| bl1zz4rd |  20.12.2008 23:52 |        Browser jumpt immer auf andere Seite    Halllo, 
immer wenn ich auf google etwas such und dann auf ein Suchergebnis drücke, werde ich auf eine andere Seite weitergeleitet die dem Suchergebnis nicht entspricht z.B. beddile. Benutzte Firefox und mit IE7 ist es dasselbe.    HTML-Code:  
 Logfile of Trend Micro HijackThis v2.0.2 
Scan saved at 23:49:13, on 20.12.2008 
Platform: Windows XP SP3 (WinNT 5.01.2600) 
MSIE: Internet Explorer v7.00 (7.00.6000.16762) 
Boot mode: Normal   
Running processes: 
C:\WINDOWS\system32\csrss.exe 
C:\WINDOWS\system32\winlogon.exe 
C:\WINDOWS\system32\services.exe 
C:\WINDOWS\system32\lsass.exe 
C:\WINDOWS\system32\Ati2evxx.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\System32\svchost.exe 
C:\WINDOWS\system32\Ati2evxx.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\system32\svchost.exe 
C:\WINDOWS\system32\spoolsv.exe 
C:\WINDOWS\Explorer.EXE 
C:\WINDOWS\system32\nvraidservice.exe 
C:\WINDOWS\system32\RunDll32.exe 
C:\WINDOWS\system32\ctfmon.exe 
C:\Programme\Bonjour\mDNSResponder.exe 
C:\WINDOWS\system32\PnkBstrA.exe 
C:\WINDOWS\system32\wbem\wmiprvse.exe 
C:\WINDOWS\system32\wbem\unsecapp.exe 
C:\Programme\1by1\1by1.exe 
C:\Programme\Steam\Steam.exe 
C:\Programme\QIP Infium\infium.exe 
C:\Programme\Spybot - Search & Destroy\SpybotSD.exe 
C:\Programme\Mozilla Firefox\firefox.exe 
C:\Programme\Trend Micro\HijackThis\HijackThis.exe 
C:\WINDOWS\system32\wbem\wmiprvse.exe   
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896 
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896 
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157 
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =  
R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://go.microsoft.com/fwlink/?LinkId=74005 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = file://C:/Dokumente und Einstellungen//Lokale Einstellungen/Anwendungsdaten/RapidSolution/Videoraptor/WebRip/profile/rrproxy_ie_48d0f598.pac 
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local 
R3 - URLSearchHook: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file) 
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll 
O3 - Toolbar: (no name) - {0124123D-61B4-456f-AF86-78C53A0790C5} - (no file) 
O3 - Toolbar: (no name) - {E8B91C06-BB8F-49D6-A79B-9DA8652E7BC9} - (no file) 
O4 - HKLM\..\Run: [NVRaidService] C:\WINDOWS\system32\nvraidservice.exe 
O4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd 
O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k 
O4 - HKLM\..\Run: [C:\WINDOWS\system32\kdtcj.exe] C:\WINDOWS\system32\kdtcj.exe 
O4 - HKLM\..\RunOnce: [Spybot - Search & Destroy] "C:\Programme\Spybot - Search & Destroy\SpybotSD.exe" /autocheck 
O4 - HKLM\..\RunOnce: [SpybotDeletingA2908] command /c del "c:\resycled\boot.com" 
O4 - HKLM\..\RunOnce: [SpybotDeletingC5084] cmd /c del "c:\resycled\boot.com" 
O4 - HKLM\..\RunOnce: [SpybotDeletingA3452] command /c del "C:\WINDOWS\system32\kdtcj.exe" 
O4 - HKLM\..\RunOnce: [SpybotDeletingC6636] cmd /c del "C:\WINDOWS\system32\kdtcj.exe" 
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe 
O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe 
O4 - HKCU\..\RunOnce: [SpybotDeletingB8053] command /c del "c:\resycled\boot.com" 
O4 - HKCU\..\RunOnce: [SpybotDeletingD9748] cmd /c del "c:\resycled\boot.com" 
O4 - HKCU\..\RunOnce: [SpybotDeletingB3856] command /c del "C:\WINDOWS\system32\kdtcj.exe" 
O4 - HKCU\..\RunOnce: [SpybotDeletingD819] cmd /c del "C:\WINDOWS\system32\kdtcj.exe" 
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') 
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') 
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') 
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') 
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll 
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll 
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe 
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe 
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1224948089703 
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab 
O17 - HKLM\System\CCS\Services\Tcpip\..\{7BEE365F-47D3-43C5-9AD0-E7350004A6C6}: NameServer = 85.255.112.10;85.255.112.103 
O17 - HKLM\System\CS1\Services\Tcpip\..\{7BEE365F-47D3-43C5-9AD0-E7350004A6C6}: NameServer = 85.255.112.10;85.255.112.103 
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe 
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe 
O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C:\Programme\Bonjour\mDNSResponder.exe 
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1050\Intel 32\IDriverT.exe 
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C:\Programme\iPod\bin\iPodService.exe 
O23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\system32\PnkBstrA.exe 
O24 - Desktop Component 0: Privacy Protection - (no file)   
-- 
End of file - 6079 bytes   MfG 
bl1zz4rd    |