vmlib.exe <---Troj/LowZoneThema ist geschlossen! |
||
---|---|---|
Thema ist geschlossen! |
||
#0
| ||
21.01.2006, 16:21
Ehrenmitglied
Beiträge: 29434 |
||
|
||
21.01.2006, 21:59
...neu hier
Beiträge: 7 |
#17
Hallo!
Nummer1: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD><TITLE>Virus Scan Report File</TITLE> <META http-equiv=Content-Type content="text/html; charset=windows-1252"> <META content="MSHTML 6.00.2900.2802" name=GENERATOR></HEAD> <BODY bgColor=#ffffff> <H1 align=center>Virus Scan Report File</H1> <H2 align=center> <HR> Virus Scan Information <HR> </H2><PRE>McAfee VirusScan for Win32 v4.40.0 Copyright (c) 1992-2004 Networks Associates Technology Inc. All rights reserved. (408) 988-3832 LICENSED COPY - Sep 23 2004 Scan engine v4.4.00 for Win32. Virus data file v4679 created Jan 20 2006 Scanning for 172110 viruses, trojans and variants. </PRE> <H2 align=center> <HR> Virus Scan Results <HR> </H2><PRE> 01/21/2006 17:25:52 Options: "C:\WINDOWS.0\SYSTEM32" /UNZIP /WINMEM /SUB /ANALYZE /PANALYZE /STREAMS /CLEAN /ALL /DEL /MIME /PROGRAM /EXCLUDE C:\AV-CLS\EXCLIST.TXT /HTML "C:\AV-CLS\MCAFEE\SCANREPORT.HTML" Scanning C: [] Scanning C:\WINDOWS.0\SYSTEM32\*.* C:\WINDOWS.0\SYSTEM32\drivers\kl1.sys ... Found trojan or variant New Malware.z !!! Please send a copy of the file to McAfee The file or process has been deleted. C:\WINDOWS.0\SYSTEM32\drivers\klick.sys ... Found trojan or variant New Malware.z !!! Please send a copy of the file to McAfee The file or process has been deleted. Summary report on C:\WINDOWS.0\SYSTEM32\*.* File(s) Total files: ........... 6896 Clean: ................. 6884 Possibly Infected: ..... 2 Cleaned: ............... 0 Deleted: ............... 2 Non-critical Error(s): 1 Time: 00:09.41 </PRE> <HR> <CENTER>Visit the <A href="http://www.mcafee.com/">McAfee Online</A> Web Site<BR>Need some help or advice? Send <A href="mailto:techsupport@mcafee.com">email</A> to Technical Support.</CENTER></BODY></HTML> Nummer 2: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD><TITLE>Virus Scan Report File</TITLE> <META http-equiv=Content-Type content="text/html; charset=windows-1252"> <META content="MSHTML 6.00.2900.2802" name=GENERATOR></HEAD> <BODY bgColor=#ffffff> <H1 align=center>Virus Scan Report File</H1> <H2 align=center> <HR> Virus Scan Information <HR> </H2><PRE>McAfee VirusScan for Win32 v4.40.0 Copyright (c) 1992-2004 Networks Associates Technology Inc. All rights reserved. (408) 988-3832 LICENSED COPY - Sep 23 2004 Scan engine v4.4.00 for Win32. Virus data file v4679 created Jan 20 2006 Scanning for 172110 viruses, trojans and variants. </PRE> <H2 align=center> <HR> Virus Scan Results <HR> </H2><PRE> 01/21/2006 17:46:07 Options: "C:\WINDOWS.0" /UNZIP /WINMEM /SUB /ANALYZE /PANALYZE /STREAMS /CLEAN /ALL /DEL /MIME /PROGRAM /EXCLUDE C:\AV-CLS\EXCLIST.TXT /HTML "C:\AV-CLS\MCAFEE\SCANREPORT.HTML" Scanning C: [] Scanning C:\WINDOWS.0\*.* Summary report on C:\WINDOWS.0\*.* File(s) Total files: ........... 36094 Clean: ................. 35982 Possibly Infected: ..... 0 Cleaned: ............... 0 Non-critical Error(s): 1 Time: 00:29.48 </PRE> <HR> <CENTER>Visit the <A href="http://www.mcafee.com/">McAfee Online</A> Web Site<BR>Need some help or advice? Send <A href="mailto:techsupport@mcafee.com">email</A> to Technical Support.</CENTER></BODY></HTML> Nummer 3: <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML><HEAD><TITLE>Virus Scan Report File</TITLE> <META http-equiv=Content-Type content="text/html; charset=windows-1252"> <META content="MSHTML 6.00.2900.2802" name=GENERATOR></HEAD> <BODY bgColor=#ffffff> <H1 align=center>Virus Scan Report File</H1> <H2 align=center> <HR> Virus Scan Information <HR> </H2><PRE>McAfee VirusScan for Win32 v4.40.0 Copyright (c) 1992-2004 Networks Associates Technology Inc. All rights reserved. (408) 988-3832 LICENSED COPY - Sep 23 2004 Scan engine v4.4.00 for Win32. Virus data file v4679 created Jan 20 2006 Scanning for 172110 viruses, trojans and variants. </PRE> <H2 align=center> <HR> Virus Scan Results <HR> </H2><PRE> 01/21/2006 18:31:23 Options: "C:\" /UNZIP /WINMEM /SUB /ANALYZE /PANALYZE /STREAMS /CLEAN /ALL /DEL /MIME /PROGRAM /EXCLUDE C:\AV-CLS\EXCLIST.TXT /HTML "C:\AV-CLS\MCAFEE\SCANREPORT.HTML" Scanning C: [] Scanning C:\*.* C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Steganos AntiVirus 2006\8.5\Bases\klick.kdz\KLICK2K.SYS ... Found trojan or variant New Malware.z !!! Please send a copy of the file to McAfee C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Steganos AntiVirus 2006\8.5\Bases\klick.kdz\KLICKNT.SYS ... Found trojan or variant New Malware.z !!! Please send a copy of the file to McAfee C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\EA GAMES\Medal of Honor Allied Assault\MOHAA online mit dem GameSpy spielen.url ... Found potentially unwanted program Adware-Url.gen. The file or process has been deleted. C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Fishtank Interactive\Play S.W.I.N.E. Online Free on Gamespy Arcade.url ... Found potentially unwanted program Adware-Url.gen. The file or process has been deleted. C:\Dokumente und Einstellungen\René Kühr\Startmenü\Programme\JoWooD\IndustrieGigant 2\Spiele IndustrieGigant 2 Online mit GameSpy Arcade.url ... Found potentially unwanted program Adware-Url.gen. The file or process has been deleted. Summary report on C:\*.* File(s) Total files: ........... 265758 Clean: ................. 264097 Possibly Infected: ..... 2 Cleaned: ............... 0 Deleted: ............... 3 Non-critical Error(s): 3 Time: 02:59.34 </PRE> <HR> <CENTER>Visit the <A href="http://www.mcafee.com/">McAfee Online</A> Web Site<BR>Need some help or advice? Send <A href="mailto:techsupport@mcafee.com">email</A> to Technical Support.</CENTER></BODY></HTML> Mfg Rene1976 |
|
|
||
21.01.2006, 22:29
Ehrenmitglied
Beiträge: 29434 |
#18
scanne mit kaspersky und poste den scanreport
http://virus-protect.org/onlinescan.html leider sind deine Spiele-url geloescht worden (Medal of Honor Allied Assault\MOHAA online u.a.) es kann sein, dass du dich neu anmelden musst) __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
22.01.2006, 18:37
...neu hier
Beiträge: 7 |
#19
-------------------------------------------------------------------------------
KASPERSKY ON-LINE SCANNER REPORT Sunday, January 22, 2006 18:34:29 Operating System: Microsoft Windows XP Home Edition, Service Pack 2 (Build 2600) Kaspersky On-line Scanner version: 5.0.67.0 Kaspersky Anti-Virus database last update: 22/01/2006 Kaspersky Anti-Virus database records: 161932 ------------------------------------------------------------------------------- Scan Settings: Scan using the following antivirus database: standard Scan Archives: true Scan Mail Bases: true Scan Target - My Computer: A:\ C:\ Kaspersky-Scan: D:\ E:\ F:\ Scan Statistics: Total number of scanned objects: 162128 Number of viruses found: 0 Number of infected objects: 0 Number of suspicious objects: 0 Duration of the scan process: 9518 sec No malware has been detected. The sections that have been scanned are CLEAN. Scan process completed. ------------------ Mfg Rene1976 |
|
|
||
22.01.2006, 20:31
Ehrenmitglied
Beiträge: 29434 |
#20
Rene1976
na also Es ist wieder alles in schoenster Ordnung. Alles Gute fuer dich + PC . __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
23.01.2006, 01:30
...neu hier
Beiträge: 7 |
#21
Hallo Sabina!
Ich bedanke mich viele mals für Deine Mühe und Deine Zeit! Wünsche Dir ebenfalls alles gute und noch einen schönen Abend! Mfg Rene1976 |
|
|
||
gehe in die Registry
Start-->Ausfuehren--> regedit
HKEY_CURRENT_USER\Control Panel\Desktop\
"Wallpaper" = "C:\WINDOWS.0\System32\wp.bmp <--loschen
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\
"NoActiveDesktopChanges"=dword:00000001 -> in 0 aendern
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
NoDispAppearancePage =dword:00000001 -> in 0 aendern
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\System
NoDispBackgroundPage =dword:00000001 -> in 0 aendern
KILLBOX - Pocket KillBox
http://virus-protect.org/killbox.html
Options: Delete on Reboot --> anhaken
reinkopieren:
...
und klicke auf das rote Kreuz, wenn gefragt wird, ob "Do you want to reboot? "---- klicke auf "no",und kopiere das nächste rein, erst beim letzten auf "yes"
C:\WINDOWS.0\system32\intercept.dll
C:\WINDOWS.0\system32\zlbw.dll
C:\WINDOWS.0\system32\wp.bmp
C:\WINDOWS.0\system32\done1
C:\WINDOWS.0\intercept.dll
PC neustarten
multiavtool
http://virus-protect.org/multiavtool.html
klicke "1" nun beginnt der Scan von Sophos
--------------------------------------------
klicke "3" - McAfee -- es erscheint ein leeres DOS-Fenster.
- man muss eingeben, was gescannt werden soll
- C:\Windows\System32 dann beginnt der Scan, man sollte dann auch scannen lassen:
- C:\Windows
- C:\
----------------------------------------------
klicke "6 --> der PC wird neustarten --> suche die 3 Scanreporte in C:\AV-CLS und kopiere sie hier.
__________
MfG Sabina
rund um die PC-Sicherheit