|
Log-Analyse und Auswertung: System kompromittiert? Bitte um HilfeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
08.09.2005, 20:30 | #46 |
Moderator, a.D. | System kompromittiert? Bitte um Hilfe An deiner Stelle würd ich einfach neu aufsetzen. Die Zeit, die du bislang für Lösungsversuche aufgewendet hast, hätte zum Neuaufsetzen von einem dutzend Rechnern gereicht. Gruß Yopie |
08.09.2005, 20:32 | #47 | |
| System kompromittiert? Bitte um HilfeZitat:
|
08.09.2005, 20:37 | #48 |
System kompromittiert? Bitte um Hilfe jep hab ich auch gedacht das neuinstallieren besser ist in diesem fall.
__________________aber ich war hald net sicher, ob das wirklich notwendig ist. naja Neuaufsetzen is besser - also mach es auch is aber schade, ich hätte auch noch gern gesehen ob und welche malware hier mal wieder im spiel zu sovielen tausenden ist. |
08.09.2005, 21:50 | #49 |
| System kompromittiert? Bitte um Hilfe poste bitte nur die Dateien, die als Infected angezeigt werden
__________________ MfG Sabina |
09.09.2005, 20:53 | #50 |
| System kompromittiert? Bitte um Hilfe Hallo, ich habe jetzt nochmal im abgesicherten Modus mit escan mein syystem gescannt dass ist die statistik: (Die komplette mwav.log datei ist 36,1 MB groß!!! Wenn ich sie öffne dauert`s an die 2 Minuten bis sie angezeigt wird!!!) Fri Sep 09 18:41:50 2005 => ***** Scanning complete. ***** Fri Sep 09 18:41:50 2005 => Total Objects Scanned: 205400 Fri Sep 09 18:41:50 2005 => Total Virus(es) Found: 71592 Fri Sep 09 18:41:50 2005 => Total Disinfected Files: 0 Fri Sep 09 18:41:50 2005 => Total Files Renamed: 0 Fri Sep 09 18:41:50 2005 => Total Deleted Objects: 0 Fri Sep 09 18:41:50 2005 => Total Errors: 107 Fri Sep 09 18:41:50 2005 => Time Elapsed: 03:39:44 Fri Sep 09 18:41:50 2005 => Virus Database Date: 2005/09/07 Fri Sep 09 18:41:50 2005 => Virus Database Count: 148193 Fri Sep 09 18:41:50 2005 => Scan Completed. Fri Sep 09 21:37:45 2005 => Total Objects Scanned: 205400 Fri Sep 09 21:37:45 2005 => Total Virus(es) Found: 71592 Fri Sep 09 21:37:45 2005 => Total Disinfected Files: 0 Fri Sep 09 21:37:45 2005 => Total Files Renamed: 0 Fri Sep 09 21:37:45 2005 => Total Deleted Objects: 0 Fri Sep 09 21:37:45 2005 => Total Errors: 107 Fri Sep 09 21:37:45 2005 => Time Elapsed: 03:39:44 Fri Sep 09 21:37:45 2005 => AV Library Unloaded (3)... ...schon bisschen merkwürdig oder??? |
09.09.2005, 20:58 | #51 |
| System kompromittiert? Bitte um Hilfe ...ich hab hier mal nen kleinen Ausschnitt, der vielleicht von interesse sein dürfte: Fri Sep 09 15:21:55 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\QUAR32.DLL Fri Sep 09 15:21:55 2005 => Scanning Folder: C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\*.* Fri Sep 09 15:21:55 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00004490.TMP Fri Sep 09 15:48:04 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00004490.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:04 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00007BB3.TMP Fri Sep 09 15:48:04 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00007BB3.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:04 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000107FF.TMP Fri Sep 09 15:48:05 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000107FF.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:05 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00010DF0.TMP Fri Sep 09 15:48:05 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00010DF0.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:05 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0001316F.TMP Fri Sep 09 15:48:05 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0001316F.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:05 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00022B1E.tmp Fri Sep 09 15:48:05 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00022B1E.tmp infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:05 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000360DA.TMP Fri Sep 09 15:48:05 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000360DA.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:05 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00036E8D.TMP Fri Sep 09 15:48:05 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00036E8D.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:05 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000425AF.TMP Fri Sep 09 15:48:05 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000425AF.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:05 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00046082.TMP Fri Sep 09 15:48:05 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00046082.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:05 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00051961.TMP Fri Sep 09 15:48:05 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00051961.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:05 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0005551A.tmp Fri Sep 09 15:48:05 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0005551A.tmp infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:05 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00055B6C.TMP Fri Sep 09 15:48:05 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00055B6C.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:05 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00060AD6.TMP Fri Sep 09 15:48:05 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00060AD6.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:05 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00061889.TMP Fri Sep 09 15:48:06 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00061889.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:06 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00074FAC.TMP Fri Sep 09 15:48:06 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00074FAC.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:06 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000801F6.TMP Fri Sep 09 15:48:06 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000801F6.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:06 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00080568.TMP Fri Sep 09 15:48:06 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00080568.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:06 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00085BF8.TMP Fri Sep 09 15:48:06 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00085BF8.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:06 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00087F16.tmp Fri Sep 09 15:48:06 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00087F16.tmp infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:06 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000934D3.TMP Fri Sep 09 15:48:06 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000934D3.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:06 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000A4286.TMP Fri Sep 09 15:48:06 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000A4286.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:06 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000A47AF.TMP Fri Sep 09 15:48:06 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000A47AF.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:06 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000A79A8.TMP Fri Sep 09 15:48:06 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000A79A8.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:06 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000B05F5.TMP Fri Sep 09 15:48:06 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000B05F5.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:06 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000B2913.tmp Fri Sep 09 15:48:07 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000B2913.tmp infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:07 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000B2F64.TMP Fri Sep 09 15:48:07 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000B2F64.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:07 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000C0D68.TMP Fri Sep 09 15:48:07 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000C0D68.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:07 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000C5ECF.TMP Fri Sep 09 15:48:07 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000C5ECF.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:07 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000D23A5.TMP Fri Sep 09 15:48:07 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000D23A5.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:07 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000D6C82.TMP Fri Sep 09 15:48:07 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000D6C82.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:07 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000E5961.TMP Fri Sep 09 15:48:07 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000E5961.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:07 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000F530F.tmp Fri Sep 09 15:48:07 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\000F530F.tmp infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:07 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001008CB.TMP Fri Sep 09 15:48:07 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001008CB.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:07 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0010167E.TMP Fri Sep 09 15:48:07 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0010167E.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:07 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00114DA1.TMP Fri Sep 09 15:48:07 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00114DA1.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:07 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0012016E.TMP Fri Sep 09 15:48:07 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0012016E.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:07 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0012035D.TMP Fri Sep 09 15:48:08 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0012035D.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:08 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001259ED.TMP Fri Sep 09 15:48:08 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001259ED.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:08 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00127651.TMP Fri Sep 09 15:48:08 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00127651.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:08 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00127D0C.tmp Fri Sep 09 15:48:08 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00127D0C.tmp infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:08 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001332C8.TMP Fri Sep 09 15:48:08 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001332C8.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:08 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0013407B.TMP Fri Sep 09 15:48:08 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0013407B.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:08 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00144726.TMP Fri Sep 09 15:48:08 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00144726.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:08 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0014779E.TMP Fri Sep 09 15:48:08 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0014779E.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:08 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001503EA.TMP Fri Sep 09 15:48:08 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001503EA.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:08 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00152708.tmp Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00152708.tmp infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00152D5A.TMP Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00152D5A.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00153A57.TMP Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00153A57.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00165CC4.TMP Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00165CC4.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0017219A.TMP Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0017219A.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00176A77.TMP Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00176A77.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00182DE6.TMP Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00182DE6.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00185104.tmp Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00185104.tmp infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00185756.TMP Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\00185756.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001A06C1.TMP Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001A06C1.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001A1474.TMP Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001A1474.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001A4B96.TMP Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001A4B96.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001B3090.TMP Fri Sep 09 15:48:09 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001B3090.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:09 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001C0152.TMP Fri Sep 09 15:48:10 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001C0152.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:10 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001C7B01.tmp Fri Sep 09 15:48:10 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001C7B01.tmp infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:10 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001D30BD.TMP Fri Sep 09 15:48:10 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001D30BD.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:10 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001D3E70.TMP Fri Sep 09 15:48:10 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001D3E70.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:10 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001E4766.TMP Fri Sep 09 15:48:10 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001E4766.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:10 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001E7593.TMP Fri Sep 09 15:48:10 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001E7593.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:10 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001F01DF.TMP Fri Sep 09 15:48:10 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001F01DF.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:10 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001F058E.TMP Fri Sep 09 15:48:10 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001F058E.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:10 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001F24FD.tmp Fri Sep 09 15:48:10 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001F24FD.tmp infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. Fri Sep 09 15:48:10 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001F2B4F.TMP Fri Sep 09 15:48:10 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\001F2B4F.TMP infected by "Trojan.Win32.EliteBar.a" Virus! Action Taken: No Action Taken. (....) ...und so geht`s dann halt auch noch ewig weiter! Was bedeutet das kann man da was machen??? |
09.09.2005, 21:20 | #52 | |
| System kompromittiert? Bitte um Hilfe @themitch666 Zitat:
|
09.09.2005, 21:21 | #53 | |
| System kompromittiert? Bitte um Hilfe Hi, leere den Quarantäneordner vom Norton lösche die Logdatei vom eScan. Boote in den abgesicherten Modus und führe den escan nochmal aus und poste dann das Ergebnis Vergesse aber bei dem ganzen nicht die Zeilen von Yopie Zitat:
|
10.09.2005, 18:15 | #54 |
| System kompromittiert? Bitte um Hilfe Sat Sep 10 18:43:36 2005 => ***** Scanning complete. ***** Sat Sep 10 18:43:36 2005 => Total Objects Scanned: 126354 Sat Sep 10 18:43:37 2005 => Total Virus(es) Found: 2 Sat Sep 10 18:43:37 2005 => Total Disinfected Files: 0 Sat Sep 10 18:43:37 2005 => Total Files Renamed: 0 Sat Sep 10 18:43:37 2005 => Total Deleted Objects: 0 Sat Sep 10 18:43:37 2005 => Total Errors: 181 Sat Sep 10 18:43:37 2005 => Time Elapsed: 01:07:58 Sat Sep 10 18:43:37 2005 => Virus Database Date: 2005/09/07 Sat Sep 10 18:43:37 2005 => Virus Database Count: 148193 Sat Sep 10 18:43:37 2005 => Scan Completed. Sat Sep 10 19:07:01 2005 => Total Objects Scanned: 126354 Sat Sep 10 19:07:01 2005 => Total Virus(es) Found: 2 Sat Sep 10 19:07:01 2005 => Total Disinfected Files: 0 Sat Sep 10 19:07:01 2005 => Total Files Renamed: 0 Sat Sep 10 19:07:01 2005 => Total Deleted Objects: 0 Sat Sep 10 19:07:01 2005 => Total Errors: 181 Sat Sep 10 19:07:01 2005 => Time Elapsed: 01:07:58 Sat Sep 10 19:07:02 2005 => AV Library Unloaded (3)... das ist die neue statistik nachdem ich den norton quaraty ordner gelöscht habe!!! |
11.09.2005, 18:23 | #55 |
| System kompromittiert? Bitte um Hilfe Hallo, also ich glaube mein System ist soweit wieder in Ordnung, hab hier mal ein HijackThis log File, dachte vielleicht bringt`s was euch das mal zu zeigen: Logfile of HijackThis v1.99.1 Scan saved at 19:19:59, on 11.09.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe C:\Programme\Norton Internet Security\ISSVC.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\SPBBCSvc.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE D:\Programme\AVPersonal\AVGUARD.EXE D:\Programme\AVPersonal\AVWUPSRV.EXE C:\Programme\Norton Internet Security\Norton AntiVirus\navapsvc.exe C:\WINDOWS\System32\nvsvc32.exe C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\svchost.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe C:\Programme\Winamp\winampa.exe C:\Programme\iTunes\iTunesHelper.exe C:\Programme\QuickTime\qttask.exe C:\WINDOWS\system32\rundll32.exe C:\Programme\iPod\bin\iPodService.exe C:\Programme\Java\j2re1.4.2_06\bin\jusched.exe C:\Programme\Lexmark X1100 Series\lxbkbmgr.exe C:\Programme\Lexmark X1100 Series\lxbkbmon.exe C:\Programme\SlySoft\AnyDVD\AnyDVD.exe C:\Programme\Elaborate Bytes\CloneCD\CloneCDTray.exe C:\Programme\D-Tools\daemon.exe C:\Programme\PopUp Killer\popupkiller.EXE D:\Programme\AVPersonal\AVGNT.EXE C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe C:\WINDOWS\system32\ctfmon.exe C:\Programme\Messenger\msmsgs.exe C:\Programme\Spybot - Search & Destroy\TeaTimer.exe C:\Dokumente und Einstellungen\Michael Prax\Eigene Dateien\HijackThis.exe O2 - BHO: Norton Internet Security - {9ECB9560-04F9-4bbc-943D-298DDF1699E1} - C:\Programme\Gemeinsame Dateien\Symantec Shared\AdBlocking\NISShExt.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton Internet Security\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Norton Internet Security - {0B53EAC3-8D69-4b9e-9B19-A37C9A5676A7} - C:\Programme\Gemeinsame Dateien\Symantec Shared\AdBlocking\NISShExt.dll O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton Internet Security\Norton AntiVirus\NavShExt.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKLM\..\Run: [iTunesHelper] C:\Programme\iTunes\iTunesHelper.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_06\bin\jusched.exe O4 - HKLM\..\Run: [Lexmark X1100 Series] "C:\Programme\Lexmark X1100 Series\lxbkbmgr.exe" O4 - HKLM\..\Run: [UpdateManager] "C:\Programme\Gemeinsame Dateien\Sonic\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programme\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon O4 - HKLM\..\Run: [AnyDVD] C:\Programme\SlySoft\AnyDVD\AnyDVD.exe O4 - HKLM\..\Run: [CloneCDTray] C:\Programme\Elaborate Bytes\CloneCD\CloneCDTray.exe O4 - HKLM\..\Run: [ElbyCheckElbyCDFL] "C:\Programme\Elaborate Bytes\CloneCD\ElbyCheck.exe" /L ElbyCDFL O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Programme\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [PopUpKiller] C:\Programme\PopUp Killer\popupkiller.EXE O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [AVGCtrl] D:\Programme\AVPersonal\AVGNT.EXE /min O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe O8 - Extra context menu item: Easy-WebPrint - Drucken - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint - Vorschau - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\System32\msjava.dll O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra button: Klicke hier um das Projekt xp-AntiSpy zu unterstützen - {F3A6BA13-FB48-452F-B14D-C3877A607AF5} - C:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU) O9 - Extra 'Tools' menuitem: Unterstützung für xp-AntiSpy - {F3A6BA13-FB48-452F-B14D-C3877A607AF5} - C:\Programme\xp-AntiSpy\sponsoring\sponsor.html (HKCU) O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) http://www.kaspersky.com/downloads/k...an_unicode.cab O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) -www-secure.symantec.com/techsupp/asa/LSSupCtl.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-24.cab O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) http://www.pandasoftware.com/actives...ree/asinst.cab O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - www-secure.symantec.com/techsupp/asa/SymAData.cab O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - D:\Programme\AVPersonal\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - D:\Programme\AVPersonal\AVWUPSRV.EXE O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe O23 - Service: ISSvc (ISSVC) - Symantec Corporation - C:\Programme\Norton Internet Security\ISSVC.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: Norton AntiVirus Auto-Protect-Dienst (navapsvc) - Symantec Corporation - C:\Programme\Norton Internet Security\Norton AntiVirus\navapsvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SAVScan - Symantec Corporation - C:\Programme\Norton Internet Security\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec SPBBCSvc (SPBBCSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SPBBC\SPBBCSvc.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe O23 - Service: Symantec Core LC - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-LC\symlcsvc.exe O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe |
13.09.2005, 16:57 | #56 |
| System kompromittiert? Bitte um Hilfe ....schaut sich niemand mehr mein log file an??? |
13.09.2005, 17:11 | #57 |
| System kompromittiert? Bitte um Hilfe Hallo@themitch666 Das Log ist in Ordnung
__________________ MfG Sabina |
13.09.2005, 19:52 | #58 | |
| System kompromittiert? Bitte um Hilfe Hi, das Log ist in Ordnung, aber was ist das: Zitat:
cacatoa
__________________ Der Mensch sollte eine Hundeseele haben |
13.09.2005, 22:32 | #59 |
| System kompromittiert? Bitte um Hilfe Hallo@cacatoa das musst du schon den User fragen. Das LOG ist sauber.Vielleicht erbarmt er sich unser und schickt endlich mal den Scanreport vom escan, mit den Pfadangaben. Eine Glaskugel habe ich leider nicht......
__________________ MfG Sabina |
14.09.2005, 08:14 | #60 |
| System kompromittiert? Bitte um Hilfe @ Sabina: die Frage war doch nicht an Dich gerichtet sondern an themitch666 cacatoa
__________________ Der Mensch sollte eine Hundeseele haben |
Themen zu System kompromittiert? Bitte um Hilfe |
antivirus, bitte um hilfe, canon, computer, dll, drivers, explorer, file, hijack, hijackthis, hijackthis log, internet, internet explorer, internet security, log, log file, monitor, neu, nvidia, popup, programme, rundll, security, security center, settings manager, software, symantec, system, temp, windows, windows xp |