|
Log-Analyse und Auswertung: Brauche Hilfe mit meinem HJT Log!!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
21.07.2006, 22:14 | #1 |
| Brauche Hilfe mit meinem HJT Log!! Hallihallo! Ich habe einige probleme mit meinem Ibm Thinkpad...er moechte sich nichtmehr mit dem Internet verbinden (nicht ueber kabel aber auch nicht wireless), er braucht ca. 7 bis 8 minuten um hochzufahren und wenn ich ihn hochfahre habe ich zahlreiche fehlermeldungen dass programme wie z.b. symnatecs AV nicht starten koennen...ich selber weiss nicht woran es liegt, adaware hat nix gefunden und auch spyware search and destroy meinte alles waere ok! mein antivir program moechte nicht starten...und auch nach Neuinstallation gibt es noch schwierigkeiten...ihr seid meine letzte hoffnung also hier is mal mein HJT log und wenns noch fragen gibt mir schreiben... Logfile of HijackThis v1.99.1 Scan saved at 4:03:39 PM, on 7/21/2006 Platform: Windows XP SP2 (WinNT 5.01.2600) MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\System32\ibmpmsvc.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\System32\S24EvMon.exe C:\WINDOWS\Explorer.EXE C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe C:\WINDOWS\system32\spoolsv.exe C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe C:\Program Files\Symantec AntiVirus\DefWatch.exe C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe C:\WINDOWS\System32\mnmsrvc.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\System32\RegSrvc.exe C:\Program Files\Symantec AntiVirus\SavRoam.exe C:\Program Files\Spyware Doctor\sdhelp.exe C:\WINDOWS\System32\svchost.exe C:\Program Files\Symantec AntiVirus\Rtvscan.exe C:\Program Files\Common Files\Symantec Shared\ccApp.exe C:\WINDOWS\System32\hkcmd.exe C:\WINDOWS\System32\igfxtray.exe C:\PROGRA~1\SYMANT~1\VPTray.exe C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe C:\WINDOWS\system32\TpShocks.exe C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe C:\Program Files\Common Files\Real\Update_OB\realsched.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY\TPONSCR.exe C:\Program Files\ThinkPad\PkgMgr\HOTKEY_1\TpScrex.exe C:\Program Files\Synaptics\SynTP\SynTPLpr.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Real\RealPlayer\RealPlay.exe C:\Program Files\Synaptics\SynTP\SynTPEnh.exe C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe C:\WINDOWS\system32\ctfmon.exe C:\Program Files\QuickTime\qttask.exe C:\IBMTOOLS\UTILS\ibmprc.exe C:\Program Files\IBM\Messages By IBM\ibmmessages.exe C:\Program Files\Lexmark 7100 Series\ezprint.exe C:\WINDOWS\system32\rundll32.exe C:\WINDOWS\system32\RunDll32.exe C:\Program Files\Microsoft AntiSpyware\gcasDtServ.exe C:\WINDOWS\system32\lxbxcoms.exe C:\HijackThis.exe C:\WINDOWS\system32\ZoneLabs\vsmon.exe R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = filter.lausanneschool.com:80 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 199.91.47.60:8000;<local> O1 - Hosts: 56.127.201.72 avp.com O1 - Hosts: 191.113.246.162 ca.com O1 - Hosts: 213.206.229.238 customer.symantec.com O1 - Hosts: 119.140.134.46 dispatch.mcafee.com O1 - Hosts: 215.189.107.7 download.mcafee.com O1 - Hosts: 210.7.204.83 downloads1.kaspersky-labs.com O1 - Hosts: 61.184.188.244 downloads3.kaspersky-labs.com O1 - Hosts: 26.90.181.166 downloads4.kaspersky-labs.com O1 - Hosts: 17.130.54.43 downloads-eu1.kaspersky-labs.com O1 - Hosts: 105.171.153.22 downloads-eu2.kaspersky-labs.com O1 - Hosts: 27.123.162.188 downloads-eu3.kaspersky-labs.com O1 - Hosts: 185.187.92.51 downloads-eu4.kaspersky-labs.com O1 - Hosts: 230.167.221.163 downloads-us1.kaspersky-labs.com O1 - Hosts: 34.144.148.251 downloads-us2.kaspersky-labs.com O1 - Hosts: 99.200.122.34 downloads-us3.kaspersky-labs.com O1 - Hosts: 218.83.230.155 downloads-us4.kaspersky-labs.com O1 - Hosts: 79.51.198.236 f-secure.com O1 - Hosts: 86.117.250.20 ftp.avp.com O1 - Hosts: 0.187.170.93 ftp.ca.com O1 - Hosts: 36.228.190.130 ftp.customer.symantec.com O1 - Hosts: 232.45.88.63 ftp.dispatch.mcafee.com O1 - Hosts: 175.73.253.104 ftp.download.mcafee.com O1 - Hosts: 132.219.196.28 ftp.downloads1.kaspersky-labs.com O1 - Hosts: 69.220.66.142 ftp.downloads2.kaspersky-labs.com O1 - Hosts: 1.183.118.44 ftp.downloads3.kaspersky-labs.com O1 - Hosts: 107.199.10.113 ftp.downloads4.kaspersky-labs.com O1 - Hosts: 192.248.156.71 ftp.downloads-eu1.kaspersky-labs.com O1 - Hosts: 139.28.80.61 ftp.downloads-eu2.kaspersky-labs.com O1 - Hosts: 169.93.6.109 ftp.downloads-eu3.kaspersky-labs.com O1 - Hosts: 107.205.89.98 ftp.downloads-eu4.kaspersky-labs.com O1 - Hosts: 201.111.210.218 ftp.downloads-us1.kaspersky-labs.com O1 - Hosts: 243.75.222.174 ftp.downloads-us2.kaspersky-labs.com O1 - Hosts: 194.228.8.51 ftp.downloads-us3.kaspersky-labs.com O1 - Hosts: 200.34.126.124 ftp.downloads-us4.kaspersky-labs.com O1 - Hosts: 142.3.231.178 ftp.f-secure.com O1 - Hosts: 181.169.4.117 ftp.grisoft.com O1 - Hosts: 142.31.162.248 ftp.kaspersky.com O1 - Hosts: 97.78.121.91 ftp.kaspersky-labs.com O1 - Hosts: 106.165.77.91 ftp.liveupdate.symantec.com O1 - Hosts: 215.91.138.234 ftp.liveupdate.symantecliveupdate.com O1 - Hosts: 193.54.51.207 ftp.mast.mcafee.com O1 - Hosts: 229.230.193.199 ftp.mcafee.com O1 - Hosts: 174.78.113.224 ftp.my-etrust.com O1 - Hosts: 190.60.128.124 ftp.nai.com O1 - Hosts: 145.128.223.51 ftp.networkassociates.com O1 - Hosts: 240.97.94.134 ftp.norton.com O1 - Hosts: 182.195.82.30 ftp.rads.mcafee.com O1 - Hosts: 183.170.70.121 ftp.sandbox.norman.com O1 - Hosts: 195.76.163.84 ftp.secure.nai.com O1 - Hosts: 13.222.112.169 ftp.securityresponse.symantec.com O1 - Hosts: 247.114.142.146 ftp.sophos.com O1 - Hosts: 19.97.32.105 ftp.symantec.com O1 - Hosts: 63.51.98.110 ftp.symantecliveupdate.com O1 - Hosts: 77.0.193.220 ftp.symatec.com O1 - Hosts: 16.181.243.40 ftp.trendmicro.com O1 - Hosts: 42.187.69.84 ftp.uk.trendmicro-europe.com O1 - Hosts: 157.231.246.21 ftp.update.symantec.com O1 - Hosts: 89.51.91.59 ftp.updates.symantec.com O1 - Hosts: 86.43.15.143 ftp.updates1.kaspersky-labs.com O1 - Hosts: 118.143.240.24 ftp.updates2.kaspersky-labs.com O1 - Hosts: 184.10.195.3 ftp.updates3.kaspersky-labs.com O1 - Hosts: 254.135.14.154 ftp.updates4.kaspersky-labs.com O1 - Hosts: 236.6.185.3 ftp.us.mcafee.com O1 - Hosts: 157.116.113.182 ftp.viruslist.com O1 - Hosts: 60.113.192.236 grisoft.com O1 - Hosts: 63.118.9.219 kaspersky.com O1 - Hosts: 76.88.48.33 kaspersky-labs.com O1 - Hosts: 1.157.182.167 liveupdate.symantec.com O1 - Hosts: 179.0.144.76 liveupdate.symantecliveupdate.com O1 - Hosts: 98.185.100.190 mast.mcafee.com O1 - Hosts: 87.232.155.57 mcafee.com O1 - Hosts: 209.33.102.163 my-etrust.com O1 - Hosts: 30.114.9.56 nai.com O1 - Hosts: 4.152.178.172 networkassociates.com O1 - Hosts: 108.127.39.24 norton.com O1 - Hosts: 156.201.230.250 pandasoftware.com O1 - Hosts: 249.176.74.43 rads.mcafee.com O1 - Hosts: 38.59.149.141 sandbox.norman.com O1 - Hosts: 238.52.137.220 secure.nai.com O1 - Hosts: 91.236.116.223 securityresponse.symantec.com O1 - Hosts: 86.155.201.217 sophos.com O1 - Hosts: 191.243.198.148 symantec.com O1 - Hosts: 222.197.155.197 symantecliveupdate.com O1 - Hosts: 7.51.44.185 symatec.com O1 - Hosts: 230.221.228.1 trendmicro.com O1 - Hosts: 77.22.171.144 uk.trendmicro-europe.com O1 - Hosts: 227.225.99.129 update.symantec.com O1 - Hosts: 35.235.32.115 updates.symantec.com O1 - Hosts: 13.62.241.182 updates1.kaspersky-labs.com O1 - Hosts: 97.194.230.61 updates2.kaspersky-labs.com O1 - Hosts: 96.248.41.1 updates3.kaspersky-labs.com O1 - Hosts: 211.94.101.205 updates4.kaspersky-labs.com O1 - Hosts: 109.235.202.55 us.mcafee.com O1 - Hosts: 50.183.225.19 viruslist.com O1 - Hosts: 253.14.1.65 virusscan.jotti.org O1 - Hosts: 103.148.35.171 virustotal.com O1 - Hosts: 253.81.101.184 www.avp.com O1 - Hosts: 43.164.229.149 www.ca.com O1 - Hosts: 65.8.224.163 www.customer.symantec.com O1 - Hosts: 106.51.37.103 www.dispatch.mcafee.com O1 - Hosts: 146.100.217.184 www.download.mcafee.com O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll O4 - HKLM\..\Run: [LXBXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\LXBXtime.dll,_RunDLLEntry@16 O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe O4 - HKLM\..\Run: [ccApp] "C:\Program Files\Common Files\Symantec Shared\ccApp.exe" O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exe O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\System32\igfxtray.exe O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\VPTray.exe O4 - HKLM\..\Run: [Zone Labs Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [TpShocks] TpShocks.exe O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\ThinkPad\PkgMgr\HOTKEY\TPHKMGR.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Program Files\Java\jre1.5.0_06\bin\jusched.exe O4 - HKLM\..\Run: [StorageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /r O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [lxbxmon.exe] "C:\Program Files\Lexmark 7100 Series\lxbxmon.exe" O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k O4 - HKLM\..\Run: [IBMPRC] C:\IBMTOOLS\UTILS\ibmprc.exe O4 - HKLM\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\\ibmmessages.exe O4 - HKLM\..\Run: [gcasServ] "C:\Program Files\Microsoft AntiSpyware\gcasServ.exe" O4 - HKLM\..\Run: [EzPrint] "C:\Program Files\Lexmark 7100 Series\ezprint.exe" O4 - HKLM\..\Run: [BMMMONWND] rundll32.exe C:\PROGRA~1\ThinkPad\UTILIT~1\BatInfEx.dll,BMMAutonomicMonitor O4 - HKLM\..\Run: [BMMLREF] C:\Program Files\ThinkPad\Utilities\BMMLREF.EXE O4 - HKLM\..\Run: [BMMGAG] RunDll32 C:\PROGRA~1\ThinkPad\UTILIT~1\pwrmonit.dll,StartPwrMonitor O4 - HKLM\..\RunOnce: [!CleanupNetMeetingDispDriver] "C:\WINDOWS\system32\rundll32.exe" msconf.dll,CleanupNetMeetingDispDriver 0 O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [ibmmessages] C:\Program Files\IBM\Messages By IBM\ibmmessages.exe O4 - HKCU\..\RunServices: [Microsoft HDCP for NT] msdhcp.exe O4 - Global Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = C:\Program Files\Microsoft Office\OFFICE11\ONENOTEM.EXE O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_06\bin\ssv.dll (file missing) O9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~2\tools\iesdpb.dll (file missing) O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files\ICQLite\ICQLite.exe O9 - Extra button: Run IMVU - {d9288080-1baa-4bc4-9cf8-a92d743db949} - C:\Documents and Settings\HeecktV\Start Menu\Programs\>IMVU\Run IMVU.lnk (file missing) O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O10 - Broken Internet access because of LSP chain gap (#11 in chain of 17 missing) O16 - DPF: {48884C41-EFAC-433D-958A-9FADAC41408E} (EGamesPlugin Class) - https://www.e-games.com.my/com/EGamesPlugin.cab O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing) O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll O20 - Winlogon Notify: NavLogon - C:\WINDOWS\system32\NavLogon.dll O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - Unknown owner - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe O23 - Service: avast! Antivirus - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashServ.exe O23 - Service: avast! Mail Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe" /service (file missing) O23 - Service: avast! Web Scanner - Unknown owner - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe" /service (file missing) O23 - Service: Boonty Games - BOONTY - C:\Program Files\Common Files\BOONTY Shared\Service\Boonty.exe O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccEvtMgr.exe O23 - Service: Symantec Password Validation (ccPwdSvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccPwdSvc.exe O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\ccSetMgr.exe O23 - Service: Symantec AntiVirus Definition Watcher (DefWatch) - Symantec Corporation - C:\Program Files\Symantec AntiVirus\DefWatch.exe O23 - Service: IBM Rapid Restore Ultra Service - Unknown owner - C:\Program Files\IBM\IBM Rapid Restore Ultra\rrpcsb.exe O23 - Service: IBM PM Service (IBMPMSVC) - Unknown owner - C:\WINDOWS\System32\ibmpmsvc.exe O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe O23 - Service: iPodService - Apple Computer, Inc. - C:\Program Files\iPod\bin\iPodService.exe O23 - Service: lxbx_device - Lexmark International, Inc. - C:\WINDOWS\system32\lxbxcoms.exe O23 - Service: MrPostman - Unknown owner - C:\Program Files\MrPostman\wrapper\wrapper.exe" -s wrapper.conf (file missing) O23 - Service: IBM PSA Access Driver Control (PsaSrv) - Unknown owner - C:\WINDOWS\system32\PsaSrv.exe (file missing) O23 - Service: RegSrvc - Intel Corporation - C:\WINDOWS\System32\RegSrvc.exe O23 - Service: Spectrum24 Event Monitor (S24EventMonitor) - Intel Corporation - C:\WINDOWS\System32\S24EvMon.exe O23 - Service: SAVRoam (SavRoam) - symantec - C:\Program Files\Symantec AntiVirus\SavRoam.exe O23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exe O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exe O23 - Service: Software Secure Service (SSISvr32) - Unknown owner - C:\WINDOWS\system32\ssisvr32.exe (file missing) O23 - Service: Symantec AntiVirus - Symantec Corporation - C:\Program Files\Symantec AntiVirus\Rtvscan.exe O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe O23 - Service: VNC Server (winvnc) - Unknown owner - C:\Program Files\RealVNC\WinVNC\WinVNC.exe" -service (file missing) hoffe jemand findet das problem...MFG Evilvic |
22.07.2006, 08:42 | #2 | |
Administrator > Competence Manager | Brauche Hilfe mit meinem HJT Log!! Hallo,
__________________dein Logfile sieht zielich zugemüllt aus, es deuten aber keine Einträge auf spezielle unerwünschte Gäste hin...nur diese hier: Zitat:
Scanne dein System mit eScan sowie mit F-Secure Blacklight, und poste anschliessend die Ergebnisse. 1.) eScan Ergebnis mit Hilfe der "find.bat" (Beschreibung genau durchlesen!) 2.) Inhalt Report.txt von F-Secure Blacklight Gruß Daniel
__________________ |
Themen zu Brauche Hilfe mit meinem HJT Log!! |
antispyware, antivir, antivirus, avast, avast!, brauche hilfe, computer, dll, drivers, excel, explorer, frage, google, hijack, hijackthis, internet, internet explorer, nicht starten, pc tools spyware doctor, programme, rundll, settings manager, software, spyware, start menu, starten, symantec, system, windows, windows xp, wrapper |