Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 09:54:01, on 21.03.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:ProgrammeWindows DefenderMsMpEng.exe
C:WINDOWSsystem32svchost.exe
C:ProgrammeGemeinsame DateienSymantec SharedccSvcHst.exe
C:WINDOWSsystem32spoolsv.exe
C:WINDOWSSYSTEM32astsrv.exe
C:ProgrammeSymantecLiveUpdateAluSchedulerSvc.exe
C:ProgrammeComodoCOMODO Internet Securitycmdagent.exe
C:WINDOWSsystem32NMSAccessU.exe
C:PROGRA~1GEMEIN~1SYMANT~1CCPD-LCsymlcsvc.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSExplorer.EXE
C:ProgrammeWindows DefenderMSASCui.exe
C:ProgrammeTuneUp Utilities 2008MemOptimizer.exe
C:ProgrammeGemeinsame DateienSymantec SharedccSvcHst.exe
C:ProgrammeComodoCOMODO Internet Securitycfp.exe
C:ProgrammeExpress ClickYesClickYes.exe
C:ProgrammeTwoDirsTwoDirs.exe
C:WINDOWSsystem32ctfmon.exe
G:VPC ImageSWTest SWHijackThis.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = about:blank
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = Xhttp://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = Xhttp://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = Xhttp://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = Xhttp://go.microsoft.com/fwlink/?LinkId=69157 R1 - HKCUSoftwareMicrosoftInternet Connection Wizard,ShellNext = Xhttp://www.philipp-winterberg.de/software/rarzilla_free_unrar.php
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Window Title = Microsoft Internet Explorer
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:ProgrammeGemeinsame DateienSymantec SharedcoSharedBrowser2.0coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:PROGRA~1GEMEIN~1SYMANT~1IDSIPSBHO.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:ProgrammeJavajre1.6.0_07inssv.dll
O3 - Toolbar: Norton-Symbolleiste anzeigen - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:ProgrammeGemeinsame DateienSymantec SharedcoSharedBrowser2.0CoIEPlg.dll
O4 - HKLM..Run: [Windows Defender] "C:ProgrammeWindows DefenderMSASCui.exe" -hide
O4 - HKLM..Run: [TuneUp MemOptimizer] "C:ProgrammeTuneUp Utilities 2008MemOptimizer.exe" autostart
O4 - HKLM..Run: [ccApp] "C:ProgrammeGemeinsame DateienSymantec SharedccApp.exe"
O4 - HKLM..Run: [osCheck] "C:ProgrammeNorton Internet SecurityosCheck.exe"
O4 - HKLM..Run: [COMODO Internet Security] "C:ProgrammeComodoCOMODO Internet Securitycfp.exe" -h
O4 - HKCU..Run: [Express ClickYes] "C:ProgrammeExpress ClickYesClickYes.exe"
O4 - HKCU..Run: [TwoDirs] "C:ProgrammeTwoDirsTwoDirs.exe"
O4 - HKCU..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe
O4 - HKUSS-1-5-19..Run: [InfoCockpit] C:ProgrammeT-OnlineT-Online_Software_6Info-CockpitIC_START.EXE /nosplash (User 'LOKALER DIENST')
O4 - HKUSS-1-5-20..Run: [InfoCockpit] C:ProgrammeT-OnlineT-Online_Software_6Info-CockpitIC_START.EXE /nosplash (User 'NETZWERKDIENST')
O4 - HKUSS-1-5-21-842925246-1450960922-725345543-1004..Run: [ctfmon.exe] C:WINDOWSsystem32ctfmon.exe (User 'Josef Jaser')
O4 - HKUSS-1-5-21-842925246-1450960922-725345543-1004..Run: [TwoDirs] C:ProgrammeTwoDirsTwoDirs.exe (User 'Josef Jaser')
O6 - HKCUSoftwarePoliciesMicrosoftInternet ExplorerControl Panel present
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C:PROGRA~1MICROS~2Office10EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgrammeJavajre1.6.0_07inssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Konsole - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:ProgrammeJavajre1.6.0_07inssv.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammeMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:ProgrammeMessengermsmsgs.exe
O10 - Unknown file in Winsock LSP: c:windowssystem32
wprovau.dll [= MS?]
O20 - AppInit_DLLs: C:WINDOWSsystem32guard32.dl [= Comodo?]
O23 - Service: AST Service (astcc) - Advanced Software Technologies - C:WINDOWSSYSTEM32astsrv.exe
O23 - Service: Automatisches LiveUpdate - Scheduler (Automatic LiveUpdate Scheduler) - Symantec Corporation - C:ProgrammeSymantecLiveUpdateAluSchedulerSvc.exe
O23 - Service: Symantec Event Manager (ccEvtMgr) - Symantec Corporation - C:ProgrammeGemeinsame DateienSymantec SharedccSvcHst.exe
O23 - Service: Symantec Settings Manager (ccSetMgr) - Symantec Corporation - C:ProgrammeGemeinsame DateienSymantec SharedccSvcHst.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Symantec Corporation - C:ProgrammeGemeinsame DateienSymantec SharedccSvcHst.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - Unknown owner - C:ProgrammeComodoCOMODO Internet Securitycmdagent.exe
O23 - Service: COM Host (comHost) - Symantec Corporation - C:ProgrammeGemeinsame DateienSymantec SharedVAScannercomHost.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:ProgrammeGemeinsame DateienInstallShieldDriver11Intel 32IDriverT.exe
O23 - Service: LiveUpdate - Symantec Corporation - C:ProgrammeSymantecLiveUpdateLuComServer_3_4.EXE
O23 - Service: LiveUpdate Notice - Symantec Corporation - C:ProgrammeGemeinsame DateienSymantec SharedccSvcHst.exe
O23 - Service: NMSAccessU - Unknown owner - C:WINDOWSsystem32NMSAccessU.exe [Numedia Soft, Inc.]
O23 - Service: Symantec Core LC - Unknown owner - C:PROGRA~1GEMEIN~1SYMANT~1CCPD-LCsymlcsvc.exe
O23 - Service: DSL-Manager (TDslMgrService) - T-Systems Enterprise Services GmbH - C:ProgrammeDSL-ManagerDslMgrSvc.exe
O23 - Service: TuneUp Drive Defrag-Dienst (TuneUp.Defrag) - TuneUp Software GmbH - C:WINDOWSSystem32TuneUpDefragService.exe





















































