| Plagegeist stört Google und behindert mein Internet Zitat: SDFix SDFix: Version 1.240
Run by Florian on 09.02.2009 at 23:01
Microsoft Windows XP [Version 5.1.2600]
Running From: C:\SDFix Checking Services : Name :
noskrnl.sys Path :
\??\C:\WINDOWS\system32\noskrnl.sys
noskrnl.sys - Deleted
Restoring Default Security Values
Restoring Default Hosts File
Rebooting Checking Files :
Trojan Files Found:
C:\WINDOWS\NDNUNI~3.EXE - Deleted
C:\WINDOWS\system32\TDSSlxcp.dll - Deleted
C:\WINDOWS\system32\TDSSmtvd.dat - Deleted
C:\WINDOWS\system32\TDSSkkai.log - Deleted
Could Not Remove C:\WINDOWS\system32\TDSSoiqt.dll
Could Not Remove C:\WINDOWS\system32\TDSShrxx.dll
Could Not Remove C:\WINDOWS\system32\TDSSvkql.dll
Could Not Remove C:\WINDOWS\system32\TDSSxfmm.dll
Removing Temp Files ADS Check : Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2009-02-09 23:48:28
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
disk error: C:\WINDOWS\system32\config\system, 0
scanning hidden registry entries ...
disk error: C:\WINDOWS\system32\config\software, 0
disk error: C:\Dokumente und Einstellungen\Florian\ntuser.dat, 0
scanning hidden files ...
disk error: C:\WINDOWS\
please note that you need administrator rights to perform deep scan Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Programme\\FRITZ!DSL\\FritzDsl.exe"="C:\\Programme\\FRITZ!DSL\\FritzDsl.exe:*:Enabled:FRITZ!web DSL"
"C:\\Programme\\Messenger\\msmsgs.exe"="C:\\Programme\\Messenger\\msmsgs.exe:*:Enabled:Windows Messenger"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Programme\\Valve\\hl.exe"="C:\\Programme\\Valve\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Programme\\Mozilla Firefox\\firefox.exe"="C:\\Programme\\Mozilla Firefox\\firefox.exe:*:Enabled:Firefox"
"C:\\Programme\\Valve\\Steam\\SteamApps\\bozz_online\\counter-strike\\hl.exe"="C:\\Programme\\Valve\\Steam\\SteamApps\\bozz_online\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"C:\\Dokumente und Einstellungen\\Florian\\Desktop\\Flo\\Programme\\qip\\qip.exe"="C:\\Dokumente und Einstellungen\\Florian\\Desktop\\Flo\\Programme\\qip\\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\\Programme\\qip\\qip.exe"="C:\\Programme\\qip\\qip.exe:*:Enabled:Quiet Internet Pager"
"C:\\Programme\\MSN Messenger\\msnmsgr.exe"="C:\\Programme\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Programme\\MSN Messenger\\livecall.exe"="C:\\Programme\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)"
"C:\\Programme\\Haufe\\iDesk\\iDeskService\\pythonw.exe"="C:\\Programme\\Haufe\\iDesk\\iDeskService\\pythonw.exe:*:Enabledythonw"
"C:\\Programme\\EnemyTerritory2.60b\\ET.exe"="C:\\Programme\\EnemyTerritory2.60b\\ET.exe:*:Enabled:ET"
"C:\\Programme\\TrackMania Nations ESWC\\TmNationsESWC.exe"="C:\\Programme\\TrackMania Nations ESWC\\TmNationsESWC.exe:*:Enabled:TmNationsESWC"
"C:\\Programme\\Microsoft Games\\Age of Empires II\\empires2.EXE"="C:\\Programme\\Microsoft Games\\Age of Empires II\\empires2.EXE:*:Enabled:Age of Empires II"
"C:\\UT2004\\System\\UT2004.exe"="C:\\UT2004\\System\\UT2004.exe:*:Enabled:UT2004"
"C:\\Programme\\Skype\\Phone\\Skype.exe"="C:\\Programme\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
"C:\\Programme\\Opera\\Opera.exe"="C:\\Programme\\Opera\\Opera.exe:*isabled:Opera Internet Browser"
"C:\\Programme\\FRITZ!DSL\\IGDCTRL.EXE"="C:\\Programme\\FRITZ!DSL\\IGDCTRL.EXE:*:Enabled:FRITZ!DSL - igdctrl.exe"
"I:\\fsetup.exe"="I:\\fsetup.exe:*:Enabled:AVM FSetup Application"
"C:\\Programme\\FRITZ!DSL\\FBOXUPD.EXE"="C:\\Programme\\FRITZ!DSL\\FBOXUPD.EXE:*:Enabled:AVM FRITZ!Box Firmware-Update"
"C:\\Programme\\THQ\\Juiced\\Juiced.exe"="C:\\Programme\\THQ\\Juiced\\Juiced.exe:*:Enabled:Juiced"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"C:\\Programme\\onlineTV 2\\onlineTV.exe"="C:\\Programme\\onlineTV 2\\onlineTV.exe:*:EnablednlineTV"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"C:\\Programme\\MSN Messenger\\msnmsgr.exe"="C:\\Programme\\MSN Messenger\\msnmsgr.exe:*:Enabled:Windows Live Messenger 8.1"
"C:\\Programme\\MSN Messenger\\livecall.exe"="C:\\Programme\\MSN Messenger\\livecall.exe:*:Enabled:Windows Live Messenger 8.1 (Phone)" Remaining Files :
C:\WINDOWS\system32\TDSSoiqt.dll Found
C:\WINDOWS\system32\TDSShrxx.dll Found
C:\WINDOWS\system32\TDSSvkql.dll Found
C:\WINDOWS\system32\TDSSxfmm.dll Found
File Backups: - C:\SDFix\backups\backups.zip Files with Hidden Attributes :
Sun 27 Nov 2005 4,348 ..SH. --- "C:\Dokumente und Einstellungen\All Users\DRM\DRMv1.bak"
Fri 15 Dec 2006 0 A.SH. --- "C:\Dokumente und Einstellungen\All Users\DRM\Cache\Indiv01.tmp"
Wed 19 Nov 2003 1,125,167 A..H. --- "C:\Programme\Google\require\comedy\Soundkartoffel.exe"
Mon 16 Jan 2006 111,967 A..H. --- "C:\Programme\Google\require\fonts\drift.zip"
Sun 18 Feb 2007 181,729 A..H. --- "C:\Programme\Google\require\fonts\el_font_gohtic.zip"
Mon 16 Jan 2006 26,142 A..H. --- "C:\Programme\Google\require\fonts\fontz_354_cocacola.zip"
Mon 16 Jan 2006 7,278 A..H. --- "C:\Programme\Google\require\fonts\fontz_498_graffiti.zip"
Mon 16 Jan 2006 32,223 A..H. --- "C:\Programme\Google\require\fonts\fontz_44_bloodofdracula.zip"
Mon 16 Jan 2006 14,506 A..H. --- "C:\Programme\Google\require\fonts\fontz_1008_monsterfreak.zip"
Mon 16 Jan 2006 232,304 A..H. --- "C:\Programme\Google\require\fonts\fontz_1011_charming.zip"
Mon 16 Jan 2006 26,234 A..H. --- "C:\Programme\Google\require\fonts\fontz_1038_csnpwdt.zip"
Mon 16 Jan 2006 44,461 A..H. --- "C:\Programme\Google\require\fonts\fontz_1056_electronics.zip"
Mon 16 Jan 2006 77,337 A..H. --- "C:\Programme\Google\require\fonts\rothenburg.zip"
Sun 10 Feb 2008 27,172,823 A..H. --- "C:\Programme\Google\require\Handygames, fun & shit\274_games.zip"
Wed 2 Nov 2005 15,974,943 A..H. --- "C:\Programme\Google\require\Programme\AlienMorph.zip"
Mon 6 Jun 2005 687,057 A..H. --- "C:\Programme\Google\require\Programme\HamachiSetup-0.9.9.7.exe"
Thu 10 Feb 2005 417,792 A..H. --- "C:\Programme\Google\require\Programme\lupe.exe"
Wed 10 Nov 2004 238,592 A..H. --- "C:\Programme\Google\require\Programme\pdx-cpd6.exe"
Mon 7 Apr 2008 71,816 A..H. --- "C:\Programme\Google\require\Handygames, fun & shit\225.Java.Games.240x320.Fullscreen\JADMaker.zip"
Mon 13 Aug 2001 763,258 A..H. --- "C:\Programme\Google\require\Programme\scherz\alkoholwaffe.exe"
Mon 16 Nov 1998 207,360 A..HR --- "C:\Programme\Google\require\Programme\scherz\bean.exe"
Sun 15 Jul 2001 583,985 A..H. --- "C:\Programme\Google\require\Programme\scherz\bierbrille1.exe"
Wed 3 Jul 2002 906,837 A..H. --- "C:\Programme\Google\require\Programme\scherz\britney.exe"
Fri 4 Jun 1999 407,119 A..H. --- "C:\Programme\Google\require\Programme\scherz\dipsy.exe"
Sun 30 Nov 1997 1,039,872 A..HR --- "C:\Programme\Google\require\Programme\scherz\fred.exe"
Thu 26 Aug 2004 667,960 A..H. --- "C:\Programme\Google\require\Programme\scherz\karnickel.exe"
Mon 1 Dec 2003 1,179,138 A..H. --- "C:\Programme\Google\require\Programme\scherz\maus.exe"
Tue 30 Oct 2001 22,016 A..HR --- "C:\Programme\Google\require\Programme\scherz\pause.exe"
Sat 27 Mar 1999 1,212,416 A..H. --- "C:\Programme\Google\require\Programme\scherz\peepshow.exe"
Tue 30 Oct 2001 356,352 A..HR --- "C:\Programme\Google\require\Programme\scherz\showergirl.exe"
Tue 30 Nov 2004 29,698 A..H. --- "C:\Programme\Google\require\Programme\scherz\traumfrau-generator.exe"
Fri 6 Apr 2001 20,480 A..H. --- "C:\Programme\Google\require\Programme\scherz\Alcotest\Alcotest.exe"
Mon 11 Feb 2002 102,400 A..H. --- "C:\Programme\Google\require\Programme\scherz\alkomat\alkomat.exe"
Tue 7 Mar 2000 618,793 A..H. --- "C:\Programme\Google\require\Programme\scherz\fart\fart.exe"
Thu 25 Feb 1999 290,304 A..HR --- "C:\Programme\Google\require\Programme\scherz\message\message.exe"
Sat 2 Feb 2002 19,456 A..H. --- "C:\Programme\Google\require\Programme\scherz\mouseScherz\mouseScherz.exe" Finished! | Zitat:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 23:53:31, on 09.02.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16762)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Gemeinsame Dateien\G DATA\AVKProxy\AVKProxy.exe
C:\Programme\G DATA\TotalCare\AVK\AVKService.exe
C:\Programme\G DATA\TotalCare\AVK\AVKWCtl.exe
C:\Programme\FRITZ!DSL\IGDCTRL.EXE
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\G DATA\TotalCare\Firewall\GDFwSvc.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programme\Java\jre1.5.0_05\bin\jusched.exe
C:\Programme\QuickTime\qttask.exe
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Programme\ScanSoft\PaperPort\pptd40nt.exe
C:\Programme\G DATA\TotalCare\Firewall\GDFirewallTray.exe
C:\Programme\G DATA\TotalCare\AVKTray\AVKTray.exe
C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Gadwin Systems\PrintScreen\PrintScreen.exe
C:\Programme\Brother\ControlCenter3\brccMCtl.exe
C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe
C:\Programme\Brother\Brmfcmon\BrMfcmon.exe
C:\Dokumente und Einstellungen\Florian\Desktop\highjackthis\asdf.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.de/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer bereitgestellt von 1 & 1 Internet AG
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programme\Gemeinsame Dateien\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [PaperPort PTD] "C:\Programme\ScanSoft\PaperPort\pptd40nt.exe"
O4 - HKLM\..\Run: [IndexSearch] "C:\Programme\ScanSoft\PaperPort\IndexSearch.exe"
O4 - HKLM\..\Run: [PPort11reminder] "C:\Programme\ScanSoft\PaperPort\Ereg\Ereg.exe" -r "C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\ScanSoft\PaperPort\11\Config\Ereg\Ereg.ini
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k
O4 - HKLM\..\Run: [GDFirewallTray] C:\Programme\G DATA\TotalCare\Firewall\GDFirewallTray.exe
O4 - HKLM\..\Run: [G DATA AntiVirus Trayapplication] C:\Programme\G DATA\TotalCare\AVKTray\AVKTray.exe
O4 - HKLM\..\Run: [BrMfcWnd] C:\Programme\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUN
O4 - HKLM\..\Run: [ControlCenter3] C:\Programme\Brother\ControlCenter3\brctrcen.exe /autorun
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Gadwin PrintScreen 2.6] C:\Programme\Gadwin Systems\PrintScreen\PrintScreen.exe /nosplash
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O14 - IERESET.INF: START_PAGE_URL=http://www.1und1.de/Herzlich_Willkommen/b1/
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary...r.cab31267.cab
O16 - DPF: {62789780-B744-11D0-986B-00609731A21D} (Autodesk MapGuide ActiveX Control) - http://pub.plan.at/mgaxctrlde.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary...t.cab31267.cab
O16 - DPF: {A672558F-A878-4D5A-A921-627C091CEB60} (Flatcast Producer 4.15) - http://www.flatcast.com/de/download/NpFp415.dll
O16 - DPF: {B38870E4-7ECB-40DA-8C6A-595F0A5519FF} (MsnMessengerSetupDownloadControl Class) - http://messenger.msn.com/download/Ms...Downloader.cab
O16 - DPF: {E55FD215-A32E-43FE-A777-A7E8F165F551} (Flatcast Viewer 4.15) - http://www.flatcast.com/de/download/NpFv415.dll
O16 - DPF: {FB48C7B0-EB66-4BE6-A1C5-9DDF3C37249A} (MCSendMessageHandler Class) - http://xtraz.icq.com/xtraz/activex/MISBH.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D3E63EEB-EBBA-468C-9F30-5E2797CC0A8B}: NameServer = 192.168.122.252,192.168.122.253
O18 - Protocol: haufereader - (no CLSID) - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: G DATA AntiVirus Proxy (AVKProxy) - G DATA Software AG - C:\Programme\Gemeinsame Dateien\G DATA\AVKProxy\AVKProxy.exe
O23 - Service: G DATA Scheduler (AVKService) - G DATA Software AG - C:\Programme\G DATA\TotalCare\AVK\AVKService.exe
O23 - Service: AntiVirus Wächter (AVKWCtl) - G DATA Software AG - C:\Programme\G DATA\TotalCare\AVK\AVKWCtl.exe
O23 - Service: AVM IGD CTRL Service - AVM Berlin - C:\Programme\FRITZ!DSL\IGDCTRL.EXE
O23 - Service: AVM FRITZ!web Routing Service (de_serv) - AVM Berlin - C:\Programme\Gemeinsame Dateien\AVM\de_serv.exe
O23 - Service: G DATA Backup Service - G DATA Software AG - C:\Programme\G DATA\TotalCare\AVKBackup\AVKBackupService.exe
O23 - Service: G DATA Tuner Service - G DATA Software AG - C:\Programme\G DATA\TotalCare\AVKTuner\AVKTunerService.exe
O23 - Service: G DATA Personal Firewall (GDFwSvc) - G DATA Software AG - C:\Programme\G DATA\TotalCare\Firewall\GDFwSvc.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe
O24 - Desktop Component 0: (no name) - http://www.chip.de/ii/29179727_131d347da9.jpg
O24 - Desktop Component 2: XXX On Ice - http://www.xxxonice.com/
--
End of file - 7665 bytes
| Weitere Logs folgen |