![]() |
|
Plagegeister aller Art und deren Bekämpfung: blanck und TLBASSUI.EXEWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
| ![]() blanck und TLBASSUI.EXE Hallöchen, also erstmal, ich hab eigentlich keine Ahnung und hab vor 3 Stunden erst gelernt was ein Hijacker ist..... Also in meinem IExplorer ist die Startseite jetzt immer http://default.home/ und erscheint natürlich immer wieder... Die leitet mich dann automatisch zur Seite res://C:\WINDOWS\System32\shdoclc.dll/navcancl.htm erstmal. Mein Virenscanner hat c:\windows\TLBASSui.EXE schon dutzende male gelöscht. Habe mir jetzt gerade SpySubtract herunter geladen und der meldet mir in der Registry 40 suspects siehe hier: --------------------------------- SpySubtract session started --------------------------------- Machine=NAME-X5Q2G9MLQX Time=Mon Jan 10 18:59:37 2005 Product Version=1, 0, 1, 49 OS Version=Microsoft Windows XP Home Edition Service Pack 1 (Build 2600) Started Scanning Programs in Memory Finished Scanning Started Scanning Internet Cookies Programs in Memory Windows Registry Found '' in 'Software\DIALPASS' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\InprocServer32' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\MiscStatus' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\MiscStatus\1' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\ProgID' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\ToolboxBitmap32' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\TypeLib' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\Version' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\VersionIndependentProgID' Found '' in 'Software\CLASSES\IEAccess2.IEDial' Found '' in 'Software\CLASSES\IEAccess2.IEDial.1' Found '' in 'Software\CLASSES\IEAccess2.IEDial.1\CLSID' Found '' in 'Software\CLASSES\IEAccess2.IEDial\CLSID' Found '' in 'Software\CLASSES\IEAccess2.IEDial\CurVer' Found '' in 'Software\CLASSES\Interface\{3CD945A2-E413-4956-B9D8-A67FB6A7CB66}' Found '' in 'Software\CLASSES\Interface\{3CD945A2-E413-4956-B9D8-A67FB6A7CB66}\ProxyStubClsid' Found '' in 'Software\CLASSES\Interface\{3CD945A2-E413-4956-B9D8-A67FB6A7CB66}\ProxyStubClsid32' Found '' in 'Software\CLASSES\Interface\{3CD945A2-E413-4956-B9D8-A67FB6A7CB66}\TypeLib' Found '' in 'Software\CLASSES\Interface\{D24A1963-9951-4153-A340-6648759EB77D}' Found '' in 'Software\CLASSES\Interface\{D24A1963-9951-4153-A340-6648759EB77D}\ProxyStubClsid' Found '' in 'Software\CLASSES\Interface\{D24A1963-9951-4153-A340-6648759EB77D}\ProxyStubClsid32' Found '' in 'Software\CLASSES\Interface\{D24A1963-9951-4153-A340-6648759EB77D}\TypeLib' Found '' in 'Software\CLASSES\TypeLib\{9D6ADDBF-8227-4D36-AE46-116AFBDAFCA0}\1.0' Found '' in 'Software\CLASSES\TypeLib\{9D6ADDBF-8227-4D36-AE46-116AFBDAFCA0}\1.0\0\win32' Found '' in 'Software\CLASSES\TypeLib\{9D6ADDBF-8227-4D36-AE46-116AFBDAFCA0}\1.0\FLAGS' Found '' in 'Software\CLASSES\TypeLib\{9D6ADDBF-8227-4D36-AE46-116AFBDAFCA0}\1.0\HELPDIR' Found '' in 'SOFTWARE\Classes\Interface\{95B92D92-8B7D-4A19-A3F1-43113B4DBCAF}' Found '' in 'SOFTWARE\Classes\Interface\{95B92D92-8B7D-4A19-A3F1-43113B4DBCAF}\ProxyStubClsid' Found '' in 'SOFTWARE\Classes\Interface\{95B92D92-8B7D-4A19-A3F1-43113B4DBCAF}\ProxyStubClsid32' Found '' in 'SOFTWARE\Classes\Interface\{95B92D92-8B7D-4A19-A3F1-43113B4DBCAF}\TypeLib' Found '' in 'SOFTWARE\Classes\ToolBand.ToolBandObj' Found '' in 'SOFTWARE\Classes\ToolBand.ToolBandObj.1' Found '' in 'SOFTWARE\Classes\ToolBand.ToolBandObj.1\CLSID' Found '' in 'SOFTWARE\Classes\ToolBand.ToolBandObj\CLSID' Found '' in 'SOFTWARE\Classes\ToolBand.ToolBandObj\CurVer' Found '' in 'SOFTWARE\Classes\TypeLib\{5297E905-1DFB-4A9C-9871-A4F95FD58945}\1.0' Found '' in 'SOFTWARE\Classes\TypeLib\{5297E905-1DFB-4A9C-9871-A4F95FD58945}\1.0\0\win32' Found '' in 'SOFTWARE\Classes\TypeLib\{5297E905-1DFB-4A9C-9871-A4F95FD58945}\1.0\FLAGS' Found '' in 'SOFTWARE\Classes\TypeLib\{5297E905-1DFB-4A9C-9871-A4F95FD58945}\1.0\HELPDIR' Internet URL Shortcuts Files and Directories Finished Scanning Started Scanning Internet Cookies Programs in Memory Windows Registry Found '' in 'Software\DIALPASS' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\InprocServer32' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\MiscStatus' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\MiscStatus\1' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\ProgID' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\ToolboxBitmap32' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\TypeLib' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\Version' Found '' in 'Software\CLASSES\CLSID\{1D2DCA0D-B30F-40AD-9690-087105F214EC}\VersionIndependentProgID' Found '' in 'Software\CLASSES\IEAccess2.IEDial' Found '' in 'Software\CLASSES\IEAccess2.IEDial.1' Found '' in 'Software\CLASSES\IEAccess2.IEDial.1\CLSID' Found '' in 'Software\CLASSES\IEAccess2.IEDial\CLSID' Found '' in 'Software\CLASSES\IEAccess2.IEDial\CurVer' Found '' in 'Software\CLASSES\Interface\{3CD945A2-E413-4956-B9D8-A67FB6A7CB66}' Found '' in 'Software\CLASSES\Interface\{3CD945A2-E413-4956-B9D8-A67FB6A7CB66}\ProxyStubClsid' Found '' in 'Software\CLASSES\Interface\{3CD945A2-E413-4956-B9D8-A67FB6A7CB66}\ProxyStubClsid32' Found '' in 'Software\CLASSES\Interface\{3CD945A2-E413-4956-B9D8-A67FB6A7CB66}\TypeLib' Found '' in 'Software\CLASSES\Interface\{D24A1963-9951-4153-A340-6648759EB77D}' Found '' in 'Software\CLASSES\Interface\{D24A1963-9951-4153-A340-6648759EB77D}\ProxyStubClsid' Found '' in 'Software\CLASSES\Interface\{D24A1963-9951-4153-A340-6648759EB77D}\ProxyStubClsid32' Found '' in 'Software\CLASSES\Interface\{D24A1963-9951-4153-A340-6648759EB77D}\TypeLib' Found '' in 'Software\CLASSES\TypeLib\{9D6ADDBF-8227-4D36-AE46-116AFBDAFCA0}\1.0' Found '' in 'Software\CLASSES\TypeLib\{9D6ADDBF-8227-4D36-AE46-116AFBDAFCA0}\1.0\0\win32' Found '' in 'Software\CLASSES\TypeLib\{9D6ADDBF-8227-4D36-AE46-116AFBDAFCA0}\1.0\FLAGS' Found '' in 'Software\CLASSES\TypeLib\{9D6ADDBF-8227-4D36-AE46-116AFBDAFCA0}\1.0\HELPDIR' Found '' in 'SOFTWARE\Classes\Interface\{95B92D92-8B7D-4A19-A3F1-43113B4DBCAF}' Found '' in 'SOFTWARE\Classes\Interface\{95B92D92-8B7D-4A19-A3F1-43113B4DBCAF}\ProxyStubClsid' Found '' in 'SOFTWARE\Classes\Interface\{95B92D92-8B7D-4A19-A3F1-43113B4DBCAF}\ProxyStubClsid32' Found '' in 'SOFTWARE\Classes\Interface\{95B92D92-8B7D-4A19-A3F1-43113B4DBCAF}\TypeLib' Found '' in 'SOFTWARE\Classes\ToolBand.ToolBandObj' Found '' in 'SOFTWARE\Classes\ToolBand.ToolBandObj.1' Found '' in 'SOFTWARE\Classes\ToolBand.ToolBandObj.1\CLSID' Found '' in 'SOFTWARE\Classes\ToolBand.ToolBandObj\CLSID' Found '' in 'SOFTWARE\Classes\ToolBand.ToolBandObj\CurVer' Found '' in 'SOFTWARE\Classes\TypeLib\{5297E905-1DFB-4A9C-9871-A4F95FD58945}\1.0' Found '' in 'SOFTWARE\Classes\TypeLib\{5297E905-1DFB-4A9C-9871-A4F95FD58945}\1.0\0\win32' Found '' in 'SOFTWARE\Classes\TypeLib\{5297E905-1DFB-4A9C-9871-A4F95FD58945}\1.0\FLAGS' Found '' in 'SOFTWARE\Classes\TypeLib\{5297E905-1DFB-4A9C-9871-A4F95FD58945}\1.0\HELPDIR' Internet URL Shortcuts Files and Directories Finished Scanning Nun trau ich mich an die Registry eigentlich als "normaler" User eigentlich nicht ran und lösch dort nicht einfach mal alles raus was komisch aussieht ![]() ![]() Also am liebsten wäre mir ein Link mit Download, wo alles wie von selbst geht natürlich aber auch jede andere Hilfe ist natürlich willkommen. :-) Gruß Gerd |
Themen zu blanck und TLBASSUI.EXE |
automatisch, bla, download, hijacker, iexplorer, inprocserver32, keine ahnung, leitet, link, microsoft, registry, scan, scanner, seite, service pack 1, software, startseite, system, system32, version, virenscanner, von selbst, win32, windows, windows xp, xp home |