Ich mache mal einen Doppelpost, sonst wird es vll. etwas unübersichtlich.
SDFix-Log: Code:
SDFix: Version 1.221
Run by admin on Sat 09/06/2008 at 03:43 PM
Microsoft Windows XP [Version 5.1.2600]
Running From: F:\SDFix\SDFix Checking Services :
Restoring Default Security Values
Restoring Default Hosts File
Rebooting Checking Files :
Trojan Files Found:
F:\DOCUME~1\*\APPLIC~1\THINST~1\POWERA~1.6\400000~1\TAG.EXE - Deleted
Removing Temp Files ADS Check :
Final Check :
catchme 0.3.1361.2 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-09-06 15:46:58
Windows 5.1.2600 Service Pack 3 NTFS
scanning hidden processes ...
scanning hidden services & system hive ...
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg]
"s1"=dword:2df9c43f
"s2"=dword:110480d0
"h0"=dword:00000001
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:90,60,bd,5b,a2,63,3a,ac,5d,ff,bd,ce,50,45,cc,99,67,8c,93,0e,f1,..
"p0"="h:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,46,a3,75,ee,0f,b2,c5,89,f2,94,2e,b6,16,a8,99,15,28,..
"khjeh"=hex:c3,aa,28,70,1d,3b,0e,d7,97,07,7f,dd,c9,97,7f,31,96,dc,5d,48,92,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:db,2f,8d,c8,bb,07,24,68,99,84,93,2b,7a,8d,15,27,4b,ed,31,38,99,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:b7,34,85,43,a6,94,ec,55,7a,f0,26,5b,29,d0,a0,e5,3e,ac,93,25,9c,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:c9,8c,16,59,c3,9b,f9,af,ef,c1,da,8d,4b,f3,c8,d7,7b,4a,e2,f6,f4,..
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43]
"khjeh"=hex:03,77,15,e1,8f,34,d9,09,59,6d,35,b1,9c,4b,72,5e,58,72,5e,87,f5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:90,60,bd,5b,a2,63,3a,ac,5d,ff,bd,ce,50,45,cc,99,67,8c,93,0e,f1,..
"p0"="h:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,46,a3,75,ee,0f,b2,c5,89,f2,94,2e,b6,16,a8,99,15,28,..
"khjeh"=hex:c3,aa,28,70,1d,3b,0e,d7,97,07,7f,dd,c9,97,7f,31,96,dc,5d,48,92,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:72,50,5f,57,22,c4,9a,eb,16,e8,17,f1,16,62,f9,6f,24,88,51,93,13,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:55,89,c6,a3,ad,99,34,74,99,a3,36,f5,98,f8,84,8d,2f,c2,a0,39,1b,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:c9,8c,16,59,c3,9b,f9,af,ef,c1,da,8d,4b,f3,c8,d7,7b,4a,e2,f6,f4,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43]
"khjeh"=hex:03,77,15,e1,8f,34,d9,09,59,6d,35,b1,9c,4b,72,5e,58,72,5e,87,f5,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4]
"h0"=dword:00000000
"khjeh"=hex:90,60,bd,5b,a2,63,3a,ac,5d,ff,bd,ce,50,45,cc,99,67,8c,93,0e,f1,..
"p0"="h:\Program Files\DAEMON Tools\"
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001]
"a0"=hex:20,01,00,00,46,a3,75,ee,0f,b2,c5,89,f2,94,2e,b6,16,a8,99,15,28,..
"khjeh"=hex:c3,aa,28,70,1d,3b,0e,d7,97,07,7f,dd,c9,97,7f,31,96,dc,5d,48,92,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf40]
"khjeh"=hex:db,2f,8d,c8,bb,07,24,68,99,84,93,2b,7a,8d,15,27,4b,ed,31,38,99,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf41]
"khjeh"=hex:b7,34,85,43,a6,94,ec,55,7a,f0,26,5b,29,d0,a0,e5,3e,ac,93,25,9c,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf42]
"khjeh"=hex:c9,8c,16,59,c3,9b,f9,af,ef,c1,da,8d,4b,f3,c8,d7,7b,4a,e2,f6,f4,..
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet003\Services\sptd\Cfg\19659239224E364682FA4BAF72C53EA4\00000001\0Jf43]
"khjeh"=hex:03,77,15,e1,8f,34,d9,09,59,6d,35,b1,9c,4b,72,5e,58,72,5e,87,f5,..
scanning hidden registry entries ...
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\System]
"OODEFRAG10.00.00.01WORKSTATION"="801906291272F4655BDA426EBAB48615D327CBDB60FB2227B8CA0FB309B47D90647C81B3A32C78D655A1EA331FB5B1D5515141139C9FA6DC1BB90EFE2CF7E61040C4707E221ED8A6641C2251682E07F2B0ED11A8F9AB88B848110F1E5B8EF0564AE98909A81550BCF030D3A03465CA39ADEF8167B904B78EE7EF506F949CD25BBF5A25E9970F8354E637140A63D72AC9033EFDADD9458683296CB5689BF8A9EADFF53FCB9340F4FCB801980C1B36B197753315EF2439AD913F0C478FF6AC75A26D91F8E88590109AD84E3AB8C56653ECC89F7A35A0E3C886614CB004F2F61CF5B0761793981BA1E54256F7B78E00E6E6FEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CFEBC9E127BECC74CA6A0AC4980AC7933A2D97226D213B555C038D530D6EB3452A2D97226D213B555C3851C42CE37FEEF20AF5DC6E2C386B85E79803225E481EAA81FA2BACAFE39C4797B4F62EFCD40ADB04B441ABA088FF23934D1AE8350A36A4321430E9800ACD50873DAD28B35D69A9F7AD7A910BA16CC6A4217FDE5BF110984B0B8F95D5289164DEE5D5D663FE7E77F2CEF95A6AF49DBD4A0FD32B11FA05DBEF4A8294121EE452DE317DD86747D976341838D8868B988DC3EDA7491118F574A0960552ECA60F691BA6B483A108583E49032D9831FDE0FEDFC237E73E9FBB7817ECECFD1E0C70F624FE59E8F024FD520E43E5327BF1481F4B472208A35E915C158897CA22CF04B13F4B17C5C6D138F367A0DE9C9EA154363AF873D4BAE4058EE8EC6D455A40CB914EEA08DB7A967834C84279E8375870E2FAE454B7149CA3FEE0E62E365FAAD3CDF762715FE43CB5A0AA8BC093267EE6ED0E2B25879A9B85C2D35DD4A93104E897038DD66D1F89F8F9B021F51F67DB744C7F3F98127291D1517DADBBC60FA4AAD4557026B93BDAA72B21D43B7B6A8AE4614FC6B7AFE55EF2321C325831507E207636674A26DBA95A784FBC30D9B0C08FABC0D780BCCF08D94C0AE2479BCB13A48506F3A1C4AC8ECA549155E3991035941C927B88E1DEF334AF0C96A1126AEDAF69A70FC7DDBFAA138BBD374B44A969C48CAC16873C3FB067A30BAAA4D6362B0EECED887FE15128A019F140D8EBA0AB015D049633D56740C3180973D464C698BDF030F4DEEAE07E073B7A9D0E91C50D702F09BAF04AEE832C7E96D1E29FC12A04BCD6AE02FA484C1D44D598E7CEA93383A450CF172EA1F4673F53D6EB4D35D07884A39FCB337EAAFC32C5DB80FE9AD5CBE6AE17648EC12FCB934F96FBF7383BCC119BCFC076B4C8DAE25E3E3039CB233E404D7AA58DB6D6D72378B8AAF446FA1F65EA86345877126590F8FCAC74D638FD4B59CA389A09391CC94CD4C8270BCF9794027542019D6275BBE754AE4093BA58B2A5417576A9A4B4AE612E2C867C0EDF0"
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Prefetcher]
"TracesProcessed"=dword:00000084
"TracesSuccessful"=dword:00000006
scanning hidden files ...
scan completed successfully
hidden processes: 0
hidden services: 0
hidden files: 0 Remaining Services :
Authorized Application Key Export:
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\standardprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000"
"H:\\Program Files\\ICQ6\\ICQ.exe"="H:\\Program Files\\ICQ6\\ICQ.exe:*:Enabled:ICQ6"
"H:\\Games\\Copy of EVE\\bin\\ExeFile.exe"="H:\\Games\\Copy of EVE\\bin\\ExeFile.exe:*:Enabled:CCP ExeFile"
"H:\\Games\\Steam2\\steamapps\\zwei1\\counter-strike\\hl.exe"="H:\\Games\\Steam2\\steamapps\\zwei1\\counter-strike\\hl.exe:*:Enabled:Half-Life Launcher"
"H:\\Games\\EVE\\bin\\ExeFile.exe"="H:\\Games\\EVE\\bin\\ExeFile.exe:*:Enabled:CCP ExeFile"
"H:\\Games\\Unreal Anthology2\\UT2004\\System\\UT2004.exe"="H:\\Games\\Unreal Anthology2\\UT2004\\System\\UT2004.exe:*:Enabled:UT2004"
"H:\\Games\\Clonk Rage\\Clonk.exe"="H:\\Games\\Clonk Rage\\Clonk.exe:*:Enabled:Clonk Rage"
"I:\\Games\\UT3\\Binaries\\UT3.exe"="I:\\Games\\UT3\\Binaries\\UT3.exe:*:Enabled:Unreal Tournament 3"
"F:\\Program Files\\uTorrent\\uTorrent.exe"="F:\\Program Files\\uTorrent\\uTorrent.exe:*:Enabled:æTorrent"
"I:\\Games\\Civilization 4\\Civilization4.exe"="I:\\Games\\Civilization 4\\Civilization4.exe:*:Enabled:Sid Meier's Civilization 4"
"F:\\Program Files\\Skype\\Phone\\Skype.exe"="F:\\Program Files\\Skype\\Phone\\Skype.exe:*:Enabled:Skype"
[HKEY_LOCAL_MACHINE\system\currentcontrolset\services\sharedaccess\parameters\firewallpolicy\domainprofile\authorizedapplications\list]
"%windir%\\system32\\sessmgr.exe"="%windir%\\system32\\sessmgr.exe:*:enabled:@xpsp2res.dll,-22019"
"%windir%\\Network Diagnostic\\xpnetdiag.exe"="%windir%\\Network Diagnostic\\xpnetdiag.exe:*:Enabled:@xpsp3res.dll,-20000" Remaining Files :
File Backups: - F:\SDFix\SDFix\backups\backups.zip Files with Hidden Attributes :
Sun 13 Jan 2008 0 A.SH. --- F:\DOCUME~1\ALLUSE~1\DRM\CACHE\INDIV01.TMP Finished! Anm.: Kann den Accountnamen dazuschreiben, wenn das behilflich ist.
Nun das Hijackthis-Log: Code:
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 3:53:03 PM, on 9/6/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
F:\WINDOWS\System32\smss.exe
F:\WINDOWS\system32\winlogon.exe
F:\WINDOWS\system32\services.exe
F:\WINDOWS\system32\lsass.exe
F:\WINDOWS\system32\Ati2evxx.exe
F:\WINDOWS\system32\svchost.exe
F:\WINDOWS\System32\svchost.exe
I:\Program Files\Adaware\aawservice.exe
F:\WINDOWS\system32\Ati2evxx.exe
F:\WINDOWS\system32\spoolsv.exe
F:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
F:\WINDOWS\Explorer.EXE
F:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
F:\WINDOWS\system32\oodag.exe
F:\WINDOWS\system32\wscntfy.exe
F:\WINDOWS\system32\notepad.exe
F:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe
F:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe
F:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe
F:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
H:\Program Files\Winamp\winampa.exe
F:\Program Files\Common Files\Real\Update_OB\realsched.exe
F:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDClock.exe
F:\Program Files\Logitech\GamePanel Software\LCD Manager\Applets\LCDCountdown.exe
H:\Program Files\DAEMON Tools\daemon.exe
F:\WINDOWS\system32\ctfmon.exe
F:\Program Files\PeerGuardian2\pg2.exe
F:\Program Files\Logitech\SetPoint\SetPoint.exe
H:\Program Files\OpenOffice.org 2.3\program\soffice.exe
F:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
H:\Program Files\OpenOffice.org 2.3\program\soffice.BIN
H:\Program Files\Firefox 3.0\firefox.exe
H:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = 192.168.0.1:80
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - F:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O4 - HKLM\..\Run: [avgnt] "F:\Program Files\Avira\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
O4 - HKLM\..\Run: [Launch LCDMon] "F:\Program Files\Logitech\GamePanel Software\LCD Manager\LCDMon.exe"
O4 - HKLM\..\Run: [Launch LGDCore] "F:\Program Files\Logitech\GamePanel Software\G-series Software\LGDCore.exe" /SHOWHIDE
O4 - HKLM\..\Run: [SunJavaUpdateSched] "F:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [WinampAgent] "H:\Program Files\Winamp\winampa.exe"
O4 - HKLM\..\Run: [TkBellExe] "F:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [IMJPMIG8.1] "F:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] F:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] F:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [QuickTime Task] "H:\Program Files\Quicktime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [UpdReg] UpdReg.exe
O4 - HKLM\..\RunOnce: [CTxfiReg] CTxfiReg.exe /FAIL0
O4 - HKLM\..\RunOnce: [CTxfiHlp] CTxfiHlp.exe
O4 - HKLM\..\RunOnce: [YouP-PAX 3.63.03 Tone Color Restorer] F:\WINDOWS\system32\Fi2.32tcr2.2.exe
O4 - HKCU\..\Run: [DAEMON Tools] "h:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [ctfmon.exe] F:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [PeerGuardian] F:\Program Files\PeerGuardian2\pg2.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] F:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')
O4 - Startup: OpenOffice.org 2.3.lnk = H:\Program Files\OpenOffice.org 2.3\program\quickstart.exe
O4 - Startup: Shortcut to SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe
O4 - Global Startup: Logitech SetPoint.lnk = F:\Program Files\Logitech\SetPoint\SetPoint.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - F:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - F:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1200172691093
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{4EA99AF0-6D60-436A-90B1-CB84292B67F8}: NameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\..\{D8B7F0D3-FB52-4746-8923-5868B0480473}: NameServer = 192.168.0.1
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - F:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - I:\Program Files\Adaware\aawservice.exe
O23 - Service: AntiVir PersonalEdition Classic Scheduler (AntiVirScheduler) - Avira GmbH - F:\Program Files\Avira\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Guard (AntiVirService) - Avira GmbH - F:\Program Files\Avira\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - F:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - F:\WINDOWS\system32\ati2sgag.exe
O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - F:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe
O23 - Service: O&O Defrag - O&O Software GmbH - F:\WINDOWS\system32\oodag.exe
O23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - F:\Program Files\WinPcap\rpcapd.exe
--
End of file - 6976 bytes edit: Ein Zombie weniger. Was nun? |