Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   bitte log prüfen - hardware wird nicht erkannt (https://www.trojaner-board.de/12588-bitte-log-pruefen-hardware-erkannt.html)

slowhand1 22.01.2005 17:52

bitte log prüfen - hardware wird nicht erkannt
 
hallo,

habe seit einiger zeit folgendes problem. eine installierte firewire-karte wird zwar erkannt, es kommt aber die meldung, dass die software nicht gefunden wird. das selbe ist mir mit einem ipod passiert, obwohl die ipod-cd im player war. außerdem ist mein internet ziemlich angsam geworden. könntet ihr bitte das log prüfen. habe bereits spybot und adaware probiert.

Logfile of HijackThis v1.97.7
Scan saved at 17:48:57, on 22.01.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\Programme\ewido\security suite\ewidoctrl.exe
C:\Programme\ewido\security suite\ewidoguard.exe
C:\Programme\Norton AntiVirus\navapsvc.exe
C:\Programme\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\WinZip\WZQKPICK.EXE
C:\Programme\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Programme\hjt.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aon.at/portal
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.aon.at/portal
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Programme\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Programme\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] D:\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programme\WinZip\WZQKPICK.EXE
O4 - Global Startup: ZoneAlarm.lnk = C:\Programme\Zone Labs\ZoneAlarm\zonealarm.exe
O9 - Extra button: Recherche-Assistent (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O12 - Plugin for .spop: C:\Programme\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/tech...a/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-17.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/17de1586...dxIE601_de.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1093077346687
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} - http://v4.windowsupdate.microsoft.co...866.0038657407
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...a/SymAData.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/s...sh/swflash.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex...l_v1-0-3-0.cab
O16 - DPF: {F0BC061F-DAF9-4533-8011-53BCB4C10307} (Installations Assistent) - http://install.serviceurl.de/InstallationsAssistent.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{55755930-FD73-4A6E-BB22-D6DF867EBFCB}: NameServer = 195.3.96.67 195.3.96.68

HerrKautz 22.01.2005 17:55

Lad dir bitte die aktuelle Version von HijackThis runter und poste ein neues Log

http://hijackthis.de/downloads/hijackthis_199.zip

slowhand1 22.01.2005 18:01

hier das neue log:

Logfile of HijackThis v1.99.0
Scan saved at 18:00:56, on 22.01.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\Programme\ewido\security suite\ewidoctrl.exe
C:\Programme\ewido\security suite\ewidoguard.exe
C:\Programme\Norton AntiVirus\navapsvc.exe
C:\Programme\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Alcatel\SpeedTouch USB\Dragdiag.exe
C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
C:\WINDOWS\System32\ezSP_Px.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\WinZip\WZQKPICK.EXE
C:\Programme\Zone Labs\ZoneAlarm\zonealarm.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\PROGRA~1\WINZIP\winzip32.exe
C:\Dokumente und Einstellungen\walter\Lokale Einstellungen\Temp\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aon.at/portal
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.aon.at/portal
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Programme\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
O4 - HKLM\..\Run: [EM_EXEC] C:\PROGRA~1\Logitech\MOUSEW~1\SYSTEM\EM_EXEC.EXE
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb07.exe
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Programme\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [ezShieldProtector for Px] C:\WINDOWS\System32\ezSP_Px.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [iTunesHelper] D:\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programme\WinZip\WZQKPICK.EXE
O4 - Global Startup: ZoneAlarm.lnk = C:\Programme\Zone Labs\ZoneAlarm\zonealarm.exe
O9 - Extra button: Recherche-Assistent - {9455301C-CF6B-11D3-A266-00C04F689C50} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Encarta Researcher\EROPROJ.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programme\Internet Explorer\Plugins\NPDocBox.dll
O16 - DPF: {1F2F4C9E-6F09-47BC-970D-3C54734667FE} (LSSupCtl Class) - https://www-secure.symantec.com/tech...a/LSSupCtl.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/S...in/AvSniff.cab
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/acti..._v1-0-3-17.cab
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/17de1586...dxIE601_de.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1093077346687
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/S.../bin/cabsa.cab
O16 - DPF: {CE28D5D2-60CF-4C7D-9FE8-0F47A3308078} (ActiveDataInfo Class) - https://www-secure.symantec.com/tech...a/SymAData.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex...l_v1-0-3-0.cab
O16 - DPF: {F0BC061F-DAF9-4533-8011-53BCB4C10307} (Installations Assistent) - http://install.serviceurl.de/InstallationsAssistent.ocx
O17 - HKLM\System\CCS\Services\Tcpip\..\{55755930-FD73-4A6E-BB22-D6DF867EBFCB}: NameServer = 195.3.96.67 195.3.96.68
O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
O23 - Service: ewido security suite control - ewido networks - C:\Programme\ewido\security suite\ewidoctrl.exe
O23 - Service: ewido security suite guard - ewido networks - C:\Programme\ewido\security suite\ewidoguard.exe
O23 - Service: iPod Service - Apple Computer, Inc. - D:\bin\iPodService.exe
O23 - Service: Norton AntiVirus Auto-Protect-Dienst - Symantec Corporation - C:\Programme\Norton AntiVirus\navapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programme\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
O23 - Service: Sony SPTI Service - Sony Corporation - C:\PROGRA~1\GEMEIN~1\SONYSH~1\AVLib\Sptisrv.exe
O23 - Service: SymWMI Service - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe
O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

Chris14 22.01.2005 18:04

das log enthält nichts ungewöhnliches, außer einen dialer.
fixe mal diesen eintrag:
O16 - DPF: {F0BC061F-DAF9-4533-8011-53BCB4C10307} (Installations Assistent) - http://install.serviceurl.de/InstallationsAssistent.ocx

aber lade dir escan trotzdem runter und gehe genau nach dieser anleitung vor.
gehe dann wenn er fertig ist, wieder in den normalen modus, wo du die datei mwav.log öffnest, auf bearbeiten und anschließend auf suchen klickst
Gebe dann infected ein.Suche weiter,markiere die Treffer und kopiere sie ins forum

slowhand1 23.01.2005 12:50

das hat mwav.log ergeben. ich habe allerdings im abgesichertem modus diese dateien wie ich meine bereits entfernt. könnte das der grund für die problematische hardwareerkennung sein - hab ich mir vielleicht da etwas wichtiges gelöscht? bitte um prüfung

C:\WINDOWS\UnstSA2.exe infected by "TrojanDropper.Win32.Delf.z" Virus. Action Taken: No Action Taken.
Thu Nov 18 23:30:45 2004 => File C:\WINDOWS\system32\p2esocks_1023.dll infected by "Trojan.Win32.P2E.ak" Virus. Action Taken: No Action Taken
Thu Nov 18 23:31:09 2004 => File C:\WINDOWS\system32\smartbus.exe infected by "Trojan-Downloader.Win32.Lookme.g" Virus. Action Taken: No Action Taken

Thu Nov 18 23:31:55 2004 => File C:\DOKUME~1\walter\LOKALE~1\Temp\iinstall.exe infected by "TrojanDownloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Thu Nov 18 23:53:45 2004 => File C:\Dokumente und Einstellungen\miriam\Lokale Einstellungen\Temp\sp.html infected by "Trojan.JS.StartPage.u" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:04:01 2004 => File C:\Dokumente und Einstellungen\walter\Lokale Einstellungen\Temp\iinstall.exe infected by "TrojanDownloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:11:15 2004 => File C:\Programme\backup-20040910-143651-330.dll infected by "Trojan.Win32.P2E.ak" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:11:15 2004 => File C:\Programme\backup-20040910-143652-566.dll infected by "TrojanDownloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:27:29 2004 => File C:\Programme\Norton AntiVirus\Quarantine\0D2C0A67.tmp infected by "I-Worm.NetSky.aa" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:27:29 2004 => File C:\Programme\Norton AntiVirus\Quarantine\0DA963E5.tmp infected by "I-Worm.NetSky.aa" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:27:29 2004 => File C:\Programme\Norton AntiVirus\Quarantine\0DD05BBA.tmp infected by "I-Worm.NetSky.aa" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:27:29 2004 => File C:\Programme\Norton AntiVirus\Quarantine\33CD4D4D.tmp infected by "I-Worm.NetSky.aa" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:27:29 2004 => File C:\Programme\Norton AntiVirus\Quarantine\52051136.tmp infected by "I-Worm.NetSky.aa" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:27:29 2004 => File C:\Programme\Norton AntiVirus\Quarantine\54FE3286.tmp infected by "I-Worm.NetSky.aa" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:30:16 2004 => File C:\RECYCLER\S-1-5-21-1778060467-2796855311-768402015-1007\Dc7.html infected by "Trojan.JS.StartPage.u" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:32:42 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP220\A0034977.dll infected by "Trojan.Win32.P2E.ak" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:43:40 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP238\A0042267.exe infected by "TrojanDownloader.Win32.Dyfuca.da" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:43:41 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP238\A0042271.exe infected by "TrojanDownloader.Win32.Dyfuca.da" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:46:00 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP264\A0045232.exe infected by "TrojanDropper.Win32.Delf.z" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:46:00 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP264\A0045233.dll infected by "Trojan.Win32.P2E.ak" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:46:00 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP264\A0045234.exe infected by "Trojan-Downloader.Win32.Lookme.g" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:46:01 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP264\A0045235.dll infected by "Trojan.Win32.P2E.ak" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:46:01 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP264\A0045236.dll infected by "TrojanDownloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:46:03 2004 => File C:\temp\Installer2.exe infected by "TrojanDropper.Win32.Delf.z" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:52:58 2004 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\058439as.exe infected by "Trojan.Win32.Dialer.az" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:52:58 2004 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\ISTactivex.dll infected by "Trojan-Downloader.Win32.IstBar.fz" Virus. Action Taken: No Action Taken.

Fri Nov 19 00:52:59 2004 => File C:\WINDOWS\Downloaded Program Files\ISTactivex.dll infected by "TrojanDownloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Fri Nov 19 01:22:06 2004 => File C:\winhelp.chm infected by "Trojan.Win32.Dialer.ce" Virus. Action Taken: No Action Taken.

Fri Nov 19 06:29:59 2004 => File C:\!Submit\backup-20040910-143651-330.dll infected by "Trojan.Win32.P2E.ak" Virus. Action Taken: No Action Taken.

Fri Nov 19 06:29:59 2004 => File C:\!Submit\backup-20040910-143652-566.dll infected by "TrojanDownloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Fri Nov 19 06:30:00 2004 => File C:\!Submit\iinstall.exe infected by "TrojanDownloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Fri Nov 19 06:30:00 2004 => File C:\!Submit\p2esocks_1023.dll infected by "Trojan.Win32.P2E.ak" Virus. Action Taken: No Action Taken.

Fri Nov 19 06:30:00 2004 => File C:\!Submit\smartbus.exe infected by "Trojan-Downloader.Win32.Lookme.g" Virus. Action Taken: No Action Taken.

Fri Nov 19 06:30:00 2004 => File C:\!Submit\sp.html infected by "Trojan.JS.StartPage.u" Virus. Action Taken: No Action Taken.

slowhand1 23.01.2005 12:51

hier ist die fortsetzung:


Fri Nov 19 06:30:00 2004 => File C:\!Submit\UnstSA2.exe infected by "TrojanDropper.Win32.Delf.z" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:22:44 2004 => File C:\Programme\Norton AntiVirus\Quarantine\0D2C0A67.tmp infected by "I-Worm.NetSky.aa" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:22:44 2004 => File C:\Programme\Norton AntiVirus\Quarantine\0DA963E5.tmp infected by "I-Worm.NetSky.aa" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:22:44 2004 => File C:\Programme\Norton AntiVirus\Quarantine\0DD05BBA.tmp infected by "I-Worm.NetSky.aa" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:22:44 2004 => File C:\Programme\Norton AntiVirus\Quarantine\33CD4D4D.tmp infected by "I-Worm.NetSky.aa" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:22:44 2004 => File C:\Programme\Norton AntiVirus\Quarantine\52051136.tmp infected by "I-Worm.NetSky.aa" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:22:44 2004 => File C:\Programme\Norton AntiVirus\Quarantine\54FE3286.tmp infected by "I-Worm.NetSky.aa" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:25:19 2004 => File C:\RECYCLER\S-1-5-21-1778060467-2796855311-768402015-1007\Dc7.html infected by "Trojan.JS.StartPage.u" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:27:43 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP220\A0034977.dll infected by "Trojan.Win32.P2E.ak" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:38:38 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP238\A0042267.exe infected by "TrojanDownloader.Win32.Dyfuca.da" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:38:39 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP238\A0042271.exe infected by "TrojanDownloader.Win32.Dyfuca.da" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:40:54 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP264\A0045232.exe infected by "TrojanDropper.Win32.Delf.z" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:40:54 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP264\A0045233.dll infected by "Trojan.Win32.P2E.ak" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:40:55 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP264\A0045234.exe infected by "Trojan-Downloader.Win32.Lookme.g" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:40:55 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP264\A0045235.dll infected by "Trojan.Win32.P2E.ak" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:40:55 2004 => File C:\System Volume Information\_restore{54E7B767-123F-48A2-8687-619C2A973D25}\RP264\A0045236.dll infected by "TrojanDownloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:40:57 2004 => File C:\temp\Installer2.exe infected by "TrojanDropper.Win32.Delf.z" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:47:49 2004 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\058439as.exe infected by "Trojan.Win32.Dialer.az" Virus. Action Taken: No Action Taken.

Fri Nov 19 07:47:49 2004 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\ISTactivex.dll infected by "Trojan-Downloader.Win32.IstBar.fz" Virus. Action Taken: No Action Taken.
Fri Nov 19 07:47:50 2004 => File C:\WINDOWS\Downloaded Program Files\ISTactivex.dll infected by "TrojanDownloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.

Fri Nov 19 08:16:31 2004 => File C:\winhelp.chm infected by "Trojan.Win32.Dialer.ce" Virus. Action Taken: No Action Taken.

Sat Jan 22 21:12:57 2005 => File C:\WINDOWS\system32\seqsb.dll infected by "not-a-virus:AdWare.ToolBar.Neon.c" Virus. Action Taken: No Action Taken.

Sat Jan 22 21:13:26 2005 => File C:\WINDOWS\Q3669140.exe infected by "Trojan-Downloader.JS.Small.ac" Virus. Action Taken: No Action Taken.

Sat Jan 22 21:13:26 2005 => File C:\WINDOWS\Q3669281.exe infected by "Trojan-Downloader.JS.Small.ac" Virus. Action Taken: No Action Taken.

Sat Jan 22 21:16:05 2005 => File C:\WINDOWS\system32\uninistneo.exe infected by "not-a-virus:AdWare.ToolBar.Neon.c" Virus. Action Taken: No Action Taken.

Sat Jan 22 22:04:02 2005 => File C:\Dokumente und Einstellungen\walter\Eigene Dateien\universal.zip infected by "Trojan.Win32.StartPage.bf" Virus. Action Taken: No Action Taken.

Sat Jan 22 22:35:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\1F8553DB infected by "not-a-virus:Porn-Dialer.Win32.Intexdial" Virus. Action Taken: No Action Taken.

Sat Jan 22 22:35:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\5DEA7063 infected by "not-a-virus:AdWare.WinAD.b" Virus. Action Taken: No Action Taken.

Sat Jan 22 22:46:40 2005 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll infected by "not-a-virus:AdWare.Gator.1019" Virus. Action Taken: No Action Taken.

Sat Jan 22 22:46:40 2005 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1019.dll infected by "not-a-virus:AdWare.Gator.1019" Virus. Action Taken: No Action Taken.

Sat Jan 22 23:06:07 2005 => File C:\WINDOWS\Q3669140.exe infected by "Trojan-Downloader.JS.Small.ac" Virus. Action Taken: No Action Taken.

Sat Jan 22 23:06:07 2005 => File C:\WINDOWS\Q3669281.exe infected by "Trojan-Downloader.JS.Small.ac" Virus. Action Taken: No Action Taken.

Sat Jan 22 23:16:00 2005 => File C:\WINDOWS\system32\uninistneo.exe infected by "not-a-virus:AdWare.ToolBar.Neon.c" Virus. Action Taken: No Action Taken.

Sat Jan 22 23:17:08 2005 => File C:\WINDOWS\Temp\SearchBar\Run.exe infected by "not-a-virus:AdWare.WinAD.b" Virus. Action Taken: No Action Taken.

Focus 23.01.2005 16:26

alternativ:
Zitat:

Manuelle Entfernung von Viren

Sichtbarmachen von Dateien und Ordnern: --> Windows Explorer -> "Extras/Ordneroptionen" -> "Ansicht" -> Haken entfernen bei "Geschützte Systemdateien ausblenden (empfohlen)" und "Alle Dateien und Ordner anzeigen" aktivieren.

Dialer-Dateien vor Entfernung auf Diskette sichern: Dialerschutz
nicht löschen: C:\System Volume Information\_restore- u. Tool.Win32.Reboot - Einträge
Ordner leeren: C:\Programme\Norton AntiVirus\Quarantine
Temporäre Ordner leeren: Clear Prog downloaden. Häkchen bei "Clear all" u. auf "Clear" klicken.
Adware: Entfernungstools zur System-Bereinigung.

In abgesicherten Modus booten, bei winXP u. winME Systemwiederherstellung deaktivieren, Datei(en) markieren/kopieren, in die Windows Suche übertragen, löschen. Nach dem Löschvorgang in normalen Modus booten. Systemwiederherstellung bei winXP u. winME aktivieren. Neu booten.


Alle Zeitangaben in WEZ +1. Es ist jetzt 17:15 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131