Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Mülltonne (https://www.trojaner-board.de/muelltonne/)
-   -   escan Log!! (https://www.trojaner-board.de/42768-escan-log.html)

lilmiss 29.08.2007 01:33

escan Log!!
 
Hallo,

ich habe bei mir mal escan durchlaufen lassen und das wurde gefunden.
Kann mir jemand bei der auswertung bzw beseitigung helfen??


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Header
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Microsoft Windows XP [Version 5.1.2600]
Wed Aug 29 01:26:48 2007 => Version 9.3.8 (C:\DOKUME~1\Besitzer\LOKALE~1\Temp\mexe.com)
Wed Aug 29 02:05:00 2007 => Virus Database Date: 8/22/2007
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Infektionsmeldungen
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Wed Aug 29 01:37:45 2007 => System found infected with yahoospymon Spyware/Adware ({a4643a87-99a0-4404-9bc5-2322bdd61637})! Action taken: No Action Taken.
Wed Aug 29 01:37:45 2007 => System found infected with yahoospymon Spyware/Adware ({a46e5261-9956-4767-88ca-dfced050d09e})! Action taken: No Action Taken.
Wed Aug 29 01:37:45 2007 => System found infected with yahoospymon Spyware/Adware ({a7ec2cd3-9941-4fd4-9d01-105dc16a4313})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with video activex access Trojan ({7e853d72-626a-48ec-a868-ba8d5e23e045})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with yahoospymon Spyware/Adware ({1df3afed-99e0-4474-9900-954b8fd24e86})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with yahoospymon Spyware/Adware ({06544919-f559-4ae5-9001-f903bd8a84e6})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with yahoospymon Spyware/Adware ({4340df8e-d7a3-4675-be74-80077b2b3e81})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with yahoospymon Spyware/Adware ({51a0888c-9970-44de-8c2c-835ba870d06f})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with yahoospymon Spyware/Adware ({5acae4b8-62d9-4124-a58a-9b1258b77e99})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with yahoospymon Spyware/Adware ({7d37ded8-1945-4e42-a3fd-b9620e0ad8e3})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with whenu.savenow Spyware/Adware ({c285d18d-43a2-4aef-83fb-bf280e660a97})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with yahoospymon Spyware/Adware ({c4c23b78-db98-444c-b601-dcac6ebbec54})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with yahoospymon Spyware/Adware ({ccb7fb40-99ec-4678-9202-52798da78aba})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with yahoospymon Spyware/Adware ({d12fb216-99da-4eb3-9cc0-c0f760b174a0})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with yahoospymon Spyware/Adware ({d56c1af1-3fde-471c-9bc2-c52515f260c1})! Action taken: No Action Taken.
Wed Aug 29 01:37:46 2007 => System found infected with yahoospymon Spyware/Adware ({e656b867-992c-4462-a27d-ebe604ec3a48})! Action taken: No Action Taken.
Wed Aug 29 01:38:00 2007 => System found infected with uplink Adware (inetload.dll)! Action taken: No Action Taken.
Wed Aug 29 01:38:00 2007 => System found infected with uplink Adware (inetload.dll)! Action taken: No Action Taken.
Wed Aug 29 01:38:05 2007 => System found infected with yahoospymon Spyware/Adware (C:\WINDOWS\system32\mxpvct25.dat)! Action taken: No Action Taken.
~~~~~~~~~~~
Dateien
~~~~~~~~~~~
~~~~ Infected files
~~~~~~~~~~~
~~~~~~~~~~~
~~~~ Tagged files
~~~~~~~~~~~
~~~~~~~~~~~
~~~~ Offending files
~~~~~~~~~~~
Wed Aug 29 01:38:00 2007 => Offending file found: C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\temp\nskb.tmp\inetload.dll
Wed Aug 29 01:38:00 2007 => Offending file found: C:\Dokumente und Einstellungen\Besitzer\Lokale Einstellungen\temp\nssd.tmp\inetload.dll
Wed Aug 29 01:38:05 2007 => Offending file found: C:\WINDOWS\system32\mxpvct25.dat
~~~~~~~~~~~
Ordner
~~~~~~~~~~~
Wed Aug 29 01:37:52 2007 => Offending Folder found: C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\icq\bart\1024
~~~~~~~~~~~
Registry
~~~~~~~~~~~
Wed Aug 29 01:37:48 2007 => Offending Key found: HKLM\Software\magnet !!!
Wed Aug 29 01:37:49 2007 => Offending Key found: HKCU\\chilkat.email2 !!!
Wed Aug 29 01:37:49 2007 => Offending Key found: HKCU\\chilkat.emailbundle2 !!!
Wed Aug 29 01:37:49 2007 => Offending Key found: HKCU\\chilkat.mailman2 !!!
Wed Aug 29 01:37:49 2007 => Offending Key found: HKCU\\chilkatmail2.chilkatemail2 !!!
Wed Aug 29 01:37:49 2007 => Offending Key found: HKCU\\chilkatmail2.chilkatemailbundle2 !!!
Wed Aug 29 01:37:49 2007 => Offending Key found: HKCU\\chilkatmail2.chilkatmailman2 !!!
Wed Aug 29 01:37:49 2007 => Offending Key found: HKCU\\magnet !!!
Wed Aug 29 01:37:49 2007 => Offending Key found: HKLM\System\CurrentControlSet\Services\nwsapagent !!!
Wed Aug 29 01:37:49 2007 => Offending Key found: HKLM\System\ControlSet002\Services\nwsapagent !!!
Wed Aug 29 01:37:49 2007 => Offending Key found: HKLM\System\ControlSet003\Services\nwsapagent !!!
Wed Aug 29 01:38:10 2007 => Offending Key found: HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\X !!!
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Statistiken:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

ordell1234 29.08.2007 02:09

Hi,

welche Probleme hast du mit dem PC? Kein escan im abgesicherten Modus? Poste zusätzlich ein HJT-log. Aus den Einträgen allein werde ich ehrlich gesagt auch nicht schlau. Nutzt du winamp? Yahoo-Toolbar installiert? Azureus auf jeden Fall ;) und das ist gern Quell allen Übels.

Gruß


Alle Zeitangaben in WEZ +1. Es ist jetzt 19:41 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131