Hallo erstmal^^ ich hab ein problem mit meinem pc und zwar :
Svhost.exe 100% system auslastung
explorer.exe 108.000k speicherverbrauch
unentlich lange zum hochfahren
ich kann mein system nicht neu aufsetzen, da ich ein acer laptop habe und mir keine betriebssysteme mitgeliefert wurden.
ich poste auch, damit niemand mehr fragen muss, meinen hijack file :
Zitat:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 01:58:42, on 03.07.2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16640)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Gemeinsame Dateien\Symantec
Shared\ccSvcHst.exe
C:\Programme\Gemeinsame Dateien\Symantec
Shared\AppCore\AppSvc32.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\Avira\AntiVir PersonalEdition
Classic\sched.exe
C:\Programme\Intel\Intel Matrix Storage
Manager\Iaanotif.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\RTHDCPL.EXE
C:\Programme\Avira\AntiVir PersonalEdition
Classic\avguard.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\ccApp.exe
C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe
C:\Programme\Intel\Intel Matrix Storage
Manager\Iaantmon.exe
C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe
C:\WINDOWS\system32\igfxtray.exe
C:\WINDOWS\system32\hkcmd.exe
C:\WINDOWS\system32\igfxpers.exe
C:\WINDOWS\system32\igfxsrvc.exe
C:\Programme\Microsoft SQL Server\MSSQL.1
\MSSQL\Binn\sqlservr.exe
C:\Acer\Empowering Technology\eDataSecurity\eDSloader.exe
C:\Acer\Empowering Technology\eRecovery\eRAgent.exe
C:\PROGRA~1\LAUNCH~1\LManager.exe
C:\Programme\Java\jre1.6.0_05\bin\jusched.exe
C:\DOKUME~1\*USERNAME*\LOKALE~1\Temp\RtkBtMnt.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\OneStepSearch\onestep.exe
C:\Programme\OneStepSearch\onestep.exe
C:\Programme\Raxco\PerfectDisk\PDAgent.exe
C:\WINDOWS\system32\PnkBstrA.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\igfxext.exe
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
C:\WINDOWS\System32\alg.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\WINDOWS\system32\wbem\unsecapp.exe
C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-
LC\symlcsvc.exe
C:\WINDOWS\system32\mdm.exe
C:\Programme\Avira\AntiVir PersonalEdition
Classic\avgnt.exe
C:\Programme\Internet Explorer\iexplore.exe
C:\Programme\Windows Live\Messenger\msnmsgr.exe
C:\Programme\MessengerDiscovery\MessengerDiscovery Live.exe
C:\Programme\Teamspeak2_RC2\TeamSpeak.exe
C:\Programme\Trend Micro\HijackThis\HijackThis.exe
C:\WINDOWS\system32\wbem\wmiprvse.exe
C:\Programme\Mozilla Firefox\firefox.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = ht*tp://internetsearchservice.com
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = ht*tp://internetsearchservice.com
R1 - HKCU\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = ht*tp://internetsearchservice.com
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start
Page = ht*tp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Page_URL = ht*tp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet
Explorer\Main,Default_Search_URL = ht*tp://internetsearchservice.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Bar = ht*tp://internetsearchservice.com/ie6.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search
Page = ht*tp://internetsearchservice.com
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start
Page = ht*tp://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet
Explorer\Search,SearchAssistant = ht*tp://internetsearchservice.com
R3 - URLSearchHook: Yahoo! Toolbar mit Pop-Up-Blocker -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51
-7695ECA05670} - C:\Programme\Yahoo!
\Companion\Installs\cpn\yt.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-
4D59-B87D-784B7D6BE0B3} - C:\Programme\Gemeinsame
Dateien\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {1E8A6170-7264-4D0F-BEAE-
D42A53123C75} - C:\Programme\Gemeinsame Dateien\Symantec
Shared\coShared\Browser\1.0\NppBho.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-
2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-
D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-
BA8D5E23E045} - (no file)
O3 - Toolbar: Norton-Symbolleiste anzeigen - {90222687-
F593-4738-B738-FBEE9C7B26DF} - C:\Programme\Gemeinsame
Dateien\Symantec Shared\coShared\Browser\1.0\UIBHO.dll
O3 - Toolbar: Yahoo! Toolbar mit Pop-Up-Blocker -
{EF99BD32-C1FB-11D2-892F-0090271D4F88} -
C:\Programme\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Acer eDataSecurity Management - {5CBE3B7C-
1E47-477e-A7DD-396DB0476E29} - C:\WINDOWS\system32
\eDStoolbar.dll
O4 - HKLM\..\Run: [preload] C:\Windows\RUNXMLPL.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Programme\Intel\Intel
Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [SynTPEnh]
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [AzMixerSel]
C:\Programme\Realtek\InstallShield\AzMixerSel.exe
O4 - HKLM\..\Run: [ccApp] "C:\Programme\Gemeinsame
Dateien\Symantec Shared\ccApp.exe"
O4 - HKLM\..\Run: [osCheck] "C:\Programme\Norton Internet
Security\osCheck.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1
\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32
\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32
\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [RemoteControl] "C:\Program
Files\CyberLink\PowerDVD\PDVDServ.exe"
O4 - HKLM\..\Run: [LanguageShortcut] "C:\Program
Files\CyberLink\PowerDVD\Language\Language.exe"
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32
\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32
\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32
\igfxpers.exe
O4 - HKLM\..\Run: [Acer ePresentation HPD]
C:\Acer\Empowering
Technology\ePresentation\ePresentation.exe
O4 - HKLM\..\Run: [ePower_DMC] C:\Acer\Empowering
Technology\ePower\ePower_DMC.exe
O4 - HKLM\..\Run: [Boot] C:\Acer\Empowering
Technology\ePower\Boot.exe
O4 - HKLM\..\Run: [eDataSecurity Loader] C:\Acer\Empowering
Technology\eDataSecurity\eDSloader.exe 0
O4 - HKLM\..\Run: [eRecoveryService] C:\Acer\Empowering
Technology\eRecovery\eRAgent.exe
O4 - HKLM\..\Run: [LManager] C:\PROGRA~1\LAUNCH~1
\LManager.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched]
"C:\Programme\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [Symantec PIF AlertEng]
"C:\Programme\Gemeinsame Dateien\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}
\PIFSvc.exe" /a /m "C:\Programme\Gemeinsame
Dateien\Symantec Shared\PIF\{B8E1DD85-8582-4c61-B58F-
2F227FCA9A08}\AlertEng.dll"
O4 - HKLM\..\Run: [snpstd] C:\WINDOWS\vsnpstd.exe
O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir
PersonalEdition Classic\avgnt.exe" /min
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32
\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE]
C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Global Startup: Acer Empowering Technology.lnk = ?
O4 - Global Startup: Adobe Gamma Loader.lnk =
C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe
Gamma Loader.exe
O8 - Extra context menu item: Nach Microsoft E&xel
exportieren - res://C:\PROGRA~1\MICROS~2\Office12
\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-
00401C608501} - C:\Programme\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-
4FCB-11CF-AAA5-00401C608501} -
C:\Programme\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra button: Mojicon Dispenser - {3B3628FF-E084-47ef
-8797-FA36FC2571EA} -
C:\Programme\Mojicon\Mojicon\mojiwin.exe
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-
3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-
58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy
Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} -
C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-
FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-
A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-
00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910
-F110-11d2-BB9E-00C04F795683} -
C:\Programme\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C}
(WUWebControl Class) - http://ht*tp://www.update.microsoft..../v6/V5Controls
/en/x86/client/wuweb_site.cab?1209328732358
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3}
(MUWebControl Class) - http://ht*tp://www.update.microsoft....te/v6/V5Contro
ls/en/x86/client/muweb_site.cab?1211176136140
O17 - HKLM\System\CCS\Services\Tcpip\..\{CD4D6A29-701C-
4B56-A50F-89F8DF41C70A}: NameServer = 85.255.115.84
85.255.112.175
O22 - SharedTaskScheduler: delayingly - {e89fa8e9-5c0b-
45f6-a70e-f7b177bcd193} - (no file)
O23 - Service: Avira AntiVir Personal – Free Antivirus
Planer (AntiVirScheduler) - Avira GmbH -
C:\Programme\Avira\AntiVir PersonalEdition
Classic\sched.exe
O23 - Service: Avira AntiVir Personal – Free Antivirus
Guard (AntiVirService) - Avira GmbH -
C:\Programme\Avira\AntiVir PersonalEdition
Classic\avguard.exe
O23 - Service: Automatisches LiveUpdate - Scheduler -
Symantec Corporation -
C:\Programme\Symantec\LiveUpdate\ALUSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec
Corporation - C:\Programme\Gemeinsame Dateien\Symantec
Shared\ccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) -
Symantec Corporation - C:\Programme\Gemeinsame
Dateien\Symantec Shared\ccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service
(CLTNetCnService) - Symantec Corporation -
C:\Programme\Gemeinsame Dateien\Symantec
Shared\ccSvcHst.exe
O23 - Service: COM Host (comHost) - Symantec Corporation -
C:\Programme\Gemeinsame Dateien\Symantec
Shared\VAScanner\comHost.exe
O23 - Service: eLock Service (eLockService) - -
C:\Acer\Empowering Technology\eLock\Service\eLockServ.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor
(IAANTMON) - Intel Corporation - C:\Programme\Intel\Intel
Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) -
Macrovision Corporation - C:\Programme\Gemeinsame
Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Symantec IS Kennwortprüfung (ISPwdSvc) -
Symantec Corporation - C:\Programme\Norton Internet
Security\isPwdSvc.exe
O23 - Service: LightScribeService Direct Disc Labeling
Service (LightScribeService) - Hewlett-Packard Company -
C:\Programme\Gemeinsame Dateien\LightScribe\LSSrvc.exe
O23 - Service: LiveUpdate - Symantec Corporation -
C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXE
O23 - Service: LiveUpdate Notice Service Ex (LiveUpdate
Notice Ex) - Symantec Corporation - C:\Programme\Gemeinsame
Dateien\Symantec Shared\ccSvcHst.exe
O23 - Service: LiveUpdate Notice Service - Symantec
Corporation - C:\Programme\Gemeinsame Dateien\Symantec
Shared\PIF\{B8E1DD85-8582-4c61-B58F-2F227FCA9A08}
\PIFSvc.exe
O23 - Service: OneStep Search Service - OneStepSearch.net,
Inc. - C:\Programme\OneStepSearch\onestep.exe
O23 - Service: PDAgent - Raxco Software, Inc. -
C:\Programme\Raxco\PerfectDisk\PDAgent.exe
O23 - Service: PDEngine - Raxco Software, Inc. -
C:\Programme\Raxco\PerfectDisk\PDEngine.exe
O23 - Service: PnkBstrA - Unknown owner -
C:\WINDOWS\system32\PnkBstrA.exe
O23 - Service: Cyberlink RichVideo Service(CRVS)
(RichVideo) - Unknown owner - C:\Programme\CyberLink\Shared
Files\RichVideo.exe (file missing)
O23 - Service: PC Tools Auxiliary Service (sdAuxService) -
PC Tools - C:\Programme\Spyware Doctor\pctsAuxs.exe
O23 - Service: PC Tools Security Service (sdCoreService) -
PC Tools - C:\Programme\Spyware Doctor\pctsSvc.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programme\PC
Connectivity Solution\ServiceLayer.exe
O23 - Service: Symantec Core LC - Unknown owner -
C:\Programme\Gemeinsame Dateien\Symantec Shared\CCPD-
LC\symlcsvc.exe
O23 - Service: Symantec AppCore Service (SymAppCore) -
Symantec Corporation - C:\Programme\Gemeinsame
Dateien\Symantec Shared\AppCore\AppSvc32.exe
O23 - Service: TuneUp Drive Defrag-Dienst (TuneUp.Defrag) -
TuneUp Software GmbH - C:\WINDOWS\System32
\TuneUpDefragService.exe
--
End of file - 13170 bytes
|
danke schonmal ^^