Hallo!
Ich wollte mal HijackThis Durchlaufen lassen, und wissen,was ich löschen muss!
Hier der Log:
Logfile of HijackThis v1.98.0
Scan saved at 14:24:49, on 01.07.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C
rogrammeGemeinsame DateienSymantec SharedccEvtMgr.exe
C
rogrammeATI TechnologiesATI Control Panelatiptaxx.exe
C:WINDOWSSOUNDMAN.EXE
C:WINDOWSAGRSMMSG.exe
C
rogrammeApoint2KApoint.exe
C:WINDOWSSystem32Ati2evxx.exe
C
rogrammeGemeinsame DateienMicrosoft SharedVS7Debugmdm.exe
C
rogrammeGemeinsame DateienSymantec SharedccApp.exe
C:WINDOWSSystem32spooldriversw32x863hpztsb04.exe
C:WINDOWSSOINTGR.EXE
C
rogrammeinKline GlobalPC Boosterpcbooster.exe
C:WINDOWSTwain_32SlimU2HotKey.exe
C
rogrammeNorton AntiVirusnavapsvc.exe
C
rogrammeVeriSignNAVInaviagent.exe
C
rogrammeT-DSL SpeedManagerSpeedMgr.exe
C
rogrammeJavaj2re1.4.2_04binjusched.exe
C
rogrammeGemeinsame DateienRealUpdate_OBrealsched.exe
C
rogrammeGemeinsame DateienLogitechQCDriver3LVCOMS.EXE
C
ROGRA~1ZONELA~1ZONEAL~1zlclient.exe
C
rogrammeT-OnlineT-Online_Software_5Basis-SoftwareBasis1ToADiMon.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32ctfmon.exe
C:WINDOWSsystem32ZoneLabsvsmon.exe
C
rogrammeApoint2KApntex.exe
C
rogrammeInterVideoCommonBinWinCinemaMgr.exe
C
rogrammeT-OnlineT-Online_Software_5Basis-SoftwareBasis2kernel.exe
C
rogrammeT-DSL SpeedManagertsmsvc.exe
C
rogrammeT-OnlineT-Online_Software_5Basis-SoftwareBasis2sc_watch.exe
C
rogrammeMessengermsmsgs.exe
C
ROGRA~1T-OnlineT-ONLI~1BASIS-~1Basis2PROFIL~1.EXE
C
rogrammeInternet Exploreriexplore.exe
C
okumente und EinstellungenFamilie BeerLokale EinstellungenTempTemporäres Verzeichnis 1 für hijackthis[1].zipHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.google.com/ie
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.google.com
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://mysearchnow.com/searchbar.html
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://mysearchnow.com/searchbar.html
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.google.com/ie
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://www.google.com/keyword/%s
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = iexplore
R3 - URLSearchHook: VeriSign Inc. i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C
rogrammeVeriSigni-Navi-nav_4_1_4.dll
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:WINDOWSsystem32userinit.exe,
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C
rogrammeTechSmithSnagIt 7SnagItBHO.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C
rogrammeAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c
rogrammegooglegoogletoolbar2.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C
rogrammeNorton AntiVirusNavShExt.dll
O2 - BHO: VeriSign Inc. i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C
rogrammeVeriSigni-Navi-nav_4_1_4.dll
O2 - BHO: (no name) - {E77EBC60-200F-1D3F-3E59-83C9177A5DBD} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C
rogrammeNorton AntiVirusNavShExt.dll
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C
rogrammeTechSmithSnagIt 7SnagItIEAddin.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c
rogrammegooglegoogletoolbar2.dll
O4 - HKLM..Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM..Run: [ATIPTA] C
rogrammeATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM..Run: [Apoint] C
rogrammeApoint2KApoint.exe
O4 - HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 - HKLM..Run: [ccApp] "C
rogrammeGemeinsame DateienSymantec SharedccApp.exe"
O4 - HKLM..Run: [ccRegVfy] "C
rogrammeGemeinsame DateienSymantec SharedccRegVfy.exe"
O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32spooldriversw32x863hpztsb04.exe
O4 - HKLM..Run: [SO5 Integrator Pass Two] C:WINDOWSSOINTGR.EXE
O4 - HKLM..Run: [PC Booster] C
rogrammeinKline GlobalPC Boosterpcbooster.exe
O4 - HKLM..Run: [HotKey] C:WINDOWSTwain_32SlimU2HotKey.exe
O4 - HKLM..Run: [CloneCDElbyCDFL] "C
rogrammeElaborate BytesCloneCDElbyCheck.exe" /L ElbyCDFL
O4 - HKLM..Run: [T-DSL SpeedMgr] "C
rogrammeT-DSL SpeedManagerSpeedMgr.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] C
rogrammeJavaj2re1.4.2_04binjusched.exe
O4 - HKLM..Run: [TkBellExe] "C
rogrammeGemeinsame DateienRealUpdate_OBrealsched.exe" -osboot
O4 - HKLM..Run: [LVCOMS] C
rogrammeGemeinsame DateienLogitechQCDriver3LVCOMS.EXE
O4 - HKLM..Run: [Zone Labs Client] C
ROGRA~1ZONELA~1ZONEAL~1zlclient.exe
O4 - HKLM..Run: [ToADiMon.exe] C
rogrammeT-OnlineT-Online_Software_5Basis-SoftwareBasis1ToADiMon.exe -TOnlineAutodialStart
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C
rogrammeInterVideoCommonBinWinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C
rogrammeMicrosoft OfficeOffice10OSA.EXE
O8 - Extra context menu item: &Google Search - res://C
rogrammeGoogleGoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C
rogrammeGoogleGoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C
rogrammeGoogleGoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C
ROGRA~1MICROS~2Office10EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C
rogrammeGoogleGoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Vorlesen! - C:WINDOWSWebtoyagd.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Hilfe zu i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: Hilfe zu i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - (no file)
O9 - Extra 'Tools' menuitem: Optionen für i-Nav - {CE000996-A58C-4441-8938-744CD72AB27F} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
rogrammeMessengerMSMSGS.EXE
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
rogrammeMessengerMSMSGS.EXE
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O17 - HKLMSystemCCSServicesTcpip..{1242A4A0-B313-453E-B4B6-F47567F1DD7A}: NameServer = 217.237.151.97 194.25.2.129
O17 - HKLMSystemCS1ServicesTcpip..{1242A4A0-B313-453E-B4B6-F47567F1DD7A}: NameServer = 217.237.151.97 194.25.2.129
Tschüss,
stefbeer
Ich wollte mal HijackThis Durchlaufen lassen, und wissen,was ich löschen muss!
Hier der Log:
Logfile of HijackThis v1.98.0
Scan saved at 14:24:49, on 01.07.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C
C
C:WINDOWSSOUNDMAN.EXE
C:WINDOWSAGRSMMSG.exe
C
C:WINDOWSSystem32Ati2evxx.exe
C
C
C:WINDOWSSystem32spooldriversw32x863hpztsb04.exe
C:WINDOWSSOINTGR.EXE
C
C:WINDOWSTwain_32SlimU2HotKey.exe
C
C
C
C
C
C
C
C
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32ctfmon.exe
C:WINDOWSsystem32ZoneLabsvsmon.exe
C
C
C
C
C
C
C
C
C
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://www.google.com/ie
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.google.com
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://mysearchnow.com/searchbar.html
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://mysearchnow.com/searchbar.html
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://www.google.com/ie
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) = http://www.google.com/keyword/%s
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = iexplore
R3 - URLSearchHook: VeriSign Inc. i-Nav IDN SearchHook - {CE000994-A58C-4441-8938-744CD72AB27F} - C
F0 - system.ini: Shell=
F2 - REG:system.ini: UserInit=C:WINDOWSsystem32userinit.exe,
O2 - BHO: HelperObject Class - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C
O2 - BHO: VeriSign Inc. i-Nav IDN Resolver - {CE000992-A58C-4441-8938-744CD72AB27F} - C
O2 - BHO: (no name) - {E77EBC60-200F-1D3F-3E59-83C9177A5DBD} - (no file)
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c
O4 - HKLM..Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM..Run: [ATIPTA] C
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [AGRSMMSG] AGRSMMSG.exe
O4 - HKLM..Run: [Apoint] C
O4 - HKLM..Run: [NeroCheck] C:WINDOWSSystem32\NeroCheck.exe
O4 - HKLM..Run: [ccApp] "C
O4 - HKLM..Run: [ccRegVfy] "C
O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32spooldriversw32x863hpztsb04.exe
O4 - HKLM..Run: [SO5 Integrator Pass Two] C:WINDOWSSOINTGR.EXE
O4 - HKLM..Run: [PC Booster] C
O4 - HKLM..Run: [HotKey] C:WINDOWSTwain_32SlimU2HotKey.exe
O4 - HKLM..Run: [CloneCDElbyCDFL] "C
O4 - HKLM..Run: [T-DSL SpeedMgr] "C
O4 - HKLM..Run: [SunJavaUpdateSched] C
O4 - HKLM..Run: [TkBellExe] "C
O4 - HKLM..Run: [LVCOMS] C
O4 - HKLM..Run: [Zone Labs Client] C
O4 - HKLM..Run: [ToADiMon.exe] C
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C
O4 - Global Startup: Microsoft Office.lnk = C
O8 - Extra context menu item: &Google Search - res://C
O8 - Extra context menu item: Backward &Links - res://C
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C
O8 - Extra context menu item: Si&milar Pages - res://C
O8 - Extra context menu item: Vorlesen! - C:WINDOWSWebtoyagd.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Hilfe zu i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra 'Tools' menuitem: Hilfe zu i-Nav - {CE000992-A58C-4441-8938-744CD72AB27F} - http://idn.verisign-grs.com/plug-in/support/index.jsp (file missing)
O9 - Extra button: (no name) - {CE000996-A58C-4441-8938-744CD72AB27F} - (no file)
O9 - Extra 'Tools' menuitem: Optionen für i-Nav - {CE000996-A58C-4441-8938-744CD72AB27F} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
O9 - Extra 'Tools' menuitem: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
O16 - DPF: ppctlcab - http://www.pestscan.com/scanner/ppctlcab.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) - http://www.pestscan.com/scanner/axscanner.cab
O16 - DPF: {9A54032D-31F7-400D-B184-83B33BDE65FA} (MSN File Upload Control) - http://sc.groups.msn.com/controls/FileUC/MsnUpld.cab
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O17 - HKLMSystemCCSServicesTcpip..{1242A4A0-B313-453E-B4B6-F47567F1DD7A}: NameServer = 217.237.151.97 194.25.2.129
O17 - HKLMSystemCS1ServicesTcpip..{1242A4A0-B313-453E-B4B6-F47567F1DD7A}: NameServer = 217.237.151.97 194.25.2.129
Tschüss,
stefbeer