|
Log-Analyse und Auswertung: auch Problem mit "about:blank" und IE Einstellungen. Bitte um HilfeWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
06.02.2005, 14:59 | #1 |
| auch Problem mit "about:blank" und IE Einstellungen. Bitte um Hilfe Hallo zusammen, habe auch das about:blank Problem und mein IE übernimmt nicht meine Einstellungen, habe immer die Leiste "Links" unter meiner Adresse, aber er verschiebt sie immer neben die Adresse. Hier mal meine Logfile und eScan: Logfile of HijackThis v1.99.0 Scan saved at 13:04:32, on 06.02.2005 Platform: Windows XP SP1 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\PROGRA~1\eScan\helperservice.exe C:\PROGRA~1\eScan\AVKWCTL.EXE C:\PROGRA~1\eScan\avkserv.exe C:\Programme\Belkin\Bluetooth Software\bin\btwdins.exe C:\WINDOWS\System32\CTsvcCDA.EXE C:\PROGRA~1\eScan\TRAYSSER.EXE C:\Programme\Norton AntiVirus\AdvTools\NPROTECT.EXE C:\WINDOWS\System32\nvsvc32.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe C:\WINDOWS\System32\MsPMSPSv.exe C:\WINDOWS\Explorer.EXE C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe C:\Programme\Java\j2re1.4.2_03\bin\jusched.exe C:\Programme\Microsoft IntelliPoint\point32.exe C:\WINDOWS\system32\dla\tfswctrl.exe C:\WINDOWS\System32\CTHELPER.EXE C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe C:\WINDOWS\PTBSync.EXE C:\Program Files\ASUS\Probe\AsusProb.exe C:\PROGRA~1\eScan\TRAYICOS.EXE C:\Programme\NoPopUp 2001\nopopup.exe C:\WINDOWS\System32\ctfmon.exe C:\PROGRA~1\eScan\MAILDISP.EXE C:\Programme\Belkin\Bluetooth Software\BTTray.exe C:\PROGRA~1\eScan\SPOOLER.EXE C:\PROGRA~1\Belkin\BLUETO~1\BTSTAC~1.EXE D:\Programme\eMule\eMule.exe C:\Programme\Internet Explorer\iexplore.exe E:\Downloads\XP Powertoys\hijackthis\HijackThis.exe R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.richfind.com/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.richfind.com/ie/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.richfind.com/ie/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.richfind.com/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.richfind.com/ie/ R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.richfind.com/ie/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page_bak = http://www.t-online.de/ R3 - URLSearchHook: Search - {CFF098BC-D7A3-4DA9-A568-65BD34B1C6C6} - C:\WINDOWS\System32\Q20333765.dll R3 - URLSearchHook: Search - {00000000-0000-0000-0000-000000000000} - C:\WINDOWS\System32\Q20333765.dll O2 - BHO: Search - {00000000-0000-0000-0000-000000000000} - C:\WINDOWS\System32\Q20333765.dll O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll O2 - BHO: Search - {7B485DF9-EB10-430D-B3FD-690BB9130AD5} - C:\WINDOWS\System32\Q20333765.dll O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Programme\Norton AntiVirus\NavShExt.dll O3 - Toolbar: Copernic Agent - {F2E259E8-0FC8-438C-A6E0-342DD80FA53E} - D:\PROGRA~2\COPERN~1\COPERN~1.DLL O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Programme\Norton AntiVirus\NavShExt.dll O3 - Toolbar: (no name) - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - (no file) O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx O3 - Toolbar: Search - {B0DF002F-55D3-48DB-9F49-A172B9CCE3E4} - C:\WINDOWS\System32\Q20333765.dll O3 - Toolbar: Search - {00000000-0000-0000-0000-000000000000} - C:\WINDOWS\System32\Q20333765.dll O4 - HKLM\..\Run: [Zone Labs Client] C:\PROGRA~1\ZONELA~1\ZONEAL~1\zlclient.exe O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe O4 - HKLM\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\SYMNET~1\SNDMon.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_03\bin\jusched.exe O4 - HKLM\..\Run: [SSC_UserPrompt] C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\UsrPrmpt.exe O4 - HKLM\..\Run: [SetCacheMode] Rundll32.exe ptipbmf.dll,SetWriteCacheMode O4 - HKLM\..\Run: [PinnacleDriverCheck] C:\WINDOWS\System32\PSDrvCheck.exe O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe O4 - HKLM\..\Run: [mspd] C:\WINDOWS\System32\mspd.exe O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [Jet Detection] C:\Programme\Creative\SBAudigy\PROGRAM\ADGJDet.exe O4 - HKLM\..\Run: [IntelliPoint] "C:\Programme\Microsoft IntelliPoint\point32.exe" O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXE O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [Atomuhr Synchronisation] PTBSync.EXE /Start O4 - HKLM\..\Run: [ASUS Probe] C:\Program Files\ASUS\Probe\AsusProb.exe O4 - HKLM\..\Run: [Advanced Tools Check] C:\PROGRA~1\NORTON~1\AdvTools\ADVCHK.EXE O4 - HKLM\..\Run: [MailScan Dispatcher] "C:\Programme\eScan\LAUNCH.EXE" O4 - HKLM\..\Run: [eScan Updater] C:\PROGRA~1\eScan\TRAYICOS.EXE /App O4 - HKCU\..\Run: [NoPopUp] C:\Programme\NoPopUp 2001\nopopup.exe /autorun O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\System32\ctfmon.exe O4 - Global Startup: BTTray.lnk = ? O8 - Extra context menu item: Download with GetRight - C:\Programme\GetRight\GRdownload.htm
__________________ Grüsse, Eightball69 |
06.02.2005, 15:00 | #2 |
| auch Problem mit "about:blank" und IE Einstellungen. Bitte um Hilfe O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://D:\PROGRA~2\MICROS~1\Office10\EXCEL.EXE/3000
__________________O8 - Extra context menu item: Open with GetRight Browser - C:\Programme\GetRight\GRbrowse.htm O8 - Extra context menu item: Senden an &Bluetooth - C:\Programme\Belkin\Bluetooth Software\btsendto_ie_ctx.htm O8 - Extra context menu item: Suchen mit Copernic Agent - D:\Programme\Copernic Agent\Web\SearchExt.htm O9 - Extra button: Search - {00000000-0000-0000-0000-000000000000} - C:\WINDOWS\System32\Q20333765.dll O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\j2re1.4.2_03\bin\npjpi142_03.dll O9 - Extra button: Preispiraten 2.1.1 - {86DE8B3B-1EB7-4386-84BD-EBE94348A913} - C:\Programme\Preispiraten\Preispiraten2\preispiraten2ie.exe O9 - Extra button: Search - {B0DF002F-55D3-48DB-9F49-A172B9CCE3E4} - C:\WINDOWS\System32\Q20333765.dll O9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\Belkin\Bluetooth Software\btsendto_ie.htm O9 - Extra 'Tools' menuitem: @btrez.dll,-4017 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Programme\Belkin\Bluetooth Software\btsendto_ie.htm O10 - Broken Internet access because of LSP provider 'mwtsp.dll' missing O12 - Plugin for .UVR: C:\Programme\Internet Explorer\Plugins\NPUPano.dll O16 - DPF: {00000000-0000-0000-0000-000020030000} - http://www.advnt01.com/dialer/gerpep_nopop.exe O16 - DPF: {03F998B2-0E00-11D3-A498-00104B6EB52E} (MetaStreamCtl Class) - https://components.viewpoint.com/ado...nailFrame.html O16 - DPF: {1C78AB3F-A857-482E-80C0-3A1E5238A565} - file://C:\install.cab O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1094680446984 O17 - HKLM\System\CCS\Services\Tcpip\..\{425115A6-D93A-44EF-ABD9-FE6ABF088E45}: NameServer = 217.237.151.33 217.237.149.225 O18 - Filter: text/html - {00000000-0000-0000-0000-000000000000} - C:\WINDOWS\System32\Q20333765.dll O18 - Filter: text/plain - {00000000-0000-0000-0000-000000000000} - C:\WINDOWS\System32\Q20333765.dll O23 - Service: AVK Service - Unknown - C:\PROGRA~1\eScan\helperservice.exe O23 - Service: AVK Wächter - Unknown - C:\PROGRA~1\eScan\AVKWCTL.EXE O23 - Service: Bluetooth Service - WIDCOMM, Inc. - C:\Programme\Belkin\Bluetooth Software\bin\btwdins.exe O23 - Service: Symantec Event Manager - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\ccSetMgr.exe O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.EXE O23 - Service: eScan Server-Updater - Unknown - C:\PROGRA~1\eScan\TRAYSSER.EXE O23 - Service: License Management Service ESD - element5 - C:\Programme\Gemeinsame Dateien\element5 Shared\Service\Licence Manager ESD.exe O23 - Service: Norton AntiVirus Auto-Protect-Dienst - Symantec Corporation - C:\Programme\Norton AntiVirus\navapsvc.exe O23 - Service: Norton Unerase Protection - Symantec Corporation - C:\Programme\Norton AntiVirus\AdvTools\NPROTECT.EXE O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe O23 - Service: SAVScan - Symantec Corporation - C:\Programme\Norton AntiVirus\SAVScan.exe O23 - Service: ScriptBlocking Service - Symantec Corporation - C:\PROGRA~1\GEMEIN~1\SYMANT~1\SCRIPT~1\SBServ.exe O23 - Service: Symantec Network Drivers Service - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe O23 - Service: SymWMI Service - Symantec Corporation - C:\Programme\Gemeinsame Dateien\Symantec Shared\Security Center\SymWSC.exe O23 - Service: TSMService - T-Systems Nova, Berkom - C:\Programme\T-DSL SpeedManager\tsmsvc.exe O23 - Service: TuneUp WinStyler Theme Service - TuneUp Software GmbH - C:\Programme\TuneUp Utilities 2004\WinStylerThemeSvc.exe O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINDOWS\system32\ZoneLabs\vsmon.exe und eScan Log: gesucht nach infected und tagged: Sun Feb 06 01:06:50 2005 => File C:\WINDOWS\webdlg32.dll tagged as not-a-virus:AdWare.ToolBar.SBSoft.g. No Action Taken. Sun Feb 06 01:06:50 2005 => File C:\WINDOWS\winsx.dll tagged as not-a-virus:AdWare.Puper.c. No Action Taken. Sun Feb 06 01:08:21 2005 => File C:\WINDOWS\webdlg32.dll tagged as not-a-virus:AdWare.ToolBar.SBSoft.g. No Action Taken. Sun Feb 06 01:08:21 2005 => File C:\WINDOWS\winsx.dll tagged as not-a-virus:AdWare.Puper.c. No Action Taken. Sun Feb 06 13:44:14 2005 => File C:\System Volume Information\_restore{370AA6D1-4B14-457A-AF76-C79BC29CFA36}\RP2\A0000234.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:44:16 2005 => File C:\System Volume Information\_restore{370AA6D1-4B14-457A-AF76-C79BC29CFA36}\RP2\A0000244.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:44:16 2005 => File C:\System Volume Information\_restore{370AA6D1-4B14-457A-AF76-C79BC29CFA36}\RP2\A0000253.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:44:18 2005 => File C:\System Volume Information\_restore{370AA6D1-4B14-457A-AF76-C79BC29CFA36}\RP2\A0000263.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:44:21 2005 => File C:\System Volume Information\_restore{370AA6D1-4B14-457A-AF76-C79BC29CFA36}\RP4\A0001365.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:44:22 2005 => File C:\System Volume Information\_restore{370AA6D1-4B14-457A-AF76-C79BC29CFA36}\RP4\A0001397.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:44:26 2005 => File C:\System Volume Information\_restore{370AA6D1-4B14-457A-AF76-C79BC29CFA36}\RP4\A0003401.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:44:26 2005 => File C:\System Volume Information\_restore{370AA6D1-4B14-457A-AF76-C79BC29CFA36}\RP4\A0003402.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:44:27 2005 => File C:\System Volume Information\_restore{370AA6D1-4B14-457A-AF76-C79BC29CFA36}\RP4\A0003440.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:46:31 2005 => File C:\WINDOWS\Downloaded Program Files\axload.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:46:31 2005 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.1\HDPlugin1019.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:46:31 2005 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.2\HDPlugin1019.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:46:31 2005 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.3\HDPlugin1019.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:46:31 2005 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.4\HDPlugin1019.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:46:31 2005 => File C:\WINDOWS\Downloaded Program Files\CONFLICT.5\HDPlugin1019.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 13:46:33 2005 => File C:\WINDOWS\Downloaded Program Files\www.sexonline.pl.exe infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Sun Feb 06 14:04:25 2005 => File C:\WINDOWS\wt\wtvh.dll infected by "BkCln.Unknown" Virus. Action Taken: File Renamed. Hoffe ihr könnt mir helfen, das Problem zu lösen, wenn es möglich ist, ohne Neuinstall. des Systems Danke schonmal im Voraus
__________________ |
Themen zu auch Problem mit "about:blank" und IE Einstellungen. Bitte um Hilfe |
"about:blank", adobe, antivirus, asus, bho, bitte um hilfe, einstellungen, escan, explorer, hijack, hijackthis, internet, internet explorer, logfile, microsoft, monitor, nvcpl.dll, pdf, problem, programme, rundll, security, security center, software, symantec, synchronisation, system, urlsearchhook, verschiebt, windows, windows xp |