**habe mittlerweile mehrere scans hinter mir und mit security taskmanager "media creative.exe" bzw. "army settings.exe" in quarantäne geschickt...
Code:
Logfile of HijackThis v1.99.1
Scan saved at 15:31:03, on 10.07.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Unable to get Internet Explorer version!
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\SYSTEM32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\devldr32.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
f:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
f:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
C:\WINDOWS\system32\crypserv.exe
C:\WINDOWS\system32\DVDRAMSV.exe
f:\Programme\Kerio\Personal Firewall\persfw.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\SYSTEM32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
F:\Programme\DU Meter\DUMeter.exe
F:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe
F:\Programme\RivaTuner v2.0 RC 15.6\RivaTuner.exe
F:\Programme\Cherry\KeyMan\KeyMan.exe
F:\Programme\Motherboard Monitor 5\MBM5.EXE
F:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
C:\Programme\RK Launcher\RKLauncher.exe
C:\WINDOWS\system32\RAMASST.exe
F:\Programme\Cherry\CDI\CDI.exe
F:\Programme\foobar2000\foobar2000.exe
C:\Programme\Mozilla Thunderbird\thunderbird.exe
C:\Programme\Mozilla Firefox\firefox.exe
C:\Dokumente und Einstellungen\Dom\Desktop\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - Default URLSearchHook is missing
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - F:\Programme\Adobe\Acrobat 6.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: (no name) - {C7806610-CE16-DA97-8BAC-22DAF83FA763} - C:\DOKUME~1\Dom\ANWEND~1\INTERN~1\Dumb Proxy.exe
O4 - HKLM\..\Run: [UpdReg] C:\WINDOWS\Updreg.exe
O4 - HKLM\..\Run: [AHQInit] f:\Programme\Creative\SBLive\Program\AHQInit.exe
O4 - HKLM\..\Run: [DU Meter] F:\Programme\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [AVG7_CC] f:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe /STARTUP
O4 - HKLM\..\Run: [RivaTuner] "f:\Programme\RivaTuner v2.0 RC 15.6\RivaTuner.exe" /T
O4 - HKLM\..\Run: [RivaTunerStartupDaemon] "f:\Programme\RivaTuner v2.0 RC 15.6\RivaTuner.exe" /S
O4 - HKLM\..\Run: [NVIDIA nTune] "F:\Programme\NVIDIA Corporation\nTune\\nTune.exe" clear
O4 - HKLM\..\Run: [CherryKeyMan] "F:\Programme\Cherry\KeyMan\KeyMan.exe"
O4 - HKLM\..\Run: [CloneCDTray] "f:\Programme\SlySoft\CloneCD\CloneCDTray.exe" /s
O4 - HKLM\..\Run: [MBM 5] "F:\Programme\Motherboard Monitor 5\MBM5.EXE"
O4 - HKLM\..\Run: [AVG7_EMC] f:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe
O4 - HKCU\..\Run: [RK Launcher] C:\Programme\RK Launcher\RKLauncher.exe
O4 - Startup: wichtig.txt
O4 - Global Startup: RAMASST.lnk = C:\WINDOWS\system32\RAMASST.exe
O15 - ProtocolDefaults: '@ivt' protocol is in My Computer Zone, should be Intranet Zone
O15 - ProtocolDefaults: 'file' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'ftp' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'http' protocol is in My Computer Zone, should be Internet Zone
O15 - ProtocolDefaults: 'https' protocol is in My Computer Zone, should be Internet Zone
O16 - DPF: {14F65762-96FB-44B9-8DAC-93845F377A0E} (FileSharingCtrl Class) - http://appdirectory.messenger.msn.co...haringctrl.cab
O16 - DPF: {5DA9D8E0-5A57-11CF-9E36-00C0930198C0} (Pegasus ImagN' 32-bit (Windowed) ActiveX Control v4.00) - http://192.168.0.221/LNetCam.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.co...?1102622603081
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall-Kontrolle) - http://a840.g.akamai.net/7/840/537/2...ll/xscan53.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{C4FF3269-3D64-460D-9D04-06678930034E}: NameServer = 192.168.0.1
O18 - Filter: text/html - (no CLSID) - (no file)
O20 - AppInit_DLLs: ,
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - f:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe
O23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - f:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe
O23 - Service: Cherry Device Interface - Cherry Gmbh, Auerbach Germany, www.cherry.de - F:\Programme\Cherry\CDI\CDI.exe
O23 - Service: Crypkey License - Kenonic Controls Ltd. - C:\WINDOWS\SYSTEM32\crypserv.exe
O23 - Service: DVD-RAM_Service - Matsu****a Electric Industrial Co., Ltd. - C:\WINDOWS\system32\DVDRAMSV.exe
O23 - Service: Kerio Personal Firewall (PersFw) - Kerio Technologies - f:\Programme\Kerio\Personal Firewall\persfw.exe
3D-Fahrschule 2
Ad-Aware SE Personal
Adobe Acrobat 6.0.1 Professional - English, Français, Deutsch
Advanced Archive Password Recovery
Anti-Leech Plugin for Internet Explorer
Anti-Leech Plugin for Netscape, Mozilla, Opera
ArcSoft Camera Suite 1.3
ATI - Software Uninstall Utility
ATI Control Panel
ATI Display Driver
ATITool Overclocking Utility
AVG Free Edition
AVI/MPEG/RM/WMV Joiner 4.81
Bradford Smith Easy SFV Creator
Cheating-Death 4.29.5
Cherry Keyboard Manager V2.4 Build 15
ClearType Tuning Control Panel Applet
CloneCD
CloneDVD2
DAEMON Tools
DC++ 0.670
Digital TV
Digital TV UPDATE v2.1.7
Disk Space Inspector v.2.9.6
DivX Player
DU Meter
DVD Decrypter (Remove Only)
DVD Shrink 3.1.7
DVD2one 1.5.2
DVD-RAM-Treiber
eMule
Euro-Fahrschule 2005
FlashFXP v3
FlashGet(JetCar)
FlyakiteOSX v2.0
Folder Lock
foobar2000
GTA San Andreas
GTK+ Runtime 2.6.7 rev a (nur entfernen)
HijackThis 1.99.1
HyperVcam Mobile
iColorFolder
ICQ
IrfanView (remove only)
IsoBuster 1.7
J2SE Runtime Environment 5.0 Update 2
Jasc Paint Shop Pro 9
Java 2 Runtime Environment, SE v1.4.2_06
Kerio Personal Firewall 2.1.5
Mac:MSN Skin
Macromedia Shockwave Player
Magic ISO Maker v4.9 (build 0144)
Microsoft Encarta Enzyklopädie 2005
Microsoft Office Professional Edition 2003
Microsoft Plus! for Windows XP
Microsoft® Winter Fun Pack 2004 for Windows® XP
mIRC
Motherboard Monitor 5
Motherboard Monitor 5 Languages
Mozilla Firefox (1.0.4)
Mozilla Thunderbird (1.0)
Mozilla Thunderbird (1.0.2)
MSN Messenger 7.0
Need for Speed Underground 2
Nero 6 Enterprise Edition
NetLimiter 1.30 (remove only)
NVIDIA Drivers
NVIDIA nTune
O&O Defrag Professional Edition
PowerDVD
PowerStrip 3 (remove only)
QuickTime
RealPlayer
Remove DivX Codec
RivaTuner v2.0 RC 15.6
RollerCoaster Tycoon 2
Shockwave
Skype 1.2
Sound Blaster Live!
Spybot - Search & Destroy 1.4
Spyware Doctor 3.2
TMPGEnc Plus 2.5
TV-Browser 1.0
TVgenial
Tweak UI
USB MP3 Player WIN98 Drivers
VideoLAN VLC media player 0.8.1
VNC 4.0
Wecker 2.2 2.2
Windows Installer 3.1 (KB893803)
Windows XP Service Pack 2
Windows XP-Hotfix - KB834707
Windows XP-Hotfix - KB867282
Windows XP-Hotfix - KB873333
Windows XP-Hotfix - KB873339
Windows XP-Hotfix - KB885250
Windows XP-Hotfix - KB885835
Windows XP-Hotfix - KB885836
Windows XP-Hotfix - KB886185
Windows XP-Hotfix - KB887472
Windows XP-Hotfix - KB887742
Windows XP-Hotfix - KB888113
Windows XP-Hotfix - KB888302
Windows XP-Hotfix - KB890047
Windows XP-Hotfix - KB890175
Windows XP-Hotfix - KB890859
Windows XP-Hotfix - KB890923
Windows XP-Hotfix - KB891781
Windows XP-Hotfix - KB893066
Windows XP-Hotfix - KB893086
WinRAR Archivierer
Xfire (remove only)
xp-AntiSpy 3.92
XPlite PROFESSIONAL
Process list saved on 15:29:41, on 10.07.2005
Platform: Windows XP SP2 (WinNT 5.01.2600)
[pid] [full path to filename] [file version] [company name]
536 C:\WINDOWS\System32\smss.exe 5.1.2600.2180 Microsoft Corporation
600 C:\WINDOWS\system32\csrss.exe 5.1.2600.2180 Microsoft Corporation
624 C:\WINDOWS\SYSTEM32\winlogon.exe 5.1.2600.2180 Microsoft Corporation
672 C:\WINDOWS\system32\services.exe 5.1.2600.2180 Microsoft Corporation
684 C:\WINDOWS\system32\lsass.exe 5.1.2600.2180 Microsoft Corporation
852 C:\WINDOWS\system32\Ati2evxx.exe 6.14.10.4115 ATI Technologies Inc.
864 C:\WINDOWS\system32\svchost.exe 5.1.2600.2180 Microsoft Corporation
944 C:\WINDOWS\system32\svchost.exe 5.1.2600.2180 Microsoft Corporation
952 C:\WINDOWS\system32\devldr32.exe 1.0.0.22 Creative Technology Ltd.
1016 C:\WINDOWS\System32\svchost.exe 5.1.2600.2180 Microsoft Corporation
1072 C:\WINDOWS\System32\svchost.exe 5.1.2600.2180 Microsoft Corporation
1188 C:\WINDOWS\System32\svchost.exe 5.1.2600.2180 Microsoft Corporation
1332 C:\WINDOWS\system32\spoolsv.exe 5.1.2600.2180 Microsoft Corporation
1524 f:\PROGRA~1\Grisoft\AVGFRE~1\avgamsvr.exe 7.1.0.321 GRISOFT, s.r.o.
1560 f:\PROGRA~1\Grisoft\AVGFRE~1\avgupsvc.exe 7.1.0.321 GRISOFT, s.r.o.
1584 C:\WINDOWS\system32\crypserv.exe 5.4.0.0 Kenonic Controls Ltd.
1604 C:\WINDOWS\system32\DVDRAMSV.exe 2.0.7.0 Matsu****a Electric Industrial Co., Ltd.
1664 f:\Programme\Kerio\Personal Firewall\persfw.exe 2.1.5.0 Kerio Technologies
1756 C:\WINDOWS\System32\svchost.exe 5.1.2600.2180 Microsoft Corporation
2036 C:\WINDOWS\System32\alg.exe 5.1.2600.2180 Microsoft Corporation
1104 C:\WINDOWS\SYSTEM32\Ati2evxx.exe 6.14.10.4115 ATI Technologies Inc.
1408 C:\WINDOWS\Explorer.EXE 6.0.2900.2180 Microsoft Corporation
2028 F:\Programme\DU Meter\DUMeter.exe 3.0.7.192 Hagel Technologies
248 F:\PROGRA~1\Grisoft\AVGFRE~1\avgcc.exe 7.1.0.321 GRISOFT, s.r.o.
1940 F:\Programme\RivaTuner v2.0 RC 15.6\RivaTuner.exe 2.0.15.6
1900 F:\Programme\Cherry\KeyMan\KeyMan.exe 2.4.0.15 Cherry GmbH
436 F:\Programme\Motherboard Monitor 5\MBM5.EXE 5.3.7.0 Alex van Kaam
1896 F:\PROGRA~1\Grisoft\AVGFRE~1\avgemc.exe 7.1.0.321 GRISOFT, s.r.o.
784 C:\Programme\RK Launcher\RKLauncher.exe 0.4.0.0 RaduKing
520 C:\WINDOWS\system32\RAMASST.exe 1.0.9.0 Matsu****a Electric Industrial Co., Ltd.
332 F:\Programme\Cherry\CDI\CDI.exe 2.2.1.11 Cherry Gmbh, Auerbach Germany, www.cherry.de
2876 F:\Programme\foobar2000\foobar2000.exe
2360 C:\Programme\Mozilla Thunderbird\thunderbird.exe 1.0.2.0 Mozilla.org
2908 C:\Programme\Mozilla Firefox\firefox.exe 1.0.4.0 Mozilla
3124 C:\Dokumente und Einstellungen\Dom\Desktop\HijackThis.exe 1.99.0.1 Soeperman Enterprises Ltd.