- Mitglied seit
- 3 März 2007
- Beiträge
- 105
Hi leute
Hab da seit einigen tagen das Problem das sich irgendeine scheisse werbung automatisch aufmacht jedesmal geht der iexplorer in den vordergrund und andere sachen hängen sich dann auf!!
Logfile of HijackThis v1.99.1
Scan saved at 18:58:08, on 31.01.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32LEXBCES.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32LEXPPS.EXE
C:WINDOWSExplorer.EXE
C
rogrammeGemeinsame DateienAutodata Limited SharedServiceADCDLicSvc.exe
C:WINDOWSsystem32CTsvcCDA.exe
C
rogrammeEsetnod32krn.exe
C
rogrammeCyberLinkShared filesRichVideo.exe
C
rogrammeAlcohol SoftAlcohol 120StarWindStarWindService.exe
C:WINDOWSsystem32svchost.exe
C
rogrammeVirtual CD v8SystemVC8SecS.exe
C:WINDOWSsystem32MsPMSPSv.exe
C
rogrammeAdobeAcrobat 7.0DistillrAcrotray.exe
C
rogrammeJavajre1.5.0_10binjusched.exe
C
rogrammeDell AIO Printer A920dlbkbmgr.exe
C
rogrammeCyberLinkPowerDVDPDVDServ.exe
C
rogrammeDell AIO Printer A920dlbkbmon.exe
C
rogrammeCreativeCreative Live! CamVideoFXStartFX.exe
C
rogrammeGemeinsame DateienInstallShieldUpdateServiceissch.exe
C:WINDOWSsystem32LVCOMSX.EXE
C:WINDOWSsystem32CTHELPER.EXE
C:WINDOWSsystem32v6.exe
C
rogrammeEsetnod32kui.exe
C
rogrammeCreativeSBAudigy2Surround MixerCTSysVol.exe
C
rogrammeCreativeSBAudigy2DVDAudioCTDVDDet.EXE
C:WINDOWSsystem32ctfmon.exe
C
rogrammeGemeinsame DateienAheadlibNMBgMonitor.exe
C
rogrammeInternet Exploreriexplore.exe
C
rogrammeGoogleGoogleToolbarNotifier1.2.1128.5462GoogleToolbarNotifier.exe
c
rogra~1intern~1iexplore.exe
C
rogrammeGemeinsame DateienAheadLibNMIndexStoreSvr.exe
C
rogrammeXfirexfire.exe
C
rogrammeSkypePhoneSkype.exe
C
OKUME~1ADMINI~1LOKALE~1Temp~e5.0001
C
OKUME~1ADMINI~1LOKALE~1Temp~e5.0001
C
OKUME~1ADMINI~1LOKALE~1Temp~e5.0001
C
rogrammeInternet Exploreriexplore.exe
C
rogrammeInternet Exploreriexplore.exe
D
rogrammeHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C
rogrammeAdobeAcrobat 7.0ActiveXAcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C
rogrammeJavajre1.5.0_10binssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c
rogrammegooglegoogletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C
rogrammeAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C
rogrammeAdobeAcrobat 7.0AcrobatAcroIEFavClient.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c
rogrammegooglegoogletoolbar2.dll
O4 - HKLM..Run: [Acrobat Assistant 7.0] "C
rogrammeAdobeAcrobat 7.0DistillrAcrotray.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C
rogrammeJavajre1.5.0_10binjusched.exe"
O4 - HKLM..Run: [Dell AIO Printer A920] "C
rogrammeDell AIO Printer A920dlbkbmgr.exe"
O4 - HKLM..Run: [RemoteControl] C
rogrammeCyberLinkPowerDVDPDVDServ.exe
O4 - HKLM..Run: [LanguageShortcut] C
rogrammeCyberLinkPowerDVDLanguageLanguage.exe
O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 - HKLM..Run: [AVFX Engine] C
rogrammeCreativeCreative Live! CamVideoFXStartFX.exe
O4 - HKLM..Run: [NeroFilterCheck] C
rogrammeGemeinsame DateienAheadLibNeroCheck.exe
O4 - HKLM..Run: [ISUSPM Startup] C
ROGRA~1GEMEIN~1INSTAL~1UPDATE~1isuspm.exe -startup
O4 - HKLM..Run: [ISUSScheduler] "C
rogrammeGemeinsame DateienInstallShieldUpdateServiceissch.exe" -start
O4 - HKLM..Run: [exit army book log] C
okumente und EinstellungenAll UsersAnwendungsdatenProxy License Exit ArmyLicense heart.exe
O4 - HKLM..Run: [LVCOMSX] C:WINDOWSsystem32LVCOMSX.EXE
O4 - HKLM..Run: [CTHelper] CTHELPER.EXE
O4 - HKLM..Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 - HKLM..Run: [syswin] C:WINDOWSsystem32v6.exe
O4 - HKLM..Run: [nod32kui] "C
rogrammeEsetnod32kui.exe" /WAITSERVICE
O4 - HKLM..Run: [CTSysVol] C
rogrammeCreativeSBAudigy2Surround MixerCTSysVol.exe
O4 - HKLM..Run: [CTDVDDet] C
rogrammeCreativeSBAudigy2DVDAudioCTDVDDet.EXE
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C
rogrammeGemeinsame DateienAheadlibNMBgMonitor.exe"
O4 - HKCU..Run: [Skype] "C
rogrammeSkypePhoneSkype.exe" /nosplash /minimized
O4 - HKCU..Run: [swg] C
rogrammeGoogleGoogleToolbarNotifier1.2.1128.5462GoogleToolbarNotifier.exe
O4 - HKCU..Run: [16 2] C
OKUME~1ADMINI~1ANWEND~1REMOTE~1Pop Web Online.exe
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C
rogrammeMicrosoft OfficeOffice10OSA.EXE
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C
rogrammeJavajre1.5.0_10binnpjpi150_10.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C
rogrammeJavajre1.5.0_10binnpjpi150_10.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C
ROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C
rogrammeICQLiteICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C
rogrammeICQLiteICQLite.exe
O12 - Plugin for .wav: C
rogrammeInternet ExplorerPLUGINSnpqtplugin.dll
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C
rogrammeYahoo!Commonyinsthelper.dll
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -
O17 - HKLMSystemCCSServicesTcpip..{11A02CAA-B933-4D99-B9E9-E4357FDFC7B9}: NameServer = 192.168.2.1
O17 - HKLMSystemCS1ServicesTcpip..{11A02CAA-B933-4D99-B9E9-E4357FDFC7B9}: NameServer = 192.168.2.1
O17 - HKLMSystemCS2ServicesTcpip..{11A02CAA-B933-4D99-B9E9-E4357FDFC7B9}: NameServer = 192.168.2.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C
ROGRA~1GEMEIN~1SkypeSKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C
rogrammeGemeinsame DateienAdobe Systems SharedServiceAdobelmsvc.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: Autodata Limited License Service - Autodata Limited - C
rogrammeGemeinsame DateienAutodata Limited SharedServiceADCDLicSvc.exe
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:WINDOWSsystem32CTsvcCDA.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:MAGIXCommonDatabasebinfbserver.exe
O23 - Service: Google Updater Service (gusvc) - Google - C
rogrammeGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C
rogrammeGemeinsame DateienInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE
O23 - Service: NBService - Nero AG - C
rogrammeNeroNero 7Nero BackItUpNBService.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C
rogrammeEsetnod32krn.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C
rogrammeCyberLinkShared filesRichVideo.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C
rogrammeAlcohol SoftAlcohol 120StarWindStarWindService.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C
rogrammeTuneUpUtilities2006WinStylerThemeSvc.exe
O23 - Service: Virtual CD v8 Management Service (VC8SecS) - H+H Software GmbH - C
rogrammeVirtual CD v8SystemVC8SecS.exe
das einzige was ich her sehe ist der iexplorer mehr mals offen warum auch immer und V6.exe kenne ich nicht was ist das für eine???
Bitte schnell um hilfe
Mfg
Hab da seit einigen tagen das Problem das sich irgendeine scheisse werbung automatisch aufmacht jedesmal geht der iexplorer in den vordergrund und andere sachen hängen sich dann auf!!
Logfile of HijackThis v1.99.1
Scan saved at 18:58:08, on 31.01.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32LEXBCES.EXE
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSsystem32LEXPPS.EXE
C:WINDOWSExplorer.EXE
C
C:WINDOWSsystem32CTsvcCDA.exe
C
C
C
C:WINDOWSsystem32svchost.exe
C
C:WINDOWSsystem32MsPMSPSv.exe
C
C
C
C
C
C
C
C:WINDOWSsystem32LVCOMSX.EXE
C:WINDOWSsystem32CTHELPER.EXE
C:WINDOWSsystem32v6.exe
C
C
C
C:WINDOWSsystem32ctfmon.exe
C
C
C
c
C
C
C
C
C
C
C
C
D
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
Please,
Anmelden
or
Registrieren
to view URLs content!
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Local Page =
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext =
Please,
Anmelden
or
Registrieren
to view URLs content!
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c
O4 - HKLM..Run: [Acrobat Assistant 7.0] "C
O4 - HKLM..Run: [SunJavaUpdateSched] "C
O4 - HKLM..Run: [Dell AIO Printer A920] "C
O4 - HKLM..Run: [RemoteControl] C
O4 - HKLM..Run: [LanguageShortcut] C
O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 - HKLM..Run: [AVFX Engine] C
O4 - HKLM..Run: [NeroFilterCheck] C
O4 - HKLM..Run: [ISUSPM Startup] C
O4 - HKLM..Run: [ISUSScheduler] "C
O4 - HKLM..Run: [exit army book log] C
O4 - HKLM..Run: [LVCOMSX] C:WINDOWSsystem32LVCOMSX.EXE
O4 - HKLM..Run: [CTHelper] CTHELPER.EXE
O4 - HKLM..Run: [AsioReg] REGSVR32.EXE /S CTASIO.DLL
O4 - HKLM..Run: [UpdReg] C:WINDOWSUpdReg.EXE
O4 - HKLM..Run: [syswin] C:WINDOWSsystem32v6.exe
O4 - HKLM..Run: [nod32kui] "C
O4 - HKLM..Run: [CTSysVol] C
O4 - HKLM..Run: [CTDVDDet] C
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C
O4 - HKCU..Run: [Skype] "C
O4 - HKCU..Run: [swg] C
O4 - HKCU..Run: [16 2] C
O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerRestrictions present
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C
O12 - Plugin for .wav: C
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O17 - HKLMSystemCCSServicesTcpip..{11A02CAA-B933-4D99-B9E9-E4357FDFC7B9}: NameServer = 192.168.2.1
O17 - HKLMSystemCS1ServicesTcpip..{11A02CAA-B933-4D99-B9E9-E4357FDFC7B9}: NameServer = 192.168.2.1
O17 - HKLMSystemCS2ServicesTcpip..{11A02CAA-B933-4D99-B9E9-E4357FDFC7B9}: NameServer = 192.168.2.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll
O23 - Service: Adobe LM Service - Adobe Systems - C
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: Autodata Limited License Service - Autodata Limited - C
O23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:WINDOWSsystem32CTsvcCDA.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:MAGIXCommonDatabasebinfbserver.exe
O23 - Service: Google Updater Service (gusvc) - Google - C
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C
O23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:WINDOWSsystem32LEXBCES.EXE
O23 - Service: NBService - Nero AG - C
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C
O23 - Service: Virtual CD v8 Management Service (VC8SecS) - H+H Software GmbH - C
das einzige was ich her sehe ist der iexplorer mehr mals offen warum auch immer und V6.exe kenne ich nicht was ist das für eine???
Bitte schnell um hilfe
Mfg