|
Log-Analyse und Auswertung: Microsoft Visual C++Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
29.09.2008, 18:36 | #1 |
| Microsoft Visual C++ Hallo, ich habe das Prog. für meine Logitech Quick Cam installieren wollen und bekomme eine ziemlich magere, kleine Fehlermeldung von Microsoft Visual C++. Ohne weiteren Link etc. nur mit einer Reportdatei. Inhalt wie folgt: <?xml version="1.0" encoding="UTF-16"?> <DATABASE> <EXE NAME="Setup.exe" FILTER="GRABMI_FILTER_PRIVACY"> <MATCHING_FILE NAME="Setup.exe" SIZE="578832" CHECKSUM="0xE44B2D8E" BIN_FILE_VERSION="11.80.1065.0" BIN_PRODUCT_VERSION="11.80.1065.0" PRODUCT_VERSION="11.80.1065.0" FILE_DESCRIPTION="Setup program" COMPANY_NAME="Logitech Inc." PRODUCT_NAME="Logitech QuickCam" FILE_VERSION="11.80.1065.0" ORIGINAL_FILENAME="Setup.exe" INTERNAL_NAME="Setup.exe" LEGAL_COPYRIGHT="(c) 1996-2008 Logitech. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x10001" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x9A07D" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="11.80.1065.0" UPTO_BIN_PRODUCT_VERSION="11.80.1065.0" LINK_DATE="08/15/2008 00:07:38" UPTO_LINK_DATE="08/15/2008 00:07:38" VER_LANGUAGE="Englisch (USA) [0x409]" /> <MATCHING_FILE NAME="videoc.dll" SIZE="1414416" CHECKSUM="0xD4AC7FEA" BIN_FILE_VERSION="11.80.1065.0" BIN_PRODUCT_VERSION="11.80.1065.0" PRODUCT_VERSION="11.80.1065.0" FILE_DESCRIPTION="VideoControl Library" COMPANY_NAME="Logitech Inc." PRODUCT_NAME="Logitech QuickCam" FILE_VERSION="11.80.1065.0" ORIGINAL_FILENAME="VideoC.dll" INTERNAL_NAME="VideoC.dll" LEGAL_COPYRIGHT="(c) 1996-2008 Logitech. All rights reserved." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x10001" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x15C7F5" LINKER_VERSION="0x0" UPTO_BIN_FILE_VERSION="11.80.1065.0" UPTO_BIN_PRODUCT_VERSION="11.80.1065.0" LINK_DATE="08/15/2008 00:03:55" UPTO_LINK_DATE="08/15/2008 00:03:55" VER_LANGUAGE="Englisch (USA) [0x409]" /> </EXE> <EXE NAME="kernel32.dll" FILTER="GRABMI_FILTER_THISFILEONLY"> <MATCHING_FILE NAME="kernel32.dll" SIZE="1057280" CHECKSUM="0xD52AA7B7" BIN_FILE_VERSION="5.1.2600.2180" BIN_PRODUCT_VERSION="5.1.2600.2180" PRODUCT_VERSION="5.1.2600.2180" FILE_DESCRIPTION="Client-DLL für Windows NT-Basis-API" COMPANY_NAME="Microsoft Corporation" PRODUCT_NAME="Betriebssystem Microsoft® Windows®" FILE_VERSION="5.1.2600.2180 (xpsp_sp2_rtm.040803-2158)" ORIGINAL_FILENAME="kernel32" INTERNAL_NAME="kernel32" LEGAL_COPYRIGHT="© Microsoft Corporation. Alle Rechte vorbehalten." VERFILEDATEHI="0x0" VERFILEDATELO="0x0" VERFILEOS="0x40004" VERFILETYPE="0x2" MODULE_TYPE="WIN32" PE_CHECKSUM="0x108430" LINKER_VERSION="0x50001" UPTO_BIN_FILE_VERSION="5.1.2600.2180" UPTO_BIN_PRODUCT_VERSION="5.1.2600.2180" LINK_DATE="08/04/2004 07:57:08" UPTO_LINK_DATE="08/04/2004 07:57:08" VER_LANGUAGE="Deutsch (Deutschland) [0x407]" /> </EXE> </DATABASE> Keine Ahnung ob das was bringt?! Ansonsten Logfile: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 19:33:40, on 29.09.2008 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\csrss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\RTHDCPL.EXE C:\WINDOWS\system32\RUNDLL32.EXE C:\Programme\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe C:\Programme\iTunes\iTunesHelper.exe C:\Programme\Java\jre1.6.0_07\bin\jusched.exe C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Programme\Logitech\GamePanel Software\LCD Manager\LCDMon.exe C:\Programme\Logitech\GamePanel Software\G-series Software\LGDCore.exe C:\Programme\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe C:\Programme\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe C:\Programme\Logitech\GamePanel Software\LCD Manager\Applets\LCDPop3.exe C:\Programme\Logitech\GamePanel Software\LCD Manager\Applets\LCDMedia.exe C:\WINDOWS\system32\ctfmon.exe C:\PROGRA~1\ICQ6\ICQ.exe C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe C:\Programme\Bonjour\mDNSResponder.exe C:\Programme\ICQ6Toolbar\ICQ Service.exe C:\Programme\Logitech\Desktop Messenger\8876480\Program\LogitechDesktopMessenger.exe C:\Programme\Logitech\SetPoint II\SetpointII.exe C:\WINDOWS\System32\nvsvc32.exe C:\Programme\Gemeinsame Dateien\Logishrd\KHAL2\KHALMNPR.EXE C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\wdfmgr.exe C:\Programme\iPod\bin\iPodService.exe C:\WINDOWS\System32\alg.exe C:\Programme\Mozilla Firefox\firefox.exe C:\WINDOWS\system32\msiexec.exe C:\Programme\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\System32\wbem\wmiprvse.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/ R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local R3 - URLSearchHook: (no name) - - (no file) R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Programme\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /s O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [Launch LCDMon] "C:\Programme\Logitech\GamePanel Software\LCD Manager\LCDMon.exe" O4 - HKLM\..\Run: [Launch LGDCore] "C:\Programme\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKCU\..\Run: [ICQ] "C:\PROGRA~1\ICQ6\ICQ.exe" silent O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user') O4 - Global Startup: SetPointII.lnk = ? O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL O23 - Service: Avira AntiVir Personal - Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Programme\Bonjour\mDNSResponder.exe O23 - Service: ICQ Service - Unknown owner - C:\Programme\ICQ6Toolbar\ICQ Service.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe O23 - Service: Process Monitor (LVPrcSrv) - Unknown owner - c:\programme\gemeinsame dateien\logitech\lvmvfm\LVPrcSrv.exe (file missing) O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: TuneUp Drive Defrag-Dienst (TuneUp.Defrag) - TuneUp Software GmbH - C:\WINDOWS\System32\TuneUpDefragService.exe -- End of file - 6329 bytes Habe heute erst ein System-Reboot hinter mir, wobei ich nicht verstehen kann wieso das nicht klappt?! Würde mich auf Antwort freuen! |
06.10.2008, 13:27 | #2 | |
Gast | Microsoft Visual C++Zitat:
Das was du da hast sieht eher nach einer hp aus xml ist ein format genauso wie html(siehe unten) Ich hoffe das ich dich auf die richtige spur gebracht habe html dir="ltr" lang="de"><head> <meta http-equiv="Content-Type" content="text/html; charset=ISO-8859-15"> <meta http-equiv="Content-Style-Type" content="text/css"> <!-- This OnlineStore is brought to you by XT-Commerce, Community made shopping XTC is a free open source e-Commerce System created by Mario Zanier & Guido Winger and licensed under GNU/GPL. Information and contribution at http://www.xt-commerce.com --> <meta name="generator" content="(c) by xt:Commerce v3.0.4 , http://www.xt-commerce.com"> <meta name="robots" content="index,follow"> <meta name="language" content="de,at,ch"> <meta name="author" content="Figuren - Gothic - Shop"> <meta name="publisher" content="Figuren - Gothic - Shop"> <meta name="company" content="Figuren - Gothic - Shop"> <meta name="page-topic" content="Gothic Shopping"><meta name="reply-to" content="info@figuren-shop.de"> <meta name="distribution" content="global"> <meta name="revisit-after" content=""> <meta name="description" content=""> <meta name="keywords" content=""> <title>Gothic Figuren Shop - Widderschädel - Totenkopf</title> <!-- base href="http://www.figuren-shop.de/gothic-shop/" --> <link rel="stylesheet" type="text/css" href="Widderschaedel-Totenkopf%203244-Dateien/stylesheet.css"> <script type="text/javascript" src="Widderschaedel-Totenkopf%203244-Dateien/mootools.js"> </script> <script type="text/javascript" src="Widderschaedel-Totenkopf%203244-Dateien/slimbox.js"></script> <link rel="stylesheet" href="Widderschaedel-Totenkopf%203244-Dateien/slimbox.css" type="text/css" media="screen"> <script type="text/javascript"><!-- var selected; var submitter = null; function submitFunction() { submitter = 1;} function popupWindow(url) { window.open(url,'popupWindow','toolbar=no,location=no,directories=no,status=no,menubar=no,scrollbars=yes,resizable=yes,copyhistory=no,width=100,height =100,screenX=150,screenY=150,top=50,left=150') } function selectRowEffect(object, buttonSelect) { if (!selected) { if (document.getElementById) { selected = document.getElementById('defaultSelected'); } else { selected = document.all['defaultSelected']; } } if (selected) selected.className = 'moduleRow'; object.className = 'moduleRowSelected'; selected = object; // one button is not an array if (document.getElementById('payment'[0])) { document.getElementById('payment'[buttonSelect]).checked=true; } else { //document.getElementById('payment'[selected]).checked=true; } } function rowOverEffect(object) { if (object.className == 'moduleRow') object.className = 'moduleRowOver'; } function rowOutEffect(object) { if (object.className == 'moduleRowOver') object.className = 'moduleRow'; } function popupImageWindow(url) { window.open(url,'popupImageWindow','toolbar=no,location=no,directories=no,status=no,menubar=no,scrollbars=no,resizable=yes,copyhistory=no,width=100,he ight=100,screenX=150,screenY=150,top=150,left=150') } //--></script> <script type="text/javascript"><!-- statit=new Image(3,2); statit.src="http://www.figuren-shop.de/statit4/statit.php?st_id=4&st_w="+screen.width+"&st_h="+screen.height+"&st_c="+screen.colorDepth+"&st_ref="+encodeURIComponent(document.referrer)+"&st_dat="+e ncodeURIComponent(window.location.pathname+window.location.search); //--></script> </head><body> <div id="Layer1" style="position: absolute; left: 10px; top: 10px; width: 5px; height: 5px; z-index: 1; visibility: hidden;">xtc_fr24 Template IDxtc_frings24 Template by Hartmut Frings</div> <table class="tableShop" align="center" cellpadding="0" cellspacing="0" width="100%"> <tbody><tr> <td> <table class="box" border="0" cellpadding="0" cellspacing="0" width="100%"> <tbody><tr> <td><div class="box_ol"></div></td> <td class="box_om"></td> <td><div class="box_or"></div></td> </tr> <tr> <td class="box_ml"></td> <td><div class="box_mm"> <table class="header" border="0" cellpadding="0" cellspacing="0" width="100%"> <tbody><tr> <td class="pageHeaderleft"></td> <td class="pageHeaderright"> <table align="right" border="0" cellpadding="0" cellspacing="0" width="100%"> <tbody><tr><td nowrap="nowrap"><div align="center"> </div></td> <td nowrap="nowrap"><div align="center"> <a href="http://www.figuren-shop.de/gothic-shop/account.php"><img src="Widderschaedel-Totenkopf%203244-Dateien/konto.png" align="middle"></a> <br> <a href="http://www.figuren-shop.de/gothic-shop/account.php"><font color="#ffffff">Ihr Konto</font></a></div></td> <td nowrap="nowrap"><div align="center"><a href="http://www.figuren-shop.de/gothic-shop/checkout_shipping.php"><img src="Widderschaedel-Totenkopf%203244-Dateien/kasse.png" align="middle"></a><br> <a href="http://www.figuren-shop.de/gothic-shop/checkout_shipping.php"><font color="#ffffff">Kasse</font></a></div></td> <td nowrap="nowrap"><div align="center"><a href="http://www.figuren-shop.de/gothic-shop/shopping_cart.php"><img src="Widderschaedel-Totenkopf%203244-Dateien/cart.png" align="middle"></a><br> <a href="http://www.figuren-shop.de/gothic-shop/checkout_shipping.php"><font color="#ffffff">Warenkorb</font></a></div></td> </tr></tbody></table> </td> </tr> </tbody></table> </div> </td> <td class="box_mr"></td> </tr> <tr> <td><div class="box_ul2"></div></td> <td class="box_um2"></td> <td><div class="box_ur2"></div></td> </tr> </tbody></table> </td> </tr> <tr> <td> <table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"> <tbody><tr> <td class="navileiste_1"></td> <td class="navileiste_2"><a href="http://www.figuren-shop.de/" class="headerNavigation">Startseite</a> » <a href="http://www.figuren-shop.de/gothic-shop/index.php" class="headerNavigation">Katalog</a> » <a href="http://www.figuren-shop.de/gothic-shop/Totenkoepfe:::92.html" class="headerNavigation">Totenköpfe</a> » <a href="http://www.figuren-shop.de/gothic-shop/Totenkoepfe/Widderschaedel-Totenkopf::3244.html" class="headerNavigation">708-3401L</a></td> <td class="navileiste_3"></td> </tr> </tbody></table> </td> </tr> <tr> <td> <table align="center" border="0" cellpadding="0" cellspacing="0" width="100%"> <tbody><tr> <td align="center"> <img src="Widderschaedel-Totenkopf%203244-Dateien/auge_l.gif"><a href="http://www.figuren-shop.de/gothic-shop/specials.php"><img src="Widderschaedel-Totenkopf%203244-Dateien/angebote.png"></a><a href="http://www.figuren-shop.de/gothic-shop/products_new.php"><img src="Widderschaedel-Totenkopf%203244-Dateien/neuheiten.png"></a><a href="http://www.figuren-shop.de/gothic-shop/lager.php"><img src="Widderschaedel-Totenkopf%203244-Dateien/lager.png"></a><a href="http://www.figuren-shop.de/gothic-shop/reviews2.php"><img src="Widderschaedel-Totenkopf%203244-Dateien/bewertungen.png"></a><img src="Widderschaedel-Totenkopf%203244-Dateien/auge_r.gif"></td> Bis dahin |
Themen zu Microsoft Visual C++ |
adobe, antivir, antivirus, avg, avira, bho, bonjour, desktop, excel, exe, explorer, fehlermeldung, firefox, hijack, hijackthis, hkus\s-1-5-18, internet, internet explorer, launch, logfile, monitor, mozilla, nvidia, rundll, software, tuneup.defrag, urlsearchhook, windows, windows xp |