![]() |
|
Log-Analyse und Auswertung: Virus oder ähnlich auf meinem RechnerWindows 7 Wenn Du Dir einen Trojaner eingefangen hast oder ständig Viren Warnungen bekommst, kannst Du hier die Logs unserer Diagnose Tools zwecks Auswertung durch unsere Experten posten. Um Viren und Trojaner entfernen zu können, muss das infizierte System zuerst untersucht werden: Erste Schritte zur Hilfe. Beachte dass ein infiziertes System nicht vertrauenswürdig ist und bis zur vollständigen Entfernung der Malware nicht verwendet werden sollte.XML. |
![]() | #1 |
![]() | ![]() Virus oder ähnlich auf meinem Rechner Hallo erstmal hoffe einfach mal, dass ihr mir helfen könnt... Hier die Log-File: Logfile of Trend Micro HijackThis v2.0.2 Scan saved at 00:20:33, on 27.09.2008 Platform: Windows XP SP3 (WinNT 5.01.2600) MSIE: Internet Explorer v7.00 (7.00.6000.16705) Boot mode: Normal Running processes: C:\WINDOWS\System32\smss.exe C:\WINDOWS\system32\winlogon.exe C:\WINDOWS\system32\services.exe C:\WINDOWS\system32\lsass.exe C:\WINDOWS\system32\svchost.exe C:\WINDOWS\System32\svchost.exe C:\WINDOWS\system32\spoolsv.exe C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe C:\WINDOWS\Explorer.EXE C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe C:\xampp\apache\bin\apache.exe C:\Programme\Gemeinsame Dateien\Autodesk Shared\Service\AdskScSrv.exe C:\Programme\Bonjour\mDNSResponder.exe C:\Programme\Autodesk\3ds Max 2009\mentalray\satellite\raysat_3dsMax2009_32server.exe C:\Programme\Marvell\61xx\Apache2\bin\Apache.exe c:\xampp\mysql\bin\mysqld-nt.exe C:\Programme\Marvell\61xx\Apache2\bin\Apache.exe C:\Programme\Nero\Nero8\Nero BackItUp\NBService.exe C:\WINDOWS\system32\nvsvc32.exe C:\xampp\apache\bin\apache.exe C:\WINDOWS\system32\PnkBstrA.exe C:\Programme\CyberLink\Shared Files\RichVideo.exe C:\WINDOWS\system32\svchost.exe C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe C:\Programme\Java\jre1.6.0_07\bin\jusched.exe C:\WINDOWS\system32\RUNDLL32.EXE C:\Programme\CyberLink\PowerDVD\PDVDServ.exe C:\WINDOWS\RTHDCPL.EXE C:\Programme\SyncroSoft\Pos\H2O\cledx.exe C:\WINDOWS\system32\ctfmon.exe C:\Programme\DAEMON Tools Lite\daemon.exe C:\Programme\Gemeinsame Dateien\Nero\Lib\NMBgMonitor.exe C:\Programme\Gemeinsame Dateien\Nero\Lib\NMIndexingService.exe C:\Programme\Spybot - Search & Destroy\TeaTimer.exe C:\Programme\Mozilla Firefox\firefox.exe C:\Programme\Trend Micro\HijackThis\HijackThis.exe C:\WINDOWS\system32\NOTEPAD.EXE C:\Programme\Windows Live\Messenger\msnmsgr.exe R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://www2.iesearch.com/ R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = h**p://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = h**p://go.microsoft.com/fwlink/?LinkId=54896 R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = h**p://go.microsoft.com/fwlink/?LinkId=54896 R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = h**p://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Programme\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll O4 - HKLM\..\Run: [NeroFilterCheck] C:\Programme\Gemeinsame Dateien\Nero\Lib\NeroCheck.exe O4 - HKLM\..\Run: [avgnt] "C:\Programme\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime O4 - HKLM\..\Run: [LanguageShortcut] C:\Programme\CyberLink\PowerDVD\Language\Language.exe O4 - HKLM\..\Run: [NBKeyScan] "C:\Programme\Nero\Nero8\Nero BackItUp\NBKeyScan.exe" O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\Java\jre1.6.0_07\bin\jusched.exe" O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit O4 - HKLM\..\Run: [nwiz] nwiz.exe /install O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup O4 - HKLM\..\Run: [RemoteControl] C:\Programme\CyberLink\PowerDVD\PDVDServ.exe O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE O4 - HKLM\..\Run: [H2O] C:\Programme\SyncroSoft\Pos\H2O\cledx.exe O4 - HKLM\..\Run: [Amok Mode Dupe Platform] C:\Dokumente und Einstellungen\All Users\Anwendungsdaten\Hold Trust Amok Mode\up bash.exe O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Programme\DAEMON Tools Lite\daemon.exe" -autorun O4 - HKCU\..\Run: [ICQ] "C:\Programme\ICQ6\ICQ.exe" silent O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Programme\Gemeinsame Dateien\Nero\Lib\NMBgMonitor.exe" O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized O4 - HKCU\..\Run: [Steam] "C:\Programme\Steam\Steam.exe" -silent O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\Windows Live\Messenger\MsnMsgr.Exe" /background O4 - HKCU\..\Run: [ball four] C:\DOKUME~1\***\ANWEND~1\FLAWMU~1\PILE DEFY THIRD.exe O4 - HKCU\..\Run: [SpybotSD TeaTimer] C:\Programme\Spybot - Search & Destroy\TeaTimer.exe O4 - HKCU\..\RunOnce: [SpybotDeletingD6349] cmd /c del "C:\Programme\NetPumper\NPNetPumper_Application.dll" O4 - HKCU\..\RunOnce: [SpybotDeletingB8129] command /c del "C:\Programme\NetPumper\NPNetPumper_Audio.dll" O4 - HKCU\..\RunOnce: [SpybotDeletingD1572] cmd /c del "C:\Programme\NetPumper\NPNetPumper_Audio.dll" O4 - HKCU\..\RunOnce: [SpybotDeletingB7616] command /c del "C:\Programme\NetPumper\NPNetPumper_Video.dll" O4 - HKCU\..\RunOnce: [SpybotDeletingD3052] cmd /c del "C:\Programme\NetPumper\NPNetPumper_Video.dll" O4 - HKCU\..\RunOnce: [SpybotDeletingB4130] command /c del "C:\Programme\NetPumper\shutdown.exe" O4 - HKCU\..\RunOnce: [SpybotDeletingD1589] cmd /c del "C:\Programme\NetPumper\shutdown.exe" O4 - HKCU\..\RunOnce: [SpybotDeletingB5382] command /c del "C:\Programme\NetPumper\TurnLog.exe" O4 - HKCU\..\RunOnce: [SpybotDeletingD8348] cmd /c del "C:\Programme\NetPumper\TurnLog.exe" O4 - HKCU\..\RunOnce: [SpybotDeletingB7312] command /c del "C:\Programme\NetPumper\help\commonheadfoot.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingD4243] cmd /c del "C:\Programme\NetPumper\help\commonheadfoot.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingB6652] command /c del "C:\Programme\NetPumper\help\compat.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingD757] cmd /c del "C:\Programme\NetPumper\help\compat.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingB6011] command /c del "C:\Programme\NetPumper\help\details.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingD1375] cmd /c del "C:\Programme\NetPumper\help\details.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingB1777] command /c del "C:\Programme\NetPumper\help\features.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingD4241] cmd /c del "C:\Programme\NetPumper\help\features.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingB9825] command /c del "C:\Programme\NetPumper\help\index.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingD4049] cmd /c del "C:\Programme\NetPumper\help\index.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingB8966] command /c del "C:\Programme\NetPumper\help\mainwin.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingD8719] cmd /c del "C:\Programme\NetPumper\help\mainwin.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingB1014] command /c del "C:\Programme\NetPumper\help\prefwindow.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingD3223] cmd /c del "C:\Programme\NetPumper\help\prefwindow.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingB1266] command /c del "C:\Programme\NetPumper\help\register.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingD9981] cmd /c del "C:\Programme\NetPumper\help\register.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingB4080] command /c del "C:\Programme\NetPumper\help\schedwin.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingD2255] cmd /c del "C:\Programme\NetPumper\help\schedwin.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingB6557] command /c del "C:\Programme\NetPumper\help\tips.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingD8121] cmd /c del "C:\Programme\NetPumper\help\tips.htm" O4 - HKCU\..\RunOnce: [SpybotDeletingB1721] command /c del "C:\Programme\NetPumper\help\nphelp.css" O4 - HKCU\..\RunOnce: [SpybotDeletingD5313] cmd /c del "C:\Programme\NetPumper\help\nphelp.css" O4 - HKCU\..\RunOnce: [SpybotDeletingB2672] command /c del "C:\Programme\NetPumper\help\images\apllimit.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD1944] cmd /c del "C:\Programme\NetPumper\help\images\apllimit.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB6516] command /c del "C:\Programme\NetPumper\help\images\bandwidthpanel.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD7654] cmd /c del "C:\Programme\NetPumper\help\images\bandwidthpanel.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB6124] command /c del "C:\Programme\NetPumper\help\images\buttons.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD3524] cmd /c del "C:\Programme\NetPumper\help\images\buttons.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB6365] command /c del "C:\Programme\NetPumper\help\images\cmdadd.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD1145] cmd /c del "C:\Programme\NetPumper\help\images\cmdadd.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD1869] cmd /c del "C:\Programme\NetPumper\help\images\cmdaddtoschedule.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB8041] command /c del "C:\Programme\NetPumper\help\images\cmddetails.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD2800] cmd /c del "C:\Programme\NetPumper\help\images\cmddetails.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB5756] command /c del "C:\Programme\NetPumper\help\images\cmdeditschedule.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD1596] cmd /c del "C:\Programme\NetPumper\help\images\cmdeditschedule.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB2738] command /c del "C:\Programme\NetPumper\help\images\cmdfolder.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD106] cmd /c del "C:\Programme\NetPumper\help\images\cmdfolder.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB8527] command /c del "C:\Programme\NetPumper\help\images\cmdhelp.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD3028] cmd /c del "C:\Programme\NetPumper\help\images\cmdhelp.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB9394] command /c del "C:\Programme\NetPumper\help\images\cmdopen.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD5135] cmd /c del "C:\Programme\NetPumper\help\images\cmdopen.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB3002] command /c del "C:\Programme\NetPumper\help\images\cmdopenfolder.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD5472] cmd /c del "C:\Programme\NetPumper\help\images\cmdopenfolder.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB8710] command /c del "C:\Programme\NetPumper\help\images\cmdpause.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD4851] cmd /c del "C:\Programme\NetPumper\help\images\cmdpause.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB6437] command /c del "C:\Programme\NetPumper\help\images\cmdprefs.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD1421] cmd /c del "C:\Programme\NetPumper\help\images\cmdprefs.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB5441] command /c del "C:\Programme\NetPumper\help\images\cmdremove.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD1255] cmd /c del "C:\Programme\NetPumper\help\images\cmdremove.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB7625] command /c del "C:\Programme\NetPumper\help\images\cmdresume.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD6552] cmd /c del "C:\Programme\NetPumper\help\images\cmdresume.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB5113] command /c del "C:\Programme\NetPumper\help\images\cmdselectall.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD7968] cmd /c del "C:\Programme\NetPumper\help\images\cmdselectall.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB8451] command /c del "C:\Programme\NetPumper\help\images\detailwin-wide.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD4384] cmd /c del "C:\Programme\NetPumper\help\images\detailwin-wide.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB2213] command /c del "C:\Programme\NetPumper\help\images\detailwin.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD8852] cmd /c del "C:\Programme\NetPumper\help\images\detailwin.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB8793] command /c del "C:\Programme\NetPumper\help\images\droptoschedule.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD2614] cmd /c del "C:\Programme\NetPumper\help\images\droptoschedule.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB3384] command /c del "C:\Programme\NetPumper\help\images\editbandwidth.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD9965] cmd /c del "C:\Programme\NetPumper\help\images\editbandwidth.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB4640] command /c del "C:\Programme\NetPumper\help\images\ignlimit.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD9381] cmd /c del "C:\Programme\NetPumper\help\images\ignlimit.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB9086] command /c del "C:\Programme\NetPumper\help\images\limserver.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD7072] cmd /c del "C:\Programme\NetPumper\help\images\limserver.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB4247] command /c del "C:\Programme\NetPumper\help\images\limservergold.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD1446] cmd /c del "C:\Programme\NetPumper\help\images\limservergold.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB9185] command /c del "C:\Programme\NetPumper\help\images\limuser.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD9076] cmd /c del "C:\Programme\NetPumper\help\images\limuser.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB7659] command /c del "C:\Programme\NetPumper\help\images\mainwin.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD7431] cmd /c del "C:\Programme\NetPumper\help\images\mainwin.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB9740] command /c del "C:\Programme\NetPumper\help\images\moveicons.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD387] cmd /c del "C:\Programme\NetPumper\help\images\moveicons.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB5661] command /c del "C:\Programme\NetPumper\help\images\prefw-bandwidth.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD793] cmd /c del "C:\Programme\NetPumper\help\images\prefw-bandwidth.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB636] command /c del "C:\Programme\NetPumper\help\images\prefw-connections.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD9768] cmd /c del "C:\Programme\NetPumper\help\images\prefw-connections.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB6169] command /c del "C:\Programme\NetPumper\help\images\prefw-general.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD5764] cmd /c del "C:\Programme\NetPumper\help\images\prefw-general.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB9516] command /c del "C:\Programme\NetPumper\help\images\prefw-login.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD2736] cmd /c del "C:\Programme\NetPumper\help\images\prefw-login.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB6407] command /c del "C:\Programme\NetPumper\help\images\prefw-monitoring.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD3730] cmd /c del "C:\Programme\NetPumper\help\images\prefw-monitoring.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB9861] command /c del "C:\Programme\NetPumper\help\images\prefw-proxy-ftp.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD5277] cmd /c del "C:\Programme\NetPumper\help\images\prefw-proxy-ftp.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB9160] command /c del "C:\Programme\NetPumper\help\images\prefw-proxy-http.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD17] cmd /c del "C:\Programme\NetPumper\help\images\prefw-proxy-http.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB3588] command /c del "C:\Programme\NetPumper\help\images\register-1.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD9904] cmd /c del "C:\Programme\NetPumper\help\images\register-1.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB5646] command /c del "C:\Programme\NetPumper\help\images\register-2.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD6883] cmd /c del "C:\Programme\NetPumper\help\images\register-2.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB9372] command /c del "C:\Programme\NetPumper\help\images\register-3-1.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD2406] cmd /c del "C:\Programme\NetPumper\help\images\register-3-1.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB7942] command /c del "C:\Programme\NetPumper\help\images\register-3-2.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD8629] cmd /c del "C:\Programme\NetPumper\help\images\register-3-2.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB8272] command /c del "C:\Programme\NetPumper\help\images\schedulewin.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD324] cmd /c del "C:\Programme\NetPumper\help\images\schedulewin.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB4163] command /c del "C:\Programme\NetPumper\help\images\scnoresume.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD1367] cmd /c del "C:\Programme\NetPumper\help\images\scnoresume.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB2068] command /c del "C:\Programme\NetPumper\help\images\scresumes.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD1476] cmd /c del "C:\Programme\NetPumper\help\images\scresumes.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB2536] command /c del "C:\Programme\NetPumper\help\images\scunk.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD3189] cmd /c del "C:\Programme\NetPumper\help\images\scunk.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB7249] command /c del "C:\Programme\NetPumper\help\images\stanalyzing.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD3828] cmd /c del "C:\Programme\NetPumper\help\images\stanalyzing.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB4151] command /c del "C:\Programme\NetPumper\help\images\starticon.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD1462] cmd /c del "C:\Programme\NetPumper\help\images\starticon.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB3734] command /c del "C:\Programme\NetPumper\help\images\stcompleted.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD1805] cmd /c del "C:\Programme\NetPumper\help\images\stcompleted.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB2681] command /c del "C:\Programme\NetPumper\help\images\stfatal.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD5936] cmd /c del "C:\Programme\NetPumper\help\images\stfatal.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB3608] command /c del "C:\Programme\NetPumper\help\images\stinpro.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD6176] cmd /c del "C:\Programme\NetPumper\help\images\stinpro.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB8618] command /c del "C:\Programme\NetPumper\help\images\stnhelp-old.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD3089] cmd /c del "C:\Programme\NetPumper\help\images\stnhelp-old.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB2975] command /c del "C:\Programme\NetPumper\help\images\stnhelp.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD4025] cmd /c del "C:\Programme\NetPumper\help\images\stnhelp.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB759] command /c del "C:\Programme\NetPumper\help\images\stopicon.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD9399] cmd /c del "C:\Programme\NetPumper\help\images\stopicon.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB2459] command /c del "C:\Programme\NetPumper\help\images\stpaused.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD3292] cmd /c del "C:\Programme\NetPumper\help\images\stpaused.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB2155] command /c del "C:\Programme\NetPumper\help\images\stqueued.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD6185] cmd /c del "C:\Programme\NetPumper\help\images\stqueued.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB4356] command /c del "C:\Programme\NetPumper\help\images\stretrying.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD4029] cmd /c del "C:\Programme\NetPumper\help\images\stretrying.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB306] command /c del "C:\Programme\NetPumper\help\images\stscheduled.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD7628] cmd /c del "C:\Programme\NetPumper\help\images\stscheduled.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB1488] command /c del "C:\Programme\NetPumper\help\images\summary.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD3287] cmd /c del "C:\Programme\NetPumper\help\images\summary.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB2887] command /c del "C:\Programme\NetPumper\help\images\throtdn.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD7893] cmd /c del "C:\Programme\NetPumper\help\images\throtdn.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingB2506] command /c del "C:\Programme\NetPumper\help\images\zoombtn.gif" O4 - HKCU\..\RunOnce: [SpybotDeletingD4616] cmd /c del "C:\Programme\NetPumper\help\images\zoombtn.gif" O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKALER DIENST') O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETZWERKDIENST') O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM') O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user') O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programme\Java\jre1.6.0_07\bin\ssv.dll O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll O9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Programme\ICQ6\ICQ.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - h**p://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - h**p://messenger.zone.msn.com/DE-DE/a-UNO1/GAME_UNO1.cab O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - h**p://messenger.zone.msn.com/binary/ZIntro.cab56649.cab O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - h**p://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - h**ps://fpdownload.macromedia.com/pub/shockwave/cabs/flash/swflash.cab O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - h**p://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\GEMEIN~1\Skype\SKYPE4~1.DLL O23 - Service: Adobe LM Service - Adobe Systems - C:\Programme\Gemeinsame Dateien\Adobe Systems Shared\Service\Adobelmsvc.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\sched.exe O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Programme\Avira\AntiVir PersonalEdition Classic\avguard.exe O23 - Service: Apache2.2 - Apache Software Foundation - C:\xampp\apache\bin\apache.exe |
Themen zu Virus oder ähnlich auf meinem Rechner |
adobe, antivir, antivirus, avira, bho, bonjour, browser, dll, einstellungen, excel, explorer, firefox, helfen, hijack, hijackthis, hkus\s-1-5-18, internet, internet explorer, log-file, mozilla, object, plug-in, rundll, skype.exe, software, system, virus, windows, windows xp, windows xp sp3, xp sp3 |