|
Log-Analyse und Auswertung: eScan bricht ab. Woran könnte das liegen?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
09.12.2007, 18:25 | #1 |
| eScan bricht ab. Woran könnte das liegen? Hallo, ich habe seit kurzem das Problem, dass eScan mit im Scan abbricht und runterfährt. Vorher gibt das Programm an, dass es mirar Spyware gefunden hat. Ich lasse es regelmäßig im abgesicherten Modus von XP laufen. Neuinstallation und Update haben das Problem nicht gelöst. Ich hatte erst Mirar in Verdacht, aber sowohl Spybot, SpyHunter und SpywareDoctor haben es nicht gefunden. Dafür hat SpyHunter zwei und SpywareDoctor 104 andere Bedrohungen ausfindig gemacht. Irgendwie habe ich aber das Gefühl, dass diese Warnungen eher dazu animieren sollen die Programme zu kaufen, als tatsächlich den Rechnerzustand wiederzugeben. Ich habe mal HJT durchlaufen lassen und folgendes Log erhalten. Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe D:\Programme\AV\AntiVir PersonalEdition Classic\avguard.exe C:\WINDOWS\System32\svchost.exe D:\Programme\AV\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\System32\ati2evxx.exe C:\Programme\Speed Disk\nopdb.exe C:\WINDOWS\system32\wdfmgr.exe C:\WINDOWS\System32\alg.exe C:\WINDOWS\Explorer.EXE C:\Programme\Apoint\Apoint.exe C:\WINDOWS\system32\Atiptaxx.exe D:\Programme\AV\AntiVir PersonalEdition Classic\avgnt.exe C:\Programme\Adobe\Distillr\acrotray.exe C:\PROGRA~1\ICQ\ICQ.exe C:\PROGRA~1\Mozilla Firefox\firefox.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\taskmgr.exe D:\Programme\Spyware Doctor\svcntaux.exe D:\Programme\Spyware Doctor\swdsvc.exe D:\Programme\Spyware Doctor\SDTrayApp.exe D:\Programme\AV\HJT202\HijackThis.exe D:\Programme\Spyware Doctor\swdoctor.exe C:\WINDOWS\System32\wbem\wmiprvse.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.club-vaio.sony-europe.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.club-vaio.sony-europe.com R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.club-vaio.sony-europe.com/ O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\AV\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe O4 - HKLM\..\Run: [avgnt] "D:\Programme\AV\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Acrobat 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [SpyHunter Security Suite] C:\Programme\Enigma Software Group\SpyHunter\SpyHunter3.exe O4 - HKLM\..\Run: [SDTray] "D:\Programme\Spyware Doctor\SDTrayApp.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: Common Information.rtf O4 - Global Startup: Acrobat Assistant.lnk = C:\Programme\Adobe\Distillr\acrotray.exe O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\AV\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\AV\SPYBOT~1\SDHelper.dll O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.sony-europe.com O15 - Trusted Zone: *.sony-europe.com O15 - Trusted Zone: *.sonystyle-europe.com O17 - HKLM\System\CCS\Services\Tcpip\..\{610D547F-0550-4F06-B944-116EF6AA733C}: NameServer = *IP*,*IP* O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - D:\Programme\AV\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - D:\Programme\AV\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\ati2evxx.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - D:\Programme\Spyware Doctor\svcntaux.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - D:\Programme\Spyware Doctor\swdsvc.exe O23 - Service: ServiceLayer - Nokia. - C:\Programme\Gemeinsame Dateien\PCSuite\Services\ServiceLayer.exe O23 - Service: Speed Disk service - Symantec Corporation - C:\Programme\Speed Disk\nopdb.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\SPTISRV.exe -- End of file - 5698 bytes Eine Online-Prüfung des Logs hat keine sichtbaren Fehler aufgezeigt. Was könnte ich also noch tun, außer den Rechner neu aufzusetzen? Gruß, Cobrus
__________________ Computer sind die logische Weiterentwicklung des Menschen: Intelligenz ohne Moral. (John Osborne) |
10.12.2007, 08:40 | #2 |
/// AVZ-Toolkit Guru | eScan bricht ab. Woran könnte das liegen? Hallöle Cobrus.
__________________Poste bitte noch den Kopf dees HijackThis logs! Dann deinstalliere am besten SpyHunter und den SpywareDoctor.. Spybot macht seine Sache schon ganz gut, keine Angst Wenn du unbedingt noch eine zweite Meinung einholen möchtest so solltest du AdAware Se benutzen! Poste danach bitte ein frisches HijackThis log und führe einen eScan durch wie es in meiner Sigantur beschrieben wird.
__________________ |
10.12.2007, 11:52 | #3 |
| eScan bricht ab. Woran könnte das liegen? Okay, hier ist der Kopf des ersten Logs:
__________________Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:25:10, on 09.12.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Hier ist das frische Log: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 11:49:13, on 10.12.2007 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe D:\Programme\AV\AntiVir PersonalEdition Classic\avguard.exe D:\Programme\AV\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\System32\ati2evxx.exe C:\Programme\Speed Disk\nopdb.exe C:\WINDOWS\Explorer.EXE C:\Programme\Apoint\Apoint.exe C:\WINDOWS\system32\Atiptaxx.exe D:\Programme\AV\AntiVir PersonalEdition Classic\avgnt.exe C:\Programme\Apoint\Apntex.exe C:\PROGRA~1\ICQ\ICQ.exe C:\Programme\Adobe\Distillr\acrotray.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\PROGRA~1\Mozilla Firefox\firefox.exe D:\Programme\AV\HJT202\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:blank R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = [url=http://www.club-vaio.sony-europe.com/]Club VAIO | Home R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = [url=http://www.club-vaio.sony-europe.com]Club VAIO | Home R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = about:blank R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = [url=http://www.club-vaio.sony-europe.com/]Club VAIO | Home O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - D:\PROGRA~1\AV\SPYBOT~1\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat\AcroIEFavClient.dll O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat\AcroIEFavClient.dll O4 - HKLM\..\Run: [Apoint] C:\Programme\Apoint\Apoint.exe O4 - HKLM\..\Run: [AtiPTA] Atiptaxx.exe O4 - HKLM\..\Run: [avgnt] "D:\Programme\AV\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Mirabilis ICQ] C:\PROGRA~1\ICQ\ICQNet.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Acrobat 8.0\Reader\Reader_sl.exe" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Startup: Common Information.rtf O4 - Global Startup: Acrobat Assistant.lnk = C:\Programme\Adobe\Distillr\acrotray.exe O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - C:\PROGRA~1\ICQ\ICQ.exe O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\AV\SPYBOT~1\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - D:\PROGRA~1\AV\SPYBOT~1\SDHelper.dll O14 - IERESET.INF: START_PAGE_URL=http://www.club-vaio.sony-europe.com O15 - Trusted Zone: *.sony-europe.com O15 - Trusted Zone: *.sonystyle-europe.com O17 - HKLM\System\CCS\Services\Tcpip\..\{610D547F-0550-4F06-B944-116EF6AA733C}: NameServer = *IP*,*IP* O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - D:\Programme\AV\AntiVir PersonalEdition Classic\sched.exe O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - D:\Programme\AV\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\ati2evxx.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe O23 - Service: ServiceLayer - Nokia. - C:\Programme\Gemeinsame Dateien\PCSuite\Services\ServiceLayer.exe O23 - Service: Speed Disk service - Symantec Corporation - C:\Programme\Speed Disk\nopdb.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - C:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\SPTISRV.exe -- End of file - 4966 bytes Escan hat sich geschlagenen 13 Minuten mit der Untersuchung des gesamten Systems aufgehalten, bevor es abgeschaltet wurde. Hier das Ergebnis der find.bat: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "infected" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Mon Dec 10 11:29:20 2007 => System found infected with mirar Spyware/Adware (hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\net-nucleus.com)! Action taken: Keine Aktion vorgenommen. Mon Dec 10 11:34:50 2007 => [Scanne Ordner: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AntiVir PersonalEdition Classic\INFECTED] ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Funde für "tagged" ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Statisktiken: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Mon Dec 10 11:29:20 2007 => Offending Registry Entry found: hkey_local_machine\software\microsoft\windows\currentversion\internet settings\zonemap\domains\net-nucleus.com ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~ © Haui ;-) ~~~~~~~ ~~~~~~~ Dank an Cidre ~~~~~~~
__________________ |
10.12.2007, 13:29 | #4 | |
/// AVZ-Toolkit Guru | eScan bricht ab. Woran könnte das liegen? Hast du die IP editiert? Zitat:
Dein eScan log verstehe ich nicht so ganz.. Hast du die Anleitung haargenau befolgt? Kannst du verifizieren bei welcher Datei bzw. Ordner der scan abbricht? Magst du das komplette log, unausgewertet mal irgentwo hochladen? Vorher aber bitte das komplette log löschen und dann einen neuen Scan machen.. Sonst sind in dem Dokument alle Scan-Berichte drin und nicht nur der letzte..
__________________ - Sämtliche Hilfestellungen im Forum werden ohne Gewährleistung oder Haftung gegeben - |
11.12.2007, 13:08 | #5 |
| eScan bricht ab. Woran könnte das liegen? Hi, ich habe dasselbe Problem unter Windows Vista: wenn ich im abgesicherten Modus escan v. 9.5.9. laufen lasse, scannt das Programm erst ca. 1/2 h und dann bricht es plötzlich ab (schliesst sich!). davor wurden einige Viren/Troj. gefunden (unter anderetm Spyware infomonitor, win32.agent.fwc und win32.superjuan.ao). Hier der mwavXface.log: [msvL64.dll] [0x000007f0] 11/12/2007 10:34:27:219 :Process Name = C:\Users\Admin\AppData\Local\Temp\mexe.com [9.5.9.0] [msvL64.dll] [0x000007f0] 11/12/2007 10:34:27:219 LL Name = C:\Users\Admin\AppData\Local\Temp\msvl64.dll [5.0.0.22] [msvL64.dll] [0x000007f0] 11/12/2007 10:34:27:219 :Registry Key Deleted Properly!!! [msvL64.dll] [0x000007f0] 11/12/2007 10:34:27:219 :Setting LibPath to C:\Users\Admin\AppData\Local\Temp [Lib Version: 5.0.1.85] [msvL64.dll] [0x000007f0] 11/12/2007 10:34:29:825 atabase Path = C:\Users\Admin\AppData\Local\Temp [msvL64.dll] [0x000007f0] 11/12/2007 10:34:32:991 :Taken Backup of signatures in folder: C:\Users\Admin\AppData\Local\Temp\AVCBack [msvL64.dll] [0x000007f0] 11/12/2007 10:34:32:991 :Options Set by External applications mexe.com are 95 (0x5f): [msvL64.dll] [0x000007f0] 11/12/2007 10:34:32:991 :Mode :PACKED,ARCHIVED,CA,REDUNDANT,WARNINGS,MAILPLAIN [msvL64.dll] [0x000007f0] 11/12/2007 10:34:32:991 :TimeOut : 15 secs [msvL64.dll] [0x000007f0] 11/12/2007 10:34:32:991 :Priority : NORMAL [msvL64.dll] [0x000007f0] 11/12/2007 10:34:39:684 :VirusCount = 472863 Latest Date = 2007/12/05 [msvL64.dll] [0x000007f0] 11/12/2007 10:35:43:613 :Reload Function Succeeded. [msvL64.dll] [0x000007f0] 11/12/2007 10:35:43:644 :VirusCount = 479650 Latest Date = 2007/12/11 [msvL64.dll] [0x00000158] 11/12/2007 10:36:59:787 :Result For Object: "C:\Users\Admin\Desktop\mwav.exe". [msvL64.dll] [0x00000158] 11/12/2007 10:36:59:787 :ERROR : Timeout expired [msvL64.dll] [0x00000544] 11/12/2007 10:36:59:787 :File: "C:\Users\Admin\Desktop\mwav.exe" Scan was Cancelled! [msvL64.dll] [0x000002d8] 11/12/2007 10:36:59:787 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x00000544] 11/12/2007 10:37:43:405 :Result For Object: "C:\Windows\bthservsdp.dat". [msvL64.dll] [0x00000544] 11/12/2007 10:37:43:405 :ERROR : Access denied [msvL64.dll] [0x00000158] 11/12/2007 10:37:43:405 :File: "C:\Windows\bthservsdp.dat" Access Denied! [msvL64.dll] [0x000002d8] 11/12/2007 10:37:43:405 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Access Denied] [msvL64.dll] [0x00000544] 11/12/2007 10:38:04:590 :File: "C:\Windows\system32\ddccbcd.dll" Infected With "Trojan-Downloader.Win32.Agent.fwc". [msvL64.dll] [0x00000544] 11/12/2007 10:38:11:937 :File: "C:\Windows\system32\ewsnepfw.dll_possiblevirus" Infected With "not-a-virus:AdWare.Win32.SuperJuan.ao". [msvL64.dll] [0x00000158] 11/12/2007 10:39:33:369 :File: "C:\Windows\system32\yaywwxu.dll" Infected With "Trojan-Downloader.Win32.Agent.fwc". [msvL64.dll] [0x00000158] 11/12/2007 10:40:29:339 :Result For Object: "C:\$Recycle.Bin\S-1-5-21-2715920482-3163938950-140759060-1000\$REV9IB8\MSWorks\redist\ocp\O12Conv.cab". [msvL64.dll] [0x00000158] 11/12/2007 10:40:29:339 :ERROR : Timeout expired [msvL64.dll] [0x00000544] 11/12/2007 10:40:29:354 :File: "C:\$Recycle.Bin\S-1-5-21-2715920482-3163938950-140759060-1000\$REV9IB8\MSWorks\redist\ocp\O12Conv.cab" Scan was Cancelled! [msvL64.dll] [0x000002d8] 11/12/2007 10:40:29:354 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x00000544] 11/12/2007 10:40:44:751 :Result For Object: "C:\$Recycle.Bin\S-1-5-21-2715920482-3163938950-140759060-1000\$REV9IB8\MSWorks\redist\ppv\ppviewer.cab". [msvL64.dll] [0x00000544] 11/12/2007 10:40:44:751 :ERROR : Timeout expired [msvL64.dll] [0x00000158] 11/12/2007 10:40:44:767 :File: "C:\$Recycle.Bin\S-1-5-21-2715920482-3163938950-140759060-1000\$REV9IB8\MSWorks\redist\ppv\ppviewer.cab" Scan was Cancelled! [msvL64.dll] [0x000002d8] 11/12/2007 10:40:44:767 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x00000544] 11/12/2007 10:41:02:192 :Result For Object: "C:\Boot\BCD". [msvL64.dll] [0x00000544] 11/12/2007 10:41:02:192 :ERROR : Access denied [msvL64.dll] [0x00000158] 11/12/2007 10:41:02:192 :File: "C:\Boot\BCD" Access Denied! [msvL64.dll] [0x000002d8] 11/12/2007 10:41:02:192 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Access Denied] [msvL64.dll] [0x00000544] 11/12/2007 10:41:02:208 :Result For Object: "C:\Boot\BCD.LOG". [msvL64.dll] [0x00000544] 11/12/2007 10:41:02:208 :ERROR : Access denied [msvL64.dll] [0x00000158] 11/12/2007 10:41:02:208 :File: "C:\Boot\BCD.LOG" Access Denied! [msvL64.dll] [0x000002d8] 11/12/2007 10:41:02:208 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Access Denied] [msvL64.dll] [0x00000158] 11/12/2007 10:41:54:171 :Result For Object: "C:\MSOCache\All Users\90000407-6000-11D3-8CFE-0150048383C9\M4561410.CAB". [msvL64.dll] [0x00000158] 11/12/2007 10:41:54:171 :ERROR : Timeout expired [msvL64.dll] [0x00000544] 11/12/2007 10:41:54:171 :File: "C:\MSOCache\All Users\90000407-6000-11D3-8CFE-0150048383C9\M4561410.CAB" Scan was Cancelled! [msvL64.dll] [0x000002d8] 11/12/2007 10:41:54:171 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x00000158] 11/12/2007 10:42:26:947 :Result For Object: "C:\MSOCache\All Users\90000407-6000-11D3-8CFE-0150048383C9\ZC561401.CAB". [msvL64.dll] [0x00000158] 11/12/2007 10:42:26:947 :ERROR : Timeout expired [msvL64.dll] [0x00000544] 11/12/2007 10:42:26:947 :File: "C:\MSOCache\All Users\90000407-6000-11D3-8CFE-0150048383C9\ZC561401.CAB" Scan was Cancelled! [msvL64.dll] [0x000002d8] 11/12/2007 10:42:26:947 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x00000544] 11/12/2007 10:44:07:068 :Result For Object: "C:\nero\Installation\Cab\D6C89E66.cab". [msvL64.dll] [0x00000544] 11/12/2007 10:44:07:068 :ERROR : Timeout expired [msvL64.dll] [0x00000158] 11/12/2007 10:44:07:083 :File: "C:\nero\Installation\Cab\D6C89E66.cab" Scan was Cancelled! [msvL64.dll] [0x000002d8] 11/12/2007 10:44:07:083 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x00000544] 11/12/2007 10:44:31:622 :Result For Object: "C:\pagefile.sys". [msvL64.dll] [0x00000544] 11/12/2007 10:44:31:622 :ERROR : Access denied [msvL64.dll] [0x00000158] 11/12/2007 10:44:31:622 :File: "C:\pagefile.sys" Access Denied! [msvL64.dll] [0x000002d8] 11/12/2007 10:44:31:622 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Access Denied] [msvL64.dll] [0x00000158] 11/12/2007 10:49:02:516 :Result For Object: "C:\Program Files\Microsoft Office\OFFICE11\1031\HTMLREF.CHM". [msvL64.dll] [0x00000158] 11/12/2007 10:49:02:516 :ERROR : Timeout expired [msvL64.dll] [0x00000544] 11/12/2007 10:49:02:516 :File: "C:\Program Files\Microsoft Office\OFFICE11\1031\HTMLREF.CHM" Scan was Cancelled! [msvL64.dll] [0x000002d8] 11/12/2007 10:49:02:516 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x00000158] 11/12/2007 10:52:53:505 :Result For Object: "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a6d7e99bffd2b0868839f3319a084862_1b8a0431-c825-4556-a2e2-8cf7394eb03d". [msvL64.dll] [0x00000158] 11/12/2007 10:52:53:505 :ERROR : Access denied [msvL64.dll] [0x00000544] 11/12/2007 10:52:53:505 :File: "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a6d7e99bffd2b0868839f3319a084862_1b8a0431-c825-4556-a2e2-8cf7394eb03d" Access Denied! [msvL64.dll] [0x000002d8] 11/12/2007 10:52:53:505 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Access Denied] [msvL64.dll] [0x00000654] 11/12/2007 12:02:52:921 :Process Name = C:\Users\Admin\AppData\Local\Temp\mexe.com [9.5.9.0] [msvL64.dll] [0x00000654] 11/12/2007 12:02:52:921 LL Name = C:\Users\Admin\AppData\Local\Temp\msvl64.dll [5.0.0.22] [msvL64.dll] [0x00000654] 11/12/2007 12:02:52:921 :Registry Key Deleted Properly!!! [msvL64.dll] [0x00000654] 11/12/2007 12:02:52:921 :Setting LibPath to C:\Users\Admin\AppData\Local\Temp [Lib Version: 5.0.1.85] [msvL64.dll] [0x00000654] 11/12/2007 12:02:53:545 atabase Path = C:\Users\Admin\AppData\Local\Temp [msvL64.dll] [0x00000654] 11/12/2007 12:02:56:009 :Options Set by External applications mexe.com are 95 (0x5f): [msvL64.dll] [0x00000654] 11/12/2007 12:02:56:009 :Mode :PACKED,ARCHIVED,CA,REDUNDANT,WARNINGS,MAILPLAIN [msvL64.dll] [0x00000654] 11/12/2007 12:02:56:009 :TimeOut : 15 secs [msvL64.dll] [0x00000654] 11/12/2007 12:02:56:025 :Priority : NORMAL [msvL64.dll] [0x00000654] 11/12/2007 12:02:56:493 :VirusCount = 479666 Latest Date = 2007/12/11 [msvL64.dll] [0x0000065c] 11/12/2007 12:04:12:793 :Result For Object: "C:\Users\Admin\Desktop\mwav.exe". [msvL64.dll] [0x0000065c] 11/12/2007 12:04:12:793 :ERROR : Timeout expired [msvL64.dll] [0x000006d8] 11/12/2007 12:04:12:793 :File: "C:\Users\Admin\Desktop\mwav.exe" Scan was Cancelled! [msvL64.dll] [0x000002cc] 11/12/2007 12:04:12:793 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x0000065c] 11/12/2007 12:05:02:416 :Result For Object: "C:\Windows\bthservsdp.dat". [msvL64.dll] [0x0000065c] 11/12/2007 12:05:02:416 :ERROR : Access denied [msvL64.dll] [0x000006d8] 11/12/2007 12:05:02:416 :File: "C:\Windows\bthservsdp.dat" Access Denied! [msvL64.dll] [0x000002cc] 11/12/2007 12:05:02:416 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Access Denied] [msvL64.dll] [0x000006d8] 11/12/2007 12:05:23:227 :File: "C:\Windows\system32\ddccbcd.dll" Infected With "Trojan-Downloader.Win32.Agent.fwc". [msvL64.dll] [0x000006d8] 11/12/2007 12:05:30:371 :File: "C:\Windows\system32\ewsnepfw.dll_possiblevirus" Infected With "not-a-virus:AdWare.Win32.SuperJuan.ao". [msvL64.dll] [0x000006d8] 11/12/2007 12:06:55:672 :File: "C:\Windows\system32\yaywwxu.dll" Infected With "Trojan-Downloader.Win32.Agent.fwc". [msvL64.dll] [0x0000065c] 11/12/2007 12:07:54:671 :Result For Object: "C:\$Recycle.Bin\S-1-5-21-2715920482-3163938950-140759060-1000\$REV9IB8\MSWorks\redist\ocp\O12Conv.cab". [msvL64.dll] [0x0000065c] 11/12/2007 12:07:54:671 :ERROR : Timeout expired [msvL64.dll] [0x000006d8] 11/12/2007 12:07:54:687 :File: "C:\$Recycle.Bin\S-1-5-21-2715920482-3163938950-140759060-1000\$REV9IB8\MSWorks\redist\ocp\O12Conv.cab" Scan was Cancelled! [msvL64.dll] [0x000002cc] 11/12/2007 12:07:54:687 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x000006d8] 11/12/2007 12:08:10:115 :Result For Object: "C:\$Recycle.Bin\S-1-5-21-2715920482-3163938950-140759060-1000\$REV9IB8\MSWorks\redist\ppv\ppviewer.cab". [msvL64.dll] [0x000006d8] 11/12/2007 12:08:10:115 :ERROR : Timeout expired [msvL64.dll] [0x0000065c] 11/12/2007 12:08:10:131 :File: "C:\$Recycle.Bin\S-1-5-21-2715920482-3163938950-140759060-1000\$REV9IB8\MSWorks\redist\ppv\ppviewer.cab" Scan was Cancelled! [msvL64.dll] [0x000002cc] 11/12/2007 12:08:10:131 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x000006d8] 11/12/2007 12:08:28:789 :Result For Object: "C:\Boot\BCD". [msvL64.dll] [0x000006d8] 11/12/2007 12:08:28:789 :ERROR : Access denied [msvL64.dll] [0x0000065c] 11/12/2007 12:08:28:789 :File: "C:\Boot\BCD" Access Denied! [msvL64.dll] [0x000002cc] 11/12/2007 12:08:28:789 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Access Denied] [msvL64.dll] [0x000006d8] 11/12/2007 12:08:28:804 :Result For Object: "C:\Boot\BCD.LOG". [msvL64.dll] [0x000006d8] 11/12/2007 12:08:28:804 :ERROR : Access denied [msvL64.dll] [0x0000065c] 11/12/2007 12:08:28:804 :File: "C:\Boot\BCD.LOG" Access Denied! [msvL64.dll] [0x000002cc] 11/12/2007 12:08:28:804 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Access Denied] [msvL64.dll] [0x0000065c] 11/12/2007 12:09:21:189 :Result For Object: "C:\MSOCache\All Users\90000407-6000-11D3-8CFE-0150048383C9\M4561410.CAB". [msvL64.dll] [0x0000065c] 11/12/2007 12:09:21:189 :ERROR : Timeout expired [msvL64.dll] [0x000006d8] 11/12/2007 12:09:21:189 :File: "C:\MSOCache\All Users\90000407-6000-11D3-8CFE-0150048383C9\M4561410.CAB" Scan was Cancelled! [msvL64.dll] [0x000002cc] 11/12/2007 12:09:21:189 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x0000065c] 11/12/2007 12:09:52:732 :Result For Object: "C:\MSOCache\All Users\90000407-6000-11D3-8CFE-0150048383C9\ZC561401.CAB". [msvL64.dll] [0x0000065c] 11/12/2007 12:09:52:732 :ERROR : Timeout expired [msvL64.dll] [0x000006d8] 11/12/2007 12:09:52:732 :File: "C:\MSOCache\All Users\90000407-6000-11D3-8CFE-0150048383C9\ZC561401.CAB" Scan was Cancelled! [msvL64.dll] [0x000002cc] 11/12/2007 12:09:52:732 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x000006d8] 11/12/2007 12:11:29:390 :Result For Object: "C:\nero\Installation\Cab\D6C89E66.cab". [msvL64.dll] [0x000006d8] 11/12/2007 12:11:29:390 :ERROR : Timeout expired [msvL64.dll] [0x0000065c] 11/12/2007 12:11:29:405 :File: "C:\nero\Installation\Cab\D6C89E66.cab" Scan was Cancelled! [msvL64.dll] [0x000002cc] 11/12/2007 12:11:29:405 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x000006d8] 11/12/2007 12:11:53:492 :Result For Object: "C:\pagefile.sys". [msvL64.dll] [0x000006d8] 11/12/2007 12:11:53:492 :ERROR : Access denied [msvL64.dll] [0x0000065c] 11/12/2007 12:11:53:492 :File: "C:\pagefile.sys" Access Denied! [msvL64.dll] [0x000002cc] 11/12/2007 12:11:53:492 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Access Denied] [msvL64.dll] [0x0000065c] 11/12/2007 12:16:18:801 :Result For Object: "C:\Program Files\Microsoft Office\OFFICE11\1031\HTMLREF.CHM". [msvL64.dll] [0x0000065c] 11/12/2007 12:16:18:801 :ERROR : Timeout expired [msvL64.dll] [0x000006d8] 11/12/2007 12:16:18:801 :File: "C:\Program Files\Microsoft Office\OFFICE11\1031\HTMLREF.CHM" Scan was Cancelled! [msvL64.dll] [0x000002cc] 11/12/2007 12:16:18:801 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Scan Cancelled] [msvL64.dll] [0x0000065c] 11/12/2007 12:20:12:629 :Result For Object: "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a6d7e99bffd2b0868839f3319a084862_1b8a0431-c825-4556-a2e2-8cf7394eb03d". [msvL64.dll] [0x0000065c] 11/12/2007 12:20:12:629 :ERROR : Access denied [msvL64.dll] [0x000006d8] 11/12/2007 12:20:12:629 :File: "C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\a6d7e99bffd2b0868839f3319a084862_1b8a0431-c825-4556-a2e2-8cf7394eb03d" Access Denied! [msvL64.dll] [0x000002cc] 11/12/2007 12:20:12:629 :ERROR!!! ScanFile Function Failed! Reason: The function failed. [Result: Object Access Denied] [msvL64.dll] [0x000005f0] 11/12/2007 12:26:43:702 :Process Name = C:\Users\Admin\AppData\Local\Temp\mexe.com [9.5.9.0] [msvL64.dll] [0x000005f0] 11/12/2007 12:26:43:702 LL Name = C:\Users\Admin\AppData\Local\Temp\msvl64.dll [5.0.0.22] [msvL64.dll] [0x000005f0] 11/12/2007 12:26:43:702 :Registry Key Deleted Properly!!! [msvL64.dll] [0x000005f0] 11/12/2007 12:26:43:702 :Setting LibPath to C:\Users\Admin\AppData\Local\Temp [Lib Version: 5.0.1.85] [msvL64.dll] [0x000005f0] 11/12/2007 12:26:43:842 atabase Path = C:\Users\Admin\AppData\Local\Temp [msvL64.dll] [0x000005f0] 11/12/2007 12:26:46:385 :Options Set by External applications mexe.com are 95 (0x5f): [msvL64.dll] [0x000005f0] 11/12/2007 12:26:46:385 :Mode :PACKED,ARCHIVED,CA,REDUNDANT,WARNINGS,MAILPLAIN [msvL64.dll] [0x000005f0] 11/12/2007 12:26:46:385 :TimeOut : 15 secs [msvL64.dll] [0x000005f0] 11/12/2007 12:26:46:385 :Priority : NORMAL [msvL64.dll] [0x000005f0] 11/12/2007 12:26:46:853 :VirusCount = 479666 Latest Date = 2007/12/11 Bitte um Hilfe! Ramhunter0 |
12.12.2007, 17:11 | #6 | |||
| eScan bricht ab. Woran könnte das liegen?Zitat:
Zitat:
Haargenaues Befolgen der Anleitung ist nicht denkbar. Folgende sind die Punkte, die abweichen: 4. Als Sprache Englisch oder Deutsch wählen: Nicht möglich. Geht gleich ins Hauptmenü über. 6. Aktualisieren/Update anklicken und warten bis die Aktualisierung abgeschlossen ist: Fehlermeldung: "Download konnte nicht abegeschlossen werden." Neuinstallation des Programmes ändert daran nichts. Er bricht jedesmal bei der gleichen Datei ab. Leider komme ich nicht an sie ran, um sie mal von VirusTotal o. ä. prüfen zu lassen. Zitat:
__________________ --> eScan bricht ab. Woran könnte das liegen? Geändert von Cobrus (12.12.2007 um 18:07 Uhr) |
13.12.2007, 11:03 | #7 | ||
/// AVZ-Toolkit Guru | eScan bricht ab. Woran könnte das liegen?Zitat:
Zitat:
__________________ - Sämtliche Hilfestellungen im Forum werden ohne Gewährleistung oder Haftung gegeben - |
13.12.2007, 13:02 | #8 | ||
| eScan bricht ab. Woran könnte das liegen?Zitat:
Zitat:
__________________ Computer sind die logische Weiterentwicklung des Menschen: Intelligenz ohne Moral. (John Osborne) |
Themen zu eScan bricht ab. Woran könnte das liegen? |
abgesicherten modus, adobe, antivir, avira, bho, ctfmon.exe, enigma, escan, excel, fehler, file, firefox, hijack, hkus\s-1-5-18, internet, internet explorer, log, microsoft, mozilla, mozilla firefox, pdf, problem, programm, programme, s-1-5-18, security, security suite, software, spyware, symantec, system, windows |