Fehlermeldung"You have a secruity problem"

  • geschlossen

  • bomber09
  • 1679 Aufrufe 22 Antworten

Diese Seite verwendet Cookies. Durch die Nutzung unserer Seite erklären Sie sich damit einverstanden, dass wir Cookies setzen. Weitere Informationen

  • Fehlermeldung"You have a secruity problem"

    Icg habe seit gestern Abend dieses Problem !

    Unten rechts in der Leiste gibt es jetzt ein neues Symbol was fast so aussieht wie das von Windows!! und es kommen alls paar sec "You have a Secruity Problem"

    Bitte um Hilfe bomber09
    [COLOR="Blue"]Meine UP´s Kinder Hörspiele[/color]

    Dieser Beitrag wurde bereits 1 mal editiert, zuletzt von bomber09 ()

  • hihi,
    ...mehr infos wären nicht schlecht!!was für proggis. im spez. kommen bei dir zum einsatz ??

    es handelt sich um ne meldung vom sicherheitscenter,irgendwas stimmt nicht mit deinem virenscanner,nehme ich mal stark an.




    lizens abgelaufen,?
    key blacklisted,?
    firewall checken.?usw. alles eben was mit der sicherheit zu tun hat!!

    geh mal ins menue vom virenscanner und check deine einstellungen,meistens bekommst du hier auch schon die antwort durch ein pop fenster selbst.

    greets jo :D
    .... wenn du abends in den himmel schaust,dann denke an ihn....

    User helfen Usern: die FSB-Tutoren!(Zum Chat) mit den Tutoren
    Haltet euch an den Ehrencodex hier im Board
  • Problem - Fehlermeldung => "You have a secruity problem"

    Hört sich ganz nach Spyware an. Lass mal Spybot - Search and Destroy (ist kostenlos) drüberlaufen !


    Gruss

    Wolf_57 - ;)
  • Wolf_57 schrieb:

    Hört sich ganz nach Spyware an. Lass mal Spybot - Search and Destroy (ist kostenlos) drüberlaufen !




    ...und auch mit hyjackthis nen logfile erstellen und auf der webseite überprüfen lassen,junge hast dir irgendwas eingefangen.

    da handelt es sich um einen veränderten regestryeintrag der geändert werden muss!!

    zudem mal die autostarteintäge kontrollieren!!

    ....und dann würd ich mal deinen virenscanner schärfer einstellen ,oder nen anderen besorgen der was taugt ,-sonst wäre es ja nicht erst soweit gekommen.

    greets jo :D
    .... wenn du abends in den himmel schaust,dann denke an ihn....

    User helfen Usern: die FSB-Tutoren!(Zum Chat) mit den Tutoren
    Haltet euch an den Ehrencodex hier im Board
  • eindeutig was eingefangen.... ich hoffe, du bist schlau genug, die angebotene SW (sie müssen unbedingt dies & das installieren) abzulehnen :D

    ===> verschoben zu den Kollegen der Krankenabteilung, nach Viren, Würmer & Trojaner



    gute Besserung, NeHe
    Da, wo die Neurosen blüh'n, da möcht' ich Landschaftsgärtner sein!
    Rechteübersicht * Forenregeln * F.A.Q. * Lexikon
    Suchfunktion * Chat * User helfen User
    Der Minister nimmt flüsternd den Bischof beim Arm: »Halt' du sie dumm, ich halt' sie arm!« (R. Mey)
  • 1.) Poste ein (neues) Hijackthis Logfile
    HijackThis Logfileauswertung

    2.) Deaktiviere die Systemwiederherstellung, im Verlauf der Infektion wurden auch Malwaredateien in Wiederherstellungspunkten mitgesichert - die sind alle nun unbrauchbar, da ein Zurücksetzen des System durch einen Wiederherstellungspunkt das System wahrscheinlich wieder infizieren würde.

    3.) Führe dieses MBR-Tool aus und poste die Ausgabe.Hier ist es Downzuloaden.
    rootkit in master boot record

    4.) Blacklight und Malwarebytes Antimalware ausführen und Logfiles posten
    F-Secure Blacklight > Rootkit Elimination Technology
    Malwarebytes.org

    5.) Führe Silentrunners nach dieser Anleitung aus und poste das Logfile
    Silentrunner


    Oder mach einfach Format C : ;)


    Wer sich solche Sachen auf dem PC einfängt,sollte sich wirklich mal Gedanken über seine Sicherheitstools machen.
    Der PC ist irgendwo ungenügend geschützt.Sonst würden solche Malware Programme sich nicht auf dem PC einnisten können.
    Also nach einer Neuinstallation des Systems,dieses richtig absichern.

    Virenscanner,Firewall,Popup Blocker,Adware Scanner,sind Pflicht in der Heutigen Zeit.
    Wer ohne Schutz ins Internet geht,ist selber Schuld.

    Greetz
    [COLOR="Blue"][SIZE="3"]Das Problem ist nicht der Computer,das Problem sitzt davor.[/SIZE][/color]

    Dieser Beitrag wurde bereits 1 mal editiert, zuletzt von Firecat ()

  • Sorry forget it.
    Ein komprimittiertes System kriegst Du nicht mehr sauber.

    1) Avira Free ist mE Müll
    2) Sollten Deine Daten nicht gesichtert sein, kannst von einer RettungsCD booten und versuchen die Daten extern zu sichern
    3)Dann wird neu aufgesetzt (incl. Neupartitionierung zuvor), voll geupdatet und ein ordentlicher Virenscann installiert
    4)Dann werden die zuvor gesicherten Daten mit dem Virenscan vollständig geprüft und gereinigt
    5)Was bei 4 übrig bleibt kannst Du zurück auf Dein System kopieren

    mfg
    Miraculix
  • HijackThis

    PHP-Quellcode

    1. Logfile of Trend Micro HijackThis v2.0.2
    2. Scan saved at 20:34:41, on 13.12.2008
    3. Platform: Windows Vista (WinNT 6.00.1904)
    4. MSIE: Internet Explorer v7.00 (7.00.6000.16386)
    5. Boot mode: Normal
    6. Running processes:
    7. C:\Windows\system32\taskeng.exe
    8. C:\Windows\system32\Dwm.exe
    9. C:\Windows\Explorer.EXE
    10. C:\Program Files\Windows Defender\MSASCui.exe
    11. C:\hp\support\hpsysdrv.exe
    12. C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe
    13. C:\WINDOWS\RtHDVCpl.exe
    14. C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
    15. C:\Program Files\Java\jre6\bin\jusched.exe
    16. C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
    17. C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
    18. C:\Program Files\Winamp\winampa.exe
    19. C:\WINDOWS\System32\rundll32.exe
    20. C:\WINDOWS\PixArt\PAC207\Monitor.exe
    21. C:\WINDOWS\System32\svhost.exe
    22. C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
    23. C:\Program Files\Windows Sidebar\sidebar.exe
    24. C:\Program Files\Valve\Steam\Steam.exe
    25. C:\Program Files\Skype\Phone\Skype.exe
    26. C:\Windows\System32\mobsync.exe
    27. C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe
    28. C:\Program Files\Nokia\Nokia PC Suite 7\PcSync2.exe
    29. C:\Program Files\ICQ6.5\ICQ.exe
    30. C:\Users\marcel\AppData\Local\Temp\yyy1542.exe
    31. C:\Program Files\Windows Sidebar\sidebar.exe
    32. C:\Program Files\Mozilla Firefox\firefox.exe
    33. C:\Program Files\Common Files\Nokia\MPAPI\MPAPI3s.exe
    34. C:\Program Files\Skype\Plugin Manager\skypePM.exe
    35. C:\Windows\system32\wuauclt.exe
    36. C:\Windows\system32\SearchFilterHost.exe
    37. C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
    38. R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    39. R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.conduit.com?SearchSource=10&ctid=CT1700389
    40. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=73&bd=Pavilion&pf=desktop
    41. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
    42. R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
    43. R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=DE_DE&c=73&bd=Pavilion&pf=desktop
    44. R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
    45. R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
    46. R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
    47. R3 - URLSearchHook: (no name) - - (no file)
    48. R3 - URLSearchHook: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    49. R3 - URLSearchHook: IsoBuster Toolbar - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - C:\Program Files\IsoBuster\tbIsoB.dll
    50. O1 - Hosts: ::1 localhost
    51. O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    52. O2 - BHO: Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
    53. O2 - BHO: IsoBuster Toolbar - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - C:\Program Files\IsoBuster\tbIsoB.dll
    54. O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL
    55. O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
    56. O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll
    57. O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
    58. O2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\PROGRA~1\FlashFXP\IEFlash.dll
    59. O3 - Toolbar: Yahoo! Toolbar mit Pop-Up-Blocker - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll
    60. O3 - Toolbar: IsoBuster Toolbar - {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6} - C:\Program Files\IsoBuster\tbIsoB.dll
    61. O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
    62. O4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exe
    63. O4 - HKLM\..\Run: [OsdMaestro] "C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"
    64. O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
    65. O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
    66. O4 - HKLM\..\Run: [WinSys2] C:\Windows\system32\startup.exe
    67. O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
    68. O4 - HKLM\..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
    69. O4 - HKLM\..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
    70. O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"
    71. O4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systray
    72. O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
    73. O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
    74. O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
    75. O4 - HKLM\..\Run: [Monitor] C:\Windows\PixArt\PAC207\Monitor.exe
    76. O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
    77. O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
    78. O4 - HKLM\..\Run: [svhost] C:\WINDOWS\system32\svhost.exe
    79. O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
    80. O4 - HKLM\..\RunOnce: [Launcher] %WINDIR%\SMINST\launcher.exe
    81. O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
    82. O4 - HKCU\..\Run: [{11BF71CA-F5C0-AE98-09CB-11AAFA56CE30}] C:\Users\marcel\AppData\Roaming:winupd.exe
    83. O4 - HKCU\..\Run: [winupd.exe] C:\Users\marcel\AppData\Roaming:winupd.exe
    84. O4 - HKCU\..\Run: [Steam] "c:\program files\valve\steam\steam.exe" -silent
    85. O4 - HKCU\..\Run: [Tunebite] C:\Program Files\RapidSolution\Tunebite\Tunebite.exe -tray
    86. O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
    87. O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_SA19B.tmp" /EF "HKCU"
    88. O4 - HKCU\..\Run: [{B1F199CC-C2D4-6D78-F49D-69FD404D74E2}] C:\Users\marcel\AppData\Roaming\svchost.exe
    89. O4 - HKCU\..\Run: [PC Suite Tray] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray
    90. O4 - HKCU\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog
    91. O4 - HKCU\..\Run: [ICQ] "C:\Program Files\ICQ6.5\ICQ.exe" silent
    92. O4 - HKCU\..\Run: [Cognac] C:\Users\marcel\AppData\Local\Temp\~tmpb.exe
    93. O4 - HKCU\..\Run: [MSFox] C:\Users\marcel\AppData\Local\Temp\yyy1542.exe
    94. O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKALER DIENST')
    95. O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKALER DIENST')
    96. O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETZWERKDIENST')
    97. O8 - Extra context menu item: Nach Microsoft E&xel exportieren - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
    98. O9 - Extra button: An OneNote senden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    99. O9 - Extra 'Tools' menuitem: An OneNote s&enden - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll
    100. O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
    101. O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
    102. O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exe
    103. O13 - Gopher Prefix:
    104. O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files\Yahoo!\Common\yinsthelper.dll
    105. O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~3\Office12\GR99D3~1.DLL
    106. O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
    107. O23 - Service: Avira AntiVir Personal - Free Antivirus Planer (AntiVirScheduler) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
    108. O23 - Service: Avira AntiVir Personal - Free Antivirus Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
    109. O23 - Service: BlueSoleil Hid Service - Unknown owner - C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe
    110. O23 - Service: CyberGhost VPN Client (CGVPNCliSrvc) - mobile concepts GmbH - C:\Program Files\S.A.D\CyberGhost VPN\CGVPNCliService.exe
    111. O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
    112. O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
    113. O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exe
    114. O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe
    115. O23 - Service: RoxMediaDB9 - Sonic Solutions - c:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxMediaDB9.exe
    116. O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
    117. O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
    118. O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files\Common Files\SureThing Shared\stllssvr.exe
    119. O23 - Service: @%SystemRoot%\System32\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software GmbH - C:\Windows\System32\TuneUpDefragService.exe
    120. O23 - Service: @%SystemRoot%\System32\TUProgSt.exe,-1 (TuneUp.ProgramStatisticsSvc) - TuneUp Software GmbH - C:\Windows\System32\TUProgSt.exe
    121. --
    122. End of file - 10301 bytes
    Alles anzeigen

    Mbr

    PHP-Quellcode

    1. Stealth MBR rootkit detector 0.2.4 by Gmer, http://www.gmer.net
    2. device: opened successfully
    3. user: error reading MBR
    4. kernel: error reading MBR


    Blacklight

    PHP-Quellcode

    1. Keine Funde


    Malware

    PHP-Quellcode

    1. Bin dabei


    Silentrunner

    Quellcode

    1. "Silent Runners.vbs", revision 59, http://www.silentrunners.org/
    2. Operating System: Windows Vista
    3. Output limited to non-default values, except where indicated by "{++}"
    4. Startup items buried in registry:
    5. ---------------------------------
    6. HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
    7. "Sidebar" = "C:\Program Files\Windows Sidebar\sidebar.exe /autoRun" [MS]
    8. "{11BF71CA-F5C0-AE98-09CB-11AAFA56CE30}" = "C:\Users\marcel\AppData\Roaming:winupd.exe" [** WMI GetObject error **]
    9. "winupd.exe" = "C:\Users\marcel\AppData\Roaming:winupd.exe" [** WMI GetObject error **]
    10. "Steam" = ""c:\program files\valve\steam\steam.exe" -silent" ['Valve Corporation']
    11. "Tunebite" = "C:\Program Files\RapidSolution\Tunebite\Tunebite.exe -tray" [file not found]
    12. "Skype" = ""C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized" ['Skype Technologies S.A.']
    13. "EPSON Stylus DX4400 Series" = "C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "C:\Windows\TEMP\E_SA19B.tmp" /EF "HKCU"" ['SEIKO EPSON CORPORATION']
    14. "{B1F199CC-C2D4-6D78-F49D-69FD404D74E2}" = "C:\Users\marcel\AppData\Roaming\svchost.exe" [file not found]
    15. "PC Suite Tray" = ""C:\Program Files\Nokia\Nokia PC Suite 7\PCSuite.exe" -onlytray" ['Nokia']
    16. "Nokia.PCSync" = ""C:\Program Files\Nokia\Nokia PC Suite 7\PCSync2.exe" /NoDialog" ['Time Information Services Ltd.']
    17. "ICQ" = ""C:\Program Files\ICQ6.5\ICQ.exe" silent" ['ICQ, Inc.']
    18. "Cognac" = "C:\Users\marcel\AppData\Local\Temp\~tmpb.exe" [null data]
    19. "MSFox" = "C:\Users\marcel\AppData\Local\Temp\yyy1542.exe" [null data]
    20. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
    21. "Windows Defender" = "C:\Program Files\Windows Defender\MSASCui.exe -hide"
    22. "hpsysdrv" = "c:\hp\support\hpsysdrv.exe" ['Hewlett-Packard Company']
    23. "OsdMaestro" = ""C:\Program Files\Hewlett-Packard\On-Screen OSD Indicator\OSD.exe"" ['OsdMaestro']
    24. "RtHDVCpl" = "RtHDVCpl.exe" ['Realtek Semiconductor']
    25. "(Default)" = "(empty string)" [file not found]
    26. "avgnt" = ""C:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min" ['Avira GmbH']
    27. "WinSys2" = "C:\Windows\system32\startup.exe" [null data]
    28. "SunJavaUpdateSched" = ""C:\Program Files\Java\jre6\bin\jusched.exe"" ['Sun Microsystems, Inc.']
    29. "ProfilerU" = "C:\Program Files\Saitek\SD6\Software\ProfilerU.exe" ['Saitek']
    30. "SaiMfd" = "C:\Program Files\Saitek\SD6\Software\SaiMfd.exe" ['Saitek']
    31. "WinampAgent" = ""C:\Program Files\Winamp\winampa.exe"" [null data]
    32. "NapsterShell" = "C:\Program Files\Napster\napster.exe /systray" [file not found]
    33. "NvSvc" = "RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart" [MS]
    34. "NvCplDaemon" = "RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup" [MS]
    35. "NvMediaCenter" = "RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit" [MS]
    36. "Monitor" = "C:\Windows\PixArt\PAC207\Monitor.exe" ['PixArt Imaging Incorporation']
    37. "QuickTime Task" = ""C:\Program Files\QuickTime\QTTask.exe" -atboottime" ['Apple Inc.']
    38. "Adobe Reader Speed Launcher" = ""C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"" ['Adobe Systems Incorporated']
    39. "svhost" = "C:\WINDOWS\system32\svhost.exe" [null data]
    40. "GrooveMonitor" = ""C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"" [MS]
    41. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce\ {++}
    42. "Launcher" = "C:\Windows\SMINST\launcher.exe"
    43. HKLM\SOFTWARE\Microsoft\Active Setup\Installed Components\
    44. >{26923b43-4d38-484f-9b9e-de460746276c}\(Default) = "Internet Explorer"
    45. \StubPath = "C:\Windows\system32\ie4uinit.exe -UserIconConfig" [MS]
    46. {44BBA840-CC51-11CF-AAFA-00AA00B6015C}\(Default) = "Microsoft Windows Mail 7"
    47. \StubPath = ""C:\Program Files\Windows Mail\WinMail.exe" OCInstallUserConfigOE" [MS]
    48. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
    49. {02478D38-C3F9-4EFB-9B51-7695ECA05670}\(Default) = (no title provided)
    50. -> {HKLM...CLSID} = "Yahoo! Toolbar Helper"
    51. \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ['Yahoo! Inc.']
    52. {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
    53. -> {HKLM...CLSID} = "Adobe PDF Reader"
    54. \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll" ['Adobe Systems Incorporated']
    55. {266fcdca-7bb3-4da7-b3bf-f845dea2ebd6}\(Default) = (no title provided)
    56. -> {HKLM...CLSID} = "IsoBuster Toolbar"
    57. \InProcServer32\(Default) = "C:\Program Files\IsoBuster\tbIsoB.dll" ['Conduit Ltd.']
    58. {72853161-30C5-4D22-B7F9-0BBC1D38A37E}\(Default) = (no title provided)
    59. -> {HKLM...CLSID} = "Groove GFS Browser Helper"
    60. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    61. {761497BB-D6F0-462C-B6EB-D4DAF1D92D43}\(Default) = (no title provided)
    62. -> {HKLM...CLSID} = "Java(tm) Plug-In SSV Helper"
    63. \InProcServer32\(Default) = "C:\Program Files\Java\jre6\bin\ssv.dll" ['Sun Microsystems, Inc.']
    64. {AF69DE43-7D58-4638-B6FA-CE66B5AD205D}\(Default) = (no title provided)
    65. -> {HKLM...CLSID} = "Google Toolbar Notifier BHO"
    66. \InProcServer32\(Default) = "C:\Program Files\Google\GoogleToolbarNotifier\5.0.926.3450\swg.dll" ['Google Inc.']
    67. {DBC80044-A445-435b-BC74-9C25C1C588A9}\(Default) = (no title provided)
    68. -> {HKLM...CLSID} = "Java(tm) Plug-In 2 SSV Helper"
    69. \InProcServer32\(Default) = "C:\Program Files\Java\jre6\bin\jp2ssv.dll" ['Sun Microsystems, Inc.']
    70. {E5A1691B-D188-4419-AD02-90002030B8EE}\(Default) = (no title provided)
    71. -> {HKLM...CLSID} = "FlashFXP Helper for Internet Explorer"
    72. \InProcServer32\(Default) = "C:\PROGRA~1\FlashFXP\IEFlash.dll" ['IniCom Networks, Inc.']
    73. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
    74. "{00020d75-0000-0000-c000-000000000046}" = "Microsoft Office Outlook Desktop Icon Handler"
    75. -> {HKLM...CLSID} = "Microsoft Office Outlook"
    76. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\MLSHEXT.DLL" [MS]
    77. "{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
    78. -> {HKLM...CLSID} = "DesktopContext Class"
    79. \InProcServer32\(Default) = "C:\Windows\system32\nvcpl.dll" ['NVIDIA Corporation']
    80. "{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
    81. -> {HKLM...CLSID} = "RealOne Player Context Menu Class"
    82. \InProcServer32\(Default) = "C:\Program Files\Real\RealPlayer\rpshell.dll" ['RealNetworks, Inc.']
    83. "{5858A72C-C2B4-4dd7-B2BF-B76DB1BD9F6C}" = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search"
    84. -> {HKLM...CLSID} = "Microsoft Office OneNote Namespace Extension for Windows Desktop Search"
    85. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\ONFILTER.DLL" [MS]
    86. "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
    87. -> {HKLM...CLSID} = (no title provided)
    88. \InProcServer32\(Default) = "C:\Program Files\Microsoft Office\Office12\msohevi.dll" [MS]
    89. "{993BE281-6695-4BA5-8A2A-7AACBFAAB69E}" = "Microsoft Office Metadata Handler"
    90. -> {HKLM...CLSID} = "Microsoft Office Metadata Handler"
    91. \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]
    92. "{C41662BB-1FA0-4CE0-8DC5-9B7F8279FF97}" = "Microsoft Office Thumbnail Handler"
    93. -> {HKLM...CLSID} = "Microsoft Office Thumbnail Handler"
    94. \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\msoshext.dll" [MS]
    95. "{7F67036B-66F1-411A-AD85-759FB9C5B0DB}" = "ShellViewRTF"
    96. -> {HKLM...CLSID} = "ShellViewRTF"
    97. \InProcServer32\(Default) = "C:\Windows\System32\ShellvRTF.dll" ['XSS']
    98. "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}" = "Shell Extension for Malware scanning"
    99. -> {HKLM...CLSID} = "Shell Extension for Malware scanning"
    100. \InProcServer32\(Default) = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll" ['Avira GmbH']
    101. "{B41DB860-8EE4-11D2-9906-E49FADC173CA}" = "WinRAR shell extension"
    102. -> {HKLM...CLSID} = "WinRAR"
    103. \InProcServer32\(Default) = "C:\Programme\WinRAR\rarext.dll" [null data]
    104. "{44440D00-FF19-4AFC-B765-9A0970567D97}" = "TuneUp Theme Extension"
    105. -> {HKLM...CLSID} = "TuneUp Theme Extension"
    106. \InProcServer32\(Default) = "C:\Windows\System32\uxtuneup.dll" ['TuneUp Software GmbH']
    107. "{4858E7D9-8E12-45a3-B6A3-1CD128C9D403}" = "TuneUp Shredder Shell Extension"
    108. -> {HKLM...CLSID} = "TuneUp Shredder Shell Extension"
    109. \InProcServer32\(Default) = "C:\Program Files\TuneUp Utilities 2009\SDShelEx-win32.dll" ['TuneUp Software GmbH']
    110. "{4838CD50-7E5D-4811-9B17-C47A85539F28}" = "TuneUp Disk Space Explorer Shell Extension"
    111. -> {HKLM...CLSID} = "TuneUp Disk Space Explorer Shell Extension"
    112. \InProcServer32\(Default) = "C:\Program Files\TuneUp Utilities 2009\DseShExt-x86.dll" ['TuneUp Software GmbH']
    113. "{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A}" = "Nokia Phone Browser"
    114. -> {HKLM...CLSID} = "Nokia Phone Browser"
    115. \InProcServer32\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 7\phonebrowser.dll" ['Nokia']
    116. "{72853161-30C5-4D22-B7F9-0BBC1D38A37E}" = "Groove GFS Browser Helper"
    117. -> {HKLM...CLSID} = "Groove GFS Browser Helper"
    118. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    119. "{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}" = "Groove GFS Explorer Bar"
    120. -> {HKLM...CLSID} = "Groove Folder Synchronization"
    121. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    122. "{A449600E-1DC6-4232-B948-9BD794D62056}" = "Groove GFS Stub Icon Handler"
    123. -> {HKLM...CLSID} = "Groove GFS Stub Icon Handler"
    124. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    125. "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"
    126. -> {HKLM...CLSID} = "Groove GFS Stub Execution Hook"
    127. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    128. "{6C467336-8281-4E60-8204-430CED96822D}" = "Groove GFS Context Menu Handler"
    129. -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
    130. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    131. "{387E725D-DC16-4D76-B310-2C93ED4752A0}" = "Groove XML Icon Handler"
    132. -> {HKLM...CLSID} = "Groove XML Icon Handler"
    133. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    134. "{16F3DD56-1AF5-4347-846D-7C10C4192619}" = "Groove Explorer Icon Overlay 3 (GFS Folder)"
    135. -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 3 (GFS Folder)"
    136. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    137. "{AB5C5600-7E6E-4B06-9197-9ECEF74D31CC}" = "Groove Explorer Icon Overlay 2 (GFS Stub)"
    138. -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 2 (GFS Stub)"
    139. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    140. "{2916C86E-86A6-43FE-8112-43ABE6BF8DCC}" = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"
    141. -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 4 (GFS Unread Mark)"
    142. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    143. "{99FD978C-D287-4F50-827F-B2C658EDA8E7}" = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"
    144. -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 1 (GFS Unread Stub)"
    145. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    146. "{920E6DB1-9907-4370-B3A0-BAFC03D81399}" = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"
    147. -> {HKLM...CLSID} = "Groove Explorer Icon Overlay 2.5 (GFS Unread Folder)"
    148. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    149. "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon Handler"
    150. -> {HKLM...CLSID} = "Outlook File Icon Extension"
    151. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\OLKFSTUB.DLL" [MS]
    152. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
    153. <<!>> "{B5A7F190-DDA6-4420-B3BA-52453494E6CD}" = "Groove GFS Stub Execution Hook"
    154. -> {HKLM...CLSID} = "Groove GFS Stub Execution Hook"
    155. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    156. HKLM\SOFTWARE\Classes\PROTOCOLS\Filter\
    157. <<!>> text/xml\CLSID = "{807563E5-5146-11D5-A672-00B0D022E945}"
    158. -> {HKLM...CLSID} = "Microsoft Office InfoPath XML Mime Filter"
    159. \InProcServer32\(Default) = "C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL" [MS]
    160. HKLM\SOFTWARE\Classes\Folder\shellex\ColumnHandlers\
    161. {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
    162. -> {HKLM...CLSID} = "PDF Shell Extension"
    163. \InProcServer32\(Default) = "C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\PDFShell.dll" ['Adobe Systems, Inc.']
    164. HKLM\SOFTWARE\Classes\*\shellex\ContextMenuHandlers\
    165. EPPShellEx\(Default) = "{509FE1AF-ADD5-49EC-BC55-7CF81FD16E78}"
    166. -> {HKLM...CLSID} = (no title provided)
    167. \InProcServer32\(Default) = "C:\Program Files\EPSON\Creativity Suite\Easy Photo Print\EPPShell.dll" ['SEIKO EPSON CORPORATION']
    168. Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
    169. -> {HKLM...CLSID} = "Shell Extension for Malware scanning"
    170. \InProcServer32\(Default) = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll" ['Avira GmbH']
    171. TuneUp Shredder Shell Extension\(Default) = "{4858E7D9-8E12-45a3-B6A3-1CD128C9D403}"
    172. -> {HKLM...CLSID} = "TuneUp Shredder Shell Extension"
    173. \InProcServer32\(Default) = "C:\Program Files\TuneUp Utilities 2009\SDShelEx-win32.dll" ['TuneUp Software GmbH']
    174. WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
    175. -> {HKLM...CLSID} = "WinRAR"
    176. \InProcServer32\(Default) = "C:\Programme\WinRAR\rarext.dll" [null data]
    177. XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
    178. -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
    179. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    180. HKLM\SOFTWARE\Classes\Directory\shellex\ContextMenuHandlers\
    181. TuneUp Disk Space Explorer Shell Extension\(Default) = "{4838CD50-7E5D-4811-9B17-C47A85539F28}"
    182. -> {HKLM...CLSID} = "TuneUp Disk Space Explorer Shell Extension"
    183. \InProcServer32\(Default) = "C:\Program Files\TuneUp Utilities 2009\DseShExt-x86.dll" ['TuneUp Software GmbH']
    184. TuneUp Shredder Shell Extension\(Default) = "{4858E7D9-8E12-45a3-B6A3-1CD128C9D403}"
    185. -> {HKLM...CLSID} = "TuneUp Shredder Shell Extension"
    186. \InProcServer32\(Default) = "C:\Program Files\TuneUp Utilities 2009\SDShelEx-win32.dll" ['TuneUp Software GmbH']
    187. WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
    188. -> {HKLM...CLSID} = "WinRAR"
    189. \InProcServer32\(Default) = "C:\Programme\WinRAR\rarext.dll" [null data]
    190. XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
    191. -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
    192. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    193. HKLM\SOFTWARE\Classes\Folder\shellex\ContextMenuHandlers\
    194. Shell Extension for Malware scanning\(Default) = "{45AC2688-0253-4ED8-97DE-B5370FA7D48A}"
    195. -> {HKLM...CLSID} = "Shell Extension for Malware scanning"
    196. \InProcServer32\(Default) = "C:\Program Files\Avira\AntiVir PersonalEdition Classic\shlext.dll" ['Avira GmbH']
    197. WinRAR\(Default) = "{B41DB860-8EE4-11D2-9906-E49FADC173CA}"
    198. -> {HKLM...CLSID} = "WinRAR"
    199. \InProcServer32\(Default) = "C:\Programme\WinRAR\rarext.dll" [null data]
    200. XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
    201. -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
    202. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    203. HKLM\SOFTWARE\Classes\AllFilesystemObjects\shellex\ContextMenuHandlers\
    204. XXX Groove GFS Context Menu Handler XXX\(Default) = "{6C467336-8281-4E60-8204-430CED96822D}"
    205. -> {HKLM...CLSID} = "Groove GFS Context Menu Handler"
    206. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    207. Group Policies {GPedit.msc branch and setting}:
    208. -----------------------------------------------
    209. Note: detected settings may not have any effect.
    210. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System\
    211. "ConsentPromptBehaviorAdmin" = (REG_DWORD) dword:0x00000002
    212. {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    213. User Account Control: Behavior Of The Elevation Prompt For Administrators In Admin Approval Mode}
    214. "ConsentPromptBehaviorUser" = (REG_DWORD) dword:0x00000001
    215. {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    216. User Account Control: Behavior Of The Elevation Prompt For Standard Users}
    217. "EnableInstallerDetection" = (REG_DWORD) dword:0x00000001
    218. {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    219. User Account Control: Detect Application Installations And Prompt For Elevation}
    220. "EnableLUA" = (REG_DWORD) dword:0x00000001
    221. {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    222. User Account Control: Run All Administrators In Admin Approval Mode}
    223. "EnableSecureUIAPaths" = (REG_DWORD) dword:0x00000001
    224. {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    225. User Account Control: Only elevate UIAccess applications that are installed in secure locations}
    226. "EnableVirtualization" = (REG_DWORD) dword:0x00000001
    227. {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    228. User Account Control: Virtualize file and registry write failures to per-user locations}
    229. "PromptOnSecureDesktop" = (REG_DWORD) dword:0x00000001
    230. {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    231. User Account Control: Switch to the secure desktop when prompting for elevation}
    232. "shutdownwithoutlogon" = (REG_DWORD) dword:0x00000001
    233. {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    234. Shutdown: Allow system to be shut down without having to log on}
    235. "undockwithoutlogon" = (REG_DWORD) dword:0x00000001
    236. {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    237. Devices: Allow undock without having to log on}
    238. "FilterAdministratorToken" = (REG_DWORD) dword:0x00000000
    239. {Computer Configuration|Windows Settings|Security Settings|Local Policies|Security Options|
    240. User Account Control: Admin Approval Mode for the Built-in Administrator Account}
    241. Active Desktop and Wallpaper:
    242. -----------------------------
    243. Active Desktop may be disabled at this entry:
    244. HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState
    245. Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
    246. HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
    247. "Wallpaper" = "C:\Windows\web\wallpaper\img24.jpg"
    248. Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
    249. HKCU\Control Panel\Desktop\
    250. "Wallpaper" = "C:\Windows\web\wallpaper\img24.jpg"
    251. Enabled Screen Saver:
    252. ---------------------
    253. HKCU\Control Panel\Desktop\
    254. "SCRNSAVE.EXE" = "C:\Windows\Snow3.scr" [null data]
    255. Windows Portable Device AutoPlay Handlers
    256. -----------------------------------------
    257. HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\AutoplayHandlers\Handlers\
    258. EpsonCreativitySuite\
    259. "Provider" = "FileManager"
    260. "InvokeProgID" = "EpsonCreativitySuite"
    261. "InvokeVerb" = "Play"
    262. HKLM\SOFTWARE\Classes\EpsonCreativitySuite\shell\Play\DropTarget\CLSID = "{7720BCC1-4F11-4f17-A80F-0BB69EF9788F}"
    263. -> {HKLM...CLSID} = (no title provided)
    264. \LocalServer32\(Default) = "C:\Program Files\EPSON\Creativity Suite\File Manager\eppqcom.exe" [null data]
    265. HPAutoplayPSE\
    266. "Provider" = "HP Photosmart Essential 2.0"
    267. "InvokeProgID" = "HpqPSApl.Autoplay"
    268. "InvokeVerb" = "Play"
    269. HKLM\SOFTWARE\Classes\HpqPSApl.Autoplay\shell\Play\DropTarget\CLSID = "{A6873065-D632-4615-A3A9-C5F05EE109C1}"
    270. -> {HKLM...CLSID} = (no title provided)
    271. \LocalServer32\(Default) = "c:\Program Files\HP\Digital Imaging\bin\HpqPsApl.exe" ['Hewlett-Packard']
    272. LightScribeOnArrivalAP\
    273. "Provider" = "LightScribe Direct Disc Labeling"
    274. "InvokeProgID" = "LightScribe.AutoPlayHandler"
    275. "InvokeVerb" = "LabelLightScribeDisc"
    276. HKLM\SOFTWARE\Classes\LightScribe.AutoPlayHandler\shell\LabelLightScribeDisc\command\(Default) = "c:\Program Files\Common Files\LightScribe\LsLauncher.exe" ['Hewlett-Packard Company']
    277. MediaCapture9Music\
    278. "Provider" = "Media Import"
    279. "InvokeProgID" = "RoxioMediaCapture9"
    280. "InvokeVerb" = "Audio"
    281. HKLM\SOFTWARE\Classes\RoxioMediaCapture9\shell\Audio\command\(Default) = "c:\Program Files\Roxio\Media Import 9\MediaCapture9.exe -audio %L" ['Sonic Solutions']
    282. MediaCapture9Photos\
    283. "Provider" = "Media Import"
    284. "InvokeProgID" = "RoxioMediaCapture9"
    285. "InvokeVerb" = "Photo"
    286. HKLM\SOFTWARE\Classes\RoxioMediaCapture9\shell\Photo\command\(Default) = "c:\Program Files\Roxio\Media Import 9\MediaCapture9.exe -photo %L" ['Sonic Solutions']
    287. MediaCapture9VideoCamera\
    288. "Provider" = "Media Import"
    289. "ProgID" = "Shell.HWEventHandlerShellExecute"
    290. "InitCmdLine" = "c:\Program Files\Roxio\Media Import 9\MediaCapture9.exe"
    291. HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}"
    292. -> {HKLM...CLSID} = "Shell Execute Hardware Event Handler"
    293. \LocalServer32\(Default) = "C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]
    294. MediaCapture9Videos\
    295. "Provider" = "Media Import"
    296. "InvokeProgID" = "RoxioMediaCapture9"
    297. "InvokeVerb" = "Video"
    298. HKLM\SOFTWARE\Classes\RoxioMediaCapture9\shell\Video\command\(Default) = "c:\Program Files\Roxio\Media Import 9\MediaCapture9.exe -video %L" ['Sonic Solutions']
    299. NMMPlayCDAudioOnArrival\
    300. "Provider" = "Nokia Music Manager"
    301. "InvokeProgID" = "NokiaMusicManager"
    302. "InvokeVerb" = "NMMPlayCD"
    303. HKLM\SOFTWARE\Classes\NokiaMusicManager\shell\NMMPlayCD\command\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 7\MusicManager.exe /playCD "%L"" ['Nokia']
    304. NMMRipCDAudioOnArrival\
    305. "Provider" = "Nokia Music Manager"
    306. "InvokeProgID" = "NokiaMusicManager"
    307. "InvokeVerb" = "NMMRipCD"
    308. HKLM\SOFTWARE\Classes\NokiaMusicManager\shell\NMMRipCD\command\(Default) = "C:\Program Files\Nokia\Nokia PC Suite 7\MusicManager.exe /ripCD "%L"" ['Nokia']
    309. RoxioSCAudioCDTask33\
    310. "Provider" = "Roxio Creator Audio"
    311. "InvokeProgID" = "Roxio.RoxioCentral33"
    312. "InvokeVerb" = "AudioCDTask"
    313. HKLM\SOFTWARE\Classes\Roxio.RoxioCentral33\shell\AudioCDTask\Command\(Default) = ""c:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe" /Launch {8E376824-EA6C-4CB7-AA05-A30CB84D359B}" [null data]
    314. RoxioSCCopyCD33\
    315. "Provider" = "Roxio Creator Copy"
    316. "InvokeProgID" = "Roxio.RoxioCentral33"
    317. "InvokeVerb" = "ExactCopyJob"
    318. HKLM\SOFTWARE\Classes\Roxio.RoxioCentral33\shell\ExactCopyJob\Command\(Default) = ""c:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe" /Launch {6123D5C0-0B6A-4B67-A692-C0863AB98CDA}" [null data]
    319. RoxioSCCopyDisc33\
    320. "Provider" = "Roxio Creator Copy"
    321. "InvokeProgID" = "Roxio.RoxioCentral33"
    322. "InvokeVerb" = "ExactCopyJob"
    323. HKLM\SOFTWARE\Classes\Roxio.RoxioCentral33\shell\ExactCopyJob\Command\(Default) = ""c:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe" /Launch {6123D5C0-0B6A-4B67-A692-C0863AB98CDA}" [null data]
    324. RoxioSCDataProject33\
    325. "Provider" = "Roxio Creator Data"
    326. "InvokeProgID" = "Roxio.RoxioCentral33"
    327. "InvokeVerb" = "DataGuide"
    328. HKLM\SOFTWARE\Classes\Roxio.RoxioCentral33\shell\DataGuide\Command\(Default) = ""c:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe" /Launch Data" [null data]
    329. RoxioSCDataTask33\
    330. "Provider" = "Roxio Creator Data"
    331. "InvokeProgID" = "Roxio.RoxioCentral33"
    332. "InvokeVerb" = "DataTask"
    333. HKLM\SOFTWARE\Classes\Roxio.RoxioCentral33\shell\DataTask\Command\(Default) = ""c:\Program Files\Common Files\Roxio Shared\9.0\Roxio Central33\Main\Roxio_Central33.exe" /Launch {D085B12D-4D9B-49C2-8323-5053831CBD54}" [null data]
    334. VLCPlayCDAudioOnArrival\
    335. "Provider" = "VideoLAN VLC media player"
    336. "InvokeProgID" = "VLC.CDAudio"
    337. "InvokeVerb" = "play"
    338. HKLM\SOFTWARE\Classes\VLC.CDAudio\shell\play\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file cdda:%1" ['VideoLAN Team']
    339. VLCPlayDVDMovieOnArrival\
    340. "Provider" = "VideoLAN VLC media player"
    341. "InvokeProgID" = "VLC.DVDMovie"
    342. "InvokeVerb" = "play"
    343. HKLM\SOFTWARE\Classes\VLC.DVDMovie\shell\play\command\(Default) = "C:\Program Files\VideoLAN\VLC\vlc.exe --started-from-file dvd:%1" ['VideoLAN Team']
    344. WinampMTPHandler\
    345. "Provider" = "Winamp"
    346. "ProgID" = "Shell.HWEventHandlerShellExecute"
    347. "InitCmdLine" = "C:\Program Files\Winamp\winamp.exe"
    348. HKLM\SOFTWARE\Classes\Shell.HWEventHandlerShellExecute\CLSID\(Default) = "{FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}"
    349. -> {HKLM...CLSID} = "Shell Execute Hardware Event Handler"
    350. \LocalServer32\(Default) = "C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {FFB8655F-81B9-4fce-B89C-9A6BA76D13E7}" [MS]
    351. WinampPlayMediaOnArrival\
    352. "Provider" = "Winamp"
    353. "InvokeProgID" = "Winamp.File"
    354. "InvokeVerb" = "Play"
    355. HKLM\SOFTWARE\Classes\Winamp.File\shell\Play\command\(Default) = ""C:\Program Files\Winamp\winamp.exe" "%1"" ['Nullsoft']
    356. HKLM\SOFTWARE\Classes\Winamp.File\shell\Play\DropTarget\CLSID = "{46986115-84D6-459c-8F95-52DD653E532E}"
    357. -> {HKLM...CLSID} = (no title provided)
    358. \LocalServer32\(Default) = ""C:\Program Files\Winamp\winamp.exe"" ['Nullsoft']
    359. Winsock2 Service Provider DLLs:
    360. -------------------------------
    361. Namespace Service Providers
    362. HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\ {++}
    363. 000000000001\LibraryPath = "%SystemRoot%\system32\NLAapi.dll" [MS]
    364. 000000000002\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
    365. 000000000003\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
    366. 000000000004\LibraryPath = "%SystemRoot%\system32\napinsp.dll" [MS]
    367. 000000000005\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
    368. 000000000006\LibraryPath = "%SystemRoot%\system32\pnrpnsp.dll" [MS]
    369. Transport Service Providers
    370. HKLM\SYSTEM\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\ {++}
    371. 0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
    372. %SystemRoot%\system32\mswsock.dll [MS], 01 - 22
    373. Toolbars, Explorer Bars, Extensions:
    374. ------------------------------------
    375. Toolbars
    376. HKCU\Software\Microsoft\Internet Explorer\Toolbar\WebBrowser\
    377. "{266FCDCA-7BB3-4DA7-B3BF-F845DEA2EBD6}"
    378. -> {HKLM...CLSID} = "IsoBuster Toolbar"
    379. \InProcServer32\(Default) = "C:\Program Files\IsoBuster\tbIsoB.dll" ['Conduit Ltd.']
    380. HKLM\SOFTWARE\Microsoft\Internet Explorer\Toolbar\
    381. "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
    382. -> {HKLM...CLSID} = "Yahoo! Toolbar mit Pop-Up-Blocker"
    383. \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ['Yahoo! Inc.']
    384. "{266FCDCA-7BB3-4DA7-B3BF-F845DEA2EBD6}" = "IsoBuster Toolbar"
    385. -> {HKLM...CLSID} = "IsoBuster Toolbar"
    386. \InProcServer32\(Default) = "C:\Program Files\IsoBuster\tbIsoB.dll" ['Conduit Ltd.']
    387. Explorer Bars
    388. HKLM\SOFTWARE\Microsoft\Internet Explorer\Explorer Bars\
    389. HKLM\SOFTWARE\Classes\CLSID\{2A541AE1-5BF6-4665-A8A3-CFA9672E4291}\(Default) = "Groove Folder Synchronization"
    390. Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
    391. InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\GRA8E1~1.DLL" [MS]
    392. HKLM\SOFTWARE\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) = "&Recherchieren"
    393. Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
    394. InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL" [MS]
    395. Extensions (Tools menu items, main toolbar menu buttons)
    396. HKLM\SOFTWARE\Microsoft\Internet Explorer\Extensions\
    397. {2670000A-7350-4F3C-8081-5663EE0C6C49}\
    398. "ButtonText" = "An OneNote senden"
    399. "MenuText" = "An OneNote s&enden"
    400. "CLSIDExtension" = "{48E73304-E1D6-4330-914C-F5F514E3486C}"
    401. -> {HKLM...CLSID} = "Send to OneNote from Internet Explorer button"
    402. \InProcServer32\(Default) = "C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll" [MS]
    403. {92780B25-18CC-41C8-B9BE-3C9C571A8263}\
    404. "ButtonText" = "Research"
    405. {E59EB121-F339-4851-A3BA-FE49C35617C2}\
    406. "ButtonText" = "ICQ6"
    407. "MenuText" = "ICQ6"
    408. "Exec" = "C:\Program Files\ICQ6.5\ICQ.exe" ['ICQ, Inc.']
    409. Miscellaneous IE Hijack Points
    410. ------------------------------
    411. HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks\
    412. <<H>> "{EF99BD32-C1FB-11D2-892F-0090271D4F88}" = (no title provided)
    413. -> {HKLM...CLSID} = "Yahoo! Toolbar mit Pop-Up-Blocker"
    414. \InProcServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\yt.dll" ['Yahoo! Inc.']
    415. <<H>> "{266fcdca-7bb3-4da7-b3bf-f845dea2ebd6}" = (no title provided)
    416. -> {HKLM...CLSID} = "IsoBuster Toolbar"
    417. \InProcServer32\(Default) = "C:\Program Files\IsoBuster\tbIsoB.dll" ['Conduit Ltd.']
    418. Running Services (Display Name, Service Name, Path {Service DLL}):
    419. ------------------------------------------------------------------
    420. Avira AntiVir Personal - Free Antivirus Guard, AntiVirService, ""C:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe"" ['Avira GmbH']
    421. Avira AntiVir Personal - Free Antivirus Planer, AntiVirScheduler, ""C:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe"" ['Avira GmbH']
    422. BlueSoleil Hid Service, BlueSoleil Hid Service, "C:\Program Files\IVT Corporation\BlueSoleil\BTNtService.exe" [null data]
    423. Computerbrowser, Browser, "C:\Windows\System32\svchost.exe -k netsvcs" {"C:\Windows\System32\browser.dll" [MS]}
    424. CyberGhost VPN Client, CGVPNCliSrvc, "C:\Program Files\S.A.D\CyberGhost VPN\CGVPNCliService.exe" ['mobile concepts GmbH']
    425. Google Updater Service, gusvc, ""C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe"" ['Google']
    426. LightScribeService Direct Disc Labeling Service, LightScribeService, ""c:\Program Files\Common Files\LightScribe\LSSrvc.exe"" ['Hewlett-Packard Company']
    427. NVIDIA Display Driver Service, nvsvc, "C:\Windows\system32\nvvsvc.exe" ['NVIDIA Corporation']
    428. ServiceLayer, ServiceLayer, ""C:\Program Files\PC Connectivity Solution\ServiceLayer.exe"" ['Nokia.']
    429. Steam Client Service, Steam Client Service, "C:\Program Files\Common Files\Steam\SteamService.exe /RunAsService" ['Valve Corporation']
    430. Windows Driver Foundation - Benutzermodus-Treiberframework, wudfsvc, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\System32\WUDFSvc.dll" [MS]}
    431. Windows-Bilderfassung, stisvc, "C:\Windows\system32\svchost.exe -k imgsvc" {"C:\Windows\System32\wiaservc.dll" [MS]}
    432. Zugriff auf Eingabegeräte, hidserv, "C:\Windows\system32\svchost.exe -k LocalSystemNetworkRestricted" {"C:\Windows\system32\hidserv.dll" [MS]}
    433. Print Monitors:
    434. ---------------
    435. HKLM\SYSTEM\CurrentControlSet\Control\Print\Monitors\
    436. EPSON Stylus DX4400 Series 32MonitorBE\Driver = "E_FLBCAE.DLL" ['SEIKO EPSON CORPORATION']
    437. Send To Microsoft OneNote Monitor\Driver = "msonpmon.dll" [MS]
    438. ---------- (launch time: 2008-12-13 20:47:22)
    439. <<!>>: Suspicious data at a malware launch point.
    440. <<H>>: Suspicious data at a browser hijack point.
    441. + This report excludes default entries except where indicated.
    442. + To see *everywhere* the script checks and *everything* it finds,
    443. launch it from a command prompt or a shortcut with the -all parameter.
    444. + To search all directories of local fixed drives for DESKTOP.INI
    445. DLL launch points, use the -supp parameter or answer "No" at the
    446. first message box and "Yes" at the second message box.
    447. ---------- (total run time: 74 seconds, including 14 seconds for message boxes)
    Alles anzeigen


    Welches Antivir Programm könnt ihr mir empfehlen?
    [COLOR="Blue"]Meine UP´s Kinder Hörspiele[/color]
  • Also in deinem HijackThis Log sind einige Sachen drin die nicht hin gehören

    beende im Taskmanager folgende Prozesse und lasse die Dateien bei VirusTotal
    einmal scannen, poste dann das Ergebnis:

    C:Windows\system32\taskeng.exe
    C:Windows\system32\Dwm.exe
    C:WINDOWS\PixArtPAC207\Monitor.exe
    C:WINDOWS\System32\svhost.exe
    C:Windows\system32\wuauclt.exe

    PS: ich kann dir jetzt schon sagen das beste wird wohl eine Neuinstallation sein. Meine Vermutung gehen zu MYDOOM
    Gruß Fotoprinz
  • oki ich hab einfach mal alle datei´n mit HijackThis gefixt die fehlerhaft waren un kaspersky installeiert

    neustart von windows hat zwart über 5 min gedauert aber jzz geht alles ohne problem un fährt jzz auch wieder schneller hoch

    ach und noch was nachdem ersten neustart waren die NETZWERKTREIBER deaktiviert also nich wundere´n wenn ihr kein Internet habt!!!

    Gruß bomber09:blink:
    [COLOR="Blue"]Meine UP´s Kinder Hörspiele[/color]
  • bomber09 schrieb:

    oki ich hab einfach mal alle datei´n mit HijackThis gefixt die fehlerhaft waren un kaspersky installeiert




    Das war das beste was Du tun konntest.Kaspersky ist meiner meinung nach immer noch das beste Antiviren Programm was es gibt.

    Freut mich das es Deinem System wieder besser geht.:)


    Greetz
    [COLOR="Blue"][SIZE="3"]Das Problem ist nicht der Computer,das Problem sitzt davor.[/SIZE][/color]