![]() |
|
Log-Analyse und Auswertung: IE öffnet Werbefenster (Firefox Benutzer), Virus msb.exe & b.exe etc.Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #4 |
| ![]() IE öffnet Werbefenster (Firefox Benutzer), Virus msb.exe & b.exe etc. Und als letztes: CCleaner-Ergebnisse: Code:
ATTFilter Acrobat.com Adobe Creative Suite 3 Design Premium hinzufügen oder entfernen Adobe Creative Suite 4 Master Collection Adobe Flash Player 10 ActiveX Adobe Flash Player 10 Plugin Adobe Reader 9.1.2 - Deutsch Apple Application Support Apple Mobile Device Support Apple Software Update Avira AntiVir Personal - Free Antivirus Bonjour Canon i350 CCleaner CDBurnerXP ConvertXtoDVD 3.8.0.193f DisplayManager DivX Codec DivX Converter DivX Player DivX Plus DirectShow Filters DivX Web Player High Definition Audio - KB888111 HijackThis 2.0.2 InfraRecorder Intel(R) PROSet/Wireless Software iTunes Java(TM) 6 Update 15 Last.fm 1.5.4.24567 Logitech QuickCam Logitech QuickCam-Treiberpaket Logitech Updater Magic Keyboard Microsoft .NET Framework 2.0 Service Pack 2 Microsoft .NET Framework 2.0 Service Pack 2 Language Pack - DEU Microsoft .NET Framework 3.0 Service Pack 2 Microsoft .NET Framework 3.0 Service Pack 2 Language Pack - DEU Microsoft .NET Framework 3.5 Language Pack SP1 - DEU Microsoft .NET Framework 3.5 SP1 Microsoft Office Enterprise 2007 Microsoft Office Live Add-in 1.3 Microsoft Silverlight Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17 Mozilla Firefox (3.5.3) Mozilla Thunderbird (2.0.0.22) MSXML 4.0 SP2 (KB954430) MSXML 6.0 Parser Notebook Hardware Control 2.0 Pre-Release-06 Bugfix NVIDIA Drivers NVIDIA PureVideo Decoder QuickTime Security Update for Windows Search 4 - KB963093 SENS LT56ADW Modem Skype™ 4.0 SoundMAX Total Commander (Remove or Repair) TuneUp Utilities 2009 Update für Windows XP (KB943729) Vodafone Mobile Connect Modem Winamp Winamp Toolbar Windows Genuine Advantage Validation Tool (KB892130) Windows Live Anmelde-Assistent Windows Live Essentials Windows Live-Uploadtool Windows Search 4.0 Windows XP Service Pack 3 WOW XT and TSXT Filter Driver XnView 1.96 Xvid 1.2.1 final uninstall GMER-Ergebnisse: Code:
ATTFilter GMER 1.0.15.15163 - http://www.gmer.net Rootkit scan 2009-10-27 05:38:27 Windows 5.1.2600 Service Pack 3 Running: malschauen.exe; Driver: C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\pxtdqpow.sys ---- System - GMER 1.0.15 ---- SSDT F7FB3AC6 ZwCreateKey SSDT F7FB3ABC ZwCreateThread SSDT F7FB3ACB ZwDeleteKey SSDT F7FB3AD5 ZwDeleteValueKey SSDT F7FB3ADA ZwLoadKey SSDT F7FB3AA8 ZwOpenProcess SSDT F7FB3AAD ZwOpenThread SSDT F7FB3AE4 ZwReplaceKey SSDT F7FB3ADF ZwRestoreKey SSDT F7FB3AD0 ZwSetValueKey SSDT F7FB3AB7 ZwTerminateProcess ---- User IAT/EAT - GMER 1.0.15 ---- IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\ole32.dll [USER32.dll!CreateWindowExA] [00419808] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\ole32.dll [USER32.dll!CreateWindowExW] [00419880] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\ole32.dll [USER32.dll!DialogBoxParamW] [00419A12] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\ole32.dll [USER32.dll!MessageBoxW] [00419A1E] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\ole32.dll [USER32.dll!ShowWindow] [004198F8] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\wininet.dll [USER32.dll!CreateWindowExW] [00419880] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\wininet.dll [USER32.dll!MessageBoxW] [00419A1E] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\wininet.dll [USER32.dll!SetWindowPos] [004199A6] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\wininet.dll [USER32.dll!DialogBoxParamW] [00419A12] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!DialogBoxParamA] [00419A12] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!DialogBoxParamW] [00419A12] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!CreateWindowExA] [00419808] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!CreateWindowExW] [00419880] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!MessageBoxA] [00419A1E] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!MessageBoxW] [00419A1E] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!MessageBoxIndirectA] [00419A0C] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!MessageBoxIndirectW] [00419A0C] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [004199A6] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!ShowWindow] [004198F8] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\shell32.dll [USER32.dll!CreateWindowExW] [00419880] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\shell32.dll [USER32.dll!DialogBoxParamW] [00419A12] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\shell32.dll [USER32.dll!ShowWindow] [004198F8] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\shell32.dll [USER32.dll!SetWindowPos] [004199A6] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\shell32.dll [USER32.dll!MessageBoxW] [00419A1E] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\shell32.dll [USER32.dll!MessageBoxA] [00419A1E] C:\WINXP\msb.exe IAT C:\WINXP\msb.exe[348] @ C:\WINXP\system32\shell32.dll [USER32.dll!MessageBoxIndirectW] [00419A0C] C:\WINXP\msb.exe IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\Explorer.EXE [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\kernel32.dll [ntdll.dll!NtCreateFile] [012E2F20] C:\WINXP\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\kernel32.dll [ntdll.dll!NtDeviceIoControlFile] [012E2C90] C:\WINXP\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\kernel32.dll [ntdll.dll!NtClose] [012E2CF0] C:\WINXP\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\kernel32.dll [ntdll.dll!NtDuplicateObject] [012E2CC0] C:\WINXP\TEMP\logishrd\LVPrcInj01.dll (Camera Helper Library./Logitech Inc.) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\ADVAPI32.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\RPCRT4.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\Secur32.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\GDI32.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\USER32.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\msvcrt.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\ole32.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\SHLWAPI.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\CRYPT32.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\NETAPI32.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\WININET.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\SHELL32.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\USERENV.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\PSAPI.DLL [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\iphlpapi.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\WS2_32.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\WINXP\Explorer.EXE[1664] @ C:\WINXP\system32\WS2HELP.dll [KERNEL32.dll!GetProcAddress] [5CF07774] C:\WINXP\system32\ShimEng.dll (Shim Engine DLL/Microsoft Corporation) IAT C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe[1924] @ C:\WINXP\system32\ole32.dll [USER32.dll!CreateWindowExA] [004169A0] C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe IAT C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe[1924] @ C:\WINXP\system32\ole32.dll [USER32.dll!CreateWindowExW] [00416A1A] C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe IAT C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe[1924] @ C:\WINXP\system32\ole32.dll [USER32.dll!ShowWindow] [00416A94] C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe IAT C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe[1924] @ C:\WINXP\system32\WININET.dll [USER32.dll!CreateWindowExW] [00416A1A] C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe IAT C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe[1924] @ C:\WINXP\system32\WININET.dll [USER32.dll!SetWindowPos] [00416B46] C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe IAT C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe[1924] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!CreateWindowExA] [004169A0] C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe IAT C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe[1924] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!CreateWindowExW] [00416A1A] C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe IAT C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe[1924] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!SetWindowPos] [00416B46] C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe IAT C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe[1924] @ C:\WINXP\system32\SHLWAPI.dll [USER32.dll!ShowWindow] [00416A94] C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe IAT C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe[1924] @ C:\WINXP\system32\shell32.dll [USER32.dll!CreateWindowExW] [00416A1A] C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe IAT C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe[1924] @ C:\WINXP\system32\shell32.dll [USER32.dll!ShowWindow] [00416A94] C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe IAT C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe[1924] @ C:\WINXP\system32\shell32.dll [USER32.dll!SetWindowPos] [00416B46] C:\DOKUME~1\ADMINI~1\LOKALE~1\Temp\b.exe ---- Files - GMER 1.0.15 ---- File C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temporary Internet Files\Content.IE5\A1VLCZUH\info_48[1] 0 bytes File C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temporary Internet Files\Content.IE5\A1VLCZUH\navcancl[1] 0 bytes File C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temporary Internet Files\Content.IE5\HPYDEIT9\background_gradient[1] 0 bytes File C:\Dokumente und Einstellungen\Administrator\Lokale Einstellungen\Temporary Internet Files\Content.IE5\HPYDEIT9\httpErrorPagesScripts[1] 0 bytes ---- EOF - GMER 1.0.15 ---- |
Themen zu IE öffnet Werbefenster (Firefox Benutzer), Virus msb.exe & b.exe etc. |
adobe, antivir, antivir guard, avg, avira, bho, bonjour, cdburnerxp, desktop, einstellungen, firefox, hijack, hijackthis, hilfe trojaner msb ie werbung, hkus\s-1-5-18, internet, internet explorer, konvertieren, logfile, monitor, mozilla, mozilla thunderbird, pdf-datei, plug-in, rundll, software, system, temp, tuneup.defrag, virus, werbefenster, windows, windows xp |