Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   escan resultat! (https://www.trojaner-board.de/16898-escan-resultat.html)

ville 21.04.2005 00:57

escan resultat!
 
Habe heute escan das erstemal durchlaufen lassen, hat einge sachen gefunden wie muss ich jetzt vorgehen?
was mach ich mit denn dateien?
wie komme ich im "C:\System Volume Information" ordner rein?

log:

Wed Apr 20 23:40:56 2005 => System found infected with BearShare Spyware/Adware ({905d0df2-3a0a-4d94-853c-54a12a745905})! Action taken: No Action Taken.
Wed Apr 20 23:40:56 2005 => File System Found infected by "BearShare Spyware/Adware" Virus. Action Taken: No Action Taken.

Wed Apr 20 23:40:56 2005 => System found infected with BearShare Spyware/Adware ({9f95f736-0f62-4214-a4b4-caa6738d4c07})! Action taken: No Action Taken.
Wed Apr 20 23:40:56 2005 => File System Found infected by "BearShare Spyware/Adware" Virus. Action Taken: No Action Taken.

Wed Apr 20 23:40:56 2005 => System found infected with BearShare Spyware/Adware ({558ec983-bedb-9168-b2de-31dbf0ee543e})! Action taken: No Action Taken.
Wed Apr 20 23:40:56 2005 => File System Found infected by "BearShare Spyware/Adware" Virus. Action Taken: No Action Taken.

Wed Apr 20 23:40:56 2005 => System found infected with BearShare Spyware/Adware ({5f95e1af-2620-4f15-bdf9-7fdce4607e17})! Action taken: No Action Taken.
Wed Apr 20 23:40:56 2005 => File System Found infected by "BearShare Spyware/Adware" Virus. Action Taken: No Action Taken.

Wed Apr 20 23:40:56 2005 => System found infected with bearshare Spyware/Adware! Action taken: No Action Taken.
Wed Apr 20 23:40:56 2005 => File System Found infected by "bearshare Spyware/Adware" Virus. Action Taken: No Action Taken.

Wed Apr 20 23:46:04 2005 => File C:\Programme\BearShare\Installer\BSINSTALLDE.exe infected by "not-a-virus:AdWare.SaveNow.z" Virus. Action Taken: No Action Taken.

Wed Apr 20 23:49:24 2005 => Scanning Folder: C:\Programme\Softwin\BitDefender8\Infected\*.*

Thu Apr 21 00:15:14 2005 => File C:\System Volume Information\_restore{E187DAA8-4CB8-43F2-8DDE-A49A88DED6BC}\RP7\A0004558.exe infected by "not-a-virus:AdWare.SaveNow.z" Virus. Action Taken: No Action Taken.

Thu Apr 21 00:16:31 2005 => File C:\System Volume Information\_restore{E187DAA8-4CB8-43F2-8DDE-A49A88DED6BC}\RP8\A0004817.exe infected by "not-a-virus:AdWare.SaveNow.z" Virus. Action Taken: No Action Taken.

Wed Apr 20 23:59:32 2005 => File C:\System Volume Information\_restore{E187DAA8-4CB8-43F2-8DDE-A49A88DED6BC}\RP10\A0005218.exe tagged as not-a-virus:RiskWare.Tool.RegPatch.a. No Action Taken.

Wed Apr 20 23:59:34 2005 => File C:\System Volume Information\_restore{E187DAA8-4CB8-43F2-8DDE-A49A88DED6BC}\RP11\A0005226.exe tagged as not-a-virus:RiskWare.Tool.RegPatch.a. No Action Taken


ich habe sp2 und alle windows updates drauf (gleich windows install gemacht)
benutze gute firewall/virenprog (bitdefender)

danke schonmal im vorraus, hoffe auf schnelle antwort!

Rene-gad 21.04.2005 07:31

@ville
Zitat:

was mach ich mit denn dateien?
Dateien im abgesicherten Modus löschen.
Zitat:

wie komme ich im "C:\System Volume Information" ordner rein?
Gar nicht ;). Hier klicken
BearShare über Systemsteuerung/Software deinstallieren.

ville 21.04.2005 11:24

Thu Apr 21 00:15:14 2005 => File C:\System Volume Information\_restore{E187DAA8-4CB8-43F2-8DDE-A49A88DED6BC}\RP7\A0004558.exe infected by "not-a-virus:AdWare.SaveNow.z" Virus. Action Taken: No Action Taken.

Thu Apr 21 00:16:31 2005 => File C:\System Volume Information\_restore{E187DAA8-4CB8-43F2-8DDE-A49A88DED6BC}\RP8\A0004817.exe infected by "not-a-virus:AdWare.SaveNow.z" Virus. Action Taken: No Action Taken.

Wed Apr 20 23:59:32 2005 => File C:\System Volume Information\_restore{E187DAA8-4CB8-43F2-8DDE-A49A88DED6BC}\RP10\A0005218.exe tagged as not-a-virus:RiskWare.Tool.RegPatch.a. No Action Taken.

Wed Apr 20 23:59:34 2005 => File C:\System Volume Information\_restore{E187DAA8-4CB8-43F2-8DDE-A49A88DED6BC}\RP11\A0005226.exe tagged as not-a-virus:RiskWare.Tool.RegPatch.a. No Action Taken



wie kann ich diese dateien löschen wenn ich nicht im "C:\System Volume Information" ordner komme?

danke schonmal!

Gigamail 21.04.2005 11:38

Systemwiederherstellung deaktivieren neu booten Systemwiederherstellung wieder aktivieren (siehe link von Rene- gad)


Alle Zeitangaben in WEZ +1. Es ist jetzt 00:54 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129