Log Kopie: Ich habe schon die übeltäter ausgemacht. Sag dir bescheid was zu tun ist
Running processes:
C:WINDOWSSystem32smss.exe
C:WINDOWSsystem32winlogon.exe
C:WINDOWSsystem32services.exe
C:WINDOWSsystem32lsass.exe
C:WINDOWSsystem32svchost.exe
C:WINDOWSSystem32svchost.exe
C:WINDOWSsystem32spoolsv.exe
C

rogrammeAviraAntiVir Desktopsched.exe
C

rogrammeAviraAntiVir Desktopavguard.exe
C:WINDOWSExplorer.EXE
C:WINDOWSsystem32oodtray.exe
C

rogrammeAviraAntiVir Desktopavgnt.exe
C:WINDOWSsystem32rundll32.exe
C:WINDOWSsystem32ctfmon.exe
C

rogrammeSamsungSamsung New PC StudioNPSAgent.exe
C

rogrammeLogitechSetPointSetPoint.exe
C:EwaldTk-Suitetoolsctimon.exe
C

rogrammeGemeinsame DateienLogishrdKHAL2KHALMNPR.EXE
C

rogrammeGemeinsame DateienAppleMobile Device SupportbinAppleMobileDeviceService.exe
C

rogrammeBonjourmDNSResponder.exe
C:WINDOWSsystem32FsUsbExService.Exe
C

rogrammeGemeinsame DateienLightScribeLSSrvc.exe
C

rogrammeGemeinsame DateienMicrosoft SharedVS7DEBUGMDM.EXE
C:WINDOWSsystem32nvsvc32.exe
C:WINDOWSsystem32oodag.exe
C:WINDOWSsystem32svchost.exe
C:EwaldTk-Suitetkservertksock.exe
C:EwaldTk-Suitetkservertkmedia.exe
C

rogrammeFirefoxfirefox.exe
X

etup.exe
C

rogrammeTrend MicroHijackThisHijackThis.exe
C:WINDOWSsystem32msiexec.exe
R0 - HKCUSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Page_URL =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLMSoftwareMicrosoftInternet ExplorerMain,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLMSoftwareMicrosoftInternet ExplorerMain,Start Page =
http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCUSoftwareMicrosoftInternet ExplorerMain,First Home Page =
http://go.microsoft.com/fwlink/?LinkId=54843R1 - HKCUSoftwareMicrosoftWindowsCurrentVersionInternet Settings,ProxyOverride = *.local
R3 - URLSearchHook: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C

rogrammeSearch Settingskb128SearchSettings.dll
F3 - REG:win.ini: run=
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C

rogrammeGemeinsame DateienAdobeAcrobatActiveXAcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: (no name) - {8a194578-81ea-4850-9911-13ba2d71efbd} - (no file)
O2 - BHO: Windows Live Anmelde-Hilfsprogramm - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C

rogrammeGemeinsame DateienMicrosoft SharedWindows LiveWindowsLiveLogin.dll
O2 - BHO: SearchSettings Class - {E312764E-7706-43F1-8DAB-FCDD2B1E416D} - C

rogrammeSearch Settingskb128SearchSettings.dll
O4 - HKLM..Run: [NvCplDaemon] RUNDLL32.EXE C:WINDOWSsystem32NvCpl.dll,NvStartup
O4 - HKLM..Run: [OODefragTray] C:WINDOWSsystem32oodtray.exe
O4 - HKLM..Run: [CmPCIaudio] RunDll32 CMICNFG3.CPL,CMICtrlWnd
O4 - HKLM..Run: [avgnt] "C

rogrammeAviraAntiVir Desktopavgnt.exe" /min
O4 - HKLM..Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM..Run: [Adobe ARM] "C

rogrammeGemeinsame DateienAdobeARM1.0AdobeARM.exe"
O4 - HKLM..Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKCU..Run: [CTFMON.EXE] C:WINDOWSsystem32ctfmon.exe
O4 - HKCU..Run: [AutoStartNPSAgent] C

rogrammeSamsungSamsung New PC StudioNPSAgent.exe
O4 - HKUSS-1-5-19..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'LOKALER DIENST')
O4 - HKUSS-1-5-20..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'NETZWERKDIENST')
O4 - HKUSS-1-5-18..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'SYSTEM')
O4 - HKUS.DEFAULT..Run: [CTFMON.EXE] C:WINDOWSsystem32CTFMON.EXE (User 'Default user')
O4 - Startup: Logitech . Produktregistrierung.lnk = C

rogrammeGemeinsame DateienLogishrdeRegSetPointeReg.exe
O4 - Global Startup: Logitech SetPoint.lnk = C

rogrammeLogitechSetPointSetPoint.exe
O4 - Global Startup: TK-Suite Client.lnk = C:EwaldTk-Suitetoolsctimon.exe
O8 - Extra context menu item: Nach Microsoft &Excel exportieren - res://C

ROGRA~1MICROS~2OFFICE11EXCEL.EXE/3000
O9 - Extra button: Recherchieren - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C

ROGRA~1MICROS~2OFFICE11REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:WINDOWSNetwork Diagnosticxpnetdiag.exe
O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C

rogrammeICQ6.5ICQ.exe
O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C

rogrammeICQ6.5ICQ.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C

rogrammeMessengermsmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C

rogrammeMessengermsmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) -
http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1142091956531O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) -
http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?
1236790090937O16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) -
http://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO17 - HKLMSystemCCSServicesTcpip..{E961942E-22E8-4E0C-8941-F626FA2AB2B6}: NameServer = 192.168.178.1
O23 - Service: Avira AntiVir Planer (AntiVirSchedulerService) - Avira GmbH - C

rogrammeAviraAntiVir Desktopsched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C

rogrammeAviraAntiVir Desktopavguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C

rogrammeGemeinsame DateienAppleMobile Device SupportbinAppleMobileDeviceService.exe
O23 - Service: Bonjour-Dienst (Bonjour Service) - Apple Inc. - C

rogrammeBonjourmDNSResponder.exe
O23 - Service: FsUsbExService - Teruten - C:WINDOWSsystem32FsUsbExService.Exe
O23 - Service: Google Update Service (gupdate1c9d18770a63260) (gupdate1c9d18770a63260) - Google Inc. - C

rogrammeGoogleUpdateGoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C

rogrammeGemeinsame DateienInstallShieldDriver1050Intel 32IDriverT.exe
O23 - Service: iPod-Dienst (iPod Service) - Apple Inc. - C

rogrammeiPodbiniPodService.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C

rogrammeGemeinsame DateienLogishrdBluetoothLBTServ.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C

rogrammeGemeinsame DateienLightScribeLSSrvc.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:WINDOWSsystem32nvsvc32.exe
O23 - Service: O&O Defrag - O&O Software GmbH - C:WINDOWSsystem32oodag.exe
O23 - Service: ServiceLayer - Nokia. - C

rogrammePC Connectivity SolutionServiceLayer.exe
O23 - Service: TK-Suite Server (tksock) - AGFEO - C:EwaldTk-Suitetkservertksock.exe
O23 - Service: TuneUp Drive Defrag-Dienst (TuneUp.Defrag) - TuneUp Software GmbH - C:WINDOWSSystem32TuneUpDefragService.exe
--
End of file - 7933 bytes