![]() |
|
Plagegeister aller Art und deren Bekämpfung: Win32:Zlob-BN (Trj) geht trotz 1000 Versuchen nicht weg!!!VERZWEIFLUNGWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() Win32:Zlob-BN (Trj) geht trotz 1000 Versuchen nicht weg!!!VERZWEIFLUNG Hallo leute, ich werde wahnsinnig. Seit zwölf uhr mittags versuche ich meinen Pc von einem(?) oder mehreren(?) Trojaner/n, Virus/Viren und/oder Spyware zu reinigen. Das mein Computer verseucht ist, wurde mir zuerst von meinem Virenscanner (avast!) gemeldet. nachdem ich die verseuchte Datei (win32:Zlob-Bn) in den Container verschoben hatte, meldete "avast!" erneut, dass mein Computer von diesem Trojaner verseucht wurde. Diesen Vorgang habe ich mehrmals wiederholt. Leider ohne Erfolg. Mittlerweile lässt sich die Datei nichtmal mehr in den Container verschieben, der Zugriff wird verweigert, da die verseuchte Datei angeblich von einem anderen Programm benutzt wird. Die Meldung, dass sich ein Trojaner auf meinem Computer befindet, wiederholte sich zunächst nur halbstündlich und jetzt mittlerweile schon fast alle fünf Minuten!! Ich habe desweiteren versucht über den abgesicherten Modus die Datei manuell zu entfernen (mit Hilfe von eScan, killbox und clear prog). Leider hatte auch dies keinen Erfolg. Jetzt meldet avast! auch noch, dass mein Arbeitsspeicher infiziert ist. ![]() ach ja: ausserdem öffnet sich jedesmal, wenn ich den Internet Explorer starte, folgende Seite.=>http://www.syssecuritysite.com/ ...und dies, obwohl es nicht als Startseite von mir festgelegt wurde. Auch wenn ich unter Eigenschaften des IE als Startseite eine andere (zb www.web.de) eingebe, öffnet sich die besagte Seite. Kann mir jemand sagen, um was für eine Seite es sich handelt? schätzungweise irgendeine fake-site. oder? Verdammt ich dreh langsam am rad. und habe keine ahnung was machen soll. eine komplette neu installation kommt aus verschieden Gründen erstmal nicht in frage. Bitte um schnelle Hilfe! Vielen Dank Hier noch der escan Report: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Infektionsmeldungen ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue Jun 27 19:29:27 2006 => System found infected with smitfraud variant Browser Hijacker (ot.ico)! Action taken: No Action Taken. Tue Jun 27 19:29:27 2006 => System found infected with smitfraud variant Browser Hijacker (ts.ico)! Action taken: No Action Taken. Tue Jun 27 19:38:04 2006 => System found infected with smitfraud variant Browser Hijacker (ot.ico)! Action taken: No Action Taken. Tue Jun 27 19:38:04 2006 => System found infected with smitfraud variant Browser Hijacker (ts.ico)! Action taken: No Action Taken. Tue Jun 27 19:50:56 2006 => System found infected with smitfraud variant Browser Hijacker (ot.ico)! Action taken: No Action Taken. Tue Jun 27 19:50:56 2006 => System found infected with smitfraud variant Browser Hijacker (ts.ico)! Action taken: No Action Taken. Tue Jun 27 20:42:09 2006 => System found infected with zlob Trojan-Downloader (dcomcfg.exe)! Action taken: No Action Taken. Tue Jun 27 20:42:09 2006 => System found infected with zlob Trojan-Downloader (simpole.tlb)! Action taken: No Action Taken. Tue Jun 27 20:42:13 2006 => System found infected with smitfraud Browser Hijacker (antivirus test online.url)! Action taken: No Action Taken. Tue Jun 27 21:11:18 2006 => System found infected with zlob Trojan-Downloader (dcomcfg.exe)! Action taken: No Action Taken. Tue Jun 27 21:11:18 2006 => System found infected with zlob Trojan-Downloader (simpole.tlb)! Action taken: No Action Taken. Tue Jun 27 21:11:21 2006 => System found infected with smitfraud Browser Hijacker (antivirus test online.url)! Action taken: No Action Taken. Tue Jun 27 19:29:26 2006 => Object "downloadware Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:29:26 2006 => Object "winfixer/errorsafe Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:29:27 2006 => Object "smitfraud variant Browser Hijacker" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:29:27 2006 => Object "downloadware Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:29:27 2006 => Object "errorguard Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:29:27 2006 => Object "winfixer/errorsafe Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:38:01 2006 => Object "downloadware Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:38:01 2006 => Object "winfixer/errorsafe Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:38:04 2006 => Object "smitfraud variant Browser Hijacker" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:38:04 2006 => Object "downloadware Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:38:04 2006 => Object "errorguard Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:38:04 2006 => Object "winfixer/errorsafe Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:50:54 2006 => Object "downloadware Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:50:55 2006 => Object "winfixer/errorsafe Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:50:56 2006 => Object "smitfraud variant Browser Hijacker" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:50:56 2006 => Object "downloadware Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:50:56 2006 => Object "errorguard Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 19:50:56 2006 => Object "winfixer/errorsafe Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 20:42:07 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 20:42:07 2006 => Object "downloadware Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 20:42:07 2006 => Object "winfixer/errorsafe Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 20:42:07 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 20:42:07 2006 => Object "winfixer/errorsafe Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 20:42:07 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 20:42:07 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 20:42:09 2006 => Object "smitfraud Browser Hijacker" found in File System! Action Taken: No Action Taken. Tue Jun 27 20:42:09 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 20:42:19 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 20:42:19 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 21:11:15 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 21:11:15 2006 => Object "downloadware Spyware/Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 21:11:15 2006 => Object "winfixer/errorsafe Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 21:11:16 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 21:11:16 2006 => Object "winfixer/errorsafe Adware" found in File System! Action Taken: No Action Taken. Tue Jun 27 21:11:16 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 21:11:16 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 21:11:18 2006 => Object "smitfraud Browser Hijacker" found in File System! Action Taken: No Action Taken. Tue Jun 27 21:11:18 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 21:11:30 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. Tue Jun 27 21:11:31 2006 => Object "emule P2P-worm" found in File System! Action Taken: No Action Taken. ~~~~~~~~~~~ Dateien ~~~~~~~~~~~ ~~~~ Infected files ~~~~~~~~~~~ Tue Jun 27 20:41:36 2006 => File C:\WINDOWS\system32\regperf.exe infected by "Trojan-Downloader.Win32.Zlob.vr" Virus! Action Taken: File to be deleted on reboot. ~~~~~~~~~~~ ~~~~ Offending files ~~~~~~~~~~~ Tue Jun 27 19:29:27 2006 => Offending file found: C:\WINDOWS\system32\ot.ico Tue Jun 27 19:29:27 2006 => Offending file found: C:\WINDOWS\system32\ts.ico Tue Jun 27 19:38:04 2006 => Offending file found: C:\WINDOWS\system32\ot.ico Tue Jun 27 19:38:04 2006 => Offending file found: C:\WINDOWS\system32\ts.ico Tue Jun 27 19:50:56 2006 => Offending file found: C:\WINDOWS\system32\ot.ico Tue Jun 27 19:50:56 2006 => Offending file found: C:\WINDOWS\system32\ts.ico Tue Jun 27 20:42:09 2006 => Offending file found: C:\WINDOWS\system32\dcomcfg.exe Tue Jun 27 20:42:09 2006 => Offending file found: C:\WINDOWS\system32\simpole.tlb Tue Jun 27 20:42:13 2006 => Offending file found: C:\Dokumente und Einstellungen\***\Favoriten\antivirus test online.url Tue Jun 27 21:11:18 2006 => Offending file found: C:\WINDOWS\system32\dcomcfg.exe Tue Jun 27 21:11:18 2006 => Offending file found: C:\WINDOWS\system32\simpole.tlb Tue Jun 27 21:11:21 2006 => Offending file found: C:\Dokumente und Einstellungen\***\Favoriten\antivirus test online.url ~~~~~~~~~~~ ~~~~ Tagged files ~~~~~~~~~~~ ~~~~~~~~~~~ Ordner ~~~~~~~~~~~ Tue Jun 27 19:29:27 2006 => Offending Folder found: C:\WINDOWS\system32\1024 Tue Jun 27 19:29:27 2006 => Offending Folder found: C:\WINDOWS\system32\webinstall Tue Jun 27 19:29:27 2006 => Offending Folder found: C:\Programme\errorguard Tue Jun 27 19:29:27 2006 => Offending Folder found: C:\Programme\errorsafe Tue Jun 27 19:38:04 2006 => Offending Folder found: C:\WINDOWS\system32\1024 Tue Jun 27 19:38:04 2006 => Offending Folder found: C:\WINDOWS\system32\webinstall Tue Jun 27 19:38:04 2006 => Offending Folder found: C:\Programme\errorguard Tue Jun 27 19:38:04 2006 => Offending Folder found: C:\Programme\errorsafe Tue Jun 27 19:50:56 2006 => Offending Folder found: C:\WINDOWS\system32\1024 Tue Jun 27 19:50:56 2006 => Offending Folder found: C:\WINDOWS\system32\webinstall Tue Jun 27 19:50:56 2006 => Offending Folder found: C:\Programme\errorguard Tue Jun 27 19:50:56 2006 => Offending Folder found: C:\Programme\errorsafe Tue Jun 27 20:42:09 2006 => Offending Folder found: C:\WINDOWS\system32\1024 Tue Jun 27 20:42:09 2006 => Offending Folder found: C:\Programme\emule Tue Jun 27 20:42:19 2006 => Offending Folder found: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\emule Tue Jun 27 20:42:19 2006 => Offending Folder found: C:\Dokumente und Einstellungen\All Users\Startmenü\programme\emule Tue Jun 27 21:11:18 2006 => Offending Folder found: C:\WINDOWS\system32\1024 Tue Jun 27 21:11:18 2006 => Offending Folder found: C:\Programme\emule Tue Jun 27 21:11:30 2006 => Offending Folder found: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\emule Tue Jun 27 21:11:31 2006 => Offending Folder found: C:\Dokumente und Einstellungen\All Users\Startmenü\programme\emule ~~~~~~~~~~~ Registry ~~~~~~~~~~~ Tue Jun 27 19:29:25 2006 => Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\webinstall !!! Tue Jun 27 19:29:26 2006 => Offending Key found: HKLM\Software\errorsafe !!! Tue Jun 27 19:37:45 2006 => Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\webinstall !!! Tue Jun 27 19:38:01 2006 => Offending Key found: HKLM\Software\errorsafe !!! Tue Jun 27 19:50:54 2006 => Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\webinstall !!! Tue Jun 27 19:50:55 2006 => Offending Key found: HKLM\Software\errorsafe !!! Tue Jun 27 20:42:06 2006 => Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\emule !!! Tue Jun 27 20:42:07 2006 => Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\webinstall !!! Tue Jun 27 20:42:07 2006 => Offending Key found: HKLM\Software\errorsafe !!! Tue Jun 27 20:42:07 2006 => Offending Key found: HKCU\Software\emule !!! Tue Jun 27 20:42:07 2006 => Offending Key found: HKCU\Software\errorsafe !!! Tue Jun 27 20:42:07 2006 => Offending Key found: HKCU\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\emule !!! Tue Jun 27 20:42:07 2006 => Offending Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\emule !!! Tue Jun 27 21:11:15 2006 => Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\emule !!! Tue Jun 27 21:11:15 2006 => Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\webinstall !!! Tue Jun 27 21:11:15 2006 => Offending Key found: HKLM\Software\errorsafe !!! Tue Jun 27 21:11:16 2006 => Offending Key found: HKCU\Software\emule !!! Tue Jun 27 21:11:16 2006 => Offending Key found: HKCU\Software\errorsafe !!! Tue Jun 27 21:11:16 2006 => Offending Key found: HKCU\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\emule !!! Tue Jun 27 21:11:16 2006 => Offending Key found: HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Start Menu\Programs\emule !!! ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statistiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Tue Jun 27 19:32:32 2006 => Total Errors: 2 Tue Jun 27 19:49:14 2006 => Total Errors: 0 Tue Jun 27 19:55:00 2006 => Total Errors: 0 Tue Jun 27 20:45:41 2006 => Total Errors: 1 Tue Jun 27 21:15:28 2006 => Total Errors: 0 Tue Jun 27 19:32:32 2006 => Time Elapsed: 00:04:03 Tue Jun 27 19:49:14 2006 => Time Elapsed: 00:12:03 Tue Jun 27 19:55:00 2006 => Time Elapsed: 00:04:26 Tue Jun 27 20:45:41 2006 => Time Elapsed: 00:04:46 Tue Jun 27 21:15:28 2006 => Time Elapsed: 00:04:49 Tue Jun 27 19:32:32 2006 => Total Objects Scanned: 14086 Tue Jun 27 19:49:14 2006 => Total Objects Scanned: 16874 Tue Jun 27 19:55:00 2006 => Total Objects Scanned: 14293 Tue Jun 27 20:45:41 2006 => Total Objects Scanned: 15568 Tue Jun 27 21:15:28 2006 => Total Objects Scanned: 15598 Tue Jun 27 19:32:32 2006 => Virus Database Date: 2/24/2006 Tue Jun 27 19:35:38 2006 => Virus Database Date: 2/24/2006 Tue Jun 27 19:35:53 2006 => Virus Database Date: 2/24/2006 Tue Jun 27 19:49:14 2006 => Virus Database Date: 2/24/2006 Tue Jun 27 19:49:49 2006 => Virus Database Date: 2/24/2006 Tue Jun 27 19:55:00 2006 => Virus Database Date: 2/24/2006 Tue Jun 27 20:25:30 2006 => Virus Database Date: 2/24/2006 Tue Jun 27 20:35:27 2006 => Virus Database Date: 2/24/2006 Tue Jun 27 20:40:31 2006 => Virus Database Date: 6/27/2006 Tue Jun 27 20:45:41 2006 => Virus Database Date: 6/27/2006 Tue Jun 27 21:15:28 2006 => Virus Database Date: 6/27/2006 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ -------------------------------------------------- C:\Programme\eScan\LOG\MWAV.LOG -------------------------------------------------- |
Themen zu Win32:Zlob-BN (Trj) geht trotz 1000 Versuchen nicht weg!!!VERZWEIFLUNG |
abgesicherten modus, als startseite, antivirus, avast, avast!, browser, computer, einstellungen, entfernen, explorer, file, fraud, handel, infiziert, installation, internet, internet explorer, keine ahnung, langsam, log, mehrere, object, programm, programme, scan, schnelle hilfe, smitfraud, software, spyware, start menu, system, windows, öffnet |