![]() |
|
Plagegeister aller Art und deren Bekämpfung: eScan Funde! Bitte um Hilfe!Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() eScan Funde! Bitte um Hilfe! Hallo zusammen! Würde mich freuen, wenn ihr mir bei der Auswertung der Virus Log Information behilflich sein könntet. Anscheinend wurde da doch einiges gefunden. Vielen Dank im Vorraus! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue Jan 10 01:01:49 2006 => System found infected with cws.loadadv.400 Browser Hijacker (ms1.exe)! Action taken: No Action Taken. Tue Jan 10 01:01:49 2006 => System found infected with cws.loadadv.401 Browser Hijacker (tool3.exe)! Action taken: No Action Taken. Tue Jan 10 01:01:50 2006 => System found infected with elite toolbar Spyware/Adware (toolbar.exe)! Action taken: No Action Taken. Tue Jan 10 01:01:50 2006 => System found infected with paymite Trojan-Spy (paytime.exe)! Action taken: No Action Taken. Tue Jan 10 01:51:48 2006 => Scanning Folder: D:\Programme\AVPersonalPremium\INFECTED\*.* Tue Jan 10 01:51:51 2006 => Scanning Folder: D:\Programme\AVPersonalPremium\MAIL\INFECTED\*.* Tue Jan 10 02:05:01 2006 => File D:\Programme\mozilla-1.7.5.de-AT.win32\Profile\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-3.1\Inbox infected by "Trojan-Spy.HTML.Bayfraud.in" Virus! Action Taken: No Action Taken. Tue Jan 10 02:36:08 2006 => File D:\Programme\mozilla-1.7.5.de-AT.win32\Profile\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-4.1\Inbox infected by "Email-Worm.Win32.Swen" Virus! Action Taken: No Action Taken. Tue Jan 10 02:36:23 2006 => File D:\Programme\mozilla-1.7.5.de-AT.win32\Profile\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-4.1\Trash infected by "Email-Worm.Win32.Bagle.bq" Virus! Action Taken: No Action Taken. Tue Jan 10 02:40:52 2006 => File D:\Programme\mozilla-1.7.5.de-AT.win32\Profile\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-6.1\Inbox infected by "Email-Worm.Win32.NetSky.y" Virus! Action Taken: No Action Taken. Tue Jan 10 02:41:23 2006 => File D:\Programme\mozilla-1.7.5.de-AT.win32\Profile\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-6.1\Trash infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken. Tue Jan 10 02:44:46 2006 => File D:\Programme\mozilla-1.7.5.de-AT.win32\Profile\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-9.1\Inbox infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken. Tue Jan 10 02:47:55 2006 => File D:\Programme\mozilla-1.7.5.de-AT.win32\Profile\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-9.1\Trash infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken. Tue Jan 10 03:45:04 2006 => File E:\Backup\Mozilla\Profile 11.05.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-4.1\Inbox infected by "Email-Worm.Win32.Swen" Virus! Action Taken: No Action Taken. Tue Jan 10 03:48:09 2006 => File E:\Backup\Mozilla\Profile 11.05.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-6.1\Inbox infected by "Email-Worm.Win32.NetSky.y" Virus! Action Taken: No Action Taken. Tue Jan 10 03:48:35 2006 => File E:\Backup\Mozilla\Profile 11.05.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-6.1\Trash infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken. Tue Jan 10 03:50:34 2006 => File E:\Backup\Mozilla\Profile 11.05.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-9.1\Inbox infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken. Tue Jan 10 03:53:12 2006 => File E:\Backup\Mozilla\Profile 11.05.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-9.1\Trash infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken. Tue Jan 10 04:13:36 2006 => File E:\Backup\Mozilla\Profile 29.05.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-4.1\Inbox infected by "Email-Worm.Win32.Swen" Virus! Action Taken: No Action Taken. Tue Jan 10 04:16:38 2006 => File E:\Backup\Mozilla\Profile 29.05.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-6.1\Inbox infected by "Email-Worm.Win32.NetSky.y" Virus! Action Taken: No Action Taken. Tue Jan 10 04:17:02 2006 => File E:\Backup\Mozilla\Profile 29.05.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-6.1\Trash infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken. Tue Jan 10 04:19:05 2006 => File E:\Backup\Mozilla\Profile 29.05.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-9.1\Inbox infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken. Tue Jan 10 04:21:41 2006 => File E:\Backup\Mozilla\Profile 29.05.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-9.1\Trash infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken. Tue Jan 10 04:25:06 2006 => File E:\Backup\Mozilla\Profile 29.09.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-3.1\Inbox infected by "Trojan-Spy.HTML.Bayfraud.in" Virus! Action Taken: No Action Taken. Tue Jan 10 04:52:54 2006 => File E:\Backup\Mozilla\Profile 29.09.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-3.1\Trash infected by "Trojan-Spy.HTML.Bayfraud.in" Virus! Action Taken: No Action Taken. Tue Jan 10 04:52:54 2006 => File E:\Backup\Mozilla\Profile 29.09.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-4.1\Inbox infected by "Email-Worm.Win32.Swen" Virus! Action Taken: No Action Taken. Tue Jan 10 04:52:59 2006 => File E:\Backup\Mozilla\Profile 29.09.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-4.1\Trash infected by "Email-Worm.Win32.Bagle.bq" Virus! Action Taken: No Action Taken. Tue Jan 10 04:56:27 2006 => File E:\Backup\Mozilla\Profile 29.09.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-6.1\Inbox infected by "Email-Worm.Win32.NetSky.y" Virus! Action Taken: No Action Taken. Tue Jan 10 04:56:55 2006 => File E:\Backup\Mozilla\Profile 29.09.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-6.1\Trash infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken. Tue Jan 10 05:00:05 2006 => File E:\Backup\Mozilla\Profile 29.09.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-9.1\Inbox infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken. Tue Jan 10 05:03:03 2006 => File E:\Backup\Mozilla\Profile 29.09.05\Standard-Profil\b5a5xhu0.slt\Mail\192.168.0-9.1\Trash infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken. Tue Jan 10 07:57:55 2006 => Total Disinfected Objects: 0 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue Jan 10 02:57:20 2006 => File D:\System Volume Information\_restore{897F8A43-17CE-4A09-9ACB-4D77B40C74FE}\RP55\A0024635.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.4. No Action Taken. Tue Jan 10 02:57:20 2006 => File D:\System Volume Information\_restore{897F8A43-17CE-4A09-9ACB-4D77B40C74FE}\RP55\A0024637.dll tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.4. No Action Taken. Tue Jan 10 02:57:20 2006 => File D:\System Volume Information\_restore{897F8A43-17CE-4A09-9ACB-4D77B40C74FE}\RP55\A0024638.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.4. No Action Taken. Tue Jan 10 02:57:20 2006 => File D:\System Volume Information\_restore{897F8A43-17CE-4A09-9ACB-4D77B40C74FE}\RP55\A0024639.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.4. No Action Taken. Tue Jan 10 03:25:59 2006 => File E:\03-Setups\weitere\tightvnc-1.2.9-setup.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC-based.h. No Action Taken. Tue Jan 10 05:08:56 2006 => File E:\System Volume Information\_restore{897F8A43-17CE-4A09-9ACB-4D77B40C74FE}\RP55\A0025664.exe tagged as not-a-virus:RemoteAdmin.Win32.WinVNC.4. No Action Taken. Tue Jan 10 07:57:43 2006 => File G:\System Volume Information\_restore{897F8A43-17CE-4A09-9ACB-4D77B40C74FE}\RP55\A0026076.exe tagged as "not-a-virus:Porn-Dialer.Win32.Intexdial". Action Taken: No Action Taken. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "offending" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue Jan 10 01:01:49 2006 => Offending file found: C:\WINDOWS\ms1.exe Tue Jan 10 01:01:49 2006 => Offending file found: C:\WINDOWS\tool3.exe Tue Jan 10 01:01:50 2006 => Offending file found: C:\WINDOWS\toolbar.exe Tue Jan 10 01:01:50 2006 => Offending file found: C:\WINDOWS\system32\paytime.exe Tue Jan 10 01:01:53 2006 => Offending Folder found: C:\Dokumente und Einstellungen\All Users\Dokumente\linotype library goldedition 1.7 cd2 (true type fonts)\goldedition 1.7 pc tt\goldedition 1.7 pc tt family\f\forbes ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue Jan 10 07:57:55 2006 => Total Errors: 25 Tue Jan 10 07:57:55 2006 => Time Elapsed: 06:47:15 Tue Jan 10 07:57:55 2006 => Total Objects Scanned: 237966 Tue Jan 10 01:00:31 2006 => Virus Database Date: 1/10/2006 Tue Jan 10 07:57:55 2006 => Virus Database Date: 1/10/2006 Tue Jan 10 10:21:55 2006 => Virus Database Date: 1/10/2006 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~ © Haui ;-) ~~~~~~~ ~~~~~~~ Dank an Cidre ~~~~~~~ |
Themen zu eScan Funde! Bitte um Hilfe! |
.dll, auswertung, bitte um hilfe, browser, browser hijacker, einstellungen, escan, file, gen, hijacker, hilfe!, infected, log, mail, not-a-virus, programme, scan, system, system volume information, system32, tool, trojan-spy, ups, virus, windows |