|
Log-Analyse und Auswertung: hiJack Log (pls help,TR/Swizzor.GF)Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
19.11.2005, 13:20 | #1 |
| hiJack Log (pls help,TR/Swizzor.GF) hallo liebe comm! Poste hier ein Log von einem Verwanten, dessen Antivir heut morgen die meldung gab ein Trojanisches Pferd namens TR/Swizzor.GF gefunden zu haben! Hier der Log: Logfile of HijackThis v1.99.1 Scan saved at 1:11:27 PM, on 11/19/2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRAMME\AVPERSONAL\AVGUARD.EXE C:\Programme\AVPersonal\AVWUPSRV.EXE C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\Explorer.EXE C:\Programme\AVPersonal\AVGNT.EXE C:\Program Files\D-Tools\daemon.exe C:\WINDOWS\SOUNDMAN.EXE C:\Program Files\QuickTime\qttask.exe C:\Program Files\Logitech\Video\LogiTray.exe C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe C:\Program Files\MessengerPlus! 3\MsgPlus.exe C:\Programme\Winamp\winampa.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\Messenger\msmsgs.exe C:\Program Files\MSN Messenger\MsnMsgr.Exe C:\Program Files\Internet Explorer\iexplore.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe c:\progra~1\intern~1\iexplore.exe C:\WINDOWS\system32\LVComsX.exe C:\Program Files\Logitech\Video\FxSvr2.exe C:\WINDOWS\system32\wscntfy.exe C:\WINDOWS\system32\wuauclt.exe C:\Program Files\Mozilla Firefox\firefox.exe C:\Program Files\X-Chat 2\xchat.exe C:\Documents and Settings\xxx\Desktop\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = h**p://w*w.yfulqrxdhbbmbkcb.com/sHQrfoh7YioVNABiE9Jm9b/30fg3HgfXoGWKmrd9_geMbWfbSV0S/XH2m//mT6lM.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*h**p://w*w.yahoo.com R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://w*w.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://w*w.yahoo.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*h**p://w*w.yahoo.com R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = h**p://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*h**p://w*w.yahoo.com/ext/search/search.html R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://us.rd.yahoo.com/customize/ie/defaults/sp/msgr7/*h**p://w*w.yahoo.com R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://w*w.yahoo.com/ R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = h**p://us.rd.yahoo.com/customize/ie/defaults/su/msgr7/*h**p://w*w.yahoo.com O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll O2 - BHO: UberButton Class - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O2 - BHO: YahooTaggedBM Class - {65D886A2-7CA7-479B-BB95-14D1EFB7946A} - C:\Program Files\Yahoo!\Common\YIeTagBm.dll O2 - BHO: (no name) - {EA5DB5F3-1C66-0D5B-2AB5-9B88808E6565} - C:\DOCUME~1\xxx\APPLIC~1\flagcast\heck aim.exe (file missing) O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min O4 - HKLM\..\Run: [DAEMON Tools-1033] "C:\Program Files\D-Tools\daemon.exe" -lang 1033 O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_04\bin\jusched.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [MessengerPlus3] "C:\Program Files\MessengerPlus! 3\MsgPlus.exe" O4 - HKLM\..\Run: [Acereadmeroadchin] C:\Documents and Settings\All Users\Application Data\Cdrom Bore Ace Readme\Joy option.exe O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background O4 - HKCU\..\Run: [googletalk] "C:\Program Files\Google\Google Talk\googletalk.exe" /autostart O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\MSN Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [Yahoo! Pager] C:\Program Files\Yahoo!\Messenger\ypager.exe -quiet O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\Run: [onlinesave] C:\DOCUME~1\xxx\APPLIC~1\OPTION~1\GLOBAL FRAG.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE O8 - Extra context menu item: &Yahoo! Search - file:///C:\Program Files\Yahoo!\Common/ycsrch.htm O8 - Extra context menu item: E&xporter vers Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000 O8 - Extra context menu item: Yahoo! &Dictionary - file:///C:\Program Files\Yahoo!\Common/ycdict.htm O8 - Extra context menu item: Yahoo! &Maps - file:///C:\Program Files\Yahoo!\Common/ycmap.htm O8 - Extra context menu item: Yahoo! &SMS - file:///C:\Program Files\Yahoo!\Common/ycsms.htm O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_04\bin\npjpi150_04.dll O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - AppInit_DLLs: MsgPlusLoader.dll O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\PROGRAMME\AVPERSONAL\AVGUARD.EXE O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Program Files\TuneUp Utilities 2004\WinStylerThemeSvc.exe Danke, Charmin |
19.11.2005, 16:12 | #2 | ||
| hiJack Log (pls help,TR/Swizzor.GF) @Charmin
__________________Zitat:
Zitat:
Mach bitte noch Folgendes: 1.Systemwiederherstellung abschalten 2. Dieses Bereinigungsprogramm hilft dir, den ganzen Müll aus den Temp-Ordner und Papierkorb zu entfernen. 3. Infected-Ordner des Antivirus-Programms, ggf. auch von Spybot Search & Destroy, Ad-Aware usw. leeren. Der Name des Ordners sowie Pfad sind Programm- und Benutzerabhängig. Bitte RTFM zum AV-Programm. Bei einigen Programmen (z. B. AVPE) ist diese Option nicht im Programm integriert. In dem Fall soll dies manuell erfolgen. 4. eScan genau nach Anleitung (bitte ausdrucken und aufmerksam lesen) im abgesicherten Modus laufen lassen. Log hier Posten. |
19.11.2005, 19:14 | #3 |
| hiJack Log (pls help,TR/Swizzor.GF) hallo,
__________________schritt 1 und 2 habe ich gemacht, dann habe ich den Rechner im abgesicherten Modus gestartet und das System mit eScan gescannt.. Hier ist nun der Log: Sat Nov 19 17:00:32 2005 => ********************************************************** Sat Nov 19 17:00:32 2005 => MicroWorld Anti Virus & Spyware Toolkit Utility. Sat Nov 19 17:00:32 2005 => Copyright © 2003-2005, MicroWorld Technologies Inc. Sat Nov 19 17:00:32 2005 => ********************************************************** Sat Nov 19 17:00:32 2005 => Version 7.2.9 (C:\Bases_X\mwavscan.com) Sat Nov 19 17:00:32 2005 => Log File: C:\Bases_X\MWAV.LOG Sat Nov 19 17:00:32 2005 => MWAV Registered: FALSE. Sat Nov 19 17:00:32 2005 => MWAV Mode: Only Scan files. Sat Nov 19 17:00:35 2005 => Latest Date of files inside MWAV: 17 Nov 2005 09:06:53. Sat Nov 19 17:00:39 2005 => AV Library Loaded... Sat Nov 19 17:00:39 2005 => MWAV doing self scanning... Sat Nov 19 17:00:39 2005 => Scanning File C:\Bases_X\kavss.exe Sat Nov 19 17:00:40 2005 => Scanning File C:\Bases_X\Getvlist.exe Sat Nov 19 17:00:40 2005 => Scanning File C:\Bases_X\kavss.dll Sat Nov 19 17:00:40 2005 => Scanning File C:\Bases_X\kavssdi.dll Sat Nov 19 17:00:40 2005 => Scanning File C:\Bases_X\kavssi.dll Sat Nov 19 17:00:40 2005 => Scanning File C:\Bases_X\kavvlg.dll Sat Nov 19 17:00:40 2005 => Scanning File C:\Bases_X\msvlclnt.dll Sat Nov 19 17:00:40 2005 => Scanning File C:\Bases_X\ipc.dll Sat Nov 19 17:00:40 2005 => Scanning File C:\Bases_X\main.avi Sat Nov 19 17:00:40 2005 => Scanning File C:\Bases_X\virus.avi Sat Nov 19 17:00:40 2005 => MWAV files are clean. Sat Nov 19 17:00:44 2005 => Virus Database Date: 2005/11/17 Sat Nov 19 17:00:44 2005 => Virus Database Count: 160228 Sat Nov 19 17:02:17 2005 => ********************************************************** Sat Nov 19 17:02:17 2005 => MicroWorld Anti Virus & Spyware Toolkit Utility. Sat Nov 19 17:02:17 2005 => Copyright © 2003-2005, MicroWorld Technologies Inc. Sat Nov 19 17:02:17 2005 => Sat Nov 19 17:02:17 2005 => Support: support@mwti.net Sat Nov 19 17:02:17 2005 => Web: http://www.mwti.net Sat Nov 19 17:02:17 2005 => ********************************************************** Sat Nov 19 17:02:17 2005 => Version 7.2.9 (C:\Bases_X\mwavscan.com) Sat Nov 19 17:02:17 2005 => Log File: C:\Bases_X\MWAV.LOG Sat Nov 19 17:02:17 2005 => User Account: xxx Sat Nov 19 17:02:17 2005 => Windows Root Folder: C:\WINDOWS Sat Nov 19 17:02:17 2005 => Windows Sys32 Folder: C:\WINDOWS\system32 Sat Nov 19 17:02:17 2005 => OS: Windows NT Sat Nov 19 17:02:17 2005 => Latest Date of files inside MWAV: 17 Nov 2005 09:06:53. Sat Nov 19 17:02:17 2005 => Options Selected by User: Sat Nov 19 17:02:17 2005 => Memory Check: Enabled Sat Nov 19 17:02:17 2005 => Registry Check: Enabled Sat Nov 19 17:02:17 2005 => StartUp Folder Check: Disabled Sat Nov 19 17:02:17 2005 => System Folder Check: Disabled Sat Nov 19 17:02:17 2005 => System Area Check: Disabled Sat Nov 19 17:02:17 2005 => Services Check: Enabled Sat Nov 19 17:02:17 2005 => Drive Check: Disabled Sat Nov 19 17:02:17 2005 => All Drive Check :Enabled Sat Nov 19 17:02:17 2005 => Folder Check: Disabled Sat Nov 19 17:03:07 2005 => ***** Scanning Registry and File system for Adware/Spyware ***** Sat Nov 19 17:03:07 2005 => Loading Spyware Signatures from new External Database (Size: 145282). Sat Nov 19 17:03:09 2005 => Indexed Spyware Databases Successfully Created... Sat Nov 19 17:04:04 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\temporary internet files\content.ie5\3gmdedm9\common[1].js Sat Nov 19 17:04:04 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sat Nov 19 17:04:33 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\temporary internet files\content.ie5\8hubw5en\common[1].js Sat Nov 19 17:04:33 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sat Nov 19 17:04:38 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\temporary internet files\content.ie5\8hubw5en\global[1].js Sat Nov 19 17:04:38 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Sat Nov 19 17:04:38 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\temporary internet files\content.ie5\8wf2yb6a\common[1].js Sat Nov 19 17:04:38 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sat Nov 19 17:04:59 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\temporary internet files\content.ie5\o2kl2hdt\common[1].js Sat Nov 19 17:04:59 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:04 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\temporary internet files\content.ie5\w56j05ab\blank[1].htm Sat Nov 19 17:05:04 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Sat Nov 19 17:05:04 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\temporary internet files\content.ie5\w56j05ab\common[1].js Sat Nov 19 17:05:04 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:05 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\temporary internet files\content.ie5\w56j05ab\global[1].js Sat Nov 19 17:05:05 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:06 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\temporary internet files\content.ie5\wxqbwhe7\common[1].js Sat Nov 19 17:05:06 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:07 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\temporary internet files\content.ie5\wxqbwhe7\global[1].js Sat Nov 19 17:05:07 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:07 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\Temporary Internet Files\content.ie5\3gmdedm9\common[1].js Sat Nov 19 17:05:07 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:08 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\Temporary Internet Files\content.ie5\8hubw5en\common[1].js Sat Nov 19 17:05:08 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:08 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\Temporary Internet Files\content.ie5\8hubw5en\global[1].js Sat Nov 19 17:05:08 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:08 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\Temporary Internet Files\content.ie5\8wf2yb6a\common[1].js Sat Nov 19 17:05:08 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:08 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\Temporary Internet Files\content.ie5\o2kl2hdt\common[1].js Sat Nov 19 17:05:08 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:08 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\Temporary Internet Files\content.ie5\w56j05ab\blank[1].htm Sat Nov 19 17:05:08 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Sat Nov 19 17:05:08 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\Temporary Internet Files\content.ie5\w56j05ab\common[1].js Sat Nov 19 17:05:08 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:08 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\Temporary Internet Files\content.ie5\w56j05ab\global[1].js Sat Nov 19 17:05:08 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:09 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\Temporary Internet Files\content.ie5\wxqbwhe7\common[1].js Sat Nov 19 17:05:09 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken. Sat Nov 19 17:05:09 2005 => Offending file found: C:\Documents and Settings\xxx\Local Settings\Temporary Internet Files\content.ie5\wxqbwhe7\global[1].js Sat Nov 19 17:05:09 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Sat Nov 19 17:09:01 2005 => Scanning File C:\Documents and Settings\xxx\Application Data\Option The Poll\eiuiaxkm.exe Sat Nov 19 17:09:02 2005 => File C:\Documents and Settings\xxx\Application Data\Option The Poll\eiuiaxkm.exe tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:09:02 2005 => Scanning File C:\Documents and Settings\xxx\Application Data\Option The Poll\GLOBAL FRAG.exe Sat Nov 19 17:09:02 2005 => Scanning File C:\Documents and Settings\xxx\Application Data\Option The Poll\jcrcjzfe.exe Sat Nov 19 17:09:02 2005 => File C:\Documents and Settings\xxx\Application Data\Option The Poll\jcrcjzfe.exe tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:09:02 2005 => Scanning File C:\Documents and Settings\xxx\Application Data\Option The Poll\qsrnurld.exe Sat Nov 19 17:09:02 2005 => File C:\Documents and Settings\xxx\Application Data\Option The Poll\qsrnurld.exe tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:09:02 2005 => Scanning File C:\Documents and Settings\xxx\Application Data\Option The Poll\shtfiecf.exe Sat Nov 19 17:09:02 2005 => File C:\Documents and Settings\xxx\Application Data\Option The Poll\shtfiecf.exe tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:02:50 2005 => File C:\DOCUME~1\ALLUSE~1\APPLIC~1\CDROMB~1\JOYOPT~1.EXE tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:02:53 2005 => File C:\DOCUME~1\xxx\APPLIC~1\OPTION~1\GLOBAL~1.EXE tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:05:54 2005 => File C:\Documents and Settings\All Users\Application Data\Cdrom Bore Ace Readme\flaw mfcd.exe tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:05:54 2005 => File C:\Documents and Settings\All Users\Application Data\Cdrom Bore Ace Readme\Mix live.exe tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:05:54 2005 => Scanning File C:\Documents and Settings\All Users\Application Data\Cdrom Bore Ace Readme\PLUSCOAL.exe Sat Nov 19 17:05:54 2005 => File C:\Documents and Settings\All Users\Application Data\Cdrom Bore Ace Readme\PLUSCOAL.exe tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:09:02 2005 => File C:\Documents and Settings\xxx\Application Data\Option The Poll\eiuiaxkm.exe tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:09:02 2005 => Scanning File C:\Documents and Settings\xxx\Application Data\Option The Poll\GLOBAL FRAG.exe Sat Nov 19 17:09:02 2005 => Scanning File C:\Documents and Settings\xxx\Application Data\Option The Poll\jcrcjzfe.exe Sat Nov 19 17:09:02 2005 => File C:\Documents and Settings\xxx\Application Data\Option The Poll\jcrcjzfe.exe tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:09:02 2005 => Scanning File C:\Documents and Settings\xxx\Application Data\Option The Poll\qsrnurld.exe Sat Nov 19 17:09:02 2005 => File C:\Documents and Settings\xxx\Application Data\Option The Poll\qsrnurld.exe tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:09:02 2005 => Scanning File C:\Documents and Settings\xxx\Application Data\Option The Poll\shtfiecf.exe Sat Nov 19 17:09:02 2005 => File C:\Documents and Settings\xxx\Application Data\Option The Poll\shtfiecf.exe tagged as "not-a-virus:AdWare.Win32.Lop.ag". Action Taken: No Action Taken. Sat Nov 19 17:09:35 2005 => File C:\Documents and Settings\xxx\Desktop\mirc616.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken. Sat Nov 19 17:26:04 2005 => File C:\Program Files\Adverts\uninst.exe tagged as "not-a-virus:AdWare.Win32.Lop.ai". Action Taken: No Action Taken. Sat Nov 19 17:34:39 2005 => File C:\Program Files\mIRC\mirc.exe tagged as not-a-virus:Client-IRC.Win32.mIRC.616. No Action Taken. Sat Nov 19 18:39:00 2005 => ***** Scanning complete. ***** Sat Nov 19 18:39:00 2005 => Total Objects Scanned: 124702 Sat Nov 19 18:39:00 2005 => Total Virus(es) Found: 32 Sat Nov 19 18:39:00 2005 => Total Disinfected Files: 0 Sat Nov 19 18:39:00 2005 => Total Files Renamed: 0 Sat Nov 19 18:39:01 2005 => Total Deleted Objects: 0 Sat Nov 19 18:39:01 2005 => Total Errors: 126 Sat Nov 19 18:39:01 2005 => Time Elapsed: 01:36:04 Sat Nov 19 18:39:01 2005 => Virus Database Date: 2005/11/17 Sat Nov 19 18:39:01 2005 => Virus Database Count: 160228 Sat Nov 19 18:39:01 2005 => Scan Completed. Vielen Dank schonmal, charmin |
19.11.2005, 19:53 | #4 | ||
| hiJack Log (pls help,TR/Swizzor.GF) @Charmin Zitat:
Zitat:
Du musst nochmal mit Clearprog TIF bereinigen und noch Spybot Search & Destroy und AdAware laufen lassen. http://www.safer-networking.org/de/news/index.html http://www.lavasoftusa.com/support/download/ |
19.11.2005, 20:15 | #5 | |
| hiJack Log (pls help,TR/Swizzor.GF)Zitat:
Also nochmal reinigen (diesmal überall häckchen setzen?) und dann mit spy bot und antivir den rechner nochmal durchlaufen lassen? Muss ich mit dem eScan tool nichts mehr machen? Und hat der Log jetzt was gebracht? gruß Charmin |
20.11.2005, 10:24 | #6 | |||
| hiJack Log (pls help,TR/Swizzor.GF) @Charmin Zitat:
Zitat:
Zitat:
|
Themen zu hiJack Log (pls help,TR/Swizzor.GF) |
adobe, antivir, appinit_dlls, application, bho, desktop, excel, explorer, firefox, google, help, hijack, hijackthis, internet, internet explorer, log, microsoft, mozilla, mozilla firefox, msn, nvidia, programme, rundll, software, system, trojanisches pferd, tuneup utilities, windows, windows xp |