Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Plagegeister aller Art und deren Bekämpfung (https://www.trojaner-board.de/plagegeister-aller-art-deren-bekaempfung/)
-   -   Windows Security Alert (https://www.trojaner-board.de/80959-windows-security-alert.html)

syxx 29.12.2009 12:21

Windows Security Alert
 
Moin moin,

habe das selbe problem seid heut morgen, ich weiss nicht mal wann ich mir den mist eingefangen habe...
naja schnell angemeldet hier und und und...

hab mir das programm eben auch schnell gezogen und bin deiner anleitung gefolgt.

mir spuckt er das aus:

Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "H8SRTd.sys" found!
ImagePath: \systemroot\system32\drivers\H8SRTfwospyxufj.sys
Driver disabled successfully.

Rootkit scan completed.


Error: file "C:\WINDOWS\system32\sdra64.exe" not found!
Deletion of file "C:\WINDOWS\system32\sdra64.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open file "C:\DOKUME~1\Resi\LOKALE~1\Temp\settdebugx.exe"
Deletion of file "C:\DOKUME~1\Resi\LOKALE~1\Temp\settdebugx.exe" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist

File "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\sysReserve.ini" deleted successfully.

Error: folder "C:\WINDOWS\system32\lowsec" not found!
Deletion of folder "C:\WINDOWS\system32\lowsec" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.

syxx 29.12.2009 12:33

oh ok mach ich wusste ich nich

syxx 29.12.2009 12:37

Windows Security Alert
 
Habe mir wohl irgendwie "Windows Security Alert" und "Malware Defense" (vllt gehörts auch zu dem anderen dazu) eingefangen,

habe Avenger mit dem Script:

files to delete:
C:\WINDOWS\system32\sdra64.exe
C:\DOKUME~1\Resi\LOKALE~1\Temp\settdebugx.exe
C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\sysReserve.ini

folders to delete:
C:\WINDOWS\system32\lowsec


laufen lassen und folgenden text bekommen:


Logfile of The Avenger Version 2.0, (c) by Swandog46
http://swandog46.geekstogo.com

Platform: Windows XP

*******************

Script file opened successfully.
Script file read successfully.

Backups directory opened successfully at C:\Avenger

*******************

Beginning to process script file:

Rootkit scan active.

Hidden driver "H8SRTd.sys" found!
ImagePath: \systemroot\system32\drivers\H8SRTfwospyxufj.sys
Driver disabled successfully.

Rootkit scan completed.


Error: file "C:\WINDOWS\system32\sdra64.exe" not found!
Deletion of file "C:\WINDOWS\system32\sdra64.exe" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Error: could not open file "C:\DOKUME~1\Resi\LOKALE~1\Temp\settdebugx.exe"
Deletion of file "C:\DOKUME~1\Resi\LOKALE~1\Temp\settdebugx.exe" failed!
Status: 0xc000003a (STATUS_OBJECT_PATH_NOT_FOUND)
--> bad path / the parent directory does not exist

File "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\sysReserve.ini" deleted successfully.

Error: folder "C:\WINDOWS\system32\lowsec" not found!
Deletion of folder "C:\WINDOWS\system32\lowsec" failed!
Status: 0xc0000034 (STATUS_OBJECT_NAME_NOT_FOUND)
--> the object does not exist


Completed script processing.

*******************

Finished! Terminate.


wie gehts nun weiter?


Alle Zeitangaben in WEZ +1. Es ist jetzt 03:11 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29