Logfile of Trend Micro HijackThis v2.0.5
Scan saved at 16:38:20, on 01.10.2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
FIREFOX: 24.0 (de)
Boot mode: Normal
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32spoolsv.exe
C
rogrammeGemeinsame DateienG DATAAVKProxyAVKProxy.exe
C
rogrammeG DATAAntiVirusAVKAVKService.exe
C
rogrammeG DATAAntiVirusAVKAVKWCtl.exe
C:WINDOWSSystem32svchost.exe
C
rogrammeJavajre7binjqs.exe
C
rogrammeGemeinsame DateienMicrosoft SharedVS7DEBUGmdm.exe
C:WINDOWSsystem32ScsiCommandService2.exe
C:WINDOWSsystem32ieconfig_1und1_svc.exe
C:WINDOWSsystem32svchost.exe
C
rogrammeCanonCALCALMAIN.exe
C
rogrammeGemeinsame DateienG DATAGDScanGDScan.exe
C:WINDOWSSOUNDMAN.EXE
C:WINDOWSsystem32VTTimer.exe
C:WINDOWSsystem32VTtrayp.exe
C
rogrammeQuickTimeqttask.exe
C
rogrammeScanSoftOmniPageSE2.0OpwareSE2.exe
C
rogrammeG DATAAntiVirusAVKTrayAVKTray.exe
C:WINDOWSsm56hlpr.exe
C
rogrammeGemeinsame DateienJavaJava Updatejusched.exe
C:WINDOWSsystem32ctfmon.exe
C
rogrammeMessengermsmsgs.exe
C
rogrammeMicrosoft ActiveSyncWcescomm.exe
C
rogrammeWindows Media PlayerWMPNSCFG.exe
C
ROGRA~1MI3AA1~1rapimgr.exe
C:WINDOWSsystem32wbemwmiapsrv.exe
C
rogrammeBVS Solitaire CollectionCARDS.EXE
C
rogrammeMozilla Firefoxfirefox.exe
C
okumente und EinstellungenBarbaraEigene DateienDownloadsHijackThis.exe
R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://home.1und1.de
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page = http://www.google.de/
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLMSoftwareMicrosoftInternet ExplorerSearch,SearchAssistant =
R3 - URLSearchHook: (no name) - {d2f11d8b-3eb5-4b42-9511-370dbec707fb} - (no file)
O2 - BHO: G Data WebFilter Class - {0124123D-61B4-456f-AF86-78C53A0790C5} - C
rogrammeG DATAAntiVirusWebfilterAVKWebIE.dll
O2 - BHO: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O2 - BHO: 1und1 Konfiguration - {17166733-40EA-4432-A85C-AE672FF0E236} - C
okumente und EinstellungenAll UsersAnwendungsdaten1und1InternetExplorerAddonBHOXML.dll
O2 - BHO: Suchspur - {5D945E9A-DC10-4670-83EB-99DAA616628A} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C
rogrammeJavajre7binssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C
rogrammeGoogleGoogle ToolbarGoogleToolbar_32.dll
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C
rogrammeGoogleGoogleToolbarNotifier5.4.4525.1752swg.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C
rogrammeJavajre7binjp2ssv.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C
rogrammeCanonEasy-WebPrintToolband.dll
O3 - Toolbar: G Data WebFilter - {0124123D-61B4-456f-AF86-78C53A0790C5} - C
rogrammeG DATAAntiVirusWebfilterAVKWebIE.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C
rogrammeGoogleGoogle ToolbarGoogleToolbar_32.dll
O3 - Toolbar: QuickStores-Toolbar - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - mscoree.dll (file missing)
O4 - HKLM..Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM..Run: [VTTimer] VTTimer.exe
O4 - HKLM..Run: [VTTrayp] VTtrayp.exe
O4 - HKLM..Run: [NeroFilterCheck] C:WINDOWSsystem32NeroCheck.exe
O4 - HKLM..Run: [QuickTime Task] "C
rogrammeQuickTimeqttask.exe" -atboottime
O4 - HKLM..Run: [OpwareSE2] "C
rogrammeScanSoftOmniPageSE2.0OpwareSE2.exe"
O4 - HKLM..Run: [Easy-PrintToolBox] C
rogrammeCanonEasy-PrintToolBoxBJPSMAIN.EXE /logon
O4 - HKLM..Run: [G DATA AntiVirus Trayapplication] C
rogrammeG DATAAntiVirusAVKTrayAVKTray.exe
O4 - HKLM..Run: [UserFaultCheck] %systemroot%system32dumprep 0 -u
O4 - HKLM..Run: [SMSERIAL] sm56hlpr.exe
O4 - HKLM..Run: [KernelFaultCheck] %systemroot%system32dumprep 0 -k
O4 - HKLM..Run: [Adobe ARM] "C
rogrammeGemeinsame DateienAdobeARM1.0AdobeARM.exe"
O4 - HKLM..Run: [SunJavaUpdateSched] "C
rogrammeGemeinsame DateienJavaJava Updatejusched.exe"
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [MSMSGS] "C
rogrammeMessengermsmsgs.exe" /background
O4 - HKCU..Run: [NBJ] "C
rogrammeAheadNero BackItUpNBJ.exe"
O4 - HKCU..Run: [H/PC Connection Agent] "C
rogrammeMicrosoft ActiveSyncWcescomm.exe"
O4 - HKCU..Run: [WMPNSCFG] C
rogrammeWindows Media PlayerWMPNSCFG.exe
O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'LOKALER DIENST'
O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'NETZWERKDIENST'
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM'
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user'
O8 - Extra context menu item: Bild in &Microsoft PhotoDraw öffnen - res://C
ROGRA~1MICROS~2Office1031phdintl.dll/phdContext.htm
O8 - Extra context menu item: Easy-WebPrint - Drucken - res://C
rogrammeCanonEasy-WebPrintResource.dll/RC_Print.html
O8 - Extra context menu item: Easy-WebPrint - Schnelldruck - res://C
rogrammeCanonEasy-WebPrintResource.dll/RC_HSPrint.html
O8 - Extra context menu item: Easy-WebPrint - Vorschau - res://C
rogrammeCanonEasy-WebPrintResource.dll/RC_Preview.html
O8 - Extra context menu item: Easy-WebPrint - Zu Druckliste hinzufügen - res://C
rogrammeCanonEasy-WebPrintResource.dll/RC_AddToList.html
O8 - Extra context menu item: Google Sidewiki... - res://C
rogrammeGoogleGoogle ToolbarComponentGoogleToolbarDynamic_mui_en_60D6097707281E79.dll/cmsidewiki.html
O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C
ROGRA~1MICROS~2Office12ONBttnIE.dll
O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C
ROGRA~1MICROS~2Office12ONBttnIE.dll
O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C
ROGRA~1MI3AA1~1INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C
ROGRA~1MI3AA1~1INetRepl.dll
O9 - Extra 'Tools' menuitem: Mobilen Favoriten erstellen... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C
ROGRA~1MI3AA1~1INetRepl.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C
ROGRA~1MICROS~2Office12REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
rogrammeMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C
rogrammeMessengermsmsgs.exe
O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://www3.snapfish.de/SnapfishActivia.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1150275963426
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1158254484333
O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:WINDOWSsystem32browseui.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:WINDOWSsystem32browseui.dll
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:WINDOWSsystem32MacromedFlashFlashPlayerUpdateService.exe
O23 - Service: G Data AntiVirus Proxy (AVKProxy) - G Data Software AG - C
rogrammeGemeinsame DateienG DATAAVKProxyAVKProxy.exe
O23 - Service: G Data Scheduler (AVKService) - G Data Software AG - C
rogrammeG DATAAntiVirusAVKAVKService.exe
O23 - Service: G Data Dateisystem Wächter (AVKWCtl) - G Data Software AG - C
rogrammeG DATAAntiVirusAVKAVKWCtl.exe
O23 - Service: Canon Camera Access Library 8 (CCALib
- Canon Inc. - C
rogrammeCanonCALCALMAIN.exe
O23 - Service: G Data Scanner (GDScan) - G Data Software AG - C
rogrammeGemeinsame DateienG DATAGDScanGDScan.exe
O23 - Service: Google Software Updater (gusvc) - Google - C
rogrammeGoogleCommonGoogle UpdaterGoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C
rogrammeGemeinsame DateienInstallShieldDriver1050Intel 32IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C
rogrammeJavajre7binjqs.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C
rogrammeMozilla Maintenance Servicemaintenanceservice.exe
O23 - Service: SCSI command service (ScsiCommandService2) - Mobile Leader Co.,Ltd. - C:WINDOWSsystem32ScsiCommandService2.exe
O23 - Service: IEConfig 1und1/WEB.DE/GMX Edition (serviceIEConfig) - Unknown owner - C:WINDOWSsystem32ieconfig_1und1_svc.exe
--
End of file - 10121 bytes