neue Favoriten + Startseitenwechsel |
||
---|---|---|
#0
| ||
26.08.2004, 21:38
...neu hier
Beiträge: 2 |
||
|
||
27.08.2004, 13:25
Ehrenmitglied
Beiträge: 29434 |
#2
Hallo@MichaelMicha
scanne mit dem HijackThis, dann hake genau an, was ich poste , dann <fix< und neustarten R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://countere.com/?a=2&b=hc R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://countere.com/?a=2&b=hc R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://countere.com/?a=2&b=hc R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://countere.com/?a=2&b=hc R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://countere.com/?b=hc R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://countere.com/?a=2&b=hc R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://countere.com/?a=2&b=hc R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://countere.com/?a=2&b=hc R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://countere.com/?a=2&b=hc R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://countere.com/?a=2&b=hc R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://countere.com/?a=2&b=hc R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file) O1 - Hosts: 69.56.223.196 t.rack.cc O1 - Hosts: 69.56.223.196 www.alfa-search.com O1 - Hosts: 69.56.223.196 webcoolsearch.com O1 - Hosts: 69.56.223.196 in.webcounter.cc O1 - Hosts: 69.56.223.196 i-lookup.com O1 - Hosts: 69.56.223.196 www.hand-book.com O1 - Hosts: 69.56.223.196 www.maxxxhosters.com O1 - Hosts: 69.56.223.196 allneedsearch.com O1 - Hosts: 69.56.223.196 nativehardcore.com O1 - Hosts: 69.56.223.196 teen-biz.com O1 - Hosts: 69.56.223.196 tits.hardcore4ever.net O1 - Hosts: 69.56.223.196 best.royalsearch.net O1 - Hosts: 69.56.223.196 default-homepage-network.com O1 - Hosts: 69.56.223.196 xwebsearch.biz O1 - Hosts: 69.56.223.196 www.rightfinder.net O1 - Hosts: 69.56.223.196 www.search-1.net O1 - Hosts: 69.56.223.196 www.searchv.com O1 - Hosts: 69.56.223.196 www.websearch.com O1 - Hosts: 69.56.223.196 mysearchnow.com O1 - Hosts: 69.56.223.196 www.therealsearch.com O1 - Hosts: 69.56.223.196 www.find-itnow.com O1 - Hosts: 69.56.223.196 find.microgirls.com O1 - Hosts: 69.56.223.196 super-spider.com O1 - Hosts: 69.56.223.196 www.searching-the-net.com O1 - Hosts: 69.56.223.196 www.firstbookmark.com O1 - Hosts: 69.56.223.196 just.find-itnow.com O1 - Hosts: 69.56.223.196 www.find-itnow.com O1 - Hosts: 69.56.223.196 qwertysearch123.biz O1 - Hosts: 69.56.223.196 www.search-space.com O1 - Hosts: 69.56.223.196 www.windowws.cc O1 - Hosts: 69.56.223.196 aifind.info O1 - Hosts: 69.56.223.196 www.find4u.net O1 - Hosts: 69.56.223.196 find4u.net O1 - Hosts: 69.56.223.196 www.lookfor.cc O1 - Hosts: 69.56.223.196 www.008i.com O1 - Hosts: 69.56.223.196 www.viewpornkey.com O1 - Hosts: 69.56.223.196 www.hugesearch.net O1 - Hosts: 69.56.223.196 www.F***.com O1 - Hosts: 69.56.223.196 www.seznam.cz O1 - Hosts: 69.56.223.196 aifind.cc O1 - Hosts: 69.56.223.196 www.onet.pl O1 - Hosts: 69.56.223.196 teenhqpics.com O1 - Hosts: 69.56.223.196 www.ttjj.com O1 - Hosts: 69.56.223.196 www.search-dot.com O1 - Hosts: 69.56.223.196 www.search-and-go.com O1 - Hosts: 69.56.223.196 www.slotch.com O1 - Hosts: 69.56.223.196 www.2fastsearch.net O1 - Hosts: 69.56.223.196 awebfind.biz O1 - Hosts: 69.56.223.196 www.power-search.info O1 - Hosts: 69.56.223.196 www.naver.com O1 - Hosts: 69.56.223.196 www.daum.net O1 - Hosts: 69.56.223.196 www.ohcorea.com O1 - Hosts: 69.56.223.196 www.hao123.com O1 - Hosts: 69.56.223.196 58q.com O1 - Hosts: 69.56.223.196 www.hotwebsearch.com O1 - Hosts: 69.56.223.196 www.startium.com O1 - Hosts: 69.56.223.196 www.gajai.com O1 - Hosts: 69.56.223.196 www.wazzupnet.com O1 - Hosts: 69.56.223.196 freshvideogals.com O1 - Hosts: 69.56.223.196 www.xgmm.com O1 - Hosts: 69.56.223.196 searchmyrequest.com O1 - Hosts: 69.56.223.196 yourbookmarks.ws O1 - Hosts: 69.56.223.196 wmmse.com O1 - Hosts: 69.56.223.196 link.startmake.com O1 - Hosts: 69.56.223.196 www.boredlife.com O1 - Hosts: 69.56.223.196 approvedlinks.com O1 - Hosts: 69.56.223.196 www.nkvd.us O1 - Hosts: 69.56.223.196 www.8095.com O1 - Hosts: 69.56.223.196 www.dreamwiz.com O1 - Hosts: 69.56.223.196 ie-search.com O1 - Hosts: 69.56.223.196 auto.ie.searchforge.com O1 - Hosts: 69.56.223.196 search.psn.cn O1 - Hosts: 69.56.223.196 www.couldnotfind.com O1 - Hosts: 69.56.223.196 www.iquicksearch.com O1 - Hosts: 69.56.223.196 1-se.com O1 - Hosts: 69.56.223.196 www.spidersearch.com O1 - Hosts: 69.56.223.196 search.ieplugin.com O1 - Hosts: 69.56.223.196 itseasy.us O1 - Hosts: 69.56.223.196 searchbar.findthewebsiteyouneed.com O1 - Hosts: 69.56.223.196 www.searchxl.com O1 - Hosts: 69.56.223.196 www.hotsearchbox.com O1 - Hosts: 69.56.223.196 www.searchforge.com O1 - Hosts: 69.56.223.196 www.omega-search.com O1 - Hosts: 69.56.223.196 searchcentrix.com O2 - BHO: (no name) - {2257B486-4918-419F-B701-F4D7668C059F} - C:\WINDOWS\System32\ngpndb.dll (file missing) O4 - HKLM\..\Run: [MPB] C:\WINDOWS\System32\MPB.exe O4 - HKLM\..\Run: [hh32PEmssy] C:\WINDOWS\system32\hh32PEmssy.exe O4 - HKLM\..\Run: [u42774i] C:\WINDOWS\system32\u42774i.exe O4 - HKCU\..\Run: [SpywareGuard] C:\WINDOWS\system32\winmm64.exe O4 - HKCU\..\Run: [hh32PEmssy] C:\WINDOWS\system32\hh32PEmssy.exe O4 - HKCU\..\Run: [u42774i] C:\WINDOWS\system32\u42774i.exe NEUSTARTEN #Gehe in die Host-Datei(mit Editor oeffnen) schau mal in c:\Windows\System32\drivers\etc\hosts Im Normalfall sollte dass hier drin stehen, alles andere loeschen !!! 127.0.0.1 localhost #Orginal Host Datei #Ueberpruefe mit Kaspersky(falls<bad< loeschen, aber auch mir posten, was angezeigt wurde http://www.kaspersky.com/remoteviruschk.html C:\WINDOWS\System32\MPB.exe............(Musical Paint Brush 3.1. ?) C:\WINDOWS\system32\hh32PEmssy.exe....(Virus ?) C:\WINDOWS\system32\u42774i.exe....(Virus ?) #[SpywareGuard] #C:\WINDOWS\system32\winmm64.exe deinstallieren und alles loeschen. #loesche unter <Internetoptionen< die TemporaryInternetfiles , auch die Offline #Gehe in Start<Ausfuehren<%temp% und loesche die temp.-Dateien #Lade eScan (entpacke in C:\bases...die du erstellst http://www.mwti.net/antivirus/free_utilities.asp Nun suchst du eine "kavupd.exe" und anklicken. <Es oeffnet sich ein DOS-Fenster und es wird ein Update ausgeführt(dauert ein bisschen) ________________________ ---Gehe in den abgesicherten Modus http://www.bsi.de/av/texte/winsave.htm <den Scanner mit der "mwav.exe starten. Alle Häkchen setzen und "Scan clean" klicken. Danach die <Virus Log <Information posten. (ALLES was als <infiziert<gefunden wird) _________________________ http://service1.symantec.com/SUPPORT/INTER/tsgeninfointl.nsf/gdocid/20030807105707924 Deaktiviere die Wiederherstellung #Stelle eine neue Startseite ein und poste das Log noch mal + Infos Kaspersky+ Virenlog mwav.exe (nur den infizierten Teil) mfg Sabina __________ MfG Sabina rund um die PC-Sicherheit Dieser Beitrag wurde am 30.08.2004 um 16:28 Uhr von Sabina editiert.
|
|
|
||
30.08.2004, 16:12
...neu hier
Themenstarter Beiträge: 2 |
#3
Hallo Sabina!
Herzlichen Dank, es hat geholfen glaub ich. Keine Startseitenwechsel mehr und die nicht gewollten Fovouriten haben endlich kapiert, dass ich sie nicht fovourisiere. Danke |
|
|
||
30.08.2004, 16:27
Ehrenmitglied
Beiträge: 29434 |
#4
Hallo@MichaelMicha
Poste das neue Log noch mal. mfg Sabina __________ MfG Sabina rund um die PC-Sicherheit Dieser Beitrag wurde am 30.08.2004 um 16:27 Uhr von Sabina editiert.
|
|
|
||
Normalerweise löse ich meine kleinen Alltagspröblemchen prinzipiell immer selbst, sogar wenn ich von nix keine Ahnung hab ;-), aber da ich schon einiges versucht habe und ihr hier so freundlich Eure Hilfe anbietet, möchte ich diese gerne in Anspruch nehmen.
1. Also ich hab mir da was eingefangen, was mir Antivir nicht wegkriegt. Und zwar hab ich immer wieder neue Links in meinen Favoriten - wie immer Werbung und Porno - habs schon ixmal gelöscht, kommt aber immer wieder.
2. Meine Startseite wird immerwieder geändert.
Hier mein Hijack-Dingbums:
Logfile of HijackThis v1.98.2
Scan saved at 21:24:09, on 26.08.2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\PROGRA~1\0900WA~1\w0svc.exe
C:\WINDOWS\System32\alg.exe
C:\Programme\AVPersonal\AVWUPSRV.EXE
C:\Programme\Sophos SWEEP for NT\SWNETSUP.EXE
C:\Programme\Sophos SWEEP for NT\SWEEPSRV.SYS
C:\WINDOWS\wanmpsvc.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\htpatch.exe
C:\WINDOWS\System32\khooker.exe
C:\WINDOWS\System32\MPB.exe
C:\WINDOWS\System32\pctspk.exe
C:\PROGRA~1\0900WA~1\WARN0900.EXE
C:\Programme\AVPersonal\AVGNT.EXE
C:\WINDOWS\system32\u42774i.exe
C:\Programme\Synaptics\SynTP\SynTPLpr.exe
C:\Programme\Synaptics\SynTP\SynTPEnh.exe
C:\Programme\QuickTime\qttask.exe
C:\Programme\MSI\Live Update 3\LMonitor.exe
C:\Programme\Gemeinsame Dateien\Real\Update_OB\evntsvc.exe
C:\Programme\Winamp\winampa.exe
C:\WINDOWS\System32\ctfmon.exe
C:\WINDOWS\system32\winmm64.exe
C:\Programme\Skype\Phone\Skype.exe
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Programme\Sophos SWEEP for NT\ICMON.EXE
C:\Programme\Nikon\NkView6\NkvMon.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\wisptis.exe
C:\Programme\Internet Explorer\IEXPLORE.EXE
C:\Dokumente und Einstellungen\Michael Hilbert\Lokale Einstellungen\Temp\Temporäres Verzeichnis 1 für hijackthis.zip\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://countere.com/?a=2&b=hc
R1 - HKLM\Software\Microsoft\Internet Explorer,SearchURL = http://countere.com/?a=2&b=hc
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://countere.com/?a=2&b=hc
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://countere.com/?a=2&b=hc
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://countere.com/?b=hc
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://countere.com/?a=2&b=hc
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://countere.com/?a=2&b=hc
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://countere.com/?a=2&b=hc
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://countere.com/?a=2&b=hc
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://countere.com/?a=2&b=hc
R1 - HKLM\Software\Microsoft\Internet Explorer\SearchURL,SearchURL = http://countere.com/?a=2&b=hc
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = wwwproxy.uni-frankfurt.de:80
R3 - URLSearchHook: (no name) - _{CFBFAE00-17A6-11D0-99CB-00C04FD64497} - (no file)
O1 - Hosts: 69.56.223.196 t.rack.cc
O1 - Hosts: 69.56.223.196 www.alfa-search.com
O1 - Hosts: 69.56.223.196 webcoolsearch.com
O1 - Hosts: 69.56.223.196 in.webcounter.cc
O1 - Hosts: 69.56.223.196 i-lookup.com
O1 - Hosts: 69.56.223.196 www.hand-book.com
O1 - Hosts: 69.56.223.196 www.maxxxhosters.com
O1 - Hosts: 69.56.223.196 allneedsearch.com
O1 - Hosts: 69.56.223.196 nativehardcore.com
O1 - Hosts: 69.56.223.196 teen-biz.com
O1 - Hosts: 69.56.223.196 tits.hardcore4ever.net
O1 - Hosts: 69.56.223.196 best.royalsearch.net
O1 - Hosts: 69.56.223.196 default-homepage-network.com
O1 - Hosts: 69.56.223.196 xwebsearch.biz
O1 - Hosts: 69.56.223.196 www.rightfinder.net
O1 - Hosts: 69.56.223.196 www.search-1.net
O1 - Hosts: 69.56.223.196 www.searchv.com
O1 - Hosts: 69.56.223.196 www.websearch.com
O1 - Hosts: 69.56.223.196 mysearchnow.com
O1 - Hosts: 69.56.223.196 www.therealsearch.com
O1 - Hosts: 69.56.223.196 www.find-itnow.com
O1 - Hosts: 69.56.223.196 find.microgirls.com
O1 - Hosts: 69.56.223.196 super-spider.com
O1 - Hosts: 69.56.223.196 www.searching-the-net.com
O1 - Hosts: 69.56.223.196 www.firstbookmark.com
O1 - Hosts: 69.56.223.196 just.find-itnow.com
O1 - Hosts: 69.56.223.196 www.find-itnow.com
O1 - Hosts: 69.56.223.196 qwertysearch123.biz
O1 - Hosts: 69.56.223.196 www.search-space.com
O1 - Hosts: 69.56.223.196 www.windowws.cc
O1 - Hosts: 69.56.223.196 aifind.info
O1 - Hosts: 69.56.223.196 www.find4u.net
O1 - Hosts: 69.56.223.196 find4u.net
O1 - Hosts: 69.56.223.196 www.lookfor.cc
O1 - Hosts: 69.56.223.196 www.008i.com
O1 - Hosts: 69.56.223.196 www.viewpornkey.com
O1 - Hosts: 69.56.223.196 www.hugesearch.net
O1 - Hosts: 69.56.223.196 www.F***.com
O1 - Hosts: 69.56.223.196 www.seznam.cz
O1 - Hosts: 69.56.223.196 aifind.cc
O1 - Hosts: 69.56.223.196 www.onet.pl
O1 - Hosts: 69.56.223.196 teenhqpics.com
O1 - Hosts: 69.56.223.196 www.ttjj.com
O1 - Hosts: 69.56.223.196 www.search-dot.com
O1 - Hosts: 69.56.223.196 www.search-and-go.com
O1 - Hosts: 69.56.223.196 www.slotch.com
O1 - Hosts: 69.56.223.196 www.2fastsearch.net
O1 - Hosts: 69.56.223.196 awebfind.biz
O1 - Hosts: 69.56.223.196 www.power-search.info
O1 - Hosts: 69.56.223.196 www.naver.com
O1 - Hosts: 69.56.223.196 www.daum.net
O1 - Hosts: 69.56.223.196 www.ohcorea.com
O1 - Hosts: 69.56.223.196 www.hao123.com
O1 - Hosts: 69.56.223.196 58q.com
O1 - Hosts: 69.56.223.196 www.hotwebsearch.com
O1 - Hosts: 69.56.223.196 www.startium.com
O1 - Hosts: 69.56.223.196 www.gajai.com
O1 - Hosts: 69.56.223.196 www.wazzupnet.com
O1 - Hosts: 69.56.223.196 freshvideogals.com
O1 - Hosts: 69.56.223.196 www.xgmm.com
O1 - Hosts: 69.56.223.196 searchmyrequest.com
O1 - Hosts: 69.56.223.196 yourbookmarks.ws
O1 - Hosts: 69.56.223.196 wmmse.com
O1 - Hosts: 69.56.223.196 link.startmake.com
O1 - Hosts: 69.56.223.196 www.boredlife.com
O1 - Hosts: 69.56.223.196 approvedlinks.com
O1 - Hosts: 69.56.223.196 www.nkvd.us
O1 - Hosts: 69.56.223.196 www.8095.com
O1 - Hosts: 69.56.223.196 www.dreamwiz.com
O1 - Hosts: 69.56.223.196 ie-search.com
O1 - Hosts: 69.56.223.196 auto.ie.searchforge.com
O1 - Hosts: 69.56.223.196 search.psn.cn
O1 - Hosts: 69.56.223.196 www.couldnotfind.com
O1 - Hosts: 69.56.223.196 www.iquicksearch.com
O1 - Hosts: 69.56.223.196 1-se.com
O1 - Hosts: 69.56.223.196 www.spidersearch.com
O1 - Hosts: 69.56.223.196 search.ieplugin.com
O1 - Hosts: 69.56.223.196 itseasy.us
O1 - Hosts: 69.56.223.196 searchbar.findthewebsiteyouneed.com
O1 - Hosts: 69.56.223.196 www.searchxl.com
O1 - Hosts: 69.56.223.196 www.hotsearchbox.com
O1 - Hosts: 69.56.223.196 www.searchforge.com
O1 - Hosts: 69.56.223.196 www.omega-search.com
O1 - Hosts: 69.56.223.196 searchcentrix.com
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programme\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {2257B486-4918-419F-B701-F4D7668C059F} - C:\WINDOWS\System32\ngpndb.dll (file missing)
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Programme\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: 0190/0900 Warner Browser Helper - {D2F63D33-C571-41E9-9525-A17CA1804D3B} - C:\PROGRA~1\0900WA~1\whelper1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe irprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [HTpatch] C:\WINDOWS\htpatch.exe
O4 - HKLM\..\Run: [SiS KHooker] C:\WINDOWS\System32\khooker.exe
O4 - HKLM\..\Run: [MPB] C:\WINDOWS\System32\MPB.exe
O4 - HKLM\..\Run: [PCTVOICE] pctspk.exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\\NeroCheck.exe
O4 - HKLM\..\Run: [0900 Warner] C:\PROGRA~1\0900WA~1\WARN0900.EXE
O4 - HKLM\..\Run: [0190 Warner] C:\PROGRA~1\0190WA~1\WARN0190.EXE
O4 - HKLM\..\Run: [hh32PEmssy] C:\WINDOWS\system32\hh32PEmssy.exe
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programme\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [u42774i] C:\WINDOWS\system32\u42774i.exe
O4 - HKLM\..\Run: [SynTPLpr] C:\Programme\Synaptics\SynTP\SynTPLpr.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Programme\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Programme\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [LiveMonitor] C:\Programme\MSI\Live Update 3\LMonitor.exe
O4 - HKLM\..\Run: [TkBellExe] C:\Programme\Gemeinsame Dateien\Real\Update_OB\evntsvc.exe -osboot
O4 - HKLM\..\Run: [WinampAgent] C:\Programme\Winamp\winampa.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\ctfmon.exe
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [YAW starten] "C:\Programme\YAW 3.5\yawguard.exe"
O4 - HKCU\..\Run: [MsnMsgr] "C:\Programme\MSN Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [SpywareGuard] C:\WINDOWS\system32\winmm64.exe
O4 - HKCU\..\Run: [hh32PEmssy] C:\WINDOWS\system32\hh32PEmssy.exe
O4 - HKCU\..\Run: [u42774i] C:\WINDOWS\system32\u42774i.exe
O4 - HKCU\..\Run: [Skype] "C:\Programme\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - Global Startup: Adobe Gamma Loader.lnk = C:\Programme\Gemeinsame Dateien\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Global Startup: GStartup.lnk = C:\Programme\Gemeinsame Dateien\GMT\GMT.exe
O4 - Global Startup: InterCheck Monitor.LNK = C:\Programme\Sophos SWEEP for NT\ICMON.EXE
O4 - Global Startup: NkvMon.exe.lnk = C:\Programme\Nikon\NkView6\NkvMon.exe
O8 - Extra context menu item: &Add animation to IncrediMail Style Box - C:\PROGRA~1\INCRED~1\bin\resources\WebMenuImg.htm
O9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programme\Messenger\MSMSGS.EXE
O16 - DPF: {4C39376E-FA9D-4349-BACC-D305C1750EF3} (EPUImageControl Class) - http://tools.ebayimg.com/eps/wl/activex/EPUWALControl_v1-0-3-12.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093188629390
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall-Kontrolle) - http://housecall.trendmicro-europe.com/housecall/Xscan53.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F00F4763-7355-4725-82F7-0DA94A256D46} (IMDownloader Class) - http://www2.incredimail.com/contents/setup/downloader/imloader.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{E7DD5F86-71DF-40D9-9D3E-CBD385BCAA57}: NameServer = 141.2.22.74,141.2.149.10
Any tips?
Vielen vielen Dank!