Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Bitte auswerten! HILFE!!! (https://www.trojaner-board.de/18093-bitte-auswerten-hilfe.html)

Andimann 21.05.2005 18:54

Bitte auswerten! HILFE!!!
 
Liebe Forenmitglieder + Retter,
da ich ich nur einen begrenzten Horizont an Ahnung von PC's habe "muss" ich mich an euch wenden und um Hilfe rufen.
"HILFE!!!"
Hab seit 2 Wochen immer die AntiVir Warunung von so nem "POLLER Virus" und nem "ZPJHVSUJJNM Trojaner"! Da mir das fürchtbar viel sagt und da AntiVir den natürlich auch net komplett löschen kann oder überschreiben, da die beide in System32 sind... und ich die da auch nirgends finde, bin ich verzweifelt und bin, gottseidank, auf das Forum gestoßen und auf die SEHR GUTE Anleitung für eScan...
Bin für jede Antwort dankbar - in dem Sinne

ANDIMANN


P.S.
Hier natürlich noch meine Log Daten


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~
Funde für "infected"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~
Wed May 11 21:20:21 2005 => File C:\WINDOWS\svcproc.exe infected by "Trojan.Win32.Stervis.c" Virus. Action Taken: No Action Taken.
Wed May 11 21:20:23 2005 => System found infected with SideFind Spyware/Adware ({10e42047-deb9-4535-a118-b3f6ec39b807})! Action taken: No Action Taken.
Wed May 11 21:20:23 2005 => File System Found infected by "SideFind Spyware/Adware" Virus. Action Taken: No Action Taken.
Wed May 11 21:22:13 2005 => File C:\WINDOWS\system32\sfx_webhancer.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Wed May 11 21:24:17 2005 => File C:\DOKUME~1\Andi\LOKALE~1\TEMPOR~1\Content.IE5\19R ANQYB\istsvc[1].exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.
Wed May 11 21:24:23 2005 => File C:\DOKUME~1\Andi\LOKALE~1\TEMPOR~1\Content.IE5\YKO 6G2DE\sidefind13[1].dll infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken.
Wed May 11 21:24:23 2005 => File C:\DOKUME~1\Andi\LOKALE~1\TEMPOR~1\Content.IE5\YKO 6G2DE\svcproc[1].exe infected by "Trojan.Win32.Stervis.c" Virus. Action Taken: No Action Taken.
Wed May 11 21:31:40 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temporary Internet Files\Content.IE5\19RANQYB\istsvc[1].exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.
Wed May 11 21:31:45 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YKO6G2DE\sidefind13[1].dll infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken.
Wed May 11 21:31:45 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YKO6G2DE\svcproc[1].exe infected by "Trojan.Win32.Stervis.c" Virus. Action Taken: No Action Taken.
Wed May 11 21:40:50 2005 => File C:\Program Files\Win_whcr\webhancer_winrar.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Wed May 11 21:55:28 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.*
Thu May 19 18:27:02 2005 => C:\WINDOWS\svcproc.exe possibly infected and removed by background antivirus package!
Thu May 19 18:27:05 2005 => File C:\WINDOWS\svcproc.exe infected by "BkCln.Unknown" Virus. Action Taken: No Action Taken.
Thu May 19 18:27:07 2005 => System found infected with SideFind Spyware/Adware ({10e42047-deb9-4535-a118-b3f6ec39b807})! Action taken: No Action Taken.
Thu May 19 18:27:07 2005 => File System Found infected by "SideFind Spyware/Adware" Virus. Action Taken: No Action Taken.
Thu May 19 18:29:18 2005 => File C:\WINDOWS\system32\sfx_webhancer.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:55 2005 => Scanning Folder: C:\Programme\AVPersonal\INFECTED\*.*
Thu May 19 18:56:55 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.001
Thu May 19 18:56:55 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.001 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:55 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.002
Thu May 19 18:56:55 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.002 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:55 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.003
Thu May 19 18:56:56 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.003 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.004
Thu May 19 18:56:56 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.004 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.005
Thu May 19 18:56:56 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.005 infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.VIR
Thu May 19 18:56:56 2005 => File C:\Programme\AVPersonal\INFECTED\POLLER.EXE.VIR infected by "Trojan.Win32.Agent.cp" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:56 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 01
Thu May 19 18:56:57 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 01 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 02
Thu May 19 18:56:57 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 02 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 03
Thu May 19 18:56:57 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 03 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 04
Thu May 19 18:56:57 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 04 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:57 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 05
Thu May 19 18:56:58 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 05 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 06
Thu May 19 18:56:58 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 06 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 07
Thu May 19 18:56:58 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 07 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 08
Thu May 19 18:56:58 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 08 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:58 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 09
Thu May 19 18:56:59 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 09 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:59 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 10
Thu May 19 18:56:59 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.0 10 infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
Thu May 19 18:56:59 2005 => Scanning File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.V IR
Thu May 19 18:56:59 2005 => File C:\Programme\AVPersonal\INFECTED\ZPJHVSUJJNM.EXE.V IR infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010888.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010889.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010890.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010891.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010901.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:36:45 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0010903.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:37:02 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP75\A0012087.exe infected by "not-a-virus:AdWare.WebHancer.351" Virus. Action Taken: No Action Taken.
Thu May 19 19:37:08 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP77\A0012149.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:37:08 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP77\A0012150.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:37:10 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP77\A0012173.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:37:15 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012227.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:37:15 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012231.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:37:17 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012287.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:37:18 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012288.exe infected by "not-a-virus:AdWare.WebHancer.351" Virus. Action Taken: No Action Taken.
Thu May 19 19:37:18 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012291.dll infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:37:18 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012292.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 19:37:18 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP78\A0012294.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 20:54:44 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP96\A0014816.dll infected by "not-a-virus:AdWare.ToolBar.SideFind" Virus. Action Taken: No Action Taken.
Thu May 19 20:56:14 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP97\A0016058.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
Thu May 19 21:14:01 2005 => File C:\WINDOWS\system32\sfx_webhancer.exe infected by "not-a-virus:AdWare.WebHancer" Virus. Action Taken: No Action Taken.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~
Funde für "tagged"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~
Wed May 11 21:24:03 2005 => File C:\DOKUME~1\Andi\LOKALE~1\Temp\Temporäres Verzeichnis 1 für radmin22.zip\RADMIN22.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken.
Wed May 11 21:27:27 2005 => File C:\Dokumente und Einstellungen\Andi\Eigene Dateien\Downloads\vnc-4.0b5-x86_win32.exe tagged as not-a-virus:RiskWare.RemoteAdmin.WinVNC.4. No Action Taken.
Wed May 11 21:31:26 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temp\Temporäres Verzeichnis 1 für radmin22.zip\RADMIN22.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken.
Thu May 19 18:31:59 2005 => File C:\DOKUME~1\Andi\LOKALE~1\Temp\Temporäres Verzeichnis 1 für radmin22.zip\RADMIN22.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken.
Thu May 19 18:37:31 2005 => File C:\Dokumente und Einstellungen\Andi\Eigene Dateien\Downloads\vnc-4.0b5-x86_win32.exe tagged as not-a-virus:RiskWare.RemoteAdmin.WinVNC.4. No Action Taken.
Thu May 19 18:42:41 2005 => File C:\Dokumente und Einstellungen\Andi\Lokale Einstellungen\Temp\Temporäres Verzeichnis 1 für radmin22.zip\RADMIN22.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken.
Thu May 19 19:36:40 2005 => File C:\System Volume Information\_restore{821D6D7F-0007-48CE-83F5-D45228851C10}\RP72\A0009840.EXE tagged as not-a-virus:RiskWare.RemoteAdmin.RAdmin.22. No Action Taken.

Cidre 21.05.2005 19:12

Hallo Andimann,

deaktiviere die Systemwiederherstellung und wechsle anschließend in den abgesicherten Modus. Leere nun den Infected und den TIF Ordner [1] und lösche die restliche verbliebene Malware mit KillBox.

Erstelle mit Hilfe dieser bebilderten Anleitung ein HiJackThis Log-File und poste es.
Beachte die Hinweise!

[1] Rechtsklick auf IE -> Eigenschaften -> Reiter 'Allgemein' und unter Temporäre Internetdateien -> Dateien löschen -> 'Alle Offlineinhalte löschen' anhaken -> OK


Alle Zeitangaben in WEZ +1. Es ist jetzt 06:23 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131