![]() |
|
Log-Analyse und Auswertung: EXP/Exploit.MS04-28.JPEG.A beim Drehen von BildernWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() EXP/Exploit.MS04-28.JPEG.A beim Drehen von Bildern Hallo PC-Kenner, schön dass es euch gibt! Problembeschreibung: Nachdem ich heute mit der Digitalkamera Bilder gemacht habe, diese auf den PC übertragen habe, wollte ich einige davon zurechtdrehen. Unabhängig davon, dass einige bilder halb-rosa, verschoben, überbelichtet oder andere merkwürdigkeiten aufweisen, erscheint eine Fehlermeldung von Antivir: "Auf Ihrem Computer wurde ein Virus oder unerwünschtes Programm gefunden!.. usw... C:\Users\XXXXXXX\AppData\Local\Temp\~PIB14A.tmp erhält das Erkennungsmuster des Exploits EXP/Exploit.MS04-28.JPEG.A" Man kann die Möglichkeit "Reparieren" nicht auswählen. Was kann das sein, ihr könnt mir sicher weiterhelfen, nachdem Google zu diesen Thema leider keine weiteren Informationen ausgespuckt hat.. Mein System: ASUS G2SV-7R011J OS: Vista Ultimate 64, SP1 Angeschlossene Hardware: Logitech MX518, Samsung CLP 315 (Drucker), ein SIGMA USB-Hub und eine Externe HDD von Maxtor Anhand des nachfolgenden HJT-Logs, könnt ihr mir sicher weiterhelfen, ich habe allen Anweisungen befolgt, damit der Log leserlich und anonym ist, ich hoffe das hat geklappt. Sollten jemandem zufällig unnütze Programme oder leistungsmindernder Abfall auffallen, könnt ihr mich anhand dieser "Psychoanalyse" sehr gern darauf aufmerksam machen. Vielen lieben Dank im Voraus! ![]() Hier der LOG: Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.2 Code:
ATTFilter Scan saved at 22:52:59, on 07.12.2008 Code:
ATTFilter Platform: Windows Vista SP1 (WinNT 6.00.1905) Code:
ATTFilter MSIE: Internet Explorer v7.00 (7.00.6001.18000) Code:
ATTFilter Boot mode: Normal Code:
ATTFilter Running processes: Code:
ATTFilter C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe Code:
ATTFilter C:\Program Files\ATKOSD2\ATKOSD2.exe Code:
ATTFilter C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe Code:
ATTFilter C:\Program Files\ASUS\ASUS Direct Console\LCMP.exe Code:
ATTFilter C:\Windows\Samsung\PanelMgr\SSMMgr.exe Code:
ATTFilter C:\Program Files\SetPoint\x86\SetPoint32.exe Code:
ATTFilter C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\avgnt.exe Code:
ATTFilter C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE Code:
ATTFilter C:\Program Files (x86)\Mozilla Firefox\firefox.exe Code:
ATTFilter C:\Program Files (x86)\Trillian\trillian.exe Code:
ATTFilter C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe Code:
ATTFilter C:\Program Files (x86)\Skype\Phone\Skype.exe Code:
ATTFilter C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe Code:
ATTFilter C:\Windows\SysWOW64\conime.exe Code:
ATTFilter C:\Users\XXXXXXXX\Desktop\HiJackThis.exe Code:
ATTFilter h**p://go.microsoft.com/fwlink/?LinkId=54896 Code:
ATTFilter h**p://go.microsoft.com/fwlink/?LinkId=69157 Code:
ATTFilter h**p://go.microsoft.com/fwlink/?LinkId=69157 Code:
ATTFilter h**p://go.microsoft.com/fwlink/?LinkId=54896 Code:
ATTFilter h**p://go.microsoft.com/fwlink/?LinkId=54896 Code:
ATTFilter h**p://go.microsoft.com/fwlink/?LinkId=69157 Code:
ATTFilter R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = Code:
ATTFilter R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = Code:
ATTFilter R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local Code:
ATTFilter R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Code:
ATTFilter F2 - REG:system.ini: UserInit=userinit.exe Code:
ATTFilter O1 - Hosts: ::1 localhost Code:
ATTFilter O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll Code:
ATTFilter O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll Code:
ATTFilter O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll Code:
ATTFilter O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll Code:
ATTFilter O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll Code:
ATTFilter O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file) Code:
ATTFilter O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe" Code:
ATTFilter O4 - HKLM\..\Run: [ATKMEDIA] "C:\Program Files (x86)\ASUS\ATK Media\DMEDIA.EXE" Code:
ATTFilter O4 - HKLM\..\Run: [zDirectMessenger] "C:\Program Files\ASUS\ASUS Direct Console\LCMP.EXE" Code:
ATTFilter O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe Code:
ATTFilter O4 - HKLM\..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun Code:
ATTFilter O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min Code:
ATTFilter O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun Code:
ATTFilter O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe Code:
ATTFilter O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST') Code:
ATTFilter O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST') Code:
ATTFilter O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST') Code:
ATTFilter O4 - Global Startup: SetPoint.lnk = ? Code:
ATTFilter O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000 Code:
ATTFilter O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll Code:
ATTFilter O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll Code:
ATTFilter O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll Code:
ATTFilter O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll Code:
ATTFilter O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll Code:
ATTFilter O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL Code:
ATTFilter O13 - Gopher Prefix: Code:
ATTFilter 16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - h**p://messenger.zone.msn.com/DE-DE/a-UNO1/GAME_UNO1.cab Code:
ATTFilter O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - h**p://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab Code:
ATTFilter O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - h**p://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab Code:
ATTFilter O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll Code:
ATTFilter O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL Code:
ATTFilter O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe Code:
ATTFilter O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe Code:
ATTFilter O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing) Code:
ATTFilter O23 - Service: Avira AntiVir Personal - Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\sched.exe Code:
ATTFilter O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\avguard.exe Code:
ATTFilter O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files (x86)\ATK Hotkey\ASLDRSrv.exe Code:
ATTFilter O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe Code:
ATTFilter O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe Code:
ATTFilter O23 - Service: Automatisches LiveUpdate - Scheduler (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe Code:
ATTFilter O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe Code:
ATTFilter O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing) Code:
ATTFilter O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe Code:
ATTFilter O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing) Code:
ATTFilter O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe Code:
ATTFilter O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe Code:
ATTFilter O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) Code:
ATTFilter O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE Code:
ATTFilter O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing) Code:
ATTFilter O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) Code:
ATTFilter O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing) Code:
ATTFilter O23 - Service: O&O Defrag - Unknown owner - C:\Windows\system32\oodag.exe (file missing) Code:
ATTFilter O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe Code:
ATTFilter O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe Code:
ATTFilter O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) Code:
ATTFilter O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe Code:
ATTFilter O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing) Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing) Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing) Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing) Code:
ATTFilter O23 - Service: spmgr - Unknown owner - C:\Program Files (x86)\ASUS\NB Probe\SPM\spmgr.exe Code:
ATTFilter O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing) Code:
ATTFilter O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe Code:
ATTFilter O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe Code:
ATTFilter O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - Unknown owner - C:\Windows\System32\TuneUpDefragService.exe (file missing) Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing) Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing) Code:
ATTFilter O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing) Code:
ATTFilter O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing) Code:
ATTFilter O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing) Code:
ATTFilter O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing) Code:
ATTFilter End of file - 10904 bytes |
Themen zu EXP/Exploit.MS04-28.JPEG.A beim Drehen von Bildern |
add-on, antivir, antivirus, avgnt.exe, avira, bho, bonjour, browser, computer, desktop, excel, firefox, firefox.exe, gfnexsrv.exe, google, hijack, hijackthis, local\temp, logfile, object, programm, scan, sched.exe, security, senden, skype.exe, software, symantec, system, syswow64, toolbars, tuneup.defrag, userinit.exe, virus, vista, windows, windows sidebar |