![]() |
|
Log-Analyse und Auswertung: [XP, SP3]Facebook meldet VirusWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #16 |
![]() ![]() | ![]() [XP, SP3]Facebook meldet Virus ESET Code:
ATTFilter ESETSmartInstaller@High as downloader log: all ok # version=8 # OnlineScannerApp.exe=1.0.0.1 # OnlineScanner.ocx=1.0.0.6920 # api_version=3.0.2 # EOSSerial=a2bdb16479a95a4ba045f74ec803f1a0 # engine=16391 # end=finished # remove_checked=false # archives_checked=false # unwanted_checked=false # unsafe_checked=false # antistealth_checked=true # utc_time=2013-12-24 07:35:50 # local_time=2013-12-24 08:35:50 (+0100, Westeuropäische Normalzeit) # country="Germany" # lang=1033 # osver=5.1.2600 NT Service Pack 3 # scanned=40709 # found=0 # cleaned=0 # scan_time=7179 Code:
ATTFilter Results of screen317's Security Check version 0.99.77 Windows XP Service Pack 3 x86 Internet Explorer 6 Out of date! ``````````````Antivirus/Firewall Check:`````````````` Warten Sie, w„hrend WMIC installiert wird.d i s p l a y N a m e ECHO ist ausgeschaltet (OFF). E m s i s o f t ECHO ist ausgeschaltet (OFF). A n t i M a l w a r e ECHO ist ausgeschaltet (OFF). Antivirus up to date! `````````Anti-malware/Other Utilities Check:````````` Malwarebytes Anti-Malware Version 1.75.0.1300 Java 7 Update 45 Adobe Reader XI Mozilla Firefox (26.0) Google Chrome 31.0.1650.63 ````````Process Check: objlist.exe by Laurent```````` Emsisoft Anti-Malware a2service.exe emsisoft Anti-Malware a2guard.exe `````````````````System Health check````````````````` Total Fragmentation on Drive C:: ````````````````````End of Log`````````````````````` Code:
ATTFilter Additional scan result of Farbar Recovery Scan Tool (x86) Version: 23-12-2013 01 Ran by Admin at 2013-12-24 20:58:02 Running from C:\Dokumente und Einstellungen\Admin\Desktop\TB Boot Mode: Normal ========================================================== ==================== Security Center ======================== AV: Emsisoft Anti-Malware (Disabled - Up to date) {0F8591BB-342B-4493-91C3-4E948ED21255} ==================== Installed Programs ====================== Adobe Reader XI (11.0.05) - Deutsch (Version: 11.0.05) ATI - Dienstprogramm zur Deinstallation der Software (Version: 6.14.10.1021) ATI Catalyst Control Center (Version: 2.008.0407.2138) ATI Display Driver (Version: 8.477-080407a-062896C-Toshiba) ATI Parental Control & Encoder (Version: 3.0) Camera Assistant Software for Toshiba (Version: 1.7.175.0123) Catalyst Control Center - Branding (Version: 1.00.0000) Catalyst Control Center Core Implementation (Version: 2008.0407.2139.36897) Catalyst Control Center Graphics Full Existing (Version: 2008.0407.2139.36897) Catalyst Control Center Graphics Full New (Version: 2008.0407.2139.36897) Catalyst Control Center Graphics Light (Version: 2008.0407.2139.36897) Catalyst Control Center Localization Chinese Standard (Version: 2008.0407.2139.36897) Catalyst Control Center Localization Chinese Traditional (Version: 2008.0407.2139.36897) Catalyst Control Center Localization Dutch (Version: 2008.0407.2139.36897) Catalyst Control Center Localization French (Version: 2008.0407.2139.36897) Catalyst Control Center Localization German (Version: 2008.0407.2139.36897) Catalyst Control Center Localization Italian (Version: 2008.0407.2139.36897) Catalyst Control Center Localization Japanese (Version: 2008.0407.2139.36897) Catalyst Control Center Localization Korean (Version: 2008.0407.2139.36897) Catalyst Control Center Localization Portuguese (Version: 2008.0407.2139.36897) Catalyst Control Center Localization Spanish (Version: 2008.0407.2139.36897) Catalyst Control Center Localization Swedish (Version: 2008.0407.2139.36897) CCC Help Chinese Standard (Version: 2008.0407.2138.36897) CCC Help Chinese Traditional (Version: 2008.0407.2138.36897) CCC Help Dutch (Version: 2008.0407.2138.36897) CCC Help English (Version: 2008.0407.2138.36897) CCC Help French (Version: 2008.0407.2138.36897) CCC Help German (Version: 2008.0407.2138.36897) CCC Help Italian (Version: 2008.0407.2138.36897) CCC Help Japanese (Version: 2008.0407.2138.36897) CCC Help Korean (Version: 2008.0407.2138.36897) CCC Help Portuguese (Version: 2008.0407.2138.36897) CCC Help Spanish (Version: 2008.0407.2138.36897) CCC Help Swedish (Version: 2008.0407.2138.36897) ccc-core-preinstall (Version: 2008.0407.2139.36897) ccc-core-static (Version: 2008.0407.2139.36897) ccc-utility (Version: 2008.0407.2139.36897) CD/DVD Drive Acoustic Silencer (Version: 1.00.008) Cisco AnyConnect Secure Mobility Client (Version: 3.1.04072) Cisco AnyConnect Secure Mobility Client (Version: 3.1.04072) Emsisoft Anti-Malware (Version: 8.1) ESET Online Scanner v3 Google Chrome (Version: 31.0.1650.63) Google Update Helper (Version: 1.3.22.3) High Definition Audio Driver Package - KB888111 (Version: 20040219.000000) Java 7 Update 45 (Version: 7.0.450) Java Auto Updater (Version: 2.1.9.8) Malwarebytes Anti-Malware Version 1.75.0.1300 (Version: 1.75.0.1300) Microsoft .NET Framework 2.0 Microsoft .NET Framework 2.0 (Version: 2.0.50727) Microsoft Silverlight (Version: 5.1.20913.0) Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319 (Version: 10.0.30319) Mozilla Firefox 26.0 (x86 de) (Version: 26.0) Mozilla Maintenance Service (Version: 26.0) OANDA - MetaTrader (Version: 4.00) REALTEK GbE & FE Ethernet PCI-E NIC Driver (Version: 1.35.0000) Realtek High Definition Audio Driver (Version: 5.10.0.5599) RICOH R5C83x/84x Flash Media Controller Driver Ver.3.54.02 (Version: 3.54.02) Skins (Version: 2008.0407.2139.36897) SpeedFan (remove only) TOSHIBA Assist TOSHIBA PC Diagnostic Tool (Version: 3.2.6) TOSHIBA Power Saver (Version: 7.04.02.I) WebFldrs XP (Version: 9.50.7523) Windows XP Service Pack 3 (Version: 20080414.031514) WinRAR 5.01 (32-Bit) (Version: 5.01.0) ==================== Restore Points ========================= 13-12-2013 19:59:48 Systemprüfpunkt 13-12-2013 20:05:53 Installiert REALTEK GbE & FE Ethernet PCI-E NIC Driver 13-12-2013 20:07:22 Installed Intel(R) PROSet/Wireless WiFi-Software. 13-12-2013 20:09:21 Installiert Realtek High Definition Audio Driver 13-12-2013 20:09:30 Installed Windows XP KB888111WXPSP2. 13-12-2013 20:17:06 Windows Installer KB893803v2 wurde installiert. 13-12-2013 20:19:22 Installiert ATI Catalyst Control Center 13-12-2013 20:20:48 ATI Parental Control & Encoder wird installiert 13-12-2013 20:38:12 Windows XP Service Pack 3 wurde installiert. 13-12-2013 21:44:55 Konfiguriert REALTEK GbE & FE Ethernet PCI-E NIC Driver 13-12-2013 21:50:55 Installiert Atheros Client Utility 13-12-2013 21:52:01 Installiert Atheros Client Utility 13-12-2013 21:55:36 Entfernt Atheros Client Utility 13-12-2013 21:57:32 Removed Intel(R) PROSet/Wireless WiFi-Software. 13-12-2013 22:17:19 Installiert REALTEK GbE & FE Ethernet PCI-E NIC Driver 13-12-2013 22:43:32 Installiert REALTEK GbE & FE Ethernet PCI-E NIC Driver 13-12-2013 22:46:27 Installiert Atheros Wireless LAN MiniPCI card Driver 13-12-2013 22:48:30 Installiert Atheros Client Utility 13-12-2013 22:54:53 Installiert Camera Assistant Software for Toshiba 13-12-2013 23:01:23 Konfiguriert REALTEK GbE & FE Ethernet PCI-E NIC Driver 13-12-2013 23:02:06 Entfernt Atheros Client Utility 13-12-2013 23:04:53 Installed TOSHIBA PC Diagnostic Tool 13-12-2013 23:07:39 Installiert CD/DVD Drive Acoustic Silencer 13-12-2013 23:13:03 Installiert RICOH R5C83x/84x Flash Media Controller Driver Ver.3 13-12-2013 23:14:36 Installiert TOSHIBA Assist 13-12-2013 23:18:17 Installiert TOSHIBA Common Module 13-12-2013 23:23:24 Installiert REALTEK GbE & FE Ethernet PCI-E NIC Driver 13-12-2013 23:48:41 Entfernt REALTEK GbE & FE Ethernet PCI-E NIC Driver 13-12-2013 23:49:33 Installiert REALTEK GbE & FE Ethernet PCI-E NIC Driver 13-12-2013 23:54:16 Entfernt Atheros Wireless LAN MiniPCI card Driver 14-12-2013 12:22:19 Ask Toolbar wird entfernt 14-12-2013 20:55:19 Java 7 Update 45 wird installiert 14-12-2013 20:57:21 Java 7 Update 45 wird entfernt 14-12-2013 20:57:52 Java 7 Update 45 wird installiert 14-12-2013 21:07:48 Installed Cisco AnyConnect Secure Mobility Client 16-12-2013 16:37:28 Systemprüfpunkt 17-12-2013 19:46:33 Systemprüfpunkt 18-12-2013 22:05:12 Windows XP KB2879017 wurde installiert. 19-12-2013 11:24:16 Windows XP KB2879017 wurde installiert. 21-12-2013 14:51:37 ComboFix created restore point ==================== Hosts content: ========================== 2004-08-04 13:00 - 2013-12-21 16:06 - 00000027 ____A C:\WINDOWS\system32\Drivers\etc\hosts 127.0.0.1 localhost ==================== Scheduled Tasks (whitelisted) ============= Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineCore.job => C:\Programme\Google\Update\GoogleUpdate.exe Task: C:\WINDOWS\Tasks\GoogleUpdateTaskMachineUA.job => C:\Programme\Google\Update\GoogleUpdate.exe ==================== Loaded Modules (whitelisted) ============= 2013-12-14 00:18 - 2007-04-03 18:21 - 00049152 _____ () C:\Programme\Toshiba\Toshiba Applet\TouchPad_OnOff.dll 2013-12-13 21:29 - 2013-12-04 03:48 - 04055504 _____ () C:\Programme\Google\Chrome\Application\31.0.1650.63\pdf.dll 2013-12-13 21:29 - 2013-12-04 03:48 - 00399312 _____ () C:\Programme\Google\Chrome\Application\31.0.1650.63\ppGoogleNaClPluginChrome.dll 2013-12-13 21:29 - 2013-12-04 03:47 - 01619408 _____ () C:\Programme\Google\Chrome\Application\31.0.1650.63\ffmpegsumo.dll ==================== Alternate Data Streams (whitelisted) ========= ==================== Safe Mode (whitelisted) =================== HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\CleanHlp.sys => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp => ""="Driver" HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\CleanHlp.sys => ""="Driver" ==================== Faulty Device Manager Devices ============= Name: Description: Class Guid: {4D36E97E-E325-11CE-BFC1-08002BE10318} Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: ATI HDMI Audio Description: ATI HDMI Audio Class Guid: {4D36E96C-E325-11CE-BFC1-08002BE10318} Manufacturer: Realtek Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Modem Device on High Definition Audio Bus Description: Modem Device on High Definition Audio Bus Class Guid: Manufacturer: Service: Problem: : The drivers for this device are not installed. (Code 28) Resolution: To install the drivers for this device, click "Update Driver", which starts the Hardware Update wizard. Name: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows Description: Cisco AnyConnect Secure Mobility Client Virtual Miniport Adapter for Windows Class Guid: {4D36E972-E325-11CE-BFC1-08002BE10318} Manufacturer: Cisco Systems Service: vpnva Problem: : This device is disabled. (Code 22) Resolution: In Device Manager, click "Action", and then click "Enable Device". This starts the Enable Device wizard. Follow the instructions. ==================== Event log errors: ========================= Application errors: ================== Error: (12/21/2013 03:59:13 PM) (Source: crypt32) (User: ) Description: Der automatische Aktualisierungsabruf der Drittanbieterstammlisten-Sequenznummer von <hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt> ist fehlgeschlagen mit dem Fehler: Die Serververbindung konnte nicht hergestellt werden. . Error: (12/19/2013 04:45:36 PM) (Source: PerfNet) (User: ) Description: Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen werden nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0. Error: (12/19/2013 00:56:11 PM) (Source: Application Hang) (User: ) Description: Stillstehende Anwendung iexplore.exe, Version 6.0.2900.5512, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error: (12/19/2013 00:40:01 PM) (Source: PerfNet) (User: ) Description: Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen werden nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0. Error: (12/19/2013 00:28:56 PM) (Source: PerfNet) (User: ) Description: Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen werden nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0. Error: (12/19/2013 00:10:37 PM) (Source: PerfNet) (User: ) Description: Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen werden nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0. Error: (12/19/2013 09:30:13 AM) (Source: PerfNet) (User: ) Description: Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen werden nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0. Error: (12/19/2013 08:52:52 AM) (Source: Application Hang) (User: ) Description: Stillstehende Anwendung iexplore.exe, Version 6.0.2900.5512, Stillstandmodul hungapp, Version 0.0.0.0, Stillstandadresse 0x00000000. Error: (12/19/2013 08:14:53 AM) (Source: PerfNet) (User: ) Description: Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen werden nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0. Error: (12/18/2013 11:10:52 PM) (Source: PerfNet) (User: ) Description: Der Serverdienst konnte nicht geöffnet werden. Die Server-Leistungsinformationen werden nicht zurückgegeben. Der zurückgegebene Fehlercode befindet sich in DWORD 0. System errors: ============= Error: (12/21/2013 02:44:49 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Gatewaydienst auf Anwendungsebene" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/21/2013 02:44:49 PM) (Source: Service Control Manager) (User: ) Description: Zeitüberschreitung (30000 ms) beim Verbindungsversuch mit Dienst Gatewaydienst auf Anwendungsebene. Error: (12/19/2013 04:47:01 PM) (Source: Service Control Manager) (User: ) Description: Der Dienst "Cisco AnyConnect Secure Mobility Agent" wurde aufgrund folgenden Fehlers nicht gestartet: %%1053 Error: (12/19/2013 04:47:01 PM) (Source: Service Control Manager) (User: ) Description: Zeitüberschreitung (30000 ms) beim Verbindungsversuch mit Dienst Cisco AnyConnect Secure Mobility Agent. Error: (12/18/2013 09:35:11 PM) (Source: 0) (User: ) Description: \Device\Ide\IdePort0 Error: (12/18/2013 09:34:05 PM) (Source: 0) (User: ) Description: \Device\Ide\IdePort0 Error: (12/18/2013 09:33:21 PM) (Source: 0) (User: ) Description: \Device\Ide\IdePort0 Error: (12/18/2013 09:32:55 PM) (Source: 0) (User: ) Description: \Device\Ide\IdePort0 Error: (12/18/2013 09:32:31 PM) (Source: 0) (User: ) Description: \Device\Ide\IdePort0 Error: (12/18/2013 09:32:30 PM) (Source: 0) (User: ) Description: \Device\Ide\IdePort0 Microsoft Office Sessions: ========================= Error: (12/21/2013 03:59:13 PM) (Source: crypt32)(User: ) Description: hxxp://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txtDie Serververbindung konnte nicht hergestellt werden. Error: (12/19/2013 04:45:36 PM) (Source: PerfNet)(User: ) Description: Error: (12/19/2013 00:56:11 PM) (Source: Application Hang)(User: ) Description: iexplore.exe6.0.2900.5512hungapp0.0.0.000000000 Error: (12/19/2013 00:40:01 PM) (Source: PerfNet)(User: ) Description: Error: (12/19/2013 00:28:56 PM) (Source: PerfNet)(User: ) Description: Error: (12/19/2013 00:10:37 PM) (Source: PerfNet)(User: ) Description: Error: (12/19/2013 09:30:13 AM) (Source: PerfNet)(User: ) Description: Error: (12/19/2013 08:52:52 AM) (Source: Application Hang)(User: ) Description: iexplore.exe6.0.2900.5512hungapp0.0.0.000000000 Error: (12/19/2013 08:14:53 AM) (Source: PerfNet)(User: ) Description: Error: (12/18/2013 11:10:52 PM) (Source: PerfNet)(User: ) Description: ==================== Memory info =========================== Percentage of memory in use: 41% Total physical RAM: 3069.92 MB Available physical RAM: 1791.82 MB Total Pagefile: 4955.8 MB Available Pagefile: 3529.71 MB Total Virtual: 2047.88 MB Available Virtual: 1960.43 MB ==================== Drives ================================ Drive c: () (Fixed) (Total:232.88 GB) (Free:210.88 GB) NTFS ==>[Drive with boot components (Windows XP)] ==================== MBR & Partition Table ================== ======================================================== Disk: 0 (Size: 233 GB) (Disk ID: 600BADED) Partition 1: (Active) - (Size=233 GB) - (Type=07 NTFS) ==================== End Of Log ============================ |
Themen zu [XP, SP3]Facebook meldet Virus |
4d36e972-e325-11ce-bfc1-08002be10318, adblock, administrator, adobe, branding, chromium, cyberghost, desktop, einstellungen, emsisoft, explorer, flash player, format, gesperrt, google, helper, homepage, hotkey, mozilla, msiinstaller, netzwerkkarte, openvpn, plug-in, programme, realtek, registry, security, software, svchost.exe, system error, usb, virus, windows, windows xp |