Trojaner-Board

Trojaner-Board (https://www.trojaner-board.de/)
-   Log-Analyse und Auswertung (https://www.trojaner-board.de/log-analyse-auswertung/)
-   -   Home Search Assistent - Search Extender - Shopping Wizard (https://www.trojaner-board.de/17471-home-search-assistent-search-extender-shopping-wizard.html)

Tuca 06.05.2005 08:20

Home Search Assistent - Search Extender - Shopping Wizard
 
Hallo zusammen,

Ich denke, dass dieses Thema nicht mehr ganz neu ist, nach dem ich schon so ziemlich alle foren durchkämmt habe, konnte auch ich diese dinger nicht entfernen.

Hier mal das Logfile:

Logfile of HijackThis v1.99.1
Scan saved at 09:05:14, on 06.05.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
D:\Internet\sicherheit\f-secure\Common\FSM32.EXE
D:\Programme\Brenner\CloneCD\CloneCDTray.exe
C:\Programme\Gemeinsame Dateien\Cloanto\Software Manager\softmngr.exe
C:\Programme\Eraser\eraser.exe
D:\Internet\sicherheit\GPG\GPGshell\GPGtray.exe
D:\Programme\palmOne\HOTSYNC.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
D:\Internet\Trillian\trillian.exe
D:\Programme\Text\OpenOffice\program\soffice.exe
C:\WINDOWS\system32\CAPRPCSK.EXE
C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
D:\Internet\sicherheit\f-secure\Anti-Virus\fsgk32st.exe
D:\Internet\sicherheit\f-secure\Anti-Virus\FSGK32.EXE
D:\Internet\sicherheit\f-secure\BackWeb\7681197\program\fsbwsys.exe
D:\Internet\sicherheit\f-secure\Common\FSMA32.EXE
D:\Internet\sicherheit\f-secure\Common\FSMB32.EXE
D:\Internet\sicherheit\Kerio\Personal Firewall 4\kpf4ss.exe
D:\Internet\sicherheit\f-secure\Anti-Virus\fssm32.exe
D:\Internet\sicherheit\f-secure\Common\FCH32.EXE
D:\Internet\sicherheit\f-secure\Common\FAMEH32.EXE
C:\WINDOWS\System32\nvsvc32.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\System32\svchost.exe
D:\Internet\sicherheit\Kerio\Personal Firewall 4\kpf4gui.exe
D:\Internet\sicherheit\f-secure\Common\FNRB32.EXE
D:\Internet\sicherheit\Kerio\Personal Firewall 4\kpf4gui.exe
D:\Internet\sicherheit\f-secure\Anti-Virus\fsav32.exe
D:\Internet\sicherheit\f-secure\Common\FIH32.EXE
D:\Internet\sicherheit\f-secure\FWES\Program\fsdfwd.exe
D:\Internet\sicherheit\f-secure\FSGUI\fsguiexe.exe
D:\Programme\totalcmd\TOTALCMD.EXE
D:\Internet\sicherheit\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Programme\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {AA0E4412-0B6E-ABBD-EAAF-67B877E2B4D7} - C:\WINDOWS\system32\javaoi.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - D:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - D:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [F-Secure Manager] "D:\Internet\sicherheit\f-secure\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "D:\Internet\sicherheit\f-secure\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [CloneCDElbyCDFL] "D:\Programme\Brenner\CloneCD\ElbyCheck.exe" /L ElbyCDFL
O4 - HKLM\..\Run: [CloneCDTray] "D:\Programme\Brenner\CloneCD\CloneCDTray.exe"
O4 - HKLM\..\Run: [CloantoSoftwareManager] "C:\Programme\Gemeinsame Dateien\Cloanto\Software Manager\softmngr.exe" /s
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKCU\..\Run: [BackWeb LiteInstaller] C:\DOKUME~1\Lars\LOKALE~1\Temp\ins1.tmp\LiteInst.exe /NoIntervention
O4 - HKCU\..\Run: [Eraser] C:\Programme\Eraser\eraser.exe -hide
O4 - HKCU\..\Run: [NBJ] "D:\Programme\Brenner\Ahead\Nero BackItUp\NBJ.exe"
O4 - Startup: GPGtray.lnk = D:\Internet\sicherheit\GPG\GPGshell\GPGtray.exe
O4 - Startup: HotSync Manager.lnk = D:\Programme\palmOne\HOTSYNC.EXE
O4 - Startup: OpenOffice.org 1.1.4.lnk = D:\Programme\Text\OpenOffice\program\quickstart.exe
O4 - Startup: trillian.lnk = ?
O4 - Global Startup: Canon LBP-810-Statusfenster.LNK = C:\WINDOWS\system32\spool\drivers\w32x86\3\CAPPSWK.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0\bin\npjpi150.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{AB6D956F-ADD9-4AAB-BE11-AD0A92AF1CAA}: NameServer = 192.168.0.1
O18 - Protocol: bw+0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw+0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw-0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw00s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw10s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw20s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw30s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw40s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw50s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw60s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw70s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw80s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bw90s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwa0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwb0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwc0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwd0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwe0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwf0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwfile-8876480 - {9462A756-7B47-47BC-8C80-C34B9B80B32B} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\GAPlugProtocol-8876480.dll
O18 - Protocol: bwg0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwg0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwh0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwi0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwj0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwk0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwl0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwm0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwn0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwo0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwp0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwq0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwr0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bws0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwt0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwu0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwv0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bww0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwx0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwy0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: bwz0s - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O18 - Protocol: offline-8876480 - {A88D1A61-5AF5-4741-A066-92DFCB1010A6} - C:\Programme\Logitech\Desktop Messenger\8876480\Program\BWPlugProtocol-8876480.dll
O23 - Service: Adobe LM Service - Unknown owner - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: F-Secure Automatic Update (BackWeb Plug-in - 7681197) - Unknown owner - D:\Internet\SICHER~1\f-secure\BackWeb\7681197\Program\SERVIC~1.EXE
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - D:\Internet\sicherheit\f-secure\Anti-Virus\fsgk32st.exe
O23 - Service: F-Secure Network Request Broker - F-Secure Corporation - D:\Internet\sicherheit\f-secure\Common\FNRB32.EXE
O23 - Service: fsbwsys - F-Secure Corp. - D:\Internet\sicherheit\f-secure\BackWeb\7681197\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - D:\Internet\sicherheit\f-secure\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure Management Agent (FSMA) - F-Secure Corporation - D:\Internet\sicherheit\f-secure\Common\FSMA32.EXE
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: Kerio Personal Firewall 4 (KPF4) - Kerio Technologies - D:\Internet\sicherheit\Kerio\Personal Firewall 4\kpf4ss.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe

Cidre 06.05.2005 08:27

Hallo,

wechsle in den abgesicherten Modus und fixe diese Einträge (Haken setzen und auf Fix Checked klicken):
Zitat:

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Int ernet Settings,ProxyOverride = localhost
R3 - Default URLSearchHook is missing
F2 - REG:system.ini: Shell=
O2 - BHO: (no name) - {AA0E4412-0B6E-ABBD-EAAF-67B877E2B4D7} - C:\WINDOWS\system32\javaoi.dll
O4 - HKCU\..\Run: [BackWeb LiteInstaller] C:\DOKUME~1\Lars\LOKALE~1\Temp\ins1.tmp\LiteInst.e xe /NoIntervention
Alle O18
Lösche diese Dateien:
C:\WINDOWS\system32\javaoi.dll

Leere diesen Ordner:
C:\DOKUME~1\Lars\LOKALE~1\Temp

Lade und scanne mit eScan AntiVirus im abgesicherten Modus und lösche die gefundene Malware manuell.
Poste danach die Virus Log Information und ebenso eine aktuelles HJT Log-File.
Beachte die Hinweise!


Alle Zeitangaben in WEZ +1. Es ist jetzt 16:52 Uhr.

Copyright ©2000-2025, Trojaner-Board


Search Engine Optimization by vBSEO ©2011, Crawlability, Inc.

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131