Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Ping(Counterstrike) bei 1000! (https://www.trojaner-board.de/18129-ping-counterstrike-1000-a.html)

Killu 21.05.2005 16:22

Brauche Dringend LogFile Auswertung!!! Ping bei Counterstrike ca. bei 600 :(
 
Hio Leuts
hab n dummes Problem seit mein Norton AntiVir Abo abgelaufen ist!
hab mir wahrscheinlich direkt danach n virus eingefangen oda Trojaner oda wat weiss ich auf jeden Fall is mein Ping bei Counterstrike (normalerweise 20) jetzt auf 600 oder höher!
Ich brauche UNBEDINGT eure Hilfe!!! Hier mein Logfile von HijackThis:


Logfile of HijackThis v1.99.1
Scan saved at 17:16:46, on 21.05.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
C:\Programme\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe
C:\Programme\Norton AntiVirus\SAVScan.exe
C:\WINDOWS\Explorer.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\WINDOWS\system32\rundll32.exe
C:\WINDOWS\Dit.exe
C:\Programme\ICQLite\ICQLite.exe
C:\Program Files\Kdlgddl\Rzqdnsp.exe
C:\Programme\Java\jre1.5.0_02\bin\jusched.exe
C:\Program Files\Media Access\MediaAccK.exe
c:\windows\system32\ghbqhrp.exe
C:\WINDOWS\DitExp.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Tools\Steam\Steam.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Programme\Adobe\Acrobat 5.0\Reader\AcroRd32.exe
C:\Programme\Tools\LeechGet 2004\LeechGet.exe
C:\PROGRA~1\Lavasoft\AD-AWA~1\Ad-Aware.exe
C:\Program Files\Media Access\MediaAccess.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\Tools\eMule\Incoming\hijackthis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = h**p://google.icq.com/search/search_frame.php
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://google.icq.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://www.google.de/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = h**p://www.google.de/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {17D84409-9F46-16D4-D352-105509AD2C69} - C:\WINDOWS\System32\hlxddq.dll (file missing)
O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Programme\NewDotNet\newdotnet6_38.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Tools\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar2.dll
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: (no name) - {4B56CCDF-3BCC-4FCF-99E8-E35A667B9C02} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar2.dll
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [CloneDVDElbyDelay] "C:\Programme\Elaborate Bytes\CloneDVD\ElbyCheck.exe" /L ElbyDelay
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [Dit] Dit.exe
O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe /Consumer
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [Rdbwn] C:\Program Files\Kdlgddl\Rzqdnsp.exe
O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\Programme\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_02\bin\jusched.exe
O4 - HKLM\..\Run: [Media Access] C:\Program Files\Media Access\MediaAccK.exe
O4 - HKLM\..\Run: [odylwjyx] C:\WINDOWS\odylwjyx.exe
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
O4 - HKLM\..\Run: [mywcjl] c:\windows\system32\ghbqhrp.exe
O4 - HKCU\..\Run: [Spbe] C:\Dokumente und Einstellungen\Felix\Anwendungsdaten\thta.exe
O4 - HKCU\..\Run: [Ssrojcx] C:\WINDOWS\System32\rmh.exe
O4 - HKCU\..\Run: [Steam] "c:\programme\tools\steam\steam.exe" -silent
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot
O8 - Extra context menu item: &Google Search - res://c:\programme\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML
O8 - Extra context menu item: Backward Links - res://c:\programme\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\programme\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Mit dem LeechGet Wizard laden - file://C:\Programme\Tools\LeechGet 2004\\Wizard.html
O8 - Extra context menu item: Mit LeechGet herunterladen - file://C:\Programme\Tools\LeechGet 2004\\AddUrl.html
O8 - Extra context menu item: Mit LeechGet parsen - file://C:\Programme\Tools\LeechGet 2004\\Parser.html
O8 - Extra context menu item: Similar Pages - res://c:\programme\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\programme\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_02\bin\npjpi150_02.dll
O9 - Extra button: Preispiraten 2.1.1 - {86DE8B3B-1EB7-4386-84BD-EBE94348A913} - C:\Programme\Tools\Preispiraten\Preispiraten2\preispiraten2ie.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: eBay Homepage - {D4951B60-8FF9-4813-B716-FF3E75386E74} - h**p://www.preispiraten.de/cgi-bin/e/tracker_short.pl?http://www.ebay.de (file missing)
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - C:\Programme\Tools\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Programme\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - h**p://static.windupdates.com/cab/MediaAccess/ie/bridge-c5.cab
O16 - DPF: {8FA9D107-547B-4DBC-9D88-FABD891EDB0A} (shizmoo Class) - h**p://playroom.icq.com/odyssey_web11.cab
O16 - DPF: {91433D86-9F27-402C-B5E3-DEBDD122C339} - h**p://www.netvenda.com/sites/games-intl/de/games4.cab
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - h**p://messenger.msn.com/download/msnmessengersetupdownloader.cab
O16 - DPF: {C5E28B9D-0A68-4B50-94E9-E8F6B4697514} (NsvPlayX Control) - h**p://www.nullsoft.com/nsv/embed/nsvplayx_vp3_mp3.cab
O16 - DPF: {D7A4D8FB-83F0-40E5-954F-88F48D15AE96} (ICQVideoWindow Class) - h**p://xtraz.icq.com/xtraz/activex/ICQVideoControl.cab
O16 - DPF: {FB48C7B0-EB66-4BE6-A1C5-9DDF3C37249A} (MCSendMessageHandler Class) - h**p://xtraz.icq.com/xtraz/activex/MISBH.cab
O18 - Filter: text/html - {2AAB780E-9B5B-4A26-BD27-1E459BAA3B0B} - C:\Dokumente und Einstellungen\Felix\Lokale Einstellungen\Anwendungsdaten\microsoft\internet explorer\V0.26.dat
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Network Proxy (ccProxy) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccProxy.exe
O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe
O23 - Service: Norton AntiVirus Auto-Protect-Dienst (navapsvc) - Symantec Corporation - C:\Programme\Norton AntiVirus\navapsvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: SAVScan - Symantec Corporation - C:\Programme\Norton AntiVirus\SAVScan.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
O23 - Service: SymWMI Service (SymWSC) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe

Hoffentlich findet ihr das Problem
Danke schonma

Felix

_____________
Anm.
Aktive Links editiert!
Beachte die Hinweise dieser Anleitung: HiJackThis

LG Cidre
S-Mod TB

Meerjungfraumann 21.05.2005 16:35

Servus,
lass mal das AdAware im abgesicherten Windows Modus durchlaufen und berichte ob und was er gefunden hatt.Findet meistens im abgesicherten Modus mehr als im normalen da sich manche Sachen im normalen Modus verbergen können.Weil wenn da ein Programm im Hintergrund mitläuft ist es kein Wunder das Dein Ping verändert ist.Und erneuere Dein Abo bei Symantec sonst bist Du vor neuen Bedrohungen nicht mehr geschützt.

Greetings from Meerjungfraumann (Spongebob Member) :D :zzwhip:

chaosman 21.05.2005 16:41

@Killu
du hast jede menge malware im system,
überprüfe dein system bitte mit escan
chaosman

Rene-gad 21.05.2005 16:46

Die Kollegen waren schneller, aber trotzdem poste ich mein Traktat ;):
@Killu
Bitte alle Links im Log deaktivieren (z.B. h**p statt http)
Zitat:

hab n dummes Problem seit mein Norton AntiVir Abo abgelaufen ist!
Freu dich und kaufe dir ein anständiges Programm.
New.Net und Ebates_MoeMoneyMaker musst du über Systemsteuerung/Software am besten im abgesicherten Modus deinstallieren.
Im abgesicherten Modus löschen
Zitat:

C:\Program Files\Kdlgddl\Rzqdnsp.exe
c:\windows\system32\ghbqhrp.exe
C:\WINDOWS\Nail.exe
C:\WINDOWS\satmat.exe
C:\Program Files\Kdlgddl\Rzqdnsp.exe
C:\WINDOWS\odylwjyx.exe
C:\WINDOWS\system32\gah95on6.exe
C:\Dokumente und Einstellungen\Felix\Anwendungsdaten\thta.exe
C:\WINDOWS\System32\rmh.exe
C:\Dokumente und Einstellungen\Felix\Lokale Einstellungen\Anwendungsdaten\microsoft\internet explorer\V0.26.dat
C:\WINDOWS\svcproc.exe
Einträge fixen:
Zitat:

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:blank
F2 - REG:system.ini: Shell=Explorer.exe C:\WINDOWS\Nail.exe
O2 - BHO: (no name) - {17D84409-9F46-16D4-D352-105509AD2C69} - C:\WINDOWS\System32\hlxddq.dll (file missing)
O2 - BHO: URLLink Class - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - C:\Programme\NewDotNet\newdotnet6_38.dll
O3 - Toolbar: (no name) - {4B56CCDF-3BCC-4FCF-99E8-E35A667B9C02} - (no file)
O4 - HKLM\..\Run: [New.net Startup] rundll32 C:\PROGRA~1\NEWDOT~1\NEWDOT~2.DLL,NewDotNetStartup -s
O4 - HKLM\..\Run: [satmat] C:\WINDOWS\satmat.exe
O4 - HKLM\..\Run: [Rdbwn] C:\Program Files\Kdlgddl\Rzqdnsp.exe
O4 - HKLM\..\Run: [EbatesMoeMoneyMaker0] "C:\Programme\Ebates_MoeMoneyMaker\EbatesMoeMoneyMaker0.exe"
O4 - HKLM\..\Run: [odylwjyx] C:\WINDOWS\odylwjyx.exe
O4 - HKLM\..\Run: [gah95on6] C:\WINDOWS\system32\gah95on6.exe
O4 - HKLM\..\Run: [mywcjl] c:\windows\system32\ghbqhrp.exe
O4 - HKCU\..\Run: [Spbe] C:\Dokumente und Einstellungen\Felix\Anwendungsdaten\thta.exe
O4 - HKCU\..\Run: [Ssrojcx] C:\WINDOWS\System32\rmh.exe
O9 - Extra button: Ebates - {6685509E-B47B-4f47-8E16-9A5F3A62F683} - file://C:\Programme\Ebates_MoeMoneyMaker\Sy350\Tp350\scri350a.htm (file missing) (HKCU)
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O16 - DPF: {15AD6789-CDB4-47E1-A9DA-992EE8E6BAD6} - http://h**p://static.windupdates.com.../bridge-c5.cab
O18 - Filter: text/html - {2AAB780E-9B5B-4A26-BD27-1E459BAA3B0B} - C:\Dokumente und Einstellungen\Felix\Lokale Einstellungen\Anwendungsdaten\microsoft\internet explorer\V0.26.dat
O23 - Service: System Startup Service (SvcProc) - Unknown owner - C:\WINDOWS\svcproc.exe
BTW:Wenn dein Verhalten im Internet sich nicht ändert, hiflt dir kein Antivirus-Programm

Killu 21.05.2005 16:53

ok dann werd ich das ma machen
danke!!!

Otrebor 21.05.2005 16:59

Kann der Killu sich die sachen eingefangen haben als Norton Antivir noch lief?

cronos 21.05.2005 17:00

Kurz und knapp: Ja!

Killu 21.05.2005 22:17

hmm also vielen dank nomma für die hilfe
das mit den Einträgen fixen von Rene-gad versteh ich aber net :balla:
wie und wozu? :o

Felix :D

Cidre 21.05.2005 22:25

Die Antwort steht in meiner Anmerkung in deinem ersten Post . ;)

Killu 22.05.2005 19:10

brauche escan Auswertung!!! Ping(Counterstrike) bei 1000!!!
 
hi
hab jetzt wie mir gesagt wurde escan durchlaufen lassen und mit der find.bat folgende Informationen bekommen:
Bitte helft mir bei der Auswertung und sagt mir was ich noch tun muss :confused: damit mein PC ENDLICH wieder ordentlich läuft.. :heulen: :

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Funde für "infected"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Sat May 21 19:21:35 2005 => File C:\PROGRA~2\Kdlgddl\Rzqdnsp.exe infected by "Trojan.Win32.Small.cy" Virus! Action Taken: No Action Taken.
Sat May 21 19:21:35 2005 => File c:\windows\system32\trrcbj.exe infected by "Trojan.Win32.Agent.cp" Virus! Action Taken: No Action Taken.
Sat May 21 19:21:50 2005 => File C:\WINDOWS\svcproc.exe infected by "Trojan.Win32.Stervis.c" Virus! Action Taken: No Action Taken.
Sat May 21 19:23:55 2005 => File C:\WINDOWS\system32\DrPMon.dll infected by "Trojan.Win32.Agent.db" Virus! Action Taken: No Action Taken.
Sat May 21 19:31:57 2005 => File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy\Recovery\DyFuCAInternetOptimizer5.zip infected by "Password-protected-EXE" Virus! Action Taken: No Action Taken.
Sat May 21 19:33:46 2005 => File C:\Dokumente und Einstellungen\Felix\Lokale Einstellungen\Anwendungsdaten\Microsoft\Internet Explorer\V0.26.dat infected by "Trojan.Win32.Dialer.fy" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:25 2005 => File C:\Programme\Norton AntiVirus\Quarantine\078358A2 infected by "Trojan-Downloader.Win32.Dyfuca.du" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:25 2005 => File C:\Programme\Norton AntiVirus\Quarantine\0E603303 infected by "Trojan-Downloader.Win32.Agent.ae" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:25 2005 => File C:\Programme\Norton AntiVirus\Quarantine\0E832ABB infected by "Trojan-Downloader.Win32.IstBar.gen" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:25 2005 => File C:\Programme\Norton AntiVirus\Quarantine\11744923 infected by "Trojan-Downloader.Win32.Dyfuca.bw" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:25 2005 => File C:\Programme\Norton AntiVirus\Quarantine\117B1D1C infected by "Trojan-Downloader.Win32.Dyfuca.gen" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:26 2005 => File C:\Programme\Norton AntiVirus\Quarantine\117E4718 infected by "Trojan-Downloader.Win32.Agent.ae" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:26 2005 => File C:\Programme\Norton AntiVirus\Quarantine\16DD1789 infected by "Trojan-Downloader.Win32.Dyfuca.dp" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:26 2005 => File C:\Programme\Norton AntiVirus\Quarantine\16E14185 infected by "Trojan.Win32.Dialer.dc" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:26 2005 => File C:\Programme\Norton AntiVirus\Quarantine\19C86493 infected by "Trojan-Downloader.Win32.Agent.ae" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:26 2005 => File C:\Programme\Norton AntiVirus\Quarantine\1ECE2BA6 infected by "Trojan-Downloader.Win32.Dyfuca.gen" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:26 2005 => File C:\Programme\Norton AntiVirus\Quarantine\2C067FE0 infected by "Trojan-Downloader.Win32.Dyfuca.cq" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:27 2005 => File C:\Programme\Norton AntiVirus\Quarantine\2E804100 infected by "Trojan-Downloader.Win32.Dyfuca.dk" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:27 2005 => File C:\Programme\Norton AntiVirus\Quarantine\2E8714F9 infected by "Trojan-Downloader.Win32.Stubby.d" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:27 2005 => File C:\Programme\Norton AntiVirus\Quarantine\2F1B495D.htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:27 2005 => File C:\Programme\Norton AntiVirus\Quarantine\2F9D58CE.htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:27 2005 => File C:\Programme\Norton AntiVirus\Quarantine\31BF7CB5 infected by "Trojan-Downloader.Win32.Dyfuca.bq" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:27 2005 => File C:\Programme\Norton AntiVirus\Quarantine\38243087 infected by "Trojan-Downloader.Win32.Dyfuca.dt" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:27 2005 => File C:\Programme\Norton AntiVirus\Quarantine\38915673 infected by "Trojan-Downloader.Win32.Dyfuca.ds" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:27 2005 => File C:\Programme\Norton AntiVirus\Quarantine\3B524771 infected by "Trojan-Downloader.Win32.Dyfuca.cw" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:28 2005 => File C:\Programme\Norton AntiVirus\Quarantine\3BB976FF infected by "Trojan-Downloader.Win32.IstBar.fa" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:28 2005 => File C:\Programme\Norton AntiVirus\Quarantine\3BBC20FB infected by "Trojan-Downloader.Win32.Dyfuca.cq" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:28 2005 => File C:\Programme\Norton AntiVirus\Quarantine\403526AB.htm infected by "Exploit.VBS.Phel.a" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:28 2005 => File C:\Programme\Norton AntiVirus\Quarantine\40457899.htm infected by "Exploit.VBS.Phel.a" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:28 2005 => File C:\Programme\Norton AntiVirus\Quarantine\46B33CEF.tmp infected by "Email-Worm.Win32.Sober.p" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:28 2005 => File C:\Programme\Norton AntiVirus\Quarantine\473362F2 infected by "Trojan-Downloader.Win32.Agent.ae" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:28 2005 => File C:\Programme\Norton AntiVirus\Quarantine\4A884A0F infected by "Trojan-Downloader.Win32.Dyfuca.da" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:29 2005 => File C:\Programme\Norton AntiVirus\Quarantine\52C31EF1 infected by "Trojan-Downloader.Win32.Stubby.d" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:29 2005 => File C:\Programme\Norton AntiVirus\Quarantine\59064DA6 infected by "Trojan-Downloader.Win32.Dyfuca.cs" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:29 2005 => File C:\Programme\Norton AntiVirus\Quarantine\5A8537C1 infected by "Trojan.Win32.Small.cy" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:29 2005 => File C:\Programme\Norton AntiVirus\Quarantine\687C6071 infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\6C8E07F1 infected by "Trojan-Downloader.Win32.Dyfuca.cr" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\6C9231EE infected by "Trojan-Downloader.Win32.Dyfuca.cs" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\6C955BEA infected by "Trojan-Spy.Win32.Briss.g" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\6E535385.exe infected by "Trojan.Win32.Favadd.m" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\71486043.htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\764E650D infected by "Trojan-Downloader.Win32.Dyfuca.de" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\76510F0A infected by "Trojan-Downloader.Win32.Dyfuca.de" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\76553906 infected by "Trojan-Downloader.Win32.Dyfuca.gen" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:31 2005 => File C:\Programme\Norton AntiVirus\Quarantine\784A2367 infected by "Trojan-Downloader.Win32.PurityScan.i" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:31 2005 => File C:\Programme\Norton AntiVirus\Quarantine\784D4D64 infected by "Trojan-Downloader.Win32.Agent.ae" Virus! Action Taken: No Action Taken.
Sat May 21 20:26:31 2005 => File C:\Programme\Norton AntiVirus\Quarantine\7B183EF6 infected by "Trojan-Spy.Win32.Briss.g" Virus! Action Taken: No Action Taken.
Sat May 21 21:48:08 2005 => File C:\WINDOWS\system32\DrPMon.dll infected by "Trojan.Win32.Agent.db" Virus! Action Taken: No Action Taken.
Sat May 21 22:07:50 2005 => Total Disinfected Files: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Funde für "tagged"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Sat May 21 19:21:09 2005 => File C:\Programme\NewDotNet\newdotnet6_38.dll tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.
Sat May 21 19:21:22 2005 => File C:\Programme\NewDotNet\newdotnet6_38.dll tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.
Sat May 21 19:21:33 2005 => File C:\WINDOWS\Dit.exe tagged as not-a-virus:Garbage.Win32.CustomIcons. No Action Taken.
Sat May 21 19:23:12 2005 => File C:\WINDOWS\DitExp.exe tagged as not-a-virus:Garbage.Win32.CustomIcons. No Action Taken.
Sat May 21 19:23:17 2005 => File C:\WINDOWS\Nail.exe tagged as "not-a-virus:AdWare.BetterInternet.b". Action Taken: No Action Taken.
Sat May 21 19:23:17 2005 => File C:\WINDOWS\NDNuninstall6_38.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.
Sat May 21 19:23:18 2005 => File C:\WINDOWS\ordbamcami.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.
Sat May 21 19:23:21 2005 => File C:\WINDOWS\tgsuzj.exe tagged as "not-a-virus:AdWare.BetterInternet.c". Action Taken: No Action Taken.
Sat May 21 19:27:09 2005 => File C:\DOKUME~1\Felix\LOKALE~1\Temp\temp.fr4DB1 tagged as "not-a-virus:AdWare.WinAD.ao". Action Taken: No Action Taken.
Sat May 21 19:31:30 2005 => File C:\DOKUME~1\Felix\LOKALE~1\TEMPOR~1\Content.IE5\OXQBS1I7\Painkiller_SP_Demo2_Setup[1].zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
Sat May 21 19:34:39 2005 => File C:\Dokumente und Einstellungen\Felix\Lokale Einstellungen\Temp\temp.fr4DB1 tagged as "not-a-virus:AdWare.WinAD.ao". Action Taken: No Action Taken.
Sat May 21 19:38:31 2005 => File C:\Dokumente und Einstellungen\Felix\Lokale Einstellungen\Temporary Internet Files\Content.IE5\OXQBS1I7\Painkiller_SP_Demo2_Setup[1].zip tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
Sat May 21 19:38:57 2005 => File C:\program files\Media Access\MediaAccK.exe tagged as "not-a-virus:AdWare.WinAD.an". Action Taken: No Action Taken.
Sat May 21 20:26:17 2005 => File C:\Programme\NewDotNet\uninstall6_38.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.
Sat May 21 20:26:25 2005 => File C:\Programme\Norton AntiVirus\Quarantine\00625A7E tagged as "not-a-virus:AdWare.ToolBar.GigatechSuperBar". Action Taken: No Action Taken.
Sat May 21 20:26:25 2005 => File C:\Programme\Norton AntiVirus\Quarantine\00E51F15 tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.
Sat May 21 20:26:25 2005 => File C:\Programme\Norton AntiVirus\Quarantine\00EC730E tagged as "not-a-virus:AdWare.BiSpy.t". Action Taken: No Action Taken.
Sat May 21 20:26:25 2005 => File C:\Programme\Norton AntiVirus\Quarantine\07892C9B tagged as "not-a-virus:AdWare.SaveNow.az". Action Taken: No Action Taken.
Sat May 21 20:26:26 2005 => File C:\Programme\Norton AntiVirus\Quarantine\11827114 tagged as "not-a-virus:AdWare.PowerScan.b". Action Taken: No Action Taken.
Sat May 21 20:26:26 2005 => File C:\Programme\Norton AntiVirus\Quarantine\14BD59C1 tagged as "not-a-virus:AdWare.BiSpy.f". Action Taken: No Action Taken.
Sat May 21 20:26:26 2005 => File C:\Programme\Norton AntiVirus\Quarantine\25A0683A tagged as "not-a-virus:AdWare.WebRebates.c". Action Taken: No Action Taken.
Sat May 21 20:26:26 2005 => File C:\Programme\Norton AntiVirus\Quarantine\25A31236 tagged as "not-a-virus:AdWare.180Solutions". Action Taken: No Action Taken.
Sat May 21 20:26:26 2005 => File C:\Programme\Norton AntiVirus\Quarantine\25A63C33 tagged as "not-a-virus:AdWare.BiSpy.f". Action Taken: No Action Taken.
Sat May 21 20:26:26 2005 => File C:\Programme\Norton AntiVirus\Quarantine\25AA662F tagged as "not-a-virus:AdWare.BiSpy.f". Action Taken: No Action Taken.
Sat May 21 20:26:27 2005 => File C:\Programme\Norton AntiVirus\Quarantine\2E836AFD tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.
Sat May 21 20:26:27 2005 => File C:\Programme\Norton AntiVirus\Quarantine\2E8A3EF6 tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.
Sat May 21 20:26:27 2005 => File C:\Programme\Norton AntiVirus\Quarantine\3B581B69 tagged as "not-a-virus:AdWare.Toolbar.GigatechSuperBar". Action Taken: No Action Taken.
Sat May 21 20:26:28 2005 => File C:\Programme\Norton AntiVirus\Quarantine\3D240F05 tagged as "not-a-virus:AdWare.ToolBar.GigatechSuperBar". Action Taken: No Action Taken.
Sat May 21 20:26:28 2005 => File C:\Programme\Norton AntiVirus\Quarantine\3D4F38B4 tagged as "not-a-virus:AdWare.PowerScan.b". Action Taken: No Action Taken.
Sat May 21 20:26:29 2005 => File C:\Programme\Norton AntiVirus\Quarantine\4B66594D tagged as "not-a-virus:AdWare.SaveNow.ay". Action Taken: No Action Taken.
Sat May 21 20:26:29 2005 => File C:\Programme\Norton AntiVirus\Quarantine\4EF57BC2 tagged as "not-a-virus:AdWare.180Solutions". Action Taken: No Action Taken.
Sat May 21 20:26:29 2005 => File C:\Programme\Norton AntiVirus\Quarantine\55CE377D tagged as "not-a-virus:AdWare.BiSpy.f". Action Taken: No Action Taken.
Sat May 21 20:26:29 2005 => File C:\Programme\Norton AntiVirus\Quarantine\68715923 tagged as "not-a-virus:AdWare.BiSpy.m". Action Taken: No Action Taken.
Sat May 21 20:26:29 2005 => File C:\Programme\Norton AntiVirus\Quarantine\68793675 tagged as "not-a-virus:AdWare.180Solutions". Action Taken: No Action Taken.
Sat May 21 20:26:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\6AB2072A tagged as "not-a-virus:AdWare.SaveNow.g". Action Taken: No Action Taken.
Sat May 21 20:26:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\72493D72 tagged as "not-a-virus:AdWare.WinAD.ak". Action Taken: No Action Taken.
Sat May 21 20:26:30 2005 => File C:\Programme\Norton AntiVirus\Quarantine\775C3106 tagged as "not-a-virus:AdWare.180Solutions". Action Taken: No Action Taken.
Sat May 21 20:39:50 2005 => File C:\Programme\Spiele\Sierra\Half-Life\cstrike\PODBot\Setup\pod25ins.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
Sat May 21 20:52:47 2005 => File C:\Programme\Spiele\Sierra\Half-Life\hltv.exe tagged as not-a-virus:RiskWare.Proxy.Hltv. No Action Taken.
Sat May 21 20:53:07 2005 => File C:\Programme\Spiele\Sierra\Half-Life\Update\ghl1110.exe tagged as not-a-virus:RiskWare.Proxy.Hltv. No Action Taken.
Sat May 21 21:12:08 2005 => File C:\Programme\Tools\Ares\Setup\setup_ares.exe tagged as "not-a-virus:AdWare.NavExcel.d". Action Taken: No Action Taken.
Sat May 21 21:15:53 2005 => File C:\Programme\Tools\eMule\Incoming\Setups\podbot25.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
Sat May 21 21:16:25 2005 => File C:\Programme\Tools\GDiVX Player\SuperBarInstall.exe tagged as "not-a-virus:AdWare.ToolBar.GigatechSuperBar". Action Taken: No Action Taken.
Sat May 21 21:16:42 2005 => File C:\Programme\Tools\mIRC\mirc.exe tagged as not-a-virus:RiskWare.mIRC.6.16. No Action Taken.
Sat May 21 21:16:43 2005 => File C:\Programme\Tools\mIRC\Setup\mirc616.exe tagged as not-a-virus:RiskWare.mIRC.6.16. No Action Taken.
Sat May 21 21:31:49 2005 => File C:\WINDOWS\DitExp.exe tagged as not-a-virus:Garbage.Win32.CustomIcons. No Action Taken.
Sat May 21 21:36:50 2005 => File C:\WINDOWS\Nail.exe tagged as "not-a-virus:AdWare.BetterInternet.b". Action Taken: No Action Taken.
Sat May 21 21:36:50 2005 => File C:\WINDOWS\NDNuninstall6_38.exe tagged as "not-a-virus:AdWare.NewDotNet". Action Taken: No Action Taken.
Sat May 21 21:36:51 2005 => File C:\WINDOWS\ordbamcami.exe tagged as "not-a-virus:AdWare.BetterInternet". Action Taken: No Action Taken.
Sat May 21 21:51:18 2005 => File C:\WINDOWS\tgsuzj.exe tagged as "not-a-virus:AdWare.BetterInternet.c". Action Taken: No Action Taken.
Sat May 21 21:52:47 2005 => File D:\Felix\Games\Counterstrike\PODBot\Setup\pod25ins.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
Sat May 21 22:06:03 2005 => File E:\Tools\DivX504Bundle.exe tagged as not-a-virus:Tool.WinCap.Reboot. No Action Taken.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Statistiken:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Sat May 21 22:07:50 2005 => Total Virus(es) Found: 103
Sat May 21 22:07:50 2005 => Total Errors: 271
Sat May 21 22:07:50 2005 => Time Elapsed: 02:45:42
Sat May 21 22:07:50 2005 => Total Objects Scanned: 92246
Sat May 21 19:19:35 2005 => Virus Database Date: 2005/05/21
Sat May 21 22:07:50 2005 => Virus Database Date: 2005/05/21
Sat May 21 22:55:45 2005 => Virus Database Date: 2005/05/21
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~ © Haui ;-) ~~~~~~~
~~~~~~~ Dank an Cidre ~~~~~~~


Danke schonmal!!!
bitte helft mir :(

mfg Felix

Meerjungfraumann 22.05.2005 19:18

Hy,
lösche erstmal Dein Norton Antivir Quarantäne brauchst Du nämlich nicht aufzuheben.Dann lade Dir AdAware Se von Lavasoft runter und lass es im abgesicherten Modus durchlaufen findet mitsicherheit einiges.Lösche das gefundene mit Adaware.Lass dan nochmal EScan laufen.

Greetings from MEERJUNGFRAUMANN (SPONGEBOB MEMBER) :teufel3:

chaosman 22.05.2005 19:31

@Killu
bei dieser menge ist neuaufsetzen vom system das schnellste und das beste
hier eine anleitung

sry
chaosman

Cidre 22.05.2005 19:48

Hallo Killu,

wieviel Threads willst du eigentlich noch eröffnen?
Glaubst du nicht auch, daß es für die hier helfenden Member einfacher wäre, wenn du deinen 'alten Thread' fortführen würdest?!

Deine Threads werden zwecks Übersichtlichkeit zusammengeführt!

btw:
Deine [!] Taste prellt!


Alle Zeitangaben in WEZ +1. Es ist jetzt 22:12 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19