![]() |
|
Log-Analyse und Auswertung: Internetseiten oeffnen sich einfach, TrojanerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #3 |
| ![]() Internetseiten oeffnen sich einfach, Trojaner dannach nochmal im runscan:
__________________Runscanner logfile http://www.runscanner.net * = signed file - = file not found General info ------------ Computer name : *** Creation time : 2008-12-16 14:38:39 Hosts <> 127.0.0.1 : 0 Hosts file location : %SystemRoot%\System32\drivers\etc IE version : 7.0.5730.13 OS : Microsoft Windows XP OS Build : 2600 OS SP : Dodatek Service Pack 2 RunScanner Version : 1.7.0.0 User Language : Polski User rights : Administrator Windows folder : C:\WINDOWS Running processes ----------------- C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe * C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe (Adobe Systems Incorporated) C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (Avira GmbH) C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (Avira GmbH) C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe (Avira GmbH) * C:\WINDOWS\system32\winlogon.exe (Microsoft Corporation) C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe * C:\WINDOWS\System32\alg.exe (Microsoft Corporation) C:\WINDOWS\System32\ALERTM~1\ALERTM~1.EXE C:\PROGRA~1\NEOSTR~1\Inactivity.exe C:\PROGRA~1\NEOSTR~1\Toaster.exe (France Telecom R&D) C:\PROGRA~1\NEOSTR~1\PollingModule.exe C:\Program Files\Sony Ericsson\Mobile2\Mobile Phone Monitor\epmworker.exe (Sony Ericsson Mobile Communications AB) * C:\WINDOWS\system32\csrss.exe (Microsoft Corporation) * D:\instalki\voipdiscount\voipdiscount.exe (VoipDiscount) * C:\WINDOWS\system32\ctfmon.exe (Microsoft Corporation) * C:\WINDOWS\Explorer.EXE (Microsoft Corporation) C:\PROGRA~1\NEOSTR~1\neostradatp.exe (France Télécom R&D) * D:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) C:\WINDOWS\System32\FTRTSVC.exe (France Telecom) C:\Program Files\Common Files\Teleca Shared\Generic.exe (Teleca AB) * C:\WINDOWS\system32\svchost.exe (Microsoft Corporation) * C:\WINDOWS\system32\svchost.exe (Microsoft Corporation) * C:\WINDOWS\system32\svchost.exe (Microsoft Corporation) * C:\WINDOWS\System32\svchost.exe (Microsoft Corporation) * C:\WINDOWS\system32\svchost.exe (Microsoft Corporation) * C:\WINDOWS\system32\svchost.exe (Microsoft Corporation) C:\PROGRA~1\NEOSTR~1\TaskBarIcon.exe (France Télécom R&D) C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe (Hewlett-Packard) C:\Program Files\Hewlett-Packard\Toolbox2.0\Javasoft\JRE\1.3.1\bin\javaw.exe * C:\WINDOWS\system32\lsass.exe (Microsoft Corporation) * c:\windows\System32\smss.exe (Microsoft Corporation) C:\PROGRA~1\NEOSTR~1\ComComp.exe (France Télécom R&D) C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Corporation) * D:\Program Files\Picasa2\PicasaMediaDetector.exe (Google Inc.) D:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.) C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.) * D:\RunScanner.exe (Runscanner.net) * C:\WINDOWS\system32\spoolsv.exe (Microsoft Corporation) C:\PROGRA~1\NEOSTR~1\Watch.exe (France Télécom R&D) * C:\WINDOWS\system32\RUNDLL32.EXE (Microsoft Corporation) * C:\WINDOWS\system32\services.exe (Microsoft Corporation) * C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe (Microsoft Corporation) * C:\WINDOWS\system32\wscntfy.exe (Microsoft Corporation) * C:\WINDOWS\system32\wdfmgr.exe (Microsoft Corporation) Unrated items ------------- 002 C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe (Avira GmbH) 002 C:\WINDOWS\system32\NvCpl.dll (NVIDIA Corporation) 002 C:\WINDOWS\system32\NvMcTray.dll (NVIDIA Corporation) 002 d:\Program Files\PowerISO\PWRISOVM.EXE (PowerISO Computing, Inc.) 002 C:\Program Files\QuickTime\qttask.exe (Apple Computer, Inc.) 002 C:\Program Files\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe 002 C:\Program Files\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe (Hewlett-Packard) 002 C:\Program Files\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe (Hewlett-Packard) 002 C:\PROGRA~1\NEOSTR~1\GestMaj.exe (France Télécom R&D) 002 C:\PROGRA~1\NEOSTR~1\Watch.exe (France Télécom R&D) 003 * C:\Documents and Settings\***\Ustawienia lokalne\Dane aplikacji\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe (Octoshape ApS) 003 * D:\instalki\voipdiscount\voipdiscount.exe (VoipDiscount) 005 C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe 010 C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe (Avira AntiVir Personal - Free Antivirus Guard) 010 C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe (Avira AntiVir Personal - Free Antivirus Planer) 010 C:\WINDOWS\System32\FTRTSVC.exe (France Telecom Routing Table Service) 010 C:\WINDOWS\system32\nvsvc32.exe (NVIDIA Display Driver Service) 011 * C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgio.sys (avgio) 011 * C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgntflt.sys (avgntflt) 011 * C:\WINDOWS\system32\DRIVERS\avipbb.sys (avipbb) 011 C:\WINDOWS\System32\Drivers\e4ldr.sys (General Purpose USB Driver (e4ldr.sys)) 011 C:\WINDOWS\system32\DRIVERS\nv4_mini.sys (nv) 011 * C:\WINDOWS\system32\drivers\pavboot.sys (pavboot) 011 C:\WINDOWS\system32\PCANDIS5.SYS (PCANDIS5 NDIS Protocol Driver) 011 * C:\WINDOWS\System32\Drivers\PxHelp20.sys (PxHelp20) 011 C:\WINDOWS\system32\drivers\SCDEmu.sys (SCDEmu) 011 * C:\WINDOWS\system32\DRIVERS\s816bus.sys (Sony Ericsson Device 816 driver (WDM)) 011 * C:\WINDOWS\system32\DRIVERS\s816nd5.sys (Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (NDIS)) 011 * C:\WINDOWS\system32\DRIVERS\s816unic.sys (Sony Ericsson Device 816 USB Ethernet Emulation SEMCMR7 (WDM)) 011 * C:\WINDOWS\system32\DRIVERS\s816mgmt.sys (Sony Ericsson Device 816 USB WMC Device Management Drivers (WDM)) 011 * C:\WINDOWS\system32\DRIVERS\s816mdm.sys (Sony Ericsson Device 816 USB WMC Modem Driver) 011 * C:\WINDOWS\system32\DRIVERS\s816mdfl.sys (Sony Ericsson Device 816 USB WMC Modem Filter) 011 * C:\WINDOWS\system32\DRIVERS\s816obex.sys (Sony Ericsson Device 816 USB WMC OBEX Interface) 011 C:\WINDOWS\System32\Drivers\sptd.sys (sptd) 011 C:\WINDOWS\system32\DRIVERS\ssmdrv.sys (ssmdrv) 011 C:\WINDOWS\system32\DRIVERS\e4usbaw.sys (USB ADSL2 WAN Adapter) 011 C:\WINDOWS\System32\Drivers\pcouffin.sys (VSO Software pcouffin) 040 C:\PROGRA~1\NEOSTR~1\SEARCH~1.DLL {08C06D61-F1F3-4799-86F8-BE1A89362C85} 061 C:\WINDOWS\system32\nvshell.dll {1CDB2949-8F65-4355-8456-263E7C208A5D} 061 C:\WINDOWS\system32\nvshell.dll {1E9B04FB-F9E5-4718-997B-B8DA88302A47} 061 d:\Program Files\Codec\Haali\mmfinfo.dll {0561EC90-CE54-4f0c-9C55-E226110A740C} 061 d:\Program Files\Codec\Haali\mmfinfo.dll {5574006C-28F5-4a65-A28C-74DE6BFBE0BB} 061 d:\Program Files\Codec\Haali\mmfinfo.dll {327669A0-59A7-4be9-B99E-1C9F3A57611A} 061 C:\Program Files\Sony Ericsson\Mobile2\File Manager\FM.dll (Popwire AB) {03DAACC5-10BA-4E3E-9D54-2A569F6B4B87} 061 C:\Program Files\Sony Ericsson\Mobile2\File Manager\FM.dll (Popwire AB) {738D66C6-0149-4D40-84E4-A7BB2D0CE949} 061 C:\WINDOWS\system32\nvcpl.dll (NVIDIA Corporation) {A70C977A-BF00-412C-90B7-034C51DA2439} 061 C:\WINDOWS\system32\nvshell.dll {1E9B04FB-F9E5-4718-997B-B8DA88302A48} 061 C:\WINDOWS\system32\nvcpl.dll (NVIDIA Corporation) {FFB699E0-306A-11d3-8BD1-00104B6F7516} 061 d:\Program Files\PowerISO\PWRISOSH.DLL (PowerISO Computing, Inc.) {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} 061 C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll (Avira GmbH) {45AC2688-0253-4ED8-97DE-B5370FA7D48A} 061 * C:\PROGRA~1\TUNEUP~1\SDShelEx-win32.dll (TuneUp Software GmbH) {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} 061 * C:\WINDOWS\system32\uxtuneup.dll (TuneUp Software GmbH) {44440D00-FF19-4AFC-B765-9A0970567D97} 061 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA} 062 d:\Program Files\Codec\Haali\mmfinfo.dll {0561EC90-CE54-4f0c-9C55-E226110A740C} 100 Start Page HKCU : http://www.google.pl/ 104 GUID / CLSID not found {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} 105 &Windows Live Search : res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm 105 E&ksport do programu Microsoft Excel : res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 105 ÓñČĚŘľ«ÁéĎÂÔŘ(&B) : 105 Pobierz z &BitSpirit : D:\Program Files\BitSpirit\bsurl.htm 120 NameServer {F988697C-6960-41E0-985F-D99BFE9132DB} : 194.204.159.1 217.98.63.164 170 {1d060757-76f4-11db-a7b8-806d6172696f} : C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com c: 170 {1d060758-76f4-11db-a7b8-806d6172696f} : C:\WINDOWS\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL resycled\boot.com d: 173 d:\Program Files\PowerISO\PWRISOSH.DLL (PowerISO Computing, Inc.) {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} 173 C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll (Avira GmbH) {45AC2688-0253-4ED8-97DE-B5370FA7D48A} 173 * C:\PROGRA~1\TUNEUP~1\SDShelEx-win32.dll (TuneUp Software GmbH) {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} 173 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA} 221 d:\Program Files\PowerISO\PWRISOSH.DLL (PowerISO Computing, Inc.) {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} 221 C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll (Avira GmbH) {45AC2688-0253-4ED8-97DE-B5370FA7D48A} 221 * C:\PROGRA~1\TUNEUP~1\SDShelEx-win32.dll (TuneUp Software GmbH) {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} 221 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA} 225 d:\Program Files\PowerISO\PWRISOSH.DLL (PowerISO Computing, Inc.) {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} 225 d:\Program Files\PowerISO\PWRISOSH.DLL (PowerISO Computing, Inc.) {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} 225 C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll (Avira GmbH) {45AC2688-0253-4ED8-97DE-B5370FA7D48A} 225 C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll (Avira GmbH) {45AC2688-0253-4ED8-97DE-B5370FA7D48A} 225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA} 225 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA} 227 d:\Program Files\PowerISO\PWRISOSH.DLL (PowerISO Computing, Inc.) {967B2D40-8B7D-4127-9049-61EA0C2C6DCE} 227 * C:\PROGRA~1\TUNEUP~1\SDShelEx-win32.dll (TuneUp Software GmbH) {4858E7D9-8E12-45a3-B6A3-1CD128C9D403} 227 C:\Program Files\WinRAR\rarext.dll {B41DB860-8EE4-11D2-9906-E49FADC173CA} 229 C:\WINDOWS\system32\nvshell.dll {1E9B04FB-F9E5-4718-997B-B8DA88302A48} 229 C:\WINDOWS\system32\nvcpl.dll (NVIDIA Corporation) {A70C977A-BF00-412C-90B7-034C51DA2439} 231 d:\Program Files\Codec\Haali\mmfinfo.dll Haali Column Provider Missing files ------------- 011 C:\WINDOWS\system32\drivers\Abiosdsk.sys 011 C:\WINDOWS\system32\drivers\abp480n5.sys 011 C:\WINDOWS\system32\drivers\adpu160m.sys 011 C:\WINDOWS\system32\drivers\Aha154x.sys 011 C:\WINDOWS\system32\drivers\aic78u2.sys 011 C:\WINDOWS\system32\drivers\aic78xx.sys 011 C:\WINDOWS\system32\drivers\AliIde.sys 011 C:\WINDOWS\system32\drivers\amsint.sys 011 C:\WINDOWS\system32\drivers\asc.sys 011 C:\WINDOWS\system32\drivers\asc3350p.sys 011 C:\WINDOWS\system32\drivers\asc3550.sys 011 C:\WINDOWS\system32\drivers\Atdisk.sys 011 C:\WINDOWS\system32\drivers\cd20xrnt.sys 011 C:\WINDOWS\system32\drivers\Changer.sys 011 C:\WINDOWS\system32\drivers\CmdIde.sys 011 C:\WINDOWS\system32\drivers\Cpqarray.sys 011 C:\WINDOWS\system32\drivers\dac2w2k.sys 011 C:\WINDOWS\system32\drivers\dac960nt.sys 011 C:\WINDOWS\system32\drivers\dpti2o.sys 011 E:\INSTALL\GMSIPCI.SYS 011 C:\WINDOWS\system32\drivers\hpn.sys 011 C:\WINDOWS\system32\drivers\i2omgmt.sys 011 C:\WINDOWS\system32\drivers\i2omp.sys 011 C:\WINDOWS\system32\drivers\ini910u.sys 011 C:\WINDOWS\system32\drivers\IntelIde.sys 011 C:\WINDOWS\system32\drivers\lbrtfdc.sys 011 C:\WINDOWS\system32\drivers\mraid35x.sys 011 E:\NTACCESS.sys 011 c:\windows\system32\drivers\PalmUSBD.sys 011 C:\WINDOWS\system32\PCAMPR5.SYS 011 C:\WINDOWS\system32\drivers\PCIDump.sys 011 C:\WINDOWS\system32\drivers\PCIIde.sys 011 C:\WINDOWS\system32\drivers\PDCOMP.sys 011 C:\WINDOWS\system32\drivers\PDFRAME.sys 011 C:\WINDOWS\system32\drivers\PDRELI.sys 011 C:\WINDOWS\system32\drivers\PDRFRAME.sys 011 C:\WINDOWS\system32\drivers\perc2.sys 011 C:\WINDOWS\system32\drivers\perc2hib.sys 011 C:\WINDOWS\system32\drivers\ql1080.sys 011 C:\WINDOWS\system32\drivers\Ql10wnt.sys 011 C:\WINDOWS\system32\drivers\ql12160.sys 011 C:\WINDOWS\system32\drivers\ql1240.sys 011 C:\WINDOWS\system32\drivers\ql1280.sys 011 E:\NTGLM7X.sys 011 C:\WINDOWS\system32\drivers\Simbad.sys 011 C:\WINDOWS\system32\drivers\Sparrow.sys 011 C:\WINDOWS\system32\drivers\sym_hi.sys 011 C:\WINDOWS\system32\drivers\sym_u3.sys 011 C:\WINDOWS\system32\drivers\symc810.sys 011 C:\WINDOWS\system32\drivers\symc8xx.sys 011 C:\WINDOWS\system32\drivers\TosIde.sys 011 C:\WINDOWS\system32\drivers\ultra.sys 011 C:\WINDOWS\system32\drivers\WDICA.sys 061 deskpan.dll 121 fopumn.dll 167 C:\Program Files\WebMediaViewer\itunes.exe hoffe das bring euch weiter ![]() |
Themen zu Internetseiten oeffnen sich einfach, Trojaner |
adobe, antivir, antivirus, application, avira, content.ie5, downloader, excel, explorer, file, firefox, hijack, hijackthis, hkus\s-1-5-18, internet explorer, messenger, micro, microsoft, monitor, namen, neue, nvidia, photoshop, picasa, poweriso, programm, seiten, software, trojane, trojaner, windows xp |