|
Log-Analyse und Auswertung: bitte mal anschauenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
17.10.2005, 22:31 | #1 |
| bitte mal anschauen Hallo!! mein Computer ist total lahm geworden und der AntiVir meldet die ganze Zeit Viren, die dann aber nicht weggehen... Bitte, kann da mal jemand drüber gucken und bescheid sagen, wie groß das Dilemma ist und wie ich alles wieder weg krieg... Danke schonmal!! hier kommt mein EScan-Log: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Sun Oct 16 17:40:30 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 17:40:31 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 17:40:31 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 17:40:31 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 17:40:31 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 17:40:31 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 17:40:31 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 17:40:31 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 18:05:23 2005 => Total Disinfected Files: 0 Sun Oct 16 18:18:07 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 18:18:08 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 18:18:08 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 18:18:08 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 18:18:09 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 18:18:09 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 18:18:09 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 18:18:09 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sun Oct 16 18:21:54 2005 => Scanning Folder: E:\Programme\AVPersonal\INFECTED\*.* Sun Oct 16 19:47:24 2005 => File E:\WINDOWS\system32\o infected by "Trojan-Downloader.BAT.Ftp.ai" Virus! Action Taken: No Action Taken. Sun Oct 16 19:57:39 2005 => Total Disinfected Files: 0 Mon Oct 17 10:52:24 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Mon Oct 17 10:52:25 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Mon Oct 17 10:52:25 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Mon Oct 17 10:52:25 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Mon Oct 17 10:52:26 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Mon Oct 17 10:52:26 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Mon Oct 17 10:52:26 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Mon Oct 17 10:52:26 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Mon Oct 17 11:05:16 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001603.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:16 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001604.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:16 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001605.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:16 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001606.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:16 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001607.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:17 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001608.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:18 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001609.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:18 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001610.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:18 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001611.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:18 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001612.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:18 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001613.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:18 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001614.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:19 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001615.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:19 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001616.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:19 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001617.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:19 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001618.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:05:20 2005 => File D:\System Volume Information\_restore{A3AE8538-7568-42E3-A161-E99EB2047E98}\RP11\A0001619.exe infected by "Virus.Win32.Parite.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:10:36 2005 => Scanning Folder: E:\Programme\AVPersonal\INFECTED\*.* Mon Oct 17 11:10:36 2005 => Scanning File E:\Programme\AVPersonal\INFECTED\TFTP1188.VIR Mon Oct 17 11:10:36 2005 => File E:\Programme\AVPersonal\INFECTED\TFTP1188.VIR infected by "Backdoor.Win32.PoeBot.b" Virus! Action Taken: No Action Taken. Mon Oct 17 11:32:30 2005 => File E:\WINDOWS\system32\o infected by "Trojan-Downloader.BAT.Ftp.ai" Virus! Action Taken: No Action Taken. Mon Oct 17 11:34:17 2005 => Total Disinfected Files: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Sun Oct 16 19:56:43 2005 => File E:\WINDOWS\szqmtfk.exe tagged as "not-a-virus:AdWare.Win32.BetterInternet.s". Action Taken: No Action Taken. Mon Oct 17 11:34:05 2005 => File E:\WINDOWS\szqmtfk.exe tagged as "not-a-virus:AdWare.Win32.BetterInternet.s". Action Taken: No Action Taken. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "offending" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Sun Oct 16 17:40:30 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\temporary internet files\content.ie5\23ofun4x\common[1].js Sun Oct 16 17:40:31 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\temporary internet files\content.ie5\w34pohor\common[1].js Sun Oct 16 17:40:31 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\temporary internet files\content.ie5\w5238fcb\common[1].js Sun Oct 16 17:40:31 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\temporary internet files\content.ie5\wbyvg5yh\common[1].js Sun Oct 16 17:40:31 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\content.ie5\23ofun4x\common[1].js Sun Oct 16 17:40:31 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\content.ie5\w34pohor\common[1].js Sun Oct 16 17:40:31 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\content.ie5\w5238fcb\common[1].js Sun Oct 16 17:40:31 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\content.ie5\wbyvg5yh\common[1].js Sun Oct 16 18:18:07 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\temporary internet files\content.ie5\23ofun4x\common[1].js Sun Oct 16 18:18:08 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\temporary internet files\content.ie5\w34pohor\common[1].js Sun Oct 16 18:18:08 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\temporary internet files\content.ie5\w5238fcb\common[1].js Sun Oct 16 18:18:08 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\temporary internet files\content.ie5\wbyvg5yh\common[1].js Sun Oct 16 18:18:09 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\content.ie5\23ofun4x\common[1].js Sun Oct 16 18:18:09 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\content.ie5\w34pohor\common[1].js Sun Oct 16 18:18:09 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\content.ie5\w5238fcb\common[1].js Sun Oct 16 18:18:09 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\content.ie5\wbyvg5yh\common[1].js Mon Oct 17 10:52:24 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\temporary internet files\content.ie5\23ofun4x\common[1].js Mon Oct 17 10:52:25 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\temporary internet files\content.ie5\w34pohor\common[1].js Mon Oct 17 10:52:25 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\temporary internet files\content.ie5\w5238fcb\common[1].js Mon Oct 17 10:52:25 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\temporary internet files\content.ie5\wbyvg5yh\common[1].js Mon Oct 17 10:52:26 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\content.ie5\23ofun4x\common[1].js Mon Oct 17 10:52:26 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\content.ie5\w34pohor\common[1].js Mon Oct 17 10:52:26 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\content.ie5\w5238fcb\common[1].js Mon Oct 17 10:52:26 2005 => Offending file found: E:\Dokumente und Einstellungen\***\Lokale Einstellungen\Temporary Internet Files\content.ie5\wbyvg5yh\common[1].js ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Sun Oct 16 18:05:23 2005 => Total Virus(es) Found: 8 Sun Oct 16 19:57:39 2005 => Total Virus(es) Found: 10 Mon Oct 17 11:34:17 2005 => Total Virus(es) Found: 28 Sun Oct 16 18:05:23 2005 => Total Errors: 17 Sun Oct 16 19:57:39 2005 => Total Errors: 24 Mon Oct 17 11:34:17 2005 => Total Errors: 26 Sun Oct 16 18:05:23 2005 => Time Elapsed: 00:25:50 Sun Oct 16 19:57:39 2005 => Time Elapsed: 01:40:29 Mon Oct 17 11:34:17 2005 => Time Elapsed: 00:42:39 Sun Oct 16 18:05:23 2005 => Total Objects Scanned: 21423 Sun Oct 16 19:57:39 2005 => Total Objects Scanned: 38374 Mon Oct 17 11:34:17 2005 => Total Objects Scanned: 46014 Sun Oct 16 17:39:05 2005 => Virus Database Date: 2005/10/08 Sun Oct 16 18:05:23 2005 => Virus Database Date: 2005/10/08 Sun Oct 16 18:05:34 2005 => Virus Database Date: 2005/10/08 Sun Oct 16 18:16:55 2005 => Virus Database Date: 2005/10/08 Sun Oct 16 19:57:39 2005 => Virus Database Date: 2005/10/08 Sun Oct 16 22:33:56 2005 => Virus Database Date: 2005/10/08 Mon Oct 17 10:51:25 2005 => Virus Database Date: 2005/10/17 Mon Oct 17 11:34:17 2005 => Virus Database Date: 2005/10/17 Mon Oct 17 21:33:36 2005 => Virus Database Date: 2005/10/17 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~ © Haui ;-) ~~~~~~~ ~~~~~~~ Dank an Cidre ~~~~~~~ |
17.10.2005, 22:53 | #2 |
Administrator, a.D. | bitte mal anschauen Hallo,
__________________aus dem geposteten Log kann man leider nicht mehr entnehmen, was eventuell schon bereinigt wurde oder derzeit noch aktiv ist. Lösche zunächst die alte Datei 'mwav.log' und führe einen erneuten Scan mit eScan durch. Anschließend postest du uns nochmals die Virus Log Information (Find.bat).
__________________ |
Themen zu bitte mal anschauen |
1.exe, antivir, antivir meldet, computer, content.ie5, einstellungen, files, found, infected, information, lahm, lokale, melde, meldet, not-a-virus, programme, scanning, schonmal, system, system volume information, system32, temporary, total, viren, virus, wieder weg, windows, _restore |