Wie entferne ich den Virus W32/Nsag.B?

Thema ist geschlossen!
Thema ist geschlossen!
#0
28.12.2005, 01:40
Member

Beiträge: 19
#76 eins nach dem anderen ;-)

log3:

C:\Windows\system32: nichts gefunden
C:\WINDOWS:

12/28/2005 01:00:13

Options:
"C:\WINDOWS" /UNZIP /WINMEM /SUB /ANALYZE /PANALYZE /STREAMS /CLEAN /ALL /DEL /PROGRAM /EXCLUDE C:\AV-CLS\EXCLIST.TXT /MIME /HTML "C:\AV-CLS\MCAFEE\SCANREPORT.HTML"

Scanning C: [System]
C:\WINDOWS\KB886185.log:odsgm ... Found the AdClicker-AJ trojan !!!
The file or process has been deleted.
C:\WINDOWS\KB902400.log:zhqtck ... Found the AdClicker-AJ.gen trojan !!!
The file or process has been deleted.
C:\WINDOWS\msgsocm.log:ukfwvj ... Found the AdClicker-AJ trojan !!!
The file or process has been deleted
.
Scanning C:\WINDOWS\*.*

Summary report on C:\WINDOWS\*.*
File(s)
Total files: ........... 33974
Clean: ................. 33959
Possibly Infected: ..... 3
Cleaned: ............... 0
Deleted: ............... 3
Non-critical Error(s): 1


Time: 00:10.27
Seitenanfang Seitenende
28.12.2005, 02:14
Ehrenmitglied
Avatar Sabina

Beiträge: 29434
#77 schau schau, da gab es noch Streams .....

nun der Kaspersky und dann sollten wir langsam zum Ende kommen ;)
__________
MfG Sabina

rund um die PC-Sicherheit
Seitenanfang Seitenende
28.12.2005, 09:04
Member

Beiträge: 19
#78 Der läuft gleich an. erst noch log3 Teil 3 :-)

c:\


12/28/2005 01:44:10


Options:
"C:\" /UNZIP /WINMEM /SUB /ANALYZE /PANALYZE /STREAMS /CLEAN /ALL /DEL /PROGRAM /EXCLUDE C:\AV-CLS\EXCLIST.TXT /MIME /HTML "C:\AV-CLS\MCAFEE\SCANREPORT.HTML"

Scanning C: [System]
Scanning C:\*.*
C:\Dokumente und Einstellungen\Walter\Favoriten\Search the web.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Seven days of free porn.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Ab scissor.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Broadband comparison.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Credit counseling.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Credit report.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Crm software.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Debt credit card.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Escorts.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Fha.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Health insurance.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Help desk software.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Insurance home.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Loan for debt consolidation.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Loan for people with bad credit.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Marketing email.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Mortgage insurance.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Mortgage life insurance.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Nevada corporations.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Online Betting Site.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Online gambling casino.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Online instant loan.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Order phentermine.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Payroll advance.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Personal loans online.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Personal loans with bad credit.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Prescription Drugs Rx Online.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Refinancing my mortgage.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Tahoe vacation rental.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Unsecured bad credit loans.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\Videos.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.
C:\Dokumente und Einstellungen\Walter\Favoriten\Sites about\What is hydrocodone.url ... Found potentially unwanted program Adware-Url.gen.
The file or process has been deleted.

Summary report on C:\*.*
File(s)
Total files: ........... 57305
Clean: ................. 57196
Possibly Infected: ..... 0
Cleaned: ............... 0
Deleted: ............... 32
Non-critical Error(s): 2


Time: 00:12.48



____________________________________________________________


So und nun der KASPERSKY ON-LINE SCANNER REPORT:

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, December 28, 2005 10:39:09
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 28/12/2005
Kaspersky Anti-Virus database records: 157732
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
J:\
Z:\

Scan Statistics:
Total number of scanned objects: 135241
Number of viruses found: 5
Number of infected objects: 42
Number of suspicious objects: 0
Duration of the scan process: 2348 sec

Infected Object Name - Virus Name
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP287\A0030873.exe Infected: Trojan-Downloader.Win32.Small.vu
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP287\A0031110.exe Infected: Trojan.Win32.Small.ev
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031153.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031153.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031158.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031158.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031163.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031163.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031165.dll Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031166.dll Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031171.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031171.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031181.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031181.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031184.dll Infected: Trojan.Win32.Small.ev
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031189.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031189.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031198.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031198.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031207.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031207.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031215.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031215.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031226.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031226.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031248.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP289\A0031248.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP290\A0031251.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP290\A0031251.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP291\A0031266.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP291\A0031266.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP291\A0031273.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP291\A0031273.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP291\A0031306.old Infected: Virus.Win32.Nsag.b
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP291\A0031325.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP291\A0031325.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP291\A0031328.dll Infected: Trojan-Downloader.Win32.Agent.acc
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP291\A0031360.ini:sxsxpu:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP291\A0031361.ini:gostq:$DATA Infected: Trojan-Downloader.Win32.Agent.td
C:\System Volume Information\_restore{0A0549E3-FF04-40E5-BDC5-F4672D6A69E5}\RP291\A0031361.ini:ltwvz:$DATA Infected: Trojan-Downloader.Win32.Agent.acc
F:\Download\hijackthis\backups\backup-20051224-140146-821.dll Infected: Trojan-Downloader.Win32.Agent.acc
F:\Download\hijackthis\backups\backup-20051224-140146-979.dll Infected: Trojan-Downloader.Win32.Agent.acc

Scan process completed.
Dieser Beitrag wurde am 28.12.2005 um 10:39 Uhr von stta editiert.
Seitenanfang Seitenende
28.12.2005, 13:18
Ehrenmitglied
Avatar Sabina

Beiträge: 29434
#79 deaktiviere die Systemwiederherstellung (dann aktiviere sie wieder)
http://virus-protect.org/systemwiederherstellung.html

loesche die backups vom Hijackthis und scanne noch einmal
__________
MfG Sabina

rund um die PC-Sicherheit
Seitenanfang Seitenende
28.12.2005, 14:15
Member

Beiträge: 19
#80 KASPERSKY scan:

Die backups vom Hijackthis lagen noch im Papierkorb ;-)

-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, December 28, 2005 14:15:04
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 28/12/2005
Kaspersky Anti-Virus database records: 157758
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
J:\
Z:\

Scan Statistics:
Total number of scanned objects: 132665
Number of viruses found: 1
Number of infected objects: 2
Number of suspicious objects: 0
Duration of the scan process: 2274 sec

Infected Object Name - Virus Name
F:\RECYCLER\S-1-5-21-1935655697-573735546-682003330-1003\Df10.dll Infected: Trojan-Downloader.Win32.Agent.bc
F:\RECYCLER\S-1-5-21-1935655697-573735546-682003330-1003\Df8.dll Infected: Trojan-Downloader.Win32.Agent.bc

Scan process completed.
Seitenanfang Seitenende
28.12.2005, 14:16
Ehrenmitglied
Avatar Sabina

Beiträge: 29434
#81 stta

leere den papierkorb, dann versuche die Dateien mit der Killbox zu loeschen

F:\RECYCLER\S-1-5-21-1935655697-573735546-682003330-1003\Df10.dll
F:\RECYCLER\S-1-5-21-1935655697-573735546-682003330-1003\Df8.dll

dann sollte wieder alles in Ordnung sein ... uff... einen guten Rutsch ins neue jahr ;)
__________
MfG Sabina

rund um die PC-Sicherheit
Seitenanfang Seitenende
28.12.2005, 15:02
Member

Beiträge: 19
#82 Kaspersky log:


-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Wednesday, December 28, 2005 15:03:38
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 28/12/2005
Kaspersky Anti-Virus database records: 157758
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
J:\
Z:\

Scan Statistics:
Total number of scanned objects: 132681
Number of viruses found: 0
Number of infected objects: 0
Number of suspicious objects: 0
Duration of the scan process: 2280 sec
No malware has been detected. The sections that have been scanned are CLEAN.

Scan process completed.


Ist damit etwa schon alles erledigt? ;)
Dieser Beitrag wurde am 28.12.2005 um 15:05 Uhr von stta editiert.
Seitenanfang Seitenende
28.12.2005, 15:52
...neu hier

Beiträge: 6
#83 So hab den Scan durch geführt.

------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT
Tuesday, December 27, 2005 15:53:13
Operating System: Microsoft Windows XP Professional, Service Pack 2 (Build 2600)
Kaspersky On-line Scanner version: 5.0.67.0
Kaspersky Anti-Virus database last update: 28/12/2005
Kaspersky Anti-Virus database records: 157758
-------------------------------------------------------------------------------

Scan Settings:
Scan using the following antivirus database: standard
Scan Archives: true
Scan Mail Bases: true

Scan Target - My Computer:
A:\
C:\
D:\
E:\
F:\
G:\
H:\
J:\

Scan Statistics:
Total number of scanned objects: 79901
Number of viruses found: 5
Number of infected objects: 19
Number of suspicious objects: 0
Duration of the scan process: 4032 sec

Infected Object Name - Virus Name
C:\!KillBox\ibm00001.exe Infected: Trojan-PSW.Win32.Agent.bu
C:\!KillBox\kl.exe Infected: Trojan-Spy.Win32.Small.dg
C:\!KillBox\scmt16.exe Infected: Trojan-Downloader.Win32.Harnig.ax
C:\System Volume Information\_restore{7B17723E-C26C-4E1F-AFC4-464C411057BE}\RP101\A0040144.dll Infected: Trojan.Win32.Small.ev
C:\System Volume Information\_restore{7B17723E-C26C-4E1F-AFC4-464C411057BE}\RP101\A0040176.exe Infected: Trojan-PSW.Win32.Agent.bu
C:\System Volume Information\_restore{7B17723E-C26C-4E1F-AFC4-464C411057BE}\RP101\A0040177.exe Infected: Trojan-Downloader.Win32.Harnig.ax
C:\System Volume Information\_restore{7B17723E-C26C-4E1F-AFC4-464C411057BE}\RP101\A0040178.exe Infected: Trojan-Spy.Win32.Small.dg
D:\Style xp\114949.exe/WISE0016.BIN Infected: Trojan-Downloader.Win32.Small.bke
D:\Style xp\114949.exe Infected: Trojan-Downloader.Win32.Small.bke
D:\Style xp\115587.exe/WISE0016.BIN Infected: Trojan-Downloader.Win32.Small.bke
D:\Style xp\115587.exe Infected: Trojan-Downloader.Win32.Small.bke
D:\Style xp\115589.exe/WISE0016.BIN Infected: Trojan-Downloader.Win32.Small.bke
D:\Style xp\115589.exe Infected: Trojan-Downloader.Win32.Small.bke
D:\Style xp\118802.exe/WISE0017.BIN Infected: Trojan-Downloader.Win32.Small.bke
D:\Style xp\118802.exe Infected: Trojan-Downloader.Win32.Small.bke
D:\Style xp\122004.exe/WISE0015.BIN Infected: Trojan-Downloader.Win32.Small.bke
D:\Style xp\122004.exe Infected: Trojan-Downloader.Win32.Small.bke
D:\Style xp\123472.exe/WISE0015.BIN Infected: Trojan-Downloader.Win32.Small.bke
D:\Style xp\123472.exe Infected: Trojan-Downloader.Win32.Small.bke

Scan process completed.
Seitenanfang Seitenende
28.12.2005, 16:15
Ehrenmitglied
Avatar Sabina

Beiträge: 29434
#84 Redfire

deaktiviere die Systemwiederherstellung (dann aktiviere sie wieder)
http://virus-protect.org/systemwiederherstellung.html

C:\!KillBox\ibm00001.exe <--loesche
C:\!KillBox\kl.exe <--loesche
C:\!KillBox\scmt16.exe <--loesche

stelle vorher dein normalen Windows-Syle ein, damit es nach dem Loeschen keine Probleme in der Registry gibt


loeschen (am besten gleich alles: D:\Style xp )

D:\Style xp\114949.exe/WISE0016.BIN
D:\Style xp\114949.exe
D:\Style xp\115587.exe
D:\Style xp\115589.exe/WISE0016.BIN
D:\Style xp\115589.exe
D:\Style xp\118802.exe/WISE0017.BIN
D:\Style xp\118802.exe
D:\Style xp\122004.exe/WISE0015.BIN
D:\Style xp\122004.exe
D:\Style xp\123472.exe/WISE0015.BIN
D:\Style xp\123472.exe

dann scanne noch mal mit kaspersky
__________
MfG Sabina

rund um die PC-Sicherheit
Seitenanfang Seitenende
28.12.2005, 16:18
Ehrenmitglied
Avatar Sabina

Beiträge: 29434
#85 stta

Zitat

Ist damit etwa schon alles erledigt?
uff ... reicht es nicht? ;)
Hat wohl Spass gemacht ???? Nun, es ist alles wieder in Ordung
__________
MfG Sabina

rund um die PC-Sicherheit
Seitenanfang Seitenende
28.12.2005, 17:00
...neu hier

Beiträge: 6
#86 Ok hab alles gemacht und nichts mehr gefunden.
THX für alles :-)


MfG Redfire
Seitenanfang Seitenende
28.12.2005, 17:47
Member

Beiträge: 19
#87 Naja kann mir schöneres vorstellen ;)
Trotzdem nochmals vielen vielen Dank für die Hilfe, ansonsten hätte ich das Biest wohl nicht mehr so leicht wegbekommen.

Danke und Dir auch nen guten Rutsch!
Seitenanfang Seitenende
Um auf dieses Thema zu ANTWORTEN
bitte erst » hier kostenlos registrieren!!

Folgende Themen könnten Dich auch interessieren: