![]() |
|
Log-Analyse und Auswertung: 2 mal iexplorer.exeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #16 |
![]() | ![]() 2 mal iexplorer.exe FIxwareout Report: Username "A**** T****" - 09.12.2007 15:15:30 [Fixwareout edited 9/01/2007] ~~~~~ Prerun check HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters "nameserver"="85.255.115.58 85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{507C0D22-2A91-46EF-B6B2-ADFAA20BD7E1} "nameserver"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{59F726AD-5337-4F2C-848E-53258A4A046B} "nameserver"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{62B32074-5B26-46DC-944D-0FACE7124250} "nameserver"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{AF88EC71-67A7-434D-AB89-8B51DF1B9D28} "nameserver"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{B4937DE5-2C00-4764-A4D2-BA1AABE5FBE4} "nameserver"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{D5199E48-F0AB-425F-B433-1AE144A3E2FA} "nameserver"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{D52BA482-ED36-47BC-AE56-B14E7D8592E7} "nameserver"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{ECF4994B-E4C3-4381-B91A-A1A3FC71C323} "nameserver"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{F7AD1209-C40A-491F-AEB0-750C73EE51D7} "nameserver"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{62B32074-5B26-46DC-944D-0FACE7124250} "DhcpNameServer"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{758FCB2A-4B8E-4C29-AEAB-510BC4BB3CF3} "DhcpNameServer"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{AF88EC71-67A7-434D-AB89-8B51DF1B9D28} "DhcpNameServer"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{B4937DE5-2C00-4764-A4D2-BA1AABE5FBE4} "DhcpNameServer"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{D5199E48-F0AB-425F-B433-1AE144A3E2FA} "DhcpNameServer"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{D52BA482-ED36-47BC-AE56-B14E7D8592E7} "DhcpNameServer"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{ECF4994B-E4C3-4381-B91A-A1A3FC71C323} "DhcpNameServer"="85.255.115.58,85.255.112.159" <Value cleared. HKEY_LOCAL_MACHINE\system\currentcontrolset\services\tcpip\parameters\interfaces\{F7AD1209-C40A-491F-AEB0-750C73EE51D7} "DhcpNameServer"="85.255.115.58,85.255.112.159" <Value cleared. Der DNS-Auflösungscache wurde geleert. System was rebooted successfully. ~~~~~ Postrun check HKLM\SOFTWARE\~\Winlogon\ "System"="" .... .... ~~~~~ Misc files. .... ~~~~~ Checking for older varients. .... ~~~~~ Current runs (hklm hkcu "run" Keys Only) [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "Verknüpfung mit der High Definition Audio-Eigenschaftenseite"="HDAShCut.exe" "RTHDCPL"="RTHDCPL.EXE" "SkyTel"="SkyTel.EXE" "Alcmtr"="ALCMTR.EXE" "BluetoothAuthenticationAgent"="rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent" "WinampAgent"="C:\\Programme\\Winamp\\winampa.exe" "NeroFilterCheck"="C:\\Programme\\Gemeinsame Dateien\\Ahead\\Lib\\NeroCheck.exe" "HotKey"="C:\\Programme\\HotKey\\hotkey.exe" "AVMWlanClient"="C:\\Programme\\avmwlanstick\\wlangui.exe" "HP Software Update"="C:\\Programme\\HP\\HP Software Update\\HPWuSchd2.exe" "NvCplDaemon"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvCpl.dll,NvStartup" "nwiz"="nwiz.exe /install" "NvMediaCenter"="RUNDLL32.EXE C:\\WINDOWS\\system32\\NvMcTray.dll,NvTaskbarInit" "SunJavaUpdateSched"="\"C:\\Programme\\Java\\jre1.6.0_03\\bin\\jusched.exe\"" "BigDog305"="C:\\WINDOWS\\VM305_STI.EXE VIMICRO USB PC Camera (ZC0305)" "avgnt"="\"C:\\Programme\\AntiVir PersonalEdition Classic\\avgnt.exe\" /min" [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "CTFMON.EXE"="C:\\WINDOWS\\system32\\ctfmon.exe" "SkinClock"="C:\\Programme\\Desktop Tray Clock\\DTClock.exe" "BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"="\"C:\\Programme\\Gemeinsame Dateien\\Ahead\\Lib\\NMBgMonitor.exe\"" "TuneUp MemOptimizer"="\"C:\\Programme\\TuneUp Utilities 2007\\MemOptimizer.exe\" autostart" "clockfile"="C:\\DOKUME~1\\ANLACT~1\\ANWEND~1\\BLAHON~1\\ace amen.exe" .... Hosts file was reset, If you use a custom hosts file please replace it... ~~~~~ End report ~~~~~ |
Themen zu 2 mal iexplorer.exe |
andere probleme, antivir, avira, bho, browser, desktop, firefox, helper, hijack, hijackthis, hkus\s-1-5-18, iexplorer.exe, internet, internet explorer, logfile, magix, mozilla, mozilla firefox, problem, prozesse, rundll, s-1-5-18, senden, software, stick, system, trend micro, tuneup utilities, usb, vista, wenig ahnung, windows, windows xp |