M
Mark_Xp
Guest
Hallo Freunde,
mein system war total infestiert, habe es glaube ich gesaeubert, kann bitte ihr profis mal nachsehen ob da was noch laeuft? danke
Gruss
Mark
Logfile of HijackThis v1.99.0
Scan saved at 12:47:12 PM, on 1/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C
ROGRA~1GrisoftAVGFRE~1avgamsvr.exe
C
ROGRA~1GrisoftAVGFRE~1avgupsvc.exe
C
rogram FilesCommon FilesSymantec SharedccSetMgr.exe
C:WINDOWSSystem32gearsec.exe
C
rogram FilesCommon FilesSymantec SharedccEvtMgr.exe
C:WINDOWSExplorer.EXE
C
rogram FilesATI TechnologiesATI Control Panelatiptaxx.exe
C
rogram FilesiTunesiTunesHelper.exe
C
rogram FilesQuickTimeqttask.exe
C
rogram FilesSynapticsSynTPSynTPLpr.exe
C
rogram FilesSynapticsSynTPSynTPEnh.exe
C
rogram FilesiPodbiniPodService.exe
C:WINDOWSSystem32hphmon05.exe
C
rogram FilesRoxioEasy CD Creator 6DragToDiscDrgToDsc.exe
C:WINDOWSStealthControl.exe
C
rogram FilesCommon FilesRealUpdate_OBrealsched.exe
C
rogram FilesSlySoftCloneCDCloneCDTray.exe
C
rogram FilesHewlett-PackardHP Software UpdateHPWuSchd2.exe
C
rogram FilesCommon FilesSymantec SharedccApp.exe
C:WINDOWSsystem32carpserv.exe
C
ROGRA~1GrisoftAVGFRE~1avgcc.exe
C
rogram FilesMessengermsmsgs.exe
C
rogram FilesYahoo!Messengerypager.exe
C
rogram FilesMicrosoft ActiveSyncWCESCOMM.EXE
C
rogram FilesAdobeAcrobat 5.0DistillrAcroTray.exe
C
rogram FilesYahooPOPsYahooPOPs.exe
C
rogram FilesT-OnlineT-Online_Software_5Basis-SoftwareBasis2kernel.exe
C
rogram FilesT-OnlineT-Online_Software_5Basis-SoftwareBasis2sc_watch.exe
C
ROGRA~1T-OnlineT-ONLI~1BASIS-~1Basis2PROFIL~1.EXE
C
ROGRAM FILESMOZILLA FIREFOXFIREFOX.EXE
C
OCUME~1MarkLOCALS~1TempTemporary Directory 1 for hijackthis.zipHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak =
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.yahoo.com"); (C
ocuments and SettingsMarkApplication DataMozillaProfilesdefaultqfv7pfo0.sltprefs.js)
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C
ocuments and SettingsMarkApplication DataMozillaProfilesdefaultqfv7pfo0.sltprefs.js)
O4 - HKLM..Run: [ATIPTA] C
rogram FilesATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [iTunesHelper] C
rogram FilesiTunesiTunesHelper.exe
O4 - HKLM..Run: [QuickTime Task] "C
rogram FilesQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [Display Settings] C
rogram FilesHPQNotebook Utilitieshptasks.exe /s
O4 - HKLM..Run: [SynTPLpr] C
rogram FilesSynapticsSynTPSynTPLpr.exe
O4 - HKLM..Run: [SynTPEnh] C
rogram FilesSynapticsSynTPSynTPEnh.exe
O4 - HKLM..Run: [HPHUPD05] c
rogram FilesHewlett-Packard{45B6180B-DCAB-4093-8EE8-6164457517F0}hphupd05.exe
O4 - HKLM..Run: [HPHmon05] C:WINDOWSSystem32hphmon05.exe
O4 - HKLM..Run: [RoxioEngineUtility] "C
rogram FilesCommon FilesRoxio SharedSystemEngUtil.exe"
O4 - HKLM..Run: [RoxioDragToDisc] "C
rogram FilesRoxioEasy CD Creator 6DragToDiscDrgToDsc.exe"
O4 - HKLM..Run: [Cpqset] C
rogram FilesHPQDefault Settingscpqset.exe
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [StealthControl] C:WINDOWSStealthControl.exe
O4 - HKLM..Run: [TkBellExe] "C
rogram FilesCommon FilesRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [PCDRealtime] C:WINDOWSrealtime.exe
O4 - HKLM..Run: [CloneCDTray] "C
rogram FilesSlySoftCloneCDCloneCDTray.exe" /s
O4 - HKLM..Run: [HP Software Update] "C
rogram FilesHewlett-PackardHP Software UpdateHPWuSchd2.exe"
O4 - HKLM..Run: [lssas Monitoring Startup] lssas.exe
O4 - HKLM..Run: [ccApp] "C
rogram FilesCommon FilesSymantec SharedccApp.exe"
O4 - HKLM..Run: [CARPService] carpserv.exe
O4 - HKLM..Run: [QT4HPOT] C
rogram FilesHPQOne-TouchOneTouch.EXE
O4 - HKLM..Run: [Admilli Service] C
rogram FilesAdmilli ServiceAdmilliServ.exe
O4 - HKLM..Run: [AVG7_CC] C
ROGRA~1GrisoftAVGFRE~1avgcc.exe /STARTUP
O4 - HKLM..RunServices: [lssas Monitoring Startup] lssas.exe
O4 - HKCU..Run: [MSMSGS] "C
rogram FilesMessengermsmsgs.exe" /background
O4 - HKCU..Run: [Yahoo! Pager] C
rogram FilesYahoo!Messengerypager.exe -quiet
O4 - HKCU..Run: [MoneyAgent] "c
rogram FilesMicrosoft MoneySystemmnyexpr.exe"
O4 - HKCU..Run: [H/PC Connection Agent] "C
rogram FilesMicrosoft ActiveSyncWCESCOMM.EXE"
O4 - HKCU..Run: [Win32 SSL Driver] winssv.exe
O4 - HKCU..Run: [lssas Monitoring Startup] lssas.exe
O4 - HKCU..RunServices: [] iexpl0res.exe
O4 - Startup: YahooPOPs.lnk = ?
O4 - Global Startup: Acrobat Assistant.lnk = C
rogram FilesAdobeAcrobat 5.0DistillrAcroTray.exe
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C
rogram FilesCommon FilesAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: Billminder.lnk = C
rogram FilesQuickenbillmind.exe
O4 - Global Startup: Quicken Scheduled Updates.lnk = C
rogram FilesQuickenbagent.exe
O4 - Global Startup: Quicken Startup.lnk = C
rogram FilesQuickenQWDLLS.EXE
O8 - Extra context menu item: &Yahoo! Search - file:///C
rogram FilesYahoo!Common/ycsrch.htm
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C
ROGRA~1MICROS~3OFFICE11EXCEL.EXE/3000
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C
rogram FilesYahoo!Common/ycdict.htm
O8 - Extra context menu item: Yahoo! &Maps - file:///C
rogram FilesYahoo!Common/ycdict.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C
rogram FilesJavaj2re1.4.2binnpjpi142.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C
rogram FilesJavaj2re1.4.2binnpjpi142.dll
O9 - Extra button: Mobilen Favoriten erstellen - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C
rogram FilesMicrosoft ActiveSyncINetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C
rogram FilesMicrosoft ActiveSyncINetRepl.dll
O9 - Extra 'Tools' menuitem: Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C
rogram FilesMicrosoft ActiveSyncINetRepl.dll
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C
rogram FilesYahoo!Messengeryhexbmes0521.dll
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C
rogram FilesYahoo!Messengeryhexbmes0521.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C
ROGRA~1MICROS~3OFFICE11REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
rogram FilesMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
rogram FilesMessengermsmsgs.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
O17 - HKLMSystemCCSServicesTcpip..{73533EC7-7DBD-4773-988C-E7FC926B5B75}: NameServer = 217.237.151.97 217.237.150.33
O17 - HKLMSystemCS1ServicesTcpip..{73533EC7-7DBD-4773-988C-E7FC926B5B75}: NameServer = 217.237.151.97 217.237.150.33
O23 - Service: Ati HotKey Poller - Unknown - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C
ROGRA~1GrisoftAVGFRE~1avgamsvr.exe
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C
ROGRA~1GrisoftAVGFRE~1avgupsvc.exe
O23 - Service: Symantec Event Manager - Symantec Corporation - C
rogram FilesCommon FilesSymantec SharedccEvtMgr.exe
O23 - Service: Symantec Password Validation - Symantec Corporation - C
rogram FilesCommon FilesSymantec SharedccPwdSvc.exe
O23 - Service: Symantec Settings Manager - Symantec Corporation - C
rogram FilesCommon FilesSymantec SharedccSetMgr.exe
O23 - Service: Gear Security Service - GEAR Software - C:WINDOWSSystem32gearsec.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C
rogram FilesiPodbiniPodService.exe
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C
rogram FilesNorton AntiVirusnavapsvc.exe
O23 - Service: SAVScan - Symantec Corporation - C
rogram FilesNorton AntiVirusSAVScan.exe
O23 - Service: ScriptBlocking Service - Symantec Corporation - C
ROGRA~1COMMON~1SYMANT~1SCRIPT~1SBServ.exe
mein system war total infestiert, habe es glaube ich gesaeubert, kann bitte ihr profis mal nachsehen ob da was noch laeuft? danke

Gruss
Mark
Logfile of HijackThis v1.99.0
Scan saved at 12:47:12 PM, on 1/4/2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C
C
C
C:WINDOWSSystem32gearsec.exe
C
C:WINDOWSExplorer.EXE
C
C
C
C
C
C
C:WINDOWSSystem32hphmon05.exe
C
C:WINDOWSStealthControl.exe
C
C
C
C
C:WINDOWSsystem32carpserv.exe
C
C
C
C
C
C
C
C
C
C
C
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
Please,
Anmelden
or
Registrieren
to view URLs content!
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak =
Please,
Anmelden
or
Registrieren
to view URLs content!
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
N3 - Netscape 7: user_pref("browser.startup.homepage", "www.yahoo.com"); (C
N3 - Netscape 7: user_pref("browser.search.defaultengine", "engine://C%3A%5CProgram%20Files%5CNetscape%5CNetscape%5Csearchplugins%5CSBWeb_01.src"); (C
O4 - HKLM..Run: [ATIPTA] C
O4 - HKLM..Run: [iTunesHelper] C
O4 - HKLM..Run: [QuickTime Task] "C
O4 - HKLM..Run: [Display Settings] C
O4 - HKLM..Run: [SynTPLpr] C
O4 - HKLM..Run: [SynTPEnh] C
O4 - HKLM..Run: [HPHUPD05] c
O4 - HKLM..Run: [HPHmon05] C:WINDOWSSystem32hphmon05.exe
O4 - HKLM..Run: [RoxioEngineUtility] "C
O4 - HKLM..Run: [RoxioDragToDisc] "C
O4 - HKLM..Run: [Cpqset] C
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [StealthControl] C:WINDOWSStealthControl.exe
O4 - HKLM..Run: [TkBellExe] "C
O4 - HKLM..Run: [PCDRealtime] C:WINDOWSrealtime.exe
O4 - HKLM..Run: [CloneCDTray] "C
O4 - HKLM..Run: [HP Software Update] "C
O4 - HKLM..Run: [lssas Monitoring Startup] lssas.exe
O4 - HKLM..Run: [ccApp] "C
O4 - HKLM..Run: [CARPService] carpserv.exe
O4 - HKLM..Run: [QT4HPOT] C
O4 - HKLM..Run: [Admilli Service] C
O4 - HKLM..Run: [AVG7_CC] C
O4 - HKLM..RunServices: [lssas Monitoring Startup] lssas.exe
O4 - HKCU..Run: [MSMSGS] "C
O4 - HKCU..Run: [Yahoo! Pager] C
O4 - HKCU..Run: [MoneyAgent] "c
O4 - HKCU..Run: [H/PC Connection Agent] "C
O4 - HKCU..Run: [Win32 SSL Driver] winssv.exe
O4 - HKCU..Run: [lssas Monitoring Startup] lssas.exe
O4 - HKCU..RunServices: [] iexpl0res.exe
O4 - Startup: YahooPOPs.lnk = ?
O4 - Global Startup: Acrobat Assistant.lnk = C
O4 - Global Startup: Adobe Gamma Loader.exe.lnk = C
O4 - Global Startup: Billminder.lnk = C
O4 - Global Startup: Quicken Scheduled Updates.lnk = C
O4 - Global Startup: Quicken Startup.lnk = C
O8 - Extra context menu item: &Yahoo! Search - file:///C
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C
O8 - Extra context menu item: Yahoo! &Dictionary - file:///C
O8 - Extra context menu item: Yahoo! &Maps - file:///C
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C
O9 - Extra button: Mobilen Favoriten erstellen - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C
O9 - Extra 'Tools' menuitem: Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - C
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: {B9191F79-5613-4C76-AA2A-398534BB8999} (YAddBook Class) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O17 - HKLMSystemCCSServicesTcpip..{73533EC7-7DBD-4773-988C-E7FC926B5B75}: NameServer = 217.237.151.97 217.237.150.33
O17 - HKLMSystemCS1ServicesTcpip..{73533EC7-7DBD-4773-988C-E7FC926B5B75}: NameServer = 217.237.151.97 217.237.150.33
O23 - Service: Ati HotKey Poller - Unknown - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: AVG7 Alert Manager Server - GRISOFT, s.r.o. - C
O23 - Service: AVG7 Update Service - GRISOFT, s.r.o. - C
O23 - Service: Symantec Event Manager - Symantec Corporation - C
O23 - Service: Symantec Password Validation - Symantec Corporation - C
O23 - Service: Symantec Settings Manager - Symantec Corporation - C
O23 - Service: Gear Security Service - GEAR Software - C:WINDOWSSystem32gearsec.exe
O23 - Service: iPod Service - Apple Computer, Inc. - C
O23 - Service: Norton AntiVirus Auto Protect Service - Symantec Corporation - C
O23 - Service: SAVScan - Symantec Corporation - C
O23 - Service: ScriptBlocking Service - Symantec Corporation - C