![]() |
|
Log-Analyse und Auswertung: Mein HiJackThis-LOG, habe explorer-ProblemeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
| ![]() Mein HiJackThis-LOG, habe explorer-Probleme Hallo, habe das Problem, dass mein explorer immer abstürzt, desktop dann komplett leer. vielleicht erkennt jemand das Problem in meinem Log : StartupList report, 17.09.2004, 23:10:45 StartupList version: 1.52.2 Started from : F:\TEST\Virus_Wurm\hjt.EXE Detected: Windows XP SP1 (WinNT 5.01.2600) Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106) * Using default options ================================================== Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\AVPersonal\AVGUARD.EXE C:\Programme\AVPersonal\AVWUPSRV.EXE C:\Programme\Gemeinsame Dateien\EPSON\EBAPI\SAgent2.exe C:\WINDOWS\System32\GEARSec.exe C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe D:\Programme_Test\MotherboardMonitor5\MBM5.EXE C:\Programme\AVPersonal\AVGNT.EXE C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe D:\Programme_Test\NetMeter\NetMeter.exe C:\WINDOWS\System32\wuauclt.exe C:\WINDOWS\explorer.exe C:\Programme\Internet Explorer\IEXPLORE.EXE F:\TEST\Virus_Wurm\hjt.exe -------------------------------------------------- Checking Windows NT UserInit: [HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon] UserInit = C:\WINDOWS\system32\userinit.exe, -------------------------------------------------- Autorun entries from Registry: HKLM\Software\Microsoft\Windows\CurrentVersion\Run NvCplDaemon = RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup MBM 5 = "D:\Programme_Test\MotherboardMonitor5\MBM5.EXE" AVGCtrl = "C:\Programme\AVPersonal\AVGNT.EXE" /min TkBellExe = "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot -------------------------------------------------- Autorun entries from Registry: HKCU\Software\Microsoft\Windows\CurrentVersion\Run D:\Programme_Test\NetMeter\NetMeter.exe = D:\Programme_Test\NetMeter\NetMeter.exe -------------------------------------------------- Shell & screensaver key from C:\WINDOWS\SYSTEM.INI: Shell=*INI section not found* SCRNSAVE.EXE=*INI section not found* drivers=*INI section not found* Shell & screensaver key from Registry: Shell=Explorer.exe SCRNSAVE.EXE=*Registry value not found* drivers=*Registry value not found* Policies Shell key: HKCU\..\Policies: Shell=*Registry key not found* HKLM\..\Policies: Shell=*Registry value not found* -------------------------------------------------- Enumerating Browser Helper Objects: (no name) - C:\Programme\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocx - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -------------------------------------------------- Enumerating Download Program Files: [ppctlcab] CODEBASE = http://www.pestscan.com/scanner/ppctlcab.cab OSD = C:\WINDOWS\Downloaded Program Files\OSD406.OSD [CoGSManager Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\GSManager.dll CODEBASE = http://gamingzone.ubisoft.com/dev/pa.../GSManager.cab [PPSDKActiveXScanner.MainScreen] InProcServer32 = C:\WINDOWS\Downloaded Program Files\PPSDKActiveXScanner.ocx CODEBASE = http://www.pestscan.com/scanner/axscanner.cab [Microsoft.WinRep] InProcServer32 = C:\WINDOWS\System32\Winrep.dll CODEBASE = https://webresponse.one.microsoft.co...veX/winrep.cab [RdxIE Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\RdxIE.dll CODEBASE = http://software-dl.real.com/133f5e1c...dxIE601_de.cab [WUWebControl Class] InProcServer32 = C:\WINDOWS\System32\wuweb.dll CODEBASE = http://v5.windowsupdate.microsoft.co...?1093029709390 [HouseCall-Kontrolle] InProcServer32 = C:\WINDOWS\DOWNLO~1\xscan53.ocx CODEBASE = http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab [AvxScanOnline Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\BITDEF~1.OCX CODEBASE = http://www.bitdefender.com/scan/Msie/bitdefender.cab [{91413D86-9F27-402C-B5E3-DEBDD122C339}] CODEBASE = http://content.netvenda.com/sites/ga.../de/games5.cab [ActiveScan Installer Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\asinst.dll CODEBASE = http://www.pandasoftware.com/activescan/as5/asinst.cab [{9F1C11AA-197B-4942-BA54-47A8489BB47F}] CODEBASE = http://v4.windowsupdate.microsoft.co...924.1870717593 [{A45F39DC-3608-4237-8F0E-139F1BC49464}] CODEBASE = http://www.mymovielist.net/debby/plugin.exe [WebResponseAttachments Control] InProcServer32 = C:\WINDOWS\DOWNLO~1\FILETR~1.OCX CODEBASE = https://webresponse.one.microsoft.co...X/FileXfer.cab [Shockwave Flash Object] InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash.ocx CODEBASE = http://download.macromedia.com/pub/s...sh/swflash.cab [IEPlugIn Class] InProcServer32 = C:\Programme\my-playlist\ieudsplugin.dll CODEBASE = http://install.cokemusic.de/client/p...LER_loader.exe [EPSImageControl Class] InProcServer32 = C:\WINDOWS\Downloaded Program Files\EPScontrol.dll CODEBASE = http://tools.ebayimg.com/eps/activex...l_v1-0-3-0.cab [MoneyTree Dialer] CODEBASE = http://cdn.climaxbucks.com/internet-...istIOcrack.CAB -------------------------------------------------- Enumerating ShellServiceObjectDelayLoad items: PostBootReminder: C:\WINDOWS\system32\SHELL32.dll CDBurn: C:\WINDOWS\system32\SHELL32.dll WebCheck: C:\WINDOWS\System32\webcheck.dll SysTray: C:\WINDOWS\System32\stobject.dll -------------------------------------------------- End of report, 6.259 bytes Report generated in 0,062 seconds Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only |
Themen zu Mein HiJackThis-LOG, habe explorer-Probleme |
adobe, browser, dateien, desktop, dll, download, explorer, helper, hijack, internet, internet explorer, log, meinem, microsoft, nvcpl.dll, problem, programme, registry, registry key, registry value, rundll, saver, screensaver, shockwave, software, system, system32, update, userinit.exe, virus, windows, windows xp, wurm |