Brauchen Sie Hilfe bitte. (Keylogger): [
- GTAmute
- Born


- Registriert: Mai 27, 2008
- Beiträge: 3
- Status: Offline
Im neu für diese Art von Stuff (HijackThis und so weiter) so id liebe es, wenn euch helfen könnte mich ein wenig.
Ich wurde getäuscht, und einen Link geklickt ich definitiv nicht. Ich kam in diesem Board und sah einige haben das gleiche getan, und HijackThis heruntergeladen. So I post it here?
Logfile von HijackThis v1.99.1
Scan gespeichert um 12:18:43 Uhr, am 5/27/2008
Betriebssystem: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900. 2180)
Laufende Prozesse:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ Spoolsv.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Program Files \ Intel \ Intel Application Accelerator \ iaantmon.exe
C: \ WINDOWS \ system32 \ NVSVC32.EXE
C: \ WINDOWS \ System32 \ SnoopFreeSvc. exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Programme \ Gemeinsame Dateien \ Symantec Shared \ CCPD-LC \ symlcsvc.exe
C: \ Program Files \ Viewpoint \ Common \ ViewpointService.exe
c: \ WINDOWS \ system32 \ ZuneBusEnum.exe
C: \ WINDOWS \ system32 \ wscntfy.exe
C: \ WINDOWS \ explorer.exe
C: \ Program Files \ Intel \ Intel Application Accelerator \ iaanotif.exe
C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe
C: \ Program Files \ QuickTime \ qttask.exe
C: \ WINDOWS \ SnoopFreeUI.exe
C: \ WINDOWS \ system32 \ CTHELPER. EXE
C: \ WINDOWS \ system32 \ rundll32.exe
C: \ Program Files \ Zune \ ZuneLauncher.exe
C: \ Program Files \ D-Link AirPlus \ AirPlus.exe
C: \ Program Files \ Nikon \ PictureProject \ NkbMonitor.exe
C: \ Programme \ Gemeinsame Dateien \ Sonic Shared \ CineTray.exe
C: \ WINDOWS \ system32 \ wuauclt.exe
C: \ Program Files \ Trillian \ trillian.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Dokumente und Einstellungen \ Nick1 \ Desktop \ hijackthis_sfx.exe
C: \ Program Files \ HijackThis \ HijackThis. exe
R3 - URLSearchHook: Yahoo! ¤ u ¨ ã | C - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ CPN \ yt.dll
O2 - BHO: & Yahoo! Toolbar Helper - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ CPN \ yt.dll
O2 - BHO: Adobe Reader PDF-Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Programme \ Gemeinsame Dateien \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper. DLL
O2 - BHO: BitComet ClickCapture - (39F7E362-828A-4B5A-BCAF-5B79BFDFEA60) - C: \ Program Files \ BitComet \ Tools \ BitCometBHO_1.2.1.2.dll
O2 - BHO: (no name) - (53707962-6F74-2D53-2644-206D7942484F) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc.dll
O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv. DLL
O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (keine Datei)
O2 - BHO: Windows Live Sign-In Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Programme \ Gemeinsame Dateien \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! ¤ u ¨ ã | C - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ CPN \ yt.dll
O4 - HKLM \ .. \ Run: [IAAnotif] C: \ Program Files \ Intel \ Intel Application Accelerator \ iaanotif.exe
O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvCpl.dll, NvStartup
O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe"
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM \ .. \ Run: [CTHelper] CTHELPER.EXE
O4 - HKLM \ .. \ Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvMcTray.dll, NvTaskbarInit
O4 - HKLM \ .. \ Run: [Zune Launcher] "c: \ Program Files \ Zune \ ZuneLauncher.exe"
O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Program Files \ Adobe \ Reader 8,0 \ Reader \ Reader_sl.exe"
O4 - HKCU \ .. \ Run: [Steam] "c: \ program files \ valve \ Dampf \ steam.exe"-silent
O4 - HKCU \ .. \ Run: [ISMModule2] "C: \ Program Files \ ISM \ ISMModule2.exe"
O4 - HKCU \ .. \ Run: [Yahoo! Pager] "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe"-quiet
O4 - Global Startup: D-Link AirPlus.lnk =?
O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C: \ Program Files \ Nikon \ PictureProject \ NkbMonitor.exe
O4 - Global Startup: Sonic CinePlayer Quick Launch.lnk = C: \ Programme \ Gemeinsame Dateien \ Sonic Shared \ CineTray. exe
O8 - Extra Kontext Menüpunkt: & D & & ownload mit BitComet -- res://C : \ Program Files \ BitComet \ BitComet.exe / AddLink.htm
O8 - Extra Kontext Menüpunkt: & & D ownload alle Video mit BitComet -- res://C : \ Program Files \ BitComet \ BitComet.exe / AddVideo.htm
O8 - Extra Kontext Menüpunkt: & & D ownload alle mit BitComet -- res://C : \ Program Files \ BitComet \ BitComet.exe / AddAllLink. htm
O8 - Extra Kontext Menüpunkt: E & xportieren auf Microsoft Excel -- res://C : \ PROGRA ~ 1 \ MICROS ~ 2 \ Office10 \ EXCEL.EXE/3000
O9 - Extra Knopf: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
O9 - Extra "Extras" menuitem: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
O9 - Extra-Taste: Yahoo! Services - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc.dll
O9 - Extra-Schalter: BitComet - (D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A) -- res://C : \ Program Files \ BitComet \ Tools \ BitCometBHO_1.2.1.2.dll/206 (Datei fehlt)
O9 - Extra-Taste: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra "Extras" menuitem: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs. exe
O16 - DPF: (30528230-99f7-4bb4-88d8-fa1d4f56a2ab) (Installations-Support) - C: \ Program Files \ Yahoo! \ Common \ Yinsthelper.dll
O16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://update.microsoft.com/windowsupda ... 7510304000
O18 - Protokoll: livecall - (828030A1-22C1-4009-854F-8E305202313F) - C: \ PROGRA ~ 1 \ WI1F86 ~ 1 \ MESSEN ~ 1 \ MSGRAP ~ 1.DLL
O18 - Protokoll: msnim - (828030A1-22C1-4009-854F-8E305202313F) - C: \ PROGRA ~ 1 \ WI1F86 ~ 1 \ MESSEN ~ 1 \ MSGRAP ~ 1. DLL
O20 - Winlogon Notify: WgaLogon - C: \ WINDOWS \ SYSTEM32 \ WgaLogon.dll
O21 - SSODL: WPDShServiceObj - (AAA288BA-9A4C-45B0-95D7-94D524869DB5) - C: \ WINDOWS \ system32 \ WPDShServiceObj.dll
O23 - Service: IAA Event Monitor (IAANTMon) - Intel - C: \ Program Files \ Intel \ Intel Application Accelerator \ iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Programme \ Gemeinsame Dateien \ InstallShield \ Driver \ 11 \ Intel 32 \ IDriverT. exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ system32 \ NVSVC32.EXE
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unbekannter Eigentümer - C: \ WINDOWS \ System32 \ SnoopFreeSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C: \ Programme \ Gemeinsame Dateien \ Symantec Shared \ CCPD-LC \ symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C: \ Program Files \ Viewpoint \ Common \ ViewpointService. exe
Vielen Dank im Voraus.
Ich wurde getäuscht, und einen Link geklickt ich definitiv nicht. Ich kam in diesem Board und sah einige haben das gleiche getan, und HijackThis heruntergeladen. So I post it here?
Logfile von HijackThis v1.99.1
Scan gespeichert um 12:18:43 Uhr, am 5/27/2008
Betriebssystem: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900. 2180)
Laufende Prozesse:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ Spoolsv.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Program Files \ Intel \ Intel Application Accelerator \ iaantmon.exe
C: \ WINDOWS \ system32 \ NVSVC32.EXE
C: \ WINDOWS \ System32 \ SnoopFreeSvc. exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Programme \ Gemeinsame Dateien \ Symantec Shared \ CCPD-LC \ symlcsvc.exe
C: \ Program Files \ Viewpoint \ Common \ ViewpointService.exe
c: \ WINDOWS \ system32 \ ZuneBusEnum.exe
C: \ WINDOWS \ system32 \ wscntfy.exe
C: \ WINDOWS \ explorer.exe
C: \ Program Files \ Intel \ Intel Application Accelerator \ iaanotif.exe
C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe
C: \ Program Files \ QuickTime \ qttask.exe
C: \ WINDOWS \ SnoopFreeUI.exe
C: \ WINDOWS \ system32 \ CTHELPER. EXE
C: \ WINDOWS \ system32 \ rundll32.exe
C: \ Program Files \ Zune \ ZuneLauncher.exe
C: \ Program Files \ D-Link AirPlus \ AirPlus.exe
C: \ Program Files \ Nikon \ PictureProject \ NkbMonitor.exe
C: \ Programme \ Gemeinsame Dateien \ Sonic Shared \ CineTray.exe
C: \ WINDOWS \ system32 \ wuauclt.exe
C: \ Program Files \ Trillian \ trillian.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Dokumente und Einstellungen \ Nick1 \ Desktop \ hijackthis_sfx.exe
C: \ Program Files \ HijackThis \ HijackThis. exe
R3 - URLSearchHook: Yahoo! ¤ u ¨ ã | C - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ CPN \ yt.dll
O2 - BHO: & Yahoo! Toolbar Helper - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ CPN \ yt.dll
O2 - BHO: Adobe Reader PDF-Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Programme \ Gemeinsame Dateien \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper. DLL
O2 - BHO: BitComet ClickCapture - (39F7E362-828A-4B5A-BCAF-5B79BFDFEA60) - C: \ Program Files \ BitComet \ Tools \ BitCometBHO_1.2.1.2.dll
O2 - BHO: (no name) - (53707962-6F74-2D53-2644-206D7942484F) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc.dll
O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv. DLL
O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (keine Datei)
O2 - BHO: Windows Live Sign-In Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Programme \ Gemeinsame Dateien \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! ¤ u ¨ ã | C - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ CPN \ yt.dll
O4 - HKLM \ .. \ Run: [IAAnotif] C: \ Program Files \ Intel \ Intel Application Accelerator \ iaanotif.exe
O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvCpl.dll, NvStartup
O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe"
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: [SnoopFreeUI] SnoopFreeUI.exe
O4 - HKLM \ .. \ Run: [CTHelper] CTHELPER.EXE
O4 - HKLM \ .. \ Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvMcTray.dll, NvTaskbarInit
O4 - HKLM \ .. \ Run: [Zune Launcher] "c: \ Program Files \ Zune \ ZuneLauncher.exe"
O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Program Files \ Adobe \ Reader 8,0 \ Reader \ Reader_sl.exe"
O4 - HKCU \ .. \ Run: [Steam] "c: \ program files \ valve \ Dampf \ steam.exe"-silent
O4 - HKCU \ .. \ Run: [ISMModule2] "C: \ Program Files \ ISM \ ISMModule2.exe"
O4 - HKCU \ .. \ Run: [Yahoo! Pager] "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe"-quiet
O4 - Global Startup: D-Link AirPlus.lnk =?
O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C: \ Program Files \ Nikon \ PictureProject \ NkbMonitor.exe
O4 - Global Startup: Sonic CinePlayer Quick Launch.lnk = C: \ Programme \ Gemeinsame Dateien \ Sonic Shared \ CineTray. exe
O8 - Extra Kontext Menüpunkt: & D & & ownload mit BitComet -- res://C : \ Program Files \ BitComet \ BitComet.exe / AddLink.htm
O8 - Extra Kontext Menüpunkt: & & D ownload alle Video mit BitComet -- res://C : \ Program Files \ BitComet \ BitComet.exe / AddVideo.htm
O8 - Extra Kontext Menüpunkt: & & D ownload alle mit BitComet -- res://C : \ Program Files \ BitComet \ BitComet.exe / AddAllLink. htm
O8 - Extra Kontext Menüpunkt: E & xportieren auf Microsoft Excel -- res://C : \ PROGRA ~ 1 \ MICROS ~ 2 \ Office10 \ EXCEL.EXE/3000
O9 - Extra Knopf: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
O9 - Extra "Extras" menuitem: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
O9 - Extra-Taste: Yahoo! Services - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc.dll
O9 - Extra-Schalter: BitComet - (D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A) -- res://C : \ Program Files \ BitComet \ Tools \ BitCometBHO_1.2.1.2.dll/206 (Datei fehlt)
O9 - Extra-Taste: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra "Extras" menuitem: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs. exe
O16 - DPF: (30528230-99f7-4bb4-88d8-fa1d4f56a2ab) (Installations-Support) - C: \ Program Files \ Yahoo! \ Common \ Yinsthelper.dll
O16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://update.microsoft.com/windowsupda ... 7510304000
O18 - Protokoll: livecall - (828030A1-22C1-4009-854F-8E305202313F) - C: \ PROGRA ~ 1 \ WI1F86 ~ 1 \ MESSEN ~ 1 \ MSGRAP ~ 1.DLL
O18 - Protokoll: msnim - (828030A1-22C1-4009-854F-8E305202313F) - C: \ PROGRA ~ 1 \ WI1F86 ~ 1 \ MESSEN ~ 1 \ MSGRAP ~ 1. DLL
O20 - Winlogon Notify: WgaLogon - C: \ WINDOWS \ SYSTEM32 \ WgaLogon.dll
O21 - SSODL: WPDShServiceObj - (AAA288BA-9A4C-45B0-95D7-94D524869DB5) - C: \ WINDOWS \ system32 \ WPDShServiceObj.dll
O23 - Service: IAA Event Monitor (IAANTMon) - Intel - C: \ Program Files \ Intel \ Intel Application Accelerator \ iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Programme \ Gemeinsame Dateien \ InstallShield \ Driver \ 11 \ Intel 32 \ IDriverT. exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ system32 \ NVSVC32.EXE
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unbekannter Eigentümer - C: \ WINDOWS \ System32 \ SnoopFreeSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C: \ Programme \ Gemeinsame Dateien \ Symantec Shared \ CCPD-LC \ symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C: \ Program Files \ Viewpoint \ Common \ ViewpointService. exe
Vielen Dank im Voraus.
- Anonymous
- Bot


- Registriert: 25 Feb 2008
- Beiträge: ?
- Loc: Ozzuland
- Status: Online
Mai 27th, 2008, 12:23 pm
- Don2007
- Web Master


- Registriert: Nov 21, 2006
- Beiträge: 4455
- Loc: NY
- Status: Offline
O2 - BHO: BitComet ClickCapture - (39F7E362-828A-4B5A-BCAF-5B79BFDFEA60) - C: \ Program Files \ BitComet \ Tools \ BitCometBHO_1.2.1.2.dll
O4 - HKCU \ .. \ Run: [ISMModule2] "C: \ Program Files \ ISM \ ISMModule2.exe"
O18 - Protokoll: livecall - (828030A1-22C1-4009-854F-8E305202313F) - C: \ PROGRA ~ 1 \ WI1F86 ~ 1 \ MESSEN ~ 1 \ MSGRAP ~ 1.DLL
O16 - DPF: (30528230-99f7-4bb4-88d8-fa1d4f56a2ab) (Installations-Support) - C: \ Program Files \ Yahoo! \ Common \ Yinsthelper. DLL
Der letzte ist ein Teil von Yahoo, aber es ist als ein Sicherheitsloch.
O4 - HKCU \ .. \ Run: [ISMModule2] "C: \ Program Files \ ISM \ ISMModule2.exe"
O18 - Protokoll: livecall - (828030A1-22C1-4009-854F-8E305202313F) - C: \ PROGRA ~ 1 \ WI1F86 ~ 1 \ MESSEN ~ 1 \ MSGRAP ~ 1.DLL
O16 - DPF: (30528230-99f7-4bb4-88d8-fa1d4f56a2ab) (Installations-Support) - C: \ Program Files \ Yahoo! \ Common \ Yinsthelper. DLL
Der letzte ist ein Teil von Yahoo, aber es ist als ein Sicherheitsloch.
- GTAmute
- Born


- Registriert: Mai 27, 2008
- Beiträge: 3
- Status: Offline
Don2007 hat geschrieben:
O2 - BHO: BitComet ClickCapture - (39F7E362-828A-4B5A-BCAF-5B79BFDFEA60) - C: \ Program Files \ BitComet \ Tools \ BitCometBHO_1.2.1.2.dll
O4 - HKCU \ .. \ Run: [ISMModule2] "C: \ Program Files \ ISM \ ISMModule2.exe"
O18 - Protokoll: livecall - (828030A1-22C1-4009-854F-8E305202313F) - C: \ PROGRA ~ 1 \ WI1F86 ~ 1 \ MESSEN ~ 1 \ MSGRAP ~ 1.DLL
O16 - DPF: (30528230-99f7-4bb4-88d8-fa1d4f56a2ab) (Installations-Support) - C: \ Program Files \ Yahoo! \ Common \ Yinsthelper. DLL
Der letzte ist ein Teil von Yahoo, aber es ist als ein Sicherheitsloch.
O4 - HKCU \ .. \ Run: [ISMModule2] "C: \ Program Files \ ISM \ ISMModule2.exe"
O18 - Protokoll: livecall - (828030A1-22C1-4009-854F-8E305202313F) - C: \ PROGRA ~ 1 \ WI1F86 ~ 1 \ MESSEN ~ 1 \ MSGRAP ~ 1.DLL
O16 - DPF: (30528230-99f7-4bb4-88d8-fa1d4f56a2ab) (Installations-Support) - C: \ Program Files \ Yahoo! \ Common \ Yinsthelper. DLL
Der letzte ist ein Teil von Yahoo, aber es ist als ein Sicherheitsloch.
Ich weiss nicht genau folgen. Bin ich zu löschen, was jedes youve aufgelistet?
- Don2007
- Web Master


- Registriert: Nov 21, 2006
- Beiträge: 4455
- Loc: NY
- Status: Offline
- GTAmute
- Born


- Registriert: Mai 27, 2008
- Beiträge: 3
- Status: Offline
Ich sehe. Ich habe, was Sie gesagt haben Buddy, und hier sind die Ergebnisse!
Bin ich jetzt sauber? = D
Logfile von HijackThis v1.99.1
Scan gespeichert um 5:26:39 Uhr, am 5/27/2008
Betriebssystem: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Laufende Prozesse:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost. exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ Spoolsv.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Program Files \ Intel \ Intel Application Accelerator \ iaantmon.exe
C: \ WINDOWS \ system32 \ NVSVC32.EXE
C: \ WINDOWS \ System32 \ SnoopFreeSvc.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Programme \ Gemeinsame Dateien \ Symantec Shared \ CCPD-LC \ symlcsvc.exe
C: \ Program Files \ Viewpoint \ Common \ ViewpointService.exe
c: \ WINDOWS \ system32 \ ZuneBusEnum. exe
C: \ WINDOWS \ system32 \ wscntfy.exe
C: \ WINDOWS \ explorer.exe
C: \ Program Files \ Intel \ Intel Application Accelerator \ iaanotif.exe
C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe
C: \ Program Files \ QuickTime \ qttask.exe
C: \ WINDOWS \ SnoopFreeUI.exe
C: \ WINDOWS \ system32 \ CTHELPER.EXE
C: \ WINDOWS \ system32 \ rundll32.exe
C: \ Program Files \ Zune \ ZuneLauncher.exe
C: \ Program Files \ D-Link AirPlus \ AirPlus.exe
C: \ Program Files \ Nikon \ PictureProject \ NkbMonitor. exe
C: \ Programme \ Gemeinsame Dateien \ Sonic Shared \ CineTray.exe
C: \ WINDOWS \ system32 \ wuauclt.exe
C: \ Program Files \ Trillian \ trillian.exe
C: \ Program Files \ Vent \ Ventrilo.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Program Files \ HijackThis \ HIJACKTHIS.EXE
R3 - URLSearchHook: Yahoo! ¤ u ¨ ã | C - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ CPN \ yt.dll
O2 - BHO: & Yahoo! Toolbar Helper - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ CPN \ yt.dll
O2 - BHO: Adobe Reader PDF-Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Programme \ Gemeinsame Dateien \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll
O2 - BHO: (no name) - (53707962-6F74-2D53-2644-206D7942484F) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc. DLL
O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (keine Datei)
O2 - BHO: Windows Live Sign-In Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Programme \ Gemeinsame Dateien \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! ¤ u ¨ ã | C - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ CPN \ yt. DLL
O4 - HKLM \ .. \ Run: [IAAnotif] C: \ Program Files \ Intel \ Intel Application Accelerator \ iaanotif.exe
O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvCpl.dll, NvStartup
O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe"
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: [SnoopFreeUI] SnoopFreeUI. exe
O4 - HKLM \ .. \ Run: [CTHelper] CTHELPER.EXE
O4 - HKLM \ .. \ Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvMcTray.dll, NvTaskbarInit
O4 - HKLM \ .. \ Run: [Zune Launcher] "c: \ Program Files \ Zune \ ZuneLauncher.exe"
O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Program Files \ Adobe \ Reader 8,0 \ Reader \ Reader_sl.exe"
O4 - HKCU \ .. \ Run: [Steam] "c: \ program files \ valve \ Dampf \ steam.exe"-silent
O4 - HKCU \ .. \ Run: [Yahoo! Pager] "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe"-quiet
O4 - Global Startup: D-Link AirPlus.lnk =?
O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C: \ Program Files \ Nikon \ PictureProject \ NkbMonitor.exe
O4 - Global Startup: Sonic CinePlayer Quick Launch.lnk = C: \ Programme \ Gemeinsame Dateien \ Sonic Shared \ CineTray. exe
O8 - Extra Kontext Menüpunkt: & D & & ownload mit BitComet -- res://C : \ Program Files \ BitComet \ BitComet.exe / AddLink.htm
O8 - Extra Kontext Menüpunkt: & & D ownload alle Video mit BitComet -- res://C : \ Program Files \ BitComet \ BitComet.exe / AddVideo.htm
O8 - Extra Kontext Menüpunkt: & & D ownload alle mit BitComet -- res://C : \ Program Files \ BitComet \ BitComet.exe / AddAllLink. htm
O8 - Extra Kontext Menüpunkt: E & xportieren auf Microsoft Excel -- res://C : \ PROGRA ~ 1 \ MICROS ~ 2 \ Office10 \ EXCEL.EXE/3000
O9 - Extra Knopf: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
O9 - Extra "Extras" menuitem: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
O9 - Extra-Taste: Yahoo! Services - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc.dll
O9 - Extra-Schalter: BitComet - (D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A) -- res://C : \ Program Files \ BitComet \ Tools \ BitCometBHO_1.2.1.2.dll/206 (Datei fehlt)
O9 - Extra-Taste: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra "Extras" menuitem: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs. exe
O16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://update.microsoft.com/windowsupda ... 7510304000
O18 - Protokoll: msnim - (828030A1-22C1-4009-854F-8E305202313F) - C: \ PROGRA ~ 1 \ WI1F86 ~ 1 \ MESSEN ~ 1 \ MSGRAP ~ 1.DLL
O20 - Winlogon Notify: WgaLogon - C: \ WINDOWS \ SYSTEM32 \ WgaLogon.dll
O21 - SSODL: WPDShServiceObj - (AAA288BA-9A4C-45B0-95D7-94D524869DB5) - C: \ WINDOWS \ system32 \ WPDShServiceObj. DLL
O23 - Service: IAA Event Monitor (IAANTMon) - Intel - C: \ Program Files \ Intel \ Intel Application Accelerator \ iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Programme \ Gemeinsame Dateien \ InstallShield \ Driver \ 11 \ Intel 32 \ IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ system32 \ nvsvc32. exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unbekannter Eigentümer - C: \ WINDOWS \ System32 \ SnoopFreeSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C: \ Programme \ Gemeinsame Dateien \ Symantec Shared \ CCPD-LC \ symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C: \ Program Files \ Viewpoint \ Common \ ViewpointService.exe
Bin ich jetzt sauber? = D
Logfile von HijackThis v1.99.1
Scan gespeichert um 5:26:39 Uhr, am 5/27/2008
Betriebssystem: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Laufende Prozesse:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost. exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ Spoolsv.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Program Files \ Intel \ Intel Application Accelerator \ iaantmon.exe
C: \ WINDOWS \ system32 \ NVSVC32.EXE
C: \ WINDOWS \ System32 \ SnoopFreeSvc.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Programme \ Gemeinsame Dateien \ Symantec Shared \ CCPD-LC \ symlcsvc.exe
C: \ Program Files \ Viewpoint \ Common \ ViewpointService.exe
c: \ WINDOWS \ system32 \ ZuneBusEnum. exe
C: \ WINDOWS \ system32 \ wscntfy.exe
C: \ WINDOWS \ explorer.exe
C: \ Program Files \ Intel \ Intel Application Accelerator \ iaanotif.exe
C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe
C: \ Program Files \ QuickTime \ qttask.exe
C: \ WINDOWS \ SnoopFreeUI.exe
C: \ WINDOWS \ system32 \ CTHELPER.EXE
C: \ WINDOWS \ system32 \ rundll32.exe
C: \ Program Files \ Zune \ ZuneLauncher.exe
C: \ Program Files \ D-Link AirPlus \ AirPlus.exe
C: \ Program Files \ Nikon \ PictureProject \ NkbMonitor. exe
C: \ Programme \ Gemeinsame Dateien \ Sonic Shared \ CineTray.exe
C: \ WINDOWS \ system32 \ wuauclt.exe
C: \ Program Files \ Trillian \ trillian.exe
C: \ Program Files \ Vent \ Ventrilo.exe
C: \ Program Files \ Mozilla Firefox \ firefox.exe
C: \ Program Files \ HijackThis \ HIJACKTHIS.EXE
R3 - URLSearchHook: Yahoo! ¤ u ¨ ã | C - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ CPN \ yt.dll
O2 - BHO: & Yahoo! Toolbar Helper - (02478D38-C3F9-4efb-9B51-7695ECA05670) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ CPN \ yt.dll
O2 - BHO: Adobe Reader PDF-Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Programme \ Gemeinsame Dateien \ Adobe \ Acrobat \ ActiveX \ AcroIEHelper.dll
O2 - BHO: (no name) - (53707962-6F74-2D53-2644-206D7942484F) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O2 - BHO: Yahoo! IE Services Button - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc. DLL
O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
O2 - BHO: (no name) - (7E853D72-626A-48EC-A868-BA8D5E23E045) - (keine Datei)
O2 - BHO: Windows Live Sign-In Helper - (9030D464-4C02-4ABF-8ECC-5164760863C6) - C: \ Programme \ Gemeinsame Dateien \ Microsoft Shared \ Windows Live \ WindowsLiveLogin.dll
O3 - Toolbar: Yahoo! ¤ u ¨ ã | C - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ PROGRA ~ 1 \ Yahoo! \ Companion \ Installs \ CPN \ yt. DLL
O4 - HKLM \ .. \ Run: [IAAnotif] C: \ Program Files \ Intel \ Intel Application Accelerator \ iaanotif.exe
O4 - HKLM \ .. \ Run: [NvCplDaemon] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvCpl.dll, NvStartup
O4 - HKLM \ .. \ Run: [nwiz] nwiz.exe / install
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ jusched.exe"
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: [SnoopFreeUI] SnoopFreeUI. exe
O4 - HKLM \ .. \ Run: [CTHelper] CTHELPER.EXE
O4 - HKLM \ .. \ Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM \ .. \ Run: [NvMediaCenter] RUNDLL32.EXE C: \ WINDOWS \ system32 \ NvMcTray.dll, NvTaskbarInit
O4 - HKLM \ .. \ Run: [Zune Launcher] "c: \ Program Files \ Zune \ ZuneLauncher.exe"
O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Program Files \ Adobe \ Reader 8,0 \ Reader \ Reader_sl.exe"
O4 - HKCU \ .. \ Run: [Steam] "c: \ program files \ valve \ Dampf \ steam.exe"-silent
O4 - HKCU \ .. \ Run: [Yahoo! Pager] "C: \ Program Files \ Yahoo! \ Messenger \ YahooMessenger.exe"-quiet
O4 - Global Startup: D-Link AirPlus.lnk =?
O4 - Global Startup: Microsoft Office.lnk = C: \ Program Files \ Microsoft Office \ Office10 \ OSA.EXE
O4 - Global Startup: NkbMonitor.exe.lnk = C: \ Program Files \ Nikon \ PictureProject \ NkbMonitor.exe
O4 - Global Startup: Sonic CinePlayer Quick Launch.lnk = C: \ Programme \ Gemeinsame Dateien \ Sonic Shared \ CineTray. exe
O8 - Extra Kontext Menüpunkt: & D & & ownload mit BitComet -- res://C : \ Program Files \ BitComet \ BitComet.exe / AddLink.htm
O8 - Extra Kontext Menüpunkt: & & D ownload alle Video mit BitComet -- res://C : \ Program Files \ BitComet \ BitComet.exe / AddVideo.htm
O8 - Extra Kontext Menüpunkt: & & D ownload alle mit BitComet -- res://C : \ Program Files \ BitComet \ BitComet.exe / AddAllLink. htm
O8 - Extra Kontext Menüpunkt: E & xportieren auf Microsoft Excel -- res://C : \ PROGRA ~ 1 \ MICROS ~ 2 \ Office10 \ EXCEL.EXE/3000
O9 - Extra Knopf: (no name) - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
O9 - Extra "Extras" menuitem: Sun Java Console - (08B0E5C0-4FCB-11CF-AAA5-00401C608501) - C: \ Program Files \ Java \ jre1.6.0_03 \ bin \ ssv.dll
O9 - Extra-Taste: Yahoo! Services - (5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897) - C: \ Program Files \ Yahoo! \ Common \ yiesrvc.dll
O9 - Extra-Schalter: BitComet - (D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A) -- res://C : \ Program Files \ BitComet \ Tools \ BitCometBHO_1.2.1.2.dll/206 (Datei fehlt)
O9 - Extra-Taste: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs.exe
O9 - Extra "Extras" menuitem: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Program Files \ Messenger \ msmsgs. exe
O16 - DPF: (6414512B-B978-451D-A0D8-FCFDF33E833C) (WUWebControl Class) -- http://update.microsoft.com/windowsupda ... 7510304000
O18 - Protokoll: msnim - (828030A1-22C1-4009-854F-8E305202313F) - C: \ PROGRA ~ 1 \ WI1F86 ~ 1 \ MESSEN ~ 1 \ MSGRAP ~ 1.DLL
O20 - Winlogon Notify: WgaLogon - C: \ WINDOWS \ SYSTEM32 \ WgaLogon.dll
O21 - SSODL: WPDShServiceObj - (AAA288BA-9A4C-45B0-95D7-94D524869DB5) - C: \ WINDOWS \ system32 \ WPDShServiceObj. DLL
O23 - Service: IAA Event Monitor (IAANTMon) - Intel - C: \ Program Files \ Intel \ Intel Application Accelerator \ iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Programme \ Gemeinsame Dateien \ InstallShield \ Driver \ 11 \ Intel 32 \ IDriverT.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C: \ WINDOWS \ system32 \ nvsvc32. exe
O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unbekannter Eigentümer - C: \ WINDOWS \ System32 \ SnoopFreeSvc.exe
O23 - Service: Symantec Core LC - Symantec Corporation - C: \ Programme \ Gemeinsame Dateien \ Symantec Shared \ CCPD-LC \ symlcsvc.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C: \ Program Files \ Viewpoint \ Common \ ViewpointService.exe
- Don2007
- Web Master


- Registriert: Nov 21, 2006
- Beiträge: 4455
- Loc: NY
- Status: Offline
- janebush08
- Newbie


- Registriert: Nov 17, 2008
- Beiträge: 6
- Status: Offline
Seite 1 von 1
Um Antworten zu diesem Thema müssen Sie sich einloggen oder registrieren. Es ist kostenlos.
Buchung Informationen
- Beiträge in diesem Thema: 7 Beiträge
- Mitglieder in diesem Forum: 0 Mitglieder und 244 Gäste
- Du darfst keine neuen Themen in diesem Forum erstellen.
- Du darfst keine Antworten zu Themen in diesem Forum erstellen.
- Du darfst deine Beiträge in diesem Forum nicht ändern.
- Du darfst deine Beiträge in diesem Forum nicht löschen.
- Du darfst keine Dateianhänge in diesem Forum erstellen.

