![]() |
|
Log-Analyse und Auswertung: IE öffnet sich von selbst mit Werbung...Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
|
![]() | #1 |
| ![]() IE öffnet sich von selbst mit Werbung... und hier noch die Fortsetzung von gmer (war zu groß für nur eine Antwort...) C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueExW] [6C559BA7] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyExW] [6C559639] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegDeleteValueW] [6C559CF9] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegSetValueW] [6C559A53] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegCreateKeyW] [6C559498] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!SetFileSecurityW] [6C559DF4] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!AccessCheck] [6C55883A] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\SHELL32.dll [ADVAPI32.dll!RegOpenKeyExA] [6C559741] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!PrivCopyFileExW] [6C558EEA] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!MoveFileExW] [6C558C14] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!DeleteFileW] [6C558A65] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [70A14618] C:\Windows\system32\ShimEng.dll IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!CreateFileW] [6C55A391] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\USERENV.dll [KERNEL32.dll!SetFileAttributesW] [6C558FA6] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!SetFileSecurityW] [6C559DF4] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!RegCreateKeyExW] [6C559639] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!RegSetValueExW] [6C559BA7] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\USERENV.dll [ADVAPI32.dll!RegOpenKeyExW] [6C559815] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!CreateFileW] [6C55A391] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [70A14618] C:\Windows\system32\ShimEng.dll IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\Secur32.dll [ADVAPI32.dll!RegCreateKeyExW] [6C559639] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\Secur32.dll [ADVAPI32.dll!RegSetValueExW] [6C559BA7] C:\Windows\AppPatch\AcGenral.DLL IAT C:\Users\Stephie\Desktop\gmer\gmer.exe[3908] @ C:\Windows\system32\Secur32.dll [ADVAPI32.dll!RegOpenKeyExW] [6C559815] C:\Windows\AppPatch\AcGenral.DLL AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_CREATE [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_CREATE_NAMED_PIPE [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_CLOSE [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_READ [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_WRITE [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_QUERY_INFORMATION [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_SET_INFORMATION [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_QUERY_EA [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_SET_EA [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_FLUSH_BUFFERS [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_QUERY_VOLUME_INFORMATION [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_SET_VOLUME_INFORMATION [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_DIRECTORY_CONTROL [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_FILE_SYSTEM_CONTROL [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_DEVICE_CONTROL [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_INTERNAL_DEVICE_CONTROL [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_SHUTDOWN [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_LOCK_CONTROL [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_CLEANUP [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_CREATE_MAILSLOT [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_QUERY_SECURITY [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_SET_SECURITY [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_POWER [804F1F42] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_SYSTEM_CONTROL [804F1F42] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_DEVICE_CHANGE [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_QUERY_QUOTA [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass0 IRP_MJ_SET_QUOTA [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_CREATE [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_CREATE_NAMED_PIPE [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_CLOSE [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_READ [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_WRITE [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_QUERY_INFORMATION [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_SET_INFORMATION [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_QUERY_EA [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_SET_EA [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_FLUSH_BUFFERS [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_QUERY_VOLUME_INFORMATION [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_SET_VOLUME_INFORMATION [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_DIRECTORY_CONTROL [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_FILE_SYSTEM_CONTROL [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_DEVICE_CONTROL [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_INTERNAL_DEVICE_CONTROL [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_SHUTDOWN [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_LOCK_CONTROL [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_CLEANUP [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_CREATE_MAILSLOT [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_QUERY_SECURITY [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_SET_SECURITY [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_POWER [804F1F42] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_SYSTEM_CONTROL [804F1F42] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_DEVICE_CHANGE [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_QUERY_QUOTA [804F1D1B] Wdf01000.sys AttachedDevice \Driver\kbdclass \Device\KeyboardClass1 IRP_MJ_SET_QUOTA [804F1D1B] Wdf01000.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_CREATE [826B07F0] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_CREATE_NAMED_PIPE [826B07F0] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_CLOSE [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_READ [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_WRITE [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_QUERY_INFORMATION [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_SET_INFORMATION [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_QUERY_EA [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_SET_EA [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_FLUSH_BUFFERS [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_QUERY_VOLUME_INFORMATION [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_SET_VOLUME_INFORMATION [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_DIRECTORY_CONTROL [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_FILE_SYSTEM_CONTROL [826B0DC8] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_DEVICE_CONTROL [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_INTERNAL_DEVICE_CONTROL [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_SHUTDOWN [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_LOCK_CONTROL [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_CLEANUP [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_CREATE_MAILSLOT [826B07F0] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_QUERY_SECURITY [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_SET_SECURITY [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_POWER [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_SYSTEM_CONTROL [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_DEVICE_CHANGE [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_QUERY_QUOTA [8269EB56] fltmgr.sys AttachedDevice \FileSystem\fastfat \Fat IRP_MJ_SET_QUOTA [8269EB56] fltmgr.sys ---- Registry - GMER 1.0.13 ---- Reg \Registry\USER\S-1-5-21-4022781497-3537278231-3995956278-1003\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY@?? 0x34 0xEC 0x65 0x4A ... Reg \Registry\USER\S-1-5-21-4022781497-3537278231-3995956278-1003\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY@?? 0xE3 0xC1 0xD6 0x7C ... ---- EOF - GMER 1.0.13 ---- |
![]() |
Themen zu IE öffnet sich von selbst mit Werbung... |
adobe, antivir, avg, avira, bho, defender, desktop, download, ebay, explorer, gservice, hijack, hijackthis, hilfe!!, hilfe!!!, internet, internet explorer, launch, microsoft, monitor, object, pdf, problem, senden, shockwave, svchost.exe, uleadburninghelper, unknown file in winsock lsp, von selbst, windows, windows defender, windows sidebar, wmp, öffnet |