|
Plagegeister aller Art und deren Bekämpfung: TR/Crypt.XPACK.Gen lässt sich nicht löschenWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
01.06.2007, 19:27 | #16 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen und dann auf die ampel? weil kann da ja noch nix eingeben. kommt des dann erst? sorry, bin echt laie... |
01.06.2007, 19:31 | #17 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen Input script manually -> Auf die Lupe -> Reinkopiere -> Grüne Ampel.
__________________Dein PC startet neu. |
01.06.2007, 19:51 | #18 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen da kommt ne fehlermeldung.
__________________zuerst: "could not create zip file" und dann "could not initiate system shutdown" |
01.06.2007, 19:54 | #19 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen Hm. Versuch mal den Avenger umzubenennen. Entpackt hast du ihn schon? |
01.06.2007, 20:18 | #20 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen so, ging doch noch. das hat mir der avenger nach dem reboot angezeigt: ////////////////////////////////////////// Avenger Pre-Processor log ////////////////////////////////////////// Error: could not create zip file. Error code: 0 ////////////////////////////////////////// Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\ioajaimq ******************* Script file located at: \??\C:\Program Files\orqeryqb.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: File c:\windows\system32\awvvuuu.dll deleted successfully. File C:\Programme\RXToolBar\RXToolBar.dll deleted successfully. File C:\Programme\RXToolBar\sfcont.dll not found! Deletion of file C:\Programme\RXToolBar\sfcont.dll failed! Could not process line: C:\Programme\RXToolBar\sfcont.dll Status: 0xc0000034 Folder C:\Programme\RXToolBar deleted successfully. Completed script processing. ******************* Finished! Terminate.////////////////////////////////////////// Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\foaaejyj ******************* Script file located at: \??\C:\WINDOWS\mppbapdw.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: File c:\windows\system32\awvvuuu.dll not found! Deletion of file c:\windows\system32\awvvuuu.dll failed! Could not process line: c:\windows\system32\awvvuuu.dll Status: 0xc0000034 Could not open file C:\Programme\RXToolBar\RXToolBar.dll for deletion Deletion of file C:\Programme\RXToolBar\RXToolBar.dll failed! Could not process line: C:\Programme\RXToolBar\RXToolBar.dll Status: 0xc000003a Could not open file C:\Programme\RXToolBar\sfcont.dll for deletion Deletion of file C:\Programme\RXToolBar\sfcont.dll failed! Could not process line: C:\Programme\RXToolBar\sfcont.dll Status: 0xc000003a Folder C:\Programme\RXToolBar not found! Deletion of folder C:\Programme\RXToolBar failed! Could not process line: C:\Programme\RXToolBar Status: 0xc0000034 Completed script processing. ******************* Finished! Terminate.////////////////////////////////////////// Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\gtjfelxx ******************* Script file located at: \??\C:\roamnvjm.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: File c:\windows\system32\awvvuuu.dll not found! Deletion of file c:\windows\system32\awvvuuu.dll failed! Could not process line: c:\windows\system32\awvvuuu.dll Status: 0xc0000034 Could not open file C:\Programme\RXToolBar\RXToolBar.dll for deletion Deletion of file C:\Programme\RXToolBar\RXToolBar.dll failed! Could not process line: C:\Programme\RXToolBar\RXToolBar.dll Status: 0xc000003a Could not open file C:\Programme\RXToolBar\sfcont.dll for deletion Deletion of file C:\Programme\RXToolBar\sfcont.dll failed! Could not process line: C:\Programme\RXToolBar\sfcont.dll Status: 0xc000003a Folder C:\Programme\RXToolBar not found! Deletion of folder C:\Programme\RXToolBar failed! Could not process line: C:\Programme\RXToolBar Status: 0xc0000034 Completed script processing. ******************* Finished! Terminate.////////////////////////////////////////// Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\slscrvfx ******************* Script file located at: \??\C:\cfpqfhpy.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: File c:\windows\system32\awvvuuu.dll not found! Deletion of file c:\windows\system32\awvvuuu.dll failed! Could not process line: c:\windows\system32\awvvuuu.dll Status: 0xc0000034 Could not open file C:\Programme\RXToolBar\RXToolBar.dll for deletion Deletion of file C:\Programme\RXToolBar\RXToolBar.dll failed! Could not process line: C:\Programme\RXToolBar\RXToolBar.dll Status: 0xc000003a Could not open file C:\Programme\RXToolBar\sfcont.dll for deletion Deletion of file C:\Programme\RXToolBar\sfcont.dll failed! Could not process line: C:\Programme\RXToolBar\sfcont.dll Status: 0xc000003a Folder C:\Programme\RXToolBar not found! Deletion of folder C:\Programme\RXToolBar failed! Could not process line: C:\Programme\RXToolBar Status: 0xc0000034 Completed script processing. ******************* Finished! Terminate.////////////////////////////////////////// Logfile of The Avenger version 1, by Swandog46 Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\kemvrvrw ******************* Script file located at: \??\C:\Program Files\ymo^uolf.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: File c:\windows\system32\awvvuuu.dll not found! Deletion of file c:\windows\system32\awvvuuu.dll failed! Could not process line: c:\windows\system32\awvvuuu.dll Status: 0xc0000034 Could not open file C:\Programme\RXToolBar\RXToolBar.dll for deletion Deletion of file C:\Programme\RXToolBar\RXToolBar.dll failed! Could not process line: C:\Programme\RXToolBar\RXToolBar.dll Status: 0xc000003a Could not open file C:\Programme\RXToolBar\sfcont.dll for deletion Deletion of file C:\Programme\RXToolBar\sfcont.dll failed! Could not process line: C:\Programme\RXToolBar\sfcont.dll Status: 0xc000003a Folder C:\Programme\RXToolBar not found! Deletion of folder C:\Programme\RXToolBar failed! Could not process line: C:\Programme\RXToolBar Status: 0xc0000034 Completed script processing. ******************* Finished! Terminate. ich lass jetzt noml hjt laufen... bitteschön: Logfile of HijackThis v1.99.1 Scan saved at 21:23:43, on 01.06.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\AntiVir PersonalEdition Classic\sched.exe C:\Programme\AntiVir PersonalEdition Classic\avguard.exe C:\Programme\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe C:\Programme\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe C:\Programme\CA\eTrust Antivirus\InoRpc.exe C:\Programme\CA\eTrust Antivirus\InoRT.exe C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\Programme\CyberLink\Shared Files\RichVideo.exe C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe C:\Programme\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\Programme\Home Cinema\PowerCinema\PCMService.exe C:\Programme\Medion Info Display\MdionLCM.exe C:\WINDOWS\mHotkey.exe C:\WINDOWS\CNYHKey.exe C:\PROGRA~1\CA\ETRUST~1\realmon.exe C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe C:\Programme\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe C:\Programme\iTunes\iTunesHelper.exe C:\Programme\QuickTime\qttask.exe C:\Programme\iPod\bin\iPodService.exe C:\WINDOWS\system32\ctfmon.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Mozilla Firefox\firefox.exe C:\Dokumente und Einstellungen\Leni\Desktop\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Welcome to ALDI R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = Welcome to ALDI R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar4.dll O2 - BHO: (no name) - {b1f73c6f-9bab-4c43-897b-464b7e38826e} - C:\WINDOWS\system32\iprpv6.dll O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programme\Canon\Easy-WebPrint\Toolband.dll O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar4.dll O4 - HKLM\..\Run: [ALDI_SUED_FotoSuite] "C:\Programme\ALDI Sued Foto Service\ALDI_Foto_Service\FotoSuite.exe" /autorun O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [PCMService] "C:\Programme\Home Cinema\PowerCinema\PCMService.exe" O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [MedionVFD] "C:\Programme\Medion Info Display\MdionLCM.exe" O4 - HKLM\..\Run: [CHotkey] mHotkey.exe O4 - HKLM\..\Run: [ledpointer] CNYHKey.exe O4 - HKLM\..\Run: [AntivirusRegistration] C:\Programme\CA\Etrust Antivirus\Register.exe O4 - HKLM\..\Run: [Realtime Monitor] C:\PROGRA~1\CA\ETRUST~1\realmon.exe -s O4 - HKLM\..\Run: [InstantOn] "C:\Programme\CyberLink\PowerCinema Linux\ion_install.exe /c " O4 - HKLM\..\Run: [Easy-PrintToolBox] C:\Programme\Canon\Easy-PrintToolBox\BJPSMAIN.EXE /logon O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Programme\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe" O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe" O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Programme\Nokia\Nokia PC Suite 6\LaunchApplication.exe -startup O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [fyilqgbb] C:\vyksckwu.bat O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [NBJ] "C:\Programme\Ahead\Nero BackItUp\NBJ.exe" O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe O4 - Startup: Trillian.lnk = C:\Programme\Trillian\trillian.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Reader 8.0\Reader\reader_sl.exe O4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Programme\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML O8 - Extra context menu item: Easy-WebPrint - Drucken - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html O8 - Extra context menu item: Easy-WebPrint - Vorschau - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programme\PartyGaming\PartyPoker\RunApp.exe O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programme\PartyGaming\PartyPoker\RunApp.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O14 - IERESET.INF: START_PAGE_URL=http://www.aldi.com O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204 O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1128778405937 O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1141142460296 O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/MsnMessengerSetupDownloader.cab O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL O20 - AppInit_DLLs: c:\windows\system32\awvvuuu.dll O20 - Winlogon Notify: iprpv6 - C:\WINDOWS\SYSTEM32\iprpv6.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: Adobe LM Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: CyberLink Background Capture Service (CBCS) (CLCapSvc) - Unknown owner - C:\Programme\Home Cinema\PowerCinema\Kernel\TV\CLCapSvc.exe O23 - Service: CyberLink Task Scheduler (CTS) (CLSched) - Unknown owner - C:\Programme\Home Cinema\PowerCinema\Kernel\TV\CLSched.exe O23 - Service: CyberLink Media Library Service - Cyberlink - C:\Programme\Home Cinema\PowerCinema\Kernel\CLML_NTService\CLMLServer.exe O23 - Service: Google Updater Service (gusvc) - Google - C:\Programme\Google\Common\Google Updater\GoogleUpdaterService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: eTrust Antivirus RPC Server (InoRPC) - Computer Associates International, Inc. - C:\Programme\CA\eTrust Antivirus\InoRpc.exe O23 - Service: eTrust Antivirus Realtime Server (InoRT) - Computer Associates International, Inc. - C:\Programme\CA\eTrust Antivirus\InoRT.exe O23 - Service: eTrust Antivirus Job Server (InoTask) - Computer Associates International, Inc. - C:\Programme\CA\eTrust Antivirus\InoTask.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Programme\CyberLink\Shared Files\RichVideo.exe O23 - Service: ServiceLayer - Nokia. - C:\Programme\PC Connectivity Solution\ServiceLayer.exe O23 - Service: X10 Device Network Service (x10nets) - X10 - C:\PROGRA~1\COMMON~1\X10\Common\x10nets.exe Geändert von Leni1893 (01.06.2007 um 20:26 Uhr) |
01.06.2007, 20:23 | #21 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen Ja, ohne das HijackthisLog kann ich dir nämlich nicht helfen. |
01.06.2007, 20:49 | #22 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen des aktuelle logfile is schon im beitrag davor, da wo des zeug vom avenger au drin is |
01.06.2007, 20:53 | #23 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen c:\windows\system32\awvvuuu.dll und C:\WINDOWS\SYSTEM32\iprpv6.dll bei www.virustotal.com prüfen. Ergebnis hier posten. |
01.06.2007, 21:08 | #24 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen ok, läuft. den 2. auch nochmal prüfen? hab ich weiter unten schonmal gemacht... |
01.06.2007, 21:09 | #25 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen Oh, entschuldigung, nein, du brauchst den zweiten dann nicht nochmal zu checken. Edit: Oder doch, die zweite bitte auch nochmal. Und vergiss diesmal nicht, bitte den Kopf mitrauszukopieren, also wo oben steht, welche Datei gescannt wurde. Sonst blickt man auf die Dauer nicht mehr durch. |
01.06.2007, 21:23 | #26 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen also, die erste datei is nich mehr da. irgendwie komisch, weil hjt die ja noch gefunden hat... jedenfalls is der scan also nich möglich (trojaner weg?) die 2. läuft grad noml durch... |
01.06.2007, 21:43 | #27 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen Complete scanning result of "iprpv6.dll", received in VirusTotal at 06.01.2007, 22:21:28 (CET). Antivirus Version Update Result AhnLab-V3 2007.5.31.2 06.01.2007 no virus found AntiVir 7.4.0.29 06.01.2007 no virus found Authentium 4.93.8 05.23.2007 no virus found Avast 4.7.997.0 06.01.2007 no virus found AVG 7.5.0.467 06.01.2007 no virus found BitDefender 7.2 06.01.2007 no virus found CAT-QuickHeal 9.00 06.01.2007 no virus found ClamAV devel-20070416 06.01.2007 no virus found DrWeb 4.33 06.01.2007 no virus found eSafe 7.0.15.0 05.31.2007 no virus found eTrust-Vet 30.7.3682 06.01.2007 no virus found Ewido 4.0 06.01.2007 no virus found FileAdvisor 1 06.01.2007 no virus found Fortinet 2.85.0.0 06.01.2007 suspicious F-Prot 4.3.2.48 06.01.2007 no virus found F-Secure 6.70.13030.0 06.01.2007 no virus found Ikarus T3.1.1.8 06.01.2007 no virus found Kaspersky 4.0.2.24 06.01.2007 no virus found McAfee 5044 06.01.2007 no virus found Microsoft 1.2503 06.01.2007 no virus found NOD32v2 2305 06.01.2007 no virus found Norman 5.80.02 06.01.2007 no virus found Panda 9.0.0.4 06.01.2007 Suspicious file Prevx1 V2 06.01.2007 no virus found Sophos 4.18.0 06.01.2007 no virus found Sunbelt 2.2.907.0 05.30.2007 VIPRE.Suspicious Symantec 10 06.01.2007 no virus found TheHacker 6.1.6.128 05.31.2007 no virus found VBA32 3.12.0 06.01.2007 AdWare.Win32.Virtumonde.ke VirusBuster 4.3.23:9 06.01.2007 no virus found Webwasher-Gateway 6.0.1 06.01.2007 Win32.Malware.gen (suspicious) Aditional Information File size: 37481 bytes MD5: 5135e868cc5f91add46eb593cada820d SHA1: 9a841e4a5023479b8b7323ae9585f9046df38276 packers: RLPack Sunbelt info: VIPRE.Suspicious is a generic detection for potential threats that are deemed suspicious through heuristics. |
01.06.2007, 21:54 | #28 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen Downloade dir Kaspersky free trial version: http://www.kaspersky.co.uk/trials?chapter=186685226 Der erkennt die malware, die sich in der Datei "iprpv6.dll" versteckt. lasse diese bitte löschen und poste dein report. ( Hijackthis ) |
01.06.2007, 22:21 | #29 |
| TR/Crypt.XPACK.Gen lässt sich nicht löschen des kann ich ned installieren, weil des mit antivir ned kompatibel is... |
Themen zu TR/Crypt.XPACK.Gen lässt sich nicht löschen |
antivir, antivirus, appinit_dlls, avg, avira, bho, canon, computer, cyberlink, downloader, excel, firefox, google, helfen, hijack, hijackthis, home, install.exe, internet, internet explorer, monitor, mozilla, mozilla firefox, programm, rundll, software, solution, super, system, tr/crypt.xpack.ge, tr/crypt.xpack.gen, tracker, trojaner, urlsearchhook, windows, windows xp |