Re: Systemauslaustung steigt sprunghaft an
Habe das selbe Problem,hier mal meine Daten die angezeigt werden.
Vielleicht hilft mir ja dabei jemand?
LG micha
Logfile of HijackThis v1.97.7
Scan saved at 12:40:49, on 23.05.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeGemeinsame DateienSymantec SharedccEvtMgr.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeNorton Personal FirewallNISUM.EXE
C:WINDOWSSystem32hphmon04.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeHewlett-PackardHP Share-to-Webhpgs2wnd.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeGemeinsame DateienSymantec SharedccApp.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeGemeinsame DateienLogitechQCDriver3LVCOMS.EXE
C:WINDOWSsysupd.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeISTsvcistsvc.exe
C:WINDOWSSystem32ctfmon.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
ROGRA~1Yahoo!MESSEN~1ypager.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeHewlett-PackardHP Share-to-Webhpgs2wnf.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeNorton Personal FirewallccPxySvc.exe
C:WINDOWSsystem32cisvc.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeGemeinsame DateienSymantec SharedDJSNETCN.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeNorton AntiVirusnavapsvc.exe
C:WINDOWSSystem32nvsvc32.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSSystem32HPHipm11.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeMessengermsmsgs.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeT-OnlineT-Online_Software_5Basis-SoftwareBasis2kernel.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeT-OnlineT-Online_Software_5Basis-SoftwareBasis2sc_watch.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
ROGRA~1T-OnlineT-ONLI~1BASIS-~1Basis2PROFIL~1.EXE
C:WINDOWSsystem32cidaemon.exe
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeInternet ExplorerIEXPLORE.EXE
C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
ROGRA~1WINZIPwinzip32.exe
C:unzippedhijackthis1977HijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page =
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearchURL,(Default) =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak =
R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,Shellnext =
O1 - Hosts: 12.129.205.209 search.netscape.com12.129.205.209 sitefinder.verisign.com
O2 - BHO: (no name) - {001F2570-5DF5-11d3-B991-00A0C9BB0874} - C:WINDOWSDownloaded Program FileseBayBand.dll
O2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeMyWaySearchAt4.binMWSSRCAS.DLL
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeYahoo!Messengerycomp.dll
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeMyWaybar4.binMWSBAR.DLL
O2 - BHO: Com.Win IE-BHO - {47EE33DA-0E2B-41E4-8923-0899631D2CF7} - C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeWEB.DEWEB.DE Com.WinAcwIE.dll
O2 - BHO: (no name) - {49E0E0F0-5C30-11D4-945D-000000000001} - C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
ROGRA~1GDATAD~1DSLTUN~1.DLL
O2 - BHO: (no name) - {BDF3E430-B101-42AD-A544-FADC6B084872} - C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeNorton AntiVirusNavShExt.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINDOWSSystem32msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeNorton AntiVirusNavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeYahoo!Messengerycomp.dll
O3 - Toolbar: My &Way Speedbar - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeMyWaybar4.binMWSBAR.DLL
O3 - Toolbar: eBay Toolbar - {46AE04C0-BCFA-4728-90E7-00EB4A8B3863} - C:WINDOWSDownloaded Program FileseBayBand.dll
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSSystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [nwiz] nwiz.exe /install
O4 - HKLM..Run: [HPDJ Taskbar Utility] C:WINDOWSSystem32spooldriversw32x863hpztsb07.exe
O4 - HKLM..Run: [HPHmon04] C:WINDOWSSystem32hphmon04.exe
O4 - HKLM..Run: [HPHUPD04] "C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeHP Photosmart 11hphinstallUniPatchhphupd04.exe"
O4 - HKLM..Run: [Share-to-Web Namespace Daemon] C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeHewlett-PackardHP Share-to-Webhpgs2wnd.exe
O4 - HKLM..Run: [ccApp] "C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeGemeinsame DateienSymantec SharedccApp.exe"
O4 - HKLM..Run: [ccRegVfy] "C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeGemeinsame DateienSymantec SharedccRegVfy.exe"
O4 - HKLM..Run: [LVCOMS] C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeGemeinsame DateienLogitechQCDriver3LVCOMS.EXE
O4 - HKLM..Run: [LogitechGalleryRepair] C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeLogitechImageStudioISStart.exe
O4 - HKLM..Run: [Realtime Audio Engine] mmrtkrnl.exe
O4 - HKLM..Run: [SysUpd] C:WINDOWSsysupd.exe
O4 - HKLM..Run: [LogitechImageStudioTray] C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeLogitechImageStudioLogiTray.exe
O4 - HKLM..Run: [IST Service] C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeISTsvcistsvc.exe
O4 - HKLM..RunServices: [DJSNetCN] C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeGemeinsame DateienSymantec SharedDJSNETCN.exe
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSSystem32ctfmon.exe
O4 - HKCU..Run: [Yahoo! Pager] C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
ROGRA~1Yahoo!MESSEN~1ypager.exe -quiet
O4 - HKCU..Run: [Shareaza] "C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeShareazaShareaza.exe" -tray
O4 - HKCU..Run: [AIM] C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeAIM95aim.exe -cnetwait.odl
O4 - HKCU..Run: [LDM] ProgramBackWeb-8876480.exe
O4 - HKCU..Run: [Eraser] C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeErasereraser.exe -hide
O4 - Global Startup: Logitech Desktop Messenger.lnk = C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeLogitechDesktop Messenger8876480ProgramLDMConf.exe
O4 - Global Startup: Microsoft Office.lnk = C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeMicrosoft OfficeOffice10OSA.EXE
O8 - Extra context menu item: &Search -
O8 - Extra context menu item: Mit DSL-Tuning 2004 downloaden - C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
rogrammeG DATA DSL-Tuning 2004IEDownload.htm
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C
![Stick out tongue :p :p](data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEAAAAALAAAAAABAAEAAAIBRAA7)
ROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra 'Tools' menuitem: Sun Java Console (HKLM)
O9 - Extra button: eBay Toolbar (HKLM)
O9 - Extra 'Tools' menuitem: eBay Toolbar (HKLM)
O9 - Extra button: AIM (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Messenger (HKLM)
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O10 - Unknown file in Winsock LSP: c:windowssystem32pidlsp.dll
O16 - DPF: Yahoo! Chat -
O16 - DPF: {00000000-CDDC-0704-0B53-2C8830E9FAEC} (IELoaderCtl Class) -
O16 - DPF: {001F2570-5DF5-11D3-B991-00A0C9BB0874} (eBay Helper Object) -
O16 - DPF: {018B7EC3-EECA-11D3-8E71-0000E82C6C0D} (Installer Class) -
O16 - DPF: {103DFAE7-50CC-41FC-9D57-1A4BCA0DFD87} (Upload Control) -
O16 - DPF: {166B1BCA-3F9C-11CF-8075-444553540000} (Shockwave ActiveX Control) -
O16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} -
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) -
O16 - DPF: {33564D57-0000-0010-8000-00AA00389B71} -
O16 - DPF: {358DF899-C98C-4A31-AABA-E110A0E6BF1D} (Acw Control) -
O16 - DPF: {3E68E405-C6DE-49FF-83AE-41EE9F4C36CE} (Office Update Installation Engine) -
O16 - DPF: {51EA44E6-C8C3-4E30-8F3D-D8EE71A44DCB} (Upload Control) -
O16 - DPF: {91413D86-9F27-402C-B5E3-DEBDD122C339} -
O16 - DPF: {AA5E9ECE-2A7D-4BDC-8BF3-3B945DB526D1} (DSUpload Control) -
O16 - DPF: {B91AEDBE-93DF-4017-8BB3-F1C300C0EC51} -
O16 - DPF: {C2FCEF52-ACE9-11D3-BEBD-00105AA9B6AE} (Symantec RuFSI Registry Information Class) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLMSystemCCSServicesTcpip..{7BF42685-80A7-42A5-9A76-DCA171F41A44}: NameServer = 192.168.122.252,192.168.122.253
O17 - HKLMSystemCCSServicesTcpip..{7ED0D063-FB30-46C3-AFA4-49834196C9A5}: NameServer = 192.168.120.252,192.168.120.253
O17 - HKLMSystemCCSServicesTcpip..{97CAF95B-87B2-4EB5-8410-9441D94E4431}: NameServer = 217.237.151.225 194.25.2.129