|
Log-Analyse und Auswertung: Log File prüfen bitteWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
04.07.2005, 09:59 | #1 |
| [MIST/HILFE]Log File prüfen bitte...[KEIN ZUGANG ZUM INET MEHR] so, wollte mich mal wieder vergewissern, dass mein PC ein paar Pannen hat, um ihn wieder neu zu formatieren...ausser natürlcih das lässt sich umgehen.... Logfile of HijackThis v1.99.1 Scan saved at 10:56:15, on 04.07.2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\system32\spoolsv.exe C:\AVPersonal\AVGUARD.EXE C:\AVPersonal\AVWUPSRV.EXE C:\Programme\D-Link\AirPlus Xtreme G\AirPlusCFG.exe C:\Programme\Alpha Networks\ANIWZCS Service\WZCSLDR.exe C:\WINDOWS\System32\svchost.exe C:\Programme\Intuwave\Shared\mRouterRunTime\mRouterConfig.exe C:\Programme\ICQLite\ICQLite.exe C:\Programme\Java\jre1.5.0_02\bin\jusched.exe C:\AVPersonal\AVGNT.EXE C:\Programme\ZoneAlarm\zlclient.exe C:\Programme\Intuwave\Shared\mRouterRunTime\mRouterRuntime.exe C:\Programme\MessengerPlus! 3\MsgPlus.exe C:\WINDOWS\System32\ctfmon.exe C:\Programme\AOL Messenger\aim.exe C:\Programme\SMS Manager\GMX SMS-Manager\SMSMngr.exe C:\Programme\Siemens Data Suite SX1\SDS\SDSScheduler.exe C:\PROGRA~1\SIEMEN~1\SDS\SPHONE~2.EXE C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SYMBIA~1.EXE C:\PROGRA~1\Symbian\Shared\SYMBIA~1\SCBAL.exe C:\PROGRA~1\FIREFOX\FIREFOX.EXE C:\Programme\Internet Explorer\IEXPLORE.EXE C:\Programme\Internet Explorer\IEXPLORE.EXE C:\Programme\WinRAR\WinRAR.exe D:\2-loWRenCe\reMixCLuB\sOfTWaRe\Hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = hxxp://www.aabmumvzxgs.uk/o7SPNVNnVY...4ePUp9GZD.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/ R3 - URLSearchHook: (no name) - {02EE5B04-F144-47BB-83FB-A60BD91B74A9} - C:\Programme\SurfSideKick 3\SskBho.dll O2 - BHO: CeresObj Class - {00000049-8F91-4D9C-9573-F016E7626484} - C:\WINDOWS\ceres.dll (file missing) O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O4 - HKLM\..\Run: [D-Link AirPlus Xtreme G] C:\Programme\D-Link\AirPlus Xtreme G\AirPlusCFG.exe O4 - HKLM\..\Run: [ANIWZCSService] C:\Programme\Alpha Networks\ANIWZCS Service\WZCSLDR.exe O4 - HKLM\..\Run: [mRouterConfig for Siemens Data Suite SX1] C:\Programme\Intuwave\Shared\mRouterRunTime\mRouterConfig.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_02\bin\jusched.exe O4 - HKLM\..\Run: [SurfSideKick 3] C:\Programme\SurfSideKick 3\Ssk.exe O4 - HKLM\..\Run: [yhqpv] C:\WINDOWS\System32\yhqpv.exe O4 - HKLM\..\Run: [AVGCtrl] "C:\AVPersonal\AVGNT.EXE" /min O4 - HKLM\..\Run: [Zone Labs Client] C:\Programme\ZoneAlarm\zlclient.exe O4 - HKLM\..\Run: [MessengerPlus3] "C:\Programme\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\RunOnce: [WIAWizardMenu] RUNDLL32.EXE C:\WINDOWS\System32\sti_ci.dll,WiaCreateWizardMenu O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [SurfSideKick 3] C:\Programme\SurfSideKick 3\Ssk.exe O4 - HKCU\..\Run: [AIM] C:\Programme\AOL Messenger\aim.exe -cnetwait.odl O4 - HKCU\..\Run: [GMX SMS-Manager] C:\Programme\SMS Manager\GMX SMS-Manager\SMSMngr.exe O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot O4 - Global Startup: Microsoft Office.lnk = ? O4 - Global Startup: SDSScheduler.lnk = C:\Programme\Siemens Data Suite SX1\SDS\SDSScheduler.exe O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\BRO~1\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_02\bin\npjpi150_02.dll O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Programme\AOL Messenger\aim.exe O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE O12 - Plugin for .spop: C:\Programme\Internet Explorer\Plugins\NPDocBox.dll O15 - Trusted Zone: hxxp://www.neededware.com O16 - DPF: NDWCab - hxxp://www.neededware.com/ndw3.cab O16 - DPF: {1239CC52-59EF-4DFA-8C61-90FFA846DF7E} (Musicnotes Viewer) - hxxp://www.musicnotes.com/download/mnviewer.cab O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - hxxp://static.windupdates.com/cab/Me...bridge-c18.cab O16 - DPF: {42F2C9BA-614F-47C0-B3E3-ECFD34EED658} (Installer Class) - hxxp://www.ysbweb.com/ist/softwares/...sb_1002952.cab O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - hxxp://by103fd.bay103.hotmail.msn.co...s/MsnPUpld.cab O16 - DPF: {7C559105-9ECF-42B8-B3F7-832E75EDD959} (Installer Class) - hxxp://www.xxxtoolbar.com/ist/softwa...06_regular.cab O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - hxxp://messenger.zone.msn.com/binary...t.cab31267.cab O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} - hxxp://activex.microsoft.com/objects/ocget.dll O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - hxxp://messenger.msn.com/download/ms...downloader.cab O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - hxxp://activex.microsoft.com/objects/ocget.dll O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - hxxp://messenger.zone.msn.com/binary...n.cab31267.cab O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\AVPersonal\AVWUPSRV.EXE O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe Geändert von DaLonStyliciouz (14.07.2005 um 13:07 Uhr) |
05.07.2005, 20:51 | #2 |
| Log File prüfen bitte hab cih was falsch geacmht mit meinem logfile???
__________________oder is da alles korrekt, dass man dazu ncihts schreiben muss?.... |
05.07.2005, 21:01 | #3 | ||
| Log File prüfen bitteZitat:
Deaktiviere alle aktiven Hyperlinks so, wie es in der HijackThis-Anleitung beschrieben ist. Zitat:
Führe bitte mal einen Scan mit eScan durch und stelle uns die Virus-Log-Information zur Verfügung. BTW: Warum ist dein Windows nicht auf dem aktuellen Stand? |
14.07.2005, 09:18 | #4 |
| Log File prüfen bitte so hier ist mein escan ergebniss ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Thu Jul 14 02:06:04 2005 => System found infected with YourSiteBar Spyware/Adware ({42F2C9BA-614F-47C0-B3E3-ECFD34EED658})! Action taken: No Action Taken. Thu Jul 14 02:06:05 2005 => System found infected with IstBAR Spyware/Adware ({0985c112-2562-46f2-8da6-92648ba4630f})! Action taken: No Action Taken. Thu Jul 14 02:06:05 2005 => System found infected with IstBAR Spyware/Adware ({67907b3c-a6ef-4a01-99ad-3fcd5f526429})! Action taken: No Action Taken. Thu Jul 14 02:06:05 2005 => System found infected with XXXToolbar Spyware/Adware ({7C559105-9ECF-42B8-B3F7-832E75EDD959})! Action taken: No Action Taken. Thu Jul 14 02:06:05 2005 => System found infected with Alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Thu Jul 14 02:06:06 2005 => System found infected with VX2 Spyware/Adware ({92daf5c1-2135-4e0c-b7a0-259abfcd3904})! Action taken: No Action Taken. Thu Jul 14 02:06:06 2005 => System found infected with VX2 Spyware/Adware ({bb0d5adc-028d-4185-9288-722ddce2c757})! Action taken: No Action Taken. Thu Jul 14 02:06:06 2005 => System found infected with VX2 Spyware/Adware ({00000049-8f91-4d9c-9573-f016e7626484})! Action taken: No Action Taken. Thu Jul 14 02:06:06 2005 => System found infected with BetterInternet Adware (ceresdll.ceresdllobj)! Action taken: No Action Taken. Thu Jul 14 02:06:08 2005 => System found infected with Roings Spyware/Adware (objsafe.tlb)! Action taken: No Action Taken. Thu Jul 14 02:07:54 2005 => Scanning Folder: C:\AVPersonal\INFECTED\*.* Thu Jul 14 02:16:19 2005 => File C:\Dokumente und Einstellungen\Jerrold\Anwendungsdaten\wayburnowns\RECT POP.exe infected by "Trojan-Downloader.Win32.Swizzor.bo" Virus! Action Taken: No Action Taken. Thu Jul 14 02:40:53 2005 => File C:\Dokumente und Einstellungen\Jerrold\Lokale Einstellungen\Temporary Internet Files\Content.IE5\SHUR09QV\home[1].htm infected by "Trojan.JS.Cardst" Virus! Action Taken: No Action Taken. Thu Jul 14 02:43:22 2005 => File C:\Dokumente und Einstellungen\Jerrold\SSK3_B5 Verticlick 8.exe infected by "Trojan-Dropper.Win32.Small.qn" Virus! Action Taken: No Action Taken. Thu Jul 14 02:43:55 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.* Thu Jul 14 02:43:55 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\CA8DMJGD.HTM.VIR Thu Jul 14 02:43:55 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\CERES.DLL.VIR Thu Jul 14 02:43:55 2005 => File C:\Programme\AVPersonal\INFECTED\CERES.DLL.VIR tagged as "not-a-virus:AdWare.BetterInternet.d". Action Taken: No Action Taken. Thu Jul 14 02:43:55 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\EPX30105.EXE.VIR Thu Jul 14 02:43:56 2005 => File C:\Programme\AVPersonal\INFECTED\EPX30105.EXE.VIR infected by "Trojan-Downloader.Win32.Lastad.p" Virus! Action Taken: No Action Taken. Thu Jul 14 02:43:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\IINSTALL.EXE.VIR Thu Jul 14 02:43:56 2005 => File C:\Programme\AVPersonal\INFECTED\IINSTALL.EXE.VIR infected by "Trojan-Downloader.Win32.IstBar.jn" Virus! Action Taken: No Action Taken. Thu Jul 14 02:43:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\INSTALLER_MARKETING35.EXE.VIR Thu Jul 14 02:43:56 2005 => File C:\Programme\AVPersonal\INFECTED\INSTALLER_MARKETING35.EXE.VIR infected by "Trojan-Downloader.Win32.Adload.a" Virus! Action Taken: No Action Taken. Thu Jul 14 02:43:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\INTERNAZIONALE_VER11.OCX.VIR Thu Jul 14 02:43:57 2005 => File C:\Programme\AVPersonal\INFECTED\INTERNAZIONALE_VER11.OCX.VIR infected by "Trojan-Clicker.Win32.Adpower.b" Virus! Action Taken: No Action Taken. Thu Jul 14 02:43:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ISTACTIVEX.DLL.VIR Thu Jul 14 02:43:57 2005 => File C:\Programme\AVPersonal\INFECTED\ISTACTIVEX.DLL.VIR infected by "Trojan-Downloader.Win32.IstBar.gen" Virus! Action Taken: No Action Taken. Thu Jul 14 02:43:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\PROMPT[1].HTM.001 Thu Jul 14 02:43:57 2005 => File C:\Programme\AVPersonal\INFECTED\PROMPT[1].HTM.001 infected by "Trojan-Downloader.JS.IstBar.k" Virus! Action Taken: No Action Taken. Thu Jul 14 02:43:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\PROMPT[1].HTM.002 Thu Jul 14 02:43:57 2005 => File C:\Programme\AVPersonal\INFECTED\PROMPT[1].HTM.002 infected by "Trojan-Downloader.JS.IstBar.k" Virus! Action Taken: No Action Taken. Thu Jul 14 02:43:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\PROMPT[1].HTM.VIR Thu Jul 14 02:43:57 2005 => File C:\Programme\AVPersonal\INFECTED\PROMPT[1].HTM.VIR infected by "Trojan-Downloader.JS.IstBar.k" Virus! Action Taken: No Action Taken. Thu Jul 14 02:43:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\SE.DLL.001 Thu Jul 14 02:44:00 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\SE.DLL.002 Thu Jul 14 02:44:03 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\SE.DLL.003 Thu Jul 14 02:44:06 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\SE.DLL.004 Thu Jul 14 02:44:10 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\SE.DLL.005 Thu Jul 14 02:44:13 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\SE.DLL.VIR Thu Jul 14 02:44:16 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\WUAMPDR.VIR Thu Jul 14 02:44:16 2005 => File C:\Programme\AVPersonal\INFECTED\WUAMPDR.VIR infected by "Backdoor.Win32.Wootbot.gen" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:16 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\WUAMPDR.VIR00.VIR Thu Jul 14 02:44:17 2005 => File C:\Programme\AVPersonal\INFECTED\WUAMPDR.VIR00.VIR infected by "Backdoor.Win32.Wootbot.gen" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:17 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\WUAMPDR.VIR01.VIR Thu Jul 14 02:44:17 2005 => File C:\Programme\AVPersonal\INFECTED\WUAMPDR.VIR01.VIR infected by "Backdoor.Win32.Wootbot.gen" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:17 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPV.EXE.VIR Thu Jul 14 02:44:18 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPV.EXE.VIR infected by "Trojan-Downloader.Win32.Lastad.p" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:18 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.001 Thu Jul 14 02:44:18 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.001 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:18 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.002 Thu Jul 14 02:44:18 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.002 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:18 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.003 Thu Jul 14 02:44:18 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.003 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:18 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.004 Thu Jul 14 02:44:18 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.004 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:18 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.005 Thu Jul 14 02:44:18 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.005 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:18 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.006 Thu Jul 14 02:44:18 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.006 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:18 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.007 Thu Jul 14 02:44:18 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.007 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:18 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.008 Thu Jul 14 02:44:18 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.008 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:18 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.009 Thu Jul 14 02:44:18 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.009 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:18 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.010 Thu Jul 14 02:44:18 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.010 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:18 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.011 Thu Jul 14 02:44:18 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.011 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:18 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.012 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.012 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.013 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.013 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.014 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.014 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.015 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.015 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.016 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.016 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.017 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.017 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.018 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.018 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.019 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.019 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.020 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.020 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.021 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.021 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.022 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.022 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.023 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.023 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.024 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.024 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.025 Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YHQPVAEG05.DLL.025 infected by "Trojan-Downloader.Win32.Lastad.h" Virus! Action Taken: No Action Taken. Thu Jul 14 02:44:19 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\YSBACTIVEX.DLL.VIR Thu Jul 14 02:44:19 2005 => File C:\Programme\AVPersonal\INFECTED\YSBACTIVEX.DLL.VIR infected by "Trojan-Downloader.Win32.IstBar.gen" Virus! Action Taken: No Action Taken. Thu Jul 14 02:57:58 2005 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.2\EPXActiveX.ocx infected by "Trojan-Dropper.Win32.Agent.or" Virus! Action Taken: No Action Taken. Thu Jul 14 03:48:12 2005 => Total Disinfected Files: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Thu Jul 14 02:05:49 2005 => File C:\PROGRA~1\SURFSI~1\Ssk.exe tagged as "not-a-virus:AdWare.SurfSide.l". Action Taken: No Action Taken. Thu Jul 14 02:17:29 2005 => File C:\Dokumente und Einstellungen\Jerrold\Lokale Einstellungen\Temp\DrTemp\ceres.cab tagged as "not-a-virus:AdWare.BetterInternet.d". Action Taken: No Action Taken. Thu Jul 14 02:17:29 2005 => File C:\Dokumente und Einstellungen\Jerrold\Lokale Einstellungen\Temp\DrTemp\ceres.dll tagged as "not-a-virus:AdWare.BetterInternet.d". Action Taken: No Action Taken. Thu Jul 14 02:23:43 2005 => File C:\Dokumente und Einstellungen\Jerrold\Lokale Einstellungen\Temp\i2.tmp tagged as "not-a-virus:AdWare.SurfSide.j". Action Taken: No Action Taken. Thu Jul 14 02:23:47 2005 => File C:\Dokumente und Einstellungen\Jerrold\Lokale Einstellungen\Temp\MsgPlusSetup-B.tmp tagged as "not-a-virus:AdWare.Lop". Action Taken: No Action Taken. Thu Jul 14 02:43:55 2005 => File C:\Programme\AVPersonal\INFECTED\CERES.DLL.VIR tagged as "not-a-virus:AdWare.BetterInternet.d". Action Taken: No Action Taken. Thu Jul 14 02:44:20 2005 => File C:\Programme\C2Media\Setup.exe tagged as "not-a-virus:AdWare.Lop". Action Taken: No Action Taken. Thu Jul 14 02:56:13 2005 => File C:\Programme\SurfSideKick 3\SskBho.dll tagged as "not-a-virus:AdWare.SurfSide.l". Action Taken: No Action Taken. Thu Jul 14 02:56:13 2005 => File C:\Programme\SurfSideKick 3\SskCore.dll tagged as "not-a-virus:AdWare.SurfSide.n". Action Taken: No Action Taken. Thu Jul 14 02:57:59 2005 => File C:\WINDOWS\Downloaded Program Files\MediaAccX.dll tagged as "not-a-virus:AdWare.WinAD.ba". Action Taken: No Action Taken. Thu Jul 14 03:13:27 2005 => File C:\WINDOWS\system32\WinStat11.dll tagged as "not-a-virus:AdWare.Winsta.a". Action Taken: No Action Taken. Thu Jul 14 03:13:27 2005 => File C:\WINDOWS\system32\WinStat12.dll tagged as "not-a-virus:AdWare.Winsta.a". Action Taken: No Action Taken. Thu Jul 14 03:15:46 2005 => File D:\2-loWRenCe\reMixCLuB\mIRC\mirc.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.16. No Action Taken. Thu Jul 14 03:15:47 2005 => File D:\2-loWRenCe\reMixCLuB\mIRC\mirc616.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.16. No Action Taken. Thu Jul 14 03:45:44 2005 => File D:\System Volume Information\_restore{767B03EC-5A58-409F-B8F0-4D11021A54B7}\RP10\A0016196.exe tagged as "not-a-virus:AdWare.Altnet.m". Action Taken: No Action Taken. Thu Jul 14 03:46:03 2005 => File D:\System Volume Information\_restore{767B03EC-5A58-409F-B8F0-4D11021A54B7}\RP13\A0016791.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.12. No Action Taken. Thu Jul 14 03:47:54 2005 => File D:\System Volume Information\_restore{767B03EC-5A58-409F-B8F0-4D11021A54B7}\RP9\A0015195.dll tagged as "not-a-virus:AdWare.Altnet.c". Action Taken: No Action Taken. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ Thu Jul 14 03:48:12 2005 => Total Virus(es) Found: 74 Thu Jul 14 03:48:12 2005 => Total Errors: 40 Thu Jul 14 03:48:12 2005 => Time Elapsed: 01:42:16 Thu Jul 14 03:48:12 2005 => Total Objects Scanned: 73846 Thu Jul 14 02:04:42 2005 => Virus Database Date: 2005/07/10 Thu Jul 14 03:48:12 2005 => Virus Database Date: 2005/07/10 Thu Jul 14 09:56:09 2005 => Virus Database Date: 2005/07/10 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~ ~~~~~~~ © Haui ;-) ~~~~~~~ ~~~~~~~ Dank an Cidre ~~~~~~~ 1. wieso mein windows nicht auf den neuesten stand is kann ich le3ider nciht sagen, da mein onkel alles installiert hat.... 1. alle links wurden in meinem ersten post geändert Geändert von DaLonStyliciouz (14.07.2005 um 09:28 Uhr) |
14.07.2005, 13:09 | #5 |
| Log File prüfen bitte mist, jez kann ich auch nciht mehr ins internet mit dem computer....ich bin jez auf einem anderem....der virus zeigt jez wohl seine wirkung....HILFE!!! |
14.07.2005, 22:11 | #6 |
| Log File prüfen bitte öhm, hab ich iweder was falsch gemacht mit meinen posts, ausser dass ich euch vielleicht nerve der virus kotzt mich echt an... |
Themen zu Log File prüfen bitte |
adobe, antivir, antivir update, ci.dll, excel, explorer, file, firefox, hijack, hijackthis, internet, internet explorer, log, log file, microsoft, monitor, msn, neu, programme, prüfen, rundll, rundll32.exe, software, system, system32, urlsearchhook, windows, windows messenger, windows xp |