Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Lästige Spyware lässt sich nicht entfernen :( (https://www.trojaner-board.de/38612-laestige-spyware-laesst-entfernen.html)

fava 12.06.2007 22:22

Hmm :(
@ nochdigger...
schreibst ja gar nix mehr :(
Schade...
Na ich hol mal den thread wieder hoch :)
Grüßle,
Fava

nochdigger 13.06.2007 06:56

Moin

Zitat:

@ nochdigger...
schreibst ja gar nix mehr
doch doch ich war aber im Urlaub und irgendwie ist der Beitrag dann untergegangen.

Also die letzten logs sahen für mich sauber aus, aber ich gehe davon aus, dass du noch immer Popups hast.
Lade dir bitte mal CounterSpy, halte dich bitte an die Anleitung von Ruby, anschließend poste die entfernten Funde aber bitte keine Funde von Cockies.

MFG

fava 16.06.2007 13:49

Hey Nochdigger :)

Aha...cool - Danke das du mir weiterhin hilfst :)
Hab den "Counter Spy geladen und doch schon noch interessante Sachen gefunden :) Danke für den Hinweis!

Sehe selbst:

-------------------------------
Slagent/Navipromo
Type: Adware (General)
Level: Elevated

Description: Slagent/Navipromo runs without user notification after initial installation and can download and execute arbitrary files on the computer. Slagent/Navipromo contacts a Web site for advertisement purposes.

Advice: This is an elevated risk and should be removed or quarantined as it may compromise your privacy and security, make unwanted changes to your computer's settings, and negatively impact your computer's performance and stability.

-------------------------------
MediaPipe/MovieLand
Type: Hijacker
Level: Elevated
Author: MovieLand & MediaPipe

Description: MediaPipe/MovieLand is an online content access program that badgers using into paying for the application if they do not cancel the "trial" within a certain time period.

Advice: This is an elevated risk and should be removed or quarantined as it may compromise your privacy and security, make unwanted changes to your computer's settings, and negatively impact your computer's performance and stability.

----------------------------------

Die 2 Teile habe ich jetzt in Quarantäne gesteckt und 6 Cookies gelöscht :)
Soll ich die 2 Sachen auch löschen ??

Herzlichen Dank für alles!
Grüße,
Fava

fava 16.06.2007 13:56

Hoppla...
hier natürlich noch die gesamte Auswertung :)


----------------------------
Scan History Details
Start Date: 16.06.2007 12:54:42
End Date: 16.06.2007 13:50:32
Total Time: 55 Min 50 Sec
Detected security risks

Cookie: BS.Serving-Sys Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\dokumente und einstellungen\isi\cookies\isi@bs.serving-sys[1].txt
c:\dokumente und einstellungen\isi\cookies\isi@serving-sys[1].txt


Cookie: Overture.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\dokumente und einstellungen\isi\cookies\isi@overture[2].txt


Cookie: PriceGrabber Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\dokumente und einstellungen\isi\cookies\isi@pricegrabber[1].txt


Cookie: RealMedia.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\dokumente und einstellungen\isi\cookies\isi@realmedia[2].txt


Cookie: Weborama Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\dokumente und einstellungen\isi\cookies\isi@weborama[2].txt


Slagent/Navipromo Adware (General) more information...
Details: Slagent/Navipromo runs without user notification after initial installation and can download and execute arbitrary files on the computer. Slagent/Navipromo contacts a Web site for advertisement purposes.
Status: Quarantined

Files detected
C:\WINDOWS\system32\nvs2.inf


Cookie: Radar Spy Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\dokumente und einstellungen\isi\cookies\isi@yourmedia[1].txt


CoolOnlineOffers.ScreenSaver Adware Bundler more information...
Details: CoolOnlineOffers.ScreenSaver is a program which delivers advertisiment on you computer depending on your surfing behaviour.
Status: Ignored

Files detected
C:\WINDOWS\DiamondView Demo dir\EXPIRE.SCF


MailSkinner Potentially Unwanted Program more information...
Status: Ignored

Registry entries detected
HKEY_USERS\S-1-5-21-2255018123-993939828-2508340356-1006\SOFTWARE\EPK_EXTR


MediaPipe/MovieLand Hijacker more information...
Details: MediaPipe/MovieLand is an online content access program that badgers using into paying for the application if they do not cancel the "trial" within a certain time period.
Status: Quarantined

Registry entries detected
HKEY_LOCAL_MACHINE\Software\Classes\APPID\DOWNLOADMANAGER.EXE
HKEY_LOCAL_MACHINE\Software\Classes\APPID\DOWNLOADMANAGER.EXE

----------------------------------------

Grüße,
Fava

nochdigger 16.06.2007 14:12

Hallo

is ja doch noch was gefunden worden, wie sieht es aus mit Popups oder sonstigen Problemen?

Eventuell musst du Counter Spy auch öfter übers System laufen lassen, damit alles erwischt wird.

MFG

fava 18.06.2007 21:56

Hey :)

Habe den Scan nochmal laufen lassen -
er hat nur noch cookies gefunden.
Hatte aber schon noch Probleme mit popups :(
Werd es morgen nochmal laufen lassen...
Vielen Dank für alles!!!!
Hier der Bericht:

Scan History Details
Start Date: 18.06.2007 21:44:38
End Date: 18.06.2007 22:52:45
Total Time: 68 Min 7 Sec
Detected security risks

Cookie: BS.Serving-Sys Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\dokumente und einstellungen\isi\cookies\isi@bs.serving-sys[1].txt
c:\dokumente und einstellungen\isi\cookies\isi@serving-sys[1].txt


Cookie: Overture.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\dokumente und einstellungen\isi\cookies\isi@overture[1].txt


Cookie: QuestionMarket.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\dokumente und einstellungen\isi\cookies\isi@questionmarket[1].txt


Cookie: RealMedia.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\dokumente und einstellungen\isi\cookies\isi@realmedia[1].txt


Cookie: Weborama Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\dokumente und einstellungen\isi\cookies\isi@weborama[2].txt


CoolOnlineOffers.ScreenSaver Adware Bundler more information...
Details: CoolOnlineOffers.ScreenSaver is a program which delivers advertisiment on you computer depending on your surfing behaviour.
Status: Ignored

Files detected
C:\WINDOWS\DiamondView Demo dir\EXPIRE.SCF


MailSkinner Potentially Unwanted Program more information...
Status: Ignored

Registry entries detected
HKEY_USERS\S-1-5-21-2255018123-993939828-2508340356-1006\SOFTWARE\EPK_EXTR

nochdigger 18.06.2007 22:49

Moin

ich hatte vergessen zu schreiben das immer - Remove - bei jedem Fund gewählt werden sollte, damit du das Zeug loswirst.

Zitat:

Hatte aber schon noch Probleme mit popups
Welcher Art Popups?

MFG

fava 19.06.2007 21:20

Hey :)

Habe heute nochmals gescannt und wieder nur cookies gefunden - hier der bericht:

Scan History Details
Start Date: 19.06.2007 20:45:14
End Date: 19.06.2007 21:51:18
Total Time: 66 Min 4 Sec
Detected security risks

Cookie: RealMedia.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count unique visitors to web pages; and to allow web surfers to use virtual "shopping carts." Online advertising networks use cookies to track users across web sites and to measure ad impressions and click-throughs.
Status: Deleted

Cookies detected
c:\dokumente und einstellungen\isi\cookies\isi@realmedia[2].txt


CoolOnlineOffers.ScreenSaver Adware Bundler more information...
Details: CoolOnlineOffers.ScreenSaver is a program which delivers advertisiment on you computer depending on your surfing behaviour.
Status: Deleted

Files detected
C:\WINDOWS\DiamondView Demo dir\EXPIRE.SCF


MailSkinner Potentially Unwanted Program more information...
Status: Deleted

Registry entries detected
HKEY_USERS\S-1-5-21-2255018123-993939828-2508340356-1006\SOFTWARE\EPK_EXTR

------------------------------------------------

Habe auch die Sachen, die in Quarantäne waren, nun gelöscht.
Hmm, waren weiterhin werbepopups, bzw. auch sex seiten - bzw. so partnerkontaktseiten eher...
ich werde nun mal sehen wie es sich entwickelt :)
werde morgen nochmals scannen...
Danke sehr für alles!
Fava

nochdigger 19.06.2007 21:49

Moin

mir sind leider grad die Ideen aus:( sorry, aber ich habe in deinen Logs auch nix mehr gefunden.
Oder doch schau mal unter Start -> Einstellungen -> Systemsteuerung -> Software ob es eine Software "Mediapipe" o.ä. dort gibt diese könnte für die Popups verantwortlich sein wenn vorhanden bitte deinstallieren.

MFG


Alle Zeitangaben in WEZ +1. Es ist jetzt 17:11 Uhr.

Copyright ©2000-2024, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130