Logfile of HijackThis v1.99.1
Scan saved at 14:41:50, on 14.08.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
G:\WINDOWS\System32\smss.exe
G:\WINDOWS\system32\winlogon.exe
G:\WINDOWS\system32\services.exe
G:\WINDOWS\system32\lsass.exe
G:\WINDOWS\System32\Ati2evxx.exe
G:\WINDOWS\system32\svchost.exe
G:\WINDOWS\System32\svchost.exe
G:\WINDOWS\system32\spoolsv.exe
G:\Programme\AntiVir PersonalEdition Classic\sched.exe
G:\Programme\AntiVir PersonalEdition Classic\avguard.exe
G:\WINDOWS\system32\Ati2evxx.exe
G:\WINDOWS\Explorer.EXE
G:\Programme\AntiVir PersonalEdition Classic\avgnt.exe
G:\Programme\Mozilla Firefox\firefox.exe
G:\Dokumente und Einstellungen\Chris\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.aol.de/
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://search.qsrch.com/
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - H:\Programme\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - G:\Programme\NewDotNet\newdotnet7_22.dll
O4 - HKLM\..\Run: [avgnt] "G:\Programme\AntiVir PersonalEdition Classic\avgnt.exe" /min
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Programme\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - G:\Programme\Java\jre1.5.0\bin\npjpi150.dll
O9 - Extra button: @h:\Programme\Messenger2\im2_ie_plugin.dll,-4 - {410C30C7-098A-4090-928E-F1D356D34C7F} - h:\Programme\Messenger2\im2_ie_plugin.dll
O9 - Extra 'Tools' menuitem: Run IM2 Messenger - {410C30C7-098A-4090-928E-F1D356D34C7F} - h:\Programme\Messenger2\im2_ie_plugin.dll
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - H:\Programme\AIM95\aim.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - h:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - h:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: eBay - Homepage - {EF79EAC5-3452-4E02-B8BD-BA4C89F1AC7A} - h:\Programme\IrfanView\Ebay\Ebay.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - G:\Programme\Messenger\msmsgs.exe
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O10 - Hijacked Internet access by New.Net
O17 - HKLM\System\CCS\Services\Tcpip\..\{23BFF2C2-9472-42D9-A95A-BD57A3F1F11F}: NameServer = 217.237.150.33 217.237.151.161
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "G:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O23 - Service: AntiVir PersonalEdition Classic Planer (AntiVirScheduler) - Avira GmbH - G:\Programme\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - AVIRA GmbH - G:\Programme\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - G:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - G:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - G:\Programme\Gemeinsame Dateien\Symantec Shared\SNDSrvc.exe
O2 - BHO: URLLink - {4A2AACF3-ADF6-11D5-98A9-00E018981B9E} - G:\Programme\NewDotNet\newdotnet7_22.dll
Spyware Scan Details
Start Date: 14.08.2006 16:50:00
End Date: 14.08.2006 17:24:50
Total Time: 34 mins 50 secs
Detected spyware
NewDotNet Browser Plug-in more information...
Details: New.Net is an Internet Explorer spyware/hijacker plug-in that adds subdomains of 'new.net' to your name resolution system (Windows Host file), resulting in what appear to be extra top-level domains (.shop, and so on) being resolvable.
Status: Deleted
Infected files detected
g:\windows\ndnuninstall6_38.exe
g:\windows\ndnuninstall7_14.exe
g:\windows\ndnuninstall7_22.exe
D:\WINDOWS\NDNuninstall6_38.exe
D:\System Volume Information\_restore{B193CE47-ACB1-4F5D-9931-F2DB3C6737E2}\RP23\A0049192.exe
D:\System Volume Information\_restore{B193CE47-ACB1-4F5D-9931-F2DB3C6737E2}\RP23\A0049193.exe
D:\System Volume Information\_restore{B193CE47-ACB1-4F5D-9931-F2DB3C6737E2}\RP23\A0049423.dll
D:\System Volume Information\_restore{B193CE47-ACB1-4F5D-9931-F2DB3C6737E2}\RP23\A0049424.dll
G:\WINDOWS\NDNuninstall6_98.exe
H:\Downloads\Programme\backups\backup-20060814-160224-374.dll
Infected registry entries detected
HKEY_CLASSES_ROOT\tldctl2.urllink.1
HKEY_CLASSES_ROOT\tldctl2.urllink.1\CLSID {4A2AACF3-ADF6-11D5-98A9-00E018981B9E}
HKEY_CLASSES_ROOT\tldctl2.urllink.1 URLLink
HKEY_CLASSES_ROOT\tldctl2.urllink
HKEY_CLASSES_ROOT\tldctl2.urllink\CLSID {4A2AACF3-ADF6-11D5-98A9-00E018981B9E}
HKEY_CLASSES_ROOT\tldctl2.urllink\CurVer Tldctl2.URLLink.1
HKEY_CLASSES_ROOT\tldctl2.urllink URLLink
HKEY_CLASSES_ROOT\tldctl2.urllink\clsid
HKEY_CLASSES_ROOT\tldctl2.urllink\clsid {4A2AACF3-ADF6-11D5-98A9-00E018981B9E}
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net DisplayName New.net Domains 7.22
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net UninstallString G:\WINDOWS\ND5837~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net DisplayIcon G:\WINDOWS\ND5837~1.EXE
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net DisplayVersion 7.22
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net Publisher New.net, Inc.
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net URLInfoAbout http://www.new.net/
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net HelpLink http://www.new.net/help_faq.tp
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net URLUpdateInfo http://www.new.net/index.tp
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net VersionMajor 7
HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\uninstall\new.net VersionMinor 22
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\New.net URLUpdateInfo http://www.new.net/index.tp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\New.net HelpLink http://www.new.net/help_faq.tp
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\New.net URLInfoAbout http://www.new.net/
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\New.net Publisher New.net, Inc.
HKEY_LOCAL_MACHINE\SOFTWARE\New.net Search 1
HKEY_LOCAL_MACHINE\SOFTWARE\New.net LSPStatus 0
HKEY_LOCAL_MACHINE\SOFTWARE\New.net Prt
HKEY_LOCAL_MACHINE\SOFTWARE\New.net Source
HKEY_LOCAL_MACHINE\SOFTWARE\New.net DiscardTag
HKEY_LOCAL_MACHINE\software\new.net
HKEY_LOCAL_MACHINE\software\new.net Activity 49407
HKEY_LOCAL_MACHINE\software\new.net InstalledVersion 458774
HKEY_LOCAL_MACHINE\software\new.net InstalledPath G:\Programme\NewDotNet\newdotnet7_22.dll
HKEY_LOCAL_MACHINE\software\new.net Tag id=c4a7a0c2834985b0d56a6be47d373f17
HKEY_LOCAL_MACHINE\software\new.net DiscardTag
HKEY_LOCAL_MACHINE\software\new.net FirstTime
HKEY_LOCAL_MACHINE\software\new.net Source NNEZTY638
HKEY_LOCAL_MACHINE\software\new.net Prt NNEZTY638
HKEY_LOCAL_MACHINE\software\new.net LSPStatus 0
HKEY_LOCAL_MACHINE\software\new.net NextUpgradeHi 29802726
HKEY_LOCAL_MACHINE\software\new.net NextUpgradeLo 463351104
HKEY_LOCAL_MACHINE\software\new.net UpgradeCounter 2
HKEY_LOCAL_MACHINE\software\new.net Search 1
HKEY_LOCAL_MACHINE\software\new.net XpiDone 1
HKEY_CURRENT_USER\Software\New.net
HKEY_LOCAL_MACHINE\SOFTWARE\New.net Tag
Zango.SearchAssistant Adware (General) more information...
Details: Zango Search Assistant opens new browser windows showing websites based on the previous websites you visit.
Status: Deleted
Infected files detected
g:\programme\mozilla firefox\plugins\npclntax.dll
Win-Spy Commercial Key Logger more information...
Details: Win-Spy is a keylogger and monitoring tool that records keystrokes and other data.
Status: Deleted
Infected files detected
C:\Programme\Messenger2\sounds\default\IncomingMessage.wav
H:\Programme\Messenger2\sounds\default\IncomingMessage.wav
Altnet P2P Networking Low Risk Adware more information...
Details: Altnet P2P Networking is a program that uses peer-to-peer functionality to enable the delivery of content, including advertising, to PC desktops. This content may be used by other programs.
Status: Deleted
Infected files detected
D:\WINDOWS\system32\P2P Networking v126.cpl
D:\WINDOWS\system32\P2P Networking\MARSHAL.DLL
D:\WINDOWS\system32\P2P Networking\P2P Networking.eng
D:\WINDOWS\system32\P2P Networking\P2P Networking.exe
D:\WINDOWS\Downloaded Program Files\WebP2PInstaller.dll
NewDotNet.QuickSearchBar Adware (General) more information...
Details: A toolbar from new.net that monitors web usage and submits you to advertising, and popups.
Status: Deleted
Infected files detected
D:\Programme\QuickSearch\QuickSearchBar1_27.dll
Download Accelerator Plus Low Risk Adware more information...
Details: Download Accelerator Plus (DAP) is an advertising-supported download manager program from SpeedBit.com.
Status: Deleted
Infected files detected
D:\System Volume Information\_restore{B193CE47-ACB1-4F5D-9931-F2DB3C6737E2}\RP19\A0043221.dll
MediaPass LoaderX Trojan Downloader more information...
Status: Deleted
Infected files detected
H:\RECYCLER\S-1-5-21-1644491937-2000478354-725345543-1003\Dh1\system32\drivers\videoprt.sys
AntiLeech Plugin Adware (General) more information...
Details: Plugin is an Ad-Ware software which enables the broadcasting of advertisements, and execution of e-commerce and other internet related services on the user-interface of the software.
Status: Deleted
Infected registry entries detected
HKEY_CURRENT_USER\Software\Anti-Leech\Anti-Leech Plugin
HKEY_CURRENT_USER\Software\Anti-Leech\Anti-Leech Plugin Mozilla Firefox 1.0.3 G:\Programme\Mozilla Firefox\Plugins
HKEY_CURRENT_USER\Software\Anti-Leech\Anti-Leech Plugin Mozilla Firefox 1.0.4 G:\Programme\Mozilla Firefox\Plugins
HKEY_CURRENT_USER\Software\Anti-Leech\Anti-Leech Plugin Mozilla Firefox 1.0.7 G:\Programme\Mozilla Firefox\Plugins
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALNN
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALNN DisplayName Anti-Leech Plugin for Mozilla, Opera, Netscape
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti-Leech ALNN UninstallString H:\Programme\Anti-Leech\ALNN\setup2.exe -u
DoubleClick Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted
Infected cookies detected
g:\dokumente und einstellungen\chris\cookies\chris@doubleclick[1].txt
ATDMT.com Cookie (General) more information...
Details: Cookies are small "data tags" that web sites store on PCs in order to recognize unique visitors. Cookies are used to identify returning visitors who have registered for special services; to measure and analyze visitors' use of web site features; to count
Status: Deleted
Infected cookies detected
g:\dokumente und einstellungen\chris\cookies\chris@atdmt[1].txt
| Internetverbindung wird unterbrochen Forum: DFÜ, Netzwerk, Internet Autor: dean Antworten: 17 |
Internetverbindung DSL wird unterbrochen Forum: DFÜ, Netzwerk, Internet Autor: sun72 Antworten: 3 |
Wichtig: Internetverbindung wird unterbrochen Forum: DFÜ, Netzwerk, Internet Autor: Greische Antworten: 2 |
verbindung wird einfach getrennt ohne grund Forum: Online- und PC-Sicherheit Autor: peerolav Antworten: 1 |
Internetverbindung seit Fritz Box ständig unterbrochen Forum: DFÜ, Netzwerk, Internet Autor: Xara Antworten: 0 |
Zurück zu Online- und PC-Sicherheit
Mitglieder in diesem Forum: 0 Mitglieder und 0 Gäste