|
Log-Analyse und Auswertung: Firefox leitet mich auf andere Seiten um!Windows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
04.05.2009, 17:59 | #16 |
/// TB-Ausbilder | Firefox leitet mich auf andere Seiten um! Hi, stecke den Stick bitte nohcmal ein und führe Combofix nochmal aus. Poste das Ergebnis hier. Wenn die Malware noch aktiv war, dann hat einstecken gereicht um den Stick zu infizieren. lg myrtille
__________________ Anfragen per Email, Profil- oder privater Nachricht werden ignoriert! Hilfe gibts NUR im Forum! Wer nach 24 Stunden keine weitere Antwort von mir bekommen hat, schickt bitte eine PM Spelling mistakes? Never, but keybaord malfunctions constantly! |
04.05.2009, 18:15 | #17 |
| Firefox leitet mich auf andere Seiten um! Ok,soll ich den Log nochmal posten?
__________________ |
04.05.2009, 18:36 | #18 |
/// TB-Ausbilder | Firefox leitet mich auf andere Seiten um! Ja bitte
__________________lg myrtille
__________________ |
04.05.2009, 19:32 | #19 |
| Firefox leitet mich auf andere Seiten um!Code:
ATTFilter ComboFix 09-05-03.6 - Christopher 04.05.2009 20:26.2 - NTFSx86 Microsoft® Windows Vista™ Home Premium 6.0.6001.1.1252.49.1031.18.2047.1321 [GMT 2:00] ausgeführt von:: c:\users\Christopher\Desktop\ComboFix.exe . ((((((((((((((((((((((( Dateien erstellt von 2009-04-04 bis 2009-05-04 )))))))))))))))))))))))))))))) . 2009-05-04 15:23 . 2009-03-24 14:08 55640 ----a-w c:\windows\system32\drivers\avgntflt.sys 2009-05-04 15:23 . 2009-05-04 15:23 -------- d-----w c:\programdata\Avira 2009-05-04 15:23 . 2009-05-04 15:23 -------- d-----w c:\program files\Avira 2009-05-04 13:32 . 2009-05-04 16:45 -------- d-----w c:\programdata\TrackMania 2009-05-04 12:43 . 2009-05-04 12:44 -------- d-----w c:\program files\TmNationsForever 2009-05-02 15:21 . 2009-05-02 15:21 -------- d-----w c:\program files\CCleaner 2009-05-02 10:41 . 2009-05-02 10:41 -------- d-----w c:\users\Christopher\AppData\Roaming\Malwarebytes 2009-05-02 09:55 . 2009-04-06 13:32 15504 ----a-w c:\windows\system32\drivers\mbam.sys 2009-05-02 09:55 . 2009-04-06 13:32 38496 ----a-w c:\windows\system32\drivers\mbamswissarmy.sys 2009-05-02 09:55 . 2009-05-02 09:55 -------- d-----w c:\programdata\Malwarebytes 2009-05-02 09:55 . 2009-05-02 10:41 -------- d-----w c:\program files\Malwarebytes' Anti-Malware 2009-04-30 14:44 . 2009-05-04 17:20 -------- d-----w c:\program files\Silkroad 2009-04-29 08:44 . 2009-04-29 09:44 -------- d-----w c:\users\Christopher\AppData\Roaming\Bioshock 2009-04-27 16:37 . 2009-04-27 16:37 -------- d-----w c:\program files\Monte Cristo 2009-04-25 12:21 . 2009-04-28 20:58 -------- d-----w c:\program files\World of Warcraft 2009-04-22 16:12 . 2009-04-27 14:36 -------- d-----w c:\users\Christopher\Nachhilfe 2009-04-20 13:07 . 2009-05-04 17:20 -------- d-----w c:\users\Christopher\Spiele 2009-04-15 15:44 . 2009-04-15 15:44 -------- d-----w c:\users\Christopher\AppData\Local\Fallout3 2009-04-15 15:21 . 2009-04-15 15:21 -------- d-----w c:\program files\Bethesda Softworks 2009-04-14 16:26 . 2009-04-15 10:09 -------- d-----w c:\users\Christopher\AppData\Roaming\temp . (((((((((((((((((((((((((((((((((((( Find3M Bericht )))))))))))))))))))))))))))))))))))))))))))))))))))))) . 2009-05-04 17:19 . 2009-02-20 11:11 -------- d-----w c:\program files\Ubisoft 2009-05-04 17:19 . 2008-01-10 16:04 -------- d--h--w c:\program files\InstallShield Installation Information 2009-05-04 17:19 . 2008-07-21 14:08 -------- d-----w c:\program files\Google 2009-05-04 17:18 . 2008-09-30 18:19 -------- d-----w c:\program files\Game Cam V2 2009-05-04 14:57 . 2008-01-10 16:59 -------- d-----w c:\program files\Norton Internet Security 2009-05-04 14:57 . 2008-01-10 16:57 -------- d-----w c:\program files\Common Files\Symantec Shared 2009-05-04 14:42 . 2006-11-02 10:25 86016 ----a-w c:\windows\inf\infstor.dat 2009-05-04 14:42 . 2006-11-02 10:25 51200 ----a-w c:\windows\inf\infpub.dat 2009-05-04 14:42 . 2006-11-02 10:25 143360 ----a-w c:\windows\inf\infstrng.dat 2009-05-04 07:56 . 2006-11-02 15:33 664044 ----a-w c:\windows\system32\perfh007.dat 2009-05-04 07:56 . 2006-11-02 15:33 142222 ----a-w c:\windows\system32\perfc007.dat 2009-04-29 18:23 . 2008-12-17 14:52 -------- d-----w c:\program files\Fraps 2009-04-29 11:50 . 2008-09-11 11:25 -------- d-----w c:\program files\Runes of Magic 2009-04-29 08:14 . 2008-10-02 15:19 -------- d-----w c:\program files\2K Games 2009-04-26 17:45 . 2006-11-02 12:37 -------- d-----w c:\program files\Microsoft Games 2009-04-25 14:54 . 2009-03-18 19:16 -------- d-----w c:\program files\Diablo II 2009-04-25 14:44 . 2009-02-23 16:27 -------- d-----w c:\program files\Common Files\Blizzard Entertainment 2009-04-25 10:46 . 2008-04-04 14:32 90568 ----a-w c:\users\Christopher\AppData\Local\GDIPFONTCACHEV1.DAT 2009-04-24 20:25 . 2008-12-01 13:47 -------- d-----w c:\program files\Bethesda 2009-04-24 20:23 . 2009-03-27 18:21 -------- d-----w c:\program files\OnkoS 2009-04-24 20:11 . 2009-03-01 18:08 -------- d-----w c:\program files\Anno 1602 Königs-Edition 2009-04-20 13:04 . 2009-03-23 10:00 -------- d-----w c:\program files\DNA 2009-04-16 14:53 . 2006-11-02 11:18 -------- d-----w c:\program files\Windows Mail 2009-04-14 16:27 . 2008-10-05 12:32 -------- d-----w c:\program files\EA GAMES 2009-04-07 15:34 . 2008-04-04 19:47 -------- d-----w c:\program files\Warcraft III 2009-04-07 10:49 . 2009-02-21 17:31 -------- d-----w c:\program files\Steam 2009-04-06 23:19 . 2008-04-23 13:19 -------- d-----w c:\program files\Valve 2009-04-06 16:34 . 2008-04-04 19:51 133409 ----a-w c:\windows\War3Unin.dat 2009-04-04 16:55 . 2008-08-14 17:50 -------- d-----w c:\program files\ICQ6 2009-04-04 15:11 . 2008-12-05 14:41 -------- d-----w c:\program files\Electronic Arts 2009-04-02 14:42 . 2009-04-02 14:42 5434 ----a-w c:\windows\system32\ealregsnapshot1.reg 2009-03-31 16:32 . 2008-05-05 15:37 98304 ----a-w c:\windows\system32\CmdLineExt.dll 2009-03-29 08:17 . 2009-03-29 08:16 -------- d-----w c:\program files\Unechtes Turnier 2009-03-28 18:00 . 2008-05-16 19:30 -------- d-----w c:\program files\WarRock 2009-03-27 15:18 . 2009-03-23 17:07 -------- d-----w c:\program files\RouterControl 2009-03-25 15:06 . 2008-08-19 17:56 -------- d-----w c:\program files\THQ 2009-03-23 13:41 . 2009-03-23 13:14 614 ----a-w c:\windows\eReg.dat 2009-03-21 18:30 . 2009-03-21 18:08 -------- d-----w c:\program files\Starcraft 2009-03-20 16:52 . 2009-03-20 16:52 -------- d-----w c:\program files\DivX 2009-03-20 16:52 . 2009-03-20 16:52 -------- d-----w c:\program files\Common Files\PX Storage Engine 2009-03-20 16:52 . 2009-03-20 16:52 -------- d-----w c:\program files\Common Files\DivX Shared 2009-03-18 19:29 . 2009-03-18 19:19 19284 ----a-w c:\windows\DIIUnin.dat 2009-03-18 19:19 . 2009-03-18 19:19 2829 ----a-w c:\windows\DIIUnin.pif 2009-03-18 19:19 . 2009-03-18 19:19 102400 ----a-w c:\windows\DIIUnin.exe 2009-03-17 03:38 . 2009-04-15 10:06 13824 ----a-w c:\windows\system32\apilogen.dll 2009-03-17 03:38 . 2009-04-15 10:06 24064 ----a-w c:\windows\system32\amxread.dll 2009-03-16 19:58 . 2009-03-16 19:58 -------- d-----w c:\program files\directx 2009-03-15 16:47 . 2009-03-15 16:47 -------- d-----w c:\program files\SweetIM 2009-03-12 18:20 . 2009-03-12 18:20 -------- d-----w c:\program files\VisionGS PE 2009-03-11 15:38 . 2009-02-21 17:31 -------- d-----w c:\program files\Common Files\Steam 2009-03-08 13:25 . 2008-11-09 13:14 -------- d-----w c:\program files\Common Files\Wise Installation Wizard 2009-03-08 11:35 . 2009-03-08 11:35 56 ---ha-w c:\windows\system32\ezsidmv.dat 2009-03-08 11:32 . 2009-03-08 11:32 -------- d-----w c:\program files\Common Files\Skype 2009-03-08 11:32 . 2009-03-08 11:32 -------- d-----r c:\program files\Skype 2009-03-03 04:46 . 2009-04-15 10:06 3599328 ----a-w c:\windows\system32\ntkrnlpa.exe 2009-03-03 04:46 . 2009-04-15 10:06 3547632 ----a-w c:\windows\system32\ntoskrnl.exe 2009-03-03 04:40 . 2009-04-15 10:06 827392 ----a-w c:\windows\system32\wininet.dll 2009-03-03 04:39 . 2009-04-15 10:06 183296 ----a-w c:\windows\system32\sdohlp.dll 2009-03-03 04:39 . 2009-04-15 10:06 551424 ----a-w c:\windows\system32\rpcss.dll 2009-03-03 04:39 . 2009-04-15 10:06 26112 ----a-w c:\windows\system32\printfilterpipelineprxy.dll 2009-03-03 04:37 . 2009-04-15 10:06 78336 ----a-w c:\windows\system32\ieencode.dll 2009-03-03 04:37 . 2009-04-15 10:06 98304 ----a-w c:\windows\system32\iasrecst.dll 2009-03-03 04:37 . 2009-04-15 10:06 54784 ----a-w c:\windows\system32\iasads.dll 2009-03-03 04:37 . 2009-04-15 10:06 44032 ----a-w c:\windows\system32\iasdatastore.dll 2009-03-03 03:04 . 2009-04-15 10:06 666624 ----a-w c:\windows\system32\printfilterpipelinesvc.exe 2009-03-03 02:38 . 2009-04-15 10:06 17408 ----a-w c:\windows\system32\iashost.exe 2009-03-03 02:28 . 2009-04-15 10:06 26624 ----a-w c:\windows\system32\ieUnatt.exe 2009-02-25 17:55 . 2009-03-27 20:22 4224 ----a-w c:\windows\system32\drivers\NVStrap.sys 2009-02-13 08:49 . 2009-04-15 10:06 72704 ----a-w c:\windows\system32\secur32.dll 2009-02-13 08:49 . 2009-04-15 10:06 1255936 ----a-w c:\windows\system32\lsasrv.dll 2009-02-09 03:10 . 2009-03-11 05:59 2033152 ----a-w c:\windows\system32\win32k.sys 2008-05-29 15:45 . 2006-11-02 12:50 174 --sha-w c:\program files\desktop.ini 2009-01-27 01:34 . 2009-01-27 01:34 1044480 ----a-w c:\program files\mozilla firefox\plugins\libdivx.dll 2009-01-27 01:34 . 2009-01-27 01:34 200704 ----a-w c:\program files\mozilla firefox\plugins\ssldivx.dll 2008-09-28 17:01 . 2008-09-28 16:50 24 --sh--w c:\windows\SE2D238D6.tmp 2008-10-24 19:12 . 2008-08-26 19:44 168 --sh--r c:\windows\System32\F125D974EB.sys 2006-05-03 10:06 . 2009-01-11 19:29 163328 --sh--r c:\windows\System32\flvDX.dll 2008-10-24 19:12 . 2008-08-26 19:34 2516 --sha-w c:\windows\System32\KGyGaAvL.sys 2007-02-21 11:47 . 2009-01-11 19:29 31232 --sh--r c:\windows\System32\msfDX.dll 2008-03-16 13:30 . 2009-01-11 19:29 216064 --sh--r c:\windows\System32\nbDX.dll . ((((((((((((((((((((((((((((( SnapShot@2009-05-04_15.03.39 ))))))))))))))))))))))))))))))))))))))))) . + 2009-05-04 15:22 . 2009-05-04 15:22 62976 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90RUS.DLL + 2009-05-04 15:22 . 2009-05-04 15:22 46080 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90KOR.DLL + 2009-05-04 15:22 . 2009-05-04 15:22 46592 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90JPN.DLL + 2009-05-04 15:22 . 2009-05-04 15:22 64512 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ITA.DLL + 2009-05-04 15:22 . 2009-05-04 15:22 66048 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90FRA.DLL + 2009-05-04 15:22 . 2009-05-04 15:22 65024 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ESP.DLL + 2009-05-04 15:22 . 2009-05-04 15:22 65024 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ESN.DLL + 2009-05-04 15:22 . 2009-05-04 15:22 56832 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90ENU.DLL + 2009-05-04 15:22 . 2009-05-04 15:22 66560 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90DEU.DLL + 2009-05-04 15:22 . 2009-05-04 15:22 39936 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90CHT.DLL + 2009-05-04 15:22 . 2009-05-04 15:22 38912 c:\windows\winsxs\x86_microsoft.vc90.mfcloc_1fc8b3b9a1e18e3b_9.0.30729.1_none_da4695fc507e16e1\MFC90CHS.DLL + 2009-05-04 15:22 . 2009-05-04 15:22 59904 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90u.dll + 2009-05-04 15:22 . 2009-05-04 15:22 59904 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfcm90.dll - 2008-01-10 15:25 . 2009-05-04 14:59 52920 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2008-01-10 15:25 . 2009-05-04 15:16 52920 c:\windows\System32\WDI\ShutdownPerformanceDiagnostics_SystemData.bin + 2008-04-04 18:21 . 2009-05-04 15:16 13030 c:\windows\System32\WDI\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-759913723-362470790-2232644708-1000_UserData.bin + 2009-05-04 15:23 . 2009-02-13 10:49 28376 c:\windows\System32\drivers\ssmdrv.sys + 2009-05-04 15:23 . 2009-03-30 08:33 96104 c:\windows\System32\drivers\avipbb.sys - 2008-04-04 14:29 . 2009-05-04 12:29 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat + 2008-04-04 14:29 . 2009-05-04 15:28 16384 c:\windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat - 2008-04-04 14:29 . 2009-05-04 12:29 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat + 2008-04-04 14:29 . 2009-05-04 15:28 32768 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat - 2008-04-04 14:29 . 2009-05-04 12:29 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2008-04-04 14:29 . 2009-05-04 15:28 16384 c:\windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat + 2008-04-06 16:10 . 2009-05-04 15:10 4882 c:\windows\System32\WDI\ERCQueuedResolutions.dat + 2009-05-04 15:13 . 2009-05-04 15:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat - 2009-05-04 14:57 . 2009-05-04 14:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat + 2009-05-04 15:13 . 2009-05-04 15:13 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat - 2009-05-04 14:57 . 2009-05-04 14:57 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat + 2009-05-04 15:22 . 2009-05-04 15:22 655872 c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcr90.dll + 2009-05-04 15:22 . 2009-05-04 15:22 572928 c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcp90.dll + 2009-05-04 15:22 . 2009-05-04 15:22 225280 c:\windows\winsxs\x86_microsoft.vc90.crt_1fc8b3b9a1e18e3b_9.0.30729.1_none_e163563597edeada\msvcm90.dll + 2009-05-04 15:22 . 2009-05-04 15:22 161784 c:\windows\winsxs\x86_microsoft.vc90.atl_1fc8b3b9a1e18e3b_9.0.30729.1_none_e29d1181971ae11e\ATL90.dll + 2006-11-02 13:05 . 2009-05-04 15:16 106432 c:\windows\System32\WDI\BootPerformanceDiagnostics_SystemData.bin - 2008-01-11 08:52 . 2009-05-04 14:59 262144 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat + 2008-01-11 08:52 . 2009-05-04 18:24 262144 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\usrclass.dat - 2008-01-11 08:51 . 2009-05-04 15:03 262144 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat + 2008-01-11 08:51 . 2009-05-04 18:29 262144 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\usrclass.dat + 2009-05-04 15:22 . 2009-05-04 15:22 3783672 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90u.dll + 2009-05-04 15:22 . 2009-05-04 15:22 3768312 c:\windows\winsxs\x86_microsoft.vc90.mfc_1fc8b3b9a1e18e3b_9.0.30729.1_none_dcc7eae99ad0d9cf\mfc90.dll + 2006-11-02 10:22 . 2009-05-04 15:23 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT - 2006-11-02 10:22 . 2009-04-16 19:05 6553600 c:\windows\System32\SMI\Store\Machine\SCHEMA.DAT + 2009-05-04 18:25 . 2009-05-04 18:25 6402048 c:\windows\ERDNT\Hiv-backup\SCHEMA.DAT + 2008-04-04 18:23 . 2009-05-04 15:23 217821837 c:\windows\winsxs\ManifestCache\6.0.6001.18000_001c50b5_blobs.bin |
04.05.2009, 19:34 | #20 |
| Firefox leitet mich auf andere Seiten um! [code] (((((((((((((((((((((((((((( Autostartpunkte der Registrierung )))))))))))))))))))))))))))))))))))))))) . . *Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt. REGEDIT4 [HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{EEE6C35C-6118-11DC-9C72-001320C79847}] 2008-10-08 11:22 1172792 ----a-w c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar] "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792] [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}] [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3] [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}] [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE] [HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Toolbar\Webbrowser] "{EEE6C35B-6118-11DC-9C72-001320C79847}"= "c:\program files\SweetIM\Toolbars\Internet Explorer\mgToolbarIE.dll" [2008-10-08 1172792] [HKEY_CLASSES_ROOT\clsid\{eee6c35b-6118-11dc-9c72-001320c79847}] [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE.3] [HKEY_CLASSES_ROOT\TypeLib\{EEE6C35E-6118-11DC-9C72-001320C79847}] [HKEY_CLASSES_ROOT\SWEETIE.SWEETIE] [HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "ISUSPM"="c:\program files\Common Files\InstallShield\UpdateService\ISUSPM.exe" [2007-08-30 205480] "ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-18 125952] "WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-18 202240] [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run] "NvCplDaemon"="c:\windows\system32\NvCpl.dll" [2009-02-09 13683232] "NvMediaCenter"="c:\windows\system32\NvMcTray.dll" [2009-02-09 92704] "Diamondback"="c:\program files\Razer\Diamondback 3G\razerhid.exe" [2007-08-01 147456] "avgnt"="c:\program files\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153] "RtHDVCpl"="RtHDVCpl.exe" - c:\windows\RtHDVCpl.exe [2007-12-13 4710400] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "EnableLUA"= 0 (0x0) "EnableUIADesktopToggle"= 0 (0x0) [HKLM\~\startupfolder\C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^HP Digital Imaging Monitor.lnk] path=c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\HP Digital Imaging Monitor.lnk backup=c:\windows\pss\HP Digital Imaging Monitor.lnk.CommonStartup backupExtension=.CommonStartup [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus] "DisableMonitoring"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall] "DisableMonitoring"=dword:00000001 [HKLM\~\services\sharedaccess\parameters\firewallpolicy\FirewallRules] "{0209C1EB-BEE2-42D5-824A-8F96C8B8FB66}"= UDP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{981582D9-84D6-401A-8333-F849B43EF022}"= TCP:c:\program files\Microsoft Office\Office12\ONENOTE.EXE:Microsoft Office OneNote "{7168CAD2-EDA5-4760-B7C5-D172F6D2F463}"= UDP:c:\program files\Warcraft III\Frozen Throne.exe:Warcraft III - The Frozen Throne "{B45A25CC-46A3-4E17-9229-7D1DF3FC5EB7}"= TCP:c:\program files\Warcraft III\Frozen Throne.exe:Warcraft III - The Frozen Throne "{903E5ED0-F469-46E1-BBD8-9987A8BD16E6}"= UDP:c:\program files\Warcraft III\Warcraft III.exe:Warcraft III "{770F760E-4416-4C4D-B122-FF42EE201C65}"= TCP:c:\program files\Warcraft III\Warcraft III.exe:Warcraft III "TCP Query User{502672C6-3C9F-4910-B8AB-8C10B3F3C470}c:\\program files\\warcraft iii\\war3.exe"= UDP:c:\program files\warcraft iii\war3.exe:Warcraft III "UDP Query User{783160AC-7616-4765-AA68-3FC6198D056C}c:\\program files\\warcraft iii\\war3.exe"= TCP:c:\program files\warcraft iii\war3.exe:Warcraft III "TCP Query User{E9AC9D13-7A3A-4667-98C6-F20B0233EA73}c:\\program files\\utorrent\\utorrent.exe"= UDP:c:\program files\utorrent\utorrent.exe:uTorrent "UDP Query User{79BB1CFA-1308-4F12-88F7-9381D14DA49C}c:\\program files\\utorrent\\utorrent.exe"= TCP:c:\program files\utorrent\utorrent.exe:uTorrent "{CCE7C36B-172F-4C09-94FD-8205E31CD9EF}"= UDP:c:\program files\KalOnlineEng\KalOnline.exe:KalOnline "{F0D56D46-4573-429B-BA1C-372D341AB254}"= TCP:c:\program files\KalOnlineEng\KalOnline.exe:KalOnline "{5DCD25B3-36E5-4593-B768-93BEC8D23299}"= c:\program files\Windows Live\Messenger\livecall.exe:Windows Live Messenger (Phone) "{B1B5526B-81F3-4717-B43F-783B78EF06E2}"= UDP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{C4250CFD-B2A1-455C-8635-77C580970467}"= TCP:c:\program files\Bonjour\mDNSResponder.exe:Bonjour "{A7E19DE2-CAF4-4191-BE9C-8AA23B10920D}"= UDP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager "{920FC360-1281-41FE-8E02-D908132D5BD7}"= TCP:c:\programdata\NexonUS\NGM\NGM.exe:Nexon Game Manager "{5D60376C-D259-4CBF-AAEF-8127EC898087}"= UDP:c:\program files\EA GAMES\Die Schlacht um Mittelerde(tm)\game.datie Schlacht um Mittelerde (tm) "{B129296A-85E7-4E73-B8BA-13F180C177FC}"= TCP:c:\program files\EA GAMES\Die Schlacht um Mittelerde(tm)\game.datie Schlacht um Mittelerde (tm) "{54B5772C-44E5-4FC5-AE6B-576F46CEAC30}"= UDP:c:\program files\Anno 1701\Anno1701.exe:Anno 1701 "{127BF77D-7984-4C61-9B29-AC9BBFA67F8C}"= TCP:c:\program files\Anno 1701\Anno1701.exe:Anno 1701 "{73387CB1-9A13-458F-9147-4AACE55090D3}"= UDP:c:\programdata\NexonEU\NGM\NGM.exe:Nexon Game Manager "{AF2A47B5-85BF-42C9-AD34-FE0887BD6831}"= TCP:c:\programdata\NexonEU\NGM\NGM.exe:Nexon Game Manager "{0F341A35-09C9-4FE7-86E1-446D50403311}"= UDP:c:\program files\Combat Arms EU\NMService.exe:Nexon Messenger Core "{1FD873DC-A4A2-443C-B815-A492C3720F78}"= TCP:c:\program files\Combat Arms EU\NMService.exe:Nexon Messenger Core "{76362B2A-86D2-47EA-BC59-2F812D9E1641}"= UDP:c:\program files\Hamachi\hamachi.exe:Hamachi "{94CDBE7C-75CC-43FE-9228-0045DC6A0DCC}"= TCP:c:\program files\Hamachi\hamachi.exe:Hamachi "{11097455-858D-49B1-9E1D-EFE3580E4E06}"= UDP:6112:Warcraft 3 "{A31F1B1A-3347-4182-B5B5-8FD70113BF1B}"= UDP:c:\program files\Electronic Arts\Die Schlacht um Mittelerde II\game.datie Schlacht um Mittelerde™ II "{DFBCCF8D-441E-4B05-804B-928DBBF53C26}"= TCP:c:\program files\Electronic Arts\Die Schlacht um Mittelerde II\game.datie Schlacht um Mittelerde™ II "{55B99994-13AA-4A1C-AB46-A2065ECFFC66}"= UDP:c:\users\Christopher\Downloads\utorrent-1.8.2.upx.exe:µTorrent (TCP-In) "{C1A16C7A-0F18-4609-8CC5-70653567F561}"= TCP:c:\users\Christopher\Downloads\utorrent-1.8.2.upx.exe:µTorrent (UDP-In) "TCP Query User{35D944C3-0A16-4CE4-852A-FA14238A4D7D}c:\\program files\\lucasarts\\star wars republic commando\\gamedata\\system\\swrepubliccommando.exe"= UDP:c:\program files\lucasarts\star wars republic commando\gamedata\system\swrepubliccommando.exe:SWRepublicCommando "UDP Query User{DC725E17-DF88-4158-817D-839826F1E697}c:\\program files\\lucasarts\\star wars republic commando\\gamedata\\system\\swrepubliccommando.exe"= TCP:c:\program files\lucasarts\star wars republic commando\gamedata\system\swrepubliccommando.exe:SWRepublicCommando "{69BBAEC1-7557-412C-8411-A970511CB0B8}"= UDP:c:\program files\gamigo\levelr\LevelR\LevelR.bin:LEVEL- "{992CB4AA-6147-4E5F-8D30-F52BC6F6FB53}"= TCP:c:\program files\gamigo\levelr\LevelR\LevelR.bin:LEVEL- "{88CC8670-3611-4FFF-BD7D-39EED605FA48}"= UDP:c:\program files\Sunflowers\ParaWorld\bin\PWServer.exe:ParaWorld Server "{098D56CC-53E4-4DBF-B2F5-B122091AAC41}"= TCP:c:\program files\Sunflowers\ParaWorld\bin\PWServer.exe:ParaWorld Server "{383100EE-015B-46FF-A79A-8119899F6C8B}"= UDP:c:\program files\Firefly Studios\Stronghold 2\Stronghold2.exe:Stronghold 2 "{1DC0F295-31C1-42FB-8326-13F00210BBC2}"= TCP:c:\program files\Firefly Studios\Stronghold 2\Stronghold2.exe:Stronghold 2 "{EF80FDD8-E576-4C71-8336-2EDC2571B46E}"= c:\program files\Skype\Phone\Skype.exe:Skype "{C5741607-E847-486A-A49C-B17D28B23D35}"= UDP:c:\users\Christopher\Downloads\utorrent.exe:µTorrent (TCP-In) "{264CCE17-3A75-4E0B-BD00-DA644775D075}"= TCP:c:\users\Christopher\Downloads\utorrent.exe:µTorrent (UDP-In) "{FB123311-4F78-452F-97D0-3201D18619DE}"= UDP:c:\program files\DNA\btdna.exeNA (TCP-In) "{AAA930F9-3906-4A03-A843-BF34A64588F5}"= TCP:c:\program files\DNA\btdna.exeNA (UDP-In) "{FFC98B26-81CE-481B-AEF4-85564B97ED03}"= UDP:c:\program files\Unechtes Turnier\Binaries\UT3.exe:Unreal Tournament 3 "{C17CAB19-D678-4C41-AB09-F10E9847CD9F}"= TCP:c:\program files\Unechtes Turnier\Binaries\UT3.exe:Unreal Tournament 3 "{28925910-40BE-4DB9-A120-1403EFC7550B}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main "{34ECB7B2-FBC9-4AD9-A08A-4241FC471100}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main.exe:Neverwinter Nights 2 Main "{2DE0C830-039F-409C-8AED-A884DC463E2D}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD "{A1E7526F-3BB0-4623-8274-1EF086D2C535}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2main_amdxp.exe:Neverwinter Nights 2 AMD "{7A9FFA39-F02C-42F8-AC48-4C837BEFD612}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater "{D3A46323-6870-4066-890F-E405A3C23BC8}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwupdate.exe:Neverwinter Nights 2 Updater "{DED357B9-FD3A-4E08-A69E-6FC424FB3751}"= UDP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server "{6A51C871-1A21-4BB6-87C0-68B519C80459}"= TCP:c:\program files\Atari\Neverwinter Nights 2\nwn2server.exe:Neverwinter Nights 2 Server "{E306C1C9-48AB-469C-A6C1-98B3509705DA}"= UDP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout(TM) Paradise The Ultimate Box "{53A0367B-3A1D-422C-B7B3-CA1F654B8902}"= TCP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutLauncher.exe:Burnout(TM) Paradise The Ultimate Box "{E3EBAB2E-DBAA-4187-83AF-EC0628CBBBA3}"= UDP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout(TM) Paradise The Ultimate Box "{F7EC7937-140A-49EF-BCD6-08544E9F809E}"= TCP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutConfigTool.exe:Burnout(TM) Paradise The Ultimate Box "{36F3976B-E8A3-46B5-B2FD-83FB1A6CD16C}"= UDP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:Burnout(TM) Paradise The Ultimate Box "{58690264-8D22-4AE8-AA50-5600EC979C75}"= TCP:c:\program files\Electronic Arts\Burnout(TM) Paradise The Ultimate Box\BurnoutParadise.exe:Burnout(TM) Paradise The Ultimate Box "TCP Query User{195B7CB4-9846-4B1B-858C-8460EACD6F97}c:\\program files\\tmnationsforever\\tmforever.exe"= UDP:c:\program files\tmnationsforever\tmforever.exe:TmForever "UDP Query User{D5CC90BC-F547-4124-A71E-E24218FC9274}c:\\program files\\tmnationsforever\\tmforever.exe"= TCP:c:\program files\tmnationsforever\tmforever.exe:TmForever R3 npggsvc;nProtect GameGuard Service;c:\windows\system32\GameMon.des [2009-02-17 2736890] R3 XDva092;XDva092; [x] R3 XDva190;XDva190; [x] R4 O2MDRDR;O2MDRDR;c:\windows\system32\drivers\o2media.sys [2005-08-05 34144] R4 O2SDRDR;O2SDRDR;c:\windows\system32\drivers\o2sd.sys [2005-12-19 28800] S2 AntiVirSchedulerService;Avira AntiVir Planer;c:\program files\Avira\AntiVir Desktop\sched.exe [2009-04-01 108289] S3 phaudlwr;Philips Audio Filter;c:\windows\system32\DRIVERS\phaudlwr.sys [2008-05-07 88704] S3 Razerlow;Diamondback 3G USB Filter Driver;c:\windows\system32\Drivers\DB3G.sys [2005-04-24 13225] S3 SPC520;Philips SPC520NC PC Camera;c:\windows\system32\drivers\SPC520.sys [2007-10-01 483328] S3 SPC520m;Philips SPC520NC PC Cameram;c:\windows\system32\drivers\SPC520m.sys [2007-10-01 7680] --- Andere Dienste/Treiber im Speicher --- *NewlyCreated* - AVGIO *NewlyCreated* - AVGNTFLT *NewlyCreated* - AVIPBB [HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\svchost] HPZ12 REG_MULTI_SZ Pml Driver HPZ12 Net Driver HPZ12 hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09afeb93-8d76-11dd-b7ef-001e8c906253}] \shell\AutoRun\command - K:\LaunchRC.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09afeb95-8d76-11dd-b7ef-001e8c906253}] \shell\AutoRun\command - L:\LaunchBFII.exe [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{09afeb97-8d76-11dd-b7ef-001e8c906253}] \shell\AutoRun\command - M:\autorun.exe -auto [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{c074acdd-4438-11dd-9024-806e6f6e6963}] \shell\AutoRun\command - E:\Start.exe [HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\{10880D85-AAD9-4558-ABDC-2AB1552D831F}] "c:\program files\Common Files\LightScribe\LSRunOnce.exe" . . ------- Zusätzlicher Suchlauf ------- . uInternet Settings,ProxyOverride = *.local IE: Nach Microsoft E&xel exportieren - c:\progra~1\MICROS~3\Office12\EXCEL.EXE/3000 DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://games.icq.com/online/online2/zuma/popcaploader_v6.cab FF - ProfilePath - c:\users\Christopher\AppData\Roaming\Mozilla\Firefox\Profiles\ud4o5gfb.default\ FF - prefs.js: browser.startup.homepage - www.google.de FF - component: c:\program files\Mozilla Firefox\extensions\{B13721C7-F507-4982-B2E5-502A71474FED}\components\NPComponent.dll FF - plugin: c:\programdata\NexonEU\NGM\npNxGameeu.dll FF - plugin: c:\programdata\NexonUS\NGM\npNxGameUS.dll . ************************************************************************** catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net Rootkit scan 2009-05-04 20:29 Windows 6.0.6001 Service Pack 1 NTFS Scanne versteckte Prozesse... Scanne versteckte Autostarteinträge... Scanne versteckte Dateien... c:\users\CHRIST~1\AppData\Local\Temp\catchme.dll 53248 bytes executable Scan erfolgreich abgeschlossen versteckte Dateien: 1 ************************************************************************** [HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\npggsvc] "ImagePath"="c:\windows\system32\GameMon.des -service" . --------------------- Gesperrte Registrierungsschluessel --------------------- [HKEY_USERS\S-1-5-21-759913723-362470790-2232644708-1000\Software\SecuROM\!CAUTION! NEVER A OR CHANGE ANY KEY*] "??"=hex:2d,fb,54,94,2b,97,59,32,ed,06,4d,31,92,4a,9d,2a,30,e4,80,2d,44,a2,7f, de,98,d0,06,44,f5,b3,83,3b,dd,20,a8,23,41,40,1a,03,1a,ee,0b,b4,38,70,90,dc,\ "??"=hex:35,fc,c6,3d,c9,02,ad,db,37,1f,61,de,0f,33,8f,50 [HKEY_USERS\S-1-5-21-759913723-362470790-2232644708-1000\Software\SecuROM\License information*] "datasecu"=hex:41,4c,f4,29,d1,92,15,fe,82,71,c5,d5,a8,ed,2f,28,16,4e,32,03,c9, fb,20,26,41,a3,24,3e,6b,8e,c6,1e,fe,b8,0d,26,be,ea,73,a2,50,13,c0,ad,50,7c,\ "rkeysecu"=hex:ae,1f,71,ba,90,aa,7c,d2,dd,49,4d,96,2e,c0,e8,08 . --------------------- Durch laufende Prozesse gestartete DLLs --------------------- - - - - - - - > 'Explorer.exe'(888) c:\program files\ArcSoft\Software Suite\PhotoImpression\share\pihook.dll . Zeit der Fertigstellung: 2009-05-04 20:30 ComboFix-quarantined-files.txt 2009-05-04 18:30 ComboFix2.txt 2009-05-04 15:04 Vor Suchlauf: 25 Verzeichnis(se), 117.885.911.040 Bytes frei Nach Suchlauf: 25 Verzeichnis(se), 117.856.190.464 Bytes frei 336 --- E O F --- 2009-05-01 14:32[code] |
04.05.2009, 22:25 | #21 |
/// TB-Ausbilder | Firefox leitet mich auf andere Seiten um! Hi, das sieht gut aus Du kannst dann Combofix deinstallieren, wenn keine Probleme mehr existieren. Einfach combofix /u unter Start->ausführen eingeben. lg myrtille
__________________ --> Firefox leitet mich auf andere Seiten um! |
05.05.2009, 13:13 | #22 |
| Firefox leitet mich auf andere Seiten um! Viiellen Dank myrtille,du hast mir sehr geholfen! Das Forum kann ich nur empfehlen! -CLOSED- |
Themen zu Firefox leitet mich auf andere Seiten um! |
adobe, ashampoo uninstaller, bho, browser, defender, explorer, firefox, google, hijack, hijackthis, hängen, internet, internet explorer, intrusion prevention, log-file, logfile, malwarebytes' anti-malware, mozilla, object, plug-in, rundll, seiten, senden, software, sweetim, symantec, system, toolbars, trojaner-board, umleiten, vista, windows, windows sidebar |