

Zitat
mir ist es auch erst richtig aufgefallen als ich mal wieder ein windows update machen wollte da ich ja Firefox benutze



|
|
Quellcode |
1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 |
Logfile of HijackThis v1.99.1
Scan saved at 19:06:54, on 10.09.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:ProgrammeTGTSoftStyleXPStyleXPService.exe
C:WINDOWSsystem32spoolsv.exe
C:ProgrammeAntiVir PersonalEdition Classicsched.exe
C:ProgrammeAntiVir PersonalEdition Classicavguard.exe
C:ProgrammeInternet Update ManagerUPDMGR.EXE
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32Tablet.exe
C:WINDOWSsystem32Ati2evxx.exe
C:WINDOWSExplorer.EXE
C:ProgrammeATI TechnologiesATI.ACEcli.exe
C:WINDOWSsystem32RunDll32.exe
C:ProgrammeAntiVir PersonalEdition Classicavgnt.exe
C:ProgrammeJavajre1.5.0_08binjusched.exe
C:WINDOWSSOUNDMAN.EXE
C:WINDOWSsystem32ctfmon.exe
C:ProgrammeTGTSoftStyleXPStyleXP.exe
C:ProgrammeSkypePhoneSkype.exe
C:Programme3 Mega Digital CameraICON.EXE
C:ProgrammeHPDigital Imagingbinhpqtra08.exe
C:WINDOWSsystem32WTabletTabUserW.exe
C:ProgrammeSamurizeClient.exe
C:WINDOWSSystem32svchost.exe
C:ProgrammeATI TechnologiesATI.ACEcli.exe
C:ProgrammeATI TechnologiesATI.ACEcli.exe
C:ProgrammeTrilliantrillian.exe
C:ProgrammeSteamSteam.exe
C:ProgrammeMozilla Firefoxfirefox.exe
C:Dokumente und EinstellungenRaphaelDesktopwinfuture.de_winxpsp2_updatepack_v2.13.exe
C:DOKUME~1RaphaelLOKALE~1Temp7zS22.tmpSetup.exe
C:DOKUME~1RaphaelLOKALE~1Temp7zS22.tmpDataWindowsXP-KB893357-v2-x86-DEU.exe
C:DOKUME~1RaphaelLOKALE~1Temp7zS63.tmpupdateupdate.exe
c:windows$hf_mig$KB918899updateupdate.exe
C:Dokumente und EinstellungenRaphaelDesktopHijackThis.exe
R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyServer = 212.162.158.85:80
O2 - BHO: CvgraphObj Object - {12355F3E-90C3-41AA-8705-15969AF7F210} - C:WINDOWSvgraph.dll
O2 - BHO: (no name) - {1da7dbe8-c51b-4ae4-bc6e-21863349b0b4} - (no file)
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:ProgrammeJavajre1.5.0_08binssv.dll
O2 - BHO: (no name) - {B6F22A5A-9C1E-00FE-E9FD-71DD71E0FDAC} - (no file)
O2 - BHO: CoTGT_BHO Class - {C333CF63-767F-4831-94AC-E683D962C63C} - C:ProgrammeTGTSoftStyleXPTGT_BHO.dll
O3 - Toolbar: (no name) - {a2595f37-48d0-46a1-9b51-478591a97764} - (no file)
O4 - HKLM..Run: [ATICCC] "C:ProgrammeATI TechnologiesATI.ACEcli.exe" runtime -Delay
O4 - HKLM..Run: [CmUsbSound] RunDll32 cmcnfgu.cpl,CMICtrlWnd
O4 - HKLM..Run: [avgnt] "C:ProgrammeAntiVir PersonalEdition Classicavgnt.exe" /min
O4 - HKLM..Run: [SunJavaUpdateSched] "C:ProgrammeJavajre1.5.0_08binjusched.exe"
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..RunOnce: [KB886716] rundll32.exe apphelp.dll,ShimFlushCache
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [STYLEXP] C:ProgrammeTGTSoftStyleXPStyleXP.exe -Hide
O4 - HKCU..Run: [Skype] "C:ProgrammeSkypePhoneSkype.exe" /nosplash /minimized
O4 - HKCU..Run: [XP Tools] C:ProgrammeXP Toolsxptools.exe /min
O4 - Startup: Samurize (2).lnk = C:ProgrammeSamurizeClient.exe
O4 - Global Startup: 3 Mega Digital Camera Monitor.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk = C:ProgrammeGemeinsame DateienAdobeCalibrationAdobe Gamma Loader.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:ProgrammeHPDigital Imagingbinhpqtra08.exe
O4 - Global Startup: TabUserW.exe.lnk = C:WINDOWSsystem32WTabletTabUserW.exe
O8 - Extra context menu item: Download with NetPumper - C:ProgrammeNetPumperAddUrl.htm
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgrammeJavajre1.5.0_08binssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgrammeJavajre1.5.0_08binssv.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:PartyGamingPartyPokerRunApp.exe (file missing)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:PartyGamingPartyPokerRunApp.exe (file missing)
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:ProgrammeICQLiteICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:ProgrammeICQLiteICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammeMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammeMessengermsmsgs.exe
O12 - Plugin for .pdf: C:ProgrammeInternet ExplorerPLUGINSnppdf32.dll
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - [url]http://go.microsoft.com/fwlink/?linkid=39204[/url]
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - [url]http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1137607293531[/url]
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - [url]http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab[/url]
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - [url]http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1137971995328[/url]
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:PROGRA~1MSNMES~1MSGRAP~1.DLL
O20 - Winlogon Notify: WgaLogon - C:WINDOWSSYSTEM32WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:WINDOWSsystem32WPDShServiceObj.dll
O21 - SSODL: bestreak - {874443fe-aa33-4ebf-a6ac-73208787e62d} - (no file)
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:ProgrammeAntiVir PersonalEdition Classicsched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:ProgrammeAntiVir PersonalEdition Classicavguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:WINDOWSsystem32Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:WINDOWSsystem32ati2sgag.exe
O23 - Service: AntiVir Update Manager (AVUpdateManager) - H+BEDV Datentechnik GmbH, Germany - C:ProgrammeInternet Update ManagerUPDMGR.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:ProgrammeGemeinsame DateienInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:ProgrammeiPodbiniPodService.exe
O23 - Service: Macromedia Licensing Service - Unknown owner - C:ProgrammeGemeinsame DateienMacromedia SharedServiceMacromedia Licensing.exe
O23 - Service: Pml Driver HPZ12 - HP - C:WINDOWSsystem32HPZipm12.exe
O23 - Service: StyleXPService - Unknown owner - C:ProgrammeTGTSoftStyleXPStyleXPService.exe
O23 - Service: TabletService - Wacom Technology, Corp. - C:WINDOWSsystem32Tablet.exe
O23 - Service: TuneUp WinStyler Theme Service (TUWinStylerThemeSvc) - TuneUp Software GmbH - C:ProgrammeTuneUp Utilities 2006WinStylerThemeSvc.exe
|
