J
japanese-toy
Guest
Moin User,
auch bei mir eine CPU Auslastung von bis 99 %, Explorer.exe.
Hier der Logfile von HIJACKTHIS:
Logfile of HijackThis v1.98.2
Scan saved at 20:07:26, on 25.10.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C
rogrammeSygateSPFsmc.exe
C:WINDOWSsystem32spoolsv.exe
C
rogrammeGemeinsame DateienSymantec SharedccSetMgr.exe
C
rogrammeNorton AntiVirusnavapsvc.exe
C
rogrammeNorton AntiVirusAdvToolsNPROTECT.EXE
C:WINDOWSsystem32nvsvc32.exe
C
rogrammeNorton AntiVirusSAVScan.exe
C:WINDOWSSystem32svchost.exe
C
rogrammeGemeinsame DateienSymantec SharedccEvtMgr.exe
C
rogrammeGemeinsame DateienSymantec SharedSecurity CenterSymWSC.exe
C:WINDOWSsystem32RunDll32.exe
C
rogrammeGemeinsame DateienSymantec SharedccApp.exe
C:WINDOWSsystem32RUNDLL32.EXE
D
rogrammePopup Ad FilterPopFilter.exe
C:WINDOWSsystem32wscntfy.exe
C
rogrammeSpywareGuardsgmain.exe
C
rogrammeSpywareGuardsgbhp.exe
C
rogrammeInternet Exploreriexplore.exe
C:WINDOWSsystem32taskmgr.exe
C:WINDOWSexplorer.exe
D:HijackThis.exe
C
rogrammeMessengermsmsgs.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WINDOWSPCHealthHelpCtrSystempanelsblank.htm
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak =
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:WINDOWSlocalNRD.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C
rogrammeYahoo!CompanionInstallscpnycomp5_3_12_0.dll
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C
rogrammeAdobeAcrobat 5.0ReaderActiveXAcroIEHelper.ocx
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C
rogrammeSpywareGuarddlprotect.dll
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:WINDOWSwsem301.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C
rogrammeNorton AntiVirusNavShExt.dll
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C
rogrammeNorton AntiVirusNavShExt.dll
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C
rogrammeYahoo!CompanionInstallscpnycomp5_3_12_0.dll
O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - (no file)
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM..Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM..Run: [ccApp] "C
rogrammeGemeinsame DateienSymantec SharedccApp.exe"
O4 - HKLM..Run: [Advanced Tools Check] C
ROGRA~1NORTON~1AdvToolsADVCHK.EXE
O4 - HKLM..Run: [SmcService] C
ROGRA~1SygateSPFsmc.exe -startgui
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [LogitechVideoRepair] C
rogrammeLogitechVideoISStart.exe
O4 - HKLM..Run: [LogitechVideoTray] C
rogrammeLogitechVideoLogiTray.exe
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit
O4 - HKCU..Run: [Popup Ad Filter] D
rogrammePopup Ad FilterPopFilter.exe
O4 - Startup: SpywareGuard.lnk = C
rogrammeSpywareGuardsgmain.exe
O4 - Global Startup: Microsoft Office.lnk = C
rogrammeMicrosoft OfficeOffice10OSA.EXE
O8 - Extra context menu item: Allow Popups - D
rogrammePopup Ad FilterWhiteGetUrl.js
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C
ROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
O9 - Extra button: concept/design's onlineTV - {541830BD-DDCA-4725-B14F-A845BB5D0812} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
rogrammeMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
rogrammeMessengermsmsgs.exe
O12 - Plugin for .spop: C
rogrammeInternet ExplorerPluginsNPDocBox.dll
O16 - DPF: Yahoo! Hearts -
O16 - DPF: Yahoo! Pool 2 -
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} (Installer Class) -
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) -
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) -
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) -
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) -
O17 - HKLMSystemCCSServicesTcpip..{5F8B00C6-6D62-4644-92D9-08F2A9623C8E}: NameServer = 194.97.173.124 194.97.173.125
Dank und Gruß
Andreas
auch bei mir eine CPU Auslastung von bis 99 %, Explorer.exe.
Hier der Logfile von HIJACKTHIS:
Logfile of HijackThis v1.98.2
Scan saved at 20:07:26, on 25.10.2004
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C
C:WINDOWSsystem32spoolsv.exe
C
C
C
C:WINDOWSsystem32nvsvc32.exe
C
C:WINDOWSSystem32svchost.exe
C
C
C:WINDOWSsystem32RunDll32.exe
C
C:WINDOWSsystem32RUNDLL32.EXE
D
C:WINDOWSsystem32wscntfy.exe
C
C
C
C:WINDOWSsystem32taskmgr.exe
C:WINDOWSexplorer.exe
D:HijackThis.exe
C
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
Please,
Anmelden
or
Registrieren
to view URLs content!
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
Please,
Anmelden
or
Registrieren
to view URLs content!
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
Please,
Anmelden
or
Registrieren
to view URLs content!
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Local Page = C:WINDOWSPCHealthHelpCtrSystempanelsblank.htm
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak =
Please,
Anmelden
or
Registrieren
to view URLs content!
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O2 - BHO: BHObj Class - {00000010-6F7D-442C-93E3-4A4827C2E4C8} - (no file)
O2 - BHO: LocalNRDObj Class - {00320615-B6C2-40A6-8F99-F1C52D674FAD} - C:WINDOWSlocalNRD.dll
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C
O2 - BHO: SpywareGuardDLBLOCK.CBrowserHelper - {4A368E80-174F-4872-96B5-0B27DDD11DB2} - C
O2 - BHO: BHObj Class - {8F4E5661-F99E-4B3E-8D85-0EA71C0748E4} - C:WINDOWSwsem301.dll
O2 - BHO: CNavExtBho Class - {BDF3E430-B101-42AD-A544-FADC6B084872} - C
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C
O3 - Toolbar: &Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C
O3 - Toolbar: YourSiteBar - {86227D9C-0EFE-4f8a-AA55-30386A3F5686} - (no file)
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM..Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM..Run: [ccApp] "C
O4 - HKLM..Run: [Advanced Tools Check] C
O4 - HKLM..Run: [SmcService] C
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [LogitechVideoRepair] C
O4 - HKLM..Run: [LogitechVideoTray] C
O4 - HKLM..Run: [NvMediaCenter] RUNDLL32.EXE C:WINDOWSsystem32NvMcTray.dll,NvTaskbarInit
O4 - HKCU..Run: [Popup Ad Filter] D
O4 - Startup: SpywareGuard.lnk = C
O4 - Global Startup: Microsoft Office.lnk = C
O8 - Extra context menu item: Allow Popups - D
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C
O9 - Extra button: Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger - {4528BBE0-4E08-11D5-AD55-00010333D0AD} - (no file)
O9 - Extra button: concept/design's onlineTV - {541830BD-DDCA-4725-B14F-A845BB5D0812} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
O12 - Plugin for .spop: C
O16 - DPF: Yahoo! Hearts -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: Yahoo! Pool 2 -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: {771A1334-6B08-4A6B-AEDC-CF994BA2CEBE} (Installer Class) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: {8A94C905-FF9D-43B6-8708-F0F22D22B1CB} (Wwlaunch Control) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: {9CCE3B43-4DE0-4236-A84E-108CA848EE6A} (WebCam Control) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: {A17E30C4-A9BA-11D4-8673-60DB54C10000} (YahooYMailTo Class) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: {F04A8AE2-A59D-11D2-8792-00C04F8EF29D} (Hotmail Attachments Control) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O16 - DPF: {FAE74270-E5EE-49C3-B816-EA8B4D55F38F} (H2hPool Control) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O17 - HKLMSystemCCSServicesTcpip..{5F8B00C6-6D62-4644-92D9-08F2A9623C8E}: NameServer = 194.97.173.124 194.97.173.125
Dank und Gruß
Andreas