antivir kann 9 probleme (dldr.mediket..., agobot.afk.12, etc.) nicht löschenThema ist geschlossen! |
||
---|---|---|
Thema ist geschlossen! |
||
#0
| ||
09.11.2005, 20:28
Ehrenmitglied
Beiträge: 29434 |
||
|
||
09.11.2005, 20:44
Member
Themenstarter Beiträge: 41 |
#17
außer dem löschen von scchost.exe habe ich alles erledigt. die scchost.exe habe ich weder selbst, noch mit suchfunktion gefunden.
was ist eine .pf datei? :-) |
|
|
||
09.11.2005, 21:33
Ehrenmitglied
Beiträge: 29434 |
#18
das duerfte der %windir%\prefetch sein...kannst du alles loeschen in diesem Ordner, nur nicht die hauptdatei (weiss in der Eile nicht den Namen)
so, nun der Winfixer: poste das Log (nur von Option 1) http://virus-protect.org/l2mfix.html __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
09.11.2005, 22:20
Member
Themenstarter Beiträge: 41 |
#19
wenn ich versuche die l2mfix.bat zu starten öffnet sich zwar ein dos fenster, aber bevor ich dazu komme etwas zu lesen bzw. eine 1 zu drücken verschwindet es wieder.
habe es jetzt schon 2 mal installiert, aber das problem bleibt bestehen... :-) |
|
|
||
09.11.2005, 22:42
Ehrenmitglied
Beiträge: 29434 |
#20
Dll.Compare
http://virus-protect.org/artikel/tools/dll.html poste das Log vom Scan __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
09.11.2005, 22:51
Member
Themenstarter Beiträge: 41 |
#21
* DLLCompare Log version(1.0.0.127)
Files Found that Windows does not See or cannot Access *Not everything listed here means you are infected! ________________________________________________ C:\WINDOWS\SYSTEM32\prflbm ________________________________________________ Administrator Account = True --------------------End log--------------------- |
|
|
||
09.11.2005, 22:51
Ehrenmitglied
Beiträge: 29434 |
#22
Zitat 08.11.2005 08:12 6.784 npqss.bak2rechtsklick auf den Link--> Ziel speichern unter-->waehle Desktop--> dann erscheint eine vundo.reg auf dem Desktop http://virus-protect.org/reg/vundo.reg VundoFix.exe http://www.atribune.org/downloads/VundoFix.exe reinkopieren C:\WINDOWS\System32\ssqpn.dll # Enter -> F6 --> Enter # dann wird erscheinen: Please type in the second filepath as instructed by the forum staff Then Press Enter, Then F6, Then Enter Again to continue with the fix. # Enter --> dann die F6 Taste --> Enter reinkopieren: C:\WINDOWS\System32\npqss.* # Enter --> F6 --> Enter # HijackThis wird sich oeffnen # In HijackThis --> Haekchen setzen vor diese Eintraege --> FIX CHECKED: O2 - BHO: (no name) - {00DBDAC8-4691-4797-8E6A-7C6AB89BC441} - C:\WINDOWS\system32\ssttq.dll O2 - BHO: MSEvents Object - {79A576C4-B7A9-47EC-B57C-2CE5CA6ECC6A} - C:\WINDOWS\System32\ssqpn.dll O20 - Winlogon Notify: ssqpn - C:\WINDOWS\System32\ssqpn.dll O20 - Winlogon Notify: ssttq - C:\WINDOWS\SYSTEM32\ssttq.dll # schliesse Hijackthis, druecke irgendeine Taste und der PC wird neustarten # es wird einen"Blue Screen of Death" geben, das ist normal Computer in den abgesicherten Modus neustarten (F8 beim Starten drücken). Die Datei "vundo.reg" auf dem Desktop doppelklicken und bestaetigen, dass sie der Registry beigefuegt wird loesche: C:\WINDOWS\SYSTEM32\ssttq.dll ------------------------------------------------------ cleanup http://virus-protect.org/cleanup.html dann poste das neue Log vom HijackThis __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
09.11.2005, 23:07
Member
Themenstarter Beiträge: 41 |
#23
nachdem ich vundofix installiert habe und die sspqn.dll in das verzeichnis kopiert habe kommt beim öffnen der killvundo.bat und der process.exe jeweils nur kurz ein dos-fenster und ich habe keine möglichkeit F6 oder enter zu drücken. was habe ich falsch gemacht?
mfg |
|
|
||
09.11.2005, 23:08
Ehrenmitglied
Beiträge: 29434 |
#24
Zitat C:\WINDOWS\SYSTEM32\prflbmkannst du den kompletten Namen + dll sehen ???? prflbm~1.dll __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
09.11.2005, 23:13
Ehrenmitglied
Beiträge: 29434 |
#25
oeffne das HijackThis
Öffne HijackThis --> Config --> Misc. Tools --> Open process manager beende diesen Prozess: C:\WINDOWS\system32\cmd.exe dann versuche es noch mal, eventuell muss du den PC neustarten oder versuche es im abgesicherten Modus __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
09.11.2005, 23:14
Member
Themenstarter Beiträge: 41 |
||
|
||
09.11.2005, 23:18
Ehrenmitglied
Beiträge: 29434 |
#27
loesche prflbmsg.dll
wenn vundofix geklappt hat zusammen mit der ssttq.dll __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
10.11.2005, 00:17
Member
Themenstarter Beiträge: 41 |
#28
ich habe es sowohl abgesichert, als auch normal versucht - vundofix hat scheinbar geklappt, danach habe ich mit hijackthis gefixt und neu gestartet. aber die ssttq.dll wird permanent verwendet und läßt sich nicht löschen.
und im normalmodus gehen immernoch alle fenster direkt nach dem öffnen wieder zu... :-/ |
|
|
||
10.11.2005, 00:46
Ehrenmitglied
Beiträge: 29434 |
#29
dann loesche die zwei dll mit der Killbox
C:\WINDOWS\system32\ssttq.dll C:\WINDOWS\system32\prflbmsg.dll versuche auch mal mit der Killbox, ob es das hier gibt: C:\WINDOWS\system32\cmd.ftp wenn ja...loeschen installiere (scanne im abgesicherten Modus)-->poste die scanreporte http://virus-protect.org/multiavtool.html und mache auch gleich noch mal einen scan mit Antivirus im abgesicherten modus und berichte -------------- wahrscheinlich morgen Onlinescan mit Kaspersky und panda http://virus-protect.org/onlinescan.html __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
10.11.2005, 13:38
Member
Themenstarter Beiträge: 41 |
#30
guten tag,
die ssttq.dll läßt sich überhaupt nicht löschen (im abges. mod., mit hijack, mit killbox) - sie wird permanent benutzt und kann nicht verschoben oder gelöscht werden. eine cmd.ftp habe ich nicht gefunden, nur eine cmd.exe. scannen habe ich versucht, hat nicht mit allen programmen funktioniert, hier die logs: þ AVPDOS32 Start 10-11-2005 12:29:23 Version 3.0 build 135 Last update: 10.11.2005, 159156 records. Command line: None Profile defdos32.prf (from 27.06.2001 03:00:00) Scan process completed. Result for all objects: Sector Objects : 0 Known viruses : 0 Files : 1 Virus bodies : 0 Folders : 0 Disinfected : 0 Archives : 0 Deleted : 0 Packed : 0 Warnings : 0 Suspicious : 0 Scan speed (Kb/sec) : 62 Corrupted : 0 Scan time : 00:00:04 I/O Errors : 0 sophos: Error initialising detection engine [0xa0040223] /--------------------------------------------------------------\ | Trend Micro Sysclean Package | | Copyright 2002, Trend Micro, Inc. | | http://www.trendmicro.com | \--------------------------------------------------------------/ 2005-11-10, 12:04:28, Auto-clean mode specified. 2005-11-10, 12:04:28, Running scanner "c:\AV-CLS\Trend\TSC.BIN"... 2005-11-10, 12:08:11, Scanner "c:\AV-CLS\Trend\TSC.BIN" has finished running. 2005-11-10, 12:08:11, TSC Log: Damage Cleanup Engine (DCE) 3.9(Build 1020) Windows XP(Build 2600: Service Pack 1) Start time : Do Nov 10 2005 12:04:29 Load Damage Cleanup Template (DCT) "c:\AV-CLS\Trend\tsc.ptn" (version 674) [success] Complete time : Do Nov 10 2005 12:08:11 Execute pattern count(4515), Virus found count(0), Virus clean count(0), Clean failed count(0) 2005-11-10, 12:08:30, An error occurred while scanning file "C:\Dokumente und Einstellungen\Administrator\ntuser.dat": Zugriff verweigert 2005-11-10, 12:08:30, An error occurred while scanning file "C:\Dokumente und Einstellungen\Administrator\NTUSER.DAT.LOG": Zugriff verweigert 2005-11-10, 12:08:57, An error occurred while scanning file "C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat": Zugriff verweigert 2005-11-10, 12:08:57, An error occurred while scanning file "C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\Microsoft\Windows\UsrClass.dat.LOG": Zugriff verweigert 2005-11-10, 12:14:17, An error was detected on "C:\System Volume Information\*.*": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\ACRORD32.EXE-0BE2C5CE.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\ACRORD32.EXE-1A1A65B9.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\ADI4.EXE-2D5A9ED9.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\ADSSPY.EXE-08F98EE8.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\ANTIVIR_WORKSTATION_WIN_DE_H.-21BF25F1.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\ASD.EXE-27B85FF2.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\AUPDATE.EXE-089630E1.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\AUTORUN.EXE-321338FA.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\AV32.PIF-242AD5BE.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\AVGNT.EXE-11DE492C.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\AVNOTIFY.EXE-0488930C.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\AVWIN.EXE-1CCB3880.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\AVWUPSRV.EXE-16AD196E.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\BLING.EXE-2027B591.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\CCLEANER.EXE-03CA012D.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\CHICKENINVADERS.EXE-3498BBDD.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\CLIENT.EXE-2E76FCAD.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\CLIENT1.EXE-30FE591A.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\CMD.EXE-087B4001.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\CTFMON.EXE-0E17969B.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\CTSVCCDA.EXE-39508B82.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\DEFRAG.EXE-273F131E.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\DFRGNTFS.EXE-269967DF.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\DRWTSN32.EXE-2B4B52AC.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\ERASEME_23578.EXE-1E4CBF2E.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\ERASEME_35731.EXE-30660691.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\ERASEME_53267.EXE-184E1D8D.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\EXPL0RER.PIF-0BF97225.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\EXPLORER.EXE-082F38A9.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\FTP.EXE-0FFFB5A3.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\GHA.EXE-0B745C50.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\HELPCTR.EXE-3862B6F5.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\HELPSVC.EXE-2878DDA2.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-2F696A0F.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-3184503A.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-31F32B76.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\HIJACKTHIS.EXE-340E11A1.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\HYPERBOWL.EXE-19ABFB58.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\IEXPLORE.EXE-2CA9778D.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\IEXPLORER.EXE-1D8CB1E8.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\IEXPLORER.EXE-281149FB.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\IMAPI.EXE-0BF740A4.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\INETUPD.EXE-118424B4.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\IPCONFG32.EXE-11C6D6C8.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\IPCONFG32.EXE-31659947.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\JRDPLFSECY.EXE-30340FDB.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\KILLBOX.EXE-06114DCA.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\KILLBOX.EXE-0DEBC32F.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\KILLBOX.EXE-3A1A72C4.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\Layout.ini": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\LOGONUI.EXE-0AF22957.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\.EXE-2E1D7CB2.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\LUCOMS~1.EXE-02DB5950.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\LXBBAIOX.EXE-25CFBF6A.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\LXBBJSWX.EXE-127DBEB2.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\LXBBPSWX.EXE-20474BBA.pf": Zugriff verweigert 2005-11-10, 12:15:50, Could not set file for reading on "C:\WINDOWS\Prefetch\MDM.EXE-27F66238.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MMDIAG.EXE-34585558.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MMJB.EXE-3AE024CF.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MMJBLAUNCH.EXE-2F923EB2.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MMUPDATEMGR.EXE-00193038.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MM_DIRECTOR.EXE-2531EF72.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MM_TDM~1.EXE-1A5D2F35.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MORDILLO-JUNGLE-FEVER-XS.EXE-2DAC247F.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MSIMN.EXE-0B61806C.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MSMEDIA.EXE-1DF7AF22.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\MSN32.EXE-09674AD0.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\NDETECT.EXE-38C3701D.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\NERO.EXE-32314E31.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\NOTEPAD.EXE-336351A9.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\NOTIFIER.EXE-05341E0E.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\NSLOOKUP.EXE-160B1221.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\NTOSBOOT-B00DFAAD.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\NTVDM.EXE-1A10A423.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\NVSVC32.EXE-1F9EED18.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\OSA.EXE-0082CBE3.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\PHOTOED.EXE-0635276A.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\REGEDIT.EXE-1B606482.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\REGSVR32.EXE-25EEFE2F.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\REGSVR32.EXE-326C00C4.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RPCMON.EXE-03B3DAAD.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-12E6ED95.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-16620C81.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-19CE4AAE.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-1F29D216.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-25AC6E97.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-26DA8C9B.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-2A30B44A.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-3173C16A.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-37ACD30D.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-3C8BF040.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-3E4BE505.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-42C4EDF2.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-451FC2C0.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-47A42AF0.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNDLL32.EXE-4A603BCB.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUNONCE.EXE-2803F297.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\RUSSSQR.EXE-10FACA06.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SCCHOST.EXE-35577915.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SCCHOSTC.EXE-35398262.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SETPROXY.EXE-0D65258D.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP.EXE-0B2C9AAE.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP.EXE-37C1B37A.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SETUP.EXE-393E66AE.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SPYBOTSD.EXE-1D495A65.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SVCHOST.EXE-16C7D411.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SVCHOST.EXE-3530F672.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SVEN.EXE-3896D1B8.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\SYSHOST32.EXE-1847DDE6.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\TASKMGR.EXE-20256C55.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\TFTP.EXE-2FB50BCA.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\UPLOADM.EXE-3A6595CD.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WDFMGR.EXE-2CF4013B.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WEB1.EXE-38A141EB.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WINCNTRL.EXE-00F4353D.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WINDAT.EXE-211D97EE.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WINHLP32.EXE-2C18E975.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WINMX.EXE-155782C2.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WINWORD.EXE-20846988.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WMIADAP.EXE-2DF425B2.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WMIPRVSE.EXE-28F301A9.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-09969332.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-09969333.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-09969337.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-09969338.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WMPLAYER.EXE-0996933C.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WORDPAD.EXE-1EFCC5C1.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WSCRIPT.EXE-32960AB9.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\WUAUCLT.EXE-399A8E72.pf": Zugriff verweigert 2005-11-10, 12:15:51, Could not set file for reading on "C:\WINDOWS\Prefetch\ZXCCC.EXE-0AF0A63B.pf": Zugriff verweigert 2005-11-10, 12:17:55, An error occurred while scanning file "C:\WINDOWS\system32\config\default": Zugriff verweigert 2005-11-10, 12:17:55, An error occurred while scanning file "C:\WINDOWS\system32\config\default.LOG": Zugriff verweigert 2005-11-10, 12:17:55, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM": Zugriff verweigert 2005-11-10, 12:17:55, An error occurred while scanning file "C:\WINDOWS\system32\config\SAM.LOG": Zugriff verweigert 2005-11-10, 12:17:55, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY": Zugriff verweigert 2005-11-10, 12:17:55, An error occurred while scanning file "C:\WINDOWS\system32\config\SECURITY.LOG": Zugriff verweigert 2005-11-10, 12:17:55, An error occurred while scanning file "C:\WINDOWS\system32\config\software": Zugriff verweigert 2005-11-10, 12:17:55, An error occurred while scanning file "C:\WINDOWS\system32\config\software.LOG": Zugriff verweigert 2005-11-10, 12:17:55, An error occurred while scanning file "C:\WINDOWS\system32\config\system": Zugriff verweigert 2005-11-10, 12:17:55, An error occurred while scanning file "C:\WINDOWS\system32\config\system.LOG": Zugriff verweigert 2005-11-10, 12:19:35, Running scanner "c:\AV-CLS\Trend\VSCANTM.BIN"... 2005-11-10, 12:19:35, Files Detected: Copyright (c) 1990 - 2004 Trend Micro Inc. Report Date : 11/10/2005 12:19:35 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Command Line: c:\AV-CLS\Trend\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=c:\AV-CLS\Trend 2005-11-10, 12:19:35, Files Clean: Copyright (c) 1990 - 2004 Trend Micro Inc. Report Date : 11/10/2005 12:19:35 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Command Line: c:\AV-CLS\Trend\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=c:\AV-CLS\Trend 2005-11-10, 12:19:35, Clean Fail: Copyright (c) 1990 - 2004 Trend Micro Inc. Report Date : 11/10/2005 12:19:35 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Command Line: c:\AV-CLS\Trend\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 C:\*.* /P=c:\AV-CLS\Trend 2005-11-10, 12:19:35, Scanner "c:\AV-CLS\Trend\VSCANTM.BIN" has finished running. 2005-11-10, 12:24:52, An error was detected on "D:\System Volume Information\*.*": Zugriff verweigert 2005-11-10, 12:24:52, Running scanner "c:\AV-CLS\Trend\VSCANTM.BIN"... 2005-11-10, 12:24:55, Files Detected: Copyright (c) 1990 - 2004 Trend Micro Inc. Report Date : 11/10/2005 12:24:55 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Command Line: c:\AV-CLS\Trend\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=c:\AV-CLS\Trend 2005-11-10, 12:24:55, Files Clean: Copyright (c) 1990 - 2004 Trend Micro Inc. Report Date : 11/10/2005 12:24:55 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Command Line: c:\AV-CLS\Trend\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=c:\AV-CLS\Trend 2005-11-10, 12:24:55, Clean Fail: Copyright (c) 1990 - 2004 Trend Micro Inc. Report Date : 11/10/2005 12:24:55 VSAPI Engine Version : 7.510-1002 VSCANTM Version : 1.1-1001 Command Line: c:\AV-CLS\Trend\VSCANTM.BIN /NBPM /S /CLEANALL /LAPPEND /LD /LC /LCF /NM /NB /C /ACTIVEACTION=5 D:\*.* /P=c:\AV-CLS\Trend 2005-11-10, 12:24:55, Scanner "c:\AV-CLS\Trend\VSCANTM.BIN" has finished running. mfg :-) |
|
|
||
O4 - HKLM\..\Run: [Alive SYstem] C:\WINDOWS\System32\scchost.exe
O4 - HKLM\..\Run: [MICROSFT RAMA UPDATE SUPPORT] MSN32.EXE
O4 - HKLM\..\RunServices: [MICROSFT RAMA UPDATE SUPPORT] MSN32.EXE
neustarten
suchen/loeschen
C:\WINDOWS\System32\scchost.exe
C:\WINDOWS\System32\MSN32.EXE
__________
MfG Sabina
rund um die PC-Sicherheit