Here you go.
ComboFix 09-07-24.01 - User 25.07.2009 15:33.1.2 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.3.1252.49.1031.18.2046.1368 [GMT 2:00]
ausgeführt von:: c:\dokumente und einstellungen\User\Desktop\ComboFix.exe
.
(((((((((((((((((((((((((((((((((((( Weitere Löschungen ))))))))))))))))))))))))))))))))))))))))))))))))
.
c:\recycler\S-1-5-21-4172071277-2194094571-159085178-500
c:\windows\Installer\203d8.msi
c:\windows\Installer\3c5569.msi
c:\windows\regedit.com
c:\windows\system32\taskmgr.com
F:\start.bat
.
((((((((((((((((((((((( Dateien erstellt von 2009-06-25 bis 2009-07-25 ))))))))))))))))))))))))))))))
.
2009-07-25 03:45 . 2009-07-25 03:45 -------- d-----w- c:\dokumente und einstellungen\User\Anwendungsdaten\Malwarebytes
2009-07-25 03:45 . 2009-07-13 11:36 38160 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2009-07-25 03:45 . 2009-07-25 03:45 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Malwarebytes
2009-07-25 03:45 . 2009-07-13 11:36 19096 ----a-w- c:\windows\system32\drivers\mbam.sys
2009-07-24 11:48 . 2009-07-24 11:48 410984 ----a-w- c:\windows\system32\deploytk.dll
2009-07-24 08:53 . 2009-07-24 08:53 -------- d-----w- c:\windows\system32\Macromed
2009-07-24 08:43 . 2009-07-24 08:43 -------- d-----w- c:\windows\system32\XPSViewer
2009-07-24 08:43 . 2009-07-24 08:43 -------- d-----w- c:\programme\MSBuild
2009-07-24 08:43 . 2009-07-24 08:43 -------- d-----w- c:\programme\Reference Assemblies
2009-07-24 08:43 . 2008-07-06 12:06 89088 ------w- c:\windows\system32\dllcache\filterpipelineprintproc.dll
2009-07-24 08:43 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\xpsshhdr.dll
2009-07-24 08:43 . 2008-07-06 12:06 575488 ------w- c:\windows\system32\dllcache\xpsshhdr.dll
2009-07-24 08:43 . 2008-07-06 12:06 117760 ------w- c:\windows\system32\prntvpt.dll
2009-07-24 08:43 . 2008-07-06 10:50 597504 ------w- c:\windows\system32\dllcache\printfilterpipelinesvc.exe
2009-07-24 08:43 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\xpssvcs.dll
2009-07-24 08:43 . 2008-07-06 12:06 1676288 ------w- c:\windows\system32\dllcache\xpssvcs.dll
2009-07-24 08:36 . 2009-07-24 08:36 -------- d-sh--w- c:\dokumente und einstellungen\User\IECompatCache
2009-07-24 08:33 . 2009-07-24 08:33 -------- d-sh--w- c:\dokumente und einstellungen\User\PrivacIE
2009-07-24 06:55 . 2009-07-24 06:55 -------- d---a-w- c:\windows\system32\runouce.exe
.
(((((((((((((((((((((((((((((((((((( Find3M Bericht ))))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2009-07-25 12:26 . 2008-06-01 22:08 -------- d-----w- c:\programme\Gemeinsame Dateien\Adobe
2009-07-24 21:46 . 2008-07-05 21:19 -------- d-----w- c:\dokumente und einstellungen\User\Anwendungsdaten\.purple
2009-07-24 13:46 . 2009-03-13 15:25 1 ----a-w- c:\dokumente und einstellungen\User\Anwendungsdaten\OpenOffice.org\3\user\uno_packages\cache\stamp.sys
2009-07-24 09:33 . 2006-01-27 01:01 84722 ----a-w- c:\windows\system32\perfc007.dat
2009-07-24 09:33 . 2006-01-27 01:01 459396 ----a-w- c:\windows\system32\perfh007.dat
2009-07-24 09:18 . 2008-05-04 02:50 73336 ----a-w- c:\dokumente und einstellungen\User\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT
2009-07-24 09:15 . 2007-11-28 05:47 73336 ----a-w- c:\dokumente und einstellungen\Administrator\Lokale Einstellungen\Anwendungsdaten\GDIPFONTCACHEV1.DAT
2009-07-24 08:30 . 2008-06-09 05:38 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Spybot - Search & Destroy
2009-07-23 23:21 . 2009-03-22 18:09 -------- d-----w- c:\dokumente und einstellungen\All Users\Anwendungsdaten\Aspell
2009-07-08 20:57 . 2008-06-06 10:34 -------- d-----w- c:\dokumente und einstellungen\User\Anwendungsdaten\FileZilla
2009-06-30 15:34 . 2008-07-05 21:21 -------- d-----w- c:\dokumente und einstellungen\User\Anwendungsdaten\gtk-2.0
2009-06-28 12:57 . 2008-09-07 21:00 -------- d-----w- c:\dokumente und einstellungen\User\Anwendungsdaten\dvdcss
2009-06-16 14:36 . 2006-01-27 01:01 119808 ----a-w- c:\windows\system32\t2embed.dll
2009-06-16 14:36 . 2006-01-27 01:01 81920 ----a-w- c:\windows\system32\fontsub.dll
2009-06-03 19:09 . 2006-01-27 01:01 1296896 ----a-w- c:\windows\system32\quartz.dll
2009-05-13 05:02 . 2006-01-27 01:01 915456 ----a-w- c:\windows\system32\wininet.dll
2009-05-09 16:03 . 2009-05-09 16:03 721904 ----a-w- c:\windows\system32\drivers\sptd.sys
2009-05-07 15:32 . 2006-01-27 01:01 348160 ----a-w- c:\windows\system32\localspl.dll
.
(((((((((((((((((((((((((((( Autostartpunkte der Registrierung ))))))))))))))))))))))))))))))))))))))))
.
.
*Hinweis* leere Einträge & legitime Standardeinträge werden nicht angezeigt.
REGEDIT4
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="c:\windows\system32\ctfmon.exe" [2008-04-14 15360]
"WMPNSCFG"="c:\programme\Windows Media Player\WMPNSCFG.exe" [2006-11-03 204288]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"PWRMGRTR"="c:\progra~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL" [2006-05-25 151552]
"BLOG"="c:\progra~1\ThinkPad\UTILIT~1\BatLogEx.DLL" [2006-05-25 208896]
"SynTPLpr"="c:\programme\Synaptics\SynTP\SynTPLpr.exe" [2007-08-10 110592]
"SynTPEnh"="c:\programme\Synaptics\SynTP\SynTPEnh.exe" [2007-08-10 512000]
"TPHOTKEY"="c:\progra~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe" [2006-07-25 94208]
"SoundMAXPnP"="c:\programme\Analog Devices\Core\smax4pnp.exe" [2005-05-20 925696]
"SunJavaUpdateSched"="c:\programme\own\Programmierung\Java\jre6\bin\jusched.exe" [2009-07-24 148888]
"TpShocks"="TpShocks.exe" - c:\windows\system32\TpShocks.exe [2006-03-15 106496]
"TP4EX"="tp4ex.exe" - c:\windows\system32\TP4EX.exe [2005-10-17 65536]
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="c:\windows\system32\CTFMON.EXE" [2008-04-14 15360]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]
"NoSMHelp"= 01000000
"NoSMMyDocs"= 00000000
"NoSMMyPictures"= 00000000
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\psfus]
2006-04-25 18:20 40448 ----a-w- c:\windows\system32\psqlpwd.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tpfnf2]
2005-07-05 14:45 28672 ----a-w- c:\windows\system32\notifyf2.dll
[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\winlogon\notify\tphotkey]
2005-11-30 11:16 24576 ----a-w- c:\windows\system32\tphklock.dll
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Notification Packages REG_MULTI_SZ scecli psqlpwd
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Wdf01000.sys]
@="Driver"
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"tvtnetwk"=2 (0x2)
"TVT Scheduler"=2 (0x2)
"TVT Backup Service"=2 (0x2)
"ThinkVantage Registry Monitor Service"=2 (0x2)
"TapiSrv"=3 (0x3)
"PsaSrv"=3 (0x3)
"IBMPMSVC"=2 (0x2)
"btwdins"=2 (0x2)
"Ati HotKey Poller"=2 (0x2)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusOverride"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"c:\\WINDOWS\\system32\\sessmgr.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"f:\\apache2\\bin\\httpd.exe"=
"c:\\Programme\\own\\Internet\\Pidgin\\pidgin.exe"=
"c:\\Programme\\own\\Tools\\MusicBrainz Picard\\picard.exe"=
"c:\\Programme\\own\\Programmierung\\Eclipse\\eclipse.exe"=
R0 Shockprf;Shockprf;c:\windows\system32\drivers\shockprf.sys [28.11.2007 07:03 88576]
R1 ShockMgr;ShockMgr;c:\windows\system32\drivers\ShockMgr.sys [28.11.2007 07:03 4736]
R1 TPPWRIF;TPPWRIF;c:\windows\system32\drivers\TPPWRIF.SYS [28.11.2007 07:02 4442]
R2 smihlp;SMI helper driver;c:\programme\ThinkVantage Fingerprint Software\smihlp.sys [25.04.2006 20:00 3456]
S3 Apache2.2;Apache2.2;f:\apache2\bin\httpd.exe [13.06.2008 04:05 24635]
S3 VtcDrv;Philips SA60xx Recovery Device;c:\windows\system32\drivers\vtcdrv.sys [15.03.2009 22:38 18560]
[HKEY_LOCAL_MACHINE\software\microsoft\active setup\installed components\>{60B49E34-C7CC-11D0-8953-00A0C90347FF}]
"c:\windows\system32\rundll32.exe" "c:\windows\system32\iedkcs32.dll",BrandIEActiveSetup SIGNUP
.
- - - - Entfernte verwaiste Registrierungseinträge - - - -
Notify-NavLogon - (no file)
.
------- Zusätzlicher Suchlauf -------
.
uStart Page = hxxp://lenovo.live.com
IE: Senden an &Bluetooth-Gerät... - c:\programme\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
FF - ProfilePath - c:\dokumente und einstellungen\User\Anwendungsdaten\Mozilla\Firefox\Profiles\rthkfn9x.default\
FF - plugin: c:\programme\own\Multimedia\VLC\npvlc.dll
FF - plugin: c:\programme\own\Programmierung\Java\jre6\bin\new_plugin\npdeploytk.dll
FF - plugin: c:\programme\own\Programmierung\Java\jre6\bin\new_plugin\npjp2.dll
---- FIREFOX Richtlinien ----
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("media.enforce_same_site_origin", false);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("media.cache_size", 51200);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("media.ogg.enabled", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("media.wave.enabled", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("media.autoplay.enabled", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("browser.urlbar.autocomplete.enabled", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("capability.policy.mailnews.*.wholeText", "noAccess");
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("dom.storage.default_quota", 5120);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("content.sink.event_probe_rate", 3);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("network.http.prompt-temp-redirect", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("layout.css.dpi", -1);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("layout.css.devPixelsPerPx", -1);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("gestures.enable_single_finger_input", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("dom.max_chrome_script_run_time", 0);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("network.tcp.sendbuffer", 131072);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\all.js - pref("geo.enabled", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\greprefs\security-prefs.js - pref("security.remember_cert_checkbox_default_setting", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr", "moz35");
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox-branding.js - pref("browser.search.param.yahoo-fr-cjkt", "moz35");
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("extensions.blocklist.level", 2);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("browser.urlbar.restrict.typed", "~");
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("browser.urlbar.default.behavior", 0);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.history", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.formdata", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.passwords", false);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.downloads", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cookies", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.cache", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.sessions", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.offlineApps", false);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.clearOnShutdown.siteSettings", false);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.cpd.history", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.cpd.formdata", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.cpd.passwords", false);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.cpd.downloads", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.cpd.cookies", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.cpd.cache", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.cpd.sessions", true);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.cpd.offlineApps", false);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.cpd.siteSettings", false);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("privacy.sanitize.migrateFx3Prefs", false);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("browser.ssl_override_behavior", 2);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("security.alternate_certificate_error_page", "certerror");
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("browser.privatebrowsing.autostart", false);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("browser.privatebrowsing.dont_prompt_on_enter", false);
c:\programme\own\Internet\Mozilla Firefox 3 Beta 5\defaults\pref\firefox.js - pref("geo.wifi.uri", "https://www.google.com/loc/json");
.
**************************************************************************
catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer,
http://www.gmer.net
Rootkit scan 2009-07-25 15:35
Windows 5.1.2600 Service Pack 3 NTFS
Scanne versteckte Prozesse...
Scanne versteckte Autostarteinträge...
Scanne versteckte Dateien...
Scan erfolgreich abgeschlossen
versteckte Dateien: 0
**************************************************************************
[HKEY_LOCAL_MACHINE\System\ControlSet001\Services\MySQL]
"ImagePath"="\"f:\mysql\bin\mysqld-nt\" --defaults-file=\"f:\mysql\my.ini\" MySQL"
.
--------------------- Gesperrte Registrierungsschluessel ---------------------
[HKEY_LOCAL_MACHINE\software\DeterministicNetworks\DNE\Parameters]
"SymbolicLinkValue"=hex(6):5c,00,52,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,4d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,79,00,73,00,\
.
--------------------- Durch laufende Prozesse gestartete DLLs ---------------------
- - - - - - - > 'winlogon.exe'(1008)
c:\windows\system32\vrlogon.dll
c:\windows\system32\Ati2evxx.dll
c:\windows\system32\psqlpwd.dll
c:\programme\ThinkVantage Fingerprint Software\infra.dll
c:\programme\ThinkVantage Fingerprint Software\homefus2.dll
c:\windows\system32\biologon.dll
c:\programme\ThinkVantage Fingerprint Software\homepass.dll
c:\programme\ThinkVantage Fingerprint Software\bio.dll
c:\programme\ThinkVantage Fingerprint Software\remote.dll
c:\windows\system32\tphklock.dll
c:\programme\ThinkVantage Fingerprint Software\crypto.dll
- - - - - - - > 'lsass.exe'(1064)
c:\windows\system32\psqlpwd.dll
c:\programme\ThinkVantage Fingerprint Software\infra.dll
c:\programme\ThinkVantage Fingerprint Software\homefus2.dll
.
Zeit der Fertigstellung: 2009-07-25 15:36
ComboFix-quarantined-files.txt 2009-07-25 13:36
Vor Suchlauf: 4.905.988.096 Bytes frei
Nach Suchlauf: 5.076.312.064 Bytes frei
WindowsXP-KB310994-SP2-Pro-BootDisk-DEU.exe
[boot loader]
timeout=2
default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS
[operating systems]
c:\cmdcons\BOOTSECT.DAT="Microsoft Windows Recovery Console" /cmdcons
multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect
229 --- E O F --- 2009-07-25 01:00
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 15:42:25, on 25.07.2009
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\Programme\Intel\Wireless\Bin\EvtEng.exe
C:\Programme\Intel\Wireless\Bin\S24EvMon.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programme\own\Internet\VPN Client\cvpnd.exe
C:\WINDOWS\System32\svchost.exe
C:\Programme\own\Programmierung\Java\jre6\bin\jqs.exe
C:\Programme\Intel\Wireless\Bin\RegSrvc.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\TPHDEXLG.EXE
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\Programme\Synaptics\SynTP\SynTPLpr.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\WINDOWS\system32\TpShocks.exe
C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
C:\Programme\Analog Devices\Core\smax4pnp.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programme\Windows Media Player\WMPNSCFG.exe
C:\Programme\Lenovo\PkgMgr\HOTKEY\TPONSCR.exe
C:\Programme\Lenovo\PkgMgr\HOTKEY_1\TpScrex.exe
C:\WINDOWS\system32\notepad.exe
C:\WINDOWS\explorer.exe
C:\Programme\own\Internet\Mozilla Firefox 3 Beta 5\firefox.exe
C:\Programme\own\Sicherheit\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
http://lenovo.live.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programme\own\Programmierung\Java\jre6\bin\jp2ssv.dll
O2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Programme\own\Programmierung\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dll
O4 - HKLM\..\Run: [PWRMGRTR] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\PWRMGRTR.DLL,PwrMgrBkGndMonitor
O4 - HKLM\..\Run: [BLOG] rundll32 C:\PROGRA~1\ThinkPad\UTILIT~1\BatLogEx.DLL,StartBattLog
O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TpShocks] TpShocks.exe
O4 - HKLM\..\Run: [TPHOTKEY] C:\PROGRA~1\Lenovo\PkgMgr\HOTKEY\TPHKMGR.exe
O4 - HKLM\..\Run: [TP4EX] tp4ex.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Programme\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programme\own\Programmierung\Java\jre6\bin\jusched.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Programme\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O8 - Extra context menu item: Senden an &Bluetooth-Gerät... - C:\Programme\ThinkPad\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\msmsgs.exe
O23 - Service: Apache2.2 - Apache Software Foundation - F:\apache2\bin\httpd.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Programme\own\Internet\VPN Client\cvpnd.exe
O23 - Service: Intel(R) PROSet/Wireless Event Log (EvtEng) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\EvtEng.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Programme\Gemeinsame Dateien\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Programme\own\Programmierung\Java\jre6\bin\jqs.exe
O23 - Service: MySQL - Unknown owner - F:\MySQL\bin\mysqld-nt (file missing)
O23 - Service: Intel(R) PROSet/Wireless Registry Service (RegSrvc) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\RegSrvc.exe
O23 - Service: Intel(R) PROSet/Wireless Service (S24EventMonitor) - Intel Corporation - C:\Programme\Intel\Wireless\Bin\S24EvMon.exe
O23 - Service: ServiceLayer - Nokia. - C:\Programme\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: ThinkPad HDD APS Logging Service (TPHDEXLGSVC) - Lenovo. - C:\WINDOWS\System32\TPHDEXLG.EXE
--
End of file - 5085 bytes