| sozialesAbseits |  09.08.2008 08:57 |        Antivir2008 Befall - Jetzt wieder alles save?!    Hallo community!  
Könnt ihr mal bitte uber das LogFile schauen und bewerten, ob euch etwas nich ganz sicher vorkommt? Hatte diesen häßlichen Antivir2008 Befall und hab diesen mit ComboFix wegbekommen. Hoffe ich zumindestens?!    Zitat:      
			
				Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 09:49, on 09.08.2008 
Platform: Windows XP SP2 (WinNT 5.01.2600) 
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180) 
Boot mode: Normal   
Running processes: 
C:\WINDOWS\System32\smss.exe 
C:\WINDOWS\system32\winlogon.exe 
C:\WINDOWS\system32\services.exe 
C:\WINDOWS\system32\lsass.exe 
C:\WINDOWS\system32\Ati2evxx.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\System32\svchost.exe 
C:\WINDOWS\system32\svchost.exe 
C:\Programme\Intel\Wireless\Bin\EvtEng.exe 
C:\Programme\Intel\Wireless\Bin\S24EvMon.exe 
C:\WINDOWS\system32\spoolsv.exe 
C:\Programme\AntiVir PersonalEdition Classic\sched.exe 
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe 
C:\WINDOWS\system32\bmwebcfg.exe 
C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe 
C:\Programme\Intel\Wireless\Bin\RegSrvc.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\system32\Ati2evxx.exe 
C:\WINDOWS\Explorer.EXE 
C:\Programme\Synaptics\SynTP\SynTPEnh.exe 
C:\Programme\BenQ\Common\Bin\iviRCService.exe 
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe 
C:\Programme\BenQ\IMCSvr\IMCSvr.exe 
C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe 
C:\Programme\Intel\Wireless\Bin\EOUWiz.exe 
C:\Programme\Intel\Wireless\Bin\ifrmewrk.exe 
C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe 
C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe 
C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe 
C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe 
C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe 
C:\Programme\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe 
C:\PROGRA~1\Intel\Wireless\Bin\Dot1XCfg.exe 
C:\WINDOWS\system32\wuauclt.exe 
C:\Programme\Mozilla Firefox\firefox.exe 
C:\Dokumente und Einstellungen\Thomas K***\Desktop\HiJackThis.exe   
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://softwarereferral.com/jump.php?wmid=6010&mid=MjI6Ojg5&lid=2 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://www.benq.com/ 
O2 - BHO: (no name) - AutorunsDisabled - (no file) 
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll 
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Programme\Winamp Toolbar\winamptb.dll 
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe 
O4 - HKLM\..\Run: [IviRCService] C:\Programme\BenQ\Common\Bin\iviRCService.exe 
O4 - HKLM\..\Run: [QPower] C:\Programme\BenQ\QPower\QPower.exe /s 
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min 
O4 - HKLM\..\Run: [Logitech Hardware Abstraction Layer] KHALMNPR.EXE 
O4 - HKLM\..\Run: [IMCServerAutoStart] C:\Programme\BenQ\IMCSvr\IMCSvr.exe 
O4 - HKLM\..\Run: [IntelZeroConfig] "C:\Programme\Intel\Wireless\bin\ZCfgSvc.exe" 
O4 - HKLM\..\Run: [EOUApp] "C:\Programme\Intel\Wireless\Bin\EOUWiz.exe" 
O4 - HKLM\..\Run: [IntelWireless] "C:\Programme\Intel\Wireless\Bin\ifrmewrk.exe" /tf Intel PROSet/Wireless 
O4 - HKLM\..\Run: [Samsung PanelMgr] C:\WINDOWS\Samsung\PanelMgr\ssmmgr.exe /autorun 
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime 
O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Programme\SUPERAntiSpyware\SUPERAntiSpyware.exe 
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') 
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') 
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') 
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') 
O4 - Global Startup: Adobe Reader - Schnellstart.lnk = C:\Programme\Adobe\Acrobat 7.0\Reader\reader_sl.exe 
O4 - Global Startup: Bluetooth Manager.lnk = ? 
O8 - Extra context menu item: &Winamp Toolbar Search - C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html 
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 
O9 - Extra button: (no name) - AutorunsDisabled - (no file) 
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_09\bin\ssv.dll 
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_09\bin\ssv.dll 
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL 
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Programme\Gemeinsame Dateien\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL 
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe 
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe 
O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dll 
O10 - Unknown file in Winsock LSP: bmnet.dll 
O10 - Unknown file in Winsock LSP: bmnet.dll 
O10 - Unknown file in Winsock LSP: bmnet.dll 
O14 - IERESET.INF: START_PAGE_URL=http://WWW.BenQ.COM/ 
O17 - HKLM\System\CCS\Services\Tcpip\..\{E0FD8C02-9413-4255-B808-582FA2B95C35}: NameServer = 139.7.30.125 139.7.30.126 
O20 - Winlogon Notify: !SASWinLogon - C:\Programme\SUPERAntiSpyware\SASWINLO.dll 
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe 
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe 
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe 
O23 - Service: Bytemobile Web Configurator (bmwebcfg) - Bytemobile, Inc. - C:\WINDOWS\system32\bmwebcfg.exe 
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\EvtEng.exe 
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\HPZipm12.exe 
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\RegSrvc.exe 
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation  - C:\Programme\Intel\Wireless\Bin\S24EvMon.exe 
O23 - Service: ServiceLayer - Nokia. - C:\Programme\PC Connectivity Solution\ServiceLayer.exe   
-- 
End of file - 6791 bytes
			
			   |       Danke im Vorraus!  
Grüsse 
Thomas    |