|  | 
| 
 | |||||||
| Log-Analyse und Auswertung: Warezov und andere GesellenWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. | 
|  | 
|  | 
|  21.01.2007, 16:56 | #1 | 
|  |   Warezov und andere Gesellen Hey Sunny, hab gerade noch den online-check von kaspersky.com laufen...der hat mir auch schon einiges wieder angezeigt,... kannst du mit den ergebnissen von kaspersky auch arbeiten? Dann poste ich später das ergebnis. andernfalls arbeite ich deine liste ab und poste das dann. Danke schon ma!   | 
|  21.01.2007, 16:58 | #2 | |
| Administrator  > Competence Manager |   Warezov und andere GesellenZitat: 
   
				__________________ | 
|  21.01.2007, 17:07 | #3 | 
|  |   Warezov und andere Gesellen hier das kaspersky-logfile:__________________ ------------------------------------------------------------------------------- KASPERSKY ONLINE SCANNER REPORT Sunday, January 21, 2007 5:04:58 PM Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky Online Scanner version: 5.0.83.0 Kaspersky Anti-Virus database last update: 21/01/2007 Kaspersky Anti-Virus database records: 246005 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: C:\ D:\ F:\ Scan Statistics: Total number of scanned objects: 92503 Number of viruses found: 9 Number of infected objects: 98 / 0 Number of suspicious objects: 0 Duration of the scan process: 01:17:33 Infected Object Name / Virus Name / Last Action C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\McAfee\SpamKiller\Logs\Filtering.log Object is locked skipped C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\McAfee.com\Agent\Logs\TaskScheduler\McTskshd000.log Object is locked skipped C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Downloader\qmgr0.dat Object is locked skipped C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Microsoft\Network\Downloader\qmgr1.dat Object is locked skipped C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\QSLLPSVCShare Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Anwendungsdaten\Mozilla\Firefox\Profiles\q4nuijvz.default\cert8.db Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Anwendungsdaten\Mozilla\Firefox\Profiles\q4nuijvz.default\googlesafebrowsing.db Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Anwendungsdaten\Mozilla\Firefox\Profiles\q4nuijvz.default\history.dat Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Anwendungsdaten\Mozilla\Firefox\Profiles\q4nuijvz.default\key3.db Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Anwendungsdaten\Mozilla\Firefox\Profiles\q4nuijvz.default\parent.lock Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Cookies\index.dat Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\q4nuijvz.default\Cache\_CACHE_001_ Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\q4nuijvz.default\Cache\_CACHE_002_ Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\q4nuijvz.default\Cache\_CACHE_003_ Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Lokale Einstellungen\Anwendungsdaten\Mozilla\Firefox\Profiles\q4nuijvz.default\Cache\_CACHE_MAP_ Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Lokale Einstellungen\Temporary Internet Files\AntiPhishing\B3BB5BBA-E7D5-40AB-A041-A5B1C0B26C8F.dat Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped C:\Dokumente und Einstellungen\Amrei\Lokale Einstellungen\Verlauf\History.IE5\MSHist012007012120070122\index.dat Object is locked skipped C:\Dokumente und Einstellungen\Amrei\NTUSER.DAT Object is locked skipped C:\Dokumente und Einstellungen\Amrei\ntuser.dat.LOG Object is locked skipped C:\Dokumente und Einstellungen\LocalService\Cookies\index.dat Object is locked skipped C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat Object is locked skipped C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat Object is locked skipped C:\Dokumente und Einstellungen\LocalService\NTUSER.DAT Object is locked skipped C:\Dokumente und Einstellungen\LocalService\ntuser.dat.LOG Object is locked skipped C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat Object is locked skipped C:\Dokumente und Einstellungen\NetworkService\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG Object is locked skipped C:\Dokumente und Einstellungen\NetworkService\NTUSER.DAT Object is locked skipped C:\Dokumente und Einstellungen\NetworkService\ntuser.dat.LOG Object is locked skipped C:\Programme\FRITZ!DSL\access\access.lock Object is locked skipped C:\System Volume Information\MountPointManagerRemoteDatabase Object is locked skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068430.pif Infected: Email-Worm.Win32.Warezov.et skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068431.exe Infected: Email-Worm.Win32.Warezov.et skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068432.dll Infected: Email-Worm.Win32.Warezov.hw skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068434.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068446.dll Infected: Email-Worm.Win32.Warezov.hw skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068449.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068460.dll Infected: Email-Worm.Win32.Warezov.hw skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068461.scr Infected: Email-Worm.Win32.Warezov.et skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068462.exe Infected: Email-Worm.Win32.Warezov.et skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068464.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068478.dll Infected: Email-Worm.Win32.Warezov.hw skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068479.exe Infected: Email-Worm.Win32.Warezov.hw skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068517.exe Infected: Email-Worm.Win32.Warezov.jh skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068519.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068532.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068546.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068575.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068671.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0068684.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0069684.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0069728.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0069792.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0069816.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP171\A0069829.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP181\A0069855.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP181\A0069882.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP181\A0069909.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP181\A0069985.exe Infected: Email-Worm.Win32.Warezov.fh skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP181\A0069989.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP181\A0070002.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP181\A0070043.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP181\A0070096.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP181\A0070117.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP182\A0070137.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP182\A0070153.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP182\A0070166.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP183\A0070190.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP183\A0070242.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP183\A0070255.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP184\A0070296.exe Infected: Email-Worm.Win32.Warezov.hx skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP184\A0070298.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP184\A0070330.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP184\A0070394.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP184\A0070448.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP184\A0070518.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP184\A0070532.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP184\A0070583.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP184\A0070641.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP184\A0070696.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP184\A0070710.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP184\A0070753.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP185\A0070792.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP185\A0070818.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP185\A0070831.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP185\A0070849.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP185\A0072915.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP185\A0072953.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP185\A0072972.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP186\A0074000.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP186\A0075000.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP187\A0077021.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP187\A0077410.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP187\A0077417.dll Infected: Email-Worm.Win32.Warezov.hx skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP187\A0077421.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP187\A0077425.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP188\A0077645.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP188\A0077947.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP189\A0078354.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP189\A0079354.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP189\A0079494.exe Infected: Email-Worm.Win32.Warezov.cu skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0079528.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0079928.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0080928.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0082930.dll Infected: Email-Worm.Win32.Warezov.dq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0083928.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0083932.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0085933.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0086933.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0086936.dll Infected: Email-Worm.Win32.Warezov.et skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0086937.dll Infected: Email-Worm.Win32.Warezov.et skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0086938.dll Infected: Email-Worm.Win32.Warezov.hx skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0086939.dll Infected: Email-Worm.Win32.Warezov.hx skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0086940.dll Infected: Email-Worm.Win32.Warezov.et skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0086943.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0087943.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088008.exe Infected: Email-Worm.Win32.Warezov.hx skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088010.exe Infected: Email-Worm.Win32.Warezov.cu skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088011.exe Infected: Email-Worm.Win32.Warezov.ij skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088012.dll Infected: Email-Worm.Win32.Warezov.hx skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088013.dll Infected: Email-Worm.Win32.Warezov.dq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088014.exe Infected: Email-Worm.Win32.Warezov.et skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088015.dll Infected: Email-Worm.Win32.Warezov.hx skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088016.dll Infected: Email-Worm.Win32.Warezov.hx skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088017.dll Infected: Email-Worm.Win32.Warezov.hx skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088018.dll Infected: Email-Worm.Win32.Warezov.et skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088019.dll Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088020.exe Infected: Email-Worm.Win32.Warezov.eq skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP190\A0088021.dll Infected: Email-Worm.Win32.Warezov.et skipped C:\System Volume Information\_restore{08A5F15B-D5F0-4D17-893D-8B358608DCF6}\RP191\change.log Object is locked skipped C:\WINDOWS\Debug\PASSWD.LOG Object is locked skipped C:\WINDOWS\SchedLgU.Txt Object is locked skipped C:\WINDOWS\SoftwareDistribution\ReportingEvents.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\edb.log Object is locked skipped C:\WINDOWS\system32\CatRoot2\tmp.edb Object is locked skipped C:\WINDOWS\system32\config\AppEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\DEFAULT Object is locked skipped C:\WINDOWS\system32\config\default.LOG Object is locked skipped C:\WINDOWS\system32\config\Internet.evt Object is locked skipped C:\WINDOWS\system32\config\SAM Object is locked skipped C:\WINDOWS\system32\config\SAM.LOG Object is locked skipped C:\WINDOWS\system32\config\SecEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SECURITY Object is locked skipped C:\WINDOWS\system32\config\SECURITY.LOG Object is locked skipped C:\WINDOWS\system32\config\SOFTWARE Object is locked skipped C:\WINDOWS\system32\config\software.LOG Object is locked skipped C:\WINDOWS\system32\config\SysEvent.Evt Object is locked skipped C:\WINDOWS\system32\config\SYSTEM Object is locked skipped C:\WINDOWS\system32\config\system.LOG Object is locked skipped C:\WINDOWS\system32\drivers\dtscsi.sys Object is locked skipped C:\WINDOWS\system32\drivers\sptd.sys Object is locked skipped C:\WINDOWS\system32\drivers\sptd6653.sys Object is locked skipped C:\WINDOWS\system32\h323log.txt Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.BTR Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\INDEX.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING.VER Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING1.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\MAPPING2.MAP Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.DATA Object is locked skipped C:\WINDOWS\system32\wbem\Repository\FS\OBJECTS.MAP Object is locked skipped C:\WINDOWS\WindowsUpdate.log Object is locked skipped Scan process completed.   | 
|  21.01.2007, 17:23 | #4 | 
| Administrator  > Competence Manager |   Warezov und andere Gesellen Das sieht schlimmer aus als es ist.   Deaktiviere einfach die Systemwiederherstellung, starte danach das System neu, und alles sollte verschwunden sein was Kaspersky gefunden hat.  Systemwiederherstellung kann nun wieder aktiviert werden. Nun den Rest von mir posten.. 
				__________________ Anfragen per Email, Profil- oder privater Nachricht werden ignoriert! Hilfe gibts NUR im Forum! Stulti est se ipsum sapientem putare. | 
|  21.01.2007, 17:28 | #5 | 
|  |   Warezov und andere Gesellen na das klingt doch schon ganz zuversichtlich. Ich werd nu die systemwiederherstellung deaktivieren, neustarten und dann deine liste abarbeiten. wird wohl n bisschen dauern, bis ich die ergebnisse posten kann. Bis später dann.     | 
|  21.01.2007, 19:54 | #6 | 
|  |   Warezov und andere Gesellen puhh..endlich kann ich die escan log posten... ich hab ma nur die Vireninfos gepostet,...der rest der logfile ist extrem lang und enthält nur die pfade in denen gesucht wurde,...brauchst die komplette file? die anderen beiden prüfungen stehen noch aus. Entry "HKCR\DirectAnimation.PathControl" refers to invalid object "{D7A7D7C3-D47F-11D0-89D3-00A0C90833E6}". Action Taken: Entries Removed. Entry "HKCR\DirectAnimation.Sequence" refers to invalid object "{4F241DB1-EE9F-11D0-9824-006097C99E51}". Action Taken: Entries Removed. Entry "HKCR\DirectAnimation.SequencerControl" refers to invalid object "{B0A6BAE2-AAF0-11D0-A152-00A0C908DB96}". Action Taken: Entries Removed. Entry "HKCR\DirectAnimation.SpriteControl" refers to invalid object "{FD179533-D86E-11D0-89D6-00A0C90833E6}". Action Taken: Entries Removed. Entry "HKCR\DirectAnimation.StructuredGraphicsControl" refers to invalid object "{369303C2-D7AC-11D0-89D5-00A0C90833E6}". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Jasc Software Inc\Paint Shop Pro Studio\". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\Installer\Folders" refers to invalid object "C:\Dokumente und Einstellungen\Besitzer\Anwendungsdaten\Jasc Software Inc\". Action Taken: Entries Removed. Entry "HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts" refers to invalid object ".mds". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "InstallShield_{501BADCD-F8F7-44CB-AC3F-6ED25C1A28B5}". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "InstallShield_{929408E6-D265-4174-805F-81D1D914E2A4}". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB873339". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB885250". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB885835". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB885855". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB887472". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB888113". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB888310". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB890175". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB891781". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB892627". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB893056". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB896422". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB896423". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB896727". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB899588". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB899591". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "KB901214". Action Taken: Entries Removed. Entry "HKLM\Software\Microsoft\Windows\CurrentVersion\App Management\ARPCache" refers to invalid object "QuickTime". Action Taken: Entries Removed. | 
|  21.01.2007, 19:58 | #7 | 
|  |   Warezov und andere Gesellen das progi blacklight hat keine probleme gefunden, ne logfile zum kopieren hab ich auch nicht entdeckt. aber mit smitfraudfix hab ich wat gefunden... SmitFraudFix v2.133 Scan done at 19:56:28,34, 21.01.2007 Run from C:\Dokumente und Einstellungen\Amrei\Desktop\SmitfraudFix OS: Microsoft Windows XP [Version 5.1.2600] - Windows_NT The filesystem type is NTFS Fix run in normal mode »»»»»»»»»»»»»»»»»»»»»»»» C:\ »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\Web »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32 »»»»»»»»»»»»»»»»»»»»»»»» C:\WINDOWS\system32\LogFiles »»»»»»»»»»»»»»»»»»»»»»»» C:\Dokumente und Einstellungen\Amrei »»»»»»»»»»»»»»»»»»»»»»»» C:\Dokumente und Einstellungen\Amrei\Application Data »»»»»»»»»»»»»»»»»»»»»»»» Start Menu »»»»»»»»»»»»»»»»»»»»»»»» C:\DOKUME~1\Amrei\FAVORI~1 »»»»»»»»»»»»»»»»»»»»»»»» Desktop »»»»»»»»»»»»»»»»»»»»»»»» C:\Programme »»»»»»»»»»»»»»»»»»»»»»»» Corrupted keys »»»»»»»»»»»»»»»»»»»»»»»» Desktop Components [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Desktop\Components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="Die derzeitige Homepage" »»»»»»»»»»»»»»»»»»»»»»»» Sharedtaskscheduler !!!Attention, following keys are not inevitably infected!!! SrchSTS.exe by S!Ri Search SharedTaskScheduler's .dll »»»»»»»»»»»»»»»»»»»»»»»» AppInit_DLLs !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows] "AppInit_DLLs"=" vb5dmspo.dll e1.dll confbrw.dll brwstat.dll diagisr.dll" »»»»»»»»»»»»»»»»»»»»»»»» Winlogon.System !!!Attention, following keys are not inevitably infected!!! [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon] "System"="" »»»»»»»»»»»»»»»»»»»»»»»» pe386-msguard-lzx32 »»»»»»»»»»»»»»»»»»»»»»»» Scanning wininet.dll infection »»»»»»»»»»»»»»»»»»»»»»»» End   | 
|  | 
| Themen zu Warezov und andere Gesellen | 
| adobe, antivir, appinit_dlls, avira, bho, c:\windows\temp, computer, confused, drivers, dsl, explorer, firefox, hijack, hijackthis, internet, internet explorer, logfile, mehrere, monitor, mozilla, mozilla firefox, object, opera, rundll, server, software, system, temp, träge, tuneup utilities, urlsearchhook, windows, windows xp, windows\temp |