Hallo,
ok, feLogfile of HijackThis v1.99.1
Scan saved at 20:28:18, am 18.01.2010
Plattform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Laufende Prozesse:
C: \ WINDOWS \ System32 \ smss.exe
C: \ WINDOWS \ system32 \ winlogon.exe
C: \ WINDOWS \ system32 \ services.exe
C: \ WINDOWS \ system32 \ lsass.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ WINDOWS \ system32 \ Ati2evxx.exe
C: \ WINDOWS \ system32 \ svchost.exe
c: \ Programme \ Hewlett-Packard \ Drive Encryption \ HpFkCrypt.exe
C: \ WINDOWS \ System32 \ svchost.exe
C: \ Programme \ WIDCOMM \ Bluetooth Software \ bin \ btwdins.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ WINDOWS \ system32 \ spoolsv.exe
C: \ Programme \ Avira \ AntiVir Desktop \ Sched.exe
C: \ WINDOWS \ system32 \ Ati2evxx.exe
c: \ Programme \ Hewlett-Packard \ IAM \ Bin \ AsGHost.exe
C: \ WINDOWS \ Explorer.EXE
C: \ WINDOWS \ system32 \ AccelerometerSt.Exe
C: \ Programme \ ActivIdentity \ ActivClient \ accrdsub.exe
C: \ Programme \ Hewlett-Packard \ HP ProtectTools Security Manager \ PTHOSTTR.EXE
C: \ Programme \ Synaptics \ bin \ jusched.exe
C: \ Programme \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe
C: \ Programme \ Hewlett-Packard \ HP Quick Launch Buttons \ QlbCtrl.exe
C: \ Programme \ Analog Devices \ Core \ smax4pnp.exe
C: \ Programme \ iTunes \ iTunesHelper.exe
C: \ Programme \ Gemeinsame Dateien \ ArcSoft \ Connection Service \ Bin \ ACDaemon.exe
C: \ WINDOWS \ vsnpstd3.exe
C: \ Programme \ Avira \ AntiVir Desktop \ avgnt.exe
c: \ Programme \ ActivIdentity \ ActivClient \ acevents.exe
C: \ PROGRA ~ 1 \ Companion 2 \ ONETOU ~ 3.EXE
C: \ Programme \ ScanSoft \ PaperPort \ pptd40nt.exe
C: \ Programme \ Companion Suite IH \ MFServices.exe
C: \ Programme \ Companion Suite IH \ MFPrintServer.exe
C: \ Programme \ Philips \ SA19XX \ Philips Device Manager \ Bin \ DeviceManager.exe
C: \ Programme \ Java \ JRE6 \ bin \ jusched.exe
C: \ WINDOWS \ system32 \ ctfmon.exe
C: \ Programme \ Google \ GoogleToolbarNotifier \ GoogleToolbarNotifier.exe
c: \ Programme \ ActivIdentity \ ActivClient \ accoca.exe
C: \ Programme \ WIDCOMM \ Bluetooth Software \ BTTray.exe
C: \ Programme \ Gemeinsame Dateien \ ArcSoft \ Connection Service \ Bin \ ACService.exe
C: \ WINDOWS \ system32 \ agrsmsvc.exe
C: \ Programme \ Avira \ AntiVir Desktop \ avguard.exe
C: \ Programme \ FinePixViewerS \ QuickDCF2.exe
C: \ Programme \ Windows Desktop Search \ WindowsSearch.exe
c: \ Programme \ Hewlett-Packard \ HP ProtectTools Security Manager \ PTChangeFilterService.exe
C: \ Programme \ Gemeinsame Dateien \ InterVideo \ RegMgr \ iviRegMgr.exe
C: \ Programme \ Java \ JRE6 \ bin \ jqs.exe
C: \ WINDOWS \ system32 \ svchost.exe
C: \ Programme \ Google \ Update \ 1.2.183.13 \ GoogleCrashHandler.exe
C: \ WINDOWS \ system32 \ SearchIndexer.exe
C: \ WINDOWS \ system32 \ fxssvc.exe
C: \ WINDOWS \ system32 \ mqsvc.exe
C: \ WINDOWS \ system32 \ mqtgsvc.exe
C: \ Programme \ Hewlett-Packard \ Shared \ hpqwmiex.exe
C: \ Programme \ Hewlett-Packard \ HP Quick Launch Buttons \ Com4QLBEx.exe
C: \ Programme \ Hewlett-Packard \ Shared \ HpqToaster.exe
C: \ Programme \ SpeedFan \ speedfan.exe
C: \ Programme \ Internet Explorer \ iexplore.exe
C: \ WINDOWS \ system32 \ taskmgr.exe
C: \ Dokumente und Einstellungen \ Administrator \ Lokale Einstellungen \ Temporary Internet Files \ Content.IE5 \ G7YFIW4E \ pruefung [1]. Com
R1 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=83&bd=all&pf=cmnb
R0 - HKCU \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://www.yahoo.de/
R1 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=83&bd=all&pf=cmnb
R0 - HKLM \ Software \ Microsoft \ Internet Explorer \ Main, Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=de_de&c=83&bd=all&pf=cmnb
O2 - BHO: AcroIEHelperStub - (18DF081C-E8AD-4283-A596-FA578C2EBDC3) - C: \ Programme \ Gemeinsame Dateien \ Adobe \ Acrobat \ ActiveX \ AcroIEHelperShim.dll
O2 - BHO: AOL Toolbar BHO - (7C554162-8CB7-45A4-B8F4-8EA1C75885F9) - C: \ Programme \ AOL \ AOL Toolbar 5.0 \ aoltb.dll
O2 - BHO: Google Toolbar Helper - (AA58ED58-01DD-4d91-8333-CF10577473F7) - C: \ Programme \ Google \ Google Toolbar \ GoogleToolbar_32.dll
O2 - BHO: Google Toolbar - (AF69DE43-7D58-4638-B6FA-CE66B5AD205D) - C: \ Programme \ Google \ GoogleToolbarNotifier \ 5.4.4525.1752 \ swg.dll
O2 - BHO: Java (tm) Plug-In 2 SSV Helper - (DBC80044-A445-435B-BC74-9C25C1C588A9) - C: \ Programme \ Java \ JRE6 \ bin \ jp2ssv.dll
O2 - BHO: Credential Manager für HP ProtectTools - (DF21F1DB-80C6-11D3-9483-B03D0EC10000) - C: \ Programme \ Hewlett-Packard \ IAM \ Bin \ ItIEAddIn.dll
O2 - BHO: JQSIEStartDetectorImpl - (E7E6F031-17CE-4C07-BC86-EABFE594F69C) - C: \ Programme \ Java \ JRE6 \ lib \ deploy \ JQS \ dh \ jqs_plugin.dll
O3 - Toolbar: AOL Toolbar - (DE9C389F-3316-41A7-809B-AA305ED9D922) - C: \ Programme \ AOL \ AOL Toolbar 5.0 \ aoltb.dll
O3 - Toolbar: Easy-WebPrint - (327C2873-E90D-4C37-AA9D-10AC9BABA46C) - C: \ Programme \ Canon \ Easy-WebPrint \ Toolband.dll
O3 - Toolbar: Google Toolbar - (2318C2B1-4965-11d4-9B18-009027A5CD4F) - C: \ Programme \ Google \ Google Toolbar \ GoogleToolbar_32.dll
O4 - HKLM \ .. \ Run: [NvMediaCenter] regsvr32 / s mqrt.dll
O4 - HKLM \ .. \ Run: [AccelerometerSysTrayApplet] C: \ WINDOWS \ system32 \ AccelerometerSt.Exe
O4 - HKLM \ .. \ Run: [accrdsub] "c: \ Programme \ ActivIdentity \ ActivClient \ accrdsub.exe"
O4 - HKLM \ .. \ Run: [PTHOSTTR] c: \ Programme \ Hewlett-Packard \ HP ProtectTools Security Manager \ PTHOSTTR.EXE / Start
O4 - HKLM \ .. \ Run: [CognizanceTS] rundll32.exe C: \ PROGRA ~ 1 \ HEWLET ~ 1 \ IAM \ Bin \ ASTSVCC.dll, RegisterModule
O4 - HKLM \ .. \ Run: [SynTPEnh] C: \ Programme \ Synaptics \ bin \ jusched.exe
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] C: \ Programme \ Hewlett-Packard \ HP Wireless Assistant \ HPWAMain.exe
O4 - HKLM \ .. \ Run: [QlbCtrl.exe] C: \ Programme \ Hewlett-Packard \ HP Quick Launch Buttons \ QlbCtrl.exe / Start
O4 - HKLM \ .. \ Run: [HP Software Update] C: \ Programme \ Hewlett-Packard \ Default Settings \ cpqset.exe
O4 - HKLM \ .. \ Run: [DLA] C: \ Programme \ Analog Devices \ Core \ smax4pnp.exe
O4 - HKLM \ .. \ Run: [SoundMAX] C: \ Programme \ Analog Devices \ SoundMAX \ Smax4.exe / tray
O4 - HKLM \ .. \ Run: [QuickTime Task] "C: \ Programme \ QuickTime \ qttask.exe"-atboottime
O4 - HKLM \ .. \ Run: [Adobe Reader Speed Launcher] "C: \ Programme \ Adobe \ Acrobat 9.0 \ Reader \ Reader_sl.exe"
O4 - HKLM \ .. \ Run: [WatchDog] C: \ Programme \ InterVideo \ DVD Check \ DVDCheck.exe
O4 - HKLM \ .. \ Run: [tsnpstd3] C: \ WINDOWS \ tsnpstd3.exe
O4 - HKLM \ .. \ Run: [ArcSoft Connection Service] C: \ Programme \ Gemeinsame Dateien \ ArcSoft \ Connection Service \ Bin \ ACDaemon.exe
O4 - HKLM \ .. \ Run: [snpstd3] C: \ WINDOWS \ vsnpstd3.exe
O4 - HKLM \ .. \ Run: [AVP] "C: \ Programme \ Avira \ AntiVir Desktop \ avgnt.exe" / min
O4 - HKLM \ .. \ Run: [SSBkgdUpdate] "C: \ Programme \ Gemeinsame Dateien \ Scansoft Shared \ bin \ jusched.exe"-Embedding-boot
O4 - HKLM \ .. \ Run: [CTFMON.EXE] C: \ Programme \ ScanSoft \ iTunes \ iTunesHelper.exe
O4 - HKLM \ .. \ Run: [OneTouch Monitor] C: \ PROGRA ~ 1 \ Companion 2 \ ONETOU ~ 3.EXE
O4 - HKLM \ .. \ Run: [PaperPort PTD] C: \ Programme \ ScanSoft \ PaperPort \ pptd40nt.exe
O4 - HKLM \ .. \ Run: [MFServices] "C: \ Programme \ Companion Suite IH \ MFServices.exe"-n
O4 - HKLM \ .. \ Run: [MFPrintServer] "C: \ Programme \ Companion Suite IH \ MFPrintServer.exe"
O4 - HKLM \ .. \ Run: [ARM] "C: \ Programme \ Gemeinsame Dateien \ Adobe \ ARM \ 1.0 \ AdobeARM.exe"
O4 - HKLM \ .. \ Run: [PhilipsDM \ SA1916] C: \ Programme \ Philips \ SA19XX \ Philips Device Manager \ Bin \ DeviceManager.exe OS_STARTUP
O4 - HKLM \ .. \ Run: [SunJavaUpdateSched] "C: \ Programme \ Java \ JRE6 \ bin \ jusched.exe"
O4 - HKCU \ .. \ Run: [CTFMON.EXE] C: \ WINDOWS \ system32 \ ctfmon.exe
O4 - HKCU \ .. \ Run: [ICQ] "C: \ Programme \ Google \ GoogleToolbarNotifier \ GoogleToolbarNotifier.exe"
O4 - HKCU \ .. \ Run: [CTFMON.EXE] C: \ Programme \ TomTom HOME 2 \ TomTomHOMERunner.exe "
O4 - HKCU \ .. \ Run: [Shockwave Updater] C: \ WINDOWS \ system32 \ Adobe \ Shockwave 11 \ SwHelper_1150596.exe-Update -1150596 - "Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.1; SV1; GTB6 ;. NET CLR 1.1.4322;. NET CLR 2.0.50727;. NET CLR 3.0.4506.2152;. NET CLR 3.5.30729) "-" http://www8.agame.com/games/shockwave/h/horse_eventing/ horse_eventing_girlsgogames_de / horse_eventing_girlsgogames_de.html "
O4 - Startup: BTTray.lnk =?
O4 - Startup: DVD Check.lnk = C: \ Programme \ InterVideo \ DVD Check \ DVDCheck.exe
O4 - Startup: Exif Launcher S.lnk =?
O4 - Startup: Windows Search.lnk = C: \ Programme \ Windows Desktop Search \ WindowsSearch.exe
O8 - Extra context menu item: & AOL Toolbar-Suche - C: \ Dokumente und Einstellungen \ All Users \ Anwendungsdaten \ AOL \ IEToolbar \ resources \ de-DE \ local \ search.html
O8 - Extra context menu item: Easy-WebPrint - Drucken - res: / / C: \ Programme \ Canon \ Easy-WebPrint \ Resource.dll / RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - res: / / C: \ Programme \ Canon \ Easy-WebPrint \ Resource.dll / RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint - Vorschau - res: / / C: \ Programme \ Canon \ Easy-WebPrint \ Resource.dll / RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - res: / / C: \ Programme \ Canon \ Easy-WebPrint \ Resource.dll / RC_AddToList.html
O8 - Extra context menu item: Google Sidewiki ... - Res: / / C: \ Programme \ Google \ Google Toolbar \ Component \ GoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O8 - Extra context menu item: Nach Microsoft E & xel exportieren - res: / / C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ EXCEL.EXE/3000
O8 - Extra context menu item: Senden an & Bluetooth-Gerät ... - C: \ Programme \ WIDCOMM \ Bluetooth Software \ btsendto_ie_ctx.htm
O8 - Extra context menu item: Senden an Bluetooth - C: \ Programme \ WIDCOMM \ Bluetooth Software \ btsendto_ie.htm
O9 - Extra button: Research - (92780B25-18CC-41C8-B9BE-3C9C571A8263) - C: \ PROGRA ~ 1 \ MICROS ~ 2 \ Office12 \ REFIEBAR.DLL
O9 - Extra button: @ btrez.dll, -4015 - (CCA281CA-C863-46ef-9331-5C8D4460577F) - C: \ Programme \ WIDCOMM \ Bluetooth Software \ btsendto_ie.htm
O9 - Extra 'Tools' menuitem: @ btrez.dll, -12650 - (CCA281CA-C863-46ef-9331-5C8D4460577F) - C: \ Programme \ WIDCOMM \ Bluetooth Software \ btsendto_ie.htm
O9 - Extra Knopf: (no name) - (e2e2dd38-d088-4134-82b7-f2ba38496583) -% windir% \ Network Diagnostic \ xpnetdiag.exe (file missing)
O9 - Extra 'Tools' menuitem: @ xpsp3res.dll, -20001 - (e2e2dd38-d088-4134-82b7-f2ba38496583) -% windir% \ Network Diagnostic \ xpnetdiag.exe (file missing)
O9 - Extra button: Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Programme \ Messenger \ msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - (FB5F1910-F110-11d2-BB9E-00C04F795683) - C: \ Programme \ Messenger \ msmsgs.exe
O16 - DPF: (E2883E8F-472 f-4FB0-9522-AC9BF37916A7) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O17 - HKLM \ System \ CCS \ Services \ Tcpip \ .. \ (B2FFF1A6-AA76-43D8-98C5-4C20A24FC101): NameServer = 192.168.121.252,192.168.121.253
O18 - Protocol: ms-help - (314111C7-A502-11D2-BBCA-00C04F8EC294) - C: \ Programme \ Gemeinsame Dateien \ Microsoft Shared \ Help \ hxds.dll
O18 - Filter hijack: text / xml - (807563E5-5146-11D5-A672-00B0D022E945) - C: \ PROGRA ~ 1 \ GEMEIN ~ 1 \ MICROS ~ 1 \ OFFICE12 \ Msoxmlmf.dll
O20 - AppInit_DLLs: APSHook.dll
O20 - Winlogon Notify: ackpbsc - C: \ WINDOWS \ system32 \ ackpbsc.dll
O20 - Winlogon Notify: acunlock - c: \ Programme \ ActivIdentity \ ActivClient \ acunlock.dll
O20 - Winlogon Notify: dimsntfy -% SystemRoot% \ System32 \ dimsntfy.dll (file missing)
O20 - Winlogon Notify: OneCard - c: \ Programme \ Hewlett-Packard \ IAM \ Bin \ ASWLNPkg.dll
O20 - Winlogon Notify: WgaLogon - C: \ WINDOWS \ system32 \ WgaLogon.dll
O21 - Service: WPDShServiceObj - (AAA288BA-9A4C-45B0-95D7-94D524869DB5) - C: \ WINDOWS \ system32 \ wpdshserviceobj.dll
O23 - Service: ActivClient Middleware Service (accoca) - ActivIdentity - c: \ Programme \ ActivIdentity \ ActivClient \ accoca.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C: \ Programme \ Gemeinsame Dateien \ ArcSoft \ Connection Service \ Bin \ ACService.exe
O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C: \ WINDOWS \ system32 \ agrsmsvc.exe
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C: \ Programme \ Avira \ AntiVir Desktop \ Sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C: \ Programme \ Avira \ AntiVir Desktop \ avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C: \ WINDOWS \ system32 \ Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C: \ WINDOWS \ system32 \ ati2sgag.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C: \ Programme \ WIDCOMM \ Bluetooth Software \ bin \ btwdins.exe
O23 - Service: Com4QLBEx - Hewlett-Packard Development Company, LP - C: \ Programme \ Hewlett-Packard \ HP Quick Launch Buttons \ Com4QLBEx.exe
O23 - Service: AVM FRITZ! Web Routing Service (de_serv) - AVM Berlin - C: \ Programme \ Gemeinsame Dateien \ AVM \ de_serv.exe
O23 - Service: Google Update Service (gupdate1c9ef2610c0a0a8) (gupdate1c9ef2610c0a0a8) - Unknown owner - C: \ Programme \ Google \ Update \ GoogleUpdate.exe "/ svc (file missing)
O23 - Service: Google Software Updater (gusvc) - Google - C: \ Programme \ Google \ Common \ Google Updater \ GoogleUpdaterService.exe
O23 - Service: HP ProtectTools Service - Hewlett-Packard Development Company, LP - C: \ Programme \ Hewlett-Packard \ HP ProtectTools Security Manager \ PTChangeFilterService.exe
O23 - Service: Drive Encryption Service (HpFkCryptService) - SafeBoot International - c: \ Programme \ Hewlett-Packard \ Drive Encryption \ HpFkCrypt.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, LP - C: \ Programme \ Hewlett-Packard \ Shared \ hpqwmiex.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C: \ Programme \ Gemeinsame Dateien \ InstallShield \ Driver \ 1150 \ Intel 32 \ IDriverT.exe
O23 - Service: IviRegMgr - InterVideo - C: \ Programme \ Gemeinsame Dateien \ InterVideo \ RegMgr \ iviRegMgr.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Unknown owner - C: \ Programme \ Java \ JRE6 \ bin \ jqs.exe "-service-config" C: \ Programme \ Java \ JRE6 \ lib \ deploy \ JQS \ JQS . conf (file missing)
O23 - Service: ServiceLayer - Nokia. - C: \ Programme \ PC Connectivity Solution \ ServiceLayer.exe
O23 - Service: sgbx_device - Sagem - C: \ WINDOWS \ system32 \ sgbxcoms.exe
Fertig zum Operieren!
Hat der Patient Überlebenschancen? Zur Info, es auf dem Laptop weitere 3 Stümper Rum Fröschen!
Danke