![]() |
| |||||||
Log-Analyse und Auswertung: EXP/Exploit.MS04-28.JPEG.A beim Drehen von BildernWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
| | #1 |
| | EXP/Exploit.MS04-28.JPEG.A beim Drehen von Bildern Hallo PC-Kenner, schön dass es euch gibt! Problembeschreibung: Nachdem ich heute mit der Digitalkamera Bilder gemacht habe, diese auf den PC übertragen habe, wollte ich einige davon zurechtdrehen. Unabhängig davon, dass einige bilder halb-rosa, verschoben, überbelichtet oder andere merkwürdigkeiten aufweisen, erscheint eine Fehlermeldung von Antivir: "Auf Ihrem Computer wurde ein Virus oder unerwünschtes Programm gefunden!.. usw... C:\Users\XXXXXXX\AppData\Local\Temp\~PIB14A.tmp erhält das Erkennungsmuster des Exploits EXP/Exploit.MS04-28.JPEG.A" Man kann die Möglichkeit "Reparieren" nicht auswählen. Was kann das sein, ihr könnt mir sicher weiterhelfen, nachdem Google zu diesen Thema leider keine weiteren Informationen ausgespuckt hat.. Mein System: ASUS G2SV-7R011J OS: Vista Ultimate 64, SP1 Angeschlossene Hardware: Logitech MX518, Samsung CLP 315 (Drucker), ein SIGMA USB-Hub und eine Externe HDD von Maxtor Anhand des nachfolgenden HJT-Logs, könnt ihr mir sicher weiterhelfen, ich habe allen Anweisungen befolgt, damit der Log leserlich und anonym ist, ich hoffe das hat geklappt. Sollten jemandem zufällig unnütze Programme oder leistungsmindernder Abfall auffallen, könnt ihr mich anhand dieser "Psychoanalyse" sehr gern darauf aufmerksam machen. Vielen lieben Dank im Voraus! ![]() Hier der LOG: Code:
ATTFilter Logfile of Trend Micro HijackThis v2.0.2 Code:
ATTFilter Scan saved at 22:52:59, on 07.12.2008
Code:
ATTFilter Platform: Windows Vista SP1 (WinNT 6.00.1905)
Code:
ATTFilter MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Code:
ATTFilter Boot mode: Normal
Code:
ATTFilter Running processes:
Code:
ATTFilter C:\Program Files (x86)\ASUS\ASUS Live Update\ALU.exe
Code:
ATTFilter C:\Program Files\ATKOSD2\ATKOSD2.exe
Code:
ATTFilter C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
Code:
ATTFilter C:\Program Files\ASUS\ASUS Direct Console\LCMP.exe
Code:
ATTFilter C:\Windows\Samsung\PanelMgr\SSMMgr.exe
Code:
ATTFilter C:\Program Files\SetPoint\x86\SetPoint32.exe
Code:
ATTFilter C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\avgnt.exe
Code:
ATTFilter C:\Program Files (x86)\Microsoft Office\Office12\OUTLOOK.EXE
Code:
ATTFilter C:\Program Files (x86)\Mozilla Firefox\firefox.exe
Code:
ATTFilter C:\Program Files (x86)\Trillian\trillian.exe
Code:
ATTFilter C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe
Code:
ATTFilter C:\Program Files (x86)\Skype\Phone\Skype.exe
Code:
ATTFilter C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
Code:
ATTFilter C:\Windows\SysWOW64\conime.exe
Code:
ATTFilter C:\Users\XXXXXXXX\Desktop\HiJackThis.exe
Code:
ATTFilter h**p://go.microsoft.com/fwlink/?LinkId=54896
Code:
ATTFilter h**p://go.microsoft.com/fwlink/?LinkId=69157
Code:
ATTFilter h**p://go.microsoft.com/fwlink/?LinkId=69157
Code:
ATTFilter h**p://go.microsoft.com/fwlink/?LinkId=54896
Code:
ATTFilter h**p://go.microsoft.com/fwlink/?LinkId=54896
Code:
ATTFilter h**p://go.microsoft.com/fwlink/?LinkId=69157
Code:
ATTFilter R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
Code:
ATTFilter R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
Code:
ATTFilter R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
Code:
ATTFilter R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
Code:
ATTFilter F2 - REG:system.ini: UserInit=userinit.exe
Code:
ATTFilter O1 - Hosts: ::1 localhost
Code:
ATTFilter O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
Code:
ATTFilter O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
Code:
ATTFilter O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
Code:
ATTFilter O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dll
Code:
ATTFilter O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dll
Code:
ATTFilter O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
Code:
ATTFilter O4 - HKLM\..\Run: [ATKOSD2] "C:\Program Files\ATKOSD2\ATKOSD2.exe"
Code:
ATTFilter O4 - HKLM\..\Run: [ATKMEDIA] "C:\Program Files (x86)\ASUS\ATK Media\DMEDIA.EXE"
Code:
ATTFilter O4 - HKLM\..\Run: [zDirectMessenger] "C:\Program Files\ASUS\ASUS Direct Console\LCMP.EXE"
Code:
ATTFilter O4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exe
Code:
ATTFilter O4 - HKLM\..\Run: [Samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorun
Code:
ATTFilter O4 - HKLM\..\Run: [avgnt] "C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
Code:
ATTFilter O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
Code:
ATTFilter O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
Code:
ATTFilter O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
Code:
ATTFilter O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
Code:
ATTFilter O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
Code:
ATTFilter O4 - Global Startup: SetPoint.lnk = ?
Code:
ATTFilter O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
Code:
ATTFilter O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
Code:
ATTFilter O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~2\Java\JRE16~1.0_0\bin\ssv.dll
Code:
ATTFilter O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
Code:
ATTFilter O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
Code:
ATTFilter O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
Code:
ATTFilter O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
Code:
ATTFilter O13 - Gopher Prefix:
Code:
ATTFilter 16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - h**p://messenger.zone.msn.com/DE-DE/a-UNO1/GAME_UNO1.cab
Code:
ATTFilter O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - h**p://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
Code:
ATTFilter O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - h**p://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
Code:
ATTFilter O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
Code:
ATTFilter O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
Code:
ATTFilter O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files (x86)\Common Files\Acronis\Schedule2\schedul2.exe
Code:
ATTFilter O23 - Service: Adobe LM Service - Unknown owner - C:\Program Files (x86)\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
Code:
ATTFilter O23 - Service: ADSM Service (ADSMService) - Unknown owner - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
Code:
ATTFilter O23 - Service: Avira AntiVir Personal - Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\sched.exe
Code:
ATTFilter O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files (x86)\Avira\AntiVir PersonalEdition Classic\avguard.exe
Code:
ATTFilter O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files (x86)\ATK Hotkey\ASLDRSrv.exe
Code:
ATTFilter O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
Code:
ATTFilter O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files (x86)\Common Files\Autodesk Shared\Service\AdskScSrv.exe
Code:
ATTFilter O23 - Service: Automatisches LiveUpdate - Scheduler (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:\Program Files (x86)\Symantec\LiveUpdate\AluSchedulerSvc.exe
Code:
ATTFilter O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
Code:
ATTFilter O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
Code:
ATTFilter O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\EvtEng.exe
Code:
ATTFilter O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
Code:
ATTFilter O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
Code:
ATTFilter O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
Code:
ATTFilter O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
Code:
ATTFilter O23 - Service: LiveUpdate - Symantec Corporation - C:\Program Files (x86)\Symantec\LiveUpdate\LuComServer_3_4.EXE
Code:
ATTFilter O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
Code:
ATTFilter O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
Code:
ATTFilter O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
Code:
ATTFilter O23 - Service: O&O Defrag - Unknown owner - C:\Windows\system32\oodag.exe (file missing)
Code:
ATTFilter O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
Code:
ATTFilter O23 - Service: PnkBstrB - Unknown owner - C:\Windows\system32\PnkBstrB.exe
Code:
ATTFilter O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
Code:
ATTFilter O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Program Files\Intel\Wireless\Bin\RegSrvc.exe
Code:
ATTFilter O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
Code:
ATTFilter O23 - Service: spmgr - Unknown owner - C:\Program Files (x86)\ASUS\NB Probe\SPM\spmgr.exe
Code:
ATTFilter O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
Code:
ATTFilter O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
Code:
ATTFilter O23 - Service: Acronis Try And Decide Service (TryAndDecideService) - Unknown owner - C:\Program Files (x86)\Common Files\Acronis\Fomatik\TrueImageTryStartService.exe
Code:
ATTFilter O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - Unknown owner - C:\Windows\System32\TuneUpDefragService.exe (file missing)
Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
Code:
ATTFilter O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
Code:
ATTFilter O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
Code:
ATTFilter O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
Code:
ATTFilter O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
Code:
ATTFilter O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
Code:
ATTFilter End of file - 10904 bytes
|
| Themen zu EXP/Exploit.MS04-28.JPEG.A beim Drehen von Bildern |
| add-on, antivir, antivirus, avgnt.exe, avira, bho, bonjour, browser, computer, desktop, excel, firefox, firefox.exe, gfnexsrv.exe, google, hijack, hijackthis, local\temp, logfile, object, programm, scan, sched.exe, security, senden, skype.exe, software, symantec, system, syswow64, toolbars, tuneup.defrag, userinit.exe, virus, vista, windows, windows sidebar |