Ich bekomme zumindestens eine Virusmeldung
Also hier ist mal mein log file:
Logfile of HijackThis v1.99.1
Scan saved at 20:48:32, on 04.09.2006
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Running processes:
C:\WINDOWS\Explorer.EXE
C:\windows\system\hpsysdrv.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programme\HP\HP Software Update\HPwuSchd2.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programme\cablecom hispeed security package\Common\FSM32.EXE
C:\Programme\cablecom hispeed security package\FSGUI\ispnews.exe
C:\Programme\SlySoft\AnyDVD\AnyDVD.exe
C:\PROGRA~1\CABLEC~1\ANTI-S~1\fsaw.exe
C:\Programme\iTunes\iTunesHelper.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\phonostar\ps_timer.exe
C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe
C:\Programme\cablecom hispeed security package\FSGUI\fsguidll.exe
C:\Programme\ICQLite\ICQLite.exe
C:\Programme\cablecom hispeed security package\backweb\9038346\Program\fspex.exe
C:\Programme\Internet Explorer\IEXPLORE.EXE
C:\Dokumente und Einstellungen\HP_Besitzer\Lokale Einstellungen\Temporary Internet Files\Content.IE5\IXKN89EZ\HijackThis[1].exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://google.icq.com/search/search_frame.php
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.ch/webhp?sourceid=nav ... e&ie=UTF-8
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\programme\google\googletoolbar2.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Programme\FlashFXP\IEFlash.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\programme\google\googletoolbar2.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\jre1.5.0_05\bin\jusched.exe
O4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /installquiet /keeploaded /nodetect
O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXE
O4 - HKLM\..\Run: [HP Software Update] C:\Programme\HP\HP Software Update\HPwuSchd2.exe
O4 - HKLM\..\Run: [BJCFD] C:\Programme\BroadJump\Client Foundation\CFD.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [F-Secure Manager] "C:\Programme\cablecom hispeed security package\Common\FSM32.EXE" /splash
O4 - HKLM\..\Run: [F-Secure TNB] "C:\Programme\cablecom hispeed security package\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW
O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\Programme\cablecom hispeed security package\FSGUI\FSSW.EXE" /reboot
O4 - HKLM\..\Run: [News Service] "C:\Programme\cablecom hispeed security package\FSGUI\ispnews.exe"
O4 - HKLM\..\Run: [AnyDVD] C:\Programme\SlySoft\AnyDVD\AnyDVD.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Programme\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\Run: [PhonostarTimer] C:\Programme\phonostar\ps_timer.exe
O4 - HKCU\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKCU\..\RunOnce: [ICQ Lite] C:\Programme\ICQLite\ICQLite.exe -trayboot
O4 - Global Startup: Acrobat Assistant.lnk = C:\Programme\Adobe\Acrobat 6.0\Distillr\acrotray.exe
O4 - Global Startup: hispeed security package.lnk = C:\Programme\cablecom hispeed security package\backweb\9038346\Program\fspex.exe
O4 - Global Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office10\OSA.EXE
O8 - Extra context menu item: &Google-Suche - res://c:\programme\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: &Ins Deutsche übersetzen - res://c:\programme\google\GoogleToolbar2.dll/cmwordtrans.html
O8 - Extra context menu item: Dieses Popup &blockieren - C:\Programme\cablecom hispeed security package\Anti-Spyware\blockpopups.htm
O8 - Extra context menu item: Im Cache gespeicherte Seite - res://c:\programme\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~3\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Verweisseiten - res://c:\programme\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Ähnliche Seiten - res://c:\programme\google\GoogleToolbar2.dll/cmsimilar.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.5.0_05\bin\npjpi150_05.dll
O9 - Extra button: Webfilter - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programme\cablecom hispeed security package\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Programme\cablecom hispeed security package\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Webfilter - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\Programme\cablecom hispeed security package\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Programme\cablecom hispeed security package\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Webseitenfilter &aussetzen - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\Programme\cablecom hispeed security package\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Programme\cablecom hispeed security package\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Diese Website &sperren - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\Programme\cablecom hispeed security package\FSPC\fspcmsie.dll
O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Programme\cablecom hispeed security package\FSPC\fspcmsie.dll
O9 - Extra 'Tools' menuitem: Diese Website &zulassen - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\Programme\cablecom hispeed security package\FSPC\fspcmsie.dll
O9 - Extra button: IE-Schutzschild - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programme\cablecom hispeed security package\Anti-Spyware\ieshield.dll
O9 - Extra 'Tools' menuitem: IE-Schutzschild... - {300DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\Programme\cablecom hispeed security package\Anti-Spyware\ieshield.dll
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programme\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Programme\PartyGaming\PartyPoker\RunApp.exe
O9 - Extra button: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra 'Tools' menuitem: ICQ Lite - {B863453A-26C3-4e1f-A54D-A2CD196348E9} - C:\Programme\ICQLite\ICQLite.exe
O9 - Extra button: Hilfe zu Verbindungen - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra 'Tools' menuitem: Hilfe zu Verbindungen - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htm
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O10 - Broken Internet access because of LSP provider 'winsflt.dll' missing
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 5390310687
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftup ... 4876093875
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.de/scan/Msie/bitdefender.cab
O16 - DPF: {94EB57FE-2720-496C-B33F-D9353C6E23F7} (F-Secure Online Scanner 2.1) - http://support.f-secure.com/ols/fscax.cab
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O23 - Service: hispeed security package (BackWeb Plug-in - 9038346) - BackWeb Technologies Inc. - C:\PROGRA~1\CABLEC~1\backweb\9038346\Program\SERVIC~1.EXE
O23 - Service: F-Secure Gatekeeper Handler Starter - F-Secure Corp. - C:\Programme\cablecom hispeed security package\Anti-Virus\fsgk32st.exe
O23 - Service: fsbwsys - F-Secure Corp. - C:\Programme\cablecom hispeed security package\backweb\9038346\program\fsbwsys.exe
O23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Programme\cablecom hispeed security package\FWES\Program\fsdfwd.exe
O23 - Service: F-Secure HTTP Server (fshttps) - F-Secure Corporation - C:\Programme\cablecom hispeed security package\FSPC\fshttps\fshttps.exe
O23 - Service: FSMA - F-Secure Corporation - C:\Programme\cablecom hispeed security package\Common\FSMA32.EXE
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Programme\Ahead\InCD\InCDsrv.exe
O23 - Service: iPodService - Apple Computer, Inc. - C:\Programme\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: StarWind iSCSI Service (StarWindService) - Rocket Division Software - C:\Programme\Alcohol Soft\Alcohol 120\StarWind\StarWindService.exe
Datentr„ger in Laufwerk C: ist System Daten
Volumeseriennummer: 5287-3A34
Verzeichnis von C:\WINDOWS\system32
04.09.2006 21:06 29'204 nvapps.xml
04.09.2006 14:14 1'158 wpa.dbl
25.08.2006 01:10 402'542 perfh009.dat
25.08.2006 01:10 63'152 perfc009.dat
09.08.2006 21:03 8'325'544 MRT.exe
28.07.2006 13:28 3'075'072 mshtml.dll
27.07.2006 15:25 679'424 inetcomm.dll
25.07.2006 22:33 615'936 urlmon.dll
21.07.2006 10:29 72'704 hlink.dll
14.07.2006 17:38 332'288 netapi32.dll
14.07.2006 17:25 546'304 hhctrl.ocx
14.07.2006 12:29 417'312 perfh007.dat
14.07.2006 12:29 76'066 perfc007.dat
14.07.2006 12:29 975'140 PerfStringBackup.INI
13.07.2006 15:34 8'494'592 shell32.dll
05.07.2006 12:55 1'057'792 kernel32.dll
26.06.2006 19:40 148'480 dnsapi.dll
26.06.2006 19:40 8'192 rasadhlp.dll
23.06.2006 13:10 664'576 wininet.dll
23.06.2006 13:10 39'424 pngfilt.dll
23.06.2006 13:10 146'432 msrating.dll
23.06.2006 13:10 532'480 mstime.dll
23.06.2006 13:10 474'624 shlwapi.dll
23.06.2006 13:10 1'494'016 shdocvw.dll
23.06.2006 13:10 448'512 mshtmled.dll
23.06.2006 13:10 251'392 iepeers.dll
23.06.2006 13:10 1'056'256 danim.dll
23.06.2006 13:10 16'384 jsproxy.dll
23.06.2006 13:10 1'022'976 browseui.dll
23.06.2006 13:10 152'064 cdfview.dll
23.06.2006 13:10 55'808 extmgr.dll
23.06.2006 13:10 205'312 dxtrans.dll
23.06.2006 13:10 96'768 inseng.dll
23.06.2006 13:10 357'888 dxtmsft.dll
23.06.2006 10:53 27'136 xpsp3res.dll
19.06.2006 16:20 702'768 WgaLogon.dll
19.06.2006 16:19 571'184 LegitCheckControl.dll
19.06.2006 16:19 304'944 WgaTray.exe
02.06.2006 13:47 48'640 Suchspur.dll
01.06.2006 20:47 27'648 jgpl400.dll
Datentr„ger in Laufwerk C: ist System Daten
Volumeseriennummer: 5287-3A34
Verzeichnis von C:\DOKUME~1\HP_BES~1\LOKALE~1\Temp
04.09.2006 21:07 512 ~DF5118.tmp
04.09.2006 21:07 147'456 ~WRF0000.tmp
04.09.2006 21:07 512 ~DF190E.tmp
04.09.2006 21:07 512 ~DF16B3.tmp
4 Datei(en) 148'992 Bytes
0 Verzeichnis(se), 140'854'755'328 Bytes frei
Datentr„ger in Laufwerk C: ist System Daten
Volumeseriennummer: 5287-3A34
Verzeichnis von C:\WINDOWS
04.09.2006 20:59 0 0.log
04.09.2006 20:58 1'168'849 WindowsUpdate.log
04.09.2006 20:58 2'048 bootstat.dat
04.09.2006 20:57 32'558 SchedLgU.Txt
04.09.2006 02:31 1'611 cdplayer.ini
03.09.2006 00:55 89'514 wmsetup.log
01.09.2006 23:08 867'259 setupapi.log
31.08.2006 23:08 238'080 setupact.log
26.08.2006 09:34 116 NeroDigital.ini
26.08.2006 00:55 214 WININIT.INI
15.08.2006 15:55 432 BRWMARK.INI
15.08.2006 03:03 170'515 comsetup.log
15.08.2006 03:03 75'379 iis6.log
15.08.2006 03:03 1'374 imsins.log
15.08.2006 03:03 102'595 ntdtcsetup.log
15.08.2006 03:03 190'970 tsoc.log
15.08.2006 03:03 27'078 ocmsn.log
15.08.2006 03:03 18'735 KB920214.log
15.08.2006 03:03 244'760 ocgen.log
15.08.2006 03:03 24'614 msgsocm.log
15.08.2006 03:03 500'574 FaxSetup.log
15.08.2006 03:03 1'374 imsins.BAK
15.08.2006 03:03 19'038 KB922616.log
15.08.2006 03:02 27'186 updspapi.log
15.08.2006 03:02 18'685 KB921398.log
15.08.2006 03:02 21'565 KB918899.log
15.08.2006 03:01 12'746 KB920670.log
15.08.2006 03:01 12'081 KB917422.log
15.08.2006 03:01 12'332 KB920683.log
10.08.2006 01:07 11'098 KB921883.log
04.08.2006 23:42 151 PhotoSnapViewer.INI
31.07.2006 23:06 216 wiadebug.log
31.07.2006 20:10 50 wiaservc.log
14.07.2006 13:01 4'141 spupdsvc.log
14.07.2006 12:58 9'179 WgaNotify.log
13.07.2006 22:07 11'837 KB917159.log
13.07.2006 22:07 12'351 KB914388.log
13.07.2006 22:07 10'505 KB916595.log
01.07.2006 00:51 121 GEARInstall.log
28.06.2006 20:09 21'388 fsiuupd.log
15.06.2006 09:55 573 win.ini
15.06.2006 09:55 227 system.ini
15.06.2006 03:02 13'233 KB917734.log
15.06.2006 03:01 15'794 KB918439.log
15.06.2006 03:01 16'474 KB917344.log
15.06.2006 03:01 15'434 KB917953.log
15.06.2006 03:01 15'413 KB911280.log
15.06.2006 03:01 18'578 KB916281.log
15.06.2006 03:00 11'662 KB914389.log
07.06.2006 01:41 400 ODBC.INI
Datentr„ger in Laufwerk C: ist System Daten
Volumeseriennummer: 5287-3A34
Verzeichnis von C:\
04.09.2006 21:09 0 sys.txt
04.09.2006 21:09 11'322 system.txt
04.09.2006 21:08 443 systemtemp.txt
04.09.2006 21:07 103'454 system32.txt
04.09.2006 20:58 536'268'800 hiberfil.sys
04.09.2006 20:58 805'306'368 pagefile.sys
18.08.2006 11:30 938 DirDPF.txt
18.08.2006 11:30 2 DirDPFCns.txt
18.08.2006 03:32 1'202 error.htm
18.08.2006 01:56 0 infect.htm
15.06.2006 09:55 293 boot.ini
10)DPF????
Datentr„ger in Laufwerk C: ist System Daten
Volumeseriennummer: 5287-3A34
Verzeichnis von C:\WINDOWS\Downloaded Program Files
07.10.2004 22:16 815 bitdefender.inf
07.10.2004 23:05 327'680 bitdefender.ocx
25.07.2002 19:13 24'576 dwusplay.dll
25.07.2002 19:13 196'608 dwusplay.exe
08.12.2005 15:29 652'736 fscax.dll
12.07.2000 03:02 36'864 fxfileop.dll
27.07.2004 17:48 323'584 isusweb.dll
26.05.2005 04:19 293 muweb.inf
29.06.2005 17:17 227 opuc.inf
27.03.2006 13:00 5'019 swflash.inf
31.10.2001 11:37 118 uninst.bat
26.05.2005 04:19 291 wuweb.inf
12 Datei(en) 1'568'811 Bytes
Anzahl der angezeigten Dateien:
12 Datei(en) 1'568'811 Bytes
0 Verzeichnis(se), 139'051'683'840 Bytes frei
10)DPF????
Datentr„ger in Laufwerk C: ist System Daten
Volumeseriennummer: 5287-3A34
Verzeichnis von C:\WINDOWS\Downloaded Program Files
07.10.2004 22:16 815 bitdefender.inf
07.10.2004 23:05 327'680 bitdefender.ocx
25.07.2002 19:13 24'576 dwusplay.dll
25.07.2002 19:13 196'608 dwusplay.exe
08.12.2005 15:29 652'736 fscax.dll
12.07.2000 03:02 36'864 fxfileop.dll
27.07.2004 17:48 323'584 isusweb.dll
26.05.2005 04:19 293 muweb.inf
29.06.2005 17:17 227 opuc.inf
27.03.2006 13:00 5'019 swflash.inf
31.10.2001 11:37 118 uninst.bat
26.05.2005 04:19 291 wuweb.inf
12 Datei(en) 1'568'811 Bytes
Anzahl der angezeigten Dateien:
12 Datei(en) 1'568'811 Bytes
0 Verzeichnis(se), 140'854'767'616 Bytes frei