![]() |
|
Plagegeister aller Art und deren Bekämpfung: Explorer.exe startet bei Anmeldung nicht mehr automatischWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #7 |
![]() ![]() | ![]() Explorer.exe startet bei Anmeldung nicht mehr automatisch Ich hoffe dashier ist gemeint! All processes killed ========== OTL ========== Service xhhnw stopped successfully! Service xhhnw deleted successfully! File C:\WINDOWS\System32\tiugezqb.dll not found. Service fnwwbfwj stopped successfully! Service fnwwbfwj deleted successfully! File C:\WINDOWS\System32\01.tmp not found. Prefs.js: "Ask.com" removed from browser.search.defaultengine Prefs.js: "ICQ Search" removed from browser.search.defaultenginename Prefs.js: "Games Bar 1 Customized Web Search" removed from browser.search.defaultthis.engineName Prefs.js: "hxxp://search.sweetim.com/search.asp?src=2&q=" removed from browser.search.defaulturl Prefs.js: "Ask.com" removed from browser.search.order.1 Prefs.js: "ICQ Search" removed from browser.search.selectedEngine Prefs.js: true removed from browser.search.useDBForOrder Prefs.js: "hxxp://search.conduit.com/?ctid=CT2452474&SearchSource=13" removed from browser.startup.homepage Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{855F3B16-6D32-4fe6-8A56-BBB695989046} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{855F3B16-6D32-4fe6-8A56-BBB695989046}\ deleted successfully. C:\Programme\ICQ6Toolbar\ICQToolBar.dll moved successfully. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{D4027C7F-154A-4066-A1AD-4243D8127440} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D4027C7F-154A-4066-A1AD-4243D8127440}\ not found. Registry value HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\\{EEE6C35B-6118-11DC-9C72-001320C79847} deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EEE6C35B-6118-11DC-9C72-001320C79847}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d6a0a94-d901-11de-af88-000ea64e7f5b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2d6a0a94-d901-11de-af88-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{2d6a0a94-d901-11de-af88-000ea64e7f5b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2d6a0a94-d901-11de-af88-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{378c0505-293e-11df-b040-000cf6809d00}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{378c0505-293e-11df-b040-000cf6809d00}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{378c0505-293e-11df-b040-000cf6809d00}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{378c0505-293e-11df-b040-000cf6809d00}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{534e1f7c-d607-11de-af7e-000ea64e7f5b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{534e1f7c-d607-11de-af7e-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{534e1f7c-d607-11de-af7e-000ea64e7f5b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{534e1f7c-d607-11de-af7e-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74107caa-a7a4-11de-aeb5-000ea64e7f5b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74107caa-a7a4-11de-aeb5-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{74107caa-a7a4-11de-aeb5-000ea64e7f5b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{74107caa-a7a4-11de-aeb5-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7c9f5e9b-a169-11de-ae9b-000ea64e7f5b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7c9f5e9b-a169-11de-ae9b-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7c9f5e9b-a169-11de-ae9b-000ea64e7f5b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7c9f5e9b-a169-11de-ae9b-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7c9f5e9c-a169-11de-ae9b-000ea64e7f5b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7c9f5e9c-a169-11de-ae9b-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{7c9f5e9c-a169-11de-ae9b-000ea64e7f5b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{7c9f5e9c-a169-11de-ae9b-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9077f6b8-a14b-11de-ae99-000ea64e7f5b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9077f6b8-a14b-11de-ae99-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{9077f6b8-a14b-11de-ae99-000ea64e7f5b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9077f6b8-a14b-11de-ae99-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a7b3a0ee-c14b-11de-af2f-000ea64e7f5b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a7b3a0ee-c14b-11de-af2f-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{a7b3a0ee-c14b-11de-af2f-000ea64e7f5b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{a7b3a0ee-c14b-11de-af2f-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{be1ccad3-ef31-11de-afd5-000ea64e7f5b}\ deleted successfully. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{be1ccad3-ef31-11de-afd5-000ea64e7f5b}\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\{be1ccad3-ef31-11de-afd5-000ea64e7f5b}\ not found. Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{be1ccad3-ef31-11de-afd5-000ea64e7f5b}\ not found. C:\WINDOWS\system32\drivers\smhb.sys moved successfully. ADS C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\TEMP:661DFA1C deleted successfully. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: Administrator ->Temp folder emptied: 364806686 bytes ->Temporary Internet Files folder emptied: 56067086 bytes ->Java cache emptied: 47351111 bytes ->FireFox cache emptied: 81769915 bytes ->Flash cache emptied: 1985637 bytes User: administrator.KANZLEI ->Temp folder emptied: 22857965 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: administrator.KANZLEI.000 ->Temp folder emptied: 53036221 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: All Users User: Default User ->Temp folder emptied: 16384 bytes ->Temporary Internet Files folder emptied: 32768 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 79763213 bytes ->Flash cache emptied: 1239 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: pc03 ->Temp folder emptied: 85066 bytes ->Temporary Internet Files folder emptied: 32902 bytes User: sb ->Temp folder emptied: 95538596 bytes ->Temporary Internet Files folder emptied: 90483513 bytes ->Java cache emptied: 581841 bytes ->Flash cache emptied: 300 bytes User: sb.KANZLEI ->Temp folder emptied: 109441954 bytes ->Temporary Internet Files folder emptied: 43412265 bytes ->Java cache emptied: 8362094 bytes ->Flash cache emptied: 996 bytes %systemdrive% .tmp files removed: 2 bytes %systemroot% .tmp files removed: 1626148 bytes %systemroot%\System32 .tmp files removed: 2951 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 44537525 bytes RecycleBin emptied: 2807210 bytes Total Files Cleaned = 1.054,00 mb OTL by OldTimer - Version 3.2.9.0 log created on 10172010_204345 Files\Folders moved on Reboot... File move failed. C:\WINDOWS\temp\hlktmp scheduled to be moved on reboot. Registry entries deleted on Reboot... Geändert von Jerryloo (17.10.2010 um 20:50 Uhr) |
Themen zu Explorer.exe startet bei Anmeldung nicht mehr automatisch |
anmeldung, antivir, arten, automatisch, explorer.exe, festgestellt, gestellt, gestern, guten, manuell, meldung, nicht mehr, problem, schlägt, starte, starten, startet, task-manager, updates |