Hallo,
ich habe Probleme, daß mein Notebook nicht mehr komplett herunterfährt. Durch Zufall habe ich das Programm Hijack entdeckt und habe ein Logfile erstellt:
Da ich kein PC-Spezialist bin, hoffe ich, dass ich alles richtig gemacht habe beim Einstellen des FilesCode:Logfile of HijackThis v1.99.1 Scan saved at 17:45:49, on 28.06.05 Platform: Windows 98 SE (Win9x 4.10.2222A) MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106) Running processes: C:\WINDOWS\SYSTEM\KERNEL32.DLL C:\WINDOWS\SYSTEM\MSGSRV32.EXE C:\WINDOWS\SYSTEM\MPREXE.EXE C:\WINDOWS\SYSTEM\mmtask.tsk C:\WINDOWS\SYSTEM\MSTASK.EXE c:\windows\SYSTEM\KB891711\KB891711.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\COMMON\FSMA32.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\COMMON\FSMB32.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\COMMON\FCH32.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSPC\FSHTTPS\FSHTTPS.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\BACKWEB\2581593\PROGRAM\FSBWSYS.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\BACKWEB\2581593\PROGRAM\FSPEX.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\COMMON\FAMEH32.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\ANTI-VIRUS\FSGK32.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FWES\PROGRAM\FSDFWD.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSPC\FSPC.EXE C:\WINDOWS\EXPLORER.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\ANTI-VIRUS\FSSM32.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\ANTI-VIRUS\FSAV32.EXE C:\WINDOWS\SYSTEM\RNAAPP.EXE C:\WINDOWS\SYSTEM\TAPISRV.EXE C:\WINDOWS\TASKMON.EXE C:\WINDOWS\SYSTEM\SYSTRAY.EXE C:\WINDOWS\SYSTEM\IRMON.EXE C:\WINDOWS\SYSTEM\PRPCUI.EXE C:\WINDOWS\ptsnoop.exe C:\LOGITE~1\MOUSE\SYSTEM\EM_EXEC.EXE C:\WINDOWS\TPPALDR.EXE C:\PROGRAMME\BORLAND\INTERBASE\BIN\IBGUARD.EXE C:\PROGRAMME\LOGITECH\ITOUCH\ITOUCH.EXE C:\WINDOWS\SYSTEM\QTTASK.EXE C:\PROGRAMME\GEMEINSAME DATEIEN\REAL\UPDATE_OB\REALSCHED.EXE C:\WINDOWS\SYSTEM\E_S5I0C1.EXE C:\WINDOWS\SYSTEM\SPOOL32.EXE C:\WINDOWS\SYSTEM\STIMON.EXE C:\PROGRAMME\FREEPDF\FREEPDFA.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\COMMON\FSM32.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSGUI\ISPNEWS.EXE C:\PROGRAMME\MESSENGER\MSMSGS.EXE C:\PROGRAMME\BORLAND\INTERBASE\BIN\IBSERVER.EXE C:\PROGRAMME\SAMSUNG\INTERNET LAUNCHER\LAUNCHER.EXE C:\PROGRAMME\LOGITECH\ITOUCH\KBDTRAY\KBDTRAY.EXE C:\WINDOWS\SYSTEM\WMIEXE.EXE C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSGUI\FSGUIEXE.EXE C:\PROGRAMME\RTL NET\STARTERKIT 1.0\RTLDIALER.EXE C:\WINDOWS\SYSTEM\PSTORES.EXE C:\PROGRAMME\INTERNET EXPLORER\IEXPLORE.EXE C:\PROGRAMME\MICROSOFT OFFICE\OFFICE\OUTLOOK.EXE C:\PROGRAMME\MICROSOFT OFFICE\OFFICE\1031\WFXMSRVR.EXE C:\PROGRAMME\MICROSOFT OFFICE\OFFICE\1031\OLFMOD32.EXE C:\WINDOWS\SYSTEM\DDHELP.EXE C:\WINDOWS\SYSTEM\BRQIKMON.EXE C:\WINDOWS\TEMP\HIJACKTHIS.EXE R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmx.de/ R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer O2 - BHO: IPInsigtObj Class - {000004CC-E4FF-4F2C-BC30-DBEF0B983BC9} - C:\WINDOWS\IPINSIGT.DLL O2 - BHO: TwaintecObj Class - {000020DD-C72E-4113-AF77-DD56626C6C42} - C:\WINDOWS\TWAINTEC.DLL (file missing) O2 - BHO: myBar BHO - {0494D0D1-F8E0-41ad-92A3-14154ECE70AC} - C:\PROGRAMME\MYWAY\MYBAR\1.BIN\MYBAR.DLL O2 - BHO: MyWay Search Assistant BHO - {04079851-5845-4dea-848C-3ECD647AA554} - C:\PROGRAMME\MYWAY\SRCHASTT\1.BIN\MYSRCHAS.DLL O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\PROGRAMME\ADOBE\ACROBAT 5.0\READER\ACTIVEX\ACROIEHELPER.OCX O2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\PROGRAMME\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM\MSDXM.OCX O3 - Toolbar: &SearchBar - {0494D0D9-F8E0-41ad-92A3-14154ECE70AC} - C:\PROGRAMME\MYWAY\MYBAR\1.BIN\MYBAR.DLL O3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\PROGRAMME\EPSON\EPSON WEB-TO-PAGE\EPSON WEB-TO-PAGE.DLL O4 - HKLM\..\Run: [ScanRegistry] c:\windows\scanregw.exe /autorun O4 - HKLM\..\Run: [TaskMonitor] c:\windows\taskmon.exe O4 - HKLM\..\Run: [SystemTray] SysTray.Exe O4 - HKLM\..\Run: [IrMon] IrMon.exe O4 - HKLM\..\Run: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe O4 - HKLM\..\Run: [PRPCMonitor] PRPCUI.exe O4 - HKLM\..\Run: [CountrySelection] pctptt.exe O4 - HKLM\..\Run: [PTSNOOP] ptsnoop.exe O4 - HKLM\..\Run: [CriticalUpdate] c:\windows\SYSTEM\wucrtupd.exe -startup O4 - HKLM\..\Run: [EM_EXEC] c:\LOGITE~1\MOUSE\SYSTEM\EM_EXEC.EXE O4 - HKLM\..\Run: [SENTRY] C:\WINDOWS\SENTRY.exe O4 - HKLM\..\Run: [TPP Auto Loader] C:\WINDOWS\TPPALDR.EXE O4 - HKLM\..\Run: [InterBaseGuardian] C:\Programme\Borland\InterBase\bin\ibguard.exe -a O4 - HKLM\..\Run: [zBrowser Launcher] C:\PROGRA~1\LOGITECH\ITOUCH\iTouch.exe O4 - HKLM\..\Run: [QuickTime Task] C:\WINDOWS\SYSTEM\QTTASK.EXE O4 - HKLM\..\Run: [TkBellExe] "C:\Programme\Gemeinsame Dateien\Real\Update_OB\realsched.exe" -osboot O4 - HKLM\..\Run: [EPSON Stylus Photo RX420 Series] C:\WINDOWS\SYSTEM\E_S5I0C1.EXE /P31 "EPSON Stylus Photo RX420 Series" /O5 "LPT1:" /M "Stylus Photo RX420" O4 - HKLM\..\Run: [StillImageMonitor] C:\WINDOWS\SYSTEM\STIMON.EXE O4 - HKLM\..\Run: [FreePDFAssistent] C:\PROGRA~1\FreePDF\FreePDFA.exe O4 - HKLM\..\Run: [F-Secure Manager] "C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\Common\FSM32.EXE" /splash O4 - HKLM\..\Run: [F-Secure TNB] "C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\TNB\TNBUtil.exe" /CHECKALL /WAITFORSW O4 - HKLM\..\Run: [F-Secure Startup Wizard] "C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSGUI\FSSW.EXE" /reboot O4 - HKLM\..\Run: [News Service] "C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSGUI\ispnews.exe" O4 - HKLM\..\RunServices: [LoadPowerProfile] Rundll32.exe powrprof.dll,LoadCurrentPwrScheme O4 - HKLM\..\RunServices: [SchedulingAgent] mstask.exe O4 - HKLM\..\RunServices: [MiniLog] C:\WINDOWS\SYSTEM\ZONELABS\MINILOG.EXE -service O4 - HKLM\..\RunServices: [KB891711] c:\windows\SYSTEM\KB891711\KB891711.EXE O4 - HKLM\..\RunServices: [F-Secure Management Agent] C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\Common\FSMA32.EXE O4 - HKCU\..\Run: [MSMSGS] C:\Programme\Messenger\msmsgs.exe /background O4 - Startup: Internet launcher.lnk = C:\Programme\SAMSUNG\Internet Launcher\launcher.exe O4 - Startup: Microsoft Office.lnk = C:\Programme\Microsoft Office\Office\OSA9.EXE O4 - Global Startup: T-TeleSec Personal Security Service.lnk = C:\Programme\T-TeleSec Personal Security Service\backweb\2581593\Program\fspex.exe O8 - Extra context menu item: Zur Filterliste hinzufügen (WebWasher) - http://-Web.Washer-/ie_add O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\SYSTEM\Shdocvw.dll O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE O9 - Extra 'Tools' menuitem: MSN Messenger Service - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE O9 - Extra button: iFinger - {936E5D60-596C-11D3-BB96-00600816DF55} - C:\WINDOWS\SYSTEM\SHDOCVW.DLL O9 - Extra button: Webfilter - {200DB664-75B5-47c0-8B45-A44ACCF73C00} - C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSPC\FSPCMSIE.DLL O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSPC\FSPCMSIE.DLL O9 - Extra 'Tools' menuitem: Diese Website &zulassen - {200DB664-75B5-47c0-8B45-A44ACCF73F04} - C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSPC\FSPCMSIE.DLL O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSPC\FSPCMSIE.DLL O9 - Extra 'Tools' menuitem: Diese Website &sperren - {200DB664-75B5-47c0-8B45-A44ACCF73F03} - C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSPC\FSPCMSIE.DLL O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSPC\FSPCMSIE.DLL O9 - Extra 'Tools' menuitem: Webseitenfilter &aussetzen - {200DB664-75B5-47c0-8B45-A44ACCF73F02} - C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSPC\FSPCMSIE.DLL O9 - Extra button: (no name) - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSPC\FSPCMSIE.DLL O9 - Extra 'Tools' menuitem: Website-&Liste anzeigen - {200DB664-75B5-47c0-8B45-A44ACCF73F01} - C:\PROGRAMME\T-TELESEC PERSONAL SECURITY SERVICE\FSPC\FSPCMSIE.DLL O12 - Plugin for .mp3: C:\PROGRA~1\INTERN~1\PLUGINS\npqtplugin3.dll O15 - Trusted Zone: www2.dtg.de O16 - DPF: {AE7E5F20-35C3-11D2-A16C-006008662F80} (Internet-Banking) - https://www.onlinebankservice.de/brokat/srwgib187.cab O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a224.g.akamai.net/7/224/52/20010419/qtinstall.info.apple.com/qt501/us/win/QuickTimeInstaller.exe O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/218abcbee7618708b605/netzip/RdxIE601_de.cab O16 - DPF: {205FF73B-CA67-11D5-99DD-444553540000} (CInstall Class) - http://www.spywarestormer.com/files2/Install.cab O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-12.cab. Virenscanner und Firewall ist installiert und ich arbeite mit Win98.
Kann mir bitte jemand den File analysieren und vielen Dank schon an Dich.
Viele Grüße
Ulrike


. Virenscanner und Firewall ist installiert und ich arbeite mit Win98.


(tja, ist alles nicht so einfach!!).
ialer.Win32.gen. No Action Taken.
)). Schlage mich aber immer noch wacker durch und gebe natürlich (auch dank Deiner geduldigen Hilfe) nicht auf.