Hallo
Ich hab das unwohle Gefühl das ein Virus auf meinem PC ist... weil Antivir hat 16 Viren gefunden...habe sie zwar gelöscht aber will sichergehen das alles weg ist
Hier die Log-File:
Logfile of Trend Micro HiJackThis v2.0.2
Scan saved at 00:20:33, on 27.09.2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe
C:\xampp\apache\bin\apache.exe
C:\Programme\Gemeinsame Dateien\Autodesk Shared\Service\AdskScSrv.exe
C:\Programme\Bonjour\mDNSResponder.exe
C:\Programme\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32serve r.exe
C:\Programme\Marvell\61xx\Apache2\bin\Apache.exe
c:\xampp\mysql\bin\mysqld-nt.exe
C:\Programme\Marvell\61xx\Apache2\bin\Apache.exe
C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\xampp\apache\bin\apache.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\Programme\CyberLink\Shared Files\RichVideo.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programme\Java\jre1.6.0_07\bin\jusched.exe
C:\WINDOWS\system32\RUNDLL32.EXE
C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programme\SyncroSoft\Pos\H2O\cledx.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\DAEMON Tools Lite\daemon.exe
C:\Programme\Gemeinsame Dateien\Nero\Lib\NMBgMonitor.exe
C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe
C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\NOTEPAD.EXE
C:\Programme\Windows Live\Messenger\msnmsgr.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://www2.iesearch.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = *.local
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll
O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Programme\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LanguageShortcut] C:\Programme\CyberLink\PowerDVD\Language\Language. exe
O4 - HKLM\..\Run: [NBKeyScan] "C:\Programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_07\bin\jusched.exe "
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [RemoteControl] C:\Programme\CyberLink\PowerDVD\PDVDServ.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [H2O] C:\Programme\SyncroSoft\Pos\H2O\cledx.exe
O4 - HKLM\..\Run: [Amok Mode Dupe Platform] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Hold Trust Amok Mode\up bash.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programme\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKCU\..\Run: [ICQ] "C:\Programme\ICQ6\ICQ.exe" silent
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Nero\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKCU\..\Run: [Steam] "C:\Programme\Steam\Steam.exe" -silent
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [ball four] C:\DOKUME~1\***\ANWEND~1\FLAWMU~1\PILE DEFY THIRD.exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\RunOnce: [SpybotDeletingD6349] cmd /c del "C:\Programme\NetPumper\NPNetPumper_Application.dl l"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8129] command /c del "C:\Programme\NetPumper\NPNetPumper_Audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1572] cmd /c del "C:\Programme\NetPumper\NPNetPumper_Audio.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7616] command /c del "C:\Programme\NetPumper\NPNetPumper_Video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3052] cmd /c del "C:\Programme\NetPumper\NPNetPumper_Video.dll"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4130] command /c del "C:\Programme\NetPumper\shutdown.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1589] cmd /c del "C:\Programme\NetPumper\shutdown.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5382] command /c del "C:\Programme\NetPumper\TurnLog.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8348] cmd /c del "C:\Programme\NetPumper\TurnLog.exe"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7312] command /c del "C:\Programme\NetPumper\help\commonheadfoot.ht m"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4243] cmd /c del "C:\Programme\NetPumper\help\commonheadfoot.ht m"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6652] command /c del "C:\Programme\NetPumper\help\compat.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD757] cmd /c del "C:\Programme\NetPumper\help\compat.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6011] command /c del "C:\Programme\NetPumper\help\details.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1375] cmd /c del "C:\Programme\NetPumper\help\details.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1777] command /c del "C:\Programme\NetPumper\help\features.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4241] cmd /c del "C:\Programme\NetPumper\help\features.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9825] command /c del "C:\Programme\NetPumper\help\index.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4049] cmd /c del "C:\Programme\NetPumper\help\index.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8966] command /c del "C:\Programme\NetPumper\help\mainwin.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8719] cmd /c del "C:\Programme\NetPumper\help\mainwin.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1014] command /c del "C:\Programme\NetPumper\help\prefwindow.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3223] cmd /c del "C:\Programme\NetPumper\help\prefwindow.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1266] command /c del "C:\Programme\NetPumper\help\register.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD9981] cmd /c del "C:\Programme\NetPumper\help\register.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB4080] command /c del "C:\Programme\NetPumper\help\schedwin.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD2255] cmd /c del "C:\Programme\NetPumper\help\schedwin.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6557] command /c del "C:\Programme\NetPumper\help\tips.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingD8121] cmd /c del "C:\Programme\NetPumper\help\tips.htm"
O4 - HKCU\..\RunOnce: [SpybotDeletingB1721] command /c del "C:\Programme\NetPumper\help\nphelp.css"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5313] cmd /c del "C:\Programme\NetPumper\help\nphelp.css"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2672] command /c del "C:\Programme\NetPumper\help\images\apllimit.g if"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1944] cmd /c del "C:\Programme\NetPumper\help\images\apllimit.g if"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6516] command /c del "C:\Programme\NetPumper\help\images\bandwidthpanel .gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7654] cmd /c del "C:\Programme\NetPumper\help\images\bandwidthpanel .gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6124] command /c del "C:\Programme\NetPumper\help\images\buttons.gi f"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3524] cmd /c del "C:\Programme\NetPumper\help\images\buttons.gi f"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6365] command /c del "C:\Programme\NetPumper\help\images\cmdadd.gif "
O4 - HKCU\..\RunOnce: [SpybotDeletingD1145] cmd /c del "C:\Programme\NetPumper\help\images\cmdadd.gif "
O4 - HKCU\..\RunOnce: [SpybotDeletingD1869] cmd /c del "C:\Programme\NetPumper\help\images\cmdaddtoschedu le.gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8041] command /c del "C:\Programme\NetPumper\help\images\cmddetails.gif "
O4 - HKCU\..\RunOnce: [SpybotDeletingD2800] cmd /c del "C:\Programme\NetPumper\help\images\cmddetails.gif "
O4 - HKCU\..\RunOnce: [SpybotDeletingB5756] command /c del "C:\Programme\NetPumper\help\images\cmdeditschedul e.gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1596] cmd /c del "C:\Programme\NetPumper\help\images\cmdeditschedul e.gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingB2738] command /c del "C:\Programme\NetPumper\help\images\cmdfolder. gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingD106] cmd /c del "C:\Programme\NetPumper\help\images\cmdfolder. gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8527] command /c del "C:\Programme\NetPumper\help\images\cmdhelp.gi f"
O4 - HKCU\..\RunOnce: [SpybotDeletingD3028] cmd /c del "C:\Programme\NetPumper\help\images\cmdhelp.gi f"
O4 - HKCU\..\RunOnce: [SpybotDeletingB9394] command /c del "C:\Programme\NetPumper\help\images\cmdopen.gi f"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5135] cmd /c del "C:\Programme\NetPumper\help\images\cmdopen.gi f"
O4 - HKCU\..\RunOnce: [SpybotDeletingB3002] command /c del "C:\Programme\NetPumper\help\images\cmdopenfolder. gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingD5472] cmd /c del "C:\Programme\NetPumper\help\images\cmdopenfolder. gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8710] command /c del "C:\Programme\NetPumper\help\images\cmdpause.g if"
O4 - HKCU\..\RunOnce: [SpybotDeletingD4851] cmd /c del "C:\Programme\NetPumper\help\images\cmdpause.g if"
O4 - HKCU\..\RunOnce: [SpybotDeletingB6437] command /c del "C:\Programme\NetPumper\help\images\cmdprefs.g if"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1421] cmd /c del "C:\Programme\NetPumper\help\images\cmdprefs.g if"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5441] command /c del "C:\Programme\NetPumper\help\images\cmdremove. gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingD1255] cmd /c del "C:\Programme\NetPumper\help\images\cmdremove. gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingB7625] command /c del "C:\Programme\NetPumper\help\images\cmdresume. gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingD6552] cmd /c del "C:\Programme\NetPumper\help\images\cmdresume. gif"
O4 - HKCU\..\RunOnce: [SpybotDeletingB5113] command /c del "C:\Programme\NetPumper\help\images\cmdselectall.g if"
O4 - HKCU\..\RunOnce: [SpybotDeletingD7968] cmd /c del "C:\Programme\NetPumper\help\images\cmdselectall.g if"
O4 - HKCU\..\RunOnce: [SpybotDeletingB8451] command /c del "C:\Programme\NetPumper\help\images\detailwin-wide.gif"
KHoRneR Gast |