|
Log-Analyse und Auswertung: Bitte Logfile überprüfenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
03.10.2005, 23:58 | #1 |
| Bitte Logfile überprüfen Hallo zusammen. Kann mir jemand meien logfile überprüfen? Ich komme damit nicht klar. Ich habe den win32.nsag.b auf dem rechner und kriege ihn nicht runter. Hier ist mein logfile: Logfile of HijackThis v1.99.1 Scan saved at 00:15:42, on 04.10.2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\Programme\AVPersonal\AVGUARD.EXE C:\WINDOWS\System32\Ati2evxx.exe C:\Programme\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\SYSTEM32\GEARSEC.EXE C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\snmp.exe C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\System32\atiptaxx.exe C:\WINDOWS\System32\LXSUPMON.EXE C:\WINDOWS\System32\rmctrl.exe C:\PROGRA~1\TCMMOU~1\MouseDrv.exe C:\PROGRA~1\GEMEIN~1\PCSuite\DATALA~1\DATALA~1.EXE C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE C:\Programme\Winamp\winampa.exe C:\Programme\Siemens\Gigaset USB Adapter 54\PRISMSVR.EXE C:\Programme\AVPersonal\AVGNT.EXE C:\WINDOWS\System32\ctfmon.exe C:\Programme\WinZip\WZQKPICK.EXE C:\Programme\Siemens\Gigaset USB Adapter 54\GigasetUSBMonitor.exe C:\PROGRA~1\GEMEIN~1\PCSuite\Services\SERVIC~1.EXE C:\Programme\Internet Explorer\iexplore.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\explorer.exe C:\Jan\Downloads\Progs\hijackthis_199\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe O4 - HKLM\..\Run: [VOBID] C:\Programme\DVD Movie Copy\InstantDrive\InstantDrive.exe /remount O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe O4 - HKLM\..\Run: [TCMKeyboard ] C:\PROGRA~1\TCMMOU~1\PS2USBKBDDrv.exe O4 - HKLM\..\Run: [TCMMouse ] C:\PROGRA~1\TCMMOU~1\MouseDrv.exe O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\GEMEIN~1\PCSuite\DATALA~1\DATALA~1.EXE O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Programme\Siemens\Gigaset USB Adapter 54\PRISMSVR.EXE" /APPLY O4 - HKLM\..\Run: [KAVPersonal50] "C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programme\WinZip\WZQKPICK.EXE O4 - Global Startup: Gigaset WLAN Adapter Monitor.lnk = C:\Programme\Siemens\Gigaset USB Adapter 54\GigasetUSBMonitor.exe O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file) O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\SYSTEM32\GEARSEC.EXE O23 - Service: kavsvc - Kaspersky Lab - C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe |
04.10.2005, 00:28 | #2 |
| Bitte Logfile überprüfen Zunächst einmal was grundsätzliches:
__________________Bei dir fehlen jegliche Windowsupdates, da ist es kein Wunder, dass du dir was einfängst.Service Pack 2 ist mitlerweile aktuell. Da ist es kein Wunder, dass du dir was einfängst. Da helfen dir auch keine 2 gleichzeitig laufenden AV-Programme. Entscheide dich für Antivir oder für Kaspersky. Arbeite zunächst folgendes ab: http://www.trojaner-board.de/showthread.php?t=21709 Melde dich mit allen geforderten Logs zurück.
__________________ |
04.10.2005, 10:25 | #3 |
| Bitte Logfile überprüfen Hallo cronos.
__________________Erstmal danke für deine anleitung. Ich habe deine anleitung bis auf das windows update gemacht. Muß ich jetzt den ganzen escan log hier posten oder finde ich den virus log auch einzeln? Hier ist schonmal mein smitrem log und mein neuer hijack log. smitRem log file version 2.5 by noahdfear ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Pre-run Files Present ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Post-run Files Present ~~~ Program Files ~~~ ~~~ Shortcuts ~~~ ~~~ Favorites ~~~ ~~~ system32 folder ~~~ ~~~ Icons in System32 ~~~ ~~~ Windows directory ~~~ ~~~ Drive root ~~~ ~~~ Miscellaneous Files/folders ~~~ ~~~ Wininet.dll ~~~ CLEAN! Logfile of HijackThis v1.99.1 Scan saved at 11:44:24, on 04.10.2005 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\LEXBCES.EXE C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\LEXPPS.EXE C:\WINDOWS\System32\Ati2evxx.exe C:\WINDOWS\SYSTEM32\GEARSEC.EXE C:\WINDOWS\system32\slserv.exe C:\WINDOWS\System32\snmp.exe C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\atiptaxx.exe C:\WINDOWS\System32\LXSUPMON.EXE C:\WINDOWS\System32\rmctrl.exe C:\PROGRA~1\TCMMOU~1\MouseDrv.exe C:\PROGRA~1\GEMEIN~1\PCSuite\DATALA~1\DATALA~1.EXE C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE C:\Programme\Winamp\winampa.exe C:\Programme\Siemens\Gigaset USB Adapter 54\PRISMSVR.EXE C:\WINDOWS\System32\ctfmon.exe C:\Programme\WinZip\WZQKPICK.EXE C:\Programme\Siemens\Gigaset USB Adapter 54\GigasetUSBMonitor.exe C:\PROGRA~1\GEMEIN~1\PCSuite\Services\SERVIC~1.EXE C:\Programme\Internet Explorer\iexplore.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Jan\Downloads\Progs\hijackthis_199\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file) O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe O4 - HKLM\..\Run: [VOBID] C:\Programme\DVD Movie Copy\InstantDrive\InstantDrive.exe /remount O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe O4 - HKLM\..\Run: [TCMKeyboard ] C:\PROGRA~1\TCMMOU~1\PS2USBKBDDrv.exe O4 - HKLM\..\Run: [TCMMouse ] C:\PROGRA~1\TCMMOU~1\MouseDrv.exe O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\GEMEIN~1\PCSuite\DATALA~1\DATALA~1.EXE O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Programme\Siemens\Gigaset USB Adapter 54\PRISMSVR.EXE" /APPLY O4 - HKLM\..\Run: [KAVPersonal50] "C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programme\WinZip\WZQKPICK.EXE O4 - Global Startup: Gigaset WLAN Adapter Monitor.lnk = C:\Programme\Siemens\Gigaset USB Adapter 54\GigasetUSBMonitor.exe O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file) O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file) O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\SYSTEM32\GEARSEC.EXE O23 - Service: kavsvc - Kaspersky Lab - C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe Geändert von Stocki80 (04.10.2005 um 10:56 Uhr) |
04.10.2005, 12:18 | #4 |
| Bitte Logfile überprüfen Hier ist mein escan virus found log. Tue Oct 04 10:23:14 2005 => System found infected with flashget Spyware/Adware ({e0e899ab-f487-11d5-8d29-0050ba6940e3})! Action taken: No Action Taken. Tue Oct 04 10:23:14 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Tue Oct 04 10:23:14 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Tue Oct 04 10:23:14 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Tue Oct 04 10:23:18 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Eigene Dateien\stronghold 2\config.dat Tue Oct 04 10:23:18 2005 => System found infected with startsurfing Spyware/Adware (config.dat)! Action taken: No Action Taken. Tue Oct 04 10:23:18 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Eigene Dateien\stronghold 2\config.dat Tue Oct 04 10:23:18 2005 => System found infected with startsurfing Spyware/Adware (config.dat)! Action taken: No Action Taken. Tue Oct 04 10:23:19 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\idvmif3e\common[1].js Tue Oct 04 10:23:19 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Tue Oct 04 10:23:19 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\jh193emv\common[1].js Tue Oct 04 10:23:19 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Tue Oct 04 10:23:19 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\6vihi1mx\common[1].js Tue Oct 04 10:23:19 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Tue Oct 04 10:23:19 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\6vihi1mx\blank[1].htm Tue Oct 04 10:23:19 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:19 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\67pl1n2m\common[1].js Tue Oct 04 10:23:19 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\056rkxan\ads[1].htm Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\056rkxan\ads[2].htm Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\o9mfcd67\ads[1].htm Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\o9mfcd67\ads[2].htm Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\q3urul6z\ads[1].htm Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\i98jm1i5\show_ads[2].js Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (show_ads[2].js)! Action taken: No Action Taken. Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\i98jm1i5\ads[1].htm Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\kjtnqi31\ads[2].htm Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\kjtnqi31\ads[1].htm Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\idvmif3e\common[1].js Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\jh193emv\common[1].js Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\6vihi1mx\common[1].js Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\6vihi1mx\blank[1].htm Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\67pl1n2m\common[1].js Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\056rkxan\ads[1].htm Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\056rkxan\ads[2].htm Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\o9mfcd67\ads[1].htm Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\o9mfcd67\ads[2].htm Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\q3urul6z\ads[1].htm Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\i98jm1i5\show_ads[2].js Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (show_ads[2].js)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\i98jm1i5\ads[1].htm Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\kjtnqi31\ads[2].htm Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\kjtnqi31\ads[1].htm Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Tue Oct 04 10:23:22 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Eigene Dateien\stronghold 2\config.dat Tue Oct 04 10:23:22 2005 => System found infected with startsurfing Spyware/Adware (config.dat)! Action taken: No Action Taken. Tue Oct 04 10:23:22 2005 => Offending file found: C:\WINDOWS\iun6002.exe Tue Oct 04 10:23:22 2005 => System found infected with zipitpro Spyware/Adware (C:\WINDOWS\iun6002.exe)! Action taken: No Action Taken. Tue Oct 04 11:04:39 2005 => File C:\System Volume Information\_restore{FE8CEDBF-F2C1-4799-A000-289B08C42FFA}\RP287\A0045638.DLL infected by "Virus.Win32.Nsag.b" Virus! Action Taken: No Action Taken. |
05.10.2005, 21:50 | #5 |
| Bitte Logfile überprüfen ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue Oct 04 23:21:03 2005 => System found infected with flashget Spyware/Adware ({e0e899ab-f487-11d5-8d29-0050ba6940e3})! Action taken: No Action Taken. Tue Oct 04 23:21:03 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Tue Oct 04 23:21:03 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Tue Oct 04 23:21:04 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken. Tue Oct 04 23:21:07 2005 => System found infected with startsurfing Spyware/Adware (config.dat)! Action taken: No Action Taken. Tue Oct 04 23:21:08 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Tue Oct 04 23:21:08 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Tue Oct 04 23:21:09 2005 => System found infected with startsurfing Spyware/Adware (config.dat)! Action taken: No Action Taken. Tue Oct 04 23:21:09 2005 => System found infected with zipitpro Spyware/Adware (C:\WINDOWS\iun6002.exe)! Action taken: No Action Taken. Tue Oct 04 23:32:30 2005 => Scanning File C:\Jan\infected.doc Tue Oct 04 23:42:32 2005 => Scanning File C:\Dokumente und Einstellungen\My PC\Anwendungsdaten\Microsoft\Office\Zuletzt verwendet\infected.LNK Tue Oct 04 23:42:40 2005 => Scanning File C:\Dokumente und Einstellungen\My PC\Recent\infected.lnk Tue Oct 04 23:51:56 2005 => Scanning File C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal\Infected.wav Wed Oct 05 00:01:12 2005 => File C:\System Volume Information\_restore{FE8CEDBF-F2C1-4799-A000-289B08C42FFA}\RP287\A0045638.DLL infected by "Virus.Win32.Nsag.b" Virus! Action Taken: No Action Taken. Wed Oct 05 00:10:57 2005 => Total Disinfected Files: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "offending" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue Oct 04 23:21:04 2005 => Offending Key found: HKCU\Software\gnu !!! Tue Oct 04 23:21:07 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Eigene Dateien\stronghold 2\config.dat Tue Oct 04 23:21:08 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\q3urul6z\blank[1].htm Tue Oct 04 23:21:08 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\q3urul6z\blank[1].htm Tue Oct 04 23:21:09 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Eigene Dateien\stronghold 2\config.dat Tue Oct 04 23:21:09 2005 => Offending file found: C:\WINDOWS\iun6002.exe ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Wed Oct 05 00:10:57 2005 => Total Virus(es) Found: 11 Wed Oct 05 00:10:57 2005 => Total Errors: 199 Wed Oct 05 00:10:57 2005 => Time Elapsed: 00:50:18 Wed Oct 05 00:10:57 2005 => Total Objects Scanned: 85560 Wed Oct 05 00:10:57 2005 => Virus Database Date: 2005/10/04 Wed Oct 05 06:44:00 2005 => Virus Database Date: 2005/10/04 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~ © Haui ;-) ~~~~~~~ ~~~~~~~ Dank an Cidre ~~~~~~~ |
Themen zu Bitte Logfile überprüfen |
adapter, adobe, antivir, bho, explorer, hijack, hijackthis, hotkey, icq, icqtoolbar, internet, internet explorer, kaspersky, logfile, messenger, microsoft, programme, server, software, system, system32, update, urlsearchhook, usb, windows, windows xp, wlan |