Re: Updaten von XP klappt nicht mehr
Logfile of HijackThis v1.99.1
Scan saved at 07:38:37, on 20.02.2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16414)
Running processes:
G:\XPHOME\System32\smss.exe
G:\XPHOME\system32\winlogon.exe
G:\XPHOME\system32\services.exe
G:\XPHOME\system32\lsass.exe
G:\XPHOME\system32\Ati2evxx.exe
G:\XPHOME\system32\svchost.exe
G:\XPHOME\System32\svchost.exe
G:\XPHOME\system32\svchost.exe
G:\XPHOME\system32\Ati2evxx.exe
G:\XPHOME\Explorer.EXE
G:\XPHOME\system32\spoolsv.exe
G:\Programme\AntiVir PersonalEdition Classic\sched.exe
G:\Programme\AntiVir PersonalEdition Classic\avguard.exe
G:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe
G:\XPHOME\system32\tcpsvcs.exe
G:\XPHOME\System32\snmp.exe
G:\XPHOME\system32\svchost.exe
G:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
G:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
G:\XPHOME\SOUNDMAN.EXE
G:\XPHOME\system32\ctfmon.exe
G:\XPHOME\system32\wscntfy.exe
G:\Programme\Internet Explorer\iexplore.exe
G:\SAV32CLI\SAV32CLI.EXE
G:\XPHOME\Explorer.EXE
G:\Programme\WinRAR\WinRAR.exe
G:\DOKUME~1\SASCHA~1.REC\LOKALE~1\Temp\Rar$EX00.906\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = G:\windows\system32\blank.htm
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - G:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - G:\PROGRA~1\SPYBOT~1\SDHelper.dll
O4 - HKLM\..\Run: [avgnt] "G:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Zone Labs Client] "G:\Programme\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [Trojancheck 6 Guard] G:\Programme\Trojancheck 6\tcguard.exe
O4 - HKLM\..\Run: [ATIPTA] G:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [Ptipbmf] rundll32.exe ptipbmf.dll,SetWriteCacheMode
O4 - HKLM\..\Run: [iMJPMIG8.1] "G:\XPHOME\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [iMEKRMIG6.1] G:\XPHOME\ime\imkr6_1\IMEKRMIG.EXE
O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE
O4 - HKCU\..\Run: [ctfmon.exe] G:\XPHOME\system32\ctfmon.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - G:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - G:\Programme\ICQLite\ICQLite.exe
O11 - Options group: [iNTERNATIONAL] International*
O12 - Plugin for .UVR: G:\Programme\Internet Explorer\Plugins\NPUPano.dll
O16 - DPF: ppctlcab -
O16 - DPF: {215B8138-A3CF-44C5-803F-8226143CFC0A} (Trend Micro ActiveX Scan Agent 6.6) -
O16 - DPF: {2FC9A21E-2069-4E47-8235-36318989DB13} (PPSDKActiveXScanner.MainScreen) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) -
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) -
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) -
O16 - DPF: {9D190AE6-C81E-4039-8061-978EBAD10073} (F-Secure Online Scanner 3.0) -
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
O17 - HKLM\System\CCS\Services\Tcpip\..\{0F23FCD9-5391-4C40-8145-42586EEE5D69}: NameServer = 195.50.140.114 195.50.140.252
O17 - HKLM\System\CS1\Services\Tcpip\..\{0F23FCD9-5391-4C40-8145-42586EEE5D69}: NameServer = 195.50.140.114 195.50.140.252
O17 - HKLM\System\CS3\Services\Tcpip\..\{0F23FCD9-5391-4C40-8145-42586EEE5D69}: NameServer = 195.50.140.114 195.50.140.252
O17 - HKLM\System\CS4\Services\Tcpip\..\{0F23FCD9-5391-4C40-8145-42586EEE5D69}: NameServer = 195.50.140.114 195.50.140.252
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - G:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - G:\XPHOME\system32\WPDShServiceObj.dll
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - G:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - G:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - G:\XPHOME\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - G:\XPHOME\system32\ati2sgag.exe
O23 - Service: AVG Anti-Spyware Guard - Anti-Malware Development a.s. - G:\Programme\Grisoft\AVG Anti-Spyware 7.5\guard.exe
O23 - Service: Pml Driver HPZ12 - HP - G:\XPHOME\system32\HPZipm12.exe
O23 - Service: ServiceLayer - Nokia. - G:\Programme\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - G:\XPHOME\system32\ZoneLabs\vsmon.exe
taskmgr.exe
wscntfy.exe
ctfmon.exe
SOUNDMAN.EXE
atiptaxx.exe
alg.exe
avgnt.exe
explorer.exe
ati2ecxx.exe (mal 2)
svchost.exe (mal
Isass.exe
services.exe
winlogon.exe
csrss.exe
snmp.exe
smss.exe
tcpsvcs.exe
guard.exe
avguard.exe
sched.exe
iexplore.exe
spoolsv.exe
system
leerlaufprozess
3 GHz Prozessor, ASUS P4P-800 E Deluxe Motherboard, Radeon 9800 Pro Grafikkatte, 1,5 GB RAM, 120 GB Festplatte Hitachi, 250 GB Festplatte Maxtor.