|
Log-Analyse und Auswertung: irlyak.exe?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
20.07.2013, 09:35 | #16 |
| irlyak.exe? Hallo nochmal. So, nach einer langen Funkstille bin ich wieder da, aber leider nur diesen Tag, weil morgen bin ich für 5 Wochen im Urlaub. Deswegen werde ich versuchen, das alles heute zu machen. Soo, ich hab rkill durchlaufen lassen, das erste Mal, dass mal etwas beim ersten Versuch geklappt hat (yay). Die Logfile ist im Anhang. Danach ging es weiter mit mbar.exe. Die hab ich auch durchlaufen lassen, aber siehe da, es gibt schon wieder ein Problem. Dieses Mal nicht mit der Datei "SoundXML3.bar", sondern mit der Datei "Sound3.bar". Ein Screenshot und die unfertige Logfile findet sich wieder im Anhang. |
20.07.2013, 17:41 | #17 |
/// Helfer-Team | irlyak.exe? nicht schlecht, ganz schoen hartnaeckig.
__________________Beende bitte Deine Schutzsoftware um eventuelle Konflikte zu vermeiden.
__________________ |
20.07.2013, 19:31 | #18 |
| irlyak.exe? Erledigt. Ich poste die Logfile mal als Code, zur Abwechslung.
__________________Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.1.7 (07.20.2013:1) OS: Microsoft Windows XP x86 Ran by svemore on 20.07.2013 at 20:27:27,76 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services Successfully stopped: [Service] browserprotect Failed to delete: [Service] browserprotect ~~~ Registry Values Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\DisplayName Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\\URL Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\AboutURLs\\Tabs ~~~ Registry Keys Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\escort.dll Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\escortapp.dll Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\escorteng.dll Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\escortlbr.dll Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\esrv.exe Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\{09c554c3-109b-483c-a06b-f14172f1a947} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\{39cb8175-e224-4446-8746-00566302df8d} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\{4e1e9d45-8bf9-4139-915c-9f83cc3d5921} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\{b12e99ed-69bd-437c-86be-c862b9e5444d} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\{c26644c4-2a12-4ca6-8f2e-0ede6cf018f3} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\appid\{d7ee8177-d51e-4f89-92b6-83ea2ec40800} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{261dd098-8a3e-43d4-87aa-63324fa897d8} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{3c471948-f874-49f5-b338-4f214a2ee0b1} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{4fcb4630-2a1c-4aa1-b422-345e8dc8a6de} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{86838207-681d-469d-9511-d0dcc6f19f9b} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{bc9fd17d-30f6-4464-9e53-596a90aff023} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\clsid\{e97a663b-81a6-49c5-a6d3-bcb05ba1de26} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\escort.escortiepane Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\escort.escortiepane.1 Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\interface\{03e2a1f3-4402-4121-8b35-733216d61217} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\interface\{9e3b11f6-4179-4603-a71b-a55f4bcb0bec} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\typelib\{39cb8175-e224-4446-8746-00566302df8d} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\typelib\{9c049ba6-ea47-4ac3-aed6-a66d8dc9e1d8} Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\typelib\{d7ee8177-d51e-4f89-92b6-83ea2ec40800} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\1clickdownload Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\babsolution Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\babylon Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\babylontoolbar Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\conduit Failed to delete: [Registry Key] HKEY_CURRENT_USER\Software\datamngr_toolbar Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\delta Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\delta Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\windows\currentversion\ext\bprotectsettings Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\delta.deltaappcore Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\delta.deltaappcore.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\esrv.deltaesrvc Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\esrv.deltaesrvc.1 Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Classes\prod.cap Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\classes\Toolbar.CT2625848 Failed to delete: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9} Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b} ~~~ Files ~~~ Folders Successfully deleted: [Folder] "C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\babsolution" Successfully deleted: [Folder] "C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\babylon" Successfully deleted: [Folder] "C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\delta" Successfully deleted: [Folder] "C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\dvdvideosoftiehelpers" Successfully deleted: [Folder] "C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\file scout" Successfully deleted: [Folder] "C:\Programme\conduit" Successfully deleted: [Folder] "C:\Programme\delta" ~~~ FireFox Successfully deleted: [File] "C:\Programme\Mozilla Firefox\searchplugins\babylon.xml" Successfully deleted: [File] C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\mozilla\firefox\profiles\aw2ppbe3.default\user.js Successfully deleted: [File] C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\mozilla\firefox\profiles\aw2ppbe3.default\bprotector_extensions.sqlite Successfully deleted: [File] C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\mozilla\firefox\profiles\aw2ppbe3.default\bprotector_prefs.js Successfully deleted: [File] C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\mozilla\firefox\profiles\aw2ppbe3.default\searchplugins\babylon.xml Successfully deleted: [File] C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\mozilla\firefox\profiles\aw2ppbe3.default\searchplugins\browserprotect.xml Successfully deleted: [File] C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\mozilla\firefox\profiles\aw2ppbe3.default\searchplugins\delta.xml Successfully deleted: [Folder] C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\mozilla\firefox\profiles\aw2ppbe3.default\jetpack Successfully deleted: [Folder] C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\mozilla\firefox\profiles\aw2ppbe3.default\extensions\ffxtlbr@delta.com Successfully deleted the following from C:\Dokumente und Einstellungen\svemore\Anwendungsdaten\mozilla\firefox\profiles\aw2ppbe3.default\prefs.js user_pref("CT2625848_Firefox.csv", "[{\"from\":\"Abs Layer\",\"action\":\"loading toolbar\",\"time\":1355837357142,\"isWithState\":\"\",\"timeFromStart\":0,\"timeFromPrev\":0} user_pref("extensions.delta.admin", false); user_pref("extensions.delta.aflt", "babsst"); user_pref("extensions.delta.appId", "{C26644C4-2A12-4CA6-8F2E-0EDE6CF018F3}"); user_pref("extensions.delta.autoRvrt", "false"); user_pref("extensions.delta.dfltLng", "en"); user_pref("extensions.delta.excTlbr", false); user_pref("extensions.delta.ffxUnstlRst", true); user_pref("extensions.delta.id", "947829eb0000000000000018f3649fe0"); user_pref("extensions.delta.instlDay", "15814"); user_pref("extensions.delta.instlRef", "sst"); user_pref("extensions.delta.newTab", false); user_pref("extensions.delta.prdct", "delta"); user_pref("extensions.delta.prtnrId", "delta"); user_pref("extensions.delta.rvrt", "false"); user_pref("extensions.delta.smplGrp", "none"); user_pref("extensions.delta.tlbrId", "base"); user_pref("extensions.delta.tlbrSrchUrl", ""); user_pref("extensions.delta.vrsn", "1.8.16.16"); user_pref("extensions.delta.vrsnTs", "1.8.16.1620:30:05"); user_pref("extensions.delta.vrsni", "1.8.16.16"); ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 20.07.2013 at 20:29:40,01 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
20.07.2013, 19:54 | #19 |
/// Helfer-Team | irlyak.exe? Rechner neustarten und nochmal laufen lassen. |
20.07.2013, 20:23 | #20 |
| irlyak.exe? erledigt. Code:
ATTFilter ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 5.1.7 (07.20.2013:1) OS: Microsoft Windows XP x86 Ran by svemore on 20.07.2013 at 21:19:58,90 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys Failed to delete: [Registry Key] HKEY_CURRENT_USER\Software\datamngr_toolbar ~~~ Files ~~~ Folders ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on 20.07.2013 at 21:22:07,26 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ |
21.07.2013, 10:29 | #21 |
/// Helfer-Team | irlyak.exe? Sehr gut! ESET Online Scanner
danach: Downloade Dir bitte SecurityCheck und:
__________________ --> irlyak.exe? |
12.10.2013, 12:20 | #22 |
/// Helfer-Team | irlyak.exe? Fehlende Rückmeldung Gibt es Probleme beim Abarbeiten obiger Anleitung? Um Kapazitäten für andere Hilfesuchende freizumachen, lösche ich dieses Thema aus meinen Benachrichtigungen. Solltest Du weitermachen wollen, schreibe mir eine PN oder eröffne ein neues Thema. http://www.trojaner-board.de/69886-a...-beachten.html Hinweis: Das Verschwinden der Symptome bedeutet nicht, dass Dein Rechner sauber ist. |
Themen zu irlyak.exe? |
abbrechen, anhänge, ausführbare, datei, entdeck, entdeckt, entstanden, freue, gründe, gründen, guten, hänge, kleine, lange, logfiles, nichts, private, programme, starte, systems, systemstart, verschiedene, verschiedenen, worte, überprüft |