Administrator - 06-10-27 16:48:49,59 Service Pack 2 ComboFix 06.10.19 - Running from: "H:\Dokumente und Einstellungen\Administrator\Desktop" ((((((((((((((((((((((((((((((( Files Created from 2006-09-27 to 2006-10-27 )))))))))))))))))))))))))))))))))) 2006-10-12 15:10 8,704 --a------ H:\WINDOWS\system32\drivers\ggsemc.sys 2006-10-05 10:43 367,104 --a------ H:\WINDOWS\system32\drivers\Netfwdsl.sys 2006-10-05 10:43 31,232 --a------ H:\WINDOWS\system32\i2errDeu.dll 2006-10-05 10:43 28,160 --a------ H:\WINDOWS\system32\drivers\Aadev.sys 2006-10-05 10:43 11,264 --a------ H:\WINDOWS\system32\drivers\NETDSL.SYS 2006-10-05 10:42 53,760 -ra------ H:\WINDOWS\system32\avmadd32.dll 2006-10-05 10:42 16,896 -ra------ H:\WINDOWS\system32\avmprmon.dll (((((((((((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))) 2006-10-27 15:37 -------- d-------- H:\Programme\CleanUp! 2006-10-27 14:26 -------- d-------- H:\Programme\Google 2006-10-27 13:29 -------- d-------- H:\Programme\VideoKeyCodec 2006-10-27 13:26 -------- d-------- H:\Programme\Apple Software Update 2006-10-27 12:45 -------- d-------- H:\Programme\Letstrade 2006-10-27 12:45 -------- d-------- H:\Programme\Gemeinsame Dateien\Buhl Data Service 2006-10-27 06:48 -------- d-------- H:\Programme\Gemeinsame Dateien\Symantec Shared 2006-10-24 18:12 -------- d-------- H:\Programme\iTunes 2006-10-24 18:12 -------- d-------- H:\Programme\iPod 2006-10-24 18:11 -------- d-------- H:\Programme\QuickTime 2006-10-16 10:52 -------- d-------- H:\Programme\MSXML 4.0 2006-10-12 15:08 -------- d--h----- H:\Programme\Zero G Registry 2006-10-12 15:08 -------- d-------- H:\Programme\Sony Ericsson 2006-10-05 11:38 -------- d-------- H:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\FRITZ! 2006-10-05 10:43 -------- d-------- H:\Programme\Gemeinsame Dateien\AVM 2006-10-05 10:43 -------- d-------- H:\Programme\FRITZ!DSL 2006-10-05 10:42 -------- d-------- H:\Programme\Gemeinsame Dateien 2006-10-05 10:42 -------- d-------- H:\Programme\FRITZ!Box 2006-10-03 17:09 -------- d-------- H:\Programme\Symantec 2006-10-02 18:23 -------- d---s---- H:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Microsoft 2006-10-02 17:59 -------- d-------- H:\Programme\Gemeinsame Dateien\Microsoft Shared 2006-10-02 17:58 -------- d-------- H:\Programme\MSN Messenger 2006-09-27 11:31 -------- d-------- H:\Programme\Gemeinsame Dateien\Teleca Shared 2006-09-26 12:01 -------- d-------- H:\Programme\Belkin 2006-09-25 17:38 -------- d-------- H:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Teleca 2006-09-25 17:37 -------- d-------- H:\Programme\Disc2Phone 2006-09-25 17:25 -------- d--h----- H:\Programme\InstallShield Installation Information 2006-09-17 11:27 -------- d-------- H:\Dokumente und Einstellungen\Administrator\Anwendungsdaten\Google 2006-09-15 22:04 48816 --a------ H:\WINDOWS\system32\S32EVNT1.DLL 2006-09-15 22:04 109744 --a------ H:\WINDOWS\system32\drivers\SYMEVENT.SYS 2006-09-13 07:02 1084416 --a------ H:\WINDOWS\system32\msxml3.dll 2006-09-12 17:51 1245184 --a------ H:\WINDOWS\system32\msxml4.dll 2006-09-12 08:24 -------- d-------- H:\Programme\PDFCreator 2006-09-06 12:06 -------- d-------- H:\Programme\PCODEC 2006-08-25 17:46 617472 --a------ H:\WINDOWS\system32\comctl32.dll 2006-08-21 14:26 16896 --a------ H:\WINDOWS\system32\fltlib.dll 2006-08-21 11:14 23040 --a------ H:\WINDOWS\system32\fltmc.exe 2006-08-16 13:58 100352 --a------ H:\WINDOWS\system32\6to4svc.dll 2006-08-07 16:02 534208 --a------ H:\WINDOWS\system32\SymNeti.dll 2006-08-07 16:02 161472 --a------ H:\WINDOWS\system32\SymRedir.dll 2006-07-29 19:32 48936 --a------ H:\WINDOWS\system32\sirenacm.dll 2006-07-27 15:25 679424 --a------ H:\WINDOWS\system32\inetcomm.dll (((((((((((((((((((((((((((((((((((((((((( Reg Loading Points )))))))))))))))))))))))))))))))))))))))))))))))) *Note* empty entries are not shown [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\run] "CTFMON.EXE"="H:\\WINDOWS\\system32\\ctfmon.exe" "DrvMon.exe"="H:\\WINDOWS\\system32\\DrvMon.exe" "swg"="H:\\Programme\\Google\\GoogleToolbarNotifier\\1.2.908.5008\\GoogleToolbarNotifier.exe" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run] "SunJavaUpdateSched"="H:\\Programme\\Java\\jre1.5.0_06\\bin\\jusched.exe" "type32"="\"H:\\Programme\\Microsoft IntelliType Pro\\type32.exe\"" "IntelliPoint"="\"H:\\Programme\\Microsoft IntelliPoint\\point32.exe\"" "Cmaudio"="RunDll32 cmicnfg.cpl,CMICtrlWnd" "PMCS"="H:\\Programme\\Pinnacle\\Shared Files\\Programs\\MediaCenterService\\PMC.Service.Main.exe -host -clearDebug" "PinnacleDriverCheck"="H:\\WINDOWS\\system32\\PSDrvCheck.exe -CheckReg" "Google Desktop Search"="\"H:\\Programme\\Google\\Google Desktop Search\\GoogleDesktop.exe\" /startup" "ccApp"="\"H:\\Programme\\Gemeinsame Dateien\\Symantec Shared\\ccApp.exe\"" "TkBellExe"="\"H:\\Programme\\Gemeinsame Dateien\\Real\\Update_OB\\realsched.exe\" -osboot" @="" "Sony Ericsson PC Suite"="\"H:\\Programme\\Sony Ericsson\\Mobile2\\Application Launcher\\Application Launcher.exe\" /startoptions" "QuickTime Task"="\"H:\\Programme\\QuickTime\\qttask.exe\" -atboottime" "iTunesHelper"="\"H:\\Programme\\iTunes\\iTunesHelper.exe\"" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\IMAIL] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MAPI] "NoChange"="1" "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\run\OptionalComponents\MSFS] "Installed"="1" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\runservices] "DJSNetCN"="H:\\Programme\\Gemeinsame Dateien\\Symantec Shared\\DJSNETCN.exe" [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components] "DeskHtmlVersion"=dword:00000110 "DeskHtmlMinorVersion"=dword:00000005 "Settings"=dword:00000001 "GeneralFlags"=dword:00000001 [HKEY_CURRENT_USER\software\microsoft\internet explorer\desktop\components\0] "Source"="About:Home" "SubscribedURL"="About:Home" "FriendlyName"="Die derzeitige Homepage" "Flags"=dword:00000002 "Position"=hex:2c,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,00,00,00,\ 00,00,00,01,00,00,00,01,00,00,00,01,00,00,00,00,00,00,00,00,00,00,00 "CurrentState"=hex:04,00,00,40 "OriginalStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,\ 00,00,04,00,00,40 "RestoredStateInfo"=hex:18,00,00,00,00,01,00,00,00,00,00,00,00,04,00,00,e2,03,\ 00,00,01,00,00,00 [HKEY_USERS\.default\software\microsoft\windows\currentversion\run] "CTFMON.EXE"="H:\\WINDOWS\\System32\\CTFMON.EXE" [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\run] "CTFMON.EXE"="H:\\WINDOWS\\System32\\CTFMON.EXE" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\sharedtaskscheduler] "{438755C2-A8BA-11D1-B96B-00A0C90312E1}"="Browseui preloader" "{8C7461EF-2B13-11d2-BE35-3078302C2030}"="Component Categories cache daemon" [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shellexecutehooks] "{AEB6717E-7E19-11d0-97EE-00C04FD91972}"="" [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 "NoDrives"=dword:00000000 "NoViewOnDrive"=dword:00000000 [HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer\Run] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system] "dontdisplaylastusername"=dword:00000000 "legalnoticecaption"="" "legalnoticetext"="" "shutdownwithoutlogon"=dword:00000001 "undockwithoutlogon"=dword:00000001 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer] [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer\run] "isamonitor.exe"="H:\\Programme\\VideoKeyCodec\\isamonitor.exe" "pmsngr.exe"="H:\\Programme\\VideoKeyCodec\\pmsngr.exe" [HKEY_USERS\.default\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_USERS\s-1-5-18\software\microsoft\windows\currentversion\policies\explorer] "NoDriveTypeAutoRun"=dword:00000091 [HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\shellserviceobjectdelayload] "PostBootReminder"="{7849596a-48ea-486e-8937-a2a3009f31a9}" "CDBurn"="{fbeb8a05-beee-4442-804e-409d6c4515e9}" "WebCheck"="{E6FB5E20-DE35-11CF-9C87-00AA005127ED}" "SysTray"="{35CEC8A3-2BE6-11D2-8773-92E220524153}" [HKEY_LOCAL_MACHINE\system\currentcontrolset\control\securityproviders] "SecurityProviders"="msapsspc.dll, schannel.dll, digest.dll, msnsspc.dll" Contents of the 'Scheduled Tasks' folder H:\WINDOWS\tasks\AppleSoftwareUpdate.job H:\WINDOWS\tasks\Norton AntiVirus - Vollst„ndige Systemprfung ausfhren - Administrator.job Completion time: 06-10-27 16:49:29.96 H:\ComboFix.txt ... 06-10-27 16:49 H:\ComboFix2.txt ... 06-10-27 15:51