Hallo
Meine Internetstartseite und meine Favoriten werden nach jedem Start von irgendeinem Programm umbenannt. Mal WWW.---woods.com oder C:\WINDOWS\_h.html. Wer kann mir helfen? Habe jetzt schon mal 2 verschiedene Virenscanner F-secure, antivir und adaware drüberlaufen lassen, Keine Angaben von den Programmen zu meinem Problem.
Hier nun mein Hijack logfile:
Logfile of HijackThis v1.97.7
Scan saved at 09:55:36, on 20.10.04
Platform: Windows 98 SE (Win9x 4.10.2222A)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\SYSTEM\KERNEL32.DLL
C:\WINDOWS\SYSTEM\MSGSRV32.EXE
C:\WINDOWS\SYSTEM\MPREXE.EXE
C:\WINDOWS\SYSTEM\mmtask.tsk
C:\WINDOWS\SYSTEM\MSTASK.EXE
D:\SICHERHEIT\F-SECURE\COMMON\FSMA32.EXE
D:\SICHERHEIT\F-SECURE\COMMON\FSMB32.EXE
C:\WINDOWS\EXPLORER.EXE
D:\SICHERHEIT\F-SECURE\BACKWEB\4476822\PROGRAM\FSBWSYS.EXE
D:\SICHERHEIT\F-SECURE\COMMON\FCH32.EXE
D:\SICHERHEIT\F-SECURE\BACKWEB\4476822\PROGRAM\BACKWEB-4476822.EXE
D:\SICHERHEIT\F-SECURE\COMMON\FAMEH32.EXE
D:\SICHERHEIT\F-SECURE\ANTI-VIRUS\FSGK32.EXE
D:\SICHERHEIT\F-SECURE\FWES\PROGRAM\FSDFWD.EXE
C:\WINDOWS\TASKMON.EXE
C:\WINDOWS\SYSTEM\SYSTRAY.EXE
D:\SICHERHEIT\F-SECURE\ANTI-VIRUS\FSSM32.EXE
D:\SICHERHEIT\F-SECURE\ANTI-VIRUS\FSAV32.EXE
C:\WINDOWS\SYSTEM\LOADING.EXE
D:\SICHERHEIT\F-SECURE\COMMON\FSM32.EXE
C:\WINDOWS\SYSTEM\RNAAPP.EXE
C:\WINDOWS\SYSTEM\TAPISRV.EXE
C:\PROGRAMME\QUICKNET ISDN\CAPICTRL.EXE
C:\WINDOWS\SYSTEM\WMIEXE.EXE
D:\OFFICE\OFFICE\WINWORD.EXE
C:\WINDOWS\SYSTEM\SPOOL32.EXE
D:\SICHERHEIT\HIJACKTHIS.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = C:\WINDOWS\_s.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = C:\WINDOWS\_h.html
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.---hit.net/
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = C:\WINDOWS\_h.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = C:\WINDOWS\_h.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = C:\WINDOWS\_s.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = C:\WINDOWS\_h.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = C:\WINDOWS\_h.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = C:\WINDOWS\_h.html
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = C:\WINDOWS\_h.html
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\_s.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,SearchAssistant = C:\WINDOWS\_s.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,(Default) = C:\WINDOWS\_s.html
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX
O4 - HKLM\..\Run: [ScanRegistry] C:\WINDOWS\scanregw.exe /autorun
O4 - HKLM\..\Run: [TaskMonitor] C:\WINDOWS\taskmon.exe
O4 - HKLM\..\Run: [SystemTray] systray.exe
O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\Run: [MSUpdSrv] msupdsrv.exe
O4 - HKLM\..\Run: [ControlPanel] C:\WINDOWS\SYSTEM\twink64.exe internat.dll,LoadKeyboardProfile
O4 - HKLM\..\Run: [Windows Shell Library Loader] loading shell32.dll /c /set
O4 - HKLM\..\Run: [F-Secure Manager] "D:\SICHERHEIT\F-SECURE\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "D:\SICHERHEIT\F-SECURE\TNB\TNBUtil.exe" /CHECKALL
O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme
O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe
O4 - HKLM\..\RunServices: [F-Secure Management Agent] D:\SICHERHEIT\F-SECURE\Common\FSMA32.EXE
O4 - HKCU\..\Run: [winltmpv] c:\windows\winln.exe
O4 - Startup: CAPI Control.lnk = C:\Programme\QuickNet ISDN\CAPICTRL.EXE
O4 - Startup: Microsoft Office.lnk = D:\Office\Office\OSA9.EXE
O4 - Global Startup: F-Secure Internet Security 2004.lnk = D:\Sicherheit\F-secure\backweb\4476822\Program\backweb-4476822.exe
O8 - Extra context menu item: Zur Filterliste hinzufügen (WebWasher) - http://-Web.Washer-/ie_add
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O15 - Trusted Zone: *.windupdates.com
O15 - Trusted Zone: *.skoobidoo.com
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Kann mir jemand helfen?
Viruskid Gast |