![]() |
|
Log-Analyse und Auswertung: Problem mit TR/Monderb.aqlWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #3 |
![]() ![]() | ![]() Problem mit TR/Monderb.aql Alles klar, hier wäre ich wieder
__________________Danke für die schnell Antwort 1.Extra Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft Windows XP Professional (build 2600) SP 1.0 Architecture: X86; Language: German CPU 0: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+ CPU 1: AMD Athlon(tm) 64 X2 Dual Core Processor 3800+ Percentage of Memory in Use: 39% Physical Memory (total/avail): 1023.23 MiB / 620.63 MiB Pagefile Memory (total/avail): 2465.19 MiB / 2123.49 MiB Virtual Memory (total/avail): 2047.88 MiB / 1921.41 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 11.72 GiB total, 1.43 GiB free. D: is Fixed (NTFS) - 64.6 GiB total, 9.89 GiB free. E: is CDROM (No Media) F: is CDROM (CDFS) \\.\PHYSICALDRIVE0 - Maxtor 6Y080L0 - 76.33 GiB - 2 partitions \PARTITION0 (bootable) - Installierbares Dateisystem - 11.72 GiB - C: \PARTITION1 - Installierbares Dateisystem - 64.6 GiB - D: -- Security Center ------------------------------------------------------------- AUOptions is not configured. -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Dokumente und Einstellungen\All Users APPDATA=C:\Dokumente und Einstellungen\p***** a******\Anwendungsdaten CLIENTNAME=Console CommonProgramFiles=C:\Programme\Gemeinsame Dateien COMPUTERNAME=P***** ComSpec=C:\WINDOWS\system32\cmd.exe HOMEDRIVE=C: HOMEPATH=\Dokumente und Einstellungen\p***** a****** LOGONSERVER=\\P***** NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Programme\Gemeinsame Dateien\Adobe\AGL PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 75 Stepping 2, AuthenticAMD PROCESSOR_LEVEL=15 PROCESSOR_REVISION=4b02 ProgramFiles=C:\Programme PROMPT=$P$G SESSIONNAME=Console SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOKUME~1\P*****~1\LOKALE~1\Temp TMP=C:\DOKUME~1\P*****~1\LOKALE~1\Temp USERDOMAIN=P***** USERNAME=p***** a****** USERPROFILE=C:\Dokumente und Einstellungen\p***** a****** windir=C:\WINDOWS -- User Profiles --------------------------------------------------------------- p**** a****** (admin) -- Add/Remove Programs --------------------------------------------------------- --> C:\Programme\Nero\Nero 7\nero\uninstall\UNNERO.exe /UNINSTALL --> C:\WINDOWS\UNNeroBackItUp.exe /UNINSTALL --> C:\WINDOWS\UNNeroMediaHome.exe /UNINSTALL --> C:\WINDOWS\UNNeroShowTime.exe /UNINSTALL --> C:\WINDOWS\UNNeroVision.exe /UNINSTALL --> C:\WINDOWS\UNRecode.exe /UNINSTALL --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf ABBYY FineReader 6.0 Sprint --> MsiExec.exe /I{ACF60000-22B9-4CE9-98D6-2CCF359BAC07} Adobe Acrobat 5.0 --> C:\WINDOWS\ISUNINST.EXE -f"C:\Programme\Gemeinsame Dateien\Adobe\Acrobat 5.0\NT\Uninst.isu" -c"C:\Programme\Gemeinsame Dateien\Adobe\Acrobat 5.0\NT\Uninst.dll" Adobe Common File Installer --> MsiExec.exe /I{8EDBA74D-0686-4C99-BFDD-F894678E5101} Adobe Flash Player 9 ActiveX --> C:\WINDOWS\System32\Macromed\Flash\FlashUtil9b.exe -uninstallDelete Adobe Flash Player Plugin --> C:\WINDOWS\System32\Macromed\Flash\uninstall_plugin.exe Adobe Help Center 1.0 --> MsiExec.exe /I{E9787678-119F-4D52-B551-6739B2B22101} Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0407-2E257A25E34D} Adobe Photoshop CS2 --> msiexec /I {236BB7C4-4419-42FD-0409-1E257A25E34D} Adobe Reader 7.1.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002} Adobe Stock Photos 1.0 --> MsiExec.exe /I{786C5747-1033-0000-B58E-000000000001} Adobe Stock Photos 1.0 --> MsiExec.exe /I{EE0D5DCD-2B97-4473-98DF-E93C0BD92F7A} Avira AntiVir Personal - Free Antivirus --> C:\Programme\AntiVir PersonalEdition Classic\SETUP.EXE /REMOVE AVM FRITZ!DSL --> C:\WINDOWS\IsUn0407.exe -fC:\Programme\FRITZ!DSL\WebUnins.isu -cC:\Programme\FRITZ!DSL\Webunins.dll Benutzerhandbuch ESDX5000_CX4900 --> C:\Programme\EPSON\TPMANUAL\ESDX5000_CX4900\USE_G\DOCUNINS.EXE Call of Duty(R) 4 - Modern Warfare(TM) 1.3 Patch --> C:\Programme\InstallShield Installation Information\{050C1C8E-4A4D-4C2F-B9AE-67E60EE91B7F}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM) 1.4 Patch --> C:\Programme\InstallShield Installation Information\{3BD633E0-4BF8-4499-9149-88F0767D449C}\setup.exe -runfromtemp -l0x0409 Call of Duty(R) 4 - Modern Warfare(TM) 1.5 Multiplayer Patch --> C:\Programme\InstallShield Installation Information\{8503C901-85D7-4262-88D2-8D8B2A7B08B8}\setup.exe -runfromtemp -l0x0409 dMSN --> "C:\Programme\dMSN\UninstallerData\Uninstall dMSN.exe" Doomsday --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{69464949-AD9C-4C98-933F-C32FFC86F3C8}\setup.exe" -l0x7 EPSON-Drucker-Software --> C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\EPUPDATE.EXE /R EPSON Attach To Email --> C:\Programme\Gemeinsame Dateien\InstallShield\Driver\8\Intel 32\IDriver.exe /M{20C45B32-5AB6-46A4-94EF-58950CAF05E5} /l1033 ADDREMOVEDLG EPSON Copy Utility 3 --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{67EDD823-135A-4D59-87BD-950616D6E857}\SETUP.EXE" -l0x7 -UnInstall EPSON Easy Photo Print --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{BC69DDB8-4840-4D9B-BB31-0D4DB2BA1312}\SETUP.EXE" -l0x7 UNINST EPSON File Manager --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{E86BC406-944E-41F6-ADE6-2C136734C96B}\Setup.exe" -l0x7 UNINST EPSON Scan --> C:\Programme\epson\escndv\setup\setup.exe /r EPSON Scan Assistant --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}\Setup.exe" -l0x7 -u EPSON Web-To-Page --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{7F14F68C-17FA-4F88-B3FD-7F449C1EBF32}\SETUP.EXE" -l0x7 -anything EXPERTool --> RunDll32 Setupapi.dll,InstallHinfSection TB.Remove 4 TBNT4.inf Fraps --> "D:\Fraps\uninstall.exe" FRITZ!Box --> C:\Programme\FRITZ!Box\install.exe -d Gemeinsam genutzte Internet-Komponenten von Westwood --> D:\Westwood\Internet\UnstllAP.EXE Hearts of Iron 2 Doomsday Armageddon Patch 1.1 --> "D:\Programme\Paradox Interactive\Doomsday\unins000.exe" High Definition Audio Driver Package - KB888111 --> "C:\WINDOWS\$NtUninstallKB888111WXP$\spuninst\spuninst.exe" HijackThis 2.0.2 --> "C:\Programme\Trend Micro\HijackThis\HijackThis.exe" /uninstall ICQ Toolbar --> regsvr32 /u /s "C:\PROGRA~1\ICQTOO~1\toolbaru.dll" ICQ6 --> "C:\Programme\InstallShield Installation Information\{60DE4033-9503-48D1-A483-7846BD217CA9}\setup.exe" -runfromtemp -l0x0009 -removeonly J2SE Runtime Environment 5.0 Update 11 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150110} Java(TM) 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020} Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030} Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050} Java(TM) 6 Update 7 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160070} Java(TM) SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010} Malwarebytes' Anti-Malware --> "C:\Programme\Malwarebytes' Anti-Malware\unins000.exe" Messenger Plus! Live --> "C:\Programme\Messenger Plus! Live\Uninstall.exe" MessengerDiscovery Live 1.5.0720 --> "C:\Programme\MessengerDiscovery\unins000.exe" Mozilla Firefox (3.0.1) --> C:\Programme\Mozilla Firefox\uninstall\helper.exe MSXML4 Parser --> MsiExec.exe /I{01501EBA-EC35-4F9F-8889-3BE346E5DA13} Musicmatch® Jukebox --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\09\01\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{8EF1122E-E90C-4EE9-AB0C-7FDE2BA42C26}\setup.exe" -l0x7 -uninst Nero 7 Demo --> MsiExec.exe /I{3DBD33CF-E905-7E8C-7FBF-BD80FFD71031} Nero Reloaded PlugIn Pack 2.0.4 by GEAR --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\10\50\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{F3D7915D-6B42-49FA-9FC8-5020479A6A57}\setup.exe" -l0x7 -removeonly Nokia Connectivity Cable Driver --> MsiExec.exe /X{6882DD11-33B8-4DEA-8305-7E765BF74BD3} Nokia PC Connectivity Solution --> MsiExec.exe /I{9F2BDC61-4D2D-47C0-BCB6-7D43D0EA7948} Nokia PC Suite --> MsiExec.exe /I{79880ACC-B5AB-486A-B95D-03F55DF3F9C6} Norton™ Security Scan --> MsiExec.exe /I{666CF041-77BE-414E-9A9D-0A227E9B48F8} NVIDIA Drivers --> C:\WINDOWS\System32\nvudisp.exe UninstallGUI oggcodecs 0.71.0946 --> C:\Programme\illiminable\oggcodecs\uninst.exe OpenOffice.org 2.3 --> MsiExec.exe /I{A625D45F-1DC4-47FB-ABCF-6B27684AA717} PCFriendly --> C:\Program Files\PCFriendly\inuninst.exe Picasa 2 --> "C:\Programme\Picasa2\Uninstall.exe" PIF DESIGNER --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{B90450DF-E781-46FD-B1F1-0C86DA40E443}\SETUP.EXE" -l0x7 anything Realtek High Definition Audio Driver --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}\Setup.exe" -l0x7 -removeonly Rise of Persia v2.2 --> D:\Programme\Activision\Rome - Total War\uninst-ROP.exe Rome - Total War - Alexander --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{6C1804BC-094F-431A-BEA5-37A837958029}\setup.exe" -l0x7 -removeonly Rome Total War - patch 1.3 --> RunDll32 C:\PROGRA~1\GEMEIN~1\INSTAL~1\PROFES~1\RunTime\0701\Intel32\Ctor.dll,LaunchSetup "C:\Programme\InstallShield Installation Information\{A5D65411-8E73-4C85-AD80-9FE8B7391CF9}\Setup.exe" -l0x9 System Requirements Lab --> C:\Programme\SystemRequirementsLab\Uninstall.exe TeamSpeak 2 RC2 --> D:\Programme\Teamspeak2_RC2\unins000.exe VeohTV BETA --> C:\Programme\InstallShield Installation Information\{0405E51E-9582-4207-8F38-AC44201D3808}\setup.exe -runfromtemp -l0x0409 Windows Driver Package - Nokia Modem (06/12/2006 6.81.0.21) --> C:\PROGRA~1\DIFX\D6ACC4BE676423A2B130B78A4B627FC457D98997\dpinst.exe /u C:\WINDOWS\System32\DRVSTORE\nokbtmdm_62A340731F8930057B44B8864F236850B0D49D65\nokbtmdm.inf Windows Live Messenger --> MsiExec.exe /X{2B091530-69AA-442E-AB09-39ED06B58220} WinRAR Archivierer --> D:\Programme\WinRAR\uninstall.exe Xfire (remove only) --> "D:\Programme\Xfire\uninst.exe" -- Application Event Log ------------------------------------------------------- Event Record #/Type5627 / Warning Event Submitted/Written: 07/28/2008 08:57:47 PM Event ID/Source: 4113 / Avira AntiVir Event Description: TR/Monderb.aglC:\WINDOWS\system32\rqRJBssp.dll Event Record #/Type5625 / Warning Event Submitted/Written: 07/28/2008 08:57:36 PM Event ID/Source: 4113 / Avira AntiVir Event Description: TR/Monderb.aglC:\WINDOWS\system32\rqRJBssp.dll Event Record #/Type5622 / Warning Event Submitted/Written: 07/28/2008 06:39:56 PM Event ID/Source: 4113 / Avira AntiVir Event Description: TR/Monderb.aglC:\WINDOWS\System32\rqRJBssp.dll Event Record #/Type5621 / Error Event Submitted/Written: 07/28/2008 02:51:14 PM Event ID/Source: 1002 / Application Hang Event Description: Stillstehende Anwendung msnmsgr.exe, Version 8.5.1302.1018, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Event Record #/Type5620 / Error Event Submitted/Written: 07/28/2008 02:51:14 PM Event ID/Source: 1002 / Application Hang Event Description: Stillstehende Anwendung msnmsgr.exe, Version 8.5.1302.1018, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type79461 / Error Event Submitted/Written: 07/29/2008 04:59:26 PM Event ID/Source: 7000 / Service Control Manager Event Description: Der Dienst "Cardex" wurde aufgrund folgenden Fehlers nicht gestartet: %%183 Event Record #/Type79430 / Error Event Submitted/Written: 07/29/2008 04:54:20 PM Event ID/Source: 10005 / DCOM Event Description: Bei DCOM ist der Fehler "%%1058" aufgetreten, als der Dienst "usnjsvc" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1} Event Record #/Type79429 / Error Event Submitted/Written: 07/29/2008 04:54:09 PM Event ID/Source: 10005 / DCOM Event Description: Bei DCOM ist der Fehler "%%1058" aufgetreten, als der Dienst "usnjsvc" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1} Event Record #/Type79428 / Error Event Submitted/Written: 07/29/2008 04:53:59 PM Event ID/Source: 10005 / DCOM Event Description: Bei DCOM ist der Fehler "%%1058" aufgetreten, als der Dienst "usnjsvc" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1} Event Record #/Type79427 / Error Event Submitted/Written: 07/29/2008 04:53:48 PM Event ID/Source: 10005 / DCOM Event Description: Bei DCOM ist der Fehler "%%1058" aufgetreten, als der Dienst "usnjsvc" mit den Argumenten "" gestartet wurde, um den folgenden Server zu verwenden: {98AC5C33-EE18-4EC2-BE25-3B16EE8F75F1} -- End of Deckard's System Scanner: finished at 2008-07-29 17:01:26 ------------ |
Themen zu Problem mit TR/Monderb.aql |
adobe, antivir, avira, browser, dsl, explorer, firefox, gainward, hijack, hijackthis, hkus\s-1-5-18, infizierte, infizierte dateien, internet, internet explorer, launch, mozilla, mozilla firefox, nvidia, pc infiziert, picasa, plug-in, problem, programme, quara, rundll, scan, schuelervz, security, security scan, software, system, trojaner, urlsearchhook, windows, windows xp |