Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Laie braucht Hilfe! (https://www.trojaner-board.de/16687-laie-braucht-hilfe.html)

Rotterdamer 15.04.2005 16:25

Laie braucht Hilfe!
 
Hallo,

hatte vor kurzem ziemliche Probleme mit meinem Rechner (Dialer, Trojaner, Spyer und sonstiges) Fragt mich bloß nicht woher, keine Ahnung. Habe mich mit Hijack this, Adware, und Spyboot so durch gewurschtelt. Bin mir aber nicht sicher ob alles soweit runter ist. Habe anscheind eine Reg. zuviel gefixt, mein Rechner fragt jetzt beim rauffahren nach C:/windows/system32/msoffice.exe. Wie bekomm ich dass denn wieder. Anbei mal meine aktuelle Logfile, kann mir jemand sagen ob etwas "misteriös" oder vielleicht sogar etwas fehlt. Und kann ich mir wiederum sicher sein, dass mein Computer "sicher" ist. Traue mich nämlich z. Zt. noch nicht wieder an Internet-Banking ran.

Logfile of HijackThis v1.99.1
Scan saved at 17:27:47, on 15.04.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\S24EvMon.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
C:\Programme\Kerio\ServerFirewall\srvfw.exe
C:\Programme\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\System32\RegSrvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZCfgSvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\1XConfig.exe
C:\WINDOWS\ATK0100\Hcontrol.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\Programme\SAMSUNG\Keydefin\KeyDefin.exe
C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programme\Synaptics\SynTP\SynTPLpr.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\AGRSMMSG.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
C:\PROGRA~1\COMMON~1\uwwk\uwwkm.exe
C:\Programme\Messenger\msmsgs.exe
C:\Programme\AT-AR215\AT-AR215 USB ADSL WAN Adapter\DSLMON.exe
C:\WINDOWS\ATK0100\ATKOSD.exe
C:\PROGRA~1\COMMON~1\uwwk\uwwka.exe
C:\WINDOWS\system32\ntvdm.exe
C:\T-Online\Browser\Browser.exe
C:\WINDOWS\system32\taskmgr.exe
C:\T-ONLINE\BSW4\ToDuCAlC.EXE
C:\DOKUME~1\DANIEL~1\LOKALE~1\Temp\Temporäres Verzeichnis 4 für hijackthis.zip\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.t-online.de/
R3 - Default URLSearchHook is missing
F3 - REG:win.ini: run=C:\WINDOWS\system32\msoffice.exe
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [Hcontrol] C:\WINDOWS\ATK0100\Hcontrol.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [ccRegVfy] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccRegVfy.exe"
O4 - HKLM\..\Run: [SAMSUNG Keydefin] C:\Programme\SAMSUNG\Keydefin\KeyDefin.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM\..\Run: [2kadiras] 2kadiras.exe
O4 - HKLM\..\Run: [5Qo7prek] C:\WINDOWS\xuetbqqv.exe
O4 - HKLM\..\Run: [Stop-Sign_Install_Recovery] C:\DOKUME~1\DANIEL~1\LOKALE~1\Temp\ss_stopsign.exe -k
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [uwwk] C:\PROGRA~1\COMMON~1\uwwk\uwwkm.exe
O4 - HKCU\..\Run: [MSMSGS] "C:\Programme\Messenger\msmsgs.exe" /background
O4 - Global Startup: DSLMON.lnk = C:\Programme\AT-AR215\AT-AR215 USB ADSL WAN Adapter\DSLMON.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O8 - Extra context menu item: Easy-WebPrint - Drucken - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint - Vorschau - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - res://C:\Programme\Canon\Easy-WebPrint\Resource.dll/RC_AddToList.html
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINDOWS\system32\msjava.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O12 - Plugin for .spop: C:\Programme\Internet Explorer\Plugins\NPDocBox.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{07EB3E5C-D0F7-4C73-B3B7-77DE10F5BD4B}: NameServer = 217.237.151.225 217.237.150.225
O17 - HKLM\System\CS1\Services\Tcpip\..\{07EB3E5C-D0F7-4C73-B3B7-77DE10F5BD4B}: NameServer = 217.237.151.225 217.237.150.225
O18 - Protocol: haufereader - {39198710-62F7-42CD-9458-069843FA5D32} - C:\Programme\Haufe\HaufeReader\HRInstmon.dll
O18 - Filter: text/html - {950238FB-C706-4791-8674-4D429F85897E} - (no file)
O20 - Winlogon Notify: Sebring - C:\WINDOWS\System32\LgNotify.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe
O23 - Service: Symantec Password Validation Service (ccPwdSvc) - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe
O23 - Service: Kerio ServerFirewall (KerioServerFirewall) - Kerio Technologies - C:\Programme\Kerio\ServerFirewall\srvfw.exe
O23 - Service: Norton AntiVirus Auto-Protect-Dienst (navapsvc) - Symantec Corporation - C:\Programme\Norton AntiVirus\navapsvc.exe
O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe
O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe
O23 - Service: ScriptBlocking Service (SBService) - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe

Yopie 15.04.2005 17:22

Wie lautet die genaue Fehlermeldung bzgl. msoffice.exe?

Mindestens folgendes
Zitat:

O4 - HKLM\..\Run: [5Qo7prek] C:\WINDOWS\xuetbqqv.exe
solltest Du noch fixen. Deutet imho auf einen Backdoor hin, der mal aktiv war. Wenn dem so ist, solltest Du formatieren und neu aufsetzen.

"Dialer, Trojaner, Spyer und sonstiges" installiert sich nicht von alleine, sondern entweder durch Anwenderhand oder unsichere Programme wie z.B. einen (veralteten) Internet Explorer. Der T-Online-Browser ist ein IE. Ein Browserwechsel ist also anzuraten.

Gruß :daumenhoc
Yopie

Rotterdamer 15.04.2005 22:08

Ersteinmal vielen Dank für die Hilfe. :huepp:

So! Jetzt oute ich mich wohl total als Laie, aber nun ja. Wie genau ist das gemeint mit formatieren und neu aufsetzen? Bedeutet das umgangsprachlich soviel wie das system komplett löschen und neu aufspielen? Was passiert den dann mit meine Programmen und Daten? Ich habe auch schon eine Systemwiederherstellung versucht, aber irgendwie funkioniert das nicht, obwohl im System etwas von Prüfpunkten steht, einmal von Windows und von Spyboot.

Die Fehlermeldungen (2 x beim Systemstart) reiche ich gleich nach muss noch mal hochfahren.

Bezüglich dem wie ? (Dialer, Trojaner, Spyer und sonstiges) Wird wohl letztendlich doch irgendwie meine Schuld gewesen sein!!! :mad:

Habe auch Mozilla, funktioniert auch! Das Problem ist alle anderen Browser auch!!!

Das letztendliche Resultat lautet also, wenn ich es richtig deute, ich kann mir nicht 100 % sicher sein, dass nicht doch irgendwo in meinem System ein bösartiges Programm "schlummert" und das dieses nur durch das formatieren des Programms zu beheben ist. Toll und wie mach ich das genau. Haben keine Windows CD. Dass war nämlich auf meinem Laptop schon vorinstalliert. :blabla:

Schon im voraus VIELEN DANK

Rotterdamer 15.04.2005 22:34

Hier die 2 Fehlermeldungen

1. c:/windows/system32/msoffice.exe konnte nicht gefunden werden, stellen Sie sicher dass Sie den Namen korrekt eingegeben haben und wiederholen Sie den Vorgang. Klicken Sie auf Start und anschließend auf suchen, um die Datei zu suchen.

2. Die in der Regestrierung angengebene Regestrierung c:/windows/system32/msoffice.exe konnte nicht geladen oder gestartet werden. Stellen Sie sicher, dass die Datei vorhanden ist oder entfernen Sie den Eintrag mit Bezug auf diese Datei aus der Regestrierung.

Cidre 16.04.2005 06:45

Hallo Rotterdamer,

führe zunächst folgendes aus, um mehr Licht ins Dunkel zu bringen:
Lade und scanne mit eScan AntiVirus im abgesicherten Modus wie beschrieben.
Poste anschliessend die Virus Log Information von eScan AntiVirus:
Öffne die mwav.log im Ordner C:\bases_X -> Bearbeiten -> Suchen -> infected oder tagged eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen.
Zitat:

Wie genau ist das gemeint mit formatieren und neu aufsetzen? Bedeutet das umgangsprachlich soviel wie das system komplett löschen und neu aufspielen?
JA, das ist richtig. Eine Anleitung findest du in meiner Signatur.
Zitat:

Was passiert den dann mit meine Programmen und Daten?
Die Programme und deine Daten werden 'fast' unwiderruflich gelöscht, sofern sie auf der Systempartition liegen.
Zitat:

Haben keine Windows CD. Dass war nämlich auf meinem Laptop schon vorinstalliert.
Ausnahme wie in deinem Fall: Du verwendest eine Recovery CD, dann werden alle Partitionen in den Urzustand, wie beim Kauf, zurück versetzt. Du musst also alle deine Daten/Dateien auf CD/DVD sichern.

Zitat:

c:/windows/system32/msoffice.exe konnte nicht gefunden werden
Fixe diesen Eintrag (Haken setzen und auf Fix Checked klicken) und die Fehlermeldung wird zukünftig nicht mehr erscheinen:
F3 - REG:win.ini: run=C:\WINDOWS\system32\msoffice.exe

Rotterdamer 18.04.2005 18:09

Hallo.

habe gerade eine Schreck bekommen ESCAN hat 199 böse Einträge. Hier ein kleiner Ausschnitt:

4AA4-840C-0C563876F0AB}\RP135\A0013796.exe infected by "Trojan-Downloader.Win32.Dyfuca.du" Virus. Action Taken: No Action Taken.

Sat Apr 16 19:30:25 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013797.ini
Sat Apr 16 19:30:25 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013798.lnk
Sat Apr 16 19:30:25 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013799.lnk
Sat Apr 16 19:30:25 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013800.new
Sat Apr 16 19:30:26 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013801.exe
Sat Apr 16 19:30:26 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013801.exe infected by "Trojan-Downloader.Win32.IstBar.ij" Virus. Action Taken: No Action Taken.

Sat Apr 16 19:30:26 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013802.exe
Sat Apr 16 19:30:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013802.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken.

Sat Apr 16 19:30:27 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013803.dll
Sat Apr 16 19:30:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013803.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken.

Sat Apr 16 19:30:27 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013804.exe
Sat Apr 16 19:30:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013804.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken

Sat Apr 16 18:57:11 2005 => File C:\WINDOWS\system32\drivers\delprot.sys infected by "Trojan.Win32.Delprot.a" Virus. Action Taken: No Action Taken.

Sat Apr 16 19:29:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013336.exe infected by "Trojan-Downloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.

Sat Apr 16 19:29:27 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013337.exe
Sat Apr 16 19:29:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013337.exe infected by "Trojan-Downloader.Win32.Dyfuca.du" Virus. Action Taken: No Action Taken.

Sat Apr 16 19:29:27 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013338.ini
Sat Apr 16 19:29:27 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013339.lnk
Sat Apr 16 19:29:27 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013340.lnk
Sat Apr 16 19:29:27 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013341.new
Sat Apr 16 19:29:28 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013342.exe
Sat Apr 16 19:29:28 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013342.exe infected by "Trojan-Downloader.Win32.IstBar.ij" Virus. Action Taken: No Action Taken.

Sat Apr 16 19:29:28 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013343.exe
Sat Apr 16 19:29:28 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013343.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken.

Sat Apr 16 19:29:28 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013344.dll
Sat Apr 16 19:29:29 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013344.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken.

Sat Apr 16 19:29:29 2005 => Scanning File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013345.exe
Sat Apr 16 19:29:29 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013345.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.


Die Einträge sehen in etwa alle so aus. Sag Bitte bescheid wenn du alle einträge benötigst, könnte dann allerdings etwas dauern.

Wäre unheimlich nett wenn Du mir ganz genau und detailliert schildern könntest was ich jetzt tun soll.

Danke schon im vorraus.

cronos 18.04.2005 18:12

Alle Eintrge wären schon hilfreich.Dazu:

Teile uns dann das Ergebnis des eScan mit: welche Viren wurden auf Deinem Rechner gefunden: "öffne die mwav.log -> Bearbeiten -> Suchen -> infected eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen." (Zitat Cidre)

Haui45 18.04.2005 18:19

Zitat:

Zitat von cronos
Teile uns dann das Ergebnis des eScan mit: welche Viren wurden auf Deinem Rechner gefunden: "öffne die mwav.log -> Bearbeiten -> Suchen -> infected eingeben -> Weitersuchen -> Treffer markieren/kopieren und ins Forum übertragen." (Zitat Cidre)

Alternativ kannst du auch die angehängte Datei runterladen, in Find.bat umbenennen, dann ausführen und den Inhalt der c:\find.txt posten.
Ich hab's noch nicht ausführlich getestet, aber es scheint zu funktionieren (zumindest bei mir) ;)

Es funktioniert nur, wenn die mwav.log tatsächlich im Verzeichnis c:\bases_x liegt!

MfG Haui

Cidre 18.04.2005 18:49

Zitat:

Zitat von Haui45
Es funktioniert nur, wenn die mwav.log tatsächlich im Verzeichnis c:\bases_x liegt!

Funktioniert und für sehr gut empfunden. :daumenhoc
btw:
Wenn nichts funktioniert, dann sollte der Pfad c:\bases_x in der find.txt manuell abgeändert und dann erst als find.bat abgespeichert werden.

Haui45 18.04.2005 18:52

Zitat:

Zitat von Cidre
Funktioniert und für sehr gut empfunden. :daumenhoc

Über positives Feedback freue ich mich immer :aplaus:

Zitat:

Zitat von Cidre
btw:
Wenn nichts funktioniert, dann sollte der Pfad c:\bases_x in der find.txt manuell abgeändert und dann erst als find.bat abgespeichert werden.

Ja, aber da die meisten wahrscheinlich die neue Version verwenden werden, hab ich's bei c:\bases_x belassen.

btw: ist eigentlich aus Faulheit entstanden ;)


P.S.: Die alte mwav.log sollte aber vor jedem Scan gelöscht werden.

Cidre 18.04.2005 19:28

Zitat:

Ja, aber da die meisten wahrscheinlich die neue Version verwenden werden, hab ich's bei c:\bases_x belassen.
Sehe ich genauso, war ja nur als Ergänzung angedacht.;)

Zitat:

P.S.: Die alte mwav.log sollte aber vor jedem Scan gelöscht werden.
Warum? :confused:
Die wird doch bei jedem Scan automatisch überschrieben.

Haui45 18.04.2005 19:30

Zitat:

Zitat von Cidre
Die wird doch bei jedem Scan automatisch überschrieben.

Nein, sie wird weitergeführt (gerade nochmal getestet).

Haui45 18.04.2005 20:34

Also, wer noch Interesse daran hat, kann es gerne ausprobieren, ich hab's noch so verändert, dass es egal ist, ob c:\bases c:\bases_x oder beide ;)

btw: auf eine elegantere Lösung verzichte ich vorerst :blabla:

*EDIT*
Anhang gelöscht, bitte das lesen. Funktioniert natürlich immer noch mit den "älteren" und "neueren" Versionen von eScan.

Rotterdamer 19.04.2005 17:20

Hallo

Ich danke Haui vielmals für diesen Tipp, hätte ehrlich gesagt nicht die Zeit gefunden alles einzeln und mühsam zu kopieren.

Anbei nun meine Schreckensbilanz :teufel2:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Funde für "infected"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
605:Sat Apr 16 18:57:11 2005 => File C:\WINDOWS\system32\drivers\delprot.sys infected by "Trojan.Win32.Delprot.a" Virus. Action Taken: No Action Taken.
785:Sat Apr 16 18:57:22 2005 => System found infected with tsa Spyware/Adware! Action taken: No Action Taken.
786:Sat Apr 16 18:57:22 2005 => File System Found infected by "tsa Spyware/Adware" Virus. Action Taken: No Action Taken.
789:Sat Apr 16 18:57:22 2005 => System found infected with vendor Spyware/Adware! Action taken: No Action Taken.
790:Sat Apr 16 18:57:22 2005 => File System Found infected by "vendor Spyware/Adware" Virus. Action Taken: No Action Taken.
792:Sat Apr 16 18:57:22 2005 => System found infected with text/html Spyware/Adware! Action taken: No Action Taken.
793:Sat Apr 16 18:57:22 2005 => File System Found infected by "text/html Spyware/Adware" Virus. Action Taken: No Action Taken.
811:Sat Apr 16 18:57:24 2005 => File C:\WINDOWS\ceres.dll infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
822:Sat Apr 16 18:57:24 2005 => File C:\WINDOWS\df12e.exe infected by "Trojan.Win32.LowZones.av" Virus. Action Taken: No Action Taken.
825:Sat Apr 16 18:57:25 2005 => File C:\WINDOWS\edxde.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.aa" Virus. Action Taken: No Action Taken.
878:Sat Apr 16 18:57:28 2005 => File C:\WINDOWS\nxifie.exe infected by "Trojan-Downloader.Win32.IstBar.ij" Virus. Action Taken: No Action Taken.
889:Sat Apr 16 18:57:28 2005 => File C:\WINDOWS\private-zone.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken.
902:Sat Apr 16 18:57:29 2005 => File C:\WINDOWS\rgdfed.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken.
921:Sat Apr 16 18:57:30 2005 => File C:\WINDOWS\su1111fka.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
960:Sat Apr 16 18:57:32 2005 => File C:\WINDOWS\ysb_plugin.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken.
1069:Sat Apr 16 18:57:40 2005 => File C:\WINDOWS\system32\boln.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken.
1409:Sat Apr 16 18:58:02 2005 => File C:\WINDOWS\system32\elitewsu32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
2337:Sat Apr 16 18:59:00 2005 => File C:\WINDOWS\system32\regular_plugin.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken.
2529:Sat Apr 16 18:59:11 2005 => File C:\WINDOWS\system32\SSK_B5_MVSSK2.EXE infected by "Trojan-Downloader.Win32.Small.qn" Virus. Action Taken: No Action Taken.
2597:Sat Apr 16 18:59:15 2005 => File C:\WINDOWS\system32\temperror32.dat infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
6651:Sat Apr 16 19:01:55 2005 => File C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy\Recovery\TIBS2.zip infected by "Password-protected-EXE" Virus. Action Taken: No Action Taken.
13521:Sat Apr 16 19:15:15 2005 => File C:\Programme\Common Files\uwwk\uwwka.exe infected by "Trojan-Downloader.Win32.TSUpdate.l" Virus. Action Taken: No Action Taken.
13530:Sat Apr 16 19:15:15 2005 => File C:\Programme\Common Files\uwwk\uwwkl.exe infected by "Trojan-Downloader.Win32.TSUpdate.j" Virus. Action Taken: No Action Taken.
13534:Sat Apr 16 19:15:15 2005 => File C:\Programme\Common Files\uwwk\uwwkm.exe infected by "Trojan-Downloader.Win32.TSUpdate.k" Virus. Action Taken: No Action Taken.
13538:Sat Apr 16 19:15:15 2005 => File C:\Programme\Common Files\uwwk\uwwkp.exe infected by "not-a-virus:AdWare.Xupiter.m" Virus. Action Taken: No Action Taken.
18955:Sat Apr 16 19:23:17 2005 => File C:\Programme\Mozilla Firefox\extensions\{2bafa858-4ff3-4207-822e-ef46d1b431de}\chrome\isearch.jar infected by "not-a-virus:AdWare.ToolBar.ISearch.e" Virus. Action Taken: No Action Taken.
23417:Sat Apr 16 19:28:48 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP120\A0012980.exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken.
23503:Sat Apr 16 19:28:53 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP122\A0013003.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
23507:Sat Apr 16 19:28:53 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP122\A0013005.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken.
23510:Sat Apr 16 19:28:53 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP122\A0013006.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken.
23517:Sat Apr 16 19:28:53 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP122\A0013011.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
23605:Sat Apr 16 19:28:58 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP123\A0013068.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
23721:Sat Apr 16 19:29:04 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP125\A0013122.dll infected by "Trojan-Downloader.Win32.Small.amg" Virus. Action Taken: No Action Taken.
23724:Sat Apr 16 19:29:04 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP125\A0013123.exe infected by "Trojan-Dropper.Win32.Agent.hh" Virus. Action Taken: No Action Taken.
23727:Sat Apr 16 19:29:04 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP125\A0013124.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.af" Virus. Action Taken: No Action Taken.
23828:Sat Apr 16 19:29:10 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP126\A0013192.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken.
23835:Sat Apr 16 19:29:10 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP126\A0013197.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
23838:Sat Apr 16 19:29:10 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP126\A0013198.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken.
23883:Sat Apr 16 19:29:13 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP127\A0013209.exe infected by "not-a-virus:AdWare.Suggestor.g" Virus. Action Taken: No Action Taken.
23887:Sat Apr 16 19:29:13 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP127\A0013211.exe infected by "not-a-virus:AdWare.MDH.a" Virus. Action Taken: No Action Taken.
23890:Sat Apr 16 19:29:13 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP127\A0013212.exe infected by "not-a-virus:AdWare.MDH.a" Virus. Action Taken: No Action Taken.
23893:Sat Apr 16 19:29:13 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP127\A0013213.dll infected by "not-a-virus:AdWare.Suggestor.g" Virus. Action Taken: No Action Taken.
23904:Sat Apr 16 19:29:14 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP127\snapshot\MFEX-32.DAT infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.
23937:Sat Apr 16 19:29:15 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP128\A0013219.exe infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.
23952:Sat Apr 16 19:29:16 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP128\snapshot\MFEX-32.DAT infected by "Trojan-Downloader.Win32.IstBar.gen" Virus. Action Taken: No Action Taken.
24106:Sat Apr 16 19:29:25 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013321.exe infected by "not-a-virus:AdWare.Xupiter.m" Virus. Action Taken: No Action Taken.
24109:Sat Apr 16 19:29:26 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013322.exe infected by "Trojan-Downloader.Win32.TSUpdate.l" Virus. Action Taken: No Action Taken.
24112:Sat Apr 16 19:29:26 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013323.exe infected by "Trojan-Downloader.Win32.TSUpdate.j" Virus. Action Taken: No Action Taken.
24115:Sat Apr 16 19:29:26 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013324.exe infected by "Trojan-Downloader.Win32.TSUpdate.k" Virus. Action Taken: No Action Taken.
24123:Sat Apr 16 19:29:26 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013330.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken.
24126:Sat Apr 16 19:29:26 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013331.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
24129:Sat Apr 16 19:29:26 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013332.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
24132:Sat Apr 16 19:29:26 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013333.exe infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus. Action Taken: No Action Taken.
24135:Sat Apr 16 19:29:26 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013334.EXE infected by "Trojan-Downloader.Win32.Small.qn" Virus. Action Taken: No Action Taken.
24138:Sat Apr 16 19:29:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013335.exe infected by "Trojan-Dropper.Win32.Mudrop.o" Virus. Action Taken: No Action Taken.
24141:Sat Apr 16 19:29:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013336.exe infected by "Trojan-Downloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.
24144:Sat Apr 16 19:29:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013337.exe infected by "Trojan-Downloader.Win32.Dyfuca.du" Virus. Action Taken: No Action Taken.
24151:Sat Apr 16 19:29:28 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013342.exe infected by "Trojan-Downloader.Win32.IstBar.ij" Virus. Action Taken: No Action Taken.
24154:Sat Apr 16 19:29:28 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013343.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken.
24157:Sat Apr 16 19:29:29 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013344.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken.
24160:Sat Apr 16 19:29:29 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013345.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
24164:Sat Apr 16 19:29:29 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013347.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken.
24192:Sat Apr 16 19:29:35 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013373.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.z" Virus. Action Taken: No Action Taken.
24195:Sat Apr 16 19:29:35 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013374.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
24198:Sat Apr 16 19:29:35 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP130\A0013375.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.aa" Virus. Action Taken: No Action Taken.
24334:Sat Apr 16 19:29:45 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013474.exe infected by "not-a-virus:AdWare.Xupiter.m" Virus. Action Taken: No Action Taken.
24337:Sat Apr 16 19:29:45 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013475.exe infected by "Trojan-Downloader.Win32.TSUpdate.l" Virus. Action Taken: No Action Taken.
24340:Sat Apr 16 19:29:45 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013476.exe infected by "Trojan-Downloader.Win32.TSUpdate.j" Virus. Action Taken: No Action Taken.
24343:Sat Apr 16 19:29:45 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013477.exe infected by "Trojan-Downloader.Win32.TSUpdate.k" Virus. Action Taken: No Action Taken.
24351:Sat Apr 16 19:29:46 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013483.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken.
24354:Sat Apr 16 19:29:46 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013484.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
24357:Sat Apr 16 19:29:46 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013485.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
24360:Sat Apr 16 19:29:46 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013486.exe infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus. Action Taken: No Action Taken.
24363:Sat Apr 16 19:29:46 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013487.EXE infected by "Trojan-Downloader.Win32.Small.qn" Virus. Action Taken: No Action Taken.
24366:Sat Apr 16 19:29:46 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013488.exe infected by "Trojan-Dropper.Win32.Mudrop.o" Virus. Action Taken: No Action Taken.
24369:Sat Apr 16 19:29:46 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013489.exe infected by "Trojan-Downloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.
24372:Sat Apr 16 19:29:46 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013490.exe infected by "Trojan-Downloader.Win32.Dyfuca.du" Virus. Action Taken: No Action Taken.
24379:Sat Apr 16 19:29:48 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013495.exe infected by "Trojan-Downloader.Win32.IstBar.ij" Virus. Action Taken: No Action Taken.
24382:Sat Apr 16 19:29:48 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013496.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken.
24385:Sat Apr 16 19:29:48 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013497.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken.
24388:Sat Apr 16 19:29:48 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013498.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
24392:Sat Apr 16 19:29:49 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013500.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken.
24420:Sat Apr 16 19:29:54 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013526.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.z" Virus. Action Taken: No Action Taken.
24423:Sat Apr 16 19:29:54 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013527.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
24426:Sat Apr 16 19:29:55 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP132\A0013528.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.aa" Virus. Action Taken: No Action Taken.
24562:Sat Apr 16 19:30:05 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013627.exe infected by "not-a-virus:AdWare.Xupiter.m" Virus. Action Taken: No Action Taken.
24565:Sat Apr 16 19:30:05 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013628.exe infected by "Trojan-Downloader.Win32.TSUpdate.l" Virus. Action Taken: No Action Taken.
24568:Sat Apr 16 19:30:05 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013629.exe infected by "Trojan-Downloader.Win32.TSUpdate.j" Virus. Action Taken: No Action Taken.
24571:Sat Apr 16 19:30:05 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013630.exe infected by "Trojan-Downloader.Win32.TSUpdate.k" Virus. Action Taken: No Action Taken.
24579:Sat Apr 16 19:30:06 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013636.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken.
24582:Sat Apr 16 19:30:06 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013637.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
24585:Sat Apr 16 19:30:06 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013638.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
24588:Sat Apr 16 19:30:06 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013639.exe infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus. Action Taken: No Action Taken.
24591:Sat Apr 16 19:30:06 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013640.EXE infected by "Trojan-Downloader.Win32.Small.qn" Virus. Action Taken: No Action Taken.
24594:Sat Apr 16 19:30:06 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013641.exe infected by "Trojan-Dropper.Win32.Mudrop.o" Virus. Action Taken: No Action Taken.
24597:Sat Apr 16 19:30:06 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013642.exe infected by "Trojan-Downloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.
24600:Sat Apr 16 19:30:06 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013643.exe infected by "Trojan-Downloader.Win32.Dyfuca.du" Virus. Action Taken: No Action Taken.
24607:Sat Apr 16 19:30:08 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013648.exe infected by "Trojan-Downloader.Win32.IstBar.ij" Virus. Action Taken: No Action Taken.

Rotterdamer 19.04.2005 17:22

24610:Sat Apr 16 19:30:08 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013649.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken.
24613:Sat Apr 16 19:30:08 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013650.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken.
24616:Sat Apr 16 19:30:08 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013651.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
24620:Sat Apr 16 19:30:08 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013653.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken.
24648:Sat Apr 16 19:30:14 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013679.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.z" Virus. Action Taken: No Action Taken.
24651:Sat Apr 16 19:30:14 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013680.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
24654:Sat Apr 16 19:30:14 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP134\A0013681.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.aa" Virus. Action Taken: No Action Taken.
24760:Sat Apr 16 19:30:24 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013780.exe infected by "not-a-virus:AdWare.Xupiter.m" Virus. Action Taken: No Action Taken.
24763:Sat Apr 16 19:30:24 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013781.exe infected by "Trojan-Downloader.Win32.TSUpdate.l" Virus. Action Taken: No Action Taken.
24766:Sat Apr 16 19:30:24 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013782.exe infected by "Trojan-Downloader.Win32.TSUpdate.j" Virus. Action Taken: No Action Taken.
24769:Sat Apr 16 19:30:24 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013783.exe infected by "Trojan-Downloader.Win32.TSUpdate.k" Virus. Action Taken: No Action Taken.
24777:Sat Apr 16 19:30:24 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013789.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken.
24780:Sat Apr 16 19:30:25 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013790.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
24783:Sat Apr 16 19:30:25 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013791.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
24786:Sat Apr 16 19:30:25 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013792.exe infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus. Action Taken: No Action Taken.
24789:Sat Apr 16 19:30:25 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013793.EXE infected by "Trojan-Downloader.Win32.Small.qn" Virus. Action Taken: No Action Taken.
24792:Sat Apr 16 19:30:25 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013794.exe infected by "Trojan-Dropper.Win32.Mudrop.o" Virus. Action Taken: No Action Taken.
24795:Sat Apr 16 19:30:25 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013795.exe infected by "Trojan-Downloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.
24798:Sat Apr 16 19:30:25 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013796.exe infected by "Trojan-Downloader.Win32.Dyfuca.du" Virus. Action Taken: No Action Taken.
24805:Sat Apr 16 19:30:26 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013801.exe infected by "Trojan-Downloader.Win32.IstBar.ij" Virus. Action Taken: No Action Taken.
24808:Sat Apr 16 19:30:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013802.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken.
24811:Sat Apr 16 19:30:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013803.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken.
24814:Sat Apr 16 19:30:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013804.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
24818:Sat Apr 16 19:30:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013806.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken.
24846:Sat Apr 16 19:30:33 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013832.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.z" Virus. Action Taken: No Action Taken.
24849:Sat Apr 16 19:30:33 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013833.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
24852:Sat Apr 16 19:30:33 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP135\A0013834.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.aa" Virus. Action Taken: No Action Taken.
25017:Sat Apr 16 19:30:56 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0013991.exe infected by "not-a-virus:AdWare.Xupiter.m" Virus. Action Taken: No Action Taken.
25020:Sat Apr 16 19:30:56 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0013992.exe infected by "Trojan-Downloader.Win32.TSUpdate.l" Virus. Action Taken: No Action Taken.
25023:Sat Apr 16 19:30:56 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0013993.exe infected by "Trojan-Downloader.Win32.TSUpdate.j" Virus. Action Taken: No Action Taken.
25026:Sat Apr 16 19:30:56 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0013994.exe infected by "Trojan-Downloader.Win32.TSUpdate.k" Virus. Action Taken: No Action Taken.
25034:Sat Apr 16 19:30:57 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014000.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken.
25037:Sat Apr 16 19:30:57 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014001.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
25040:Sat Apr 16 19:30:57 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014002.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
25043:Sat Apr 16 19:30:57 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014003.exe infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus. Action Taken: No Action Taken.
25046:Sat Apr 16 19:30:57 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014004.EXE infected by "Trojan-Downloader.Win32.Small.qn" Virus. Action Taken: No Action Taken.
25049:Sat Apr 16 19:30:57 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014005.exe infected by "Trojan-Dropper.Win32.Mudrop.o" Virus. Action Taken: No Action Taken.
25052:Sat Apr 16 19:30:57 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014006.exe infected by "Trojan-Downloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.
25055:Sat Apr 16 19:30:57 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014007.exe infected by "Trojan-Downloader.Win32.Dyfuca.du" Virus. Action Taken: No Action Taken.
25062:Sat Apr 16 19:30:59 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014012.exe infected by "Trojan-Downloader.Win32.IstBar.ij" Virus. Action Taken: No Action Taken.
25065:Sat Apr 16 19:30:59 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014013.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken.
25068:Sat Apr 16 19:30:59 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014014.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken.
25071:Sat Apr 16 19:30:59 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014015.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
25075:Sat Apr 16 19:30:59 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014017.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken.
25103:Sat Apr 16 19:31:05 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014043.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.z" Virus. Action Taken: No Action Taken.
25106:Sat Apr 16 19:31:05 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014044.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
25109:Sat Apr 16 19:31:05 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP136\A0014045.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.aa" Virus. Action Taken: No Action Taken.
25180:Sat Apr 16 19:31:10 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP137\A0014104.exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken.
25209:Sat Apr 16 19:31:11 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP137\A0014131.exe infected by "Trojan-Downloader.Win32.Dyfuca.dx" Virus. Action Taken: No Action Taken.
25228:Sat Apr 16 19:31:12 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP137\A0014148.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken.
25232:Sat Apr 16 19:31:12 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP137\A0014150.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
25235:Sat Apr 16 19:31:12 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP137\A0014151.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken.
25238:Sat Apr 16 19:31:12 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP137\A0014152.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken.
25244:Sat Apr 16 19:31:13 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP137\A0014156.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
25248:Sat Apr 16 19:31:13 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP137\A0014158.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
25262:Sat Apr 16 19:31:13 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP137\A0014170.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.aa" Virus. Action Taken: No Action Taken.
25299:Sat Apr 16 19:31:15 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014174.exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken.
25326:Sat Apr 16 19:31:16 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014202.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken.
25336:Sat Apr 16 19:31:17 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014210.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
25339:Sat Apr 16 19:31:17 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014211.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken.
25342:Sat Apr 16 19:31:17 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014212.exe infected by "Virus.Win32.Bube.k" Virus. Action Taken: No Action Taken.
25345:Sat Apr 16 19:31:17 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014213.exe infected by "Virus.Win32.Bube.k" Virus. Action Taken: No Action Taken.
25348:Sat Apr 16 19:31:17 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014214.exe infected by "Trojan-Dropper.Win32.Small.rd" Virus. Action Taken: No Action Taken.
25351:Sat Apr 16 19:31:17 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014215.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken.
25354:Sat Apr 16 19:31:17 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014216.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
25360:Sat Apr 16 19:31:17 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014220.exe infected by "Virus.Win32.Bube.k" Virus. Action Taken: No Action Taken.
25363:Sat Apr 16 19:31:17 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014221.exe infected by "Virus.Win32.Bube.k" Virus. Action Taken: No Action Taken.
25366:Sat Apr 16 19:31:17 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014222.exe infected by "Trojan-Downloader.Win32.IstBar.ij" Virus. Action Taken: No Action Taken.
25369:Sat Apr 16 19:31:18 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014223.exe infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken.
25372:Sat Apr 16 19:31:18 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\A0014224.dll infected by "not-a-virus:AdWare.ToolBar.EliteBar.z" Virus. Action Taken: No Action Taken.
25413:Sat Apr 16 19:31:20 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\snapshot\MFEX-32.DAT infected by "not-a-virus:Porn-Dialer.Win32.Tibs" Virus. Action Taken: No Action Taken.
25416:Sat Apr 16 19:31:20 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP138\snapshot\MFEX-33.DAT infected by "not-a-virus:Porn-Downloader.Win32.TibSystems" Virus. Action Taken: No Action Taken.
25531:Sat Apr 16 19:31:27 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP140\A0014294.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken.
25587:Sat Apr 16 19:31:30 2005 => File C:\System Volume Information\_restore{8D724808-CFA6-4AA4-840C-0C563876F0AB}\RP141\A0014343.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken.
31357:Sat Apr 16 19:40:38 2005 => File C:\WINDOWS\ceres.dll infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
31561:Sat Apr 16 19:40:43 2005 => File C:\WINDOWS\df12e.exe infected by "Trojan.Win32.LowZones.av" Virus. Action Taken: No Action Taken.
31566:Sat Apr 16 19:40:43 2005 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\website.ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken.
31570:Sat Apr 16 19:40:43 2005 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.2\website.ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken.
31575:Sat Apr 16 19:40:44 2005 => File C:\WINDOWS\Downloaded Program Files\internazionale_ver10.ocx infected by "Trojan-Clicker.Win32.Adpower.n" Virus. Action Taken: No Action Taken.
31580:Sat Apr 16 19:40:44 2005 => File C:\WINDOWS\Downloaded Program Files\website.ocx infected by "Trojan-Downloader.Win32.Agent.ex" Virus. Action Taken: No Action Taken.
31591:Sat Apr 16 19:42:16 2005 => File C:\WINDOWS\edxde.exe infected by "not-a-virus:AdWare.ToolBar.EliteBar.aa" Virus. Action Taken: No Action Taken.
40352:Sat Apr 16 19:54:41 2005 => File C:\WINDOWS\inst\3p_1.exe infected by "Trojan-Downloader.Win32.Dyfuca.du" Virus. Action Taken: No Action Taken.
40355:Sat Apr 16 19:54:41 2005 => File C:\WINDOWS\inst\3p_1n.exe infected by "not-a-virus:AdWare.BetterInternet" Virus. Action Taken: No Action Taken.
40358:Sat Apr 16 19:54:41 2005 => File C:\WINDOWS\inst\3p_2.exe infected by "Trojan-Downloader.Win32.TSUpdate.f" Virus. Action Taken: No Action Taken.
40361:Sat Apr 16 19:54:42 2005 => File C:\WINDOWS\inst\3p_3.exe infected by "Trojan-Dropper.Win32.Mudrop.o" Virus. Action Taken: No Action Taken.
40950:Sat Apr 16 19:55:10 2005 => File C:\WINDOWS\isrvs\desktop.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
40953:Sat Apr 16 19:55:10 2005 => File C:\WINDOWS\isrvs\edmond.exe infected by "Trojan.Win32.Delprot.a" Virus. Action Taken: No Action Taken.
40960:Sat Apr 16 19:55:10 2005 => File C:\WINDOWS\isrvs\isearch.xpi infected by "not-a-virus:AdWare.ToolBar.ISearch.e" Virus. Action Taken: No Action Taken.
40963:Sat Apr 16 19:55:11 2005 => File C:\WINDOWS\isrvs\mfiltis.dll infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
40967:Sat Apr 16 19:55:11 2005 => File C:\WINDOWS\isrvs\sysupd.dll infected by "Trojan-Downloader.Win32.Ieser.a" Virus. Action Taken: No Action Taken.
41147:Sat Apr 16 19:55:40 2005 => File C:\WINDOWS\nxifie.exe infected by "Trojan-Downloader.Win32.IstBar.ij" Virus. Action Taken: No Action Taken.
42303:Sat Apr 16 19:56:36 2005 => File C:\WINDOWS\private-zone.exe infected by "Trojan-Downloader.Win32.Delf.dg" Virus. Action Taken: No Action Taken.
42517:Sat Apr 16 19:56:51 2005 => File C:\WINDOWS\rgdfed.exe infected by "Trojan-Clicker.Win32.Agent.bn" Virus. Action Taken: No Action Taken.
47175:Sat Apr 16 20:04:33 2005 => File C:\WINDOWS\su1111fka.exe infected by "not-a-virus:AdWare.ToolBar.ISearch.d" Virus. Action Taken: No Action Taken.
47357:Sat Apr 16 20:04:47 2005 => File C:\WINDOWS\system32\boln.dll infected by "Trojan-Downloader.Win32.Druser.b" Virus. Action Taken: No Action Taken.
49372:Sat Apr 16 20:07:17 2005 => File C:\WINDOWS\system32\elitewsu32.exe infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
50657:Sat Apr 16 20:08:34 2005 => File C:\WINDOWS\system32\regular_plugin.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken.
51295:Sat Apr 16 20:09:11 2005 => File C:\WINDOWS\system32\SSK_B5_MVSSK2.EXE infected by "Trojan-Downloader.Win32.Small.qn" Virus. Action Taken: No Action Taken.
51363:Sat Apr 16 20:09:16 2005 => File C:\WINDOWS\system32\temperror32.dat infected by "Trojan.Win32.StartPage.nk" Virus. Action Taken: No Action Taken.
52052:Sat Apr 16 20:09:59 2005 => File C:\WINDOWS\ysb_plugin.exe infected by "Trojan-Downloader.Win32.IstBar.it" Virus. Action Taken: No Action Taken.
52076:Sat Apr 16 20:09:59 2005 => Total Disinfected Files: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Funde für "tagged"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~ © Haui ;-) ~~~~~~~

Wie kann so etwas passieren. (Hatte mich eigendlich für einen vorsichtigen Internet User gehalten) :heilig:

Habe von einigen Informatikern bei mir an der Uni gehört, das das mit einem Microsoft Update zu tun haben kann, was ich mir kürzlich auf mein Notebook geladen habe. Habe aber keinerlei Medienberichte diesbezüglich vernommen.

Hoffe jetzt mal wieder auf eure (bis jetzt ohne Ausnahme, sehr hilfreiche!!!!) Hilfe.

Danke


Alle Zeitangaben in WEZ +1. Es ist jetzt 20:00 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131