![]() |
|
Log-Analyse und Auswertung: Cleaner für Problem about:blank funktioniert nichtWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #16 |
![]() | ![]() Cleaner für Problem about:blank funktioniert nicht sorry, dass mit escan war beim ersten Mal nicht so richtig angekommen. Sind ein bisschen viel neue Tools in den letzten Tagen. Nun aber nachstehend das Log. Ganz unten dann log von startdreck. Damit konnte ich allerdings nicht sehr viel anfangen, ich hoffe das ist die Liste, die Ihr sehen wollt. Bin völlig frustiert vom escan: Was bitte haben Norton-Anivrus und die Firewall die letzten 2 Jahre getan ???????? Gruß, Anja P.s. IE 6 sofort laden oder erst wenn System wieder sauber ?? File C:\WINDOWS\SYSTEM\WINXS32.DLL infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINDOWS\ADDMF.EXE infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\WINDOWS\ADDMF.EXE infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\IPOW.EXE infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\IPOW.EXE infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\WINXS32.DLL infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\IPOW.EXE infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\WINDOWS\ADDMF.EXE infected by "Trojan.Win32.Agent.bi" Virus! Action Taken: No Action Taken. Object "sw Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "CoolWebSearch Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "hsa Spyware/Adware" found in File System! Action Taken: No Action Taken. Object "ISearchTech Spyware/Adware" found in File System! Action Taken: No Action Taken. File C:\WINDOWS\gato.dll tagged as "not-a-virus:AdWare.AdBreak". Action Taken: No Action Taken. File C:\WINDOWS\od-boob18.exe tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\WINDOWS\od-stnd500.exe tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\WINDOWS\od-stnd499.exe tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\WINDOWS\od-stnd196.exe tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\WINDOWS\od-stnd327.exe tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\WINDOWS\winrn32.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\ydaa.dll infected by "Trojan-Downloader.Win32.Small.ats" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\appev.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINDOWS\TEMP\E385.TMP infected by "Trojan-Downloader.Win32.WinShow.ay" Virus! Action Taken: No Action Taken. File C:\WINDOWS\TEMP\91D1.TMP infected by "Trojan-Downloader.Win32.WinShow.ay" Virus! Action Taken: No Action Taken. File C:\WINDOWS\TEMPOR~1\CONTENT.IE5\IMQOSQ91\granny-thumbs[1] infected by "Trojan-Clicker.JS.Linker.c" Virus! Action Taken: No Action Taken. File C:\WINDOWS\TEMPOR~1\CONTENT.IE5\WTU3C1A3\go[1].hta infected by "Trojan-Dropper.VBS.Inor.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\TEMPOR~1\CONTENT.IE5\CF0VI56F\go[2].hta infected by "Trojan-Dropper.VBS.Inor.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\TEMPOR~1\CONTENT.IE5\4PMZ4P27\Counters[1].jar tagged as "not-a-virus:Porn-Dialer.Win32.RelaxDial". Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\ydaa.dll infected by "Trojan-Downloader.Win32.Small.ats" Virus! Action Taken: No Action Taken. File C:\WINDOWS\SYSTEM\appev.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\WINDOWS\TEMP\E385.TMP infected by "Trojan-Downloader.Win32.WinShow.ay" Virus! Action Taken: No Action Taken. File C:\WINDOWS\TEMP\91D1.TMP infected by "Trojan-Downloader.Win32.WinShow.ay" Virus! Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\hotxxx.exe tagged as "not-a-virus:Porn-Dialer.Win32.StarLux". Action Taken: No Action Taken. File C:\WINDOWS\Downloaded Program Files\topsex.exe tagged as "not-a-virus:Porn-Dialer.Win32.StarLux". Action Taken: No Action Taken. File C:\WINDOWS\Temporary Internet Files\Content.IE5\IMQOSQ91\granny-thumbs[1] infected by "Trojan-Clicker.JS.Linker.c" Virus! Action Taken: No Action Taken. File C:\WINDOWS\Temporary Internet Files\Content.IE5\WTU3C1A3\go[1].hta infected by "Trojan-Dropper.VBS.Inor.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\Temporary Internet Files\Content.IE5\CF0VI56F\go[2].hta infected by "Trojan-Dropper.VBS.Inor.a" Virus! Action Taken: No Action Taken. File C:\WINDOWS\Temporary Internet Files\Content.IE5\4PMZ4P27\Counters[1].jar tagged as "not-a-virus:Porn-Dialer.Win32.RelaxDial". Action Taken: No Action Taken. File C:\WINDOWS\gato.dll tagged as "not-a-virus:AdWare.AdBreak". Action Taken: No Action Taken. File C:\WINDOWS\od-boob18.exe tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\WINDOWS\od-stnd500.exe tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\WINDOWS\od-stnd499.exe tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\WINDOWS\od-stnd196.exe tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\WINDOWS\od-stnd327.exe tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\WINDOWS\winrn32.dll infected by "Trojan-Downloader.Win32.Agent.bc" Virus! Action Taken: No Action Taken. File C:\Programme\Norton SystemWorks\Norton CleanSweep\Backup\5-4-2740.BUD tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\Programme\Norton SystemWorks\Norton CleanSweep\Backup\5-4-9211.BUD tagged as "not-a-virus:Porn-Dialer.Win32.Generic". Action Taken: No Action Taken. File C:\Programme\Norton SystemWorks\Norton CleanSweep\Backup\od-t6389.BUD tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\Programme\Norton SystemWorks\Norton CleanSweep\Backup\od-s8410.BUD tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\Programme\Norton SystemWorks\Norton CleanSweep\Backup\od-s1853.BUD tagged as "not-a-virus:Porn-Dialer.Win32.WebDialer". Action Taken: No Action Taken. File C:\Programme\Norton SystemWorks\Norton CleanSweep\Backup\mfcw7709.BUD infected by "Trojan-Downloader.Win32.Agent.bq" Virus! Action Taken: No Action Taken. File C:\Recycled\Q678340.exe infected by "Trojan-Downloader.Win32.Small.rr" Virus! Action Taken: No Action Taken. File C:\Recycled\Q330995.exe infected by "Trojan-Downloader.Win32.Small.amb" Virus! Action Taken: No Action Taken. File C:\1970.exe tagged as "not-a-virus:Porn-Dialer.Win32.Generic". Action Taken: No Action Taken. File C:\1286.exe tagged as "not-a-virus:Porn-Dialer.Win32.Generic". Action Taken: No Action Taken. File C:\ms32.tmp infected by "Trojan-Downloader.Win32.Small.ats" Virus! Action Taken: No Action Taken. StartDreck (build 2.1.7 public stable) - 2005-05-24 @ 18:33:24 (GMT +02:00) Platform: Windows ME (Win 4.90.3000 ) Internet Explorer: 5.50.4134.0100 Logged in as Standard at PPP221 »Registry »Run Keys »Current User »Run *Reminder=C:\Programme\Microsoft Money\System\reminder.exe *Taskbar Display Controls=RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY »RunOnce »Default User »Run *Reminder=C:\Programme\Microsoft Money\System\reminder.exe *Taskbar Display Controls=RunDLL deskcp16.dll,QUICKRES_RUNDLLENTRY »RunOnce »Local Machine »Run *ScanRegistry=C:\WINDOWS\scanregw.exe /autorun *PCHealth=C:\WINDOWS\PCHealth\Support\PCHSchd.exe -s *SystemTray=SysTray.Exe *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *POINTER=C:\Programme\Microsoft Hardware\Mouse\point32.exe *HaMFrontPanel=C:\WINDOWS\hampanel /B:Software\Ambient\HaM *CHotKey=mHotkey.exe *NvColorInit=RUNDLL32.EXE NVQTWK.DLL,NvColorInit *ccApp="C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" *ccRegVfy="C:\Programme\Gemeinsame Dateien\Symantec Shared\ccRegVfy.exe" *NPROTECT=C:\Programme\Norton SystemWorks\Norton Utilities\NPROTECT.EXE *Symantec NetDriver Warning=C:\PROGRA~1\SYMNET~1\SNDWARN.EXE *IEXPLORE.EXE=C:\PROGRAMME\INTERNET EXPLORER\IEXPLORE.EXE *IPOW.EXE=C:\WINDOWS\SYSTEM\IPOW.EXE +OptionalComponents +IMAIL *Installed=1 +MAPI *NoChange=1 *Installed=1 +MAPI *NoChange=1 *Installed=1 »RunOnce »RunServices *SchedulingAgent=mstask.exe *SSDPSRV=C:\WINDOWS\SYSTEM\ssdpsrv.exe **StateMgr=C:\WINDOWS\System\Restore\StateMgr.exe *StillImageMonitor=C:\WINDOWS\SYSTEM\STIMON.EXE *ccEvtMgr="C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe" *ScriptBlocking="C:\Programme\Gemeinsame Dateien\Symantec Shared\Script Blocking\SBServ.exe" -reg *CSINJECT.EXE=C:\Programme\Norton SystemWorks\Norton CleanSweep\CSINJECT.EXE *NPROTECT=C:\Programme\Norton SystemWorks\Norton Utilities\NPROTECT.EXE *SymTray - Norton SystemWorks=C:\Programme\Gemeinsame Dateien\Symantec Shared\SymTray.exe "Norton SystemWorks" *Nisum=C:\Programme\Norton Personal Firewall\NISUM.EXE *ccPxySvc=C:\PROGRA~1\NORTON~3\CCPXYSVC.EXE *Machine Debug Manager=C:\WINDOWS\SYSTEM\MDM.EXE *LoadPowerProfile=Rundll32.exe powrprof.dll,LoadCurrentPwrScheme *ADDMF.EXE=C:\WINDOWS\ADDMF.EXE /s »RunServicesOnce »RunOnceEx »RunServicesOnceEx »File Associations (CR) +.bat *batfile="%1" %* +.com *comfile="%1" %* +.disabled *SpybotSD.DisabledFile="C:\PROGRAMME\SPYBOT - SEARCH & DESTROY\blindman.exe" "%1" +.exe *exefile="%1" %* +.hta *htafile=C:\WINDOWS\SYSTEM\MSHTA.EXE "%1" %* +.htm *htmlfile="C:\PROGRA~1\INTERN~1\iexplore.exe" -nohome +.html *htmlfile="C:\PROGRA~1\INTERN~1\iexplore.exe" -nohome +.js *JSFile=C:\WINDOWS\WScript.exe "%1" %* +.jse *JSEFile=C:\WINDOWS\WScript.exe "%1" %* +.pif *piffile="%1" %* +.reg *regfile=regedit.exe "%1" +.scr *scrfile="%1" /S +.txt *txtfile=C:\WINDOWS\NOTEPAD.EXE %1 +.vbs *VBSFile=C:\WINDOWS\WScript.exe "%1" %* +.vbe *VBEFile=C:\WINDOWS\WScript.exe "%1" %* +.wsh *WSHFile=C:\WINDOWS\WScript.exe "%1" %* +.wsf *WSFFile=C:\WINDOWS\WScript.exe "%1" %* +.lnk `lnkfile= [key or value does not exist] »Browser Helper Objects (LM) *Navbho.CNavExtBho.1/{BDF3E430-B101-42AD-A544-FADC6B084872} `InprocServer32=C:\Programme\Norton SystemWorks\Norton AntiVirus\NavShExt.dll *AcroIEHelper.AcroIEHlprObj.1/{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} `InprocServer32=C:\PROGRAMME\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX *Class/{989B58CA-7938-6DF7-7AC1-44A97F291E4E} `InprocServer32=C:\WINDOWS\SYSTEM\WINXS32.DLL »Files »Autostart Folders »Current User *C:\WINDOWS\Startmenü\Programme\Autostart\Microsoft Office.lnk *C:\WINDOWS\Startmenü\Programme\Autostart\CleanSweep Smart Sweep-Internet Sweep.lnk *C:\WINDOWS\Startmenü\Programme\Autostart\WinZip Quick Pick.lnk »Default User *C:\WINDOWS\Startmenü\Programme\Autostart\Microsoft Office.lnk *C:\WINDOWS\Startmenü\Programme\Autostart\CleanSweep Smart Sweep-Internet Sweep.lnk *C:\WINDOWS\Startmenü\Programme\Autostart\WinZip Quick Pick.lnk »Local Machine »INI-Files »WIN.INI\[windows] *LOAD= *RUN= »SYSTEM.INI\[boot] *SHELL=Explorer.exe »Text Files *C:\WINDOWS\msdos.sys *C:\msdos.sys *C:\config.sys *C:\autoexec.bat *C:\WINDOWS\wininit.bak *C:\WINDOWS\winstart.bat *C:\WINDOWS\dosstart.bat *C:\WINDOWS\command\cmdinit.bat »System/Drivers »Running Processes +FF0F1E4D=C:\WINDOWS\SYSTEM\KERNEL32.DLL +FFFFEBAD=C:\WINDOWS\SYSTEM\MSGSRV32.EXE +FFFE4C6D=C:\WINDOWS\SYSTEM\mmtask.tsk +FFFE4611=C:\WINDOWS\SYSTEM\MPREXE.EXE +FFFE60A5=C:\WINDOWS\SYSTEM\MSTASK.EXE +FFFE7359=C:\WINDOWS\SYSTEM\SSDPSRV.EXE +FFFEC47D=C:\WINDOWS\SYSTEM\STIMON.EXE +FFFEFCC5=C:\PROGRAMME\GEMEINSAME DATEIEN\SYMANTEC SHARED\CCEVTMGR.EXE +FFFD6899=C:\PROGRAMME\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINJECT.EXE +FFFD0531=C:\PROGRAMME\NORTON SYSTEMWORKS\NORTON UTILITIES\NPROTECT.EXE +FFFD16E1=C:\PROGRAMME\GEMEINSAME DATEIEN\SYMANTEC SHARED\SYMTRAY.EXE +FFFD3F6D=C:\PROGRAMME\NORTON PERSONAL FIREWALL\NISUM.EXE +FFFDDE8D=C:\PROGRAMME\NORTON PERSONAL FIREWALL\CCPXYSVC.EXE +FFFDF16D=C:\WINDOWS\SYSTEM\MDM.EXE +FFFD9B3D=C:\WINDOWS\EXPLORER.EXE +FFFC4BF9=C:\WINDOWS\ADDMF.EXE +FFFC0AC9=C:\WINDOWS\SYSTEM\RESTORE\STMGR.EXE +FFF9702D=C:\WINDOWS\SYSTEM\SYSTRAY.EXE +FFF92309=C:\PROGRAMME\MICROSOFT HARDWARE\MOUSE\POINT32.EXE +FFF9D741=C:\WINDOWS\SYSTEM\WMIEXE.EXE +FFF9FF1D=C:\WINDOWS\HAMPANEL.EXE +FFF98C65=C:\WINDOWS\MHOTKEY.EXE +FFF9C235=C:\PROGRAMME\GEMEINSAME DATEIEN\SYMANTEC SHARED\CCAPP.EXE +FFF8F6DD=C:\WINDOWS\SYSTEM\IPOW.EXE +FFF7507D=C:\PROGRAMME\MICROSOFT MONEY\SYSTEM\REMINDER.EXE +FFF72CBD=C:\WINDOWS\RunDLL.exe +FFF80BDD=C:\PROGRAMME\NORTON SYSTEMWORKS\NORTON CLEANSWEEP\CSINSM32.EXE +FFF80651=C:\PROGRAMME\WINZIP\WZQKPICK.EXE +FFF7E0E1=C:\Programme\Norton SystemWorks\Norton CleanSweep\Monwow.exe +FFFA4399=C:\PROGRAMME\MICROSOFT OFFICE\OFFICE\WINWORD.EXE +FFF70FC9=C:\PROGRAMME\MICROSOFT WORKS\MSWORKS.EXE +FFFAA411=C:\WINDOWS\SYSTEM\SPOOL32.EXE +FFF346B1=C:\WINDOWS\SYSTEM\HPZSTATX.EXE +FFF23A5D=C:\WINDOWS\EXPLORER.EXE +FFF8E41D=C:\PROGRAMME\STARTDRECK217\STARTDRECK.EXE »NT Services »Application specific |
Themen zu Cleaner für Problem about:blank funktioniert nicht |
about, about:blank, ad-aware, bla, blank, cleaner, diverse, ergebnis, fehler, files, folge, found, funktioniert, funktioniert nicht, gen, hallo zusammen, löschen, nichts, not, problem, reboot, software, steal, task-manager, vielen dank, windows |