Es öffnen sich immer komische Startseiten. Der IE merkt sich nie meine eingegebene Startseite. Und es kommt fast immer boredelife vor meiner eingegebenen Site. Habe mit hijackthis unten stehendes kog file erstellt. Was muss ich jetzt davon rauslöschen?
Logfile of HijackThis v1.97.7
Scan saved at 14:41:24, on 20.03.2004
Platform: Windows 2000 SP2 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:WINNTSystem32smss.exe
C:WINNTsystem32winlogon.exe
C:WINNTsystem32services.exe
C:WINNTsystem32lsass.exe
C:WINNTsystem32svchost.exe
C:WINNTsystem32spoolsv.exe
C:WINNTSystem32Ati2evxx.exe
C:ProgrammeMcAfeeMcAfee VirusScanAvsynmgr.exe
C:ProgrammeAVPersonalAVWUPSRV.EXE
C:WINNTSystem32svchost.exe
C:WINNTsystem32regsvc.exe
C:WINNTSystem32r_server.exe
C:WINNTsystem32MSTask.exe
C:WINNTSystem32WBEMWinMgmt.exe
C:ProgrammeMcAfeeMcAfee VirusScanVsStat.exe
C:ProgrammeMcAfeeMcAfee VirusScanVshwin32.exe
C:ProgrammeGemeinsame DateienNetwork AssociatesMcShieldMcshield.exe
C:ProgrammeMcAfeeMcAfee VirusScanAvconsol.exe
C:WINNTExplorer.EXE
C:WINNTSystem32RunDll32.exe
C:ProgrammeATI TechnologiesATI Control Panelatiptaxx.exe
C:ProgrammeElaborate BytesCloneCDCloneCDTray.exe
C:ProgrammeWinamp3winampa.exe
C:ProgrammeD-Toolsdaemon.exe
C:ProgrammeTelefonCDOtbStart.EXE
C:PROGRA~1A4TechMouseAmoumain.exe
C:ProgrammeMcAfeeMcAfee Shared ComponentsInstant UpdaterRuLaunch.exe
C:ProgrammeInterVideoCommonBinWinCinemaMgr.exe
C:ProgrammeInternet ExplorerIEXPLORE.EXE
C:DownloadsHijackThishijackthis1977HijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet Explorer,SearchURL = http://in.webcounter.cc/--/?cxlow (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://ozbdet.t.muxa.cc/s.php?aid=420 (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Search Page = http://riviera.cc (obfuscated)
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.at/
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://in.webcounter.cc/-/?cxlow (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://in.webcounter.cc/--/?cxlow (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://riviera.cc (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerSearch,CustomizeSearch = http://in.webcounter.cc/--/?cxlow (obfuscated)
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://riviera.cc (obfuscated)
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Bar = http://ozbdet.t.muxa.cc/s.php?aid=420 (obfuscated)
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://riviera.cc (obfuscated)
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://in.webcounter.cc/--/?cxlow (obfuscated)
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant = http://riviera.cc (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page_bak = http://www.boredlife.com/p/www.yahoo.de
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,HomeOldSP = http://riviera.cc (obfuscated)
R1 - HKCUSoftwareMicrosoftInternet Explorer,Search = http://in.webcounter.cc/--/?cxlow (obfuscated)
R1 - HKLMSoftwareMicrosoftInternet Explorer,Search = http://in.webcounter.cc/--/?cxlow (obfuscated)
O2 - BHO: (no name) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:ProgrammeAdobeAcrobat 6.0ReaderActiveXAcroIEHelper.dll
O2 - BHO: (no name) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:programmegooglegoogletoolbar1.dll
O3 - Toolbar: McAfee VirusScan - {ACB1E670-3217-45C4-A021-6B829A8A27CB} - C:ProgrammeMcAfeeMcAfee VirusScanVSCShellExtension.dll
O3 - Toolbar: (no name) - {3C624F62-E7D9-4154-9C93-F3489069FD52} - (no file)
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:programmegooglegoogletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:WINNTSystem32msdxm.ocx
O4 - HKLM..Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM..Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWnd
O4 - HKLM..Run: [ATIPTA] C:ProgrammeATI TechnologiesATI Control Panelatiptaxx.exe
O4 - HKLM..Run: [CloneCDElbyCDFL] "C:ProgrammeElaborate BytesCloneCDElbyCheck.exe" /L ElbyCDFL
O4 - HKLM..Run: [CloneCDTray] "C:ProgrammeElaborate BytesCloneCDCloneCDTray.exe"
O4 - HKLM..Run: [WinampAgent] "C:ProgrammeWinamp3winampa.exe"
O4 - HKLM..Run: [DAEMON Tools-1033] "C:ProgrammeD-Toolsdaemon.exe" -lang 1033
O4 - HKLM..Run: [OtbStart] C:ProgrammeTelefonCDOtbStart.EXE
O4 - HKLM..Run: [WheelMouse] C:PROGRA~1A4TechMouseAmoumain.exe
O4 - HKLM..Run: [CloneDVDElbyDelay] "C:ProgrammeElaborate BytesCloneDVDElbyCheck.exe" /L ElbyDelay
O4 - HKLM..Run: [NeroFilterCheck] C:WINNTsystem32NeroCheck.exe
O4 - HKLM..Run: [SBHC] C:ProgrammeSuperBarsbhc.exe
O4 - HKLM..Run: [sys] regedit -s sysdllwm.reg
O4 - HKCU..Run: [McAfee.InstantUpdate.Monitor] "C:ProgrammeMcAfeeMcAfee Shared ComponentsInstant UpdaterRuLaunch.exe" /STARTMONITOR
O4 - HKCU..Run: [winlogon] c:winntwinlogon.exe
O4 - HKCU..Run: [16zgtws1h2] C:WINNTxxxv8j61nc.exe
O4 - HKCU..Run: [2a3dv5h7fe] C:WINNTjgbr8heb1s.exe
O4 - Startup: PowerReg Scheduler V3.exe
O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:ProgrammeInterVideoCommonBinWinCinemaMgr.exe
O4 - Global Startup: Microsoft Office.lnk = C:ProgrammeMicrosoft OfficeOfficeOSA9.EXE
O8 - Extra context menu item: &Google Search - res://C:ProgrammeGoogleGoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:ProgrammeGoogleGoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:ProgrammeGoogleGoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: Si&milar Pages - res://C:ProgrammeGoogleGoogleToolbar1.dll/cmsimilar.html
O9 - Extra button: Related (HKLM)
O9 - Extra 'Tools' menuitem: Show &Related Links (HKLM)
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/x86/unicod…8058.4489930556
O17 - HKLMSystemCCSServicesTcpip..{FCCDDA0F-B5D1-428E-B6D3-1F4292A2B52E}: NameServer = 195.58.160.2,195.58.160.3,195.58.161.3,195.3.96.67,195.3.96.68
O19 - User stylesheet: C:WINNTWebtips.ini
O19 - User stylesheet: C:WINNThh.htt (HKLM)
