Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Windows Security Alert (https://www.trojaner-board.de/80959-windows-security-alert.html)

syxx 29.12.2009 12:21

Windows Security Alert
 
Moin moin,

habe das selbe problem seid heut morgen, ich weiss nicht mal wann ich mir den mist eingefangen habe...
naja schnell angemeldet hier und und und...

hab mir das programm eben auch schnell gezogen und bin deiner anleitung gefolgt.

mir spuckt er das aus:

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "H8SRTd.sys" found!
ImagePath: \systemroot\system32\drivers\H8SRTfwospyxufj.sys
Driver disabled successfully.

Rootkit scan completed.


Error: file "C:\WINDOWS\system32\sdra64.exe" not found!
Deletion of file "C:\WINDOWS\system32\sdra64.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open file "C:\DOKUME~1\Resi\LOKALE~1\Temp\settdebugx.exe"
Deletion of file "C:\DOKUME~1\Resi\LOKALE~1\Temp\settdebugx.exe" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist

File "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\sysReserve.ini" deleted successfully.

Error: folder "C:\WINDOWS\system32\lowsec" not found!
Deletion of folder "C:\WINDOWS\system32\lowsec" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.

syxx 29.12.2009 12:33

oh ok mach ich wusste ich nich

syxx 29.12.2009 12:37

Windows Security Alert
 
Habe mir wohl irgendwie "Windows Security Alert" und "Malware Defense" (vllt gehörts auch zu dem anderen dazu) eingefangen,

habe Avenger mit dem Script:

files to delete:
C:\WINDOWS\system32\sdra64.exe
C:\DOKUME~1\Resi\LOKALE~1\Temp\settdebugx.exe
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\sysReserve.ini

folders to delete:
C:\WINDOWS\system32\lowsec


laufen lassen und folgenden text bekommen:


Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "H8SRTd.sys" found!
ImagePath: \systemroot\system32\drivers\H8SRTfwospyxufj.sys
Driver disabled successfully.

Rootkit scan completed.


Error: file "C:\WINDOWS\system32\sdra64.exe" not found!
Deletion of file "C:\WINDOWS\system32\sdra64.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open file "C:\DOKUME~1\Resi\LOKALE~1\Temp\settdebugx.exe"
Deletion of file "C:\DOKUME~1\Resi\LOKALE~1\Temp\settdebugx.exe" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist

File "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\sysReserve.ini" deleted successfully.

Error: folder "C:\WINDOWS\system32\lowsec" not found!
Deletion of folder "C:\WINDOWS\system32\lowsec" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.


wie gehts nun weiter?


Alle Zeitangaben in WEZ +1. Es ist jetzt 18:54 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131