![]() |
Hilfe! Computervirus lässt PC herunterfahren Hallo und Hilfe!! :heulen: Irgendwelche Viren haben mein System befallen. Wenn ich ins Internet gehe kommt nach ca. 1 Minute die Nachricht, dass wegen C:\WINDOWS\SYSTEM32.lsass.exe der Computer heruntergefahren wird. Ich habe es mit mehreren Antivirus Programmen im abgesicherten Modus versucht wie Spybot Search und Ad Aware. Außerdem benutzte ich HijackThis, habe aber alle mir verdächtigen Dateien gelöscht und die sind übrig geblieben: Logfile of HijackThis v1.98.2 Scan saved at 18:31:11, on 10.12.2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\Explorer.EXE C:\DOKUME~1\SCHNEI~1\LOKALE~1\Temp\mwavscan.com C:\DOKUME~1\SCHNEI~1\LOKALE~1\Temp\kavss.exe C:\Programme\Microsoft Office\Office10\WINWORD.EXE C:\Dokumente und Einstellungen\Schneider\Desktop\HijackThis.exe F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE Dazu haben ich auch noch E-scan ausgeführt und diese lange Liste erhalten. Wäre sehr nett, wenn mir jemand helfen könnte!!! Moritz File C:\WINDOWS\telnet.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: No Action Taken. File C:\WINDOWS\silent48.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\msmsgsui.exe infected by "Trojan.Win32.StartPage.lj" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSCOM.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\remove_me.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: No Action Taken. File C:\WINDOWS\silent_install.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\notepad.com infected by "TrojanDropper.Win32.Small.lx" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wintii32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\bkmsf32.dat infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wintxa32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winnne32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winjei32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wintru32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\windfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winunu32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wincoz32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\windns32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wintft32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvhin32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\SYSCOM.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvbjd32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\bhosave.dat infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvdcm32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winmm64.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvcop32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvyfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvvaj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\remove_me.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\MSMSGSVC.exe infected by "TrojanDropper.Win32.Small.lx" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\79SETTHI\silent48[1].exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\79SETTHI\protector[1].exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YQ4H1I86\bobby[1].exe infected by "TrojanDownloader.Win32.Small.sg" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YQ4H1I86\protector_update[1].exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\24WEN45B\silent_install[1].exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\notepad.com infected by "TrojanDropper.Win32.Small.lx" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wintii32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\bkmsf32.dat infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wintxa32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winnne32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winjei32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wintru32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\windfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winunu32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wincoz32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\windns32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wintft32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvhin32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\SYSCOM.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvbjd32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\bhosave.dat infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvdcm32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winmm64.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvcop32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvyfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvvaj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\remove_me.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: No Action Taken. File C:\WINDOWS\telnet.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: No Action Taken. File C:\WINDOWS\silent48.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\msmsgsui.exe infected by "Trojan.Win32.StartPage.lj" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSCOM.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\remove_me.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: No Action Taken. Es geht noch weiter leider reicht der Platz nicht aus.... Vielleicht könnt ihr schon daraus erkennen wo der wurm drinsteckt. Danke im Voraus!! |
Hi, 1. Das ist nie und nimmer das ganze Logfile, oder? 2. Ja, man kann was erkennen --> Lade Dir erst mal clearprog 1.4.0 final runter und mache alle Häkchen bei IE und Windows. Drücke dann auf "löschen", wenn fertig auf "beenden". Dann erstellst du ein HJT Logfile im normalen Modus und postest das komplette Logfile hier rein. Dann gehts weiter. cacatoa |
Vielen Dank CACATOA!! habe clear prog durchlaufen lassen (allerding 1.4.1 final auch OK oder?) Hier die Logfile von Hijackthis (brauchst du auch die von Escan?) lieben gruss moritz :) Logfile of HijackThis v1.98.2 Scan saved at 19:02:14, on 11.12.2004 Platform: Windows XP (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 (6.00.2600.0000) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\AVPersonal\AVGUARD.EXE C:\WINDOWS\System32\atievxx.exe C:\Programme\AVPersonal\AVWUPSRV.EXE C:\WINDOWS\Explorer.EXE C:\Dokumente und Einstellungen\Schneider\Desktop\HijackThis.exe F2 - REG:system.ini: UserInit=C:\WINDOWS\System32\userinit.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE |
Ja, wenn Du schon ein neues eScan Logfile hast, dann rein damit! ;) |
Dein Logfile ist absolut sauber; aber es ist so kurz - hast Du wirklich nicht mehr laufen - oder was nicht reinkopiert? |
ja hijackthis findet nicht viel, dafür Escan umso mehr. ich lass es gerade durchlaufen und poste es dann hier Moritz |
Hier ist der Hauptteil vom Log. Der Rest kommt (aus Platzgründen) gleich. mo File C:\WINDOWS\telnet.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: No Action Taken. File C:\WINDOWS\silent48.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\msmsgsui.exe infected by "Trojan.Win32.StartPage.lj" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSCOM.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\remove_me.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: No Action Taken. File C:\WINDOWS\silent_install.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\notepad.com infected by "TrojanDropper.Win32.Small.lx" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wintii32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\bkmsf32.dat infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wintxa32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winnne32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winjei32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wintru32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\windfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winunu32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wincoz32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\windns32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wintft32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvhin32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\SYSCOM.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvbjd32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\bhosave.dat infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvdcm32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winmm64.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvcop32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvyfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvvaj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\remove_me.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\MSMSGSVC.exe infected by "TrojanDropper.Win32.Small.lx" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\79SETTHI\silent48[1].exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\79SETTHI\protector[1].exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YQ4H1I86\bobby[1].exe infected by "TrojanDownloader.Win32.Small.sg" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YQ4H1I86\protector_update[1].exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\24WEN45B\silent_install[1].exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\notepad.com infected by "TrojanDropper.Win32.Small.lx" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wintii32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\bkmsf32.dat infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wintxa32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winnne32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winjei32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wintru32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\windfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winunu32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wincoz32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\windns32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wintft32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvhin32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\SYSCOM.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvbjd32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\bhosave.dat infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvdcm32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winmm64.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvcop32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvyfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvvaj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\remove_me.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: No Action Taken. File C:\WINDOWS\telnet.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: No Action Taken. File C:\WINDOWS\silent48.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\msmsgsui.exe infected by "Trojan.Win32.StartPage.lj" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSCOM.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\remove_me.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: No Action Taken. File C:\WINDOWS\silent_install.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. |
Sag mal, was machst Du da? Im HJT-Logfile taucht gar nix von den Dateien auf, die eScan als infiziert zeigt; nix aus dem System32 Ordner z.B. Hast Du das HJT Logfile im normalen Modus erstellt? Das mußt Du nämlich; sonst hilfts gar nix... |
Ja hab ich! finds auch komisch, dass er nichts erkennt??? Hier der rest des escans. Hoffentlich kannst du irgendwas entdecken/bzw mir empfehlen zu tun! Danke für die Hilfe!!! File C:\WINDOWS\System32\notepad.com infected by "TrojanDropper.Win32.Small.lx" Virus. Action Taken:.No Action Taken. File C:\WINDOWS\System32\wintii32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\bkmsf32.dat infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wintxa32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winnne32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winjei32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wintru32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\windfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winunu32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wincoz32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\windns32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\wintft32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvhin32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\SYSCOM.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvbjd32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\bhosave.dat infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvdcm32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\winmm64.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvcop32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvyfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\kalvvaj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\System32\remove_me.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\MSMSGSVC.exe infected by "TrojanDropper.Win32.Small.lx" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\79SETTHI\silent48[1].exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.j" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\79SETTHI\protector[1].exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YQ4H1I86\bobby[1].exe infected by "TrojanDownloader.Win32.Small.sg" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YQ4H1I86\protector_update[1].exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\24WEN45B\silent_install[1].exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.q" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\notepad.com infected by "TrojanDropper.Win32.Small.lx" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wintii32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\bkmsf32.dat infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wintxa32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winnne32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winjei32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wintru32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\windfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\winunu32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wincoz32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\windns32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\wintft32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM32\kalvhin32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken. |
Also, ich kapier´s nicht. Jetzt mach mal folgendes: Du hast ja einen Ordner C:\bases für den eScan erstellt. Den leerst du jetzt. Lasse den Ordner bestehen!! Lade Dir diesen eScan (mwav.exe) runter; entpacke die Datei in den Ordner C:\bases. Update (kavupd.exe) und lasse den eScan im abgesicherten Modus laufen (mwavscan.com). Mache alle Häkchen, vor allem "scan all local drives". Dies ist eine alte eScan version, die die Malware auch löscht. Dann neuen Bericht von escan (mwavlog). Bis dann cacatoa |
Danke meld mich morgen wieder Schönen Abend Moritz |
Irgendwie lässt sich der scan nicht ausführern. Escan empfiehlt eine neuere Version downzuloaden und startet nicht?? Wie kann ich das umgehen? |
Mach doch einfach das, was ich Dir geschrieben habe. Genau lesen! (entpacke die Datei) |
Ok. Hier das neue Escan Log: File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\79SETTHI\silent48[1].exe tagged as not-a-virus:AdWare.ToolBar.EliteBar.j. No Action Taken. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\79SETTHI\protector[1].exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YQ4H1I86\bobby[1].exe infected by "TrojanDownloader.Win32.Small.sg" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\YQ4H1I86\protector_update[1].exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\config\systemprofile\Lokale Einstellungen\Temporary Internet Files\Content.IE5\24WEN45B\silent_install[1].exe tagged as not-a-virus:AdWare.ToolBar.EliteBar.q. No Action Taken. File C:\WINDOWS\SYSTEM32\notepad.com infected by "TrojanDropper.Win32.Small.lx" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\wintii32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\bkmsf32.dat infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\wintxa32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\winnne32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\winjei32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\wintru32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\windfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\winunu32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\wincoz32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\windns32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\wintft32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\doolsav.dat tagged as not-a-virus:AdWare.EliteBar. No Action Taken. File C:\WINDOWS\SYSTEM32\kalvhin32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\SYSCOM.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\kalvbjd32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\bhosave.dat tagged as not-a-virus:AdWare.ToolBar.EliteBar.q. No Action Taken. File C:\WINDOWS\SYSTEM32\kalvdcm32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\winmm64.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\kalvcop32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\kalvyfj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\kalvvaj32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSTEM32\remove_me.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: File Deleted. File C:\WINDOWS\telnet.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: File Deleted. File C:\WINDOWS\silent48.exe tagged as not-a-virus:AdWare.ToolBar.EliteBar.j. No Action Taken. File C:\WINDOWS\dpe.dll infected by "Trojan.Win32.StartPage.lj" Virus. Action Taken: File Deleted. File C:\WINDOWS\msmsgsui.exe infected by "Trojan.Win32.StartPage.lj" Virus. Action Taken: File Deleted. File C:\WINDOWS\SYSCOM.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: File Deleted. File C:\WINDOWS\remove_me.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: File Deleted. File C:\WINDOWS\silent_install.exe tagged as not-a-virus:AdWare.ToolBar.EliteBar.q. No Action Taken. File C:\Q8276112.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: File Deleted. File C:\RECYCLED\Q330995.exe infected by "Trojan.Win32.Small.bb" Virus. Action Taken: File Deleted. File C:\prot.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\FOUND.011\FILE0034.CHK infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\FOUND.012\FILE0000.CHK infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\FOUND.014\FILE0000.CHK infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\FOUND.018\FILE0015.CHK tagged as not-a-virus:AdWare.ToolBar.EliteBar.q. No Action Taken. File C:\ied_s7m.cab infected by "Trojan-Downloader.Win32.Mediket.h" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094840.dll tagged as not-a-virus:AdWare.ToolBar.EliteBar.n. No Action Taken. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094841.dll tagged as not-a-virus:AdWare.ToolBar.EliteBar.k. No Action Taken. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094842.dll tagged as not-a-virus:AdWare.ToolBar.EliteBar.k. No Action Taken. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094843.dll tagged as not-a-virus:AdWare.ToolBar.EliteBar.m. No Action Taken. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094844.dll tagged as not-a-virus:AdWare.ToolBar.EliteBar.q. No Action Taken. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094852.exe infected by "Trojan.Win32.StartPage.lj" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094853.exe infected by "TrojanDownloader.Win32.Small.sg" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094854.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094864.exe infected by "TrojanDownloader.Win32.Small.sg" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094865.exe infected by "Trojan.Win32.StartPage.lj" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094867.dll tagged as not-a-virus:AdWare.EliteBar. No Action Taken. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094871.DLL infected by "Trojan.Win32.StartPage.lj" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP81\A0094884.dll tagged as not-a-virus:AdWare.EliteBar. No Action Taken. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097492.exe infected by "TrojanDropper.Win32.Small.lx" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097495.com infected by "TrojanDropper.Win32.Small.lx" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097496.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097497.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097498.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097499.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097500.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097501.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097502.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097503.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097504.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097505.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097506.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. |
und der 2.teil File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097507.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097508.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097509.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097510.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097511.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097512.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097513.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097514.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097517.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097519.dll infected by "Trojan.Win32.StartPage.lj" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097520.exe infected by "Trojan.Win32.StartPage.lj" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097521.dll infected by "TrojanDownloader.Win32.Small.zq" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097522.dll infected by "Trojan.Win32.StartPage.ld" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097529.exe infected by "Trojan.Win32.StartPage.ht" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097530.exe infected by "Trojan.Win32.Small.bb" Virus. Action Taken: File Deleted. File C:\System Volume Information\_restore{502F088A-BAD0-4436-B496-08B0C33443C7}\RP82\A0097531.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: File Deleted. |
Alle Zeitangaben in WEZ +1. Es ist jetzt 09:59 Uhr. |
Copyright ©2000-2025, Trojaner-Board