![]() |
... und du schreibst, während eScan läuft, von einem anderen Rechner, oder? |
Zitat:
ich schreib vom rechner und an dem hängt(patch weg.i-net) das notebook um welches es hier geht! |
so scan ist fertig : virus logfile info hier reinstellen??? hat 188 viren gefunden |
Nicht das gesamte Log, sondern die infected-Einträge (s.o.). |
laut beschreibung für escan auf der http://www.trojaner-board.de/42731-escan-anleitung.html seite muß ich nun manuell im abgesicherten modus die dateien löschen... na bravo.... ???? |
Hallo MountainKing Zitat:
Zitat:
in deinem Log sind viele Sachen, die mir gar nicht gefallen, z.B. Zitat:
Zitat:
Und noch dazu Zitat:
Bitte verliere keine Zeit, du bekommst dein PC nicht sauber. Folge den Anweisungen: http://www.trojaner-board.com/showthread.php?t=12154 Und lese vor dem Einschlafen: http://faq.underflow.de/ |
Zitat:
danke nachtlektüre hab ich genug von meinem chef! ;) ich hab @mountainMaster vom Escan ein virus log file! poste ich das da? und stimmt es das ich das alles im abgesicherten modus manuell löschen muß? (diese frage ist noch offen) danke ! _p_ |
@ Rene-gad Naja, ich würde schon vorher gern noch wissen, was genau auf dem Rechner ist. Es ist sicher Schrott drauf, aber Hijacker und Adware würde ich noch nicht als Grund für eine Neuinstallation ansehen. Schaden würde es sicher nichts, wenn Princessa alles neu macht und danach auf der Basis einen sauberen Rechners einie Dinge grundlegend ändert, aber ich würde, wie gesagt, schon gern noch wissen, was E-Scan so entdeckt hat. @ princessa Steht doch eigentlich alles schon da, suche die mwav.log und kopiere daraus die "infected"-Einträge. |
Hallo prinzessa, ich meine jetzt schon ganz ernst: du musst deinen PC neu aufsetzen. Es gibt keinen Grund für Diskussion, denn deine Kiste ist mit Malware verseucht und ist nicht ungefährlich für alle Internet-User. PS:Lasse bitte meine Message für MoutainKing für ihn persönlich zu beantworten. ;). |
@masterMountain ich stell da nun einfach mal rein ...virus log informaton von ESCAN (sollten einige über meine blödheit diesbezüglich lachen wollen..nur zu aber nix diesbezüglich posten, der thread ist eh schon zulang! ) File C:\WINDOWS\SYSTEM\WJ2IT.EXE infected by "Trojan-Downloader.Win32.Apropo.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\WJ2IT.EXE infected by "Trojan-Downloader.Win32.Apropo.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\WEBLGN32.EXE infected by "Trojan-Downloader.Win32.Agent.hc" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\WEBLGN32.EXE infected by "Trojan-Downloader.Win32.Agent.hc" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\WJ2IT.EXE infected by "Trojan-Downloader.Win32.Apropo.d" Virus. Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\WEBLGN32.EXE infected by "Trojan-Downloader.Win32.Agent.hc" Virus. Action Taken: No Action Taken. File C:\WINDOWS\n20050308.exe infected by "not-a-virus:AdWare.EZula.ah" Virus. Action Taken: No Action Taken. File C:\WINDOWS\woinstall.exe infected by "not-a-virus:AdWare.EZula.ak" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\vmstmp\vmstmp.exe infected by "not-a-virus:AdWare.DelphinMediaViewer.c" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\PVCAMDAT.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\SLFTPUB.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\DKDMOPRP.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\SGLSTR.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\OVSLB400.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\SBGR.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\DDSERIAL.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\OXETHK32.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\OJEACCRC.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\WSLP16T.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\DIEML.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\IFETCPLC.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\DNGSIG.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\DLMV2CLT.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\BNOWSELC.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\RRCLTCCM.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\QPDWIPES.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MPR2C.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\NVDLL.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MKOEACCT.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\CXWMDM.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\DAUSIC.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\IVMFIL~1.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\IHM32.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\NFTUR.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\LKEXPAND.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MNDXMLC.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MMJET40.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\WKBCHECK.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\CKMCAT.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\BOOWSELC.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\LWRT.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\LANKINFO.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. TEIL I % |
% TEIL II File C:\_RESTORE\TEMP\MLWMDM.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\IKSCONFG.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\CVYPTUI.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\PNWRPROF.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\RGCLTC3.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\CBRVIDDC.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\SOLWOA.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MTPMSP.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\WGDMPS.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\ID50_32.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MWTIME.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\ITITPKI.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\GFI32.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\JPSD400.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\NKTUR.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\TGUMBVW.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\PJFMGR.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\LUNKINFO.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\IAAGING.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\WQADEFUI.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\WUICORE.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\SLDOCLC.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MLVBVM50.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\OGBCJT32.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\PXUSTAB.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\CRMMDLG.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\RSCLTSCM.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MFIQTZ32.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\RDCLTS3.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\SATUPX32.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\ALVAPI32.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\OVE2DISP.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\RAAUI.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\DCMM.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MKHTMLER.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\USDM32.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\UDP10.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\WEDMPS.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\IXMFIL~1.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\CSBVIEW.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\DFMSSHRN.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\BISEBALL.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MMPBDE40.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MWLTUS40.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MVRD3X40.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\NPTAPI.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\NJDLL.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\JPT.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\RKISEN.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\GEU32.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MXIDENT.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\WGN32S16.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\INANIU.0 infected by "Trojan-Downloader.Win32.Qoologic.f" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\CYGWIZ.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\_RESTORE\TEMP\MPVCRT40.0 infected by "not-a-virus:AdWare.Look2Me.r" Virus. Action Taken: No Action Taken. File C:\WINDOWS\TEMP\vmstmp\vmstmp.exe infected by "not-a-virus:AdWare.DelphinMediaViewer.c" Virus. Action Taken: No Action Taken. File C:\WINDOWS\n20050308.exe infected by "not-a-virus:AdWare.EZula.ah" Virus. Action Taken: No Action Taken. File C:\WINDOWS\woinstall.exe infected by "not-a-virus:AdWare.EZula.ak" Virus. Action Taken: No Action Taken. File C:\Programme\AdDestroyer\AdDestroyer.exe infected by "not-a-virus:AdWare.VirtualBouncer.g" Virus. Action Taken: No Action Taken. File C:\downloads\Install(2-lke-0-0-,lke-3).exe infected by "Trojan-Clicker.Win32.Agent.as" Virus. Action Taken: No Action Taken. File C:\RECYCLED\Dc18.IE5\AD2LS1SD\track[1].htm infected by "Exploit.HTML.Mht" Virus. Action Taken: No Action Taken. File C:\RECYCLED\Dc18.IE5\AD2LS1SD\eZinstall[1].exe infected by "not-a-virus:AdWare.EZula.ak" Virus. Action Taken: No Action Taken. File C:\RECYCLED\Dc18.IE5\8N4FO1UN\woinstall[1].exe infected by "not-a-virus:AdWare.EZula.ak" Virus. Action Taken: No Action Taken. File C:\RECYCLED\Dc30\ph.exe infected by "Trojan-Downloader.Win32.Agent.hc" Virus. Action Taken: No Action Taken. File C:\RECYCLED\Dc30\pm.exe infected by "Trojan-Downloader.Win32.Apropo.d" Virus. Action Taken: No Action Taken. File C:\RECYCLED\Dc41\mmod.exe infected by "not-a-virus:AdWare.EZula.z" Virus. Action Taken: No Action Taken. File C:\RECYCLED\Dc41\eabh.dll infected by "not-a-virus:AdWare.EZula.x" Virus. Action Taken: No Action Taken. |
@MountainKing Zitat:
Du weisst nicht genau, was das ist, gehst aber aus dem Best Case aus! Und wo genau liegt die Grenze zwischen 'nem Hijacker und 'nem Trojaner? |
@MountainKing Zitat:
|
Tja nun, die Downloader sind für mich immer so ein etwas schwieriger Fall, einige laden ja "nur" Adware, es sind keine Trojaner im eigentlichen Sinne, mit Backdoor-Funktionen, das Zitat passt also nicht direkt, da es keinen "Attacker" gibt, zumindest keinen nachweisbaren. Strenggenommen hast du sicher Recht, Hinweise auf Schädlinge, die anderen gefährlich werden, gibts aber eigentlich keine, andererseits ist ja das, was sie herunterladen, manipulierbar. Die Grenze zwischen Hijacker im Sinne von geänderten Startseiten und Trojaner besteht IMO darin, dass letzere direkten Zugriff auf das System ermöglichen, Hiijacker oder Adaware ist zwar ärgerlich, aber nicht genauso gefährlich. Ich gehe auch nicht vom Best Case aus, wenn ich feststellen möchte, um welche Prozesse es sich handelt. Ziehst du die Grenze tatsächlich so eng, dass ein Startseitenhijacker bereits eine Neuinstallation nach sich zieht? @ princessa Dir wird das im Moment sicher wenig helfen, prinzipiell wäre es sicher eine gute Idee, wenn du dein System neu installieren würdest. Hast du das schon gemacht bzw. jemand an der Hand, der dir dabei helfen könnte? |
hallo @MK also im moment hab ich niemanden der mir bei der neuinstall des sys helfen könnte. bin auch ab do wieder eine woche berufl. weg... aber abgesehn von euren hin und her... gäbe es akut noch eine möglichkeit was zu tun???? pls um info! danke und lg an alle! _p_ |
Alle Zeitangaben in WEZ +1. Es ist jetzt 11:22 Uhr. |
Copyright ©2000-2025, Trojaner-Board