Zurück   Trojaner-Board > Malware entfernen > Plagegeister aller Art und deren Bekämpfung

Plagegeister aller Art und deren Bekämpfung: Virus

Windows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen.

Antwort
Alt 25.08.2005, 19:35   #1
MegaroGR
 
Virus - Standard

Virus



Hallo liebe Experten des Trojaner- Boards....
Also ich hab folgendes Problem bei mir festgestellt......kann mein PC IE Windows Pr...nicht normal über Start und Ausschalten herrunterfahren.....zudem kommt noch hinzu das ich geoffnete Fenster nicht mehr schließen kannn .....es tut sich also nichts ....also hab schon sämtliche Virenscanner durchgejagt.....spy boot....adaware....und und ...Dann habe ich den eScan im abgesicherten Modus durchlaufen lassen und hab einen bösartigen gefunden ....kann aber damit nichts anfangen...???
Kann man den entfernen?

Thu Aug 25 20:14:03 2005 => System found infected with ezula Spyware/Adware (internet.lnk)! Action taken: No Action Taken?????????????

Könntet ihr mir irgendwie helfen?,das wäre schön.Danke



Gruss MegaroGR

Alt 25.08.2005, 19:38   #2
chaosman
 
Virus - Standard

Virus



@MegaroGR
poste bitte auch folgendes:
Öffne C:\bases\mwav.log
Am Ende folgendes suchen und hier rein kopieren:
Zitat:
Total Files Scanned:
Total Virus(es) Found:
Total Disinfected Files:
Total Files Renamed:
Total Deleted Files:
Total Errors:
Time Elapsed:
Virus Database Date:
Virus Database Count:

poste auch bitte ein HJT logfile

chaosman
__________________

__________________

Alt 25.08.2005, 20:21   #3
MegaroGR
 
Virus - Standard

Virus



Hier die infizierten Dateien:



Thu Aug 25 21:25:58 2005 => Offending file found: C:\DOKUME~1\ioannis\Desktop\internet.lnk
Thu Aug 25 21:25:58 2005 => System found infected with ezula Spyware/Adware (internet.lnk)! Action taken: No Action Taken.

Thu Aug 25 21:39:50 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0B3E29E3.cla infected by "Trojan.Java.ClassLoader.b" Virus! Action Taken: No Action T
Thu Aug 25 21:39:50 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\05A15FAA.htm
Thu Aug 25 21:39:50 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0B3E29E3.cla
Thu Aug 25 21:39:50 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0B3E29E3.cla infected by "Trojan.Java.ClassLoader.b" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:50 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0DAC4B97.hta
Thu Aug 25 21:39:50 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0DAC4B97.hta infected by "Trojan.HTA.Zones.a" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:50 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0F8B7BE2.htm
Thu Aug 25 21:39:50 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\0F8B7BE2.htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:50 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\1D4871A4.htm
Thu Aug 25 21:39:50 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\1D4871A4.htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:50 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\261734B9.exe
Thu Aug 25 21:39:51 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\261734B9.exe infected by "Trojan.Win32.Agent.e" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\26AE18EE.cla
Thu Aug 25 21:39:51 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\26AE18EE.cla infected by "Trojan.Java.ClassLoader.b" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\26B142EA.cla
Thu Aug 25 21:39:51 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\26B142EA.cla infected by "Trojan.Java.ClassLoader.Dummy.a" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\26B142EA.zip
Thu Aug 25 21:39:51 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\26B142EA.zip infected by "Trojan.Java.ClassLoader.b" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\34A90E38.htm
Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\37DB1D78.cla
Thu Aug 25 21:39:51 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\37DB1D78.cla infected by "Trojan.Java.ClassLoader.b" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\37DE4774.cla
Thu Aug 25 21:39:51 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\37DE4774.cla infected by "Trojan.Java.ClassLoader.Dummy.a" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\37DE4774.zip
Thu Aug 25 21:39:51 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\37DE4774.zip infected by "Trojan.Java.ClassLoader.b" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\381D7E20.htm
Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\3B826AF2.htm
Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\492735E1.zip
Thu Aug 25 21:39:51 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\492735E1.zip infected by "Trojan.Java.ClassLoader.c" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\492A5FDE.zip
Thu Aug 25 21:39:51 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\492A5FDE.zip infected by "Trojan.Java.ClassLoader.c" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\4BA54C8A.zip
Thu Aug 25 21:39:51 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\4BA54C8A.zip infected by "Trojan.Java.ClassLoader.c" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\4C2D3295.cla
Thu Aug 25 21:39:51 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\4C2D3295.cla infected by "Trojan.Java.ClassLoader.b" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\64FF75F0.cla
Thu Aug 25 21:39:51 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\64FF75F0.cla infected by "Trojan.Java.ClassLoader.u" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:51 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\6CAD6684.cla
Thu Aug 25 21:39:52 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\6CAD6684.cla infected by "Trojan.Java.ClassLoader.u" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:52 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\77DE15F0.gif
Thu Aug 25 21:39:52 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\77DE15F0.gif infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:52 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\77DE15F0.htm
Thu Aug 25 21:39:52 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\77DE15F0.htm infected by "Trojan-Downloader.JS.Weis.b" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:52 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\780C61BE.gif
Thu Aug 25 21:39:52 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\780C61BE.gif infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:52 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\780C61BE.htm
Thu Aug 25 21:39:52 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\780C61BE.htm infected by "Trojan-Downloader.JS.Weis.b" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:52 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\782631A1.gif
Thu Aug 25 21:39:52 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\782631A1.gif infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:52 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\782631A1.htm
Thu Aug 25 21:39:52 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\782631A1.htm infected by "Trojan-Downloader.JS.Weis.b" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:52 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\7847557D.gif
Thu Aug 25 21:39:52 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\7847557D.gif infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:52 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\7847557D.htm
Thu Aug 25 21:39:52 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\7847557D.htm infected by "Trojan-Downloader.JS.Weis.b" Virus! Action Taken: No Action Taken.

Thu Aug 25 21:39:52 2005 => Scanning File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\796D455A.htm
Thu Aug 25 21:39:52 2005 => File C:\Programme\Norton Internet Security\Norton AntiVirus\Quarantine\796D455A.htm infected by "Exploit.HTML.Mht" Virus! Action Taken: No Action Taken.

Also das sind erstmal die Infizierten dateien.....und die Total Errors waren 42,
Logfiles Information 27 .....Totale Objecte 43987.....und die anderen hatten nichts an infection....ich hoffe du kannst damit was anfangen oder mir eine Hilfestellung geben


Vielen Dank

Gruss MegaroGR
__________________

Geändert von MegaroGR (25.08.2005 um 21:07 Uhr)

Alt 25.08.2005, 20:39   #4
chaosman
 
Virus - Standard

Virus



@MegaroGR

wechsle in den abgesicherten modus und fixe mit HJT
O2 - BHO: (no name) - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - (no file)
O4 - HKLM\..\Run: [stnospy] C:\Programme\SinEspias\no-spy.exe /autorun

lösche danach manuell
C:\Programme\SinEspias\no-spy.exe
neu booten, neues HJT logfile posten

chaosman
__________________
Bonus vir semper tiro

Antwort

Themen zu Virus
?????, abgesicherten, abgesicherten modus, entfernen, escan, experten, fenster, folge, folgendes, found, helfen, infected, interne, modus, nicht mehr, nichts, problem, scan, scanner, schließen, start, system, sämtliche, virenscan, virenscanner, virus, windows





Zum Thema Virus - Hallo liebe Experten des Trojaner- Boards.... Also ich hab folgendes Problem bei mir festgestellt......kann mein PC IE Windows Pr...nicht normal über Start und Ausschalten herrunterfahren.....zudem kommt noch hinzu das ich - Virus...
Archiv
Du betrachtest: Virus auf Trojaner-Board

Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.