DDS logs :
Jau der link hat geklappt, dankeschön
und bitteschön :
DDS :
DDS (Ver_09-12-01.01) - NTFSx86
Run by 1234 at 14:58:23,06 on 22.01.2010
Internet Explorer: 6.0.2900.2180 BrowserJavaVersion: 1.6.0_13
Microsoft Windows XP Home Edition 5.1.2600.2.1252.49.1031.18.2559.2106 [GMT 1:00]
AV: Norton Internet Security *On-access scanning enabled* (Outdated) {E10A9785-9598-4754-B552-92431C1C35F8}
FW: Norton Internet Security *enabled* {7C21A4C9-F61F-4AC4-B722-A6E19C16F220}
============== Running Processes ===============
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost -k DcomLaunch
svchost.exe
C:\WINDOWS\System32\svchost.exe -k netsvcs
svchost.exe
svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
svchost.exe
C:\WINDOWS\ALCWZRD.EXE
C:\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Programme\FRITZ!DSL\IGDCTRL.EXE
C:\Programme\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\Programme\FRITZ!DSL\FwebProt.exe
C:\Programme\Java\jre6\bin\jqs.exe
C:\Programme\FRITZ!DSL\StCenter.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\System32\svchost.exe -k HTTPFilter
C:\Programme\firefox\firefox.exe
C:\Dokumente und Einstellungen\1234\Desktop\dds.exe
============== Pseudo HJT Report ===============
uSearch Page = hxxp://www.google.com
uSearch Bar = hxxp://www.google.com/ie
uSearchMigratedDefaultURL = hxxp://www.google.com/search?q={searchTerms}&sourceid=ie7&rls=com.microsoft:en-US&ie=utf8&oe=utf8
uStart Page = hxxp://www.google.de/
uWindow Title =
mDefault_Page_URL = file://c:\apps\ie\offline\ger.htm
mDefault_Search_URL = hxxp://www.google.com/ie
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
mSearchAssistant = hxxp://www.google.com/ie
BHO: AcroIEHlprObj Class: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - c:\programme\adobe\acrobat 7.0\activex\AcroIEHelper.dll
BHO: Google Toolbar Helper: {aa58ed58-01dd-4d91-8333-cf10577473f7} - c:\programme\google\google toolbar\GoogleToolbar_32.dll
BHO: Google Toolbar Notifier BHO: {af69de43-7d58-4638-b6fa-ce66b5ad205d} - c:\programme\google\googletoolbarnotifier\5.5.4723.1820\swg.dll
TB: Norton Internet Security: {0b53eac3-8d69-4b9e-9b19-a37c9a5676a7} - c:\programme\gemeinsame dateien\symantec shared\adblocking\NISShExt.dll
TB: Norton AntiVirus: {42cdd1bf-3ffb-4238-8ad1-7859df00b1d6} - c:\programme\norton internet security\norton antivirus\NavShExt.dll
TB: Google Toolbar: {2318c2b1-4965-11d4-9b18-009027a5cd4f} - c:\programme\google\google toolbar\GoogleToolbar_32.dll
EB: &Discuss: {bdeade7f-c265-11d0-bced-00a0c90ab50f} - shdocvw.dll
EB: &Recherchieren: {ff059e31-cc5a-4e2e-bf3b-96e929d65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
uRun: [swg] "c:\programme\google\googletoolbarnotifier\GoogleToolbarNotifier.exe"
mRun: [Verknüpfung mit der High Definition Audio-Eigenschaftenseite] HDAudPropShortcut.exe
mRun: [AlcWzrd] ALCWZRD.EXE
mRun: [ATIPTA] c:\ati technologies\ati control panel\atiptaxx.exe
mRun: [PostOOBE] c:\windows\system32\wscript.exe c:\drivers\POSTOOBE.NEC //E:VBS
mRun: [Alcmtr] ALCMTR.EXE
dRun: [CTFMON.EXE] c:\windows\system32\CTFMON.EXE
StartupFolder: c:\dokume~1\1234\startm~1\progra~1\autost~1\fritz!~2.lnk - c:\programme\fritz!dsl\FwebProt.exe
StartupFolder: c:\dokume~1\1234\startm~1\progra~1\autost~1\fritz!~1.lnk - c:\programme\fritz!dsl\StCenter.exe
uPolicies-explorer: NoRecentDocsNetHood = 01000000
uPolicies-explorer: NoNetworkConnections = 01000000
uPolicies-explorer: NoStrCmpLogical = 00000000
IE: Google Sidewiki... - c:\programme\google\google toolbar\component\GoogleToolbarDynamic_mui_en_5F1A57F0B9B89E2E.dll/cmsidewiki.html
IE: Nach Microsoft &Excel exportieren - c:\progra~1\micros~3\office11\EXCEL.EXE/3000
IE: Save YouTube Video - c:\programme\gemeinsame dateien\dvdvideosoft\dll\IEContextMenuY.dll/scriptY2MP4.htm
IE: Save YouTube Video as MP3 - c:\programme\gemeinsame dateien\dvdvideosoft\dll\IEContextMenuY.dll/scriptY2MP3.htm
IE: {CD67F990-D8E9-11d2-98FE-00C0F0318AFE}
IE: {FB5F1910-F110-11d2-BB9E-00C04F795683} - c:\programme\messenger\msmsgs.exe
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503} - c:\progra~1\micros~3\office11\REFIEBAR.DLL
DPF: {33564D57-0000-0010-8000-00AA00389B71} - hxxp://download.microsoft.com/download/F/6/E/F6E491A6-77E1-4E20-9F5F-94901338C922/wmv9VCM.CAB
DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} - hxxp://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1189022904546
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_13-windows-i586.cab
DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - hxxp://fpdownload.macromedia.com/get/flashplayer/current/swflash.cab
Notify: AtiExtEvent - Ati2evxx.dll
mASetup: {9C450606-ED24-4958-92BA-B8940C99D441} - c:\programme\pixiepack codec pack\InstallerHelper.exe
Hosts: 209.85.135.104 msnfix.changelog.fr
Hosts: 209.85.135.104
www.incodesolutions.com
Hosts: 209.85.135.104 virusinfo.prevx.com
Hosts: 209.85.135.104 download.bleepingcomputer.com
Hosts: 209.85.135.104
www.dazhizhu.cn
Note: multiple HOSTS entries found. Please refer to Attach.txt
================= FIREFOX ===================
FF - ProfilePath - c:\dokume~1\1234\anwend~1\mozilla\firefox\profiles\z4oi9pz1.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.google.de/
FF - prefs.js: network.proxy.type - 2
FF - plugin: c:\programme\google\google earth\plugin\npgeplugin.dll
FF - plugin: c:\programme\google\google updater\2.4.1487.6512\npCIDetect13.dll
FF - plugin: c:\programme\google\update\1.2.183.13\npGoogleOneClick8.dll
FF - plugin: c:\programme\quicktime7\plugins\npqtplugin.dll
FF - plugin: c:\programme\quicktime7\plugins\npqtplugin2.dll
FF - plugin: c:\programme\quicktime7\plugins\npqtplugin3.dll
FF - plugin: c:\programme\quicktime7\plugins\npqtplugin4.dll
FF - plugin: c:\programme\quicktime7\plugins\npqtplugin5.dll
FF - plugin: c:\programme\quicktime7\plugins\npqtplugin6.dll
FF - plugin: c:\programme\quicktime7\plugins\npqtplugin7.dll
FF - plugin: c:\programme\real\netscape6\nppl3260.dll
FF - plugin: c:\programme\real\netscape6\nprjplug.dll
FF - plugin: c:\programme\real\netscape6\nprpjplug.dll
FF - HiddenExtension: Java Console: No Registry Reference - c:\programme\firefox\extensions\{CAFEEFAC-0016-0000-0013-ABCDEFFEDCBA}
============= SERVICES / DRIVERS ===============
R3 AVMUNET;AVM FRITZ!Box;c:\windows\system32\drivers\avmunet.sys [2007-5-30 15104]
R3 RRNetCapMP;RRNetCapMP;c:\windows\system32\drivers\rrnetcap.sys [2009-10-7 27168]
S2 SAVRTPEL;SAVRTPEL;\??\c:\programme\norton internet security\norton antivirus\savrtpel.sys --> c:\programme\norton internet security\norton antivirus\SAVRTPEL.SYS [?]
S3 epmntdrv;epmntdrv;c:\windows\system32\epmntdrv.sys [2009-8-25 8704]
S3 EuGdiDrv;EuGdiDrv;c:\windows\system32\EuGdiDrv.sys [2009-8-25 3072]
S3 NAVENG;NAVENG;c:\progra~1\gemein~1\symant~1\virusd~1\20041020.038\NAVENG.SYS [2007-5-13 68168]
S3 NAVEX15;NAVEX15;c:\progra~1\gemein~1\symant~1\virusd~1\20041020.038\NAVEX15.SYS [2007-5-13 617288]
S3 RRNetCap;RRNetCap Service;c:\windows\system32\drivers\rrnetcap.sys [2009-10-7 27168]
S3 SAVRT;SAVRT;\??\c:\programme\norton internet security\norton antivirus\savrt.sys --> c:\programme\norton internet security\norton antivirus\SAVRT.SYS [?]
S3 Slnt7554;USB Soft Modem Driver;c:\windows\system32\drivers\slnt7554.sys [2009-9-20 129535]
S4 ccEvtMgr;Symantec Event Manager;c:\programme\gemeinsame dateien\symantec shared\ccEvtMgr.exe [2004-9-3 197752]
S4 ccProxy;Symantec Network Proxy;c:\programme\gemeinsame dateien\symantec shared\ccProxy.exe [2004-9-3 234616]
S4 ccPwdSvc;Symantec Password Validation;c:\programme\gemeinsame dateien\symantec shared\ccPwdSvc.exe [2004-9-3 78968]
S4 ccSetMgr;Symantec Settings Manager;c:\programme\gemeinsame dateien\symantec shared\ccSetMgr.exe [2004-9-3 164984]
S4 gupdate1c987d458552984;Google Update Service (gupdate1c987d458552984);c:\programme\google\update\GoogleUpdate.exe [2009-2-5 133104]
S4 navapsvc;Norton AntiVirus Auto-Protect-Dienst;"c:\programme\norton internet security\norton antivirus\navapsvc.exe" --> c:\programme\norton internet security\norton antivirus\navapsvc.exe [?]
S4 SAVScan;SAVScan;"c:\programme\norton internet security\norton antivirus\savscan.exe" --> c:\programme\norton internet security\norton antivirus\SAVScan.exe [?]
=============== Created Last 30 ================
2010-01-22 13:40:09 367104 ----a-w- c:\windows\system32\drivers\Netfwdsl.sys
2010-01-22 13:40:09 3069 ----a-w- c:\windows\system32\NETDSL.INF
2010-01-22 13:40:09 28160 ----a-w- c:\windows\system32\drivers\Aadev.sys
2010-01-22 13:40:09 1783 ----a-w- c:\windows\system32\Netfwdsl.inf
2010-01-22 13:40:09 11264 ----a-w- c:\windows\system32\drivers\NETDSL.SYS
2010-01-22 13:40:08 0 d-----w- c:\programme\FRITZ!DSL
2010-01-22 13:39:55 0 d-----w- c:\programme\FRITZ!Box
2010-01-22 11:42:02 76013 ----a-w- c:\windows\_detmp.3
2010-01-22 11:42:02 131072 ----a-w- c:\windows\_detmp.4
2010-01-21 23:15:35 273024 ------w- c:\windows\system32\drivers\bthport.sys
2010-01-21 23:15:35 273024 ------w- c:\windows\system32\dllcache\bthport.sys
2010-01-21 23:12:52 128512 ------w- c:\windows\system32\dllcache\dhtmled.ocx
2010-01-21 23:11:32 331776 ------w- c:\windows\system32\dllcache\msadce.dll
2010-01-21 23:10:52 655872 ------w- c:\windows\system32\dllcache\mstscax.dll
2010-01-21 23:09:31 1196000 ------w- c:\windows\system32\dllcache\sysmain.sdb
2010-01-20 09:40:41 0 d-----w- c:\programme\XGMER
2010-01-20 09:23:41 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-01-20 09:23:39 19160 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-01-19 12:49:40 17920 ---ha-w- c:\dokumente und einstellungen\1234\ppbxg.exe
2010-01-18 15:20:49 17920 ---ha-w- c:\dokumente und einstellungen\1234\ijtjvyf.exe
2010-01-18 15:20:33 204800 --sh--r- c:\windows\system32\wmihtsp.exe
2010-01-17 12:45:21 6 ----a-w- c:\windows\WS_FTP.EXT
2010-01-17 12:45:21 0 ----a-w- c:\windows\WS_FTP.CNV
2009-12-30 16:17:42 0 d-----w- c:\programme\FREEVIDEOJOINER
==================== Find3M ====================
2009-12-16 12:57:07 18432 ----a-w- c:\windows\system32\dllcache\iedw.exe
2009-12-08 09:10:19 474624 ------w- c:\windows\system32\dllcache\shlwapi.dll
2009-11-21 16:37:59 470528 ------w- c:\windows\system32\dllcache\aclayers.dll
2009-10-26 22:01:21 63778 ----a-w- c:\windows\system32\perfc007.dat
2009-10-26 22:01:21 391330 ----a-w- c:\windows\system32\perfh007.dat
2006-05-03 09:06:54 163328 --sh--r- c:\windows\system32\flvDX.dll
2007-02-21 10:47:16 31232 --sh--r- c:\windows\system32\msfDX.dll
2007-12-17 12:43:00 27648 --sh--w- c:\windows\system32\Smab0.dll
============= FINISH: 14:58:33,84 ===============
ATTACH :
UNLESS SPECIFICALLY INSTRUCTED, DO NOT POST THIS LOG.
IF REQUESTED, ZIP IT UP & ATTACH IT
DDS (Ver_09-12-01.01)
Microsoft Windows XP Home Edition
Boot Device: \Device\HarddiskVolume1
Install Date: 13.05.2007 03:50:08
System Uptime: 22.01.2010 14:49:42 (0 hours ago)
M[...]
==== System Restore Points ===================
No restore point in system.
==== Hosts File Hijack ======================
Hosts: 209.85.135.104 msnfix.changelog.fr
Hosts: 209.85.135.104 virusinfo.prevx.com
Hosts: 209.85.135.104 download.bleepingcomputer.com
[...]
==== End Of File ===========================
aber blee.. ist für mich nicht zugänglich
Gruss
Andy