J
jack_12
Guest
Es öffnen sich immer komische Startseiten. Der IE merkt sich nie meine eingegebene Startseite. Und es kommt fast immer boredelife vor meiner eingegebenen Site. Habe mit hijackthis unten stehendes kog file erstellt. Was muss ich jetzt davon rauslöschen?
Logfile of HijackThis v1.97.7
Scan saved at 14:41:24, on 20.03.2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINNTSystem32smss.exe
C:WINNTsystem32winlogon.exe
C:WINNTsystem32services.exe
C:WINNTsystem32lsass.exe
C:WINNTsystem32svchost.exe
C:WINNTsystem32spoolsv.exe
C:WINNTSystem32Ati2evxx.exe
C
rogrammeMcAfeeMcAfee VirusScanAvsynmgr.exe
C
rogrammeAVPersonalAVWUPSRV.EXE
C:WINNTSystem32svchost.exe
C:WINNTsystem32regsvc.exe
C:WINNTSystem32r_server.exe
C:WINNTsystem32MSTask.exe
C:WINNTSystem32WBEMWinMgmt.exe
C
rogrammeMcAfeeMcAfee VirusScanVsStat.exe
C
rogrammeMcAfeeMcAfee VirusScanVshwin32.exe
C
rogrammeGemeinsame DateienNetwork AssociatesMcShieldMcshield.exe
C
rogrammeMcAfeeMcAfee VirusScanAvconsol.exe
C:WINNTExplorer.EXE
C:WINNTSystem32RunDll32.exe
C
rogrammeATI TechnologiesATI Control Panelatiptaxx.exe
C
rogrammeElaborate BytesCloneCDCloneCDTray.exe
C
rogrammeWinamp3winampa.exe
C
rogrammeD-Toolsdaemon.exe
C
rogrammeTelefonCDOtbStart.EXE
C
ROGRA~1A4TechMouseAmoumain.exe
C
rogrammeMcAfeeMcAfee Shared ComponentsInstant UpdaterRuLaunch.exe
C
rogrammeInterVideoCommonBinWinCinemaMgr.exe
C
rogrammeInternet ExplorerIEXPLORE.EXE
C
ownloadsHijackThishijackthis1977HijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet Explorer,SearchURL =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page =
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar =
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak =
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP =
R1 - HKCUSoftwareMicrosoftInternet Explorer,Search =
R1 - HKLMSoftwareMicrosoftInternet Explorer,Search =
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C
rogrammeAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c
rogrammegooglegoogletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C
rogrammeMcAfeeMcAfee VirusScanVSCShellExtension.dll
O3 - Toolbar: (no name) - {3C624F62-E7D9-4154-9C93-F3489069FD52} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c
rogrammegooglegoogletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINNTSystem32msdxm.ocx
O4 - HKLM..Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM..Run: [ATIPTA] C
rogrammeATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [CloneCDElbyCDFL] "C
rogrammeElaborate BytesCloneCDElbyCheck.exe" /L ElbyCDFL
O4 - HKLM..Run: [CloneCDTray] "C
rogrammeElaborate BytesCloneCDCloneCDTray.exe"
O4 - HKLM..Run: [WinampAgent] "C
rogrammeWinamp3winampa.exe"
O4 - HKLM..Run: [DAEMON Tools-1033] "C
rogrammeD-Toolsdaemon.exe" -lang 1033
O4 - HKLM..Run: [OtbStart] C
rogrammeTelefonCDOtbStart.EXE
O4 - HKLM..Run: [WheelMouse] C
ROGRA~1A4TechMouseAmoumain.exe
O4 - HKLM..Run: [CloneDVDElbyDelay] "C
rogrammeElaborate BytesCloneDVDElbyCheck.exe" /L ElbyDelay
O4 - HKLM..Run: [NeroFilterCheck] C:WINNTsystem32NeroCheck.exe
O4 - HKLM..Run: [SBHC] C
rogrammeSuperBarsbhc.exe
O4 - HKLM..Run: [sys] regedit -s sysdllwm.reg
O4 - HKCU..Run: [McAfee.InstantUpdate.Monitor] "C
rogrammeMcAfeeMcAfee Shared ComponentsInstant UpdaterRuLaunch.exe" /STARTMONITOR
O4 - HKCU..Run: [winlogon] c:winntwinlogon.exe
O4 - HKCU..Run: [16zgtws1h2] C:WINNTxxxv8j61nc.exe
O4 - HKCU..Run: [2a3dv5h7fe] C:WINNTjgbr8heb1s.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C
rogrammeInterVideoCommonBinWinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C
rogrammeMicrosoft OfficeOfficeOSA9.EXE
O8 - Extra context menu item: &Google Search - res://C
rogrammeGoogleGoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C
rogrammeGoogleGoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C
rogrammeGoogleGoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C
rogrammeGoogleGoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
O17 - HKLMSystemCCSServicesTcpip..{FCCDDA0F-B5D1-428E-B6D3-1F4292A2B52E}: NameServer = 195.58.160.2,195.58.160.3,195.58.161.3,195.3.96.67,195.3.96.68
O19 - User stylesheet: C:WINNTWebtips.ini
O19 - User stylesheet: C:WINNThh.htt (HKLM)
Logfile of HijackThis v1.97.7
Scan saved at 14:41:24, on 20.03.2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINNTSystem32smss.exe
C:WINNTsystem32winlogon.exe
C:WINNTsystem32services.exe
C:WINNTsystem32lsass.exe
C:WINNTsystem32svchost.exe
C:WINNTsystem32spoolsv.exe
C:WINNTSystem32Ati2evxx.exe
C
C
C:WINNTSystem32svchost.exe
C:WINNTsystem32regsvc.exe
C:WINNTSystem32r_server.exe
C:WINNTsystem32MSTask.exe
C:WINNTSystem32WBEMWinMgmt.exe
C
C
C
C
C:WINNTExplorer.EXE
C:WINNTSystem32RunDll32.exe
C
C
C
C
C
C
C
C
C
C
R1 - HKCUSoftwareMicrosoftInternet Explorer,SearchURL =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
Please,
Anmelden
or
Registrieren
to view URLs content!
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak =
Please,
Anmelden
or
Registrieren
to view URLs content!
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R1 - HKCUSoftwareMicrosoftInternet Explorer,Search =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)R1 - HKLMSoftwareMicrosoftInternet Explorer,Search =
Please,
Anmelden
or
Registrieren
to view URLs content!
(obfuscated)O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C
O3 - Toolbar: (no name) - {3C624F62-E7D9-4154-9C93-F3489069FD52} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINNTSystem32msdxm.ocx
O4 - HKLM..Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM..Run: [ATIPTA] C
O4 - HKLM..Run: [CloneCDElbyCDFL] "C
O4 - HKLM..Run: [CloneCDTray] "C
O4 - HKLM..Run: [WinampAgent] "C
O4 - HKLM..Run: [DAEMON Tools-1033] "C
O4 - HKLM..Run: [OtbStart] C
O4 - HKLM..Run: [WheelMouse] C
O4 - HKLM..Run: [CloneDVDElbyDelay] "C
O4 - HKLM..Run: [NeroFilterCheck] C:WINNTsystem32NeroCheck.exe
O4 - HKLM..Run: [SBHC] C
O4 - HKLM..Run: [sys] regedit -s sysdllwm.reg
O4 - HKCU..Run: [McAfee.InstantUpdate.Monitor] "C
O4 - HKCU..Run: [winlogon] c:winntwinlogon.exe
O4 - HKCU..Run: [16zgtws1h2] C:WINNTxxxv8j61nc.exe
O4 - HKCU..Run: [2a3dv5h7fe] C:WINNTjgbr8heb1s.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C
O4 - Global Startup: Microsoft Office.lnk = C
O8 - Extra context menu item: &Google Search - res://C
O8 - Extra context menu item: Backward &Links - res://C
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C
O8 - Extra context menu item: Si&milar Pages - res://C
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) -
Please,
Anmelden
or
Registrieren
to view URLs content!
O17 - HKLMSystemCCSServicesTcpip..{FCCDDA0F-B5D1-428E-B6D3-1F4292A2B52E}: NameServer = 195.58.160.2,195.58.160.3,195.58.161.3,195.3.96.67,195.3.96.68
O19 - User stylesheet: C:WINNTWebtips.ini
O19 - User stylesheet: C:WINNThh.htt (HKLM)