Tony [Gast] schrieb am 20.April.2010, 17:09:43 in der Kategorie pc.security
Könnt ihr kurz nach sehn ob alles in ordnung ist? thx ^^
R1 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://www3.iamwired.net/
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,SearchAssistant =
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Search,CustomizeSearch =
R0 - HKLM\\Software\\Microsoft\\Internet Explorer\\Main,Local Page = C:\\Windows\\SysWOW64\\blank.htm
R0 - HKCU\\Software\\Microsoft\\Internet Explorer\\Toolbar,LinksFolderName =
R3 - URLSearchHook: SweetIM ToolbarURLSearchHook Class - {EEE6C35D-6118-11DC-9C72-001320C79847} - C:\\Program Files (x86)\\SweetIM\\Toolbars\\Internet Explorer\\mgHelper.dll
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\\PROGRA~2\\Yahoo!\\Companion\\Installs\\cpn\\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\\Program Files (x86)\\Common Files\\Adobe\\Acrobat\\ActiveX\\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\\Program Files (x86)\\AVG\\AVG9\\avgssie.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\\Program Files (x86)\\Common Files\\Microsoft Shared\\Windows Live\\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\\Program Files (x86)\\Java\\jre6\\bin\\jp2ssv.dll
O2 - BHO: installnetworkonline - {e180e12b-75fb-f3f7-73ab-ff158f765d90} - C:\\Windows\\SysWow64\\c-GK-QuB_i35dM-.dll
O2 - BHO: SWEETIE - {EEE6C35C-6118-11DC-9C72-001320C79847} - C:\\Program Files (x86)\\SweetIM\\Toolbars\\Internet Explorer\\mgToolbarIE.dll
O2 - BHO: SMTTB2009 - {FCBCCB87-9224-4B8D-B117-F56D924BEB18} - C:\\Program Files (x86)\\HypreCam Toolbar\\tbcore3.dll
O2 - BHO: SingleInstance Class - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\\PROGRA~2\\Yahoo!\\Companion\\Installs\\cpn\\YTSingleInstance.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\\PROGRA~2\\Yahoo!\\Companion\\Installs\\cpn\\yt.dll
O3 - Toolbar: SweetIM Toolbar for Internet Explorer - {EEE6C35B-6118-11DC-9C72-001320C79847} - C:\\Program Files (x86)\\SweetIM\\Toolbars\\Internet Explorer\\mgToolbarIE.dll
O3 - Toolbar: HypreCam Toolbar - {338B4DFE-2E2C-4338-9E41-E176D497299E} - C:\\Program Files (x86)\\HypreCam Toolbar\\tbcore3.dll
O4 - HKLM\\..\\Run: [Adobe Reader Speed Launcher] \"C:\\Program Files (x86)\\Adobe\\Reader 9.0\\Reader\\Reader_sl.exe\"
O4 - HKLM\\..\\Run: [BDRegion] \"C:\\Program Files (x86)\\Cyberlink\\Shared Files\\brs.exe\"
O4 - HKLM\\..\\Run: [RemoteControl] \"C:\\Program Files (x86)\\CyberLink\\PowerDVD\\PDVDServ.exe\"
O4 - HKLM\\..\\Run: [LanguageShortcut] \"C:\\Program Files (x86)\\CyberLink\\PowerDVD\\Language\\Language.exe\"
O4 - HKLM\\..\\Run: [Google EULA Launcher] c:\\Program Files\\Google\\Google EULA\\GoogleEULALauncher.exe IE PA
O4 - HKLM\\..\\Run: [LogitechQuickCamRibbon] \"C:\\Program Files\\Logitech\\Logitech WebCam Software\\LWS.exe\" /hide
O4 - HKLM\\..\\Run: [AVG9_TRAY] C:\\PROGRA~2\\AVG\\AVG9\\avgtray.exe
O4 - HKLM\\..\\Run: [SunJavaUpdateSched] \"C:\\Program Files (x86)\\Common Files\\Java\\Java Update\\jusched.exe\"
O4 - HKLM\\..\\Run: [SweetIM] C:\\Program Files (x86)\\SweetIM\\Messenger\\SweetIM.exe
O4 - HKCU\\..\\Run: [Sidebar] C:\\Program Files\\Windows Sidebar\\sidebar.exe /autoRun
O4 - HKCU\\..\\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter
O4 - HKCU\\..\\Run: [Picasa Media Detector] C:\\Program Files (x86)\\Picasa2\\PicasaMediaDetector.exe
O4 - HKCU\\..\\Run: [Logitech Vid] \"C:\\Program Files (x86)\\Logitech\\Logitech Vid\\vid.exe\" -bootmode
O4 - HKCU\\..\\Run: [Skype] \"C:\\Program Files (x86)\\Skype\\Phone\\Skype.exe\" /nosplash /minimized
O4 - HKCU\\..\\Run: [Messenger (Yahoo!)] ~\"C:\\PROGRA~2\\Yahoo!\\Messenger\\YahooMessenger.exe\" -quiet
O4 - HKCU\\..\\Run: [LosAlamos] rundll32.exe C:\\Windows\\system32\\sshnas.dll,AddAtomAW
O4 - HKCU\\..\\Run: [J8RPLTROBQ] C:\\Users\\NGUYEN~1\\AppData\\Local\\Temp\\c.exe
O4 - HKCU\\..\\Run: [LEO0WTUNO7] C:\\Users\\Nguyen Duc Toan\\AppData\\Local\\Temp\\b.exe
O4 - HKCU\\..\\Run: [test] C:\\Users\\Nguyen Duc Toan\\Downloads\\Bettler.exe
O4 - HKCU\\..\\Run: [TOY5KNQ8OC] C:\\Users\\Nguyen Duc Toan\\AppData\\Local\\Temp\\Tbl.exe
O4 - HKCU\\..\\Run: [Canaveral] rundll32.exe C:\\Users\\NGUYEN~1\\AppData\\Local\\Temp\\sshnas21.dll,BackupReadW
O4 - HKCU\\..\\Run: [QZAIB7KITK] C:\\Users\\NGUYEN~1\\AppData\\Local\\Temp\\Tbk.exe
O4 - HKCU\\..\\Run: [YVIBBBHA8C] C:\\Users\\NGUYEN~1\\AppData\\Local\\Temp\\Tbl.exe
O4 - HKCU\\..\\Run: [WMPNSCFG] C:\\Program Files (x86)\\Windows Media Player\\WMPNSCFG.exe
O4 - HKUS\\S-1-5-19\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /detectMem (User \'LOKALER DIENST\')
O4 - HKUS\\S-1-5-19\\..\\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User \'LOKALER DIENST\')
O4 - HKUS\\S-1-5-20\\..\\Run: [Sidebar] %ProgramFiles%\\Windows Sidebar\\Sidebar.exe /detectMem (User \'NETZWERKDIENST\')
O4 - HKUS\\S-1-5-18\\..\\Run: [Picasa Media Detector] C:\\Program Files (x86)\\Picasa2\\PicasaMediaDetector.exe (User \'SYSTEM\')
O4 - HKUS\\.DEFAULT\\..\\Run: [Picasa Media Detector] C:\\Program Files (x86)\\Picasa2\\PicasaMediaDetector.exe (User \'Default user\')
O4 - Startup: CurseClientStartup.ccip
O13 - Gopher Prefix:
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\\Program Files (x86)\\AVG\\AVG9\\avgpp.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\\PROGRA~2\\COMMON~1\\Skype\\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\\system32\\Alg.exe,-112 (ALG) - Unknown owner - C:\\Windows\\System32\\alg.exe (file missing)
O23 - Service: ASP.NET-Zustandsdienst (aspnet_state) - Unknown owner - C:\\Windows\\Microsoft.NET\\Framework\\v2.0.50727\\aspnet_state.exe (file missing)
O23 - Service: AVG Free E-mail Scanner (avg9emc) - AVG Technologies CZ, s.r.o. - C:\\Program Files (x86)\\AVG\\AVG9\\avgemc.exe
O23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\\Program Files (x86)\\AVG\\AVG9\\avgwdsvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\\Windows\\system32\\DFSR.exe (file missing)
O23 - Service: FABS - Helping agent for MAGIX media database (Fabs) - MAGIX AG - C:\\Program Files (x86)\\Common Files\\MAGIX Services\\Database\\bin\\FABS.exe
O23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\\Program Files (x86)\\Common Files\\MAGIX Services\\Database\\bin\\fbserver.exe
O23 - Service: Google Update Service (gupdate1ca7b5479152a60) (gupdate1ca7b5479152a60) - Google Inc. - C:\\Program Files (x86)\\Google\\Update\\GoogleUpdate.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\\Program Files (x86)\\Google\\Common\\Google Updater\\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\\Program Files (x86)\\Common Files\\InstallShield\\Driver\\11\\Intel 32\\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)
O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\\Program Files\\Common Files\\LogiShrd\\LVMVFM\\LVPrcSrv.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\\Windows\\System32\\msdtc.exe (file missing)
O23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\\Program Files (x86)\\Common Files\\Nero\\Nero BackItUp 4\\NBService.exe
O23 - Service: @%SystemRoot%\\System32\\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\\Windows\\system32\\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\\Windows\\system32\\PnkBstrA.exe
O23 - Service: @%systemroot%\\system32\\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)
O23 - Service: @%systemroot%\\system32\\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\\Windows\\system32\\locator.exe (file missing)
O23 - Service: @%SystemRoot%\\system32\\samsrv.dll,-1 (SamSs) - Unknown owner - C:\\Windows\\system32\\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\\system32\\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\\Windows\\system32\\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\\system32\\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\\Windows\\System32\\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\\system32\\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\\Windows\\System32\\spoolsv.exe (file missing)
O23 - Service: Fujitsu Diagnostic Testhandler (TestHandler) - Fujitsu Technology Solutions - C:\\Program Files (x86)\\Fujitsu\\SystemDiagnostics\\OnlineDiagnostic\\TestManager\\TestHandler.exe
O23 - Service: @%SystemRoot%\\system32\\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\\Windows\\system32\\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\\system32\\vds.exe,-100 (vds) - Unknown owner - C:\\Windows\\System32\\vds.exe (file missing)
O23 - Service: @%systemroot%\\system32\\vssvc.exe,-102 (VSS) - Unknown owner - C:\\Windows\\system32\\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\\system32\\wbem\\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\\Windows\\system32\\wbem\\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\\Windows Media Player\\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\\Program Files (x86)\\Windows Media Player\\wmpnetwk.exe (file missing)
O23 - Service: Yahoo! Updater (YahooAUService) - Yahoo! Inc. - C:\\Program Files (x86)\\Yahoo!\\SoftwareUpdate\\YahooAUService.exe
--
End of file - 11128 bytes