Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Diverse Applikationen lassen sich nicht starten (https://www.trojaner-board.de/43856-diverse-applikationen-lassen-starten.html)

Beatfried 23.09.2007 23:08

Diverse Applikationen lassen sich nicht starten
 
Hi leute

Also, ich habe diverse Probleme.

Als erstes, weniger wichtig, trotzdem ziemlich nervig und auch schon länger vorhanden: Wenn ich am Surfen bin mit FF (ich surfe nut mit FF also kann ich nicht sagen wies mit IE aussehen würde) wird mir plötzlich ein Tab geöffnet das auf die URL w*w.systemdocter.com/... verweist. Dies geschieht ohne jegliche Logik rein zufällig (also, einmal beim öffnen von Altavista, einmal beim öffnen von Bluewin, oder auch ganz anderen Seiten).

Das zweite, und für mich schlimmere Probnlem ist folgendes:

Seit gestern, bin ich nicht mehr in der Lage, diverse Applikationen zu starten.
Darunter fallen unter anderen: MediaMonkey (Mp3 Player), TvGenial (Fernsehprogramm), WinRAR (bekannt oder?), Ad-Aware (Spyware entfernungstool, das ich normalerweise als erstes bei solchen Problemen anwerfe). Dies sind 4 Beispiele die ich gerade heraus gepickt habe, es gibt da auch noch andere.
Hingegen lässt sich z.B. XoftSpySE oder auch FireFox problemlos öffnen.

XoftSpySE habe ich dann nach festellung des Problems einmal angeworfen. Es wurden mir diverse RegistryKeys als "Serve Risk" oder "Low Risk" angezeigt. Welche ich dann auch gereinigt habe. Welche diese Waren kann ich leider nicht mehr sagen, da die jetzt auch grösstenteils nicht mehr auftauchten.

Der einzige der noch da ist, nennt sich "Vundo Trojan" und versteckt sich in software\microsoft\uniqdata. Der lässt sich einfach nicht entfernen.

Wenn ich all diese RegistryKeys & Cookies (ja, gestern abend waren noch Cookies befallen, die aber auch nicht mehr auftauchten als ich sie gelöscht habe) bereinigt habe und den Computer neu starte ,funktioniert alles wunderbar. ich Kann die oben genannten Appliatkionen starten und sie funktionieren. Nach ca. 2-3 Minuten allerdings schliessen sie sich von selbst und verabschieden sich.

Als drittes und auch unwichtigstes Problem wäre da noch (wie könnte es auch anders sein.......) etwas das nur den IE betrifft.
Ich arbeite Grundsätzlich nicht mit dem IE und weiss auch nicht wo dieses Zeug herkommt. Aber es werden Regelmässig PopUps vom IE angezeigt, die sich jetzt natürlich genau nicht zeigen. Also wenn sich dieses Problem auch gerade herauslesen liesse wäre ich dankbar, aber das zweite ist das Wichtigste :D



Hier der hjt-Log:

Logfile of HijackThis v1.99.1
Scan saved at 23:51:09, on 23.09.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\brsvc01a.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\brss01a.exe
C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe
C:\Programme\Pinnacle\MediaServer\Microsoft SQL Server\MSSQL$PINNACLESYS\Binn\sqlservr.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programme\Analog Devices\SoundMAX\SMAgent.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Analog Devices\SoundMAX\Smtray.exe
C:\Programme\SyncroSoft\Pos\H2O\cledx.exe
C:\Programme\PowerISO\PWRISOVM.EXE
C:\Programme\ScanSoft\PaperPort\pptd40nt.exe
C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe
C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedhlp.exe
C:\Programme\Acronis\TrueImageHome\TimounterMonitor.exe
C:\Programme\Java\jre1.6.0_01\bin\jusched.exe
C:\Programme\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe
C:\Programme\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe
C:\Programme\MSN Messenger\MsnMsgr.Exe
D:\Programme\BitTorrent\bittorrent.exe
C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe
C:\Programme\Illuminated Dark Metal Keyboard\MagicKey.exe
C:\WINDOWS\system32\wscntfy.exe
C:\Programme\Illuminated Dark Metal Keyboard\OSD.EXE
C:\WINDOWS\System32\wbem\wmiapsrv.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\XoftSpySE\XoftSpy.exe
D:\Programme\HiJackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://w*w.altavista.ch
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://w*w.altavista.ch
O3 - Toolbar: Copernic Desktop Search 2 - {968631B6-4729-440D-9BF4-251F5593EC9A} - C:\Programme\Copernic Desktop Search 2\DesktopSearchBand201013011.dll
O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup"
O4 - HKLM\..\Run: [nwiz] "nwiz.exe /install"
O4 - HKLM\..\Run: [Smapp] "C:\Programme\Analog Devices\SoundMAX\Smtray.exe"
O4 - HKLM\..\Run: [BigDogPath] "C:\WINDOWS\VM_STI.EXE USB PC Web Camera"
O4 - HKLM\..\Run: [H2O] "C:\Programme\SyncroSoft\Pos\H2O\cledx.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe"
O4 - HKLM\..\Run: [ControlCenter2.0] "C:\Programme\Brother\ControlCenter2\brctrcen.exe /autorun"
O4 - HKLM\..\Run: [C-Media Mixer] "Mixer.exe /startup"
O4 - HKLM\..\Run: [unowbgvo] "C:\guewnbcs.bat"
O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Programme\PowerISO\PWRISOVM.EXE"
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Programme\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Programme\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [BrMfcWnd] "C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN"
O4 - HKLM\..\Run: [ControlCenter3] "C:\Programme\Brother\ControlCenter3\brctrcen.exe /autorun"
O4 - HKLM\..\Run: [TrueImageMonitor.exe] "C:\Programme\Acronis\TrueImageHome\TrueImageMonitor.exe"
O4 - HKLM\..\Run: [AcronisTimounterMonitor] "C:\Programme\Acronis\TrueImageHome\TimounterMonitor.exe"
O4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedhlp.exe"
O4 - HKLM\..\Run: [NeroFilterCheck] "C:\WINDOWS\system32\NeroCheck.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKLM\..\Run: [PinnacleDriverCheck] "C:\WINDOWS\system32\PSDrvCheck.exe -CheckReg"
O4 - HKLM\..\Run: [PMCRemote] "C:\Programme\Pinnacle\Shared Files\Programs\Remote\Remoterm.exe"
O4 - HKLM\..\Run: [PMCS] "C:\Programme\Pinnacle\Shared Files\Programs\MediaCenterService\PMC.Service.Main.exe"
O4 - HKLM\..\Run: [SearchIndexer] rundll32.exe "C:\WINDOWS\system32\ptokypnj.dll",sitypnow
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe"
O4 - HKCU\..\Run: [BitTorrent] "D:\Programme\BitTorrent\bittorrent.exe" --force_start_minimized
O4 - HKCU\..\Run: [NVIEW] "rundll32.exe nview.dll,nViewLoadHook"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Ahead\lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe"
O4 - HKCU\..\Run: [TVgenial] D:\Programme\TVgenial\TVgenial.exe -d
O4 - HKCU\..\Run: [Copernic Desktop Search 2] "C:\Programme\Copernic Desktop Search 2\DesktopSearchService.exe" /tray
O4 - HKCU\..\RunOnce: [FFTI] "C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\Profiles\jke2crwj.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /DestPath="C:\Dokumente und Einstellungen\thomas\Anwendungsdaten\Mozilla\Firefox\Profiles/jke2crwj.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}""
O4 - Startup: Adobe Gamma.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Illuminated Dark Metal Keyboard.lnk = C:\Programme\Illuminated Dark Metal Keyboard\MagicKey.exe
O8 - Extra context menu item: Download with YouTube Video Converter - C:\Programme\Xilisoft\YouTube Video Converter\upod_link.HTM
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {13EC55CF-D993-475B-9ACA-F4A384957956} (Controller Class) - https://www.windowsonecare.com/install/cli/1.1.1067.14/WinSSWebAgent.CAB
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{A37E7263-9AB3-40FE-A84D-04F201F1BD0C}: NameServer = ***
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Programme\Gemeinsame Dateien\Acronis\Schedule2\schedul2.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: BrSplService (Brother XP spl Service) - brother Industries Ltd - C:\WINDOWS\system32\brsvc01a.exe
O23 - Service: DomainService - Unknown owner - C:\WINDOWS\system32\fqcdxlyf.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - c:\Programme\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Pinnacle Systems Media Service (PinnacleSys.MediaServer) - Pinnacle Systems - C:\Programme\Pinnacle\Shared Files\Programs\MediaServer\PMSHost.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Programme\Analog Devices\SoundMAX\SMAgent.exe



Ich bedanke mich schon einmal für die Hilfe :D

Gruss

Beatfried

Cleriker 24.09.2007 09:48

Morgeen und :)Herzlich Willkommen im Trojaner-Board:)

Wenn du Vundo auf deinem System hast, dann als erstes
erst mal folgendes:

* Vundofix
- Lade dir vundofix.exe
- Doppelklick VundoFix.exe
- Klicke "Scan" --> Vundo button.
- Nach dem Scannen, klicke den "Remove" Vundo button.
- Man wird nun gefragt, ob man "remove" will --> klicke YES
- Danach werden alle Desktop-Symbole verschwinden
- Dann wird man gefragt, ob der PC neustarten soll --> klicke OK.

Direkt kann ich in deinem Logfile nichts zu deinen anderen
Problemen finden, aber ich bin mir ziemlich sicher, dass
folgender Eintrag nicht erwünscht ist und mit deinem Problem
zu haben könnte:
Zitat:

O4 - HKCU\..\RunOnce: [FFTI] "C:\Dokumente und Einstellungen\***\Anwendungsdaten\Mozilla\Firefox\ Profiles\jke2crwj.default\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\ffti.exe /VERYSILENT /SUPPRESSMSGBOXES /NORESTART /DestPath="C:\Dokumente und Einstellungen\thomas\Anwendungsdaten\Mozilla\Firef
Starte bitte Hijack noch einmal und fixe diesen Eintrag.

Als drittes schlage ich einen escan vor, um zu überprüfen,
ob noch mehr hinter steckt.

* MWAV (eScan) - Free Antivirus
-Lies dir folgende Anleitung genau durch und arbeite sie ab
-> Anleitung eScan
Wichtig: Poste im Anschluss das Ergebnis mit Hilfe der *find.bat'.
(rechte Maustaste auf den LINK 'find.bat' , dann "Ziel Speichern unter" -> Desktop)


mfg Cleriker

BataAlexander 24.09.2007 10:37

Jonas1993

Bitte erstelle einen eigenen Thread. :)

Beatfried 24.09.2007 17:21

sooo... habe das jetzt alles wie geschrieben ausgeführt :D

der Vundo war nach 3x rebooten beseitigt.

das entfernen des HiJackThis eintrags war kein Problem.

Und der im Fenster erschienene Inhalt kopiere ich anschliessend hier rein.

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Header
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
find.bat Version 2007.06.16.01

Microsoft Windows XP [Version 5.1.2600]
Bootmodus: NETWORK

eScan Version: 9.4.4
Sprache: English
Virus Database Date: 9/24/2007

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Infektionsmeldungen
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
System found infected with stylexp Spyware/Adware ({c333cf63-767f-4831-94ac-e683d962c63c})! Action taken: No Action Taken.
System found infected with winzix Spyware/Adware ({ee91f4cc-6ba2-424c-a1fe-64910ccb6a42})! Action taken: No Action Taken.
System found infected with video activex access Trojan ({7e853d72-626a-48ec-a868-ba8d5e23e045})! Action taken: No Action Taken.
System found infected with winzix Spyware/Adware ({10954590-2b3a-41ec-97bb-c95a5e646da9})! Action taken: No Action Taken.
System found infected with winzix Spyware/Adware ({41ca7d4d-ae77-4b13-9459-e9ab7efecaad})! Action taken: No Action Taken.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (process.exe)! Action taken: No Action Taken.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (swreg.exe)! Action taken: No Action Taken.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (swsc.exe)! Action taken: No Action Taken.
System found infected with smitfraud Browser Hijacker (online security guide.url)! Action taken: No Action Taken.
System found infected with smitfraud Browser Hijacker (security troubleshooting.url)! Action taken: No Action Taken.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (process.exe)! Action taken: No Action Taken.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (reboot.exe)! Action taken: No Action Taken.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (swreg.exe)! Action taken: No Action Taken.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (swsc.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with blurax BackDoor (a.exe)! Action taken: No Action Taken.
System found infected with xrenoder Spyware/Adware (display.php)! Action taken: No Action Taken.
System found infected with xrenoder Spyware/Adware (display.php)! Action taken: No Action Taken.
System found infected with smitfraud Browser Hijacker (online security guide.url)! Action taken: No Action Taken.
System found infected with smitfraud Browser Hijacker (security troubleshooting.url)! Action taken: No Action Taken.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (process.exe)! Action taken: No Action Taken.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (reboot.exe)! Action taken: No Action Taken.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (swreg.exe)! Action taken: No Action Taken.
System found infected with trojan-downloader.bat.ftp.ab Trojan-Downloader (swsc.exe)! Action taken: No Action Taken.
Object "video access activex object Trojan" found in File System! Action Taken: No Action Taken.
Object "zlob Trojan" found in File System! Action Taken: No Action Taken.
Object "winzix Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "winzix Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "winzix Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "winzix Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "winzix Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "winzix Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "winzix Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "winzix Spyware/Adware" found in File System! Action Taken: No Action Taken.
Object "winzix Spyware/Adware" found in File System! Action Taken: No Action Taken.
~~~~~~~~~~~
Dateien
~~~~~~~~~~~
~~~~ Infected files
~~~~~~~~~~~
File C:\WINDOWS\system32\aewapbxc.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\afsnwvpg.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\alopqmle.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\amkksrur.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.

Beatfried 24.09.2007 17:23

File C:\WINDOWS\system32\anonxfws.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\anouuqcw.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\aqiklxtj.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\arjrswjd.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\blirolfn.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\bvqjykst.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\chclykvy.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\cnhjtnte.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\cnrenktl.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\dpafokrx.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\dqgyeary.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\dsmlmpqg.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\dupsujno.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\dvyycoww.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\edqpjgwy.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\edypeymt.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ekttyxdg.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\emmddnde.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\eoywoomi.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\fhkqdjon.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\flkeirmj.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\gjcensqx.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\gkkdpgyy.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\gnxmvoiq.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\grxnsqwc.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\hjeyxyke.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\hkgyvsdm.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\hpqkcyuv.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\htialjwt.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\htiihxoa.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\hujgdlgq.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\icypualy.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\idqrcaoh.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\iqssugle.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\jgclbkbf.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\jnnwpphi.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\jpcavtrc.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\jqmvoqvw.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\jsaqvbna.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\juxiklct.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\kcgvxais.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\kethfrnk.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\kgdewluj.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\kgfighcd.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\khrqxqhw.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\kixonspu.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\kkrtidar.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\lbmqjbik.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\lhgsmbhg.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\mbhgxtfg.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\mppycikm.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\mruyvuoe.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\nepsussc.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\nyibqlgj.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ocldpbsv.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\oqccgtjn.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\oupbnomw.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\phnjrxpv.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\pjpfnmlw.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\prttlkoq.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\pryyorru.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\qlhpcnyy.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\qoxrbssp.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\qrcbqvkm.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\qwccgoqi.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\qxlrqhhm.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\raqfkdpf.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\rkhkvxel.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\rxaernrk.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\sbxqgsgg.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\syeflmix.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\syfsujxo.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\syidwwfa.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\sytvvqck.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\tejgkblg.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\thcemxwr.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\tnxrsynx.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\tpytkihv.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\udqkmaco.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ugypjiva.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ukwuxovo.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\uqxarakg.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\vclsdurf.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\vdcqiwlr.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\vdmqthbi.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\vfakvekf.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\vvqrykkn.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\wegmymaf.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\wnhyitoa.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\womcrnpr.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\xftrgtro.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\xqswlmrt.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\xvasfiwu.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\xvpfbpud.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ympkfjfu.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ymtcotyb.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ytlnrlcl.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ywacwtqn.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\yxjfolga.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\DOKUME~1\thomas\LOKALE~1\Temp\bis11E.exe infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
File C:\DOKUME~1\thomas\LOKALE~1\Temp\Exporer32.exe infected by "Trojan-Dropper.Win32.Agent.bcw" Virus! Action Taken: No Action Taken.
File C:\DOKUME~1\thomas\LOKALE~1\Temp\keygen.exe//data0000.cab/mar02.exe infected by "Backdoor.Win32.VanBot.br" Virus! Action Taken: No Action Taken.
File C:\DOKUME~1\thomas\LOKALE~1\TEMPOR~1\Content.IE5\CTA7SD2B\k[1].txt infected by "Backdoor.Win32.VanBot.cd" Virus! Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\All Users\Dokumente\Sicherung C und D\Desktop\Desktop 25.8.06\loaded.exe infected by "NULL.Corrupted" Virus! Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\thomas\Lokale Einstellungen\Temp\bis11E.exe infected by "Trojan.Win32.Obfuscated.en" Virus! Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\thomas\Lokale Einstellungen\Temp\Exporer32.exe infected by "Trojan-Dropper.Win32.Agent.bcw" Virus! Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\thomas\Lokale Einstellungen\Temp\keygen.exe//data0000.cab/mar02.exe infected by "Backdoor.Win32.VanBot.br" Virus! Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\thomas\Lokale Einstellungen\Temporary Internet Files\Content.IE5\CTA7SD2B\k[1].txt infected by "Backdoor.Win32.VanBot.cd" Virus! Action Taken: No Action Taken.
File C:\RECYCLER\S-1-5-21-839522115-329068152-2147167427-1003\Dc3.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034299.dll infected by "Trojan-Spy.Win32.VBStat.h" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034300.dll infected by "Trojan-Spy.Win32.VBStat.h" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034311.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034314.dll infected by "Packed.Win32.Morphine.a" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034315.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034316.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034320.dll//Virtumonde//PE_Patch.UPX//UPX infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034321.exe infected by "Trojan.Win32.Agent.anr" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034322.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034323.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034325.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034327.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034330.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034331.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034335.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034336.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034340.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034342.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034343.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034351.exe infected by "Trojan-Clicker.Win32.Small.mw" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034354.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034356.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034357.exe infected by "Trojan.Win32.Agent.anr" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034361.exe infected by "Trojan.Win32.Agent.anr" Virus! Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034362.dll infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\bwucjshy.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\dbqjohla.dll.bad infected by "Packed.Win32.Morphine.a" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\dqlvlfhl.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\dtrbgagb.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\ehobpqsk.dll.bad//Virtumonde//PE_Patch.UPX//UPX infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\esmtdsro.exe.bad infected by "Trojan.Win32.Agent.anr" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\ffqdgkiu.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\fhqsesgp.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\gbdrbrle.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\hdciddiy.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\ieqfnblo.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\iourjhce.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.

Beatfried 24.09.2007 17:26

File C:\VundoFix Backups\kifwslmm.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\kjskgent.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\mbqioxka.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\ndbrhamc.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\nwoxmxss.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\rlkqxpyh.exe.bad infected by "Trojan-Clicker.Win32.Small.mw" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\tfqjqqtx.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\trlwtynr.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\ugtrjdqe.exe.bad infected by "Trojan.Win32.Agent.anr" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\ycxtkvid.exe.bad infected by "Trojan.Win32.Agent.anr" Virus! Action Taken: No Action Taken.
File C:\VundoFix Backups\yxwbngcy.dll.bad infected by "Trojan.Win32.BHO.bd" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\aewapbxc.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\afsnwvpg.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\alopqmle.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\amkksrur.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\anonxfws.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\anouuqcw.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\aqiklxtj.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\arjrswjd.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\blirolfn.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\bvqjykst.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\chclykvy.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\cnhjtnte.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\cnrenktl.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\dpafokrx.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\dqgyeary.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\dsmlmpqg.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\dupsujno.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\dvyycoww.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\edqpjgwy.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\edypeymt.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ekttyxdg.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\emmddnde.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\eoywoomi.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\fhkqdjon.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\flkeirmj.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\gjcensqx.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\gkkdpgyy.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\gnxmvoiq.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\grxnsqwc.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\hjeyxyke.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\hkgyvsdm.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\hpqkcyuv.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\htialjwt.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\htiihxoa.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\hujgdlgq.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\icypualy.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\idqrcaoh.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\iqssugle.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\jgclbkbf.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\jnnwpphi.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\jpcavtrc.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\jqmvoqvw.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\jsaqvbna.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\juxiklct.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\kcgvxais.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\kethfrnk.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\kgdewluj.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\kgfighcd.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\khrqxqhw.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\kixonspu.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\kkrtidar.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\lbmqjbik.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\lhgsmbhg.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\mbhgxtfg.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\mppycikm.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\mruyvuoe.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\nepsussc.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\nyibqlgj.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ocldpbsv.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\oqccgtjn.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\oupbnomw.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\phnjrxpv.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\pjpfnmlw.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\prttlkoq.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\pryyorru.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\qlhpcnyy.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\qoxrbssp.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\qrcbqvkm.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\qwccgoqi.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\qxlrqhhm.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\raqfkdpf.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\rkhkvxel.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\rxaernrk.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\sbxqgsgg.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\syeflmix.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\syfsujxo.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\syidwwfa.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\sytvvqck.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\tejgkblg.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\thcemxwr.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\tnxrsynx.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\tpytkihv.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\udqkmaco.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ugypjiva.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ukwuxovo.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\uqxarakg.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\vclsdurf.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\vdcqiwlr.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\vdmqthbi.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\vfakvekf.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\vvqrykkn.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\wegmymaf.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\wnhyitoa.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\womcrnpr.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\xftrgtro.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\xqswlmrt.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\xvasfiwu.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\xvpfbpud.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ympkfjfu.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ymtcotyb.exe infected by "Trojan-Dropper.Win32.Agent.bmk" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ytlnrlcl.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\ywacwtqn.exe infected by "Trojan.Win32.Agent.aoy" Virus! Action Taken: No Action Taken.
File C:\WINDOWS\system32\yxjfolga.exe infected by "Trojan.Win32.Agent.bck" Virus! Action Taken: No Action Taken.
File D:\Eigene Dateien\BitTorrent Downloads\Photoshop CS2 V9 KEYGEN\photoshop keygen.exe infected by "Backdoor.Win32.Ciadoor.ar" Virus! Action Taken: No Action Taken.
File D:\Eigene Dateien\BitTorrent Downloads\Photoshop CS2 V9 KEYGEN.zip/photoshop keygen.exe infected by "Backdoor.Win32.Ciadoor.ar" Virus! Action Taken: No Action Taken.
File D:\Eigene Dateien\My Received Files\FireFox Downloads\setup.exe//PE_Patch.UPX//UPX//stream//data0006 infected by "Trojan-Downloader.Win32.Zlob.bqr" Virus! Action Taken: No Action Taken.
File D:\StyleXP\Iconz\Orbital Transparent\122477.exe//WiseSFX Dropper//WISE0016.BIN infected by "Trojan-Downloader.Win32.Small.bke" Virus! Action Taken: No Action Taken.
File D:\StyleXP\LogonScreenz\128949.exe//WiseSFX Dropper//WISE0016.BIN infected by "Trojan-Downloader.Win32.Small.bke" Virus! Action Taken: No Action Taken.
File D:\StyleXP\Screensaverz\MAtrixcode\Intelore_Matrix_Reality_3D_Screensaver.zip/crack.exe//FSG infected by "Trojan-Downloader.Win32.Small.cbx" Virus! Action Taken: No Action Taken.
~~~~~~~~~~~
~~~~ Tagged files
~~~~~~~~~~~
File C:\WINDOWS\system32\meujesiv.dll tagged as "not-a-virus:AdWare.Win32.BHO.v". Action Taken: No Action Taken.

Beatfried 24.09.2007 17:27

File C:\DOKUME~1\thomas\LOKALE~1\TEMPOR~1\Content.IE5\CTA7SD2B\windings[1].exe//Virtumonde tagged as "not-a-virus:AdWare.Win32.Virtumonde.if". Action Taken: No Action Taken.
File C:\DOKUME~1\thomas\LOKALE~1\TEMPOR~1\Content.IE5\K16J8963\freelogomaker[1].exe//Virtumonde tagged as "not-a-virus:AdWare.Win32.Virtumonde.if". Action Taken: No Action Taken.
File C:\DOKUME~1\thomas\LOKALE~1\TEMPOR~1\Content.IE5\O1AF4T6F\lo1[1]//Virtumonde tagged as "not-a-virus:AdWare.Win32.Virtumonde.ic". Action Taken: No Action Taken.
File C:\DOKUME~1\thomas\LOKALE~1\TEMPOR~1\Content.IE5\O1AF4T6F\lo1[2]//Virtumonde tagged as "not-a-virus:AdWare.Win32.Virtumonde.ic". Action Taken: No Action Taken.
File C:\DOKUME~1\thomas\LOKALE~1\TEMPOR~1\Content.IE5\O1AF4T6F\loli[1].txt//Virtumonde tagged as "not-a-virus:AdWare.Win32.Virtumonde.if". Action Taken: No Action Taken.
File C:\DOKUME~1\thomas\LOKALE~1\TEMPOR~1\Content.IE5\ODIV4XQN\lo1[1]//PE_Patch.PECompact tagged as "not-a-virus:AdWare.Win32.Virtumonde.fp". Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\thomas\Lokale Einstellungen\Temporary Internet Files\Content.IE5\CTA7SD2B\windings[1].exe//Virtumonde tagged as "not-a-virus:AdWare.Win32.Virtumonde.if". Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\thomas\Lokale Einstellungen\Temporary Internet Files\Content.IE5\K16J8963\freelogomaker[1].exe//Virtumonde tagged as "not-a-virus:AdWare.Win32.Virtumonde.if". Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\thomas\Lokale Einstellungen\Temporary Internet Files\Content.IE5\O1AF4T6F\lo1[1]//Virtumonde tagged as "not-a-virus:AdWare.Win32.Virtumonde.ic". Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\thomas\Lokale Einstellungen\Temporary Internet Files\Content.IE5\O1AF4T6F\lo1[2]//Virtumonde tagged as "not-a-virus:AdWare.Win32.Virtumonde.ic". Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\thomas\Lokale Einstellungen\Temporary Internet Files\Content.IE5\O1AF4T6F\loli[1].txt//Virtumonde tagged as "not-a-virus:AdWare.Win32.Virtumonde.if". Action Taken: No Action Taken.
File C:\Dokumente und Einstellungen\thomas\Lokale Einstellungen\Temporary Internet Files\Content.IE5\ODIV4XQN\lo1[1]//PE_Patch.PECompact tagged as "not-a-virus:AdWare.Win32.Virtumonde.fp". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034309.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034312.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034313.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034318.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034324.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034332.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034334.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034337.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034339.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034341.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034344.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034345.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034348.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034352.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034358.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034360.dll//Virtumonde tagged as "not-a-virus:AdWare.Win32.Virtumonde.ic". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034367.dll//PE_Patch.PECompact tagged as "not-a-virus:AdWare.Win32.Virtumonde.fp". Action Taken: No Action Taken.
File C:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP485\A0034373.dll tagged as "not-a-virus:AdWare.Win32.Virtumonde.jp". Action Taken: No Action Taken.
File C:\VundoFix Backups\axvigpcg.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\cnhaxqfl.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\cnvwxeck.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\ecmvphvu.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\fhwjrcpe.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\iifgheb.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.jp". Action Taken: No Action Taken.
File C:\VundoFix Backups\iyentpbw.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\jwxedtbe.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\koppxabj.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\loaaidsu.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\mljge.dll.bad//PE_Patch.PECompact tagged as "not-a-virus:AdWare.Win32.Virtumonde.fp". Action Taken: No Action Taken.
File C:\VundoFix Backups\mthktcmb.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\owavxfxa.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\ppjxjrrh.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\qxmtkiei.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\sakwolxv.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\ukxfcorc.dll.bad tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\VundoFix Backups\vtsts.dll.bad//Virtumonde tagged as "not-a-virus:AdWare.Win32.Virtumonde.ic". Action Taken: No Action Taken.
File C:\WINDOWS\system32\meujesiv.dll tagged as "not-a-virus:AdWare.Win32.BHO.v". Action Taken: No Action Taken.
File C:\WINDOWS\Temp\TMP0000000EC956300F971BB192 tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\WINDOWS\Temp\TMP000000846AA4B7DACE0979EB tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File C:\WINDOWS\Temp\TMP00000096E6596CB3B5A4C1BD tagged as "not-a-virus:AdWare.Win32.Virtumonde.hb". Action Taken: No Action Taken.
File D:\Eigene Dateien\My Received Files\FireFox Downloads\SmitfraudFix\SmitfraudFix\Reboot.exe tagged as "not-a-virus:RiskTool.Win32.Reboot.f". Action Taken: No Action Taken.
File D:\Eigene Dateien\My Received Files\FireFox Downloads\SmitfraudFix.zip/SmitfraudFix/Reboot.exe tagged as "not-a-virus:RiskTool.Win32.Reboot.f". Action Taken: No Action Taken.
File D:\StyleXP\Screensaverz\MAtrixcode\neomatrix3dinst.exe//WiseSFX Dropper//WISE0019.BIN tagged as "not-a-virus:AdWare.Win32.WebRebates.p". Action Taken: No Action Taken.
File D:\StyleXP\Screensaverz\Neo\neomatrix3dinst.exe//WiseSFX Dropper//WISE0019.BIN tagged as "not-a-virus:AdTool.Win32.WhenU.a". Action Taken: No Action Taken.
File D:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP483\A0033703.exe tagged as "not-a-virus:Client-IRC.Win32.mIRC.616". No Action Taken.
File D:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP483\A0033988.exe tagged as "not-a-virus:Client-IRC.Win32.mIRC.62". No Action Taken.
File D:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP483\A0033991.exe//stream//data0006 tagged as "not-a-virus:Client-IRC.Win32.mIRC.62". No Action Taken.
File D:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP483\A0034000.exe tagged as "not-a-virus:Client-IRC.Win32.mIRC.616". No Action Taken.
File D:\System Volume Information\_restore{6C9E4A40-90C1-4857-B57A-F00017968911}\RP483\A0034135.EXE tagged as "not-a-virus:Client-IRC.Win32.mIRC.591". No Action Taken.
~~~~~~~~~~~
~~~~ Offending files
~~~~~~~~~~~
Offending file found: C:\WINDOWS\system32\process.exe
Offending file found: C:\WINDOWS\system32\swreg.exe
Offending file found: C:\WINDOWS\system32\swsc.exe
Offending file found: C:\Dokumente und Einstellungen\thomas\Desktop\desktop\blubb\online security guide.url
Offending file found: C:\Dokumente und Einstellungen\thomas\Desktop\desktop\blubb\security troubleshooting.url
Offending file found: D:\Eigene Dateien\my received files\firefox downloads\smitfraudfix\smitfraudfix\process.exe
Offending file found: D:\Eigene Dateien\my received files\firefox downloads\smitfraudfix\smitfraudfix\reboot.exe
Offending file found: D:\Eigene Dateien\my received files\firefox downloads\smitfraudfix\smitfraudfix\swreg.exe
Offending file found: D:\Eigene Dateien\my received files\firefox downloads\smitfraudfix\smitfraudfix\swsc.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a10\a\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a10\a\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a10\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a10\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a11\a\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a11\a\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a11\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a11\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a13\a\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a13\a\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a13\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a13\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a14\a\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a14\a\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a14\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a14\a\obj\debug\a.exe

Beatfried 24.09.2007 17:29

Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a15\a\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a15\a\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a15\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a15\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a4\a\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a4\a\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a4\b\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a4\b\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a4\c\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a4\c\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a4\d\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a4\d\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a5\a\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a5\a\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a5\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a5\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a6\a\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a6\a\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a6\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a6\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a7\a\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a7\a\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a7\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a7\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a8\a\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a8\a\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a8\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a8\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a9\a\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a9\a\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a9\a\bin\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\schule\m118\a9\a\obj\debug\a.exe
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\sicherung c und d\desktop\desktop 25.8.06\forum\1. save 1.7.06\sources\display.php
Offending file found: C:\Dokumente und Einstellungen\All Users\Dokumente\sicherung c und d\desktop\desktop 25.8.06\forum\2. save 7.8.06\sources\display.php
Offending file found: C:\Dokumente und Einstellungen\All Users\Startmenü\online security guide.url
Offending file found: C:\Dokumente und Einstellungen\All Users\Startmenü\security troubleshooting.url
Offending file found: D:\Eigene Dateien\my received files\firefox downloads\smitfraudfix\smitfraudfix\process.exe
Offending file found: D:\Eigene Dateien\my received files\firefox downloads\smitfraudfix\smitfraudfix\reboot.exe
Offending file found: D:\Eigene Dateien\my received files\firefox downloads\smitfraudfix\smitfraudfix\swreg.exe
Offending file found: D:\Eigene Dateien\my received files\firefox downloads\smitfraudfix\smitfraudfix\swsc.exe
~~~~~~~~~~~
Ordner
~~~~~~~~~~~
Offending Folder found: C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\winzix
Offending Folder found: C:\Dokumente und Einstellungen\All Users\Startmenü\programme\winzix
~~~~~~~~~~~
Registry
~~~~~~~~~~~
Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\video access activex object !!!
Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\windows safety alert !!!
Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache\winzix_is1 !!!
Offending Key found: HKLM\Software\Microsoft\Windows\CurrentVersion\uninstall\winzix_is1 !!!
Offending Key found: HKCU\software\microsoft\windows\currentversion\explorer\menuorder\start menu\programs\winzix !!!
Offending Key found: HKCR\.zix !!!
Offending Key found: HKCR\winzix !!!
Offending Key found: HKCR\winzixmanager.winzixshell !!!
Offending Key found: HKCR\winzixmanager.winzixshell.1 !!!


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Diverses
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
Prozesse und Module
~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~
Scanfehler
~~~~~~~~~~~~~~~~~~~~~~
C:\DOKUME~1\thomas\LOKALE~1\Temp\5spvbkbo.exe not Scanned. Possibly password protected...
C:\Dokumente und Einstellungen\thomas\Lokale Einstellungen\Temp\5spvbkbo.exe not Scanned. Possibly password protected...
C:\Programme\Adobe\Adobe Premier Pro 7.0\Andere Software\DivX_Pro_v5.0.5_(ECLIPSE)_shared_by_scheune2003.rar not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SDK\v2.0\CompactFramework\netcfsetupv2.msi not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v1.0\WindowsCE\Diagnostics\System_SR_CHS_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v1.0\WindowsCE\Diagnostics\System_SR_CHT_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v1.0\WindowsCE\Diagnostics\System_SR_DE_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v1.0\WindowsCE\Diagnostics\System_SR_ENU_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v1.0\WindowsCE\Diagnostics\System_SR_ES_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v1.0\WindowsCE\Diagnostics\System_SR_FR_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v1.0\WindowsCE\Diagnostics\System_SR_IT_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v1.0\WindowsCE\Diagnostics\System_SR_JA_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v1.0\WindowsCE\Diagnostics\System_SR_KO_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v1.0\WindowsCE\WCE500\ARMV4i\NETCFv1.WM.ARMV4I.CAB not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\Diagnostics\System_SR_CHS_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\Diagnostics\System_SR_CHT_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\Diagnostics\System_SR_DE_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\Diagnostics\System_SR_ENU_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\Diagnostics\System_SR_ES_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\Diagnostics\System_SR_FR_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\Diagnostics\System_SR_IT_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\Diagnostics\System_SR_JA_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\Diagnostics\System_SR_KO_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\Diagnostics\System_SR_pt-BR_wm.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\wce400\armv4\NETCFv2.ppc.armv4.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\wce500\armv4i\NETCFv2.wce5.armv4i.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\wce500\armv4i\NETCFv2.wm.armv4i.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\wce500\mipsii\NETCFv2.wce5.mipsii.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\wce500\mipsiv\NETCFv2.wce5.mipsiv.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\wce500\sh4\NETCFv2.wce5.sh4.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\CompactFramework\2.0\v2.0\WindowsCE\wce500\x86\NETCFv2.wce5.x86.cab not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\SQL Server\Client\v2.0\wce500\armv4i\sql.dev.DE.phone.wce5.armv4i.CAB not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\SQL Server\Client\v2.0\wce500\armv4i\sql.dev.DE.ppc.wce5.armv4i.CAB not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\SQL Server\Client\v2.0\wce500\armv4i\sql.phone.wce5.armv4i.CAB not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\SQL Server\Client\v2.0\wce500\armv4i\sql.ppc.wce5.armv4i.CAB not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\SQL Server\Mobile\v3.0\wce500\armv4i\sqlce30.dev.DE.phone.wce5.armv4i.CAB not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\SQL Server\Mobile\v3.0\wce500\armv4i\sqlce30.dev.DE.ppc.wce5.armv4i.CAB not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\SQL Server\Mobile\v3.0\wce500\armv4i\sqlce30.phone.wce5.armv4i.CAB not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\SQL Server\Mobile\v3.0\wce500\armv4i\sqlce30.ppc.wce5.armv4i.CAB not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\SQL Server\Mobile\v3.0\wce500\armv4i\sqlce30.repl.phone.wce5.armv4i.CAB not Scanned. Possibly password protected...
C:\Programme\Microsoft Visual Studio 8\SmartDevices\SDK\SQL Server\Mobile\v3.0\wce500\armv4i\sqlce30.repl.ppc.wce5.armv4i.CAB not Scanned. Possibly password protected...
C:\WINDOWS\Resources\Themes\Eclipse\shell\normalcolor\shellstyle.dll not Scanned. Possibly password protected...
D:\RECYCLER\S-1-5-21-1292428093-1383384898-725345543-1003\Dd69.exe not Scanned. Possibly password protected...
D:\RECYCLER\S-1-5-21-1292428093-1383384898-725345543-1003\Dd70\RENEGADE KeyGen\Sony 5.1 Surround Plug-in Pack KeyGen 1.exe not Scanned. Possibly password protected...
D:\RECYCLER\S-1-5-21-1292428093-1383384898-725345543-1003\Dd70\RENEGADE KeyGen\Sony 5.1 Surround Plug-in Pack KeyGen 2.exe not Scanned. Possibly password protected...
D:\RECYCLER\S-1-5-21-1292428093-1383384898-725345543-1003\Dd73\RENEGADE KeyGen\KEYGEN.EXE not Scanned. Possibly password protected...
~~~~~~~~~~~~~~~~~~~~~~
Hosts-Datei
~~~~~~~~~~~~~~~~~~~~~~
DataBasePath: %SystemRoot%\System32\drivers\etc
C:\WINDOWS\System32\drivers\etc\hosts :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Statistiken:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Total Critical Objects: 417
Total Disinfected Objects: 0
Total Objects Renamed: 0
Total Deleted Objects: 0
Total Errors: 279
Time Elapsed: 03:38:52
Total Objects Scanned: 248037
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan-Optionen
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Memory Check: Enabled
Registry Check: Enabled
System Folder Check: Enabled
System Area Check: Disabled
Services Check: Enabled
Drive Check: Disabled
All Drive Check :Enabled
All Drive Check :Enabled

Batchstart: 18:16:35.17
Batchende: 18:17:19.21

Beatfried 24.09.2007 17:30

entschuldgt bitte die vielen Posts

Aber ich darf ja nur 25'000 Zeichen pro Post setzen, dadurch musste ich das Logfile ein bisschen auseinander nehmen.

KarlKarl 24.09.2007 17:58

Hi,

bei dem Durchseuchungsgrad, dazu dem Umstand, dass Du dein System mit Cracks und Keygens installierst, solltest Du einfach mal formatieren und neu installieren. Diesmal ohne Cracks und Keygens. Solltest Du kein Geld für Software haben, dann habe ich hier eine coole Seite, wo Du dir Spitzensoftware frei laden kannst.

Gruß, Karl

BataAlexander 24.09.2007 18:05

Ich habe noch nie solch ein eScan Log gesehen, wundere mich das KarlKarl da schon durch ist. :D
Aber er hat recht, Keygens, Cracks etc bringen Dein System dahin, wo es jetzt ist.
Hier hilft nur das.


Alle Zeitangaben in WEZ +1. Es ist jetzt 15:22 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131