Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   about:blankm startseite (https://www.trojaner-board.de/11896-about-blankm-startseite.html)

germanguy 10.01.2005 14:58

about:blankm startseite
 
o.k., also noch mal mein problem!
ich hab auch so eine tolle startseite, die ich nicht wegbekomme und die mir genügned seiten versperrt durch ständiges auftreten! :(

also hier meine auswertung:

hxxp://www.hijackthis.de/logfiles/209491127496387f78ba6c3755ec91a6.html

danke!

HerrKautz 10.01.2005 15:22

Hallo,

es ist für uns einfacher,wenn du das Log "hier" reinstellst,das lässt sich für uns wesentlich besser kopieren!

germanguy 10.01.2005 15:27

gut, kein problem!

Logfile of HijackThis v1.99.0
Scan saved at 14:38:04, on 10.01.2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\System32\GEARSEC.EXE
C:\Programme\Ahead\InCD\InCDsrv.exe
C:\WINDOWS\System32\nvsvc32.exe
C:\Programme\Trend Micro\PC-cillin 2002\Tmntsrv.exe
C:\Programme\Trend Micro\PC-cillin 2002\PCCPFW.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\htpatch.exe
C:\WINDOWS\System32\RunDll32.exe
C:\Programme\Ahead\InCD\InCD.exe
C:\Programme\Trend Micro\PC-cillin 2002\pccguide.exe
C:\Programme\Trend Micro\PC-cillin 2002\PCCClient.exe
C:\Programme\Trend Micro\PC-cillin 2002\Pop3trap.exe
C:\Programme\iTunes\iTunesHelper.exe
C:\Programme\QuickTime\qttask.exe
C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
C:\Programme\Hewlett-Packard\HP Software Update\HPWuSchd2.exe
C:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\NCLAUNCH.EXe
C:\Programme\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
C:\Programme\MSN Messenger\MsnMsgr.Exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\iPod\bin\iPodService.exe
C:\Programme\Microsoft AntiSpyware\gcasDtServ.exe
C:\Programme\iTunes\iTunes.exe
C:\PROGRA~1\INTERN~1\iexplore.exe
C:\WINDOWS\ISW\netcol.dsl\signup\Tray.exe
C:\WINDOWS\System32\wuauclt.exe
C:\Dokumente und Einstellungen\Röbse\Desktop\Spyware\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = about:NavigationFailure
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = about:NavigationFailure
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,HomeOldSP = about:blank
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx
O2 - BHO: (no name) - {2FCF8DEE-3C4F-472A-B62F-B23ABFC44C17} - C:\WINDOWS\System32\nggpfaa.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar1.dll
O3 - Toolbar: MSN - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Programme\MSN Apps\MSN Toolbar\01.02.3000.1001\de\msntb.dll (file missing)
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [InCD] C:\Programme\Ahead\InCD\InCD.exe
O4 - HKLM\..\Run: [pccguide.exe] "C:\Programme\Trend Micro\PC-cillin 2002\pccguide.exe"
O4 - HKLM\..\Run: [PCCClient.exe] "C:\Programme\Trend Micro\PC-cillin 2002\PCCClient.exe"
O4 - HKLM\..\Run: [Pop3trap.exe] "C:\Programme\Trend Micro\PC-cillin 2002\Pop3trap.exe"
O4 - HKLM\..\Run: [iTunesHelper] C:\Programme\iTunes\iTunesHelper.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [WinDSL MTU-Adjust] WinDSL_MTU.exe
O4 - HKLM\..\Run: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -minimize
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb08.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Programme\Hewlett-Packard\HP Software Update\HPWuSchd2.exe"
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Programme\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [Microsoft Update Config] winsl.exe
O4 - HKLM\..\Run: [sys32diag] C:\WINDOWS\System32\expolrer.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [gcasServ] "C:\Programme\Microsoft AntiSpyware\gcasServ.exe"
O4 - HKLM\..\RunServices: [Microsoft Update Config] winsl.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [NCLaunch] C:\WINDOWS\NCLAUNCH.EXe
O4 - HKCU\..\Run: [Microsoft Update Config] winsl.exe
O4 - HKCU\..\Run: [crypt] C:\WINDOWS\System32\expolrer.exe
O4 - HKCU\..\Run: [PeerGuardian] C:\Programme\PeerGuardian pr14\PeerGuardian_1.99b_pr14.exe
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\programme\google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Im Cache gespeicherte Seite - res://c:\programme\google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Verweisseiten - res://c:\programme\google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Ähnliche Seiten - res://c:\programme\google\GoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE
O12 - Plugin for .spop: C:\Programme\Internet Explorer\Plugins\NPDocBox.dll
O14 - IERESET.INF: START_PAGE_URL=http://www.internetcologne.de
O17 - HKLM\System\CCS\Services\Tcpip\..\{9DB41665-61F1-492E-96E0-6A5B4072C0A0}: NameServer = 81.173.194.68 194.8.194.60
O18 - Filter: text/html - {0760B7CB-B253-44B7-B722-12EC90FFD758} - C:\WINDOWS\System32\nggpfaa.dll
O18 - Filter: text/plain - {0760B7CB-B253-44B7-B722-12EC90FFD758} - C:\WINDOWS\System32\nggpfaa.dll
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\System32\GEARSEC.EXE
O23 - Service: InCD File System Service - AHEAD Software - C:\Programme\Ahead\InCD\InCDsrv.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Driver Helper Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: PC-cillin PersonalFirewall - Trend Micro Inc. - C:\Programme\Trend Micro\PC-cillin 2002\PCCPFW.exe
O23 - Service: Trend NT Realtime Service - Trend Micro Inc. - C:\Programme\Trend Micro\PC-cillin 2002\Tmntsrv.exe

HerrKautz 10.01.2005 15:31

Ich denke bei dir ist einiges im argen,es sieht nicht gut aus,und vermutlich musst du das System neu aufsetzen,mach aber bitte noch einen escan im abgesicherten Modus,gehe dazu genau nach Anleitung vor http://www.trojaner-board.de/42731-escan-anleitung.html poste dann bitte das Ergebnis hier her!

germanguy 10.01.2005 17:34

so, bin durch...mitdem scan!
ist aber richtig lang das log file..
soll ichs trotzdem hier posted?

Chris14 10.01.2005 17:35

ähm nein. das ganze log nicht. du öffnest die logdatei (also mwav.log), klickst auf bearbeiten dann auf suchen. dort gibst du infected ein. suche weiter und poste alle treffer indem du die treffer markierst und ins forum kopierst

germanguy 10.01.2005 18:13

guti

also los:

=> File C:\WINDOWS\System32\nggpfaa.dll infected by "Trojan.Win32.StartPage.ix" Virus. Action Taken: No Action Taken.

=> File C:\WINDOWS\system32\Explorer.exe infected by "Trojan-Downloader.Win32.Small.aeb" Virus. Action Taken: No Action Taken.

=> File C:\WINDOWS\internet.exe infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken.

=> File C:\WINDOWS\System32\d2kndr.exe infected by "Trojan.Win32.Dialer.bh" Virus. Action Taken: No Action Taken.

=> File C:\WINDOWS\System32\datsobex.wwr infected by "I-Worm.Sober.g" Virus. Action Taken: No Action Taken.

=> File C:\WINDOWS\System32\vbsys2.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\WINDOWS\System32\xdatxzap.zxp infected by "I-Worm.Sober.g" Virus. Action Taken: No Action

=> File C:\DOKUME~1\RBSE~1\LOKALE~1\Temp\sp.html infected by "Trojan.JS.StartPage.u" Virus. Action Taken: No Action Taken.

=> File C:\DOKUME~1\RBSE~1\LOKALE~1\TEMPOR~1\Content.IE5\O567S12B\safxx[1].chm infected by "Trojan.Win32.Dialer.by" Virus. Action Taken: No Action Taken.

=> File C:\bla.exe infected by "Trojan-Downloader.Win32.Small.aaq" Virus. Action Taken: No Action Taken.

=> File C:\Dokumente und Einstellungen\Röbse\Lokale Einstellungen\Temp\sp.html infected by "Trojan.JS.StartPage.u" Virus. Action Taken: No Action Taken.

File C:\Dokumente und Einstellungen\Röbse\Lokale Einstellungen\Temporary Internet Files\Content.IE5\O567S12B\safxx[1].chm infected by "Trojan.Win32.Dialer.by" Virus. Action Taken: No Action Taken.

=> File C:\msinfo.exe infected by "TrojanDownloader.Win32.Agent.ci" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Microsoft AntiSpyware\Quarantine\4165E7AE-6DEA-4998-AC50-E9B6C8\3800AF61-E154-4D1C-8A1B-01F9C4 infected by "not-a-virus:AdWare.SaveNow.af" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Microsoft AntiSpyware\Quarantine\4165E7AE-6DEA-4998-AC50-E9B6C8\9C3D185C-47F5-4109-8409-AB23BD infected by "not-a-virus:AdWare.SaveNow.ah" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Microsoft AntiSpyware\Quarantine\4165E7AE-6DEA-4998-AC50-E9B6C8\C3E5B782-89E7-453C-8486-E650D1 infected by "not-a-virus:AdWare.SaveNow.m" Virus. Action Taken: No Action Taken.

=> File C:\Programme\pl.exe infected by "TrojanDownloader.Win32.Small.fo" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\1.tmp infected by "I-Worm.Sober.g" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\10.tmp infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: No Action Taken

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\10E9.tmp infected by "I-Worm.LoveLetter" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\11.tmp infected by "TrojanDownloader.Win32.Pitux.a" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\12.tmp infected by "TrojanDownloader.Win32.Small.lz" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\13.tmp infected by "TrojanDownloader.Win32.Small.lz" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\14.tmp infected by "TrojanDownloader.Win32.PurityScan.e" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\15.tmp infected by "Trojan.WinREG.StartPage" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\16.tmp infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\17.tmp infected by "TrojanDownloader.Win32.PurityScan.e" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\18.tmp infected by "TrojanDownloader.Win32.PurityScan.e" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\1CF.tmp infected by "TrojanClicker.Win32.Small.c" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\2.tmp infected by "Backdoor.SdBot.mu" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\3.tmp infected by "I-Worm.Sober.g" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\4.tmp infected by "TrojanDownloader.Win32.Pitux.a" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\5.tmp infected by "I-Worm.Sober.g" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\6.tmp infected by "I-Worm.Sober.g" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\7.tmp infected by "TrojanClicker.Win32.Small.c" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\8.tmp infected by "Backdoor.SdBot.mu" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\9.tmp infected by "Backdoor.Win32.Rbot.gen" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\A.tmp infected by "TrojanDownloader.Win32.Donn.r" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\B.tmp infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\C.tmp infected by "Trojan.VBS.StartPage.g" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\D.tmp infected by "Trojan.Java.ClassLoader.c" Virus. Action Taken: No Action Taken.

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\E.tmp infected by "TrojanDownloader.Win32.Small.kq" Virus. Action Taken: No Action Taken

=> File C:\Programme\Trend Micro\PC-cillin 2002\QUARANTINE\F.tmp infected by "TrojanDownloader.Win32.Holica.a" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP234\A0062063.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP235\A0062093.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP236\A0062132.exe infected by "TrojanDownloader.Win32.Agent.ec" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP236\A0062138.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP239\A0062339.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP240\A0062406.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP247\A0065014.dll infected by "TrojanClicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP248\A0065140.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

erster teil

germanguy 10.01.2005 18:14

zweiter teil

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP251\A0066216.exe infected by "TrojanDownloader.Win32.Agent.ec" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP251\A0066217.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP252\A0067365.exe infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067946.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067947.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067948.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067949.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067950.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067951.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067952.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067953.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067954.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067955.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067956.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067957.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067958.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067959.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067960.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067961.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067962.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067963.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067964.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067965.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067966.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067967.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067968.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067969.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067970.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067971.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067972.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067973.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067974.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067975.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067976.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067977.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067978.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067979.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067980.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067981.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067982.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067983.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067984.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067985.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067986.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067987.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067988.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067989.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067990.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken

germanguy 10.01.2005 18:15

dritter und letzter teil!

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067991.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067992.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067993.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067994.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067995.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067996.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0067997.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0068000.exe infected by "Trojan.Win32.Favadd.c" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0068001.exe infected by "Trojan-Clicker.Win32.Small.bt" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0068002.exe infected by "Trojan.Win32.Regger.f" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP262\A0068004.exe infected by "TrojanDownloader.Win32.Agent.bj" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP263\A0068046.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP263\A0068047.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP263\A0068050.exe infected by "Trojan.Win32.Favadd.c" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP263\A0068051.exe infected by "Trojan-Clicker.Win32.Small.bt" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP263\A0068052.exe infected by "Trojan.Win32.Regger.f" Virus. Action Taken: No Action Taken

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP263\A0068054.exe infected by "TrojanDownloader.Win32.Agent.bj" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP264\A0068117.exe infected by "TrojanProxy.Win32.Agent.bm" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP265\A0069302.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP278\A0070936.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP280\A0071054.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP299\A0072341.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP316\A0073758.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP324\A0076118.exe infected by "not-a-virus:AdWare.SaveNow.af" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP324\A0076119.exe infected by "not-a-virus:AdWare.SaveNow.m" Virus. Action Taken: No Action Taken.

> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP324\A0076120.exe infected by "not-a-virus:AdWare.SaveNow.ah" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP324\A0076124.exe infected by "Backdoor.Win32.Agent.ec" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP324\A0076125.EXE infected by "not-a-virus:AdWare.Toolbar.MyWay.b" Virus. Action Taken: No Action Taken.

=> File C:\System Volume Information\_restore{66372F38-11D0-4F9C-A119-F21FD8762A90}\RP324\A0076126.DLL infected by "not-a-virus:AdWare.ToolBar.MyWay.f" Virus. Action Taken: No Action Taken

=> File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\loader.exe infected by "TrojanDownloader.Win32.Small.xa" Virus. Action Taken: No Action Taken

=> File C:\WINDOWS\Downloaded Program Files\loader.exe infected by "TrojanDownloader.Win32.Small.xa" Virus. Action Taken: No Action Taken.

=> File C:\WINDOWS\internet.exe infected by "Trojan-Downloader.Win32.Small.or" Virus. Action Taken: No Action Taken.

=> File C:\WINDOWS\system32\d2kndr.exe infected by "Trojan.Win32.Dialer.bh" Virus. Action Taken: No Action Taken.

=> File C:\WINDOWS\system32\datsobex.wwr infected by "I-Worm.Sober.g" Virus. Action Taken: No Action Taken.

=> File C:\WINDOWS\system32\vbsys2.dll infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\WINDOWS\system32\vbsys2.dll_old infected by "Trojan-Clicker.Win32.Agent.ac" Virus. Action Taken: No Action Taken.

=> File C:\WINDOWS\system32\xdatxzap.zxp infected by "I-Worm.Sober.g" Virus. Action Taken: No Action Taken.


Alle Zeitangaben in WEZ +1. Es ist jetzt 22:59 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19