SuppiSuppenh | 12.01.2012 15:05 | Vorsorgescan eröffnete Trojanerverseuchung, jedoch keine Symptome ... Hallo Gemeinde,
aus purer Paranoia habe ich einen Scan meines Systems mit dem Avira Rescue Stick durchgeführt.
Dummerweise fand er diverse Trojaner auf meinem System und jetzt bin ich verunsichert. Code:
Avira / Linux Version 1.9.152.0
Copyright (c) 2010 by Avira GmbH
All rights reserved.
engine set: 8.2.8.22
VDF Version: 7.11.20.251
Scan start time: Thu Jan 12 08:35:31 2012
configuration file: /etc/avira/scancl.conf
WARNING: [Archive is invalid or corrupt] /media/Devices/sda2/Program Files/WinRAR/rarnew.dat
WARNING: [Unexpected end of file] /media/Devices/sda2/Program Files (x86)/Alcohol Soft/Alcohol 120/KillAlSrvN.exe
WARNING: [Unexpected end of file] /media/Devices/sda2/Program Files (x86)/Alcohol Soft/Alcohol 120/PatCh503Ru.exe
WARNING: [Unexpected end of file] /media/Devices/sda2/Program Files (x86)/Alcohol Soft/Alcohol 120/unins.exe
WARNING: [Bad compressed data] /media/Devices/sda2/Program Files (x86)/SlySoft/AnyDVD/AnyDVD-uninst.exe
ALERT: [TR/Injector.afc.1] /media/Devices/sda2/Program Files (x86)/SlySoft/AnyDVD/AnyTrial.exe <<< Is the Trojan horse TR/Injector.afc.1 [renamed]
WARNING: [Unexpected end of file] /media/Devices/sda2/Program Files (x86)/MP3Gain/uninst-mp3gain.exe
WARNING: [Bad compressed data] /media/Devices/sda2/Program Files (x86)/Elaborate Bytes/CloneDVD2/CloneDVD2-uninst.exe
WARNING: [Unexpected end of file] /media/Devices/sda2/Program Files (x86)/Object/facetheme_uninstall.exe
ALERT: [TR/Crypt.ZPACK.Gen] /media/Devices/sda2/ProgramData/Norton/{0C55C096-0F1D-4F28-AAA2-85EF591126E7}/NIS_19.1.1.3/QBackup/{5AB57B46-38BE-4CBA-98CB-3CA51D075444}/{F2BCF3DF-F925-42B3-8C93-835C1F7659D6}.qbd <<< Is the Trojan horse TR/Crypt.ZPACK.Gen [renamed]
ALERT: [TR/Dropper.Gen] /media/Devices/sda2/ProgramData/Norton/{0C55C096-0F1D-4F28-AAA2-85EF591126E7}/NIS_19.1.1.3/QBackup/{C6975345-DAAB-4338-9927-97A5CF33BA91}/{94201659-727B-4878-9DF3-FE2B2F403229}.qbd <<< Is the Trojan horse TR/Dropper.Gen [renamed]
ALERT: [TR/Crypt.ULPM.Gen] /media/Devices/sda2/ProgramData/Norton/{0C55C096-0F1D-4F28-AAA2-85EF591126E7}/NIS_19.1.1.3/QBackup/{EAB2611A-BD47-4F38-BED7-84FF5B2D671B}/{15AD2FBF-2067-410D-B1C6-B6A1755F032A}.qbd <<< Is the Trojan horse TR/Crypt.ULPM.Gen [renamed]
ALERT: [TR/Crypt.XPACK.Gen] /media/Devices/sda2/ProgramData/Norton/{0C55C096-0F1D-4F28-AAA2-85EF591126E7}/NIS_19.1.1.3/QBackup/{FFA31738-2261-40FD-86F2-C21DF04CCFEA}/{DB9F1F46-9668-4800-8E63-9BC47EE3BF74}.qbd <<< Is the Trojan horse TR/Crypt.XPACK.Gen [renamed]
ALERT: [TR/Spy.41202.1] /media/Devices/sda2/ProgramData/Norton/{0C55C096-0F1D-4F28-AAA2-85EF591126E7}/NIS_19.1.1.3/QBackup/{1ED15F57-0285-4E37-A5AE-D45A1EEF1F4B}/{9509E049-433A-4FBA-92E0-02A10BFF418F}.qbd <<< Is the Trojan horse TR/Spy.41202.1 [archive scan abort]
[renamed]
WARNING: [Unexpected end of file] /media/Devices/sda2/Windows.old/Program Files/MP3Gain/uninst-mp3gain.exe
WARNING: [Bad compressed data] /media/Devices/sda2/Windows.old/Program Files/Elaborate Bytes/CloneDVD2/CloneDVD2-uninst.exe
ALERT: [TR/Crypt.XPACK.Gen] /media/Devices/sda2/Windows.old/ProgramData/Norton/{0C55C096-0F1D-4F28-AAA2-85EF591126E7}/NIS_17.0.0.136/QBackup/{8E186677-7927-41DC-97D5-CD3F2F3A4456}/{6784A321-4E45-45B1-8535-57CAC02E191E}.qbd <<< Is the Trojan horse TR/Crypt.XPACK.Gen [renamed]
ALERT: [TR/Crypt.XPACK.Gen] /media/Devices/sda2/Windows.old/ProgramData/Norton/{0C55C096-0F1D-4F28-AAA2-85EF591126E7}/NIS_17.0.0.136/QBackup/{AF1E1C15-B8B9-45EF-9B8E-23C86F775CD7}/{593BB74B-042D-4B42-82A0-B68BC4179113}.qbd <<< Is the Trojan horse TR/Crypt.XPACK.Gen [renamed]
ALERT: [TR/Crypt.XPACK.Gen] /media/Devices/sda2/Windows.old/ProgramData/Norton/{0C55C096-0F1D-4F28-AAA2-85EF591126E7}/NIS_17.0.0.136/QBackup/{CE02A57B-070C-4ACD-9BDA-35310E78E91A}/{EB210285-D334-4AD1-B188-3505212E5E9A}.qbd <<< Is the Trojan horse TR/Crypt.XPACK.Gen [renamed]
ALERT: [TR/Crypt.XPACK.Gen] /media/Devices/sda2/Windows.old/ProgramData/Norton/{0C55C096-0F1D-4F28-AAA2-85EF591126E7}/NIS_17.0.0.136/QBackup/{A7DD84D1-596C-4785-98CE-FF0652F57212}/{9E0D410E-185D-43D2-9534-58CE656CE803}.qbd <<< Is the Trojan horse TR/Crypt.XPACK.Gen [renamed]
ALERT: [TR/Dropper.Gen] /media/Devices/sda2/Windows.old/ProgramData/Norton/{0C55C096-0F1D-4F28-AAA2-85EF591126E7}/NIS_17.0.0.136/QBackup/{856109F9-AB1F-4379-89E4-6F3B7D08495B}/{F15262FE-F1CD-456F-9E24-7D6406C0E90B}.qbd <<< Is the Trojan horse TR/Dropper.Gen [renamed]
ALERT: [TR/Crypt.XPACK.Gen] /media/Devices/sda2/Windows.old/ProgramData/Norton/{0C55C096-0F1D-4F28-AAA2-85EF591126E7}/NIS_17.0.0.136/QBackup/{E7F4F7F9-4C75-4150-B40A-4DA409498524}/{E0FAFCEE-8338-4152-A6B9-111F2D5954CF}.qbd <<< Is the Trojan horse TR/Crypt.XPACK.Gen [renamed]
WARNING: [Bad compressed data] /media/Devices/sda3/$RECYCLE.BIN/S-1-5-21-70281867-4158294589-2997307768-1000/$RXCXIN3/SlySoft CloneDVD 2.9.2.7 Final/SetupCloneDVD2927Slysoft.exe
WARNING: [Unexpected end of block read] /media/Devices/sda3/$RECYCLE.BIN/S-1-5-21-811033279-2739718686-4159157551-1000/$REPG40C.mdf
WARNING: [Unexpected end of block read] /media/Devices/sda3/$RECYCLE.BIN/S-1-5-21-811033279-2739718686-4159157551-1000/$RXGJU57.mdf
WARNING: [Unsupported archive version] /media/Devices/sda3/Downloads/CD_MARKER.7z/CD_MARKER.7z
WARNING: [File is encrypted] /media/Devices/sda3/Downloads/AnyDVD_&_AnyDVD_HD_v6.8.7.0_Final.rar
WARNING: [Bad compressed data] /media/Devices/sda3/Downloads/PDFCreator-1_2_0_setup.exe
WARNING: [All files in archive are encrypted] /media/Devices/sda3/Downloads/2927.exe
WARNING: [File is encrypted] /media/Devices/sda3/Downloads/Tobias-Riefer_Download_14-09-2009_01-35.exe
WARNING: [All files in archive are encrypted] /media/Devices/sda3/Downloads/Eni90.rar
WARNING: [File is encrypted] /media/Devices/sda3/Downloads/CloneDVD_v2.9.3.0.rar
WARNING: [Unsupported archive version] /media/Devices/sda3/Downloads/lm98.zip --> LM98INST.EXE
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/clockworkŭOdက/backup/2011-09-01-06.45.47/data.img
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/262364
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/276524
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/277011
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/277360
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/278426
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/278490
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/278626
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/278958
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/279036
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/280579
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/280632
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/280771
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/281561
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/281779
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/286159
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/286223
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/293900
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/294609
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/294848
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/294862
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/294972
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/295623
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/295635
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/295640
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/295647
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/295932
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/296017
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/298016
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/298055
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/298163
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/298170
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/298645
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/298678
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/298700
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/298835
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/298875
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/298886
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/298932
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/298998
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/299123
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/299405
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/299778
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/299884
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/299941
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/300010
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/300232
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/300519
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/300590
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/300877
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/300943
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/301200
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/301390
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/301476
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/301509
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/301542
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/301779
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/301792
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/301816
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/302149
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/311892
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/311922
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/312447
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/313280
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/313528
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/314149
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/314604
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/314611
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/314821
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/314900
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/315142
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/315148
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/315390
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/315708
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/315721
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/316823
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/317596
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/317629
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/317775
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/317800
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/317821
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/318547
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/320221
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/320399
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/299362
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/315790
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/316807
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/320793
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/363936
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/363973
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/364844
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/364862
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/364899
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/365648
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/366103
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/366430
WARNING: [Bad archive header] /media/Devices/sda3/Handy_SD/LOST.DIR/403610
WARNING: [Archive not completly scanned. Reason: maximum compression ratio (250) reached] /media/Devices/sda3/Handy_SD/titani~1. 0/com.aurorasoftworks.quadrant.ui.standard-20110901-043747.tar.gz --> com.aurorasoftworks.quadrant.ui.standard-20110901-043747.tar
WARNING: [An abort was triggered by the progress callback] /media/Devices/sda3/Handy_SD/titani~1. 0/com.aurorasoftworks.quadrant.ui.standard-20110901-043747.tar.gz/com.aurorasoftworks.quadrant.ui.standard-20110901-043747.tar
WARNING: [Archive not completly scanned. Reason: maximum compression ratio (250) reached] /media/Devices/sda3/Handy_SD/TIÈANI~2/com.aurorasoftworks.quadrant.ui.standard-20111026-054217.tar.gz --> com.aurorasoftworks.quadrant.ui.standard-20111026-054217.tar
WARNING: [An abort was triggered by the progress callback] /media/Devices/sda3/Handy_SD/TIÈANI~2/com.aurorasoftworks.quadrant.ui.standard-20111026-054217.tar.gz/com.aurorasoftworks.quadrant.ui.standard-20111026-054217.tar
WARNING: [All files in archive are encrypted] /media/Devices/sda3/Navigation/ploq.rar
WARNING: [The files in archive are multiple volume] /media/Devices/sda3/OFFICE10_SP3.mdf --> FILES/OSP/1031/IE5/GE/IENT_S1.CAB --> IENT_1.CAB
WARNING: [The files in archive are multiple volume] /media/Devices/sda3/OFFICE10_SP3.mdf --> FILES/OSP/1031/IE5/GE/IENT_S2.CAB --> IENT_2.CAB
WARNING: [The files in archive are multiple volume] /media/Devices/sda3/OFFICE10_SP3.mdf --> FILES/OSP/1031/IE5/GE/IENT_S3.CAB --> IENT_3.CAB
WARNING: [The files in archive are multiple volume] /media/Devices/sda3/OFFICE10_SP3.mdf --> FILES/OSP/1031/IE5/GE/IENT_S4.CAB --> IENT_4.CAB
WARNING: [The files in archive are multiple volume] /media/Devices/sda3/OFFICE10_SP3.mdf --> FILES/OSP/1031/IE5/GE/IENT_S5.CAB --> IENT_5.CAB
WARNING: [The files in archive are multiple volume] /media/Devices/sda3/OFFICE10_SP3.mdf --> FILES/OSP/1031/IE5/GE/IE_S1.CAB --> IE_1.CAB
WARNING: [The files in archive are multiple volume] /media/Devices/sda3/OFFICE10_SP3.mdf --> FILES/OSP/1031/IE5/GE/IE_S2.CAB --> IE_2.CAB
WARNING: [The files in archive are multiple volume] /media/Devices/sda3/OFFICE10_SP3.mdf --> FILES/OSP/1031/IE5/GE/IE_S3.CAB --> IE_3.CAB
WARNING: [The files in archive are multiple volume] /media/Devices/sda3/OFFICE10_SP3.mdf --> FILES/OSP/1031/IE5/GE/IE_S4.CAB --> IE_4.CAB
WARNING: [File is encrypted] /media/Devices/sda3/Spiele/Ankh - Kampf der Götter/Disk/ANKH_3.mdf --> files/programme/DarkVoid_PhysX_Update_Patch.exe
WARNING: [Error writing file] /media/Devices/sda3/Spiele/Ankh - Kampf der Götter/Disk/ANKH_3.mdf
WARNING: [Unexpected end of file] /media/Devices/sda3/Spiele/NDS/RToolDS/uninst.exe
WARNING: [All files in archive are encrypted] /media/Devices/sda3/Spiele/Simon the Sorcerer - Chaos ist das halbe Leben/Patch/Simon The Sorcerer 4/Crack/crack.exe
WARNING: [All files in archive are encrypted] /media/Devices/sda3/Spiele/Simon the Sorcerer - Chaos ist das halbe Leben/Patch/Simon The Sorcerer 4 Crack Nocd - Activation Multilanguage - Certified -.zip --> Simon The Sorcerer 4/Crack/crack.exe
ALERT: [SPR/Tool.PassView.XA] /media/Devices/sda3/Werkzeuge/Keyfinder.2.0.1/keyfinder.exe <<< Contains signature of the SPR/Tool.PassView.XA program [renamed]
Statistics :
Directories............... : 49757
Archives.................. : 8463
Files..................... : 1300074
Infected.............. : 13
Renamed........... : 13
Warnings.............. : 137
Suspicious............ : 0
Infections................ : 13 Habe dann gleich versucht die Anweisungen von hier umzusetzen.
Dummerweise erzeugt OTL einen "Out of Memory" Fehler. :-(
Kann mir jemand helfen ?
Gruß,
Suppi
PS:
Benutze Win7 64bit mit 4GB Arbeitspeicher
Norton Internet Security 2012
Systemwiederherstellung ist aus
Bin jetzt nach einigem Lesen auf RSIT gestoßen und habe mal die LOGS von RSIT (info.txt) und - trotzdem - HJT (log.txt) angehängt ... |