![]() |
|
Log-Analyse und Auswertung: Verschiedene Probleme nach BefallWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #11 |
![]() ![]() ![]() | ![]() Verschiedene Probleme nach Befall Ich habe mein Posting aufsplitten müssen. Bekam ständig eine Fehlermeldung. Liegt das eventuell an der Größe des Postings? Hier nun der weitere Teil. OTL Extras logfile created on: 27.04.2010 17:51:22 - Run 2 OTL by OldTimer - Version 3.2.3.0 Folder = C:\Dokumente und Einstellungen\User\Eigene Dateien Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 8.0.6001.18702) Locale: 00000407 | Country: Deutschland | Language: DEU | Date Format: dd.MM.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 70,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 88,00% Paging File free Paging file location(s): C:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Programme Drive C: | 149,04 Gb Total Space | 13,54 Gb Free Space | 9,09% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: NAME-9CF4F91750 Current User Name: User Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .exe [@ = secfile] -- C:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Anwendungsdaten\ave.exe () [HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>] .exe [@ = secfile] -- C:\WINDOWS\System32\config\systemprofile\Lokale Einstellungen\Anwendungsdaten\ave.exe File not found .html [@ = FirefoxHTML] -- C:\Programme\Mozilla Firefox\firefox.exe (Mozilla Corporation) ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [open] -- "%1" %* cmdfile [open] -- "%1" %* comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. piffile [open] -- "%1" %* regfile [merge] -- Reg Error: Key error. scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusOverride" = 1 "FirewallOverride" = 1 "AntiVirusDisableNotify" = 1 "FirewallDisableNotify" = 1 "UpdatesDisableNotify" = 1 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 1 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 0 "DoNotAllowExceptions" = 0 "DisableNotifications" = 1 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Programme\Bayern 3D\Bayern3D.exe" = C:\Programme\Bayern 3D\Bayern3D.exe:*:Enabled:Bayern3D -- () ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{00020407-78E1-11D2-B60F-006097C998E7}" = Microsoft Office 2000 Standard "{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 "{03B1B42B-F6DE-41d9-8CFF-DC44E895C7A7}" = PhotoGallery "{052FDD78-A6EA-3187-8386-C82F4CA3A929}" = Microsoft .NET Framework 3.5 Language Pack SP1 - deu "{09984AEC-6B9F-4ca7-B78D-CB44D4771DA3}" = Destinations "{15EE79F4-4ED1-4267-9B0F-351009325D7D}" = HP Software Update "{1FFBEF6F-98F3-4EEA-8103-7A85C1017D20}" = Geogrid®-Viewer "{21DB3D90-D816-4092-A260-CA3F6B55A6DD}" = Sonic_PrimoSDK "{23A7B376-BBEC-4e76-BBD7-0F155E70D74B}" = CP_Panorama1Config "{26A24AE4-039D-4CA4-87B4-2F83216016FF}" = Java(TM) 6 Update 19 "{2CADCEAB-D5DA-44D6-B5FC-7DEE87AB3C0C}" = Unload "{2D87E961-577B-492B-AD54-1368680FB9A7}" = Bing Maps 3D "{30C19FF2-7FBA-4d09-B9DE-1659977F64F6}" = TrayApp "{32BDCCB8-9DC8-496d-9DB1-F77510775BDB}" = InstantShareDevices "{350C97B3-3D7C-4EE8-BAA9-00BCB3D54227}" = WebFldrs XP "{36E47DA1-10E1-45d9-8B19-14D19607CDCF}" = CP_CalendarTemplates1 "{381D847E-7E56-4E82-B261-F799E0F40EB4}" = PHOTOfunSTUDIO 4.0 "{402ED4A1-8F5B-387A-8688-997ABF58B8F2}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729 "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{4ACBBFC6-3F39-48DE-8D85-182736B2749B}" = Garmin MapSource "{53EE9E42-CECB-4C92-BF76-9CA65DAF8F1C}" = FullDPAppQFolder "{56EE8B17-8274-418d-89AC-C057C5DB251E}" = RandMap "{56F8AFC3-FA98-4ff1-9673-8A026CBF85BE}" = WebReg "{5943B7F7-678B-477E-9AEE-6E4C6962322B}" = Sparwelt.de Gutschein Alarm "{5A01C58E-B0EC-49b9-AD71-7C0468688087}" = CP_Package_Basic1 "{5B622B7A-60FB-4630-B11D-F121D20BCCD6}" = MarketResearch "{5C161FB3-7E16-4771-9314-06FB37F3BBA7}" = Top50 V5 Viewer "{5F26311C-B135-4F7F-B11E-8E650F83651E}" = DeviceFunctionQFolder "{641FE800-650B-4E99-A304-9D50E7235BAF}" = Topo Deutschland v2 "{66BA8C26-AFE4-4408-807B-43E76B57EF53}" = SkinsHP1 "{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder "{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD "{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder "{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable "{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 "{79546A5F-AE7C-4693-8670-A3401B43ABD2}" = HP Deskjet 5900 series "{7E27304E-BAA2-4d90-A34E-76641FAFABB4}" = CP_AtenaShokunin1Config "{8234A27D-C5A4-4F84-8718-3BF34BCFC89F}" = JourneySoftwarePromo "{92DF2F1B-F63C-4D9A-B3E1-B2D11AE29790}" = Windows Presentation Foundation Language Pack (DEU) "{97C82B44-D408-4F14-9252-47FC1636D23E}_is1" = IZArc 3.81 "{A3051CD0-2F64-3813-A88D-B8DCCDE8F8C7}" = Microsoft .NET Framework 3.0 Service Pack 2 "{A5222E5A-13CB-4C98-9F5C-21CF6896A25C}" = HPDeskjet5900Series "{A5BB5365-EFB4-44c3-A7E2-EB59B7EFD23D}" = CueTour "{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder "{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.2 - Deutsch "{AF600F7B-67A7-48D9-BA3B-0FF97F35F970}" = ABBYY FineReader 6.0 Professional "{B996AE66-10DB-4ac5-B151-E8B4BFBC42FC}" = BufferChm "{BA9C8A3B-7A17-4A52-9F11-A6E823EE4305}" = Google SketchUp 7 "{BAF78226-3200-4DB4-BE33-4D922A799840}" = Windows Presentation Foundation "{C09FB3CD-3D0C-3F2D-899A-6A1D67F2073F}" = Microsoft .NET Framework 2.0 Service Pack 2 "{C2C284D2-6BD7-3B34-B0C5-B2CAED168DF7}" = Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU "{C314CE45-3392-3B73-B4E1-139CD41CA933}" = Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU "{C3896A21-47E5-4B40-9E90-529C1D6EDDF5}" = PDF Genie 3.0 "{C8B34404-2E52-4C1F-A2B7-D26E46E5974D}" = Norman Security Suite "{C9BED750-1211-4480-B1A5-718A3BE15525}" = REALTEK GbE & FE Ethernet PCI-E NIC Driver "{CB2F7EDD-9D1F-43C1-90FC-4F52EAE172A1}" = Microsoft .NET Framework 1.1 "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware Free Edition "{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1 "{E3F90083-80D4-4b5a-87C7-E97E12F5516D}" = HPProductAssistant "{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant "{E59113EB-0285-4BFD-A37A-B79EAC6B8F4B}" = Microsoft SQL Server Compact 3.5 SP1 English "{E78BFA60-5393-4C38-82AB-E8019E464EB4}" = Microsoft .NET Framework 1.1 German Language Pack "{EA103B64-C0E4-4C0E-A506-751590E1653D}" = SolutionCenter "{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver "{F2A7F421-1679-48D5-B918-96999014ED53}" = Microsoft .NET Framework 3.0 German Language Pack "{F4C2E5F5-2970-45f4-ABD3-C180C4D961C4}" = Status "Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Bayern 3D" = Bayern 3D "CCleaner" = CCleaner "Defraggler" = Defraggler (remove only) "Dr. Hardware 2009_is1" = Dr. Hardware 2009 9.9.5d "Exif-Viewer" = Exif-Viewer 2.50 "Free YouTube Download_is1" = Free YouTube Download 2.3 "Free YouTube to iPod Converter_is1" = Free YouTube to iPod Converter version 3.2 "HDMI" = Intel(R) Graphics Media Accelerator Driver "Helicon Filter_is1" = Helicon Filter 4.93.2 "HijackThis" = HijackThis 2.0.2 "HP Imaging Device Functions" = HP Imaging Device Functions 5.0 "HP Photo & Imaging" = HP Image Zone 5.0 "HP PrecisionScan LTX" = HP PrecisionScan LTX "HP Solution Center & Imaging Support Tools" = HP Solution Center & Imaging Support Tools 5.0 "HPExtendedCapabilities" = HP Extended Capabilities 5.0 "Hugin_is1" = Hugin 0.7.0 (SVN 3465) "Hugin_release_is1" = Hugin 2009.4.0 "ie8" = Windows Internet Explorer 8 "Image Analyzer" = Image Analyzer "ImageConverter Plus_is1" = ImageConverter Plus 8.0 "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "Maniac Mansion Deluxe" = Maniac Mansion Deluxe "Microsoft .NET Framework 1.1 (1033)" = Microsoft .NET Framework 1.1 "Microsoft .NET Framework 3.0 German Language Pack" = Microsoft .NET Framework 3.0 German Language Pack "Microsoft .NET Framework 3.5 Language Pack SP1 - deu" = Microsoft .NET Framework 3.5 Language Pack SP1 - DEU "Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1 "Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3) "MSCompPackV1" = Microsoft Compression Client Pack 1.0 for Windows XP "PC Wizard 2009_is1" = PC Wizard 2009.1.88 "Picasa 3" = Picasa 3 "ShiftN_is1" = ShiftN 3.5 "softonic-de3 Toolbar" = softonic-de3 Toolbar "Tank Blaster II" = Tank Blaster II "TDSLSM" = T-DSL SpeedManager "Uninstall_is1" = Uninstall 1.0.0.1 "Windows Media Format Runtime" = Windows Media Format 11 runtime "Windows Media Player" = Windows Media Player 11 "WinGimp-2.0_is1" = GIMP 2.6.7 "Winload Toolbar" = Winload Toolbar "WMFDist11" = Windows Media Format 11 runtime "wmp11" = Windows Media Player 11 "Wudf01000" = Microsoft User-Mode Driver Framework Feature Pack 1.0 "XpsEPSC" = XML Paper Specification Shared Components Pack 1.0 "XPSEPSCLP" = XML Paper Specification Shared Components Language Pack 1.0 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Gnumeric" = Gnumeric Spreadsheet 1.9.1-win32-20080505 ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 23.11.2009 07:04:00 | Computer Name = NAME-9CF4F91750 | Source = Application Hang | ID = 1002 Description = Stillstehende Anwendung HeliconFilter.exe, Version 4.93.2.0, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error - 23.11.2009 12:08:35 | Computer Name = NAME-9CF4F91750 | Source = Application Hang | ID = 1002 Description = Stillstehende Anwendung iexplore.exe, Version 8.0.6001.18702, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error - 23.11.2009 12:09:13 | Computer Name = NAME-9CF4F91750 | Source = Application Hang | ID = 1002 Description = Stillstehende Anwendung iexplore.exe, Version 8.0.6001.18702, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error - 23.11.2009 12:09:14 | Computer Name = NAME-9CF4F91750 | Source = Application Hang | ID = 1001 Description = Fehlerhafter Speicherbereich 1180947459. Error - 26.11.2009 07:00:23 | Computer Name = NAME-9CF4F91750 | Source = Application Hang | ID = 1002 Description = Stillstehende Anwendung Picasa3.exe, Version 3.1.71.43, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error - 26.11.2009 14:26:00 | Computer Name = NAME-9CF4F91750 | Source = Application Hang | ID = 1002 Description = Stillstehende Anwendung Picasa3.exe, Version 3.1.71.43, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error - 29.11.2009 05:33:56 | Computer Name = NAME-9CF4F91750 | Source = Application Error | ID = 1000 Description = Fehlgeschlagene Anwendung hugin_stitch_project.exe, Version 0.0.0.0, fehlgeschlagenes Modul hugin_stitch_project.exe, Version 0.0.0.0, Fehleradresse 0x00205f13. Error - 29.11.2009 05:34:38 | Computer Name = NAME-9CF4F91750 | Source = Application Error | ID = 1000 Description = Fehlgeschlagene Anwendung hugin_stitch_project.exe, Version 0.0.0.0, fehlgeschlagenes Modul hugin_stitch_project.exe, Version 0.0.0.0, Fehleradresse 0x00205f13. Error - 29.11.2009 05:37:28 | Computer Name = NAME-9CF4F91750 | Source = Application Error | ID = 1000 Description = Fehlgeschlagene Anwendung hugin_stitch_project.exe, Version 0.0.0.0, fehlgeschlagenes Modul hugin_stitch_project.exe, Version 0.0.0.0, Fehleradresse 0x00205f13. Error - 02.12.2009 11:49:37 | Computer Name = NAME-9CF4F91750 | Source = Application Hang | ID = 1002 Description = Stillstehende Anwendung Picasa3.exe, Version 3.1.71.43, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. [ OSession Events ] Error - 28.12.2009 04:02:15 | Computer Name = NAME-9CF4F91750 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = Error - 28.12.2009 04:03:15 | Computer Name = NAME-9CF4F91750 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = Error - 28.12.2009 04:03:31 | Computer Name = NAME-9CF4F91750 | Source = Microsoft Office 12 Sessions | ID = 7001 Description = [ System Events ] Error - 25.04.2010 14:37:38 | Computer Name = NAME-9CF4F91750 | Source = DCOM | ID = 10010 Description = Der Server "{FB7199AB-79BF-11D2-8D94-0000F875C541}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. Error - 25.04.2010 17:20:18 | Computer Name = NAME-9CF4F91750 | Source = sr | ID = 1 Description = Beim Verarbeiten der Datei "SRUI-Pick[1]" auf Volume "HarddiskVolume1" ist im Wiederherstellungsfilter der unerwartete Fehler "0xC000009A" aufgetreten. Die Volumeüberwachung wurde angehalten. Error - 26.04.2010 17:26:24 | Computer Name = NAME-9CF4F91750 | Source = DCOM | ID = 10010 Description = Der Server "{0002DF01-0000-0000-C000-000000000046}" konnte innerhalb des angegebenen Zeitabschnitts mit DCOM nicht registriert werden. < End of report > Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Datenbank Version: 3930 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 26.04.2010 22:52:11 mbam-log-2010-04-26 (22-52-11).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Durchsuchte Objekte: 30096 Laufzeit: 8 Minute(n), 3 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 0 Infizierte Verzeichnisse: 0 Infizierte Dateien: 3 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: (Keine bösartigen Objekte gefunden) Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Alte Daten\Drive(F)\Acrobat\freezip.exe (Trojan.Agent) -> No action taken. C:\Alte Daten\Drive(F)\Acrobat\GAP_Scop_03_1600-720.jpg.EXE (Trojan.Email.Gen) -> No action taken. C:\Alte Daten\Drive(F)\Acrobat\GAP_Scop_03_9374-6630.jpg.EXE (Trojan.Email.Gen) -> No action taken. Malwarebytes' Anti-Malware 1.45 www.malwarebytes.org Datenbank Version: 3930 Windows 5.1.2600 Service Pack 3 Internet Explorer 8.0.6001.18702 27.04.2010 19:44:44 mbam-log-2010-04-27 (19-44-44).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|) Durchsuchte Objekte: 341391 Laufzeit: 1 Stunde(n), 55 Minute(n), 58 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 1 Infizierte Registrierungswerte: 4 Infizierte Dateiobjekte der Registrierung: 7 Infizierte Verzeichnisse: 0 Infizierte Dateien: 11 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\cdrom (Trojan.Patched) -> No action taken. Infizierte Registrierungswerte: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\syncman (Trojan.Agent) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\regedit32 (Trojan.Agent) -> No action taken. HKEY_CLASSES_ROOT\.exe\shell\open\command\(default) (Hijack.ExeFile) -> No action taken. HKEY_CLASSES_ROOT\secfile\shell\open\command\(default) (Rogue.MultipleAV) -> No action taken. Infizierte Dateiobjekte der Registrierung: HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Anwendungsdaten\ave.exe" /START "C:\Programme\Mozilla Firefox\firefox.exe") Good: (firefox.exe) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\IEXPLORE.EXE\shell\open\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Anwendungsdaten\ave.exe" /START "C:\Programme\Internet Explorer\iexplore.exe") Good: (iexplore.exe) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Clients\StartMenuInternet\FIREFOX.EXE\shell\safemode\command\(default) (Hijack.StartMenuInternet) -> Bad: ("C:\WINDOWS\system32\config\systemprofile\Lokale Einstellungen\Anwendungsdaten\ave.exe" /START "C:\Programme\Mozilla Firefox\firefox.exe" -safe-mode) Good: (firefox.exe -safe-mode) -> No action taken. HKEY_CLASSES_ROOT\.exe\(default) (Hijacked.exeFile) -> Bad: (secfile) Good: (exefile) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\AntiVirusDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\FirewallDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\UpdatesDisableNotify (Disabled.SecurityCenter) -> Bad: (1) Good: (0) -> No action taken. Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: C:\Alte Daten\Drive(F)\System Volume Information\_restore{4EA7DCED-C474-4611-AD9D-054543A1C373}\RP1028\A0508270.exe (Trojan.Agent) -> No action taken. C:\Dokumente und Einstellungen\User\Eigene Dateien\Acrobat\freezip.exe (Trojan.Agent) -> No action taken. C:\Dokumente und Einstellungen\User\Eigene Dateien\Acrobat\GAP_Scop_03_1600-720.jpg.EXE (Trojan.Email.Gen) -> No action taken. C:\Dokumente und Einstellungen\User\Eigene Dateien\Acrobat\GAP_Scop_03_9374-6630.jpg.EXE (Trojan.Email.Gen) -> No action taken. C:\System Volume Information\_restore{3DBDB387-7509-4FD8-9380-E70EF9D34BF9}\RP207\A0035579.dll (Trojan.FakeAlert) -> No action taken. C:\System Volume Information\_restore{3DBDB387-7509-4FD8-9380-E70EF9D34BF9}\RP207\A0036193.exe (Trojan.Agent) -> No action taken. C:\WINDOWS\system32\config\systemprofile\wuaucldt.exe (Trojan.Agent) -> No action taken. C:\WINDOWS\system32\dllcache\cdrom.sys (Trojan.Patched) -> No action taken. C:\WINDOWS\system32\drivers\cdrom.sys (Trojan.Patched) -> No action taken. C:\Dokumente und Einstellungen\LocalService\oashdihasidhasuidhiasdhiashdiuasdhasd (Malware.Trace) -> No action taken. C:\Dokumente und Einstellungen\User\Anwendungsdaten\avdrn.dat (Malware.Trace) -> No action taken. |
Themen zu Verschiedene Probleme nach Befall |
.exe anwendung, adobe, aufrufe, becker, bho, c:\windows\system32\rundll32.exe, excel, explorer, fehlermeldung, firefox, firewall, google, hijack, hijackthis, hkus\s-1-5-18, internet, internet explorer, jusched.exe, malwarebytes' anti-malware, mozilla, nicht gefunden, object, outlook express, plug-in, rundll, schutz, security, software, starten, studio, superantispyware, system, taskleiste, windows, windows xp, winload, winload toolbar, öffnet |