Hmmm hier ist mal das neuste Logfile. Hab nachdem ich mein System mal Mit dem Tool überprüft hab einige Einträge gelöscht, wovon einige wieder erschienen sind...
Hoffe dass ich das ganze noch hinkriege ohne den ganzen Rechner auf den Kopf zu stellen... :/
Logfile of HijackThis v1.99.1
Scan saved at 10:48:08, on 03.01.2008
Platform: Windows 2003 SP1 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 SP1 (6.00.3790.1830)
Running processes:
E:\WINDOWS\SOUNDMAN.EXE
E:\Programme (x86)\Gemeinsame Dateien\{0449F9C4-0711-1033--002b}\Update.exe
E:\WINDOWS\SysWOW64\rundll32.exe
E:\Programme (x86)\Spybot - Search & Destroy\TeaTimer.exe
E:\WINDOWS\SysWOW64\ctfmon.exe
E:\Programme (x86)\Eraser\eraser.exe
E:\Programme (x86)\WinAble\winable.exe
E:\Programme (x86)\Words\Words.exe
E:\Documents and Settings\Administrator\Application Data\WinTouch\WinTouch.exe
E:\Programme (x86)\QdrPack\QdrPack11.exe
E:\Programme (x86)\Internet Explorer\iexplore.exe
E:\Programme (x86)\Last.fm\LastFMHelper.exe
E:\Program Files (x86)\MessengerPlus! 3\MsgPlus.exe
E:\Program Files (x86)\Java\jre1.5.0_05\bin\jusched.exe
E:\Program Files (x86)\QuickTime\qttask.exe
E:\Programme (x86)\DAEMON Tools\daemon.exe
E:\Programme (x86)\CyberLink\PowerDVD\PDVDServ.exe
E:\Programme (x86)\Winamp\winampa.exe
C:\Program Files (x86)\ICQLite\ICQLite.exe
E:\WINDOWS\SysWOW64\drivers\CDAC11BA.EXE
E:\Programme (x86)\Internet Explorer\iexplore.exe
E:\WINDOWS\xplxbaqb.exe
E:\Programme (x86)\Internet Explorer\iexplore.exe
E:\WINDOWS\SysWow64\service.exe
E:\Programme (x86)\Last.fm\LastFM.exe
E:\Programme (x86)\mozilla.org\Mozilla\mozilla.exe
E:\hijackthis_199\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar =
http://www.oixwnrdjyloeev.com/7396Wf...Pwm7kmvQs.html
F2 - REG:system.ini: UserInit=userinit
O4 - HKLM\..\Run: [MessengerPlus3] "E:\Program Files (x86)\MessengerPlus! 3\MsgPlus.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files (x86)\Java\jre1.5.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "E:\Program Files (x86)\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [DAEMON Tools] "E:\Programme (x86)\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [RemoteControl] "E:\Programme (x86)\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [WinampAgent] E:\Programme (x86)\Winamp\winampa.exe
O4 - HKLM\..\Run: [ICQ Lite] "C:\Program Files (x86)\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run: [nsh6244c] RUNDLL32.EXE w0c23623.dll,n 003624490000000a0c23623
O4 - HKLM\..\Run: [runner1] E:\WINDOWS\mrofinu1000137.exe 61A847B5BBF72813329B385771FE01F0B3E35B6638993F4661 AA4EBD86D67C56389B284534F310F3D1DC7E4638EE323A1580 6F97BDE4417E6FD967002BA754E2C2832213319C26033AAC
O4 - HKLM\..\Run: [SfKg6w] E:\WINDOWS\xplxbaqb.exe
O4 - HKLM\..\Run: [WinTouch] E:\Programme (x86)\WinTouch\WinTouch.exe
O4 - HKLM\..\Run: [ACTX1] E:\WINDOWS\v1201.exe
O4 - HKLM\..\Run: [webHancer Agent] E:\Programme (x86)\webHancer\Programs\whagent.exe
O4 - HKLM\..\Run: [Heck Bows Upload Test] E:\Documents and Settings\All Users\Application Data\REGS HIDE HECK BOWS\intranurb.exe
O4 - HKLM\..\Run: [{ZN}] E:\System Volume Information\_restore{58FAD2F0-0F06-470A-AE0B-7B2B74F5A090}\RP503\A0101910.exe SKY008
O4 - HKLM\..\Run: [MDNS] E:\WINDOWS\SysWow64\service.exe
O4 - HKLM\..\Run: [p2p networking] p2pnetworking.exe
O4 - HKLM\..\Run: [{0449F9C4-0711-1033-9-9002b}] "E:\Programme (x86)\Gemeinsame Dateien\{0449F9C4-0711-1033-9-9002b}\Update.exe" mc-110-12-0000140
O4 - HKLM\..\Run: [windows] C:\\windows_e57.exe
O4 - HKLM\..\Run: [newname] C:\\nwnmff_e57.exe
O4 - HKLM\..\Run: [defender] C:\\dfndrff_e46.exe
O4 - HKLM\..\Run: [keyboard] C:\\kybrdff_e46.exe
O4 - HKLM\..\Run: [Stupid Data Dart Wave] E:\Documents and Settings\All Users\Application Data\flag ace stupid data\Link Hole.exe
O4 - HKLM\..\RunServices: [p2p networking] p2pnetworking.exe
O4 - HKCU\..\Run: [CTFMON.EXE] E:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [MsnMsgr] "E:\Program Files (x86)\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [Scriso] E:\DOCUME~1\ADMINI~1\APPLIC~1\DELETE~1\ForHtmOkay. exe
O4 - HKCU\..\Run: [SpybotSD TeaTimer] E:\Programme (x86)\Spybot - Search & Destroy\TeaTimer.exe
O4 - HKCU\..\Run: [Eraser] E:\Programme (x86)\Eraser\eraser.exe -hide
O4 - HKCU\..\Run: [IpWins] E:\Programme (x86)\Ipwindows\ipwins.exe
O4 - HKCU\..\Run: [WinAble] E:\Programme (x86)\WinAble\winable.exe
O4 - HKCU\..\Run: [Words] E:\Programme (x86)\Words\Words.exe
O4 - HKCU\..\Run: [WinTouch] E:\Documents and Settings\Administrator\Application Data\WinTouch\WinTouch.exe
O4 - HKCU\..\Run: [QdrPack11] "E:\Programme (x86)\QdrPack\QdrPack11.exe"
O4 - HKCU\..\Run: [Wsme] "E:\WINDOWS\system32\STEM32~1\netdde.exe" -vt yazb
O4 - HKCU\..\Run: [OuterinfoUpdate] "E:\Programme (x86)\Outerinfo\OuterinfoUpdate.exe"
O4 - HKCU\..\Run: [Gfirmklb] E:\WINDOWS\system32\?racle\s?chost.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Program Files (x86)\ICQLite\ICQLite.exe -trayboot
O4 - Startup: TA_Start.lnk = E:\System Volume Information\_restore{58FAD2F0-0F06-470A-AE0B-7B2B74F5A090}\RP503\A0101910.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = E:\Program Files (x86)\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Last.fm Helper.lnk = E:\Programme (x86)\Last.fm\LastFMHelper.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files (x86)\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\Program Files (x86)\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files (x86)\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Program Files (x86)\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programme\Messenger\msmsgs.exe (file missing)
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - E:\Programme\Messenger\msmsgs.exe (file missing)
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - E:\PROGRA~4\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - E:\PROGRA~4\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - E:\PROGRA~4\GEMEIN~1\Skype\SKYPE4~1.DLL
O18 - Filter: text/html - {07851C6A-1C43-41d9-8319-BC89154A8C00} - E:\Programme (x86)\RcvSystem\httpdchk.dll
O20 - AppInit_DLLs: MsgPlusLoader.dll
O20 - Winlogon Notify: Controls Folder - E:\WINDOWS\system32\mphtmled.dll (file missing)
O20 - Winlogon Notify: dimsntfy - E:\WINDOWS\SYSTEM32\dimsntfy.dll
O20 - Winlogon Notify: EFS - E:\WINDOWS\SYSTEM32\sclgntfy.dll
O20 - Winlogon Notify: MCD - E:\WINDOWS\system32\Iovu9_32.dll (file missing)
O20 - Winlogon Notify: MS-DOS Emulation - E:\WINDOWS\system32\kedpl.dll (file missing)
O20 - Winlogon Notify: Syncmgr - E:\WINDOWS\system32\gztext.dll (file missing)
O23 - Service: C-DillaCdaC11BA - C-Dilla Ltd - E:\WINDOWS\system32\drivers\CDAC11BA.EXE
O23 - Service: Client IP-IPX - Unknown owner - E:\WINDOWS\system32\svchosts.exe" -e mc-110-12-0000137 (file missing)
O23 - Service: Logical Disk Manager Administrative Service (dmadmin) - Unknown owner - E:\WINDOWS\System32\dmadmin.exe (file missing)
O23 - Service: Event Log (Eventlog) - Unknown owner - E:\WINDOWS\system32\services.exe (file missing)
O23 - Service: HTTP SSL (HTTPFilter) - Unknown owner - E:\WINDOWS\System32\lsass.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - E:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: IMAPI-CD-Brenn-COM-Dienste (ImapiService) - Unknown owner - E:\WINDOWS\system32\imapi.exe (file missing)
O23 - Service: NetMeeting Remote Desktop Sharing (mnmsrvc) - Unknown owner - E:\WINDOWS\system32\mnmsrvc.exe (file missing)
O23 - Service: Distributed Transaction Coordinator (MSDTC) - Unknown owner - E:\WINDOWS\system32\msdtc.exe (file missing)
O23 - Service: Net Logon (Netlogon) - Unknown owner - E:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NT LM Security Support Provider (NtLmSsp) - Unknown owner - E:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - E:\WINDOWS\system32\nvsvc64.exe (file missing)
O23 - Service: Plug and Play (PlugPlay) - Unknown owner - E:\WINDOWS\system32\services.exe (file missing)
O23 - Service: IPSEC Services (PolicyAgent) - Unknown owner - E:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Protected Storage (ProtectedStorage) - Unknown owner - E:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: Sitzungs-Manager für Remotedesktophilfe (RDSessMgr) - Unknown owner - E:\WINDOWS\system32\sessmgr.exe (file missing)
O23 - Service: Security Accounts Manager (SamSs) - Unknown owner - E:\WINDOWS\system32\lsass.exe (file missing)
O23 - Service: SiSoftware Database Agent Service (SandraDataSrv) - SiSoftware - E:\Programme\SiSoftware\SiSoftware Sandra Lite XIIc\Win32\RpcDataSrv.exe
O23 - Service: SiSoftware Sandra Agent Service (SandraTheSrv) - SiSoftware - E:\Programme\SiSoftware\SiSoftware Sandra Lite XIIc\RpcSandraSrv.exe
O23 - Service: Virtual Disk Service (vds) - Unknown owner - E:\WINDOWS\System32\vds.exe (file missing)
O23 - Service: Volume Shadow Copy (VSS) - Unknown owner - E:\WINDOWS\System32\vssvc.exe (file missing)
O23 - Service: WMI-Leistungsadapter (WmiApSrv) - Unknown owner - E:\WINDOWS\system32\wbem\wmiapsrv.exe (file missing)