|
Log-Analyse und Auswertung: Probleme wg. worm.win32netskyWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
19.01.2008, 00:33 | #16 |
| Probleme wg. worm.win32netsky Hallo Jaipur, hab alles so gemacht wie Du gesagt hast: 1. Java deinstalliert 2. CCleaner: gescannt und geloescht, Registry ebenfalls 3. PC-Neustart im abgesicherten Modus 4. Scannen und loeschen mit Spybot und Adaware 5. CCleaner im abgesicherten Modus 6. Scannen mit Antivir, hier das Ergebnis: AntiVir PersonalEdition Classic Report file date: Freitag, 18. Januar 2008 20:36 Scanning for 1054433 virus strains and unwanted programs. Licensed to: Avira AntiVir PersonalEdition Classic Serial number: 0000149996-ADJIE-0001 Platform: Windows XP Windows version: (Service Pack 2, v.2096) [5.1.2600] Username: Administrator Computer name: RICK Version information: BUILD.DAT : 270 15603 Bytes 19.09.2007 13:32:00 AVSCAN.EXE : 7.0.6.1 290856 Bytes 05.09.2007 23:12:10 AVSCAN.DLL : 7.0.6.0 49192 Bytes 05.09.2007 23:12:10 LUKE.DLL : 7.0.5.3 147496 Bytes 05.09.2007 23:12:12 LUKERES.DLL : 7.0.6.1 10280 Bytes 05.09.2007 23:12:12 ANTIVIR0.VDF : 6.40.0.0 11030528 Bytes 18.07.2007 22:57:36 ANTIVIR1.VDF : 7.0.1.95 3367424 Bytes 14.12.2007 20:57:58 ANTIVIR2.VDF : 7.0.2.0 948736 Bytes 15.01.2008 22:40:44 ANTIVIR3.VDF : 7.0.2.15 191488 Bytes 17.01.2008 22:40:26 AVEWIN32.DLL : 7.6.0.48 3080704 Bytes 15.01.2008 22:40:44 AVWINLL.DLL : 1.0.0.7 14376 Bytes 20.04.2007 22:55:42 AVPREF.DLL : 7.0.2.2 25640 Bytes 05.09.2007 23:12:10 AVREP.DLL : 7.0.0.1 155688 Bytes 20.04.2007 22:55:42 AVPACK32.DLL : 7.6.0.3 360488 Bytes 15.01.2008 22:40:44 AVREG.DLL : 7.0.1.6 30760 Bytes 05.09.2007 23:12:10 AVARKT.DLL : 1.0.0.20 278568 Bytes 05.09.2007 23:12:08 AVEVTLOG.DLL : 7.0.0.20 86056 Bytes 05.09.2007 23:12:08 NETNT.DLL : 7.0.0.0 7720 Bytes 20.04.2007 22:55:42 RCIMAGE.DLL : 7.0.1.30 2342952 Bytes 05.09.2007 23:12:02 RCTEXT.DLL : 7.0.62.0 86056 Bytes 05.09.2007 23:12:02 SQLITE3.DLL : 3.3.17.1 339968 Bytes 05.09.2007 23:12:12 Configuration settings for the scan: Jobname..........................: Manual Selection Configuration file...............: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\AntiVir PersonalEdition Classic\PROFILES\folder.avp Logging..........................: low Primary action...................: interactive Secondary action.................: ignore Scan master boot sector..........: off Scan boot sector.................: off Scan memory......................: on Process scan.....................: on Scan registry....................: on Search for rootkits..............: off Scan all files...................: Intelligent file selection Scan archives....................: on Recursion depth..................: 20 Smart extensions.................: on Macro heuristic..................: on File heuristic...................: medium Start of the scan: Freitag, 18. Januar 2008 20:36 The scan of running processes will be started Scan process 'avscan.exe' - '1' Module(s) have been scanned Scan process 'avcenter.exe' - '1' Module(s) have been scanned Scan process 'Explorer.EXE' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'aawservice.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'svchost.exe' - '1' Module(s) have been scanned Scan process 'lsass.exe' - '1' Module(s) have been scanned Scan process 'services.exe' - '1' Module(s) have been scanned Scan process 'winlogon.exe' - '1' Module(s) have been scanned Scan process 'csrss.exe' - '1' Module(s) have been scanned Scan process 'smss.exe' - '1' Module(s) have been scanned 12 processes with 12 modules were scanned Starting to scan the registry. The registry was scanned ( '22' files ). Starting the file scan: Begin scan in 'C:\' <ACER> C:\pagefile.sys [WARNING] The file could not be opened! C:\Dokumente und Einstellungen\user\Eigene Dateien\SmitfraudFix.zip [0] Archive type: ZIP --> SmitfraudFix/SmiUpdate.exe [DETECTION] Is the Trojan horse TR/VB.20480 [WARNING] The file was ignored! C:\Dokumente und Einstellungen\user\Eigene Dateien\SmitfraudFix\SmitfraudFix\SmiUpdate.exe [DETECTION] Is the Trojan horse TR/VB.20480 [WARNING] The file was ignored! End of the scan: Freitag, 18. Januar 2008 22:02 Used time: 1:26:27 min The scan has been done completely. 10050 Scanning directories 240714 Files were scanned 2 viruses and/or unwanted programs were found 0 Files were classified as suspicious: 0 files were deleted 0 files were repaired 0 files were moved to quarantine 0 files were renamed 1 Files cannot be scanned 240712 Files not concerned 6886 Archives were scanned 3 Warnings 0 Notes ___________________________________________________________________________ 7. PC Neustart normal 8. Alle Scans noch einmal, hier das Ergebnis: CCleaner: Ergebnis CCleaner Registry Cleaner: Problem: Daten: Registry-Schluessel: - Ungueltige Dateiendungen (327C8820-8DED-4BD2-A7F6-D07B9DD5698F) HKCR\(327C8820-8DED-4BD2-A7F6-D07B9DD5698F) - ungueltige Dateiendungem (A4B980AE-402C-4EA49D1B-83A7A8CEE7E4) HKCR\(A4B980AE-402C-4EA49D1B-83A7A8CEE7E4) ______________________________________________________________ Spybot: KEINE SPIONE GEFUNDEN! _______________________________________________________________ Adaware (kompl Report im Anhang): Ad-Aware 2007 Build Log File Created on: 2008-01-18 23:11:33 Using Definitions File: C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Lavasoft\Ad-Aware 2007\core.aawdef Computer name: RICK Name of user performing scan: SYSTEM System information =========================== Number of processors: 1 Processor type: Intel(R) Pentium(R) M processor 1.73GHz Memory Available: 56% Total Physical Memory: 1063305216 Bytes Available Physical Memory: 591851520 Bytes Total Page File Size: 2563792896 Bytes Available On Page File: 2180374528 Bytes Total Virtual Memory: 2147352576 Bytes Available Virtual Memory: 2003877888 Bytes OS: Microsoft Windows XP Service Pack 2, v.2096 (Build 2600) Ad-Aware 2007 Settings =========================== Skipping files larger than 1048576 kB Ignoring infections with lower TAI than: 3 Extended Ad-Aware 2007 Settings =========================== Unloading known modules during scan Ignoring spanned files when scanning cab archives Reanalyzing results after scanning before displaying results Trying to unload modules prior to removal Let Windows remove files currently in use at next reboot Removing quarantined objects after restore Deactivating Ad-Watch during scans Writeprotecting system files after repairs Include info about ignored objects in log file Including basic settings in log file Including advanced settings in log file Including user and computer name in log file Notify when Definitions File is outdated Create and save WebUpdate log file Databaseinfo =========================== Version number: 44 Build Number: 0 Build Date and Time: 2008/01/14 09:22:58 Scan Statistics =========================== Method: Smart Scan tracking cookies.............................: On Scan ADS filestreams..............................: Off Item Scanned: 106675 Infections Detected: 1 Infections Ignored: 0 Scan detailed statistics =========================== Type Critical Total Process Scan....: 0 0 Registry Scan...: 0 0 Registry PE Scan: 0 0 Hosts File Scan.: 0 0 File Scan.......: 0 0 Folder Scan.....: 0 0 LSP Scan........: 0 0 ADS Scan........: 0 0 Cookie Scan.....: 0 0 File Hash Scan..: 0 0 Infections Found =========================== Family Id: 9999 Name: MRU Object Category: MRU Object TAI:0 Item Id: 1 Value: MRU Path: C:\Dokumente und Einstellungen\user\Recent Count: 4 Items Ignored During Scan =========================== |
22.01.2008, 00:14 | #17 |
| Probleme wg. worm.win32netsky Hallo,
__________________waere euch sehr dankbar, wenn noch mal jemand auf diese scan-ergebnisse schauen kann. trotz loeschen mit ccleaner, spybot und adaware scheint es immer noch malware zu geben. bin nach wie vor ratlos und leider nicht in der lage, jeden tag online zu gehen, sonst waere das problem wahrscheinlich schon behoben. derzeit zeigt sich als einzig uebrig gebliebene stoerung nur, das die Internetseiten wesentl laenger brauchen, bis sie geladen sind... vielen dank im voraus! |
Themen zu Probleme wg. worm.win32netsky |
adaware, antispyware, antivir, anzeige, aufrufe, automatisch, automatische, computer, eingestellt, fenster, gen, hijack, hijackthis, internet-explorer, kein bild, kleine, kleinen, meldungen, probleme, rechner, silentrunner, smitfraudfix, spybot, systemsteuerung, taskmanager, viren, warnmeldungen |