Ich hoffe mal ich hab alles richtig gemacht mit dem Ersetzen der persönlichen Informationen und so.
Zitat:
logfile of trend micro HijackThis v2.0.2
scan saved at 15:00:13, on 28.01.2010
platform: Windows xp sp2 (winnt 5.01.2600)
msie: Internet explorer v6.00 sp2 (6.00.2900.2180)
boot mode: Normal
running processes:
C:\windows\system32\smss.exe
c:\windows\system32\winlogon.exe
c:\windows\system32\services.exe
c:\windows\system32\lsass.exe
c:\windows\system32\svchost.exe
c:\windows\system32\svchost.exe
c:\windows\system32\spoolsv.exe
c:\programme\avira\antivir desktop\sched.exe
c:\programme\avira\antivir desktop\avguard.exe
c:\programme\gemeinsame dateien\apple\mobile device support\bin\applemobiledeviceservice.exe
c:\programme\bonjour\mdnsresponder.exe
c:\programme\icq6toolbar\icq service.exe
c:\windows\system32\nvsvc32.exe
c:\windows\system32\svchost.exe
c:\programme\ipod\bin\ipodservice.exe
c:\windows\system32\winlogon.exe
c:\windows\explorer.exe
c:\programme\avmwlanstick\fritzwlanmini.exe
c:\programme\avira\antivir desktop\avgnt.exe
c:\programme\itunes\ituneshelper.exe
c:\windows\rthdcpl.exe
c:\programme\canon\myprinter\bjmyprt.exe
c:\windows\system32\ctfmon.exe
c:\programme\messenger\msmsgs.exe
c:\programme\openoffice.org 3\program\soffice.exe
c:\windows\alcfdrtm.exe
c:\programme\openoffice.org 3\program\soffice.bin
c:\programme\avira\antivir desktop\avcenter.exe
c:\programme\mozilla firefox\firefox.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\msiexec.exe
c:\windows\system32\wuauclt.exe
c:\programme\avira\antivir desktop\avscan.exe
c:\dokumente und einstellungen\xxx\eigene dateien\downloads\hijackthis.exe
r0 - hkcu\software\microsoft\internet explorer\main,start page = h**p://start.icq.com/
r1 - hkcu\software\microsoft\windows\currentversion\internet settings,proxyoverride = *.local
r3 - urlsearchhook: (no name) - - (no file)
r3 - urlsearchhook: Icqtoolbar - {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\programme\icq6toolbar\icqtoolbar.dll
o3 - toolbar: Icqtoolbar - {855f3b16-6d32-4fe6-8a56-bbb695989046} - c:\programme\icq6toolbar\icqtoolbar.dll
o4 - hklm\..\run: [avmwlanclient] c:\programme\avmwlanstick\fritzwlanmini.exe
o4 - hklm\..\run: [avgnt] "c:\programme\avira\antivir desktop\avgnt.exe" /min
o4 - hklm\..\run: [quicktime task] "c:\programme\quicktime\qttask.exe" -atboottime
o4 - hklm\..\run: [ituneshelper] "c:\programme\itunes\ituneshelper.exe"
o4 - hklm\..\run: [rthdcpl] rthdcpl.exe
o4 - hklm\..\run: [skytel] skytel.exe
o4 - hklm\..\run: [alcmtr] alcmtr.exe
o4 - hklm\..\run: [nvcpldaemon] rundll32.exe c:\windows\system32\nvcpl.dll,nvstartup
o4 - hklm\..\run: [nwiz] nwiz.exe /install
o4 - hklm\..\run: [canonmyprinter] c:\programme\canon\myprinter\bjmyprt.exe /logon
o4 - hklm\..\run: [canonsolutionmenu] c:\programme\canon\solutionmenu\cnslmain.exe /logon
o4 - hkcu\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe
o4 - hkcu\..\run: [msmsgs] "c:\programme\messenger\msmsgs.exe" /background
o4 - hkus\s-1-5-19\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'lokaler dienst')
o4 - hkus\s-1-5-20\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'netzwerkdienst')
o4 - hkus\s-1-5-21-515967899-2049760794-725345543-1005\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'xxx')
o4 - hkus\s-1-5-18\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'system')
o4 - hkus\.default\..\run: [ctfmon.exe] c:\windows\system32\ctfmon.exe (user 'default user')
o4 - s-1-5-21-515967899-2049760794-725345543-1005 startup: Openoffice.org 3.1.lnk = c:\programme\openoffice.org 3\program\quickstart.exe (user 'xxx')
o4 - startup: Openoffice.org 3.1.lnk = c:\programme\openoffice.org 3\program\quickstart.exe
o9 - extra button: Icq6 - {e59eb121-f339-4851-a3ba-fe49c35617c2} - c:\programme\icq6.5\icq.exe
o9 - extra 'tools' menuitem: Icq6 - {e59eb121-f339-4851-a3ba-fe49c35617c2} - c:\programme\icq6.5\icq.exe
o9 - extra button: Messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\programme\messenger\msmsgs.exe
o9 - extra 'tools' menuitem: Windows messenger - {fb5f1910-f110-11d2-bb9e-00c04f795683} - c:\programme\messenger\msmsgs.exe
o23 - service: Avira antivir planer (antivirschedulerservice) - avira gmbh - c:\programme\avira\antivir desktop\sched.exe
o23 - service: Avira antivir guard (antivirservice) - avira gmbh - c:\programme\avira\antivir desktop\avguard.exe
o23 - service: Apple mobile device - apple inc. - c:\programme\gemeinsame dateien\apple\mobile device support\bin\applemobiledeviceservice.exe
o23 - service: Bonjour-dienst (bonjour service) - apple inc. - c:\programme\bonjour\mdnsresponder.exe
o23 - service: Icq service - unknown owner - c:\programme\icq6toolbar\icq service.exe
o23 - service: Ipod-dienst (ipod service) - apple inc. - c:\programme\ipod\bin\ipodservice.exe
o23 - service: Nvidia display driver service (nvsvc) - nvidia corporation - c:\windows\system32\nvsvc32.exe
--
end of file - 4905 bytes
|
Die genauen Pfade sehen so aus:
E:\Spiele\Age an Halifax\mythxpak.exe
E:\System Volume Information\_restore{E53F11B2-4CAB-4DC5-97C7-B334077C89EE}\RP40\A0006431.exe
__________________