000
21.12.2004, 13:50
Sir_Killalot
|
wie im titel schon steht, hab ich seit neustem die "Begin2Search.com Bar" im IE. Ich benutze den zwar nicht (benutze eigentlich Firefox), aber ich brauche den für Informatik HP's etc. Also stört diese schei* leiste da. Ich kann sie zwar ausschalten, aber beim neustarten vom IE is sie wieder da. Hab schon Cookies gelöscht, Temp ordner, hab schon Ad-Aware drüber laufen lassen, SpybotS&D. was kann ich machen damit die leiste wieder verschwindet? thx 4 help
--
|
|
Profil || Suche
|
001
21.12.2004, 14:10
Acumen
|
hast auch mal cwshredder und hijackthis drüberlaufen lassen ? Die warn mir schon mehrmals bei solchen komischen Leisten recht hilfreich. Wundert mich aber auch, dass spybot das net findet :/
--
|
|
Profil || Suche
|
002
21.12.2004, 14:34
Sir_Killalot
|
das erste programm hat nix gefunden, mit dem zweiten komm ich nich so gut klar x_X
--
|
|
Profil || Suche
|
003
21.12.2004, 18:14
Primzahl
|
Diese Leisten sind mittlerweile idR. sehr hartnäckig.
Die eine versteckt sich in .dlls, die nächste in 2-3 Tasks die sich immerwieder gegenseitig starten, andere in der Registry und manche weiß ich nicht wo um Gottes willen die sich versteckt haben.
Viel Glück beim Suchen :/
--
Trollpolizei!!! °_o "War is God's way of teaching geography to Americans." "RTFM du beschissener Kack-B00n..." Forenregeln | TheWall Wiki | Source SDK Dokumentation
|
|
Profil || Suche
|
004
22.12.2004, 17:29
Grim_Reaper
|
poste mal die hijackthis log, damit kann man viel anfangen
--
Ich hab mal meine Sig ausgenistet , O O , `´°¤|Webmaster beim XdT-Clan|¤°`´°¤|Me at Deviantart|¤°`´ `´°¤|Quatronic|¤°`´`´°¤|Clubwear|¤°`´
|
|
Profil || Suche
|
005
22.12.2004, 17:46
BRoDO
|
mal ne (nicht ganz zum thema passende) frage: kann man die leute (Begin2Search.com) deswegen eigentlich verklagen??
--
[ Kein STEAM | Kein TGC/TCPA | Keine Softwarepatente |Keine Alternativ-OS-Propaganda in Windows-Threads | Keine Bewertungen ][KEIN GARNIX!]
|
|
Profil || Suche
|
006
22.12.2004, 19:18
Primzahl
|
Wenn es dir dadurch zu körperlichen oder finaziellen Schaden gekommen ist (denkbar wäre in extremfällen ggf. Arbeitsausfall) ja.
--
Trollpolizei!!! °_o "War is God's way of teaching geography to Americans." "RTFM du beschissener Kack-B00n..." Forenregeln | TheWall Wiki | Source SDK Dokumentation
|
|
Profil || Suche
|
007
22.12.2004, 19:23
Sir_Killalot
|
da is die log datei:
Logfile of HijackThis v1.99.0 Scan saved at 19:22:14, on 22.12.2004 Platform: Windows 2000 SP4 (WinNT 5.00.2195) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes: C:\WINNT\System32\smss.exe C:\WINNT\system32\winlogon.exe C:\WINNT\system32\services.exe C:\WINNT\system32\lsass.exe C:\WINNT\system32\Ati2evxx.exe C:\WINNT\system32\svchost.exe C:\WINNT\system32\spoolsv.exe F:\AnitVir\AVGUARD.EXE F:\FoxServ\Apache\bin\Apache.exe F:\AnitVir\AVWUPSRV.EXE C:\WINNT\system32\drivers\CDAC11BA.EXE C:\WINNT\system32\DRIVERS\CDANTSRV.EXE C:\WINNT\System32\svchost.exe F:\FoxServ\Apache\bin\Apache.exe F:\FoxServ\mysql\bin\mysqld-nt.exe C:\WINNT\system32\regsvc.exe C:\WINNT\system32\MSTask.exe C:\WINNT\system32\ZoneLabs\vsmon.exe C:\WINNT\System32\WBEM\WinMgmt.exe C:\WINNT\system32\MsPMSPSv.exe C:\WINNT\system32\svchost.exe C:\WINNT\System32\svchost.exe C:\Programme\Citrix\ICA-Client\ssonsvr.exe C:\WINNT\system32\Ati2evxx.exe C:\WINNT\Explorer.EXE C:\WINNT\Mixer.exe C:\WINNT\system32\svchostn.exe C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe C:\Programme\Java\j2re1.4.2_05\bin\jusched.exe F:\ZoneAlarm\zlclient.exe F:\PTBSync\PTBSync.exe C:\WINNT\system32\svcload.exe C:\Programme\NVIDIA Corporation\NvMixer\NVMixerTray.exe C:\WINNT\system32\svcnhost.exe F:\AnitVir\AVGNT.EXE C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe C:\WINNT\system32\svchostn.exe C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\wkcalrem.exe F:\ICQ\Icq.exe F:\Mozilla Firefox\firefox.exe F:\Winamp5\winamp.exe C:\WINNT\explorer.exe C:\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.popupsearches.com/sidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.popupsearches.com/sidesearch.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web.de/ R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINNT\system32\winb2s32.dll O2 - BHO: ohb - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - C:\WINNT\system32\dsktrf.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 - Toolbar: Begin2Search.com Bar - {52FE5233-367C-4EFB-BDD7-0BE4D212C107} - C:\WINNT\system32\winb2s32.dll O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon O4 - HKLM\..\Run: [C-Media Mixer] Mixer.exe /startup O4 - HKLM\..\Run: [netservices] svchostn.exe O4 - HKLM\..\Run: [Configuration Loader] securefix.exe O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [dwStart] F:\FarStone\Firewall\FireWall.exe O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINNT\system32\NeroCheck.exe O4 - HKLM\..\Run: [CloneCDTray] "F:\CloneCD\CloneCDTray.exe" /s O4 - HKLM\..\Run: [SunJavaUpdateSched] C:\Programme\Java\j2re1.4.2_05\bin\jusched.exe O4 - HKLM\..\Run: [Zone Labs Client] "F:\ZoneAlarm\zlclient.exe" O4 - HKLM\..\Run: [PTBSync] F:\PTBSync\PTBSync.exe /Start O4 - HKLM\..\Run: [svcload] svcload.exe O4 - HKLM\..\Run: [NVMixerTray] "C:\Programme\NVIDIA Corporation\NvMixer\NVMixerTray.exe" O4 - HKLM\..\Run: [svcnhost] svcnhost.exe O4 - HKLM\..\Run: [AVGCtrl] "F:\AnitVir\AVGNT.EXE" /min O4 - HKLM\..\Run: [RebateNation0] C:\Programme\Rebate_Nation\RebateNation0.exe O4 - HKLM\..\Run: [ATIPTA] C:\Programme\ATI Technologies\ATI Control Panel\atiptaxx.exe O4 - HKLM\..\RunServices: [netservices] svchostn.exe O4 - HKLM\..\RunServices: [Configuration Loader] securefix.exe O4 - HKLM\..\RunServices: [svcload] svcload.exe O4 - HKLM\..\RunServices: [svcnhost] svcnhost.exe O4 - HKCU\..\Run: [WashAndGo - Cleanup of old Backupfiles] F:\Purgatio Pro\checker.exe /check O4 - HKCU\..\Run: [netservices] svchostn.exe O4 - HKCU\..\Run: [BackWeb LiteInstaller] C:\DOKUME~1\Martin\LOKALE~1\Temp\ins1.tmp\LiteInst.exe /NoIntervention O4 - HKCU\..\Run: [LDM] \Program\BackWeb-8876480.exe O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe O4 - Global Startup: Erinnerungen für Microsoft Works-Kalender.lnk = C:\Programme\Gemeinsame Dateien\Microsoft Shared\Works Shared\wkcalrem.exe O4 - Global Startup: Logitech Desktop Messenger.lnk = F:\Logitech\Desktop Messenger\8876480\Program\LDMConf.exe O4 - Global Startup: Microsoft Office.lnk = F:\Microsoft Office\Office\OSA9.EXE O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\WINNT\system32\msjava.dll O9 - Extra button: ICQ Pro - {6224f700-cba3-4071-b251-47cb894244cd} - F:\ICQ\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ - {6224f700-cba3-4071-b251-47cb894244cd} - F:\ICQ\ICQ.exe O9 - Extra button: Related - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm O9 - Extra 'Tools' menuitem: Show &Related Links - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\WINNT\web\related.htm O10 - Broken Internet access because of LSP provider 'farlsp.dll' missing O16 - DPF: {27527D31-447B-11D5-A46E-0001023B4289} (CoGSManager Class) - http://gamingzone.ubisoft.com/dev/packages/GSManager.cab O16 - DPF: {30000273-8230-4DD4-BE4F-6889D1E74167} - http://download.abetterinternet.com/download/cabs/FON14006/thin.cab O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (FilePlanet Download Control Class) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_1_0_0_42.cab O16 - DPF: {62475759-9E84-458E-A1AB-5D2C442ADFDE} - http://a1540.g.akamai.net/7/1540/52/20040428/qtinstall.info.apple.com/saba/de/win/QuickTimeInstaller.exe O23 - Service: AntiVir Service - H+BEDV Datentechnik GmbH - F:\AnitVir\AVGUARD.EXE O23 - Service: Apache - Apache Software Foundation - F:\FoxServ\Apache\bin\Apache.exe O23 - Service: Ati HotKey Poller - Unknown - C:\WINNT\system32\Ati2evxx.exe O23 - Service: ATI Smart - Unknown - C:\WINNT\system32\ati2sgag.exe O23 - Service: AntiVir Update - H+BEDV Datentechnik GmbH, Germany - F:\AnitVir\AVWUPSRV.EXE O23 - Service: C-DillaCdaC11BA - Macrovision - C:\WINNT\system32\drivers\CDAC11BA.EXE O23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINNT\system32\DRIVERS\CDANTSRV.EXE O23 - Service: Verwaltungsdienst für die Verwaltung logischer Datenträger - VERITAS Software Corp. - C:\WINNT\System32\dmadmin.exe O23 - Service: MySql - Unknown - F:/FoxServ/mysql/bin/mysqld-nt.exe O23 - Service: Atomuhr Synchronisation - ElmüSoft - F:\PTBSync\PTBSync.exe O23 - Service: TrueVector Internet Monitor - Zone Labs Inc. - C:\WINNT\system32\ZoneLabs\vsmon.exe
--
|
|
Profil || Suche
|
008
23.12.2004, 00:22
common
|
suspekt scheinen
C:\WINNT\system32\drivers\CDAC11BA.EXE C:\WINNT\system32\DRIVERS\CDANTSRV.EXE
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.popupsearches.com/sidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.popupsearches.com/sidesearch.html R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.popupsearches.com/sidesearch.html R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.web.de/ R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.popupsearches.com/sidesearch.html O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - F:\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll O2 - BHO: ohb - {4D568F0F-8AC9-40AB-88B7-415134C78777} - C:\WINNT\system32\winb2s32.dll O2 - BHO: ohb - {CB5B2BC6-F957-4D8A-BE67-83F3EC58BA01} - C:\WINNT\system32\dsktrf.dll O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\System32\msdxm.ocx O3 - Toolbar: Begin2Search.com Bar - {52FE5233-367C-4EFB-BDD7-0BE4D212C107} - C:\WINNT\system32\winb2s32.dll O4 - HKLM\..\Run: [svcnhost] svcnhost.exe
--
|
|
Profil || Suche
|
009
23.12.2004, 11:15
Sir_Killalot
|
ah, THX, jetzt ist der scheis wieder weg!!
--
Dieser Beitrag wurde am 23.12.2004 um 11:25 von Sir_Killalot bearbeitet.
|
|
Profil || Suche
|
010
23.12.2004, 17:03
Primzahl
|
C:\WINNT\system32\drivers\CDAC11BA.EXE C:\WINNT\system32\DRIVERS\CDANTSRV.EXE Das ist afaik nicht böse, dürfte C-Dilla sein. Rest ist verdächtig.
--
Trollpolizei!!! °_o "War is God's way of teaching geography to Americans." "RTFM du beschissener Kack-B00n..." Forenregeln | TheWall Wiki | Source SDK Dokumentation
|
|
Profil || Suche
|
011
24.12.2004, 16:00
Grim_Reaper
|
O4 - HKLM\..\Run: [RebateNation0] C:\Programme\Rebate_Nation\RebateNation0.exe
den würd ich auch nochma abchecken.
--
Ich hab mal meine Sig ausgenistet , O O , `´°¤|Webmaster beim XdT-Clan|¤°`´°¤|Me at Deviantart|¤°`´ `´°¤|Quatronic|¤°`´`´°¤|Clubwear|¤°`´
|
|
Profil || Suche
|