|
Plagegeister aller Art und deren Bekämpfung: escan log ???????Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
13.10.2005, 10:09 | #1 |
| escan log ??????? Hallo nachdem mein Hijack log ja gut aussah, hab ich mal escan drüberlaufen lassen und der fand 53 viren?????? Kann das sein??? Schauts euch mal an. Thu Oct 13 09:46:40 2005 => ***** Scanning Registry and File system for Adware/Spyware ***** Thu Oct 13 09:46:40 2005 => Loading Spyware Signatures from new External Database (Size: 145065). Thu Oct 13 09:46:42 2005 => Indexed Spyware Databases Successfully Created... Thu Oct 13 09:50:46 2005 => System found infected with searchexe Spyware/Adware ({807553e5-5146-11d5-a672-00b0d022e945})! Action taken: No Action Taken. Thu Oct 13 09:50:48 2005 => Offending Key found: HKCU\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\powerstrip !!! Thu Oct 13 09:50:48 2005 => Object "powerstrip Spyware/Adware" found in File System! Action Taken: No Action Taken. Thu Oct 13 09:50:48 2005 => Offending Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\powerstrip !!! Thu Oct 13 09:50:48 2005 => Object "powerstrip Spyware/Adware" found in File System! Action Taken: No Action Taken. Thu Oct 13 09:50:52 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Anwendungsdaten\xcpcsync.oem\siemens.smartsync.5.2\data\app.dat Thu Oct 13 09:50:52 2005 => System found infected with clientman Spyware/Adware (app.dat)! Action taken: No Action Taken. Thu Oct 13 09:50:53 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Eigene Dateien\!!!!!!!! achtung download !!!!!!!!!\smartcard1\humax\humax fernbedienung\help\new.gif Thu Oct 13 09:50:53 2005 => System found infected with ezula toptext Spyware/Adware (new.gif)! Action taken: No Action Taken. Thu Oct 13 09:50:56 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Eigene Dateien\smartcard1\humax\humax fernbedienung\help\new.gif Thu Oct 13 09:50:56 2005 => System found infected with ezula toptext Spyware/Adware (new.gif)! Action taken: No Action Taken. Thu Oct 13 09:50:57 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\3bxj3tww\ads[1].htm Thu Oct 13 09:50:57 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:57 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\3bxj3tww\ticker[1].js Thu Oct 13 09:50:57 2005 => System found infected with whenu.savenow Spyware/Adware (ticker[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:57 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\5007lx0p\adsend[1].js Thu Oct 13 09:50:57 2005 => System found infected with whenu.savenow Spyware/Adware (adsend[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:57 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\5z77lx0e\adswrapper[1].js Thu Oct 13 09:50:57 2005 => System found infected with whenu.savenow Spyware/Adware (adswrapper[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:57 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\7ag3v5ox\adswrapper[1].js Thu Oct 13 09:50:57 2005 => System found infected with whenu.savenow Spyware/Adware (adswrapper[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:57 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\7ag3v5ox\ads[1].htm Thu Oct 13 09:50:57 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:57 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\8nt36aj1\ads[1].htm Thu Oct 13 09:50:57 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:57 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\8nt36aj1\ads[2].htm Thu Oct 13 09:50:57 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\8nt36aj1\show_ads[2].js Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (show_ads[2].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\alt6vyt4\ads[1].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\e5zg9cjy\adsend[1].js Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (adsend[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\e5zg9cjy\formie[1].css Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (formie[1].css)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\gb5zuazd\adsend[1].js Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (adsend[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\tf77t1ce\adswrapper[1].js Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (adswrapper[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\tf77t1ce\index[1].html Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (index[1].html)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\tj3jt9ce\ads[1].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\wz7fm8p9\ads[1].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\wz7fm8p9\ads[2].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\wz7fm8p9\global[1].js Thu Oct 13 09:50:58 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\temporary internet files\content.ie5\yjafmxqz\ads[1].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\3bxj3tww\ads[1].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\3bxj3tww\ticker[1].js Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ticker[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\5007lx0p\adsend[1].js Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (adsend[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\5z77lx0e\adswrapper[1].js Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (adswrapper[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\7ag3v5ox\adswrapper[1].js Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (adswrapper[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\7ag3v5ox\ads[1].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\8nt36aj1\ads[1].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\8nt36aj1\ads[2].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\8nt36aj1\show_ads[2].js Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (show_ads[2].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\alt6vyt4\ads[1].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\e5zg9cjy\adsend[1].js Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (adsend[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\e5zg9cjy\formie[1].css Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (formie[1].css)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\gb5zuazd\adsend[1].js Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (adsend[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\tf77t1ce\adswrapper[1].js Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (adswrapper[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\tf77t1ce\index[1].html Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (index[1].html)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\tj3jt9ce\ads[1].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\wz7fm8p9\ads[1].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\wz7fm8p9\ads[2].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\wz7fm8p9\global[1].js Thu Oct 13 09:50:58 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Thu Oct 13 09:50:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Lokale Einstellungen\Temporary Internet Files\content.ie5\yjafmxqz\ads[1].htm Thu Oct 13 09:50:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Thu Oct 13 09:51:00 2005 => Offending file found: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\gtek\gtupdate\aupdate\channels\channels.ini Thu Oct 13 09:51:00 2005 => System found infected with clipgenie Spyware/Adware (channels.ini)! Action taken: No Action Taken. Thu Oct 13 09:51:02 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Eigene Dateien\!!!!!!!! achtung download !!!!!!!!!\smartcard1\humax\humax fernbedienung\help\new.gif Thu Oct 13 09:51:02 2005 => System found infected with ezula toptext Spyware/Adware (new.gif)! Action taken: No Action Taken. Thu Oct 13 09:51:02 2005 => Offending file found: C:\Dokumente und Einstellungen\Mike\Eigene Dateien\smartcard1\humax\humax fernbedienung\help\new.gif Thu Oct 13 09:51:02 2005 => System found infected with ezula toptext Spyware/Adware (new.gif)! Action taken: No Action Taken. Thu Oct 13 09:51:03 2005 => System found infected with cws.therealsearch Spyware/Adware (waol.exe)! Action taken: No Action Taken. Thu Oct 13 09:51:03 2005 => System found infected with cws.therealsearch Spyware/Adware (waol.exe)! Action taken: No Action Taken. |
13.10.2005, 10:16 | #2 |
| escan log ??????? das geht noch weiter
__________________:-( hu Oct 13 09:51:05 2005 => ***** Scanning Registry for errors created because of Adware/Spyware ***** Thu Oct 13 09:51:06 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\DIMM.DLL". Action Taken: No Action Taken. Thu Oct 13 09:51:06 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\QuickTime\QuickTimeEffects.qtx". Action Taken: No Action Taken. Thu Oct 13 09:51:06 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\QuickTime\QuickTimeMusic.qtx". Action Taken: No Action Taken. Thu Oct 13 09:51:06 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\QuickTimeMusicalInstruments.qtx". Action Taken: No Action Taken. Thu Oct 13 09:51:06 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Symantec\LiveUpdate\S32LIVE1.DLL". Action Taken: No Action Taken. Thu Oct 13 09:51:06 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Symantec\LiveUpdate\S32LUIS1.DLL". Action Taken: No Action Taken. Thu Oct 13 09:51:06 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\AOL 8.0\Aol.hlp". Action Taken: No Action Taken. Thu Oct 13 09:51:06 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\AOL 8.0\Aol.cnt". Action Taken: No Action Taken. Thu Oct 13 09:51:06 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "F:\AOL\AOL 8.0a\Aol.hlp". Action Taken: No Action Taken. Thu Oct 13 09:51:06 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "F:\AOL\AOL 8.0a\Aol.cnt". Action Taken: No Action Taken. Thu Oct 13 09:51:06 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\pxwma.dll". Action Taken: No Action Taken. Thu Oct 13 09:51:06 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\CTDetect.cpl". Action Taken: No Action Taken. Thu Oct 13 09:51:07 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\zlib.dll". Action Taken: No Action Taken. Thu Oct 13 09:51:07 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "F:\Mozilla\plugins\NPSWF32.dll". Action Taken: No Action Taken. Thu Oct 13 09:51:07 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Gemeinsame Dateien\Ahead\DSFilter\NeQTVDec.ax". Action Taken: No Action Taken. Thu Oct 13 09:51:07 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Gemeinsame Dateien\Ahead\DSFilter\NeQTADec.ax". Action Taken: No Action Taken. Thu Oct 13 09:51:07 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Ahead\Nero ShowTime\Skins\Icy.bmp". Action Taken: No Action Taken. Thu Oct 13 09:51:07 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Ahead\NeroDigital\settings.xml". Action Taken: No Action Taken. Thu Oct 13 09:51:07 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "I:\doom3\base\game00.pk4". Action Taken: No Action Taken. Thu Oct 13 09:51:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\shutdowncomputer.exe". Action Taken: No Action Taken. Thu Oct 13 09:51:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\WINDOWS\System32\ControlWZCSVC.exe". Action Taken: No Action Taken. Thu Oct 13 09:51:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\Printme\ConsoleApp.exe". Action Taken: No Action Taken. Thu Oct 13 09:51:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\SharedDlls" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\Printme\PMAdobeIndex.url". Action Taken: No Action Taken. Thu Oct 13 09:51:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\ga_main.exe" refers to invalid object "". Action Taken: No Action Taken. Thu Oct 13 09:51:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\LUALL.EXE" refers to invalid object "C:\Programme\Symantec\LiveUpdate\LUALL.EXE". Action Taken: No Action Taken. Thu Oct 13 09:51:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\MediaRack.exe" refers to invalid object "C:\Programme\C-Media 3D Audio\MediaRack.exe". Action Taken: No Action Taken. Thu Oct 13 09:51:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\pbrush.exe" refers to invalid object "%SystemRoot%\system32\mspaint.exe". Action Taken: No Action Taken. Thu Oct 13 09:51:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Paths\setup.exe" refers to invalid object "C:\Programme\ATI Technologies\ATI Control Panel\setup.exe". Action Taken: No Action Taken. Thu Oct 13 09:51:08 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Gemeinsame Dateien\Symantec Shared\Script Blocking\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Microsoft Bootvis\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Dokumente und Einstellungen\Mike\Startmenü\Programme\MSXML 4.0\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Java\j2re1.4.2_01\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\ACD Systems\PlugIns\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\ACD Systems\FotoVac\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "J:\Dvd Maker 6\FileCD\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\ACD Systems\ACDSee\6.0\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\ACD Systems\FotoCanvas\3.0\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\ACD Systems\FotoCanvas\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\McAfee\McAfee VirusScan\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\McAfee\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\McAfee\McAfee VirusScan\Activity Log\". Action Taken: No Action Taken. Thu Oct 13 09:51:09 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\ArtRage\". Action Taken: No Action Taken. Thu Oct 13 09:51:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "I:\doom3\base\". Action Taken: No Action Taken. Thu Oct 13 09:51:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Humax Toolbox\". Action Taken: No Action Taken. Thu Oct 13 09:51:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Logitech QuickCam\". Action Taken: No Action Taken. Thu Oct 13 09:51:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\VDKHome\". Action Taken: No Action Taken. Thu Oct 13 09:51:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\VDKHome\DEU\". Action Taken: No Action Taken. Thu Oct 13 09:51:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\VDKHome\ENU\". Action Taken: No Action Taken. Thu Oct 13 09:51:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\ImageViewer\". Action Taken: No Action Taken. Thu Oct 13 09:51:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\ImageViewer\de_DE\". Action Taken: No Action Taken. Thu Oct 13 09:51:10 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\ImageViewer\en_US\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\Annotations\Stamps\ENU\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\Annotations\Stamps\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\Annotations\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\Annotations\Stamps\DEU\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\Printme\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\Multimedia\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\Multimedia\MPP\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\OLS\Locale\ENU\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\OLS\Locale\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\OLS\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\Howto\images\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\Howto\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\OLS\Locale\DEU\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Programme\Adobe\Acrobat 6.0\Reader\plug_ins\PictureTasks\Templates\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\PrintMe Internet Printing\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "I:\swat4\Content\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "I:\swat4\Content\System\". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".$$$". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".1". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".20004". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".5". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".ave". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".avg". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".avs". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".bak". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".BUP". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".cha". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".CKL". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".cue". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".d2v". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".dlf". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".dop". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".dra". Action Taken: No Action Taken. Thu Oct 13 09:51:11 2005 => Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".DragonPatch". Action Taken: No Action Taken. |
13.10.2005, 11:55 | #3 |
| escan log ??????? nix ????
__________________ |
13.10.2005, 16:19 | #4 |
| escan log ??????? sagt euch das was??? ich hab mit meinem normalen Panda Antivirus Titanium keine einzige meldung hmmmmmmm !!!!! |
13.10.2005, 18:52 | #5 |
Administrator, a.D. | escan log ??????? Hallo, leere das Cache des IE [1] und wende RegSeeker [2] an. [1] Rechtsklick auf IE -> Eigenschaften -> Reiter 'Allgemein' und unter Temporäre Internetdateien -> Dateien löschen -> 'Alle Offlineinhalte löschen' anhaken -> OK [2] Sichern vor Löschen anhaken und nur die grünen Funde entfernen! |
13.10.2005, 18:57 | #6 |
| escan log ??????? DDAANNKKEE nun bin ich beruhigt Gruß Marv |
Themen zu escan log ??????? |
?????, bedienung, content.ie5, dateien, download, einstellungen, escan, explorer, fernbedienung, file, gen, help, hijack, hijack log, infected, internet, log, microsoft, object, registry, software, start, start menu, system, update, viren, viren?, windows |