![]() |
|
Log-Analyse und Auswertung: TR/Dldr.Tiny.brmWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #4 |
![]() | ![]() TR/Dldr.Tiny.brm Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Home Edition (build 2600) SP 3.0 Architecture: X86; Language: German CPU 0: Intel(R) Pentium(R) 4 CPU 3.20GHz Percentage of Memory in Use: 43% Physical Memory (total/avail): 1023.48 MiB / 573.85 MiB Pagefile Memory (total/avail): 2463.37 MiB / 2083.86 MiB Virtual Memory (total/avail): 2047.88 MiB / 1909.86 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 149.04 GiB total, 103.84 GiB free. D: is CDROM (No Media) E: is CDROM (No Media) F: is Removable (No Media) H: is Removable (No Media) I: is Removable (No Media) J: is Removable (No Media) \\.\PHYSICALDRIVE0 - ST3160021A - 149.05 GiB - 1 partition \PARTITION0 (bootable) - Installierbares Dateisystem - 149.04 GiB - C: \\.\PHYSICALDRIVE3 - Medion Flash XL MMC/SD USB Device \\.\PHYSICALDRIVE1 - Medion Flash XL CF USB Device \\.\PHYSICALDRIVE2 - Medion Flash XL MS USB Device \\.\PHYSICALDRIVE4 - Medion Flash XL SM USB Device -- Security Center ------------------------------------------------------------- AUOptions is disabled. -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Dokumente und Einstellungen\All Users APPDATA=C:\Dokumente und Einstellungen\schmigie\Anwendungsdaten CLIENTNAME=Console CommonProgramFiles=C:\Programme\Gemeinsame Dateien COMPUTERNAME=FRANK ComSpec=C:\WINDOWS\system32\cmd.exe FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Dokumente und Einstellungen\schmigie LOGONSERVER=\\FRANK NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 9, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=0209 ProgramFiles=C:\Programme PROMPT=$P$G SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOKUME~1\schmigie\LOKALE~1\Temp TMP=C:\DOKUME~1\schmigie\LOKALE~1\Temp tvdumpflags=8 USERDOMAIN=FRANK USERNAME=schmigie USERPROFILE=C:\Dokumente und Einstellungen\schmigie windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- schmigie (admin) -- Add/Remove Programs --------------------------------------------------------- --> C:\PROGRA~1\FOLDER~1\FOLDER~1.EXE UnInstall --> C:\Programme\DivX\DivXConverterUninstall.exe /CONVERTER --> C:\Programme\Gemeinsame Dateien\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf 7-Zip 4.57 --> "C:\Programme\7-Zip\Uninstall.exe" Acronis True Image Home --> MsiExec.exe /X{3D2975E7-DD28-4145-811A-225140FF87F0} Adobe Acrobat and Reader 8.1.2 Security Update 1 (KB403742) --> MsiExec.exe /X{6846389C-BAC0-4374-808E-B120F86AF5D7} Adobe Flash Player ActiveX --> C:\WINDOWS\system32\Macromed\Flash\uninstall_activeX.exe Adobe Flash Player Plugin --> C:\WINDOWS\system32\Macromed\Flash\uninstall_plugin.exe Adobe Photoshop 7.0 --> C:\WINDOWS\ISUN0407.EXE -f"C:\Programme\Adobe\Photoshop 7.0\Uninst.isu" -c"C:\Programme\Adobe\Photoshop 7.0\Uninst.dll" Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0407-1E257A25E34D} Adobe Reader 8.1.2 - Deutsch --> MsiExec.exe /I{AC76BA86-7AD7-1031-7B44-A81200000003} Adobe Reader 8.1.2 Security Update 1 (KB403742) --> Ahead Nero OEM --> C:\Programme\Ahead\nero\uninstall\UNNERO.exe /UNINSTALL Alldj DVD To AVI Converter 2.0 --> "C:\Programme\Alldj_DVD_To_AVI\unins000.exe" AnyDVD --> "C:\Programme\SlySoft\AnyDVD\AnyDVD-uninst.exe" /D="C:\Programme\SlySoft\AnyDVD" Apple Software Update --> MsiExec.exe /I{B74F042E-E1B9-4A5B-8D46-387BB172F0A4} ArcSoft PhotoStudio 5.5 --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{4A81B632-07AB-4CAC-BB04-DF20DFFBFFA0}\setup.exe" -l0x7 ArcSoft Software Suite --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{9E397B40-13F7-4CA2-9943-ADB29ACBBFDF}\setup.exe" -l0x7 Ashampoo ClipFinder 1.33 --> "C:\Programme\Ashampoo\Ashampoo ClipFinder\unins000.exe" Audiograbber 1.83 SE --> "C:\Programme\Audiograbber\Uninstall.exe" Avira AntiVir Personal – Free Antivirus --> C:\Programme\Avira\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE AVM FRITZ!Box-Kindersicherung --> MsiExec.exe /X{A47AFECA-7F0F-471A-82A3-68DEB673A311} Azureus --> C:\Programme\Azureus\Uninstall.exe C-Media 3D Audio --> C:\WINDOWS\CMIUnInstall.exe Call of Duty --> C:\PROGRA~1\CALLOF~1\Uninstall\Unwise.exe /u C:\PROGRA~1\CALLOF~1\Uninstall\Install.log Camtasia Studio 5 --> MsiExec.exe /I{93D135EB-7D19-41EA-BEEF-72ECD4FE617C} CCleaner (remove only) --> "C:\Programme\CCleaner\uninst.exe" Colin McRae Rally 04 --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{F8718F95-21A1-44B9-97EC-679C93020BAE}\setup.exe" -l0x7 concept/design onlineTV 4 --> "C:\Programme\concept design\onlineTV 4\unins000.exe" Deutsche Sprachdatei für Winamp 5.02 v14 --> C:\Programme\Winamp\WA502DeUnInst.exe Die Sims™ 2 Deluxe --> C:\Programme\EA GAMES\Die Sims 2 Deluxe\EAUninstall.exe Die Sims™ 2 Haustiere --> C:\Programme\EA GAMES\Die Sims 2 Haustiere\EAUninstall.exe DivX Codec --> C:\Programme\DivX\DivXCodecUninstall.exe /CODEC DivX Converter --> C:\Programme\DivX\DivXConverterUninstall.exe /CONVERTER DivX Player --> C:\Programme\DivX\DivXPlayerUninstall.exe /PLAYER DivX Web Player --> C:\Programme\DivX\DivXWebPlayerUninstall.exe /PLUGIN ElsterFormular 2006/2007 --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{CBBCBE04-EA5E-4201-A924-E7ED3E8686AE}\setup.exe" -l0x7 -removeonly ElsterFormular 2007/2008 --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{B480BD2A-F1BA-4FE6-8C8E-34C6111B72C9}\setup.exe" -l0x7 -removeonly EPSON Printer Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R Free YouTube to Mp3 Converter version 2.5 --> "C:\Programme\DVDVideoSoft\Free YouTube to Mp3 Converter\unins000.exe" HijackThis 2.0.2 --> "C:\Dokumente und Einstellungen\schmigie\Eigene Dateien\Downz\HijackThis.exe" /uninstall HP Photo and Imaging 2.2 - Scanjet 3970 Series --> MsiExec.exe /I{796ADAFF-7C5B-4CED-BA11-55A3644F1E0D} HP Speicher-Disc --> MsiExec.exe /X{B376402D-58EA-45EA-BD50-DD924EB67A70} IrfanView (remove only) --> C:\Programme\IrfanView\iv_uninstall.exe IsoBuster 1.7 --> "C:\Programme\Smart Projects\IsoBuster\Uninst\unins000.exe" J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060} Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030} Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050} Java(TM) 6 Update 7 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070} JD Secure 3.1 --> C:\WINDOWS\System32\JDSecure31.exe /u Microsoft Office Professional Edition 2003 --> MsiExec.exe /I{90110407-6000-11D3-8CFE-0150048383C9} Microsoft Visual C++ 2005 Redistributable --> MsiExec.exe /X{7299052b-02a4-4627-81f2-1818da5d550d} Mozilla Firefox (2.0.0.15) --> C:\Programme\Mozilla Firefox\uninstall\helper.exe NVIDIA Drivers --> C:\WINDOWS\System32\nvudisp.exe UninstallGUI O&O Defrag Professional Edition --> MsiExec.exe /I{53480370-6CA2-47EC-BC05-02B4B9271C31} O&O DiskRecovery --> MsiExec.exe /X{53480880-18E0-4097-A460-F22DD3AC6D70} Opera 9.51 --> MsiExec.exe /X{179624B1-2683-45ED-965A-B72189EB5820} Parallel Port Joystick --> C:\WINDOWS\unvise32.exe C:\Programme\Parallel Port Joystick\uninstal.log Pro Evolution Soccer 6 --> C:\PROGRA~1\GEMEIN~1\INSTAL~1\Driver\9\INTEL3~1\IDriver.exe /M{EBB794ED-D282-4334-92FB-254481EFF514} /l1031 RealPlayer --> C:\Programme\Gemeinsame Dateien\Real\Update_OB\r1puninst.exe RealNetworks|RealPlayer|6.0 Riva FLV Player --> "C:\Programme\Riva\Riva FLV Player\unins000.exe" Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} SFT Loader 2006 --> C:\Programme\SFT Loader\uninstall.exe Sicherheitsupdate für Windows XP (KB913433) --> C:\WINDOWS\system32\MacroMed\Flash\genuinst.exe C:\WINDOWS\system32\MacroMed\Flash\KB913433.inf Sicherheitsupdate für Windows XP (KB941569) --> "C:\WINDOWS\$NtUninstallKB941569$\spuninst\spuninst.exe" Sicherheitsupdate für Windows XP (KB950759) --> "C:\WINDOWS\$NtUninstallKB950759$\spuninst\spuninst.exe" Sicherheitsupdate für Windows XP (KB950760) --> "C:\WINDOWS\$NtUninstallKB950760$\spuninst\spuninst.exe" Sicherheitsupdate für Windows XP (KB950762) --> "C:\WINDOWS\$NtUninstallKB950762$\spuninst\spuninst.exe" Sicherheitsupdate für Windows XP (KB951376-v2) --> "C:\WINDOWS\$NtUninstallKB951376-v2$\spuninst\spuninst.exe" Sicherheitsupdate für Windows XP (KB951698) --> "C:\WINDOWS\$NtUninstallKB951698$\spuninst\spuninst.exe" Sicherheitsupdate für Windows XP (KB951748) --> "C:\WINDOWS\$NtUninstallKB951748$\spuninst\spuninst.exe" SMA USB Bus Direct Driver --> C:\WINDOWS\system32\FTD2XXUN.exe C:\WINDOWS\system32\FTD2XXUN.INI SopCast 1.1.0 --> C:\Programme\SopCast\uninst.exe Spb AirIslands VGA --> C:\Programme\Microsoft ActiveSync\Spb AirIslands VGA\Uninstall.exe Spb AirIslands VGA Spelling Dictionaries Support For Adobe Reader 8 --> MsiExec.exe /I{AC76BA86-7AD7-5464-3428-800000000003} Spybot - Search & Destroy --> "C:\Programme\Spybot - Search & Destroy\unins000.exe" Steganos Security Suite 2006 (8.0.6) --> C:\Programme\Steganos Security Suite 2006\uninstall.exe Streamripper Plugin 1.62.2 (Remove only) --> C:\Programme\Winamp\streamripper_uninstall.exe Sunny Data Control --> C:\PROGRA~1\SMA\SUNNYD~1\UNWISE.EXE C:\PROGRA~1\SMA\SUNNYD~1\INSTALL.LOG TCPMP --> C:\Programme\Microsoft ActiveSync\TCPMP\Uninstall.exe TCPMP TuneUp Utilities 2007 --> MsiExec.exe /I{C8BB4912-12D9-42AE-B571-E580D8CD1B5B} Uninstall 1.0.0.0 --> "C:\Programme\Gemeinsame Dateien\DVDVideoSoft\unins000.exe" Update für Windows XP (KB951978) --> "C:\WINDOWS\$NtUninstallKB951978$\spuninst\spuninst.exe" VOX 3D Planer 2.0 --> C:\Programme\VOX3DPlaner2\unins000.exe Winamp --> "C:\Programme\Winamp\UninstWA.exe" Winamp Toolbar for Firefox --> "C:\Dokumente und Einstellungen\schmigie\Anwendungsdaten\Mozilla\Firefox\Profiles\xdtk61uf.Standard-Benutzer\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}\uninstall.exe" Windows Live Anmelde-Assistent --> MsiExec.exe /I{AFA4E5FD-ED70-4D92-99D0-162FD56DC986} Windows Live installer --> MsiExec.exe /X{7A7B0BF3-2F00-4F03-8A9B-6ABCC07B90C6} Windows Live Messenger --> MsiExec.exe /X{2B091530-69AA-442E-AB09-39ED06B58220} Windows XP Service Pack 3 --> "C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe" WinRAR Archivierer --> C:\Programme\WinRAR\uninstall.exe xp-AntiSpy 3.96-6 --> C:\Programme\xp-AntiSpy\Uninstall.exe Yahoo! Messenger --> C:\PROGRA~1\Yahoo!\MESSEN~1\UNWISE.EXE /U C:\PROGRA~1\Yahoo!\MESSEN~1\INSTALL.LOG ZoneAlarm --> C:\Programme\Zone Labs\ZoneAlarm\zauninst.exe -- Application Event Log ------------------------------------------------------- Event Record #/Type11284 / Warning Event Submitted/Written: 07/14/2008 07:11:43 PM Event ID/Source: 4113 / Avira AntiVir Event Description: DR/KGBSpy.34.9C:\Dokumente und Einstellungen\schmigie\Eigene Dateien\Downz\InternetHa!!\Keylogger\kgbspy394.exe Event Record #/Type11283 / Warning Event Submitted/Written: 07/14/2008 07:11:16 PM Event ID/Source: 4113 / Avira AntiVir Event Description: DR/KGBSpy.34.9C:\Dokumente und Einstellungen\schmigie\Eigene Dateien\Downz\InternetHa!!\Keylogger\kgbspy394.exe Event Record #/Type11282 / Warning Event Submitted/Written: 07/14/2008 07:00:12 PM Event ID/Source: 4113 / Avira AntiVir Event Description: DR/KGBSpy.34.9C:\Dokumente und Einstellungen\schmigie\Eigene Dateien\Downz\InternetHa!!\Keylogger\kgbspy394.exe Event Record #/Type11281 / Warning Event Submitted/Written: 07/14/2008 05:57:35 PM Event ID/Source: 4113 / Avira AntiVir Event Description: TR/Dldr.Tiny.brmC:\Dokumente und Einstellungen\schmigie\Lokale Einstellungen\Temp\Rar$DR07.078\UPS_Lieferschein_8102\UPS_Lieferschein.exe Event Record #/Type11280 / Warning Event Submitted/Written: 07/14/2008 05:57:35 PM Event ID/Source: 4113 / Avira AntiVir Event Description: TR/Dldr.Tiny.brmC:\Dokumente und Einstellungen\schmigie\Lokale Einstellungen\Temp\Rar$DR07.078\UPS_Lieferschein_8102\UPS_Lieferschein.exe -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type95384 / Warning Event Submitted/Written: 07/11/2008 06:08:18 PM Event ID/Source: 20 / Print Event Description: Druckertreiber Microsoft Office Document Image Writer Driver für Windows NT x86 Version-3 wurde hinzugefügt oder aktualisiert. Dateien:- mdigraph.dll, mdiui.dll, mdiui.dll. Event Record #/Type95383 / Warning Event Submitted/Written: 07/11/2008 06:08:16 PM Event ID/Source: 3 / Print Event Description: Der Drucker "Microsoft Office Document Image Writer" wurde gelöscht. Event Record #/Type95382 / Warning Event Submitted/Written: 07/11/2008 06:08:14 PM Event ID/Source: 4 / Print Event Description: Das Löschen des Druckers "Microsoft Office Document Image Writer" steht noch aus. Event Record #/Type95366 / Error Event Submitted/Written: 07/11/2008 05:48:46 PM Event ID/Source: 8032 / BROWSER Event Description: Das Einlesen der Sicherungsliste durch den Suchdienst schlug auf Transport "\Device\NetBT_Tcpip_{49B2B8CE-0724-4A82-872D-B36E37E84B5C}" zu oft fehl. Der Sicherungssuchdienst wird beendet. Event Record #/Type95365 / Warning Event Submitted/Written: 07/11/2008 05:46:43 PM Event ID/Source: 4226 / Tcpip Event Description: TCP/IP hat das Sicherheitslimit erreicht, das für die Anzahl gleichzeitiger TCP-Verbindungsversuche festgelegt wurde. -- End of Deckard's System Scanner: finished at 2008-07-14 19:31:52 ------------ |
Themen zu TR/Dldr.Tiny.brm |
adobe, antivir, antivirus, avg, avira, bho, einstellungen, excel, explorer, firefox, hijack, hijackthis, hijackthis logfile, hkus\s-1-5-18, internet, internet explorer, logfile, mozilla, mozilla firefox, quara, rundll, scan, security, security suite, software, system, tr/dldr., trojaner, windows, windows xp, windows xp sp3, xp sp3 |