![]() |
| |||||||
Log-Analyse und Auswertung: Firefox leitet mich auf andere Seiten um!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
| | #16 |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Firefox leitet mich auf andere Seiten um! Hi, stecke den Stick bitte nohcmal ein und führe Combofix nochmal aus. Poste das Ergebnis hier. Wenn die Malware noch aktiv war, dann hat einstecken gereicht um den Stick zu infizieren. lg myrtille
__________________ Anfragen per Email, Profil- oder privater Nachricht werden ignoriert! Hilfe gibts NUR im Forum! Wer nach 24 Stunden keine weitere Antwort von mir bekommen hat, schickt bitte eine PM Spelling mistakes? Never, but keybaord malfunctions constantly! |
| | #17 |
![]() | Firefox leitet mich auf andere Seiten um! Ok,soll ich den Log nochmal posten?
__________________ |
| | #18 |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Firefox leitet mich auf andere Seiten um! Ja bitte
__________________![]() lg myrtille
__________________ |
| | #19 |
![]() | Firefox leitet mich auf andere Seiten um!Code:
ATTFilter ComboFix 09-05-03.6 - Christopher 04.05.2009 20:26.2 - NTFSx86
Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.49.1031.18.2047.1321 [GMT 2:00]
ausgeführt von:: c:\users\Christopher\Desktop\ComboFix.exe
.
((((((((((((((((((((((( Dateien erstellt von 2009-04-04 bis 2009-05-04 ))))))))))))))))))))))))))))))
.
2009-05-04 15:23 . 2009-03-24 14:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys
2009-05-04 15:23 . 2009-05-04 15:23 -------- d-----w c:\programdata\Avira
2009-05-04 15:23 . 2009-05-04 15:23 -------- d-----w c:\program files\Avira
2009-05-04 13:32 . 2009-05-04 16:45 -------- d-----w c:\programdata\TrackMania
2009-05-04 12:43 . 2009-05-04 12:44 -------- d-----w c:\program files\TmNationsForever
2009-05-02 15:21 . 2009-05-02 15:21 -------- d-----w c:\program files\CCleaner
2009-05-02 10:41 . 2009-05-02 10:41 -------- d-----w c:\users\Christopher\AppData\Roaming\Malwarebytes
2009-05-02 09:55 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys
2009-05-02 09:55 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys
2009-05-02 09:55 . 2009-05-02 09:55 -------- d-----w c:\programdata\Malwarebytes
2009-05-02 09:55 . 2009-05-02 10:41 -------- d-----w c:\program files\Malwarebytes' Anti-Malware
2009-04-30 14:44 . 2009-05-04 17:20 -------- d-----w c:\program files\Silkroad
2009-04-29 08:44 . 2009-04-29 09:44 -------- d-----w c:\users\Christopher\AppData\Roaming\Bioshock
2009-04-27 16:37 . 2009-04-27 16:37 -------- d-----w c:\program files\Monte Cristo
2009-04-25 12:21 . 2009-04-28 20:58 -------- d-----w c:\program files\World of Warcraft
2009-04-22 16:12 . 2009-04-27 14:36 -------- d-----w c:\users\Christopher\Nachhilfe
2009-04-20 13:07 . 2009-05-04 17:20 -------- d-----w c:\users\Christopher\Spiele
2009-04-15 15:44 . 2009-04-15 15:44 -------- d-----w c:\users\Christopher\AppData\Local\Fallout3
2009-04-15 15:21 . 2009-04-15 15:21 -------- d-----w c:\program files\Bethesda Softworks
2009-04-14 16:26 . 2009-04-15 10:09 -------- d-----w c:\users\Christopher\AppData\Roaming\temp
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-05-04 17:19 . 2009-02-20 11:11 -------- d-----w c:\program files\Ubisoft
2009-05-04 17:19 . 2008-01-10 16:04 -------- d--h--w c:\program files\InstallShield Installation Information
2009-05-04 17:19 . 2008-07-21 14:08 -------- d-----w c:\program files\Google
2009-05-04 17:18 . 2008-09-30 18:19 -------- d-----w c:\program files\Game Cam V2
2009-05-04 14:57 . 2008-01-10 16:59 -------- d-----w c:\program files\Norton Internet Security
2009-05-04 14:57 . 2008-01-10 16:57 -------- d-----w c:\program files\Common Files\Symantec Shared
2009-05-04 14:42 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstor.dat
2009-05-04 14:42 . 2006-11-02 10:25 51200 ----a-w c:\windows\inf\infpub.dat
2009-05-04 14:42 . 2006-11-02 10:25 143360 ----a-w c:\windows\inf\infstrng.dat
2009-05-04 07:56 . 2006-11-02 15:33 664044 ----a-w c:\windows\system32\perfh007.dat
2009-05-04 07:56 . 2006-11-02 15:33 142222 ----a-w c:\windows\system32\perfc007.dat
2009-04-29 18:23 . 2008-12-17 14:52 -------- d-----w c:\program files\Fraps
2009-04-29 11:50 . 2008-09-11 11:25 -------- d-----w c:\program files\Runes of Magic
2009-04-29 08:14 . 2008-10-02 15:19 -------- d-----w c:\program files\2K Games
2009-04-26 17:45 . 2006-11-02 12:37 -------- d-----w c:\program files\Microsoft Games
2009-04-25 14:54 . 2009-03-18 19:16 -------- d-----w c:\program files\Diablo II
2009-04-25 14:44 . 2009-02-23 16:27 -------- d-----w c:\program files\Common Files\Blizzard Entertainment
2009-04-25 10:46 . 2008-04-04 14:32 90568 ----a-w c:\users\Christopher\AppData\Local\GDIPFONTCACHEV1.DAT
2009-04-24 20:25 . 2008-12-01 13:47 -------- d-----w c:\program files\Bethesda
2009-04-24 20:23 . 2009-03-27 18:21 -------- d-----w c:\program files\OnkoS
2009-04-24 20:11 . 2009-03-01 18:08 -------- d-----w c:\program files\Anno 1602 Königs-Edition
2009-04-20 13:04 . 2009-03-23 10:00 -------- d-----w c:\program files\DNA
2009-04-16 14:53 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail
2009-04-14 16:27 . 2008-10-05 12:32 -------- d-----w c:\program files\EA GAMES
2009-04-07 15:34 . 2008-04-04 19:47 -------- d-----w c:\program files\Warcraft III
2009-04-07 10:49 . 2009-02-21 17:31 -------- d-----w c:\program files\Steam
2009-04-06 23:19 . 2008-04-23 13:19 -------- d-----w c:\program files\Valve
2009-04-06 16:34 . 2008-04-04 19:51 133409 ----a-w c:\windows\War3Unin.dat
2009-04-04 16:55 . 2008-08-14 17:50 -------- d-----w c:\program files\ICQ6
2009-04-04 15:11 . 2008-12-05 14:41 -------- d-----w c:\program files\Electronic Arts
2009-04-02 14:42 . 2009-04-02 14:42 5434 ----a-w c:\windows\system32\ealregsnapshot1.reg
2009-03-31 16:32 . 2008-05-05 15:37 98304 ----a-w c:\windows\system32\CmdLineExt.dll
2009-03-29 08:17 . 2009-03-29 08:16 -------- d-----w c:\program files\Unechtes Turnier
2009-03-28 18:00 . 2008-05-16 19:30 -------- d-----w c:\program files\WarRock
2009-03-27 15:18 . 2009-03-23 17:07 -------- d-----w c:\program files\RouterControl
2009-03-25 15:06 . 2008-08-19 17:56 -------- d-----w c:\program files\THQ
2009-03-23 13:41 . 2009-03-23 13:14 614 ----a-w c:\windows\eReg.dat
2009-03-21 18:30 . 2009-03-21 18:08 -------- d-----w c:\program files\Starcraft
2009-03-20 16:52 . 2009-03-20 16:52 -------- d-----w c:\program files\DivX
2009-03-20 16:52 . 2009-03-20 16:52 -------- d-----w c:\program files\Common Files\PX Storage Engine
2009-03-20 16:52 . 2009-03-20 16:52 -------- d-----w c:\program files\Common Files\DivX Shared
2009-03-18 19:29 . 2009-03-18 19:19 19284 ----a-w c:\windows\DIIUnin.dat
2009-03-18 19:19 . 2009-03-18 19:19 2829 ----a-w c:\windows\DIIUnin.pif
2009-03-18 19:19 . 2009-03-18 19:19 102400 ----a-w c:\windows\DIIUnin.exe
2009-03-17 03:38 . 2009-04-15 10:06 13824 ----a-w c:\windows\system32\apilogen.dll
2009-03-17 03:38 . 2009-04-15 10:06 24064 ----a-w c:\windows\system32\amxread.dll
2009-03-16 19:58 . 2009-03-16 19:58 -------- d-----w c:\program files\directx
2009-03-15 16:47 . 2009-03-15 16:47 -------- d-----w c:\program files\SweetIM
2009-03-12 18:20 . 2009-03-12 18:20 -------- d-----w c:\program files\VisionGS PE
2009-03-11 15:38 . 2009-02-21 17:31 -------- d-----w c:\program files\Common Files\Steam
2009-03-08 13:25 . 2008-11-09 13:14 -------- d-----w c:\program files\Common Files\Wise Installation Wizard
2009-03-08 11:35 . 2009-03-08 11:35 56 ---ha-w c:\windows\system32\ezsidmv.dat
2009-03-08 11:32 . 2009-03-08 11:32 -------- d-----w c:\program files\Common Files\Skype
2009-03-08 11:32 . 2009-03-08 11:32 -------- d-----r c:\program files\Skype
2009-03-03 04:46 . 2009-04-15 10:06 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe
2009-03-03 04:46 . 2009-04-15 10:06 3547632 ----a-w c:\windows\system32\ntoskrnl.exe
2009-03-03 04:40 . 2009-04-15 10:06 827392 ----a-w c:\windows\system32\wininet.dll
2009-03-03 04:39 . 2009-04-15 10:06 183296 ----a-w c:\windows\system32\sdohlp.dll
2009-03-03 04:39 . 2009-04-15 10:06 551424 ----a-w c:\windows\system32\rpcss.dll
2009-03-03 04:39 . 2009-04-15 10:06 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll
2009-03-03 04:37 . 2009-04-15 10:06 78336 ----a-w c:\windows\system32\ieencode.dll
2009-03-03 04:37 . 2009-04-15 10:06 98304 ----a-w c:\windows\system32\iasrecst.dll
2009-03-03 04:37 . 2009-04-15 10:06 54784 ----a-w c:\windows\system32\iasads.dll
2009-03-03 04:37 . 2009-04-15 10:06 44032 ----a-w c:\windows\system32\iasdatastore.dll
2009-03-03 03:04 . 2009-04-15 10:06 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe
2009-03-03 02:38 . 2009-04-15 10:06 17408 ----a-w c:\windows\system32\iashost.exe
2009-03-03 02:28 . 2009-04-15 10:06 26624 ----a-w c:\windows\system32\ieUnatt.exe
2009-02-25 17:55 . 2009-03-27 20:22 4224 ----a-w c:\windows\system32\drivers\NVStrap.sys
2009-02-13 08:49 . 2009-04-15 10:06 72704 ----a-w c:\windows\system32\secur32.dll
2009-02-13 08:49 . 2009-04-15 10:06 1255936 ----a-w c:\windows\system32\lsasrv.dll
2009-02-09 03:10 . 2009-03-11 05:59 2033152 ----a-w c:\windows\system32\win32k.sys
2008-05-29 15:45 . 2006-11-02 12:50 174 --sha-w c:\program files\desktop.ini
2009-01-27 01:34 . 2009-01-27 01:34 1044480 ----a-w c:\program files\mozilla firefox\plugins\libdivx.dll
2009-01-27 01:34 . 2009-01-27 01:34 200704 ----a-w c:\program files\mozilla firefox\plugins\ssldivx.dll
2008-09-28 17:01 . 2008-09-28 16:50 24 --sh--w c:\windows\SE2D238D6.tmp
2008-10-24 19:12 . 2008-08-26 19:44 168 --sh--r c:\windows\System32\F125D974EB.sys
2006-05-03 10:06 . 2009-01-11 19:29 163328 --sh--r c:\windows\System32\flvDX.dll
2008-10-24 19:12 . 2008-08-26 19:34 2516 --sha-w c:\windows\System32\KGyGaAvL.sys
2007-02-21 11:47 . 2009-01-11 19:29 31232 --sh--r c:\windows\System32\msfDX.dll
2008-03-16 13:30 . 2009-01-11 19:29 216064 --sh--r c:\windows\System32\nbDX.dll
.
((((((((((((((((((((((((((((( SnapShot@2009-05-04_15.03.39 )))))))))))))))))))))))))))))))))))))))))
.
+ 2009-05-04 15:22 . 2009-05-04 15:22 62976 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90RUS.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22 46080 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90KOR.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22 46592 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90JPN.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22 64512 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ITA.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22 66048 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90FRA.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22 65024 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ESP.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22 65024 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ESN.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22 56832 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ENU.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22 66560 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90DEU.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22 39936 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90CHT.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22 38912 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90CHS.DLL
+ 2009-05-04 15:22 . 2009-05-04 15:22 59904 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90u.dll
+ 2009-05-04 15:22 . 2009-05-04 15:22 59904 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90.dll
- 2008-01-10 15:25 . 2009-05-04 14:59 52920 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-01-10 15:25 . 2009-05-04 15:16 52920 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2008-04-04 18:21 . 2009-05-04 15:16 13030 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-759913723-362470790-2232644708-1000_UserData.bin
+ 2009-05-04 15:23 . 2009-02-13 10:49 28376 c:\windows\System32\drivers\ssmdrv.sys
+ 2009-05-04 15:23 . 2009-03-30 08:33 96104 c:\windows\System32\drivers\avipbb.sys
- 2008-04-04 14:29 . 2009-05-04 12:29 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2008-04-04 14:29 . 2009-05-04 15:28 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
- 2008-04-04 14:29 . 2009-05-04 12:29 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2008-04-04 14:29 . 2009-05-04 15:28 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2008-04-04 14:29 . 2009-05-04 12:29 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-04 14:29 . 2009-05-04 15:28 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2008-04-06 16:10 . 2009-05-04 15:10 4882 c:\windows\System32\WDI\ERCQueuedResolutions.dat
+ 2009-05-04 15:13 . 2009-05-04 15:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
- 2009-05-04 14:57 . 2009-05-04 14:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2009-05-04 15:13 . 2009-05-04 15:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2009-05-04 14:57 . 2009-05-04 14:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2009-05-04 15:22 . 2009-05-04 15:22 655872 c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcr90.dll
+ 2009-05-04 15:22 . 2009-05-04 15:22 572928 c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcp90.dll
+ 2009-05-04 15:22 . 2009-05-04 15:22 225280 c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcm90.dll
+ 2009-05-04 15:22 . 2009-05-04 15:22 161784 c:\windows\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e\ATL90.dll
+ 2006-11-02 13:05 . 2009-05-04 15:16 106432 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin
- 2008-01-11 08:52 . 2009-05-04 14:59 262144 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-01-11 08:52 . 2009-05-04 18:24 262144 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat
- 2008-01-11 08:51 . 2009-05-04 15:03 262144 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2008-01-11 08:51 . 2009-05-04 18:29 262144 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat
+ 2009-05-04 15:22 . 2009-05-04 15:22 3783672 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90u.dll
+ 2009-05-04 15:22 . 2009-05-04 15:22 3768312 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90.dll
+ 2006-11-02 10:22 . 2009-05-04 15:23 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
- 2006-11-02 10:22 . 2009-04-16 19:05 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT
+ 2009-05-04 18:25 . 2009-05-04 18:25 6402048 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT
+ 2008-04-04 18:23 . 2009-05-04 15:23 217821837 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin
|
| | #20 |
![]() | Firefox leitet mich auf andere Seiten um! [code] (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}] 2008-10-08 11:22 1172792 ----a-w c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792] [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}] [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3] [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}] [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792] [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}] [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3] [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}] [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13683232] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 92704] "Diamondback"="c:\program files\Razer\Diamondback 3G\razerhid.exe" [2007-08-01 147456] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-12-13 4710400] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup backupExtension=.CommonStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{0209C1EB-BEE2-42D5-824A-8F96C8B8FB66}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{981582D9-84D6-401A-8333-F849B43EF022}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{7168CAD2-EDA5-4760-B7C5-D172F6D2F463}"= UDP:c:\program files\Warcraft III\Frozen Throne.exe:Warcraft III - The Frozen Throne "{B45A25CC-46A3-4E17-9229-7D1DF3FC5EB7}"= TCP:c:\program files\Warcraft III\Frozen Throne.exe:Warcraft III - The Frozen Throne "{903E5ED0-F469-46E1-BBD8-9987A8BD16E6}"= UDP:c:\program files\Warcraft III\Warcraft III.exe:Warcraft III "{770F760E-4416-4C4D-B122-FF42EE201C65}"= TCP:c:\program files\Warcraft III\Warcraft III.exe:Warcraft III "TCP Query User{502672C6-3C9F-4910-B8AB-8C10B3F3C470}c:\\program files\\warcraft iii\\war3.exe"= UDP:c:\program files\warcraft iii\war3.exe:Warcraft III "UDP Query User{783160AC-7616-4765-AA68-3FC6198D056C}c:\\program files\\warcraft iii\\war3.exe"= TCP:c:\program files\warcraft iii\war3.exe:Warcraft III "TCP Query User{E9AC9D13-7A3A-4667-98C6-F20B0233EA73}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent "UDP Query User{79BB1CFA-1308-4F12-88F7-9381D14DA49C}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent "{CCE7C36B-172F-4C09-94FD-8205E31CD9EF}"= UDP:c:\program files\KalOnlineEng\KalOnline.exe:KalOnline "{F0D56D46-4573-429B-BA1C-372D341AB254}"= TCP:c:\program files\KalOnlineEng\KalOnline.exe:KalOnline "{5DCD25B3-36E5-4593-B768-93BEC8D23299}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{B1B5526B-81F3-4717-B43F-783B78EF06E2}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{C4250CFD-B2A1-455C-8635-77C580970467}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{A7E19DE2-CAF4-4191-BE9C-8AA23B10920D}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager "{920FC360-1281-41FE-8E02-D908132D5BD7}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager "{5D60376C-D259-4CBF-AAEF-8127EC898087}"= UDP:c:\program files\EA GAMES\Die Schlacht um Mittelerde(tm)\game.dat ie Schlacht um Mittelerde (tm)"{B129296A-85E7-4E73-B8BA-13F180C177FC}"= TCP:c:\program files\EA GAMES\Die Schlacht um Mittelerde(tm)\game.dat ie Schlacht um Mittelerde (tm)"{54B5772C-44E5-4FC5-AE6B-576F46CEAC30}"= UDP:c:\program files\Anno 1701\Anno1701.exe:Anno 1701 "{127BF77D-7984-4C61-9B29-AC9BBFA67F8C}"= TCP:c:\program files\Anno 1701\Anno1701.exe:Anno 1701 "{73387CB1-9A13-458F-9147-4AACE55090D3}"= UDP:c:\programdata\NexonEU\NGM\NGM.exe:Nexon Game Manager "{AF2A47B5-85BF-42C9-AD34-FE0887BD6831}"= TCP:c:\programdata\NexonEU\NGM\NGM.exe:Nexon Game Manager "{0F341A35-09C9-4FE7-86E1-446D50403311}"= UDP:c:\program files\Combat Arms EU\NMService.exe:Nexon Messenger Core "{1FD873DC-A4A2-443C-B815-A492C3720F78}"= TCP:c:\program files\Combat Arms EU\NMService.exe:Nexon Messenger Core "{76362B2A-86D2-47EA-BC59-2F812D9E1641}"= UDP:c:\program files\Hamachi\hamachi.exe:Hamachi "{94CDBE7C-75CC-43FE-9228-0045DC6A0DCC}"= TCP:c:\program files\Hamachi\hamachi.exe:Hamachi "{11097455-858D-49B1-9E1D-EFE3580E4E06}"= UDP:6112:Warcraft 3 "{A31F1B1A-3347-4182-B5B5-8FD70113BF1B}"= UDP:c:\program files\Electronic Arts\Die Schlacht um Mittelerde II\game.dat ie Schlacht um Mittelerde™ II"{DFBCCF8D-441E-4B05-804B-928DBBF53C26}"= TCP:c:\program files\Electronic Arts\Die Schlacht um Mittelerde II\game.dat ie Schlacht um Mittelerde™ II"{55B99994-13AA-4A1C-AB46-A2065ECFFC66}"= UDP:c:\users\Christopher\Downloads\utorrent-1.8.2.upx.exe:µTorrent (TCP-In) "{C1A16C7A-0F18-4609-8CC5-70653567F561}"= TCP:c:\users\Christopher\Downloads\utorrent-1.8.2.upx.exe:µTorrent (UDP-In) "TCP Query User{35D944C3-0A16-4CE4-852A-FA14238A4D7D}c:\\program files\\lucasarts\\star wars republic commando\\gamedata\\system\\swrepubliccommando.exe"= UDP:c:\program files\lucasarts\star wars republic commando\gamedata\system\swrepubliccommando.exe:SWRepublicCommando "UDP Query User{DC725E17-DF88-4158-817D-839826F1E697}c:\\program files\\lucasarts\\star wars republic commando\\gamedata\\system\\swrepubliccommando.exe"= TCP:c:\program files\lucasarts\star wars republic commando\gamedata\system\swrepubliccommando.exe:SWRepublicCommando "{69BBAEC1-7557-412C-8411-A970511CB0B8}"= UDP:c:\program files\gamigo\levelr\LevelR\LevelR.bin:LEVEL- "{992CB4AA-6147-4E5F-8D30-F52BC6F6FB53}"= TCP:c:\program files\gamigo\levelr\LevelR\LevelR.bin:LEVEL- "{88CC8670-3611-4FFF-BD7D-39EED605FA48}"= UDP:c:\program files\Sunflowers\ParaWorld\bin\PWServer.exe:ParaWorld Server "{098D56CC-53E4-4DBF-B2F5-B122091AAC41}"= TCP:c:\program files\Sunflowers\ParaWorld\bin\PWServer.exe:ParaWorld Server "{383100EE-015B-46FF-A79A-8119899F6C8B}"= UDP:c:\program files\Firefly Studios\Stronghold 2\Stronghold2.exe:Stronghold 2 "{1DC0F295-31C1-42FB-8326-13F00210BBC2}"= TCP:c:\program files\Firefly Studios\Stronghold 2\Stronghold2.exe:Stronghold 2 "{EF80FDD8-E576-4C71-8336-2EDC2571B46E}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C5741607-E847-486A-A49C-B17D28B23D35}"= UDP:c:\users\Christopher\Downloads\utorrent.exe:µTorrent (TCP-In) "{264CCE17-3A75-4E0B-BD00-DA644775D075}"= TCP:c:\users\Christopher\Downloads\utorrent.exe:µTorrent (UDP-In) "{FB123311-4F78-452F-97D0-3201D18619DE}"= UDP:c:\program files\DNA\btdna.exe NA (TCP-In)"{AAA930F9-3906-4A03-A843-BF34A64588F5}"= TCP:c:\program files\DNA\btdna.exe NA (UDP-In)"{FFC98B26-81CE-481B-AEF4-85564B97ED03}"= UDP:c:\program files\Unechtes Turnier\Binaries\UT3.exe:Unreal Tournament 3 "{C17CAB19-D678-4C41-AB09-F10E9847CD9F}"= TCP:c:\program files\Unechtes Turnier\Binaries\UT3.exe:Unreal Tournament 3 "{28925910-40BE-4DB9-A120-1403EFC7550B}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main "{34ECB7B2-FBC9-4AD9-A08A-4241FC471100}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main "{2DE0C830-039F-409C-8AED-A884DC463E2D}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD "{A1E7526F-3BB0-4623-8274-1EF086D2C535}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD "{7A9FFA39-F02C-42F8-AC48-4C837BEFD612}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater "{D3A46323-6870-4066-890F-E405A3C23BC8}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater "{DED357B9-FD3A-4E08-A69E-6FC424FB3751}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server "{6A51C871-1A21-4BB6-87C0-68B519C80459}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server "{E306C1C9-48AB-469C-A6C1-98B3509705DA}"= UDP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout(TM) Paradise The Ultimate Box "{53A0367B-3A1D-422C-B7B3-CA1F654B8902}"= TCP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout(TM) Paradise The Ultimate Box "{E3EBAB2E-DBAA-4187-83AF-EC0628CBBBA3}"= UDP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout(TM) Paradise The Ultimate Box "{F7EC7937-140A-49EF-BCD6-08544E9F809E}"= TCP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout(TM) Paradise The Ultimate Box "{36F3976B-E8A3-46B5-B2FD-83FB1A6CD16C}"= UDP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:Burnout(TM) Paradise The Ultimate Box "{58690264-8D22-4AE8-AA50-5600EC979C75}"= TCP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:Burnout(TM) Paradise The Ultimate Box "TCP Query User{195B7CB4-9846-4B1B-858C-8460EACD6F97}c:\\program files\\tmnationsforever\\tmforever.exe"= UDP:c:\program files\tmnationsforever\tmforever.exe:TmForever "UDP Query User{D5CC90BC-F547-4124-A71E-E24218FC9274}c:\\program files\\tmnationsforever\\tmforever.exe"= TCP:c:\program files\tmnationsforever\tmforever.exe:TmForever R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-02-17 2736890] R3 XDva092;XDva092; [x] R3 XDva190;XDva190; [x] R4 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2005-08-05 34144] R4 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2005-12-19 28800] S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-04-01 108289] S3 phaudlwr;Philips Audio Filter;c:\windows\system32\DRIVERS\phaudlwr.sys [2008-05-07 88704] S3 Razerlow;Diamondback 3G USB Filter Driver;c:\windows\system32\Drivers\DB3G.sys [2005-04-24 13225] S3 SPC520;Philips SPC520NC PC Camera;c:\windows\system32\drivers\SPC520.sys [2007-10-01 483328] S3 SPC520m;Philips SPC520NC PC Cameram;c:\windows\system32\drivers\SPC520m.sys [2007-10-01 7680] --- Andere Dienste/Treiber im Speicher --- *NewlyCreated* - AVGIO *NewlyCreated* - AVGNTFLT *NewlyCreated* - AVIPBB [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09afeb93-8d76-11dd-b7ef-001e8c906253}] \shell\AutoRun\command - K:\LaunchRC.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09afeb95-8d76-11dd-b7ef-001e8c906253}] \shell\AutoRun\command - L:\LaunchBFII.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09afeb97-8d76-11dd-b7ef-001e8c906253}] \shell\AutoRun\command - M:\autorun.exe -auto [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c074acdd-4438-11dd-9024-806e6f6e6963}] \shell\AutoRun\command - E:\Start.exe [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "c:\program files\Common Files\LightScribe\LSRunOnce.exe" . . ------- Zusätzlicher Suchlauf ------- . uInternet Settings,ProxyOverride = *.local IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://games.icq.com/online/online2/zuma/popcaploader_v6.cab FF - ProfilePath - c:\users\Christopher\AppData\Roaming\Mozilla\Firefox\Profiles\ud4o5gfb.default\ FF - prefs.js: browser.startup.homepage - www.google.de FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\programdata\NexonEU\NGM\npNxGameeu.dll FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-04 20:29 Windows 6.0.6001 Service Pack 1 NTFS Scanne versteckte Prozesse... Scanne versteckte Autostarteinträge... Scanne versteckte Dateien... c:\users\CHRIST~1\AppData\Local\Temp\catchme.dll 53248 bytes executable Scan erfolgreich abgeschlossen versteckte Dateien: 1 ************************************************************************** [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- Gesperrte Registrierungsschluessel --------------------- [HKEY_USERS\S-1-5-21-759913723-362470790-2232644708-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:2d,fb,54,94,2b,97,59,32,ed,06,4d,31,92,4a,9d,2a,30,e4,80,2d,44,a2,7f, de,98,d0,06,44,f5,b3,83,3b,dd,20,a8,23,41,40,1a,03,1a,ee,0b,b4,38,70,90,dc,\ "??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50 [HKEY_USERS\S-1-5-21-759913723-362470790-2232644708-1000\Software\SecuROM\License information*] "datasecu"=hex:41,4c,f4,29,d1,92,15,fe,82,71,c5,d5,a8,ed,2f,28,16,4e,32,03,c9, fb,20,26,41,a3,24,3e,6b,8e,c6,1e,fe,b8,0d,26,be,ea,73,a2,50,13,c0,ad,50,7c,\ "rkeysecu"=hex:ae,1f,71,ba,90,aa,7c,d2,dd,49,4d,96,2e,c0,e8,08 . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- - - - - - - - > 'Explorer.exe'(888) c:\program files\ArcSoft\Software Suite\PhotoImpression\share\pihook.dll . Zeit der Fertigstellung: 2009-05-04 20:30 ComboFix-quarantined-files.txt 2009-05-04 18:30 ComboFix2.txt 2009-05-04 15:04 Vor Suchlauf: 25 Verzeichnis(se), 117.885.911.040 Bytes frei Nach Suchlauf: 25 Verzeichnis(se), 117.856.190.464 Bytes frei 336 --- E O F --- 2009-05-01 14:32[code] |
| | #21 |
| /// TB-Ausbilder ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() | Firefox leitet mich auf andere Seiten um! Hi, das sieht gut aus ![]() Du kannst dann Combofix deinstallieren, wenn keine Probleme mehr existieren. Einfach combofix /u unter Start->ausführen eingeben. lg myrtille
__________________ --> Firefox leitet mich auf andere Seiten um! |
| | #22 |
![]() | Firefox leitet mich auf andere Seiten um! Viiellen Dank myrtille,du hast mir sehr geholfen! Das Forum kann ich nur empfehlen! -CLOSED- |
![]() |
| Themen zu Firefox leitet mich auf andere Seiten um! |
| adobe, ashampoo uninstaller, bho, browser, defender, explorer, firefox, google, hijack, hijackthis, hängen, internet, internet explorer, intrusion prevention, log-file, logfile, malwarebytes' anti-malware, mozilla, object, plug-in, rundll, seiten, senden, software, sweetim, symantec, system, toolbars, trojaner-board, umleiten, vista, windows, windows sidebar |