|
Log-Analyse und Auswertung: 2mal Iexplorer.exe/ CiD popups/ Soap.exe/Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
11.03.2008, 18:26 | #1 |
| 2mal Iexplorer.exe/ CiD popups/ Soap.exe/ Hallo, ich brauche unbedingt Hilfe. Ich habe sooooo viel müll auf meinem pc und die AntiVir sofware von Norton löscht nicht alles. Kann mir bitte jemand helfen. Hier ist das Log-File. Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 18:17, on 2008-03-11 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16608) Boot mode: Normal Running processes: E:\WINDOWS\System32\smss.exe E:\WINDOWS\system32\winlogon.exe E:\WINDOWS\system32\services.exe E:\WINDOWS\system32\lsass.exe E:\WINDOWS\system32\svchost.exe E:\WINDOWS\System32\svchost.exe E:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe E:\WINDOWS\system32\spoolsv.exe E:\Programme\Gemeinsame Dateien\AccSys\accsvc.exe E:\Programme\Symantec\LiveUpdate\AluSchedulerSvc.exe E:\WINDOWS\system32\nvsvc32.exe E:\WINDOWS\system32\PnkBstrA.exe E:\WINDOWS\system32\svchost.exe E:\WINDOWS\system32\UAService7.exe E:\WINDOWS\Explorer.EXE E:\WINDOWS\SOUNDMAN.EXE E:\Programme\Java\jre1.6.0_03\bin\jusched.exe E:\WINDOWS\system32\LVCOMSX.EXE E:\Programme\Logitech\Video\LogiTray.exe E:\Programme\WLAN Monitor\wlconfig.exe E:\Programme\A4Tech\Mouse\Amoumain.exe E:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe E:\WINDOWS\system32\ctfmon.exe E:\Programme\Messenger\MSMSGS.EXE E:\Programme\Internet Explorer\IEXPLORE.EXE E:\Programme\Eraser\Eraser.exe E:\Programme\Internet Explorer\IEXPLORE.EXE E:\Programme\Slim Multimedia Keyboard\MagicKey.exe E:\Programme\Slim Multimedia Keyboard\OSD.EXE E:\WINDOWS\system32\wuauclt.exe E:\Programme\Logitech\Video\FxSvr2.exe E:\DOKUME~1\V****r\LOKALE~1\Temp\Rar$EX00.531\HijackThis.exe R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,First Home Page = h**p://www.arcor.de R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = h**p://www.freenet.de/ O2 - BHO: IE7Pro - {00011268-E188-40DF-A514-835FCD78B1BF} - E:\Programme\IEPro\iepro.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - E:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - E:\PROGRA~1\GEMEIN~1\SYMANT~1\IDS\IPSBHO.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Programme\Java\jre1.6.0_03\bin\ssv.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - E:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE E:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE E:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE O4 - HKLM\..\Run: [NeroFilterCheck] E:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Programme\Java\jre1.6.0_03\bin\jusched.exe" O4 - HKLM\..\Run: [cctray] "E:\Programme\CA\CA Internet Security Suite\cctray\cctray.exe" O4 - HKLM\..\Run: [LVCOMSX] E:\WINDOWS\system32\LVCOMSX.EXE O4 - HKLM\..\Run: [LogitechVideoRepair] E:\Programme\Logitech\Video\ISStart.exe O4 - HKLM\..\Run: [LogitechVideoTray] E:\Programme\Logitech\Video\LogiTray.exe O4 - HKLM\..\Run: [wlconfig] "E:\Programme\WLAN Monitor\wlconfig.exe" -autostart O4 - HKLM\..\Run: [WheelMouse] E:\Programme\A4Tech\Mouse\Amoumain.exe O4 - HKLM\..\Run: [QuickTime Task] "E:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ccApp] "E:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [osCheck] "E:\Programme\Norton AntiVirus\osCheck.exe" O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [LDM] C:\Program Files\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe O4 - HKCU\..\Run: [LogitechSoftwareUpdate] E:\Programme\Logitech\Video\ManifestEngine.exe boot O4 - HKCU\..\Run: [MSMSGS] "E:\Programme\Messenger\MSMSGS.EXE" /background O4 - HKCU\..\Run: [DriveDiscoveryMemoryResident] E:\Programme\NotsoSoftware\DriveDiscovery\NSSMR.exe O4 - HKCU\..\Run: [city chin] E:\DOKUME~1\Viktor\ANWEND~1\4PLUS~1\Soapkeep.exe O4 - HKCU\..\Run: [Eraser] E:\Programme\Eraser\Eraser.exe -hide O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Global Startup: Slim Multimedia Keyboard.lnk = E:\Programme\Slim Multimedia Keyboard\MagicKey.exe O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://E:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - E:\Programme\IEPro\iepro.dll O9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - E:\Programme\IEPro\iepro.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Programme\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Programme\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - E:\Programme\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - E:\Programme\ICQLite\ICQLite.exe O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file) O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - E:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programme\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programme\Messenger\MSMSGS.EXE O14 - IERESET.INF: START_PAGE_URL=h**p://www.lycos.de/ O16 - DPF: {00B71CFB-6864-4346-A978-C0A14556272C} (Checkers Class) - []h**p://messenger.zone.msn.com/binary/msgrchkr.cab31267.cab[] O16 - DPF: {14B87622-7E19-4EA8-93B3-97215F77A6BC} (MessengerStatsClient Class) - []h**p://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab31267.cab[] O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - []h**p://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab[] O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - []h**p://messenger.zone.msn.com/binary/ZIntro.cab47946.cab[] O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - []h**p://arcade.icq.com/online/online2/bejeweled2/popcaploader_v6.cab[] O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - []h**p://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab[] O23 - Service: AccSys WiFi Component (accsvc) - AccSys GmbH - E:\Programme\Gemeinsame Dateien\AccSys\accsvc.exe O23 - Service: Adobe LM Service - Adobe Systems - E:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Unknown owner - E:\Programme\AntiVir PersonalEdition Classic\sched.exe (file missing) O23 - Service: Automatisches LiveUpdate - Scheduler (Automatic LiveUpdate Scheduler) - Symantec Corporation - E:\Programme\Symantec\LiveUpdate\AluSchedulerSvc.exe O23 - Service: CaCCProvSP - Unknown owner - E:\Programme\CA\CA Internet Security Suite\ccprovsp.exe (file missing) O23 - Service: CAISafe - Unknown owner - E:\Programme\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exe (file missing) O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - E:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - E:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - E:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe O23 - Service: LiveUpdate - Symantec Corporation - E:\Programme\Symantec\LiveUpdate\LuComServer_3_4.EXE O23 - Service: LiveUpdate Notice - Symantec Corporation - E:\Programme\Gemeinsame Dateien\Symantec Shared\ccSvcHst.exe O23 - Service: MSCSPTISRV - Sony Corporation - E:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\MSCSPTISRV.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - E:\WINDOWS\system32\nvsvc32.exe O23 - Service: PACSPTISVR - Sony Corporation - E:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\PACSPTISVR.exe O23 - Service: PnkBstrA - Unknown owner - E:\WINDOWS\system32\PnkBstrA.exe O23 - Service: Sony SPTI Service (SPTISRV) - Sony Corporation - E:\Programme\Gemeinsame Dateien\Sony Shared\AVLib\SPTISRV.exe O23 - Service: Symantec Core LC - Unknown owner - E:\PROGRA~1\GEMEIN~1\SYMANT~1\CCPD-LC\symlcsvc.exe O23 - Service: SecuROM User Access Service (V7) (UserAccess7) - Sony DADC Austria AG. - E:\WINDOWS\system32\UAService7.exe O23 - Service: VET Message Service (VETMSGNT) - Unknown owner - E:\Programme\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe (file missing) O24 - Desktop Component 0: (no name) - file:///H:/files/extras/wallpapers/1280x1024/images/wallpaper_monster_hunter_freedom_01_1280.jpg -- End of file - 10061 bytes
__________________ 24 Trojaner und der PC steht noch |
Themen zu 2mal Iexplorer.exe/ CiD popups/ Soap.exe/ |
adobe, antivir, antivirus, bho, cid, desktop, eraser, excel, explorer, hijack, hijackthis, hkus\s-1-5-18, home, internet, internet explorer, internet security, intrusion prevention, monitor, nvidia, object, preferences, rundll, security, security suite, software, symantec, system, temp, windows, windows xp, wlan |