![]() |
|
Log-Analyse und Auswertung: Firefox "ein anderes Programm...Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #6 |
![]() | ![]() Firefox "ein anderes Programm... ======Scheduled tasks folder====== C:\WINDOWS\tasks\AppleSoftwareUpdate.job C:\WINDOWS\tasks\Google Software Updater.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineCore.job C:\WINDOWS\tasks\GoogleUpdateTaskMachineUA.job C:\WINDOWS\tasks\WGASetup.job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Adobe PDF Reader - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [2006-10-22 62080] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5CA3D70E-1895-11CF-8E15-001234567890}] DriveLetterAccess - C:\WINDOWS\System32\DLA\DLASHX_W.DLL [2005-10-06 110652] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{AF69DE43-7D58-4638-B6FA-CE66B5AD205D}] Google Toolbar Notifier BHO - C:\Programme\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll [2009-03-30 668656] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA}] ZoneAlarm Spy Blocker BHO - C:\Programme\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-11-05 262144] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - ZoneAlarm Spy Blocker - C:\Programme\ZoneAlarmSB\bar\1.bin\SPYBLOCK.DLL [2008-11-05 262144] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "ATICCC"=C:\Programme\ATI Technologies\ATI.ACE\cli.exe [2005-08-12 45056] "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2005-12-10 15691264] "Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-04 69632] "AGRSMMSG"=C:\WINDOWS\AGRSMMSG.exe [2005-10-15 88203] "TPSMain"=C:\WINDOWS\system32\TPSMain.exe [2005-08-03 266240] "TFncKy"=TFncKy.exe [] "DLA"=C:\WINDOWS\System32\DLA\DLACTRLW.EXE [2005-10-06 122940] "CFSServ.exe"=CFSServ.exe -NoClient [] "KernelFaultCheck"=C:\WINDOWS\system32\dumprep 0 -k [] "SmoothView"=C:\Programme\TOSHIBA\TOSHIBA Zoom-Dienstprogramm\SmoothView.exe [2005-05-13 118784] "Adobe Reader Speed Launcher"=C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe [2007-10-10 39792] "PDFPrint"=C:\Programme\PDFDrucker\PDFPrintBackend.exe [2005-07-03 71080] "avgnt"=C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe [2008-06-12 266497] "Adobe Photo Downloader"=C:\Programme\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe [2005-06-23 57344] "AppleSyncNotifier"=C:\Programme\Gemeinsame Dateien\Apple\Mobile Device Support\bin\AppleSyncNotifier.exe [2009-03-06 177472] "QuickTime Task"=C:\Programme\QuickTime\QTTask.exe [2009-01-05 413696] "iTunesHelper"=C:\Programme\iTunes\iTunesHelper.exe [2009-04-02 342312] "ZoneAlarm Client"=C:\Programme\Zone Labs\ZoneAlarm\zlclient.exe [2009-02-16 981384] " Malwarebytes Anti-Malware (reboot)"=C:\Programme\Malwarebytes' Anti-Malware\mbam.exe [2009-09-10 1312080] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"=C:\WINDOWS\system32\ctfmon.exe [2004-08-04 15360] "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Programme\Gemeinsame Dateien\Ahead\Lib\NMBgMonitor.exe [2007-01-15 147456] "AdobeUpdater"=C:\Programme\Gemeinsame Dateien\Adobe\Updater5\AdobeUpdater.exe [2007-02-28 2321600] "MSMSGS"=C:\Programme\Messenger\msmsgs.exe [2004-10-13 1694208] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Adobe Photo Downloader] C:\Programme\Adobe\Photoshop Album Starter Edition\3.0\Apps\apdproxy.exe [2005-06-23 57344] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelWireless] C:\Programme\Intel\Wireless\Bin\ifrmewrk.exe [2005-11-28 602182] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\IntelZeroConfig] C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe [2005-12-05 667718] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\iTunesHelper] C:\Programme\iTunes\iTunesHelper.exe [2009-04-02 342312] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\MSMSGS] C:\Programme\Messenger\msmsgs.exe [2004-10-13 1694208] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NapsterShell] C:\Programme\Napster\napster.exe [2007-01-12 323216] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Ahead\Lib\NeroCheck.exe [2006-01-12 155648] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\QuickTime Task] C:\Programme\QuickTime\QTTask.exe [2009-01-05 413696] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Skype] C:\Programme\Skype\Phone\Skype.exe [2006-12-18 25365032] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Sony Ericsson PC Suite] C:\Programme\Sony Ericsson\Mobile2\Application Launcher\Application Launcher.exe [2006-11-24 487424] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\StatusClient] C:\Programme\Hewlett-Packard\Toolbox2.0\Apache Tomcat 4.0\webapps\Toolbox\StatusClient\StatusClient.exe [2002-12-16 36864] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe [2005-12-17 761945] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TDispVol] C:\WINDOWS\system32\TDispVol.exe [2005-09-16 73728] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\THotkey] C:\Programme\Toshiba\Toshiba Applet\thotkey.exe [2006-01-05 352256] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TomcatStartup] C:\Programme\Hewlett-Packard\Toolbox2.0\hpbpsttp.exe [2003-03-31 155648] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\TOSCDSPD] C:\Programme\TOSHIBA\TOSCDSPD\toscdspd.exe [2005-04-12 65536] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\Tvs] C:\Programme\TOSHIBA\Tvs\TvsTray.exe [2005-11-30 73728] [HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\updateMgr] C:\Programme\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_9 -reboot 1 [] C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart Bluetooth Manager.lnk - C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe EPSON Status Monitor 3 Environment Check.lnk - C:\WINDOWS\system32\spool\drivers\w32x86\3\E_SRCV03.EXE C:\Dokumente und Einstellungen\*****\Startmenü\Programme\Autostart Nikon Monitor.lnk - C:\Programme\Gemeinsame Dateien\Nikon\Monitor\NkMonitor.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\AtiExtEvent] C:\WINDOWS\system32\Ati2evxx.dll [2005-12-21 48128] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\igfxcui] C:\WINDOWS\system32\igfxdev.dll [2005-11-28 135168] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] C:\WINDOWS\system32\WgaLogon.dll [2008-09-06 267304] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa] "authentication packages"=msv1_0 nwprovau [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\vsmon] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "HonorAutoRunSetting"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "C:\Programme\Bonjour\mDNSResponder.exe"="C:\Programme\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour" "C:\Programme\iTunes\iTunes.exe"="C:\Programme\iTunes\iTunes.exe:*:Enabled:iTunes" "C:\Programme\Skype\Phone\Skype.exe"="C:\Programme\Skype\Phone\Skype.exe:*:Enabled:Skype" "C:\WINDOWS\system32\PnkBstrA.exe"="C:\WINDOWS\system32\PnkBstrA.exe:*:Enabled:PnkBstrA" "C:\WINDOWS\system32\PnkBstrB.exe"="C:\WINDOWS\system32\PnkBstrB.exe:*:Enabled:PnkBstrB" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" ======List of files/folders created in the last 1 months====== 2009-09-14 22:23:01 ----D---- C:\rsit 2009-09-14 22:00:39 ----D---- C:\WINDOWS\LastGood 2009-09-14 20:12:11 ----D---- C:\Programme\Trend Micro 2009-09-13 23:09:22 ----A---- C:\WINDOWS\system32\SET5D.tmp 2009-09-13 21:21:57 ----D---- C:\WINDOWS\ie8updates 2009-09-13 21:17:40 ----HDC---- C:\WINDOWS\ie8 2009-09-13 20:58:23 ----HDC---- C:\WINDOWS\$NtUninstallKB932823-v3$ 2009-09-11 22:47:59 ----D---- C:\Dokumente und Einstellungen\****\Anwendungsdaten\Malwarebytes 2009-09-11 22:47:52 ----D---- C:\Programme\Malwarebytes' Anti-Malware 2009-09-11 22:47:52 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes 2009-09-10 22:01:49 ----HDC---- C:\WINDOWS\$NtUninstallKB961118$ 2009-09-10 22:01:39 ----HDC---- C:\WINDOWS\$NtUninstallKB956844$ 2009-09-10 22:01:18 ----HDC---- C:\WINDOWS\$NtUninstallKB968816_WM9$ 2009-09-10 22:01:11 ----HDC---- C:\WINDOWS\$NtUninstallKB925720$ 2009-09-10 22:00:55 ----HDC---- C:\WINDOWS\$NtUninstallKB971961$ 2009-09-07 22:12:05 ----D---- C:\WINDOWS\system32\XPSViewer 2009-09-07 22:11:56 ----D---- C:\Programme\MSBuild 2009-09-07 22:11:52 ----D---- C:\WINDOWS\system32\en-US 2009-09-07 22:11:38 ----D---- C:\Programme\Reference Assemblies 2009-09-07 22:10:39 ----N---- C:\WINDOWS\system32\xpsshhdr.dll 2009-09-07 22:10:39 ----N---- C:\WINDOWS\system32\prntvpt.dll 2009-09-07 22:10:38 ----N---- C:\WINDOWS\system32\xpssvcs.dll 2009-09-07 22:10:37 ----D---- C:\dc5616a626ccba1cadbceb10ea 2009-09-07 22:02:32 ----HDC---- C:\WINDOWS\$NtUninstallWIC$ 2009-09-07 22:02:22 ----D---- C:\Programme\MSXML 6.0 2009-08-31 23:01:43 ----HDC---- C:\WINDOWS\$NtUninstallKB970653-v3$ 2009-08-15 21:01:02 ----HDC---- C:\WINDOWS\$NtUninstallKB968389$ 2009-08-15 19:12:29 ----HDC---- C:\WINDOWS\$NtUninstallKB960859$ 2009-08-15 19:12:18 ----HDC---- C:\WINDOWS\$NtUninstallKB971657$ 2009-08-15 19:12:09 ----HDC---- C:\WINDOWS\$NtUninstallKB971557$ 2009-08-15 19:11:57 ----HDC---- C:\WINDOWS\$NtUninstallKB973869$ 2009-08-15 19:11:41 ----HDC---- C:\WINDOWS\$NtUninstallKB973540_WM9L$ 2009-08-15 19:10:55 ----HDC---- C:\WINDOWS\$NtUninstallKB973507$ 2009-08-15 19:10:44 ----HDC---- C:\WINDOWS\$NtUninstallKB973354$ 2009-08-15 19:08:38 ----D---- C:\WINDOWS\ServicePackFiles 2009-08-15 19:08:35 ----HDC---- C:\WINDOWS\$NtUninstallKB958470$ 2009-08-15 19:08:22 ----HDC---- C:\WINDOWS\$NtUninstallKB973815$ 2009-08-15 19:08:00 ----HDC---- C:\WINDOWS\$NtUninstallKB971032$ ======List of files/folders modified in the last 1 months====== 2009-09-14 22:01:39 ----HD---- C:\WINDOWS\inf 2009-09-14 22:01:37 ----D---- C:\WINDOWS 2009-09-14 22:01:33 ----RSHDC---- C:\WINDOWS\system32\dllcache 2009-09-14 22:01:32 ----D---- C:\WINDOWS\system32 2009-09-14 22:01:01 ----D---- C:\WINDOWS\Temp 2009-09-14 22:00:40 ----HD---- C:\WINDOWS\$hf_mig$ 2009-09-14 20:12:11 ----RD---- C:\Programme 2009-09-14 19:08:21 ----SD---- C:\WINDOWS\Tasks 2009-09-14 19:08:13 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Google Updater 2009-09-14 18:13:39 ----D---- C:\WINDOWS\Internet Logs 2009-09-13 21:43:47 ----D---- C:\WINDOWS\Help 2009-09-13 21:28:55 ----D---- C:\WINDOWS\system32\CatRoot2 2009-09-13 21:25:39 ----D---- C:\WINDOWS\system32\Lang 2009-09-13 21:24:31 ----D---- C:\WINDOWS\system32\de-de 2009-09-13 21:24:29 ----D---- C:\WINDOWS\Media 2009-09-13 21:24:29 ----D---- C:\Programme\Internet Explorer 2009-09-13 21:23:28 ----A---- C:\WINDOWS\SchedLgU.Txt 2009-09-13 21:22:37 ----A---- C:\WINDOWS\imsins.BAK 2009-09-13 21:17:27 ----D---- C:\WINDOWS\Prefetch 2009-09-13 21:04:30 ----D---- C:\Programme\AskTBar 2009-09-13 21:02:18 ----D---- C:\Programme\Mozilla Firefox 2009-09-13 21:01:46 ----SHD---- C:\WINDOWS\Installer 2009-09-13 21:00:45 ----D---- C:\Programme\ElsterFormular 2009-09-12 19:24:29 ----D---- C:\WINDOWS\Microsoft.NET 2009-09-12 00:49:57 ----D---- C:\Dokumente und Einstellungen\****\Anwendungsdaten\Adobe 2009-09-11 22:48:34 ----D---- C:\WINDOWS\system32\drivers 2009-09-10 22:02:16 ----D---- C:\WINDOWS\system32\CatRoot 2009-09-08 07:54:00 ----RSD---- C:\WINDOWS\assembly 2009-09-07 22:20:35 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2009-09-07 22:19:31 ----D---- C:\WINDOWS\WinSxS 2009-09-07 22:11:48 ----RSD---- C:\WINDOWS\Fonts 2009-09-07 22:11:09 ----D---- C:\WINDOWS\system32\spool 2009-08-28 23:38:20 ----A---- C:\WINDOWS\system32\MRT.exe 2009-08-15 19:28:18 ----D---- C:\WINDOWS\system32\Setup 2009-08-15 19:11:11 ----D---- C:\WINDOWS\ie7updates 2009-08-15 19:10:47 ----D---- C:\Programme\Outlook Express |
Themen zu Firefox "ein anderes Programm... |
antivir, antivirus, avira, bho, bitte um hilfe, bonjour, downloader, excel, firefox, google, gupdate, hijack, hijackthis, hkus\s-1-5-18, home, internet, internet explorer, keine antwort, logfile, malwarebytes anti-malware, malwarebytes' anti-malware, monitor, programm, registry, schädling, software, symantec, system, windows, windows xp |