PDA

Archiv verlassen und diese Seite im Standarddesign anzeigen : Infiziert?



Freepler
06.10.2007, 17:15
Moin,
also ich habe folgende Probleme:
Bei mir sind komische Edtior Dateien die sowas (http://www.free-hack.com/viewtopic.php?t=37167) oder so etwas(die beiden waren in 2 Ts-Ordnern)

---------------------------------------------------------------
-------------- log started at 02-10-07 14:01 -------------
---------------------------------------------------------------
02-10-07 14:01:50,824,DEBUG,All,Startup,Client version 2.0.33.7
---------------------------------------------------------------
--------------- log ended at 02-10-07 14:01 --------------
---------------------------------------------------------------
bzw.

---------------------------------------------------------------
-------------- log started at 07-08-07 02:44 -------------
---------------------------------------------------------------
07-08-07 02:44:05,2920,WARNING,All,procedure TDICallBack.execute,"The operation had no effect." or "The device buffer overflowed and some input was lost." or "The device exists but is not currently attached." or "The change in device properties had no effect."
07-08-07 02:44:08,3836,ERROR,All,TClientEventThread.DoLogin Step4,Size error in loginstep4, iteration 2
07-08-07 02:44:33,664,ERROR,ProcedureInfo,Client Open,Exception: Client ip banned
07-08-07 02:44:41,664,ERROR,ProcedureInfo,Client Open,Exception: Client ip banned
07-08-07 02:44:56,664,ERROR,ProcedureInfo,Client Open,Exception: Timeout on recv LoginStep2 wait
07-08-07 02:44:56,2920,WARNING,All,procedure TDICallBack.execute,"The operation had no effect." or "The device buffer overflowed and some input was lost." or "The device exists but is not currently attached." or "The change in device properties had no effect."
07-08-07 02:44:58,3836,ERROR,All,TClientEventThread.DoLogin Step4,Size error in loginstep4, iteration 2
---------------------------------------------------------------
--------------- log ended at 07-08-07 02:49 --------------
---------------------------------------------------------------
soetwas enthalten.

Hier von Netstat -n ein Screen(alle Internet-Sachen aus):
http://img2.imagebanana.com/img/hj35lxc/thumb/netsat.bmp.png (http://img2.imagebanana.com/view/hj35lxc/netsat.bmp.png)
Doch hier von Tasmanager,wobei dreimal svchost ich ein bisschen verdächtig fand:
http://img2.imagebanana.com/img/h4riub3/thumb/taskmanager.bmp.png (http://img2.imagebanana.com/view/h4riub3/taskmanager.bmp.png)

Destroyer
06.10.2007, 17:25
also mit dem Editordaten und netstat -n kann ich net viel sagen, aber svchost.exe ist bei mir jenau so. Das ist glaub ich System Standart.

RaG3
06.10.2007, 17:26
Netstat nix verdächtiges