Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Bitte Logfile überprüfen (https://www.trojaner-board.de/22418-bitte-logfile-ueberpruefen.html)

Stocki80 03.10.2005 23:58

Bitte Logfile überprüfen
 
Hallo zusammen.

Kann mir jemand meien logfile überprüfen? Ich komme damit nicht klar. Ich habe den win32.nsag.b auf dem rechner und kriege ihn nicht runter.

Hier ist mein logfile:

Logfile of HijackThis v1.99.1
Scan saved at 00:15:42, on 04.10.2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\Programme\AVPersonal\AVGUARD.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\WINDOWS\SYSTEM32\GEARSEC.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\snmp.exe
C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\System32\atiptaxx.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\System32\rmctrl.exe
C:\PROGRA~1\TCMMOU~1\MouseDrv.exe
C:\PROGRA~1\GEMEIN~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Programme\Winamp\winampa.exe
C:\Programme\Siemens\Gigaset USB Adapter 54\PRISMSVR.EXE
C:\Programme\AVPersonal\AVGNT.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\WinZip\WZQKPICK.EXE
C:\Programme\Siemens\Gigaset USB Adapter 54\GigasetUSBMonitor.exe
C:\PROGRA~1\GEMEIN~1\PCSuite\Services\SERVIC~1.EXE
C:\Programme\Internet Explorer\iexplore.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\explorer.exe
C:\Jan\Downloads\Progs\hijackthis_199\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [VOBID] C:\Programme\DVD Movie Copy\InstantDrive\InstantDrive.exe /remount
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe
O4 - HKLM\..\Run: [TCMKeyboard ] C:\PROGRA~1\TCMMOU~1\PS2USBKBDDrv.exe
O4 - HKLM\..\Run: [TCMMouse ] C:\PROGRA~1\TCMMOU~1\MouseDrv.exe
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\GEMEIN~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Programme\Siemens\Gigaset USB Adapter 54\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programme\WinZip\WZQKPICK.EXE
O4 - Global Startup: Gigaset WLAN Adapter Monitor.lnk = C:\Programme\Siemens\Gigaset USB Adapter 54\GigasetUSBMonitor.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O23 - Service: AntiVir Service (AntiVirService) - H+BEDV Datentechnik GmbH - C:\Programme\AVPersonal\AVGUARD.EXE
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: AntiVir Update (AVWUpSrv) - H+BEDV Datentechnik GmbH, Germany - C:\Programme\AVPersonal\AVWUPSRV.EXE
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\SYSTEM32\GEARSEC.EXE
O23 - Service: kavsvc - Kaspersky Lab - C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

cronos 04.10.2005 00:28

Zunächst einmal was grundsätzliches:

Bei dir fehlen jegliche Windowsupdates, da ist es kein Wunder, dass du dir was einfängst.Service Pack 2 ist mitlerweile aktuell.
Da ist es kein Wunder, dass du dir was einfängst.
Da helfen dir auch keine 2 gleichzeitig laufenden AV-Programme.
Entscheide dich für Antivir oder für Kaspersky.

Arbeite zunächst folgendes ab:

http://www.trojaner-board.de/showthread.php?t=21709

Melde dich mit allen geforderten Logs zurück.

Stocki80 04.10.2005 10:25

Hallo cronos.

Erstmal danke für deine anleitung. Ich habe deine anleitung bis auf das windows update gemacht. Muß ich jetzt den ganzen escan log hier posten oder finde ich den virus log auch einzeln? Hier ist schonmal mein smitrem log und mein neuer hijack log.


smitRem log file
version 2.5

by noahdfear


~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Pre-run Files Present


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~


~~~ Miscellaneous Files/folders ~~~




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~



Post-run Files Present


~~~ Program Files ~~~



~~~ Shortcuts ~~~



~~~ Favorites ~~~



~~~ system32 folder ~~~



~~~ Icons in System32 ~~~



~~~ Windows directory ~~~



~~~ Drive root ~~~



~~~ Miscellaneous Files/folders ~~~




~~~ Wininet.dll ~~~

CLEAN! :)


Logfile of HijackThis v1.99.1
Scan saved at 11:44:24, on 04.10.2005
Platform: Windows XP (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 (6.00.2600.0000)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\LEXBCES.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\LEXPPS.EXE
C:\WINDOWS\System32\Ati2evxx.exe
C:\WINDOWS\SYSTEM32\GEARSEC.EXE
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\System32\snmp.exe
C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\System32\atiptaxx.exe
C:\WINDOWS\System32\LXSUPMON.EXE
C:\WINDOWS\System32\rmctrl.exe
C:\PROGRA~1\TCMMOU~1\MouseDrv.exe
C:\PROGRA~1\GEMEIN~1\PCSuite\DATALA~1\DATALA~1.EXE
C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
C:\Programme\Winamp\winampa.exe
C:\Programme\Siemens\Gigaset USB Adapter 54\PRISMSVR.EXE
C:\WINDOWS\System32\ctfmon.exe
C:\Programme\WinZip\WZQKPICK.EXE
C:\Programme\Siemens\Gigaset USB Adapter 54\GigasetUSBMonitor.exe
C:\PROGRA~1\GEMEIN~1\PCSuite\Services\SERVIC~1.EXE
C:\Programme\Internet Explorer\iexplore.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Jan\Downloads\Progs\hijackthis_199\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
R3 - URLSearchHook: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O3 - Toolbar: (no name) - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: ICQ Toolbar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQToolbar\toolbaru.dll
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] atiptaxx.exe
O4 - HKLM\..\Run: [VOBID] C:\Programme\DVD Movie Copy\InstantDrive\InstantDrive.exe /remount
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\System32\NeroCheck.exe
O4 - HKLM\..\Run: [LXSUPMON] C:\WINDOWS\System32\LXSUPMON.EXE RUN
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe
O4 - HKLM\..\Run: [TCMKeyboard ] C:\PROGRA~1\TCMMOU~1\PS2USBKBDDrv.exe
O4 - HKLM\..\Run: [TCMMouse ] C:\PROGRA~1\TCMMOU~1\MouseDrv.exe
O4 - HKLM\..\Run: [DataLayer] C:\PROGRA~1\GEMEIN~1\PCSuite\DATALA~1\DATALA~1.EXE
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\PROGRA~1\Nokia\NOKIAP~1\TRAYAP~1.EXE
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe
O4 - HKLM\..\Run: [PRISMSVR.EXE] "C:\Programme\Siemens\Gigaset USB Adapter 54\PRISMSVR.EXE" /APPLY
O4 - HKLM\..\Run: [KAVPersonal50] "C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal\kav.exe" /minimize
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programme\WinZip\WZQKPICK.EXE
O4 - Global Startup: Gigaset WLAN Adapter Monitor.lnk = C:\Programme\Siemens\Gigaset USB Adapter 54\GigasetUSBMonitor.exe
O8 - Extra context menu item: &ICQ Toolbar Search - res://C:\Programme\ICQToolbar\toolbaru.dll/SEARCH.HTML
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINDOWS\web\related.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: (no name) - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - (no file)
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: GEARSecurity - GEAR Software - C:\WINDOWS\SYSTEM32\GEARSEC.EXE
O23 - Service: kavsvc - Kaspersky Lab - C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal\kavsvc.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\WINDOWS\system32\LEXBCES.EXE
O23 - Service: SmartLinkService (SLService) - - C:\WINDOWS\SYSTEM32\slserv.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe

Stocki80 04.10.2005 12:18

Hier ist mein escan virus found log.

Tue Oct 04 10:23:14 2005 => System found infected with flashget Spyware/Adware ({e0e899ab-f487-11d5-8d29-0050ba6940e3})! Action taken: No Action Taken.
Tue Oct 04 10:23:14 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken.
Tue Oct 04 10:23:14 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken.
Tue Oct 04 10:23:14 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken.
Tue Oct 04 10:23:18 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Eigene Dateien\stronghold 2\config.dat
Tue Oct 04 10:23:18 2005 => System found infected with startsurfing Spyware/Adware (config.dat)! Action taken: No Action Taken.

Tue Oct 04 10:23:18 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Eigene Dateien\stronghold 2\config.dat
Tue Oct 04 10:23:18 2005 => System found infected with startsurfing Spyware/Adware (config.dat)! Action taken: No Action Taken.

Tue Oct 04 10:23:19 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\idvmif3e\common[1].js
Tue Oct 04 10:23:19 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken.

Tue Oct 04 10:23:19 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\jh193emv\common[1].js
Tue Oct 04 10:23:19 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken.

Tue Oct 04 10:23:19 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\6vihi1mx\common[1].js
Tue Oct 04 10:23:19 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken.

Tue Oct 04 10:23:19 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\6vihi1mx\blank[1].htm
Tue Oct 04 10:23:19 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:19 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\67pl1n2m\common[1].js
Tue Oct 04 10:23:19 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken.

Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\056rkxan\ads[1].htm
Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\056rkxan\ads[2].htm
Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\o9mfcd67\ads[1].htm
Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\o9mfcd67\ads[2].htm
Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\q3urul6z\ads[1].htm
Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\i98jm1i5\show_ads[2].js
Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (show_ads[2].js)! Action taken: No Action Taken.

Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\i98jm1i5\ads[1].htm
Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\kjtnqi31\ads[2].htm
Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:20 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\kjtnqi31\ads[1].htm
Tue Oct 04 10:23:20 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\idvmif3e\common[1].js
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\jh193emv\common[1].js
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\6vihi1mx\common[1].js
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\6vihi1mx\blank[1].htm
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\67pl1n2m\common[1].js
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (common[1].js)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\056rkxan\ads[1].htm
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\056rkxan\ads[2].htm
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\o9mfcd67\ads[1].htm
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\o9mfcd67\ads[2].htm
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\q3urul6z\ads[1].htm
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\i98jm1i5\show_ads[2].js
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (show_ads[2].js)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\i98jm1i5\ads[1].htm
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\kjtnqi31\ads[2].htm
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[2].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:21 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\kjtnqi31\ads[1].htm
Tue Oct 04 10:23:21 2005 => System found infected with whenu.savenow Spyware/Adware (ads[1].htm)! Action taken: No Action Taken.

Tue Oct 04 10:23:22 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Eigene Dateien\stronghold 2\config.dat
Tue Oct 04 10:23:22 2005 => System found infected with startsurfing Spyware/Adware (config.dat)! Action taken: No Action Taken.

Tue Oct 04 10:23:22 2005 => Offending file found: C:\WINDOWS\iun6002.exe
Tue Oct 04 10:23:22 2005 => System found infected with zipitpro Spyware/Adware (C:\WINDOWS\iun6002.exe)! Action taken: No Action Taken.

Tue Oct 04 11:04:39 2005 => File C:\System Volume Information\_restore{FE8CEDBF-F2C1-4799-A000-289B08C42FFA}\RP287\A0045638.DLL infected by "Virus.Win32.Nsag.b" Virus! Action Taken: No Action Taken.

Stocki80 05.10.2005 21:50

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Funde für "infected"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Tue Oct 04 23:21:03 2005 => System found infected with flashget Spyware/Adware ({e0e899ab-f487-11d5-8d29-0050ba6940e3})! Action taken: No Action Taken.
Tue Oct 04 23:21:03 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken.
Tue Oct 04 23:21:03 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken.
Tue Oct 04 23:21:04 2005 => System found infected with alexa Spyware/Adware ({c95fe080-8f5d-11d2-a20b-00aa003c157a})! Action taken: No Action Taken.
Tue Oct 04 23:21:07 2005 => System found infected with startsurfing Spyware/Adware (config.dat)! Action taken: No Action Taken.
Tue Oct 04 23:21:08 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken.
Tue Oct 04 23:21:08 2005 => System found infected with whenu.savenow Spyware/Adware (blank[1].htm)! Action taken: No Action Taken.
Tue Oct 04 23:21:09 2005 => System found infected with startsurfing Spyware/Adware (config.dat)! Action taken: No Action Taken.
Tue Oct 04 23:21:09 2005 => System found infected with zipitpro Spyware/Adware (C:\WINDOWS\iun6002.exe)! Action taken: No Action Taken.
Tue Oct 04 23:32:30 2005 => Scanning File C:\Jan\infected.doc
Tue Oct 04 23:42:32 2005 => Scanning File C:\Dokumente und Einstellungen\My PC\Anwendungsdaten\Microsoft\Office\Zuletzt verwendet\infected.LNK
Tue Oct 04 23:42:40 2005 => Scanning File C:\Dokumente und Einstellungen\My PC\Recent\infected.lnk
Tue Oct 04 23:51:56 2005 => Scanning File C:\Programme\Kaspersky Lab\Kaspersky Anti-Virus Personal\Infected.wav
Wed Oct 05 00:01:12 2005 => File C:\System Volume Information\_restore{FE8CEDBF-F2C1-4799-A000-289B08C42FFA}\RP287\A0045638.DLL infected by "Virus.Win32.Nsag.b" Virus! Action Taken: No Action Taken.
Wed Oct 05 00:10:57 2005 => Total Disinfected Files: 0
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Funde für "tagged"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Funde für "offending"
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Tue Oct 04 23:21:04 2005 => Offending Key found: HKCU\Software\gnu !!!
Tue Oct 04 23:21:07 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Eigene Dateien\stronghold 2\config.dat
Tue Oct 04 23:21:08 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\temporary internet files\content.ie5\q3urul6z\blank[1].htm
Tue Oct 04 23:21:08 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Lokale Einstellungen\Temporary Internet Files\content.ie5\q3urul6z\blank[1].htm
Tue Oct 04 23:21:09 2005 => Offending file found: C:\Dokumente und Einstellungen\My PC\Eigene Dateien\stronghold 2\config.dat
Tue Oct 04 23:21:09 2005 => Offending file found: C:\WINDOWS\iun6002.exe
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Statistiken:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Wed Oct 05 00:10:57 2005 => Total Virus(es) Found: 11
Wed Oct 05 00:10:57 2005 => Total Errors: 199
Wed Oct 05 00:10:57 2005 => Time Elapsed: 00:50:18
Wed Oct 05 00:10:57 2005 => Total Objects Scanned: 85560
Wed Oct 05 00:10:57 2005 => Virus Database Date: 2005/10/04
Wed Oct 05 06:44:00 2005 => Virus Database Date: 2005/10/04
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
~~~~~~~ © Haui ;-) ~~~~~~~
~~~~~~~ Dank an Cidre ~~~~~~~


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:23 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131