![]() |
Rechner mit XP stürzt beim booten immer wieder ab Hallo! Unser Rechner mit xp stürzt beim Booten immer wieder ab, jedesmal "schafft" er es bis zu einer andern Stelle, bis er einfach hängenbleibt ohne eine Fehlermeldung. Ich starte ihn dann immer wieder mit Kaltstart neu und irgendwann schafft er es dann ganz hoch und dann läuft er auch, wie bisher. Wo kann das Problem liegen?confused: Ich poste hier mal den log file vom Hiijacker: Vielen Dank im Voraus für alle Hilfe: Logfile of HijackThis v1.98.2 Scan saved at 09:47:59, on 25.09.2010 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16674) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\sched.exe C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avguard.exe C:\Programme\FRITZ!DSL\IGDCTRL.EXE C:\WINDOWS\system32\CSHelper.exe C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avshadow.exe C:\Programme\ICQ6Toolbar\ICQ Service.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe C:\WINDOWS\system32\nvsvc32.exe C:\WINDOWS\Explorer.EXE C:\WINDOWS\System32\tcpsvcs.exe C:\WINDOWS\System32\svchost.exe C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe C:\WINDOWS\system32\fxssvc.exe C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avgnt.exe C:\Programme\QuickTime\qttask.exe C:\WINDOWS\system32\ctfmon.exe C:\Programme\FRITZ!DSL\FwebProt.exe C:\Programme\FRITZ!DSL\StCenter.EXE C:\Programme\Internet Explorer\iexplore.exe C:\WINDOWS\system32\wuauclt.exe C:\WINDOWS\System32\svchost.exe C:\Programme\virenschutz\hijackthis\HijackThis.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.ejweinsberg.net/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R3 - URLSearchHook: (no name) - - (no file) R3 - URLSearchHook: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll O3 - Toolbar: ICQToolBar - {855F3B16-6D32-4fe6-8A56-BBB695989046} - C:\Programme\ICQ6Toolbar\ICQToolBar.dll O4 - HKLM\..\Run: [avgnt] "C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avgnt.exe" /min O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [AutoStart-Manager] C:\tools\autostart manager\AutoStart-Manager.exe /AUTOSTART O4 - HKCU\..\Run: [Microsoft Works Update Detection] C:\Programme\Microsoft Works\WkDetect.exe O4 - Startup: FRITZ!DSL Protect.lnk = C:\Programme\FRITZ!DSL\FwebProt.exe O4 - Startup: Herrnhuter Losungen.LNK = C:\Programme\ComBib\Herrnhuter Losungen\Herrnhuter Losungen.exe O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_03\bin\ssv.dll O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ\ICQ6\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ\ICQ6\ICQ.exe O10 - Unknown file in Winsock LSP: c:\programme\fritz!dsl\sarah.dll O10 - Unknown file in Winsock LSP: c:\programme\fritz!dsl\sarah.dll O10 - Unknown file in Winsock LSP: c:\programme\fritz!dsl\sarah.dll O10 - Unknown file in Winsock LSP: c:\programme\fritz!dsl\sarah.dll O10 - Unknown file in Winsock LSP: c:\programme\virenschutz\avira antivir\avira\antivir desktop\avsda.dll O10 - Unknown file in Winsock LSP: c:\programme\virenschutz\avira antivir\avira\antivir desktop\avsda.dll O10 - Unknown file in Winsock LSP: c:\programme\fritz!dsl\sarah.dll O10 - Unknown file in Winsock LSP: c:\programme\virenschutz\avira antivir\avira\antivir desktop\avsda.dll O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} (Java Runtime Environment 1.6.0) - hxxp://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab O16 - DPF: {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} (InetDownload Class) - https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab |
Hallo, Zitat:
Warum ist bei Dir kein SP3 und IE8 installiert? Bitte routinemäßig einen Vollscan mit malwarebytes machen und Log posten. Denk daran, dass Malwarebytes vor jedem Scan manuell aktualisiert werden muss! Danach OTL: Systemscan mit OTL Lade Dir bitte OTL von Oldtimer herunter und speichere es auf Deinem Desktop
|
hallo, hier der file von Malware, die anderen zwei folgen... Malwarebytes' Anti-Malware 1.46 Malwarebytes Datenbank Version: 4702 Windows 5.1.2600 Service Pack 2 Internet Explorer 7.0.5730.11 27.09.2010 17:19:03 mbam-log-2010-09-27 (17-19-03).txt Art des Suchlaufs: Vollständiger Suchlauf (C:\|D:\|E:\|) Durchsuchte Objekte: 389748 Laufzeit: 5 Stunde(n), 49 Minute(n), 54 Sekunde(n) Infizierte Speicherprozesse: 0 Infizierte Speichermodule: 0 Infizierte Registrierungsschlüssel: 0 Infizierte Registrierungswerte: 0 Infizierte Dateiobjekte der Registrierung: 1 Infizierte Verzeichnisse: 0 Infizierte Dateien: 0 Infizierte Speicherprozesse: (Keine bösartigen Objekte gefunden) Infizierte Speichermodule: (Keine bösartigen Objekte gefunden) Infizierte Registrierungsschlüssel: (Keine bösartigen Objekte gefunden) Infizierte Registrierungswerte: (Keine bösartigen Objekte gefunden) Infizierte Dateiobjekte der Registrierung: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Advanced\Start_ShowMyComputer (Hijack.StartMenu) -> Bad: (0) Good: (1) -> No action taken. Infizierte Verzeichnisse: (Keine bösartigen Objekte gefunden) Infizierte Dateien: (Keine bösartigen Objekte gefunden) |
und hier das zweite file von ODT erstellt: (wenn ich ODT.txt schicken will stürzt der Rechner immer ab, es scheint wohl zu lang zu sein???) also hier extras.txt:OTL EXTRAS Logfile: Code: OTL Extras logfile created on: 27.09.2010 21:59:38 - Run 1 Gruß ana123 |
Das andere zippen und hier anhängen |
Hallo , anbei das OTL.zip. Kann man da etwas erkennen?? Gruß ana123 |
Beende alle Programme, starte OTL und kopiere folgenden Text in die "Custom Scan/Fixes" Box (unten in OTL): (das ":OTL" muss mitkopiert werden!!!) Code: :OTL Das Logfile müsste geöffnet werden, wenn Du nach dem Fixen auf ok klickst, poste das bitte. Evtl. wird der Rechner neu gestartet. |
Hallo, also hier schließlich der log: All processes killed ========== OTL ========== File move failed. G:\autorun.inf scheduled to be moved on reboot. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found. Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\MountPoints2\F\ not found. File F:\INSTALL.EXE not found. ========== COMMANDS ========== C:\WINDOWS\System32\drivers\etc\Hosts moved successfully. HOSTS file reset successfully [EMPTYTEMP] User: Administrator ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: All Users User: Andrea ->Temp folder emptied: 344064 bytes ->Temporary Internet Files folder emptied: 13490235 bytes ->Java cache emptied: 0 bytes ->Flash cache emptied: 405 bytes User: Besitzer ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: David ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Default User ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Hans-Jörg ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: Internet ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes User: LocalService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33237 bytes ->Flash cache emptied: 0 bytes User: NetworkService ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 33170 bytes User: otto ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes User: Simon ->Temp folder emptied: 0 bytes ->Temporary Internet Files folder emptied: 0 bytes ->Flash cache emptied: 0 bytes %systemdrive% .tmp files removed: 0 bytes %systemroot% .tmp files removed: 0 bytes %systemroot%\System32 .tmp files removed: 0 bytes %systemroot%\System32\dllcache .tmp files removed: 0 bytes %systemroot%\System32\drivers .tmp files removed: 0 bytes Windows Temp folder emptied: 664 bytes RecycleBin emptied: 0 bytes Total Files Cleaned = 13,00 mb OTL by OldTimer - Version 3.2.14.1 log created on 10052010_113517 Files\Folders moved on Reboot... File move failed. G:\autorun.inf scheduled to be moved on reboot. File\Folder C:\Dokumente und Einstellungen\Andrea\Lokale Einstellungen\Temporary Internet Files\Content.IE5\RJX73L8W\028-2360842-8564503[1]. not found! File move failed. C:\WINDOWS\temp\hlktmp scheduled to be moved on reboot. Registry entries deleted on Reboot... |
Dann bitte jetzt CF ausführen: ComboFix Ein Leitfaden und Tutorium zur Nutzung von ComboFix
http://saved.im/mtm0nzyzmzd5/cofi.jpg
Combofix darf ausschließlich ausgeführt werden, wenn ein Kompetenzler dies ausdrücklich empfohlen hat! |
Hallo hier der logfile von Combofix: (außderdem habe ich jetzt das Problem, daß Outlook Express nicht mehr die emails vom Server abholt, dirket im Netz kann ich mich aber auf mein Konto einloggen, ob das auch etwas damit zu tun hat?) Combofix Logfile: Code: ComboFix 10-10-05.03 - Andrea 06.10.2010 13:25:11.1.1 - x86 |
Zitat:
Ich würde Dir ja aber eher von OE abraten und sowas wie Mozilla Thunderbird empfehlen. Bitte Logs mit GMER und OSAM erstellen und posten. GMER stürzt häufiger ab, wenn das Tool auch beim 2. Mal nicht will, lass es einfach weg und führ nur OSAM aus Downloade Dir anschließend bitte MBRCheck (by a_d_13) und speichere die Datei auf dem Desktop.
|
Hallo, melde mich nach einer Krankheitsphase zurück... Also Outlook geht wieder, das war nur ein Problem mit Antivir, es hatte den Zugang blockiert. Dann hier die drei logfiles: 1.) GMER 2.) OSAM 3.) MBR GMER hat ganz schön Zeit gekostet und ich habe es merhmals starten müssen, hier der logfile: -------------------------------------------------------------------- GMER Logfile: Code: GMER 1.0.15.15315 - hxxp://www.gmer.net __________________________________________________________--- 2.) OSAM Report of OSAM: Autorun Manager v5.0.11926.0 hxxp://www.online-solutions.ru/en/ Saved at 11:47:08 on 20.10.2010 OS: Windows XP Home Edition Service Pack 2 (Build 2600) Default Browser: Microsoft Corporation Internet Explorer 7.00.6000.16674 Scanner Settings Rootkits detection (hidden registry) Rootkits detection (hidden files) Retrieve files information Check Microsoft signatures Filters Trusted entries Empty entries Hidden registry entries (rootkit activity) Exclusively opened files Not found files Files without detailed information Existing files Non-startable services Non-startable drivers Active entries Disabled entries Risk Name Publisher Full Path Status Common %SystemRoot%\Tasks "Gesamtsicherung.job" "Microsoft Corporation" C:\WINDOWS\system32\ntbackup.exe File exists Control Panel Objects %SystemRoot%\system32 "FINDFAST.CPL" "Microsoft Corporation" C:\WINDOWS\system32\FINDFAST.CPL File exists |||||| "javacpl.cpl" "Sun Microsystems, Inc." C:\WINDOWS\system32\javacpl.cpl File exists |||||| "QTW32.CPL" "Apple Computer, Inc." C:\WINDOWS\system32\QTW32.CPL File exists |||||| "QuickTime.cpl" "Apple Computer, Inc." C:\WINDOWS\system32\QuickTime.cpl File exists "slcpappl.cpl" C:\WINDOWS\system32\slcpappl.cpl File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Control Panel\Cpls "Avira AntiVir PersonalEdition Classic" C:\ANTIVI~1\avconfig.cpl File not found "Avira AntiVir PersonalEdition Classic Konfiguration" C:\PROGRA~1\VIRENS~1\AVGANT~1\ANTIVI~1\avconfig.cpl File not found |||||| "Avira AntiVir Premium" "Avira GmbH" C:\PROGRA~1\VIRENS~1\AVIRAA~1\Avira\ANTIVI~1\avconfig.cpl File exists Drivers HKLM\SYSTEM\CurrentControlSet\Services |||||| "ACEDRV05" (ACEDRV05) "Protect Software GmbH" C:\WINDOWS\system32\drivers\ACEDRV05.sys File exists |||||| "avgio" (avgio) "Avira GmbH" C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avgio.sys File exists |||||| "avgntflt" (avgntflt) "Avira GmbH" C:\WINDOWS\System32\DRIVERS\avgntflt.sys File exists |||||| "avipbb" (avipbb) "Avira GmbH" C:\WINDOWS\System32\DRIVERS\avipbb.sys File exists "catchme" (catchme) C:\DOKUME~1\Andrea\LOKALE~1\Temp\catchme.sys File not found "Changer" (Changer) C:\WINDOWS\system32\drivers\Changer.sys File not found "i2omgmt" (i2omgmt) C:\WINDOWS\system32\drivers\i2omgmt.sys File not found "lbrtfdc" (lbrtfdc) C:\WINDOWS\system32\drivers\lbrtfdc.sys File not found "LGE Mobile Composite USB Device" (usbbus) C:\WINDOWS\System32\DRIVERS\lgusbbus.sys File not found "LGE Mobile USB Modem" (USBModem) C:\WINDOWS\System32\DRIVERS\lgusbmodem.sys File not found "LGE Mobile USB Serial Port" (UsbDiag) C:\WINDOWS\System32\DRIVERS\lgusbdiag.sys File not found "PCIDump" (PCIDump) C:\WINDOWS\system32\drivers\PCIDump.sys File not found "PDCOMP" (PDCOMP) C:\WINDOWS\system32\drivers\PDCOMP.sys File not found "PDFRAME" (PDFRAME) C:\WINDOWS\system32\drivers\PDFRAME.sys File not found "PDRELI" (PDRELI) C:\WINDOWS\system32\drivers\PDRELI.sys File not found "PDRFRAME" (PDRFRAME) C:\WINDOWS\system32\drivers\PDRFRAME.sys File not found |||||| "SSHDRV61" (SSHDRV61) C:\WINDOWS\System32\drivers\SSHDRV61.sys File found, but it contains no detailed information "SSHDRV75" (SSHDRV75) C:\WINDOWS\system32\drivers\SSHDRV75.sys File exists |||||| "ssmdrv" (ssmdrv) "Avira GmbH" C:\WINDOWS\System32\DRIVERS\ssmdrv.sys File exists |||||| "StarForce Protection Environment Driver (version 1.x)" (sfdrv01) "Protection Technology (StarForce)" C:\WINDOWS\System32\drivers\sfdrv01.sys File exists |||||| "StarForce Protection Helper Driver (version 2.x)" (sfhlp02) "Protection Technology (StarForce)" C:\WINDOWS\System32\drivers\sfhlp02.sys File exists |||||| "StarForce Protection Synchronization Driver (version 4.x)" (sfsync04) "Protection Technology (StarForce)" C:\WINDOWS\System32\drivers\sfsync04.sys File exists |||||| "StarForce Protection VFS Driver (version 2.x)" (sfvfs02) "Protection Technology" C:\WINDOWS\System32\drivers\sfvfs02.sys File exists "WDICA" (WDICA) C:\WINDOWS\system32\drivers\WDICA.sys File not found Explorer HKCU\Software\Microsoft\Internet Explorer\Desktop\Components "(0) Source" hxxp://www.alphakurs.de/images/tl_alpha.gif HTTP value HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components |||||| {89B4C1CD-B018-4511-B0A1-5476DBF70820} "StubPath" "Microsoft Corporation" c:\WINDOWS\system32\Rundll32.exe c:\WINDOWS\system32\mscories.dll,Install File exists HKLM\Software\Classes\Folder\shellex\ColumnHandlers |||||| {F9DB5320-233E-11D1-9F84-707F02C10627} "PDF Shell Extension" "Adobe Systems, Inc." C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\PDFShell.dll File exists HKLM\Software\Classes\Protocols\Filter |||||| {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" "Microsoft Corporation" C:\WINDOWS\system32\mscoree.dll File exists |||||| {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" "Microsoft Corporation" C:\WINDOWS\system32\mscoree.dll File exists |||||| {1E66F26B-79EE-11D2-8710-00C04F79ED0D} "Cor MIME Filter, CorFltr, CorFltr 1" "Microsoft Corporation" C:\WINDOWS\system32\mscoree.dll File exists HKLM\Software\Classes\Protocols\Handler |||||| {0A9007C0-4076-11D3-8789-0000F8105754} "Microsoft Infotech Storage Protocol for IE 4.0" "Microsoft Corporation" C:\Programme\Gemeinsame Dateien\Microsoft Shared\Information Retrieval\msitss.dll File exists |||||| {CD00020A-8B95-11D1-82DB-00C04FB1625D} "Microsoft PKM KnowledgePluggable Class" "Microsoft Corporation" C:\Programme\Gemeinsame Dateien\Microsoft Shared\Web Folders\PKMCDO.DLL File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved {0107B611-5FC7-11D5-B092-00C026283F7F} "Büro Plus SendenAn Erweiterung" C:\WINDOWS\system32\BpShellEx.dll File found, but it contains no detailed information {792F0537-F929-4eb7-AC1D-FB6334C71550} "LG Phone" File not found | COM-object registry key not found |||||| {BB7DF450-F119-11CD-8465-00AA00425D90} "Microsoft Access Symbol-DLL" "Microsoft Corporation" C:\programme\office\Access\soa300.dll File exists |||||| {42042206-2D85-11D3-8CFF-005004838597} "Microsoft Office HTML Icon Handler" "Microsoft Corporation" C:\Programme\Microsoft Office\Office10\msohev.dll File exists {59850401-6664-101B-B21C-00AA004BA90B} "Microsoft Office-Sammelmappen-Teiler" "Microsoft Corporation" C:\programme\office\Office\explode.dll File exists |||||| {F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} "RealOne Player Context Menu Class" "RealNetworks, Inc." C:\Programme\Real\Realoneplayer\rpshell.dll File exists |||||| {45AC2688-0253-4ED8-97DE-B5370FA7D48A} "Shell Extension for Malware scanning" "Avira GmbH" C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\shlext.dll File exists |||||| {E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} "Shell Icon Handler for Application References" "Microsoft Corporation" c:\WINDOWS\system32\dfshim.dll File exists |||||| {e82a2d71-5b2f-43a0-97b8-81be15854de8} "ShellLink for Application References" "Microsoft Corporation" c:\WINDOWS\system32\dfshim.dll File exists |||||| {BDEADF00-C265-11D0-BCED-00A0C90AB50F} "Webordner" "Microsoft Corporation" C:\PROGRA~1\GEMEIN~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL File exists Internet Explorer HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser |||| "&Google" "Google Inc." c:\programme\google\googletoolbar3.dll File exists "ITBar7Layout" File not found | COM-object registry key not found "ITBarLayout" File not found | COM-object registry key not found HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks |||| {855F3B16-6D32-4fe6-8A56-BBB695989046} "ICQToolBar" "ICQ" C:\Programme\ICQ6Toolbar\ICQToolBar.dll File exists "{855F3B16-6D32-4fe6-8A56-BBB695989046}" File not found | COM-object registry key not found HKLM\SOFTWARE\Microsoft\Code Store Database\Distribution Units || {A922B6AB-3B87-11D3-B3C2-0008C7DA6CB9} "InetDownload Class" https://media.pineconeresearch.com/ActiveX/downloadcontrol.cab "Approach Inc." C:\WINDOWS\Downloaded Program Files\WMDownload.dll File exists |||| {CAFEEFAC-0014-0001-0001-ABCDEFFEDCBA} "Java Plug-in 1.4.1_01" hxxp://java.sun.com/products/plugin/1.4/jinstall-14_01-windows-i586.cab "JavaSoft / Sun Microsystems, Inc." C:\Programme\Opera\Java\j2re1.4.1_01\bin\npjpi141_01.dll File exists |||| {CAFEEFAC-0015-0000-0010-ABCDEFFEDCBA} "Java Plug-in 1.5.0_10" hxxp://java.sun.com/update/1.5.0/jinstall-1_5_0_10-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.5.0_10\bin\npjpi150_10.dll File exists |||||| {8AD9C840-044E-11D1-B3E9-00805F499D93} "Java Plug-in 1.6.0_03" hxxp://javadl-esd.sun.com/update/1.6.0/jinstall-6u3-windows-i586-jc.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.6.0_03\bin\npjpi160_03.dll File exists |||||| {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBA} "Java Plug-in 1.6.0_03" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.6.0_03\bin\npjpi160_03.dll File exists |||||| {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} "Java Plug-in 1.6.0_03" hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_03-windows-i586.cab "Sun Microsystems, Inc." C:\Programme\Java\jre1.6.0_03\bin\npjpi160_03.dll File exists Microsoft XML Parser for Java "Microsoft XML Parser for Java" file://C:\WINDOWS\Java\classes\xmldso.cab File not found | COM-object registry key not found |||||| {D27CDB6E-AE6D-11CF-96B8-444553540000} "Shockwave Flash Object" hxxp://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab "Adobe Systems, Inc." C:\WINDOWS\system32\Macromed\Flash\Flash10a.ocx File exists HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions |||||| {CAFEEFAC-0016-0000-0003-ABCDEFFEDCBC} "ClsidExtension" "Sun Microsystems, Inc." C:\Programme\Java\jre1.6.0_03\bin\npjpi160_03.dll File exists |||| "ICQ6" "ICQ, Inc." C:\Programme\ICQ\ICQ6\ICQ.exe File exists HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar |||| {855F3B16-6D32-4fe6-8A56-BBB695989046} "ICQToolBar" "ICQ" C:\Programme\ICQ6Toolbar\ICQToolBar.dll File exists HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects |||||| {18DF081C-E8AD-4283-A596-FA578C2EBDC3} "Adobe PDF Link Helper" "Adobe Systems Incorporated" C:\Programme\Gemeinsame Dateien\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll File exists |||| {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} "SSVHelper Class" "Sun Microsystems, Inc." C:\Programme\Java\jre1.6.0_03\bin\ssv.dll File exists Logon %AllUsersProfile%\Startmenü\Programme\Autostart |||||| "desktop.ini" C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart\desktop.ini File exists %UserProfile%\Startmenü\Programme\Autostart |||||| "desktop.ini" C:\Dokumente und Einstellungen\Andrea\Startmenü\Programme\Autostart\desktop.ini File exists |||||| "FRITZ!DSL Protect.lnk" "AVM Berlin" C:\Programme\FRITZ!DSL\FwebProt.exe Shortcut exists | File exists "Herrnhuter Losungen.LNK" C:\Dokumente und Einstellungen\Andrea\Startmenü\Programme\Autostart\Herrnhuter Losungen.LNK Shortcut exists | File not found HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "AutoStart-Manager" "Wolfgang Wirth - IT-Consultant / Visit my web-site at www.lab1.de" C:\tools\autostart manager\AutoStart-Manager.exe /AUTOSTART File exists "Microsoft Works Update Detection" C:\Programme\Microsoft Works\WkDetect.exe File not found HKLM\Software\Microsoft\Windows\CurrentVersion\Run |||||| "avgnt" "Avira GmbH" "C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avgnt.exe" /min File exists |||| "QuickTime Task" "Apple Computer, Inc." "C:\Programme\QuickTime\qttask.exe" -atboottime File exists Print Monitors HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors |||||| "avm:" "AVM Berlin GmbH" C:\WINDOWS\system32\avmprmon.dll File exists |||||| "Canon BJ Language Monitor i250" "CANON INC." C:\WINDOWS\system32\CNMLM50.DLL File exists |||||| "Canon BJ Language Monitor PIXMA iP1500" "CANON INC." C:\WINDOWS\system32\CNMLM5y.DLL File exists |||||| "Canon BJ Language Monitor PIXMA iP2000" "CANON INC." C:\WINDOWS\system32\CNMLM66.DLL File exists |||||| "Canon BJ Language Monitor S300" "CANON INC." C:\WINDOWS\system32\CNMLM38.DLL File exists |||||| "FRITZ!fax Color Port Monitor" "AVM Berlin GmbH" C:\WINDOWS\system32\FritzColorPort.dll File exists |||||| "FRITZ!fax Port Monitor" "AVM Berlin GmbH" C:\WINDOWS\system32\FritzPort.dll File exists |||||| "Redirected Port" C:\WINDOWS\system32\redmonnt.dll File found, but it contains no detailed information Services HKLM\SYSTEM\CurrentControlSet\Services |||||| ".NET Runtime Optimization Service v2.0.50727_X86" (clr_optimization_v2.0.50727_32) "Microsoft Corporation" C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe File exists "Anwendungsverwaltung" (AppMgmt) C:\WINDOWS\System32\appmgmts.dll File not found |||||| "ASP.NET State Service" (aspnet_state) "Microsoft Corporation" C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe File exists |||||| "Avira AntiVir Guard" (AntiVirService) "Avira GmbH" C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avguard.exe File exists |||||| "Avira AntiVir MailGuard" (AntiVirMailService) "Avira GmbH" C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avmailc.exe File exists |||||| "Avira AntiVir Planer" (AntiVirSchedulerService) "Avira GmbH" C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\sched.exe File exists |||||| "Avira AntiVir WebGuard" (AntiVirWebService) "Avira GmbH" C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\AVWEBGRD.EXE File exists |||||| "AVM FRITZ!web Routing Service" (de_serv) "AVM Berlin" C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe File exists |||||| "AVM IGD CTRL Service" (AVM IGD CTRL Service) "AVM Berlin" C:\Programme\FRITZ!DSL\IGDCTRL.EXE File exists || "CopySafe Helper Service" (CSHelper) C:\WINDOWS\system32\CSHelper.exe File found, but it contains no detailed information |||| "ICQ Service" (ICQ Service) C:\Programme\ICQ6Toolbar\ICQ Service.exe File exists |||| "Machine Debug Manager" (MDM) "Microsoft Corporation" C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe File exists |||||| "Ulead Burning Helper" (UleadBurningHelper) "Ulead Systems, Inc." C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe File exists Winlogon HKCU\Control Panel\IOProcs "MVB" mvfs32.dll File not found HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\GPExtensions {c6dc5466-785a-11d2-84d0-00c04fb169f7} "Softwareinstallation" appmgmts.dll File not found HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify |||| "WgaLogon" "Microsoft Corporation" C:\WINDOWS\system32\WgaLogon.dll File exists Winsock Providers HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries |||||| "Sarah NSP" "AVM Berlin" C:\Programme\FRITZ!DSL\sarah.dll File exists HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries |||||| "AVSDA" "Avira GmbH" C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avsda.dll File exists |||||| "SARAH LSP" "AVM Berlin" C:\Programme\FRITZ!DSL\sarah.dll File exists If You have questions or want to get some help, You can visit hxxp://forum.online-solutions.ru ________________________________________________________________ 3.) MBR: MBRCheck, version 1.2.3 (c) 2010, AD Command-line: Windows Version: Windows XP Home Edition Windows Information: Service Pack 2 (build 2600) Logical Drives Mask: 0x0000007d Kernel Drivers (total 126): 0x804D7000 \WINDOWS\system32\ntoskrnl.exe 0x806EC000 \WINDOWS\system32\hal.dll 0xF9EB2000 \WINDOWS\system32\KDCOM.DLL 0xF9DC2000 \WINDOWS\system32\BOOTVID.dll 0xF9962000 ACPI.sys 0xF9EB4000 \WINDOWS\System32\DRIVERS\WMILIB.SYS 0xF9951000 pci.sys 0xF99B2000 isapnp.sys 0xF993F000 sfsync04.sys 0xF9EB6000 intelide.sys 0xF9C32000 \WINDOWS\System32\DRIVERS\PCIIDEX.SYS 0xF99C2000 MountMgr.sys 0xF9920000 ftdisk.sys 0xF9C3A000 PartMgr.sys 0xF99D2000 VolSnap.sys 0xF9908000 atapi.sys 0xF99E2000 disk.sys 0xF99F2000 \WINDOWS\System32\DRIVERS\CLASSPNP.SYS 0xF98E8000 fltmgr.sys 0xF98D6000 sr.sys 0xF98BF000 KSecDD.sys 0xF9832000 Ntfs.sys 0xF9805000 NDIS.sys 0xF97F2000 sfvfs02.sys 0xF9C42000 sfhlp02.sys 0xF97E0000 sfdrv01.sys 0xF9A02000 ohci1394.sys 0xF9A12000 \WINDOWS\System32\DRIVERS\1394BUS.SYS 0xF97C5000 Mup.sys 0xF9A22000 agp440.sys 0xF9A52000 \SystemRoot\System32\DRIVERS\nic1394.sys 0xF90DE000 \SystemRoot\system32\DRIVERS\nv4_mini.sys 0xF90CA000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS 0xF9D6A000 \SystemRoot\system32\DRIVERS\RTL8139.SYS 0xF9062000 \SystemRoot\System32\DRIVERS\CTXH51.sys 0xF9D72000 \SystemRoot\System32\Drivers\Modem.SYS 0xF9B42000 \SystemRoot\System32\DRIVERS\cdrom.sys 0xF9B52000 \SystemRoot\System32\DRIVERS\redbook.sys 0xF903F000 \SystemRoot\System32\DRIVERS\ks.sys 0xF9B62000 \SystemRoot\System32\DRIVERS\imapi.sys 0xF9D7A000 \SystemRoot\System32\DRIVERS\usbuhci.sys 0xF901C000 \SystemRoot\System32\DRIVERS\USBPORT.SYS 0xF9004000 \SystemRoot\system32\drivers\ac97intc.sys 0xF8FE0000 \SystemRoot\system32\drivers\portcls.sys 0xF9B72000 \SystemRoot\system32\drivers\drmk.sys 0xF9D82000 \SystemRoot\System32\DRIVERS\fdc.sys 0xF8FCF000 \SystemRoot\System32\DRIVERS\serial.sys 0xF9355000 \SystemRoot\System32\DRIVERS\serenum.sys 0xF8FBB000 \SystemRoot\System32\DRIVERS\parport.sys 0xF9B82000 \SystemRoot\System32\DRIVERS\i8042prt.sys 0xF9D8A000 \SystemRoot\System32\DRIVERS\kbdclass.sys 0xF9351000 \SystemRoot\System32\DRIVERS\gameenum.sys 0xFA0F5000 \SystemRoot\system32\drivers\msmpu401.sys 0xFA0F8000 \SystemRoot\System32\DRIVERS\audstub.sys 0xF9BC2000 \SystemRoot\System32\DRIVERS\rasl2tp.sys 0xF934D000 \SystemRoot\System32\DRIVERS\ndistapi.sys 0xF8FA4000 \SystemRoot\System32\DRIVERS\ndiswan.sys 0xF9BD2000 \SystemRoot\System32\DRIVERS\raspppoe.sys 0xF9BE2000 \SystemRoot\System32\DRIVERS\raspptp.sys 0xF9D92000 \SystemRoot\System32\DRIVERS\TDI.SYS 0xF9D9A000 \SystemRoot\System32\DRIVERS\ptilink.sys 0xF9DA2000 \SystemRoot\System32\DRIVERS\raspti.sys 0xF9BF2000 \SystemRoot\System32\DRIVERS\termdd.sys 0xF9DAA000 \SystemRoot\System32\DRIVERS\mouclass.sys 0xF9EF6000 \SystemRoot\System32\DRIVERS\swenum.sys 0xF8F3A000 \SystemRoot\System32\DRIVERS\update.sys 0xF9341000 \SystemRoot\System32\DRIVERS\mssmbios.sys 0xF9C12000 \SystemRoot\System32\Drivers\NDProxy.SYS 0xF91F8000 \SystemRoot\System32\DRIVERS\usbhub.sys 0xF9F12000 \SystemRoot\System32\DRIVERS\USBD.SYS 0xF9C72000 \SystemRoot\System32\DRIVERS\flpydisk.sys 0xF91B8000 \??\C:\WINDOWS\System32\drivers\SSHDRV61.sys 0xF32ED000 \??\C:\WINDOWS\system32\drivers\SSHDRV75.sys 0xF9F38000 \SystemRoot\System32\Drivers\Fs_Rec.SYS 0xF9FBD000 \SystemRoot\System32\Drivers\Null.SYS 0xF9F3A000 \SystemRoot\System32\Drivers\Beep.SYS 0xF9C82000 \SystemRoot\System32\drivers\vga.sys 0xF9F3C000 \SystemRoot\System32\Drivers\mnmdd.SYS 0xF9F3E000 \SystemRoot\System32\DRIVERS\RDPCDD.sys 0xF9C8A000 \SystemRoot\System32\Drivers\Msfs.SYS 0xF9C92000 \SystemRoot\System32\Drivers\Npfs.SYS 0xF9E7A000 \SystemRoot\System32\DRIVERS\rasacd.sys 0xF32BA000 \SystemRoot\System32\DRIVERS\ipsec.sys 0xF9A62000 \SystemRoot\System32\DRIVERS\msgpc.sys 0xF3262000 \SystemRoot\System32\DRIVERS\tcpip.sys 0xF323A000 \SystemRoot\System32\DRIVERS\netbt.sys 0xF9E82000 \SystemRoot\System32\drivers\ws2ifsl.sys 0xF3218000 \SystemRoot\System32\drivers\afd.sys 0xF9A72000 \SystemRoot\System32\DRIVERS\netbios.sys 0xF9C9A000 \SystemRoot\system32\DRIVERS\ssmdrv.sys 0xF31ED000 \SystemRoot\System32\DRIVERS\rdbss.sys 0xF317E000 \SystemRoot\System32\DRIVERS\mrxsmb.sys 0xF9A82000 \SystemRoot\System32\Drivers\Fips.SYS 0xF315D000 \SystemRoot\System32\DRIVERS\ipnat.sys 0xF313B000 \SystemRoot\system32\DRIVERS\avipbb.sys 0xF9A92000 \SystemRoot\System32\DRIVERS\wanarp.sys 0xF9AA2000 \SystemRoot\System32\DRIVERS\arp1394.sys 0xF9F58000 \??\C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avgio.sys 0xF9CAA000 \SystemRoot\System32\DRIVERS\usbprint.sys 0xF3331000 \SystemRoot\system32\DRIVERS\hidusb.sys 0xF9AC2000 \SystemRoot\system32\DRIVERS\HIDCLASS.SYS 0xF9CCA000 \SystemRoot\system32\DRIVERS\HIDPARSE.SYS 0xF30F0000 \SystemRoot\System32\Drivers\Fastfat.SYS 0xF3321000 \SystemRoot\System32\DRIVERS\mouhid.sys 0xF9AF2000 \SystemRoot\System32\Drivers\Cdfs.SYS 0xF3038000 \SystemRoot\System32\Drivers\dump_atapi.sys 0xF9EC0000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS 0xBF800000 \SystemRoot\System32\win32k.sys 0xF312B000 \SystemRoot\System32\drivers\Dxapi.sys 0xF9D02000 \SystemRoot\System32\watchdog.sys 0xBF000000 \SystemRoot\System32\drivers\dxg.sys 0xFA086000 \SystemRoot\System32\drivers\dxgthk.sys 0xBF012000 \SystemRoot\System32\nv4_disp.dll 0xF2E22000 \SystemRoot\system32\DRIVERS\avgntflt.sys 0xF2DC3000 \??\C:\WINDOWS\system32\drivers\ACEDRV05.sys 0xF2E43000 \SystemRoot\System32\DRIVERS\ndisuio.sys 0xF2B67000 \SystemRoot\System32\DRIVERS\mrxdav.sys 0xF9EDA000 \SystemRoot\System32\Drivers\ParVdm.SYS 0xF2A6D000 \??\C:\WINDOWS\System32\drivers\hardlock.sys 0xF2883000 \SystemRoot\System32\DRIVERS\srv.sys 0xF2EA7000 \SystemRoot\System32\DRIVERS\secdrv.sys 0xF22F6000 \SystemRoot\system32\drivers\wdmaud.sys 0xF23A3000 \SystemRoot\system32\drivers\sysaudio.sys 0xF20FF000 \SystemRoot\System32\Drivers\HTTP.sys 0xF1FE4000 \SystemRoot\system32\drivers\kmixer.sys 0x7C910000 \WINDOWS\system32\ntdll.dll Processes (total 39): 0 System Idle Process 4 System 336 C:\WINDOWS\system32\smss.exe 388 csrss.exe 412 C:\WINDOWS\system32\winlogon.exe 456 C:\WINDOWS\system32\services.exe 468 C:\WINDOWS\system32\lsass.exe 640 C:\WINDOWS\system32\svchost.exe 688 svchost.exe 768 C:\WINDOWS\system32\svchost.exe 828 svchost.exe 896 svchost.exe 980 C:\WINDOWS\system32\spoolsv.exe 1032 C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\sched.exe 1152 C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avguard.exe 1164 C:\Programme\FRITZ!DSL\IGDCTRL.EXE 1188 C:\WINDOWS\system32\CSHelper.exe 1224 C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avshadow.exe 1244 C:\Programme\ICQ6Toolbar\ICQ Service.exe 1364 C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7Debug\mdm.exe 1420 C:\WINDOWS\system32\nvsvc32.exe 1456 locator.exe 1488 C:\WINDOWS\system32\tcpsvcs.exe 1540 C:\WINDOWS\system32\svchost.exe 1564 C:\Programme\Gemeinsame Dateien\Ulead Systems\DVD\ULCDRSvr.exe 1640 C:\WINDOWS\system32\fxssvc.exe 1144 C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avmailc.exe 1416 C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avwebgrd.exe 2148 alg.exe 3148 C:\WINDOWS\explorer.exe 3464 C:\WINDOWS\system32\wuauclt.exe 3632 C:\WINDOWS\system32\ctfmon.exe 3828 C:\Programme\virenschutz\AVIRA Antivir\Avira\AntiVir Desktop\avgnt.exe 3852 C:\Programme\QuickTime\qttask.exe 796 C:\Programme\FRITZ!DSL\FwebProt.exe 2288 C:\Programme\FRITZ!DSL\StCenter.exe 2612 C:\WINDOWS\system32\svchost.exe 4068 C:\Programme\Internet Explorer\iexplore.exe 3092 C:\Programme\virenschutz\MBRcheck\MBRCheck.exe \\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS) \\.\D: --> \\.\PhysicalDrive0 at offset 0x0000000b`2e2b1a00 (NTFS) \\.\E: --> \\.\PhysicalDrive0 at offset 0x00000011`c6268000 (FAT32) PhysicalDrive0 Model Number: ST380020A, Rev: 3.34 Size Device Name MBR Status -------------------------------------------- 74 GB \\.\PhysicalDrive0 Windows XP MBR code detected SHA1: ADFE55CD0C6ED2E00B22375835E4C2736CE9AD11 Done! |
Sieht ok aus. Mach bitte zur Kontrolle Vollscans mit Malwarebytes und SASW und poste die Logs. Denk dran beide Tools zu updaten vor dem Scan!! |
Alle Zeitangaben in WEZ +1. Es ist jetzt 17:25 Uhr. |
Copyright ©2000-2025, Trojaner-Board