|
Log-Analyse und Auswertung: Versteckte Viren, aber wo?Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
23.06.2010, 14:54 | #1 | |
| Versteckte Viren, aber wo? hallo Trojaner-Team, ich habe seit längerem manche Probleme mit dem PC die auf Viren andeuten. 1. Jedesmal wenn ich mich in ICQ auf "Login" klicke, stürzt mein ICQ ab. 2. Beim Surfen öffnen sich Werbe-Fenster 3. In unregelmäßigen Abständen hängt mein PC für einige sekunden. Ich habe lange versucht die Viren zu finden. Einige Trojaner, Würmer habe ich schon gelöscht. Ich habe mein komplette PC mit "Malewarebytes", "Superantispyware", "Panda online-scan" und mit mein Antir-Programm "AVG". Auch in "abgesicherten Modus". Hier Hijackthis-Logfile. Ich habe keine ahnung was bösartig sein könnte. ich kenn mich mit diesem Logfile garnicht aus. Zitat:
LG Burak |
23.06.2010, 15:38 | #2 |
/// Winkelfunktion /// TB-Süch-Tiger™ | Versteckte Viren, aber wo? Hallo und
__________________bitte nen Vollscan mit Malwarebytes machen und Log posten. Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
__________________ |
23.06.2010, 17:12 | #3 | |
| Versteckte Viren, aber wo? Danke für die schnelle Antwort !
__________________Als erstens poste ich mal die Malwarebytzes-Logfile. Zitat:
Das OLT-Logfile folgt .... |
23.06.2010, 17:19 | #4 | |
| Versteckte Viren, aber wo? OHL-Logfile part 1 !! Zitat:
|
23.06.2010, 17:21 | #5 |
| Versteckte Viren, aber wo? OHL-Logfile part 2 OTL EXTRAS Logfile: Code:
ATTFilter OTL Extras logfile created on: 6/23/2010 18:14:22 - Run 1 OTL by OldTimer - Version 3.2.6.1 Folder = C:\Documents and Settings\Administrator\Belgelerim\Downloads Windows XP Professional Edition Service Pack 3 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 7.0.5730.13) Locale: 0000041f | Country: Türkiye | Language: TRK | Date Format: M/d/yyyy 479.00 Mb Total Physical Memory | 170.00 Mb Available Physical Memory | 35.00% Memory free 1.00 Gb Paging File | 1.00 Gb Available in Paging File | 63.00% Paging File free Paging file location(s): C:\pagefile.sys 720 1440 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 74.52 Gb Total Space | 62.78 Gb Free Space | 84.24% Space Free | Partition Type: NTFS D: Drive not present or media not loaded E: Drive not present or media not loaded F: Drive not present or media not loaded G: Drive not present or media not loaded H: Drive not present or media not loaded I: Drive not present or media not loaded Computer Name: CONAXEDITION Current User Name: Administrator Logged in as Administrator. Current Boot Mode: Normal Scan Mode: Current user Company Name Whitelist: Off Skip Microsoft Files: Off File Age = 30 Days Output = Minimal ========== Extra Registry (SafeList) ========== ========== File Associations ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>] .inf [@ = inffile] -- C:\WINDOWS\System32\NOTEPAD.EXE () .ini [@ = inifile] -- C:\WINDOWS\System32\NOTEPAD.EXE () .txt [@ = txtfile] -- C:\WINDOWS\System32\NOTEPAD.EXE () ========== Shell Spawning ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command] batfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 () batfile [open] -- "%1" %* batfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 () cmdfile [edit] -- %SystemRoot%\System32\NOTEPAD.EXE %1 () cmdfile [open] -- "%1" %* cmdfile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 () comfile [open] -- "%1" %* exefile [open] -- "%1" %* htmlfile [edit] -- Reg Error: Key error. inffile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 () inffile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 () inifile [open] -- %SystemRoot%\System32\NOTEPAD.EXE %1 () inifile [print] -- %SystemRoot%\System32\NOTEPAD.EXE /p %1 () jsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 () jsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 () jsefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 () jsefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 () piffile [open] -- "%1" %* regfile [edit] -- %SystemRoot%\system32\NOTEPAD.EXE %1 () regfile [merge] -- Reg Error: Key error. regfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 () scrfile [config] -- "%1" scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation) scrfile [open] -- "%1" /S txtfile [edit] -- Reg Error: Key error. txtfile [open] -- %SystemRoot%\system32\NOTEPAD.EXE %1 () txtfile [print] -- %SystemRoot%\system32\NOTEPAD.EXE /p %1 () txtfile [printto] -- %SystemRoot%\system32\notepad.exe /pt "%1" "%2" "%3" "%4" () vbefile [edit] -- %SystemRoot%\System32\Notepad.exe %1 () vbefile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 () vbsfile [edit] -- %SystemRoot%\System32\Notepad.exe %1 () vbsfile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 () wsffile [edit] -- %SystemRoot%\System32\Notepad.exe %1 () wsffile [print] -- %SystemRoot%\System32\Notepad.exe /p %1 () Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) Folder [open] -- %SystemRoot%\Explorer.exe /idlist,%I,%L (Microsoft Corporation) Folder [explore] -- %SystemRoot%\Explorer.exe /e,/idlist,%I,%L (Microsoft Corporation) Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation) ========== Security Center Settings ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center] "FirstRunDisabled" = 1 "AntiVirusOverride" = 1 "FirewallOverride" = 0 "AntiVirusDisableNotify" = 0 "FirewallDisableNotify" = 0 "UpdatesDisableNotify" = 0 [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\AhnlabAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ComputerAssociatesAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\McAfeeFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\PandaFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SymantecFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TinyFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendAntiVirus] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\TrendFirewall] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\ZoneLabsFirewall] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile] "EnableFirewall" = 1 "DoNotAllowExceptions" = 0 "DisableNotifications" = 0 [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List] "1900:UDP" = 1900:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22007 "2869:TCP" = 2869:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22008 "139:TCP" = 139:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22004 "445:TCP" = 445:TCP:LocalSubNet:Enabled:@xpsp2res.dll,-22005 "137:UDP" = 137:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22001 "138:UDP" = 138:UDP:LocalSubNet:Enabled:@xpsp2res.dll,-22002 "3389:TCP" = 3389:TCP:*:Enabled:@xpsp2res.dll,-22009 ========== Authorized Applications List ========== [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] "C:\Program Files\ICQ7.1\ICQ.exe" = C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1 -- File not found "C:\Program Files\ICQ7.1\aolload.exe" = C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe -- File not found "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation) "C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (IniCom Networks, Inc.) "C:\Program Files\ICQ7.2\ICQ.exe" = C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2 -- (ICQ, LLC.) "C:\Program Files\ICQ7.2\aolload.exe" = C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC) [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] "C:\Program Files\ICQ7.1\ICQ.exe" = C:\Program Files\ICQ7.1\ICQ.exe:*:Enabled:ICQ7.1 -- File not found "C:\Program Files\ICQ7.1\aolload.exe" = C:\Program Files\ICQ7.1\aolload.exe:*:Enabled:aolload.exe -- File not found "C:\Program Files\Windows Live\Messenger\wlcsdk.exe" = C:\Program Files\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call -- (Microsoft Corporation) "C:\Program Files\Rockstar Games\Midnight Club II Demo\mc2_demo.exe" = C:\Program Files\Rockstar Games\Midnight Club II Demo\mc2_demo.exe:*:Enabled:mc2_demo -- () "C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe" = C:\Program Files\Kodak\Kodak EasyShare software\bin\EasyShare.exe:*:Enabled:EasyShare -- (Eastman Kodak Company) "C:\Documents and Settings\Administrator\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe" = C:\Documents and Settings\Administrator\Application Data\Octoshape\Octoshape Streaming Services\OctoshapeClient.exe:*:Enabled:Main program for Octoshape client -- (Octoshape ApS) "C:\Program Files\TeamViewer\Version5\TeamViewer.exe" = C:\Program Files\TeamViewer\Version5\TeamViewer.exe:*:Enabled:Teamviewer Remote Control Application -- (TeamViewer GmbH) "C:\Program Files\WinSCP\WinSCP.exe" = C:\Program Files\WinSCP\WinSCP.exe:*:Enabled:WinSCP: SFTP, FTP and SCP client -- (Martin Prikryl) "C:\Program Files\ICQ7.2\ICQ.exe" = C:\Program Files\ICQ7.2\ICQ.exe:*:Enabled:ICQ7.2 -- (ICQ, LLC.) "C:\Program Files\ICQ7.2\aolload.exe" = C:\Program Files\ICQ7.2\aolload.exe:*:Enabled:aolload.exe -- (AOL LLC) "C:\Documents and Settings\Administrator\Desktop\Hauptmenü\Controllcenter\AZ.exe" = C:\Documents and Settings\Administrator\Desktop\Hauptmenü\Controllcenter\AZ.exe:*:Enabled:Dreambox Control Center -- (BernyR) "C:\Documents and Settings\Administrator\Desktop\Controllcenter\AZ.exe" = C:\Documents and Settings\Administrator\Desktop\Controllcenter\AZ.exe:*:Enabled:Dreambox Control Center -- File not found "C:\Documents and Settings\Administrator\Desktop\Yükleme\DreamUP_1_3_3_5.exe" = C:\Documents and Settings\Administrator\Desktop\Yükleme\DreamUP_1_3_3_5.exe:*:Enabled:DreamUP_1_3_3_5 -- File not found "C:\Documents and Settings\Administrator\Desktop\DreamUP_1_3_3_5.exe" = C:\Documents and Settings\Administrator\Desktop\DreamUP_1_3_3_5.exe:*:Enabled:DreamUP_1_3_3_5 -- File not found "C:\Program Files\FlashFXP\FlashFXP.exe" = C:\Program Files\FlashFXP\FlashFXP.exe:*:Enabled:FlashFXP v3 -- (IniCom Networks, Inc.) "C:\Documents and Settings\Administrator\Desktop\DreamUP_1.3.3.5\DreamUP_1_3_3_5.exe" = C:\Documents and Settings\Administrator\Desktop\DreamUP_1.3.3.5\DreamUP_1_3_3_5.exe:*:Disabled:DreamUP_1_3_3_5 -- File not found "C:\Program Files\AVG\AVG9\avgupd.exe" = C:\Program Files\AVG\AVG9\avgupd.exe:*:Enabled:avgupd.exe -- (AVG Technologies CZ, s.r.o.) "C:\Program Files\AVG\AVG9\avgnsx.exe" = C:\Program Files\AVG\AVG9\avgnsx.exe:*:Enabled:avgnsx.exe -- (AVG Technologies CZ, s.r.o.) "C:\Documents and Settings\Administrator\Desktop\DreamUP_1_3_3_4\DreamUP_1_3_3_4\DreamUP.exe" = C:\Documents and Settings\Administrator\Desktop\DreamUP_1_3_3_4\DreamUP_1_3_3_4\DreamUP.exe:*:Enabled:DreamUP -- File not found "C:\Documents and Settings\Administrator\Local Settings\Temp\Rar$EX00.750\DCC_E2.exe" = C:\Documents and Settings\Administrator\Local Settings\Temp\Rar$EX00.750\DCC_E2.exe:*:Enabled:Dreambox Control Center -- File not found ========== HKEY_LOCAL_MACHINE Uninstall List ========== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator "{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card "{02BC140F-504C-4DB5-B581-FD2920BBE363}" = Midnight Club II Demo "{0CB9668D-F979-4F31-B8B8-67FE90F929F8}" = Bonjour "{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD "{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live-Uploadtool "{2217B0B4-35CB-48C6-B640-864DF2F30F99}" = OpenOffice.org 3.2 "{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT "{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java(TM) 6 Update 20 "{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt "{41E654A9-26D0-4EAC-854B-0FA824FFFABB}" = Windows Live Messenger "{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore "{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg "{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater "{52B97218-98CB-4B8B-9283-D213C85E1AA4}" = Windows Live Anmelde-Assistent "{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001 "{542068F1-9AAE-4E1B-8ACA-094FE03728BE}" = Carambis Driver Updater "{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book "{5791B7D3-8B34-4218-9750-6A8E45D0AD32}" = pdfforge Toolbar v1.1.2 "{5C209D68-1411-4725-8CDE-1676A85E083E}_is1" = ICQ Contact Revealer 1.0 "{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053 "{5FC68772-6D56-41C6-9DF1-24E868198AE6}" = Windows Live Call "{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA "{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr "{6956856F-B6B3-4BE0-BA0B-8F495BE32033}" = Apple Software Update "{7057ABC2-EFF3-4E43-9806-8BCB6EEA9FE6}" = Microsoft IntelliPoint 7.1 "{7131646D-CD3C-40F4-97B9-CD9E4E6262EF}" = Microsoft .NET Framework 2.0 "{72EFBFE4-C74F-4187-AEFD-73EA3BE968D6}" = ICQ7.2 "{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable "{85309D89-7BE9-4094-BB17-24999C6118FC}" = ArcSoft PhotoStudio 5.5 "{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr "{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS "{8A708DD8-A5E6-11D4-A706-000629E95E20}" = Intel(R) Extreme Graphics 2 Driver "{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini "{90120000-0020-0407-0000-0000000FF1CE}" = Compatibility Pack für 2007 Office System "{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui "{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting "{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse "{96E3AED5-3D0B-4BB0-84C2-1EDADB204487}" = FlashFXP v3 "{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL "{A1F66FC9-11EE-4F2F-98C9-16F8D1E69FB7}" = Segoe UI "{AC76BA86-7AD7-1031-7B44-A93000000001}" = Adobe Reader 9.3.2 - Deutsch "{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK "{AFAC914D-9E83-4A89-8ABE-427521C82CCF}" = Safari "{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook "{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI "{B2D328BE-45AD-4D92-96F9-2151490A203E}" = Apple Application Support "{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore "{BA4DF4C3-196E-4128-969A-00996B5A46F8}" = Canon MP500 "{C1A80F67-656F-4DF3-A6C4-DE18A47477C5}_is1" = ICQ Away Reader 1.4 "{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar "{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations "{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware "{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare Software "{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR "{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page "{ED00D08A-3C5F-488D-93A0-A04F21F23956}" = Windows Live Communications Platform "{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card "{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard "{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK "{F8FF18EE-264A-43FD-B2F6-5EAD40798C2F}" = Windows Live Essentials "{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS "{FB08F381-6533-4108-B7DD-039E11FBC27E}" = Realtek AC'97 Audio "{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock "ActiveScan 2.0" = Panda ActiveScan 2.0 "Adobe Acrobat 4.0" = Adobe Acrobat 4.0 "Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin "Adobe Shockwave Player" = Adobe Shockwave Player 11 "AVG9Uninstall" = AVG Free 9.0 "CCleaner" = CCleaner "DivX Setup.divx.com" = DivX-Setup "DreamBoxEdit" = DreamBoxEdit -- The one and only settings editor for your Dreambox "Easy-PhotoPrint" = Canon Utilities Easy-PhotoPrint "Easy-WebPrint" = Easy-WebPrint "ICQToolbar" = ICQ Toolbar "IsoBuster_is1" = IsoBuster 2.7 "MakeISO right click extensions" = MakeISO right click extensions "Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware "MediaNavigation.CDLabelPrint" = CD-LabelPrint "Microsoft .NET Framework 2.0" = Microsoft .NET Framework 2.0 "Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3) "MP Navigator 2.0" = Canon MP Navigator 2.0 "Office8.0" = Microsoft Office 97, Professional Edition "Robin Hood: The Legend Of Sherwood" = Robin Hood: The Legend Of Sherwood "RocketDock_is1" = RocketDock 1.3.5 "SearchAnonymizer" = SearchAnonymizer "TeamViewer 5" = TeamViewer 5 "WinGimp-2.0_is1" = GIMP 2.6.8 "WinLiveSuite_Wave3" = Windows Live Essentials "WinRAR archiver" = WinRAR "winscp3_is1" = WinSCP 4.2.7 ========== HKEY_CURRENT_USER Uninstall List ========== [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall] "Octoshape Streaming Services" = Octoshape Streaming Services ========== Last 10 Event Log Errors ========== [ Application Events ] Error - 4/30/2010 09:54:14 | Computer Name = CONAXEDITION | Source = PerfNet | ID = 2004 Description = Sunucu hizmeti açılamıyor. Suınucu performans verileri döndürülemeyecek. Döndürülen hata kodu, DWORD 0 verisinde. Error - 5/7/2010 03:10:02 | Computer Name = CONAXEDITION | Source = MsiInstaller | ID = 11305 Description = Product: OmniPage SE -- Error 1305.Error reading from file C:\Program Files\ScanSoft\OmniPageSE2.0\Guide BRA.pdf. Verify that the file exists and that you can access it. Error - 5/7/2010 03:11:26 | Computer Name = CONAXEDITION | Source = MsiInstaller | ID = 11305 Description = Product: OmniPage SE -- Error 1305.Error reading from file C:\Program Files\ScanSoft\OmniPageSE2.0\Guide BRA.pdf. Verify that the file exists and that you can access it. Error - 5/7/2010 03:12:21 | Computer Name = CONAXEDITION | Source = MsiInstaller | ID = 11305 Description = Product: OmniPage SE -- Error 1305.Error reading from file C:\Program Files\ScanSoft\OmniPageSE2.0\Guide BRA.pdf. Verify that the file exists and that you can access it. Error - 5/7/2010 03:13:19 | Computer Name = CONAXEDITION | Source = MsiInstaller | ID = 11305 Description = Product: OmniPage SE -- Error 1305.Error reading from file C:\Program Files\ScanSoft\OmniPageSE2.0\Guide BRA.pdf. Verify that the file exists and that you can access it. Error - 5/7/2010 03:15:11 | Computer Name = CONAXEDITION | Source = MsiInstaller | ID = 11305 Description = Product: OmniPage SE -- Error 1305.Error reading from file C:\Program Files\ScanSoft\OmniPageSE2.0\Guide BRA.pdf. Verify that the file exists and that you can access it. Error - 5/7/2010 03:16:02 | Computer Name = CONAXEDITION | Source = MsiInstaller | ID = 11305 Description = Product: OmniPage SE -- Error 1305.Error reading from file C:\Program Files\ScanSoft\OmniPageSE2.0\Guide BRA.pdf. Verify that the file exists and that you can access it. Error - 5/7/2010 03:16:49 | Computer Name = CONAXEDITION | Source = MsiInstaller | ID = 11305 Description = Product: OmniPage SE -- Error 1305.Error reading from file C:\Program Files\ScanSoft\OmniPageSE2.0\Guide BRA.pdf. Verify that the file exists and that you can access it. [ System Events ] Error - 6/13/2010 12:38:39 | Computer Name = CONAXEDITION | Source = SideBySide | ID = 16842811 Description = Generate Activation Context tarafından başarılamayan C:\Program Files\RocketDock\RocketDock.dll. Başvuru hata iletisi: İşlem başarıyla tamamlandı. . Error - 6/16/2010 03:22:54 | Computer Name = CONAXEDITION | Source = Ntfs | ID = 262199 Description = Diskteki dosya sistemi yapısı bozuk ve kullanılamaz durumda. C: birimindeki chkdsk yardımcı programını çalıştırın. Error - 6/18/2010 16:15:43 | Computer Name = CONAXEDITION | Source = sptd | ID = 262148 Description = Sürücü, için kullandığı veri yapılarında bir iç hata belirledi. Error - 6/18/2010 16:15:53 | Computer Name = CONAXEDITION | Source = DCOM | ID = 10005 Description = DCOM EventSystem hizmetini "" değişkenleriyle başlatmaya çalışırken "%1084" hatasını aldı ve sunucuyu çalıştıramadı: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error - 6/18/2010 16:15:56 | Computer Name = CONAXEDITION | Source = DCOM | ID = 10005 Description = DCOM netman hizmetini "" değişkenleriyle başlatmaya çalışırken "%1084" hatasını aldı ve sunucuyu çalıştıramadı: {BA126AE5-2166-11D1-B1D0-00805FC1270E} Error - 6/18/2010 16:41:57 | Computer Name = CONAXEDITION | Source = DCOM | ID = 10005 Description = DCOM EventSystem hizmetini "" değişkenleriyle başlatmaya çalışırken "%1084" hatasını aldı ve sunucuyu çalıştıramadı: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error - 6/22/2010 15:28:32 | Computer Name = CONAXEDITION | Source = DCOM | ID = 10005 Description = DCOM EventSystem hizmetini "" değişkenleriyle başlatmaya çalışırken "%1084" hatasını aldı ve sunucuyu çalıştıramadı: {1BE1F766-5536-11D1-B726-00C04FB926AF} Error - 6/22/2010 15:28:36 | Computer Name = CONAXEDITION | Source = DCOM | ID = 10005 Description = DCOM netman hizmetini "" değişkenleriyle başlatmaya çalışırken "%1084" hatasını aldı ve sunucuyu çalıştıramadı: {BA126AE5-2166-11D1-B1D0-00805FC1270E} Error - 6/22/2010 15:29:38 | Computer Name = CONAXEDITION | Source = DCOM | ID = 10005 Description = DCOM StiSvc hizmetini "" değişkenleriyle başlatmaya çalışırken "%1084" hatasını aldı ve sunucuyu çalıştıramadı: {A1F4E726-8CF1-11D1-BF92-0060081ED811} Error - 6/22/2010 16:15:01 | Computer Name = CONAXEDITION | Source = DCOM | ID = 10005 Description = DCOM EventSystem hizmetini "" değişkenleriyle başlatmaya çalışırken "%1084" hatasını aldı ve sunucuyu çalıştıramadı: {1BE1F766-5536-11D1-B726-00C04FB926AF} < End of report > Also ich habe hier kein überblick, hoffe ihr findet was verdächtiges ! Danke ! |
23.06.2010, 18:54 | #6 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Versteckte Viren, aber wo?Zitat:
Die (Be)nutzung von Cracks, Serials und Keygens ist illegal, somit gibt es im Trojaner-Board keinen weiteren Support mehr. Für Dich geht es hier weiter => Neuaufsetzen des Systems Bitte auch alle Passwörter abändern (für E-Mail-Konten, StudiVZ, Ebay...einfach alles!) da nicht selten in dieser dubiosen Software auch Keylogger und Backdoorfunktionen stecken. Danach nie wieder sowas anrühren!
__________________ --> Versteckte Viren, aber wo? |
23.06.2010, 19:04 | #7 |
| Versteckte Viren, aber wo? Dieses Programm wurde schon langem gelöscht. Da mein Betriebssystem neu ist, habe ich bislang keine Passwörter gespeichert. Seiten wie ebay, facebook habe ich besucht, nur muss ich jedesmal mein PW-selber eingeben. Ist es wirklich riskant ? Wegen diesem einen Programm? Boah hät ich nicht gedacht. Aber trotzdem danke in einem Tag viel geholfen. |
23.06.2010, 22:19 | #8 | |
/// Winkelfunktion /// TB-Süch-Tiger™ | Versteckte Viren, aber wo?Zitat:
__________________ Logfiles bitte immer in CODE-Tags posten |
25.06.2010, 10:46 | #9 | |
| Versteckte Viren, aber wo? Habe mein System jetzt neu aufgesetzt und alle Programm die ich benötige runtergeladen. Hier ist der Logfile: Zitat:
|
Themen zu Versteckte Viren, aber wo? |
administrator, adobe, avg, avg free, avg security toolbar, bho, brauche hilfe, canon, explorer, firefox, hijack, hkus\s-1-5-18, hängt, icq, internet, internet explorer, micro, microsoft, mozilla, pdfforge toolbar, plug-in, rundll, rundll32, security, software, sp3, spigot, superantispyware, surfen, system, versteckte viren, viren, viren or trojanerverdacht, windows, windows xp |