Logfile von Trend Micro HijackThis v2.0.2
Scan gespeichert um 4:00:10 Uhr, am 04/03/2008
Betriebssystem: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)
Boot-Modus: Normal
Laufende Prozesse:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ spoolsv. exe
C: \ WINDOWS \ explorer.exe
C: \ Program Files \ Widcomm \ Bluetooth Software \ bin \ btwdins.exe
C: \ WINDOWS \ system32 \ cisvc.exe
C: \ WINDOWS \ system32 \ HPConfig.exe
C: \ PROGRA ~ 1 \ McAfee \ MSC \ mcmscsvc.exe
c: \ PROGRA ~ 1 \ COMMON ~ 1 \ McAfee \ MNA \ mcnasvc.exe
C: \ PROGRA ~ 1 \ McAfee.com \ Agent \ mcagent.exe
c: \ PROGRA ~ 1 \ COMMON ~ 1 \ McAfee \ mcproxy \ mcproxy.exe
C: \ Program Files \ McAfee \ MPF \ MPFSrv.exe
C: \ Program Files \ McAfee \ MSK \ MskSrver.exe
C: \ WINDOWS \ System32 \ tcpsvcs. exe
C: \ Program Files \ Synaptics \ SynTP \ SynTPLpr.exe
C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe
C: \ Programme \ Gemeinsame Dateien \ Real \ Update_OB \ realsched.exe
C: \ WINDOWS \ System32 \ snmp.exe
C: \ Program Files \ SiteAdvisor \ 6172 \ SiteAdv.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ WinHlp32.exe
C: \ WINDOWS \ WinHlp32.exe
C: \ WINDOWS \ WinHlp32.exe
C: \ WINDOWS \ WinHlp32.exe
C: \ WINDOWS \ WinHlp32.exe
C: \ WINDOWS \ system32 \ Cidaemon.exe
C: \ WINDOWS \ system32 \ wscntfy. exe
C: \ Program Files \ McAfee \ MSC \ mcuimgr.exe
C: \ Program Files \ Slimbrowser \ sbrowser.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Eigene Downloads \ HijackThis. exe
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Search Bar =
http://home.peoplepc.com/searchR0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Search, SearchAssistant =
http://home.peoplepc.com/searchR0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Local Page =
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Local Page =
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Window Title = Randys der Chef
R3 - URLSearchHook: (no name) - _ (37D2CDBF-2AF4-44AA-8113-BD0D2DA3C2B8) - (keine Datei)
F2 -- REG: system.ini: Userinit = C: \ WINDOWS \ system32 \ userinit.exe
O2 - BHO: Yahoo! Toolbar Helper - (02478D38-C3F9-4EFB-9B51-7695ECA05670) - C: \ Program Files \ Yahoo! \ Companion \ Installs \ cpn0 \ yt.dll
O2 - BHO: Adobe Reader PDF-Link Helper - (06849E9F-C8D7-4D59-B87D-784B7D6BE0B3) - C: \ Program Files \ Adobe \ Acrobat 7,0 \ ActiveX \ AcroIEHelper.dll
O2 - BHO: (no name) - (089FD14D-132B-48FC-8861-0048AE113215) - C: \ Program Files \ SiteAdvisor \ 6253 \ SiteAdv. DLL
O2 - BHO: McAntiPhishingBHO - (377C180E-6F0E-4D4C-980F-F45BD3D40CF4) - C: \ Program Files \ McAfee \ MSK \ mcapbho.dll
O2 - BHO: PaltalkWebLogin - (502C3BA4-2C3E-4317-BC29-C0445E82B1F9) - C: \ Programme \ Gemeinsame Dateien \ Paltalk \ PaltalkWebLogin.dll
O2 - BHO: Spybot-S & D IE Schutz - (53707962-6F74-2D53-2644-206D7942484F) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O2 - BHO: SSVHelper Class - (761497BB-D6F0-462C-B6EB-D4DAF1D92D43) - C: \ Program Files \ Java \ jre1.5.0_06 \ bin \ ssv. DLL
O2 - BHO: scriptproxy - (7DB2D5A0-7241-4E79-B68D-6309F01C5231) - C: \ Program Files \ McAfee \ VirusScan \ scriptsn.dll
O2 - BHO: Viewpoint Toolbar BHO - (A7327C09-B521-4EDB-8509-7D2660C9EC98) - C: \ Program Files \ Viewpoint \ Viewpoint Toolbar \ ViewBarBHO. DLL
O2 - BHO: (no name) - (A8FB8EB3-183B-4598-924D-86F0E5E37085) - (keine Datei)
O2 - BHO: (no name) - (D70E6A20-7060-4829-B3D7-B6624A1DE7C6) - (keine Datei)
O3 - Toolbar: Viewpoint Toolbar - (F8AD5AA5-D966-4667-9DAF-2561D68B2012) - C: \ Program Files \ Viewpoint \ Viewpoint Toolbar \ ViewBar.dll
O3 - Toolbar: Yahoo! Toolbar - (EF99BD32-C1FB-11D2-892F-0090271D4F88) - C: \ Program Files \ Yahoo! \ Companion \ Installs \ cpn0 \ yt. DLL
O3 - Toolbar: McAfee SiteAdvisor - (0BF43445-2F28-4351-9252-17FE6E806AA0) - C: \ Program Files \ SiteAdvisor \ 6253 \ SiteAdv.dll
O4 - HKLM \ .. \ Run: [SynTPLpr] C: \ Program Files \ Synaptics \ SynTP \ SynTPLpr.exe
O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Program Files \ Synaptics \ SynTP \ SynTPEnh.exe
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Program Files \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: [TkBellExe] "C: \ Programme \ Gemeinsame Dateien \ Real \ Update_OB \ realsched. exe "-osboot
O4 - HKLM \ .. \ Run: [mcagent_exe] C: \ Program Files \ McAfee.com \ Agent \ mcagent.exe / runkey
O4 - HKLM \ .. \ Run: [SiteAdvisor] C: \ Program Files \ SiteAdvisor \ 6172 \ SiteAdv.exe
O4 - HKLM \ .. \ Run: [KernelFaultCheck]% systemroot% \ system32 \ dumprep 0-k
O4 - HKCU \ .. \ Run: [SpybotSD TeaTimer] C: \ Program Files \ Spybot - Search & Destroy \ TeaTimer.exe
O4 -. Default User-Startup: AutoTBar.exe (User Default-Benutzer)
O4 - Startup: Spybot - Search & Destroy. lnk = C: \ Program Files \ Spybot - Search & Destroy \ SpybotSD.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C: \ Program Files \ Adobe \ Acrobat 7,0 \ Reader \ reader_sl.exe
O8 - Extra Kontext Menüpunkt: Optionen & ieSpell --
res://C : \ Program Files \ ieSpell \ iespell.dll / SPELLOPTION.HTM
O8 - Extra Kontext Menüpunkt: & Viewpoint Suche --
res://C : \ Program Files \ Viewpoint \ Viewpoint Toolbar \ ViewBar.dll / CXTSEARCH. HTML
O8 - Extra Kontext Menüpunkt: Check & Spelling --
res://C : \ Program Files \ ieSpell \ iespell.dll / SPELLCHECK.HTM
O8 - Extra Kontext Menüpunkt: "Senden an & Bluetooth - C: \ Program Files \ Widcomm \ Bluetooth Software \ btsendto_ie_ctx.htm
O9 - Extra Knopf: (no name) - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper. DLL
O9 - Extra "Extras" menuitem: Spybot - Search & Destroy Konfiguration - (DFB852A3-47F8-48C4-A200-58CAB36FD2A2) - C: \ PROGRA ~ 1 \ Spybot ~ 1 \ SDHelper.dll
O10 - Unbekannt-Datei in Winsock LSP: c: \ windows \ system32 \ nwprovau.dll
O14 - IERESET.INF: START_PAGE_URL = http://us8l.hpwis.com
O16 - DPF: DigiChat Applet --
http://host16.digichat.com/DigiChat/Dig ... ent_IE.cabO16 - DPF: Yahoo! Chat --
http://us.chat1.yimg.com/us.yimg.com/i/ ... 1/chat.cabO16 - DPF: (9CCE3B43-4DE0-4236-A84E-108CA848EE6A) (WebCam Control) --
http://webcamnow.com/fs5/ax/ActiveXWebCam.cabO23 - Service: Bluetooth Service (btwdins) - Widcomm, Inc. - C: \ Program Files \ Widcomm \ Bluetooth Software \ bin \ btwdins.exe
O23 - Service: HP Configuration Interface Service (HPConfig) - Hewlett-Packard - C: \ WINDOWS \ system32 \ HPConfig.exe
O23 - Service: iPod Service (iPodService) - Apple Computer, Inc. - C: \ Program Files \ iPod \ bin \ iPodService. exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C: \ PROGRA ~ 1 \ McAfee \ MSC \ mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c: \ PROGRA ~ 1 \ COMMON ~ 1 \ McAfee \ MNA \ mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C: \ PROGRA ~ 1 \ McAfee \ VIRUSS ~ 1 \ mcods.exe
O23 - Service: McAfee-Proxy-Service (McProxy) - McAfee, Inc. - c: \ PROGRA ~ 1 \ COMMON ~ 1 \ McAfee \ mcproxy \ mcproxy.exe
O23 - Service: McAfee Echtzeit-Scanner (McShield) - McAfee, Inc. -- C: \ PROGRA ~ 1 \ McAfee \ VIRUSS ~ 1 \ mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C: \ PROGRA ~ 1 \ McAfee \ VIRUSS ~ 1 \ mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C: \ Program Files \ McAfee \ MPF \ MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C: \ Program Files \ McAfee \ MSK \ MskSrver.exe
--
Ende der Datei - 7025 bytes