![]() |
|
Log-Analyse und Auswertung: Google Redirect brauche hilfeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() |
|
![]() | #1 |
![]() ![]() | ![]() Google Redirect brauche hilfe Hallo alle zusammen, seit gestern hab ich das lästige Virus, und werde ständig auf anderen Seiten weitergeleitet. Siet heute geht mein e-mail auch nicht ( hotmail ). Ich hab alle mögliche scans laufen lassen und werd hier die resultate posten viellcht kann mir jemand helfen. Ihr seid meine letzte schance. 1.Hijaker laufen lassen gerade eben Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 17:36:31, on 18.07.2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = hp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = hp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\McAfee\VirusScan\scriptsn.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O4 - HKLM\..\Run: [mcagent_exe] "C:\Programme\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NBKeyScan] "C:\Programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [SynTPStart] C:\Programme\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [BisonHK] C:\WINDOWS\BisonCam\BisonHK.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [DeLay] C:\WINDOWS\BisonCam\DeLay.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKLM\..\Run: [RemoteControl8] c:\Programme\CyberLink\PowerDVD8\PDVD8Serv.exe O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB PC Camera 302 O4 - HKLM\..\Run: [PDVD8LanguageShortcut] c:\Programme\CyberLink\PowerDVD8\Language\Language.exe O4 - HKLM\..\Run: [Hotkey Software] "C:\Programme\Hotkey\HotKeyDriver.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [ISTray] "C:\Programme\Spyware Doctor\pctsTray.exe" O4 - HKCU\..\Run: [AdobeUpdater] C:\Programme\Gemeinsame Dateien\Adobe\Updater5\AdobeUpdater.exe O4 - HKCU\..\Run: [autochk] rundll32.exe C:\DOKUME~1\LOCALS~1\protect.dll,_IWMPEvents@16 O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe O4 - HKCU\..\Run: [VoipRaider] "C:\Programme\VoipRaider.com\VoipRaider\VoipRaider.exe" -nosplash -minimized O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [cmmyawk] "c:\dokumente und einstellungen\***\lokale einstellungen\anwendungsdaten\cmmyawk.exe" cmmyawk O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: ChkDisk.lnk = ? O4 - Startup: OpenOffice.org 3.0.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe O4 - Startup: Think Green Weather.lnk = C:\Programme\Stardock\DesktopGadgets\Think Green Weather\Think Green Weather.exe O15 - ESC Trusted Zone: h**p://*.update.microsoft.com O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: skype4com - (no CLSID) - (no file) O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programme\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Programme\McAfee\SiteAdvisor\McSACore.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\GEMEIN~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\GEMEIN~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Programme\McAfee\MPF\MPFSrv.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programme\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programme\Spyware Doctor\pctsSvc.exe -- End of file - 7619 bytes 2. McAffee scan gerade eben durchgeführt scan results Detection type :Trojan Detectiona names: Generic.dx!wq Generic.dx!wq Status : Qurantined ( restart required ) File name: C:\WINDOWS\SYSTEM32\ AUTOCHK.DLL 3. Blacklight rootkit entferner hidden processes hidden programm and folders found : 0 4. .Spyware doctor suchergebnisse - Trojan-Spy.Agent ( 28 infizierungen ) - bedrhung hoch prozesse notepad.exe ( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL ) firefox.exe ( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL pctsGui.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL mcvsshld.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL skypePM.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL unsecapp.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL soffice.bin( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL Think Green Wheather.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL cmmyawk.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL msnmsgr.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL NMIndex Store.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL VoipRaider.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL Skype.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL rundll32.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL pctsTray.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL SynTPEnh.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL RTHDCPL.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL mcagent.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL explorer.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL wbload.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL firefox.exe( C:\WINDOWS\SYSTEM32\AUTOCHK.DLL datei: C:\WINDOWS\SYSTEM32\autochk.dll C:\Dokumnete und Einstelungen\LOCALSERVIce\protect.dll C:\Dokumnete und Einstelungen\ADMIN\protect.dll autostrat programm HKEY_USERS\S-1-5-21-679692210-489760867-1431980292-1005\Sotware\Microsot\Windows\ CurrentVersion\Run,autochk=rundll32.exeC:\Dokumen~1\Locals~protect.dll,_IWPEvents@16 zu korrigirender Registrirungswert: HKEY_LOCAL_MASHINE\SOftware /MicrosoftNT\CurrentVersion\Winlogon, Userinit -Trojan-Spy.Zbot.YETH ( 3 infizierungen) bedrohung mittel datei: C:\WINDOWS\SYSTEM32\lowsec\local.ds C:\WINDOWS\SYSTEM32\lowsec\user.ds ordner: C:\WINDOWS\SYSTEm32\lowsec\ -Trojan.Smallfeg ( 1 infizierungen ) bedrohung mittel registry wert HKEY_USERS\S-1-5-21-679692210-489760867-1431980292-1005\Sotware\Microsot\Windows\ CurrentVersion\Run,svchost.exe 5.Malwarebytes.Antimalware scan ergebnisse 12 infizierte dateien leider wenn ich die deteils ansehen will, meldet mir keine Rückmeldung hab mehrmals versucht 6. Registry Easy Scan resultate Probleme: Active , OLE/ Com Entries 204 Applictions paths 3 Empty registry keys 188 File Exstensions 31 Font Entries 0 Help Sections 1 Invalid File Association 163 Invalid shortcuts 0 Most recently used files 189 Shared Dll sections 10 Sound sections 0 Start menu items 0 Startuo Programms 89 System Services 0 System Software settings 726 Uninstall Entries 1 User software settngs 145 Cleaned problems : 0 Jeder scan zeigt was anderes, so ich weiss nicht was und wo und ob ich was löschen muss oder kann. Ich hab auch im Internet gelesen das das problem zu lösen ist indem man auf systemsterung /system / hardware / geräte manager / ausgeblendete geräte und TDDS.sys deaktiviert aber ich hab das TDDS.sys bei mir nicht gefunden uh nicht ws änliches-. Ich brauche dringend eure Hilfe. Ich danke euch alle im Voraus liebe Grüsse VIa |
![]() | #2 |
/// Selecta Jahrusso ![]() ![]() ![]() ![]() ![]() ![]() | ![]() Google Redirect brauche hilfe![]() Bitte alles der Reihe nach abarbeiten 1. Navilog1 - von IL-MAFIOSO Bitte lade Dir Navilog1 herunter.
(Anleitung von Myrtille) 2.
3. Wende bitte Gmer wie beschrieben an 4. Starte Malwarebytes >> Scanberichte >> poste den Aktuellsten Bericht
__________________ |
![]() | #3 |
![]() ![]() | ![]() Google Redirect brauche hilfe Hallo Vielen Dank für die schnele Antwoert Hab die Anweisungen wie becshrieben gefolgt und hier sind die Resultate
__________________1. navilog 1 ergebnisse cleannavi.text Fix Navipromo version 4.0.1 began on 19.07.2009 0:33:03,39 !!! Warning, this report may include legitimate files/programs!!! !!! Post this report on the forum you are being helped !!! Fix running from C:\Programme\navilog1 Updated on 18.07.2009 at 11h00 by IL-MAFIOSO Microsoft Windows XP Professional ( v5.1.2600 ) Service Pack 3 X86-based PC ( Multiprocessor Free : Intel(R) Core(TM)2 Duo CPU T5750 @ 2.00GHz ) BIOS : BIOS Revision: 1.00.04 USER : *** ( Administrator ) BOOT : Normal boot Antivirus : McAfee VirusScan (Not Activated) Firewall : McAfee Personal Firewall (Activated) C:\ (Local Disk) - NTFS - Total:232 Go (Free:160 Go) D:\ (CD or DVD) Search done in normal mode Cleanning stage done on Reboot C:\Dokumente und Einstellungen\***\lokale~1\anwend~1\cmmyawk.exe deleted ! C:\Dokumente und Einstellungen\***\lokale~1\anwend~1\cmmyawk.dat deleted ! C:\Dokumente und Einstellungen\***\lokale~1\anwend~1\cmmyawk_nav.dat deleted ! C:\Dokumente und Einstellungen\***\lokale~1\anwend~1\cmmyawk_navps.dat deleted ! Cleaning of C:\WINDOWS\Temp done ! Cleaning of C:\Dokumente und Einstellungen\***\lokale~1\Temp done ! *** Copy Registry to Safebackup folder *** Backing up Registry done ! *** Cleaning Registry *** Nettoyage Registre Ok *** Scan completed 19.07.2009 0:59:03,81 *** Geändert von ViaViolet (19.07.2009 um 18:46 Uhr) |
![]() | #4 |
![]() ![]() | ![]() Google Redirect brauche hilfe 2.RESULTATE VON Random's System Information Tool (RSIT) log.txt Logfile of random's system information tool 1.06 (written by random/random) Run by *** at 2009-07-19 01:25:00 Microsoft Windows XP Professional Service Pack 3 System drive C: has 168 GB (70%) free of 238 GB Total RAM: 2045 MB (57% free) Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 01:25:02, on 19.07.2009 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v8.00 (8.00.6001.18702) Boot mode: Normal R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = h**p://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (file missing) O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file) O2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Programme\McAfee\VirusScan\scriptsn.dll O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\Java\jre6\bin\jp2ssv.dll O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O4 - HKLM\..\Run: [mcagent_exe] "C:\Programme\McAfee.com\Agent\mcagent.exe" /runkey O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [NBKeyScan] "C:\Programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [SynTPStart] C:\Programme\Synaptics\SynTP\SynTPStart.exe O4 - HKLM\..\Run: [BisonHK] C:\WINDOWS\BisonCam\BisonHK.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre6\bin\jusched.exe" O4 - HKLM\..\Run: [DeLay] C:\WINDOWS\BisonCam\DeLay.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe O4 - HKLM\..\Run: [RemoteControl8] c:\Programme\CyberLink\PowerDVD8\PDVD8Serv.exe O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent O4 - HKLM\..\Run: [BigDogPath] C:\WINDOWS\VM_STI.EXE USB PC Camera 302 O4 - HKLM\..\Run: [PDVD8LanguageShortcut] c:\Programme\CyberLink\PowerDVD8\Language\Language.exe O4 - HKLM\..\Run: [Hotkey Software] "C:\Programme\Hotkey\HotKeyDriver.exe" O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe" O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [autochk] rundll32.exe C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16 O4 - HKCU\..\Run: [AdobeUpdater] C:\Programme\Gemeinsame Dateien\Adobe\Updater5\AdobeUpdater.exe O4 - HKCU\..\Run: [autochk] rundll32.exe C:\DOKUME~1\LOCALS~1\protect.dll,_IWMPEvents@16 O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [SVCHOST.EXE] C:\WINDOWS\system32\drivers\svchost.exe O4 - HKCU\..\Run: [VoipRaider] "C:\Programme\VoipRaider.com\VoipRaider\VoipRaider.exe" -nosplash -minimized O4 - HKCU\..\Run: [IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020 O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O4 - Startup: ChkDisk.lnk = ? O4 - Startup: OpenOffice.org 3.0.lnk = C:\Programme\OpenOffice.org 3\program\quickstart.exe O4 - Startup: Think Green Weather.lnk = C:\Programme\Stardock\DesktopGadgets\Think Green Weather\Think Green Weather.exe O15 - ESC Trusted Zone: http://*.update.microsoft.com O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll O18 - Protocol: skype4com - (no CLSID) - (no file) O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Programme\Bonjour\mDNSResponder.exe O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\Java\jre6\bin\jqs.exe O23 - Service: McAfee SiteAdvisor Service - Unknown owner - C:\Programme\McAfee\SiteAdvisor\McSACore.exe O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\GEMEIN~1\mcafee\mna\mcnasvc.exe O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\GEMEIN~1\mcafee\mcproxy\mcproxy.exe O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Programme\McAfee\MPF\MPFSrv.exe O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe O23 - Service: NMIndexingService - Nero AG - C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe O23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exe O23 - Service: ProtexisLicensing - Unknown owner - C:\WINDOWS\system32\PSIService.exe O23 - Service: PC Tools Auxiliary Service (sdAuxService) - PC Tools - C:\Programme\Spyware Doctor\pctsAuxs.exe O23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Programme\Spyware Doctor\pctsSvc.exe -- |
![]() | #5 |
![]() ![]() | ![]() Google Redirect brauche hilfe End of file - 7407 bytes ======Scheduled tasks folder====== C:\WINDOWS\tasks\McDefragTask.job C:\WINDOWS\tasks\McQcTask.job C:\WINDOWS\tasks\Schedule Task Weekly.job C:\WINDOWS\tasks\SDMsgUpdate (TE).job ======Registry dump====== [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}] Adobe PDF Reader - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll [] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{5C255C8A-E604-49b4-9D64-90988571CECB}] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{7DB2D5A0-7241-4E79-B68D-6309F01C5231}] scriptproxy - C:\Programme\McAfee\VirusScan\scriptsn.dll [2009-05-13 62784] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{9030D464-4C02-4ABF-8ECC-5164760863C6}] Windows Live Sign-in Helper - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Windows Live\WindowsLiveLogin.dll [2009-01-22 408448] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{B164E929-A1B6-4A06-B104-2CD0E90A88FF}] McAfee SiteAdvisor BHO - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2009-02-13 150032] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{DBC80044-A445-435b-BC74-9C25C1C588A9}] C:\Programme\Java\jre6\bin\jp2ssv.dll [2009-03-09 35840] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{E7E6F031-17CE-4C07-BC86-EABFE594F69C}] JQSIEStartDetectorImpl Class - C:\Programme\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll [2009-03-09 73728] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - McAfee SiteAdvisor Toolbar - c:\PROGRA~1\mcafee\SITEAD~1\mcieplg.dll [2009-02-13 150032] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run] "mcagent_exe"=C:\Programme\McAfee.com\Agent\mcagent.exe [2009-05-01 645328] "RTHDCPL"=C:\WINDOWS\RTHDCPL.EXE [2008-02-19 16858112] "NBKeyScan"=C:\Programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe [2008-06-08 2221352] "SynTPStart"=C:\Programme\Synaptics\SynTP\SynTPStart.exe [2007-08-17 102400] "BisonHK"=C:\WINDOWS\BisonCam\BisonHK.exe [2008-03-25 77824] "SunJavaUpdateSched"=C:\Programme\Java\jre6\bin\jusched.exe [2009-03-09 148888] "DeLay"=C:\WINDOWS\BisonCam\DeLay.exe [2008-03-11 53248] "nwiz"=nwiz.exe /install [] "WinampAgent"=C:\Programme\Winamp\winampa.exe [2008-08-04 36352] "RemoteControl8"=c:\Programme\CyberLink\PowerDVD8\PDVD8Serv.exe [2008-03-20 83240] "BluetoothAuthenticationAgent"=bthprops.cpl,,BluetoothAuthenticationAgent [] "BigDogPath"=C:\WINDOWS\VM_STI.EXE [2003-01-21 40960] "PDVD8LanguageShortcut"=c:\Programme\CyberLink\PowerDVD8\Language\Language.exe [2007-12-14 50472] "Hotkey Software"=C:\Programme\Hotkey\HotKeyDriver.exe [2008-08-18 4730880] "NvCplDaemon"=C:\WINDOWS\system32\NvCpl.dll [2008-03-28 13529088] "Adobe Reader Speed Launcher"=C:\Programme\Adobe\Reader 8.0\Reader\Reader_sl.exe [2008-01-11 39792] "NeroFilterCheck"=C:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe [2008-06-19 570664] "Alcmtr"=C:\WINDOWS\ALCMTR.EXE [2005-05-03 69632] "QuickTime Task"=C:\Programme\QuickTime\qttask.exe [2009-01-05 413696] "autochk"=C:\WINDOWS\system32\autochk.dll,_IWMPEvents@16 [] [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run] "AdobeUpdater"=C:\Programme\Gemeinsame Dateien\Adobe\Updater5\AdobeUpdater.exe [2007-03-01 2321600] "autochk"=C:\DOKUME~1\LOCALS~1\protect.dll,_IWMPEvents@16 [] "Skype"=C:\Programme\Skype\Phone\Skype.exe [2008-11-07 21633320] "SVCHOST.EXE"=C:\WINDOWS\system32\drivers\svchost.exe [] "VoipRaider"=C:\Programme\VoipRaider.com\VoipRaider\VoipRaider.exe [2009-06-30 9065264] "IndxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}"=C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexStoreSvr.exe [2008-06-24 1840424] "MsnMsgr"=C:\Programme\Windows Live\Messenger\MsnMsgr.Exe [2009-02-06 3885408] C:\Dokumente und Einstellungen\Admin\Startmenü\Programme\Autostart ChkDisk.lnk - C:\WINDOWS\system32\rundll32.exe OpenOffice.org 3.0.lnk - C:\Programme\OpenOffice.org 3\program\quickstart.exe Think Green Weather.lnk - C:\Programme\Stardock\DesktopGadgets\Think Green Weather\Think Green Weather.exe [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WB] C:\Programme\Stardock\MyColors\fastload.dll [2007-08-13 24576] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\WgaLogon] C:\WINDOWS\system32\WgaLogon.dll [2009-03-10 265096] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad] UPnPMonitor - {e57ce738-33e8-4c51-8354-bb4de9d215d1} - C:\WINDOWS\system32\upnpui.dll [2008-04-14 239616] WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll [2006-10-18 133632] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdauxservice] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\sdcoreservice] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\mcmscsvc] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MCODS] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\MpfService] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdauxservice] [HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\network\sdcoreservice] [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\System] "dontdisplaylastusername"=0 "legalnoticecaption"= "legalnoticetext"= "shutdownwithoutlogon"=1 "undockwithoutlogon"=1 [HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "NoDriveTypeAutoRun"=145 [HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Policies\explorer] "HonorAutoRunSetting"= [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list] "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Programme\Messenger\msmsgs.exe"="C:\Programme\Messenger\msmsgs.exe:*:Enabled:Windows Messenger" "C:\Programme\Winamp Remote\bin\Orb.exe"="C:\Programme\Winamp Remote\bin\Orb.exe:*:Enabled:Orb" "C:\Programme\Winamp Remote\bin\OrbTray.exe"="C:\Programme\Winamp Remote\bin\OrbTray.exe:*:Enabled:OrbTray" "C:\Programme\Winamp Remote\bin\OrbStreamerClient.exe"="C:\Programme\Winamp Remote\bin\OrbStreamerClient.exe:*:Enabled:Orb Stream Client" "C:\Programme\Bonjour\mDNSResponder.exe"="C:\Programme\Bonjour\mDNSResponder.exe:*:Enabled:Bonjour" "C:\Programme\LimeWire\LimeWire.exe"="C:\Programme\LimeWire\LimeWire.exe:*:Enabled:LimeWire" "C:\Programme\Electronic Arts\EADM\Core.exe"="C:\Programme\Electronic Arts\EADM\Core.exe:*:Enabled:EA Download Manager" "C:\Programme\Windows Live\Messenger\wlcsdk.exe"="C:\Programme\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call" "C:\Programme\Windows Live\Messenger\msnmsgr.exe"="C:\Programme\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger" "%windir%\system32\drivers\svchost.exe"="%windir%\system32\drivers\svchost.exe:*:Enabled:svchost" "C:\Programme\Gemeinsame Dateien\McAfee\MNA\McNASvc.exe"="C:\Programme\Gemeinsame Dateien\McAfee\MNA\McNASvc.exe:*:Enabled:McAfee Network Agent" "C:\Programme\VoipRaider.com\VoipRaider\VoipRaider.exe"="C:\Programme\VoipRaider.com\VoipRaider\VoipRaider.exe:*:Enabled:VoipRaider" "C:\Programme\Skype\Phone\Skype.exe"="C:\Programme\Skype\Phone\Skype.exe:*:Enabled:Skype" [HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list] "%windir%\Network Diagnostic\xpnetdiag.exe"="%windir%\Network Diagnostic\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" "%windir%\system32\sessmgr.exe"="%windir%\system32\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019" "C:\Programme\Windows Live\Messenger\wlcsdk.exe"="C:\Programme\Windows Live\Messenger\wlcsdk.exe:*:Enabled:Windows Live Call" "C:\Programme\Windows Live\Messenger\msnmsgr.exe"="C:\Programme\Windows Live\Messenger\msnmsgr.exe:*:Enabled:Windows Live Messenger" "%windir%\system32\drivers\svchost.exe"="%windir%\system32\drivers\svchost.exe:*:Enabled:svchost" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{9cdc2860-8d77-11dd-a83f-0015afd5fdb7}] shell\AutoRun\command - E:\Menu.exe ======List of files/folders created in the last 1 months====== 2009-07-19 01:25:00 ----D---- C:\rsit 2009-07-18 22:31:31 ----A---- C:\cleannavi.txt 2009-07-18 22:29:27 ----D---- C:\Programme\Navilog1 2009-07-18 21:28:34 ----D---- C:\Programme\Sophos 2009-07-18 16:34:44 ----A---- C:\WINDOWS\system32\muweb.dll 2009-07-18 15:55:08 ----HDC---- C:\WINDOWS\$NtUninstallKB973346$ 2009-07-18 15:54:58 ----HDC---- C:\WINDOWS\$NtUninstallKB971633$ 2009-07-18 15:54:19 ----A---- C:\WINDOWS\system32\MRT.INI 2009-07-18 15:50:38 ----HDC---- C:\WINDOWS\$NtUninstallKB961371$ 2009-07-18 03:08:25 ----D---- C:\Programme\Gemeinsame Dateien\PC Tools 2009-07-18 03:08:19 ----D---- C:\Programme\Spyware Doctor 2009-07-18 03:08:19 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\PC Tools 2009-07-18 03:08:19 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\PC Tools 2009-07-18 01:12:32 ----D---- C:\Programme\Registry Easy 2009-07-18 01:11:55 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Malwarebytes 2009-07-18 01:11:47 ----D---- C:\Programme\Malwarebytes' Anti-Malware 2009-07-18 01:11:47 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Malwarebytes 2009-07-17 18:13:49 ----D---- C:\Programme\Trend Micro 2009-07-17 16:42:32 ----A---- C:\WINDOWS\system32\geyekrlptuwqbd.dll 2009-07-17 16:41:02 ----A---- C:\WINDOWS\system32\geyekrmpetegqx.dll 2009-07-17 16:39:22 ----A---- C:\WINDOWS\system32\geyekrrecqobww.dll 2009-07-17 16:37:49 ----A---- C:\WINDOWS\system32\geyekroijixtnx.dll 2009-07-17 16:33:15 ----A---- C:\WINDOWS\system32\geyekrnhuleynt.dll 2009-07-17 16:32:33 ----SHD---- C:\WINDOWS\system32\lowsec 2009-07-16 22:48:39 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\My Games 2009-07-16 20:43:35 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Peace Craft 2009-07-16 17:59:01 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\MythPeople 2009-07-14 18:55:03 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\VoipRaider 2009-07-14 18:49:31 ----D---- C:\Programme\VoipRaider.com 2009-07-11 02:55:57 ----D---- C:\Programme\Miriel The Magical Merchant 2009-07-09 20:30:46 ----D---- C:\Programme\Photo To Color Sketch 2009-07-08 10:20:00 ----HDC---- C:\WINDOWS\$NtUninstallKB961501$ 2009-07-08 10:19:52 ----HDC---- C:\WINDOWS\$NtUninstallKB969898$ 2009-07-08 10:19:14 ----D---- C:\WINDOWS\ie8updates 2009-07-08 10:16:44 ----HDC---- C:\WINDOWS\ie8 2009-07-08 10:11:24 ----HDC---- C:\WINDOWS\$NtUninstallKB970238$ 2009-07-08 10:09:50 ----HDC---- C:\WINDOWS\$NtUninstallKB968537$ 2009-07-06 01:51:25 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\MAXON 2009-07-04 04:03:06 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\SiteAdvisor 2009-07-04 03:59:09 ----D---- C:\Programme\Gemeinsame Dateien\McAfee 2009-07-04 03:59:06 ----D---- C:\Programme\McAfee.com 2009-07-04 03:58:56 ----D---- C:\Programme\McAfee 2009-07-04 03:39:34 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\McAfee 2009-07-04 03:19:00 ----SHD---- C:\Config.Msi 2009-07-04 03:14:14 ----HDC---- C:\WINDOWS\$NtUninstallKB959426$ 2009-07-04 03:14:06 ----HDC---- C:\WINDOWS\$NtUninstallKB961373$ 2009-07-04 03:13:55 ----HDC---- C:\WINDOWS\$NtUninstallKB961503$ 2009-07-04 03:13:33 ----HDC---- C:\WINDOWS\$NtUninstallKB956572$ 2009-07-04 03:13:18 ----HDC---- C:\WINDOWS\$NtUninstallKB952004$ 2009-07-04 03:11:00 ----HDC---- C:\WINDOWS\$NtUninstallKB960803$ 2009-07-04 03:10:51 ----HDC---- C:\WINDOWS\$NtUninstallKB923561$ 2009-07-04 02:44:41 ----D---- C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Corel 2009-07-03 00:46:30 ----D---- C:\Dokumente und Einstellungen\Admin\Anwendungsdaten\Ultra Fractal 5 ======List of files/folders modified in the last 1 months====== 2009-07-19 01:13:33 ----D---- C:\WINDOWS\Temp 2009-07-19 01:02:48 ----D---- C:\Programme\Mozilla Firefox 2009-07-19 00:57:54 ----D---- C:\WINDOWS\system32\ias 2009-07-19 00:54:09 ----D---- C:\WINDOWS\system32 2009-07-19 00:53:01 ----A---- C:\WINDOWS\SchedLgU.Txt 2009-07-19 00:30:43 ----AD---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Temp 2009-07-19 00:24:46 ----D---- C:\WINDOWS 2009-07-19 00:00:05 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\skypePM 2009-07-18 23:00:42 ----D---- C:\WINDOWS\system32\drivers 2009-07-18 22:29:27 ----RD---- C:\Programme 2009-07-18 22:03:29 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Skype 2009-07-18 21:55:15 ----D---- C:\WINDOWS\system32\CatRoot2 2009-07-18 15:55:13 ----HD---- C:\WINDOWS\inf 2009-07-18 15:55:07 ----HD---- C:\WINDOWS\$hf_mig$ 2009-07-18 15:55:02 ----A---- C:\WINDOWS\imsins.BAK 2009-07-18 15:55:01 ----RSHDC---- C:\WINDOWS\system32\dllcache 2009-07-18 03:08:25 ----D---- C:\Programme\Gemeinsame Dateien 2009-07-18 02:58:58 ----SD---- C:\WINDOWS\Downloaded Program Files 2009-07-18 01:12:40 ----SD---- C:\WINDOWS\Tasks 2009-07-18 00:51:09 ----D---- C:\WINDOWS\Minidump 2009-07-17 23:32:39 ----D---- C:\WINDOWS\Network Diagnostic 2009-07-17 22:20:44 ----A---- C:\WINDOWS\NeroDigital.ini 2009-07-17 20:29:10 ----A---- C:\WINDOWS\system32\PerfStringBackup.INI 2009-07-16 22:48:20 ----D---- C:\My Games 2009-07-16 20:47:01 ----D---- C:\My Download Files 2009-07-16 17:58:46 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\BigFishGamesCache 2009-07-15 20:20:36 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Adobe 2009-07-09 21:29:10 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\gtk-2.0 2009-07-08 19:08:38 ----D---- C:\Programme\Adobe Photoshop CS3 2009-07-08 10:24:02 ----D---- C:\WINDOWS\Prefetch 2009-07-08 10:22:29 ----D---- C:\WINDOWS\system32\de-de 2009-07-08 10:22:28 ----D---- C:\WINDOWS\Media 2009-07-08 10:22:28 ----D---- C:\WINDOWS\Help 2009-07-08 10:22:28 ----D---- C:\Programme\Internet Explorer 2009-07-07 17:10:56 ----A---- C:\WINDOWS\system32\MRT.exe 2009-07-06 02:46:52 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Avira 2009-07-05 14:18:44 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Google 2009-07-04 12:04:44 ----D---- C:\Downloads 2009-07-04 03:55:09 ----D---- C:\Programme\Google 2009-07-04 03:55:09 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Google 2009-07-04 03:55:06 ----SHD---- C:\WINDOWS\Installer 2009-07-04 03:21:30 ----D---- C:\Programme\Gemeinsame Dateien\Adobe 2009-07-04 03:21:11 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Adobe 2009-07-04 03:20:39 ----D---- C:\Programme\Adobe 2009-07-04 03:16:12 ----D---- C:\WINDOWS\system32\wbem 2009-07-04 03:16:11 ----D---- C:\WINDOWS\AppPatch 2009-07-04 03:02:07 ----D---- C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Corel 2009-07-04 02:51:08 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Aveyond II 2009-07-04 02:51:08 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\AveDesk 2009-07-04 02:51:08 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Ashtons Family Resort 2009-07-04 02:51:08 ----D---- C:\Dokumente und Einstellungen\***\Anwendungsdaten\Apple Computer 2009-06-23 13:06:47 ----D---- C:\Programme\Stellarium 2009-06-20 14:42:34 ----D---- C:\Programme\ZC2.10 2009-06-20 14:42:13 ----D---- C:\Programme\Zylom Games 2009-06-20 14:38:55 ----D---- C:\Programme\RealArcade ======List of drivers (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R1 intelppm;Intel-Prozessortreiber; C:\WINDOWS\system32\DRIVERS\intelppm.sys [2008-04-14 40448] R1 mfehidk;McAfee Inc. mfehidk; C:\WINDOWS\system32\drivers\mfehidk.sys [2009-05-13 214024] R1 MPFP;MPFP; C:\WINDOWS\System32\Drivers\Mpfp.sys [2009-04-09 120136] R1 Tcpip6;Microsoft IPv6-Protokolltreiber; C:\WINDOWS\system32\DRIVERS\tcpip6.sys [2008-06-20 225856] R1 WmiAcpi;Microsoft Windows-Verwaltungsschnittstelle für ACPI; C:\WINDOWS\system32\DRIVERS\wmiacpi.sys [2008-04-14 8832] R3 CmBatt;Treiber für Microsoft-ACPI-Kontrollmethodenkompatible Batterie; C:\WINDOWS\system32\DRIVERS\CmBatt.sys [2008-04-14 13952] R3 EMSCR;EMSCR; C:\WINDOWS\system32\DRIVERS\EMS7SK.sys [2007-04-11 66432] R3 ESDCR;ESDCR; C:\WINDOWS\system32\DRIVERS\ESD7SK.sys [2007-04-11 46080] R3 HDAudBus;Microsoft UAA-Bustreiber für High Definition Audio; C:\WINDOWS\system32\DRIVERS\HDAudBus.sys [2008-04-14 144384] R3 IntcAzAudAddService;Service for Realtek HD Audio (WDM); C:\WINDOWS\system32\drivers\RtkHDAud.sys [2008-02-26 4737024] R3 mfeavfk;McAfee Inc. mfeavfk; C:\WINDOWS\system32\drivers\mfeavfk.sys [2009-05-13 79816] R3 mfebopk;McAfee Inc. mfebopk; C:\WINDOWS\system32\drivers\mfebopk.sys [2009-05-13 35272] R3 nv;nv; C:\WINDOWS\system32\DRIVERS\nv4_mini.sys [2008-03-28 6551008] R3 RTL8187B;Realtek RTL8187B Wireless 802.11b/g 54Mbps USB 2.0 Network Adapter; C:\WINDOWS\system32\DRIVERS\RTL8187B.sys [2007-12-26 288000] R3 sdbus;sdbus; C:\WINDOWS\system32\DRIVERS\sdbus.sys [2008-04-14 79232] R3 SiSGbeXP;SiS191/SiS190 Ethernet Device NDIS 5.1 Driver; C:\WINDOWS\system32\DRIVERS\SiSGbeXP.sys [2008-03-03 43392] R3 SynTP;Synaptics TouchPad Driver; C:\WINDOWS\system32\DRIVERS\SynTP.sys [2007-08-17 212704] R3 tunmp;Microsoft Tun-Miniportadaptertreiber; C:\WINDOWS\system32\DRIVERS\tunmp.sys [2008-04-14 12288] R3 usbehci;Miniporttreiber für erweiterten Microsoft USB 2.0-Hostcontroller; C:\WINDOWS\system32\DRIVERS\usbehci.sys [2008-04-14 30208] R3 usbhub;Microsoft USB-Standardhubtreiber; C:\WINDOWS\system32\DRIVERS\usbhub.sys [2008-04-14 59520] R3 usbohci;Miniporttreiber für Microsoft USB Open Host-Controller; C:\WINDOWS\system32\DRIVERS\usbohci.sys [2008-04-14 17152] S2 adfs;adfs; C:\WINDOWS\system32\drivers\adfs.sys [] S2 ancfylmqolyow;ancfylmqolyow; \??\C:\WINDOWS\system32\drivers\malwyphbjskiuc.sys [] S3 aujasnkj;aujasnkj; \??\C:\DOKUME~1\Admin\LOKALE~1\Temp\aujasnkj.sys [] S3 BthEnum;Bluetooth-Anforderungsblocktreiber; C:\WINDOWS\system32\DRIVERS\BthEnum.sys [2008-04-14 17024] S3 BTHMODEM;Serieller Kommunikationstreiber für Bluetooth; C:\WINDOWS\system32\DRIVERS\bthmodem.sys [2008-04-14 37888] S3 BthPan;Bluetooth-Gerät (PAN); C:\WINDOWS\system32\DRIVERS\bthpan.sys [2008-04-14 101120] S3 BTHPORT;Bluetooth-Porttreiber; C:\WINDOWS\System32\Drivers\BTHport.sys [2008-06-14 273024] S3 BTHUSB;USB-Treiber für Bluetooth-Funkgerät; C:\WINDOWS\System32\Drivers\BTHUSB.sys [2008-04-14 18944] S3 Cam5607;BisonCam, NB Pro; C:\WINDOWS\System32\Drivers\BisonC07.sys [2008-03-31 1069608] S3 catchme;catchme; \??\C:\DOKUME~1\Admin\LOKALE~1\Temp\catchme.sys [] S3 CCDECODE;Untertiteldecoder; C:\WINDOWS\system32\DRIVERS\CCDECODE.sys [2008-04-14 17024] S3 HidUsb;Microsoft HID Class-Treiber; C:\WINDOWS\system32\DRIVERS\hidusb.sys [2008-04-14 10368] S3 MEMSWEEP2;MEMSWEEP2; \??\C:\WINDOWS\system32\19F.tmp [] S3 mferkdk;McAfee Inc. mferkdk; C:\WINDOWS\system32\drivers\mferkdk.sys [2009-05-13 34248] S3 mfesmfk;McAfee Inc. mfesmfk; C:\WINDOWS\system32\drivers\mfesmfk.sys [2009-05-13 40552] S3 mouhid;Maus-HID-Treiber; C:\WINDOWS\system32\DRIVERS\mouhid.sys [2001-08-18 12288] S3 MSTEE;Microsoft Streaming Tee/Sink-to-Sink-Konvertierung; C:\WINDOWS\system32\drivers\MSTEE.sys [2008-04-14 5504] S3 NABTSFEC;NABTS/FEC VBI-Codec; C:\WINDOWS\system32\DRIVERS\NABTSFEC.sys [2008-04-14 85248] S3 NdisIP;Microsoft TV-/Videoverbindung; C:\WINDOWS\system32\DRIVERS\NdisIP.sys [2008-04-14 10880] S3 RFCOMM;Bluetooth-Gerät (RFCOMM-Protokoll-TDI); C:\WINDOWS\system32\DRIVERS\rfcomm.sys [2008-04-14 59136] S3 SLIP;BDA Slip De-Framer; C:\WINDOWS\system32\DRIVERS\SLIP.sys [2008-04-14 11136] S3 streamip;BDA-IPSink; C:\WINDOWS\system32\DRIVERS\StreamIP.sys [2008-04-14 15232] S3 usbaudio;USB-Audiotreiber (WDM); C:\WINDOWS\system32\drivers\usbaudio.sys [2008-04-14 60032] S3 usbccgp;Microsoft Standard-USB-Haupttreiber; C:\WINDOWS\system32\DRIVERS\usbccgp.sys [2008-04-14 32128] S3 USBSTOR;USB-Massenspeichertreiber; C:\WINDOWS\system32\DRIVERS\USBSTOR.SYS [2008-04-14 26368] S3 usbvideo;USB-Videogerät (WDM); C:\WINDOWS\System32\Drivers\usbvideo.sys [2008-04-14 121984] S3 WSTCODEC;World Standard Teletext-Codec; C:\WINDOWS\system32\DRIVERS\WSTCODEC.SYS [2008-04-14 19200] S3 WudfPf;Windows Driver Foundation - User-mode Driver Framework Platform Driver; C:\WINDOWS\system32\DRIVERS\WudfPf.sys [2006-09-28 77568] S3 WudfRd;Windows Driver Foundation - User-mode Driver Framework Reflector; C:\WINDOWS\system32\DRIVERS\wudfrd.sys [2006-09-28 82944] S3 ZSMC302;USB PC Camera 302; C:\WINDOWS\System32\Drivers\usbvm302.sys [2004-04-23 90513] S4 IntelIde;IntelIde; C:\WINDOWS\system32\drivers\IntelIde.sys [] |
![]() | #6 |
![]() ![]() | ![]() Google Redirect brauche hilfe ======List of services (R=Running, S=Stopped, 0=Boot, 1=System, 2=Auto, 3=Demand, 4=Disabled)====== R2 6to4;IPv6-Hilfsdienst; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336] R2 Bonjour Service;##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762##; C:\Programme\Bonjour\mDNSResponder.exe [2006-02-28 229376] R2 BthServ;Bluetooth Support Service; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336] R2 Iprip;RIP-Überwachung; C:\WINDOWS\System32\svchost.exe [2008-04-14 14336] R2 JavaQuickStarterService;Java Quick Starter; C:\Programme\Java\jre6\bin\jqs.exe [2009-03-09 152984] R2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service; C:\Programme\McAfee\SiteAdvisor\McSACore.exe [2009-02-11 210216] R2 mcmscsvc;McAfee Services; C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe [2009-05-01 865832] R2 McNASvc;McAfee Network Agent; c:\PROGRA~1\GEMEIN~1\mcafee\mna\mcnasvc.exe [2009-04-09 2482848] R2 McProxy;McAfee Proxy Service; c:\PROGRA~1\GEMEIN~1\mcafee\mcproxy\mcproxy.exe [2009-04-09 359952] R2 McShield;McAfee Real-time Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe [2009-05-13 144704] R2 MpfService;McAfee Personal Firewall Service; C:\Programme\McAfee\MPF\MPFSrv.exe [2009-05-08 893112] R2 Nero BackItUp Scheduler 3;Nero BackItUp Scheduler 3; C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe [2008-06-08 877864] R2 NVSvc;NVIDIA Display Driver Service; C:\WINDOWS\system32\nvsvc32.exe [2008-03-28 155716] R2 PLFlash DeviceIoControl Service;PLFlash DeviceIoControl Service; C:\WINDOWS\system32\IoctlSvc.exe [2006-12-19 81920] R2 ProtexisLicensing;ProtexisLicensing; C:\WINDOWS\system32\PSIService.exe [2006-11-02 174656] R2 SimpTcp;Einfache TCP/IP-Dienste; C:\WINDOWS\system32\tcpsvcs.exe [2008-04-14 19456] R2 SNMP;SNMP-Dienst; C:\WINDOWS\System32\snmp.exe [2008-04-14 33280] R3 NMIndexingService;NMIndexingService; C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe [2008-06-24 537896] S3 Adobe LM Service;Adobe LM Service; C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe [2009-01-26 72704] S3 aspnet_state;ASP.NET-Zustandsdienst; C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe [2007-10-24 33800] S3 clr_optimization_v2.0.50727_32;.NET Runtime Optimization Service v2.0.50727_X86; c:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe [2007-10-24 70144] S3 FLEXnet Licensing Service;FLEXnet Licensing Service; C:\Programme\Gemeinsame Dateien\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [2008-11-16 655624] S3 FontCache3.0.0.0;Windows Presentation Foundation Font Cache 3.0.0.0; c:\WINDOWS\Microsoft.Net\Framework\v3.0\WPF\PresentationFontCache.exe [2007-10-09 36864] S3 IDriverT;InstallDriver Table Manager; C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe [2005-04-04 69632] S3 idsvc;Windows CardSpace; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\infocard.exe [2007-10-11 864256] S3 LPDSVC;TCP/IP-Druckserver; C:\WINDOWS\system32\tcpsvcs.exe [2008-04-14 19456] S3 McODS;McAfee Scanner; C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe [2009-05-08 365072] S3 p2pgasvc;Peernetzwerk-Gruppenauthentifizierung; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336] S3 p2pimsvc;Peernetzwerkidentitäts-Manager; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336] S3 p2psvc;Peernetzwerk; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336] S3 PNRPSvc;Peer Name Resolution-Protokoll; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336] S3 sdAuxService;PC Tools Auxiliary Service; C:\Programme\Spyware Doctor\pctsAuxs.exe [2009-01-07 348752] S3 sdCoreService;PC Tools Security Service; C:\Programme\Spyware Doctor\pctsSvc.exe [2009-01-21 1095560] S3 SNMPTRAP;SNMP-Trap-Dienst; C:\WINDOWS\System32\snmptrap.exe [2008-04-14 8704] S3 WMPNetworkSvc;Windows Media Player-Netzwerkfreigabedienst; C:\Programme\Windows Media Player\WMPNetwk.exe [2006-10-24 920576] S3 WudfSvc;Windows Driver Foundation - User-mode Driver Framework; C:\WINDOWS\system32\svchost.exe [2008-04-14 14336] S4 McSysmon;McAfee SystemGuards; C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe [2009-05-08 606736] S4 NetTcpPortSharing;Net.Tcp Port Sharing Service; C:\WINDOWS\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe [2007-10-11 122880] -----------------EOF----------------- |
![]() |
Themen zu Google Redirect brauche hilfe |
acroiehelper.dll, association, bho, bonjour, brauche hilfe, computer, dringend, e-mail, einstellungen, exe, generic.dx, google, hijack, hijackthis, hkus\s-1-5-18, infizierte dateien, internet, internet explorer, jusched.exe, nicht gefunden, nmindexstoresvr.exe, plug-in, required, rootkit, rundll, security, siteadvisor, skype.exe, software, spyware, svchost.exe, system, trojan-spy.agent, usb, virus, windows, windows xp |