|
Log-Analyse und Auswertung: Bitte um Hilfe / HijackThis-checkWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
30.06.2005, 12:10 | #1 |
| Bitte um Hilfe / HijackThis-check Bitte um Hilfe: seit einigen Tagen ist mein PC quälend langsam und stürzt regelmäßig ab. Kann es sein, dass ich Viren, Trojaner, etc. auf dem PC habe? Für Hilfe wäre ich sehr dankbar. Hier mein Hijack-Log: Logfile of HijackThis v1.99.1 Scan saved at 12:55:20, on 30.06.05 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\MSTASK.EXE C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE C:\PROGRAMME\GEMEINSAME DATEIEN\SYMANTEC SHARED\CCEVTMGR.EXE C:\PROGRAMME\GEMEINSAME DATEIEN\SYMANTEC SHARED\CCSETMGR.EXE C:\PROGRAMME\NORTON ANTIVIRUS\IWP\NPFMNTOR.EXE C:\WINDOWS\EXPLORER.EXE C:\WINDOWS\SYSTEM\RNAAPP.EXE C:\WINDOWS\SYSTEM\TAPISRV.EXE C:\WINDOWS\TASKMON.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\PROGRAMME\LOGITECH\MOUSEWARE\SYSTEM\EM_EXEC.EXE C:\WINDOWS\SYSTEM\STIMON.EXE C:\PROGRAMME\KFH\CL\LAUNCHER.EXE C:\WINDOWS\SYSTEM\LVHIDSVC.EXE C:\WINDOWS\SYSTEM\DESBYHDW.EXE C:\WINDOWS\ASRD.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\PROGRAMME\ZONE LABS\ZONEALARM\ZLCLIENT.EXE C:\PROGRAMME\GUILLEMOT\MAXI STUDIO ISIS\ISISMAN.EXE C:\PROGRAMME\GEMEINSAME DATEIEN\REAL\UPDATE_OB\REALSCHED.EXE C:\PROGRAMME\GEMEINSAME DATEIEN\SYMANTEC SHARED\CCPD-LC\SYMLCSVC.EXE C:\PROGRAMME\GEMEINSAME DATEIEN\SYMANTEC SHARED\CCAPP.EXE C:\PROGRAMME\SAVE\SAVE.EXE C:\PROGRAMME\GHOSTSURF EXPRESS\GHOSTSURF.EXE C:\PROGRAMME\DIAMOND\INCONTROL TOOLS 99\DMHKEY.EXE C:\PROGRAMME\REAL\REALPLAYER\REALPLAY.EXE C:\PROGRAMME\ZYDAS TECHNOLOGY CORPORATION\ZYDAS_802.11G_UTILITY\ZDWLAN.EXE C:\WINDOWS\WINIPCFG.EXE C:\PROGRAMME\GEMEINSAME DATEIEN\SYMANTEC SHARED\SNDSRVC.EXE C:\PROGRAMME\MOZILLA FIREFOX\FIREFOX.EXE C:\PROGRAMME\ACDSEE32\ACDSEE32.EXE C:\PROGRAMME\SYMANTEC\LIVEUPDATE\AUPDATE.EXE C:\PROGRAMME\SYMANTEC\LIVEUPDATE\LUCOMSERVER_2_5.EXE C:\PROGRAMME\WINZIP\WINZIP32.EXE C:\WINDOWS\TEMP\HIJACKTHIS.EXE R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = h**p://www.yyep.com/search/search05.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://www.web.de/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://www.lycos.de/ R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = h**p://www.yyep.com/search/search05.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer bereitgestellt von Lycos Europe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 127.0.0.1:7212 O2 - BHO: (no name) - {83DE62E0-5805-11D8-9B25-00E04C60FAF2} - C:\WINDOWS\2_0_1browserhelper2.dll (file missing) O2 - BHO: ADP UrlCatcher Class - {F4E04583-354E-4076-BE7D-ED6A80FD66DA} - C:\WINDOWS\SYSTEM\MSBE.DLL O2 - BHO: NLS UrlCatcher Class - {AEECBFDA-12FA-4881-BDCE-8C3E1CE4B344} - C:\WINDOWS\SYSTEM\NVMS.DLL O2 - BHO: CB UrlCatcher Class - {CE188402-6EE7-4022-8868-AB25173A3E14} - C:\WINDOWS\SYSTEM\MSCB.DLL O2 - BHO: IEWatchObj Class - {9527D42F-D666-11D3-B8DD-00600838CD5F} - C:\WINDOWS\SYSTEM\IETie.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHELPER.DLL O2 - BHO: ngsh33.clsIS - {941CA48C-3984-4E7D-AAF8-8755ED76EB50} - C:\WINDOWS\SYSTEM32\NGSH33.DLL O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\LOGITECH\MOUSEW~1\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM\QTTASK.EXE" -atboottime O4 - HKLM\..\Run: [Launcher] "C:\Programme\KFH\cl\launcher.exe" /P O4 - HKLM\..\Run: [SienaManager] siena95.exe O4 - HKLM\..\Run: [LvRemote] "C:\WINDOWS\SYSTEM\lvhidsvc.exe" O4 - HKLM\..\Run: [RecSche] "c:\programme\tvcapture\RecSche.exe" O4 - HKLM\..\Run: [njbctnnpmnw] C:\WINDOWS\SYSTEM\desbyhdw.exe O4 - HKLM\..\Run: [BullsEye Network] C:\Programme\BullsEye Network\bin\bargains.exe O4 - HKLM\..\Run: [ALCHEM] C:\WINDOWS\ALCHEM.exe O4 - HKLM\..\Run: [satmat] C:\WINDOWS\SATMAT.exe O4 - HKLM\..\Run: [GminiSystrayUtility] asrd.exe O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe O4 - HKLM\..\Run: [ISIS Manager] C:\Programme\Guillemot\Maxi Studio ISIS\ISISMan.exe /BOOTUP O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [Symantec Core LC] C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe start O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [WhenUSave] "C:\Programme\Save\Save.exe" O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKLM\..\RunServices: [TrueVector] C:\WINDOWS\SYSTEM\ZONELABS\VSMON.EXE -service O4 - HKLM\..\RunServices: [ccEvtMgr] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe" O4 - HKLM\..\RunServices: [ccSetMgr] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe" O4 - HKLM\..\RunServices: [NPFMonitor] C:\Programme\Norton AntiVirus\IWP\NPFMntor.exe O4 - HKLM\..\RunServices: [ScriptBlocking] "C:\Programme\Gemeinsame Dateien\Symantec Shared\Script Blocking\SBServ.exe" -reg O4 - HKCU\..\Run: [AIM] C:\PROGRAMME\NETSCAPE\COMMUNICATOR\PROGRAM\AIM\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [ngpw36] C:\windows\system32\ngpw36.exe O4 - HKCU\..\Run: [adprot] C:\windows\system32\adprot.exe O4 - Startup: GhostSurf Express.lnk = C:\Programme\GhostSurf Express\GhostSurf.exe O4 - Startup: InControl Desktop Manager.lnk = C:\Programme\Diamond\InControl Tools 99\DMHKEY.EXE O4 - Startup: CAPI Control.lnk = C:\Programme\Eumex 604PC HomeNet\Capictrl.exe O4 - Startup: HomeNet Control.lnk = C:\Programme\Eumex 604PC HomeNet\HNetCtrl.exe O4 - Startup: ZDWLan Utility.lnk = C:\Programme\ZyDAS Technology Corporation\ZyDAS_802.11g_Utility\ZDWlan.exe O4 - Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: NetShow PowerPoint Helper.lnk = C:\Programme\NetShow Services\Tools\nsppthlp.exe O8 - Extra context menu item: Block this advertisement - file://C:\PROGRAMME\GHOSTSURF EXPRESS\menu.blockimg.html O8 - Extra context menu item: Allow this advertisement - file://C:\PROGRAMME\GHOSTSURF EXPRESS\menu.allowimg.html O8 - Extra context menu item: Block popups on this site - file://C:\PROGRAMME\GHOSTSURF EXPRESS\popup.block.html O8 - Extra context menu item: Allow popups on this site - file://C:\PROGRAMME\GHOSTSURF EXPRESS\popup.allow.html O8 - Extra context menu item: Block personal info from this site - file://C:\PROGRAMME\GHOSTSURF EXPRESS\info.block.html O8 - Extra context menu item: Allow personal info to reach this site - file://C:\PROGRAMME\GHOSTSURF EXPRESS\info.allow.html O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll O9 - Extra button: (no name) - {578FC4E3-151E-456c-AF8E-B63061EFE228}} - (no file) O9 - Extra button: GhostSurf Privacy Center - {578FC4E3-151E-456c-AF8E-B63061EFE228} - C:\PROGRAMME\GHOSTSURF EXPRESS\LaunchPCC.exe O9 - Extra 'Tools' menuitem: GhostSurf Privacy Center - {578FC4E3-151E-456c-AF8E-B63061EFE228} - C:\PROGRAMME\GHOSTSURF EXPRESS\LaunchPCC.exe O12 - Plugin for .pca: C:\PROGRA~1\INTERN~1\PLUGINS\nppcaplg.dll O14 - IERESET.INF: START_PAGE_URL=h**p://www.lycos.de/ Schöne Grüße. |
30.06.2005, 15:47 | #2 |
| Bitte um Hilfe / HijackThis-check Hallo mgrules,
__________________Downloade Dir clearprog, nimm eine Datenträgerbereinigung vor (Häckchen bei “alles Löschen” und auf “löschen” klicken) und leere den Quarantäne-Ordner Deines Antivir-Programms. Desweiteren führe Escan aus und befolge genau an die Anleitung. dartus
__________________ |
01.07.2005, 13:21 | #3 |
| Bitte um Hilfe: Virus Log Information erstellt - und weiter? Hallo,
__________________ich habe nach dartus' Tip (vielen Dank auch!) eScan und danach Find.bat durchlaufen lassen. Und es wurde doch so allerhand gefunden. Mit den Ergebnissen kann ich aber leider nicht viel anfangen... Kann mir jemand beim beseitigen helfen?! Vielen Dank im voraus!!! Hier das eScan_neu - log: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ ---------- c:\bases_x\mwav.log Fri Jul 01 11:16:34 2005 => File C:\WINDOWS\SYSTEM\desbyhdw.exe infected by "Trojan-Downloader.Win32.Agent.ae" Virus! Action Taken: No Action Taken. Fri Jul 01 11:16:34 2005 => File C:\WINDOWS\ALCHEM.exe infected by "Trojan-Downloader.Win32.Alchemic" Virus! Action Taken: No Action Taken. Fri Jul 01 11:16:41 2005 => File C:\windows\system32\adprot.exe infected by "Trojan-Clicker.Win32.VB.gn" Virus! Action Taken: No Action Taken. Fri Jul 01 11:18:01 2005 => System found infected with BearShare Spyware/Adware ({905d0df2-3a0a-4d94-853c-54a12a745905})! Action taken: No Action Taken. Fri Jul 01 11:18:01 2005 => System found infected with BearShare Spyware/Adware ({9f95f736-0f62-4214-a4b4-caa6738d4c07})! Action taken: No Action Taken. Fri Jul 01 11:18:01 2005 => System found infected with BearShare Spyware/Adware ({558ec983-bedb-9168-b2de-31dbf0ee543e})! Action taken: No Action Taken. Fri Jul 01 11:18:01 2005 => System found infected with BearShare Spyware/Adware ({5f95e1af-2620-4f15-bdf9-7fdce4607e17})! Action taken: No Action Taken. Fri Jul 01 11:18:01 2005 => System found infected with Bargain Buddy Spyware/Adware ({8eee58d5-130e-4cbd-9c83-35a0564e2468})! Action taken: No Action Taken. Fri Jul 01 11:18:01 2005 => System found infected with Bargain Buddy Spyware/Adware ({ce188402-6ee7-4022-8868-ab25173a3e14})! Action taken: No Action Taken. Fri Jul 01 11:18:01 2005 => System found infected with Bargain Buddy Spyware/Adware ({4eb7bbe8-2e15-424b-9ddb-2cdb9516b2c3})! Action taken: No Action Taken. Fri Jul 01 11:18:01 2005 => System found infected with Bargain Buddy Spyware/Adware ({c6906a23-4717-4e1f-b6fd-f06ebed15678})! Action taken: No Action Taken. Fri Jul 01 11:18:01 2005 => System found infected with Bargain Buddy Spyware/Adware ({8eee58d5-130e-4cbd-9c83-35a0564e5678})! Action taken: No Action Taken. Fri Jul 01 11:18:01 2005 => System found infected with Bargain Buddy Spyware/Adware ({f4e04583-354e-4076-be7d-ed6a80fd66da})! Action taken: No Action Taken. Fri Jul 01 11:18:01 2005 => System found infected with Alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Fri Jul 01 11:18:01 2005 => System found infected with WhenU Spyware/Adware (wusn)! Action taken: No Action Taken. Fri Jul 01 11:18:07 2005 => System found infected with eZula Spyware/Adware (exul.exe)! Action taken: No Action Taken. Fri Jul 01 11:18:07 2005 => System found infected with eZula Spyware/Adware (exdl.exe)! Action taken: No Action Taken. Fri Jul 01 11:18:07 2005 => System found infected with eZula Spyware/Adware (bbchk.exe)! Action taken: No Action Taken. Fri Jul 01 11:19:18 2005 => File C:\WINDOWS\Sngpw36.exe infected by "Trojan-Clicker.Win32.VB.gn" Virus! Action Taken: No Action Taken. Fri Jul 01 11:21:36 2005 => File C:\WINDOWS\SYSTEM\POLALL1M.EXE infected by "Trojan-Downloader.Win32.Agent.ae" Virus! Action Taken: No Action Taken. Fri Jul 01 11:32:15 2005 => File C:\WINDOWS\SYSTEM\POLALL1M.EXE infected by "Trojan-Downloader.Win32.Agent.ae" Virus! Action Taken: No Action Taken. Fri Jul 01 11:34:03 2005 => File C:\WINDOWS\SYSTEM32\ngpw36.exe.exe infected by "Trojan-Clicker.Win32.VB.gn" Virus! Action Taken: No Action Taken. Fri Jul 01 11:41:45 2005 => File C:\WINDOWS\Sngpw36.exe infected by "Trojan-Clicker.Win32.VB.gn" Virus! Action Taken: No Action Taken. Fri Jul 01 12:23:28 2005 => File C:\Programme\Norton AntiVirus\Quarantine\2066722E.exe infected by "P2P-Worm.Win32.SdDrop.c" Virus! Action Taken: No Action Taken. Fri Jul 01 12:23:28 2005 => File C:\Programme\Norton AntiVirus\Quarantine\4F652677.exe infected by "P2P-Worm.Win32.SdDrop.c" Virus! Action Taken: No Action Taken. Fri Jul 01 12:23:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\6F8A7317.dll infected by "Trojan-Clicker.Win32.Delf.r" Virus! Action Taken: No Action Taken. Fri Jul 01 12:23:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\6F94710C.exe infected by "Trojan-Spy.Win32.Briss.e" Virus! Action Taken: No Action Taken. Fri Jul 01 12:23:31 2005 => File C:\Programme\Norton AntiVirus\Quarantine\6F94710C.dll infected by "Trojan-Spy.Win32.Briss.i" Virus! Action Taken: No Action Taken. Fri Jul 01 12:23:31 2005 => File C:\Programme\Norton AntiVirus\Quarantine\5DCB6947.exe infected by "Trojan-Spy.Win32.Briss.j" Virus! Action Taken: No Action Taken. Fri Jul 01 12:23:31 2005 => File C:\Programme\Norton AntiVirus\Quarantine\6F9A4505.TMP infected by "Trojan-Spy.Win32.Briss.j" Virus! Action Taken: No Action Taken. Fri Jul 01 12:23:33 2005 => File C:\Programme\Norton AntiVirus\Quarantine\6F9E6F01.exe infected by "Trojan-Dropper.Win32.Delf.z" Virus! Action Taken: No Action Taken. Fri Jul 01 12:44:28 2005 => Total Disinfected Files: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ ---------- c:\bases_x\mwav.log Fri Jul 01 11:16:29 2005 => File C:\WINDOWS\SYSTEM\MSBE.DLL tagged as "not-a-virus:AdWare.BargainBuddy.j". Action Taken: No Action Taken. Fri Jul 01 11:16:29 2005 => File C:\WINDOWS\SYSTEM\NVMS.DLL tagged as "not-a-virus:AdWare.BargainBuddy.j". Action Taken: No Action Taken. Fri Jul 01 11:16:29 2005 => File C:\WINDOWS\SYSTEM\MSCB.DLL tagged as "not-a-virus:AdWare.BargainBuddy.j". Action Taken: No Action Taken. Fri Jul 01 11:16:29 2005 => File C:\WINDOWS\SYSTEM32\NGSH33.DLL tagged as "not-a-virus:AdWare.AdBlaster.b". Action Taken: No Action Taken. Fri Jul 01 11:16:38 2005 => File C:\Programme\Save\Save.exe tagged as "not-a-virus:AdWare.SaveNow.bc". Action Taken: No Action Taken. Fri Jul 01 11:18:33 2005 => File C:\WINDOWS\TWAINTEC.DLL tagged as "not-a-virus:AdWare.BiSpy.t". Action Taken: No Action Taken. Fri Jul 01 11:19:05 2005 => File C:\WINDOWS\cep1unin.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 11:19:06 2005 => File C:\WINDOWS\x-launch.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 11:19:07 2005 => File C:\WINDOWS\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 11:19:16 2005 => File C:\WINDOWS\NDNuninstall4_50.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken. Fri Jul 01 11:19:18 2005 => File C:\WINDOWS\Sngsh33.dll tagged as "not-a-virus:AdWare.AdBlaster.b". Action Taken: No Action Taken. Fri Jul 01 11:19:25 2005 => File C:\WINDOWS\PREINSTT.EXE tagged as "not-a-virus:AdWare.BiSpy.f". Action Taken: No Action Taken. Fri Jul 01 11:21:45 2005 => File C:\WINDOWS\SYSTEM\exdl.exe tagged as "not-a-virus:AdWare.BargainBuddy.j". Action Taken: No Action Taken. Fri Jul 01 11:21:45 2005 => File C:\WINDOWS\SYSTEM\exul.exe tagged as "not-a-virus:AdWare.BargainBuddy.j". Action Taken: No Action Taken. Fri Jul 01 11:21:46 2005 => File C:\WINDOWS\SYSTEM\apuc.dll tagged as "not-a-virus:AdWare.BargainBuddy.j". Action Taken: No Action Taken. Fri Jul 01 11:22:29 2005 => File C:\WINDOWS\SYSTEM\FSG.exe_data.dat tagged as "not-a-virus:AdWare.Gator.1050". Action Taken: No Action Taken. Fri Jul 01 11:27:15 2005 => File C:\WINDOWS\OPTIONS\CABS\EBD.CAB tagged as not-a-virus:Tool.DOS.Restart. No Action Taken. Fri Jul 01 11:27:17 2005 => File C:\WINDOWS\OPTIONS\CABS\OLS\AOL\AOL40DE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 11:30:33 2005 => File C:\WINDOWS\SYSTEM\MACROMED\Shockwave 10\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 11:32:26 2005 => File C:\WINDOWS\SYSTEM\exdl.exe tagged as "not-a-virus:AdWare.BargainBuddy.j". Action Taken: No Action Taken. Fri Jul 01 11:32:26 2005 => File C:\WINDOWS\SYSTEM\exul.exe tagged as "not-a-virus:AdWare.BargainBuddy.j". Action Taken: No Action Taken. Fri Jul 01 11:32:26 2005 => File C:\WINDOWS\SYSTEM\apuc.dll tagged as "not-a-virus:AdWare.BargainBuddy.j". Action Taken: No Action Taken. Fri Jul 01 11:33:10 2005 => File C:\WINDOWS\SYSTEM\FSG.exe_data.dat tagged as "not-a-virus:AdWare.Gator.1050". Action Taken: No Action Taken. Fri Jul 01 11:33:16 2005 => File C:\WINDOWS\TWAINTEC.DLL tagged as "not-a-virus:AdWare.BiSpy.t". Action Taken: No Action Taken. Fri Jul 01 11:34:03 2005 => File C:\WINDOWS\SYSTEM32\stmtreco.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken. Fri Jul 01 11:41:32 2005 => File C:\WINDOWS\cep1unin.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 11:41:33 2005 => File C:\WINDOWS\x-launch.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 11:41:34 2005 => File C:\WINDOWS\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 11:41:44 2005 => File C:\WINDOWS\NDNuninstall4_50.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken. Fri Jul 01 11:41:56 2005 => File C:\WINDOWS\Sngsh33.dll tagged as "not-a-virus:AdWare.AdBlaster.b". Action Taken: No Action Taken. Fri Jul 01 11:42:03 2005 => File C:\WINDOWS\PREINSTT.EXE tagged as "not-a-virus:AdWare.BiSpy.f". Action Taken: No Action Taken. Fri Jul 01 12:06:46 2005 => File C:\Programme\ACDSee32\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 12:14:52 2005 => File C:\Programme\Opera\UnInst\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 12:15:34 2005 => File C:\Programme\DVDlab\DVD-lab 1.1.crack.exe tagged as not-a-virus:Tool.Win32.TPE.a. No Action Taken. Fri Jul 01 12:19:09 2005 => File C:\Programme\Steinberg\Cubase VST32 Demo\Uninstall.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 12:19:10 2005 => File C:\Programme\BearShare\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 12:19:15 2005 => File C:\Programme\BearShare\Installer\saveinstwm.exe tagged as "not-a-virus:AdWare.SaveNow.z". Action Taken: No Action Taken. Fri Jul 01 12:19:18 2005 => File C:\Programme\BearShare\Installer\BSINSTALL.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 12:23:49 2005 => File C:\Programme\Save\SaveUninst.exe tagged as "not-a-virus:AdWare.SaveNow.bc". Action Taken: No Action Taken. Fri Jul 01 12:31:16 2005 => File C:\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 12:32:15 2005 => File C:\Audio\Logic Audio Platinum\UNWISE.EXE tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 12:36:31 2005 => File D:\My Downloads\RADTools.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 12:36:51 2005 => File D:\My Downloads\ow32dede754.exe tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 12:38:57 2005 => File D:\My Downloads\LiveDemo404_DE.zip tagged as not-a-virus:Tool.Win32.Reboot. No Action Taken. Fri Jul 01 12:39:07 2005 => File D:\My Downloads\dvdlab_final.zip tagged as not-a-virus:Tool.Win32.TPE.a. No Action Taken. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ ---------- c:\bases_X\mwav.log Fri Jul 01 12:44:28 2005 => Total Objects Scanned: 57102 ---------- c:\bases_X\mwav.log Fri Jul 01 12:44:28 2005 => Total Virus(es) Found: 91 ---------- c:\bases_x\mwav.log Fri Jul 01 12:44:28 2005 => Total Errors: 201 ---------- c:\bases_x\mwav.log Fri Jul 01 12:44:28 2005 => Time Elapsed: 01:19:05 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ ~~~~~~~ © Haui ;-) ~~~~~~~ ~~~~~~~ Dank an Cidre ~~~~~~~ _____________ Anm. Threads zusammengeführt! LG Cidre S-Mod TB Geändert von Cidre (01.07.2005 um 15:33 Uhr) |
01.07.2005, 15:32 | #4 | |
Administrator, a.D. | Bitte um Hilfe / HijackThis-check Hallo, Zitat:
Der Übersichtlichkeit wegen wäre es sinnvoller, wenn du in einem Thread bleiben würdest. Darum werden jetztbeide Threads wieder zusammengeführt! Lösche, wie in der eScan Anleitung beschrieben, die einzelnen Funde und wende zusätzlich Ad-Aware und Spybot S&D im abgesicherten Modus an. Poste anschließend ein neues HJT Log-File. |
Themen zu Bitte um Hilfe / HijackThis-check |
.dll, 1.exe, adware.betterinternet, antivirus, audio, bitte um hilfe, c.exe, c:\windows, cubase, erstellt, escan, file, files, helfen, infected, information, install, install.exe, log, neu, norton, not-a-virus, opera, platinum, programme, quara, shockwave, system, system32, total, uninstall.exe, vielen dank, virus, windows |