TitanShield Antispyware |
||
---|---|---|
#0
| ||
23.06.2006, 15:34
Ehrenmitglied
Beiträge: 29434 |
||
|
||
23.06.2006, 15:36
Ehrenmitglied
Themenstarter Beiträge: 29434 |
#2
1.
Avenger http://virus-protect.org/artikel/tools/avenger.html kopiere rein: Zitat Files to delete:Klicke die gruene Ampel das Script wird nun ausgeführt, dann wird der PC automatisch neustarten ** 2. poste das log vom Avenger, was erscheint ** 3. öffne das HijackThis -- Button "scan" -- vor die Malware-Einträge Häkchen setzen -- Button "Fix checked" -- PC neustarten Zitat R3 - URLSearchHook: _URLHandler - {7FF23285-DBBC-49B6-818C-34AC459D5BB3} - C:\WINDOWS\system32\pidd.dll (file missing) PC neustarten 4. arbeite smitfraud.fix ab (poste den scanreport) http://virus-protect.org/artikel/tools/smitfrautfix.html 5. stelle den CleanUp genauso ein, wie hier angegeben: http://virus-protect.org/cleanup.html ** 6. Kopiere diese 4 Textdateien ab . (rechtsklick mit der Maus -> den Text markieren -> kopieren -> einfügen) Sie sind nach Datum geordnet. (kopiere nur die letzten 3 Monate ab) http://virus-protect.org/datfindbat.html ** 7. Den folgenden Text in den Editor (Start - Zubehör - Editor) kopieren und als listen.bat mit 'Speichern unter' auf dem Desktop. Gebe bei Dateityp 'Alle Dateien' an. Du solltest jetzt auf dem Desktop diese Datei finden. --> die listen.bat doppelt klicken--> kopiere den Text, der erscheint Zitat cd\ __________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
23.06.2006, 16:01
...neu hier
Beiträge: 1 |
#3
Logfile of The Avenger version 1, by Swandog46
Running from registry key: \Registry\Machine\System\CurrentControlSet\Services\cylwlubn ******************* Script file located at: \??\C:\WINDOWS\system32\tudphwgd.txt Script file opened successfully. Script file read successfully Backups directory opened successfully at C:\Avenger ******************* Beginning to process script file: File C:\WINDOWS\SYSTEM32\nwbxltxk.vld not found! Deletion of file C:\WINDOWS\SYSTEM32\nwbxltxk.vld failed! Could not process line: C:\WINDOWS\SYSTEM32\nwbxltxk.vld Status: 0xc0000034 File C:\WINDOWS\system32\susp.exe not found! Deletion of file C:\WINDOWS\system32\susp.exe failed! Could not process line: C:\WINDOWS\system32\susp.exe Status: 0xc0000034 File C:\WINDOWS\SYSTEM32\winlogon.ini deleted successfully. File C:\WINDOWS\SYSTEM32\bridge.dll deleted successfully. File C:\WINDOWS\SYSTEM32\a.exe deleted successfully. File C:\WINDOWS\SYSTEM32\runsrv32.exe deleted successfully. File C:\WINDOWS\SYSTEM32\dailytoolbar.dll deleted successfully. File C:\WINDOWS\SYSTEM32\alxres.dll deleted successfully. File C:\WINDOWS\SYSTEM32\users32.exe deleted successfully. File C:\WINDOWS\SYSTEM32\lrf.dat deleted successfully. File C:\WINDOWS\SYSTEM32\wstart.dll deleted successfully. File C:\WINDOWS\SYSTEM32\ikhcore.log not found! Deletion of file C:\WINDOWS\SYSTEM32\ikhcore.log failed! Could not process line: C:\WINDOWS\SYSTEM32\ikhcore.log Status: 0xc0000034 File C:\WINDOWS\SYSTEM32\thlwin32.dll deleted successfully. File C:\WINDOWS\SYSTEM32\qjrkvy.exe deleted successfully. File C:\WINDOWS\SYSTEM32\winflash.dll deleted successfully. File C:\WINDOWS\SYSTEM32\adobepnl.dll deleted successfully. File C:\WINDOWS\SYSTEM32\udpmod.dll deleted successfully. File C:\WINDOWS\SYSTEM32\questmod.dll deleted successfully. File C:\WINDOWS\SYSTEM32\jao.dll deleted successfully. File C:\WINDOWS\SYSTEM32\txfdb32.dll deleted successfully. File C:\WINDOWS\SYSTEM32\runsrv32.dll deleted successfully. File C:\WINDOWS\SYSTEM32\tcpservice2.exe deleted successfully. File C:\WINDOWS\SYSTEM32\hexicuer.exe not found! Deletion of file C:\WINDOWS\SYSTEM32\hexicuer.exe failed! Could not process line: C:\WINDOWS\SYSTEM32\hexicuer.exe Status: 0xc0000034 File C:\WINDOWS\spacer.gif' deleted successfully. File C:\WINDOWS\header_1.gif deleted successfully. File C:\WINDOWS\footer_back.jpg deleted successfully. File C:\WINDOWS\footer_back.gif deleted successfully. File C:\WINDOWS\features.gif deleted successfully. File C:\WINDOWS\download_box.gif deleted successfully. File C:\WINDOWS\button_freescan.gif deleted successfully. File C:\WINDOWS\button_buynow.gif deleted successfully. File C:\WINDOWS\box_3.gif deleted successfully. File C:\WINDOWS\box_2.gif deleted successfully. File C:\WINDOWS\box_1.gif deleted successfully. File C:\WINDOWS\bg.gif deleted successfully. File C:\WINDOWS\as_header.gif deleted successfully. File C:\WINDOWS\as.gif deleted successfully. File C:\WINDOWS\about_spyware_bottom.gif deleted successfully. File C:\WINDOWS\about_spyware_bg.gif deleted successfully. File C:\WINDOWS\dlmax.dll deleted successfully. File C:\WINDOWS\Pynix.dll deleted successfully. File C:\WINDOWS\BTGrab.dll deleted successfully. File C:\WINDOWS\alxtb1.dll deleted successfully. File C:\WINDOWS\alxie328.dll deleted successfully. File C:\WINDOWS\alexaie.dll deleted successfully. Completed script processing. ******************* Finished! Terminate. |
|
|
||
23.06.2006, 16:34
Ehrenmitglied
Themenstarter Beiträge: 29434 |
#4
nun arbeite alles weitere ab und poste die logs von datfindbat und listen.bat
__________ MfG Sabina rund um die PC-Sicherheit |
|
|
||
Zitat
__________
MfG Sabina
rund um die PC-Sicherheit