Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Fenster: May be detected (https://www.trojaner-board.de/19086-fenster-may-be-detected.html)

Poelziminator 19.06.2005 20:06

Fenster: May be detected
 
Hallo...,
ich habe Win XP home mit SP 1 und Norton Internet Security (mit den aktuellsten Update) und habe den MS Internet Explorer deinstalliert und arbeite mit Firefox. Von Zeit zu Zeit gehen Fenster mit dem Titel Internet Explorer auf. In diesen sind meistens die Meldung: "Warning: Your computer may be infected with spy ware" zu lesen.

Ich habe mein System mit Ad Aware, F-Prot und Spybot gescannt. Alle finden auch jeweils etwas. Bei keinem der Tools hat ein entfernen etwas genutzt. Hier habe ich mal den Report von F-Prot beigefügt.


F-PROT ANTIVIRUS
Program version: 3.16b
Engine version: 3.16.6

VIRUS SIGNATURE FILES
MACRO.DEF created 6/14/2005
SIGN.DEF created 6/17/2005
SIGN2.DEF created 6/18/2005

StartTime: 06.19.2005 14:27

Scan settings:

Path to scan:
<Hard drive> C:\

Which files:
Depending on file content and extensions.
Scan inside archives.
Scan inside compressed executables
Scan inside subfolders.

Action if malware is found:
Disinfect.
How to scan:
Use heuristics (always in normal mode).

C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy\Recovery\CleverIEHookerJeired.zip->tvmupdater.exe could be a suspicious file (encrypted program in archive)
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy\Recovery\ErrorGuard.zip->setupactive.exe could be a suspicious file (encrypted program in archive)
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy\Recovery\SpywareStormer1.zip->Setup.exe could be a suspicious file (encrypted program in archive)
C:\Dokumente und Einstellungen\Eric\Eigene Dateien\Eigene Downloads\setuperrorguard.exe is a security risk or a "backdoor" program
File deleted.
C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\11F65E7D.exe->(CryptFF)->(FSG) could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\20610BEC.tmp->(CryptFF) is a security risk named W32/Downloader.NW
Could not delete the file.
C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\271E6770.exe->(CryptFF) is a dropper for W32/Rameh.D@dl
Could not delete the file.
C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\2721116D.exe->(CryptFF) is a security risk or a "backdoor" program
Could not delete the file.
C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\2721116D.tmp->(CryptFF) is a security risk named W32/Downloader.NW
Could not delete the file.
C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\27286566.exe->(CryptFF)->(FSG) could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\2F4624B8.exe->(CryptFF)->(FSG) could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\5A992DED.dll->(CryptFF) is a security risk named W32/Rameh.D@dl
Could not delete the file.
C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\628B7D2A.exe->(CryptFF)->(FSG) could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\662969EC.exe->(CryptFF) is a security risk or a "backdoor" program
Could not delete the file.
C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\76A422C6.exe->(CryptFF)->(FSG) could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\76A84CC2.exe->(CryptFF)->(FSG) could be infected with an unknown virus
Viruses cannot be disinfected unless they are identified.
C:\WINDOWS\Downloaded Program Files\CONFLICT.1\Install.dll is a security risk named W32/Hexa.A
File deleted.
C:\WINDOWS\protector.exe is a destructive program named W32/Startpage.TJ
File deleted.
Scan settings:

Path to scan:
<Hard drive> D:\

Which files:
Depending on file content and extensions.
Scan inside archives.
Scan inside compressed executables
Scan inside subfolders.

Action if malware is found:
Disinfect.
How to scan:
Use heuristics (always in normal mode).

Scan settings:

Path to scan:
<Hard drive> E:\

Which files:
Depending on file content and extensions.
Scan inside archives.
Scan inside compressed executables
Scan inside subfolders.

Action if malware is found:
Disinfect.
How to scan:
Use heuristics (always in normal mode).

The scanning ended successfully, with infected or suspicious object found

Results of virus scanning:

MBRs scanned..........: 3
Boot sectors scanned..: 6
Files total...........: 58735
Scanned objects.......: 46054
Infected objects......: 0
Suspicious objects....: 18
Deleted objects.......: 3
Disinfected objects...: 0
Renamed objects.......: 0
Moved objects.........: 0

Endtime: 06.19.2005 15:04

Scantime: 37:26 min.
------------------------------- END OF REPORT ------------------------------



Jetzt wollte ich dann einfach mein System neu installieren: Also XP-Diskette ins Laufwerk und neu gebootet. Zugriff erfolgt auf die CD mit der Frage ob von der CD gebootet werden soll. Dies habe ich bestätigt. Dann kommt die Meldung, dass die Hardware überprüft wird und der Bildschirm bleibt schwarz und nichts tut sich mehr.

Mir würde es ja reichen, wenn ich meinen Rechner neu installieren könnte. Weiss hierzu jemand einen Rat?

Gruß

Cidre 19.06.2005 21:45

Hallo,
Zitat:

Dann kommt die Meldung, dass die Hardware überprüft wird und der Bildschirm bleibt schwarz und nichts tut sich mehr.
Wie lange hält dieser Zustand an bzw. nach welcher Zeit hast du abgebrochen? Eventuell hat dein System sich einmalig 'aufgehängt', versuche es deshalb nochmal.
Halte dich aber beim Neuaufsetzen an die Anleitung in meiner Signatur, insbesondere an Windows neu oder erstmalig installieren (Screenshotguide).


Alle Zeitangaben in WEZ +1. Es ist jetzt 15:06 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131