|
Log-Analyse und Auswertung: TrojanerfarmWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
17.12.2005, 18:42 | #1 |
| Trojanerfarm hallo leute, eine bekannte hat ein problem, dass dauernd internet fenster bei ihr aufgehen und sie ausserdem einige trojaner hatte / hat. ich hab schon einiges geschafft, bin nun aber am ende mit meinem latein...wer kann mir helfen? ich wäre euch für jede idee oder hilfe echt sehr dankbar und meine bekannte sicherlich auch *g* vielleicht kann mir ja jemand sagen was verdächtig ist und was ich löschen soll oder so? Logfile of HijackThis v1.99.1 Scan saved at 18:22:33, on 17.12.2005 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\WINDOWS\system32\rundll32.exe C:\Programme\Symantec AntiVirus\DefWatch.exe C:\WINDOWS\system32\inetsrv\inetinfo.exe C:\WINDOWS\system32\oodag.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Symantec AntiVirus\Rtvscan.exe C:\WINDOWS\system32\Ati2evxx.exe C:\WIN! DOWS\Explorer.EXE C:\Programme\CyberLink\PowerDVD\PDVDServ.exe C:\WINDOWS\system32\taskswitch.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Programme\NVIDIA Corporation\NvMixer\NVMixerTray.exe C:\Programme\HP\HP Software Update\HPWuSchd2.exe C:\Programme\HP\hpcoretech\hpcmpmgr.exe C:\Programme\ICQLite\ICQLite.exe C:\Programme\Java\jre1.5.0_05\bin\jusched.exe C:\Programme\AonInformer\informer.exe C:\Programme\Thomson\SpeedTouch USB\Dragdiag.exe C:\WINDOWS\system32\ctfmon.exe C:\Programme\Skype\Phone\Skype.exe C:\PROGRA~1\GEMEIN~1\urwi\urwim.exe C:\Programme\Spybot - Search & Destroy\TeaTimer.exe C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe C:\Programme\CASIO\Photo Loader\Plauto.exe C:\Programme\RealVNC\VNC4\WinVNC4.exe C:\PROGRA~1\GEMEIN~1\urwi\urwia.exe C:\Programme\HP\Digital Imaging\bin\hpqgalry.exe C:\WINDOWS\system32\wuauclt.exe C:\PROGRA~1\GEMEIN! ~1\urwi\urwil.exe C:\Dokumente und Einstellungen\C:\WINDOWS\Eigene Dateien\ICQ Lite\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://search.Aon.at R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.orf.at/ R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = c:\secure32.html R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = ftp=proxy.aon.at:8080;http=proxy.aon.at:8080 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.aon.at;*.jet2web.net;<local> R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56! -BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar1.dll O3 - Toolbar: eBlocs Security Toolbar - {68FF9E0F-2E96-4467-87FA-1A8B9734C7E7} - C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Anwendungsdaten\ssstbar\sssTbar.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [RemoteControl] C:\Programme\CyberLink\PowerDVD\PDVDServ.exe O4 - HKLM\..\Run: [CoolSwitch] C:\WINDOWS\system32\taskswitch.exe O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [NVMixerTray] "C:\Programme\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [HP Software Update] "C:\Programme\HP\HP Software Update\HPWuSchd2.exe" O4 - HKLM\..\Run: [HP Component Manager] "C:\Programme\HP\hpcoretech\hpcmpmg! r.exe" O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.ex e -minimize O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_05\bin\jusched.exe O4 - HKLM\..\Run: [winsync] C:\WINDOWS\system32\ppioqc.exe reg_run O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe O4 - HKLM\..\Run: [jservice] C:\Programme\AonInformer\informer.exe O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Programme\Thomson\SpeedTouch USB\Dragdiag.exe" /icon O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [urwi] C:\PROGRA~1\GEMEIN~1\urwi\urwim.exe O4 - HKCU\..\Run: [SpyBlocs] C:\Programme\eBlocs\SpyBlocs\GLF9.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programme\HP\Digital Imaging\bin\hpqt! ra08.exe O4 - Global Startup: HP Image Zone Schnellstart.lnk = C:\Programme\HP\Digital Imaging\bin\hpqthb08.exe O4 - Global Startup: Photo Loader resident.lnk = C:\Programme\CASIO\Photo Loader\Plauto.exe O8 - Extra context menu item: &Google Search - res://C:\Programme\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: &Translate English Word - res://C:\Programme\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Programme\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Programme\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Programme\Googl! e\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: T ranslate Page into English - res://C:\Programme\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_05\bin\npjpi150_05.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_05\bin\npjpi150_05.dll O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O17 - HKLM\System\CCS\Services\Tcpip\..\{061638D7-! 707F-4062-8D03-0A563396D8D5}: NameServer = 195.3.96.67 195.3.96.68 O17 - HKLM\System\CS1\Services\Tcpip\..\{061638D7-707F-4062-8D03-0A563396D8D5}: NameServer = 195.3.96.67 195.3.96.68 O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: PCANotify - C:\WINDOWS\SYSTEM32\PCANotify.dll O20 - Winlogon Notify: SMDEn - C:\WINDOWS\system32\r2p8lc7u1f.dll O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe O23 - Service: pcAnywhere Host-Modul (awhost32) - Symantec Corporation - C:\Programme\Symantec\pcAnywhere\awhost32.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programm! e\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe O23 - Service: Sy mantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Programme\Symantec AntiVirus\DefWatch.exe O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Programme\Symantec AntiVirus\SavRoam.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Programme\Symantec AntiVirus\Rtvscan.exe O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: VNC Server Version 4 (WinVNC4) - Unknown owner - C:\Programme\RealVNC\VNC4\WinVN! C4.exe" -service (file missing) Geändert von Mithrandir0000001 (17.12.2005 um 19:07 Uhr) |
18.12.2005, 09:52 | #3 | |
| TrojanerfarmZitat:
meine kristallkugel hat mich geblendet :-) anbei nun die auswertung von escan - schaut nicht gut aus, kann man da ohne format c: noch was richten? wär für jede "analyse" und tipps dankbar wie ich den pc wieder hinbekomme - ohne format c: danke leute! --------------- ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Sun Dec 18 09:22:24 2005 => File C:\WINDOWS\system32\iiousno.dll infected by "Trojan-Downloader.Win32.Qoologic.az" Virus! Action Taken: No Action Taken. Sun Dec 18 09:22:29 2005 => File C:\PROGRA~1\GEMEIN~1\urwi\urwim.exe infected by "Trojan-Downloader.Win32.TSUpdate.n" Virus! Action Taken: No Action Taken. Sun Dec 18 09:22:30 2005 => File C:\PROGRA~1\GEMEIN~1\urwi\urwia.exe infected by "Trojan-Downloader.Win32.TSUpdate.l" Virus! Action Taken: No Action Taken. Sun Dec 18 09:22:39 2005 => File C:\WINDOWS\system32\ppioqc.exe infected by "Trojan-Downloader.Win32.Qoologic.at" Virus! Action Taken: No Action Taken. Sun Dec 18 09:22:40 2005 => File C:\PROGRA~1\GEMEIN~1\urwi\urwim.exe infected by "Trojan-Downloader.Win32.TSUpdate.n" Virus! Action Taken: No Action Taken. Sun Dec 18 09:22:47 2005 => System found infected with searchexe Spyware/Adware ({807553e5-5146-11d5-a672-00b0d022e945})! Action taken: No Action Taken. Sun Dec 18 09:22:48 2005 => System found infected with downloadplus Spyware/Adware (installer.exe)! Action taken: No Action Taken. Sun Dec 18 09:22:48 2005 => System found infected with spywareno!/spysheriff Commercial KeyLogger (winstall.exe)! Action taken: No Action Taken. Sun Dec 18 09:22:48 2005 => System found infected with cws.loadadv.400 Browser Hijacker (tool2.exe)! Action taken: No Action Taken. Sun Dec 18 09:22:48 2005 => System found infected with cws.loadadv.401 Browser Hijacker (tool3.exe)! Action taken: No Action Taken. Sun Dec 18 09:22:48 2005 => System found infected with elite toolbar Spyware/Adware (toolbar.exe)! Action taken: No Action Taken. Sun Dec 18 09:22:48 2005 => System found infected with target saver Spyware/Adware (tsuninst.exe)! Action taken: No Action Taken. Sun Dec 18 09:22:48 2005 => System found infected with redv Spyware/Adware (insthelp.dll)! Action taken: No Action Taken. Sun Dec 18 09:22:51 2005 => System found infected with redv Spyware/Adware (insthelp.dll)! Action taken: No Action Taken. Sun Dec 18 09:22:51 2005 => System found infected with clientman Spyware/Adware (disable.dll)! Action taken: No Action Taken. Sun Dec 18 09:22:51 2005 => System found infected with clientman Spyware/Adware (firstrun.log)! Action taken: No Action Taken. Sun Dec 18 09:22:52 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:22:52 2005 => System found infected with whenu.savenow Spyware/Adware (adsend[1].js)! Action taken: No Action Taken. Sun Dec 18 09:22:52 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Sun Dec 18 09:22:52 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:22:52 2005 => System found infected with whenu.savenow Spyware/Adware (ticker[1].js)! Action taken: No Action Taken. Sun Dec 18 09:22:52 2005 => System found infected with whenu.savenow Spyware/Adware (adswrapper[1].js)! Action taken: No Action Taken. Sun Dec 18 09:22:52 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:22:53 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Sun Dec 18 09:22:58 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:00 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:00 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:00 2005 => System found infected with whenu.savenow Spyware/Adware (formie[1].css)! Action taken: No Action Taken. Sun Dec 18 09:23:00 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Sun Dec 18 09:23:01 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:02 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:04 2005 => System found infected with whenu.savenow Spyware/Adware (adswrapper[1].js)! Action taken: No Action Taken. Sun Dec 18 09:23:05 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:06 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:06 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:06 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:07 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:08 2005 => System found infected with whenu.savenow Spyware/Adware (adsend[1].js)! Action taken: No Action Taken. Sun Dec 18 09:23:08 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:08 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:08 2005 => System found infected with whenu.savenow Spyware/Adware (stylesheet[1].css)! Action taken: No Action Taken. Sun Dec 18 09:23:09 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:09 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Sun Dec 18 09:23:09 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:09 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:09 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:09 2005 => System found infected with whenu.savenow Spyware/Adware (formie[1].css)! Action taken: No Action Taken. Sun Dec 18 09:23:09 2005 => System found infected with redv Spyware/Adware (global[1].js)! Action taken: No Action Taken. Sun Dec 18 09:23:09 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:09 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:10 2005 => System found infected with whenu.savenow Spyware/Adware (adswrapper[1].js)! Action taken: No Action Taken. Sun Dec 18 09:23:10 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:10 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:10 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:10 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:10 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:10 2005 => System found infected with whenu.savenow Spyware/Adware (adsend[1].js)! Action taken: No Action Taken. Sun Dec 18 09:23:10 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:10 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:10 2005 => System found infected with whenu.savenow Spyware/Adware (stylesheet[1].css)! Action taken: No Action Taken. Sun Dec 18 09:23:10 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken. Sun Dec 18 09:23:10 2005 => System found infected with cydoor.topicks.a Spyware/Adware (settings.dat)! Action taken: No Action Taken. Sun Dec 18 09:23:11 2005 => System found infected with target saver Spyware/Adware (C:\WINDOWS\system32\tsuninst.exe)! Action taken: No Action Taken. Sun Dec 18 09:23:22 2005 => File C:\WINDOWS\secure32.html infected by "not-virus:Hoax.Win32.Renos.y" Virus! Action Taken: No Action Taken. Sun Dec 18 09:23:23 2005 => File C:\WINDOWS\timessquare.exe infected by "Trojan.Win32.StartPage.aw" Virus! Action Taken: No Action Taken. Sun Dec 18 09:23:23 2005 => File C:\WINDOWS\tool2.exe infected by "Trojan-Clicker.Win32.Spywad.l" Virus! Action Taken: No Action Taken. Sun Dec 18 09:23:23 2005 => File C:\WINDOWS\tool3.exe infected by "Packed.Win32.Klone.b" Virus! Action Taken: No Action Taken. Sun Dec 18 09:23:23 2005 => File C:\WINDOWS\toolbar.exe infected by "Trojan-Downloader.Win32.Adload.j" Virus! Action Taken: No Action Taken. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Sun Dec 18 09:22:31 2005 => File C:\Programme\RealVNC\VNC4\WinVNC4.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.4110. No Action Taken. Sun Dec 18 09:22:45 2005 => File C:\Programme\RealVNC\VNC4\WinVNC4.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.4110. No Action Taken. Sun Dec 18 09:23:20 2005 => File C:\WINDOWS\icont.exe tagged as "not-a-virus:AdWare.Win32.AdURL.c". Action Taken: No Action Taken. Sun Dec 18 09:23:28 2005 => File C:\WINDOWS\system32\azsldpc.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.ab". Action Taken: No Action Taken. Sun Dec 18 09:23:34 2005 => File C:\WINDOWS\system32\dDdim700.dll tagged as "not-a-virus:AdWare.Win32.Look2Me.ab". Action Taken: No Action Taken. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "offending" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Sun Dec 18 09:22:48 2005 => Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\tsa !!! Sun Dec 18 09:22:48 2005 => Offending Key found: HKLM\Software\kazaa !!! Sun Dec 18 09:22:48 2005 => Offending Key found: HKCU\Software\gnu !!! Sun Dec 18 09:22:48 2005 => Offending Key found: HKCU\Software\kazaa !!! Sun Dec 18 09:22:48 2005 => Offending file found: C:\installer.exe Sun Dec 18 09:22:48 2005 => Offending file found: C:\winstall.exe Sun Dec 18 09:22:48 2005 => Offending file found: C:\WINDOWS\tool2.exe Sun Dec 18 09:22:48 2005 => Offending file found: C:\WINDOWS\tool3.exe Sun Dec 18 09:22:48 2005 => Offending file found: C:\WINDOWS\toolbar.exe Sun Dec 18 09:22:48 2005 => Offending file found: C:\WINDOWS\system32\tsuninst.exe Sun Dec 18 09:22:48 2005 => Offending file found: C:\DOKUME~1\SYSTEM~1\LOKALE~1\Temp\insthelp.dll Sun Dec 18 09:22:51 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temp\insthelp.dll Sun Dec 18 09:22:51 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temp\nav\support\help\external\common\symshare\help\disable.dll Sun Dec 18 09:22:51 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temp\outlook logging\firstrun.log Sun Dec 18 09:22:52 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temp\temporary internet files\content.ie5\au7l44mp\blank[1].htm Sun Dec 18 09:22:52 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temp\temporary internet files\content.ie5\hazzqe2v\adsend[1].js Sun Dec 18 09:22:52 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temp\temporary internet files\content.ie5\hazzqe2v\global[1].js Sun Dec 18 09:22:52 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temp\temporary internet files\content.ie5\rwaieqf9\blank[1].htm Sun Dec 18 09:22:52 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temp\temporary internet files\content.ie5\rwaieqf9\ticker[1].js Sun Dec 18 09:22:52 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temp\temporary internet files\content.ie5\zrsk34eo\adswrapper[1].js Sun Dec 18 09:22:52 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temp\temporary internet files\content.ie5\zrsk34eo\blank[1].htm Sun Dec 18 09:22:53 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\012nkl2r\global[1].js Sun Dec 18 09:22:58 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\45y3opeb\ads[1].htm Sun Dec 18 09:23:00 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\6lsbix65\ads[1].htm Sun Dec 18 09:23:00 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\6lsbix65\ads[2].htm Sun Dec 18 09:23:00 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\6lsbix65\formie[1].css Sun Dec 18 09:23:00 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\6lsbix65\global[1].js Sun Dec 18 09:23:01 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\8ft7eivd\blank[1].htm Sun Dec 18 09:23:02 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\94cjhhk5\ads[1].htm Sun Dec 18 09:23:04 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\ch2zg5y3\adswrapper[1].js Sun Dec 18 09:23:05 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\k5y381uf\ads[1].htm Sun Dec 18 09:23:06 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\kterclmb\ads[1].htm Sun Dec 18 09:23:06 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\kterclmb\ads[2].htm Sun Dec 18 09:23:06 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\kxyzodq3\ads[1].htm Sun Dec 18 09:23:07 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\kxyzodq3\blank[1].htm Sun Dec 18 09:23:08 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\s5ijklan\adsend[1].js Sun Dec 18 09:23:08 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\tfbzd1ge\ads[1].htm Sun Dec 18 09:23:08 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\tfbzd1ge\blank[1].htm Sun Dec 18 09:23:08 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\tfbzd1ge\stylesheet[1].css Sun Dec 18 09:23:09 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\temporary internet files\content.ie5\w5izghmf\ads[1].htm Sun Dec 18 09:23:09 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\012nkl2r\global[1].js Sun Dec 18 09:23:09 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\45y3opeb\ads[1].htm Sun Dec 18 09:23:09 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\6lsbix65\ads[1].htm Sun Dec 18 09:23:09 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\6lsbix65\ads[2].htm Sun Dec 18 09:23:09 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\6lsbix65\formie[1].css Sun Dec 18 09:23:09 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\6lsbix65\global[1].js Sun Dec 18 09:23:09 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\8ft7eivd\blank[1].htm Sun Dec 18 09:23:09 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\94cjhhk5\ads[1].htm Sun Dec 18 09:23:10 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\ch2zg5y3\adswrapper[1].js Sun Dec 18 09:23:10 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\k5y381uf\ads[1].htm Sun Dec 18 09:23:10 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\kterclmb\ads[1].htm Sun Dec 18 09:23:10 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\kterclmb\ads[2].htm Sun Dec 18 09:23:10 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\kxyzodq3\ads[1].htm Sun Dec 18 09:23:10 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\kxyzodq3\blank[1].htm Sun Dec 18 09:23:10 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\s5ijklan\adsend[1].js Sun Dec 18 09:23:10 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\tfbzd1ge\ads[1].htm Sun Dec 18 09:23:10 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\tfbzd1ge\blank[1].htm Sun Dec 18 09:23:10 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\tfbzd1ge\stylesheet[1].css Sun Dec 18 09:23:10 2005 => Offending file found: C:\Dokumente und Einstellungen\Systemroot\Lokale Einstellungen\Temporary Internet Files\content.ie5\w5izghmf\ads[1].htm Sun Dec 18 09:23:10 2005 => Offending file found: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\symantec\common client\settings.dat Sun Dec 18 09:23:11 2005 => Offending file found: C:\WINDOWS\system32\tsuninst.exe ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Sun Dec 18 09:21:11 2005 => Virus Database Date: 2005/12/12 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~ © Haui ;-) ~~~~~~~ ~~~~~~~ Dank an Cidre ~~~~~~~ |
18.12.2005, 11:12 | #4 |
| Trojanerfarm @Mithrandir0000001 du hast diesen hier im system. deswegena kann ich dir nur raten dein system neuaufzusetzen, reinigungsversuche sind IMHO nur zeitverschwendung da dein system kompromittiert ist. kompromittiert hier eine anleitung zum neuaufsetzen sry chaosman
__________________ Bonus vir semper tiro |
18.12.2005, 11:25 | #5 | |
| TrojanerfarmZitat:
danke mal für deine hilfe - genau das wollte ich vermeiden, aber wenn du sagst, es gibt keine andere möglichkeit..... |
Themen zu Trojanerfarm |
antivirus, cyberlink, diagnostics, dll, drivers, einstellungen, excel, explorer, ftp, google, helfen, hijack, hijackthis, icqtoolbar, internet, internet explorer, löschen, nvidia, problem, programme, rundll, security, settings manager, software, symantec, system, thomson, trojaner, tuneup utilities, urlsearchhook, usb, windows, windows xp |