche Hilfe beim Entfernen von VIren! |
adobe, brauche hilfe, computer, computern, danke, dateien, downloader, einstellungen, entfernen, escan, festplatte, file, infected, log, löschen, microsoft, object, photoshop, programme, registry, software, system, system32, temp, viren, virus, windows |