Ich habe das abgearbeitet:
1.
stelle den CleanUp genauso ein, wie hier angegeben:
http://virus-protect.org/cleanup.html
2.
Kopiere diese 4 Textdateien ab . (rechtsklick mit der Maus -> den Text markieren -> kopieren -> einfügen) Sie sind nach Datum geordnet. (kopiere nur die letzten 3 Monate ab)
http://virus-protect.org/datfindbat.html
3.
echo.zip --> entpacken--> klicke echo.bat --> der Texteditor wird sich öffnen--> Text abkopieren
http://virus-protect.org/bat/echo.zip
Logfile of HijackThis v1.99.1
Scan saved at 13:08:32, on 2006-07-05
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Gemeinsame Dateien\Microsoft Shared\VS7DEBUG\MDM.EXE
C:\WINDOWS\system32\netdde.exe
C:\WINDOWS\system32\oodag.exe
C:\WINDOWS\System32\snmp.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\MsPMSPSv.exe
C:\Programme\WUSB54G Wireless-G Adapter\WLService.exe
C:\Programme\WUSB54G Wireless-G Adapter\WUSB54G.exe
C:\WINDOWS\Explorer.EXE
C:\Programme\FreePDF_XP\fpassist.exe
C:\Programme\iTunes\iTunesHelper.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\ICQLite\ICQLite.exe
C:\WINDOWS\system32\sistray.EXE
C:\Programme\HP\hpcoretech\hpcmpmgr.exe
C:\Programme\HP\HP Software Update\HPWuSchd2.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\system32\taskmgr.exe
C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe
C:\Programme\Mousometer\mousometer.exe
C:\Programme\iPod\bin\iPodService.exe
C:\WINDOWS\system32\HPZipm12.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Programme\iTunes\iTunes.exe
C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
C:\Programme\AntiVir PersonalEdition Classic\sched.exe
C:\Programme\Temperaturmesser\EVEREST Home Edition\everest.bin
C:\Programme\Microsoft Office\OFFICE11\MSPUB.EXE
C:\Dokumente und Einstellungen\User\Desktop\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://web.de/
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll
O4 - HKLM\..\Run: [SiSUSBRG] C:\WINDOWS\SiSUSBrg.exe
O4 - HKLM\..\Run: [avgnt] "C:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [FreePDF Assistant] C:\Programme\FreePDF_XP\fpassist.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [ICQ Lite] "C:\Programme\ICQLite\ICQLite.exe" -minimize
O4 - HKLM\..\Run: [SiS Tray] C:\WINDOWS\system32\sistray.EXE
O4 - HKLM\..\Run: [DXDllRegExe] dxdllreg.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot
O4 - Startup: Mousometer.lnk = C:\Programme\Mousometer\mousometer.exe
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Programme\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_06\bin\ssv.dll
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {0EB0E74A-2A76-4AB3-A7FB-9BD8C29F7F75} (CKAVWebScan Object) - http://www.kaspersky.com/kos/eng/partne ... nicode.cab
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 8236301589
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - C:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service (AntiVirService) - AVIRA GmbH - C:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe
O23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - Unknown owner - %ProgramFiles%\WinPcap\rpcapd.exe" -d -f "%ProgramFiles%\WinPcap\rpcapd.ini (file missing)
O23 - Service: WUSB54GSVC - Unknown owner - C:\Programme\WUSB54G Wireless-G Adapter\WLService.exe" "WUSB54G.exe (file missing)
datFind:
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: D066-6D47
Verzeichnis von C:\WINDOWS\system32
2006-07-05 11:15 403.054 perfh009.dat
2006-07-05 11:15 62.722 perfc009.dat
2006-07-05 11:15 418.016 perfh007.dat
2006-07-05 11:15 75.796 perfc007.dat
2006-07-05 11:14 972.014 PerfStringBackup.INI
2006-07-05 11:11 1.374 wpa.dbl
2006-07-05 11:10 31.428 OODBS.lor
2006-06-26 16:20 308 results.txt
2006-06-26 16:18 1.575 WLAN.INI
2006-06-25 20:24 403.920 FNTCACHE.DAT
2006-06-19 16:20 702.768 WgaLogon.dll
2006-06-19 16:19 571.184 LegitCheckControl.dll
2006-06-19 16:19 304.944 WgaTray.exe
2006-06-10 10:49 473 schecklog.txt
2006-06-10 10:49 34.915 1_ssetup.ini
2006-06-10 10:49 16.819 sunistlog.ini
2006-06-10 10:03 57.384 avsda.dll
2006-06-10 09:50 55 VGAunistlog.ini
2006-06-09 09:21 664 d3d9caps.dat
2006-06-09 03:19 5.967.776 MRT.exe
2006-06-01 20:47 163.840 jgdw400.dll
2006-06-01 20:47 27.648 jgpl400.dll
2006-05-31 07:24 230.168 xactengine2_2.dll
2006-05-29 17:30 1.494.016 shdocvw.dll
2006-05-27 21:50 16.832 amcompat.tlb
2006-05-27 21:50 23.392 nscompat.tlb
2006-05-19 17:09 3.073.536 mshtml.dll
2006-05-18 07:36 450.560 jscript.dll
2006-05-14 10:48 181.248 rasmans.dll
2006-05-11 10:57 27.136 xpsp3res.dll
2006-05-10 07:23 664.064 wininet.dll
2006-05-10 07:22 474.624 shlwapi.dll
2006-05-10 07:22 615.936 urlmon.dll
2006-05-10 07:22 448.512 mshtmled.dll
2006-05-10 07:22 146.432 msrating.dll
2006-05-10 07:22 532.480 mstime.dll
2006-05-10 07:22 39.424 pngfilt.dll
2006-05-10 07:22 96.768 inseng.dll
2006-05-10 07:22 16.384 jsproxy.dll
2006-05-10 07:22 1.056.256 danim.dll
2006-05-10 07:22 205.312 dxtrans.dll
2006-05-10 07:22 251.392 iepeers.dll
2006-05-10 07:22 55.808 extmgr.dll
2006-05-10 07:22 357.888 dxtmsft.dll
2006-05-10 07:22 1.022.976 browseui.dll
2006-05-10 07:22 152.064 cdfview.dll
2006-05-09 22:36 6.656 WdfMgr.exe
2006-05-09 22:36 6.656 uWDF.exe
2006-05-09 22:26 564.736 WMSPDMOD.dll
2006-05-09 22:26 221.696 SET7D.tmp
2006-05-09 22:26 4.096 wmvdmod.dll
2006-05-09 22:26 4.096 WMVADVD.dll
2006-05-09 22:26 4.096 wmsdmod.dll
2006-05-09 22:26 203.776 wmpsrcwp.dll
2006-05-09 22:26 97.792 wmpshell.dll
2006-05-09 22:26 4.096 WMVADVE.DLL
2006-05-09 22:26 4.096 MP43DMOD.dll
2006-05-09 22:26 4.096 wdfApi.dll
2006-05-09 22:26 7.706.112 wmploc.dll
2006-05-09 22:26 1.641.472 wmpencen.dll
2006-05-09 22:26 306.688 MSWMDM.dll
2006-05-09 22:26 212.480 msnetobj.dll
2006-05-09 22:26 433.152 wmpeffects.dll
2006-05-09 22:26 301.056 wmpdxm.dll
2006-05-09 22:26 237.056 wmpasf.dll
2006-05-09 22:26 10.394.624 wmp.dll
2006-05-09 22:26 267.776 Audiodev.dll
2006-05-09 22:26 219.648 CEWMDM.dll
2006-05-09 22:26 4.096 wmvdmoe2.dll
2006-05-09 22:26 992.256 WMNetMgr.dll
2006-05-09 22:26 155.136 wmidx.dll
2006-05-09 22:26 705.024 WMADMOD.dll
2006-05-09 22:26 1.280.000 WMSPDMOE.dll
2006-05-09 22:26 337.408 wmdrmnet.dll
2006-05-09 22:26 4.096 MP4SDMOD.dll
2006-05-09 22:26 26.112 MsPMSNSv.dll
2006-05-09 22:26 4.096 MPG4DMOD.dll
2006-05-09 22:26 417.280 wmdrmdev.dll
2006-05-09 22:26 201.728 qasf.dll
2006-05-09 22:26 36.864 WMDMPS.dll
2006-05-09 22:26 31.744 WMDMLOG.dll
2006-05-09 22:26 221.696 wmasf.dll
2006-05-09 22:26 165.376 MsPMSP.dll
2006-05-09 22:26 135.680 wmpps.dll
2006-05-09 22:26 1.063.424 WMADMOE.dll
2006-05-09 22:26 4.096 wmsdmoe2.dll
2006-05-09 22:26 218.112 wmerror.dll
2006-05-09 22:26 7.168 asferror.dll
2006-05-09 22:26 9.728 LAPRXY.dll
2006-05-09 22:22 2.463.744 SET8B.tmp
2006-05-09 22:22 2.463.744 wmvcore.dll
2006-05-09 21:02 230.400 l3codecp.acm
2006-05-09 21:02 84.480 logagent.exe
2006-05-09 21:01 1.359.360 WMVSDECD.dll
2006-05-09 21:01 1.463.808 WMVDECOD.dll
2006-05-09 21:00 299.520 MP4SDECD.dll
2006-05-09 21:00 241.152 MPG4DECD.dll
2006-05-09 21:00 1.455.616 WMVENCOD.dll
2006-05-09 21:00 770.560 WMVSENCD.dll
2006-05-09 21:00 636.928 WMVXENCD.dll
2006-05-09 21:00 241.152 MP43DECD.dll
2006-05-09 21:00 546.816 wmpmde.dll
2006-05-09 21:00 382.976 MFPLAT.dll
2006-05-09 21:00 1.350.656 drmv2clt.dll
2006-05-09 20:59 513.536 wmdrmsdk.dll
2006-05-09 20:59 417.280 MSSCP.dll
2006-05-09 20:59 229.376 drmupgds.exe
2006-05-09 20:59 585.216 blackbox.dll
2006-05-09 20:58 52.224 WPDShServiceObj.dll
2006-05-09 20:58 3.745.280 WpdShext.dll
2006-05-09 20:58 13.824 wpdshextautoplay.exe
10)DPF????
Volume in Laufwerk C: hat keine Bezeichnung.
Volumeseriennummer: D066-6D47
Verzeichnis von C:\WINDOWS\Downloaded Program Files
1997-10-14 18:52 697 DirectAnimation Java Classes.osd
2002-07-25 19:13 24.576 dwusplay.dll
2002-07-25 19:13 196.608 dwusplay.exe
2005-02-09 16:54 1.271 erma.inf
2000-04-10 17:12 1.765 fhg.inf
2004-06-16 07:02 323.584 isusweb.dll
2003-08-25 18:12 1.096 iuctl.inf
2006-02-07 17:30 576 kavwebscan.inf
2005-11-03 21:24 495 LegitCheckControl.inf
2000-01-20 15:25 1.162 Microsoft XML Parser for Java.osd
2005-05-26 04:19 293 muweb.inf
2005-01-17 17:09 227 opuc.inf
2003-12-08 13:58 3.759 swflash.inf
13 Datei(en) 556.109 Bytes
Anzahl der angezeigten Dateien:
13 Datei(en) 556.109 Bytes
0 Verzeichnis(se), 1.058.287.616 Bytes frei
Ist der Rechner sauber?
2006-05-09 20:58 103.424 PortableDeviceWiaCompat.dll
2006-05-09 20:58 670.208 wpd_ci.dll
2006-05-09 20:58 188.928 PortableDeviceWMDRM.dll
2006-05-09 20:58 345.600 PortableDeviceApi.dll
2006-05-09 20:58 101.376 PortableDeviceClassExtension.dll
2006-05-09 20:58 343.552 WPDSp.dll
2006-05-09 20:58 35.840 wpdconns.dll
2006-05-09 20:58 55.808 wpdmtpus.dll
2006-05-09 20:58 144.896 wpdmtp.dll
2006-05-09 20:58 13.312 wpdtrace.dll
2006-05-09 20:58 168.960 PortableDeviceTypes.dll
2006-05-09 20:57 11.264 ehETW.dll
2006-05-09 20:45 304.640 MSDelta.dll
2006-05-09 20:00 22.752 spupdsvc.exe
2006-05-04 17:35 65.536 QuickTimeVR.qtx
2006-05-04 17:35 49.152 QuickTime.qts
2006-04-28 22:10 477.184 autoprnt.exe
2006-04-28 22:10 37.888 setupnt.dll
2006-04-28 22:10 118.784 snapapi.dll
2006-04-12 19:55 21.840 SIntfNT.dll
2006-04-12 19:55 17.212 SIntf32.dll
2006-04-12 19:55 12.067 SIntf16.dll
2006-04-11 14:30 93.752 WUDFCoinstaller.dll
2006-04-11 14:27 130.048 WudfHost.exe
2006-04-11 14:27 304.640 WUDFx.dll
2006-04-11 14:26 54.272 WudfSvc.dll
2006-04-11 14:26 158.208 WudfPlatform.dll
2006-04-09 16:53 7.006 jupdate-1.5.0_06-b05.log
2006-04-09 11:50 98.304 CmdLineExt.dll
2006-04-08 09:24 2.321.408 TUKernel.exe
2006-04-03 11:40 14.048 spmsg.dll
2006-03-31 12:40 2.388.176 d3dx9_30.dll
2006-03-31 12:39 229.584 xactengine2_1.dll
2006-03-31 12:39 62.672 xinput1_1.dll