Hab schon in der Reg nachgeschaut...aber nix Virenscanner und Adware ergaben auch nichts.... Hi-Jack This log ergab :
StartupList report, 11.01.2004, 12:30:18 StartupList version: 1.52 Started from : C:\Dokumente und Einstellungen\SON\Eigene Dateien\hijackthis\HijackThis.EXE Detected: Windows XP (WinNT 5.01.2600) Detected: Internet Explorer v6.00 (6.00.2600.0000) * Using default options ==================================================
-------------------------------------------------- End of report, 4.240 bytes Report generated in 0,016 seconds
Command line options: /verbose - to add additional info on each section /complete - to include empty sections and unsuspicious data /full - to include several rarely-important sections /force9x - to include Win9x-only startups even if running on WinNT /forcent - to include WinNT-only startups even if running on Win9x /forceall - to include all Win9x and WinNT startups, regardless of platform /history - to list version history only
Hab auch schon den Sicherheitspatch für IE geladen. Irgendwie muß ich doch das wieder loswerden....BITTE helft mir .
Gruß SONO
Um auf dieses Thema zu ANTWORTEN bitte erst » hier kostenlos registrieren!!
also ich verzweifel echt seit tagen hier...
Immer wenn ich IE ( 6er ) aufmache wechseln sich bei jedem aufmachen diese 4 Seiten ab:
http://wetsearch.ws/
http://searchclub.ws/
http://cool-search.ws/
http://allsearch.ws/
Hab schon in der Reg nachgeschaut...aber nix
Virenscanner und Adware ergaben auch nichts....
Hi-Jack This log ergab :
StartupList report, 11.01.2004, 12:30:18
StartupList version: 1.52
Started from : C:\Dokumente und Einstellungen\SON\Eigene Dateien\hijackthis\HijackThis.EXE
Detected: Windows XP (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 (6.00.2600.0000)
* Using default options
==================================================
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\SOUNDMAN.EXE
C:\PROGRA~1\Zone Labs\ZoneAlarm\zapro.exe
C:\WINDOWS\TPPALDR.EXE
C:\Programme\Winamp\winampa.exe
C:\Programme\Chameleon Clock\ChamClock.exe
C:\PROGRA~1\INCRED~1\bin\IncMail.exe
C:\Programme\FRITZ!\FriFax32.exe
C:\Programme\Antivirus-Profi-Paket\AVKService.exe
C:\Programme\Antivirus-Profi-Paket\AVKWCtl.exe
C:\WINDOWS\system32\ZONELABS\vsmon.exe
C:\Programme\mIRC6.12Invision2.0\mirc.exe
C:\WINDOWS\system32\notepad.exe
C:\Programme\Internet Explorer\IEXPLORE.EXE
C:\Dokumente und Einstellungen\SON\Eigene Dateien\hijackthis\HijackThis.exe
--------------------------------------------------
Listing of startup folders:
Shell folders Common Startup:
[C:\Dokumente und Einstellungen\All Users\Startmenü\Programme\Autostart]
FRITZ!fax.lnk = C:\Programme\FRITZ!\FriFax32.exe
--------------------------------------------------
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
--------------------------------------------------
Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
SiSUSBRG = C:\WINDOWS\sisUSBrg.exe
SoundMan = SOUNDMAN.EXE
SiS Tray =
SiS KHooker = C:\WINDOWS\System32\khooker.exe
Tweak UI 1.33 deutsch = RUNDLL32.EXE TWEAKUI.CPL,TweakMeUp
Zone Labs Client = C:\PROGRA~1\Zone Labs\ZoneAlarm\zapro.exe
TPP Auto Loader = C:\WINDOWS\TPPALDR.EXE
NeroFilterCheck = C:\WINDOWS\system32\NeroCheck.exe
WinampAgent = C:\Programme\Winamp\winampa.exe
--------------------------------------------------
Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HomeAlarm = C:\Programme\Chameleon Clock\ChamClock.exe
IncrediMail = C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
--------------------------------------------------
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
Shell=Explorer.exe
SCRNSAVE.EXE=C:\WINDOWS\AQUATI~1.SCR
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry key not found*
HKLM\..\Policies: Shell=*Registry value not found*
--------------------------------------------------
Enumerating Download Program Files:
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\macromed\flash\Flash.ocx
CODEBASE = http://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
[IMDownloader Class]
CODEBASE = http://www2.incredimail.com/contents/setup/downloader/imloader.cab
--------------------------------------------------
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
--------------------------------------------------
End of report, 4.240 bytes
Report generated in 0,016 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Hab auch schon den Sicherheitspatch für IE geladen.
Irgendwie muß ich doch das wieder loswerden....BITTE helft mir .
Gruß SONO