![]() |
|
Plagegeister aller Art und deren Bekämpfung: Kann mit keinem browser googlemail öffnen - 404 Not FoundWindows 7 Wenn Du nicht sicher bist, ob Du dir Malware oder Trojaner eingefangen hast, erstelle hier ein Thema. Ein Experte wird sich mit weiteren Anweisungen melden und Dir helfen die Malware zu entfernen oder Unerwünschte Software zu deinstallieren bzw. zu löschen. Bitte schildere dein Problem so genau wie möglich. Sollte es ein Trojaner oder Viren Problem sein wird ein Experte Dir bei der Beseitigug der Infektion helfen. |
![]() | #1 |
![]() | ![]() Kann mit keinem browser googlemail öffnen - 404 Not Found Hallo zusammen, ich kann unabhängig vom verwendeten Browser (firefox, opera, explorer) googlemail nicht laden. Die Fehlermeldung ist die Folgende: 404 Not Found The requested URL /mail/ was not found on this server. Apache/2.2.12 (Ubuntu) Server at mail.google.com Port 80 Scheint mir ein Virus/Malware-Problem zu sein, denn das Problem persistiert auch nach dem Löschen von Cache & Cookies aller Browser, und nach dem Scannen mit den gängigen Programmen. Demnach liste ich hier die Funde auf. Gescannt ist das System einmal mit Avira Antivir und einmal mit Spybot Search & Destroy. Antivir Detections (=> Gelöscht/Quarantäne) TR/Crypt.XPACK.Gen Trojan TR/Crypt.ZPACK.Gen Trojan TR/Crypt.XPACK.Gen Trojan JAVA/MundGura.D Java virus JAVA/Exdoer.BE.2 Java virus JAVA/Rast.A Java virus ADSPY/AdSpy.Gen2 adware or spyware TR/Vilsel.ayjv Trojan Spybot Detections: 04.05.2011 22:44:22 - found: Fraud.HDDDefragmenter Link 04.05.2011 22:44:22 - found: Fraud.HDDDefragmenter Link 04.05.2011 22:46:59 - found: Microsoft.WindowsSecurityCenter.AntiVirusOverride Settings 04.05.2011 22:58:40 - found: DoubleClick Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:40 - found: Tradedoubler Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:40 - found: Tradedoubler Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:40 - found: Tradedoubler Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:40 - found: MediaPlex Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:40 - found: MediaPlex Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:40 - found: MediaPlex Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: FastClick Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: FastClick Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Statcounter Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: MediaPlex Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: MediaPlex Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: MediaPlex Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: MediaPlex Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: WebTrends live Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: FastClick Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Adviva Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: DoubleClick Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: MediaPlex Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: MediaPlex Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: MediaPlex Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Statcounter Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Tradedoubler Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Tradedoubler Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: HitsLink Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: FastClick Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: FastClick Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Tradedoubler Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Zedo Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Zedo Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Zedo Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Zedo Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Zedo Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Zedo Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: Zedo Tracking cookie (Firefox: *** (default)) 04.05.2011 22:58:41 - found: DoubleClick Tracking cookie (Chrome: Chrome) 04.05.2011 22:58:41 - found: MediaPlex Tracking cookie (Chrome: Chrome) 04.05.2011 22:58:41 - found: MediaPlex Tracking cookie (Chrome: Chrome) 04.05.2011 22:58:41 - found: MediaPlex Tracking cookie (Chrome: Chrome) Hier folgt nur der LOG-File:OTL Logfile: Code:
ATTFilter OTL logfile created on: 5.5.2011 13:23:28 - Run 1 OTL by OldTimer - Version 3.2.22.3 Folder = C:\Documents and Settings\***\Desktop Windows XP Professional Edition Service Pack 2 (Version = 5.1.2600) - Type = NTWorkstation Internet Explorer (Version = 6.0.2900.2180) Locale: 0000041A | Country: *** | Language: HRV | Date Format: d.M.yyyy 2,00 Gb Total Physical Memory | 1,00 Gb Available Physical Memory | 60,00% Memory free 4,00 Gb Paging File | 3,00 Gb Available in Paging File | 85,00% Paging File free Paging file location(s): c:\pagefile.sys 2046 4092 [binary data] %SystemDrive% = C: | %SystemRoot% = C:\WINDOWS | %ProgramFiles% = C:\Program Files Drive C: | 232,88 Gb Total Space | 151,08 Gb Free Space | 64,88% Space Free | Partition Type: NTFS Computer Name: R2D2 | User Name: *** | Logged in as Administrator. Boot Mode: Normal | Scan Mode: Current user Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days ========== Processes (SafeList) ========== PRC - C:\Documents and Settings\***\Desktop\OTL.exe (OldTimer Tools) PRC - C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation) PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWTray.exe (Lavasoft Limited) PRC - C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited) PRC - C:\Program Files\Avira\AntiVir Desktop\avshadow.exe (Avira GmbH) PRC - C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) PRC - C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) PRC - C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) PRC - C:\Program Files\DivX\DivX Plus Web Player\DDMService.exe (DivX, LLC) PRC - C:\Program Files\DivX\DivX Update\DivXUpdate.exe () PRC - C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.) PRC - C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.) PRC - C:\Documents and Settings\***\Local Settings\Temp\{29A1889A-AC4C-461A-B5AB-1D459ECA1EBF}\{061A431C-86E7-4DB4-92B8-36DE783865CF}\STK2135\Win2KXP\stk2135bsrv.exe () PRC - C:\WINDOWS\system32\acs.exe (Atheros) PRC - C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) PRC - C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel(R) Corporation) PRC - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation) PRC - C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.) PRC - C:\Program Files\ThinkPad\Bluetooth Software\BTStackServer.exe (Broadcom Corporation.) PRC - C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.) PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone) PRC - C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone) PRC - C:\WINDOWS\explorer.exe (Microsoft Corporation) ========== Modules (SafeList) ========== MOD - C:\Documents and Settings\***\Desktop\OTL.exe (OldTimer Tools) MOD - C:\WINDOWS\system32\BtMmHook.dll (Broadcom Corporation.) MOD - C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03\comctl32.dll (Microsoft Corporation) ========== Win32 Services (SafeList) ========== SRV - (Lavasoft Ad-Aware Service) -- C:\Program Files\Lavasoft\Ad-Aware\AAWService.exe (Lavasoft Limited) SRV - (AntiVirSchedulerService) -- C:\Program Files\Avira\AntiVir Desktop\sched.exe (Avira GmbH) SRV - (AntiVirService) -- C:\Program Files\Avira\AntiVir Desktop\avguard.exe (Avira GmbH) SRV - (FLEXnet Licensing Service) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Macrovision Europe Ltd.) SRV - (vpnagent) -- C:\Program Files\Cisco\Cisco AnyConnect VPN Client\vpnagent.exe (Cisco Systems, Inc.) SRV - (XYNTService) -- C:\Documents and Settings\***\Local Settings\Temp\{29A1889A-AC4C-461A-B5AB-1D459ECA1EBF}\{061A431C-86E7-4DB4-92B8-36DE783865CF}\STK2135\Win2KXP\stk2135bsrv.exe () SRV - (acs) -- C:\WINDOWS\system32\acs.exe (Atheros) SRV - (EvtEng) Intel(R) -- C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel(R) Corporation) SRV - (S24EventMonitor) Intel(R) -- C:\Program Files\Intel\WiFi\bin\S24EvMon.exe (Intel(R) Corporation) SRV - (RegSrvc) Intel(R) -- C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel(R) Corporation) SRV - (btwdins) -- C:\Program Files\ThinkPad\Bluetooth Software\bin\btwdins.exe (Broadcom Corporation.) SRV - (VMCService) -- C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\VMCService.exe (Vodafone) SRV - (WMConnectCDS) -- C:\Program Files\Windows Media Connect 2\wmccds.exe (Microsoft Corporation) ========== Driver Services (SafeList) ========== DRV - (Lbd) -- C:\WINDOWS\system32\DRIVERS\Lbd.sys (Lavasoft AB) DRV - (Lavasoft Kernexplorer) -- C:\Program Files\Lavasoft\Ad-Aware\kernexplorer.sys () DRV - (avipbb) -- C:\WINDOWS\system32\drivers\avipbb.sys (Avira GmbH) DRV - (avgntflt) -- C:\WINDOWS\system32\drivers\avgntflt.sys (Avira GmbH) DRV - (ssmdrv) -- C:\WINDOWS\system32\drivers\ssmdrv.sys (Avira GmbH) DRV - (avgio) -- C:\Program Files\Avira\AntiVir Desktop\avgio.sys (Avira GmbH) DRV - (vpnva) -- C:\WINDOWS\system32\drivers\vpnva.sys (Cisco Systems, Inc.) DRV - (SCDEmu) -- C:\WINDOWS\System32\drivers\scdemu.sys (PowerISO Computing, Inc.) DRV - (NETw5x32) Intel(R) -- C:\WINDOWS\system32\drivers\NETw5x32.sys (Intel Corporation) DRV - (BTWDNDIS) -- C:\WINDOWS\system32\drivers\btwdndis.sys (Broadcom Corporation.) DRV - (BTWUSB) -- C:\WINDOWS\system32\drivers\btwusb.sys (Broadcom Corporation.) DRV - (BTDriver) -- C:\WINDOWS\system32\drivers\btport.sys (Broadcom Corporation.) DRV - (btwmodem) -- C:\WINDOWS\system32\drivers\btwmodem.sys (Broadcom Corporation.) DRV - (BTKRNL) -- C:\WINDOWS\system32\drivers\btkrnl.sys (Broadcom Corporation.) DRV - (btaudio) -- C:\WINDOWS\system32\drivers\btaudio.sys (Broadcom Corporation.) DRV - (s24trans) -- C:\WINDOWS\system32\drivers\s24trans.sys (Intel Corporation) DRV - (DCamUSBGene) -- C:\WINDOWS\system32\drivers\USBSTK.sys () DRV - (CnxtHdAudService) -- C:\WINDOWS\system32\drivers\CHDAU32.sys (Conexant Systems Inc.) DRV - (IntcHdmiAddService) Intel(R) -- C:\WINDOWS\system32\drivers\IntcHdmi.sys (Intel(R) Corporation) DRV - (HSF_DPV) -- C:\WINDOWS\system32\drivers\HSF_DPV.sys (Conexant Systems, Inc.) DRV - (HSFHWAZL) -- C:\WINDOWS\system32\drivers\HSFHWAZL.sys (Conexant Systems, Inc.) DRV - (winachsf) -- C:\WINDOWS\system32\drivers\HSF_CNXT.sys (Conexant Systems, Inc.) DRV - (hwdatacard) -- C:\WINDOWS\system32\drivers\ewusbmdm.sys (Huawei Technologies Co., Ltd.) DRV - (rimmptsk) -- C:\WINDOWS\system32\drivers\rimmptsk.sys (REDC) DRV - (WSIMD) -- C:\WINDOWS\system32\drivers\wsimd.sys (Atheros Communications, Inc.) DRV - (RTLE8023xp) -- C:\WINDOWS\system32\drivers\Rtenicxp.sys (Realtek Semiconductor Corporation ) DRV - (rismxdp) -- C:\WINDOWS\system32\drivers\rixdptsk.sys (REDC) DRV - (rimsptsk) -- C:\WINDOWS\system32\drivers\rimsptsk.sys (REDC) ========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = hxxp://www.google.hr/ IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0 ========== FireFox ========== FF - prefs.js..browser.startup.homepage: "google.de" FF - prefs.js..extensions.enabledItems: jqs@sun.com:1.0 FF - prefs.js..extensions.enabledItems: {AB2CE124-6272-4b12-94A9-7303C7397BD1}:5.0.0.6906 FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.0.900 FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.0.900 FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24 FF - HKLM\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files\DivX\DivX Plus Web Player\firefox\html5video [2010.12.25 00:16:29 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Firefox\Extensions\\{6904342A-8307-11DF-A508-4AE2DFD72085}: C:\Program Files\DivX\DivX Plus Web Player\firefox\wpa [2010.12.25 00:16:29 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2011.05.04 22:46:34 | 000,000,000 | ---D | M] FF - HKLM\software\mozilla\Mozilla Firefox 3.6.17\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2011.05.04 22:46:32 | 000,000,000 | ---D | M] [2010.06.01 18:18:40 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Extensions [2011.05.05 12:53:46 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\wd2x791w.default\extensions [2010.07.25 20:31:16 | 000,000,000 | ---D | M] (Microsoft .NET Framework Assistant) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\wd2x791w.default\extensions\{20a82645-c095-46ed-80e3-08825760534b} [2010.07.10 23:29:16 | 000,000,000 | ---D | M] (No name found) -- C:\Documents and Settings\***\Application Data\Mozilla\Firefox\Profiles\wd2x791w.default\extensions\{ba14329e-9550-4989-b3f2-9732e92d17cc} [2011.05.05 12:53:47 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files\Mozilla Firefox\extensions [2011.02.18 14:02:07 | 000,000,000 | ---D | M] (Skype extension) -- C:\Program Files\Mozilla Firefox\extensions\{AB2CE124-6272-4b12-94A9-7303C7397BD1} [2011.05.05 12:25:50 | 000,000,000 | ---D | M] (Java Console) -- C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} [2010.12.25 00:16:29 | 000,000,000 | ---D | M] (DivX Plus Web Player HTML5 <video>) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\HTML5VIDEO [2010.12.25 00:16:29 | 000,000,000 | ---D | M] (DivX HiQ) -- C:\PROGRAM FILES\DIVX\DIVX PLUS WEB PLAYER\FIREFOX\WPA [2010.07.07 11:40:31 | 000,000,000 | ---D | M] (Java Quick Starter) -- C:\PROGRAM FILES\JAVA\JRE6\LIB\DEPLOY\JQS\FF [2011.02.02 21:40:24 | 000,472,808 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npdeployJava1.dll [2010.06.29 06:01:22 | 000,012,800 | ---- | M] (Nullsoft, Inc.) -- C:\Program Files\Mozilla Firefox\plugins\npwachk.dll O1 HOSTS File: ([2011.01.07 11:34:20 | 000,000,984 | ---- | M]) - C:\WINDOWS\system32\drivers\etc\hosts O1 - Hosts: 127.0.0.1 localhost O1 - Hosts: 213.175.216.204 google.com www.google.com O1 - Hosts: 213.175.216.205 mail.google.com O2 - BHO: (DivX Plus Web Player HTML5 <video>) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (DivX HiQ) - {593DDEC6-7468-4cdd-90E1-42DADAA222E9} - C:\Program Files\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC) O2 - BHO: (Skype Plug-In) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {EE2AC4E5-B0B0-4EC6-88A9-BCA1A32AB107} - No CLSID value found. O4 - HKLM..\Run: [avgnt] C:\Program Files\Avira\AntiVir Desktop\avgnt.exe (Avira GmbH) O4 - HKLM..\Run: [DivX Download Manager] C:\Program Files\DivX\DivX Plus Web Player\DDmService.exe (DivX, LLC) O4 - HKLM..\Run: [DivXUpdate] C:\Program Files\DivX\DivX Update\DivXUpdate.exe () O4 - HKLM..\Run: [MobileConnect] C:\Program Files\Vodafone\Vodafone Mobile Connect\Bin\MobileConnect.exe (Vodafone) O4 - HKLM..\Run: [WinampAgent] C:\Program Files\Winamp\winampa.exe (Nullsoft, Inc.) O4 - HKCU..\Run: [mscj2] File not found O4 - Startup: C:\Documents and Settings\All Users\Start Menu\Programs\Startup\Bluetooth.lnk = C:\Program Files\ThinkPad\Bluetooth Software\BTTray.exe (Broadcom Corporation.) O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HonorAutoRunSetting = 1 O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145 O8 - Extra context menu item: Send to &Bluetooth Device... - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm () O8 - Extra context menu item: Send To Bluetooth - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm () O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O9 - Extra Button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm () O9 - Extra 'Tools' menuitem : @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\ThinkPad\Bluetooth Software\btsendto_ie.htm () O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab (Java Plug-in 1.6.0_24) O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} hxxp://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab (Shockwave Flash Object) O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1 O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll (Skype Technologies) O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.) O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\WINDOWS\explorer.exe (Microsoft Corporation) O24 - Desktop WallPaper: C:\Documents and Settings\***\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O24 - Desktop BackupWallPaper: C:\Documents and Settings\***\Local Settings\Application Data\Microsoft\Wallpaper1.bmp O32 - HKLM CDRom: AutoRun - 1 O32 - AutoRun File - [2010.05.20 21:57:41 | 000,000,000 | ---- | M] () - C:\AUTOEXEC.BAT -- [ NTFS ] O33 - MountPoints2\{8999d418-6756-11df-87cf-001fe2e62a20}\Shell - "" = AutoRun O33 - MountPoints2\{8999d418-6756-11df-87cf-001fe2e62a20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{8999d418-6756-11df-87cf-001fe2e62a20}\Shell\AutoRun\command - "" = F:\setup.exe O33 - MountPoints2\{a9e3bd4c-6463-11df-87c4-0016ead7c7d4}\Shell - "" = AutoRun O33 - MountPoints2\{a9e3bd4c-6463-11df-87c4-0016ead7c7d4}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{a9e3bd4c-6463-11df-87c4-0016ead7c7d4}\Shell\AutoRun\command - "" = E:\autorun.exe O33 - MountPoints2\{b444c885-682f-11df-87d1-001fe2e62a20}\Shell - "" = AutoRun O33 - MountPoints2\{b444c885-682f-11df-87d1-001fe2e62a20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{b444c885-682f-11df-87d1-001fe2e62a20}\Shell\AutoRun\command - "" = E:\setup.exe O33 - MountPoints2\{b444c886-682f-11df-87d1-001fe2e62a20}\Shell - "" = AutoRun O33 - MountPoints2\{b444c886-682f-11df-87d1-001fe2e62a20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{b444c886-682f-11df-87d1-001fe2e62a20}\Shell\AutoRun\command - "" = E:\setup.exe O33 - MountPoints2\{c3f7577f-2332-11e0-890d-001fe2e62a20}\Shell - "" = AutoRun O33 - MountPoints2\{c3f7577f-2332-11e0-890d-001fe2e62a20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{c3f7577f-2332-11e0-890d-001fe2e62a20}\Shell\AutoRun\command - "" = E:\setup.exe O33 - MountPoints2\{f83ba03f-828c-11df-8819-001fe2e62a20}\Shell - "" = AutoRun O33 - MountPoints2\{f83ba03f-828c-11df-8819-001fe2e62a20}\Shell\AutoRun - "" = Auto&Play O33 - MountPoints2\{f83ba03f-828c-11df-8819-001fe2e62a20}\Shell\AutoRun\command - "" = E:\setup.exe O34 - HKLM BootExecute: (autocheck autochk *) - File not found O34 - HKLM BootExecute: (lsdelete) - C:\WINDOWS\System32\lsdelete.exe () O35 - HKLM\..comfile [open] -- "%1" %* O35 - HKLM\..exefile [open] -- "%1" %* O37 - HKLM\...com [@ = comfile] -- "%1" %* O37 - HKLM\...exe [@ = exefile] -- "%1" %* ========== Files/Folders - Created Within 30 Days ========== [2011.05.05 13:21:53 | 000,580,608 | ---- | C] (OldTimer Tools) -- C:\Documents and Settings\***\Desktop\OTL.exe [2011.05.05 12:26:13 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java [2011.05.05 12:25:48 | 000,157,472 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaws.exe [2011.05.05 12:25:48 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\javaw.exe [2011.05.05 12:25:48 | 000,145,184 | ---- | C] (Sun Microsystems, Inc.) -- C:\WINDOWS\System32\java.exe [2011.05.05 08:07:55 | 000,000,000 | ---D | C] -- C:\WINDOWS\Internet Logs [2011.05.04 23:04:59 | 000,000,000 | ---D | C] -- C:\Program Files\MSXML 6.0 [2011.05.04 22:38:13 | 000,000,000 | ---D | C] -- C:\Documents and Settings\LocalService\Application Data\Adobe [2011.05.04 22:13:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\Local Settings\Application Data\Opera [2011.05.04 22:13:05 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\Application Data\Opera [2011.05.04 22:12:49 | 000,000,000 | ---D | C] -- C:\Program Files\Opera [2011.05.04 22:04:17 | 000,098,392 | ---- | C] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys [2011.05.04 21:44:26 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Spybot - Search & Destroy [2011.05.04 21:44:18 | 000,000,000 | ---D | C] -- C:\Program Files\Spybot - Search & Destroy [2011.05.04 21:44:18 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy [2011.05.04 21:41:52 | 000,064,512 | ---- | C] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys [2011.05.04 21:41:38 | 000,000,000 | ---D | C] -- C:\Program Files\Lavasoft [2011.05.04 21:41:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Lavasoft [2011.05.04 21:41:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Lavasoft [2011.05.04 20:26:28 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\Application Data\Avira [2011.05.04 20:21:11 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Start Menu\Programs\Avira [2011.05.04 20:20:48 | 000,028,520 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\ssmdrv.sys [2011.05.04 20:20:40 | 000,137,656 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avipbb.sys [2011.05.04 20:20:40 | 000,061,960 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntflt.sys [2011.05.04 20:20:40 | 000,022,360 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntmgr.sys [2011.05.04 20:20:39 | 000,045,416 | ---- | C] (Avira GmbH) -- C:\WINDOWS\System32\drivers\avgntdd.sys [2011.05.04 20:20:38 | 000,000,000 | ---D | C] -- C:\Program Files\Avira [2011.05.04 20:20:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\All Users\Application Data\Avira [2011.05.03 20:55:07 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\Application Data\AntiVirus_AntiSpyware_2011 [2011.05.03 20:54:38 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\Application Data\1561484 [2011.04.13 09:26:30 | 000,000,000 | ---D | C] -- C:\Documents and Settings\***\My Documents\DW1 [9 C:\Documents and Settings\***\Desktop\*.tmp files -> C:\Documents and Settings\***\Desktop\*.tmp -> ] [6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\Documents and Settings\***\My Documents\*.tmp files -> C:\Documents and Settings\***\My Documents\*.tmp -> ] ========== Files - Modified Within 30 Days ========== [2011.05.05 13:21:54 | 000,580,608 | ---- | M] (OldTimer Tools) -- C:\Documents and Settings\***\Desktop\OTL.exe [2011.05.05 12:50:19 | 000,000,486 | ---- | M] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2011.05.05 12:49:42 | 000,002,048 | --S- | M] () -- C:\WINDOWS\bootstat.dat [2011.05.05 12:34:00 | 000,001,024 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-117609710-1993962763-839522115-1003UA.job [2011.05.05 08:34:00 | 000,000,972 | ---- | M] () -- C:\WINDOWS\tasks\GoogleUpdateTaskUserS-1-5-21-117609710-1993962763-839522115-1003Core.job [2011.05.04 22:13:00 | 000,001,510 | ---- | M] () -- C:\Documents and Settings\***\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk [2011.05.04 22:06:36 | 000,000,745 | ---- | M] () -- C:\Documents and Settings\***\Desktop\Shortcut to IEXPLORE.lnk [2011.05.04 22:04:16 | 000,098,392 | ---- | M] (Sunbelt Software) -- C:\WINDOWS\System32\drivers\SBREDrv.sys [2011.05.04 22:04:14 | 000,016,432 | ---- | M] () -- C:\WINDOWS\System32\lsdelete.exe [2011.05.04 21:42:06 | 000,000,797 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk [2011.05.04 20:21:11 | 000,001,707 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk [2011.05.04 18:32:45 | 000,002,271 | ---- | M] () -- C:\Documents and Settings\***\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk [2011.05.04 18:32:44 | 000,002,293 | ---- | M] () -- C:\Documents and Settings\***\Desktop\Google Chrome.lnk [2011.05.03 20:55:14 | 000,001,932 | ---- | M] () -- C:\Documents and Settings\***\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiVirus_AntiSpyware_2011.lnk [2011.05.02 16:29:35 | 000,000,476 | -H-- | M] () -- C:\WINDOWS\tasks\Norton Security Scan for ***.job [2011.04.29 21:57:42 | 000,032,256 | ---- | M] () -- C:\Documents and Settings\***\Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2011.04.29 12:12:00 | 000,064,512 | ---- | M] (Lavasoft AB) -- C:\WINDOWS\System32\drivers\Lbd.sys [2011.04.27 21:30:31 | 000,435,828 | ---- | M] () -- C:\WINDOWS\System32\perfh009.dat [2011.04.27 21:30:31 | 000,068,558 | ---- | M] () -- C:\WINDOWS\System32\perfc009.dat [2011.04.26 12:05:43 | 000,084,355 | ---- | M] () -- C:\Documents and Settings\***\Desktop\plakat.pdf [2011.04.26 08:30:16 | 000,002,206 | ---- | M] () -- C:\WINDOWS\System32\wpa.dbl [2011.04.21 08:38:46 | 000,002,265 | ---- | M] () -- C:\Documents and Settings\All Users\Desktop\Skype.lnk [2011.04.20 10:19:43 | 000,714,426 | ---- | M] () -- C:\Documents and Settings\***\Desktop\rjesenja.pdf [2011.04.19 12:08:54 | 000,211,820 | ---- | M] () -- C:\Documents and Settings\***\My Documents\Elektricna ograda.pdf [2011.04.14 12:05:39 | 000,714,426 | ---- | M] () -- C:\Documents and Settings\*** \My Documents\rjesenja.pdf [9 C:\Documents and Settings\***\Desktop\*.tmp files -> C:\Documents and Settings\***\Desktop\*.tmp -> ] [6 C:\WINDOWS\System32\*.tmp files -> C:\WINDOWS\System32\*.tmp -> ] [3 C:\WINDOWS\*.tmp files -> C:\WINDOWS\*.tmp -> ] [1 C:\Documents and Settings\***\My Documents\*.tmp files -> C:\Documents and Settings\***\My Documents\*.tmp -> ] ========== Files Created - No Company Name ========== [2011.05.05 12:09:06 | 000,016,432 | ---- | C] () -- C:\WINDOWS\System32\lsdelete.exe [2011.05.04 22:13:00 | 000,001,510 | ---- | C] () -- C:\Documents and Settings\***\Application Data\Microsoft\Internet Explorer\Quick Launch\Opera.lnk [2011.05.04 22:13:00 | 000,001,498 | ---- | C] () -- C:\Documents and Settings\All Users\Start Menu\Programs\Opera.lnk [2011.05.04 22:06:36 | 000,000,745 | ---- | C] () -- C:\Documents and Settings\***\Desktop\Shortcut to IEXPLORE.lnk [2011.05.04 21:42:13 | 000,000,486 | ---- | C] () -- C:\WINDOWS\tasks\Ad-Aware Update (Weekly).job [2011.05.04 21:42:06 | 000,000,797 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Ad-Aware.lnk [2011.05.04 20:21:11 | 000,001,707 | ---- | C] () -- C:\Documents and Settings\All Users\Desktop\Avira AntiVir Control Center.lnk [2011.05.03 20:55:13 | 000,001,932 | ---- | C] () -- C:\Documents and Settings\***\Application Data\Microsoft\Internet Explorer\Quick Launch\AntiVirus_AntiSpyware_2011.lnk [2011.04.26 12:05:43 | 000,084,355 | ---- | C] () -- C:\Documents and Settings\***\Desktop\plakat.pdf [2011.04.20 10:19:43 | 000,714,426 | ---- | C] () -- C:\Documents and Settings\***\Desktop\rjesenja.pdf [2011.04.19 12:08:54 | 000,211,820 | ---- | C] () -- C:\Documents and Settings\***\My Documents\Elektricna ograda.pdf [2011.04.14 12:05:39 | 000,714,426 | ---- | C] () -- C:\Documents and Settings\***\My Documents\rjesenja.pdf [2011.01.27 10:59:28 | 020,268,251 | ---- | C] () -- C:\Program Files\vlc-1.1.6-win32.exe [2011.01.07 10:52:44 | 000,004,569 | ---- | C] () -- C:\WINDOWS\System32\secupd.dat [2011.01.07 10:52:35 | 000,272,128 | ---- | C] () -- C:\WINDOWS\System32\perfi009.dat [2011.01.07 10:52:34 | 000,028,626 | ---- | C] () -- C:\WINDOWS\System32\perfd009.dat [2011.01.07 10:52:30 | 013,107,200 | ---- | C] () -- C:\WINDOWS\System32\oembios.bin [2011.01.07 10:52:30 | 000,004,463 | ---- | C] () -- C:\WINDOWS\System32\oembios.dat [2011.01.07 10:52:03 | 000,673,088 | ---- | C] () -- C:\WINDOWS\System32\mlang.dat [2011.01.07 10:52:01 | 000,046,258 | ---- | C] () -- C:\WINDOWS\System32\mib.bin [2011.01.07 10:51:38 | 000,218,003 | ---- | C] () -- C:\WINDOWS\System32\dssec.dat [2011.01.07 10:51:23 | 000,001,788 | ---- | C] () -- C:\WINDOWS\System32\Dcache.bin [2011.01.05 16:40:25 | 000,004,212 | -H-- | C] () -- C:\WINDOWS\System32\zllictbl.dat [2011.01.04 22:12:24 | 000,000,218 | ---- | C] () -- C:\WINDOWS\System32\MRT.INI [2010.12.20 22:46:56 | 000,000,056 | -H-- | C] () -- C:\WINDOWS\System32\ezsidmv.dat [2010.09.10 13:49:13 | 000,007,680 | ---- | C] () -- C:\WINDOWS\System32\CNMVS5y.DLL [2010.06.01 18:16:21 | 000,000,000 | ---- | C] () -- C:\WINDOWS\nsreg.dat [2010.05.22 09:27:57 | 000,032,256 | ---- | C] () -- C:\Documents and Settings\*** \Local Settings\Application Data\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini [2010.05.21 01:21:23 | 000,116,224 | ---- | C] () -- C:\WINDOWS\System32\pdfcmnnt.dll [2010.05.21 00:57:27 | 000,262,216 | ---- | C] () -- C:\WINDOWS\System32\IPTests.dll [2010.05.21 00:57:26 | 000,651,264 | ---- | C] () -- C:\WINDOWS\System32\libeay32.dll [2010.05.21 00:57:26 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\ssleay32.dll [2010.05.21 00:51:58 | 001,991,464 | ---- | C] () -- C:\WINDOWS\System32\igkrng500.bin [2010.05.21 00:51:52 | 000,147,456 | ---- | C] () -- C:\WINDOWS\System32\igfxCoIn_v4953.dll [2010.05.21 00:51:51 | 000,432,400 | ---- | C] () -- C:\WINDOWS\System32\igcompkrng500.bin [2010.05.21 00:42:07 | 000,086,016 | ---- | C] () -- C:\WINDOWS\stk2135bsrv.exe [2010.05.21 00:41:44 | 000,522,256 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBSTK1.sys [2010.05.21 00:41:44 | 000,299,920 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBSTK0.sys [2010.05.21 00:41:44 | 000,173,584 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBSTK.sys [2010.05.21 00:41:44 | 000,145,424 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBSTK2.sys [2010.05.21 00:41:44 | 000,025,616 | ---- | C] () -- C:\WINDOWS\System32\drivers\USBSTK3.sys [2010.05.21 00:41:43 | 000,055,824 | ---- | C] () -- C:\WINDOWS\CamUnist.exe [2010.05.20 22:02:42 | 000,002,048 | --S- | C] () -- C:\WINDOWS\bootstat.dat [2010.05.20 21:53:59 | 000,022,720 | ---- | C] () -- C:\WINDOWS\System32\emptyregdb.dat [2010.05.20 14:43:21 | 000,004,161 | ---- | C] () -- C:\WINDOWS\ODBCINST.INI [2010.05.20 14:41:46 | 000,283,720 | ---- | C] () -- C:\WINDOWS\System32\FNTCACHE.DAT [2009.02.09 18:48:24 | 002,854,976 | ---- | C] () -- C:\WINDOWS\System32\btwicons.dll [2008.03.07 17:43:56 | 000,084,734 | R--- | C] () -- C:\Documents and Settings\All Users\Application Data\DeviceManager.xml.rc4 [2008.03.07 14:47:30 | 000,020,270 | ---- | C] () -- C:\Documents and Settings\All Users\Application Data\DeviceInstaller.xml [2002.12.31 14:00:00 | 000,435,828 | ---- | C] () -- C:\WINDOWS\System32\perfh009.dat [2002.12.31 14:00:00 | 000,068,558 | ---- | C] () -- C:\WINDOWS\System32\perfc009.dat [2002.12.31 14:00:00 | 000,000,741 | ---- | C] () -- C:\WINDOWS\System32\noise.dat [2001.11.14 13:56:00 | 001,802,240 | ---- | C] () -- C:\WINDOWS\System32\lcppn21.dll [2000.10.26 03:15:00 | 000,017,920 | ---- | C] () -- C:\WINDOWS\System32\Implode.dll < End of report > Besten Dank für jegliche Hilfe! |
Themen zu Kann mit keinem browser googlemail öffnen - 404 Not Found |
ad-aware, adware, antispyware, antivir, avgntflt.sys, avira, bho, browser, explorer, fehlermeldung, firefox, format, found, google, googlemail, launch, location, log-file, logfile, monitor, mozilla, object, oldtimer, opera, plug-in, port, poweriso, realtek, registry, scan, sched.exe, security scan, shortcut, software, start menu, system, temp, vodafone, öffnen |